Techstrong TV – February 28, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. So are AI agents unionizing? I don't know.
You're watching Text on Gang. Hi, everyone. Happy Friday, man.
Where did this week go? It was a crazy week, but it went so fast. It's like a blur in my mind, but I'm happy for us to be here on Friday.
I hope you've got great plans for the weekend. I do. It's supposed to be nice down here in South Florida for a change, so I, I may even get out on the boat and do something.
But until then, we've got a lot to cover today on the gang, and we've got some of my favorite gang members on here with me. We've got our, this is the West Coast, east Coast, the coastal elite lineup, right? Coming at you.
But out on the West Coast. First of all, she is our, oh, editor, radio host, analyst, marketing guru, and everything else. Our favorite.
Lisa Martin. Hey Lisa, how are you? Hey, Alan.
Doing well. How are you? Very well.
It's good to see you out, out Pi I like, I like the look with the glasses and the stripes. It's happening. Thank you.
And I Can see it's Brilliant. Yeah, no, that always helps. Always helps.
Speaking of seeing Perched high at top Silicon Valley where nothing gets done without his purview of it, it's our editor at large, Jon Swartz. Hey, John, how are you? I'm good.
It was a crazy week and it was overwhelming, but as a wise man from Harrison, New York has said it beats the alternative of not enough news. That's right. Speaking of the Wise man of Harrison, New York, he is the dean of, uh, of Techstrong, as well as Harrison.
He's our Chief Content Officer. It's also counting down the days to opening day at Yankee Stadium. Someone got him tickets.
This is true. Um, our Chief Content Officer, Mike Vizard. Hey Mike.
We might have, uh, some single digit weather here this weekend, but after that it's looking good Spring's here. All right. Spring Spring's Eternal and everyone thinks they're World Series contender at this stage of the game.
That's true. Not not, not us Giants fans. Anyway, carry on.
I too, your record is still zero. Zero, John, just like everyone else. Alright.
I like you're up, you're tied for first. Uh, you're also tied for one day. Exactly.
Anyway, guys, it's a, uh, segments we're gonna cover. Mike, why don't you kick us off? I teased it a little bit.
Are AI agents looking to unionize? Do they have rights? So every time we turn around lately somebody is launching an AI agent, and there's gonna be a debate about whether or not I need an AI agent from every software provider or whether I'll get something from somebody who has a platform that manages multiple applications.
But these things are gonna be pervasive. But it, a debate has emerged, and I think it got started with the folks at Workday when they announced that you could manage your quote unquote agents through their HR application. And that started this whole conversation about, well, is an agent gonna be an employee?
Is this somebody I'm, or something that I am going to hire for X number of hours as a week to perform a task? There are at least a half a dozen other models for paying for AI agents, including outcomes and, uh, traditional software licensing. But Lisa, this conversation is starting to pick up, and I don't know what you're seeing out there, but from my perspective, it's the wild mile west.
It is literally, especially where Workday's down the street from me here in Silicon Valley, it's such an interesting topic because one of the first things that popped into my mind was, who's gonna pay the employee employee tax? But we're seeing role-based agents versus task-based agents doing a lot of jobs, recruiting expenses on the, on the part of Workdays Illuminate, for example, succession optimization. And a lot of these agents on that are working today are following step-by-step instructions like an employee would.
Um, Workday's, CEO, Carl Eschenbach, I remember him back from the VMware days, says, you know, task-based agents have to evolve into role-based agents. That's what Workdays kind of differentiating themself on, which contain this configurable set of skills that give them more autonomy and better able to support humans in their roles. But it does beg the question of are they going to be treated as employees with some of the tasks that are being offloaded from humans to them?
How are they coexisting together? It's an interesting debate. Um, op key also introduced a suite of AI agents to its lifecycle management platform for ERP applications.
Um, and the goal is to augment individuals. So I think there's a message there that needs to be really, really clearly defined from enhancing augmentation versus replacing on the human side. Alan, when I look at this and my, my cynical nature comes into play here, and I, software vendors have been trying to put their hands deeper into the pockets of businesses for as long as I can remember.
And there was always this case that says, we're gonna price this based on value to you as the company. But, um, is this just another effort here by the software providers to kind of experiment with a different business model that maybe drives more revenue to them, but increases our total costs in ways that are not really sustainable? Look, software software companies wanna make money.
Like girls wanna have fun, right? As someone once saying, but that, that being said, this one's a little different and, and it's been tried before, but the, I think the value prop here is by using these agents and, and this bleeds into our B block, by the way, by using these agents. Are we lose, are you using less people?
Because when you look at most businesses, their most significant cost are people. I mean, I've been a founder and a leader, you know, of companies for executive companies for many, many years. Your biggest cost are people always, unless you're so in something very, you know, manufacturing intensive where, uh, uh, supplies cost, but it's mostly people.
So if you are telling me that the, the right metric to measure these agents' value is my decrease in people cost. Well, that's, that's not productivity. That's not, you know, that's a whole different scale, if you will.
And, and I think, you know, it's, I think people are gonna swallow it. I, I, as a matter of fact, I think a lot of business executives already have swallowed it. They're already thinking, oh, this AI is gonna let me lay off a couple of heads.
I'm gonna have people, and, you know, they're wrapping their hands in, in glee. But, um, so that's, that's the metric here. And this, so it, and, and for the first time, this truly is potentially true, right?
I mean, this, this could be a reduction of workforce of, I was just, we were talking off camera, right? A Gartner report. You could see a reduction in workforce of five to 10%.
And wow, that's, that's significant. That pays for a lot of these agents. Now, of course, the devil's in the details.
Is this agent really, are these agents really going to replace people? And then, then the issue is, are they employees? Right?
So, look, in legal terms, an agent is a very specific legal entity. When an agent acts on your behalf, you are liable, right? He's your agent or it's your agent.
Similar thing here, right? What about the liability of what agents do? Is that gonna be the software producer who produced?
The agent's gonna be liable? Is it gonna be you because he's the agent is quote unquote employed by you? Are you gonna be liable for it?
Right? This opens up kind of a whole new can of worms for lawyers there who are also rubbing their heads. And these lawyers love to get new cases of first impression here that we can, you know, run up the flagpole.
So, I I, I do think th this is, uh, in some respects a brave new world, right? If you're a fan fan of robots in Asimov, you, you can take some lessons and cues from it. But, you know, the, do we need to put limits on what these agents can do, right?
We, you know, agents don't get sick. They could work 24 7, uh, you know, until they don't. Right?
Why do agents have feelings? Do agents dream? Uh, well, nice Philip Dick reference.
Yeah. And you know, this, this is, so, there, there's no timeline on this, but this is the end game. Alan, you were spot on.
You know, Salesforce and Nvidia are discussing these things called digital workforces. I was just talking yesterday with a friend of mine who does consulting work with Salesforce. He, he, he's considered within Salesforce and a Benioff whisperer, which is the reference to Mark Benioff.
And with, even within Salesforce, they've developed a couple of these concepts. One of them is called the Quiet Erosion of entry level jobs. So they're convinced that these AI related jobs or tasks will replace the lower level jobs, and they're actually referring to the agents as ES or virtual employees.
So we've got this, we also have this idea, I mean, not to get too, too cynical, but the federal government, what's happening with Doge, et cetera, I think some of the tasks, they, they're gonna try to find a way to replace the tasks of humans within government agencies with agents. I think Amazon's gonna do this with warehouses. They've, they've made it clear they, they're dropping breadcrumbs everywhere.
The, the only question is the timeframe, but I think it's inevitable. And I think we're gonna see a lot of loss losses of jobs where people can't adapt, which will create all sorts of union issues, all sorts of culpability issue, corporate governance. It's gonna be wild.
You know, I'm sorry, go ahead, Mike. In theory, You can argue the other side of this though, right? So it's pretty clear that we or may not have enough workers, 'cause the boomers are gonna retire and there's not enough of air folks running around.
So maybe we do need to have AI agents handle more things. And maybe the definition of what it means to be a, a worker, let's say knowledge worker is replaced by somebody who's, you know, a knowledge orchestrator or a supervisor, and they are handling more things, um, through their team of folks. And then we're all more collectively productive.
But we may not have as many people in the first place. I always wanted to be an orchestrator. Do I get a baton with that?
No, no. That's different. It's an orchestra.
Um, so Mike, you, you are right, but, you know, I'm reminded of a, a discussion we had earlier this week around the Apple $500 billion announcement. It's gonna create 20,000 jobs. That's about 25 million a job.
Um, and by the way, I'm going to, I spoke about this Thursday on LinkedIn live yesterday on my shimmy says, but the bottom line is, you know, we talk about opening data centers and factories and all these things, but when the jobs in those data centers and factories are handled by agents, you're not creating the amount or the type of jobs that they may want in the heartland here, right? Those good assembly line jobs in those factory positions, agents may do that. Robots are going to do that.
And so, you know, do we come to a te, a Star Trek kind of world where humans really don't do menial labor and don't do physical labor? And, you know, and quite frankly, even a lot of service mental tasks can be handled by agents, AKA writing software and, and all of these things. So, well, what do humans do?
We, we can't just get fat and walk around on those chairs, right? We talked about this with Wally. What do we do?
Have I not told you my favorite stupid it joke before? You know, what's the future of the data center? It's, it's, it's one guy and a dog.
And the dog is there to keep him from touching anything. It's gonna be a boy, it's gonna be a boy and his dog, another science fiction reference. But you know, that you're, you're right, Mike, there's gonna be a, there already is, uh, in the, especially in the healthcare industry, a lack of doctors, optometrists, dentists, so, so AI in a sense, and these agents and robotics will actually fill the gap there.
So there is a, there is a good side that benefits all of us, but I just think, I mean, I just think that the problem is, given what our oligarchs in tech are doing these days, it's very hard for me to trust anything they say or any, any of their intentions. They're building these data centers. They're looking at ways to move forward in robotics, in ways to maximize profits.
Because that's all I really care about, in my opinion, that at this point in time that might change. And it's so kind of where we're moving in terms of job displacement. And you're gonna see more union activity, uh, around this and more strikes or threats of strikes.
So You think it's more displacement versus, excuse me, augmentation or enhancement? 'cause I see it, I, I guess I look at it from a different lens, um, from a messaging perspective and what really needs to be very crisp there to explain how these agents are helping humans. But it sounds like you guys are thinking more, there's gonna be more displacement than there is enhancement.
Well, we talked about this previous show where we were, um, you know, given Andreessen some grief about some of his comments. But one of the things that he said is, we're gonna burn down the economy first and then rebuild it. Well, that's all right.
Burn down the economy without a plan though results in a massive amount of disruption. And it's not too long before, Even with a plan, the Pitchforks are outside the White House. Even with a plan burning down the economy is going to create lots of disruption.
And when you're an oligarch sitting on a couple tens of billions of dollars, you, you can ride it through Mr. And Mrs. America who are voting for this, I think are in for a bit of a, a rude awakening.
And, and we'll, we'll see where, where that goes. Um, I mean, but, but here's the other flip side though too. I've never seen progress stop be for, for feelings, for feel goods, progress rolls on and it stops for no man or woman or worker or country or economy.
And if you could, if you could do it, they will. And I, I will, let me pose in another scenario. When you hire somebody, you're actually hiring them.
And there are 15 digital assistants that they trained, and they are, you know, a small army of people and agents that are, are as the new employee that you're hiring. And when they Leave, oh, they're, they're all through egos. Yeah, they're all through egos.
But, but let's be clear, there's a difference between digital agents on our Salesforce who are gonna go do digital task on the net or on your network for you versus robots that have AI embedded and are doing physical tasks, right? This is, this is a PI movement here, right? Where, where, where they're attacking menial, physical task, not attacking, but potentially replacing menial physical workers at the same time replacing what's called them brain workers.
Well, let's go to the, let's go to the bean block 'cause that's where we're going. Absolutely. All right.
You know what? That's a good one. We'll, we'll, uh, we're gonna take a break here on text.
And again, you know, I always wanted a Jetsons flying car. It looks like I'm going to get rosy. First.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching it, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Techron Group. All right? So as Alan noted, we are talking about robotics and robots are coming to the home.
Meta has signaled that it wants to build robots that will do everything from wash your car to do your laundry. And well, what could go wrong with all that? But, um, Alan's point, we are seeing these, you could argue a robot is a form of an AI agent, and it's gonna go do menial tasks.
And to this is part of that pincer movement. But what happens to all those folks who are doing those various tasks out there? I don't know, and I don't know how far away these robots are, but I can think of a few dozen things that might go wrong, including, well, is that robot sharing data about what's going on in, you know, your laundry with some AI somewhere that then is gonna pop it out somewhere in an interesting way.
Will, you know, littles, what was little Susie doing with her boyfriend? And the, when they were supposed to be doing homework is suddenly gonna pop up on a screen somewhere? I don't know.
But Shades of Monica Lewin, Um, only if you check the box that allows your robot to share that information back with meta headquarters solely for the purpose of improving your laundry. But, uh, no one wants to air their dirty laundry on Techstar gang. But, you know, look, guys, take a lesson from the internet.
What industry led the way in breakthroughs on digital, uh, commerce, on video over the internet and everything else, the porn industry, they're liable to lead the way in this robotic industry as well, right? And I could only imagine what all hell breaks loose here. What John, I'm sorry.
Oh, It's like a West World reference too. I mean, Yeah, yeah, yeah. A little west world that was ing, if you remember that.
Yeah, that was great. Series speaking. Well, we'll come back to this, but, but you don't need a pretty guy Beefcake guy or a pretty woman robot to wash the car, do the laundry, do your rosy, like Jetson's, Rosie's, you know, electronic maid, do that kind of stuff.
They don't even have to actually be humanoid, right? They don't have to have two eyes, and you don't have to look humid. Whatever the most efficient form is to complete the particular task.
I, I think the question is, and it's similar to the digital agent, are we gonna have many different robots that are single function robots, car washer that services multiple houses or something like that? Or do we have a jack of all trades robot, the English butler, so to speak? Who?
Or Rosie, right? Who, who does runs the dishwasher, runs the washing machine, washes the cars, tidies up the house, folds the clothes. Um, you know, the beauty of it is, is if you've been following what's been going on in robotics over the years, and for most of us, it's just watching how nimble the robotic dog is, right?
You could take out a, a leg and he still figures out how to balance himself and how fast they run and how, you know, how much progress they've made in, in these robotic, uh, you know, mechanisms and, and mobility. But then you marry that to true ai, right? To a really good AI that that's programmed to do certain tasks.
Sky's the limit. Sky's the, I mean, think, think of, do I need, you know, one of my big things is if we, if we deport 12 million immigrants, all the fruit that's rotting in the, in the fields and, and you know, John and Joe Smith from Kansas City aren't gonna go out and do farm work. Well, if I got robots to do 'em, that really helps.
That really helps. And I Think we're a long way, we're a long way from the single purpose or the multipurpose robot. So I think we'll get there in phases.
We'll have single purpose robots, then we'll wind up with this multipurpose robot. But, um, this is not all that far off in the sense that, you know, there are reports that the Chinese are building millions of robots already. So It's, you know, it's, it's also, I mean, it's also happening here.
There's a startup out here called physical intelligence, and one of its major investors is Jeff Bezos. And there are videos of what these specific robots do, some wash dishes, some sort and box, uh, items. So it is going in that direction.
I actually, when I recently went to Carnegie Mellon, the, um, PhD students there were showing me their robots that did things as, as, as weird as like picking apples outta trees, um, using sound rather than visuals. Um, it's, it's happening. And a lot of the agriculture companies are working with the Carnegie Mellon folks about raising crops and picking crops.
So, you're right, Mike, this is a lot of specialization before we go to the multi varied robots. But it, it, it's happening. I mean, it's just, I just don't know the timeframe.
And again, with meta, I don't know if this is a concept they're talking about how far along they are. I guess it depends on where they, where they are. But physical intelligence actually is something that I think you're gonna see elements of that being used within Amazon and their warehouses within a couple years.
Definitely. We saw a lot of that at CES actually, sorry, guys from a, from an agricultural perspective, all the things that they're doing, working with robots to do special tasks, to, to aid the humans. Um, so that was a big theme at CES this year too.
So there, there are lots of undocumented workers out there who are doing a lot of these jobs for about, I don't know, 15 to 20 bucks an hour, we shall say. Um, so does the robot need to come in under that price, or am I gonna have to buy the robot? I mean, going back to our earlier conversation about these AM regions, you know, how does the cost of the robot get figured out?
And maybe the robot will be too costly Spoken like a true coastal elite Mike, they're not paying those undocumented immigrants, 15, 20 bucks an hour. Those people, you know what I mean? Come on down from Harrison Dean.
Um, those people are getting five to $7 an hour, unfortunately, and they're happy to get it, and that's what makes that world go round. But look, when you compare human labor to robotic labor, though, it's in no win. The human can't win, right?
Because the robot never gets sick. It could break, yes, but the robot doesn't get sick. The robot doesn't take days off, the robot doesn't steal the robot doesn't hate you or love you or whatever.
The robot can work 24 7 theoretically. And over time that robot's going to get cheaper and cheaper as, you know, scales of economy kick in. So, you know, to say, oh, you know, there's a, there's a, a, a, an actual comparison of cost, I think hands down, eventually the robot's gotta win that game.
But I'll tell you one area, But there is, there is, but there is, Ellen, just to be fair, there is a, there is a level of hesitancy among places like John Deere. The initial cost, the outlay Yeah. Is expensive.
It's CapEx Prohibitive. Yeah. Unless, unless you a major company, it's, it's gonna, it's, they, it's gonna start with them.
But yeah, you're right. The costs are, are dropping, but not exponentially. So it's, it's that that's the one thing that humans Have going mean, you know, a couple of issues.
Number one, you know, who's really out ahead and is just besides themselves with this are, you know, to, to go back to the other day, we were talking about Ike and Eisenhower, our industrial military complex, because probably the first robots we're gonna see are military robots, right? Clone wars, warrior class robots who just follow orders, they don't have a conscience. And, and that, that's a whole new set of, you know, potential problems we need to be thinking about.
The other thing though is who really is gonna be the robot? Who's gonna make the robot that you buy for your house? Who's gonna make your rosy?
Is it gonna be a Google, a meta, an Apple, a, you know, one of the mag seven oligarchs an Amazon? Or, or is there a chance for, uh, a new, a new class to rise, you know, a new group of US robotics? Didn't they make the modems we used?
Wouldn't it be great if US robotics came back and we, for our robots in the house? But, um, you know, there's an opportunity there. And the question is, will the Mets of the world who are, you know, making noise and the apples and the Amazons making noise, are they gonna let new, new growth come in here?
Right? And that, that's sometimes why you need a government to calm the, the market at, you know, pure market forces to make sure we don't get monopolized with this. And we do have, uh, innovation coming from new companies in this exciting new area.
You're right, though. You know, you talked about the, oh, go ahead. Go ahead, Lisa.
I, sorry, Jon. I was gonna say, I think that's a great point. From a competitive perspective, how can smaller companies, those newer ones, leverage the, what the metas, the apples, the Amazons are doing from a robotics perspective to drive more innovation, to drive more competition, that's gonna help drive prices down as well.
But Alan, you bring up a great point there in terms of where is this innovation? Where's the, we're seeing the, the leaders with some of those Mag seven companies already, but it would be nice to see some of the smaller companies from an innovation perspective be able to bring up that competitiveness so that this becomes more of a, of a cost effective reality. Oh, um, I'm just gonna say me, you mentioned the military.
That's a great example. I mean, in addition to the porn industry, the military has always been kind of at the forefront of terms of using technology. And when you mentioned robotics, it made me think about 20 years ago I did this project with CNN, and it involved UAVs.
And also remember the Global Hawk, the predator, these drones, um, there were emergency, there were underwater, uh, submarines that were, uh, robotic. They, they were done mainly to protect humans from in, in terms of war. Uh, right, right.
I mean, they'll be used for something else. I'm, I'm sure I already have been, for all we know. But the, the whole, the whole idea, the whole concept though, was to try to, as Eisenhower, you mentioned earlier, you know, a way to spend money on the military without spending it too much on people and, and more on technology.
Uh, as we kind of go forward in, into this brave new world, I think this is gonna be a massive exercise in marketing because the only robot that's coming into my house has to come from some brand that I trust. Right. And it's not just gonna be, you know, any random company.
It's gotta be somebody who I can feel like I can call up and say, come get this thing. 'cause it's going crazy. No, but look, I, I'll give you, for instance, any of you guys use robotic vacuum cleaners in your house, IRobot, it's exactly.
Bingo. What a great story. The Roomba from iRobot was my friend Brad Feldy was an investor in that early on.
And that, you know, there was a long, it wasn't, it was one of those 10 year overnight successes, right? It took a long time to get that technology right. And it, and it's relatively dumb technology if you've used it, you know?
Right. But people, you know, that's worked its way in, is a brand that people didn't, didn't Amazon buy that one, John? Yes.
You know, now, of course, it's part Amazon, I think have one in the, I think I have one in the attic somewhere. I think we stopped using it just 'cause Well, no, I have one here in the office. I brought it in from the house because our previous dog, Sandy, used to hate it.
She'd chase it around biting it, and she cracked her canine teeth on it, and she had that f look. So when we got the new puppy, now, I immediately took it out of the house. 'cause I didn't need any more cracked teeth.
I had to pay for enough orthodontist work for my children. I don't need it for my dogs. But, um, yeah, I don't know how many people, I don't know how good they are to tell you the truth.
Dyson never came out with one. How good they could they be. Um, Mike brings up a great point on trust though.
Sorry, John, on customer trust, you're saying, like looking at, you know, the apples, the Amazons, the metas that, that we're buying products from and where we are the product versus somebody that's unknown. So maybe there's collaboration between some of these larger companies and some of the smaller ones to drive that innovation. But you bring up a great point.
'cause from a, from a marketing perspective, it's all about earning customer trust and retaining it. That's just table stakes to driving revenue. Mm-hmm.
And I'll tell you what, I trust Samsung a lot more than I do Hewlett Packard, you know what I mean? What kind of American are you, I'm kidding. Is American with good taste in terms of technology?
Sometimes Uhhuh Uhhuh, but they haven't, I didn't see them at the White House pledging a couple of hundred billion dollars. Well then half the country Wait day is young Then, then half the country's gonna trust them more. I don't know.
What can I tell you? Anyway, Hey, let's take a break. We're going to come back.
Little bye-Bye. Miss American Pie. Well, actually, it's UK pie.
This time you're watching text and gang. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Alright, we're back in. It was kind of an amazing stunt.
Uh, about a thousand or so artists in the uk music artists got together, released an album, and there's no music on it. And they were basically protesting this law that's being considered in the UK that will allow anybody who has an AI thing just to use copyrighted content to train that AI and not have to actually compensate anybody. And of course, all the artists in the UK are flipping out about this, and it's not just gonna be music, I suspect.
But John, you've been following this for years now. What's going on here? Yes.
So it's more content creators against ai, right? It's, um, it is interesting, this concept of this, this album, which was called, is This What We Want? There were a dozen recordings of empty studios and performance spaces and with the likes of Kate Bush, Annie Lennox.
And I remember also a couple of weeks ago, Paul McCartney had talked to the BBC, and he had said this interesting quote, he says, the truth is the money's going somewhere when it gets on the streaming platforms. Somebody is getting it, and it should be the person who created it. It shouldn't be some tech giant somewhere.
And, and, and again, what what's especially heinous to the artists of this case is that this considered plan or law, AI law, copyright law, would allow tech companies to use copyrighted material to help train AI models unless the creators themselves explicitly opt out. And I think there are already laws there. I mean, based on what I've read, there are, the copyright law already can covers this, but the fact is you have to actively protect your own rights, which is gonna be almost impossible.
Um, the, this opt-out proposal's been met with scorn from opponents to say there's no evidence of a water type rights reservation process anywhere in the world. So I suspect we're gonna see this cascade beyond music and into film and into writing, into even our stories, into, into everything imaginable Again. It's, um, it's quite interesting in, in the amount of force that the artists in the UK took.
I applaud because I think they're making the, the Labor Party, which is thinking of this plan, kind of reconsider it. And I mean, it's a story that's fluid, but I think there's been enough resistance where I think we might see some sort of action. But again, this is something that we've seen in Hollywood with writers.
We see it with voice actors. I mean, they're being replaced, especially voice actors. That's one of the worst areas where you can replicate their voice and basically use the AI voice instead of the human and not pay the human.
So again, it just spares repeating. I think it's a really important story, But it's also authors. It's not just musicians, it's authors, it's artists, it's newspaper publishers.
And then we have companies like OpenAI saying, Hey, we can't train our models without copyrighted materials. So this, this war, and you've mentioned some of the, um, of the big names, Paul McCarney, Elton John, for example, as well as a lot of smaller artists. And what I thought was interesting was that the 12 tracks on this album of silence spell out the British government must not legalize music theft to benefit AI companies.
And they're really, these creatives are really speaking for, for, um, all, all, all creative industries globally that we're seeing it obviously rise up here in the uk, but it's, it's the creative saying, we need to be protected and compensated. And, but the big OpenAI companies saying, we can't train the models without your copyrighted materials. So did the, So Alan, did the politicians sell out the content providers here, essentially for money?
Everybody wants to ride the AI train to quote some song, right? Everybody wants to ride the train. But you look, the fact of the matter is there is a long bloody history of large companies exploiting artists for their own capital benefit, right?
If you're familiar with the Bruce Springsteen lawsuit, uh, back in the day, several others now, we had a bit of a revolution with digital. All of a sudden, those, the, you know, the recording, uh, industry, the, the, the record labels, they didn't, they stopped holding the power because everything was streaming and, and payments. Now artists can get royalties directly from the streaming providers, Spotify's and so forth of the world, though there's still a place for labels.
It's just not, you know, like what it was when we were younger, let's say. Um, but you know, th this is true now, I thought, John, that the, the after and the, the Hollywood strikes with the writers and actors that you could not use voice and duplicate one's voice without permission. As a matter of fact, I believe it came out that when James Earl Jones passed away, he had sold the digital rights to his voice so they can continue doing Darth Vader and some of the other roles, you know, iconic roles that he played, that his voice is, is the role.
And, and he sold the, the, he, he, his estate sold that for a pretty penny. You know, similar to the Bella Lago case, which originally said you have a, artists have rights to their images, artists have rights to their voice. Artists have rights, you know, to their likeness.
Um, unless it's satire now. But this really begs the question. I mean, think about what you said, Lisa OpenAI says, well, we can't train our models without copyrighted material.
They acknowledge this is copyrighted material. Well, thanks for telling me that. 'cause that's why I thought my copyright was valuable, otherwise I would've just let you use it.
You know what I mean? You, you hear people crying with two loaves of bread under their arm about why can't we use copyrighted material so we can make money? The honestly, the nerve, the nerve of that to actually make that argument and expect us to have sympathy for them.
Have we gone bonkers? I didn't see them at the White House pledging him. Actually, he did, he did pledge money.
All right. He pledged money, no tariffs. He could do whatever he wants, right?
But honestly, where, what are we coming to here? If copyright and IP means nothing? What's our beef with the Chinese?
That was always the thing. They don't respect our ip. Well, if we don't res, you know, my grandmother always told me, if you don't respect yourself, don't let, don't expect other people to respect you.
We don't respect our ip. Other people won't either. So I say more power to these musicians.
And I'm, you know, it's funny how these things always take place in the e UK and the eu where they seem to still have a, a sense of, of individual rights. And they haven't sold out to the oligarchy quite yet, but more power to 'em. So John will, the artists of which, you know, many have, are native to Great Britain.
And Great Britain has driven rock and roll and all this other stuff from, will they just leave that whole country and will they say, we're not gonna put our product and make it available in the uk 'cause it's gonna be stolen by AI companies? Yeah, that's a really good point. You know, that that's, you know what, in a sense, it has happened before because of the taxation in Britain.
A lot of artists left the country relocated to France, Switzerland, United States to avoid that. So there is precedence. Um, and in terms of recording, you can record anywhere, I think.
I think that the, the British government probably is stepping back and thinking, Jesus, you know, what have we gotten ourselves into and trying to figure out a compromise. Like all these things, usually we try to do at least with, with so much power that's been represented by these artists. But I think there's a a very good chance that they, that they lead.
Yeah, I think it could happen. But, But, but let, practically speaking, okay, so they pick up and move to the south of France or to the Dakota building in New York City or whatever, right? Does that stop the British government from allowing the AI companies to use their, their music to train their models to make good music?
Well, I, I think, I think it sends a message to the government. And when you have the mega stars leave, which impacts an industry and the economy in a certain sense, maybe it does. And maybe they sec they, they rethink what they, what they did.
I mean, that's, I guess the leverage you have. But I understand your point. Those, Those guys generate a lot of taxable revenue for the uk.
So that will just disappear. And then their recording companies might just say, we're not gonna let any, any station or any outlet in the UK have the next album. 'cause the other stuff's already out.
So that horse is out of the barn door. But anything new they could theoretically lock down. And then maybe, you know, I don't know, Malta sets up and says, you know, Hey, we're gonna welcome all you guys here to live, and we will have friendly courts for you to pursue these cases, and we will tax your revenue less than the UK did.
And for Malta, it'll be a huge win. I don't know. I'm making that up.
Yeah. But theoretically, Yeah, no, I just, yeah, it's, I'm just gonna throw this out too. Maybe I'm going down a rabbit hole.
But the whole thing with, uh, Taylor Swift rerecording all of her albums in terms of owning the rights to that, I mean, I'm not, I'm not sure about the particulars, but the, the fact is, if you are big enough and strong enough as an artist, you can flex your muscle and have the fair amount of influence. Especially if you have somebody like McCartney who, when I lived in England, the joke was he made a a pound a second from royalties alone. Um, this, this is, I mean, this has a lot of weight behind it.
We shall see, we shall see, I, this isn't just a UK thing, right? Because what are you gonna do not allow the ais in the uk? I mean, and what about the EU and the US and the brick countries and the rest of them?
So what happens when the artists say there'll be no concerts in the UK either, because remember, you know, people wanna go to the experience and, uh, I don't really wanna sit at a concert and watch a digital robot. So, you know, there's a lot of leverage here, Man. I'm just, Hey, don't knock it until you tried it, until you walked a mile in those shoes.
Talk to the porn guys. Um, but, uh, no, I mean, so that is one way that though, where like, I don't know if moving out of the country gets 'em what they want, but refusing to perform in the country. I think that'll put the screws to 'em a little bit.
That happened in South Africa. Remember all those Oh, yeah. Were no, no.
Major artists would go To, yeah, yeah. Well, they tried, they tried it in Israel too, the boycott, divest, whatever it's called. I tried to pressure artists not to perform in Israel.
Yeah, If you live in the middle and you wanna see a concert, you're gonna have to go to Dublin. That's all there is too. I'd rather go there.
Um, you know, the, the thing too is the, the, it is just as you said, Alan, in Europe, they are, they do value copyrights, privacy. Um, they're personal data, and they're so far ahead of people, they're so far ahead of us. Uh, I, I just can't imagine something like that happening in, in the US to this extent.
Not as long as they pledge some money for AI data centers. Yeah, I know. Um, all right.
Hey, let's wrap up our Friday. What a good, this was a good, this was a good panel today with some great topics. We hope you've enjoyed this at home.
We have, of course, our usual text on tv, uh, schedule right behind us here on the gang. So stay tuned right here on this bat channel. And you, you'll be able to see that.
Of course, you could also catch Textron Gang on TechOne TV and watch past episodes. You can also catch in on our YouTube channel, our text drug tv, YouTube channel. It's on there as well as on your favorite podcast platforms, right?
It's probably being, you could probably, probably being used to be trained for that OpenAI thing too. But, um, but it's on Apple Podcast and Spotify and the rest. But until Monday, we'll be back with lots of great new content.
Monday. This is Alan Shimel. On behalf of Textron Gang and Textron, have a great weekend, everyone.
We're outta here. This is Textron tv. Hey everyone, welcome back here to another Techron TV interview.
Our, uh, guest for this session is Rob Truesdell. Rob is the chief product officer of a company named Pangea. We're gonna find out a little bit about Rob and Pangea here and discuss some AI related, uh, information.
Like we don't all have enough AI related information we're discussing. Hey, Rob, welcome to Text Drug tv. It's great to have you on here.
Thanks for having me on, Alan, I appreciate it. My pleasure. So, Rob, I mentioned your CPO Chief Product Officer over there at Pan G, but give a, give us a sense of kind of your career arc or, you know, things you've done in your life.
Yeah, yeah, absolutely. So I started as a practitioner myself, building secure networks, uh, utilizing firewalls. I-P-S-I-D-S, VPNs, doing a lot of that for government, federal contracts as well.
Um, and then I got more onto the product side of things and started building, uh, network acceleration for intrusion prevention, intrusion detection, doing things like deep TCP flow analysis. Um, and then started transitioning that over to security operations. And, um, there, that was a great experience.
Uh, had the opportunity to work with our, our broader team still now at Pangaea. Uh, but we worked together before at a company called Phantom. And, uh, there we created the security automation orchestration space.
Um, very, very popular product. Um, Splunk was, it wasn't Phantom acquired by Splunk, right? That, that's right, that's right.
It was all about, what was great about it were it brought together, um, engineering efficiency and security into the same product. So it was all about, uh, trying to triage security alerts as quickly and efficiently and, um, diligently as possible through the use of automation. And what's interesting about that is now a lot of that work is going to be done with AI agents, which is, which is pretty cool to see.
But, um, yeah, we were acquired by Splunk in 2018 and then, uh, led the security operations business there at Splunk. And then, uh, in 2021, uh, late 2021, uh, joined the Pangaea team and started building what we're gonna talk about today. Very cool.
Very cool. Yeah, I know Phantom was, as you said, it kind of defined a, a market there, right? Yeah.
And it was a great acquisition by Splunk as well. Um, give us the Panga background then. It sounds like with there more phantom people at Pan G, or is that it, or?
Yeah, I mean, uh, our, our, our core founding team, um, were also involved at Phantom. Um, and, uh, really what, what had happened were, during that time, uh, uh, of course, cloud security was, was booming at the time and, and specifically application development in cloud and securing that whole dynamic. Uh, so we started looking at that problem and came to this realization that, uh, that developers should be focusing on building the applications that are delivering value to their business, and less so worried about building security features.
Um, they're not experts at building security features. And when I talk about security features, I mean things like data handling, uh, the right way. So handling PII and sensitive information handling, authentication access controls.
