transcribe

The new attack surface writes code with Travis McPeak from Cursor | Zero-Shot Learning

1Password · 35m · transcribed Jun 2026
More from 1Password Business
𝕏 Share ▶ YouTube 📥 PDF 🤖 .md

Transcript

0:02 Hi everyone. I'm Nancy Wang, Chief Technology Officer at 1Password. Welcome to Zero Shot Learning, which is a podcast about the reality of developing with AI from the people actually doing the work. I host this show alongside Dave Taggart, who's a senior director and head of engineering for a Gemini Enterprise and Business at Google. Today, we're going to be talking with Travis McPeak, a long-time friend of mine who's now at Cursor. Travis has spent his career securing real systems across cloud, application security, and product security at places like Netflix, Databricks, IBM, HP, and Symantec.

0:36 All that experience has taught him that businesses must be made to move. So, he's taken a realistic approach to security. Travis has also realized that teams will adopt new tools, and it is security's job to help them do so safely. In my opinion, Travis is one of those security leaders who brings both conviction and pragmatism. He knows where the risks are, but he also knows that being perfect kills progress. So, we're going to talk about what it means to secure an AI-native company like Cursor, how security teams should support the business without blocking it, and how to think clearly when the technology is moving faster than guardrails that you can put around it.

1:12 Lock in. This is Zero Shot Learning. We have the pleasure of having Travis McPeak in our studio today. >> Thanks for having me. >> You've helped build security in some very different worlds like Netflix, Scale Cloud, you know, Databricks, like pretty massive product surface. And now AI-first coding workflows at Cursor. Um what's one hard constraint that never goes away, uh and you find that people tend to underestimate every time the tech stack changes?

1:50 >> Yeah, so I think the hardest thing in security is always just chaos. Um there was a quote from a long time ago, but the NSA's like elite hacking group, I think it was tailored access operations. They would come in and they would just be quiet in an organization and just observe what's going on. And by the time they would go do whatever it is they had to do, they understood the inner workings of the business and, you know, complex systems and all that better than anybody that worked at that company did.

2:17 And the reason this is so hard in security is because a for a business to function as a good business, like things are moving forward. Things are changing all the time. There's a lot of work being done um that you I just have no visibility into. You often find out things late and then on top of that security is already spread thin, you know, there's like large stuff changing that may introduce risk. So, like security has to be very very choosy with how and where they get involved. Um I think that's the the number one dynamic is like we're always going to have more that we have to be doing than we can actually do.

2:47 >> And so, when obviously the volume is so much greater, right, than what's possible to to be done, um you know, let's maybe talk through like how, for example, if you're securing an agent, right, and not the user, like how does that translate into your workload today? >> It's really like interesting and unanswered question in industry, uh identity, right? Like what identity is this agent? Is it the identity of the user that launched it? Is it the identity of where it's running from, like the platform, you know, like an AWS instance or something? Does it have like some own identity? Uh so, I don't think anybody's like really figured that out and I assume like most things in industry, we're going to get completely different answers to that question. So, that's the first thing is like you have an identity like we've always had. And then you have to go and grant the identity access to things, which is IAM and access control, which we've also historically been awful at as an industry. Like setting up things least privilege, like I did a talk on this one time. Like we've been talking about least privilege as like a we should do this thing since 1970 and it's never been done well and over per- permissive things have always caused like tons of problems. Um at Netflix I did a project called Repo Kid, which I think is like the best kind of this, which is you just deliberately give a little bit more than you think anybody needs and then you observe over time and you cut it down to the right size. And then of course, when you do that, like you need to add permissions, you need a system for doing that. Like I think that's kind of the best that we can get and what's interesting in this model is that everything is moving so fast driven by just new technology, um transformational technology that people really want to adopt into their business and we in security just don't have great answers for like what we're going to do here. Um and at the same time, because of the urgency as of it, many businesses are not going to wait, you know, 3 years for the security team to figure out a clue of what to do. So, we in security are acknowledging that businesses want to adopt this technology. Um we can't just throw up our arms and say this is hard, we have to do something and so we're trying to adopt old practices and technology onto a a vastly new thing and varying degrees of success, I would say, amongst uh people doing that.

