Distinguishing between movement and progress, in AI, security, and more
44m 39s
The transcription begins with a personal reflection on finding joy and prioritizing human connections despite a demanding career confronting dark aspects of humanity. It then shifts to a podcast episode featuring Ryan Clark, CSO at Black Rifle Coffee Company. The hosts discuss the AI model Claude Methos, which some claim could cause a "software apocalypse" by finding and exploiting vulnerabilities. They express healthy skepticism, viewing the hype as potentially driven by marketing and a need for the AI industry to justify investments. They argue that core security issues stem from a lack of basic practices like patching and effective organizational response, not a lack of advanced threat detection. The conversation critiques the cybersecurity industry's tendency for alarmism and notes that large companies, not open-source maintainers, often get early access to such tools. Finally, Clark describes his innovative, integrated security program that combines physical, cyber, and crisis management to eliminate gaps and improve decision-making.
Because the job I've had and even though it's still we are literally observing the worst parts of humanity, right? The worst shit there is stuff that just Rubbs you a burns you out internally burns out my soul man like seeing it But it also gives me the perspective of like you know what actually matters is As I should I need to feel joy all day. I can't be you know part of the organization or the enterprise that stops this bad shit And then let that ruin me. I cannot let what that happened and I can't let my kids see that like oh Daddy Fats bad guys on the internet and he comes home and he's just you know Regions terrible or yeah, or I have to compensate for that by like, you know Let me get this expensive watch which is totally fine I mean people should treat themselves if you got it go for you can't take you with you but like None of that matters man none of that matters people matter people matter so much and people you know Is my angelic people remember how you made them feel right so I love investing in my time and people Yo, it's Baronuckles and brass tax. This is the tech podcast about humans. I'm George K I'm George a and Today our guest is Ryan Clark who is the chief security officer at black rifle coffee company He joined us right after getting off the plane and we want to tackle some Topical issues and get into I guess more philosophical issues So I guess the most obvious thing is we talk a little bit about Claude Methos and the supposed impact it has on cybersecurity But then we go way Left field and get into some more stuff on the innovation side that Ryan is a part of and then also the culture that he builds on his teams Yeah, I really appreciate it like Ryan and I you know go back a few years and then It's actually an interesting friendship with him. I met him on a can a US seesaw exchange in Ireland all things and You know he's always in the kind of guy that stood out to me because he's a brilliantly smart guy who comes from a very blue color background I think we've come from very similar backgrounds and It's kind of nice in industry when you meet your spirit animals and then he's definitely one of them and you know he lives it and I Think if you have the pleasure of ever knowing him or working with him person hopefully this episode Primes people up to see that there are awesome people still in this industry doing great things and if you get a chance to Work with Ryan or again involved in any of his projects. You really should go for it Ryan Clark welcome to the show Yeah, man. Thanks for inviting me. It's great to be here. I'm super tired for all his travel But yeah, man, thanks for making it work Yeah, absolutely. I am also exhausted and recording from a hotel room So the travel fatigue is real and then you know tourist doesn't sleep. So we got that too. That's true All right, Ryan well you are Head of security seeso all this at black rifle coffee company which you know more power to you death before decaf but We have you on to dispel some myths. So let's set the table Some of our audiences in cyber some is not You know, there's this big hula baloo around Claude's mythos model, which is apparently Quote unquote unsafe to release to the public because it is so good at finding and chaining together vulnerabilities It threatens what some might say is a software apocalypse Others have said is a lot of hot air So why don't we start there? Let's get your thoughts on it. Where do you think it? Oh, man, you know, it's funny because the the idea of me though, so wherever it was that there is gonna be some Some apocalypse to capability that comes out is gonna see everything and Daisy chained together all these lows and mediums and Information holes into always critical stats been We're talking about for a while right What was gonna be called is it even now like is it happening now? I don't know is it happening in six months? But I think it's funny because everyone Yeah, like you use some words right now like the apocalypse, right? Man, I see a whole lot of really strong language being used that's like yeah, there's definitely something to consider But all of it's really the same problems we've had right? It's the same basics in the end whether it be some big changes in how I think all software is or compiled if If these capabilities are true. Yes You could think suck for a while for us as this kind of gets out there Maybe you know, however things have sucked for all of us before as practitioners, right? I think that it's I think either way though if it's true or not that this mythos capabilities gonna find the smallest or the hardest to find vulnerabilities and Then take advantage of them Then just it's if it's true. Just just plan for it now. And if it's not true plan for me from a year from now Yeah, but like probably