Skip to content
AppSec PodcastThe Application Security Podcast — home
42 minSeason 10, episode 14

Kim Wuyts -- The Future of Privacy Threat Modeling

with Kim Wuyts

on Threat Modeling, Secure Development, AI and LLM Security and Privacy and Compliance

Audio hosted by Buzzsprout. Nothing loads until you press play.

Kim Wuyts discusses her work in privacy threat modeling with LINDDUN, a framework inspired by Microsoft’s STRIDE for security threat modeling. LINDDUN provides a structure to analyze privacy threats across multiple categories such as linking, detecting data disclosure, and unawareness. The framework has been updated over the years to incorporate new knowledge and developments in privacy, and it has become recognized as a go-to approach for privacy threat modeling.

Kim believes that privacy and security can be combined and highlights the importance of protecting individuals’ rights and data while securing systems and assets.

Privacy by design, which focuses on reducing unnecessary data collection and considering individual needs, is discussed in relation to secure architecture and threat modeling. The Threat Modeling Manifesto is emphasized as a significant resource for promoting privacy threat modeling. 

Kim addresses emerging trends in privacy, including the concerns surrounding AI and responsible AI, and stresses the need for increased awareness among individuals and companies about privacy issues and the importance of privacy protection.

Listen in as Kim explains the importance of collaboration between security and privacy teams, integrating privacy into security practices, and recognizing the value of privacy for both privacy protection and overall security.

Mentioned in this episode

Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.

Transcript

6,550 words · assemblyai

0:00Chris RomeoKim Wutz is a senior privacy researcher at the IMEC DISTRINET research group at KU Leuven, Belgium. She has more than 15 years of experience in security and privacy engineering. Kim is one of the driving forces behind the development and extension of Linden, a privacy threat modeling framework. She's also a co-author of the Threat Modeling Manifesto, program co-chair of the International Workshop on Privacy Engineering, and a member of ENISA's Working Group on Data Protection Engineering. Kim joins us to catch us up on the world of privacy threat modeling with Linden and also extend our knowledge into privacy by design and privacy engineering. We hope you enjoy this conversation with Kim Voetz.

0:49Kim WuytsHow do you create security champions? Security Journey brings together 2 powerful approaches to provide application security education to help developers become security champions and produce safer applications. Security Journey training content extends beyond developers to reach the entire SDLC, creating a security-first organization. Learn more about our enterprise security training at securityjourney.com.

1:13Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I'm the CEO of Curve Ventures, also joined today as always by my good friend Robert Hurlbut. Hey Robert.

1:41Robert HurlbutHey Chris. Yeah, Robert Hurlbut, Principal Application Security Architect and Threat Modeling Lead at Acquia, and excited about talking about privacy today.

1:51Chris RomeoYeah, something that, uh, I never know enough about. I always wish I knew more about privacy. Whenever I start talking about it, I'm like, I really don't know that much about this. But so it'll be excellent to be educated by our good friend, Kim Voetz, who is back joining the podcast for her second visit. The first visit Kim made to the podcast was in March 2020, where we talked about privacy threat modeling specifically. And it was awesome to see Kim as the keynote speaker at OWASP Dublin back in February of 2023. And then also, on the RSA conference stage. I don't remember what month that was. It's a blur, but I know it happened in the last, I think it was April maybe or somewhere around in that timeframe. So, it was great to see you, Kim, on the big stage talking about privacy, talking about threat modeling, bringing that message to the industry that needs to hear it. So, we have so much more to learn. Now, I understand you're, you know, we're not going to hear your security origin story because people have to go listen to the first episode to hear that.

2:55Robert HurlbutYes.

2:56Chris RomeoBut I understand you're in the midst of a transition from the world of academia to the private sector. So give us a little bit of context on that, if you would.

