Techstrong TV – August 1, 2022
Catch discussions on Security for the Atomized Network, interactive application security testing, chaos tests and more on today’s episode of Techstrong TV.
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, Cybersecurity, Cloud-Native, Containers and deep-dives into specific technologies and best practices.
You can watch the free live stream on the web, or on YouTube at DevOpsTV Channel, Facebook Live, Linkedin Live, Twitter or on Roku, Apple TV and Amazon Fire TV via the DevOps.com TV app. Also on Android and iOS devices via the DevOps.com mobile app.
Transcript
Hello everyone and welcome to techstrong TV. Today is Monday August 1st, and I'm your host Nathan Solomon. Today we kick off an action packed a month of content and in this episode, we'll bring you some incredible interviews.
So be sure to stay tuned. I'll start by bringing you the text strong news recap to catch you up on the biggest Tech headlines. then Alan sits down with Martin Roche.
Who's the CEO of natography in this interview? Alan and Martin talk about how natography is the only company that delivers security for the atomized network and they're also talk over the intricacies of the atomized network. Next Allen meets with Lenny zeltzer Lenny's the Sea seeso of axonius and in this interview him and Allen discuss the scale of the risk companies are inheriting with acquisition and he offers advice on what companies going through m&a can do to protect themselves.
Well, then bring you to kubecon Cloud nativecon where Alan meets with the filled CTO of harness Nick Durkin in this interview, Alan and Nick just discussed the acquisition of chaos native and litmus chaos, which is an open source, chaos engineering platform that enables teams to identify vulnerabilities through Controlled Chaos tests. Next we turn to RSA where Alan talked with Larry mashironi the devsecops transformation architect at contrast Security in this interview, Alan and Larry go over contrast app security platform, which uses interactive application security testing. Also at RSA Charlene interviewed Rami SAS about the rebranding of white source to men.
So be sure to check that out. Next we have our very own Cody Brown who will come on to tell us about some upcoming webinars on the schedule. Afterwards Mitch meets with Rick Spencer at kubecon Cloud nativecon.
Rick is the VP of product that influx data and the two discussed down sampling and influx DB Cloud a fast serverless real-time monitoring platform. To round out the show. We have a two-piece of view of the art.
In the first Mike meets with Vadim lubashevsky a principal research scientist at IBM in this interview Vadim explains why organizations need to swap out encryption schemes today for quantum computers arrive tomorrow? And the second Mike meets with the German Bartow VP and general manager of it asset management for service. Now jeremon dives into why the team is finally come to converge with the management of it as we have coming up for you here on Textron TV.
Let's get the show started. Enjoy. com is the number one online destination for devops education and Community Building.
com covers all aspects of devops including devops best practices and tools devops culture devsecops business impact continuous testing continuous delivery and more. com where the world meets devops. Hi again, everyone.
Today's Monday August 1st and here the headlines. First the news the House of Representatives approved to 280 billion dollar package to boost the semiconductor conductor industry and Aid scientific research. The bill will work to create more high-tech jobs in the US countering China.
It also provides more than 52 billion dollars in Grants and other benefits for the semiconductor industry as well as a 25% tax credit for companies that invest in American ship plans. Congressional budget office predicted that the bill would increase deficits by 79 billion dollars over the next decade. Next the US Navy is moving towards the use of waterborne drones drone ships as an affordable way to grow their Fleet.
Navy struggling to keep up pace with both Russia and China a disparity that has continued to grow in recent years. It is looking to AI to create a resilient networked Fleet. These drone ships can provide greater weapons range scouting and improved command and control with lower costs.
Drone ships have already been deployed in the Middle East. Top Navy officers say that AI is the potential to make fleets much more effective and the Navy plants to deploy 100 of these crude vessels by next year. In other news Russia has find WhatsApp and Snapchat for failing to store Russian users data on local servers.
The regulation comes as part of Russian government efforts to control online activity. All those Snapchats find was only one million Rubles. What's up got slapped with an 18 million Ruble fine or 300,000 US dollars.
For years, the Russian government has been trying to increase its control over the media and what sort of information makes its way into the country. Considering the ongoing conflict with Ukraine. These efforts have been Amplified.
The court said it was Finding WhatsApp for repeatedly refusing to localize data of Russian users. This definitely isn't the first instance though as WhatsApp is fine four million rubles in August 2021. Next medipot forms says it will no longer pay us news organizations to have their material appear in Facebook's news tab ending a partnership that began in 2019.
The news tab displayed headlines from The Wall Street Journal The Washington Post BuzzFeed news Business Insider NBC USA Today the Los Angeles Times and more. Although meta didn't disclose how much it was paying for the privilege report suggests somewhere in the Millions for the larger Outlets alone. In a statement released by meta the company said a lot has changed since the deal was originally signed three years ago.
This may hint towards an economic downturn that has seen meta post the first Revenue decline in its history. Although Facebook news will change in the US it will continue in other countries like the UK France, Germany and Australia. Another tech company making headlines is Shopify as it announced it will lay off 10% of its staff.
The move comes after it made the wrong decision on how long online shopping would continue to rise in the wake of the pandemic throughout covid-19 online shopping saw surges that boosted companies like Shopify, but the Boost has since come back to earth. The layoffs spend divisions including recruiting support and sales and we'll take effect by the end of Tuesday. According to CEO to Toby Luke Kay.
This is huge news a Shopify reported having about 10,000 employees as of the end of 2021. During the pandemic Shopify expanded rapidly betting that the e-commerce shift would be here to stay However as much of the tech World continues on a downward trajectory Shopify is suffering the consequences. com.
We have an article discussing how the great resignation is affecting open source Developers. Many organizations whose foundational software applications run on open source need developers who are more and more looking towards jobs elsewhere. From the 2022 EDB Open Source Talent survey developers say that increased workloads mentorship options and career advancement opportunities are reasons developers are open to changing jobs.
Organizations that want to retain developers will need to support these needs. On Security Boulevard, we have an article questioning if proof of concepts are helping cybercriminals. Throughout the article connections are drawn between proof of concept disclosures and spikes in dwell time, which show how the two may be linked.
That also talks about how initial access Brokers are closely monitoring pocs and then selling information to cybercriminals Dangerously granting the access to learn more. Be sure to check out Security Boulevard. Finally on container Journal we discuss why you should use kubernetes to secure your data with data loss and ransomware being some of the biggest threats to data security organizations need security measures in place and kubernetes is a great tool to help.
com covers all aspects of cybersecurity including data security deaf secops Cloud Security application security network security threats and more. com to learn more. com home of security bloggers Network me from my devops crowd or not security people and not familiar with with Martin Martin basically invented the IDS open source idea snort that's in no RT.
I think you Martin we still working at the government at that point for the US government or is this after? Yeah, I was I was a contractor at the time and yeah, my day job was doing stuff on government contracts. Yep.
and then you know He then founded sourcefire, which was kind of a vehicle built around snort initially, but then it became so much more clam AV was added as the world moved from IDs to PS and then UTM and everything else sorts by a grew along with we didn't even call it cyber security then we called it info sec. security but sourcefire grew with that and eventually was sold to Cisco where Martin stayed through there for a bit, but then you kind of left Cisco and You know, we didn't I didn't hear from you for I didn't see you out on you know on the on the webs as much. And now you've you've come back with the Vengeance here with netography.
I don't hope I didn't embarrass you by any of this. But so Martin first of all welcome and thanks for being here. Second of all tell us about nitrography.
Okay. Well so natography, you know, it's it's interesting. I did come back.
I took some time off post Cisco and you know went out and enjoyed myself for a little bit till the pandemic hit and then you know much like everybody else. I found myself sitting around the house a lot and thinking about what I was gonna do with my time. So I've been advising a number of companies number startups and including natography since about 2019 and the company had gotten to a point where they were ready to really start pushing the product out building out go to market and you know Marketing sales operations Finance all the other stuff and the co-founder CEO Company Barrett Lyon asked if I would like to come around the show so whatnotography was doing was a flow based analytics platform that was essentially giving you this this view into what was going on in your Cloud environment as well as in your on-prem environment, but all Under One Roof, so didn't have to do anything fancy to make it work.
In fact, it's the most frictionless network security technology that I've ever seen because it's all sass it's all cloud-based. So there's nothing to deploy no Hardware no software anything like that. So, you know, but but it's it's meditated analysis, you know, I've built my career doing Deepak and inspection.
So there was always kind of this this Great Divide between the metadata guys and the Deepak inspection guys because Deepak inspection is High Fidelity very finicky. You know tuning rules and stuff like that on one hand, but it's very precise. It can be very precise on the other hand.
If you know what you're doing and then on the metadata side you get a much broader view of what's going on in your ability to deploy and follow what's happening is is greatly expanded because it's not a sensory based architecture necessarily it's you know, it can be done in a number of ways. So anyway, I spent a little time coming in high about you know, do I want to cross the divide and go into the metadata side and I asked for the competitive Intel now at the time the company was kind of styling self as a new way of doing ndr Network detection and response which is kind of the the second coming of intrusion detection. I guess you would say and I asked Barrett to give me the competitive Intel that he had on, you know, the other companies that we're doing ndr.
I look through it and I was like, holy cow. Everybody is still doing Deepak and inspection and everybody believe it. Yeah, right.
Everybody's still doing Appliance architectures. Well networks are becoming increasingly encrypted. You know, we saw this all the way back in the source fire days.
And as Cisco it was turning into a problem. So, you know what five years ago. So, you know move forward five years and Deepak an inspection architectures are going to be really problematic especially given how much money you have to spend to deploy them and get clear text packets to them essentially.
So then re-encrypted to send that traffic to destination. Yeah reduce some sort of weird. You got to keep getting bigger and bigger machines at the edge to grab it whether you decrypted that that machine or up in the cloud and send the fact.
Yeah. It's it's well capital for latency, but good. So because you know because once again, I you know, spent 20 years plus building and so that was an issue and then the appliance architectures that they were on was also an issue.
It's like science don't really translate to the cloud World very well at all and Appliance architect. So we've got this life cycle management curation thing that's got to be done. It's just it's really clunky in this world that we're in now, so I was like, you know what this is like there's big opportunity here.
Nobody's on the right architecture except us. So all we have to do is is stay smart and keep you know pushing and we're gonna be well positioned in space. So that was the thing that got me to join and then once I got on board something else happened, I started talking at like customers and Prospects and I started here in the same thing over and over again, you know, since the pandemic we're multi-cloud hybrid Cloud what's on Prem infrastructure still and rubble and remote workforces or hybrid work for us and I I heard it this many times.
I started kind of putting the pieces together and I said, you know, what like up until the pandemic hit like moving to the cloud for most Enterprises was kind of this early transition, right? We had a program. It's like we're gonna decommission the data center in Chicago.
We're gonna move it to the cloud and we're gonna move these applications. So, you know people came up with plans or committees and all this other stuff and then the pandemic hit and it just blew up overnight because everybody got sent home and you have these massive Enterprises with tens of thousands of workers. Everybody is at home.
