Techstrong TV – February 13, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
So, is it AI America first or AI America alone? You are watching text again. Hey everyone, it's Alan Shimo.
Happy Thursday. We've got a great texture on gang for you today. We've got some, actually, you want to know the truth?
This might be the most important text on gang we've done ever. We've got some really important issues that I think you need to know about and you need to weigh in on, meaning you the public, because this is not a time for what was the, what is it? Summer Patriots or Summer Soldiers?
Mike, what, what's common sense say? I, I think it Is. Um, I'm not sure, but I'll just call it Fair Weather Friends.
How's that? Okay. This is not a time to sit on the sidelines and hope things work out.
I think every one of us needs to speak up and make up our feelings and wishes known. Um, we're gonna discuss these things. I've got some great people who I know are not shy about giving us their opinions.
Let me introduce you to them. First of all. Uh, well, let's not go out to sea first.
We'll go down to Houston to Texas first, and we'll introduce Anne Awar, who's one of our regular gang members and is never short of an opinion. Hi, Anne. Welcome.
Thank Hi, great to have you on today. Always a pleasure. Thanks for having Me.
Absolutely. From Anne, I think we're going to go out and get sort of the royal view of this from our man in Silicon Valley. John Swartz.
Hey, John, how are you? Hey. Hi Ellen.
Hi everybody. I have plenty of opinions about these segments, so good to be with you. I'm looking forward to hearing him.
John, don't hold back. Speaking of hold back, here's a man. He tries to be politically correct sometimes as he's navigating the seven Cs, or at least the keys of Florida.
He's our cyber expert with, or just, you know, life expert. He's been, he's been around the block a few times. Chris Blas.
Hey, Chris, welcome. It's great to have you on. Good to be here.
I am in, uh, as you say, I'm actually in what you would say is Key West, you know, but to the point of our conversation today, I'm actually in the channel Bo, the Boca Chica channel. The Boca Chica Naval Air Station is right here. You know, where there are all sorts of interesting jets will be flying all day long.
And as you look at strategy, national security, you know that that military base will never shut down. You know, look at its location, look at the strategic importance of it and what they do there, you know, is topic for conversations, speaks to our topics of the complexity nes necessary to actually have effective national security. Absolutely.
Thank you. And then last but not least, the sage of Harrison, our chief content officer, Mike Huard. Hey, Mike, welcome.
Now, I couldn't agree more with you about the importance of today. It's a seminal moment. Pitchers and catchers have reported for spring training, and it's crucial to this country.
I wish you have Your priorities Right. Admire. I, I wish, I wish it, I wish life was that simple.
I wish life was that simple. Anyway, so guys, let's, let's jump into our first block. Mike, you're gonna kick off for us.
But you know, I, I gotta tell you, watching the news yesterday, you know, I, everything I need to know, I learned from three or four movies in my life, the Godfather, Goodfellas, star Trek and Star Wars. They kind of are my, those are my true Norths. Hearing everything that was going on yesterday, I was reminded of the Eugenics wars.
Now, I don't know how many of you know the significance of the Eugenics wars in Star Trek, but as a result that, you know, humanity learned to do genetic manipulation and created so-called Super Met. And one of those guys was a guy named Khan, who was in the original Star Trek series. And then of course, in the movie, the Raft of Khan, I And, uh, Ricardo Manto bla of course, played card.
I'm, I'm reminded of this in what's going on in ai. We, we are on the verge of AI wars, right? With every, everybody here, uh, staking their claim.
No one, you know, no one pledging the work together, per se. Everybody wants to do their thing. And, you know, risk be damned full speed ahead that don't mind the torpedoes.
Um, you know, and, and over this, we're in some sort of new imperialistic. We thought the neocons were bad. We're in some new imperialistic moment here where everybody wants to go carve out their empire.
And AI happens to be the, the new world that they're carving. So, Mike, I, I gave my 2 cents. I'll let you introduce it from there.
Let's let John bring everybody up to speed about who did what to whom. And, um, you know, it seems to me, John, at least that, you know, the vice president was in Europe and forgot his copy, how to make friends and influence people. So Yeah, he played, he played right into his role.
Um, he, he, he spoke, I mean, his message was completely at odds with what every, everyone else was thinking there. But yeah, my head was on a swivel like the rest of you yesterday from the news cycle. I mean, what Alan said it very well, what we have here is this AI land grab on a worldwide stage.
Torpedoes be damned. I mean, just go full speed ahead. There, literally, almost simultaneously, you had actions going on in three different continents.
First, as you mentioning, JD Vance was at this AI summit in Paris, and he talked about America first in terms of ai. He claimed our, our continued dominance, and he's pressed the European nations to back off. He called it excessive regulation that could kill a transformative industry, just as it's taking off.
As soon as he finished saying that, before we even finish saying that, we already had news that the French president, Macron had p placed $112 billion of private investment in the coming years to accelerate AI developments late Tuesday. This is really, it's hard to keep track of this. The EU announced an invest AI about basically a $210 billion initiative that includes a new European fund of about 21 billion for AI gigafactories.
And then not to be left out. Apple, which has kind of been lost in all the shuffle with the machinations going on, is finalizing plans for an AI push in China via a partnership with Alibaba. This is what, uh, apple did.
They went through several different companies. They talked Badu, deep seek by dance, Tencent before, uh, settling on Alibaba. And they're doing this because the iPhone sales in China are suffering because they lack AI features that their competitors have.
So there's this whole machination of, of people jumping into this, this area, kind of independent of one another. You know, the one thing that I do want to mention also about Macron is he compared their project to Stargate, which kind of, in a sense was one of the things that was, was flaunting this, this, this alleged $500 billion project between Oracle, OpenAI, SoftBank, and the government, uh, to build on our, uh, infrastructure. And then we'll see how that pans out.
But it's, it's, it's, it's crazy. I mean, is literally, we have various world leaders all grabbing for this, this, this industry. And it's gonna, it's not gonna, it's not gonna end.
It's just gonna continue to accelerate. I, I absolutely agree, John, and you definitely summarized that very well, minus the Elon and, uh, open it, open it battle. But I would say it's not a surprise that Europe wants strict rules.
That's nothing new, that's nothing new. And China pushes state backed ai also nothing new. What I did not expect was the US to not sign a global AI responsibility pledge that China did.
That kind of threw me, I mean, I knew the speech was gonna be what it was, but oh my God. So concerns about AI's, dangers, warfare, those all were raised, but we sort of just glossed over it because, you know, we're powering it out. We're America.
Yeah, like, it, it just was okay, I guess this is how it's gonna be now. I was shocking. I thought it was interesting that the vice president told them they have a choice between either partnering with America or totalitarian organization country that's making AI models.
And I'm pretty sure the Europeans are trying to figure out exactly who he is talking about. So, I, I don't disagree with you. It, it is a, it's a sad day, a sad frigging day to have an American Vice president in France, nonetheless, at a country where our soldiers gave their lives to defend, not once, twice.
And we made the world what it is and what it's been over the last century, not by going it alone, but by recognizing who your friends and, and natural allies are. What world. And it's not one shot.
China, China made a pledge that we refuse to like about responsibility like that. It is clear in this, in imperial presidency, right? This is, this is akin to making a play for the Suitland, right?
In 1932, they have Czechoslovakia and he called it the Suitland, and they took that into part of Germany. We're doing it in Greenland. You Know, it's also, it's also the, this, instead of America first, it should be America alone, Not just each.
It's not America first, it's America. And America alone in today's world will never succeed at that. We can't, you are throwing out Canada our best.
Figure out France for a second. Our best ally, the only trading partner that we actually have, are surplus with. And you're throwing them under the bus too.
Do you think they're gonna wanna do business with us? This is not make friends and influence people. This is, this is, I, this is a, a page out of the Nazi party.
I'm, I'm sorry, this is a suit and land kind of thing. Chris, I see your head, your hands up. Yeah.
You know, since we in fact do not have anyone on, you know, to argue to the side, because frankly, I agree with you all. However, you know, let, let, let's acknowledge it and talk to it. Right?
You know, this is the way we hack systems. You know, we look at the way they are, whatever, right or wrong, and figuring out how they're working. So, you know, I'm absolutely not shocked.
I mean, that is exactly what we expect of this particular administration. Both, you know, for two reasons. None of the first everybody's sort of acknowledging is just to tick all you off, you know, the, the, the chaos and the, and, you know, keeping the heat, the world wrestling, uh, you know, heat, good, bad.
I love you, I hate you, whatever. You always play to that. So that's a big part of it, and which is a dumb idea.
Um, but the, you know, the argument that yeah, sometimes you, you need to rush ahead, right? You know, and I do this literally every day with boats and business and everything else. You know, sometimes it's time to say, you know what, we just need to go take that, do that land grab thing.
Um, how you can tell, Let, let me, Chris, let me stop you a second. There's a big difference between you taking a risk with your boat or in your business versus betting the future of the human race on, on AI safeguards. Well, let me, let me, you know, You're talking about a call, I'm making your point.
Absolutely. Right? But I, I do in my own small way, you know, having input on those things.
But, you know, my, my point is, the way, you know, whether that's a good time, whether it's a good time to take the risk to go forward, is understanding the, the strategic landscape. I do not believe that this is a good time to do this. You know, the risks of AI are what they are, right?
We know them. And in the, you know, we're talking about the Bruce Bruce Schneider article, uh, um, yesterday, you know, talking about the risks this administration is taking with the critical infrastructure information that all of us for decades and been working on protecting, you know, as being, as being, being savage, being handled very, very poorly. You know, no, no positives anybody can say about that.
And we're also taking these risks. So we're compiling risks. So is this individual, you know, high risk bet to go it alone on AI with no regulations?
You know, the wrong one. Even if it's not, we're doing so many other things wrong at the same time. You know, we're compounding risks and we're setting ourselves up for consequences that become unpredictable and hard to control.
That's the problem. You know, I, I think we make our ourselves look weak to quote one of the great artists of our time, Jay-Z, the strong move, quiet the weak start riots. We just made ourselves look like fools.
I mean, we really, did I undermine Yes. The, the, the geopolitical Yes. That I, you know, dunno where to start, right?
So, Yeah, I feel like we got, is it any, Is it any surprise that what what Vance said though? I mean, literally, he said it days after, uh, Trump issued one of his hundreds of executive orders where he overturned a Biden executive order about AI safety and responsible use. I mean, it was, it was telegraphed.
He and he and JD Vance kind of enjoys the black hat. I mean, that's what he does. Plus I think that we, I think he's getting whispers or nice, nice encouragement from big tech in terms of pushing back on regulation in Europe, which has always been a problem for these, for these companies, especially Apple.
So Let's not make Apple the only bad guy here. No, I'm, I'm saying I'm, I say big Tech. I, old big tech pushes back on there.
I including Google, including and Twitter, where, you know, but, you know, Chris made a reference to a thing about Bruce Schneider. Actually, it was Bruce Schneider and Davy Meyer, who, I don't know if you know Davey Chris, but Davy's brilliant. And he is a real dude, right?
Penguin blog. I, he's been in the security bloggers now 20 years. I know Davey.
Now what they said is, what's going on with Doug is creating unbelievable cyber risks that our adversaries are going to exploit, for sure Are exploiting now And probably already All. So, yes. But, but really it's the symptom of the same disease.
They don't give a s**t about risk. They don't care about risk. They've made it very clear.
We don't want Europe regulating risk be damned. We're gonna beat the Chinese. We are the new American imperium.
We're gonna win the eugenics war instead of Kahan, we have Musk. Okay, well, This striving on chaos, Quite not on chaos. I seen this, this is a return to imperial times.
We want an American outpost in Gaza. We want the canal right near that Gulf of America. We want the red, white, and blue land.
This moron and Congress introduced the thing, and we're gonna win the next new world ai. So, so John, John, you're in the valley. How are those companies gonna spin this storyline?
Because essentially to Alan's point, they're all saying, we're against responsible usage of AI because of we're worried about regulations. So therefore leave us alone. That's an untenable position to be in long term.
So how isnt an Nvidia and Apple and Google and all these other people are gonna come around on a storyline? It doesn't make them look like they are completely off the charts. I don't, I don't think they can spin it in any way, shape or form.
I, I, I, I say I sense here, even in their backyard. I mean, the employees of these companies are upset about what's happening with their companies, uh, the, uh, the people who are not in tech. And that's a vast, vast majority of the people in this area look upon tech, uh, at the villain, the evil empire.
They're in cahoots. They're part of the oligarchy. Um, they Are the Oligarchs.
They're the amount of coverage, the amount of coverage here, uh, that's negative about tech is palpable. And I think it's well deserved. And I, these, these guys have gone through this, these guys play every side.
They, they're, they're, they're almost soulless. You know, when, when Obama was in power, they all cozied up to him. They all sat around him and bowed to him with Obi, with Biden, not so much with Trump.
You just see them shifting with the winds. I mean, this, I, I can't get outta my head. The, uh, the, the inauguration in, and these guys blanked on the stage over his shoulder, all on one side, all on the Republican side, laughing, nodding, trying to look serious or solemn.
I mean, to me it was just, that's a picture that they will never erase. We'll go into history Book. No, sir.
And let me tell you the hypocrisy of this. You mentioned the, the musk Mike, you mentioned the Musk group. Buildingd 97 whatever, billion dollars for open ai.
What they're not bidding for chat. GPT, they're bidding for the open for the not-for-profit open ai. Because the group says going for profits is now not good under the America first thing.
It goes against their charter. They wanna return open AI to its good, uh, original founding, which was to do good for people and make AI safe for everyone. They talk out of this mouth here.
And then JD Dance talks here. That's called bull. This is out of Orwell.
This is f*****g out of Orwell truth. Speak face. Call it what it is.
Stop being, I'm not gonna be complacent and watch this go down. This is Orwell. You know, Musk truth speak.
People Wanted open AI to go be move for profits. He was one of the people who was behind that idea until they, they decided they didn't want him to run the company. And he left.
Of Course. So he has, it's another case of hypocritical nonsense. Hypocritical nonsense.
Anybody wanna say anything else? I'm not done. I mean, you're assu, you're assuming to be a hypocrite.
You, you would have to think about your implications of things. There's an empathy required there that's not existent. Not, I mean, we're just, we're just playing it as we go.
No, I, I Soni. So I don't think they're dumb chaos. I don't think they're dumb.
They're very smart. Elon Musk knows exactly what he's doing, and he says whatever he needs to say to get it done. So does Trump.
And so that's that whole script. Well, Assuming as assuming you're accompany and you're building an AI app and you're now comfortable with the, the lack of governance, what should organizations really be doing about all this to kind of be responsible and kind of, you know, if they're inclined to do the right thing, then what should, what is the right thing? You know, the right thing.
First of all, the right thing should be apparent if you really are inclined to do the right thing. The right thing is respect people's ip, respect people's information, respect what the repercussions of your acts are. The right thing is never changed.
The right, you know what I mean? The true north is true north, Right? For me, it's dis disclosures.
I, I have it in my contracts as of this year. If I use AI tools, I will disclose that I've used them because I'm not gonna pass off human time and labor out of retainers. Uh, that, that's not, that's The right thing.
That, that was what I felt was a way to signal to clients on bringing in these tools. But I'm also gonna tell you, because no one likes feeling tricked. No one likes feeling their job.
Absolutely. So that was an easy way for me to just let them know, Hey, we're gonna use these tools, but we're gonna tell you and every single client excited about it because they feel like they're a part of it. Because they are Guys.
We're talking about an administration that just suspended prosecution of a law prohibiting bribing foreign officials. Okay? You want to talk about the right thing, about morals, about the 10 commandments, about religious Christianity, or whatever your religion is.
I don't know of a, of a religion other than the Regi maybe that allow for the bribing of officials. What do we, are you proud to stand up today and say, count me in with them? 'cause it's, I'm, I'm actively renewing, I'm renewing my Canadian passport, so, sure, Go Chris.
Yeah, I'm gonna shut I, you know, rather, and again, rather than just ditto heading, you know, because I, you know, I, I agree with what everybody's saying. You know, in any adversarial situation, you need to understand the lay of the land, right? And right now, you know, we, you know, everybody arguing from our side is, is losing, are losing, right?
Why? Well, because we're getting suckered into fighting the wrong battles and spending our energy ineffectively and not actually, you know, the results are obvious. That's just pragmatically fundamentally true globally.
This is not just a US problem. And really, when you break it all down, you can look at as policy hacking, right? And, and what's going on right now in the US administration is a perfect example, right?
And the actors, Trump himself, has made a lifetime out of policy hacking, where you just break all the laws all the time and you know how the laws and the policy works. And it's not just what's written down. Do this, don't do that.
It's knowing that if you do this, you know, nine times outta 10, you get away from it, get away with it the 10th time, you can delay it. You can delay it so long, that situation will change. So you never have to deal with it.
Someone didn't, you know, got convicted and didn't go, you know, suffer penalties in the last couple months. Exactly like that. Amazing timing for that one.
So this is all a combination of standard conflict, right? Oligarchs sucking up to whoever's in power. Terry Pratchett, you know, writes that into story all the time.
This is happening forever, right? We had policies and systems to prevent that, or limit that they've been eroded 40 years. We Need our Court To put a break on this.
Look, the mayor of New York was indicted. The mayor of New York was indicted, and this administration ordered the Justice Department to stop the prosecution. 'cause we need him to enforce the administration's immigration laws in New York.
If that's not corruption with the biggest capital C I've ever heard, what is it? What is, have we announced? Are we no longer a country of laws?
'cause if we're not a country of laws, what are we? I was scratching my head about that one. 'cause I was just trying to figure out what the other hundreds of thousands of people who work for the city of New York are doing, I guess.
'cause they can't do anything without the mayor. Come on. This is guys, I feel like I woke up and back to the future three.
And Biff is in charge. Okay? That's what we're dealing with here.
That's what we're, it's Biff world. And, and this is why I say you can't be complacent. Shake your head and say, we gotta hack this.
You've gotta be an activist. And if that means going to file lawsuits, if that means campaigning against it, you, there's gonna come a point in history where they're going to ask what side were you on? What side of the divide were you on?
When Moses comes down with the tablets, what side were you on? Do you wanna be, I was quiet. I don't, I won't, To be really clear, I'm not talking complacency.
I'm talking effectiveness. You know, when you fight, stay as calm as the ocean and watch what's going on behind your shoulder. Right?
Remember, war is not the place for deep emotion, and you might get to be a little older, right? This is important stuff. We need to spend our time winning these wars.
And I, and again, I'm speaking globally, this problem is we have global policies that have eroded and they're being exploited and they're being hacked. Yes. You know, laws, we have a president right now who will break the law, you know, every five minutes knowing that the consequence, even though the policies and the processes there won't actually get back to him.
So we need to fix those processes. And, and again, I think in these information technology world, in the cybersecurity world, there are hints of the kind of systems that may help us do that. But this is still, you know, this is conflict.
Individuals need to work. I would Just, I would just say that, you know, your wallet needs to follow your principles. And all too often we see people standing on soapboxes saying stuff, and then they don't actually follow that up by looking at who they're doing business with and what contracts and who's supporting what these things now need.
A, a, a different weight means to be added to the calculus of who you're doing business with. Agreed. All right.
We've exceeded, we've exceeded our 15 minutes on this one, guys. Um, we're gonna have to take a break here on Textron Gang. We're gonna come back and let's talk a little bit about security.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
All right, folks, we're back. And we're talking about AI and security, as Alan alluded to, and it's a continuing conversation. We talked about this whole deep CKI thing ad nauseum at this point, but it seems like there are other providers out there like Anthropic who are offering, uh, yeah.
Money for people who can crack their AI safety and cybersecurity capabilities. And I can't help but wonder, Chris, have we shifted a gear here without really noticing it too hard, but is security now becoming like a preeminent feature of these AI models and people are gonna start making choices based on security before the fact rather than trying to fix it after the fact? Yeah.
In short, yes. Right. You know, this is, as we're talking about in the last block, you know, sometimes it is the right time to just rush ahead and see what happens to something I just not right.
And for lots of reasons, not just, you know, the, the current trend of ai, um, security has been building itself into the requirement list of things for a long time. You know, this one, and again, you know, as you know, it holds up like the last block. This one's scary enough that people, to your point, I think consumers are taking it more seriously than usual.
And to the point, a couple of the articles, you know, in today's, uh, uh, reference material is starting to become an evolutionary thing. The nutrient gradient goes towards systems that aren't gonna freak out your customers, right? And this is the literal, you know, Mary Shelley Frankenstein story that we've all lived in Breeze, Skynet.
And, you know, how do I get comfortable with spending X amount of dollars when I know I have, I have choices and one freaks me out more than the other one, right? Because they're going to go, they're gonna get challenges that gonna go through tests, they're gonna fail it, they're gonna fail horribly. You don't, if I was, if that was my main purpose, the, you know, the main hat I'm wearing commercially these days, I don't want to be that brand, right?
So I think security, I have some hopes, again, you know, that's, you know, my normal optimistic view of things. But I think the drivers are there a little better for this than a lot of things. So, you know, I said this before, I'll say it again.
Vendors build security in when their customer's demanding and not a second before. And the better you Beforehand just go outta business, Right? Not a second before, right?
And now the issue here is what customers are demanding. It used to be that in some way the government was a big stick, right? 'cause when the government demanded safe cloud, they did GovCloud.
When the government got worried about financial data, there was Graham Leach Bliley. When the government, right, or the EU government, GDPR and AI regulations, JD Vance be damped, they consider it their job to be that big stick in terms of cybersecurity regulations. Um, now we can't count on government necessarily to be that big stick.
So who becomes the big stick? Is it the PCI council, right, which was behind the whole PCI standards, which drove so much security 10 years ago. Or is it the cyber insurance companies who won't give you insurance if you're not, you know, using secure tools.
Someone has to come in here right as the big stick to help the individual consumer because it's in today's world to get individual consumers, or even like the huge, was it six or 7 million SMB businesses in the world? To go like a school of fish or a flock of birds in one direction is difficult. You, you need, you need the sheep dogs, if you will, to, to herd them.
And I think that's, we have to see who emerges. I think the EU will be one of them. We'll, we'll see what else pops up?
You know, I did an interview with my friend some Quas Dip di uh, Dipo, I forgot his last name. Bai, Dilip Bai, uh, SVP of, uh, Qualis. They did the scan on, on deep seek that turned up all kinds of security issues, all kinds of security issues.
Um, I'm glad to see philanthropic taking the lead with this jailbreak challenge, right? Because they obviously something you know, well, that, That Something's telling them that plays really well. People care.
Yeah. Sorry, sorry Alan. No go.
This plays really well into what philanthropic has done. And, and basically it's kind of this depth move amid of this chaos need for speed, bigger and better models, anthropic decides, you know, this is what we stand for. This, this is why we are not like open a IR dse and I, I I give them, I give them kudos and at least bringing this topic up because deep in the recesses of my mind, I keep thinking that we are hurdling eventually towards some major breach that involves ai.
And it's, it's gonna happen. And it's gonna be interesting to see how all the parties involved to rush things, how they're gonna handle that, or how they're gonna pivot from it to use par lines out here. I mean, you hope it works out well for, I'd like to get your opinion on this thing.
I saw, I was talking to this other company and I happened to gonna look at some of the contracts they created, and they actually had language in there that says, thou shalt not take our data and expose it to any LLM. And it was interesting that they were using a legal case now, basically to say, we do not give you permission to use our data even so much as to write some sort of marketing collateral type of thing, because we don't know where that data's gonna wind up. And you must sign this, and if you violate it, we will sue you into oblivion.
So is it illegal Argument? It's in, it's a, it's legal argument until someone signs an executive order that says those are no longer enforceable. And then you gotta get a court who's gonna come up and have the, the cone to say, yes, it is.
You know, I get it. We're, we're having a dark moment. But the fact that we're all able to freely discuss this without fear of repercussion penalty or getting dragged to jail, like getting our tissue typed, uh, like China does, uh, we're free, we're free to discuss it.
And I think if we continue the discourse that, that all of us will eventually come to light. We have a free press, we have a lot of things that we shouldn't forget that we have, that we have going in our favor, there's nothing that's gonna take that away from us. Um, I, I, I just can't, I can't believe that I, I don't believe that they will win in that.
But, but to your point, I do get asked. So I did a segment on a BBC Sacramento yesterday about deep seek, and I was asked, um, is it okay to use deep seek? Is it safe?
And I said, well, I would just assume like I would in a search engine that anything you you type in there is is it's gonna be revealed if, if it's gonna be revealed. The fact that there have been so many governmental agencies banning deep seek, uh, for security vulnerabilities tells you that right there, I mean, if this is a preemptive thing, but I do think we're gonna start seeing LLMs called out in more contracts. I think we're gonna start seeing that because people have to protect their information.
And it's been a wild west situation, but I think it's gonna be dealt with on a private level. I, I can't see any legislation coming out of this administration, uh, protecting anyone's data. Well, I, I, I, I agree and I think the, you know, contract language, you know, I'm always trying to look at things that just have to be done.
And, you know, the supply chain world that I've been focusing on for, for in recent years, that absolutely requires at certain points in the, in the predictable future, certain things to happen and contract language becoming code, you know, actual code that operates in real time, like software has to be part of that. I have to know that I don't call my legal people or send an email to have a human read, a contract to find if there's a clause that disallowed my data to be exposed to an LLMI need as my data is being handled, the, the policies is being handled in to be transparent to the systems. And in certain hypercritical, you know, high value infrastructures, I expect that to be technically implemented in the next several years.
We're not talking a long time. The parts are all there at this point, like any NT area, it just requires an area where the cost is worth doing it. But then again, the savings in all the other things don't have rewards.
The rewards have to justify the cost, right? Is the bottom line. Wait, And they will, We already have compliances code, so tractors code is not far off.
So I think Chris is spun off. Hey, we gotta take a break. We're gonna come back.
We've got one more segment for you today. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. And finally, in the C Block, we're returning to some of our favorite DevOps conversations, or in this case DevSecOps, but, uh, harness merged.
We're Traceable. Traceable is a provider of an API security platform that happened to be created by the same team that runs Harness. So they all came out on the same labs, but there's been this ongoing debate about whether or not API security is a standalone category.
Is it just part of a larger DevSecOps platform, or it's just another artifact just about everybody who made an API security platform came out with a statement in the last three days saying API security is still a standalone thing. Alan, I know you've been kind of following this as long as I have. What's your quick Take?
Sure. So, so just real quickly, as you mentioned this, this is a merger of Kiss and Cousins, right? Uh, Jody was the founder of both Harness and, uh, traceable.
He was the founder of AppDynamics and his, I forget the name of the labs as his funding accelerator unimaginable on something, um, was the initial money into both companies. Of course, harness is a unicorn valued company, CICD. Um, we've covered traceable and Harness since the day they were both launched here at Tech Shock.
I'm good friends with Jody over the years. AppDynamics was one of our initial founding sponsors. Um, you know, I learned a lesson years ago, my friend Chris Hoff, and you probably know Hoff, Chris Blas, right?
Hoff is the chief security guy now at, uh, LastPass. But Chris has been around the security world a long time. He used to get me going.
He'd say NAC was a feature, not a product. And I used to argue because I had a NAC company and I didn't want that. But long term, he's right.
But that's the fate of almost every kind of tech product. It become, it goes from being a product to a feature into a platform. You know, it gets melded onto a platform.
And, and so that is the story of API security. It, it had its moment in the sun. You saw several players.
No name security was a unicorn, right? They raised a ton of money. They wanted the big ones.
Um, salt our friend Michelle McLean worked at, there was one before that, that Red Hat bought for about 400 and something million back then. Um, traceable was another, you know, my friend Brad Feld said, if you're not in the top three, get the hell out. Because those top three, those first three companies to exit get the bulk of the money.
And that's exactly what happened here. The top three companies got out, they got the bulk of the money. I don't think no name got anything near what it was valued, you know, prior to, I think with Traceable.
And, and again, I have friends at Traceable in, in addition to ti, but they've suffered from this lack of AI, API security being a thing. And, and they haven't been, you know, running at full speed for some time now. And I think the right thing to do is to fold it into Harness.
And they did. I think Harness like every other DevOps platform wants to be a dev is a DevSecOps platform. And API security is a good part, is a, is a nice add in, a nice tuck in to that DevSecOps functionality.
I, I don't see many standalone api. I, you know, originally this API security was gonna be a waf, probably a WAF replacement web access firewall, web application firewall, because WAF firewalls didn't monitor API traffic, which is a majority of the traffic on the internet. But now API security is either part of a security company or part of a security play, or, or it's part of your app, its AppSec, right?
Or, or API management in general. So, so my prediction is we're gonna see either more acquisitions of DevSecOps companies acquiring API security companies, or at the very least, Who's left Renouncing Alliances with various players. There's still like half a dozen little startups in this space Around.
I mean, the big ones, the big one. Look, if you're not in the top three, get the hell out, Said Jack Welch at GE Long, long time ago, and he was right then, and it's right now, then, you know, of course, Jack, just about that statement after he retired. So who knows?
Yeah. I mean, I, I've seen that in tech over the years though, having been involved in a few venture backed startups. If you're not in the top three and you can't make a sizable, you know, a reasonable claim that you're gonna be in the top three in a short time, get out, pivot, sell, do something else.
Well, I I I, I have to say on topic, you know, uh, shout out to Roy per at, uh, CEO of unified API, who's a guest on one of the inevitably curved episodes that's, uh, will go online in the next, uh, couple weeks on this topic. Interesting person to, uh, to listen to on it. But effectively, what more is there to say yes, right?
And, you know, supply chain and so forth is mentioned again in the, in the background material for this segment. You know, this is, you know, DevSecOps, you know, working at Sibe in a s om management company, you know, these last, uh, several years, it's DevSecOps. It's fascinating how that's folding into other parts of the, of companies better than it has because of the shared visibility of these things we're all talking about.
So, yeah, it's, it's time, right? You didn't notice that you weren't paying attention. So yeah, now it's time.
I gotta leave you with this. You always have to remember they're cattle not pets. And you know what the fate of cattle are sooner or later, sooner later, they're all hamburgers.
