mnemonic security podcast

Policy as Code (Part 1)

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 35:57

In this episode of the mnemonic security podcast, Robby is joined by Ricardo Ferreira, CISO EMEA at Fortinet, to explore the power of policy as code and its role in technical resilience. 

Ferreira explains how organisations can move beyond manual processes to automate security policies, reduce complexity, and enhance agility. They discuss cloud transformation, the challenges of enforcing policy at scale, and why automation and cultural change are essential for security teams. Plus, the growing role of AI and what the future holds for policy-driven security.

You can find his book Policy Design in the Age of Digital Adoption, here: https://www.amazon.com/Policy-Design-Digital-Adoption-transformation-ebook/dp/B09WJBQ7L7

Send us Fan Mail

Speaker

From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the mnemonic security podcast.

Robby Peralta

I thought I'd heard it all in regards to buzzwords and acronyms in security, but sometimes the important concepts get drowned out in the noise. Fashionably late, I introduced policy as code. Sort of like a brother to infrastructure as code, or maybe like a non-identical twin of security as code, and in essence, it enforces security and compliance rules programmatically. Initially, my brain took me to regulatory frameworks and mapping policy to standards, but it's much more than that. And has much larger implications and strategic importance to concepts like digital transformation and autonomous, scalable, and agile IT operations. And today's guest wrote a book about it.

Ricardo Ferreira

Hey Robby, nice to be here.

Robby Peralta

Is it Portuguese?

Ricardo Ferreira

It is Portuguese, but for example, how do you say like a Ferrari? It's the same, so Ferreira.

Robby Peralta

Ferreira.

Ricardo Ferreira

Ferreira. But uh I'm just being picky, you know.

Robby Peralta

I listen to it over and over again on Google Translate, and I can't make that noise.

Ricardo Ferreira

Yeah, that's fine. That's fine.

Robby Peralta

Anyway, welcome to the podcast. You speak a lot more languages than I do. Five of them to be exact, according to LinkedIn. And you have education from fancy places like Stanford and Oxford, as well as a Spanish university that uh I won't try to pronounce. It looks Spanish to me, but now that I look at you, maybe it's Portuguese.

Ricardo Ferreira

Maybe it's Portuguese. It should be Urucidad Transmonteuro. That one. Yes. Yes. Yeah, uh it's Portuguese.

Robby Peralta

That's why I got a bad grade in my Spanish class, apparently.

Ricardo Ferreira

Universidad? Universidad. So it's very, very similar.

Robby Peralta

But in addition to that, Universidad, you've also uh served as an advisor uh for the Cloud Native Computing Foundation, Cloud Security Alliance, of course, Association with Computing Machinery. You've worked at a bunch of cool places, Rackspace, HSPC, EY, and are now the EMEA CISO at Fortinet. And last but not least, and perhaps the most relevant to this episode, uh the author of the book, Policy Design and the Age of Digital Adoption. And which have, if I've understood correctly, delves into the concept of policy as code, which I have never heard before.

Ricardo Ferreira

So I have a copy right here. There you go, there you go. My thesis or my assumption and my um hypothesis and what I propose is that organizations should leverage something that will help them get digital in a structured manner. And in order to do that, I propose a framework. And one of the aspects to do that is actually the policy as code.

Robby Peralta

Yes. When I heard it, it was like, duh. And I've been like a board member of ISACA in Norway, and I've never heard of the concept of policy as a code. So that actually, I just want to start off. I want to talk to you today about technical resilience, which is another term that you introduced me to when we talked last time. But I'm sure that policy as a code builds into technical resilience, so it probably makes sense to start with policy as a code.

Ricardo Ferreira

That's fine.

Robby Peralta

So is that relevant for everybody, or who is policy as code relevant for?

