How Open-Source Linux Is Evolving to Meet Modern Security and Compliance Demands
Brian Dawson discusses his role at CIQ and the growing importance of proactive security strategies in Linux environments. The conversation explores the evolution of enterprise Linux, the role of Rocky Linux in delivering stability and compliance, and how organizations are hardening infrastructure to keep pace with rapid technological change and escalating threat landscapes.
Transcript
Hey everyone. Welcome to back here to Techstrong tv. You know, as I was saying before in the Green room, before we got on here versus the Green Ball that I used behind us in the studio, Brian Dawson has been doing videos on Techstrong.
com. Yeah. And I'm happy to have him back.
He's wor a lot of hats over the year. He'll tell you all about it. But let's welcome my friend Brian Dawson to Techstrong, back to Techstrong tv.
Brian, it's good to see you. How are you man? Alan, good to see you as well.
Looking good. It's, it's been a bit, but, uh, but yeah, always been a minute. Good to see it.
com. Been great, um, to see Techstrong grow to what it is today. I mean, it's 12 years, 12 years ago.
Yeah. Actually next month will be 12 years. So Crazy.
Yeah. And Brian, I wanna be you when I grow up. Alan, I was gonna say, you've done a great job.
Well, you don't wanna be me. You be, be the best Brian Dawson. You can, and that'll be enough of this world, my friend.
Okay. Brian, give people, you know, I, I said you've been around and, and we've know each other a long time, but give people a sense of kind of your career arc and kind of things you've done. Yeah, I would love to share because I think it's, it's somewhat been atypical, but I have a lot of pride in it.
Um, so, you know, I frankly, uh, started my career, uh, deciding I wanted to become a computer programmer so that I can, uh, build video games. I was able to be, uh, one of the first 100 people at Sony, uh, PlayStation or Sony Computer Entertainment of America. And, uh, and, um, you know, that gave me, um, a great chance to learn about how you enable smart developers and smart teams to deliver technology, literally from start to finish.
I had the benefit of then, uh, moving forward and, uh, building out our tools and technology program for Sony Worldwide Studios, um, which led me to open source, uh, and developer tooling. And then from there, most of my career has been focused on kind of that underlying, um, substrate, um, that enables technology delivery, um, but then also with a particular focus on, on open source inner source reuse. Um, and, you know, how do we efficiently sort of, um, capture the power of community to help us deliver software, uh, better, faster.
And, uh, now we'll talk about more secure. Excellent. Love it.
So, as I think people see under your name here on the screen, you're the director of Product Management for Linux at CIQ. Tell us, well, let's start with, tell us about CIQ. There might be people out here who are not familiar with them.
And then tell us about, you know, what your role is here now, uh, with this title. Okay, great. Great.
And actually I'll segue from before I saw a, a fantastic fit or opportunity to come, um, join, um, CIQ 'cause CIQ, uh, is not only, uh, built on open source, and I'll tell that history in a minute. Uh, they are focused on, on emerging and leading edge technology, starting with an HPC background and now sort of reframing and, and revolutionizing Linux. So when I had an opportunity to come here, uh, about a year ago, um, I jumped on now to tell you a bit about CIQ, really cool story.
Uh, so our CEO and founder Greg Kurtzer, who I know you've had conversations with, is one of the co-founders of Cintas Linux, uh, which were those that don't know, eventually went under Red Hat. Um, and while he was, uh, prior to and while he was found in Linux, uh, he was building out performant compute infrastructure, uh, for high performance computing for our national labs. You know, the systems that power, uh, our cancer research, our simulations, our our weapons armory, um, and really what a lot of people are trying to adopt with ai, um, today, um, after building that out and, um, delivering some, I think, really impactful open source technologies like, like Tainer, uh, uh, werewolf, um, uh, he founded CIQ and CIQ has a focus on delivering modern infrastructure for the gener for the generation of AI or the AI generation.
And, you know, we believe that, um, both with, um, building widely adopted, um, um, um, open source platforms like Linux, as well as being able to scale high performance computing, uh, and real production environments that we're, we're in a situation where we have the skills, knowledge and experience, um, to build the modern infrastructure that people need for the next age of compute. You know, there's another interesting story as we get, um, tele Linux where I think we'll drill in. Um, you know, IBM bought CentOS.
