Techstrong TV December 1, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Spice flows again on the Desert Planet. Ar Iraqis Shy Haud, you're watching Text and Gang, Man, anytime I could start my day with a little dune reference, I'm a happy camper. Um, who knew that it would take some kind of, you know, bad malware for me to talk Dune on Textron gang.
But hey, whatever. I'm, I'm happy with it. I'm happy to go with Dune.
Um, welcome everyone to our Monday version of Textron Gang. And, uh, I hope you had a, for those of you who celebrated the long Thanksgiving holiday, I hope you had a great time, a great time with family and friends and loved ones, and enjoyed your day off or your days off. And you're here refreshed, ready, eager to get back to work and talk about things that are important to us in the tech world.
Uh, we've got a great gang lineup to, to talk about stuff today. Let me introduce you to them. We have, uh, Terry Robinson, resident Cyber Pres person, our Silicon Valley, John Schwartz up in Canada.
She celebrated Thanksgiving earlier. Karima Bal Karima, good to see you. And of course, well, we we're calling him the dean, but yesterday, I think, or at our last show pre-Thanksgiving, we decided he's now a Bard.
The Bard, Mike Ard, um, welcome gang. How are you today? I hope you all had a great weekend and long holiday.
So, Mike Ude is back. The spice is flowing again on ar Iraqis. Yeah, the Guild is happy Security people and Linux administrators, not so much what's going on.
Yeah, things are a little crazy out there. Most of a lot of security folks spent the holiday cleaning up after this mess because, well, Shai, 'cause well, shy Ude is back. It is a self propagating worm this time.
It seems to have also included some malware that basically exposed everybody's tokens. So now anybody could just basically log into anybody's repository. This mainly affects MPM packages and, uh, repositories holding a lot of JavaScript code, but it's a bit of a mess.
And Alan, I'm gonna put this to you. I mean, this is not the first time that we've gotten this kinda wake up call about software supply chain security. But my question is, we're just gonna roll over and hit the snooze button one more time.
You know, this ain't my first worm, as they say on dude. Um, seriously, I, I don't wanna minimize this, right? We've got a serious problem in NPMs, and it's the same kind of problem we see, of course, the repo world in general, which is people because they download it from a repo or from a, a package manager, assume all as well.
And they, and off they run with their software. And no one is policing these packages. No one is policing the uploads to the reposts.
So, you know, buyer beware, user beware is the, is the day, but is this worm, I mean, we've seen a lot of worms come over the years, right? The worms crawl in, the worms crawl out. This particular UDE two, or the sequel, or whatever you want to call it, seems to be a better version than the original in that it's faster, it propagates better, and it can therefore be more dangerous.
Um, and we've seen this happen too, right? You, you get iterations and reiterations of, of these, of these malware variants like viruses, you know, that's what their name, we call 'em viruses, right? Because they're like viruses in the real world that are constantly evolving and evading, right?
It's a cat and mouse game. And now we see the next variant of Shy Haute. Is this gonna be the last one?
Probably not. I, the bigger issue though is what do we do? We all, you know, 80%, 75% of the software in our apps is downloaded from JavaScript repositories or Artifactory, you know, artifact repositories or you know, Maven Java or, or there's so many different repos where we get our software docker containers.
Um, there are, you know, what do we do? There are a lot of companies that are now starting to put out safe packages, safe distros safe containers that they certify, you know, for these common, and, and you know, you can't have one for everything. 'cause there's millions of different variants.
But for these very popular ones, we have a, you know, a clean version that we guarantee is clean. And if you use our stuff and use that, you're okay. SUSE does it for one, right?
Uh, there are others. Maybe that is where we're headed that because, and I've said this before, I lay this at the blame of the, of the repo managers of the maintainers, I think they have a duty to make sure what goes into their repos, into their collections is safe. So that's where I am.
Did they, did, you know, you talked about, did we roll over and hit the snooze button, whatever, roll over. Um, is that what happened between September and now? Um, or did this just come so quickly?
No, no. This is a new variant. Okay.
This is definitely a new variant. You, it's, look, this is a virus and vaccine, right? You, you change the, the DNA coding or the cellular coating or what have you, and it evades what you had before.
So though you may have thought you were protected against ude one, this, this is definitely a, a, a, a better version of it. That's more insidious Mima are developers just frankly spending too much time engaging in what you might refer to as unprotected downloading, I dunno, Right? I mean, uh, to build some more context, and I'll come to that question, uh, Mike, uh, in a while.
So what this, uh, virus is all about, this is a major cyber attack, which is also very fast moving and dangerous as, uh, the article refers to, because it hits the supply chain. And what it does is it does data harvesting, it steals developer credentials. For example, if you have open credentials in your, like, you know, ecosystem, API keys cloud tokens, and it exfiltrate them to a public repository, right?
So when this infected packages are installed, the warms harvest developer credentials or API keys or cloud tokens, and then, you know, uh, you can kind of, uh, be susceptible to any number of, uh, you know, attacks like secrets from your local environment, CICD pipeline. Your credentials are kind of, you know, at a risk and stolen data, for example. So it becomes a Dropbox for stolen, stolen data, for example, right?
Mm-hmm. So now what we can do as practitioners and developers, I mean, uh, the first and foremost thing, I mean, uh, um, Ellen, you mentioned about this. Many organizations have been, uh, working tightly, uh, with this open source ecosystem.
Our good old friend, Tracy Reagan, for example, is heavily invested in open SSF. And, uh, we have from CD Foundation, there is a sig, which looks at these kind of, you know, practical cyber attacks on ci cd pipelines. There, there are assessments and order mechanisms available.
Now, what we should be doing as an organization, of course, you know, there are, uh, from enterprise perspective, we always have wrappers, for example, right? Security, uh, guidelines to kind of ensure and secure our environment. But more or less, I think it also, uh, is a strategic imperative for defenders.
You know, how do we build robust supply chain audits, for example? And this is not something which is like off the table. I mean, you have to do it because, you know, these attacks are getting even more smarter, like dependencies to detect an anomalies.
For example, unexpected pre-installed scripts, which in this case you will see that, right? Suspicious package updates. So these are things which you should actually monitor your system for credential hygienes least privilege.
Uh, of course, if you expose your credentials, uh, it's like combined risk of, you know, having, uh, these attackers to kind of, uh, also decipher it. Also, I think, uh, from a hygiene perspective, it limits the possibility of what your application could do. Proactive threat hunting and anomaly detection.
I mean, we have been talking about chaos engineering and all those kind of things. It's time we take it seriously, right? So if this kind of attack happens, what is, uh, uh, the, uh, poster, we have to hunt them back and to try to kind of be, uh, from a real time perspective, uh, more proactive in, um, detecting as well as, uh, protecting our environment, collaboration with open source communities.
I mean, uh, it is needless to say, if you're not aware of what open SF uh, foundation is doing, CD Foundation is doing, um, talk to, uh, some of our, like, community leaders like Tracy Reagan, and there are many more in the ecosystem who can actually guide and help you in this direction. And, uh, more or less, I mean, it's matter of education and awareness. I mean, uh, again, these attacks are not new.
It's just faster and more dangerous, as Ellen you mentioned, right? So how do we educate our ecosystem? How do you invest in more like AI native defending technology applications, which can defend your kind of, you know, um, applications, uh, from these attacks?
And I mean, from long-term attack patterns perspective, it's evident that this supply chain risk persists. You know? So we have to think about how we manage these, uh, malwares.
We, how do we manage these risk attacks and, uh, how do we ensure that automated self replication doesn't happen, right? Credentials, thefts, and, you know, reuse of these kind of attacking mechanism do not happen over and over again. To your point, Terry, you know, what we were doing from September to now?
I mean, it's a different form of form, but then again, uh, is our poster improving? Do we have taken enough action on this? Right?
And again, it's needless to say that, you know, one of the most important things, which will change our developer's profile is how security savvy we are. This is what like, you know, how your, uh, developer ecosystem would change is So garima. I, I've gotta disagree.
Yeah. As someone who is in instrumental in starting the whole DevSecOps movement as being real, one of the lessons I've learned 10 years doing this is don't throw this on the developer's shoulders. It's not the developer's job to be the security professional.
It's the security professional's job to be the security professional. When the developer goes to a repo, whether it's an NPM or Artifactory or Maven or wherever they're downloading their software from GitHub, there's got, there's gotta be a level of trust or docker containers. There's gotta be a level of trust that what I am getting from here, at least today, it may wind up down the road, I find out there was a bug in it or something.
But at least today, it's free from this kind of worm. It's free from this kind of self-replicating Trojan. And to say, you know, buyer beware, it's on the developer.
When the developer's downloading literally dozens of these from different places, you know, packages and components and scripts. I don't think that ever works. It, it hasn't worked.
And we've come down this road in DevSecOps, don't, the developer has enough on their shoulders. We, you know, we came up with the whole system of SBOs. That's something we haven't mentioned here, right?
SBOs was supposed to help secure the supply chain. No. And SBOs a great tool for forensics, right?
What did this have in it? Where did this bad? How did this bad piece get put into my package?
Into my pipeline? But it doesn't really address this issue. And I, I, and I've preaching about this for years, we need repo firewalls.
When before you can download something from a repo, it has to, you know, JFR has it for artifactory, just it's called X-ray. But we need one that's generic that goes across repos and, and either puts these scripts and, and, and so forth in a sandbox and make sure that they're free of malware or something. So that a developer has a high degree of, of, of, uh, certainty that the, this software is, is good to use, otherwise you're just making the developer's job impossible.
Well, yeah, I hear you. I think, uh, um, I agree with certain aspects of what you're saying, but it's also not this or that, right? I mean, you, uh, have actually put forward a very good point on, you know, what kind of security, uh, loopholes we have today, which we can restrict or have strict control on, which probably, uh, be the job or responsibility of the security professionals.
But let's assume that this attack happens. The defenders are, you know, if they are not supported by the developer ecosystem, they would be be failing at that point in time. So this is a cross-functional collaboration like vulnerability disclosure, or transparency of dependency of, uh, you know, on, on dependencies or, you know, health of the, uh, code itself, the, the, the whole, you know, rapid patching mechanism.
We need some kind of, you know, ecosystems to support that. And the developers need that support. But I think it's also needless to say that developers also need to move and shift in the direction to understand what kind of modern attack patterns are happening, what kind of hygiene in, you know, coding needs to be kind of put in practice.
What, what collaboration your security professionals would need. If you don't see the guardrails in the CICD pipeline, would you be the whistleblower and try to kind of ensure that this collaboration gets developed? So I think there is some kind of potential in, you know, securing that collaboration.
Of course, we have been talking about this since like two decades now. Ellan, you know, about DevOps and DevSecOps and mm-hmm. Those kind of, uh, definitions and, you know, how do you put this into practice?
But I think the sweet spot lies into the synergy rather than building, like, uh, hard boundaries. I think it's, you know, and shared responsibility kind of, you know, on, on, on both sides. Yeah.
Alan, it's not fair to just put everything on the developer's shoulders. They're not security people, but they have to be somewhat savvy in security, you know, for all of this to work. I, I, I think in, well, I mean, if You're a security person, the way you look at this as you go, Hey, I told you not to go and engage in that behavior, and you went and engaged in that behavior, and then you came back and I patched you up and I sent you back out there again, but now you're just gonna do the same thing over again.
And eventually, like a good doctor, they just shrug and go, I'm telling you not to do this, but you know, you gotta, at some point stop doing it. That's like, right. And going out and committing the same sin over and over again.
Wait, What? So, so like in theory, you're talking about all these prescriptive measures in this history, but I mean, when I read both these stories, I come to the conclusion of pace. It's always about the pace, and the pace is it's getting worse.
Yeah. And it's probably gonna give, so you're talking about a thousand new repositories re uh, surfacing every 30 minutes, which is significantly more than the previous iteration. At the same time, you've got more code being developed, which is just gonna increase the number of repositories that need to be secured.
So it's just like this escalating math. And I, I know it's not easy to solve, but it's, that's just a terrifying takeaway for me at least. Yeah.
And of this code is written through ai, you know? Right? Yeah, exactly.
Yeah. 0, I'm pretty sure it's, that's Coming. That's, that's coming too.
Look, yeah. Yeah. So Shy Ude happens to be the one hitting NPMs and JavaScript.
They'll, they'll, they'll be the Baron Hocon next on somewhere else, right? And the Paul Lares Modi over here. There's, we've been, we've been naming these worms for as long as I've been in tech mm-hmm.
From the Love virus. Remember the Love bug virus or whatever it was called to bug codex code red, you know, there, there's, there's always a next one. We need another sound novel.
We need a sanitary a a a a checkpoint Charlie for these things. Oh dear. So who, anyway, hey, we're over time on this, though.
We gotta take a break. We, I'm sure we'll be talking about it again, unfortunately. But you are watching Text Junk Gang.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions. Your home life included, that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back in, well, interesting times in the land of social media, but we may have some actual transparency into what's going on, or at least a little more political chaos. But apparently the folks at X are letting you see where the account is that somebody is actually following. And turns out some of the political accounts are in places that are not in the United States.
They're in Africa and all kinds of places. 'cause somebody's paying for that. But John, is this gonna become the new standard?
Will everybody have this level of transparency, or is this a one-off kind of thing and it's just gonna go away? You know, it may be a one-off base on what's happening with X. Uh, this is, I mean, we talked about Dune.
How about Dr. Strangelove? This is like some dark satire that, that, you know, I know the intent is the intents to, for security purposes.
So there's this transparency tool that X introduced over the weekend that re reveals accounts that claim to be that claim to represent American political views. And what they're finding is that, wait a second, through their geotracking, they're finding that they're coming from overseas. So I'll give you a couple of examples.
There's, there's an account called Ultra MAGA Trump 2028, which claimed to be from Washington, DC Well, it's actually from Africa. There's another account Where in Africa though, John, I, I don't know. Well, because, you know, I have a Nigerian prince who runs a lot of these things.
Right? Well, good. So there's another, exactly, there's another account that shows up that's, that's, that is coming from Macedonia where it was subsequently deleted.
Then there's another one, uh, called just, uh, ampersand American, which is a bald eagle for flag. And that originated from South Asia. So that's all well and good.
So they're identifying these, there's a one little glitch out. So some reporters started looking into it, and the accuracy is not always on the spot. So NBC for instance, they had several of their reporters display their locations where they had recently traveled, and that's where they were located rather than where their actually base where they do their job.
Um, the controversy got even worse when there were some viral screenshots that claimed the Department of Homeland Security account was based in Tel Aviv. So that was, that was disabled the same night. So DHS has issued this denial stating the account has only ever been run and operated from the us.
So X is finding itself scrambling, trying to, trying to fix the accounts that it got wrong. So we don't know what the percentage is. I think it's highly accurate, but there's just enough to leave doubt.
And again, I, I mean this, you can't make this stuff up. When Mike sent this to me, I thought it was a satire. And then I started reading some accounts in NBC and, and BBC and elsewhere.
And it's, I, I know the intent, but the execution as it always is with x, is a little off base. It's so funny too, though, I have to say, if you've been sort of online and watching this, like, you know, on, on X and people, you know, chatting or whatever, now there are some commenters who are using this like, as a bludgeon, right? Against Magna or whatever.
They're like saying, they're just dismissing whatever they said because they said, oh, well that was from Nigeria, that was from, uh, Russia, you know, or whatever. So it's been a little hilarious to watch people try to respond. Well, you know, the one, one of the thing I should have mentioned was, um, that's right, Terry.
One, one thing we wanna mention is that X this is like, to me, confounds me. They, they, it's like an Elon Musk move. They eviscerate their technical support.
They get rid of all their, their engineering talent. Then they try something like this. For what reason?
I'm not quite sure. And it just blows up in their face. I mean, what did they expect was going to happen?
This is not the first time this type of scenario has unfolded at X. But again, I couldn't sh then again, I shouldn't be surprised 'cause of social media, Well, didn't they like test this out before they sort of made it public? Or Extensively You would think Go fast, Baby, have two people.
That's, that's the valley. But, but guys, let, lemme lemme play play devil's advocate here. I think this is a great thing because anything that gives us a little transparency on the fake news of social media, and if we remember right, that's why Elon supposedly bought Twitter, the bots and the fake stuff.
He was going to, you know, eliminate all of that. Now, my friend Andy Ellis, who's a pretty well known ciso, he was, was CSO at Akamai for 20 years. He, he posted something on this, and it was around the, the supposedly, uh, pro Gaza news media and news and Pro Gaza X accounts that it turned out none of them are actually in Gaza, right?
They're all reporting from Gaza, but from somewhere else. And I'm not saying that makes it any, I'm not getting involved in the Israeli Gaza. I think I, you know, but it's that kind of transparency that I think we'd all applaud.
Hey, all these people who are, are supposedly MAGA haters or MAGA supporters, it's good to see that they're coming from Venezuela or China or North Korea or South Korea or wherever. Right? It, it, I think it does give us transparency that we all would, like, my problem is what stops a Chinese deep state, uh, uh, campaign activity from flying into Nigeria or Venezuela or Brazil and carrying this on from there.
So at least it doesn't point back to China, right? It points to Brazil rather, or for that matter, what stops it, the now that this is the cat's outta the bag, what stops them from using Chinese nationals who are here in the us Right? So while I, I think it's a great idea and I applaud it.
I just don't know how effective it'll ever be. Yeah. Yeah.
The concept is good. This is, the execution is flawed. I mean, but yeah, It's, I just want the other social media platforms to follow suit.
I mean, some transparency is better than no transparency. Yeah. So I wonder if this raises the bar.
Well, okay. And I agree with all of that, except that there's also a whole facet of our society that doesn't care about the transparency. They're gonna believe whatever that stuff says, they don't care if Elon Musk and them find out it's from Nigeria or Moscow or wherever.
Right? They're, um, they're going to, they're gonna stick to the narrative. I guess that's a whole different problem.
And not, Well, there, there is that Right? That's the Joe Bels, Joe Joe Goebbels social media view. If you say it loud enough and often enough people believe you.
Yeah. I guess, you know, when they forward that stuff to me, I just wanna know where it came from in the first place so I can at least have something that feels like a rational conversation. Yeah.
I also feel this is a generational thing, right? I mean, uh, we would see more generational awareness about how to treat social media and what kind of social engineering happens in the background. So, for example, me being from a millennial club, we are a bit more aware.
But I think, uh, moving on, I think the Gen Zs and the gen Alphas, I think they're very conscious about their choices. And I think these social engineering of, uh, you know, politicizing things, I, I think this will not be something which is something which we have seen so far. Yeah.
Agreed. Agreed. I wouldn't be surprised to see, uh, meta try, try to use this concept.
No, I, no, I think we'll see copy cats here. Yeah. They're all, we definitely see, and, and here's the thing.
As we get other social media companies copycatting this, they'll continue to refine it. Mm-hmm. Right?
Uh, 'cause like I'd like to see is, okay, so this account that's in Nigeria, what's its history, right? Where, what, what's the connection here? And see if you can start tracing it back.
And, and maybe that's the first steps towards retaking, right? Taking back our society from, from the, from the fake news. I would also wanna know how much of the content of AI generated, I'm not saying you use it, but I just wanna know like, how much of this is noise?
Well, not all AI contact is noise there, boomer? No, it is not. But a lot of it is, you know, somebody created sort of video that doesn't exist.
And, you know, it's like, I wanna know. Yeah. But it's a matter of trust also, right?
I mean, even if it's not noise, nobody trusts us. Well, but, and that's the whole thing. If we're gonna have trust and if you're gonna be able to, you know, look, Terry, to your point, people who are living in an echo chamber and just weren't their particular message reinforced, don't give a crap whether it's fake or not at some level, right?
They just wanna reinforce their real, they just wanna reinforce their bias, right? Yeah. But for the rest of us, and especially for young people, 'cause I think young people are savvier than, you know, I make fun of Mike, I'm older than him.
You know, young people are savvier than we are. I'm getting tired of, you know, people coming up to me and showing me stuff on social media. And the first thing they ask me is, is this true?
'cause nobody believes anything anymore. Anyway, so, but it's crazy. But this is the same thing.
90% of developers use AI and 40% of them don't trust it. But they use it anyway. They use It anyway.
Well, you know, it was interesting, and not that this is so related, but I had a recently in a estate sale at my mom's house. And one of the things that they, when they staged everything and, you know, whatever, it was all great, but they had my, my world book encyclopedias. Oh, I loved the World book.
Yeah. From the sixties and seventies, right? Mm-hmm.
So I had every, like the yearbook that they put out every year. Yeah, yeah. Whatever.
And it got us to talking about like, how we were kid when we were kids. We would consult the World book. And it seemed to be the authority on, you know, It was A certain level of How many reports did you write using your world book?
Of Course. Exactly. You know, and, and, uh, my fiance said that his dad, like if they were at the dinner table and they ask a question about something, his dad would say, go get the World Book.
Yeah. And let's look at That. You know what?
I'll show you how crazy we were in my house. My brother, I have two brothers, but the one closest to me, we would each take turns with a different letter every night. Because we remember the World Book used to have the transparency.
Oh, like the human, human body, the circulatory system and Oh gosh, my favorite one, Or, or ones you know, about exotic places that we wanted to visit one day. My brother made that list and kept that list and he's visited all those places. That's, Yeah.
You know, it was, it was the source of all knowledge, Those trans that Was back, that was back in the day when you had the encyclopedia. You had like only three networks and you could basically trust, Well yeah, you had three networks and you had the World book, or you could go down to the library And not, not, not criticizing, getting a lot of information from a lot of different places. But there's something to be said, like when you just had the three networks, there was a certain amount of journalist discretion, right.
You, they chose what was sort of important and they didn't necessarily hype, you know, sort of bsy little, Their view of things. But you knew Walter Cronkite was in CBS headquarters in New York and Yeah. And, and so was Huntley and Brinkley and whoever else was on, uh, a, b, C at the time.
Mm-hmm. But Right. It was, you didn't have the subterfuge of I am in the Congo.
And, and you know, commenting on, on what's going on in the US or, or what have you. Those are simpler times. So, so let's bring back World Book, social media site.
What do you say? I know, I, I see, I see nobody, Only the oldest. I see a niche for World Book book here.
You know, I really didn't. Well, You know what? I could have AI draw me up on in no time.
I don't know. Those transparencies were the bomb though, man. They were, they were.
I I used to trace over them from my books reports. Yeah, they too. Me too.
Reem is looking at us like, what are these old people talking about? He's like, what the hell are you talking about? Yeah.
It's another, but the rest of us remember. Yeah. Okay.
Alright. Hey, hey, let's take a break here. We are coming at you from Boca.
I'm at least in Boca Raton, Florida. You can count on it. This is Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back in. By the time you're watching this, Alan and I will be in Las Vegas for AWS Reinvent conference. And we've already been a steady drumbeat of news and issues coming up before the conference, including AWS is now using AI tools to accelerate migrations to their cloud platform.
And we'll also see things like, well, Sumo Logic will be talking about how they're gonna reinvent their entire approach to AI using AI agents for security and observability and collecting telemetry data. And there's just gonna be a ton of stuff. AWS will also be, of course, highlighting their Kiro AI agent tool that they are proud of the fact that it is, uh, specification driven.
So if you've watched any of our previous shows, you know what that's all about. But it's a more reliable way of creating AI Coach, shall we say. And they're gonna be touting the fact that, well, you know what, we can get better AI coach, but there's just gonna be a lot going on.
Alan, I know we've been in this show in the past, and you're gonna be doing some videos while we're out there. But, um, what's your take on the state of AWS Well, yes, we we're gonna be doing more than some videos, Mike. We're really booked up for the whole week there.
Um, looking forward to it. I, you know, the state of AWS is, they're still the 800 pound gorilla in the cloud hyperscaler space, right? Google, Microsoft has had, have had some good runs.
Oracle Clouds had some great, well, they have one big customer that accounts for two thirds of their business, but nevertheless, they, they, you know, they have some money on the books. Um, but AWS is still the undisputed king and heavyweight champion. I think we're gonna see a lot of announcements.
It's funny, I've got new next door neighbors. Their son came in for Thanksgiving, turns out he works for AWS and their generative of AI team, and he's presenting at Reinvent, so I'm gonna hook up with him out there. Um, but the beauty of reinvent is it's not just AWS you come for AWS but you get everything else because literally the entire ecosystem is on display there, you know, flashing their wares.
And, um, so it's a great time to hear stories. I, I will tell you that our tech drunk TV coverage, which we will be streaming live Tuesday, Wednesday, and Thursday at, uh, from Vegas, uh, is sponsored this year by Susa, who has a huge rollout of, of, uh, related announcements and technologies around AWS and of course AI and the Edge and everything else, red Hat is, is very, very much engaged there. And so you think about that, these are not necessarily companies that you think of as, you know, big AWS components because you need to go, you know, to run, uh, OpenShift, yes, it's available in the AWS marketplace, but it's probably not the default.
Same thing with suse and rancher and those kinds of things. So, but just like Mike in the last year or two, look, the big story's gonna be ai. Mm-hmm.
I think the big story this time will be AG agentic ai, where last year was more generative, but AWS you know, from investing in anthropic to, to doing bedrock and kiro have, have not shied away from being an, uh, an AI friendly hyperscaler. Mm-hmm. They don't have necessarily Google's position in ai.
Right. Google has that vertical integration that's hard to beat. And they, they are, you know, their stocks flying.
They're a $4 trillion company now. And and I think people are recognizing that they, they have a, you know, a catbird seed here coming around the, the bend in the AI race. They don't have Microsoft's GitHub and, and all that comes with that and their open ai, uh, relationship.
But they, they seem to be much more open to everybody's ai, right? If you've got some AI stuff, we'll run it on AWS and I think that's what we're going to hear a lot about. I think there's one shadow that will show up in Las Vegas, and it's this whole notion of sovereign clouds.
And folks are kind of think talking more about moving workloads from one cloud, maybe into an on-premise environment or something that they have more control over. It certainly is a bigger conversation in Europe these days. And maybe our friends in Canada as well.
Well, Wella, my Mike, Mike Susa has a whole it sovereign cloud right. Division now. And, And even though AWS these days is talking about using AI to migrate existing workloads into their cloud, AI will go the other way.
Right? These things mm-hmm. Will enable people to take workloads more easily out of an AWS cloud and move them to either another cloud or something else.
But Garima, what's your take on what's going on here? I agree with you, Mike, and you know, I'll connect the dots here. So sometime back, we covered the story with, uh, OpenAI and AWS partnership, right?
So we had speculations at that time that which regions will be benefited out of this, uh, partnership. We saw that Silicon Valley might be like, uh, the key contenders for it, right? And then the uc that they have launched this tool AI capability, AWS capability tool, which is basically providing you insights into regional capabilities, uh, of services, uh, which a w has, and also forward thinking roadmaps.
So, I mean, pros are obvious to understand, but I will, uh, talk about a little bit of the cons, like how the AWS ecosystem is, uh, you know, developing and ensuring that, you know, they probably move the workloads in the right regions, you know, for the sake of sanity. I would say that, you know, they have not integrated it with the live, uh, like the console management system, but they are putting it as a dashboard. So the AWS capability tool will give you more possibilities to see through what kind of regions are more proactive forward thinking, what kind of pre-deployment integrations you could do, and also talk about the cost and risk, right?
So it's kind of, you know, I'm yet to kind of see if this prediction of mine or this speculation of mine is, uh, to the point or not. But I think this is driving workloads in a, in a pragmatic way to some specific regions for some specific capabilities. Of course, this, uh, tool, which we have talked about, uh, the AWS capability tool, they don't advocate, they just say that it's a planning tool, right?
But you can influence the planning, right? So I, I would see that, you know, that can be one of the possibilities. And then, uh, like capabilities, like Kiro and all these other things, I think there will be some announcement made, uh, kiro for uh, sure, because it's of interest, it's an id and they, they compete in a large scale kind of ID ecosystem.
So it would be interesting to see what they're doing there. You wanna know something else? I'm looking forward to what's Google's counter programming, right?
The last couple years at AWS, Google's always done something on site or around site there to say, Hey, we're here Last year, I think they took over the outside of the sphere and made it into the Google colors. Um, so it'll be interesting to see what, what Google goes there. But look, it's, you know, it's 60,000 people.
It takes up a good part of the strip. I'm, I'm looking forward to it. You know, what I'm looking forward to, I'm looking forward to discovering that X thinks that Techstrong is now moved to Las Vegas.
'cause we'll be tweeting Out while y'all are there. And I'm also looking forward for some kind of a cloud diagnostic, uh, days, uh, you know, looking ahead of like how we compare AWS Google and other platforms like, or Oracle and so, and Clouds, uh, for example, like Canada has their own coherent, uh, but I mean, from cost constraint perspective, it'll be very interesting discussions, uh, moving on. Right?
Well, I'm with you. I, I am, it's been a long time coming, but I feel like rational conversations are finally being had about where workloads go and AWS is fine, and it's a good choice, but it's not the only choice. And I think people are getting smarter about maybe not locking themselves into all those proprietary APIs, and they're figuring out, well, let's let the workload decide where they, You know, they, they make the exact, you know, it's funny you say that.
They make the exact opposite argument when they talk about, and we've done a series of webinars here on, uh, with AWS partners on modernization and transformation and basically moving off of VMware mm-hmm. And an on-prem level. 'cause you're locked in to their pricing and their licensing and everything, where AWS actually offers you choices.
Right? And, and so, you know, some people don't view it as a lockin, Right? Well, what they're really saying is give up the VMware proprietary APIs in favor of our proprietary, The old boss.
That Was a Takeaway from the webinar that I, well, we voted Fool Again. It's a good place to end today's show. I think it The new bus, the old bus guys have a great, have a great, uh, Monday we will be continuing, I think we have one more show before we'll be live doing Gangs live in Vegas at, uh, Textron for Strong Gang.
We'll probably do our first show there Tuesday. So, uh, hopefully then. Until then, though, thank you for joining us as always here on the gang, Terry Garima, Mike John, thank you for of course, lending your thoughts and into this.
Thank you for watching. We've got a full text, drunk TV following, but for now, I'm Alan Shimmel and we're out. Hey, everyone, welcome back here to Text Drunk tv.
So I, I want to introduce you all to Guy, a Razzi, uh, guy is someone who has deep expertise in the security cyberspace, as we call it now. I still call it security, but, uh, in the cyberspace guy is also the co-founder and CEO of a, of a cybersecurity startup that's in stealth right now. So we won't necessarily be talking about that company.
We're gonna talk more with Guy and around, uh, a well, what else do we talk about? AI and adversaries in ai, AI and security? Hey guy, welcome to Text on tv.
It's nice to meet you and it's nice to have you on here. Thank you for having me. Appreciate It.
Pleasure. So, guy, why don't we start off maybe kinda giving our audience a sense of who you are, where you've been, what you do, what you've done, right. Establishing that.
Yeah. So if you wouldn't mind share with us. Sure.
Um, first of all, as you said, I'm Guy Razzi. I was born and raised in Israel, started off security very early on in my life, even before I had something that's called career. Um, I guess I was very interested, uh, in security and the way you can bypass security boundaries, uh, of the software.
So I was doing some cybersecurity, let's say, stuff in the inte, like in the intelligence for the intelligence in the Army. Um, and basically my first official role was a ciso. I was kind of high level, uh, doing audits and running penetration test reports, but then I wanted to go even more hands-on, uh, because I wanted to go back and, and be on the offensive side.
Uh, kind of like in between the blue team and the red team. Mm-hmm. So I joined Banca Pauline.
I was leading the application security deal. I was also a few months in doing some research. And then I spent the next seven years in Microsoft.
I started off as a security researcher for Microsoft Defender, EDL, where I was basically, uh, founded the ransomware detection vertical. Um, when I go to Microsoft, they only detected the issues on a single machine. And I had some crazy vision on how to connect the machines, uh, in, in an enterprise.
So you can detect network infections and stop ransomware from compromising with entire network. And then, uh, I was a vulnerability researcher for Azure. And in my last, uh, year at Microsoft, right before I left my to do the startup, I was, uh, uh, at M-S-R-C-M, SRC is basically the Microsoft Response Center, uh, was in a security research team called mitigations and Vulnerabilities.
We basically got like all the reports from, uh, externally, uh, externally search sales, like all the vulnerability disclosure, back bounty program, anything that basically comes to Microsoft and get out of Microsoft, uh, in, in terms of security. Very interesting. A lot of issues, but good issues as well.
And you have to come up with brilliant ideas on how to mitigate them. And I also spent two years in Palo Alto Networks, uh, in between really? So you went Microsoft, Palo Alto and then back to Microsoft?
