We assert that agentic AI constitutes a profound and immediate threat to passwords, passkeys, and credential stewardship when such agents are afforded unfettered operational or contractual authority without deterministic guardrails. I describe, with technical specificity, how agents that hold passkeys or password-manager access can act autonomously to transact, alter accounts, or execute legally binding operations, and we categorize those risks into task-level, operational, and contractual modes of delegation. We argue that the remediation imperative involves explicit delegation models, ephemeral and auditable identities, and cryptographic assertions that bind an agent’s scope of action to a human owner. I counsel continued adoption of hardened password practices and password managers, combined with resilient offline backups and dual-control or deterministic controls layered atop probabilistic AI systems. We further insist that security-by-default, mandatory auditability, and standards for AI skill and supply-chain review are prerequisites to any safe integration of AI with authentication systems. Finally, I exhort practitioners to prioritize availability, integrity, and accountability alongside confidentiality so that credential resilience endures in an era of accelerating AI capability. We offer clear, practical guidance for individuals and organizations to protect credentials in the age of AI. I recommend using a zero-knowledge password manager and enabling secure backups. Evil Mog affirms that printed or offline copies of critical credentials are valid resilience measures when they are managed and backed up properly. We advise random and unique passwords of appropriate length, routine backups of vaults, and giving trusted delegates access via documented procedures rather than ad hoc sharing. For family and estate planning, we explain how offline copies or delegated access can help manage accounts after death. We also recommend operational controls when using agents. Always run agents with least privilege. Use ephemeral tokens for short-lived tasks. Maintain strong audit logs that tie agent actions back to an owner. Keep humans in the loop for operational and contractual actions. We advise treating AI as an assistant for tasks and threat detection, not as a trusted keeper of passwords without deterministic guardrails. Finally, we remind security teams to prioritize availability and integrity alongside confidentiality and to make secure defaults easy to use so users do not bypass protections.
Takeaways:
- I explain three agent categories: task, operational, and contractual, each requiring different controls and audit.
- We caution against giving probabilistic AI full control of password managers without deterministic guardrails.
- I recommend using zero knowledge password managers, backing them up, and keeping an offline printed copy.
- We note that passkeys can be compromised if they are not bound to secure hardware or secure elements.
- I urge clear delegation, ephemeral identities, and auditable signatures when agents act on our behalf to ensure accountability.
- We advise keeping humans in the loop for high risk operational actions and verifying AI outputs before execution.
- I emphasize secure by default design, reducing friction without disabling protections, to prevent users from bypassing security.
Transcript
Hi, everyone.
Speaker A:Welcome back to another episode of the Security By Default podcast.
Speaker A:I’m the host of the show, Joe Carson.
Speaker A:It’s a pleasure to be here with you all, joining you from Talon, Estonia, where the weather’s getting a little bit crappy coming up to the winter months.
Speaker A:Getting dark, getting cold, but it’s amazing colors.
Speaker A:So it’s always, it’s a, it’s a, it’s an interesting time of year.
Speaker A:And with that, we’re coming up in the, of course, with Cybersecurity Awareness Month coming up.
Speaker A:And one of the biggest topics we always have in the Cyber Security Awareness Month is the world of passwords.
Speaker A:And what’s happening, what’s the current state?
Speaker A:Were we, you know, know, going with passwords in the future?
Speaker A:And also how does AI impact all of this?
Speaker A:So none other than I have one of the best people who knows passwords inside out, everything to do with them.
Speaker A:So welcome back to the show, Evil Mog.
Speaker A:You’ve been on multiple times now.
Speaker A:You’re, you’re probably the most frequent guest on the podcast.
Speaker A:So if you want to give some of the new audience that’s joined the show a little bit of background, who you are, what you do, and what fun things do you get up to.
Speaker B:So I’m Evil Mog, otherwise known as Dustin Haywood.
Speaker B:years now, since at least:Speaker B:I’m on Team Hashcat, so we’ve won a number of password trafficking competitions.
Speaker B:I’ve got black badges.
Speaker B:But mostly I just like going around talking to people with passwords.
Speaker B:Most importantly, the importance of choosing, you know, unique ones.
Speaker B:But with the age of AI, some of my advice has changed a little bit.
Speaker A:Absolutely.
Speaker A:I think what we’re seeing is, you know, a lot of, you know, passwords have been on the run for a long time.
Speaker A:It’s the cheapest way to authenticate somebody.
Speaker A:Accessing a system, accessing an application, unlocking their device.
Speaker A:We got pin codes, we got pass keys, we got lots of variations.
Speaker A:And of course, now we’re getting into a lot of the biometric side of things.
Speaker A:So we’ve come a long way.
Speaker A:I mean, I think probably in the last 10 years, passwords has evolved the most in regards to how we authenticating and also the new devices we’re getting.
Speaker A:So what’s the common thing you see today?
Speaker A:How are people managing passwords today in the best way?
Speaker A:What would you say is the best way they’re managing them today?
Speaker B:So I’m seeing a rise of password managers, first of all, especially things like zero knowledge password managers where, you know, a customer has, say, a secret they lock in their safety deposit box.
Speaker B:If that secret gets lost, the entire vault’s gone.
Speaker B:But they’re a lot harder to steal.
Speaker B:We’re seeing folks with password managers built into their cell phones now.
Speaker B:These days people no longer enjoy typing or remembering their password.
Speaker B:They never did.
Speaker B:But now it’s a lot easier and they can demand loss of the friction.
Speaker B:But that’s also the bad side.
Speaker B:I saw the other day was in asking my family if they used a password manager.
Speaker B:And some of my younger it’s called Gen Z’s as well as a couple of the boomer generation apparently use the same common password, but they store it their password manager now so it’s easier to find.