like I mean You like I you know, we we we spun up this conversation thing because you saw I just you know, I was George was saying one of my sleepless nights working on side projects because like clearly that's what I do and I hate myself I was literally just taking it taking a to get a biobake if you will As just scrolling through and I just got so pissed off at the the grift because like every every Man, okay, cool whatever if we had trouble so be it like every loser that I see in like tacking and cyber Who just looks for like something to talk about because they have nothing relevant in their actual career So they're sitting there all day post about dumb things like they start talking about this thing like it's it is the doomsday Right and you're like well guess what AI was supposed to be the dooms day and then you know What was it like all these zero days were supposed to be the dooms day and you know There's always something new and at days and I'm not saying that you know someone capable couldn't take something like that and Weaponize it and you know like you have the case of like the petches and not patches which turn into like global spread Right which at the end of the day all rely on an inability or Enterprises public private commercial academic whatever to do Basic fundamental security which is patch management which is vulnerability management which is basic log monitoring Which is basic reporting which is basic visibility and understanding what's in your environment components and segmentation and BCDR and all the things that you know you go through the Stupid or the other paid absorbent amount of money to maybe learn from a boot camp and get a shirt on or you just do the job and you figure out Oh, how do I not get poned right and I think we just And like look even open AI and it's like look the open AI response and George. I love to hear you talk about this because like Sam ultman You know blessed Sam ultman the So he comes out like a week later or whatever he's like oh we have our model that super powerful Merr and Merr I'm like bro nerd rage elsewhere no one cares Like seriously. Yeah, so I think You are correct healthy dose of skepticism right? So I'm gonna point out I worked for a startup that was trying to train social engineering detections early days using GPT-2 and If everyone recalls open AI also tried to say that GPT-2 was too dangerous to release Obviously that was not true or they didn't heed their own warnings um I just think There are a lot of things happening at the same time one is the fox watching the henhouse Who does it be who to say that you have developed things that are so powerful that you know Watch out Uh, it would be the people trying to invent the everything machine and I say that as somebody who likes and uses clawed but like that's some strong marketing from Anthropic um, and then the other thing is uh as count newport recently pointed out When they pointed some open source open weight models at these same projects like open bds which is um a open source Operating system used in firewalls for our audience Those models also found the same vulnerabilities. So is it like the uniqueness of mythos or is it literally the ethos and mythos being created around me ethos um, I think maybe Ryan it's more like The four-minute mile as a as a close friend Connor Sherman just put it here's like it was bound to happen That's kind of the watershed is the time maybe But you know llem's for searching for bugs and code is not a new thing No, I I just think of it this way like so if like George what you said earlier about this sold to basics of what you must do and all that I think people are also forgetting to talk about the I don't know alleged positive this about this saying hey they When this gets released and it is doomsday Uh at the same time with it will be a capability that also helps prevent that Help stop that maybe I don't mean be on being old to uh idealist no no say say more. I mean I think
like Marcus Hutchins and KCLS former guest on the show have said the same thing that we all, we seem to overweight in the adversary thinking and not like, hey, what if defenders also have this? - Yeah, it could help, but I think what's funny though is it's not gonna solve the problem that gets on our way anyway right now. The problem isn't, can I see what's wrong? Like the whole industry and cyber is happy to sell us things that will observe what's happening. None of it. Well, not none of it. A lot of it does not orient it to, what does it mean to me? And giving that information so we can go get the decision done, whether that be with me, if my team has agency to go take care of it or another stakeholder in a way that they can say yes, go do this. And then we act, 'cause we know we know we're looking for, we know we see it, we know a little bit of what it means to have business or organization when we have to go and patch this thing or take that down, we don't always know. And we certainly know what we need to do to get after it. We must go patch this thing. We must get a compensate control for that. So I don't think that problem is gonna be solved still though. The decision point. Do you have enough information orienting to your organization so that you can go and do it as fast or, I was asking so many this week, like what do you think this is gonna look like in your daily life when, if all this is true, if it's all true, okay? You think it gonna be unlike emergency patch calls all day? Is that what it is? And you think you're gonna be like saying things that we already sound hyperbolic, right? When we show up with numbers and all the crap we deal with. But are you gonna be like, we have to patch it right now? Well why not tonight? Because we have minutes. Like I don't know, man, it's just the students day of you, I've seen other people and I'm like, dude, you know, I don't know that's gonna be what the reality