註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

Insecure Agents Podcast
@insecureagents
AI engineers and security practitioners listen to us to learn how to give their agents the security they need to reach full autonomy and capability.
加入 June 2025
117 正在關注    1K 粉絲
"Is This Tool Call Allowed? It's Never That Simple": Michael Davis (J.P. Morgan) "Is the AI agent still making good decisions? Maybe it's made 30 tool calls already. With a classifier, say, well, did it make the right tool calls? Is it still moving semantically towards its goal?" Michael Davis, Global Chief Security Architect at @jpmorgan, explains the complexity of architecting secure agents, and why runtime security decisions should model the way robotics deals with uncertainty. We get into why  if you think you need memory, you're probably not thinking about your problem the right way. We also explore why software factories need to operate as a  cumulative, progressive process versus a one shot "go build me this SaaS". Over the course of the episode we piece together what a good reference architecture for agents ought to include. We get into: > The four dimensions robotics uses to decide it is safe to move an arm > Why memory is an extremely complex addition to your agent > How to know an agent will call an API in the right order with the right parameters at the right time > Software Factories: what works and what doesn't TIMESTAMPS (00:01) The cybersecurity poverty line, and why your suppliers' breaches become yours (00:03) Patching is harder for the models than finding the vulnerability (00:04) Partial coverage, unnecessary functions, and trading a security incident for an ops incident (00:05) The loop ends at the patch, which is where the application teams begin (00:06) Software monoculture, and why we all get one patch (00:07) 7,000 shipping configurations was a people problem, now it is a compute problem (00:09) Skills are code, and every skill brings its own dependencies (00:13) Taxonomies for vulnerabilities and mitigations (00:14) A mitigation is deleting the code (00:15) Pioneers and settler teams inside a very large bank (00:18) Multiple paved paths, and when to merge them into an expressway (00:22) How do you know that read-only role is really read-only (00:24) Removing the ability to read an email and send one in the same session (00:26) Verification asks whether the test passed, not whether the agent did the right thing (00:29) The handoff leaked the data, and both agents were authorized (00:31) "I don't believe memory is a thing" (00:34) Why memory makes just-in-time access impossible (00:37) Exfiltrating data through a batch of calendar invites (00:39) Where could you point me to a good reference architecture (00:41) The four dimensions robotics uses to decide it is safe to move an arm (00:43) Retries are not a bad thing
顯示更多