4:48 >> Well, I do love the identity shout-out cuz that's one thing that, you know, we're we're spending a lot of time kind of thinking about how to secure identities, of course, here at 1Password. Dave, what about you? I'm I I'm sure you're seeing this >> Yeah, totally. I come from like the opposite role, Travis, where it's it's mostly about build, build, build, ship, ship, ship uh all the time. Um so so the top question in my mind really is like what's your definition of like secure by default that doesn't like slow down teams? And where where would you draw the line of like, "Hey, this is the default, you have to do this. It's a baseline. I don't care. Slow down until you get there." kind of thing.

5:25 >> Like one thing that I believe about security teams is they exist to serve the business, right? Like your business exists for a reason and security teams that obstruct that reason in a meaningful way are not good security teams. Like your job is to do the best risk minimization that you can within the amount of slow down that a business will tolerate. So, obviously, like ideal solutions are not only do you do not get slower, they actually get faster. Like you win security delivered a system that makes things secure by default, you know, sets things up well, and it's actually like faster and easier than the old system.

5:57 Like those are very, very rare, especially with the types of people that do security work. And so like not neutral is like the processes just happen on top of it. So you add security, it's passive, does absolutely nothing until the point when it saves you. And then then it comes in and does something. And then of course like many, many security teams are in we're going to slow down the business as much as we can and still get away with it kind of mode. So yeah, I mean that's kind of I actually like am more in your philosophy of what you said. Like I'm in ship, ship, ship. Like that's what I want too. Like you know, I work I work here. I want the company to be very successful. Like there's obviously like some very bad security things that it's my job to help us mitigate and like buy down risk, but like the biggest thing that I want is for us to be like successful and thrive as a business. So my usual answer to this is not like how much can I block you, but it's like okay, yeah, I see why this thing that you're doing is very important. How can I support you in getting that done in a way that's like the way that you wanted to do it, but you know, safer for this reason that I don't even want you to have to worry about.

6:59 >> Totally. And like, you know, in in this spectrum of like options that we have to support the business accelerate from like a security perspective, what do you think actually sticks? Is permissions, templates, you know, everything is code kind of paradigm, uh reduce the the entry barrier like the the the communication back and forth? Like what's been like the most successful patterns or techniques you've seen here? >> Well, everything as code has become surprisingly hot because like so prior prior to joining Cursor in June, I was running a business called Resourcely that was secure by default, you know, infrastructure patterns for developers.

7:37 And as a we worked our way into like producing Terraform is the way we did that. So we would produce Terraform patterns with, you know, standard templates and then the users' opinions and security policies and like merge all of that together and deploy Terraform. Now, what's become really interesting about the AI revolution is we have these like wonderful tools that operate like very well on anything that's text-based. So, now, if you can actually do configuration as code, like that's very powerful because the LLM can produce it and you can also have other people or independent like LLMs come and review that. And once everything's good, then it just gets auto deployed. So, I think that thing's become very powerful and I find myself reaching for that even more than I did like before I did all of this.

8:17 >> Sure. So, moving into one of, I would say, my favorite sections of the podcast is let's get deeper. Right? So, you know, as developers, we often talk about like, "Hey, let's secure the pipeline." But it's really a lot of theory. And so, if you take a look at like the coding workflow, right, which is very similar to just how we used to write code before LLMs, right? So, you think about local to remote, right, pushing from your local IT to your light repo and then from CI runners to the cloud. What are some trust boundaries that really matter in your opinion?

