Down the Security Rabbithole Podcast (DtSR)

DtSR Episode 717 - Your UI is Bullshit

Guest: Micheal Farnum, Sam Van Ryder

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 40:25

Guests: Michael Farnum, Sam Van Ryder

TL;DR: Most cybersecurity dashboards don’t fail because they’re ugly. They fail because they don’t change what we do next.

Description

In Episode 717, Rafal sits down with Michael Farnum (Cybersec Community) and Sam (Dragos, a long-time OT and industrial cybersecurity practitioner) to talk about the uncomfortable truth behind security UI/UX: much of what shows up in the GUI is pure noise. We dig into the split between “pretty but useless” interfaces and tools that are practical but painful, then map out what a real practitioner-focused dashboard should deliver: contextual metrics, clear workflows, and data that drives action inside a SOC, an MDR, or an enterprise security team.

From SIEM and EDR lessons to product management realities, we unpack why companies miss the mark when marketing drives the roadmap or when engineering builds for engineers only. We also get candid about the analyst ecosystem, the difference between grounded practitioner feedback and “ivory tower” trend-chasing, and how that can steer executives toward tools that are hard to operationalize.

Then we move into AI and CTEM, continuous threat exposure management, and why the win isn’t a flashier interface. The win is faster telemetry correlation, so we can answer the questions that matter: is this vulnerability reachable in our environment, is it exploitable, and what should we prioritize right now? We also touch on modern “interfaces” like APIs and MCP, where the UX becomes how efficiently you can get results, even when the user is another machine.

If you care about security tools that actually work under pressure, hit play, subscribe, share the episode with a teammate, and leave a review with your biggest UI pet peeve.

YouTube Video: https://youtube.com/live/ts2rU1-j4EI

Have something to say? Let's hear it.

Support the show

>>> Please consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast

Welcome And Introductions

SPEAKER_04

All right, good morning, good afternoon, and good evening. Welcome down the security rabbit hole to yet another edition of the Down the Security Rabbit Hole podcast. This is Raf. I've got two good friends joining me this week. Welcome to your favorite cybersecurity podcast. Happy Tuesday when you're listening to this. And this is gonna be another one of those fun episodes where we just grab some friends. We'll talk about something interesting. A topic always rears its head. Let's do some quick intros. We'll start with Michael. You go first.

SPEAKER_02

Hey, Rav, thanks for having us, man. Good to see you. Michael Farnum, CEO of Cybersec Community, co-founder of Cybersec Community, along with my buddy Sam here. Okay, Sam, your turn.

SPEAKER_01

Yeah. So I'm I'm co-founder here, and I do a whole lot less than Michael does, but I am responsible for the content and speaker lineup and all that kind of good stuff for the conference that we do. And I also have a day job. So I did work for Drago's in the during the day and have been in the industrial sector for a very long time now.

SPEAKER_04

Yeah, you've been uh you've been on the OT side for a bit. By the way, congrats on the uh the the journey there. That's been uh that's been pretty cool to watch. That's uh it's been great. I love watching the trajectory of that organization because it's like small scrappy, bigger, struggle, bigger, bigger still, you know, finding purpose. I love it. It's nice to see that there's still focus being paid to something that's actually kind of a big kind of a big problem. You know, we be

Pretty Dashboards Versus Real Work

SPEAKER_04

let's dive in. So we we're for those of you guys that weren't listening, that's not the three of us here, before we hit record, we said, okay, what do we, you know, how do we want to couch this? What do we want to talk about? And Sam had this great quote of and he starts talking about GUIs. Most of the things in the GUI are bullshit. I was like, that's the name of the podcast. All right. So Sam, you wanna you wanna go ahead and kick kick that off? That was a good rant. Let's let's let's wind that back and just like I'm gonna wind you up and let you go.

