Techstrong TV August 13, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
Sh be very quiet. I'm hunting CEOs, they're endangered. You know, you're watching Text on Gang.
Hey everyone, it's Alan Shimel. It's Wednesday. And no, that was a little Elmer fud, but hey, CEOs are becoming an endangered species again.
You know, when things get tight, you see this happen, right? The boys at the top who've been collecting the big bucks all of a sudden, and unfortunately it is usually boys. Um, but all of a sudden the screws get tightened and off they go.
Of course, you know, don't cry for them. They all gold, golden parachute, usually that they're jumping out into. So there we are.
Anyway, we, we have an interesting gang here for you this Wednesday. We've got some of my favorite people on the gang. Let me quickly introduce them to you.
We have Chris Blak, Kate Scarsella, Mitch Ashley, and of course the dean, Mike Ard. Mike, what do we got? Well, starting with the CEO conversation, the CEO of GitHub has decided to call it a day and is leaving the company, and allegedly, he is gonna go back to creating additional startups.
And, but the more interesting thing to me was that GitHub is essentially gonna get pulled back into the mothership in Microsoft and become more of a mainstream element of their application development strategy. Um, Mitch, I mean, I think a lot of us expected this to happen a while ago, but the question is here, uh, what's your take on it? And B, will the rest of the open source community kind of take this as an opportunity maybe to have a referendum on whether they will still trust Microsoft as an open source company?
Well, It cer it certainly could have that consequence. Um, if GitHub loses its sort of acumen and, and mantra with the open developer community, both open source and just being a platform for everybody to use, I don't think that's gonna be the part that's gonna significantly change. This is, this is a sign of AI is not only coming for your job, whether you're a CEO or anybody, it's coming for your strategy.
And this is a realignment of strategy tying directly into core ai, which is the group that runs is, is in charge of all AI for Microsoft. And while they didn't hint at this, at their, at their BUILD conference, you could see that at the elevation of core ai, uh, taking on more and more, they didn't hint anything about GitHub. But the time is right.
You know, CEOs leave for a couple of reasons. One, financial performance is bad, or strategy change, or somebody just doesn't like him, right? So new chairman doesn't like him, whatever it might be.
Um, so this is clearly a realignment of strategy. So I don't, I don't think Microsoft will go in and clean house and just change all of what's happening. GitHub, I'm also not naive enough to say they're gonna leave it all alone.
I think they're gonna get much tighter connected into the AI strategy of what GitHub is doing and what Microsoft is doing, because there is sort of this uncomfortable distance between the two that has existed so far. You know, is it GitHub actions and Microsoft vs code, and where's the AI part of it? You know, it's, it's a little murky and I think this will help clarify that.
Hmm. Well, I I would characterize it as this resistance is futile as the borgs say, you know, Mitch reasons, the CEO leaves their stock option grant is finished. They don't like being part of the big corporate culture, the startup people, open source people who are chafing under the, you know, the big corporate thing.
And I, I think that might be the case here. I I do think that, um, the CEO is, uh, a, as Mike said, look, we are expecting this to happen a lot sooner than it did. But I think you also, let's give him some credit, right?
Um, you know, and if I mispronounce Thomas, it's Thomas Donkey, right? Or, or dunk. Yeah, it's donkey.
You know, look, he took a company here, GI GitHub. When Microsoft first bought it, it was a repository you gave, you gave software stars if you liked it, you voted for the software you liked, but it was an open source repo. And then, you know, they, they allowed you to maybe create your own on-prem version of it.
But when Microsoft bought it, the idea was, oh my God, Microsoft already has a fantastic developer channel. They're strong in the developer world, but they just bought in, I think at the time it was 27,000, or excuse me, 27 million, something like that. 22 million, uh, developer accounts.
And this is gonna make Microsoft the king of the developer hill. Well, a funny thing happened in the ensuing years. GitHub went from being just a pure repo, if you will, to the place where, where the action is GitHubs GI ups, it became A-C-I-C-D solution.
It became an IDE. It became the place where copilot, which I never knew if it was Microsoft or GitHub, was copilot. To your point, Mitch, That's where it lived.
I think for most developers, the the clippy thing that's going on in WordPress and Excel now is not the copilot that they have in GitHubs. Much more powerful. The GitHub copilot is, is, you know, a bit of a real deal compared to what we see in, in work.
So, you know, I, I think Thomas job well done. Go back to your peeps, take your money, cash your options. Satchi will keep growing this thing and make it more valuable for you and go build your next adventure, right?
He's, he's leaving, he's leaving at the top of the mountain, right? He's not, he's not sneaking out in the middle of the night. He, he's staying on for the next six, seven of five months, whatever, four months.
Because, you know, he's, he's, he's leaving in triumph. That's a, that's a good way to go. I think people will be closely watching GitHub actions in the age of AI and Microsoft.
'cause a lot of folks who do use it don't necessarily always drop everything on Azure, right? They're kind of using that as a, as a front end. But if Microsoft starts, you know, thinks it's gonna optimize GitHub actions for Microsoft Azure, a lot of people may decide that those optimizations are maybe lock-ins.
So to me, that's the thing that maybe I would keep the closest I am. I don't think Microsoft will be that heavy handed. So we, I think Microsoft of old would've been.
But yes, I think it's a concern, but I don't think they will either. Sorry, go ahead, Kate. I stepped On you.
No, I, I, but I, I do think that we see this slow erosion of GitHub's independent, um, spirit personally, I, I only because of the people who are putting into GitHub are going to other sources, is there's been a slow, um, you know, slow leak of people going and looking at other places to put their code. So mm-hmm. Chris, Yeah, and I, it, yeah, I think it's an interesting one because, you know, I, I, again, I'm not a real coder.
I just play one on tv, right? You know, so I had a GitHub, uh, account, Chris Blast, uh, so far back and did a little bit that I lost the password. So, and now Chris Blasts, right?
But with this whole civic AI thing, I Turned that to, Right? But, but the, you know, and it's not because it's GitHub, you know, the Civic AI canon was all written in documents in Google Drive and so forth. But as you look at principle, where you, where you put something like that, it needs to be, you know, a detestable repo kind of thing with version control.
So it's MD documents, it's not executable code, but it's a fantastic repo. It's replicable, you know, fork. There's Arabic translations.
It's all the same, but it's not about GitHub. It's about that type of strata. And so there's that side of it.
And, you know, we've just finished the cisa sbo, you know, cycle that Alan Friedman's leading. And the whole, you know, again, it's not just about, uh, Washington with the SBOs thing in the supply chain is we're an era of what's the next thing we do? And some of us are looking at that, you know, we've been involved in those working groups, having conversations, you know, in this era, you know, this month, the next month.
And my thought is that I want working groups to use GitHub, um, to file all the documents and actually execute all of the, the, the programs. You know, I would like to, to in supply chain, have a bunch of GitHub attestations, you know, that have all the terms and everything you need, you know, to actually exercise supply chain, uh, demonstrations at least. And in a lot of cases, I, you know, those sick, again, not about GitHub, but those sorts of capabilities are intrinsic for all these systems to coordinate with each other.
So, yeah, I, you know, to our point, Microsoft taking over the co-pilot, um, as I was saying in the Green, green Room, the co-pilot attached to GitHub is a really fascinating little creature, what they does a corporation do with it. I'm with you, good and bad, otherwise, we'll see. But I understand, I, I, I still go back to, and multiple things, of course can be true at once.
You know your point about what, what he stumped he's accomplished, Alan. Um, but I, but the way I look at this is it is trench warfare for fight for the developer right now, because it isn't just Microsoft and AWS and Google. It's, it's all the small startups.
It's the lovable, the, the cursors, the, the win wind serve. And while the numbers aren't as big, the innovation from the model creators, I mean, they clearly know that the owning the developers is key to their strategy, whether you're anthropic or, or, uh, open ai. And they're not gonna give that up.
So, so the field has widened for people that are fighting for mindshare of the developers in the world. And I think Microsoft sees this, this is my opinion, they've not told me this. I think Microsoft sees this as we gotta get our act together to play at an even more aggressive layer level, not meaning being the Borg of Microsoft, being the developer friendly, open developer friendly, and really go after the development market, because they could start to see some serious erosion to a significant advantage that they have right now.
And no one else has the advantage that Microsoft has today. Mm. Kate, you know, to Alan's point, and the CEO did some awesome things here, but I felt like one part of the job that was kind of left undone was just making GitHub and those repositories more secure.
I, I feel like there's been an opportunity to maybe think about putting more of the DevSecOps motion around the repository. We've talked about that in previous shows, but I felt like that was an opportunity missed. I 100%.
Thank you for bringing that up, Mike. That's a one, not only a wonderful point, but we know within, um, many of the, um, of, you know, GitHub, that there is vulnerabilities in code that we know about that we don't get rid of, that we just reuse over and over again. And this would've been a phenomenal time to do what we've been talking about with software de bloating, right?
And getting rid of code that nobody uses anymore. And, you know, quite frankly, isn't even needed. We have so much information.
I mean, cybersecurity is not just, you know, one of the things that I talk about is that there's so much out there that we can't grasp, we can't get our arms around, which in itself is vulnerabilities that we have just open vulnerabilities. So, yes, I think that they totally have missed this, and I'm hoping that moving forward, that they will really, I, I, I hope it's, I hope it's not over with, I mean, I hope that they really take this on. That would be, that would be such a huge, um, a huge help for, for cybersecurity people.
So thank you for the, and go ahead, Chris. Yeah, Alan, you're the host of, stop Me if I'm completely off topic here, but Right what you're saying, Kate, you know, I, as I, and we as Qwi looks at in the near future, we're looking at, you know, uh, adaptively, configuring, you know, so software for devices on the fly, because these things all sort of line up. You know, we, you know, whether it's our devices are unusable because they're so packed with apps and settings that getting them to work ever and never touching 'em again is our only goal as technology people having held the rest of the folks.
And to your point, because they're doing a million things they don't need to do. They're full of bloat and security problems and everything else. And I think with, with AI and the, the speed and the, and the complexity, if we can do the supply chain end to end, if we can do some of the other things, then, for example, saying, here's the code base, here's everything on, on GitHub, you know, trying to stay in, in the theme, and I want this device to do these things this afternoon, and put just that software on it, and actually do it, and stop saying, I'm gonna develop this stack and put it out there for seven years.
It's like, ah, no. Uh, yes, absolutely. I'll never forget, um, you know, being with IBM walking into a c, uh, CISOs and him, him saying, you know, cursing me out and him saying, you know, this can do so much, and I don't want it to do all these things.
I just want it to do X. Why do you do this to us? So to your point, Chris, yes.
I mean, wouldn't that be nice? I, I think I am hoping that cybersecurity becomes as easy as you walk into your home, you turn a lock, and that's it, that's what we need. And, uh, perhaps I'm delusional, but by golly, that's, you know, that's what I want in GitHub with, you know, going more into the Microsoft's, um, core ai.
Who knows. I mean, back to your point, Mike, I mean, you know, is it a lost opportunity? Well, maybe it's not lost yet.
You know, I, I, I'll tell you something though. When you think about how big a honeypot GitHub is, right? With all that code up there and all those accounts, I don't think they've failed its security as, as security failures go, there's a lot worse out there.
Could it be better? Yeah, it could always be better. Could always be better.
But I, I don't view them as, as being, you know, a sieve, you know, leaky, a leaky sieve here from a security point of view, they've tried, you know, will it be better as part of the mothership? I hope so. We'll see.
But I, you know, again, to Thomas Donkey's legacy, I don't know if that's gonna stick to 'em, that, you know, that it was, they, they didn't take security seriously enough. Well, we gotta talk about the scale issue here. I just looked up the numbers.
They have four 20 million repositories. The GitHub supports, they support over a hundred million developers. So maybe opportunity lost, I, I don't know if it, it's a hundred million developers or a hundred million developer Accounts.
Accounts. That's developer accounts, yeah. Is what it is.
So saying missed opportunity, okay, yes. But that's an opportunity. Solving it at a scale of 420 million repositories, and you could very easily p**s off your community, you know, especially developers when you start, you know, getting in the middle of their work.
Um, and yes, we can make code safer, but I, I'm just arguing to say it's easy to say, it's much harder to do. 'cause at that kind of scale, it'd be different if I was running a repository of, you know, 2000 different repositories and, you know, a hundred, a hundred thousand developers or 10,000 developers, whatever, the scale's so large. But, but I'm sorry, but can't we agree that there is, um, information out there that really is so old that we should just get rid of it?
Yes. There's also glass, um, glass. There's also, yes, there's also, uh, file servers with files that have infections and, and stuff in it too.
And we don't do anything about that either, Kate. So I, I'm not arguing that we shouldn't do this, but at some point, um, you know, is, is it, is it really GitHub's responsibility to clean up all that code? It's not their code, it's other people's code that they're hosting.
They have done things to clean up their own repository, their own things that they offer with, they've now are offering some security tools as part of their GitHub actions. Um, so I, I just, I think declaring that part of failure and, and blaming GitHub for it, I could blame a lot of people for that failure. I, I, I think you guys are onto something.
I think what we really need is bring out your dead code day once a year. Everybody just Is just a mon python. Python, python.
It's like a Monty Python thing, huh? Witch. It's not a French word, by the way, de bloat de all, I don't know anyone who ever deletes anything code wise, but, um, exactly.
Let's take a break. We're over time here. We're gonna come back to our B block here, CEOs at OpenText.
The next, the next trophy on the wall you're watching techron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks. Yes.
We're continuing to talk about CEOs this time. This CEO of OpenText is out, um, gonna be replaced by a temporary interim CEO while they go look for a new one. And the discussion that they seem to be having is, or the debate within the company is to what degree should they keep all these elements of OpenText that have been pulled together over the last few years, or start selling off some of these assets because maybe they're worth more independently than they are together.
This is not the first time this conversation is being had on any company, Allen. But, um, is there anything in here as you look at all this that says, Hey, maybe they have a point, or is the former CEO Mark Baria who built all this stuff as both CEO and CTO? Probably, right?
'cause everybody else is doing the same thing anyway. Yeah. So first of all, you know, Mitch, to your point about why do CEOs leave, this is a classic one, obviously, uh, change of strategy and philosophy from the board.
They said, mark, thank you for your time. I will tell you that, you know, I don't know how many of you out here are familiar with OpenText, but you're right, Mike, over the last 4, 5, 6 years, they've built quite the collection of, of, uh, bobbles software bubbles and SAS Bobs, they don't always all fit together nicely, but it, it, it is a, an an eclectic collection of, of assets. And some of them are more valuable and more profitable than others.
But Mark himself, I had the chance, I believe, to interview him once. He, he was a kind of unique guy because he wasn't, he was the CTO as much as he was the CEO. And that might be the reason why they have this collection, right?
Because at the end of the day, he was as geeky as any of us. And he was really, you know, he wasn't the business suit guy. He was the, he was the, the techie guy.
Um, and I, you know, and I, we've worked full disclosure Tech Strongs, worked with OpenText for many years. I love working with the company. Generally, they're good people.
They have so many different areas that they play in that you can really get lost within it. However, I'll tell you the, in my mind, the real story here is ai, AI is a threat to some of their business lights. They need to go all in on AI to keep their pro their, their profit centers profitable.
And my my thought was maybe they, the board felt Mark and his team were not moving fast enough to embrace ai. Um, I would Say they had a lot of AI initiatives, and they had this kind of notion of agents and trying to stitch together something that looked like a common UI across all these things. And it was an, an ambitious effort.
But it also seems to me it's really hard to do that across a bunch of Code that you, 'cause they're so disparate and, and they're also disparate things. They don't all kind of fit in like that. But if you look at who they appointed as the interim and the committee that they formed to, to run this thing until, I guess they bring in someone very sales oriented, very revenue orientated.
And, um, I mean, I don't wanna talk outta school, but I, I think that's where their focus is going to be, is, you know, increasing revenue and then also perhaps shedding some assets or some, you know, pieces that don't fit into this AI world going forward that don't, aren't core to the mission. You know, these are the kinds of things you start hearing. Um, they reported their financial results.
Not terrible. Um, I mean, open, I look, I, I happen to think OpenText is a solid company. I like them.
