How Will New Technology Change Cybersecurity?

TL;DR
Security teams must anticipate how new technologies alter both system behavior and potential failure modes before deploying them. Machine learning can help analyze raw data, reveal relationships, clusters, and trends, but broad claims about replacing people obscure what the technology actually does. Connected devices, microservices, and data sharing also expand the landscape that defenders must understand.
Transcript
Good morning, everybody. How are you? Good morning. Good morning. Good to see you. I'm happy, uh, you recovered from the party last night. I wasn't sure after I saw the, uh, depth of partying that actually occurred. But thanks so much for taking the time to be here. Uh, this session is focused on the future. So what's, what's gonna happen in terms ... Read More
Key Insights
- Technology adoption is a human adaptation problem as well as a technical challenge. The RFID badge story shows that people can unintentionally disable a new system when its physical requirements and operational limitations are not communicated to everyone handling it.
- Security work is shaped by continuously changing definitions of correct behavior. New devices and operating modes alter what systems are expected to do, while creative adversaries devote substantial effort to breaking products that developers have worked hard to build.
- Consumer device protection led Benjamin Jun into cybersecurity. A request to prevent piracy and misuse of a portable audio player prompted him to investigate digital rights management, contribute protections to the file format, and meet future collaborators in cryptography research.
- Vulnerability research can connect academic work with practical security. Hugh Thompson's team studied 5,000 vulnerabilities in released products to determine their root causes, identify how developers could have prevented them, and consider how testers might have detected them.
- Machine learning is frequently used as an industry buzzword without sufficient explanation. The speakers compare its prominence with the earlier popularity of big data and argue that understanding what operates under the label is more useful than accepting sweeping claims.
- Modern data analysis works by combining raw information across multiple contexts. The described approach examines transactions, user sessions, and products across an entire stack, then uses visualization tools to expose relationships, clusters, and trends within the collected information.
- Artificial intelligence contains competing schools of thought rather than one uniform method. The discussion informally labels them East Coast AI and West Coast AI, while associating East Coast AI with linguistics and the tradition of expert systems.
- Future security planning must account for multiple technology shifts. The session description identifies microservices, data sharing, connected things, and machine learning as developments that can create new capabilities while also producing tomorrow's security challenges.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How should security teams prepare for new technology?
Security teams should examine how a technology changes expected system behavior, what new operating modes it introduces, and how users or partners may misunderstand it. The conference badge example shows why this matters: an RFID chip was added for room tracking, but a party vendor punched holes in badges and could disable the technology. Planning must therefore include human handling and adaptation.
Q: Why can new technology create unexpected security problems?
New technology can create problems because organizations may deploy it faster than people learn its requirements and limitations. The RFID badges worked as scanners recorded attendance and enabled summaries, but punching a hole in a badge could interfere with its chip. The incident demonstrates that a technically useful design can fail when surrounding operational practices remain based on older tools.
Q: How did Benjamin Jun become interested in cybersecurity?
Benjamin Jun became interested in security while working on a handheld audio playback device that used flash memory. A senior colleague asked the team to prevent users from pirating content or misusing the device. As the lowest-ranking team member, Jun investigated the request, studied digital rights management, helped add protections to the file format, and met people with whom he later co-founded Cryptography Research.
Q: What did the study of 5,000 software vulnerabilities examine?
The study examined 5,000 vulnerabilities found in released products that had already passed quality assurance and had been written by reasonable developers. The researchers sought each flaw's root cause, considered how a developer could have prevented it, and asked how a tester might have discovered it. The work also revealed the creativity and sustained effort that adversaries apply to breaking systems.
Q: Why is cybersecurity described as a continuously changing field?
Cybersecurity changes continuously because new technologies add devices and operating modes, which can alter the meaning of functionally correct behavior. Defenders are also trying to build systems without flaws while intelligent adversaries invest energy in finding ways to break them. These pressures force security professionals to reconsider existing boundaries and adapt their assumptions as the technology landscape evolves.
Q: What can modern analytics reveal from raw data?
Modern analytics can combine raw data across the full context of a transaction, a user session, or a product. Once that information is brought together, visualization tools can help people identify relationships, clusters, and trends. The discussion presents this capability as an important industrial shift in how organizations examine data, while separating it from exaggerated claims that machines eliminate the need for humans.
Q: What does the discussion say about machine learning hype?
The discussion says machine learning has become a prominent industry buzzword, much as big data had been before it. Vendors may display the term widely, while public discussion often jumps to claims that machines can be taught anything or make humans unnecessary. The speakers propose looking under the hood, clarifying what machine learning means, and examining the competing ideas within artificial intelligence.
Q: Which technology developments may shape future security challenges?
The session identifies microservices, data sharing, connected things, and machine learning as developments with implications for future security. Its central premise is that today's technical changes produce tomorrow's challenges for security professionals. The speakers therefore connect current advances with the need to plan for altered system behavior, additional devices, new data relationships, changing operations, and the possibility of human misunderstanding.
Summary & Key Takeaways
-
Rapid technology adoption can create unexpected security and operational failures when people do not understand how new components work. The damaged RFID conference badges illustrate the problem: organizers introduced useful tracking technology, but a party vendor punched holes in the badges without recognizing that this action could prevent the embedded chips from functioning.
-
Both presenters entered security by investigating practical protection and failure problems. Benjamin Jun began studying digital rights management while developing a portable audio device. Hugh Thompson became involved through a DARPA grant that examined the root causes of 5,000 vulnerabilities in released products and considered how developers and testers might prevent them.
-
Machine learning has replaced big data as a prominent industry term, but the discussion urges professionals to examine what it actually means. Modern analytics can combine raw information across transactions, user sessions, and products, then provide tools that visualize relationships, clusters, and trends. Competing schools of artificial intelligence approach these problems differently.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator