In short
Odd Lots Podcast Episode Summary
Episode Title
Legendary Hacker Matt Suiche on Cyberwar in the Age of AI
Episode Description
In this episode, hosts Joe Weisenthal and Tracy Alloway explore the evolving nature of warfare, particularly the intersection of cyber capabilities and physical conflicts. They are joined by Matt Suiche, a renowned hacker and founder of OnDB, who provides insights into Iran's cyber capabilities, the current landscape of digital warfare, and the implications of AI on hacking and cybersecurity.
---
Key Themes and Discussion Points
- Blurring Lines Between Physical and Digital Warfare
- Recent events highlight the merging of kinetic and cyber warfare.
- Incidents include Iranian drone strikes on UAE and Bahrain data centers, Israel hacking traffic lights in Tehran, and suspected Iranian cyberattacks on US companies.
- Matt Suiche's Background and Expertise
- An experienced cybersecurity professional with a history of involvement in significant hacking events (e.g., Shadow Brokers, WannaCry).
- Discusses the relevance of cyber tactics in the context of ongoing wars, emphasizing that traditional cyber capabilities are more effective during pre-war phases for intelligence gathering.
- The Role of AI in Cyber Warfare
- AI is transforming approaches to hacking and cybersecurity.
- The emergence of AI tools presents new capabilities but also raises risks related to data privacy and security.
- Current Cyber Events and Observations
- Israel's use of cyber operations to create confusion in Iran and the effectiveness of these tactics.
- Discussion of recent Iranian attempts at cyberattacks which seem less destructive compared to traditional kinetic warfare.
- Traditional Cybersecurity vs. Kinetic Attacks
- Suiche argues that while cyberattacks typically focus on espionage, kinetic attacks can directly disrupt crucial infrastructure (e.g., data centers).
- The cost-effectiveness of low-cost drones for targeted attacks highlights a shift in warfare strategy.
- Perception and Reality of Cyber Threats
- Public perceptions of cybersecurity threats often overshadow the reality of their impact; much of the ongoing tension is tied to historical context and ongoing geopolitical dynamics.
- The discussion covers how misinformation proliferates during high-stakes international conflicts.
- Future of Cyber Capabilities
- Governments are investing in tech partnerships with private companies for cybersecurity solutions, which has implications for national security.
- Concerns about insider threats and leaks within government cybersecurity infrastructure.
- Impact of AI on Software Development
- The concept of the "SaaSpocalypse," where the cost of developing software approaches zero due to AI capabilities.
- Exploration of how enterprises might handle security amidst rapidly changing software landscapes.
- Cultural Shift in Software Development and Cybersecurity
- A shift from traditional high-quality code to an acceptance of "slop code" as AI-generated outputs become more commonplace.
- The increasing importance of data quality amidst a landscape filled with misinformation.
---
Key Takeaways
- The intersection of kinetic and digital warfare is becoming increasingly blurred, with traditional cyber tactics giving way to more direct physical attacks on infrastructure.
- AI is a double-edged sword in cybersecurity, offering new capabilities while also introducing new risks.
- Understanding the dynamics of misinformation and public perception is critical in the context of national security and cyber capabilities.
- The future of software development and cybersecurity will be heavily influenced by AI, impacting costs, security protocols, and the overall approach to building and maintaining infrastructure.
---
Conclusion This episode provides a comprehensive look at the current state of cyber warfare, the potential future with AI integration, and the evolving landscape of national security. Matt Suiche's insights offer valuable perspectives on the need for robust cybersecurity measures, especially as geopolitical tensions rise.
---
For more information and to stay updated on similar topics, follow [Odd Lots](https://www.bloomberg.com/markets) and subscribe to their newsletter.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOPrepper Tendencies and Cash Discussions
1:18 to 2:18
Tracy and Joe discuss their prepper tendencies and the importance of cash in uncertain times.
“Hello and welcome to another episode of the Odd Thoughts podcast.”
The Cyber Threat Landscape
2:18 to 3:19
A discussion on potential cyber attacks related to geopolitical tensions, particularly concerning Iran.
“By the way, have I told you my idea for business?”
AI's Impact on Cyber Warfare
3:19 to 4:44
Exploration of how AI is changing the landscape of cyber warfare and the implications for national security.
“But there's already within the war itself, or even over the last couple of years, there was the pager attack that Israel had executed.”
Introduction of Matt Suiche
4:44 to 6:02
Matt Suiche is introduced as a guest expert on cybersecurity and AI.
“And there's been examples of leaks where, you know, people upload data to the AI and somehow other people see it.”
Matt's Background in Cybersecurity
6:02 to 7:14
Matt shares his extensive background and experiences in the hacking community.
“But as we have seen now, you can use like drones that are like$20 ,000 and create more chaos that you would do with any sort of exploits.”
Cyber vs Kinetic Warfare
7:14 to 8:38
Discussion on the differences between cyber and kinetic warfare, especially in the context of recent events.
“But this is a really interesting point that you made, this idea between, okay, mostly it sounds like when people imagine cyber attacks, they imagine what Tracy talked about in the beginning.”
The Nature of Recent Attacks
8:38 to 10:34
Matt discusses recent cyber attacks and their actual impact during warfare.
“And once you have some sort of centralization in terms of dependence, you also become an easy target.”
Monitoring the Situation
10:34 to 11:30
Exploring how to effectively monitor the cyber threat landscape amidst misinformation.
“so it's more like to create confusion than being actually destructive and now we're definitely entering in a stage where it's been extremely destructive.”
Data Center Attacks and Their Impact
11:30 to 14:03
Discussion on the significance of attacks on data centers and how they blur the lines between cyber and kinetic warfare.
“How do you actually know what's real and so forth and avoid just sort of the delusion of staring at the screen and engaging with slop?”
Data Center Attacks: A New Kind of Warfare
14:14 to 14:57
Discussion on the impact and dynamics of kinetic attacks on data centers.
“Can you actually talk a little bit more about the data center attack?”
Show all 26 chapters
Shifts in Government Cyber Capabilities
14:58 to 18:36
An overview of how governments are adapting their cybersecurity strategies in the AI era.
“like thinking about hardening these data centers and as you say, like making them, they're going to be increasingly targets for war.”