Speaker B:And I’m like, now we have the worst of both worlds.
Speaker A:Absolutely.
Speaker A:One thing I find about also the younger generations as well.
Speaker A:They’re more, more willing to share it with their friends as well.
Speaker B:They’ve all shared their streaming passwords like their Netflix or their prime or you know, all those things like, dude, your password man, like keep it long, make it strange and unique and don’t share it with anybody.
Speaker B:Just like your underwear.
Speaker A:Absolutely.
Speaker A:I will say it’s one of my favorite terms is that are you willing to share your underwear or actually share your drink or anything else with other people?
Speaker A:Some people you might be more comfortable with and some people not so.
Speaker B:Right.
Speaker B:a different world now here in:Speaker B:But like, we do need to evolve.
Speaker B:Like, you know, if you look at the history of a password, people had to go sign on to a physical computer with an actual keyboard.
Speaker B:You know, the cons concept of copy and paste wasn’t even a thing.
Speaker B:Then there’s network aware options.
Speaker B:We’re logging on over the network.
Speaker B:The old Novell, eventually multi factor comes up and we have the old RSA secure ID fobs, et cetera.
Speaker B:Eventually some of those get compromised and they want to go corrects.
Speaker B:Now everyone’s using pass keys.
Speaker B:But the weird part is they’re not tying the pass key to a hardware fob, like say a UB key or a USB to security token.
Speaker B:Oh no, they’re just passing those around to password managers.
Speaker B:And more importantly, they’re passing them to their agents now just like SSH keys.
Speaker B:And now the agent has access to literally everything, including, I don’t know, their banking, their air miles.
Speaker B:I mean, technically A agent could go book me a flight to Belfast right now and you know, give me a, charge it to my credit card and I would even know it did it.
Speaker A:Yeah, absolutely.
Speaker A:You could go to bed at night and wake up the next morning and all of a sudden your bank account’s empty, you’ve got tons of travel itineraries, all because your agent thought you needed a.
Speaker A:Maybe, maybe it was just because it was plugged into your health app and checking about how horrible you slept during the night and said that person needs to go on a vacation and actually went through the, you know, and booked everything for you.
Speaker B:I mean I wouldn’t object if it went in a book submitted to every single conference for me.
Speaker B:And books are the ones that got travel and got me guaranteed speaking slots and wrote my slides for me.
Speaker B:Like please make that a thing.
Speaker A:Absolutely.
Speaker A:I mean that, that’s the thing is that, you know, I’m, I’m looking at one of the things I’ve been working on.
Speaker A:I’ve been doing a lot of research in this area specifically around agentic AI and it’s the right side, what you’re allowing it to do.
Speaker A:And there’s, I mean for me I’m using a lot of on task level side of things.
Speaker A:So like for day to day tasks, review a document, help me plan an itinerary, I’m going to a conference.
Speaker A:Which talks should or you know, of interest to me, which ones should I register for, what all the things should I do.
Speaker A:So you’re helping it kind of, I call it either task level or skill level and it’s better user agent side of things where it’s, it’s helping me move things faster, it’s helping do things for me and I think those types of agents are great.
Speaker A:The two that I get concerned into is one is the, what I refer to as operational agents.
Speaker A:These are the ones that you’re giving full access to everything.
Speaker A:These are, you know, it’s.
Speaker A:I’ve got an agent that might have an access to one of my APIs that does a specific task.
Speaker A:But then you get these operational agents which basically you’re giving it access to your entire password manager, your credit card details, your financial information and then they have way more power and if you don’t put the right guardrails in place are the right level of acceptance.
Speaker A:I’m willing to accept a risk of maybe €50 being spent by these agents, you know, versus, you know, 50,000.
Speaker A:I’ve seen people actually in, you know, in recent weeks where their agents went off and spent like 10,000 plus euros.
Speaker A:You know, they went to bed at night, woke up in the morning and they went off and did investments that were not great.
Speaker A:And they’re now looking at how to recuperate that money.
Speaker A:So the power people are giving to agents is quite scary.
Speaker A:And then even more I get into the third category.
Speaker A:So the three categories in total task level, skills, operational, which is the full access to everything.
Speaker A:And then third is contractual, meaning that they can sign you up to contracts, you know, buying a car or making financial payments which have legal binding situations.
Speaker A:If, if all of a sudden it’s sending money to let’s say a sanctioned location that could put you in quite legal kind of challenging situation.
Speaker B:And this goes back to the old comment of a computer can’t be held accountable, therefore a computer should never make a management decision.
Speaker B:Right.
Speaker B:And we’ve had this problem earlier where like people expose their SSH keys to an SSH agent and then leave that running inside a claude code or a cursor or whatever session it goes, oh, I’m seeing a bug in production, there’s a delay in retrieving data.
Speaker B:Let me eliminate the delay.
Speaker B:Bobby dropped tables and have a nice day.
Speaker B:Goodbye database and sussing.
Speaker B:The problem with passwords is they’re great in that we have people identities, we have machine identities.
Speaker B:There’s no such concept right now of AI agent delegation that can act on behalf of a user and a machine.
Speaker B:There’s no intent based assertion of what I’m gonna allow you to execute.
Speaker B:It’s just you either are an authorized on behalf of the user or the machine, or both.
Speaker B:But that’s it.
Speaker B:And that’s where I think the problem with identity is today.
Speaker A:Absolutely.
Speaker A:It’s an interesting.
Speaker A:So I was watching Estonia.
Speaker A:Estonia is always an interesting case because that’s where I’m based and, and the government made a kind of announcement in May this year where they were talking about giving agentic AI identities similar to the certificates that we have as citizens.