SPEAKER_01

Yeah, so it really came from Michael had a uh uh a snippet out there, a video out there uh talking about this and comparing value of the of the GUI to the practitioner essentially and you know, art versus value. And it was a good message. But it for me, the thing is I've been this is my this is my seventh startup that I've done at Drago's, right? I have seen everything from a GUI with absolutely nothing behind it, a total marketing ploy to try to hook people, right? I've seen, you know, I've seen movie producing backgrounds do really cool GUIs and they really didn't do they look cool, pew-pew maps, all that kind of stuff. And yeah, and I've been in plenty of stocks where they have some sort of a pew-pew map up there because when the execs come, that goes up on the screen. Because now the execs know, hey, look, I our software does stuff. Yeah, but when you look at the the data that's there, it's not necessarily practitioner focused, or it's not easy to get to the data you need to make it easy to make decisions when you're working through an interface. Right.

SPEAKER_04

You know, the the I'll I'll post a link to the video because I think it's it's interesting, Michael. Your your explanation. But like pretty but useless, practical, but maybe boring. I mean maybe I've oversimplified, but but but I I I feel like there that those are those are the extremes, right? You've got you've got stuff that I remember this maybe taking us back a bit. I remember uh when I was still with with with Optive, we had uh an RSA one year, we had a couple of startup guys come in and pitch us this this product. Uh it was an EDR tool, it had the owl as the logo, you guys all know who I'm talking about. And they had the world's most amazing, like that GUI was awesome. It it it made sense, it was intuitive. Like you could just look at it and go, oh, I know what to do next. And and then like somewhere between there and them disappearing, thing you know, things got complicated, obviously. But there there are really it I think it's uh it's it's a it's an it's is it endemic to our our practice that it's really hard to absolutely nail the practical versus visual aspect of things. The crossing point where it was. Yeah, like where does where does the because I I've you're Sam's right. I've I've been in GUIs where you're like, this is really pretty, but it's actually telling me nothing. Like I gotta go do you know, I gotta go command line if I want something to to work. And then there's like that brut, like I remember the uh the very first uh iteration of the Symantec Sin. Like the UX was just like it made you want to throw the thing out the window, but it was actually kind of useful for its time, for its time, right? And so why why can't why is this so hard to get right?

SPEAKER_02

I mean, my take on it is that the crossing point is is not actually where you want to be. So because I much, much, much prefer, and I and I'm not thinking, I mean, usability is one thing. So there's there's in my video I talk

UI Versus UX And Context

SPEAKER_02

about UI and I talk about UX. So UX, you user interface versus user experience. Those are two different things. User experience, yeah, you absolutely need to have something that is easy to use, that to your point gives you kind of a you know, I know where to go next type of thing. And I think there are a couple of vendors out there, especially on the EDR side, who have nailed that really, really well, or at least did in you know their first few versions. But but my my thing is always practicality of the UI, not necessarily the UX. And that's what I talked about more in the video, which was around what are the metrics that you're giving me. So we've all heard the data that you're giving me, maybe not just metrics, but data. We've all heard vanity metrics and things like that. And to Sam's point earlier, you know, being in a SOC where you see, you know, things up on the wall, and it's like, oh, you know, and you want to you want to bring in, especially some of the MDRs where you know you want to bring in your customer to show them that you're doing cool stuff and you show off the big screens and all of that. And when you look close at the screens, you're like, I mean, from a worldview perspective, that's a great data point from a contextual perspective for my business, that has absolutely no practical value. All it is is a marketing piece on the wall. And I think that's what we run into with interfaces a lot of times is it you'll see marketing stuff on my personal dashboard. And I'm like, I have no desire to see how many vulnerabilities you know about in the wild. I want to know what's contextual to our environment. And what I talked about in that video was a customer that I'm advising, a startup that I'm advising, and they went from a nice UI, UX, but it had very little practical value. It was decent, but it was like if it was down here where it was crossing or you know, up here or whatever. We advised them, some other people advised them. They came out with a dashboard that looked really good, solid, easy to use. You can move around, you know where all your stuff is. And it did cross that line right where it should have, RAF, was which was all of the metrics on there were contextual. They were automatically usable. If that was in my environment, I would be able to go, okay, I know. And it was, it's all specifically to AI governance. So I know how many different AI tools are being used, either through the browser or on the desktop. I know here's my, you know, how many that are applicable, like I that I've are not applicable, that I've approved in my environment, and here are the ones that aren't. And I can click on those, and it just did a fantastic job. And that's what I'm talking about. You you definitely can hit it. Why it's hard, I think, is because we have a bunch of engineers that are building this stuff. Nothing against engineers, I love them, but they're always thinking practical value before they're thinking UX. And then and one of the companies, and I can't remember the name of it that Sam worked at, they literally had the person that designed the interface on the what was the movie report? It was Morty.