Um, so we started looking at solving that problem for developers in a scalable way, making it really easy for developers to integrate that functionality into their own applications with spending a lot of engineering time. What we found over time were that our users were leveraging all of these capabilities that we had built for AI use cases as over, uh, the AI use cases started becoming very popular over the last, like, two years. And it's just going up and up and up.
Now all of the new application development is around, uh, the interaction with LLMs. What we, again, what we found were developers and, um, and enterprises that were using our APIs, they were using them to secure, um, interactions with LLMs, uh, from within their applications. So we thought, wow, that's, that's pretty interesting.
Um, and the key use cases that led it were things like, uh, again, securing, securing data interactions. So if you're encountering social security numbers or driver's license numbers or credit card numbers, those type of things, people are always concerned about that information leaking or an LLM sharing it back to a user, being able to protect against those type of things in a scalable way. We're perfect for that.
Um, auditability and traceability, those are other APIs that we had delivered. People need that for visibility into how the LLMs are behaving. So, um, over time I said we were building this comprehensive library of security capabilities for developers and found that the killer use case was ai.
So we started pointing everything towards that use case, and it kind of evolved to there into going deeper down the security challenges of AI and protecting against things like prompt injection attacks and jailbreak attempts and securing, um, access controls across rag data pipelines. And more and more I'm sure we'll get into, but that's, that's the background of kind of where we started and how we got to where we're at now. Excellent.
Very cool. Um, website. Yeah.
cloud, and what's great about, uh, if anybody were to go check out the website today, what's, what's great about, uh, engaging with the company right now are, uh, there's, there's two very interesting things that are happening. One, uh, we have an AI escape room challenge that's happening where, uh, you can register and basically there's a three room challenge and rooms are unlocked. Um, it's gonna be happening throughout the month of March, but rooms are unlocked, uh, pretty much each week in, throughout the month of March.
And it's all about, uh, optimizing prompts to escape the current room that you're in. And of course, at the end of the very cool, yeah, yeah, at the end of the competition, there's a cash prize. There's a lot of fun things involved in it, like with the community and all that.
But, uh, but yeah, if you go on the website, you'll see that that's a great way to kind of get engaged with the company. And then second, um, for the people who are like really interested in the, the product offerings, everything that we have is self-serve. So you're not working through, um, a sales team or anything like that to get access to it.
You basically, you know, create a login to our SaaS offering, and then you get access to all of the capabilities that I mentioned plus prompt injection detection, data protection with AI guard and, and other things. But, uh, yeah, there's, there's a great engaging game for, for people to play throughout month, uh, the month of March, and then there's our whole self-serve experience of the product. I love that.
Very cool. Yeah, very cool. Indeed.
7 couple days ago, and there was a lot of talk about, you know, it's, it seems to be much better than its predecessor on code generation. Mm-hmm. When you look at the people who are using Pangaea, is it people who are using it, that are using AI for co-generation or using AI for marketing?
I mean, one of the things, you know, I I'm asking people is what are you using AI for? Right? And we all, you know, if you believe the hype, we're all going to use AI some way or another, right?
But I mean, I know how I use it, it helps me every day, right? Whether it's articles or abstracts or marketing related, I don't code as much, so I don't use it, but I'm wondering who, who the base is at Pangea. Who and what are they using AI for?
Yeah, great question. So, um, I, I mentioned before that the, um, the original focus of the company was all around application development. So, uh, and, and developers and even, uh, um, those in the security space were utilizing our APIs to help secure the applications that we were building.
So when you kind of peel back the onion on that, it's enterprises who are building applications, both internal as well as external, um, to either, um, uh, supplement internal employee use cases or supplement customer experience, um, reduce friction in their user experience, things like that. Um, and what ends up happening are they use a combination of foundation, foundational, LLMs, um, and sometimes, uh, internal LLMs internally trained, but in a lot of cases, they're bringing their enterprise data together with those LLMs. And that creates a lot of risk, uh, a lot of risk because access controls are lost in that trans transition.
We hear that a lot, and that's a problem that we're, we're working with a lot of customers to help them solve with. We have an authorization, API that synchronizes permissions across data sources all the way through to vector dbs and the actual vectorized representation of the data in that database. Hmm.
Um, that's a, it's a pretty powerful use case, and we're seeing that on the application development side. So Enterprise is building AppSec that are utilizing LLMs. Now, there's another half of that, which are the enterprise workforce use case.
And this is where things like co-pilots come into play. So using co-pilots for, um, whether it's a, a Google workspace, a Microsoft workspace, gi GitHub, uh, things like that. Um, which, which is a whole other kind of, um, whole other problem to solve.
And what we're finding are that, um, the people that are utilizing Pangaea to help solve that problem are taking advantage of our gateway integrations. So, um, there are, there are two primary ways to utilize these guardrails. You could use APIs with our guardrails and integrate them directly into your application, or you could leverage a gateway plugin.
So things like, um, Kong or portkey, there are several others that are out there that, that integrations exist with. And what's great about that is it kind of funnels all the, a AI activity into a, like a single choke point, and you can apply guardrails, uh, and even have visibility and things like that at that point. So those are kind of like the two different approaches that we're seeing, like the application style use case where they may be integrating with an API and then a workforce style use case integrating with a gateway.
And by the way, those can be mixed and matched as well. It really is dependent on how that enterprise is, uh, implementing and rolling out ai. Got it.
Got it. Um, let's shift deep, really come back to that. But let's turn to our topic of discussion today.
You know, the whole idea of LLMs has become a bit risky, right? I mean, I, I, I forgot the exact term you used, but using, you know, the large, the LLMs, that sort of chat GPT or, or Tropic and so forth, run, you know, industrial LLMs, whatever you wanna call them, and then companies creating their own LLMs, right? Um, different sort of risk, uh, you know, uh, models there.
One, you have, you know, all the control over. You created that LL M1, you kind of taking what people have given you, uh, but nevertheless, risk involved in both of those risk models. Um, and then, you know, you mentioned Vector database.
Well, you know, we got Word IBM bought data stacks, right? Um, you probably saw that news. And of course, they, they pivoted from a Cassandra kind of thing to a Vector database type around this AI stuff.
What, how do you define the risks for LLMs? Let's, let's, why are they risky? Where, where's the risk there?
Let's go start from there, and then we'll talk about how, what we could do about it. Well, um, especially when you, when you start, when, when companies are getting the most value out of LLMs, they're bringing their enterprise data with it. And the easiest way to do that, the fastest path to doing that are with the rag, the, the retrieval augmented generation.
So the utilizing Vector DBS to marry that data together with an LLM. Um, so that is, that's, that's where a lot of value gets unlocked. The risk in that, um, that, that we're finding in people who are doing that are all about data access controls, and the, the use case that everybody is afraid of is the one where I have, I am servicing my customers with an LLM and customer sensitive data, and I have customer A asking questions and obtaining data about customer B could be receipt information, or it could be, you know, if it's a healthcare use case, it could be sensitive, sensitive, uh, private health information.
But that, that's the, the core fundamental problem when you start marrying the enterprise data or, or, um, or sensitive data with the LLM are the access controls behind it. The access controls get, get lost, and it's a hard problem to solve. And it requires, uh, it really requires integration with that rag pipeline all the way through to the Vector db and having permissions persist at the vector level.
That's really the way to solve the problem. Um, at least that's the way that we're solving it with our customers who are doing it with our authorization API. Um, but that, that's the major, major threat behind, um, or the risk you asked about, or the, the leaking of that information because you lose permissions as that ra as that data's flowing through a rag pipeline, into a vector db.
So it's important for anybody who's, who's bringing those two worlds together to really think through the architecture of when that data's getting vectorized, how do you persist permissions? How do you keep permissions in sync with the, the origin data source? Because at the end of the day, these vectors are coming from some data store somewhere inside of the enterprise.
So keeping those things in synchronization are also important as well. Excellent. Yeah.
Um, let's talk a little bit about what Pangea does in this space. Right. So, um, the major things, I, I talk about the foundational secure or security APIs and services that we've built, but it, again, over the last year, it's evolved a lot.
We just announced general availability of our AI guard and prompt guard services. Uh, in fact, that announcement went out last week, so it was a very exciting time for us. We've been working with a lot of customers to build that capability.
Um, what's great about the AI guard and the prompt guard use cases are they protect against everything from prompt injection and jailbreak attempts all the way through to, um, identifying, uh, toxic, toxic behavior or language, uh, in, in la uh, prompts being submitted to and from an LLM and identifying sensitive data and a lot of those, um, a lot of the use cases that we talked about before. Now, uh, what, what's great about what we built there is we built it in a way such that no matter how an enterprise is utilizing AI or LLMs, we built it so that we can intersect at any, uh, implementation point. So if they're writing code and they wanna integrate this via API, they can do it with an API, uh, if they wanna integrate the guardrails at the network level, you can integrate with an AI gateway.
Uh, for, for enterprises that are very SaaS and cloud friendly, they can utilize our, our SaaS offering, or if they need ultimate control over how these guardrails are deployed, they can take a self-managed, self deployable version of these guardrails also. So, we're, we've tried to, um, knowing that the people that are utilizing these capabilities to their fullest extent have pretty, pretty strong infra, uh, skill sets. We wanted to make every option available to, to consume this.
So there's a, there's a pretty wide variety of ways to deploy and adopt LLM. So, um, yeah, integrating with gateways, integrating with APIs, self-manage SaaS, the full spectrum's there for, for people to be able to, um, take advantage of these guardrails. Fantastic.
Rob, we only have 15 minutes. I think we're probably at 20 or more. cloud.
That's right. That's right. Go check it out.
Keep up the great work. You know, we're just, honestly, a lot of this stuff's just scratching the surface, right? If people are just beginning to realize some of the implications here.
I just a quick plug. We're actually at RSA this year on Monday, every, for the last 10 years we've been doing the DevSecOps, uh, event This year it's about cybersecurity, AI and app dev. And we, we actually have the CSO from, uh, from OpenAI, uh, anthropic, senior security guy from Meta and Google DeepMind, ciso, I think.
And we're talking a lot about securing your data, making sure it doesn't get sucked into the, the LLMs and, and how to, you know, do all these things. So, should be an interesting session, or it's actually a seminar. It's all day.
Um, but we'll come back. We'll hear more from you, man. I appreciate it.
Thanks for having me on, Alan. It's, uh, it was a lot of fun talking to you. Absolutely, Rob, it's a lot of fun speaking to you.
Rob Truesdell, chief product officer of Pan G are here on Techron tv. We're gonna take a break. We'll be back with more.
This is Textron tv. Hey guys, thanks for the throne. We're here with Howard Bobbell, who is president of engineering and consulting services for DXC technology, and we're talking about quantum computing, of which there's been a lot of noise lately.
Howard, welcome to the show. I'm pleased to be here. Mike, good to see you.
We saw Microsoft most recently and Google before that, talking about new processors for quantum computing and making some interesting claims about advancing the pace at which we think we're gonna be able to, uh, operationalize this technology, shall we say. But is this more hype than reality? Because I'm still scratching my head about, well, is there such a thing as a compiler for quantum computing?
How do we actually invoke this stuff? Yeah, well, certainly there's a, a, a crossover between classical computing and, uh, quantum computing. So in terms of the algorithms that are being created for quantum computing at the rudimentary level, it's at, with the number of qubits they use, um, still needs classical computing to set that data to do further work with it.
Um, but this is the decade of quantum computing, um, that continuously pronounced by luminaries in the field. Vin Krishna from IBM, who is being one of the lead, um, person in research and development in terms of building the capabilities that they have. And then when you look at all of the actual billions of dollars around the world by companies as being invested to address the actual basic issues with quantum physics to be sold in order for quantum computing to get to a million qubits that was announced by Satya earlier this week, um, I think it continues to show even more promise that actually it'll become a real thing.
What kinds of applications can we build and are they gonna be things that we build and deploy alongside classical computing applications, or will eventually quantum kind of just supersede everything? It will be complimentary. Um, essentially if we think about advances in mathematics, um, which originally were formulated in the mind and then written in sand or put in cuni formm on the clear tablets, there's been advances in technology that's allowed branches of mathematics to become available on a broader sense.
And classical computing kind of ones and zeroes allowed things such as databases, which is complex mathematical means of organizing data to come alive, become alive. And that then created companies like Oracle, like IBM's database services. And then as classical computers have become, uh, more powerful, it allowed other more complex branches of mathematics to become available.
So graph, in terms of lots of nodal information, then created companies like Facebook and Instagram and so on, certainly less productive, um, uh, applications relative to what happened with databases. And quantum computing is a mechanism of unleashing branches of mathematics that is impossible to compute on classical computing. So particularly in terms of materials management, materials creation, health and life sciences where proteins, where new material management can be modeled, um, through, uh, mathematical algorithms on a quantum computer.
But then coming from that, in a number of cases, the actual further work will be done in classical computing because it's more appropriate relative to the types of mathematics that are being used relative to the ones on the breakthroughs with quantum computing. And you concern that maybe we are gonna wind up in some sort of crazy hype cycle that we saw with ai, or, um, is this kind of from your perspective on some, you know, natural order of things, curve of adoption? It's, it will go through natural hype cycles.
Um, and we're probably about to, to kind of come into that now to get to true production, um, volumes. There is this feud that you have to be at about, uh, 1 million qubits. We're short of a hundred thousand qubits currently, so materially less from where you need to be.
There's issues around stability of the atoms. Um, there's issues around capturing the data, um, on a sustainable basis. So there's a lot of material work, cooling work, um, stability in terms of the, um, atoms that needs to be established before quantum computing is truly, um, uh, commercial value.
But the approach that Microsoft has taken is interesting. It, it uses in 1930s it Italian physicists methodologies ma, which is actually the name of the chip. And that gives us stability in terms of the atoms all being precisely placed on the actual chip set.
It's taken the team 17 years to create all the various technologies for that chip to actually come into reality. It's topological, um, quantum computing. Um, but it's interesting, it's kind of the synthesis of pure science then into actually applied science.
Um, but I was reading IBM's, um, quarterly reports. They've already generated a billion dollars of revenues through their quantum computing, um, offerings. So, um, there is clearly some commercial use cases in a material sense that's been used given that that amount of money is being spent by third parties, either public sector or private sector in terms of their platform.
And that would be the same for the other, um, uh, cloud the other quantum providers as well, For lack of a better phrase. Um, the atomic unit for quantum computing that people refer to are these cubits. What exactly is a qubit and why are they not just automatically stable?
The, um, the best way to describe it is to do it by means a comparison. So a classical computer uses ones and zeroes to actually do the calculations. So thing, this thing is either on or it's off.
Um, so that's, that's the digital term in the case of quantum computing by using atoms. So it's actually very much getting back to nature to do, uh, comp, uh, calculations as opposed to ones and zeros. A a calculation can be a one or a zero, or it can be anything in between.
Uh, which then gives just a much broader me means of actually the different types of calculations and increases the pace by which the calculations can take place. It's a notion of superposition is, is the actual, uh, physics terms. Um, and it's because of the nature of an atom when observed will actually operate in a different way.
Um, so because of that, when you're doing these complex mathematical equations, you've got a much greater range than either a one or a zero. And how does that get us to being able to maybe conduct research that we couldn't do before, such as, I don't know, maybe finding cancer clusters that seem to allude us. What is it about the nature of that style of computing that is more, uh, richer in some instances than what I would do with classical computing?
Yeah, so it is the speed of its computational capabilities and the different types of computational capabilities that you could do. And again, by weird example, um, there's always a, a ying and a yang to any technology that comes through. So for example, nuclear power is a potential mechanism to help, uh, reduce the amount of dependency on fossil fuels.
But also the, the, the ying of that, the dark side of nuclear power is nuclear, uh, uh, bot in the case of, uh, quantum computing, it has incredible potential of these types of mathematics that can allow us to address things such as life sciences and cancer, um, or all sorts of other different disease treatments. But the, the, the ying of that is, um, quantum computers can unencrypt encryption techniques that have served as well for quite some time. Um, so RSA encryption techniques, so that means that the data that we have is protected and therefore intellectual properties protected, people's privacy is protected and so on.
And the current encryption techniques that we have, if you were to use a, the most powerful classical computer that exists, it will take a billion plus years to go through all the potential permutations to deen encrypt those levels of RD and encryption. However, when we get to a production level, quantum computing, um, something that would take over a billion years on the most powerful classical computer can be done in seconds, DCR in seconds. It gives you a sense to the actual incredible power of the computational capability of the quantum computer relative to a classical computer.
And obviously with that, it means we can do analysis of all things. Mathematics can actually underpin everything within nature, everything within materials, uh, design and management, everything within the university. We also hear the phrase quantum resistant encryption and the rise of something known as Q Day when these quantum computers are able to break all existing encryption.
But based on what you're saying, is there such a thing as quantum resistant encryption? 'cause it seems like the quantum computers are getting bigger and better and faster than we thought. The better way to to think about it is to be post quantum agile.
So, so DXC has a post quantum security practice where we will give advisory services to our customers to actually first understand and prioritize the vulnerabilities that they have within their environments, and then think about how they actually, um, protect them. There is a standards body called nist, um, which is, um, used on an international basis. It's an American standards basis, but very often used on an international basis.
And they continue to run competitions to, with various research labs around the world to come up with encryption techniques that will be quantum resistant. Now, I, I think the, the reason for your question is it's been proven on a number of occasions that the actual research labs that have notionally had encryption techniques that have been felt to be post quantum secure, then ultimately being un-encrypted through, through classical computing that let alone, um, quantum computing. Um, and that's why the word agile is more important.
So you create an environment where you can actually be agile with the new encryption techniques that you put in place. Now, the simplest mechanism is to actually keep yourself ahead of the quantum computing is simply to extend the length of the keys. So an exce, uh, uh, an encryption technique uses factoring, and the longer you make the key, the harder it is to deen encrypt.
Um, now that means also that there's a lot of work you have to do in your own environments because the longer the key is, the more memory you need in your applications or in your hardware. Um, and that's the kind of work that we at DX c Al, uh, do. And that keeps you ahead at the actual arms risk of, uh, quantum computing.
And it's an ability to unencrypt encryption techniques. The systems I've seen so far are sizable. Um, it's not like something I'm gonna deploy in my own little data center somewhere.
So is this always gonna be some sort of cloud service in a shared resource or over time will these systems continue to get smaller and smaller and more energy efficient? So they're actually materially more energy efficient than classical computing already. Um, they, um, they do have to be, um, cool.
They're incredibly, uh, cool temperatures. They have to be called an outer space in order to have stability with the actual atoms. Um, in terms of their size, everything will reduce in size, but the form factor that will be the majority, but not the only mechanism of actually using quantum computers will be through cloud-based solutions.
You can already use quantum computer, you can already program against quantum computers with both IBM and Google. The actual open source language you do that against is quiz kit, which you can download and then start to actually do some fairly rudimentary work on the, on the, the, uh, the more basic, um, quantum computers that are out there. But there are some health and life science companies and hedge funds that actually buy the quantum computers themselves so that they have a proprietary advantage in terms of what they're doing with them.
So what is it that I'm going to use to, you mentioned this language, is there a different way of thinking that software developers are gonna have to have to invoke these things? I mean, 'cause we've trained developers to think in a specific kinda way all these years. And is that gonna need to change in a, in a quantum model where maybe, you know, the old fashioned saying of two things can be true at once, but how do I program to that?
So it's, it's the way that you program against quantum computing is not a thin else statements that we may be familiar with from rudimentary, um, uh, application development courses. We've done it's algorithms. So it's, it's, it's kind of quantum physicists.
It's deep applied mathematicians looking to get answers to complex mathematical problems that are computated through this incredibly powerful computational capabilities of the actual supervision superposition state that are, uh, quantum computing could be in it's then the output of that in terms of the answers to those questions that then you would put into classical computing and apply the more logic based, um, application development there as well. That's the need for the complimentary element. Um, so you get the kind of the, the turbo boost, um, capability of quantum computing to get the answers to very complex mathematical questions that you're asking.
Whether it's protein analysis, whether it's CO2 analysis, whether it's how you actually create a new alloy at certain, um, at tensile qualities, um, um, is, is how you all see that come together. Really, that's not two difference to how, um, final financial institutions and other organizations and regionally used GPUs. GPUs are get a lot of publicity now because they're used for large language models, um, for ai, again, because they got a lot more horsepower than what a classical CPU is.
But prior to that, GPU by Nvidia were very used extensively across financial services institutions for their, uh, capital markets businesses. So how they would do equity trading, fixed income trading, so again, complex mathematical elements using bit pap and statistical models on a, on a, a form factor that was appropriate for that. Quantum computing is the next mechanism to do even more complex other ethnic work.
So how do I have a reasonable conversation with C-level executives who have already shown a tendency to get a little overly excited about AI because of fear of missing out? And am I gonna see that come full circle and how do I manage that conversation more successfully and maybe we manage the AI conversation so far? Yeah, so, so quantum computing I've been talking about and kind of been concerned about on the kind of the deen encryption elements since probably about 2015, so 10 for 10 years, but it's a conversation that resonates with next to nobody in any enterprise environment.
However, what I would say is at the end of last year, and now in 2025, there is a increasing appreciation as to what it can be, what it will be, but more importantly the risk. And I think what's driven that is that under the previous administration in the United States, there's a been a number of executive orders put out that all federal agencies have to be paused quantum agile, um, by a set debt. So that's a recognition by the US government that they are vulnerable from a, um, a cybersecurity attack for their data to be taken and then deen encrypted.
And as a consequence of that bringing into federal agencies, when federal agencies contract with their supply chain and the private sector, they also want their supply chain to be post quantum, agile and secure. And therefore that starts to get an interest in terms of how you deal with the negative consequences of quantum computing as opposed to the positive. Um, and on the, the, um, your, your reference to Q there, um, the problem statement that has to be resolved here is the same problem statements for people of a particular vintage that will remember Y 2K.
And that was the concern back in 1999, December 31st, that because computers for some reason never imagined that there would be the year 2000, the applications would cause all sorts of problems that banks could no longer give money, airplanes would fall out the air and so on, and a full raft of every banking system and every software system that served all industries had to be reworked in terms of our applications to deal with that issue. Post quantum encryption and deen encryption presents the very same problem. And there is a thing called a Moscow score that calculates and your environment and the encryption envir, uh, techniques that you have and the amount of time it takes to deen encrypt.
It will tell you when you need to start to do a remediation relative to when quantum computing gets to a position work in the encrypt. And the reality for every medium and large size enterprise is the deadline is already passed. Y 2K has already passed, the work should have started some time ago.
Um, so what we will see, and we're starting to see within our post quantum security practice, is a trickle of conversations, and I would expect throughout the course of this year that would turn from a trickle into a deluge. Some folks would say, not only has the deadline passed, but um, nation states are already hoarding encrypted data on the assumption they will be able to decrypt it someday soon. So we should we just assume that everything we thought was secure is gonna be shared soon.
Yep. So that has been a stated objective for certain nature states to steal the data now, harvest the data now and d cripple it. Um, and that has been going on for some time.
Um, it's public demand that if you look at all the various big, um, uh, data breaches in the US over the past three years, we've all had our, we've all had our identity stolen at least three times, um, uh, because of the, the large companies with the large datasets that have been stolen. And that is not by accident. That's very clear nation state, um, cyber attacks to create a situation where it can be harvest.
Now deen encrypt letter. And therefore, as a consequence of that, not only in the private public sector, but in private sector, individuals need to think about, okay, what does that mean for their own personal protection of their identity? And increasingly, we're starting to see more and more companies come up with solutions in this space, particularly in the deep fake space, um, um, and how, um, individuals can protect themselves.
So in the same way as the, the negative side of quantum computing is starting to come into the consciousness of the public sector and the private sector, it will need to come into the consciousness of private individuals as well. What is that one thing from your perspective then that we're kind of overlooking as we have this discussion? 'cause you know, on the one hand you'll see the CEO of Nvidia saying this is more than a decade away.
And other folks are saying, we've got this amazing thing that we just built yesterday. I think folks are looking for guidance. So what do you tell 'em?
The key element is to start to estimate and understand what the risk is in your environment. Um, it would be easy to panic and then think you have to remediate everything going forward. And that's the advisory services that we provide where we will help you understand where your risks are, how you should prioritize that relative to your core business processes or the data sets that you have.
And then take a measured approach to de-risk those environments for yourself going forward. There'd be some areas that you, they're not mission critical to you, you're not gonna impact your core business processes as a consequence of what happy happen here. So that's the first element to actually get visibility.
'cause, 'cause the hysteria in life in any dimension is always highest when comprehension is lost. This advisory services that we provide is get comprehension to a non level, and then you can understand the risk you have, high inherent risk. What's the compensating controls you'll put in place?
What's the residual risk you have when those controls were in place, and does that meet your risk appetite? All right, folks, you're hearing it here. Quantum computing, it's real, but like most things in life, it's a sword that cuts both ways.
So we gotta handle it with some care. Howard, thanks for being on the show. You're more than welcome, Mike.
Thank you. Alright, and back to you guys in the studio. Hey everyone, it's Alan Sch here for another episode of Jimmy Said, Jimmy says, says, thanks for joining us.
Whether you're watching us live on LinkedIn or maybe on our YouTube channel or text from TV or wherever you're watching it, I appreciate you joining and look forward. If you have any questions or comments, feel free if you're on live here to, to put it in. I wanna talk today about some irrational exuberance, perhaps or maybe not around AI and data center space.
You know, it's been going on now for a while, but it's certainly been accelerated with the incoming administration who likes to parade tech oligarchs up to the White House and talk about what a commitment they're making to, uh, the, the AI and data specifically in the us. But many mistake, this is not just the US pork barrel or, or passive of, of, you know, pledging dollars for telephone, for AI and data center. It's a worldwide phenomena, whether we're talking about Europe or Asia, China, everywhere in the world, money's being pledged to plow into AI technology and data centers.
And I, you know, I get it and I get the promise of ai, but if you look at the numbers, it just doesn't add up. You gotta ask yourself is, are we, who, who are we doing, are we doing this to political favor to keep tariffs slow or to just keep up with the Joneses? But let me give you an idea of what I'm talking about here, if you don't mind.
I'm old school on me here and come up to a flip chart and, and write some numbers down. I promise I won't write cursive, so you'll be able to, to read it. But let, let's just look at like some of the, the money that's been pledged in, in this AI data center, telethon just this week.
Apple pledged 500 billion. Everything I'm going to give you today is in billions, by the way. So that's from Apple.
They pledged $500 billion in US investment. Now, truthfully, this wasn't done as part of a President Trump thing or anything like that. It's consistent with numbers they've talked about before, but they also claim that that $500 billion will lead to perhaps, uh, 20 K jobs, 20,000 new jobs.
Wow, sounds great. $500 billion or 20,000 new jobs means each job costs us about $25 million. Those are pretty expensive jobs.
I hope people will be paid that well, but that's not all right. We, we previously saw the Stargate project, you know, with the headline by Oracle and, and, uh, SoftBank and OpenAI. So that's Stargate.
They also pledged $500 billion and said it could lead to hundreds of thousands, hundreds of thousands of jobs. Well, that's at least cheaper per job than Apple has us. But we're, we're at a trillion dollars here, guys.
Let's add in some other money. Meta has pledged certainly $65 billion this year on AI and data centers, but there's talk of them even going up to 200 billion. Okay?
Microsoft alone, that's meta Microsoft, well, they've pledged for sure 65 billion of their own, Excuse me, 40 billion of their own, but are also working with the good folks at BlackRock, the largest, you know, PE company in the world on another $80 billion pledge. And with the UAEI, I believe it's their sovereign fund for a hundred billion dollars investment. That's not all US by the way, but a hundred billion dollars.
Then we have the damac, D-A-M-A-C demac, they run by that fellow from Dubai that also currys favor with the administration. They've pledge asked small potatoes, a mere $20 billion to dmic. By the way, Microsoft says that that a hundred plus billion dollars will lead to the next billion jobs that are AI related.
That's a billion jobs AI related, much cheaper than the Apple jobs. I don't know what our economy would be like with a billion jobs, more or worldwide economy. I guess we could use it.
Now we have Jeff Bezo, he, Jeff Bezos, he's of, we're only talking about free trade and, and personal freedom fame. He claims Amazon is gonna pledge 11 billion yeah, me, a bag of shells for Amazon. But they've already committed via AWS and Amazon to a hundred billion dollars this year in data center and capital expenditures in, in infrastructure like that.
Not to be outdone, the Royal Fi family of, of Saudi Arabia. 9 billion in AI in Saudi, in Saudi itself. That's an awful lot of money.
But you know, that by the way, comes outta business, the business standard. Most of these other ones I came out of here, uh, were from, uh, all from the business standard. So if you wanted to look them up, the uk they haven't really announced their full project yet, but they have already pledged 14 billion.
So in line with Saudi Arabia, France, of course, went out and made a bold, bold mark right at that last conference. They pledged $112 billion, and not to be outdone the eu. The EU went out and said, well, France, you're not alone.
The EU stepped up for $206 billion. These are all billions with B Now, China, well, they don't really give you the real numbers and you don't know what they're really paying their people. But China has said that they are definitely committing $22 billion to ai.
And they've also claimed that China, the state government itself, in support of the Alibaba, Tencent by dance, the Chinese tech industry, the state is gonna put in $138 billion. It's probably more than that even, but 138 billion state sponsors for Chinese tech, Their version of Stargate. And then the good folks at Alibaba, one of the Chinese tech giants have pledged another $53 billion for AI and data centers.
Wow. Get your calculators out. I I tried to calculate this off, off, uh, camera earlier, depending on which some of these, you know, uh, are, are ranges we're dealing with over 2 trillion, that's with a t, not a B, $2 trillion in investments in AI and data center.
$2 trillion plus 2 trillion. Now, let me put it in perspective for you. Sorry for the aids here, Fay, but I, I like to do this.
So this is a chart, and hopefully you could see it. These are the top 20 countries with the largest GDP gross domestic product in 2024 and 2023. As you can see, the US leads this past year was just shy of $30 trillion, China 18 and change, but, and it, it falls off pretty rapidly from there.
7. Japan is just over four. India just under four UK at three and a half, but it over $2 trillion.
The amount of money pledged to AI and data centers comes in somewhere around here between Italy and Canada, right in the top 10. So the, the amount to AI and data centers ex is bigger than the GDP of, except maybe the top six or seven countries in the world. It exceeds that.
Now, where are we spending $2 trillion? Well, probably, maybe as much as half of it. I'm gonna sit back down here.
Maybe as much as half of it goes to semiconductors. Wow, that's an awful lot of semiconductors. I'd be buying more, more Jensen Wongs, Nvidia two, if I were you.
Um, you know, that's, that's a trillion dollars in semiconductor sales. Um, a lot of it's gonna go to condu generating electricity for all these data centers and all these AI processors and cooling them down and everything. We don't have the electrical capacity to do this, so we're going to need to build electrical infrastructure or maybe come up with new electrical, uh, technologies that are more efficient, less wasteful, more sustainable.
Those sustainability seems to be a dirty word in the US these days. Uh, um, or you could take another view. Is this all nonsense?
Is this just people wanting to stake their flag in the race? How much will actually be spent? How much do we know of this will actually work, right?
How much of it is going to, because we've seen this cycle before, right? The last time Trump was president, the guy from SoftBank marched his butt up there, and I think he at that time pledged $50 billion and was gonna do, I don't know, 50,000 jobs or some still cheaper than Apple's jobs. A million dollar job, 50,000.
And it was dubious whether it was spent, by the way, this doesn't include the money that was included under the Biden administration for the CHIP act to build chip foundries and data centers and so forth. I'm all for a digital future. I, I, I've been in the digital world for 30 plus years, but in the words of Alan Greenspan, is this irrational exuberance?
Is this just people trying to flatter the administration and the president in particular so that he doesn't impose tariffs on them? Is this the world involved in, in, you know, making up an AI gap? Like there was a missile gap with the Soviets, by the way, we haven't heard anything.
I don't know if Russia has this kind of money to be putting in here. 184 trillion. There's more than, you know, it's about what we're, uh, investing in AI and data centers alone.
Um, as a, a user here is writing this signals a shift towards AI driven economics, cloud expansion, expansion, and computing power dominance. I hope so, because there's another school of thought that says, Hey, AI is relatively unproven. We don't know how game changing it's gonna be.
It certainly has the promise to be game changing. I believe it could be game changing as much as the internet itself was. But at what price?
At what price, right? Are we, I don't know. Where could that $2 trillion be used?
Is it something for space? Is it for medical research? Is it to make sure no one's hungry or dying of measles in this country?
Is it supporting our aging population? Maybe we need it for more jobs, right? We, we have less people who are gonna be working.
We need AI to do more of these jobs. Ai, agentic ai, robotic ai, all, all of the above. What we're really building as Jensen Wong says is, are AI factories and that's what these data centers represent.
Or is this really all just political stunts? I don't know what the right answer is and what's true or not true here. What I do know is we certainly seem to be in some sort of bubble and, and hyperinflation or hyper expansive kind of, uh, area.
If I was a young person out there, I'd be thinking about how do I ride this wave? com days, and I was right in the middle of the dot coms. We have seen nothing like this.
It, it has the potential to change the, the world economic, uh, order strap in. 'cause I think we're in for a ride, guys. This is Shimmy.
Says, we'll see you next Thursday, Says, Hey, welcome to my session on transforming from security silos to intelligent continuous security. I wish to thank Techron Predict 25 program Committee for allowing me this opportunity to speak to you today. My name's Mark Hornby.
I am CEO and principal consultant of a little en, uh, boutique consulting firm called Engineering DevOps Consulting. I'm also author of some books engineering DevOps, as well as the more recent one eng, uh, continuous testing, quality security and feedback. I'm a member of IEEE, the Deming Institute and the Value Street Management Consortium.
I'm also an ambassador of People Cert and the DevOps Institute. And, um, my general, uh, area of focus, of course is DevOps. I've been the principal consultant for more than 90 different continuous engineering DevOps, DevSecOps and SRE transformations over my 50 year career, uh, since publishing engineering DevOps five years ago, I've been pointing out that in an area of, uh, in the era, I should say, of escalating cyber threats, the traditional separation between DevSecOps and SecOps is leaving organizations vulnerable.
Uh, siloed approaches fail to provide the cohesive insights needed to detect vulnerabilities early and respond effectively to incidents. That's, uh, despite the fact that, you know, DevSecOps has SecOps in the name, really they're still siloed operations. Typically in many organizations.