Yeah. Interesting, interesting. Of course, Palo Alto just bought last week.
They announced, uh, K Chronosphere Yeah. With Three and a half billion dollars and for, uh, observability. Yeah.
But Guy, you know, you know, there's this old, they call it an Irish proverb that you live in interesting times. We certainly are living in inst interesting times. Not to say that security wasn't always an interesting place, let's say, right?
But with the advent of ai, the, the mission, well, attack surfaces have expanded. The mission has changed in many ways. You know, what they say, God gives and takes away.
God gives one thing, it takes away another with ai, it, it could truly be a gift to security in, in helping us to do security better. But it's also a gift to our adversaries, right? Who are also not stupid and are very well organized and well financed.
And they understand. And so, you know, at the, it, it's both a weapon and a shield, if you will. It could be used as, as a, as a offensive and defensive.
Um, and, and the thing is, is it's fairly new, right? When all those years ago when you were in, I, I'm gonna assume it was 8,200 or, you know, within the IDF, they weren't really, this wasn't really something you guys were using back then, or, and if you were, don't say you were, but, um, you know, it, it's in in many ways changed the game. It did.
Talk to us how it's changed the game and kinda what's you, what, when you look at this landscape now, what do you see and what do you think? Well, like companies produce code in an insane way right now, right? It gets a more business.
Um, they can hire less people and they can just ship features and products. It's very appealing. Um, but on the other hand, even be, even before AI was introduced, product security teams and application security teams couldn't even handle the, the, the burden, right?
They had like yeah, had backlog, a huge backlog of issues that they had to fix and they were trying to chase after developers to fix it. And nothing was really moving the needle. When AI was uh, introduced, then there were many startups and many companies that just used AI to deal with that backlog.
But developers still don't want to fix those issues because in most cases there are either false positive or it's might, it might take them too long to fix it. And it's not part of their KPI, like, no one measures them on like, how well are you doing security in our company, right? They measure them by how quick can you ship it and if the feature is actually working well.
And I think that probably the biggest issue is when, when ai uh, when AI is being leveraged all across big enterprises, it copied be different antipas. So there is some code that is being used. Then agents might assume that this code is already valid and it's uh, uh, like it can reuse it.
And then it's, you reuse it in 50, a hundred different places and basically creates something that might be a more of like a systematic issue without anyone understanding. Now the product security team or the application security team are the same size, right? They never grow and they never grow more than, uh, the developers.
And on the other hand, they're still using the same traditional tools that they had in the last decade. Maybe they are, some of them are branded with ai, but they have the same approach, the same architecture. And in, in my opinion, it's a double-edged sword because no one know right now what are the actual vulnerabilities that are laying in their software.
And, and, and, and that's probably the biggest danger. They're trying to kinda walk in a land of minds without realizing where should they step. Now it's either it's a false positive or they're either getting compromised, but they need to decide like, what is the next thing, next thing I need to tackle?
And in many cases, our biggest advantage as human is to use humans, uh, to find human issues or agent issues. So you can see things like, especially in Microsoft, it was, um, it was something that went really well. We use external researchers to help us validate features and products that are already in production in case we, we missed something in the threat modeling or the scan maybe didn't pick up, uh, a, a specific issue.
And then we kind of under trying to understand if it's part of a biggest, a bigger issue if it's a systematic issue. Because AI cannot say if an AI is wrong, right? You need some human to label that specific issue and say, this is wrong.
This is right. At the end of the day, it's like, it's statistics, right? This is how AI works.
If you wouldn't tell him, uh, or you wouldn't guide it in a way that fits you. And again, enterprise are different. Everyone mitigate different issues in a different way.
It's gonna be very, very hard to uh, overcome these issues. And I think this is probably the biggest way that, uh, I see as the double-edged sword because we're still using the technology, but we have no idea how to defend against it. And adversaries are, you know, they're just out there using the same thing.
But, you know, di I, I've been around a long time in this space and, and this and this, and it's not just insecurity. I think this is very common. When you dealing with an adversarial kind of thing, you, you tend to over, uh, you you give them more credit than they due.
Do you know what I mean? You, you think, boy, everything I do where the, where the ample we're the apple dumpling gang, we can't shoot straight and the other guys are marksman, right? They're fantastic shots.
Do you really think, I mean, look, AppSec has been always playing catch up for a long time. And, and I wanna say it's almost not their fault, but it is, right? Uh, we don't put the budget and resources necessary, but it always seems we're playing catch up there.
Do you really think though, that the adversaries are this sharp on ai but they're not going through sort of the same growing pains learning cycles that we are? They do, but their KPI is pretty straightforward. Uh, it's either they compromise or they don't.
Right now they might compromise, um, a year ago, and you might know in five years from now, if an attack is executed properly, you would never know it existed maybe in, in the next few heels or in the long term, like in the long future. Got it. And that is part of it too, right?
That these guys play the long game where, I mean, quite frankly, look, most budgets for AppSec enterprise companies are, you know, quarter to quarter. You know, and if you didn't get attacked this quarter, that means that nothing happened this quarter, would it very well might have something happened, but you won't see it till next year. So it's a different, it's almost like you're playing by different rules, by different time parameters, if you will.
Um, so I, but I guess this begs the question though, guy, of what's a poor company to do? What's a poor enterprise? What's a security team to do?
What can we, you know, it's, it's reminds me of the old story about you take like a, a, a blind person and put them in a round room and tell 'em to find the corners. You know what I mean? It's not fair.
So what, what can we do here as we kind of fumble in the dark to prevent these kinds of things from taking place Just to make sure that we're aligning on prioritization. Uh, the most volatile and dangerous, uh, indicator that we have in the product security realm is probably there is some idea, some insight, some report that claims that they can compromise your company. Okay?
Now researchers, they like trophies. I also like trophies. What we all do now, sometimes we might share it with a friend, we might share it with the social media and adversaries are just listening for that.
Now, you might fix this specific issue, uh, from that specific feature, but it might, if it exists in other features, they take this specific issue and try to expand it into attacking all your features and other products with the same technique. Now, you might think that you found everything and, and you might not. And that's the race.
Like how long, how fast can you detect it? And, and especially when it's already like a public insight or, or something that is already out there, you need to make sure that you are prioritizing this insight out of, because that's exactly what adversaries see, right? They're not assuming that they might breach you through this technique.
They know that someone managed to get into your systems using some approach. And if this approach might cost them, I dunno, $10 to attack all your infrastructure right now, it's probably gonna be more what, more than just guessing. Maybe they're using this tech stack, maybe they're using this specific library in this specific way.
Um, they don't need to assume they know something will happened and then they take that, by the way, same with ai. They take this specific insight and they try to use, like, they try to leverage it as much as possible. Absolutely.
Absolutely. Um, so again, what, what can we do though? Like what steps do you think we could take?
Yeah. Anticipating this? So I, I think that, um, any insights that basically, uh, compromise your systems, something like any, anything like higher critical that has a proof.
So someone already shown you either from your vulnerability disclosure, your pen test reports, even if like, I dunno, like an internal engineer or developer found something that could be significant, you need to prioritize this over adult things, especially when it's like a written insight. Take this specific report and see if you can find this issue, um, as a bigger, uh, systematic issue and try to carry re remediation for that specific thing. Then probably the next thing would make sure that you are not repeating on the same issues, right?
Because you might, you might remediate it, but the organization is still developing in the same way. Maybe one team is aware of it, but the other one isn't. Now it's like a whack-a-mole game because there is no way right now to automate this unless the product security teams can be like one-to-one, to every feature group or every department development.
And I think that it would just be tried, try to use AI as, as, as, as much as possible to make sure that these things are not happening over and over. It could be implementing local rules in your cursor. It could be creating some designated prompts for copilot to pull, like to create a, uh, uh, pull request reviews to your changes that you're about to push to production.
But there are many ways and, and it really depends on what is the specific issue, but I guess this is where I would start from. I love it. Yeah, I agree with you.
Let me ask you philosophically That, You know, I always say we're still kind of, almost at the beginning of the beginning when it comes to using AI and how we're going to integrate it not just in insecurity, but in, in our daily lives, right? And, you know, in our jobs across the board, do you think this is a problem that gets worse before it gets better? So in other words, is there gonna be a gap between solutions versus, unfortunately the, the adversaries, you know, doing these bad things and like we talked about before, it may be years before we realize these time bombs have been planted already.
Interesting. Yeah, I think there'll always be gap. Like as long as the technology enables you to do something, it goes either way.
It has to go either way. Uh, the the strange and, and the cool fact about adversaries that they're always instilled, they don't need to expose anything. No one knows like what they're basically doing.
Some researchers and some analysts would assume what they're doing right now, but they can do many things and you never know what they're gonna do next. So they're Literally assuming and you know what happens. Yeah.
When you assume, right? That's, it's, it's a guess. Educated guess maybe, but a guess nevertheless.
Yeah. And, and maybe there is another thing that I would add to your previous question around remediation is that there are a lot of companies that don't think defense in depth. So they would only fix something that is publicly available and only like, you can only exploit it from the outside, but in some cases there's common practices that you have to apply even internally, because you might have like a malicious user, or maybe you could have, uh, another vulnerability that that might expose you to the internal networks.
Uh, and then you can use this type of vulnerability to access something. You would assume that it's not public, right? But if this, I dunno, resource opens up all your financials, uh, and, and opens a, a gate that you don't think that there is open only because you didn't implement different mitigations around it, it's more than lacking.
Right? And, and by the way, these things are real, like s srf and, um, are, are extremely common. I think that they even went to the first in oas, like in 2025, they went to the top, like the highly ranked attack, a part of broken access control.
So it's not something that, you know, I assume, like we already see that that's what they're using in order to bypass boundaries from the outside. Like you might say, yeah, this is internal. Like this is my internal let, nothing, nothing is gonna reach hills.
So why do I need to add those litigations or add this defense in depth? And then you are getting a very straight and simple vulnerability that enables them to amplify their attack by a thousand x and both in impact and, and in in speed. Understood.
Agreed guy, we're, we're about outta time. No pressure. But as I said in the beginning, you are co-founder CEO at a stealth cybersecurity startup timeframe on when we might find out more.
Probably, probably very soon. You'll be, yeah, you'll be the first person that I'll keep updated. Don't worry, I'm gonna hold you to that.
Okay, man, Don't worry. Alright. Hey guy, thanks for coming here on text, on TV and talking to us about, you know, it's almost, I I call it like a shadow war going on right now, right?
We're not quite sure, you know, what capabilities or what and who is who, but nevertheless, the, the, the, the sparring, the, the dance, if you will, has started. And, uh, it's going be something that we, we need to watch closer and closer. So thanks for coming on and talking to us.
Good luck. And as I, you, you said it as soon as you launch, you gotta come back on. Will Do.
Thank you. I appreciate it. Alrighty.
Di Razzi, co-founder, CEO of a, a, uh, stealth security startup. We'll be talking about soon, but really here talking just more as an expert around the challenge of AI and security and AppSec and so forth. You're watching Textron Gang, we're gonna take a break.
We'll be back in a minute. Hey everyone, it's Alan Shimo. Welcome to Cube Con North America, 2025, or some people call it Cloud Native con, or as I called it, way too long a line to get in here today.
They gotta do a better job. During COVID when they were checking vaccines, it wasn't this long a line. There was no reason for it.
I waited 45 minutes to get in here today, so I don't know if it's an a TL thing or an a TL cloud native thing, but we expect better anyway. Now we started early, so I had some time to kill with that. Let me introduce you to our first guest here from the show floor at CubeCon.
Andy Suman. Andy, you may, if you, if you're a fan of tech strong learning events and webinars, you might have seen Andy. He's done more than a few with us.
Um, Andy is with Fairwinds, and don't worry if you don't know Fairwinds, we're going to make sure you know him after this. Andy, welcome to our coverage. Thanks for being our first guest.
Thanks for having Me. You wait online this morning? I did.
I'm glad I made it here in time for the Interview. Yeah, me too. I was not sure I was gonna make it.
It was a little crazy. Anyway, Andy. Yeah, I said you're with, uh, Fairwinds, but tell us a little bit of kind of what your role at Fairwinds is and how you came to Yeah.
To that position. Yeah, Definitely. So I, I've been a long time infrastructure guy.
I've worked in infrastructures, worked on infrastructure basically since I was a kid. And, um, about nine years ago at my previous company, I got into Kubernetes, was really excited about it. It was very early days.
And then I joined, at the time, reactive ops was the name of the company. What Was the Name? Reactive Ops, uh, react to V after op Reactive Manifesto, which many People know about.
Alright. Uh, a Little trivia right there. Yeah.
Yeah. So we, we built and maintained Kubernetes infrastructure for other companies, and I've been doing that ever since, uh, for the last seven and a half years. Uh, working with Fairwinds.
It's part of delivering services is an AWS partner as well. Yes, we are, uh, an AWS advanced tier partner at the moment. Um, and we've been working closely with them for many years the entire time, but over the last couple years, we've really strengthened that partnership.
The majority of our customers are on AWS uh, we are, we also operate across all three clouds, but AWS is definitely the lion's share of that and Very cool. Yeah. So, you know, I know a little bit about Fair Ones, but let's assume the audience out here doesn't, you guys, I mean, number one, Kubernetes experts first and foremost, right?
Some of the Number one thing. Yeah. Yeah, I mean that's, I I've listened in on a lot of the webinars.
As I mentioned, the, the, the knowledge and skill gap for Kubernetes infrastructure deployments is, is second to none. Um, but as you said, you work with all the different cloud environments. You work with a law, a big range of software, including a lot of open source tools.
Yes. Yeah. We actually have several of our own that are very popular.
Goldilocks is something you guys have have, and it's open source. Anyone, you don't have to be a, a Fairwinds customer to use Goldilocks. And, and that's yet another interesting thing about fairwinds, right?
As you guys are developing the tools that you use for your customer engagements, you actually open source them so then anyone could use them, which is pretty cool. Yeah. Yeah.
We really enjoy, you know, sharing the knowledge that we have back with the community, not just in the form of services, but also in the form of open source. Uh, Another, I love that One of our major projects is, um, Pluto. So if anybody went, lived through the Kubernetes one 16 upgrade and all of those APIs got removed, uh, at the time it was very hard to tell if you were still using those APIs.
And so we wrote Pluto to help with that. And I think today it still helps a little bit. It's not as big of a problem as it used to be, but APIs get deprecated and removed all the time.
It doesn't change. So I, I, I would embed it against it. Not, well, I wouldn't bet against it not being a problem At some point, I'm sure in the Future, again, with APIs and AI and MCO server.
What about MCO servers? What are you doing with them? MCP servers, MCP, excuse Me.
Yeah. Um, not a ton at the moment. We do have an MCP server kind of in the works for our product that we use to do.
Of course you do. Everyone has What the cost, I mean, yeah, it's kind of table stakes at this point. Yeah.
So our, uh, software product, Fairwinds Insights, which all of our customers use to get insight about their, their, uh, clusters, and they'll be able to access that via MCP here in the, you know, within the next year or So. Of course, MCO came before MCP and I guess soon you'll have M-C-Q-R-R, but, Um, Uh, Andy, for people who want to get more information on Fairwinds, where do they go? com, uh, go to our GitHub where all of our open source lives, that's Fairwinds ops is the company on GitHub.
Uh, those are the two primary ways to get ahold of us. We all have, so have an open source Slack community, uh, that you can join. It's on any one of the read mes on our projects.
Excellent. Alright. If you don't mind, I want to kind of pivot a little bit and talk about recent, uh, development, recent announcement with you guys partnering with AWS in the, you know, in the platform engineering space, right?
Yeah. You guys are, uh, partnering with AWS on a new IDP offering, internal development platform offering. Yep.
Or internal developer platform offering. Tell us about it. Yeah, so we've always managed the base level of infrastructure, but our customers often need something above that.
So it's always been, it's your job to deploy your applications and do your CICD and these days, um, I think there's a need really for, you know, platforms internally for platform teams to be able to deliver clusters and deployments and standard pa happy paths to their developers. And so AWS has built, uh, sort of a blueprint for this with a whole bunch of different open source projects. So we've got Argo workflows, Argo cd, backstage, cross plane, all put together in this really nice package.
And so what we are starting to do is we are offering this as a service offering to our customers. So we'll come in, set that up, build the, you know, kind of control plane cluster for you, give you all the patterns that you need, help you deploy your first application through the platform, and then hand that off to you. Or we can manage it long term with our standard managed services, but really it's about zero to 60 on a platform in a very short amount of time.
And so, you know, there's a few different flavors of backstage. There's the open source backstage, and then we have, you know, uh, I think Spotify still has, They have One, they productized it was there, they know they pioneered it. I'm not, I'm not banging for it Or anything.
Oh, no, absolutely. But, um, how, how does this offering stack up to some of the commercial backstage offerings? Um, I'm not entirely familiar with all of them.
You know, there are quite a, there's a lot a few out there, right? There's a lot. Um, but really this is truly based on the open source.
They're also working closely with the, uh, canoe effort uhhuh, um, to really build this fully open source. And so I think as with all open source, what you'll get is ultimate configurability. You'll be able to do anything with it you want, but it will be a little bit more complex than using an off the shelf solution.
Yeah. So it really, It's not, it's not as pretty maybe. Yeah.
Yeah. And that's where we come in. We're gonna come in and help you make it as pretty.
So I think once we are done delivering this open source to you, I think it'll stack up really well against those paid offerings, really. Yeah. UI and everything else.
Absolutely. Yep. Very cool.
And now that's an offering you're doing with AWS Yes. As an AWS partner, we're working with them to deliver that. They're the ones who are they picking, like besides Backstage?
You mentioned that some GI ops and some other stuff, they're the ones picking that, or does the customer get to put anything they want in there? So they've picked kind of the core pieces of it, and then there are certain parts of it that the customer will be able to pick and choose and swap in and out, because there's an entire, um, off solution built into it. So at the moment, the open source uses key cloak, but obviously not everybody's gonna use Key cloak for SSO.
So there'll be plug and play options for SSO for your code repositories. So we'll be able to do GitLab or GitHub or gitt or any of the other, you know, kind of flavors of that. Very cool.
So it'll be a little bit of both. And then because they have you doing their service, if they want to add other things that maybe even aren't in the core, right? Yeah.
We can add things on, we can help to customize it. You know, everything we do is very, uh, highly tailored to our customers. Right, right.
You know, obviously for operational reasons, we try to keep them similar. We use best practices everywhere, right? It's question scalability.
Sure. We are a very high touch service, and we really wanna make sure our customers get the, the platform that they need for them that fits them, which is why I think a lot of off the shelf platforms don't work because they're not custom tailored, but then building your own takes so much time. com days, you probably weren't there.
I wasn't working. No, no, I, I realized that when I was talking to someone, the other, they said, yeah, I was in high school. com days, I helped start a company that was what we call an A SP application Service provider and back, it was before this cloud, before this hypervisor, all that stuff.
Yeah. And, uh, we were offering Lotus Notes, which you probably have heard. I, I've heard of what?
Yes. Lotus Notes, PeopleSoft, Oracle, bunch of like major enterprise Onyx or CRM and stuff, major enterprise, uh, um, applications. Right.
And the rule of thumb we learned then it was in 80 20. No one just takes some app like that and just plugs it in and runs. There's always about 20% that needs to be, our mics are good for that.
There's always about 20 cent, 20% of customization that needs to be done. I don't think that's changed. I don't think so either.
In fact, I think the percentage might be higher when you get into open Source. Really. Yeah, maybe with open source.
'cause it is, you may not have UIs. And also you just have a lot more, uh, options. You know, if you want it to be green on Mondays and blue on Tuesdays with open source, you could do that.
Yep. Excellent. Andy, I don't know if we mentioned the website for Fairwinds.
Did we? Uh, I'm not sure we did. com.
It's very simple. Very simple. Yep.
Guys, so take it from me here. Shimmy. com.
Andy, it's great to see you in person after you, after always seeing you on those little webinar screens. Same thing. We're gonna take a break.
We're live here at Kon Cloud Native Con, we'll be back. We've got a full opening day here, so stay tuned. Hey guys, thanks for throwing.
We're here with Raj Sethi, who's senior vice president and go to market leader for software development lifecycle for Global Logic. And we're talking about, well, all this noise about how AI is gonna eliminate the need for junior developers. It's a hot debate, but I don't know.
It's a lot of things about AI these days may or may not be true. Raj, welcome to the show. Good to be here, Mike.
We're looking forward to having this chat with you, talking about a very hot topic. So what's your code? We hear it's hard for the kids come outta college to get a job.
And we're also hearing a lot about how senior developers are now automating a lot of the tasks they might have assigned once to junior developers. And this is resulting in maybe not as many junior developers being hired. And certainly there's been a lot of layoffs lately, but I'm not sure those are because of AI or not.
But Raj, what's your take on what's going on here? Well, I think what is, this has to do with how the industry sort of, uh, you know, expanded. Uh, we had a moment in time where there were, you know, fairly large amount of organizations, hired a lot of people on staff, assuming there's gonna be business coming up.
And I think a lot of those forecasts were changed because of gene ai and the need for that. And that's one of the reasons why we see some of these layoffs that we see in the industry. However, I think that when you look at the larger trend, I, it is an area of flux.
Businesses want to truly understand how Genai adds to that productivity. There are lots of claims, but, uh, if you look into some of this claims, they're all added up with an additional step where they'll say, oh, 60 and 70% of our lines of code is written by Genai. But, uh, we still need people to look at this code, review it, ensure that they're right, or they would say, we still need to proc the system, which is another form of programming, um, to, to get these lines of code.
Uh, and you know, one may argue, well, there's, it's a one time job, or it's a constant tweaking. That's a separate issue. The key part though is the systems are not there where they're gonna produce massive amounts of lines of code without any human intervention.
So that being said, um, I think that the junior developers in a far better position, sometimes I'll look at, because they have an option to adapt. Um, senior developers are more sort of set in their ways of thinking and doing things. So, you know, from a geni perspective, all organizations wanna move there.
So I do see that the opportunity for junior developers is still there. However, it looks very different. It's not about writing boilerplate code, it's not about, uh, you know, writing test cases.
Those are low hanging fruit that gene AI is gonna do far better job at. But I still think that there is the process of validating, reviewing, being, doing critical analysis that's still junior developers can do. Uh, it's really about building that muscle within yourself.
So coming out of the school, think more around critical thinking, how systems are developed, rather than doing the traditional ways of software coding. It's really about not competing with ai, but how would you use AI more effectively? How does a junior developer get that expertise?
If we're not hiring junior developers in the first place, who will be the senior developers tomorrow? And where will we get that cognitive capability? So it's, it's interesting, you know, how things have changed back.
You know, when I came into the workforce in the nineties, uh, uh, it was all about getting this first job to do things. There was, internet was just coming around, uh, you know, email was just coming around. So obviously you needed access to an infrastructure or an enterprise to even gain experience.
That has changed. I mean, if you wanna learn today, there's ton of information on YouTube. There are so many courses that you could take online.
You could literally build your own portfolio today and not have to wait for that first job to show up. Right? Uh, that to me is a, a game changer today because you don't need to give your just a resume.
You actually show your work to people. And I think often, um, you know, young people don't focus on that. They all, they too, they index over index on that first opportunity.
That first opportunity will certainly come their way if they're prepared. But the question is, what's that preparation? It's not necessarily just a degree from a college.
Um, it, you, you could demonstrate your work, uh, far more effectively than you could do before. There are some critics of the junior developers who are coming outta college who are maybe too attached to AI and not doing enough critical thinking of the code that's being generated, because some of that code is, shall we say, overly verbose and maybe even doesn't make a whole lot of sense and certainly doesn't run particularly efficiently. So, um, are we in danger of kind of going down a path here that's gonna lead to, I don't know, massive amounts of technical debt that's unsustainable?
I, I don't think the issue is that I just need a engineer to drive ai. I think that, like I said, you need to have critical thinking. You should know algorithms.
You should be able to review code faster, looking at the code. You, I mean, there are times when I, you could look at the code and say, well, this thing meets two loops. I don't see the second loop.
There's a problem in this code. Um, so proofreading and understanding what is written there is, is a, is is a paramount, uh, skill that you would still need. I don't think that is gone.
And to the extent where people are thinking about white coding, yeah, prototyping is fine. You could do white coding there. I don't think white coating has been very successful in the large enterprise.
And I'll give you an example. Uh, rep being one of the, uh, providers of it, they, they went, like, they were in their, uh, upper, you know, maybe in 2020 third, uh, million dollar revenue. And then when they started focusing on the business and business community, uh, their a RR went through the roof five times.
Um, and I'm saying that it's good to prototype, but these are not software tools where you can just get away with white coding. Um, I think that the junior developers that we're talking about need to have proper formal training in software need to understand how things work because although a lot of times when I see people pushing the boundary of what gen AI is supposed to, you know, there's a, there's an idea that somehow you can reason anything as opposed to reason few things. Having that ability to figure out what's the right problem to solve, that's critical thinking.
Um, that's not gonna come if you, if you haven't gone through formal training in schools or, or haven't gone through any formal learning. I mean, I'm not necessarily have to go to school. There's ton of material, right?
Which can prep you off for that world. Do we need to revisit how we teach all these skills in school? I have, I feel like sometimes maybe, uh, the kids who are coming out are not as well versed in the fundamentals and they're maybe too dependent upon ai and that's probably not a good thing.
And maybe that's the fault of the way they were taught. I do agree with you. There's a fair bit of that has to, that has to happen.
Um, but I do think that a lot of curriculum is getting influenced with, uh, with, you know, how some of the material that's available online through several organizations that are offering this. And, uh, I would generally say that that is a, would be a good approach. But I do think that what needs to be inculcated is that learning doesn't stop at school, in my opinion.
You decline STAs once you leave school. So learning has to be a continual process. It's an investment one has to make.
Uh, if you stop at any point in time, well, it's downhill from there. But, uh, I think that junior developers should come with that mindset that they're coming at the top. It's just that they need to learn how to apply that knowledge.
And that could be something that they can invest during school. Like I said, if you build your own portfolio where you want to demonstrate your work, that's, that's a seeding ground for, for you to show your capability in the enterprise when you joined the workforce, how productive and how contributing you would be as an individual. I think the, the joy of being a software developer is that you are solving problems using code.
And I think a lot of people who do that today kind of have attached the actual writing of that code to their brain as part of the joy. And, but is that gonna be the case going forward? Or is it gonna be more about proofreading and reading the code to optimizing when it's created by a machine who probably won't get it perfect, but at the end of the day, we'll do it faster?
Well, I, I, I think it, it's two ways to look at it, right? It's really about abstraction. I mean, think about Lego blocks.
Uh, have they taken the joy of creating things? I mean, look, and the people of all ages use Lego blocks to put things together. Nobody's interested in how Lego blocks are made.
Um, but that abstraction of the block is the important part. And I think problem solving to a certain extent, works that way. We've developed these skills and capabilities depending on where the technology was.
I mean, we've been waiting for, uh, an opportunity where we could talk to a machine to do something faster for us. I think Gene has started unlocking that for us. So there is a significant, um, work that is involved in structuring your thinking.
So when you talk about systems, it's never about a point where you say, solve this problem for me. It is more to that today. Uh, and the software is not anywhere, uh, or the systems don't exist today where I could take a very high level problem and solve it at, like, for example, improve my, um, you know, uh, Campaign management, uh, or improve the efficacy of my marketing by 1%.
That's the problem. Business would pose, what does that translate back into the systems is a problem that Gen AI is not quite capable of doing that, but a human would be. Uh, you could use gen AI to make that faster, better, but that's the way you need to start thinking about that.
It's really not about coding. Uh, it's more about structured thinking and having that ability now to communicate. So I think it unlocks the opportunity to, for lots of folks, uh, to, to sort of participate in systems building rather than just the developers who knew how to code in a specific language or a set up languages.
So I think there's, there's more fun coming up. Speaking of fun, um, are we going to build more software faster or maybe we're just focused, uh, too narrowly and maybe we should be thinking more about maybe making the software we do build today higher quality and just better. I think it's all of that.
I think software is going nowhere, uh, because the interface between the machine and the human, uh, is, is will be bridged with technology one way or the other. I don't know at what point in time we build biological systems that are exactly the way we work as humans or, or, uh, organisms. But the key part is that the software is there to stay.
The question is whether there's gonna be packaged software, the, the one that we have known for the longest time, that where you buy and then you configure or customize it to suit your business needs. Or would there be a situation where you build software to your specification, you could talk to it. I, I think that that's where the trend is going to be.
Uh, or at least I predict. I I I, nobody has this crystal ball, but I think that there will be an opportunity for people to create software that meets their needs and that's secure and that's high quality. Um, and it's, it's not, or it's always end when it comes to quality and and security, right?
The key part is that do I need to deal with packaged software or do I get something the way I want it? I think that's where the market's gonna move you, you would wanna buy software the way you want to use it. Well, you talked about abstraction, so let's go down that path for a little bit.
'cause I might argue that, you know, we created Java and other programming languages to have a higher level of abstraction with the machine. But maybe as we go along here and we start talking to the machine to write code, well, we'll just write everything back in assembly. 'cause that's more efficient.
Yeah, I, I do agree with you. I think that these are intermediate languages. Um, you know, compilers were created because it was too hard to quote them in assembly.
Uh, I think that gen AI gets rid of some of this stuff and says, well, I can go straight to this or create some intermediate language, and that gets compiled down, but it's not relevant, whether it's Java or whether it's C The key aspect is can you define your system, um, you know, in a precise manner? Can you define the way you would want to test it? Those are the elements that will become material.
So spec is there to stay. I think that machines will get better so that you don't even need to define spec at that, the lowest level. But spec is the key part.
I mean, we still need to communicate with humans. So you wanna, we wanna get work done. We, we communicate with humans.
And I think that's the line of communication that that will needs to be established with a machine. So gen AI is suitable. Whether these intermediate languages are required, I don't know.
I think that, uh, they probably will lose favor over a period of time. They're going nowhere in the short term, for sure. Mm-hmm.
So ultimately, what's your best advice though, to kids coming outta college right now? What would you be telling them and what might you tell their parents? Oh, I, I, I think that, uh, they should be constantly learning.
Start experimenting right now. There's so much information. It's democratized today.
It's all over. Whether it's not just necessarily in developed countries. It is available to every human on this earth.
And, and the question really is how driven are you? And, and, and you know it, so it'll all depend on what drives you. If learning is something that you enjoy, this is the best time to live.
Um, and, and, and I think that you will, you will bear the fruits of your industry. Uh, if you are in that path of learning, you will get opportunities. And you know, I look at it from a very optimistic point of view that if ever in the human history, a technology got rid of the young, we would be doomed as a species.
Not happened, hasn't happened. And I don't think it will happen. I think the young will always adapt.
I, I think more about senior folks like myself and others, that what will happen to them? Will they work till they're in their seventies, eighties? I don't know.
That is, that's a question that I, I pondered out. I, i, I worry less about the young. But I do would say that focus on learning, focus on learning, focus on mathematics, focus on linguistics.
This is where the game is. Uh, science is, uh, and this, there's no better time to live today to learn about all these areas, cross-pollinate ideas, use gen AI as, as a communicator, as a friend that you could talk to. I'm not asking, suggesting getting social advice.
I'm talking about, uh, very specifically, um, you know, science-based information, engineering based information. These are, this is a great idea where you could crosspollinate ideas, take ideas from software industry or automotive industry, apply it to, um, you know, energy and vice versa. I mean, things that are now at your disposal, uh, weren't there.
I mean, you have a PhD friend sitting to you who is knowledgeable in any field you want. I don't think that has been an area we've had in the past. So young people, great time to live.
Don't worry about these short term stories about this thing. It'll come and go. I think it's a matter of few years here or there.
The industry is gonna settle down. All right, folks, you heard it here. The diploma is not an end.
It's a means to a larger end. And frankly, there's more interesting things to learn outside the classroom as there are in it. So maybe just enjoy what we do because there's always gonna be some great new innovation and some new awesome thing that nobody ever thought of.
It's all gonna start with somebody who did something with code. Hey Raj, thanks for being on the show. My, My pleasure.
Thank you. All right. And back to you guys at the studio.
Hey everyone. Welcome to Ingram Micro one. I'm Daniel Newman and we are here on the ground at the event as it's getting kicked off.
Very excited to have a couple of great conversations here at the event. Starting off, we're gonna talk a little bit about AI and so much more. I've got Jim s Jim, Dan, thank you.
Thank you for being here with us. Yeah. Well, you know, look, I love the opportunity to spend time with Ingram Micro.