8:48 >> Yeah, so I mean, everyone's got different [clears throat] philosophy about this. And also, there's a lot of cultural considerations. Like, for example, some companies with very good security teams take a, you know, extremely locked-down laptop approach. Like, they might not even allow their developers to to run with privileges on their own machine. Um that could be like one approach. Like, my general approach is that's too abstract to give to a business. So, my North Star is like mostly just treat treat the laptops as compromised at some rate and then act accordingly. So, anything coming from those laptops to anything else get increasing level of scrutiny from me. So, like CI is one, you know, like if you're an engineer, that's probably the thing that you're going to touch directly. That gets scrutiny. Um and then, you know, CI gets bundled up and deployed on the infra, that gets scrutiny. The thing The stuff that's happening on infra, the changes to it, all back it's a lot of scrutiny. And then at the end of the day, like I think any good security team, like I said in the beginning, we have so much more to cover than we can actually cover. Like, if you sat me down in a room and said like, you know, for your life you have to make a list of 50,000 like really sketchy things that are going on, like I think any security team can do that, right? Like there's just There's infinity things that are like, "Oh, that's not optimal. That's not up to standard." and whatever. So, like really the art in this is being risk-based. And so, for me, like my my number one crown jewel is customer data.

10:09 And so, like all of those systems that I talked about up until this point are a tier below like wherever that customer data like flows. So, I spend like a ton of time on that, like infrastructure hardening around it, auditing, like all of the usual good stuff. >> Uh, you know, I'm very curious about like security-first approaches, uh, which is that Auntie and I are friends. Uh, and I'm not a great security practitioner in that sense. So, so my my one of my key questions here really is you know, there's many security approaches that assume like the developer is a careful operator.

10:42 Agent Dick Tool sort of like flipped that model, right? Uh, in this case, systems can take actions that like machine speed autonomously. So, in the new paradigm, what's your recommended capability model for agents? Like think scopes, approvals, break glass, time-based ones, uh, you know, role-based ones, if you will. Uh, how do you think about that paradigm where, you know, effectively agents are just YOLOing it in the world? >> Yeah, uh, excited to answer that. I want to push back a question to you really fast. Like, what do you mean by security-first?

11:16 >> Uh, yeah. So, so the thing is like when I go back and I and author an agent, I, you know, write a plug-in, run it against the plug-in, could talk to three P's, could talk to like inherit a bunch of permissions. In this paradigm, what I'm thinking is you know, naturally giving super large permission sets is not a great idea. It's very viral these days. Uh but it doesn't seem like that the most uh you know, promising idea longer term or even for enterprises, right? Uh with that in perspective I think there has to be a like a minimum barrier uh to make agents viable uh to be shared, to be run in enterprises, so on and so forth. So, I'm I'm like really honing in on what are the table stakes to make these even usable in a in a shareable setting.

12:06 >> So, you mean like security first for agents, not like security first like industry-wide. Yeah, okay. >> Yeah, like secure by default. That's why you know, the reason why we launched uh cursor hooks. >> Yeah, that makes more sense cuz I would my first thing was going to be like challenging the like developers or like super trusted like premise. Like I don't I don't feel that way. Like I've seen so many studies about defects rates, you know, and like we we go and like haul these poor developers in like every year and like make them do the you know, the full developer security training thing and like it's annoying for them and they forget it because if they don't use it all the time.

12:39 >> Right. Oh, oh, by the way, I forgot the question with like we assume that they are super trusted, but like the implication was that they're not cuz we all forget our trainings, yeah. >> Yeah, well, and like that's the reason that like least privilege is important, right? Like if every if every developer like was actually like a security person, first of all, we'd like never get anything done. Uh but secondly, like you could give them more permissions. You wouldn't have to worry so much about like least privilege all the time. But anyway, we don't live in that world. So, I would say like developers weren't mega trusted in the first place. Not because they're bad people. They just have other priorities. So, um now we now we're talking about agents. So, like um agents, obviously, like there's the spectre of prompt injection, which has been around since the beginning. I I think it's hilarious that like yet another like, you know, asterisk injection has like come and like plagued the new thing. Like we just never got that like separation of control plane and data plane right like in the history of computers. Anyway, this is the new evolution of that. So there's that and like also these are I still think think people don't understand how non-deterministic these systems are. Like you write code like code has bugs but like modulo the bugs like it does that thing all the time.

13:48 Then now you get like very reliable systems like AWS I am and like doesn't really have bugs like for the most part, you know? Anyway, like agents aren't like that. It could be like green green green green green green purple like for no reason. You know, it's phase of the moon or like some inference bug or like any number of things that people don't understand. So basically like the net of all of that I think is that you always have to treat an individual agent as untrusted like especially if it has access to something that really matters.

