Loading...
Loading...

Psst, how'd you like to listen to DotNet Rocks with no ads?
Easy, become a patron.
For just $5 a month, you get access to a private RSS feed where all the shows have no ads.
$20 a month will get you that and a special DotNet Rocks patron mug.
Sign up now at patreon.netrocks.com.
Hey and welcome back to DotNet Rocks.
I'm Carl Franklin and I'm Richard Gavill and Michael Howard's here with us will have him
jump in if he wants to in the beginning and introduce him a little bit later after the
first bits.
You know what those are.
Here we go.
Here we go.
2020.
It's episode 20 when we're all done, right?
This ends in 20 after 2026 so we got like six more of these and it's becoming less and
less interesting because most people have lived through the last six years.
It's so current.
Yeah, it's kind of now.
Especially 2020 because of course, what can you talk about except COVID?
Oh my God.
COVID.
All right, I'm done, Richard.
What about some things are playing?
Well, the other thing I would talk about is that's when the UK officially leaves the
EU like, oh, there's greatest.
There's more news, but COVID is the big one.
George Floyd is the big one.
Yeah.
Um, you know, big, big reaction to that that sparked off a lot of stuff.
Joe Biden beat Donald Trump.
Yes, there I said it because that's the truth worldwide.
Economic collapse caused by COVID lockdowns.
Yeah, it's just stall.
It was just horrible.
Donald Trump was impeached for the first time all in the first year.
I was the end.
A lot of wildfires in Australia and Western US, the terrible ones.
Here's a story you probably don't know about and now and today it's really relevant.
In September, the second Nagorno-Karabakh war.
So this is between Azerbaijan and Armenia.
This is an enclave that normally is controlled by Armenia, but the Azerbaijanis wanted it
and they attacked.
And so the Ayurveda, by John, they're the ones with the oil money and their Muslim,
the Armenians are predominantly Christian.
The Azerbaijanis attack and to be clear, this is a very complicated conflict.
It's gone on the dirty for centuries.
But it was a drone war.
It was arguably the first drone war.
The Yaris-Ibrahim-Rajani's bought Turkish-Berakatar drones.
They bought some of the surveillance equipment from the Iranian, from the Israelis.
And so they had continuous surveillance.
They were using drones for attack.
They destroyed missile sites and so forth.
They destroyed the Armenians for fighting the old-style with Soviet equipment and just
got rolled over.
You'd think the Russians would have taken a hint watching their stuff be torn up by drones
in 2020.
Instead, they got a lot of drones.
Well, they did eventually.
But first, they got hit pretty hard.
Anyway, it was only six weeks.
That doesn't change the fact that a lot of people died.
It did result in the fall of the region and the change in the environment over there.
But it's just a precursor conflict.
We saw an example.
Of course, it was COVID.
There was all the things going on at that time in that year that nobody was paying attention
to it.
A couple of other notable deaths in 2020, Ruth Bader Ginsburg, what a blunder.
Yeah.
Kobe Bryant.
Yeah.
The helicopter accident.
And good trouble himself, John Lewis.
Right.
Dad said we're right, Tycon.
Yeah.
It was just a bad year.
A bad year.
Tough year.
Do you want to know what happened in space?
There wasn't any time.
But this is an important one.
In February, solar orbiter launches.
You don't really know much about this one.
This was a joint ESA NASA mission in that order.
It's really much a European mission with NASA, instrumentations, and they provided the
Atlas V as well, but it was built by Airbus.
And its goal was to get a view of the poles of the sun.
Normally, you're launching your spacecraft because the Earth's in the plane of the ecliptic,
your spacecraft are going to be as well, trying to get to high inclinations very, very difficult.
Of the Galovat high, they'll fly down into a looping orbit inside the orbit of Mercury
and then use Venus to do the slingshots and repeatedly tip the spacecraft.
So it is about 24 degrees off the pylonytic ecliptic.
Takes a ton of energy to do that.
They borrowed lots of energy from Venus, but it's a one ton spacecraft.
So you can do that.
But it will get us our first visual views of the poles of the sun.
Cool mission.
Yeah.
That is cool.
First crew dragon demo mission.
So this was Bob Benniken and Doug Hurley go up to the space station and demonstrate that
the commercial spacecraft can actually go to the space station properly.
And that will be followed up in November with a regular crew flight of four astronauts
to crew the space station.
So there you go after, this will be nine years since the Atlanta has landed and the
only support for the station was VSO used.
Now the Americans had a vehicle again in the former crew dragon.
I got a question which Michael might know the answer to, but you said issa and NASA
did this thing together in 2020, but Brexit was in 2020 was was Britain part of issa in
2020.
Did they participate?
No, that's not issa.
Yeah, it could be wrong, but I didn't think so.
Especially Germany France.
Yeah, okay.
It's Airbus, it's defensive space.
All right.
July the perseverance rover.
So this was the test article for the original curiosity rover with a bunch of upgraded things,
their wheels, better suspension, new instruments, the ingenuity helicopter, all of that stuff
gets launched in July.
July is the perfect time to launch to Mars July 2020.
There's a there's a synchronicity to the orbits right there in a two three period.
And so every, you know, roughly two years you get a chance to do much flights.
So July there's actually three.
There's the perseverance rover which is huge.
There's also China's very first mission to Mars, Tianwen one.
And then the UAE, the United Airmen's launches their hope climate orbiter to Mars.
So three launches in the same month.
Wow.
Did they all make it in October?
The US made it.
They all make it.
Yeah, actually.
Very cool.
And I mean, I'll talk more about the Tianwen one when it lands next year, so in episode
2021, because that was China's first attempt to go to Mars and it fully worked.
Nobody's pulled that off before.
Everybody loses a few trying to get to Mars.
Name it.
Everybody does, but China didn't.
But you know, the advantage of being, I don't know, fourth or fifth mover or something
like that.
In October, Osiris Rex, one of the asteroid missions, touches on asteroid Bennu and collects
a sample there.
In fact, it does a little too well because when it touches, Bennu is very much a rubble
pile and all that gravel goes everywhere.
And they actually have trouble closing up the sample container because there's too much
stuff.
They have to come up with such technical maneuvers as shaking a little off to try and get
the thing closed up so they can put it in the capsule to return.
Another asteroid mission at the end of the year in December, high of Usa 2, will actually
successfully return its sample payload from the asteroid Riku, and that is a jack submission.
A little recap on what SpaceX did in 2020.
There was actually 25 launches from SpaceX, which at the time was an amazing number.
Just remembering that SpaceX will do 150 this year.
So obviously, the two crew dragons, the test run in March and then the real, the full payload
in November, they'll also fly 14 star-linked missions, 833 satellites for a network of almost
a 900 by the end of the year.
Have you ever seen the Starlink satellites leaving the spaceship?
Yeah.
It's like pizza boxes going out.
Yeah, yeah.
Well, now they've gotten bigger because of the V2 minis and so they only fly like 24 or
28 of them depending on the inclination, but at this time, they're flying 60 a run.
That's great.
Wow.
Just these huge numbers of satellites.
And that's where they also, this is the year where they have the reflectivity problems.
Oh, right.
And so you can see them for an extended period of time until they learn how to orient them
and paint them correctly so they're not so visible and don't bother people so much.
Yeah, remember there was a bunch of astronomers that were complaining they were polluting the
night sky with their telescopes.
Yeah.
Still in the issue, although let's say the digital processing can fix that, right?
But making bright lights make it worse.
So making sure it doesn't reflect sunlight helps.
I've seen them though.
I've seen the trail.
Go across and it's pretty fascinating and a little bit, I don't know.
You know, SpaceX does some things that if you weren't paying attention, you'd think we're
being invaded by aliens.
Well, or you know, or Dr. No is in full swing.
Like the line between supervillain and tech billionaire is getting very narrow.
People don't know like, you know, the first time that I saw the booster rocket spinning,
you know, when it, yeah, I thought I thought it was like a spaceship.
And so did a million other people until I found, oh, that's just SpaceX.
That's what they do.
And what are those lights going?
Hey, is that Santa Claus?
No, that's the SpaceX.
Yeah, I use, I use Stellarium and it'll show you all the SpaceX.
Yeah, it's something that's waving around.
I know.
Must be my Facebook friends.
Here are a average intelligence or ability to look things up.
Only 10,000 plus of them by the end of this year.
Just saying, you know, there'll be a bunch of other missions as well, including a couple
of GPS satellites.
So also start doing their starship flights, the hop tests, and the first what they called
belly flop test, where they fire it up to a few kilometers up and then let it fall on
as belly suit.
They could actually land it.
That was SN8 by the end of 2020.
It does not go well, but they'll solve that and prove that this whole idea is even possible.
All right.
Shall we move on to computing?
Yeah.
My idea, we've definitely come into other techniques from there, but this paper is kind
of the stimulus for what will be the insanity coming in the next couple of years.
Yeah.
A January is also in Microsoft switches over to Chromium as they're rendering engine in
the new edge browser.
The pandemic's in full swing and marches when lockdowns really kick off and everybody
goes home and everybody's got Zoom teams explodes for better or worse.
But a little thing I paid attention to was the Terry Breton, who is the EU internal market
commissioner, reached out to Netflix and YouTube and Amazon Prime and asked him to turn
off all the 4K features.
He was concerned about the amount of available bandwidth across Europe as everybody went home
and used the internet differently.
Does it actually a crisis?
Nobody knows for sure or releases not talking about it.
They start turning up the bandwidth again in May and Netflix's posts about this are interesting
because they talk about network changes and increasing capacity and things like that.
So maybe there really was a crisis because of the change in the internet consumption due
to COVID, but a lot of details aren't revealed necessarily.
But that to me was very interesting.
April is when Uncle Satya says, two years worth of digital transformation in two months
because everybody had a hard work lately.
This is when I started doing true running as a week, just talking about topics around what
was necessary for Siss admins during where everybody was working from home.
My brother is a programmer at a local company.
He's been there for years and years and they basically do online vehicle registrations.
They were the first in the area to do it.
And their customers are states, not individual sales places, dealerships.
But anyway, they were renting an office building and an office park out here.
I'm team billion square feet and during COVID people went to work at home and I just remember
Jay coming to rehearsal once and said, well, I've resigned myself to the idea that I'm
never going back to the office.
And they basically moved out of the office.
Yeah, lots of stopped renting it.
And I think in general office space took a big dive.
Oh, it goes out of that.
2020.
You make about all the property that Microsoft gave up in Bellevue.
Yeah.
They kept their buildings in Redmond, but all that rent is based in Bellevue.
What do I, and all of it went to Zoom.
Yeah.
Well, to teams, the first virtual build in May is also when they do the full release of
Blazer WebAssembly.
Yeah.
Obviously, a bunch of other cool announcements around building that time span.
Of course, Blazer, not the first WA programming language go laying at a WA support back in
2018.
In June, and again, no, people remember much about this because it was mid pandemic.
Microsoft is a big splash about open AI GPT3 being built on what they called the Azure
Supercomputer, which was a bunch of different Azure days and it's harnessed together with
10,000 GPUs, 285,000 CPU cores to build a get this 175 billion parameter model.
Wow.
I mean, big, big, big for the time.
Not so much anymore, but at the time.
I remember Brian McKay, who's one of my happy next guys, getting on Slack and telling
us how awesome this GPT thing was, but it was difficult to set up at the time.
But then, you know, I tried it and of course, like everybody else, it's kind of blown away.
Yeah.
I mean, later that year in September is when Microsoft actually licenses GPT3 from open
AI, which I presume is how GitHub gets access to it and will make it have a co-pilot
in the following year.
Right.
A couple more stories.
In November, Apple announces the M1 processor.
Yes.
And I mentioned this because this, I would argue is Tim Cook's most memorable move.
Like, he was always a hardware guy.
This is a staunch, he's a hardware.
He's a system on a chip, amazing.
Where the GPU and CPU, NPU, the IO and security buses and so forth are all literally in the
same die.
The memory is in the same package.
Yeah.
So this is made by TSMC, 5 nanometer process, about 16 billion transistors total.
That includes 8 CPU cores, 8 GPU cores, a 16 core neural engine, and up to 16 gigabytes
of RAM right on the package.
So you get both lower power consumption and higher performance.
And the little would we realize, I have a MacBook Pro with an M1.
Yeah.
First gen.
And it's good.
Is that 16?
Is that megabytes?
Well, gigabytes.
Gigs.
Yeah.
That's RAM, RAM.
That's RAM, RAM.
Yeah, they're not putting cash on.
Cash is there too.
But also that RAM is shared with the GPU, right?
So there's, you know, what we're doing right now with LLMs and the new agent models and so
forth.
The M1 was built for it, not knowing it was built for it.
They were just trying to make the most efficient computer they could consume at least power.
This is my apples move back to ARM, having come from the Motorola chipset, moved to Intel
for a few years.
Now they're making their own thing based on ARM.
Two more.
December, both in December.
The solar wind supply chain attack.
So this is Russian SVR.
The pure brilliance of this is unbelievable.
So in September of 2019, hackers successfully break into the solar wind development environment.
And the insert code into the development chain.
The way they do it is incredibly in cities.
It's part of their build system that they replace code in the build without actually changing
the visible source code.
So developers don't think their code has changed at all.
But what they're actually compiling is different code with this thing called the Sunburst
Backdoor.
They can, they, they, it takes them a few months of doing testing to get this to work by
March.
They do the for, they, they have actually figured it out.
And the Orion monitoring software, solar winds builds this infrastructure monitor software
is now distributed to 18,000 customers with the Sunburst Backdoor in it.
They're, the Russians are successful enough.
Then June, they actually remove the whole build injection system, like they're done and
they're happily operating it.