3:03Kim WuytsYeah, so I'm almost at the end of my academic career. I've been a privacy or an academic researcher for, I think it's 17 years now, where I've been doing all kinds of, from foundational research to more applied research. mainly on privacy and on threat modeling. And well, yeah, the time has come to move on. I'm looking for something more, like, practical, hands-on, making a real impression, and making a, and really applying it to the real world instead of just focusing on the academic foundation. So, I'm really excited about that. Still looking into my options. So, if anybody is looking into a privacy engineer or privacy threat modeling expert, definitely reach out to me.

3:53Chris RomeoYeah, I would. And I will second that word there. If somebody is looking for someone to work for your company in the field of privacy, I can't think of anybody that I would rather have representing privacy in my company than Kim Putz. So, sure thing. So, let's catch up a little bit on privacy threat modeling, Lindon, This, let's pretend that people don't know what it is. Like, I know what it is, but let's pretend that people don't. Let's start, kind of start from the beginning and lay the foundation before we get into what's been new and happening there. So, let's just introduce Lindon, if you would.

4:36Kim WuytsOkay, sure. So, Lindon is a privacy threat modeling approach, very similar to STRIDE, the security threat modeling approach created at Microsoft. We've used it in our research to work on, well, security analysis, And we realized that there wasn't really such a thing for privacy. So we got that inspiration from STRIDE and started building a privacy-specific privacy threat modeling approach, which is Lindon. It evolved over time. I think the first publication is from 2010. It got a big update in 2015. We added a more kind of lean applied deck of cards, which is Lindon Go. in 2020. And since then, we kind of tried to bring all that knowledge we captured throughout the 10+ years on privacy, on threat modeling, on different domain-specific things, on ways to capture all that knowledge. Because what is the main contribution of Linden is that similar, like STRIDE, STRIDE is basically an acronym for the specific security threat categories you need to analyze. Linden is also an acronym for the different privacy threat categories you have to analyze, which are linking, identifying, non-repudiation, detecting, data disclosure, unawareness, and non-compliance. I hope I didn't miss any. But so in addition to being an acronym, Linden has this whole set of knowledge that will help you understand those specific privacy threats and will guide you, will facilitate discussions So, that's where the deck of cards can help. But so, we decided that the Linden knowledge base needed an update. So, we added more structure to that. Well, my colleagues were the main driver there. They built this knowledge base that captures all that information and makes it easy to extract both a set of cards a paper catalog, something that can be used by a threat modeling tool such as, well, we have our in-house Sparta tool for risk assessment, but you can extract like an XML file for, let's say, the Microsoft threat modeling tool or other tools. So the idea is that we capture all that knowledge in a more structured form in a way that can be extracted so that it's useful, usable, for all different types of requirements, people, tools. And we rebranded some of the categories as well, added some new information because, well, the world of privacy keeps evolving, technology keeps evolving. And that way, we also hope to be able to keep our knowledge base more up to date when new things arise. So that's basically the That final part is the last 3 years of research, of work by the Linen team.

7:43Chris RomeoSo, when I think about how prolific STRIDE is in the world of security threat modeling, anybody, almost anybody who's done threat modeling from a security point of view started with STRIDE. At least those of us that started, you know, 10-plus years ago. Like, it's a very well-known term. When you interact with people that are focusing on privacy, does Linden have the same impact in the privacy, like, in privacy engineering teams that Stride does in security engineering teams?

8:20Kim WuytsThat's a good question because I'm probably biased because the people that come talk to me know I created Linden. So, that's probably why I get a lot of people saying, well, yes, of course, we know Linden. Linden is, like, the go-to place when you want to get started with privacy and privacy threat modeling. So, it's kind of hard to say. I mean, there are different, you have TRIM as an extension to STRIDE, or at least to elevation of privilege, which is also a deck of knowledge base resources, or an extension of, well, you have STRIPED, which is STRIDE plus a P.

9:00Chris RomeoOkay.

9:02Kim WuytsMITRE is also working on something for privacy threat modeling. So that's also really exciting to have a look at. But I think, and that's hard for me to say because, you know, I don't like to brag, but I think Lindon is kind of a well-known approach, at least within that space of threat modeling for privacy. Yeah.