Ricardo Ferreira

The thing is, if you want to affect change in an organization, I feel that if you do the changes bottom-up, they are gonna fail because you don't have the support of the executives. And if you do the changes top down, the guys doing the actual work, they are like, what the hell? This doesn't make any sense, and it's also fail. So the best approach is always a prong approach, right? Top down, bottom up. And in order to do that, and in order for this policy as code also to be effective, there needs to be the support of the leadership. But at the same time, the people actually doing the work, the DevOps, the security guys, also need to be hyped with it. And what I've seen personally is that it's normally the DevOps guys, the risk guys that actually want this, and it's mostly trying to show the executives that this will bring value for their organization as well. So to answer your question concisively, yes, so this is uh something that from CISOs to the guys doing the changes and doing the policy changes to the DevOps guys, it's important. And how it ties to resilience, this is something that we can actually explore further for sure.

Robby Peralta

When I think of policy, I think of like uh, yeah, you're not allowed to look at Pornhub at work, but that's not the kind of policy as code that we're talking about here. Can you give me an example of what policy as code could be and why it's effective?

Ricardo Ferreira

We want to build policies that allows us to go to market fast, but at the same time to work fast within the constraints. Why is that important? Because it ties nicely to the automation piece. Uh a lot of the organizations are moving to the cloud, they are going, want to move faster. But what's at the core of it? One, you have the public cloud providers, which are helping accelerate some of those journeys, moving the workloads pay as you go. There's a lot of benefits to that. I'm not gonna say the public cloud is gonna be nice for everything, but still it's a precursor. And secondly, it's the automation. How do organizations move fast if they don't have automation behind it? They don't. And I've been in many organizations, Robbie, where there's that guy still logging into machines, fixing it, and that's fine. If you're an organization with little or you really don't care about automating, that's fine. But if you really want to be proficient, go to market quicker, establish yourself as a brand, automation needs to be part of that. And that's where policy as code comes in, right? A very good example is okay, we are now a large organization, or we want to accelerate. Where so let me ask you this, Robbie. Where do you want to take this? Because as a policy, it's open to whatever you want. I can create a policy to improve the cloud adoption in an organization. I can create a policy for not allowing external APIs to be accessed. So, where do you want to take this?

Robby Peralta

Where, okay, so policy as code from if I'm a security practitioner or security practitioner's listen to it, where would they get the most value out of policy as code? The API one sounds like a really good example.

Ricardo Ferreira

Yes, but the thing is, I feel that the most value is changing the people's behavior. Uh, because if you look at what the digital transformation has behind it, you'll look at um the people changing the culture as the number one. Obviously, then there comes the tools. Uh, Fortinet has a lot of tools and also open source tools such as Open Policy Engine, which are more on the enforcement side, right? But what I also discuss in my book is that that's just part of the equation that enforcement. In order to build a very good policy, you also need to have suasion, meaning that let's say that uh we want to move into the cloud, making sure that you provide training or you provide financial incentives to those employees is something that you can do in also to affect behavior. No, so I think for this conversation, we can focus on the on the enforcement side. Or for example, let's say that from an API perspective, we within an organization want to make sure that uh the costs are contained. So our policy is to limit the the costs. We seem that a lot of the organizations uh there's this thing called shadow IT, where I just take my credit card, I just spin some resources within the organization. That's not aligned with the policy, right? So if we want to create a policy of just using the resources and properly tagging the resources so we can understand which group is using what, this is how we would do it, just hypothetically speaking. So we would, for example, in our cloud environment, create a policy that the only resources that would be spun up would be the ones that contain the specific tag. For example, the the cost center. That's just an example, that's just an instrument. But that would be important because then for the CFO and for the rest of the organization, they understand from a cost perspective: hey, this is the group that is actually using more cloud. Why is this important, Robbie? Oh, if I'm trying to affect change, wouldn't it be nice to have that group that is still struggling with cloud adoption to reach out to the group that it's ahead in order to have some cross-pollination? Booyah, fuck yeah. Right? Right. So that's the type of thing that we are talking about, policy as code and policy as an enabler for the organizational change.