You are one of those companies, like, I call it like a bellwether company. Yeah. You spend so much time with the implementers, with the integrators, you work with all of the vendors.
It gives so much visibility. Sometimes, you know, when you're spending too much time at one part of the stack mm-hmm. Too close to the customer, too close to the vendor, you don't see it.
You guys really spend that time right there in the middle, all of it. And so much of that's on display here. But is there anything, Jim, that we could talk about today that people would want to hear that's bigger than what's going on with ai?
I, I think AI is the topic. Uh, not, not just here, but I think everywhere. You can't escape it, whether it's in the news, in the general media, or even when we're talking about, uh, technology specific and specialization.
It is the story to your Point. Yeah, absolutely. Is.
And, and by the way, just the morning and my flight here, between the time I left my house and the time I got here to Washington, DC there was like over $65 billion worth of new AI deals announced. Um, that is how fast and furious this is happening. It, The, it's it, the investment is happening almost as fast as the rate of change, it seems like at this point.
Did you see that? Um, there was that graph out there that kinda talked about the internet versus ai, and it basically said that this AI pivot is seven times faster. I hadn't seen that, but it doesn't surprise me Yeah.
At all. Because a lot of people are trying to compare, well, is this another internet bubble? Mm-hmm.
You know, but the proliferation is happening so much quicker. Which brings me kind of a question I'd like you to dig in for me, Jen. Yeah.
Is AI is not like a monolith. It is not all one thing. Right.
You've got, you know, we've been doing, by the way, AI algorithms four or five decades, easily, easily. Um, you had generative AI come out three or four years ago in terms of at scale, right. Started to become made available in the last, uh, I don't know, 12 months.
Eight gen has been the trend line. Kind of, you know, talk a little bit about kind of what all this means and why it's such a big game changer. Yeah.
It, it's a, it's a great topic because these are all steps in the process. The evolution of how we're interacting with AI tech, AI technology and, and the benefits we get from it. I think generative was a great stepping stone for a lot of people, because everyone could use it in their everyday lives, right?
When you're at home sitting around, even something as simple as making me an image that looks like this and getting the result, and it really took hold. And if you think about design or even coating, right? Using that to accelerate that, I think a gentech is this big pivot that everyone's trying to wrap their arms around.
To your point where the model is shifting, where you have essentially an assistant that you're giving a set of objectives to, and it's gonna take autonomous actions to help you achieve those objectives. And so that interaction model is the first big change I think people are gonna encounter is this back and forth conversational, um, you know, dynamic. That's new.
The, the second if you think about it is the, you know, the architecture. And now we're moving from a single agent trying to do one thing to an orchestrated experience where you have a, an agent that is in charge of achieving your objective. Yep.
And then orchestrating purpose-driven agents to bring that together. And then the need, especially in agent, to have this fact checking or antagonistic check to make sure what's being brought back to you is actually gonna meet your objectives. So I think it, it's a big, big explosion in, in how the technology is built, but also how we interact with it.
It is, and we're seeing the same thing. And by the way, it's gone from like an age it to a platform. Mm-hmm.
Which is something I know you at Ingram are focused on as well, is you have the X vantage platform. Absolutely. Um, this is, you know, democratizing mm-hmm.
For many of your partners. I'd love to kind of hear a little bit about what your thought process is. Maybe start a little bit about what, what a X vantage is just for everyone out there, but then what are you building in terms of an agentic platform and how is that being, you know, consumed and how is that changing the user experience for all the Ingram, you know, ecosystem?
Absolutely. Uh, AI's been the heart of the platform since the very beginning. When you think about advantage, it really how it drives value for our partners, whether it's vendor or customer Yeah.
Is really in two parts. One is, as you know, you've been in this industry a long time. We, despite all the great technological innovation and the advancements we've had to run, the business has been highly manual.
Yep. Ray's taken a lot of manual effort inefficiency. So the first thing is how do we, how do we take those inefficiencies out of doing business for all of our partners to free up time.
Mm-hmm. And then the second part of the platform is giving curated experiences to reinvest that time in that help us all grow. 'cause we're spending historically more time running the business than growing it.
Yeah. So if you think about AI and how that's been integrated since the beginning in the platform, it's to help take the manual work or friction out. So for example, uh, integrations.
So having seamless integrations where you don't have to hire a team of 50 to try and plug your native applications into the platform, it's done using ai so you can come as you are. Yep. And then when you talk about reinvestment, insights, recommendations, you know, customized to our partners business that are based upon the objectives they're trying to achieve.
So it could be something as simple as an add-on or identifying brand new opportunities on an upcoming tech refresh that tie into specific software opportunities. So really harnessing the power of AI to help our, our customers go faster and achieve new levels of growth In a big part of your world, right? Is you are moving the equipment, you mean that's the scale.
Of course, you've also been sort of the pacesetter in many ways to how those companies you provide, uh, hardware and technology to mm-hmm. Build services. Mm-hmm.
Okay. So you've got kind of the transactional part of the business. It's always been something you've been great at, and people understand that very well, but part of the growth story has been adding more.
Yep. Right? Absolutely.
So how are you sort of thinking about that from the standpoint of how the Advantage platform, what it is, how it grows? Because I can see a ton of ways like age genically, the transactions platform has value, like mm-hmm. Everything from how it tracks to how it helps you understand what to consume.
A lot of the automations we talked about in the RPA era, like I'm starting to really come to life with age. Absolutely. But then you've got, it's, it's gotta be more than that though, right?
You've built this thing to be so much, you know, I'd love to hear a little more about how you're thinking about that. Absolutely. If you think about challenges for our partners, it's where are you going to invest for growth?
And it's a, it's a tough question because you're investing ahead of the return. Yeah. Could be a quarter, two quarters, three quarters a whole year.
And we're, we're really leveraging a agentic and AI to work with our partners is to how do you quickly and simply identify the areas of opportunity that convert to return fastest. So you think about the questions a, a, uh, partner may have of, if you think about the upcoming AI enabled refresh of laptops that people keep talking about, yeah, okay, we all talk about it, but we're partner. How can they quickly understand where their top 10 opportunities in that space with which customers, what's the best approach, what are they upsell, cross-sell opportunities associated with that, and turn those insights into actually opportunities to go pursue with a pitch that's, that's generated by framework, by ai.
That's the same as having in two, three years ago, having to hire five, six business development resources to go go through manual data to come up with those ideas. Yeah. And then now you can match those to programs and go to market in real time.
So I think it's, it's really transforming growth Yeah. In the Industry. It's really interesting.
I I was thinking about that. So if I'm breaking this down for everybody out there, right? It's, you have a lot of data, right?
And of course your customers mm-hmm. The ones that are buying from you, the MSPs, the channel partners, the implementers mm-hmm. Integrators, they have mountains of sort of, of data in, by the way, some of it's probably really well organized.
Mm-hmm. Some of it's probably not. Yeah.
Very True. Uh, structured, unstructured, some of it sits in emails and slack messages, and some of it sits in, you know, tables. Things that we've been great at doing analytics on Absolutely.
For a long time. This is part of what you're doing, right? It's building that exchange that you're giving that infrastructure and exchange of data mm-hmm.
To be able to do, um, integrations mm-hmm. To say, Hey, this is your customer profile. This is all the work they've been doing over whatever period of time.
This is all the equipment that they have deployed. And where here is a series of, and what you're saying, right, let me make sure, is that here are five different recommendations mm-hmm. Based on this customer of upsell, cross-sell, refresh.
Is that, is that kind of what this is building towards? Absolutely. And it, and it goes beyond that a little bit to bringing in the, the wider industry and market data, right?
So what are the overall macro trends? Where are the opportunities with those? Then to your point, how do you match that up with a personalized data and experience of a partner?
So it's applicable to them. Insights are great, but unless they're actionable for the partner partner, it's just information at the end of the day. And that's not what we're driving.
We're trying to work with them to drive outcomes. Yep. And you have faster and at a larger scale.
And the other part of this that's great with AG gentech is you may start off with a data set to your point, but then your experience interacting with the agents points out where you need to bring more data in from different sources that you may not have had access to before to have a more robust view of where the opportunities are and how to action them. So it's constantly evolving. So this is not new, but it's new, right?
These, these next level X vantage AI and agentic capabilities, are you able to share at all sort of anecdotally, or maybe, you know, some specific, like how it's changing customer? Because I'd kinda love to hear some practical stories and probably for this audience just to kind of hear what, what does success look like? You know, And, and it's, it's a great topic.
You know, we've already have our partners already interacting with AI and agentic AI right now with us. And I could give a few examples. One, one easy one would be integrations, is we were talking about before, simplifying, taking the friction out.
Where as a partner of ours, you can send us your information, your quote request, your order request in any format you could send us to it. Even an email unstructured, you don't have to conform to sending in a specific format to us to have it processed. And we're using AI to pick that up, process your order in seconds, right?
So getting you that speed to market, helping speed up the quote to cash cycle. So efficiency improvement, taking down the burden on our partners when it comes to interacting with us. If you think about the growth story or opportunities, we're, we're using ida, intelligent digital assistant right now to go find and help prioritize opportunities that our partners are working on with their end users.
52 different dimensions of data that it's analyzing and actually enables our associates to reach out to partners and say, these four thing items that you're working on, these four opportunities for these three customers have the highest propensity to close based upon all this data that we're looking at in the next 30 days. You should focus your effort there. And it's a new way of helping our partners align their resources with outcomes.
And we're seeing tremendous, tremendous benefit for our partners. Hundreds of millions of dollars of opportunities. We're helping them close a quarter using that model.
So when, when I say integrations, you're saying ERP systems, you're saying, uh, it's connecting to their CRMs, it's connecting Cq, But I'm saying it's, you know, for those integrators, channel partners, uh, MSPs that work with Ingram, you've built the integrations across a, a wide swath of well understood, well known. Absolutely. And it sounds like also you've built some integrations for things like unstructured data that come, that comes from Absolutely.
You know, people's, uh, uh, word documents. Yeah, Absolutely. Absolutely.
Spreadsheets and chicken scratch. And they've now, you know, scanned into their system so that they can, because again, what a real org looks like, you know, we all know, and you, you, you lead a big org, right? We all know how much salespeople love putting stuff into Sierra.
Yeah. It's gonna be a challenge. It's, It's, but so half the battle's been there, but if all of a sudden now, hey, there was a Slack interaction that took place yesterday that had a bunch of really juicy, good, valuable details mm-hmm.
That stuff can be constantly being mined. Absolutely. It, it's the that multidimensional perspective Yeah, right.
That you're talking about, which is what's the holistic view of the partner, the interaction, the opportunity, because really we don't live in a world where one individual is gonna have all the interactions with one partner or opportunity. Yeah. It's bringing those together and identifying not only the best, the best action to take, but then often who's the best person to take that action.
Yeah. I, it's funny, I, I talk about a lot of the tools we're building now, we're gonna start building for AI to talk to ai. It's, it's, We're Getting a little ahead of ourselves.
Yeah. We like, we're not that far away though, from the fact that what, who's gonna actually might, who may be reading your best idea that you came up with for an upgrade, maybe an AI that's gonna then filter that system down. It's, it's going that way.
And If you, if you think about it, the amount of time it's freeing up for the people in the business, it's this, it's non-linear. It's an exponential level of growth. Because now think if you have your own assistant to go mine and do that research and come back with the answers for you, now your focus is on doing something with that data.
Yeah. It, it's a huge transformational shift in the industry For sure. Yeah.
It's very exciting. And by the way, every business, every industry has a place for it. There's so much more productivity to be gained.
There's so many efficiencies to be found. And, you know, I keep saying that this industry picking your right partners, and, you know, we started this conversation talking a little bit about like, some of the, the deals that were announced today. You know, you look at a company like OpenAI and it picks its partners, it's a MD, it's Nvidia, it's Microsoft, it's Amazon, it's Right.
They're like, who are the companies I wanna be around? If you're a implementer, an integrator, and you want access to hardware, software services, consulting, gram, I mean, it seems like that's what you guys have built your, your, your lifeblood on being able to support all those needs. Yeah, absolutely.
And it, it ties in AI as well as, if you think about the investments we were just going through a few that we've continue to make, right? We're an AI centric platform with advantage, the benefit to the partner bases. You don't have to go make your own massive investments in technology or, you know, the structuring data, creating data lakes and event driven architectures.
You can leverage what we've built as being part of our partner. And the more interactions you have with us, the richer the data, the richer the opportunities that are presented. So it's, you have your own AI factory, which is us to leverage and then turn those into actions and outcomes for your business.
Well, if you build the event driven architecture, correct. We've done this on our own company, built our own platform for research, and it can be very flexible. And that's probably for a lot of people out there that might say, well, if I am using the same thing everyone else is using, then how do I be different?
Because you can use it around your data, around your processes, and it'll look completely different in your organization than someone else's. That's just something that Yeah, I thought everybody should know. So on the way out mm-hmm.
Um, you know, one message to the viewer, one message, one prediction about the future of ai. You get a choice. A choice.
Yeah. What, what would you, what would you share with them? I, you know, what I, what I would say is AI eventually is gonna become, likely gonna become the primary UI for our interactions, right?
So we're gonna, you know, you still have to have very strongly developed applications that are underneath all that. But I think we're gonna go more and more to a conversational user experience where that agentic, you know, your personal agent is gonna be helping you accomplish your objectives, might take you away in a, around it, a curated experience to do it. But I think that's gonna be a big shift.
And how do we get comfortable with that conversational business transactional flow that today has been more embedded within a workflow, becomes a, a conversation tomorrow. That's a, that's AI is the new ui. I've heard it a few times, uh, a few different sources.
Totally agree. More semantic, more contextual, more natural. Um, even these devices may or may not be the thing that we'll be using forever.
Uh, we hear a lot about that. Jim s thank you so much for joining me here. A lot fun Chat to you.
Pleasure. Thank you everybody for tuning in here at Ingram Micro One. We are on the ground.
That was a great conversation. Stay with us for more. Hey everyone.
We're back here. Live on the floor of CubeCon and it's, well, it's Wednesday and it's, I'm going to guess it's about two o'clock, right? And we've had an amazing day and a half so far of some great conversations.
You probably see behind us, people moving in and out. The, the show floor, as I think I mentioned is, is really big this year, like CubeCon style, not too much on top of each other, but a little bit more, um, concentrated than like, let's say during COVID when stuff was really spread out. I want to introduce you to our next guest.
His name is EP Go Goswani. Gowan. Did I get that right?
Go. Swami Sudi is the CEO of a company called Traffic Labs, but it's spelled a little funny. We're gonna get into it, but first let's find out more about Sadeep.
Welcome. How are you man? Yeah, Hi Alan.
Great to be here. Great to have you. So Sadeep, before we talk about Traffic Labs and CubeCon and all this, let's talk a little bit, you, as I said, you're the CEO here, but you know, you weren't born the CEO of traffic.
Give us a little bit of your journey. Yeah, so engineer by trade, um, used to implement technology before I got on the other side and started to build technology and then sell technology. So really kind of dealt with the challenges of day two ops and what users have to do after they buy a certain piece of technology and all the trials and tribulations they have to go through and being able to, to implement that at scale.
Yep. So I'm gonna assume that being that you said that traffic deals with sort of a day two ops problem. Is that what you would think?
Yes. We definitely focus on day two ops for microservices and cloud native infrastructure in general. Got it.
Let's talk about how you went from being the, how you came to be the CEO at Traffic Labs. Right? That that's a, there's a lot of people out there who, of course, who aspire to be CEOs and having been a CEO now a few times I don't.
But, uh, how did you know, when did you, let's say, take the track and say, you know what, I want to be a c, the CEO? Well, I, I'm a problem solver at Heart Uhhuh. For me, it's all about solving problems, you know, whether it's a technical problem or a business problem.
So I joined the company as a CRO. Okay. And then, uh, we had a conversation internally and try to match my skill sets to what the company needed and the problems that needed to be solved.
And, uh, you know, the rest is, the Rest is history as they say. Yeah. Cool.
Let's talk about the history of traffic, if you don't mind. Sure. You know, again, probably Traffic Labs company that maybe a lot of our folks haven't heard of.
As I mentioned, it's spelled a little different. Why don't we start there? How do you spell it?
Yeah, traffic's spelled T-R-A-E-F-I-K. io and the traffic's claim to fame, uh, it's really around the open source project when traffic started almost 10 years ago now. Mm-hmm.
Uh, where our founder and now the CTO put out, basically, he's a problem solver as well. You know, he found a problem deploying microservices, was found it very painful. So he came up with his own solution, put it out there on GitHub, and overnight took off.
It just took off. So is the open source project called Traffic as well? Yes.
That is called, that is called Traffic Now or Traffic. Some people know it as traffic proxy. I'm sorry, say that again.
Traffic Proxy. Traffic Proxy. Yeah, Absolutely.
And, uh, you know, that was in 2016. 4 billion with a b downloads. Wow.
It's got over almost 60,000 GitHub stars. Got a very vibrant community of active contributors both inside and outside the company. Yeah, I Love it.
It's, it's one of the best projects and, you know, people who come to our booth here, uh, they know the brand. Uh, the, the brand is the gopher, uh, that's the the brand, The Masco if you will, Mascot. Exactly.
So people are always coming to our booth for the Gopher go Shirts. Got it. Um, it's funny, I'm old enough to remember when Gopher meant something else in the internet right before there was a web, we had wide Area Search Gopher and stuff like that.
That's right. You remember? That's right.
Yep. Um, wanted, so is I, I just wanted from like a book of housekeeping, is traffic A-C-N-C-F project or No, just traffic Labs. Traffic is not A-C-N-C-F project.
It is an open source project, and it's got an open core model. Mm-hmm. And then, so it has the open source, uh, binary itself, and then there's a secondary binary for all the enterprise features.
So we built on top of the open source as the foundation. Got it. And, and that, you know, the open core, the open, uh, core model is one of course that's very familiar to everyone here in the, uh, in the, uh, open source community.
Right. It's, it's evolved. Um, so with open source, I'm assuming you have like freemium modules or premium modules that ride on top of the open core, open source one that give you enhanced, you know, capabilities.
Let's talk about, you know, what comes in the, in the pure open source one. Mm-hmm. And then what some of the add-on, uh, modules are and what they do.
Yeah, Sure. I'll talk about what comes in the add-on modules, but I also want to talk about the upgrade process because we have made that extremely user friendly and seamless. Mm-hmm.
So let's start with the capabilities in the open source. People can deploy that as a reverse proxy, as a load balancer, and as a router, it auto discovers all of the microservices that you're running. So you don't have to do that manual work.
Wow. And that's the core value proposition of the open source that people love That. Yeah.
They don't have to deal with kind of fi finding a microservice by microservice. It automatically does. That creates the routes.
So traffic starts flowing to it. Okay. That's the foundation.
It's, uh, That's in the open Source. That's in the open source. People love that.
And a lot of people for them that is enough. And then we can give them enterprise support on top of that. So they have the peace of mind for when they do need to call us and get support.
Got It. Now moving to the, uh, the paid add-ons, Premium or premium, All the additional things which comes with our advanced, uh, or the another binary, so to speak. That's it.
People use that. One of the most common use cases for that is security from an authentication and authorization standpoint. So when their microservices need that front door where you can authenticate and authorize users and traffic coming in, that's when you need what's called an API gateway.
Okay. And that is the most, uh, common use case for our paid offering. What we have done is built on top of that.
And that API gateway. So when you say it's an API gateway, it's an, it's a API built, or that rides on top of the open source core that allows other people to plug in? Correct.
Okay. It's can, so we have our own API gateway, but there are plugins available on the open source, uh, binary Yeah. That communities can contribute to.
So you can pull off of that. Yeah. You can add functionality or you would go with our paid offering that we have written at Traffic Labs and we support.
So, and that's the most natural path people take. Got it. Is the API gateway.
And then we have created extensions of that API gateway into dev, uh, developing an AI gateway and an CP gateway. So that be sort of an MCP. Okay.
So that's an MCP gateway. Yeah. An AI gateway is separate, and an MCP gateway is separate.
Now they have different, So the ai, like a A two A, uh, was a two A or something Different ai. Think of the AI gateway as, uh, uh, LLM router. Okay.
So, you know, it does many more things. So at its core, it's routing to different LLM endpoints while and before it's routing. We also provide a way to, uh, enrich the traffic or to guardrail the traffic.
So not every query that you send to an LM should be sent there. Maybe your corporate policies don't allow certain types of content. Got it.
So we integrated with NVIDIA's safety name guardrails. So before you route the traffic to an LLM, you take it through a set of safety guardrails, then comes some kind of caching layer. So if you keep asking the same question over and over again, you don't need to consume these expensive tokens.
So only then do you route all of that. Right. Is offered as part of the AI gateway.
Got it. MCP gateway is, uh, it requires that as the foundation, but it's not enough. MCP gateway needs more than that because it's a new protocol.
Right. And what that requires is for your agents to be able to talk to the MCP resources, and then the MCP gateway provides that governance layer. So it allows which tools under the MCP umbrella can you talk to?
How do you, uh, talk to those tools? What operations can you do under those tools? So it's an extra layer of complexity that needs to be governed properly.
That the API gateway definitely is not gonna give you outta the box. And AI gateway is not enough. So you need essentially what we call the triple gate pattern.
For MCP, you need the AI conversations protected, you need the API conversations protected, and you need the MCP conversations Protected. Protected. And all three of those are premium.
And, and I, I could see, And all of these are premium. Give us an example of some of the other premium models, The other premiums. Yeah.
And which is really around API lifecycle management as everything is becoming an API. So your LLM endpoints are being exposed as a, uh, a APIs, even your MCP endpoints become exposed as APIs. You need, you have an API manage, uh, management problem, or you have an API proliferation problem.
So what you need is a full lifecycle management of that. That means your APIs need to be versioned controlled, they need to be sunsetted, they need to be deprecated. You need to provide rate limits and quotas.
So, you know, there's a layer of defense. This is why you have a, a true sort of gateway that controls all that. Right.
Rather than just, uh, you know, uh, an API to API. So, I mean, just the Correct. Yeah.
Uh, a direct connection. If You, plus you also need to share those APIs with your community of developers. They could be internal, they could be external.
So this is where developer portal is needed. So all those things come under the umbrella of API Lifecycle manage. Got It.
Got it. Now, the beauty of this, going from open source to all these extra paid capabilities, it takes 30 seconds to do the upgrade. And it's an in place upgrade mm-hmm.
That you would do. It preserves all the configuration that you do with the open source. And after 30 seconds you have On Top of that and you have export you.
So it's like a mesh layer that sits on top of the pure open, uh, stack, if you will. Um, I'm, I'm wondering, so it's not like, so people host this and run this themselves. It's not, you know, 'cause that's another model.
Right. An open source Right. Where I, I'll take my open source and I'll run it as a SaaS, so you don't have to worry about.
Right. We will, We provide a self-hosted model, A Self-hosted, so people usually deploy this on public cloud. So because we're Kubernetes native mm-hmm.
They can deploy it on any of the public Kubernetes distro. So A-K-S-E-K-S-G-K-E-O-K Got it. LKE.
But they can also deploy this on-prem in a completely air gapped and offline environment. Okay. So it doesn't even need connectivity at That point?
No, it does not. And people can deploy it at the edge. We are natively integrated in the K three s with rancher.
Mm-hmm. They can deploy this in, you know, a bigger environment. You name it.
Like it works seamlessly everywhere. Excellent. And so does it require, it requires Kube though.
Um, the, the Kubernetes native that if you're deploying in Kubernetes, yes, it's gonna require Kubernetes, but because we started in 2016 when Kubernetes was not even around, we have had into native integration with many different alternative ways of deploying microservices, starting with just bare metal Linux. Okay. And then came HashiCorp Nomad.
Yep. We can be deployed just as a Docker container. Okay.
Or we could be deployed in Kubernetes. Okay. Got it.
And we can even be deployed in Windows, if you like. Listen to that. Oh, you're the first one to mention.
Any deployment Windows. People don't Talk about the W No, they don't. They don't.
They don't. It's the year of the Linux desktop. But anyway, um, did we mention the website?
io. Say it again for me. io.
Dot io. io to, and download the open source Yes. Package and install it yourself.
Yeah. It's on, it's on GitHub. You can download it through Helm Chart.
Uh, there are many ways to install it. Install, absolutely. And then once you're up and running, putting in the, uh, the, the third, the, the premium modules, as you said, is the 32nd.
It's a helm chart update. Takes 30 seconds and you're good to go. Excellent.
I can't, what, well, let me ask you, what has the show been for you this year? It's great. It's great.
We announced actually some, some great stuff this Week. What'd you announce? So, uh, there's a, you know, with everything we just discussed, there is a fragmentation problem happening now in the industry.
It's a big realization. People are having that, uh, virtual machines are not going away. No.
So there's gonna be a coexistence of virtual machines and containers, and now serverless workloads as well. Mm-hmm. So, and, But they're not mutually exclusive.
They're not mutually exclusive, but the way people manage them are very independently and differently managed. The way you manage a VM stack and the way you expose your services running inside a VM is very different than the way you expose and manage a Kubernetes. Yeah.
So what we have launched is a unified layer, uh, which we call the application layer intelligence that connects the VM environment and the Kubernetes environment, and also the serverless environment. We launched support for, you can Manage all three. So you can manage all three in a very cohesive way, and it's through a single application layer, which is a layer seven, uh, construct.
Mm-hmm. And you can seamlessly redirect traffic, because what's happening is, as monoliths are being decomposed into microservices, your backend might be sitting in a vm, but your front end is going into Kubernetes. Absolutely.
Right. But it's still, still the same application. Yep.
So, at the application layer, when a traffic comes in, you want to have that intelligence so you can seamlessly direct traffic to where it goes left or right, or somewhere else. I mean, with containers, they literally could be distributed anywhere. Right.
It, it's not just Right. And we did the integration with Nutanix as a, as a reference architecture. Oh, very cool.
Because Nutanix, as a platform does a great job of providing a virtualized environment and the Kubernetes environment, you know, so they have their A HV with flow networking for virtual machines. Right. We have done the integration with them, and what that allows users to do is to auto discover all the virtual machines that are running, so then they can write policies against it.
We are already working with them in the kuber, in their Kubernetes distro, and we can all auto discover services running there. And now with K native, with serverless, they are the perfect reference architecture for this solution. Mm-hmm.
Excellent. Any other announcements here? Um, just that we on the gateway, API, you know, which is on everybody's mind, uh, here, uh, we continue to lead support on that.
4. Uh, our founder and CTO and other team members, they're part of the c you know, the community actively working with the Gateway, API community and advancing it forward. So, you know, that's one of the other big announcements that we continue to open source is important for us.
It's very strategic for us, and we continue to invest in that. Love it. Alright.
I think we're about outta time here. I think we hit most everything. Is there anything we left About?
I think so. Nope. Just, uh, you know, you know where to find us.
io. Very cool. Thank you very much for being here.
Hey, thank you Alan. Enjoy the rest of CubeCon. Hey, we're going to take a break.
We've got, well, we probably have another two hours or more of coverage here at Q Con today. We'll be back again tomorrow, but let's take a quick, uh, break. We'll be back in a moment.
Hey everyone. Welcome to Ingram Micro one. We are on the ground here at the event on the floor.
I'm Daniel Newman, CEO of Futurum. Excited to have this conversation. Today.
We're gonna talk a little bit about ai. We're gonna talk about a lot more here as well. Excited for this conversation.
Talk a little bit about the eye and the lens of the CTO, the MSP and how they're thinking about their business transformation. And for that, I am joined by Dom. Dom, welcome to the show.
Good morning. Good to have you here. Happy To be here.
Yeah. So, um, let's start. I mean, Ingram is in the middle of its own transformation, right?
People that had followed the company for a long time probably knew it best for being one of, if not the enabler facilitator, uh, for all of that infrastructure that is being deployed now. That's a hot topic itself today. Yes.
But you're, you're becoming so much more in many ways, becoming a platform company yourself, kind of interested in your role, you know, how you're thinking about that. Um, you know, CTO role, the transformation of a big business. Love to start you out.
Just talk about what, what kind of what you're doing there with Ingram. Yeah. Was all great to be here.
Thank you for the opportunity Right after it. You know, when I started, uh, at Ingram Micro, this is one of the best opportunity in my lifetime. We don't want to build technology for the sake of building technology.
The reason I join here is to build technology, which will bring outcomes. Yep. Not only for Ingram, it's for our e partner ecosystem.
So if you go back and see what we did with X vantage, we built based on the data, the data is the new fabric. We knew this three years ago. We took a big bet on AI three years ago, build and centralize all our data to a one single data lake.
And now our AI factory is what's based on that data lake. And now we got like 400 a models and like, you know, 30 plus patterns pending. It sits on like, uh, four petabytes of data.
We are able to sit in the middle and understand, not only distribute the data, not only distribute the technologies, we are able to distribute the intelligence to the community. That makes a humongous difference. That's what this X one is all about.
You know, I love what you said, you're kind of right in the middle of it all, but like, you have thousands if not millions of, of, of integrators that that depend on in integrators, MSPs, channel partners, consultants, that all depend on Ingram to get equipment and software and services. Then of course, you have thousands of vendors, uh, OEMs and others that you guys are basically handling distribution. Like was it, did they come to you and say, you know, Dom, help us.
We need to build, uh, something that a data lake we need to, or was this kind of the foresight that you had to say, like, we see where this is all going. We're gonna need to build something that can connects the end users and implementers all the way up the food chain to those that are building the most advanced NVIDIA servers on the planet? Yeah.
Great question. So B2B industry was not that far ahead. Like three, four years ago when we saw from our lens, the B2B C industry was up there.
Yeah. But the B2B industry wasn't. Yeah.
So our vision was bring that B2C experience into the B2B ecosystem. If you wanna bring that, there is no other better per place than England. We, we always know data is the new currency.
If you're able to bring the data into one place every time, Dave, when you go to them, you know what they ask, don't gimme the data. I have dashboards, I have reports, I have bi, I have this gimme intelligence. That was our spark.
If you really wanna give them, distribute the intelligence, like if we, the way we started was we started with our customer platform. Simple as that. Hey, listen, we just sold the last 10 orders.
Can you please tell me which one I missed? Attach a warranty. They just didn't know.
We knew That is the beauty of having all that dish. So you basically, if I, if I break that into a couple parts for the audience, it's like, one is, you know, you were sort of looking at the Amazons and the Shopifys and the com and it sort of revolutionized, you know, I know we talked off stage a little bit about E-Trade and different, like the platforms that sort of brought consumers in retail to things that were always done in sort of a B2B behind the wall with, you know, what I call the Abba cadabra? Yeah.
You know, and you're saying, why are we doing it and making it so hard? Why don't we democratize this? Why don't we, if you can get anything you want ordered and delivered to your house in 12 hours, why is our system, you know, a bunch of a black screen with orange text on it?
Right? I mean, but that is kinda what it, what being at times, like it moves slow. Um, so talk about how you pick which things to do For, for us is, you know, we don't wanna build technology for the sake of technology.
We wanna build technology which will bring the outcomes. Yeah. Because like I said, there is people, people can build more chat bots, more dashboards, and more techno.
No, we are, we are not in that business. Focus is outcomes. Can you remove complexity?
Can you remove friction? So if you look at, if you focus on outcome, and when it comes to about prioritization, that becomes our biggest, biggest focus. Let's say, if you take, if you wanna save time, time is the biggest commodity.
Right. You know, when you talk about outcome, there is like, oh, it's a top line, it's bottom line. But everything starts with time.
Where is the bigger place you can save time for your partners today? Like we built so many things and it's all about saving time. Like, you know, if you want things like X one integrations Yeah.
Where before the partners used to call us, email us, and the orders used to take hours and days sometime to get processed. What we said, listen, please come as you are. Don't change your system.
The integrations get complicated. You got Excel sheet with a bunch of information about your transaction, just send it to us. We will process that using ai.
We will normalize the data. We will go transact. You don't have to change your system.
We just save time for them. And same thing with, you know, PD ft SKUs. There's so many ways where these partners are struck in the way they do stuff.
Either they're coding, they're ordering their invoicing, their subscriptions. Now we made that all that so simple for them. Yep.
The money you simplify. That's our focus. Because you, like you said, there is a million things to do.
But if you focus on outcome, not just for Ingram, also for your partners, that will distill your priorities straight out. And that somehow has to flow to the MSPs and partners focusing on outcomes for their customers. Yeah.
Because now what you've done is you've taken some of the monotony out, you've taken some of the, you know, the extra layers of work. You've probably enabled some of them to reduce some of the back office overhead and invest more in front office and growth. And like, what are you seeing there?