9:25Robert HurlbutMm-hmm.

9:28Chris RomeoOkay. So, do you think Linden— when will Linden need to be refreshed? So, I started a discussion. I was talking to Loren Kohnfelder, and you both probably saw this, I think.

9:41Kim WuytsYes.

9:42Chris RomeoKim, you even commented on this on LinkedIn. I was exchanging emails with Loren for a different podcast interview process. And Loren's the person who created Stride back at Microsoft 24 years ago, not 25, let the record be clear. He corrected me after. Um, or corrected his initial guess at 25 years ago. And so the question we posed on the Stride context was, Stride's almost 25 years old, like, what needs— does it still stand up? And so I'm curious for your thoughts on Linden. You said what, 2010 is when it kind of came into— into— so I mean, Linden's third— it's a teenager. Linden's reached the teenage years, um, with all the angst and other things that come— no, not at all. But what— Like, does it still meet what you need as a privacy engineering person, or is there something that could be added to it that doesn't need to be adapted right now and updated?

10:39Kim WuytsYeah. Yeah. So, that was kind of also part of the work of the past 3 years to have a look at that. So, we added more structure and we made it in a way more generic that we think we now covered kind of a more complete set of linking specific threats and identifying specific threats. What we did was also we rebranded the second D of Lindon, which used to be disclosure of information, and that was kind of a placeholder to plug in STRIDE, or at least information disclosure threats there. But we decided to rebrand that to a very privacy-specific category, which is now data disclosure. which has nothing to do with confidentiality, but which is really about minimization, minimality, like collecting too much information, sharing too much information, collecting too specific data types, storing it for too long of a time. So that was, I think, our main update because we felt we captured that somewhere, but it's such an important part of privacy that we decided that it needs to be captured in that entire category, in a specific category there. What else did we do? Well, unawareness now covers both the need for transparency and control, which are 2, especially from a GDPR European perspective, are data subject rights. Like the system needs to be able to support those rights for the individual. And we kind of have a placeholder in the non-compliance category because, well, privacy kind of, well, cannot be done on its own. We rely on security. I mean, you can do all the fancy crypto stuff and anonymization or de-identification that you want. If it's not confidential, you're still losing data, so it's not private. You also need to Worked closely together with legal because, well, you need to have like a legal basis to process personal data. If you are, for instance, also collecting large amounts of personal data and you're not based in the EU, you need an EU representative. There's also a lot of things that you need to do from a legal perspective to be okay with data protection and compliance. You need to work on data lifecycle management because, well, privacy, it's all about personal data, so that also needs to be managed. So, I think we also focused on that interaction, that privacy should not be done in isolation, but it's kind of a team effort. You need to team up with other qualities, with other experts, with other teams to make it a good whole scenario, preferably as soon as possible. So, that's where threat modeling is a—

13:35Robert HurlbutYeah.

13:36Kim WuytsIt's great.

13:38Chris RomeoI think you just taught me a new word in the midst of explaining that too, minimality. I'm gonna work that in. I'm gonna use that today. That's my goal.

13:48Kim WuytsI don't know if it's an actual English word, but yeah.

13:50Chris RomeoI thought, I'm like, I'm gonna work this. I'm gonna try to. Now my challenge is, can I use this word sometime in the next week?

13:55Robert HurlbutIn a sentence somewhere?

13:56Kim WuytsI hope I didn't make it up, okay?

13:58Chris RomeoLet me ask one more question about the, 'cause you talked about security and privacy, then Robert, I'll let you cover the kind of privacy engineering things we were thinking about. But since this is— you just made a mention of privacy and security, and this is now my favorite question to ask privacy people. Why does privacy have to be separate from security? Like, why is there this whole separate discipline? Like, we have security engineering, we have privacy engineering, we have privacy threat modeling, we have security threat modeling. We have these two, they're very different. They're being separated between the two. And is that the right way to do it? Is that what, like, 10 years from now, would we expect security and privacy to be the same, or would we expect them to be different? Like, what are your thoughts on this whole issue?

