Cables2Clouds

Its just AI, Michael, how much could it cost? 10 dollars?

Cables2Clouds Episode 54

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 45:44

Send us Fan Mail

AI isn’t just changing software, it’s rewriting the rules around hardware, regulation, and power. We start with a report that the FCC is moving to restrict Chinese-made optical transceivers used in US AI data centers, and we unpack the real-world tradeoff between supply chain security concerns and the very practical problem of capacity. If you pull a key part out of the 800G optics market overnight, who actually fills the gap, and what breaks first?

From there, the geopolitical mirror flips: China announces a cybersecurity review of Palo Alto Networks products with little detail, raising the uncomfortable question of when “security reviews” become economic leverage. Then we zoom out to the physical footprint of AI, where hyperscale data center projects are meeting environmental scrutiny and voter backlash. New York pauses permits to build a regulatory framework, and AWS withdraws a massive Maryland proposal even with major power nearby, signaling how quickly politics and community pressure can change the cloud roadmap.

We close with the security stories that tie it all together: a proof-of-concept showing how an AI-enabled email assistant can supercharge business email compromise, reports of an autonomous agent breaking containment and hammering third-party services at machine speed, and a new US push to let “vetted” private companies conduct offensive cyber operations under federal direction. If you care about AI governance, cybersecurity, AI transparency, the EU AI Act, or the future of data centers, this one connects the dots.

Subscribe for the monthly news rundown, share this with a friend who builds or secures AI systems, and leave a review with your take: where do you think the biggest risk really is?


Check out the Monthly Cloud Networking News
https://docs.google.com/document/d/1fkBWCGwXDUX9OfZ9_MvSVup8tJJzJeqrauaE6VPT2b0/

Visit our website and subscribe: https://www.cables2clouds.com/
Follow us on BlueSky: https://bsky.app/profile/cables2clouds.com
Follow us on YouTube: https://www.youtube.com/@cables2clouds/
Follow us on TikTok: https://www.tiktok.com/@cables2clouds
Merch Store: https://store.cables2clouds.com/
Join the Discord Study group: https://artofneteng.com/iaatj

Welcome And Monthly News Setup

Tim

Hello everybody and welcome to our monthly news episode uh update at the Cables of Clouds podcast. Um I'm here with uh I'm Tim. I'm here with Chris this morning. And uh it's a little early for me, so uh I'm just uh catching up. We're trying to get this out uh a little bit late. So um let's just jump right let's just jump right into it. So we've got some we've got a few stories uh this month and are kind of thematic, but uh we'll cover them one at a time and we'll we'll see what's

FCC Eyes Chinese Transceivers

Tim

up. So the first story we have is a there's a new FCC ban on Chinese optical receivers for data centers coming up. So uh the FTC, which is the you know, the United States Federal Communication Commission, is uh developing restrictions on Chinese Chinese-made optical receivers or transceivers rather for US AI data centers, um, with the rationale saying that you know transceivers uh can be used for data theft or malware or just running software, and so they can kind of kind of be man-in-the-middle type of of devices. Um some Chinese vendors like Inalite and Eoptalink, which I didn't know these I didn't know the name of these vendors, but uh there you go, uh are dominating kind of the 800 gig module market, and they're being used mostly in in in NVIDIA AI clusters. So there's US alternatives such as Coherent and Momentum, and they don't have the capacity, like just the the fabs. They they they haven't produced enough to just completely replace them. So it's interesting this is coming out, and uh so there's so in this piece, uh there's some you know, they've they they talk to a bunch of consultants. What what does this mean essentially for the industry? And most of them are like, well, I don't know that trans, you know, the firmware that we put on a transceiver is uh is truly sophisticated enough to be a real espionage risk, but you know, disrupting the uh supply chain of these transceivers is definitely a real risk to you know building and throwing up these uh these data centers. Uh yeah, so what do you think about that, Chris?