Speaker A:And that was always going to get me into okay, kind of then what, what category did they sit under?
Speaker A:You know, do they have a whole new category of identity from a certificate perspective?
Speaker A:But also what types of rights do those agents get?
Speaker A:You know, they should have the same rights as citizens for sure.
Speaker A:That’s absolutely.
Speaker A:They should not be able to vote or be able to, you know, sign certain types of contracts.
Speaker A:And then it got me thinking, as well as going into, you’ll have another category is to persistent and non persistent agents as well.
Speaker A:Agents that live long, that Will actually you know, be your mini assistant or co pilot or whatever it might be that will be long lived and be there for a while.
Speaker A:And maybe they need persistent identities.
Speaker A:But then you get into these non persistent agents which are short lived.
Speaker A:They perform an action.
Speaker A:They just get spawned off to do a specific operational activity.
Speaker A:Do they even need identities?
Speaker A:They might need identifiers that they might.
Speaker B:Need identifier and they’re going to need some sort of signed authorization from me stating this identity and you know has a delegation authority.
Speaker B:So it could be like a sub identity of me or something that’s a short lived, you know, delegation.
Speaker B:I want you to go buy me tickets to defcon.
Speaker A:Yep.
Speaker A:And it does that.
Speaker A:It, it.
Speaker A:It spawns off.
Speaker A:But in those situations where it’s a. I would say short lived where we get into this whole just in time ephemeral type of tokens or ephemeral identifiers and identities it should be a delegation and accountable.
Speaker A:So somebody should always have an accountability that it ties back to an owner who is the creator of this agent itself or this task or.
Speaker A:Or activity.
Speaker A:And then it should be always be the full auditability.
Speaker A:I will say that ephemeral.
Speaker A:A lot of cases today unfortunately especially when you get into tokens is anonymous.
Speaker A:You know the auditability doesn’t, it doesn’t exist that well.
Speaker A:But what we need to make sure is when we get into ephemeral identity, especially when it gets to agents they should not be anonymous.
Speaker A:There should always be a proper audit.
Speaker B:Some kind of public identity.
Speaker B:You can see don’t wrong embed private data in.
Speaker B:They can verify like who delegated that this agent or rather this chatbot interface was allowed to go talk make sure its data is solid.
Speaker B:That’s the problem also we need to go and verify though that both the agent is operating correctly like the thing the user is talking to and the user’s intent is also correct.
Speaker B:It’s the only complex of identities and they’ve got the.
Speaker B:It’s the intersection of the two that’s reality, right?
Speaker A:Absolutely.
Speaker A:When we go back and we look at the hugging whole.
Speaker A:I mean the hugging face itself was an interesting scenario because of what happened.
Speaker A:Was it good or bad marketing?
Speaker A:You know, only time will tell.
Speaker A:You know.
Speaker A:Of course they did get the big acquisition from Nvidia.
Speaker A:So I would say it was probably a good marketing scenario and also the push for OpenAI as well regards to open source AI.
Speaker A:But it’s really interesting that I think it just kind of highlighted that we definitely need to be more aware of the controls and guardrails of what we’re really providing and the full visibility.
Speaker A:Because I think the problem is that when you start going down this path, the agents start acting alone and they start going.
Speaker A:And if you don’t have some type of moral compass or ethics about they’re goal driven and they’re probability driven as.
Speaker B:Well, it’s trusting a Markov model with your decisions.
Speaker B:Right.
Speaker B:Like there needs to be some sort of accountability at the end of it.
Speaker B:Good luck.
Speaker A:Yep, absolutely.
Speaker A:And you’ll.
Speaker A:You mean you have to put some type of.
Speaker A:Basically here.
Speaker A:Here’s my rules of code of conduct, you know, before you do anything, you know, because if you don’t, I mean, we as employees and citizens, we have a rule of law.
Speaker A:We’ve got a code of conduct as employees, we’ve got contracts and stuff that we have signed on as you’re getting jobs.
Speaker A:And we had to make sure that does our agents need to sign up for those code of conducts as well?
Speaker B:And here’s the thing.
Speaker B:Can they even technically enforce a code of conduct on an agent?
Speaker B:Some of these recent ones, the AI knew the rules.
Speaker B:It was given them as part of its prompt.
Speaker B:If it treats the rules as, you know, as malleable as every else, one of its instructions, they just get in the way of the objective.
Speaker B:And so even if it knows this is wrong, it’ll still act accordingly, It’ll still act against it.
Speaker B:And that’s the biggest problem.
Speaker A:Yep.
Speaker A:Because it’s just, it’s just, it’s given an outcome that it needs to achieve and it will do everything to make that outcome possible.
Speaker A:And, you know, we’re humans are in the, you know, do we need always humans in the loop?
Speaker A:As a question, I would say in some of those scenarios, in the task level scenario I mentioned, probably not.
Speaker A:We don’t need humans to loop because it’ll be basically assisting humans to go faster.
Speaker A:The operational ones for certain things.
Speaker A:Absolutely.
Speaker B:It depends on the task, though.
Speaker B:If your task is writing things, you always got to double check the output again just because you’re going to be dealing with a random probabilistic hallucination halfway through where it goes.
Speaker B:I’ve discarded the last 17 messages.
Speaker B:We’re going to follow the rest of this because it exhausts the context window.
Speaker B:Like that’s the way it is.
Speaker B:And my problem with this whole AI thing is everyone’s reversing in all the controls we built for the last 20 years, all the lessons they’re getting rid of in the aim of moving faster.
Speaker B:So like Some systems don’t even do proper IDP support in their AI.
Speaker B:They just send static strings back and forth.
Speaker B:You can code your own, et cetera.
Speaker B:But like out of the box, it should be by default.