The Role of AI in Cybersecurity
18:37 to 20:46
Exploring the integration of AI in exploit development and its potential risks.
“How are you balancing those decisions nowadays versus, say, 10 or 20 years ago?”
The Cost of Software and Implications of AI
20:47 to 23:28
Analyzing the decreasing costs of software production and its effects on security.
“So we started to see people leveraging AI for bug discovery, which actually is becoming pretty good.”
AI Agents: Opportunities and Security Risks
23:29 to 28:00
Discussion on AI agents' capabilities and the new security challenges they bring.
“Because like that's the only thing that's really going to have value long term if agents need something to transact or to take decision on.”
Data Security Concerns in AI
28:00 to 28:31
Discussing vulnerabilities in AI and enterprise security practices.
The Evolution of Privacy Concerns
28:31 to 29:26
Exploring the changing attitudes towards privacy from the Snowden era to today.
“But, you know, if people are ignoring what has been done in terms of software security for the last 20 years, that's why we're going to have a lot of problems.”
AI's Current Utility and Limitations
29:26 to 31:04
Examining the practical applications and challenges of AI in security and data analysis.
“coding experience would have been different if you were, say, starting out now in 2026 versus, I guess you would have started out in like the late 90s or early 2000s, maybe even before that.”
The Future of Software Development
31:04 to 32:51
Discussing how AI is changing the landscape of software development and costs.
“So you must think that it's going to be used or that, you know, or that there's clearly something there.”
The Transformation of Data Economics
32:51 to 34:31
Analyzing how data consumption and payment models are evolving with AI.
“So our conclusion is that data is the only thing that's going to be like timeless in the AI economy.”
Streamlining Data Access for AI
34:31 to 36:32
Discussing how to simplify data access for AI applications and agents.
“So it's us anticipating that enterprise is going to look very different, and they won't just run like anything they find online.”
Challenges of AI-Generated Code
36:32 to 38:45
Exploring the implications of AI on coding practices and software quality.
“A bit like open router for AI models, but for data providers.”
Quality of AI-Generated Code
38:45 to 42:11
Evaluating the quality of code produced by AI and how to improve it.
“Because I remember one of the things that happened in the early days of AI development.”
Understanding Code Quality and AI Interaction
42:11 to 43:30
Learn how to effectively communicate with AI to improve code quality.
“It needs all kinds of fixing and so forth.”
Cybersecurity and Geopolitical Implications
43:30 to 45:28
Explore the connection between cybersecurity and recent geopolitical events.
“You know, like, the more explicit you are, the better it's going to understand how far it is from the requirement.”
The Future of AI in Warfare
45:28 to 46:58
Discuss the ramifications of AI usage in modern warfare and its economic impact.
Cyber Warfare and Physical Security
46:58 to 48:52
Understand how cyber warfare integrates with physical security measures.
“Tough choices potentially coming for Havelock as your token costs go up.”
Transcript
Automatic transcript. May contain errors.0:00Tracy Alloway:Running a business means dealing with a lot of overly complicated software, and most CRMs tend to follow the same pattern. They're packed with endless features you'll never use, interfaces that feel clunky, and teams end up spending way too much time just trying to find basic information. Today's sponsor, Pipedrive, is a simple CRM tool designed for small and medium businesses. Pipedrive brings you entire sales processes into one dashboard, giving you a crystal clear, complete view of sales processes and customer information designed to help teams stay in control and close more deals faster. It all centers around the visual sales pipeline, where you can see every deal, what stage it's in, and what needs to happen next.
0:35Tracy Alloway:Since everything is in one platform, PipeDrive is designed to unite your team, keep track of sales tasks, and stay on top of your leads. Switch to a CRM built by salespeople, for salespeople, and join the over 100 ,000 companies already using PipeDrive. Right now, you'll get a 30-day free trial. No credit card or payment needed. Just head to pipedrive.com slash simpleCRM to get started. That's pipedrive.com slash simple CRM.
1:02Joe Weisenthal:Bloomberg Audio Studios.
1:05Tracy Alloway:Podcasts.
1:06Joe Weisenthal:Radio. News.
1:18Matt Suiche:Hello and welcome to another episode of the Odd Thoughts podcast. I'm Tracy Alloway.
1:22Tracy Alloway:And I'm Joe Weisenthal.
1:23Matt Suiche:Joe, you know I have some prepper tendencies.
1:28Tracy Alloway:Yeah.
1:28Matt Suiche:Slightly prepper tendencies. Prepper adjacent.
1:31Tracy Alloway:I know you do because my plan for when everything goes bad is to bring my family over to your place. So I'm relying on you, actually.
1:40Matt Suiche:That's fine. I actually figured that and I've been building an extra store of supplies.
1:44Tracy Alloway:I'm going to send you a whole list of things my kids like to eat and stuff like that just so that we're all ready.
1:51Matt Suiche:OK, well, one of the things I saw on a bunch of the prepper boards that I sometimes look at, I don't want people to think that I'm crazy about it, but I find it interesting. I find it interesting seeing how people's like insecurities manifest in physical stuff. But anyway, one of the things everyone was saying was you need to start taking cash out because of the situation in Iran, because we're all expecting a big cyber attack that's going to absolutely destroy the U.S. financial infrastructure. sure.
2:19Tracy Alloway:By the way, have I told you my idea for business? Like I've looked at prepper meals, like prepared meals, and they all look terrible. They do. Like a slightly high end version for yuppies, I think would be really good. Like something that, you know, like some nice.
2:32Matt Suiche:I think it's a physical limitation on how good you can actually get like dry food.
2:37Tracy Alloway:Science can do a lot of things these days. Anyway, let's talk about the actual issue at hand. Yeah. Well, are you taking cash out? No, I haven't.
2:45Matt Suiche:I haven't yet. I'm relying on my store of gold and silver. That's right. But I think this raises a legitimate and actually very interesting topic, which is what do we know about Iran's cyber, I guess, facilities, skills, what could happen in this context? And then also everything that's going on with the world of AI, right? Like cybersecurity, cyber hacking, it's changing really rapidly given this new technology.