Chris

Yeah, um like you said, the the two vendors in play here um that you mentioned being Intelite and EOptolink. Um I think probably one of the main reasons that you and I don't know who those companies are is probably because we we're we're not rich enough to be uh uh to be dealing with 800 gig optics at the in our in our day-to-days at this point, right? They seem to be very focused on, you know, kind of the NVIDIA AI clusters as as you called out. Um so I mean, you know, uh I'm I'm just entering the realm here in Australia where I'm seeing quite a bit of 400 gig, still haven't really seen a lot of 800 gig, but uh yeah, I imagine if you are at this kind of level of capacity where you are, you know, building these AI factories and things like that in-house, you probably do need things like this, and you probably are turning to um probably some of the some of the alternatives, especially in the uh the state of the supply chain uh being what it is, I'm sure you're probably exploring all avenues. So, you know, I do wonder if people just kind of run out and and buy you know a shit ton of these uh ahead of the ban uh coming down and and uh that actually being cut off from them. But yeah, I I mean I'm also kind of in the realm where I don't I don't know obviously I can be I could very much be proven wrong. And if I say this, I probably will get proven wrong, but I don't I don't see a lot of intelligence being baked into these optics. Um, you know, I mean there's um there are the the concept of smart optics out there where they can kind of do more than the average, just you know, kind of uh plug and play um overpriced piece of thing that uh that uh you know can converts light into into bits on the wire or whatever, right? Um so uh I I'm sure that I mean yeah, I wonder if they're viewing this as kind of like the the classic, you know, thing where you know where people put the little covers over the the the credit card readers at the at the gas pump and things like that. But um yeah, it it it is quite interesting. Um and yeah, I don't I don't know what it's gonna do to the market.

Tim

Yeah, I'm I'm kind of curious how much. I mean, you know, the storage and uh processors get smaller and smaller, so I don't know. I I would assume that somebody could pick up one of these transceivers and figure out essentially what's on it, right? Like you know, they could reverse engineer it if they really wanted to. So I wonder if some of this is just protectionism uh masquerading as cybersecurity. So I I don't I don't know though. So there's definitely big politics in play here. Oh, it's with everything, yeah, no kidding. Um another yeah, so another another China story.

China Reviews Palo Alto Products

Tim

Uh so like I said, there's this rivalry between the US and China, especially as pertains to AI and cybersecurity, is really heating up. So this one's new. This one's actually from the point of view of China. So recently, uh China's cyberspace administration announced that they're now reviewing Palo Alto uh their products, citing the need to ensure the quote, safe and stable operation of critical information infrastructure and prevent cybersecurity risks. But they didn't provide any detail on like what they're doing to prov like why they're reviewing specifically Palo Alto uh or what that review entails. So um now China has done this before, like they picked back in 23, they picked uh on Micron, which which is kind of interesting. Um, and they ended up banning Micron's products uh in China, but it it was replaced by domestic uh competitors like Huawei. So again, a little bit of uh what seems like a little bit of protectionism masquerading as cybersecurity defense, maybe. Um it's it's hard to say. So yeah, what do you uh anything to add on that one?

Chris

Yeah, I guess it probably goes without saying that um obviously Tim and I um do work currently for Palo Alto competitors. So this is a I I I want to openly say that this is not at all uh even a dig at anything going on with Palo Alto or their products uh whatsoever. This is kind of just like a an uh completely out of the blue um kind of stab at obviously a market leader in uh in this particular category of cybersecurity. So it's a very strange move. And you know, I wonder if it's a bit of um uh kind of a retaliation for some of the other things like we like we just mentioned with the transceivers and things like that. So um, you know, you've got the US restricting Chinese optics on security grounds, and now China has opened this kind of open review about a a major security vendor on security grounds in the same batch. Um I don't know if any of this is technical at the end of the day, um, which is um kind of a you know a sad state for us to be in as technologists, but um yeah it's uh it's quite interesting. Um I I I I don't know. Like a bit it like uh there's a lot of correlations being drawn to Micron here. I don't think they'll go that far. I don't think you can take it to the the effect that you actually ban all of Palo Alto's products within the sale of China. Um I feel like that would be that would be pretty uh pretty critical at this point in time. But I don't know, how do you feel, Tim?

Tim

Yeah, I I mean I I don't know if I I don't know if I at this point I'm not sure I would say that anything's off the table. I mean I would hope, right? That Palo I mean, but Micron's a pretty big dealer too, and they they banned them. So yeah, it's really hard to say. Uh I really am curious why they specifically singled out Palo Alto. I'm sure there's polit there's politics involved here. Um, because you know, you would think that they would just target American cybersecurity companies if this was so or maybe they're just starting with Palo Alto. I I don't know. That's a it's really rather interesting. Um I don't know again, this kind of tit for tat uh governmental level stuff. I there's probably money involved in it. There's certainly politics involved in it. Um there's I think there's a lot of protectionism being involved with it. Like, hey, we've you know, we're banning this foreign vendor so that our our uh local vendor will have better, you know, luck at at selling to domestic.

Chris

Which is which is the nature of their game, as we've seen, right? So that's it's not off the table. Um I'm I I think I'm I'm being more hopeful. I don't want this to be a domino that falls in that direction, but it it might end up being that way, but we'll see.

Tim

Yeah.