14:14 Which is why you know, we have all these mechanisms in cursor about like you approving stuff that like agent can do that might impact stuff that you really care about. And now like yes, we're all in this like big mad rush. Like wouldn't it be awesome if the agent could like just handle all the customer emails and then like you know, issue refunds and stuff. Question becomes like what about when it you know, issues was listening to Risky Business this morning. I heard some company accidentally gave away like 44 billion of Bitcoin or something. So like you know, what about that? Yeah, what about that kind of stuff? Like yeah they meant to it wasn't an agent thing actually. They meant to like give Korean won and then they picked the wrong like currency.

14:53 >> Oh, yeah. >> Yes, they I think they issued like 2,000 Bitcoin or some something crazy 20,000. It was some like giant number. But now we're going to have that kind of stuff, right? Where it's just like we set up the agent probably did it in a hurry cuz like it's wow, it's going to be so cool like when we don't have to be like answering these like customer requests all the time. And it's got the tool and oh, we forgot to put like safeguards and guardrails and like logging and like anomaly detection all of that stuff. So I think that the cheap kind of like easy answer for this that we we're talking about since the beginning of AI is like have one agent that's, you know, unaffected like supervising the behavior of another agent. Um and then as the industry matures, we're going to get some more to like normal like anomaly detection kind of stuff. So, agent you know, we notice that um 999 times out of a thousand, agent says green. And every time it says purple, then we like slow it down and we're like, "Are you sure about that?" And we go and like look at it's all the input that it consumed and like it's reasoning and how it got to there. And like maybe it can continue anyway, but that's the point where we like slow it down.

15:56 >> Makes all sense. So, like just taking this uh argument further, I promise. Um now now imagine a world where, you know, the one agent paradigm shifts to like the agentic mesh where thousands of developers are writing these agents. There could be a central orchestrator, but it's unlikely to govern all the thousand agents. It's probably just like facilitating are you in my mesh or not, like control plane and sort of semantics. Um now agents are talking to each other.

16:23 Could be A to A, could be tool calling locations via MCP. Any new paradigm that might come up in this world, do you think credential management becomes more persistent or goes down more the ephemeral path? How would like this this identity exchange and like scope exchange happen in in the true agentic mesh? >> I mean, so we're going to have a couple of of like iterations of this, right? Because yeah, it would be awesome if we had like just-in-time ephemeral token, you know, just used by that agent and like all of the all of the off-Z knobs that we want to tune for it and we can do that granularly. We could do it based on profiles. They can request new ones, like all of that. But like that's a whole bunch of existing tech that has to change. So, I think in the beginning we're going to have, you know, more um more coarse-grained controls here. So, it'll be like, "Do you want to offer it this tool or not?" It could be like a the of turning it on and off, like um and then I think beyond that, there will be like obviously we've seen like tons of MCP brokers, stuff like that, where it can already do those kind of access controls. That's like one intermediate step that will get to you. But yeah, long term I think what'll probably happen is we're going to rewrite significant parts of the auth in and auth Z stack here to make these things work better.

17:36 >> Do you think it looks more and more like, "Hey, here's agent one, here's agent two, there's a gateway." And do all of your policy enforcement at the gateway. And then it just looks everything looks like uh microservices again, except we call them agents now. >> Yeah, I mean I have a colleague and he, you know, at first like when you said it, I thought he was joking, but now I think he's actually right. Like everything in security ends up being a proxy, right? Like like it's just proxy all the way down.

18:02 So yeah, like the first of all the concept of like agentic mesh sketches me out a little bit. But yeah, I mean like we're for sure going to go towards something >> Yeah, yeah, exactly. >> Galaxies, what what have you. >> Yeah, we just use like increasingly scary terms to describe this thing. >> Yeah, so we've been talking about like securing um agents, right? So now of course uh one thing that we're also hearing about, which I'm sure you probably read about in like Risky Business or other podcasts, is actually now using AI to do security, right? So obviously when Opus 4.6 came out, um I think the the whole security world was in for a surprise cuz, you know, with the what the researchers could do with like red teaming and discovering new vulns, right? It did incredibly well, right? Almost like expert level. And so when we think now about this new landscape of, you know, static analysis or bandit self-tooling, like what still applies and what doesn't?