Um, Cintas was really kind of, uh, the developer's real that allowed you to learn, uh, enterprise Linux. It allowed you to deploy enterprise Linux in your dev and test environments without, um, high cost. Um, eventually Cintas was sort of shut down and move upstream as Linux as sort of its testing bed.
Um, so developers lost their, their, their dev stage environment, their testing, ground learning ground. I think within a week of that happening, um, Greg, uh, went to, uh, the channels and said, Hey, um, let's start a new cent toss. Immediately people responded, they named it Rocky and owed to one of his co-founders who was no longer with us.
Uh, and, uh, and so that's CIQ and that brings me here with CIQ, um, today. Um, I, I will add as to kind of, uh, lean in. One of the thesis we have here at CIQ is that, uh, while Lennox is widely adopted, uh, general purpose Linux, um, takes significant full-time engineer hours risk and iteration to tune for the purpose workloads like security, like container hosts like ai.
And, uh, we believe it's our responsibility and contribution to the industry and the Linux community to sort of build workloads specific variants that close out at least 80% of that gap. Um, so that people just have to finish off the bespoke 20%. You know, it's funny, uh, 19 98, 99, I'm helping build a company an early a SP called Inter Reliance.
We went public in I think 2000. Um, and, and we learned that lesson in the a SP world. Hmm, Interesting.
25 years ago. That's the a SP World Application Service provider. Yep.
And, uh, in that out of the box complex applications at best can do 80%. Right. You, you always need to fine tune the 20%.
Yeah. And it, here we are 25 years later, hasn't changed Talking the same thing. Yeah.
I mean, even in SaaS, right? Salesforce, Yeah. SaaS is the same thing.
Yeah. Yeah. You think you're just gonna log in and you're good to go.
Right? What do you think all those Salesforce consultants are doing? But you know, all, you know, all that aside, Brian Rocky Linux has made a name for itself as a secure, a hardened colonel, if you will, a hardened, uh, Linux os.
Um, and in today's world, you know, where the attack surface is multiplying, you know, every day with ai and now all of that, that, that it brings, uh, what a, what a good type to have a hardening, you know, a really hardened OS here and a, and a and a, not only just the OS itself, but the, the package is the whole process around it that you can, you know, have something you trust in. 6 came out Yes. Within a couple days, it found 600 vulnerabilities in open exist Code that existed for decades.
Right. Some existed for decades. Yes.
If that's not enough to scare your pants off what is Right. Right. I mean, it's enough to keep you up at night and, and just I imagine that makes a good, you know, it's a good reason to take a look at Rocky.
Yeah. Yeah. Well, and you know, to, to tell you a bit our, about our relationship to Rocky, to, to set the stages.
So, um, Rocky is downstream of RL it is. Right? Uh, free and open source run by, uh, the Rocky Enterprise Software Foundation.
Yes. Or, or RESF. And, um, what that does is that gives sort of enterprise Linux, um, stability and base security that people can access for free.
Right. Replace the Cintas. Um, now what what we found is that, um, still to take that and harden it, and for many people, harden means compliant.
It means, I, I can figure se Linux, I, um, I run some OpenSCAP, uh, playbooks like disa, STIG or, uh, or NIST 800 dash 1 71 acronym soup. Right. To kind of harden my system to be compliant and pass audits.
Right. Um, so we did realize that people need help with that. 'cause that in itself Yes.
Is important and takes a lot of time. Right. But as you said, Alan, um, I think the statistic is, uh, uh, most, uh, software applications use something like 200 open source components.
Um, there are roughly, uh, estimates of, uh, you know, in the area of 40 new, um, um, vulnerabilities be being discovered across the whole open source ecosystem every day. Um, and the time to remediate those takes anywhere from 47 days to a hundred plus days. In some cases, like for some of our FRO entities, you never patch or remediate this.
Right. So now we enter the discussion of proactive hardening, right. We take Rocky, we give you your compliance checkbox, but, but your Claude Opus story is a perfect example.
There are CVS that haven't been, that will be CVEs, that have not been identified or, or exposed yet. How do you protect yourself against those? Right.
And that is it right there, right. In a world where, you know, there's a clawed opus every day. Right.
Or someone's, and, and it's not just the good guys that are gonna use it, you know, thank God it's the good guys that found these 600 vulnerabilities, but the bad guys are using it too. Yeah. Well, and they'd be better.