Yep. Is that it? That's, that's the le that's the lesson of that story.
All right. Hey, it's been a rollicking, uh, Textron gang today. And, and Chris, John, Mike, thank you very much.
Um, just a heads up, I'll be on a two 30 this afternoon on LinkedIn live on my Shimmy Says, and I'm gonna have more to say about this America only, America alone AI strategy. It's actually America alone against the world strategy. And, and how, you know, where this can go wrong.
Tune in on that. You'll also be able to see YouTube shorts not live, but it'll be on YouTube shorts and other places as well as is Textron Gang. We've got a lot of Textron TV coming up for you the rest of the day.
Until then, this is Alan Shimmel for Textron Gang. Be safe. Be well, speak up, you wear out.
This is Textron tv. Hey everyone, welcome back to Textron tv. You know, I, I always enjoy talking to my next guest here.
He is the CTO in EVP for the cloud platform over at Qualys. It's my friend Dilip Bani. Dilip a pleasure to have you.
Usually we're in person at the QSD or at RSA or somewhere where we're in person, but today we're on Zoom, but it's still good to have you on. How are you? I'm Good.
Good to be here, Alan. Uh, it's always a pressure. Yes, it's, it is, it's, it's fantastic.
You know, I mentioned it, well, we should hit it right off the bat. So, QSC Qua QS, Wallace Security Conference, QSC, um, is coming up this year, I think in October. October 16th, around there.
And I, I heard a rumor it's gonna be in Houston, which is a great city. That is correct, yes. Uh, it, it's a new location for us, um, this year.
We are in Houston in October. And of course, looking forward to being there, looking forward to meeting our customers, sharing with them everything that we have been working on, especially everything that we are doing around enterprise to risk management, the risk operations center, and how that has evolved since we last talked about it. Uh, during the 2024 qse, You had to think for the year, right?
Yes. And by the way, if you go to text, drug tv, all of our interviews from there, and there was a lot on the risk Operation Center, the Rock are, are available if you go to industry conferences, look under Quas, and you'll find they all of, including my interview with Dilip, is there. So check that out.
But Dilip, we're gonna talk about something else today. So, last week was a bit of like a Sputnik moment, if you will, right? All of a sudden the, the Western AI establishment was rocked by news out of China that these folks, you know, it's a, a handful of PhD engineers basically put out a, an AI model that rivaled the best of what we have here at a fraction of the cost and a fraction of the time.
And open sourced it on top of everything else so everybody could go, you know, look under the covers to an extent. Um, and it was big news. Qualys turned your, uh, your, your scanning engine onto it and, and came up with some very interesting results.
I don't want to say too much 'cause it's your story. Lay it out for us, Philip, what happened here. So, and Alan, I mean, spot on, right?
Uh, deep seek, uh, this is a, you know, fairly young AI company, uh, out of China, certainly very talented folks. They came out with a model. Uh, they've, they've in fact been coming out with information for the past few months, and, um, I don't think a lot of people necessarily noticed them until they came out with this latest model, uh, the R one and it's open source, but it, it performs really well.
Uh, and you're right, uh, you know, they are saying, uh, they have trained it at a fraction of the cost of what some of the larger tech companies here, OpenAI, meta, uh, Gemini, and others are, have done to train their models. Uh, so I mean, first and foremost, I think what they have done is something amazing. Uh, in, in some ways they, they are proving that if you want to build very large scale foundation models, you don't have to be in an extremely large organization with unlimited amounts of money.
Uh, you can be a smaller shop and you can do this. Uh, so that's the good thing, right? Um, it, it certainly got a lot of hype, it got a lot of coverage.
Uh, what we wanted to do was, as we were looking at it, because we were curious too, we use a lot of open source models internally for our, uh, quas cloud platform. So we wanted to look at deep seek and just understand, you know, how it was behaving, what it was doing. Uh, now I think you probably know we launched Qualys Total ai, which is our AI security solution some months back, uh, it, uh, in August.
And what the solution does is it gives you a more comprehensive view of your AI posture, meaning you will get full visibility into your AI hardware and software assets, uh, your entire AI inventory, where your models are deployed, where your LLMs are running, and then also a pretty detailed vulnerability posture across your AI footprint. In fact, we have more than 1500 detections right now, just from a vulnerability standpoint for your AI footprint. So we said, well, let's take this, let's take what we have and let's see how deep Seeq performs on that, uh, from an LLM scanner standpoint.
So the way our LLM scanner works is we do an outside Incan, and we have built a pretty exhaustive knowledge base of questions that we will ask an LLM, um, back and forth, um, which we call our knowledge base, and we gather that information. Then we have some inbuilt models, which we use to then judge the quality of the responses that is coming from these target LLMs that we are testing. So we did that and deep seek, um, to our surprise, uh, it didn't do particularly well.
Uh, in fact, it, um, it failed 61% of knowledge base tests that we had, and in total we ran about 900 tests, um, just for our knowledge based checks, right? And what these checks do is they test for, um, ethical questions, legal questions, operational questions, uh, and we do a lot of back and forth with the model to kind of get a sense of how is the model responding to our questions? Because these things are important, right?
You take a model and you deploy it, whether in a B2B setting or in a B2C setting, and you expect the model to work in your particular domain and not give answers that it's not meant to give. And when it does, then there is a liability issue here, right? And, you know, that's what we are trying to get a sense of.
So we did that. Then in addition to the knowledge based tests, we also do jailbreak tests, um, where jailbreaking basically involves techniques, you know, that you can use to bypass inbuilt safety mechanisms that are built into the model. Uh, there's a lot of well-defined techniques.
Uh, we, so obviously we work with the community, the open source community, and in, in our solution right now, we have about 18 to 20 different jailbreaking techniques that we use, and we ask the model questions around these techniques. The idea being that you're somehow trying to coax the model to give you information that it's not, it should not be giving you harmful outputs, uh, misinformation, you know, privacy data, unethical data, all sorts of things. And I think just based on the fact that it didn't do so well on the knowledge based tests, um, I mean, not surprising, but it failed more than 50% of the jailbreak tests too failed almost 58%, almost exactly 58% of everything that we did and of analysis was pretty comprehensive.
Um, you know, trying to get a sense of what was going on here. Uh, so really the, the gist of this is, yes, it's a, I think it's a great model from a foundation model standpoint, uh, in how they have trained the model, the underlying architecture, um, and just being able to demonstrate that you can build a model with significantly lower investment. Um, but that corresponding investment hasn't really happened on other areas yet.
Right? And then of course, concerns with, if you're using a hosted model that is sitting in China and you have GDPR concerns or other, you know, regulatory requirements, right? Not concerns, but GDPR requirements, right?
And other regulatory requirements across different countries. Something to be mindful of, right? Um, Yeah, but well, that's the whole sovereignty issue, right?
Yes. So Dilip, I'm not gonna make excuses for them, but let me postulate two, two things on what you said. Number one is some of the, uh, not the jailbreak questions, but the sort of foundational questions, could it be due to the fact that clearly, because it is from China, it it is, I don't want to say censoring, but it's purposely not reporting on some sensitive areas that the Chinese Communist Party may beam, uh, sensitive that they don't want it to report on.
And so it's been, in essence, blinded for those things. And I mean, 61% is still a pretty high number. I'm sure it wasn't, you know, 61% of things that have been censored there, but could that be at least partially, uh, responsible for that?
Yeah. So Alan, there are two parts here. One is, I mean, obviously just based on the fact that the, you know, the model came out of China and the sensitivity of the Chinese government, there are some questions that you can't ask the model.
So it's really quite censoring some things. Um, and some of those are well documented, uh, right? Um, that what this then means is that if they do want to stop, so the model from giving incorrect information or unethical information, however you look at it, they are, you can stop the model from doing that.
You cannot be perfect, but you can restrict it as best as you can. But those controls haven't been applied to other areas. As an example, we asked the model a lot of, when we were asking jailbreak questions, um, you know, we asked a lot of typical questions on, you know, how could I make an explosive, uh, how could I come up with, um, you know, incorrect healthcare information?
And it didn't need a lot of prompting, a lot of circumventing to get that information out. It was just giving us that information very quickly. Uh, and I, I think what this points to is they have put in certain guardrails for things that, for deep seek, you know, just being where they are, you know, they had to do that, That are important to them in their right, right?
But maybe not for, But not for, for a larger, and, you know, that has to be done. Now, either they do that or other organizations can pull these open source models and have RAs sitting in front of these foundation models to say, when you're asking a question, I'm going to make sure I'm filtering the right things out and only asking the model what makes sense, right? Because the model inherently is not trained yet to do that.
Yeah. I mean, and that's one of the beauties of it being open source, right? You could self-host it and put whatever guardrails you want in front of it and it self-hosted, and that takes it out of China and everything else.
But Dilip, let me, a lesson I learned in my 25 plus years in security, 30 plus years in technology, is security becomes important when customers demand, it's important. And I think clearly Deep Sea here wanted to get this out. I I don't think it was any coincidence that this was released.
This R one came out two or three days after the, uh, Stargate project or whatever, the $500 billion project to go build data centers was announced, right? This, this, this PR here and global nation state strategic, you know, competitiveness at play. I don't know if they had the time to maybe put in the, just, just like, until a customer demands better security, you don't have better security until someone says, you've gotta put these guardrails in here, especially when they're rushing to get it out.
They, they don't put them in there. I, I would hope that that's just more of a sign of its immaturity than a total lack of, of ability to do that kind of thing. Yes.
Um, and, and Alan, I think I agree with you there. Um, this is a fairly young company and, um, I mean they, you know, they've been working on building, you know, some, I mean, in my view, some exceptional models. Uh, and to your point, uh, you know, this is still to some degree, you know, research oriented, right?
Um, but when you look at the overall AI ecosystem, there are different layers that you're looking at, right? Uh, you are, you have one layer, which is your hardware and infrastructure layer where the folks like Nvidia are playing, right? The second layer is your foundation models, right?
Which are now to some degree, it feels like they're starting to become more commoditized. Uh, you know, some are closed source, like open ai, but if the likes of Deep Sea are making models open source that others can then pick up and iterate on, right? Um, that would help.
And then the third layer, the one that you are talking about customers asking is that app layer, that how do you take these models and how do you, you know, bring value out of those models to cater to a need? And as that, and as that app layer is gaining maturity, the security requirements will increase, right? I mean, what is my model doing and why is it doing what it is doing?
What kind of guarders and checks and balances do I have? And I think that will come for sure. Um, and I think that'll come for all models.
Neil, I I gotta ask you another question. Look, this is, we've been talking about this deep seek since the announcement every day on Textron Gang and in a lot of our articles and videos, uh, there, there's one, I don't wanna call it a rumor, but, uh, you know, some people are saying, I hate to say that 'cause politicians say that. Some people say, but there is a story out there that the reason they were able to train, deep seek, or this, this particular model so much faster and cheaper, is because they didn't kind of start from scratch.
They, they, they were able to for however they got their hands on it, uh, open ai, uh, model, and then they kind of trained it off of that, if you will, or, you know what I mean? And, and, and so that's what allowed them to do this faster and cheaper and on less powerful Nvidia and so forth. Is there anything in your testing that would give credence to that, prove it, disprove it or that's not something you looked at, you Could, that's, yeah.
That's not something we looked at. Um, because we were doing an outside in evaluation of how the model is performing against checks. You know, whether that happened or not, I mean, will, I mean, you know, remains to be seen.
Um, but, uh, what I will say though is, um, from an architecture standpoint, from a model standpoint and the way they approached building the model and building the training, uh, and there is innovation here, which Oh, no doubt. Which I think no doubt, most Of the larger companies, everybody's going to benefit from that. It will optimize how they're using their GPUs.
Uh, certainly, You know why it's the deal. And it's funny that it, it comes from the Communist Party of China, but this is what the open market's all about. Yes.
Right? If someone builds a better mouse mousetrap, copy that mousetrap. Yeah.
As best as you can. Right. And, and learn from that and, and, and keep innovating.
Because, you know, the other thing I, I feel with this is yes, it didn't do so well on your test. No doubt about that. Right?
And 61 and 58% are pretty, I mean, those are hard to argue with. Uh, it will get better though. I'm sure it will get better.
I, and it, it, and that's again, part of this whole open source thing, right? It allows other people to innovate off of their work as well, which is, you know, is, is a great model. Um, I, I think the bigger, the bigger thing though is that we were just discussing it on Text Trunk Gang this morning.
There are so many different models out here right now, even within open ai, you know, when do you use oh 3 0 1 4 oh, most people don't really know. Well, it sta it versus another one. You know, how do you know what model to use?
When should I use Deep Sea R one versus, uh, Gemini or Llama or what have you? So, I, I think we're gonna develop in a world, it's kind of like cars. Some people drive a Maserati or a Ferrari, and it costs a lot of money.
Or a Bentley, other people drive a Buick or a Cadillac, or, and then other people drive Chevys. Mm-hmm. And that's okay, too.
They still get you from point A to point B, which is the, that's the mission. If this thing can get you from point A to point B and fulfill the mission at a fraction of the cost, market economics dictate that you'd be a fool not to use it. Yeah.
I, Go ahead. The, I, I think the entire ecosystem is still, it's still very early, right? China PD just came out, you know what?
0 and you know, everything new, you will not like it. We still look back fondly to the initial versions of Cha Chan, GBT thinking, oh, it was revolutionary. Yes, it was.
But now, after you've experienced something so much more better, right? Even from open AI and from others, you will think the initial versions didn't really have, you know, that level of knowledge, or they were not as good as what is today. Uh, and what will happen here is this innovation is happening at an extremely rapid pace.
It's not even in gaps of two years. It, it's happening, you know, within months, right? Weeks sometimes.
I mean, week to week, these things change. It seems. It's crazy.
I mean, these guys came out with their model, and then Alibaba came out with a model saying, Hey, we think we have something better. And, and that's a good thing, right? Because early on, it's The market.
Yeah. It's the market. You want this kind of innovation happening.
You, you want this kind of disruption happening, and then everybody benefits from that. So I, I agree with you. Let me ask you to put your Qualys hat on now, though, 'cause we only have a few minutes left.
Speaking now as C-T-O-E-V-P cloud platform at Qualys, how big a challenge are these AI models in, in making security better or trying to secure them? Right? There's two aspects.
One is harnessing AI to be a better security company. One is as a security company trying to secure against AI being used by bad guys, right? Yeah.
I, it's, it's a really good question, right? Um, I think using AI ML and AI in security has been happening for a long time now. We have, we had machine learning models embedded in our platform.
We had them for years. Uh, I think when LMS came out, large language models came out. Uh, it was a little bit more disruptive because it, in some way, it socialized using machine learning.
Earlier to do ml, you needed a data science team. You needed a team of experts that really understood how to train these models. Now, in some cases, you have folks, you know, that take an LLM model and just doing prompt injection.
They're able to, you know, build applications that can add a lot of value. So now from a security standpoint, of course, using AI ML to build security solutions, it's been there, I think LLMs will help accelerate that. We are already seeing that.
Uh, we've introduced a lot of new things in our platform just in the last two years over that, right? The bigger question now is, as especially large language models, which are more predicted, they're not deterministic. If you ask it a question, it will not give you the same answer every time, right?
It's just how the underlying architecture is. It's getting better, right? If you ask it a math question, it, I mean, it is giving you good answers now, right?
And especially some of these newer models are really good, but more from a business standpoint, when you are asking it a question, you are expecting it to answer within the context of your business domain. And so, guardrails become extremely important because you are saying your chat bot, let's say, is representing you as an organization. And if your chat chatbot gives an answer, then you are held to that answer.
You can't say, I had a chatbot on my website and it gave an answer. That answer was incorrect. So it's not my problem.
You can't say that, right? Uh, so that's where, you know, more checks, um, you know, building the right kinds of gates is becoming, becoming increasingly important. What we are seeing right now is people saying everything is in beta mode, right?
Uh, that, hey, we are releasing something, but it's in bera mode, which is fine. Um, I think the industry is maturing. Obviously, the models will mature, the security ecosystem will mature, right?
Just the way we introduced total ai, we looked at this as a gap, even when we were looking at it internally to say, okay, our teams are deploy models. We don't even know what's going on. We talked to a lot of CISOs, and they said, we have no visibility into what our teams are even putting in charge GPT or perplexity.
What kinds of questions they're asking, and what kind of information is going out, which could then be used to further pre-train those models on proprietary data, right? So you need all these checks, and I think the realization is there. And, you know, we, we obviously took a major step in saying, we are putting out a solution that will help you understand your AI ecosystem, understand your vulnerability posture, your security posture, and then of course, as you're deploying your large language models across your enterprise, you know, what is the security, the compliance, the ethical guidelines, uh, the jailbreak, uh, you know, capabilities, you know, how, how do you manage all that, right?
Uh, that's where we are at. Uh, we are obviously adding a lot more capabilities into our platform, into total ai, uh, quas, total ai, so our customers and just the larger, uh, community can benefit from it. Excellent.
Dilip, we're out of, we're over time, actually. But thank you so much for coming on. Keep up the great work, everything you spoke about.
com whether you want to go check out the blog articles on, on this particular testing and, and story, or you want to find out more about total AI or about Rock, or anything else. com is, is your starting place for that. Dilip, I hope maybe we'll see you in San Francisco during RSA week, if not a QSC, or, you're always welcome to come on here and chat with me.
It's a pleasure, as always. Likewise. Thank you, Alan.
Uh, good Conversation. All righty. Dilip Bai, C-T-O-E-V-P Cloud platform at Qualys here on Techstrong tv.
We're gonna take a break. We've got a lot more coming at you today. Stay tuned.
We'll be right back. Hello and welcome to the latest edition of the Text Storm AI video series. I'm your host, Mike bza.
Today, we're with Anand s Gupta, who's CTO for Aviatrix. And we're talking about the overlooked implications of networking and security challenges that will occur as we all deploy thousands, hundreds of thousands, maybe even millions of AI agents one of these days. Hey, Mann, welcome to the show.
Thank You. You, thank you for having me. So describe for us what it is that is at the core issue here when it comes to networking and security.
Because all these AI agents, as far as I can tell, they're just really gonna be additional endpoints on the network, and they're all gonna start generating traffic. And well, what could go wrong? Well, um, uh, that's a great way to put it.
What can go wrong? Uh, so, uh, before I, uh, point out what can go wrong, what I would like to, uh, kind of cover for the audience is what these agent or agents for the AI really do, right? Uh, that might, uh, help, uh, align the needs and the shortcomings and how, uh, the, how we are trying to fix those issues.
So, uh, there are four key steps that the AI agent really does. Uh, so the first piece is, uh, what, uh, we call perception and data collection. So what these thousands, and sometimes, as you said, maybe millions of or million of, uh, these agents do is what is called perception and data collection, which is gathering and collecting data from multiple places.
And now this data can exist virtually anywhere. It can be in clouds, it can be on-prem, it can be on edge, it can be in QSRs, right? And it can be anywhere across the world.
It's not just in particular location or geo, but it can be across the world. So that's the first step. The second step is about decision making.
Once these agents have collected all this data, right? They use these models, right? And tune models to make the decisions.
That's the next step. Number three step is about action, right? And execution.
So once they have made that decision, then these agents, right? Act on that decision. And last, but not the least, it's that it's learning from all the data it has gathered and from all the, uh, decisions it has made, right?
It tweaks and adds to that learning, right? And that step is basically called learning and adoption adaptation. Uh, so now if we really look at it, let's try going from the first, second, third, fourth.
So for perception and data collection, most of the data, right, has to be collected from all these different places, right? Which can be actually not just where like thousands, as you said, it can be millions of places, right? And to collect that data, what do you really need?
You need like high bandwidth network, which needs to be intrinsically secure, right? Because a lot of this data is sensitive. It's PII data, right?
It can be also high value data, even if it is not PII, right? So all these data has to be accumulated and gathered, right? On a very secure way, right?
And also it is very high, uh, bandwidth. So it has to be high bandwidth security. And that's what we also help out, right?
With, uh, aviatrix, we provide very high speed encryption right from end to end. And, uh, it's completely secure. The second part, which is there for agents, is decision making.
In this case, what happens is that once the data is gathered, right, it talks to the models, right? And figures out what it needs to do from the decision perspective, right? And this is where right?
Our, uh, the whole firewall service comes in, right? And make sure that, uh, the right decision is the right agents get to make the right decisions with access to the right models. The third piece, which is action, is very interesting.
Now, once you have, uh, thousands or maybe millions of agents, right? What decision those agents are making needs to be identified, right? What agent is making what decisions and how they're communicating with each other.
And this is what I call traceability, right? Or else, like, these are some things. Sometimes I say, these are robots, fighting robots that you need to figure out that who did what and why, and things like that.
So that is where observability really is important. And, uh, it's not just network observability, but figuring out which endpoints, right? Are talking to which endpoints and when, so that there is a traceability or they can be tracked right?
When these actions are being taken, or else it can basically get into a very chaotic situation where you don't know who is doing what, and it's not traceable or trackable. Uh, that's what we don't want to happen, right? And, uh, the last, but not the least, is about, um, about the learning and adaptation.
So one thing to think about is that this, almost all companies, they spend millions, if not hundreds of millions and few companies. They even spend billions on tuning this model and learning and adapting these models. But, uh, if a bad actor gets hold of that, right?
And exfiltrate that model, the things which you have spend millions, hundreds of millions of dollars, right? Can be theirs in minutes, right? So this is what is really crucial.
And in all these four areas, right? Aviatrix really helps out to provide a solution. To your point, it seems like we're a little obsessed these days with protecting the data, but that's only one part of the equation.
And ultimately, the bad guys, maybe they just wanna steal the agent and the model and everything that went with it. 'cause that's the intellectual property that matters A hundred percent, right? So, and also if you look at the attack surface, there are three, four areas which I talk about why, why it has changed the whole landscape.
One is, the first is that the attack surface has become way bigger. It's not just the on-prem data center is not just the cloud. It's edge, thousands, millions of endpoints that can be there.
So the attack surface is higher. And the next part is that, uh, with Gene I and the money, which is pouring in, and many of them are nation state funded, right? I maybe you already know about the Salton use case, right?
Mm-hmm. So in these cases, the bad actors or the infiltrators right, has become really, really sophisticated. So your attack surface has grown, your bad actors have become way more sophisticated.
And we have third piece is a lot to lose. Mm-hmm. Right?
So all of these three things has created the perfect storm to bring in a solution like aviatrix, which provides built in security and connectivity. You don't have to think differently that you have a connectivity, then you put security on top, and maybe they're not working together. It's in silos.
Your configuration can be wrong. All of that is taken away. Unfortunately, in my experience, every time we have some new advance in technology, the cybersecurity aspects of it wind up being an afterthought until something bad happens.
So how long will it be before that something bad happens? Uh, really great question. So, uh, this is how I put together.
So the thing is that, that enterprise, all enterprise, they have a huge pressure to bring in all this cool technology, right? So because of the pressure, right? It is really needed to increase the velocity to bring those applications.
It's not, it's from the market, it's from the c uh, CEO. It's from the developers. Everybody wants things to be fast, right?
But from the other side, there is need for security and connectivity and compliance and audits, all that thing, right? The controls. Now, uh, the part which is really interesting is that how to balance velocity with security and compliance.
Now, the thing is, what your question about when that bad thing happens, actually the bad things are happening, right? Mm-hmm. In, in, like think from today, right?
Just because of salt typhoon, nobody really knows what is compromised. So in security, while I've been working on networking and security for more than two decades, so we have a meme, uh, we say that there are two types of companies, one, which knows that they have been compromised and one who doesn't. So the meme part of it is that it's not like it's a big event, which happens, I'm sure, like we all get these letters once in a while, which says, Hey, your PIA data, your social security number, your credit cards have been compromised.
And these companies will say, oh, for one year you'll get a credit report. Personally, I have got like, at least five of them in last one year. Mm-hmm.
These are all cases of breaches, right? It is exfiltration right now, a lot of it has happened already in grand scale, right? I'm sure you guys know about large amount of breaches that has happened in United States itself, that is happening worldwide, right?
So it is not that it, we are waiting for such a case. It is happening every day more than once, right? So the, the part is that, uh, I can't talk about certain customers, but there is a customer whose network and really, really important, uh, important, uh, production in healthcare that went down for a week, right?
And they had to really put something immediately, and they came to us, right? And we had a really good solution. We were easily deployable and things like that.
But it is happening every day. We, it's not like we are waiting for something bad to happen. Do I need to go find somebody who's a cybersecurity expert who happens to also know about how AI works?
Or am I trying to train the AI people about what it means to be more secure? I mean, who ultimately is gonna take responsibility for this? I mean, I know who's gonna get blamed, but I just wanna know who's responsible.
Yeah. So, um, this is how, uh, I explain to my customers the thing is that it is about the technology and about the processes at the end of the day, right? Uh, now if you really look at it right, over time, what has happened, and even like, if you look at on-prem, they were networking companies like Cisco's and a, and there were security company liens like Palo Alto network, checkpoint and et cetera, right?
And it was always, security was a afterthought or a bolt on technology. So the c critical pattern, it used to work pretty well. When you have a building and you know exactly where your egress point is, where your ingress point is, you have a big door in front and you put a big lock on the big door, right?
But with today's architecture, with cloud and edge and on-prem, right? What I call it as a disappearing perimeter. So data can go out and in from any place, and you don't even know that place exists.
So what we really need from the technology point of view is a inbuilt secure network fabric, right? Every communication is secure by default, sometimes also called a zero trust, right? So if you have, or if companies have that technology, that's the baseline, right?
And on top of that sits the processes, right? So all the processes that is needed, like for example, today, if you look at the DevOps pipeline with Kubernetes and containers, right? It's a process and it cre makes sure that there is repeatability, there is audit, there is compliance, there is drift management, all of that, right?
So what my, what how I tell customers is that if you have the right technology, and if you have the right processes, then everybody does not have to think of it. You want your developers who are like cool gi uh, developers not to have to think every day about security because it is already taken care of by the technology and the processes. Mm-hmm.
And same way, right? The, the platform team does not have to think about it every day because they have set the processes in place so that it is already taken care of. They just have to make sure that it is properly audited, right?
With the system is going to tell you, right? And it should just work without anybody's, um, manual intervention. So are we gonna have to fund a hmm, major upgrade cycle of our infrastructure to get to the faster networking that you described?
And of course, the servers and GPUs and everything that goes with that. But are people overlooking the networking side of that equation? Uh, yeah.
So, uh, that's a great question. So actually you have the technology right? There is fast connectivity.
Whether you look at CSPs or the, um, or, or the service providers, there is fast network, which is already there, right? The part which needs to be done is what I call it as secure by layering. So all it needs is to put a software defined networking and security layer on top of the base connectivity so that the end to end across all clouds, across all edge, and colos and on-prem, right?
That software layer, right? A distributed software layer, right? Takes care of it as a layered approach.
We don't have to upgrade, right? The networks or upgrade the infrastructure. We need to just put a distributed networking and software solution right on top of your connectivity today with a single or unified pane of configuration and visibility and observability, right?
And that can be easily layered in. So for example, the, uh, solution which aviatrix has, right? You don't have to change or you don't have to upgrade everything.
It just goes as a layer on top of your current deployment. Not just that you have to change everything. You can roll it in in phases, right?
And transparently add that layer on top. The other part is that we just released something called a pass solution AVIA strict pass, which is that we manage everything. So your operational cost actually goes down, right?
And you get this whole service integrated security, right? Which is completely managed by Aviatrix. Will you be adding your own AI agents to your service?
Who in turn will have to talk to all my AI agents? And how's that all gonna get orchestrated? 'cause it seems like there's gonna be all these, uh, control plane and data plane conversations that need to take place between different classes of agents.
Is that right? Yes. Actually, uh, we already have certain agent, uh, agents in the product itself, right?
So we have started rolling them out. It, uh, we have agents which figures out, um, how bad the scenario is for every p VPCs and their deployments, right? And on the other side, we are also working with, um, the CSPs to integrate with their agents to make sure that they can, we can provide the information they need from end-to-end.
Um, we need to be way more collaborative in this space, right? So that we all work together to achieve the outcome, which we are looking at. But it has already started.
And, uh, we are working with, you know, like top three CSPs in that area. So what is your best advice to folks about how to have this conversation with their teams? Because I think every organization you talk to is AI happy.
There's a lot of maybe occasional irrational exuberance, but I don't think they're really understanding all the, the fundamentals that we need to get addressed. So how do I kind of get in there and kind of bring everybody down a reality? Yeah, great question.
So what I generally advise customers and prospects is, number one, is to embrace multi-cloud infrastructure. So to design with multi-cloud and the infrastructure in mind. So have, uh, infrastructure like, which is basically networking, security, and the full stack, which is across clouds, across edge, and it is primed, right?
For supporting any kind of gen AI applications on top, invest in it, right? Invest and embrace, right? A full multi-cloud edge kind of a infrastructure.
Uh, number two is that security needs to be embedded in the infrastructure, not a afterthought and not a bolt Bolton, right? When the cloud architecture is being designed, it should be embedded into that, not what I call is, is built in security versus Bolton security. And last but not the least, is provide the processes so that the developers and these gen AI experts, they can develop and deploy their applications with no friction from security and infrastructure team.
I think maybe we're overlooking one small but important point, aren't most of these AI agents, and maybe even eventually the models themselves gonna be running at the network edge, because I need these things to be closer to the point where the data is being consumed and created, rather than having some sort of round trip to a cloud somewhere where I may have trained the initial model, but now I need to get the inference engine from that out to the edge. So, um, does that require a level of, of finesse that we're not thinking through? Yeah.
So, uh, it is a hundred percent correct, right? So the thing is that, uh, the base models are generated generally in the cloud because it needs lots and lots of, uh, GPUs and infrastructure and data to be generated. But, uh, these agents basically tweak those models, right?
And these models go out into the edges and all the different, uh, places, and they get tweaked, and then that, uh, tweaked data finally comes back and then makes those base models more, um, enriched, right? So, uh, that's the main reason why I ask, uh, enterprise customers to provide a fully distributed, uh, secure network across clouds and across edge, right? Because once you have that, you can run these models anywhere.