18:55 >> So I will admit when GPT came out, I was caught off guard. Like I obviously been hearing about AI forever. Um and long predating me, like vendors in security were selling AI snake oil that didn't end up being good. So I have this part of my brain that just learned to turn off, like yeah, it's snake oil, it's BS. And so I missed the actual like AI, you know, take off until ChatGPT came out. And then I was like, wow, this is actually like very interesting. And since then I've been following it like a hawk. So, that's that's for me personally. And so for me, like Opus felt like significantly better model. Um, but not like a wow, this is like a whole new thing. Like we had, you know, increasingly good models up to that point. So I've been using it for security work like you're talking about.

19:40 You know, since like January of last year. Um, so it's not like a a brand new thing. It's it's definitely at the point now where you have to put less into it. People that were building at the at the app layer on top of it, you know, doing all this juggling to like just keep it on track and make it do stuff. Like a lot of that is less relevant than it had to be. But anyway, all of that said, I've been using it for quite a while and the way I would describe it is you know, earlier I said security teams just can't keep up with everything.

20:08 Um, there's way much way more stuff going on than we have time to deal with. And so examples of that would be like careful code review. Like wouldn't it be awesome if everybody in the security org could in-depth review every single change. Sounds great, like completely impractical. We're never going to be, you know, one-to-one with developers. And like those security reviews, if you're being careful with it, take a long time. But now, when you have like very, very sophisticated uh things that you pay by token, they can just do it and like never get bored and have full attention, um we can lower the bar to like what we can review. So that would be a good example. Um, even just like looking for the nature of change and like get the security team in at the right time. So it's like I care about X, Y, and Z. Like look at every single change and all your your only job is to tell me like are X, Y, and Z happening? And if they are, you go at me and like bring me in. Um, threat modeling like didn't scale before. I did that for, you know, a whole year in 2015. It was awful. We hated it. Devs hated it. Like that kind of stuff actually like scales now because you can have an agent go and produce an architecture diagram and go look for potential vectors and then go match that up to any code that was written and see if those are are mitigated. So, I think that it's like a a huge win and I'm surprised that people are just ramping into the idea that uh agents are going to be great for security, but it's better late than never.

21:22 >> And what about cases where let's say you are have a you know AI generate code for you, right? Do you treat those diffs actually differently from you know in terms of like policy reviews or gating? >> No, not at all. In fact, like I so you know there's this term vibe coding which everyone uses. Like I don't like that term at all for um what we produce um because like to me vibe coding is like agent go do work, you know, and it like produces a bunch of code and I'm like yeah, it sounds good, merge it. Um that's not what I do. So, I when I develop something obviously like use AI cuz I'm like so much faster and better with it, but I will use it to like ramp myself into some new knowledge domain.

22:01 So, like in doing something I don't understand how it works, I'll just question. It gives me an answer. I'm like I still don't understand it. Like ask the question differently. Get an answer. I'm like I don't believe you. Show me the docs. Like you just ask questions so fast and like if you want like line by line, you just like copy and paste these three paste it into the AI, like ask it to explain it as much detail as you need, and then also like it will it or other agents will find bugs in the implementation that like maybe I wouldn't have seen or I would have seen, but it will find it earlier. So, anyway, the net product of me writing something with AI is like one I understand it much better than if I did it myself because previously like maybe I'm like I don't quite get this thing, but it's going to take me 3 hours to go like research it, so I'm just going to live with like not fully understanding it. Now there's like no friction. I can just within 2 minutes I can have an answer to that thing with the docs and impetus to prove that it's not a hallucination. So, it lowers the bar to my understanding. So, I end up understanding that code much better, and there's multiple sets of eyes like going and looking at it and finding problems.

22:58 Like anytime you want, you just spin an agent and you're like go look for A, B, and C class of issue on this PR. Like tell me anything. Like it'll go and eagerly search and then you can have another agent go and like triage all of those and get rid of the ones that are not verifiable and then you yourself like look and interrogate about the the remaining results. >> So Jarvis, like rewinding a little bit, going down to to AWS again, Repokid was about making these privilege achievable in like a high-velocity AWS style environment.