Now, the minute they don't actually use that backdoor much, maybe 100 customers are totally
affected.
But it's in December when one of those customers, a security company called FireI, realizes
they've been exploited and traces it back to the Orion code base and basically pops the
whole thing open.
It's incredibly sophisticated supply chain attack and scares just not out of actually
everybody.
It's not the first one, but in a lot of ways is the one that made the most news.
It could be, it could be made into a feature film, actually, if it was handled correctly.
It's astonishing.
Yeah.
And if they had, if the Russians had decided to go after FireI, who knows when it would
have been detected?
Yeah.
Just do you went after the guys who were in the security space and good enough at attacking
breach properly?
Hmm.
Yeah.
I was invited to a meeting to be briefed on the attack when we sort of knew what was
going on.
And yeah, they all be frank.
And I was kind of gobsmacked, actually, by gobsmacked.
Gobsmacked, isn't it?
By the sophistication.
It's so clever, holy man.
I don't expect bad guys to be this smart, right?
If they were smart, they'd be good guys.
Like the idea that bad guys would come up with something this clever.
But again, state actors like they're working for more than just a paycheck here.
Yeah, we remember though, you know, Sherrod Dugrapo has told me many, many times.
This is their day job, right?
They come to work.
They clock in.
They do the work.
They work every year.
They go home to their families and they start against them or they get promotions by
figuring this stuff out.
Exactly.
It's just a joy.
Yeah.
As Dwayne LaFlaut would say, oh, this is awesome, guys.
This is awesome.
It's a stunner.
All right.
And I'll finish out the year of Compute in 2020 with China's shoe-hanging, photonic
quantum computer, which I think is a particularly relevant for today's conversation.
This was a dedicated machine using photonic quantum entanglement, which is very, very clever,
unique, very different from Sikamor with the Google's device from the previous year,
which was the hanging chandelier and liquid helium.
This doesn't need any of this, but it was built specifically for Gaussian boasts and
sampling.
Nobody knows what you're talking about, Roger.
I'm OK.
I'm OK.
Michael Paz.
I mean, is one...
I'm not known enough to be dangerous.
It's always been about the software side of it.
Yeah.
And that's the whole thing is this is nowhere near a general purpose computer, even a super
computer.
This is a machine to demonstrate the quantum entanglement, contact one kind of problem,
the Gaussian boasts and sample problem.
Now that's an important problem, but it was sort of a proof point.
I think very much this is a, hey, we get to play too.
And I think everybody reacted to it that way, because this 200 second run for something
that in theory would have taken its computer, super computer, two billion years, not that
anybody's going to test that.
You just put China instantly on the map and really made it very clear.
There's more than one way to quantum.
And this is a wildly different way, not that we've heard much from them since, but in 2020,
that was a really big deal.
But does it run doom?
It really doesn't.
No, not a bit.
No, it won't.
It won't.
I mean, and you know, super computers are limited in their own way too as well.
But this was literally built for one thing.
This is like, you know, Turing's device for cracking enigma.
Good for one thing.
Right.
The idea of general purposes computing is a much different idea than what we're doing in
this kind of class of work anyway.
100%.
I think people need to understand that, you know, it's, yeah, I do.
Still people don't grapple that.
These, you know, there won't be an office for quantum, you know, it's not going to exist.
Oh, man.
I'm sorry.
You sold me that subscription.
Let's get them on the phone.
Yeah.
This is a, and as much as we can tell at this time, these will always be super computers
for particular problem spaces.
Also, them very deterministic problem places too.
But let's wrap up the history lesson and get on to our larger conversation about quantum.
Well, but first we have to do, but first better know a framework.
Roll the music.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
You know, so I'm.
Yeah.
Awesome.
Yeah, so.
I know you know it.
Awesome.
Cool.
Awesome.
Awesome.
So, you know, most of your friends may play random mechanics super smart, but they're
to battle.
Definitely.
T Wow.
Awesome.
Awesome.
Awesome.
Awesome.
Awesome.
Paul Girls.
ram and it's, you know, blinky lights and quiet as anything, right?
It's amazing.
So on coated with AI, Jeff Fritz and I did a series on taking a whole bunch of models
that would run on Olamma and running them and then putting it through a test.
Basically, a lot of them failed.
More so because of context, I think, then this is what I'm learning now, the context size
if it's too small, we'll just barf, you know, the LLM will just, and lose it, or get
into an infinite loop.
And basically, what I came down to is running llama.cpp.
And llama.cpp is like Olamma, but it's not.
It's a different thing.
It's open source.
And I can run the new fairly, fairly new, Quen 3.827B model.
And llama.cpp will use V-RAM and system RAM at the same time and it will balance them
out and figure out automatically how much of which to use.
And let me tell you something.
This is what I've been waiting for.
It works so well that I don't feel the need to go back for what I do.
You know, debugging, coding, all of that stuff, I don't need to go back to any frontier
models anymore.
Right.
I haven't found, I've been using it for a couple of weeks.
You're just working local now.
I'm just working local.
Yeah.
The only thing that's costing me is electricity, but I got solar panels.
There you go.
Some pretty good, especially in the summer.
You feel feeling good in that machine you bought, like to build that machine today.
That's the big, big bucks.
Yeah.
Right thing.
Well, I thought it was big bucks back then, but now it was.
Yeah.
It was a lot of money for a PC back then.
Yeah.
Doesn't seem that way at this moment.
Well anyway, almost at a performance you're getting out of it, like token processing.
That's great.
It's as good as any frontier model that I've been using.
I've been using GitHub Copilot CLI, mostly with CloudSonic.
It's as good as that.
You know, I don't find myself waiting around.
It can do anything that I throw at it.
It handles local stuff on the computer, stuff in an Azure and GitHub.
It's just really good.
This model compared to other models is good, but you run it in Lama CPP and it's like
beautiful on this particular configuration I've found the sweet spot.
So I wrote a document and that is the link that we'll put on the page.
It's a GitHub readme basically running Quinn 3.827b with Lama CPP and GitHub Copilot CLI
on Windows.
It tells you exactly how to install everything, all the stuff that you got to go, put everything
where it needs to go, and download Quinn and run it and how you access it remotely.
It's great.
I have my dev machine, my GPU machine, and it's a match made in heaven.
There's a lot of people running those kinds of headless systems with Windows, mostly the
Linux.
Cool.
It's good.
And also, this model, Quinn 3.8 has vision support so I can pay screenshots in, you know,
and it just works.
It's wonderful.
Cool.
That's when I got Richard who's talking to us.
I grabbed a comment of show 1963, which you did last year with one Michael Howard talking
about 30 years of application security.
This is back when you were still the red teamer.
So I know your life is different now.
And this comment comes from also a past guest, Arnold Axelrod, who said great show is
always one comment regarding input validation because of course we talked about input validation.
Toward the end of the show, Michael mentions that all inputs should be considered evil.
It must be validated in order to be considered secure, right?
