Techstrong TV August 7, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
Hey, everyone. Welcome back here to Techstrong tv. You know, I'm really happy to have this next guest.
He's been with us before. Uh, he's actually been with us probably through a number of companies along his journey, and we're gonna hear about that. But let me intro introduce you if you don't know, to Assef aan, uh, and I mispronounced his name, but Assef is the co-founder and chief product Officer at Stack Gen Assef.
Correct me. How do we pronounce your last name? Aan.
I was right. All right. Yeah, everyone's, you're pretty close.
Even a blind, even a blind squirrel gets one Right. Once in a while. But thanks, Assef.
I appreciate having you on. How have you been? I've been good.
And thanks for having me on the show. Thank you. It's always a pleasure to have you on.
So, as Assef, I, as I mentioned, I've been interviewing you now longer than Stock Gen's been around even, but for people who aren't familiar with your journey, why don't you share a little bit about, uh, kinda where you've been and how you got here? Absolutely. I've been in the enterprise product development space for 30 plus years.
You know, this is my fifth startup at Stag Gen. Um, 20 plus years. Of those 30 years that I've spent building enterprise class products, I was, uh, focused in the security space, or I was focused on building security products.
So my first three startups were in the security space, you know, the first one in mobile security, second one in container security, and the third one in IAC security, which I was not part of the operational team, but, uh, I incubated the company, which was acquired by Tenable. It was a company called Accurates. Um, the fourth one was in the ML ops space, uh, which I did right before, uh, uh, stag Gen or Founding Stack Gen.
And now I am squarely in the DevOps ai ops, uh, gen AI ops space, Gen AI ops space. I love it. Yeah.
Look, but, you know, the good thing is security is part of all that, right? You, we can't do any of that and just ignore security. You know, I wrote, I wrote an article last week, say it said, the s in vibe coding is for security.
Mm-hmm. We can't forget security, even though we have in the past, you and I as security people know this, right? But we can't forget security going forward.
Um, for people who aren't familiar with Stack Gen Mm-hmm. Give them, give them the Stack Gen story, Asaf. Absolutely.
Um, stack Gen was founded, uh, starting from the very top right. Uh, stack Cgen was founded around mid of, uh, 2023, you know, so it's just been a close to two years since we have been at it. And what we initially focused on, which hasn't changed, right?
Our vision has always been right from day one, right? Even before the, the current agent, AI hype has always been that we want a developer focusing on the best possible developer experience, so that the developer just specifies the intent of wanting to deploy their application after having written the business logic in whatever language of their choice, right? And along came all of these cursor, uh, chat interfaces and all that to aid the developers.
But our North Star, the vision with which we started the company was always the autonomous infrastructure, right? So that the users, now, whether it be be they be developers or platform engineers or DevOps, they just specify the intent of creating the infrastructure and the infrastructure automatically gets provision. It ge it, it complies with the governance, security, and compliance, uh, uh, guard rails.
Uh, it complies. I mean, it, uh, self adapts, uh, and or heals itself. And it also optimizes, you know, so what we did till now, and, um, you know, while we worked towards, uh, our specific agents at the etic AI launch that I'm going to spend some time talking about in a few minutes, but, uh, what we have built is all the deterministic capabilities to, like, I like to call it sort of the bottom of the iceberg, right?
Because without determinism the agents, anybody can build agents these days, you know? But having that deterministic foundation is what we have spent time, and which is what positions stack gen, uh, or provides that unique ability to the Stack Gen platform to be able to stand, uh, I mean, be very unique in the market, and also at the same time be able to provide the capabilities, uh, towards working towards that autonomous infrastructure. I love it.
Thank you for that detailed kinda look. Because look, it's a, I don't have to tell you, it's a crazy market today. Everybody's has an AI story or an MCP server, and they're helping automate this and automate that, and it's important that people understand One thing we didn't mention the URL for Stack Gen.
Oh, what, what is the website? com. Excellent.
Alright, let's jump in. You know, you, you, you talked about a lot of things there, uhs, but I, I wanna talk specifically about autonomous infrastructure. Mm-hmm.
Right? And, you know, it, it, it, that's a loaded term, frankly, right? Let's start with this.
What does autonomous infrastructure mean to you as the chief product officer remind you here? Right, Excellent question. You know, I mean, it's very important to define, like you, uh, uh, as, as, as you're alluding to, uh, asking me the question, which is autonomous infrastructure to me and to, um, uh, to the entire team at Stack Gen means four things.
You know, the first one is that it should be self-provisioning from an intent. Okay? Alan could be a developer and could be a DevOps engineer or a platform engineer who wants to provision the infrastructure for his or their own needs.
Right? Now, there are different ways to capture that intent. It could be in the form of a natural language.
It could be in the form of a, a YAML specification file. It could be more explicit and deterministic, right? I mean, there are backstage we are working on, we already support Backstage had something called system models, uh, specification.
But without getting into the details, it's however the user is comfortable specifying that intent. So self-provisioning, okay? The next thing is, once you are provisioned, you do not want to provision some random stuff, because in large enterprises, they need things to be provisioned within the guard rail of security, within the guard rails of their compliance framework.
So it needs to be self-governing, right? As new policies are coming in, as policies are being applied, right, new vulnerabilities are detected. So the second important thing is it needs to be self-governing.
The third one, once it's been deployed, I mean the, the resources have been provisioned, infrastructure has been provisioned, it is being governed. What's the next thing, right? Because changes always happen that something breaks down, right?
I mean, so it needs to be self-healing slash self adapting, right? So that's the, the third most important thing. And the final one is self-optimizing, be it for the cost reasons for, for the business, uh, outcome reasons for SLA reasons.
So those are the four pillars of, um, based on which an autonomous infrastructure offering needs to be built. And that is what we at Stack General are building with a whole bunch of agents exposing certain higher level agents, uh, uh, uh, to the users. Excellent.
So let me just make sure I got this right, though. Stack Gen has developed their own agent AI agents that users can utilize in, in this autonomous infrastructure. That is correct, correct.
Yeah. So we have whole bunch of, uh, uh, lower level agents, if we can call them. So, right, uh, uh, AI agents just to, uh, to qualify.
But the agents that we are exposing to the users, there are seven of them along with our control play. So once again, when we talk about Agentic ai, um, um, uh, platform, right? Our autonomous infrastructure platform that we are working on, Alan, it comprises three different layers, right?
There is the, the, uh, you can call it the AI command center or the control claim. There is the foundational layer, which I was alluding to earlier, that we spent o over one and a half years building those foundational capabilities. And the third one is integrations, right?
Because as you were just alluding to MCP servers, we need to support the integrations, which we already have. Whole bunch of integrations with various different tools, various different MCP servers, and where the uniqueness comes for any agent, TKI offering, be it from Stack Gen or anybody else that is out there, the key differentiator is how good of your platform, how good of a platform you have in terms of capturing the knowledge from the tools MCP servers, and creating that context and providing that context within which the agents need to operate. And that is what we have built.
Excellent. Excellent. Now, a lot of companies are talking about MCP servers to help manage, coordinate, orchestrate, I guess is a good word.
All of these AI agents, both the AI agents from their own company as well as independent AI agents. Sounds like I'm selling insurance. Um, is that something, without getting us all in trouble, is that something stack gen's working on?
Yeah, absolutely. Uh, so once again, right? I mean, um, we are not, uh, in the business of defining the agent to agent communication.
We are leaving that to the Googles or AWS or Azures of the world as we speak. Actually, we do support, uh, a to a, uh, protocol for inter agent complication Yeah. And coordination uhhuh, but That's Quad Linux Foundation now, right?
Exactly. Right. I mean, so mm-hmm.
All of that, that, uh, communication layer, how things need to be sort of orchestrated and put together, that is not where we are focusing on. What we are focusing on is that it, uh, that that autonomous infrastructure capabilities that we are building through various different agents. But to answer your question very directly, Alan, regarding the MCP server, the short answer is that we have our own MCP servers as we speak.
We already support, uh, other MCP servers, other tools, as well as you can bring your own aj I like this term, BYO, right? So we walk in enterprise, they say that, Hey, we already have an MMCP server. Yes, we'll hook it up to, I think of it as in those good old movies they used to show, right?
Skynet, right? Uh, there are tentacles that are, uh, that are spreading out, and it is sucking instead of blood, which seems weird and gory, but it is sucking the, the, the data from the data resources and forming that knowledge and getting more and more intelligent, you know? Agreed, agreed.
Um, look, I, I have to ask you this question just because of this nature of where we live today, right? Is this all future wear or is this stuff that's ready right now? Um, some of it is ready, as you know, right?
Uh, uh, let me, uh, sort of, uh, go back to the last statement that I made. When you are in the business of building a knowledge base, it's just like us, uh, humans, right? We are constantly learning.
The same is the case with agents, you know, as more and more data is fed to them or they have access to more and more data, either directly through tools or, uh, MCP servers or indirectly through other agents, right? For agents also, it's a lifelong learning journey. So we are, but to answer your question about what is it that we are launching, we are launching a couple of agents, you know, but, uh, we are continuing to build other agents that are going to be in preview and various different agents are going to have different kind of GA or general availability timelines, right?
And we will continue building the agents. So this is, this is, we are on, I would say, at least 10 plus years journey, just building the capabilities, refining the agents, and providing the capabilities so that any user can just come in and in the whatever natural language of their choice, they just specify the intent and voila, right? Everything else is taken care of for them.
So as, as assef with the, with the, uh, the advantage of having my notes in front of me, I, on the issue of availability, I, I, I just wanted to put out there, 'cause you know, we do these without notes. You and I, we've been doing these a long time, but the Stack builder, uh, AI agents, it's in early access for app developers. And that comes out July 29th.
So by the time people watch this, it is probably available and it's beta for platform engineers right now. com is one of our sites, right? It's our newest site.
If you watching it through there, you could go get it right now. com, cloud native now, whatever, by the, actually by the time you watch this, it's probably available as preview there as well. So I wanted to put that in there.
com. Um, I would love to get the feedback. I think we've hit it.
Yeah, would love to have people try it out. Well, I open the stack as well. Yep.
All good stuff. Assef, continued success to you and the team at Stacked. Some of my favorite people.
Come back soon and keep us posted. Okay. Thank you so much once again for having me.
Thanks a lot for the kind wishes. Always. com, autonomous infrastructure.
It's a term you're gonna be hearing more of, I'm sure. Uh, thank you for coming on. You're watching Techstrong tv.
We'll take a break. We'll be right back. Hey guys, thanks with Drought, we're here with Dave Donatelli is the CEO for Riverbed, and we're talking about how AI is gonna be applied to network observability with a bunch of new offerings that these guys are rolling out.
Dave, welcome to the show. Hey, Mike, great to see you again. Yeah.
Um, we've been talking about observability and networking for a long, long time and I guess everybody knows now there's this thing called AI in the land, but how do these things come together in some sort of, uh, primordial suit that becomes a catalyst for changing the way we think about networking and walk us through it a little bit. Sure. Well, you know, Riverbed's had a very exciting year of innovation already.
So we did a major launch in April of this year for our, in essence desktop and mobile ai, uh, around observability. Then we did a huge acceleration launch in May. And now this is our third launch we're doing right now, which is around our classic NPM products.
And what we've done with those NPM products is we've not only updated the hardware aspect of them that runs now three times faster. But addition, we've added our IQ technology on top so that people can now collectively pull the data from NPM sources from their desktop sources together and apply AI intelligence to it. Whether that's generative AI or agent AI or whatever, you know, all the major forms of AI available today on people spending more time observing network performance these days as it relates to applications.
It seems to me a lot more of the applications are latency sensitive these days. And is this becoming something of a, of art as much as it is science? Well, I think the art part is that it continues to become more challenging, right?
Because people are running applications, you know, in traditional environments, they're running into the cloud, they have SaaS based applications and it gets more and more challenging for customers to sort out where problems are. For instance, in the SaaS world, although you're usually depending on your SaaS supplier to make sure that application works if there is a problem. And, and we've seen that with our customers, they've had issues.
It takes a while for them to really sort out where that issue is coming from. Is it on their side or on the SaaS provider's side as just an example. So therefore that elongates troubleshooting times, it certainly frustrates end users who are looking for the availability of the application and therefore people are looking for tools to help sort through these issues.
And that's what we're delivering. So where are we on this AI spectrum? Because some folks, early on we started with co-pilots and now everybody's talking about AI agents.
And are we just talking about something that, uh, will alert me to an issue or might it go out and fix the issue? Well, the good news is we, we offer what we call automations or remediations. So that gives you the customer the ability to put in pre-configured remediations of problems and then report what's happened in places like ServiceNow.
So in essence, we can automatically open up a call, fix a common problem you're seeing through automation, through ai, and then also close that call out so you know what happened. And you know, we see many of the large financial institutions as an example, using this technology to both reduce mean time to repair and at the same time reduce the total number of calls coming in since they, you know, through ai we can also do predictive work. So if you see something that's gonna run off the rails, actually launch a remediation before something goes bad.
And you know, the best problem is they always say is a problem that doesn't occur. And that's what this new technology allows. So what will be the role in the network engineer going forward?
'cause everybody's having these kind of moments where they're ultimately thrilled that they don't have to do all this manual work and then, you know, somewhat concerned about what it is that they will be doing for a living. I think they're gonna be very busy for a long period of time. You know, all we're trying to, you know, if you look at the technologies today, what they help to do is take out a lot of kind of the, in essence, the drudge work of the job and let 'em focus on really the smart things that they do to really understand what's happening across the environment and fix things without, again, wasting a lot of time collecting data and trying to find the proverbial needle in the haystack.
But if you look at the amount of data growth that's happening now, a lot of it actually even caused by ai. Um, everybody working in the network space has plenty of work to do even despite all the great new innovations that are out there. Do you think that as we advance this, that there might be more collaboration across all these IT silos?
Because the networking team has often been an island onto itself, apart from the application development team and everybody else. And usually the one thing everybody can agree on is it's the networking guy's fault. Yeah.
A lot of the networking folks talk to me about what I, what they term mean, time to innocence, right? They spend a lot of their time trying to say, it's not me. 'cause everybody points, fingers at the network.
What I mentioned with all these announcements we've been doing is all about building the Riverbed platform. And it's ga it's in the marketplace today. Customers can run it.
What's unique about it is it expands applications, networks, and endpoints. So all the major things that you're gonna touch, you know, in, in terms of diagnosis or a problem, we can now look at and we put that at all that data into what we call the Riverbed data store. So we have a common pool of data across all those areas.