Emerging technologies like generative AI and machine learning now offer more transformative potential to bridge the gaps, enabling the creation of intelligent continuous security, uh, adapting and, uh, learning in real time. So this session we'll explore how unifying DevSecOps and SecOps with AI augmented solutions can redefine security management will examine real world security events where traditional metrics failed and demonstrate how AI and ML could, you know, have delivered predictive insights faster, um, have faster incident responses, enhanced vulnerability detection, and I'll leave you with some practical knowledge of how to apply generative AI and ML to build smarter more unified continuous security insights of a safeguard against today's sophisticated threats. So one item of note, anyone who attends this session in person, I offer a free ebook copy of my latest book, continuous Testing, quality Security, and Feedback.
com. All right, so without further ado, let's, uh, get started. So here's my prediction, uh, basically in a nutshell as far as predict is concerned, now the Predict 25 event is all about prediction.
So my prediction is that this year, a new security framework, which I call intelligent continuous security, will bridge the longstanding silos between DevSecOps and SecOps. Creating a unified approach to proactive cyber defense by leveraging AI organizations will automate threat detection, streamline compliance, and achieve end-to-end security with unprecedented speed and accuracy, and calling it in, uh, intelligent continuous security, because basically it leverages AI and com, the combination of DevOps and DevSecOps and SecOps. I would say that, uh, you know, a relevant quote comes to mind.
William Gibson's is an acclaimed American Canadian writer, often referred to as the father of Cyberpunk, uh, for his groundbreaking work in cyber in, uh, science fiction, such as his 1984 novel, uh, increments, or he is particularly known for envisioning the a digital future and the rise of the internet in this, uh, famous quotation. The future's already here. It's not, it's just not evenly distributed.
Well, hopefully it'll become more distributed in 2025. Okay, so the session introduces a number of things that I hope are good takeaways for you. Um, how AI can revolutionize the way we approach continuing security end to end across both development and operations, uh, portions of a value stream and, uh, services.
It prescribes how AI, augmented tools and AI assisted workflow practices can enhance integrated security automation practices, enable faster detection of vulnerabilities, improve incident response, and provides new and, uh, hopefully unique practical prescriptive insights with the customer use cases. How organizations can transition with AI assistance from a traditional siloed DevSecOps and siloed model to, uh, AI assisted continuous security approach that's more efficient and resilient. I'll focus on, uh, first of all, uh, an understanding of what I mean by continuous security itself and why it's crucial for modern, uh, security practices, especially in large organizations.
We'll also explore how to transition from the traditional sometimes siloed models to a more unified approach, and how AI plays a vital role in this transformation. In fact, it, I argue it's, you know, it's the enabler, uh, already security people complain things are too complex and without AI's help, maybe this isn't even completely feasible, but, um, it makes it more feasible. So by helping to automate and assist in threat detection and all the different aspects of security, the ultimate goal is to help you bridge the gap between development and operations, while leveraging AI to make the make it feasible, intelligent, continuous security focus on applying ai augmented security practices across the entire development lifecycle and production operations.
In DevSecOps, the goal is to prevent vulnerabilities during planning engineering, and in CI/CD pipelines, assuring that security is integrated from the start all the way up to delivery to production. Once the release is deployed into production, SecOps focuses on shifting to defending against exploits and attacks in production environments. What makes AI assisted or intelligent continued security more powerful is its ability to provide real-time threat detection, automated security testing, and seamless integration of security measures across both development and operations.
This ensures that we, as we progress from development to production security, uh, remains a constant and a proactive aspect. There are stark differences between DevSecOps and SecOps and the challenges they face due to cultural, as well as, uh, operational, you know, siloed activities. DevSecOps prioritizes rapid software delivery, focusing on CI/CD automation.
Well dev, well, SecOps emphasizes stability, risk, and compliance with a focus on monitoring, detection and incident response and production environments. The lack of a cohesive security strategy between these teams is often caused by misaligned goals, fragmented tools, uh, measures that don't overlap. Uh, this disconnect is further exacerbated by legacy structures, insufficient training, and the slow adoption of integrated security tools.
For organizations to truly secure their environments, we need to bring these team together, aligning their tools, data communication strategies under one cohesive security framework. There are a large number of environments where intelligent continuous security becomes and has become, you know, as as absolutely essential. For instance, in large organizations where DevSecOps and SecOps teams operate in silos, AI enables continuous collaboration and coordination, uh, ensuring the security is embedded across both development and production.
In cases where software suppliers are separated from their customers, AI assisted security enables continuous threat monitoring, ensuring that software secure even as it integrates with the customer's environment for government institutions and military applications where sensitive informations at stake, AI can manage continuous compliance checks, realtime threat detection, security policy enforcement. In network infrastructure where software manufacturers are disconnected from network system operators, AI ensures that both the software and the network aspects are secured in tandem in industries like finance secure or healthcare critical infrastructures. You know, where security breaches can have a catastrophic consequence.
AI assisted continuous security can provide continuous protection needed to meet regulatory requirements and defend against ever evolving cyber threats. Today, you know, we're facing a new wave of cyber attacks where AI is playing a central role. Criminals are using AI driven attacks that dramatically and dynamically adapt and approve, improve making their attacks harder to detect and combat.
Uh, criminals are using AI driven phishing attacks, for example, that dynamically adapt and approve making them harder to detect polymorphic malware such as deep blocker uses AI to change its behavior and e evade traditional security measures. We're also seeing the rise of AI generated fake media like DeepFakes, which are being used for fraud and extortion. Additionally, ransomware attacks are becoming more sophisticated with AI helping to evade, uh, detection by continuously altering attack patterns.
Criminals are also leveraging botnets with AI for command and control operations, making these attacks more coordinated and harder to shut down. Organizations need intelligent continuous security to match these advanced AI based threats and ensure they're well protected. Uh, recent advances in generative and predictive ai augmented tools and AI assisted workflows facilitate the transformation of security prevention and defense, uh, uh, which previously would've considered too complex and to time consuming to attempt by most organizations.
Just to be clear and to put a bow on it, so to speak, intelligent Continued security is a strategy that leverages AI and automation to enhance the integration of security measures into continuous development, delivery and operations. This goal is to proactively reduce frequency impact in response times of security events, while continuously improving detection and resolution through data-driven insights and adaptive mechanisms. Uh, this strategy builds on continuous security principles by embedding proactive and intelligence security practices into the entire software lifecycle that ensures realtime adaptability to emerging threats, maintains software integrity and fosters trust through enhanced visibility and automation intelligence con, intelligent continued security goes, you know, way beyond just traditional approaches that rely solely on agile DevSecOps and SecOps by integrating AI driven automation, continuous insights, and proactive security across the entire lifecycle.
While Agile focuses on speed collaboration and reliable software delivery, DevSecOps integrates security into development pipelines to ensure vulnerabilities are detected early, and SecOps defends production and systems responding to threats and ensuring operational security. These frameworks focusing on integration of security incrementally, but still rely heavily on manual intervention, siloed tools and periodic uh, processes. Intelligent continuous security provides end-to-end security coverage by co combining AI driven intelligence automation and real-time monitoring across the entire development, deployment, and production lifecycle.
Focusing on continuous feedback and learning to predict, detect, and mitigate threats proactively and ensures security is not just a separate phase of practice, but is always on an intelligent process. Uh, ai, DevSecOps and SecOps rely on tools for automation, uh, and generally are reactive in their workflows and require manual analysis to act on security results. Intelligent continuous security uses AI and machine learning to identify vulnerabilities faster with predictive analytics, automating threat detection or remediation processes, and prioritizing security risks intelligently based on real-time data and reducing workflows.
A agile DevSecOps and SecOps, um, is shifted, uh, left DevOps in DevOps. It shifted left to address issues earlier in development, but it still focuses on prevention and compliance. SecOps in is inherently reactive, focusing on detecting and responding to threats post-deployment, whereas intelligent continued security shifts security both left and right, ensuring continuous monitoring feedback and action before, during, and after deployment.
In the ICS intelligent continuous security framework, I outline, uh, eight pillars of practice continuous security culture in which we foster a organization-wide mindset where security is a shared responsibility embedded in every process and decision across the lifecycle. Continuing security awareness and training, providing ongoing education and training to ensure all team members understand and address evolving security threats, security integration in the lifecycle, so seamlessly embedding security practices and tools throughout the development, deployment and operations life cycles. Uh, automated security testing.
So utilizing automated tools and techniques to ensure continuous detection of vulnerabilities and compliance occurs with within security standards, proactive security risk management. So anticipating, evaluating and mitigating potential security risks before the impact systems. Rapid, uh, incident response and develop and execute different response plans to, uh, minimize damage and downtime during security incidents, continuous monitoring and sec, uh, and compliance, maintaining real-time vigilance over systems to ensure security and compliance to regulatory and organizational standards are met.
And finally, security feedback and continuous improvement. Using feedback, uh, loops, uh, to refine security practices and adapt to new challenges proactively. The following specific gaps were identified during a recent assessment, just a, as an example, uh, inconsistent AI usage.
Well, some teams use machine learning to identify code vulnerabilities. Others depended on outdated scanning tools. Uh, a lack of unified metrics.
Agile developers measured success by sprint velocities. Uh, well SecOps tracked incident response times, leaving, you know, really no shared understanding of the end-to-end security health. And the third finding was, you know, siloed communication.
You know, critical security feedback from SecOps wasn't getting its way back to the agile teams, and this was leading to recurring issues in the code base. So these are some actual examples from a, a recent assessment and for one organization. Uh, as a result of the evaluation, the team decided to investigate an intelligent continuous security approach to address the following needs.
Uh, there's always people, process and, uh, technology concerns. So in the people area, it's all about, you know, addressing cultural concerns, collaboration, again, training and awareness pillar we talked about in processes, it's getting unified security integration activities going AI driven automation. So using AI in a smarter way.
Uh, realtime feedback loops, end-to-end visibility where developers and, uh, DevOps engineers, SecOps engineers gain a single source of truth of their integrated dashboards. Uh, and technologies, again, the many possibilities here, it's always the case of where do you focus first, but AI enhanced observability tools is a good place to start. Realtime collaboration platforms, again, things like having a unified dashboard that's used by both development and ops and AI driven testing.
Uh, so having common testing tools, or at least being able to, uh, understand each other's testing results is a good idea. And that was some of the recommendations. Here are some examples of other incidents, you know, uh, demonstrating the necessity of intelligent continued security practices, integrating security testing, monitoring, patching and response times.
Uh, you can examine, for example, you know, the solar wind supply chain attack log four, Equifax. You know, many of these incidents occurred, and when you really look at it due to gaps between DevSecOps and SecOps practices, and in some cases gaps within those practices as well. Um, in the SolarWinds breach, for example, attackers exploited weaknesses in the software supply chain.
If ai, augmented continuous security had been applied, insights from continuous testing and patching could have identified tampering earlier for log four J. You know, AI augmented tools could have flagged vulnerable, vulnerable versions of the library and automatically patched systems as soon as the vulnerability was disclosed. Uh, the Equifax breach, for example, highlights importance of continuous monitoring.
AI tools could have provided ongoing scans and threat detection that would've alerted teams to the unpatched vulnerability. In all these cases, integrated, uh, continuous security, intelligent continuous security would've integrated both DevSecOps and SecOps practices, enabling continuous real-time protection against emerging threats across the entire lifecycle. This is a, a breakdown of of the move, uh, supply chain ransomware attack that occurred in May 23.
The, uh, ransomware got a gang exploited a zero day vulnerability in MoveIt file transfer software to steal sensitive data. That's costs of this were enormous. Ultimately between 200 and $500 million to some estimates, impacts across financial services, education and governance institution.
Uh, um, areas. The attack highlights the critical need for proactive security measures, uh, as DevSecOps focus on vulnerability protection. While SecOps handles exploit defense, the failure to implement patches and address new vulnerable immediately led to widespread disruption.
Uh, this case illustrates the importance of continuously monitoring, enhancing security through software lifecycle. This chart shows how intelligent continuing security could have played a critical role in mitigating the move its supply chain attack. First, with AI driven vulnerability detection, the platform could have identified the SQL injection vulnerability earlier, even before it was exploited AI scans and testing code in real time flagging vulnerabilities and automatically suggesting patches.
In this case, rapid patching would've accelerated if AI can orchestrate the deployment of patches across multiple environments simultaneously. Uh, beyond patching for active threat monitoring, powered by AA would've, uh, provided realtime alerts. Allowing the organization to respond to potential threats before they escalate can also enhance the effectiveness of system hardening.
And, uh, security chaos experiments could have, um, help with continuous testing security defenses, making them more resilient to attacks. Uh, in general, continuous security would've reduced response times, mitigated the breach impact and protection. To successfully implement intelligent continuous security organizations need to focus on a strategic transformation that begins with vision and, uh, goal alignment.
This includes setting clear objectives and aligning security goals with business priorities. Uh, next, conduct strategic assessments, which involve discovery surveys, gap assessments, current straight, uh, value stream mapping to, to establish a baseline. From there, a comprehensive strategic plan has developed the, you know, the plan includes future state value stream map analysis, themes, uh, definition, tool selection, roadmaps, implementation, uh, determining what's the appropriate governance and monitoring, ensure the accountability throughout the transformation.
In general, the entire process is accelerated by leveraging AI assisted tools to analyze results, provide insights, and guide the implementation by following the strategic blueprint organizations achieve a secure, you know, AI driven future. This slide is a prescription for transformation after strategic roadmaps established, uh, using the blueprint in the prior slides, um, the implementation roadmap is divided into four themes. So theme one is usually about preparing your AI platforms test environments and tools includes metrics and workflows that will be used to monitor and track progress.
Theme two, focus on standardization, migrating applications to standardized pipelines, farming centers of excellence for continuous security training. Theme three expands the security coverage to include additional applications in the advanced training. And finally, theme four, optimizing security processes by accelerating test creation, execution, and analysis.
EASE theme builds on the last one to create a fully optimized and scalable AI security environment. One thing I often find, which is frustrating to me, is people love to jump to theme four without, uh, investing in the earlier ones because they think they know the answer, but in reality, that often causes them to have to backtrack later and end up costing and wasting more time than it would've if it just followed the approach in the first place. Yeah, there are problems with traditional measurement approaches, uh, for SecOps and Dev SecOps and SecOps that focus on shifting security left, integrating security measures into the development of and CI/CD pipelines, ensuring vulnerabilities are caught earlier.
Uh, DevSecOps metrics are primarily inward focused, reporting the results of security scanners and tasks of software that's transiting the CI/CD pipeline. Well, SecOps, on the other hand, is concerned with in production security defense focusing on monitoring and protecting live systems from external threats exploiting exploitations. So despite the concepts of collaboration, you know, that are espoused between dev and ops and SEC teams, in reality, there's often a lack of colla of co correlation between development vulnerabilities and runtime threats and mis missing patterns in complex attack scenarios happen due to the fragmented nature of the data that's being reported.
Instead, you know, you really should look at three types of continuous security insights that are important to help understand not only the progress of a transformation, but the effectiveness of the solution as it transforms and the impact on the business mission. So to understand the progress, um, you know, look at things like the percentage of security checks and CIC pipelines and compare vulnerabilities detected pre-production, first post-production, meantime to detect, as well as DevSecOps, SecOps collaboration metrics, things like joint incident response plans. Incident insights are derived from, uh, sorry.
Effectiveness insights are derived from improvements to meantime to remediate, um, reduction in security incidents, false alerts, compliance and costs, making those things visible across the whole lifecycle. And business mission insights could be things such as downtime due to security breaches and security spending as a percentage of IT budget, uh, to understand the overall effectiveness of your strategy. Uh, these metrics basically are important to understand how AI augmented continuous security improves outcomes and performance at the business level.
Uh, platform engineering these days is a hot topic, but frankly, it's not really a new concept as far as I can tell. In having been involved in platforms for many, many years. The idea of providing a simple to use portal for stakeholders greatly, uh, simplifies the use of many tools and tech stacks needed for day-to-day tasks.
Certainly that is true for security as well. Uh, platform engineering, specifically around intelligent continuous security brings together automated and AI enhanced capabilities into a centralized environment to manage security across the entire software lifecycle. The platform provides continuous monitoring, automated compliance checks and proactive incident response.
That's an opportunity for platform engineers. One of the greatest advantages here is the scalability. It offers helping your organization stay ahead of emerging threats by enabling real-time detection and mitigation.
While aligning development ops and security teams creating more efficient security posture. Intelligent continued security helps close a number of critical gaps that arise from siloed, uh, DevSecOps and SecOps practices. Some of the key gaps include inconsistent or delayed threat detection manual processes that lack automation, fragmented security postures across development and ops.
These gaps lead to vulnerability, blind spots, misaligned security objectives, and slow response to threats, uh, especially emerging threats. By leveraging ai, we achieve continuous monitoring, real time detection, automation across the lifecycle, ensuring they're no longer, uh, operating in isolation, but integrating and unifying across the, the lifecycle. Alright, I think I skipped this line.
Yeah. As we move through AI assisted transformation, it's important to avoid common pitfalls. I'm not gonna read this whole chart, but basically, you know, for example, lack of team alignment can lead to delays.
So it's critical to create shared goals and hold regular cross team security standups. Infras vision automation is another issue. Automating security processes such as CSD, patch management and incident responses key, uh, ensuring real-time monitoring is important.
Siloed tools, you know, try to align tools better and, you know, try to, uh, really focus on continuous improvement. Uh, o over omitting that is a critical error because there's always gonna be ongoing requirements Changes also is important to motivate and successfully manage transformations. And no doubt, you know, this is a complex topic and, uh, it's important to educate, align, and motivate people to keep, uh, to get momentum and to keep momentum going.
Uh, demonstrating value with clear IRI examples is a good approach. Developing necessary skills, fostering culture shift towards automation, or just some ideas, encouraging innovation with teams, adapting pro, uh, project management processes that support transformations rather than just compliance and strengthened. Vendor partnerships are, are some examples.
So as we wrap up, you know, um, there's some advantages of continuous security, intelligent continuous security. You wanna just summarize with that. First, we see I ai augmented security teams, uh, improving safety deployments and enhancing threat detection across the lifecycle, providing faster and more accurate results, and, um, reducing false positives, providing more efficient vulnerability management and adaptive security automation.
Some examples continuing on this, uh, conferences theme of predictions. You know, if I look further ahead, you know, I believe in a longer term future where security is heading towards what I'm just, uh, penciling as something I call the SEC dev and ops model, where, you know, as we get, uh, more security becomes and AI becomes more integrated into security practices, traditional distinctions between development, security and operations, I think are going to blur faster. Lead times continuous delivery and shift left strategies are already pushing security towards faster deployments.
Uh, AI will push this further, enabling predictive threat analytics, autonomous security measures, and AI automa augmented decision making with advances like feature flag rollouts and no shift deployment models. You know, smart automation will allow us to secure systems with minimal human intervention. So it's an exciting feature where security becomes part of the fabric of all operations.
So my last slide, if you wanna learn more about intelligent continuous security, continuous testing, quality engineering, DevSecOps, SRE, I encourage you to get a copy of my new book. And again, if you're attending this talk, uh, send me an email, I'll send you an e e-version. com.
Thank you for your attention, I appreciate it. I hope you have, uh, a good conference for the rest of the talks. Thank you.
Hi everybody, and happy new year. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jodi Ashley, executive producer here at Techstrong, and I'm here with my co-host Tracy Ragan, creator and CEO of Deploy hub, and very busy lady when working with the Linux Foundation.
I'm sure it'll come up today. Before I introduce today's guest, I wanna give you a quick update about what's happening here at Textron. com, so be sure to go and check that out.
We have a lot of virtual events happening, uh, predict 2025 is coming up. If this airs after that, you can go out and watch it on demand, and I would recommend it. It's gonna be an awesome virtual event, so you wanna be sure and check it out.
com, and be sure to tune in every day to Tech Textron TV for great shows and interviews. Okay, Tracy, it's 2025. What's on your mind today?
So, over the Christmas holiday, I, I, you know, I, it didn't do a whole lot, but I would still watch kind of news coming across, particularly around cybersecurity and Space Force because it's something that I'm particularly interested in right now. And this, this article came across about the DOD and, um, you know, tackling Weapons Cybersecurity, and it talk, it talked about, you know, that there's work that's being done to address cyber threats all the way down to like code level. But something in that really bothered me and it said, let me see if I can, I'm looking at the quote.
Um, basically it said that they know that there are, uh, vulnerabilities out there, but they're willing to take the risk not to address them. Um, I'm not sure why that would be the case. I don't understand it, uh, because it bothers me that we can do better.
And even in weapons security, I, I, I feel like there is a lack of real understanding what these vulnerabilities are across the whole spectrum of cybersecurity. So to just say, you know, the, the risk is there, we understand it, but we're gonna move forward anyway, um, is kind of a bother. It kind of reminds me of the recent fires in, uh, California, that area, Pacific Palisades that they've been, they've known for quite some time that it's a high risk area for, uh, flooding and fires.
Uh, but we did, how much did they do to, to, to make sure something as catastrophic as a firestorm didn't happen, or how, how prepared were they? So I feel like we've gotten into a, a place, maybe this happened in 2024 or maybe it's always happened that we're complacent when it comes to, um, predictions, right? Predictions about what could happen in weapons cybersecurity and saying, we can take the risk even though we don't know completely what we're talking about, we're okay with taking the risk, or is there something more we could do with protecting something like the Pacific Palisades from Firestorm?
So it, it bothers me and as, as we go into 2025 with Gartner predicting a tripling of vulnerabilities, I feel like we've just been bombarded so much with these kinds of threats that we're just, we're numb to it. So that's my concern for 2025. And I, I feel like it's a discussion that should be had within all organizations right now about how proactive we need to be.
Yeah, I can imagine reading that drove you bonkers. It was kind of shocking, right? It was like, yeah, something like Space Force sa something like Space Force, you know, that a general would say, you know, I accept the risk without any clue of what they're, what I'm actually accepting.
I'm just gonna move forward. God knows what's gonna happen in 10 days. Well, the people who are attacking us are not that complacent.
They're on their toes, right? Yeah. So we have a formidable, uh, uh, component, uh, component opponent out there that we need to be serious about.
Yeah. But we have an incoming president who wants to change his mind again and move Space Force to the state of one of his cronies. Like he, before, before the last election, he was moving it to Alabama and then Biden said, no, it's staying in Colorado.
Which obviously I pay a lot of attention to living here. And now he's talking about moving it again. So let's not focus on the secure side, let's focus on moving it and wasting a ton of tax dollars in the process.
But that's a whole nother conversation. Yes, it is. All right.
Well we have a really cool guest today. I would like you to introduce you to Sal Kimmich. Is ki it Kim or Kimmit?
They're both good. They're Both good. Want me Say, I like to say it right though, so well welcome and tell us a little bit about yourself.
Yeah, actually, um, it's probably, I'd love to dive into a little bit the commentary on the DOD. Um, so I have a pretty unique background in and with open source in that throughout my career I have inhabited almost every profile of an end consumer that you, you can map. So I have been an active consumer in a federally funded program between both the US and the uk.
I have been a machine learning engineer working within the DOD. So my first contracting role in DC was with the Missile Defense Agency. And then I moved to go work with the US Air Force, their Kessel run software incubator.
I then only left security clearance because I got married and moved to the uk and I did ask, can I work remotely for this skiff in a foreign country? And they said, no, obviously not. You read the contract, you know how this works.
Um, so I jumped into for the first time the corporate layer of open source, uh, which is generally what most people get exposure to if they're using advertising or marketing to understand it. That's the only layer that they'll ever experience. But it's really, really important and we probably should dive into why they would accept vulnerabilities, um, in the DOD specifically, uh, because it's changed a lot in the last five years.
And I think that's really positive the ways that it's changed. Um, so if you are an end consumer of open source as a federal developer, there's a couple of really interesting things. So number one, you're never going to upstream.
If you upstream once onto the thing that you were consuming in the last couple of years, you would not just immediately lose your job, you would lose your security clearance, you would never have a career again, right? And it's not one or 3% of open source consumption that is specifically in this case, federal. We're not just talking about the larger and global government consumption.
That's a different number. And that varies particularly by the European country that you're dealing with. And they've got government style OPOs in order to be able to engage with it.
But I had someone come up to me at a conference earlier this year, it was someone really early in the career, and they did ask me this question, what percentage of open source consumption do you think is federal? And I was sitting at a table with a color, couple of other open source leaders and I said, Ooh, it's literally impossible to know that answer given the design of the system. But I would estimate somewhere between 30 and 35%.
And then the only reason why I'm willing to say that publicly as something slightly more than a conjecture, even though that's all it is, there's no stats. I then turn to someone who works in a major corporation that I know has not just a general osbo, but a specific federal osbo. And they did not speak a word, but they did give me odd and a shrug as if that is about correct.
Right? So for every two of the developers that developers that you're thinking about consuming an upstreaming to open source, generally there's one that is consuming that information and has to have alternative pathways of communication, mainly regulation, in order to make sure that those things are secure. And I think this is really, really interesting when it comes to security vulnerabilities of the supply chain.
So the first job that I ever took coming out of security clearance consumption and coming into the open and general corporate layer of production and open source was specifically sonotype. I did that because I think that they have a really, really interesting and pretty direct approach and engagement. They are really focusing on making sure that they can secure that supply chain or that end consumer class.
Now, I think in order to not be so afraid of vulnerabilities as they exist on the internet and on platforms like GitHub and GitLab, you have to understand that all of these things are built over kernels. And there are many different kernels. I've mostly studied and investigated the Linux kernel.
There are other kernels as well. And even the Linux kernel is not a single kernel. There's about seven of them that are really, really important.
There's three of them. There's like the main line, the main kernel, which most people generally use. And then there's a long term kernel of which they're very, very sincere in making sure that no vulnerabilities come into place.
And then number three, when you're dealing with vulnerabilities and open source, you have to become extremely familiar with understanding the zero day marketplace. So when there is a critical vulnerability that has been observed and been highlighted in the days and sometimes weeks before, a zero day, a zero day just literally means you have zero days to patch zero days. That's what it means.
It is bad, it's immediate, and it's pervasive. Um, and so when you received a zero day vulnerability, you have to understand that all of the work has already been done to secure the critical infrastructures that you depend on. Now this is not just the DOD, these zero days and the work done before the zero day hits.
Public and corporate are protecting things like major cities, water filtration systems, those largely run on things like, like Kubernetes these days. So I think that's really interesting to dive into and to to consider. It's a very different world of open source.
Um, but it's increasingly important. And the nature and the style of leadership within the DOD has changed. This is not so much due to the leadership in the executive branch.
They are separate, but it has changed because of one very, very specific condition. Uh, this is the fact that generally, depending on the country that you're dealing with, it takes exactly four days of unlimited assault onto a foreign territory before you go into a condition of what is defined as protracted war. When you're in protracted war, you begin to engage in a very, very different series of process, specifically in the chains of command with NDOD, so that you can be highly responsive to it.
So that's had an impact on the way that open source interplays with it. But also there's no difference in the actual nature of playing with the human gen like DTUs that is open source. You have to use it because it is where the progress is made.
You have to use the intelligence of the commons in order to get the right answer. And then you have to set up additional processes to make sure that is maintained as secure. Um, so I I really enjoy watching that space.
And I also really now getting to watch it from afar. 'cause I'm absolutely just engaging in the corporate layer. Um, which doesn't typically have this kind of insight once you're in security clearance, unless you leave the country, you're probably gonna be in security clearance the rest of your career.
But in the, uh, Gartner, uh, report, I, uh, I only read snippets from it, it said that 58% of they, they said that code level vulnerabilities would probably triple with about 58% going after government and cyber infrastructure, right? Are, you know, our utilities are, uh, healthcare, the, the, the infrastructure, the technical infrastructure that we depend upon, that's where those vulnerabilities will be targeting. Um, and I, you know, I, uh, it would be a curious thing to be able to get an SBO m from every single one of those cyber, uh, kind of infrastructure teams and the code they're delivering and look to see exactly what's what, what open source packages they're consuming, because those you would think would be the most then critical ones that we should be monitoring.
You know, and at least minimum require for those teams to have an open SSF scorecard, right? At minimum to show that they have some commitment to adhering to security policies. Just a, it's a, it's an interesting topic and I think that, um, there's part of us, and I'm reading this really interesting book, book called Sapiens and it talks about how we um, as our brain kind of developed, what drives us, if this is a weird one, is gossip and fiction and it has for thousands and thousands of years.
Sounds About right. I know. And we will believe anything we choose to believe, right?
So it's easy to say, that will never happen to me. It's easy to say, I can excuse those risks 'cause I don't believe it will ever happen because we wanna believe in fiction and if somebody tells us we're okay, even though we may know the data shows differently, we're gonna believe what we want to believe. Really interesting right now.
Now Sal, you have a PhD? Uh, yes. Interesting story.
I don't, but I can explain why. So, um, so I, most of my undergraduate training was funded by, uh, the National Institutes of Health. And it included both a total consumption of my costs.
So it included everything down to my rent and my healthcare. And then I was immediately positioned to do an accelerated PhD between the US and the United Kingdom, specifically working on realtime signal processing, um, for medical interventions for the human brain. So I have this great and interesting background and one quick note there, if you can get one of these unlimited, uh, government funded undergraduate degrees.
I went and I checked the contract that I was signing and it said, we will pay for all of the classes that you need to complete your degree. And I said, wait, is this limited or is this unlimited? And I found out it was unlimited.
So I in fact left my undergrad with two majors and two minors because I didn't have to pay for them. I could just pursue it as true education, much more European style. So I got a degree in cognitive science with a focus on neuroscience where I was doing all of my statistical work.
And I got another degree in political science with a focus on public law. I really enjoy. And I find it very interesting to look at history from the perspective of codified law because it gives you much more information about who is in power, how is the PowerT and how is it maintained or lost.
You can do that by analyzing law much better than you can by sociology. Um, but then I jumped into this accelerated PhD, so it was a three year minimum. I already had a first author paper route and if you wanna look at anything from my security clearance or my academic background, just don't search sal, search Sarah, SARA, I go by Sal because I asked mechanical Turk what three letter moniker was easiest to remember and signaled authority.
And then I used that in order to enter open source quite literally. And when I, when I look at gender and pronoun dynamics, I really, myself, personally don't care. Any pronoun said to me with respect will be treated with respect.
However, generally if it's in writing, I'm going to prefer they them because I don't wanna be indexed into a specific profile that could have a bias and an algorithm. And 100% of the time, if I'm pursuing a promotion, I will request that we use he him pronouns. Not so much because I believe there's gonna be any bias from individuals that have previously worked with me.
But because it's very likely that there's an internal system that is relying on an algorithm that probably does have bias. So let me just bias it me right direction for myself. But here's why I don't have a PhD.
It's a great story and it comes from a very good mentor. So I had two different mentors. I had one at the signal processing lab at the National Institutes of Mental Health in dc technically Maryland.
Um, and then I had another mentor who is the head of the art and sciences, uh, section of the University College London, who was generally just there for life advice. And, uh, I had put together a online course that taught about a thousand people how to, uh, put together a machine learning pipeline specifically for brain imaging. And if they completed that and they did a peer review style, uh, or prepared for peer review style paper, then I got AWS open source to fund the credits for them to be able to complete it.
I got that done, I put that out online and I immediately started getting inbound requests for jobs. I turned most of them down 'cause I didn't find them interesting. But there was one job that sounded very interesting because for about four months, the CEO just kept on calling me up and we would have discussions about potentially what I would do if I went into security clearance.
'cause I was not interested and I had to be convinced. Um, the CEO was also previously a, uh, a, uh, fighter jet pilot. So very interesting because they were leading based on the profile that is impacted by the end consumption of open source, right?
Very serious. They know that if they get this wrong, right, if we mess up this vulnerability chain that will result in a death, right? So sincere and that kind of leadership style is much more available in systems outside of the corporate space.
Um, and I always look for it, but the reason why I don't have a PhD is because my advisor on the UCL side, I said, okay, unfortunately I really do think there is a job here that I am inspired by and would really like to do. And he said, Hmm, how much money are they offering you? And I said, this much money.
And he said, oh, okay. If money matters to you, I need you to know that that's more money than I'm making right now. I said, I, I think that matters to me.
And then he said, okay, you know what? Go do this. Go do this for a year, 365 days from when we stand down your PhD research.
I want you to send me an email and let me know if you wanna come back and finish. And, uh, I remember the day, 'cause there were moments in and out of my first year of getting involved and stood up in federal software production where I didn't know if it was the right fit for me. And, uh, but it happened to be that on day 365, I was working remotely in Barcelona that week.
So I wasn't producing code that week. I was just attending internal meetings. You cannot produce code outside of a skiff.
But I was doing a like semi vacation working on a beach in a foreign country. And I thought to myself, I can do this while making more money than I would make in literally the highest leadership position that I could ever possibly get into in open, in, uh, in academia. Uh, so yeah, it's just because money mattered to me and because I had been able to raise the signal on all the things that are important to a corporate producer or to a security clearance producer.
Can you demonstrate that you can do the work? Yes. I already had a first author paper out, so I didn't really need to wait.
I had already gotten it done. And then number three, can you excellently communicate and propagate not just your understanding of the topic, but the ability to actually do the topic to other people? And if you have those three things, it makes it very easy to get a very, very good and interesting job because there are so few people with that combination of skill.
And um, yeah, sometimes I fantasize about going back to academia, but I just cannot pull myself to do it. 'cause it used to be that I had to be in academia 'cause I needed access to supercomputers. And I really particularly love the supercomputer at NIH because if you work in this space, high performance computing of any type, you know, that our clusters are called, uh, bale wolf clusters, but not at NIH.
We named them bio wolf clusters. And I'm very get over thinking that. I I just love that.
Um, but, uh, we've Had a very interesting journey then into employment as a woman in tech. You know, it is so many avenues and I don't think we've heard this avenue before. You know, that you yes, you basically did add the, um, the idea of getting, basically getting your education covered.
Mm-hmm. That's amazing. How, so how did you find out about that?
Did, did you just stumble across it or did somebody point you in the right direction? Yeah, well I had very sincere financial need. Um, so I was looking for the best opportunity out there.
And I got involved in research the second that I got to school, quite literally the first quarter of my first year as an undergraduate, I went to uc, San Diego. And, uh, there was a professor there that was doing research on the cognitive design of cockpits for Boeing. And I myself am a pilot.