SPEAKER_01

Yeah.

SPEAKER_02

And that freaking interface, Sam brought it in. Like they came into our company when I was at Set Solutions, and I was like, holy shit, this thing is awesome. This is the coolest interface in the world. But when I started looking at it, I was like, I'm not sure what to do next. Like, what is this telling me? Like it was really cool, but it just so you've got both extremes, and why we can't do both, it's I think it a lot of it comes down to who leads the company. Does marketing lead the company or do engineers lead the company? And if you can't find somebody with both mindsets to bring that in the middle, then you're gonna run into one extreme or the other.

SPEAKER_01

But I might argue too, though, user engagement, right? I mean, really what you want is the end user's input is what they and that's the other problem with those, right? It's you have users that have different ways of working. So, you know, one socks gonna work a little different than the other, and so that you know, that interface might look a little different or the things that they want to see.

Who Drives Product Decisions

SPEAKER_01

So it becomes complex. So the best thing to do is have something that's very flexible on the back end that you can easily engineer or or create on the front end so that you can easily find that value that are specific to your users, right?

SPEAKER_04

Do you everything you guys are saying, do you guys remember ArcSight? Oh, yeah, yeah. Built by engineers for engineers only. Like amazing piece of kit, but you handed it to a customer and they'd be like, and and all of them said the same thing. I have no idea how to make this work. Like, but you just buy a 25-page manual.

SPEAKER_01

200 $25,000, you get a use case done, no problem, right? So yeah.

SPEAKER_02

It reminds me of Archer, August, on the GRC side. Exactly the same thing, yes. Yeah, but and it's still around and it's a massive ton of value in it, but it takes so much work to get anything out of it and to put in the right modules and everything else.

SPEAKER_04

It's interesting the extent to which the the team that runs product has to really be keen on the the you know the the the the functionality is driven by an engineering and and make sure you get your product requirements a good feedback channel from your customer and the and your users. You know, I I've seen I've seen good versions of that and I've seen bad versions of that. I think in bad versions of that on the extreme, customers drive and it it's it's it's kind of useless, but for different reasons, right? Where there's it's just too specific for to some use cases, it's it's impractical to be used in in in what you're trying to build versus what somebody wants it to be. Let's let's take the let's take the sim for example. That's the one that gets beat up on all the time, right? Like what do you want to see? What is it supposed to do? How do you make it do what you want? You know, ticketing platforms, sores, uh, you were talking CTEM earlier, like all these things. You have to strike that right balance, and it's not necessarily 50-50, I don't think. So I'm willing to give, I'm willing to give a little bit of like visual pleasantry for the fact that it can actually do something. But like going back, as far as I can I I can remember, guys, us security people have historically said, bah, GUI, I've got my command line, right? And now it's blah, GUI, I've got my API, and then and now it's transitioning to bah API, I've got my MCP. Like it's it's moving, it's a moving target. We're we're not crazy at the on the technical side about the visuals of it, but somebody cares, and it matters to people. Those that it matters to, it matters a lot to.

SPEAKER_02

Well, I like I've I've had conversations with startups that I'm like, you do not need from a practical perspective, a UI. Like they were all integration, they were complete like API integration. They were pulling telemetry, they were delivering that telemetry from one spot to another. And I was like, guys, if you create a dashboard, a reporting dashboard, it's nobody's gonna use it because what you're doing is moving data from here, telemetry from here to this sim. Everybody wants to view it in the SIM. You're redirecting engineering resources because you think you need this UI. Now, that being said, if you're a startup that's only doing that to that, you're probably not a product, you're a feature. However, right this is like don't waste your engineering resources on this because all anybody's gonna do is instrument you into their process and they're gonna use you from here to here, and that's all that you're you're gonna be used for.