3:15Tracy Alloway:Totally. I mean, also, just within the context of the war itself, setting aside hypothetical doom scenarios, there's a really interesting report in the Financial Times about Israel having been able to hack into all of the traffic lights in Tehran. Almost unbelievable and shocking. But there's already within the war itself, or even over the last couple of years, there was the pager attack that Israel had executed. And so, yes, cyber is part of it. And the timing is wild here because speaking of AI, it was just on Friday. We're recording this March 5th. I'm not exactly sure the date is coming out.
3:50Tracy Alloway:But a week ago, basically, there was the news, the complete collapse of the anthropic relationship with the Department of Defense or the Department of War. And so it's all in the mix right now. And how is AI actually going to change warfare? And what are the national security implications of AI and AI and hacking? There is a lot in this sort of mix that's all happening right now.
4:10Matt Suiche:Absolutely. The thing that really caught my eye was the story about a hacker using Claude to hack into like the Mexican government system. Did you see that?
4:18Tracy Alloway:That was really interesting because it seemed like the hacker extracted a bunch of information from Claude itself. You know, I'm pretty sure you cannot go to Claude code and say, like, I want to break into the Mexican government website. Help me, like, build this app. It won't do that. It's trained to avoid malicious uses. But people find a way to jailbreak them. people find a way to sort of extract information from the AI itself that it has in its training and so forth. And there's been examples of leaks where, you know, people upload data to the AI and somehow other people see it. Anyway, there's a lot here that we have to learn more about.
4:53Matt Suiche:We should talk about all of it. And we do, in fact, have the perfect guest, someone who's been on the podcast before, but it's been a while. We're going to be speaking with Matt Swish. He is the founder of ONDB, which is a data infrastructure startup for Agentic AI. So So honestly, the perfect person. And a legendary hacker. A legendary French hacker. I should have said that first. Matt, thank you so much for coming back on All Thoughts.
5:16Joe Weisenthal:Thank you very much. It's been a while. I think it's been, what, four years? Yeah, I think it has been.
5:20Matt Suiche:The last time we spoke to you, you were still in Dubai. And now you're coming to us from Sweden and a very Gustavian-looking background over there.
5:28Tracy Alloway:I think actually when we talked to us right after Russia's invasion of Ukraine. So I guess, yeah, wow, that has been almost four years now.
5:34Matt Suiche:Every time there's a war, we call you Matt.
5:35Tracy Alloway:But because war is so intermixed with cyber espionage, cybersecurity, hacking, and so forth, it's a natural time.
5:42Matt Suiche:So for the benefit of people who didn't listen to the episode four years ago, can you just give some context around who you actually are and your sort of history in the hacking community, including, you know, shadow brokers and the WannaCry era and all that stuff?
5:56Joe Weisenthal:So I've been in enterprise software for almost like 20 years, particularly cybersecurity. And my name appeared in a few of the different leaks because of various analysis that I've done of private information that was being leaked, but also a lot of attacks that happened that happened to target critical infrastructure over the last 10 years. and last time we were on the podcast one of the things we talked about is does cyber really matter once you enter into a kinetic war which is exactly what's happening now and the main takeaway was once you start using missiles most of these cyber elements are not really relevant because you would use cyber mostly to gather information and intelligence to prepare an attack or to disorganize an enemy, you create confusion.
6:49Joe Weisenthal:But as we have seen now, you can use like drones that are like$20 ,000 and create more chaos that you would do with any sort of exploits.
6:59Tracy Alloway:You know, I like how you're introduced as a legendary hacker. And then you're like, oh, I've been 20 years in enterprise software. I feel like this is like the Winnie the Pooh meme. It's like, you know, the casual. That's right. And then fancy dressed up.
7:11Matt Suiche:Hacker and then enterprise software.
7:13Tracy Alloway:It's like 20 years in enterprise software. But this is a really interesting point that you made, this idea between, okay, mostly it sounds like when people imagine cyber attacks, they imagine what Tracy talked about in the beginning. Suddenly the entire financial infrastructure, like it would just come to a hall of people worried about, or there's going to be a blackout, et cetera. But in reality, or what we've seen so far by and large, is that cyber in the context of war is still much more about data collection, espionage, and so forth, rather than these more like, you know, the types of things you might see in a movie.
7:50Joe Weisenthal:Yeah, exactly. I mean, over the last like 10, 15 years, we have seen some like attacks, like cyber attacks against a critical infrastructure. Iran targeted like Aramco around like 2012. They were just mostly using what we call a wiper. That was like a malware that was erasing the hard drive of most of the machines. And then we obviously have the case of Stuxnet a few years before, where it was a joint Israeli-US operation against some of the nuclear centrals in Iran, where some of the PLCs were targeted. But what we have seen over the weekend is some of the drones happened to target some of the Amazon data centers.
8:32Joe Weisenthal:And that created so much instability because multiple of the zones have been down. And I think two out of three and the third one is still recovering days after because most of companies, either private companies or public companies now relying on the cloud, which is something that was not really the case before. And once you have some sort of centralization in terms of dependence, you also become an easy target. And most of governments, AI companies, cloud companies do not really have$20 ,000 drones in their threat models, which is like something that's pretty new, but also confirms that kinetic wars can have more impact.
9:17Matt Suiche:So I take the point about cyber being perhaps more useful before a war when it comes to info gathering and things like that. But we have seen some deployment of cyber attacks in the past week or so. So we know Israel is attacking some cyber infrastructure in Iran. And we know that Iran has perhaps attempted some things, maybe not as successfully. But walk us through what we've actually seen so far.
9:42Joe Weisenthal:So, so far, we have seen an Israeli operation where one of the prayer app has been hijacked and some message was sent to the users. So it's more like to create confusion within people. Also, the traffic light operation to understand the position of some of the targets, but it's more used for like reconning. And in terms of destruction, we didn't see anything significant. Even the government itself of Iran shut down most of the internet for a lot of the users. and a lot of what we see on social media is the usual disinformation and misinformation campaign especially now with ai there's so much ai slop with like the videos the text the bots that's becoming pretty common now even when there is no war so it's not really like really impactful so it's more like to create confusion than being actually destructive and now we're definitely entering in a stage where it's been extremely destructive.
10:44Joe Weisenthal:And I cannot remember the last time we've seen so many countries being targeted, which is pretty like a first, I would say, in term of like a war climate.