And in that common pool is where we apply our AI technology. So in essence, what it's meant to do is to start to solve that problem of finger pointing among silos. With unified data, you get to a more, you know, unified answer.
And by also unifying your data, you get to a more accurate answer because you have, you know, data from all these different places in one place at the same time. And, uh, that speeds problem determination and certainly speeds problem resolution for our customers. So you've been at this a long time and, and I'm wondering, will the rise of AI in that common data pool start to help us to converge some of these job functions in it?
I don't think that the jobs are going away, but the way that we are structured might change. 'cause maybe we can be structured around some sort of outcome rather than around the core technologies that we're trying to babysit. Well, you know, I I I, I'd answer it slightly differently.
Here's what I do think is happening, like short term and then we can talk a little longer term. I think short term, what I see with most of our customers around the world is they're all doing some form of tools, consolidation. And if you think about it, having all these very distinct point product tools really causes some of the silos that you see, right?
'cause people are just expert on their tool, then they have to talk to someone else who's expert on another tool. So clearly customers are now starting to consolidate down because they literally have dozens and dozens of tools in these very large organizations trying to figure out what's going on. So I think that's a first step.
And as that happens, then you can start to get to, to the point you just mentioned, Mike, which is then you can start to have people look more cross domain and start to break down some of those silos. AI also demands this because people, you know, what's the biggest challenge around ai For most enterprises and organizations, it's getting your data in one place in a common format. So, you know, I think the first piece that's practical that's happening right now that we see everywhere again is app application, consolidation on observability.
From there then you start to centralize your data and from there then you'll start to see people again looking more cross domain would be my view of it. Do you think folks are distinguishing between monitoring and observability, or do they all just consider one extension on the other? Because, um, you know, when I think of monitoring, I'm like, well, it's a bunch of predefined metrics that we're gonna track.
Observability to me is more about I can query stuff and go look for that needle in a haystack that I might not know existed in the first place. Yeah, I, I, I agree with you. It is different.
And really what observability is moving towards very rapidly is actioning. So it's one, I, I personally never liked the word observability in a sense. 'cause it sounds so passive, right?
Someone observing what's happening and what people really want to do is prevent problems or if they have a problem, they wanna fix it very quickly. And so when we talk about automations and remediations, we have, you know, on the AI front, something called predictive AI where you can keep things and and, and understand that they are about ready to go south. You need to take action, alert somebody, things like that.
You make the products much more action oriented and then much more effective for customers 'cause they're getting better value by fixing things quicker or preventing problems from happening in the first place. And that to me is the exciting part of where the technology is heading. And you know, this is always done against a backdrop of more and more complex environments.
You know, it environments are more complex today than they were a year ago, uh, because of all the new technologies that's coming out all the time. So it's always this race between can the tools keep up with the innovation and vice versa. Mm-hmm.
You mentioned earlier, meantime to innocence and I've always argued that the second most important metric is meantime the remediation after that, which is also known as meantime to return to innocence. Um, is that gonna get faster as we go along? I mean, because the amount of time that I have an issue, I should be able to reduce.
'cause I have some AI tool that will discover it faster and hopefully fix it faster. Well, we're shipping products today that literally will alert you to your phone that says you're having a problem. So let's say you're at a scenario, right?
You've left work, maybe you're out eating lunch and um, you'll get an alert on your phone, you're having a problem, which everybody dreads. And then we, we give you in, in essence what this three different circles, network application, uh, endpoint. And from there, you know, green, green, red, well the red one means this is what AI is pointing to the problem.
It will prompt, it'll tell you what the problem is and then suggests an automated remediation that you can trigger from your phone to fix. And that's available today. General, you know, generally available now.
And this technology is only gonna progress further and and quicker. So, you know, we're on a pace to do that now and it's moving as everybody knows very, very quickly in the marketplace. The, the ability, you know, what we can do this year versus what we could do last year has progressed immensely.
And it's on a pace to keep going because again, the more data you have and the more you run your algorithms, the smarter they get and the more they can handle. So I think it's a very exciting future. And I think, again, in my, in my judgment and observability, it's nothing to fear.
It actually makes people's lives much more enjoyable in terms of doing their, their job. Mm-hmm. Speaking of observability, we've always thought about networking in terms of number of endpoints and number of end users accessing.
How many things in the backend will AI just throw that math out of the window? Because as I look at it, I'm like, well now there's gonna be AI agents, hundreds of thousands of these things that are essentially end users and they're gonna be calling more data than ever. So, uh, are we gonna have just a network bandwidth issue because we're gonna have all this stuff on the front end and the back end that's gonna be exponentially greater?
Well, uh, uh, well I'll give you a real example. So, you know, we, I i, I don't, I can't mention names, but I'll say, look, we've been talking to, let's call them one of the major cloud providers and they're, they're referencing their customers who to reload their AI models is taking days, not hours, you know, days over, you know, over a week, which is a little bit like back to the future. I feel like I went back to the 1980s right when moving data was so slow and it's just the sheer volume of data required.
So that's why if you look at our acceleration products, you know, there, we grow our acceleration business very rapidly in the first half of this year. 'cause people need those in order to speed data, even though the network pipes have never been fatter, right? So they, so they need that.
The new technology is driving those types of bottlenecks where people need these new solutions. And um, so it's very interesting if you, if you look at the agents themselves, you know, you're having bots now talking to bots. What I think will be kind of the, the interesting thing to see is, you know, we allow ours to be configured by customers.
'cause they get somewhat nervous of, Hey, how many bots are you gonna create? What is this gonna do to my network? Is, you know, as you said, is the network just gonna be too bogged down to really work through all this?
So it's, it's a transitional time. Um, it is very exciting, but I think it is gonna be a transition versus a revolution mainly. 'cause customers I think are not gonna wanna unleash, um, agentic without restrictions in their environment.
'cause they're worried about, as you said, secondary effects, like slowing their network too much. Alright, and then I'm gonna heading 'em back to the future. When we revoke younger, they taught us that nothing good happens when you move data and you should always bring the compute to the data.
And then the cloud came along and we wound up moving a lot of data to the compute. Have we come full circle now and are we kind of going back to, well, let's bring the compute to the data because, uh, the networking essentially needs to be more efficient and that will work better if we have more cash at the place where the data's being accessed? Yeah, I mean, I, if you look at our data store, so our data store by the way, is a free product we make, and this is part of this, you know, announcement that, that runs all this ai, we actually leave the data in place and only call data as necessary.
So our, our algorithms are smart enough to know, hey, this is a hot zone where the problem is only pull that data versus to your point, if you just tried to stream all the network data out there constantly all the time, one, you couldn't have enough place to store, you know, you'd have to have a whole different storage form just to do that. Probably couldn't scale well and would really crush your network. So yeah, I think they agreed upon architecture out there is leave as much data in place as you can, don't move it as much as you can.
You heard my example of taking over weeks for people who are trying to move and it's the most practical way to do it. Now the challenge with that, of course is getting your, your data store and ability to actually work that way. You know, in our case it's a proprietary design we designed from the ground up ourselves strictly for that purpose.
Uh, most conventional technology though, doesn't work that way outta the box. So that, that requires other, you know, architectural considerations. Ultimately.
Then, what's your best advice for folks who are in the networking space these days? Should they just sit tight and wait for all this to come to be? Or are there things they should be doing more proactively to get ready for what amounts to a new era of computing?
Well, I think first of all, I think sitting tight is, is the worst thing you can do right now in, in that sense. I, you know, to me, and I, as you mentioned, I've been doing this, you know, for decades. This is the most exciting change I've seen in my career in the sense that it really does fundamentally change everything.
And I think, um, you know, most people are gonna be like pre AI workers, post AI workers, right? It's if your career ended before ai, you, you're really gonna be kind of set back. 'cause you know, the future I think is very exciting.
I will say there's tools available to them now. Those tools do speed troubleshooting. We've got tons of real world customers already doing it.
Um, you know, I try not to overhype, you know, we, we have not solved world hunger yet. That's gonna take time. But I do think that, uh, the progression of the technology we see has, has fundamentally altered the game for people.
Like when you have people say, Hey, I've reduced my meantime to repair by 30%, I've reduced the amount of calls that come in by 30% all helpful. And it allows them to stay ahead of this ever complex curve that they're always battling. So there's real things they can do today.
And I'm very convinced, you know, if you look at our rate of innovation, we've launched 25 new products in the last two years, um, with the rate of innovation, there's gonna be better and better solutions coming. So it's important to kind of get on the track to learn it. And then so you're ready as all the new stuff comes along as well.
And of course, a lot of folks are concerned about how their job may or may not exist in the age of the enterprise where we can scale more with fewer people on the IT team. However, conversely, it also seems to me like more organizations will be able to afford to build more complex networking than ever. So might not there be ultimately more organizations is looking to hire networking people than there were before.
Ai. If you look at the history of our market, it's, it's actually a history of what I call the expanding circles. So I mean, when I first started mainframe, you know, dating myself a little mainframe was the core architecture.
And you know, desktop PCs were just coming in and people were like, oh, client. And then obviously client server was a part of this whole movement and what happened, guess what? Here we are now, decades later, we're still selling mainframes, you know, and we're still selling desktops and everybody's got mobility and then everybody has the cloud, everybody has SaaS and now we're doing ai.
And I, I, my, I'm doing my hands moving outward 'cause why? Because the total market did nothing but grow, right? There's more people working in tech than there were when I started.
The market size itself, you know, now measured, you know, in the trillions is much bigger than it's ever been. And I don't think that changes, you know, the form might change a little bit, but my joke is as well that, you know, when the cloud first came out, what did everybody say? It's timeshare.
You know, if you, if you're around in the sixties, so, you know, we do things a little differently, but the fundamental principles are all still the same. You know, ai, I think people way over complicate, right? It's about centralizing data, running very smart algorithms against it, getting those algorithms smarter than applying them to a problem in your business.
If you think about it that way, it's not so scary. And, um, and again, I think it opens up more opportunities for people and I think our industry continues to grow and as you said, the less expensive we make things, the more use cases we find. And it's always been that way, and I don't think that's gonna change.
All right folks, you heard it here. The best time to be in it and networking specifically is right now. Hey, nice to meeting on the show, Mike.
Great. See you again. Thank you.
All right, and back to you guys in the studio. Hello everyone. Thanks for joining us today on the inaugural Red Hat Cloud Fridays with AWS session where you get real talk about real solutions.
This is going to be an introductory session where myself and my colleague on video here from AWS Thanos es Princes. Did I nearly get it right? Thanos?
You can introduce yourself almost. You can just say Thanos, Just say Amish. Okay.
So my, my colleague Thanos is here to join us to talk through what we are doing with the Klan Fridays event and introduce you to why AWS and Red Hat value the partnership between the two organizations. So much the way this session's going to go, we're gonna talk about the event in entirety and the different sessions that you can enjoy today if you choose to. And then go on to the partnership itself highlights some of Red Hat's software, which is available through AWS and how that partnership and that software can really help you as customers, giving you some real examples of case studies to give you a guide to what you could expect from that benefit.
So the itinerary for today is as follows. You'll have this introductory session for about 30 minutes, then there'll be a break where an interactive session with a coffee maker. We'll go through some ideas for how you might be able to get your caffeine fixed, uh, for the next events that come along during this Count Crowd Friday.
Then afterwards, we're hoping you'll, you will gather with us for the first of our breakout sessions. The breakout sessions are designed to have two sessions running simultaneously. The first breakout sessions will be in one stream, a session about Red Hat OpenShift service on AWS, where we'll talk about accelerating and innovating to deliver value at speed using Rosa.
And then the second session that runs concurrently will be about Red Hat Enterprise Linux, where we will, um, talk about beyond the standard unlocking re's full value on AWS. You can choose to go to either session and we will of course make the other session available if you are interested in both topics to catch up with later during the second breakout. You can see there that, uh, we've got a session, um, that's called your Fast Track to it Automation Genius, where we focus on Ansible automation platform and how you can consume it and best use it in an AWS environment.
And then at the same time also we will have a session about maximizing your marketplace spend with AWS. As I said, you will have to choose one or the other if you stay with the breakouts, but you will be able to catch up with the other one later as a recorded session. Then we are going to, uh, wrap up the event with a real time, uh, question and answer, um, session where we talk about takeaways, answer any questions that come up, and, um, then move into a very informal possibility to have a networking lounge.
The networking lounge, um, will be available for you voluntarily. And there if you want to come in and speak to us as presenters, um, in an informal way, talk about the way you are using software and how you might want to utilize it in different fashions, then we'll be available there to talk to you, um, face-to-face. So that's what we're doing today, but let's talk about the really essential, uh, partnership that Red Hat and AWS has formed and why we have the day today to talk to you.
Well, Thanos is the best person to talk to you about the power of AWS so over to you Thanos. Thank you Simon. Thank you Aaron.
Thank you for the introduction. Um, I'm Tan es and I'm super excited to be joining, uh, this event, the Cloud Fridays from Red Hat. I'm representing AWS I'm the partner development specialist for, uh, red Hat at AWS and I'm here to provide you with a brief overview of the world's most comprehensive and broadly adopted cloud.
And also talk about our partnership with Red Hat as we're jointly addressing customers, including some of the most, uh, the largest enterprises, fast growing startups and leading government agencies. AWS almost 19 years old has experienced a remarkable growth over the past several years. Yet we estimate that only 15% of IT workloads have moved to the cloud, indicating an enormous potential ahead.
Our mission is to help customers like you lower costs become more agile and innovate faster. Let me explain why AWS gives this transformation through five key differentiators. First, it's all about functionality.
AWS has significantly more services than any other cloud provider. Most, most importantly, we have the deepest functionality within those services. Whether you are running basic, uh, web applications or complex AI workloads, we have the right tools optimized for both cost and uh, performance.
This makes it faster, easier and more cost effective to move your existing applications to the cloud and build nearly anything you can imagine. We have also built the world's largest, and I may add the most dynamic cloud community with millions of active customers and over a hundred of thousand partners globally. That gives us the right to claim experience with every type of customer and use case experience that is always augmented, uh, by a wide selection of system integrators.
With deep cloud expertise and a much broader collection of third party software you can use on top of AWS security remains our number one job. And this is a central pillar around which AWS infrastructure and services are designed and managed. AWS is detected to be the most flexible and secure cloud computing environment available built to satisfy the strictest security requirements for the military, global banks and other high sensitivity organizations.
As we commonly say at AWS, we've built our services with secure by design principles from day one, and that means including features that are, that are the bar high for our customers default security posture. Of course, let's not forget our ecosystem of security partners and solutions through AWS marketplace, which enables customers to create a multi-layered defense with security technology and consulting services from familiar solution providers they already know and trust. Fourth, innovation, innovation is in our DNA.