23:27 What's the 2026 version of that idea for tool-using agents? >> Yeah, um well, so I'll do the 2026 version for not tool-using agents first. So IAM is like unparsable. It's a great technology, honestly. It's like probably the best implementation of this thing, but you know, even me, I've dealt with it for years and it's like, how does this condition work? What's the syntax like? It's just so hard for anybody to understand. But um models, I would say like their default training is like better than 99.99% of people for that.

24:00 So like it's just out of the box going to produce better than like what you copied from Stack Overflow in the past. And then you can ask questions about it and like get it even even further better. You and the security team can just go ask somebody else's agent, like, why did you why did you pick that? And like maybe it'll resolve itself. So I would say like the the floor has gone up for anybody using AI in terms of like how good that stuff's going to be. So strictly good from from that perspective. Um you can also just tell the agent, like, go look at all of the code and go suggest like the least privileged set of permissions I need here.

24:30 Um now, what's the what's the agentic one? You know, that's a good question. Like I think what we want is we want to have standing like no permissions. Um like or least permissions. And then based on like the actual like agent and its profile and like what it's supposed to be able to do, there should be some like requestable, auditable like set that it receives. Um you definitely want to know like what it was granted with and like what it actually ended up using from that and whatever and then there should be like an escalation path.

24:59 So, uh you know, my agent's working on something. If it just gets like hard blocked uh at a point, like it might crap out, like it's going to be like bad for for everybody using it, but if it's like, "You know what? I actually need the CEO's salary from this system." Like super weird, never asked for this thing before, but like here's the set of approvers that can go grant it for this agent or whatever. Like I think that's, you know, to to an extreme example. Like that kind of things what we're going to want.

25:26 >> All right. All right. That that makes a lot of sense and it kind of talks to uh me a lot cuz we've been doing some work on uh or I've been thinking about doing some work on agent behaviors and almost like assigning a a scorecard over time on on how the agent is evolving. >> Yeah. Kind of like an employee, right? >> Yeah. Kind of like an employee, you know, it's it's your appraisal or your perf over time, but it's modeled on like agent behaviors, trust and safety scores, so on and so forth. Um and to that, I've been thinking a lot about like how can I right-size the permissions or of scopes for a given agent somewhat autonomously uh without too much of human intervention.

26:07 And and where do you think that equilibrium possibly could be? Where you have some notion of a health score or trust score. And then how would you like go about getting that signal in and assigning it to uh to the agents? Is it still agent take or more like deterministic sort of thing? >> Yeah, I mean there's really cool stuff here, too, right? So, like you deploy an agent. Like that agent has a a purpose and like you should be able to use some combination of like patterns and other agents to analyze that and come up with an accepted, you know, like a expected set of tools that it's going to be using or or calls or whatever. Skills, doesn't matter. So, you have this like baseline and then that just becomes a static list and any any requests outside of that list, like that could be like you don't have the permissions and you need to go request to add it or it could fire your anomaly detection. Like there's a whole bunch of stuff that you could do here because like the baseline like normal behavior of like a well-formed you know, you don't want to have this like megalith like agent that's like you know, does all the things that the company. You want to have like purpose-driven agents so then that way you can baseline them and give them the right access to stuff.

27:09 >> And then like on that paradigm where you think uh skills come into the play, right? Like now we're talking a lot about like agent skills. Uh they seem to be moving agents in a direction which is there's one single omni agent that has access to a bunch of tools, potentially access to a bunch of tools depending on on the rule and scope etc. And then you mutate agent behaviors with skills effectively. Um that maybe goes against the the paradigm a little bit or you think we >> don't think so. I think you I think you just attach the baseline normal to the skills. So like you know, the the main agent is like a a hollow vessel that has some like basic instructions about like how to go and find and like use the skills it wants and like you know, user instructions like it's general purpose but then you just apply the the access control to like the skills that are loaded.