is. And I'm more confident in our skill set to innovate. Like we've come up with some pretty good technology to solve a lot of these problems. And I think you're gonna see the scrappy innovators come with some stuff to less than the blow if it is a blow, right? Well, the other thing too, man, like I think, I think, you know, it's kind of like the whole, like, sex sells bad new sells and media, right? So like, I think everyone gets hyped up about, the adversary is gonna do this and do that. I'm not saying that there aren't, like, capable adversaries or nation state actors aren't gonna try to weaponize it, right? But at day's end, like, I think there is a lot more, positive progress that is really gonna be made out of this, as a capability set, once it gets trickled down into solutions that the rest of the mainstream market can use outside of project class swing or whatever. And, you know, I just, I think it's a case where, whenever, like, those global compromises happen, it's almost dumb luck. It's not necessarily intentional. Like, nation state actors and major cybercrime groups, trying to pull off global scams every day, every day, right? And the ones that succeed, the ones that really, really hit is like, once every like five to 10 years, right? And, and to your point, Ryan also, like, sometimes we get it right, like, you know, log for Jay threatened to do all the bad shit on Christmas. And there was a massive sort of community swell in that direction and, you know, fortunately, no, like, huge things went. - You know, when you and I were at Defcon, and we met that dude, like, actually found like the original log for Jay got it, found it. - Yeah. - He asked him, and he was like, oh yeah, it was by accident. So even, he was discovering the remediation was by accident. - Yes. - Well, I think about this too, like, to your point, George, about after log for Jay, or any other ones that boiled the planet, right? We did respond, but later, and we did an after action that we were like, oh shit, we need something for this. And then even, like, even everything I saw, the, I won't call it vaporware, but I will certainly call it like the marketing rush companies, I saw it, are safer of AI, observability, enforcement tools. Like, those are a response. And I remember when, when, you know, at Generv AI, like, was first coming out, we're talking about it, right? I mean, I don't know, George, how many times we say, in a room, we would like to stop talking about this guys. Please stop. But then the market responded with some technology, right? Is this, I don't know, I'm not saying, 10-File Hat Conspiracy Guy here, 'cause that's totally not what I'm saying, but this is a podcast, so hell, you have to say it. Is this all just saying, listen, this type of thing will come eventually. Maybe it's not happening right now. Maybe it's not, but historically, we need to build the defenses way too late, right? Do we need to build them now? Well, I think we have an AI industry with a lot of big players who have sunk a lot of money, a lot of investors money, and it's created something of a bubble because there isn't an actual tangible ROI for all the resources wasted in the infrastructure and, you know, kind of the initiatives built. So it would make sense to me to create a need for suddenly purchasing a whole bunch of AI-driven solutions which are modeled off of the same companies that built a model like Mythos. Well, yes, and so one comment and then the question. So the one comment that I forgot to include to your point, George, about people just popping off about whatever is, despite being an analytical industry, cyber is still made of humans who fall prey or have been warped by social media habituation. Oh, I need to comment on something. Like, no, no, you don't. I mean, I saw the glass wing announcement. I saw that and I was like, I do not, I have a feeling I do not understand the nuances of this. So I do not need to comment on that. Yeah, I, it built to me. I saw it, I was like, oh, you are assembling the justice league or the eventors, and I do believe in all the right things. Like, I don't know. And those are the same companies that in dark room as we call the evil empire. So, so yes, so to that point and to George's point, I thought, I don't know if you guys saw Raffi Cacorian, the CTO at Mozilla had an op-ed in the New York Times, which was saying, look, if this thing is going after, it's so powerful, it's going to undermine a lot of the open source components that underpin everything, right? Open BDS and firewalls, I think you pointed out to another piece of open source software that is pretty much behind all streaming online, all these open source projects that are maintained by developers, but the people who got invited into private glass wing are these multi-billion dollar companies. So they get first access to supposedly the thing that is very good and protective, and not the independent developers upon whom people have built, again, billion dollar companies. Right, and so I thought his point was like, the better rollout would be, we know who the developers are, we know who the people who've poured hours into maintaining these projects are, why are they not being invited in to help be the protectors if they're the ones maintaining the software? I don't know, I thought that was a good democratization point. - I just don't know that those big companies that are part of it, or stuff, I don't really know what they're actually doing, but as this, hey, they're just getting together to talk about it. They're getting together to ideate on what we should do next to answer the question, use kind of post, like, hey, how do you push this out and in response to what everyone else, so it's helpful and not destructive? I hope that's what they're doing. I honestly don't know. And part of me, the part of me it's been-- - I mean, hopefully, I think they're supposed to be using