10:55Tracy Alloway:Can you talk about, you know, people stare at their screens all day and they fool themselves into thinking that they're, quote, monitoring the situation, et cetera, but mostly...
Read the full transcript
11:05Matt Suiche:Is that projection, Joe? I don't delude myself.
11:08Tracy Alloway:No, I like actually like I sort of look at my screen and I know that I'm being inundated with contextless garbage and slop and propaganda and so forth. I'm curious how you monitor the situation actually as someone who takes these topics seriously and doesn't just sort of become an overnight expert, you know, the day after bombings begin. And like, how do you pay attention to what matters? How do you actually know what's real and so forth and avoid just sort of the delusion of staring at the screen and engaging with slop?
11:42Joe Weisenthal:It's a good question because there's so much of it. So I think the default reaction is to ignore most of it unless it becomes really significant. In this case, I think it comes down to looking at the actual damage. many people from the military world but also the intelligence community has been underestimating our own capabilities exactly like people used to do with north korea and now north korea are some of the best hackers in the world when we see them like targeting financial institutions whereas before they would not do like much so there is definitely like internal capabilities that are available but there is so much noise now like you say a lot of people are monitoring the situation, giving that quote-unquote overnight expert opinions, and that's becoming a lot of noise.
12:31Joe Weisenthal:But I would say that in this particular case, we have heard of the imminent threat of Iran for around 40 years. And that's also not really a new situation. So most of people would have context around it. And even for like the attack that happened last weekend, many people were expecting them for weeks, especially as they are a continuation of what happened last summer.
13:14Tracy Alloway:Running a business means dealing with a lot of overly complicated software, and most CRMs tend to follow the same pattern. They're packed with endless features you'll never use, interfaces that feel clunky, and teams end up spending way too much time just trying to find basic information. Today's sponsor, PipeDrive, is a simple CRM tool designed for small and medium businesses. PipeDrive brings you entire sales processes into one dashboard, giving you a crystal clear, complete view of sales processes and customer information designed to help teams stay in control and close more deals faster. It all centers around the visual sales pipeline, where you can see every deal, what stage it's in, and what needs to happen next.
13:49Tracy Alloway:Since everything is in one platform, PipeDrive is designed to unite your team, keep track of sales tasks, and stay on top of your leads. Switch to a CRM built by salespeople for salespeople and join the over 100 ,000 companies already using PipeDrive. Right now, you'll get a 30-day free trial. No credit card or payment needed. Just head to pipedrive.com slash simpleCRM to get started. That's pipedrive.com slash simpleCRM. Can you actually talk a little bit more about the data center attack? Because that's not cyber, really. I mean, that's just kinetic warfare against the data center. I was surprised how disruptive was that?
14:28Tracy Alloway:I sort of would assume that cloud service providers, that it's fairly liquid. Okay, one goes down, but it can just be the same software can be run from numerous other clouds. But I saw that there were disruptions. I saw Fortnite tweeting about the fact that some of their gameplay was impaired due to the attack on data centers. How disruptive have those attacks been? Because this is, of course, a very, you know... This is where kinetic meets cyber. Yeah, and there's a lot, you know, in the future, like thinking about hardening these data centers and as you say, like making them, they're going to be increasingly targets for war.
15:05Tracy Alloway:Like how disruptive was that?
15:07Joe Weisenthal:Very good question. So I think one of the main takeaways is that it has been extremely successful. So like we said before, like a Shahid drone is around$20 ,000 and they managed to shut down two of the zones of Amazon. Actually, even if you look at the official report from Amazon, for like 36 hours, they were just saying, some objects struck the data centers before they actually explicitly said there were drone strikes. So a lot of services that have been using them have been targeted. So from like local applications, from two banks, because in a data center, you are taking care of multiple different services.
15:47Joe Weisenthal:Right. And even Versal had to reroute their data to Bombay and to exclude Middle East as deployment. So even if you take the cost of most of zero-day exploits that can go up to multi-million dollar attacks, if you are really aiming at destructing things, the cost reward of using such an attack is really efficient. So you really enter into some sort of asymmetric conflict where you can just spend like some really old material and have way more impact than someone who's going to be like cutting edge and just trying to impress with like capabilities, because at the end of the day, it does not really matter.
16:34Matt Suiche:How do governments actually build up their cyber capabilities nowadays? is because I have this image in my head of maybe 10 or 20 years ago, you know, they would recruit like a 20 year old such as yourself at the time and they would be working in a dark room, that sort of thing.
16:51Tracy Alloway:But then Red Bull, drinking Red Bull.
16:53Matt Suiche:That's right. But then, you know, we had the boom in Silicon Valley. And so you had competition from private companies. Now we have the boom in AI and again, even more competition from private companies. And at the same time, governments seem to be, I guess, seeding some of their own skill set to potentially private companies like Anthropic and ChatGPT and some others. Walk us through how, I guess, the development of governmental cyber capacity has actually shifted.
17:25Joe Weisenthal:I mean, something that didn't really change over the last years in terms of capabilities, I guess we all remember the Snowden leaks in 2013 when we started to see more about the inside of capabilities from a government, including domestic mass surveillance, global surveillance, exploitation capabilities. And since then, every other year, we have seen an history of data being leaked that belongs to the government. So in a way, things have been changing a lot, but not really much. Like most recently, there was a contractor from L3 Harris that was sentenced to 87 months sentence because he happened to sell zero day exploits to a Russian broker.
18:17Joe Weisenthal:And that's like actual exploit that belonged to the government because there was some sort of integrator. So we see like nation states or like governments like the U.S. investing like enormous amount of money into offensive capabilities, but they also keep being burned by insiders. A lot of those capabilities are also as strong as the internal coercion.
18:42Matt Suiche:But I guess what I'm asking is, you know, if you're the Department of Defense, or I guess now the Department of War, and you're thinking about developing in-house capabilities versus partnering with a company like Anthropic, and we should talk about all the drama that's going on there. How are you balancing those decisions nowadays versus, say, 10 or 20 years ago?