I, I do think some of the buying spree over the last couple years was a bit of Black Friday shopping and just throwing stuff in the card. 'cause hey, it was a good price. You know, will I ever use it?
I don't know. But it was a good price. Um, so the, I, I think there is some of that.
And I think also the board felt, wait, how long was Mark there? Like 13 years or something? Right?
I think they felt it was time for a change, and they wanted to go in a fresh AI direction. You know, Alan, it, it is multiple things happening here because they reported their financials and they actually were quite good. Um, their cloud revenue cloud bookings were up 32%.
Revenues not so much, but that's an emerging part of their business. And a, uh, they did a $300 million share buyback program alongside doing a, a dividend bump. But the fi, that wasn't the whole story.
They've been, they've been seeing a degradation or a decline in their full year revenue, somewhere between six to 10%. So while it's good, it's not pointed, you know, it's not on that upward arc, um, it's going the opposite direction. So there's financial incentive, there's discipline around portfolio, right?
How do all these products fit together? Or do we end up to selling to four different parts of the organization? And, you know, we have, we have trouble cross-selling them.
Let's make sense. Rationale, bringing these things together. So it looks like a platform.
It is a platform, and it operates like, like a platform. And shed the things that don't make sense necessarily to do. And back to what I was saying in the first segment, ai, it's, it is realigning.
They have to innovate on ai. They've done some good things, uh, to this point, and they've been doing it for a while, but they really have to double, triple, quadruple down on AI to stay in this race. Right.
Alan, do you think they go private because it's a lot easier to re-engineer when you're private than when You're public? Oh, I, you know what, I, no short answer. No, because, you know, to go private with the idea that you're gonna go back out public at some point, you know, Michael Dell could do stuff like that.
I, I don't, I don't see OpenText doing that unless there was some big PE company involved who was gonna take them private. Right? I don't think they would do it absent that.
And they're like seven and a half, seven, seven something billion market cap. So it's gonna have to be some with deep pockets to get Yeah, no, there's old enough of that. Yeah.
There's gotta be a big PE in there. Who's gonna take it? And, and, and if a pe and if they do do that with a pe, then it's Gordon Gecko type, right?
The sum of its parts greater than the whole green is good. I was, uh, full disclosure, I was part of the micro focus, micro focus transition into OpenText. And what I will say, what I saw within the company is there was a lot of talk about ai, but you didn't, you know, when you see trying to grab a bunch of different products, it's, it's not, it's too hard.
It's, it's too many systems to try to put together and grab, you know, and try to make some sort of AI strategy. So there were some good, um, AI companies that were part of that transition. But again, um, the focus beca, there wasn't a really, I think, personally a good understanding on how to take what they had and go forward with ai.
It became more about, you know, keeping the products, um, maintaining the products that they brought, and then how did they grab these pieces of AI and all these different products. And, and it just, it, it really wasn't a good strategy personally. And so I, I think you'll start to see things sell law.
I, well, that's what I would do. I, I mean, you look, micro focus itself was a bit of a conglomerate, right? Brought into another conglomerate.
So there are, there are a lot of disparate pieces here, I'm not sure. And, and working with OpenText all these years, I don't even know all the pieces. I don't know if they know all the pieces, how it all fits in.
I don't think they do either. Because, yeah, because I mean, they really have some amazing products. Yes, they do.
Um, but at the end of the day, I just, I don't think you have somebody who understands all that's out there and then to bring it into a cohesive strategy. And again, you know, there are some things that you shouldn't have. I'm, I'm a big believer of getting rid of things.
Um, there's just some things that you just need to let go in order to move fast. And yeah. So we see you wanna delete old code blasphemy, I tell you all great product and delete it and see who notices.
That's what we'll do. Still can't believe that. Alright, let's take a break here on Textron Gang.
We're gonna come back and talk a little bit about China syndrome. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Hey, folks, we're back in the Trump administration is added again. This time.
We're gonna see folks in China who are using GPUs from Nvidia and a MD are gonna pay a 15% increase. I guess they're paying that, or I guess maybe a MD and Nvidia will just pass that back to the government directly. But the United States taxpayer is gonna be the beneficiary of all this.
And I have a lot of questions about how all this might play out. But Chris, from your side, um, as a quote unquote American, um, do you look at this and say, um, well, does this just mean that there's gonna be more demand for those GPUs outta China and the overall cost of those GPUs is probably gonna be higher anyway, so we're all gonna pay more for these GPUs. So why wouldn't everybody just salute and say, well, this is great for Nvidia and a MD.
Is there anything else to say more than that? I don't know. I mean, it, it, yeah, you, you, you've, you've taken all of all my points.
You know, I don't see the sense in this, I don't see it achieving any of the goals necessary. Um, yeah, the best I can do is, is, so tomorrow, um, I'm on a panel on Salt Typhoon with, uh, CS two ai, Derek Har in that crowd. And I, I've been looking at it.
What I gonna say about that, and I think it plays to this, right? So Salt Typhoon, is everybody not familiar as this Microsoft name for this? You know, what, if you read the articles, there's new Chinese, you know, uh, attack against infrastructure, but it's not, it's the accumulation of 30 years between the difference between what, what people like me and Kate, you may say in our premise, you know, in the most extreme security people, it's the difference between that and what we've actually done.
It's just gap. And China has just inhabited that and just, you know, and it's not any one thing. It's millions of little log files that are slightly changed, little configuration slightly changed.
So we take AI and put it into that. And my summation is that the Chinese government right now could play our infrastructure like an orchestra. Like literally just, uh, you could literally, you know, take play chi chi, uh, chi I play, but like, can say it, right?
Uhhuh. And, and it's, uh, so yeah, we just dive into this sort of GPU war thing. I don't know.
I mean, that's, does that make any bloody difference other than, you know, moving some money around to places that I think aren't really great places for that money? No. So, Mike, I, I've got a few things to say on this one.
There's a lot to unpack here. First of all, you said John and Suzy Q taxpayer are gonna be the beneficiary of this. I didn't see anything about where this money's going and where it's going to be spent on.
We don't know. Is this going into some slush fund to pay to stop illegal immigration? Is this Iran contra to, is this, who the heck knows where this money's going for to, or, or what it's gonna be used For?
We're, we're, we're using it to demolish the Rose garden. Didn't you hear? Well, No, that's already paid for by private donations on the East Wing.
But, but here's the issue. And I wrote, I wrote the, one of the articles cited here. You can't talk outta one side of your mouth and say, we can't send this technology to China.
It's, it's strategically important. We cannot send this stuff to China. We gotta put in controls.
We can't, we're gonna sanction any country that plays like man in the middle forwarding this technology to China, and then all of a sudden say, oh, wait a second. Did you say 15%? You could have it?
Hey, I wanna buy a nuclear bomb. I'll give you 25. Yeah.
Can I get, can I get a missile? That's, And, and per and personally, Alan, when I read your article, I'm not just saying this, I thought you're spot on. Absolutely.
100%. It's, I personally, and, and Chris, I, I mean, I unders, I, I really, it to me, I feel like we've just given the Chinese the advantage and well, we've Proven what we are. It's just a question of the price.
Yeah. I mean, it's not just the Chinese when Russia offers, right, Right. Or, or someone else.
Or, we're not for sale. We're not for sale. We're not for sale.
Well, Alaska might be up for sale. Well, we, we bought it once. Let's not sell it back.
He's meeting was, we worked for sales, I think is what you meant. But, but here's the other issue, guys. The other issue is just from a separation of, of church and state, and I'm not talking about church per se, but the US government is not a shareholder and partner in private companies.
You know, I, I, I, I'm a, I, I'll have to admit, I'm a political science major. I went to college a long time ago. One of the things they taught us about what was the difference between socialism, capitalism, fascism in fascism and socialism, which of course is including in communism, the government controls the means of production.
Right? And capitalism, private companies control the means of production when the US And, and that's my bigger problem here. It, it's, it's the problem with calling for the firing of Intel's, CEO and everything else, when the government is heavily handed, be in the operations day to day of private companies, you wind up with Putin's Russia, you wind up with the, that's one model you wind up with the Chinese Communist Party being the, the big brother of the Chinese capitalist system, if you want to call it a capitalist system.
That's another model. Neither one of those models are anything that resembles what America is or was. Right.
And Alan, I, I totally agree. I, I mean, this is, I think one of, I mean, if we're not sounding the alarm a about this, I, I, I was not a political science major, but I am so concerned about, you know, the government getting involved in, especially in business, that they don't understand. I mean, quite frankly, who un, you know, who understands.
Uh, there's, you know, we keep throwing tech people, and I think one of the failures personally is that we are putting people in place that don't really understand the technology. And it's like, well, it's, it's a big deal. So the silliest argument that I've heard about all of this so far is that when you listen to the Chipmaker say, well, we need to sell these chips to China.
'cause otherwise they'll just go out and reverse and engineer them, build them themselves. They're going To anyway. They're already going out to build them themselves.
They're, they're going to anyway. But let me, let me give you a more sane counter argument. Mm-hmm.
And it comes from Mark Cuban, right? Mark Cuban came out and said, Hey, what are you guys upset about? We just did what we've been trying to do for a very long time.
We increased the corporate tax rate by 15%, right? Mm-hmm. So if we start charging all of these, so it's almost like a reverse tariff.
We don't charge you to, as a foreign company, to bring in products to us. We're going to charge you an export tax to bring products to them. Now, in this case, it's very selective, but if you took that at a broader level and just added, any American technology gets a 10 or a 15% tax added to it, and that money does go into the general treasury and not the Donald Trump Presidential library.
Um, you know, mark Cuban says, that's not a bad thing. So, no, Alan, though, I, I think the mistake that we make, and I'm not, I'm trying to say, I'm trying not to say that just to be critical of Trump, but we, we want to impart on him, uh, political ideology. He does not have a political ideology.
He is a deal maker. He will sell it. Hey, I'd like, I'd like to sell you this table.
Remember interviewing salespeople. Yeah. No.
Sell me this table. Should we sell me the pen? The pen?
If I, if you'll buy that pen, I'll sell it to you. Right? Right.
And, and you combine that with nationalism of, that's really in populism. That's really, if anything, aligns with some kind of an ideology, you know, the right terms better than I do from political science. But I, so I think, you know, it's like anthropomorphizing uh, robots and humans.
It's like, we're putting on this, what's his, why doesn't he, why does he do this? It doesn't fit our ideologies. 'cause he doesn't have one.
So, I mean, there are maybe a few advantages if I try to put lipstick on the pig, is, well, at least China's paying the, uh, the 15% directly instead of us paying the tariffs and into our coffers. Where that money goes is probably into the Republican National Committee or some damn place like that. Who knows where it goes.
But I, I think we, we live in a world where there's not one model of what he's doing. He's doing every model that he think he can spin. And we'll see what comes out with, with Russia.
You know, Russia may be making chips as of Friday afternoon for all we know. I, I'll, I'll go for a, a pig lipstick on this one. Right?
So to be clear, this, this is, this is all incredibly stupid and bad for actual security and national security and everything else. However, um, as a security person and as an American, I think both of those are true. You know, I have lived my entire life saying, okay, right now, and you seen my boats, right?
You know, arcade storms. You're never gonna get all the perfect things. You work it out.
And this is an exercise of what, you know, whether our system can survive, you know, aggressive, intentional incompetence is the wrong word. You know what, what if our government did the exact opposite of everything we did? If we can still survive, that really proves our point.
Right? And this, Kate, to your point about the, you know, yeah. So the whole GPU salt typhoon thing, this absolutely plays into China's favor.
Let me say that in public, nothing here is good for us national security at all. But I didn't assume that China wasn't gonna be able to get GPUs in the first place. Right?
I think there is ways to address salt typhoon, and they don't actually require any government support or a lot of money. So if this, if nothing else, this forces us to evolve into the available cracks, which in this case, I think are the right ones. But for stupid reasons, I mean, to be clear, it's not, this is not, this is not smart Is political.
I don't see how a 10 per 10 to 15% increase on the cost of US products overseas is good for business. Because ultimately it will drive people not to buy our stuff. Well, No, it incense them to reverse engineer it, Right?
Yeah. And that's what they do very well. Yes.
Mm-hmm. But, you know, it shouldn't be lost on us that the week before this was announced, Jensen Wong was in the White House having a private one-on-one with Trump. And I'm sure they cooked this up, and Donald said, cut us in on a piece of the action, and I'll let it happen.
I'll call my people and make it happen. This is, this is like going down to the Bergen Hunt and Social Club in Little Italy and, and making deals. Well, we, you know, we are, we, we do have kind of, we're involved in these companies now.
Just take the US steel sale that occurred. Yeah. We have a golden share in that way.
And one share, which is basically veto on any decision we don't like. It's not a financial share. It's, it's, but it's control.
It's socialism or fascism, both sides of the spectrum. It it's government control of the means of production. Exactly.
So it could say, I don't like that deal you're doing with whoever, or I want you to favor this company or this country over that one. So what are you gonna do? You're gonna follow Nice, nice GPU Business.
You got there. It's shame if something happened to it. Yeah.
I'm telling you, like, I'd like your blessing to sell this olive oil. All right. Um, That's all I'm gonna say.
I'm glad no one raised their voice here. And we, we remain calm in discussing it. And I will tell you the truth though, with everything that goes on, I wonder why people are not in the streets More.
Yeah, I agree. Mm-hmm. It is what it is.
Well, I, I, I think that's because, you know, the other situations that's going on in the world, it's August and all the criminals are like, well, they're only gonna be here for 30 days. We're on vacation. We'll see you guys in September.
Could be. And it's really hot out there right now. Yes, it is.
A ask the National Guard troops patrolling DC Yeah. All right. Let, let's not go there.
Hey, this has been a great text gang. Kate, Chris, Mitch, Mike, thanks for joining. Thank you for watching.
As usual, we have a whole bunch of good, uh, text strong TV content behind this, including some of our Black Hat coverage from last week. So check that out. We did some really nice interviews on the show floor there, so check that out.
We'll be back tomorrow with more gang and more good discussion. Until then, everyone have a great day. This Alan Hummel.
We're out. Hey everyone. Welcome back here to Techstrong tv.
So we came off of that crazy show floor to our luxurious broadcast suite here at the Luxor Hotel. MGM Tell my wife I love her. Yes.
Um, but thanks for joining us in our continuing Black Hat 2025 coverage. My next guest really needs no introduction to, to security people and, and, uh, our audience at Techstrong. It's my friend Rich Mogul.
First of all, rich, welcome back to Text Drunk tv. Thanks. Thanks for only the best for you, rich.
Only the best. But, um, thanks for coming up and being with us. I appreciate it.
Rich. Of course, you're at Fireman. Yep.
You know, I forgot your title. Is it VP of Cloud Security? S VP of Cloud Security.
You got It. SSP of Cloud Security. The S is for special.
Well, you know, I wrote an article last month. The S in Vibe, in Vibe coding stands for security. And, you know, that brings me up.
Remember we did a podcast once with the CEO of MongoDB. I'll never Forget that. Me, I bring it up all the time And I talk about it all The time.
And why not is that, is no sequel, mean no security. And they said, we'll have security. When our customers asked Was their answer, and then everybody got breached and then they added security.
And I think the same thing's gonna happen with Vibe. Yep. Coding Agree.
When people start demanding security, they'll do something about it. But until then, as I said, the s and vibe coating stands for security. Um, but Rich, you're at Fireman as we mentioned, but of course, if you know Rich Long distinguished career as a Gartner analyst covering the, uh, Data security DLP DLP space.
Yes. Yep. That, that, well, those were my days.
Those are my years. DLP and stuff like that. And then of course, rich and our good friend Mike Rothman went on to found, uh, Securosis.
Yep. Uh, kind of reset, broke the mold in security analyst firms over the years. And then you guys, rich, you were the primary driver of, of a product vision that that came out and that's how you came to Firemont.
Yeah. So they, uh, acquired our startup Disrupt ops mm-hmm. About three or so years ago.
And, uh, yeah. And then So it's been a ride. It's been a ride, my friend.
It's, uh, yeah. Any little corner of this industry you could hit. I've probably, I'm, Well, you know, I always like to think it's a round room And there are no corners.
But you're, you're right. We've been there. But you, you wanna know the nice thing coming to Black Hat?