14:45Kim WuytsIt's a great question. I think it kind of grew because privacy was not a technical thing. It just came from compliance and was more an organizational or legal thing. So, that's why it's It's often not in the security or the technical teams, I think. Whether it should be combined, well, I think there is a lot of value there. I mean, one of my privacy friends, Nandita Narla, who's a privacy engineer at DoorDash, she actually combines security and privacy threat modeling together, and she made this statement saying, well, by combining it, we get 60% more coverage and more efficiency.

15:25Chris RomeoYeah.

15:26Kim WuytsSo, it does make sense. But I think one of the big challenges there is, and that's also, there's some misconception, especially with security people. When you say also do privacy, they say, well, we can't do it because, well, it will screw up our security, or, well, we don't need it because we do confidentiality. But I think the main issue is that privacy and security are different things. You have the CIA for security. a triad for privacy, which are 3 completely different words, which are unlinkability, intervenability, and transparency. And I know some people hate the word intervenability, so I prefer to call it control. So it's about transparency, control, and making sure you cannot link information, you cannot deduce more information than you should. And because these are 2 different triads, that means you need to have 2 different mindsets because the CIA is really about, let's protect the system as a whole. Let's protect this process or this data store or like really big chunks. And for privacy, you really need to look into the data items. Is this personal data? How can we minimize it? Do we need it all? So, for security, you look at how can we protect our system, our assets? And for privacy, it's more about how can we protect the individuals and the individual's rights and how can we we act in the best interest of these individuals. So, it can definitely be done together, but you need to like change heads going because you have different viewpoints to tackle that. But it can definitely be done and it should be done. But I think we still have a way ahead of us before everybody will start combining it.

17:17Robert HurlbutYeah, those are some of the challenges I remember seeing in a large international company I used to work for, when they would try to think about the legal aspects of privacy versus the implementation. And that sort of leads us into this next question about key challenges that you've encountered in the field of privacy engineering.

17:42Kim WuytsYeah, I, well, I tackled a couple of them before. It's like the big I think one is just convincing people that privacy is important. Because people will say, well, I have nothing to hide. I don't care. While, well, when you start thinking about it, everybody has some stuff that you want to keep, well, not as a secret, but only share with like your close friends or your family. And it doesn't need to be public. So everybody needs privacy. And because there's so much personal data out there because we have so much cool technologies and devices and whatever, we still kind of give it away. And even when we think we have some cool privacy settings and protect everything, we see so many examples of situations where it goes wrong. So I hope people are becoming more aware of that. We need to have privacy. And you sometimes, I know some people switch from WhatsApp to Signal because there was an update in privacy policies, for instance. So people are getting more aware. Now it's up to the companies to follow that trend and to really embrace that privacy idea. And I think that's now where the big challenge is, convincing companies that privacy is worth the investment, which is a challenge. I mean, if I talk to, like, you guys, the security people, I hear that even getting funding for security is already a challenge, and that's about protecting our assets now investing in privacy, which means protecting, well, kind of reducing the information we collect, which is kind of, well, the more data, the more money, or that's at least the misconception that a lot of companies have. So I think there lies still a big challenge in convincing companies because there are studies that show that you get twice to 5 times the return on investment if you invest in privacy. And I mean, if you don't, well, especially in Europe, you get lots of fines. if there is a check if we fail to have privacy by design. So, there are sufficient reasons, but now companies need to follow that idea.

19:56Chris RomeoAnd you mentioned privacy by design. What's the— I've always legitimately always wondered this, and I never knew the answer to this. So, I'm curious to get directly from you. What is the connection between Linden and privacy by design? Is there a connection, or is there supposed to be? Like, what's your take on that?

20:17Robert HurlbutYeah.