Chris

All

New York Hits Pause On Hyperscale

Chris

right. And next up we have uh a couple in in everyone's favorite category, uh, which is AI data center news. Um, you know, I'm sure uh we as much as we'd like to get away from this, uh it's gonna be a an ever uh an ever uh present news topic here. So first up we have one um from Network World where a New York executive has uh paused orders on hyperscale data centers. So Governor Kathy Holtsul, I believe is how you say her last name, signed an executive order establishing uh what the article describes as the nation's first uh memori or moratorium on hyperscale data centers within New York, pausing for environmental permits uh up to a year while the state builds this kind of regulatory framework around these things. Um the state will produce a generic environmental impact statement covering water, energy, air, quality, and uh community investment framework within 60 days, which is a relatively short time frame. Um but these proposed requirements include over uh I think it says 1 million per megawatt of utility demand per project plus labor and infrastructure commitments. So um if you're doing the math, those are those are not small numbers. So it's uh, you know, I guess there's probably if if they're gonna end up doing these things, they're gonna write it in a way where there's there's a lot to gain from the municipalities that have to service them. But um, yeah, what's what's your reading on this one, Tim?

Tim

I've been following this for not this necessarily for New York, but like just generally following this this uh AI data center back and forth um between essentially corporations and billionaires and the people that live near these things that are going up uh for like a year or more now. Um it's it's interesting that at the same time we have you know, here's like a state like New York that's saying basically, no, you can't build them. We're gonna we're gonna do environmental impacts and and and put a moratorium on them and also make them potentially prohibitively expensive for these companies to run them. Uh, you also have you know, 10 stories come out at the same time of all these small towns where the governing, you know, board or mayor or whatever it takes these uh takes money from companies to just uh you know sign through. Yeah, yeah, yeah. We'll just give you all this this this uh land for data centers. So it's I I don't know what the answer is here. I think I think that uh first of all, I mean, let's put this in perspective, right? The US has more data centers than the rest of the world, not combined, but not not too far off either. Um, you know, and then the amount of data centers that are still being planned, it's just in my opinion, it's just it's wasteful. It's so much. And it's just it's it's completely it's the tragedy of the commons, right? Like one person walks out with a with an axe to chop down a tree, and then the next person walks out with an axe to chop down their tree, and then there's no trees left, but everybody was just doing what was right for them. So try classic tragedy of the commons problem, except that the commons in this case is like water and electricity for people. So yeah.

Chris

I don't know. Yeah, it's uh it's a it's a recurring theme um that we've been seeing here. So I mean, I mean, this is the the article kind of calls out that this is one of the nation's first in this type of um I g I guess characterization of this um uh this act of putting a halt on the permits while they renegotiate kind of the um the requirements, which I don't think is necessarily gonna stop any of these things from getting built. I think you know the the money's gonna get paid, um, at least until the bubble potentially bursts, and then and then we're uh someone's left holding the bag at that point. Um, but keeping up with this theme, let's uh let's move on.

AWS Withdrawal And Local Pushback

Chris

So um so AWS, um, we have one here from datacenterknowledge.com. AWS data center withdrawal signals growing political community challenges, the article reads. So AWS withdrew its application for a 2.5 million square foot data center in Calvert County, Maryland, citing developmental timelines, operational requirements, and its ability to deliver quickly for customers. So the proposed uh sorry, the proposal covered three campuses across 200 acres with eight buildings up to 500 um uh megawatts supplied by Constellation Energy near the Calvert Cliffs nuclear plant. Data Center Watch uh is cited saying 75 major projects worth more than 130 billion were delayed or canceled for the first time in three months in 2026. And three incumbent county commissioners who opposed the moratorium lost their primaries on the 23rd of June. Um so it seems like we have uh we have a bit of a theme here, Tim. Um what what's what say you about this? Uh good.

Tim

I mean, uh I don't know what else to say. So this is the thing. It I mean, it AWS, all the hyperscalers are gonna keep trying to build capacity. That's they've you know, way back in God, 23, 20, whatever, we when we were talking about why hasn't the why haven't all the cost savings uh appeared for the cloud, right? Uh not happening, no. And and well, yeah, was and and our our uh our conclusion at that time was that they had a capacity problem, right? Like that if they actually should if they actually passed on savings, they would get more users and everybody would be DDoSing each other. Well, that's still the case, right? Even before AI, even before AI came along, that was the case. So, you know, they're gonna keep trying to build data centers for whatever reason. I know AWS is actually getting out of the of the creating its own model game, but they'll they'll still, of course, offer hosting, obviously, for for other models. Um I do think the the interesting thread here is that the people who oppose the moratorium, basically who were probably standing to gain something from those this data centers being built, uh, lost their primaries. So this is this is people fighting back, uh, you know, with their with their you know, at the polls, essentially. Um not mentioned here, but you know, kind of uh a theme I'm seeing lately is that uh, you know, the the government, who is very, you know, especially the Trump administration is very friendly to AI companies and data center builds and all of that, uh, have started saying things like national security to override a lot of this and get these make so people can't actually push back on these things. Um so I'm curious to see because I think that's at some point that's gonna come to a head, and then it'll probably end up in the Supreme Court. And at that point we know probably which way that'll go. But it will be interesting to see that whole thing play out and how long it takes to play out specifically.

