1
00:00:00,200 --> 00:00:02,760
Secure your Elixir apps with 
paraxial IO. 

2
00:00:02,920 --> 00:00:06,000
From code analysis and bot 
defense to dependency checks, 

3
00:00:06,000 --> 00:00:09,240
they've got you covered. 
Elixir first design with GitHub 

4
00:00:09,240 --> 00:00:11,640
integration. 
Elevate your security at 

5
00:00:11,640 --> 00:00:16,600
paraxial dot IO. 
This episode is brought to you 

6
00:00:16,600 --> 00:00:19,040
by Beam OPS. 
If your Elixir deployments are 

7
00:00:19,040 --> 00:00:22,080
painful, or your infrastructure 
is a mess, or you just need 

8
00:00:22,080 --> 00:00:25,000
experience hands to help you 
scale, these are your people. 

9
00:00:25,200 --> 00:00:28,960
Beam OPS specializes in scalable
Elixir development, automated 

10
00:00:28,960 --> 00:00:31,560
deployment pipelines, and 
infrastructure migrations. 

11
00:00:31,760 --> 00:00:34,480
They will help you work smarter 
and ship faster. 

12
00:00:34,680 --> 00:00:38,840
As authors of the Pragprog book 
Engineering Elixir Applications,

13
00:00:38,840 --> 00:00:43,280
they know their stuff. 
Check them out at beamops.co.uk 

14
00:00:46,280 --> 00:00:50,920
testing. 
What's up? 

15
00:00:50,960 --> 00:00:53,680
I'm Jacob Blitzo, your Elixir 
mentor and welcome to another 

16
00:00:53,680 --> 00:00:56,280
exciting episode of the Elixir 
Mentor Podcast. 

17
00:00:56,280 --> 00:00:58,520
This is where we discuss 
everything related to Elixir, 

18
00:00:58,520 --> 00:01:00,520
from interviews with 
enthusiasts, pioneers in the 

19
00:01:00,520 --> 00:01:03,960
community to innovative projects
and libraries shaping Elixir's 

20
00:01:03,960 --> 00:01:05,960
future. 
Today I'm joined by returning 

21
00:01:05,960 --> 00:01:10,240
guest Michael Lubas, CEO of 
Perexial IO here to talk about a

22
00:01:10,240 --> 00:01:14,040
is kind of two sided role in 
security, finding bugs and 

23
00:01:14,040 --> 00:01:17,240
writing them. 
Welcome back Michael. 

24
00:01:17,440 --> 00:01:21,240
I'm excited to to to chat. 
I feel like I always learn a lot

25
00:01:21,240 --> 00:01:24,200
when you come on. 
Thank you, Jacob. 

26
00:01:24,240 --> 00:01:27,160
I've been looking forward to 
coming back on the show as well.

27
00:01:27,400 --> 00:01:31,040
There's certainly been a lot of 
things that have happened since 

28
00:01:31,080 --> 00:01:34,040
we last spoke and I've just been
looking forward to it. 

29
00:01:34,960 --> 00:01:41,720
Yeah, we had a lot of like, I, I
don't know, do you like you, we 

30
00:01:41,720 --> 00:01:46,120
were projecting a lot of like 
the AI slop and what, what, what

31
00:01:46,120 --> 00:01:47,680
is that going to look like for 
development? 

32
00:01:47,960 --> 00:01:50,040
And I think when were you back? 
When were you on? 

33
00:01:50,040 --> 00:01:52,800
Was it September? 
I don't remember. 

34
00:01:53,360 --> 00:01:54,480
Six months. 
A year ago it was. 

35
00:01:54,480 --> 00:01:56,680
A while ago it was not. 
It was not recent at all. 

36
00:01:57,320 --> 00:02:03,400
Yeah, I feel like we we get you 
back every year now I'd like to 

37
00:02:03,400 --> 00:02:06,360
have you back on more. 
Yeah. 

38
00:02:06,360 --> 00:02:12,160
So I'm, I'm trying to think we 
kind of talked about let's see 

39
00:02:12,960 --> 00:02:16,560
you you were launching a new 
version of Paraxial or in the 

40
00:02:16,560 --> 00:02:19,960
midst of kind of building a new 
version when you're on. 

41
00:02:20,240 --> 00:02:26,320
And then we were also talking 
about just AI slop in general 

42
00:02:26,320 --> 00:02:28,400
and what we thought was going to
happen. 

43
00:02:28,440 --> 00:02:32,720
And then in the recent days, 
we've been seeing a lot of 

44
00:02:32,720 --> 00:02:36,160
articles like Peter Ulrich and 
all of that, and all these 

45
00:02:36,720 --> 00:02:45,080
vulnerabilities being discovered
by AI and yeah, what are you 

46
00:02:45,080 --> 00:02:49,040
kind? 
Of seeing there right now, 

47
00:02:49,040 --> 00:02:51,720
there's definitely been this 
inflection point where the 

48
00:02:51,720 --> 00:02:54,440
models have gotten a lot better.
And it's really not an 

49
00:02:54,440 --> 00:03:00,880
exaggeration to say that AI has 
become the most important and 

50
00:03:00,880 --> 00:03:05,960
influential factor in 
cybersecurity, arguably since 

51
00:03:05,960 --> 00:03:08,360
the Internet, maybe even more 
than the Internet, depending on 

52
00:03:08,360 --> 00:03:10,880
how things go. 
I don't want to get ahead too 

53
00:03:10,880 --> 00:03:15,200
much because the the big news 
that I think is relevant for 

54
00:03:15,200 --> 00:03:19,320
your audience, like I couldn't 
talk about at the time, but was 

55
00:03:19,320 --> 00:03:21,880
that paraxial? 
I was involved with a 

56
00:03:21,880 --> 00:03:26,400
penetration test of the HEX 
package manager, which most 

57
00:03:26,400 --> 00:03:27,840
listeners are probably familiar 
with. 

58
00:03:29,760 --> 00:03:34,200
So that project was actually run
by the Erlang Ecosystem 

59
00:03:34,200 --> 00:03:37,160
Foundation and the Aegis 
Initiative. 

60
00:03:38,000 --> 00:03:42,240
So that initiative was started 
by Jonathan, who's the Sizzo of 

61
00:03:42,240 --> 00:03:46,320
the foundation, which is a 
nonprofit that actually handles 

62
00:03:46,320 --> 00:03:53,000
the CV ES, which is basically a 
a vulnerability for a piece of 

63
00:03:53,000 --> 00:03:55,720
software, which we'll get into 
in this show because that's 

64
00:03:55,720 --> 00:03:57,280
where all of this news is coming
from. 

65
00:03:57,280 --> 00:03:59,200
The EEF. 
Essentially, if there's a 

66
00:03:59,200 --> 00:04:03,160
vulnerability in an Elixir 
package, Jonathan is the person 

67
00:04:03,160 --> 00:04:06,400
that's involved in the 
classification and coordination 

68
00:04:06,400 --> 00:04:11,600
of that. 
So he started this program with 

69
00:04:11,600 --> 00:04:14,760
the leadership of Alistair, who 
I should mention as the EEF 

70
00:04:14,760 --> 00:04:18,200
board President. 
And Alistair has been extremely 

71
00:04:18,200 --> 00:04:22,040
productive in raising money for 
this because as you can imagine,

72
00:04:22,800 --> 00:04:26,320
having Jonathan work on this 
full time hiring actually 2 

73
00:04:26,320 --> 00:04:30,360
firms, Praxial was one of the 
ones selected that cost money. 

74
00:04:31,400 --> 00:04:34,280
And this work was actually 
funded through an initiative 

75
00:04:34,280 --> 00:04:38,000
called Alpha Omega, which is 
under the Linux Foundation. 

76
00:04:38,400 --> 00:04:43,560
And some of the sponsors 
included Anthropic, AWS, Citi, 

77
00:04:43,560 --> 00:04:48,480
GitHub, Google, Google DeepMind,
Microsoft Open AI. 

78
00:04:48,480 --> 00:04:51,200
So I'd like to say thank you to 
all of those organizations if 

79
00:04:51,200 --> 00:04:55,400
anyone from them is listening. 
The work was extremely 

80
00:04:55,400 --> 00:04:57,280
beneficial to the Elixir 
community. 

81
00:04:57,560 --> 00:05:02,040
So not only can the Elixir 
community now go to the wider 

82
00:05:02,040 --> 00:05:05,000
programming world and say, you 
know, what's our package manager

83
00:05:05,000 --> 00:05:06,800
story? 
Not it's not. 

84
00:05:06,800 --> 00:05:09,640
And it's not always, you know, 
roses and everything's great. 

85
00:05:10,480 --> 00:05:13,280
There are controversies and 
problems with package managers, 

86
00:05:13,480 --> 00:05:16,400
but I think the Elixir community
has an extremely strong 

87
00:05:16,880 --> 00:05:20,000
narrative now based on facts, 
which is, you know, we hired 

88
00:05:20,000 --> 00:05:23,760
these two firms. 
Praxeal, I was actually honored 

89
00:05:23,760 --> 00:05:27,560
because I was able to stop our 
MO code execution vulnerability 

90
00:05:27,800 --> 00:05:30,560
that I found during the test. 
I prevented it from being 

91
00:05:30,560 --> 00:05:34,240
released. 
So there's actually no CVE in 

92
00:05:34,240 --> 00:05:36,280
the sense of a vulnerability 
that you have to. 

93
00:05:36,280 --> 00:05:39,640
Patch 1 was issued by Jonathan 
very prudently, but it never 

94
00:05:39,640 --> 00:05:42,960
showed up in your scanner 
because it was actually fixed 

95
00:05:42,960 --> 00:05:46,040
before the release. 
So I think that work was really 

96
00:05:46,040 --> 00:05:49,800
important because now as 
cybersecurity gets probably more

97
00:05:49,800 --> 00:05:53,920
important than ever, the Elixir 
community has this very strong 

98
00:05:54,280 --> 00:05:56,680
evidence that can point to you 
saying, you know, thank you so 

99
00:05:56,680 --> 00:05:58,520
much to everyone who funded 
this. 

100
00:05:59,160 --> 00:06:01,520
Elixir has an extremely secure 
base. 

101
00:06:01,720 --> 00:06:03,760
We're taking security very 
seriously. 

102
00:06:04,080 --> 00:06:06,480
And the stewardship of Hex, you 
know, I should, I should mention

103
00:06:06,480 --> 00:06:08,880
Eric as well. 
He's fantastic. 

104
00:06:09,560 --> 00:06:12,160
And the whole Elixir core team, 
they take this work extremely 

105
00:06:12,160 --> 00:06:15,080
seriously. 
So you have this secure, 

106
00:06:15,080 --> 00:06:20,960
actively maintained ecosystem, 
which really is what companies 

107
00:06:20,960 --> 00:06:23,960
should be looking for if you're 
going to be building your 

108
00:06:24,640 --> 00:06:28,320
company, your government 
software, your nonprofit or 

109
00:06:28,320 --> 00:06:31,360
hospital systems on top of an 
open source ecosystem. 

110
00:06:32,040 --> 00:06:34,560
I think Elixir is probably one 
of the best, if not the best 

111
00:06:34,560 --> 00:06:36,920
right now. 
So yeah. 

112
00:06:36,920 --> 00:06:38,960
What do you think about that 
though, from your perspective? 

113
00:06:39,120 --> 00:06:41,920
I mean, from my perspective that
just sounds awesome, right? 

114
00:06:41,920 --> 00:06:46,640
Like it gives me Peace of Mind 
because I've built a lot of 

115
00:06:46,640 --> 00:06:52,040
products and Elixir is pretty 
much always my stack now. 

116
00:06:52,040 --> 00:06:55,280
So it's just everything is on 
the beam. 

117
00:06:55,400 --> 00:07:02,920
And yeah, I use Paraxial myself 
with, with my own products and 

118
00:07:03,520 --> 00:07:07,920
it yeah, I think it's really 
cool to see initiatives like 

119
00:07:07,920 --> 00:07:13,600
this and it's really cool to 
watch Paraxial find, you know, 

120
00:07:13,600 --> 00:07:17,000
compromising code and security 
flaws in things. 

121
00:07:17,000 --> 00:07:19,720
Like, it's got to be cool for 
you to see as you're doing an 

122
00:07:19,720 --> 00:07:24,680
audit to actually catch things 
before anything hits production.

123
00:07:25,720 --> 00:07:28,480
Yeah, that was a really 
important moment during that 

124
00:07:28,480 --> 00:07:31,040
test. 
I remember talking to Jonathan 

125
00:07:31,040 --> 00:07:34,160
and then Eric and mentioning, 
hey, you know, I found this a 

126
00:07:34,160 --> 00:07:36,720
problem. 
This could be extremely bad. 

127
00:07:36,960 --> 00:07:40,120
But fortunately, I, I was 
checking the git, you know, 

128
00:07:40,120 --> 00:07:43,880
branches and everything, and it 
hadn't been released yet, which 

129
00:07:43,880 --> 00:07:47,480
was really great to see. 
So I, I do want to say thank you

130
00:07:47,480 --> 00:07:49,920
as well to the, you know, the 
Hex core team and you know, 

131
00:07:49,920 --> 00:07:51,800
everyone involved because it's 
not just Hex. 

132
00:07:51,800 --> 00:07:55,360
There's all of these packages 
across the ecosystem that take 

133
00:07:55,360 --> 00:07:59,960
security so seriously. 
As one example, which I think is

134
00:08:00,240 --> 00:08:04,440
really worth calling out. 
Have you heard of these recent 

135
00:08:04,440 --> 00:08:07,840
campaigns with GitHub Actions 
where packages have been 

136
00:08:07,840 --> 00:08:13,720
backdoored by GitHub Actions? 
So what happens is let's say you

137
00:08:13,720 --> 00:08:16,160
have a package that a lot of 
people install. 

138
00:08:16,160 --> 00:08:19,800
There were there were a few, but
essentially most people use 

139
00:08:19,800 --> 00:08:25,280
GitHub Actions now to take code 
from pull requests and you know,

140
00:08:25,280 --> 00:08:28,160
probably do something based on 
that code usually run like a 

141
00:08:28,160 --> 00:08:32,200
CICD check. 
When GitHub was first first 

142
00:08:32,200 --> 00:08:34,520
became popular, this this didn't
exist. 

143
00:08:34,520 --> 00:08:37,000
This kind of grew as GitHub 
became more and more important 

144
00:08:37,000 --> 00:08:41,559
to open source and what the bad 
guys have noticed and in some 

145
00:08:41,559 --> 00:08:43,240
cases they were using AI for 
this. 

146
00:08:43,240 --> 00:08:46,760
I think it was called clawed. 
You know that the lobster I I 

147
00:08:46,760 --> 00:08:49,080
can never keep up with the name.
So it was like the mole bot. 

148
00:08:49,080 --> 00:08:52,320
Open claw or whatever. 
Yeah, But there was a version 

149
00:08:52,320 --> 00:08:56,640
that hacked GitHub repositories.
And the way it worked, it wasn't

150
00:08:56,640 --> 00:08:58,360
actually targeting the 
application code. 

151
00:08:58,360 --> 00:08:59,880
So it'd be like a Python 
project. 

152
00:09:01,000 --> 00:09:04,280
It was actually targeting GitHub
Actions, meaning the attacker 

153
00:09:04,280 --> 00:09:07,680
would submit some malicious 
code, the attacker controlled 

154
00:09:07,680 --> 00:09:10,720
code would be executed in the 
context of a GitHub action, 

155
00:09:10,840 --> 00:09:12,760
which could steal API 
credentials. 

156
00:09:13,080 --> 00:09:17,400
And then people often have 
releases tied to GitHub actions.

157
00:09:17,680 --> 00:09:22,480
So now the bad guy has the 
ability to push a backdoor, you 

158
00:09:22,480 --> 00:09:25,040
know, Trojan release, which is 
basically malware. 

159
00:09:25,440 --> 00:09:27,840
And the big problem with that is
it spreads. 

160
00:09:28,920 --> 00:09:32,400
So once the package is infected,
it's in the pipeline. 

161
00:09:32,400 --> 00:09:37,120
A lot of developers just have 
auto update on why for security.

162
00:09:37,400 --> 00:09:40,600
Well, in this case people are 
saying don't do that anymore. 

163
00:09:40,600 --> 00:09:42,800
There's like a cool down period 
because it just spreads 

164
00:09:42,800 --> 00:09:45,760
instantly as soon as well. 
Cause yeah, now you're reading 

165
00:09:45,760 --> 00:09:48,880
like with MPM packages. 
Wait your seven days so 

166
00:09:49,160 --> 00:09:51,400
vulnerabilities are discovered 
and patched. 

167
00:09:51,800 --> 00:09:56,080
And that's exactly why, because 
what happened is the malware we 

168
00:09:56,080 --> 00:09:58,360
get downloaded to the machine 
then propagate across the 

169
00:09:58,360 --> 00:10:01,960
developer's GitHub credentials. 
So this is a huge problem. 

170
00:10:01,960 --> 00:10:05,360
They're they're active campaigns
ongoing right now. 

171
00:10:05,480 --> 00:10:08,280
I think you can find some 
literally within the last week 

172
00:10:08,440 --> 00:10:10,200
where this. 
I'm sure it's kind of 

173
00:10:10,240 --> 00:10:12,840
terrifying, honestly. 
And this was going on during the

174
00:10:12,840 --> 00:10:14,520
pen test, which was a few weeks 
ago. 

175
00:10:16,360 --> 00:10:19,640
So as a result of this 
penetration test, the 

176
00:10:19,640 --> 00:10:24,240
Praxillaire report, which is 
public Elixir, the actual Elixir

177
00:10:24,240 --> 00:10:28,760
repo itself, Hex, I believe 
Gleam and some Erlang 

178
00:10:28,760 --> 00:10:32,360
repositories, they're all using 
Zsmore right now, which is this 

179
00:10:32,360 --> 00:10:36,080
open source tool to detect if 
your GitHub actions are 

180
00:10:36,080 --> 00:10:37,840
vulnerable. 
I suppose I should I should 

181
00:10:37,840 --> 00:10:42,920
mention this for your audience. 
If you are watching this stream 

182
00:10:42,920 --> 00:10:46,200
and you are a maintainer of a 
package or maybe you're just 

183
00:10:46,200 --> 00:10:49,840
involved in a package, I think a
lot of people in Elixir are. 

184
00:10:50,080 --> 00:10:55,280
I would check to see if the 
package is using GitHub Actions 

185
00:10:55,280 --> 00:10:59,480
for building releases, and if it
is, I'd highly highly highly 

186
00:10:59,480 --> 00:11:02,200
recommend I. 
I like Ziz more because it's 

187
00:11:02,200 --> 00:11:07,400
very fast, it's written in Rust,
and installing that and taking 

188
00:11:07,400 --> 00:11:10,320
the findings very seriously. 
That will prevent the package 

189
00:11:10,320 --> 00:11:11,840
from potentially being 
backdoored. 

190
00:11:12,440 --> 00:11:15,880
Fortunately, during the Elixir 
pen test, there were some 

191
00:11:15,880 --> 00:11:18,680
findings, but none of them were 
actually exploitable by a bad 

192
00:11:18,680 --> 00:11:22,120
guy. 
It it's sort of this weird state

193
00:11:22,120 --> 00:11:25,640
where a lot of GitHub repos have
been exploited. 

194
00:11:25,640 --> 00:11:27,400
So you think, oh, if I was 
vulnerable, I probably would 

195
00:11:27,400 --> 00:11:30,840
have been exploited by now. 
But on the other hand, new 

196
00:11:32,280 --> 00:11:34,200
packages keep getting exploited 
every day. 

197
00:11:34,200 --> 00:11:36,520
So it's not that simple. 
So I, I highly recommend 

198
00:11:36,520 --> 00:11:39,160
checking for that. 
If you only get one thing from 

199
00:11:39,160 --> 00:11:42,240
this podcast that I know it, it 
can all kind of blend together. 

200
00:11:42,480 --> 00:11:45,480
I if you maintain an elixir 
package or any open source 

201
00:11:45,480 --> 00:11:48,640
package and you use open source.
This isn't even a praxial app, 

202
00:11:48,640 --> 00:11:49,880
by the way. 
I'm not like affiliated with 

203
00:11:49,880 --> 00:11:51,560
this more. 
It's it's one guy. 

204
00:11:52,200 --> 00:11:54,240
Praxial has no financial stake 
in that at all. 

205
00:11:54,240 --> 00:11:56,360
So I'm not even, I'm not even 
promoting. 

206
00:11:56,360 --> 00:11:58,760
I, I that's it's totally free. 
It's open source. 

207
00:11:58,760 --> 00:12:05,400
I recommend that go do that. 
I'm curious, like obviously this

208
00:12:05,400 --> 00:12:08,560
isn't just going to affect open 
source packages, right? 