Our next guest is in the green room waiting for us here. Fred, I've had a chance to meet so many people and you've met more, you know, more than me. And, but we've met so many people and you come to this or you come to an RSA, maybe twice a year, we get together and, uh, it's good to see these people.
I mean, some of these relationships are 20, 25 or more years old. I've Known you for over 20 years. Absolutely.
I'm ashamed to tell you longer than that, my friend, because I think the first security bloggers network was over 20 years ago. Party. Yeah.
I think it was 2003. I, I'm bad at math. No, I know.
Well, I, it's easy 'cause we're in a 25 year, so it's easy to say what 25 years is, right? Yeah. But next year it'll throw me off.
Anyway. Hey Rich, we're here to talk a little bit about Fireman, though. I think most of our audience knows Firearm, but for those who maybe aren't, why don't we start there at that 50,000 foot level?
What, what is Fire? Yeah. Firearm focuses on security operations, and the area that we're most focused on is network security policy management.
So NSPM is the core product. Uh, we do also have, uh, my old product, which is a cloud security posture management product. Uh, we have an asset manager product as well.
Okay. And if you have really large, complex, uh, it doesn't even need to be really large. If you need to manage firewalls from different vendors, different environments, make sure those things are all compliant, uh, fireman is kind of the best at that.
Yep. And just, you know, to serve as a cybersecurity historian, fireman, of course, was spun out of Gary Fish's, fishnet security. The CTO of Fishnet was a guy named Jody Brazil, Brazel.
And, and Jodi, they spun it out as fireman. And Jodi was the first CEO he left for a while, but he came back. He's still CEO.
Yeah. So it was, uh, it was a pretty wild story. So Jodi invented it, basically because he was doing these consulting projects and he did the, let's see if I can automate myself out of a job thing.
Mm-hmm. And he came up with ways to do automation, connected to all of these different firewalls and have this consistent policy enforcement went to Gary. Gary spun it out.
So Jodi was, he was the tech founder. Everything became CEO. Now, when he left after some, they got some external investment years later, uh, I was his next startup.
So he was my co-founder of Disrupt ops, uh, him, Brandy Peterson, Mike Roth, and Adrian Lane. We all founded this company, disrupt Ops. And then Firemont acquired Disrupt Ops.
And it was like a reverse merger because Jody then took FireMon back over again. Right. It's an, it is an interesting story, but, you know, politics makes strange bed bed flows.
Yeah. And security stories are constantly, you know, strange. It's a strange industry.
And circular. And circular. Right.
Exactly. No corners. Um, but Rich, I, I, you know, speaking of network policy management and I, I left a a, an A, uh, an initial outta there, didn't I?
It's NSPM network. I worked Security Policy Management. Yep.
Fireman recently put out a report. Yep. Talk to us.
What's it about? So, Uh, we had this new product called Insights. Mm-hmm.
And well, you know, kind of product kind of feature. So we actually leveraged some of the stuff that I had done in cloud as the base platform for this, or me, our team. I mean, it was 30 people won't get acquired.
But, uh, the insights product for customers that are willing to share the, uh, um, use this, it uses their data and does analysis to help them optimize their use of their firewalls. So it gives you all this really wild reporting and stuff that nobody else has seen before. Well, we found out that there was, uh, some interesting things that we didn't even know, because historically we've got our little silos of customers here, here, and here.
And we had a way to look at kind of the data in the big picture. Now again, all privacy preserving customer driven, like, let's, let's be careful we're not stealing our customer's data, but we found that like 90% of firewalls had, uh, critical policy failures. And what, what do we mean by that is it's a compliance failure, uh, and obvious compliance failure.
And it can be anything like somebody left Port 22 open where that shouldn't have been. Or, uh, clearex protocols where it shouldn't have been or, or anything along those lines. So those policies, and, and there are standards around, like PCI, for example, we map those specific firewall rules to what PCI requires.
And there were that the high degree of failure, but then there's some, or sorry, it was 60%. I'm gonna cheat and pull my numbers up. 60%.
Okay. The high severity compliance checks, the 90% is actually 95% of numbers, uh, Falling short of critical levels. Yeah.
Well, it wasn't even that. It's like inefficiencies. So 95% of the application objects that people define, so you can define application objects and firewall rules weren't used.
Right. So you're turning on, you're burning CPU cycles. You have these bigger, complex policies that are gonna be problematic to deal with, and, uh, point And you're not in compliance, that you're not secure.
Yeah. So here's what I find not fascinating, revolting that, you know, I've known about fireman since he spun it out. Yeah.
I remember going to Kansas City and talking to them, um, and we've had firewalls, next generation, firewalls, web application firewalls, this firewall, that firewall. We've had companies like Fireman and, and some of their competitors back in the day two Finn, and, uh, I forgot the other one, I forgot 'em all, But whoever they are, but, you know, that have preached firewall policy management religiously for 15, 20 years. Well, it's In every audit and every assessment.
So why, why do we still deal with this? Why are we still, it's ai Help me. Yeah.
Right. I mean, can AI automate this once and for all? I mean, and we actually have some of that available in insights to help you, like, explore your environment.
So we have an AI chat bot up there, uh, which you didn't even know when you asked me the question, but the, it's more of, um, so this was new to me. Like even though I've been in security forever, I haven't really dug into firewalls too much. And, uh, after the acquisition, even though I'm very cloud focused, uh, some of what I had to do also began having to focus a lot more on the network security angle.
Specifically. There's so many reasons why. One is like somebody will put a rule in to get something working.
Mm-hmm. And they'll forget to take it out or manually trying to manage these rules in these heterogeneous environments. If you have, you know, checkpoint and Palo and Cisco and Fortinet, and a lot of organizations do, and even if they try to standardize on one, then they're gonna acquire or have a merger or something like that, and they're gonna get other ones out there.
So it's just creates all of these extra levels of complexity. The other is, is when you're dealing with these at scale, the process of manning managing those rule changes and pushing those out to where they need to be, I, it blew me away how much goes into that. There's organizations that literally have dozens of people dedicated to just managing firewall world changes.
And it's not an exaggeration. I, I was like, wait, you have how many people? And I'm like, don't you have any automation?
They go, yes, this is after the automation. These are all the exceptions. 'cause some of these orgs just have these, you know, incredibly large, complex environments.
Oh, absolutely. And then the mid-size, they don't have enough people to manage what they do have. And that's also been a problem.
Yeah. Forever and ever. Right.
But that's why we love the insights, because that is exposing information to them. That was, that data was al always there. But within the, the market, like, we weren't providing that in a way that was like impactful.
Like, you can go to your CEO go, we're failing 60%. I mean, that's the average in the report, not the 90, I said at first. Right.
The 60% we're failing 60% of our compliance checks, uh, you know, that are higher or above. Mm-hmm. We're, we have 95% of our application objects aren't even used.
Like that's just wasted space and added complexity. Yep. So that's the kind of stuff that was like the, I'll, I'll be honest, when our team saw the results, they were like, oh, this is really good.
Well, it's good for fireman. Right? But well, yeah.
It's bad for what's going on out there. I think you pulled the 90% number, 60% of enterprise enterprise firewalls fail high severity compliance checks. Yep.
Another 34% falling short at critical levels. Yeah. So that's where you probably got 90, 95%, 94%.
I wanna pivot if we can a little bit. Recently Fireman announced an integration with Illumio. Yep.
The Zero Trust. And of course, alum Illumio is the leader in the segment network segmentation market. Let's talk about that.
Yeah. So, and that was, uh, actually what one of the things that I was involved with, so that was, uh, kind of the products that I work on with the Illumio integration. So we're not releasing all the specific technical details around this, but when you're using these microsegmentation products and you have traditional firewalls and other network security controls in your environment, uh, there can be conflict.
So a lot of time, the reason an enterprise is gonna bring in Illumio is because of, uh, a couple of different things. Maybe not enough firewalls where they need deeper segmentation, you know, and there's cost effectiveness becomes a factor there. Uh, you can't necessarily drop boxes everywhere in.
And then there's also the additional layer of what products like Lumia are good for is they start giving you a better ability to manage rules based on what something is, as opposed to firewalls, which were designed purely to protect a good network from a bad network. Well, the problem that you can encounter is that for products like Lumio at work, they have to have agents everywhere. And so there's a couple of different layers of issues where you, you can potentially run into issues.
One of those is, uh, imagine you are a hospital or manufacturing or other facilities. You can't always install agents on everything. Mm-hmm.
And so you're still gonna need the firewalls to provide the rules, uh, around protecting those objects. But you still want it to work well with Illumio. So what we've done a lot of the, and as we announced more about this, get out more details, but it actually can glue together the firewalls and illumio in intelligent ways so that they can actually be more compatible.
The other issue is, is what if you want your, uh, lumio assets to talk to each other, but you've gotta get across the firewalls. And sometimes that can be a problem as well. Sure.
So those are like the two most common problems that we've kind of built this to, uh, go ahead and be able to address. And, and that's why it's great 'cause we can get to the asset level, attribute level security, and we can do it with your existing firewalls and then, and have that also work with the microsegmentation with Got it. Now look, it's a zero trust play.
Yeah. But we should also mention it. It is, uh, it's, it's about resilience too.
Yep. Right. And, and that's a big thing, right.
You know, people may not associate, uh, network security, uh, posture manager NSPM with resilience, but that's part of the resilience model, right. Is try to contain Yeah. Where we, where we, where we're threatened, where something goes on, right.
So we don't lose the whole ship. Yeah. Being able to respond more dynamically.
So there's that security, resilience Mm. Play. And then there's also the resilience of what if a firewall goes down or this goes down or that goes down, and being able to actually, you know, have the ability to like, update your environments to account for those kinds of situations.
Yeah. And, and it plays into the zero trust thing, which I, I think is finally, you know, with all due respect to John Kinder, that guy who was talking to John a couple weeks ago, a lot of people poo-pooed it and gave it a hard time, but it's really become part of the concept. Every, every company I talk like I had to do a bunch of research for our new products that we're working on.
And uh, it blew me away that they all had some kind of zero trust initiative. Yeah. It's, it's the way it is.
Yeah. It's the way it is. Anyway, rich, I think we covered the topics that our corporate overlords have, uh, asked us to, to cover.
Is there anything else that we missed, you think or? No, it was, uh, I mean, pretty good. The, uh, you know, tying in a little bit back to the zero trust piece of it too.
The part as I like, like you, I, I poo-pooed some of the early stuff. Uhhuh, let's, let's be honest, we all Did. Yeah.
And, but I've come around on it because, uh, particularly now, because we have all this complexity, uh, that's been added to our networks with cloud and with containers and, you know, ephemeral, virtualized assets and everything else. And like a lot of our security models just haven't worked for that on the network security side because it's port protocol source destination. And as somebody who's very cloud centric, this has been the, I had forgotten how much harder a problem.
It's in a data like cloud. I have a lot of capabilities. I can do all these.
You Thought, and that's funny. 'cause initially we thought we didn't have that in the cloud. Yeah, right.
We didn't have enough control, we didn't have enough insight. We didn't have enough ability to manipulate what we needed. But now you're saying, you know, I'm so used to doing that, that the stuff in the data center is a lot harder.
It is a lot harder. But some of those principles, like in cloud, I can very easily write rules that refer to the assets or the attributes. I mean, that's a really powerful part of this.
Like this asset with these tags connect to this thing over here. And those are things that we have really struggled intensely with in the data center. And so, you know, either with our, you know, bringing that asset intelligence and doing it in a way that works for enterprises, like that's a big part of all of this is, is really easy to show this stuff off in a lab.
Agreed. But you go into some of these large, It's a real world And our clients are huge. Some of these environments.
Oh, I, I remember that. I mean, I, you know, I know the firewall story. What, what freaked me out and when I first became from really familiar with Fireman, is you had customers who had dozens, if not hundreds of Firewalls.
Hundreds or thousands is not uncommon. Yeah. It's crazy that have to be managed and now in multiple locations.
And now you've got a layer in cloud capabilities, like understand the cloud network and then harmonize the cloud network with the on-premises network. Um, because you've got all this hybrid stuff that needs to talk to each other, and yet in the end, we want this thing to talk to this thing and not talk to this thing. It's A relatively simple thing, right?
Yeah. So that's where like this lumio partnership and other things that, you know, come out someday, being able to have more of an ability to kind of make those decisions, uh, and have that, that higher level intelligence so you're not down to a five couple of firewall rule anymore. I get it.
Hey Rich, we're about outta time. I appreciate you coming up here to the thanks for having Faj Mahal and, uh, Am I allowed to leave? Yeah, Yeah.
No, you just, you gotta see why is there plastic shady, Yeah. Corner there. Yeah.
We're gonna edit all this out, guys. Um, just make sure you stop in the bathroom. Wash your hands real good.
Okay. Rich Mogul Fireman here at Black Hat. We're gonna take a break.
We are going to continue with my friend Fred Wilmont coming up next on Textron tv. Hey everyone, welcome back to our Techstrong TV coverage of Black Hat. This is actually the last scheduled interview.
We're gonna do a black hat 2025. So if you've caught our previous ones, great. If you haven't, you know, through the magic of the internet, you could go back and uh, click on them.
But let me introduce you, uh, to my next guest. We are here at the Push security booth, that's Push Security. And my guest is Tyn Erasmus.
That's right. Yeah. Hey, how you doing?
You know what, after two days and 30 interviews, I got your name right? You Did. I'm impressed.
I'm doing damn good. Damn good. Tyn, welcome to Text Strong tv.
It's great to have you on here. Cool. Thanks very much.
So besides the cool name, tell us more about yourself. Cool. So yeah, I am, I kind of am a, a computer engineering graduate from, uh, quite a while ago.
And really I've, I started my career in, uh, pen testing. So I worked for pen testing companies and really kind of worked on the red teaming and offensive security side of, of security for probably about half of my career. Uh, yeah, did a lot of security research, one mobile phone to own written books.
So kind of done all the things on the offensive side. Uh, and then really kind of got to a point where I, I always, always enjoyed, um, writing hacking tools. Um, and then I kind of switched focus onto the defensive side and started making cybersecurity products.
Uh, and uh, yeah, that's kind of led me into my journey into, into push security as well. I love it. What a and that is, so that profile right there is almost the perfect black hat profile, isn't it?
That's probably, there's 19,000, 20,000 people here. 5,000 of them. Well maybe not writing the book, but 5,000 of them have done that Red Team journey.
Offense defense, they've switched from vendors to, to end users. Yeah. And, and everything And in between.
What's your current role here at Push? Cool. So I'm one of the co-founders of, of push security.
I wear the CTO hat. And so yeah, day to day it's really just about, uh, building a product with a team that actually matters and, and makes an impact and, uh, stops the attacks. And so yeah.
It's, uh, day to day is really kind of in the, in the weeds with a team and, uh, building the product. Well, with your background I would expect that, right? You, you.
But, you know, being a co-found, I've co-founded four companies myself. Wow. Venture backed and, um, you know, being a co-founder, you don't always get the opportunity to do those kinds of things that you like mm-hmm.
'cause you're busy doing co-founder things like talking to investors and boards Yep. Key customers. Yep.
Chief people officers and, and playing all of that game that, you know, even now I'm the CEO at Techstrong and it's not my favorite things to do. Yeah. We, we always joke and say we get the jobs that, uh, no one else wants when, uh, you know, the hardest thing in the company, that's your job Absolutely.
For the next few months. And, uh, Well, no, no. Sometimes it's the lowest, you know, I'll tell you a quick story.
When I was a little boy, my dad, my dad owned a, uh, a restaurant and one summer I was young, maybe 12, 13, 14 years old, and I got the bright idea I was gonna work that summer and make some money. And he said, sure. Come in.
And that first day he said, uh, you gotta go mop the bathroom. And I said, dad, I'm your son. I don't mop the bathroom.
You got pe. He said, no, if it's going to be your business, you gotta be prepared to do every job there. Yeah.
Yeah. Because that's what it is when you have your own business. Yeah, Yeah.
The chef and the dishwasher Yeah. And Everything in between. Exactly.
Yeah. And I'm sure you're living that. Um, anyway, let's talk about push security.
There aren't a lot of, you know, there aren't a lot that we, I, they can't see 'cause they're looking this way. As you and I look out, there's a sea of of security companies here. Yeah.
