Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andy Ellis

πŸ‘€ Speaker
414 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

One reasonable choice is you authorize that computer for that user to log in on it, or you make it impossible for that user to use that computer.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

What often happens is people say, well, by policy, you can't do it, but we won't support you.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

But then that means you don't actually have a good authentication system in place if you're allowing the person to log in from an unknown computer.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

I don't even want to use the word trust.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

I just want to say known.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Like when we first did our zero trust implementation over a decade ago, my attitude was, if you've got 12 computers at home you're going to log in on, I'm going to put a credential on every single one of them so that I know that they're yours.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

We'll worry about trust later.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

But the first thing I want to do is say you can't log in from an unknown device.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Then we'll worry about trust.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So first of all, just as a warning to everything, they can vibe code every solution out there.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Almost any company you could build their basic functionality that they have in a weekend.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

If you're an amazing developer vibe, coding makes that a little bit faster, but basic functionality is not what people tend to buy.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Right.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Nobody's buying threat locker since I've got Danny here, like just to do the basics of what threat locker can describe in 30 seconds.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

It's the details and the hard work of making sure things work at scale, right?

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Why do people still use Google search?

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

Isn't hard search at high quality is.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So be careful, like if you're vibe coding your SCA, if you wanted really good SCA, you might not get that out of vibe coding.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

So it's just your cautionary tale.

CISO Series Podcast
There's Nothing an LLM Can Screw Up That the Cloud Didn't Do First

But here's the answer, which is think of your vibe coding agent, whether it's Claude or something else, as a new sort of fractional employee, and you should be onboarding them and teaching them how to do their job.