We pioneered several as computing with Lambda, we democratized machine learning with SageMaker. AWS is innovating faster than anyone else, especially in the new areas such as artificial intelligence and machine learning, the internet of things and quantum computing. Our pace of innovation is continuously accelerating with our customer obsession to help customers solve problems faster, leverage the latest technologies to experiment and innovate more quickly, differentiate their experience and transform their business.
What is unique about our innovation approach approach is that 90% comes directly from customer feedback. We listen, we learn and we build exactly what you need. Finally, we have experience with 18 years of operating at global scale, running a wide variety of use cases, allowing you the flexibility of choosing how and where you want us to run your workloads.
With big spanning 114 availability zones with 36 re within 36 regions, we process millions of requests per second, maintain consistent load latency and have proven that customers can depend upon us for the most important applications now and to the future. And not to forget that we are still expanding. That's one of the most proven operational expertise out there at greater scale of any cloud provider.
Our unmatched experience, maturity, liability, security, and performance is something that we can depend upon for most of our applications. These are not just claims, they are backed up by numbers. And our customers, 90% of our fortune of Fortune 100 companies use AWS.
Whether you are looking to reduce costs, accelerating innovation, or transforming your business, AWS provides the most comprehensive, secure and proven platform to build your future on and a natural choice for many of our partners to deliver their offerings, solutions, services upon. At AWS we say there is no compression algorithm for experience. What does it mean?
You can't shortcut the lessons learned from running infrastructure at a massive scale for every imaginable use case. This experience from AWS translate translates directly into reliability performance for customer workloads and that work in mind experience. And coming into the partnership between Red Hat and a WSA strategic synergy that delivers a trusted enterprise grade platform for accelerating cloud adoption and modernization across hybrid environments, leveraging Red Hat's expertise in open source solutions and AWS comprehensive cloud infrastructure.
Customers can confidently run their mission critical workloads on AWS while maintaining enterprise support and security with support for both traditional and containerized applications. Through rail and r plus integration with Red Hat products on AWS uh, marketplace, the partnership enables seamless workload mobility to AWS Red Hat and AWS can help your organization run smoothly on AWS cloud, migrate your VMs to a new platform, simplify hybrid cloud management and adopt a comprehensive AI portfolio to support each, uh, each stage of the AI journey With Red Hat, we share a common vision and have a longstanding relationship with a partnership. Going back to 2008, a partnership that has recently deepened and strengthened focusing on hybrid cloud innovation, virtualization and AI deployment.
We have signed both parties have signed a strategic collaboration agreement to propel virtualization and AI innovation across the hybrid cloud supported by the new marketplace availability and jointly optimized cloud platforms and synergy between our companies that enables you and your organizations to navigate the complexities of digital transformation more efficiently, ensuring you remain agile and competitive in an increasingly technology driven landscape. And with that, I'll pass it back to Simon to explain more on how this, how Red Hat can help you more within this trip. Thank you.
Thank you Thanos. That's a fantastic introduction to the power of AWS one party in this really powerful partnership. So give me a few moments to explain how powerful Red Hat is too and why a vendor like AWS would really want to partner with us.
Well, of course Red Hat's very proud to say we are the world's leading open source IT solution provider. Obviously a few years ago that was proven out by, uh, IBM's investment into us as an organization. And um, at the point we were invested into, um, these metrics, um, really, uh, show how powerful Red Hat had become.
So at the time we were a 3 billion open source company from dollar point of view. And of course, over the years since that, um, purchase by IBM took place, we have only grown even greater, um, most organizations globally, um, particularly the large ones utilize our software in some description. Uh, we have nearly 20,000 employees now across most of the globe.
So as a vendor, we're very proud of our position and what we can bring to the AWS partnership. So Thanos has already told you how important AWS sees partnership, but I always like to show this slide to, um, really call out, um, how powerful senior leaders in AWS understand this power, uh, this relationship to be. Um, the particularly strong part of this slide is the quote Dan at the bottom from Andy Jassy, one of the leaders at um, AWS.
And he calls out the fact that because Red Hat has such a global reach and has revolutionized, um, Linux services within organizations and open source capability, we are obviously an important vendor to them. And you can see there with the metrics on the right hand side that over 60,000 organizations customers of Red Hat work on the AWS platform with us in the partnership. And as Thanos did mention, we have been partners from very early on, A quick spot check might be to ask anyone if they know when AWS delivered its first services.
So that was only, I believe around 2006. If Thanos nods then I think I'm about correct, almost 19 years, almost 19 years old now. Yes.
So within a couple of years, red Hat saw that their customers and the wider it market were seeing great value in working with AWS on their global service delivery. And as you can see here, it's, we've got an example of how much our partnership has innovated since its inception. So over time we've added more and more of our capability, obviously concentrating initially on our Red Hat at Linux Platform RL, but then bringing in other services as they became more applicable to our customers.
In recent years, AWS has worked very closely with Red Hat to bring those services even closer together. So, um, in 2001, I actually, um, joined Red Hats shortly before the release of Red Hat OpenShift service on AWS, the Rosa service that Thanos mentioned earlier. And that's a very special moment in time from a Red Hat point of view because it was the first service that Red Hat and AWS delivered jointly to our customers to give them the value of Red Hat software, but also supported directly by AWS and Red Hat site reliability Engineering underneath.
Over time we've enhanced that. Um, I've got a call out for the new, very new, in fact only just announced that reinvent in December. Um, the new managed service of Ansible automation platform that's now available to customers where, um, using AWS's Cloud Red Hat's able to deliver, um, the managed control planes for customers Ansible, if the customers are finding it difficult to manage those environments themselves.
And recently we have even expanded this relationship to allow distribution partners to help partner organizations deliver value to end customers when they're looking at purchasing with a value add partner. Um, and those distributors are able to help us in that overall process of sale on AWS's marketplace. So that tells us why the partnership is important to the two organizations and who we are, but I'm sure you are asking yourself what actual software products can Red Fat sell us via AWS?
And this blue side is actually an AWS slide. I stole it from a deck that AWS presented, uh, last year at the Red Hat Summit Connect events where we go around important cities within our regions and, um, our important, um, partner vendors present their solutions to our customers. And this side points out that actually there's two major forms of delivery of Red Hat software to customers via A to Bs.
There's, um, the original, as I like to think of it, capability where AWS from their console sell on behalf of Red Hat to customers. Our software services baked into EC2 instances that they deliver on their cloud. Now you can see there that very heavily concentrates on Red Hat Enterprise Linux.
And over time we've expanded the service to include different facets of Red Hat Enterprise Linux to give customers the most powerful capability possible to utilize Red Hat software through AWS console. On the right hand side, we can also now sell Red Hat software through AWS marketplace. Thanos did call out the fact that AWS have innovated throughout that nearly 19 years of their existence.
And one of the fantastic innovations they've brought to market over the last 12 years is their e-commerce marketplace solution. This drives, um, customers towards the ability to buy independent software vendors such as Red Hat's software packages to package on top of AWS's, um, networked global services. And in this case, red Hat has now been able to, over the last couple of years, roll out more and more of our software to become available via AWS marketplace.
It not only includes the uh, red Hat solutions that are available on console, but it also includes OpenShift services, Ansible based services, some of our middleware services such as JBoss and um, even extensions such as being able to take, um, a third party, uh, Linux may be based on CentOS, an open source project, which was based on Red Hat Enterprise Linux. But now that those services no longer get a level of support, we even offer a listing on the marketplace that allows organizations to migrate, um, those CentOS workloads into RL on the AWS marketplace. I'll also call, call out a recent innovation where Red Hat has actually embedded some, um, predictive AI capability such as a large language model in the IBM Granite Model and, um, projects from the open source community such as Instruct Labs, which allow organizations to build prototype test and deploy their first predictive AI workloads to their customers.
Um, and that comes in the form of Red Hat Enterprise in server ai and that is one of the listings that's available on AWS today. You can even buy non-software products there as well, such as Red Hat Learning subscriptions and our support packages, sorry, consultancy packages very quickly. Um, it's very difficult to explain to organizations the difference between AWS console consumption of Red Hat software and AWS marketplace software.
So I try to build a couple of slides to give you an example of how the two things work differently because sometimes you may have a choice of buying the same solution such as Red Hat Enterprise xenex from either capability in the first case, the case number one, let's concentrate on the AWS console offerings. That's actually Red Hat Software sold by A-W-S-A-W-S. Um, take that product against the defined price and deliver it to customers directly.
They sell the product to the customers and they provide support for that software directly to their customers. With Red Hat acting as a third line backup support agent on AWS's behalf. If you then move to concentrate on how the marketplace works, it is subtly different.
The seller of record for a marketplace listing is actually Red Hat themselves in amea. It would normally be listed as Red Hat Limited in this case because it's Red Hat that's selling you the solution. Even though we're using AWS's marketplace, red Hat has a responsibility of delivering all the support for that software solution to the customer.
And importantly, to many organizations, red Hat is able to take into account different pricing models for a customer in the form of what's called a private offer, which will recognize customers' commitments to overall usage of Red Hat's software over time, rather than being a standardized pricing through the initial console or PayGo offering, um, that we discussed earlier. Importantly though, red Hat's trying to make sure that all our software's available to you. So here's a quick table which shows you that you might be able to buy some of these products from the first option or the second option, or actually you've got a choice between either.
But importantly all of them are available today to you via AWS. I'd like to take a moment though to call out my fantastic new service that I'm very proud of. So I did touch on it when I was describing the large list of software that's available from Red Hat via the marketplace today, but I really want to give a moment to concentrate on that technology.
It's a bit of a bit of a pet project for me. So this solution was released, as I said, announced in December at Reinvent in the us And what this solution is, is it's run by, uh, red Hat and we're integrating a W S's um, services to deliver the control plane of Ansible automation platform straight to our customers. It's billed via the AWS marketplace.
Private offers are available for organizations if they want to enter into commitment, um, contracts with us. And importantly, any commitment they make is recognized against, um, PPA private purchase agreements they may already have with AWS as well as that agreement with Red Hat. And that starts to dig into the customer value that AWS and Red Hat are bringing to you in our partnership.
Essentially through the partnership, we want to be able to deliver a reach to our customers, the benefits of AWS and their powerful, um, cloud Global services cannot be denied. And by being able to deliver Red Hat's technology combined with that capability further extends the ability for customers to enter into an open hybrid cloud approach. Many customers today are moving to the cloud, but many of them feel they still need to deliver assets in more traditional models, maybe on premises.
And when you combine the capability of being able to deliver Red Hat software in both those locations in the same way through the same procurement tensions, we are providing reach for organizations to migrate and augment their capability as rapidly as possible. And that's the speed that we think we bring to organizations. The managed services I've touched on, Rosa managed a a p the capability to have a managed advanced cluster security platform, wrapping your Kubernetes resources.
All these things are built with speed in mind and as speed to value for customers. What we are trying to do with AWS is squeeze the amount of time it takes for organizations to build their services and accelerate organizations into the situation where they're delivering powerful solutions on top of those services rather than concentrating on engineering the building of them. But at the same time, we are delivering all the control, visibility, and risk management that Red Hat provides with AWS.
We have great visibility tools that we will go into in more detail during the breakout sessions during the Cloud Friday, which help organizations make sure that even though they're traveling at speed, they're not incurring great risk. And finally, here's some of those case studies that I was talking about at the start. Red Hat's business on AWS is now massive and we have some of the biggest organizations in the globe working with us in that partnership in Europe today.
Some great examples across all the different software products and services that we are delivering. And As you can see here from a Red Hat OpenShift service on AWS point of view, bp, the well-known energy company, is delivering very powerful business transformation using our ROSA service in their organization. And we're very proud to say, has created a full case study and video to, uh, walk customers through that, um, journey that they took.
And if you are interested in that story, the breakout session, concentrating on ELL will give you much more details. The second example there, as I said to you earlier, I'm very proud of the managed Ansible Automation platform service, and it's just been released. And part of why I'm so proud of it is I work to help the Department of Work and Pensions in the uk.
As most of you probably know, the UK government is rather large, and the DWP is a very large part of that large government. And they have found delivering automation across their organization and all the, um, advances that brings to them as an IT operation, they have found it very hard to deliver across their whole infrastructure. And the managed ible automation service from AWS has given them the opportunity to centralize that delivery and rollout to their whole organization in standardized fashion.
Again, there is a session in the second breakout where myself and a great colleague from Italy discussed the power of this service and Ansible overall. And we will dig into that case study in more detail there from a Red Hat Enterprise Linux point of view, we also, um, I'm very happy to say, have another very large UK government body who is the largest pego consumer or console rail consumer for Red Hat, um, on AWS globally. They use it extensively and they find the power of the dynamic capability to turn on rail services on EC2 dynamically whenever they need them, wherever they need them, um, a great value for their organization.
And we will be, uh, driving a separate, um, session to talk about, um, the rail services as well during the breakouts. So with that said, we're coming to wrap up this introductory session. I'll quickly remind you about the itinerary today and also take opportunity to thank Thanos for joining us.
It's very, um, exciting to have AWS to come and speak to our customers at any point in time, point in time, and I think it really helped show customers the value of our partnership together. So what's gonna happen after this? It's, thank you.
So let's remind ourselves it's gonna be a short, um, breakout kind of session where, um, a coffee expert, we'll talk to you about your caffeine fix. You probably need it after listening to Thanos and I for this long in the introduction. And then there's going to be the breakout sessions.
Importantly, you can, um, during the session being delivered today and Cloud Fridays, you will have to pick one of the sessions in each of the breakouts because each pairing run concurrently. But we do encourage you to come back and watch the other breakout session as well as it will be made available as a recorded resource to you. But yeah, I think Simon, I think it's important for everybody, absolutely everybody to access all sessions, all sessions.
Thanks. Thank you. And importantly, though, just, um, to underline each one of those sessions covers the different pillars of our software, which is Red Hat's, OpenShift, red Hat's, enterprise ux, red Hat's, uh, automation platform Ansible, and our capability to deliver value through the AWS marketplace.
Then we will have a, um, a wrap up session where we will, um, give, uh, our feedback on the overall day, give opportunity to answer q and a if questions have been asked during the sessions, and allow you to ask questions directly of our expert panel. And then afterwards, we are going to provide what's called a networking lounge, where you can join those experts informally for a short while and talk to them about your, um, requirements, talk to them about your software usage or just come in to say hello and tell us who you are. It would be wonderful if you could join us for all these sessions.