SPEAKER_04

So that that that begs a different question because I I have recently worked for a company that it's living that that product living its most practical best life meant that people don't go in, like don't have that tab open or don't have that GUI open very often. Yep, right? So okay, I get it. You're essentially supplying data and uh and metrics and and actions and context and all these things into something else. Cool. But on the occasion that somebody did have to go into the their GUI, it had to be ultra precise because they were going in there for a few specific reasons that were like you can't things that you can't do outside. And that was never well understood, in my opinion, right? That it was it was sort of they built it to be general purpose and not for the specific use cases that you get the other like 80% of the time. And so it felt like product management was

When Customers Shape The Tool

SPEAKER_04

saying, no, no, we want like I want you in this dashboard, and people were like, that's not how it's gonna work. Give me these three use cases, everything else I'm doing over here, and and and that was a big miss. And and so you you had this push and pull of you know, uh of customers wanting this, engineering releasing this, product releasing this feature, and you're like, why are these like you're you're supposed to be doing this? They were kind of doing this, right? And and it was very difficult to explain, but that's the other Prattfall, I think, is knowing what it is that you like this comes back to me for like what is it that you do? What's the value you deliver, and and how do you provide value to whoever to your user? And there's uh I can't remember how many times that we said this on his podcast. We still there's too many people that suck at this that are in product management jobs.

SPEAKER_02

Yeah, oh, I was gonna bring that up, absolutely. I know Sam gets that too. Like Sam and I had a very brief moment at where we were both at HP together. And I don't know, Sam, if you remember this, like their product management departments were they did not report into the product group that they were in. Yeah. So I would specifically remember those conversations, Michael. Yeah. I was at Fortify on Demand. The product manager worked for a product management group that reported up to a big higher-level product manager or whatever. Yeah, up higher. And it it both drove us crazy and also proved to be very useful in some ways because the fact that they did not rely or they didn't, they weren't beholden to the unit leader, the business unit leader, and they weren't beholden to the developers. They were beholden to the customer. Now, could that get out of hand? 100%. Like customers want stuff all over the place, they're like their brains are going all over, they're trying to solve a billion problems. It's like you they're gonna ask for every feature under the sun. So they had you had to have a good prior product manager that would prioritize stuff and not do, you know, the oh yeah, we can have that next week for you type of thing. Because they but so that structure was interesting, but if you had a good one, and we did at HP Fortify on Demand, we had a really good product manager, Scott. He he did a really good job of that. And he would put together, him and uh guy named uh Dylan would put together a hell of a customer advisory board to do that. So if you got a good one, like it'll it works out well. So I have a rough OD. Those are some good days. Oh, I miss those days. Miss those days bad. Jason, Daniel, Jason Haddock's Daniel Meesler, David Nestor, Greg Patton, all the time.

SPEAKER_04

I haven't talked to Nestor in forever, but I just had I just had Meesler on the pod a couple episodes ago.

SPEAKER_02

That's how Miesler and I got to know each other really, really well was working together there. So that was good that good days.

SPEAKER_04

Yeah, yeah. It's interesting, but like you you bring up a really interesting point is where where you get your direction from matters, right? Like what what how do you what drives that product? And I think where you start from an from an initial, I don't know, where you kick off the product, right? What it what it what do you do first? Do you develop a MVP that is functional but maybe not particularly pretty, or do you just go to show something that looks cool that doesn't really that doesn't actually function? Because I've seen both. I've seen both be relatively successful, to be frank, but I think it's harder to meet the whims and and and uh and whimsy of of all of your buyers when you when the the uh the functionality isn't there because it could be gorgeous and and extremely simple to use and look at and intuitive and all those happy words, it doesn't function like it's like it doesn't do the thing that you know you want it to do well. That excitement is very short-lived.

SPEAKER_01

Well, if you don't have your product management engaging with customers and getting that direct feedback, they're in an echo chamber, and then they're gonna go, you know, then it gets aligned with marketing, then they're gonna go out and tell other sales guy people in the next release, hey, look at this really cool stuff we're doing. And they're gonna go out and tell their custom tell out all the customers, look at all this really cool stuff we're doing. And all the customers are gonna be like, so what? Right. And it's not you want the customer to be the sales people, you want the customer out there saying, telling their peers at other the other company going, this thing's badass. It works. Like we love this thing. That's what you want. And so if you're not taking that customer feedback, you are it's a huge, huge mess. And to but you know, to your point, Michael, like if you have too much stuff, right? You have to prioritize. And you'll I've had situations where customers wanted to put a you know, a round peg and a square hole type thing and all that, right? It's just not you gotta also got to know where to delineate and say, okay, we do not know that. That's not our thing, right? But you can prioritize that.