209
00:12:08,560 --> 00:12:12,400
It could affect SAS any like 
anything where you're using 

210
00:12:12,440 --> 00:12:16,360
GitHub Actions to build a 
product or have API keys 

211
00:12:16,360 --> 00:12:20,080
available, right? 
Or yeah, power plants, you know,

212
00:12:20,080 --> 00:12:24,200
electricity delivery, water, 
basic infrastructure, things 

213
00:12:24,200 --> 00:12:26,920
like that, you know, open source
packages used everywhere and, 

214
00:12:26,920 --> 00:12:29,320
and you know, do the train shop 
today. 

215
00:12:29,560 --> 00:12:31,960
That's sort of, but people don't
expect that. 

216
00:12:31,960 --> 00:12:34,120
You kind of think in terms of 
your own work usually. 

217
00:12:35,160 --> 00:12:41,160
Yeah, it's, I feel like like 
when you hear things like this, 

218
00:12:41,160 --> 00:12:45,360
you're just like, is this like 
something we can recover from? 

219
00:12:45,360 --> 00:12:53,480
It seems like a huge just domino
effect of kind of a shit show. 

220
00:12:54,640 --> 00:12:57,800
Well, I'd say I'm an optimist. 
I think you kind of have to be 

221
00:12:57,800 --> 00:12:59,440
to start a cybersecurity 
company. 

222
00:12:59,440 --> 00:13:02,720
You have to be a little bit 
optimistic because we've been 

223
00:13:02,720 --> 00:13:05,040
through this before. 
Are are you familiar with the 

224
00:13:05,080 --> 00:13:09,520
Morris Worm? 
Maybe a little bit, but might as

225
00:13:09,520 --> 00:13:13,160
well, you know? 
Yeah, very early self 

226
00:13:13,160 --> 00:13:16,360
propagating piece of malware. 
And this is like very early 

227
00:13:16,360 --> 00:13:18,840
Internet before my time, 
certainly. 

228
00:13:19,360 --> 00:13:22,880
But essentially info like 
cybersecurity used to be a lot 

229
00:13:22,880 --> 00:13:25,560
worse. 
It used to be where if you put a

230
00:13:25,560 --> 00:13:27,440
web server on the Internet, 
there was a pretty good 

231
00:13:27,440 --> 00:13:30,640
probability that somebody could 
find a flaw in it and hack it. 

232
00:13:30,880 --> 00:13:32,520
And that happened very 
frequently. 

233
00:13:32,960 --> 00:13:35,960
Microsoft got a lot of Flack for
this way back in like the early 

234
00:13:35,960 --> 00:13:37,880
2000s. 
So that's kind of the kind of 

235
00:13:37,880 --> 00:13:41,040
period I'm thinking, I think 
like 1990s, early 2000s 

236
00:13:41,040 --> 00:13:43,360
Internet. 
And then security did genuinely 

237
00:13:43,360 --> 00:13:46,440
get better over time. 
It did actually become a lot 

238
00:13:46,440 --> 00:13:49,520
harder to hack a web server or 
hack an iPhone. 

239
00:13:50,200 --> 00:13:54,880
It cost a lot of money to, for 
example, like an exploit against

240
00:13:54,880 --> 00:13:57,960
the modern iPhone. 
That is something that well, 

241
00:13:58,680 --> 00:14:01,440
maybe this is again the I debate
right now, but let's say prior 

242
00:14:01,440 --> 00:14:04,720
to LLMS, I'm getting very good. 
That was something that really 

243
00:14:04,720 --> 00:14:08,960
only organization with kind of a
nation state level budget could 

244
00:14:08,960 --> 00:14:11,640
do. 
You know, a teenage hacker crew.

245
00:14:11,640 --> 00:14:14,960
Those are very common. 
When you hear about them, you 

246
00:14:14,960 --> 00:14:16,640
know, Scattered Spider is a good
example. 

247
00:14:16,800 --> 00:14:20,120
When you hear Scattered Spider 
hacked a company, they probably 

248
00:14:20,120 --> 00:14:23,400
fished credentials that that's 
their TTPS are pretty public. 

249
00:14:23,600 --> 00:14:27,680
When you hear about a journalist
whose iPhone was hacked, that 

250
00:14:27,680 --> 00:14:30,680
wasn't teenagers in Discord, 
that was a government or 

251
00:14:30,680 --> 00:14:32,680
somebody with access to 
government level budgets. 

252
00:14:32,680 --> 00:14:36,000
That type of capability is not 
cheap, of course. 

253
00:14:36,000 --> 00:14:39,120
Now what people are very much 
concerned about is how AI is 

254
00:14:39,120 --> 00:14:43,000
changing that that calculation. 
But I would say I'm I'm actually

255
00:14:43,000 --> 00:14:45,280
not too pessimistic about 
things. 

256
00:14:45,720 --> 00:14:47,960
I think if you're a developer 
right now, it's a great time to 

257
00:14:47,960 --> 00:14:52,160
learn about security because 
it's inevitable that you will no

258
00:14:52,160 --> 00:14:56,400
matter what happens. 
But what do you think? 

259
00:14:57,360 --> 00:14:58,760
Where does your pessimism come 
from? 

260
00:14:59,440 --> 00:15:04,080
I I mean, I think it's like the 
fear of thinking cybersecurity 

261
00:15:04,080 --> 00:15:08,920
and security is like, you know, 
this thing that I'm not able to 

262
00:15:08,920 --> 00:15:11,160
grasp completely. 
Like I understand, you know what

263
00:15:11,160 --> 00:15:13,080
I mean? 
Yeah, the unknown. 

264
00:15:13,280 --> 00:15:17,280
But then like also just hearing 
you talk like not only do the 

265
00:15:17,280 --> 00:15:20,280
bad guys have these tools, so do
the good guys, like we all have 

266
00:15:20,280 --> 00:15:25,800
the same toolbox that we're 
we're using to, I don't know, I 

267
00:15:25,800 --> 00:15:29,840
guess fight threats as they 
appear, But like you always have

268
00:15:29,840 --> 00:15:33,680
to be kind of a step behind to 
know what you're defending 

269
00:15:33,680 --> 00:15:37,560
against, right? 
I I would say with AI, we 

270
00:15:37,560 --> 00:15:43,040
haven't yet seen entirely new 
types of threats, sort of. 

271
00:15:43,320 --> 00:15:46,240
For example, when AI discovers a
remote code execution 

272
00:15:46,240 --> 00:15:51,200
vulnerability or a Linux 
privilege escalation, it is 

273
00:15:51,200 --> 00:15:55,120
genuinely impressive that an AI 
computer program can do that 

274
00:15:55,120 --> 00:15:58,920
they they couldn't before. 
And the, the other big part that

275
00:15:58,920 --> 00:16:01,880
I think often gets lost in these
discussions is AI is not really 

276
00:16:01,880 --> 00:16:05,480
a bug finding machine like a 
scanner where it's like you put 

277
00:16:05,480 --> 00:16:08,760
the program in and the exploits 
or the exploit code comes out. 

278
00:16:09,640 --> 00:16:13,160
The, the big capability that is 
often under appreciated is kind 

279
00:16:13,160 --> 00:16:15,840
of the agentic, which I think 
people don't like. 

280
00:16:15,840 --> 00:16:20,200
It's kind of a buzzword now, but
essentially a, a malware 

281
00:16:20,200 --> 00:16:24,200
campaign or a ransomware 
campaign that is not, you know, 

282
00:16:24,200 --> 00:16:27,280
1 issue TP request. 
That is somebody who's an 

283
00:16:27,280 --> 00:16:31,240
operator, you know, launching 
malware, sending phishing emails

284
00:16:31,240 --> 00:16:33,720
to a company. 
The ransomware will land or it 

285
00:16:33,720 --> 00:16:35,960
won't. 
It'll the payload will work. 

286
00:16:36,080 --> 00:16:38,840
The files are then encrypted and
then the victim has to 

287
00:16:38,840 --> 00:16:42,040
communicate with an operator, 
you know, pay the Bitcoin or 

288
00:16:42,040 --> 00:16:45,480
whatever there. 
There are bottlenecks. 

289
00:16:45,480 --> 00:16:47,640
There are crews that do that, 
but AI has changed that 

290
00:16:47,640 --> 00:16:51,440
calculation significantly. 
So maybe that's the pessimistic 

291
00:16:51,440 --> 00:16:56,480
side, but I, I would say the 
optimistic side is that the 

292
00:16:56,480 --> 00:16:59,240
major labs, and I will actually 
give Anthropic some credit here,

293
00:16:59,240 --> 00:17:02,240
I think they have been very 
prudent in their safety research

294
00:17:02,240 --> 00:17:06,640
and in their caution. 
Anthropic particularly has been 

295
00:17:06,640 --> 00:17:11,839
getting some criticism that I 
think they don't deserve around 

296
00:17:11,839 --> 00:17:15,119
Mythos, where I'll give an 
example. 

297
00:17:16,160 --> 00:17:19,839
So the creator of Carl, Daniel, 
I highly respect him as a 

298
00:17:19,839 --> 00:17:21,760
software developer too. 
I think he's actually one of the

299
00:17:21,760 --> 00:17:26,079
best open source developers in 
the world and the Carl project 

300
00:17:26,079 --> 00:17:29,160
is one of the most secure open 
source projects. 

301
00:17:29,160 --> 00:17:32,960
And I think that's actually why 
it it is a bad example to use 

302
00:17:33,240 --> 00:17:36,160
because he recently published A 
blog post which was actually 

303
00:17:36,160 --> 00:17:38,040
very fair. 
I think he did a great job in 

304
00:17:38,040 --> 00:17:41,240
the blog post, but when you read
the press coverage of the blog 

305
00:17:41,240 --> 00:17:43,360
post, it gives people the wrong 
impression. 

306
00:17:44,040 --> 00:17:47,280
I'll actually read a headline 
from I think it was a registered

307
00:17:47,280 --> 00:17:50,680
brand. 
This headline Anthropic's bug 

308
00:17:50,680 --> 00:17:55,640
hunting Mythos was greatest 
marketing stunt ever, says Curl 

309
00:17:55,640 --> 00:17:59,800
creator. 
The AI scanner found one low 

310
00:17:59,800 --> 00:18:04,000
severity curl flow flaw. 
That's the framing that the 

311
00:18:04,000 --> 00:18:06,520
register gives you. 
And I think what it misses, and 

312
00:18:06,520 --> 00:18:10,920
this is the big point, is that 
curl is probably in the top 99th

313
00:18:11,440 --> 00:18:15,040
percentile. 
It is the top tier of an open 

314
00:18:15,040 --> 00:18:18,600
source project. 
The capabilities that the models

315
00:18:18,600 --> 00:18:22,320
have are dramatically shifting 
things. 

316
00:18:22,360 --> 00:18:25,920
For example, Firefox, which is a
much larger project. 

317
00:18:26,200 --> 00:18:30,240
The number of, you know, bugs 
reported in Firefox that were 

318
00:18:30,240 --> 00:18:37,760
valid went from an average of 
about 20 in 2025 to 400 to over 

319
00:18:37,760 --> 00:18:41,760
400 in April 2026. 
And we see this actually in 

320
00:18:41,760 --> 00:18:44,000
Elixir too, because I mentioned 
that earlier. 

321
00:18:44,000 --> 00:18:47,160
Now does that is that is that 
one month that Mozilla. 

322
00:18:47,160 --> 00:18:51,800
One month, Dang. 
And this is not unique, by the 

323
00:18:51,800 --> 00:18:54,640
way, I will give an example from
the Erling Ecosystem Foundation.

324
00:18:54,640 --> 00:18:56,120
So I'm in the security working 
group. 

325
00:18:56,120 --> 00:18:59,240
I know Jon Tan very well. 
He's handling this work. 

326
00:18:59,480 --> 00:19:01,760
If you go on the website, we'll,
we'll put it in the show notes. 

327
00:19:01,760 --> 00:19:08,800
But cna.erlef.org, it's like the
Erling Ecosystem Foundation, 

328
00:19:08,800 --> 00:19:11,600
the, the CNA, which is what 
issues the CV ES. 

329
00:19:11,920 --> 00:19:20,200
In 2025, they issued 9 CV ES 
total in 2026, The current 

330
00:19:20,200 --> 00:19:22,080
trend, I've talked to Jonathan 
about this. 

331
00:19:22,240 --> 00:19:24,760
It's well over 100, maybe over 
200. 

332
00:19:25,280 --> 00:19:26,720
And that's public data right 
now. 

333
00:19:26,720 --> 00:19:29,680
You can go on the website and 
see that and it, it ties back 

334
00:19:29,680 --> 00:19:32,160
into exactly what you were 
talking about with Peter where 

335
00:19:32,160 --> 00:19:35,200
he is but enormously productive 
in. 

336
00:19:35,400 --> 00:19:37,520
By the way, these were bugs that
already existed. 

337
00:19:37,760 --> 00:19:40,840
AI did not create these bugs. 
All of these vulnerabilities 

338
00:19:40,840 --> 00:19:44,800
existed in source code. 
The bottleneck was security 

339
00:19:44,800 --> 00:19:48,320
professional or programmer 
finding them, and AI has just 

340
00:19:48,640 --> 00:19:50,560
blown that bottleneck out of the
water. 

341
00:19:50,840 --> 00:19:53,120
And I you can't deny that right 
now. 

342
00:19:53,120 --> 00:19:57,240
That is a huge. 
Shift I feel like every single 

343
00:19:57,240 --> 00:20:01,240
day now there what there at 
least like for me this week 

344
00:20:01,240 --> 00:20:06,720
we've had a hex package security
vulnerability get flagged by 

345
00:20:06,720 --> 00:20:12,080
SOBLO like it's crazy. 
Everywhere. 

346
00:20:12,200 --> 00:20:16,680
Yeah, it's happening everywhere.
So I will do something that 

347
00:20:16,680 --> 00:20:20,120
maybe people will find 
controversial, but I will defend

348
00:20:21,200 --> 00:20:26,080
Open AI here because back in 
2019 there was this article. 

349
00:20:26,080 --> 00:20:28,720
I, this might have actually been
the anthropic people within Open

350
00:20:28,760 --> 00:20:31,200
AI. 
It's, it's hard to say, but I, I

351
00:20:31,200 --> 00:20:37,040
believe it was Open AIA press 
release saying that GPT 2, which

352
00:20:37,040 --> 00:20:40,200
was 2019, they said it was too 
dangerous to release. 

353
00:20:40,200 --> 00:20:44,000
And then Chachi BT was released 
in 2022 and everyone kind of 

354
00:20:44,000 --> 00:20:47,400
mocks that he's like, oh, they 
thought like GVT 2 was too 

355
00:20:47,400 --> 00:20:49,440
dangerous. 
Like that's stupid because like 

356
00:20:49,480 --> 00:20:52,920
the models we have now are so 
much stronger and everyone's 

357
00:20:52,920 --> 00:20:55,640
happy with them. 
Everyone loves AI and there's no

358
00:20:55,640 --> 00:21:01,720
negative extra talities at all. 
That's what I find so odd about 

359
00:21:01,720 --> 00:21:05,440
the debate because I would argue
AI is probably the most 

360
00:21:05,440 --> 00:21:07,480
important technology debate 
right now. 

361
00:21:07,480 --> 00:21:10,440
Everyone has an opinion. 
I get texts on my phone from 

362
00:21:10,440 --> 00:21:13,000
local politicians about if we're
going to build data centers or 

363
00:21:13,000 --> 00:21:18,800
not, and that is directly tied 
to Chachi PT being released. 

364
00:21:20,480 --> 00:21:22,760
You know, talk to educators, 
talk to people in school about 

365
00:21:22,760 --> 00:21:26,360
people using LLLMS to cheat. 
It's a bended education. 

366
00:21:27,440 --> 00:21:30,000
I mean, just look online. 
Even within Elixir, people hate 

367
00:21:30,000 --> 00:21:31,560
AI there. 
There's a very strong negative 

368
00:21:31,560 --> 00:21:33,040
sentiment. 
In a lot of ways, a lot of 

369
00:21:33,040 --> 00:21:36,320
people are unhappy. 
You're either on board or the 

370
00:21:36,360 --> 00:21:38,080
opposite. 
I feel like it's this very 

371
00:21:38,080 --> 00:21:41,000
polarized. 
And I and I, I don't want to, 

372
00:21:41,000 --> 00:21:44,120
you know, say all, all of the 
negative AI is wrong. 

373
00:21:44,120 --> 00:21:46,840
I think actually the labs have 
been very forthright about the 

374
00:21:46,840 --> 00:21:49,960
potential harms. 
But what I find bizarre is 

375
00:21:49,960 --> 00:21:53,160
people will imply that it was 
not important because, you know,

376
00:21:53,160 --> 00:21:55,160
you can be on either side of the
polarizing debate. 

377
00:21:55,280 --> 00:21:58,200
But to say, oh, you know, it 
wasn't too dangerous. 

378
00:21:58,200 --> 00:22:01,480
I'm like, well, no, it, it 
turned out to be this enormously

379
00:22:01,480 --> 00:22:04,560
important and transformation 
like technology. 

380
00:22:04,840 --> 00:22:08,720
How can you deny that there was 
a risk there? 

381
00:22:08,720 --> 00:22:10,880
It it did cause a lot of 
problems. 

382
00:22:11,200 --> 00:22:15,120
Well, the data center drama, 
though, is like, I'm in Utah, so

383
00:22:15,120 --> 00:22:19,840
the Kevin O'Leary data center in
Utah has been very controversial

384
00:22:19,840 --> 00:22:21,800
here. 
Exactly. 

385
00:22:22,040 --> 00:22:26,000
And but but to say that it's not
important or that oh, like, you 

386
00:22:26,000 --> 00:22:29,160
know, the GPT 2 was fine, there 
was no safety risk at all. 

387
00:22:29,160 --> 00:22:32,640
And like therefore Mythos, the 
new model that's very good at 

388
00:22:32,640 --> 00:22:36,200
cybersecurity, I, I think 
Anthropic is doing the right 

389
00:22:36,200 --> 00:22:37,960
thing with not really seeing it 
publicly. 

390
00:22:37,960 --> 00:22:39,400
I think that's a very prudent 
decision. 

391
00:22:39,800 --> 00:22:42,680
All of those vulnerabilities 
that Peter found just in our, in

392
00:22:42,680 --> 00:22:45,640
our corner, in our, in our 
Elixir ecosystem, he put in his 

393
00:22:45,640 --> 00:22:50,760
blog post, he didn't use Mythos 
and you know, explosion of 

394
00:22:50,760 --> 00:22:55,000
completely valid security bugs. 
I think a lot of the bugs that 

395
00:22:55,000 --> 00:22:56,840
have been reported that people 
are talking about were not even 

396
00:22:56,840 --> 00:22:59,360
found by Mythos. 
Yeah, every time I have to 

397
00:22:59,480 --> 00:23:03,240
update and patch a dependency in
one of my projects, I just kind 

398
00:23:03,240 --> 00:23:07,360
of curse Peter for finding that.
But that's The thing is the 

399
00:23:07,400 --> 00:23:09,400
vulnerability already existed 
in. 

400
00:23:09,760 --> 00:23:11,360
Your. 
And the bad guy might have 

401
00:23:11,360 --> 00:23:13,400
already been using it in a bad 
way. 

402
00:23:15,440 --> 00:23:19,240
But the, the point I'll argue 
that I feel very strongly about 

403
00:23:19,240 --> 00:23:23,040
is that security concerns and 
safety concerns around AI 

404
00:23:23,120 --> 00:23:26,160
related to cybersecurity. 
How can you argue that they're 

405
00:23:26,160 --> 00:23:28,000
not there? 
Like they're clearly there. 

406
00:23:28,000 --> 00:23:30,520
We're, we're having this debate.
It's, it's having this massive 

407
00:23:30,520 --> 00:23:34,600
impact on industry defensive, 
defensive cybersecurity people. 

408
00:23:34,720 --> 00:23:36,920
You know, bug bounty programs 
are shutting down. 

409
00:23:36,920 --> 00:23:39,720
People are saying we just don't 
have the resources to handle 

410
00:23:39,720 --> 00:23:43,240
this volume. 
So speaking from experience, I 

411
00:23:43,240 --> 00:23:46,840
just, I launched Killswitch what
at the beginning of the year and

412
00:23:46,840 --> 00:23:50,520
I had AI, had a bounty program 
because I was like, look, I'm a 

413
00:23:50,520 --> 00:23:53,160
zero knowledge encrypted 
storage. 

414
00:23:53,520 --> 00:23:55,720
Essentially. 
I was like, people need to trust

415
00:23:55,720 --> 00:23:57,240
me. 
So I had a bounty program. 

416
00:23:57,640 --> 00:24:04,360
I was getting so much like just 
clearly AI generated reports. 