Robby Peralta

So let me pause you there. So if I understood you correctly, like the enforcement part, that's almost kind of like the technical, almost the easier part. Like you can, you can, as long as you understand what your use case is, you will find somebody. You could go to Fortnet and get a consultant, whatever, and you can make it happen through code. So that's that part is easy. But if I understood what you just said, it the harder part is like uh getting the organization to to go with you and be able to improve along the way. Is that maybe what your book was about? Is more of like the not just the technical, but the rest of the journey?

Ricardo Ferreira

Yes. So the frameworks that I built was actually around the journey on itself. But there's three parts of my book. I introduced the topic, I build a framework which contains all the elements that we were just discussing. And then the last part is a technical part. It discusses some open source uh software such as open policy engine, it discusses the zero trust concept, which is also something that Fortinet is an accelerator, but a lot of organizations are also trying to move into that. And I feel that if you have a centralized from an enforcement perspective, if you have a centralized engine, it's easy to that to do that enforcement for sure.

Robby Peralta

Cool. Well, go into those other parts then. Because I since you wrote a book about two-thirds of the book we haven't discussed yet. Tell tell me about give me some juice.

Ricardo Ferreira

So the first part is just uh trying to uh make sure that people understand what is a policy, how it's a goal, how are the different instruments, because the instruments are actually the levers that matter, right? I can have, for example, Suasion instruments. If you have kids or you want your kids to eat more fruit, you just put the fruit at their eye level. The products in the supermarket are not just placed there by random choice, no, you know, and it should be the same with policies. When you're trying to affect change in an organization, you also need to think, you need to get the different stakeholders, and in order to build something that will get your organization quicker and with some structure into the desired outcome. And most of what I focus is on this digital transformation because governments have been doing policy for as long as there's been governments, right? Or try to reduce smoking in our country, try to improve uh education in impoverished countries. So there's a lot of policies. But my book is focused on digital policies, on how organizations can get quicker from point A to point B in a digital journey with some structure behind it, not just from the technical part, but also from the people aspect and how we can use the different levers, suasion, financial, and so on, in order to actually put all the people behind that policy. When you say suasion, what do you mean by that? Like persuasion? Yes. So normally in policy design, you use suasion mechanisms. For example, a nudge, Rackspace is a very good example. Every time that you would complete uh a course in Google architecture, in Amazon Architect, you would get a flag to put proudly above you. And there was this ethos around it where you would enter the building and you would see all the people with all these different flags. And for example, if you were looking for AWS expert, you would just scan. Oh, there's an AWS guy. And why is that important? Because people would also feel proud of displaying those flags because it was also a knowledge thing. Hey, I've done all of this, you know. So it's a suasion mechanism as well.

Robby Peralta

Cool. So, anybody that's interested in uh going through cloud transformation, it how many companies are actually doing that? Is that are we over with that, or is that like just in your experience, like how many companies are actually going through that still?