That's why I'm always interested and have a portfolio that keeps leaning into aviation. Um, but uh, they had shown us some transcripts that I just knew could not be correct. 'cause you have to use alpha numerical when you're talking to a, uh, a control center.
And I said, Hey, I think I can just correct these for you. Um, and that was how I got involved my first year, my first week of undergrad in research. So it really, and and, and this is true.
So when I, you have to be so sincere about research itself. All of the classes that you ever take at any university that you ever take, you will never be better than everyone else in the room. And there's already gonna be 30 of you or 300 of you.
But when you're pursuing research, you have the ability to see if there is knowledge that needs to be redu produced, go and pursue that knowledge and then share that knowledge as widely as possible. So the first study that I was ever published on was on, uh, cockpit design of Boeing seven 30 sevens. And to this day, in my own consulting work, I use that all the time.
I typically go and I'll speak to like mid-sized banks or something that has a critical service to it. And I simply explain to them this, you now exist in a world where you had site reliability engineering and you understood that that was real time. But as we think about cybersecurity and the conditions that we have been growing into, cybersecurity is now a real time event.
It has to be acknowledged in real time, has to be patched and as near to real time as possible. So I go in and I will teach them to use their dashboards like a cockpit combining both SRE and cybersecurity whenever possible. But here's the second layer of that, that's really important, especially if you're paying attention to, say the Cyber Resilience Act right now.
Um, there's something different about aviation than software and I think these are going to converge. We're going to create a thing like a com, like a compliance crap. It's all gonna look the same at the end of the day as this evolves.
So if you are in a commercial aircraft, you're gonna have a black box. If the thing fails, there is going to be a perfectly preserved audit log that should allow them to understand exactly what went wrong. That is essentially the ask of the CRA.
They need you to have a verifiable and reproducible audit log of your cybersecurity methods and operations. And you should make that as automated as possible and work into your operational design. Um, and I'm super excited to see that.
'cause I think that's really important work. And when I look at the way that compliance and regulation are evolving for software generally for open source to some degree specifically, but generally in the sector, I do think it's really appropriate to go look at the past 50 to 60 years of aviation compliance and understand how similar those things begin to look. I could not agree more.
You just just described what we've been doing at our and Deploy hub. We used to call ourself the black box of software because the problem is is that the, the, the pipeline itself for every c when we were doing monolithic, we, this argument of didn't hold as much water because everything you did in the pipeline related to that one software solution that you were delivering to end users in one big monolithic ball, right? So you could have a black box, you could see, you knew where, at least where the logs were.
But when we're fragmented with hundreds of microservices that make up a single application, that black box is a hundred black boxes. They, it nothing is, nothing is centralized. And you don't know if they're all, um, living by the same security compliance.
You don't, you have, it's very hard to see that. So centralizing this kind of data in, in the way you just described should be applied to every piece of software that we, we push out the door so we have a full view of it. And it has to be versioned.
It can, it's not just for the application at the time that it's executing, it's over. It's the history that gives us the insights. It's the change, right?
It's the change that shows what went wrong. Mm-hmm. Um, so yeah, there's so much to be done in, in software for this discussion.
We recently, this continuous delivery foundation, of course I'm pushing it recently started a new SIG called the CI/CD Cybersecurity sig that we're really gonna look at models because pro, part of the problem of building that black box is that DevOps engineers don't necessarily have time to go figure out what they need to add to every single workflow. And this is going to be a manual effort to build that black box. We gotta make it easy.
We gotta make a, a model that people can say, here's a, an example plug in that I can use. Here's an example command line interface that I could use to generate SBOM for god's sakes. Something as simple as that.
So I'm glad that you bring that up because it is incredibly important for software as we move forward. Now I wanna talk about your background. You said you were in Barcelona, but now you are in Italy.
Tell us what you're doing in Italy with uh, awarding open source. Okay, well first off, I think I do a lot of personal travel now because when I was on government funding as an undergraduate, the one thing they would not let you do is study abroad. They'd let you go study at MIT in the summer, but not abroad.
And I wanted to see the world. Um, so, uh, for the last three months I have been here in Kunio, Italy, which is not a well-known place, it's not a very large town. It sits on a wedge in the Alps.
Uh, and it's extremely protected traditionally from uh, like land attacks. Um, so I came here 'cause I was really interested in this place, which is well known to people that study sovereignty as a physical location where this city itself has remained sovereign to both political influence and religious institutional influence, which is very unique to Italy. Um, and to kind of just observe that and understand that.
So I'm here 'cause I'm doing my own midlife study abroad, but, um, I'll point you right up to the ceiling real quick because you should be able to see that is beautiful masterpiece. Absolutely. I know, I thought she was sitting in the Sistine Chapel for a minute when she, when she logged in.
I'm like, oh no, that's actually a real room. Yeah. But, uh, that was commissioned by the family, the body family in the 17 hundreds.
That's their crest right behind me. Um, and uh, I came here specifically because, you know, I've, I've got insight into the government layer, government consumption layer. I've been working in the corporate consumption layer.
Um, but there's something that everybody forgets and it's that open source is also just incredibly fun. Um, when you look at vulnerability, sustainability, maintainability, you have to recognize that these are all building blocks. And some of them are created specifically to be supporting critical infrastructures.
Those are well protected. Those are well maintained. They'll be sitting in something like an antitrust.
But there's a lot of one-offs, really interesting things that are produced in open source that aren't meant to have a general audience. And if they are, it's a very small audience. So we're doing a series of awards.
I'm working with Art Farrow on this and I'm waiting for whatever his videos come out to be. 'cause I said the one thing I'm not is creative. You do that part.
But, um, we're doing a series of awards based on every single Greek muse and we're gonna go find the open source, either project or committed commit, uh, community, um, that really aligns to those values. Are you working in science? Are you working in art or music or in historical preservation?
Um, if you're doing something like that in open source, I think it's really important to remember that that whole world still exists. And then to also understand this, um, it's very, very true that there's an absolute alternative to burning out in anything. And you can call it something very simple, just call it burning in.
Like stop paying attention to your retention statistics at a corporation. Pay attention, right? If they're about loss, really pay attention to what is it that you're doing when you're doing it right.
Um, and one of those things is allowing people to have and to develop their passions with technology. So I'm using this opportunity as a time to help to highlight people that are genuinely showing something that is so passionate that I find it interesting and inspiring and worth sharing. I have one last question before, 'cause I know we're gonna run outta time, but I really have to get this question out because if there is somebody who's watching this who is an undergrad, which I hope they are, how did you find your research project and was that a government grant that the, uh, uc, San Diego was involved in?
Yeah, so I, I mean honestly I started applying for funding in my first year. Whatever I could find, like, is there an associate, so You yourself were looking when you were applying for funding, where were you applying to? So I started at the institution and then I started looking, uh, specifically into my, uh, degree program.
And I started going and getting the professional level education that you need and pursuing external organizations. So two things that really helped there. I was working with the cognitive science department and they had a bursary that was available exclusively to graduate students to support their research with training.
Okay. It's not exclusive if you go and ask. And so I went in and I got some funding to be able to pursue independent training.
That's how I got connected originally with the Martino Center outside of, uh, or in Boston. And the, uh, like brain, uh, and Cognition Institute from MIT. Um, so I went and I pursued education that was at one level higher than what was expected for me at my level because why would you wait to get it done?
And then number two, I just break through whenever I see an arbitrary gate being kept closed and I will ask the questions, what are the conditions by which I can open this gate and I will ask it to the person who has the door locked. Um, one of those conditions was very important to me. Uh, so I really wanted to join the association for the Scientific Study of Consciousness because I was studying real time interventions using FMRI brain imaging.
Um, and I was told at the time that, that's great. We'd love for you to participate in our student committee, but that's for graduate students. Now, one year later, I show up to the same person who helped me in my PhD as well.
I show up to the same person who had that door locked and I said, hello, I am still an undergraduate. I have full funding, not just for myself, but for my research. Does that satisfy the condition of being a serious researcher in this space?
They said, yes. They let me join. I was immediately working with the professionals in that field.
Um, so go and look at gates, see if they're actually closed, see if you can get them open and if they are closed, make the conditions discreet, get them in writing and see if you can fulfill them. When you're fulfilling those conditions, great, you're done. You're set.
Now there is another thing that's really important. I pursued biomedical research. So in order to do that with human subjects particularly, you have to be working under something that is called an IRB form.
So the in Institutional Review board, um, I have a curd of many undergraduates old in one of those themselves under their name. But I was pursuing independent research. I was creating my own research designs and then using the funding to get the data done and then to produce those methods.
Um, and that worked. I just didn't tell myself that any of those were conditions just because they're arbitrary and they exist to satisfy a societal expectation of when you'll be ready to produce intellectual property. And if you're pursuing open source, you're ready already.
It's why you're here. Um, but one thing's really important because it's mentorship and I know the best mentor that I ever had in life was Dr. Lisa Eer.
Uh, uh, Dr. Lisa Eiler, uh, from the VA hospital in San Diego. And I remember going to her early on and I was shopping around and asking every single lab that I went to, do you think I can get a first author paper done as an undergraduate?
And I had some people actually laugh in my face when I said, that doesn't matter to me. That's just a closed door. I'll knock on the next one.
But I went into her office and she said like five words to me that were so powerful 'cause I had never heard them before. I've been well supported, well coached my whole life, but no one had ever just said about something I wanted to do. You can and I'll help you.
So simple. But that's not something that women hear. Women versus men are much more likely statistically to hear a no when making requests around funding, when making requests around promotions, all of these things.
Um, and she just recognized something burning in me, the fact that I was really burning into consciousness studies and to modeling and interacting with consciousness as a computational design. Um, and she fully, fully supported me. And I will always be grateful for that.
And it's something that I make sure to say explicitly to anyone that I am mentoring, find out exactly what it is that they wanna do in life, see if I can support it. And then I do everything in my power to do that. Sincerely, You can and I can help you.
Those are very, very powerful words, right? Mm-hmm. That's amazing.
Absolutely amazing. It, you know, we hear, uh, the journey of women all the time and mentorship is always at the core of very successful. Absolutely.
Mm-hmm. That's what we hear. And it's not just mentorship from other women, it's mentorship from men as well.
Mm-hmm. Yes. Mm-hmm.
Yes, absolutely. Men are part of the solution. They are so much part of the solution.
Yeah. They're also part of the problem, but that's a yes. Yeah.
Yes they are. And I don't know how much time we have. Yeah, we're pretty much there.
You ladies. Um, can we just ask a question? Yes.
You ask your question. Recommendation. What is a book recommendation?
Tracy always have recommendation. Uh, so there's two books that are super important. Um, actually I have one of them sitting right over there.
It's, uh, cybersecurity for Generative Systems. It's very good. Um, another book that you should read if you're really interested in understanding the state of cybersecurity is, uh, the Cyber Deception book.
So there's a Cyber Deception 1 0 1 book that comes out for, um, FinTech services, uh, about every two years. And it basically explains how you create honeypots and artificial systems in order to observe Adversarials attempting to get into your system without letting them do it. Um, that still is incredibly important work and it's one of the most evolving areas of cybersecurity because now it's just agent on agent artificial intelligence.
Um, but I do wanna jump back to one thing that I think is really important to consider and think about, especially at the corporate layer for vulnerability, uh, analysis and awareness generally. There's two approaches to it that we can take. One of them is the one that most people are currently taking, and it's basically doing a scan semantic analysis and identifying either the vulnerable project or the vulnerable code snip, uh, that's incredibly computationally extensive.
And it may also encourage people to be pursuing a vector of comp of compound vulnerabilities always remind people that log four J in itself was not a vulnerability. It was a compound vulnerability when in place with j and DI that made it harder to catch for a while. Um, but there's another approach to this that is entirely different and it is using category theory in order to find those conditions.
So applied category theory is a way to begin analyzing vulnerability. Uh, and it would allow you to find categorical conditions and to avoid not just a single code snippet, but to actually be able to see, and when I say categorically, it means we have set condition A feeds to set condition B feeds to set condition C. We now know exactly how many projects have that logical, substantial backend, and we can remove that vulnerability, whether or not it looks the same, we can remove that logical compound across languages, across semantic complexity.
That's a direction that we absolutely have to go into. And it's not something that is a far out there idea. There are some r and d spaces that are looking into this.
And you must understand very importantly that this is an idea that particularly the US pays attention to NIST organizational design. All of the things that it gives down for us to be compliant to are to be a CT compliant. So if you're interested in this space and you wanna understand and start thinking about it, then go to the top of the supply chain.
Well, mental chain of understanding. Can we categorically provide the best solution possible? We're gonna do that with applied category theory.
It then comes down, it gets right now interpreted into a semantic language that we're communicating out. And that's where there's a lot of lossiness in communication 'cause it's human to human communication. But if in the next 10 years or so, and I always say apply category theory is the answer to everything, we just haven't found it yet.
And that is so true. Um, but if we can close that gap, uh, we're gonna be able to avoid those conditions, not just in the current reality of production, but also moving into a quantum compute reality where they also will be able to have a much more efficient way of scanning if they're doing it as an adversarial. So we want to make sure to categorically remove those logical conditions moving forward.
And that I think is the most interesting area of cybersecurity right now. Well, thank you so much. Um, that's a great place for us to wrap today and we really appreciate you being here.
Tracy, you got anything else before we wrap this? I'm just glad she mentioned Quantum. Yeah, I know you're into that too.
All right, well thank you so much for being with us today, Sal. And thanks to our audience for joining us for another, um, fun filled and very technical episode of Up Techstrong Women. Um, we're excited you were here and as I said, keep watching Techstrong tv.
There's a lot of a lot more shows to watch today, so stay with us. Thanks again. Have a good day.
Hey everyone, this is Alan Shimel for Techstrong and you are watching another edition of CD pipelines. Ed Pipeline is a, uh, monthly video series put on by us here at Techstrong in partnership with our friends at the Continuous Delivery Foundation, the CDF. And, uh, we're gonna tell you a little bit about the CDF in just a moment.
So if you're not familiar with it, not to worry we'll get you familiar with it. But basically we every month pick another topic of interest to those in the world of continuous delivery, CI/CD, DevOps, and, um, explore it a bit. We've looked at the various projects that are under the cd f umbrella that they manage and own.
Uh, we've looked at trends in the market and how some of the mega trends are affecting cd, just about anything that that touches on cd. Uh, we unfortunately, I, you know, taping a recording, no one tapes anything anymore. Who am I kidding recording this?
Uh, right after, uh, a Ws re event last week, we've lost a person or two from our panel. Uh, so as we call it the AWS Reinfect kind of syndrome where people get stuck. So our co-host, Lori Larussa, is, is not available to us today.
She is under the weather as is we think the DC sonika, who actually happens to also be the chairperson, uh, for the CDF. So we hope both of them are feeling better and we'll have 'em on at our next CD pipeline show. But the show must go on as some famous someone said at one point.
So let let us March on. Let me introduce you to our, uh, panel members today. First of all, uh, well joining us, he's the open source advocate at IBM, Andrea Fritolli, Friley Fri, not Fri Friley.
Oh, is that Andrea? Welcome. And I, I said you were an open source advocate at IBM, but maybe you can add some more color to that for us.
Thanks, Alan. It's great to be here. Yes.
So I work at IBMA software engineer and developer advocate. I focus on open source and as part of my open source, um, job and work that I do, uh, I serve, uh, for the Continuous Delivery Foundation for the CDF as chair of the Technical Oversight Committee. And I'm a, as well a, a member of the governing board and, but I'm a software engineer, uh, and I'm involved in maintaining some of the projects within the CDF and I co-founded the C events project that we're talking about today.
Wonderful. And thank you. Thank you for what you do, you volunteering as well.
Next I want to introduce you to Gerard McMahon. I messed that up, but Gerard correct me please. Uh, so it's Gerard McMahon, as we say over here in our end.
And, and Yes, Gerard McMahon. Gerard, why don't you introduce Yourself? Thank you, Alan.
Um, so my name is Beck Mahan. I work for Fidelity Investments and I'm part of the CDF governing board at representing the end user members. Um, my role here in Fidelity is heading up what we call a LM Tools and Platforms.
So providing the tools, the platforms, and the services for all of our developers at Fidelity to, to, you know, to build their code, write their code, build their code, test their code, and deploy their code to our customers. Okay, thank you and welcome Gerard. Uh, last but certainly not least is Ben Powell.
Hey, Ben, how are you? Good. Doing good.
How about you, Alan? Very well, thank you. Ben.
Why don't you introduce yourself? Cool. Yeah, so I am a software engineer at Apple.
Uh, so I work primarily on continuous delivery tools. Uh, prior to that I was actually at a WAS, uh, speaking of reinvent, um, I was on the SDKs and tools, uh, team and then eventually ECS. So a lot of experience, uh, in that regard.
Um, so I am a retainer of the CD events, uh, org and repos as well. So I help kind of facilitate, uh, the spec as well as, um, a sig lead for the implementation sig a part of CD events. Excellent.
All right. Um, so guys, I, I feel it necessary for people who maybe are catching this show CD pipeline for the first time. We've been doing CD pipeline for more than a year, maybe going on two, but for people who are familiar with the Continuous Delivery Foundation or the CD Foundation as sometimes we refer to it, or CDF, which seems to be the new, the preferred nomenclature these days, right?
The CDF is a, I call it a daughter foundation of the Linux Foundation. So it's under the Linux Foundation umbrella, and it is, it was set up specifically to focus in on the continuous delivery market and, and it, uh, community and, uh, you know, perhaps its biggest job is managing, you know, I think is it eight or nine projects that have been donated, given to fostered under the, uh, CDF umbrella among, which is the CD events project that we're gonna talk about today, but also some, some kind of household names in the tech world. Jenkins for one.
Um, oh, I'm Jerry Blake, my goodness. Netflix, Google Spin Sticker, spin Spinnaker for two. Um, who you are all board members here?
What, what are the other projects under the CDF umbrella? Well, we have project like Screwdriver, uh, for instance, and Jenkins and Vinegar that you mentioned. We have tacton, uh mm-hmm.
Um, yeah, the city events protest and what else? We have, uh, Jenkins Sachs. Yeah.
Um, which is also GitHubs in the GitHubs area. Uh, yeah. Yeah.
Excellent. I mean, it's from, you know, and, and our audience is DevOps and cloud native folks and cybersecurity, and so these are kind of very well known projects and tools to, to the audience. Um, again, before we say, should also mention that the, uh, CDF recently announced their annual conference, which is coming up, actually, Gerard, do you maybe have some of the, uh, particulars on that one?
Yeah, so CD Con has been running as a kind of Precon micro conference as part of the Open source summit in, um, north America. So this year it'll be on, in June in Denver on the 23rd to the 25th. So we look forward, you want to come participate?
I think there was a call for speakers open at this point, isn't there? Yes. org?
So it's CD Foundation. CD Foundation, excuse me. Yeah.
Yep. Excellent. I just wanted to get that out there.
All righty, folks. If it's okay, then let's turn to our topic at hand today, which is to get people aware and familiar with, uh, a project under the CDF umbrella called CD Events Project. Andrea, you mentioned you were one of the co-founders of this, so if it's okay, I'd like to start it off with you and give us kind of the background.
What is CD events, what kind of drove you to wanting to, you know, make this project? And we could go from there, Right? Um, yeah, thanks Alan.
Um, so, um, I mean, we, we started in the, of course, in the continuous delivery landscape, but more generally, uh, what we call the Software factory. So looking at, you know, the, the software, how it's built, starting from source all the way to, to production. Um, and there we, we have a number of tools that are involved in these.
Um, you have your CD tools, your CI tools, your, uh, software management, uh, systems, your deployment system, and so forth. Um, and there are several options for all these tools, and a lot of them are hosted by, by the CDF as we discussed before, but others are also hosted by other foundation. Um, but, uh, what we notice is that there is a lot of fragmentation in how these tools are set up in the data models they use and how they, they talk to each other.
And so, um, the CDF project, we created it basically to try and address this, this fragmentation and bring interoperability in this space, right? So we want to, um, make it possible for these, uh, tools to, to talk to each other, to generate data that can be processed, uh, seamlessly across the different tools and, you know, make it easier for organization that use many of these tools to not have to reinvent the wheels and, you know, integrate them these tools with each other or, um, in house all the time. So, but yeah, mainly we want to bring interoperability in this space, and that's how city events was, was born.
And City Event itself as a project is, it's a specification. Um, so it basically defines, um, formats for events that can be produced and consumed by, by tools in this space. And expand a little bit to kinda give it a little bit more of a, some concreteness like, uh, imagine you have like your whole, let's say your company and you have your whole SDLC, which is software development lifecycle, um, architecture, you know, you have all these services and tools running, and let's say you want to actually add or even switch out a tool to do that today, it's very, very difficult.
You're gonna spend, you know, months, maybe even years, just trying to get to that place where you are at to just deploy that software again, at the same, same level or same criteria. So what the goal CD oed, as, as Andrea has had alluded to is, is interoperability. So you're, you're, our goal is to be able to just be able to pick up pieces and just put new pieces in very easily and transparently.
Absolutely. So, but when we say it's a spec, I don't wanna lessen what CD events project is, right? It's, it's, it's more than a spec.
Is that fair to say? Um, yeah, absolutely. I mean, the project started with a specification, uh, but we went on to implement a number of SDKs or software development kits that can be used by the different tools to make it easy to, you know, consume the events or produce them, validate them, and so forth.
And, uh, more recently the, the project expanded even further, uh, through one of the, um, working groups that May Ben mentioned earlier, that is chairing that, uh, it's the implementation working group, because of course it's nice to, to have a specification, but, you know, we want to actually provide guidance, uh, on how to go about implementing it and, you know, benefiting from, from this, uh, interoperability, um, that we're setting up. Yeah, and Alan, I, I add to that, and I totally agree, it's far more or allows it, it creates a framework or a way to, to go much further. So, you know, for a company like Fidelity, you know, using CD events, you know, allows us to express, you know, all of the different events that happen across the L-S-D-L-C into a common form, and then allows us to be able to have conversations across all of those events in a very consistent and common way.
Um, helping us, you know, join events, you know, from disparate systems and allows us then to say, you know, how do we measure governance? How we, how we might measure compliance, how do we ensure that codes being created, built and tested according to the kind of our standards and the kind of the specifications fidelity might have or any, any enterprise might have. And really CD events allows us to express those events in a way that it can achieve those outcomes.
Fair. Um, You know, look, I think all of us on here are very familiar with how open source communities work. Not everyone watching this is gonna be as familiar though.
Let's talk a little bit about the relationship between like CDF and how it sponsors this particular project and where kinda rubber meets the road with the broader community. Do, do you know what I'm saying? I mean, it's one thing for the CDF to say, okay, we, we are gonna sponsor CD events and we're gonna, you know, have people like Andre or on our board who are kind of co-founding it, but in terms of growing the community, in terms of, you know, making breathing life into a day, day by day, it's not the CDF per se that's doing that, right?
It's the maintainers, it's the, the community as we say. Can you give us a sense of the size of the community, of the involvement of the community here, Aja, I hate to put it on you, but you are, you know, you are one of the, Um, you know, growing, uh, growing community, uh, is a continuous effort. And, but we've been lucky, uh, with a, with a great community, um, in, in the city events project.
I mean, we, we've had like, uh, early adopters from the beginning, like, uh, uh, friends, uh, you know, Gerard and, and Ben here that, uh, started at the early days, uh, contributing to the project, um, components as to the specification and, you know, taking it on and starting adopting it and, you know, bringing the, the invaluable feedback back to the community. So, um, yeah, and we, we have, uh, a core group of, uh, contributors that, uh, are kind of always within the project, you know, helping, facilitating the working groups and con bringing the discussion on. And then we have other, we have had other companies that maybe joined the project.
They're interested in a specific career, contribute some to the project, and then, you know, take that home and, uh, may contribute later in the future. But, yeah, so we, we, we have, uh, several companies that contributed over time. So we had, um, Ericsson contributing, uh, a lot of, um, a lot of the, uh, specifications and TK we had companies like Cube, uh, cube Show, Bloomberg and Red Hat, uh, do while.
So SAS. So we have many companies involved and each, you know, contributing to different areas and, um, other, the project itself. Yeah, And one thing I wanna, I wanna add to that as well, 'cause it's more on the open source side of that, is, um, so generally with open source, you have this concept called like working groups or SIGs, which are special interest groups.
And so these are like, you know, some sort of timeframe meeting. So it's like every week, every couple weeks, every month, you know, it could be any sort of allocated amount of time for any sort of, um, for any sort of period. Um, so with these groups, the maintainers and anyone that's interested in the project can join these calls.
So these calls are completely public. You can just go to a GitHub repo and, um, you know, we'll, well establish ones and find a calendar, which will have these meetings. And then you can just hop in.
You can hop in and just start participating. So we encourage anyone that's interested in open source to go ahead and do that. Just go to any sort of interesting, uh, repo that you find that you wanna contribute to and just attend.
You don't even have to speak. You can just attend. And we're always looking for maintainers.
We're always looking for more people to join. So, you know, feel free to go to CD events, take a look at our calendars, and please, please, uh, show up. We'll, we'll, we'll encourage the discussions.
Absolutely. Gentlemen, if it's okay, I'd like to pivot a little bit. Look, it's December, it's the end of the year.
Everybody's forward thinking. What is 2025 look like? What is 2025 gonna bring in ways, you know, in ways of technologies, in ways of business, in ways of, it's a crazy time in the world.
There's wars and there's regime change and there's elections and just, you know, it's, it's, it's a busy, crazy time in our world now, CD events. You know, someone once told me, don't do anything if it's not going to be big enough. Right?
It's gonna have, if it doesn't have the potential to be impactful, don't waste your time. See the events is a project that has tremendous potential to, to be impactful, really help our organization streamline their, their pipelines, their delivery pipelines and collaboration. As you look at 2025, where do you think kind of the promise or the potential is specifically there with CD events that, that could make this really impactful in this coming year?
Andre, I'm not gonna pick on you for a spin, if it's okay, let's pick with you and then Gerard and Andrea, you can fill in from there. Uh, sure. Yeah.
So for me, um, 2025 is gonna be a really good year. 'cause like I said, like, um, we started the implementation sig about, I don't know, maybe a month or two months ago. And so we're gonna start implementing the things that we're talking about, the, the specifications instead of the theory, you know, and try to prove that these concepts work, um, and ensure that they are of quality and, and are very efficient as well.
So that's gonna be very key for us in 2025, is getting, um, the actual implementations down so companies can actually start using these technologies, or even people, you know, if they're interested in seeing how this stuff works and wanting to see, um, the efficiency and the, the eases ability of tr uh, just changing tools, you know, we wanna be able to provide that. And then also on top of that, we also want to kind of, we, we talked a lot about interoperability, but there's also another side of the coin that CD events, um, really caters to, which, which I think we want to also cover here is, is metrics and, and telemetry. So that's another good job that we've done, um, at CD events spec wise is, is when you're looking at CD events from afar, um, there's this concept called links, which allows you to like link the individual events together.
So if you're some sort of like, let's say you're very happy, you're some sort of on the very top of the leaderboard, or, you know, in, in terms of like you just said, like CEO or CFO or something, you could actually look at the impact of, let's say, when a ticket was open to how long it took to actually get that feature out into production and all the bugs that were associated with it, just with CD events. So that's, that's gonna be our overarching goal. Are we gonna get there in 2025?
Uh, I could hope, but probably not. But we're gonna try to strive there through the, through the implementation stakes by answering, you know, like what the spec looks like, as well as how do we address the observability portion of it. So that's gonna be the focus, well, at least my focus for the next year is the implementation of these concepts.
Yeah, I think jam to, to kind of, um, lean in on what Ben said and, you know, even potentially go further and broader, is the more enterprises, um, that kind of adopt CD events, I think, you know, from where what we have seen so far in our adoption is it's actually created new questions and new things we can ask of information that we didn't actually think have think of before. 'cause there was no visibility or transparency into the underlying data. So therefore we didn't realize there was even questions to be asked.
So, you know, how do, how could we apply this in, in a governance compliance perspective? Can we apply this in a security perspective? Can we in product, even if we wanted to try, you know, the, the million dollar question, does Gen AI deliver on its productivity?
You know, are we now being able to look inside the data, right? The data's the currency and the data's the evidence. And are we able to look inside this data, um, to, to gain understanding from it?
I think, I think there's a lot of exploration yet that I think CD events has opened up to us. Um, and we're looking actually forward to sit to innovating into that, exploring that, innovating within that space, and see what other opportunities outside of the ones we already know and that, you know, Andre and Ben have articulated that we're, that the community is focusing on building in 25. But I think I'm look also looking forward to 25 is what does the 26 roadmap look like?
What does the 27 roadmap? So I think there's great potential and opportunity here. Yeah.
I just wanna make note, we got about 22 to 23 minutes in before Gen AI was mentioned today. That's pretty darn good. Pretty darn good.
Um, but I agree with you Gerard, Andrea, I'm back to you. Yeah. Um, thanks.
And I totally agree with, um, Moger and, and Ben mentioned, and I mean from, uh, I look at it from, from a kind of, uh, open source project point of view and what we, we plan and what we, we hope to, to, to achieve in, in 2025. And, um, we, we discussed about the, um, implementation working group and what we really want to focus on in, you know, to, to help enterprises company and open source project adopt CD events and make the most of it, you know, starting from small, uh, and, you know, to grow to, uh, a larger scale like, you know, covering the entire SDLC like Ben was saying, you know, asking new questions, building new, new metrics. And so, you know, we, we keep on like working, improving our SDKs, um, increasing more languages, um, uh, you know, drawing kind of reference architecture that companies can use to say, okay, this is how we we go about, uh, adopting city events.
We need this component and that component and so forth, and what, what characteristics do they need and so forth. And so this is, uh, uh, some of the areas where we are going to focus. And of course, I mean, I, I was talking about city events at the, the Linux Foundation member Summit couple of weeks ago, and I think it was a bit further than 20%, but maybe about 50, 60% from my slides.
I also had a mention of Gen AI because it must be there. Uh, and, and that's an area actually though that, um, where we, we might consider expanding the, uh, the specification as well, uh, because, um, we've been talking about building software and the software, uh, uh, lifecycle build and, uh, software factory. Uh, but now something that, uh, a lot of companies are doing here is building AI applications.
And so we want to make sure that we have all the, uh, events that are relevant for those kind of application as well as part of the specification. And I made a call to action during my, uh, my, my talk, and there was quite good response already. Someone in that space said, oh, yeah, but be interested, you know, in contributing events in that space.
So we hope to see that's that going, It would be great. It certainly would be great. Um, how does CD events play with the other CDF projects?
Right? This is something I've bought in the past too, right? Because, you know, if you look at it, you look at the CDF projects, they all kinda live in their own silo, right?
And there's not as much integration as one may think, but CD events seems to me to be something that would work with some of the other CD foundation projects, right? And there can be integrations there and there can be crossover, cross promotion, cross use, so forth. Um, community building, is there someone from cd, you know, on the CD events side that is looking at that?
Is that something the CDF board is looking at? You know, where do we get one plus one equals three maybe? That's a great question, Alan.
Thanks. Thanks for that. So, um, indeed, one of the goals of C events is to, you know, be supported by as many communities as possible, and being at the CDF, the CDF project, our, our first, you know, and the closest project, our thees project.
And, uh, we discussed this also as part of the technical oversight committee. And, you know, uh, we think as a, as a TOC from a TOC point of view, that's definitely a priority to get CD van support in all the CDF projects. Um, and that's, uh, already the case for many of the projects.
Uh, I mean, thanks to the Fidelity, uh, contributed the, the Jenkins plugin. So you can produce CD vans, um, um, from, from Jenkins already. And we, there is support, uh, on Spinnaker that was contributed by, uh, apple and Ericsson.
Uh, so we have experimental support in Tacton, and so many of the projects are already coming on board. And we are also working on a, a mechanism that we call the, the web adapter to integrate more and more projects as a, as a kind of translation layer that we want to, to, um, we started implementing and with plugins that can decode physically translate messages from, uh, different platforms into, into city events, you know, to speed up the, the adoption. Excellent.
Um, guys, we're almost outta time. You know what I realized? Did we mention a website specifically for the, I know we mentioned the CD Foundation website, but did we mention the website for the CD events project?
You did not. Where can we go get more CD events, project specific info CD events Dev, I think, right? Andrea?
Yeah. CD events Dev, yeah, CD events. Do dev.
And then from there we have documentation, we have the community page. We'll send you, like Ben was saying earlier, to where all the community meetings and details and how to contribute. Um, and we have the city events organization and GitHub as well with all our specification as the case and, and more, You know, will there be a specific track for CD events at the CD Foundation Summit in June, or too early to tell yet?
And the CD con is kind of like a mini summit. I think it happens the day before. Uh, right, the day, I think it might be day zero or is it our, um, vu of the conference.
So as part of the call for papers, um, you know, we'll have multiple, multiple talks during that mini-conference. And yeah, absolutely hope we have, uh, CD events being one of those talks where we, you know, we can share more with them with the audience that, that are all, that are around that day. Excellent.
Excellent. Do you know where in Denver the event is? In the Colorado Convention Center?
That's what I was thinking. The Convention Center. It's a nice place, a nice place for this.
So do check that out. You can get to the Open Source Summit as part of the Lennox Foundation, uh, website as well. It's Open Source Summit North America.
We're about outta time. Andrea, Andrea, not thank you for being on here today, but also thank you for all you're doing around the CD events project, right? It's not easy, as I said before, kind of breathing life into these things day to day.
So thank you very much, and thanks for being on the show today, Gerard, thank you for joining us as well, and for all you do. You know, it's one thing for, and I don't mean to slide anyone, but when a vendor has people on board, generally the vendor's paying for them, but the vendor has an agenda, right? Yeah.
Here, you know, Gerard, you represent the every man and woman, right? And as part of Fidelity, and Fidelity is a huge supporter of Open source as, as I think most of us know. But, um, thank you for all you do on CD Foundation and, and, uh, volunteering your time.
And then of course, Ben, thank you for what you're doing and staying on top of all this. It really does take a village to, to, you know, maintain these foundations. So it's not just the Linux Foundation, you know, sprinkling some money and dust on these things.
It's, it's the day-to-day work that, that keeps it going. So thank all three of you. We'll, we, we'll be back next month with another topic for our CD pipeline show, Lori and d, we hope you feel better.