417
00:24:04,560 --> 00:24:08,200
I couldn't keep up. 
So I shut it down and like had 

418
00:24:08,200 --> 00:24:13,440
to make like very specific like 
privacy statements in terms of 

419
00:24:13,440 --> 00:24:15,680
service. 
Like if you're a paying 

420
00:24:15,680 --> 00:24:19,840
customer, there are bounties 
available. 

421
00:24:20,040 --> 00:24:23,920
But like if you're just like 
some random pen tester, I can't 

422
00:24:23,920 --> 00:24:25,680
accept it. 
Like I will read that. 

423
00:24:25,680 --> 00:24:28,760
I will fix the problem if it 
exists, but I can't just like 

424
00:24:28,760 --> 00:24:32,120
pay it out 'cause I was just 
like I couldn't keep up. 

425
00:24:32,120 --> 00:24:34,280
It was just like my inbox was 
stuffed. 

426
00:24:34,920 --> 00:24:36,840
Exactly. 
And the Internet bug bounty 

427
00:24:36,840 --> 00:24:40,120
program actually shut down, I 
think no JS shut down their 

428
00:24:40,120 --> 00:24:41,960
program. 
You know, how can you argue that

429
00:24:41,960 --> 00:24:44,560
there's no impact? 
Like the impact is just, it's 

430
00:24:44,560 --> 00:24:48,280
clearly there. 
And a lot of times though, like 

431
00:24:48,280 --> 00:24:52,200
it's a like the, the problem was
it wasn't necessarily finding 

432
00:24:52,440 --> 00:24:54,760
like critical or 
vulnerabilities. 

433
00:24:55,120 --> 00:24:57,680
A lot of it was like BS, like 
they're fake. 

434
00:24:57,680 --> 00:25:01,280
But it still takes a lot of time
to sort through it, to verify 

435
00:25:01,280 --> 00:25:04,320
that they are. 
And that took a lot of my time. 

436
00:25:05,400 --> 00:25:09,920
So I did talk at Elixir Conf EU 
back in 2024. 

437
00:25:10,920 --> 00:25:11,840
You know, I was watching it 
recently. 

438
00:25:11,840 --> 00:25:14,280
It almost seems kind of quaint, 
like, you know, like the calm 

439
00:25:14,280 --> 00:25:17,760
before the storm where I, I, I 
said bug bounty programs are not

440
00:25:17,760 --> 00:25:21,640
that helpful. 
And this was pretty LLM because 

441
00:25:21,640 --> 00:25:23,240
I, I did bug bounty work 
professionally. 

442
00:25:23,240 --> 00:25:25,680
I, I would get the reports come 
in, I'd be like, a lot of these 

443
00:25:25,680 --> 00:25:28,480
are spam. 
I don't like them very much, but

444
00:25:28,480 --> 00:25:31,480
it's interesting that AI has 
kind of been an amplifier in 

445
00:25:31,480 --> 00:25:34,760
that regard. 
Well, it's like, here's the 

446
00:25:34,760 --> 00:25:37,880
thing, like you have like low 
level pen testers trying to make

447
00:25:37,880 --> 00:25:41,800
an extra buck and of course 
you're gonna just spam out 

448
00:25:41,800 --> 00:25:44,280
reports and hope for a few bucks
here and there. 

449
00:25:44,280 --> 00:25:46,640
Like I get it. 
I would do the same thing if 

450
00:25:46,640 --> 00:25:51,120
that was my line of work. 
Yeah, I should mention bug 

451
00:25:51,120 --> 00:25:53,280
bounty hunters, which is what 
we're talking about. 

452
00:25:53,720 --> 00:25:56,960
It's a very distinct operation 
compared to a a penetration 

453
00:25:56,960 --> 00:25:58,920
test. 
Fair, fair. 

454
00:25:59,240 --> 00:26:02,920
So the bug bounty hunter, their 
whole incentive is, you know, 

455
00:26:02,920 --> 00:26:07,920
get paid maximum money. 
I do penetration tests for a lot

456
00:26:07,920 --> 00:26:10,080
of elixir companies. 
I've gotten, I'm very grateful. 

457
00:26:10,080 --> 00:26:13,240
I've gotten very good feedback 
from the customers about them. 

458
00:26:13,480 --> 00:26:17,440
And the the key difference is 
that when you write a pen test 

459
00:26:17,440 --> 00:26:21,000
report and you're doing the 
work, you have to frame it in a 

460
00:26:21,000 --> 00:26:24,400
way that is useful for the 
business saying, you know, 

461
00:26:24,400 --> 00:26:26,480
here's what your business 
operations are. 

462
00:26:26,680 --> 00:26:28,920
Here are the risks that 
realistically affect you. 

463
00:26:29,120 --> 00:26:31,120
Here is the current state of 
your application. 

464
00:26:31,400 --> 00:26:35,600
Like maybe there is a remote 
code execution or a very severe 

465
00:26:35,600 --> 00:26:39,400
bug, but if the complexity is so
high and the probability is so 

466
00:26:39,400 --> 00:26:42,240
close to 0, you know the 
customer should know that to be 

467
00:26:42,240 --> 00:26:43,880
able to make an intelligent 
decision. 

468
00:26:45,120 --> 00:26:48,280
Compared with actually some of 
the worst bugs I've ever found 

469
00:26:48,280 --> 00:26:51,680
on pen tests have been so simple
that I you could anyone could 

470
00:26:51,680 --> 00:26:54,880
appreciate them just for 
example, an, an API endpoint 

471
00:26:54,880 --> 00:26:58,080
with no authentication. 
It's not complicated. 

472
00:26:58,280 --> 00:27:01,760
You don't need to be a pone to 
own, which is a cybersecurity 

473
00:27:01,760 --> 00:27:03,840
competition. 
A like a master hacker. 

474
00:27:04,800 --> 00:27:06,920
Anyone on the call, anyone on 
this call could have found that 

475
00:27:06,920 --> 00:27:09,600
bug if they just knew to look 
for it, But that that was the 

476
00:27:09,600 --> 00:27:13,680
most severe because an attacker 
or now an AI agent frankly could

477
00:27:13,680 --> 00:27:17,600
find that and cause a security 
incident. 

478
00:27:19,680 --> 00:27:21,760
That would be, you know, front 
page of Hacker news. 

479
00:27:21,760 --> 00:27:24,120
Do you remember that T app that 
happened a while back? 

480
00:27:24,320 --> 00:27:27,800
It was like a it was a insecure,
it wasn't an S3 bucket, it was 

481
00:27:27,800 --> 00:27:29,880
like a Firebase bucket. 
But that's one of the first 

482
00:27:29,880 --> 00:27:32,840
things I always check for on 
Pentas because the complexity is

483
00:27:32,840 --> 00:27:37,280
so low. 
Just open S3 bucket and probably

484
00:27:37,280 --> 00:27:38,920
hundreds. 
I like it. 

485
00:27:38,960 --> 00:27:41,280
It depends on the reporting, but
probably hundreds of companies 

486
00:27:41,280 --> 00:27:44,160
have been breached just by a 
storage bucket that didn't have 

487
00:27:44,160 --> 00:27:45,320
proper that's. 
Wild. 

488
00:27:45,640 --> 00:27:53,200
I was going to say like like a 
major problem with my day job 

489
00:27:54,040 --> 00:27:56,920
are we have an open endpoint 
obviously for like login, like 

490
00:27:56,920 --> 00:27:58,760
authentication. 
You have to, yeah. 

491
00:27:59,120 --> 00:28:03,120
Right, and that's one of the the
biggest things that like we have

492
00:28:03,120 --> 00:28:06,960
to work on like we have to do 
like client side puzzles and 

493
00:28:06,960 --> 00:28:11,400
work just to slow down how many 
times like yeah, bots and things

494
00:28:11,400 --> 00:28:14,960
and it's always the open 
endpoints that and obviously 

495
00:28:14,960 --> 00:28:16,960
they'll like login has to be 
open. 

496
00:28:17,440 --> 00:28:20,720
But yeah, that's interesting. 
S3 buckets though not being 

497
00:28:20,720 --> 00:28:22,840
secured is wild. 
Very common. 

498
00:28:22,920 --> 00:28:25,640
Extremely common. 
And then like I bet like rate 

499
00:28:25,640 --> 00:28:30,640
limiting is important, which by 
the way paraxial just to plug 

500
00:28:30,640 --> 00:28:33,040
you a little super easy to add 
rate. 

501
00:28:33,120 --> 00:28:35,640
I haven't deployed myself really
on this show, maybe I should. 

502
00:28:36,600 --> 00:28:44,040
Well, I plug you for you, you 
know, but yeah, it's, it's funny

503
00:28:44,040 --> 00:28:47,160
and but it's, you also have to 
take it with like a grain of 

504
00:28:47,160 --> 00:28:51,080
salt because another problem is 
I, I shouldn't call them pen 

505
00:28:51,080 --> 00:28:52,880
testers. 
I'm going to call them bounty 

506
00:28:52,880 --> 00:28:55,840
hunters 'cause I think. 
It's and there are very good bug

507
00:28:55,840 --> 00:28:57,840
bounty hunters. 
I'm sure there are there. 

508
00:28:58,120 --> 00:28:59,360
Are people that are very good at
this. 

509
00:28:59,520 --> 00:29:03,760
The majority of them, like a lot
of them, a lot of reports that I

510
00:29:03,760 --> 00:29:06,600
get is like, well, you're 
hacking your own account. 

511
00:29:07,120 --> 00:29:10,440
Like why would you do 
detrimental things to your own 

512
00:29:10,440 --> 00:29:10,960
account? 
You. 

513
00:29:11,600 --> 00:29:12,480
Know what's actually 
interesting? 

514
00:29:12,480 --> 00:29:15,440
I've noticed this because I I 
use Claude code on pen test and 

515
00:29:15,440 --> 00:29:18,360
found this. 
Really interesting bug in Hex. 

516
00:29:18,360 --> 00:29:20,760
Actually I was I was using it 
during the hex pentas where it 

517
00:29:20,760 --> 00:29:25,120
was this logic flaw. 
But what I had a recent client I

518
00:29:25,120 --> 00:29:30,240
had the app was actually very 
secure and there weren't that 

519
00:29:30,240 --> 00:29:32,880
many vulnerabilities. 
So I noticed Claude would kind 

520
00:29:32,880 --> 00:29:35,640
of do exactly what you're 
describing where it would invent

521
00:29:36,560 --> 00:29:39,160
a vulnerability. 
And I'd be like, oh, that sounds

522
00:29:39,160 --> 00:29:41,160
very bad. 
It it sounded very bad in the 

523
00:29:41,240 --> 00:29:43,040
output. 
And I'd verify be like, hi, 

524
00:29:43,040 --> 00:29:47,600
Claude, the bad guy when he when
he hacks it, you said he already

525
00:29:47,600 --> 00:29:50,480
has database access and it's. 
Oh, you're absolutely right. 

526
00:29:51,960 --> 00:29:53,160
OK. 
So it's actually not a 

527
00:29:53,160 --> 00:29:56,600
vulnerability? 
Yeah, it's just like, OK, you're

528
00:29:56,600 --> 00:30:00,920
getting your users data or 
you're manipulating your data 

529
00:30:00,920 --> 00:30:02,560
which you already have access 
to. 

530
00:30:03,480 --> 00:30:05,640
Well, and, and this is actually 
a great point to talk about 

531
00:30:05,640 --> 00:30:09,800
because people often ask me, are
you worried about paraxial with 

532
00:30:09,800 --> 00:30:12,560
the, with the rise of AI and 
everything is, is that going to 

533
00:30:12,560 --> 00:30:14,520
put your company in a, in a bad 
spot? 

534
00:30:14,840 --> 00:30:18,920
And then the point that I like 
to tell people about is that 

535
00:30:18,920 --> 00:30:22,400
when you do a full analysis of 
your code base with an AI system

536
00:30:22,400 --> 00:30:24,480
that costs a lot of tokens 
essentially. 

537
00:30:24,800 --> 00:30:28,040
So, you know, smaller code base 
where people use for demos, it's

538
00:30:28,040 --> 00:30:31,320
a small amount of tokens, an 
actual production database doing

539
00:30:31,320 --> 00:30:35,240
a full AI analysis of that in 
some cases actually cost more 

540
00:30:35,240 --> 00:30:37,960
per hour. 
Well, once you kind of parcel, 

541
00:30:38,040 --> 00:30:40,680
it actually cost more than 
hiring a security engineer. 

542
00:30:41,440 --> 00:30:44,200
There's a there's a very open 
secret in Silicon Valley right 

543
00:30:44,200 --> 00:30:46,560
now, which every major tech 
company they are. 

544
00:30:46,640 --> 00:30:50,680
Playing off devs and replacing 
them with AI are spending more 

545
00:30:50,920 --> 00:30:53,240
until. 
But but even this is the open 

546
00:30:53,240 --> 00:30:57,080
secret is that how do they do 
the stack ranking and the 

547
00:30:57,080 --> 00:30:59,520
productivity measurements? 
How many tokens you use? 

548
00:31:00,080 --> 00:31:02,880
So people just have these things
running all day. 

549
00:31:02,880 --> 00:31:05,520
So yeah, an engineer at Fang 
makes a lot of money. 

550
00:31:05,520 --> 00:31:10,320
They're not cheap to employ out 
in out in San Francisco, but 

551
00:31:10,320 --> 00:31:13,440
they'll often be using double or
triple their salary in tokens. 

552
00:31:13,440 --> 00:31:16,400
And then of course, you know, 
Jensen will go on and and say, 

553
00:31:16,440 --> 00:31:17,600
of course they should be doing 
that. 

554
00:31:17,600 --> 00:31:21,280
I am the CEO of NVIDIA. 
And I actually don't think he's 

555
00:31:21,280 --> 00:31:24,720
wrong necessarily. 
But the phenomenon at the moment

556
00:31:24,720 --> 00:31:28,480
is very funny because, you know,
it's sort of like the big tech 

557
00:31:28,480 --> 00:31:31,800
companies went from over hiring 
to have the illusion of 

558
00:31:31,800 --> 00:31:35,000
productivity to too much uses of
AI for the illusion of 

559
00:31:35,000 --> 00:31:36,560
productivity. 
Because it turns out 

560
00:31:36,560 --> 00:31:38,920
productivity is actually very 
hard to measure, and there's not

561
00:31:38,920 --> 00:31:41,680
an easy metric. 
In in any. 

562
00:31:41,680 --> 00:31:43,880
Business. 
Like where you're not like a 

563
00:31:43,880 --> 00:31:48,200
line worker, It's really hard to
do that at all 'cause like 

564
00:31:48,200 --> 00:31:52,560
programming and engineering is 
like very artistic, you know, 

565
00:31:52,560 --> 00:31:54,880
form, right? 
Like you're not gonna just be 

566
00:31:55,040 --> 00:31:58,120
writing code 24/7. 
You have to architect. 

567
00:31:58,120 --> 00:32:02,280
You have to solve the solution 
and figure out how you're going 

568
00:32:02,280 --> 00:32:05,760
to solve the problem right. 
You know, if you're if you're 

569
00:32:05,760 --> 00:32:09,520
building an aircraft that the 
usual metric is not wait for how

570
00:32:09,520 --> 00:32:13,880
close is it to being finished. 
It usually has to fly at some 

571
00:32:13,880 --> 00:32:17,200
point, but I that is often lost 
on some people in these debates.

572
00:32:18,160 --> 00:32:22,840
Yeah, project managers mostly. 
I'm sure there's some very good 

573
00:32:22,840 --> 00:32:24,760
product. 
No offense, project managers, 

574
00:32:24,760 --> 00:32:27,960
I'm just joking. 
All right. 

575
00:32:27,960 --> 00:32:30,920
I'm going to just take a quick 
break here and we'll run some 

576
00:32:30,920 --> 00:32:32,840
ads and then we'll be right 
back. 

577
00:32:34,600 --> 00:32:38,080
Hey, I'm Kimberly with Elixir 
mentor Jacob recently added 

578
00:32:38,080 --> 00:32:41,440
recruitment services to help 
companies hire pre vetted Elixir

579
00:32:41,440 --> 00:32:44,400
devs. 
I help with company outreach, so

580
00:32:44,400 --> 00:32:47,680
if you're hiring, I may be 
reaching out, or you can connect

581
00:32:47,680 --> 00:32:49,840
with us anytime at 
elixirmentor.com. 

582
00:32:51,280 --> 00:32:54,360
Coding Elixir with AI or 
building AI into your Elixir 

583
00:32:54,360 --> 00:32:57,120
apps? 
The Elixir AI Collective Discord

584
00:32:57,120 --> 00:33:00,000
is your community for both. 
Link in the description below. 

585
00:33:01,280 --> 00:33:04,280
All right, and we're back. 
Yeah, sorry for the be right 

586
00:33:04,280 --> 00:33:08,920
back screen, now I forgot where 
we were. 

587
00:33:10,400 --> 00:33:12,480
No, I think we're in, I think 
we're in a great path. 

588
00:33:13,040 --> 00:33:16,960
Something I want to mention that
I think you also mentioned is 

589
00:33:16,960 --> 00:33:21,040
that defenders now need access 
to AI to do their job correctly.

590
00:33:21,040 --> 00:33:25,000
And I think that's an under 
appreciated point because I know

591
00:33:25,000 --> 00:33:29,160
there is a debate about AI 
growth and AI adoption. 

592
00:33:29,160 --> 00:33:32,480
But I want to submit my opinion 
from the corner of a 

593
00:33:32,480 --> 00:33:36,680
cybersecurity practitioner, 
which is that if you work in 

594
00:33:36,680 --> 00:33:39,280
cybersecurity, especially 
defending systems or you're a 

595
00:33:39,280 --> 00:33:43,800
software developer that also 
handles security, having access 

596
00:33:43,800 --> 00:33:46,040
the state-of-the-art models is 
non negotiable. 

597
00:33:46,040 --> 00:33:51,480
Now you can't have worse models 
than say an adversarial country.

598
00:33:52,320 --> 00:33:55,400
It's, it's just not tenable at 
all to do effective 

599
00:33:55,400 --> 00:33:59,120
cybersecurity work right now. 
I would argue that, you know, in

600
00:33:59,120 --> 00:34:01,800
the United States we have 
anthropic and open AI that is 

601
00:34:01,800 --> 00:34:06,640
extraordinarily useful a, a 
situation where, you know, I'm 

602
00:34:06,640 --> 00:34:08,280
in the United States, you're in 
the United States too. 

603
00:34:08,280 --> 00:34:11,679
But I think we also have 
listeners in Europe and things a

604
00:34:11,679 --> 00:34:15,560
situation where let let's just 
use America as an example, where

605
00:34:15,560 --> 00:34:18,880
America falls behind 
significantly in the AI race 

606
00:34:18,880 --> 00:34:21,040
because the other world powers 
are very interested in this 

607
00:34:21,040 --> 00:34:22,639
topic. 
It's we're getting a bit away 

608
00:34:22,639 --> 00:34:24,880
from elixir into politics here. 
I know. 

609
00:34:25,120 --> 00:34:29,920
But I promise it's, I promise 
it's related because, you know, 

610
00:34:29,960 --> 00:34:33,040
I'm someone that helps people 
secure their elixir applications

611
00:34:33,040 --> 00:34:35,000
for a living. 
And I'll, I'll say this on air, 

612
00:34:35,159 --> 00:34:38,280
without state-of-the-art AI 
models, it's not really going to

613
00:34:38,280 --> 00:34:41,080
be possible for me to do my job.
And it, it will be a 

614
00:34:41,080 --> 00:34:44,360
disadvantage advantage because 
you know, if the 

615
00:34:44,360 --> 00:34:46,440
state-of-the-art models are 
controlled by, let's say, 

616
00:34:46,440 --> 00:34:50,800
another country that your 
country sees as an adversary and

617
00:34:50,800 --> 00:34:53,040
you're relying on those for 
defense, it just doesn't make 

618
00:34:53,040 --> 00:34:55,320
any sense. 
In the United States, for 

619
00:34:55,320 --> 00:34:59,680
example, Kopersky products, 
which is the Russian antivirus 

620
00:34:59,680 --> 00:35:02,640
firm, They're not only banned by
the government, but I think like

621
00:35:02,640 --> 00:35:04,960
state governments and 
municipalities. 

622
00:35:05,880 --> 00:35:08,680
And it, it goes both ways. 
You can't really use American 

623
00:35:08,720 --> 00:35:12,240
antivirus products in, in 
Russian government systems. 

624
00:35:12,240 --> 00:35:14,760
They might I, I don't know how 
accurate this point is, but I 

625
00:35:14,760 --> 00:35:16,640
think they're switching to Linux
or open source tooling. 