Yeah. 3 codex yet, but I was just reading news that OpenAI is, uh, uh, safety Commission in California, I believe it is, feels they may be in violation of AI safety laws because they're the first ones to publicly release a model that has a high level risk because it is good enough that it can be easily used by bad actors to exploit systems. Right.
So, on that note, I just saw a flash come across my screen earlier that Anthropic announced something about that anthro, that Claude can be used for heinous crimes or something to that nature. Right. Which sounds similar to what you are talking about.
Yeah. Yeah. And, um, look, they probably all can Brian, I mean, you know, this is, but when did people ever stop for security?
It's full speed ahead here and the security's we're gonna have to play catch up as we always do. Yeah. And I think, you know, what you highlight, um, and I'm just preparing a couple of, uh, sort of things, numbers, the numbers I wanna cite, but you highlight a key thing about, um, uh, what is sweeping over technology, especially in this ai, right?
Is the technology sector in the technology space at this point is dictated by speed, who can move the fastest, right? But what we are not necessarily doing and have not figured out is, um, how can we move faster in identifying security threats, protecting ourselves against those, um, um, so we can stay ahead of the bad guys, right? So how do we balance this fact that we have this wide attack surface, the attack rate is increasing at astounding rates.
We're being told we need to ship yesterday, so we don't have the privilege to sit down and butt down all of the hatches. Well, you know what we believe, um, uh, what you need to do is you need to practice what we call proactive hardening. We no longer can, um, deploy a system and then sit and wait for alerts to bomb us and tell us that there's a potential risk.
Go out, evaluate that risk, analyze where it lives across our infrastructure, and then stop everything to go patch it. Right? Um, what we need to be able to do is know that when we install this foundational piece of our infrastructure, that thing that lays beneath, beneath, um, um, our hardware, our compute, and the rest of our workloads, we need some level of assurance or protection that if somebody gets in, they're going to be stopped.
And so that's what we're building with Rocky Linux, uh, from CIQ hard, this could have been a, um, a honestly say a Al and us having known us each other for a while, uh, I think this is gonna turn out to be one of my prouder moments of my career being able to be part of the team that delivered this, You know, what, we're gonna come back to this day sometime in the future, hopefully. Yes. Brian.
And you'll say, Hey, I told you I did. I would and I did. Right?
So I, I hope that happens. You know what, we're, we're running a little low on time, but for people who wanna get more information about CIQ maybe even information about Rocky, I realize, you know, it's different. But where, where, where can we send people to get smarter, Brian?
com. Um, and, uh, and, uh, you know, everybody go take a look at our resources and blogs in particular around some key vulnerabilities and how they're mitigated. Uh, if you're interested in rocking Linux from CIQ hardened and ensuring that you are protected against unknown vulnerabilities in zero days, um, or you just need to become compliant, um, uh, reach out, hit the contact us, uh, and, and let's have a conversation.
I, I do, Alan, before I get the hook, I, I want to call out as an example here. There's a number of vulnerabilities. One that recently in 2025, I think it hit around, uh, April, may of last year was publicly disclosed as something called BPF Door.
And many of us in the sector probably heard about the SK Telecom brief breach. Um, there was a vulnerability that lived in SK telecom's systems for five years, undetected, where that thing lived and stayed. Resident was in the kernel, and it was able to sort of activate when needed for BPF door, inspect that PA packet traffic, um, and take actions.
Um, we did some investigations, we did some tests. I have 'em running on my system now. And this is a case where if, uh, five years ago SK Telecom had installed the Linux kernel runtime guard that our own solar designer builds into Rocky Linux from CIQ hardened, chances are they never would've been affected by, uh, BPF Door.
And, and just to drive home the importance of that, not only was a bunch of personally identifiable information compromised, um, estimates for what that cost was for Estee Telecom are somewhere between $610 million and close to $900 million, um, just for that single breach alone. So, So there's value here. Agreed.
Agreed. Brian, Hey, man, it's great to have you back on here. Come back and visit us again soon.
Keep us posted, okay? Okay. Thank you, Alan.
It was great to see you again. Great to see you. Brian Dawson, director of Product Management Linux at CIQ talking about you.
If you're looking for real hard and systems, especially hard and Rocky Linux System, CIQ is a good place to go, check it out. com. Brian, we'll see you soon.
That's it for Techstrong tv. We'll be back with more in a minute.