Ricardo Ferreira

Most of them, and that's the thing because shamelessly there's a cloud graveyard. This is what I'm trying to say. And so sorry for being a bit pessimist, it's just that we've been in this hype for what uh 10 years now almost. Hey, let's go into the cloud, let's gonna be a nice journey, but it's just been an up and down journey throughout because a lot of organizations move into the cloud, they don't change the culture, and then for example, to give you examples, I've been working with organizations that their cloud journey is adopting Office 365. That isn't cloud, you know, so it's also a perception thing. So, to answer your question precisely, Robbie, a lot of organizations are still going into this journey. We still have a lot of cyclical movements, if you say so, because a couple of years ago, most of these hyperscalers were also pushing credits, meaning that hey, moving to the cloud will cost you zero. A lot of organizations moved into the cloud at a speed without thinking about the implications, how to move this culture. And most of those migrations were to just lift and shift, where you took this workload, you just put it on the cloud without any without much thinking behind it. And then when those credits ran out, those freebies ran out, what happened was, oh, ouch, this is a huge bill. Well, I wasn't expecting this. And some of them now are thinking, okay, so for some of the strategic stuff, uh, I'll keep them on the cloud, but for some of the stuff, I'll move them back until I can re-architect, readapt, or something, something else that I can make it more cloud native. And that's why we go into the cloud native panorama. There's this big thing about cloud native, cloud native uh application protection, cloud native whatever. This is the panacea where organizations move into the cloud and they actually adopt this concept about microservices, about serverless, which is on how organizations should be building on the cloud on the first place, not with those big infrastructure as a service servers that they use to run and just move into the cloud. It can do, but they don't get any benefits, you know? And once again, that ties to the policy as code, because policy as code, in its essence, is uh policies as code, meaning that machines can read that, humans can read that, and there can be automation behind it, there can be consistency about it. Uh think about this, Robby. Risk team, compliance team, network team, right? With policy as code, they can all have access to the same source of truth, they can all work on it concurrently, and and they can reach consensus. While previously you have the compliance folks going around in Excel spreadsheet. Okay, but if I want to do a change when the network guys, it's all oh, let me go to the Excel spreadsheet. It doesn't scale, it doesn't scale. You know, this is why having this approach as policy as code, infrastructure is code is a cloud's native way in order to move forward.

Robby Peralta

That means all your security people and risk people, that means they all have to understand code at that point, right? Is that maybe one of the problems why it that's part of the culture? That must be an important part of the culture.

Ricardo Ferreira

Is the it is, it is, and I'm not gonna sugarcoat it. It's a requirement, but the thing is, there's a lot of abstraction that normal people can try to read and understand. But obviously, it will require a certain effort for the person to at least try to make uh an intellectual effort in order to understand that. But the abstraction has come so long for the last 30 years that if somebody doesn't really want to do that, they are just being lazy, in my opinion. Yeah, there's a lot of resources, Robby. Come on, there's books, there's online courses, there's a lot. But to your point, this is something that uh the people in this transformational journey would need to do would be read high-level code in order to be able to talk with your peers. Because let's let's I learn English and I'm here talking with you, otherwise, I would fall in Portuguese. No, I do not exactly. If I speak in Portuguese, you will not understand. It's the same thing. If you are in an organization, there needs to be some kind of common alignment, at least for the people doing the work at the high-level perspective, having those policies and those frameworks with the instruments, it's the natural language, it's English, whatever language it is, you know. It's the constraint part, the enforcement part that needs to be codified because you want to leverage automation. Yeah. What does this have to do with technical resilience or resilience as a concept? So resilience is a big buzzword these days, true. But why is that? Because as uh things get more and more complex, and we have also seen that from a threat perspective, uh cyber threats, um, bad guys, they understand that uh everything is getting more and more integrated, things are just exploding, devices, connectivity, APIs, environments. And as that rises and those threats rises, the potential for disruption rises as well. It goes in tandem. The complexity rises, the threat rises as well. Why is that important? What it has to do with resilience. So in risk management, you have uh using NIST as a framework. I really love NIST because it's a simple framework, it has five major pillars identification, detection, protection, response, and recovery. Those five pillars tell you on what is your posture from an organizational perspective in those five strategies. And if you think about resilience, it means that you're putting your strategy more on the latter stages. From no, I need to embrace that there's gonna be some kind of disruption, but what I do after I detect this disruption is the key, and this is resilience. You fall down, you quickly bounce back up. And why is that important? Because in order to do that, you need to have some fundamental concepts. Uh, I'm not gonna go through all of them, but automation is one of those key fundamental aspects from a cybersecurity perspective. There's something called SOAR, security orchestration and response, which is all about that. Something happens, you put the glue in order to okay, this happens, then I need to do that, that, and that, those playbooks that people call it, right? And this is why for me it's so important for resilience because when we are talking about policy as code or everything as code, if you don't have that automation, then your resilience honestly is non-existent. That's why why I feel that everything as code, policy as code is tied directly to your maturity levels of resilience, that automation.

Robby Peralta

So, in order to have everything automated to the level of detail that you needed to be able to report and fill fulfill all these requirements, you have to have policy as a code.