19:02Joe Weisenthal:My understanding is that now a lot of it is also outsourced because they cannot really develop as many capabilities internally. So now we have seen with Entropic that it had been used in the Maduro operation. And then after that, there was a pull out from Entropic because they said it was violating their ethical policy. So I would say now something that's really changing very fast is the incorporation of AI into those decisions. But as we all know, AI can also hallucinate. So even Dario, the CEO of Anthropix, said it's definitely not in a state where it can be used for fully autonomous decisions like that.
19:55Joe Weisenthal:So I would say the AI element would be the main difference. Even we start to see it now for exploit development or vulnerability discovery, but it's still too early to give a definitive opinion about it. But overall, I would say it's very similar.
20:13Tracy Alloway:Well, talk to us about exploit development, because I know that you can't just go to Claude Code and say, like, I'm working on a zero day malware attack. Help me figure this out. But, you know, I also know that there are some very talented people who pride themselves in being able to jailbreak AI and elicit outputs that the labs do not want their AIs to produce. So do you have a sense how just within the pure hacker community, AI is being employed today for these purposes or what they're able to get out of these tools?
20:46Joe Weisenthal:It's a good question. So we started to see people leveraging AI for bug discovery, which actually is becoming pretty good. I think even Entropic published an article explaining how cloud can be used for discovery into smart contracts and how it found some bugs automatically. And I think even recently they released something called Cloud for Security that was aiming at doing a code assessment. But now we're entering into this interesting paradigm shift where the cost of software is going towards zero. So if you're a company and if your cost of building software is becoming less and less, it's also hard to convince people that auditing software for security reasons is going to be more expensive than developing the actual software.
21:37Joe Weisenthal:So I think that's one of the shifts we're going to see. But when it comes down to... Wait, sorry, can you explain? Sorry, pause that last part. What did you mean by that? It's going to be hard to convince. If you're going to have like to allocate budget for like building a product. So you have most of the budget that's usually allocated for like your software engineers to build the software. and then you do some code review afterwards to make sure there is no vulnerabilities before it gets released to the public. But security's risk is usually pretty high. You cannot just rely on AI tools, at least not at the moment.
22:15Joe Weisenthal:Maybe in a year from now, it's going to be possible. So it's going to be really interesting to see how it's going to do a market shift because now with Cloud Code, And as the famous vibe coder, Joe, I'm sure you know that the cost of building software is approaching like zero if you just look on the timeline.
22:37Matt Suiche:Are you actually on this note, are you a believer in the SaaSpocalypse? Because obviously there's the argument that, well, now everyone can just create their own software fairly easily using natural language. But on the other hand, if you are a big corporation or presumably a government, you're going to want to have you're going to still want to buy software from an external provider, given some of the security concerns, given that it might not necessarily make sense for various reasons, management reasons, perhaps to recreate an entire software business in-house.
23:10Joe Weisenthal:So I'm definitely biased on that. But as someone who thinks like the cost of software is going towards zero and as someone who is like watching the software costs like collapsing, one of the things that we realized is that data is the only durable asset in the AI economy. That's why we decided to work on DB, the current startup I'm working on. Because like that's the only thing that's really going to have value long term if agents need something to transact or to take decision on. Because even if you look in terms of like in any context, if agents are designed to think autonomously, you need to have enough information to take those decisions whenever you're going to have your reasoning loops.
23:54Joe Weisenthal:So software itself, if you just build it, is pretty static. Whereas the agentic feedback loops are more dynamic. But what changes is the context they take decision on. So definitely SaaS business are going to have a hard time because if anyone, including the Shopify CEO, can just rewrite an MRI software in one afternoon just to look at his back MRIs, you can imagine how disruptive it's going to be by the end of this year. I think the only thing we haven't seen yet is enterprise AI agent. So far, I would say since Christmas, people are mostly still playing around, trying to find a proper use case.
24:41Joe Weisenthal:We see a lot of consumer AI agents, open-clothed that really made agents more mainstream. But we really haven't seen yet enterprise AI agents. So as everyone is kind of scared of being replaced for their jobs, we haven't really seen actual AI agents replacing entire departments or full-on employees. So we have seen some disruption around software engineering mostly to make software engineering more efficient, especially in terms of development with shorter timelines. But we haven't seen yet proper enterprise AI agents.
25:20Tracy Alloway:How do you define an AI agent?
25:22Joe Weisenthal:So my view of an AI agent, and I like to remind people what an AI agent actually is, at the moment, most of AI agent is just like a piece of code usually written in Python or in TypeScript that's just doing a bunch of calls to like Entropic OpenAI and running in a loop and taking decisions and calling like third party tools like MCPs or web searches. So that's mostly what an AI agent is. We tend to think of AI agent as a completely different persona. But at the end of the day, it is just like a piece of software that's running as a service on a machine or on a server. So from a security standpoint, which is pretty interesting, it's just like another service or software.
26:12But people really like to think of it in another way.
26:16Tracy Alloway:Well, just so like from the security standpoint, I mean, one of the exciting aspects of AI agents is that they can work autonomously, right? You set a task and it can go out and find what it needs to do. And it seems like, okay, this didn't work. I'm going to try. It's going to try this thing. It's going to try this thing. Oh, I need to connect to this web service to get this information, et cetera. The downside of AI agents is precisely the same. The downside of AI agents is that they could do whatever they want to do. And if it accidentally deletes a bunch of files because it thinks that's what's necessary to execute the task.
26:51Tracy Alloway:So, like, I'm curious, like, from a security standpoint, like, I mean, we've already seen examples of people getting private information exposed or, as I mentioned, the example of deleting a bunch of information. Is this like a new way to think about the security threat model, the fact that the capability and the downside are one and the same? It's the same. It's sort of like hallucinations, right? The ability to like create an output and it also, you know, is hand in hand with the ability to create a wrong output, a false output. And so, you know, the ability to do to act on its own is also the ability to destroy on its own.
27:27Tracy Alloway:Is this sort of like a novel threat model or a novel paradigm in thinking about enterprise security? From an enterprise security standpoint, it is pretty much the same thing in the sense of like, if you're building software, you cannot just really like patch software afterwards and stuff because it never ends.
27:48Joe Weisenthal:Like security must be like built in and you need to have like a safe design from the beginning. what we have seen now is like whenever people do something agentic they just give like all permissions up front yeah which is like probably the worst thing you can do and if you're an enterprise as you can imagine if you just give like all permissions to an agent it just becomes murphy's laws if something bad can happen because you gave it access to it will happen so you're And I see like more data leaks for sure, because there is no safety by design in those like architectures or like those like agents, which is in terms of vulnerabilities and like exposure would be like very similar to what we have seen over the last like 10, 20 years.