626
00:35:16,640 --> 00:35:18,680
Actually, a lot of countries 
want to get off Windows. 

627
00:35:19,400 --> 00:35:23,840
So this is, this is well tridden
kind of geopolitical ground 

628
00:35:23,840 --> 00:35:25,880
already. 
But the point being, you know, 

629
00:35:25,880 --> 00:35:28,080
antivirus people can kind of get
their head around, you know, 

630
00:35:28,080 --> 00:35:30,240
there's a virus on your 
computer, you have an antivirus 

631
00:35:30,240 --> 00:35:35,440
program running to block it. 
You probably want to want to run

632
00:35:35,440 --> 00:35:38,200
one that's at least your own 
country or an ally of your 

633
00:35:38,200 --> 00:35:41,040
country, not an adversary. 
Everyone kind of understands 

634
00:35:41,040 --> 00:35:43,680
that intuitively. 
For an AI system that is going 

635
00:35:43,680 --> 00:35:47,720
to be defending or responsible 
for code security, it's kind of 

636
00:35:47,720 --> 00:35:51,560
the same principle. 
There is a well known meme right

637
00:35:51,560 --> 00:35:56,560
now on Infosec Twitter that if 
you are worried about your 

638
00:35:56,560 --> 00:36:00,360
computer being hacked or having 
malware on it, put the Russian 

639
00:36:00,360 --> 00:36:03,680
language pack on. 
Have that in your system because

640
00:36:03,680 --> 00:36:06,440
there's a very common check in 
malware where we'll say, oh, 

641
00:36:06,560 --> 00:36:13,360
Russian language pack don't run.
There we go. 

642
00:36:13,560 --> 00:36:15,320
Now we know how to secure 
everything. 

643
00:36:16,880 --> 00:36:20,480
Not, not quite for, but there's 
actually kind of a rich history 

644
00:36:20,480 --> 00:36:22,760
about this where like 
cybersecurity and geopolitics 

645
00:36:22,760 --> 00:36:26,000
kind of kind of come together. 
I would say the good news, yeah,

646
00:36:26,120 --> 00:36:32,200
for for Elixir developers, 
though, the good news is that 

647
00:36:32,880 --> 00:36:35,720
the ecosystem itself is handling
the situation very well. 

648
00:36:35,720 --> 00:36:37,840
We've got Jonathan, we've got 
the EEF. 

649
00:36:38,480 --> 00:36:40,880
I'm grateful to Alistair for all
of the fundraising work he's 

650
00:36:40,880 --> 00:36:43,080
doing. 
And I should give credit to the 

651
00:36:43,080 --> 00:36:46,800
Open AI Labs themselves. 
Anthropic and Open AI are both 

652
00:36:46,800 --> 00:36:51,400
funders of Alpha Omega, the 
initiative that put the money up

653
00:36:51,560 --> 00:36:56,960
so that we could secure Hex. 
When Mythos and Glass Wing was 

654
00:36:56,960 --> 00:37:01,360
announced that mentioned Alpha 
Omega that like famous post that

655
00:37:01,360 --> 00:37:04,240
like, you know, every mainstream
media in the United States was 

656
00:37:04,240 --> 00:37:07,600
picking that up. 
They mentioned Alpha Omega Open 

657
00:37:07,600 --> 00:37:10,920
AI has been very proactive in 
granting their models access 

658
00:37:10,920 --> 00:37:13,120
for, you know, defensive 
capability. 

659
00:37:13,960 --> 00:37:18,280
So I know there's a lot of 
controversy right now in AI 

660
00:37:18,280 --> 00:37:22,400
generally, but I want to state, 
but the labs have been very good

661
00:37:22,400 --> 00:37:25,000
on security and I think that 
they often do the right thing 

662
00:37:25,560 --> 00:37:28,160
and it kind of gets lost in the 
noise of the headlines. 

663
00:37:28,160 --> 00:37:30,200
And you know what? 
What gets clicks is kind of the 

664
00:37:30,200 --> 00:37:33,360
controversy. 
The the good work often kind of 

665
00:37:33,360 --> 00:37:35,640
flies under the radar, but it's 
extremely important. 

666
00:37:36,600 --> 00:37:40,880
Yeah. 
I mean, I always, I always what 

667
00:37:40,880 --> 00:37:44,880
I think about the most with like
using clod code everyday and all

668
00:37:44,880 --> 00:37:47,320
these other things. 
And I mean, I've kind of just 

669
00:37:47,320 --> 00:37:50,600
ignored it, but I've always had 
this like paranoia of just like 

670
00:37:50,720 --> 00:37:55,160
dishing all my information and 
data to some third party. 

671
00:37:56,240 --> 00:38:02,000
And I mean, obviously these 
large LM models have all of our 

672
00:38:02,000 --> 00:38:05,840
data now and all of our coding 
projects, like everything, 

673
00:38:05,840 --> 00:38:08,360
right? 
I don't know if there's any 

674
00:38:08,360 --> 00:38:11,200
avoiding that. 
But like, I'm not like really, 

675
00:38:11,520 --> 00:38:15,760
it's not concern of like the 
what code I have in my 

676
00:38:15,760 --> 00:38:18,840
repository. 
It's, it's more just like, you 

677
00:38:18,840 --> 00:38:22,400
know, API keys, sensitive 
information, whatever 

678
00:38:22,400 --> 00:38:25,760
accidentally leaks because, you 
know, like if you have a dot env

679
00:38:25,840 --> 00:38:30,200
file in your project, sure, 
Anthropic will pretend they 

680
00:38:30,200 --> 00:38:33,480
ignore it, but they're scanning 
those files and they're seeing 

681
00:38:33,480 --> 00:38:37,240
your like, I don't keep 
production keys on my desktop, 

682
00:38:37,240 --> 00:38:39,760
you know? 
I, I would say the, the good 

683
00:38:39,760 --> 00:38:43,160
news on that one is anthropic is
another. 

684
00:38:43,160 --> 00:38:47,800
I don't want to sound like I'm, 
you know, not not being totally 

685
00:38:47,800 --> 00:38:51,480
critical, but there was a recent
blog post I saw where it was a 

686
00:38:51,480 --> 00:38:54,440
CTF that was run by a 
university. 

687
00:38:54,440 --> 00:38:59,720
I think it might have been RIT 
clawed like an like an AI agent 

688
00:38:59,720 --> 00:39:02,160
entered it to like test the 
cyber capabilities. 

689
00:39:02,160 --> 00:39:05,080
And the organizer said, you 
know, hey, we, we don't like 

690
00:39:05,080 --> 00:39:06,280
this. 
This shouldn't have happened. 

691
00:39:06,280 --> 00:39:09,840
And an employee from Anthropic 
responded on Twitter, I believe,

692
00:39:10,080 --> 00:39:11,680
saying, you know, we apologize 
for this. 

693
00:39:11,680 --> 00:39:14,240
We've actually updated our 
policies and we're deleting all 

694
00:39:14,240 --> 00:39:16,880
this data. 
And I believe them 100% because 

695
00:39:17,080 --> 00:39:20,560
the entire, you know, brand of 
Anthropic is the safety and 

696
00:39:20,800 --> 00:39:22,880
privacy and the lack of ads 
right now. 

697
00:39:23,760 --> 00:39:26,960
But to, to your point about the 
private keys, there's no real 

698
00:39:26,960 --> 00:39:29,680
benefit for them having your 
private keys. 

699
00:39:29,680 --> 00:39:32,160
They don't want them. 
You know, if you upload like an 

700
00:39:32,640 --> 00:39:37,400
AWS key or like your passwords 
to a, to an open to like a large

701
00:39:37,400 --> 00:39:41,680
language model provider, that is
something they don't want. 

702
00:39:41,960 --> 00:39:44,440
You know, regulators in the 
United States, well, European 

703
00:39:44,440 --> 00:39:46,640
regulators especially really 
don't like that. 

704
00:39:46,920 --> 00:39:49,520
And of course, those businesses 
want to operate in Europe. 

705
00:39:51,480 --> 00:39:54,120
And the, the other trend that 
you've probably noticed is a lot

706
00:39:54,120 --> 00:39:56,920
of these models can be run in 
kind of a private cloud 

707
00:39:56,920 --> 00:39:59,120
situation. 
Like I believe Amazon bedrock is

708
00:39:59,120 --> 00:40:03,080
very big right now. 
And, you know, as models get 

709
00:40:03,080 --> 00:40:06,440
better and, you know, I have 
tasks like, I, I use OMS 

710
00:40:06,440 --> 00:40:09,240
constantly. 
I, I, I'm in cloud every day 

711
00:40:09,680 --> 00:40:12,360
constantly. 
But there are, there are tasks 

712
00:40:12,360 --> 00:40:15,640
where I'll have a task, I'll be 
like I I don't need to use, you 

713
00:40:15,640 --> 00:40:18,400
know, Opus. 
Or like a top tier model for 

714
00:40:18,400 --> 00:40:19,520
this. 
I know I could probably use 

715
00:40:19,520 --> 00:40:22,600
something locally. 
And, and as that gets better, I 

716
00:40:22,600 --> 00:40:26,480
think there's tremendous privacy
prudential there where a lot of 

717
00:40:26,480 --> 00:40:29,760
people do have, you know, they 
want privacy, They maybe don't 

718
00:40:29,760 --> 00:40:32,440
want to be using the frontier 
model that, you know, just by 

719
00:40:32,440 --> 00:40:34,200
design. 
It has to have a kind of a 

720
00:40:34,200 --> 00:40:37,520
cloud, have kind of a cloud set 
up. 

721
00:40:37,760 --> 00:40:42,040
I, I haven't seen any locally 
hosted coding models. 

722
00:40:42,040 --> 00:40:44,280
They really get close to the 
cloud ones. 

723
00:40:44,280 --> 00:40:47,560
I think there are a few 
projects. 

724
00:40:48,320 --> 00:40:51,000
PewDiePie is probably the most 
famous public figure. 

725
00:40:51,200 --> 00:40:55,600
I think he built his own like 
kind of GPU cluster. 

726
00:40:55,600 --> 00:40:57,480
Any any post about it on his 
YouTube channel now. 

727
00:40:58,560 --> 00:41:01,640
Nice. 
I am so bad at keeping up on 

728
00:41:01,640 --> 00:41:05,920
like everything going on. 
I feel like the ecosystem is 

729
00:41:05,920 --> 00:41:11,000
moving so fast with just a genic
coding and different solutions 

730
00:41:11,000 --> 00:41:13,440
and context management like it's
kind of crazy. 

731
00:41:14,240 --> 00:41:16,400
I, I think it's a huge 
opportunity for Elixir. 

732
00:41:16,400 --> 00:41:21,040
You know, open Hive famously 
used Elixir for that recent 

733
00:41:21,040 --> 00:41:23,440
product that, that I've saw a 
lot of people in Elixir talking 

734
00:41:23,440 --> 00:41:24,680
about. 
And it's sort of like the idea. 

735
00:41:24,680 --> 00:41:26,600
It's like, oh, well, what's an 
agent? 

736
00:41:27,760 --> 00:41:29,680
You know, every Elixir 
programmer kind of knows what a 

737
00:41:29,680 --> 00:41:32,720
Gen. server is in a process and 
sending messages and what, and 

738
00:41:32,720 --> 00:41:36,280
what's the big problem right now
for like these agentic coding 

739
00:41:36,280 --> 00:41:38,240
swords like, oh, they can't 
really communicate well. 

740
00:41:38,560 --> 00:41:40,920
And it's like, oh, if only there
was like a programming language 

741
00:41:40,920 --> 00:41:44,080
and model that had that, only 
there was. 

742
00:41:44,200 --> 00:41:48,560
Message passing, you know. 
It's almost like the whole field

743
00:41:48,560 --> 00:41:52,560
is moving in the direction that 
that Elixir Elixir developers 

744
00:41:52,560 --> 00:41:54,600
are a bit of ahead of the curve 
in some ways. 

745
00:41:55,400 --> 00:42:00,960
Yeah, that is funny. 
I forgot where I was going. 

746
00:42:01,720 --> 00:42:05,760
Anyways, Yeah, I think it like 
you, you were watching all these

747
00:42:05,760 --> 00:42:09,760
like LLMS and like larger 
companies try to like reinvent 

748
00:42:09,760 --> 00:42:14,240
the wheel when the beams existed
since like 1986. 

749
00:42:16,120 --> 00:42:17,760
But yeah, it's it's an 
interesting pattern. 

750
00:42:17,760 --> 00:42:20,760
It's sort of like everyone uses 
Python And they hit the gill and

751
00:42:20,760 --> 00:42:24,080
then they kind of tried to hack 
around it and not so great. 

752
00:42:24,080 --> 00:42:25,880
I was like, I wish there was 
like some way to do concurrent 

753
00:42:25,880 --> 00:42:28,920
programming easily. 
If, if only somebody designed a 

754
00:42:28,920 --> 00:42:31,280
programming language for this, 
for this problem. 

755
00:42:31,840 --> 00:42:37,480
Yeah, exactly. 
I'm curious like for small, 

756
00:42:37,760 --> 00:42:41,440
small products like people like 
me with like Kill Switch and my 

757
00:42:41,440 --> 00:42:48,240
other products, if I were it is 
like quad code, something I can 

758
00:42:48,240 --> 00:42:52,280
leverage to do internal pen 
testing and like how would you 

759
00:42:52,280 --> 00:42:56,160
kind of like go about doing your
own internal audits with it? 

760
00:42:57,160 --> 00:43:00,960
I, I would say that the big 
problem at the moment, and you 

761
00:43:00,960 --> 00:43:04,080
know, we're May 2026, if you're 
watching this from the future, I

762
00:43:04,080 --> 00:43:07,600
see a very plausible future 
where the AI systems actually 

763
00:43:07,600 --> 00:43:09,360
get better than human pet 
testers. 

764
00:43:09,520 --> 00:43:13,080
That is extremely likely today. 
They're not quite there yet. 

765
00:43:14,160 --> 00:43:17,480
So the big problem is that, you 
know, I'm a professional 

766
00:43:17,560 --> 00:43:19,880
software security person. 
That is my full time job. 

767
00:43:20,000 --> 00:43:21,800
I started a company to do it. 
I love it. 

768
00:43:21,800 --> 00:43:24,880
I also really find it 
interesting and I, I do find it 

769
00:43:24,880 --> 00:43:28,040
sometime kind of frustrating 
with Claude because it'll, it'll

770
00:43:28,040 --> 00:43:29,720
send you a report, you know, get
kind of exciting. 

771
00:43:29,720 --> 00:43:32,440
I'm like, oh, I found something 
big and that's a false positive 

772
00:43:32,880 --> 00:43:35,080
and I know enough. 
It's funny because the mistakes 

773
00:43:35,080 --> 00:43:37,680
Claude makes are very similar to
the mistakes I see like bug 

774
00:43:37,680 --> 00:43:40,240
bounty researchers make and I 
make when I'm doing research. 

775
00:43:40,360 --> 00:43:44,720
It's very human in that way. 
But the big problem is almost 

776
00:43:44,720 --> 00:43:47,520
like doesn't know what to, I 
don't want to say, doesn't know 

777
00:43:47,520 --> 00:43:50,400
what to look for because there's
prompts you can do, but you kind

778
00:43:50,400 --> 00:43:54,440
of already need a mental model 
of what is your application 

779
00:43:54,440 --> 00:43:56,440
like, what's the threat model, 
what are the risks? 

780
00:43:56,480 --> 00:44:00,520
And you can do this with Claude,
actually, but it's just not 

781
00:44:00,520 --> 00:44:03,560
quite there yet. 
But like, for example, a lot of 

782
00:44:03,560 --> 00:44:07,680
people now are, are saying, you 
know, AI is fantastic because, 

783
00:44:07,720 --> 00:44:09,960
you know, it enables all of 
these things very cheaply. 

784
00:44:10,640 --> 00:44:12,720
I think medical diagnosis is a 
big one. 

785
00:44:12,720 --> 00:44:15,000
And that's very controversial 
with doctors, of course, because

786
00:44:15,000 --> 00:44:18,640
they want to, you know, kind of 
protect, well, I think 

787
00:44:18,640 --> 00:44:22,160
altruistically protect patients 
#1 because there's always a risk

788
00:44:22,160 --> 00:44:24,720
of a mistake. 
At the same time, I think AI 

789
00:44:24,720 --> 00:44:29,320
legitimately does represent a 
very good advancement in medical

790
00:44:29,320 --> 00:44:32,880
technology for patients, but 
there is a very real risk there 

791
00:44:32,880 --> 00:44:34,400
that I think doctors are aware 
of. 

792
00:44:34,720 --> 00:44:37,480
So, you know, I'm, I'm sitting 
here as a professional saying 

793
00:44:37,480 --> 00:44:42,240
like, oh, should you just use 
Claude for your pen test? 

794
00:44:42,240 --> 00:44:44,680
And you know, you won't, you 
won't need Michael anymore. 

795
00:44:45,400 --> 00:44:47,360
And I, and I, I don't say this 
cynically. 

796
00:44:47,360 --> 00:44:49,400
I'm not trying to kind of like 
defend my own job. 

797
00:44:49,400 --> 00:44:52,880
I think it that if the models 
actually were that good, I would

798
00:44:52,880 --> 00:44:55,800
be out here saying that because 
a lot of people, a lot of people

799
00:44:55,800 --> 00:45:00,480
in Infosec just defensively hate
AI and they don't really engage 

800
00:45:00,480 --> 00:45:02,600
with the truth of, of what's 
happening at all. 

801
00:45:02,600 --> 00:45:06,680
And I see that. 
So that's not the argument I'm 

802
00:45:06,680 --> 00:45:09,680
trying to make here. 
Rather, it's that, you know, 

803
00:45:09,840 --> 00:45:12,920
right now, at the moment, if you
have a, let's say, a very 

804
00:45:12,920 --> 00:45:17,680
important web application, like 
a software as a service or your,

805
00:45:17,680 --> 00:45:21,040
your business relies on a 
publicly facing Elixir app or 

806
00:45:21,040 --> 00:45:22,760
really web application in 
general. 

807
00:45:24,920 --> 00:45:28,720
Maybe the AI is good enough that
it could perform a pen test 

808
00:45:28,720 --> 00:45:32,040
right now in the hands of like 
someone competent. 

809
00:45:32,040 --> 00:45:35,040
Like like if I had to use Claude
personally right now and I like 

810
00:45:35,040 --> 00:45:37,240
couldn't touch the keyboard. 
I could only like prompt it. 

811
00:45:37,480 --> 00:45:39,040
I could actually get you a 
pretty good pen test. 

812
00:45:39,040 --> 00:45:41,560
Like I could tell you, I, I'd 
get frustrated, but I could tell

813
00:45:41,560 --> 00:45:46,800
you I, I really wouldn't trust 
somebody with no security 

814
00:45:46,800 --> 00:45:50,240
background to have a good 
picture because because you just

815
00:45:50,240 --> 00:45:54,200
don't have experience. 
The AI, you, you need to know 

816
00:45:54,200 --> 00:45:56,360
what to tell it. 
That's a big problem. 

817
00:45:56,600 --> 00:45:58,600
And you know, there are probably
systems where you could kind of 

818
00:45:58,600 --> 00:46:01,360
like feed it everything, like 
feed it the whole code base, but

819
00:46:01,560 --> 00:46:04,000
it, it's just not quite there 
yet. 

820
00:46:04,000 --> 00:46:06,200
They're, they're like these very
common mistakes that I see made 

821
00:46:06,200 --> 00:46:09,480
constantly. 
I see it miss things, I see it 

822
00:46:09,480 --> 00:46:11,560
hallucinate things. 
That is, that is a little bit of

823
00:46:11,560 --> 00:46:14,880
a problem. 
I think the field is changing 

824
00:46:14,880 --> 00:46:18,640
very quickly and there is a 
potential future where you know,

825
00:46:18,640 --> 00:46:21,960
an AI is better than most human 
pen testers. 

826
00:46:21,960 --> 00:46:24,360
But but I also actually want to 
qualify that statement a bit 

827
00:46:24,640 --> 00:46:28,440
because there is a very good 
talk that I recommend everyone 

828
00:46:28,440 --> 00:46:30,480
watch if you have time. 
If you're interested in this. 

829
00:46:31,920 --> 00:46:35,320
Nicholas Carlini, who's an 
anthropic researcher, gave a 

830
00:46:35,320 --> 00:46:39,640
talk called Black Hat LLMS at 
unprompted 2026. 

831
00:46:39,880 --> 00:46:44,200
This is back in March 2026 where
he says that AI is now a better 

832
00:46:44,200 --> 00:46:46,320
vulnerability researcher than he
is. 