Yeah, hard to argue with that.
I'm not a security expert, but I have a different take on that.
I don't think that the problem lies in the lack of input validation, but I think that
input validation should be a business requirement.
The example being zip codes, why don't I certainly know what a formal zip code is or will
ever be consistent around the world?
Answer is absolutely no.
When you consider the idea that Ireland only got postal codes in 2015, like good luck.
In my opinion, the problem lies with the use of parses and interpreters and not using
escape sequences or other structures to separate arbitrary input from structure ones,
like separating the inputs from the SQL statement itself appropriately.
Both SQL JavaScript and command through the process start and C sharp are interpreters.
And if you construct an input to them, that contains an arbitrary user input without sanitizing
it with the correct escape sequences, where is where in predictability comes to play,
which causes the risk.
Are you RRI also having structured format?
That is parsed by a browser and constructing a URI, let's say, with an arbitrary query
string that may be harmful, but you're probably using URI encoding on the inputs and that
should make you safe.
This doesn't require you to limit the input in any way, just to format it correctly.
There is where the focus should be, if as far as I'm concerned, not just to invalidate
all inputs.
I'd love to hear your opinions on it.
Are you on my opinion?
Go for it.
Yeah, Hitchie.
It all got turned on its head right with LLM's and jailbreaking.
What is the input?
What is valid?
Can you even escape it?
Even escape versions can still get through any kind of checks.
So yeah, I wrote about that recently in the...
Our new injection attack starts with ignorable previous instructions.
Exactly.
So Matt was in a bit, actually, has a t-shirt with that on the back.
He showed it to me at Bill's last time.
I almost fell over laughing.
It was so proud of it.
Hey, Michael, check this out.
It is completely turned on its head.
That's how we've got all the other defenses that come into playing these guard rails and
so on in LLM's, because we need to...
We don't know what the input is.
LLM's need to get a sense of humor, right?
A sense of sarcasm, a sense of irony, and they got to get sensitive to that just like
we humans do.
I don't know.
I don't know.
Yeah, we really want to pass every input through an LLM to say, is this a potential attack?
Good luck with that.
No, but of course not.
But I mean, if you're dealing with an LLM and you're at the keyboard and talking to
it, right?
And you give it some ridiculous prompt, that's clearly satirical or something.
It should laugh back at you, you know?
Well, that happens to me once.
Yeah, that's a good one.
Yeah.
Do that happen to me once?
Oh, seriously.
I was working on the podcast website or something and asked it to do a quick security review
of the code.
And it found something.
I was just running Visual Studio, I think.
And it found something and it said, here is an outdated HTTP header that been deprecated.
I didn't know.
A supposedly security header that had been deprecated.
And it said, by the way, this HTTP underscore blah, blah, blah has been deprecated for security
reasons.
And it's really ironic that you as the author of running secure code didn't find this.
Oh, that's great.
Yeah.
That's what I'm talking about.
Yeah.
I don't know what the backend model was because of course Visual Studio, you can jump around,
but I don't know.
But yeah, it was quite a quite happy to yell at me and laugh at me.
That's pretty good.
When the tool says the word, it is trying to detect irony, that's just ironic actually.
Right?
Yeah.
It's very recursive.
Arnon, thank you so much for your comment and a copy of Musicobiles on its way to
you.
And if you had copy of Musicobiles, write a comment on the website at dot air rocks dot com
or on the Facebook's that public show ever show there.
And if you've got my data reading the show, send you a copy of Musicobiles.
If you'd just rather buy Musicobiles, go to Musicobiles.net.
You get the tracks in MP3, Wave, and Flak formats.
But before we introduce Michael, let's take a little break for these very important messages.
And we're back.
Dot net rocks.
I'm Carl Franklin.
That's Richard Campbell.
Hey.
Let me introduce him formally.
Your bio has changed a little bit.
Michael Howard's been at Microsoft since 1992.
Wow.
Always in some form of security, IIS, SDL, founder of SDL.
Well, it's one of the guys that worked on the very, very earliest versions.
It was like two or three of us.
Yeah, back in the day.
Awesome.
That was the security lifecycle.
Security development lifecycle, yeah.
Yeah.
I can get the earliest like 2004.
So you worked in Azure Data on the red team.
Last time we talked in now, you're in Post Quantum Crypto.
Woohoo.
Yeah, baby.
Man, I'm happy to be here.
It's a lot of fun.
I mean, how can you post quantum if we haven't had quantum?
Yeah, because it's because the attacks, the real attacks start post quantum, you know,
that's the reason why.
Yeah, you're right.
Yeah, I got it.
Yeah, you need to be ready.
Yeah.
I think it's a lot of things, certain things maybe not, but we can discuss that later.
But yeah, what does it mean?
Post Quantum Crypto.
Well, so that you know, you think of things in three ways.
This is where we think about it at Microsoft, anyway, I'm sure most of the industry does.
Data on, data in transit, data at rest and then cryptographic trust.
So data on the wire, you know, stuff flying across the internet is probably protected
by TLS today, more than likely, perhaps SSH, but certainly TLS.
So at rest is encrypted most of the time or should be.
And those encryption keys are wrapped with other keys, key wrapping keys.
And then you got cryptographic trust, which is, you know, signatures, certificates, all
that sort of good stuff.
The real threat is dead on the wire is being, you know, being ployed as it flies across
the wire.
Yeah.
And then when a quantum computer comes out in the future, that stuff can be broken.
And then the breaking, the breaking aspect is essentially just breaking the RSA or the
elliptic curve wrapping that goes on and pop out, pops out pops the AES key that's used
for the bulk encryption.
And they just decrypt everything.
And then the case of data at rest is the key wrapping keys, right?
They can be, they can be broken because they usually, for example, RSA, which can be broken
with an algorithm called Shores algorithm, SH, O, R.
And it basically finds periodicity in the way those algorithms work, that's what takes
advantage of.
Or are logs at risk for being pilfered by crypto, you know, post-ponsum crypto?
I mean, if they contain sensitive data, which you shouldn't be logging sensitive data,
right?
No, no, no, but even if it wasn't containing sensitive data, is that something because
it can go through so much data so fast that it could, I mean, if I had to prioritize stuff,
I would focus on the actual data result.
Yeah, okay.
So data in transit and then real data in your databases.
Correct.
Yeah.
Again, they can be, you know, snuffled today and then once a quantum computer is made available.
And that's where a lot of you say snuffled, hostile and snuffled, poloined, snuffled.
That's a good British word.
Snuffled.
Yeah.
That is actually a real word.
I don't even know.
It's a real word.
It is mad.
I don't know, but I never heard it before.
It is now.
There you go.
Thank you.
So you learn on Don Errach's.
Alright.
That's all good.
Yeah.
So the risk is the asymmetric keys that are used to wrap asymmetric keys that do
the tend to the number of prime numbers.
In the case of RSA.
Yeah.
But that's not the attack.
The attack is the period.