And not everyone at home knows every company. Some may know push, some may not. Mm-hmm.
For those of us who are not familiar with push security, tell us about push. Cool. So Push Security is a browser detection and response company.
So that's a, a lot of, uh, words to say that basically we see ourselves as an EDR in the browser. And, uh, you know, you may ask yourself, why do, why does anyone even need that? What does that mean?
And, uh, yeah. I suppose this really comes down to the trends that we've been seeing over the last few years. Um, EDR has really matured.
Um, and yeah, it's, you know, so attacking endpoints has become quite difficult and attackers are really opportunistic. They always go the past of, of least resistance. Yep.
And so really what we've started seeing is that attackers try their best now to stay off the endpoint. And because there's, you know, the, the, the tooling there is really mature. And so they've started executing attacks that don't touch the endpoint at all.
And, and really what that boils down to is, is identity attacks. They're finding really unique ways to phish users to do MFA downgrade attacks, to deliver malware in very, uh, you know, unique ways using the browser. But yeah, at the end of the day, a lot of the attacks that people are seeing end up happening in the browser.
And so that's why we are a browser extension that people deploy out into the browser. And so yeah. We we're kind of just stopping attacks where they happen.
Absolutely. And that's the kind of premise. Yeah.
Well, look, You get in a world where people sometimes work on Chromebooks mm-hmm. Or tablets Yeah. That, you know, are, let's call them non-traditional endpoints.
It's not the OS per se, Chrome os Yeah. But it's not Windows, it's not Mac. Yeah.
And when the browser is the interface for the applications that we run and use. Exactly. Yeah.
It only makes sense that, that you, you gotta go where the, where the bad guys are. Exactly. And, and, and, you know, work kind of happens in the browser now.
I, I'd say like the majority of people's everyday work is just no doubt in the browser. Uh, and so really what we've seen is kind of this shift as well from having internal networks where people kind of log in over VPNs to basically people just being, having a laptop connected to, you know, 50 or a hundred whatever SaaS applications. And so really we see ourselves as that kind of layer between the user and the apps that they use.
We can see where they're logging in, how they're logging in, do they have MFA enabled on all of these things. Um, that's kind of on the proactive side. And then on the reactive side, are there applications or websites out there trying to phish them?
Um, yeah. And do all of these kind of novel attacks against, and because we're in the browser, we can see all of that stuff. Absolutely.
Now, you mentioned this is an extension for the browser. That's right. So I'm gonna assume it works in Chrome.
Oh, yes, yes. It works on all the browsers. Uh, yeah, we, Well, I'm glad you brought that up because it works on all the browsers today.
Yeah. Chrome, safari M Firefox, yeah. Et cetera.
But we're about to see a new generation of browsers mm-hmm. Right, perplexity. Yep.
What, what is it called? Cosmo or, Yes, yes, yes. Uh, I know what you mean.
All those kind of AI browsers, Open AI is coming out with a browser. If you believe the hype, it's gonna redefine Yeah. The browser experience.
Yeah. Have you guys looked at that yet? Yeah, definitely.
We, we, we keep a, a close eye on all the new browser variants that come up, but yeah, I, I suppose like all of these things that the end of the day are all just chromium based browsers. Yes. And so, you know, they may have a different setting that you need to set in order to force install extensions, but at the end of the day, they're all just chromium.
And so we all support them too. And that, That's the beautiful thing about open source Exactly, isn't it Exactly. Is they all have that base.
We kind of, we develop it once and you, you kind of end up hitting a lot of browsers and all of these new browsers that are based on chromium as well. Yeah, Absolutely. Alright, a couple other questions then I wanna jump in.
Yeah. Uh, so they, I'm assuming you could just get this in the, in, whether it's the Chrome store or the, or the Safari, uh, marketplace or whatever, it's just a quick download install done. Yeah.
So, so actually, um, in order to install it, people would have to kind of sign up on the website first, and then you can, you present it with a few options of different ways to install it. You can see, uh, I want to use MDM or GPO or one of the many ways to install extensions, and then it kind of guides you through the process. Okay.
And so, yeah, uh, it's generally Not, so it's primarily through the push website? Exactly. Not the marketplace.
If you'll, yeah. So, so the marketplace, the, the, um, push security extension is on the marketplaces, but kind of if you go that route, you don't really get the, the guided tour on how to extension, but on how to install it. But yeah, exactly.
There are on the, on the stores. Excellent. But it does beg the question of what is the website?
Yeah. com. Excellent.
So you can go check it out. It's also free to sign up. Um, we give 10 free licenses for people to go have a play around, see if it's suit to, uh, you know, try some identity attacks, uh, try some SaaS discovery, kind of hit the use cases you're looking for.
And, uh, yeah, I love it. All right. I'm going to switch gears a little bit.
Let's come back here to Black Hat. Yeah. How's the show been?
What are you seeing? What are you hearing? What is Push security?
Talking about a black hat? Yeah, so it's, uh, it's uh, been an interesting one. It's been a big one.
We've seen a lot of foot traffic through the booth, which has been good. Um, yeah, I, I suppose from, from our perspective, the, the things that we're really seeing is that people are really starting to pay attention to the browser. Um, you know, in, in, in previous years, I think it was, uh, quite a foreign concept to people.
You know, people think of the, the, the magical triad there, network logs, endpoints, uh, and then maybe some cloud. Um, and yeah, I, I think it's really becoming quite commonplace for people to see the browser as a unique place to get telemetry from a unique enforcement points. And yeah, there's, there's actually been quite a few players kind of popping up in this space as well.
So, um, yeah, it's definitely been interesting from, from that perspective for us. But yeah, our, our, um, kind of what we've brought to Black Hat this year is just, uh, a whole new bunch of features that we're showing people. I think, um, one of the really interesting ones is we're kind of one of the first, uh, companies now to also bring this to, uh, to mobile devices as well to this, uh, where, so we've got a, a Safari extension, uh, that runs on iOS devices that we've been demoing as well.
So yeah, we are, we're kind of, um, yeah, been kind of showcasing some of the, some of the new stuff, uh, mobile. I gotta ask you about ai, what anything there would push using in regarding ai? Yeah.
Yeah. So I, I must say, like we, uh, if you kind of look around our booth as well, uh, we don't really like to push AI narratives. I think, I think at this point it's, uh, it's kind of become a, a bit of a nothing word to add onto things.
So we, we try to, uh, stick, uh, clear of that and just really give practical, uh, you know, does what it says on the tin, uh, type, uh, defenses. So you're, you're not trying to surf that wave? No, I, I would say not like, you know, we, we, we do a lot with AI in the product.
Uh, we can detect usage of ai, uh, for, for customers. So yeah, I, I suppose there are ur ai use cases that we cover, but, um, no, we're certainly not trying to, trying to ride that wave. I got it.
Um, what are you hearing from people? You said there's a lot of booth traffic. I've seen a lot of booth traffic.
I was here this morning actually, and talking to my friend Chris, and, uh, what are you hearing from people coming by, coming in and talking? Yeah, I, I think one of the, kind of the coolest things that, that I've seen is, um, you know, once you've kind of seen this data, you can't unsee it. You know, I, I, I think we provide a really unique, um, vantage point as well.
Um, and so once people see like, okay, so across all of these apps I can see, you know, MFA status, I can see people reusing passwords, I can see stolen credentials, like people are using credentials in that same credentials have been stolen on, on, on the dark web. Um, and kind of just the way that we can detect and respond to attacks and the telemetry that comes out. It's been really cool.
We've had some really positive feedback on just, you know, like, it's such an obvious, um, insertion point, uh, to be in, in the browser. And so I, I think people are really kind of having their, their eyes open to the possibilities of, of being inside the browser, which has been cool. Excellent.
I, yeah, I think we've covered, whoop, sorry, I dropped my mic there a little bit. I think we've covered, I think everything I wanna say, but is there anything else you think we wanna share with the audience? Yeah, there's some really novel attacks happening out there.
Um, go give us a try. You'll, you'll probably have your eyes opened and, uh, yeah, yeah. com.
com. Yeah, you Heard it. com.
Hey, that's gonna wrap up our, uh, coverage at Black Hat 2025. We are here on the floor. Thank you very much.
Let me say this right? Try out, try Tyron. Tyra Tyra.
Yeah. Thanks very much man. Tyra Rasmus, co-founder CTO at Push Security.
Hey guys. Thanks Joe. We're here with Dave Donatelli.
He's the CEO for Riverbed. And we're talking about how AI is gonna be applied to network observability with a bunch of new offerings that these guys are rolling out. Dave, welcome to show.
Hey, Mike, great to see you again. Yeah. Um, we've been talking about observability and networking for a long, long time, and I guess everybody knows now there's this thing called AI in the land, but how do these things come together in some sort of, uh, primordial suit that becomes a catalyst for changing the way we think about networking and walk us through it a little bit.
Sure. Well, you know, riverbeds had a very exciting year of innovation already. So we did a major launch in April of this year for our, in essence desktop and mobile ai, uh, around observability.
Then we did a huge acceleration launch in May. And now this is our third launch we're doing right now, which is around our classic MPM products. And what we've done with those MPM products is we've not only updated the hardware aspect of them that runs now three times faster, but addition, we've added our IQ technology on top so that people can now collectively pull the data from MPM sources, from their desktop sources together and apply AI intelligence to it.
Whether that's generative AI or agent AI or whatever, you know, all the major forms of AI available today are people spending more time observing network performance these days as it relates to applications. It seems to me a lot more of the applications are latency sensitive these days. And is this becoming something of a, of art as much as it is science?
Well, I think the art part is that it continues to become more challenging, right? Because people are running applications, you know, in traditional environments, they're running into the cloud, they have SaaS based applications, and it gets more and more challenging for customers to sort out where problems are. For instance, in the SaaS world, although you're usually depending on your SaaS supplier to make sure that application works if there is a problem.
And, and we've seen that with our customers, they've had issues. It takes a while for them to really sort out where that issue is coming from. Is it on their side or on the SaaS provider's side as just an example.
So therefore that elongates troubleshooting times, it certainly frustrates the end users who are looking for the availability of the application and therefore people are looking for tools to help sort through these issues. And that's what we're delivering. So where are we on this AI spectrum?
Because some folks, early on we started with copilots and now everybody's talking about AI agents. And are we just talking about something that, uh, will alert me to an issue or might it go out and fix the issue? Well, the good news is we, we offer what we call automations or remediations.
So that gives you the customer the ability to put in pre-configured remediations of problems and then report what's happened in places like ServiceNow. So in essence, we can automatically open up a call, fix a common problem you're seeing through automation, through ai, and then also close that call out so you know what happened. And you know, we see many of the large financial institutions as an example, using this technology to both reduce mean time to repair and at the same time reduce the total number of calls coming in since they, you know, through ai.
We can also do predictive work. So if we see something that's gonna run off the rails, actually launch a remediation before something goes bad. And you know, the best problem is they always say is a problem that doesn't occur.
And that's what this new technology allows. So what will be the role in the network engineer going forward? 'cause everybody's having these kind of moments where they're ultimately thrilled that they don't have to do all this manual work and then, you know, somewhat concerned about what it is that they will be doing for a living.
I think they're gonna be very busy for a long period of time. You know, all we're trying to, you know, if you look at the technologies today, what they help to do is take out a lot of kind of the, in essence, the drudge work of the job and let 'em focus on really the smart things that they do to really understand what's happening across the environment and fix things without, again, wasting a lot of time collecting data and trying to find the proverbial needle in the haystack. But if you look at the amount of data growth that's happening now, a lot of it actually even caused by ai.
Um, everybody working in the network space has plenty of work to do even despite all the great new innovations that are out there. Do you think that as we advance this, that there might be more collaboration across all these IT silos? Because the networking team has often been an island onto itself, apart from the application development team and everybody else.
And usually the one thing everybody can agree on is it's the networking guy's fault. Yeah. A lot of the networking folks talk to me about what I, what they term mean, time to innocence, right?
They spend a lot of their time trying to say, it's not me. 'cause everybody points, fingers at the network. What I mentioned with all these announcements we've been doing is all about building the Riverbed platform.
And it's ga it's in the marketplace today. Customers can run it. What's unique about it is it expands applications, networks, and endpoints.
So all the major things that you're gonna touch, you know, in, in terms of diagnosis or a problem, we can now look at. And we put that at all that data into what we call the Riverbed data store. So we have a common pool of data across all those areas.
And in that common pool is where we apply our AI technology. So in essence, what it's meant to do is to start to solve that problem of finger pointing amongst silos. With unified data, you get to a more, you know, unified answer.
And by also unifying your data, you get to a more accurate answer because you have, you know, data from all these different places in one place at the same time. And, uh, that speeds problem determination and certainly speeds problem resolution for our customers. So you've been at this a long time and, and I'm wondering, will the rise of AI in that common data pool start to help us to converge some of these job functions in it?
I don't think that the jobs are going away, but the way that we are structured might change. 'cause maybe we can be structured around some sort of outcome rather than around the core technologies that we're trying to babysit. Well, you know, I I I, I'd answer it slightly differently.
Here's what I do think is happening, like short term and then we can talk a little longer term. I think short term, what I see with most of our customers around the world is they're all doing some form of tools, consolidation. And if you think about it, having all these very distinct point product tools really causes some of the silos that you see, right?
'cause people are just expert on their tool, then they have to talk to someone else who's expert on another tool. So clearly customers are now starting to consolidate down because they literally have dozens and dozens of tools in these very large organizations trying to figure out what's going on. So I think that's a first step.
And as that happens, then you can start to get to, to the point you just mentioned, Mike, which is then you can start to have people look more cross domain and start to break down some of those silos. AI also demands this because people, you know, what's the biggest challenge around ai For most enterprises and organizations, it's getting your data in one place in a common format. So, you know, I think the first piece that's practical that's happening right now that we see everywhere again, is app application, consolidation on observability.
From there, then you start to centralize your data and from there then you'll start to see people again looking more cross domain would be my view of it. Do you think folks are distinguishing between monitoring and observability, or do they all just consider one extension of the other? Because, um, you know, when I think of monitoring, I'm like, well, it's a bunch of predefined metrics that we're gonna track.
Observability to me is more about I can query stuff and go look for that needle in a haystack that I might not know existed in the first place. Yeah, I, I, I agree with you. It is different.
And really what observability is moving towards very rapidly is actioning. So it's one, I, I personally never liked the word observability in a sense. 'cause it sounds so passive, right?
Someone observing what's happening. And what people really want to do is prevent problems or if they have a problem, they want to fix it very quickly. And so when we talk about automations and remediations, we have, you know, on the AI front, something called predictive AI where you can keep things and, and, and understand that they are about ready to go south.
You need to take action, alert somebody, things like that. You make the products much more action oriented and then much more effective for customers. 'cause they're getting better value by fixing things quicker or preventing problems from happening in the first place.
And that to me is the exciting part of where the technology is heading. And you know, this is always done against a backdrop of more and more complex environments. You know, it environments are more complex today than they were a year ago, uh, because of all the new technologies that's coming out all the time.
So it's always this race between can the tools keep up with the innovation and vice versa. Mm-hmm. You mentioned earlier, meantime, the innocence.
And I've always argued that the second most important metric is meantime the remediation after that, which is also known as meantime to return to innocence. Um, is that gonna get faster as we go along? I mean, because the amount of time that I have an issue, I should be able to reduce.
'cause I have some AI tool that will discover it faster and hopefully fix it faster. Well, we're shipping products today that literally will alert you to your phone that says you're having a problem. So let's say you're at a scenario, right?
You've left work, maybe you're out eating lunch and um, you'll get an alert on your phone, you're having a problem, which everybody dreads. And then we, we give you in, in essence what this three different circles, network application, uh, endpoint. And from there, you know, green, green, red, well the red one means this is what AI is pointing to the problem.
It will prompt, it'll tell you what the problem is and then suggests an automated remediation that you can trigger from your phone to fix. And that's available today. General, you know, generally available now.
And this technology is only gonna progress further and and quicker. So, you know, we're on a pace to do that now and it's moving as everybody knows very, very quickly in the marketplace. The, the ability, you know, what we can do this year versus what we could do last year has progressed immensely.