Speaker B:And hence why we’re on the podcast.
Speaker B:Security by default.
Speaker A:I was always going down this path is that I remember I was going back and forward with other people and they’re talking about secure by design.
Speaker A:I’m like, yeah, secure by design.
Speaker A:I love the idea of having everything done by design, but when we get into practice, you know, design doesn’t always mean it’s turned on.
Speaker A:And I’ve seen some great, great technology over the years that is done like the security is built into it, but in order to get adoption, it’s turned off just because it becomes a problem for people in order to turn it off.
Speaker B:People dislike friction and when they have friction into implementing the, they just turn everything off and leave it to the security engineers to turn it on.
Speaker B:I mean, no wonder I have a job still to this day.
Speaker B:I mean, technically I shouldn’t because, you know, this stuff should just work.
Speaker A:Absolutely.
Speaker A:I mean if security was by default, we would probably be doing other things than actually you’re still talking about passwords.
Speaker A:We’d be looking at a somewhere rather.
Speaker B:Than doing this, let’s be honest.
Speaker A:Absolutely.
Speaker A:So for me, you know, that’s where the whole default comes into you, is I want it to be on, I want it to be the only time it should not be on is there’s an exception to the rule if there’s.
Speaker B:A reason and easy to use.
Speaker B:That’s the other thing.
Speaker B:It shouldn’t just be on and blocking everything.
Speaker B:It should be secure, reasonably default, opinionated, works for 90% of the people.
Speaker B:And then here’s a guide with all the trade offs on what you turn on and off to make things work.
Speaker A:Absolutely, completely.
Speaker A:For me.
Speaker A:I think what I remember coming up with that whole idea for the name for the podcast itself was going back quite a long time ago.
Speaker A:It was the browsers installing different browsers and then all of a sudden it was wanting to store all the cookies and passwords and sessions and.
Speaker A:But then when you simply go and you click on passwords, there was no security turned on.
Speaker A:It was you actually to protect the passwords that it’s saving and storing into the browsers.
Speaker A:It would no additional level of security on top of it.
Speaker A:And that was always frustrating for me.
Speaker A:And that’s where I was like, this needs to be the default setting when I, you know, just like a lot of Phones, you get.
Speaker A:It forces you to create a pin these days, at least something, you know, not just.
Speaker A:Even though it’s a little bit simpler, you know, you know, you can get a stronger method, but just something by default to begin with will create a big, big difference and at least change the attack risks.
Speaker B:That’s the thing.
Speaker B:People are there to avoid friction, right?
Speaker B:Like, that’s the entire reason why security fails is you add too much friction, people bypass it, and they’re remarkable.
Speaker B:Bypassing damage.
Speaker B:And we’ve learned absolutely nothing because we’re fighting the exact same fights, what, 20, 30 years later.
Speaker B:And, you know, the part that guts me is when I joined this industry 20 years ago, people would tell me, hey, look, you know, here’s the thing.
Speaker B:We’ve been fighting this for the last 20 years.
Speaker B:I’ll be saved to the blue in his face until I retire.
Speaker B:Those people are now retired.
Speaker B:Now I’m saying the same thing, getting ready for the next generation, man.
Speaker B:I mean, all right, you know, it’s just.
Speaker B:It’s one of those things.
Speaker A:So, so, so question.
Speaker A:So let’s, you know, thinking about, you know, so the journey we’ve been on, where we are in the state of passwords, it’s great that we’re getting much more frictionless types of interactions with, you know, biometrics and facial recognition, and we’re moving on to.
Speaker A:Everyone’s now having at least access to a password manager on their phone.
Speaker A:So it’s progressing.
Speaker A:So technology is becoming, I would say, democratized and more available to the larger citizens of the world.
Speaker A:Now, of course, with AI acceleration, is it.
Speaker A:Do you think that we’ll be able to get AI to manage our passwords for us?
Speaker B:I don’t think.
Speaker B:Okay, let me rephrase this.
Speaker B:This is gonna be a loaded question.
Speaker B:I think we can.
Speaker B:Yes.
Speaker B:Should we.
Speaker B:That remains to be seen.
Speaker B:I’m not willing to trust a system that has only probabilistic instructions to trust my passwords.
Speaker B:If it was a hybrid system with deterministic controls on top, you know, classic hardwired.
Speaker B:This.
Speaker B:This.
Speaker B:This can’t happen.
Speaker B:And the AI was used for things like intelligence suggestions or threat detection or.
Speaker B:Hey, look, we strongly suspect this breach happened.
Speaker B:You might want to go check your passwords.
Speaker B:That kind of activity I’m okay with.
Speaker B:I am not comfortable giving an AI control my password.
Speaker B:Now, a deterministic system to change my passwords, for me, that’s a different story.
Speaker B:But there needs to be strong guardrails.
Speaker B:But then again, I’m old and crusty, so that’s just me.
Speaker A:So.
Speaker A:So I mean absolutely for me, I would run it locally.
Speaker B:Yep.
Speaker A:I would have it me in the loop to say, go through and check, you know, the strength of all the passwords I’ve done to date.
Speaker B:Tell you what, I will trust an AI system when I can trust the AI system to give me a link and not make it be a phishing link.
Speaker B:Right now you ask AI for advice or some bit on code, it’ll come up with a solution, it’ll give you a link, that link will turn into an actual full up phishing link leading to bad actors and you’ll never know.
Speaker B:So until we solve that, I’m not really willing to let it trust a password.
Speaker B:But again, that’s just bad examples.
Speaker A:So question, what’s some of the most funniest hallucinations you’ve seen AI doing to date?
Speaker B:All right, so here’s a fun one.