We're sorry you missed it, but this Alan Shimel for Text Strong and CD Pipeline. Have a great day. Hey, everyone.
So our AI agents unionizing, I don't know you're watching Textron Gang. Hi, everyone. Happy Friday, man.
Where did this week go? It was a crazy week, but it went so fast. It's like a blur in my mind, but I'm happy for us to be here on Friday.
I hope you've got great plans for the weekend. I do. It's supposed to be nice down here in South Florida for a change.
So I, I may even get out on the boat and do something. But until then, we've got a lot to cover today on the gang, and we've got some of my favorite gang members on here with me. We've got our, this is the West coast, east Coast, the coastal elite lineup, right?
Coming out here, but out on the west coast. First of all, she is our, oh, editor, radio host, analyst, marketing guru, and everything else. Our favorite.
Lisa Martin. Hey, Lisa, how are you? Hey, Alan.
Doing well. How are you? Very well.
It's good to see you out. Uh, PI I like, I like the look with the glasses and the stripes it's happening. Thank you.
And I can, can see it's brilliant. Yeah, no, that always helps, always helps. Speaking of seeing Perched high at top Silicon Valley where nothing gets done without his purview of it, it's our editor at large, Jon Swartz.
Hey, John, how are you? I'm good. It was a crazy week and it was overwhelming, but is a wise man from Harrison, New York has said it beats the alternative of not enough news.
That's right. Speaking of the Wise man of Harrison, New York, he is the dean of, uh, of Techstrong, as well as Harrison. He's our chief Content Officer.
It's also counting down the days to opening day at Yankee Stadium. Someone got him tickets. This is true.
Um, Our Chief Content officer, Mike Vizard. Hey, Mike, We might have, uh, some single digit weather here this weekend, but after that it's looking good Spring's here. All right.
Spring Spring's Eternal, and everyone thinks they're a World Series contender at this stage of the game. That's true. Not not, not us Giants fans.
Anyway, carry, I too, your record is still zero, zero, John, just like everyone else, I like, you're up, you're tied for first. Uh, you're also tied for one day. Exactly.
Anyway, guys, it's a great Friday to be here on the gang. Uh, we've got a couple of good, uh, segments we're gonna cover. Mike, why don't you kick us off?
I teased it a little bit. Are AI agents looking to unionize? Did they have rights?
So every time we turn around lately, somebody is launching an AI agent, and there's gonna be a debate about whether or not I need an AI agent from every software provider, or whether I'll get something from somebody who has a platform that manages multiple applications with these things are gonna be pervasive, but it, a debate has emerged, and I think it got started with the folks at Workday when they announced that you could manage your quote unquote agents through their HR application. And that started this whole conversation about, well, is an agent gonna be an employee? Is this somebody I'm, or some thing that I am going to hire for X number of hours as so a week to perform a task?
There are at least a half a dozen other models for paying for AI agents, including outcomes and, uh, traditional software licensing. But Lisa, this conversation is starting to pick up, and I Don't know what you're seeing out there, but from my perspective, it's the wild, wild west. It is literally, especially where Workdays and just down the street from me here in Silicon Valley, it's such an interesting topic because one of the first things that popped into my mind was, who's gonna pay the employee employee tax?
But we're seeing role-based agents versus task-based agents doing a lot of jobs, recruiting expenses on the, on the part of Workday Illuminate, for example, succession optimization. And a lot of these agents on that are working today are following step-by-step instructions like an employee would. Um, Workday's, CEO, Carl Eschenbach, I remember him back from the VMware days, says, you know, task-based agents have to evolve into role-based agents.
That's what Workday kind of differentiating themself on, which contain this configurable set of skills that give them more autonomy and better able to support humans in their roles. But it does beg the question of are they going to be treated as employees with some of the tasks that are being offloaded from humans to them? How are they coexisting together?
It's an interesting debate. Um, op key also introduced a suite of AI agents to its lifecycle management platform for ERP applications. Um, and the goal is to augment individuals.
So I think there's a message there that needs to be really, really clearly defined from enhancing augmentation versus replacing on the human side. Alan, when I look at this, and my, my cynical nature comes into play here, and I, software vendors have been trying to put their hands deeper into the pockets of businesses for as long as I can remember. And there was always this case that says, we're gonna price this based on value to you as the company.
But, um, is this just another effort here by the software providers to kind of experiment with a different business model that maybe drives more revenue to them, but increases our total costs in ways that are not really sustainable? Look, software software companies wanna make money, like girls want, have fun, right? As someone once sang.
But that, that being said, this one's a little different and, and it's been tried before, but the, I think the value prop here is by using these agents and, and this bleeds into our B block, by the way, by using these agents. Are we lose, are you using less people? Because when you look at most businesses, their most significant cost are people.
I mean, I've been a founder and a leader, you know, companies for executive companies for many, many years. Your biggest costs are people always, unless you're so in something very, you know, manufacturing intensive where, uh, uh, supplies cost, but it's mostly people. So if you are telling me that the, the right metric to measure these agents' value is might decrease in people cost, well, that's, that's not productivity.
That's not, you know, that's a whole different scale, if you will. And, and I think, you know, it's, I think people are gonna swallow it. I, I, as a matter of fact, I think a lot of business executives already have swallowed it.
They're already thinking, Ooh, this AI's gonna let me lay off a couple of heads. I'm gonna have people, and, you know, they're wrapping their hands in, in glee. But, um, so that's, that's the metric here.
And this, so it, and, and for the first time, this truly is potentially true, right? I mean, this, this could be a reduction of workforce. If I was just, we were talking off camera, read a Gartner report, you could see a reduction in workforce of five to 10%.
And wow, that's, that's significant. That pays for a lot of these agents, agents. Now, of course, the devil's in the details is, is this agent really, are these agents really going to replace people?
And then, then the issue is, are they employees? Right? So look, in legal terms, an agent is a very specific legal entity.
When an agent acts on your behalf, you are liable, right? He's your agent or it's your agent. Similar thing here, right?
What about the liability of what agents do? Is that gonna be the software producer who produced, the agent's gonna be liable? Is it gonna be you because he's the agent isn't quote unquote employed by you?
Are you gonna be liable for it? Right? This opens up kind of a whole new can of worms for lawyers there who are also rubbing their heads.
And these lawyers love to get new cases of first impression here that we can, you know, run up the flagpole. So, I I, I do think th this is, uh, in some respects a brave new world, right? If you are a fan, fan of robots in Asimov, you, you can take some lessons and cues from it.
But, you know, do, do we need to put limits on what these agents can do, right? We, you know, agents don't get sick. They could work 24 7, you know, until they don't.
Right? Why do agents have feelings? Do agents dream?
Uh, nice Philip Dick reference. Yeah. And you know, this, this is, so, there, there's no timeline on this, but this is the end game.
Alan, you were spot on. You know, Salesforce and Nvidia are discussing these things called digital workforces. I was just talking yesterday with a friend of mine who does consulting work with Salesforce.
He, he, he's considered within Salesforce and a Benioff whisperer, which is the reference to Mark Benioff. And with, even within Salesforce, they've developed a couple of these concepts. One of 'em is called the Quiet Erosion of Entry level jobs.
So they're convinced that these AI related jobs or tasks will replace the lower level jobs, and they're actually referring to the agents as s or virtual employees. So we've got this, we also have this idea, I mean, not to get too, too cynical, but the federal government, what's happening with Doge, et cetera, I think some of the tasks, they, they're gonna try to find a way to replace the tasks of humans within government agencies, with agents. I think Amazon's gonna do this with warehouses.
They've, they've made it clear they, they're dropping breadcrumbs everywhere. The, the only question is the timeframe, but I think it's inevitable. And I think we're gonna see a lot of loss losses of jobs where people can't adapt, which will create all sorts of union issues, all sorts of culpability issue, corporate governance.
It's gonna be wild. You know, I'm sorry, go ahead, Mike. In theory, You can argue the other side of this though, right?
So it's pretty clear that we or may not have enough workers, 'cause the boomers are gonna retire and there's not enough of air folks running around. So maybe we do need to have AI agents handle more things, and maybe the definition of what it means to be a, a worker, let's say knowledge worker is replaced by somebody who's, you know, a knowledge orchestrator or a supervisor, and they are handling more things, um, through their team of folks. And then we're all more collectively productive.
But we may not have as many people in the first place. I always wanted to be an orchestrator. Do I get a baton with that?
No, no. That's different. That's an orchestra.
Um, so Mike, you, you are right, but you know, I'm reminded of a, a discussion we had earlier this week around the Apple. $500 billion announcement is gonna create 20,000 jobs. That's about 25 million a job.
Um, and by the way, I'm going to, I spoke about this Thursday on LinkedIn live yesterday on my shimmy says, but the bottom line is, you know, we talk about opening data centers and factories and all these things, but when the jobs in those data centers and factories are handled by agents, you are not creating the amount or the type of jobs that they may want in the heartland here, right? Those good assembly line jobs in those factory positions, agents may do that. Robots are going to do that.
And so, you know, do we come to a, a Star Trek kind of world where humans really don't do menial labor and don't do physical labor and, you know, know, and quite frankly, even a lot of service mental tasks can be handled by agents, AKA writing software and, and all of these things. So, well, what do humans do? We, we can't just get fat and walk around on those chairs, right?
We talked about this with Wally. What do we do? Have I not told you my favorite stupid it joke before?
You know, what's the future of the data center? It's, it's, it's one guy and a dog, and the dog is there to keep him from touching anything. It's gonna be a boy, it's gonna be a boy and his dog, another science fiction reference.
But you know, that you're, you're right, Mike, there there's gonna be a, there already is, uh, in the, especially in the healthcare industry, a lack of doctors, optometrists, dentists, so, so AI in a sense, and these agents and robotics will actually fill the gap there. So there is a, there is a good side that benefits all of us, but I just think, I mean, I just think that the problem is, given what our oligarchs in tech are doing these days, it's very hard for me to trust anything they say or any, any of their intentions. They're building these data centers.
They're looking at ways to move forward in robotics, in ways to maximize profits. Because that's all I really care about, in my opinion, that at this point in time that might change. And it's so kind of where we're moving in terms of job displacement, and you're gonna see more union activity, uh, around this and more strikes or threats of strikes.
So You think it's more displacement versus, excuse me, augmentation or enhancement? 'cause I see it, I, I guess I look at it from a different lens, um, from a messaging perspective and what really needs to be very crisp there to explain how these agents are helping humans. But it sounds like you guys are thinking more, there's gonna be more displacement than there is enhancement.
Well, We talked about this previous show where we were, um, you know, given Andreessen some grief about some of his comments. But one of the things that he said is, we're gonna burn down the economy first and then rebuild it. Well, that's all right.
Burn down the economy without a plan though results in a massive amount of disruption. And it's not too long. E even with a plan, the Pitchforks are outside the White House, Even with a plan burning down the economy is going to create lots of disruption.
And when you're an oligarch sitting on a couple tens of billions of dollars, you, you can ride it through Mr. And Mrs. America who are voting for this, I think are in for a bit of a, a rude awakening.
And, and we'll, we'll see where, where that goes. Um, I mean, but, but here's the other flip side though too. I've never seen progress stop be for, for feelings, for feel goods, progress rolls on and it stops for no man or woman or worker or country or economy.
And if you could, if you could do it, they will. And I, I will, let me pose this scenario. When you hire somebody, you're actually hiring them.
And they're 15 digital assistants that they trained, and they are, you know, a small army of people and agents that are, are as the new employee that you're hiring. And when they leave, Oh, they're, they're all through egos. Yeah, they're all through egos.
But, but let's be clear, there's a difference between digital agents, all our Salesforce, who are gonna go do digital tasks on the net or on your network for you versus robots that have AI embedded and are doing physical tasks, right? This is, this is a pit movement here, right? Where, where, where they're attacking menial, physical task, not attacking, but potentially replacing menial physical workers at the same time replacing what's called them brain workers.
Well, let's go to the, let's go to the bean block 'cause that's where we're going. Absolutely. All right.
You know what? That's a good one. We'll, we'll, uh, we're gonna take a break here on Textron Gang.
You know, I always wanted a Jetsons flying car. It looks like I'm going to get rosy. First.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching it, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right? So as Alan noted, we are talking about robotics and robots are coming to the home.
Meta has signaled that it wants to build robots that will do everything from wash your car to do your laundry. And well, what could go wrong with all of that? But, um, tale's point, we are seeing these, you could argue a robot is a form of an AI agent, and it's gonna go do menial tasks and to, this is part of that pincer movement.
But what happens to all those folks who are doing those various tasks out there? I don't know, and I don't know how far away these robots are, but I can think of a few dozen things that might go wrong, including, well, is that robot sharing data about what's going on in, you know, your laundry with some AI somewhere that then is gonna pop it out somewhere in an interesting way? Well, you know, little, what was little Susie doing with her boyfriend and the, when they were supposed to be doing homework is suddenly gonna pop up on a screen somewhere, I don't know.
But shades of Monica le Um, only if you check the box that allows your robot to share that information back with meta headquarters solely for the purpose of improving your laundry. But, uh, no one wants to air their dirty laundry on Techstar gang. But, you know, look, guys, take a lesson from the internet.
What industry led the way and breakthroughs on digital, uh, commerce on video over the internet and everything else, the porn industry, they're liable to lead the way in this robotic industry as well, right? And I could only imagine what all hell breaks loose here. What John, I'm sorry.
Oh, it's like a West World reference too. I mean, yeah, yeah, yeah. A little west world that was ing, if you remember that.
Yeah, that was great. Series speaking. Well, we'll come back to this, but, but you don't need a pretty guy Beefcake guy or a pretty woman robot to wash the car, do the laundry, do your rosy, like Jetson's, Rosie's, you know, electronic maid, do that kind of stuff.
They don't even have to actually be humanoid, right? They don't have to have two eyes, and you don't have to look humid whenever the most efficient form is to complete the particular task. I, I think the question is, and it's similar to the digital agent, are we gonna have many different robots that are single function robots, car washer that services multiple houses or something like that?
Or do we have a jack of all trades robot, the English butler, so to speak? Who? Or Rosie, right?
Who, who does runs the dishwasher, runs the washing machine, washes the cars, tidies up the house, folds the clothes. Um, you know, the beauty of it is, is if you've been following what's been going on in robotics over the years, and for most of us it's just watching how nimble the robotic dog is, right? You could take out a, a leg and he still figures out how to balance himself and how fast they run and how, you know, how much progress they've made in, in these robotic, uh, you know, mechanisms and, and mobility.
But then you marry that to true ai, right? To a really good AI that that's programmed to do certain task. Sky's the limit.
Sky's the, I mean, think, think of, do I need, you know, one of my big things is if we, if we deport 12 million immigrants, all the fruit that's rotting in the, in the fields and, and you know, John and Joe Smith from Kansas City aren't gonna go out and do farm work. Well, if I got robots to do 'em, that really helps. That really helps.
And I think we're a long way, we're a long way from the single purpose or the multipurpose robot. So I think we'll get there in phases. We'll have single purpose robots, then we'll wind up with this multipurpose robot.
But, um, this is not all that far off in the sense that, you know, there are reports that the Chinese are building millions of robots already. So It's, you know, it's, it's also, I mean, it's also happening here. There's a startup out here called physical intelligence, and one of its major investors is Jeff Bezos.
And there are videos of what these specific robots do, some wash dishes, some sort and box, uh, items. So it is going in that direction. I actually, when I recently went to Carnegie Mellon, the um, PhD students there were showing me their robots that did things as, as, as weird as like picking apples outta trees, um, using sound rather than visuals.
Um, it, it's, it's happening. And a lot of the agriculture companies are working with the Carnegie Mellon folks about raising crops and picking crops. So you're right, Mike, it's, it's a lot of specialization before we go to the multi varied robots.
But it, it, it's happening. I mean, it's just, I just don't know the timeframe. And again, with meta, I don't know if this is a concept they're talking about how far along they are.
I guess it depends on where they, where they are. But physical intelligence actually is something that I think you're gonna see elements of that being used within Amazon and their warehouses within a couple years. Definitely.
We saw a lot of that at CES actually, sorry, guys from a, from an agricultural perspective, all the things that they're doing, working with robots to do special tasks, to, to aid the humans. Um, so that was a big theme at CES this year too. So there, there are lots of undocumented workers out there who are doing a lot of these jobs for about, I don't know, 15 to 20 bucks an hour, we shall say.
Um, so does the robot need to come in under that price, or am I gonna have to buy the robot? I mean, going back to our earlier conversation about these A regions, you know, how does the cost of the robot get figured out? And maybe the robot will be too costly Spoken like a true coastal elite Mike, they're not paying those undocumented immigrants, 15, 20 bucks an hour.
Those people, you know what I mean? Come on down from Harrison Dean. Um, those people are getting five to $7 an hour, unfortunately, and they're happy to get it, and that's what makes that world go round.
But look, when you compare human labor to robotic labor, though, it's in no win. The human can't win, right? Because the robot never gets sick.
It could break, yes, but the robot doesn't get sick. The robot doesn't take days off, the robot doesn't steal the robot doesn't hate you or love you or whatever. The robot can work 24 7 theoretically.
And over time that robot's going to get cheaper and cheaper as, you know, scales of economy kick in. So, you know, to say, oh, you know, there's a, there's a, a, a, an actual comparison of cost, I think hands down, eventually the robot's gotta win that game. But I'll tell you one area, But there is, there is, but there is, Ellen, just to be fair, there is a, there is a level of hesitancy among places like John Deere.
The initial cost, the outlay Is expensive. It's CapEx Prohibitive. Yeah.
Unless, unless you're a major company, it's, it's gonna, it's, it's gonna start with them. But y you're right, the costs are are dropping, but not exponentially. So it's, it's that, that's the one thing humans Have going.
I mean, you know, a couple of issues, number one, you know, who's really out ahead and is just besides themselves with this are, you know, to, to go back to the other day, we were talking about Ike and Eisenhower, our industrial military complex, because probably the first robots we're gonna see are military robots, right? Clone wars, warrior class robots who just follow orders. They don't have a conscience.
And, and that, that it's a whole new set of, you know, potential problems we need to be thinking about. The other thing though is who really is gonna be the robot? Who's gonna make the robot that you buy for your house?
Who's gonna make your rosy? Is it gonna be a Google, a meta, an apple, you know, one of the mag seven oligarchs on Amazon? Or, or is there a chance for a, a new, a new class to rise, you know, a new group of US robotics?
Didn't they make the modems we used? Wouldn't it be great if US robotics came back and we, for our robots in the house? But, um, you know, there's an opportunity there.
And the question is, will the meds of the world who are, you know, making noise and the apples and the Amazons making noise, are they gonna let new new growth come in here? Right? And that, that's sometimes why you need a government to calm the, the market at, you know, pure market forces to make sure we don't get monopolized with this.
And we do have, uh, innovation coming from new companies in this exciting new area. You're right though. You know, you talked about, oh, go ahead.
Go ahead, Lisa. I, Sorry, Jon. I was gonna say, I think that's a great point.
From a competitive perspective, how can smaller companies, those newer ones, leverage the, what the metas, the apples, the Amazons are doing from a robotics perspective to drive more innovation, to drive more competition, that's gonna help drive prices down as well. But Alan, you bring up a great point there in terms of where is this innovation? Where's the, we're seeing the, the leaders with some of those mag seven companies already, but it would be nice to see some of the smaller companies from an innovation perspective be able to bring up that competitiveness so that this becomes more of a, of a cost effective reality.
Oh, um, I'm just gonna say, me, me, you mentioned the military. That's a great example. I mean, in addition to the porn industry, the military has always been kind of at the forefront of terms of using technology.
And when you mentioned robotics, it made me think about 20 years ago I did this project with CNN and it involved UAVs and also remember the global hawk of the Predator, these drones, um, there were emergency, there were underwater, uh, submarines that were, uh, robotic. They, they were done mainly to protect humans from in, in terms of war. Uh, right, right.
I mean, they'll be used for something else. I'm, I'm sure I already have been for, for all we know. But the, the whole, the whole idea, the whole concept though, was to try to, as Eisenhower, you mentioned earlier, you know, a way to spend money on the military without spending it too much on people and, and more on technology.
Uh, as we kind of go forward in, into this brave new world, I think this is gonna be a massive exercise in marketing because the only robot that's coming into my house has to come from some brand that I trust. Right. And it's not just gonna be, you know, any random company.
It's gotta be somebody who I can feel like I can call up and say, come get this thing 'cause it's going crazy. No, but look, I, I'll give you for instance, any you guys use robotic vacuum cleaners in your house. IRobot is exactly.
Bingo. What a great story. The Roomba from iRobot was my friend Brad Feldy was an investor in that early on.
And that, you know, there was a long, it wasn't ex, it was one of those 10 year overnight successes, right? It took a long time to get that technology right. And it, and it's relatively dumb technology if you've used it, you know?
Right. But people, you know, that's worked its way in, is a brand that people didn't, didn't Amazon buy that one, John? Yes.
You know, now of course it's part Amazon I think have one in the, I think I have one in the attic somewhere. I think we stopped using just because, Well, no, I have one here in the office. I brought it in from the house because our previous dog, Sandy used to hate it.
She chase it around biting it, and she cracked her canine teeth on it, and she had that f look. So when we got the new puppy, now I immediately took it out of the house. 'cause I didn't need any more cracked teeth.
I had to pay for enough orthodontist work for my children. I don't need it for my dogs. But, um, yeah, I don't know how many people, I don't know how good they are to tell you the truth.
Dyson never came out with one. How good They good they be. Um, Mike brings up a great point on trust though.
Sorry, John, on customer trust, you're saying, like looking at, you know, the apples, the Amazons, the metas that, that we're buying products from and where we are the product versus somebody that's unknown. So maybe there's collaboration between some of these larger companies and some of the smaller ones to drive that innovation. But you bring up a great point.
'cause from a, from a marketing perspective, it's all about earning customer trust and retaining it. That's just table stakes to driving revenue. Mm-hmm.
And I'll tell you what, I trust Samsung a lot more than I do Hewlett Packard, you know what I mean? What kind of American are you, I'm kidding it. American with good taste in terms of technology.
Sometimes Uhhuh Uhhuh, but they haven't, I didn't see them at the White House pledging a couple of hundred billion dollars. Well then half the country Wait, today is Young then, then half the country's gonna trust them more. I don't know.
What can I tell you? Anyway, Hey, let's take a break. We're going to come back.
Little bye-Bye. Miss American Pie. Well, actually, it's UK Pie.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Alright, we're back in. It was kind of an amazing stunt. Uh, about a thousand or so artists in the uk music artists got together, released an album, and there was no music on it.
And they were basically protesting this law that's being considered in the UK that will allow anybody who has an AI thing just to use copyrighted content to train that AI and not have to actually compensate anybody. And of course, all the artists in the UK are flipping out about this, and it's not just gonna be music, I suspect, but John, you've been following this for years now. What's going on here?
Yes. So it's more content creators against ai, right? It's, um, it is interesting, this concept of this, this album, which was called, is This What We Want?
There were a dozen recordings of empty studios and performance spaces and with the likes of Kate Bush, Annie Lennox. And I remember also a couple of weeks ago, Paul McCartney had talked to the BBC and he had said this interesting quote, he says, the truth is the money's going somewhere when it gets on the streaming platforms. Somebody is getting it, and it should be the person who created it.
It shouldn't be some tech giant somewhere. And, and, and again, what what's especially heinous to the artists of this case is that this considered plan or law, AI law, copyright law would allow tech companies to use copyrighted material to help train AI models unless the creators themselves explicitly opt out. And I think there are already laws there.
I mean, based on what I've read, there are, the copyright law already can covers this, but the fact is you have to actively protect your own rights, which is gonna be almost impossible. Um, the, this opt-out proposal's been met with scorn from opponents to say there's no evidence of a water type rights reservation process anywhere in the world. So I suspect we're gonna see this cascade beyond music and into film and into writing, into even our stories, into, into everything imaginable again.
It's, um, it's quite interesting. And, and the amount of force that the artists in the UK took, I applaud because I think they're making the, the Labor Party, which is thinking of this plan, kind of reconsider it. And I mean, it's a story that's fluid, but I think there's been enough resistance where I think we might see some sort of action.
But again, this is something that we've seen in Hollywood with writers. We see it with voice actors. I mean, they're being replaced, especially voice actors.
That's one of the worst areas where you can replicate their voice and basically use the AI voice instead of the human and not pay the human. So again, it just spares repeating. I think it's a really important story, but It's also authors.
It's not just musicians, it's authors, it's artists, it's newspaper publishers. And then we have companies like OpenAI saying, Hey, we can't train our models without copyrighted materials. So this, this war, and you've mentioned some of the, um, of the big names, Paul McCartney, Elton John, for example, as well as a lot of smaller artists.
And what I thought was interesting was that the 12 tracks on this album of silence spell out the British government must not legalize music theft to benefit AI companies. And they're really, really, these creatives are really speaking for, for, um, all, all, all creative industries globally that we're seeing it obviously rise up here in the uk, but it's, it's the creative saying we need to be protected and compensated. And, but the big OpenAI companies saying, we can't train the models without your copyrighted materials.
So did the, So Alan, did the politicians sell out the content providers here essentially for money? Everybody wants to ride the AI train to quote some song, right? Everybody wants to ride the train.
But you look, the fact of the matter is there is a long bloody history of large companies exploiting artists for their own capital benefit, right? If you're familiar with the Bruce Springsteen lawsuit, uh, back in the day, several others now, we had a bit of a revolution with digital. All of a sudden those, the, you know, the recording, uh, industry, the, the, the record labels, they didn't, they stopped holding the power because everything was streaming and, and payments.
Now artists can get royalties directly from the streaming providers, Spotify's and so forth of the world, though there's still a place for labels. It's just not, you know, like what it was when we were younger, let's say. Um, but you know, thi this is true now, I thought, John, that the, the after and the, the Hollywood strikes with the writers and actors that you could not use voice and duplicate one's voice without permission.
As a matter of fact, I believe it came out that when James Earl Jones passed away, he had sold the digital rights to his voice so they could continue doing Darth Vader and some of the other roles, you know, iconic roles that he played, that his voice is, is the role. And, and he sold the, the, he he, his estate sold that for a pretty penny. You know, similar to the Bella Lago case, which originally said you have a, artists have rights to their images, artists have rights to their voice.
Artists have rights, you know, to their likeness. Um, unless it's satire now. But this really begs the question.
I mean, think about what you said, Lisa OpenAI says, well, we can't train our models without copyrighted material. They acknowledge this is copyrighted material. Well, thanks for telling me that.
'cause that's why I thought my copyright was valuable, otherwise I would've just let you use it. You know what I mean? You, you hear people crying with two loaves of bread under their arm about why can't we use copyrighted material so we can make money The honestly, the nerve, the nerve of them to actually make that argument and expect us to have sympathy for them.
Have we gone bonkers? I didn't see them at the White House pledging anymore. Actually.
He did, he did pledge money. All right. He pledged money, no tariffs.
He could do whatever he wants, right? But honestly, where, what are we coming to here? If copyright and IP means nothing?
What's our beef with the Chinese? That was always the thing. They don't respect our ip.
Well, if we don't re you know, my grandmother always told me, if you don't respect yourself, don't let, don't expect other people to respect you. We don't respect our ip. Other people won't either.
So I say more power to these musicians and I'm, you know, it's funny how these things always take place in the e UK and the EU where they seem to still have a, a sense of, of individual rights. And they haven't sold out to the oligarchy quite yet, but more power to 'em. So John will, the artists of which, you know, many have, are native to Great Britain and Great Britain has driven rock and roll and all this other stuff from, will they just leave that whole country and will they say, we're not gonna put our product and make it available in the uk 'cause it's gonna be stolen by AI companies?
Yeah, that's a really good point. You know, that that's, you know what, in a sense, it has happened before because of the taxation in Britain. A lot of artists left the country relocated to France, Switzerland, United States to avoid that.
So there is precedence. Um, and in terms of recording, you can record anywhere. I think, I think the, the British government probably is stepping back and thinking, Jesus, you know, what have we gotten ourselves into and trying to figure out a compromise.
Like all these things, usually we try to do at least with, with so much power that's been represented by these artists. But I think there's a a very good chance that they, that they lead. Yeah, I think it could happen.
But, but, but from practically speaking, okay, so they pick up and move to the south of France or to the Dakota building in New York City or whatever, right? Does that stop the British government from allowing the AI companies to use their, their music to train their models to make good music? Well, I, I think, I think it sends a message to the government.
And when you have the mega stars leave, which impacts an industry and the economy in a certain sense, maybe it does. And maybe they sec they, they rethink what they, what they did. I mean, that's, I guess the leverage you have.
But I understand your point. Those, Those guys generate a lot of taxable revenue for the uk. So that will just disappear.
And then their recording companies might just say, we're not gonna let any, any station or any outlet in the UK have the next album. 'cause the other stuff's already out. So that horse out of the barn door, but anything new they could theoretically lock down.
And then maybe, you know, I don't know, Malta sets up and says, you know, Hey, we're gonna welcome all you guys here to live and we will have friendly courts for you to pursue these cases, and we will tax your revenue less than the UK did. And for Malta, it'll be a huge win. I don't know, I'm making that up, but theoretically, Yeah, no, I just, yeah, it's, I'm just gonna throw this out too.
Maybe I'm going down a rabbit hole. But the whole thing with, uh, Taylor Swift rerecording all of her albums in terms of owning the rights to that, I mean, I'm not, I'm not sure about the particulars, but the, the fact is, if you are big enough and strong enough as an artist, you can flex your muscle and have a fair amount of influence. Especially if you have somebody like McCartney who, when I lived in England, the joke was he made a, a pound a second from royalties alone.
Um, this, this is, I mean, this has a lot of weight behind it. We shall see, we shall see. I, this isn't just a UK thing, right?
Because what are you gonna do not allow the ais in the uk? I mean, and what about the EU and the US and the brick countries and the rest of them? So what happens when the artists say there'll be no concerts in the UK either.
'cause remember, you know, people wanna go to the experience and, uh, I don't really wanna sit at a concert and watch a digital robot. So, you know, there's a lot of leverage here Beyond this. Hey, don't knock it until you tried it, until you walked a mile in those shoes.
Talk to the porn guys. Um, but, uh, no, I mean, so that is one way that though, where like, I don't know if moving out of the country gets 'em what they want, but refusing to perform in the country. I think that'll put the screws to 'em a little bit.
That happened in South Africa. Remember all those Oh, screws were no, no. Major artists would go To.
Yeah, yeah. Well, they tried, they tried it in Israel too. The boycott, divest, whatever it's called.
I try to pressure artists not to perform in Israel. Yeah. If you live in and you wanna see a concert, you're gonna have to go to Dublin.
That's all there is too. I'd rather go there. Um, you know, the, the thing too is it's just, as you said, Alan, in Europe, they are, they do value copyrights, privacy, um, their personal data.
And they're so far ahead of people, they're so far ahead of us. Uh, I, I just can't imagine something like that happening in, in the US to this extent. Not as long as they pledge some money for AI data centers.
Yeah, I know. Um, you all right, Hey, let's wrap up our Friday. What a good, this was a good, this was a good panel today with some great topics.
We hope you've enjoyed this at home. We have, of course, our usual text on tv, uh, schedule right behind us here on the Gang. So stay tuned right here on this bat channel.
And you, you'll be able to see that. Of course, you could also catch Textron Gang on Textron TV and watch past episodes. You can also catch in on our YouTube channel, our text Drug tv, YouTube channel.
It's on there as well as on your favorite podcast platforms, right? It's probably being, you could probably, probably being used to be trained for that OpenAI thing too. But, um, but it's on Apple Podcast and Spotify and the rest.
But until Monday, we'll be back with lots of great new content. Monday. This is Alan Shimel.
On behalf of Textron Gang and Textron, have a great weekend, everyone. We're outta here. This is Textron tv.
Hey everyone, welcome back here to another Textron TV interview. Our, uh, guest for this session is Rob Truesdell. Rob is the Chief product officer of a company named Pangea.
We're gonna find out a little bit about Rob and Pangea here and discuss some AI related, uh, information. Like we don't all have enough AI related information we're discussing. Hey, Rob, welcome to Tech Drug tv.
It's great to have you on here. Thanks for having me on, Alan. I appreciate it.
My pleasure. So, Rob, I mentioned your CPO Chief Product Officer over there at Pan G, but give a, give us a sense of kind of your career arc or, you know, things you've done in your life. Yeah, yeah, absolutely.
So I started as a practitioner myself, building secure networks, uh, utilizing firewalls. I-P-S-I-D-S, VPNs, doing a lot of that for government, federal contracts as well. Um, and then I got more onto the product side of things and started building, uh, network acceleration for intrusion prevention, intrusion detection, doing things like deep TCP flow analysis.
Um, and then started transitioning that over to security operations. And, um, there, that was a great experience. Uh, had the opportunity to work with our, our broader team still now at Pangaea.
Uh, but we worked together before at a company called Phantom. And, uh, there we created the security automation orchestration space. Um, very, very popular product.
Um, Splunk was, it wasn't Phantom acquired by Splunk, right? That, That's right, that's right. It was all about, what was great about it were it brought together, um, engineering efficiency and security into the same product.
So it was all about, uh, trying to triage security alerts as quickly and efficiently and, um, diligently as possible through the use of automation. And what's interesting about that is now a lot of that work is going to be done with AI agents, which is, which is pretty cool to see. But, um, yeah, we were acquired by Splunk in 2018 and then, uh, led the security operations business there at Splunk.
And then, uh, in 2021, uh, late 2021, uh, joined the Pangea team and started building what we're gonna talk about today. Very cool. Very cool.
Yeah, I know Phantom was, as you said, it kind of defined a, a market there, right? Yeah. And it was a great acquisition by Splunk as well.
Um, give us the Pangaea background then, it sounds like with there more phantom people at, is that it or? Yeah, I mean, uh, our, our, our core founding team, um, were also involved at Phantom. Um, and, uh, really what, what had happened were, during that time, uh, uh, of course, cloud security was, was booming at the time and, and specifically application development in cloud and securing that whole dynamic.
Uh, so we started looking at that problem and came to this realization that, uh, that developers should be focusing on building the applications that are delivering value to their business, and less so worried about building security features. Um, they're not experts at building security features. And when I talk about security features, I mean things like data handling, uh, the right way.
