Techstrong TV – February 3, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Happy Monday has, has deep seek, become deep stink. You're watching Text On Gang.
Hey everyone, it's Alan Shimmel for Techron Gang, and we're back. It's a Monday. Happy Monday to you.
You know, we, uh, we were last week out in Silicon Valley with a special edition of Textron Gang, ed Tech Field Day. We experiment with these things, right? And, uh, Steve Foskett and John Willis and Mitch Ashley and the gang out there, uh, you know, covered the tech field day event, but there's been so much going on in the world besides that, that we wanted to, glad to be back here to talk about it.
But, you know, focus still remains on, on deep seek and the pros and cons and what does it mean for our tech world. We're going to get to that and some more good stuff on AI and, and, and more. Uh, but first, let me introduce you to our gang on this fine Monday.
First of all, I'm really glad I haven't seen her on the gang with me in a couple weeks at least. She is our voice in DC and there aren't a lot of voices left in dc uh, our own Trace Bannon. Hey, trace, how are you?
I'm just excited to get to talk to y'all today. This Gonna be fun. It's good to see you.
Thanks and welcome. So we go from Trace to Tracy, I guess she's our voice in New Mexico, but she's also our voice at the Linux Foundation and on open source of microservices and so much more. She's CEO of Deploy hub, Tracy Reagan.
Hey, Tracy. It's good to see you. Thank you, Alan.
Great to be here. Thanks. Great to have you.
And getting out of his sick bed to join us today, because that's the kind of dedication this guy has. He's future analyst, uh, vi, CTO, co-founder, our friend, guy Courier. Hey, guy.
How are you? I'm much better, thanks. It was a rough week last week.
Um, I did manage to, to stay engaged. Um, I heard there was a little bit of news in, in the AI world, so I just checked in real quick. Didn't seem like a big deal at the time, but There gonna talk.
There you go. Well, the good news is by the time he got better, it wasn't such a big deal anymore. Or maybe it was, maybe it wasn't.
Anyway, and then of course, uh, running the anchor lab. The anchor lab for us. He's our own four by 100 guy at a Cardinal Spellman High School in the Bronx.
Mike Ard. Hey, Mike, how are you? Good.
Good to see you. I'm hiding out in my, uh, fallout shelter in, I see that New York to, uh, because, you know, you don't know what the heck's gonna happen with China and this AI stuff, so yeah, I'm no, no windows in that room. Right?
It's all good. It's all good. Um, so gang, let's jump right into it.
Deep seek, has it become deep stink where every day this thing is, is peeling away like a rotten garlic clove or something stinking? Um, you know, the latest Mike, why don't, well, why don't you give us the latest Mike. Yeah.
So things are kind of crazy. On the one hand, we have reports saying that sensitive data is being exposed inside a deep seek because there aren't any guardrails to speak of. And, uh, folks are kind of downloading this thing like crazy and all kinds of havoc could ensue.
Uh, some countries, Ireland, Italy and the US Navy also are, uh, banning usage of this stuff. But at the same time, much to my personal amazement, at least, uh, AWS Microsoft, Google, and now Invidia are all seem to be embracing this model and making it available to customers. And you gotta ask yourself, like, did we not pay any attention to this TikTok conversation or what's going on here?
Alan, from your perspective? Well, from my perspective, you know, wasn't it Carl Mar Marx who said, or maybe it was s but I think it was Marx who said that we could sell the capitalist the rope with which they will hang themselves. This is a great example, right?
I I think whether you think the deep seek relearning techniques, breakthroughs in doing it cheaper, faster, faster, I don't know wanna say better necessarily, but certainly cheaper, faster is are real or not. What, what's for sure that we've seen is they may be able to build an AI engine. They don't know how to secure data.
So good. And it may be because in China, you know, people who try to break into stuff get a quick 22 to the back of the head and you don't do it again after that. Um, that being said, look, the wiz researchers exposed this hole where supposedly a hundred towels in people's confidential information was, was exposed open on the internet.
Um, they, they, you know, I don't believe they were the victims of a cyber attack that took them down. I think they were the victims of too many people hitting inadequate infrastructure and service to handle that kind of traffic. I, I, I think, you know, it's not ready for prime time.
It was an open source experiment by a couple of PhDs backed by a hedge fund who, whether they shorted Nvidia or not, we could discuss another time. That's a whole nother conversation. Yes, it is.
But, but that's what I, I think is here you're dealing with, you know, they, they don't have the infrastructure, processes, policies, cyber place in place. There's, there's so much to unpack with this. Something that, just to make sure everybody understands kind of the difference here, when it's popping up on Azure, when it's popping up on AWS when it's popping up on perplexity, um, it's not pointed at the deep seek subscription, right?
Right. So there's the deep, right, it's not quite good the Chinese infrastructure, Right? It's not ver and, but that's what we know when everybody started to download this app and it's suddenly shot higher than chat GPT with its opening.
It was pointing there, right? So there is a, there's a SaaS option that it's that SaaS, right? Software as a service, the subscription that has suffered from that exposure, right?
So that, I just wanna clarify. Yeah, there's a problem because they were not, um, capable or not yet mature, didn't have those things in place to be able to surface something, provide that kind of service. The other thing though is well, they did something unique, right?
IGI mean there's, I would say nearly, almost, they're just shy of the United States in terms of their research publishing. Like right now, China's a powerhouse when it comes well to what they, they're doing well, they're Going into labs in basic research for 20 years. They have, and in this case, they didn't have access to Mary because they didn't have access to all the same things that we have here.
They came up with an ingenious way, right? To look at how they could pair different chip types together to get some interesting performance. But it's not, I don't necessarily think it's a bad thing unless there is some kind of umbilical every time you instantiate the model that somehow is calling home.
But we've got folks like, um, the University of Florida. They have a massive new super pod. Nvidia has invested something like $70 million.
Every student has to take two AI courses before they graduate. Everybody, you can't graduate with that AI courses. It doesn't matter if you're nursing, it doesn't matter if you're business.
But I say that because they are decomposing this model to truly understand, right? They are looking at how the weightings are going, they're looking at all the different layers and they're seeing some different things. So there's goodness there putting it out there for Alan to install in his environment, in his AWS environment.
Okay? It's up to Alan, right? But he has, doesn't necessarily know what all the risks are yet, but it is a new model.
There is some sexiness to taking a look at it, but they're two very different, different things. I do wanna ask your opinion, Alan, don't you think it's kind of interesting that it popped up when it did in terms of the US change in administration. Like, couldn't they have released it three weeks earlier or five weeks later?
I don't think they bought all their shorts in time. Well, wasn't it also announced? Was it two days after the giant government funded OpenAI, blah, blah, blah, came out, Whatever that was after, right?
Project, uh, sure Stargate Sure took the wind, wind outta the sails of that one. It did, it it least temporary. It tooken the wind out of a lot of different sails.
A lot of right. Yeah. Well, Yeah.
It's trillion dollars. Let, let me, you Know, lemme trick you hit on something here. Let me tie it up.
So for people understand what you're saying is, look, instead of relying on the Chinese infrastructure, a lot of these places that we're seeing carrying it, if you will, are offering it as a self-hosted option. Correct. Now, my understanding with Amazon is just for AWS I'm talking about right now, you can run self-hosted in AWS or you can plug in the Chinese one into, not Broadcom, what do they call their bedrock.
You can plug in the Chinese version in a bedrock if you want, or you could run yourself hosted version. And I think the same goes for a lot of the, the, uh, web, the, uh, the cloud providers. That being said, you know, I used to sell security software to the federal government.
You sure did. You Sure did. For a long time.
And back, this was in the 2000 4, 5, 6. And even back then, there was a strong prejudice in the federal government about buying checkpoint firewalls and checkpoint uh, hardware. Because the rumor was the mo sod had a back door that would allow them to log into these machines remotely or what have you, would allow 'em to get home, phone, home, whatever you want to say.
And that was enough checkpoint, you know, it was a lot easier to sell Cisco firewalls back then, or net screen juniper or whatever. Um, what makes you think that's not the case here? Well, I actually, uh, am always erring on the side of the caution when it comes to national security, right?
Obviously. So I don't advocate that somebody connect and say, I wanna use the bedrock version that connects to China. Um, I also think about the ITAR, right?
Our export controls that we have in place. So a lot of, I'm not gonna send any of my data over there, I'm just not. But if AWS allows me to instantiate it and I want to experiment with it, and I wanna bet my business or my farm on it, well, that's my business inside the context, right?
Inside the confines of the continental, right? So I'm, I'm not farming out my, my data Externally, but, so now you've got choice make, got unit 42 out of Beijing who rents a small office in San Francisco and, and, and has the back door key into every self-hosted version. 'cause it's built into the source code, but it's open source, of course it's safe.
And, uh, and I see what you did there. Yeah. You made a joke and someone, and, and unit 42 logs into your instincts outta San Francisco.
No one realizes it. There's always Gonna be race. There's always gonna be ways to break into the stuff.
It's chaos. And, you know, the faster, the better we can respond to chaos, the better. But I wanna point out here that every technology gets disrupted, right?
We are all disrupted at one at some point. And I feel like this is a disruptive moment. If everything that they say and how they've built this and the cost around it is true, then it's a massive disruption.
And it goes to a bigger question that I keep asking myself. Why are we still putting so much money into one company if in in fact we could have some PhD students create a better solution? Why is OpenAI looking at getting a $40 billion investment?
There is a limited amount of funding available. And, you know, maybe China, I'll tell you why Or democratize them when it comes to funding and research. I, I've been in venture backed companies most of my career, and here's the rule.
If you're not in the top three, get the hell out. Money Goes to the top three. Well, this company was not the top three.
This company was not in the top three showed Up. They're, they, they, they come from sort of an alien culture, if you will. Right.
Though, truth be told, they're backed by a, you know, my joke about shorting Nvidia, they're backed by a hedge fund, right? The hedge fund took a, what was it, a $6 million flyer here. And, you know, if they did short Nvidia, they made that back a hundred times.