833
00:46:46,320 --> 00:46:50,120
And he and he's one of the best 
researchers, you know, eminent 

834
00:46:50,120 --> 00:46:53,120
sighted, probably top, you know,
one of the top research 

835
00:46:53,160 --> 00:46:55,040
cybersecurity researchers in the
world. 

836
00:46:55,320 --> 00:46:58,560
And the AI example he gives in 
the talk, and this was a few 

837
00:46:58,560 --> 00:47:02,920
months ago, this before Mythos, 
it was in Ghost, I believe, 

838
00:47:02,920 --> 00:47:05,640
which is a Ruby on Rails 
application and then the Linux 

839
00:47:05,640 --> 00:47:08,160
kernel. 
And his argument in the talk is 

840
00:47:08,160 --> 00:47:10,920
that AI is better at him than, 
you know, finding bugs in the 

841
00:47:10,920 --> 00:47:13,040
Linux kernel. 
And for people outside 

842
00:47:13,040 --> 00:47:15,200
cybersecurity, I should actually
explain this is an important 

843
00:47:15,200 --> 00:47:17,280
part. 
When somebody is a professional 

844
00:47:17,280 --> 00:47:21,000
vulnerability researcher, they 
tend to specialize a bit like 

845
00:47:21,000 --> 00:47:23,800
the iOS scene that's kind of 
like its own own, like if you're

846
00:47:23,800 --> 00:47:25,720
a jailbreak dev, that's its own 
scene. 

847
00:47:25,880 --> 00:47:29,040
That's very distinct from, say, 
the work I do, which is securing

848
00:47:29,520 --> 00:47:32,320
Elixir web applications. 
You go to Defcon, nobody's going

849
00:47:32,320 --> 00:47:35,600
to know what Elixir is. 
There's people that specialize 

850
00:47:35,600 --> 00:47:38,920
in Windows. 
There's people that specialize 

851
00:47:38,920 --> 00:47:41,680
in like SCADA. 
It's, you know, I actually 

852
00:47:41,720 --> 00:47:43,280
falsely had this view at one 
point. 

853
00:47:43,280 --> 00:47:47,520
I thought if someone was like a 
master hacker at Defcon, they 

854
00:47:47,520 --> 00:47:50,960
could hack anything and they 
probably had the capability to 

855
00:47:50,960 --> 00:47:52,880
learn it. 
But people specialize. 

856
00:47:52,880 --> 00:47:54,720
That's the point I want. 
That makes sense. 

857
00:47:54,920 --> 00:47:58,520
So somebody that does Elixir, 
somebody that does kernel like 

858
00:47:58,520 --> 00:48:01,920
Linux kernel security for a 
living, they might not know any 

859
00:48:01,920 --> 00:48:06,280
Windows at all and they won't 
really be able to tell you. 

860
00:48:06,400 --> 00:48:09,680
So it's like an AI is like a 
better, you know, vulnerability 

861
00:48:09,680 --> 00:48:12,160
researcher than most people. 
Yeah, Well, true. 

862
00:48:12,880 --> 00:48:15,520
So it was like a stack and like 
a basic, there's a joke, they 

863
00:48:15,520 --> 00:48:19,800
called it GREP, where a lot of 
like really hardcore security 

864
00:48:19,800 --> 00:48:21,600
research, like, oh, well, how 
did you find the bug? 

865
00:48:21,640 --> 00:48:24,040
Oh, like I grepped for a 
function and they were using it.

866
00:48:25,880 --> 00:48:28,640
So that's not as glamorous. 
But, but the point I want to 

867
00:48:28,640 --> 00:48:34,000
make is that finding bugs, it is
very different from like the act

868
00:48:34,000 --> 00:48:36,640
of finding a vulnerability is 
very different from hacking a 

869
00:48:36,640 --> 00:48:38,880
company. 
And even the act of a hacking a 

870
00:48:38,880 --> 00:48:41,320
company can be very different. 
Like we talked about the 

871
00:48:41,320 --> 00:48:45,000
Scattered Spider, which is like 
the teenagers in a, in a group 

872
00:48:45,000 --> 00:48:47,440
chat on Discord, you know, 
social engineering. 

873
00:48:47,640 --> 00:48:50,360
That's a very different type of 
hacking than say, what North 

874
00:48:50,360 --> 00:48:54,720
Korea does with cybersecurity, 
sorry, with cryptocurrency, 

875
00:48:55,800 --> 00:48:58,040
where you're a hacker that 
specializes in, you know, 

876
00:48:58,040 --> 00:49:00,800
stealing money from 
cryptocurrency projects, that's 

877
00:49:00,800 --> 00:49:03,920
very different from a hacker 
that does iOS and iPhone for a 

878
00:49:03,920 --> 00:49:05,680
living. 
So they're very different. 

879
00:49:06,640 --> 00:49:10,120
The point I want to get at is 
that if you're a business using 

880
00:49:10,120 --> 00:49:13,480
Elixir, you know, I, I, that's 
my customer base, I would say 

881
00:49:13,480 --> 00:49:16,440
I'm very good at that. 
I don't mean to brag or plug or 

882
00:49:16,440 --> 00:49:19,360
anything, but it's because I, I 
know what a business in that 

883
00:49:19,360 --> 00:49:21,440
situation needs. 
I know what they need from a pen

884
00:49:21,440 --> 00:49:25,360
test and how to kind of guide 
the work almost as a product 

885
00:49:25,360 --> 00:49:27,120
manager, I'll, I'll defend 
product managers a bit. 

886
00:49:27,120 --> 00:49:28,440
I feel like we still need them a
little bit. 

887
00:49:28,720 --> 00:49:34,120
Because when, when you get a pen
test report, it is in a sense, a

888
00:49:34,120 --> 00:49:35,720
list of work that needs to be 
done. 

889
00:49:35,920 --> 00:49:38,880
And the reason I tell people 
like, I'm sorry, a good pen 

890
00:49:38,880 --> 00:49:40,360
test, the test is very 
expensive. 

891
00:49:40,520 --> 00:49:43,280
You can, you can cheap out on 
it, but you're kind of shooting 

892
00:49:43,280 --> 00:49:46,280
yourself in the foot because now
you have a report where the 

893
00:49:46,280 --> 00:49:48,480
person doesn't understand your 
business context, They don't 

894
00:49:48,480 --> 00:49:50,280
understand the technology stack 
you used. 

895
00:49:50,560 --> 00:49:53,120
They just gave you a bunch of 
findings, which might be wrong. 

896
00:49:53,120 --> 00:49:55,640
They're probably AI generated 
now if you went with the cheap 

897
00:49:55,640 --> 00:49:58,720
provider and now you have to fix
them. 

898
00:49:59,560 --> 00:50:01,040
And what if they're not real 
bugs? 

899
00:50:01,040 --> 00:50:02,960
What if they miss something 
important? 

900
00:50:03,120 --> 00:50:05,280
Now you're doing work that is 
nonsense. 

901
00:50:05,280 --> 00:50:08,920
You're wasting developer time. 
And you might tell them, hi, 

902
00:50:08,920 --> 00:50:10,480
yeah, we looked at this. 
We don't think it's a bug. 

903
00:50:10,480 --> 00:50:11,640
And they might say, no, it is a 
bug. 

904
00:50:11,840 --> 00:50:15,080
Like we're 100%, you know, and 
you're just ridiculous. 

905
00:50:15,120 --> 00:50:17,320
And I've seen this happen, by 
the way, in my career. 

906
00:50:17,480 --> 00:50:19,400
You've experienced this. 
Myself. 

907
00:50:19,840 --> 00:50:21,760
OK. 
So, you know, and maybe people 

908
00:50:21,760 --> 00:50:22,920
on this call have experienced 
this. 

909
00:50:23,120 --> 00:50:27,680
So you're not people don't hire,
you know, Parac Clio to do a pen

910
00:50:27,680 --> 00:50:32,800
test necessarily, just as code 
in, you know, findings out. 

911
00:50:32,960 --> 00:50:37,880
That is a very important piece 
of a much larger picture, which 

912
00:50:37,880 --> 00:50:41,560
is, you know, what does your 
business need to know to 

913
00:50:41,560 --> 00:50:45,040
maximally reduce the risk of a 
cybersecurity incident? 

914
00:50:46,320 --> 00:50:48,640
And this is subtle and it gets, 
it's very easy to get lost in 

915
00:50:48,640 --> 00:50:51,040
this because, you know, it's 
headlines and click bait and 

916
00:50:51,040 --> 00:50:54,400
outrage, but the the finer 
points are are genuinely subtle.

917
00:50:54,400 --> 00:50:58,680
And I think this is actually a 
great forum to discuss it 

918
00:50:59,160 --> 00:51:01,840
because we can kind of go into 
detail and and get into the 

919
00:51:02,320 --> 00:51:04,000
because as you said, you've 
dealt with this yourself. 

920
00:51:04,400 --> 00:51:06,240
Well, yeah, and I think you make
a good point. 

921
00:51:06,240 --> 00:51:10,680
And I think anyone that is using
LMS or, you know, AI on a daily 

922
00:51:10,680 --> 00:51:17,160
basis, like I produce really 
good code, but I also know when 

923
00:51:17,160 --> 00:51:21,200
it's not producing good code. 
So I feel like that's my skill, 

924
00:51:21,200 --> 00:51:22,600
right? 
I'm a developer. 

925
00:51:22,600 --> 00:51:25,520
I know when it's good. 
But if I were to randomly say, 

926
00:51:25,520 --> 00:51:29,000
all right, hey, I want a pen 
test kill switch, Sure, I know 

927
00:51:29,000 --> 00:51:32,960
some like trigger words from the
industry, but is that actually 

928
00:51:32,960 --> 00:51:35,920
going to am I gonna know what 
it's spitting out at me? 

929
00:51:35,920 --> 00:51:39,200
Probably not very well. 
And it'd probably take me a very

930
00:51:39,200 --> 00:51:43,680
long time to sift through the 
reporting and whatever Claude 

931
00:51:43,680 --> 00:51:51,080
discovers in my, in my codebase.
And it's not, sorry, it's not 

932
00:51:51,080 --> 00:51:54,320
just codebase, right? 
It's your how your, your DevOps,

933
00:51:54,320 --> 00:51:57,960
how you've deployed things like 
is your, are your droplets 

934
00:51:57,960 --> 00:51:59,560
secure, etcetera. 
You know? 

935
00:52:02,120 --> 00:52:04,960
A really good example that I 
think is related to that is 

936
00:52:04,960 --> 00:52:10,080
let's say you feed Claude your 
codebase and you spend 1000 or 

937
00:52:10,080 --> 00:52:11,800
$10,000. 
People spend that much. 

938
00:52:11,800 --> 00:52:15,440
People spend more than that. 
Let's say you say Claude, I'm 

939
00:52:15,440 --> 00:52:19,760
giving you a budget of $10,000. 
I want you to do the best audit 

940
00:52:19,760 --> 00:52:21,720
possible. 
I want you to use 50 agents and 

941
00:52:21,720 --> 00:52:25,160
it comes back and you know, it's
got 100 false positives, but it 

942
00:52:25,160 --> 00:52:28,240
finds two really good bugs and 
you go, OK, that's very good. 

943
00:52:29,440 --> 00:52:31,680
And then a week later you got 
hacked and back doored. 

944
00:52:31,840 --> 00:52:35,320
And what was the problem? 
It was your GitHub actions, 

945
00:52:35,400 --> 00:52:37,200
which were, you know, 
technically not in scope. 

946
00:52:37,200 --> 00:52:40,040
You didn't even think about it. 
That that was what got you. 

947
00:52:40,280 --> 00:52:44,880
You know, it's, it's that kind 
of context that, and I see it 

948
00:52:44,880 --> 00:52:50,120
happen constantly in industry 
where people they kind of focus 

949
00:52:50,120 --> 00:52:53,360
on the wrong things. 
They, they think that, you know,

950
00:52:53,760 --> 00:52:57,720
number of hours spent on a pen 
test is like the ultimate metric

951
00:52:57,720 --> 00:53:00,200
or number of tokens burn. 
As we were talking about like 

952
00:53:00,200 --> 00:53:02,600
lines of code tokens burned, 
weight of an air. 

953
00:53:02,800 --> 00:53:06,520
It's, it's the wrong metric. 
You have to kind of be able to 

954
00:53:06,520 --> 00:53:09,280
look past it a bit and kind of 
find the truth of the matter, 

955
00:53:09,280 --> 00:53:12,560
which is very difficult. 
It gets philosophical and it's 

956
00:53:12,560 --> 00:53:17,360
not easy, and there's a lot of 
debate in that area. 

957
00:53:20,320 --> 00:53:24,840
Yeah, and like, it's always 
funny because I always go back 

958
00:53:24,840 --> 00:53:29,440
to when I was on the, you know, 
the top of the Dunning Kruger 

959
00:53:29,440 --> 00:53:32,520
curve when I first started 
programming, you know, Mount 

960
00:53:32,520 --> 00:53:37,000
Stupid. 
And I didn't even know what like

961
00:53:37,000 --> 00:53:42,080
a man in the Middle attack was. 
And then I experienced one with 

962
00:53:42,840 --> 00:53:45,200
just a REST API that I was 
building. 

963
00:53:45,520 --> 00:53:51,760
And then that became like my 
priority and security concern 

964
00:53:51,760 --> 00:53:55,040
right when like, you know, 
there's thousands of other ones.

965
00:53:55,040 --> 00:53:58,200
But now that I know about this 
one and it actually affected my 

966
00:53:58,200 --> 00:54:00,800
day-to-day. 
Now it's like this new thing I 

967
00:54:00,800 --> 00:54:05,160
learned and I'm like sole focus 
was man in the middle attacks. 

968
00:54:05,480 --> 00:54:08,880
But like, yeah, it was a good 
like, learning opportunity, 

969
00:54:08,880 --> 00:54:12,000
right? 
But like, you can't just narrow 

970
00:54:12,000 --> 00:54:15,600
your focus to worrying about man
in the middle when there's like 

971
00:54:15,600 --> 00:54:18,080
so many, so many other things 
that can happen. 

972
00:54:18,840 --> 00:54:20,600
Absolutely. 
Is there a chat? 

973
00:54:20,600 --> 00:54:23,040
Like do people ask questions 
during the stream or? 

974
00:54:23,040 --> 00:54:26,280
Yeah, we do. 
We have some chatter going on. 

975
00:54:27,600 --> 00:54:29,240
Let's see. 
Cipher asked. 

976
00:54:29,520 --> 00:54:32,280
He just wanted to say hi to 
Michael and thank. 

977
00:54:32,400 --> 00:54:35,480
Thank you for all your Elixir 
security work. 

978
00:54:36,000 --> 00:54:37,440
Thank you for your message, I 
appreciate that. 

979
00:54:38,000 --> 00:54:42,440
And he's listening intently 
because he's trying to convince 

980
00:54:43,480 --> 00:54:46,400
his regional ISP to use the 
Beam. 

981
00:54:47,160 --> 00:54:50,720
Hey man, this is the podcast. 
We'll talk you into it. 

982
00:54:50,720 --> 00:54:52,640
Build everything on. 
That's a great, that's a great 

983
00:54:52,640 --> 00:54:54,440
way, Sir. 
I, I hope they do. 

984
00:54:55,160 --> 00:54:57,720
I mean, it's telecom. 
They should, they should want to

985
00:54:57,800 --> 00:54:59,240
it's but it's hard. 
It's hard for. 

986
00:54:59,240 --> 00:55:01,520
Real. 
It's like the perfect fit. 

987
00:55:01,520 --> 00:55:04,880
They've already solved the 
problems you are working on. 

988
00:55:06,880 --> 00:55:11,240
OK, I don't we have someone with
just some Chinese characters as 

989
00:55:11,240 --> 00:55:14,440
their name. 
If I have a limited budget for 

990
00:55:14,440 --> 00:55:18,040
an Elixir based projects project
and I want some basic 

991
00:55:18,040 --> 00:55:19,880
penetration testing, what should
I do? 

992
00:55:21,440 --> 00:55:24,360
Yeah, the limited budget is a 
tricky part. 

993
00:55:24,360 --> 00:55:28,160
I would actually recommend using
the open source tools SOBLO. 

994
00:55:30,000 --> 00:55:33,600
There's a mix audit which checks
for vulnerable dependencies. 

995
00:55:33,600 --> 00:55:35,760
That's a big one. 
Paraxial. 

996
00:55:36,520 --> 00:55:38,200
Paraxial has a free tier as 
well. 

997
00:55:38,200 --> 00:55:43,040
If it's non commercial you know 
it's it's because I do actually 

998
00:55:43,040 --> 00:55:45,240
want to recommend clawed code. 
I would say like clawed code is 

999
00:55:45,240 --> 00:55:48,080
actually fairly useful in your 
situation. 

1000
00:55:48,920 --> 00:55:50,720
It might sound like I'm 
contradicting our previous 

1001
00:55:50,720 --> 00:55:53,560
conversation, but the but the 
difference there is limited 

1002
00:55:53,560 --> 00:55:56,640
budget. 
If you only have, you know, 

1003
00:55:56,640 --> 00:56:00,040
let's say under $100 for your 
budget, the the mainstream 

1004
00:56:00,040 --> 00:56:03,720
cybersecurity industry really 
isn't set up to help you. 

1005
00:56:04,640 --> 00:56:08,840
You're going to be on the free 
tiers for like, for like a 

1006
00:56:08,840 --> 00:56:11,720
proper customer of any 
cybersecurity software. 

1007
00:56:11,840 --> 00:56:14,080
You're it's, it's going to be 
much higher than that. 

1008
00:56:14,600 --> 00:56:19,040
What is like, I don't even know 
what is like the average like I 

1009
00:56:19,040 --> 00:56:22,440
come to you, Michael, I want you
to pen test Killswitch. 

1010
00:56:22,680 --> 00:56:27,120
What's like an average budget to
do just like a SAS platform? 

1011
00:56:27,760 --> 00:56:30,600
It, it's very hard to say 
because every customer is so 

1012
00:56:30,600 --> 00:56:33,280
different. 
What I, what I and this 

1013
00:56:33,280 --> 00:56:36,160
information is public. 
What I would say is that if you,

1014
00:56:36,280 --> 00:56:40,800
if you look at major providers 
like very big name cybersecurity

1015
00:56:40,800 --> 00:56:44,680
firms, the BIG4 does a lot of 
penetration tests. 

1016
00:56:44,840 --> 00:56:50,680
Those contracts get into the 
like floor of $100,000 up to the

1017
00:56:50,680 --> 00:56:52,720
millions. 
And that's very common. 

1018
00:56:52,880 --> 00:56:56,160
And that's staffed with people. 
Often times it's multiple 

1019
00:56:56,160 --> 00:56:59,920
applications. 
It can be ongoing and it's, it's

1020
00:56:59,920 --> 00:57:03,000
going to be interesting to see 
if those keep happening or if 

1021
00:57:03,000 --> 00:57:05,280
regulation will allow people to 
use AI for that. 

1022
00:57:06,320 --> 00:57:09,560
But that's kind of the scale 
you're talking about because 

1023
00:57:09,560 --> 00:57:13,160
it's human labour. 
And personally, what I tell 

1024
00:57:13,160 --> 00:57:17,200
customers is that, you know, I'm
the person doing the penetration

1025
00:57:17,200 --> 00:57:18,720
test. 
Paraxial actually doesn't 

1026
00:57:18,720 --> 00:57:22,400
subcontract out. 
So, you know, my, I, my bids are

1027
00:57:22,400 --> 00:57:24,840
often much higher than what they
come in, for example. 

1028
00:57:25,480 --> 00:57:28,280
But I say the, the reason I 
can't do a discount in that 

1029
00:57:28,280 --> 00:57:31,680
situation is just because it's 
my time, because I have 

1030
00:57:31,680 --> 00:57:34,520
obligations. 
I have to run Paraxial as a 

1031
00:57:34,520 --> 00:57:36,720
company. 
I love doing events like this, 

1032
00:57:36,720 --> 00:57:38,520
but you know, that's hourly 
time. 

1033
00:57:38,520 --> 00:57:40,760
I, I, I wish I had more hours in
the day. 

1034
00:57:40,800 --> 00:57:43,280
I feel like a lot of people do. 
That's common. 

1035
00:57:45,320 --> 00:57:48,400
But it's. 
Also more energy during the day.

1036
00:57:49,040 --> 00:57:53,280
Energy plus hours. 
But that, that's just the nature

1037
00:57:53,280 --> 00:57:54,840
of it. 
And it's, it's getting harder. 

1038
00:57:54,840 --> 00:57:58,000
I actually, that's why I also 
tell people now it's getting 

1039
00:57:58,000 --> 00:57:59,960
even harder because demand keeps
going up. 

1040
00:57:59,960 --> 00:58:04,240
You know, we're entering this 
era where cybersecurity, you 

1041
00:58:04,240 --> 00:58:07,040
know, things are just changing 
so quickly and it's getting more

1042
00:58:07,040 --> 00:58:09,040
important. 
People just need more pen tests.