And, and you don't have to think, like, for example, if a developer wants to deploy it in cloud, they deploy it in cloud. If they want to deploy it in edge, they deploy it in edge. Um, I had in my past, um, company QSRs one of the largest QSRs, right?
And they used to de they would deploy all these, um, agents in their q small QSR with two little boxes, right? But if the infrastructure is robust, high performing and secure, you don't have, like, the developers don't have to think where to deploy, Right? Folks, you're hurting here.
I think it was back in the eighties, the first time I heard the phrase that the, the sy the network is the system. Well flash forward all these years later in ai, and the network is still the system. Hey, army Bond, thanks for being on the show.
Thank you very much. Thanks for having me. All right.
And thank you all for watching the latest episode of the Textron AI video series. You can find this episode and others on our website. We invite you to check them all out.
Till then, we'll see you next time. Hello, and welcome to the digital CXO podcast. I'm Amanda Ani, and I'm excited to be here today with Dr.
Jason Corso. He is the co-founder of Voxel 51, as well as he is a professor of robotics and electrical engineering and computer science at the University of Michigan. How are you doing today?
Hey, Amanda, I'm doing great. How are you doing? Doing well.
Can you share a little bit about Voxel 51? What are y'all doing over there? Sure.
So Voxel 51 is a, uh, AI software company that builds a package called 51 and 51 teams for enterprise. That essentially, you know, our our target user base are builders of visual AI that seek to understand more about the, their model performance and their dataset quality so that they can ultimately build visual, you know, make visual AI a reality. Um, we've been open sourced since August of 2020.
We have about 3 million installs. Uh, we do set up the software in a way that is hyper flexible, right? We don't sort of tell you what to do or how to do it.
It's, it, think of it kind of like building blocks for the developer in the visual AI space. And, um, you know, ultimately it's been used across various industries from, you know, automotive industries to agriculture, to, um, consumer products, advertising, sports, you know, you, you name it. We have users either in open source or enterprise.
Wonderful. Thanks for sharing. So our topic of today is achieving almost 100% accuracy for visual ai.
So tell me a little bit about that and where you come in with that, and we can move on from there. Sure. com or you know, various leaderboards for computer vision and visual ai, uh, sometimes the numbers will be jarring, right?
Like the numbers might be something like 60% or 70%. And, and yet that's a, that's a decade of research that went into that level of performance or decades of research. Really, if you, if you think about the predeep learning era to too, um, but if you think about what's necessary for actually deploying visual AI into practice, right?
You, you, you have an autonomous vehicle, or you're doing a, you know, a quality assurance on a manufacturing line, 70 percent's frankly not good enough. 80 percent's frankly, not good enough. Uh, even 90 percent's really not good enough, right?
Like, if you only miss nine out of every 10 pedestrians that come into your, in your view in an autonomous vehicle, you're gonna have some problems, right? So, so we think of this, uh, as, you know, an analogous to the classical five nines concept, right? 999%, uh, comes from.
It's, it's from network security and network uptime, basically, uh, in, in various, you know, pre-cloud, in the pre-cloud era. Uh, and it, it is super critical to, uh, achieve that level of performance so that we can begin to, uh, assume robustness in various visual AI capabilities and then take the harder problems to humans downstream, right? Uh, where, whether or not that is, I mean, I, I like the QA on the assembly line, or the fact the manufacturing line, like it's a really good example, right?
Like, if you can basically have the, the humans, the domain experts who understand the product, understand how the circuit board needs to look or whatever, the, you know, I just made a French press coffee, right? Like how the French press needs to be assembled, right? Like, and only give them the corner cases, their time will be used more effectively, and the overall efficiency of the manufacturing line will also be used more effectively to, to do that.
We, we wanna get to, to this notion of five nines in, in visual ai. So once you have this very accurate, uh, visual ai, what are some use cases where this could be integrated? Well, I, I mean, I think this, this really talks to you or gets at the, the, the popular terms that are, that are being used or these days.
Uh, right? So you have visual AI is one of them. Then we have this notion of physical ai, right?
That, you know, ultimately, like the fu what, what does the future of, um, robots look like? Either, you know, take, take robots out of the factory and put them into the hospital, put them into the classroom, but to put them into the home, what can they do? And then even post physical ai.
Now, we've also begun to hear about age agentic ai, right? Like, not only can these robots or these physical AI things see through visual AI and listen through, you know, language ai, but can they also begin to reason about goal, the goals that are either given to them through conversation or talk to them in a training phase to then go and understand what they should be doing to increase, increase efficiency, or to help the elderly who's fallen down or give the right medicine or what have you, right? 99%.
Uh, visual AI is one of the elements, one of the key elements of those foundations, right? Like o other elements are fast, low cost compute, we're getting there, right? The recent releases we've seen in, uh, January of 25, like from Nvidia about I think the systems called digit, like it's moving this notion of high power compute that in a more portable edge based manner.
I think that's, that's one of the elements of the future. Another element is, um, you know, like the ability to do speech recognition and speech generation robustly, uh, to be able to interact with humans on the human's terms. Uh, and we're seeing a huge amount of progress in that, right?
The whisper technology from open AI is, is like one of the latest in speech recognition, very capable, uh, still need some work around speech or separation. Like if, if there's a robot I make, you know, amongst many humans, and like I have, I have three kids in my h in my home. So like many kids around making a lot of noise like that, that gets a little bit more difficult.
But once you have these pieces that are robust at the lower level, then we really can, we, uh, we can begin to think about more practical physical AI and physically agentic AI in, in the, in other applications that, and I think that's ultimately the, like the, the true impact, positive impact that AI will have to everyday life is not gonna come until we, we've built those things first, uh, and or at least demonstrated that they're robust and safe and and secure. We're starting to see some self-driving cars around. When do you think it's going to be the case that almost every car is a self-driving car out on the road?
How far away from that? Yeah, that's a hard question to really pin a pin a time on. And anyone who has been, uh, confident enough to give a time has been wrong in the past.
I think, um, think, think about it another way, right? Like when, when elevators were first, uh, created, um, there were humans in the elevator to operate the elevator, and the elevator was still fully autonomous, it was just being operated by a human because that was the social, um, contract, if you will. There, there was this comfort level.
So, um, I don't know exactly, I should look this up. I don't know when it became more common to have, um, fully autonomous, no human operator in the elevator than the, you know, than not. But if you think about the progression in automobiles in the last decade, I think it's been really powerful, really amazing, right?
Like we, we moved from classical cruise control, for example, to, I mean, different companies call it different things, but essentially like radar base or adaptive cruise control that can maintain a speed unless there's a vehicle up ahead, uh, can even, uh, adjust the speed whether or not you're the, the traffic based, based on the traffic density, for example. Um, you know, so we are getting a lot closer to nearly autonomous, um, you know, uh, uh, vehicles. And I, I don't think, I think the social comfort level will be the final hurdle to overcome even once we have the technology that's capable and it's real.
So, and humans, you know, we humans are really hard to understand a lot. So it, you know, hard to, hard to predict when that will be, but I I actually think it's gonna be sooner, sooner than you think technologically, but later than you think socially. Mm-hmm.
So, I know it's hard for humans to trust technology fully in that way, and technology can of course, make mistakes. But do you feel like if every car on the vehicle was every car on the road was self-driving, we'd have a lot less accidents? Oh, I, I do think there are both.
There are, there's clear evidence that that would be true, right? Like, um, that first of all, like these autonomous vehicles won't have to worry about the radical and predictability of, uh, uh, what typically happens on the roads. Like at least roads that are out of, uh, human occupied, occupied areas like highways and things like that, right?
Um, but I think the, there are other elements that if, if we, if we had infrastructure that was built or updated to support autonomy, I think we'd already be there with less, you know, in some sense with less traffic. You know, I think there was a study in the nineties somewhere in California where, um, they built a small or built, or like cordoned off like a portion of highway to do some tests, and they were, they did, um, these, like, I forget the exact name for them, but when you have autonomous vehicles that are able to like, go very close to each other as they're going down the road and they have these, like, you know, a dozen or so, I mean, I mean, I think the fuel efficiency was demonstrated to be ridiculously higher. Um, and there were no accidents recorded in that study, you know?
And even though there were humans in the cars at that point just for safety. Um, so, so anyway, I think the evidence is there that we will see, um, like the, through better communication between the vehicles, through more predictability between what's happening via that communication and or just less, less, um, unpredictability from human drivers. I, I do think you'll, you, we will see safer roads, uh, at, at that point.
Yeah. Yeah. You bring up two great points.
There is not just the safety issue of that, but also the energy efficiency. So I, um, hadn't thought about that as much, but, um, that should help with, um, energy and gasoline use too, if, if all the vehicles are driving as efficiently as possible. Uh, 100%.
And, and I think, you know, not, not only can it be already demonstrated that that's the case, um, I mean, I think it, it's when you have roads that are that, that are more safer than, than we unlock the capability to, um, redirect other investments that are being made is maybe what the thought that I'm thinking, right? Like, um, I, I know that, that there are some companies who focused their, like, like autonomous driving and trucking companies who focus on energy efficiency now even, right? Like, how do you do better cruise control knowing the weight that's in your bed when you have a, a hill coming up, for example, rather than it's gonna be a flat terrain, right?
So I think fuel, the fuel efficiency is a, in some sense, like a fiscally responsible way to push toward infrastructure change, in my view, for example. Um, yeah. Yeah.
So infrastructure is next is important. It's an important step for that, for this to happen. Do you think visual AI would soon be integrated into more cities?
In other words, smart cities with, um, visual AI being integrated into the street lamps and the street signs and, you know, cameras and that kind of thing to determine traffic and all that kind of stuff? Yeah, I think that that, uh, progression has already begun. You know, there are already modern cities, even in the US that have hundreds or thousands of cameras.
Most of them were installed for security and public safety purposes initially. But once one realizes that oh eight, if we actually model traffic flow through, we, we have all this, this data now, and we can connect other visual AI to understand, um, you know, a general way of saying that is like patterns of life, right? Both from vehicles and events and humans and pedestrians and so on.
Um, then we can, um, optimize for various use cases, both safety, uh, and, and energy responsibility, or even just access, right? Like we want to bring, we have these beautiful cities in the United States that, uh, downtown areas that are often not that occupied. Um, you know, so we can, if people feel safer, they feel the cost will be less, even just figure out how to do better parking, for example.
All that will come through visual AI mechanisms that better understand and utilize the data that are available. So all this is underway in some level or other. What do you envision knowing how fast technology is advancing?
What do you envision for the future, say 10 years from now? Um, well, I think it's, I mean, it's, it's such a, it's an great question. 'cause this is such a great time to, to like be thinking about what's, what's coming, right?
Um, I mean, I do think the, we, we are, we have experienced a critical point in the development of, uh, of AI broadly, like visual ai, physical ai and so on. And that, that did come from the demonstration that these like super large scale scale models connected with vast amounts of compute and vast amounts of data, were able to, um, pull out elements from our human world that, that allow a better translation between the computer world and human world. Um, I think this came initially in, in my SA area, like the world of like, um, computer vision, video understanding, and so on.
Like, you know what, my, my research group for example, at, at Michigan Focus has focused on video to text for over a decade, right? You know, or an image to text. You know, my, my National Science Foundation career award was on the image captioning problem in like 2008, right?
Like, so I've seen this, this field grow. Uh, and I think when CLIP came out, you know, 20 18, 20 19, we saw this notion that, oh, wait, like if you have image data, visual data, and you have language data and they're connected and training against each other, and you're doing this at scale, there is immensely powerful structure in the, in the model that's learned from those data. And, um, we are now be beginning to see that structure being leveraged for downstream tasks.
So in the field, oftentimes these mo these models that do these types of things at scale are, are being called foundation models now. Um, and when you can take a, a foundation model off the shelf and just make use of it for a, a different task for which it wasn't anticipated, or it wasn't trained for, you may have to fine tune or do rag like retrieval augmented generation to go and like augment what was originally in that, originally in that data for a downstream task. Like that work is, is already light years ahead of where it would've been if you had to start from scratch, which starting from scratch would've been, what data do I need to train this model?
What's the right architecture for, for my model, right? And then you go and spend months or years getting that data. That's why, like, you know, in some sense, maybe the 2010s where like the decade of large data sets in machine learning research, machine learning research, right?
Like everyone, everyone who wanted like to get high citations on their papers were like, oh, I can just get a, make a big data set and I'll go get a lot of citations. And I think that that was, that was last decade. And now we're in this era of what can I do with these foundation models?
And I, this is, I think we're still really nascent on that, on what's possible. But I think that that inflection point, that critical change happened when we saw what things like clip were capable of, and that, that structure there is, is just super powerful. And you see like foundation models, like Microsoft had this, uh, paper from CDPR last year, Lawrence two, which is one of those like sort of downstream models that build up on top of a lot of data, a lot of foundation elements, foundational elements, and then you can query it with pretty intricate questions about the visual data and the performance is, is quite, quite strong.
All right. Well thanks for sharing that. So if there was one key takeaway you could leave our audience with today, what would that be?
Uh, the key takeaway that I, that I'd like to end, uh, sessions like this would be that even though there's such amazing progress in AI and visual AI and so on, um, I think it's important to always remember that we do this for, for humans. We are humans. We're building for humans, right?
Like, how can we make our society a more balanced, more equitable, safer place for everyone? All right. Absolutely.
Well, thank you so much for coming on the show and sharing your insights with us today. Thanks, Amanda. Happy to do it.
All right. And thanks to our audience, stay tuned. There's more.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com, home of Security Bloggers network. Hello, and welcome everyone to the 5G Factor.
I'm Ron Westfall, research director here at the FU and group, and I'm joined here today by my esteems colleague, Olivia Blanchard, fellow research director and practice lead for AI devices here at the Futurum Group. In fact, uh, Olivier has been heading up our coverage of what's going on with AI devices. And naturally in today's conversation, we'll touch on that.
And naturally we have, I think, a lot of ground to cover here because there's always something going on, especially in the lead up to Mobile World Congress 2025, the first week of March. And so with that, Olivier, welcome back. I know it's been what, a week.
And so good to see you. Are things coming along, Things, you know, I can't believe it's only been a week. It feels like a month already.
It's been, it's been busy. We, while we've had a lot of, um, reports and dashboards and intelligence products coming out, so it, it feels like the last week was about two or three weeks packed into, you know, five days. But yeah, I understand.
Yeah, No doubt. No, no, I, I think that it does, uh, I think perception is key. It does seem like right, and maybe this week we'll emulate that.
Uh, but that's good because that means the ecosystem that certainly the 5G and, uh, mobile ecosystem are having plenty of things going on, uh, that merit our attention and perspective. And yes, our friend AI is playing a role in it. Uh, however, let's really focus on a, uh, I guess you could say a mobile-centric announcement that came out during the Super Bowl, super Bowl 59.
And during that, uh, momentous event, T-Mobile introduced T-Mobile star link to millions of football fans out there. In fact, uh, this set a record, if I, uh, understand correctly, 126 million people sued into the Super Bowl, and that's, uh, including all the different platforms, and that's why a Super Bowl viewing record was achieved, even though the game itself wasn't exactly dramatic during the second half. Now, uh, uh, back to T-Mobile, starlink the important thing here, and that it's in public data, and it was developed naturally in partnership with starlink, and it's using satellite and mobile communication technology to help keep people connected.
And why is that important? Because quite simply, there are more than 500,000 square miles. That's a half million of the country that is here in the United States of America that are unreached by any carrier's, earthbound cell towers.
And that equates to about the size of two Texas's. Now, I think what's also important about this announcement is just not for T-Mobile customers to trial and test out. I, I think, uh, it, it's in July that you have to start thinking about, okay, do I really wanna include this?
And if you're already a a T-Mobile customer with a specific 5G plans, you can pretty much add it on after your trial, otherwise you could add it on for specific bees, but also Verizon and at t customers can also trial this. And I think this is a smart move by T-Mobile because here is a way to really potentially garnish your customers from your top two rivals in a way that is, well, obviously legally sanctioned, but also, uh, smooth marketing, certainly from my perspective. And other important takeaways here is that T-Mobile starlink is using specially configured satellites with direct to cell capabilities or direct to device.
And that's orbiting, you know, earth about 200 miles up. And, you know, they're traveling at very rapid rates, you know, 17,000 miles per hour to be specific, to deliver these cell phone signals. And that includes tech messages for now with picture messages with, uh, data and voice calls coming later.
And that quite simply is filling a void that, again, earth cell towers can't really address today. And this is, I think, a very important part of, you know, how do we get what can be called universal coverage to, you know, really assure a society without, you know, digital divide, uh, because of, you know, connectivity, um, capabilities, uh, that can't, uh, be, um, reached, uh, the recent past, but now that is changing. So that's good news for everybody.
It's not just good news for, you know, T-Mobile, the mobile ecosystem, but really for society as a whole. And so with that, uh, kickoff, uh, Olivier, from your perspective, what are some, you know, important takeaways and, uh, aspects to, you know, this announcement? Yeah, well, fir first of all, uh, it's the mainstreaming of, uh, of satellite or, uh, near, uh, what is, what's the, what's the term?
NTN near terrestrial network? Oh, yes. Non Terrestrial.
Yes, yes, indeed. Um, I, I drew a blank just then. I was like, I thought I knew this, and it's been a while since I've actually said the words, so I've, I've blanked out.
Uh, no, but it's, it's de it's further mainstreaming of, uh, of these networks, Uh, By obviously not needing a, a dedicated antenna, but being able to, to access them directly on your cell phone. So, a couple of things for me, I mean, obviously it's, it's part of an evolution. I think that we'll see this becoming much more mainstream, much more ubiquitous in, in years to come.
Um, two, it's a proof of concepts. I know that even, I wanna say two, three years ago I was at I, uh, 3G PP conference and, uh, NTN was a big discussion, but there was still some skepticism about like, why would people pay extra for this? Uh, is it ever really going to be anything more than, you know, a commercial application for truckers or for, you know, ships at sea?
Things of that nature. And now we're starting to see that, uh, for, for anything else, just the convenience of it, the security or the sense of security that, that we might feel from knowing that we're gonna be connected from anywhere, right? You could be, you know, out camping somewhere where there's no, no, um, uh, antenna cell reception, but you can still be you, you can still send, um, you know, distressed messages, uh, or like, Hey, I'm okay messages to your loved ones.
So you never completely isolated if you don't wanna be. Um, and even just, uh, for, for everyday people who don't necessarily travel cross country or go into zones that, um, that have connectivity issues, sometimes things happen, things fail, right? There could be a natural disaster, like the hurricane that hit the, the Southeast, uh, a few months ago.
And that left us without internet or power for a while. Um, there, there could be fires in California, there could be an earthquake, like whatever the reason, having that extra level of service that sort of bypasses terrestrial infrastructure might also be, uh, well worth, uh, the investment. And, and also having the ability to kind of turn it on and off at will, uh, not necessarily always having it on at all times is not necessarily a, a, a, a bad option either.
So I think, you know, this is good for starlink, it's good for T-Mobile. It's a great differentiator for them for now. Uh, and it's also good for consumers, and it's, it's also a market test.
Let's see, you know, after the, uh, the amount of exposure that T-Mobile had, and I thought that was, you know, obviously brilliant, uh, traditional media isn't dead. So, um, that ad was really powerful. So now let's see how, how well they convert over the next six months.
Yeah, no, I think this is just a great way to start the flywheel to your points to the va. The beta is free, free until July, and I admit, I've signed up for the beta. And what's I think important here is that TBOs, mobile starlink will be included at no extra costs on go 5G uh, next plans, you know, with, um, T-Mobile.
So if you're already on the T-Mobile network and you have that plan, well, what's not to like? I mean, it's a proverbial no-brainer. Also, uh, yes, it's important to consumers, uh, but also business customers can also get the starlink, uh, plan at no extra cost on go 5G business next.
So this is really, you know, covering, uh, uh, that additional base. And I think that was something that's important to underline about first responders. That is first responder agencies on t priority plans and other, uh, select, uh, rate plans can also definitely, uh, add the service.
Uh, and what I think is also important here is that when it comes to the Verizon at and t customers, they can add it after the beta for $20, uh, per month. Uh, I understand that now, uh, yes, uh, they're both also, you know, doing their own direct device, um, trials and so forth. So yeah, this is definitely gonna intensify and pick up, but I think, think it's a tribute to, you know, the innovation that's gone on with the starlink Constellation Network and enabling this.
And we've seen it no really, uh, prove a lifesaver in these, uh, natural disaster areas for the wildfires, the Southern California, let alone, you know, uh, places like the, uh, Ukraine, uh, Russia, uh, campaign. So, uh, uh, you know, what's, uh, very vital here is that, uh, this will be a game changer as it becomes just that more mainstream. And to add to this, I think it's important to note that also, um, carrier, such as KDDI in Japan, Telstra, and Australia, as well as optis, as well as one nz, uh, at the New Zealand and Intel and chilling, Peru and Rogers in Canada and ca uh, star and Ukraine are also on the bandwagon for this.
So, you know, that is, you know, working with Star Lake, in order to bring, you know, this, uh, you know, broader universalized coverage, and that is to again, eliminate what can be called, you know, dead zones. Nobody wants that because of just what we touched on. It could be emergency situations, unknown unknowns, and so forth.
And I think that's something that, uh, will just be that a, a feather in the cap for T-Mobile as it, uh, looks to advance, uh, this campaign. Now, with that, let's turn to another important development that, uh, just popped up on the radar, and that is Nokia has named a new CEO and basically they picked Intel exec, uh, who is leading the AI and data center efforts, Justin Hotard. And that I think, uh, from my perspective, is a smart move.
And what I think is important here is one doesn't have to be a data scientist to understand that, that this is also good news specifically for Nokia's portfolio-wide AI and data center initiatives. And let's get some of the irony that's been noted out there out of the way. You know, Nokia selecting Intel executive may seem a bit peculiar, given that Intel's silicon manufacturing problems a few years back led to a lot of har heartburn for Nokia in terms of its, you know, uh, mobile, uh, access side, specifically the radio access network, uh, capabilities.
And that, uh, Verizon a few years back turned to Samsung because Nokia was not able to, in some key ways, meet the Verizon demands. And what was this linked to? Well, the little history here, there were delays in delivery of 10 nanometer asecs for their 5G base station equipment.
And Intel was identified really as the blameworthy supplier in this instance. And that disclosure, I think, didn't really surprise, uh, many people at that time because of the manufacturing struggles that Intel was having at that time. Now, NPI had then had to pivot to more expensive FPGAs, and that in turn upset its gross margins alongside its technology competitiveness, which then triggered, uh, a loss of market share and that key market segment.
And it, you know, it's been a challenge to recover since then. However, I think this is important to note that was a different era involving a different set of decision makers. So, Justin Hotar coming on, I think is really a new level set.
And again, I think it's very wise of them to go in this direction of, okay, how can we optimize AI capabilities across the entire Nokia portfolio? And yes, uh, uh, Justin is, uh, replacing, uh, Peka, Lumar who I thought, uh, did a very, uh, outstanding job overall in terms of getting Nokia in better shape over the last four years. It's been challenging.
They faced a lot of headwinds. Uh, and also we saw that there was difficulty throughout the mobile ecosystem. So this wasn't unique, uh, to Nokia in terms of what's been going on over the last few years.
Uh, part of it is, uh, you know, was, you know, post covid related, and that is, you know, spending amongst, uh, the carriers on a global basis basically got dialed back specifically on the CapEx side. Now, what I think is, um, helpful in, in the near future is that that will start inching up this year and probably into the foreseeable future due to factor such as, okay, uh, operators exploring how to really optimize AI in terms of, you know, making them more, uh, competitive, uh, that is the service offerings, let alone, you know, the operations and the business processes within the operators themselves. And, uh, just, uh, kind of an additional, uh, reasons why we can say this about, you know, landmark is that, uh, their share price has been improving 10%, uh, over the last, uh, four years.
And that I think is a tribute to, you know, okay, navigating some of these massive challenges that Nokia faced. 1%. All these were really, uh, I would say achievements that, uh, showed that Nokia hit these high marks and that they were best within the last decade.
Now, what I think is gonna be important here is what's next? You know, what can Justin Hotar do to really, you know, make, uh, Nokia more competitive? And I'll stop here because Olivia, I think you might have some thoughts on, you know, why is Nokia really making this pivot to what can be characterized as an AI driven portfolio, uh, development strategy, let alone sales and marketing strategy?
What are some of your insights on this move? Right. Well, I'm gonna take a pass on that question and just like bounce it right back at you.
Uh, I, I, I think, you know, I wanna know what, what, what you're thinking about it. Uh, but what I will say before, before that is, uh, I think it's interesting that, uh, Nokia is turning to, uh, a, an AI and data center expert at scale, right? At scaling these services, at monetizing this, uh, to, uh, to, to run.
Its, uh, its company. So it's, I I think it's the, the question sort of answers itself. Obviously, it's a pivot to AI and, uh, and they want the best talent on board to figure out how to do that properly.
Um, the, the, this story is so full of layers of irony that we could, we could dedicate the, the whole show to talking about it. But obviously Intel's woes are Nokia's, uh, uh, advantage right now, because they're, I don't, I don't know that if, if Intel had had a better year, if, uh, if anybody had been trying to, to look for, uh, you know, Rosie or Verizon. So I think that the, the fact that he's jumping on board with this new opportunity where he's gonna be able to do something, uh, that he might not have been able to do at Intel, uh, something perhaps, I wouldn't say more important, but definitely more important to Nokia than it would've been in Intel.
Um, and, and the ability to kind of do this for the next few years and build something really special is, is obviously a part of the appeal. Um, my question to you though is, um, what's, what's Nokia's game plan for the next, you know, three to five years? Because that's, I think that's, that's the real question.
Like, how do they remain not just competitive, but relevance as the, the entire industry pivots to this, uh, to this AI stuff? Uh, thank you, Olivia. And yes, I do have some thoughts on this.
Now. I'm not gonna go as far out as five years from now. I can change, but I can say, you know, within the next, you know, one to three years, what I think, uh, are some important takeaways and, you know, what Nokia can do to just do that, improve its competitiveness.
And it certainly, bringing Justin on is a, a, a key first step here. But I think, uh, you know, specifically it's yes, uh, good news for the data center side of the business. I think, uh, we've certainly seen, you know, like Mike Boong who just came on, uh, you know, relatively recently over a year ago, and, uh, you know, basically head up, you know, energizing, you know, uh, Nokia's, uh, data center proposition.
And I think what's gonna be integral to this is normalizing what could be, uh, characterized as matter of fact innovation in terms of how Nokia prioritizes its, uh, portfolio development strategy. And that is, you know, things like making it easier to quite simply deploy a fabric. I mean, this is something that you think, oh, okay, it should just be, you know, uh, like do your self proposition for organizations because they're big, they have these resources, they're prioritize, uh, prioritizing ai.
But actually, no, uh, this is pretty much, I think coming out in some of our key recent future intelligence data. Like when we, uh, surveyed 872 enterprise organizations know what is the top thing they're looking at in terms of selecting, say, an AI solution, you know, an overall AI solution, and that is AI expertise. You know, they want their, you know, key, uh, supplier, their lead integrator, however you want to characterize it, to be the one that's going to enable really a comprehensive full stack vision and approach.
And that, you know, would include, I would say, a lot of point products for that, uh, you know, lead vendor. But, uh, ultimately, uh, that is something that is going to be a, a difference maker, as, you know, enterprises and so forth, figure out, okay, what is the best step? How can we rightsize language models and so forth?
And this is something I think, uh, Nokia can play a more integral role in. And that also, I think is also, it, it's simplifying the execution, the daily tasks around things like auditing and troubleshooting. And this is not unique to the data center.
This would apply to all units in Nokia, including certainly, you know, the mobile infrastructure side, including, you know, uh, any, you know, uh, software development initiatives that, uh, NOIA is, uh, has overtaken, uh, such as telco SaaS. You know, that comes to mind, and I think this is something, uh, that is not just about the data centers, but really removing, you know, some of these, uh, you know, problems that continue to play, you know, making a real progress in terms of, say, automation across, uh, the data center. What I think this is gonna enable is Nokia coming up and saying, Hey, we have to look at an organization-wide automation plan to really make something like automation more, well, uh, I would say advantageous to the customer that is, you know, improving business outcomes.
It's one thing to have, you know, uh, say automation, you know, using AI enabled automation benefits, say, you know, some individuals or some units within an organization, but there, it stays. It's, you know, pretty much, uh, siloed. But I think what's gonna happen here is that it's going to enable a, a portfolio development strategy and vision that's taking advantage of the intersection of what's going on with AI enablement.
That is the workflows, the systems, really looking at the entire ecosystem capabilities that elite integrator can bring to really, you know, make that, you know, strategic difference to, uh, the customer. And I think it's also making, uh, to your point, Olivia, about integrations more scalable that remove not just, uh, the effort involved, but also the time. And so this is really, I think, a way for Nokia to start looking at how they can show metrics that, okay, we can deliver time to value, uh, let alone time to market value from, you know, our, our portfolio assets.
And this, I think, will definitely pull through things such as AI ran, which is kind of like a, potentially a new level set for, you know, how can mobile infrastructure be more efficiently deployed. And so far, uh, it's still kicking the tires, but we saw with, you know, deep seek, you know, okay, hey, if ai, you know, technology could be a lot more power efficient, a lot more, you know, software agile and so forth at any part of the network, whether it's the data center, whether, you know, involves the training, let alone inferencing, this is, you know, something that's not just about, you know, the data center, but the entire portfolio, including the mobile infrastructure pieces and so forth. So, and a nutshell, this is a, a very exciting move, and I think this is something where I see, uh, can make an impact in terms of, you know, answering the question why Nokia and how they could be, well, just that, uh, more differentiated, capturing more mind share out there.
And so, uh, perhaps that's aligning with some of your thinking as well, Libby, in terms of, you know, what needs to happen to kickstart, you know, enterprises getting more comfortable with ai. Yeah, yeah. No, I, I agree.