Uh, I've, that could be true, but I'm, I'm still gonna push that. We need, I believe that we are hurting ourselves in our, in the United States and our research by believing in one or two people. But, but that's the difference.
It's Either between government funding and VC funding. When I'm a VC or a PE person, and I've got investors to answer to, I'm not playing Johnny Appleseed and trying to go trees all over the country, I wanna bet on the winner. And you look at like the Andree Andre Andreessen Horowitz model, the Andre Andre Mark Andree in, in Horowitz's model is they pick one player in a given market, they pick a market they, they think is gonna be big.
They don't care if it's the best player. They're going to give them that player enough money to bury everyone else and get way out ahead. And so they'll capture a substantial share of that market, and their investment pays off.
And they became the most successful VC in Silicon Valley on that premise. And that's, that's, maybe It doesn't work anymore. Well, no, maybe VCs, You know, a lot of people say VCs are, what's wrong with this whole thing?
That's what I'm saying. You know, it's, we're not democratizing the, the funding to create the disruption ourselves. So we're gonna get disrupted by somebody else Supposed to be democratized.
Hold on, Hold on. Go ahead, chase. I'm gonna come back to that guy.
You've got something to say. Well, I, I know, I feel like two topics are being mixed here. Mm-hmm.
So I wanted to ask a question of everybody because Alan, the, the, the scenario you described, we went from security to, to funding in VC and competition and all that sort of stuff, sort of seamlessly. And I think those are really different discussions. I wanna get back to the security question.
Um, first of all, uh, let me just point out that Nvidia has a NIM for running, uh, uh, a deep seek. Um, so you could air gap a, a, a, a small system and run it. Yep.
Yep. Uh, yep. Yep.
But that put the, put that aside, w you described the scenario, Alan, of, of like, you know, using Bedrock or one of these services and all that other sort of stuff, you know, that it, it's not fully mature. I remember who said that. My question is why run deep?
Seek why? I think deep seek proved, not proved, I shouldn't say proved, is demonstrating the possibility of training models. This is what a quarter trillion parameters in, in, in R one or two, right.
Um, large models, uh, without these giant investments in hardware. Great. Okay.
But I, I've, I'm investigating deep seek. I've used it, but I don't know why I wouldn't use that. It's kind of perplexity or copilot or, I, I use a smattering.
So that's my question to everybody. Why use, why, why do, other than validate that it works? Why Do mart acted to a flame?
Well, I wanna, so there's so many pieces of this. So I wanna answer from a, from a security perspective. It's more than that.
Um, I'm jokingly said that umbilical, but Alan brought up a potent, you know, that potentiality of getting into, um, tapping into it, we can't lose track of the site that even our US based models, there's poisoning of the models there. It's a real thing. And we're working after.
How do we get rid of that? Well, do you really believe, um, you know, taking a step back, being a, um, you know, yay, go USA, do we really believe that China was looking after the types of things that we would want to make sure were secured from that model, from a poisoning perspective? Som some of my concerns around it actually have to do with the training data that the actual data itself, which we don't, don't worry they open ai.
Yeah. Well, that's what they're saying. Yeah.
And I don't, I, we're get, we're gonna get at that. What I'm trying to, what I'm trying to ask is, you're an enterprise, you are an organization, NG novelty, whatever kind of organization you are, It's novelty, right? Well, yeah.
Well, yeah. Yeah. That's great.
I mean, type a novelty. If you're in, if you're in the tech or r and d, you might wanna take a look at it and you'll pretty quickly find that's a perfectly good model. Uh, that's fine.
However, whatever it's prominence, and then mm-hmm. You like, I, it's not preferable to me. Well, but that, I wanna tie that back to something that Tracy asked about, or Tracy mentioned, um, was about, you know, the fact that OpenAI is a proprietary model.
Why are we putting our, all of our eggs one basket? So some of the research I did over the last year was looking at hundreds and hundreds of peer reviewed studies, and what bloom a frigging mind was, how many of them are using a model that has sourced out of OpenAI? But why, why is all the, well, we believe that part of that is free accessibility, right?
The free version, the things that people can get after for free. It isn't, wasn't the necessarily the GI coming from GitHub, it wasn't looking at philanthropic, it wasn't looking at the others. It was around their, their specific models.
So there is, uh, a research domination that we have to think about on the US side of the house, right? On the US side of the house. The other thing that this should really shake up, and I kind of like it, the models that we say are so wonderful, and it may help us, right?
We've built massive industries around this. They're proprietary. I don't get to see inside open AI's model this, shake things, shakes things up a bit, right?
Yes. We're in a capitalist society. Yes.
We wanna make money. It's just like big pharma. Why do they make a, why do they make a, a, a new drug?
It's not because they just wanna be altruistic and help the humanity. It's 'cause they're gonna make money off it. OpenAI makes a lot of money off their models and on keeping them proprietary.
This kind of shakes things up. Yes, there are open source models, there are, but this kind of takes something that has had in kind results open sourced in kind results to something that is hyper proprietary. So I think I'm, I like that shakeup.
But to guy's point with a little bit of pragmatism, um, you know, it's okay to be excited by the hype and, and and such, but we have to be ready for what's gonna come downstream. Uh, Alan, I, you, you named it, And it's important that we just demystify some of these technologies. And when I, when I read that story, it was like, okay, we're taking some of the mystery out of what OpenAI does, right?
So, and I think the more we demystify it, the more we all believe we could go ride it as well. And if some college students with $6 million did it, why not? Yeah.
So Mike's dying to ask a question, but I just, I read the white paper. Most of the math is far, far over my head. Mm-hmm.
But, um, for me, yes. The, the, the thing is they're, they're claiming, they're saying they used a different training method. It's not feed forward.
It's, yeah. It's, it's, it's, it's, it's slightly recursive. It's et cetera.
Like, you, you gotta read it. I don't want to get into those wonky details that's of abiding interest to the AI industry in terms of development. Mm-hmm.
Yep. But as far as Does anybody, nobody's talking about that really. Go ahead.
Sorry. Does anybody find that the irony, a little rich here that if I understand this correctly, open AI is saying that they quote unquote distilled their AI models without permission, the very open AI models that were created using a lot of data without permission? Well, Yeah.
Oh, yeah. I, well Do, as I say, I think we, We All saw that immediate do as I do, as I say, not as I do. Yeah.
Anyway, guys, we're, we're, we're over 20 minutes on this one. I'm gonna need to end it off. I wanna end it with this though.
If you wanna get a little more, it, it, it has certainly disrupted permanently or temporarily. It's made a big splash in the AI market. Our friends at Futura have, uh, a little paper.
They put, I think it came out Friday, uh, deep Seek disrupts AI market. You can get it over, I think John Schwartz probably covered it over on Textron ai. You can check out the article and the link to the paper there.
So go have at it if you'd like. But we're gonna take a break here on Textron Gang. We got more AI to talk about.
But let's talk about AI and testing. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, everybody, we're back and we're talking about AI and testing because, well, last week we saw Perforce has a new tool that eliminates the need for building your own scripts.
Uh, harness is talking about putting an AI agent in front of their chaos engineering tool. And now AWS has extended its platform to include the ability to generate tests. So everybody's kind of going down the same path here.
And one of the things I do like about this is I'm reminded of that, uh, a woman who said, you know, when they were talk, talking to her about AI and its ability to create art and do all these things, she says, I don't want AI to create art. I want AI to clean up the kitchen so I can go create Art Trace. Is this the roughly the equivalent of that?
Are we gonna use AI to create the test because nobody wants to clean up the applications anywhere? Well, gosh, there are two completely divergent topics that I'm not gonna cover, because the first one I'll talk about Bridge just a second, and then we'll put it and put a pin in it. If we are helping people to truly write decent software, they're starting out understanding requirements in the first place, right?
Kind of the big R vision of those things. First place that you go is understanding how is it gonna be tested? You don't go straight to code.
So there's that whole thing that we need to talk about. And the, IM the impact of having a, a holistic testing mindset end to end, not just as a Chevron that follows build, right? That's one of the problems with the whole modern DevSecOps, little continuum.
It says that we just test in this one place. So pin in that right over there. I love the concepts.
I love what's happening with moving from, Hey, we're gonna gen code, gen code, gen code to, we're gonna leverage this in a way that can help us to generate some assets. But there's also another really important part of this right there. When you're using generative ai, there are two big buckets of ways that you use it.
Eye roll, you use it to generate things, okay? Eye roll there. But the other thing is augmenting human reasoning.
So it, it really serves this wonderful purpose. I like it better for testing, because there was a report that came out, and I'll have to, uh, find the actual report and send you guys. So we have that in the, the link and available to people.
47% of organizations have automated their testing. So that means 53% have not, that should make jaws drop. So things that we can do to improve it, hell yeah.
Now remember that all tools, no AI augmented tool is immutable and is perfect. But this gets us a, a lot further along the path. One post that I'll say, or one nugget that I'll, I'll share is right now, if you're trying to use it to generate your code, and also trying to use it to generate your tests, if you're actually generating tests from it, you wanna be a little bit careful about that because you have no verification, right?
You've got AI on both sides, and right now, today, six months, it'll be different. But today that's a little bit tenuous. But there's so many awesome ways to set it loose to help, to help the humans with the testing.
It does a lot on its own. But again, at the end of the day, you're gonna have the humans in the loop. So trace, I know that you spend a lot of time and, you know, dealing with this, right?
In every endeavor that you, you go down there, there's testing involved myriad types of testing. And One of the problems with the scripts, so per force is going down the right road. I, you know, I've advocated for getting rid of scripts and the builds process for how long now?
30 years. Mm-hmm. I've been taking, talking about that.
Um, because scripting is very static and it can adapt. Uh, and when you talk about 43% of the companies, uh, have implemented automated testing, uh, it means that they've put a, a, a group of, uh, testers who have some development background who can write these test scripts. So, you know, one time I was talking to an individual who was really loved his build scripts, by the way.