Speaker

Yes, yes, Robby, and also from a transparency perspective, especially on highly regulated industries, there's a lot of compliance, and the auditors will go there. Oh, I want to see the controls that you have for encryption address for your data. Oh, there comes the guy with the Excel. Yeah, right. That doesn't work because yes, you can come with an Excel, but the source of truth, where is the source of truth? Is that Excel? It doesn't work like that. What you really need to do is have some code, and then you translate those controls that uh that code into Excel. You can do that. There's a lot of organizations that are mature that do that. You actually, your your documentation is the code, is that infrastructure is code, which better way to see what you have in an environment, if not the code that was used to create it. Yeah, and you don't need to talk to people. You still do, you still know. It's just that sometimes we use sources of truth that are not the best, and that just causes friction between the different teams, that just causes slowness, and once again, to your point, having automation, having that uh central source of truth is ideal for even for the different teams that are working their project and so on.

Robby Peralta

Okay, so thank you for explaining everything. I know that I'm like a little kid right now. This is the first time I heard of this, but once you get into policy as a code, once you've understood it, put yourself at my level. Okay. So, how where do you start on that sort of uh journey? I guess a lot of people don't start with policies as code, as as like a hey, we're gonna start doing this because it's important now. But like, what are some of the um lessons learned that you can share advice around that?

Ricardo Ferreira

I I think Robby, a lot of organizations will use policy as code even they don't under fully understand that. Let me give you an example um AWS, Azure, Google, all of them. Have policy engines. For example, in AWS, you have something like IM, Identity and Access Management. You have AWS config, you have a different tool set that can actually allow you to write policies. For example, let me give an example of a policy. There should not be a machine with port 22, which is SSH, which allows you to get in into a machine exposed to the internet, right? And you write those policies. So a lot of organizations already have those capabilities and they use it. Where I feel that they don't have the maturity is to have that vision of okay, what are we trying to do with this? Are we trying to reduce the surface of attack? Is that a goal? Are we trying to improve access to the security teams? Are we trying to improve access for the business unit team in order to get quicker to what they really need to do? Sometimes what I feel is that a lot of organizations don't have a framework, something that puts that into context and it's loose sheets all over it, you know. And once again, there's that guy with the Excel spreadsheet taking into consideration about the policies that are in that environment. But more importantly, how does that environment part of the entire organizational ecosystem? And this is what I'm trying to advocate: don't work in silos, even if it is cloud, work as a part of a whole which you define the policies, and then it just trickles down for the different environments and what you are trying to achieve. How do you get to that vision? Maturity, trying to understand where you are right now, understanding your capabilities. Where you don't have those capabilities, okay. What do you need to do? Do we need to change the culture? Do we need to change uh the mechanisms of cross-pollination? Do we need technical capabilities? Okay, where we are. So it's measuring where you are currently, where do you want to go? Because sometimes we are also talking, but sometimes you really don't need to go to the level of automation that a large organization, if you have only a hosted website, right? It doesn't make any sense. But if you measure yourself, understand where you want to go, that's the first step.

Robby Peralta

Is policy as code relevant for a CEO? What should they know about it actually?

Ricardo Ferreira

They want to know about agility. And agility is achieved by what? Uh commodification of assets, cloud, public cloud, APIs. And secondly, automation. If you don't have that automation once again in your organization, you're not going to be agile. There's going to be this guy spinning up resources. It doesn't work. So for a CEO, he's going to care much about opening new revenue streams and where those do those revenue streams come. Number one, new quicker go to market. If I go quicker to market, you can you can establish yourself as a new revenue stream. Secondly, improving your agility of the organization. And thirdly, making sure that you have a culture that it's going to support you during that transformation. Otherwise, you can have all these visions, but if you also don't have the people to support you with that, it's going to fail. As with any CEO knows that.