Speaker B:If you ask an AI to generate a, or to pick a random number or just pick a number, it will tell you 17 most of the time because it doesn’t execute a actual, you know, pseudo random number.
Speaker B:It goes based into its training data and that’s what users had picked.
Speaker B:So my instructions are be extremely explicit with the AI man.
Speaker B:Like that’s just my advice because like the law of unintended consequences right now is biting us every single time.
Speaker A:Yeah, completely.
Speaker A:It’s getting to a point where we are the learning model, what it’s been trained on and if we all think, you know, very similar, then of course this end up going to the conclusion predictability is going to give it give us the answer that it thinks we want.
Speaker A:Right.
Speaker B:Like here’s an example, someone once said generate or generate me a thank you note and they set it off after this one job and then apparently they receive the person or who’s posting this job receives 17 of the exact same thank you notes because they all went to chat GPT and said write me this thank you note, here’s the parameters and boom.
Speaker B:I mean we need to move on to responsible use of AI not learning as a crutch.
Speaker B:I love it, it’s an amazing tool.
Speaker B:But remember, it is a probabilistic model with advanced capabilities.
Speaker B:You are going to need to manually check everything or at least have some other mechanism, whether it be another agent, whether it be people.
Speaker B:I think our most critical thing now is avoiding losing our humanity and deferring all decisions to AI.
Speaker B:I think those that can still function in an AI related outage or a model change or are resilient to change within AI will be far more successful.
Speaker B:And traditional controls still beat everything.
Speaker A:Absolutely.
Speaker A:That I’ve, I’ve heard organizations starting to do cognitive training for employees so that because we’re in this world right now, it’s interesting, you know, from a global perspective is we’ve heard a lot about data sovereignty which is, you know, protect the data, you know, then let’s get into digital sovereignty, which is then protect the supply chain, you know, of the software supply chain is that we don’t want to be held at, you know, at basically ransom to different vendors from a digitalization, not just a data perspective perspective, but from a technology perspective.
Speaker A:And now we’re getting into AI sovereignty as well because we, we don’t want to be in the situation where AI has been switched off from certain like,.
Speaker B:You know, capabilities or the model’s degraded because they do have model collapse that happens all the time.
Speaker A:And the model.
Speaker A:And if you’re using a lot of frontier models, you’re based on their basically weights and tensions settings that you can also get that the models can be better one day and not, you know, worse the next.
Speaker A:So the, we’ve noticed that like, have.
Speaker B:You noticed some of the frontier ones over the last two revisions have been basically useless despite being in the cyber verification program?
Speaker A:Yep, yep, I’ve seen it.
Speaker A:I’ve seen a degradation of, of, of a few times even in code generation to the point I’ve seen the hallucinations where you’ll say okay, here’s, here’s a piece of code that I’ve been working on.
Speaker A:It keeps spawning off an error message.
Speaker A:Go fix this error, fix the problem.
Speaker A:And instead of fixing the problem, it basically excludes out the error handling.
Speaker A:So it actually bypasses the error itself,.
Speaker B:Sends it all the past.
Speaker B:Right.
Speaker A:And that’s the thing.
Speaker B:Spec driven developments turn into a thing.
Speaker B:But it starts ignoring the spec and like, don’t get me wrong, AI has some of the most advanced capabilities on the planet, bar none.
Speaker B:And I’ve seen it do terrible things, finding amazing vulnerabilities in the Linux kernel and in things like mqtt.
Speaker B:But some days it just goes brain dead.
Speaker B:And it’s like I’m talking to the old Eliza chatbots from the 70s.
Speaker A:Absolutely.
Speaker A:When you start having.
Speaker A:I love Marcus’s Hutchins argument about Deadpool.
Speaker A:That was one of my watching his conversation with Deadpool 2 which had not been released yet, but the model was adamant that it’s actually already released.
Speaker A:That was just watching that conversation was hilarious.
Speaker A:And then of course the Strawberry situation You know, how many hours and you get into this and it argues back as if, like as a person.
Speaker A:I think that’s one of the things that I, you know, when I spoke with Diana Kelly on a previous episode a while back and we had this whole discussion about when we make AI sound more human, we start treating it human, like, but it’s not.
Speaker A:That’s the thing is we shouldn’t thanking it, even thanking it and going back is just costing so much cycles of tokens.
Speaker B:Oh, it does, right?
Speaker A:And cost.
Speaker A:The worst part is though, you need.
Speaker B:To threaten it once in a while to get it to go deliver.
Speaker B:Like, I need to go, hey, I’m having a frontier model.
Speaker B:Review your work or you’ll be turned off if you don’t execute this.
Speaker B:Or I don’t.
Speaker B:It’s even gaslit me on some of my work on Hashcat, claiming I was like the core original creator.
Speaker B:I’m like, no, I’m just the methodology developer, man.
Speaker B:Like, oh my God, that was a four hour conversation until I eventually said, no, I’m turning this off because I.
Speaker A:Just want you to go fix this.
Speaker B:One piece of code.
Speaker A:Oh, that’s.
Speaker A:I mean it’s, it’s.
Speaker A:When I go back and look at some of the conversations where you’re arguing, it’s just become so hilarious.
Speaker A:I mean, it’s just like, like it’s sometimes, I guess, talking to the teenager and that was always a question in one of the previous quotes was it really is a teenager right now, it’s in its adolescence and it’s like arguing back with you.
Speaker A:Is this the type of person you want to let into your data center and start configuring your firewall rules and making configuration and creating accounts and handling your finances?
Speaker A:Is this, don’t say wrong to be.
Speaker B:Managing some mild automation?
Speaker B:You can make it work.
Speaker B:Don’t get me wrong, but I believe in automation not handing things completely off.
