Submind YouTube summaries
Thumbnail for The Hidden Cost of AI Traffic Nobody Is Measuring | Steve Winterfeld, Akamai

The Hidden Cost of AI Traffic Nobody Is Measuring | Steve Winterfeld, Akamai

Watch on YouTube

Video summary

The video discusses the evolving landscape of digital threats where malicious actors leverage advanced artificial intelligence to create sophisticated tools for fraud and data harvesting. Steve Winterfeld highlights that while some bad actors are indeed creative, the real concern lies in how AI capabilities can now be rented or generated through platforms like Fraud GPT and Worm GPT, allowing attackers to develop code rapidly. This shift means that traditional scrapers are no longer just simple scripts but are becoming highly efficient systems capable of harvesting proprietary and customer information at unprecedented speeds and volumes, fundamentally changing the nature of cyber threats. A significant portion of the discussion focuses on the difficulty in distinguishing between helpful AI agents, known as "friends," and harmful ones, referred to as "enemies" or "front-enemies." Winterfeld explains that while legitimate users want to buy new products like tennis shoes, malicious bots can exploit these same AI-driven processes to purchase entire inventories for resale at inflated prices, a practice known as scalping. This blurring of lines makes it increasingly hard for organizations to identify and protect against attacks that mimic normal consumer behavior, forcing security teams to constantly adapt their defenses against faster and more complex strategies employed by adversaries. The core argument presented is the hidden cost associated with this surge in AI-generated traffic, which often goes unmeasured and unmanaged despite its impact on business operations. As a Chief Information Security Officer, Winterfeld expresses concern that the sheer volume of traffic generated by these AI systems provides no valuable insights while simultaneously draining resources and degrading customer experiences. The ability to buy code and capabilities via AI has lowered the barrier to entry for attacks, increasing their sophistication and speed, which necessitates continuous investment in protection measures to ensure fair access to products and maintain trust in digital ecosystems. In conclusion, the transcript emphasizes that the integration of AI into both defensive and offensive security operations is creating a new paradigm where the line between innovation and exploitation is thinner than ever before. Organizations must remain vigilant against the rapid evolution of these threats, recognizing that the tools used to automate legitimate tasks can be easily repurposed for malicious intent. The ultimate goal is to balance the benefits of AI in enhancing customer experiences with robust protections that prevent bad actors from undermining market integrity through automated scalping and data theft, ensuring that technology serves users rather than adversaries.
Read the full video transcript
You and I have talked a lot about, you know, the whole this scalping and, you know, fishing and how I mean some of these bad actors know offices are very creative people, you know, the the way they come out. I wish they were on our side, not on the opposite side. But what what is happening to some of those traditional tags and threats, which may not be as malicious, but they have their own, you know, of course, malicious intent as well. >> So, I will say one thing that, you know, looking at at things like Project Glass Wing, um the speed and volume is changing. You know, the the sophistication of of somebody being able to do this, you can now go rent these capabilities. You can go on AI and and have AI help you develop code. Um there are sites out there, Fraud GPT or Worm GPT that that are malicious in nature. And so, do we still see scrapers coming in to harvest information, proprietary information, customer information? Absolutely. You know, we Again, something we protect against. We track that. We talk about that. Um am I worried as a CISO about the traffic cost of all these, you know, we just talked about buying shoes through AI. All that volume of traffic is now AI systems, which I'm getting no insights from. So, that, you know, that traditional you and I talked about friends or shoppers, front-enemies are people that are informing shoppers. So, if again somebody's saying, "Hey, you know, you can buy shoes over here." Then that's helpful. And then enemies. So, friends, front-enemies, and enemies. Getting a little harder to tell those apart. Um you know, one thing I worry about as as again, when I was back at Nordstrom, is customer experience. And so, again, if there's a new tennis shoe coming out, I want everybody to be able to buy one, but I don't want one bot to buy all my inventory and then resell them at a higher price, scalping them basically. And so all these are protections we continue have to do, and we're seeing AI increase the sophistica- sophistication and speed of these kind of attacks, absolutely.