So, you know, outside of just efficiency and uptime, like what are you seeing in terms of your MSPs translating what you're doing in the platform and, and what are they building for their customers? Yeah. See, I would say my humble as to the MSPs, they gotta become this AI enablers.
There is no more break fix and maintaining infrastructure and all that. They really gotta get into this train of what's happening. I can tell you from Ingram perspective, my own experience, how we and our jobs change.
You know, how we transform, we distributed intelligence through our customer platform where they can come download their business review, they can see what is they're selling, what they're not selling, what is a cross-sell upsell. We distributed that intelligence through the customer platform on the web. Then we moved on to the next level is, hey, we wanna make integration simpler.
We use AI and completely changed the made all those autonomous work. We just automated it. But now what they want is they want the data, their data with our intelligence into their ecosystem.
Which means if they use CPQ, Salesforce, any CRMs, anything they got, now these MCP connectors are all over the place. You go to AWS, you go to hp, you go to Ingram, everybody has provided this MCP connectors now where it can provide their intelligence into your system. And that's what Ms.
P is really keep their eyes open. Don't try to do everything by yourself. Look out for your partners, look out for Ingram, look out for those integrations, and look out for so many technologies, what we provided.
How you can become the first platform mindset and then you become that a enabler your life is going to change for good. Have you seen any, you know, I know it's early days, but have you seen any anecdotal, have you seen any, you know, with the MSPs you talked to work with like really cool implementations, applications even theoretically, that you could show? I'm just kinda curious like, oh yeah.
You know, things that you're seeing them now do with that extra capacity that you're giving them. So Where, where they will go is like going from what we really want them to make is go from auto takers to auto makers means save time. Don't be in doing this autonomous job of doing stuff, which you don't have to do.
We, when we save the time, now they're doing that in the proactive sales where they're able to go to take care of their end customer. What is their job? Their job is to take care of end customers.
Not doing this middleman job of just, you know, typing in codes and orders and invoices and splitting. We, we completely take that now. We clearly see their teams are able to go back and do a proactive sales with their end customers.
So what about the MSPs from all the work you're doing right in terms of, you know, building agents, building platforms. Like you do it at such a big scale. And I think sometimes, uh, when you're a li smaller company, you know these MSPs that you work with, some of them are a handful of millions, some of them are hundreds of millions, some of 'em billion dollar companies.
But in compared to your scale, some of them are, they're all still maybe smaller, many are still, what are you seeing? What do you think from the experiences of the work you're doing translates? I mean, the things that they can learn from to, to build in their own businesses?
Great Question. You know, automation, I would say that's a common denominator for all of us because they also have their ID ecosystem. So go back and see where you can automate, automate, automate everything possible.
And that could, you can take help from like people like Ingram Micro or like go to your AWS or HP or any of these vendors. So for example, you take your A one L two ticketing system. You don't have to do this with the multiple vendors in multiple ways.
Now you can use these agents to harmonize all the data, bring a single pane of glass for your end customer. So to me, that automation is a common thread. And they can use AI to a very large extent where not only they can create their own L LMS and their own agents, they should automate and connect that with every other players in the ecosystem.
Once they connect that, they will bring that single unified experience because standardization is key. You can't let your end customers go to five different system to see five different things. That's returns, that's clients, their tickets, their codes, their orders, their invoices.
They cannot be in a multiple in multiple systems. If they can bring all that into a single unified experiences through that automation, that's gonna make everybody life easier. It's Funny, I keep thinking about when Sam Altman talked about the one person billion dollar company.
I mean, there's probably orders of magnitude in between where we are and there, but what you're saying, and what at least we're finding even in our own business is, look, so many of the processes can be done. It's either 10 x or one 10th. Like you need one, like with automation.
And it's kind of the promise that we never had with RPA, right? Like RPA just it, it did some things well, but it was always too fra. I, fragile is the word I would use.
It was just too fragile to scale. And now with, with automation and ag agentic, we can do these things like much, much Faster, much fun. Like I have built APIs, I built RPAs, I build screen scrapers, I build all kind of technology.
I can see it, I can say my job has changed as a chief technology officer in the last two years, the way we build platforms and now we build this agents. Now it is become, I can go to market so fast right now with these technologies either writing code or writing the agents. And they are making things so fast.
So good for us. I'm telling you, that is what this industries and MSPs has to cat, get onto the train, understand how these technologies work. Please lean on your partners.
Go look at integration hubs. So many plugins, so much is available for you to take it and make things easier. That's a great, great way to maybe sort of end.
I wanna ask you about just the role of the MSB. 'cause what I'm hearing from you is you're a believer. You buy into the power of AI as someone who's done development work, not just kinda lead technology, you're kind of saying it's making things better.
It's, you know, 'cause there's a lot of that debate. Like is it eliminating the code? Is it, but like for the MSP that is seeing all the power, all the potential, everything that automation agentic, that ai, that data, uh, and and into integrations can do.
Like, how do you recommend that they think about evolving their businesses to make sure that they're gonna be successful throughout this transformation? You know, my first ask to them is like, go centralize your data. The technology like ai, it's cannot work without the data.
If you got multiple sources, your code, your orders, your invoices, your if, if these are in different, different systems and places, you are going to have a very hard time harmonizing this data. Start there, harmonize your data, try to put them in one place, and there is multiple technologies available to make it so easy for you. Now, before, like five years, 10 years ago when I was trying to do that, it was a lot harder.
Right now, harmonizing all your data in one place, it is going to make it so easy. Then you can plug and play any AI you want. That's a general DOI or even even your AI agents.
They can come and consume the data and bring intelligence to you and automate anything what you want. But start thinking about how you can harmonize the data across your systems that will set you for a very long time. Sounds like a great way to end this conversation, Dom, what a pleasure.
Congratulations on all the progress you're making. Love to keep chatting to you more. Have a great rest of your Ingram Micro one event.
Thank you Daniel. And thank you everybody for joining us here on the ground at Ingram Micro one here in Washington, dc Great conversations stick with us here on the channel for more to come. Nvidia has cloud aspirations, more like our don't Dino NATO is googling some stuff.
Amazon launches some satellite antennas. Splunk donates open telemetry injector project, sudden catcher in space. And we're gonna dive into the new AI infrastructure investments from Nokia and AWS in this week's episode of the Tech Field Day Rundown.
Hello everyone out there and welcome to the Tech Field Day rundown to today is the 26th of November. And if you are listening to us in the United States, I hope you're not doing it at work because of course it is the week of Thanksgiving, which means that most people have already decided that Wednesday and Thursday and Friday are national holidays, even though it's really just Thursday. But it is National cake day, no lie for everybody that celebrates.
And joining me, of course, is my wonderful co-host who doesn't celebrate Thanksgiving this week. Mr. Alistair Cook.
Al, it's good to see you again. It's always good to be here. And it was great to see you in person last week.
I'm looking forward to some of the interesting news we have coming up. Yeah, it should be a really fun time because of course everybody's trying to cram in their last little bits of important stuff before everybody then goes to eat, uh, gravy that has giblets, you know, little bits of Turkey in it. Uh, we're gonna go ahead and start off with, uh, some big money news because Nvidia plans on spending $26 billion over the next six years to secure cloud GPU capacity for its AI projects that would make it one of the largest cloud infrastructure buyers company is partnering with providers, the names that you've heard before, like Lambda Core Weave and Oracle.
And they're gonna create a system where they're both the supplier and the customer. The move comes among, among strong AI demand regulatory uncertainty, and frankly limited GPU supply highlighting how even leading chip makers are gonna have to lock in compute resources to stay competitive. Al is it weird that Nvidia is not only selling them the GPUs, but also buying that capacity right back from them?
It is a weird continuing trend that we've seen. So this is, uh, very much the, the idea that the money go round of AI is, uh, Nvidia giving money and receiving it, giving money with one hand and receiving it with the other, uh, in terms of what's going on. That is a, a very big uplift.
So NVIDIA's talking about this as being their need to run AI for their internal business requirements. And they're talking about it as being 1 billion in this year, rising through to 6 billion, uh, for the, the, the following couple of years and then tapering off maybe in this particular filing. I mean, who knows what you're gonna spend money on in five years time?
It may not have been invented. Uh, but there is definitely a a lot of money being spent here and it's being spent by Nvidia at customers of Nvidia who are buying NVIDIA's cpu, uh, GPUs. Uh, one of the vital things to see in this is that, uh, NVIDIA's GPUs are hard to get hold of if you're not buying them by the thousand.
And, uh, that's what we're seeing is these, uh, cloud providers in particular, some of the, uh, core cloud providers for ai in this case, we, we saw sort of said core weave and, and Oracle and Lambda in here. Uh, some of this is that, uh, Nvidia themselves are stepping away from the idea that they will do a renter GPU model. That was something that was the, the DGX cloud was supposed to be this renter GPU that are gonna be providing to others.
It looks like we were actually seeing this, the shift away from that. Instead, Nvidia has been very aggressively encouraging neo cloud providers and new people to spring up and deliver clouds that are just for ai. Um, Nvidia has been pushing those very hard so that there isn't so much of a market dominance from the existing cloud players.
Uh, some of the spend will be on, on exactly those same neo cloud vendors. And I do wonder whether there's an element here that they're going to be customer number one for these neo cloud vendors who allows the neo cloud vendor to get funding to then buy more GPUs or buy their initial seating set of GPUs from Nvidia. So there is a little bit of a sniff of this, of being kind a tenuous go around to make things look good.
But I think there is also a requirement for Nvidia to use their own GPUs to, to actually transform their business with AI in the same way that they're telling their customers to transform their businesses. Uh, one of the other elements to keep in mind here is that, uh, the restrictions on export of the, uh, Nvidia GPUs to, uh, less friendly states has had some impact on NVIDIA's, uh, financials. They've, uh, incurred a four and a half billion dollar charge earlier this, this year, tied to not being able to fulfill orders because of these restrictions.
Uh, and so this may also be some of the play around keeping things priced still, $26 billion is quite a lot of cloud investment and seeing that go to established cloud players, providers who are, uh, delivering good GPU services, it's probably good for the market, but I'm not sure that it's a huge nest change. Qualcomm's new terms for the Arduino have angered the maker community, uh, including maybe myself since I write a, a whole bunch of Arduino code. They've added sweeping rights over user content.
So since Qualcomm acquired Arduino, they're basically saying anything that you produce on our platform belongs to us. Uh, and the other thing is that they've, there's a ban on reverse engineering, which goes away from the whole core open source ness of Arduino makers and companies like, uh, ADA Fruit argue that Qualcomm is undermining what made Arduino successful and prompts many to switch to other types of, uh, CPUs for these, the same projects, things like the Raspberry Pi 2040 MCU and my favorite, the ESP 32, uh, AO says the changes are were for clarity and compliance, but no, Tom, uh, it seems to have angered a few people. I think it angered a lot of people.
And honestly, I am not surprised because I secretly kind of knew this was coming. Uh, remember Major League two when Charlie Sheen puts on the the suit jacket and gets rid of the bad boy image and everyone's like, oh, well, he's still the same picture. He is just, he's a little bit more grown up now.
And, and that's like a whole plot line in the movie. I, I won't spoil it for you, but that's exactly what, what, what's happened here is that Arduino basically said, well, we want to ba we wanna be underneath the umbrella of Qualcomm, uh, because we would like to get money and not go out of business and ar the Arduino folks were happy to do that. And they, they said the things that you're supposed to say when you, when you become part of a corporate organization right, is that, you know, nothing's gonna change.
We're still the same people. We just maybe wear suits to the office now. And Qualcomm was like, okay, cool.
You know, we, we promised that we're not gonna really mess things up. We just need you to agree to this legal writer that says all of the things that everything else says, right? We're gonna collect your data.
We're going to, uh, anything you make with our stuff is technically ours because you're using our stuff. And, uh, we are also going to restrict your ability to reverse engineer a whole bunch of stuff that we don't want you to poke around in. I got news for everybody out there that's boilerplate.
That is pretty standard. If you go to work for any major organization and you invent something on their dime, it's their invention, not yours, IBM, Cisco, you name it. Any patent you file when you work for them is the patent of the company, not yours.
I agree wholeheartedly. You, you're gonna be the, I'll be the first person in line to say that this is not what the Arduino community wanted. But I think the other thing is the Arduino community did not want Arduino to go out of business.
So you've got this catch 22, right? If we wanna stay in business, we have to play by Qualcomm's rules, and they are Qualcomm's rules. I, I'm, I'm almost positive that every company that Qualcomm has acquired same kinds of things.
And yes, a lot of people in the community are gonna come right out and say exactly what we've heard from companies like Ada Fruit, I don't like this. You're, you're destroying the, the rebel spirit of, of who we are. Yeah.
When that's what happens when a company has to basically mature. And if that means that someone's gonna have to just jump out on their own and kind of spin some things out and do their own thing, okay, great. We're all better off for that.
How many startups exist in Silicon Valley? Because the company, the founders of the company realized they couldn't make what they wanted to make under the umbrella of the corporate entity. Like that's the, the part and parcel, that's the other rebel spirit, right?
That's, uh, Steve Jobs and his team going across the Apple campus to make Macintosh flying the jolly Roger from all the windows because they really were the gang of pirates over there. And, and now look at it. So I think that there's gonna have to be some give and take here.
Qualcomm's gonna have to understand that they may have tole relax some of these restrictions if they want to continue to let Arduino kind of be the, the leader in this space. But at the same time, the people who are fans of Arduino are gonna have to realize that, you know, maybe what you want to do with the system is not compatible with what corporate America wants. And if that's the case, there's nothing wrong with moving on mass to the next thing, but just make sure that you've got all your breadboards wired correctly.
NATO is working with Google Cloud to build a fully air gap cloud for classified workloads, letting its joint analysis, training and education center, also known as JT e run AI analytics without using the public internet. The system combine strict security with commercial cloud tools, giving NATO both control and high performance computing. This deal, which is part of NATO's multi-vendor approach alongside a s and Microsoft, reflects a growing trend in defense towards secure hybrid cloud architectures for sensitive data and advanced analytics.
Al do you think NATO made the right choice here by kind of spreading the resources out along with Google Cloud? You know, I think having a strategy of using different technologies for to solve different problems is pretty common. And, uh, the reality for any large organization for cloud adoption is typically hybrid multi-cloud.
But defense and NATO in this case are, is always a special case because there are always the networks that are secretive of some sort, uh, whether that's top or extra top secret. Uh, and these networks are supposed to be fully disconnected. They are supposed to be separated from anything that's accessible on the internet.
And, uh, it's one of the, the fun things of working in defense is working with these area gap networks where you can carry your install media into the bunker where the network exists, but you're not carrying that install media outta that bunker ever. Uh, that's the kind of network they're talking about and cloud they're talking about. What's different here is those networks that are highly secure, usually very tightly controlled, very sort of waterfall development kind of, uh, environments.
And the suggestion of using Google Cloud platform inside this air gap highly secure network suggest to me that they're looking for more agility and the ability to do new things on these secured networks that they would previously have had to do on a public network. And there's been some interesting challenges around sovereignty recently. Some of the discussions around sovereignty have come up and that if a US company is operating a cloud and your stuff is in that cloud, well, US jurisdiction may still apply.
Well, that's not the case if it's completely disconnected from the us uh, networks from the internet. I believe this is a way of avoiding any kind of oversight from outside of NATO on the data that's in this, this network. So it's not NATO turn their back on doing things on the public internet.
That's why they still have, uh, both the AWS and the Microsoft relationships. But it is a, a symptom that those secure networks are getting a lot more agility and particularly getting a lot more AI in there. And you can imagine that there's secure networks are involved in things like, well, maybe running surveillance, uh, drones and systems, and that AI could be very beneficial to lightening the load on the human operators who are involved.
Uh, I think this is definitely gonna be an interesting project. Uh, I would love to be working on this project just to see what's going on inside it. Although I would also hate to be working on any defense project that requires security clearance because then you can't talk about it.
Amazon Leo formerly Project Cooper has launched its new ultra and antennas offering up to one gigabit per second down and 400 megabits up along with an enterprise, uh, preview for select customers more than 150 satellites in orbit. The service targets business and government, uh, agencies needing fast and secure connectivity in remote areas. The new ultra terminal uses Amazon design silicon and supports private networking options like direct to AWS and is built for demanding environments.
Early partners includes JetBlue and Hunt Energy, and I'll be testing this new antenna before broader rollout in the next year. Tom, this sounds like an incredible piece of mobility that maybe is targeted against some other provider of cite, uh, internet, Who knew that the two people who were racing to be the first, uh, CEOs in space would come out with competing projects that were designed to provide connectivity to space. Yeah, I would, IIII totally knew this.
Uh, this is the outgrowth of what we saw as Project Kuper, right? Is they're gonna launch all these communication satellites into a lower earth orbit and now they have an antenna that will allow you to talk to them. I will say it is nice that it is gigabit downlink and 400 megabit up link.
So, you know, that's, that's competing with most of your home internet plans. And I, that's like the, the ultra tier, so I'm sure that's gonna be like the ultra expensive tier. Uh, there is a smaller tier that runs nano, which is a smaller antenna.
So naturally the, the, the bandwidth is a little bit more restricted. There's also a pro tier, which I'm sure probably just means that you can cut in front of everybody else in line. Uh, they're testing it with partners like JetBlue.
And JetBlue is gonna be using it to augment their existing, uh, plain wifi. And, and this is a trend that I've actually seen in a lot of other places because starlink is becoming the defacto communication system on a lot of like, hyper hypermobile things. All of the billionaires that are building brand new luxury yachts, they all have starlink terminals integrated into the yacht.
Uh, that's so that they can pretend to be in the office when they're actually floating somewhere off of a coast and they're doing work and they, they, they spend all of their money kind of refurbishing these offices so that it looks like they're actually working when in fact we know that they're probably not even wearing shoes at that point. And that I think is one of the places that we're gonna start seeing some of this kind of, uh, flushing out a little bit, is remote access terminals. We, we've seen that with starlink quite a bit.
In fact, I know a couple people who have starlink terminals who use them for things like, uh, being a digital mo nomad or, uh, providing ultra high-speed connectivity in places where it's really impossible to get a cell signal like the back country. And I think that the value here is that with the smaller nano antenna, you're gonna be able to basically carry that like a backpacker, right? Uh, but for those kind of fixed in placements, think oil rigs, uh, think remote construction sites, uh, this is a great way to provide a, a deployable network without needing to like, you know, run cables and get access points up and running and deploy, like a huge infrastructure.
You can just drop this antenna down and it works. And the key advantage here over starlink is that this is built by Amazon and it's optimized to use Amazon services. You can get a direct Amazon link, which I'm sure will, you know, speed up any kind of AWS uh, a blink down link type stuff, which is what you would want if all your stuff is located in AWS.
But also by optimizing it for things like video conferencing and other applications that you use, it means that you either A, don't use nearly as much bandwidth, or b it will give you a better experience overall in case there's some kind of weird outage, sunspot, solar flare, you name it. I, I think that the other advantage of doing of having this come out of Amazon is that it will create a competitive market so that then it will force other providers, cough, cough, starlink, cough, cough to get better at what they're doing and to provide better service, to provide better connectivity, to not have weird restrictions like, oh, you can only buy this smaller antenna if you're a customer on the bigger antenna and that kind of thing like that. So this should be good overall.
I just hope that we don't end up populating low earth orbit with a constellation of satellites so thick that we can't fly through it. Um, 'cause you never know who's gonna do something crazy, like decide to build even more stuff in orbit. Wait, hold that thought.
Splunk has contributed its open telemetry injector library to the CNCF open source project, making it easier to monitor legacy non-con containerized applications. The tool automates instrumentation for production apps, helping DevOps teams collect telemetry with minimal effort. Splunk also added a schema for tracking AI workloads and LLM performance, supporting consistent metrics for cost, performance and bias.
This donation highlights the growing importance of observability for improving operation security and AI readiness beyond traditional DevOps. Al do you think that this is going to encourage people to wanna adopt more CNCF, uh, telemetry tools, or is this Splunk just basically saying, we're getting rid of this because we're moving on to better things? Well, I did see at Kon this year a huge amount of open telemetry, um, adoption or observability really coming back with open telemetry at its core as a way of getting data, uh, telemetry data from your applications to somewhere else.
Be that to Splunk core, to any other, uh, open telemetry compatible, uh, receiver, uh, in terms of what's what's announced here, I like that what, uh, Splunk has donated is a, a really simple tool to install on a legacy, uh, virtual machine or physical machine that is running a legacy application. A non-con containerized, I'm sorry, I should be calling that a heritage application because legacy seems like a bad thing. Uh, a heritage application that is still running in, in physical machines or virtual machines.
Uh, you know, those of you living in the cloud native world may not realize that there are still an awful lot of applications that just run in virtual machines because there's no value to shifting those into containers immediately breaking them into a tiny set of microservices. There's a huge amount of work there. So being able to instrument those applications without having to rewrite the applications, uh, the, the injector that's been, uh, donated here is just a piece of software that gets in installed on a machine and sends what is local metrics into hotel and into open telemetry.
And very much as an enabler for adding, uh, your legacy components of your application to your modernized components of your application. This is absolutely vital where companies are developing new capabilities that still leverage older data sources or that are following the Strangler model where you start building microservices probably in containers, uh, on top of Kubernetes to build the new features around your existing legacy application will lets us instrument that legacy application. I like it.
I also like that they, uh, announced more open telemetry and, uh, large language models, being able to gather more information out of your, uh, LM based applications, particularly as we see that move towards ag agentic applications, getting more telemetry data out of what the actual LLM is doing. Not just the performance information, but is it actually doing the thing it's supposed to do? Is it doing things safely?
Uh, are we having sort of compromises in in the, uh, LLM? These are things that the companies are very much concerned about. And I think it's, it's great to see more visibility of what's actually going on inside, inside these modern applications.
So both really good things. I think Splunk has done a great thing here. Uh, I don't think that it's entirely altruistic.
I think they definitely want to show some leadership in the world of open telemetry because sometimes Tel is talks about as a way of replacing your, uh, heritage, uh, logged tools like Splunk that charge by volume of data move through them. So it's, it's not entirely altruistic, but it is a great thing. So I'm told you to hold an idea.
Recall that idea now, because Google's project SunCatcher is testing the idea of moving AI data centers into low earth orbit using solar powered satellites with high speed laser links. The system aims to provide more energy and faster connections than earth based data centers. Hmm.
Early tests show promising speeds for connections and prototype satellites are planned, uh, by Planet Labs in 2027, uh, full scale orbital data centers. Yeah, probably a little further away. And the project reflects a growing effort to meet the massive demand for computing and power for AI applications.
Does lead us to some concerns about filling the night sky with data centers and making the whole place blow in the wrong place and dark in the wrong place. Tom, are you gonna service these AI data centers in the, in the, uh, low earth orbit? Yeah.
Let me just, uh, break out one of those space shuttles and, uh, and oh wait, we, we retired those, uh, dragon capsules. Yeah, maybe, I guess. I don't know.
I, we, we, we heard about this from Amazon, remember, remember, like they, they wanted to, they wanted to launch things into space, and now Google's like, no, no, no, we, we wanna do it too. Uh, can I see the tests that, that, that these things are promising? Because I have a lot of questions about how this is supposed to work.
Uh, number one, how are you gonna cool all this stuff in space? And before everybody out there says, well, space is really cold. No, no, it's not.
Space is empty. There's a difference. One of the things that we've learned over the years is that things in space can actually get really, really hot for two reasons.
One, when there's no particles around, you can't radiate heat away. And two, there's this thing that's about 93 million miles that way that, uh, will really heat stuff up. Because again, there's nothing to block the, the solar radiation, uh, when you're in space, uh, we, we've learned that a lot from astronauts.
Like it's, it's, it's a little bit different out there. Like literally these sides of your spacesuit can be two radically different temperatures because one side is being hit by the sun and one isn't. Uh, the other thing is, like you said, what what's gonna happen when something breaks?
Uh, you think it's hard to do a truck roll to a data center in the middle of prior Oklahoma? Uh, wait until that, uh, truck is gonna have to roll, you know, a few a hundred kilometers north, uh, Andy Galactic North, by the way, just, you know, this straight up, that that's gonna be a huge problem. I, I wonder though, why, why are we launching these things into orbit?
Because one, if you wanna use solar power to power data center, cool. Build it down here. Like, like there's nothing stopping you from building a solar array down here.
Uh, they, we turns out we're really good at building those things. Is it a space congestion problem? I don't know.
Uh, there's a lot of space, but here's the thing that most people don't understand. For things to work down here, they have to be in relatively close space. That's why they're in low earth orbit.
Uh, GPS satellites are actually almost too far away, uh, for the amount of data transfer that they're gonna have to do. Uh, something like the James Webb Space Telescope doesn't even orbit earth. It orbits a LaGrange point, uh, closer to the sun.
Uh, if you wanna look that up, that is not the song by ZC Top, by the way, by, uh, but the, the ultimate problem that I have here is there's no reason to be building these things in space other than somebody said that they wanted to do it. There's still plenty of space down here to build those data centers. I think that this is a, uh, marketing tactic, a ploy to get people to maybe give more favorable terms to have it built somewhere.
Uh, you know, 'cause I guess their argument is you can't tax things in space. Uh, unless Google or Amazon or Microsoft or Oracle or whomever, uh, develop their own fleet of space vehicles last week, they're still gonna have to pay somebody to launch this stuff. And I promise you, if you thought getting overnight delivery on something from Amazon not on Prime was expensive, wait until you see what it costs to lift that stuff into orbit.
It's not cheap at all. So I I, I watch this with bated breath only because I'm hoping that somebody in this weird fever dream is gonna wake up and go, why are we putting things in space? Uh, if we, if we can't maintain the ISS and we're worried about having to de-orbit that thing pretty soon, the last thing we need to be doing is putting a whole bunch of data centers up there, because eventually those suckers are gonna come back down to, we hinted at it in the opening of the video, but we wanted to take a closer look at some big investments that have been going on this week.
It seems like right before the holiday, everybody wanted to announce the fact they're investing a lot of money into AI infrastructure. I wanna start off with a company that we just recently covered, uh, networking Field Day. And that's Nokia because they've agreed to commit $4 billion to US research development and manufacturing to speed up ai ready network infrastructure.
Most of the funding will support r and d at Bell Labs in New Jersey, and the rest is gonna be going to facilities in Texas and Pennsylvania as well. The initiative, which is backed by the current presidential administration aims to boost domestic AI capabilities, improve connectivity and strengthen national security, while also meeting growing demand from AI and cloud customers with and advancing Nokia's partnership with Nvidia. Al I'm gonna jump in here and talk a little bit about this, because Nokia is really trying to make moves to be a valuable partner in the networking space.
They're building out infrastructure that will allow them to build AI ready networks. And one of the things that we learned at networking Field A is that's not easy to do. So you may probably look at this and say, $4 billion doesn't sound like a whole lot.
Well, when you're looking at the amount of money that Nvidia and Microsoft and open AI and cloud core, we and all these other companies are throwing back and forth at each other. Yeah, 4 billion doesn't sound like a lot, but $4 billion for a company like Nokia to invest in AI networking. That is a ton.
And I think it's super important because that's the way that the data gets moved from where it is resting currently to where it needs to be processed and run on these inferencing tools and things like that. I'm glad to see that they're, they're doing this. And the, the discussion that we had at Bell Labs, uh, it was actually something that was discussed by Scotton from solution during the Nokia presentation at Networking Field Day.
You know, they have a lot of good data points on this. Like, they've done a lot of work out there. They're really, you know, hitting this pretty hard.
I think it's important to understand that, that just because we're not seeing huge dollar values flying back and forth outside of GPUs and compute clusters, doesn't mean that there's not a lot of research going on. Al, what's your take on this? I think it is important to put context on, on what $4 billion of networking, uh, and particular networking research looks like compared to the tens of billions of dollars that we talk about for buying GPUs.
And, uh, GPUs are ridiculously expensive. Uh, a single GPU can cost as much as a new car. Uh, but you don't need a, a new network switch for each of those, uh, GPUs, you, you hang those g multiple GPEs off a switch.
So in terms of what things cost and, and the scale of investment, yeah, $4 billion is a big deal here. Uh, and as you say, the, the network is often one of the challenges in building an infrastructure for ai. And we'll look at this, uh, again in January with AI infrastructure field day.
Uh, moving the data to feed those very expensive GPUs is a, a vital part of getting the most value out them. This is why network design for AI is a critical part of any AI data center infrastructure design and this commitment to, to do r and d, uh, onshore in the us really great thing. It's very helpful for, uh, the US sovereignty to here to not be looking outside to network vendors that may be Chinese, but, you know, having Huawei and, uh, the likes being on, on the outside these days, um, due to some, uh, concerns around sovereignty.
So seeing Nokia committing in here, supported by the, the current government, uh, hopefully supported by future governments as well. Uh, really good thing to see. Of course, at the same time, AWS is spending lots of money as well.
Uh, AWS is spending the, the kind of money for building entire data centers, so $50 billion for government AI infrastructure. 3 gigawatts of computing capacity across, uh, the government cloud regions that AWS operates, that's, that's pretty significant. We know the government cloud regions are usually slow to adopt new technologies.
It takes quite a while for the technologies to get certified. And I think what we're seeing is US government customers saying to AWS, we, we need this certified, we need these AI capabilities, and we're going to take them from the cloud. So this, uh, $50 in invest, uh, 50, $50 doesn't get you very far.
It doesn't even power the GPU for an hour. Uh, $50 billion is, uh, quite an investment in the GovCloud side and bringing AI to it. Tom, uh, do you see the same thing going on with more and more AI being used in, in government use cases?
Yeah, actually I do. And I think that one of the things that you have to understand about why this is happening is that the government is kind of running behind here, but that's the government's job, right? The government doesn't jump out on the, the bleeding edge and do all of this stuff.
They want tried and true, secure, capable systems because when they buy, they buy for, well, a decade or more. And, and by announcing this huge investment, because we've also got the project target stuff hanging out there and a bunch of other things, this is specific to government agencies. This is kind of, you know, remember Project Jedi?
We've talked about that a lot. Uh, it feels almost kind of antiquated at this point to think about, oh, well, you know, the, the pentagon's gonna be moving into the cloud. Oh, my man, that was, so six years ago now, we're, we're talking about getting up and running on AI tools and, and figuring out how to do all this stuff.
And it's important to note that this is something that was laid out in the previous presidential administration into their action plan. And the idea is, is that we need to start adopting this stuff. We need to start moving along.
But of course, as you mentioned, these things are not sudden. And so I think that the value here is that any advances that are made will probably end up trickling down into other offerings from Amazon. We're not gonna get access specifically to the stuff that's gonna get built out through this big investment, right?
Like that's, that's government is government, and we don't touch government, but the lessons that they learn will be kind of cross pollinated everywhere else. And so maybe we see better connectivity, maybe we see reduced resource utilizations. Maybe the government decides to build a couple of new nuclear power plants to run these things, and we all kind of benefit from that.
Who knows? Maybe the AI will figure out the secret to cold fusion, and then we won't have to worry about power ever again. But I'm not holding my breath on that one.
Well, Al that's, uh, a good look at what's going on in the news. And I know that we're kind of bumping up against a holiday here in the us, but what's the excitement that we've got on tap for 2026 already? Well, 2026 is gonna kick off with a big event, uh, at least for Tech Field Day.
It'll be a big event with the AI infrastructure field. Day number four, uh, we're looking at spending three days out in California hearing from a whole collection of people, including people we've mentioned on this podcast in particular. We'll have NAIA there.
Uh, we'll also have a bunch of other interesting companies talking about how to build infrastructure to support your AI requirements. And particularly I think we're gonna see lots of support for production ai, you know, inference where you get value from your ai. The next event I've got locked in is Cloud Field Day 25.
I'll be back to California March 11th and 12th. And again, we'll be looking at some fun technologies in your hybrid multi-cloud world. Uh, some of the topics we often visit here.
Uh, check out all of the upcoming events on the Tech Field Day website. And you may find that events get added. We've got some interesting things still in the works, maybe in that first quarter as well.
Thanks for watching this episode of The Tech Field Day Rundown. You can catch new episodes every Wednesday, uh, as a YouTube video or on your favorite podcast application. Remember to give us a review.
And maybe a little like in there, the Rundowns also streamed on Techstrong tv. So you can catch us on other tech strong properties, and you'll often find Tom and I at RUM Group events and other fun places. We'll be back next Wednesday to talk about all of the IT news for the week.
