Back to MCSC_2026

DEF CON Meets MCSC 2026: Why policy hast failed to address the risks of next gen technologies?

533 lines English Added about 1 month ago

Transcript:

533 lines
(speaker_0)

Okay.

(speaker_0)

So for this panel, we've heard a little bit about the, the mm- movement of AI, we've heard about civil society and, um, maybe some agency around that.

(speaker_0)

In this one, we're gonna talk a little bit more maybe about the role government regulation, um, some of the things we can possibly do about this, why haven't we done some of the, what we would consider easy things by now.

(speaker_0)

Uh, and so, uh, Daniel's involved with, uh, UK Government Cyber Advisory Board.

(speaker_0)

Jake was at ONCD.

(speaker_0)

Uh, Luis was, uh, i- in a prior life at ICANN, so a bit of internet...

(speaker_0)

yeah, a little bit of internet governance.

(speaker_0)

Now, you're at RUSI, so a little bit of think tank, right?

(speaker_0)

Perri was a special assistant to the director of DARPA, so a little bit of insight on how research agencies and governments think about this.

(speaker_0)

So we've got a mix of, of perspectives.

(speaker_0)

Um, one of the things I, I want people to think about, and I realized I didn't bring this up earlier, um, was why, why do we think there's only one Internet Archive and it's in America?

(speaker_0)

Why is there one Signal in America?

(speaker_0)

Why is there one Wikipedia in America?

(speaker_0)

Why is there one Let's Encrypt certificate authority that provides free certificates for the planet in America?

(speaker_0)

Come on, guys.

(speaker_0)

Get with the fucking program.

(speaker_0)

We need some more diversity.

(speaker_0)

Th- there's a fundamental problem.

(speaker_0)

Why aren't there three in India and five in China and eight in Europe?

(speaker_0)

Like, something is going on here and we don't understand it.

(speaker_0)

If Signal's $50 million a year, let's say Let's Encrypt's $50 million a year, I think I saw some math that Internet Archive could do about $100 million a year.

(speaker_0)

Well, we're talking $400 million, $500 million, and nobody is willing to put that up, but we'll spend billions on mining, you know, Bitcoin or something.

(speaker_0)

So I just wanna...

(speaker_0)

I wanna say that there's, there's something going on where either governments aren't prevening- providing the correct incentive structures, or for some weird reason, all the incentives exist in the States and they don't exist anywhere else, which I don't, I don't believe.

(speaker_0)

Um, okay.

(speaker_0)

So, the topic for this panel is regulate the outcome, um, and we talked a bit about it briefly before.

(speaker_0)

W- we seem or government seem obsessed with regulating the steps, not the outcome.

(speaker_0)

And my goal here with bringing this up is if we could regulate...

(speaker_0)

if we could think about the outcome, ch-...

(speaker_0)

let's say, as a society, we decide, uh, privacy-preserving technology should be the norm, or, uh, there should be low tr- uh, switching costs.

(speaker_0)

I'm on a social media platform, I should have the right to back up my social media identity and be able to transport it somewhere else.

(speaker_0)

It should be in a machine-readable format.

(speaker_0)

Um, we should have the right to repair.

(speaker_0)

Whatever the foundational model we go with then can be applied to whatever the generation of technology is.

(speaker_0)

So, if it's a right to repair, what does that mean to AI?

(speaker_0)

If we have the right to be transportable, what does that mean in AI or in any other model?

(speaker_0)

But since we don't seem to ever really regulate the outcome, it doesn't feel like we'll ever get ahead of these situations.

(speaker_0)

So, in, in, in various work and when you're advising people, um, am I fixating on the wrong thing?

(speaker_0)

Is regulate the outcome a worthwhile goal, um, to increase our, uh, government's ability to regulate intelligently, or are we just gonna be talking about...

(speaker_0)

And I, I...

(speaker_0)

one other aside Jake and I were talking about.

(speaker_0)

We've been going to security conferences for 20-plus, 30 years, and, you know, we have not said we need, uh, threat intelligence-sharing, we don't need...

(speaker_0)

what was the other one?

(speaker_0)

Uh...

(speaker_0)

Public-private.

(speaker_0)

...

(speaker_0)

public-private partnership, right?

(speaker_0)

You're gonna get kicked off the stage if you were saying that.

(speaker_0)

There's, uh, e-...

(speaker_0)

there's just certain things that we always fall back on as crutches that never deliver, but yet we keep repeating them, and so I'm trying to move the conversation away fr-...

(speaker_0)

Workforce development, yeah.

(speaker_0)

Okay.

(speaker_0)

Go for it, guys.

(speaker_0)

Perri's in for the kill.

(speaker_1)

Things that Perri's going.

(speaker_0)

Okay.

(speaker_0)

Yes.

(speaker_2)

Oh, dear.

(speaker_2)

I, uh...

(speaker_2)

I put myself on the chopping block with that one.

(speaker_0)

Yeah.

(speaker_2)

Uh, as you're talking, I, I...

(speaker_2)

and I am going to give the caveat that I am coming on stage after Meredith and I'm about to say something about cryptography.

(speaker_2)

Uh, and it will only be a letdown.

(speaker_2)

But, uh, eh, something that strikes me as you're talking about a number of these technologies and government, uh, intervention and regulation is the export control space, which had really deleterious effects on, uh,

(speaker_2)

cryptography and the ability to make and sell cryptographically secure products in the, uh, 2000s in the United States.