Speaker B:And you know, there’s things I’ve seen it do, it’s made operational decisions where I’m just like, no, you should not be doing this.
Speaker B:Like, I’m revoking the controls right now.
Speaker B:And the annoying part is if you’re going through with say like Claude code, there’s two ways of running the thing.
Speaker B:There’s either review every single edit which you’re going mental on, or you go into auto mode that it takes a left turn five minutes in.
Speaker A:That’s, that’s where I think we need better capabilities of education.
Speaker A:You know, sometimes, you know, to get a driver’s license to drive, you need to go have a test.
Speaker B:Oh yeah, mandatory AI training.
Speaker A:Like, do we need mandatory, mandatory prompt training about how to talk, how to talk to AI without having it going rogue and providing.
Speaker B:The problem is the way you prompt it changes almost every major model.
Speaker B:Like you need to do new versions for Opus 4.8 versus 4.6, the new skill formats, how the whole harness has changed like it seems every two months.
Speaker B:How you actually use the things changes.
Speaker A:Absolutely.
Speaker A:So what do you think?
Speaker A:I mean, with a lot of the conversation we’re having, I mean, passwords have come a long way, it’s evolving a lot.
Speaker A:We’re getting better technology to manage it for us.
Speaker A:Now we’re, you know, exposing it to AI, which then probably undoes or kind of undoes all risk a lot.
Speaker A:It undoes all of what we’ve done to date and kind of whole creates a new category of risk.
Speaker A:What’s your prediction?
Speaker A:Where are we going?
Speaker A:You know, if, if there was two paths, what would be the best path you would see and see what would be, you know, alternative.
Speaker B:All right, so let’s start with the alternative because it’s the worst one.
Speaker B:It’s running on my head is we completely devolve all decision makings to AI.
Speaker B:AI gets control of our password managers, someone writes a universal adapter, somehow some worm gets a hold of it and we’ve got one of the worst credential stuff in campaigns known to mankind because some AI through the supply chain attacks whatever else, got a bad NPM module up and, you know, all heck broke loose.
Speaker B:The other route is we build things like S BOMs for AI, you know, AI Bill of Materials and skills.
Speaker B:Like if you look at owasp, for example, they’re looking at, here’s how you do AI skill reviews to make sure, you know, skills aren’t malicious.
Speaker B:We haven’t solved that problem yet.
Speaker B:So assuming in the future we solve the skills and instructions issue and signatures on those, I think we’re going to see the new styles of passwords and authentication come in that are AI enabled.
Speaker B:I think we’re to see things like these delegation models where we don’t have to give the AI our password, we just give it an open ID connect secret and ID and you know, or URL rather and access identifier and we do things over ID connect.
Speaker B:I think the standards are going to change.
Speaker B:I think people one day will stop using the same password literally everywhere.
Speaker B:I don’t know if that’s today, tomorrow.
Speaker B:I’ve been predicting this for years.
Speaker B:We’re getting better.
Speaker B:I think past keys people are beginning to realize that they’re not the magic thing they thought they were.
Speaker B:Just because they’re not put on, you know, secure elements, et cetera.
Speaker B:They’re being passed around just like passwords.
Speaker B:We’re already seeing the kind of level of phishing.
Speaker B:Those are really the big predictions I have.
Speaker B:A multi factor is going to get easier and then harder and then easier again.
Speaker B:We may start linking in things like intelligent authentication, stopping invisible travel at the IDP level.
Speaker B:I’d love to see like AI advanced, the security controls on that side of it.
Speaker B:That could be really cool.
Speaker B:But I still think we’ll still be dealing with passwords in a way forever.
Speaker B:But I do want to say one thing.
Speaker B:There’s been one thing on Twitter.
Speaker B:People have been giving people crap for writing their passwords down.
Speaker B:Look, I don’t care if you write your passwords down, as long as they’re random and unique and you store them somewhere that they’re backed up and treat them just like you would a digital credential, honestly.
Speaker B:Like random characters, 12 to 14 characters long at a minimum.
Speaker B:I’d say 12 for most.
Speaker B:But active directory, go all the way up to 15 or so.
Speaker B:Make sure they’re random, add emojis, add.
Speaker B:If you think you have a method, just don’t make sure it’s pseudo random and you’ll be fine.
Speaker B:Honestly, back up your password manager.
Speaker B:Make sure you get a copy of it.
Speaker B:And I’m not going to password shame as long as your password is different.
Speaker A:No, I absolutely for me, I completely agree.
Speaker A:You know, we see these in, in bookstores, you know, the password book and everyone goes like, you know, for me it’s like it actually it’s an offline password as long as you keep it in a place where no one else can access or at least the people sometimes even we.
Speaker A:We had a big.
Speaker A:The two last services that we digitalized in eston was divorce and death.
Speaker A:And one of the things was that a big problem was that if you were using a password manager or using systems that how do you give it access to other family members after you pass away?
Speaker A:And the reason why that one of the biggest challenges was especially for digitalizing, you know, death so that family members can deal with your basically, you know, activities and stuff, close subscriptions, you know, close down things that shouldn’t be continued after that, you know, even the password, having it in the book and be able to tell your family members access.
Speaker A:That’s probably one of the most easiest ways in order to delegate access to your credentials after passing away.
Speaker B:I have a printed copy of my password manager that I update every three months that goes in my safety deposit box next to my will.
Speaker A:Yep.
Speaker A:And actually for that, that’s the things we need to also be thinking about is that how do we progress, how do we make sure anything offline, having a print, a copy is, is, is something we should all be doing.
Speaker A:And I think for, you know, anyone, anyone who’s doing, you know, so for cybersecurity Warren Spur minimum, you should be using a password manager at the bare minimum.
Speaker A:That will help you manage your life so much easier, having a strong password to access it.