That was until then for myself and for Tom Hollingsworth and for all of us here at Tick Field Day, wishing you and yours a great day and a great Thanksgiving Spice flows again on the desert planet. Arra Shy Ude, you're watching Textron Gang, Man, anytime I could start my day with a little dune reference, I'm a happy camper. Um, who knew that it would take some kind of, you know, bad malware for me to talk Dune on Textron gang, but hey, whatever.
I'm, I'm happy with it. I'm happy to go with Dune. Um, welcome everyone to our Monday version of Textron Gang.
And, uh, I hope you had a, for those of you who celebrated the long Thanksgiving holiday, I hope you had a great time, a great time with family and friends and loved ones and enjoyed your day off or your days off. And you're here, refresh ready, eager to get back to work and talk about things that are important to us in the tech world. Uh, we've got a great gang lineup to, to talk about stuff today.
Let me introduce you to them. We have, uh, Terry Robinson, resident Cyber cyber per person, our Silicon Valley. John Schwartz up in Canada.
She celebrated Thanksgiving earlier. Karima, Bal Karima, good to see you. And of course, well, we we're calling him the dean, but yesterday, I think, or at our last show pre-Thanksgiving, we decided he's now a Bard.
The Bard, Mike Ard, um, welcome Yang. How are you today? I hope you all had a great weekend and long holiday.
So, Mike Ude is back. The spice is flowing again on Iraqis. Yeah, the Guild is happy security people in Linux.
Administrators, not so much what's going on. Yeah, things are a little crazy out there. Most of a lot of security folks spent the holiday cleaning up after this mess because, well, shy Ude is back.
It is a self propagating worm this time. It seems to have also included some malware that basically exposed everybody's tokens. So now anybody could just basically log into anybody's repository.
This mainly affects MPM packages and, uh, repositories holding a lot of JavaScript code, but it's a bit of a mess. And Alan, I'm gonna put this to you. I mean, this is not the first time that we've gotten this kinda wake up call about software supply chain security.
But my question is, are we're just gonna roll over and hit the snooze button one more time. You know, this ain't my first worm, as they say on dude. Um, seriously, I, I don't wanna minimize this, right?
We've got a serious problem in NPMs, and it's the same kind of problem we see of across the repo world in general, which is people, because they download it from a repo or from a a package manager, assume all is well, and they, and off they run with their software. And no one is policing these packages. No one is policing the uploads to the reposts.
So, you know, buyer beware, user beware is the, is the day, but is this worm, I mean, we've seen a lot of worms come over the years, right? The worms crawl in, the worms crawl out. This particular UDE two, or the sequel, or whatever you want to call it, seems to be a better version than the original in that it's faster, it propagates better, and it can therefore be more dangerous.
Um, and we've seen this happen too, right? You, you get iterations and reiterations of, of these, of these malware variants like viruses, you know, that's what their name, we call 'em viruses, right? Because they're like viruses in the real world that are constantly evolving and evading, right?
It's a cat and mouse game. And now we see the next variant of Shy Haute. Is this gonna be the last one?
Probably not. I, the bigger issue though is what do we do? We all, you know, 80%, 75% of the software in our apps is downloaded from JavaScript repositories or Artifactory, you know, artifact repositories or, you know, Maven Java, or, or there's so many different repos where we get our software docker containers.
Um, there are, you know, what do we do? There are a lot of companies that are now starting to put out safe packages, safe distros safe containers that they certify, you know, for these common, and, and, you know, you can't have one for everything. 'cause there's millions of different variants.
But for these very popular ones, we have a, you know, a clean version that we guarantee is clean. And if you use our stuff and use that, you're okay. SUSE does it for one, right?
Uh, there are others. Maybe that is where we're headed that because it, and I've said this before, I lay this at the blame of the, of the repo managers of the maintainers, I think they have a duty to make sure what goes into their repos, into their collections is safe. So that's where I am.
Did they, did, you know, you talked about do we roll over and hit the snooze button, whatever rollover? Um, is that what happened between September and now? Um, or did this just come so quickly?
No, no. This is a new variant. Okay.
This is definitely a new variant. You, it's, look, this is a virus and vaccine, right? You, you change the, the DNA coding or the cellular coding or what have you, and it evades what you had before.
Mm. So though you may have thought you were protected against shy ude one, this, this is definitely is a, a, a better version of it. That's more insidious Mima are developers just frankly spending too much time engaging in what you might refer to as unprotected downloading, I dunno, Right?
I mean, uh, to build some more context, and I'll come to that question, uh, Mike, uh, in a while. So what this, uh, virus is, uh, all about, this is a major cyber attack, uh, which is also very fast moving and dangerous as, uh, the article refers to, because it hits the supply chain. And what it does is it does data harvesting, it steals developer credentials.
For example, if you have open credentials in your, like, you know, ecosystem, API keys cloud tokens, and it exfiltrate them to a public repository, right? So when this infected packages are installed, the worms harvest developer credentials or API keys or cloud tokens, and then, you know, uh, you can kind of, uh, be susceptible to end number of, uh, you know, attacks like secrets from your local environment, CICD pipeline. Your credentials are kind of, you know, at a risk and stolen data, for example.
So it becomes a Dropbox for stolen, stolen data, for example, right? Mm-hmm. So now, what we can do as practitioners and developers, I mean, uh, the first and foremost thing, I mean, uh, Ellen, you mentioned about this.
Many organizations have been, uh, working tightly, uh, with this open source ecosystem. Our good old friend, Tracy Reagan, for example, is heavily invested in open SSF. And, uh, we have from CD Foundation, there is a sig, which looks at these kind of, you know, practical cyber attacks on CI ICD pipelines.
There, uh, there are assessments and audit mechanisms available. Now, what we should be doing as an organization, of course, you know, there are, uh, from enterprise perspective, we always have wrappers, for example, right? Security, uh, guidelines to kind of ensure and secure our environment.
But more or less, I think it also, uh, is a strategic imperative for defenders. You know, how do we build robust supply chain audits, for example? And this is not something which is like off the table.
I mean, you have to do it because, you know, these attacks are getting even more smarter, like dependencies to detect an anomalies. For example, unexpected pre-installed scripts, which in this case you will see that, right? Suspicious package updates.
So these are things which you should actually monitor your system for credential hygienes least privilege. Uh, of course in if you expose your credentials. And it's like a mind risk of, you know, having, uh, these attackers to kind of, uh, also decipher it.
Also, I think, uh, from a hygiene perspective, it limits the possibility of what your application could do. Proactive threat hunting and anomaly detection. I mean, we have been talking about chaos engineering and all those kind of things.
It's time we take it seriously, right? So if this kind of attack happens, what is, uh, uh, the, uh, posture, we have to hunt them back and to try to kind of be, uh, from a real time perspective, uh, more proactive in, um, detecting as well as, uh, protecting our environments, collaboration with open source communities. I mean, uh, it is leadless to say, if you're not aware of what open SSF, uh, foundation is doing, CD Foundation is doing, um, talk to, uh, some of our, like, community leaders like Tracy Reagan, and there are many more in the ecosystem who can actually guide and help you in this direction.
And, uh, more or less, I mean, it's a matter of education and awareness. I mean, uh, again, these attacks are not new. It's just faster and more dangerous, as Ellen you mentioned, right?
So how do we educate our ecosystem? How do you invest in more like AI native defending technology applications, which can defend your kind of, you know, um, applications, uh, from these attacks? And I mean, from long-term attack patterns perspective, it's evident that this supply chain risk persist.
You know? So we have to think about how we manage these, uh, malwares. We, how do we manage these risk attacks, and, uh, how do we ensure that automated self replication doesn't happen, right?
Credentials, thefts, and, you know, reuse of these kind of attacking mechanism do not happen over and over again. To your point, Terry, you know, what we were doing from September to now? I mean, it's a different form of form, but then again, uh, is our poster improving?
Do we have taken enough action on this? Right? And again, it's needless to say that, you know, one of the most important things, which will change our developer's profile is how security savvy we are.
This is what, like, you know, how your, uh, developer ecosystem would change is so Garima, I, I've gotta disagree. Yeah. As someone who is in instrumental in starting the whole DevSecOps movement as being real, one of the lessons I've learned 10 years doing this is don't throw this on the developer's shoulders.
It's not the developer's job to be the security professional. It's the security professional's job to be the security professional. When the developer goes to a repo, whether it's an NPM or artifact or Maven or wherever they're downloading their software from GitHub, there's got, there's gotta be a level of trust or docker containers.
There's gotta be a level of trust that what I am getting from here, at least today, that may wind up down the road. I find out there was a bug in it or something. But at least today, it's free from this kind of worm.
It's free from this kind of self-replicating Trojan. And to say, you know, buyer beware, it's on the developer. When the developers downloading literally dozens of these from different places, you know, packages and components and scripts.
I don't think that ever works. It, it hasn't worked. And we've come down this road in DevSecOps, don't, the developer has enough on their shoulders.
We, you know, we came up with the whole system of SBOs. That's something we haven't mentioned here, right? SBOs was supposed to help secure the supply chain.
No. And SBOs a great tool for forensics, right? What did this have in it?
Where did this bad? How did this bad piece get put into my package? Into my pipeline?
But it doesn't really address this issue. And I, I, and I've been preaching about this for years, we need repo firewalls. When before you can download something from a repo, it has to, you know, JFR has it for Artifactory, Justin, it's called X-ray.
But we need one that's generic that goes across reposts and, and either puts these scripts and, and, and so forth in a sandbox and makes sure that they're free of malware or something. So that a developer has a high degree of, of, of, uh, certainty that the, this software is, is good to use, otherwise you're just making the developer's job impossible. Well, yeah, I hear you.
I think, uh, um, I agree with certain aspects of what you're saying, but it's also not this or that, right? I mean, you, uh, have actually put forward a very good point on, you know, what kind of security, uh, loopholes we have today, which we can restrict or have strict control on, which probably, uh, be the job or responsibility of the security professionals. But let's assume that this attack happens.
The defenders are, you know, if they are not supported by the developer ecosystem, they would be be failing at that point in time. So this is a cross-functional collaboration like vulnerability disclosure, or transparency of dependency of, uh, you know, on, on dependencies or, you know, health of the, uh, code itself, the, the, the whole, you know, rapid patching mechanism. We need some kind of, you know, ecosystems to support that.
And the developers need that support. But I think it's also needless to say that developers also need to move and shift in the direction to understand what kind of modern attack patterns are happening, what kind of hygiene in, you know, coding needs to be kind of put in practice. What, what collaboration your security professionals would need.
If you don't see the guardrails in the CICD pipeline, would you be the whistleblower and try to kind of ensure that this collaboration gets developed? So I think there is some kind of potential in, you know, securing that collaboration. Of course, we have been talking about this since like two decades now, Ellen, you know, about DevOps and DevSecOps and mm-hmm.
Those kind of, uh, definitions and, you know, how do you put this into practice? Into, but I think the sweet spot lies into the synergy rather than building, like, uh, hard boundaries. I think it's, and shared, shared responsibility kind of, you know, on, on, on both sides.
Yeah. Alan, it's not fair to just put everything on the developer's shoulders. They're not security people, but they have to be somewhat savvy in security, you know, for all of this to work.
I, I, I think in, I Mean, if you're a security person, the way you look at this is you go, Hey, I told you not to go and engage in that behavior. And you went engaged in that behavior, and then you came back and I patched you up and I sent you back out there again. But now you're just gonna do the same thing over again.
And eventually, like a good doctor, they just shrug and go, I'm telling you not to do this, but you know, you gotta, at some point stop doing it. It's right. And going out and committing the same sin over and over again.
Wait, what? So, so like in theory, you're talking about all these prescriptive measures in this history, but I mean, when I read both these stories, I come to the conclusion of pace. It's always about the pace and the pace is just getting worse.
Yeah. Yeah. And it's probably gonna give, so you're talking about a thousand new repositories re uh, surfacing every 30 minutes, which is significantly more than the previous iteration.
At the same time, you've got more code being developed, which is just gonna increase the number of repositories that need to be secured. So it's just like this escalating math. And I, I know it's not easy to solve, but it's, that's just a terrifying takeaway for me at least.
Yeah. And portion of this code is written through ai, you know? Right?
Yeah, exactly. Yeah. 0, I'm pretty sure that's Coming.
That's coming too. Look, Yeah. Yeah.
So Shy Ude happens to be the one hitting NPMs in JavaScript. They'll, they'll, they'll be the Barron Koan next on somewhere else, right? And the Paul Lares, the Modi over here.
There's, we've been, we've been naming these worms for as long as I've been in tech mm-hmm. From the Love virus. Remember the Love bug virus or whatever it was called to love bug codex, code red, you know, there, there's, there's always a next one.
Well, we Need, We need another sound novel. We need a sanitary, a, a a checkpoint charlie for these things. Oh dear.
So anyway, Hey, we're over time on this, though. We gotta take a break. We, I'm sure we'll be talking about it again, unfortunately.
But you are watching Textron Gang, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions, your home life included, that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back in, well, interesting times in the land of social media, but we may have some actual transparency into what's going on, or at least a little more political chaos. But apparently the folks at X are letting you see where the account is that somebody is actually following. And turns out some of the political accounts are in places that are not in the United States.
They're in Africa and all kinds of places. 'cause somebody's paying for that. But John, is this gonna become the new standard?
Will everybody have this level of transparency, or is this a one-off kind of thing and it's just gonna go away? You know, it may be a one-off based on what's happening with X. Uh, this is, I mean, we talked about Dune.
How about Dr. Strangelove? This is like some dark satire that, that, you know, I know the intent is the intents to, for security purposes.
So there's this transparency tool that X introduced over the weekend that re reveals accounts that claim to be, they claim to represent American political views. And what they're finding is that, wait a second, through their geotracking, they're finding that they're coming from overseas. So I'll give you a couple of examples.
There's, there's an account called Ultra Mag Trump 2028, which claimed to be from Washington, DC Well, it's actually from Africa. There's another account Where in Africa though, John, I, I don't know. Well, because, you know, I have a Nigerian prince who runs a lot of these things.
Alright, well, good. So there's another, exactly, there's another account that shows up that's, that's, that's coming from Macedonia where it was subsequently deleted. Then there's another one, uh, called just, uh, ampersand American, which is a bald eagle for flag.
And that originated from South Asia. So that's all well and good. So they're identifying these, there's a one little glitch over.
So some reporters started looking into it, and the accuracy is not always on the spot. So NBC for instance, they had several of their reporters display their locations where they had recently traveled, and that's where they were located rather than where they're actually based, where they do their job. Um, the controversy got even worse when there were some viral screenshots that claimed that Department of Homeland Security account was based in Tel Aviv.
So that was, that was disabled the same night. So DHS has issued this denial stating the account has only ever been run and operated from the us. So X is finding itself scrambling, trying to, trying to fix the accounts that it got wrong.
So we don't know what the percentage is. I think it's highly accurate, but there's just enough to leave doubt. And again, I, I mean this, you can't make this stuff up.
When Mike sent this to me, I thought it was a satire. And then I started reading some accounts in NBC and, and BBC and elsewhere. And it's, I, I know the intent, but the execution as it always is with x, is a little off base.
It's so funny too, though, I have to say, if you've been sort of online and watching this, like, you know, on, on X and people, you know, chatting or whatever, now there are some commenters who are using this like, as a bludgeon, right? Against MAGA or whatever. They're like saying, they're just dismissing whatever they said because they said, oh, well that was from Nigeria, that was from, uh, Russia, you know, or whatever.
So it's been a little hilarious to watch people try to respond. Well, you know, the one, one of the thing I should have mentioned was, um, that's right, Terry. One, one thing we wanna mention is that, that this just like, to me, confounds me.
They, they, it's like an Elon Musk move. They eviscerate their technical support. They get rid of all their, their engineering talent.
Then they try something like this. For what reason? I'm not quite sure.
And it just blows up on their face. I mean, what did they expect was going to happen? This is not the first time this type of scenario has unfolded at X.
But again, I couldn't, then again, I shouldn't be surprised 'cause of social media, Well, didn't they like test this out before they sort of made it public? Or what O extensively You would think. Yeah, Go like, baby, like, You know, have Two people testing.
That's, that's the valley. But, but guys, let, lemme lemme play devil's advocate here. I think this is a great thing because anything that gives us a little transparency on the fake news of social media, and if we remember right, that's why Elon supposedly bought Twitter, the bots and the fake stuff.
He was going to, you know, eliminate all of that. Now, my friend Andy Ellis, who's a pretty well known ciso, he was, was CSO at Akamai for 20 years. He, he posted something on this, and it was around the, the supposedly, uh, pro Gaza news media and news and Pro Gaza X accounts that it turned out none of them are actually in Gaza, right?
They're all reporting from Gaza, but from somewhere else. And I'm not saying that makes it any, I'm not getting involved in the Israeli Gaza. I thing I, you know, but it's that kind of transparency that I think we'd all applaud.
Hey, all these people who are, are supposedly MAGA haters or MAGA supporters, it's good to see that they're coming from Venezuela or China or North Korea or South Korea or wherever. Right? It, it, I think it does give us transparency that we all would, like, my problem is what stops a Chinese deep state, uh, uh, campaign activity from flying into Nigeria or Venezuela or Brazil and carrying this on from there.
So at least it doesn't point back to China, right? It points to Brazil rather, or for that matter, what stops it, the now that this is the cat's outta the bag, what stops them from using Chinese nationals who are here in the us Right? So while I, I think it's a great idea and I applaud it.
I just don't know how effective it'll ever be. Yeah. Yeah.
The concept is good. This is, the execution is flawed. I mean, but yeah, It's, I just want the other social media platforms to follow suit.
I mean, some transparency is better than no transparency. Yeah. So I wonder if this raises the bar.
Well, okay. And I agree with all of that, except that there's also a whole facet of our society that doesn't care about the transparency. They're gonna believe whatever that stuff says, they don't care if Elon Musk and them find out it's from Nigeria or Moscow or wherever.
Right? They're, um, they're going to, they're gonna stick to the narrative. I guess that's a whole different problem.
And not, Well, there, there is that, right? That's the Joe Bels, Joe Joe Goebbels social media view. If you say it loud enough and often enough people believe you.
Yeah. I guess, you know, when they forward that stuff to me, I just want to know where it came from in the first place so I can at least have something that feels like a rational conversation. I also feel this is a generational thing, right?
I mean, uh, we would see more generational awareness about how to treat social media and what kind of social engineering happens in the background. So, for example, me being from a millennial club, we are a bit more aware. But I think, uh, moving on, I think the Gen Zs and the gen Alphas, I think they're very conscious about their choices.
And I think the social engineering of, uh, you know, politicizing things, I, I think this will not be something which is something which we have seen so far. Yeah. Agreed.
Agreed. I wouldn't be surprised to see, uh, meta try, try to use this concept. Yeah, I know.
I think we'll see copycat here. Yeah. Yeah.
They're all gonna, we'll definitely see, and, and here's the thing. As we get other social media companies copycatting this, they'll continue to refine it. Mm-hmm.
Right? Uh, 'cause like I'd like to see is, okay, so this account that's in Nigeria, what's its history, right? Where, what, what's the connection here?
And, and see if you can start tracing it back. And, and maybe that's the first steps towards retaking, right? Taking back our society from, from the, the fake news.
I would also wanna know how much of the content of AI generated, I'm not saying they don't use it, but I just wanna know like, how much of this is noise? Well, not all AI contact is noise there, boomer? No, it is not.
But a lot of it is, you know, somebody created sort of video that doesn't exist. And, you know, it's like, I wanna know. Yeah.
But it's a matter of trust also, right? I mean, even if it's not noise, nobody trusts us. Well, but, and that's the whole thing.
If we're gonna have trust and if you're gonna be able to, you know, look, Terry, to your point, people who are living in an echo chamber and just want their particular message reinforced, don't give a crap whether it's fake or not at some level, right? They just wanna reinforce their, they just wanna Reinforce their bias, Right? Yeah.
But for the rest of us, and especially for young people, 'cause I think young people are savvier and, you know, I made fun of Mike, I'm older than him, you know, young people are savvier than we are. I'm getting tired of, you know, people coming up to me and showing me stuff on social media, and the first thing they ask me is, is this true? Because nobody believes anything anymore.
Anyway, so, but it's crazy. But this is the same thing. 90% of developers use AI and 40% of them don't trust it.
But they use it anyway. They use It anyway. Well, you know, it was interesting, and not that this is so related, but I had, um, recently an estate sale at my mom's house.
And one of the things that they, when they staged everything and, you know, whatever, it was all great, but they had my, my world book encyclopedias. Oh, I loved the World book. Yeah.
From the sixties and seventies, right? Mm-hmm. So I had every, like the yearbook that they put out every year.
Yeah, yeah. Whatever. And it got us to talking about like, how we were kid when we were kids.
We would consult the World Book. And it seemed to be the authority on, you know, It was A certain level of How many reports did you write using your world book? Of Course.
Exactly. You know, and, and, uh, my fiance said that his dad, like if they were at the dinner table and they ask a question about something, his dad would say, go get the World Book and let's look at, You know what, I'll show you how crazy we were in my house. My brother, I have two brothers, but the one closest to me, we would each take turns with a different letter every night.
Because we remember the World Book used to have the transparency, like the human body, the circulatory system. Oh Gosh. My favorite one Or, or one, you know, about exotic places that we wanted to visit one day.
My brother made that list and kept that list and he's visited all those places. That's, Yeah. You know, it was, it was the source of all knowledge, Those trans That was back, that was back in the day where you had the encyclopedia.
You had like only three networks and you could basically trust, Oh yeah. You had three, three networks and you had the World book, or you could go down to the library And not, not, not criticizing, getting a lot of information from a lot of different places, but there's something to be said, like when you just had the three networks, there was a certain amount of journalists discretion. Right.
You, they chose what was sort of important and they didn't necessarily hype, you know, sort of bsy little, Their view of things, view of, but you knew Walter Cronkite was in CBS headquarters in New York and Yeah. And, and so was Huntley Brinkley and whoever else was on, uh, a, b, C at the time. Mm-hmm.
But Right. It was, you didn't have the subterfuge of I am in the Congo. And, and you know, commenting on, on what's going on in the US or, or what have you.
It was a simpler times. So, So let's bring back World Book, social media site. What do you see?
I know, I, I see, I see nobody. We'll read it. Only us only, only the oldest.
Oldest. I see a niche for World Book book here. You know, I really, Well, you know what?
I can have AI draw me up one in no time. I don't know. Those transparencies were the bomb though, Amanda.
They were, they were. I used to trace over them from my book Reports. Yeah.
Too. Me too. Reem is looking at us like, what are these old people about?
He's like, what the hell are you talking about? Another, but the rest of us remember. Yeah.
Okay. Alright. Hey, let's take a break here.
We are coming at you from Boca. I'm at least in Boca Raton, Florida. You can count on it.
This is Techron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back in. By the time you're watching this, Alan and I will be in Las Vegas for AWS Reinvent conference.
And we're already been a steady drumbeat of news and issues coming up before the conference, including AWS is now using AI tools to accelerate migrations to their cloud platform. And we'll also see things like, well, Sumo Logic will be talking about how they're gonna reinvent their entire approach to AI using AI agents for security and observability and collecting telemetry data. And there's just gonna be a ton of stuff.
AWS will also be, of course, highlighting their Kero AI agent tool that they are proud of the fact that it is, uh, specification driven. So if you watched any of our previous shows, you know what that's all about. But it's a more reliable way of creating AI Coach, shall we say.
And they're gonna be touting in the fact that, well, you know what, we can get better AI coach, but there's just gonna be a lot going on. Alan, I know we've been in this show in the past, and you're gonna be doing some videos while we're out there. But, um, what's your take on the state of AWS Well, yes, we we're gonna be doing more than some videos, Mike.
We're really booked up for the whole week there. Um, looking forward to it. I, you know, the state of AWS is, they're still the 800 pound gorilla in the cloud hyperscaler space, right?
Google, Microsoft has had, have had some good runs. Oracle Clouds had some great, well, they have one big customer that accounts for two thirds of their business, but nevertheless, they, they, you know, they have some money on the books. Um, but AWS is still the undisputed king and heavyweight champion.
I think we're gonna see a lot of announcements. It's funny, I've got new next door neighbors. Their son came in for Thanksgiving, turns out he works for AWS and their generator of AI team, and he's presenting at Reinvent, so I'm going to hook up with him out there.
Um, but the beauty of reinvent is it's not just AWS you come for AWS but you get everything else because literally the entire ecosystem is on display there, you know, flashing their wares. And, um, so it's a great time to hear stories. I, I will tell you that our text Drunk TV coverage, which we will be streaming live Tuesday, Wednesday, and Thursday at, uh, from Vegas, uh, is sponsored this year by Susa, who has a huge rollout of, of, uh, related announcements and technologies around AWS and of course, AI and the Edge and everything else.
Red Hat is, is very, very much engaged there. And so you think about that, these are not necessarily companies that you think of as, you know, big AWS components because you need to go, you know, to run, uh, OpenShift, yes, it's available in the AWS marketplace, but it's probably not the default. Same thing with suse and rancher and those kinds of things.
So, but just like Mike in the last year or two, look, the big story is gonna be ai. Mm-hmm. I think the big story this time will be a agentic ai, where last year was more generative, but AWS you know, from investing in anthropic to, to doing bedrock and kiro have, have not shied away from being an, uh, an AI friendly hyperscaler.
Mm-hmm. They don't have necessarily Google's position in ai. Right.
Google has that vertical integration that's hard to beat. And they, they are, you know, their stocks flying. They're a $4 trillion company now.
And and I think people are recognizing that they, they have a, you know, a catbird seat here coming around the, the bend in the AI race. They don't have Microsoft's GitHub and, and all that comes with that and their open ai, uh, relationship, but they, they seem to be much more open to everybody's ai, right? If you've got some AI stuff, we'll run it on AWS and I think that's what we're going to hear a lot about.
I think there's one shadow that will show up in Las Vegas, and it's this whole notion of sovereign clouds. And folks are kind of think talking more about moving workloads from one cloud, maybe into an on-premise environment or something that they have more control over. It certainly is a bigger conversation in Europe these days.
And maybe our friends in Canada as well. Well, well, SUSE s my Mike, Mike suse has a whole it sovereign cloud right. Division now.
And even though AWS these days is talking about using AI to migrate existing workloads into their cloud, AI will go the other way, right? Mm-hmm. These things mm-hmm.
Will enable people to take workloads more easily out of an AWS cloud and move them to either another cloud or something else. But Karima, what's your take on what's going on here? I agree with you, Mike, and you know, I'll connect the dots here.
So sometime back, we covered the story with, uh, open AI and AWS partnership, right? So we had speculations at that time that which regions will be benefited out of this, uh, partnership. We saw that Silicon Valley might be like, uh, the key contenders for it, right?
And then the uc that they have launched this tool AI capability, uh, AWS capability tool, which is basically providing you insights into regional capabilities, uh, of services, uh, which AWS has, and also forward thinking roadmaps. So, I mean, pros are obvious to understand. What I will, uh, talk about a little bit of the cons, like how the AWS ecosystem is, uh, you know, developing and ensuring that, you know, they probably move the workloads in the right regions, you know, for the sake of sanity.
I would say that, you know, they have not integrated it with the live, uh, like the console management system, but they are putting it as a dashboard. So the AWS capability tool will give you more possibilities to see through what kind of regions are more proactive forward thinking, what kind of pre-deployment integrations you could do, and also talk about the cost and risk, right? So it's kind of, you know, I'm yet to kind of see if this prediction of mine or this speculation of mine is, uh, to the point or not.
But I think this is driving workloads in a, in a pragmatic way to some specific regions for some specific capabilities. Of course, this, uh, tool, which we have talked about, uh, the AWS capability tool, they don't advocate, they just say that it's a planning tool, right? But you can influence the planning, right?
So I, I would see that, you know, that can be one of the possibilities. And then, uh, like capabilities, like Kiro and all these other things, I think there will be some announcement made, uh, kiro for, uh, sure, because it's of interest, it's an id and they, they compete in a large scale kind of ID ecosystem. So it would be interesting to see what they're doing there.
You wanna know something else? I'm looking forward to what's Google's counter programming, right? The last couple years at AWS, Google's always done something on site or around site there to say, Hey, we're here Last year, I think they took over the outside of the sphere and made it into the Google colors.
Um, so it'll be interesting to see what, what Google goes there. But look, it's, you know, it's 60,000 people. It takes up a good part of the strip.
I'm, I'm looking forward to it. You know, what I'm looking forward to, I'm looking forward to discovering that X thinks that Techstrong is now moved to Las Vegas. 'cause we'll be tweeting And while y'all are there, And I'm also looking forward for some kind of a cloud diagnostic, uh, days, uh, you know mm-hmm.
Looking ahead of like how we compare AWS Google and other platforms like Oracle. And so clouds, uh, for example, like Canada has their own cohere. Uh, but I mean, from cost constraint perspective, it'll be very interesting discussions, uh, moving on, Right?
I'm, I'm with you. I, I am. It's been a long time coming, but I feel like rational conversations are finally being had about where workloads go and AWS is fine, and it's a good choice, but it's not the only choice.
And I think people are getting smarter about maybe not locking themselves into all those proprietary APIs, and they're figuring out, well, let's let the workload decide where, You know, they, they make the exact, you know, it's funny you say that. They make the exact opposite argument when they talk about, and we've done a series of webinars here on, uh, with AWS partners on modernization and transformation and basically moving off of VMware mm-hmm. At an on-prem level, right?
Because you're locked in to their pricing and their licensing and everything where AWS actually offers you choices, right? And, and so, you know, some people don't view it as a lock in, Right? Well, what they're really saying is, give up the VMware proprietary APIs in favor of our proprietary That's Meet the Boss, same as the old boss.
Takeaway from That Was the takeaway From the webinar. Weve The Fool Again, it's a good place to end today's show. I think Meet the new boss guys boss.
Have a great, have a great, uh, Monday we will be continuing, I think we have one more show before we'll be live doing Gangs live in Vegas at, uh, Textron for Textron Gang. We'll probably do our first show there Tuesday. So, uh, hopefully then.
Until then, though, thank you for joining us as always here on the gang, Terry Garima, Mike John, thank you for of course, lending your thoughts into this. Thank you for watching. We've got a full text on TV following, but for now, I'm Alan Shimmel and we're out.
Hey, everyone, welcome back here to Techstrong tv. So, I, I want to introduce you all to Guy or Razzi. Uh, guy is someone who has deep expertise in the security cyberspace, as we call it now.
I still call it security, but, uh, in the cyberspace guy is also the co-founder and CEO of a, of a cybersecurity startup that's in stealth right now. So we won't necessarily be talking about that company. We're gonna talk more with Guy and around, uh, a well, what else do we talk about?
AI and adversaries in ai, AI and security? Hey guy, welcome to Text on tv. It's nice to meet you and it's nice to have you on here.
Thank you for having me. Appreciate It. Pleasure.
So, guy, why don't we start off maybe kinda giving our audience a sense of who you are, where you've been, what you do, what you've done, right. Establishing that. Yeah.
So if you wouldn't share with us. Sure. Um, first of all, as you said, I'm Guy Razzi.
I was born and raised in Israel, started off security very early on in my life, even before I had something that's called career. Um, I guess I was very interested, uh, in security and the way you can bypass security boundaries, uh, of the software. So I was doing some cybersecurity, let's say, stuff in the intel, like in the intelligence for the intelligence in the Army.
Um, and basically my first official role was ciso. I was kind of high level, uh, doing audits and running penetration test reports, but then I wanted to go even more hands-on, uh, because I wanted to go back and, and be on the offensive side. Uh, kind of like in between the blue team and the red team.
So I joined Bank of Pauline. I was leading the application security deal. I was also a few months in doing some research, and then I spent the next seven years in Microsoft.
I started as a security researcher for Microsoft Defender, EDL, where I was basically, uh, founded the ransomware re detection vertical. Um, when I go to Microsoft, I only detected the issues on a single machine, and I had some crazy vision on how to connect the machines, uh, in, in an enterprise. So you can detect network infections and stop ransomware from compromising with data network.
And then, uh, I was a vulnerability researcher for Azure. And in my last, uh, year at Microsoft, right before I left my to do the startup, I was, uh, uh, at M-S-R-C-M, SRC is basically the Microsoft Response Center, uh, was in a security research team called Mitigations and Vulnerabilities. We basically got like all the reports from, uh, externally sell, uh, externally sell sales, like all the vulnerability disclosure, ty program, anything that basically comes to Microsoft and get out of Microsoft, uh, in, in terms of security.
Very interesting. A lot of issues, but good issues as well. And you have to come up with brilliant ideas on how to mitigate them.
And I also spent two years in Palo Alto Networks in between. Really? So you went Microsoft, Palo Alto and then back to Microsoft?