So handling PII and sensitive information handling, authentication access controls. Um, so we started looking at solving that problem for developers in a scalable way, making it really easy for developers to integrate that functionality into their own applications without spending a lot of engineering time. What we found over time were that our users were leveraging all of these capabilities that we had built for AI use cases as over, uh, the AI use cases started becoming very popular over the last, like, two years.
And it's just going up and up and up. Now all of the new application development is around, uh, the interaction with LLMs. What we, again, what we found were developers and, um, and enterprises that were using our APIs, they were using them to secure, um, interactions with LLMs, uh, from within their applications.
So we thought, wow, that's, that's pretty interesting. Um, and the key use cases that led it were things like, uh, again, securing, securing data interactions. So if you're encountering social security numbers or driver's license numbers or credit card numbers, those type of things, people are always concerned about that information leaking or an LLM sharing it back to a user, being able to protect against those type of of things in a scalable way.
We're perfect for that. Um, auditability and traceability, those are other APIs that we had delivered. People need that for visibility into how the LLMs are behaving.
So, um, over time I said we were building this comprehensive library of security capabilities for developers and found that the killer use case was ai. So we started pointing everything towards that use case, and it kind of evolved to there into going deeper down the security challenges of AI and protecting against things like prompt injection attacks and jailbreak attempts and securing, um, access controls across rag data pipelines. And more and more I'm sure we'll get into, but that's, that's the background of kind of where we started and how we got to where we're at now.
Excellent. Very cool. Um, website.
Yeah. cloud and what's great Okay. About, uh, if anybody were to go check out the website today, what's, what's great about, uh, engaging with the company right now are, uh, there's, there's two very interesting things that are happening.
One, uh, we have an AI escape room challenge that's happening where, uh, you can register and basically there's a three room challenge and rooms are unlocked. Um, it's gonna be happening throughout the month of March, but rooms are unlocked, uh, pretty much each week in, throughout the month of March. And it's all about, uh, optimizing prompts to escape the current room that you're in.
And of course, at the end of the, well, very cool. Yeah, yeah, at the end of the competition, there's a cash prize. There's a lot of fun things involved in it, like with the community and all that.
But, uh, but yeah, if you go on the website, you'll see that that's a great way to kind of get engaged with the company. And then second, um, for the people who are like really interested in the, the product offerings, everything that we have is self-serve. So you're not working through, um, a sales team or anything like that to get access to it.
You basically, you know, create a login to our SaaS offering, and then you get access to all the capabilities that I mentioned plus prompt injection detection, data protection with AI guard and, and other things. But, uh, yeah, there's, there's a great engaging game for, for people to play throughout month, uh, the month of March, and then there's our whole self-serve experience of the product. I love that.
Very cool. Yeah, very cool. Indeed.
7 a couple days ago, and there was a lot of talk about, you know, it's, it seems to be much better than its predecessor on code generation. Mm-hmm. When you look at the people who were using Pangaea, is it people who were using it, that are using AI for co-generation or using AI for marketing?
I mean, one of the things, you know, I I'm asking people is what are you using AI for? Right? And we all, you know, if you believe the hype, we're all going to use AI some way or another, right?
But I mean, I know how I use it, it helps me every day, right? Whether it's articles or abstracts or marketing related, I don't code as much, so I don't use it, but I'm wondering who, who the base is at Pangea. Who and what are they using AI for?
Yeah, great question. So, um, I, I mentioned before that the, um, the original focus of the company was all around application development. So, uh, and, and developers and even, uh, um, those in the security space we're utilizing our APIs to help secure the applications that were building.
So when you kind of peel back the onion on that, it's enterprises who are building applications, both internal as well as external, um, to either, um, uh, supplement internal employee use cases or supplement customer experience, um, reduce friction in their user experience, things like that. Um, and what ends up happening are they use a combination of foundation, foundational, LLMs, um, and sometimes, uh, internal LLMs internally trained, but in a lot of cases, they're bringing their enterprise data together with those LLMs. And that creates a lot of risk, uh, a lot of risk because access controls are lost in that trans transition.
We hear that a lot. And that's a problem that we're, we're working with a lot of customers to help them solve with. We have an authorization, API that synchronizes permissions across data sources all the way through to vector dbs and the actual vectorized representation of the data in that database.
Hmm. Uh, that's a, it's a pretty powerful use case. And we're seeing that on the application development side.
So enterprises building AppSec that are utilizing LLMs. Now, there's another half of that, which are the enterprise workforce use case. And this is where things like copilots come into play.
So using copilots for, um, whether it's a, a Google workspace, a Microsoft workspace, gi GitHub, uh, things like that. Um, which, which is a whole other kind of, um, whole other problem to solve. And what we're finding are that, um, the people that are utilizing Pangaea to help solve that problem are taking advantage of our gateway integrations.
So, um, there are, there are two primary ways to utilize these guardrails. You could use APIs with our guardrails and integrate them directly into your application, or you could leverage a gateway plugin. So things like, um, Kong or Port Key, or there are several others that are out there that, that integrations exist with.
And what's great about that is it kind of funnels all the, a AI activity into a, like a single choke point, and you can apply guardrails, uh, and even have visibility and things like that at that point. So those are kind of like the two different approaches that we're seeing, like the application style use case where they may be integrating with an API and then a workforce style use case integrating with a gateway. And by the way, those can be mixed and matched as well.
It really is dependent on how that enterprise is, uh, implementing and rolling out ai. Got it. Got it.
Um, let's shift deep, really come back to that. But let's turn to our topic of discussion today. You know, the whole idea of LLMs has become a bit risky, right?
I mean, I, I, I forgot the exact term you used, but using, you know, the large, the LLMs, that sort of chat GPT or, or Atropic and so forth, run, you know, industrial LLMs, whatever you wanna call them, and then companies creating their own LLMs, right? Um, different sort of risk, uh, you know, uh, models there. One, you have, you know, all the control over, you created that LL M1, you kind of taking what people have given you, uh, but nevertheless, risk involved in both of those risk models.
Um, and then, you know, you mentioned Vector database. Well, you know, we got Word IBM bought data stacks, right? Um, you probably saw that news.
And of course, they, they pivoted from a Cassandra kind of thing to a Vector database type A around this AI stuff. What, how do you define the risk for LLMs? Let's, let's, why are they risky?
Where, where's the risk there? Let's go start from there, and then we'll talk about how, what we could do about it. Well, um, especially when you, when you start, when, when companies are getting the most value out of LLMs, they're bringing their enterprise data with it.
And the easiest way to do that, the fastest path to doing that are with the rag, the, the augmented generation. So the utilizing Vector DBS to marry that data together with an LLM. Um, so that is, that's, that's where a lot of value gets unlocked.
The risk in that, um, that, that we're finding in people who are doing that are all about data access controls, and the, the use case that everybody is afraid of is the one where I have, I am servicing my customers with an LLM and customer sensitive data, and I have customer A asking questions and obtaining data about customer B could be receipt information, or it could be, if it's a healthcare use case, it could be sensitive, sensitive, uh, private health information. But that, that's the, the core fundamental problem when you start marrying the enterprise data or, or, um, or sensitive data with the LLM are the access controls behind it. The access controls get, get lost, and it's a hard problem to solve.
And it requires, uh, a really requires integration with that rag pipeline all the way through to the Vector db and having permissions persist at the vector level. That's really the way to solve the problem. Um, at least that's the way that we're solving it with our customers who are doing it with our authorization API.
Um, but that, that's the major, major threat behind, um, or the risk you asked about, or the, the leaking of that information, because you lose permissions as that ra as that data's flowing through a rag pipeline into a Vector db. So it's important for anybody who's, who's bringing those two worlds together to really think through the architecture of when that data's getting vectorized, how do you persist permissions? How do you keep permissions in sync with the, the origin data source?
Because at the end of the day, these vectors are coming from some data store somewhere inside of the enterprise. So keeping those things in synchronization are also important as well. Excellent.
Yeah. Um, let's talk a little bit about what Pan G does in this space. Right.
So, um, the major things, I, I talk about the foundational secure or security APIs and services that we've built, but it, again, over the last year, it's evolved a lot. We just announced general availability of our AI guard and prompt guard services. Uh, in fact, that announcement went out last week, so it was a very exciting time for us.
We've been working with a lot of customers to build that capability. Um, what's great about the AI guard and the prompt guard use cases are they protect against everything from prompt injection and jailbreak attempts all the way through to, um, identifying, uh, toxic, toxic behavior or language, uh, in, in la uh, prompts being submitted to and from an LLM and identifying sensitive data and a lot of those, um, a lot of the use cases that we talked about before. Now, uh, what, what's great about what we built there is we built it in a way such that no matter how an enterprise is utilizing AI or LLMs, we built it so that we can intersect at any, uh, implementation point.
So if they're writing code and they wanna integrate this via API, they can do it with an API, uh, if they wanna integrate the guardrails at the network level, you can integrate with an AI gateway. Uh, for, for enterprises that are very SaaS and cloud friendly, they can utilize our, our SaaS offering, or if they need ultimate control over how these guardrails are deployed, they can take a self-managed, self deployable version of these guardrails also. So we're, we've tried to, um, knowing that the people that are utilizing these capabilities to their fullest extent have pretty, pretty strong infra, uh, skill sets.
We wanted to make every option available to, to consume this. So there's a, there's a pretty wide variety of ways to deploy and adopt LLM. So, um, yeah, integrating with gateways, integrating with APIs, self-manage SaaS, the full spectrum's there for, for people to be able to, um, take advantage of these guardrails.
Fantastic. Rob, we only have 15 minutes. I think we're probably at 20 or more.
I wish we could go into this more, but Pangea Cloud, that's P-A-N-G-A cloud. That's right, that's right. Go check it out.
Keep up the great work. You know, we're just, honestly, a lot of this stuff's just scratching the surface, right? If people are just beginning to realize some of the implications here.
I just a quick plug. We're actually at RSA this year on Monday, every, for the last 10 years we've been doing the DevSecOps, uh, event this year it's about cybersecurity, AI and app dev. And we, we actually have the CSO from, uh, from OpenAI, uh, anthropic, senior security guy from Meta and Google DeepMind, ciso, I think.
And we're talking a lot about securing your data, making sure it doesn't get sucked into the, the LLMs and, and how to, you know, do all these things. So, should be an interesting session, or it's actually a seminar. It's all day.
Um, but we'll come back, we'll hear more from you, man. I appreciate it. Thanks for having me on, Alan.
It's, uh, it was a lot of fun talking to you. Absolutely. Rob, it's a lot of fun speaking to you.
Rob Truesdell, chief product officer of Pan G here on Textron tv. We're gonna take a break. We'll be back with more.
This is Textron tv. Hey guys, thanks for the throne. We're here with Howard Bob, who is president of engineering and consulting services for DXC technology, and we're talking about quantum computing, of which there's been a lot of noise lately.
Howard, welcome to the show. I'm pleased to be here, Mike, good to see you. We saw Microsoft most recently and Google before that, talking about new processors for quantum computing and making some interesting claims about advancing the pace at which we think we're gonna be able to, uh, operationalize this technology, shall we say.
But is this more hype than reality? Because I'm still scratching my head about, well, is there such a thing as a compiler for quantum computing? How do we actually invoke this stuff?
The, uh, well, certainly there's a, a, a crossover between classical computing and, uh, quantum computing. So in terms of the algorithms that are being created for quantum computing at the rudimentary level, it's at, with the number of qubits they use, um, still needs classical computing to set that data to do further work with it. Um, but this is the decade of quantum computing, um, that continues to be pronounced by luminaries in the field.
Vin Krishna from IBM, who is being one of the lead, um, person in research and development in terms of building the capabilities that they have. And then when you look at all of the actual billions of dollars around the world by companies as being invested to address the actual basic issues with quantum physics to be sold in order for quantum computing to get to a million qubits that was announced by Satya earlier this week, um, I think it continues to show even more promise that actually it will become a real thing. What kinds of applications can we build, and are they gonna be things that we build and deploy alongside classical computing applications, or will eventually quantum kind of just supersede everything?
It will be complimentary. Um, essentially if we think about advances in mathematics, um, which originally were formulated in the mind and then written in sand or put in unifor on the clear tablets, there's been advances in technology that's allowed branches of mathematics to become available on a broader sense. And classical computing kind of ones and zeroes allowed things such as databases, which is complex mathematical means of organizing data to come alive, become alive, and that then created companies like Oracle, like IBM's databases services.
And then as classical computers have become, uh, more powerful, it allowed other more complex branches of mathematics to become available. So graph, in terms of lots of nodal information, then created companies like Facebook and Instagram and so on, certainly less productive, um, uh, applications relative to what happened with databases. And quantum computing is a mechanism of unleashing branches of mathematics that isn't possible to compute on classical computing.
So particularly in terms of materials management, materials creation, health and life sciences where proteins, where new material management can be modeled, um, through, uh, mathematical algorithms on a quantum computer. But then coming from that, in a number of cases, the actual further work will be done in classical computing because it's more appropriate relative to the types of mathematics that have been used relative to the ones on the breakthroughs with quantum computing. Are you concerned that maybe we are gonna wind up in some sort of crazy hype cycle that we saw with AI, or, um, is this kind of from your perspective on some, you know, natural order of things, curve of adoption?
It's, it will go through natural hype cycles. Um, and we're probably about to, to kind of come into that now to get, get to true production, um, volumes. There is this feud that you have to be at about, uh, 1 million qubits.
We're short of a hundred thousand qubits currently, so materially less from where you need to be. There's issues around stability of the atoms. Um, there's issues around capturing the data, um, on a sustainable basis.
So there's a lot of material work, cooling work, um, stability in terms of the, um, atoms that needs to be established before quantum computing is truly, um, uh, commercial value. But the approach that Microsoft has taken is interesting. It, it uses a 1930s Italian physicists methodologies ma, which is actually the name of the chip.
And that gives us stability in terms of the atoms all being precisely placed on the actual chip set. It's taken the team 17 years to create all the various technologies for that chip to actually come into reality. It's topological, um, quantum computing.
Um, but it's interesting, it's kind of the synthesis of pure science then into actually applied science. Um, but I was reading IBM's, um, quarterly reports. They've already generated a billion dollars of revenues through their quantum computing, um, offerings.
So, um, there is clearly some commercial use cases in a material sense that's been used given that that amount of money is being spent by third parties, either public sector or private sector in terms of their platform. And that would be the same for the other, um, uh, cloud the other quantum providers as well, For lack of a better phrase. Um, the atomic unit for quantum computing that people refer to are these cubits.
What exactly is a qubit and why are they not just automatically stable? The, um, the best way to describe it is to do it by means a comparison. So a classical computer uses ones and zeroes to actually do the calculation.
So the thing, it's, the thing is either on or it's off. Um, so that's, that's the digital term in the case of quantum computing by using atoms. So it's actually very much getting back to nature to do a comp, uh, calculations as opposed to ones and zeros.
A, a calculation can be a one or a zero, or it can be anything in between. Uh, which then gives us a much broader me means of actually the different types of calculations and increases the pace by which the calculations can take place. It's a notion of superposition is, is is the actual, uh, physics terms.
Um, and it's because of the nature of an atom when observed will actually operate in a different way. Um, so because of that, when you're doing these complex mathematical equations, you've got a much greater range than either a one or a zero. And how does that get us to being able to maybe conduct research that we couldn't do before, such as, I don't know, maybe finding cancer clusters that seem to allude us.
What is it about the nature of that style of computing that is more, uh, richer in some instances than what I would do with classical computing? Yep. So it is, is the speed of its computational capabilities and the different types of computational capabilities that you could do.
And again, by we of example, um, there's always a, a ying and a yang to any technology that comes through. So for example, nuclear power is a potential mechanism to help, uh, reduce the amount of dependency on fossil fuels. But also the, the, the ying of that, the dark side of nuclear power is nuclear, uh, uh, bonds.
In the case of, uh, quantum computing, it has incredible potential of these types of mathematics that can allow us to address things such as life sciences and cancer, um, or all sorts of other different disease treatments. But the, the, the ying of that is, um, quantum computers can unencrypt encryption techniques that have served as well for quite some time. Um, so RSA encryption techniques, so that means that the data that we have is protected and therefore intellectual properties protected, people's privacy is protected.
And so, and the current encryption techniques that we have, if you were to use a, the most powerful classical computer that exists, it will take a billion plus years to go through all the potential permutations to deen encrypt those levels of, um, and encryption. However, when we get to a production level, quantum computing, um, something that would take over a billion years on the most powerful classical computer can be done in seconds, the encrypt in seconds. It gives you a sense to the actual incredible power of the computational capability of a quantum computer relative to a classical computer.
And obviously with that, it means we can do analysis of all things. Mathematics can actually underpin everything within nature, everything within materials, uh, design and management, everything within the university. We also hear the phrase quantum resistant encryption and the rise of something known as Q Day when these quantum computers are able to break all existing encryption.
But based on what you're saying, is there such a thing as quantum resistant encryption? 'cause that seems like the quantum computers are getting bigger and better and faster than we thought. The better way to to think about it is to be post quantum agile.
So, so DXE has a post quantum security practice where we will give advisory services to our customers to actually first understand and prioritize the vulnerabilities that they have within their environments, and then think about how they actually, um, protect them. There is a standards body called nist, um, which is, um, youth on an international, it's an American standards basis, but very often used on an international basis. And they continue to run competitions with various research labs around the world to come up with encryption techniques that will be quantum resistant.
Now, I, I think the, the reason for your question is it's been proven on a number of occasions that the actual research labs that have notionally had encryption techniques that have been felt to be post quantum secure, then ultimately being deen encrypted just through classical computing, let alone, um, quantum computing. Um, and that's why the word agile is more important. So you create an environment where you can actually be agile with the new encryption techniques that you put in place.
Now, the simplest mechanism is to actually keep yourself ahead of the quantum computing is simply to extend the length of the keys. So an exce, uh, uh, an encryption technique uses factoring, and the longer you make the key, the harder it is to deen encrypt. Um, now that means also that there's a lot of work you have to do in your own environments because the longer the key is, the more memory you need in your applications or in your hardware.
Um, and that's the kind of work that we at DXC do. And that keeps you ahead at the actual arms risk of, uh, quantum computing. And it's an ability to re-encrypt encryption techniques.
The systems I've seen so far are sizable. Um, it's not like something I'm gonna deploy in my own little data center somewhere. So is this always gonna be some sort of cloud service in a shared resource or over time will these systems continue to get smaller and smaller and more energy efficient?
So they're actually materially more energy efficient than classical computing already. Um, they, um, they do have to be, um, cool. They're incredibly, uh, cool temperatures.
They have to be called an outer space in order to have stability with the actual atoms. Um, in terms of their size, everything will reduce in size, but the form factor that will be the majority, but not the only mechanism of actually using quantum computers will be through cloud-based solutions. You can already use quantum compute.
You can already program against quantum computers with both IBM and Google. The actual open source language you do that against is quiz kit, which you can download and then start to actually do some fairly rudimentary work on the, on the, the, uh, the more basic, um, quantum computers are out there. But there are some health and life science companies and hedge funds that actually buy the quantum computers themselves so that they have a proprietary advantage in terms of what they're doing with them.
So what is it that I'm going to use to, you mentioned this language, is there a different way of thinking that software developers are gonna have to have to invoke these things? I mean, 'cause we've trained developers to think in a specific kind way all these years. And is that gonna need to change in a, in a quantum model where maybe, you know, the old fashioned saying of two things can be true at once, but how do I program to that?
So it's, it's the way that you program again, is quantum computing is not a thin else statements that we may be familiar with from rudimentary, um, uh, application development courses. We've done it's algorithms. So it's, it's, it's kind of quantum physicists.
It's deep applied mathematicians looking to get answers to complex mathematical problems that are computated through this incredibly powerful computational capabilities of the actual supervision superposition state that, uh, quantum computing can be in. It's then the output of that in terms of the answers to those questions that you would put into classical computing and apply the more logic based, um, application development there as well. That's the need for the complimentary element.
Um, so you get the kind of the, the turbo boost, um, capability of quantum computing to get the answers to very complex mathematical questions that you're asking, whether it's protein analysis, whether it's CO2 analysis, whether it's how you actually create a new alloy at certain, um, tensile qualities, um, um, is, is how you all see that come together. Really that's not two difference to how, um, final financial institutions and other organizations and regionally used GPUs. GPUs get a lot of publicity now because they're used for large language models, um, for ai, again, because they got a lot more horsepower than what a classical CPU is.
But prior to that, GPU by Nvidia were very used extensively across financial services institutions for their, uh, capital markets businesses. So how they were do equity trading, fixed income trading, so again, complex mathematical elements using bit pap and statistical models on a, on a, a form factor that was appropriate for that. Quantum computing is the next mechanism to do even more complex other ethnic work.
So How do I have a reasonable conversation with C-level executives who have already shown a tendency to get a little overly excited about AI because of fear of missing out? And am I gonna see that come full circle and how do I manage that conversation more successfully? And maybe we've managed the AI conversation so far.
Yeah, so, so quantum computing I've been talking about and kind of been concerned about on the kind of the deen encryption elements since probably about 2015, so 10 for 10 years, but it's a conversation that resonates with next to nobody in any enterprise environment. However, what I would say is at the end of last year and now 2025, there is a increasing appreciation as to what it can be, what it will be, but more importantly the risk. And I think what's driven that is that under the previous administration in the United States, there's have been a number of executive orders put out that all federal agencies have to be paused quantum agile, um, by a set debt.
So that's a recognition by the US government that they are vulnerable from a, um, a cybersecurity attack for their data to be taken and then deen encrypted. And as a consequence of that bringing into federal agencies, when federal agencies contract with their supply chain and the private sector, they also want their supply chain to be post quantum, agile and secure. And therefore that starts to get an interest in terms of how you deal with the negative consequences of quantum computing as opposed to the positive.
Um, and on the, the, um, your, your reference to Q there, um, the problem statement that has to be resolved here is the same problem statements for people of a particular vintage that will remember Y 2K. And that was the concern back in 1999, December 31st, that because computers for some reason never imagined that there would be the year 2000, the applications would cause all sorts of problems that banks could no longer give money, airplanes would fall out the air and so on, and a full raft of every banking system and every software system that served all industries had to be reworked in terms of their applications to deal with that issue. Course quantum encryption and deen encryption presents the very same problem.
And there is a thing called a Moscow score that calculates and your environment and the encryption envir, uh, techniques that you have and the amount of time it takes to re-encrypt. It will tell you when you need to start to do remediation relative to when quantum computing gets to a position work in d and Crip. And the reality for every medium and large size enterprise is the deadline is already passed.
Y 2K has already passed, the work should have started some time ago. Um, so what we will see, and we're starting to see within our post quantum security practice is a trickle of conversations, and I would expect throughout the course of this year that would turn from a trickle into a deluge. Some folks would say, not only has the deadline passed, but um, nation states are already hoarding encrypted data on the assumption they will be able to decrypt it someday soon.
So we should we just assume that everything we thought was secure is gonna be shared soon. Yep. So that has been a stated objective for certain nature states to steal the data now, harvest the data now and d encrypt letter.
Um, and that has been going on for some time. Um, it's public domain that if you look at all the various big, um, uh, data breaches in the US over the past three years, we've all had our, we've all had our identity stolen at least three times, um, uh, because of the, the large companies with the large datasets that have been stolen. And that is not by accident.
That's very clear nation state, um, cyber attacks to create a situation where it can be harvest now deen encrypt later. And therefore, as a consequence of that, not only in the private public sector, but, and private sector individuals need to think about, okay, what does that mean for their own personal protection of their identity? And increasingly, we're starting to see more and more companies come up with solutions in this space, particularly in the deep fake space, um, um, and how, um, individuals can protect themselves.
So in the same ways the the negative side of quantum computing is starting to come into the consciousness of the public sector and the private sector, it will need to come into the consciousness of quiet individuals as well. What is that one thing from your perspective then that we're kind of overlooking as we have this discussion? 'cause you know, on the one hand you'll see the CEO of Nvidia saying this is more than a decade away.
And other folks are saying, we've got this amazing thing that we just built yesterday. I think folks are looking for guidance. So what do you tell 'em?
The key element is to start to estimate and understand what the risk is in your environment. Um, it would be easy to panic and then think you have to remediate everything going forward. And that's the advisory services that we provide where we will help you understand where your risks are, how you should prioritize that relative to your core business processes or the data sets that you have.
And then take a measured approach to de-risk those environments for yourself going forward. There'd be some areas that you, they're not mission critical to you, you're not gonna impact your core business processes as a consequence of what happy happen here. So that's the first element to actually get visibility.
'cause, 'cause the hysteria in life in any dimension is always highest when comprehension is lost. This advisory services that we provide is get comprehension to a non level, and then you can understand the risk you have, high inherent risk. What's the compensating controls you'll put in place?
What's the residual risk you have when those controls are in place, and does that meet your risk appetite? All right, folks, you're hearing it here. Quantum computing, it's real, but like most things in life, it's a sword that cuts both ways.
So we gotta handle it with some care. Howard, thanks for being on the show. You're more than welcome, Mike.
Thank you. Alright, and back to you guys in the studio. Hey everyone, it's Alan Sch here for another episode of Jimmy Says, Shi Says, says, thanks for joining us.
Whether you're watching this live on LinkedIn or maybe on our YouTube channel or text from TV or wherever you're watching it, I appreciate you joining in and look forward. If you have any questions or comments, feel free if you're on live here to, to put it in. I wanna talk today about some irrational exuberance, perhaps or maybe not, around the AI and data center space.
You know, it's been going on now for a while, but it's certainly been accelerated with the incoming administration who likes to create tech oligarchs up to the White House and talk about what a commitment they're making to, uh, the, the AI and data center space specifically in the us. But many mistake, this is not just a US port barrel or, or face of, of, you know, pledging dollars or telephone for AI and data center. It's a worldwide phenomena, whether we're talking about Europe or Asia, China, everywhere in the world, money's being pledged to plow into AI technology and data centers.
And I, you know, I get it and I get the promise of ai, but if you look at the numbers, it just doesn't add up. You gotta ask yourself is are we, who are we doing this to Political favor to keep tariffs slow or to just keep up with the Joneses? But let me give you an idea of what I'm talking about here, if you don't mind.
I'm old school on me here and come up to a flip chart and, and write some numbers down. I promise I won't write cursive, so you'll be able to, to read it. But let, let's just look at like some of the, the money that's been pledged in, in this AI data center, telethon just this week.
Apple pledged 500 billion. Everything I'm going to give you today is in billions, by the way. So that's from Apple.
They pledged $500 billion in US investment. Now, truthfully, this wasn't done as part of a President Trump thing or anything like that. It's consistent with numbers they've talked about before, but they also claim that that $500 billion will lead to perhaps, uh, 20 K jobs, 20,000 new jobs.
Wow, sounds great. $500 billion. A 20,000 new jobs means each job costs us about $25 million.
Those are pretty expensive jobs. I hope people will be paid that well, but that's not all right. We, we previously saw the Stargate project, you know, with the headline by Oracle and, and, uh, SoftBank and ai.
So that's Stargate. They also pledged $500 billion and said it could lead to hundreds of thousands, hundreds of thousands of jobs. Well, that's at least cheaper per job than Apple has us, but we're, we're at a trillion dollars here, guys.
Let's add in some other money. Meta has pledged certainly $65 billion this year on AI and data centers, but there's talk of them even going up to 200 billion. Okay?
Microsoft alone, that's meta Microsoft. Well, they've pledged for sure 65 billion of their own, excuse me, 40 billion of their own, but also working with the good folks at BlackRock, the largest, you know, PE company in the world on another $80 billion pledge. And with the UAEI, I believe it's their sovereign fund for a hundred billion dollar investment.
That's not all US by the way, but a hundred billion dollars. Then we have the damac, D-A-M-A-C Damac run by that fellow from Dubai that also carries favor with the administration. They've pledge asked small potatoes, a mere $20 billion to dam By the way, Microsoft says that that a hundred plus billion dollars will lead to the next billion jobs that are AI related.
That's a billion jobs AI related, much cheaper than the Apple jobs. I don't know what our economy would be like with a billion jobs, more, or worldwide economy, I guess we could use it. Then we have Jeff Bezo, he, Jeff Bezos, he's of, we're only talking about freedom trade and, and personal freedom fame.
He claims Amazon is gonna pledge 11 billion, yeah, me, a bag of shells for Amazon. But they've already committed via AWS and Amazon to a hundred billion dollars this year In data center and capital expenditures in, in infrastructure like that. Not to be outdone, the Royal Fi family of, of Saudi Arabia.
9 billion in ai in Saudi, in Saudi itself. That's an awful lot of money. But you know, that by the way, comes outta business, the business standard.
Most of these other ones that came out of here, uh, were from, uh, all from the business standard. So if you wanted to look them up, the uk they haven't really announced their full project yet, but they have already pledged 14 billion. So in line with Saudi Arabia, France, of course, went out and made a bold, bold mark right at that last conference.
They pledged $112 billion, and not to be outdone the eu. The EU went out and said, well, France, you're not alone. The EU stepped up for $206 billion.
These are all billions with B Now, China, well, they don't really give you the real numbers and you don't know what they're really paying their people, but China has said that they are definitely committing $22 billion to ai. And they've also claimed That China, the state government itself, in support of the Alibaba 10 cent by dance, the Chinese tech industry, the state is gonna put in $138 billion. It's probably more than that even, but 138 billion state sponsors for Chinese tech, their version of Stargate.
And then the good folks at Alibaba, one of the Chinese tech giants have pledged another $53 billion for AI and data centers. Wow. Get your calculators out.
I I tried to calculate this off, off, uh, camera earlier, depending on which some of these, you know, uh, are, are ranges, ranges, we're dealing with over 2 trillion. That's with a t, not a B, $2 trillion in investments in AI and data center. $2 trillion plus 2 trillion.
Now, let me put it in perspective for you. Sorry for the aids here today, but I, I like to do this. So this is a chart, and hopefully you could see it.
These are the top 20 countries with the largest GDP gross domestic product in 2024 and 2023. As you can see, the US leads this past year was just shy of $30 trillion, China 18 and change, but, and it, it falls off pretty rapidly from there. 7.
Japan is just over four. India just under four UK at three and a half, but it's over $2 trillion. The amount of money pledged to AI and data centers comes in somewhere around here between Italy and Canada, right in the top 10.
So the, the amount pledge to AI and data centers ex is bigger than the GDP of, except maybe the top six or seven countries in the world. It exceeds that. Now, where are we spending $2 trillion?
Well, probably, maybe as much as half of it. I'm gonna sit back down here maybe as much as half of it goes to semiconductors. Wow, that's an awful lot of semiconductors.
I'd be buying more, more Jensen Wong's, Nvidia too, if I were you. Um, you know, that's, that's a, a trillion dollars in semiconductor sales. Um, a lot of it's gonna go to con conduct generating electricity for all these data centers and all these AI processors and cooling them down and everything.
We don't have the electrical capacity to do this, so we're going to need to build electrical infrastructure or maybe come up with new electrical, uh, technologies that are more efficient, less wasteful, more sustainable. Those sustainability seems to be a dirty word in the US these days. Um, or you could take another view.
Is this all nonsense? Is this just people wanting to stake their flag in the race? How much will actually be spent?
How much do we know of this will actually work, right? How much of it is going to, because we've seen this cycle before, right? The last time Trump was president, the guy from SoftBank marched his butt up there, and I think he at that time pledged $50 billion and was gonna do, I don't know, 50,000 jobs or some still cheaper than Apple's jobs.
A million dollar job, 50,000. And it was dubious whether it was spent, by the way, this doesn't include the money that was included under the Biden administration for the CHIP act to build chip foundries and data centers and so forth. I'm all for a digital future.
I, I, I've been in the digital world for 30 plus years, but in the words of Alan Greenspan, is this irrational exuberance? Is this just people trying to flatter the administration and the president in particular so that he doesn't impose tariffs on them? Is this the world involved in, in, you know, making up an AI gap?
Like there was a missile gap with the Soviets, by the way, we haven't heard anything. I don't know if Russia has this kind of money to be putting in here. 184 trillion.
There's more than, you know, it's about what we're, uh, investing in AI and data centers alone. Um, as a, a user here is writing this signals a shift towards AI driven economics, cloud expansion, expansion, and computing power dominance. I hope so, because there's another school of thought that says, Hey, AI is relatively unproven.
We don't know how game changing it's gonna be. It certainly has the promise to be game changing. I believe it could be game changing as much as the internet itself was.
But at what price? At what price, right? Are we, I don't know.
Where could that $2 trillion be used? Is it something for space? Is it for medical research?
Is it to make sure no one's hungry or dying of measles in this country? Is it supporting our aging population? Maybe we need it for more jobs, right?
We, we have less people who are gonna be working. We need AI to do more of these jobs. Ai, agentic ai, robotic ai, all, all of the above.
What we're really building as Jensen Wong says is, are AI factories and that's what these data centers represent. Or is this really all just political stunts? I don't know what the right answer is and what's true or not true here.
What I do know is we certainly seem to be in some sort of bubble and, and hyperinflation or hyper expansive kind of, uh, area. If I was a young person out there, I'd be thinking about how do I ride this wave? com days, and I was right in the middle of the dot coms.
We have seen nothing like this. It, it has the potential to change the, the world economic, uh, order strap in. 'cause I think we're in for a ride, guys.
This is Shimmy, says we'll see you next Thursday. Hey, welcome to my session on transforming from security silos to intelligent continuous security. I wish to thank Techstrong Predict 25 program committee for allowing me this opportunity to speak to you today.
My name's Mark Hornby. I am CEO and principal consultant of a little en, uh, boutique consulting firm called Engineering DevOps Consulting. I'm also author of some books engineering DevOps, as well as the more recent one eng, uh, continuous testing, quality security and feedback.
I'm a member of IEEE, the Deming Institute and the Value Street Management Consortium. I'm also an ambassador of People Cert and the DevOps Institute. And, um, my general, uh, area of focus, of course is DevOps.
I've been the per principal consultant for more than 90 different continuous engineering, DevOps, DevSecOps and SRE transformations over my 50 year career, uh, since publishing engineering DevOps five years ago, I've been pointing out that in an area of, uh, in the era, I should say, of escalating cyber threats, the traditional separation between DevSecOps and SecOps is leaving organizations vulnerable. Uh, siloed approaches fail to provide the cohesive insights needed to detect vulnerabilities early and respond effectively to incidents. That's, uh, despite the fact that, you know, DevSecOps has SecOps in the name, really they're still siloed operations.