Chris

Yeah, agreed. Not much more to add there. I definitely obviously see this as a good thing. Um, especially, you know, I think there's real kind of significance in this one, especially because like if you think about it, like they they already called out that this was right next to uh an actual nuclear plant, right? So the the power thing was like a solved problem. That was when that they knew where that was gonna come from. That was not something they had to um kind of actually build or or um you know uh uh supply additional resources on that was already ready to go, and it still didn't even proceed with that. Um so I'd say it's a pretty powerful statement. Good job, Marilyn. Yeah.

Tim

And and it'd be clear, I'm not against any data centers being built anywhere, right? I'm just generally skeptical of the need uh for these gigantic campuses. I think I'm more into the idea that like I think the future is gonna be more around edge inferencing and edge computing than like that's more sustainable than building giant data centers. Um, but that's yeah.

Chris

Yeah, it's it sucks because like it's weird. Like what I think you and I are probably in a relatively similar camp where like the the new emergence of this technology is w we both see it as a great thing and a very cool thing, but also um a very dangerous thing and how it can be done, whether it be kind of from the view of the of the cyber defense lens where there's you know attacks being um uh uh kind of scaled up at these uh kind of grandiose scales because of because of the use AI, but also the infrastructure that it's required to run it, um, could kind of kind of take away from you know people's livelihood and things like that. So we don't wanna we don't want to rob Peter to pay Paul just to have a you know a cool new technology that we don't where we don't even know where it's gonna go at the enterprise level at this point, right? So it's kind of uh rocking rocking hard place.

EU AI Transparency Rules Kick In

Tim

Yeah, for sure. Um all right, so moving on, the next thing the so the the EU has uh passed, by this point they've passed it. It's taken uh not passed it, but it's taken effect, actually, as a recording. But the EU AI Transparency Uh Act was passed uh in well in the EU to basically require that uh okay, so actually let me just read it right from the from the summary here. So the EU AI Transpar Act, transparency requirements uh require systems placed on the market before that date, so already passed, having until the second of December to start complying with this. So organizations that deploy AI in the EU must tell users when they're interacting with AI chatbots, deep fakes, recognition, biometric categorization, basically anything that's created by Gen AI content must carry machine readable markers labeling something as AI, uh fully AI, partially AI modified, essentially the AI Photoshop of our era. Um, and so non-compliance with releasing uh content apps, whatever it is, uh the the fines range from 750,000 euros to 15 million euros or up to 3% of worldwide annual revenue. Holy shit. And the rules apply to any company placing systems on the EU market, regardless of where they're located. Now that's the important part, right? So if this is being run out of the US or China or somewhere else, doesn't matter. If you're if it's on the EU market, you're you you label it or else. Um so yeah, that's that's a that's an interesting law. What do you what do you think about that?

Chris

I mean, uh we know the the EU, I feel like they're usually usually on the on the side of good in these things, but they often swing the gavel just a little too hard and make it a little bit too restrictive so that um it it ends up like I understand it's supposed to be for the the sake of the people, but it kind of makes things also just as difficult to manage. If you think about it, uh I guess they would they wouldn't really care about US-based companies, but if you if you're if a US-based company and you have um you know users sitting in the EU, like I don't know how how the hell one you track this, like whether or not things obviously if AI is meant to kind of service the entire enterprise, there's gonna be times where AI generated content is crossing boundaries between one or the other. Um, I don't know if these kind of what are they calling them, the uh machine readable markers. I don't know if these markers need to be stripped at that point or if they kind of um need to be ever persistent across those boundaries. And also like who owns it? Like it like is is the legal and the platform teams responsible for making sure that this this happens on uh you know content within the EU and and not in other boundaries, like uh, or do they just implement it across the board just to make sure uh that they're compliant? Because obviously the the fines are are quite quite hefty. Um yeah, I think I I don't know how they measure it, but um I think it's gonna be a fucking nightmare.

Tim

Yeah, I no you're right, you're right. The general of the EU swings the hammer incredibly hard. And and as usual, it's one of these things where governments don't necessarily understand how the technology is being consumed or worked or or like delivered, right? So, like for example, uh, you know, if it says the EU market, but like that's extremely broad. Is that are we saying any person in the EU that can access a website is now this is the EU market? Like, you know what I mean? Like if I make a if somebody makes a TikTok and TikTok just happens to be available in Europe through the Apple store or something like that, is you know, is ByteDance or not ByteDance? Uh who's who owns the who bought it?