the preview of the tool to go hunt and find the bones first and fix them. - I would, I would think-- - I hope. - I would think it's to help them as like the key players in the economy to obviously clean up their own vulnerabilities, but I think there's a backdoor deal for, you know, certain ones of them is to create new software offerings and services. - Yes. - A thousand percent. - And I think there's a deal to share revenue with Anthropic, right? And OpenAI, they're gonna try doing the same thing. It's really all just about generating new revenue instead of investment to justify the spend it's taken to build the infrastructure that they have done so without actually assuring a customer-based need for it. - Yeah, I think that's the rub. Is that behind it all, there's still a rush to market that they all have as an agenda. The rightfully, so their businesses don't get me wrong. I'm all about that. But that's, I think that's the thing. It's like you're giving it to who to do this. The guys who have all the money already. - Yes. - Okay. - Okay. - So the ones who have all the money and have all the vulnerabilities like, it's like, - Are we talking about Microsoft and Cisco and Palo, like, they just come on. - Yeah. Yeah, man, it's a lot of hype. - Oh, man. (upbeat music) - Well, okay, so let's get off of meet those and let's change tack and talk about. You said innovation earlier and building. Do you wanna talk a little bit about, I guess the approach that you're taking inside your teams
to do some innovation around, I think, what people would take for granted as accepted practice? - Oh, well, yeah, I think that's the best way to describe this. So our program, our street program, is by intentional design we started, physical, and cyber, and crisis management. And now safety, slip and fall, so don't fall, please. But the intentionally was all that the physical cyber combined because in our experience, I visualize like a bunch of circles that are bend diagrams, and each circle is the responsibility area of, on the physical security leader, I'm the cyber leader, and there's always other circles around it that are like, I'm the marketing person, I'm illegal. And where are the biggest problems I've ever seen? The areas where they either overlap or don't overlap, in terms of responsibility or tellments taking it, it's almost like a, you know, you could like it, it's like a seam in the clothing. Okay, that's where the bad guy's going. You go and take advantage of yourself. Look at fraud. Fraud happens everywhere security is not gonna be. It's so funny, 'cause it's just why we be there. Every other stuff's to worry about. So we design a program to be flexible, so that when we have to make decisions on these things that are becoming more and more cyber enabled, that hey, we have the technology and information together right away, the decision has already been decided. So anyway, that was like our starting ethos, and it's worked out. It's been about four years, we've been building it out. And then so we looked at the, I don't know, man, I guess I'll call it the pain or what life experience, I guess, of working with Sims and trying to get at a global company where we were out before, really big one where we had just data from 110 countries, so much stuff to try and pull together. And like any detection, it's monitoring, it's action logic. And then we have these partners to, I'm gonna call them that, I'm gonna call them partners a little P, and Simp providers who are kinda like these boat anchors, and it's a disingenuous partnership. It's not about they, they, you're buying something for an outcome, but you're being charged for like every step of the sausage making. And it's crazy, it's just no good, doesn't help, and they don't innovate that much. I wish they did more. So we've taken a bunch of strategies where I look, what's the complete control of all budget imagery internally? And as far as, mostly can't externally. And so we, we didn't go in like a build around Sim, like a bunch of mad scientists, 'cause that's stupid. That's not sustainable, but you can get the components of it. And you can do that, you can do it in a way that's where you can keep data longer, you can analyze it faster, you can save money, but not saving money because I'm all about being a money saver, it's 'cause I got other stuff to do, man. Like we have other stuff to use those resources for. And instead of just storage costs. Yeah, storage costs or analytics. So we've done something that we presented on it a couple of years ago at the RHI SAC, something where we said, hey, look, this is what we think we're gonna do in terms of building it out, or you're on data pipelines and storage and like S3, and then some basic analytics in advance. And we said it was a theory though, even at the time, we didn't have any contract signed with any vendors. In fact, we were still figuring it out. We said, hey, we think this can be done. And so we just sort of follow up this last Tuesday, showing what we did. That's another conference, two years later. Hey, we actually built this and we learned a lot, really cool things and we were able to be very flexible and innovative and iterate quickly with other technologies we would normally have. Like, you know, if you want to do a POC or a bake off of a company, you may only have cycles as you want or two. Or if you could do five or six or seven 'cause you have your data control, you can move it around. So it's been fun. We're still building it and now we're building it all really around this decision management because we think that's still the barrier going forward and everything and security is, you know, there's gonna continue to be tools to come out that will again help us observe what's happening. But we need to get the right information or the right context or language to deliver it to the people who help us make decisions. So like, you know, I