They got one job right one rule, you know one order from on high which is just get your job done. So, what do they do? They got stand up Cloud infrastructure everywhere across all the major Cloud providers.
But there's nobody. In the buildings to decommission the on-premit infrastructure anymore and you can't stand up new stuff in the on-prem infrastructure either. So what do they do?
They start building dependencies between it all as well, right? So all sudden this this very distributed hybrid multi-cloud architecture gets cemented in place due to these dependencies. And I started hearing this and I was like, it's like your networks of atomized isn't it?
It's like you got Adams of presence Adams of compute that are scattered across all these different Cloud providers and in your on-prem infrastructure and all your atoms of users that are scattered out to the Four Winds where you were home and Starbucks and wherever they happen to be and you know, everybody's head started going up and down. I was like, this is something new there's something new here and what it is. As I kind of like wound back a little bit.
I started thinking about it. Just kind of two classes of vendors out there, right? There's the the hardware guys The Appliance Guys, you know Cisco Palo Alto FireEye checkpoint whatever, you know, and that is kind of the foundations of the security industry and a lot of ways but as they've tried to stay relevant in the cloud, they either acquire Cloud vendors or they roll out Cloud appliances.
Of course, once again Cloud. Nobody loves a cloud Appliance right people want to use the native capabilities of the cloud, right? So, You've got kind of an artsy moron.
Yeah, you texture is he's kind of tortured architectures that results because we're trying to you know, still be an appliance vendor on the one hand. Then you got the pier cloud guys. And that's all they do.
They don't even think about your on-prem infrastructure anymore. So what you end up was you got these massive gaps between all the solutions that are out there, you know, Alex say attackers live in the gas. So by building this very gappy architecture that doesn't integrate very well together and you know, just dump it all in the Splunk and crossing your fingers is really a solution.
It's expensive try though. Right? I mean, you know don't expect a lot of value out of Splunk not saying they know is powerful but that's a tough way to live.
So as I started looking at it and I looked at what photography is had built. I said guys we are security atomized network. That's us because we don't care where you happen to be you can be on-prem or in any of the clouds and it all it's the same to us.
We're met. A platform right? We just operate on metadata and we are pure SAS base.
So like you turn it on you have sample account you put your sources at us and we start telling you what you've got what it's doing. What's happening to it straight up right each one of those buckets those three buckets you you know take the lid off. There's a lot under each one like telling you what you've got in a atomized Enterprise or across an animal's network is actually pretty complicated could be, you know could be a factory floor could be a data center could be a bunch of cloud apps.
So actually the question of what I have and we hear this over and over again, we're blind right we move to the cloud now, we're blind the tools aren't there that we try to use the native tools that the cloud providers give us but really can't tell what's going on. We certainly can't see who's talking to who especially because everybody's built these dependencies between all the stuff that they've got out there like cross Cloud traffic and things like that. So we're we are built for that World by hooker by crook like, you know, it's almost like it's almost like snorting away in that.
The guys who built this Barrett and Dan and the natography engineering team. They built the thing that they thought was right just like I built the thing that I thought was right 20 plus years ago and it happened to me, you know, it was it was the technology for the moment like and you know, here we are 20 something years later stores still very relevant very widely deployed at the core billions of dollars of business. Let's go certainly but this is a new architecture for the world as it is and is going to be not an architecture for the world as it was and what you've got out there and a lot of ways from the major vendors is architectures for the world.
That was so that's you know, that's why I'm super like I get up every day. I know I've got a cool technology platform. It's it's built for the world now and the world that we're going into and there's lots of stuff that we can do here and you know as I think about security for the itemized Network, you know, which is our tagline.
There's more that we can do here, right? So we're a visibility control platform, you know, and kind of the Big sense of you know visibility show me everything that you can show me control. Let me control the things.
I understand I kind of stuff but there's there's more to be done here this This atomized network problem is a problem of the scope of architecture that a company builds to control these atomized networks. And if it's you know Legacy architecture that's trying to be extended to the to the new world or a new world architecture that forgets about the old world. I think there's you know, there's this this middle area where you you contemplate and and can manage both sides of the world.
So anyway, that's that's what we're up to here. Absolutely, you know. Let me put my two cents in on this Marty.
One of the problems historically with security is we're kind of like the French and World War Two. We're always looking to fight the last war. Well, we're looking to fight the next one with the last words technology or tactics.
and you know what it took us as an industry a long time to wrap our heads around cloud. Right because we we had this mountain castle perimeter inline at a band heuristic. I mean you, you know better than anyone.
Right what we were all about and and we we have now we we now see. Cloud Security in its own Light being effective guardrails for developers the shift left the devset cops all of the identity and access control and all all of you know these kinds of things. And just and this is the way life is right just one we're starting to get our heads around this this the pandemic comes that kind of scrambled because we accelerated digital transformation.
We accelerated Cloud migration, but as you said it wasn't really smooth. It's a little lumpy right? We still got some stuff here.
We got some stuff there. We got something. But in my mind, we are also at the same time on a general one of these generational changes of hey, the cloud is the cloud it's not going anywhere the data center.
We decommissioned some of them, but we still have a lot of stuff in data centers. But this do anything from anywhere movement that covid kind of. gave birth to or at least accelerated right has also accelerated this Edge Computing, right and and you got 5G kind of, you know, powering that up and and the edge and and iot connected devices and 10 points anywhere.
So now you know you want to talk about was chaos before it's it's Mega chaos now, right? Yeah, you get another front that when we talk about something like an atomized Network, you gotta you got to kind of normalize all this right? You got to equalize all of them and lay down a security blanket or you know, some sort of insight.
To all of that, right? It can't be a bunch of unique things. Right?
No, you can operate on so, you know, one of the things that we did this is actually a riff on how we did Enterprise section response back in the sourcefire days where we had a cloud-based detection back and that we could you know, update the back end once and our entire deployed footprint of EDR Tech, you know connectors became smart about it. We're doing the same thing here the right wants to detect everywhere kind of architectural backend approach and that means you have to consider everything is being the same right? So that's what we do is we aggregate all the stated together we enrich and be all the stuff and then, you know, we run it through our real time detection models and you know, we see all sorts of interesting stuff.
But the thing is I don't care if you're on Prime, I don't care if you're at Starbucks, I don't care if you're in the cloud in oracles cloud or you know, Amazon's closet. It's it's all the same to us. So and we make it all the same.
We make it look and feel the same so that you know, you can operate on one thing and you know care about encryption. Anymore because you know, we're operating above that level. So, you know, one of the things that you have, you know, so almost like one of these things for you know, the first step to getting better is emitting.
You've got a problem and the first step here is admitting you know, what packets like packet says the coin of the realm for doing network security they're going away and like We've admitted it like internally we talked about we live off the land and live off the land me means packets aren't available anymore living off. The land is the data types that are available, you know and everything speaks flow the clouds speak flow all the infrastructure speaks flow. So that's what our our corner of the Romans and you know, that's going to be you know, if you learn to operate on that that's immune to kind of some of these Mega trends like zero trust encryption of everything.
Yeah. Yeah. Let's talk a little bit about metadata.
if you don't mind right for our audience out here who maybe is not a you know, our audience is pretty diverse. We get devops Cloud native cyber digital transformation that that's kind of the audience. Everyone's heard the term metadata, there's metadata and everything right binaries and so forth but in terms of security How do you turn how do you weaponize metadata and I know me from the bad.
I mean weaponized metadata for the good as a security tool. Well, okay, so there's there's a few ways to go about it. So one of the ways for like people who don't swim in this pool every day, I don't know the ways to think about it is, you know, if you look at intelligence agencies, it's kind of informative and what I mean by that is, you know, we have organizations like the NSA and their job is to crack codes to keep track of who's talking who and things like that.
Well as we all know if you know really studied up on encryption a properly implemented one-time pad system is effectively unbreakable with current technologies that are out there. So Oliver adversaries know that we know this so, you know their levels of encryption that just can't be broken and we've known this since the you know, the 40s and 50s. So one of the things that the US intelligence apparatus does is tracks metadata who's talking to who and how much and how does that change?
What are the behaviors of these operators and these, you know control points and stuff like that. So, you know if we all sudden see headquarters calling red Fleet headqu You know while a an international incident is going on that we know. Oh, okay.
Well, you know, they're they're preparing their Fleet juice something. We don't necessarily know what but let's pay attention to the harbors and see what's going on. This is kind of you know of the same milk.
So we're admitting hey, you know what network traffic's encrypted now, so let's look at who's communicating and how they're communicating and how their behaviors are normal and how they change so it's not just a behavioral system. It's not just a nonline detection system. We can characterize very specific things.
We can look for very specific things. We can also bring contacts to the table as well. So if I know things about a network like, you know, The you know, whatever.
This is. These are the phones the desk phones and everybody's you know, and everybody's desk in the offices. We don't go to anymore.
If I ever see a desk phone talking about PBX like that's a problem and that's that's very deterministic. It's behavioral. I know the behaviors of this thing should be but it's very deterministic search in that.
Hey look never does something. That's not this that's problem. So metadata is all about kind of defining the operational footprint of our organization.
It's behaviors and being able to look for anomalies outside of that and things like that. So it's operating at the next level over kind of the raw data essentially. So anytime you're doing context-driven security any time you're doing behavioral analysis anomaly detection and things like that those all operate off of this this notion of what is the the metadata that I can get about this environment and we did this all the way back into the you know into the old days and the source of our days where we characterize the networks that we're defending with our intrusion detection and prevention.
So we can make the IDS IPS engine smarter about their environments. So they were harder to evade and they gave us more valuable information. You know kind of reminds me that want to bring it up is at 0 point.
But remember the Ron and the tenable would had passive vulnerability scanning. They called it. Yeah, I think Source fire had a similar kind of Technology.
We would just listening and based upon what you were hearing. You were able to make some assumptions that you know would help you. Sharpen up with what's there?
But you know the beautiful thing about the metadata model is The more the more meta data it collects the more accurate and better it becomes. right, and and so You know, it's almost like continuously self-improving if you will getting sharper get learning better. Yeah, yes have these the data sets, you know this kind of confirmatory and disconfirmatory information and being able to model all that out things like that.
So that technology is Source fire that did the passive mapping stuff like that. I build the Prototype of it and then we hired in a team to turn it into a product. And yeah, I understand the problem really well and it's a it's very interesting problem letting the network tell you about itself and then like taking that information and building into models that you operate on is is one of the kind of metadata e things that you do.
Yeah. So let me let me get business here a little bit here organizations people watching this their organizations. Maybe they want to take a look at this.
How is it kind of packaged sold? How did they engage engaging is? Super simple?
You can go to our website and say please give me a demo and you'll be contacted. So it's really simple. We're we strive to make our engagement processes low friction as possible trying this technology out is oh if you have the passwords for your switch router firewall load balancer, whatever your on-prem slow generation technology.
So any piece of network infrastructure basically capable of generating flow, or if you have in any of the major clouds so Azure AWS gcp IBM Oracle, they all generate flow records, too. So you can turn on Flow collection. Upon S3 bucket and point us at that and you're up and running we stand up an account.