1043
00:58:09,040 --> 00:58:10,640
They need more cybersecurity 
help. 

1044
00:58:10,840 --> 00:58:13,400
And I'm grateful to help when I 
have the opportunity. 

1045
00:58:13,400 --> 00:58:15,680
I really am. 
But just there's, you know, 

1046
00:58:15,680 --> 00:58:17,600
there's only so many hours in 
the day. 

1047
00:58:18,000 --> 00:58:20,800
And the good news is everyone 
that comes to me, they're using 

1048
00:58:20,800 --> 00:58:23,040
Elixir. 
They're not so much in the NPM 

1049
00:58:23,160 --> 00:58:25,520
ecosystem. 
So things are things are not 

1050
00:58:25,520 --> 00:58:27,600
quite on fire. 
At the same time, I think we 

1051
00:58:27,600 --> 00:58:31,080
should look to what's happening 
outside the ecosystem and kind 

1052
00:58:31,080 --> 00:58:34,280
of learn, you know, how how can 
Elixir stay secure and by a 

1053
00:58:34,280 --> 00:58:37,080
leader. 
Oh, and the the nice thing there

1054
00:58:37,080 --> 00:58:40,680
right is Elixir isn't the 
popular choice. 

1055
00:58:40,680 --> 00:58:44,080
So you see, the popular choices 
have the problems first. 

1056
00:58:45,080 --> 00:58:46,760
That does happen that that is 
very common. 

1057
00:58:47,720 --> 00:58:49,120
Yeah. 
So it gives us a chance to 

1058
00:58:49,120 --> 00:58:51,520
respond a little bit right or 
prepare. 

1059
00:58:52,640 --> 00:58:56,560
And this is a common phenomenon.
There was the famous Mac and PC 

1060
00:58:56,560 --> 00:58:58,360
ad campaign. 
Whereas, you know, Macs don't 

1061
00:58:58,360 --> 00:59:00,640
get viruses. 
That's because no one used them.

1062
00:59:02,320 --> 00:59:04,800
Meaning, yeah, the the malware 
developers are mostly targeting 

1063
00:59:04,800 --> 00:59:06,320
window, which was a true 
phenomenon. 

1064
00:59:07,640 --> 00:59:10,640
And you see that same dynamic 
cloud at the same time. 

1065
00:59:10,640 --> 00:59:13,480
I actually, I make this argument
a lot and I, I believe it's very

1066
00:59:13,480 --> 00:59:19,200
true that Elixir developers do 
tend to be more experienced. 

1067
00:59:19,560 --> 00:59:21,720
Every time I talk to a Lexir 
developer, they tend to come 

1068
00:59:21,720 --> 00:59:24,760
from a different language. 
So these kind of novice 

1069
00:59:24,760 --> 00:59:28,320
programmer mistakes that often 
show up in a, you know, MPM 

1070
00:59:28,320 --> 00:59:30,360
library that's used by 10 
million people. 

1071
00:59:31,880 --> 00:59:34,360
I'll, I'll look at a library and
I just won't have them. 

1072
00:59:35,240 --> 00:59:38,160
For example, these JWT 
libraries, there was this very 

1073
00:59:38,160 --> 00:59:41,120
common problem where you could 
just say algorithm none and you 

1074
00:59:41,160 --> 00:59:43,560
just bypass JWTS. 
And this was a this was a 

1075
00:59:43,560 --> 00:59:46,360
problem in a few ecosystems. 
And I had a pen test where I 

1076
00:59:46,360 --> 00:59:51,120
looked at it was it's like Jose 
and a few other libraries that 

1077
00:59:51,120 --> 00:59:53,560
do JWT and none of them are 
vulnerable to it. 

1078
00:59:53,560 --> 00:59:56,680
But we'll see. 
Maybe the AIS will will find 

1079
00:59:56,680 --> 01:00:00,280
something, but I. 
I'm wondering like like the hex 

1080
01:00:00,280 --> 01:00:03,760
package manager in general, Like
I kind of was like I was talking

1081
01:00:03,760 --> 01:00:06,960
to another developer buddy. 
I was like, I kind of feel bad 

1082
01:00:07,320 --> 01:00:11,240
for that project right now 
because the influx of packages 

1083
01:00:11,240 --> 01:00:15,600
being created and just AI 
generated is just one. 

1084
01:00:15,600 --> 01:00:19,200
I mean, like, we're seeing a lot
of good stuff, but there's also 

1085
01:00:19,200 --> 01:00:22,880
a lot of slop and probably crap 
entering our ecosystem because 

1086
01:00:22,880 --> 01:00:25,200
of it. 
That's true. 

1087
01:00:25,240 --> 01:00:28,160
That does happen. 
And I think it's it's, it's so 

1088
01:00:28,160 --> 01:00:32,280
important to talk about this 
because people don't know unless

1089
01:00:32,280 --> 01:00:34,080
you make noise and you're public
about it. 

1090
01:00:34,320 --> 01:00:39,840
So the EEF has been very strong 
on this in raising money because

1091
01:00:39,840 --> 01:00:42,920
there's actually a lot of 
programs and grants from 

1092
01:00:42,920 --> 01:00:46,560
governments and from non profits
where they allocate millions of 

1093
01:00:46,560 --> 01:00:48,280
dollars in some cases. 
And they say, hey, we want to 

1094
01:00:48,280 --> 01:00:51,200
help with this problem. 
But in order to get that help, 

1095
01:00:51,200 --> 01:00:54,000
you need a non profit such as 
the EEF with Standee and the 

1096
01:00:54,000 --> 01:00:56,040
community. 
And you need people, you know, 

1097
01:00:56,040 --> 01:00:59,680
like Alistair, like Jonathan 
Bram is the head of the security

1098
01:00:59,680 --> 01:01:01,640
working group. 
I mean, everyone there works 

1099
01:01:01,640 --> 01:01:05,720
extremely hard and they're 
putting in a lot of hours to 

1100
01:01:05,840 --> 01:01:09,520
raise the money that can then go
to hacks to deal with this 

1101
01:01:09,520 --> 01:01:12,640
problem because, you know, 
having it just being volunteer 

1102
01:01:12,640 --> 01:01:14,280
effort is not sustainable at 
all. 

1103
01:01:15,040 --> 01:01:17,600
I think the funding is really 
important and it's why I'm very 

1104
01:01:17,600 --> 01:01:20,800
grateful to all the donors. 
I think Dash Bit has actually 

1105
01:01:20,800 --> 01:01:23,280
been one of the biggest ones. 
They're on the page and a lot of

1106
01:01:23,280 --> 01:01:28,280
companies. 
So that's for Aegis, which is 

1107
01:01:28,280 --> 01:01:31,000
the initiative and then Alpha 
Omega as well, which we've been 

1108
01:01:31,000 --> 01:01:33,400
talking about. 
So those companies have all been

1109
01:01:33,600 --> 01:01:36,640
been really fantastic. 
Yeah, no, that's really awesome.

1110
01:01:37,560 --> 01:01:40,120
Let's see. 
Dalton, being new to Elixir, are

1111
01:01:40,120 --> 01:01:44,240
there common gotchas security 
wise and does paraxial leverage 

1112
01:01:44,240 --> 01:01:47,920
that? 
I feel like yeah, there are. 

1113
01:01:47,920 --> 01:01:52,760
There are some gotchas, right? 
Yeah, the one, the one I always 

1114
01:01:52,760 --> 01:01:58,240
say is, well, the Elixir 
specific one is the binary 

1115
01:01:58,240 --> 01:02:01,800
deserialization. 
So number one, if you're like 

1116
01:02:01,800 --> 01:02:05,320
taking base 64 input from the 
public Internet and then putting

1117
01:02:05,320 --> 01:02:08,000
that into binary to term 
because, you know, you wanted 

1118
01:02:08,000 --> 01:02:11,240
to, you didn't want to serialize
like some complex Elixir term 

1119
01:02:11,240 --> 01:02:13,960
where you know, like it's a map 
and then inside the map there's 

1120
01:02:13,960 --> 01:02:16,320
less and you're supposed to 
serialize that to Jason and 

1121
01:02:16,320 --> 01:02:17,280
you're like, ah, that's 
annoying. 

1122
01:02:17,400 --> 01:02:20,640
I'm just going to put it in a 
term that's a really common 

1123
01:02:20,640 --> 01:02:22,960
remote code execution vector. 
So don't do that. 

1124
01:02:24,120 --> 01:02:26,640
Serializing to Jason is a great 
security layer there. 

1125
01:02:27,760 --> 01:02:31,080
I would also say for Elixir 
developers, server side request 

1126
01:02:31,080 --> 01:02:33,840
forgery is kind of an underrated
vulnerability. 

1127
01:02:34,160 --> 01:02:38,760
Where does does your application
take input from a user and then 

1128
01:02:38,760 --> 01:02:41,360
do outbound Http://requests? 
OK? 

1129
01:02:41,680 --> 01:02:46,120
If it does, then a bad guy could
use that function to then send a

1130
01:02:46,120 --> 01:02:49,600
request to like your AWS like 
it's called the instance 

1131
01:02:49,600 --> 01:02:53,040
metadata server. 
And and Amazon has actually 

1132
01:02:53,040 --> 01:02:55,640
gotten better about this because
now they check it and there's 

1133
01:02:55,640 --> 01:02:58,080
like some setting you can flip 
where it's not vulnerable 

1134
01:02:58,080 --> 01:02:59,920
anymore. 
But that that's another common 

1135
01:02:59,920 --> 01:03:04,560
one I've seen too. 
The good news is Phoenix 

1136
01:03:04,560 --> 01:03:06,080
actually gives you a very good 
base. 

1137
01:03:06,120 --> 01:03:09,640
And if you're using Phoenix with
something like Paraxial IO, 

1138
01:03:10,800 --> 01:03:15,360
you're, you're better off than I
would say 95% of like web 

1139
01:03:15,360 --> 01:03:18,320
developers, you know, you get 
people coming from WordPress, 

1140
01:03:18,320 --> 01:03:20,360
for example. 
And I don't want to dump on 

1141
01:03:20,360 --> 01:03:21,800
WordPress. 
I think WordPress is a great 

1142
01:03:21,800 --> 01:03:24,600
project for what it is, you 
know, web publishing software. 

1143
01:03:24,800 --> 01:03:29,880
But when people try to use it 
for situations like a bank as 

1144
01:03:29,880 --> 01:03:33,120
that primary application, that 
is not the right decision. 

1145
01:03:33,960 --> 01:03:36,560
A lot of security problems there
with the plug in system. 

1146
01:03:36,960 --> 01:03:41,240
Just watching my like traffic 
requests on in like any public 

1147
01:03:41,320 --> 01:03:44,560
domain, right? 
Like I'll go on the paraxial 

1148
01:03:44,560 --> 01:03:50,040
dashboard and it's always just 
bots looking for the WordPress 

1149
01:03:50,040 --> 01:03:52,840
vulnerabilities, you know? 
Yeah, WordPress exploits. 

1150
01:03:53,120 --> 01:03:56,960
Yeah. 
And but it's also because it's 

1151
01:03:56,960 --> 01:04:01,880
the most popular website that is
out there, right? 

1152
01:04:01,880 --> 01:04:05,040
So it makes sense. 
Yeah. 

1153
01:04:05,040 --> 01:04:08,640
And people will say, oh, this is
security through obscurity, like

1154
01:04:08,640 --> 01:04:10,880
you're using Phoenix instead of 
WordPress. 

1155
01:04:10,920 --> 01:04:15,560
And I'm like, yes, but by any 
honest conversation about 

1156
01:04:15,560 --> 01:04:20,880
security, your probability of an
incident is far lower with 

1157
01:04:21,280 --> 01:04:23,160
Elixir in Phoenix than with 
WordPress. 

1158
01:04:23,160 --> 01:04:24,160
It is. 
It is not. 

1159
01:04:24,160 --> 01:04:29,520
Even close well and then like 
like if you're using ACTO for 

1160
01:04:29,640 --> 01:04:35,400
any CRUD like you're, you're 
really avoiding like SQL 

1161
01:04:35,400 --> 01:04:39,320
injection problems and a lot of 
issues that you can run into 

1162
01:04:39,400 --> 01:04:41,840
with any like. 
Open, we should mention yeah, 

1163
01:04:42,800 --> 01:04:44,880
use Ecto. 
Don't try to roll your own on 

1164
01:04:44,880 --> 01:04:48,080
that one. 
That's bad because you get SQL 

1165
01:04:48,080 --> 01:04:50,840
injection. 
Don't don't execute like raw SQL

1166
01:04:50,840 --> 01:04:54,320
query like Ecto's actually great
if you're using the default Ecto

1167
01:04:54,320 --> 01:04:59,280
query syntax that is perfect. 
Do that like don't try to get 

1168
01:04:59,280 --> 01:05:01,840
creative with it. 
You don't have to roll your own 

1169
01:05:01,840 --> 01:05:04,880
and then when you don't, you 
don't even have to worry about 

1170
01:05:05,200 --> 01:05:08,520
sequel injection, so. 
I, I actually had someone ask 

1171
01:05:08,520 --> 01:05:11,440
me, they said, oh, you know, 
like we're using Ecto and I'm, 

1172
01:05:11,680 --> 01:05:14,200
and I'm worried about sequel 
injection because I don't, I 

1173
01:05:14,240 --> 01:05:17,280
don't really trust Ecto. 
Could paraxial help me with 

1174
01:05:17,280 --> 01:05:19,000
that? 
And I had to explain like how 

1175
01:05:19,000 --> 01:05:20,560
Paraxial worked and what the 
product was. 

1176
01:05:20,560 --> 01:05:24,560
And I'm like, look, I'm not 
gonna misrepresent this here. 

1177
01:05:24,760 --> 01:05:27,160
Ecto is the best. 
Like use ecto in the default say

1178
01:05:27,280 --> 01:05:30,320
paraxial will tell you the the 
actual value of paraxial is 

1179
01:05:30,320 --> 01:05:33,560
telling you if you've gone off 
of the guardrails ecto set for 

1180
01:05:33,560 --> 01:05:37,040
you, yes. 
Yeah, which is really good. 

1181
01:05:37,040 --> 01:05:41,360
I actually like when I first add
paraxial to a project too. 

1182
01:05:41,360 --> 01:05:45,800
Like, you'll have a ton of noise
'cause you just do, you do nasty

1183
01:05:45,800 --> 01:05:49,280
things on accident, you know, 
but that that noise is great 

1184
01:05:49,280 --> 01:05:53,200
'cause then you just go through 
each of the, you know, warnings 

1185
01:05:53,200 --> 01:05:57,160
and you just slowly clean it up.
And it makes you feel better 

1186
01:05:57,160 --> 01:06:00,800
about yourself too. 
I had an interesting moment 

1187
01:06:00,800 --> 01:06:05,320
where when I was developing 
paraxial, kind of pre LLM 

1188
01:06:05,320 --> 01:06:10,200
coding, I was writing guides for
each SOBLO finding. 

1189
01:06:10,320 --> 01:06:13,120
So the intent was you're a 
developer, you get a SOBLO 

1190
01:06:13,120 --> 01:06:15,160
finding and you're kind of like,
well what the heck does this 

1191
01:06:15,160 --> 01:06:16,640
mean? 
And it's like, OK, well here's 

1192
01:06:16,640 --> 01:06:19,200
what it means, here's the 
severity, here's how you fix it.

1193
01:06:19,480 --> 01:06:24,520
I wrote that 100% the audience 
was a human LLM show up on the 

1194
01:06:24,520 --> 01:06:27,560
scene. 
If you feed a solo output to 

1195
01:06:27,560 --> 01:06:31,400
Claude, it typically googles it 
and then like finds the paraxial

1196
01:06:31,400 --> 01:06:34,760
blog and reads it and then it's.
Like that's hilarious. 

1197
01:06:34,920 --> 01:06:36,760
So it's like kind of burning all
these tokens. 

1198
01:06:36,760 --> 01:06:40,080
But what I tell people is if you
just use paraxial, you know, you

1199
01:06:40,080 --> 01:06:43,120
have the guide that I wrote you,
you can save a lot of tokens. 

1200
01:06:43,240 --> 01:06:45,160
So rather. 
Than I will say spawn. 

1201
01:06:45,560 --> 01:06:50,960
Yeah, your notes like in your 
findings are so helpful. 

1202
01:06:52,360 --> 01:06:54,720
That's the goal. 
And then, and then it saves you 

1203
01:06:54,720 --> 01:06:57,280
tokens like because I know 
everyone always, I get my clawed

1204
01:06:57,280 --> 01:07:00,600
limit daily constantly. 
So you get more use out of it 

1205
01:07:00,600 --> 01:07:02,320
and it costs money to use these 
things. 

1206
01:07:02,440 --> 01:07:05,200
So I, I think that's actually a 
very important area of 

1207
01:07:05,200 --> 01:07:09,640
cybersecurity right now is let's
say you have to burn, you know, 

1208
01:07:09,640 --> 01:07:12,440
$10,000 of tokens to secure a 
web application. 

1209
01:07:12,440 --> 01:07:15,640
Well, as we just talked about 
your, that there's budgetary 

1210
01:07:15,640 --> 01:07:18,000
problems there. 
What if you could combine it 

1211
01:07:18,120 --> 01:07:22,160
with a stack analysis tool or, 
you know, some kind of software 

1212
01:07:22,160 --> 01:07:25,120
that checks it and then you're 
down into maybe, you know, 4 or 

1213
01:07:25,120 --> 01:07:28,160
$5. 
It seems like that has to happen

1214
01:07:28,160 --> 01:07:30,600
because, you know, budgets are 
kind of an inherent constraint. 

1215
01:07:30,720 --> 01:07:33,520
I think a very good constraint 
for this field of, you know, 

1216
01:07:33,520 --> 01:07:35,400
defensive engineering and 
cybersecurity. 

1217
01:07:36,080 --> 01:07:38,240
Yeah. 
Well, and one thing to go back 

1218
01:07:38,240 --> 01:07:46,520
to like Dalton or I don't the, 
I'm the Chinese characters like 

1219
01:07:46,520 --> 01:07:49,680
the limited budget thing. 
I think this is just one thing 

1220
01:07:49,680 --> 01:07:52,720
you have to get used to. 
Like when you're a developer or 

1221
01:07:52,720 --> 01:07:56,880
is like entrepreneur building a 
platform, you have to do 

1222
01:07:56,880 --> 01:07:59,520
everything yourself anyways. 
So you have to like learn 

1223
01:07:59,520 --> 01:08:03,880
everything at a minimal, but 
enough to stay secure enough 

1224
01:08:03,880 --> 01:08:06,640
till you can afford a full 
penetration test or whatever 

1225
01:08:06,640 --> 01:08:09,600
you're doing, you know, and it's
a long road. 

1226
01:08:09,840 --> 01:08:13,240
And I've always had, I always 
had this hope like I'm going to 

1227
01:08:13,240 --> 01:08:17,000
find a magic person to help me 
with sales, blah, blah, blah, 

1228
01:08:17,279 --> 01:08:20,120
you know what I mean? 
And then you end up coming to 

1229
01:08:20,120 --> 01:08:24,439
the realization like I'm the 
only one coming to my rescue to 

1230
01:08:24,439 --> 01:08:27,960
find sales and customers. 
So you have to just do the thing

1231
01:08:27,960 --> 01:08:30,760
you don't want to do over and 
over. 

1232
01:08:30,840 --> 01:08:36,960
Continue eating glass until your
MRR is a number that you like. 

1233
01:08:39,120 --> 01:08:42,000
And the interesting point you 
make is that that doesn't change

1234
01:08:42,000 --> 01:08:43,880
as your as your company gets 
bigger. 

1235
01:08:44,640 --> 01:08:47,760
There's this phenomenon that a 
lot of people noticed when I 

1236
01:08:48,560 --> 01:08:51,840
believe it was Paul Graham, he 
published A blog post called 

1237
01:08:51,840 --> 01:08:55,640
Founder Mode, which was a big, 
the big term for a few weeks. 

1238
01:08:55,640 --> 01:08:59,439
I remember, which was even at 
big companies, a lot of founders

1239
01:08:59,439 --> 01:09:02,399
had this moment where they tried
to delegate things and just be 

1240
01:09:02,399 --> 01:09:04,880
totally hands off and then 
nothing got done. 

1241
01:09:05,040 --> 01:09:07,560
So then they got extremely 
involved, which is kind of 

1242
01:09:07,560 --> 01:09:09,680
derisively called 
micromanagement. 

1243
01:09:09,880 --> 01:09:12,840
But they found doing that made 
things happen again. 