And I think they're gonna really love their test scripts. And to Mike's description or Mike's analogy of being the artist, they believe their art is in the scripts. They really love their scripts.
So we have a cultural problem as well. And I've watched that cultural problem for a very long time. And maybe now that AI is cool.
I mean, open makes, open make, uh, Meister was a rules based. It was a knowledge base that we generated all build scripts for Ant or whatever you needed to build a script for. But people would, like, we wanna, you know, we, we we're the shoe makers.
We wanna make perfect shoes. We love our scripts. So we'll see how, how developers embrace this, this kind of technology.
'cause I feel, I, I really feel like it, it, they will feel it takes something away from what they do, but it's the only way to go because there's so much more stuff to write than a test script. And in terms of the stuff that, um, you know, testing, uh, generated code, uh, I, you know, I keep in touch with my niece who took her first job and she told me she could generate 6,000 lines of code a day, which I think is insane. But she said she wouldn't, couldn't really use it because she didn't have the time to debug and test it.
And when it's generated, it's a lot harder. So if we have more AI doing that kind of work, it will make it easier to use these tools. So, you know, yay for perforce to talk about getting rid of scripts.
Thank God, thank God. Let's do more of that. And I'm happy after, you know, this whole last year I talked about where's AI and DevOps.
We're finally starting to see something come up. Well, I also thought you'd be happy Tracy with, uh, harness getting in the game here because mm-hmm. I know you're a, you're, you're a, I love chaos engineering.
I do. I think it's fascinating and I think it should be applied to so many other things, including security. So, yeah, I was, uh, you know, I'm, I'm glad that harness is going down that road because most companies are really struggle with putting, setting up game days for doing chaos engineering.
And this will help a lot. And I, you know, it's an, it's an area that I think companies should really focus on. How do you, how do you stand up a system if something broke and bring it back to health in a few minutes?
Not an hour, not two hours, not a day, and not even 20 minutes, but instantly, You know, you, you bring up the idea of what's the developer impact. We're seeing some pretty interesting stuff. I think I've, I chat a little bit with, uh, uh, with Mike about this before.
Right now we're in that point, we're in a, I'm not gonna say a transformation. I'm gonna say a transition where developers are creators, right? We create things, software engineers, we create things, even test and just create things.
And we're going from being creators to being reviewers editors. And here's where it gets just a little bit dicey with newer incare. If you've just learned the English language, I probably won't give you a formal journal publication to peer review.
Not yet. 'cause you need more practice with the human language. We're seeing that with earlier in career.
Don't care what their age are just earlier in career folks, because they're not getting to decompose in the same way. So that's just something, whether it's test scripts or any other thing that's being generated where we don't get to practice that, that decomposition that we, that we did before. So I think that's just a, an interesting nugget to, to throw out there and to keep involved in this conversation.
Yeah, it's like losing the ability to navigate through a command line. Mm-hmm. How many, mm-hmm.
How many developers know how to do that? Always shocked. It's coming back.
It's a vogue now. I know. Oh gosh.
What? It's, you know, What, what do, what do our students do? Right?
It's, it's kind of the, I mean, what's the core sensibility of, of software development? Is it, I mean, there's, there, of course, it's ability. Maybe I know even from, you know, back when all we had was cli there's something, there's, there's this user experience aspect to it.
There's also this sort of functional, you know, backend front end is what sort call it now. Um, but I'm not sure the core sensibility is your, your, your passionate belief that Python is the, or g or whatever is the future. And yet, that seems to be so much of the, the culture and the discussion is the, the tools, the tricks, the languages and so forth.
I think that, that, when AI can start to do a lot of these things, then it, they, it, I I, my answer to Mike's question is yes, it's doing the dishes so that the, you know, editing, supervising, whatever of like, how do you put, how do you put together good, you know, good piece of software, good app module, good service, whatever it is, um, uh, with understanding how the whole stack works. Um, you can, you know, pay more attention to that and less attention to, uh, the, how, I guess, am I starting to disagree with myself saying that? But, yeah.
Well, so it gets into, so we're going to be, it's not, I understand that we're saying that we're gonna automate the, the tedious stuff away, but there's going to be a point where we're creating, I call 'em this digital platform. We're creating these digital platforms where anybody can walk up to it. Uh, I'm, I'm a, I'm a sailor.
I'm a nurse, and I can say, these are the things that I need. I need some software that will do this. 500 billion, 500 million developers by 2030.
Exactly. Exactly. And they're not going to be, we're not going to see development in the same way that we're seeing it now.
We're going to see software engineering. We're going to be at the intersection of the data scientists are plugged in with the data. Engineers are plugged in with the software engineers who are creating that middleware, right?
So that the humans can generate the software that they need. We'll get into this software flywheel, but you guys brought up a whole bunch of different things here. I wanna, I wanna track back something you said, guy, uh, about, you know, the, and, and Tracy, you had foot stomped this as well about getting rid of the test scripts and how great it is to get rid of the test scripts.
Again, transition. I think we're going to see in highly regulated industries, whether it's government or whether it's, we're going to see that lag a bit because of the auditability. So they're going to need those tools that aren't using scripts.
They're going to need to see the auditability of that test. And if, and so I think we have a little bit of a challenge on that front can be solved, but a little bit of a challenge. But I was having a, actually, I was on the phone this morning with my buddy Pat dubois, and we were talking about what, how, where things are going, talking about agents and agent and what's gonna happen in the future.
And we talked about the B everything is going to track back to the spec. Now. We didn't talk about what the spec is, 'cause it could be dozens and dozens of different things.
Our software developers, our software professionals are gonna have, need to be heavily invested in, in that part of it. And that's also going to feed those tests, right? It's also gonna feed harness, it's gonna feed the other tools that are being improved with this stuff.
So there's just so much amazingness out there right now, but yeah. So much amazingness that's out there right now here. Here's, here's kind of a take on it though.
Um, I personally think that when we look at AI and good uses of AI app testing is probably one of the best in the whole software supply chain, you know, life cycle. There's no reason we shouldn't maximize a use to, uh, to do testing. I think it, it just lends itself, I think the same way a human could render a script.
The AI will render a script too, and it'll be fine from a compliance point of view, but at this transitionary moment where we are right now, I am hesitant to let AI generate code and then let AI test that code. I won't Right? Without, without having some human in there at some point, especially if it's anything mission critical or really valuable, um, That's a strong recommendation, Alan, that I make constantly over the last year do one or the other, but not do Both.
Or now, right Now. For now. Right.
Right. For now, because we don't have that verification, right? We don't have the verification and validation.
Well, We don't have the confidence is what we don't have, right. Because we know it's not, it's not at that level yet. Right.
Okay. Can't that be in the pipeline? I mean, I don't, I don't isn't You can have both, but not without the human intervention.
You don't want to just release, right. Even even release it into qa, honestly, like, like it no developer involved. So, so, Oh, come on, guy.
What's the answer? It depends. Yes, it Depends.
It depends. It depends on your industry, it depends on your context, it depends on your workforce. It depends on the maturity, it depends on how old the software is and the quality of the existing software.
All these things. So, yes. Mm-hmm.
And right now, if somebody says, we're starting on our journey, where should we go? I actually say, your documentation. What's the qual?
That's, that's you have enough documentation that's low hanging flute. And then let's go to testing, and then we can go backwards from there. Because when you focus on testing, especially if you're focusing on you humans being involved, and I'm not talking about this completely automated tools, which are awesome, right?
The autonomous tools. But if you talk about helping humans to get better at using the tools themselves, have them focus on testing, it still is sexy, right? It's still is sexy even to a developer to say, Hey, can you evaluate this code base?
Can you tell me where I have testing flows? Can you help me understand unit tests and to end tests, right? As it sees the bigger, brighter context.
Yeah. Start with testing. Absolutely.
Tracy, those words. Well, you know, as they stay, the more, the more things stay that change, the more things stay the same. Isn't that what they say?
Um, we, Yes. The French saying that my French wife says is stupid. So I'm, I, so We've, software has changed and changed and changed over time, but we still are writing software the same, to be quite honest.
We are, we still code it, we still, you know, manage it. We still test it. We still te you know, go through all of the same steps and those steps aren't going away.
So while develop, it might be scary to think that a developer AI would generate code and then test code. The reality is, is that when, as right, right? Today, developers still want control.
I have faith that they will continue to want control. They're gonna generate code, just like we might generate a document and they're gonna go through and they're going to read it, they're gonna learn it, they're gonna understand what they just generated because they have to deliver it. This is what I'm hearing from the developers, the new developers that I'm talking to.
Um, so yeah, testing would be a good place. And things like scripting, the problem is with those test tools, scripting can be a bit challenging. And not all testers are developers.
And so that's why we have a gap and how much automation's being done. So, and I really don't, you know, I hate to use the term AI to say we're generating scripts. You can generate scripts without it.
Oh shoot, we've been generating Stuff for 20 years. I was generating my co bo Joe's 20 years. It's nice to put them two letters in front of it, but it doesn't mean that's what it's doing.
So let's just realize that we still have to go through the same dev process no matter what happens. And we won't always catch things all. So for now, for now, the, We're gonna take a break here.
Not changing. We're Gonna Wait, wait, wait, wait, wait. The script huggers your night meeting will be next month, Colorado.
Okay. We are, we're gonna take a break right here. We're gonna come back and let's talk about conflicts of interest.
Is there such a thing anymore? com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more.
com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more. com where the world meets DevOps.
All right, folks, we're back with our final topic of the day. And I think there was so much noise in the world that nobody noticed, but Elon Musk is now partnered with Visas so you can conduct transactions across the X platform. And magically Donald Trump came up with a similar idea for his, uh, social media platform.
I'm not sure if those two are discussing these things as they go along, but it all came together in the same week. Guy. What could possibly go wrong with, that's the word that allows you to conduct any type of transaction.