27:55 >> Makes sense. >> Yeah, it's anything will end up fine. >> Yeah, mirrors what we were talking about earlier in Dave of agents as thin clients, right? In that sense. >> Right. That's my thesis. I think agents are getting thinner and thinner over time and that time is now. >> Yeah, I mean the MCP thing like made sense to get something off the ground. Um but like you know, long-term load every possible tool that the agent might need like into context is not the way we're going to end up doing this.

28:19 >> 100%. >> Yeah. >> A lot of that functionality is also moving to the models themselves, right? Like models are able to deep retrievals, have like file system access or like representation of a file system, so on and so forth. So at that point, what was tool used traditionally from like an MCP style paradigm, if it ends up moving closer to the models, then the agents effectively become an orchestrator or a hollow vessel like Travis talked about described um and all these primitive skills basically end up guiding you uh, towards the outcome.

28:51 So, in in a way less autonomy, but I think it's more directed autonomy, uh, which you might end up being making them more useful than they are today. >> Well, yeah, and if you can do the skills bundle, then you can say, you know, this workload gets these five skills. Like it can access those five skills, which means that it gets the instructions about how to use them, it gets the creds it needs to like deal with those systems, and if it's not in your payload, then you don't have those skills. And like maybe that's the request boundary.

29:16 >> Yeah, and like this is very very similar like to to your point, Travis, like how lazy loading was done. Right? >> Exactly. >> So, this is again, like a lot of software patterns are repeating themselves, manifesting a bit differently, uh, with with the agents now. >> With uh, open claw here, like how would you think about being, um, you know, scoping down permissions, right? And, uh, making sure that it took actions only on certain data uh, uh, sources that you wanted it to.

29:42 >> Um, what I might do is give my open claw a persona that's separate from mine. And so, like it can send email as itself. It can't send an email as me. I might give it a tool where it has some data that I wanted it to process, and that's just-in-time, and it automatically gets purged. So, that if something else later comes back and and like compromises it, it doesn't get like all of the data it ever had. Like I would I would just put it in as small of a box as possible as I could for it to get its job done.

30:09 >> Yeah, which actually is spawning conversations around like secure execution or runtime environments. Like what do you think about the future of that everyone having to go buy their own Mac minis to run open claw or like agents? >> Yeah, the Mac mini thing is honestly like really funny to watch. Like I don't understand why people want to do that at all. Like we have the basic stuff that you would need to run open claw. Like we have that. It's called AWS instance.

30:33 Like we've had that forever. So, like you don't The people doing Mac mini that like want to run their own models and whatever, I think it's cute and fascinating that like so many people are are really into LLMs because of open claw, but like that's not the way to go. There's like so much technology that they're voluntarily like bringing on themselves when they don't have to. Like at the end of the day, I think what the whole open claw like rise and craze speaks to you is like people really want the personal assistant. And my take is that, you know, this this is not an unfamiliar concept to Google or OpenAI or Anthropic. It's not like, you know, nobody at those companies had that idea.

31:07 It's that you producing that service and warranting it as a big company is risky. Like something bad's going to happen, you're going to get sued. So like open claw releasing is open source is genius because there's nobody to sue. It's like you just go use this at your own risk. >> I completely agree with that. I I think that the number of implications for like a personal assistant acting on your behalf is amazing and will likely end up being super litigious for a real company.

31:32 Uh yeah, makes a lot of sense, Travis. Shifting gears a little bit, uh we call this section the builder's mindset. Right? So uh my my key question to you is like uh if you had a month off to just work on anything you wanted to do, what would that be? Yeah, okay. So I had not a month off or anywhere close to that, but I did have um 50% of Christmas break. Like I did a little bit of background work that I wanted to get done for the company, and then I had some unusual amount of downtime for myself. And like some of that was like, you know, I went golfing and like mountain biking and stuff, but I I had a personal trainer, yeah, like a person that would program workouts for me um over the internet, and then they told me that they were getting out of that. They're not going to do it anymore. So I could go find a new personal trainer. This person, by the way, I was paying 120 bucks a month so like program workouts and like, you know, be like, "Good job." and whatever.