20:17Kim WuytsYeah, the connection between Lean In and privacy by design is the same as security threat modeling to security by design, or shift left, or whatever buzzwords you want to use there. I think threat modeling can be a great driver for that by-design process, because you already start early with thinking all the stuff that can go wrong. And, well, you know that if you think about that early, you can start fixing that. And the outcome of the threat modeling exercise can then be the guide to to have architectural decisions, to define pen tests, to have all these things. So I think having a threat modeling approach for privacy by design, such as Lindon, or for security by design, can really help you kind of structure maybe even that process. I know the focus is a lot on threat modeling now, but I think that that's an approach, that's a technique that can really help. I don't know. what your feeling is about Threat Modeling for Security by Design or shift-left.

21:14Chris RomeoYeah, I think secure by design is really our ultimate goal. It's one of the things I've realized in the last, maybe, number of weeks, number of months, as CISA has become more prolific in their writing about secure by design, secure by default. And somebody else explained it to me this way. I think it was Matt Coles, actually. He said, secure by design, threat modeling is a vehicle. He might not have used the word vehicle, but I'm gonna use it now. Threat modeling is a vehicle to secure by design, but threat modeling is not secure by design. They're not the same thing.

21:51Kim WuytsYeah.

21:52Chris RomeoJust like secure architecture is also a piece of secure by design. When you pull it up and you start looking at the 50,000-foot view of the system, that's not where I normally recommend people live in the threat modeling world. Because if I look at the, you know, folks like us, we can survive looking at the 50,000-foot view because we can extrapolate all of the threats that exist by looking at one box, just because we have security and privacy experience. We've looked at so many systems. But the average developer can't look at a secure architecture in one box and say, oh, I know all 50 threats that could potentially have to be dealt with in that one box. But Matt's point was secure by design, secure architecture, threat modeling, These are all things that are assisting us get to that secure by design. But, yeah, I've become more and more convinced that that's really what our goal is. That's where we should be aiming. And we use threat modeling as a vehicle and secure architecture as a vehicle to get there.

22:51Kim WuytsYeah. Yeah, I completely agree there. So, for privacy, well, I'm gonna stretch the definition a bit because GDPR mentions data protection by design, data protection by default explicitly. I'm kind of massaging that into privacy by design. There are some differences I probably shouldn't go into because everyone's definition of data protection and privacy and the overlap is different. But I definitely see it fitting in there. And even in the ISO on, was it privacy engineering or privacy by design? I think both actually mentioned the need for privacy threat modeling there explicitly. So, There is that recognition from the community in privacy as well that threat modeling is definitely beneficial. It's not a synonym for by design, but definitely, as you say, like, a vehicle that will help you and facilitate that process.

23:45Chris RomeoSo, when I do privacy by design, like, I feel like security or secure by design is me looking, is building a solid architecture, it's ensuring I have all these, assurance-creating activities. It's also knowing that I am threat modeling and looking at a list of things, and I'm not exposing data, I'm not exposing confidential information that belongs to the company. Is privacy by design a similar journey or thought process that you're going through? Like, where do you even start for privacy by design? Like, if I wanted to apply this?

24:27Kim WuytsYeah. Yeah. I think it's similar, but then again, that mindset is different. So it's basically, you know, what functionality you want to reach. And the question is then, can we reach the same but violate the privacy of the individuals less? Well, ideally we don't want to violate the privacy at all, but, but, um, like, how can we do this by collecting less information or by collecting less specific information? Do we really need all of that information? for that functionality. So the sooner you start with that, ideally at ideation already, the sooner you can start thinking of, well, okay, this is the end goal. This is the thing we want to achieve. Now, do we really need to do that in that way that we think we, I don't know, need to have our users have their location data shared with us 24/7? Or maybe we can get the same functionality, but just with an aggregated location once a day or once a month or whatever, will that still be enough? So it's kind of, it's the same, but that different mindset is again, like, how can we make this, how can we do this in the best interest of the individual? How can we make sure that the individual is fine with it? So it's also bringing the individual and their—

25:49Chris RomeoYeah.