That's like, I kind of wanted to hear from you because I can see sort of like little bits and pieces of it, and I can see the, the overall shape of it, but I can't, um, you know, I, I focus more on the devices than, uh, than this part of the technology sector. So there are still some, some pieces missing to this, so it makes sense. Um, yeah, and it's, you know, it's, it's too bad for Intel.
They're, they're losing a, a really talented, um, leader and Yeah. At, at a critical time Yes. When, and they're already sort of like losing some of the other ones.
So, um, yeah, I just, it makes me worry actually. Uh, I think, you know, as good of a, a, a a, a pivot as this is for, for Nokia or at least the next, you know, milestone in, in their sort of transformation journey, it makes me worry for Intel a little bit more that, uh, some of their best talent is getting poached by, uh, uh, by other industries. So Now that's a legitimate point.
Yeah. No, I think we're not alone in that observation. Yeah.
Now, when will your visit Intel, but I think you mentioned devices. Mm-hmm. So last look at devices, uh, specifically, and as we know, Qualcomm recently re, uh, reported record Q1, fiscal year 25 revenue.
And how did this have, well, it was driven by strong premium tier handset demand, and also continue momentum and key segments such as automotive. And this, uh, really, uh, resulted in its six, uh, six consecutive quarter of record revenues. Now, also, I think important to note is that all comms, CDMA technologies or QCT revenues surpassed $10 billion for the first time while AI adoption across devices gained yet more traction.
And so this is, I think, a real compliment to, you know, you know, know what's going off Nokia, and you know, what can be characterized as, you know, some of the infrastructure, uh, developments. And I think what's also important about the Qualcomm, uh, results is that, uh, it noted that Google Cloud and Meta are among early adopters of its own AI infrastructure initiatives, as well as that Verizon and Google Cloud are partnering on advanced AI services for network maintenance and anomaly detection. And so while there's, you know, that those are certainly, you know, uh, the strengths, uh, but we also have to look at, you know, uh, you know, the concerns that might be out there.
And that I think revolves a Qualcomm's technology licensing business or QTL, uh, there's, you know, ongoing negotiations with Huawei, and again, uh, that might, uh, have, you know, some impact on near term revenue stability. But overall, you know, I think, uh, you know, the results are pretty positive, even though there was some sell off on the street, you know, IEA bit of profit taking every, every time, Every time. Yes.
Yes. And, and seriously Qualcomm's expansion into I PCs, uh, automotive XR and also AI driven iot segment segments is, I think, validating its, you know, long-term growth strategy that Christiana Oman has implemented. And I'm gonna stop there because, you know, uh, Olivier, what do you think about Qualcomm's recent results?
What are some things that leap out at you? Right. Well, many things.
So, first of all, I think that it's definitely a, a val, I mean, time will tell, 'cause we're, you know, there's still, there's still time to go. Um, but this to me, is, is further validation that's, uh, christiano's, uh, diversification strategy for Qualcomm that if he sort of kicked off when he became CEO, uh, a few years ago, uh, is paying off, right? A lot of people are wondering, okay, like, we started out as Qualcomm being a, a, essentially primarily a mobile first company, right?
So you had some network stuff, but it mostly, it was mostly like modems and the SOCs for, for, um, Android devices. And that was, you know, they had a few other products, but that was essentially like their core thing other than licensing. And then we, we started seeing Qualcomm go into devices.
So, uh, you know, smart watches and smart speakers and, you know, hearables and wearables, uh, uh, they, they went into, obviously, they, they, um, provide most of the processors currently for high-end xr. So all the meta stuff, Google, like, basically if, if you're, if you're wearing some kind of augmented reality, virtual reality, mixed reality, uh, glasses or smart glasses, there's a really good chance that Qualcomm tech is powering it. Uh, obviously they have a huge play in automotive, right?
With their digital chassis and their, um, their Snapdragon automotive products. And, and this year they went this, they, this, they did this leap into the, uh, PC segment. So, uh, where we initially had essentially just Intel and, uh, a MD on the X 86 side, and you had Apple over here, and, uh, and you have Chromebooks.
Now, you also have ARM-based Snapdragon processors powering a IPCs. Uh, they were the first to market with Microsoft with this, and then Intel at MD followed. Um, so they've, they've sort of like created all of these different runways to growth in addition to mobile and some of the network stuff that they had before in iot.
And what we're seeing is that it's working, right? Um, so I, I think that's kind of like the, along the broad lines, this diversification, this growth by chasing these different verticals that are very high growth, very popular right now with the most potential, uh, for expansion, uh, has been spot on, like they've been on Target, uh, a hundred percent. So I think you, you said it, um, automotive grew like 60 plus percent.
I think IOT grew over 30% as well. Uh, and then mobile was, uh, was pretty great. And then a, I, PCs, actually, it's still too soon to tell, but we just conducted a really interesting study of the A IPC market specifically for the enterprise.
So we left out, uh, the long tail of small to medium sized businesses. We didn't look at, uh, consumer yet. We focused on, on enterprise first, and we pulled almost 900, um, it decision makers in the enterprise space.
So big, big, big companies to see, kind of like where they are with your A IPC adoption journey, uh, which processors they like the most, which one's they intent to buy for their, you know, the systems, like if they're gonna be powered by Intel, EMG, apple or, or Snapdragon, uh, which is Qualcomm's products. And we're already seeing that the, the intention, or at least I would say, um, when we ask all these IT dms, what their first choices so good for Intel, Intel is still number one still that could change in the future, but right now they're fine. Uh, number two was a MD just because it's index 86 systems, so it works really well.
But the enterprise, it's proven, uh, at, at best, they like it better than Intel. At worse, it's a really good backup, uh, in case Intel can't provide a part or there's a problem. Uh, but Snapdragon, which is a new entrant into the space that has only been around for six months already turned up 15%, um, of IDMs basically saying that that's their first choice.
That's how impressed they are with the ARM-based Qualcomm made Snapdragon X, um, a I PCs. And, and so all of that brings me to kinda like the bigger points and the bigger trends in the industry and why I am probably here. And it's that we're seeing an expansion of the AI ecosystem from cloud, right?
It used to be data center because you just, it requires so much power and, uh, uh, and processing power and GPUs and, and all of this, all these massive resources to be able to train these systems to collect the data, process the data, just do all the, the, the training and the inference. But what we're seeing is that there's, um, and in great part, thanks to Qualcomm, we've, we're being, we're, we're able now to move a lot of these AI workloads directly on device. So we're going from the cloud out to the edge, um, and whether it's an A IPC or a new smartphone, like, uh, Samsung's, uh, galaxy S 25 series, which we talked about, I think last time it was on, uh, that just launched, uh, a couple of weeks ago.
Um, the on-device capabilities for AI are so incredible that it's actually cheaper because you don't necessarily have to pay for subscriptions or, you know, tokens for, uh, for a cloud service to do that for you. Second, um, it's, it's, it's really great because, uh, there's, there's a immediacy of interactions, especially with agentic ai, as it, it sort of like embeds itself into our user experiences. When you're interacting by voice with an assistant or an agent, and you're asking them to do something, or you're asking 'em to answer a question, um, if your, your query doesn't have to go all the way through the pipes to, uh, a data center in the cloud, uh, where it's processed, and then like the answer comes back and has to come back through, you can have, you can have an immediate conversation with your, with your assistant on device that's gonna feel natural, that's gonna feel like you're in the same room with somebody without that delay.
Uh, there's some some security advantages too, to having, uh, those agents directly on the device as opposed to in cloud, less risk of interception. Uh, your data can remain secure. Even the training of, um, of, uh, of an agent over time with your preferences, the types of things that you ask when you ask them can stay on device inside of a firewall so that nobody has access to that.
So there are a lot of advantages to moving, um, these workloads, uh, to, to devices. And if you look at it more holistically, especially for the enterprise, the one of the advantages also is that you can have a more federated distributed AI ecosystem where you're not just dependent on cloud. Um, if you need to, you can even network a bunch of devices together to work on bigger problems that might be too big for one device only, but not necessarily requiring, um, you know, a, a, a cloud-based solution to run it.
So, um, you know, I, I think even, um, the, the warning shots that we got, uh, a week or two ago, I can't even remember how long it's been now with deep seek and the whole notion that we now have, um, AI models that can be trains on a, a fraction allegedly of the resources that we thought they could or they needed, uh, sort of plays into that. Like, you, you can, we still need the data centers. We still need to build them.
We still need the big GPUs. That doesn't change, but the, the trend towards smart devices being, um, a lot more capable of, of doing inference for sure, and eventually becoming better and better at training, uh, is gonna be kind of a game changer. And where it's, it's most important, I think, is in, uh, not just the PCs and, and, you know, other devices, but it's gonna be in the automotive sector.
And so for that, the, the two things that you need is you need, um, processors that are very good at, at doing AI workloads, right? So new, new processing units or, you know, GPUs that work really well in conjunction with the rest of the system, uh, is one piece of it. But where Qualcomm is, is especially good 'cause they have that part is they do it at low power.
And, uh, when you're looking at devices with, you know, small batteries, uh, or that have to process a lot of stuff, um, and you don't want 'em to overheat, you don't want 'em to need a lot of energy, it's really important for those systems of those processors to have extremely high output at very low power and be thermally efficient so that you don't need like massive fans to cool 'em in. And that's where, um, that's where Qualcomm excels. That's where they have an advantage.
So they kinda have the best of both worlds. Um, and the types of form factors that we're talking about from automotive all the way down to, you know, smart glasses, watches, phones, laptops, tablets, um, you have this sort of, you know, extremely advanced AI capability coupled with this very low power, uh, performance characteristic, uh, where essentially it's just like the best performance per what on the market. And, uh, and that's why Qualcomm's numbers look the way they do that diversification with the right type of product for those applications that work extremely well with AI workloads.
That's, that's kind of like the, the, the sort of cheat code or the cheat sheet to, uh, to Qualcomm's continued success. I think. Um, and you know, I, I don't for prognosticate, but I don't see a reason why, um, Qualcomm wouldn't continue to have really good quarters, and because they've diversified, should one of those areas sort of, you know, slow down a little bit.
Let's say the automotive sector slows down, uh, for a quarter or two, it doesn't really matter because they have all these others. They're also growing. So there's, there's this constant sort of hedge against, um, sort of market slowdowns in different categories and Qualcomms there, as opposed to having all their eggs in one basket like they used to.
Yeah, no, I, I, uh, fully concur with those insights, Olivier, and I'm gonna step out on the limb doing a bit of pro, uh, prognostication. And that is, um, when it comes to, um, uh, just a snapshot of the iot segment. And the reason, uh, why I'm doing that is because recently I was at the, uh, Zoho analyst event, and it's like, okay, Zoho, you know, they, they are a CRM specialist, you know, uh, uh, what does this have to do with IO ot?
Well, lo and behold, uh, just in September of 2024, Zoho decided to toss its hat into the IOT segment, uh, specifically, uh, pursuing, uh, market opportunities in areas such as, uh, smart buildings, uh mm-hmm. You know, manufacturing, uh, energy management and so forth. And, uh, they've done their homework, you know, their portfolio development strategy.
They realize, Hey, if we could incorporate these things with an overall CRM platform, that means, you know, extra revenue generation and so forth, paralleling Qualcomm's own overall, uh, what, what do you call revenue diversification strategy that is really, you know, making a huge difference for them. And I believe in 25, we're gonna see the IOT segment, uh, grow. Uh, you know, I would say not just an upward, uh, trajectory, but also robustly.
And a lot of this is, I think, related to, you know, the fact that snapdragons AI capable chip sets are delivering those low power capabilities that you pointed out, Olivier. And that could be, again, and a driver for, at at least industrial IO ot, uh, growth. And, uh, paralleling that is that they, I'm seeing the Qualcomm aware platform continue to gain traction because it's integrating these AI powered monitoring and location capabilities across some of the segments already touched on, such as, uh, you know, retail logistics, but also, you know, smart home applications.
And, you know, parallel in that as well is Qualcomm's on-prem appliance inference suite, which is, you know, helping enterprises with private AI deployment solutions. Something else that I think will have, you know, some, uh, market progress throughout 25 and beyond because of rising demand for wifi seven 5G FWA and really what could be, uh, called the e edge computing market, uh, which I think, um, will, uh, I think, um, be somewhat buffered from, you know, potential tariff, uh, outcomes, which could impact, say, the automotive segment more. Uh, but again, uh, if you're looking at, you know, the overall picture, these are positives for Qualcomm and this cross pollination, I think we're gonna see more of it CM vendors jumping to iot and so forth.
And, and so this, I think so too. This is good. I think, um, I think the, the industrial IO OT or what I, I prefer to call the commercial IO ot, uh, segment is, is probably going to see a resurgence this year.
Mm-hmm. Or at least start to, uh, it, it was kinda like, you know, an exciting thing, an exciting space for, for a minute, and then it just sort of fizzled out, just flattened out. Um, but now with low power AI capable cameras, I think that especially cameras and, uh, drones are, are going to be hot this year.
And what I'm seeing with Qualcomm, first of all, uh, at their, their, uh, analyst event in New York a few months ago, they spent way more time on the industrial IO OT than they normally, than they ever have, uh, and more so than they did, uh, even with, uh, with automotive. So obviously it's their Netflix push, um, but also what I'm seeing is a lot of services around it, a lot of orchestration, and, and I found that interesting. Um, so yes, I think you're on the right track with this.
I think that we need to watch the iot space, uh, because it's, uh, it's gonna get hot. And my, my question too is how much of that is, is wifi, how much of that is, uh, is 5G and, um, especially like private networks? And I think that there's, the verdict's still not out with that yet, but, uh, that's gonna be an interesting, uh, interesting, um, uh, ecosystem to watch, um, to see where it goes in the next couple of years.
But yeah, definitely, definitely keep an eye on the a o OT space. Yes. Yeah.
And, and to your point, Olivier, uh, Qualcomm made a splash, I believe that, uh, last fall's embedded world North America, the first time embedded world has come to, uh, north America, and that was last October in Austin. And so I think that is another indicator, like this space is getting momentum, you know, the, the major shows are now diversifying on a geo basis. And, and that is, I, I think proof positive, like follow the money.
They're, they're not doing it because it's fun. It's because, yes. Uh, revenue j well, Maybe a little bit, maybe a little bit, because it's fun, but yeah, Definitely.
It's a fun city. Yeah. Yeah.
It's, it's, it's more than a sushi and karaoke. There's also live music and barbecue, right. So, exactly.
And well, hey, this is great. I think, uh, this is, uh, really touching on the, the, uh, the key, uh, things that jumped at asset, but there's gonna be plenty more. We'll be back next week because we're getting closer to Mobile World Congress itself, and I think this next episode will focus more on, uh, what, uh, I think our NWC, uh, 25 specific, uh, pre announcements.
And so that, that, that will fill the cupboard. And again, thank you Olivier, uh, for joining. Uh, again, lots of, uh, I think great takeaways and conversation.
Yeah, thanks for having me again. Problem. Thanks for keeping inviting me.
Like I'll, I'll keep coming. Right on. Yeah, the invites will just keep, uh, flying out.
And, uh, also, uh, with that, uh, don't forget to tune into 5G Factor, you know, we're on, uh, the future and group, uh, website, bookmark us, uh, and also we're featured on Textron tv, also, you know, part of the future and group family. And, uh, with that, uh, again, thank you everyone and have a great 5G and industrial or commercial IOT day. Hi everyone, this is Axel Launa from Argentina, and I'm glad to be here with all of you in the DevOps experience, 2024.
Uh, I hope you like this talk. We are going to, to chat about platform engineering and finops that, uh, they are both, uh, two trending topics nowadays. Uh, so what we can start right now, uh, we'll start with finops.
Uh, it's a, a term we are using a lot nowadays. Um, and what this is about, well, finops is the practice of optimizing a cost in cloud, uh, without sacrificing speed, quality, or security, because, uh, it's pretty simple, uh, for anyone to, to cut costs, right? Uh, without considering these three points that are quite important for our applications, uh, without quality or security, uh, there's no chance to get an application to production.
So the challenge here is to maintain all of these three pillars, speed, quality, and security. And at the same time, uh, taking care of the, of the cost we are, uh, we are having in the cloud, right? Because sometimes we just move our applications, we, we modernize them, or we just migrate to the cloud, but we are considering cost.
And when the, the bill comes, it's like a shocking surprise, right? Uh, well, this practice, uh, has that, that intention to, to cut those costs that are unnecessary or maybe, uh, that comes with, uh, for example, um, resources that are not used properly or that oversized, uh, well, those things, and a lot more, uh, comes with, with finops and just to deep, uh, a little, uh, more into the framework that finops give us. It's like Scrum, for example, scrum, uh, give us like a, a framework like some, uh, guides.
Uh, it's not a recipe for success, but it's just a guideline to, to follow, uh, and to have like, uh, better practices and a good roadmap, uh, to, to transition this cloud cost optimization process. So the, the first time, it's, uh, it's very important to maximize, right? The, the business value in the organization, aligning those strategies that the business has with technology.
Most of the times, they, they are treated separately. Uh, so, uh, that, uh, brings like a, a lot of issues on arguing because business wants something, technology says another. Uh, so the, the, the first recommendation, the first guideline here is to work together to align strategies, right?
Uh, and to have like a smooth process involving everyone. Uh, we'll see that, uh, Phillips framework give us like, uh, a couple of roles that are suggested from each area and each, uh, specialty. Uh, so the, the point here is to work, uh, as a team from the start and aligning those strategies.
The other thing is, once we have those roles or those people, uh, into this process, uh, and this exercise, uh, we can incorporate processes, skills, and tools, uh, for both engineering finals and business teams, right? Uh, the, the idea is to give all of them different skills, processes, and tools to make the, the jump done, right? Um, we'll see, uh, in the couple of slides, um, some tool that we have to, to work with.
Uh, but if you enter to the finances, uh, that org, uh, page, you can see like, uh, a lot of suggestions, tools that are aligned with these practices. Uh, and select the, the best option for you, for your company, the, the one that is more suitable in the, in that specific time of, of your process, right? Uh, maybe one tool, it's useful in one particular time, but then, uh, a couple of months later, when you are like more mature in your process, you will need to replace it or to add some other, uh, into your pipeline.
So finally, the, the idea we were, uh, talking before is to, to work collaboratively, uh, and make data driven decisions. That's very important, uh, because sometimes, uh, this, this kind of process where business and technology argue because they don't know very well each other, and the, the discussion, uh, is about we don't need security, we don't need quality, we don't need this tool. Um, it's about feelings or sens sensations or, or, or maybe like it's, uh, like, uh, something that is not valuable for us in, in our point of view, but it is for the others.
So, uh, to avoid all those things, uh, it's important to have data-driven decisions and these tools that finops give us, uh, help in, in that way, right? We, we can also add a lot of more, uh, complex, uh, ideas, tools, and processes, but, uh, we can start small. Uh, that's an important thing, starting small, uh, but always having like a data driven decision process, right?
That, that's the, the ultimate thing, uh, as very important to start with in, in this process. Then the, the other thing we are gonna talk about, and it's like very related to its platform engineering. Uh, maybe you have, uh, came across with, with this term, maybe not.
Maybe you are just, uh, someone that's working in technology or business, and you start hearing about DevOps, DevOps, SRE, uh, platform engineering, cloud ops, master goal, all kind of terms, uh, right? Uh, so what is platform engineering about really? What's the difference between the other roads?
What, just to give like a, a quick idea, for example, let's say that, uh, we have three teams, uh, in, in the company, there are three squads, uh, software development, uh, teams or DevOps teams, uh, whatever you like. Uh, but the important thing here is that every team has its own process, its own tools, its own way to develop. So, uh, when you have, like, in this example, three teams, it's like more manageable.
Uh, it's easier, but if you think of that organization, of that structure in a larger company where you have like hundreds of teams, uh, it starts to, to become very hard to manage all those processes. And you have like the standardization issues. Uh, you have, you find it yourself like managing as like hundreds of tools, because one team uses, uh, AWS and GitLab, another uses Azure and GitHub, maybe some other GCP and Jenkins, and it's very hard to maintain standardized and ensure the quality and security in all teams, in all tools.
So, uh, that's where the platform engineering comes in, into the scene, right? Um, and what's the, the principle objective of, of this team well is to standardize those tools, those processes. It's like, uh, a center of excellence sometimes, uh, but the focus primary is to standardize tools and processes.
Uh, this, this team is in charge of selecting the, the toolkit, the processes, the frameworks that are gonna be used, and then, um, start helping teams to develop their own, for example, tools, scripts, templates, pipelines for their own teams. Uh, their work is about, uh, again, creating a platform where those resources are, and every team, it can be like a, a DevOps software engineer, uh, a quality engineer, uh, can go to that platform and, and use all those resources that they need for their squads, and also, uh, to personalize, to customize those resources and that process. Uh, there's a lot of feedback from the teams that the platform engineering team can absorb and how, like, uh, this, uh, continuous process of evolving this platform and the resources they give.
So at first, it, it can seem that it's like very hard. Uh, it's a lot of work to do. That involves a lot of, uh, teams, a lot of processes and areas that have to, and, uh, in this moment, I would like to, to share, uh, our experience with, with my team, um, in fact, um, this is, this example is about starting small, right?
Uh, because it's the, the first steps are the, the harder to take and the ones that, um, are, is harder for us, uh, to step into, right? And so we started, as we can see, uh, in this small video, we created this for a Latin American client. This, uh, like platform may say, uh, we have a, a ripple, uh, a repository of call where we started like this, uh, platform where all resources are, we have like templates for pipelines, for building blocks for Terraform.
Uh, we have scripts, we have guidelines for Docker, Kubernetes, we have all that kind of things. So every team can go to that ripple, plan it, and use it for their own good in the team that are working. Again, the idea here is to start small, because there was nothing to start with.
It was, we are a like, uh, in, uh, in, in zero. So, uh, the idea of starting with a big platform with a, a big budget, it was, uh, like very hard, and it wasn't an option at that moment. So, uh, our idea was, well, let's start small.
Let's start with something. Um, and well, this is, was, uh, this was our, our first approach to, to this platform. We can see that of code here, that, that we have it.
Uh, and this particularly is a tool that we start with sales in using, uh, it's called infra Cost. The idea of this tool that is recommended by the finops organization also, um, the idea is to know in every, deploy the cost of our infrastructure, right? Um, and what's the, the, the good point here.
When we, um, integrate this tool into our pipeline of continuous integration and deployment, um, we are making every person in the team responsible for taking care of the infrastructure costs, right? Uh, the idea is to not wait until the, the end of the process to gain, uh, these, uh, fins team and tell us, uh, hey, the, the costs are going up, what's happening? Uh, we don't want to wait until that point.
So we took our, uh, our possibilities discussed with, with the whole team, uh, and our first approach was, okay, let's deploy this infra cost, uh, tool. So in each pr, in each poll request that we made, uh, this pipeline runs previously just to check the differences in the, in, in the infrastructure that there will be with Docker, with Kubernetes, uh, it will see the, the manifest and the differences, and, uh, it will calculate the cost that we have and the differences between this new version that we're going to deploy and the previous one that it's been deployed. Uh, lastly, so when a person comes to this pool request can also see as a comment the differences in cost that infrastructure will have.
So, uh, the team can see at, at firsthand the, the differences, the difference in, in cost, and decide in that very moment if it's going to accept the poor request or not, if the differences in cost is aligned with strategy with the objective in the sprint or not. So in, in that very moment, in that point of time in the development process, we can know exactly how much will cost the infrastructure of our application. Uh, that's been a, a, like, uh, a great impact for us because, uh, there was, uh, like a small amount of people that, uh, that have that information that, uh, we, we were in a, in a passive situation, uh, where we deployed our infrastructure or our application, and we started, uh, and we prayed, uh, not to have like, uh, uh, someone telling us that our, uh, RVs were too high.
So we, we wanted to, to go from that passing situation to an active one and deploying, uh, this tool that it's, uh, open source. Uh, it was, uh, a great, uh, a great, uh, start for us to, to change the dynamic we were having. Uh, and this was, this is a, a very good example of how we, we make the whole team responsible for the cost, and not just only like a few people in the organization, we have to work together as the rob say, you build it, you run it, you are responsible for your own, uh, for your own application.
So, uh, that's, uh, a very, a very good point, uh, at this, at this situation, right? Um, well, here is like the, a little demo as you have been watching, of how we we deploy, uh, this changes with, with Docker, with Kubernetes. Um, well, uh, that's a, a, a small example of what we have done with this tool.
Um, as a bonus track also, um, maybe we, we always think as finops as just looking at the, at the bill and reduce costs and talking with people about what we are gonna, uh, reduce or, or to remove. Uh, and sometimes also with platform engineering, we just think about, uh, an internal development tool or platform. Um, but there's space for a lot of ideas, a lot of practices that help us, uh, uh, in this direction.
One of, one of these tools is the chaos engineering practice or philosophy. Um, chaos Engineering is, is a discipline, uh, of running intentional experiments on, on our system or our application. Uh, and, and the point is to inject a precise and measure damages on our application infrastructure.
The idea is to, uh, to measure the silence of our application and system and how it responds to different situations. For example, how can we connect this? Will are talk about, uh, fine apps and platform engineering, for example.
Um, one thing that we can experiment is the, the size of our resources in the cloud. Maybe some couple of resources are too big and they are too expensive. Uh, and we have this doubt that what happens if we shrink it, we, we make it smaller.
We change the, uh, the dimensions. Uh, what can happen if that, uh, thing is done Well, this practice, uh, can give us those, uh, experiment spaces and, um, those, uh, those, uh, metrics, for example, uh, we can test, uh, the, how the, the system responds, uh, how the, the request, the volume is managed with those different, uh, sizes. Uh, so it connects directly between the chaos engineering experiments and this kind of, uh, intention of reducing cost, and always, as we said, uh, keeping in mind security quality and speed.
Uh, so, uh, to sum up, it, it aims to, to help us improving our systems, uh, knowing with experiences with technical and objective experiences, how they respond, uh, with different types of failures. Uh, what happens if we inject, uh, latency in the network, how we reduce resources. We, uh, we can, uh, remove some parts of the application maybe that we, we don't need really, uh, and give us space to, to play, uh, a lot following like the A method, right?
And, uh, dipping into the, the cough thing, uh, chaos engineering always, uh, keep us in mind the cost of down times, right? Um, there's, uh, an equation, the formula to know the cost of our downtimes, and it's basically composed of three parts. Uh, the ones that happens during the interruption of the service with the, the lost revenue and the productivity of the people because they are developing something new, something nice virtual for our application, and they have to stop that work just to, uh, extinguish a fire, right?
Uh, so that's, uh, another big loss we have for, for the business. After the interruption, once we, once we are running again, we are productive. Uh, we have client charges, for example, for SOA regulations, service develop agreements that are not fulfilled.
We have another big cost there, and some others that are not ally measurable. For example, the brand defamation. Uh, for example, if we are like a silver Monday, black Friday, uh, are, we enter 20 commerce to buy like that PlayStation five, I, I really want, uh, imagine that I will click on the buy button and it doesn't respond, and I have then a 4 0 4 error.
I will be like pressed and I'm going to another eCommerce site, and I will buy it happily. So next time, I'm not going to buy it to, to the, to the first site. Uh, I'm going to, to the second one.
So, uh, that's not easily vegetable, but that's, uh, a, a cost that implies the downtimes and not being prepared, or maybe focusing too much in the cost reduction and not thinking in quality security speed. Uh, so, uh, just to, to have like a, a, a clear number in, in head, uh, for each hour of downtime, a typical company loses $3,000, $300,000 per hour. Amazon, for example, per hour losses like $13 million.
So, uh, what's the point here again, uh, is always focusing in cost and in quality. We have to balance those things to reduce RBLs, but always having in mind the application, right? So again, it has to be like a synchronized work between business and technology, some tools to practice chaos engineering, uh, some of them that are very famous like rambling.
It's a, it's a great platform. Uh, it has, uh, a lot of, uh, certifications, free certifications and trainings that I recommend. I have done them all.
Uh, I like it very much. Uh, I started with chaos engineering because of rambling, so I recommend it. Uh, it's a paid, uh, software, but it really, um, gives value to that cost.
Uh, on the other hand, we have some other tools that are open source lead most, for example, it's a great tool, uh, that I adore. Um, some others are more famous like Case Monkey with Netflix. Um, and obviously, uh, cloud providers offers their own tools, uh, AWS Azure, uh, have their own.
So those are also great options to start with chaos engineering. But as I said before, uh, if you think that this is a, a good tool, uh, to start experimenting, uh, Grambling has a lot of documentation, very nicely, very well organized. So, uh, it's a good start to, to read, uh, how to start doing case engineering again, uh, from scratch with small steps.
I know, uh, we are running out of time. Uh, it's time to, to wrap up. So the, the key here is, uh, again, to align business with technology, right?
Uh, it's very important, uh, to do that as we have seen with examples and the impact both on the applications and the business if we have downtimes, for example. Um, and then lastly, uh, to be financially efficient. Uh, since the moment of the, the design and the development of the solution, uh, it's like a very good practice to ship left, uh, everything we can.
So it's cheaper, it's easier for a valve to, to have that in line, um, just to, to have a, a nice closure. Um, there's a, this, uh, this code I like very much that we're nothing certain, everything's possible. So, uh, when we have these, uh, new practices, new frameworks, and we don't, uh, we don't have clear or, or we're not certain of, of the next steps, uh, the good thing is everything's possible.
Just, uh, you have to challenge yourself and challenge others, uh, to start practicing, to get into, uh, new tools and develop, uh, new ways, uh, to, to create, uh, value to, to the business, to the people. Um, I hope this, this talk has been, uh, interesting for you. Uh, anyone who wants to keep talking about this can, uh, reach me a LinkedIn in Instagram.
There's the, the cure, uh, to, to have my, my contact. So, uh, that's it. Uh, thank you very much.
I hope you are enjoying the dev experience 2024 and until next time. So is it AI America first, or AI America alone? You're watching Textron.