You tell us where the flow sources are flow starts coming in you're in business. I mean deployment of this technology can usually be done like initial deployment can be done and getting value from it unless than 30 minutes and we've seen this over and over again. It's crazy fast compared to the Appliance days.
And the other cool thing about it is that you know, if you do deploy it like in Earnest as a deployment, it's subscription base sales. So it's based on number of flows per second. We're going to ingest and how long we're gonna retain the data.
So that's what the pricing model is around. So it's essentially a usage based model, but the really neat thing about it is if you have something if you have a little excess capacity and your subscription and you want to go see something that you currently don't have visibility into say, you know, you're threat hunting with the product which you can do and you see an attack or go some place on your you know, your atomized network that you're not currently monitoring. You just spin it up.
It's not like geez we got A appliance to Buenos Aires and it's going to take a month to get through customs and then we got a fly guy down there and get a commissioned and plugged into the Matrix and stuff like that. It's not like that at all but our stuff you want to see buenoseries. Turn it on.
That's it. It's been literally minutes. It's very it's one of the things that gets me the most excited about it because it's like you can like in the appliance days.
You can follow anything if you were set up for something you're done. I'm just there. Yeah, we can follow the attackers and it's really it's really cool and Powerful it.
Let's do things that we never even thought about doing in the past and also the right wants to detect everywhere back and you know, if you figure out something you're interested in you just deploy it and your entire infrastructure. It's not like you deploying into a management platform and schedule a deploy out to your sensing infrastructure and it takes yeah hours or days to get it all out there. It's like update once boom everything smart now, so it's it's really cool.
But we're we're super easy to work with you know, we've got A great team here very experienced team and a lot of familiar names and faces on that team exactly. Yeah, you know a lot of people there and yeah, if you click give me a demo on the website, somebody will contact you we can do a demo for you. We can actually the demos so we usually if you have the username and password for something generating flow that you can stand up we can actually stand up and account for you and get you on board so you can see the product with your own data and a one hour demo.
Fantastic, man. Hey Marty, it's great. It's great.
It's great having you back first of all, but it's also a great having you here on Tech strong. Just one last thing people watching this, you know, black cats coming up in probably another week or two from when you're seeing this. I know you guys are at blackhat doing meetings.
And I guess demos or whatever. So if you if you are going to Black Cat and you want to check out nitrography, I suggest you go over there tonight. I think you can request a meeting or meeting, you know and in person as well.
Yeah. Absolutely. We're also having a cocktail party on Wednesday night.
So if you go to our booth or if you click on our website, you can sign up for the party. fantastic Martin Look, this is the first time you're on since netography. Don't be a stranger come back and keep us posted.
Okay? Absolutely. Love to Allen you yeah, I really appreciate that.
It's good talking great having you on man Martin roach CEO nitrography masters of the atomized network and metadata. com. We're gonna take a break and we'll be right back here on Tech strong TV.
This is texturung TV. Hey everyone, welcome to another text on TV interview. My guests for this interview is my friend Lenny's outside.
He's the ciso at exonius and Lenny. Welcome to techstruck TV. Hi, it's good to be here.
Yes, it's good to speak with you again. We haven't spoken in a while. First of all.
I hope all is well with you and your world. Lenny not everyone's gonna be I I know you in this from the security world for a long time, but not everyone out here does and every and not everyone obviously is gonna be familiar with the company so you don't mind land I'm gonna ask you to kick things off with a little bit of maybe your background and exonius. Yeah.
Sure. Well, I'm a security professional. I've been a security professional now for more than two decades and over this time.
I've enjoyed taking on different roles. So as long as it's related to security, I'm probably into it and so for a long time, I was working as a consultant for some time. I was building and managing security products and security services.
And now I'm leading a security program that exsonius and for me, it's very exciting because I started with a company when we were just very very young. And so I am very happy that I get a chance to really formalize a program and then see it mature over time and there's always room for imp Moment and evolution as the company grows. So we're a growing tech company that creates solutions that help customers address their asset management needs in the world of cybersecurity.
And so I joined exonius and gosh, Over three years ago because I was excited about the challenge of really finding a way to oversee manage. It related Assets in a way that works for Security Professionals. And so I think about Asset Management a lot, but my focus is our own security program.
And how do we build it in a way that protects our own assets our customers data and how do we earn our customers Trust? Absolutely and very fair and look you've been in security to decades. I think I know you almost that long through lending, so You know, we've been there done that been there long for the ride with you Lenny for before before we jump into today's topic.
You mentioned the company but website. So for people maybe who want to go check out and take a deeper dive. com.
Yeah you Google cybersecurity Asset Management. You can probably find it quite easily. So I'm not gonna hold you feet to the fire because you spell it for us.
com actually good stuff. All right. So Lenny what we wanted to talk today is it's kind of a soft white underbelly of m&a.
Right and you know there's so much m&a activity going on well. between the kind of go go easy money of of the covid times and now as we seem to hit this You know read Readjustment if we want to call it that as money tightens up inflation and so forth. M&a is still going strong in the previous arrows because money was plentiful.
It seemed in this era. It seems that money's not so plentiful. But both of them both of those reasons are driving m&a Activity.
One of the things that I mean, they activities, you know, it's all it's all fine and dandy when you you know, signing contracts and exchanging checks. but at some point that's over and you got to get down to business and some poor SOB, you know in the security team is handed a portfolio and says, okay, you know go make sure they're secure or let's let's merge and integrate. Technologies here and security being part of it.
Tell us a little bit about kind of your take on this. Well companies have been merging business operations acquiring each other since the beginning of time. In fact nowadays, certainly the world of tech a lot of larger more established organizations see a way of acquiring younger companies as a way of well in a way maintaining their Innovative Street as you grow big it's hard and hard to be really cutting edge Innovative.
And that's what Young companies really good at. So that's one of the reasons why typically larger more established entities acquire smaller organizations in the world of tech. And in most cases not all of them.
Security leaders are a part of the due diligence conversations not always different cultures different styles different scenarios. Sometimes these mergers and Acquisitions happen in a very secretive way. But hopefully a security leader is involved at least in the initial due diligence at a high level.
Yeah, you're trying to get a sense like how much sure is the company security program. How does it stack up to what our program is like and in this case? Probably the security leader would be asking similar questions.
That one would now days ask of a third party vendor. Yeah. Tell us you have a third party auditory viewing your security program.
What Frameworks do you follow what have been your recent security achievements or any security risks that we should know about that's initial digits. Then at some point the US closed now, it's signed now that your companies are coming together. professional to worry I Think that's what we do.
Yeah, we worry we're really good at thinking all the ways about all the ways in which things can go wrong and we think about risks and so initially that's what's on my mind. The two companies are coming together. If I am a part of the acquiring entity, I worry what did we just get in terms of risk?
Does this strengthen or weaken my security program? Could require identity already be breached and now all of a sudden I'm dealing with an unexpected incident. So that's one way in which Security Professionals are thinking about the situation.
What can go wrong. What are the big risks? But what I wanted to point out Alan, is that what I'm Training myself to do is to have another perspective on any transaction and that is how can I as a security professional enable?
Business objectives. The reason why that m&a transaction happened is because the companies had high hopes for doing something good together. They decided that they'll be better together than a part.
What are those business objectives and how can I and my team better support them to enable business? That's a very different mindset and one that I think we should bring to the table together with and more worrying risk focused mindset. I agree with you 100% And and look let me first of all say that.
I I've been involved in more than several m&a deals over the last 25 plus years. and we probably do more pre-closing security due diligence now than we did. Years ago, right we and I think unfortunately or unfortunately I think compliance.
Is a driver of that right? If you're buying recently Amazon, right, but you think in the last couple days announced a large behind the medical field a healthcare provider. I mean, obviously you if you're gonna make a Buy in the healthcare field today, you've got to be worried about HIPAA personally identifiable information.
So I would imagine that that is part of that due diligence. But and so and that I Bravo right? I'm happy with that.
It's risen there. But that level of due diligence is is you know, 50,000 feet due diligence on that's right times. It's not.
Okay. Now we're integrating and what system are you using? Does it work with the system.
I'm at that I use which system should we use going forward should we use? Especially some companies they do m&a rather regularly, right? You can't have 12 differences or can you?
Right. How do you normalize that? Well, certainly coming into the situation as a security leader.
It begins with understanding the situation. Yeah, and as you suggested we need to understand. What technologies are being used in the new company?
How do they compare to what we're using right now? But before we even go there to be able to write the right to ask the right questions about the Technologies first, let's understand what our first of all they compliance and legal obligations that we now need to follow if our company has never dealt with Healthcare and all of a sudden we're acquired an organization that is in the business of healthcare. You know, what the security team will need to work very closely with legal probably to understand.
So what do we need to do now that perhaps we weren't doing before what are the new perhaps unexpected requirements of the security program. Then we need to understand even before we talk Tech. What are the business objectives for the organization and alluded to this earlier?
Why are we coming together? Is it because let's say now. We have a brand new product line and that helps us gain access to particular vertical Market or is it that we're acquiring this company because want to get access to a new geography where we didn't have physical presence, right?
There's so many reasons why these m&a transactions happen. We need to understand this because technology that will ultimately talk about drives these business objectives. So why are we doing this?
For example, if the company's goal is product diversification and it will expect to maintain different non-integrated product lines. That means that probably the acquired entity will want to keep some of its technology. Because it's expected to operate would say independently in contrast if the goal is let's say many companies are required because of us who we call it aquifier, right?
We're just acquiring the company not because of their customers not because of their Tech we just want the people but in that case probably you want to migrate to the acquiring entities text that right away. So you understand the context from a legal regulatory perspective you understand the business objectives. And then you as a security and Technology leader can think about what do we do about the tech?
And to answer this question first of all get the lay of the land. What are the key Technologies being used by the acquired company? What are the it assets that they have?
What is the their use of cloud infrastructure how Reliant are they on SAS applications to have things on Prem off-brand? What are the employee desktops and laptops look like right you start Gathering these background details. That's your foundation for them making decisions regarding what technology to keep how to migrate and when to merge if at all the security and it operations a great, you know Lenny back in the com days, right?
I helped a good I sold my company to another company. It was a roll-up and we I helped that company go public we did about 30 Acquisitions and 36 months a lot. Almost one a month.
And the rule of thumb we followed there was when we bought a company. acquired a company we didn't do anything. with the technology or oftentimes even the people For six months or so, right?
You don't go in day one and start saying use this don't use that, you know and making wholesale changes. It's kind of let him do what they want. in the world if security you really you if something is a Miss something's not up to standards.
You can't afford to wait six months. Right. And and so how do you you know, when when when is it too early, right?
You know, when is it too early to go in after the acquisition? It's okay. We got to start we got to start doing this now.