25:50Kim Wuytsneeds, their expectations into the equation, basically.

25:53Chris RomeoSo, with privacy by design, do I start with a set of data, and then do I reduct or reduce to reach privacy by design? Or is there a state that I can get to where I know so much about privacy by design that I just don't even choose the— I don't even make the bad decisions upfront? Or how does that come together?

26:14Kim WuytsI think that's really tricky because, Well, the more data there is, the more you can deduce. And it's really hard to, like, before you actually know all the data you will be using, to see like how it all can come together and what can you deduce from it. So sometimes it's really about seeing the whole picture of the data that, well, the data items that you think will be in the system. also often, it's not a greenfield kind of analysis, but you have this system and you want to add some functionality and you have all these data, so let's just use it. But then the question becomes like, well, do I really need all that data that we already have in the system? Is that, well, we collected it for a specific purpose. Can we reuse that purpose for this purpose? Does it match? Yeah, I think it's really tricky. I mean, for security, you can never say, well, this is 100% secure. I think for privacy, especially technical privacy, data privacy, that's also tricky. But I think you can at least show that you did your best efforts and that should, let's say, hopefully be enough. It's a risk-based approach as well. Yeah.

27:35Chris RomeoAnd it sounds like when you're describing an existing system, something that we've already built, something we're already using a number of pieces of data, we're storing a number of pieces of data, in that case, applying privacy by design is likely gonna be a reduction because we're gonna look at it and say, why did we even— we don't even need to store this. Why are we keeping this? We never use it, and we don't care about it, but yet, we're taking on the liability of carrying that data forward. And it provides no business value to us. And so, for an existing system, just like a lot of security threat modeling, like, we always wish we were threat modeling something before it was ever built, but 99% of the time, that's not the case. We're joining the project after something, you know, we're like, hey, let's see if we can change out this aircraft engine while we're mid-flight and still keep the plane up in the air. So, yeah, so I could see a reduction being something that we're focused on in privacy by design for existing things, because people have notoriously not practiced good privacy principles and reduction in data and all those types of things. But in creating something new, hopefully you've got enough perspective to maybe make decisions in the process so that you don't Because you can see what'll happen if we keep that data.

28:58Kim WuytsYeah, yeah, yeah, yeah, indeed. If you can, like, at ideation, start reflecting on, well, wait a minute, it's not because we used to do it like this that we have to do it like this. Is there a way that we don't need to have, I don't know, full name, address, and date of birth to let people read a white paper or whatever? I'm just coming up with some example, but I mean, that's kind of a common situation there. Yeah. Yeah.

29:27Chris RomeoAre there patterns in, I'm really going on a rat— down a rabbit hole here, but I'm, I'm learning a lot in the process. So, are there—

29:37Kim WuytsThere are privacy patterns. There is an entire catalog of privacy patterns. It's, it's, it's, it's an academic catalog, but there is a, an, well, you have privacypatterns.org and you have privacypatterns.eu, which has like like 90% overlap, but they're still kind of managed by different people, although I think at some point there was an overlap there. But yeah, you have privacy patterns there too. And you have also a set of strategies and tactics created by Jaap-Henk Hoekman, who is a Dutch professor, and his PhD student, former PhD student, Michael Kolesky, and the tactics there, they have They call it Little Blue Book, I think, with a lot of privacy strategies that say like, you need to minimize, you need to hide, you need to enforce. So that gives you also some ideas of what are the things I can do if I want to get started, or if I found these, this bunch of privacy threats, how can I start tackling them?

30:36Robert HurlbutSo you don't immediately start looking for, I don't know, some crypto solution for something, but that you can really start by looking at more high-level strategies and tactics and That sounds to me like, you know, just like security threat modeling can lead to your requirements, those strategies and what to collect, what not to collect, can certainly lead to similar requirements related to privacy engineering and development and so forth. Shifting gears a little bit, you know, we were all co-authors on the Threat Modeling Manifesto. But in particular, for privacy engineering, could you explain the significance of the manifesto in that field?

