CS Chris Swan On The InfoQ Podcast

“If you look at the post-mortem of the Hugging Face incident, it was described ... as I think like having 10,000 drunk house robbers show up all at once. And that sounds like a very chaotic scene. But I think that might kind of perfectly encapsulate where we are at the moment.”

The InfoQ Podcast · Hands-On Engineering Podcasts · October 2026

“If you look at the post-mortem of the Hugging Face incident, it was described ... as I think like having 10,000 drunk house robbers show up all at once. And that sounds like a very chaotic scene. But I think that might kind of perfectly encapsulate where we are at the moment.” — Chris Swan, The InfoQ Podcast

Swan is passing on a description he attributes to the company's own security chief, of an attack carried out by AI agents. His point is that the attack surface is the same for humans and agents, but the scale is not, and scale causes trouble even when each attacker isn't very capable.

Transcript

The InfoQ Podcast Around 22:50 into the episode
Speaker 3

So this has been a festering problem long before AI, but AI is kind of rubbing our faces in it. As I prepare for next year's security track, I reached out to all of this year's speakers and said, who would you love to see talking on next year's security track? Victor got back to me almost straight away. And he was like, I want to see a talk about AI identity. And it's something that he's actually started writing a little open source project about. But we've always talked about a notion of least privilege, that we should give people just the privileges that they need to do their job. And actually, this notion of non-human identity has existed since way before AI. And if you look in most organizations, they've probably got something like 10x more non-human identities than they have people working in the organization. And of course, that's exploding now because of agents. It's not a new problem, but it's something that I think has often been overlooked and a little bit brushed under the carpet. And so absolutely, we should not be giving our AI agents our keys to the kingdom and saying, you know, off you go, do some stuff on my behalf. We should be very carefully controlling task-based, fine-grained permissions to do the thing that needs to be done and no more with all of the appropriate auditing and surveillance that should go along with that as well. And I think what's actually happening here is stuff that has been an air quotes enterprise problem and solved to a certain extent by enterprise identity management and the associated platforms that go with that is now becoming an individual problem. It's a hairy one to manage. And we don't want to be kind of manually thinking about this stuff. And so we now kind of get into the sort of Auroburro thing of we need an AI to help us manage the permissions that we're giving to our agents because otherwise it just becomes unmanageable.

Speaker 2

I don't know if it's fair to ask you to provide more teasers about next year, but for me, two points. Well, you mentioned one, and that's post-quantum computing or post-quantum cryptography. That's something that you have on your mind. You did mention some kind of security net for agents. Is there anything else that you would like to tease?

Speaker 3

I think there will be some more low-level talks. So there was a talk that we had lined up where the speaker couldn't actually make it this year. So I'm hoping that they're going to be able to return and we will get the newer, better version of their talk, which will be examining some of the lower-level things that we can do to build security in. And I think that applies in terms of humans and agents. The working title at the moment is about how do we defend systems from humans and agents. And I think actually there's a common convergence there that the attack surface area is the same, whether it's a human or an agent. The nature of the attack and the scale of the attack is probably very different between human and agent. If you look at the post-mortem of the hugging face incident, it was described by their siteo as I think like having 10,000 drunk house robbers show up all at once. And that sounds like a very chaotic scene. But I think that might kind of perfectly encapsulate where we are at the moment. And even if each individual attacker in that case isn't particularly capable, just the sheer scale brings a whole bunch of problems on its own. So I think I'd like to get a talk that sort of looks at that aspect of what we're confronting. But I want to kind of ground it in the reality of if you're doing a good job of defense, then that's going to defend against the human attacker, the AI. Agent attacker and the sort of human AI hybrid. And so getting that stuff right is always going to be the sort of helping yourself out way to go.

Speaker 2

Okay, just to summarize the points that I think I heard, going to lower level might help us as an industry, given that that will provide a better foundation. And hence, the ripple effect will be a lot broader, probably, and help different points, regardless if we are discussing about agents or humans. And best practices still hold. If we are doing our homework, most often than not, we are closer to safety than not.

Speaker 3

Yes.

Speaker 2

Okay. Is there anything else?

Speaker names from our own diarization · position estimated from where the line sits in the episode

More from The InfoQ Podcast