And it's on a pace to keep going because again, the more data you have and the more you run your algorithms, the smarter they get and the more they can handle. So I think it's a very exciting future. And I think, again, in my, in my judgment and observability is nothing to fear.
It actually makes people's lives much more enjoyable in terms of doing their, their job. Mm-hmm. Speaking of observability, we've always thought about networking in terms of number of endpoints and number of end users accessing.
How many things in the back end will AI just throw that math out of the window? Because as I look at it, I'm like, well now there's gonna be AI agents, hundreds of thousands of these things that are essentially end users and they're gonna be calling more data than ever. So, uh, are we gonna have just a network bandwidth issue because we're gonna have all this stuff on the front end and the back end that's gonna be exponentially greater?
Well, uh, uh, well I'll give you a real example. So, you know, we, I i, I don't, I can't mention names, but I'll say, look, we've been talking to, let's call them one of the major cloud providers. And they're, they're referencing their customers who to reload their AI models is taking days, not hours, you know, days over, you know, over a week, which is a little bit like back to the future.
I feel like I went back to the 1980s right? When moving data was so slow and it's just the sheer volume of data required. So that's why if you look at our acceleration products, you know, they're, we grow our acceleration business very rapidly in the first half of this year.
'cause people need those in order to speed data, even though the network pipes have never been fatter, right? So they, so they need that. The new technology is driving those types of bottlenecks where people need these new solutions.
And um, so it's very interesting if you, if you look at the agents themselves, you know, you're having bots now talking to bots. What I think will be kind of the, the interesting thing to see is, you know, we allow ours to be configured by customers. 'cause they get somewhat nervous of, Hey, how many bots are you gonna create?
What is this gonna do to my network? Is, you know, as you said, is the network just gonna be too bogged down to really work through all this? So it's, it's a transitional time.
Um, it is very exciting, but I think it is gonna be a transition versus a revolution mainly. 'cause customers I think are not gonna wanna unleash, um, agentic without restrictions in their environment. 'cause they're worried about, as you said, secondary effects, like slowing their network too much.
Alright. And then under the heading of back to the future, when we were both younger, they taught us that nothing good happens when you move data and you should always bring the compute to the data. And then the cloud came along and we wound up moving a lot of data to the compute.
Have we come full circle now and are we kind of going back to, well, let's bring the compute to the data because, uh, the networking essentially needs to be more efficient and that will work better if we have more cash at the place where the data is being accessed? Yeah, I mean, I, if you look at our data store, so our data store, by the way, is a free product we make, and this is part of this, you know, announcement that, that runs all this ai, we actually leave the data in place and only call data as necessary. So our, our algorithms are smart enough to know, hey, this is a hot zone where the problem is only pull that data versus to your point, if you just tried to stream all the network data out there constantly all the time, one, you couldn't have enough place to store, you know, you'd have to have a whole different storage form just to do that.
Probably couldn't scale well and would really crush your network. So yeah, I think they agreed upon architecture out there is leave as much data in place as you can, don't move it as much as you can. You heard my example of taking over weeks for people who are trying to move and it's the most practical way to do it.
Now the challenge with that, of course is getting your, your data store and ability to actually work that way. You know, in our case, it's a proprietary design we designed from the ground up ourselves strictly for that purpose. Um, most conventional technology though, doesn't work that way outta the box.
So that, that requires other, you know, architectural considerations. Ultimately. Then, what's your best advice for folks who are in the networking space these days?
Should they just sit tight and wait for all this to come to be? Or are there things they should be doing more proactively to get ready for what amounts to a new era of computing? Well, I think first of all, I think sitting tight is, is the worst thing you can do right now in, in that sense.
I, you know, to me, and I, as you mentioned, I've been doing this, you know, for decades. This is the most exciting change I've seen in my career in the sense that it really does fundamentally change everything. And I think, um, you know, most people are gonna be like pre AI workers, post AI workers, right?
It's if your career ended before ai, you, you're really gonna be kind of set back. 'cause you know, the future I think is very exciting. I will say there's tools available to them now.
Those tools do speed troubleshooting. We've got tons of real world customers already doing it. Um, you know, I try not to overhype, you know, we, we have not solved world hunger yet.
That's gonna take time. But I do think that, uh, the progression of the technology we see has, has fundamentally altered the game for people. Like when you have people say, Hey, I've reduced my meantime to repair by 30%, I've reduced the amount of calls that come in by 30% all helpful.
And it allows them to stay ahead of this ever complex curve that they're always battling. So there's real things they can do today. And I'm very convinced, you know, if you look at our rate of innovation, we've launched 25 new products in the last two years, um, with the rate of innovation, there's gonna be better and better solutions coming.
So it's important to kind of get on the track to learn it. And then so you're ready as all the new stuff comes along as well. Yeah.
And of course, a lot of folks are concerned about how their job may or may not exist in the age of the enterprise where we can scale more with fewer people on the IT team. However, conversely, it also seems to me like more organizations will be able to afford to build more complex networking than ever. So might not there be ultimately more organizations is looking to hire networking people than there were before.
Ai. If you look at the history of our market, it's, it's actually a history of what I call the expanding circles. So meaning when I first started mainframe, you know, dating myself a little mainframe was the core architecture.
And you know, desktop PCs were just coming in and people were like, oh, client. And then obviously client server was a part of this whole movement. And what happened, guess what?
Here we are now, decades later, we're still selling mainframes, you know, and we're still selling desktops and everybody's got mobility, and then everybody has the cloud, everybody has SaaS, and now we're doing ai. And I, I, my, I'm doing my hands moving outward. 'cause why?
Because the total market did nothing but grow, right? There's more people working in tech than there were when I started. The market size itself, you know, now measured, you know, in the trillions is much bigger than it's ever been.
And I don't think that changes. You know, the form might change a little bit, but my joke is as well that, you know, when the cloud first came out, what did everybody say? It's timeshare.
You know, if you, if you're around in the sixties, so, you know, we do things a little differently, but the fundamental principles are all still the same. You know, ai, I think people way over complicate, right? It's about centralizing data, running very smart algorithms against it, getting those algorithms smarter than applying them to a problem in your business.
If you think about it, that, that way it's not so scary. And, um, and again, I think it opens up more opportunities for people. And I think our industry continues to grow.
And as you said, the less expensive we make things, the more use cases we find. And it's always been that way, and I don't think that's gonna change. All right folks, you heard it here.
The best time to be in it and networking specifically is right now. Hey, d nice to meet on the show, Mike. Great.
See again. Thank you. All right, and back to you guys in the studio.
Hey everyone, A shimmel back here for Tech Drunk tv. I've got a, I think it's his first time on here to introduce you to a new, a new person. Always exciting.
A new company for us here. Uh, I want to introduce you to Daniel Meyer. My Daniel is the CTO for a company called Kaunda.
Daniel, welcome to Tech Drunk tv. It's great to have you on here. Excited to be here, Alan.
Good. Good, good. So Daniel, before we jump into about Kaunda and some stuff going on, um, why don't we hear a little bit about you?
Sure. Um, so I'm Daniel, you already shared my name. I work for a company called Kaunda.
I've been with that company for a long, long time. So I joined Kaunda in 2010. Um, and back then I was, uh, that was in, um, Berlin, Germany.
You can probably tell by my accent that I'm, that I'm European. Um, and I was studying computer science at the time and for various reasons I got interested in, um, business process management of all things. So how can, um, organizations better understand their core business processes?
How can they better manage those? And really, from the start, I was interested in that topic both from an, let's say, management perspective, um, like how do we think about that from an organizational perspective? How do we need to work?
Um, who works on what? Um, all of that. But then also from a technical perspective.
So how can we not only document our processes better, um, but how can we also automate them? And that is really the piece that, that, that caught my, my interest. And then I, um, found those, um, two other folks in Berlin, um, the two founders of KAA actually, and, um, Jacob fro and Banda.
And then I teamed up with them because from the beginning we had this vision of let's help large organizations to improve their processes, make those processes better, um, but let's do it through enabling them to automate those processes through orchestrating all the steps that need to happen in such a process. And that, that is basically what we've been doing for the last 15 years. And now orchestration is taking off.
Suddenly everybody's talking about orchestration. Everybody's interested in orchestration, and we're very happy about that because we've been doing that for the last 15 years. Sure.
Well, you know what they say if you wait long enough, right? What's the saying about London? If you wait and pick a dilly square long enough, or pick a adly circle long enough, eventually everyone in the world passes through there.
So eventually A boring topic, like, oh, you gotta, you know, you gotta organize your processes better will suddenly become hype. Yeah. Well, and you know what?
It's not boring to everyone, to some people perhaps, right? But if, when I'm not a, a business process automation person, right? And I, I've never been, but sometimes boring makes the world go round, Right?
That is the point, right? I always say, like, as consumers, right? We're all suffering from bad processes.
Just try to open a bank account, try to switch your, um, Absolutely, You know, your cable service or something like that. 1, 1, 1 experience. Some bad processes, just do that, right?
Absolute. Well, I I think sometimes companies put bad processes in place just to make it hard for you, right? Shutting off your cable account or switching, you know, to a different cable company.
Airline changes on reservations. Oh my God, is that hard? But, but you're right.
It, you know, that's when good, uh, business processes, uh, automation and so forth, that's when it shines. When you don't have a problem doing those things. And of course, exactly.
You know, Daniel, uh, uh, agent ai, chat bots, the whole AI thing promises to revolutionize this world, right? This is a world, this is a market, a business or segment that AI is already, you know, making profound changes. And I'm sure kaunda is on, on top of this, right?
At the, at the knife spear, the, not the knife spear, the, uh, spear tip, right? Leading the, the charge. But before, before we get into, yeah, it's, I'm sorry, just one sec before we get into it.
We didn't mention kundos website or anything like that. I know it's on your background here. Well, that's for the, yeah.
For the event. Yeah, exactly. So Kima is, um, as I said, has been around for a while.
We were founded in Berlin actually in 2008 in Germany right now. We're like, we grew to, to a global company. So we're, um, now than more than 700 customers worldwide.
Um, we have more than 500 employees. And basically we are helping, um, large organizations to, um, improve and automate their processes through our technology, which is key to process automation, which is process orchestration. Um, like really the ability to, okay, I'm gonna model my process from start to end.
Where does it start? Is it a customer email? Is it, um, you know, a click on the website?
And then what are all the steps that need to happen in order to, um, like fulfill whatever needs to be fulfilled? So it can be processing in order, it can be, um, you know, create, like setting up a mobile phone contract, um, processing a claim and insurance is, is a big use case. So all of those processes, you want to orchestrate them, um, from, from start to end.
And that's basically the software that we provide, and then also the consulting and, and methodology and approach that we propose to our customers in terms of how they can go about it. So that's, that's what we're all about. com.
com. com. We will be in New York, um, on October 7th and eight.
So we'll be, uh, Midtown. So please join us there. It's gonna be a fantastic conference, and we're gonna actually talk a lot about the Gentech ai, which I think you were starting to get into.
That's where we were going, and yeah, I, yeah, I, I, I pulled off the road there for a second, but thank you for that, Daniel. Let, let's talk a little bit about agentic ai, right? As I mentioned, this is having a major impact.
Um, we talk, you, you know, CDO uses the term agentic orchestration. Let's, let's start with that. What do we mean by agent orchestration?
Yeah, so I think most folks are familiar with orchestration, right? So basically the capability to, um, orchestrate a complex set of tasks, a complex set of steps, um, inside a process across all humans, right? Humans can be involved systems, APIs, devices, um, to accomplish the goal of the process that is orchestration.
And, um, over the last probably five to 10 years, process orchestration has really established itself as key to any scaled automation strategy, because it is, at the end of the day, the thing that stitches together all my systems, people, devices, bots, all my other automations that focus on specific tasks I can stitch together with an end-to-end process that then orchestrates across. So that's classic process orchestration. Now, what is a gentech orchestration?
That is now basically the next step from process orchestration. It's that next, we call it evolutionary phase, where with classic process orchestration, we have a lot of deterministic control, right? So I model my flow chart saying, here's the first step, and then this happens, and then the next step happens, and then maybe two things happen in parallel.
And then if this happens, then that happens, right? So I can model my process with deterministic logic, clearly specifying the order in which things happen. So that's classic.
Now with ai, we can get more open-ended. So there is a lot of tasks where the classic deterministic approach is a good fit. Um, but there are also many tasks where the classic deterministic approach is not such a good fit.
And those are typically the more open-ended processes. So, um, managing an exception, right? Customer support, somebody calls in and now you need to figure out how to help them.
Um, in, in banking you have things like trade, trade reconciliation, which, which can fail in, um, in, in insurance you have investigation into potential fraud around insurance, where you have more open-ended task where you, it's not easy to just predefine all the steps, but you can bring in AI to, based on a set of inputs and a goal and a set of available tools, determine what should happen next, what is the next step in the process. That is the more dynamic AI driven approach. And what now makes it a gentech process orchestration is the ability to bring those two things together.
Because for each and every process inside my organization, there'll be aspects of it that I want to control, that I want to predetermine, where I want to make sure that certain things always happen and always happen in a certain order. And then there will be aspects of it where I say, here, I want to put fewer guardrails in place because now I have a more open-ended task, and I want AI to, uh, uh, to actually decide what should happen next. And with Vitech orchestration at kaunda, we enable our customers to do just that.
That's fantastic because, you know, it's, it makes it not an all or nothing. Do you know what I mean? Um, where it's just, okay, I'm, I'm turning over the keys to the car to the agent, and let's hope it gets home on, on safely in one piece, right?
And, but no, here we can, we could determine where does the human input, where does the agent go? Where does the agent run with the human input? And, and back and forth.
And I, I think that's a, that's a, an important piece of, of this whole as we transition and adopt more AI kind of technologies. And, you know, 'cause a lot of times when you hear AgTech orchestration, I think a lot of people, you know, they liken it to Kubernetes mm-hmm. How Kubernetes orchestrates cloud native and, and containerized workloads.
But yes, this does sort of that, but it also, it orchestrates the relationship and process between the agent and the person Exactly. Right. Between the human and, and the agent.
And that's a piece again, I think we overlook as we, you know, we talk about, oh, we're moving ai, we're moving ai, but that doesn't mean the human's outta the equation. Yeah. I, I call it also the, um, the trust gap, right?
Bridging the trust gap. Because what we see is that yes, organizations are, enterprises are adopting agents, but they're still very reluctant to actually put them into core processes, mission critical processes, because how do I know it's not going off the rails, right? How do I know I can, I can trust it or do the right thing, um, because I'll be liable if it does the wrong thing.
This is particularly the case for heavily regulated industries. So there's sure, currently a big trust gap that we need to bridge. And the way we can bridge that is by basically providing the deterministic control and guardrails on the dynamic open-ended task execution.
And then I, I have the control where I say, okay, here I need to make sure that, you know, whenever we open an account, we do the KYC, for example, right? I can ensure that, um, in a deterministic way. But within KYC, now it's more, it's more open, open-ended, right?
Um, sometimes we need to check this, sometimes we need to check that. Sometimes we need to do a double check on the, on the income verification, for example. And here now I can leverage AI in combination with the human and the loop to, um, be more dynamic about that.
It's just an example, but, but it's, yeah, to your point, it's really important we can bring those two things together and blend them to then bridge that trust gap. Got it. Makes sense.
You know what, as long as you mentioned Cam und decon New York, right? com and, and click the link there. Um, how many people are you expecting?
I mean, how big of an event is this? Yeah, we had, so we, we always do one in Europe and then, and then one in, in, in North America, north America. Then we alternate every six months.
So we had our Europe conference in Amsterdam in May, and there we had more than a thousand people in the room. So, Great. Let's aim for that.
Yeah, sounds good. I love Amsterdam in May. Um, actually I think it's Cube con will be back in Amsterdam next.
Uh, I, it's usually April, actually. Yeah, March, April is, is Cube Con in Europe. Anyway, Daniel, I want to thank you for coming on here and, and really giving us a great brain dump on, on Kaunda, on, on, uh, agentic orchestration, how this all works.
As I said, I think this is an area where we're seeing really AI exert an influence, but it's good to hear that we haven't taken the humans outta the equation just Yet. Thank you so much, Alan, and, um, it's an honor to be here. Thank you.