(speaker_2)

This is also true more broadly.

(speaker_2)

And and that was a space where, in some ways, there were lessons learned.

(speaker_2)

These, uh, controls were relaxed, but now we're starting to see the same approach occur with AI and regulating how that is shared, regulating how that is used, and this is coming at a time where there's a number of open source models.

(speaker_2)

And so, as you're talking about cert-...

(speaker_2)

uh, uh, certs, free certs, as you're talking about the Internet Archive and Wikipedia, right, one also, uh, thinks that the next generation of that is going to be these open source models, these frontier models, and how those are...

(speaker_2)

how those are regulated and who is allowed to put those out and who is allowed to use them and package them.

(speaker_2)

And I think there is a significant risk to trying to, as you put it, regulate the, uh, uh, regulate the steps.

(speaker_3)

...

(speaker_3)

rather than regulate the actual outcome and how it is used.

(speaker_3)

Because you're going to really, uh, uh, uh, dampen creativity, you're going to dampen the ability to create, and you're going to s- uh, centralize it in the hands of, uh, a few, uh, companies, governments, you know?

(speaker_0)

A- and it reminds me of, like, in China th- their approach to AI is they do regulate the outcome of AI.

(speaker_0)

It has to be, uh, a politically accurate result from the search.

(speaker_0)

And you can argue all day long that that's not technically possible, these models will spit out other things.

(speaker_0)

And the political apparatus in China has decided that's irrelevant, right?

(speaker_0)

Their- the outcome must be conformant.

(speaker_0)

Uh, so you don't necessarily even have to regulate reality.

(speaker_4)

A- although, I mean, w- we're no better, uh, at least, uh, you know, across, uh, the- the West.

(speaker_4)

I know when...

(speaker_4)

in the Biden administration, we were, um, you know, very worried about AI being racist and sexist and all these things, and we were, like, really focused on the executive order and so on, trying to say, "Well, you should only train your data on...

(speaker_4)

or you...

(speaker_4)

to only train your models on this data that's gonna- gonna stop it from being racist and stop it from, you know, having bias and so on."

(speaker_4)

Um, and then, of course, Musk and those guys come in and say, "Oh, you're woke GPT," you know?

(speaker_4)

It shows all the- the famous picture of the people signing the De- the Declaration of Independence, and they're- they're not all white men, which, of course, is who signed the Declaration of Independence.

(speaker_4)

Um, and so, like, we're...

(speaker_4)

uh, I- I don't know how much bad...

(speaker_4)

I mean, okay, fine, we're not as bad as the Chinese.

(speaker_4)

But we're...

(speaker_4)

I don't know if we're much further down the road in a good way, uh, than they are.

(speaker_3)

I think, I think it's usually...

(speaker_3)

I mean, to your point, Geoff, why is it...

(speaker_3)

like, why are we not regulating outcomes?

(speaker_3)

To be honest, because it's easier not to, right?

(speaker_3)

It requires thinking about what Meredith had mentioned about the structural incentives, and maybe we are not up for conte- you know, contesting some of those.

(speaker_3)

And it's interesting, as you were talking, I was thinking about something that's potentially quite boring nowadays, because now everything's about AI, but I was thinking about the discussion about the right to be forgotten, you know, good old days, where we were talking about GDPR and, like, the

(speaker_3)

implementation of GDPR, right?

(speaker_3)

And I remember these conversations, these fiery conversations, you know?

(speaker_3)

Back then, I was working in, like, civil society academia, and we were talking about, like, how is Google gonna de-index, like, all of these kind of things, right?

(speaker_3)

And that, for me, is not regulating outcomes.

(speaker_3)

That is, again, another example of how we focus on these intermediary steps instead of going to the structural incentives, right?

(speaker_3)

Um, and that, and that's why I think, you know, again, to your point, why don't we do that?

(speaker_3)

Because it's easier.

(speaker_3)

Are we really, really willing to...

(speaker_3)

on the AI conversation?

(speaker_3)

Because nowadays, the right to be forgotten has become obsolete, you know, with- with the context of AI, with how much data can be scraped and how much you can index if you ask AI, "Give me some information on this name."

(speaker_3)

Or even Google, right?

(speaker_3)

I mean, with Google's, like, AI feature as you search for a person's name, like, it will show up, like, lots of things and a summary that's pretty accurate of that person, right?

(speaker_3)

Um, so that, for me, is a clear example of our- our- our lack of clarity.

(speaker_3)

I don't think it's lack of, um, willingness.

(speaker_3)

I think it's lack of clarity of how we go from point A to point B, which point B being regulating the outcomes.

(speaker_1)

I- I want to add to that.

(speaker_1)

I think it's easy, but I also think there's a political element.

(speaker_1)

It's also scoring political points for the voting masses, right?

(speaker_1)

So, let's take Australia with their wild thing of banning social media for people under 16.

(speaker_1)

Job's good done, right?

(speaker_1)

We've done it.

(speaker_1)

We fixed the problem.

(speaker_1)

W- it's too hard to go after tech giants, 'cause they're- they're big and tough.

(speaker_1)

So, what we've done is we've made life miserable for kids under 16, right?

(speaker_1)

Voters love it, so you don't have to use social media.

(speaker_1)

Unfortunately, you're gonna have the situation where kids are going behind the bike shed to do social media, like they do cigarettes and alcohol and everything else.

(speaker_1)

But it scores political points because the voters go, "Look, the government's doing something."