31:23Kim WuytsYeah. Well, I think it has the same significance as it does for security engineering. I think for privacy engineering, it gave an additional boost because now we have this group of people, including, well, mainly security people, who also say, like, look, privacy threat modeling, it's a thing. It's equally useful as security threat modeling. We should really embrace this. So I've seen lots of people, like, using it or referencing it, not just in the security community, but also in the privacy community saying, like, well, this threat modeling thing, this is something we should have a look at. And look at security and privacy. See, it's not just us saying privacy needs to go with security. It matters.

32:10Chris RomeoVery cool. So, when you think about emerging trends or new things that are happening in privacy, are there things that— I mean, ChatGPT and generative AI must be— I'm just thinking about that off the top of my head. That's gotta be something that's causing some privacy wrinkles for the future. But, like, what else is on your mind as a privacy professional?

32:36Kim WuytsYou're stealing my answer. already.

32:38Chris RomeoIt's gonna be really high. That's everybody's answer to every question I ask these days. They're like, oh yeah, AI.

32:44Kim WuytsYeah. Well, responsible AI is like, I think one of the big things there. So it's not just about security and privacy, it's about ethics and doing that in a responsible way. Actually, a privacy friend of mine has also, well, not extended, but based on the Linden cards, created a whole deck vet cards for responsible AI specifically. So there's even responsible AI thresholding support there. Yeah, I think that will be a very interesting one. A while ago, I read a paper about brain-to-text translation. And so that basically our brainwaves are being put into computers now and that we need to think about the security and privacy impact of that stuff too. And threat modeling can help there. So, I have no idea what crazy technology stuff will go on, but I'm sure there will be a lot of fancy things there. Let me think. Other than that, yeah, AI is the big, I think for now, AI will be the big one to tackle. Yeah.

33:57Chris RomeoSo, what are the privacy threats then? Since we're all threat modeling fans, we're gonna turn this back around on threats. What are the privacy-specific threats when we think about, let's just, let's not even use a specific generative AI. Let's just say privacy threats in regards to generative AI systems as we're seeing them deployed right now.

34:19Kim WuytsYeah, it's all the information you put in there, right? I mean, some of that contains personal information and you you kind of lose, well, ownership is not a term that the legal people prefer, but you kind of lose it. I mean, you don't know what happens with it. How is that used? How is that abused potentially? If that's used in just some AI process that feeds back only to you, then that might be okay. But if that personal information gets used in that bigger process and other people get to use that too, you cannot trace it because typically you don't see or get any feedback on what information is specifically used for a certain response or a certain answer. So, it's, yeah, it's a bit scary if you start thinking about that. Yeah, I think that's one of the big ones there.

35:24Chris RomeoAnd I've seen other folks calling for we should have a source attached to generative AI-related answers. Because right now, you enter a prompt, you get a response, but you have no idea where that came from. And if we could see a source attached to it, it would allow us as humans to say, okay, I generally trust that source of data, or that's the wackiest place they could have ever—

35:53Kim WuytsRight.

35:53Chris Romeofound a piece of information from and there's no way that's true.

35:56Robert HurlbutYeah.

35:57Chris RomeoIt, it lets us kind of measure it.

35:59Kim WuytsYeah.

35:59Robert HurlbutAnd, and generally you have to do that anyway, right? Like you said, you might get 2 or 3, let's say 3 out of 4 answers are correct, but the 4th one, how do I know it's correct or not? So you still have to do a little bit of due diligence and make sure. So there's that as well. I was going to ask about intellectual property, for example, is that another issue for privacy that in generative AI that, you know, maybe somebody's core secrets, company secrets and so forth that get pushed out there and now that's no longer private.