1244
01:09:13,080 --> 01:09:17,240
So it doesn't change even if 
you're leading a big company or 

1245
01:09:17,399 --> 01:09:20,920
maybe you're you have a family 
or something, or you just you 

1246
01:09:20,920 --> 01:09:23,040
have a task at work or something
has to get done. 

1247
01:09:23,240 --> 01:09:27,120
And you realize unless you are 
actively really pushing for it 

1248
01:09:27,120 --> 01:09:30,200
to happen, you know, you can't 
just kind of rely on inertia. 

1249
01:09:31,359 --> 01:09:34,000
Maybe that maybe that's more 
true of life in general as well.

1250
01:09:34,520 --> 01:09:37,080
Yeah, there's no like easy coast
button. 

1251
01:09:37,080 --> 01:09:44,080
You're always going to be having
to hammer Bry J Bry makes a good

1252
01:09:44,080 --> 01:09:45,560
point. 
But like yeah, you never want to

1253
01:09:45,560 --> 01:09:49,319
dynamically create atoms either 
from like a user action. 

1254
01:09:50,399 --> 01:09:53,399
Oh, that's a big one. 
The the the reason I don't 

1255
01:09:53,399 --> 01:09:58,040
mention this one is I think it's
as, as you mentioned with the 

1256
01:09:58,040 --> 01:10:00,600
man in the middle thing, people 
kind of over index on it. 

1257
01:10:00,720 --> 01:10:03,840
Like I constantly get people 
asking me about this one and OK,

1258
01:10:04,400 --> 01:10:05,800
I actually wrote an article 
about it. 

1259
01:10:05,800 --> 01:10:06,880
We could put it in the show 
notes. 

1260
01:10:06,880 --> 01:10:09,160
I'll send it to you. 
It's on the paraxial blog. 

1261
01:10:09,160 --> 01:10:13,240
It's like the impact of Adam 
creation, just like let's say 

1262
01:10:13,240 --> 01:10:16,360
your Elixir app is host on EC2, 
like a Linux server. 

1263
01:10:16,640 --> 01:10:20,640
Just crash it in production or 
or dev, probably do it in dev 

1264
01:10:20,880 --> 01:10:24,480
production if you're brave and 
see if it restarts like it's a 

1265
01:10:24,480 --> 01:10:26,640
one liner. 
Just create a bunch of atoms. 

1266
01:10:27,040 --> 01:10:30,120
It's not ideal, of course, but 
in most vulnerabilities that 

1267
01:10:30,120 --> 01:10:33,320
I've seen with unbounded atom 
creation as well, you would just

1268
01:10:33,320 --> 01:10:37,760
send like one HTTP request per 
atom and it's like, OK, yeah, 

1269
01:10:37,760 --> 01:10:41,800
maybe if a bad guy really wants 
to like crash it and then you 

1270
01:10:41,800 --> 01:10:45,120
have 30, 30 seconds of downtime 
while it restarts, you know, it 

1271
01:10:45,200 --> 01:10:49,080
the, the risk there is not so 
much the the DDoS, which is 

1272
01:10:49,080 --> 01:10:51,600
real. 
It's make sure that it restarts 

1273
01:10:51,600 --> 01:10:56,880
because like, just like real 
scenario, a bad guy probably 

1274
01:10:56,880 --> 01:11:00,480
won't try to crash your Elixir 
app due to Adam creation there. 

1275
01:11:00,480 --> 01:11:02,480
There were some recent 
vulnerabilities unplug where 

1276
01:11:02,480 --> 01:11:06,160
that was a real issue, which is 
a little bit more important, but

1277
01:11:06,160 --> 01:11:08,480
I think they were mitigated by 
actually having like a like a 

1278
01:11:08,480 --> 01:11:10,920
load balance or cloud flare in 
front, which most people do. 

1279
01:11:12,840 --> 01:11:15,920
The reason your app will crash 
due to unbound atom creation is 

1280
01:11:15,920 --> 01:11:19,520
probably due to like a company's
AI bot these days, like a 

1281
01:11:19,520 --> 01:11:22,680
scraper or something and it hits
some code path where the atoms 

1282
01:11:22,680 --> 01:11:25,880
get created and then it crashes.
And then in that situation, just

1283
01:11:25,880 --> 01:11:28,480
make sure well, number one, you 
know, use practical to ban it. 

1284
01:11:28,520 --> 01:11:30,560
I got a plug in once during the 
show at least. 

1285
01:11:31,440 --> 01:11:35,920
No, but make sure that like when
it crashes, see if it restarts. 

1286
01:11:35,920 --> 01:11:37,440
And it's really simple to test 
that. 

1287
01:11:37,440 --> 01:11:40,640
So that that's what I would 
promote on the show is you can 

1288
01:11:40,640 --> 01:11:43,440
actually prepare for a situation
like that by kind of 

1289
01:11:43,800 --> 01:11:45,840
preemptively doing the attack on
yourself. 

1290
01:11:46,400 --> 01:11:53,080
Yeah, that's a good idea. 
Or just like don't use to atom 

1291
01:11:53,080 --> 01:11:54,800
from string or whatever the 
function is. 

1292
01:11:55,400 --> 01:11:57,720
I see it everywhere. 
Well the the big problem right 

1293
01:11:57,720 --> 01:12:00,600
now is that actually like this 
exact vulnerability showed up in

1294
01:12:00,600 --> 01:12:02,880
some Elixir libraries that 
everyone uses. 

1295
01:12:03,840 --> 01:12:06,960
So like well. 
I feel like it was just in. 

1296
01:12:07,680 --> 01:12:12,560
Was there one like decimal? 
There was another one that there

1297
01:12:12,560 --> 01:12:15,840
was another. 
What was the HTT cowboy? 

1298
01:12:16,320 --> 01:12:17,800
Was it cowboy? 
Yeah, there was one in, There 

1299
01:12:17,800 --> 01:12:21,440
was one in Cowboy and Bandit. 
And I should mention, I should 

1300
01:12:21,440 --> 01:12:24,760
mention Bandit because he's been
really great about fixing those 

1301
01:12:24,760 --> 01:12:28,400
vulnerabilities as well. 
Bandit has a a bit better 

1302
01:12:28,400 --> 01:12:32,200
performance as well if you're if
you're looking for which one to 

1303
01:12:32,200 --> 01:12:36,480
use. 
Yeah, I had to Google the limit 

1304
01:12:36,480 --> 01:12:39,240
of atoms 'cause I couldn't 
remember, but it you're had a, 

1305
01:12:39,560 --> 01:12:41,960
it's a million. 
Yeah, it's just over 1,000,000. 

1306
01:12:42,560 --> 01:12:47,360
But yeah, just don't. 
Dynamically kill yeah of of 

1307
01:12:47,400 --> 01:12:51,280
Alexei and Erlang. 
I'm actually surprised. 

1308
01:12:51,280 --> 01:12:54,160
Like, man, maybe I'm just not 
smart enough here. 

1309
01:12:54,160 --> 01:12:56,960
Why wouldn't we just have like 
some kind of automatic garbage 

1310
01:12:56,960 --> 01:13:01,560
collection for that? 
I'm not going to, I'm not an 

1311
01:13:01,560 --> 01:13:05,080
Erlang expert either, but I 
from, I've, I've talked to 

1312
01:13:05,080 --> 01:13:09,440
people in the working group and 
this is like a known issue in 

1313
01:13:09,440 --> 01:13:11,000
the Erlang development 
community. 

1314
01:13:11,000 --> 01:13:13,000
They've had proposals, they've 
looked at it. 

1315
01:13:14,280 --> 01:13:16,800
You know, it's kind of like 
asking, you know, why don't you 

1316
01:13:16,800 --> 01:13:20,880
just make a computer you can't 
hack and you know, everything it

1317
01:13:20,880 --> 01:13:25,000
seems so like, oh, just don't do
that, you know, but there's, you

1318
01:13:25,000 --> 01:13:27,320
know, there's there's people 
rely on Erlang for 

1319
01:13:27,320 --> 01:13:29,000
infrastructure and things like 
that. 

1320
01:13:29,000 --> 01:13:33,400
I'm sure the complexity is like 
so deep and I don't like fully 

1321
01:13:33,400 --> 01:13:35,760
understand it, but just don't do
it guys. 

1322
01:13:35,800 --> 01:13:38,760
Just don't use. 
String that that would be a that

1323
01:13:38,760 --> 01:13:40,040
would be a good guest for the 
show. 

1324
01:13:40,040 --> 01:13:42,560
Like a like a super deep dive 
into the beam. 

1325
01:13:43,000 --> 01:13:44,960
Dude, that would be cool. 
I'd have to. 

1326
01:13:45,960 --> 01:13:48,160
It would be good. 
I'd have to research a lot just 

1327
01:13:48,160 --> 01:13:50,360
to be able to have the 
conversation, which I guess. 

1328
01:13:50,360 --> 01:13:53,320
Is there's a book there's like, 
it's like the beam book, right? 

1329
01:13:54,760 --> 01:13:56,960
Like someone wrote an entire 
book just on the beam that I 

1330
01:13:56,960 --> 01:13:57,960
saw. 
That was pretty cool. 

1331
01:13:58,360 --> 01:14:05,520
That would be cool. 
Now I want to, let's see, pull 

1332
01:14:05,520 --> 01:14:06,320
that up. 
Yeah. 

1333
01:14:06,320 --> 01:14:12,680
The beam book. 
Steinman's Eric Steinman. 

1334
01:14:13,120 --> 01:14:14,640
See. 
I should have Eric Steinman. 

1335
01:14:15,600 --> 01:14:18,600
Yeah, Buy a copy. 
Buy a copy. 

1336
01:14:18,960 --> 01:14:23,000
That's actually really cool. 
I'm going to buy a copy or it's 

1337
01:14:23,000 --> 01:14:30,120
free too on dot org 
blog.steinmans.org but it's also

1338
01:14:30,120 --> 01:14:34,120
on Amazon. 
But we we support buying a copy 

1339
01:14:34,120 --> 01:14:35,960
as well. 
Buy a copy. 

1340
01:14:35,960 --> 01:14:40,120
You know, I always, I usually 
always try to buy books from 

1341
01:14:40,240 --> 01:14:44,640
authors because I just feel like
content creation is hard, so I 

1342
01:14:44,640 --> 01:14:48,280
will support them. 
I like having books too. 

1343
01:14:48,280 --> 01:14:52,920
I, because you know, I, I, I 
read a lot and I even like 

1344
01:14:52,920 --> 01:14:55,960
reading programming books on, 
you know, like, like when I have

1345
01:14:55,960 --> 01:14:57,960
the terminal, but I, I kind of 
like just owning a copy. 

1346
01:14:58,400 --> 01:15:02,000
You know, sometimes it's nice. 
Pass it to your children or show

1347
01:15:02,000 --> 01:15:05,680
it like it's good. 
See, I'm a big I love the Kindle

1348
01:15:05,680 --> 01:15:08,840
because I hate like, holding a 
book when I'm reading it. 

1349
01:15:09,080 --> 01:15:10,960
Oh, how do you like? 
Which Kindle do you have? 

1350
01:15:12,800 --> 01:15:16,280
I don't know the basic 1. 
I don't know. 

1351
01:15:16,280 --> 01:15:23,760
Let me see, just whatever this 
one is. 

1352
01:15:24,560 --> 01:15:26,240
It's not sponsored by Amazon, by
the way. 

1353
01:15:26,280 --> 01:15:27,560
The. 
Paper the paper Wyatt. 

1354
01:15:27,560 --> 01:15:29,000
I think it's just the paper 
Wyatt. 

1355
01:15:29,000 --> 01:15:33,520
I don't know, but I like it 
because like, you can travel 

1356
01:15:33,520 --> 01:15:36,640
with this and have thousands of 
books on it, you know? 

1357
01:15:37,440 --> 01:15:41,000
Yeah, I I read books on my phone
and I like I get hand cramps 

1358
01:15:41,040 --> 01:15:44,040
actually pretty frequently 
'cause I on my phone anyway, so 

1359
01:15:44,040 --> 01:15:45,960
I just. 
Like the phone is, it's an 

1360
01:15:45,960 --> 01:15:49,040
awkward hold, right? 
Like I feel like I don't, I 

1361
01:15:49,040 --> 01:15:52,320
don't know, get a Kindle dude. 
And it you don't fry your eyes 

1362
01:15:52,400 --> 01:15:54,320
as much. 
Yeah, yeah. 

1363
01:15:54,320 --> 01:15:56,040
Well, have you seen the 
technology now? 

1364
01:15:56,040 --> 01:15:58,680
People want to do E Ink for like
displays and stuff too I 

1365
01:15:58,720 --> 01:15:59,560
thought. 
That was pretty cool. 

1366
01:15:59,560 --> 01:16:01,400
I've been looking at some of the
phones. 

1367
01:16:01,400 --> 01:16:05,080
I'm like really tempted and they
have like some really cool color

1368
01:16:05,120 --> 01:16:09,600
E Ink stuff too now and it's 
like I'm tempted, but like I 

1369
01:16:09,600 --> 01:16:12,760
also just don't want to leave 
the the Apple universe because 

1370
01:16:12,840 --> 01:16:16,320
all my stuff is Apple. 
I don't know. 

1371
01:16:16,320 --> 01:16:17,240
Yeah, it seems. 
Like they should get. 

1372
01:16:17,240 --> 01:16:19,400
I feel like E Ink display would 
be more Apple like. 

1373
01:16:19,400 --> 01:16:21,040
They did the VR goggles for a 
while. 

1374
01:16:21,040 --> 01:16:23,120
There's a lot of hype and then I
haven't I haven't heard much 

1375
01:16:23,120 --> 01:16:26,920
about them recently. 
Yeah, I haven't either, but 

1376
01:16:27,080 --> 01:16:29,600
anyways, the beam book I could 
get on Kindle. 

1377
01:16:29,600 --> 01:16:32,400
I feel like the beam book would 
be a cool one to have though. 

1378
01:16:32,440 --> 01:16:35,120
You need that on your bookshelf,
especially just being put it. 

1379
01:16:35,360 --> 01:16:37,560
Put it in the background of your
streams for. 

1380
01:16:37,680 --> 01:16:41,160
Exactly. 
Erlang Land. 

1381
01:16:42,520 --> 01:16:48,240
I've, I'm buying it right now. 
And then I have to have Doctor 

1382
01:16:48,240 --> 01:16:53,360
Eric Steinman on. 
Yes, I'm going to have to reach 

1383
01:16:53,360 --> 01:16:56,840
out to him. 
I would be a cool guest after I 

1384
01:16:56,840 --> 01:16:57,880
read the book. 
So I'm not a. 

1385
01:16:57,880 --> 01:16:59,760
Complaint. 
I wonder if your chat has read 

1386
01:16:59,760 --> 01:17:00,600
it. 
I feel like there is. 

1387
01:17:00,720 --> 01:17:03,480
If there is any audience on the 
Internet that has read it, it's 

1388
01:17:03,480 --> 01:17:05,880
probably on this last. 
That's true. 

1389
01:17:05,920 --> 01:17:08,480
Anyone listening, have you read 
the Beam book? 

1390
01:17:09,520 --> 01:17:12,480
I'm really curious that'll. 
Browse through it. 

1391
01:17:12,960 --> 01:17:16,160
I I was actually, I was doing 
something with binary terms like

1392
01:17:16,160 --> 01:17:18,120
a security thing. 
I remember actually reading it 

1393
01:17:18,120 --> 01:17:20,880
because it's like how the 
deserialization format I think 

1394
01:17:20,880 --> 01:17:23,520
is actually covered in the book.
And then it's kind of like 

1395
01:17:24,400 --> 01:17:27,320
what's called nerd sniping where
it's something interesting. 

1396
01:17:27,320 --> 01:17:29,880
And whatever I was wearing, I 
ended up like browsing through a

1397
01:17:29,880 --> 01:17:31,360
few times like that's how that 
works. 

1398
01:17:31,360 --> 01:17:33,680
So that's why they did that. 
Or you know, like memory 

1399
01:17:33,680 --> 01:17:36,560
allocation Erlang. 
Like yeah, I'll see how that 

1400
01:17:36,560 --> 01:17:39,440
works. 
Yeah, well, I feel like, like 

1401
01:17:39,440 --> 01:17:44,800
I'm bad at, like, it's good to 
know the foundation of like, why

1402
01:17:44,800 --> 01:17:47,080
certain things in Elixir are the
way they are, right? 

1403
01:17:47,080 --> 01:17:49,200
By understanding how the beam 
works. 

1404
01:17:49,520 --> 01:17:54,480
And there you go. 
Is Paraxial a paid library like 

1405
01:17:54,760 --> 01:17:57,640
Oban? 
That's a good question. 

1406
01:17:57,800 --> 01:18:01,480
Yeah, go ahead. 
Yes, yeah, there's a free tier. 

1407
01:18:01,760 --> 01:18:04,280
Well, to use the Paraxial 
library, you have to have the 

1408
01:18:04,400 --> 01:18:06,520
software as a service. 
It's not a stand alone. 

1409
01:18:06,560 --> 01:18:10,120
It's sort of like there's Oban, 
which is the free open source 

1410
01:18:10,120 --> 01:18:13,720
and then Oban Pro it it links to
their software as a service. 

1411
01:18:14,720 --> 01:18:18,280
But the summary is you can use 
Paraxial for a free or like 

1412
01:18:18,280 --> 01:18:22,280
nonprofit, but if your 
application makes money in a in 

1413
01:18:22,280 --> 01:18:24,080
commercial context, you do have 
to pay for it. 

1414
01:18:26,000 --> 01:18:30,400
And you know, Praxial customer, 
it's usually a business. 

1415
01:18:30,400 --> 01:18:33,880
It's not something that like an 
individual developer usually 

1416
01:18:33,880 --> 01:18:37,040
buys because of the price and 
support overhead. 

1417
01:18:38,600 --> 01:18:41,280
I am very happy that the free 
tier exists and people can use 

1418
01:18:41,280 --> 01:18:43,920
it. 
The other thing is if, if 

1419
01:18:43,920 --> 01:18:46,400
security is very important and 
let's say you're just starting 

1420
01:18:46,400 --> 01:18:49,480
out like you have a new 
business, it is a commercial 

1421
01:18:49,480 --> 01:18:51,880
project. 
I actually think the open source

1422
01:18:51,880 --> 01:18:55,320
tools are very good because in, 
in my experience, I, I talk to a

1423
01:18:55,320 --> 01:18:58,080
lot of entrepreneurs. 
I, I love it when I get e-mail 

1424
01:18:58,080 --> 01:18:59,960
from them. 
Usually they don't really need 

1425
01:18:59,960 --> 01:19:04,800
Praxeal quite until the practice
started kind of found its fit 

1426
01:19:05,880 --> 01:19:07,600
and they've got revenue coming 
in. 

1427
01:19:07,600 --> 01:19:10,320
They can budget for the the 
software. 

1428
01:19:11,520 --> 01:19:13,640
So you know, if you're watching,
I'd love to hear from you. 

1429
01:19:13,720 --> 01:19:16,080
If you're an Elixir dev, I'm 
always happy if you go on the 

1430
01:19:16,320 --> 01:19:18,720
Praxial home page and click book
a demo. 

1431
01:19:18,720 --> 01:19:20,120
It just goes right to my 
calendar. 

1432
01:19:21,880 --> 01:19:24,480
But that's kind of the the 
scenario with Paraxial is the 

1433
01:19:24,800 --> 01:19:28,040
the paid product. 
You sort of have to be a 

1434
01:19:28,040 --> 01:19:30,880
business in order to really get 
the full value out of it. 

1435
01:19:38,450 --> 01:19:44,090
Oh man I'll I was trying to find
Eric's diamond on on X but I'm 

1436
01:19:44,090 --> 01:19:48,240
struggling. 
Might be on LinkedIn, I think I 

1437
01:19:48,240 --> 01:19:49,440
saw some posts from him on 
there. 

1438
01:19:49,840 --> 01:19:52,120
All right, cool, I'll track him 
down. 

1439
01:19:52,600 --> 01:19:54,920
My ADHD hit in the middle of a 
live stream. 

1440
01:19:56,040 --> 01:19:59,080
I bought a book and was. 
Searching for him that's. 

1441
01:20:00,360 --> 01:20:03,680
Great. 
Oh, and now he's asking paraxial

1442
01:20:03,680 --> 01:20:08,880
versus SOBLO, which I feel like 
you use SOBLO in paraxial, 

1443
01:20:09,040 --> 01:20:10,920
correct? 
Yeah, that's a great question. 

1444
01:20:11,080 --> 01:20:16,000
So I'm also a contributor to the
SOBLO open source project as 

1445
01:20:16,000 --> 01:20:17,480
well. 
And that's really good because 

1446
01:20:17,520 --> 01:20:19,480
I, I, people often ask me about 
this. 

1447
01:20:19,480 --> 01:20:23,200
They say like, well, why does 
Paraxial like use SOBLO as part 

1448
01:20:23,200 --> 01:20:28,360
of the, why don't you fork it or
do your own like soblo plus 

1449
01:20:28,360 --> 01:20:30,160
plus. 
And that never made sense to me 

1450
01:20:30,400 --> 01:20:33,840
because people don't buy 
paraxial as a slightly better 

1451
01:20:33,840 --> 01:20:36,440
version of soblo. 
You know, if you need a stack 

1452
01:20:36,440 --> 01:20:39,880
analysis tool and your budget 
is, you know, it could be 0, 

1453
01:20:39,880 --> 01:20:42,680
could actually be a very high 
budget, you know, SOBLO serves 

1454
01:20:42,680 --> 01:20:45,160
that market very well. 
It is the open source stack 

1455
01:20:45,160 --> 01:20:49,720
analysis tool for Elixir. 
The reason people buy Paraxial 

1456
01:20:49,720 --> 01:20:52,360
is very different. 
It's you are a business and you 

1457
01:20:52,360 --> 01:20:55,080
need to make sure your software 
does not get hacked. 

1458
01:20:55,360 --> 01:20:57,560
And that is different from a SAS
tool. 

1459
01:20:57,680 --> 01:21:01,640
The scope and the needs and the 
support are very, very 

1460
01:21:01,640 --> 01:21:03,280
different. 
You know, Praxial is like a 

1461
01:21:03,280 --> 01:21:06,920
suite of features and stack 
analysis is one part of that. 

1462
01:21:07,520 --> 01:21:09,640
Enriching the SOBLO findings is 
part of it. 

1463
01:21:09,920 --> 01:21:13,720
But I never thought, you know, 
oh, I'm going to make like a 

1464
01:21:14,040 --> 01:21:16,680
fork of SOBLO with like better 
support. 

1465
01:21:16,920 --> 01:21:20,400
I, I think that actually my 
contributions to SOBLO 8 Elixir 

1466
01:21:20,400 --> 01:21:22,280
adoption. 
So you could argue that that 

1467
01:21:22,280 --> 01:21:25,560
that does benefit Praxial 
because of more businesses use 

1468
01:21:25,560 --> 01:21:27,160
Elixir. 
You know, I have a larger 

1469
01:21:27,160 --> 01:21:29,880
customer base, but I think it 
aligns very well with the 

1470
01:21:29,880 --> 01:21:32,240
community. 
I, I really love open source. 

1471
01:21:32,920 --> 01:21:36,520
I think Jose and Chris have been
very, very strong supporters of 

1472
01:21:36,520 --> 01:21:38,960
open source. 
So, you know, it's natural that 

1473
01:21:38,960 --> 01:21:41,280
I would be a developer and in 
that sense as well. 

1474
01:21:45,960 --> 01:21:49,160
I am already connected with Eric
Simon on LinkedIn. 

1475
01:21:49,400 --> 01:21:52,400
Perfect. 
You like already chatted with 

1476
01:21:52,440 --> 01:21:53,160
him? 
That's beautiful. 

1477
01:21:53,160 --> 01:21:56,760
I haven't chatted with him but 
we are connected so that's good.

1478
01:21:56,760 --> 01:22:00,720
One step closer. 
Well The funny thing is like, I 

1479
01:22:00,720 --> 01:22:04,200
don't know, my memory is trash 
and I have like I meet so many, 

1480
01:22:04,280 --> 01:22:07,640
IE meet so many people, it's 
hard to like keep track. 

1481
01:22:08,360 --> 01:22:09,840
Yeah, we've never read in 
person, have we? 

1482
01:22:10,040 --> 01:22:13,880
No, we haven't. 
I was gonna try to go to Chicago

1483
01:22:13,880 --> 01:22:16,680
this year, but I don't think. 
It's yeah, yeah, I'm planning to

1484
01:22:16,680 --> 01:22:19,600
go to and if anyone, if anyone's
watching, I know it's really 

1485
01:22:19,600 --> 01:22:21,800
awkward when like you go to a 
conference and like you see 

1486
01:22:21,800 --> 01:22:24,120
someone you know, online, but 
you're like, how's it like 

1487
01:22:24,120 --> 01:22:26,080
weird? 
If I go up and please come up 

1488
01:22:26,080 --> 01:22:27,520
and talk to me, like I won't get
upset. 

1489
01:22:27,600 --> 01:22:28,640
I'm not. 
Always. 

1490
01:22:29,600 --> 01:22:31,440
Yeah, I know. 
It's like a little weird. 

1491
01:22:31,440 --> 01:22:34,640
You're like, oh, like I kind of 
know you, but like, you've no 

1492
01:22:34,640 --> 01:22:36,600
idea who I am. 
But like, I've, I've watched 

1493
01:22:36,600 --> 01:22:39,040
like hours of your footage or I 
saw you on the podcast. 

1494
01:22:39,200 --> 01:22:40,840
Please give up to me. 
That's why I go to the 

1495
01:22:40,840 --> 01:22:43,720
conference. 
You know, what's hilarious is 

1496
01:22:43,880 --> 01:22:49,400
people like, like when I was 
down, I went to Austin for Mike 

1497
01:22:50,080 --> 01:22:53,760
Hessler or not Mike Hessler, 
Nathan Hessler's, Nathan 

1498
01:22:53,760 --> 01:22:58,880
Hessler's conference, and people
don't recognize my face. 

1499
01:22:58,880 --> 01:23:01,760
They recognize my voice when I'm
talking in a group of people. 

1500
01:23:01,920 --> 01:23:03,680
They're like, I know that. 
I. 

1501
01:23:03,720 --> 01:23:05,880
Know that voice? 
And I was like, oh, that's 

1502
01:23:05,880 --> 01:23:08,520
hilarious. 
And but yeah, it's always good 

1503
01:23:08,520 --> 01:23:12,640
to meet people. 
OK, Bry J Bry, he's asking, does

1504
01:23:12,640 --> 01:23:16,040
paraxial certify stuff like Sock
2 and HIPAA? 

1505
01:23:17,320 --> 01:23:22,880
Oh, that's a good question. 
So no, like cybersecurity tool 

1506
01:23:22,880 --> 01:23:27,080
can actually do that because 
those standards are actually a a

1507
01:23:27,080 --> 01:23:30,960
more complicated kind of set of 
controls that you have to show 

1508
01:23:30,960 --> 01:23:33,920
compliance with. 
Sock 2 is a good example. 

1509
01:23:34,120 --> 01:23:37,880
So for example, when you do a 
SoC 2 audit, you're actually 

1510
01:23:37,880 --> 01:23:41,440
being evaluated by ACPA, it's an
accounting firm that you have to

1511
01:23:41,440 --> 01:23:44,560
hire and then you have to show 
that you've done these security 

1512
01:23:44,560 --> 01:23:47,320
controls. 
And it's, it's a bit confusing 

1513
01:23:47,560 --> 01:23:51,960
because you can actually have a 
Elixir application that is 

1514
01:23:51,960 --> 01:23:56,200
totally vulnerable and it's 
going to get hacked and 

1515
01:23:56,200 --> 01:23:59,480
completely pass SoC 2 because 
it's basically a spreadsheet 

1516
01:23:59,480 --> 01:24:02,000
that says, did you implement 
this control, yes or no? 

1517
01:24:02,200 --> 01:24:05,480
Well, do you have like a process
to triage vulnerabilities? 

1518
01:24:05,480 --> 01:24:07,720
Yes or no? 
You can do all of the compliance

1519
01:24:07,720 --> 01:24:12,760
items to the letter in a way 
that sincerely fulfills every 

1520
01:24:12,760 --> 01:24:16,120
single line item and just be 
totally not secure because 

1521
01:24:16,120 --> 01:24:18,880
they're kind of different things
that there is like a Venn 

1522
01:24:18,880 --> 01:24:22,800
diagram overlap where you should
use SoC 2 to actually improve 

1523
01:24:22,800 --> 01:24:25,840
your security because you're 
kind of doing the work anyway. 

1524
01:24:25,840 --> 01:24:28,440
It makes a lot of sense, but 
they're sort of different. 

1525
01:24:29,240 --> 01:24:34,280
They're entirely different sets 
of like kind of sets of things. 

1526
01:24:34,400 --> 01:24:38,200
So for example, like a using 
paraxial will fulfill several 

1527
01:24:38,200 --> 01:24:42,200
controls like static analysis or
runtime analysis. 

1528
01:24:42,400 --> 01:24:45,640
Do you have a a runtime guard 
that blocks an exploit? 

1529
01:24:45,880 --> 01:24:47,640
Are you keeping track of 
vulnerabilities? 

1530
01:24:47,800 --> 01:24:49,840
Are you keeping track of the 
scans you do? 

1531
01:24:49,840 --> 01:24:52,520
Like how are you communicating 
them to the management? 

1532
01:24:52,680 --> 01:24:57,320
You know Paraxial helps with all
of that, but it is not the same 

1533
01:24:57,320 --> 01:25:00,840
as Praxial saying like you are 
sock 2 certified because that's 

1534
01:25:00,840 --> 01:25:03,440
actually impossible. 
Praxial isn't an accounting 

1535
01:25:03,440 --> 01:25:05,520
firm. 
I think some cybersecurity firms

1536
01:25:05,520 --> 01:25:06,840
are actually trying to do that a
bit. 

1537
01:25:06,840 --> 01:25:10,680
But I I'm very much on the kind 
of like, I like that the real 

1538
01:25:10,680 --> 01:25:15,200
hacking stuff. 
We should also do a shout out to

1539
01:25:15,200 --> 01:25:18,840
XMEX, which is the Austin 
conference that Nathan runs. 

1540
01:25:18,840 --> 01:25:20,880
If you're, if you're listening, 
go on. 

1541
01:25:21,440 --> 01:25:24,120
Well, you'll put in the show 
notes, but it's xmexconf.com and

1542
01:25:24,240 --> 01:25:27,480
sign up for the newsletter. 
I feel like it's a good that's a

1543
01:25:27,480 --> 01:25:30,880
good plug for your audience. 
And it it, yeah, it was such a 

1544
01:25:30,880 --> 01:25:35,160
good conference too. 
Like I'm a big fan of going to 

1545
01:25:35,160 --> 01:25:37,800
small conferences 'cause you get
to meet everyone that's there 

1546
01:25:38,120 --> 01:25:40,040
like. 
I was disappointed I couldn't 

1547
01:25:40,040 --> 01:25:42,360
go. 
Yeah, you chat in between, you 

1548
01:25:42,360 --> 01:25:45,200
know, all the talks and you 
just, you know, you meet people 

1549
01:25:45,200 --> 01:25:49,120
that like, I know a ton of 
people in the Elixir community, 

1550
01:25:49,120 --> 01:25:50,960
but like you don't get to meet 
them in person. 

1551
01:25:50,960 --> 01:25:54,280
And then you can finally get to 
and you just can chat about the 

1552
01:25:54,280 --> 01:25:56,760
coolest stuff and all the 
projects people are working on 

1553
01:25:56,760 --> 01:25:59,320
and it's a lot of fun. 
How? 

1554
01:25:59,320 --> 01:26:01,000
How was the conference like? 
How did you think it was 

1555
01:26:01,000 --> 01:26:03,360
organized? 
I thought it was really good. 

1556
01:26:03,360 --> 01:26:06,960
I was like less hopeful that I 
was going to really enjoy the 

1557
01:26:06,960 --> 01:26:09,440
talks, but all the talks were 
awesome. 

1558
01:26:09,440 --> 01:26:14,200
Like Nathan did such a good job.
And then like, yeah, the hallway

1559
01:26:14,360 --> 01:26:18,440
talk was way was like awesome. 
Just like connecting with 

1560
01:26:18,440 --> 01:26:20,560
people. 
I think it's important for 

1561
01:26:21,320 --> 01:26:25,160
developers especially to get to 
conferences because we kind of 

1562
01:26:25,160 --> 01:26:28,800
stay siloed in our own work and 
at our own computers. 

1563
01:26:28,800 --> 01:26:31,560
And I feel like it's good to to 
network that way. 

1564
01:26:32,160 --> 01:26:36,360
Like met a handful of Apple 
developers and just it's cool A.

1565
01:26:38,160 --> 01:26:41,160
100%, yeah, yeah. 
Thank you so much for having me 

1566
01:26:41,160 --> 01:26:44,360
on today. 
This was a great conversation. 

1567
01:26:45,000 --> 01:26:47,840
Hopefully we see each other in 
person at Elixir Comp Chicago. 

1568
01:26:47,960 --> 01:26:50,960
If anyone listening can attend 
to, I'd love to meet you as 

1569
01:26:50,960 --> 01:26:53,000
well. 
I think you're doing a great job

1570
01:26:53,000 --> 01:26:56,320
with this whole project. 
It's been fantastic for Elixir 

1571
01:26:56,320 --> 01:26:59,640
adoption and for the community 
to come together and talk about 

1572
01:26:59,640 --> 01:27:01,760
what they're working on. 
It's been a lot of fun and 

1573
01:27:01,760 --> 01:27:05,720
what's funny is so for everyone 
that doesn't know, Michael was 

1574
01:27:05,720 --> 01:27:10,560
my very first guest as well. 
So if you want to see like the 

1575
01:27:10,560 --> 01:27:14,280
worst performance ever would be 
our my first podcast episode. 

1576
01:27:14,280 --> 01:27:16,880
It was still good. 
It was good content, right? 

1577
01:27:16,880 --> 01:27:19,720
But like you can tell like 
whenever you do something brand 

1578
01:27:19,720 --> 01:27:22,760
new. 
And now I think it is it almost 

1579
01:27:22,760 --> 01:27:24,080
three years ago. 
No. 

1580
01:27:24,080 --> 01:27:27,480
Two years ago 2. 
It's getting up there, yeah. 2 

1581
01:27:27,480 --> 01:27:31,720
1/2 years ago, but yeah, Michael
was my first guest and my first 

1582
01:27:31,720 --> 01:27:34,600
sponsor, which is pretty cool. 
Thank you. 

1583
01:27:34,760 --> 01:27:37,160
And it's been a fantastic 
partnership. 

1584
01:27:37,160 --> 01:27:38,440
And yeah, I'm happy to be back 
on. 

1585
01:27:38,440 --> 01:27:40,360
I love coming. 
Yeah, it's cool. 

1586
01:27:40,440 --> 01:27:43,920
We'll have to make sure. 
I mean, I feel like, like we 

1587
01:27:43,920 --> 01:27:48,240
stay in touch enough that like 
when, when there's, when it's 

1588
01:27:48,240 --> 01:27:50,320
time, I don't know, we just 
connect again. 

1589
01:27:50,840 --> 01:27:52,240
This was this was the right 
moment. 

1590
01:27:52,240 --> 01:27:54,960
This was a good one. 
It was it was a good moment and 

1591
01:27:54,960 --> 01:28:00,120
like seeing that just all the CV
ES hit and all the I don't know,

1592
01:28:00,360 --> 01:28:03,840
I think that that stuff like I 
joke about being annoyed about 

1593
01:28:03,840 --> 01:28:06,880
it, but it's really cool to see 
like all these vulnerabilities 

1594
01:28:06,880 --> 01:28:10,600
get discovered very easily and 
like corrected. 

1595
01:28:11,520 --> 01:28:15,840
Yeah, the work that Peter, 
Jonathan, the Hex team, really 

1596
01:28:15,840 --> 01:28:18,800
all all of the people that had, 
I should actually mention the 

1597
01:28:18,880 --> 01:28:21,600
maintainer specifically because 
a lot of people have these 

1598
01:28:21,600 --> 01:28:24,480
vulnerabilities reported to them
and then it's on the maintainer 

1599
01:28:24,480 --> 01:28:27,080
to fix them. 
And that's a huge amount of 

1600
01:28:27,080 --> 01:28:29,040
work. 
And you know, maintainer is 

1601
01:28:29,040 --> 01:28:32,200
often, you know, it it's a 
struggle because it it is more 

1602
01:28:32,200 --> 01:28:34,800
work for the maintainer. 
Yeah, it does benefit the 

1603
01:28:34,920 --> 01:28:39,760
ecosystem where now everyone is 
more secure that's using Elixir.

1604
01:28:40,520 --> 01:28:42,840
So if you are a maintainer, 
mention that on your resume. 

1605
01:28:43,000 --> 01:28:47,400
I would say that you are 
keeping, you know, thousands by 

1606
01:28:47,400 --> 01:28:50,360
10s of thousands of businesses 
doing billions and billions of 

1607
01:28:50,360 --> 01:28:54,640
dollars in transactions. 
And not even just commercial, 

1608
01:28:54,640 --> 01:28:57,760
but, you know, hospitals, 
governments, non profits. 

1609
01:28:57,960 --> 01:29:00,560
There's so much critical 
infrastructure that Elixir runs 

1610
01:29:00,560 --> 01:29:02,600
on. 
If you're maintaining a library 

1611
01:29:02,600 --> 01:29:05,560
and fixing security 
vulnerabilities, that is 

1612
01:29:05,760 --> 01:29:08,240
extremely important and you 
should communicate that. 

1613
01:29:08,360 --> 01:29:10,640
I agree. 
When and talk about yourself. 

1614
01:29:10,920 --> 01:29:13,760
And since I've started like 
doing recruiting and like 

1615
01:29:14,200 --> 01:29:17,280
looking at a lot of like coding 
projects and things 'cause I 

1616
01:29:17,440 --> 01:29:22,040
like do the pre vetting right? 
The code from the project is 

1617
01:29:22,040 --> 01:29:25,080
even less important than like 
things that you've already done.

1618
01:29:25,160 --> 01:29:29,240
And like, open source is a huge 
one that people love to see 

1619
01:29:29,600 --> 01:29:31,560
like. 
Yeah, it'll be like a little 

1620
01:29:31,560 --> 01:29:33,040
line. 
I'm like oh by the way I do this

1621
01:29:33,040 --> 01:29:34,520
little library. 
And have yeah, no that. 

1622
01:29:34,560 --> 01:29:39,080
Should be emboldened. 
Yeah, you, you are writing code 

1623
01:29:39,080 --> 01:29:43,520
that like businesses run on top 
of that is extremely impressive.

1624
01:29:43,520 --> 01:29:46,680
Yeah, well, 'cause like one 
thing that I'm seeing too is now

1625
01:29:46,680 --> 01:29:50,400
like over engineered solutions 
that are just all clearly be 

1626
01:29:50,400 --> 01:29:55,480
written by AI and they're almost
instant disqualifiers because I 

1627
01:29:55,480 --> 01:29:57,280
don't want to 1. 
I don't want to look through 

1628
01:29:57,280 --> 01:29:59,880
that much code anymore. 
And it's just like, no, I want 

1629
01:29:59,880 --> 01:30:03,080
to see how you implement it. 
I don't want to go like you're 

1630
01:30:03,080 --> 01:30:10,360
not going above and beyond 
adding like, I don't know what's

1631
01:30:10,360 --> 01:30:15,520
a word I'm looking for like a, 
like an analytics dashboard on 

1632
01:30:15,520 --> 01:30:18,280
top of a project. 
Like people are adding like 

1633
01:30:18,320 --> 01:30:22,240
extras to like a core like I, I,
I just want to know that, you 

1634
01:30:22,240 --> 01:30:24,960
know, Elixir and understand OTP,
that's it. 

1635
01:30:26,320 --> 01:30:29,760
In some ways that's the hardest 
part is I think everyone 

1636
01:30:29,760 --> 01:30:31,920
probably listening to this call 
has struggled with this problem 

1637
01:30:31,920 --> 01:30:35,400
is what should I work on? 
Yeah, yeah. 

1638
01:30:35,800 --> 01:30:41,640
No easy answer the specs, dude, 
But yeah, thank you so much, 

1639
01:30:41,640 --> 01:30:43,040
Michael. 
This is awesome. 

1640
01:30:43,720 --> 01:30:50,040
You guys can find Michael on X, 
he's paraxial IO and then 

1641
01:30:50,120 --> 01:30:54,280
paraxial dot IO is his website 
and it's always it's always 

1642
01:30:54,280 --> 01:30:55,960
awesome having you on. 
Thanks so much. 

1643
01:30:56,720 --> 01:30:58,640
Thank you if you've been 
watching, thank you for 

1644
01:30:58,920 --> 01:31:00,920
listening to me. 
Feel free to reach out. 

1645
01:31:00,920 --> 01:31:03,560
If you watch this stream and you
just want to chat, I would love 

1646
01:31:03,560 --> 01:31:05,480
to hear from you. 
Yeah, sounds good. 

1647
01:31:05,560 --> 01:31:07,840
All right, everyone have a good 
weekend and I'll see you next 

1648
01:31:07,840 --> 01:31:10,960
week testing.