SPEAKER_04

What's the role? Sorry, what's the role of the analyst community?

Analyst Firms And Reality Gaps

SPEAKER_04

Because I I uh I have some thoughts on this.

SPEAKER_02

Sorry, uh not sorry.

SPEAKER_00

Yeah.

SPEAKER_02

Okay, okay, that's a whole nother topic, but it depends on what analyst you're talking about. So I will sp I I won't name the analyst company for fear of getting sued. I'll just say that they had two different types of analysts. They had one analyst that was an on-the-ground analyst that worked with customers all the time and got great feedback. And those are the analysts I loved and enjoyed to talk to because they almost all of them, I think two a T, all of them were former uh practitioners, and they moved into that kind of role, and they were considered like junior analysts, but they were the ones that actually knew what was going on. Then you had the analysts that were in their ivory tower that come up with fancy names for stuff and like have no clue. It's basically, and this is no shade on like people in education or stuff, but a lot of times they're just not burdened by principle or real reality, right? And so you can come up with really cool stuff that way. Like if you're not burdened by that, then you know, really good stuff can come out of it. But if all you're doing is just coming up with stuff and like looking at trends and not really having good practical discussions, and I've talked to these folks before, those ivory towers, and they don't listen. All they do is want to talk, a lot of them. Yeah. And so I did analyst relations at Alert Logic with uh Misha, and I had very bad experiences to where I wanted to take a shower with some of the people at the top. And then but the people on the ground, like those are fantastic analysts, and I loved and they I would get so much value out of them. As much or more than I gave to them, I would get back.

SPEAKER_01

I just don't I don't know what to make of that. You you saying you wanted to take a shower with the people at the top, like that. Not with after I talked to them.

SPEAKER_04

Thanks, Sam. Somebody clear to you. Thank you very much.

SPEAKER_02

Thank you, Sam. I should have been more clear after the fact. Speaking of adding value. I mean, you know, it's a ten thousand dollar bill, or you have to take a shower. I don't know. No, we probably need to cut that part out.

SPEAKER_04

No, there's no cuts. I'm sorry. You're stuck with it. Oh gosh. All right. Well, there we might be a good thing. But listen, I I uh I totally get though the as I as you were as you were talking, I was like, yes, we have so many academics that end up in those roles, and it's just academic exercise, right? They got a you get a PhD in something, and then you go join an analyst firm as a senior somebody, and suddenly you're you're giving advice to people that are looking at you going, that's not how that works. And you're like, no, no, but it but it that's how it should work. You're like, no, no, that's that's like I I've had those conversations too, to be to be fair. I I did I did ARPR when I was at HP, and man, there are conversations that Celeste brought me into that I like I I don't sometimes you just sit there and go, I I have no nothing to add to this because the only thing I'm gonna say is you're an idiot. Like like and I and uh there's there have been there were so many of those where you just sort of go, what? All right, all right, are we am I being am I being punked right now? Where's action coaching? Like, what's happening? What's going on?

SPEAKER_02

Let's go real old school and say like where's Allen?

SPEAKER_01

But somebody's paying you somebody's pieing those reports and somebody's talking to those executives to drive tools that the their users may not want or their employees may not want just because they talk to an analyst, and that's unfortunate. That's how you get some of this stuff, though, right?

SPEAKER_04

You get you get these, I mean, look, uh let's let's let's resurrect a funny horse. Remember that that uh Norse company with the really cool pew pew pew pew.

SPEAKER_02

I was just looking them up actually about the earlier when we were talking about it. Yeah, Norse cybersecurity.

SPEAKER_04

And and everybody's like, wow, that's amazing. It meant not like literally made up completely nonsense.

SPEAKER_02

The coolest thing I'm gonna say, I'm gonna give them credit because there was an open source project called Pew Pew that came out of that. And in 2013 or 14 Sam, I can't remember, we used that for our capture the flag for our CTF at HusekCon back in the day. And we based it all, that was a war games theme, and the final flag was we had a big TV screen up in the village, and it had it they used PewPewMap to recreate the the launches that had the launch code at the bottom of it, and then whoever got the final flag, the launch code filled out, and all the cyber attacks started happening. And that was another FOD guy, Danny, that helped us write that. And so if it wasn't for Norse, PewPew would not have got it created, and we wouldn't have been able to use that for our CTF. So we never would have had threat button.