Yeah. Interesting, interesting. Of course, Palo Alto just bought last week, they announced, uh, Chronosphere Yeah.
With three and a half billion dollars and for, uh, observability. Yeah. But Guy, you know, you know, there's this old, they call it an Irish proverb that you live in interesting times.
We certainly are living in, in interesting times. Not to say that security wasn't always an interesting place, let's say, right? But with the advent of ai, the, the mission, well, attack surfaces have expanded.
The mission has changed in many ways. You know what they say, God gives and takes away. God gives one thing and takes away another with ai, it, it could truly be a gift to security and, and helping us to do security better, but it's also a gift to our adversaries, right?
Who are also not stupid and are very well organized. They're well financed and they understand. And so, you know, at the, it, it's both a weapon and a shield, if you will.
It could be used as a, as a offensive and defensive. Um, and, and the thing is, is it's fairly new, right? When, all those years ago when you were in, I, I'm gonna assume it was 8,200 or, you know, within the IDF, they weren't really, this wasn't really something you guys were using back then, or, and if you were, don't say you were, but, um, you know, it, it's in, in many ways changed the game.
It did. Talk to us how it's changed the game and what kinda what's you, what, when you look at this landscape now, what do you see and what do you think? Well, like companies produce code in an insane way right now, right?
It gets a more business. Um, they can hire less people and they can just ship features and products. It's, it's very appealing.
Um, but on the other hand, even even before AI was introduced, product security teams and application security teams couldn't even handle the, like, the burden, right? Yeah. They had like, had backlog, a huge backlog of issues that they had to fix, and they were trying to chase off their developers to fix it.
And nothing was really moving the needle. When AI was, uh, introduced, then there were many startups and many companies that just use AI to deal with that backlog. But developers still don't want to fix those issues because in most cases, they're either false positive or it's might, it might take them too long to fix it, and it's not part of their KPI, like, no one measures them on like, how well are you doing security in our company, right?
They measure them by how quick can you ship it and if the feature is actually working well. And I think that probably the biggest issue is when, when ai uh, when AI is being leveraged all across big enterprises, it could be different antipas. So there is some code that is being used, then agents may assume that this code is already valid and it's, uh, uh, like it can reuse it.
And then it's, you reuse it in 50, a hundred different places and basically create something that might be a more of like a systematic issue without anyone understanding. Now the product security team or duplication security team, or the same size, right? They never grow and they never grow more than, uh, the developers.
And on the other hand, they're still using the same traditional tools that they had in the last decade. Maybe they are, some of them are branded with ai, but they have the same approach, the same architecture. And in, in my opinion, it's a double edged sword because no one know right now what are the actual vulnerabilities that are laying in their software.
And, and, and, and that's probably the biggest danger. They're trying to kinda walk in a land of minds with without realizing where should they step. Now it's either it's a false positive or they're either getting compromised, but they need to decide like, what is the next thing, next thing I need to tackle.
And in many cases, our biggest advantage as human is to use humans, uh, to find human issues or agent issues. So you can see things like, especially in Microsoft, it was, um, it was something that went really well. We used external researchers to help us validate features and products that are already in production in case we, we missed something in the threat modeling or the scanner maybe didn't pick up, uh, a, a specific issue.
And then we kind of under trying to understand if it's part of a biggest, a bigger issue, if it's a systematic issue. Because AI cannot say if an AI is wrong, right? You need some human to label that specific issue and say, this is wrong.
This is right. At the end of the day, it's like, it's statistics, right? This is how AI works.
If you wouldn't tell him, uh, or you wouldn't guide it in a way that fits you. And again, enterprise are different. Everyone mitigate different issues in a different way.
It's gonna be very, very hard to, uh, overcome these issues. And I think this is probably the biggest way that, uh, I see as the double-edged sword because we're still using the technology, but we have no idea how to defend against it. And adversaries are, you know, they're just out there using the same thing.
But, you know, guy, I, I've been around a long time in this space and, and this and this, and it's not just insecurity. I think this is very common. When you dealing with an adversarial kind of thing, you, you tend to over, uh, you, you give them more credit than their due.
Do you know what I mean? You, you think, boy, everything I do where the, we're the am we're the apple dumpling gang, we can't shoot straight and the other guys are marksmen, right? They're fantastic shots.
Do you really think, I mean, look, AppSec has been always playing catch up for a long time. And, and I wanna say it's almost not their fault, but it is, right? Uh, we don't put the budget and resources necessary, but it always seems we're playing catch up there.
Do you really think though, that the adversaries are this sharp on ai, but they're not going through sort of the same growing pains, learning cycles that we are? They do, but their KPI is pretty straightforward. Uh, it's either they compromise or they don't.
Right now, they might compromise, um, a year ago, and you might know in five years from now, if an attack is executed properly, you would never know it existed maybe in, in the next few years or in the long term, like in the long future. Got it. And that is part of it too, right?
That these guys play the long game where, I mean, quite frankly, look, most budgets for AppSec enterprise companies are, you know, quarter to quarter. You know, and if you didn't get attacked this quarter, that means that nothing happened this quarter, would it very well might have something happened, but you won't see it till next year. So it's a different, it's almost like you're playing by different rules, by different time parameters, if you will.
Um, so I, but I guess this begs the question though, guy, of what's a poor company to do? What's a poor enterprise? What's a security team to do?
What can we, you know, it, it's, it reminds me of the old story about you take like a, a, a blind person and put them in a round room and tell 'em to find the corners. You know what I mean? It's not fair.
So what, what can we do here as we kind of fumble in the dark to prevent these kinds of things from taking place Just to make sure that we're aligning our prioritization? Uh, the most volatile and dangerous, uh, indicator that we have in the product security realm is probably, there is some idea, some insight, some report that claims that they can compromise your company. Okay?
Now, researchers, they like trophies. I also like trophies. We, we all do.
Now sometimes we might share it with a friend, we might share it with the social media, and adversaries are just listening for that. Now, you might fix this specific issue, uh, from that specific feature, but it, if it exists in other features, they take this specific issue and try to expand it into attacking all your features and other products with the same technique. Now, you might think that you found everything and, and you might not.
And that's the race. Like how long, how fast can you detect it? And, and especially when it's already like a public insight or, or something that is already out there, you need to make sure that you're prioritizing this insight out because that's exactly what adversaries see, right?
They're not assuming that they might breach you through this technique. They know that someone managed to get into your systems using some approach. And if this approach might cost them, I dunno, $10 to attack all your infrastructure right now, it's probably gonna be more what, more than just guessing.
Maybe they're using this tech stack, maybe they're using this specific library in this specific way. Um, they don't need to assume they know something real happened and then they take that, by the way, it's same with ai. They take this specific insight and they try to use, like, they try to leverage it as much as possible.
Absolutely. Absolutely. Um, so again, what, what can we do though?
Like what steps do you think we could take? Yeah. Anticipating this.
So I, I think that, um, any insights that basically, uh, compromise your systems, something like any, anything like higher critical that has a proof. So someone already shown you either from your vulnerability disclosure, your pen test reports, even if like, I dunno, like an internal engineer or developer found something that could be significant, you need to prioritize this over adult things, especially when it's like a written insight. Take this specific report and see if you can find this issue, um, as a bigger, uh, systematic issue and try to carry re remediation for that specific thing.
Then probably the next thing would make sure that you are not repeating on the same issues, right? Because you might, you might remediate it, but the organization is still developing in the same way. Maybe one team is aware of it, but the other one isn't.
Now it's like a whack-a-mole game because there is no way right now to automate this unless the product security teams can be like one-to-one, to every feature group or every department development. And I think that it would just be try to use AI as, as, as, as much as possible to make sure that these things are not happening over and over. It could be implementing local rules in your cursor.
It could be creating some designated prompts for copilot to pull, like to create a, uh, uh, pull request reviews to your changes that you're about to push to production. There. There are many ways and, and it really depends on what is the specific issue, but I guess this is where I would start from.
I love it. Yeah, I agree with you. Let me ask you philosophically Do it.
You know, I always say we're still kind of, almost at the beginning of the beginning when it comes to using AI and how we're going to integrate it not just in security, but in, in our daily lives, right? And, you know, in our jobs across the board, do you think this is a problem that gets worse before it gets better? So in other words, is there gonna be a gap between solutions versus, unfortunately the, the adversaries, you know, doing these bad things.
And like we talked about before, it may be years before we realize these time bombs have been planted already. Interesting. Yeah, I think there'll always be gap.
Like as long as the technology enables you to do something, it goes either way. It has to go either way. Uh, the the strange and, and the cool fact about adversaries that they're always instilled, they don't need to expose anything.
No one knows like what they're basically doing. Some researchers and some analysts would assume what they're doing right now, but they can do many things and you never know what they're gonna do next. So they're Literally assuming, and you know, what happens when you assume, right?
That's, it's, it's a guess, an educated guess maybe, but a guess nevertheless. Yeah. And, and maybe there is another thing that I would add to your previous question around remediation is that there are a lot of companies that don't think defense in depth.
So they would only fix something that is publicly available and only, like, you can only exploit it from the outside, but in some cases there's common practices that you have to apply even internally because you might have like a malicious user or maybe you could have, uh, another vulnerability that that might expose you to the internal networks. Uh, and then you can use this type of vulnerability to access something. You would assume that it's not public, right?
But if this, I dunno, resource opens up all your financials, uh, and, and opens a, a gate that you don't think that there is open only because you didn't implement different mitigations around it, it's more than lacking, right? And, and by the way, these things are real, like SSFs and, um, are, are extremely common. I think that there are, even when to the first in oas, like in 2025, they went to the top, like the highly ranked attack, a part of broken access control.
So it's not something that, you know, I assume like we already see that that's what they're using in order to bypass boundaries from the outside. Like you might say, yeah, this is internal, like this is my internal nothing, nothing is gonna reach heels, so why do I need to add those litigations or add this defense in depth? And then you are getting a very straight and simple vulnerability that enables them to amplify their attack by a thousand x and both in impact and, and in in speed.
Understood. Agreed guy, we're, we're about outta time. No pressure, but as I said in the beginning, you are co-founder CEO of the stealth cybersecurity startup timeframe, or when we might find out more, Probably, probably very soon.
You'll prefer you'll be the first person that I'll keep updated. Don't worry, I'm gonna hold you to that. Okay, man, Don't worry.
Alright. Hey guy, thanks for coming here on Tech Drug TV and talking to us about, you know, it's almost like, I call it like a shadow war going on right now, right? We're not quite sure, you know, what capabilities or what and who is who, but nevertheless, the, the, the, the sparring, the, the dance, if you will, has started.
And, uh, it's gonna be something that we, we need to watch closer and closer. So thanks for coming on and talking to us. Good luck.
And as I, you, you said it, as soon as you launch, you gotta come back on. Will Do. Thank you.
I appreciate it. All righty. Di Zi, co-founder, CEO of a, a, a stealth security startup.
We'll be talking about soon, but really here talking just more as an expert around the challenge of AI and security and AppSec and so forth. You're watching Textron gang, we're gonna take a break. We'll be back in a minute.
Hey everyone, it's Alan Shimo. Welcome to CubeCon North America 2025, or some people call it Cloud Native con, or as I called it, way too long a line to get in here today. They gotta do a better job.
During COVID when they were checking vaccines, it wasn't this long a line, there was no reason for it. I waited 45 minutes to get in here today, so I don't know if it's an a TL thing or an a TL cloud native thing, but we expect better anyway. Now we started early, so I had some time to kill with that.
Let me introduce you to our first guest here from the show floor at Q Con. Andy Suman. Andy, you may, if you, if you're a fan of tech strong learning events and webinars, you might have seen Andy.
He's done more than a few with us. Okay? Um, Andy is with Fair Winds and don't worry if you don't know Fairwinds, we're going to make sure you know him after this.
Andy, welcome to our coverage. Thanks for being our first guest. Thanks for Having me.
You wait online this morning? I did. I'm glad I made it here in time for the interview.
Yeah, me too. I was not sure I was gonna make it. It was a little crazy.
Anyway, Andy, I said you with, uh, Fairwinds, but tell us a little bit of kind of what your role at Fairwinds is and how you came to Yeah. To that position. Yeah, definitely.
So I, I've been a long time infrastructure guy. I've worked in infrastructures, worked on infrastructure basically since I was a kid. And, um, about nine years ago at my previous company, I got into Kubernetes, was really excited about it.
It was very early days. And then I joined at the time reactive ops was the name of the company. What was the name?
Reactive Ops, uh, react Op Reactive Manifesto, which many People don't about. All right. Uh, we little Trivia right there.
Yeah. Yeah. So we, we built and maintained Kubernetes infrastructure for other companies, and I've been doing that ever since, uh, for the last seven and a half years.
Uh, working with Fairwinds As part of delivering services is an AWS partner as well. Yes, We are, uh, an AWS advanced tier partner at the moment. Um, and we've been working closely with them for many years the entire time, but over the last couple years we've really strengthened that partnership.
The majority of our customers are on AWS uh, we are, we also operate across all three clouds, but AWS is definitely the lion's share of that and Very cool. Yeah. So, you know, I know a little bit about Fair Ones, but let's assume the audience out here doesn't, you guys, I mean, number one, Kubernetes experts first and foremost, right?
Some of the number One thing. Yeah. Yeah, I mean that's, I I've listened in on a lot of the webinars.
As I mentioned, the, the, the knowledge and skill gap for Kubernetes infrastructure deployments is, is second to none. Um, but as you said, you work with all the different cloud environments. You work with a law, a big range of software, including a lot of open source tools.
Yes. Yeah, right. We actually have several of our own that are very popular.
Goldilocks Yep. Is something you guys have have, and it's open source, anyone. Yep.
You don't have to be a, a Fairwinds customer to use Goldilocks. And, and that's yet another interesting thing about fairwinds, right? As you guys are developing the tools that you use for your customer engagements, you actually open source them so that anyone could use them, which is pretty cool.
Yeah. Yeah. We really enjoy, you know, sharing the knowledge that we have back with the community, not just in the form of services, but also in the form of open source.
Uh, I love that. Another one of our major projects is, um, Pluto. So if anybody went, lived through the Kubernetes one 16 upgrade and all of those APIs got removed, uh, at the time it was very hard to tell if you were still using those APIs.
And so we wrote Pluto to help with that. And I think today it still helps a little bit. It's not as big of a problem as it used to be, but APIs get deprecated and removed all the time.
It doesn't change. So I I, I would bet it against it. Not, well, I wouldn't bet against it not being a problem At some point in the Future.
Again, with APIs and AI and MCO server, what about MCO servers? What do you do with them? MCP servers, MCP, excuse Me.
Yeah. Um, not a ton at the moment. We do have an MCP server kind of in the works for our product that we use to do.
Of course you do. Everyone has One the cost, I mean, yeah, it's kind of table stakes at this point. Yeah.
So our, uh, software product, Fairwinds Insights, which all of our customers use to get insight about their, their, uh, clusters, and they'll be able to access that via MCP here in the, you know, within the next year or so. Of course, MCO came before MCPI guess soon you'll have M-C-Q-R-R, but, um, uh, Andy, for people who want to get more information on Fairwinds, where do they go? com, uh, go to our GitHub where all of our open source lives, that's Fairwinds ops is the company on GitHub.
Uh, those are the two primary ways to get ahold of us. We all also have an open source Slack community, uh, that you can join. It's on any one of the read mes on our projects.
Excellent. Alright. If you don't mind, I want to kind of pivot a little bit and talk about recent, uh, development, recent announcement with you guys partnering with AWS in the, you know, in the platform engineering space, right?
Yeah. You guys are, uh, partnering with AWS on a new IDP offering, internal development platform offering. Yep.
Internal developer platform offering. Tell us about it. Yeah, so we've always managed the base level of infrastructure, but our customers often need something above that.
So it's always been, it's your job to deploy your applications and do your CICD and these days, um, I think there's a need really for, you know, platforms internally for platform teams to be able to deliver to clusters and deployments and standard pa happy paths to their developers. And so AWS has built, uh, sort of a blueprint for this with a whole bunch of different open source projects. So we've got Argo workflows, Argo cd, backstage, cross plane, all put together in this really nice package.
And so what we are starting to do is we are offering this as a service is offering to our customers. So we'll come in, set that up, build the, you know, kind of control plane cluster for you, give you all the patterns that you need, help you deploy your first application through the platform, and then hand that off to you. Or we can manage it long term with our standard managed services, but really it's about zero to 60 on a platform in a very short amount of time.
And so, you know, there's a few different flavors of Backstages Open source backstage, and then we have, you know, uh, I think Spotify still has, They have One, they productized it, it was their, you know, they pioneered it. I'm not, I'm not banging them for it Anything. Oh, no, absolutely.
But, um, how, how does this offering stack up to some of the commercial backstage offerings? Um, I'm not entirely familiar with all of them. You know, there are quite, there's a lot a few out there, right?
There's a lot. Um, but really this is truly based on the open source. They're also working closely with the, uh, canoe effort uhhuh, um, to really build this fully open source.
And so I think as with all open source, what you'll get is ultimate configurability. You'll be able to do anything with it. You, you want, but it will be a little bit more complex than using an off the shelf solution.
Yeah. So it really, It's not, it's not as pretty maybe. Yeah.
Yeah. And that's where we come in. We're gonna come in and help you make it as pretty.
So I think once we are done delivering this open source to you, I think it'll stack up really well against those paid offerings, Really. Yeah. UI and everything else.
Absolutely. Yep. Very cool.
And now that's an offering you're doing with AWS Yes. As an AWS partner, we're working with them to deliver that. They're the ones who are they picking, like besides Backstage, you mentioned there's some GI ops and some other stuff.
They're the ones picking that, or does the customer get to put anything they want in there? So They've picked kind of the core pieces of it, and then there are certain parts of it that the customer will be able to pick and choose and swap in and out, because there's an entire, um, off solution built into it. So at the moment, the open source uses key cloak, but obviously not everybody's gonna use Key cloak for SSO.
So there'll be plug and play options for SSO for your code repositories. So we'll be able to do GitLab or GitHub or gitte or any of the other, you know, kind of flavors of that. Very cool.
So it'll be a little bit of both. And then because they have you doing their service, if they want to add other things that maybe aren't in the core, right? Yeah.
We can add things on, we can help to customize it. You know, everything we do is very, uh, highly tailored to our customers. Right, right.
You know, obviously for operational reasons, we try to keep them similar. We use best practices everywhere, right? It's suspicious scalability.
Sure. We are A very high touch service, and we really wanna make sure our customers get the, the platform that they need for them that fits them, which is why I think a lot of off the shelf platforms don't work because they're not custom tailored, but then building your own takes so much time. com days, you probably weren't there.
I wasn't working. No, No, I, I realized this when I was talking to someone. The other, they said, yeah, I was in high school.
com days, I helped start a company that was what we call an A SP application Service provider and back. This is before this cloud, before this hypervisor, all that stuff. Yeah.
And, uh, we were offering Lotus Notes, which you probably have Heard I've Heard of Lot. Yes. Lotus Notes, PeopleSoft, Oracle, bunch of like major enterprise Onyx or CRM and stuff.
Major enterprise, uh, um, applications. Right. And the rule of thumb we learned then it was in 80 20.
No one just takes some app like that and just plugs it in and runs. There's always about 20% right now session that needs to be 10. Our mics are good for that.
It's always about 20 cent, 20% of customization that needs to be done. I don't think that's changed. I don't think so either.
In fact, I think the percentage might be higher when you get into Open source. Yeah, maybe with open source. 'cause it is, you may not have UIs and also you just have a lot more, uh, options.
And, you know, if you want it to be green on Mondays and blue on Tuesdays with open source, you could do that. Yep. Excellent.
Yeah. Andy, I don't know if we mentioned the website for Fairwinds. Did we?
Uh, I'm not sure We did. com. It's very simple.
Very Simple. Yep. Guys, so take it from me here.
Shimmy. com. Andy, it's great to see you in person after.
Are we seeing you on those little webinar screens? Same. Thanks.
We Gonna take a break. We're live here at K Con cloud Native Con, we'll be back. We've got a full opening day here, so stay tuned.
Hey guys, thanks for throwing. We're here with Raj Sethi, who's senior vice president and go-to-market leader for software development lifecycle for Global Logic. And we're talking about, well, all this noise about how AI is gonna eliminate the need for junior developers.
It's a hot debate, but I don't know. It's a lot of things about AI these days may or may not be true. Raj, welcome to the show.
Good to be here, Mike. We're looking forward to having you this chat with you talking about a very hot topic. So what's your code?
We hear it's hard for the kids come outta college to get a job. And we're also hearing a lot about how senior developers are now automating a lot of the tasks they might have assigned once to junior developers. And this is resulting in maybe not as many junior developers being hired.
And certainly there's been a lot of layoffs lately, but I'm not sure those are because of AI or not. But Raj, what's your take on what's going on here? Well, I think what this has to do with how the industry sort of, uh, you know, expended, uh, we had a moment in time where there were, you know, fairly large amount of organizations, hired a lot of people on staff, assuming there's gonna be business coming up.
And I think a lot of those forecasts were changed because of gen AI and the need for that. And that's one of the reasons why we see some of these layoffs that we see in the industry. However, I think that when you look at the larger trend, uh, it is an area of flux.
Businesses want to truly understand how genai adds to that productivity. There are lots of claims, but, uh, if you look into some of this claims, they're all added up with an additional step where they'll say, oh, 60 and 70% of our lines of code is written by Gen ai, but, uh, we still need people to look at this code, review it, ensure that they're right, or they would say, we still need to pro the system, which is another form of programming, um, to, to get these lines of code. Uh, and you know, one may argue, well, there's, it's a one time job, or it's a constant tweaking.
That's a separate issue. The key part though is the systems are not there where they're gonna produce massive amounts of lines of code without any human intervention. So that being said, um, I think that the junior developers in a far better position, sometimes I'll look at, because they have an option to adapt.
Um, senior developers are more sort of set in their ways of thinking and doing things. So, you know, from my Gen I perspective, all organizations want move there. So I do see that the opportunity for junior developers is still there.
However, it looks very different. It's not about writing boilerplate code, it's not about, uh, you know, writing test cases. Those are low hanging fruit that Gene is gonna do far better job at.
But I still think that there is the process of validating, reviewing, being, doing critical analysis that still junior developers can do. Uh, it's really about building that muscle within yourself. So coming out of the school, think more around critical thinking, how systems are developed, rather than doing the traditional ways of software coding.
It's really about not competing with ai, but how would you use AI more effectively? How does a junior developer get that expertise? If we're not hiring junior developers in the first place, who will be the senior developers tomorrow?
And where will we get that cognitive capability? So it's, it's interesting, you know, how things have changed back. You know, when I came into the workforce in the nineties, uh, uh, it was all about getting this first job to do things.
There was, internet was just coming around, uh, you know, email was just coming around. So obviously you needed access to an infrastructure or an enterprise to even gain experience. That has changed.
I mean, if you wanna learn today, there's ton of information on YouTube. There are so many courses that you could take online. You could literally build your own portfolio today and not have to wait for that first job to show up.
Right? Uh, that to me is a, a game changer today because you don't need to give your just a resume. You actually show your work to people.
And I think often, um, you know, young people don't focus on that. They all, they too, they index over index on that first opportunity. That first opportunity will certainly come their way if they're prepared.
But the question is, what's that preparation? It's not necessarily just a degree from a college. Um, it, you, you could demonstrate your work, uh, far more effectively than you could do before.
There are some critics of the junior developers who are coming outta college who are maybe too attached to AI and not doing enough critical thinking of the code that's being generated, because some of that code is, shall we say, overly verbose and maybe even doesn't make a whole lot of sense and certainly doesn't run particularly efficiently. So, um, are we in danger of kind of going down a path here that's gonna lead to, I don't know, massive amounts of technical debt that's unsustainable? I, I don't think the issue is that I just need a engineer to drive ai.
I think that, like I said, you need to have critical thinking. You should know algorithms, you should be able to review code faster looking at the code. You can mean, there are times when I, you could look at the code and say, well, this thing meets two loops.
I don't see the second loop. There's a problem in this code. Um, so proofreading and understanding what is written there is, is a, is is a paramount, uh, skill that you would still need.
I don't think that is gone. And to the extent where people are thinking about white coating, yeah, prototyping is fine. You could do white coding there.
I don't think white coating has been very successful in the large enterprise. And I'll give you an example. Uh, replicate being one of the, uh, providers up there.
They, they weren't like, they were in their, uh, upper, you know, maybe in 2020 third million dollar revenue. And then when they started focusing on the business analysts and business community, uh, their a RR went through the roof five times. Um, and I'm saying that it's good to prototype, but these are not software tools where you can just get away with wipe coding.
Um, I think that the junior developers that we're talking about need to have proper formal training in software need to understand how things work because although a lot of times when I see people pushing the boundary of what gen AI is supposed to, you know, there's a, there's an idea that somehow you can reason anything as opposed to reason few things. Having that ability to figure out what's the right problem to solve, that's critical thinking. Um, that's not gonna come if you, if you haven't gone through formal training in schools or, or haven't gone through any formal learning.
I mean, I'm not necessarily have to go to school. There's a ton of material, right, which can pep you off for that world. Mm-hmm.
Do we need to revisit how we teach all these skills in school? I have, I feel like sometimes maybe, you know, the kids who are coming out are not as well versed in the fundamentals in, they're maybe too dependent upon ai and that's probably not a good thing. And maybe that's the fault of the way they were taught.
I do agree with you. There's a fair bit of that has to, that has to happen. Um, but I do think that a lot of curriculum is getting influenced with, uh, with, you know, how some of the material that's available online through several organizations that are offering this.
And, uh, I would generally say that that is a, would be a good approach. But I do think that what needs to be inculcated is that learning doesn't stop at school, in my opinion. You decline stacks once you leave school.
So learning has to be a continual process. It's an investment one has to make. Uh, if you stop at any point in time, well, it's downhill from there.
But, uh, I think that junior developers should come with that mindset that they're coming at the top. It's just that they need to learn how to apply that knowledge. And that could be something that they can invest during school.
Like I said, if you build your own portfolio where you want to demonstrate your work, that's, that's a seeding ground for, for you to show your capability in the enterprise when you join the workforce, how productive and how contributing you would be as an individual. I think the, the joy of being a software developer is that you are solving problems using code. And I think a lot of people who do that today kind of have attached the actual writing of that code to their brain as part of the joy.
And, but is that gonna be the case going forward? Or is it gonna be more about proofreading and reading the code to optimizing when it's created by a machine who probably won't get it perfect, but at the end of the day, we'll do it faster? Well, I, I, I think it, it's two ways to look at it, right?
It's really about abstraction. I mean, think about Lego blocks. Uh, have they taken the joy of creating things?
I mean, look, and the people of all ages use Lego blocks to put things together. Nobody's interested in how Lego blocks are made. Um, but that abstraction of the block is the important part.
And I think problem solving to a certain extent, works that way. We've developed these skills and capabilities depending on where the technology was. I mean, we've been waiting for a, an opportunity where we could talk to a machine to do something faster for us.
I think gen has started unlocking that for us. So there is a significant, um, work that is involved in structuring your thinking. So when you talk about systems, it's never about a point where you say, solve this problem for me.
It is more to that today. Uh, and the software is not anywhere, uh, or the systems don't exist today where I could take a very high level problem and solve it at, like, for example, improve my, um, you know, uh, Campaign management, uh, or improve the efficacy of my marketing by 1%. That's the problem.
Business would pose, what does that translate back into the systems is a problem that Gene AI is not quite capable of doing that, but human would be. Uh, you could use gen AI to make that faster, better, but that's the way you need to start thinking about that. It's really not about coding.
Uh, it's more about structured thinking and having that ability now to communicate. So I think it unlocks the opportunity to, for lots of folks, uh, to, to sort of participate in systems building rather than just the developers who knew how to code in a specific language or a set of languages. So I think there's, there's more fun coming up.
Speaking of fun, um, are we going to build more software faster or maybe we're just focused, uh, too narrowly and maybe we should be thinking more about maybe making the software we do build today higher quality and just better. I think it's all of that. I think software is going nowhere, uh, because the interface between the machine and the human, uh, is, is will be bridged with technology one way or the other.
I don't know at what point in time we build biological systems that are exactly the way we work as humans or, or, uh, organisms. But the key part is that the software is there to stay. The question is whether there's gonna be packaged software, the, the one that we have known for the longest time, that where you buy and then you configure or customize it to suit your business needs.
Or would there be a situation where you build software to your specification, you could talk to it. I, I think that that's where the trend is going to be. Uh, or at least I predict.
I I, nobody has this crystal ball, but I think that there will be an opportunity for people to create software that meets their needs and that's secure and that's high quality. Um, and it's, it's not, or it's always end when it comes to quality and and security. Right?
The key part is that do I need to deal with packaged software or do I get something the way I want it? I think that's where the market's gonna move you, you would wanna buy software the way you want to use it. Well, you talked about abstractions, so let's go down that path for a little bit.
'cause I might argue that, you know, we created Java another programming languages to have a higher level of abstraction with the machine. But maybe as we go along here and we start talking to the machine to write code, well, we'll just write everything back in assembly because that's more efficient. Yeah, I, I do agree with you.
I think that these are intermediate languages. Um, you know, compilers were created because it was too hard to quote them in assembly. Uh, I think that gen AI gets rid of some of this stuff and says, well, I can go straight to this or create some intermediate language, and that gets compiled down.
It's not relevant, whether it's Java or whether it's C Sharp. The key aspect is can you define your system, um, you know, in a precise manner? Can you define the way you would want to test it?
Those are the elements that will become material. So spec is there to stay. I think that machines will get better so that you don't even need to define spec at that, the lowest level.
But spec is the key part. I mean, we still need to communicate with humans. So even if we wanna get work done, we, we communicate with humans.
And I think that's the line of communication that, that will need to be established with a machine. So Gen Geni is suitable. Whether these intermediate languages are required, I don't know.
I think that, uh, they probably will lose favor over a period of time. They're going nowhere in the short term, for sure. Mm-hmm.
So ultimately, what's your best advice though, to kids coming outta college right now? What would you be telling them and what might you tell their parents? Oh, I, I, I think that, uh, they should be constantly learning.
Start experimenting right now. There's so much information. It's democratized today.
It's all over. Uh, whether it's not just necessarily in developed countries, it is available to every human on this earth. And, and the question really is how driven are you?
And, and, and you know it, so it'll all depend on what drives you. If learning is something that you enjoy, this is the best time to live. Um, and, and, and I think that you will, you will bear the fruits of your industry.
Uh, if you are in that path of learning, you will get opportunities. And you know, I look at it from a very optimistic point of view that if ever in the human history, a technology got rid of the young, we would be doomed as a species not happened and hasn't happened. And I don't think it will happen.
I think the young will always adapt. I, I think more about senior folks like myself and others, that what will happen to them? Will they work till they're in their seventies, eighties?
I don't know. That is, that's a question that I, I pondered out. I, I, I worry less about the young.
But I do would say that focus on learning, focus on learning, focus on mathematics, focus on linguistics. This is where the game is, uh, sciences, uh, and this, there's no better time to live today to learn about all these areas, cross pollinate ideas, use gen AI as, as a communicator, as a friend that you could talk to. I'm not asking, suggesting getting social advice.
I'm talking about, uh, very specifically, uh, you know, science-based information, engineering based information. These are, this is a great idea where you could crosspollinate ideas, take ideas from software industry or automotive industry, apply it to, um, you know, energy and vice versa. I mean, things that are now at your disposal, uh, wound there.
I mean, you have a PhD friend sitting to you who's knowledgeable in any field you want. I don't think that has been an area we've had in the past. So young people, great time to live.
Don't worry about these short term stories about this thing. It'll come and go. I think it's a matter of your years here or there.
The industry is gonna settle down. All right folks, you heard it here. The diploma is not an end.
It's a means to a larger end. And frankly, there's more interesting things to learn outside the classroom as there are in it. So maybe just enjoy what we do because there's always gonna be some great new innovation and some new awesome thing that nobody ever thought of.
It's all gonna start with somebody who did something with code. Hey Raj, thanks for being on the show. My, my pleasure.
Thank you. All right. And back to you guys in the studio.
Hey everyone. Welcome to Ingram Micro one. I'm Daniel Newman and we are here on the ground at the event as it's getting kicked off.
Very excited to have a couple of great conversations here at the event. Starting off, we're gonna talk a little bit about AI and so much more. I've got Jim s Jim, Dan, thank you.
Thank you for being here with us. Yeah. Well, you know, look, I love the opportunity to spend time with Ingram Micro.
