Go offline with the Player FM app!
Security for MCP
Manage episode 493691371 series 2877784
The Model Context Protocol (MCP) specification has helped to accelerate access to a wide range of data sources for AI applications. But there are questions about the security and trust implications around a protocol that is still in its infancy. Scott Crawford and Justin Lam return to the podcast to examine the concerns that have been raised and changes that are underway in the specification with host Eric Hanselman. The previous episode introduced MCP and some of the market forces that are in play. Security considerations didn’t appear to be fully sorted out in the first version of the specification, but more work is being done to move beyond the OAuth-based approach. Automating the data access process can be powerful, but also fraught with the potential for abuse.
The larger questions in MCP revolve around understanding risk and establishing trust. Data exposure has been a constant concern in AI, but the more complex issues exist in the integrity of the data that’s being used. AI technology is moving forward rapidly and adversaries that are looking to compromise it and moving right along with these advances.
More S&P Global Content:
For S&P Global Subscribers:
- Technology Primer: Model Context Protocol explained
- Databases and analytic services get the agentic AI treatment at Google Cloud Next 2025
- IT Insider 3: A roundup for IT decision-makers
Credits:
- Host/Author: Eric Hanselman
- Guests: Scott Crawford, Justin Lam
- Producer/Editor: Adam Kovalsky
- Published With Assistance From: Sophie Carr, Feranmi Adeoshun, Kyra Smith
103 episodes
Manage episode 493691371 series 2877784
The Model Context Protocol (MCP) specification has helped to accelerate access to a wide range of data sources for AI applications. But there are questions about the security and trust implications around a protocol that is still in its infancy. Scott Crawford and Justin Lam return to the podcast to examine the concerns that have been raised and changes that are underway in the specification with host Eric Hanselman. The previous episode introduced MCP and some of the market forces that are in play. Security considerations didn’t appear to be fully sorted out in the first version of the specification, but more work is being done to move beyond the OAuth-based approach. Automating the data access process can be powerful, but also fraught with the potential for abuse.
The larger questions in MCP revolve around understanding risk and establishing trust. Data exposure has been a constant concern in AI, but the more complex issues exist in the integrity of the data that’s being used. AI technology is moving forward rapidly and adversaries that are looking to compromise it and moving right along with these advances.
More S&P Global Content:
For S&P Global Subscribers:
- Technology Primer: Model Context Protocol explained
- Databases and analytic services get the agentic AI treatment at Google Cloud Next 2025
- IT Insider 3: A roundup for IT decision-makers
Credits:
- Host/Author: Eric Hanselman
- Guests: Scott Crawford, Justin Lam
- Producer/Editor: Adam Kovalsky
- Published With Assistance From: Sophie Carr, Feranmi Adeoshun, Kyra Smith
103 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.