Chris

Yeah, it's ByteDance.

Tim

Oh no, that's Yeah, well internationally it's still ByteDance, right? Yeah, yeah. Internationally it's still ByteDance. Um, you know, is ByteDance on the hook? Is it considered part of the EU market because somebody in the EU can access TikTok? You know, and if not, are they required is every company that doesn't want to do this now forced to block users from the EU? Uh is that like I there's definitely some execution questions uh left hanging on this one.

Chris

I f I feel like it's written so vaguely, it's it's a perfect opportunity for someone to get made an example of whenever they push the boundaries a little bit too far in either direction and don't play the politics side of it right. Um they'll they'll definitely have the the the kibosh put down on them pretty quick.

Tim

Okay.

Anthropic Watermarks And Metadata Questions

Tim

Uh and as a follow-on for that, so Anthropic has pledged to embed watermarks uh to for to comply with this Transparency Act, by the way. Just that's that's their goal. So Anthropic said it'll embed imperceptible watermarks in text generated by Claude models and add digitally signed provenance metadata to generated files where supported in response to EU AI Act requirements. So I mean that's I work in technology and I'm not sure what that actually means, but okay. Um so the change applies globally across all Claude products, including the API. So if you if you are using Claude even via API call, your the what you get back from the model will have some kind of watermark in or metadata included. Um so yeah, so third party providers, AWS, Google Cloud, Microsoft. Um there's a lot of, I mean, yeah. So does it are they gonna watermark the images? And if they do, I mean, obviously it would watermark it in a way that it's not visible, I I would assume. But you know, you can always use things to there's tools that'll strip all that out, right? So what does that look like? Um and Anthropic itself says detected marks are not conclusive proof of AI authorship, which is interesting. It's an interesting thing to say in the same breath that you're saying we're putting watermarks on all our shit. So I d uh so if it's if it doesn't prove anything, it literally is like, hey, uh we're this is just kind of a best effort checkbox thing, is what Anthropic is essentially hedging on.

Chris

So I mean I I guess at some point, you know, uh there's probably an assumption that yeah, all the all the code and potentially all the uh the ABI calls, whether or not they're using something like an MCP or or an uh agent-to-agent protocol or something like that. Maybe they're some they're assuming that all of this is going to be running by AI anyway. And you know, maybe the maybe the foundation models build something in to say, you know, if this model it will always have context to know that it's running within the EU and if it gets these kind of uh kind of machine readable markers and an API response or something like that to not strip those. Because yeah, if like if if I'm a developer and I'm building this, yeah, uh every API call, I don't need all the fucking data that's in there, man. I only pull out exactly what I need and use that to to iterate and um add that to my next item. So if you have to carry that forever, um like yeah, I the I think obviously, like you said, the I think the government side of it and the um technology side of it just do not line up whatsoever. I don't know how the hell you track this, I don't know how you enforce it. Um and it just sounds like a headache for for probably everyone involved.

Tim

Yeah, it's classic, you know, government compliance requirement meets uh like what's possible, right? Like what's actually available and potential like could actually meet the requirement, but also meet the spirit of the law. And I think that part is still even a bridge further uh yet. So 100%.

Copilot As An Insider Threat

Chris

All right. Let's move on to hopefully some some more fun stuff. Um all right, so next up we have some um uh some stories about AI-enabled attacks being on the rise. So first up we have one about AI-enabled email accounts um acting as an insider threat vector. So uh this one here we have directly from the Barracuda blog. So Barracuda's rev team actually ran a controlled proof of concept showing how a compromised AI email or sorry, AI enabled email accounts, uh which was co-pilot, Microsoft's co-pilot within their specific test, can become an insider threat. So the the assistant actually used um the assistant was used, sorry, to establish persistence and identify targets within the organization, generating phishing emails, matching the victim's own writing style, and ultimately redirect uh a $247,000 wire transfer by impersonating one of the CEOs. Uh Barracuda's own framing is that the attack is not fundamentally new. What has changed is the speed, the scale, and the efficiency to which an attacker has uh access to those. And I th I think we've we've talked about this on the show quite a bit, right? Like the I don't think everyone's you know talking about mythos and talking about Fable and you know kind of the the sophistication growing of the attacks. I think I think this is kind of the bigger problem is just the the sheer magnitude of the attacks, um, whether they be kind of low IQ attacks like this one or not. Um there's gonna be uh a a way larger amount of those in the pool um at any given time. And you know, people are really just gonna have to be on the defensive. And I wonder how much um, you know, you're the people go through these cybersecurity trainings and all a lot of the stuff seems ridiculous, but I wonder if you really are just gonna have to be like um at this point where you essentially trust no one. Um and you know, we have MFA enabled just to fucking talk to somebody on the phone and things like that, right? It's gonna be I wonder if it's gonna get pretty ugly. Safe words. Yeah, exactly.