28:35Joe Weisenthal:But, you know, if people are ignoring what has been done in terms of software security for the last 20 years, that's why we're going to have a lot of problems. And I think we're probably going to start to see like people, especially in enterprise, like pushing back a lot because there's compliance that needs to be like, you know, like answered to. So you cannot just give like full access to like, you know, your agent.
29:14Matt Suiche:speaking of the long arc of history one thing i really wonder is you've obviously been in this space for a very long time at this point can you describe how you think your own career and i guess coding experience would have been different if you were, say, starting out now in 2026 versus, I guess you would have started out in like the late 90s or early 2000s, maybe even before that.
29:38Joe Weisenthal:Yeah, mid 2000. Well, I would say like what has changed is back, even like we even without going to like the 2000s, like back in the Snowden days, when the global surveillance program was being exposed like a lot of people were really like scared of it and scandalized by it and pushed back and people really cared about privacy was like now we're entering in a new arc where very few people care about privacy where you see like the CEO of Entropic being asked why he refused to work with the US government. And he says, well, they wanted to do a domestic surveillance program. So that's against or like a safety like chart.
30:31Joe Weisenthal:So this is all aspect of people relationship with data, which I guess is very different. In terms of software, obviously, like now you can write more things. Anyone can write anything. But I think we're still in this weird adequate software phase where we know what AI can do, but it cannot really do anything more, anything less yet. We still haven't seen the actual use case for it because it's obviously very exciting and it feels like a lot of it is very different from before, but we don't really have like any evidence of how it's really helping in national security i know it's been helping people who have been analyzing like epstein's emails because there's a lot of data and that makes it faster but in term of like real use case i don't think the like it feels like the current world is very different than before but there's so much noise and so much like slop all over that in a way it is pretty similar.
31:43Joe Weisenthal:I don't know if that makes sense.
31:45Tracy Alloway:Well, I mean, your company is ONDB.ai. So you must think that it's going to be used or that, you know, or that there's clearly something there. Actually, tell us about, I'm actually really, I'm on your website right now. It looks really interesting because it's something I've been thinking about. But you must have some vision for like where it's going and that there will actually be significant demand for these services?
32:10Joe Weisenthal:Sure. I mean, like I was saying, I think now we've like, anything that's agentic, building software, which is like the main use case so far for AI, is going to make software like going to zero. So the cost of building software is going to zero.
32:24Tracy Alloway:So that's real. So like, in your view, there's no question that already AI, I mean, talk about it. It's a pretty big use case right there, bringing the cost of building software to zero.
32:34Joe Weisenthal:Yeah, I mean, like, even if you look at the author of CloudCode, he said they didn't write like code since November. So like a lot of people are like this, you know, even us internally, like, we definitely like use CloudCode a lot. But if software is going to zero, like what's left in terms of like the internet layers? So our conclusion is that data is the only thing that's going to be like timeless in the AI economy. so building like a layer for that especially now there's like all those innovations around like payments and stablecoin that you can use to actually like pay like anything online yeah so we think like okay if you have like issues like entropy or like open ai just scrapping internet and using like public internet so you may as well find ways of charging like bots or agent for your data so at least you can have this new like revenue unlock that's going to emerge in this like new economy because i think a lot of the traditional like economic model like for instance like we said like with sass are going to be like disrupted a lot so there is a completely like new market around how people are going to consume data and i think people people would just be ready to pay like more to have high quality data because the more noise there is the more you want to make sure that the data you have access to is going to be like valuable and real so yeah even from a security standpoint you know like once you build like an infrastructure layer you can have this like built-in security to make sure that the data you give back or the access like for the interface that you define is actually secure because even if you'd look at open claw for instance one of the top skill was malware.
34:25Joe Weisenthal:So like, people just like living into like wild west, but they just run everything. So it's us anticipating that enterprise is going to look very different, and they won't just run like anything they find online.
34:38Tracy Alloway:Yeah, you know, this is one of the things that I've encountered in my vibe coding for is, is that one of the annoying things is, okay, you want the agent to like go out and grab some information or query some database or whatever. and then it's like, okay, like, let me know when you've gotten an API. They're like, okay, come back and get an API. And then you have to go to a website and then you have to like, get out your credit card and you have to set up an account and then you like get an API key and then you copy and paste it and so forth. And that's very annoying. I want, what I want is for the agent to just be able to go there and say, oh, you know, like, let me just pay you with some stable coins, et cetera.
35:19Tracy Alloway:Just go out and get the information on its own without having this human in the loop. But it also occurs to me, and this is something that I've asked about with others, which is that once I'm just entirely operating in the terminal and the agent is going out and scraping information for me, et cetera, why do we even have a free public internet anymore? And so I'm curious whether the direction of the internet and information in general is just entirely paying microtransaction or fees for data consumption so that the data then arrives in some usable form in the terminal that I'm operating.
35:55Joe Weisenthal:Yeah, no, I think you're raising some really good points. We need to talk after. You can be our new design partner, you know? Yeah, I can be a consultant. He's going to hack all the API keys for you.
36:07Tracy Alloway:I can be a consultant. No, I hate having to deal with all these API keys. Why am I still using my printer?
36:11Joe Weisenthal:Well, you're completely right. See, I told you, you're a famous live coder. But the US case you're describing now makes entire sense. That's why we position ourselves as a trusted provider, where instead of having to go everywhere to get data, you have this single point and unified access. A bit like open router for AI models, but for data providers. Because if you think about it, when you use Cloud now in your terminal, the level one is basically you asking the model itself for information. but as we know, the model may be a few months old and doesn't have access to all the information. So the second level is the agent, like Cloud Code or Cloud for Desktop or ChatGPT doing web searches.
37:01Joe Weisenthal:And that's just them looking on the internet, doing a Google search, et cetera. But that's still not giving you access to the actual relevant data that you would need where, for instance, you would have those API keys and stuff. So like the level after that is basically access to private information. So in private information, usually the one that's valuable, like in the case of Bloomberg, for instance, Bloomberg has a lot of extremely valuable information, but you can only have access to it through the terminal once you have the subscription. Or like any SaaS services, if you think of like SaaS platform as just like some fancy UI where you can like browse the database, but the data that's valuable is just in the database directly.