(speaker_1)

It's regulating the tools out of existence rather than doing the harder thing of, actually, what are we trying to solve?

(speaker_0)

I was gonna...

(speaker_0)

Uh, we were in the green room a little bit earlier, and we were joking around, like, "Well, okay, what- what is the regulated outcome model that we could hold up as a success?"

(speaker_0)

And I think, I think we had, um...

(speaker_0)

It's illegal to prevent you from unsubscribing to a mailing list.

(speaker_0)

Like, it's a spam solution.

(speaker_0)

There's regulation pretty much everywhere that says it's criminal to not allow somebody to unsubscribe from an email.

(speaker_0)

That's about it.

(speaker_0)

We regulated, like, one spam outcome.

(speaker_0)

And how successful is that?

(speaker_0)

Do we still get spam, you know?

(speaker_0)

So, I kind of, I'm kind of with you that- that- the incentives must be wrong or something's misaligned, but it seems like if, uh, regulating the steps isn't working, what are we left with?

(speaker_0)

No regulation or regulate the outcomes?

(speaker_0)

Maybe it's time to try the outcomes part, and maybe the outcomes requires more involvement from civil society or researchers or academics in the technical area, because we can speak truth to power.

(speaker_0)

We can say, "Hey, this is realistic.

(speaker_0)

This is not realistic."

(speaker_0)

Because I don't...

(speaker_0)

Microsoft might not tell you this is the- the truth, right?

(speaker_0)

So you need a third party's sort of validation, I guess.

(speaker_2)

Can I push back on something you said-

(speaker_0)

Yes.

(speaker_2)

...

(speaker_2)

at the beginning?

(speaker_2)

I hear this is the most...

(speaker_2)

uh, the best way to do panels is to get a little contentious.

(speaker_0)

Exactly.

(speaker_0)

Spicy.

(speaker_2)

Um, so I think that the flip of having centralization, uh, and singularity in something like Signal and something like Wikipedia is those white blood cells that Meredith was talking about, is that because Signal is the app, you have a

(speaker_2)

lot of eyes on it from a security point of view.

(speaker_2)

Some of the best researchers are looking at it.

(speaker_2)

You have an all of community response to trying to secure it.

(speaker_2)

Wikipedia, right, is the same.

(speaker_2)

The only reason Wikipedia is what it is today is because of all of the volunteers that contribute to it and keep it, uh, uh, as the internet's encyclopedia.

(speaker_2)

And one has to ask, if you start to really Balkanize that, are you going to have the same result?

(speaker_2)

Is there a value in having that centrality?

(speaker_0)

Or is it more distributed, where the German Wikipedia community has the German Wikipedia?

(speaker_0)

They- they edit the hell out of that, and it gets pushed, distributed to all the other distribu- distributed Wikipedia instances everywhere.

(speaker_0)

And so...

(speaker_0)

You might be able to, I don't know, engineer a sort of takeover of part of Wikipedia, but it's a federated connection of Wikipedias, not a central.

(speaker_1)

You want a Wikipedia blockchain.

(speaker_0)

Uh, blo- uh, I was thinking more Web3- ...

(speaker_0)

with an NFT.

(speaker_2)

Do we, do we kick him off the stage for saying blockchain?

(speaker_4)

For having jokes.

(speaker_4)

Don't worry about it, yeah.

(speaker_0)

Okay, so then my question is how, i- if you are gonna try to regulate outcomes, how do you get there?

(speaker_4)

Yeah, I mean, I, I think that-

(speaker_0)

And I don't wanna fixate on that one, Tom.

(speaker_0)

I don't wanna make this about regulate the outcomes, but I think...

(speaker_0)

I kind of wanna understand, how do we not have the same conversation five years from now?

(speaker_4)

Yeah, well, I mean, in cyber, we're always having the same conversation.

(speaker_4)

But, uh, I, I...

(speaker_4)

What I think, and if you, if you go back to the example of, you know, the Biden administration don't, don't train your models on the, on data that, you know, could make your models racist and so on.

(speaker_4)

And then Musk's point of, you know, woke GPT blah, blah, blah is a bad thing.

(speaker_4)

I think about my, my kids who will, like, look at a video and be like, "Oh dad, that's totally fake.

(speaker_4)

That's clearly AI generated.

(speaker_4)

What are you talking about?"

(speaker_4)

Like, and I think that if we can figure out a way to regulate an outcome where we get trust or we get the ability to know when things are not real, so then people can decide, okay, I do

(speaker_4)

want...

(speaker_4)

Like, if I want my kids to be scrolling TikTok eight hours a day at the ripe old age of seven, like, okay, that's your r- you know, that's your decision as a parent, fine.

(speaker_4)

But, uh, the world that I think we're, we're moving into, um, is, is one in which it's nearly impossible to decide what's actually real, um, and what's not.

(speaker_4)

And I think that if we could get to the bottom of figuring out that, then the other thing's kind of-

(speaker_0)

So your truth, truth in advertising-

(speaker_4)

Yeah, tha-

(speaker_0)

...

(speaker_0)

transparency in...

(speaker_4)

Or just the ability to know when it's fake.

(speaker_4)

Then I think we can kind of start to sift through the rest of the shit, you know?

(speaker_1)

I, I agree.

(speaker_1)

So, so I've got twin boys who are nine, they play Roblox and speak a language they don't understand anymore.

(speaker_1)

Um, they love YouTube Shorts.