SPEAKER_01

We never would have had threat button. Oh god.

SPEAKER_04

Don't get it. Oh god. Anyway, so I think there's a lot of I think it's a that's a bunch of really good points that we just uh like wrapped up sort of quickly.

AI, CTEM, And Exposure Context

SPEAKER_04

But where do we find ourselves as a lot of the tools now suddenly move and incorporate AI? Is the is is it a is it a help? Is it a hindrance? Is it of no consequence? And maybe I want to because you you brought CTEM up at the beginning of our pre-record conversation. Maybe we go there, right? Like, what are you showing me? Why are you showing it to me, and how are you showing it to me are all relevant, but not equally relevant.

SPEAKER_02

Yeah, so what we talked about before we pre-recorded, I brought up CTIM because where I think some of the vanity metrics and vanity dashboards came from originally were some of the vulnerability management companies. And look, it is what it is. I'm not I'm not knocking them. What they didn't we really didn't have a good way back then of providing contextual information around the vulnerabilities. Like it did the the tech just didn't exist where you could really dig in. It was very much a I'm gonna scan, or the closest you could come with contextual information was being able to have a vulnerability management company that had an agent that would go on your desktop. But that still didn't provide good contextual information. So what you had to do is you had to have an ability to have agents and you had to have the ability to scan everything, not just endpoints, but you know, all your network devices and all that. And then you had to some kind of bring some kind of way bring all of that together to give you some kind of context so you could prioritize. But generally, prioritization all came around what the C VSS score was on it or whatever, right? You know, this was a 10, so you got to take care of it, even though in your environment it probably was a 2.3 or something, because it it may not even exist in your environment. So I think that's where that started. What I'm seeing now with CTEM, and this I think is directly enabled in a lot of ways by AI. I don't think AI affects the I mean, you I mean, vibe coding and stuff. Can you get AI to give you a cool interface that is, you know, user-friendly and stuff? Maybe it can do a little bit better of a job than some people, but I don't think ultimately that's where it's gonna have the effect. I think the effect is the ability to take information from your infrastructure and from your network and compile that and make sense of it a lot quicker than humans can to say this particular vulnerability is in your environment and it's reachable. And if you clean it up, you have something that maybe on CVSS is a 7.2, but in your environment is in a critical infrastructure part of your company and is absolutely going to be devastating if it's taken advantage of. So, like I said in the pre-recording, I like, even though CTEM stands for continuous threat evaluation or exposure management. Exposure, there we go. Sorry, my brain just locked continuous threat exposure management. I I like to think of it in in smaller fashion as contextual threat exposure management because it's telling you not just what's CVSS, not just what's on the KVE, but what's in your environment, if it can be exploited. And if it doesn't, if it can't be exploited, if it's not really reachable, do you need to clean it up? Yes, but you don't need to prioritize it. I think that's where AI provides most of the value because most of those companies are using that in some way, shape, or form to be able to figure that out in a much quicker fashion.

SPEAKER_01

And AI needs the data to do it. So, you know, there there again, you go back to customer experience. I mean the customer input. Well, there you have it, right? The customer has an opportunity to put input here. And and that could be part of the equation, which could could make things better. I I don't know, I haven't seen it yet. I haven't seen a tool a new tool, big security tool that's been developed by AI for us all and it's gonna solve all the problems. But you know, maybe we'll see something someday. I'm sure we will, not just leveraging AI, but actually developed by, and there'll be some interesting conversations that'll be a little different at that point.

SPEAKER_04

I I I think we're gonna uh I think we're gonna need to just sort of stay grounded in there are certain ways that we as a a user of anything think like our brains go left to right, top to bottom, right? So the most important thing you're gonna need to show me is in the top left-hand corner, that's where my eyeballs go first. That's just the way my brain is wider. Like that's just and that's the same for a lot of people. Colors matter, spacing matters, you know, the the way things are laid out matter. This is the thing.