And then, um, just want to leave you with some resources as well if you follow these QR codes. There's a lot of information there about the ride wider, um, partnership that helps support this introduction session, um, separately from the breakouts, which will carry on for the rest of the event. And that just sees us with a formal thank you.
Thank you to everyone for joining us, and please stick with us for the great sessions. We have to come. Goodbye.
Enjoy, Enjoy it. Hello everyone. Welcome back to the six five Summit 2025.
We are here in the semiconductor track and we've got a great spotlight session. Excited to have you join me here. I have Chris Koopmans back for another conversation with Marvell.
How are you doing today, Chris? I'm Doing great. How are you?
Oh, it's, it's been a, a rush the last couple of years. You know, this show Chris, is AI unleashed and you know, you've been a keynote for us a few different times. I enjoy every year sitting down with you.
Um, I just thinking about the last couple years, how the conversation has progressed, Marvell has been moving along in the space, but you know, where I'd love to start this conversation is just a little bit of your general observations on sort of how the AI market is moving. You're in it in so many different ways. Sure.
Um, so why don't we, why don't we start there? AI unleashes a perfect, uh, title because it is, it's unlike anything I've ever seen in my career. Um, every time we think, wow, this thing is huge and it's, can it really grow that fast from this point into the future?
And then if you fast forward any time period, one quarter, one year, we look at it, we, it was faster. And then you ask yourself the question again, can it continue to grow this fast? And it's evolving really, really quickly.
Um, we're just seeing the levels of data center CapEx spend, um, just un unbelievable. And the amount of interest and desire for both, for much of our solutions, both high speed connectivity and building out custom AI infrastructure platforms, the opportunity set just continues to explode. So it's truly an exciting time to be in the infrastructure space.
Yeah. And and your business did really make a significant pivot and you were one of the companies that came out early and really were able to be declarative and sort of how AI was impacting your business. Right?
But I can't really let this conversation go too long without talking about the XPU space. Sure. There is, Chris, so much excitement about, you know, the custom silicon.
We've seen hundreds of billions of TAM added in the AI chip space. Um, we think the next frontier is going to be custom, um, the hyperscalers. But beyond, talk a little bit about kind of how AI factories, you know, that's a term that gets used a lot.
How do you see these kind of emerging and being built in the future? Sure. How does Marvell see that?
Yeah, so, so first of all, um, you know, the first waves of build out in AI infrastructure really were with the big hyperscalers, the ones that already had huge data center footprints and were able to very quickly mobilize and build out AI infrastructure within their footprints and of course, secure and, and build out new data centers and new infrastructure. And that was, you know, starts with the top four us, but also around the world. Um, going forward though, we're seeing, you know, call 'em a emerging hyperscalers, it's like who do we call a hyperscaler in 2028?
I actually think there's gonna be new names on that, on that list. Because you see all these new kinds of companies that either, either the model owners and builders, the application owners and builders, um, and then the rise of sovereign ai, you're starting to see just an explosion in all of these new areas as well. And, and ultimately they're all looking for this AI infrastructure.
And you, you know, you mentioned sort of the XPU side of things. You know, at Marvell we have kinda, I'll just call it two halves of the AI business. There's the interconnect, no matter whether you have a GPU or an XPU, any of those things, even CPUs, they all need to be connected with really high speed.
This business has grown so fast over the last several years 'cause it's attached to every single one of 'em. Every system that's being built and delivered by every data center operator in every AI space in the world is using Marvell interconnect technology, the high speed DSPs. And so the, the, the way that that has grown has been truly remarkable.
While at the same time we've built out this custom business that, that you talked about where we're seeing an explosion of a desire to build their own AI infrastructure optimized for their own sets of applications. So if you think about what I just mentioned, the hyperscalers are do for doing what they're trying to do and build out their application and workloads. And when part of this space with cloud, the model owners can build optimized infrastructure for their application, the application owners are building out, um, AI infrastructure optimized for their applications.
And so that's actually the custom opportunity continues to get bigger every time we look at it. And in fact, in 2021, we sat in this room and I announced, we announced Matt, our CEO announced that Marvell was entering into what we call the cloud optimized silicon business or the custom silicon business. Most people looked at us like, why would they build custom silicon?
Well, nobody's asking that question anymore. Everybody's building custom silicon and, and it's, and it goes beyond just the XPU. Yeah.
And, and, and that's a good leading question. And, and by the way, you were early, you were right. You know, gotta give you credit where credit's due.
Um, and I don't think everyone saw it right away. Right. But I do think when you kind of look at how this is emerging, right?
There's kind of these two schools, there's kind of, you know, the merchant silicon school. But if you look at, and by the way, the way you talked about hyperscalers, I think that is really interesting, and I'm glad you brought sovereign into this because I even think of things like service providers becoming hyperscalers, right? If I look at how in different regions are you gonna address sovereign cloud in Portugal, it's probably gonna be some partnership with a cloud and a, and a and a telco company and trying to, you know, that's got that regional expertise so much going on Chris.
But the platform isn't just execute, it's not just compute. Right? What are the, kind of, talk a little bit about what the platforms sure look like beyond just the, you know, fighting for those, you know, those custom AI chips.
Sure. So if you think about the space, um, one X-P-U-G-P-U doesn't is not good enough for anything. You can't build the application to fit into one XPU or GPU.
So you have to string together thousands, tens of thousands of them. Um, and so that means you fundamentally have a connectivity problem. How do you actually build these at data center scale?
And so ultimately what that really means is there's a platform around them. You know, if you, if you start with the basics of an XPU, the best thing you can do is pack as many transistors as you possibly can into one radical sized dye, not enough. So then you go with advanced packaging and Marvel's made numerous announcements on this subject over the past few months.
And you package multiple of these dye together with high bandwidth memory into a single package. Then you wanna put as many of those on a board as you can put as many of those in a rack as you can, put as many racks in a data center as you can and connect all of them with as much bandwidth and connectivity as you can to really build out a logical XPU, if you will, out of multiple, um, smaller components. And so ultimately the way that that is done tends to be tied very closely to the architecture.
So if you built a custom XPU, you probably have a custom platform. Uh, you're not just using a standard off the shelf platform. Now that is a change, you know, when if you fir at the very, when this first started, you probably did just put it into a standard like X 86 infrastructure with a top of rack switch that was running ethernet and all of these other pieces, but that, that infrastructure moves at a much slower pace.
Um, and so what you're seeing now is an investment in building new types of custom scale up fabrics and, and the rest of the platform going custom to be able to, to really get as much of, uh, this compute power available as possible, optimized and designed for your application. So it's, it's interesting though because as you know, we, we pin it at something like 10% right now, XPU versus kind of the, the big GPU spend. But it is converging, it's, it's closing in because the, the volume buying, the diversification.
But when you talk about, you know, the overall platforms, one of the big rate limiters, Chris, is going to be the network. So you're very focused on interconnect as well, right? Um, AI doesn't function all that well if you can't move the data quick enough.
So you hear a lot about scale up, you hear a lot about scale out, right? Um, Marvella has a pretty significant role to play there as well. I mean, how fast are you seeing?
Are you seeing the, the industry keep up from this space of connecting everything as we are spending time talking about doubling and tripling, you know, an exponential growth of compute power On every one of these vectors? I continue to be amazed, you know, if, if, if you start in package packaging today is achieved things that nobody's ever thought of before, um, and ultimately being able to package the number of dye and the size of these chip pack, it's hard to call 'em chips. These things are like, you know, six inches by six inches.
These are huge packages. And so that's one technology vector. The next TE technology vector is of course, how do you actually connect them together with the high speed copper interconnect?
And there's tons of innovation there. Eventually you're gonna run outta space there and it's gonna need to go optical. So we've made announcements around our, our, our co packaged optic solutions to be able to build a ending to any XPU fabric, all optically connected straight into the package.
That's a new innovation that's coming as well. And of course, once you build out that rack and you have the rack scale platform, now you need to be able to go across the data center and build as many as you can there. And Marvell demonstrated the world's first 4 48 gig, PAM four, um, optical connectivity at OFCA couple of months ago, um, a few years ago, there was debate in the industry whether you could ever do 4 48.
You know, in the technology industry, we sometimes think we will never be able to go beyond this. There's some barrier coming. And I'm always amazed at the ingenuity of engineers to, to break through that barrier.
And another one is the reach of PAM four, you know, these data centers are now getting so big that, that it's starting to hit the reach the end of that. And so the between data center, the ZR space for data center interconnect is too high a power. The PAM is too short a distance.
So Marvell announced the first coherent light solution that actually takes and combines parts of both technology that allows you to connect huge campus-wide data centers. So if you look at every one of these vectors, the race is on, the engineers are innovating, and the technology's moving at a pace, uh, unlike anything we've ever seen. And it feels in, in some way, at least as I observe, is that Marvel's innovating in many, many vectors, but there's so much concentration right now on one.
And so I think it's kind of important, you know, for everyone out there to understand that you know, what you're doing in terms of connecting in the rack, connecting between the racks, connecting between the physical buildings, and then of course sites that are far apart. There's a lot of technology in there and there's a lot of tam, right? There's a lot of tam that's accessible to you.
One other thing that, you know, I think is super important, 'cause I say kind of what are the rate limiters? It's, it's the compute, it's the network, and it's the power. Um, you know, coppers, uh, has its place, but you know, over, over distances and stuff, it becomes very power inefficient.
Um, and by the way, GPUs can be very power inefficient. Um, you know, for certain use cases they can be great. Uh, we're seeing exponential scales in some way, but there is also a reason that many companies wanna design their own, right?
They have a very specific workload in mind, or se several workloads. They can build their own software, they can do these things. How is Marvell sort of thinking about addressing that?
Because that seems like one of the biggest opportunities That's right. Sort of addressing the, the power problem. And, you know, while China might be happy to build coal fire plants to a week or whatever they're building in the us, you know, we're trying to build nuclear, but you're, I mean, that's like a decade out, Chris.
Yeah. It's not gonna happen that quickly. Yeah.
Ultimately, I mean, that, that, that's what we wake up and think about every single day. You know, when you, when you're building silicon, you tend to think about power performance in area. An area is cost.
So it's like how much is it gonna cost? What's the performance of it and how much power? And to the point you made earlier in terms of capital allocation cost is almost not the discussion anymore.
It's how much performance at what power is really the, all of the discussion that you can, you can have right now. And ultimately, everything we're doing is focused on that. I mean, you mentioned custom earlier, that's exactly why custom, I mean, why, by the way, why are we doing AI work on GPUs instead of CPUs in the first place?
Because they're more specialized to do this type of work. So if you can make a more specialized XPU or AI processor for a more specialized workload, it's gonna be more power efficient, right? And same thing if you can, if you, if you're addressing any possible application, you're gonna build one type of a platform that sort of can deal with anything.
But if you're saying, no, I really, I'm gonna focus on this model or this application, you can build not only an optimized XPU, but an optimized platform that connects those together and optimizes the connections, connections between X Ps and the connections to memory and the ratios of all of those for the way your day, your model is split and spread logically across that logical XPU. And so all of that has power and space in mind. I mean, cost is obviously an important one, but even more important is, hey, I, this is the space and power envelope that I have, what's the most optimal way to deploy infrastructure to attack my problem?
Yeah, I, I agree with you. I I actually think there is a, at least at this point, you know, if the bubble bearers, I like to call them, have anything to actually have a bubble about, it's that we have to turn all this infrastructure investment into consumption, right? And, and, and we're seeing it.
But you know, these agentic workflows where you have trillions of concurrent, right? 24 by seven agents, um, you know, and, and we are by the way, also seeing a pivot that I think is very favorable to you, which is inference, surpassing training. Right?
Now, you guys can build a custom chip for training, you can build a custom trip for trip chip for inference, but the volume and inference is where money is made, right? Training is where you, it was basically the r and d of this industry that basically scaled the models, prepared the data, all the stuff that had to be done. So how does this work going forward?
Yeah. You know, you mentioned the, you mentioned the tipping point and money to be made, turn all this infrastructure investment into, into dollars. And I, I find it interesting, you know, I started my career in mobile, right?
Where the world had two G cellular networks and was just auctioning 3G spectrum, and everybody was thinking about it going with wireless. And, and ultimately there was, you know, billions and billions of dollars being built in sort of telecommunications network and cellular communications on top of the telecommunications networks, um, around the world. And that question was asked constantly, is anybody gonna ever use 3G, 4G, 5G to do anything?
And nobody could even imagine Back then we weren't even doing SMS text messages and, and, and there was a lot of questioning, does this make any sense? The reality is it took more than a decade of just pouring money into the infrastructure build out before all the blossoms bloomed, right? Before you actually had this massive mobile economy.
It is the economy now, right? It's built on this, on this giant infrastructure that's been built. And back then nobody even knew we were gonna have, uh, you know, iPhone and Android.
Nobody knew we were gonna have the app store. Nobody knew we were gonna build, you know, all of these apps in the app store that are making billions of dollars, Certainly didn't know about chat GBT, They didn't know all the stuff that was gonna become on the back of it. And I feel like the way we're with AI is in similar, we're pouring billions into the infrastructure to develop the platform, which will eventually lead to this massive economic explosion.
But these things usually are decades. We're only like two years into this thing, Hey, I think that we don't, what, what are they gonna be? The app stores and the Androids and the ioss and all of the other parts of the platform that's gonna lead to all this economic, uh, value for the world.
We don't even know it all yet, but it's definitely happening. Yeah, There's a lot of questions. And, and to be very clear, I'm not one of the, the, the bubble bear guys, I just meant that overall that's been probably one of the questions of how fast we're building infrastructure versus how quickly it's being consumed.
And to your point, the fact that we actually have this many use cases, you know, you got CEOs of, uh, you got the Elon Musk and Sam Altman saying, my GPUs are melting. Like literally they have a use case that's consuming so much compute right now that they cannot get enough access. So we actually have some of these use cases, it's in the wild right now, well ahead of the era where, you know, Steve Ballmer when he said nobody's gonna tie it from a touchscreen, you know, there's some, been some fascinat by the way, really smart people that made some fascinatingly of course, wrong predictions in the past.
I think we're gonna get there. I think these are really exciting times. Chris, before I let you go, what is your sort of vision, you know, you kind of started alluding to it, but how, how fast does this accelerate and how big do you see this custom opportunity?
Um, so what we believe is, is that, I mean, first of all, take your numbers of how big you think the accelerated infrastructure market is gonna be and how big the accelerated, um, infrastructure, um, Tam will be over the next, you know, three, four years even, right? The compute side alone should be close to $400 billion, and we're in the sort of three to $400 billion by 2028. And what we've said is, is that we think a quarter of the market, you mentioned 10% now, um, we think it'll become a quarter of the market, whether that's in 20 28, 7, 8 or nine.