Typically in many organizations. Emerging technologies like generative AI and machine learning now offer more transformative potential to bridge the gaps, enabling the creation of intelligent continuous security, uh, adapting and, uh, learning in real time. So this session we'll explore how unifying DevSecOps and SecOps with AI augmented solutions can redefine security management will examine real world security events where traditional metrics failed and demonstrate how AI and ML could, you know, have delivered predictive insights faster, um, have faster incident responses, enhanced vulnerability detection, and I'll leave you with some practical knowledge of how to apply generative AI and ML to build smarter more unified continuous security insights of a safeguard against today's sophisticated threats.
So one item of note, anyone who attends this session in person, I offer a free ebook copy of my latest book, continuous Testing, quality Security, and Feedback. com. All right, so without further ado, let's, uh, get started.
So here's my prediction, uh, basically in a nutshell as far as predict is concerned. Now the Predict 25 event is all about predictions. So my prediction is that this year a new security framework, which I call intelligent continuous security, will bridge the longstanding silos between DevSecOps and SecOps.
Creating unified approach to proactive cyber defense by leveraging AI organizations will automate threat detection, streamline compliance, and achieve end-to-end security with unprecedented speed and accuracy. I'm calling it in, uh, intelligent continuous security because basically it leverages AI and com, the combination of DevOps and DevSecOps and SecOps. I would say that, uh, you know, a relevant quote comes to mind.
William Gibson's is an acclaimed American Canadian writer, often referred to as the father of Cyberpunk, uh, for his groundbreaking work in cyber, in, uh, science fiction such as his 1984 novel, uh, ments, or he is particularly known for envisioning the a digital future and the rise of the internet in this, uh, famous quotation. The future's already here. It's not, it's just not evenly distributed.
Well, hopefully it'll become more distributed in 2025. Okay, so the session introduces a number of things that I hope are good takeaways for you. Um, how AI can revolutionize the way we approach continuing security end to end across both development and operations, uh, portions of a value stream and, uh, services.
It prescribes how AI, augmented tools and AI assisted workflow practices can enhance integrated security automation practices, enable faster detection of vulnerabilities, improve incident response, and provides new and, uh, hopefully unique practical prescriptive insights with the customer use cases. How organizations can transition with AI assistance from a traditional siloed DevSecOps and siloed model to, uh, AI assisted continuous security approach that's more efficient and resilient. I'll focus on, uh, first of all, uh, an understanding of what I mean by continuous security itself and why it's crucial for modern, uh, security practices, especially in large organizations.
We'll also explore how to transition from the traditional sometimes siloed models to a more unified approach and how AI plays a vital role in this transformation. In fact, it one could argue it's, you know, it's the enabler, uh, already security people complain things are too complex and without AI's help, maybe this isn't even completely feasible, but, um, it makes it more feasible. So by helping to automate and assist in threat detection and all the different aspects of security, the ultimate goal is to help you bridge the gap between development and operations.
While leveraging AI to make the make it feasible, intelligent, continuous security focuses on applying ai augmented security practices across the entire development lifecycle and production operations. In DevSecOps, the goal is to prevent vulnerabilities during planning engineering, and in CI/CD pipelines, assuring that security is integrated from the start all the way up to delivery to production. Once the release is deployed into production, SecOps focuses on shifting to defending against exploits and attacks in production environments.
What makes AI assisted or intelligent continued security more powerful is its ability to provide real-time threat detection, automated security testing, and seamless integration of security measures across both development and operations. This ensures that we, as we progress from development to production security, uh, remains a constant and a proactive aspect. There are stark differences between DevSecOps and SecOps and the challenges they face due to cultural, as well as, uh, operational, you know, siloed activities.
DevSecOps prioritizes rapid software delivery, focusing on CI/CD automation. Well dev, well, SecOps emphasizes stability, risk, and compliance with a focus on monitoring, detection and incident response and production environments. The lack of a cohesive security strategy between these teams is often caused by misaligned goals, fragmented tools, uh, measures that don't overlap.
Uh, this disconnect is further exacerbated by legacy structures, insufficient training, and the slow adoption of integrated security tools. For organizations to truly secure their environments, we need to bring these team together, aligning their tools, data communication strategies under one cohesive security framework. There are a large number of environments where intelligent continuous security becomes and has become, you know, is absolutely essential.
For instance, in large organizations where DevSecOps and SecOps teams operate in silos, AI enables continuous collaboration and coordination, uh, ensuring the security is embedded across both development and production. In cases where software suppliers are separated from their customers, AI assistance security enables continuous threat monitoring, ensuring that software secure even as it integrates with the customer's environment for government, institutions and military applications where sensitive information at stake, AI can manage continuous compliance checks, real time threat detection, security policy enforcement, and network infrastructure, where software manufacturers are disconnected from network system operators. AI ensures that both the software and the network aspects are secured in tandem in industries like finance secure or healthcare critical infrastructure.
You know, where security breaches can have a catastrophic consequence. AI assisted continuous security can provide continuous protection needed to meet regulatory requirements and defend against ever evolving cyber threats. Today, you know, we're facing a new wave of cyber attacks where AI is playing a central role.
Criminals are using AI driven attacks that dramatically and dynamically adapt and approve, improve making their attacks harder to detect and combat. Uh, criminals are using AI driven phishing attacks, for example, that dynamically adapt and approve making them harder to detect polymorphic malware, such as deep blocker uses AI to change its behavior and e evade traditional security measures. We're also seeing the rise of AI generated fake media like DeepFakes, which are being used, or fraud and extortion.
Additionally, ransomware attacks are becoming more sophisticated with AI helping to evade, uh, detection by continuously altering attack patterns. Criminals are also leveraging botnets with AI for command and control operations, making these attacks more coordinated and harder to shut down. Organizations need intelligent continuous security to match these advanced AI based threats and ensure they're well protected.
Uh, recent advances in generative and predictive ai augmented tools and AI assisted workflows facilitate the transformation of security prevention and defense, uh, uh, which previously would've considered too complex and to time consuming to attempt by most organizations. Just to be clear and to put a bow on it, so to speak. Intelligent Continued security is a strategy that leverages AI and automation to enhance the integration of security measures into continuous development, delivery and operations.
This goal is to proactively reduce frequency, impact and response times of security events while continuously improving detection and resolution through data-driven insights and adaptive mechanisms. Uh, this strategy builds on continuous security principles by embedding proactive and intelligence security practices into the entire software lifecycle. It ensures real time adaptability to emerging threats, maintains software integrity and fosters trust through enhanced visibility and automation intelligence con, intelligent continued security goes, you know, way beyond just traditional approaches that rely solely on agile DevSecOps and SecOps by integrating AI driven automation, continuous insights, and proactive security across the entire lifecycle.
While Agile focuses on speed collaboration and reliable software delivery, DevSecOps integrates security into development pipelines to ensure vulnerabilities are detected early, and SecOps defends production and systems responding to threats and ensuring operational security. These frameworks focusing on integration of security incrementally, but still rely heavily on manual intervention, siloed tools and periodic uh, processes. Intelligent continuous security provides end-to-end security coverage by co combining AI driven intelligence automation and real-time monitoring across the entire development, deployment, and production lifecycle.
Focusing on continuous feedback and learning to predict, detect, and mitigate threats proactively and ensures security is not just a separate phase practice, but as always, on an intelligent process. Uh, ai, DevSecOps and SecOps rely on tools for automation, uh, and generally are reactive in their workflows and require manual analysis to act on security results. Intelligent continuous security uses AI and machine learning to identify vulnerabilities faster with predictive analytics, automating threat detection or remediation processes, and prioritizing security risks intelligently based on real-time data and reducing workflows.
A agile DevSecOps and SecOps, um, is shifted, uh, left DevOps in DevOps. It shifted left to address issues earlier in development, but it still focuses on prevention and compliance. SecOps in is inherently reactive, focusing on detecting and responding to threats post-deployment, whereas intelligent continued security shifts security both left and right, ensuring continuous monitoring feedback and action before, during, and after deployment.
In the ICS intelligent continuous security framework, I outline, uh, eight pillars of practice continuous security culture in which we foster a organization-wide mindset where security is a shared responsibility and embedded in every process and decision across the lifecycle. Continuing security awareness and training, providing ongoing education and training to ensure all team members understand and address evolving security threats, security integration in the lifecycle, so seamlessly embedding security practices and tools throughout the development, deployment and operational life cycles. Uh, automated security testing.
So utilizing automated tools and techniques to ensure continuous detection of vulnerabilities and compliance occurs with within security standards, proactive security risk management. So anticipating, evaluating and mitigating potential security risks before the impact systems. Rapid, uh, incident response and develop and execute different response plans to, uh, minimize damage and downtime during security incidents, continuous monitoring and sec, uh, and compliance, maintaining real-time vigilance over systems to ensure security and compliance to regulatory and organizational standards are met.
And finally, security feedback and continuous improvement. Using feedback, uh, loops, uh, to refine security practices and adapt to new challenges proactively. The following specific gaps were identified during a recent assessment, just to, as an example, uh, inconsistent AI usage.
While some teams use machine learning to identify code vulnerabilities, others depended on outdated scanning tools, uh, a lack of unified metrics. Agile developers measure success by sprint velocities. Uh, well SecOps tracked incident response times, leaving, you know, really no shared understanding of the end-to-end security health.
And the third finding was, you know, siloed communication. You know, critical security feedback from SecOps wasn't getting its way back to the agile teams, and this was leading to recurring issues in the code base. So these are some actual examples from a, a recent assessment and for one organization.
Uh, as a result of the evaluation, the team decided to investigate an intelligent continuous security approach to address the following needs. Uh, there's always people, process and, uh, technology concerns. So in the people area, it's all about, you know, addressing cultural concerns of collaboration.
Again, training and awareness pillar we talked about in processes, it's getting unified security integration activities going AI driven automation. So using AI in a smarter way, uh, real time feedback loops, end-to-end visibility where developers and, uh, DevOps engineers, SecOps engineers gain a single source of truth of their integrated dashboards, uh, and technologies. Again, there are many possibilities here.
It's always the case of where do you focus first, but AI enhanced observability tools is a good place to start real time collaboration platforms. Again, things like having a unified dashboard that's used by both development and ops and AI driven testing. Uh, so having common testing tools, or at least being able to, uh, understand each other's testing results is a good idea.
And that was some of the recommendations. Here are some examples of other incidents, you know, uh, demonstrating the necessity of intelligent continued security practices, integrating security testing, monitoring, patching and response times. Uh, you can examine, for example, you know, the solar wind supply chain attack log four J, Equifax, you know, many of these incidents occurred, and when you really look at it due to gaps between DevSecOps and SecOps practices, and in some cases gaps within those practices as well.
Um, in the SolarWinds breach, for example, attackers deployed weaknesses in the software supply chain. If ai, augmented continuous security had been applied, insights from continuous testing and patching could have identified tampering earlier for log four J, you know, AI augmented tools could have flagged vulnerable, vulnerable versions of the library, and automatically patched systems assumed as the vulnerability was disclosed. Uh, the Equifax breach, for example, highlights importance of continuous monitoring.
AI tools could have provided ongoing scans and threat detection that would've alerted teams to the unpatched vulnerability. And all these cases integrated, uh, continuous security, intelligent continuous security would've integrated both DevSecOps and SecOps practices, enabling continuous real-time protection against emerging threats across the entire lifecycle. This is a, a breakdown of of the MoveIt, uh, supply chain ransomware attack that occurred in May 23.
The, uh, ransomware got gang exploited a zero day vulnerability in MoveIt file transfer software to steal sensitive data that costs of this were enormous. Ultimately between 200 and $500 million to some estimates impacts across finance services, education, and governance institution. Uh, um, areas.
The attack highlights the critical need for proactive security measures, uh, as DevSecOps focus on vulnerability protection. While SecOps handles exploit defense, the failure to implement patches and address new vulnerabilities immediately led to widespread disruption. Uh, this case illustrates the importance of continuously monitoring, enhancing security through software lifecycle.
This chart shows how intelligent continuing security could have played a critical role in mitigating the move its supply chain attack. First, with AI driven vulnerability detection, the platform could have identified the SQL injection vulnerability earlier, even before it was exploited AI scans and testing code in real time flagging vulnerabilities and automatically suggesting patches. In this case, rapid patching would've accelerated if AI can orchestrate the deployment of patches across multiple environments simultaneously.
Uh, beyond patching for active threat monitoring, powered by AA would've, uh, provided real time alerts. Allowing the organization to respond to potential threats before they escalate can also enhance the effectiveness of system hardening. And, uh, security chaos experiments could have, um, help with continuous testing security defenses, making them more resilient to attacks.
Uh, in general, continuous security would've reduced response times, mitigated the breach impact and enhanced protection. To successfully implement intelligent continuous security organizations need to focus on a strategic transformation that begins with vision and, uh, goal alignment. This includes setting clear objectives and aligning security goals with business priorities.
Uh, next conducts strategic assessments, which involve discovery surveys, gap assessments, current straight, uh, value stream mapping to, to establish a baseline. From there, a comprehensive strategic plan is developed. The, you know, the plan includes future state value stream map analysis, themes, uh, definition, tool selection, roadmaps, implementation, and, uh, determining what's the appropriate governance and monitoring to ensure accountability throughout the transformation.
In general, the entire process is accelerated by leveraging AI assisted tools to analyze results, provide insights, and guide the implementation by following the strategic blueprint organizations achieve a secure, you know, AI driven future. This slide is a prescription for transformation after a strategic roadmap is established, uh, using the blueprint in the prior slide, uh, the implementation roadmap is divided into four themes. So theme one is usually about preparing your AI platforms test environments and tools includes metrics and workflows that will be used to monitor and track progress.
Theme two, focus on standardization, migrating applications to, to standardized pipelines, farming centers of excellence for continuous security training. Theme three expands the security coverage to include additional applications in the advanced training. And finally, theme four, optimizing security processes by accelerating test creation, excel execution, and analysis.
EASE theme builds on the last one to create a fully optimized and scalable AI security environment. One thing I often find, which is frustrating to me, is people love to jump to theme four without, uh, investing in the earlier ones because they think they know the answer, but in reality, that often causes them to have to backtrack later and end up costing and wasting more time than it would've if it just followed the approach in the first place. Yeah, there are problems with traditional measurement approaches, uh, for SecOps and DevSecOps and SecOps that focuses on shifting security left, integrating security measures into the development of and CI/CD pipelines, ensuring vulnerabilities are caught earlier.
Uh, DevSecOps metrics are primarily inward focused, reporting the results of security scanners and tasks of software that's transiting the CI/CD pipeline. Well, SecOps, on the other hand, is concerned with in production security defense focusing on monitoring and protecting live systems from external threats exploiting exploitations. So despite the concepts of collaboration, you know, that are espoused between dev and ops and SEC teams, in reality, there's often a lack of colla of co correlation between development vulnerabilities and runtime threats and mis missing patterns in complex attack scenarios happen due to the fragmented nature of the data that's being reported.
Instead, you, you know, you really should look at three different types of continuous security insights that are important to help understand not only the progress of a transformation, but the effectiveness of the solution as it transforms and the impact on the business mission. So to understand the progress, um, you know, look at things like the percentage of security checks and CI/CD pipelines and compare vulnerabilities detected pre-production, first post-production, meantime to detect, as well as DevSecOps, SecOps collaboration metrics, things like joint incident response plans. Incident insights are derived from, uh, sorry.
Effectiveness insights are derived from improvements in the meantime to remediate, um, reduction in security incidents, false alerts, compliance and costs, making those things visible across the whole lifecycle. And business mission insights can be things such as downtime due to security breaches and security spending as a percentage of IT budget, uh, to understand the overall effectiveness of your strategy. Uh, these metrics basically are important to understand how AI augmented continuous security improves outcomes and performance of at the business level.
Uh, platform engineering these days is a hot topic, but frankly, it's not really a new concept as far as I can tell. In having been involved in platforms for many, many years. The idea of providing a simple to use portal for stakeholders greatly, uh, simplifies the use of many tools and tech stacks needed for day-to-day tasks.
Certainly that is true for security as well. Uh, platform engineering, specifically around intelligent continuing security brings together automated and AI enhanced capabilities into a centralized environment to manage security across the entire software lifecycle. The platform provides continuous monitoring, automated compliance checks and proactive incident response.
That's an opportunity for platform engineers. One of the greatest advantages here is the scalability. It offers helping your organization stay ahead of emerging threats by enabling real time detection and mitigation.
While aligning development ops and security teams creating more efficient security posture. Intelligent continued security helps close a number of critical gaps that arise from siloed, uh, DevSecOps and SecOps practices. Some of the key gaps include inconsistent or delayed threat detection manual processes that lack automation, fragmented security postures across the development and ops.
These gaps lead to vulnerability, blind spots, misaligned security objectives, and slow response to threats, uh, especially emerging threats. By leveraging ai, we achieve continuous monitoring, real time detection, automation across the lifecycle, ensuring they're no longer, uh, operating in isolation, but integrating and unifying across, uh, the lifecycle. Alright, I think I skipped this line.
Yeah. As we move through AI assisted transformation, it's important to avoid common pitfalls. I'm not gonna read this whole chart, but basically, you know, for example, lack of team alignment can lead to delays.
So it's critical to create shared goals and hold regular cross team security. Standups. Infras sufficient automation is another issue.
Automating security processes such as CSD patch management and incident response is key. Uh, ensuring real-time monitoring is important. Siloed tools, you know, try to align tools better and, you know, try to, uh, really focus on continuous improvement, uh, o over omitting, that is a critical error because there's always gonna be ongoing requirements changes.
Also, it's important to motivate and successfully manage transformations. And no doubt, you know, there's a complex topic and, uh, it's important to educate, align, and motivate people to keep, uh, to get momentum and to keep momentum going. Uh, demonstrating value with clear IRI examples is a good approach.
Developing necessary skills, fostering culture shift towards automation, or just some ideas encouraging innovation with teams, adapting pro, uh, project management processes that support transformations rather than just compliance and strengthened. Vendor partnerships are, are some examples. So as we wrap up, you know, um, there's some advantages of continuous security, intelligent continuous security.
You wanna just summarize with that. First, we see I ai augmented security teams, uh, improving safe deployments and enhancing threat detection across the lifecycle, providing faster and more accurate results, and, um, reducing false positives, providing more efficient vulnerability management and adaptive security automation, which is some examples. Continuing on this, uh, conferences theme of predictions.
You know, if I look further ahead, you know, I believe in a longer term future where security is heading towards what I'm just, uh, penciling as something I call the SEC dev and ops model, where, you know, as we get, uh, more security becomes and AI becomes more integrated into security practices, traditional distinctions between development, security and operations, I think are going to blur faster. Lead times continuous delivery and shift left strategies are already pushing security towards faster deployments. Uh, AI will push this further, enabling predictive threat analytics, autonomous security measures, and AI auto augmented decision making with advances like feature flag rollouts and no shift deployment models.
You know, smart automation will allow us to secure systems with minimal human intervention. So it's an exciting feature where security becomes part of the fabric of all operations. So my last slide, if you wanna learn more about intelligent continuous security, continuous testing, quality engineering, DevSecOps, SRE, I encourage you to get a copy of my new book.
And again, if you're attending this talk, uh, send me an email, I'll send you an e e-version. com. Thank you for your attention.
I appreciate it. I hope you have a good conference for the rest of the talks. Thank you.
Hi, everybody, and happy new year. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jodi Ashley, executive producer here at techron, and I'm here with my co-host Tracy Ragan, creator and CEO of Deploy hub, and very busy lady when working with the Linux Foundation.
I'm sure it'll come up today. Before I introduce today's guest, I wanna give you a quick update about what's happening here at Textron. com, so be sure to go and check that out.
We have a lot of virtual events happening, uh, predict 2025 is coming up. If this airs after that, you can go out and watch it on demand, and I would recommend it. It's gonna be an awesome virtual event, so you wanna be sure and check it out.
com, and be sure to tune in every day to Techstrong TV for great shows and interviews. Okay, Tracy, it's 2025. What's on your mind today?
So, over the Christmas holiday, I, I, you know, I, it didn't do a whole lot, but I would still watch kind of news coming across, particularly around cybersecurity and Space Force because it's something that I'm particularly interested in right now. And this, this article came across about the DOD and, um, you know, tackling Weapons Cybersecurity, and it talk, it talked about, you know, that there's work that's being done to address cyber threats all the way down to like code level. But something in that really bothered me and it said, let me see if I can, I'm looking at the quote.
Um, basically it said that they know that there are, uh, vulnerabilities out there, but they're willing to take the risk not to address them. Um, I'm not sure why that would be the case. I don't understand it, uh, because it bothers me that we can do better.
And even in weapons security, I, I, I feel like there is a lack of real understanding what these vulnerabilities are across the whole spectrum of cyber security. So to just say, you know, the, the risk is there, we understand it, but we're gonna move forward anyway, um, is kind of a bother. It kind of reminds me of the recent fires in, uh, California, that area, Pacific Palisades that they've been, they've known for quite some time that it's a high risk area for, uh, flooding and fires.
Uh, but we did, how much did they do to, to, to make sure it something as catastrophic as a firestorm didn't happen, or how, how prepared were they? So I feel like we've gotten into a, a place, maybe this happened in 2024 or maybe it's always happened that we're complacent when it comes to, um, predictions, right? Predictions about what could happen in weapons cybersecurity and saying, we can take the risk even though we don't know completely what we're talking about, we're okay with taking the risk, or is there something more we could do with protecting something like the Pacific Palisades from Firestorm?
So it, it bothers me, and as, as we go into 2025 with Gartner predicting a tripling of vulnerabilities, I feel like we've just been bombarded so much with these kinds of threats that we're just n we're numb to it. So that's my concern for 2025, and I, I feel like it's a discussion that should be had within all organizations right now about how proactive we need to be. Yeah, I can imagine reading that drove you bonkers.
It was kind of shocking, right? It was like, yeah, something like Space Force sa something like Space Force, you know, that a general would say, you know, I accept the risk without any clue of what they're, what I'm actually accepting. I'm just gonna move forward.
God knows what's gonna happen in 10 days. Well, the people who are attacking us are not that complacent. They're on their toes, right?
Yeah. So we have a formidable, uh, uh, component, uh, component opponent out there that we need to be serious about. Yeah.
But we have an incoming president who wants to change his mind again and move Space Force to the state of one of his cronies. Like he, before, before the last election, he was moving it to Alabama and then Biden said, no, it's staying in Colorado. Which obviously I pay a lot of attention to living here.
And now he's talking about moving it again. So let's not focus on the secure side, let's focus on moving it and wasting a ton of tax dollars in the process. But that's a whole nother conversation.
Yes, it is. All right. Well we have a really cool guest today.
I would like you to introduce you to Sal Kimmich. Is K Kimmi or Kimmi? They're both good.
They're both Good. Want say, I like to say it right though, so well welcome and tell us a little bit about yourself. Yeah, actually, um, it's probably, I'd love to dive into a little bit the commentary on the DOD.
Um, so I have a pretty unique background in and with open source in that throughout my career I have inhabited almost every profile of an end consumer that you can imagine. So I have been an consumer in a federally funded program between both the US and the uk. I have been a machine learning engineer working within the DOD.
So my first contracting role in DC was with the Missile Defense Agency. And then I moved to go work with the US Air Force, their Kessel run software incubator. I then only left security clearance because I got married and moved to the uk and I did ask, can I work remotely for this skiff in a foreign country?
And they said, no, obviously not. We read the contract, you know how this works. Um, so I jumped into for the first time the corporate layer of open source, uh, which is generally what most people get exposure to if they're using advertising or marketing to understand it.
That's the only layer that they'll ever experience. But it's really, really important and we probably should dive into why they would accept vulnerabilities, um, in the DOD specifically, uh, because it's changed a lot in the last five years. And I think that's really positive the ways that it's changed.
Um, so if you are an end consumer of open source as a federal developer, there's a couple of really interesting things. So number one, you're never going to upstream. If you upstream once onto the thing that you were consuming in the last couple of years, you would not just immediately lose your job, you would lose your security clearance, you would never have a career again, right?
And it's not one or 3% of open source consumption that is specifically in this case, federal. We're not just talking about the larger and global government consumption. That's a different number.
And that varies particularly by the European country that you're dealing with. And they've got government style OPOs in order to be able to engage with it. But I had someone come up to me at a conference earlier this year, it was someone really early in the career, and they did ask me this question, what percentage of open source consumption do you think is federal?
And I was sitting at a table with a color, couple of other open source leaders and I said, Ooh, it's literally impossible to know that answer given the design of the system. But I would estimate somewhere between 30 and 35%. And then the only reason why I'm willing to say that publicly as something slightly more than a conjecture, even though that's all it is, there's no stats.
I then turned to someone who works in a major corporation that I know has not just a general osbo, but a specific federal osbo. And they did not speak a word, but they did give me odd and a shrug as if that is about correct. Right?
So for every two of the developers that developers that you're thinking about consuming it and upstreaming to open source, generally, there's one that is consuming that information and has to have alternative pathways of communication, mainly regulation, in order to make sure that those things are secure. And I think this is really, really interesting when it comes to security vulnerabilities of the supply chain. So the first job that I ever took coming out of security clearance consumption and coming into the open and general corporate layer of production and open source was specifically sonotype.
I did that because I think that they have a really, really interesting and pretty direct approach and engagement. They are really focusing on making sure that they can secure that supply chain or that end consumer class. Now, I think in order to not be so afraid of vulnerabilities as they exist on the internet and on platforms like GitHub and GitLab, you have to understand that all of these things are built over kernels.
And there are many different kernels. I've mostly studied and investigated the Linux kernel. There are other kernels as well.
And even the Linux kernel is not a single kernel. There's about seven of them that are really, really important. There's three of them.
There's like the main line, the main kernel, which most people generally use. And then there's a long-term kernel of which they're very, very sincere in making sure that no vulnerabilities come into place. And then number three, when you're dealing with vulnerabilities and open source, you have to become extremely familiar with understanding the zero day marketplace.
So when there is a critical vulnerability that has been observed and been highlighted in the days and sometimes weeks before, a zero day, a zero day just literally means you have zero days to patch zero days. That's what it means. It is bad, it's immediate, and it's pervasive.
Um, and so when you received a zero day vulnerability, you have to understand that all of the work has already been done to secure the critical infrastructures that you depend on. Now, this is not just the DOD, the zero days and the work done before the zero day hits. Public and corporate are protecting things like major cities, water filtration systems, those largely run on things like Kubernetes these days.
So I think that's really interesting to dive into and to to consider. It's a very different world of open source. Um, but it's increasingly important.
And the nature and the style of leadership within the DOD has changed. This is not so much due to the leadership in the executive branch. They are separate, but it has changed because of one very, very specific condition.
Uh, this is the fact that generally, depending on the country that you're dealing with, it takes exactly four days of unlimited assault onto a foreign territory before you go into a condition of what is defined as protracted war. When you're in protracted war, you begin to engage in a very, very different series of process, specifically in the chains of command within DOD, so that you can be highly responsive to it. So that's had an impact on the way that open source interplays with it.
But also there's no difference in the actual nature of playing with the human gen like Titis that is open source. You have to use it because it is where the progress is made. You have to use the intelligence of the commons in order to get the right answer.
And then you have to set up additional processes to make sure that is maintained as secure. Um, so I, I really enjoy watching that space. And I also really now getting to watch it from afar.
'cause I'm absolutely just engaging in the corporate layer. Um, which doesn't typically have this kind of insight once you're in security clearance, unless you lead the country, you're probably gonna be in security clearance the rest of your career. But in the, uh, Gartner, uh, report, I, uh, I only read snippets from it, it said that 58% of they said that code level vulnerabilities would probably triple with about 58% going after government and cyber infrastructure, right?
Are, you know, our utilities, our, uh, healthcare, the, the, the infrastructure, the technical infrastructure that we depend upon, that's where those vulnerabilities will be targeting. Um, and I, you know, I, it would be a curious thing to be able to get an SBO m from every single one of those cyber, uh, kind of infrastructure teams on the code they're delivering and look to see exactly what's what, what open source packages they're consuming, because those you would think would be the most then critical ones that we should be monitoring. You know, and at least minimum require for those teams to have an open SSF scorecard, right?
At minimum to show that they have some commitment to adhering to security policies. So it's a, it's a, it's an interesting topic and I think that, um, there's part of us, and I'm reading this really interesting book, book called Sapiens and it talks about how we um, as our brain kind of developed what drives us. It's a weird one, is gossip and fiction and it has for thousands and thousands of years.
Sounds about right. I know. And we will believe anything we choose to believe, right?
So it's easy to say, that will never happen to me. It's easy to say, I can excuse those risks 'cause I don't believe it will ever happen because we wanna believe in fiction and if somebody tells us we're okay, even though we may know the data shows differently, we're gonna believe what we want to believe. Really interesting right now.
Now Sal, you have a PhD? Uh, yes. Interesting story.
I don't, but I can explain why. So, um, so I, most of my undergraduate training was funded by, uh, the National Institutes of Health. And it included both a total consumption of my cost.
So it included everything down to my rent and my healthcare. And then I was immediately positioned to do an accelerated PhD between the US and the United Kingdom, specifically working on real-time signal processing, um, for medical interventions for the human brain. So I have this great and interesting background and one quick note there, if you can get one of these unlimited, uh, government funded undergraduate degrees.
I went and I checked the contract that I was signing and it said, we will pay for all of the classes that you need to complete your degree. And I said, wait, is this limited or is this unlimited? And I found out it was unlimited.
So I in fact left my undergrad with two majors and two minors because I didn't have to pay for them. I could just pursue it as true education, much more European style. So I got a degree in cognitive science with a focus on neuroscience where I was doing all of my statistical work.
And I got another degree in political science with a focus on public law. I really enjoy. And I find it very interesting to look at history from the perspective of codified law because it gives you much more information about who is in power, how is that power titrated and how is it maintained or lost.
You can do that by analyzing law much better than you can by sociology. Um, but then I jumped into this accelerated PhD, so it was a three year minimum. I already had a first author paper route and if you wanna look at anything from my security clearance or my academic background, just don't search sal, search Sarah, SARA.
I go by Sal because I asked mechanical Turk what three letter moniker was easiest to remember and signaled authority. And then I used that in order to enter open source quite literally. And when I, when I look at gender and pronoun dynamics, I really, myself, personally don't care.
Any pronoun said to me with respect will be treated with respect. However, generally if it's in writing, I'm going to prefer they them because I don't want to be indexed into a specific profile that could have a bias in an algorithm. And 100% of the time, if I'm pursuing a promotion, I will request that we use he him pronouns.
Not so much because I believe there's gonna be any bias from individuals that have previously worked with me. But because it's very likely that there's an internal system that is relying on an algorithm that probably does have bias. So let me just bias it in the right direction for myself.
But here's why I don't have a PhD. It's a great story and it comes from a very good mentor. So I had two different mentors.
I had one at the signal processing lab at the National Institutes of Mental Health in dc technically Maryland. Um, and then I had another mentor who is the head of the art and sciences, uh, section of the University College London, who was generally just there for life advice. And uh, I had put together a online course that taught about a thousand people how to, uh, put together a machine learning pipeline specifically for brain imaging.
And if they completed that and they did a peer review style, uh, or prepared for peer review style paper, then I got AWS open source to fund the credits for them to be able to complete it. I got that done, I put that out online and I immediately started getting inbound requests for jobs. I turned most of them down 'cause I didn't find them interesting.
But there was one job that sounded very interesting because for about four months, the CEO just kept on calling me up and we would have discussions about potentially what I would do if I went into security clearance. 'cause I was not interested and I had to be convinced. Um, the CEO was also previously a, uh, a, uh, fighter jet pilot.
So very interesting because they were leading based on the profile that is impacted by the end consumption of open source, right? Very serious. They know that if they get this wrong, right, if we mess up this vulnerability chain that will result in a death, right?
So sincere and that kind of leadership style is much more available in systems outside of the corporate space. Um, and I always look for it, but the reason why I don't have a PhD is because my advisor on the UCL side, I said, okay, unfortunately I really do think there is a job here that I am inspired by and would really like to do. And he said, Hmm, how much money are they offering you?
And I said, this much money. And he said, oh, okay. If money matters to you, I need you to know that that's more money than I'm making right now.
I said, I, I think that matters to me. And then he said, okay, you know what? Go do this.
Go do this for a year, 365 days from when we stand down your PhD research. I want you to send me an email and let me know if you wanna come back and finish. And uh, I remember the day, 'cause there were moments in and out of my first year of getting involved and stood up in federal software production where I didn't know if it was the right fit for me.
And uh, but it happened to be that on day 365, I was working remotely in Barcelona that week. So I wasn't producing code that week. I was just attending internal meetings.
You cannot produce code outside of a skiff. But I was doing a like semi vacation working on a beach in a foreign country. And I thought to myself, I can do this while making more money than I would make in literally the highest leadership position that I could ever possibly get into in open, in, uh, in academia.
Uh, so yeah, it's just because money mattered to me and because I had been able to raise the signal on all the things that are important to a corporate producer or to a security clearance producer. Can you demonstrate that you can do the work? Yes.
I already had a first author paper out, so I didn't really need to wait. I had already gotten it done. And then number three, can you excellently communicate and propagate not just your understanding of the topic, but the ability to actually do the topic to other people.
Now if you have those three things, it makes it very easy to get a very, very good and interesting job because there are so few people with that combination of skill. And um, yeah, sometimes I fantasize about going back to academia, but I just cannot pull myself to do it. 'cause it used to be that I had to be in academia 'cause I needed access to supercomputers.
And I really particularly love the supercomputer at NIH because if you work in this space, high performance computing of any type, you know, that our clusters are called, uh, bale wolf clusters, but not at NIH. We named them bio wolf clusters. And I'm very get overthinking that.
I I just love that. Um, but, uh, you've Had a very interesting journey then into employment as a woman in tech. You know, it is so many avenues and I don't think we've heard this avenue before.
You know, that you yes. You basically did a and the, um, the idea of getting, basically getting your education covered. Mm-hmm.
That's amazing. How, so how did you find out about that? Did, did you just stumble across it or did somebody point you in the right direction?
Yeah, well I had very sincere financial need. Um, so I was looking for the best opportunity out there. And I got involved in research the second that I got to school, quite literally the first quarter of my first year as an undergraduate, I went to uc, San Diego.
And uh, there was a professor there that was doing research on the cognitive design of cockpits for Boeing. And I myself am a pilot. That's why I'm always interested in having a portfolio that keeps leaning into aviation.