SPEAKER_02

I think the easiest thing to have an effect on somebody, at least for me, is to just give me an option between light mode and dark mode. Like if you if you only if you only create one or the other, and I don't have an option because I love dark mode, but I know every a lot of other people hate it and they can't, it messes with their eyes, to your point. Like it it has to do with user experience and being flexible, like Sam was saying earlier. But yeah, you you've I think AI can help there just from a flexibility standpoint, but you you're right. I mean, I think you kind of have to bring it down to some of those first principles instead of just saying what can AI

Designing For Humans And Machines

SPEAKER_02

do to make this all flashy and everything.

SPEAKER_04

Well, so you know, I know people we we tend to use UI and UX interchangeably in some place in some places, and sometimes we treat them as the same thing. But I think the the interface, the user interface, right, the way that the human or the intended user, I guess it's not necessarily human anymore, in is able to interact brings about the experience, right? So UX follows UI, I think, if if I'm if I'm thinking through it logically, right? The experience because is is a is a result of the interface. So we have to have like there are certain rules that that exist, not because uh for you know layout and and and cleanliness and and you know contrast and colors and all the other things. And but ultimately it's give me the thing that I care about the most, show me the workflows, show me the things that I need to do and why it matters and what it matters, and give me an easy way to go do my work, whatever that work is. You you think that's pretty intuitive, but that's actually kind of hard.

SPEAKER_02

Because you're designing for people. I mean, it's one thing that you put forward and it looks the most logical, it's somebody's gonna break it or somebody's gonna do something different. I that doesn't make any sense to me. You're just you're dealing with uh you know meat space instead of cyberspace, so it just is what it is.

SPEAKER_04

I wonder if that's gonna change any as computers become the user for some of these things, like right, computers using computers you don't need a GUI at that point, do you?

SPEAKER_01

Gibber speak or whatever it's called, or yeah, I mean that sounds like an API to me. That sounds I mean at the end of the day.

SPEAKER_02

Now they're yeah, they're they're ingesting telemetry and doing their own internal visualization. They don't need a dashboard to do that for them.

SPEAKER_04

They can turn dashboards, but but so there's no, I mean, there's still a UI UX there, right? The interface is just an MCP server or an API library or something. The experience then is how practical and and usable is that, right? Do you have to make 27 calls to get a task accomplished, or can you do it in one? Right.

SPEAKER_02

So that that I I liken it to like when we finally do reach having self-driving cars completely, 100%. Like, I mean, people will still drive their own cars to some degree, but like when you read what does the UI and UX become for a person? All all they have to do is say, get me to hear, and then the rest of the time you're watching a movie. It's the same thing with AI, speaking to AI. It's I need to probably see a result, or I need to have some way of inputting, which you know could just be me prompting over voice saying, I need this to happen, and you do what you you're supposed to do, and then give me the result. Same thing with driving from one place to another. I need to get to the grocery store. My okay, I'll probably I'll create the best route, I'll get you there the most efficiently without tolls, let's say. And then once I get there, I've you know, that's my end result. So to me, it's the same, kind of the same thing. Yeah.

CybersecCon Details And Closing

SPEAKER_03

Hey, before we let you go, Michael, talk to me about uh what you're putting on there.

SPEAKER_02

Uh so I've got a shirt. Oh, you mean putting okay. I was confused. I thought it's a cyber C S C R. Uh Cybersecond. Yeah. So yeah, this is cyber without an E, if you can see that, because we're cool like that, Sam's point.

SPEAKER_04

Because that's that's the hip thing to do. That I guess.

SPEAKER_02

That's the hip thing to do. Well, the other thing I came up with is community yields better resilience. So that one's a cool thing.

SPEAKER_01

So you know if you can tell he he's the GUI designer on the team.

SPEAKER_02

I'm the GUI designer. Everybody else does the practical stuff. Yeah. No, CybersecCon is a conference that we're running down here in Houston on September 15th and 16th of 2026 at the George R. Brown Convention Center. So CybersecCon came out of HUSECCon. So this was a conference that Sam and I started putting on back way back in 2010. And the last one technically was last year in 2025. And that was our 15th, or if you're we started on zero, so technically our 16th anniversary. And CybersecCon is our next iteration of that. The reason we changed the name from HUSETCON to CybersecCon is the HUSECTCCon was very much a well-loved and respected, essentially a regional cybersecurity conference that we started that went from 120 people to last year. We had over 3,000 people. And but what we started to see was a whole ton of people coming from outside of Houston and outside of Texas. So we we was like, we've gotta we gotta change this to show that we're a national cybersecurity conference.