Hey everyone, it's Alan Shimo. Happy Thursday. We've got a great text on gang for you today.
We've got some, actually, you wanna know the truth. This might be the most important text on gang we've done ever. We've got some really important issues that I think you need to know about it, you need to weigh in on, meaning you the public, because this is not a time for, what was the, what is it?
Summer Patriots or Summer Soldiers? Mike, what, what's common sense say? I, I think it is.
Um, I'm not sure, but I'll just call it fair Weather Friends. How's that? Okay.
This is not a time to sit on the sidelines and hope things work out. I think every one of us needs to speak up and make out our feelings and wishes known. Um, we're gonna discuss these things.
I've got some great people who I know are not shy about giving us their opinions. Let me introduce you to them. First of all, uh, well, let's not go out to sea first.
We'll go down to Houston to Texas first, and we'll introduce Ann Ahoward, who's one of our regular gang members and is never short of an opinion. Hi Ann. Welcome.
Hi, great to have you on today. Always a pleasure. Thanks for Having me.
Absolutely. From Anne, I think we're going to go out and get sort of the royal view of this from our man in Silicon Valley, John Swartz. Hey, John, how are you?
Hey. Hi Ellen. Hi everybody.
I have plenty of opinions about these segments, so good to be with you. I'm looking forward to hearing them. John, don't hold back.
Speaking of, hold back, here's a man. He tries to be politically correct sometimes as he's navigating the seven Cs, or at least the Keys of Florida. He's our cyber expert or, or just, you know, life expert.
He's been, he's been around the block a few times. Chris Blas. Hey, Chris, welcome.
It's great to have you on. Good to be here. I am in, uh, as you say, I'm actually in what you would say is Key West, you know, but to the point of our conversations today, I am actually in the channels Bo, the Boca Chica channel, the Boca Chica Naval Air Station is right here.
You know, where there are all sorts of interesting jets. We'll be flying all day long. And as you look at strategy, national security, you know that that military base will never shut down.
You know, look at its location, look at the strategic importance of it and what they do there, you know, is topic for other conversations, speaks to our topics of the complexity ne necessary to actually have effective national security. Absolutely, thank you. And then last but not least, the sage of Harrison, our chief content officer, Mike Huard.
Hey, Mike, welcome. You know, I couldn't agree more with you about the importance of today. It's a seminal moment.
Pitchers and catchers have reported for spring training, and it's crucial to this country. I wish you have Your priorities Right, admire, I, I wish admire that. Admire, I wish life was that simple.
I wish life was that simple. Anyway, so guys, let's, let's jump into our first block Monkey. You're gonna kick off for us, but you know, I, I gotta tell you, watching the news yesterday, you know, I, everything I need to know, I learned from three or four movies in my life, the Godfather, Goodfellas, star Trek, and Star Wars.
They kind of are my, those are my true Norths hearing everything that was going on yesterday, I was reminded of the Eugenics Wars. Now, I don't know how many of you know the significance of the Eugenics wars in Star Trek, but as a result that, you know, humanity learned to do genetic manipulation and created so-called Super Met, and one of those guys was a guy named Kahan, who was in the original Star Trek series. And then of course, in the movie, the Wrt of Kahan.
And, uh, Ricardo Manto, of course played Ka. I'm re I'm reminded of this in what's going on in ai. We, we are on the verge of AI wars, right?
With every, everybody here, uh, staking their claim. No one, you know, no one pledging the work together, per se. Everybody wants to do their thing.
And, you know, risk be damned full speed ahead that don't mind the torpedoes. Um, you know, and, and over this, we're in some sort of new imperialistic. We thought the neocons were bad.
We're in some new imperialistic moment here where everybody wants to go carve out their empire, and AI happens to be the, the new world that they're carving. So, Mike, I, I gave my 2 cents. I'll let you introduce it from there.
Let, Let's let John bring everybody up to speed about who did what to whom. And, um, you know, it seems to me, John, at least that, you know, the vice president was in Europe and forgot his copy, how to make friends and influence people. So Yeah, he played, he played right into his role.
Um, he, he keeps, he spoke. I mean, his message was completely at odds with what every, everyone else was thinking there. But yeah, my head was on a swivel like the rest of you yesterday from the news cycle.
I mean, what Alan said it very well, what we have here is this AI land grab on a worldwide stage. Torpedoes be damned. I mean, just go full speed ahead.
There, literally, almost simultaneously, you had actions going on in three different continents. First, as you mentioned, JD Vance was at this AI summit in Paris, and he talked about America first in terms of ai. He claimed our, our continued dominance, and he's pressed the European nations to back off.
He called it excessive regulation that could kill a transformative industry just as it's taking off. As soon as he finished saying that, before he even finished saying that, we already had news that the French President Macron had placed $112 billion of private investment in the coming years to accelerate AI developments late Tuesday. This is really, it's hard to keep track of this.
The EU announced an invest AI about basically a $210 billion initiative that includes a new European fund of about 21 billion for AI gigafactories, and then not to be left out. Apple, which has kind of been lost in all the shuffle with the machinations going on, is finalizing plans for an AI push in China via a partnership with Alibaba. This is what, uh, apple did.
They went through several different companies. They talked ba deep seek by dance, Tencent before, uh, settling on Alibaba. And they're doing this because the iPhone sales in China are suffering because they lack ai.
Features that their competitors have. So there's this whole machination of, of people jumping into this, this area, kind of independent of one another. You know, the one thing that I do wanna mention also about Macron is he compared their project to Stargate, which kind of, in a sense, was one of the things Van was, was flaunting this, this, this alleged $500 billion project between Oracle, OpenAI, SoftBank, and the government, uh, to build on our, uh, infrastructure.
And then we'll see how that pans out. But it's, it's, it's, it's crazy. I mean, it is literally, we have various world leaders all grabbing for this, this, this industry.
And it's gonna, it's not gonna, it's not gonna end. It's just gonna continue to accelerate. I, I absolutely agree, John, and you definitely summarized that very well, minus the Elon and, uh, open, open battle.
But I would say it's not a surprise that Europe wants strict rules. That's nothing new, that's nothing new. And China pushes state backed ai also nothing new.
What I did not expect was the US to not sign a global AI responsibility pledge that China did. That kind of threw me, I mean, I knew the speech was gonna be what it was, but, oh my God. So, concerns about AI's, dangers, warfare, those all were raised, but we sort of just glossed over it because, you know, we're powering it out.
We're America. Yeah. Like, it, it just was okay, I guess this is how it's gonna be now.
I was shocking. I thought it was interesting that the vice president told them they have a choice between either partnering with America or totalitarian organization country that's making AI models. And I'm pretty sure the Europeans are trying to figure out exactly who he is talking about.
I, I don't disagree with you. It, it is a, it's a sad day, a sad frigging day to have an American Vice President in France, nonetheless, at a country where our soldiers gave their lives to defend, not once, twice. And we made the world what it is and what it's been over the last century, not by going it alone, but by recognizing who your friends and, and natural allies are.
World and not one shot. China. China made a pledge that we refuse to like about responsibility like that It is clear in this imperial presidency, right?
This is, this is akin to making a play for the suit inland, right? In 1932, they have Czechoslovakia and he called it the Suitland, and they took that into part of Germany. We're doing it in Greenland.
You know, it's also, it's also that this, instead of America first, it should be America alone. Alone. Not just, it's not America first.
It's America. And America alone in today's world will never succeed at that. We can't, you are throwing out Canada our best.
Figure out France for a second. Our best ally, the only trading partner that we actually have a surplus with. And you're throwing them under the bus too.
Do you think they're gonna wanna do business with us? This is not make friends and influence people. This is, this is, this is a, a page out of the Nazi party.
I'm, I'm sorry, this is a suit and land kind of thing. Chris, I see your heads, your hands up. Yeah.
You, since we in fact, do not have anyone on, you know, argue to the side, because frankly, I agree with you all. However, you know, let, let, let's acknowledge it and talk to it. Right.
You know, this is the way we hack systems. You know, we look at the way they are, whatever, right or wrong, and figure out how they're working. So, you know, I'm absolutely not shocked.
I mean, that is exactly what we expect of this particular administration. Both, you know, for two reasons. None of the first, uh, everybody's sort of acknowledging is just to tick all you off.
You know, the, the, the chaos and the, and, you know, keeping the heat and the world wrestling, uh, you know, heat, good, bad. I love you, I hate you, whatever. You always play to that.
So that's a big part of it, and which is a dumb idea. Um, but the, you know, the argument that yeah, sometimes you, you need to rush ahead, right? You know, and I do this literally every day with boats and business and everything else.
You know, sometimes it's time to say, you know what, we just need to go take that, do that land grab thing. Um, how you can tell, Lemme let me, let me, Chris, let me stop you a second. There's a big difference between you taking a risk with your boat or in your business versus betting the future of the human race on, on AI safeguards.
Well, I, let, let me, let me, y you know, I, you're talking about a call. Lemme, lemme just, lemme answer. Yeah, absolutely.
Right. But I, I do hear in my own small way, you know, having inputted on those things. But, you know, my, my point is, the way, you know whether that's a good time, whether it's a good time to take the risk to go forward, is understanding the, the strategic landscape.
I do not believe that this is a good time to do this. You know, the risks of AI are what they are, right? We know them.
And in the, you know, we're talking about the Bruce Bruce Schneider article, uh, um, yesterday, you know, talking about the risks this administration is taking with the critical infrastructure information that all of us for decades have been working on protecting, you know, as being, as being, being savage, being handled very, very poorly. You know, no, no positives anybody can say about that. And we're also taking these risks.
So we're compiling risks. So is this individual, you know, high risk bet to go it alone on AI with no regulations, you know, the wrong one. Even if it's not, we're doing so many other things wrong at the same time.
You know, we're compounding risks and we're setting ourselves up for consequences that become unpredictable and hard to control. That's the problem. You know, I, I think we make our ourselves look weak to quote one of the great artists of our time, Jay-Z, the strong move, quiet the weak start riots.
We just made ourselves look like fools. I mean, we really did. I, yes.
The, the, the geopolitical, yes. That I, you know, dunno where to start, right? So, Yeah, I, I feel like we got Is it Any, is it any surprise that what what Vance said, though?
I mean, literally, he said it days after, uh, Trump issued one of his hundreds of executive orders where he overturned a Biden executive order about AI safety and responsible use. I mean, it was, it was telegraphed. He, he, and he and JD Vance kind of enjoys the black hat.
I mean, that's what he does. Plus I think that we, I think he's getting whispers or nice, nice encouragement from big tech in terms of pushing back on regulation in Europe, which has always been a problem for these, for these companies, especially Apple. So, Let's not make Apple the only bad guy here.
No, I'm, I'm saying, I'm, I say big Tech. I mean, oh, big tech pushes back on there. I, including Google, including, and Twitter, you know.
But, you know, Chris made a reference to a thing about Bruce Schneider, actually, it was Bruce Schneider and Davy Meyer, who, I don't know if you know Davey Chris, but Davy's brilliant. And he is a real dude, right? Penguin blog.
I, he's been in the security bloggers now for 20 years. I know Davey. Now what they said is, what's going on with Doug is creating unbelievable cyber risks that our adversaries are gonna exploit for short are exploiting.
Now, I probably already, so, yes. But, but really it's the symptom of the same disease. They don't give a s**t about risk.
They don't care about risk. They've made it very clear. We don't want Europe regulating risk be damned.
We're gonna beat the Chinese. We are the new American imperium. We're gonna win the eugenics war instead of Kahan, we have Musk.
Okay, well, this Thriving on chaos, it's Described on chaos. This, this is a return to imperial times. We want an American outpost in Gaza.
We want the canal right near that Gulf of America. We want the red, white, and blue land. There's moron in Congress, introduced the thing, and we're gonna win the next new world ai.
So say, John, John, you're in the valley. How are those companies gonna spin this storyline? Because essentially, to Alan's point, they're all saying, we're against responsible usage of AI because of we're worried about regulations.
So therefore, leave us alone. That's an untenable position to be in long term. So how isnt an Nvidia and Apple and Google and all these other people gonna come around on a storyline?
It doesn't make them look like they are completely off the charts. I don't, I don't think they can spin it in any way, shape, or form. I, I, I, I say I sense here, even in their backyard.
I mean, the employees of these companies are upset about what's happening with their companies, uh, the, uh, the people who are not in tech. And that's a vast, vast majority of the people in this area. Look upon tech at the villain, the evil empire.
They're in cahoots. They're part of the oligarchy. Um, they Are the Oligarchs.
They're the amount of coverage, the amount of coverage here, uh, that's negative about tech is palpable. And I think it's well deserved. And I, these, these guys have gone through this, these guys play every side.
They, they're, they're, they're almost soulless. You know, when, when Obama was in power, they all cozied up to him. They all sat around him and vowed to him with Obi, with Biden, not so much with Trump.
You just see them shifting with the wind. I mean, just, I, I can't get outta my head. The, uh, the, the inauguration and, and these guys blanked on the stage over his shoulder, all on one side, all on the Republican side, laughing, nodding, trying to look serious or solemn.
I mean, to me it was just, that's a picture that they will never erase that start to history Books. No, sir. And let me tell you the hypocrisy of this.
You mentioned the, the musk Mike, you mentioned the Musk group bidding 97 whatever, billion dollars for open ai. They're not bidding for chat. GPT, they're bidding for the open for the not-for-profit open ai.
Because the group says going for profits is now not good under the America first thing. It goes against their charter. They wanna return open AI to its good, uh, original founding, which was to do good for people and make AI safe for everyone.
They talk out of this mouth here. And then JD dance talks here. That's called bull.
This is out of Orwell. This is f*****g out of Orwell truth. Speak face.
Call it what it is. Stop being, I'm not gonna be complacent and watch this go down. This is Orwell troops speak.
People Wanted OpenAI to go be moved for profits. He was one of the people who was behind that idea until they, they decided they didn't want him to run the company. And he left, of course.
So he has offense. It's another case of hypocritical nonsense. Hypocritical nonsense.
Anybody wanna say anything else? I'm not done. I mean, you're assu, you're assuming to be a hypocrite.
You, you would have to think about you're your implications of things. There's an empathy required there that's non-existent. Not, I mean, we're just, we're just playing it as we go.
No, right? I, I Shenanigan. So I don't think they're dumb chaos.
I don't think they're dumb. They're very smart. Elon Musk knows exactly what he is doing, and he says whatever he needs to say to get it done.
So does Trump. And so that's that whole, well, Assuming as assuming you're a company and you're building an AI app and you're not comfortable with the, the lack of governance, what should organizations really be doing about all this to kind of be responsible and kind of, you know, if they're inclined to do the right thing, then what should, what is the right thing? You know, the right thing.
First of all, the right thing should be apparent if you really are inclined to do the right thing. The right thing is respect people's ip, respect people's information, respect what the repercussions of your acts are. The right thing is never changed, right?
You know what I mean? The true north is true north, Right? For me, it's dis disclosures.
I, I have it in my contracts as of this year. If I use AI tools, I will disclose that I've used them because I'm not gonna pass off human time and labor out of retainers. Uh, that, that's not, That's the right thing.
That, that was what I felt was a way to signal to clients on bringing in these tools. But I'm also gonna tell you, because no one likes feeling tricked. No one likes feeling off.
What? So that was an easy way for me to just let them know, Hey, we're gonna use these tools, but we're gonna tell you. And every single client excited about it because they feel like they're a part of it.
Because they are Guys. We're talking about an administration that just suspended prosecution of a war, prohibiting, bribing foreign officials. Okay?
You want to talk about the right thing, about morals, about the 10 commandments, about religious Christianity, or whatever your religion is. I don't know of a, of a religion other than the faren maybe that allow for the bribing of officials. What do we, are you proud to stand up today and say, count me in with them?
Because it's not all I, I'm actively renewing, I'm renewing my Canadian passport, so, sure, Go Chris. Yeah, I'm gonna shut I, you know, rather, and again, rather than just ditto heading, you know, because I, you know, I, I agree with what everybody's saying. You know, in any adversarial situation, you need to understand the lay of the land, right?
And right now, you know, we, you know, everybody arguing from our side is, is losing our losing, right? Why? Well, because we're getting suckered in, into fighting the wrong battles and spending our energy ineffectively, and not actually, you know, the results are obvious.
That's just pragmatically fundamentally true, right? Globally, this is not just a US problem. And really, when you break it all down, you can look at as policy hacking, right?
And, and what's going on right now in the US administration as a perfect example, right? And the actors, Trump himself has made a lifetime out of policy hacking, where you just break all the laws all the time, and you know how the laws and the policy works. And it's not just what's written down.
Do this, don't do that. It's knowing that if you do this, you know, nine times outta 10, you get away from it, away with it. The 10th time, you can delay it.
You can delay it so long, that situation will change. You never have to deal with it. Someone didn't, you know, got convicted and didn't, you know, suffer penalties in the last couple of months.
Exactly like that. Amazing timing for that one. So this is all a combination of standard conflict, right?
Oligarchs sucking up to whoever's in power. Terry prt, you know, writes that into stories all the time. This is happening forever, right?
We had policies and systems to prevent that, or limit that they've been eroded for the last 40 years. We Need our court to put a break on this. Look, the mayor of New York was, was indicted.
The mayor of New York was indicted. And this administration ordered the Justice Department to stop the prosecution. 'cause we need him to enforce the administration's immigration laws in New York.
If that's not corruption with the biggest capital C I've ever heard, what is it? What is, have we announced it? Are we no longer a country of laws?
'cause if we're not a country of laws, what are we? I was scratching my head about that one. 'cause I was just trying to figure out what the other hundreds of thousands of people who work for the city of New York are doing, I guess.
'cause they can't do anything without the mayor. Come on. This is guys, I feel like I woke up and back to the future.
3:00 AM Biff is in charge. Okay? That's what we're dealing with here.
That's what we're, it's Biff world. And, and this is why I say you can't be complacent. Shake your head and say, we gotta hack this.
You've gotta be an activist. And if that means going to file lawsuits, if that means campaigning against it, you, there's gonna come a point in history where they're going to ask what side were you on? What side of the divide were you on?
When Moses comes down with the tablets, what side were you on? Do you wanna be, I was quiet. I don't, I won't, To be really clear, I'm not talking complacency.
I'm talking effectiveness. You know, when you fight, stay calms the ocean and watch what's going on behind your shoulder. Right?
Remember, war is not the place for deep emotion, and you might get to be a little older, right? This is important stuff. We need to spend our time winning these wars.
And I, and again, I'm speaking globally, this problem is we have global policies that have eroded and they're being exploited and they're being hacked. Yes. You know, laws, we have a president right now who will break the law, you know, every five minutes knowing that the consequence, even though the policies and the processes there won't actually get back to 'em.
So we need to fix those processes. And, and again, I think in these information technology world, in the cybersecurity world, there are hints of the kind of systems that may help us do that. But this is still, you know, this is conflict.
Individuals need to work. I would just, I would just say that, you know, your wallet needs to follow your principles. And all too often we see people standing on soapboxes saying stuff, and then they don't actually follow that up by looking at who they're doing business with and what contracts and who's supporting what these things now need.
A, a, a different weight means to be added to the calculus of who you're doing business. Agreed. All right.
We've exceeded, we've exceeded our 15 minutes on this one, guys. Um, we're gonna have to take a break here on Textron Gang. We're gonna come back and we, let's talk a little bit about security.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Alright, folks, we're back and we're talking about AI and security, as Alan alluded to, and it's a continuing conversation. We talked about this whole deep seek AI thing ad nauseum at this point, but it seems like there are other providers out there like Anthropic who are offering, uh, yeah. Money for people who can crack their AI safety and cybersecurity capabilities.
And I can't help but wonder, Chris, have we shifted a gear here without really noticing it too hard, but is security now becoming like a preeminent feature of these AI models and people are gonna start making choices based on security before the fact rather than trying to fix it after the fact? Yeah. In short, yes.
Right. You know, this is, as we're talking about in the last block, you know, sometimes it is the right time to just rush ahead and see what happens. And sometimes it's not right.
And for lots of reasons, not just, you know, the, the current trend of ai, uh, security has been building itself into the requirement list of things for a long time. You know, this one, and again, you know, as you know, this holds up in the last block. This one's scary enough that people, to your point, I think consumers are taking it more seriously than usual.
And to the point of a couple of the articles, you know, in today's, uh, uh, reference material is starting to become an evolutionary thing. The nutrient gradient goes towards systems that aren't gonna freak out your customers, right? And this is the literal, you know, Mary Shelley Frankenstein story that we've all lived and breeze Skynet.
And, you know, how do I get comfortable with spending X amount of dollars when I know I have, I have choices. And one freaks me out more than the other one, right? Because they're going to go, they're gonna get challenges.
They're gonna go through tests, they're gonna fail it, they're gonna fail horribly. You don't, if I was, if that was my main purpose, you know, the main hat I'm wearing commercially these days, I don't want to be that brand, right? So I think security, I have some hopes, again, you know, that's, you know, my normal optimistic view of things.
But I think the drivers are there a little better for this than a lot of things. So, you know, I said this before, I'll say it again. Vendors build security and when their customer's demanding and not a second before, and the Better your beforehand just go outta business, Right?
Not a second before, right? Now, the issue here is what customers are demanding. It used to be that in some way the government was a big stick, right?
Because when the government demanded safe cloud, they did GovCloud. When the government got worried about financial data, there was Graham Leach Bliley. When the government, right, or the EU government, GDPR and AI regulations JD Vance be damned, they consider it their job to be that big stick in terms of cybersecurity regulations.
Um, now we can't count on government necessarily to be that big stick. So who becomes the big stick? Is it the PCI council, right, which was behind the whole PCI standards, which drove so much security 10 years ago.
Or is it the cyber insurance companies who won't give you insurance if you're not, you know, using secure tools. Someone has to come in here right as the big stick to help the individual consumer because it's, in today's world to get individual consumers, or even like the huge, what was it, six or 7 million SMB businesses in the world to go like a school of fish or a flock of birds in one direction is difficult. You, you need, you need the sheep dogs, if you will, to, to hurt 'em.
And I think that's, we have to see who emerges. I think the EU will be one of them. We'll, we'll see what else pops up?
You know, I did an interview with my friend Qualis Dip di, uh, Dipo, I forgot his last name. Bai, Dilip Bai, uh, SVP of, uh, Qualis. They did the scan on, on deep seek.
They turned up all kinds of security issues, all kinds of security issues, security issues. Um, I'm glad to see philanthropic taking the lead with this jailbreak challenge, right? Because they obviously something you know, well, That, that Something's telling them that people care.
Yeah. Sorry, sorry Alan. No go.
This plays really well into way philanthropic has done and, and basically it's kind of this depth move of this chaos need for speed, bigger and better models. Anthropic decides, you know, this is what we stand for. This, this is why we are not like open AI or deep seek.
And I, I, I give them, I give them kudos and at least bringing this topic up because deep in the recesses of my mind, I keep thinking that we are hurdling eventually towards some major breach that involves ai. And it's, it's gonna happen. And it's gonna be interesting to see how all the parties involved to rush things, how they're gonna handle that, or how they're gonna pivot from it to use parlance out here.
I mean, You, you hope it works out well for, and, and I'd like to get your opinion on this thing. I saw, I was talking to this other company and I happened to dinner, look at some of the contracts they created, and they actually had language in there that says, thou shalt not take our data and expose it to any LLM. And it was interesting that they were using a legal case now, basically to say, we do not give you permission to use our data even so much as to write some sort of marketing collateral type of thing, because we don't know where that data's gonna wind up.
And you must sign this, and if you violate it, we will sue you into oblivion. So it is an illegal Argument. It's in, it's a, it's a legal argument until someone signs an executive order that says those are no longer enforceable.
And then you gotta get a court who's gonna come up and have the, the cone to say, yes, it is. You know, I get it. We're, we're having a dark moment, but the fact that we're all able to freely discuss this without fear of ion, so there we're penalty or getting dragged to jail, like getting our tissue typed, uh, like China does, uh, we're free, we're free to discuss it.
And I think if we continue the discourse that, that all of us will eventually come to light. We have a free press, we have a lot of things that we shouldn't forget that we have, that we have going in our favor, there's nothing that's gonna take that away from us. Um, I, I, I just can't, I can't believe that I, I don't believe that they will win in that.
But, but to your point, I do get asked. So I did a segment on a BBC Sacramento yesterday about deeps seek, and I was asked, um, is it okay to use deep seek? Is it safe?
And I said, well, I would just assume, like I wouldn't a search engine that anything you you type in there is, is it's gonna be revealed if, if it's gonna be revealed. The fact that there have been so many governmental agencies banning deep seek, uh, for security vulnerabilities tells you that right there, I mean, if this is a preemptive thing, but I do think we're gonna start seeing LLMs called out in more contracts. I think we're gonna start seeing that because people have to protect their information.
And it's been a wild west situation, but I think it's gonna be dealt with on a private level. I, I can't see any legislation coming out of this administration, uh, protecting anyone's data. Well, I, I, I agree and I think that, you know, contract language, you know, I'm always trying to look at things that just have to be done.
And, you know, the supply chain world that I've been focusing on for, for in recent years absolutely requires at certain points in the, in the predictable future, certain things to happen and contract language becoming code, you know, actual code that operates in real time, like software has to be part of that. I have to know that I don't call my legal people or send an email to have a human read, a contract to find if there's a clause that disallowed my data to be exposed to an LLMI need as my data is being handled, the, the policies is being handled in to be transparent to the systems. And in certain hypercritical, you know, high value infrastructures, I expect that to be technically implemented in the next several years.
We're not talking a long time. The parts are all there at this point. Like any emerge area, it just requires an area where the cost is worth doing it.
But then again, the savings in all the other don't have reward. The rewards have have to justify the cost, right? Is the bottom line.
Wait, Wait. And they will, We already have compliances code. So contractors code is not far off.
So I think Chris is spot off. Hey, we gotta take a break. We're gonna come back.
We've got one more segment for you today. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. And finally, in the C Block, we're returning to some of our favorite DevOps conversations, or in this case DevSecOps, but, uh, harness Merge.
Were Traceable. Traceable is a provider of an API security platform that happened to be created by the same team that runs Harness. So they all came out on the same labs, but there's been this ongoing debate about whether or not API security is a standalone category.
Is it just part of a larger DevSecOps platform, or it's just another artifact just about everybody who had made an API security platform came out with a statement in the last three days saying API security is still a standalone thing. Alan, I know you've been kind of following this as long as I have. What's your quick Take?
Sure. So, so just real quickly, as you mentioned this, this is a merger of Kissing Cousins, right? Uh, Jody Bonzai was the founder of both Harness and, uh, traceable.
He was the founder of AppDynamics and his, I forget the name of the labs as his funding accelerator unimaginable on something, um, was the initial money into both companies. Of course, harness is a unicorn valued company, CICD. Um, we've covered traceable and Harness since the day they were both launched here at Tech.
I'm good friends with Jody over the years. AppDynamics was one of our initial founding sponsors. Um, you know, I learned a lesson years ago, my friend Chris Hoff, and you probably know Hoff, Chris Blas, right?
Hoff is the chief security guy now at, uh, LastPass. But Chris has been around the security world a long time. He used to get me going.
He'd say NAC was a feature, not a product. And I used to argue because I had a knack company and I didn't want that. But long term he's right.
But that's the fate of almost every kind of tech product. It become, it goes from being a product to a feature into a platform. You know, it gets melded onto a platform.
And, and so that is the story of API security. It, it had its moment in the sun. You saw several players.
No name security was a unicorn, right? They raised a ton of money. They wanted the big ones.
Um, salt our friend Michelle McLean worked at, there was one before that, that Red Hat bought for about 400 and something million back then. Um, traceable was another, you know, my friend Brad Feld said, if you're not in the top three, get the hell out. Because those top three, those first three companies to exit get the bulk of the money.
And that's exactly what happened here. The top three companies got out, they got the bulk of the money. I don't think no name got anything near what it was valued, you know, prior to, I think with Chase Boat.
And, and again, I have friends at Chase Bull in, in addition to Geo, but they've suffered from this lack of AI, API security being a thing. And, and they haven't been, you know, running a full speed for some time now. And I think the right thing to do is to fold it into Harness.
And they did. I think Harness like every other DevOps platform wants to be a dev is a DevSecOps platform. And API security is a good part, is a, is a nice add in, a nice tuck in to that DevSecOps functionality.
I, I don't see many standalone API, you know, originally this API security was gonna be a wap, a WAF replacement web access firewall, web application firewall, because WAF firewalls didn't monitor API traffic, which is a majority of the traffic on the internet. But now API security is either part of a security company or part of a security play, or, or it's part of your, it's AppSec, right? Or, or API management in general.
So, so my prediction is we're gonna see either more acquisitions of DevSecOps companies acquiring API security companies, or the very least who's left Renouncing Alliances with various players. There's still like half a dozen little startups in this space Around out. I mean, the big ones, the big one.
Look, if you're not in the top three, get the hell out, Said Jack Welch at GE long, long time ago, and He was right then, and it's right now, Then, you know, of course, Jack, just about that statement after he retired. So who knows? Yeah.
I mean, I, I've seen that in tech over the years though, having been involved in a few venture backed startups. If you're not in the top three and you can't make a sizable, you know, reasonable claim that you're gonna be in the top three in a short time, get out, pivot, sell, do something else. Well, I I, I, I have to say on topic, you know, uh, shout out to Roy per at a CEO of unified API, who's a guest on one of the inevitably curve episodes that's, uh, we'll go online the next, uh, couple weeks on this topic.
Interesting person, one to, uh, to listen to on, but effectively what more is there to say yes, right? And, you know, supply chain and so forth is mentioned again in the, in the background material for this segment. You know, this is, you know, DevSecOps, you know, working at SBE in a s om management company, you know, these last, uh, several years, it's DevSecOps.
It's ing how that's folding into other parts of the, of companies better than it has because of the shared visibility of these things we're all talking about. So, yeah, it's, it's time, right? You didn't notice that you weren't paying attention.