37:45Joe Weisenthal:so if you'd have access to those apis and we not have to create like 1 million subscriptions left and right because there's already like someone who's doing the integration for that kind of like as a programmatic like api marketplace but the integration now is like much easier and especially if you trust it because now what we have seen also is like whenever you use all those tools they make you install like mcps but more and more people are like moving away from mcps they're just using like skills because like you just said we start to spend more time into the terminal so like the terminal and anything that cla is becoming like a natural interface for like agents even for humans because you don't need to try to understand those like fancy ui and ux you just say like okay i want to do abc just do that so i think it just makes more sense to have like this interface for it.
38:40Joe Weisenthal:And like, like you said, you know, like, otherwise it's just like, it becomes too complicated.
38:44Matt Suiche:Just on this note, can we talk a little bit about, I guess, institutional knowledge of code? Because I remember one of the things that happened in the early days of AI development. I mean, not that early. I think it was like 2017 or something back when Facebook's AI lab still existed. What was that called again? Like the acronym was FAIR or something. Yeah, they had like a little Facebook like experimental lab. Anyway, they invented a bunch of chatbots. And the chatbots started talking to each other in pretty much incomprehensible language. But like they clearly understood what each other were saying.
39:20Matt Suiche:And so I'm just wondering if you extrapolate that to AI generated code, could we have a situation where the models are constantly iterating on themselves, they're constantly talking to each other. And so we end up with a system that becomes very, very difficult for human engineers and coders to actually understand.
39:42Joe Weisenthal:Yeah, I mean, I think what we're going to start with is like humans, you know, like us are going to move towards like creating like markdown files as like a programming language. So everything is just going to be like normal, like language. But for the machine itself, obviously, yeah, I remember that video that is like gibberish, like voice transfer thing. Well, if you think about it, it's not that much different from voice to text in that sense. And at the end of the day, it's just like bits being transferred. Because even whenever you connect on a web page, you write it in text, but behind it's just like bytes that are being exchanged.
40:22Joe Weisenthal:So agents still need to agree on the protocol that they're going to use and not necessarily an encryption format, but an encoding format. So once you know what it is, it just becomes like a reverse engineering problem or like a forensic problem where you're just like, okay, this is what's being used. When those packets are being sent, let me just decrypt it. Once you know the protocol, that's... So I don't think we're going to end up in a situation where we would have no idea of it because you're always going to have people who are pretty good reverse engineers. but at the same time you're also going to have your like ai assistant who's going to help you to like reverse engineer those things so in a way even if it happens like you are not like alone with your red bull and your laptop no ai agents we all gonna have ai agents yeah so that's also like the reality of things so we're far from just like the clippy uh plugin that we used to have in Microsoft Office.
41:26Joe Weisenthal:Now you can have this CLI interface which just give commands and then it's led that into like, okay, I understand what I need to do, you know, and that's it.
41:36Tracy Alloway:No, I love interacting with just the CLI now and every time I have to go to the web it feels like some sort of failure. I'm like, oh, I have to go to this bright website. Yeah, and I just want the information right there on the black screen communicating back and forth in English.
41:53Joe Weisenthal:You know, that's like feeling familiar for you.
41:56Tracy Alloway:You know, something I'm thinking about is I imagine that there's a lot of like crusty old Linux and Unix programmers who are like, oh, this code is this isn't high quality code that the AI that the chatbots produce. This is slop code. It needs all kinds of fixing and so forth. From your perspective, is the code itself of good quality or of improving quality? how just the lines of code itself from your standards is a good stuff yeah it's pretty good
42:25Joe Weisenthal:and even when it's bad you just tell it okay like this is bad you know like just do it better you know like if you're using like negative rewards you know if you say okay like this piece of code is garbage you know it's going to understand better because you kind of give like a strong emotion whereas like if you say oh it's okay you know you just be like okay like whatever you know If it's okay, it means it's passing the adequate test. Whereas if you would say, okay, that's garbage, you write it. I always do this.
42:53Matt Suiche:So if I ask a bot for something, I will always say, after the first version, do better. And just see what it comes up with. And then just try to iterate on that.
43:01Tracy Alloway:This is tough because when you're talking in English, the brain deludes itself into thinking that you're talking to... Or when you're talking in human language, any language. The brain deludes itself. You feel like you're talking to a person.
43:12Matt Suiche:so you have to be nice well then i feel like i don't have that problem jake oh really but then
43:18Tracy Alloway:i feel like i like i don't want to say oh this is garbage i don't but from your perspective it's actually sort of important to to be firm with the bot and you get better results by being
43:28Joe Weisenthal:more sharp with it yeah because it's the equivalent of a negative reward like just like positive reward if you if it does something you'll say okay like that's great that's exactly what I tried to explain, then it was like, okay, like, that's like a reference point was like if it starts to go on a tangent, you just say like, oh, that's completely like out of the line. Redo this. Like, why are you doing this? You know, like, the more explicit you are, the better it's going to understand how far it is from the requirement. It's tough love. I just have to get better.
44:01Tracy Alloway:You know, I'm sort of conflict avoidant.
44:03Matt Suiche:I know.
44:03Tracy Alloway:And I like being nice to people. So I just have to get...
44:05Matt Suiche:Joe still says please and thank you. So the basilisk doesn't get them.
44:09Tracy Alloway:Yeah, that's right. So I just have to be like, no, this is trash. This is garbage. You totally, we're all dumber for having seen this code. Okay, this is good to know.
44:18Joe Weisenthal:I mean, it's a good point. You know, like all those like AI companies that are recording all the prompts, you know? So who knows if they are keeping it, if there is retention around it, you know? Like we know the OpenAI is keeping them, you know? Like they can get supone, is this how you pronounce it? Yeah, so like who knows? in years from now. If there's full-on autonomous robots managed by the Department of War because they think it's lawful.
44:45Matt Suiche:We all get social scores based on our AI prompts. How well we're treated.