Wow. Where to begin? So, uh, there's, there's so many, there's so much context here.
I I don't even know what to pick first. Like, first of all, um, when Elon took over x Twitter at the time, uh, he almost immediately, uh, made it known that he wanted x to be the platform for everything. Just like Mark wanted Facebook to be the platform for everything.
And one of those things was payments. It it, it's kind of a natural in some ways you would think, like these are communications media and, uh, uh, one-to-one and one to many and all that other sort of stuff. So talking to you about a guy who made his first fortune in PayPal.
Exactly. Yes. I, let's, Let's not lose sight of that.
So This is an old idea. It's an old idea. And I think that that the track of Twitter half blown up and losing a lot of its, you know, participation and all that sort of stuff for political reasons that I'm not gonna get into here.
Um, you know, it's sort of comfortable circle a little bit with the ent rise to political power in a sense. He, he has the, the political muscle right now to, to help get the kind of deal he he wants from a visa or from anybody. And similarly to the president of the United States, having the political muscle to find somebody to back, uh, what is it?
Truth do truth fi or something. Truth do fi also payment or no, an investment platform. Um, so what could possibly go wrong?
I, I think, um, similar. It's what's really funny, the other piece of context is, um, we get, uh, the, uh, AI announcement followed by, uh, uh, Elon saying it's never gonna work. So, you know, you have sort of, sort of, you know, pairs of like parallel paths here from the president and from Elon Musk.
I, I wonder what's next? That said, these two are really different animals, really different. Um, the partly because one is a sort of payment and communications, like I said, it's an, it, it, it's a plausible extension to both Elon's background as well as to, uh, you know, the kind of medium that XX Twitter is.
Uh, and Visa itself is also a, a certain kind of a communications network as well, verified and so forth. Who's gonna use it? X users are gonna use it.
Who are X users at this point? A lot of them are Elon fan people. Uh, that's just kind of how it shook out, uh, whose guy came in.
There are other methods for communication and so forth, but are people gonna migrate into X because of this? There's lots of ways to, to, you know, to pay And be paid. There's a nugget that came out this morning, guy that you'll like, it just, there, just an article that was posted.
I just put it into the, the chat for us to be able to share with folks. It says Bezos is boosting his ad ads on X. So are there gonna be followers?
What other kinds of interesting things are gonna happen? They lost people, but they're been starting to gain people back. This is the echo political environment.
We're in the United States right now. Oh yeah. This has nothing to do With David.
So we really haven't had a president of the United States before, even Trump's first term, who was, who was actively and openly engaged in business. Oh, B******t. Trump has been doing this sort of thing.
Okay, you'll explain which, which other presidents have done this, but Trump this. To me, truth Phi is the same as going back to Trump shuttle, you know, uh, Trump Towers, Trump branding, Trump vodka, pit, Trump, you know, like all these sort of things. A new line of business where people who are attracted to him and to his brand, no judgment, just saying, attracted to him and his brand, they can do the same kinds of investing that they do elsewhere.
Only now they can do it within this culture and within this Milia. And Trump gets his take from it, as does his partner Schwab, who is essentially using Truth social as a channel partner, as Schwab uses, or TD Warehouse uses other channel partners to gain business. Alan, I would love to hear your perspective as well.
You and I and Mike, we are old New Yorkers. We've known Trump forever since he was, you know, the son of, we started Times in quarters, quarters before you moved up to a hundred dollars bills and stiffing contractors. Yeah, sure.
But that, that being the case, I'm not even gonna talk about it as a New Yorker. I wanna come at this. You know, I was a political science major, history major college, spent a lot of time looking at and learning about the American system and, you know, the Federalist papers and the founding fathers and separations and different levels of government.
A a bedrock belief in our government is it was a good government principle. We weren't here to enrich the monarch and, and make his treasure room bigger. Wait, can I get a clarification?
When you said b******t, you were saying what's happening? His b******t, or you're saying what I said? No, I'm saying in his first term, he, he, he did what?
No, president. It Wasn't, it wasn't open in this way. That's the only Difference.
It was, It wasn't open in this way. Everybody who came to Washington had to pay the Trump hotel tax. Did you forget if you didn't the hotel, you didn't get a meeting.
That's pretty damn open. No, there's not pre-social or Brand. I'm not, I'm not even gonna argue that.
Let me, let me get back to this. A bedrock of our government is number one, we're not here to enrich the monarch. There is no monarch.
Number two, everybody is equal under the law. Everybody's equal. There are that, that means that we don't discriminate against anyone.
But no one is above the law. And no one should have the, to wield the power of the office for their own private enrichment. That is, that used to be in the America I grew up in, loved that that was, even if sometimes it didn't necessarily work that way, at least on its surface, that was a given.
When a president or anybody came into office, you know, they had to set up a blind trust. They weren't allowed. They weren't, you are not allowed.
When, when the King of Saudi Arabia comes and gives you a gold plated knife or dagger, you're not allowed to keep that gift that goes, that belongs to the people of the United States of America. All of a sudden, in addition to everything else that we could talk about, everything else, till the cows come home, we've decided it's okay to allow this, whatever it is, come into office and enrich himself at our expense. And make no mistake, it's at our expense.
Now. You're right Guy. You and I are never gonna go on truth social and you Schwab file or whatever the heck it's called.
As a matter of fact, if I had any money in Schwab, I'd pull it out just because they did this. But what Trace just said about Bezos is a perfect example. Everybody wants to Curry favor.
And Elon Musk is in a position where he's gonna decide what gets spent on this government. And, and AWS and Amazon and Blue Origin, or whatever his space thing is called, is all very near and dear to Jeff Bezos. So of course he's going to suck up to Elon Musk, and of course, Schwab and his daughter or granddaughter, whoever the heck it is, is an assistant treasury secretary surprise, is gonna suck up to Donald Trump.
Now, as a matter of Fact, all of Big Tech has Mm-hmm. Now we can call them our first American oligarchs. Right?
Maybe that's What this is. And the question really? Yeah, that's what this is.
And the real question is, why are we not, um, making, Are we riot in the streets? Why aren't we out? The, Why Isn't Congress standing up and saying, no, this is wrong, because they're, 'cause the Republicans sucking on the same tee.
Yeah. That's why Yeah. The Republicans have become okay with this.
And he, he was very vocal in that it's publican early part Of December, not the Democrats, everyone should be up in arms In early December. In early December, he, Trump was interviewed, I think on Meet the press, and he said he could not divert, he could not divert his investments. He said he he couldn't do it.
Trust divest it. He couldn't divest it. Well, because He, And he said he wouldn't even know how to divest it.
No. He said there's no way he could divest it. He just said, no, you don't to dive this.
You could put it in a blind trust. I don't think he's gonna even try to do that this time. And like he said, it's very open.
Open comes, he said he not Tracy. He was lying. He was lying.
He can do it. There are ways to do it. Of Course he can.
He was lying about the 2025 project he is lying about. So, you know, the D-N-I-D-N-I people who are in the, you know, the TSA, he lies all the time. But watch what he does.
What he does is he's not going to do it. So, so mark me on this. All that crap that happens on the Silk Road and all those illicit transactions is moving over to these platforms and people are gonna start using these things to do all kinds of things that are illegal.
And they're just gonna be out in the open. 'cause nobody's gonna be tracking who's selling what, where and when on these things. I think that's right.
And I think, Alan, my response to, to, to what you're saying is that I, I, I agree with you a hundred percent about, um, the need for, at a minimum, the appearance of, of, of neutrality and objectivity, but also separation, like you say, good government separation. I believe in that completely. I, I think that I, I don't, I know that the level of cynicism, um, in general in the electorate of the United States, it's very high.
And that the general response that I've gotten to making statements like that is, well, everybody's done it. Yeah, I know Biden is, What about is Obama are even worse? They're worse.
Not just 'cause they do it more, but because they lie about it. And at least we have men. Well, Shouldn't gone to jail.
Honesty and openness about it. Now, that's Menendez gone 11 years. You know what, for doing.
So again, I'm a history major. Let me tell you something. In the 1880s, 1890s after the Civil War, right?
The robber barons, the Van Gild age. The Gilded Age, well, it was a little before, it's the beginning of the Gilded Age, before it got really giled. But there was a time not just where people were making tons of money, but that government got really, I mean, started with Andrew Johnson who came in after Lincoln.
Everything was for sale under Andrew Johnson. And, and it didn't get, you know, grant did a decent job, but he was a adjunct. And then it, it went pre progressively downhill from there.
And until the first time we, well, it's, it wasn't the first time. 'cause we've had third parties, but a third party president won the election. The talking about Teddy Roosevelt Party, Teddy Roosevelt, you know what he ran on?
Clean up government, good government. Mm-hmm. Clean up government put in, You know who, who had that message before him was Democrat, Grover Cleveland.
Yes. The former New Yorker. He, He ran once then was out.
So it was like a 30 year movement that culminated presidency in the beginning of Antit, the Cleaned it up. Now, the best we can hope for as Americans is that the sten of this becomes so rotten and stinky that we wake up, come to our senses, and we get some sort of good government movement here that may start at a local level and work its way to the federal where, you know, what I would like to see, I, any member of Congress has to put their stocks in blind trust. Let's take the insider trading out of this.
They cannot go chase, you know, this being in the beltway, you can't go work for a contractor with, for three years after you leave government. You can't be running commercial entities while you're serving this government. And you can't have quasi people like what Elon is right now, have any kind of say in things and access to top secret and everything else while he has commercial business going on with the US government.
And until we do that, this whole thing is a farce. All right. Sold.
I think, I think we're gonna have to close this out guys, but all Roosevelt speaks softly and carry a big stick, Right? Absolutely. Good old Teddy Roosevelt, the hero of, was it San Juan Hill in Yes.
Cuba. Yep. The Rough Riders.
The Rough Riders. Spanish American War or Get Creek. I was not a history major, but I did stay at a Holiday Inn Express recently.