(speaker_1)

As much as I dislike that brain rot, um, I want the ability not to block them from seeing it, but I want to curb how much time they have.

(speaker_1)

And then the same thing with, with AI and deepfakes and generated content.

(speaker_1)

I want YouTube to do more.

(speaker_1)

I don't believe it's a technical hurdle they can't fix.

(speaker_1)

I want it so that I can have a flag in the settings that says, "My kids will not see deepfake or AI-generated content."

(speaker_4)

Right, and that's something that we could regulate the big, uh, tech providers to say, "You, you must."

(speaker_4)

Like, as if they don't know.

(speaker_4)

Of course they know, and of course they can do this.

(speaker_4)

Um, uh, that regulation is completely possible.

(speaker_1)

And that's an outcome thing, right?

(speaker_1)

It's not blocking YouTube Shorts.

(speaker_1)

It's just saying, "You will ensure that your models stop that."

(speaker_3)

Just maybe stepping back and asking the question of what is the outcome that we want?

(speaker_3)

And do we have consensus to do that?

(speaker_3)

Uh, because as we're talking about these measures, right, I- I'm, I'm thinking of, like, the election cycle, like the big elections year, right?

(speaker_3)

I mean, many, like, companies such as Facebook, well, back then Facebook Meta, um, created, like, war rooms and they created, like, they flagged content that was linked to certain parties or certain, you know, that was, you know, moneti- you know,

(speaker_3)

paid or adverts from, let's say, certain parties.

(speaker_3)

That's what they could do.

(speaker_3)

That's what they did.

(speaker_3)

Again, that's a piecemeal approach and that's also kind of insufficient when you think that right after that cycle, like, most of the big platforms did cut the funding for their trust and safety teams.

(speaker_3)

So that has something to say about do we have the same outcomes that we're trying to reach?

(speaker_3)

Um, and, and I guess that's an- a question that we need to ask.

(speaker_3)

Uh, uh, now on the AI side, like, in November last year, um, I mean, now thinking about what governments can do and maybe take us to the, you know, conversation to, like, co-regulation.

(speaker_3)

Um, last year, you know, um, the, the, the European Commission had to, like, put on a digital omnibus and then it's, it basically admitted that it had to stop certain types of implementation or had to delay the implementation of certain

(speaker_3)

parts of the EU AI Act because they didn't want to stop innovation, right?

(speaker_3)

And I think that, that shows that there is this uncertainty or at least this, this need to balance, at least on the European side of things, this, this, you know, impetus or let's say the European soft power to

(speaker_3)

regulate and to be a regulatory power with, at the same time, trying to bring innovation.

(speaker_3)

That is, again, pushing the conversation.

(speaker_3)

That is what the EU is trying to balance in terms of which outcomes it's trying to reach, right?

(speaker_3)

And it, it didn't necessarily get to an answer because when we look at the other side of the coin so that we can take the conversation hopefully to, like, co-regulation, right?

(speaker_3)

If the end goal is to ensure that we all have a safe or, or secure kind of, um, use of LLMs and these models, right, how do we make sure that it's not just regulation trying to kind of speak externally to that, but that,

(speaker_3)

you know, we can have more understanding of how these models operate?

(speaker_3)

And actually, like on the work that we've been doing, and that Dan has also been kind of like doing, when looking at how third parties access Frontier AI models, you know, what are the risks of third parties accessing?

(speaker_3)

How can we make sure that that is secure?

(speaker_3)

How do we make sure that there is external validation of some...

(speaker_3)

Not validation, but let's say at least some oversight or potentially kind of some form of assurance of how these models operate, if they operate with security in mind, if developers could consider something extra?

(speaker_3)

Because obviously these companies are overstretched when they think about securing their own development of LLMs, right?

(speaker_3)

I mean, their teams are limited.

(speaker_3)

So can we think about new ways or new avenues of collaboration that can, you know, not just provide companies what they need, but also with, let's say, external party evaluators or red teamers, but also on the regulatory side,

(speaker_3)

how, what is the kind of information that we need to provide in order for regulation to be effective, right?

(speaker_0)

So, so that's the- How does civil society help provide the information to provide better policy outcomes, or...?

(speaker_2)

I think it's, it's...

(speaker_2)

We need to look at this, from my perspective at least, we need to map the different stakeholders and which place they occupy in this conversation.

(speaker_2)

If we're talking about security and safety of, of frontier AI models, I think there needs to be greater integration between communities.

(speaker_2)

What, what we found is that, you know, obviously evaluators are the third party-

(speaker_0)

Sure.

(speaker_2)

...

(speaker_2)

assurers of many of these, uh, frontier models.

(speaker_2)

But sometimes the cybersecurity community isn't as integrated, right?

(speaker_2)

And are we talking to, like, you know, uh, I mean, obviously this is in the context of assuring that a certain model is ready to be deployed, and even in pre-deployment, right?

(speaker_0)

Anybody?

(speaker_0)

Mueller?

(speaker_4)

Uh-

(speaker_0)

Go ahead.

(speaker_4)

I've...

(speaker_4)

Okay.

(speaker_4)

I-

(speaker_0)

Because I don't want it to be all about AI, but it is a good example of-

(speaker_2)

Uh, this, this will be a little about...

(speaker_0)

Yeah.

(speaker_2)

...

(speaker_2)

about AI.

(speaker_2)

But, you know, something that strikes me about what is the, what is the intended outcome, uh, especially with, with, with Signal, with Wikipedia, with, uh, frontier models.