SPEAKER_04

So we've I have my I'm I'm looking at my uh challenge coin case because I still have my house icon challenge coin in there. HusECCon. Sorry.

SPEAKER_02

It's like Houston, not HouseCon, but that's a whole joke. So yeah, we we're rooted in Houston, but we serve a national audience. That's a big thing for us. We'll always be in Houston. We've we're really want to build, we're building a community and a conference to serve, serve nationwide and even internationally as well. We've had people come from all over the world for it. We're right now we're two days long. We've got Win Schwartau coming out to open us up for our opening keynote. We've got Andy Ellis, who's kind of a part of the community and is he's doing a keynote. We've got Joe Marshall and Anne. How do you say your last name, Sam? Day Lanella. De Lanella coming out to close us out. We've got what, I Sam, 120 speakers or something like that.

SPEAKER_01

So it's we have 13 sessions, 13 tracks over the two days. And so that's over a hundred and I mean, that's over a hundred sessions, right? I mean, it's it's a lot of content that gets when we record everything and we we put it up for free, right? It's yeah, our mission's different, right? We we're not here to try to be some big, you know, for-profit conference type thing. We are here to serve the community, build it, give them a place. Uh we our ticket prices are low, exactly. We've always kept them low because of that. We want every we want it to be accessible for everybody when we bring new talent in. We started a little thing in there called Youth Second last year, which brought a bunch of high schoolers in to introduce them to cyber and give them the vibe, like have them walk the floor and everything, the exhibit hall and all that, and just you know, pick up swag and you know, do some cool things, pick locks, do all kinds of cool hacker stuff. And they left with, you know, hopefully we're gonna out of those 75 kids, we'll probably have a good chunk of them go the route of cyber. And, you know, with that, and and you know, there's there's a scholarship fund that we've got through one of the one of the organizations that we work with. And you know, so it's just a whole lot of stuff. It's very mission-driven in terms of what we're doing.

SPEAKER_02

I love it. I love it. Cybersec, Cybersec Careers is that nonprofit that we work with that we connect with to do the scholarship, do youth techcon. But we've got villages, we've got workshops, we've got we've got a ham radio in our villages. We've we're probably gonna have a bullet, a full-blown bulletin board system that you can dial connect to and dial in, like old school stuff this year. We've got lock picking, we've got AI Village, we've got all kinds of good stuff in there.

SPEAKER_04

I wish I had my 2400 bod modem still.

SPEAKER_02

You'll you'll be able to connect directly up to it, but we do have modems that'll build it, be built into it. And we've even, I don't know if it'll be integrated this year, but we got a PBX system that'll be connected.

SPEAKER_04

So that that's that's reason enough to go. All right, one more time, Dayton, Dayton place.

SPEAKER_02

September 15th, 16th, 2026, the George R. Brown Convention Center in Houston, Texas. That's a two-day con. And if you want the details on everything, go out to cyberseccon.com and remember that's cyber without the e. So c y br seccon.com.

SPEAKER_04

Awesome. Thanks you guys. It has been great having you aboard. I will probably see you there. I'd love for you to come out, man.

SPEAKER_02

Great. Get get Dave to come out, dude. I've been he he keynoted one year and I hadn't been able to get him to come back, so I need him back up.

SPEAKER_04

There you go. So uh I I now I can I can I can drag him kicking and screaming to another fun conference. All right, boys. It's been great having you on the show. Thanks so much for joining, folks. Thank you so much for listening. Go check out CyberCon. The E is silent. It's not there, it's gone. It doesn't gone. We've we've eliminated it. I'm hilarious. Boy, all right. That'll do it. We'll catch you guys another time, another place on another down the security rabbit hole podcast. Michael Sam, thanks for joining. Folks, thanks for listening. We'll catch you later. Bye-bye. See ya.

SPEAKER_06

This is for my friends for listening. Don't forget to leave my daddy review. Make sure this was your friends.