So I know Mike loves the history though. All right. We gave you a little history, a little of this, a little of that.
But we're done here on Textron Gang for this wonderful Monday. We'll be back tomorrow with more gang members, more news, more discussion, and more fun. Until then, is Alan Humma?
We're out. This is Techstrong tv. Hey everyone, welcome back here to Techstrong tv.
Our next guest is Mr. Trevor Dearing. Trevor is Director of Critical Infrastructure Solutions over to lumio.
Let's welcome him. Trevor, welcome. Thanks for coming on Textron TV today.
How are you man? I'm very well, and thank you, Alan. Thanks for having me on.
My pleasure. So, Trevor, director of Critical Infrastructure Solutions. That's a mouthful.
Tell us a little bit about kinda what your job role is, what your duties are, and then if you don't mind, tell us a little bit about yourself, how you came to be the director of critical, uh, infrastructure solutions here. Yeah, so, so I, I've, I guess, worked in cybersecurity now, 37 years, probably in this, in the IT industry, 43 years. Um, right back to sort of installing some of the first firewalls in, in uk working with some of the early AV technologies.
I was an engineer primarily. Mm-hmm. And then I suppose sort of worked my way through, you know, through various roles within the, within the industry.
And one of the, you know, one of the key things that I guess in started to interest me was what was happening in some of our more critical environments. So, you know, electricity, grids, healthcare, all of those sort of things. And I've worked for a number of vendors that everyone knows throughout the years.
Um, and about five years ago, an opportunity to join lumio came up and it just fitted in with, you know, with a lot of the things that I was interested in at the time around, you know, protecting those, those parts of critical infrastructure. Absolutely. And look, you know, I, I think especially during COVID, um, the whole idea of our critical infrastructure being vulnerable and also the whole definition of critical infrastructure, right?
I, I've been in security 25 plus years myself, I tech 30 plus years. It used to be critical infrastructure US was the electrical grid. You mentioned it right here in the us we've got NERC and FERC and all of that.
I've worked with that. And um, you know, certainly public utilities was thought of as critical infrastructure, but we found out during covid healthcare, our healthcare system is critical infrastructure, our supply chain, right? For things these days, as simple as toilet paper at some level is critical infrastructure, right?
Protecting those supply chains. And, and so to me, the mission has, ooh, mushroomed in when we talk about, you know, protecting critical infrastructure, where it is, what it is, what it does, and, and what do we have to do to protect it. Um, I'm cur we we're gonna jump back into that in a second.
'cause I want to hear how Illumio views, you know, the definition of what's critical infrastructure. But first I guess we should define the lumio, right? Many people out here probably know, but go ahead Yeah.
So, so Lumio, gosh, we've been around 12 years now. Um, yep. And what, you know, what we are fundamentally, you know, trying to do is to, is if there is an attack, is making sure it doesn't become a disaster.
And this, you know, this really is again, fits into the whole critical infrastructure. So, you know, our major customers are banks, government manufacturers, utility companies, et cetera, et cetera. And so, you know, we focus on really the resilience of an organization, how to understand where the risks are, how to contain any attacks that, when they happen, basically to, to keep organizations working when there is an attack.
So, you know, we'll, we'll, we'll look at when we, when we dive into the numbers, we'll see how, why that's important. Absolutely. And, and really, you know, what illumio's know for in the, in the market is, is kind of, they, they, they achieve this using a lot of, kinda like microsegmentation.
Yeah. Right. And being able to, I want to use the term wall off, but segment, you know, so if you do get attacked, and, and a lot of times it's not due, it's when you get attacked, you can limit the, the, the blast radius as they used to stay, right?
Yeah. Correct. Um, so before we jump in, you guys just did your, uh, cost of ransomware report.
We're gonna jump onto here in a minute, but what's critical infrastructure to you, Trevor? It's actually, um, it's actually pretty well sort of defined there within a lot of compliance and regulations around the world. And so it, it, it is what we've mentioned, it's, you know, primarily at the top end, it's power, it's utilities, it's water, it's all of those sort of things.
But as you said, it's, it's food, it's transport, it's, um, you know, modern days, it's the internet, um, and mobile phones. Mm-hmm. And, and, you know, all of those sort of areas, banking, for instance, because nothing happens without those.
So, you know, we started to see, uh, regulations all around the world now coming in, focusing on, on the, the resilience aspect of critical infrastructure. So, you know, it's not, it's, it's, it's become a thing I, I guess in its in its own right. Absolutely.
Absolutely. And, and I think it, you know, it's kinda like trying to define DevOps, right? The more you put your finger on it, the more it kind of squishes, you know, away critical infrastructure.
Something could be critical to you and not critical to me for whatever reason, right? I live in a cave and the internet's not important or what have you. Right.
But I, I think we agree there. We all agree. There are critical pieces of our lives today, and that's increased as we become more digital that gonna fall into this.
So I mentioned this ransomware report you guys did, the global cost of, of the ransomware. Um, is this the first year you've done this? Have you guys been doing this report now for a while?
So We actually were, we worked with the Ponemon Institute on this, and it's something that they've done before, but this is the first time that Yeah. That we've, we've, Well, I, I didn't realize. Yeah, he's actually right down the road from us.
We're here at Boca original Florida PO is also in it, not a tech center. Right. People don't come to Boca Raton, Florida for the tech, but for the most part, I wish they did.
But anyway, just coincidentally, he's, they're nearby here, so. Interesting. Yes.
I'm, we're, I think we're familiar PO has been doing this report a while. So for this here, before we jump into the, uh, findings, when was the surveying done? When, you know, how fresh is the data here?
So the, the, the data basically is, has was released yesterday. So the, the research, the research was done just at the end of the tail end of last year. Obviously, it's all being analyzed and consolidated and turned into a report, which you can, you know, which you can retrieve.
com, there's a banner on the front page, click and download it. So you know it, and it's, it's actually full of writ and quite surprising numbers in on a, on a positive and a negative note. Really, Really.
That's, that's the way life is. Right? Yeah.
Go ahead. Let's, let's, you know, you, let's, before we jump into surprising even, let's go to key findings. How's that?
Yeah. What, you know, what did, what are the key takeaways our audience should, should do on take on this? I think, I think one of the, you know, one of the interesting findings was that, that people are actually very confident about their ability to prevent and stop ransomware.
So, so compared to three years ago, which was the last time they did it, the, the sort of where people are saying, yep, I've, I've got more confidence. I don't believe that we're a target for ransomware. I've got more confidence in my supply chain.
I believe that we are better at, at, at, um, at stopping ransomware. All of those numbers have improved, so people are more confident. But then on the flip side, numbers, like we had to shut down for a period, have leapt from 45% to nearly 60%, or, um, our brand was damaged, has grown, or we lost significant revenue has grown, or the number of, um, attacks we had has grown.
So, so there's a sort of a, a weird dichotomy between those Two. No jive. Yeah, yeah, yeah.
The numbers don't really, Or, or unless you're telling me because I was a victim, I feel like I won't be a victim again. Right? So the lion ate this zebra once.
He's not gonna eat the same zebra twice. You've been in security longer than I have even, and I've been in it a long time. I don't believe it.
I, I, I think, not that I don't believe people said this, but I think this is false confidence in, in what they've got here, right? Um, I think everyone is the target. I think, you know, there are certainly strategic targets when it comes to ransomware.
There's something that you have that is very dear, near and dear to me that I want, right? Strategically, but I think for the most part, like a lot of cyber crime, you become a target when the bad guy walks down the hall of the hotel and your door happens to be a little more jiggly than the next door, right? And it's easier to break in.
And so I, I don't, I don't buy that. I think people are misguided if they feel that way. I also think with AI and everything, the phishing attacks that people, that the, the bad guys are using to, to get in and, you know, and plant their malware that leads to the ran, you know, the encryption and the ransom.
I think they're better than ever. Trevor, you've gotta be seeing this too, right? Yep.
Yeah. I mean, it's, there was, I was at a, a conference a couple of days ago, and there was a big discussion on, and some deep fakes are less deep and less obvious than, than others. But some are very, very good, and they will only get better over, over time.
And to a certain extent, you know, the, the primary attack vector is still phishing. Yeah. And it's becoming more and more difficult to detect that.
But there is, you know, better AI tools that are trying to detect DeepFakes and, and that battle will go, you know, will go on or not. But you know, the reality that we, that we face is that over these, you know, over that 37 years, we've got much better at reducing the probability that an attack is gonna be successful probably by, you know, over 99%. But that still means that at some point something is gonna get through, and there's probably not enough focus on what happens when the attack gets in.
And there's some, you have, there's some real, real things where they talk about, um, uh, uh, like what was the, you know, what was the primary movement for, uh, for ransomware and what was the, you know, what were the things that caused lateral movement? And it's, and it's still numbers like RDP, weak passwords, unpatched systems. So, so there's a lot of work just on the basics of security that isn't being done, that's allowing those, um, those attacks to have a, have an impact to cause that shut down for a period.
So, so I think there's two things in there, one of which is a focus on make sure you do the basic things properly, but also how do you then, you know, again, how do you then contain and control that attack? And I think we've seen sort of an improvement and a, a, a sort of a drive towards incident response. And, you know, some of that, that sort of technology that's, that's starting to help and a hopefully a shift in culture within organizations to move away from, you know, I muster everything to stop every attack, to how do I make my organization more resilient?
So I I do, I agree with you there on the resiliency. I think where we have made progress with ransomware is understanding how do we, how do we, again, limit the blast radius? How do we have copies of our data that are not subject to being, you know, encrypted here, right?
Yeah. That there's some sort of wall between them. It, it is about incident response.
This is why, frankly, Illumio with microsegmentation is a, is a great ransomware kind of fire. I, I don't wanna use the word firewall 'cause it has a different meaning in security, right? But it's a, it literally is a block, right?