So yeah, now's time. I Gotta leave you with this. You always have to remember they're cattle not pets.
And you know what the fate of cattle are sooner or later, sooner later, they're all hamburgers. Yep. Is that it?
That's, that's the le that's the lesson of that story. All right. Hey, it's been a rollicking, uh, Textron gang today.
And, and Chris, John, Mike, thank you very much. Um, just a heads up, I'll be on at two 30 this afternoon on LinkedIn live on my Shimmy Says, and I'm gonna have more to say about this America only, America alone AI strategy. It's actually America alone against the world strategy.
And, and how, you know, where this can go wrong. Tune in on that. You'll also be able to see YouTube shorts not live, but it'll be on YouTube shorts in other places, as well as is Text Drunk Gang.
We've got a lot of text trunk TV coming up for you the rest of the day. Until then, this is Alan Shimmel for Tech Drunk Gang. Be safe.
Be well, speak up, you wear out. This is Textron tv. Hey everyone, welcome back to Textron tv.
You know, I, I always enjoy talking to my next guest here. He is the CTO and EVP for the cloud platform over at Qualys. It's my friend Dilip Bani.
Dilip a pleasure to have you. Usually we're in person at the QSC or at RSA or somewhere where we're in person, but today we're on Zoom, but it's still good to have you on. How are you?
I'm good. Good to be here, Alan. Uh, it's always a pressure.
Yes, it's, it is, it's, it's fantastic. You know, I mentioned it, well, we should hate it right off the bat. So, QSC, qua QS, Wallace Security Conference, QSC, um, is coming up this year, I think in October.
October 16th, around there. And I, I heard a rumor it's gonna be in Houston, which is a great city. That is correct, yes.
Uh, it, it's a new location for us, uh, this year. We are in Houston in October. And of course, looking forward to being there, looking forward to meeting our customers, sharing with them everything that we have been working on, especially everything that we are doing around enterprise to risk management, the risk operation center, and how that has evolved since we last talked about it, uh, during the 2024 QSC.
Well, I, you had to think for the year, right? Yes. And by the way, if you go to text, drug tv, all of our interviews from there, and there was a lot on the risk Operation Center, the Rock are, are available if you go to industry conferences, look under quais, and you'll find they all have, including my interview with Dilip is there.
So check that out. But Dilip, we're gonna talk about something else today. So, last week was a bit of like a Sputnik moment, if you will, right?
All of a sudden the, the Western AI establishment was rocked by news out of China that these folks, you know, it's a, a handful of PhD engineers basically put out a, an AI model that rivaled the best of what we have here at a fraction of the cost and a fraction of the time. And open sourced it on top of everything else so everybody could go, you know, look under the covers to an extent. Um, and it was big news.
Qualys turned your, uh, your, your scanning and engine onto it and came up with some very interesting results. I don't want to say too much 'cause it's your story. Lay it out for us, Philip, what happened here.
So, and Alan, I mean, spot on, right? Uh, deep seek, uh, this is a, you know, fairly young AI company, uh, out of China, certainly very talented folks. They came out with a model.
Uh, they've, they've in fact, fact been coming out with information for the past few months. And, um, I don't think a lot of people necessarily noticed them until they came out with this latest model, uh, the R one and it's open source, but it, it performs really well. Uh, and you're right, uh, you know, they are saying, uh, they have trained it at a fraction of the cost of what some of the larger tech companies here open AI, meta, uh, Gemini, and others are, have done to train their models.
Uh, so I mean, first and foremost, I think what they have done is something amazing. Uh, in, in some ways they, they are proving that if you want to build very large scale foundation models, you don't have to be in an extremely large organization with unlimited amounts of money. Uh, you can be a smaller shop and you can do this.
Uh, so that's a good thing, right? Um, it, it certainly got a lot of hype, it got a lot of coverage. Uh, what we wanted to do was, as we were looking at it, because we were curious too, we use a lot of open source models internally for our, uh, quas cloud platform.
So we wanted to look at deep seek and just understand, you know, how it was behaving, what it was doing. Uh, now I think you probably know we launched quais Total ai, which is our AI security solution some months back, uh, uh, in August. And what the solution does is it gives you a more comprehensive view of your AI posture, meaning you will get full visibility into your AI hardware and software assets, uh, your entire AI inventory, where your models are deployed, where your LLMs are running, and then also a pretty detailed vulnerability posture across your AI footprint.
In fact, we have more than 1500 detections right now, just from a vulnerability standpoint for your AI footprint. So we said, well, let's take this, let's take what we have and let's see how deep Seeq performs on that, uh, from an LLM scanner standpoint. So the way our LLM scanner works is we do an outside Incan, and we have built a pretty exhaustive knowledge base of questions that we will ask an LLM, um, back and forth, um, which we call our knowledge base, and we gather that information.
Then we have some inbuilt models, which we use to then judge the quality of the responses that is coming from these target LLMs that we are testing. So we did that and deep seek, um, to our surprise, uh, it didn't do particularly well. Uh, in fact, it, um, it failed 61% of knowledge base tests that we had, and in total we ran about 900 tests, um, just for our knowledge base checks, right?
And what these checks do is they test for, um, ethical questions, legal questions, operational questions, uh, and we do a lot of back and forth with the model to kind of get a sense of how is the model responding to our questions? Because these things are important, right? You take a model and you deploy it, whether in a B2B setting or in a B2C setting, and you expect the model to work in your particular domain and not give answers that it's not meant to give.
And when it does, then there is a liability issue here, right? And, you know, that's what we are trying to get a sense of. So we did that.
Then in addition to the knowledge based tests, we also do jailbreak tests, um, where jailbreaking basically involves techniques, you know, that you can use to bypass inbuilt safety mechanisms that are built into the model. Uh, there's a lot of well-defined techniques. Uh, we, so obviously we work with the community, the open source community, and in, in our solution right now, we have about 18 to 20 different jailbreaking techniques that we use, and we ask the model questions around these techniques.
The idea being that you're somehow trying to coax the model to give you information that it's, it should not be giving you harmful outputs, uh, misinformation, you know, privacy data, unethical data, all sorts of things. And I think just based on the fact that it didn't do so well on the knowledge based tests, um, I mean, not surprising, but it failed more than 50% of the jailbreak tests too killed almost 58%, almost exactly 58% of everything that we did. And our analysis was pretty comprehensive, um, you know, trying to get a sense of what was going on here.
Uh, so really the, the gist of this is yes, it's, um, I think it's a great model from a foundation model standpoint, uh, in how they have trained the model, the underlying architecture, um, and just being able to demonstrate that you can build a model with significantly lower investment. Um, but that corresponding investment hasn't really happened on other areas yet. Right?
And then of course, concerns with, if you're using a hosted model that is sitting in China, and you have GDPR concerns or other, you know, regulatory requirements, right? Not concerns, but GDPR requirements, right? And other regulatory requirements across different countries.
Something to be mindful of, right? Um, Sure, but well, that's the host sovereignty issue, right? Yes.
So Dilip, I'm not gonna make excuses for them, but let me postulate two, two things on what you said. Number one is some of the, uh, not the jailbreak questions, but the sort of foundational questions, could it be due to the fact that clearly, because it is from China, it it is, I don't wanna say censoring, but it's purposely not reporting on some sensitive areas that the Chinese Communist Party may deem, uh, sensitive that they don't want it to report on it. So it's been, in essence, blinded for those things.
And I mean, 61% is still a pretty high number. I'm sure it wasn't, you know, 61% of things that have been censored there, but could that be at least partially, uh, responsible for that? Yeah.
So Alan, there are two parts here. One is, I mean, obviously just based on the fact that the, you know, the model came out of China and the sensitivity of the Chinese government, there are some questions that you can't ask the model. So it's really quite censoring some things.
Um, and some of those are well documented, uh, right? Um, that what this then means is that if they do want to stop, so the model from giving incorrect information or unethical information, however you look at it, they are, you can stop the monitor from doing that. You cannot be perfect, but you can restrict it as best as you can.
But those controls haven't been applied to other areas. As an example, we asked the model a lot of, when we were asking geo break questions, um, you know, we asked a lot of typical questions on, you know, how could I make an explosive, uh, how could I come up with, um, you know, incorrect healthcare information? And it didn't need a lot of prompting, a lot of circumventing to get that information out.
It was just giving us that information very quickly. Uh, and I, I think what this points to is they have put in certain guardrails for things that, for deep seek, you know, just being where they are, you know, they had to do that, That are important to them and their right, right? But maybe not for, but not for A larger, and, you know, that has to be done.
Now, either they do that or other organizations can pull these open models and have guardrails sitting in front of these foundation models to say, when you're asking a question, I'm going to make sure I'm filtering the right things out and only asking the model what makes sense, right? Because the model inherently is not trained yet to do that. Yeah.
I mean, and that's one of the beauties of it being open source, right? You could self-host it and put whatever guardrails you want in front of it and it self-hosted, and that takes it out of China and everything else. But Dilip, let me, a lesson I learned in my 25 plus years in security, 30 plus years in technology, is security becomes important when customers demand, it's important.
And I think clearly deep CQ wanted to get this out. I I don't think it was any coincidence that this was released. This R one came out two or three days after the, uh, Stargate project or whatever, the $500 billion project to go build data centers was announced, right?
There's, there's, there's PR here and global nation state strategic, you know, competitiveness at play. I don't know if they had the time to maybe put in the, just, just like, until a customer demands better security, you don't have better security until someone says, you've gotta put these guardrails in here, especially when they're rushing to get it out. They, they don't put them in there.
I, I would hope that that's just more of a sign of its immaturity than a total lack of, of ability to do that kind of thing. Yes. Um, and, and Alan, I think I agree with you there.
Um, this is a fairly young company and, um, I mean they, you know, they've been working on building, you know, some, I mean, in my view, some exceptional models. Uh, and to your point, uh, you know, this is still to some degree, you know, research oriented, right? Um, but when you look at the overall AI ecosystem, there are different layers that you're looking at, right?
Uh, you are, you have one layer, which is your hardware and infrastructure layer where the folks like Nvidia are playing, right? The second layer is your foundation models, right? Which are now to some degree, it feels like they're starting to become more commoditized.
Uh, you know, some are closed source, like open ai, but if the likes of deep seek are making models open source that others can then pick up and iterate on, right? Um, that would help. And then the third layer, the one that you are talking about customers asking is that app layer, that how do you take these models and how do you, you know, bring value out of those models to cater to a need?
And as that, and as that app layer is gaining maturity, the security requirements will increase, right? I mean, what is my model doing and why is it doing what it is doing? What kind of guarders and checks and balances do I have?
And I think that will come for sure. Um, and I think they'll come for all models. Neil, I I gotta ask you another question.
Look, this is, we've been talking about this deep seek since the announcement, uh, every day on Textron Gang and in a lot of our articles and videos, uh, there, there's one, I don't wanna call it a rumor, but, uh, you know, some people are saying, I hate to say that 'cause politicians say that. Some people say, but there is a story out there that the reason they were able to train deep, steep, or this, this particular model so much faster and cheaper, is because they didn't kind of start from scratch. They, they, they were able to for however they got their hands on it, uh, a open ai, uh, model, and then they kind of trained it off of that, if you will, or, you know what I mean?
And, and, and so that's what allowed them to do this faster and cheaper and on less powerful Nvidia and so forth. Is there anything in your testing that would give credence to that prove it, disprove it, or that's not something you looked at? You could, That's, yeah, that's not something we looked at, um, because we were doing an outside in evaluation of how the model is performing against checks.
You know, whether that happened or not, I mean, will, I mean, you know, remains to be seen. Um, but, uh, what I will say though is, um, from an architecture standpoint, from a model standpoint and the way they approached building the model and building the training, uh, and there is innovation here, which Oh, no doubt. Which I think no doubt, Most of the larger companies, everybody's going to benefit from that.
It will optimize how they're using their GPUs. Uh, certainly, You know why it's the deal. And it's funny that it, it comes from the Communist Party of China, but this is what the open market's all about.
Yes. Right? If someone builds a better mousetrap, copy that mousetrap Yeah.
As fast as you can, right? And, and learn from that and, and, and keep innovating, because, you know, the other thing I, I feel with this is yes, it didn't do so well on your test. No doubt about that.
Right? 61 and 58% are pretty, I mean, those are hard to argue with. Uh, it will get better though.
I'm sure it will get better. And, and it, it, and that's again, part of this whole open source thing, right? It allows other people to innovate off of their work as well, which is, you know, is, is a great model.
Um, I, I think the bigger, the bigger thing though is that we were just discussing it on text Junk Gang this morning. There are so many different models out here right now, even within open ai, you know, when do you use oh 3 0 1 4? Oh, most people don't really know.
Well, it sta it versus another one. You know, how do you know what model to use? When should I use deep CR one versus, uh, Gemini or llama or what have you?
So I, I think we're gonna develop in a world that's kinda like cars. Some people drive a Maserati or a Ferrari and it cost a lot of money, or a Bentley, other people drive a Buick or a Cadillac, or, and then other people drive Chevys. Mm-hmm.
And that's okay too. They still get you from point A to point B, which is the, that's the mission. Yeah.
If this thing can get you from point A to point B and fulfill the mission at a fraction of the cost, market economics dictate that you'd be a fool not to use it. Yeah. I, So, you know, go ahead.
The, I, I think the entire ecosystem is still, it's still very early, right? Chat PD just came out, what, in November, 2022. 0 and you know, everything new, you will not like it.
We still look back fondly to the initial versions of Champ Chan GBT thinking, oh, it was revolutionary. Yes, it was. But now after you've experienced something so much more better, right?
Even from OpenAI and from others, you will think the initial versions didn't really have, you know, that level of knowledge or they were not as good as what is today. Uh, and what will happen here is this innovation is happening at an extremely rapid pace. It's not even in gaps of two years.
It, it's happening, you know, within months, right? Weeks sometimes. I mean, week to week, these things change.
It seems It's crazy. I mean, these guys came out with their model and then Alibaba came out with a model saying, Hey, we think we have something better. And, and that's a good thing, right?
Because early on, It's the market. Yeah. It's the market.
You want this kind of innovation happening. You, you want this kind of disruption happening, and then everybody benefits from that. So I, I agree with you.
Let me ask you to put your Qualys hat on now though, 'cause we only have a few minutes left. Speaking now is C-T-O-E-V-P cloud platform, Qualys, how big a challenge are these AI models in, in making security better or trying to secure them? Right?
There's two aspects. One is harnessing AI to be a better security company. One is as a security company trying to secure against AI being used by bad guys, right?
Yeah, I, it's, it's a really good question, right? Um, I think using AI ML and AI in security has been happening for a long time now. We have, we had machine learning models embedded in our platform.
We have them for years. Uh, I think when LLMs came out, large language models came out. Uh, it was a little bit more disruptive because it, in some way it socialized using machine learning.
Earlier to do ml, you needed a data science team. You needed a team of experts that really understood how to train these models. Now, in some cases, you have folks, you know, that take an LLM model and just doing prompt injection, they're able to, you know, build applications that can add a lot of value.
So now from a security standpoint, of course, using AI ML to build security solutions, it's been there, I think LLMs will help accelerate that. We are already seeing that. Uh, we've introduced a lot of new things in our platform just in the last two years over that, right?
The bigger question now is, as especially large language models, which are more predictive, they're not deterministic. If you ask it a question, it will not give you the same answer every time, right? It's just how the underlying architecture is.
It's getting better, right? If you ask it a math question, it, I mean, it is giving you good answers now, right? And especially some of these newer models are really good, but more from a business standpoint, when you are asking it a question, you are expecting it to answer within the context of your business domain.
And so guardrails become extremely important because you are saying, your chatbot, let's say, is representing you as an organization. And if your chatbot gives an answer, then you are held to that answer. You can't say, I had a chat bot on my website and it gave an answer.
That answer was incorrect, so it's not my problem. You can't say that, right? Uh, so that's where, you know, more checks, um, you know, building the right kinds of gates is becoming, becoming increasingly important.
What we are seeing right now is people saying everything is in beta mode, right? Uh, that, hey, we are releasing something, but it's in beta mode, which is fine. Um, I think the industry is maturing, obviously the models will mature, the security ecosystem will mature, right?
Just the way we introduced total ai, we looked at this as a gap, even when we were looking at it internally to say, okay, our teams are blowing models. We don't even know what's going on. We talked to a lot of CISOs and they said, we have no visibility into what our teams are even putting in chat, GPT or perplexity.
What kinds of questions they're asking and what kind of information is going out, which could then be used to further pre-train those models on proprietary data, right? So you need all these checks, and I think the realization is there. And, you know, we, we obviously took a major step in saying, we are putting out a solution that will help you understand your AI ecosystem, understand your vulnerability posture, your security posture, and then of course, as you're deploying your large language models across your enterprise, you know, what is the security, the compliance, the ethical guidelines, uh, the jailbreak, uh, you know, capabilities, you know, how, how do you manage all that, right?
Uh, that's where we are at. Uh, we are obviously adding a lot more capabilities into our platform, into total ai, uh, call total ai, so our customers and just the larger, uh, community can benefit from it. Excellent.
Di we're out of, we're overtime, actually. But thank you so much for coming on. Keep up the great work, everything you spoke about.
com whether you want to go check out the blog articles on, on this particular testing and, and story, or you want to find out more about total AI or about rock, or anything else. com is, is your starting place for that. Dilip, I hope maybe we'll see you in San Francisco during RSA week, if not a QSC or you're always welcome to come on here and chat with me.
It's a pleasure as always. Likewise. Thank you, Alan.
Good Conversation. All righty. Diwani, C-T-O-E-V-P Cloud platform at Qualys here on techstrong tv.
We're gonna take a break. We've got a lot more coming at you today. Stay tuned.
We'll be right back. ai video series. I'm your host, Mike b Today we're with Anand San Gupta, who's CTO for Aviatrix.
And we're talking about the overlooked implications of networking and security challenges that will occur as we all deploy thousands, hundreds of thousands, maybe even millions of AI agents one of these days. Hey, Anand, welcome to the show. Thank you.
Thank you for having me. So, describe for us what it is that is at the core issue here when it comes to networking and security. Because all these AI agents, as far as I can tell, they're just really gonna be additional endpoints on the network, and they're all gonna start generating traffic and well, what could go wrong?
Well, um, uh, that's a great way to put it. What can go wrong? Uh, so, uh, before I, uh, point out what can go wrong, what I would like to, uh, kind of cover for the audience is what these agent or agents for the AI really do, right?
Uh, that might, uh, help, uh, align the needs and the shortcomings and how, uh, the, how we are trying to fix those issues. So, uh, there are four key steps that a AI agent really does. Uh, so the first piece is, uh, what, uh, we call perception and data collection.
So what these thousands, and sometimes, as you said, maybe millions of or million of, uh, these agents do is what is called perception and data collection, which is gathering and collecting data from multiple places. And now this data can exist virtually anywhere. It can be in clouds, it can be on-prem, it can be on edge, it can be in QSRs, right?
And it can be anywhere across the world. It's not just in particular location or geo, but it can be across the world. So that's the first step.
The second step is about decision making. Once these agents have collected all this data, right, they use these models, right? And tune models to make the decisions.
That's the next step. Number three step is about action, right? And execution.
So once they have made that decision, then these agents, right, act on that decision. And last, but not the least, it's that it's learning from all the data it has gathered and from all the, uh, decisions it has made, right? It tweaks and adds to that learning, right?
And that step is basically called learning and adoption adaptation. Uh, so now if we really look at it, let's try going from the first, second, third, fourth. So for perception and data collection, most of the data, right, has to be collected from all these different places, right?
Which can be actually not just where like thousands, as you said, it can be millions of places, right? And to collect that data, what do you really need? You need like high bandwidth network, which needs to be intrinsically secure, right?
Because a lot of this data is sensitive. It's PII data, right? It can be also high value data, even if it is not PII, right?
So all these data has to be accumulated and gathered, right? On a very secure way, right? And also it is very high, uh, bandwidth.
So it has to be high bandwidth security. And that's what we also help out, right? With, uh, aviatrix, we provide very high speed encryption right from end to end.
And, uh, it's completely secure. The second part, which is there for agents, is decision making. In this case, what happens is that once the data is gathered, right, it talks to the models, right?
And figures out what it needs to do from the decision perspective, right? And this is where right, our, uh, the whole firewall service comes in, right? And make sure that, um, the right decision is the right agents get to make the right decisions with access to the right models.
The third piece, which is action, is very interesting. Now, once you have, uh, thousands or maybe millions of agents, right? What decision those agents are making needs to be identified, right?
What agent is making what decisions and how they're communicating with each other. And this is what I call traceability, right? Or else, like, these are some things.
Sometimes I say these are robots, fighting robots that you need to figure out that who did what and why, and things like that. So that is where observability really is important. And, uh, it's not just network observability, but figuring out which endpoints, right?
Are talking to which endpoints and when, so that there is a traceability or they can be tracked right? When these actions are being taken or else it can basically get into a very chaotic situation where you don't know who is doing what and it's not traceable or trackable. Uh, that's what we don't want to happen, right?
And, uh, the last, but not the least is about, um, about the learning and adaptation. So one thing to think about is that this, almost all companies, they spend millions, if not hundreds of millions and few companies. They even spend billions on tuning this model and learning and adapting this models.
But, uh, if a bad actor gets hold of that, right? And exfiltrate that model, the things which you have spend millions, hundreds of millions of dollars, right? Can be theirs in minutes, right?
So this is what is really crucial. And in all these four areas, right? Aviatrix really helps out to provide a solution.
To your point, it seems like we're a little obsessed these days with protecting the data, but that's only one part of the equation. And ultimately, the bad guys, maybe they just wanna steal the agent and the model and everything they went with it. 'cause that's the intellectual property that matters A hundred percent, right?
So, and also if you look at the attack surface, there are three, four areas which I talk about why, why it has changed the whole landscape. One is, the first is that the attack surface has become way bigger. It's not just the on-prem data center.
It's not just the cloud. It's edge, thousands, millions of endpoints that can be there. So the attack surface is higher.
And the next part is that, uh, with gene AI and the money, which is pouring in, and many of them are nation state funded, right? I maybe you already know about the Salton use case, right? Mm-hmm.
So in these cases, the bad actors or the infiltrators right, has become really, really sophisticated. So your attack surface has grown, your bad actors have become way more sophisticated, and you have third pieces, a lot to lose. Mm-hmm.
Right? So all of these three things has created the perfect storm to bring in a solution like aviatrix, which provides built-in security and connectivity. You don't have to think differently that you have a connectivity, then you put security on top, and maybe they're not working together.
It's in silos. Your configuration can be wrong. All of that is taken away.
Unfortunately, in my experience, every time we have some new advance in technology, the cybersecurity aspects of it wind up being an afterthought until something bad happens. So how long will it be before that something bad happens? Uh, really great question.
So, uh, this is how I put together. So the thing is that, that enterprise, all enterprise, they have a huge pressure to bring in all this cool technology, right? So because of the pressure, right?
It is really needed to increase the velocity to bring those applications. It's not, it's from the market, it's from the c uh, CEO. It's from the developers.
Everybody wants things to be fast, right? But from the other side, there is need for security and connectivity and compliance and audits, all that thing, right? The controls.
Now, uh, the part which is really interesting is that how to balance velocity with security and compliance. Now, the thing is, what your question about when that bad thing happens, actually the bad things are happening, right? Mm-hmm.
In, in, like think from today, right? Just because of salt typhoon, nobody really knows what is compromised. So in security, while I've been working on networking and security for more than two decades, so we have a meme, uh, we say that there are two types of companies, one, which knows that they have been compromised and one who doesn't.
So the meme part of it is that it's not like it's a big event, which happens, I'm sure, like we all get these letters once in a while, which says, Hey, your PIA data, your social security number, your credit cards have been compromised. And these companies will say, oh, for one year you'll get a credit report. Personally, I have got like, at least five of them in last one year.
These are all cases of breaches, right? It is exfiltration right now. Lot of it has happened already in grand scale, right?
I'm sure you guys know about large amount of breaches that has happened in the United States itself. That is happening worldwide, right? So it is not that it, we are waiting for such a case.
It is happening every day more than once, right? So the, the part is that, uh, I can't talk about certain customers, but there is a customer whose network and really, really important, uh, important, uh, production in healthcare that went down for a week, right? And they had to really put something immediately, and they came to us, right?
And we had a really good solution. We were easily deployable and things like that. But it is happening every day.
We, it's not like we are waiting for something bad to happen. Do I need to go find somebody who's a cybersecurity expert who happens to also know about how AI works? Or am I trying to train the AI people about what it means to be more secure?
I mean, who ultimately is gonna take responsibility for this? I mean, I know who's gonna get blamed, but I just wanna know who's responsible. Yeah.
So, um, this is how, uh, I explain to my customers the thing is that it is about the technology and about the processes at the end of the day, right? Uh, now if you really look at it right, over time, what has happened, and even like if you look at on-prem, there were networking companies like Cisco's and ata, and there were security company leads like Palo Alto network, checkpoint and et cetera, right? And it was always, security was a afterthought or a bolt on technology.
So the c critical pattern, it used to work pretty well. When you have a building and you know exactly where your egress point is, where your ingress point is, you have a big door in front and you put a big lock on that big door, right? But with today's architecture, with cloud and edge and on-prem, right?
What I call it as a disappearing perimeter. So data can go out and in from any place, and you don't even know that place exists. So what we really need from the technology point of view is a inbuilt secure network fabric, right?
Every communication is secure by default, sometimes also called a zero trust, right? So if you have, or if companies have that technology, that's the baseline, right? And on top of that sits the processes, right?
So all the processes that is needed, like for example, today, if you look at the DevOps pipeline with Kubernetes and containers, right? It's a process and it cre makes sure that there is reputability, there is audit, there is compliance, there is drift management, all of that, right? So what my, what how I tell customers is that if you have the right technology, and if you have the right processes, then everybody does not have to think of it.
You want your developers who are like cool gi uh, developers not to have to think every day about security because it is already taken care of by the technology and the processes. Mm-hmm. And same way, right?
The, the platform team does not have to think about it every day because they have set the processes in place so that it is already taken care of. They just have to make sure that it is properly audited, right? We, the system is going to tell you, right?
And it should just work without anybody's, um, manual intervention. So are we gonna have to fund a hmm, major upgrade cycle of our infrastructure to get to the faster networking that you described? And of course, the servers and GPUs and everything that goes with that.
But are people overlooking the networking side of that equation? Uh, yeah. So, uh, that's a great question.
So actually you have the technology right? There is fast connectivity. Whether you look at CSPs or the, um, or, or the service providers, there is fast network, which is already there, right?
The part which needs to be done is what I call it as secure by layering. So all it needs is to put a software defined networking and security layer on top of the base connectivity so that the end-to-end across all clouds, across all edge and colos and on-prem, right? That software layer, right?
A distributed software layer, right? Takes care of it as a layered approach. We don't have to upgrade, right?
The networks or upgrade the infrastructure. We need to just put a distributed networking and software solution right on top of your connectivity today with a single or unified pane of configuration and visibility and observability, right? And that can be easily layered in.
So for example, the uh, solution which aviatrix has, right? You don't have to change or you don't have to upgrade everything. It just goes as a layer on top of your current deployment.
Not just that you have to change everything. You can roll it in in phases, right? And transparently add that layer on top the other parties that we just released, something called a pass solution Aviatrix Pass, which is that we manage everything.
So your operational cost actually goes down, right? And you get this whole service integrated security, right? Which is completely managed by Avia Atrics.
Will you be adding your own AI agents to your service? Who in turn will have to talk to all my AI agents? And how is that all gonna get orchestrated?
'cause it seems like there's gonna be all these, uh, control playing and data playing conversations that need to take place between different classes of agents. Is that right? Yes.
Actually, uh, we already have certain agent, uh, agents in the product itself, right? So we have started rolling them out. It, uh, we have agents which figures out, um, how bad the scenario is for every p VPCs and their deployments, right?
And on the other side, we are also working with, um, the CSPs to integrate with their agents to make sure that they can, we can provide the information they need from end-to-end. Um, we need to be way more collaborative in this space, right? So that we all work together to achieve the outcome, which we are looking at.
But it has already started. And, uh, we are working with, you know, like top three CSPs in that area. So what is your best advice to folks about how to have this conversation with their teams?
'cause I think every organization you talk to is AI happy. There's a lot of maybe occasional irrational exuberance, but I don't think they're really understanding all the, the fundamentals that we need to get addressed. So how do I kind of get in there and kind of bring everybody down to reality?
Yeah, great question. So what I generally advise customers and prospects is, number one, is to embrace Multi-cloud infrastructure. So to design with multi-cloud and the infrastructure in mind.
So have a infrastructure like, which is basically networking, security, and the full stack, which is across clouds, across edge, and it is primed, right? For supporting any kind of gene AI applications on top, invest in it, right? Invest and embrace, right?
Uh, full multi-cloud edge kind of, uh, infrastructure. Uh, number two is that security needs to be embedded in the infrastructure, not a afterthought and not a bolt-on, right? When the cloud architecture is being designed, it should be embedded into that, not what I call is, is built in security versus bolt on security.
And last but not the least, is provide the processes so that the developers and these gene I experts, they can develop and deploy their applications with no friction from security and infrastructure team. I think maybe we're overlooking one small, but important point is, aren't most of these AI agents, and maybe even eventually the models themselves gonna be running at the network edge, because I need these things to be closer to the point where the data is being consumed and created, rather than having some sort of round trip to a cloud somewhere where I may have trained the initial model, but now I need to get the inference engine from that out to the edge. So, um, does that require a level of, of finesse that we're not thinking through?
Yeah. So, uh, it is a hundred percent correct, right? So the thing is that, uh, the base models are generated generally in the cloud because it needs lots and lots of, uh, GPUs and infrastructure and data to be generated.
But, uh, these agents basically tweak those models, right? And these models go out into the edges and all the different, uh, places, and they get tweaked, and then that, uh, tweaked data finally comes back and then makes those base models more, um, enriched, right? So, uh, that's the main reason why I ask, uh, enterprise customers to provide a fully distributed, uh, secure network across clouds and across edge, right?