Hey, yeah, no you bring up a good point that there's a sense of urgency about some security activities that maybe is not there when it comes to other aspects of the acquisition for example, in many cases. And the reasons why you tend to leave the acquired company alone initially is because look it Beyond what's on paper and on the contracts. It's people right there there groups of people that somehow now need to work together when previously they didn't do that and that means you're dealing with the messy things like culture and Communications and expectations and you don't want people Employees leaving in Mass.
You you want you don't want them losing productivity, but when it comes to security the big question is Did I just acquire a company that is so poorly managed or perhaps is so weak security wise that when they have an incident now, they're acquired entity exposes the acquiring entity to unexpected risk brand tarnishing or regulatory fines or other Financial repercussions of a data breach. So that's why I agree that initially. Very quickly.
You need to get an understanding of what did we get? What is the set of infrastructure components that they acquired entity brings to the table? Where does the data reside how is it used?
How does it flow? And where might we have the weak points that could be compromised or maybe already compromised that once you understand this then you oftentimes embark on a project to see. Are they already compromised?
Yeah, you perhaps do some threat hunting you understand if there's already an incident happening and maybe you don't know yet because that you need to address right away. So the security professional you need to balance the need to understand the level of the land and your risk right away because if there's a reach need to deal with it right away, but also you need to think longer term. These are people with whom you'll be working together.
There's some business objectives that require collaboration and therefore you need to understand right? How do we work together? For example, how do we not alienate the ATM security team of the acquired entity because you know, what if they don't like something in this market they can probably find a job elsewhere but quickly.
So how do you make sure that they feel valued and if you're starting to poke your nose into their business, let's you let's purposely frame it in a way that sounds on Pleasant because that's how they might see it. You come into their organization, you're questioning their decisions. You're implying that they are perhaps Not good at their job.
If you're saying I want to know if you've already been compromised. So there's a human aspect to these interactions and I think for this to be successful you need to interact with them by explaining. Yes.
This is why we're doing this right now and it's urgent. But let's do it in a way that allows us to be more successful together because they security team of the acquired entity that needs to be happy with where they're going in the longer term just as much as the security team of the acquiring entity. Absolutely.
Look, I think we can follow a lot of this under. Don't forget this human beings involved here, right? It's not just some.
Corporate entity dealing with some corporate entity and a bunch of different technologies that were like, you know. Folding cards mixing cards up this there's people here and and this feelings and there's you know, there's human Humanity of it. The human aspect of it is something I think we need to to really look at buddy.
These interviews are 15 minutes. We're already over 15 minutes. But you know, I want to thank you for for you know, helping us shine a spotlight here.
We have to jump onto our next interview. com, but don't ask me to spell it. com folks.
This is Alex chevora techstroke TV will talk soon. Looking for a live conference focused on the tools Technologies and practices most important to your business inotech conferences are live one day Business and Technology conferences highlighting the latest and trends for it leaders developers and it professionals each event combines education Innovation peer-to-peer networking and the latest technology and business solutions for a diverse. It focused audience in a tech conferences occurred throughout the year in strategic Regional locations bringing together technology professionals from various Industries to learn about the solutions practices and tools impacting their day-to-day work and gain insight into what's to come presenters at enotech conferences are selected and curated to ensure each session provides the most up-to-date and relevant information without any hype whether you're interested in digital transformation cyber security Cloud it leadership or devops in a tech.
Differences deliver 2022 events are scheduled to be held in Austin Dallas, Oklahoma City, Houston and Washington, DC. In a tech conferences are produced by Tech strong live and powered by Textron group. This is digital anarchist.
Hey, good morning. We're back here day two for cubecon Club nativecon in beautiful Valencia Spain. This is Tech strong TV and welcome.
io. So we got the website URL right out of the way there Nick. And you know Nick I actually saw Nick for two days here already at Valencia.
We've got a chance to catch up but we're gonna do a little interview now as usual harness has more than a few things going on, right if they walk first off Alan. Thank you so much for having us on the show right pleasure. Genuinely appreciate it.
Always fun. Yeah. I know, you know these days and we we like our harness rights so Nick I I guess the big news for harness here is the recent acquisition of and I you know, I know it's a chaos company, but it's lit.
Okay. Let's open today. Yes, it's the cncf project.
So it's an inhibiting projects is our first for any of the cncf. Yeah, of course, we got into the open source with drone position a little bit. I remember most loved open source CI tool absolutely love it, but first for into the cncf, so we grabbed chaos native the founders of litmus chaos and ultimately phenomenal addition to the entire portfolio.
Absolutely and let's I want to jump into the whole cncf thing with you. But before we do, I just want to give people kind of sense of History here, right? So let Miss chaos, you mentioned drone harness is done a few other Acquisitions.
Absolutely, you know over the last let's say two years, right? We've grown a ton. So we started a CD continuous delivery as a service was where we started and our customers loved the security to auditability the compliance using machine learning and AI to think like your engineers and we thought that CI was solved we thought that feature flag was solved all these software delivery portions were solved.
We thought that was the only issue and a customer said can we have that same functionality across our entire software deliver stock? And so we're very different because we started in the middle and now we started to pull the branch out grab drone most loved open source CI tool we built our own feature flagging tool to have be part of pipelines and actually have control over with governance, but then we acquired over Ops which was you know, giving you source code stack Trace variable state. So that's part of our service reliability management tool really designer on the SRE air budgets and slos and potentially even slowing down your deployments.
We grab zero North and that became our security test orchestration. Yep. So now making sure that bringing that information developers when they when they can actually use it so not getting the results of your Tests two weeks later right getting them as I'm building my artifactor knowing that I introduced to cve.
And then of course we brought out a cloud cost management really bringing that again to the engineer. So making sure that they're making the right decisions because you're giving them the information for the first time. You're actually zero North acquisition.
Absolutely. Yeah. I I always like the zero North actually their whole product my good people good product good stuff there.
So Nick, let's talk though a little bit about you know, I I called this the foundational error of Open Source where you know, we've seen sort of the cathedral in the bazaar where no one owned open source. No one Managed IT. Yep.
It was a bizarre then we had big brother open source. Swear, like, you know, IBM controlled an open source project and it was really for their sole benefit. Then we have cncf or foundational open source, swear an organization like LF like Lennox Foundation like cncf, they actually managed.
They actually owned the project if you will they own the IP the trade bar. Yeah. It's truly given to them.
Yeah, it's there. They're the stewards and owners of it. However, You still have companies that I forgot who it was we interviewed yesterday come a project.
They started they donated in this case. You guys kind of bought a project that was already. Yeah castnet have donated litmus chaos.
And so we acquired Castle right you inherited sort of that, but that relationship of a Of the company that initiated the project and donated it to the cncf. It's it's almost I mean, it's almost like you put your baby up for adoption, but you still have visitation right? That's right.
That's okay. You don't guide the ship in Thailand anymore. No, you truly give it to the community.
What was nice though? We were over there. We were with the captain folks or with the litmus folks and we took a picture because it's bringing people together across and well, you have that Cooperative tissue where people it may have been yours once but it's not they're solely for your benefit.
And when I say you're company you initiated the the project and and so people are you know can feel confident enjoying in the community and making it better for all while at the same time what you'll often find with these, you know projects that we're donated by an entity is that the maintainers the people who contributing the code are still you know, good chunk in them is still employed by the organization that donated correct? Yeah, and I think See that with most of those projects. Yeah, but it works.
I mean it works much better than than the old way. That's for sure 100% It's truly Community Driven and this is one of the benefits is that you actually get to build with the community wants. Yeah as opposed to building what you assume is, correct.
We've always said yeah, you're building a community versus a community of want to be customers, right? Yeah, I'm over at the Westin here in Valencia. I happen to be sending out yesterday as people do here in the air was the day before us we will do yesterday in the afternoon having you know, the Serrano I bury ahead and addressed and I was listening to a company and not mention names.
But David an open source project not cncf and they were sitting and talking about their website and it was all about conversions. Converting not used not people to use them software to converting users of the software to pay people and I bet my time because I didn't wasn't my business right but I wanted to go over so you guys got it wrong. If you really build good software, they'll convert themselves because what you provide to them is what they're looking for and the intention here is the truly build a community.
Yeah. And so I mean we've we've taken it on full force. If you look where we were two years ago.
We didn't have open source. No, we didn't have anything Source available. No, and now the entire project so everything's either Source available and full open source, love it and we're contributing more and more to the cncf and we want to be phenomenal stewards and we proved that over the last two years with drone.
Yep, which is why there's a massive Community that's following us and willing to actually come and be part of this we want to be good stewards. Well when you're working with, you know, in this cncf sort of family if you will use that term loosely, you know. You get that?
Let me ask you another question though check and that is so now you have all these disparate pieces. Right? As you said you started in the center, you're going out to the edges not that edge, but should you see this coming together in like a platform type of play for harness?
Yeah, and that's truly what we're building. So we're building a platform, but we're doing it differently so each module. Is designed to operate by itself independent independently, if however you want to use multiple of these together.
The intention would be that one plus one equals 3, you want to gain massive benefit and this this all came from our customers. We're not an if you build it, they will come company, right? They want the same R back.
They want the same governance. They want the same reporting they want to say so this is where the platform is a massive benefit and that's with all of our modules. So do you see a single UI maybe or so this is where you know, if you look at the developer experience, which is one of the largest problems people have right now is because they have to go to seven different tools to get the information to do that.
That's what I'm kind of it. And that's and our thing is look we're not going to be an APM tool. I'm not gonna be a security scanning tool but I want to use all those inputs and make them available to the people when they're valuable.
Go to that point. Yes. I want to be that place.
It is the one location where you can get all of your information from code commit all with you to production, right and beyond that even for that matter to customer it's not just about getting into product. It's about making it good and pride looking. And all those metrics understanding what it's you know, how it should be and so that's really our whole point is that visibility and informing people if you give people the right information, they'll make the right decisions.
You never give them cost information. They're not going to make decisions based on costs. So bringing that to them and I think with litmus that's our whole point is it used to be at the SRE level way down, you know in production now, we're pulling Network chords and we're doing our experiments.
Why not bring that and allow Engineers to build resiliency to what they've actually created sure do it now as opposed to when it makes its way in the production and so really empowering it again shift left and interesting one a lot of people use the term and I think just like devops and just like cicd. There's a many variations of it. I don't see it as a burdening developers.
I see genuinely as empowering them and giving them the information when it's valuable. So we spoke a little bit off camera about this out shift left thing and you're right. You know what?
I've been in technology long enough. Any time you have a successful term, everybody wants to embrace and extend it. Yes to use Microsoft 90 speed and people have embraced and extended shift left certainly.
And I think you said it when we were off camera, which is it's not about putting more tasks on the developers plate. It's about giving the Developers. Information at their fingertips that will allow them to have the context contact content information, right?
Develop better faster and at the end of the day, that's kind of what makes them happy. Yeah, right better faster. I think every one of us we want all the information to do our job the best.
Yep, and we make the best decisions based on what we're given and that doesn't mean I need every no security and piece of information all the time. But when I when I do need it I needed at my that can call. I don't need it two weeks later after I've already built it I've changed contacts just like Comcast.
I don't need it 30 days later from the CEO. I need it now exactly because otherwise well the other way Nick is job security because all you doing you always reiterating based upon what you've done in the past. Yeah, but efficiency.
I mean no such thing much more efficient. I mean, no doubt about it. Let's turn down to the show.
So I don't know. I've heard estimates of up to 8,000 people here in Val. You which would kind of I think give it more than the last show.
We did in Europe for San chapos. Barcelona Barcelona. Yeah, and I think that was about six or seven if I'm not mistaken.
We've been pleasantly surprised. I mean, I was genuinely if you compare it to where we were at the last say coupon. Oh la very different.
Yeah, very different and oh, yeah, and it's been true interest the people that are here. And and so it's been a phenomenal show for us and we've talked even all of our other vendors and all the partners. Everyone's having a fun.
No, I so I I think one of the things that I've observed and it's hard because I'm you're doing these all day. Yeah is that this is cloud native Europe This is awful lot of folks from North America who've flown over not everyone. Here's European, correct?
I haven't seen as many folks from Asia and I think it's obvious reason. Yes. Yep, but certainly I I think this is a bit of a coming out party for the whole Community both in North America and Europe.
And you know, let's hope it continues like this. We're trying to get back to normal right events have always been a great way to meet people events have been always a great way to actually interact and understand. I think there's something about the humanity of it too.
It's different when you're a person standing next to each other versus being able to do it behind the shadow of a screen. No doubt about it. You can have you conversation.
Yeah. Yeah. You don't have to tell me I live it.
Anyway, man. Hey, I want to thank you for coming on genuinely. Thank you.
That's the luck with harness. I'm sure we'll be hearing more. Yes.
Yes more to come as good near future. But until then I think we're gonna just break right now here in Valencia. We have another guest coming up.
The moment. So enjoy if you're not here you can there is a virtual event, you know analog to this event. You can log into.
If not just stick around with us. We'll try to bring you as much news as we can. Take care.
This is Textron TV. Hey everyone. We're back here live from RSA conference.
We're in Moscone West on broadcast. Alley been here all well. We've been here all week and we'll be here through Thursday last day of the show.
I'm really happy to be joined by a good friend of mine this guy. Well first let me introduce you Larry might not Sharoni match your own matcheroni mashironi, but I don't I I don't get sensitive about I know but anyway my friend Larry here. you know if you want to know about devsecops, he's one of the probably Top five people that I would recommend you to I first met Larry he you know, we do our devset cops thing every year for the last seven years.
So I think Larry's presented in five of them, maybe more. He was a Comcast where he ran their devs said cops program. He's recently moved over to our friends in contrast security.
And doing a great job there. He's gonna tell us a little bit about contrast. But really if you get a chance Google him look up any.
Presentations he's done. He did a great one yesterday and our deaf said cops event. It'll be available online probably within about a month and our virtual.
What's the right word the virtual second half of yesterday's event, but I don't mean to embarrass him. But anyway, Larry mesharoni contrast security. Hey, Larry, welcome Alan.
Thank you. It's always a pleasure to be here with you. Absolutely man.
So I don't know if we're gonna have a lot of time to talk defsecops today in for you know, depending on what aspect but you got a lot to talk about contrast we do we do and you conscious security is a name, you know, our audience is familiar, right? We've had Jeff Williams on here many times. And others and but not everyone, you know, that's the beauty of live TV.
Who knows who's logging in watching right now? Not everyone may be familiar with contrast. So why don't we start there?
Yeah. So so contrast has a platform perhaps the most complete abstract platform on the market today. The anchor of our platform is technology that that we're really way ahead of everyone else on it's I asked not static application security testing but interactive application security testing and and I asked this great it has advantages in terms of accuracy and speed it's a little bit Limited in in terms of where you can use it certain criteria need to be met for it to be effective.
So we compliment that with the sast offering to get people started and and that's asked offering is fairly new to our platform, and that's what we're really excited about and talking about here at the conference. Absolutely and look to be clear. I mentioned Jeff Williams I remember sending similar set up here at RSA with Jeff five years ago four or five years ago, and he said if it's not application security It Don't Mean a Thing.
Right and I I laughed but he was right but that's Jeff, right? Yeah. Yeah Jeff's rude siren in the oh I found out yeah, let us know it is all about application security and the data says, you know 70% of the exploits the attacks that have been successful in the wild in the last few years were application vulnerabilities not infrastructure vulnerabilities, you go back a couple of decades and it was it was flipped the other way around absolutely we needed to shift the investment and we we did so yeah good.
So kind of set to tone here, you know what we didn't say though. What's your role at contrast? Um, so you said devsecops devsecops transformation architect is now my official title.
Okay. I help customers essentially establish a program like the program we had at come Comcast basically scaled it to 600 program 600 development teams over the course of five years essentially replace the traditional way of doing abstract with this developer first developer-centric. Yeah, I think even better person to do it.
All right, Larry. We've laid the groundwork. Okay this next part so you man yeah to us.
What's new here? Yes, I am. I'm super excited here at RSA.
We're we've announced and we're we're talking about a new product. It's called codec and it's it's and I'm not I'm not exaggerating. It is the most accurate and fastest static application security testing tool ever built by an order of Magnitude and we have the data to back it up.
So I'm sure you wouldn't be making that boast without the data to back it up. But tell me what what if you can don't do anything. It's gonna get us all in general.
No. No, what's the secret sauce here? What's enabling it to go so much faster?
Yeah. So so the first of all we have a new algorithm right at a research right out of PhD we call it demand driven fast static application screen testing and it's a Next Generation Leap Forward. So let me explain how it's the Next Generation lead forward.
So every other SAS tool on the market starts by trying to build what's called a data flow graph to to see how your data flows through the application and this is very time-consuming to explore perfectly and deeply so they make trade-offs with speed by simplifying and approximating the data flow. This introduces inaccuracies. So the SAS vendors are constantly trying to make this trade-off between speed and accuracy by turning this dial of how many approximations they make with their data flow model.
So we don't try to build the entire data flow model though. We just build the security relevant parts of the dataflow model, which is a small fraction of the whole data flow model and then we spend some of that extra time on building it deeper and more accurately. And so that's fundamentally how we pull it off.
So it's really? You getting the information we need. Not a lot of yeah extemporaneous, right right stuff that usually got caught up in the net of these static.
There are some advantages to building a complete data flow model because you don't necessarily know what security relevant when you're building the model. And so the way these things work is you define a query language that queries this model and and code ql the ql and ql github's product is query language and check marks calls there rulesets queries. And so so that that enables sort of the separation of the analysis engine and the rule set in a nice sort of clean architecture, but that clean separate architecture is also where the inaccuracy and the speed problem.
Well, I would imagine it's about Like what again? Just like we do this interview, right? You lay your foundation your Baseline and then you build upon it.
It's the same thing here. You can go do that full-blown kind of, you know, everything the whole data flow now, right, but once you have that Baseline if you will, You really it's like doing diff right doing differentials, right? You don't want lot easier.
You don't do a diff that don't do the whole thing. So this is Like that, but but we're we're we're basically figuring out which of the data flow paths that are going to actually have security implications and only exploring those got it. Which so is this available to all contrast customers now with it an add-on?
No, no it is and it's and here's here's one of the best parts about it. We're making it available for free. Really?
Yes. Oh, that's nice. So we're like free free or like free free.
Okay, we the product is targeted at developers developer first. We're going for a developer First Security Movement. We want to attack we want people to try it out and get to use it and we'll figure out how to make money on it make money on it later.
Look into this camera here then for our developers out there. Where are they going to go get this? So the contrast security calm website.
It'll be code. SEC is the name of it. Oh Jack code SEC code.
SEC is is the featured product and You click free and a few clicks and a few minutes. You can get started. Really.
Yes. It's designed to be quick and easy to use and and it's available now it's available now. Yeah, fantastic man.
Good stuff Larry anything else we want to talk about other than you rocked it yesterday as well. I I love talking about deaths. I got there are a couple things.
I I could sort of talk about with the codec product. Go ahead. So it has a sass part.
But we also have bundled. the world's best AWS serverless product with it as well. That's also free.
Also free also free today that again also free also free. Yes. It's all part of Barry who's paying for you man.
Yeah. Well, it's a command line interface. It's meant to get developers hooked.
But of course we're gonna go meet with you the security leadership at your organization. Once a bunch of your development teams are using and we will sell the whole interface in the whole package start and then you get to upgrade to our Superior is technology eventually when you mature enough to to get off of fast, I love it Larry. Thanks that way to see you man.
I'm so sorry. We haven't, you know can't help it. We could we couldn't see each other for two years.
Yeah. Let's make up for it. Okay Beyond soon right very much for any here on Tech strong live.
We're at RSA conference. There's something much to happen because there's a lot of people walking around. Let's be in between session or there's a keynote or something.
We're gonna take a break. We'll be right back go check out. What's the name of the new product code SEC by contract security.
It's free. Go check it out. We'll be right back.
Coding is changing the world making a difference in the world. We take anyone any adult and help them become the best version of themselves and become a software engineer. A texture group we've undertaken to meet this challenge with our engineering the change scholarship.
My career is completely changed to now being sought after by some of the biggest tech companies in the world full $10,000 scholarship to One winner to attend the intense software development course at Boca code. This is ready to be a suffering here. So Donald is another story right now.
Little bit roller coaster of understanding something one moment and then feeling lost the next you change the capitalization of a file name. You are going to your whole project. At the end of it gonna be a really good family.
We call Stephanie like the silent ninjas as much as he's struggling. Donald really really wants this my house. Went down twice.
The biggest thing I'm starting with definitely is time. It's pretty cool that I've been able to get expand my mind to be able to accept different ways of doing something but on the option is to succeed. I definitely getting started Lowe's would be Diaries drugs.
We've told all of them that this is the hardest thing they would have to go through all of our graduates are absolute Stars. We'll graduated become a software engineer. Hey everyone, Cody J Brown here from Textron learning.
I'm here to tell you about some programs that we have coming up this week. And so first tomorrow Tuesday, August 2nd at 3pm Eastern. We have a live Workshop titled improving performance and availability of serverless application.
This Hands-On Workshop will feature a live presentation and an interactive lab to learn how you can leverage a fully managed AI op solutions from AWS. com and is sponsored by AWS next on Thursday, August 4th at 1pm Eastern. We'll be discussing why kubernetes is the black hole of fan offs here.
We're talking about cloudspin. Do you know what it means and how to manage your cost when it comes to containers and kubernetes. com in conjunction with our friends over at Fairwinds.
And finally on Thursday August 4th at 3pm Eastern. We are inviting you to modernize your development Pipeline with this Hands-On workshop with AWS and circle CI tendies of this Workshop will build a continuous delivery pipeline that demonstrates both continuous integration and continuous deployment. com and we'll be led by Angel Rivera from Circle CI.
And so those are just three highlights that I've got for you right now. So come on come join us over on text from learning. We've got play to talk about This is texturing TV.
All right. We are back here at techstrong TV live here at RSA conference in San Francisco. I'm Charlene O'Hanlon and I am just astounded at the energy here at the conference and the just the quality of the the vendors and the Technologies and the conversations that I'm having.
I'm very very excited to have this next conversation with Rami sauce. Who is the CEO of men's which formerly known as white source. So Rami, thank you so much for joining me today.
Thank you so much. Thank you for having me. So tell me what's going on with you guys.
So quite a lot actually. Yeah many things going on. We are in the process of sort of repositioning the company completely.
We've been leading the what's called SCA markets of the composition analysis market for many years, but we've now expanded beyond that to also cover static applic. Security testing so we can Now cover your full application stack, right so we can scan both open source and proprietary code for your application and give you the full layout of what's going on. My own vulnerabilities are and also help you fix them.
And so towards that end we've also went through the process of rebranding and renaming the company into this new sort of mend identity that we're very happy with and practically being launched here at the RSA. That's great. Yeah, do you guys Announced it last week, right?
Yes. So when's public last week and we'll Now sort of celebrating this this new name? Excellent.
Excellent. Well, congratulations on the other rebranding and moving into that new the static application analysis. Steps that I security testing.
Thank you. Thank you. I don't know where my brain went there, but just kind of rent a blank on as that's too many acronym.
Yeah, I think that's what it is. Yeah, so, how's the show for you? So far?
Very busy. Yeah. Yeah.
So it's it's really good to get back into it right after a long life period shows and then events like this. They've always been a you know, very important activity for us as a company and we're super excited going back to it. We're meeting all these great people out here and you know reconnecting.
Yeah. Yeah. So very important.
I I think you know so many of us myself included I wasn't sure this was ever gonna happen again because of everything that you happen over the past couple years. I wasn't sure if people were gonna be excited to come back and to do a live conference. Yeah, or even if they just wanted to, you know, get away from their computer screens.
And actually I don't know put on pants and most people do I think yeah people I had enough The sitting at home. Yeah. Yeah.
I mean, it's it it's great to reconnect with everybody and these conversations. So so tell me get tell me a little bit about why you guys decided to take the direction of the company that that you have decided to sure. So look the way we see it.
The application security space is broken and for many many years. I know 17 18 years. It's always been around detection finding vulnerabilities.
It has to do with the history of how the smoke Market the came about which is very much compliance driven. All right. So all these years ago you had to be able to demonstrate that you are doing something to scan your application and towards some audience or customer or partner, but there was no real motivation to reduce the risk all the attack surface of your application.
So you basically had to take a box And when you do that you mostly care about finding the vulnerabilities, right? So you want a good reporting in-depth analysis broad coverage and that's what all the vendors will competing on but the reality is that just finding vulnerabilities is not very useful on its own right if you don't fix them, then you really didn't do anything. You invested all this time money effort and resources, but you didn't really gain any risk reduction.
And so what we're seeing now over the last couple of years is change in mindset where you see a huge spike in in application layer attacks. So organizations are becoming a lot more sensitive to what they're actual exposures are and how much risk they are carrying and so fixing the vulnerabilities becomes. What really drives value right and so we've took it upon ourselves to automate the action of fixing those vulnerabilities across your entire entire application.
So we've done that for the last four years with open source, and we've now started doing that for proprietary code. So we basically a closed the loop for you. Right?
So you your engineers don't need to worry about it. We will fix the vulnerabilities for them and that will really reduce the risk and reduce the attack surface of your applications and with no manual labor involved and you know, we will so bought into this concept that we named the company meant right that's kind of to reflect where we're going with without technology and products. That's That's great that you guys have been able to really kind of do you know the entire, you know, both of both the open source and the proprietary?
obviously so many organizations are relying on open source code an open source components to you know, but but even within that, you know, there's still Open sources in the proprietary code as well. Right? So you've got a you know, you've got a be able to protect both elements there.
So they should right leave the part of it. Yeah. Well, I mean, it's obviously it's it's it's a great thing when you can pretty much cover all of your bases if you will so, so are you is the company looking to kind of move Beyond?
You know what you're doing now with the with the open source and the proprietary. Are you looking to expand beyond that? Yes.
So we we also now recently announced a new offering around supply chain security and it's it's still in the same neighborhood lights. So we're still doing security for your applications as they are being developed. It's part of the shift left the motion.
So trying to find vulnerabilities as early in the development life cycle as possible. A supply chain Securities is becoming bigger and bigger topic now. It's a big shift on what we've seen in the last 10 years.
So for since forever. Open source vulnerabilities have always been accidental and so you've had developers contribute code to open source projects. Some of them would have bugs right?
They didn't mean to right. It happens. They're human and some of those bugs could have been exploited for security hacks what we're seeing in the last maybe 18 months is a new kind of vulnerability something that's malicious.
It's intentional. So individuals groups, sometimes even governments would go about and intentionally inject vulnerabilities into open source dependencies and then we kind of sit back and wait for people to to step on those landmines and those required different kind of protection and different way to identify them. Right?
So we've introduced men the defend capability to help you cover your supply chain for these kinds of malicious attacks. Fully automatic, right? So that's something that we're also announcing at RSA right now.
Well, that's exciting. And that's that's a definitely a very hot area. I've had a couple conversations with folks today about supply chain security.
So I know it is definitely on a lot of people's minds but and you know, they're looking for ways to help improve their process and do it in a way that's not going to interrupt The rest of you know, their their application development, they're you know, they're just their entire motion around applications and and security and you know the process so yeah automation is a big part of it like you want to take as much away from the developers is you can right. I'm not security Expo there to develop software bring more business value to their employers to their customers. Yeah, and then we can do the security side for them.
Right? We have the Security Experts. We can automate that for for the developers.
So they have more free time to do what they really came to. It's great. So, where do you see the space?
Especially as it as it pertains to software supply chain security. Where do you see the space evolving? Do you think that organizations just kind of by Nature because they've been hearing so much about software supply chain issues and and just the vulnerabilities.
Do you think that they're becoming a lot more aware of a lot of the issues that are plaguing organizations and and because of that they're taking steps sooner to lock down those Supply chains and to mitigate the issues that with vulnerabilities. Yes. So yes, the the is a lot more awareness today.
And those those are a lot more discussion around that topic but I think also many many organizations feel it happening in their own backyard, right? So they'll say surprising amount of real supply chain attacks going on at any given point in time. Yeah.
I think we have many many customers who've experience this kind of attack first hand. So I think it's not just hype it's something that hackers and attackers are very actively looking to exploit day in day out and that's what really drives companies to to better protect themselves. Yeah, that's I mean it's kind of terrifying actually if you think about it because we hear about the big ones, you know, the ones that impacts the federal government and and you know, the the all of the the companies that are being serviced by you know, solar winds and and you know, the headline grabbing ones, but the fact that this is happening on a regular Cadence with smaller companies or or at a smaller lower level.
I guess if you is really I wonder if there's a level of awareness with with everybody to understand that that this is this is not just a once in a while headline grabbing event. This is something that's happening daily. So again, we anyone we talk to is very well aware of this situation, right?
So I think there's there was a big increasing awareness in the last 12 months. Like maybe last year people still didn't know exactly what to think about it, but now practically everyone we talk to already understands the risk knows about the maybe hasn't implemented something yet, but knows they need to So yeah, I think we've sort of crossed the chasm in terms of having people be aware of the problem. Well, that's good.
I mean it obviously why wouldn't it be good but it's good for you guys because you're you know, you're in that space now and and it's and it's good for I think the security industry as a whole because obviously if we if we can get ground swell awareness and understanding that that this is an issue that needs to be solved soon. I think we will see more movement faster to do that and then, you know, even even moving forward with new threats and new vulnerabilities. What are you guys seeing, you know, maybe what's what's kind of The Whispers in the hallway if you will as far as and some some of the ways in which threat actors are You know, we getting into networks and breaching the you know, the organizations, you know, because we hear we hear a lot about a lot of the same types of attacks over and over again, but they're I haven't really heard of anything that's kind of coming up on the horizon lately.
So you guys have any so yeah, so we'll we are seeing a big shift actually away from the network layer. So I think Network Protection Services tools have gotten very good all these great vendors here the conference that they are blocking the network very effectively and so you see more and more attackers sort of try and find the next weakest link in the chain. Yeah, which is the application layer.
So I think it correlates with everything we've been talking about we will sing a lot more attacks. through the applications right trying to find exploits in the way that organizations develop their applications trying to find the holes in the wall and trying to sort of reach in and steal information because some damage. So yeah, that's something that's it's not that new but right on a very dramatic rise in the last a couple of years.
Yeah. Well, it's it's you know, it's interesting. You kind of see, you know, first the first they go for the network and then they go for the applications and you know, who knows what's next.
I know that API security is also something that a lot of organizations are starting to you know, really have to deal with on a regular basis as well. Yeah sure. It's another aspect of application security right?
It's about apis about of your application and they are sort of the doorway in and out. And so it's a it's a convenient way for people to to preach. Yeah.
Yeah. Well, maybe maybe this time next year. We'll be talking more about you know, the importance of API security and and other forms of security as part of the application security conversation.
I'm sure we will the market is always expanding. Yeah. Yeah.
So Rami congratulations on the rebranding the reposition and the company the new offerings and Wish you guys the best success moving forward. Thank you. Thank you so much.
Great. And thank you. Thank you for coming on and having the conversation with me.
Again. Thank you for having was a great great. Great.
All right, everybody stick around we've got a couple more conversations to finalize the day plus a couple of panel discussions coming up. I'm looking forward to those but we're going to be back right after these commercial messages. talk to hear how real world CIS are dealing with today's real world issues from enabling secure remote workers to accelerating secure Cloud adoption defending against a pandemic of security attacks in Beyond ciso talk covers the Cyber topics you want to learn about With your hosts Unisys ciso, Matt Newfield and mediaop CEO Alan Schimmel featuring a revolving panel of ciso cyber experts.
tv. Hi Rick Spencer. Who's VP product?
Yep with inflex data. Welcome Rick. Thank you.
Would you give us a brief induction yourself and tell us about in Flex data sure. So I was actually the VP of engineering for the platform team for about two and a half years at influx data. I recently moved over to the product role been in open source software for quite a while before that vietnami and had a long syntax canonical and before that actually worked at Microsoft and developer tools for quite a while but that's going way way back and dipping back a little farther there.
Well, tell us about inflicts. Yes. So at the heart we're a Time series database.
We're quite well known for our open source offering and that that's used in quite a few scenarios a very heavily used. We have some tools around that like Telegraph For people writing agents to you know, sync data and write data back to their influx DB instances and Etc first. We have an Enterprise product.
But right now our Flagship product is inflex DB Cloud, which is a fully hosted multi-tenant SAS solution just pay as you go. So if you're developer, you have a Time series use case. If you're ready at times series application because come sign up for an account.