Because it, it can limit what, what data gets attacked here. Um, and that, that is where I think we have made progress. People understand that with the best of intentions and the best of processes and policies, stuff's gonna happen, right?
They're going to it, it, the phishing gets through, you know, and it only takes one knucklehead click and something they shouldn't click. And that's, you know, where you go from there. Yes.
But how you respond to that attack and how you use a, an illumio and or how you have architected your data, you know, storage to, to insulate if you will, is a good word, I guess is, is key to it. Let's talk any, what other kind of surprising results that kind of stood out to you? I think I, I think the obvious thing of, you know, ransomware is not going away.
So yeah. So that beca that became an obvious thing that, you know, whatever, whatever we say there is a shift towards more disruptive attacks as opposed to, you know Yeah. As opposed to sort of traditional sort of things.
And there was some, and again, there was some interesting research into security controls and, you know, the top ones are MFA and patching and all that sort of stuff. But some of those, the numbers of people that are using those technologies was surprisingly small. So out of, out of the population, only 37% said they're using MFA, which really?
Yeah, he's Was actually Quite, quite surprising in itself. So, and then, you know, and that was the most popular. So I think there's still a lot of, I think what they call security poverty in a lot of organizations where, you know, if you are not a top bank or a, you know, a multinational that's got a big organization that the challenges of, Of Trying to secure your, your company, if, you know, you may have still have a, a multimillion dollar company, but if you've got four security guys and a limited budget, you've still got a problem.
So, so again, there's, there's the whole piece about, you know, making sure you either do the basics properly and, you know, put the, you know, put the, the good prevention control measures in before, before going mad on spending too much on some sophisticated AI tools. So, so I think that, you know, some of these, some of these things are still, you know, are still, uh, sort of really interesting in there. Um, and so it gives you that, it gives you that sort of view of the, again, the culture within organizations and, you know, and, and where some of that responsibility lies and, you know, and what the impact then of some of those, you know, some of those attacks are on people.
So, so I think, you know, any of these reports, you sort of look at 'em and go, well, actually, it, it's then interesting to do another 10 questions on, on that particular subject. So, so I think it gives you that, you know, when you look at this income in sort of alongside some of the other research, so you look at it against like the World Economic Forum cybersecurity report, and you look at it against some, you know, some of the sort of other reports that are coming on there, there is a picture out there that, that sort of says, there's, you know, all the things that are obvious, there's not enough people that, you know, there's a shortfall in, in, in people you can recruit. The, the things that we've done over the last few years have got more and more expensive, but we're getting less and less return from them.
So there has to be a, there has to be this shift in, in culture and attitude within organizations to stop saying, you know, if we get attacked, the CISO gets fired, we've gotta get to the point where let's all work together to make sure that if we are attacked, we stay in business. Absolutely. Ag agreed.
And that is, so I think that's been a big shift in the security world over the last, even maybe seven to 10 years, is, uh, the, the, you know, the, the response versus the prevention aspect. You know, we're, we're o over time and outta time here, I'd love to talk to you more about this because Trevor, especially when you're talking about mid-level enterprises, you know, the, the fact is a lot of these people are relying on third parties for their, they're all SaaS. No one has a server closet anymore where they're running the exchange server, right?
Or, or something. They're all using Google or Office 365. All of those emails have two factor authentication, almost by default, you gotta like, shut it off not to use it.
Yeah. So why only 37% is because people think it's a pain, pain in the butt, and they, they just decide not to use it. com, I-L-L-U-M-I-O, they could go get it right off the front page.
Trevor, thanks for coming up here on techstrong TV today. I appreciate it. And best of luck, man.
You know, it's, it's a hard job, right? But you know how they, what they say in security is when nothing happens, you've done your job. So, absolutely.
Absolutely. Alright, keep it up. Thanks, Alan.
All right. And, uh, hope to meet you again. Thank you.
Bye-bye. Alrighty. Trevor Dearing, director of Critical Infrastructure Solutions at Illumio here on Tech Drunk tv.
We're gonna take a break. We'll be back with another interview in just a moment. Hello and welcome to the Techstrong AI podcast.
I'm Amanda Ani, and with me today I'm happy to have Steve d Angelis. He is the founder and CEO of Interra Solutions. How are you doing today?
I'm doing well, Amanda. How are you? Doing well.
Can you share a little bit about Interra Solutions? What services do you provide? Sure.
Interra Solutions is a artificial intelligence and applied mathematics company that performs, um, uses artificial intelligence to perform end-to-end value chain optimization and decision making for, uh, mid-size and large corporations. Wonderful. Well, our topic of the day is AI as a job creator.
So that's a, that's an interesting topic because, you know, we hear a lot of people, they're afraid about incorporating AI because they're worried it's going to take over their jobs and they're gonna be without jobs. Or, um, recently, um, someone came out and talked about AI was gonna reduce the wages of everyone. Um, so what are your thoughts on this, and, and why do you think that it is in fact, um, going to be a, a job creator?
Well, look, you know, with any transformative tech technology, some jobs are, are created in sub jobs or lost. But like with the first wave of, of technology in the 1970s and eighties, um, certain classes of jobs went away and many more classes of jobs were opened up. And I, I'm actually very, very encouraged by AI and a particular generative AI's ability to act as a net job creator, and quite frankly, act as a net middle class job creator.
Um, lemme tell you a little bit about why I think that, you know, as you think about large, um, tech firms like OpenAI and Nvidia and others, you know, creating data centers that are going to power the, that are gonna be used to, to create generative ai, large language models, those data centers have to consume electricity. Those data centers have to, um, build infrastructure to, to support that work. So if you think about open ai, um, and Microsoft investing $120 billion in one data center in Texas, right?
It's the amount of jobs that are created in that field, um, that are both infrastructure creation. Like we have to build a new power plant to have that power plant, uh, power, the, the, uh, factory that's going to manufacture the chips to then power the data centers that are going to, that are going to create the large language bottles. And all the jobs that are incumbent with that, whether it be the construction jobs or the raw materials used in the, in the construction process, the real estate that gets purchased, the housing that gets purchased around the, the data centers and others.
It creates a massive amount of infrastructure and, um, construction and development related jobs that attend to the industry, creating a whole new set of AI jobs, right? So whether it be, you know, people at the top of a pyramid who are kind of like PhD scientists who conceive of how the chips should be manufactured or conceive of how the, the large language model should be designed and, and structured to the software engineers, to the coders, to the people that generate prompts. There's a, you know, sort of a think about a pyramid of jobs that, um, you know, you don't have to be a PhD scientist from a leading university to, to, um, play in the generative AI space.
So I think there is a whole class of, of jobs that can be built that can be replacing, quite frankly, middle class jobs that over the last several decades were offshore to other countries, right? So you used to be able to earn a middle, middle class living by working at the US steel plant. Those jobs largely went away in the 1970s, eighties and nineties, right?
And they haven't been replaced. This is a way of replacing really good wage jobs, right? Where you don't have to have the same level of education as the PhD mathematician would, but you're, you can earn a great living by, um, getting trained on ai, um, generative AI skills that would allow you to, um, you know, put your kids through college, establish a great life for yourself.
And, you know, so I, so I'm really bullish about AI being a net job creator. So what are some of the degree plans that you would recommend for people getting outta high school or younger adults looking to further their education? What, what would you recommend would be the, the best degree plans to look at?
Well, it depends. If you want to go to college, then there's a set of college related plans in computer science, college related plans, and artificial intelligence applied mathematics, right? And then there are likely vocational jobs that you can learn to be a prompt engineer, you can learn to do to, um, to build AI related applications on top of the foundational AI model.
So, for example, there will be likely an entire class of job that are creating, you know, anywhere from sort of micro applications to much bigger applications that are used that are gonna be, um, uh, developed to have people generate prompts, to have people utilize the generative AI tools that the large tech firms are going to create or have created. And those kinds of jobs, you can learn vocationally. You don't need a college degree in computer science to be a prompt engineer, right?
You can, you can learn a, a, a skill and a craft to do that very well. And those jobs are in high demand right now. There isn't a trained army of people that can do those jobs safe.
So if I was a young person and I was not inclined to go to college, but I wanted to get involved in the high tech industry, right? I can go out and get a, a, I could go get vocational training in learning how to use OpenAI or NVIDIA platform, or I IBM Watson's platform. I could learn those, those, uh, tools and I could perform work that the more, um, skilled I get, I could keep rising up the, the food chain of, of jobs in the gen AI space.
Likewise, if I wasn't inclined to go to college and I wanted to become an electrician, you know, that is a highly skilled job today that there are not enough electricians in the market to do all the electrical work necessary to fuel the AI community, right? So if you think about the, the increase in in size and scope of our electrical grid that's gonna be needed to, um, be upgraded in order to handle all of this AI growth, there's gonna be a, a ton of jobs that are gonna be created both vocationally in the, in the construction related trades and, um, vocational training for generative AI and AI tools. And then as you go up the food chain in terms of jobs that would require computer science training or would require an, you know, advanced AI training or applied mathematics training, right?
Then, you know, those jobs could be consumed with people who are interested in per pursuing, um, you know, um, college and, and, and, and graduate school, um, degrees, right? So, so there's a, you know, wide range of jobs that are gonna be created that can, you know, power this, this AI driven economy. Those are such great points to bring up.
And I think you may be one of the first ones to talk about it, creating other jobs outside of just like near ai, the fact that there are all those other components. So, and I was just recently reading about, um, the data centers and, and the amount of electricity that's needed there, and how, uh, even my city is getting some new data centers coming here because the big cities can no longer support, they don't have enough electricity. So that is opening a lot of data centers around in different, different parts of the country and the world.
I mean, I think it's gonna look, I think it will create a huge amount of jobs that are, you know, traditional manufacturing related con construction related electrical, plumbing, you know, all this sort of construction trade related jobs. It will create this, this new class of jobs for folks that can, like I said, earn a middle class living, have a cool cutting edge job, like you could be part of the, the AI revolution, and you don't have to go to Princeton or MIT to figure it out, right? You can go and get a, a set of very, very practical skill training, and then you can evolve into that.