There's a period, there's a, there's a period, a decidive.
Actually, look at the way Shores works.
Not that I say, not that you should.
It basically does a quantum fast Fourier analysis.
Yeah.
Shores is actually hybrid.
It's actually quantum and sort of classic computing.
Right.
The hard work is done by Shores and then some of the less easy, less difficult work is
done classically because it's just easier.
And so the real issue is that those asymmetric keys, RSA, elliptic curve, Diffie-Harmann, they
all exhibit some periodicity that can be detected by Shores.
And that gives you a whole bunch of possibilities that then classical computing can then just sort
of sift through and find out which ones are the actual keys.
Right.
So narrow is the scope of the testing needed.
Correct.
So you're pointing before.
Yeah.
And to your point before, rather than, you know, squallions of ages of the universe, it
could be ours or, you know, Dave.
It's a real thing.
And, you know, developers have a big part to play in this.
It's not just, you know, flips on the switch and everything's golden.
There's a lot more to it that, you know, developers need to understand as well.
So everything I've barely hung on understanding about quantum is that we're all screwed, right?
And because of the way that TLS works and, you know, SSL and all that stuff, it dramatically
has to change, doesn't it?
If we're going to be not less susceptible to quantum interference, but you're, I think
what you're saying is that there are ways that we can do that now.
And that's what, you know, post quantum crypto is all about is trying to use cryptographic
methods now that will survive the quantum onslaught.
Is that what you're basically up against?
Yeah.
One of the beauties of TLS, whether I can't believe you said SSL, like wash your mouth out.
It's been a, you know, some of us were around.
It was I.
It was I.
And so they don't use those words TLS.
I don't know.
I don't know.
I'll just pretend you didn't say that.
Yes.
So TLS, one of the beauties of TLS is that it's very agile, right?
You can change the way it works.
The site, the, the ciphers that are used, the cryptographic primitives that are used.
And you're talking about TLS 1.3.
Right.
Correct.
So TLS, why would you be using it?
Yeah.
So actually, it's a really important point.
So TLS 1.2 and prior.
So TLS 1.0 and 1.1 are deprecated anyway.
So don't use them.
Yeah.
TLS 1.2 does it cipher sweet and it's key establishments and authentication.
All is one string called the cipher sweet.
It looks like someone sneezed on the screen, basically.
It's a list of all the algorithms that are used for all of those things.
TLS 1.3 is different.
It broke apart things like the key establishments from the bulk encryption and the bulk
tamper detection.
They're completely broken apart.
Yeah.
So you can negotiate the two separately.
That's the big difference in TLS 1.3.
So the key establishment is a thing called a group.
And the reason why it's called a group is because mathematicians got a hand, a hand
hang on this and they said, you know, these things are mathematical groups.
So we'll call them groups, terrible name.
But for the key establishment, that's where you set the algorithm and or algorithm in
some cases.
And then after that, separately is how you do bulk protection of the data on the wires.
So TLS 1.3 broke those two apart.
So it is completely not compatible with TLS 1.2.
And TLS 1.2 will never be post quantum.
I mean, it's just software.
I mean, essentially, I suppose you could make it post quantum.
Right.
Yeah, but why would you?
But the interoperability story would be horrendous like no one would do it.
And also seems unnecessary too, right?
Because I set the TLS 1.3 with a drop down in Azure.
Right.
But the thing is, so here's the issue.
And this is one thing that we're having to work on for products like Front Door, for
example, is you will be able to control the group.
Not just the bulk cryptography that's used.
OK.
And the group is where the post quantum part comes in.
For the most part, symmetric stuff, AS256, Shr384 and so on, which are the baselines
are fine.
There's another algorithm that called Grovers, which is an attacking and symmetric
algorithms.
And it essentially cuts the number of bits in the key in half.
So if you have a AS256 in a quantum world, that's the same as AS128, which is fine.
So you must use AS256 and Shr384 as the minimum as well.
They're kind of OK.
They're fine.
The problem is the asymmetric stuff.
The elliptic curve, RSA, Diffie-Harmann, that's where the problem is.
And the nice thing is that NTS1.3 is that it's defined in a group and that's negotiated separately
from the bulk cryptography.
And that's where the hybrid algorithms come into play.
And the reason why they call hybrid is you use two together.
You use elliptic curve and MLKM.
So MLKM is the quantum resilient algorithm.
Elliptic curve is classic.
You build up keys in both your smoosh together, pass it through a hash and then you derive
the session keys after that.
So they're both used together.
So that would have to be implemented both at the browser level and at the server level,
right?
Yeah, everywhere.
I mean, you say browser, but I, you know, client.
I mean, that's being clients in general.
And in fact, you bring up a very important point there, Carl.
And that is that all modern browsers support hybrid TLS1.3.
Yeah.
So I mean, even the humble Xbox has hybrid.
I've tried all sorts of iOS, Android, Windows, Mac, Linux and all the common browsers support.
So anything, anything that uses it like curl or any little command line tool, all those
things have to support it.
Correct.
Correct.
So SSH, both clients serve a support as a version 10, I think maybe 9.9 or 10 supports
MLKM.
So the important part there in MLKM is the letter L in that there's lattice.
And the two major algorithms that are post quantum resilient is actually a small number, but
the two major ones MLKM and MLDSA, the L is lattice.
And the lattice that lattice construct that is quantum resilient.
Right.
So when you say quantum resilient, do you mean what you perceive as the first generation
of quantum or all quantum going forward till the end of time?
Nah, I mean, nest is still going through other algorithms.
The industry has settled and nest have settled on MLDSA and MLKM.
And there's been a lot of research for the last 20-something years in lattices, looking
at it through a quantum lens.
And they look good.
But everyone's quite happy to say, let's go and look at other algorithms as well, just
in case, and in fact, for no other reason than the resulting cipher blob is big.
So I'll give you an example.
If you have an elliptic curve, say an EC25519, which is a curve, a digital signature for
that is 64 bytes in size, it's pretty small.
If you take an MLDSA 87 certificate and you sign data with the private key of that, it's
about 4.5K.
So you imagine if you've got a whole series of certificates or with their signatures,
it adds up real quick.
And you can have problems with M2U's, with people passing stuff on query strings, the
amount of space that is set aside on disk for signatures.
Yeah, so it's a real issue.
So nest is continuing to evaluate other algorithms with an I to potentially smaller signatures.
So now, it's a static blob.
And I get why it's called lattice because it kind of makes a web of data that's hard to
penetrate.
Is that good analysis?
No, it's terrible.
Terrible.
It's terrible.
It's terrible.
I can take it.
Okay, here's how it's all good.
The way lattices work, and this is a terrible description, but it's an interesting way
of thinking about it.
It'll be better than mine, I guarantee.
I may not be.
I'm not a fan of analogies, so here's an analogy for you.
Okay.
Imagine a chess board, right?
8x8 with a knight.
We know the knight moves either 1 and 2 or 2 and 1, right?