Thank you. Daniel Meyer, CTO of Kaunda here on Tech Trunk tv. We're gonna take a break.
We'll be back in just a moment. The six five is on the road here in San Francisco. We are in the Palo Alto Network suite.
A lot of discussions about what the new threats are, what that means in the age of ai. Uh, yeah, A huge moment. I mean, the world is in a complete rebalancing.
We know that there's a lot going on. We know that AI has been a multi-year trend, but we're kind of seeing a, a convergence of forces. And as cybersecurity becomes more and more in the spotlight as data proliferates, as the needs for global economies and nations to pay attention to how we protect the data, protect their citizens.
Yeah, it does Dan. And as we've seen historically, every single major change, and whether it was, uh, client server, uh, from mainframe and minis, uh, uh, social, local, mobile, all the way, um, to, to this new age, there's always this new, the new threat that's comes out. And it's not your imagination, everybody out there.
It is a, a much more dangerous place. And whether that is nation states, uh, investing, uh, in this, whether it's ai using ai, AI to come in and attack, um, it's all up for grabs to this point. And enterprises need a stable, uh, stable technologies.
They need platforms to be able to do it more, more simply. And I can't imagine an a better person to discuss this than Nike Cash. Welcome to the six five.
Thank you very much guys. Great to have you at the Palo Alto, uh, you know, temporary suite. Well, this, this, by the Way, this is the way to do it.
You're buying companies, you're launching platforms, you're expanding product. Just start us off with kind of the big moments for Palo Alto Networks. Well, Look, as you guys said, uh, we are at yet another technological inflection point.
Uh, you talked about data, you talk about ai, and when you look at the last 12 months, the total explosion, uh, in the amount of investment that is going towards this idea of deploying AI on an enterprise basis has been amazing. Like it hasn't happened before in terms of scale and scope and size. S the amount of dollars being invested.
Now, let's assume a lot of these dollars will be successful in the investment, which means you have to try to paint a picture of the future three to five years from now. What's gonna happen, right? In that scenario, you can imagine there are, like, every company's got some element of data, to your point, data being used, AI being used to make better decisions, faster decisions, AI being used to do a whole bunch of repetitive tasks, or even some non-repetitive tasks and innovative tasks.
So if you believe that, that means, you know, the deployment of technology is gonna continue at a very rapid pace. And the more technology you deploy, the more you gotta make sure it's deployed in a protected fashion. Uh, in that regard, our reason for existence is that we have to make sure that our customers can go on and do what they need to do while they rely on us to secure them.
So we have to get ahead of the curve, anticipate these scenarios, devise the platforms needed to secure the future. So acquire, protect ai. Mm-hmm.
Um, launch expansion to your, to your platform. Mm-hmm. I mean, what's the, what was the, what kind of gets you most excited this morning of the what?
Four releases you put out? Yes. Well, look, I think part of what's important is the risk companies have, and I say companies a broader sense, the risk you have is that you say, wow, I won the last round.
And you start to rest on your laurels and you realize, well, the moment you do that, the world moves on. The next technology wave comes up, and then suddenly you have four new competitors to contend with. So in our world, you know, the more we do better, the more paranoid we are.
And from that context, I think what I'm most excited about is a, making sure that, you know, we get this AI thing right? And, you know, we learn from our Prisma cloud experience, we build a cloud platform. We could have done two things better this time.
We're saying, we're not taking any priers, we're gonna do this even better. So, you know, we're maintaining what I call the buy and build a strategy. It's not a buy strategy, it's not a build only strategy, it's a buy and build strategy.
And if you look at it this morning, we announced the acquisition of protect ai. And if you look at the challenges in ai, right? It's not just the, you talked about a little bit of the bad actors using AI to get in faster, but the challenge of deploying AI is you've gotta worry about the data now, right?
You've gotta worry about, right, the supply chain risk of ai, you gotta worry about protecting AI in runtime. And for the first time, you gotta watch out what it does, right? Because in the past you wrote an application, you knew the application was gonna behave rationally.
Now you have a risk that this AI thing could build a mind of own and do something. So you gotta watch out what is doing as well. So, so there's a whole new series of security challenges and, you know, if customers wanna deploy this, right, you've gotta give them something that is simple and stitched end to end.
So they don't have to go, you know, band it together, 10 different solutions, stitch it together, and hope they get it right. So from that perspective, I'm really excited that we're taking a very, very assertive and aggressive view and strategy on building the, what we call the AI runtime security platform. So we were announcing Prisma errors is our platform.
And I think on the other side, if you go back to, you know, the, the constant, uh, innovation and I'd say transformation of cybersecurity, which has been going on there, and we're noticing finally our customers are, begin to understand the value of security data. You look around and you'll see there's a whole bunch of companies which has sprung up, which wanna tell you how to optimize your data, use it better, make it more real time. But I, I mean, you know, I'm sure there's gonna be debate as to what are the most important words.
And I'll tell you the two are, I'm sure you could hear a lot about ai, whether it's agentic or regular, but I think the word, the the hidden word is gonna be real time, right? Because security has been sort of somewhat non real time. There's real time when I know a bad thing, I can stop it, sure.
But everything else happens non real time. The problem is the bad actors are gonna get to more and more real time with this deployment of ai. So we've gotta get as close to real time as we can.
And in that context, I think Databricks is important, and that's why you see some of our other releases, which point to the fact that we have to get more real time, we have to leverage the data much faster. We have to stitch things much faster. Dr.
Nikesh, uh, you talked a little bit in generally about, uh, where this goes the next three to five years. Mm-hmm. And there are certain milestones, you know, there, there's real time.
Mm-hmm. And there's, for lack of a better term, batch non-real time. Okay.
I know it's not batch, but couldn't give Different word. Exactly. Exactly.
Yeah, It long. Exactly, exactly. Well, I did, I did talk about mainframes.
That's right. Yes. There We go.
Look, I learned how to code ICL 1, 9 0 4. There We go. Do you know what that is?
I, I did co I did cobol. So up there we go and punch. I wasn't born yet.
Sorry. Point that out. This is supposed to be a progressive forward thinking part.
Exactly. Right. Let's make sure we stay here.
I'm gonna get there, I'm gonna get there. So, uh, talked a little bit in general, but, but how do you get, like, what is the three to five year, I don't wanna call it a roadmap, but your customers have to be thinking, how do I get there? Yeah.
But I think, look, it's what's fascinating. If you think about cybersecurity as an industry, how old do you think we are? I mean, I think it goes back to the punch cart days of Security.
No, not really. See, the cybersecurity wasn't a thing when you were in a closed loop environment Yeah. With punch cards and mainframes and Terminals steal those tapes.
Yeah, exactly. It was kind of sneaker net, right? Yeah.
You could do that. But the point is, it's really when we started to see mass connectivity, the moment we start doing apps and every company is rushing out to build app that their consumers can access, right? And the moment that happens, you start to open the doors to your data center, your infrastructure, to effectively every customer of yours, right?
When that begins to happen, the, the attack surface is exploded. So, believe it or not, we're about a 20 to 25-year-old industry. Yeah.
It's one of the youngest industries in technology barring ai. Right? So if you think about it that way, it has to go through a stages of, um, for lack of a better term, we'll say platformization, right?
'cause today the solution is there are 40 solutions in a company, and they, the, the CIOs and CSOs are busy stitching security solutions together. That's, that's right. Which is not their day job.
That's kinda like, that's, that needs to be done. So they can do their radio day job. Security's 5%, 8% of spend in technology in a company, and it's gonna take twice the effort.
That makes no sense. So I think the, the way we're gonna see it is you're gonna continue to see, I'd say you people call it consolidation, people call it, I call it platformization because I, I think there's a deep technical need to connect it. And until we get that deep connectivity, until we get multiple things working together, and the customer says, great, I can deploy, you know, 1, 2, 3 platforms and I'm done.
I mean, think about it. I mean, how many, how many CRM systems do companies have? 2.
2, right? That's not a bad place to be. Right?
How many HR systems do you have? Yeah, Typically. Yeah.
One, but let's not talk about ERP generally. It's you have, Well, that's gotta go away later applications Than you even know. That's right.
Yeah. It's A so, so we need to see that happen the next three to five years. We need to see stuff come together.
Yeah. I think that the, the, the thing that'll bring 'em together is data. 'cause you can't go replace every sensor, every edge sort of perimeter of security point product in a short period of time.
Because if you think about it, there's possibly a trillion dollars or more of security, I call it plant. Yeah. Right?
People have spent more than a trillion dollars on my security product the last 10 years. If you're gonna say that all that needs to go to an upheaval, it's not gonna happen overnight. But can we get it done in three to five years, hopefully at, you know, twice the effectiveness and half the price.
Yeah. Yeah. We had a great conversation with Nir, uh, recently.
So he joined the show, and now you've joined the show. And, you know, he was really, Did he say what I'm saying? Or am I, am I in line with our I'll, Uh, in the same constellation?
I'll, Uh, fantastic. That's Important. I'll let you know if you missed by a lot.
All thank you. Um, but, Or your listeners will. Yeah, Well, they will definitely let us know.
All right. Um, but, you know, he was very focused on kind of everything moving out to cloud, out to ai, you know, he very much was kind of like endpoint security. No, I mean, you know, and he is very, he has a very enthusiastic founder mentality.
You never, Uh, had a doubt. Yes. Really believes, but, but it was, it was very, um, aligned to what we're seeing, what I'm seeing you're doing in terms of how you're the platformization Yeah.
And in, in this game, you know, you must have Worked in the same place. Yeah. Right.
Absolutely. In this game, right. It's all about not just what you're doing now, what you announced today, but it's all about setting yourself up that in 12 or 24 months.
Yeah. Because let's face it, two, three years ago, most people, yeah, you may have, but most people didn't see how quickly generative was gonna happen. They didn't see ag agentic coming on.
We certainly didn't see $325 billion of CapEx being spent for something that, by the way, we're only consuming a fraction of so far. Yes. Yes.
This all happens your job, right? Is to figure out how do you stay ahead of this. Yes.
So, very curious, kind of, you know, the platformization, but like, what is the sort of strategy that you see that's gonna enable Palo to not only be the world's largest security, uh, player Yes. You know, but to remain relevant and to actually stay ahead and be critical as this trend proliferates. That's a great question.
Like, I think that's a very good question, and I don't think there's a perfect answer. And that's why you see us, look, we know at a macro level what our customers want. They want better security, they want a better price.
They don't wanna spend too much time stitching it together, and they want great outcomes. Now, as we go through this journey with our customers, and you saw us pivot about two years ago, almost now, where we said, listen guys, let's focus on a longer term strategy with our customers, which brings this consolidation and platformization together. So now we have our network security platform, I call it, and our sort of, you know, uh, incident response cloud cortex platform.
And what we've discovered, that conversation becomes very, very interesting and real, very, very quickly with our customers, is they want that now to stay nimble, to stay the largest cybersecurity company. Our job is to keep our ear to the ground very closely with our customers. 'cause they're actually driving the demand of what needs to happen, what their needs are.
At the same time, we have to keep an eye on technology. And at some point in time, we, we might disagree with our customer's point of view, like, you know, gimme a faster chariot. No, that's not the answer.
You're gonna have to use the car. So at some point in time, we do get into those debates, but it's a combination of working with your customers, delivering the solutions they want, keeping an eye on technology, and at the same time, having humility. Uh, it's a strange word to use in context of cybersecurity.
The reason I say that is that, look what we did this morning, we've been attacking, no pun intended, a certain track towards solving the AI security problem. And we keep our eye on the market. We saw protect was solving a different part of the same problem and say, listen, it's gonna take us six months to be able to replicate what they do, and they'll be further ahead than us.
Why don't we bring it together? So a wonderful conversation, Ian, who's a CE of Protect, and he's a smart guy, he got it. He's like, yeah, I get it.
I said, you wanna play in the big league? Yeah. The way to play in the big league and solves this problem for all of our customers to put it together.
And lo and behold, you know, fruitful discussions, and we followed our playbook in terms of how we do these things. We sit down together, have a joint vision as to what needs to happen. You know, put some product people together and know what they're doing, see how this is gonna come together.
And here we are now, it doesn't mean this is the end of the journey, because I still think there's a lot of stuff that still needs to be figured out. How do you secure agents? Well, as soon as I see one, I'll let you know.
Exactly. Yeah. And there's a lot of challenges that go into that.
Um, I mean, primarily there are themes that are in all of tech, and one of them is this best of breed point solution. Yes. And then there's platforms.
Yes. There's suites. Uh, there, there's end, end.
I think you answered it without specifically answering this question, but, but I think what I heard was that the way you balance this between where you would put r and d is, is a, a, a, you listen to your customers. Yes. Sometimes customers don't know exactly what they want as a product, but you understand their outcomes.
Mm-hmm. And then you build to the outcomes. Are there, are there any other things that go through this, you know, quote unquote best of breed versus platform that you have to make?
I think the biggest change we're gonna see in the next three to five years is the, is the shrinkage of best of breed. And I say shrinkage because I'm not saying elimination. Right.
Because there's a lot of best to breed out there that might have made sense 3, 4, 5 years ago. I think it's commoditized that it's normalized. Yeah.
I think, you know, it's six one way half a dozen. The other Is my DR better than yours? No.
There's four or five of them are, they're pretty good. Right. So the question is, do I really need to go specialize and take one and then spend my life stitching it together?
Yes. Or do I take one spot of an integrated platform? So I think you will see, as, you know, best to read, makes sense in the first 24 to 48 month cycle.
Does that best to breed, eventually lead to a platform? If it does, great. If it doesn't, it's time to go get, be part of a platform.
Right. So you see that kind of begin to happen. I think, you know, the industry is still operating in the best of breed mode.
So you see tons of companies getting funded. I think a lot of them will not see, uh, see, you see a positive outcome or not, that that's not a alive at the end of the tunnel. Yeah.
So situation. So I think you're gonna see that shrinkage happen because you are gonna see a lot more platforms evolve. I think that's a long game.
That's a long game. Because customers cannot, cannot feasibly put this stuff together. I think, as I said earlier, the the key, key sort of eureka moment is data, right?
Can you collect that data, analyze it? And I think one of the presses, the only things we announced is we have what I call cortex, uh, XI for incident response, which we saw phenomenal success in. Yeah.
It has been, you know, way past my expectations s of the company's expectations. And we're just turning on what we call cortex for peace time. 'cause we discovered when we collect so many terabytes of data for our customers, I get all the data for peace time too.
Yes. Why am I only focused on incident response and war time? Right.
So I think that's sort of giving us this idea that we can actually consolidate a whole bunch of best of beat capabilities into the peace time capabilities of our platform. Yeah. You're, you're your future, I don't think is so much point players.
I mean, look, there's always disruptor startups. Some of them become your protect ais and you acquire them. Of course.
Of course. Which is great. That's a great, uh, It's a great Outcome place for innovation to be developed in those small, nimble fa Oh, we, By the way, we love the venture industry funding innovation across the board.
Yeah. So all ideas are explored. Yeah.
We don't have the resource to do that ourselves, so thank you. Yeah, absolutely. On the other side of it, of course, the big cloud players.
Yes. You know, if, I'm trying to envision where competition actually comes from, because you've been so successful, you've grown so quickly. Yeah.
You've become such a dominant player in the space. It's actually, it seems, and if neera was correct about it all really being in the cloud Yeah. And everything happening, the multi-cloud, is that the, it is the, it's the Googles, it's the, and they're your partners too.
Yes. But like, is that where competition comes from in the future? Is it gonna be that the platform, because security kind of has always set off in this little island.
Mm-hmm. But increasingly it is all it's data, it's security, it's ai, it's application, it really all comes together. So where does conversation?
That's a great question, Dan. Look, I think it's phenomenal question. First of all, you know, they're the 800 pound gorilla.
So it is a joke like, where does the 800 pound gorilla sit? Whatever it wants. So I can't say that they're not gonna be security.
Now, what we're relying on, on a few factors, first, remember, uh, we're still about 8% of the product, business and security. So we're still used to losing 90% of the time. So we're okay, I can get from eight to 30, I'll be very happy.
So this is a good start. No, we're, we're back to humility. The trend is our friend.
Okay, let's stick there. I think the second important part is I worked at one of these companies, you know, and invariably, as good as you try to be, if you have your own thing, your products always better, work better with your thing. Right?
