At Multiplier, we've done all our deployments on-prem, under the principle "create no new additional surfaces of attack." We've negotiated zero-data-retention endpoints on our clients' behalf. (Where possible, you want to reduce the surfaces of attack, particularly when dealing with companies whose cybersecurity record is spotty.) Ben has spent many weekends cordoning off data, sandboxing agents, and clamping shut exfiltration channels, implementing SoTA prompt injection defenses, testing different models' prompt injection capabilities and resistance (both directly and in adaptive adversarial competitions, viz. theemailgame.com)...
And sure, some clients appreciate this, but it's not exactly the sexiest feature. Why bother?
Well, when we exposed a VM to the internet, we watched ≈2,000 automated attacks per hour. Like the zombies in Train to Busan scrabbling on the glass. (Based on my cursory review of Check Point's longitudinal studies, this would have been more like 700 hourly in 2021.) You have seen the headlines about AIs autonomously devising and executing sophisticated, felonious cyberattacks. That's all true; that's not marketing hype; we are fifteen minutes into the seventies disaster film. Sorry.
The good news is, rogue AIs (probably) only want your data (for now).
The bad news is, rogue people (definitely) want your money (right now). And they're equipped with obedient AIs that lag a few months behind the frontier (or, in some cases, they're equipped with frontier AIs that are just dopily helpful.)
The very-bad-but-so-far-speculative news: if you're a public markets investor of any size (and if you're not, please forward this to a public markets investor of some size), there's a new lucrative way to extract money in a cyberattack. No ransomware, no IP theft, all that stuff is petty crime. No: the real money is in quietly watching you and frontrunning every trade. (Exercise for the reader: assuming your trades are predictable by an always-on malicious AI agent watching everything that happens in your fund, and assuming market impact is mostly permanent, how much money could the bad guy drain from your perf every year?)
My message here is simply–––be afraid. (And long cybersecurity stocks.) We ain't seen nothing yet. Remember the terror Mythos wrought? Those capabilities will be open-source soon. Do your own research. Sorry... if there's demand for a more technically detailed paranoid cyber playbook, let us know, and I'll suborn Ben to write it. The point of this post is just that there sure oughta be demand!
For context, I bought surgical masks in January 2020 and $CRWD in 2023, so I'm paranoid but also right. (Well. I didn't short the market in January 2020. I still believed that markets were efficient. My loss of faith in the EMH is another post for another time.)