That's what it does.
If I give you an endpoint, and I give you a starting point, what route does the knight take
to get there?
That's pretty straightforward to do, you know, because it's just 8x8.
Now imagine if that was a schooling and by a schooling and chess board.
Right.
Got it.
I guess harder.
Now imagine it's a thousand dimensions.
Now imagine I don't tell you that 1x2 is nxm.
Right.
Now just to make things even more difficult, it's not like a equates square chess board.
The squares are kind of funky shaped, they're not quite squares.
That's the thing called learning with errors.
That's hard.
Here's a point somewhere in this end-dimensional space.
Here's your starting point.
How do you get there?
Essentially the n-m is essentially like the private key.
That's one way of looking at it.
Terrible analogy, but it's about as close as you can get without introducing math.
Okay.
Yeah.
Good.
You don't think that quantum computers could ever get so good that they could just figure
that stuff out quickly.
You mean when you throw in some AI as well?
Yeah.
Yeah.
Well, go on.
But nobody ever comes up and thinks, hey, we solved cryptography.
You're always looking at new algorithms.
You're always looking at new key links.
We expect to routinely replace our algorithms and arms race because right to bad guys are
fighting back.
Which is a beautiful segue into the next topic, which is cryptoagility.
If nothing else from a developer perspective, one thing that post-ponsum crypto will bring
to the table is the need for cryptoagility.
What happens if you wrap some keys in MLKM, KEM sends for key encapsulation method.
Let's say you wrap some keys in that and ends up being broken five years, 10 years from
now.
How can you update your application to use a new wrapping method without breaking your
existing?
You can still read your old data, but you would write out using some MLKM++ or something.
Right.
So, agility is just so important.
It's really brought it to the forefront as a need because we don't know long term if
these things will be successful or not.
And against your point, cryptographer is a very conservative when it comes to these sorts
of things.
And they want to have a big security buffer knowing that some things will start to potentially
creek a little bit.
Yeah.
And of course, you're immediately going to the at-rest encryption problem.
I'm always thinking TLS and it's just we handshake an encrypted stream.
We do our thing and then it disappears again.
And so I don't have any other than the harvest and decrypt later, I don't have to think
about this.
It's all transitory.
We'll just use the newest algorithm.
But if you've stored under an older algorithm and now it's been breached, you have to decrypt
or at least decrypt over time to get by that.
You may have to increase the data size of your fields to take those things because it's
going to take more.
Yeah.
So you go to assume that there will be change.
And unfortunately a lot of people don't know how to build cryptos or had your solutions.
It kind of drives me a bit bonkers to be honest with you.
I see you in the press.
You don't really need cryptos or agility.
You've got to do cryptos or agility.
Hey, cryptos or agility is really important.
Is that you know what?
Are you guys doing cryptos or agility?
Yeah.
But no one says, because it comes in a squirt bottling, just spray it on all your devs
and you'll be good.
I know.
But no one says how to do it.
You know.
So to me at Microsoft, there's two canonical examples of cryptos agility.
One is as is equal DB or SQL server with always encrypted.
And then the other one is the open Office XML file format, which you use for encrypt documents
and office.
So the way it works in as is equal DB, which to me is a beautiful and simple way of doing
it.
It's also very, very fast.
If you have a look at the cipher text in an always encrypted cell, the first byte
is always a one.
And that's the version number.
And that basically means AS256, cipher block chaining with a chr256 hash, like an integrity
checker over the data.
So in the future, if they decide to upgrade it to something else, then that could be version
two.
So the first byte would be a two.
Right.
And they could always read back and say, OK, that's a version.
Mom, we need this particular set of cipher primitives.
Let's read as decrypt it with these primitives.
But when they write it back, they would write it back as a whatever the latest number
was, which we have version two.
And it would be the whatever the new cipher suite is.
So you could always read the old data and you would write back using the new version.
And the way office does it is it's an XML file.
There's an XML file header.
And it contains all the cryptographic primitives.
I say, yes, it's cipher block chaining.
Here's the initialization vector.
Here's the password, the key derivation count.
Here's the key derivation algorithm.
Lots of other metadata.
So you can actually build the cipher collection completely dynamically, which is really, really
nice.
What network hardware will have to change in the?
Yes.
I mean, we won't, will we able to go to Best Buy or whatever it is you have in the UK
and buy an off the shelf router that is crypto happy?
Well, I mean, in theory, I think a lot of quantum happy rather.
I mean, unless they're doing some kind of inspection, if they're just like passing data
on, there should be no need for it, rather than decrypting stuff.
But if they are decrypting stuff, then yeah, they're going to have access to these algorithms.
If you're doing, you know, TLS termination, then yeah, for sure, the other.
It's not something you'll have in your home.
I did that stuff in racks of computers for companies, but there's a fly in the ointment.
There's a huge fly in the ointment, though.
And that is your laptop and your computer with TPMs and trusted boots and that sort of
stuff.
Right.
Right.
And we're just going through the secure boot crisis.
Thanks very much.
Right.
So that will all get busted.
And, you know, so the hardware to be created, they're all working.
You mean here, Mike?
You're just squinting, but I think of it.
You got to look at it like this.
Hey, you got to buy a new laptop.
Well, that's not a bad thing.
But there's also like, we're fixing keys all the time.
These are BIOS updates.
Like, this will come in firmware.
You think?
These drivers, and they might be slower than a hardware dedicated version of it.
But I just don't feel a lot of the stuff you're describing here, Michael, to me sounds
like configuration settings in Azure already.
You already done the work in the browser.
Like, as long as I haven't done these things stupid in code, I don't think I have to do
anything as a web dev.
That's correct.
100% correct.
I just got to make sure that my admins have set stuff right.
Well, if you're using IAAS, you're going to have to make sure you're in the latest version
of that supports it.
But in Azure.
Well, HTTP.sys.
Well, so I actually wrote a blog post on this because about six weeks ago, we released
a version of S channel, which is the Windows TLS stack that supports TLS 1.3 hybrid.
And I wrote a dumb ASP.NET application, dumb of the bucket of rocks just to keep it
really, really simple and did no configuration whatsoever in the code.
That's a really important point.
Valshelt not do any TLS configuration in code.
Leave it to the OS or to some configuration somewhere else, definitely not in code.
And yeah, I just turned on that I wanted X25519 MLK 768 in priority zero in the Cypher
suite and group order.
And I ran this application and I connected using a browser and I was living in the future.
Nice.
How long do we have before we need to configure our things correctly?
How long do we have?
I mean, it depends on risk.
I was talking to a large retailer.
You know who they are, but I can't say who they are.
And they're not concerned.
The one I bought my computer from.
They're not concerned about right now anyway with their devices that they use for shop
floor inventory management, right?
Because it's just shop floor inventory management.
It's not sensitive data.
So their Android devices that they're using will never support post quantum.
They're okay with that.
Now their corporate systems that run HR and payroll and all that sort of stuff, yes,
they do care.
So how long do we have?
I mean, the clock started now for certain types of data.
Depends on the data.
If you've got really sensitive data or data that must be set the secret for a long time,
healthcare information, military secrets, intelligence, financial records in some cases,
perhaps I don't know.
I'm not a regulatory person.
They have a time that they must maintain their secrecy.
And that clock's already started because if we take a 20, 29, 20, 30 time frame, that's
only four years.
It's only even four years away.
On the screen behind you, sentence came up a little while ago.
There's no such thing as low risk data.
But apparently this large retailer seems to think there is.
I see.
I think it's a no low risk secrets.
Oh, low risk secrets.
That's right.
Yeah.
Yeah, low risk secrets.
Secret is a secret.
So if it's a secret by default, it's by definition a risk.
Well, a small, a quote, small secret can lead to access to bigger secrets.
Is there like a low credential, for example, it can lead to something like a key?
Deal.
Sure.
Yeah.
The old classic I broke in through your, I got your Wi-Fi password from your light bulb
because you thought, well, it's just a light bulb.
What are you going to do to me?
Right.
But the fact that I got...
Sidechain attack.
I got a Wi-Fi.
There was a whole lot of other things that were there.
Yeah.
Man, that's why I put all my IoT stuff on this own virtual network.
Is that own isolated?
Oh, you're done, right?
You do.
Absolutely.
Yeah.
But at the same time, you know, I'm still sorting through what do I have to code as a dev
versus what I have to, you know, what's going to come to me just by making sure we're
using the latest bits.
Like, I love your info on always encrypted.
It's like, hey, now I want to go talk to my friends.
My DBA is like, we're up on this version, right?
Because we have all this encrypted and rest stuff and you don't want a crisis.
So if you're already running always encrypted and SQL data, then we should be good.
Like, when the new algorithms are needed, they'll work.
The big issue, and this is one thing that the, you know, a lot of products that Microsoft
happens to deal with is the symmetric stuff's fine.
It's the key wrapping.
Yeah.
That has to change.
The beauty of it, though, is it just the key wrapping.
So if you have a 256 bit AS key, you just decrypt it or unwrap it using RSA, for example,
and then you rewrap it using ASKW, which managed HSM and ASU and now Key Vault actually, Key
Vault Premium in public preview supports ASKW key wrapping, which is post-consum resilient.
So yeah, great.
So there's two, there's two issues that I see developers need to really, really think
about.
Is please don't put any TLS anything in your code.
Yeah, it'll hurt you later.
Don't restrict protocol version.
Don't restrict cypher suites.
Don't do any of that.
Just let it be configured completely outside of the application.
That's number one.
Number two is this whole cryptocurrency thing.
You know, if you're, if you got crypto code, you know, with the algorithms hard coded in
the code.
You're in trouble.
You're in crypto, you know, squiggy bytes of data.
You know, you got update your code and probably can't read the old data.
So they got, you know, it's just a mess.
Yeah.
And that's where the whole cryptocurrency comes in.
And honestly, if you haven't got crypto agility in place that are patterns you can use
to wrap existing non crypto, crypto agile blobs into like some sort of crypto agile envelope
that contains all the metadata.
So Azure is really good about letting me know when I need to move off of some version
of something and onto something else because it's being deprecated.
Do you think that sometime in the future we're going to get an Azure thing when we log
into the portal that says, Hey, you need to upgrade your whatever it is to be quantum
happy.
You think that's going to happen?
Like, should I just leave it up to Azure to warn me about things like that?
Or is there stuff that I need to do now?
I think it depends.
If you look at the shared responsibility model, that's where it really becomes important.
Like, if you got a platform managed key to encrypt data, then we're going to take care
of that, right?
Yeah.
Because a platform managed key.
But if you've got a customer managed key, which is basically a key wrapping key, then
the problem, look, I can't predict the future.
But my guess, just my guess is that there will be notifications to say, Hey, you know,
we've now got the ability and Azure blah, blah, blah to wrap your encryption keys in
quantum resilient keys.
Would you like to do this?
Yeah.
Click here.
Yeah.
And the consequence is going to be very likely that the data streams are going to get
larger because the quantum resilient keys are bigger.
But no, I don't know what other impacts I'm going to see.
No, you shouldn't see it.
No, because the only thing you're really changing is the key wrapping, which is, so if you
got a 256 bit AS key, you're going to wrap it in AS2 ASKW.
And in fact, it's probably smaller than RSA, to be honest with you.
But if you wrap it in MLCam, it will be bigger.
Right.
But it's just the key.
It's just the key.
Yeah, the data that I'm even choosing that are I'm just configuring to allow this and
it'll optimize itself.
What do you mean?
What do you mean?
I don't get.
Like, when do I have to make a decision about this?
About what?
About the re wrapping?
Well, first of all, the nice thing is it's very low friction.
Very, very low friction.
Like it's microseconds to do the work.
You know, decrypting and reencrypting petabytes of data.
Right.
So my guess is personally, as soon as it becomes available, I would just opt in and just
re-wrap your keys.
So I'm going to wait for your blog posts and then I'm just going to switch this stuff
on.
No, we'll push it through as your update.
I guess it'll be through the app as your updates website.
Yeah.
Yeah.
So, you know, I'm going to point something out here is that, you know, this post-quantum
stuff is very layered, right?
So the very bottom of the layer, you've got the algorithms.
Well, that's been in place in Windows for ages.
Yeah.
And we have called SIM crypts.
The Veloin Windows, Linux and Mac.
Hand up to my C code.
Absolutely beautiful to read.
It's so well written, honestly, it really is.
Then above that, you've got, say, TLS 1.3 with hybrid, right?
You open those floodgates because now people can use that stack.
So basically on Windows, it's to use the US channel stack.
In the case of Linux, you open SSL 3.5, which has MLK built-ins.
So you've got those two options and now available to you.
So that's the data and transit taken care of.
And then the last one, which is incredibly important, is the key wrapping.
And we now have that in Azure.
So managed HSM has had ASK wrapping since day one.
And as you keep on now, has it ASK?
So what's going to happen is that's going to open these floodgates.
And there will be a Cambrian explosion of services coming online, right?
Is there a adopt?
And look, it won't happen overnight.
Because everyone's going to be testing, make sure it works, make sure it fails correctly.
And that's all the stuff.
But to, you know, Richard, to your point next year, we'll see a lot of services rolling
this out.
But I also remember when we started switching up keys when a task got smarter and so forth,
like there was a period where we changed a number of times, different flavors of SSL and
then into TLS.
We are restarting this in some respects with these new cryptography.
I've got to think, like the first move we make may not stick for more than a year or
two before it's like, hey, now we found some problems and you probably want to switch
to this.
I just remember going through this as a yes and a few others.
Like we've done this before.
I mean, some ways we've gotten really lazy because it's worked so well for so long.
Well, actually, it's worse than that.
And that is that so we've actually become really lazy because of RSA.