(speaker_2)

Uh, yes, there is, uh, government influence and pressure and, in some cases, regulation to achieve certain outcomes.

(speaker_2)

But the end result, the product often reflects the values of that company and of that entity.

(speaker_2)

And this is not a, uh, uh, this is not me saying public-private partnership, but it's simply me saying that, uh, uh, there is a, a soft approach here as well, which is aligning the, uh, folks who are on, on the

(speaker_2)

forefront and who are achieving, uh, uh, cus- uh, largest customer base are achieving community interest.

(speaker_2)

Uh, uh, have those organizations be the ones that reflect the values that you're, uh, uh, that you would like to see in these end products, that is going to achieve the best result here.

(speaker_0)

There's, um...

(speaker_0)

I- I'm, I'm gonna go there.

(speaker_0)

Um, who uses Mastodon?

(speaker_0)

Anybody?

(speaker_0)

Or heard of the Fediverse?

(speaker_0)

Okay.

(speaker_0)

So there's this...

(speaker_0)

I- if you remember back years ago, the FBI got their hands on an iPhone that was used in a, a terror suspect in the United States.

(speaker_0)

And the FBI was trying to force Apple to unlock the phone.

(speaker_0)

Apple was resistant, they didn't want to unlock the phone.

(speaker_0)

Um, and it went back and forth.

(speaker_0)

And eventually, I think Cellebrite unlocked the phone for the FBI.

(speaker_0)

But after that, what happened is Apple decided that they didn't want to spend all their time with their, paying their lawyers to fight the FBI or any other government in the world.

(speaker_0)

So they went about engineering themselves out of the problem.

(speaker_0)

They engineered end-to-end encryption.

(speaker_0)

The end user has the key.

(speaker_0)

Apple has nothing.

(speaker_0)

They just...

(speaker_0)

They're not gonna spend their budget having this fight.

(speaker_0)

So they engineered themselves out of the equation, right?

(speaker_0)

So at some point, you make the regulation or you make something too s- difficult, companies will engineer themselves out of it.

(speaker_0)

But on the other hand, with the Fediverse, with Mastodon or whatever, if you're not getting the good moderation tools you need out of Twitter, you're not finding the community you want at Twitter, the government's not regulating the white supremacy on Twitter or the

(speaker_0)

pedophilia autogenerated images, if you're not happy with that, where do you go?

(speaker_0)

And it turns out in this Fediverse, a giant distributed network, they, the community has expressed their norms, right?

(speaker_0)

You can find different platforms, you can align with whatever your communities are.

(speaker_0)

You have strong moderation tools that are not available to you on other commercial platforms, because strong moderation tools makes you less valuable to them, right?

(speaker_0)

So it almost feels like we're starting just at the beginning point of, if we're not getting what we need from the companies and the government's not delivering for us, civil society is starting to build their own alternative replacement for Instagram,

(speaker_0)

YouTube, TikTok, X, whatever.

(speaker_0)

All the replacements are starting to come.

(speaker_0)

And they're coming in a distributed fashion with strong end user goals, with no algorithms forcing choice down your throat.

(speaker_0)

And it's, uh, just what you were talking, that triggered this memory that, oh, it's maybe the outcomes are coming now from the software creators.

(speaker_0)

And they'll only accelerate with automatically better generated source code from some of these AI tools.

(speaker_0)

Now you could actually build replacements that better reflect the values of the communities, where before you needed 5,000 engineers.

(speaker_0)

Now you maybe need 5,000 hours.

(speaker_0)

End rant.

(speaker_2)

Okay.

(speaker_0)

Yeah.

(speaker_2)

Yeah, I think that's accurate.

(speaker_2)

Uh, I think it's a really interesting question to say, how do LLMs, how does code generation, uh, help enable the open source community to become so much more powerful?

(speaker_2)

Especially at a time where there is...

(speaker_2)

while there's so much funding for open source, there's also so many well-paid jobs for developers.

(speaker_2)

And, uh, uh, it is, I, I think a community in a certain amount of flux right now.

(speaker_2)

And this is a really excellent opportunity to enable folks that don't have that much time, uh, but want to contribute, want to build things, want to put it out there to, uh, to really do that.

(speaker_4)

Yeah.

(speaker_4)

A- and I think, for example, uh, king of what Perry said, um, one of the outcomes we could, we could try and regulate toward is open source for critical infrastructure.

(speaker_4)

So for example, um, the precursor to the Almanac was the Voting Machine Hacking Village report that we used to put out, um, where, you know, we used...

(speaker_4)

At DEF CON, we would hack voting machines and voting software and so on, and produce a report on the, the vulnerabilities we found.

(speaker_4)

And one of our, um...

(speaker_4)

Uh, and by the way, which is the first time that was ever publicly done.

(speaker_4)

There had been a handful of assessments of voting equipment before, but the first time it was ever publicly done, um, was then.

(speaker_4)

...

(speaker_4)

a, as a quick aside, 'cause we've got 15 minutes.

(speaker_4)

Um, you know, of course the voting industry and the election officials were all like, "Our stuff's totally secure.

(speaker_4)

You can't hack this."

(speaker_4)

Which of course the hackers all laugh at.

(speaker_4)

Um, and, uh, our first finding was when, uh, one of the guys who was, who was running the village with us, um, opens up the back of one of the machines, and on nearly every single part it said made in,

(speaker_4)

where?