You know, a lot of the people that were at the early stages of the computer, um, you know, the pc, um, um, wave in the, in the late 1970s and early 1980s also didn't have college degrees. They were a class of, of tinkerers and hobbyists, right? In, in electrical engineering, you know, men and women who would, you know, were technically inclined and who would play with circuit boards and do things, you know, as a hobby, they evolved into an entire class of people that were the early computer science, um, folks, right?
And those were in addition to the people that were more classically trained at the university. But you know, like in any new industry, people who are willing to self-educate themselves and to be lifelong learners right, can learn the skill. It's not very hard, right?
You can learn it by focusing and taking classes online. I mean, one of the things that has happened since the first wave of the tech evolution is, you know, previously in the eighties and nineties, you didn't have the internet, so you couldn't take courses online. Many, you couldn't get free training, you know, online today, you can take courses at Harvard, at MIT, you could take courses anywhere, um, where Sierra offers courses that are relatively inexpensive.
You can take these, you know, these, this training, educate yourself and go out and apply it at a time where there's a market gap for this, for the skill that you have self-educated yourself on. Right? So I think that, you know, as we look to building up a, you know, a set of middle class jobs for younger people, they, you know, they, they, this will be the replacement, I believe, for a lot of the manufacturing jobs that have been offshore over the last several, um, tech, right?
So, so I think it's a really, you know, great opportunity. Absolutely. We're in an age where we can get so many opportunities for education at our fingertips.
I consider myself a certification junkie of sorts. Mm-hmm. And you mentioned, you mentioned, um, Harvard, they have free classes.
I I enrolled in one of their free classes a while back. Uh mm-hmm. So it, it's amazing all the opportunities that are there.
And also it makes me wonder, so as these jobs shift and the, the companies replace certain, uh, tasks with ai mm-hmm. Do you think that these companies should incorporate some sort of skill up programs where they cover the costs for their employees to skill up, um, in areas that are needed so they can keep those employees and shift them to other departments or tasks? Absolutely.
We do that today at interra. We take people who are, you know, we people who have a certain skill and they wanna evolve that skill into something else. We will invest in the employee to become, you know, trained in a, in an adjacent skill area.
Also, people are just curious if they wanna do that. You know, you know, companies will and should encourage people to upskill them themselves, right? And I think companies themselves will create internal certification programs, right?
So let's say for example, you are a data database engineer and you're really interested in gen ai, right? You, rather than lose a known good performer, you because that person wants to do something else, it is invariably less expensive to retrain that person into a job that, that, that they are super interested in, right? Because they will then think, wow, the company invested in me to get this new skill.
I'm working on stuff that I'm aspirational to work on. I get the skill that I'm excited about it. I'm gonna do a great job.
'cause I'm all psyched up about what I'm working on, right? And so I, so I think it's a win-win, but I also think it's a way for companies to build the, you know, to build a huge amount of loyalty with their employee base. Wonderful.
Well, if there was one key takeaway you could leave our audience with today, what would that be? I really think that you should not, people should not be afraid of a, of ai. Mean, look, there could be very potentially difficult things with AI when artificial and general intelligence starts to take off.
And we don't know exactly how that's gonna work. No, people don't know all the rules of a road. We don't know how to potentially regulat it effectively, right?
But ai, like any other technological, um, fundamental technological evolution, right, has the potential. And it will, in my opinion, fundamentally change the way that everything is, is, is done. Like, it'll change the way corporations operate.
It'll change the way that governmental agencies operate. And my net takeaway is don't be afraid of it. It will be a net job creator.
Don't worry about it, eliminating all these jobs, and we're gonna have, you know, robots doing all the work and pe it'll, it's gonna be a net job creator and po potentially a huge boom for the economy. All right. Well, thank you so much for coming on the show and sharing your insights with us today.
Thank you. And thanks to our audience. Stay tuned.
There's more. This is Textron tv. Hey guys, thanks for the throw.
We're here with David Weissman, who's vice president of Secure Communications for Blackberry. And well, we're talking about the need to secure not just our communications, but in particular the new administration communications. 'cause well, a lot of folks around the world are trying to listen in to conversations they probably shouldn't.
And that's probably lessons for all of us to learn now that we think about it. But David, welcome the show. Thanks, uh, glad to be here, Mike, glad to talk with you and your audience.
The administration of the United States is always a target for eavesdropping and all kinds of malware and stuff that goes on, but what do we need to be concerned about? And is it any more this time around than it was in any other administration? Yeah, I actually think, um, it's something we need to be more concerned about right now.
And it actually started about six months ago, uh, this higher level of concern because, uh, some of the, uh, bad actors got a jumpstart on new administration, and they actually, it's been in multiple Wall Street Journal, Washington Post, all across the press, salt, typhoon attacks. So, um, people have actually infiltrated into all of the US telecom networks, and they specifically were targeting the presidential candidates from both parties and their staff listening into the phone calls, reading their text messages. So, you know, the fact that we're going to admit new administration, uh, is an important aspect in terms of always sitting down and reviewing, you know, what your policies are around communications.
But in this case, we know, you know, there's already an aggressive effort in place. Do you think that, I mean, a lot of this salt stuff is pointed towards China and, and allegedly anyway, but I feel like this goes on everywhere and every country's trying to do it to every other country, and maybe the US is no exception. So, and maybe this is just something that's getting a little outta hand, or is this just the way the world is?
I I think it's the way the world is, and it is obviously been going on for a long time. Uh, you know, the US everyone's always trying to collect valuable information. Um, I, I think what's different now is that, you know, everything's done on mobile.
You know, go back 15, 20 years ago, you know, that wasn't necessarily the case. And so that's expanded the attack vectors. So it's easier for people.
You don't have to be as sophisticated to do these type of attacks before, you know, it was a very expensive endeavor, very complicated endeavor. And you typically were targeting very specific people. You know, they call it tapping the lines, right?
Uh, now what we've seen with the salt typhoon type of attack is you can target everyone en mass. And then the other thing that's different now is a lot of times people would take data and retroactively analyze it. You know, Hey, we'll go grab all the call records from this country for the past year and go see who's communicating with whom.
Now that it's embedded in the network. It's more real time. So you, you can know, hey, this party is calling this party right this minute.
And you can know that pattern. And then since you can collect voice data, you can collect message data, you can really target deep fakes and the identity spoofing at the right point in time. And with the other thing that's changed is kind of the emergence of all the AI tools, the level of expertise needed for a particular person, a particular entity to launch very sophisticated attacks is come down.
So, in other words, the cost of doing this is a lot lower, and so therefore, you know, the volume of these type of attacks, you know, becomes higher and the breadth of them becomes a lot wider. So what do we need to do to prevent these types of attacks? I mean, is it just a matter of increasing the level of encryption we have?
Or is there more to it? There's more to it. And you know, the first thing I would say is, you know, there's a lot of effort on, Hey, how do we better strengthen the telecom networks?
You know, how do they get this stuff out of their networks? Uh, my answer is, that's a good activity, but it's never actually gonna be fully successful. Uh, 'cause fundamentally, telecom networks are designed for connectivity.
That's the number one goal. Any phone can reach any other phone. And in that and ease of connectivity, low burdens on that.
And therefore, you know, security while important, it's, it's always gonna be secondary to that design goal. So if you look at, uh, cisa, the US Cybersecurity Agency, uh, they put out a report in mid-December with some very specific guidance, what people should think about, you know, in this environment. The first is, hey, everyone should use end-to-end encrypted communications.
So that's a solid first step that, you know, they mentioned there's things such as signals such as WhatsApp, you know, popular consumer apps that have been in encrypted communications. The second thing they mention is that you need to start to lock down some core security features on your devices. And this doesn't mean your devices had to be managed, uh, but there's things you can do to configure your iOS, your Android devices to better protect yourself.
And they give specific guidance. And then the other topic they talk about is, you know, identity attacks. And I actually think this is, you know, the biggest risk now, particularly with the deep fate technology.
And, and they give some guidance on things. I think this is where it becomes more complicated for the individual citizen to respond to that guidance. Uh, it's, it's not as simple as just download this app and use it.
Um, but they do give guidance of, Hey, be aware of this type of thing, be suspicious. But when I talk with cisa, they, you know, I say, Hey, this is great advice for the general public. Hey, if you're a government agency, you're a corporation.
You're someone in a sensitive role. It's really just a starting point. And, and, and they agree with that.
And, and, and so, you know, end-to-end encryption, think of it as important, but it's just a starting point. The other things that become very critical are more around control and the metadata. If you're using a consumer type application, somebody's mining that for business purposes to pay for the system, right?
So that's a, you know, a consideration, a business or a government agency has to take into account as well as whenever you have a public registration system, like a WhatsApp, like a signal, it's kinda like the phone network. It's for ease of connectivity, but that introduces additional attack vectors. So, you know, you need to look at not just end-to-end encryption, but how do I protect the metadata associated with that communication?
And how do I really have high levels of confidence in who I'm communicating with? At any point? Are we reaching a point where maybe I don't trust who it is on the phone or 'cause of these deep fakes, and do I need some other way of verifying who is on that call for that matter?
You know, like, I know it's you because there's two other people in the background here who say so, so, yeah. Yeah. I, I, I think we're already at that point, right?
It's, you know, what do you call it? Trust, but verify, I believe is the phrase. Uh, but you know, that's where, you know, crypto cryptographic identity validation techniques and things like that, you know, come into play.
But the other thing is, I think we might be moving away for, you know, very sensitive communications. We might have to move away from the model of using systems that are broadly designed for anyone to connect to 'em, to more closed down systems. So it's kind of a, it's kind of a step backwards from the relentless, uh, uh, you know, drive of connectivity ev everywhere and to anyone.
And to kind of come back to more so more closed communication systems, I think this president has some specific preferences for devices that he likes to use. And how does that factor into people's thinking about security? Because, uh, not all these devices are equally secure.