can't go and talk to, well, some people can but going and talking like a chief marketing officer like a USFO, that's not really, that's not it. We all, all the C-Sows are being trained to be business whispers, right? Like, oh, speaking the business is language. And you should, you should love your brand or whatever you do. But there's also a point where it's like, man, I can only say that so much. And some people who are stakeholders, I'm not gonna talk that way to them. There's no way. There's no way. Doesn't make sense. - Well, I think again, at the end of the day, like having to break silence was kind of like our job as C-Sows, like, you have to, you have to be a bit of an interpreter to every different type of department that you speak to. But like, ultimately, like, just quote unquote, speaking the language of business, it's understanding, okay, like, what exactly do I need to address from a need standpoint for you to get in line with what I actually need you to do, right, like, how do I sell the thing the directive I need you to do? So it's not like I'm forcing you to do it. It's like, hey, we're aligning on an opportunity to do what you need to do to meet your KPIs in a way that protects our data and protects our brand and protects our environment and protects our customers and our employees, et cetera. And I think that's where the interpretation comes in. I'm wondering from what you're saying though, like, are you guys planning on packaging this up and selling it as some kind of a solution or are you going to open source the learning and the discoveries of the framework? And just, and I hope you do this 'cause it'd be the most punk rock thing ever. Just release it to the wild and fuck with all those overpriced scene providers and platforms and all that shit and show people that there's a way to get value and capability without having to spend, you know, potentially millions of dollars to do it. - We actually did that before. In fact, the first time we presented on it, you know, as a vendor, you can sponsor a talk at a, I said, they didn't know what they were sponsoring us. I'm not gonna say their name 'cause I do love them. There's been a lot of good for the world. I just don't like some of the practices they do, okay? It was funny. They got really mad at us, one of these vendors, like really mad, like, and told us how wrong we were and you know, like, I'm trying to think of a terrible sci-fi movie where there's some like human being that gets a parasite and they go, oh my God, let's get it out of them. And then they start trying to get this parasite of a human being and the parasite starts moving and fighting back. It means like, oh, we must be doing something good at turning it. That's what we experienced from one of the providers, the same providers. It was like three years of my life. They were just escalating things inside my company and making my life hell. Because we just talked about, hey, there could be another way. Not this is the way, just, there could be more versions of right guys. So yeah, we've done that with a couple of people and a couple of really big companies, like huge ones, like, yeah, a big, big one. So we're like, hey, I got this big bill. I want to get off it, but I'm scared. And everything we did, we didn't develop most of the stuff. That's what I'm saying is, it's off the shelf things you can do, but people are just kind of, you know, people get a lot of stakeholders and a lot of things, not people that got to make happy, right? And self-preservation is a pall of a motivator, right? So like, I'm not sure we can do this. Or we'll have the meat that SLA's for enterprise requirements that I have. Well, I hit my compliance requirements. And so we've demonstrated that not only can you, you can do it very, very well with, like, little to no effort. So yeah, we're going to, we're keeping giving it. We're showing anybody. So anybody wants to see it? We'll sit down and call with them. Heck, even this is improbative. We did it for a couple of them, explained to them what we're doing. And one of them had one of their people come on, who is now a good friend of mine. And they thought he was the heavy hitter. It was going to come in and tell us how wrong we were. And he said, oh, these guys don't need us. They got to figure it out. Damn. That's hard core. That's awesome. It's cool. It's cool. I just, you know, we liked the challenge we thought of when we're doing this was, you know, there are so many small teams who don't look around and compare themselves to the big teams. Well, like man, like man, I cannot have those things. I cannot have a big sim or a sock or an MSS P or any of that. And so then I can't defend really. And then just demoralize because every day, they're still trying to do all the right stuff. And we're like, look, what, what happens of a team of small small team can do it? Because technically, technically, we have two guys in cyber. Because I don't count because I don't actually work. I just talk a lot. And so to show that, hey, we're able to defend to off some pretty impressive attacks for once in a while. But we know about things and we have good control. It's cool. It's cool to be able to show that, hey, we can do that. And we did some other things too as our program around, like, I won't say for obsec standpoint, but, you know, we did a bunch of things around like deception right away. And not because people think a deception is like some, I don't know, need to get to this level of maturity to do it. And I get it because they follow a gardener and everyone else says, these are the steps you'll do these things. I mean, Ryan, this feels like, it feels like we just talked about falling into these mental traps being habituated or acculturated into like the social media. I feel like what you're saying is the same thing is true of, you know,