(speaker_0)

China.

(speaker_4)

China.

(speaker_4)

So, we're like, "These things could be rolling off the assembly line pre-hacked.

(speaker_4)

Like, what do you mean it's secure?"

(speaker_4)

And so since then we've been saying, "Why isn't voting equipment or voting software open source?"

(speaker_4)

Like, it's crazy that it's not open source.

(speaker_4)

We should have every hacker on the planet looking at, uh, voting software just like they look at, at Signal.

(speaker_4)

Um, it's a hell of a lot more important than Signal.

(speaker_4)

No offense to Signal.

(speaker_4)

Um, but yet we still don't have that.

(speaker_4)

And we, we could have that for multiple aspects of critical infrastructure.

(speaker_4)

Uh, and so anyway, that's certainly one of the outcomes we could, we could definitely regulate.

(speaker_1)

I'm really glad you didn't mention the grain of rice when you did the back door there.

(speaker_1)

Thank you.

(speaker_0)

I remember I was there in the room that first year when they, uh, I was standing next to an election official, and he was like, so excited.

(speaker_0)

And I'm like, "What are you doing here?

(speaker_0)

Don't you have these machines?"

(speaker_0)

And he's like, "Oh yeah, we have, you know, 10,000 of these machines."

(speaker_0)

Or whatever.

(speaker_0)

But my contract says I'm prohibited from opening up and looking inside.

(speaker_0)

So I've- ...

(speaker_0)

I've never been allowed to look inside one of these machines.

(speaker_0)

And, and I've always been curious.

(speaker_0)

Um, like, okay, so the guy takes out the screws and this thing, pries it open, that guy's eyes are really big and he's like, "Wow, look at that.

(speaker_0)

That interface is not in my technical diagram.

(speaker_0)

That memory controller is not in my diagram."

(speaker_0)

You know, and he was just like horrified, like everything that he'd been told by the manufacturer and the schematics he has in his hands, and he's trying to line it up and it's like, nope.

(speaker_0)

It's all different.

(speaker_0)

And it was like that poor guy, just his whole world crumbled, you know?

(speaker_0)

Right.

(speaker_0)

And that was just some screws in the back of a voting machine.

(speaker_0)

And like you, that's why I'm thinking that, and the only reason that happened was because in America, the Digital Millennium Copyright Act enabled a carve out for good faith research in election security.

(speaker_0)

And it had just happened.

(speaker_0)

If that carve out had not occurred, none of the security research could have happened.

(speaker_0)

And so there are so, right, regulate the outcome.

(speaker_0)

They wanted to encourage researchers to go after those medical devices, uh, or life safety medical devices, I think, life critical, elections and so forth.

(speaker_0)

And they had a very positive outcome.

(speaker_0)

Um...

(speaker_1)

Maybe that's a, a, a segue into you regulate the outcome where CNI based stuff should be open source.

(speaker_1)

I know there'll be some distractors, but you know, st- if you look at say, uh, PLC controllers, which history, they've been terrible.

(speaker_1)

Sorry if anybody works for any of the companies here, they, they have not been good.

(speaker_1)

But they're closed source and people can't get access to them.

(speaker_1)

And it's, it's hard that way.

(speaker_1)

I think one of the powers I see today with a lot of the, the AI models is that you've almost homegrown a whole lot of vulnerability res- researchers that have always been afraid to do it 'cause of gatekeeping.

(speaker_1)

But now I'm really interested in a PLC that controls water.

(speaker_1)

Okay, I can see the code repo on GitHub.

(speaker_1)

I'm gonna learn how it works.

(speaker_1)

I found a vulnerability to do a whole pool request.

(speaker_1)

Maybe that's what one of the regulated outcomes needs to be.

(speaker_1)

It's, if you have something that controls water for millions of people, the code should be accessible for people to view.

(speaker_1)

I know that's a very typical hacker view to it, but...

(speaker_2)

So, uh, going back to the, uh, uh, topic that you started with, which is what happens when you try to regulate those intermediate steps.

(speaker_2)

It reminded me of a discussion I had when I was in government about how to best regulate AI.

(speaker_2)

And this is at the very beginning of kind of the concern with regard to, uh, AI and models and, uh, so many folks were very reasonably and thoughtfully trying to ensure that we had the best outcomes from that technology.

(speaker_2)

But what resulted, uh, were some policy proposals that were quite, quite serious, uh, that would say things like, um, and the one I'm thinking of is, okay, well if it generates its own code, if it's code that generates its own code,

(speaker_2)

then that's something that we need to consider to be higher risk.

(speaker_2)

Right?

(speaker_2)

And I'm reading this and I'm thinking, well, every JIT, every just in time, uh, uh, compiler in a browser, which says, oh, you are doing this action over and over and over again.

(speaker_2)

I'm going to save the machine code so that it just runs faster.

(speaker_2)

That's generating code.

(speaker_2)

This is something that's very common and there's so many other examples of that.

(speaker_2)

And this is a good faith effort to say, Hey, we wanna have a little bit more insight with people are going to regu- uh, uh, generate malware, which of course we should obviously be very concerned if you have people using AI to generate malware that they're targeting

(speaker_2)

schools and hospitals, et cetera with, right?

(speaker_2)

But that's the end result.

(speaker_2)

And if you start to, uh, uh, tailor these fine-grained regulations to intermediate steps, uh, uh, unless they are very, very technically sound, they have these really huge rippling, uh, side

(speaker_2)

effects that are, are really counterintuitive.