Right.
RSA is interesting.
RSA can do all the crypto primitives.
Right.
It can do signing, you can do encryption and all that sort of stuff.
Elipzig, Curve and Diffie, Harmon, cannot.
They can't do everything.
And so we've been used to, like you said before, Richard, I'm not trying to laugh at you,
but you said your prime numbers.
Well, that's just an RSA thing.
That's not an Elipzig curve thing.
Right.
But because everyone thinks of RSA.
Yeah.
And RSA is the Swiss army now.
If it does absolutely everything.
Sure.
And the problem is it does absolutely everything.
Absolutely everything.
Which means we've got to change it absolutely everywhere.
Yeah.
Yeah.
It went everywhere.
Well, the other side of this was because compute.
I remember when it was expensive to do encryption where we literally had separate servers
from the website for doing just the encrypted pages.
Right.
Okay.
Well, now you're going to take your shopping cart and start a payment cycle.
That needs to be SSL.
So now it was this big thing about moving the cart over to the other much more expensive
dedicated staff for completing a transaction.
Because encryption used to be so costly.
You know, these days our CPUs are so damn fast.
They're sitting around playing poker and smoking cigarettes waiting for something to
do.
So sure, encrypt everything.
Who cares?
RSA is fast.
Well, the funny thing is that first of all, it's just the key wrapping and unwrapping
part.
Yeah.
Or the key less because let's just call it key establishment because there's all
different ways of doing that's really what's going on.
That's the expensive part because all asymmetric stuff.
And Windows, I think it still exists.
There used to be a registry key called mod exp offload from modulo exponentiation offload,
which is a very expensive RSA operation.
And there was a way you can actually set a DLL in there.
And then the DLL, it would actually offload that work to a DLL, which is a shim into some
hardware to actually do the modulo expendentiation work.
But we don't need any of that stuff anymore.
You know, when I look at the work that, you know, as your front door of DUM, for example,
they've done a whole bunch of analysis on performance.
And the performance is just a couple of percent, you know, going from elliptic curve to elliptic
curve plus ML, ML cam.
And that's because of optimizations made in the library.
Sure.
I got to tell you, Michael, it is weird dichotomy going on where it's like the catastrophizing
of quantum destroying everything.
And the, oh, just touch this button problem goes away.
Yeah.
Yeah.
I'm feeling that too.
You're right.
I wish it was that simple.
Yeah.
I keep waiting for what's not the simple part.
I mean, for me is the front line debt.
Right.
I mean, I mean, like the administrator of me is, you know, a little sticky in the shorts
right now because this is all very scary.
Like, I want to check everything.
I don't want to be the guy who didn't do his homework.
Right.
But for the dev, unless you've done something dumb, I think you're good as long as your
administrators are on it.
The two, as I mentioned before, the two big dumb things are baking in crypto algorithm
and into your code and not being crypto-adential.
That's dumb thing number one.
Dumb thing number two is if you hard-coded TLS configuration.
Right.
Those are the two big ones.
Let's just ignore compatibility for a moment.
You know, if you change a server to use TLS 1.3 hybrid and only hybrid, by the way, the
reason why it's called hybrid is because you do an elliptic curve and MLK together, the
keys are derived from both.
That's why it's called hybrid.
But if you do hybrid and the client doesn't talk hybrid for whatever, you've got like a
crusty old Java application or a C-sharp application written 15 years ago, it's probably
not going to work.
Yeah.
And it's really a question of, is it going to fail with some grace to tell you what the
hell's going on?
Yeah.
Right.
It says, don't understand this cipher suite and gives you a hex value.
Yeah.
Really useful.
Yeah.
Well, that's better than object not found.
Absolutely.
Or one of the best ones in office back in the day is outer memory.
Yeah.
Yeah.
Michael, tell us about your book.
Oh, you book, man.
Yeah.
So I wrote this book with Sean Hernan, Lee Holmes and Sherry DeGropos.
So Sean and I have known each other for many, many years.
He's a partner engineering manager in Azure Security.
I've been around for a long time.
I've got the utmost respect for Sean, great guy.
Lee Holmes, he was the security guy in PowerShell.
Yeah.
He's been on the show before too.
Yeah.
My boy Lee, great guy.
Yeah.
He's good man.
He actually worked together when in the earliest days of the SDL, because when Monad, as
it was back in the day, had to go through all this SDL checks, I was the precursor to PowerShell.
To PowerShell, correct.
I was like the SDL contact from Monad.
So Lee and I got to know each other incredibly well.
And he's also partner engineering, partner engineering in Azure.
And then Sherry DeGropos, she's actually left Microsoft now.
She owns a PowerShell.
So labs, she is easily one of the preeminent experts in the world on threat access.
You know, it's absolutely everything about threat access.
So the book is threat driven software development.
And basically what it is, is looking at software development through the through the eyes of
threat access.
What does threat access actually do?
And every chapter starts off.
So first of all, Sherry has her own chapter at the beginning.
But every chapter after that looks at the contents of that chapter through the lens
of threat intel.
So every chapter starts off with anyway between half and two pages of threat intel perspective
where Sherry gives it a whole bunch of color.
And then Lee, myself and Sean go through an expert, you know, sort of explain that particular
topic in detail.
And a lot of it's not just, don't think of it like just security best practices.
It's not, it's dev ops as well as it's operational security, appsec and also threat intel,
all sort of munch together into one book.
Sounds good.
Yeah, a lot of fun.
I was in the red team.
Funny thing is, so my recent a bitch wrote the forward and my manager at the time Craig
Nelson, a CVP of the red team, he said, oh man, I really love this book.
I gave him draft to look at.
You might, you might, kind of write a chapter.
I'm like, well, why don't you write the afterword?
I've never had an afterword on a board when you write the afterward.
So we did nine pages.
But the afterwards, the after chapter, the after chapter, look, I'm not trying to besmirch
the Craig at all.
Yeah, sure.
That afterward is absolutely brilliant.
Oh, if you're to sum, if you're to sum up the afterward and like one sentence, it were
two words, it will be so what?
And he does a really, really good job of answering.
So what?
Yeah, it's really good.
Yeah.
That's good.
It's really cool.
Michael, what can we say?
It's been enlightening having you here and talking about all this crazy stuff that we
barely understand.
Well, I barely understand anyway, but I understand a little more.
I thanks to you.
So thank you very much.
You're welcome.
Thanks for having me on.
Great show, friend.
Thank you so much.
And we'll talk to you next time on DonnetRox.
DonnetRox is brought to you by Franklin's Net and produced by Klopp Studios, a full service
audio video and post-production facility located physically in New London, Connecticut, and
of course in the cloud.
Online at pwop.com.
Visit our website at DOTNTROCKS.com for RSS feeds, downloads, mobile apps, comments, and
access to the full archives going back to show number one recorded in September 2002.
And make sure you check out our sponsors.
They keep us in business.
Now go write some code.
See you next time.