But we're, we're, we believe that it's, it's on track. We said that a year ago. We said that again today.
We think that that is around a billion to, to go custom and ultimately exactly, ultimately somewhere in that sort of 80 to a hundred billion dollars worth of custom, um, opportunity. Yeah, That's a, it's a big number. It's a big opportunity.
And like I said, I think one of the biggest things right now is we've kind of built this world where people kind of limit their purview. Everyone's obsessed with the compute, but this stuff does not work if you don't get the thermals right, you don't get the connectivity right? You don't get the, of course compute, right?
You gotta have the data layer. Correct. Right.
Then of course, we've gotta have the, the, the applications and the use cases. It's the whole platform and the infrastructure is actually in some ways almost more important, really. And, and it's, and it's, and, and we're seeing that in terms of our design wind.
We can't do any of it without, without this base layer that you are helping to build. And so really appreciate that. And of course, the era of the humanoids and the fully autonomous vehicles, and we'll each have our own agent, and then you and I can, uh, we can play golf golfer going on a finally take a vacation.
So Chris, thanks so much for joining me here at the six five Summits. Great having you. Great, uh, each year talking about what's going on.
It's moving very quickly. Yeah, thanks for having me, Dan. Always a great conversation And thank you everybody for being part of this six five Summit 2025.
We are AI Unleash the spotlight session with Chris Koopman's, COO of Marvell in the semiconductor track. com/summit to get all the sessions, more insights coming after this. Hi everyone, and welcome to the six five Summit AI Unleashed.
I'm Will Townsend. I lead the networking and security practices for more insights and strategy. And joining me today is she Wong, uh, senior vice president and general manager of the connectivity business unit at Marvell.
And we're gonna discuss the intelligent edge in this special spotlight on the six five Summit Summit. She, it's a pleasure to talk to you today. Thank you.
Well, she, the theme of, uh, our topic today is AI in the million XPU era. Let's talk about that a little bit and how important networking is to support modern AI As we speak. The operator are already deploying deploy AI networks with hundred thousand of a GP altogether.
And then to support that number of GPUs you need a fast, low latency and a big network. And morale is a part of the ecosystem partners to support that enablement and the operator are moving even faster to 1 million XP altogether. There are a lot of challenges and opportunities for everyone in this industry, and we're continue to bring innovations such as low latency networks, higher optics, and also light technology to enable multi-site, high large scale networks.
And we're very proud to work with all the ecosystem partner to make that a reality. And you can see that in the past we have announced, uh, several new, uh, product, but there are more technology that in the kitchen that we're cooking. You know, I'm wondering, you know, there's a lot of debate around this, but has AI accelerated the adoption of connectivity or has it just simply changed where it gets used?
Well, definitely AI has been a huge driver for connectivity. The global market for optical interconnect has doubled since 2020 to nearly 20 billion, and it's expected to double again by 2030. Because of the increasing bandwidth and the growing size and the number of clusters.
Hyperscalers are deploying more and faster. The industry KR is around 18%. AI also jumpstarted the transition to higher bandwidth optics, traditional compute servers IO bandwidth behind the network IO bandwidth one generation.
However, when you move to ai, the AI server bandwidth leap forward by one generation. So this transition triggered much higher demand for higher bandwidth connectivity. Since AI is also based on parallel computing, the physical dimension of each node also increases that increase you requires longer distance interconnect.
So, which is the advantage of using optical transceivers or active electrical cables. The vast majority of connections three meters or longer are supported by this technology. This next generation AI will be particularly interesting because we're talking about clusters with to one X.
So how do you make a fabric with and low latencies while simultaneously improving costs and efficiency? This is where new innovation is needed. On the connectivity side, you can see innovations happening across the board at the border level.
New generations of service IO are being deployed and developed at a faster cadence, at a cluster level, optimize electrical and optical solution for each different application. Scenarios are becoming available across locations. We are delivering coherent transmission technology, which was reserved for long haul telecom, but now you're being used into their center of campuses.
So all this innovation and changes has become an enabler for next generation ai. This is not about who has the best accelerator, but who also has the best connectivity solutions. I couldn't agree more.
She, um, connectivity is the bedrock to move data around these, uh, these AI models, whether they're large language hosted in the cloud or as, uh, AI moves to network edges requires the efficient transfer of data. And so that presents a lot of challenges. So I'm wondering from your perspective, what do you see as some of the biggest challenges, uh, with respect to, uh, network and, and, and just, you know, supporting those AI workloads at scale?
Oh, indeed. I think first is we will need more GPUs that work together and we'll need a bigger fabric to connect them. A cluster with hundred thousand might need 500,000 interconnect along with thousands of servers and switches.
A million could need 10 million interconnect, but collectively, several kilometers power could approach a gigawatt. So this transition to higher bandwidth also, uh, accelerate instead of two times bandwidth every three years, we're doubling every two years. 200 gig interconnect are being deployed with 400 gig on the horizon.
So if you look at a system that enables ai, there are two separate and connected network scale up that enhances the capacity of a single server or system by combining all the resources together, scale out, bring this servers to the network in scale up, the overriding concern will be latency followed by power scale up is also a new market for connectivity. We expect lots of innovation happening here in the next few years, such as ultra low latency networks, co packaged optics, and the photonics iOS in scale out. The big issue is scalability.
There we see potential innovations such as light 400 gig optics, and we will need to support a new mod schemes to support all these use cases. No, those are, those are fascinating insights and, and from my perspective, there's another dimension to scalability and it comes with the dramatic increase in the pace of data center buildout. So there are commitments around the world just recently in the kingdom around the investment and AI infrastructure to create new use cases, drive new monetization opportunities.
I'm wondering from your perspective, what's the industry doing to sort of ease the potential supply chain in management concerns that comes with this hyper growth? Well, this is very interesting issue. I mean, usually it doesn't get a lot of tensions, uh, than the power consumptions, right?
And then the economics, but is just as important. Um, I think the short answer is the ecosystem, right? The number and the size of AI cluster have grown rapidly in part because of the ecosystem, the need, a flexible and interchangeable solution that scale to support their need.
And then if you think about it, the combination of a continual innovation of CMOs and technology pushes lower per gig at each generation. And then we are moving from five nan to three technology that the power cost efficiency, a stable and a mature plugable ecosystem provides flexibility and the scalability both on the operational side and also the commercial side. So in our mind, this vast, uh, network of ecosystem partners that support plugable, uh, ecosystem is the go-to solution for large scale network and for them to continue to scale.
Yeah, and certainly Marvell is participating in many of these areas, and as we close our discussion, she, I'd like to talk a little bit about, um, optics for inside the server, inside the chip. You touched on co packaged optics, you know, people have been talking about this for decades, but it's still not quite here yet. So will AI accelerate that whole notion?
And how will it manifest itself, do you think over time? Well, this is a really good question as well, right? So I think things are happening, um, but over time, um, currently the whole system design is focused on this aggregation, memory processors and networking.
There are all position in separate domains that are connected together, but there's a strong push that allow this separation to, uh, have, uh, enable faster transitions and then time to market for new technology. We're expecting seeing a convergence of the interconnect technology to the endpoint that can facilitate that. So those technology include, as you said, advanced packaging.
It all comes down to the implementation of the underlying technology and where you pull them together. This consideration must be done at the overall system level, including thermal power, cost come to market, and ease of operation. The semiconductor industry, like where we are in, has always been enabling higher level of integration at the right TCO intersection point.
So this time for, uh, updates going inside the server won't be any different. That is our will. Yeah, and I, you know, you touched on power.
That's one of the biggest concerns that that enterprises are facing right now. Just the immense power that it takes to, um, support these, these modern AI workloads. And Marvell is doing a lot of work in that regard, providing higher degrees of performance, while also bringing that power consumption down to make AI infrastructure more sustainable.
But, um, with that, she, I just want to thank our audience for joining this Intelligent Edge spotlight at the six five Summit. com slash summit. More insights are coming up next Stargate DC one, healthcare security AWS AI agents Intel's Linux.
Future is unclear. MS eeu deals seems to be unpopular. There's an ultra tomahawk out there, and we're gonna share a little too much about SharePoint in this episode of the Tech Field Day rundown.
Hello everyone. Welcome to the Tech Field Day rundown for July 23rd, 2025. It's hot out there.
It's summertime. Well, at least it is north of the equator, and that means you probably want some ice cream, perhaps a, a nice, uh, fudge sickle or perhaps a nutty buddy. I don't care.
Pick one or the other. Pick 'em both because it's National Ice Cream Day. And, uh, maybe you should get some for your parents too, because it's National Parents' Day, but I don't know that there's a national parents' buy your parents' ice Cream Day.
That's tomorrow. Maybe. Uh, what isn't tomorrow is the rundown because that's today and we are enjoying all of the great things that come along with doing the news on the rundown.
And joining me, of course, is my wonderful wintertime co-host Mr. Alistair Cook. Al, how's it going?
Well, it is a beautiful morning here in Ong in New Zealand, and it is a scorching 40 degrees. Unfortunately, it's 40 degrees in freedom units, not in science units. Uh, and that means that it's not scorching at all.
That makes it a good day to have ice cream because it won't melt all over your hand before you get to eat it. Yeah, well, I gotta give it to the people out there. In fact, I could give them a hand, not a melty ice cream hand for all of this news that we have to cover because we're gonna hit all the fun stuff, AI security vulnerabilities, AI security vulnerabilities, and, uh, and more.
So I hope that you're ready to tune in. Uh, we're actually gonna start off with, uh, one of my favorite projects named after a Richard Dean Anderson Showtime TV show. Uh, that's of course Stargate, the big Oracle and open AI SoftBank project.
Uh, they're touting a huge expansion of that project. They're gonna be adding four and a half gigawatts of data center capacity in the us Yeah, that's right. We did measure the data center capacity in the thing that makes the back to future DeLorean run.
Uh, there are some big promises though, but you may recall that we've been talking about Stargate for a while. 'cause well, this project's having a little trouble getting off the ground, uh, a little trouble dialing out, as it were. A recent report says that plans are already starting to be scaled back and the companies are now just hoping to have one small-ish alpha site data center open by the end of the year.
And this, they claim that this is going to create thousands of jobs. But, uh, I'd be honest with you if I didn't say that, this project feels a little bit more height than real progress right now, Al, do you think that we're ever going to have a complete dialing solution? You know, I think, uh, we should plan for that.
Uh, but what I think is, is really telling him this is, uh, this was announced in in January and it was announced with, uh, your US president and Sam Aman standing up together and saying how wonderful this was going to be, along with, of course, um, that Larry Ellison and, uh, the CEO of SoftBank. And I'm always a little cynical when a project is huge and announced in a very political way, um, makes me feel like there might be quite a gap between that and the final reality. Now, the long-term plan still spend ridiculously large amounts of money to build massive data centers for OpenAI to consume all of the GPUs and all of the power forever reality of delivery.
Well, you've gotta get something running. You've gotta get some tin in the ground, uh, some concrete in the ground, I guess, and turn on top of it. And, uh, you really need to be able to say you've delivered something, kind of takes a long time to build a four and a half gigawatts worth of capacity, and it's gonna be built across multiple locations, and that $500 billion being spent was around the world, not just in the us.
Uh, so yeah, it's, it's interesting to see that they're still talking up what they're gonna build rather than telling us what they have built in that, what is it now? Seven, six months, uh, six months and, uh, and, uh, two days, uh, since the announcement of this deal. Yeah, it's not surprising that it's taking a while to build out.
Um, we do also see other studies around suggesting that there is no way there will be enough GPUs for all of the data centers that have been announced that the actual production of the GPUs and, and the other computer hardware that's supposed to go in these data centers over the next few years, uh, there's just is no way it'll be produced. And that's an interesting piece of study that sits alongside this, right? We announce huge things are going to happen and then we don't do huge things.
Yeah. If you've followed how things work with political announcements and political alignment for large high tech organizations, you're not terribly surprised about this. You may be surprised by a new report from the fortified health security, um, and it outlining some topped cybersecurity problems in healthcare.
Actually, come to think of it, I'm not surprised to find that there is poor risk planning, weak supply chains, outdated systems, missing inventory records, and a lack of training in health. Um, these issues are connected to and have been, uh, have been exposed in major breaches like the 2024 change healthcare attack. Despite the risks, the report shows that some progress has been made in fixing old systems.
I wonder how much, uh, planning for incidents and improving leadership and identity security. The findings are based on data from 2023 to mid 2025 across various North American healthcare organizations. So supposedly the finest healthcare organizations in the world, in your US system.
And, uh, yeah, this seems like there might be a lot of old archaic systems still in play in healthcare in the us Thomas is that, um, looking after your health Well, right now? Yeah, for the time being, I guess, uh, you are right. We, we do have the best healthcare system that money can buy that then immediately takes all of the profits and plows them back into shareholder equity, which will turn out to be one of the three great lies of the modern industrial evolution area.
Um, but let me tell you why. One of these things is the hospital's fault, and one of them isn't, obviously the hospital's fault is that they're not grading their systems because why would you spend money on it when you could give it to people who really don't need it? Um, that's one of the problems of operating a for-profit enterprise like healthcare.
I mean, I, I don't want to cast aspersions, but why is that? Every, most every other country in the world operates healthcare like a, uh, like a, a, a, a basic human right and not a business, uh, that, that's a discussion for a different podcast. Uh, but the, the fact is, is that most hospitals are running on older equipment, at least from an IT perspective.
When we need a new MRI machine, we'll we'll order one of those because we can charge for that. But the wireless network and the the cabling plant and the firewalls, we can't charge the the customers for that. And so those get best effort.
The other thing that I think has kind of been a maybe not a, an explicit thing as a flight is this idea that we don't attack hospitals, right? Think of the Geneva conventions. We don't shoot churches, we don't shoot hospitals.
Uh, we don't bomb red cross trucks. So I think that what happened was is that hospitals just kind of assumed that people were gonna stay from out of there and not hack them and try to steal patient records and, and cause other outage problems. Surprise hackers don't care about your Geneva conventions.
And so hospitals are very tempting targets because they're very large enterprises, very short stabs in very old, outdated equipment. They are very tempting targets. And once you get in there, you can cause a lot of havoc.
And better yet, you know, all those profits that they have that they're trying to give away to the shareholders, that means that you might be able to lock up some systems and encrypt some data and get the regulators on your butt if you don't pay us to unlock all of it. That's right. Hospitals do have a tendency to pay ransoms and other kinds of extortion fees.