You are one of those companies, like, I call it like a bellwether company. No, you spend so much time with the implementers, with the integrators, you work with all of the vendors. It gives so much visibility.
Sometimes, you know, when you're spending too much time at one part of the stack, too close to the customer, too close to the vendor, you don't see it. You guys really spend that time right there in the middle, all of it. And so much of that's on display here.
But is there anything, Jim, that we could talk about today that people would want to hear that's bigger than what's going on with ai? Uh, I think AI is the topic. Uh, not, not just here, but I think everywhere.
You can't escape it, whether it's in the news, in the general media, or even when we're talking about, uh, technology specific and specialization. It is the story, to your Point. It absolutely is.
And, and by the way, just the morning in my flight here, between the time I left my house and the time I got here to Washington, DC there was like over $65 billion worth of new AI deals announced. Um, that is how fast and furious this is happening. It, The, it's it, the investment is happening almost as fast as the rate of change, it seems like at This point.
Did you see that? Um, there was that graph out there that kinda talked about the internet versus ai, and it basically said that this AI pivot is seven times faster. I hadn't seen that, but it doesn't surprise me Yeah.
At all. Because a lot of people are trying to compare, well, is this another internet bubble? Mm-hmm.
You know, but the proliferation is happening so much quicker. Which brings me to kind of a question I'd like you to dig in for me, Jen. Yeah.
Is AI is not like a monolith. It is not all one thing. Right.
You've got, you know, we've been doing, by the way, AI algorithms four or five decades, easily, easily. Um, you had generative ai mm-hmm. Come out three or four years ago in terms of at scale, right.
Started to become made available in the last, uh, I don't know, 12 months. Ag agentic has been the trend line. Kind of, you know, talk a little bit about kind of what all this means and why it's such a big game changer.
It, it's a, it's a great topic because these are all steps in the process. The evolution of how we're interacting with AI tech, AI technology and, and the benefits we get from it. I think generative was a great stepping stone for a lot of people because everyone could use it in their everyday lives, right?
When you're at home sitting around, even something as simple as making an image that looks like this and getting the result, and it really took hold. And if you think about design or even coding, right? Using that to accelerate that, I think ag agentic is this big pivot that everyone's trying to wrap their arms around.
To your point where the model is shifting, where you have essentially an assistant that you're giving a set of objectives to, and it's gonna take autonomous actions to help you achieve those objectives. And so that interaction model is the first big change I think people are gonna encounter is this back and forth conversational, um, you know, dynamic. That's new.
The, the second if you think about it is the, you know, the architecture. And now we're moving from a single agent trying to do one thing to an orchestrated experience where you have a, an agent that is in charge of achieving your objective. Yep.
And then orchestrating purpose-driven agents to bring that together. And then the need, especially in Ag agent, to have this fact checking or antagonistic check to make sure what's being brought back to you is actually gonna meet your objectives. So I think it, it's a big, big explosion in, in how the technology is built, but also how we interact with it.
It is, and we're seeing the same thing. And by the way, it's gone from like an age it to a platform. Mm-hmm.
Which is something I know you at Ingram are focused on as well, is you have the X vantage platform. Absolutely. Um, this is, you know, democratizing mm-hmm.
For many of your partners. I'd love to kind of hear a little bit about what your thought process is. Maybe start a little bit about what, what X vantage is just for everyone out there, but then what are you building in terms of an agentic platform and how is that being, you know, consumed and how is that changing the user experience for all of the Ingram, you know, ecosystem?
Absolutely. Uh, AI's been the heart of the platform since the very beginning. When you think about X vantage, it really, how it drives value for our partners, whether it's vendor or a customer Yeah.
Is really in two parts. One is, as you know, you've been in this industry a long time. We, despite all the great technological innovation and the advancements we've had to run, the business has been highly manual.
Yep. It's taken a lot of manual effort inefficiency. So the first thing is how do we, how do we take those inefficiencies out of doing business for all of our partners to free up time.
Mm-hmm. And then the second part of the platform is giving curated experiences to reinvest that time in that help us all grow. 'cause we're spending historically more time running the business than growing it.
Yeah. So if you think about AI and how that's been integrated since the beginning in the platform, it's to help take the manual work or friction out. So for example, uh, integrations.
So having seamless integrations where you don't have to hire a team of 50 to try and plug your native applications into the platform, it's done using ai so you can come as you are. Yep. And then when you talk about reinvestment, insights, recommendations, you know, customized to our partner's business that are based upon the objectives they're trying to achieve.
So it could be something as simple as an add-on or identifying brand new opportunities on an upcoming tech refresh that tie into specific software opportunities. So really harnessing the power of AI to help our, our customers go faster and achieve new levels of growth. And a big part of your world right, is you are moving the equipment, you, and that's the scale of course, you've also been sort of the pacesetter in many ways to how those companies you provide, uh, hardware and technology to build services.
Mm-hmm. Okay. So you've got kind of the transactional part of the business.
It's always been something you've been great at and people understand that very well, but part of the growth story has been adding more. Yep. Right?
Absolutely. So how are you sort of thinking about that from the standpoint of how the advantage platform, what it is, how it grows? Because I can see a ton of ways like age genically, the transactions platform has value.
Mm-hmm. Like everything from how it tracks to how it helps you understand what to consume. A lot of the automations we talked about in the RPA era, like starting to really come to life with agent.
Absolutely. But then you've got, it's, it's gotta be more than that though, right? You've built this thing to be so much, you know, I'd love to hear a little more about how you're thinking about that.
Absolutely. If you think about challenges for our partners, it's where are you going to invest for growth? And it's a, it's a tough question because you're investing ahead of the return.
Yeah. Could be a quarter, two quarters, three quarters a whole year. And where we're really leveraging ag agentic and AI to work with our partners is to how do you quickly and simply identify the areas of opportunity that convert to return fastest.
So you think about the questions a, a, uh, partner may have of, if you think about the upcoming AI enabled refresh of laptops that people keep talking about, okay, we all talk about it, but we're partner. How can they quickly understand where their top 10 opportunities in that space with which customers, what's the best approach, what are they upsell, cross-sell opportunities associated with that, and turn those insights into actually opportunities to go pursue with a pitch that's, that's generated by framework, by ai. That's the same as having in two, three years ago, having to hire five, six business development resources to go go through manual data to come up with those ideas.
Yeah. And then now you can match those to programs and go to market in real time. So I think it's, it's really transforming growth Yeah.
In the Industry. It's really interesting. I I was thinking about that.
So if I'm breaking this down for everybody out there, right? It's, you have a lot of data, right? And of course your customers, the ones that are buying from you, the MSPs, the channel partners, the implementers, integrators, they have mountains of sort of, of data in, by the way, some of it's probably really well organized.
Mm-hmm. Some of it's probably not. Yeah.
Very True. Uh, structured, unstructured, some of sits in emails and slack messages, and some of it sits in, you know, tables. Things that we've been great at doing analytics on Absolutely.
For a long time. This is part of what you're doing, right? It's building that exchange that you're giving that infrastructure and exchange of data mm-hmm.
To be able to do, um, integrations mm-hmm. To say, Hey, this is your customer profile. This is all the work they've been doing over whatever period of time.
This is all the equipment that they have deployed. And where here is a series of, and what you're saying, right, let me make sure, is that here are five different recommendations mm-hmm. Based on this customer of upsell, cross refresh.
Is that, is that kind of what this is building towards? Absolutely. And it, and it goes beyond that a little bit to bringing in the, the wider industry and market data, right?
So what are the overall macro trends? What are the opportunities with those? Then to your point, how do you match that up with a personalized data and experience of a partner?
So it's applicable to them. Insights are great, but unless they're actionable for the partner, it's just information at the end of the day. And that's not what we're driving.
We're trying to work with them to drive outcomes. Yep. You have faster and at a larger scale.
And the other part of this that's great with ag agentic is you may start off with a data set to your point, but then your experience interacting with the agents points out where you need to bring more data in from different sources that you may not have had access to before to have a more robust view of where the opportunities are and how to action them. So it's constantly evolving. So this is not new, but it's new, right?
Mm-hmm. These, these next level X vantage AI and agentic capabilities, are you able to share it all sort of anecdotally or maybe, you know, some specific, like how it's changing mm-hmm. Customer ex, because I'd kinda love to hear some practical stories and probably for this audience just to kind of hear what, what does success look like?
You know, In a, and it's, it's a great topic. You know, we've already have our partners already interacting with AI and agent AI right now with us. And I could give a few examples.
One, one easy one would be integrations. As we were talking about before, simplifying, taking the friction out where as a partner of ours, you can send us your information, your quote request, your order request in any format you can send us to it. Even an email unstructured, you don't have to conform to send in a specific format to us to have it processed.
And we're using AI to pick that up, process your order in seconds, right? So getting you that speed to market, helping speed up the quote to cash cycle. So efficiency improvement, taking down the burden on our partners when it comes to interacting with us.
If you think about the growth story or opportunities, we're, we're using ida, intelligent digital assistant right now to go find and help prioritize opportunities that our partners are working on with their end users. 52 different dimensions of data that it's analyzing and actually enables our associates to reach out to partners and say, these four thing items that you're working on, these four opportunities. So these three customers have the highest propensity to close based upon all this data that we're looking at in the next 30 days.
You should focus your effort there. And it's a new way of helping our partners align their resources with outcomes. And we're seeing tremendous, tremendous benefit for our partners.
Hundreds of millions of dollars of opportunities. We're helping them close a quarter using that model. So when, when I say integrations, you're saying ERP systems, you're saying, uh, it's connecting to their CRMs, it's connecting to Cq, But I'm saying it's, you know, for those integrators, channel partners, uh, MSPs that work with Ingram, you've built the integrations across a, a wide swath of well understood, well known.
Absolutely. And it sounds like also you've built some integrations for things like unstructured data that come, that comes from, you know, people's, uh, uh, word documents. Yeah, Absolutely.
Absolutely. Spreadsheets and chicken scratch. And they've now, you know, scanned into their system so that they, because again, what a real org looks like, you know, we all know, and you, you, you lead a big org, right?
We all know how much salespeople love putting stuff into Sierra. Yeah. It's gonna be challenge.
It's, it's, But so half the battle's been there, but if all of a sudden now, hey, there was a Slack interaction that took place yesterday that had a bunch of really juicy, good, valuable details mm-hmm. That stuff can be constantly being mined. Absolutely.
It, it's the that multidimensional perspective. Yeah. Right.
You're talking about, which is what's the holistic view of the partner, the interaction, the opportunity, because really we don't live in a world where one individual is gonna have all the interactions with one partner opportunity. Yeah. It's bringing those together and identifying not only the best, the best action to take, but then often who's the best person to take that action.
Yeah. I, it's funny, I, I talk about a lot of the tools we're building now. We're gonna start building for AI to talk to ai, it's, it's, we're getting a little ahead of ourselves.
Yeah. Like, we're not that far away though, from the fact that what, who's gonna actually might, who may be reading your best idea that you came up with for an upgrade, maybe an AI that's gonna then filter that system down. It's, it's going that way.
And If you, if you think about it, the amount of time it's freeing up for the people in the business, it's this, it's non-linear. It's an exponential level of growth. Because now think of you have your own assistant to go mine and do that research and come back with the answers for you.
Now your focus is on doing something with that data. Yeah. It it's a huge transformational shift.
The industry For sure. Yeah. It's very exciting.
And by the way, every business, every industry has a place for it. There's so much more productivity to be gained. There's so many efficiencies to be found.
And, you know, I keep saying that this industry, picking your right partners, and, you know, we started this conversation talking a little bit about like, some of the, the deals that were announced today. You know, you look at a company like OpenAI and it picks its partners, it's a MD, it's Nvidia, it's Microsoft, it's Amazon, it's Right. They're like, who are the companies I wanna be around?
If you're a implementer, an integrator, and you want access to hardware, software services, consulting, ingrow, I mean, it seems like that's what you guys have built your, your, your lifeblood on being able to support all those needs. Absolutely. And it ties in AI as well.
As you think about the investments, we were just going through a few that we've continue to make, right? We're an AI centric platform with advantage. The benefit to the partner base is you don't have to go make your own massive investments in technology or you the structuring data, creating data lakes and event driven architectures.
You can leverage what we've built as being part of our partner. And the more interactions you have with us, the richer the data, the richer the opportunities that are presented. So it's, you have your own AI factory, which is us to leverage and then turn those into actions and outcomes for your business.
Well, If you build the event driven architecture, correct. We've done this on our own company builds our own platform for research. And it can be very flexible.
And that's probably for a lot of people out that might say, well, if I am using the same thing everyone else is using, then how do I be different? Because you can use it around your data, around your processes, and it'll look completely different in your organization than someone else's. That's just something that Yeah.
I thought everybody should know. So, on the way out mm-hmm. Um, you know, one message to the viewer, one message, one prediction about the future of ai.
You get a choice. Yeah. What, what would you, what would you share with them?
I, you know, what I, what I would say is AI eventually is gonna become, likely gonna become the primary UI for our interactions, right? So we're gonna, you know, you still have to have very strongly developed applications that are underneath all that. But I think we're gonna go more and more to a conversational user experience where that agentic, you know, your personal agent is gonna be helping you accomplish your objectives, might take you away in a, around a curated experience to do it.
But I think that's gonna be a big shift. And how do we get comfortable with that conversational business transactional flow that today has been more embedded within a workflow, becomes a, a conversation tomorrow. That's a, that's AI is the new ui.
I've heard it a few times, a few different sources. Totally agree. More semantic, more contextual, more natural.
Um, even these devices may or may not be the thing that we'll be using forever. Uh, we hear a lot about that. Jim ans thank you so much for joining me here.
Chat to You. Pleasure. Thank you everybody for tuning in here at Ingram Micro One.
We are on the ground. That was a great conversation. Stay with us for more.
Hey everyone. We're back here. Live on the floor of CubeCon and it's, well, it's Wednesday and it's, I'm going to guess it's about two o'clock, right?
And we've had an amazing day and a half so far of some great conversations. You probably see behind us, people moving in and out. The, the show floor, as I think I mentioned is, is really big this year, like cube con style, not too much on top of each other, but a little bit more, um, concentrated than like, let's say during COVID when stuff was really spread out.
I want to introduce you to our next guest. His name Isse Got Goswani. Go Swami.
Did I get that right? Go. Swami SDI is the CEO of a company called Traffic Labs, but it's spelled a little funny.
We're gonna get into it, but first let's find out more about Sudi. Welcome. How are you man?
Yeah. Hi Alan. Great to be here.
Great to have you. So, Saddi, before we talk about Traffic Labs and CubeCon and all this, let's talk a little bit about you. As I said, you're the CEO here, but you know, you weren't born the CEO of traffic.
Give us a little bit of your journey. Yeah, so engineer by trade, um, used to implement technology before I got on the other side and started to build technology and then sell technology. So really kind of dealt with the challenges of day two ops and what users have to do after they buy to per certain piece of technology and all the trials and tribulations they have to go through, and being able to implement that at scale.
Yep. So I'm gonna assume that being that you said that traffic deals with sort of a day two ops problem. Is that what you would think Or, yes, we definitely focus on day two ops for microservices and cloud native infrastructure in general.
Got it. Let's talk about how you went from being the, how you came to be the CEO at traffic labs. Right.
That that's a, there's a lot of people out there who, of course, who aspire to be CEOs and having been a CEO now a few times I don't. But, um, how did you know, when did you, let's say, take the track and say, you know what, I want to be a c, the CEO? Well, I, I'm a problem solver at Heart Uhhuh.
For me, it's all about solving problems, you know, whether it's a technical problem or a business problem. So I joined the company as a CRO. Okay.
And then, uh, we had a conversation internally and try to match my skill sets to what the company needed and the problems that needed to be solved. And, uh, you know, the rest is the Rest history as they say. Yeah.
Cool. Let's talk about the history of traffic, if you don't mind. Sure.
You know, again, probably a Traffic Labs company that maybe a lot of our folks haven't heard of. As I mentioned, it's spelled a little different. Why don't we start there?
How do you spell it? Yeah, traffic spelled T-R-A-E-F-I-K. io.
And the traffic's claim to fame, uh, it's really around the open source project when traffic started almost 10 years ago now. Mm-hmm. Uh, where our founder and now the CTO put out, basically, he's a problem solver as well.
You know, he found a problem deploying microservices. We found it very painful. So he came up with his own solution, put it out there on GitHub, and overnight took off.
It just took off. So is the open source project called Traffic as well? Yes.
That is called, that is called Traffic Now or Traffic. Some people know it as traffic proxy. I'm sorry, say that again.
Traffic Proxy. Traffic Proxy. Yeah.
Absolutely. And, uh, you know, that was in 2016. 4 billion with a b downloads.
Wow. It's got over almost 60,000 GitHub stars. Got a very vibrant community of active contributors both inside and outside the company.
I Love it. It's, it's one of the best projects. And, you know, people who come to our booth here, uh, they know the brand.
Uh, the, the brand is the gopher, uh, that's the, the brand. You know, Matt, if you will, Mascot. Exactly.
So people are always coming to our booth for the gopher shirt, go Shirts. Got it. Um, it's funny, I'm old enough to remember when Gopher meant something else in the internet right before there was a web, we had wide area search Gopher and stuff like that.
That's right. Remember? That's right.
Yep. Um, wanted, so is I, I just wanted from like a book of housekeeping. Is traffic A-C-N-C-F project or No, just traffic Flash Traffic is not A-C-N-C-F project.
It is an open source project and it's got an open core model. Mm-hmm. And then, so it has the open source, uh, binary itself, and then there's a secondary binary for all the enterprise features.
So we built on top of the open source as the foundation. Got it. And, and that, you know, the open core, the open, uh, core model is one of course that's very familiar to everyone here in the, uh, in the, uh, open source community.
Right. It's, it's evolved. Um, so with open source, I'm assuming you have like premium modules or premium modules that ride on top of the open core, open source one that give you enhanced, you know, capabilities.
Let's talk about, you know, what comes in the, in the pure open source one. Mm-hmm. And then what some of the add-on, uh, modules are and what they do.
Yeah, Sure. I'll talk about what comes in the add-on modules, but I also want to talk about the upgrade process because we made that extremely user friendly and seamless. Mm-hmm.
So let's start with the capabilities in the open source. People can deploy that as a reverse proxy, as a load balancer, and as a router, it auto discovers all of the microservices that you're running. So you don't have to do that manual work.
Wow. And that's the core value proposition of the open source that people love. Yeah.
They don't have to deal with kind of fi finding a microservice by microservice. It automatically does. That creates the routes.
So traffic starts flowing to it. Okay. That's the foundation.
It's, uh, That's in the open source. That's in the open source. People love that.
And a lot of people for them that is enough. And then we can give them enterprise support on top of that. So they have the peace of mind for when they do need to call us and get support.
Got it. Now moving to the, uh, the paid Add-ons, premium or premium, All the additional things which comes with our advanced or the another binary, so to speak, people use that. One of the most common use cases for that is security from an authentication and authorization standpoint.
So when their microservices need that front door where you can authenticate and authorize users and traffic coming in, that's when you need what's called an API gateway. Okay. And that is the most, uh, common use case for our paid offering.
What we have done is built on top of that. And that API gateway. So when you say it's an API gateway, it's an, it's a API built that rides on top of the open source core that allows other people to plug in.
Correct. Okay. It's can, so we have our own API gateway, but there are plugins available on the open source, uh, binary Yeah.
That communities can contribute to. So you can pull off of that. Yeah.
And you can add functionality or you would go with our paid offering that we have written at Traffic labs and we support. So, and that's the most natural path people take. Got it.
Is the API gateway. And then we have created extensions of that API gateway into dev, uh, developing an AI gateway and an MCP Gateway. So that is sort of an MCP.
Okay. So that's an MCP gateway. Yeah.
An AI gateway is separate, and an MCP gateway is separate. Now they have Different, so is the AI like a, A two A, uh, was a two A or something Different? Ai.
Think of the AI gateway as, uh, uh, LLM router. Okay. So, you know, it does many more things.
So at its core, it's routing to different LLM endpoints while and before it's routing. We also provide a way to, uh, enrich the traffic or to guardrail the traffic. So not every query that you send to an LLM should be sent there.
Maybe your corporate policies don't allow certain types of content. Got it. So we integrated with NVIDIA's safety name guardrails.
So before you route the traffic to an LLM, you take it through a set of safety guardrails, then comes some kind of caching layer. So if you keep asking the same question over and over again, you don't need to consume these expensive tokens. So only then do you route all of that.
Right. Is offered as part of the AI gateway. Got it.
MCP gateway is, uh, it requires that as the foundation, but it's not enough. MCP gateway needs more than that because it's a new protocol. Right.
And what that requires is for your agents to be able to talk to the MCP resources, and then the MCP gateway provides that governance layer. So it allows which tools under the MCP umbrella can you talk to? How do you, uh, talk to those tools?
What operations can you do under those tools? So it's an extra layer of complexity that needs to be governed properly. That the API gateway definitely is not gonna give you outta the box.
And AI gateway is not enough. So you need essentially what we call the triple gate pattern. For MCP, you need the AI conversations protected, you need the API conversations protected, and you need the MCP conversations Protected.
Protected. And all three of those are premium. And, and I, I could see, And all of these are premium.
Give us an example of some of the other premium models, The other premium modules. Yeah. And which is really around API lifecycle management as everything is becoming an API.
So your LLM endpoints are being exposed as a, uh, a APIs, even your MCP endpoints become exposed as APIs. You need, you have an API management, uh, management problem, or you have an API proliferation problem. So what you need is a full lifecycle management of that.
That means your APIs need to be versioned controlled, they need to be sunsetted, they need to be, be deprecated. You need to provide rate limits and quotas. So, you know, there's a layer of Defense.
This is why you have a, a true sort of gateway that controls all of that. Right. Rather than just, uh, you know, uh, an API to API set, I mean, just a Correct.
Yeah. Uh, a direct connection. If You'll, plus you also need to share those APIs with your community or developers.
They could be internal, they could be external. So this is where a developer portal is needed. So all those things come under the umbrella of API Lifecycle manage.
Got It. Got It. Now, the beauty of this, going from open source to all these extra paid capabilities, it takes 30 seconds to do the upgrade.
And it's an in place upgrade mm-hmm. That you would do. It preserves all the configuration that you do with the open source.
And after 30 seconds you have a New Thing on top of that, and you have export you Full. So it's like a mesh layer that sits on top of the pure open, uh, stack, if you will. Um, I'm, I'm wondering, so it's not like, so people host this and run this themselves.
It's not, you know, 'cause that's another model. Right. An open source where I, I'll take my open source and I'll run it as a SaaS, so you don't have to worry about.
Right. We will, We provide a self-hosted model. Self-hosted.
So people usually deploy this on public cloud. So because we're Kubernetes native mm-hmm. They can deploy it on any of the public Kubernetes distro.
So A-K-S-E-K-S-G-K-E-O-K Got it. Lk. But they can also deploy this on-prem in a completely air gapped and offline environment.
Okay. So it doesn't even need connectivity at That point? No, it does not.
And people can deploy it at the edge. We are natively integrated into K three s with rancher. Mm-hmm.
They can deploy this in, you know, bigger environment, you name it. Like it works seamlessly everywhere. Excellent.
And so does it require, it requires Cobe though. Um, the, the Kubernetes native that if you're deploying in Kubernetes, yes, it's gonna require Kubernetes. But because we started in 2016 when Kubernetes was not even around, we have had into native integration with many different alternative ways of deploying microservices, starting with just bare metal Linux.
Okay. And then came HashiCorp Nomad. Yep.
We can be deployed just as a Docker container. Okay. Or we could be deployed in Kubernetes.
Okay. Got it. And we can even be deployed in Windows, if you like.
Listen to that. Oh, you're the first one to mention Any deployment in Windows. People don't talk about the W No, they don't.
They don't. They don't. It's the year of the Linux desktop.
But anyway, um, did we mention the website? io. Say it again for me.
io. Dot io. io to, and download the open source package and install it yourself.
Yeah. It's on, it's on GitHub. You can download it through a helm chart.
Uh, there are many ways to install it. Absolutely. And then once you're up and running, putting in the, uh, the, the third, the, the premium modules, as you said, it's a 32nd exit.
It's a helm chart update. Takes 30 seconds and you're good to go. Excellent.
I can't What, well, let me ask you, what has the show been for you this year? It's great. It's great.
We announced actually some, some great stuff this Week. Well, what you announced, So there's a, you know, with everything we just discussed, there is a fragmentation problem happening now in the industry. It's a big realization.
People are having that virtual machines are not going away. Yeah. So there's gonna be a coexistence of virtual machines and containers, and now serverless workloads as well.
Mm-hmm. So, and But they're not mutually exclusive. They're not mutually exclusive, but the way people manage them are very independently and differently managed.
The way you manage a VM stack and the way you expose your services running inside a VM is very different than the way you expose and manage a Kubernetes. Yeah. So what we have launched is a unified layer, uh, which we call the application layer intelligence that connects the VM environment and the Kubernetes environment, and also the serverless environment.
We launched support for, you can Manage all three. So you can manage all three in a very cohesive way. And it's through a single application layer, which is a layer seven, uh, construct.
Mm-hmm. And you can seamlessly redirect traffic, because what's happening is, as monoliths are being decomposed into microservices, your backend might be sitting in a vm, but your front end is going into Kubernetes. Absolutely.
Right. But it's still, still the same application. Yep.
So, at the application layer, when a traffic comes in, you want to have that intelligence so you can seamlessly direct traffic. It goes left or right, or somewhere else. I mean, with containers, they literally could be distributed anywhere.
Right. It, it's not just Right. And we did the integration with Nutanix as a, as a reference architecture.
Oh, very cool. 'cause Nutanix as a platform does a great job of providing a virtualized environment and the Kubernetes environment, you know, so they have their A HV with flow networking for virtual machines. Right.
We have done the integration with them. And what that allows users to do is to auto discover all the virtual machines that are running, so then they can write policies against it. We are already working with them in the kuber, in their Kubernetes distro, and we can auto discover services running there.
And now with K native, with serverless, they are the perfect reference architecture for this solution. Mm-hmm. Excellent.
Any other announcements here? Um, just that we on the gateway, API, you know, which is on everybody's mind, uh, here, uh, we continue to lead support on that. 4.
Uh, our founder and CTO and other team members, they're part of the c you know, the community actively working with the Gateway, API community in advancing it forward. So, you know, that's one of the other big announcements that we continue to open source is important for us. It's very strategic for us, and we continue to invest in that.
I love it. Alright, I think we're about outta time here. I think we hit most everything.
Is there anything we lost about Think so. Oh, just, uh, you know, you know where to find us. io.
Very cool. Thank you very much for being here. Hey, thank you.
A enjoy the rest of CubeCon. Hey, we're going to take a break. We've got, well, we probably have another two hours or more of coverage here at CubeCon today.
We'll be back again tomorrow, but let's take a quick, uh, break. We'll be back in a moment. Me.
Hey everyone. Welcome to Ingram Micro one. We are on the ground here at the event on the floor.
I'm Daniel Newman, CEO of Futurum. Excited to have this conversation there. We're gonna talk a little bit about ai.
We're gonna talk about a lot more here as well. Excited for this conversation. Talk a little bit about the I and the lens of the CTO, the MSP and how they're thinking about their business transformation.
And for that, I am joined by Dom. Dom, welcome to the show. Good morning.
Good to have you here. Happy to be here. Yeah.
So, um, let's start. I mean, Ingram is in the middle of its own transformation, right? People that had followed the company for a long time probably knew it best for being one of, if not the enabler facilitator, uh, for all of that infrastructure that is being deployed now.
That's a hot topic itself today. Yes. But you're, you're becoming so much more in many ways, becoming a platform company yourself, kind of interested in your role, you know, how you're thinking about that.
Um, you know, the CTO role, the transformation of a big business. I'd love to start you out. Just talk about what, what kind of what you're doing there with Ingram.
Yeah. Was all great to be here. Thank you for the opportunity right After it.
You know, when I started, uh, at Ingram Micro, this is one of the best opportunity in my lifetime. We don't want to build technology for the sake of building technology. The reason I join here is to build technology, which will bring outcomes.
Yep. Not only for Ingram, it's for our e partner ecosystem. So if you go back and see what we did with X vantage, we built based on the data, the data is the new fabric.
We knew this three years ago. We took a big bet on AI three years ago, build and centralize all our data to a one single data lake. And now our AI factory is works based on that data lake.
And now we got like 400 a models and like, you know, 30, 30 plus, uh, patents pending. It sits on like, uh, four petabytes of data. We are able to sit in the middle and understand, not only distribute the data, not only distribute the technologies, we are able to distribute the intelligence to the community.
That makes a humongous difference. That's what is advantage is all about. You know, I love what you said, you're kind of right in the middle of it all, but like, you have thousands if not millions of, of, of integrators that that depend on in integrators, MSPs, channel partners, consultants, that all depend on Ingram to get equipment and software and services.
Then of course, you have thousands of vendors, uh, OEMs and others that you guys are basically handling distribution. Like was it, did they come to you and say, you know, Dom, help us. We need to build, uh, something that a data lake we need to, or was this kind of the foresight that you had to say, like, we see where this is all going.
We're gonna need to build something that can connects the end users and implementers all the way up the food chain to those that are building the most advanced NVIDIA servers on the planet? Yeah. Great question.
So B2B industry was not that far ahead. Like three, four years ago when we saw from our lens, the B2C industry was up there. Yeah.
But the B2B industry wasn't. Yeah. So our vision was bring that B2C experience into the B2B ecosystem.
If you wanna bring that, there is no other better per place than Ingram. We, we always know data is the new currency. If you're able to bring the data into one place every time, Dave, when you go to them, you know what they ask, don't gimme the data.
I have dashboards, I have reports, I have bi, I have this gimme intelligence. That was our spark. If you really wanna give them, distribute the intelligence, like if we, the way we started was we started with our customer platform.
Simple as that. Hey, listen, we just sold the last 10 orders. Can you please tell me which one I missed?
Attach a warranty. They just didn't know. We knew That is the beauty of having all that data.
So you basically, if I, if I break that into a couple parts for the audience, it's like, one is, you know, you were sort of looking at the Amazons and the Shopifys and the com and it sort of revolutionized, you know, I know we talked off stage a little bit about E-Trade and different, like the platforms that sort of brought consumers in retail to things that were always done in sort of a B2B behind the wall with, you know what I call it? The ABBA cadabra. Yeah.
Yeah. You know, and you're saying, why are we doing it and making it so hard? Why don't we democratize this?
Why don't we, if you can get anything you want ordered and delivered to your house in 12 hours, why is our system, you know, a bunch of, uh, a black screen with orange text on it? Right? I mean, but that is kinda what it, what being at times, like it moves slow.
Um, so talk about how you pick which things to do For, for us is, you know, we don't wanna build technology for the sake of technology. We wanna build technology which will bring the outcomes. Yeah.
Because like I said, there is people, people can build more chat bots, more dashboards, and more technology. No, we are, we are not in that business. Focus is outcomes.
Can you remove complexity? Can you remove friction? So if you look at, if you focus on outcome, and when it comes about prioritization, that becomes our biggest, biggest focus.
Let's say, if you take, if you wanna save time, time is the biggest commodity. Right. You know, when you talk about outcome, there is like, oh, it's a top line, it's bottom line.
But everything starts with time. Where is the bigger place you can save time for your partners today? Like we build so many things and it's all about saving time.
Like, you know, if you want things like X one integrations Yeah. Where before the partners used to call us, email us, and the orders used to take hours and days sometime to get processed. What we said, listen, please come us you are, don't change your system.
The integrations gets complicated. You got Excel sheet with a bunch of information about your transaction. Just send it to us.
We will process that using ai. We will normalize the data. We will go transact.
You don't have to change your system. We just save time for them. And same thing with, you know, PDFT skews.
So there's so many ways where these partners are struck in the way they do stuff. Yeah. Either they're coding, they're ordering, they're invoicing, their subscriptions.
Now we made that all that so simple for them. Yep. The money you simplify.
That's our focus. Because you, like you said, there is a million things to do. But if you focus on outcome, not just for Ingram, also for your partners, that will distill your priorities straight out.
And that somehow has to flow to the MSPs and partners focusing on outcomes for their customers. Yeah. 'cause now what you've done is you've taken some of the monotony out.
You take some of the, you know, the extra layers of work. You've probably enabled some of them to reduce some of the back office overhead and invest more in front office and growth. And like, what are you seeing there?