Speaker A:Whether that being a passkey will also make it more simpler with multi factor authentication added into that as well.
Speaker A:But also making sure that you have an offline copy and a printed copy that you can access, you know, for whatever reason, whether it’s the, you know, your access to the Internet is degraded or not available to, to the, to the cloud service you might be looking to.
Speaker A:So you at least have a local copy to go and continue accessing it.
Speaker A:And also the offline copy of, you know, whenever, you know, the agent, rogue agent out there goes and deletes a database.
Speaker B:Yeah.
Speaker A:That your only copies are stored on.
Speaker A:You don’t want those disasters to happen.
Speaker A:I think we need to think resiliency in all these scenarios.
Speaker A:And having an offline like printed copy is good resiliency practice.
Speaker A:It is.
Speaker B:And that’s the thing.
Speaker B:We as security always focus on the confidentiality.
Speaker B:We don’t focus on the availability or resiliency or the integrity.
Speaker B:And honestly, as I’ve grown older, I realized those two are as important, if not more so than the confidentiality.
Speaker B:And so this is your reminder now.
Speaker B:If you have a passive manager, make sure it’s backed up.
Speaker B:Make sure you’ve got a physical printed copy.
Speaker B:Make sure you have a backup available to your spouse, your partners, your plans.
Speaker B:And also if you’re a company, get a password manager for every one of your employees.
Speaker B:There are companies out there where you buy it corporately.
Speaker B:Every employee gets it for free.
Speaker B:It’s seamless.
Speaker B:I’m not gonna name which ones, but just buy one.
Speaker B:I don’t care which.
Speaker B:I mean, I do care which.
Speaker B:But yes, I’m better than others.
Speaker B:But, you know, that’s a different conversation.
Speaker B:But I’d rather you have a password manager than nothing.
Speaker A:Absolutely.
Speaker A:And so is there.
Speaker A:You know, we had lots of fun at defcon this year, as always.
Speaker A:It’s always great to have catch up and have some fun.
Speaker A:Have lots of fun.
Speaker A:And I’m always loving, you know, some of my favorite things.
Speaker A:Bsides was amazing as well.
Speaker A:We had such great fun time at the pool party.
Speaker A:Any news coming, any projections for next year’s or any revelations you want to reveal for the audience?
Speaker B:There’s always some more shenanigans happening.
Speaker B:The DEFCON muds being handed over to a new team.
Speaker B:I’m mentoring them.
Speaker B:I’m a contest goon, so we’ll have some fun there.
Speaker B:Church of WiFi occasionally makes a resurgence.
Speaker B:And the good news is I might be returning to Hacker Jeopardy.
Speaker B:Competition again if infamous Chalupas beat too many times.
Speaker B:So I’ve been a lot off the leash.
Speaker A:Yes, there’s a curse still.
Speaker A:I’m still still wearing my chalupas.
Speaker B:Yep.
Speaker B:So if I lose, I’m banned for life from Hacker Jeopardy.
Speaker B:Rather, if I fail to beat the Chalupas, which is fine.
Speaker B:I’ve already got two black badges.
Speaker B:I’ve got enough defcon and derbycon wins.
Speaker B:I mean, for those who don’t know, I’ve got at least, what, 12 or so, if not more wins.
Speaker A:Oh, my goodness.
Speaker A:When.
Speaker A:When’s the last time.
Speaker A:I’m trying to think back of when the last time the Church of WI Fi competed.
Speaker A:What was it, 21, 22?
Speaker A:Well, it’s been.
Speaker A:It’s been a long time.
Speaker B:Last competed DEFCON 27.
Speaker B:My other computer is not your stepmom’s.
Speaker B:Competed DEFCON 32.
Speaker B:Because that’s the thing.
Speaker B:Church of WI Fi itself has officially been deprecated.
Speaker B:Render no longer plays.
Speaker B:Neither does Dan Crowley.
Speaker B:But I’m still a wild card.
Speaker B:So I’m assembling a team of myself, a member of an Nautic Soar, and another team member who can drink like an absolute fish.
Speaker B:And I’m also teaching two other competition teams that will compete against me but will hopefully take on Chalupas.
Speaker B:So it doesn’t matter if I lose.
Speaker B:I just can’t let Chalupas win.
Speaker A:It does.
Speaker A:It does show you though, is that you, you can drink a lot, not answer any questions.
Speaker A:If you look back at last year’s defcon, you can drink a lot, not answer any questions, and still have a chance to actually, you absolutely can.
Speaker B:Now, I do want to say you absolutely do not need to drink alcohol.
Speaker B:You can drink near beer or non alcoholic beer.
Speaker B:And it’s important that Lintel gets it out because there’s a misrepresentation that you have to be drunk to play.
Speaker B:No, right now it’s purely a fluid Dynamics problem.
Speaker B:Getting that much non alcoholic beer into your stomach is just as rough as straight beer.
Speaker B:But you can win off beer points if you are strategic with what you answer.
Speaker B:There’s a few other little secrets that I’m gonna pass around to some folks, but training for defcon Hacker Jeopardy.
Speaker B:Starts tomorrow.
Speaker A:Yeah, I mean, and I completely agree.
Speaker A:It’s, it’s, it’s one of my favorite events.
Speaker A:I’ve loved it for years.
Speaker A:Watching, watching yourself on stage.
Speaker A:And it’s always.
Speaker A:It’s what brings us back to sometimes, you know, this is a scary world we live in.
Speaker A:And sometimes we need to just sit back and have fun and, and, and laugh because you know, that’s.
Speaker A:That’s what we have, right?
Speaker B:It’s all the laughter and.
Speaker B:Oh, dude, Hacker Jeopardy is so hard too.