So here's a thought for all of you hospital IT administrators out there. It might be time to invest some of those profits in keeping yourselves out of the news and out of reports like this. I mean, we're not gonna get universal healthcare in this country overnight, but maybe we could keep people from dying because folks don't know how it works.
May have noticed last week that Amazon Web Services had their big New York summit, and during that summit, they announced some new tools to make it easier for companies to build and run AI agents. The main launch, which was called Amazon Bedrock Agent Core, which is also my favorite gospel band of all time, helps developers get AI agents into production a little bit faster. AWS is expanding its marketplace to offer ready to use AI tools from partners like Salesforce in Deloitte to ready support for AI with better data.
They have improved Amazon S3 storage and introduced the SageMaker catalog to help organize and find data a little bit more easily. Another tool is called kiro, and it lets developers use natural language to create and manage AI projects. Almost like it's a vibe overall.
AWS is making it simpler for businesses to adopt and scale AI across their operations. My question for you, Al, is that a good thing? Yes and no.
And maybe, and it depends. I think that's the answer to all of the questions we ask ourselves at the moment. Uh, it is nice to see AWS taking some of the heavy lifting away from the job of building AI solutions.
So seeing more packaged capabilities to, to assemble together an AI solution is good. Um, making it easier for developers to add AI to their applications when we start recognizing that AI is not the thing, it's the thing that makes the thing better. Thanks Bob.
Element, Google, um, that AI is a feature of a product, or it's a, it's a, a tool that you, you use as a capability in your thing. It's, it's not by itself valuable as a thing. And so making it easier to integrate AI into your existing applications, making it easier to get AI into your interactions with your customers or with your internal uh, staff, anything that that helps us make that easier has gotta be good, particularly if it helps us make it easier in a way that's cost effective in the long term.
That last bit might be a little interesting. Uh, one of the changes in here is, um, taking the Amazon S3 service, that place where people dump all of their big data that they dunno what to do with, uh, and en enhancing more, more capabilities around both metadata and also vectors. Vectors are a really important part for what's called retrieval, augmented generational rag.
It's the, the way that we will be taking business data and adding it to our generative AI applications. And so these are very important capabilities that are gonna be very useful for people who are really committed to using AWS to, to hold everything, make it easier for them to build applications. Um, I remain a little cynical around AI tools being used to build AI tools, just Kira.
Uh, but we'll see. We'll see how that plays out. I've been wrong in the past when I've been cynical about products and thought that, that they would never, uh, work very well.
So let's hope this one does, does work very well. From what I can tell. Kira has definitely gotten some attention and people have been playing around with Kira a lot.
Uh, but getting towards large scale pipelined ai, lots of agent ai, this is where, rather than the AI reporting to a human and actually completes some task itself, uh, this is definitely a place where we're seeing a lot of development. And that's one of the things that's in the, um, Google's Vertex AI builder, uh, AI agent builder in particular. Um, there's a, a whole collection of tools that AWS is hoping will bring them forward on that.
Uh, all of the big cloud providers are, are looking to make it easier to build your AI applications. And AWS definitely wants to be on that. Intel, on the other hand, has ended the clear Linux OS project after 10 years.
This is a Linux operating system that was built to be very lean and very high performance, specifically and exclusively on Intel hardware. Uh, it's no longer getting updates and patches and, uh, users have been advised to switch to another Linux distribution because, well, there's gonna be no updates and patches, um, no official reason for the removal of this Linux distribution. But you've gotta think that it's to do with the refocusing within Intel that they're cutting off a thing that has relatively low usage and pretty high maintenance cost.
Um, Intel says it will support Linux still, but by providing hardware optimizations for other Linux distributions, Tom, is a clear Linux an important part of your estate or your, uh, deployed environments anyway? No, and I don't think it was a very important part of anybody else's either. And I think that's the reason why Intel has decided to cut it loose, is because it does take resources to maintain things like a Linux distribution.
And when you are optimizing your Linux distribution to run on a platform, you have to make sure that it runs better than anybody else's. You have to take every trick that you can. I mean, who among us hasn't tried to emerge into distribution onto a specific architecture?
I can't even finish that sentence without laughing, because it's been a while since anybody's done that. Intel wanted you to run clear Linux on their platforms because it gave them an advantage because that Linux was faster, however much faster that was. Well, guess what?
Now they don't have a whole lot of platforms left for you to run Linux on. A lot of the things that they're focusing on don't run an operating system natively. And so they're just kind of saying, well, why don't we just slipstream our features into other more popular distributions and then we can gain that advantage across all of our, uh, locations.
'cause I promise you, unless they included like a download code in the box of the server that you bought, or the knuck that you bought, nobody was gonna go out and search for Best Linux OS for, for, uh, Intel. They were just gonna go download whatever they're used to running, whether it's two or Slack wear or whatever. And the fact that they don't even have the knuck anymore, or any of their servers or really anything that's customer facing should tell you.
I mean, the only reason that people would've wanted to use Clear Linux is if it gave them a definite advantage on that Intel GPU. Oh man, I almost got through that sentence without laughing. Uh, that's the problem is that this entire thing has become less about the OS running on the actual server and more about how you can interface with GPUs.
And Intel's not in a position to do that right now. A MD doesn't care. Nvidia doesn't care.
They're just letting you run whatever you want. So in a way, clear Linux will live because if the repos are out there, somebody will grab them and and do something with them. But I don't think it's gonna live the way that you think it will.
The, the product will live on in other Linux distributions because they'll become a little bit more optimized for certain intel architectures. But at the end of the day, the people who are responsible for maintaining it will be sacked eventually, or just reassigned somewhere and doing something boring like, I don't know, working on a car or something. Microsoft has reached a deal with C-I-S-P-E.
I'm sure there's a way to pronounce that, but it's very European because that's a group of European cloud providers. The deal, of course, is how they're going to change their software in the way that it's licensed in Europe. The agreement offers local hosting pay as you go pricing and fewer data sharing requirements.
Well, the goal of this is to help EU vendors compete with Microsoft's own cloud services. Weird. C-I-S-P-E calls it a big step forward for digital privacy and fairness, which sounds like a very EU thing to say, but those nasty critics say that it gives Microsoft a little bit too much control.
It doesn't actually fix the deeper competition issues, and it shuts out the other big global players. You know, the names Amazon and Google. Uh, some believe that it's a tactic to really try to avoid tougher regulations, but also keep a little bit of that market power, which quite honestly sounds totally on brand for a giant cloud company trying to play in Europe.
Al do you think Microsoft is just paying lip service or do you think this is part of a nefarious plot? Oh, I'm a fan of nefarious plots. At least they make interesting stories and, uh, stories.
I know I'm, I'm not too much of a conspiracy theorist, but I do think that big organizations are gonna do what's best for the big organization and, uh, Microsoft with Azure is, its Crown Jewels is gonna be no different from any other big organization. What's happened here is that the, uh, C-I-S-P-E, yeah, I dunno how to pronounce that either. Uh, have this group of, um, providers in in Europe have done a deal with Microsoft where they get better licensing for Microsoft products than other cloud providers who are potentially not in Europe.
Uh, I think this is good in terms of providing more options for Europe based customers to maintain data sovereignty. And that's, that's really one of the central elements in here is that a lot of customers in Europe would like to use Microsoft Cloud, but want guarantees that, for example, their German company's data will always remain on German soil and won't end up maybe in Polish data center or some other location that is not German soil currently. Um, so it's interesting that this has all happened in Europe, a place with a lot of regulation and market intervention through regulation also with a lot of data sovereignty.
This really to me, does come back to that data sovereignty thing around Europe. Uh, but there are a huge number of other cloud providers, both large and small, who would like to have a more friendly licensing model with Microsoft software. So I think this is getting ahead of some kind of, um, regulation and a precedent being set by that regulation that might come back and bite them around the world, uh, as maybe regulators start saying, well, Microsoft's misusing its position of dominance, uh, again and, uh, is using its licensing to be anti-competitive.
So yeah, I, I think we'll see continued little deals being done to avoid a big precedent, uh, because those deals can always be wound back later on if it suits Microsoft better that way. Like any large organization, their objective is to maximize shareholder value and they don't do that by minimizing cost to customers, at least not directly. Broadcom has launched the Tomahawk ultra powerful ethernet chips, uh, switch chip built to support large AI and high performance compute HPC systems.
It connects up to 256 processes, four times more than NVIDIA's competing product, uh, and uses open ethernet standards instead of proprietary infinity band technology. Uh, the Ultra offers very fast data speeds, uh, low delays, advanced features that supports scale up and scale out computing, making it easier and cheaper to build and manage AI networks. Chips made using TMCs five nanometer processor and is already shipping to customers.
So we should be seeing this shipping in some switches soon, Tom, we absolutely should. And if you haven't figured it out yet, the reason why this is not just a plain old tomahawk is because of ultra, the Ultra was not just a random superlative that they picked out of the dictionary. This is in fact running ultra ethernet.
You know, that industry thing that they got together with companies like Cisco and a MD to do basically is like, oh, Nvidia, you wanna create a custom proprietary protocol for doing AI ethernet stuff. 0 standard recently, uh, a few months ago, which basically means that's about enough time for a company like Broadcom to come out with something that utilizes that spec. And of course they're gonna pick Tomahawk because Tomahawk is their, their switching line.
And so I think this is a valuable lesson because we've seen Nvidia making moves in other places. Nvidia has opened up their architecture. No, no, no, no.
Hold on. Before you leave that comment talking about Nvidia and open source and all that other stuff, I wasn't talking about that. I was talking about the fact that Nvidia is allowing other companies to design and sell Spectrum X platforms.
You know, it would be like if Cisco wrote an RFC for E-I-G-R-P. They did. The idea here is that Nvidia wants more of the companies that are leading and networking to sell their Spectrum X technology.
Because once the companies that are buying Nvidia technology start using Spectrum X in the network, they're kind of locked in. You know that thing we hate vendor lock in? Well, in this case, Broadcom is hoping that people are gonna start deploying ultra ethernet.
And the idea is, is that they're selling this on a trusted platform. Tomahawk, they're selling it as well. It's a tomahawk, but it does more.
So if you're already looking to refresh to build out a new AI pod or something like that, why don't you give us a shot? We'll probably send some people out there to make sure that it works. Everything will be copacetic.
And as soon as you know that it works the way you want it to, we'll continue to improve it as new specs come out for ultra ethernet and then you won't have to use Spectrum X. Right? That is the ultimate goal here, is that they really want people to leverage their technology.
And look, I get it. There's, this is the same thing that I've had to deal with in my life in the Cisco world. There's Cisco and then there's what everybody else got together to make the standard so that it's the opposite of Cisco only this time it's companies like Broadcom and Cisco getting together to make a standard that's the opposite of Nvidia, which is one a way that you know that you are the biggest player in the market.
But two, it is probably the only way that people are gonna be able to come together to create this standard. Because if Broadcom and Cisco had been competing with each other to create a standard for an open ethernet fabric that would allow it to compete with InfiniBand, we would've never gotten to this point. The fact that Nvidia kind of won that battle tells me that they all know where the issues are.
And so that's kind of where we are. And, and Bravo to Broadcom for getting it out the door. Uh, granted, they kind of knew what it was gonna look like, so, you know, it's like when those draft, uh, wifi specification routers come out and it's like, well, we were involved in writing the draft, so we were pretty sure that this was gonna be final, so we were able to get one out the door before anybody else.
That's the kind of thing that you want from someone who's a market leader in switching technology. Well, it's time for us to take a little bit of a closer look. And we, um, saw that hackers have used a Sirius and previously unknown flaw in Microsoft's SharePoint server software to launch a major global cyber attack.
The attackers hit US government agencies, universities, energy companies, and more, uh, but only affect onsite servers, not the cloud service that Microsoft would rather you use. Uh, stolen data and encryption keys could let hackers keep access to systems even after they're patched to mitigate the original vulnerability. And Microsoft has released a fixed for some versions, but many servers are still at risk.
Authorities in the US Canada, and Australia are investigating with over 50 organizations confirmed already affected so far. Tom, have you been able to find out the attacker's identity or their goals for this attack? Uh, well, I, I can tell you what their goals are to steal as much stuff as it's not bolted down and get out the door before anybody catches us.
That's, that's every thieves idea, right? And SharePoint's pretty juicy 'cause it's a document repository so we can get in there and get all the stuff, uh, as to the identity of the, uh, the people, no, but I can wager a guess according to some articles that I read, the traffic seems to be sourced from China. Go figure.
Chinese hacking groups are exploiting vulnerabilities to steal American data news at 11 and 12 and possibly at two if we can get into SharePoint and write up the scripts. So this is basically what happened is Microsoft discovered a vulnerability and they announced it on Saturday. You knew it was bad if they announced it on Saturday, but they were already two weeks behind the curve because they were starting to see intrusions on the 7th of July.
So they've had a two week lead time to get this patch put together. And you are absolutely right. They only patch the latest versions of SharePoint back to you, I think 2019.
So if you're still running SharePoint 2016, why upgrade, please, uh, call Microsoft. I bet you they'll cut you a deal. Um, although it's funny because Microsoft has been trying for a very long time to get people to move off of self hosting.
Remember like a lot of the, the issues that we've had with Exchange over the past few years have been, and because Microsoft is slow to release patches for on-prem exchange, and their argument is, well, why don't you just move it into the cloud? Well, I mean, I know why Microsoft wants you to move it into the cloud because you get money for that, right? You get to pay a rental fee for your exchange server.
Uh, but you know, there's the pesky regulatory thing and there are companies that don't, aren't in the US and, and wanna control over their data. Um, surprise we found a bug in SharePoint. Uh, and here's the other thing too, as you mentioned in the article, this is what makes it in especially Insidious one, the traffic looks like normal user traffic.
So it's not like you're trying to send flood the machine or you're trying to do like a cross site scripting attack or anything like that. It really does look like legitimate traffic. But two, one of the things that they're able to steal before you can stop them is the hardware key to the machine.
Which means that after you abscond with that, you can just get back in unless you change a lot of things on the system. And that's a problem because this creates what we like to refer to as a foothold. And this is one of the things that if you are an attacker, you want, you want persistence, you want to be able to get into the system as surreptitiously as possible, create a foothold, persist.
And that way whenever they've deployed countermeasures, you can get back in whenever you want. And this is one of the things that we saw, I would be willing to bet this is related to the same groups that did the big email hack last year. They don't care about the executives email box today.