That's the beauty of Palo Alto. We don't have our Palo Alto cloud, right. We're effectively, uh, uh, Switzerland for, for sort of biases, right?
Yeah. We have no biases. We will try and make it work perfectly well on every cloud instance out there, every data center out there, because we don't, we don't deliver those capabilities.
So from, from that perspective, whilst we may be the consolidator, and, you know, not the domino is a bad word, but, you know, the most loved, sure. Large security company. I think outside of that, for us, what's important is we need to maintain that independence, that unbiased nature that we can deliver across all these platforms in a consistent way.
And that's kind of what we believe allows us to go out there and convince customers that they don't wanna get beholden to one stack, because it is a multi-cloud world. So, should I buy security for every cloud and then spend my time stitching that now instead of the best of breed I used to buy in the past? And I mean, the other, the last thing I'll say is that when you have a 90% or 95% of business, it's called AI and cloud and 5% of business security, how much time are you spending in the 5%?
Hopefully less than 5%. Yeah. Makes Sense.
So that's all we do. Every morning we wake up. We don't worry about, are you gonna use, you know, large database?
Are you gonna use my LLM? All I spend our time saying, how do we secure it when you use it? Yeah.
So, nsh, uh, final question. Yes, sir. Again, thank you for this time.
Uh, talked to a lot of CEOs and I mean, you just have turned on TV CNBC. Yes. Uh, this economic uncertainty.
Yes. I'm curious how you're balancing your investments versus the uncertainty. That's a great question.
Look, I think, I think part of you, you're seeing a dichotomy. The, and you kind of just illustrated that by saying there's $350 billion plus of investment going on in AI that doesn't seem to be impacted by any economic uncertainty. In fact, it's, it's sort of, it's an arms race to try and get it done quickly so we can deploy it.
So I think on the one hand, you're seeing the, the technology train is running at warp speed. And you gotta get, get ahead of it, try and make it happen On the other side, there is a little bit of uncertainty, I would say right now because of the whole tariff conversations. But guys, we powered through a pandemic.
You and I were sitting here at the beginning of the pandemic, we be worrying about the same things and look back and say, oh my God, that was one of the best opportunities. Had I known what was gonna happen, I would've put my money in the right places. Yeah.
So I think it was the same point. Will we get through it? Of course.
We'll get through it. And at some point in time, you know, you'll get used to it. Whether the answer is 10%, the answer is 5% or 25%.
I don't know. Right. Like, I try and not worry about things I can't control.
Right. So from that perspective, I think we're all getting used to the notion that this will find some new level of stability. Yeah.
And when that new level of stability will be found, we'll be all worrying about something else. Until then, it's fun to worry about this, but you, I can't control it. Don't worry about it.
Focus on your business and we'll, it'll sort of build power through on the other side. Sage Words, what do we go on TV and talk about if there's no chaos? It's funny, someone, someone showed me a chart the other day and it was basically the always a reason not to invest.
And it just shows the charges up into the right. That there's always a reason at every different point. It's the s and p just running That's right.
Up into the, right, up into the, it's the Other half a glass. Nikesh, thank you so much for joining us here on the six five. It's been great to have you.
My pleasure. Thank you for having me. Good luck with it.
Thank You. And thank you everybody for tuning in. We appreciate you so much.
Hit subscribe. Be part of our six five community. So many great conversations here for Patrick Morehead, myself.
It's time to say goodbye. We'll see you all later. The six five summit is here.
We are actually in New York City at the Nasdaq for a conversation talking about the future of ai. And I've got none other than Durga, Malti, Durga, Qualcomm 40th anniversary. We are here at the Nasdaq shooting the six five summit video.
Um, first of all, welcome back. Good to see you. Good to see you again.
Yeah. Really. And it feels nice to be here.
Yeah. It's great to be looking out at the backdrop of New York City. You know, a lot of the big shows that I think all of us watch, uh, CNBC shot right in here.
That's right. Uh, the backdrop. It looks like it was a great day.
I, I had a few minutes to attend the 40th, uh, anniversary party, but you've been with the company, I don't know, nearly three decades now. You've been through the CDMA era, you've been through 3G, 4G, 5G, six G should I say. It's not been through, but you're getting there.
Talk a little bit about kind of what it was has been like to be part of this company, this culture, this evolution, and, uh, you know, kind of what the journeys look like so far. I think Qualcomm, uh, as a company, we kind of symbolize what it takes for, uh, just a bunch of smart people coming together and taking on challenges, which seem so impossible. But then by the time you get to it, then you just keep moving on to the next one.
Uh, revolution as a company back when I joined, uh, yeah, it's my 28th year. So it feels quite, uh, both humbling and, uh, kind of, I'm in a reflective mood just in terms of thinking about 40 years, uh, is quite a journey for us in Qualcomm. But, you know, one of the nicest and the best things in Qualcomm is the ability to innovate and reinvent ourselves every so often.
And I've been through several of those reinventions of us. So it feels quite something. We started off as a wireless communications company.
Uh, we still are, but we've added so much more since then. We've been so many generations of wireless technology. And at some point we gradually transformed into a high performance computing company in addition to wireless communication.
So here we are, uh, 40 years later. Uh, it's been quite a ride and quite a journey. Now you're really becoming a compute company.
I mean, uh, you talk about, you know, handsets Yeah. Part of your business ip, part of your business, of course. But like, you know, uh, autonomous, uh, you know, vehicles, uh, and A-D-A-S-A big part of the business, um, models and on device AI become a big part of your business.
Kind. Talk about that journey. 'cause you have a big remit around AI now.
That's right. So you're doing a lot more, but you're really a computing company now with a pretty impressive AI story. So take me from the radio and mobile to this kind of era of compute and ai.
There is an analogy in history that as you start, you know, the transport, uh, was no longer, uh, the question anymore. Yeah, we could go to much higher data rates, but the natural question was, well, what are you gonna do with all that data? And, uh, the natural thinking back then was, well, you gotta have a reasonable amount of computing in a phone.
Back then it was still phones. And that was the first time we said, okay, we gotta start getting into, it's gotta be high performance, but also energy efficient computing. 'cause you have to make it work in a phone.
And if you can make it work there, you can make it work anywhere else. That was the beginning of our transformation into a computing company. And gradually, as we invested more and more into it for the next few years, we invested heavily into all the peripherals.
Not just the processes, but multimedia, camera, video display. And when it all started coming together, I think the next time we then started thinking about it was towards the birth of 5G like in 20 16, 20 17 timeframe. And I said, we gotta take it to the next level.
And not just relegate ourselves just to smartphones, but go from there into all the other industries. Automotive and PCs were the one of the first ones that we started thinking about. And gradually on top of that, we started layering in XR and IOT devices, consumer and industrial iot.
And we've, if I just look back in the last eight or nine years, oh boy, we've come such a long way since then. And the third, I, I would argue, uh, in terms of high performance computing, our transition was as we were paying attention to, in addition to data processing, well, how exactly do you do that? And there are other ways of actually doing that processing using ai.
And around that time, we decided, okay, we have to be in a position to bring in AI into devices. Into devices, because you can always run it on the cloud. And that will continue to improve, but we wanna make sure that it comes into devices.
So about five years back or so, just two years after the transformer networks came in, we really started looking at how do you bring generative AI into devices? And look around you today between IPCs smartphones, infotainment, or as we call it, digital cockpit. Inside an automotive, uh, uh, uh, you know, any kind of an, uh, automobile.
Uh, a DAS is a natural extension from then onwards into autonom. Both of them heavily involve ai. And these days now we use AI in, in every kind of a device that we can think of.
And, uh, that's been quite a journey. So at this point in time, as we started looking at, okay, what's what comes next? Uh, very recently, uh, we then, um, started talking about data center.
'cause all the lessons that we've learned with high performance and energy efficient computing, uh, with ai, we decided, yeah, actually all those attributes make sense in data centers as well. So the last two, three weeks have been extremely busy for us between, uh, the Middle East and Compex, and a lot of the announcements that came in from there. So we are very excited.
I'm personally extremely excited about our next journey into this, uh, into this era. I'm still a little hung up on the comment you made about what are we gonna do with all this, uh, this data. Right?
You know, and, and, and going back years, it feels like that's a bit of the, the theme that we as a society have right now. The same questions being, what are we gonna do with all these data centers, right? You hear about all this CapEx and all these, um, servers, and then you, you know, hear about, and, and I think what happens is, is innovation kind of, we, we build the, it's like the, it's the roads and the it, it's the, it's the pipe, right?
To create growth. And then all of a sudden innovators come in behind the developers, the, the ones that created the app ecosystem. I mean, there's a period of time like I'm sure when you're thinking back to like 3G and phones.
That's right. And nobody knew an app ecosystem was going to come. And now the, it's just become totally, you know, part of our, it's ubiquitous, right.
With, with our, with our lives. But I, I want to just double click a little bit. 'cause you have made this impressive transformation.
I've documented it a number of times. Um, talk about it pretty perpetually. 'cause I sometimes think it's, it's misunderstood.
I think sometimes Qualcomm doesn't get enough credit. Um, some of the areas I think is one is, you know, the diversification journey that you've been on. You diversified into compute, but then you diversified into the auto space in a big way.
I mean, nearly $50 billion of design pipeline. You've made a big leap into the edge AI for, for industrial use cases. You had a partnership with Palantir that you announced.
But I still think that one of the biggest opportunities Durga is actually going to be bringing like XR and iot. All those things come back to life with edge data and ai. And you seem to wanna play a really big role.
And now you're also, like you said, you kind of quietly said it, but you're also getting into the data center. So, so, you know, you go back 10 years, you're basically a handset company. Now you are a handset and ip, but you're also PCs and devices, you're xr, you're automotive, um, you're the edge data, which obviously even naturally takes you into robotics.
So, you know, the TAM is growing. It feels to me like, you know, maybe the right way to ask you this question is, what do you think are the things that you really, the market maybe doesn't fully see and appreciate about all the great innovation that's being developed at Qualcomm? And what do you kind of hope the market is able to see over these next couple of quarters in, in years?
I think, uh, for the longest period of time, Qualcomm has always been known as a, as a wireless communications company. And effectively it's about connectivity into all kinds of devices around us. I still feel sometimes that, of course, people like you and a lot of others actually do recognize the fact that we've transitioned a very successful transition into a computing company in addition to communications company.
But I think there is still something else that is not fully understood. Uh, there is an association of Qualcomm with smartphones. Uh, they continue to be a very important part of our portfolio, but we are so much more than that, especially with PCs.
Uh, uh, XR devices and iot devices will keep come back to automotive. It's a place where that's not an, these are not, uh, like PCs for example. It's like a really mature industry at one level.
But then the fact that we were able to come in and bring in AI based PCs, AI algorithms running inside your, uh, inside your PC without necessarily, you know, uh, going back to the cloud and you can always use connectivity to go to complement what you're doing. That's a place where I think, uh, there's a lot of analysts who are aware of it, but the market is gradually sitting up and taking notice and saying, okay, wow. I mean, there's a bunch of IPCs out there.
Uh, that's still a story that still continues to evolve, I would say. And I, I spent time actually explaining ourselves beyond smartphones. The same thing.
By the way, watch out for XR space because, uh, when you think of xr you think of some, you know, the back in the day there were these goofy looking glasses that someone would wear. That's not the case anymore. You know, today you can actually walk into a store and get a pretty good ray band glasses, which look no different from your regular ones, except there's a camera in it.
There's a microphone in it. You can take voice calls, you can actually, the other person can see what you're doing. This enormous amount of processing that actually is needed to get it there in a form factor that looks like an XR device.
So that's quite, quite something actually. And I think people will be surprised to see how, how far we've come and how much Qualcomm has permeated into all kinds of devices that you might not necessarily associate us with. And switching to, uh, when I go into industrial and consumer iot devices from variables to industrial equipment, it's all about AI processing.
There's so much of data, especially domain specific data that's out there, but the algorithms make the devices so much smarter, and it's quite impressive to see the applications coming in in the industrial sector. You know, that's been a specific portfolio of ours where the growth has been very slow for the longest period of time. But with the injection of, uh, generative AI and AI applications overall, it's come a long, a long way.
Automotive, uh, I think we've, right back maybe seven, eight years back when we started splitting, uh, how we thought about automotive. We, we said, okay, first there's the digital cockpit. This is the interface between the, uh, driver and what's around you.
That's just the basic interface. And there's so much of AI was activated, uh, uh, processing that occurs. You can actually point your finger like this and say, roll down this window.
And then it comes down. There's gesture recognition along with, um, uh, infrared sensors which are inside the vehicle that can do this. It's quite something, by the way, all of that processing, once again done by Qualcomm, uh, I think in that space, uh, people are waking up to the reality that we are there.
And so I almost feel like this is a story that we will continue to tell about ourselves. Not many people have paid attention to. But the quiet thing that we did, we said, Hey, by the way, we are now getting into data centers.
That is gonna be a place that I think people should watch out for because high performance computing, normalized by energy efficiency is going to be a very important attribute as we go forwards. Tons and tons of data to process energy is at a premium. So low, uh, low power based, high performance computing is key for us.
I 100% agree. We need to get more efficient. The energy race, the AI race will follow it.
And so if you can only solve it two ways, build more energy, which is complicated and is going to take a lot of time, especially if we wanna do it clean. And the alternative is build more efficient architectures, which is something that Qualcomm has long specialized in. That's right.
Uga, I wanna say thank you for making, uh, your 40th anniversary with, uh, not yours, but Qualcomm's 40th anniversary part of the six five summit this year. I see significant TAM expansion. I see a path into so much more than even what Qualcomm's doing today.
I look at things like, you know, robotics, which all this so logically fits and I see a, a, a strong path. And of course, we'll be watching very closely how this evolves in the data center. We know in terms of low power connectivity at the edge, it's something you already do.
Well, let's chat again soon. Um, you know, and have a great rest of the, uh, the celebration here in New York City. Always A pleasure, Dan.
Thanks for having me. And thank you everybody for being part of the six five Summit here. Lots more content for you kicking it back to the studio or wherever you are to join us for the next session.
Generative AI is everywhere. Everyone's talking about it. Many people are doing it.
You should probably get started and do something with generative ai, but make sure that you're getting value for what you're doing, that you are doing sensible things. Join me on this episode of the Tech Field Day podcast as we talk with the awesome experts from Signal six five. Welcome To the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about a key concept in the industry.
This podcast features a variety of perspectives from members of the tech field, a delegate community and tech field is part of the Futurum Group. And this podcast is also published on our sister company Site Techstrong tv. And this is a very special episode for me because it has some three guests from the Signal six five part of, uh, Futurum as well.
And we're gonna be discussing the idea that generative AI is evolving. You should start now and control your cost. But before we start the discussion, let's meet who's on the panel.
Hello, I'm Russ Fellows from Signal six five, and I'm one of the team members that, uh, concentrates on looking at developing proof points. And like many in the, uh, industry today, a lot of focus on ai. Hi everyone, I'm Mitch Lewis.
Uh, I, I'm also part of the Signal 65 team, uh, working with Russ and Brian as well. Um, also currently very focused on, uh, AI that we're gonna be talking today. And, uh, so to be here.
Hi, I'm Brian Martin, signal 65, uh, heading up AI and data center performance, uh, working with Russ and Mitch, uh, and in our scaling lab. And of course, I'm Alistair Cook. I'm an event lead at Tick Field Dice, specifically AI infrastructure field as one of my events.
And one of the things we have seen across the last few episodes of AI Infrastructure Field Day is the idea that you need quite a lot of infrastructure in order to run large generative AI applications, to build models to particularly fine tune models and then run them, for instance, in production. And I think we also have seen that there's a lot of uncertainty about how you go about building your application and get started. And so we wanted to look in this, this particular episode, thinking about generative ai, how it's evolving, how newer techniques, newer ways of using generative AI are really bringing better and stronger answers, possibly faster answers, but also that the business value for AI comes when you're doing the inference phase, when these AI tools are generating information that you can hand on and, and make actionable from your users.
And so managing that in that intersection between the cost and benefit is gonna be vital as we're starting to build out applications on top of ai. And Brian, I know you've recently been building out a data center for, uh, running AI projects. Have you got some thoughts about design decisions in that process of building the data center that might be valuable here?