So, you know, outside of just efficiency and uptime, like what are you seeing in terms of your MSPs translating what you're doing in the platform and, and what are they building for their customer? Yeah. See, I would say my humble as to the MSPs, they gotta become these AI enablers.
There is no more break fix and maintaining infrastructure and all that. They really gotta get into this train of what's happening. I can tell you from Ingram perspective, my own experience, how we and our jobs change and how we transform.
We distributed intelligence through our customer platform where they can come download their business review. They can see what is they're selling, what they're not selling, what is a cross-sell upsell. We distributed that intelligence through the customer platform on the web.
Then we moved on to the next level is, hey, we wanna make integration simpler. We use AI and completely changed the made all those autonomous work. We just automated it.
But now what they want is they want the data, their data with our intelligence into their ecosystem. Which means if they use CPQ, Salesforce, any CRMs, anything they got, now this MCP connectors are all over the place. You go to AWS, you go to hp, you got Ingram.
Everybody has provided these MCP connectors now where it can provide their intelligence into your system. And that's what Ms. Ps really keep their eyes open.
Don't try to do everything by yourself. Look out for your partners, look out for Ingram, look out for those integrations, and look out for so many technologies, what we provided. How you can become the first platform mindset and then you become that a enabler your life is going to change for good.
Have you seen any, you know, I know it's early days, but have you seen any anecdotal, have you seen any, you know, with the MSPs you talked to work with like really cool implementations, applications even theoretically, that you could show? I'm just kinda curious like, oh yeah. You know, things that you're seeing them now do with that extra capacity that you're giving them.
So Where, where they will go is like going from what we really want them to make is go from auto takers to order makers means save time. Don't be in doing this autonomous job of doing stuff, which you don't have to do. We, when we save the time, now they're doing that in the proactive sales where they're able to go to take care of their end customer.
What is their job? Their job is to take care of end customers. Not doing this middleman job of just, you know, typing in codes and orders and invoices and splitting.
We, we completely take that now. We clearly see their teams are able to go back and do a proactive sales with their end customers. So what about the MSPs from all the work you're doing right in terms of, you know, building agents, building platforms.
Like you do it at such a big scale. And I think sometimes, uh, when you're a smaller company, you know, these MSPs that you work with, some of them are a handful of millions, some of them are hundreds of million, some of 'em billion dollar companies. But in compared to your scale, some of them are, they're all still maybe smaller, many are still, what are you seeing?
What do you think from the experiences of the work you're doing translates? I mean, the things that they can learn from to, to build in their own businesses? Great Question.
You know, automation, I would say that's a common denominator for all of us because they also have their ID ecosystem. So go back and see where you can automate, automate, automate everything possible. And that could, you can take help from like people like Ingram Micro or like go to AWS or HP or any of these vendors.
So for example, you take your L one L two ticketing system. You don't have to do this with a multiple vendors and multiple ways. Now you can use these agents to harmonize all the data, bring a single pane of glass for your end custom.
So to me, that automation is a common thread. And they can use AI to a very large extent where not only they can create their own L LMS and their own agents, they should automate and connect that with every other players in the ecosystem. Once they connect that, they will bring that a single unified experience because standardization is key.
You can't let your end customers go to five different system to see five different things. That's returns, that's claims, their tickets, their codes, their orders, their invoices. They cannot be in a multiple in multiple systems.
If they can bring all that into a single unified experiences through that automation, that's gonna make everybody life easier. It's funny, I keep thinking about when Sam Altman talked about the one person billion dollar company. I mean, there's probably orders of magnitude in between where we are in there, but what you're saying, and what at least we're finding even in our own business is, look, so many of the processes can be done.
It's either 10 x or one 10th. Like you either need one, like with automation, and it's kind of the promise that we never had with RPA, right? Like RPA just it, it did some things well, but it was always too fra.
I, i fragile is the word I would use. It was just too fragile to scale. And now with, with automation and ag agentic, we can do these things like much, much Faster.
Much faster. Like I have built APIs, I built RPAs, I build screen scrappers, I build all kind of technology. I can see it, I can say my job has changed as a chief technology officer in the last two years, the way we build platforms and now we build these agents.
Now it has become, I can go to market so fast right now with these technologies either writing code or writing the agents. And they are making things so fast. So good for us.
I'm telling you, that is what this industry and MSPs has to ca get onto the train, understand how these technologies work. Please lean on your partners. Go look at integration hubs.
So many plugins, so much is available for you to take it in and make things easier. That's a great, great way to maybe sort of end. I want to ask you about just the role of the MSP.
'cause what I'm hearing from you is you're a believer. You buy into the power of AI as someone who's done development work, not just kinda lead technology, you're kind of saying it's making things better. It's, you know, 'cause there's a lot of that debate.
Like is it eliminating the code? Is it, but like for the MSP that is seeing all the power, all the potential, everything that it, automation, ag, agentic, that ai, that data, uh, and, and inter integrations can do. Like, how do you recommend that they think about evolving their businesses to make sure that they're gonna be successful throughout this transformation?
You know, my first ask to them is like, go centralize your data. The technology like ai, it's cannot work without the data. If you got multiple sources, your code, your orders, your invoices, your if, if these are in different, different systems and places, you are going to have a very hard time harmonizing this data.
Start there, harmonize your data, try to put them in one place, and there is multiple technologies available to make it so easy for you. Now, before, like five years, 10 years ago when I was trying to do that, it was a lot harder. Right now, harmonizing all your data in one place, it is going to make it so easy.
Then you can plug and play any AI you want. That's a general DOI or even even your AI agents. They can come and consume the data and bring intelligence to you and automate anything what you want.
But start thinking about how you can harmonize the data across your systems that will set you for a very long time. Sounds like a great way to end this conversation, Dom, what a pleasure. Congratulations on all the progress you're making.
Love to keep chatting to you more. Have a great rest of your Ingram Micro one event. Thank You Daniel.
And thank you everybody for joining us here on the ground at Ingram Micro one here in Washington, dc Great conversations stick with us here on the channel for more to come. Nvidia has cloud aspirations, more like our don't Dino NATO is googling some stuff. Amazon launches some satellite antennas.
Splunk donates open telemetry injector project, sudden catcher in space. And we're gonna dive into the new AI infrastructure investments from Nokia and AWS in this week's episode of the Tech Field Day rundown. Hello everyone out there and welcome to the Tech Field Day rundown.
Today is the 26th of November, and if you are listening to us in the United States, I hope you're not doing it at work because of course it is the week of Thanksgiving, which means that most people have already decided that Wednesday and Thursday and Friday are national holidays, even though it's really just Thursday. But it is National cake day, no lie for everybody that celebrates. And joining me, of course, is my wonderful co-host who doesn't celebrate Thanksgiving this week.
Mr. Alistair Cook. Al, it's good to see you again And it's always good to be here.
And it was great to see you in person last week. I'm looking forward to some of the interesting news we have coming up. Yeah, it should be a really fun time because of course everybody's trying to cram in their last little bits of important stuff before everybody then goes to eat, uh, gravy that has gits, you know, little bits of Turkey, Turkey in it.
Uh, we're gonna go ahead and start off with, uh, some big money news because Nvidia plans on spending 26 billion over the next six years to secure cloud GPU capacity for its AI projects that would make it one of the largest cloud infrastructure buyers company is partnering with providers, the names that you've heard before, like Lambda Core Weave and Oracle. And they're gonna create a system where they're both the supplier and the customer. The move comes among, among strong AI demand regulatory uncertainty, and frankly limited GPU supply highlighting how even leading chip makers are gonna have to lock in compute resources to stay competitive.
Al is it weird that Nvidia is not only selling them the GPUs, but also buying that capacity right back from them? It's a weird continuing trend that we've seen. So this is, uh, very much the, the idea that the money go round of AI is, uh, Nvidia giving money and receiving it, giving money with one hand and receiving it with the other, uh, in terms of what's going on, that is a, a very big uplift.
So Nvidia is talking about this as being their need to run AI for their internal business requirements. And they're talking about it as being 1 billion in this year, rising through to 6 billion, uh, for the, the, the following couple of years and then tapering off maybe in this particular volume. And who knows what you're gonna spend money on in five years time.
It may not have been invented, uh, but there is definitely a a lot of money being spent here and it's being spent by Nvidia at customers of Nvidia who are buying NVIDIA's ccp, uh, GPUs. Uh, one of the vital things to see in this is that, uh, NVIDIA's GPUs are hard to get hold of if you're not buying them by the thousand. And, uh, that's what we're seeing is these, uh, cloud providers in particular, some of the, uh, core cloud providers for ai in this case, we, we saw sort of said core weave and, and Oracle and Lambda in here.
Uh, some of this is that, uh, Nvidia themselves are stepping away from the idea that they will do a renter GPU model. That was something that was the, the DGX cloud was supposed to be this renter GPU that they're gonna be providing to others. It looks like we were actually seeing the, the shift away from that.
Instead, Nvidia has been very aggressively encouraging neo cloud providers, so new people to spring up and deliver clouds that are just for ai. Um, Nvidia has been pushing those very hard so that there isn't so much of a market dominance from the existing cloud players. Uh, some of the spend will be on, on exactly those same neo cloud vendors.
And I do wonder whether there's an element here that they're going to be customer number one for these neo cloud vendors who allows the neo cloud vendor to get funding to then buy more GPUs or buy their initial seeding set of GPUs from Nvidia. So it, there is a, a, a little bit of a sniff of this, of of being kind of a, a, a tenuous money go round to make things look good. But I think there is also a requirement for Nvidia to use their own GPUs to, to actually transform their business with AI in the same way that they're telling their customers to transform their businesses.
Uh, one of the other elements to keep in mind here is that, uh, the restrictions on export of the, uh, Nvidia GPUs to, uh, less friendly states has had some impact on NVIDIA's uh, financials. They've, uh, incurred a four and a half billion dollar charge earlier this, this year, tied to not being able to fulfill orders because of these restrictions. Uh, and so this may also be some of the play around keeping things priced still, $26 billion is quite a lot of cloud investment and seeing that go to established cloud players, providers who are are delivering good GPU services is probably good for the market, but I'm not sure that it's a, a huge net change.
Qualcomm's new terms for the Arduino have angered the maker community, uh, including maybe myself since I write a, a whole bunch of duo code, they've added sweeping rights over user content. So since Qualcomm acquired duo, they're basically saying anything that you produce on our platform belongs to us. Uh, and the other thing is that they've, there's a ban on reverse engineering, which goes away from the whole core open source ness of Arduino makers and companies like, uh, ADA Fruit argue that Qualcomm is undermining what made Arduino successful and prompts many to switch to other types of, uh, CPUs for these, the same projects, things like the Raspberry Pi 2040 MCU and my favorite, the ESP 32.
Uh, ASA says the changes, uh, were for clarity and compliance, but I dunno, Tom, uh, it seems to have angered a few people. I think it angered a lot of people. And honestly, I am not surprised because I secretly kind of knew this was coming.
Uh, remember Major League two when Charlie Sheen puts on the the suit jacket and gets rid of the bad boy image and everyone's like, oh, well he's still the same picture. He is just, he's a little bit more grown up now. And, and that's like a whole plot line in the movie.
I won't spoil it for you, but that's exactly what, what what's happened here is that Arduino basically said, well, we want to be, we wanna be underneath the umbrella of Qualcomm, uh, because we would like to get money and not go out of business. And our, the Arduino folks were happy to do that. And they, they said the things that you're supposed to say when you, when you become part of a corporate organization right, is that, you know, nothing's gonna change.
We're still the same people. We just maybe wear suits to the office now. And Qualcomm was like, okay, cool.
You know, we, we promise that we're not gonna mess things up. We just need you to agree to this legal writer that says all of the things that everything else says, right? We're gonna collect your data, we're gonna, uh, anything you make with our stuff is technically ours because you're using our stuff.
And, uh, we are also going to restrict your ability to reverse engineer a whole bunch of stuff that we don't want you to poke around in. I got news for everybody out there that's boilerplate. That is pretty standard.
If you go to work for any major organization and you invent something on their dime, it's their invention, not yours. IB bm, Cisco, you name it. Any patent you file when you work for them is the patent of the company, not yours.
I agree wholeheartedly. You're, you're gonna be the, I'll be the first person in line to say that this is not what the Arduino community wanted. But I think the other thing is the Arduino community did not want Arduino to go out of business.
So you've got this catch 22, right? If we wanna stay in business, we have to play by Qualcomm's rules and they are Qualcomm's rules. I I'm, I'm almost positive that every company that Qualcomm has acquired same kinds of things.
And yes, a lot of people in the community are gonna come right out and say exactly what we've heard from companies like Ada Fruit, I don't like this. You're, you're destroying the, the rebel spirit of, of who we are. Yeah.
When that's what happens when a company has to basically mature. And if that means that someone's gonna have to just jump out on their own and kind of spin some things out and do their own thing, okay, great. We're all better off for that.
How many startups exist in Silicon Valley? Because the company, the founders of the company realized they couldn't make what they wanted to make under the umbrella of the corporate entity. Like that's the, the part and parcel, that's the other rebel spirit, right?
That's, uh, Steve Jobs and his team going across the Apple campus to make Macintosh flying the jolly Roger from all the windows because they really were the gang of pirates over there. And, and now look at it. So I think that there's gonna have to be some give and take here.
Qualcomm's gonna have to understand that they may have to reli relax some of these restrictions if they want to continue to let Arduino kind of be the, the leader in this space. But at the same time, the people who are fans of Arduino are gonna have to realize that, you know, maybe what you want to do with the system is not compatible with what corporate America wants. And if that's the case, there's nothing wrong with moving on mass to the next thing, but just make sure that you've got all your breadboards wired correctly.
NATO is working with Google Cloud to build a fully air gap cloud for classified workloads, letting its joint analysis, training and education center, also known as JTE run AI analytics without using the public internet. The system combines strict security with commercial cloud tools giving NATO both control and high performance computing. This deal, which is part of NATO's multi-vendor approach alongside AWS and Microsoft, reflects a growing trend in defense towards secure hybrid cloud architectures for sensitive data and advanced analytics.
Al do you think NATO made the right choice here by kind of spreading the resources out along with Google Cloud? You know, I think having a strategy of using Different technologies for to solve different problems is pretty common. And, uh, the reality for any large organization for cloud adoption is typically hybrid multi-cloud.
But defense and NATO in this case are, is always a special case because there are always the networks that are secretive of some sort, uh, whether that's top or extra top secret. Uh, and these networks are supposed to be fully disconnected. They're supposed to be separated from anything that's accessible on the internet.
And, uh, it's one of the, the fun things of working in defense is working with these area gap networks where you can carry your install media into the bunker where the network exists, but you're not carrying that install media outta that bunker ever. Uh, that's the kind of network they're talking about and cloud they're talking about. What's different here is those networks that are highly secure, usually very tightly controlled, very sort of waterfall development kind of, uh, environments.
And the suggestion of using Google Cloud platform inside this air gap highly secure network suggests to me that they're looking for more agility and the ability to do new things on these secured networks that they would previously have had to do on a public network. And there's been some interesting challenges around sovereignty recently. Some of the discussions around sovereignty have come up and that if a US company is operating a cloud and your stuff is in that cloud, well, US jurisdiction may still apply.
Well, that's not the case if it's completely disconnected from the us uh, network. So from the internet, I believe this is a way of avoiding any kind of oversight from outside of NATO on the data that's in this, this network. So it's not NATO turning their back on doing things on the public internet, that's why they still have, uh, both the AWS and the Microsoft relationships.
But it is a, a symptom that those secure networks are getting a lot more agility and particularly getting a lot more AI in there. And you can imagine that these secure networks are involved in things like, well, maybe running surveillance, uh, drones and systems and that AI could be very beneficial to lightning the load on the human operators who are involved. Uh, I think this is definitely gonna be an interesting project.
Uh, I would love to be working on this project just to see what's going on inside it. Although I would also hate to be working on any defense project that requires security clearance because then you can't talk about it. Amazon Leo formally, project Cooper has launched its new ultra antennas offering up to one gigabit per second down and 400 megabits up along with an enterprise, uh, preview for select customers more than 150 satellites in orbit.
The service targets business and governments, uh, agencies needing fast and secure connectivity in remote areas. The new ultra terminal uses Amazon design silicon and support private networking like directs and built for demand environments. Early partners include JetBlue and Hunt Energy, and they'll be testing this new antenna before broader rollout in the next year.
Tom, this sounds like an incredible piece of mobility that maybe is targeted against some other provider of Tite, uh, internet, Who knew that the two people who were racing to be the first, uh, CEOs in space would come out with competing projects that were designed to provide connectivity to space. Yeah, I would, IIII totally knew this, uh, this is the outgrowth of what we saw as Project Kuper, right? Is they're gonna launch all these communication satellites into lower earth orbit and now they have an antenna that will allow you to talk to them.
I will say it is nice that it is gigabit downlink and 400 megabit uplink. So, you know, that's, that's competing with most of your home internet plans. And I, that's like the, the ultra tier, so I'm sure that's gonna be like the ultra expensive tier.
Uh, there is a smaller tier that runs nano, which is a smaller antenna. So naturally the, the, the bandwidth is a little bit more restricted. There's also a pro tier, which I'm sure probably just means that you can cut in front of everybody else in line.
Uh, they're testing it with partners like JetBlue and JetBlue's gonna be using it to augment their existing, uh, plane wifi. And, and this is a trend that I've actually seen in a lot of other places because starlink is becoming the defacto communication system on a lot of like hypermobile things. All of the billionaires that are building brand new luxury yachts, they all have starlink terminals integrated into the yacht.
Uh, that's so that they can pretend to be in the office when they're actually floating somewhere off of a coast and they're doing work and they, they, they spend all of their money kind of refurbishing these offices so that it looks like they're actually working when in fact we know that they're probably not even wearing shoes at that point. And that I think is one of the places that we're gonna start seeing some of this kind of, uh, flushing out a little bit is remote access terminals. We, we've seen that with starlink quite a bit.
In fact, I know a couple people who have starlink terminals who use them for things like, uh, being a digital mo nomad or, uh, providing ultra high speed connectivity in places where it's really impossible to get a cell signal like the backcountry. And I think that the value here is that with the smaller nano antenna, you're gonna be able to basically carry that like a backpacker, right? Uh, but for those kind of fixed in placements, think oil rigs, uh, think remote construction sites, uh, this is a great way to provide a, a deployable network without needing to like, you know, run cables and get access points up and running and deploy like a huge infrastructure.
You can just drop this antenna down and it works. And the key advantage here over starlink is that this is built by Amazon and it's optimized to use Amazon's services. So you can get a direct Amazon link, which I'm sure will in, you know, speed up any kind of AWS uh, up link down link type stuff, which is what you would want if all your stuff is located in aws.
But also by optimizing it for things like video conferencing and other applications that you use, it means that you either A, don't use nearly as much bandwidth or b it will give you a better experience overall in case there's some kind of weird outage, sunspot, solar flared, you name it. I, I think that the other advantage of doing of having this come out of Amazon is that it will create a competitive market so that then it will force other providers, cough, cough, starlink, cough, cough to get better at what they're doing and to provide better service, to provide better connectivity, to not have weird restrictions like, oh, you can only buy this smaller antenna if you're a customer on the bigger antenna and that kind of thing like that. So this should be good overall.
I just hope that we don't end up populating low earth orbit with a constellation of satellites so thick that we can't fly through it. Um, 'cause you never know who's gonna do something crazy, like decide to build even more stuff in orbit. Wait, hold that thought.
Splunk has contributed Its open telemetry injector library to the CNCF open source project, making it easier to monitor legacy non-con containerized applications. The tool automates instrumentation for production apps, helping DevOps teams collect telemetry with minimal effort. Splunk also added a schema for tracking AI workloads and LLM performance, supporting consistent metrics for cost, performance, and bias.
This donation highlights the growing importance of observability for improving operation security and AI readiness beyond traditional DevOps. Al, do you think that this is going to encourage people to wanna adopt more CNCF, uh, telemetry tools, or is this Splunk just basically saying, we're getting rid of this because we're moving on to better things? Well, I did see at Kon this year a huge amount of open telemetry, um, adoption or observability, really coming back with open telemetry at its core as a way of getting data, uh, telemetry data from your applications to somewhere else, be that, to Splunk or to any other, uh, open telemetry compatible, uh, receiver.
Uh, in terms of what's what's announced here, I like that what, uh, Splunk has donated is a, a really simple tool to install on a legacy, uh, virtual machine or physical machine that is running a legacy application. A non-con containerized, I'm sorry, I should be calling that a heritage application because legacy seems like a bad thing. Uh, heritage application that is still running in, in physical machines or virtual machines.
Uh, you know, those of you living in the cloud native world may not realize that there are still an awful lot of applications that just run in virtual machines because there's no value to shifting those into containers immediately breaking them into a tiny set of microservices. There's a huge amount of work there. So being able to instrument those applications without having to rewrite the applications, uh, the, the injector that's been, uh, donated here is just piece of software that gets ins installed on a machine and sends what is local metrics into hotel and into open telemetry, and very much as an enabler for adding, uh, your legacy components of your application to your modernized components.
Every application, this is absolutely vital, where companies are developing new capabilities that still leverage older data sources or that are following the Strangler model, where you start building microservices probably in containers, uh, on top of Kubernetes to build the new features around your existing legacy application. This lets us instrument that legacy application. I like it.
I also like that they, uh, announced more open telemetry and, uh, large language models, being able to gather more information out of your, uh, LLM based applications, particularly as we see that move towards ag agentic applications, getting more telemetry data out of what the actual LLM is doing. Not just the performance information, but is it actually doing the thing it's supposed to do? Is it doing things safely?
Uh, are we having sort of compromises in in the, uh, LLM? These are things that the companies are very much concerned about, and I think it's, it's great to see more visibility of what's actually going on inside, inside these modern applications. So both really good things.
I think Splunk has done a great thing here. Uh, I don't think that it's entirely altruistic. I think they definitely want to show some leadership in the world of open telemetry, because sometimes hotel is talked about as a way of replacing your, uh, heritage, uh, logged tools like Splunk that charge by volume of data moved through them.
So it's, it's not entirely altruistic, but it's a great thing. So I told you to hold an idea. Recall that idea.
Now, because Google's project SunCatcher is testing the idea of moving AI data centers into low earth orbit using solar powered satellites with high speed laser links. The system aims to provide more energy and faster connections than earth-based data centers. Hmm.
Early tests show promising speeds for connections and prototype satellites are planned, uh, by Planet Labs in 2027, uh, full scale orbital data centers. Yeah, probably a little further away. And the project reflects a growing effort to meet the massive demand for computing and power for AI applications.
Does lead us to some concerns about filling the night's skywood data centers and making the whole place blow in the wrong place and dark in the wrong place. Tom, are you gonna service these AI data centers in the, in the, uh, low earth orbit? Yeah.
Let me just, uh, break out one of those space shuttles and, uh, and oh, wait, we, we retired those, uh, dragon capsules. Yeah, maybe, I guess, I don't know. I, we, we, we heard about this from Amazon, remember?
Like, they, they wanted to, they wanted to launch things into space, and now Google's like, no, no, no, we, we wanna do it too. Uh, can I see the tests that, that, that these things are promising? Because I have a lot of questions about how this is supposed to work.
Uh, number one, how are you gonna cool all this stuff in space? And before everybody out there says, well, space is really cold. No, no, it's not.
Space is empty. There's a difference. One of the things that we've learned over the years is that things in space can actually get really, really hot for two reasons.
One, when there's no particles around, you can't radiate heat away. And two, there's this thing that's about 93 million miles that way that, uh, will really heat stuff up, because again, there's nothing to block the, the solar radiation, uh, when you're in space, uh, we, we've learned that a lot from astronauts. Like it's, it's, it's a little bit different out there.
Like literally the sides of your spacesuit can be two radically different temperatures because one side is being hit by the sun and one isn't. Uh, the other thing is, like you said, what what's gonna happen when something breaks? Uh, you think it's hard to do a truck roll to a data center in the middle of prior Oklahoma?
Uh, wait until that, uh, truck is gonna have to roll, you know, a few a hundred kilometers north, uh, and galactic North, by the way. Just, you know, this straight up, that that's gonna be a huge problem. I, I wonder though, why, why are we launching these things into orbit?
Because one, if you wanna use solar power to power data center, cool. Build it down here. Like, like there's nothing stopping you from building a solar array down here.
Uh, we turns out we're really good at building those things. Is it a space congestion problem? I don't know.
Uh, there's a lot of space, but here's the thing that most people don't understand. For things to work down here, they have to be in relatively close space. That's why they're in low earth orbit.
Uh, GPS satellites are actually almost too far away, uh, for the amount of data transfer that they're gonna have to do. Uh, something like the James Webb Space Telescope doesn't even orbit Earth. It orbits a LaGrange point, uh, closer to the sun.
Uh, if you wanna look that up, that is not the song by ZZ Top by the way. Uh, but the, the ultimate problem that I have here is there's no reason to be building these things in space other than somebody said that they wanted to do it. There's still plenty of space down here to build those data centers.
I think that this is a, uh, marketing tactic, a ploy to get people to maybe give more favorable terms to have it built somewhere. Uh, you know, 'cause I guess their argument is you can't tax things in space. Uh, unless Google or Amazon or Microsoft or Oracle or whomever, uh, developed their own fleet of space vehicles last week, they're still gonna pay somebody to launch this stuff.
And I promise you, if you thought getting overnight delivery on something from Amazon not on Prime was expensive, wait until you see what it costs to lift that stuff into orbit. It's not cheap at all. So I I, I watch this with bated breath only because I'm hoping that somebody in this weird fever dream is gonna wake up and go, why are we we putting things in space?
Uh, if we, if we can't maintain the ISS and we're worried about having to de-orbit that thing pretty soon. The last thing we need to be doing is putting a whole bunch of data centers up there, because eventually those suckers are gonna come back down to, we hinted at it in the opening of the video, but we wanted to take a closer look at some big investments that have been going on this week. It seems like right before the holiday, everybody wanted to announce the fact that they're investing a lot of money into AI infrastructure.
I wanna start off with a company that we just recently covered on networking Field Day, and that's Nokia because they've agreed to commit $4 billion to US research development and manufacturing to speed up AI ready network infrastructure. Most of the funding will support r and d at Bell Labs in New Jersey, and the rest is gonna be going to facilities in Texas and Pennsylvania as well. The initiative, which is backed by the current presidential administration aims to boost domestic AI capabilities, improve connectivity and strengthen national security, while also meeting growing demand from AI and cloud customers with and advancing Nokia's partnership with Nvidia.
Al I'm gonna jump in here and talk a little bit about this, because Nokia is really trying to make moves to be a valuable partner in the networking space. They're building out infrastructure that will allow them to build AI ready networks. And one of the things that we learned at networking Field A is that's not easy to do.
So you may probably look at this and say, $4 billion doesn't sound like a whole lot. Well, when you're looking at the amount of money that Nvidia and Microsoft and open AI and cloud core, we and all these other companies are throwing back and forth at each other. Yeah, 4 billion doesn't sound like a lot, a $4 billion for a company like Nokia to invest in AI networking.
That is a ton, and I think it's super important because that's the way that the data gets moved from where it is resting currently to where it needs to be processed and run on these inferencing tools and things like that. I'm glad to see that they're, they're doing this. And the, the discussion that we had at Bell Labs, uh, it was actually something that was discussed by Scott Roon from AL during the Nokia presentation at Networking Field Day.
You know, they have a lot of good data points on this. Like they've done a lot of work out there. They're really, you know, hitting this pretty hard.
I think it's important to understand that, that just because we're not seeing huge dollar values flying back and forth outside of GPUs and compute clusters doesn't mean that there's not a lot of research going on. Al what's your take on this? Yeah, I think it is important to put context on, on what $4 billion of networking, uh, and particular networking research looks like compared to the tens of billions of dollars that we talk about for buying GPUs.
And, uh, GPUs are ridiculously expensive. Uh, a single GPU can cost as much as a new car. Uh, but you don't need an, a new network switch for each of those, uh, GPUs, you, you hang those GP multiple GPS off a switch.
So in terms of what things cost and, and the scale of investment, $4 billion is a big deal here. Uh, and as you say, the, the network is often one of the challenges in building an infrastructure for ai. And we'll look at this, uh, again in January with AI infrastructure field date.
Uh, moving the data to feed those very expensive GPUs is a, a vital part of getting the most value out of them. This is why network design for AI is a critical part of any AI data center infrastructure design and this commitment to, to do r and d, uh, onshore in the us really great thing. It's very helpful for, uh, the US sovereignty to here to not be looking outside to network vendors that may be Chinese, but, you know, having Huawei and, uh, the likes being on on the outside these days, um, due to some, uh, concerns around sovereignty.
So seeing Nokia committing in here, supported by the, the current government, uh, hopefully supported by future governments as well. Uh, really good thing to see. Of course, at the same time, AWS is spending lots of money as well.
Uh, AWS is spending the, the kind of money for building entire data centers, so $50 billion for government AI infrastructure. And this is where we start seeing those, those big numbers again, where lots and lots of GPUs are gonna be stuck up in wreck. 3 gigawatts of computing capacity across, uh, the government cloud regions that AWS operates, it's, that's pretty significant.
We know the government cloud regions are usually slow to adopt new technologies. It takes quite a while for the technologies to get certified. And I think what we're seeing is US government customers saying to AWS, we, we need the certified, we need these AI capabilities and we're going to take them from the cloud.
So this, uh, $50 in invest, uh, 50, $50 doesn't get you very far. It doesn't even power the GPU for an hour. Uh, $50 billion is, uh, quite an investment in the GovCloud side and bringing AI to it.
Tom, uh, do you see the same thing going on with more and more AI being used in, in government use cases? Yeah, actually I do. And I think that one of the things that you have to understand about why this is happening is that the government is kind of running behind here, but that's the government's job, right?
The government doesn't jump out on the, the bleeding edge and do all of this stuff. They want tried and true, secure, capable systems because when they buy, they buy for, well, a decade or more. And, and by announcing this huge investment, because we've also got the Project Stargate stuff hanging out there and a bunch of other things, this is specific to government agencies.
This is kind of, you know, remember Project Jedi? We've talked about that a lot. Uh, it feels almost kind of antiquated at this point to think about, oh, well, you know, the, the pentagon's gonna be moving into the cloud.
Oh my man, that was, so six years ago now we're, we're talking about getting up and running on AI tools and, and figuring out how to do all this stuff. And it's important to note that this is something that was laid out in the previous presidential administration under their action plan. And the idea is, is that we need to start adopting this stuff.
We need to start moving along. But of course, as you mentioned, these things are not sudden. And so I think that the value here is that any advances that are made will probably end up trickling down into other offerings from Amazon.
We're not gonna get access specifically to this stuff that's gonna get built out through this big investment, right? Like that's, that's government is government and we don't touch government, but the lessons that they learn will be kind of cross-pollinated everywhere else. And so maybe we see better connectivity, maybe we see reduced resource utilizations.
Maybe the government decides to build a couple of new nuclear power plants to run these things, and we all kind of benefit from that. Who knows? Maybe the AI will figure out the secret to cold fusion and then we won't have to worry about power ever again.
But I'm not holding my breath on that one. Well, Al that's, uh, a good look at what's going on in the news. And I know that we're kind of bumping up against the holiday here in the us but what's the excitement that we've got on tap for 2026 already?
Well, 2026 is gonna kick off with a big event, uh, at least for tech field. That'll be a big event with the AI infrastructure field. Day number four, uh, we're looking at spending three days out in California hearing from a whole collection of people, including people we've mentioned on this podcast in particular.
We'll have NAIA there. Uh, we'll also have a bunch of other interesting companies talking about how to build infrastructure to support your AI requirements. And particularly I think we're gonna see lots of support for production ai, you know, inference, we get value from your, the next event I've got locked in is Cloud Field Day 25.
I'll be back to California March 11th and 12th. And again, we'll be looking at some fun technologies in your hybrid multi-cloud world. Uh, some of the topics we often visit here.
Uh, check out all of the upcoming events on the Tech Field Day website. Um, you may find that events get added. We've got some interesting things still in the works, maybe in that first quarter as well.
Thanks for watching this episode of The Tech Field Day Rundown. You can catch new episodes every Wednesday, uh, as a YouTube video or on your favorite podcast application. Remember to give us a review and maybe a little like in there, the rundowns also streamed on Text Strong tv, so you can catch us on other text Strong Properties, and you'll often find Tom and I, uh, rum group events and other fun places.
We'll be back next Wednesday to talk about all of the IT news of the week. That was until then for myself and for Hollingsworth and for all of us here at Tech Field Day. Wishing you and yours a great day and a great Thanksgiving.