In this episode of What That Means, Camille has Abhilasha Bhargav-Spantzel, principal engineer at Intel, on the show to discuss Fearless Computing. In addition to her work at Intel, Abhilasha is also working with the kids who will be tomorrow’s engineers, and the conversation touches on:
• What fearless computing is
• Why kids are naturally better at fearless computing
• Fearless computing in the time of COVID
• Biometrics and privacy
• Identity, cryptography, and security
• Multi-factor authentication
• Virtualization
• Hypervisors
... and more! Don’t miss it!
Here are some key take-aways:
• Computers are no longer just tools for tasks – they’re an integral part of our lives. But there’s a lot of fear around being hacked or downloading the wrong thing. Fearless computing is about eradicating that fear. About making it possible to innovate, experiment, and try new things, without that constant fear.
• Kids are great with fearless computing because they question everything. Adults are often more trusting, but kids often start with a sense of distrust.
• Biometrics rely on more than just an image to determine legitimacy and authentication.
• Multi-factor authentication relies on multiple different things (i.e. voice, how you speak, how you type, etc.) for verification that you are, in fact, who you say you are.
• The cloud is already virtualized. Now, we’re working on virtualizing the client/computer. When you virtualize a PC, you can isolate your applications and workspaces.
• Virtualizing workspaces allows you to create partitions that prevent the spread of malware to entire systems. That way, you can try new things within workspaces with more confidence, privacy, and security. Virtualization also allows you to try new things, without being tied to a specific operating system.
• With remote learning, WFH, and telehealth, we don’t have big firewalls or intrusion detection systems protecting us. We have to rely a lot more on our PCs to do the protecting, which is why we’re (at Intel and elsewhere) starting to build more of these capabilities into the actual systems.
• To learn more about cybersecurity programs for kids – like the ones discussed during this episode – check out Fuse Breakers and Echelon Catapult.
Some interesting quotes from today’s episode:
“My experience, working with the kids, is that they start from scratch. They're not afraid of anything, which is what we want to continue.”
“I like to tell the kids, ‘Think bad, but do good.’ So, think what else could go wrong, but at the same time, see how you can protect yourself better and protect others.”
“It's about local authentication, not releasing this information. Your PC, for example, is in your control. It's not going anywhere and not too many people will have access to it and potentially use it in ways that you did not expect it to be used. But if that same information was in the cloud somewhere, just fundamentally, by design, you don't have control. You’re just trusting that the cloud entity that has collected this information is only going to use it for that purpose and nothing else.”
“Server-side, as you say, the cloud is already virtualized. And they did it primarily for consolidation and using applications in a much more efficient way, scaling the cloud. But on the client side, this is the new thing that is happening, which is: just like the server, we are working on virtualizing the client itself.”
“When you virtualize the system, there are actual partitions that allow you to work on different types of workloads and isolate them. Fundamentally, they're isolated. So, if something goes wrong in one, it doesn't impact the other.”
“It [malware] loves to spread. It loves to find its way into every application, down into the kernel levels and across the systems that it can reach. And if you isolate them fundamentally, its reach has already been contained.”
“Virtualization not only brings you the security through isolation, but it can also basically allow you to do a lot more experimentation and creativity, like we talked about. You can try new things and you're not tied to an operating system environment. And that's another benefit.”
“All of us became remote workers in a day's time. And a lot of the times, there was a break the glass scenario, where we just needed the users to be able to access these contained applications in some way or fashion. And that's not sustainable, because the threat landscape continued to grow. Nobody was waiting for things to stabilize before they can start trying to attack the systems.”
“That's what we want to do is to build this next generation of citizens and engineers who have security mindset and [are] doing the right things for the community.”