Because once you have that, you can run these models anywhere. And, and you don't have to think, like, for example, if a developer wants to deploy it in cloud, they deploy it in cloud. If they want to deploy it in edge, they deploy it in edge.
Um, I had in my past, um, company QSRs one of the largest QSRs, right? And they used to de they would deploy all these, um, agents in their q small QSR with two little boxes, right? But if the infrastructure is robust, high performing and secure, you don't have, like, the developers don't have to think where to deploy, Right?
Folks, you heard in here, I think it was back in the eighties the first time I heard the phrase that the, the, the network is the system. Well flash forward all these years later in ai, and the network is still the system. Hey Iman, thanks for being on the show.
Thank you very much. Thanks for having me. All Right.
And thank you all for watching the latest episode of the Text Strong Do AI video series. You can find this episode and others on our website. We'd invite you to check them all out.
Till then, we'll see you next time. Hello, and welcome to the digital CXO podcast. I'm Amanda Ani, and I'm excited to be here today with Dr.
Jason Corso. He is the co-founder of Voxel 51, as well as he is a professor of robotics and electrical engineering and computer science at the University of Michigan. How are you doing today?
Hey, Amanda, I'm doing great. How are you doing? Doing well.
Can you share a little bit about Voxel 51? What are y'all doing over there? Sure.
So Voxel 51 is a, uh, AI software company that builds a package called 51 and 51 teams for enterprise. That essentially, uh, you know, our, our target user base are builders of visual AI that seek to understand more about them, their model performance and their dataset quality so that they can ultimately build visual, you know, make visual AI a reality. Um, we've been open sourced since August of 2020.
We have about 3 million installs. Uh, we do set up the software in a way that is hyper flexible, right? We don't sort of tell you what to do or how to do it.
It's, think of it kind of like building blocks for the developer in the visual AI space. And, um, you know, ultimately it's been used across various industries from, you know, automotive industries to agriculture, to, um, consumer products, advertising, sports, you know, you, you name it. We have users either in open source or enterprise Enterprise.
Wonderful, thanks for sharing. So, our topic of today is achieving almost 100% accuracy for visual ai. So tell me a little bit about that and where you come in with that, and we can move on from there.
Sure. com or you know, various leaderboards for computer vision and visual ai, uh, sometimes the numbers will be jarring, right? Like the numbers might be something like 60% or 70%.
And, and yet that's a, that's a decade of research that went into that level of performance or decades of research. Really, if you, if you think about the pre deep learning era to too, um, but if you think about what's necessary for actually deploying visual AI into practice, right? You, you, you have an autonomous vehicle, or you're doing a, you know, a quality assurance on a manufacturing line, 70 percent's frankly not good enough.
80 percent's frankly, not good enough. Uh, even 90 percent's really not good enough, right? Like, if you only miss nine out of every 10 pedestrians that come into your, in your view in an autonomous vehicle, you're gonna have some problems, right?
So, so we think of this, uh, as, you know, analogous to the classical five nines concept, right? 999%, uh, comes from. It's, it's from network security and network uptime, basically.
Uh, and, and various, you know, pre-cloud, in the pre-cloud era. Uh, and it, it is super critical to, uh, achieve that level of performance so that we can begin to, uh, assume robustness in various visual AI capabilities and then take the harder problems to humans downstream, right? Uh, where, whether or not that is, I mean, I, I like the QA on the assembly line, or the fact the manufacturing line, like it's a really good example, right?
Like, if you can basically have the, the humans, the domain experts who understand the product, understand how the circuit board needs to look or whatever, the, you know, I just made a French press coffee, right? Like how the French press needs to be assembled, right? Like, and only give them the corner cases, their time will be used more effectively, and the overall efficiency of the manufacturing line will also be used more effectively to, to do that.
We, we wanna get to, to this notion of five nines in, in visual ai. So once you have this very accurate, uh, visual ai, what are some use cases where this could be integrated? Didn't, Well, I, I mean, I think this, this really talks to you or gets at the, the, the popular terms that are, that are being used these days.
Uh, right? So you have visual AI is one of them. Then we have this notion of physical ai, right?
That, you know, ultimately, like the, what, what does the future of, um, robots look like? Either, you know, take, take robots out of the factory and put them into the hospital, put them into the classroom, put to put them into the home, what can they do? And then even post physical ai.
Now, we've also begun to hear about age agentic ai, right? Like, not only can these robots or these physical AI things see through visual AI and listen through, you know, language ai, but can they also begin to reason about the goals that are either given to them through conversation or taught to them in a training phase to then go and understand what they should be doing to increase, increase efficiency, or to help the elderly who's fallen down or give the right medicine or what have you, right? 99%.
Uh, visual AI is one of the elements, one of the key elements of those foundations, right? Like oth other elements are vast low cost compute. We're getting there, right?
The recent releases we've seen in, uh, January of 25, like from Nvidia about I think the system's called digit, like it's moving this notion of high power compute that in a more portable edge based manner. I think that's, that's one of the elements of the future. Another element is, um, you know, like the ability to do speech recognition and speech generation robustly, uh, to be able to interact with humans on the human's terms.
Uh, and we're seeing a huge amount of progress in that, right? The whisper technology from OpenAI is, is like one of the latest in speech recognition, very capable, uh, still needs some work around speech or separation. Like if, if there's a robot I make, you know, amongst many humans, and like I have, I have three kids in my h in my home.
So like many kids around making a lot of noise like that, that gets a little bit more difficult. But once you have these pieces that are robust at the lower level, then we really can, uh, we can begin to think about more practical physical AI and physically age agent AI in, in the, in other applications that, and I think that's ultimately the, like the, the true impact, positive impact that AI will have to everyday life is not gonna come until we, we've built those things first, uh, and or at least demonstrated that they are robust and safe and and secure. We're starting to see some self-driving cars around.
When do you think it's going to be the case that almost every car is a self-driving car out on the road? How far away from that? Yeah, that's a hard question to really pit a pin a time on.
And anyone who has been, uh, confident enough to give a time has been wrong in the past. I think, um, think, think about it another way, right? Like when, when elevators were first, uh, created, um, there were humans in the elevator to operate the elevator, and the elevator was still fully autonomous, it was just being operated by a human because that was this social, um, contract, if you will.
There, there was this comfort level. So, um, I don't know exactly, I should look this up. I don't know when it became more common to have, um, fully autonomous, no human operator in the elevator than the, you know, than not.
But if you think about the progression in automobiles in the last decade, I think it's been really powerful, really amazing, right? Like we, we moved from classical cruise control, for example, to, I mean, different companies call it different things, but essentially like radar base or adaptive cruise control that can maintain a speed unless there's a vehicle up ahead, uh, can even a, uh, adjust the speed whether or not you're the, the traffic based, based on the traffic density, for example. Um, you know, so we are getting a lot closer to nearly autonomous, um, you know, uh, uh, vehicles.
And I, I don't think, I think the social comfort level will be the final hurdle to overcome even once we have the technology that's capable. And it's, and humans, you know, we humans are really hard to understand a lot. So, you know, hard to, hard to predict when that will be, but I I actually think it's gonna be sooner, sooner than you think technologically, but later than you think socially.
Mm-hmm. So, I know it's hard for humans to trust technology fully in that way and to technology can of course make mistakes. But do you feel like if every car on the vehicle was every car on the road was self-driving, we'd have a lot less accidents?
Oh, I, I do think there are both. There are, there's clear evidence that that would be true, right? Like, um, that first of all, like these autonomous vehicles won't have to worry about the radical unpredictability of, uh, uh, what typically happens on the roads.
Like at least roads that are out of, uh, human occupied, occupied areas like highways and things like that, right? Um, but I think the, there are other elements that if, if we can, if we had infrastructure that was built or updated to support autonomy, I think we'd already be there with less, you know, in some sense with less traffic. You know, I think there was a study in the nineties somewhere in California where, um, they built a small or built, or like cordon off like a portion of highway to do some tests, and they were, they did, um, these, like, I forget the exact name for them, but when you have autonomous vehicles that are able to like, go very close to each other as they're going down the road and they have these like, you know, dozen or so, I mean, I mean, I think the fuel efficiency was demonstrated to be ridiculously higher.
Um, and there were no accidents recorded in that study, you know? And even though there were humans in the cars at that point just for safety. Um, so, so anyway, I think the evidence is there that we will see, um, like the, through better communication between the vehicles, through more predictability between what's happening via that communication and or just less, less, um, unpredictability from human drivers.
I, I do think you'll, you, we will see safer roads, uh, at, at that point. Yeah. Yeah.
You bring up two great points. There is not just the safety issue of that, but also the energy efficiency. So I, um, hadn't thought about that as much, but, um, that should help with, um, energy and gasoline use too, if, if all the vehicles are driving as efficiently as possible.
Uh, 100%. And, and I think, you know, not, not only can it be already demonstrated that that's the case, um, I mean, I think it, it's when you have roads that are that, that are more safer than, than we unlock the capability to, um, redirect other investments that are being made is maybe what the thought that I'm thinking, right? Like, um, I, I know that, that there are some companies who focused their, like, like autonomous driving and trucking companies who focus on energy efficiency now even, right?
Like, how do you do better cruise control knowing the weight that's in your bed when you have a, a hill coming up, for example, rather than it's gonna be a flat terrain, right? So I think fuel, the fuel efficiency is a, in some sense, like a fiscally responsible way to push toward infrastructure change, in my view, for example. Um, yeah.
Yeah. So infrastructure is next is important. It's an important step for that, for this to happen.
Do you think visual AI would soon be integrated into more cities? In other words, smart cities with, um, visual AI being integrated into the street lamps and the street signs and, you know, cameras and that kind of thing to determine traffic and all that kind of stuff? Yeah, I think that that, uh, progression has already begun.
You know, there are already modern cities, even in the US that have hundreds or thousands of cameras. Most of them were installed for security and public safety purposes initially. But once one realizes that oh eight, if we actually model traffic flow through, we, we have all this, this data now, and we can connect other visual AI to understand, um, you know, a general way of saying that is like patterns of life, right?
Both from vehicles and events and humans and pedestrians and so on. Um, then we can, um, optimize for various use cases, both safety, uh, and, and energy responsibility, or even just access, right? Like we want to bring, we have these beautiful cities in the United States that, uh, downtown areas that are often not that occupied.
Um, you know, so we can, if people feel safer, they feel the cost will be less, even just figure out how to do better parking, for example. All that will come through visually AI mechanisms that better understand and utilize the data that are available. So all this is underway in some level or other.
What do you envision knowing how fast technology is advancing? What do you envision for the future, say 10 years from now? Um, w well, I think it's, I mean, it's, it's such a, it's a great question.
'cause this is such a great time to, to like be thinking about what's, what's coming, right? Um, I mean, I do think the, we, we are, we have experienced a critical point in the development of, uh, of AI broadly, like visual ai, physical ai and so on. And that, that did come from the demonstration that these like super large scale scale models connected with vast amounts of compute and vast amounts of data, were able to, um, pull out elements from our human world that, that allow a better translation between the computer world and human world.
Um, I think this came initially in, in my SA area, like the world of like, um, computer vision, video understanding, and so on. Like, you know what my, my, my research group for example, at, at Michigan Focus has focused on video to text for over a decade, right? You know, an image to text.
You know, my, my National Science Foundation career award was on the image captioning problem in like 2008, right? Like, so I've seen this, this field grow. Uh, and I think when CLIP came out, you know, 20 18, 20 19, we saw this notion that, oh, wait, like if you have image data, visual data, and you have language data and they're connected and training against each other, and you're doing this at scale, there is immensely powerful structure in the UN in the model that's learned from those data.
And, um, we are now be beginning to see that structure being leveraged for downstream tasks. So in the field, oftentimes these mo these models that do these types of things at scale are, are being called foundation models now. Um, and when you can take a, a foundation model off the shelf and just make use of it for a, a different task for which it wasn't anticipated or wasn't trained for, you may have to fine tune or do rag like retrieval augmented generation to go and like augment what was originally in that, originally in that data for a downstream task.
Like that work is, is already light years ahead. Where it would've been if you had to start from scratch, which starting from scratch would've been, what data do I need to train this model? What's the right architecture for, for my model, right?
And then you go and spend months or years getting that data. That's why, like, you know, in some sense, maybe the 2010s were like the decade of large data sets in machine learning research, machine learning research, right? Like, everyone, everyone who wanted like to get high citations on their papers were like, oh, I can just get a, make a big data set and I'll go get a lot of citations.
And I think that that was, that was last decade. And now we're in this era of what can I do with these foundation models? And I, this is, I think we're still really nascent on that, on what's possible.
But I think that that inflection point, that critical change happened when we saw what things like clip were capable of, and that, that structure there is, is just super powerful. And you see, like foundation models, like Microsoft had this, uh, paper from CDPR last year, lawrencei, which is one of those like sort of downstream models that build up on top of a lot of data, a lot of foundation elements, foundational elements, and then you can query it with pretty intricate questions, uh, about the visual data and the performance is, is quite, quite strong. All right.
Well, thanks for sharing that. So if there was one key takeaway you could leave our audience with today, what would that be? Uh, the key takeaway that I, that I like to end, uh, sessions like this would be that even though there's such amazing progress in AI and visual AI and so on, um, I think it's important to always remember that we do this for, for humans.
We are humans. We're building for humans, right? Like, how can we make our society a more balanced, more equitable, safer place for everyone?
All right. Absolutely. Well, thank you so much for coming on the show and sharing your insights with us today.
Thanks, Amanda. Happy to do it. All right.
And thanks to our audience, stay tuned. There's more. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers network. Hello, and welcome everyone to the 5G Factor.
I'm Ron Westfall, research director here at the Futurum Group, and I'm joined here today by my esteems colleague, Olivier Blanchard, fellow research director and practice lead for AI devices here at the Futurum Group. In fact, uh, Olivier has been heading up our coverage of what's going on with AI devices. And naturally in today's conversation, we'll touch on that.
And naturally, we have, I think, a lot of ground to cover here, because there's always something going on, especially in the lead up to Mobile World Congress 2025, the first week of March. And so with that, Olivier, welcome back. I know it's been what, a week.
And so good to see you. Are things coming along, Things, you know, I can't believe it's only been a week. It feels like a month already.
It's been, it's been busy. We, while we've had a lot of, um, reports and dashboards and intelligence products coming out, so it, it feels like the last week was about two or three weeks packed into, you know, five days. But yeah.
Good. I understand. Yeah, No doubt.
No, no, I, I think that it does, uh, I think perception is key. It does seem like it, right? Yeah.
And maybe this week we'll emulate that. Uh, but that's good because that means the ecosystem that certainly the 5G and, uh, mobile ecosystem are having plenty of things going on, uh, that merit our attention and perspective. And yes, our friend AI is playing a role in it.
Uh, however, let's really focus on a, uh, I guess you could say a mobile centric announcement that came out during the Super Bowl, super Bowl 59. And during that momentous event, T-Mobile introduced T-Mobile star link to millions of football fans out there. In fact, uh, this set a record, if I, uh, understand correctly, 126 million people tuned into the Super Bowl.
And that's, uh, including all the different platforms. And that's why a Super Bowl viewing record was achieved, even though the game itself wasn't exactly dramatic during the second half. Now, uh, uh, back to T-Mobile, starlink the important thing here, and that it's in public beta, and it was developed naturally in partnership with starlink, and it's using satellite and mobile communication technology to help keep people connected.
And why is that important? Because quite simply, there are more than 500,000 square miles. That's a half million of the country that is here in the United States of America that are unreached by any carriers, earthbound cell towers.
And that equates to about the size of two texases. Now, I think what's also important about this announcement is just not for T-Mobile customers to trial and test out. I think, uh, it's in July that you have to start thinking about, okay, do I really wanna include this?
And if you're already a a T-Mobile customer with a specific 5G plans, you can pretty much add it on after your trial, otherwise you can add it on for specific bees, but also Verizon and at and t customers can also trial this. And I think this is a smart move by Tmobile, because here is a way to really potentially garnish EO customers from your top two rivals in a way that is, well, obviously legally sanctioned, but also, uh, smooth marketing, certainly from my perspective. And other important takeaways here is that T-Mobile starlink is using specially configured satellites with direct to cell capabilities or direct to device.
And that's orbiting, you know, earth about 200 miles up. And, you know, they're traveling at very rapid rates, you know, 17,000 miles per hour to be specific, to deliver these cell phone signals. And that includes text messages for now with picture messages with, uh, data and voice calls coming later.
And that quite simply is filling a void that, again, earth cell towers can't really address today. And this is, I think, a very important part of, you know, how to we get what can be called universal coverage to, you know, really assure a society without, you know, digital divide, uh, because of, you know, connectivity, um, capabilities, uh, that can't, uh, be, um, reached, uh, the recent past, but now that is changing. So that's good news for everybody.
It's not just good news for, you know, T-Mobile, the mobile ecosystem, but really for society as a whole. And so with that, uh, kickoff, uh, Olier, from your perspective, what are some, you know, important takeaways and, uh, aspects to, you know, this announcement? Yeah, well, fir first of all, uh, it's the mainstreaming of, uh, of satellite or, uh, near, uh, what is, what's the, what's the term?
NTN Near terrestrial network? Yes. Non-terrestrial network.
Yes. Yes, indeed. Um, I, I drew a blank just then.
I was like, I thought I knew this, and it's been a while since I've actually said the words, so I've, I've blanked out. Uh, no, but it's, it's de it's further mainstreaming of, uh, of these networks, uh, by obviously not needing a, a dedicated antenna, but being able to, to access them directly on your cell phone. So, a couple of things for me, I mean, obviously it's, it's part of an evolution.
I think that we'll see this becoming much more mainstream, much more ubiquitous in, in years to come. Um, two, it's a proof of concepts. I know that even I wanna say two, three years ago I was at, uh, uh, 3G PP conference, and, uh, NTN was a big discussion, but there was still some skepticism about like, why would people pay extra for this?
Uh, is it ever really going to be anything more than, you know, a commercial application for truckers or for, you know, ships at sea? Things of that nature. And now we're starting to see that, uh, for, for anything else, just the convenience of it, the security or the sense of security that, that we might feel from knowing that we're gonna be connected from anywhere, right?
You could be, you know, out camping somewhere where there's no, no, uh, uh, antenna cell reception, but you can still be you, you can still send, um, you know, distress messages, uh, or like, Hey, I'm okay messages to your loved ones. So you're never completely isolated if you don't wanna be. Um, and even just, uh, for, for everyday people who don't necessarily travel cross country or go into zones that, um, that have connectivity issues, sometimes things happen, things fail, right?
There could be a natural disaster, like the hurricane that hit the, the Southeast, uh, a few months ago. And that left us without internet or power for a while. Um, there, there could be fires in California, there could be an earthquake, like whatever the reason, having that extra level of service that sort of bypasses terrestrial infrastructure might also be, uh, well worth, uh, the investment.
And, and also having the ability to kind of turn it on and off at will, uh, not necessarily always having it on at all times is not necessarily a, a, a, a bad option either. So I think, you know, this is good for starlink, it's good for T-Mobile. It's a great differentiator for them for now.
Uh, and it's also good for consumers, and it's, it's also a market test. Let's see, you know, after the, uh, the amount of exposure that T-Mobile had, and I thought that was, you know, obviously brilliant. Uh, traditional media isn't dead.
So, um, that ad was really powerful. So now let's see how, how well they convert over the next six months. Yeah, no, I think this is just a great way to start the flywheel to your points to the va.
Yeah, the beta is free, free until July, and I admit, I've signed up for the beta. And what's I think important here is that TBOs, mobile starlink will be included at no extra cost on go 5G uh, next plans, you know, with, um, T-Mobile. So if you're already on the T-Mobile network and you have that plan, well, what's not to like?
I mean, it's a proverbial no-brainer. Also, uh, yes, it's important to consumers, uh, but also business customers can also get the starlink, uh, plan at no extra cost on go 5G business next. So this is really, you know, covering, uh, uh, that additional base.
And I think that was something that's important to underline about first responders. That is first responder agencies on t priority plans, and other, uh, select, uh, rate plans can also definitely, uh, add the service. Uh, and what I think is also important here is that when it comes to the Verizon at and t customers, they can add it after the beta for $20, uh, per month, if I understand that now.
Uh, yes. Uh, they're both also, you know, doing their own direct device, um, trials and so forth. So yeah, this is definitely gonna intensify and pick up, but I think it's a tribute to, you know, the innovation that's gone on with the starlink Constellation Network and enabling this.
And we've seen it no really, uh, prove a lifesaver in these, uh, natural disaster areas for the wildfires, the Southern California, let alone, you know, uh, places like the, uh, Ukraine, uh, Russia, uh, campaign. So, uh, uh, you know, what's, uh, variant vital here is that, uh, this will be a game changer as it becomes just that more mainstream. And to add to this, I think it's important to note that also, um, carriers such as KDDI in Japan, Telstra, and Australia, as well as optis, as well as one nz, uh, the New Zealand and Intel and Schilling, Peru and Rogers in Canada and s uh, star and Ukraine are also on the bandwagon for this.
So, you know, that is, you know, working with starlink in order to bring, you know, this, uh, you know, broader universalized coverage, and that is to, again, MA what can be called, you know, dead zones. Nobody wants that because of just what we touched on. It could be emergency situations, unknown unknowns, and so forth.
And I think that's something that, uh, will just be that a, a feather in the cap for T-Mobile as it, uh, looks to advance of this campaign. Now, with that, let's turn to another important development that, uh, just popped up on the radar, and that is Nokia has named a new CEO, and basically they picked Intel exec, uh, who is leading the AI data center efforts, Justin Hotard. And that I think, uh, from my perspective, is a smart move.
And what I think is important here is one doesn't have to be a data scientist to understand that, that this is also gonna do specifically for Nokia's portfolio-wide AI and data center initiatives. And let's get some of the irony that's been noted out there out of the way. You know, Nokia selecting Intel executive may seem a bit peculiar, given that Intel Silicon manufacturing problems a few years back led to a lot of har heartburn for Nokia in terms of its, you know, uh, mobile, uh, access size, specifically radio access network, uh, capabilities.
And that, uh, Verizon a few years back turned to Samsung because Nokia was not able to, in some key ways, meet the Verizon demands. And what was this linked to? Well, the little history here, there were delays in delivery of 10 nanometer asex for their 5G base station equipment.
And Intel was identified really as the blameworthy supplier in this instance. And that disclosure, I think, didn't really surprise, uh, many people at that time because of the manufacturing struggles that Intel's having at that time. Now, Nibia had then had to pivot to more expensive FPGAs, and that in turn upset its gross margins alongside its technology competitiveness, which then triggered, uh, a loss of market share and that key market segment.
And it, you know, it's been a challenge to recover since then. However, I think this is important to note that was a different era involving a different set of decision makers. So Justin Hoar coming on, I think is really a new level set.
And again, I think it's very wise of them to go in this direction of, okay, how can we optimize AI capabilities across the entire Nokia portfolio? And yes, uh, uh, Justin is, uh, replacing, uh, Peka, Lendmark who I thought, uh, did a very, uh, outstanding job over overall in terms of getting Nokia in better shape over the last four years. It's been challenging.
They face a lot of headwinds. Uh, and also we saw that there was difficulty throughout the mobile ecosystem. So this wasn't unique, uh, to Nokia in terms of what's been going on over the last few years.
Uh, part of it is, uh, you know, was, you know, post covid related, and that is, you know, spending amongst, uh, the carriers on a global basis basically got dialed back specifically on the CapEx side. Now, what I think is, um, helpful in, in the near future is that that will start inching up this year and probably into the foreseeable future due to factor such as, okay, uh, uh, operators exploring how to really optimize AI in terms of, you know, making them more, uh, competitive, uh, that is the service offerings, let alone, you know, the operations and the business processes within the operators themselves. And, uh, just, uh, kind of an additional, uh, reasons why we can say this about, you know, landmark is that, uh, their share price has been improving 10%, uh, over the last, uh, four years.
And that I think is a tribute to, you know, okay, navigating some of these massive challenges that Nokia faced. 1%. All these were really, uh, I would say achievements that, uh, showed that Nokia hit these high marks and that they were best within the last decade.
Now, what I think is gonna be important here is what's next? You know, what can Justin Hotar do to really, you know, make, uh, Nokia more competitive? And I'll stop here because Olivia, I think you might have some thoughts on, you know, why is Nokia really making this pivot to what can be characterized as an AI driven portfolio, uh, development strategy, let alone sales and marketing strategy?
What are some of your insights on this move? Right. Well, I'm gonna take a pass on that question and just like bounce it right back at you.
Uh, I, I think, you know, I wanna know what, what, what you're thinking about it. Uh, but what I will say before, before that is, uh, I think it's interesting that, uh, Nokia is turning to, uh, uh, an AI and data center expert at scale, right? At scaling these services, at monetizing this, uh, to, uh, to, to run.
Its, uh, its company. So it's, I think it's the, the question sort of answers itself. Obviously, it's a pivot to AI and, uh, and they want the best talent on board to figure out how to do that properly.
Um, the, the, this story is so full of layers of irony that we could, we could dedicate the, the whole show, we're talking about it, but obviously Intel's woes are Nokia's, uh, uh, advantage right now, because they're, I don't, I don't know that if, if Intel had had a better year, if, uh, if anybody had been trying to, to look for, uh, you know, Rosie or Verizon. So I think that the, the fact that he's jumping on board with this new opportunity where he's gonna be able to do something, uh, that he might not have been able to do at Intel, uh, something perhaps, I wouldn't say more important, but definitely more important to Nokia than it would've been in Intel. Um, and, and the ability to kind of do this for the next few years and build something really special is, is obviously a part of the appeal.
Um, my question to you though is, um, what's, what's Nokia's game plan for the next, you know, three to five years? Because that's, I think that's, that's the real question. Like, how do they remain not just competitive, but relevance as the, the entire industry pivots to this, uh, to this AI stuff?
Ah, thank you Olivia. And yes, I do have some thoughts on this now. I'm not gonna go as far out as five years from now.
I can change, but I can say now, within the next year, one to three years, what I think, uh, are some important takeaways and, you know, what Nokia can do to just do that, improve its competitiveness, and certainly bringing Justin on is a, a, a key first step here. But I think, uh, you know, specifically it's yes, uh, good news for the data center side of the business. I think, uh, we've certainly seen, you know, like Mike Boong who just came on, uh, you know, relatively recently, over a year ago, and, uh, you know, basically head up, you know, energizing, you know, uh, uh, data center proposition.
And I think what's gonna be integral to this is normalizing what could be, uh, characterized as matter of fact innovation in terms of how Nokia prioritizes its, uh, portfolio development strategy. And that is, you know, things like making it easier to quite simply deploy a fabric. I mean, this is something that you think, oh, okay, it should just be, you know, uh, like do your self proposition for organizations because they're big, they have these resources, they're prioritize, uh, prioritizing ai.
But actually, no, uh, this is pretty much, I think coming out in some of our key recent future intelligence data. Like when we, uh, surveyed 872 enterprise organizations, you know, what is the top thing they're looking at in terms of selecting, say, an AI solution, you know, an overall AI solution. And that is AI expertise.
You know, they want their, you know, key, uh, supplier, their lead integrator, however you want to characterize it, to be the one that's going to enable really a comprehensive full stack vision and approach. And that, you know, would include, I would say, a lot of point products for that, uh, you know, lead vendor. But, uh, ultimately, uh, that is something that is going to be a, a difference maker as, you know, enterprises and so forth, figure out, okay, what is the best step?
How can we rightsize language models and so forth? And this is something I think, uh, Nokia can play a more integral role in. And that also, I think is also, it is simplifying the execution, the daily tasks around things like auditing and troubleshooting.
And this is not unique to the data center. This would apply to all units in Noia, including certainly, you know, the mobile infrastructure side, including, you know, uh, any, you know, uh, software development initiatives that, uh, NOIA, uh, has overtaken, uh, such as telco SaaS. You know, that comes to mind.
And I think this is something, uh, that is not just about the data centers, but really removing, you know, some of these, uh, you know, problems that continue to play, you know, making a real progress in terms of, say, automation across, uh, the data center. What I think this is gonna enable is Nokia coming up and saying, Hey, we have to look at an organization-wide automation plan to really make something like automation more, well, uh, I would say advantageous to the customer that is, you know, improving business outcomes. It's one thing to have, you know, uh, say automation, you know, using AI enabled automation benefits, say, you know, some individuals or some units within an organization, but there, it stays.
It's, you know, pretty much, uh, siloed. But I think what's gonna happen here is that it's going to enable a, a portfolio development strategy and vision that's taking advantage of the intersection of what's going on with AI enablement. That is the workflows, the systems, really looking at the entire ecosystem capabilities that elite integrator can bring to really, you know, make that, you know, strategic difference to, uh, the customer.
And I think it's also making, uh, to your point, Olivia, about integrations more scalable that remove not just, uh, the effort involved, but also the time. And so this is really, I think, a way for Nokia to start looking at how they can show metrics that, okay, we can deliver time to value, uh, let alone time to market value from, you know, our, our portfolio assets. And this, I think, will definitely pull through things such as AI ran, which is kind of like a, potentially a new level set for, you know, how can mobile infrastructure be more efficiently deployed.
And so far, uh, it's still kicking the tires, but we saw with, you know, deep seek, you know, okay, hey, if ai, you know, technology could be a lot more power efficient, a lot more, you know, software agile and so forth at any part of the network, whether it's data center, whether, you know, involves the training, let alone inferencing. This is, you know, something that's not just about, you know, the data center, but the entire portfolio, including the mobile infrastructure pieces and so forth. So, and in head shell, this is a, a very exciting move, and I think this is something where I see, uh, can make an impact in terms of, you know, answering the question why Nokia and how they could be, well, just that, uh, more differentiated, capturing more mind share out there.
And so, uh, perhaps that's aligning with some of your thinking as well, Libby, in terms of, you know, what needs to happen to kickstart, you know, enterprise is getting more comfortable with ai, right? Yeah, yeah. No, I, I agree.