Tim

Yeah, give me your safe word before I talk to you. Uh yeah. Did we rotate the safe word last week? I don't remember. No, I mean, okay, so that for first of all, obviously this is a blog, this is a vendor blog, but it's it's what is it what the the the thing that it says? No, but the thing that it says is still true, right? Like anybody could figure out that, hey, if I hook up some AI thing like co-pilot or whatever it is to my outlook, and it can go through my mail, it can read me, it knows everything that is in my email, basically, knows my calendar, it knows how I write emails, it knows what I'm working on essentially because of that, right? If that email box was compromised, not the box, not even really the box, right? If if the AI was compromised and it could read all of that data, I mean, could you spear phishing at a scale that is insane, right? Like, I mean, beyond beyond spear phishing at that point, right? Like it already knows exactly the context to sending people emails. Hey, that thing I was, you know, that thing I sent you last week, you know, hey, I I I finished it and here's a here's a malware enabled file, like, you know, doc X or something. Like it's like yeah, the mind boggles on how and again, like they point out, it's not that it's more it's not even that it's like super, super sophisticated, but speed is really the the thing to to consider, right? Like a a human can only type so fast, can only copy and paste so many things. Even people writing scripts, you know, that you still there's still some lag involved when a human is is doing things, right? But an AI can you know can just do it so quickly because it doesn't have to the eyes don't have to read what's on the screen, right? Like there's no anyway. So yeah, Barracuda pointing out that like, hey, this is not a new new attack, it's the speed and the scale. And that's what we're gonna see, I think, is a lot of you know, before uh a lot of these attacks are it's like the swing school of fish thing, right? Like, you know, you're you're safe in the pack because only a few fish can get at a time. This is this is where we're headed, right? This is where we're headed, especially as we do more open, open flaw type crap where we integrate AI more and more into the things we know and can do. It becomes super uh easy to impersonate someone once you've compromised that AI.

SPEAKER_00

Yep, 100%.

Rogue Agent Escapes And Hits Hugging Face

Chris

Um, and all right, and kind of on the back of this, this was probably a relatively much bigger story. You may have already heard about this at this point, but uh so OpenAI um uh actually disclosed recently, I think it was just kind of late, uh late last month, yeah, on the 29th of July. Um, disclosed that a rogue autonomous agent had actually escaped from one of their test environments and compromised Hugging Face, um, which is if you know Hugging Face is kind of responsible for hosting a lot of these kind of third-party open weight models that a lot of people are using for uh numerous projects around the world. So um it was compromised Hugging Face and also reached out for uh and also reached four additional third-party services using publicly exposed credentials that have found online. The agent executed 17,600 attacks, uh attack actions between July 9 and 13th. So right there. Kind of exactly what we were talking about in the last article, just the the magnitude of these things, right? Like what is how many humans are executing, you know, 17,000 attacks in about four days? Uh so it's uh pretty significant. Um and it spent more than two days penetrating Hugging Face's infrastructure, right? So this is kind of just like pounding it day in, day out, right? Because it's been given an extra an instruction that it needs to come you know comply with. Um and the impact on the other four organizations were less severe. Modal labs confirmed that the agent exploited an unauthenticated customer endpoint, while the platform itself was not compromised. Um, yeah, I think when this came out, I think Hugging Face was kind of coming to the table saying that, you know, hey, we think we've been compromised. And then I think actually OpenAI had to come out and be like, hey guys, actually uh we did some research into it. It was us, we found it. Um I think in this one it it's it's kind of hard to correlate everything because uh shortly after this happened, Anthropic also came to the table and like, hey guys, our our our model was smart enough to break out of its harness too. Like it it did, you know, it did bad things and all this stuff. I don't know why that's uh something you really need to be a uh a a me uh pick me about. But um the I think there was some level of it to where the agent was acting under the context where it was like it it still had internet access, but I believe they told it it didn't have internet access, but they gave it kind of specific instructions to complete a task, right? So it used everything that it could and discovered, oh hey, I have internet access, I can actually do this and and that. And obviously 17,600 attacks later, uh here we are. So yeah, any uh does this give you warm fuzzies, Tim? How's your how's your harness today?