We actually can start on a free tier and then just pay as you go as your app, you know, as you consume more and more you pay more and more but on days where you don't consume a lot you don't pay a lot and so we've been getting a lot of traction on that people building applications on top of us a lot of iot a lot of server monitoring and a lot of Finance actually so different all those kinds of organizations produce a lot of time stamp data very high. Solution and so they sent it to us in the platform and then build their applications on top of that. Managers not just the data collection of all that because I obviously some of those situations generate large amounts of data.
It's a synthesis of that and maybe collecting that from different locations across the cloud or your data centers. Yeah, exactly. So just to clarify since we're at cubecon like we don't really think of ourselves as a kubernetes tooling provider, but we do have a lot of customers who do their monitor their clusters using influx DB and we also have a few companies that have built kubernetes monitoring or SLO as a solution on top of us like noble 9 and some other companies like that.
So so, you know, they can send all that data to us from their customers. And then we have a language called flux, which is this programming language, which is integrated into influx DB. So if you're doing you know, if you're doing monitoring, but also if you're just doing like crazy data Transformations flux has like a very rich math Library it has the ability to pull data from other data sources other DBS alert push it back.
So you can write all of these programs and flux and actually just push that down into our platform and let us play our platform run all those functions for us. I'm really tempted to ask if you have a flux capacitor going back to back to the future perfect, but we're talking earlier and I came from a briefing they were talking about KUB. Eddies in the Telco space and one of the premises was that the Edge Edge Computing Edge cloud and you talk about a distributed situation and I refer to it as kind of pop-up data centers pop-up Services pop up networks pop-up application.
Yes to you overuse that word a little bit but that really is kind of one of the scenarios around the cloud whether it's collecting data from your Kessler from your home automation systems or whatever might appear at the edge, right? So we're seeing this a lot in iot but also in other scenarios like in you know, server monitoring or more likely cluster monitoring so we have actually an OSS version which you can run as a single node. It's super easy to deploy and manage.
And so what we've added recently as a feature called Edge data replication. So imagine, you know, you have let's say 10, 20 windmills and each of those windmills has 10,000 sensors. You can deploy a edge node of influx DB just an OSS node, super easy stand it up there collect all that High Fidelity data from those 10,000.
Sensors and then do all your local processing there whether it's you know control Loop that's local alerting everything but then you can also sync that data just with a real easy configuration with our Edge data replication feature and send it back to a central cloud account. So I sign up for inflictv cloud distribute OSS node on all of your windmills. manage those all locally, you can even log into them locally if you want to visualize how it's working there and then you can downsample that data enrich that data and then sync it back and then look at all the 10 windmills globally from your Cloud accounts and you can also, you know have retention policies for that data that are appropriate for you know, long-term storage and that sort of thing what would be good example of down sampling is that just kind of identifying what the most common occurrences are or is it doing some correlation to try tie to it events or things like that or some of both so down sampling is A way of reducing your data and the reason that's important for time series data is you have to remember there's very very high resolution very big volumes of data.
And so there's really two kinds of down sampling and the first is to remove cardinality, right? So if you're looking out at kubernetes node, you care at that moment about things like like what is the identifier of that specific pod for example, but over the course of the day you could have a thousand pods 2,000 pods the next day you only care about the role of that pod. So you can down sample by removing that column before you sink it back to you know, your Cloud where you're looking at a globally because you just are interested in the health of the service not the health of you know, a specific pot at that point.
Another way of down sampling is to remove what I would call Rose by aggregating data and this is really where influx DB really shines is a Time series database. It's very easy. You say just give me an average for every hour every minute every second or whatever aggregate function.
You want to use min max mean, whatever custom function you want you can aggregate into those time windows and then sync those time Windows back. It's not just that it's much less data, which it is. It's also much faster to query it and it's often just much easier to model the world in terms of what was the average over the minute instead of what was every you know, nanosecond of data that we got.
So those are the two kinds of down sampling that people do from The Edge back to a central account cool. You know, I think there's wanting to you always think about the new things as a we're deploying and iot and at the edge there's a lot of existing equipment scada, whatever you you want to look at windmills have been out there for a while some of those things use non guaranteed delivery protocols like UDP, it's great to Great to collect data locally there and then due processing aggregated down sample synchronize it that kind of thing. So there's a lot of reasons I think to look at the edge that just for new applications, but also existing ones.
Yeah, it says something you find with your customers. Yeah. Well, we actually like really on that that data replication feature.
We really focused on having a durable queue. So as long as you can get the data to influx DB if you try to replicate it, it will get replicated. Even if your internet connectivity goes down even if the whole system reboots it's a very durable, you know file based cue to ensure that the data does eventually get there when we see people use that for scenarios where they expect intermittent connectivity.
For example, if you have a fairy tons of sensors on the ferry, you need to know how the engines performing and all kinds of data that they collect on a sensors and they do a lot of local. All while the fairies Crossing it loses internet connectivity, but then when it gets deported it regains connectivity and they really want to guarantee that that data gets synced back to a place where people can monitor all the fairies all at once and you know, aggregate across all the ferries. So we focus on that quite a bit Yeah, but it's kind of logical to see that as you're scaling up more and more kubernetes or similar kinds of Technologies.
We have to have data Technologies schemes that scale as well. Yeah from that standpoint. Well good.
It's great to talk with you Rick ditto. Hope you have a really good show here for kubernetes and and kubernetes. Yeah opportunities.
Yeah, great. Well thanks to Rick Spencer who's BP your product here with the influx data and good to have you on and always happy to have inflex here, right? Yeah.
I'm looking forward to seeing you again. Good thing. Remember to stay tuned.
Like I said, we we have more great interviews just like Rick coming and so we hope you'll be Back with us in a few minutes. com covers all aspects of software containers from container management data management for containers container security networking for containers to the entire container ecosystem kubernetes microservices serverless and more. com has the largest selection of container-related news featuring breaking news blog posts podcasts and more.
com to learn more This is Textron TV. Hey guys. Thanks for the throw.
We're here with the team you miss shenske who is a principal research scientist at IBM. We're talking about quantum computers and cryptography and all kinds of interesting things are starting to happen the dean welcome to the show. Thanks.
Good to be here Michael. Be talking about the ability of quantum computers to crack the algorithms we use for encryption and how far down the road are we towards this and what's actionable and what should people be thinking about today versus tomorrow? So, you know, that's the trillion dollar question.
When will they actually break encryption or cryptography? Well, I think if you ask people, you know, the guess is range between 10 and 30 years something around there. But you know, even if the probability in 10 years is, you know, something like, you know, five percent something very small.
You know that's still a considerable risk. I would say, you know, all of our secrets kind of leaking out. And of course the other reason why this is a bit scary, if you believe that they are coming even if you're at the higher end of this scale like 30 years, you know, that does mean that today's information for example could be intercepted harvested and then decrypted later with quantum computers.
So if you have something that's sensitive, you know, then and you believe that quantum computers are coming at the you know, at the end of that scale that that is something worrying. um And so, you know, this is why we're kind of you know, kind of nudging people along and this is nudging people along and all the kind of government agencies and nudging there, you know themselves along to switch to Quantum safe cryptography, even though you know, there's no quantum computer yet. the nation states that would have the foresight to start a harvesting data at that level of scale for use down the road but it also seems like last time I counted there was two dozen or more Quantum Computing platforms so might these things come fast and then we think You know, maybe we're a few breakthroughs away from from you know, the whole thing being sped up.
Yeah, and you know, you don't necessarily have to have a quantum computer to start harvesting, you know, maybe in the future and 30 years. They'll be pretty common and you could just you know, they'll be reachable from the cloud and you can just you know, just use them to decrypt. Decrypt the things, you know, the this part of gold that you you took 30 years ago.
How hard is it to replace our current encryption schemes what's involved in that and who's in charge of that? Is that the security team or somebody else? I'm so you know as a sort of a more in the research side.
So to me, it's it seems completely trivial. You just plug one in for the other, but apparently it's quite difficult. You know first you have to find where this old cryptography is being used.
So that that apparently is not so easy to find because the way cryptography was designed and put in you know and 20 years ago and started being used more than 24 years ago was quite you know ad hoc and it's you know, there's still stuff from the from that age still being used and no one knows how to take it out because it's so intertwined with everything else. So that has to be kind of ripped out by the guts and then, you know, then, you know, also a lot of protocols were, you know, optimized in a way that you know to if you change something they will break if you know, for example, Quantum safe cryptography will require more bandwidth And maybe some protocols will break if you know they expecting, you know, a hundred bytes and now they're getting 200 bytes. So, you know, it breaks down.
So there's quite a bit of this nitty-gritty stuff that needs to be done before we can really, you know, be Quantum safe and not break the internet in the meantime. So it's quite a quite a significant effort and you know companies like IBM, you know, the Consulting companies they will they you know, they come in and they kind of do all this stuff find out where the cryptography is and try to we'll try to replace it with the new stuff. Do you think people will draw a line in the sand and start replacing older applications with newer ones that have the better encryption for the future already baked into them and maybe it's easy to install in a more modular way when the new app and it is they're ripping replacement all that.
Yeah, that's that's a good question. I would guess I would guess the new stuff, you know, right? I mean, you know, I'm not gonna change my whatever we're using Zoom my zoom with the quantum safe Zoom, you know, you're not gonna rip it out.
I mean, they'll just update the app like you said, but there are things like You know like then the in the cloud, for example, you just you know the internet, I mean that that is all interconnected and you cannot just it has to be interoperable with someone else so you can't just so everyone kind of has to make this change together or somebody has to orchestrate this change and this is a, you know, quite quite difficult to do and there will always be Legacy things. And so so you kind of have to convince those people to to change, you know, because they will not want to get a new app, but they will not want to get a new machine or something like that. So and and yeah, so just because you're releasing a new app doesn't mean that people are going to use it.
There's there's so it's yeah things I don't know very frustrating things like that. I think people will Consultants will find in the real world. How crypto safe are the new algorithms.
I mean, well there just be a bigger better quantum computer in the future to crack those and might we be in this kind of cycle of ongoing updates or how do we know what's good today will be good tomorrow. Well, the way cryptography works is that you don't know what would be good tomorrow. Right?
So we don't even know that even forgetting quantum computers just classical computers. We have our RSA. How do we know that tomorrow?
Somebody won't come up with a great breakthrough algorithm that can factor numbers and then that's it. Our say is broken. So I mean the way cryptography works is is that You know a lot of people kind of analyze some underlying assumption.
And you know in 20 years kind of not much progress is made they believe that it's hard and we say, okay. This is a hard problem Eve for whatever model of computation classical computer quantum computer and we say, okay, let's build cryptography on that. And so just a lot of space cryptography.
That's the president standardized has been fairly extensively studied for the last two decades. I would say and it's been one of the central problems in Quantum Computing and not much progress has been made. So we are kind of thinking it's okay.
Of course, this is hedging a bit. So they're gonna select a few different types of algorithm based in different types of problems. So if one goes they will plug in another one and hope that one is okay.
Unfortunately, that's how cryptography goes. And for all we know maybe somebody's already cracked it. They're just not telling us yet, but you know, we'll see of course.