Robby Peralta

Yeah. An example of like a CEO that that was able to go quicker to market, the agility backed by the cloud that actually made them their their company more successful. Could you think of any off the top of your head? Something that we need to understand, Robbie, is that traditionally, normally this change programs are more should associated with the CIO, the chief information officer. Normally, the the CEO, the chief executive officer, is more concerned about uh the revenue, the PL from the company, and so on. The the person more responsible for changing those systems that innovation, making sure that they are modernizing, taking care of IT, and so on is a CIO. Right? So, from a CIO perspective, uh let's say that he wants to move quicker into the cloud or he wants to reduce costs. This is a very good example. The credits run out, like we were saying, right? The credits run out from that hyperscaler, and now he faced an enormous bill. How is this policy as codes gonna help? So, first, it can help by that example of enforcing mandatory tax. Every new resource from now on will need to have a tag, and this seems a very small change, but think about the implications long term or medium term. If I'm able to actually understand all of the assets that are being spun up, then I can quickly come up with ways of being more efficient. Do I really need that 400 gigabyte, 200 core machine running in development? Probably not. But how do you how do you get there if you don't have that visibility? That's the problem. And it's the same with security. If you don't have that visibility, you're not gonna be able to protect yourself because otherwise it's impossible. How how is it gonna be fighting blind? And it's the same with affecting change and this policy. In order for you to actually be to succeed, you need to have visibility across your state and then having the small levers to affect change. That's why your book is uh called uh designing trade digital transformation or something.

Ricardo Ferreira

Policy design, policy design. And and that's the thing because what I did try to do is that uh we all understand technology. Me within working with Fortinet, we are uniquely positioned uh from a portfolio perspective in order to bring that enforcement layer. But at the cultural aspect, right, this needs to be someone at the CIO level or the CISO level in order to understand how to create this framework and actually how to use the different levers in order to affect change.

Robby Peralta

How many CIOs out there do you think have understood this and would be not nodding their head and have learned this already?

Speaker

I hope some. At least the CISOs and a handful of CIOs that I showed the book, they said that it was very helpful for the cloud journey that they are going. Because you can use it for many, it's agnostic, you can use it for many ways, but the majority of the people that I got feedback, at least from a CXO perspective, was that it's gonna help them on their cloud adoption. When did you write the book? Uh 2020. No ChatGPT. No ChatGPT. Wow. And it's still just as relevant today, right? Yes, and that's why that was one of the points of contention that I had with the publisher because the publisher was amazing, but wanted me to write um a technical book. And I was like, yes, but in six months, even though I was writing about things that were upcoming in the Kubernetes ecosystem in the microservices, I knew that it was becoming outdated. And now, more than ever, look, uh, Fortinet just did an acquisition on CNAPP, Lacework.

Robby Peralta

Oh, really? I didn't know that. Cool.

Ricardo Ferreira

Yeah, Fortinet just did an acquisition on DLP, uh, which is data loss prevention and CNAPP. And a lot of the examples on how getting that dev secops teams working more frictionless with other parts of the business is a tail on the book five years ago. Yeah, right. So more it's in my opinion, it's intemporal and it's gonna become intemporal. And that was my goal as well. I didn't want to write something that was uh out had an expiry date of a few years. It doesn't make sense.

Robby Peralta

Interesting. So let's let's say you since you skipped over the technical part of the book, what does that technical part of the book look like now? Like if what would you be writing about? Just like high level, you said CNAPP already, DLP.

Ricardo Ferreira

Uh for example, the zero trust concept is something that is very relevant. A lot of organizations, especially in the security arena, are trying to move um to this new paradigm. Uh, this book details uh zero trust, the concept on how you can use a policy engine in order to do those decisions, where to get the data from. And it uses a lot of microservices, so Kubernetes, serverless, uh, but it could use a refresh on the Kubernetes policies from a cloud environment with the one that I detailed, are still relevant, but obviously as the cloud grow, now there might be some other tools that do the same um thing, but from a concept perspective, still relevant.

Robby Peralta

I always ask how is AI, LLMs, whatever you want to define as AI these days, how is that gonna add to your story in the future?