security professionals, they just kind of fall into the stream and then inertia takes over. And it's all like, well, this is the way it's been done. I guess I got to go by this thing because I bought this thing at the other place. Well, and it's because people too, like I remember George, I'm going to talk about this that people believe that there is a sequence of investments you must do and that it defines success. We're not success on the outcomes, but it's also funny because people are slinging capabilities and it's not, it's, it's like a CISO who's maybe worked for two years. Like that's considered success. That's crazy because how are you getting things strategic done? So it's the difference between progress, like progress versus just movement. Like, hey, am I going forward towards an issue or am I just kind of dance around the same spot doing the same thing? A lot of the business leaders don't know how to assess us as CISOs. And they're like, well, that guy that looks like he's doing things or buying stuff and there's really big numbers coming out to their block it must be good, you know? And even the standards for measuring us, like the ones that you get trained on like at NACD, they're like their doctrine, their curriculum they train on is behind a little bit. And they know that. So those people or board members are getting these training and it's not reality. Not keeping up. George, what do you want to say to that? I feel like I dig this entrepreneurial vibe and I don't know how we lost that. Well, I think what I really love is like going back to a sense of community, which is I think the most important thing where like, you know, right in the end of this team have like found a way to genuinely solve a problem, which has been created by what I think is like the hyper proliferation of profiteering and excessive solutions in our industry. And so, you know, going back to the roots of this thing, which is again, a lot of open source, providing a solution that can help organizations who don't have millions of dollars to spend on securing themselves find a way to get the most out of the money they do have, other resources they do have. I think that's real thought leadership. I think that's real industrial leadership. But like, like, like, like, like, Joe, I'm in joking around, you know, this whole episode or whatever, but like, like in all seriousness, like, like I have a world of respect for Ryan, he has a lot of really good things. He works at a tough environment to manage. And, you know, I'm proud to see what you've built. And I'm hopeful that there are more people like you and that you'll inspire the people who have the competence, the technical competence, the operational experience, the charisma, the convince other people like, "Hey, I have this idea. Let's try this out." Because I think we are in such an obsessive, profit-driven industry in the world where we celebrate these announcements of like, "Oh, I got a bazillion dollars in my seed round. Celebrate me." And then watch these clowns, like, go party in limos and Vegas and stuff. That's not what it is. I mean, you've built something I think you can be genuinely proud of. And it's just we are. What's cool, though, man, is like, and, you know, I don't take any credit for it. I'm just a guy that talks about my team is just badass. And we've been together a lot of us been together like 10 years. So we've got trust as like, you know, that's hard. And we have it. But what's really cool, and I'll say this about Black Rifles and organization. And this is, you know, these are my opinions, whatever, all that stuff. But this is true is that because of the nature of the military background of our founders and our leaders who were the soft guys in particular, you know, innovation is survival for them. And there are, you know, a lot of times you guys are out doing missions and stuff. We're there out alone or out and far away without a lot of support. And you got to figure out a way to make it work and innovate. And it's, you know, it's not crazy if it works, right? And so we have, we're given that leeway to also take risks and to be innovates one of our, our actual core values of our company, one of the six values. And we're given that ability to because if you look at like, I can look at like some of the technology and equipment and military, the doctrine and stuff that exists now would say common in Western militaries. I'm just going to say Western because sorry, sorry, not friends right now countries. Sorry, friend of me. You look at like what is commodity that a regular soldier, marine airman guardian, whatever might get? At one point, it was a very fringe advanced capability used by special ops. And then it became commodity after they iterated on it enough and then someone said, oh, shit. So that's what the difference is between, hey, you just had like an M16 and then, you know, a one or a three and then that evolved into Oh, and M4, Oh, and M4 all this shit on it, this extra 15 pounds of equipment that I'm sure everyone wants. But like, hey, do we do these regular soldiers need a red dot? Do they need a gangster grip? Do they need these, you know, suppressors? So that, that whole cycle of how that works, right? And how it historically worked because of our organization, we're able to do that. We're able to say, hey, we're, we're, we're making the next thing because what we have right now is, is, it's good, but it's not good enough. And to keep that edge. So I'm really thankful that we have that opportunity to do it. And it's funny, man, like, when you find like the, I must, I hate to say the vendors because I don't like using that term on them, but like when you find the real people who are building a product and they're looking for someone who's like, Hey, I want to help you build it. I want to break this shit along the way consistently. So where we like to be that team is like, Hey, well, I'll be in there really open to it. A lot of