As we go along here that there is a greater appreciation now for encryption than there was before I feel like, you know years ago people were like, oh it's too much computer horsepower and it takes up too much time and effort and let's not be bothered and now we kind of hear people running around talking about Crypt everything. So we're yeah we got from one Spectrum to the other or is there something in the middle that we should be aiming for? Um, I think you know encrypt Everything Is Not a Bad Thing, I guess maybe what changes people want their cryptocurrency protect it right?
So You know if if that's it. Okay, maybe that if that's a catalyst for Morse security and privacy find be it, but I think I think we the world is moving towards more privacy. And this is a good thing.
I would say. I mean, you know, we shouldn't move towards Anarchy that kind of privacy or anyone can do anything and no one knows what they're doing. Right?
But but I think you know encrypting your data, you know, encrypting your communication and this is this is wise. Do you think there's a set of best practices for implementing encryption that people should be following or you know, what is the thing you wish people knew up front that they would avoid once they get going and you know, I guess what do you know now that you wish you knew 20 years ago. So, you know the the famous I guess most famous saying and cryptography computer security is you know, you don't roll your own crypto, right and you you don't come up with your own things and you also if you don't have the expertise to put Crypt in, you know to you know to actually Implement crypto you shouldn't do it.
So, you know, I should leave it to the people who are because very easy to make mistakes. And this is this is what I hope people know so I you know, I don't have many lessons here because I'm not a person who knows how to implement, you know crypto. I'm more in the research and Design.
End of it. But yeah, most of the common, you know, the security breaches are caused because crypto was incorrectly implemented. So this is a something that I think people should know and I think I said earlier, you know and kind of just as a joke that you know to meet seems completely trivial to replace the current algorithms of the new ones but to do it right and to do it in Secure way and make sure all the little details are kind of are there taking care of that actually requires quite a bit of expertise and people should should know that Yeah, are there tools for discovering whether or not I properly configured encryption or how do I know?
I made a mistake. You know you offer a bug Bounty with a high enough reward and you'll know. All right with that in mind do you think as we go along here that the volume of data that we're now trying to encrypt May exceed or capabilities or is that kind of one of the things that we need to think about?
It just seems to me we have more data than ever in not all of it is of equal value. So are we really going to encrypt it all or do you think that maybe at some point? We mean you want to make some decisions about what's worth encrypting and what's not or should we just play it safe no matter what?
um, I don't think it's that expensive to encrypt and the data, you know, the day the encryption does not expand the You know the storage of data by too much. If you have enough space to store the data you have enough you almost certainly have enough space to store the encrypted data. Do you think the bad guys will start to find an ability to use quantum computers themselves and we're not talking about nation states, but actual cybercriminals because in theory, right and quantum computer will be an API call away in the cloud somewhere.
So, you know those guys just the valve themselves of a platform where somebody might not ask too many questions about what they're up to and you know starting using this thing cracks some algorithms. So this is kind of the worry right if quantum computers become. So so easy to build that and is it, you know, so prevalent that they're available, you know, the powerful enough quantum computers available via cloud.
And API like you said, yeah, I mean that that is absolutely a worry right? So that's that's why it's not just you know nation states. That one should worry about harvesting the data.
It's you know, sort of any Anyone who's has enough hard drive space can and serve enough evil intentions can prove and foresight to exploit to exploit this in the future can start doing that. But you know, hopefully if we do this migration, right then you know quantum computers will not have you know, even that much evil potential right because there's a few things they can do that's you know, really bad which is crack encryption but everything else, you know, they speak, you know, I'm not sure I know of any malicious applications of the top of my hand head Alright, well now we all have one more thing to keep us up at night about cybersecurity the team. Thanks for being on the show.
Oh, thanks a lot for having back to you guys in the studio. This is Textron TV. Hey guys.
Thanks for the throw. We're here with Herman. Bartol who is vice president in general manager for it Asset Management.
It's servicenow, and we're talking about the future of how it is going to get managed her. Mom. Welcome to shop.
Hey, Michael. Thank you. Thank you for having me.
We've been working on this Cloud thing now for the better part of 10 years and we have seen over that time almost in a lot of organizations two teams emerge one as a cloud team and one is the traditional it management team are these things finally gonna converge or we just gonna start treating the cloud as a natural extension of on-premise or maybe on premises a natural extension of the cloud either way, but is it time to bring them all together? Well, you know in some cases that that transition is already happening, right? So when we talk about Cloud, we usually think about you know, the cloud as infrastructure, right there's a service and but there's also the SAS component right which is a clearly in the in the house of the its managers responsibility today.
So this teams are likely going to come together as they already share you some of the same Charters, you know, these they are in charge of figuring out how they are spending money in Cloud both from a SAS perspective from a cloud infrastructure perspective. There are forecasting this pain they are looking at how allocate how to allocate the cost to the different business units that they're supporting and so on and so forth. So a lot of that is common to the organizations and we are seeing slow transition into you know, these two groups coming into either a single organiz.
Version or eventually becoming a single team. Some of our customers are already operating that way the asset management teams already have responsibilities for the cloud spend not so much for the operations part of it, but for the cloud spend management, so we think that this is going to be a trend that will continue to accelerate. Is there some Tipping Point that pushes people over the edge to converge these teams that have my work clothes are in the cloud or you know, what?
Have you seen amongst organizations in terms of what provides the impetus for them to go do this? You know, some of it is just in the way these teams came about in a specific company, so that that's a very specific to an organization. But in other cases it has to deal with as they migrate their workloads from on-premises data centers unknown to the cloud.
You know, what are the key challenges and in some cases this becomes, you know how to manage the the hybrid licenses for software, you know, people traditionally purchased perpetually in did running their data centers, and now they are looking to deploy those licenses on to the clouds. So depending on on the organization these organizations are already operating very closely together. So the transition into a single team is a lot easier.
In other cases, they operate as independent organizations. For example, a cloud Center of Excellence supporting them a business unit developing technology for their customers. So in those cases the the way the the teams came about we're not really close together.
So those would take a little bit longer. As we see more and more workloads transition into the cloud the you know this will this will eventually happen. Do you think that current economy May accelerate this trend because you know, if I look at the cost of it, it's generally labor is still the biggest pain point.
I'm also having a hard time finding those people anyway, but will that push people more towards convergence of these teams? think the infectionary environment and you know, the very cost conscious companies are going to see that the opportunity for spend nationalization and spend optimization is gonna be a big driver in their ability to continue to accelerate some of the other digital transformation initiatives. These are areas where the cost saving opportunities are real both on cloud deployments as well as on on fast.
So the condition the market conditions are appropriate for for that acceleration to happen and you know these things I know how to manage their their costs. So it's only natural and makes only makes sense for them to come together. Do you think we'll also have some interesting issues around software licenses to sort out?
Because if I look at the first phase of the cloud and lift and shift and I had you know something that I was paying for as Perpetual license and now I shifted over to the cloud but the infrastructure itself is paid for and kind of a monthly basis. So do we need to reconcile these things or can they just leave side by side forever or what will happen, you know, the first thing to know is that the different software Publishers allow companies to support and move their own premises Perpetual licenses to cover deployments in the clouds. So that's that one making sure that you as you transition workloads to the cloud you fully take advantage of your existing investment.
So you don't have to pay for brand new licenses there by duplicating some of this pants. So there are very specific rules on what what you can Do as far as porting these licenses and they are very specific to each publisher some Publishers favor and their own private their own public Cloud. You know, Microsoft Microsoft will be an example.
So teams need to be very conscious and careful about how they approach the problem. After is now as part of our software as in management application, we help people with that evaluation understanding the Perpetual licenses that they have and how they can be transition and deployed to cover, you know, SAS or on the cloud deployments. Do you think that in some odd way are concerns or our issues around cybersecurity these days is making Asset Management cool again, and I'm asking the question because it seems like you know our issues are not so much our security tools.
It's just the simple fact that we have so many things out there to secure and the platforms keep expanding and nobody has any idea or anything is, you know, do we need to start with some fundamentals? It is absolutely right. We are seeing that from our customers as well.
The one of the key issues is having full visibility into all the assets that they own where they are deployed how they are being utilized. And when you think about cybersecurity, you know, there's the regular scanners that run constantly and they take some time to complete those kinds. So we are looking at an approach where if we have full inventory of the software that's deployed everywhere in the organization.
I say a new woman ability gets reported. We can match that woman ability against the software that we have in our inventory, which that what that means is you have a much more really, you know faster time to identifying the the issue while the traditional scanning tools continue to do their work. So what you can get special to see how they type normal abilities you can get in much faster reaction time.
What's your best advice to folks about how to achieve this conversion? So I just take everybody involved and lock them in a room to figure out who's gonna be actually running. What or is there some more intelligent way to go about achieving this goal?
I have to wait to go about it, you know, typically the the teams In This Cloud Center of Excellence. I'm not only looking at costs. They're also looking at you know, what are the templates that they need to provide to their organizations to have the right configurations when they deploy the new virtual machine in in town if you look at containers as well.
So there are certain areas of expertise in the cloud Center of Excellence. There are not duplicated with what the typical asset managers do. So in those situations the common elements around cost management and spend allocation.
And so on those are the pieces where I expect things to kind of merge and then the others will be more complimentary so there will be working closer together but it's not gonna be one team absorbing the other I don't expect that to happen. I think it's gonna be more what are the skill sets that people bring to the table and how they can be Better aligned to work together in a single team. Armon what's the one thing you see it organizations doing that makes you shake your head just drives you crazy and says geez, why can't we just move beyond that?
I think one of the the struggles then it organizations have is as they transition to Cloud. And the Very onset of those projects they have certain expectations in terms of cost savings that they will achieve as they move to Cloud. But without the right governance program in place, they spend on in the cloud can go out of control and the the promise savings and the promise value realization.
They were expecting to to get as they migrate to Cloud. Don't really materialize. It's not that hard in this age and this time to to figure out what are the right governance controls that you can put in place to make sure that you understand how money is being spent and don't get surprised if people work to take a the time not just to focus on the migration but also on the steady state once they move to Cloud they will really get a lot more benefits in that migration and they will not be surprised by overspending which is something that is really really not very uncommon.
It's happens all the time. So their projects will be a lot more successful and it doesn't really take it a lot more on their part is just getting the right mindset and getting the right Tools in place. And of course there is now we we feel very confident that we can help customers in that in that process both in the transition to cloud and then running this day.
in the cloud Alright as they say nothing's for free. Hey, Vermont. Thanks for being on the show.
Hey, Michael. He was it my pleasure. Thank you for having me.
All right back to you guys in the studio. here Hi again, everyone. I hope you all enjoyed.
Today's episode of Textron TV. We brought you some great interviews with our host Mitch Allen Charlene and Mike Villard as well as some more fantastic content from RSA and kubecon Cloud nativecon. We'll be back again tomorrow with some more content.
So please join us for that. Once again. Thanks for joining us today, and we hope to see you again.
Stay strong. Stay strong. here