Ricardo Ferreira

I feel that we also hit uh a peak at this moment, and I think now it's gonna be optimization. And let me elaborate a bit on that. If you look at the beginnings of this LLM journey, a lot of organizations didn't even had one, and they were able to quickly catch up. And if you look at the leading ones, there's nothing groundbreaking on the LLM environment. You we even saw what happened with Deep Seek and the cause that chaos that they do with the NVIDIA and other tech stocks, and all of what they did without diminishing their effort, obviously, but it was taking already existing approaches and optimizing them, and now everyone is is trying to catch up. So I think, honestly, personally speaking, uh, that this LLM uh has its peak, and now it's a matter of optimization and making sure that we reduce the hallucinations, we also embed it more into our workflows. But uh honestly, I'm not expecting nothing major groundbreaking besides driving the cost lower and increasing the adoption whenever the roy makes sense. So sell your tech stocks. Well, because that's one of the issues, Robbie, that they face because data, where do we we train our models? And now there's things about how they um scanned a lot of torrents. And I don't know if you remember that Iron Schwartz, that guy that was convicted and unfortunately took his own life for I think it was a couple of gigabytes from JSTOR. He was sued and he couldn't pay. And yeah, he it was a tragic thing. But yes, and you see all of these major players doing probably worse on getting the data because what we need to understand is that the models are only part of the equation. I feel that the value, the biggest value, is on the data on itself. That's why a lot of organizations spend a lot of money curating that data in order to make sure that the data was valid so that those models could ingest that data. The data, in my opinion, is the new oil, is where the value is, and that's why you see regulation from the European Union in trying to democratize this data. There's some value to it, but uh for now and to wrap it up, Robbie. I feel that the models are just part of the equation, and where I feel that there's the most value out of it, even for LMs, whatever, is on the data on itself. And nobody's gonna open source that because people talk about open source this, open source that. No, bullshit. No model in the market is open source, even Deep Seek is somewhat open source, they only open source the weights, they didn't open source the data, nobody did that. No, because nobody owns all the data, true, but they own the data where the model was trained. And I think the just for concluding, because this is also important, we saw, I think it was last week, a court law that actually ruled in favor of someone whose data was getting used in order to train an LM. So this is gonna open the Pandora box because if I I'm not saying, but I just have a gut feeling that a lot of these models were trained in copyright data. And that can open the Pandora box.

Robby Peralta

Yeah. Last thing before I let you go. I have have you used the deep search function and like perplexity?

Ricardo Ferreira

Yes.

Robby Peralta

I think it's so impressive, but didn't they kind of yeah? What are you gonna say?

Ricardo Ferreira

No, perplex perplex perplexity, in my opinion, uh is the future. And unfortunately, and once again, we can have a podcast about this. It's just that we've been around for quite a while. And in the early days, the internet was quite free and quite powerful, and you could have operators on the search query in order to get data from last year or with certain codes and or or the boolean operators. Nowadays it's crap, it's full of ads. And I feel with the uh from an LLM perspective, it's gonna happen the same. We are still in the beginning on the Genesis, we are still we still can do prompt engineering, but as time advances, I'm scared that product placement would be done on those large language models. Imagine talking about, hey, how's the weather? Hey, why don't you buy an umbrella from? You know? So I think that's that that's something that concerns me, along as with the critical thinking of people losing that. That's something as well.

Robby Peralta

It's a lot of things that could concern us in this world right now, Ricardo. Ricardo Ferreira, thank you so much for your time. You're a very intelligent man. I've learned a lot from you. And uh, I will definitely have to uh ask you to come back on again with smarter questions next time.

Ricardo Ferreira

All good.

Robby Peralta

Thank you so much. Take care.

Ricardo Ferreira

Thank you, Robby.

Robby Peralta

Well, that's all for today, folks. Thank you for tuning in to the Mnemonic Security Podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.netno. Thank you for listening, and we'll see you next time.