them. We have one partner right now we work with who are coming up stealthing a little bit and I'll plug them because I'm, it's not, I don't have to plug anybody when it's the truth. You know, it's easy called, they're called ocean security. And these guys, they're really, they come in as an email of security vendor, which is, you know, that's a hard new mouse trap to create, man. Like, it's pretty hard. Yes, we threw, we threw out, and what we're pretty heavy on are forward on our email security. And we threw out one of the leaders that people right now and will always rave and recommend me because we found that their feedback loop internally was broken. They're entering feedback loop was broken. And they admitted it. Yes. I love that you highlight that because I tell founders sometimes I was like, you, probably won't lose on tech. You'll lose on service delivery and cycle time to iterate and of it. It's gotta, it's gotta come back. You're gonna be able to quickly learn what's going on, especially now, especially now. You gotta be able to very quickly apply those lessons in seconds, minutes, right? Not, it can't be weeks and months anymore. Or they can't promise it on the roadmap and then not deliver it. Yeah. Yeah. I guess it's not the speed of which is going. So these guys at ocean have been, man, it's one of the first times we've been having a hard time keeping up with them. Right. So cool. So cool. They're gonna be dominant force. I know it. Anyway, and they're good human beings though, like for real. So I, I love seeing that though. When we find people real or like, hell, yeah, let's go make this. All right. All right. Let's go. So let me ask you this then, I guess kind of close it off. Like, you've done some really cool stuff. And you know, I think it's an incredible kind of movement you're part of and kind of start. And I think it's quietly as like, this feels like a quiet revolution if you will forget all that though. Like, you're a super cool dude. And I think, you know, people need to understand like, what is generally your outlook on life? Because I think you, unlike a lot of other people I know, a lot of the receipts, I don't know a lot of other folks. I know they get to the C suite level, they bring that C suite money, they live a lot of flash. They love showing off. They love, you know what I mean? Like big house, big cars, vacation, all that noise. You're a, you're a blue color dude and you remain a blue color dude. I think why I love you. What is your kind of overall outlook on life, especially given like where you started, you know, as a troupe. And where you are now as an executive, you know, probably one of the best companies in America right now. Yeah, I mean, I was lucky to have really good mentors who like had manned been through it, who instilled in me like, Hey, what mattered? Like took the time to really focus on things that tell me that matter to them. And some of them are very successful like, like, you know, financially and all that. I mean, I look at like the, what's the best way to say this? I look at time, right? It's times I want to say I can't buy right now unless mythosism is fucking time machine. But so I'd rather like get experiences and stuff. And so like, like Georgia, what you're saying, like I've lived what like five places since you've known me. I just moved to some tiny ass town in the middle of nowhere for like house to cost no money. I lived in, I lived, I put everything I owned in storage when my family for a year to live in a 200 square foot apartment in the, in the middle of forest, the mountains, just to see like, what's this like? Can we do this? Right? It's funny. But now when we moved into a house again, as I'm taking on stuff out of storage, I don't need any of that stuff. It had, it has literally zero to do with my happiness. And I think you only get that perspective. That's from anyways, my, my, my, my, my wife and I talk about all the time is like, because the job I've had and even though it's still, we're literally
observing the worst parts of humanity, right? The worst shit there is. Stuff that just rubs you, burns you out internally, burns out my soul, man, like seeing it. But it also gives me the perspective of like, you know, what actually matters is, as I need to feel joy all day. I can't be part of the organization or the enterprise that stops this bad shit and then let that ruin me. I cannot let what that happened. And I can't let my kids see that. Like, oh, daddy fads bad guys on the internet and he comes home and he's just, you know, - A rich, yeah. - terrible. Or I have to compensate for that by like, you know, let me get this expensive watch, which is totally fine. I mean, people should treat themselves. If you got it, go for it. You can't take it with you. But like, none of that matters, man. None of that matters. People matter. People matter so much. And people, you know, my angelic people remember how you made them feel, right? So I love investing in my time and people because that is far more rewarding. That's what I had kids. It's the same thing. It's so rewarding to see it in like, in the industry, see it with other vets that we get to interact with. Like, dude, this is so awesome. And that's, I can't measure that, you know, in a number or dollar sign. I don't think it should be. So like for me, it's just try to be a good human being and then use the time I have, the time or anything. Use it really well. So that is a, no, but that's a perfect place to wrap 'cause we're not gonna get any more positive than that at this hour at least. So Ryan, thanks very much for jumping on, especially just as you got off a plane, really appreciate the time. - I appreciate you guys. I appreciate you guys doing these. Like, it's real talk, which you guys do on these podcasts, which has needed a lot. So, I think we're really bad at faking it. So this is the only avenue we have. - That's