I mean, yeah, harvesting all those emails would be really nice. They want access to that email box in six months because that's hot intel that they can use or sell or extort with, right? And that's the name of the game here.
You get access to a SharePoint server, especially Unfettered Access because you have hardware keys. You could get design documents for new software or new hardware. You could get a press release a couple of days before it gets released and possibly make yourself a little bit of coin on the side by investing heavily or selling off if you know there's bad news coming, like this is problematic.
And I promise you, there are auditors out there right now that are licking their chops because they know that SharePoint is gonna make them a small fortune for the next couple of years because the amount of time that it's gonna take to get those things patched, to verify their patch status and to continually monitor them and make sure that nobody's already got a phone hold in them is going to produce a lot of revenue for cybersecurity companies. Al would you be worried if you were running SharePoint right now? Well, yes, yes, I would.
If I was running on premises share SharePoint, whether it was my own or if I was maybe using a service that was being offered to me by a third party that's not Microsoft that were hosting a SharePoint environment for me, I've seen both of those recently in customers. And this would be kind of terrifying that there could be that persistent access over time. Uh, and the, the mitigation to, to remove that persistent access doesn't seem to be something that's being directly addressed in these patches.
Um, you know, there, there does need to be a, uh, an effort out of Microsoft to find a way or to provide a mechanism to, to lock back out that persistent access without having to, you know, pave the whole road again, rebuild all of the exchange environment, uh, your, um, SharePoint environment from the ground up, because that's a nightmare. Uh, but I think Tom, you're, you are right on this one that the slowness of releasing patches, uh, two weeks after they first saw some vulnerable or some exploitation of this vulnerability before there were patches out for, uh, the on-prem SharePoint. You've gotta imagine that the reason we haven't seen a big attack on the SharePoint on Office 3 6 5 is that that patch was released a lot faster.
Yeah, and that's one of the other things that they're talking about here because somebody asked me this yesterday, do you think that this affects the cloud services too? And my initial thought before I read, uh, more reports was, yeah, well, of course if it's flawed SharePoint, it's gonna affect it whether it's on-prem or hosted. The difference of course, is that if it's hosted in Microsoft Azure, we can patch it right away.
And I'm sure that they deployed those patches the instant they were ready so that their cloud customers were at least not affected by this, which is probably gonna be a selling point, right? If you want to be protected from all this stuff migrated into SharePoint online and, and you won't have these problems, which kind of feels a little bit disingenuous, right? If you're not gonna keep the the on-prem software up to date, why bother selling it?
I, here's the other thing that people really need to understand. We, we talk a lot about this on, on the rundown. Like we, I joke all the time that if I just wanted to do my stories all were breach stories or exploit stories, I could, I mean, that's basically what the Risky Business podcast is all about, right?
But this one was not one that was only on like bleeping computer or the register this hit the Washington Post. This hit Reuters. This was big.
This is big. When regular traditional news outlets pick up on your problems, you have messed up. And so Microsoft, you need to get the, the, the dwell time on those patches down a little bit.
And you need to start patching versions that are not, you know, like n minus two at the very least. Um, but also you need to make sure that your on-premises customers are getting the same level of service as your cloud customers. If you don't, you're gonna have a bunch of unhappy people who are just gonna dump this and go back to the good old fashioned thing of burning all their documents to CDs and passing them around the office like Frisbees.
Luckily we don't do that around here because we are a modern organization that continues to have great events like the ones that we have coming up. And we are just a couple weeks out from our next big one, which is gonna be Tech Field Day Extra at Share Cleveland that's gonna be taking place August 19th and 20th. Stephen Foskett is gonna be traveling up the road to talk about all the great stuff involved with mainframe computing.
com because we just signed up a new sponsor and you're gonna wanna check out who they are and then we're gonna take a little bit of a break and let the heat come down a little bit. And al you're gonna be back with the next event after that. I am, it's AI Infrastructure Field Day returning in September 10th, 11th, maybe 12th as well.
Um, getting together my panel of delegates for that and the, uh, presenting sponsoring companies, we're building out that list at the moment. And, uh, it's gonna be another awesome event. We're gonna have a lot of fun for those those few days and learn quite a lot about some of this AI stuff that you might have heard about.
Of course, we take a little break after that before Tom has to come out and make sure that we're not getting in the New Zealand news the way that Microsoft Exploit did this week, uh, because you are back for Security Field Day. Yeah, I'm bringing a whole bunch of friends to help me out too, because what good is a Tiger team if you don't have a team and, uh, we're gonna have some amazing delegates that are gonna be showing up to help us out with this great conversation. com for more details on that.
Um, and we get to have some fun conversations there, whether we are, um, figuring out the right frequency to hack McDonald's drive-through machines, or just talking about why we think, uh, phishing buttons don't always work the way they're supposed to. Uh, that's one of the reasons why we love getting together and talking at Field Day. Just like we love getting together and talking with you every Wednesday here on the Tech Field Day rundown.
It is a pleasure to be able to create this content for you, whether you're consuming it on our web website at Techstrong it, or you are headed over to YouTube to listen to us be snarky, and then possibly even subscribing in your favorite podcast application of choice. Let, let's be fair, if you hear my voice complaining about security, you're probably gonna wanna ride that bike a little bit faster so you can get to a stopping point and put on some real music. But no matter what you do, make sure that you check us out here as well as all of the other things that we produce because we are a part of so many other pieces of the Futurum group that, uh, there's a good chance you're gonna hear us somewhere throughout your week and not just making fun of the news either.
Um, we will be back next Wednesday with more great news and maybe some not so great news, depending on how quickly people can patch things. Um, but until then, for myself, Alistair and Corey, our amazing producer, as well as all the other folks who contribute great things to the Tech Field Day rundown, thanks for tuning in. Stay Warm or Cool as the Case may be.
And we will see you in the next episode. Hey everyone, we're here again on the floor of, uh, black Hat. You know, it's funny, it's a very interesting show floor.
You walk in and you know, it's so loud, there's so many bells and lights and whistles and, but we found a little bit of a quiet area. We actually did truth be told, we kicked a guy out who was doing a demo here from Absolute Software. We nudged Him gently.
Alright, Christie Wyatt, absolute Software. Here's my guest on, uh, text Drunk tv. Truth be told, she nudged him Gently, Gently, gently, we'll say gently.
So we're here with Absolute software, as I say with Christy Wyatt. Christy, first of all, thanks for coming on. Text Drunk TV with me today.
Secondly, here's our audience. Tell them the Christie Wyatt story. Well, first of all, thanks for having me.
Um, I'm the president and CEO of absolute. I've been with the company for about seven years, uh, software developer way, way back in the day. I've spent many years in Silicon Valley.
So, uh, Palm, for those who remember Palm Violets, uh, Motorola, apple, uh, Javas Soft back in the day I was at Citigroup for a period of time. Really insider threat company called DT EI had a company called Good Technology. Um, so I've done lots of lots of different things and now we're here with absolute Very cool.
Um, you know, assume our audience doesn't know absolute, how would you just give us the absolute story then? I like to say Absolute is the coolest cybersecurity company nobody's ever heard of. We have a very tiny piece of technology that's embedded in the bios and has been for the last 15 years of almost every PC on the planet really.
And so what that really gives you is kind of an unbreakable connection to that device once it's activated. And so the way we use that is, is a whole host of different ways, but always with a focus on creating endpoint resilience. That's really a category we've sort of created and have been evangelizing for about seven years now.
So we can use this to track and manage devices from the firmware. We can use this to, uh, monitor the health of your overall security posture, heal applications if they stop working. So make sure that your security apps are always working.
Um, we do something called rehydration, which means if, if the OS or the devices become overcome or non-responsive BSOD or ransomware, uh, again, we wake up before the operating system so we can remediate things that may be happening in the device and kind of put you back together all remotely, all without user intervention. And then I needed this, so many, We have a big zero trust product as well in our Sass e product called Secure Access. So we do a lot of different things And it's all in the bios.
It's not on the, is it in the silicon? Silicon? So it's usually in the un flushable part of the firmware.
Um, we do have products across operating systems on endpoints, but we're in the un flushable part of the firmware, mostly on Microsoft products. Our Mac OS and Chromebook products operate slightly differently 'cause their architecture's a little bit different. Got it.
Yeah. You know, it's funny, I was walking around, people you meet at Black Hat ran into my friend Alan Friedman. I don't know if you know Alan.
He's from a, he just left csa. Okay. But Allen is the father of SBOs software, biller materials.
His new thing is called hbos. Yeah, hardware bill Materials. I would imagine this is something absolute software would be perfect for.
So, so we've been doing this for a long time because we are embedded in the firmware and we have amazing partners like, you know, Dell, Lenovo, hp, Microsoft. I mean, there's 28 different, uh, hardware providers that we've been working very deeply with over, over several decades. Um, some of our customers actually activate their, the, this, uh, capability in the bios at manufacturing, which means they can actually track the device from the time it takes its first breath, virtual breath first, hello, uh, yeah.
Uh, all the way to the time it reaches your hands. And it also gives you the ability to see a lot of telemetry about what's going on in the device from within the bios that a lot of other platforms wouldn't be able to see. It sounds it's an amazing tool, an amazing tool.
Now I'm gonna imagine you sell directly to PC and Mac and, you know, Chromebook manufacturers? No, no, no. This is a, this is a commonly held, uh, so, so our great hardware ecosystem, our great resellers of our products, uh, but we sell direct to enterprise as well.
In fact, we have over, you know, 18,000 customers, everything from small business all the way up through global enterprise and federal customers. So there's a lot of different ways you can buy from your MSP, from any practically any reseller, from any PC manufacturer. Um, and you can activate it on any device you have.
So, so you don't have to activate it at the time you purchase the product. You can, you can activate us across all of your existing asset, no matter how old. 'cause we've been doing this a long time, But it's built into every bio, not every Yes.
But it's built into all of these bios. Yeah. And it's, should we, could we use the word dormant until it's turned?
Right? Right. So we don't, we don't see these devices until somebody has, uh, installed, uh, an absolute activated product and it will activate that capability in the firmware.
And then from that point, you know, that device is very aware, self-aware, and, and very aware that it is kind of connected to your enterprise. So you can, what we, when we talk about self-healing, right, we really talk about rooted in the hardware self-healing. So we're not just trying to save ourselves like a lot of anything that's running at the, uh, OS and application level is, is really kind of preserve themself.
They really can't heal themself. If you're dead, you're dead. Right?
I think the difference between us is, is we're in the hardware. So, so to us, self-healing means I can rip out the hard drive, put in a new hard drive, and the very first thing that device will do is it, we will wake up and say, wait a minute, something's missing and we'll get stood back up. We extend that concept of self-healing to our entire ecosystem of partners.
So whether it's CrowdStrike or Tanium or literally any, uh, security or many enterprise applications, we'll make sure that they're always there and always running. We actually, uh, have a research report we've been putting out for about six, seven years now, called our resilience index. And in that we actually show across millions of devices the actual resilience score for most applications.
While organizations may think, Hey, I've installed encryption, I've in installed my XDR across a hundred percent of my install base, it's probably only active and running on maybe 70, maybe 80% of they're doing a good job. Um, things happen all the time, right? And it's, it's not just about patching and and vulnerability management.
It's, it could be the user tampering, it could be just a a, an upgrade got installed. There's a whole host of reasons why endpoints go dark, uh, blue or a blue. And you, you really don't have time to send an alert to a human being and have them come.
This is really why we believe that the, the, the last point of resilience has to be on the device. The device has to be intelligent and self-aware. And, you know, we, we've seen such a, uh, an emphasis on resilience lately, right?
We, we can't prevent everything true, no matter how hard we tried. Resilience is the key. And it's funny, this is not necessarily new.
It's been there. Yeah. But it was, it's kinda like Dorothy clicky her heels.
It was there the whole time, you know, It was there the whole time. Well, to be fair, I think the company has been doing this for a long time, but the use cases, uh, historically have really been around visibility and control. So it's ironic that in this age where we're talking about some pretty sophisticated threats, one of the biggest things that people really struggle with is, where's my stuff?
Right? Oh, there's a, a big os refresh coming in front of a lot of us. People don't know where their assets are.
They don't know what state they're in. They dunno how to get to them. I think that, um, that's long time been our focus is making sure you always have that hard connection.
You know where it is. You can remotely manage it and remediate it. Sure.
It was really about seven years ago, and it was because I had come from another endpoint agent technology company, and too often something bad would happen and we'd say, oh, let's go check the logs. And, and surprise surprise, that device stopped calling in, uh, a couple of weeks ago and nobody really noticed. Yes, it threw an alert.
Yes, somebody tried to fix it, but people are busy, right? We, we don't have enough people to go fix all of these things. And so the light bulb just sort of went off that, that you have this capability to, to heal things from within.
Now this was pre COVID pre-work from home, pre VSOD event, pre ai. But, uh, but I think that it's even more relevant today if we think about the speed at which breaches and attacks are going to happen. Our, our last line of defense is at the edge.
It's where the fingers touch the keyboard. I, I agree with you a hundred percent. You mentioned ai, you mentioned, so in my mind, post COVID things changed.
The, the world changed. AI has been harbinger of a huge change. Yeah.
Um, how is that playing into the absolute vision? There's, there's a bunch of different ways aside from, you know, we'll sort of start with, there was this myth. We all sort of convinced ourselves for like a decade that any data that was of any value to us all lived in the cloud.
And that the endpoint devices were just sort of non-intelligent transactional things. Like To the dump terminal Disposable, right? If you talk to someone and said, I could restore your endpoint device, they'd go, eh, who cares?
All my data's in the cloud. I think that for, first of all, that was never true, right? People were creating all sorts of unique data and insights on the device itself.
Second of all, you know, in the age of AI where you have a lot of new content being created and context being created, your digital twin, your digital footprint, fingerprint, and the point of compromise is probably on that endpoint. You can't afford for the intelligence to be sitting in the cloud. You can't wait for your next instruction.
You know, the attack is gonna happen in five, seven seconds or less. You, you need to find a way. And, and I think there's a lot of really great innovation going on across the cybersecurity ecosystem about how to move more of that intelligence into agent tools, down to the endpoint to the edge.
We're the thing that makes it stick. Not aside from the way that we use our own data and, and, and are applying AI within our own products. I think the more AI enabled tools you deploy at the endpoint, the more critical it is that you have that undeletable connection.
Here's the thing, we're gonna get some of it wrong. People are gonna trial, and they're experiment. They're gonna push out new things, things will go go wrong, and they'll go wrong quickly.