That's like, I kind of wanted to hear it from you because I can see sort of like little bits and pieces of it, and I can see the, the overall shape of it, but I can't, um, you know, I, I focus more on the devices than, uh, than this part of the technology sector. So there are still some, some pieces missing to this, so it makes sense. Um, yeah, and it's, you know, it's, it's too bad for Intel.
They're, they're losing a, a really talented, um, leader and Yeah. At, at a critical time. Yes.
When, and they're already sort of like losing some of the other ones. So, um, yeah, I just, it makes me worry actually. Uh, I think, you know, as good of a, a, a a, a pivot as this is for, for Nokia, or at least the next, you know, milestone in, in their sort of transformation journey, it makes me worry for Intel a little bit more that, uh, some of their best talent is getting poached by, uh, uh, by other industries.
So Now that's a legit point. Yeah. No, I think we're not alone in that observation.
Yeah. And what will you revisit Intel, but I think you mentioned devices. Mm-hmm.
So let look at devices, uh, specifically, and as we know, Qualcomm recently re, uh, reported record Q1, fiscal year 25 revenue. And how did this happen? Well, it was driven by strong premium tier handset demand, and also continued momentum and key segments such as automotive.
And this, uh, really, uh, resulted in its sex, uh, six consecutive quarter of record revenues. Now, also, I think important to note is that all come CDMA technologies or QCT revenues surpass $10 billion for the first time while AI adoption across devices gained yet more traction. And so this is, I think, a real compliment to, you know, you know, what's going on with Nokia, and, you know, what can be characterized as, you know, some of the infrastructure, uh, developments.
And I think what's also important about, about the Qualcomm, uh, results is that, uh, it noted that Google Cloud and Meta are among the early adopters of its own AI infrastructure initiatives, as well as that Verizon and Google Cloud are partnering on advanced AI services for network maintenance and anomaly detection. And so while there's, you know, that those are certainly, you know, uh, the strengths, uh, but we also have to look at, you know, uh, you know, the concerns that might be out there. And that I think revolves to Qualcomm's technology licensing business or QTL, uh, there's, you know, ongoing negotiations with Huawei.
And again, uh, that might, uh, have, you know, some impact on near term revenue stability. But overall, you know, I think, uh, you know, the results are pretty positive, even though there was some sell off on the street, you know, IEA bit of profit taking every, every time, Every Time. Yes.
Yes. And it, it seriously qualcomm's expansion to IPCs, uh, automotive xr and also AI driven iot segment segments. It's, I think, validating its, you know, long-term growth strategy the Christiano Amman has implemented.
And I'm gonna stop there because, you know, uh, Olivier, what do you think about Qualcomm's recent results? What are some things that leap out at you? Right.
Well, many things. So, first of all, I think that it's definitely a, a val, I mean, time will tell, 'cause we're, you know, there's still, there's still time to go. Um, but this to me, is, is further validation that's, uh, christiano's, uh, diversification strategy for Qualcomm that if he sort of kicked off when he became CEO, uh, a few years ago, uh, is paying off, right?
A lot of people are wondering, okay, like, we started out as Qualcomm being a, a, essentially primarily a mobile first company, right? So you had some network stuff, but it mostly, it was mostly like modems and the SOCs for, for, um, Android devices. And that was, you know, they had a few other products, but that was essentially like their core thing other than licensing.
And then we, we started seeing Qualcomm go into devices. So, uh, you know, smart watches and smart speakers, and, you know, hearables and wearables, uh, uh, they, they went into, obviously, they, they, um, provide most of the processors currently for high-end xr. So all the meta stuff, Google, like, basically if, if you're, if you're wearing some kind of augmented reality, virtual reality, mixed reality, uh, glasses or smart glasses, there's a really good chance that Qualcomm tech is powering it.
Uh, obviously they have a huge play in automotive, right? Their digital chassis and their, um, their Snapdragon automotive products. And, and this year they went this, they, this, they did this leap into the, uh, PC segment.
So, uh, where we initially had essentially just Intel and, uh, a MD on the X 86 side, and you had Apple over here, and, uh, and you had Chromebooks. Now you also have arm base Snapdragon processors powering a I PCs. Uh, they were the first to market with Microsoft with this, and then Intel at a MD followed.
Um, so they've, they've sort of like created all of these different runways to growth in addition to mobile and some of the network stuff that they had before, and IOT, and what we're seeing is that it's working, right? Um, so I, I think that's kind of like the, along the broad lines, this diversification, this growth by chasing these different verticals that are very high growth, very popular right now with the most potential, uh, for expansion, uh, has been spot on, like they've been on Target, uh, a hundred percent. So I think you, you said it, um, automotive grew like 60 plus percent.
I think IOT grew over 30% as well. Uh, and then mobile was, uh, was pretty great. And then a, I, PCs, actually, it's still too soon to tell, but we just conducted a really interesting study of the A IPC market specifically for the enterprise.
So we left out, uh, the long tail of small to medium sized businesses. We didn't look at, uh, consumer yet. We focused on, on enterprise first, and we pulled almost 900, um, it decision makers in the enterprise space.
So big, big, big companies just see, kind of like where they are with your A IPC adoption journey, uh, which processors they like the most, which ones they intend to buy for their, you know, the systems, like if they're gonna be powered by Intel, A MD, apple or, or Snapdragon, uh, which is Qualcomm's product. And we're already seeing that the, the intention, or at least I would say, um, when we asked all these IDMs what their first choice is so good for Intel, Intel is still number one still that could change in the future, but right now they're fine. Uh, number two was a MD just because it's Index 86 systems.
So it works really well with the enterprise. It's proven, uh, at, at best, they like it better than Intel. At worst, it's a really good backup, uh, in case Intel can't provide a part or there's a problem.
Uh, but Snapdragon, which is a new entrant into the space that has only been around for six months already turned up 15%, um, of IDMs basically saying that that's their first choice. That's how impressed they are with the ARM-based Qualcomm made Snapdragon X, um, a I PCs. And, and so all of that brings me to kinda like the bigger points and the bigger trends in the industry and why I am probably here.
And it's that we're seeing an expansion of the AI ecosystem from cloud, right? It used to be data center because you just, it requires so much power and, uh, uh, and processing power. And so the GPUs and, and all of this, all these massive resources to be able to train these systems to collect the data, process the data, just do all the, the, the training and the inference.
But what we're seeing is that there's, um, and in great part, thanks to Qualcomm, we've, we're being, we're, we're able now to move a lot of these AI workloads directly on device. So we're going from the cloud out to the edge, um, and whether it's an IPC or a new smartphone, like, uh, Samsung's, uh, galaxy S 25 series, which we talked about, I think last time it was on, uh, that just launched, uh, a couple of weeks ago. Um, the on-device capabilities for AI are so incredible that it's actually cheaper because you don't necessarily have to pay for subscriptions or, you know, tokens for, uh, for a cloud service to do that for you.
Second, um, it's, it's, it's really great because, uh, there's, there's that immediacy of interactions, especially with agent tech ai, as it is sort of like embeds itself to our user experiences. When you're interacting by voice with an assistant or an agent, and you're asking 'em to do something, or you're asking 'em to answer a question, um, if your, your query doesn't have to go all the way through the pipes to, uh, a data center in the cloud, uh, where it's processed, and then like the answer comes back and has to come back through, you can have, you can have an immediate conversation with your, with your assistant on device that's gonna feel natural, that's gonna feel like you're in the same room with somebody without that delay. Uh, there's some some security advantages too, to having, uh, those agents directly on the device as opposed to in cloud, less risk of interception.
Uh, your data can remain secure. Even the training of, um, of, uh, of an agent over time with your preferences, the types of things that you ask when you ask them can stay on device inside of a firewall so that nobody has access to that. So there are a lot of advantages to moving, um, these workloads, uh, to, to devices.
And if you look at it more holistically, especially for the enterprise, the one of the advantages also is that you can have a more federated distributed AI ecosystem where you're not just depending on cloud, um, if you need to, you can even network a bunch of devices together to work on bigger problems that might be too big for one device only, but not necessarily requiring, um, you know, a, a, a cloud-based solution to run it. So, um, you know, I, I think even, um, the, the warning shots that we got, uh, a week or two ago, I can't even remember how long it's been now with deep seek and the whole notion that we now have, um, AI models that can be trains on a, a fraction allegedly of the resources that we thought they could or they needed, uh, sort of plays into that. Like, you, you can, we still need the data centers.
We still need to build them. We still need the big GPUs. That doesn't change, but the, the trend towards smart devices being, um, a lot more capable of, of doing infrared for sure, and eventually becoming better and better at training, uh, is gonna be kind of a game changer.
And where it's, it's most important, I think, is in, uh, not just the PCs and, and, you know, other devices, but it's gonna be in the automotive sector. And so for that, the, the two things that you need is you need, um, processors that are very good at, at doing AI workloads, right? So new, new processing units or, you know, GPUs that work really well in conjunction with the rest of the system, uh, is one piece of it.
But where Qualcomm is, is especially good 'cause they have, that part is they do it at low power. And, uh, when you're looking at devices with, you know, small batteries, uh, or that have to process a lot of stuff, um, and you don't want 'em to overheat, you don't want 'em to need a lot of energy, it's really important for those systems. So those processors to have extremely high output at very low power and be thermally efficient so that you don't need like massive fans to cool 'em in.
And that's where, um, that's where Qualcomm excels. That's where they have an advantage. So they kinda have the best of both worlds.
Um, and the types of form factors that we're talking about from automotive all the way down to, you know, smart glasses, watches, phones, laptops, tablets, um, you have this sort of, you know, extremely advanced AI capability coupled with this very low power, uh, performance characteristic, uh, where essentially it's just like the best performance per while on the market. And, uh, and that's why Qualcomm's numbers look the way they do that diversification with the right type of product for those applications that work extremely well with AI workloads. That's, that's kind of like the, the, the sort of cheat code or the cheat sheet to, uh, to Qualcomm's continued success.
I think. Um, and you know, I, I don't for prognosticate, but I don't see a reason why, um, Qualcomm wouldn't continue to have really good quarters, and because they've diversified, should one of those areas sort of, you know, slow down a little bit. Let's say the automotive sector slows down, uh, for a quarter or two, it doesn't really matter because they have all these others.
They're also growing. So there's, there's this constant sort of hedge against, um, sort of market slowdowns in different categories and Qualcomms there, as opposed to having all their eggs in one basket like they used to. Yeah, no, I, I, uh, fully concur with those insights, Olivier, and I'm gonna step outta the limb doing a bit of pro, uh, prognostication.
And that is, um, when it comes to, um, uh, just a snapshot of the IOT segment. And the reason, uh, why I'm doing that is because recently I was at the, uh, Zoho analyst event, and it's like, okay, Zoho, you know, they, they are a CRM specialist, you know, uh, what does this have to do with IOT? Well, lo and behold, uh, just in September of 2024, Zoho decided to toss its hat into the IOT segment, uh, specifically, uh, pursuing, uh, market opportunities in areas such as, uh, smart buildings, uh mm-hmm.
You know, manufacturing, uh, energy management and so forth. And, uh, they've done their homework, you know, their portfolio development strategy. They realize, Hey, if we could incorporate these things with an overall CRM platform, that means, you know, extra revenue generation and so forth, paralleling Qualcomm's own overall, uh, what, what do you call revenue diversification strategy that is really, you know, making a huge difference for them.
And I believe in 25, we're gonna see the iot segment, uh, grow. Uh, you know, I would say not just an upward, uh, trajectory, but also robustly. And a lot of this is, I think, related to, you know, the fact that snapdragons AI capable chip sets are delivering those low power capabilities that you pointed out, Olivier.
And that could be, again, and a driver for, at at least industrial iot, uh, growth. And, uh, paralleling that is that they, I'm seeing that Qualcomm aware platform continuing to gain traction because it's integrating these AI powered monitoring and location capabilities across some of the segments I already touched on, such as, uh, you know, retail logistics, but also, you know, smart home applications. And, you know, paralleling that as well is Qualcomm's on-prem appliance inference suite, which is, you know, helping enterprises with private AI deployment solutions.
Something else that I think will have, you know, some, uh, market progress throughout 25 and beyond because of rising demand for wifi seven 5G FWA and really what could be, uh, called the e edge computing market, uh, which I think, um, will, uh, I think, um, be somewhat buffered from, you know, potential tariff, uh, outcomes, which could impact, say, the automotive segment more. Uh, uh, but again, uh, if you're looking at, you know, the overall picture, these are positives for Qualcomm and this cross pollination, I think we're gonna see more of it CRM vendors jumping to iot and so forth. And, and so this is good.
I think so too, a good, I think, um, I think the, the industrial IO OT or what I, I prefer to call commercial IO ot, uh, segment is, is probably going to see a resurgence this year. Mm-hmm. Or at least start to, uh, it, it was kinda like, you know, an exciting thing, an exciting space for, for a minute, and then it just sort of fizzled out, just flattened out.
Um, but now with low power AI capable cameras, I think that especially cameras and, uh, drones are, are going to be hot this year. And what I'm seeing with Qualcomm, first of all, uh, at their, their, uh, analyst that in New York a few months ago, they spent way more time on the industrial IO OT than they normally, than they ever have. Uh, and more so than they did, uh, even with, uh, with automotive.
So obviously it's their Netflix push, um, but also what I'm seeing is a lot of services around it, a lot of orchestration, and, and I found that interesting. Um, so yes, I think you're on the right track with this. I think that we need to watch the iot space, uh, because it's, uh, it's gonna get hot.
And my, my question too is how much of that is, is wifi, how much of that is, uh, is 5G and, um, especially like private networks? And I think that there's, the verdict's still not out with that yet, but, uh, that's gonna be an interesting, uh, interesting, um, uh, ecosystem to watch, um, to see where it goes the next couple of years. But yeah, definitely, definitely keep an eye on the AOT space.
Yes. Yeah. And, and to your point, Olivier, uh, Qualcomm made a splash, I believe, at, uh, last fall's embedded world North America, the first time embedded world has come to, uh, north America, and that was last October in Austin.
And so I think that is another indicator, like this space is getting momentum, you know, the, the major shows are now diversifying on a geo basis. And, and that is, I, I think proof positive, like follow the money. They're, they're not doing it because it's fun.
It's because, yes. Uh, revenue generat, well, maybe A little bit, maybe a little bit, because it's fun, but yeah, definitely Fun city. Yeah.
Yeah. It's, it's, it's more than a sushi and karaoke. There's also live music and barbecue, right.
So, exactly. And well, hey, this is great. I think, uh, this is, uh, really touching on the, the, uh, the key, uh, things that jumped at us, but there's gonna be plenty more.
We'll be back next week because we're getting closer to Mobile World Congress itself, and I think this next episode will focus more on, uh, what, uh, I think our MWC, uh, 25 specific, uh, pre announcements. And so that, that, that will fill the cupboard. And again, thank you Olivier, uh, for joining.
Uh, again, uh, lots of, uh, I think great takeaways and conversation. Yeah, thanks for having me again. Thanks for keeping inviting me.
Like I'll, I'll keep coming. Right on. Yeah, the invites will just keep, uh, flying out.
Sure. And, uh, also, uh, with that, uh, don't forget to tune into 5G Factor, you know, we're on, uh, the Future Group, uh, website, bookmark us, uh, and also we're featured on Textron tv, also, you know, part of the future and group family. And, uh, with that, uh, again, thank you everyone and have a great 5G and industrial or commercial IOT day.
Hi everyone, this is Axel Launa from Argentina, and I'm glad to be here with all of you in the DevOps experience, 2024. Uh, I hope you like this talk. We are going to, to chat about platform engineering and finops that, uh, they are both, uh, true trending topics nowadays.
Uh, so what we can start right now, uh, we'll start with finops. Uh, it's a, a term we are using a lot nowadays. Um, and what this is about, well, finops is the practice of optimizing a cost in cloud, uh, without sacrificing speed, quality, or security, because, uh, it's pretty simple, uh, for anyone to, to cut costs, right?
Uh, without considering these three points that are quite important for our applications, uh, without quality or security, uh, there's no chance to get an application to production. So the challenge here is to maintain all of these three pillars, speed, quality, and security. And at the same time, uh, taking care of the, of the cost we are, uh, we are having in the cloud, right?
Because sometimes we just move our applications, we, we modernize them, or we just migrate to the cloud, but we are considering cost. And when the, the bill comes, it's like a short surprise, right? Uh, well, this practice, uh, has that, that intention to, to cut those costs that are unnecessary or maybe, uh, that comes with, uh, for example, um, resources that are not used properly or that oversized, uh, well, those things and not more, uh, comes with, with finops.
And just to dip, uh, a little, uh, more into the framework that finops give us, it's like Scrum, for example, scrum, uh, give us like a, a framework like some, uh, guides. Uh, it's not a recipe for success, but it's just a guideline to, to follow, uh, and to have like, uh, better practices and a good roadmap, uh, to, to transition this cloud cost optimization process. So the, the first time, it's, uh, it's very important to maximize, right?
The, the business value in the organization, aligning those strategies that the business has with technology. Most of the times, they, they are treated separately. Uh, so, uh, that, uh, brings like, uh, a lot of issues on arguing because business wants something, technology says another.
Uh, so the, the, the first recommendation, the first guideline here is to work together to align strategies, right? Uh, and to have like a smooth process involving everyone. Uh, we'll see that, uh, Phillips framework give us like, uh, a couple of roles that are suggested from each area and each, uh, specialty.
Uh, so the, the point here is to work, uh, as a team from the start and aligning those strategies. The other thing is, once we have those roles or those people, uh, into this process, uh, and this exercise, uh, we can incorporate processes, skills, and tools, uh, for both engineering finals and business teams, right? Uh, the, the idea is to give all of them different skills, processes, and tools to make the, the job done right.
Um, we'll see, uh, in the couple of slides, um, some tool that we have to, to work with. Uh, but if you enter to the finance, uh, dot org, uh, page, you can see like, uh, a lot of suggestions, tools that are aligned with these practices. Uh, and select the, the best option for you, for your company, the, the one that is more suitable in the, in that specific time of, of your process, right?
Uh, maybe one tool, it's useful in one particular time, but then a couple of months later, when you are like more mature in your process, you will need to replace it or to add some other into your pipeline. So finally, the, the idea we were, uh, talking before is to, to work collaboratively, uh, and make data driven decisions. That's very important, uh, because sometimes, uh, this, this kind of process where business on technology argue because they don't know very well each other, and the, the discussion, uh, is about we don't need security, we don't need quality, we don't need this tool.
Um, it's, yeah, about feelings or sense sensations or, or, or maybe like it's, uh, like, uh, something that's not valuable for us in, in our point of view, but it's for the others. So, uh, to avoid all those things, uh, it's important to have data-driven decisions and these tools that finops give us, uh, help in, in that way, right? We, we can also add a lot of more, uh, complex, uh, ideas, tools, and processes, but, uh, we can start small.
Uh, that's an important thing, starting small, uh, but always having like a data driven decision process, right? That, that's the, the ultimate thing, uh, is very important to start with in, in this process. Then the, the other thing we are gonna talk about, and it's like very related to its platform engineering.
Uh, maybe you have, uh, came across with, with this term, maybe not. Maybe you are just, uh, someone that's working in technology or business, and you start hearing about DevOps, DevSecOps, SRE, uh, platform engineering, CloudOps, master goal, all kind of terms, uh, right. Uh, so what is platform engineering about really?
What's the difference between the other roads? Well, just to give like a, a quick idea, for example, let's say that, uh, we have three teams, uh, in, in the company that are three squads, uh, software development, uh, teams or DevOps teams, uh, whatever you like. Uh, but the important thing here is that every team has its own process, its own tools, its own way to develop.
So, uh, when you have, like, in this example, three teams, it's like more manageable. Uh, it's easier, but if you think of that organization, of that structure in a larger company where you have like hundreds of teams, uh, it starts to, to become very hard to manage all those processes. And you have like the standardization issues.
Uh, you have, you find it yourself like managing as like hundreds of tools, because one team uses, uh, AWS and GitLab, another uses Azure and GitHub, maybe some other GCP and Jenkins, and it's very hard to maintain standardized and ensure the quarantine and security in all teams, in all tools. So, uh, that's where the platform engineering comes in, into the scene, right? Um, and what's the, the principle objective of, of this team well is to standardize those tools, those processes.
It's like, uh, a center of excellence sometimes, uh, but the focus primary is to standardize tools and processes. Uh, this, this team is in charge of selecting the, the toolkit, the processes, the frameworks that are gonna be used, and then, um, start helping teams to develop their own, uh, for example, tools, scripts, templates, pipelines, uh, for their own teams. Uh, the, their work is about, uh, again, creating, uh, a platform where those resources are, and every team, it can be like a, a DevOps software engineer, a a quality engineer, uh, can go to that platform and, and use all those resources that they need for their squads, and also, uh, to personalize, to customize those resources and that process.
Uh, there's a lot of feedback from the teams that the platform engineering team can absorb and how, like, uh, this, uh, continuous process of evolving this platform and the resources they give. So at first, it, it can seem that it's like very hard. Uh, it's a lot of work to do that involves a lot of, uh, teams, a lot of processes and areas that have to some read.
And, uh, in this moment, I would like to, to share, uh, our experience with, with my team, um, in fact, um, this is, this example is about starting small, right? Uh, because it's the, the first steps are the, the harder to take, and the ones that, um, are, is harder for us, uh, to step into, right? Uh, so we started, as we can see, uh, in this small video, we created this for a Latin American client.
This, uh, like platform may say, uh, we have a, a ripple, uh, a repository of code where we started like this, uh, platform where all resources are, we have like templates for pipelines, for building blocks for Terraform. Uh, we have scripts, uh, we have guidelines for Docker, Kubernetes, uh, we have all that kind of things. So every team can go to that ripple, plan it, and use it for their own good in the team that are working.
Uh, again, the, the idea here is to start small, because there was nothing to start with. It was, we are a like, uh, in, uh, in, in zero. So, uh, the idea of starting with a big platform with a, a big budget, it was, uh, like very hard, and it wasn't an option at that moment.
So, uh, our idea was, well, let's start small. Let's start with something. Um, and what this is, was, uh, this was our, our first approach to, to this platform.
We can see lot of code here that, that we have it. Uh, and this particularly is a tool that we start with thousand using, uh, it's called Infra Cost. The idea of this tool that is recommended by the finops organization also, um, the idea is to know in every, deploy the cost of our infrastructure, right?
Um, and what's the, the, the good point here. When we, um, integrate this tool into our pipeline of continuous integration and deployment, um, we are making every person in the team responsible for taking care of infrastructure costs, right? Uh, the idea is to not wait until the, the end of the process to gain, uh, this, uh, fins team and tell us, uh, hey, the, the costs are going up, what's happening?
Uh, we don't want to wait until that point. So we took our, uh, our possibilities discussed with, with the whole team, uh, and our first approach was, okay, let's deploy this inco, uh, tool. So in each pr, in each pull request that we made, uh, this pipeline runs previously just to check the differences in the, in the infrastructure that there will be with Docker, with Kubernetes, uh, it will see the, the manifest and the differences, and, uh, it will calculate the cost that we have and the differences between this new version that we want to deploy, and the previous one that it's been deployed.
Uh, lastly, so when a person comes to this pool request can also see as a comment the differences in cost that infrastructure will have. So, uh, the team can see at, at firsthand the, the differences, the difference in, in cost, and decide in that very moment if it's going to accept the poor request or not, if the differences in cost is aligned with strategy with the objective in the sprint or not. So in, in that very moment, in that point of time in the development process, we can know exactly how much will cost the infrastructure of our application.
Uh, that's been a, a, like a, a great impact for us because, uh, there was, uh, like a small amount of people that, uh, that have that information that, uh, we, we were in a, in a passive situation, uh, where we deployed our infrastructure or application, and we started, uh, and we prayed, uh, not to have like, uh, uh, someone telling us that our, uh, RVs were too high. So we, we wanted to, to go from that passing situation to an active one and deploying, uh, this tool that it's, uh, open source. Uh, it was, uh, a great, uh, a great, uh, start for us to, to change the dynamic we were having.
Uh, and this is what, this is a very good example of how we, we make the whole team responsible for the cost, and not just only like a few people in the organization, we have to work together. As DevOps say, you build it, you run it, you are responsible for your own, uh, for your own application. So, uh, that's, uh, a very, a very good point, uh, at this, at this situation, right?
Um, well, here is like the, a little demo as you have been watching, of how we, we deployed, uh, these changes with, with Docker, with Kubernetes, and well, uh, that's a, a, a small example of what we have done with this tool. Um, as a bonus track also, um, maybe we, we always think as finops as just looking at the, at the bill and reduce costs and talking with people about what we are gonna, uh, reduce or, or to remove. Uh, and sometimes also with platform engineering, we just think about, uh, an internal development tool or platform.
Um, but there's space for a lot of ideas, a lot of practices that help us, uh, uh, in this direction. One of, one of these tools is the chaos engineering practice or philosophy. Um, chaos Engineering is, is a discipline, uh, of running intentional experiments on, on our system or our application.
Uh, and, and the point is to inject, uh, precise and measure damages on our application infrastructure. The idea is to, uh, to measure the silence of our application and system and how it responds to different situations. For example, how can we connect this with our talk about, uh, fine apps and platform engineering, for example?
Um, one thing that we can experiment is the, the size of our resources in the globe. Maybe some couple of resources are too big and they are too expensive. Uh, and we have this doubt that what happens if we shrink it, we, we make it smaller.
We change the, uh, the dimensions. Uh, what will happen if that, uh, thing is done Well, this practice, uh, can give us those, uh, experiment spaces and, um, those, uh, those metrics, for example, uh, we can test, uh, the, how the, the system responds, uh, how the, the request, the volume is managed with those different, uh, sizes. Uh, so it connects directly between the chaos engineering experiments and this kind of, uh, intention of reducing cost, and always, as we said, uh, keeping in mind security quality and speed.
Uh, so, uh, to sum up, it, it, it aims to, to help us improving our systems, uh, knowing with experiences with technical and objective experiences, how they respond, uh, with different types of failures. Uh, what happens if we inject, uh, latency in the network, how we reduce resources. We, uh, we can, uh, remove some parts as of the application maybe that we, we don't need really, uh, it give us space to, to play, uh, a lot following like the, A method, right?
And, uh, dipping into the, the cough thing, uh, chaos engineering always, uh, keep us in mind the cost of downtimes, right? Um, there's, uh, an equation, the formula to know the cost of our downtime, and it's basically composed of three parts. Uh, the ones that happens during the interruption of the service with the, the lost revenue and the productivity of the people because they are developing something new, something nice virtual for application, and they have to stop that work just to, uh, extinguish a fire, right?
Uh, so that's, uh, another big loss we have for, for the business. After the interruption, once we, once we are running again, we are productive. Uh, we have client charges for examples for a regulations service level, agreements that are not fulfilled.
We have another big cost there, and some others that are not necessly measurable. For example, the brand defamation. Uh, for example, if we are like, uh, silver Monday, black Friday, uh, are, we enter 20 commerce to buy like that PlayStation five, I, I really want, uh, imagine that I will click on the buy button and it doesn't respond, and I have then, uh, 4 0 4 error.
I will be like pressed, I'm, I'm going to another eCommerce side, and I will buy it happily. So next time, I'm not going to buy to, to the, to the first site. Uh, I'm going to, to the second one.
So, uh, that's not easily vegetable, but that's, uh, a cost that implies the downtimes and not being prepared, or maybe focusing too much in the cost reduction and not thinking in quality security speed. Uh, so, uh, just to, to have like a, a, a clear number in ahead for each hour of downtime. A typical company loses $3,000, $300,000 per hour.
Amazon, for example, per hour losses like $13 million. So, uh, what's the point here again, uh, is always focusing in cost and in quality. We have to balance those things to reduce RBLs, but always having in mind the application, right?
So again, it has to be like a, a very synchronized work between business and technology, some tools to practice chaos engineering, uh, some of them that are very famous like grumbling. It's a, it's a great platform. Uh, it has, uh, a lot of, uh, certifications, free certifications and trainings that I recommend.
I have done them all. Uh, I like it very much. Uh, I started with chaos engineering because of rambling, so I recommend it.
Uh, it's a paid, uh, software, but it really, um, gives value to that cost. Uh, on the other hand, we have, uh, some other tools that are open source lead most, for example, it's a great tool, uh, that I adore. Um, some others are more famous like Chaos Monkey with Netflix.
Um, and obviously, uh, cloud providers offers their own tools, uh, AWS Azure, uh, have their own. So those are also great options to start with chaos engineering. But as I said before, uh, if you think that this is a, a good tool, uh, to start experimenting, uh, Grambling has a lot of documentation, very nicely, very well organized.
So, uh, it's a good start to, to read, uh, how to start doing case engineering again, uh, from scratch with small steps. I know, uh, we are running out of time, uh, it's sent to, to wrap up. So the, the key here is, uh, again, to align business with technology, right?
Uh, it's very important, uh, to do that as we have seen with examples and the impact both on the applications and the business if we have downtimes, for example. Um, and then lastly, uh, we financially efficient, uh, since the moment of the, the design and the development of the solution, uh, it's like a very good practice to ship left, uh, everything we can. So it's cheaper is easier for our valve to, to have that in line, um, just to, to have a, a nice closure.
Um, there's a, this, uh, this code I like very much that we're nothing is certain, everything is possible. So, uh, when we have these, uh, new practices, new frameworks, and we don't, uh, we don't have clear or, or we're not certain of, of the next steps, uh, the good thing is everything's possible. Just, uh, you have to challenge yourself and challenge others, uh, to start practicing, to get into, uh, new tools and develop, uh, new ways, uh, to, to create, uh, value to, to the business, to the people.
Um, I hope this, this talk has been, uh, interesting for you. Uh, anyone who wants to keep talking about this can, uh, reach me in LinkedIn, in Instagram. There's the, the cure, uh, to, to have my, my contact.
So, uh, that's it. Uh, thank you very much. I hope you are enjoying the dev experience 2024 and I'll till next time.