actually it. - Hey, I'm just saying it's a good sign of character when you suck at lying or being full of shit, right? So. - Yeah, bro. - All right, man, we will talk to you soon. - All right, yeah, I appreciate you guys. (upbeat music) - All right, so questions to take forward, question the hype. Be interested in AI, but don't believe everything you hear. I guess my question to you is how are you gut checking a lot of the noise? Because if you just kind of fall into the inertia, it really stops you from thinking critically about the issue. What is the incentive of the argument that I am hearing? And am I just kind of throwing my weight because I'm impressed with the cachet or whatever of the person who's telling me. You do really have to keep questioning what you hear. - Yeah, and I think I think too is to, you know, are you following your good instincts, right? Whether it's career path decision, your employer where it needs to do or if you're a leader in charge of a program being pressured and pushed by a vendor to make a purchase or make a decision. Does it really align with how you want to run your program and how you want to contribute to your part of the business? I mean, the way I see it, people need to start learning to trust themselves better because when they do and they don't let whoever the person is in front of them, just influence them. I think that's when we go back to starting to make good decisions again. And, yeah, I think this episode really hammered down. - Nice, all right, take this forward. We will see you next week. (upbeat music) If you like this conversation, share it with friends and subscribe wherever you get your podcasts for a weekly ballistic payload of snark insights and laughs. New episodes of Baron Arclad and Brass Tax drop every Monday. If you're already subscribed, thank you for your support and your swagger, please consider leaving a rating or a review. It helps others find the show. We'll catch you next week, but until then, stay real. (laughing) - I don't think we got drunk for like a week in Ireland. It was sweet. - I mean, I won't confirm I'm gonna deny that, but yeah, probably. (laughing)
Podcast Summary
Key Points:
The speaker's work exposes them to humanity's worst aspects, which is draining but provides perspective on what truly matters: people and joy, not material possessions.
The podcast discusses Claude Methos, an AI model rumored to be a cybersecurity threat capable of chaining vulnerabilities, but the hosts express skepticism, viewing it as hype and a potential marketing ploy rather than an imminent "apocalypse."
They argue that fundamental security practices (patch management, visibility, etc.) remain the core issue, and that both threats and defenses will evolve with AI, but the real problem is often organizational decision-making, not just detection.
The conversation criticizes the cybersecurity industry for hype, social media-driven commentary, and potentially excluding open-source developers from early access to defensive tools while favoring large corporations.
The guest, Ryan Clark, shares his innovative approach to security at Black Rifle Coffee Company, integrating physical, cyber, and crisis management into a unified program to address seams where threats typically exploit.
Summary:
The transcription begins with a personal reflection on finding joy and prioritizing human connections despite a demanding career confronting dark aspects of humanity. It then shifts to a podcast episode featuring Ryan Clark, CSO at Black Rifle Coffee Company. The hosts discuss the AI model Claude Methos, which some claim could cause a "software apocalypse" by finding and exploiting vulnerabilities.
They express healthy skepticism, viewing the hype as potentially driven by marketing and a need for the AI industry to justify investments. They argue that core security issues stem from a lack of basic practices like patching and effective organizational response, not a lack of advanced threat detection. The conversation critiques the cybersecurity industry's tendency for alarmism and notes that large companies, not open-source maintainers, often get early access to such tools.
Finally, Clark describes his innovative, integrated security program that combines physical, cyber, and crisis management to eliminate gaps and improve decision-making.
FAQs
Claude Mythos is an AI model that some claim is 'unsafe to release' because it is highly effective at finding and chaining together software vulnerabilities, potentially leading to a 'software apocalypse.' However, skepticism exists about whether its capabilities are overstated.
Ryan Clark sees it as exaggerated hype, comparing it to past doomsday predictions in cybersecurity that didn't materialize. He emphasizes that fundamental security practices like patch management and monitoring remain more critical than fearing new AI tools.
AI models like Claude Mythos could also help defenders by identifying vulnerabilities faster and improving prevention efforts. However, they don't solve underlying issues like decision-making and organizational response speed.
Skepticism arises because large companies may be using such initiatives to create new revenue streams or software offerings, rather than genuinely addressing security. There's concern that independent developers maintaining critical open-source software are excluded from these efforts.
His program intentionally combines physical security, cybersecurity, and crisis management into one flexible framework. This design helps address overlaps and gaps where threats like fraud often occur, improving decision-making and response.
He points out that the industry often focuses on observing problems rather than providing actionable insights for decision-makers. The real challenge is orienting information so teams can act quickly, such as patching or implementing controls.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.