(speaker_4)

Okay.

(speaker_4)

I wanna go for the audience.

(speaker_4)

Wanna go for the audience?

(speaker_0)

Sure.

(speaker_4)

Go for audience.

(speaker_4)

This gentleman first.

(speaker_1)

I feel like it's gonna be a good question 'cause he was very excited.

(speaker_4)

He's got a beard.

(speaker_1)

Right.

(speaker_5)

Yeah.

(speaker_5)

Hello, I'm Dean Wiesbarth from Innobyte.

(speaker_5)

Um, you talked a lot about, of regulating the outcome and that there's not a lot of laws doing that.

(speaker_5)

I was wondering, do you consider the NIS2 directive to be such a law that regulates outcome?

(speaker_0)

I have no idea what the NIS2 law is.

(speaker_4)

I have no idea.

(speaker_4)

What is it?

(speaker_5)

Uh, German directive, uh, European directive.

(speaker_5)

Thank you.

(speaker_5)

Uh, put into law in Germany last year.

(speaker_5)

That's why I was ...

(speaker_5)

if the German.

(speaker_5)

Um, it basically tells companies of a certain size and certain criticality to be, um, IT secure.

(speaker_5)

And it doesn't specify exactly how, it just mentions that you have to...

(speaker_5)

...

(speaker_5)

do some sort of two-factor authentication.

(speaker_5)

It has t- uh, to do with, um-

(speaker_0)

It's like a mature- It's like a maturity model.

(speaker_0)

You have to try to be this tall, and then each year they'll try to improve it or iterate through.

(speaker_5)

Uh, they basically give the local regulators, for example, the BSI, uh, the authority to mandate what you should do.

(speaker_0)

Yeah.

(speaker_0)

I see this model in China, where they keep increasing the protections on PIPL, their individual personal privacy laws, where, uh, in the very early days, it was your company, if you have a website, commerce site, they would

(speaker_0)

scan your website, and if they, their tools didn't show any vulnerabilities, you passed, you could stay in business.

(speaker_0)

Um, and then it got to the point where now they're doing more in-depth, like SQL injections and, and human machine audits.

(speaker_0)

And now, it's, it's on its third generation.

(speaker_0)

It's getting pretty sophisticated.

(speaker_0)

They partner with universities.

(speaker_0)

Um, the university students use this as part of their security training course where to, like, test, uh, companies.

(speaker_0)

And it's all part about, uh, China has this vision that the future of China is online, and citizens should trust the online infrastructure.

(speaker_0)

So, they spend a lot of time doing these kinds of exercises so people will trust...

(speaker_0)

right?

(speaker_0)

That, so their outcome was, we need people to trust the internet.

(speaker_0)

How do we do that?

(speaker_0)

And they have this multi-year plan, and they just keep ratcheting it up and ratcheting it up.

(speaker_1)

Uh, I'm familiar with that.

(speaker_1)

My biggest concern and criticism is that it reminds me of the OWASP Top 10, and I apologize for the OWASP Top 10.

(speaker_1)

Um, it was never meant to be what people use it as.

(speaker_1)

And unfortunately, now people say, "Well, we're safe from OWASP Top 10."

(speaker_1)

I'm like, "There's one of the...

(speaker_1)

I don't even know what that means."

(speaker_1)

So, I think the intent's there, it just doesn't go far enough.

(speaker_1)

I, I actually prefer that-

(speaker_0)

So, you really, you really believe in the OWASP Top 20 then?

(speaker_1)

I think, I think there's an AI Top 10 now.

(speaker_1)

I'm sorry.

(speaker_0)

Anybody else?

(speaker_0)

Nope.

(speaker_0)

Okay.

(speaker_0)

Uh...

(speaker_6)

Hi there.

(speaker_6)

I'm Susanna Diemel from, uh, Bitkom, German Digital Association, and I was wondering, uh, what, what is it exactly what we mean by when we talk about output-related, um, regulation?

(speaker_6)

Because, um, usually when we think about legislation, we do abstract rules for a unspecified number of cases in the, in, well, we, with regards to technologies, we

(speaker_6)

sometimes try to regulate the risks of, um, developing technologies in advance, at least in Europe that's, that's quite popular.

(speaker_6)

But the difficulty is as described.

(speaker_6)

We, we don't really know what will be the outcomes of the use of this technology.

(speaker_6)

We don't know how the technology develops.

(speaker_6)

We don't know, um, what will be the side effects, um, of...

(speaker_6)

so, so I think it's really hard to, um, to regulate the output and also with in-...

(speaker_6)

regards to enforcement, you know, you have...

(speaker_6)

yeah, so, so that's what, what I was wondering about.

(speaker_6)

What do you th-...

(speaker_6)

what do you think about that?

(speaker_1)

You've touched on a really interesting point, that the gap between the pace of technology and the fact that regulators and government are like slow-moving mammoths.

(speaker_1)

And I think the reality is, let's take the, the YouTube example.

(speaker_1)

Like, there are plenty of studies out there that now show that the excessive doomscrolling is not good, even for adults, right?

(speaker_1)

So you almost feel like the tech companies are not doing enough to self-regulate, so you look at mom and dad, right?

(speaker_1)

And mom and dad are outside having a cigarette.

(speaker_1)

For me, that's the analogy of government.

(speaker_1)

Why are they not moving faster?