36:32Kim WuytsYeah. Yeah. Yeah. So intellectual property, that's more probably corporate law than that's privacy, but definitely. Yeah. But also, yeah, if you make, you type your notes and you have I don't know what ChatGPT generate a summary or a deck of slides or whatever that can contain corporate secrets, but maybe you, you wrote down, well, this person wasn't there because they were sick or, um, well, this person asked an annoying question or whatever. That's not company secrets. That's potentially already personal data. Do you want to have that all, not just in the PowerPoint, but somewhere in that ChatGPT or whatever? interface or knowledge base stored forever.

37:21Chris RomeoRight. Okay. So, here's my final question, and then we'll go to key takeaway and call to action. If you had a magic wand, you gotta love when a question starts with, if you had a magic wand, and you could change one thing about privacy, across our industry, what would be the one thing that you would change? I'll just stop there. I won't even add any more conditions on it. I'll just say, what would be the one thing you would change about privacy?

37:56Kim WuytsSuch an easy question. Yeah, I think, well, this is gonna sound stupid probably, but awareness. To me, it all starts now with awareness, like, having both individuals realize, well, this is a thing worth fighting for. And then having at least the companies see, well, wow, this is a valuable thing. If it's not just to do good, but we really need this to grow our business and get trust from the individuals. And so I think the overall awareness, like getting people to embrace the idea, that would be so helpful. So that's, I guess that's why I like talking about it too. help bits and pieces get that awareness across.

38:44Chris RomeoYeah, I think that's an excellent answer. I think that's, I think that's still an area that we, that we lack. And you mentioned earlier how people will say, oh, I just don't care about my data. Like they already have all my data. Like that always pains me so much. It's like, that's such a, that's such a cop-out for somebody to say that. Like, do you really want them? So it's okay if they extracted to your earlier point as well about brainwaves to text. So you're saying it's okay that if, if there was a digital system that could extract all of your thoughts, feelings, and other— and deepest, darkest secrets, and then posted it in a, in a generative AI, you'd be okay with that? I think most people are going to say, well, hold on a second, I, I— that wasn't what I was talking about. I was talking about my Social Security number here in the United States, that— or my driver's license number. So yeah, I think awareness is a— is— I think there's still a long way to go.

39:37Robert HurlbutYeah.

39:37Chris RomeoI think there's still— when I think about the difference between what people know and have embraced about security versus what they know and embrace— have embraced about privacy, is there's still a big gap and a big delta between those two. And privacy, you just got more room, more work to do to get the word out. But I think it's definitely a worthy cause because, you know, after I looked at GDPR the first time, I realized I'm a privacy— I'm an individual privacy advocate as well.

40:07Kim WuytsYeah.

40:07Chris RomeoBecause I'm like, I don't want my information out there. I want my information protected as much as possible.

40:14Kim WuytsAbsolutely. Yeah.

40:18Chris RomeoHow about a key takeaway or a call to action then? You can— now, you can't use the same one. I'm sorry. I'm sorry. I checked our rulebook. The Application Security Podcast rulebook says you cannot use the same— the magic wand answer and the key takeaway answer cannot be the same one.

40:34Kim WuytsIt's the Security Application Podcast. So, let me say that I think it's important that security and privacy teams up, that we bring that privacy into security, and that because it shares so many, like, approaches and techniques, it just requires a bit of a different mindset. And yeah, if you do privacy, if you implement privacy, if you minimize data, then it doesn't just help privacy, but the less data you have, the less you can leak, the less privacy breaches, the less data breaches are there. So, I think it actually also has value for security people too.

41:10Chris RomeoVery cool. Thanks, Kim, for sharing your wisdom, expertise, knowledge, experience, all of these things in regards to privacy. I always learn something when I get a chance to chat with you. And so, really enjoyed the conversation. And just to reiterate, Kim's leaving academia in the next couple of weeks, and she's looking for her next opportunity in the field of privacy. So, if you wanna hire the best possible person on earth, she's available. Thanks, Kim.

41:41Kim WuytsThank you. Always a pleasure to talk with you guys. All right. Bye.

More like this