Sveriges mest populära poddar
What's in the SOSS? An OpenSSF Podcast
What's in the SOSS? An OpenSSF Podcast

Balancing AI's Double-Edged Sword: Software Engineering, Unlearning, and Ecosystem Sustainability with Mark Russinovich

57 min•8 september 2026

Om avsnittet

In this episode of What's in the SOSS?, host CRob sits down with Mark Russinovich – CTO and Deputy CISO of Azure, as well as Board Chair for the Open Source Security Foundation (OpenSSF) – for a wide-ranging conversation on the changing landscape of software security. Mark shares insights from his journey from Sysinternals to Azure leadership, exploring how generative AI is delivering dramatic productivity boosts while creating new talent pipeline challenges for early-in-career engineers. The discussion dives into the shift toward hardware-backed "what, not who" supply chain identity, the urgent rolling Y2K effort to fix AI-discovered vulnerabilities via initiatives like Accretis, and the reality of persistent AI hallucinations. Finally, Mark details OpenSSF's strategic priorities for package registry sustainability and gives a sneak peek into his personal vibe-coded side projects like Polypost. 

Chapters:

  • 00:00 – Sysinternals & Career Journey: Mark reflects on his transition from Sysinternals to Microsoft Azure leadership.  
  • 02:08 – OpenSSF Board Leadership: Mark outlines his vision and key priorities as the new OpenSSF Board Chair. 
  • 03:32 – Corporate & Community Alignment: How Microsoft balances its enterprise goals with open source community needs.  
  • 05:40 – AI's Impact on Software Engineering: Why AI coding shifts developer roles toward architecture, review, and preceptorships.  1
  • 2:35 – Finding vs. Fixing Vulnerabilities: Managing the rapid race against AI-assisted threats across modern systems.  
  • 16:07 – LLM Code Quality & Edge Cases: Exploring prompt specification limits and unexpected model behaviors.  
  • 22:07 – Navigating AI Hallucinations: Why model hallucinations persist despite web grounding and how experts mitigate them.  
  • 26:34 – Supply Chain: Shifting "Who" to "What": Establishing identity using hardware attestation and confidential computing.  
  • 30:44 – Machine Unlearning & Model Safety: Mark details his research on targeted unlearning and model alignment experiments.  
  • 34:06 – Rapid Response & Accretis: Standing up coordinated responses to patch critical open source vulnerabilities.  
  • 39:39 – Package Registry Sustainability: Securing package repositories and building sustainable funding models.  
  • 45:44 – Personal Projects & Vibe-Coding: Mark discusses his current AI coding stack, Polypost, and gaming.  
  • 53:44 – Rapid Fire Round: Quick takes on Emacs, Star Wars, and favorite dystopian robots.


Episode links:



What's in the SOSS? An OpenSSF Podcast med OpenSSF finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.