32:24 Um so I was like, "I bet AI could actually do a really good job of this." And I built a GPC 5.2 loop with tools that are um hosted in lambda and dynamo and fronted by an API gateway, and then I vibe coded, like legit vibe coded. Like I've seen no iPhone code of anything I've produced, um but I vibe coded a iPhone and Apple Watch apps. So, like I'd never touched Swift before and I still have not touched Swift. That's wow. Like I just asked them, "Hey, do you want to anyway?" It's great. I've been using it for a month and a half and like it's better than what I had before and I don't pay anywhere close to 120 a month. It's like $5 of of, you know, OpenAI credits and very minimal for AWS hosting, so that's my builder's mindset. I build on >> That was incredible. Truly builder's mindset.

33:07 >> Yeah. >> Yeah. Super practical as well. Um well, bringing home with an AI security question. Right. A lot of teams, um these days, you know, they're still talking about security AI workloads like it's 2019. And so, what do you think is like the biggest thing that's going to change in the next, let's say, you know, 6 to 12 months? I used to say years, but honestly it's months these days. Where uh you think security controls are just going to become table stakes?

33:32 >> There's people who embrace security engineering. Like their job is to use engineering principles and go integrate with the security risk is. >> Like yourself. >> Yeah. Yes. Yes. I I think this is the way. And then there's um security or um governance people. Like, you know, the camp like, "Our job is not to go solve anything. Our job is to like buy a bunch of tools and then go and like make sure that the right people who might benefit from these findings get them and then chase them down and make sure that they hit things in within the SLA." Um my biggest hope here is that like that second group is just going to retire.

34:05 Like they're you know, AI will be so good at like chasing tickets if that's what we want to do, that like if you can't actually build stuff and provide value to the business, then you just go find something else to do for work. Um I think honestly we have so many people in security that add like little or no value or like are sometimes destructive to the business that they operate in. So, I hope that they go away. And then um the people that are left that do security engineering, like I think that any security people are usually like very good at thinking of systems and like asking hard questions and like wondering why and like reasoning down to first principles.

34:38 So, they're going to now be able to touch a lot of systems that they didn't before cuz like they're they're ramp in time is so fast. Like this is what I've gone through. Like I was never the fastest programmer, but yeah, it was like the perfect partner to me where like it can handle a lot of the code. I can go interrogate the code and like design decisions and like we converge on something good. Or if I need to go touch a system I haven't touched before, I can learn about it in like an hour now. It would have taken me days before. So, it just lowers my bar for like where I can touch an impact. And I think it's going to do the same. And so, if we wanted to as an industry get better coverage than we had before, we could do that with less people. And so, if, you know, my my hope comes true and all these like ticket pushers go retire and like start doing something else, then those who want to do security engineering, there will be more of us and we'll go diffuse to all of the businesses that haven't been able to hire talent like that before and overall security will improve. That's like my utopia vision for this.

35:29 >> Oh, love the hot takes, Travis. >> Oh, love the hot take, yeah. Incredible. All right. Thank you, Travis, for joining us. We had a great time. Uh, hope you did as well and let's stay in touch. >> It was fun. Thank you. >> Yeah, we love security engineering.

Summary

Travis McPeak, a security expert with extensive experience in various tech companies, discusses the challenges of securing AI-native environments and how security teams can effectively support business innovation without causing delays. He emphasizes the importance of adopting a pragmatic approach to security, focusing on risk management while acknowledging the rapid pace of technological change.

- Security must adapt to the chaos of evolving tech stacks, requiring teams to prioritize their involvement strategically.
- Identity management remains a complex challenge, especially with the rise of AI agents that require careful access control.
- Security teams should aim to support business objectives by minimizing risks without obstructing progress.
- The concept of "secure by default" should enhance efficiency rather than slow down teams, integrating security seamlessly into workflows.
- AI tools can significantly improve security practices, enabling better code reviews, threat modeling, and anomaly detection.
- Future security models will likely involve more granular, just-in-time permissions for agents, emphasizing a risk-based approach.
- The industry may see a shift away from traditional security governance roles toward more engineering-focused positions that leverage AI for efficiency.
- The evolution of agent capabilities will necessitate a reevaluation of permission management and security protocols to ensure safe operations.
© transcribe · For agents Built with care and craft by Gokul Rajaram