Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andy Ellis

πŸ‘€ Speaker
414 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

The human challenge is humans don't use most of their permissions because we give people way too broad permissions because we don't understand what people do.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

The core of the problem is we don't actually govern humans.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

identity or authorization, however you want to look at that.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

What we do is we sort of say, oh, like Danny has just come into the organization.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Let's just clone somebody else's permissions and give them to Danny.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Nobody actually knows what Danny's job's going to do.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

He changes from one organization to another.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So we leave all of his old permissions there while he goes over in case he gets called.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

And over the course of 15 years at a company, Danny ends up with access to everything, but he's never using it.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Then Danny goes and deploys an agent and the agent's like, oh, I have access to these things.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

And I could probably use that in answering some question.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So I'm going to grab access to everything.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

And that's just a key piece of it, which is the thing we've never solved, which is governance over what people do, because we don't know what they do.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Authorization and permissioning is just the shadow reflection of what the business needs the person to do, but we don't understand that.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So instead we treat it like a ground truth.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

We give it lots and then agents just abuse it.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So this is not me saying this problem isn't worse.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

This is me saying this has always actually been the worst problem we have.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Now it's just gotten even worse.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

No, no.