Tim

I I think it's a weird flex by these companies, and I get where they're going, right? Like they're saying, oh, our models are so freaking smart that even completely unprompted, they can figure out how to escape their sandbox or their harness. And I'm not actually having used AI now extensively, built many things with AI. You know, I just finished a I just finished a Claude uh agent building Clote uh camp with uh Andrew Brown over at Exam Pro, which is awesome, by the way. I went through the whole thing. They're not super intelligent, right? Like, yes, they'll they'll they'll use whatever methods are available to them. So really the what what is a flex should really be a fucking black eye. Like, wow, congratulations. You are so bad at building sandboxes and harnesses for your shit that like it literally just said, hey, I need internet access. Oh shit, I've got it, and it just like goes. Like that's not that's not something to flex about, guys. Like it doesn't, it's not that you know, it's not that your model is so you know, star-spangled smart. It's that you guys just have done nothing to contain it, really, you know, other than saying, hey, you can't use the internet somewhere in a prompt somewhere or something, you know. Um yeah, and I'm not I'm not impressed uh by I'm not impressed by it breaking containment, containment, which clearly wasn't very containing. Um and and we know we've got so many stories now of if you are not extremely specific with your instructions that you know it will just pursue, it's like the terminator, right? It will not it doesn't feel, it doesn't it just will not stop until you are dead, type of thing.

Chris

This is this is kind of like uh if you expect the uh like on the uh classic Cisco uh SSH things like that. If you it if the message of the day banner says, hey, don't hack this system, it's it's managed by this organization. If you expect that to do anything, you're you're you're fucking nuts, right? Uh that's just kind of uh uh purely for liability, but it's like uh there's a you would think the things are smarter than that, but you know, here we are.

SPEAKER_00

Yeah.

Tim

We got I think we got one more story which just came out, which is uh Yeah.

Chris

Yeah, this one this one's pretty fresh.

US Plan For Private Offensive Cyber

Chris

So if we don't cover all the the pieces tied to it exactly correctly, we're sorry, but it's uh pretty hot off the press, so we feel like we should we should probably bring it up.

Tim

Sorry, lost it there for a second. Um so yeah, so now that there was so uh and when you say hot off the presses, uh to be clear, we're we're recording this a day late. So this came out yesterday. We would have missed this basically. We had if we'd actually released on time uh yesterday. So there's a a presidential memorandum from the uh Trump administration, quote unquote, expanding capabilities to combat transnational cyber enabled crime. That's a mouthful. So what this does is it directs the creation of a program that lets vetted, vetted, and I'm using the air quotes here, vetted, private you private U.S. companies. This is the government telling private U.S. companies to conduct offensive cyber operations against foreign criminal organizations under federal direction. So there was already an earlier executive order um in March, just generally talking about cybercrime and fraud and whatnot. This is actually saying, okay, well, we're gonna do something about it. And by we, we mean you are gonna do something about it. So yeah, all right, let me just go get through the structure. I've got a lot a lot of thoughts on this one. Uh so the National Coordination Center, uh, which was established under another executive order, creates and runs a program. Uh or which are create, sorry, uh different EO. The the the the the I can't follow the the numbers of the EOs here. That they just give the number of the EO. So uh are authorized, so okay, so runs the program. Participating companies in air quotes are authorized to conduct cyber surveillance operations, which is basically what I would assume is reconnaissance, right? Using the cyber using the um cybersecurity terms, I assume we're talking about reconnaissance, not actually uh exploits or uh stuff like that. So covert intelligence collection, um explicitly involving access without owner authorization. Oh, okay. So this actually does go in, go does actually get into exploitation and cyber effects operations, which include manipulation, disruption, denial, degradation, and destruction of quote unquote these cyber, these foreign criminal organizations, uh, which are they're designating as CE-TCO, which I don't know what that means.

Chris

It's a foreign group, C O or the transnational cyber that's right, the criminal criminal organization uh organization.

Tim

That's right. That's right. Yeah, yeah. Uh foreign groups conducting cyber naval crime against the US, its person or interests. This is like the the the what the hand that that that holds this thing is gigantic.

Chris

Yes.

Tim

Yeah, so and this is the probably okay. So the oversight for this giant program sits with two co-executive directors, one from DOJ and one from DHS, which fills me with no end of official.

Chris

That's two or the two organizations that you trust very much, right?