And so if you don't have that, that digital heartbeat, that connection to that device, I call this participating in your own rescue. Like when you call me and you say, Hey, you're in the bios and everything just went blue, or everything just went black, or we're just, we have a ransomware. You know, the, my question is gonna be, did you, did you activate us?
Like, did, did you, did you turn on the lifeline? If the beacon's on right, there's probably something we can do. That's a, that's a great way of saying it.
So, you know, it, it's funny. So everyone out here watching this actually already has absolute installed, probably it may not be activated. True Beacon may not be on.
So that begs the question, what can they, other than going through channel partners that you mentioned Yeah. Is there anything they could do to turn the beacon on? So first of all, uh, there's a whole host of different ways you can come see us here at blackhead.
com, right? There's, there's, uh, opportunities there. Literally any PC manufacturer, most channel partners, there's, there's no shortage of both applications that have the ability to, to, because there's a variety of different ways to turn it on to activate it.
Um, so there's a whole host, there's no lack of voice. com and you'll, you'll all things will be revealed. Excellent.
Last question. What do you think of Black Hat so far? Uh, I, I mean, aside from, it's chaotic as it always was.
Always. It's, it's, it's, it's chaotic, but I think, um, things are happening so quickly, right? And I think the top of mind for everybody here is just the rate of change, right?
I think it's, we're all very excited about ai. I think somebody in the, in the CISO summit yesterday said the words fascinating and terrifying in the same sentence. Which, which I thought was profoundly true.
I think that as things unfold, um, there's tremendous opportunity. I also think there's tremendous risk and we're all sort of painfully aware of it. I have huge respect for all of the constituents that are participating here.
'cause I think everybody's working their hardest to figure out how we all kind of band together and respond to, you know, uh, digital workers and, you know, tainted data in your Lens. It's short Territory, it's craziness, you know? Right.
You've been around, I've been around. I've seen the advent of cloud. I've, I, I remember when cell phones became a thing.
I remember when the internet became a thing and we all had these, sometimes they were probably rose colored glasses, visions of how great everything will be, but getting my experience anyway, getting from here to there. Yeah. It's always bumps in that road that we don't anticipate or we didn't see coming.
And there will be here too, as you say. I, I think, I think people are cautiously optimistic. How does that sound, I, or terrifying?
And, You know, I don't know. I, I I think it's inevitable. And so, uh, you know, I like to say that there's not a lot of benefit in having what I call the Muppet debate.
I dunno if you remember the Muppets, the two guys on the balcony, like, it's gonna take all the jobs, it's gonna be fine. I, I think the answer is, it's, it's, it's here and it's happening. It's happening with your employees.
It's happening with your customers. And so we're, you know, there's a tremendous opportunity to kind of participate and sit down and figure out what is the best way to apply this to accelerate our businesses, um, but also to help mitigate the risk. And so there's a lot to talk about there.
I agree with you. A lesson I've learned in 30 years is security. The market doesn't wait for security.
Security has to catch the market. Right. And I think that's what we're seeing here as well.
Absolutely. Anyway, best of luck. com.
com. Check it out. We're here at Black Hat.
We'll have more. Stay tuned. Alright.
Hey everyone, this is Alan Hummel from Textron tv, and we are here at Black Hat on the show floor. We were lucky enough with our media passes to sneak in early before the floor gets too crazy. And I stopped over here at our friend's booth, uh, uh, the Frogs Jfr to check in on them and what's happening here at Black Hat on the Jfr front.
And I've got my friend Paul Davis, who's field CSO at Jfr. If you've watched Text Drunk tv, Paul's been a frequent guest. Hey, Paul, welcome back to Text Drunk tv.
Thank you. Glad to be here and glad to be back in Vegas, a black hat. So we came to the swamp or the, the black hat swamp.
Yes. Yes. It is green around here.
Yes. Yes. There's the frog.
Um, so Paul, a lot of my audience out here is saying, gee, we know Jay Frog. They're a DevOps company. Yeah.
Yep. They're a DevSecOps company. Yep.
But aren't they a black hat security company? So yes, they are. Right.
This is one of the interesting things. If you imagine today's world, you can't push anything product, software out into production unless you're dealing with security. And security has many different aspects.
Yes, you've got the CVEs, you've got the vulnerabilities, but you've also got the compliance, the regulations, and also making sure you've got trusted software out there in production. So to do that, that's a security thing. And security leaders, that's what we worry about, you know?
Sure. Because if we, if we can't say yes, it's good. That's what wakes us up at three o'clock in the morning when we get the phone call saying something's happened to our software.
So it's a bit of a nightmare. That one. Absolutely.
Um, you know, Paul, obviously the, the theme and no surprise, the theme of this year's black hat is ai Oh yeah. There's AI this, there's AI that Yes. Here in ai.
There in ai. Everywhere in ai. Yep.
Um, I, I heard Caleb SEMA talk yesterday in a session from Cloud Security Alliance, and he called, he talked about AI washing Ai AI washing. Okay. Yeah.
Just slapping AI on Oh, yeah, yeah. You know, whitewash everything with ai. Yep.
Let's talk a little bit about that. Yes. About how Jfr views ai, ML ops as well.
How this is all coming together in terms of the frogs. So machine learning, ai, generative ai, these are, it's as you said, it's almost like you can't have a real product in today's world unless you've got an AI tag somewhere in there. Every brochure, everything happens.
The problem is, is that it's accelerated so fast that we're losing control. And what we've discovered is, is that many of our customers have multitude of AI and ML projects going on, but they haven't got the control. So the first thing is, is that, interestingly enough, when we talk about the attack surface around AI and machine learning, there's two sides to it.
There's the development side, and then there's one that's running in production. From that perspective, you really wanna have a strong foundation. So we started last year, first of all, we discovered that there are actually attacking the data scientists.
They're attacking the data scientists going after them. So if you download like a model, you'll actually try and compromise your endpoint, your workstation, right? They'll also do all sorts of tricks.
And especially like with MPC, with this new, uh, tech, we've recently just published some research saying, Hey, look, if this actually connects Q code and in infect your system, so that's a new attack surface. And we've, we've always worried about, Hey, let's put on point protection on the workstation. Let's do security.
But we didn't think about data scientists, data engineers, and this is a whole new world around that. And so really what we are seeing is, is companies saying, we've lost control of ml. We need to start putting control points in place.
We need a central place to do storing the mls. We need to do deep scanning. Because many organizations, I was re uh, watching a Gartner, uh, presentation yesterday, 80% of companies are now investigating how they're going to scan their ML models for malicious code.
That's either stuff they brought in from the outside world or stuff that's been introduced accidentally. You know, Paul, one of the problems though is that themes, things seem to be moving so quickly. Oh yeah.
So fast. Oh yeah. And it's, it's full speed ahead.
Damn. The torpedoes. Right?
And, and so we look at something like you mentioned MPC. Yeah. MPC was like invented in January, basically.
Yeah. Here we are in August. It's already the defacto standard.
Yep. Everybody's coming out with an MPC server and no one is sta stepping back and saying, what about the security? Yes.
And, and you know, unfortunately, as someone who's been in security for 30 plus years, this is a familiar pattern. Yes. Yes.
Right? Yeah. We're always the afterthought.
Yes. Oh yeah. Security.
And, and so I worry, yes. I worry a lot about that. You know, garner, Gartner's saying 80%.
I'll be honest with you these days, I don't know how much I believe Gartner, maybe we should file the fire their head, uh, static statistics keeper. But yeah. Do you really think 80% of companies are, are scanning their ml?
They're not. They want to, they're planning. Oh, they're Planning.
Oh, yeah. Yeah. So the actual reality, we just published the state of the union report a couple of months ago, and I think it's like over 70% of the executives think that we're using AI with scanning developers is just a little bit over 50.
So they disconnect them. Now, what's interesting is, is that some people are realizing, especially regulat compliance EU with its AI laws, they're the tough cookie. They're the people that have teeth over here.
We are slowly getting there. Well, around the rest of the world, we're starting to, so the regulatory pressures is starting to push down the executives and guess who they look at the security leaders. Yeah.
Hey, how are you gonna handle this risk? And it's like, what do you mean? Well, you, you responsible for our IT security.
I mean, You don't think you're getting more budget. No. Oh, no, no, no, no.
More or less. You know, but No, but the thing is, is that what is interesting is they're now bringing in the CISO for those conversations and the, I'm increasingly having conversation with CISOs about how do I get control of this? How do I start streamlining it?
And the interesting thing is that the lifecycle around building ML kind of aligns with what DevOps, because at some point you take that model and it's got to be integrated. And then one of the most frustrating things I find is they go and talk to somebody and says, well, what about your open source? Well, we don't deal with open source, we just have libraries.
Of course you do. Yes. They use open source for cleansing the data.
You use open source for. Well, no, There applications are built on open, open Source. Exactly.
Exactly. So there's almost this denial in education going on where we have to tell them that It's ignorant there. Yeah.
So, but basically what you've gotta have is now control points to make sure you are actually understanding what's ending up in production. And that's what's really scaring me is this thing of ML models are just being integrated in, and it's being integrated in all these applications. Applications you build, applications you buy.
How do you get control of that? That's what's really scaring me nowadays. I I will tell you, it is scary.
There's two things here. It's the velocity Yes. And the volume.
Yes. Two vs. Oh, yeah.
And I, as, as counterintuitive as it may sound, I think the only way security folk can can get their arms wrapped around this Yeah. Get their heads wrapped around it, is to use ML and AI Yeah. Themselves.
Yeah. To combat the issue. Yeah.
So you gotta, in essence, fight fire with fire. Yep. Let's talk about what Jfr O'S doing around that.
So what's interesting, we actually just released a a beta of an MPC. Really? Yes.
Which, which Jfr, but it's rarely clever because you can ask it questions saying, Hey, what vulnerable package to exist, et cetera. For vulnerability management, since we have ton, we have a thing called catalog. It is like the gold mine of vulnerability data around open source and LLMs.
And you can go in there and I've got some companies who are saying, this is our default path before we do a, when we do a triage, we're gonna look at that. So we have, first of all, we have broader company called Quack, and we've turned that into frog ml. Yes.
And that is basically how do I get a consistent building path for how I actually build out my ML models? Whether it's the data, whether it's building out the feature stores, whether it's the experiments, whether it's actually rolling it out in production. We've made that whole journey.
So jfr is very much focused on the process of building a secure foundation. Because if you've got a secure foundation, then when you're having to monitor it in production, it's got less attack surface, it's got less vulnerabilities. And you can get proactive on that.
So from a, from the AI perspective, we've got catalog, we have frog ml, we have our advanced security, we have the ability to store ML models centrally. And that means we can get access, we can generate audit logs. Really?
Yes. We can show who is downloading or trying to use that ai. So you're fighting fire with fire?
Well, I wouldn't say fire, we are a car. We are like the, uh, Pepto bno. So the calming first terrible analogy.
But with, it's really trying to put the fire down so it's manageable. So it's less painful. You don't get burnt from it.
Because as I say, the more visibility we have into the process of how something ends up in production, the better. Yep. I wanna bring up another subject with you.
Yes. Lot of stuff going on around platform platform engineering. Yes.
DevOps and platform engineering working together for the internal developer platforms. And, you know, the developer becomes the customer, if you will, of the product. How does that play into all of this ML ops and, and Right.
You know, the, the base jfr offering actually. So it is all about streamlining. Most executives want to streamlining what to simplify the process without compromising their security.
The problem is, is that at the moment, because everybody has their all favorite tools, they don't, they can't streamline it. Yeah. But we, we can't beat all things for all people.
So the platform play from the perspective of a DevOps platform, from designed all the way into production. We support that. And we have also the ability to actually, uh, use evidence files as gates to prevent something into production.
If it hasn't passed a test. J link is sexy. Yeah.
Right. But from the point of view of the, the, the developer and enabling them, that's a big thing for us. Shift left.
We've been doing shift left and focusing for years. The thing for me is I want to turn developers into Security Warriors. I want to give them the information at their fingertips.
So you say, Hey, this is really a problem. It's like, we really need to have traceability. We need to have, is this really a real threat to your software?
This's terrible saying I have, I use it multiple times. One bad function doesn't make a bad package. They're not calling the bad function.
I don't need to worry about it. I don't wanna tell the, Hey, you've got a problem. 'cause you using a bad package, but I'm not calling the bad function.
Why are you bugging the hell out of me? I just wanna write code. Yeah.
And you talk about, interesting enough, the impact of this across the whole organization. When a developer makes a mistake and it includes a bug or a secret or whatever, that ripple effect goes to the AppSec team. The AppSec team, they might miss it or they might, they might get through.
Then it goes through to IT ops to production and then SecOps. So you have all these IT ops, BizOps. So we actually call it every ops, but I've got to grips other than that, every ops, because the impact of making mistake at the beginning ripples through you double the cost of deploying somebody deploys above Double No, I think it's more than double.
Yeah, it's exponentially. Yeah. Yeah.
It's just crazy. So if I can fix it earlier, just like the kill chain, the sooner I can fix it, the cheaper it is. And as I said, the fact that in the AI world that CISOs teams are being brought in on the design, I still worry about data.
I don't think we've got data governance under control yet. No. But as far as the actual binaries, the open source, the, that sort of stuff, I think that's sexy.
Excellent. Um, just about a month out from now. Yes.
We will be in Napa at the swamp out. Oh yes. Excited for that.
We'll be there actually filming live. Wow. Brilliant.
Yeah. So we'll be there. I'll probably see you there and we'll talk some more.
Oh Yeah. I'm actually doing a training course there. Very cool.
Okay. So they've got me recorded, like as Morpheus from the, um, the Matrix. Oh yeah.
Use that. You got Right. Because I've got a training course about compliance and showing how you can automate easiest way doing security is automate.
Very cool. But yeah, it's a great event. I went there last year for the first time.
It's really like the old fashioned security communities where you actually get a chance to sit down and talk. Yeah. He actually, it's not just No, I, I've been going swamp boats for years.
It's amazing. Great community event. Yeah.
So you build long lasting connections there. So thank doubt about it. Yeah.
Looking forward to it. So that starts, I wanna say it starts the eighth, September. No, it's ninth and 10th.
Yeah. Yep. Well, you're testing me now.
I'll have, yeah, no, we'll be there the ninth and 10th filming. Yep. Paul, thank you so much for giving us a peek into j Rog here at Black Hat.
Enjoy the rest of Black Hat. Thank you so much. All righty.
Okay. Paul Davis Field CSO for J Rog here at Black Hat. We're going to continue our coverage on the show floor.
So stay tuned for now though. That's out. That's it.
We're out. We'll be back.