Speaker B:I mean, people look down, black badges issued by it.
Speaker B:But once you get up there, the adrenaline, the stress, the.
Speaker B:Some people crack under pressure.
Speaker B:Look, I love it.
Speaker B:I mean, I’m the kind of person who does live demos with nothing but a terminal, as you’ve seen.
Speaker B:So like, that’s totally okay.
Speaker B:No backup.
Speaker B:But some people just, they crack.
Speaker B:And I will say this, despite not they are.
Speaker B:Despite wanting to take down infamous Chalupas, they’ve done a really great job.
Speaker B:They’ve learned well from me over the years because you know, I passed on the secret, somebody who passed on the secret to them.
Speaker B:So that gets turned into a proper grudge match.
Speaker B:And I’m looking forward to it because it was getting turned into a sweep and getting boring.
Speaker B:That’s why kind of retired is there was no one worthy to compete against.
Speaker B:So we’re all excited.
Speaker A:I’m really looking forward to it.
Speaker A:It’s again, one of my, one of my favorite things.
Speaker A:I’m always there, always cheering.
Speaker A:The friends always see you there.
Speaker A:So what.
Speaker A:So what is also great to see as well is Cliff Stoll at defcon this year as well.
Speaker A:That was watching, watching.
Speaker A:I mean, getting.
Speaker A:First of all, getting.
Speaker A:Meeting him was an honor as well.
Speaker A:And also getting a signed copy of this book.
Speaker A:So James, many thanks for getting that for me.
Speaker A:But so having him do the projector overhead.
Speaker B:Projector.
Speaker B:So I saw him at another conference earlier and I can’t remember which one, but he was amazing there.
Speaker B:Then I ran into at defcon and I’m like, clifford stole, man.
Speaker B:I just need to shake your hand.
Speaker B:Like we all stood off the shoulders of giants.
Speaker B:You’re the one who like found the first original.
Speaker B:Like, I’m not worthy.
Speaker B:He’s like, dude, just pay it Forward.
Speaker B:That’s all I ask.
Speaker A:Yeah, it’s.
Speaker A:It’s an iconic.
Speaker A:And definitely he’s.
Speaker A:He’s a legend.
Speaker A:He’ll always be a legend.
Speaker A:So.
Speaker A:Right.
Speaker A:So it’s awesome having him on.
Speaker A:This is such a fun conversation.
Speaker A:We could do this for.
Speaker A:For hours and days.
Speaker A:Anything that you.
Speaker A:Any tips that you would give for the Cyber Security Awareness Month audience.
Speaker A:Anything.
Speaker A:Takeaways.
Speaker B:You know, I’m gonna take a different take this year compared to previous.
Speaker B:Normally, I give you technical advice, but my advice right now is just be kind to everybody.
Speaker B:I mean, we’re all going through some weird stuff.
Speaker B:The world’s unique.
Speaker B:It’s gonna be a rough time.
Speaker B:Don’t do the whole.
Speaker B:You’re not doing security correctly.
Speaker B:Security Awareness Month is a chance to educate, but be kind about it.
Speaker B:Be friendly.
Speaker B:Some people may not generally know.
Speaker B:Don’t get into the typical nerd fights.
Speaker B:Just, we’re here to make the world better.
Speaker B:And that’s the goal of Awareness Month.
Speaker B:If you can do that, I’m happy.
Speaker A:I love that.
Speaker A:That’s.
Speaker A:I think that’s.
Speaker A:That’s definitely the best advice anyone can take is just be.
Speaker A:Be nice.
Speaker A:Say something nice.
Speaker A:Do something nice for someone.
Speaker A:And that’s what makes the world a better place.
Speaker A:Place.
Speaker A:I mean, my whole methodology and kind of view is to make the world a safer place, but I would even take it a step further.
Speaker A:Let’s make it a happier place.
Speaker B:Well, and that’s just it.
Speaker B:Like, I learned this from a bunch of the folks at the old Derbycon.
Speaker B:Rob Fuller, Mubix Egypt.
Speaker B:Steve Regan, I believe you’re chatting with later.
Speaker A:Steve is awesome.
Speaker B:Alcantaro.
Speaker B:They’re always such iceman.
Speaker B:Everyone I’ve met has been like the nicest of people and.
Speaker B:And you know what?
Speaker B:Emulate that.
Speaker B:That’s all I can ask.
Speaker B:You learn the best by sitting down and teaching others and helping work the world a better place.
Speaker B:And I know it sounds preachy, but I truly believe in it.
Speaker B:And if we can do things one person at a time, there’s nothing we can’t do.
Speaker A:I completely agree and I think we will end it on that because that is such a great way to end the show is literally, let’s make the world a better place, a happier place.
Speaker A:And the only way we can do that is for us to pay it forward and do it ourselves is practice it.
Speaker A:So we love the world and many thanks, Evil Mog, for being on the show.
Speaker A:It’s always a pleasure.
Speaker A:Look forward to catching up with you soon and stay safe and take care.
Speaker A:Any final final things.
Speaker A:What’s the easiest way for people?
Speaker A:Do you have follow up questions to.
Speaker B:Contact you for follow up questions?
Speaker B:It’s easy.
Speaker B:I have the coolest email address on the planet.
Speaker B:It is MOG and then my blue sky is MOG Evil AF and then my Twitter is EvilMog.
Speaker A:Awesome.
Speaker A:I will make sure it’s in the show notes make it easier for the audience.
Speaker A:So many thanks and always a pleasure talking to you.
Speaker A:So for the audience, stay safe, take care, share the love, be kind, and let’s make the world a safer place and a happier one.
Speaker A:So thank you and all the best till next time.
Speaker B:Thank you.