(speaker_1)

Why does it take years and years and years to regulate when tech can move in days, weeks and months, and even more so now?

(speaker_1)

I think that's probably where we need to see the biggest shift, is that government, h- hate to say the word, they, they've got to be a little bit more agile.

(speaker_2)

I also think you've touched on an uncomfortable truth when it comes to technological regulation, which is that we almost treat society as, uh, uh, human subjects for research.

(speaker_2)

And we are prepared to let technology go forth in the world and then to assess its effect, and over time, collectively, uh, start to try to constrain it after the fact, which obviously has significant

(speaker_2)

risks, right?

(speaker_2)

Uh, but there's a, uh, uh, argument for doing it that way, which is that if you are too risk-averse, you can't see what technology is-

(speaker_0)

Yeah.

(speaker_2)

...

(speaker_2)

actually gonna flourish-

(speaker_0)

Okay.

(speaker_0)

But-

(speaker_2)

...

(speaker_2)

and improve.

(speaker_0)

...

(speaker_0)

if, if you had a strong child protection framework, and a child protection framework might say, um, uh, a- attention distortive, you know, whether it's radio or TV or rock and roll or whatever it is you've decided, video

(speaker_0)

games in the arcade or something, you decide that these things, uh, chi-...

(speaker_0)

children under six, like, disturb their attention span and hurt their cognitive capabilities, then fine, the internet comes along, doomscrolling falls right underneath the c-...

(speaker_0)

the, the child protection stuff for various age-appropriate content, or you...

(speaker_0)

there's a, there's studies about how many times an image changes on the screen if, if you have fast-moving images for brains that are about under three or four years old, it wires your brain differently 'cause you have to constantly be refocusing.

(speaker_0)

Like, that wasn't a problem in my age 'cause the images didn't move that fast.

(speaker_0)

I mean, they, the commercials were 30 seconds long, not four seconds, right?

(speaker_0)

Um, but once you know that, don't you have an obligation to regulate it to, to protect the children?

(speaker_0)

Like, okay, well, then YouTube Kids can't have images changing two times in a second or two times in a minute or whatever.

(speaker_1)

Do an algorithm where you...

(speaker_1)

you know, if they detect the child doing this often-

(speaker_0)

It just, it slows.

(speaker_0)

Yeah.

(speaker_1)

...

(speaker_1)

like, it, it, it does some-...

(speaker_1)

the technology's-

(speaker_0)

Yeah.

(speaker_1)

...

(speaker_1)

there.

(speaker_1)

It's just, there, there's no...

(speaker_1)

we, you know, we talked about incentives before.

(speaker_0)

Right.

(speaker_0)

So, so, so I, I really think about incentive models, like the incentives must be misaligned.

(speaker_0)

They've gotta be misaligned.

(speaker_0)

Um, and we haven't mentioned once so far on all of our sessions the word liability, which I'm pretty proud about.

(speaker_0)

But at some point, like, what levers do you have left to regulate?

(speaker_0)

When you say regulate the outcome, is it through liabilities, through incentive structures?

(speaker_0)

Is it through, um, companies generally respond to incentive structures, they probably, they try to resist liability.

(speaker_0)

They try to externalize all the risks and privatize all the profit, um, and you know that.

(speaker_0)

So how do you regulate an outcome in that environment?

(speaker_3)

I think it's, it's...

(speaker_3)

now going back to kind of, because in, in the UK it's also a big debate right now about, um, social media and whether to ban or not in schools, um, I think there's obviously the question, just thinking about out- outcomes, right?

(speaker_3)

It's, it's making sure that, let's say, there is, that, that the new generations, that they have media literacy, that they are aware, that they can use and take and make the most out of what they have in terms of, let's say, access to information, right?

(speaker_3)

That's the outcome that we want, hopefully.

(speaker_3)

Um, the other thing is you...

(speaker_3)

if you ban, uh, social media or if you ban even kind of cell phones from the school, there will be a desire to use it anyway, because it is a core part of you as an individual t- being integrated in social life.

(speaker_3)

So then the question is, what are the other elements and other stakeholders, going back to what I was saying previously, then you need to think, okay, one answer is the education system.

(speaker_3)

The other answer is how do we sp- how do we then speak to the platforms and speak them a- their response also as an answer that we need.

(speaker_3)

So we need them to do more.

(speaker_3)

And so you start to pil- to kind of paint this almost like multi-stakeholder kind of set of responsibilities that need to be encompassed if you're thinking, and so the conversation is not about should we ban or not access to

(speaker_3)

smartphones in school.

(speaker_3)

Then the conversation is, as government, how can we incentivize a, a conversation about how to best use technology within the school system, right?

(speaker_3)

So that you don't shun the conversation from the school to then the home where sometimes parents might not be as, you know, interested in saying like, "You're going to have X amount of screen time."

(speaker_3)

Right?

(speaker_3)

At home is a different ball game.

(speaker_3)

So I think that's what I meant when in, when in...

(speaker_3)

thinking about outcomes, the outcome is we're going to get the best set of technology, the younger generations are going to do that, but the responsibility is spread across.

(speaker_3)

So we need measures for each of those, let's say, stakeholders.

(speaker_3)

And I think when it comes to this, when it comes to cyber and when it comes to like securing or safety of AI, it's also about thinking what are the designated responsibilities for these different stakeholders.

(speaker_0)

Three, two, one.

(speaker_0)

All right.

(speaker_0)

Thank you everyone.