Um, but uh, they had shown us some transcripts that I just knew could not be correct 'cause you have to use alpha numerical when you're talking to a, uh, a control center. And I said, Hey, I think I can just correct these for you. Um, and that was how I got involved my first year, my first week of undergrad in research.
So it really, and and, and this is true. So when I, you have to be so sincere about research itself. All of the classes that you ever take at any university that you ever take, you will never be better than everyone else in the room.
And there's already gonna be 30 of you or 300 of you. But when you're pursuing research, you have the ability to see if there is knowledge that needs to be redu produced, go and pursue that knowledge and then share that knowledge as widely as possible. So the first study that I was ever published on was on, uh, cockpit design of Boeing seven 30 sevens.
And to this day, in my own consulting work, I use that all the time. I typically go and I'll speak to like mid-sized banks or something that has a critical service to it. And I simply explain to them this, you now exist in a world where you had site reliability engineering and you understood that that was real time.
But as we think about cybersecurity and the conditions that we have been growing into, cybersecurity is now a real time event. It has to be acknowledged in real time. It has to be patched and as near to real time as possible.
So I go in and I will teach them to use their dashboards like a cockpit combining both SRE and cybersecurity whenever possible. But here's the second layer of that, that's really important, especially if you're paying attention to say the Cyber Resilience Act right now. Um, there's something different about aviation than software and I think these are going to converge.
We're going to create a thing like a com, like a compliance crab. It's all gonna look the same at the end of the day as this evolves. So if you are in a commercial aircraft, you're gonna have a black box.
If the thing fails, there is going to be a perfectly preserved audit log that should allow them to understand exactly what went wrong. That is essentially the ask of the CRA. They need you to have a verifiable and reproducible audit log of your cybersecurity methods and operations.
And you should make that as automated as possible and work it into your operational design. Um, and I'm super excited to see that. 'cause I think that's really important work.
And when I look at the way that compliance and regulation are evolving for software generally for open source to some degree specifically, but generally in the sector, I do think it's really appropriate to go look at the past 50 to 60 years of aviation compliance and understand how similar those things begin to look. I could not agree more. You just just described what we've been doing at our and Deploy hub.
We used to call ourself the black box of software because the problem is is that the, the, the pipeline itself for every c when we were doing monolithic, we, this argument of didn't hold as much water because everything you did in the pipeline related to that one software solution that you were delivering to end users in one big monolithic ball, right? So you could have a black box, you could see, you knew where, at least where the logs were. But when we're fragmented with hundreds of microservices that make up a single application, that black box is a hundred black boxes that it, nothing is, nothing is centralized.
And you don't know if they're all, um, living by the same security compliance. You don't, you have, it's very hard to see that. So centralizing this kind of data in, in the way you just described should be applied to every piece of software that we, we push out the door so we have a full view of it.
And it has to be versioned. It can, it's not just for the application at the time that it's executing, it's over. It's the history that gives us the insights.
It's the change, right? It's the change that shows what went wrong. Mm-hmm.
Um, so yeah, there's so much to be done in, in software for this discussion. We recently, this continuous delivery foundation, of course I'm pushing it recently started a new SIG called the CI/CD Cybersecurity sig that we're really gonna look at models because pro, part of the problem of building that black box is that DevOps engineers don't necessarily have time to go figure out what they need to add to every single workflow. And this is going to be a manual effort to build that black box.
We gotta make it easy. We gotta make a, a model that people can say, here's a an example plugin that I can use. Here's an example command line interface that I can use to generate SBOM for god's sakes.
Something as simple as that. So I'm glad that you bring that up because it is incredibly important for software as we move forward. Now I wanna talk about your background.
You said you were in Barcelona, but now you are in Italy. Tell us what you're doing in Italy with uh, awarding open source. Okay, well first off, I think I do a lot of personal travel now because when I was on government funding as an undergraduate, the one thing they would not let you do is study abroad.
They'd let you go study at MIT in the summer, but not abroad. And I wanted to see the world. Um, so, uh, for the last three months I have been here in Kunio, Italy, which is not a well-known place, it's not a very large town.
It sits on a wedge in the Alps. Uh, and it's extremely protected traditionally from uh, like land attacks. Um, so I came here 'cause I was really interested in this place, which is well-known to people that study sovereignty as a physical location where this city itself has remained sovereign to both political influence and religious institutional influence, which is very unique to Italy.
Um, and to kind of just observe that and understand that. So I'm here 'cause I'm doing my own midlife study abroad, but, um, I'll point you right up to the ceiling real quick because you should be able to see it is beautiful masterpiece. Absolutely.
I Know, I thought she was sitting in the Sistine Chapel for a minute when she, when she logged in. I'm like, oh no, that's actually a real room. Yeah.
But, uh, that was commissioned by the family, the body family and the 17 hundreds. That's their crest right behind me. Um, and uh, I came here specifically because, you know, I've, I've got insight into the government layer, government consumption layer.
I've been working in the corporate consumption layer. Um, but there's something that everybody forgets and it's that open source is also just incredibly fun. Um, when you look at vulnerability, sustainability, maintainability, you have to recognize that these are all building blocks and some of them are created specifically to be supporting critical infrastructures.
Those are well protected. Those are well maintained. They'll be sitting in something like an antitrust.
But there's a lot of one-offs, really interesting things that are produced in open source that aren't meant to have a general audience. And if they are, it's a very small audience. So we're doing a series of awards.
I'm working with Art Farrow on this and I'm waiting for whatever his videos come out to be. 'cause I said the one thing I'm not is creative. You do that part.
But, um, we're doing a series of awards based on every single Greek muse and we're gonna go find the open source, either project or committed commit, uh, community, um, that really aligns to those values. Are you working in science? Are you working in art or music or in historical preservation?
Um, if you're doing something like that in open source, I think it's really important to remember that that whole world still exists. And then to also understand this, um, it's very, very true that there's an absolute alternative to burning out in anything. And you can call it something very simple, just call it burning in.
Like stop paying attention to your retention statistics at a corporation. Pay attention, right? If they're about loss, really pay attention to what is it that you're doing when you're doing it right.
Um, and one of those things is allowing people to have and to develop their passions with technology. So I'm using this opportunity as a time to help to highlight people that are genuinely showing something that is so passionate that I find it interesting and inspiring and worth sharing. I have one last question before, 'cause I know we're gonna run outta time, but I really have to get this question out because if there is somebody who's watching this who is an undergrad, which I hope they are, how did you find your research project and was that a government grant that the, uh, uc, San Diego was involved in?
Yeah, so I, I mean honestly I started applying for funding in my first year. Whatever I could find, like, is there an associate, so You yourself were looking when you were applying for funding, where were you applying to? So I started at the institution and then I started looking, uh, specifically into my, uh, degree program.
And I started going and getting the professional level education that you need and pursuing external organizations. So two things that really helped there. I was working with the cognitive science department and they had a bursary that was available exclusively to graduate students to support their research with training.
Okay. It's not exclusive if you go and ask. So I went in and I got some funding to be able to pursue independent training.
That's how I got connected originally with the Martino Center outside of, uh, or in Boston. And the, uh, like brain, uh, and Cognition Institute from MIT. Um, so I went and I pursued education that was at one level higher than what was expected for me at my level because why would you wait to get it done?
And then number two, I just break through whenever I see an arbitrary gate being kept closed and I will ask the questions, what are the conditions by which I can open this gate and I will ask it to the person who has the door locked. Um, one of those conditions was very important to me. Uh, so I really wanted to join the association for the Scientific Study of Consciousness because I was studying real time interventions using FMRI brain imaging.
Um, and I was told at the time that, that's great. We'd love for you to participate in our student committee, but that's for graduate students. Now, one year later, I show up to the same person who helped me in my PhD as well.
I show up to the same person who had that door locked and I said, hello, I am still an undergraduate. I have full funding, not just for myself, but for my research. Does that satisfy the condition of being a serious researcher in this space?
They said, yes. They let me join. I was immediately working with the professionals in that field.
Um, so go and look at gates, see if they're actually closed, see if you can get them open and if they are closed, make the conditions discreet, get them in writing and see if you can fulfill them. When you're fulfilling those conditions, great, you're done. You're set.
Now there is another thing that's really important. I pursued biomedical research. So in order to do that with human subjects particularly, you have to be working under something that is called an IRB form.
So the in Institutional Review board, um, I have occurred of many undergraduates old in one of those themselves under their name. But I was pursuing independent research. I was creating my own research designs and then using the funding to get the data done and then to produce those methods.
Um, and that worked. I just didn't tell myself that any of those were conditions just because they're arbitrary and they exist to satisfy a societal expectation of when you'll be ready to produce intellectual property. And if you're pursuing open source, you're ready already.
It's why you're here. Um, but one thing's really important because it's mentorship and I know the best mentor that I ever had in life was Dr. Lisa ier.
Uh, uh, Dr. Lisa Eiler, uh, from the VA hospital in San Diego. And I remember going to her early on and I was shopping around and asking every single lab that I went to, do you think I can get a first author paper done as an undergraduate?
And I had some people actually laugh in my face when I said, that doesn't matter to me. That's just a closed door. I'll knock on the next one.
But I went into her office and she said like five words to me that were so powerful 'cause I had never heard them before. I've been well supported, well coached my whole life, but no one had ever just said about something I wanted to do. You can and I'll help you.
So simple. But that's not something that women here, women versus men are much more likely statistically to hear a no when making requests around funding, when making requests around promotions, all of these things. Um, and she just recognized something burning in me, the fact that I was really burning into consciousness studies and to modeling and interacting with consciousness as a computational design.
Um, and she fully, fully supported me. And I will always be grateful for that. And it's something that I make sure to say explicitly to anyone that I am mentoring, find out exactly what it is that they wanna do in life, see if I can support it.
And then I do everything in my power to do that. Sincerely, You can and I can help you. Those are very, very powerful words, right?
Mm-hmm. That's amazing. Absolutely amazing.
It, you know, we hear, uh, the journey of women all the time and mentorship is always at the core of very successful. Absolutely. Mm-hmm.
That's what we hear. And it's not just mentorship from other women, it's mentorship from men as well. Mm-hmm.
Yes. Mm-hmm. Yes, absolutely.
Men are part of the solution. They are so much part of the solution. Yeah.
They're also part of the problem, but that's it. Yes. Yeah.
Yes they are. And I don't know how much time we have. Yeah, we're pretty much there.
You ladies. Um, can we just ask a question? Yes.
You ask your question. Recommendation. What is a book recommendation?
Tracy always have recommendation. Uh, so there's two books that are super important. Um, actually I have one of them sitting right over there.
It's, uh, cybersecurity for Generative Systems. It's very good. Um, another book that you should read if you're really interested in understanding the state of cybersecurity is, uh, the Cyber Deception book.
So there's a Cyber Deception 1 0 1 book. It comes out for, um, FinTech services, uh, about every two years. And it basically explains how you create honeypots and artificial systems in order to observe Adversarials attempting to get into your system without letting them do it.
Um, that still is incredibly important work, and it's one of the most evolving areas of cybersecurity because now it's just agent on agent artificial intelligence. Um, but I do wanna jump back to one thing that I think is really important to consider and think about, especially at the corporate layer for vulnerability, uh, analysis and awareness generally. There's two approaches to it that we can take.
One of them is the one that most people are currently taking. And it's basically doing a scan semantic analysis and identifying either the vulnerable project or the vulnerable code snip, uh, that's incredibly computationally expensive. And it may also encourage people to be pursuing a vector of comp of compound vulnerabilities always remind people that log four J in itself was not a vulnerability.
It was a compound vulnerability when in place with JNDI that made it harder to catch for a while. Um, but there's another approach to this that is entirely different and it is using category theory in order to find those conditions. So applied category theory is a way to begin analyzing vulnerability.
Uh, and it would allow you to find categorical conditions and to avoid not just a single code snippet, but to actually be able to see, and when I say categorically, it means we have set condition, A feeds to set condition B feeds to set condition C. We now know exactly how many projects have that logical, substantial backend, and we can remove that vulnerability. Whether or not it looks the same, we can remove that logical compound across languages, across semantic complexity.
That's a direction that we absolutely have to go into. And it's not something that is a far out there idea. There are some r and d spaces that are looking into this.
And you must understand very importantly that this is an idea that particularly the US pays attention to NIST organizational design, all of the things that it gives down for us to be compliant to are, and to be a CT compliant. So if you're interested in this space and you wanna understand and start thinking about it, then go to the top of the supply chain. Well, mental chain of understanding.
Can we categorically provide the best solution possible? We're gonna do that with applied category theory. It then comes down, it gets right now interpreted into a semantic language that we're communicating out.
And that's where there's a lot of lossiness in communication 'cause it's human to human communication. But if in the next 10 years or so, and I always say apply category theory is the answer to everything, we just haven't found it yet. And that is so true.
Um, but if we can close that gap, uh, we're gonna be able to avoid those conditions, not just in the current reality of production, but also moving into a quantum compute reality where they also will be able to have a much more efficient way of scanning if they're doing it as an adversarial. So we want to make sure to categorically remove those logical conditions moving forward. And that I think is the most interesting area of cybersecurity right now.
Well, thank you so much. Um, that's a great place for us to wrap today and we really appreciate you being here. Tracy, you got anything else before we wrap this?
I'm just glad she mentioned Quantum. Yeah, I know you're into that too. Alright, well thank you so much for being with us today, Sal.
And thanks to our audience for joining us for another, um, fun filled and very technical episode of Up Techstrong Women. Um, we're excited you were here and as I said, keep watching Techstrong tv. There's a lot of a lot more shows to watch today, so stay with us.
Thanks again. Have a good day. Hey everyone, this is Alan Shimel for Techstrong and you are watching another edition of CD pipelines.
Ed Pipeline is a, uh, monthly video series put on by us here at Techstrong in partnership with our friends at the Continuous Delivery Foundation, the CDF. And, uh, we're gonna tell you a little bit about the CDF in just a moment. So if you're not familiar with it, not to worry we'll get you familiar with it.
But basically we every month pick another topic of interest to those in the world of continuous delivery, CI/CD, DevOps, and, um, explore it a bit. We've looked at the various projects that are under the CD f umbrella that they manage and own. Uh, we've looked at trends in the market and how some of the mega trends are affecting cd, just about anything that that touches on cd.
Uh, we unfortunately, I, you know, taping a recording, no one tapes anything anymore. Who am I kidding recording this? Uh, right after, uh, AWS re event last week.
We've lost a person or two from our panel. Uh, so as we call it the AWS Reinfect kind of syndrome where people get sick. So our co-host, Lori Larussa, is, is not available to us today.
She is under the weather as is we think the DC sonika, who actually happens to also be the chairperson, uh, for the CDF. So we hope both of them are feeling better and we'll have them on at our next CD pipeline show. But the show must go on as some famous someone said at one point.
So let let us March on. Let me introduce you to our, uh, panel members today. First of all, uh, well joining us, he's the open source advocate at IBM, Andrea Fritolli.
Friley Friley, not Fri Friley. Oh, is that Andrea? Welcome.
And I, I said you were an open source advocate at IBM, but maybe you could add some more color to that for us. Thanks, Alan. It's great to be here.
Yeah. So I work at IBMA software engineer and developer advocate. I focus on open source and as part of my open source, um, job and work that I do, uh, I serve, uh, for the Continuous Delivery Foundation for the CDF as chair of the Technical Oversight Committee.
And I'm a, as well a member of the governing board. And, but I'm a software engineer, uh, and I'm involved in maintaining some of the projects within the CDF and I co-founded the C events project that we're talking about today. Wonderful.
And thank you. Thank you for what you do, you volunteering as well. Next I want to introduce you to Gerard McMahon.
I messed that up, but Gerard correct me please. Uh, so it's Gerard McMahon, as we say over here in our end. And Yes, Gerard McMahon.
Gerard, why don't you introduce yourself. Thank you, Alan. Um, so my name is German McMahan.
I work for Fidelity Investments and I'm part of the CDF governing board at representing the end user members. Um, my role here in Fidelity is heading up what we call a LM Tools and Platforms. So providing the tools, the platforms, and the services for all of our developers at Fidelity to, to, you know, to build their code, write their code, build their code, test their code, and deploy their code to our customers.
Okay. Thank you and welcome Gerard. Uh, last but certainly not least is Ben Powell.
Hey, Ben, how are you? Good. Doing good.
How about you, Alan? Very well, thank you. Ben.
Why don't you introduce yourself? Cool. Yeah, so I am a software engineer at Apple.
Uh, so I work primarily on continuous delivery tools. Uh, prior to that I was actually at AWS, uh, speaking of reinvent, um, I was on the SDKs and tools, uh, team and then eventually ECS. So a lot of experience, uh, in that regard.
Um, so I am a maintainer of the CD events, uh, org and repos as well. So I help kind of facilitate, uh, the spec as well as, um, uh, sig lead for the implementation sake, a part of CD events. Excellent.
All right. Um, so guys, I, I feel it necessary for people who maybe are catching this show CD pipeline for the first time. We've been doing CD pipeline for more than a year, maybe going on two, but for people who are familiar with the Continuous Delivery Foundation or the CD Foundation as sometimes we refer to it, or CDF, which seems to be the new, the preferred nomenclature these days, right?
The CDF is a, I call it a daughter foundation of the Linux Foundation. So it's under the Linux Foundation umbrella, and it is, it was set up specifically to focus in on the continuous delivery market and, and it, uh, community and, uh, you know, perhaps its biggest job is managing, you know, I think is it eight or nine projects that have been donated, given to fostered under the, uh, CDF umbrella among, which is the CD events project that we're gonna talk about today, but also some, some kind of household names in the tech world. Jenkins for one, um, oh, I'm drawing a blank.
My goodness. Netflix, Google sticker, Spinnaker for two. Um, who you are all board members here?
What, what are the other projects under the CDF umbrella? Well, we have project like Screwdriver, uh, for instance. Yeah.
And Jenkins and Vinegar that you mentioned. We have tacton, uh mm-hmm. Um, yeah, the city events protest.
Um, what else? We have, uh, Jenkins Sachs. Yeah.
Um, Which is also GitHubs in the GitHubs area. Uh, yeah. Yeah.
Excellent. I mean, it's, um, you know, and, and our audience is DevOps and cloud native folks and cybersecurity, and so these are kind of very well known projects and tools to, to the audience. Um, again, before we start, I should also mention that the, uh, CDF recently announced their annual conference, which is coming up, actually, Gerard, do you maybe have some of the, uh, particulars on that one?
Yeah, so CD Khan has been running as a kind of Precon micro conference as part of the Open source summit in, um, north America. So this year it'll be on, in June in Denver on the 23rd to the 25th. So we look forward Excellent to come or participate.
I think there was a call for speakers open at this point, isn't there? Yes. org?
So it's CD Foundation. CD do foundation. Excuse me.
Yep. Excellent. Just wanted to get that out there.
All righty, folks. If it's okay, then let's turn to our topic at hand today, which is to get people aware and familiar with, uh, a project under the CDF umbrella called CD Events Project. Andrea, you mentioned you were one of the co-founders of this, so if it's okay, I'd like to start it off with you and give us kind of the background.
What is CD events, what kind of drove you to wanting to, you know, make this project? And we could go from there, Right? Um, yeah, thanks, Alan.
Um, so, um, I mean, we, we started in the, of course, the, in the continuous delivery landscape, but more generally, uh, what we call the software factory. So looking at, you know, the, the software, how it's built, starting from source all the way to, to production. Um, and there we, we have a number of tools that are involved in these.
Um, you have your CD tools, your CI tools, your, uh, software management, uh, systems, your deployment system, and so forth. Um, and there are several options for all these tools, and a lot of them are hosted by, by the CDF as we discussed before, but others are also hosted by other foundation. Um, but, uh, what we notice is that there is a lot of fragmentation in how these tools are set up in the data models they use and how they, they talk to each other.
And so, um, the CDF project, we created it basically to try and address this, this fragmentation and bring interoperability in this space, right? So we want to, um, make it possible for this, uh, tools to, to talk to each other, to generate data that can be processed, uh, seamlessly across the different tools and, you know, make it easier for organization that use many of these tools to not have to reinvent the wheels and, you know, integrate them these tools with each other or, um, in-house all the time. So, but yeah, mainly we want to bring interoperability in this space, and that's how city events was, was more, and City Event itself as a project is, it's a specification.
Um, so it basically defines, um, formats for events that can be produced and consumed by, by tools in this space. And expand a little bit to kinda give it a little bit more of a, some concreteness like, uh, imagine you have like your whole, let's say you're a company and you have your whole SDLC, which is software development lifecycle, um, architecture, you know, you have all these services and tools running, and let's say you want to actually add or even switch out a tool to do that today, it's very, very difficult. You're gonna spend, you know, months, maybe even years, just trying to get to that place where you are at, to just deploy that software again, at the same, same level, or same criteria.
So with the Goal CD events, as, as Andrea has had alluded to, is, is interoperability. So your your, our goal is to be able to just be able to pick up pieces and just put new pieces in very easily and transparently. Absolutely.
So, but when we say it's a spec, I don't wanna lessen what CD events project is, right? It's, it's, it's more than a spec. Is that fair to say?
Um, yeah, absolutely. I mean, the project started with a specification, uh, but we went on to implement a number of SDKs or software development kits that can be used by the different tools to make it easy to, you know, consume the events or produce them, validate them, and so forth. And, uh, more recently the, the project expanded even further, uh, through one of the, um, working groups that May Ben mentioned earlier, that is sharing that, uh, it's the implementation working group, because of course it's nice to, to have a specification, but, you know, we want to actually provide guidance, uh, on how to go about implementing it and, you know, benefiting from, from this, uh, interoperability, um, that we're setting up.
Yeah, and Alan, I, I add to that, and I totally agree, it's far more, or allows it, it creates a framework or a way to, to go much further. So, you know, for a company like Fidelity, you know, using CD events, you know, allows us to express, you know, all of the different events that happen across the L-S-D-L-C into a common form, and then allows us to be able to have conversations across all of those events in a very consistent and common way. Um, helping us, you know, join events, you know, from disparate systems and allows us then to say, you know, how do we measure governance?
How we, how we might measure compliance, how do we ensure that codes being created, built and tested according to the kind of our standards and the kind of the specifications fidelity might have, or any, any enterprise might have. And re CD events allows us to express those events in a way that it can achieve those outcomes. Fair.
Um, You know, look, I think all of us aren't here, are very familiar with how open source communities work. Not everyone watching this is gonna be as familiar though. Let's talk a little bit about the relationship between like CDF and how it sponsors this particular project and where kinda rubber meets the road with the broader community.
Do, do you know what I'm saying? I mean, it's one thing for the CDF to say, okay, we, we are gonna sponsor CD events and we're gonna, you know, have people like Andre or on our board who are kind of co-founding it. But in terms of growing the community in terms of, you know, making breathing life into a day, day by day, it's not the CDF per se that's doing that, right?
It's the maintainers, it's the, the community as we say. Can you give us a sense of the size of the community, of the involvement of the community here? Aja, I hate to put it on you, but you are, You know, You are one of the, Um, you know, growing, uh, growing community, uh, is a continuous effort.
And, but we've been lucky, uh, with a, with a great community, um, in, in the city events project. I mean, we, we've had like, uh, early adopters from the beginning, like, uh, uh, friends, uh, you know, Gerard and, and Ben here that, uh, started at the early days, uh, contributing to the project, um, components as to the specification and, you know, taking it on and starting adopting it and, you know, bringing the, the invaluable feedback back to the community. So, um, yeah, and we, we have, uh, a core group of, uh, contributors that, uh, are kind of always within the project, you know, helping, facilitating the working groups and con bringing the discussion on.
And then we have other, we have had other companies that maybe joined the project, they're interested in a specific career, contribute some to the project, and then, you know, take that home and, uh, may contribute later in the future. But yeah, so we, we, we have, um, several companies that contributed over time. So we had, um, Ericsson contributing, uh, a lot of, um, a lot of the, uh, specifications and SDKs.
We have companies like Cube, uh, cube Shop, Bloomberg, and Red Hat, uh, do wild, so SAS So we have many companies involved in each, you know, contributing to different areas and, um, of the project itself. Yeah. And what if you that wanna, I wanna, I want to add to that as well 'cause it's more on the open source side of that is, um, so generally with open source, you have this concept called like working groups or SIGs, which are special interest groups.
And so these are like, you know, some sort of timeframe meeting. So it's like every week, every couple weeks, every month, you know, it could be any sort of allocated amount of time for any sort of, um, for any sort of period. Um, so with these groups, the maintainers and anyone that's interested in the project can join these calls.
So these calls are completely public. You can just go to a GitHub repo and, um, you know, well, well established ones and find a calendar, which will have these meetings. And then you can just hop in, you can hop in and just start participating.
So we encourage anyone that's interested in open source to go ahead and do that. Just go to any sort of interesting, uh, repo that you find that you wanna contribute to and just attend. You don't even have to speak.
You can just attend. And we're always looking for maintainers. We're always looking for more people to join.
So, you know, feel free to go to CB events, take a look at our calendars, and please, please, uh, show up. We'll, we'll, we'll encourage the discussions. Absolutely.
Gentlemen, if it's okay, I'd like to pivot a little bit. Look, it's December, it's the end of the year. Everybody's forward thinking, what does 2025 look like?
What is 2025 gonna bring in ways, you know, in ways of technologies, in ways of business, in ways of, it's a crazy time in the world. There's wars and there's regime change and there's elections and just, you know, it's, it's, it's a busy, crazy time in our world now, CD events. You know, someone once told me, don't do anything if it's not going to be big enough, right?
It's gonna have, if it doesn't have the potential to be impactful, don't waste your time. See the events is a project that has tremendous potential to, to be impactful, really help our organization streamline their, their pipelines, their delivery pipelines and collaboration. As you look at 2025, where do you think kind of the promise or the potential is specifically there with CD events that, that could make this really impactful in this coming year?
Andre, I'm not gonna pick on you for benefits. Okay. Let's pick with you and then Gerard and Andrea, you can fill in from there.
Uh, sure. Yeah. So for me, um, 2025 is gonna be a really good year.
'cause like I said, like, um, we started the implementation sig about, I don't know, maybe a month or two months ago. And so we're gonna start implementing the things that we're talking about, the, the specifications, the theory, you know, and try to prove that these concepts work, um, and ensure that they are of quality and is, and are very efficient as well. So that's gonna be very key for us in 2025, is getting, um, the actual implementations down so companies can actually start using these technologies, or even people, you know, if they're interested in seeing how this stuff works and wanting to see, um, the efficiency and the, the eases ability of tr uh, just changing tools, you know, we want to be able to provide that.
And then also on top of that, you also want to kind of, we, we talked a lot about interoperability, but there's also another side of the coin that CD events, um, really caters to, which, which I think we want to also cover here is, is metrics and, and telemetry. So that's another good job that we've done, um, at CD events spec wise is, is when you're looking at CD events from afar, um, there's this concept called links, which allows you to like link the individual events together. So if you're some sort of like, let's say you're very happy, you're some sort of on the very top of the leaderboard or, you know, in terms of like, just like CEO or CFO or something, you could actually look at the impact of, let's say, when a ticket was open to how long it took to actually get that feature out into production and all the bugs that were associated with it, just with CD events.
So that's, that's gonna be our overarching goal. Are we gonna get there in 2025? Uh, I could hope, but probably not.
But we're gonna try to strive there through the, through the implementation stakes by answering, you know, like what the spec looks like, as well as how do we address the observability portion of it. So that's gonna be the focus, well, at least my focus for the next year is the implementation of these concepts. Yeah, and I think, um, to, to kind of, um, lean on what Ben said and, you know, even potentially go further and broader, is the more enterprises, um, that kind of adopt CD events, I think, you know, from where what we have seen so far in our adoption is it's actually created new questions and new things we can ask of information that we didn't actually think have think of before.
'cause there was no visibility or transparency into the underlying data. So therefore we didn't realize there was even questions to be asked. So, you know, how do, how could we apply this in, in a governance compliance perspective?
Can we apply this in a security perspective? Can we in product, even if we wanted to try, you know, the, the million dollar question, does Gen AI deliver on its productivity? You know, are we now being able to look inside the data, right?
The data's the currency and the data's the evidence. And are we able to look inside this data, um, to, to gain understanding from it? I think, I think there's a lot of exploration yet that I think CD events has opened up to us.
Um, and we're looking actually forward to sit to innovating into that, exploring that, innovating within that space, and see what other opportunities outside of the ones we already know and that, you know, Andrea and Ben have articulated that we're, that the community is focusing on building in 25. But I think I'm look also looking forward to 25 is what does the 26 roadmap look like? What does the 27 roadmap?
Because I think there's great potential and opportunity here. Yeah. I just wanna make note, we got about 22 to 23 minutes in before Gen AI was mentioned today.
That's pretty darn good. Pretty darn good. Um, but I agree with you, Gerard, Andrea, back to you.
Yeah. Um, thanks. And I totally agree with, um, Moger and, and Ben mentioned, and I mean from, uh, I look at it from, from a kind of, uh, open source project point of view and what we, we plan and what we, we hope to, to, to achieve in, in 2025.
And, um, we, we discussed about the, um, implementation working group and what we really want to focus on in, you know, to, to help enterprises company and open source project adopt CD events and make the most of it, you know, starting from small, uh, and, you know, to grow to a, a larger scale, like, you know, covering the entire SDLC like Ben was saying, you know, asking new questions, building new, new metrics. And so, you know, we, we keep on like working, improving our SDKs, um, increasing more languages, um, uh, you know, drawing kind of reference architecture that companies can use to say, okay, this is how we we go about, uh, adopting city events. We need this component and that component and so forth, and what, what characteristics do they need and so forth.
And so this is, uh, uh, some of the areas where we are going to focus. And of course, I mean, I, I was talking about city events at the, the Linux Foundation Member Summit a couple of weeks ago, and I think it was a bit further than 20%, or maybe about 50, 60% from my slides. I also had a mention of Gen AI because it must be there.
Uh, and, and that's an area actually that, that, um, where we, we might consider expanding the, uh, the specification as well, uh, because, um, we've been talking about building software and the software, uh, uh, lifecycle and, uh, software factory. Uh, but now something that, uh, a lot of companies are doing is building AI applications. And so we want to make sure that we have all the, uh, events that are relevant for those kind of application as well as part of the specification.
And I made a call to action during my, uh, my, my talk and there was quite good response already. Someone in that space said, oh yeah, but be interested, you know, in contributing events in that space. So we hope to see that's that going.
That would be great. It certainly would be great. Um, how does CD events play with the other CDF projects?
Right? This is something I've bought in the past too, right? Because, you know, if you look at it, you look at the CDF projects, they all kinda live in their own silo, right?
And there's not as much integration as one may think, but CD event seems to me to be something that would work with some of the other CD foundation projects, right? And there can be integrations there and there can be crossover, cross promotion, cross use, so forth. Um, community building, is there someone from cd, you know, on the CD events, events side that is looking at that?
Is that something the CDF board is looking at? You know, where do we get one plus one equals three maybe? That's a great question, Alan.
Thank, thanks for that. So, um, indeed, one of the goals of CD events is to, you know, be supported by as many communities as possible and being at the CDF, the CDF project, our, our first, you know, and the closest project that our dearest project. And, uh, we discussed this also as part of the technical oversight committee.
And, you know, uh, we think as a, as a TOC from a TOC point of view, that's definitely a priority to get CD van support in all the CDF projects. Um, and that's, uh, already the case for many of the projects. Uh, I mean, thanks to, uh, fidelity, uh, contributed the, the Jenkins plugin.
So you can produce seed events, um, from, from Jenkins already and be there is support, uh, on Spinnaker that was contributed by, uh, apple and Ericsson. Uh, so we have experimental support in Tacton, and so many of the projects are already coming on board. And we are also working on a, a mechanism that we call the, the web adapter to integrate more and more projects as a, as a kind of translation layer that we want to, to, um, we started implementing and with plugins that can decode ally translate messages from, uh, different platforms into, into city events, you know, to speed up the, the adoption.
Excellent. Um, guys, we're almost outta time. You know what I realized?
Did we mention a website specifically for the, I know we mentioned the CD Foundation website, but did we mention the website for the CD events project? We did not. Where can we go get more CD events, project specific info CD events Dev, I think right under Andrea.
Yeah. CD events. Yeah, CD events, the dev.
And then from there we have documentation, we have the community page. We'll send you, like Ben was saying earlier too, where all the community meetings and details and how to contribute. Um, and we have the city events organization and GitHub as well with all our specification as the case and, and more, You know, will there be a specific track for CD events at the CD Foundation Summit in June, or too early to tell yet?
And the CD con is kind of like a mini summit. I think it happens the day before, uh, right, the days, I think it might be day zero or is it, or, um, VU of the conference. So as part of the call for papers, um, you know, we'll have multiple, multiple talks during that mini-conference, and we absolutely hope we have, uh, CD events being one of those talks where we, you know, we can share more with them, with the audience that, that are right, that are around that day.
Excellent. Excellent. Do you know where in Denver the event is?
In the Colorado Convention Center? That's what I was thinking. The Convention Center.
It's a nice place, the nice place for this. So do check that out. You can get to the Open Source Summit as part of the Linux Foundation, uh, website as well.
It's Open Source Summit North America. We're about outta time. Andrea, Andrea not thank you for being on here today, but also thank you for all you're doing around the CD events project, right?
It's not easy, as I said before, kind of breathing life into these things day to day. So thank you very much and thanks for being on the show today. Gerard, thank you for joining us as well, and for all you do.
You know, it's one thing for, and I don't mean to slide anyone, but when a vendor has people on board, generally the vendor's paying for them, but the vendor has an agenda, right? Uh, Yeah. Here, you know, Gerard, you represent the every man and woman, right?
And as part of Fidelity, and Fidelity is a huge supporter of Open source as, as I think most of us know. But, um, thank you for all you do on CD Foundation and, and, uh, volunteering your time. And then of course, Ben, thank you for what you're doing and staying on top of all this.
It really does take a village to, to, you know, maintain these foundations. So it's not just the Linux Foundation, you know, sprinkling some money and dust on these things. It's, it's the day-to-day work that, that keeps it going.
So thank all three of you. We'll be, we'll be back next month with another topic for our CD pipeline show, Laurie and d, we hope you feel better. We're sorry you missed it, but this is Alan Shimel for Techstrong and CD Pipeline.
Have a great day.