That's a great question, Alistair. Yeah. Down, uh, Colorado Springs been working on our AI scaling lab and, uh, are fortunate to be working with partners, uh, and have two eight node clusters there, 64 GPUs each, which gives us the ability to test from small scale single GPU up through much larger clusters.
Um, looking specifically at generative right now, and inferencing as that workload appears to be growing rapidly, uh, among the user base and customers, uh, we're seeing that as, um, we're seeing that we can start small and grow. Um, some of the newer models, especially mixture of experts, uh, while they take a fair amount of VAM, uh, can be very fast for their size because they're activating only a fraction of those parameters in runtime. Uh, I was recently able to run the new moonshot QK two, uh, inferencing that required 16 GPUs.
So this was 16 H two hundreds for inferencing. That's a trillion parameter model with 32 billion active and seeing token rates in the tens of thousands on a trillion parameter model. Now this is scale, uh, toward the upper side, uh, for enterprises, but that just shows what's available in on-prem usage, uh, for these types of models.
At the complete opposite end of the spectrum, I've got, uh, an eight gig jets and Oren, uh, doing inferencing on two, uh, billion parameter models, uh, for an IOT project. Uh, so inferencing is happening at all those scale points. Um, get in, try something and, and see what fits your use case.
And last time I was in Colorado, uh, sitting in Russ's office, uh, Russ, you, you had a workstation with A GPU and it's sitting on your desk that you're doing some experimentation with. And I think you've, your experimentation's gotten a little more sophisticated than it was early last year when I was with you. Um, how do people get started?
What do you see as being a good on-ramp to using generative ai? Right. Yeah, I think getting started is the important thing.
And yeah, I used to be proud that I had one of the better setups, but then, you know, Bri, Brian, uh, uh, shown us all with his, uh, a 6,000 pro, but I, I have a system with a, uh, NVIDIA 40 90, which is, you know, today, at the time it was the, the newest, highest end. That was before the 50 90 came out. But, uh, you don't need to have the, the highest end or the latest, you know, GPU to get started.
Almost anything can get you started. In fact, you can even get started on, um, CPU based systems. You don't even need A GPU, of course.
You're just gonna have to be a little bit more patient. Um, things are gonna run a bit more slowly, uh, so don't be looking for high throughput rates, but in terms of experimentation, you can do a lot even without a GPU. And, you know, even a low end one, if you don't have the funds to purchase one, you can rent those in the cloud at less than a dollar an hour as well.
So there's a lot of ways that you can get started pretty inexpensively. I've even been working recently on a, on a project here at Tech Field Day with, uh, click and, uh, was amazed at the how rapidly I could build a rag solution retrieval augmented generation solution just using their cloud. Uh, currently I'm not paying for that service because the project is on.
I'd be interested to see how it compares with, uh, other platforms for running the same kind of, um, kind of tools and development. I know Mitch, you were working on projects and we, we covered this at Cloud Field day 23, uh, a project around cost effectiveness versus necessarily straight up raw performance. And as we get into production inference, um, cost effectiveness comes to be kind of vital.
Yeah, exactly. We've done, you know, a lot of, so we've done a lot of AI testing, but what goes hand in hand with that often is, um, you know, how much you paying for it. Um, and I think there's, you know, lots of levels to it.
Like we're seeing, um, things that are maybe not super expensive where you can just, uh, get started. Like Russ is saying, like, we've done some testing on, uh, you know, AI inferencing on CPUs and, uh, as the performance, as good as, you know, Brian's big clusters. No, uh, but you can do things.
Um, so that's, you know, one way to get started and that's gonna drive the price down. Um, but you know, we've also done testing looking at different hardware solutions, um, like I talked about, uh, cloud Field Day. Um, so, you know, uh, is Nvidia your only, uh, GP vendor?
No, there's other solutions, right? So, uh, you know, we've, we've looked at, um, a MD and we've looked at Intel, um, and there's different price points. So I think people need to be kind of mindful of, um, you know, what you're doing, um, and what resources you can use, uh, to kind of bring those costs down.
Whether you just need do something quicker than cloud, uh, can you just, you know, leverage an API endpoint because you're just playing around with something and you can throw 10 bucks up to open AI and, you know, build something cool real quick just to play around. Uh, or do you need to go, you know, procure, uh, a thousand GPUs because you are, uh, building something massive? So I think there's, you know, people, people get kind of scared off by AI because they think it's just, um, you know, Tesla and open AI and Google with thousands of GPUs, uh, training these models.
But, uh, there's, there's a wide range going from, I can run something on CPU to, uh, you know, I have a whole data center with a, a nuclear power plant. Yeah, I, I'll add onto to that quickly just that, um, we, we have, uh, some upcoming research coming out, hasn't been published yet. We'll be shortly, um, evaluating, you know, three different CPU vendors.
So there are three, well, there's more than three, but, uh, believe it or not, people think of kind of two, but there's more than that. Um, but looking at doing different inferencing and some AI ML workloads as well. And, um, they've all improved significantly over the past several years.
Um, you know, there was no focus on the CPU side dedicated to, you know, giving circuitry to optimizing a lot of these matrix multiplication tasks that are behind a lot of AI models. But with more focus comes, obviously more funding in that area, more research in that area. So the, all the vendors, including CPU vendors are significantly improving, you know, their performance in that area.
So, just to add on, yes, there's choices among GPU and there's choices among CPU and they're all rapidly improving. I think there's, you know, and and beyond just, you know, the, the CPU or GPU, there's some other creative approaches that are, um, kind of emerging from, from different vendors, uh, that we've done some testing projects on, on like, how can you reduce the storage or how, um, uh, can you actually leverage the storage to offload some of the memory? Uh, so we just did a project, uh, testing out a solution for Fon, um, that takes that kind of approach.
Um, and pretty cool. We were able to run, uh, both a 70 a LAMA 70 B model and a Quin 72, uh, B model on a single, uh, workstation, GPU, um, that, you know, normally would not be able to do that. Um, so it did take a while, but there's kind of that time versus cost and performance, uh, trade off.
One of the other areas I've noticed that, uh, we talked about generative AI evolving and being price conscious is looking at the code support environments, code development, whether it's Cloud code or Cursor or Windsurf, uh, or Google Fire Base Studio. Um, they've all recently been starting to change their pricing models as well to the, to the dismay of developers and I'm sure to the, uh, delight of their accountants. Um, but I had a, a recent challenge over the weekend.
I was tracking down to pesky bugs and jumped into Claude Code and flipped it into Opus four mode. And I'm like, okay, here, here goes the most expensive approach I can to solve these problems. And, you know, within an hour and a half or so, at a cost of $19 and 88 cents, I'd knocked down two pretty good size bugs.
So, you know, it's both, uh, sobering, uh, to see the effectiveness of it. Uh, and also I like the transparency of getting a sense so we can watch what it's costing now, see how that evolves over time, but really helps put a price on some of these features. Yeah, watching the meter run is fun.
Um, I, you know, it's funny, I've been using AI coding more and more over the past, um, six months, and I use it differently than a lot of people suggest. I, I use it differently than like Brian just outlined. And I am, I'm aware of that method, and I think it's probably more productive, but I'm still a bit hesitant.
So I, I still go with the chat GPT model and I change the model depending on what I'm doing. So I always start with an O model when I'm doing the initial outline and, and you know, project, you know, what things do I wanna focus on? What libraries do I want to use?
How do I wanna design this? I use one of the thinking reasoning models, it makes a huge difference. But then I, I'll, I'll take the code and I'll copy and paste and, and so I just do the old copy and paste.
Um, it's not as effective. It is more cost effective, though I probably only burned about two to $3, I'm guessing, I don't know, over the weekend. Um, and pumped out 800 lines of working rest code.
So I think that's one of the things we see is that using the right tool has always been important, that there's a huge difference in scale and cost for different tools. So I think that it's crucial that you start optimizing for the value that you're gonna get. If Russ gets value out, spending $2 on, uh, on some, some code generation during the day, that may be, uh, all that's, that's important for him, but Brian spending, you know, $30 to, to knock out some significant bugs that maybe might have meant that your platform was unavailable for a while.
Right. That's, that's pretty cost effective too. I love that we can choose between running things ourselves and sending them to a different API.
So one of the tools I use is, is wi to do transcription on my Mac and my, um, uh, ARM-based Mac does a really good job of running through that transcription, but when I want to do something more like extract what were the key points in this conversation, then I hand it off to a cloud-based service. And so I'm minimizing cost by choosing the right tool for it. And again, like as Russ was saying, different model for different phases of your investigation.
Yeah, it's, it's like having, uh, a handful of experts available for what's needed. Uh, I have a friend who's completely vibe coding a project and has figured out a system where he uses chat GPT, like Russ for high level concepts, but when chat GPT comes up with an answer, he asks it to write it in the form of specific directions to hand to his junior developer, and then he takes that text and pastes it into his code IDE to do the edits. Yeah, that, that's good.
And actually, I've done some things back and forth between having, uh, chat check Gemini and Gemini, check, uh, chat and, you know, go back and forth, change models and, and I also use Gemini just because, uh, you know, we, we get our email through Google, so we have paid accounts. So to me, Google is a, a free service Gemini pro. So it, yeah, it, it's a useful checking.
So you, you don't have to be tied to one model, you can use two or three. So that one that you, you said though, Brian, that that's pretty creative. I'll, I'll have to try that.
Yeah, it's, I, there's a couple, two, two articles I read recently. This reminds me of one of them, which is, uh, the writer had an insight about prompting generative ai. And rather than trying to be, uh, thorough and meticulous in what he was asking for, uh, the writer instead relaxed that part and spent more time talking about how like, you know, write up something as if you're a developer at the end of a 12 hour shift chasing down bugs, you're exhausted and you're explaining to management for the fourth time why this is a problem.
And what he found was it, it invites the models to lean into what they've been trained on. They're not really good at factory called, they're not really good at specificity, but they are incredibly creative and they understand tone and presentation, I think more than we give them permission to exercise. Yeah.
Creative prompting, as you're doing ad hoc work seems to be absolutely vital. Uh, have, have any of you come across any of the coverage of challenges around particularly vibe coding, um, and hallucinations from, uh, from these AI coding tools? Because that was something I covered on the rundown recently.
Oh my goodness. Uh, I would, you know, hallucinations looping, um, over enthusiastic extra work that wasn't asked for. You know, there's probably a list of a half a dozen bad behaviors that AI coding tools have evolved as they've gotten better.
It, it's almost like they want to prove how good they are. It's like watching a junior coder overachieve when you asked them to do one thing or and them to do one thing and they come back with like, oh look, I did this and this and this, and I compiled it this way. Like, okay, thanks, but I asked for this.
I didn't need any of that. Yeah, it depends on what you call hallucination. I just call it flat out being wrong.
Um, I mean, sometimes, yeah, it depends on the model and the way you ask the questions. It'll, so I'm doing a lot of development. It's funny in a language I don't really know, which is rust.
Almost all my development now is in rust because I love the results. When, when you get the code to work, it works like flawlessly and really fast, you know, no runtime memory dumps like you get with C which I've been dealing with for 30 years, so no garbage collection with Java or go. So I love the results.
So I code almost exclusively in Rust, and there's a ton of libraries to choose from. And sometimes it'll just like dream up interfaces that don't even exist, right? And the compiler knows, it's like, this thing doesn't exist.
It's like, Hey, what are you talking about? This, this library doesn't exist. Why don't you check this again?
So, you know, you, you could call that hallucination, call it being wrong, but yeah, it happens all the time. You just have to understand that it's gonna come and how to deal with it. I see a Vibe coding podcast coming online soon called Rust On Rust.
So if we're concerned about the hallucinations that are happening in these AI coding applications, how do you feel about handling hallucinations in production applications, running inference to, to drive your, your business, to drive your interaction with your customers? Um, on a spectrum from terrified to curious? Uh, um, uh, I'd say the whole spectrum.
There's, there's an interesting, you know, speaking of evolution, there's interesting changes I've seen recently. Uh, I first saw it in deep research mode with Google Gemini Pro. Uh, and that is a listing citations.
So when the, the research comes back, when the answer comes back pointing to not a fictitious URL that they made up, but actually making sure that it's really real. And it is in fact the one they referenced. Um, I was speaking with another company earlier this week that specializes in metadata enrichment of source material.
Uh, and one of the things that they do for AI platforms is offer citations down through the data. So whether you're building a chatbot or a rag system or some other AI enabled data-driven solution, you can either in real time or after the fact audit down to citations of the actual source data. Yeah, that's, that's an important fact.
And I, I've noticed some models give those citations and some don't. Uh, but you need to check them because I found when I do check them, uh, I wouldn't even care to guess, but at least 25% of them are either wrong or made up. Um, so yeah, it'll, it'll give you citations, but uh, maybe it's an outdated one or maybe it's different than what it's assuming, or sometimes they just don't even exist.
So check the citations, uh, yeah, those can be helpful. But check references, Trust, but verify or don't trust and verify. Exactly.
And then to get back to your question, Alistair, about, you know, how much do you tell, um, how much do you trust AI coding assistance? Um, I, the way I think of it is kinda like Brian described, is sort of like a, a, a junior, you know, fresh outta college, very eager to please person, and how much would you trust them? Hmm.
You, you're gonna verify, uh, you'll let them get started, but that doesn't mean you're not gonna test the heck out of it and have some more senior people review things. So yeah, you can get a lot of code and gets things working, but that doesn't mean that you shouldn't review things and test as much or maybe even more than before because now you can automate the, the writing of test code too, right? So why not to verify, have another agent, a, a different model, write the test cases.
And there's a key thing Russ said there, which is, have a different agent write the tests. I think in general, you know, whether it's coding assistance or just general language models, I think it's just kind of reflective of where we're at with AI right now, where it's really useful. Um, but you do kind of need to know what you're doing.
It's gonna hallucinate it's gonna be wrong. Sometimes your code isn't gonna work, sometimes your citation is gonna, uh, you know, bring you to a nonexisting link. Um, but I think, you know, it is getting better, uh, for a couple reasons.
So, I mean, models are generally getting better. Uh, we found better prompting, uh, techniques. Um, and you know, there, there's some other things you can do like build and rag or, or tune or model for specific tasks to make it a little bit better and not just, um, invent things.
Um, but I think, you know, AI is kind of going out, but we need to, you know, make sure we're being intelligent about how we use it, right? So, um, if you're using AI to code, maybe you should at least sort of know how to code as well. Uh, so you can kind of fact check it as you go.
I think it is crucial that as you're building production AI systems, you are doing thorough testing and there's techniques of grounding and, and rag, uh, is the, one of the, the classic ones for grounding is gimme information out of this corpus of data that I gave you. And that the, the, the original large language model is really just providing a user interface where you can ask things in natural language. It's the, the primary, um, large language model isn't the thing that is giving you the, the source of truth.
It's coming from your own internal, um, information as well. What we could spend a long time talking about ai, in fact, we'll, we'll spend many more podcasts and many more tech field day events, both AI infrastructure field days and AI field days. Uh, thank you very much for joining us today on the Tech Field Day podcast.
But before we go, where can people connect with you and carry this conversation on, Uh, to get ahold of me? Probably the best place is, uh, find me on LinkedIn, Russ Fellows. There's only a couple of them there.
There's another guy who makes, uh, mufflers in the UK for Volkswagen, Beatles. I'm not him, I'm the other Russ fellows. com.
Yeah, pretty similar story for me. I'm on uh LinkedIn, I am on Twitter, um, and then I'm on signal com as well. And you can find me on Signal do com or LinkedIn as Mr.
Brian J. Martin. And of course you can find me Alister Cook on LinkedIn or many of your other types of social media.
com site. So thank you so much for listening to this episode of the Tech Field Day podcast. If you enjoyed the discussion, please subscribe on YouTube.
If you'd like to see our smiling faces and in your favorite podcast application as well, so you don't miss an episode, do consider giving us a review and, uh, maybe a nice positive rating. This podcast was brought to you by Tick Field Day, the home of IT experts from across the enterprise and a part of the Future Group. For upcoming events and more episodes, head to Tick Field daycom slash podcasts or view us on Tech tv.
Thanks for listening and we'll see you next week.