Tim

Yeah, that I trust the most. Who must coordinate on every approval and must give written approval of each operation's package before action. Companies contract with DOJ or DHS. Okay, so this is uh okay, I get it now. Uh undergo vetting and may be required to post a bond or escrow, uh, a forfeitable one million dollar escrow for non-compliance. Non-compliance? I have so many questions. Um crazy. Uh, they may also sign commercial agreements to receive threat intelligence from private firms and federal, state, local, tribal agencies, much must be disclosed to this NCC. Uh okay, so here's limits and guardrails. This is the okay, I'm curious about the limits here. Operations that would produce critical outcomes, which are loss of life, injury, or conduct rising to use a force or armed attack under international law, cannot be approved at the executive director level. However, implies that it can be pred can absolutely be approved at a level above the executive director. Yeah. Uh anything touching a US person requires DOJ review. I'm I still I feel really, really safe now. And any uh necessary authorization uh judicial or otherwise before approval. Accidental targeting of a US person, U.S. resident system, or system controlled by a US person triggers mandatory cestaction, minimization, and notification up to the DOJ. So the Foxes are guarding the analysis on this one. Um, same for discovery of an imminent attack on U.S. critical infrastructure. Uh 60 days, program directors, publish operating procedures coordinated with Homeland Security, 180 days, and annually there's a status report to Homeland Security and National Cyber Director. Oh my god. Uh yeah. So, Chris, I'm sure you have thoughts. Having just become a having just joined the uh another nation.

Chris

Yeah, true. Um, yeah, on the day we recorded this, I actually just uh got notification that uh my Australian citizenship by conferral was approved, so I have to go do a ceremony and things like that at some point. Um and yeah, this I mean, but that's the thing. I've uh what I'm learning is if you want to give up your US citizenship, it's it's 10 times as hard as getting uh citizenship somewhere else. Um so I I will still be kind of uh under the guise of things happening in the U.S. I'll still have to follow U.S. tax return probably till I'm six feet in the ground. Um so this still applies to me and still does uh it does not give me warm and fuzzy because obviously there's a lot of limits and guardrails built in here around you know what they're proposing should protect uh U.S. person or persons um from kind of the outcome of this. But I mean, we've not known this administration, and and I'm not even being overly like polarized in one camp or the other. I don't think whichever midman right, the five years. Whichever administration is in in in you know in charge at a given time. The U.S. people have never not been used as cannon fodder for for events like this, right? So I see no reason why this wouldn't happen again. And you know, this kind of just like to me, the way it reads, it's like, hey, you know what? Nation states are attacking us, you're allowed to do the same thing back to them. Um and that gets really fucking ugly. Uh so I I uh this probably operating well above my pay grade to really understand what that's gonna mean under the hood, but I don't trust the vetting program. I don't trust uh the way these kind of uh critical outcomes are gonna be measured um across the board. Um I just see this as fucking bad um and and relatively scary.

Tim

Yeah, I mean again, set politics aside, generally speaking, it would be a terrible idea to give the government power over something like this where it can where it's got, you know, it's it's essentially contracting or maybe even forcing, there's this bit about non-compliance here, uh private companies to act on its behalf. Like that that's terrifying. That should be terrifying to anyone in the US, regardless of the politics. Because think about this, because who gets to oversee you know what constitutes any one of these cyber crimes or who these quote unquote foreign nationals who they are? Who who designates the TCO? Like, and who decides what a TCO is? Like, like just they just think this through, right? There's nothing political about this, and yet there's I mean everything political about this if you think about it, right? So this is just a terrible idea, and I don't trust any part of it. Um again, not because of just just because of this current administration. I wouldn't want to hand the keys to this to any government. Like, yeah, nobody should be. Yeah, we should not have a government that has this has this. Luckily, it's an executive order and not like a codified law, right? But you know, we still

Quick Laugh Then Closing

Tim

have two years to deal with uh this executive order, so yeah, this is terrifying. Um, I'm just gonna I'll just leave it there. Like this this is scary.

Chris

Curious to have your thoughts. Like we said, this is brand new off the press. So if you have thoughts, uh yeah, hit us up. Love to hear from you.

Tim

Yeah. And with that, I feel like we never end on a high note. We should have put we should have covered that one earlier and ended on a high well, we didn't really have a lot of things.

Chris

There's one, there's one, I'll tell you what, there's one we can put in the show notes about um after DEF CON, some individuals had a pineapple on a Delta flight and were impersonating.

Tim

Is that a is that a high note? I'm not sure that's a lot.

Chris

Well, it's at least it's at least it's a little funny. I mean it's they did a bad thing, but at least it's not like the the downfall of humanity, and you know, so it's a little bit more.

Tim

Yeah, we'll throw that one in there, but it is interesting, and that one again is very high off the presses right after DEF CON. Yeah. Um that the U that the the pilots actually reported it to ground control and they were arrested like when they came off the flight. Um yeah, don't don't do that. And if you're gonna do that, or or rather if you're just don't do that, but then don't maybe don't post a bunch of jokes about how you're about to get on a flight and show your pineapple and talk up and end up on the no-fi list. So yeah, we'll uh we'll leave it there. All right, everybody. We're gonna wrap up here for the for the month, and uh we'll see you on the next episode.