44:49Tracy Alloway:These thoughts creep into my head unironically where it's like at some point is there going to be some, am I going to regret having, I don't know. They were there in my head.
45:01Matt Suiche:Truly a brave new world. Matt, just one last question from me, But going back to cybersecurity and the current situation with Iran, what are you on just the lookout for? Like what would pique your interest the most to see in that particular space? I think now in that particular space, because I'm one of those people who think it's related to the Epstein files, you know,
45:26Joe Weisenthal:like it's just more about like getting more Epstein files related stuff to see if there is like more connections to it, you know. so I think that will be the only thing that would kind of be like digital that will like spike my interest because now we have seen you know like just those like all drones can do like so much damage and that Iran demonstrated that they can be like really precise with their attacks so now I think it's more about seeing like which direction it's gonna go to and how long it's gonna to last which is like the the big like question mark because there's so many other components like the energy sector you know like how is it we have seen the price of like memory like increasing like a lot so now now if they're starting to block like the detroit of almost you know like like what's gonna happen to like the cost of data centers and like memory and ai in general you know like we're going towards on one side you know we're going towards like the cost of tokens and inference going down but that may also like bring the cost up you know so if you're gonna use like ai for like your next generation wars but if your enemy can just like increase your cost of token and inference what does that even mean like do you even need ai in the first place is it even relevant so i think there's these all like asymmetric like warfare that's gonna happen that we really haven't seen yet and i think that's gonna be like really interesting but the same time, there's so much noise and so many things happening at once that it's becoming extremely hard to focus and extract what's really relevant.
47:02Matt Suiche:Yeah, definitely feels like that. Tough choices potentially coming for Havelock as your token costs go up. Matt, it was so wonderful to reconnect again. Thank you so much for coming back on Oddlots. And yeah, you'll have to get back to Joe about those APIs.
47:17Tracy Alloway:Yeah, I'm happy. Let's go. The most famous web provider on Twitter now. Yeah, bring me on as a consultant. Sounds good. Take care, Matt.
47:24Matt Suiche:Thanks, Matt.
47:24Tracy Alloway:Bye-bye.
47:37Matt Suiche:Joe, always good to catch up with Matt.
47:40Tracy Alloway:Super interesting. It's incredible how much is happening right now at this particular nexus, especially, obviously, the anthropic stuff. But, you know, it's interesting. You know, you think about cyber warfare and you think about, OK, we're going to hack into a system and take out critical infrastructure. But another thing you can do is just attack a data center directly.
47:58Matt Suiche:Just send a drone to a data center. I thought that was really interesting. That sort of like we got very used to thinking about cyber as like this thing that exists only in code. But now you have this like new front of kinetic warfare where the two like really intersect.
48:14Tracy Alloway:Yeah, they do really intersect. And yeah, these are like huge national security vulnerabilities. And he pointed out, I mean, certainly today, but, you know, was this in anyone's threat model? Thinking about the risks to it, you know, the cheapness of drones, the ability to take them out. Super interesting. Also, just this idea like, yes, you know, obviously, again, as your observation, the point we think of like cyber attacks, like we're going to take out this whole thing. But at least in the warfare context, his point, like most of it is like before the war, et et cetera, the sort of information gathering, spy craft and so forth prior to the actual attacks.
48:51Matt Suiche:But it is interesting to see Israel in particular use some cyber attacks as a sort of sower of chaos in Iran. I can't imagine what it's like to actually be on the ground there at the moment for many reasons. But like, you imagine just being there worried about your physical safety and then the traffic lights aren't working as well.
49:10Tracy Alloway:Well, right. And also just think like, wait, there's cameras everywhere? or how much is being recorded, create a sense of paranoia among everyone about everything.
49:21Matt Suiche:And also the interesting thing, obviously this is very topical in markets, but the SaaSpocalypse idea, Matt in particular, seemed pretty bearish on the outlook for existing software companies, I guess. And I did think his comments about what that would mean for security budgets within organizations were pretty relevant and worrying.
49:42Tracy Alloway:Absolutely. All right.
49:43Matt Suiche:Shall we leave it there?
49:44Tracy Alloway:Let's leave it there.
49:45Matt Suiche:This has been another episode of the Odd Lots podcast. I'm Tracy Alloway. You can follow me at Tracy Alloway.
49:50Tracy Alloway:And I'm Joe Weisenthal. You can follow me at The Stalwart. Follow our guest, Matt Swish. She's at mswish. Follow our producers, Carmen Rodriguez at Carmen Armin. Dashiell Bennett at Dashbot and Kale Brooks at Kale Brooks. And for more Odd Lots content, go to Bloomberg.com slash Odd Lots for the daily newsletter and all of our episodes. And you can chat about all of these topics 24-7 in our Discord, discord.gg slash Odd Lots.
50:12Matt Suiche:And if you enjoy Odd Lots, if you like it when we talk about the intersection of kinetic and cyber warfare, then please leave us a positive review on your favorite podcast platform. And remember, if you are a Bloomberg subscriber, you can listen to all of our episodes absolutely ad-free. All you need to do is find the Bloomberg channel on Apple Podcasts and follow the instructions there. Thanks for listening.
50:43Thank you.
From the publisher
We tend to think of warfare in two distinct arenas: the physical and the digital. Increasingly, however, those lines are blurring. Last week, Iran launched drone strikes on data centers in the UAE and Bahrain. Israel has reportedly been hacking traffic lights in Tehran, and this week brought a suspected Iranian cyberattack on US medical device company Stryker, all underscoring long-held fears that hackers could take aim at vital physical infrastructure. On this episode, we speak with Matt Suiche, the legendary French hacker and founder of OnDB, a data infrastructure startup for agentic AI. We discuss what we know of Iran’s cyber capabilities, what digital warfare looks like today, and how AI is transforming coding and hacking.
Read more:
Stryker Remains Offline After Cyberattack Linked to Iran Group
Google to Provide Pentagon With AI Agents for Unclassified Work
Only http://Bloomberg.com subscribers can get the Odd Lots newsletter in their inbox each week, plus unlimited access to the site and app. Subscribe at bloomberg.com/subscriptions/oddlots
Subscribe to the Odd Lots Newsletter
Join the conversation: discord.gg/oddlots
See omnystudio.com/listener for privacy information.