So there are some folks who would say, you know, back in the day you had to have a Blackberry phone because that was a more secure mechanism, but now everybody's got all kinds of different phones. What role does hardware play in this conversation? So I think hardware and the operating systems, you know, do play an important role because, you know, what we've been talking about with salt typhoon and this type of thing are network-based attacks, but you still have a attacks on the devices, people trying to put malware on the devices, that type of thing.
So, you know, I think couple of things. One, supply chain becomes very critical. You know, is this truly a, a trusted supplier?
Um, you know, is, is the way that you got that phone, do you know, in the chain of custody? And so obviously if you're the president, you know, that type of thing is being looked at on a regular basis. But also, you know, device management, you know, whether it's self-management of, you know, set these policies, which, you know, depending on your attention span may or may or may not be effective, or whether it's, um, you know, make a mobile device management type of systems that automatically set those.
But that, that's important because without those type of protections and policy checks on the device, even a device that you totally trust the vendor, you totally trust the supply chain is, you know, vulnerable to external attacks. Is AI gonna play a role for the defenders? We're clearly seeing that the attackers are harnessing it, but how should the defenders think about maybe using AI to help themselves?
Yeah, absolutely. So I think one is, you know, there are AI tools that can analyze video, that can analyze audio and tell you if you're more susceptible to, you know, a deep fake. Um, and, and so, you know, building some of these type of tools into the networks, into the communication systems is an effective approach.
Uh, the other way is just as I mentioned, the bar is lower for launching, uh, you know, broad scale attacks on the communications network. The bar is also lower for being able to analyze what's going on and detect patterns that could indicate that attack. So I think the AI tools can allow a lot of automation to, uh, you know, counter the offensive attacks, but it's always gonna be, you know, cat and mouse, right?
And it's, you know, the models learn, they change, they evolve, but you, you, you have to use it on both sides of the equation. As we look at all of this, it seems like to your earlier point, um, if the cost of launching these types of attacks continues to drop, you know, are smaller countries and smaller organizations gonna start doing this? I mean, where does it end?
I, I think at the end of the day, we, we will get to the point where almost everybody needs to do this, you know? Um, but from an organizational viewpoint, you know, we're already getting a lot of inquiries from, you know, relatively small companies, you know, dozens of people type of companies saying, Hey, I don't have all the tools in a large company or government would have, but, you know, how can I, you know, what can you do to help me? And so I think there's awareness of that.
And some of the work that SIS is doing is they're trying to find, provide pragma pragmatic enough guidance that even an individual on the street can do some self of hold protection. So what's your sense of the probability that sometime in the next four years, there's gonna be some rather embarrassing information leak because somebody hacked into somebody's phone? Oh, about 100%.
In fact, I think that data's already out there. Someone's just waiting for the right type. And The other thing I would mention is we should keep in mind that this data's already being collected in mind.
And, you know, they, and people don't change phone numbers very often. You know, you usually you'd have a phone number for decades, often 'cause it's a hassle to change. So the data's already out there.
And if different people come into different roles, now that data can be put to use in a negative manner. I mean, we hear a lot about quantum computers, but right. Those folks are already harvesting encrypted data that they intend to someday decrypt.
And I'm sure it may not be as valuable as it is today, but it could still be rather embarrassing, right? Uh, absolutely. You know, store harvest is, you know, a well-known technique.
I think it's already been going on for a while. Um, you know, don't know the exact timelines on, you know, when somebody actually would be able to, uh, break that encryption. But that's one of the reasons that, um, particularly for communications encryption, uh, quantum resistant algorithms are being applied now for, uh, key exchanges specifically to, uh, mitigate the store and harvest challenge.
And NIST has put out algorithms for that. Um, NSA and other agencies have, uh, put out guidance to the, um, tech community and to the government about, you know, when you need to start doing this stuff. I'm still trying to figure out a little bit about what's the tail and what's the dog here, and is it gonna be the end customers that drive the carriers to put better technologies to encrypt things and protect them in?
Or is it gonna be the carriers who are drive that 'cause they're sick of, um, getting hacked and then having all these difficult conversations with government officials. I mean, I'm trying to figure out which dog is the lead in the sled. Uh, it's, it's gonna be the consumer.
'cause there's, the carriers are never gonna be able to put enough security in place in a way that's unintrusive enough that it doesn't defeat kind of the purpose of their networks. Plus that's very, to be very costly. So it's gonna be the consumer saying, okay, we've got this network.
I need to use the network, but I need to assume any data I put over that network is at risk. So I need to protect that myself To that end. Does that make this whole thing more expensive?
Or are we willing to pay that cost? Or is there some way to get at this without necessarily increasing our costs? There's different ways to look at cost.
So, so one is what's the cost of, you know, of losing that information? The other is, well, what's just the cost of, you know, protecting my communications? So I think a, as a just an everyday citizen and everyday person, it's very low cost for you to adopt an encrypted messaging app.
And that's gonna move you pretty far along, uh, as an organization. Um, there, there's cost to setting up higher levels of protection, but I think those costs are relatively minor, uh, when you consider the cost and the implications of large data leaks. All right, folks, you heard in here data leaks are coming, they're gonna be embarrassing and it might be something of a train wreck, but hey, the very least, we'll learn some valuable lessons.
Hey David, thanks for being on the show. Thanks. All right, I'm back to you guys in the studio.
ai video series. I'm your host, Mike Bezu. Today we're with Lauren Hassan, who is AI officer for CoreLogics, and they just bought a company called ea and he's gonna explain the relationship between these things.
But the new company is called CoreLogics ai, which is an arm of CoreLogics. Lauren, welcome to the show. Thank you, Michael.
Thank you for having me. All right, so explain to us how this acquisition came about and how did these pieces all fit together? Absolutely.
Um, so what we've done in por, you know, we started actually before AI was called back in 2019. Um, and we sat on the mission, like we realized that on one hand AI is extremely powerful. We all know that by now.
Um, and with that we also know that it's very, very risky. So we realized there has to be some human oversight and control so that we, you know, human beings, society companies can actually rely on it. Uh, and that's how we started aporia.
And over the time we built our platform to provide full observability for AI systems and AI applications as well as guardrails for this system. So the companies that are using these technologies can do it in a responsible way. I don't think a lot of people understand what observability is and how it applies to ai.
And then, you know, we can then connect the dots back to, you know, how these things might then be used to govern this stuff. So walk us through it a little bit. Absolutely.
So we've all been using applications and software, right? And we all know that sometimes, sometimes, um, it might not work. It might have a bug or something could break down.
For the companies who develop these applications, they need some way to identify these issues, you know, as soon as possible so they can mitigate any, you know, potential negative outcome. Um, so observability is really providing the means and tools for these developers to constantly be in control. Things like the monitor, um, in an ICU room, right?
Like he can see there's always a heartbeat. So essentially observability systems give you a heartbeat for software. Now what we've built is this heartbeats monitoring system, but not for traditional software, which already, you know, there are quite, um, wide variety of companies that provide solutions for that, but rather for AI applications that could e eliminate, make up fact, um, you know, um, um, perform or act in an irresponsible manner or unethical way.
Um, so this is what we've done. And then how does that get used to build the guardrails? That is, are those guardrails just code that I'm writing or are they themselves AI agents that are trained specifically to protect other AI models and agents?
So it's a tricky question, right? Like on one hand, I, I, I wanna, I wanna tell you that yes, there's 100% deterministic, no AI involved. Um, and honestly like when, when we started, you know, that was our main approach.
We'll make it as deterministic as possible. Uh, but as time went by and as we worked with more use cases and processed more data, we realized, okay, we have to include ai. Um, and the way we do it is really, we built a very unique detection engine that is built on small language models or s SLMs.
So if Chad GPT is like this massive hundreds of billions parameters language model, we've built an engine that is built of multiple small language models, each one specialized in the specific area of issues or challenges in the ai. So you've come to the heart of the challenge that I think a lot of people are having is so many of the processes, especially in it, are deterministic and the AI models are probabilistic. And so there's a chance that the AI model is not going to pursue, present the same result the exact same way every time.
And people are expecting that it will do exactly that. So how do we kinda incorporate something that is probabilistic and adds value, but to a deterministic workflow so that we can figure out, you know, what's reliable and what may be the best guess, Right? So I think it's all about kind of aligning expectations with the users and with us or society as users of these apps, right?
Uh, because if we do expect, you know, CHE and this kind of AI applications to be 100% correct, even in the cost of, you know, they would make up something, then I don't think it's realistic to get there. But if we kind of limit the boundaries, right? So the way I like to think about it, AI is like this crazy machine or crazy monster, um, that moves around and is doing all sorts of things we need to have and draw some boundaries in which we say in these areas our, under these subjects, for example, the, we trust the AI to provide a reliable trustable answer.
Okay? So let's take an example. Um, let's say we have a customer chat support, right?
That aims to support customers when they have an issue. Um, and let's take an example company. com, right?
So it's okay for that chat bot to answer on the subject that relate to purchasing an item with Amazon, um, I don't know, maybe refund policy and so on and so forth. But as we get kind of further away from this main subject, the chances that this AI agent is going to provide a correct answer is reducing Now without any proper guardrails mechanism, the error will operate, it'll continue to output something, even if it's completely far off, right? Even if you'd ask, Hey, should I buy Nvidia stock?
Right? Like, I think today it becomes a very, very interesting question. It would answer it even though it shouldn't, right?
So providing doorbell is kind of for us human beings is how do we limit it to a known region or a known, um, list of subjects that feel more confident with, if that makes sense. Mm-hmm. Who should be in charge of the guardrails and observability?
'cause sometimes I feel like if I ask the data science team to go do this, am I not essentially asking the proverbial fox to guard the hen house because you know, they're gonna have a bias opinion in the first place. So do we need like a third party here to kind of be the, the overseer of the observability, as it were? I, I think we have in, in total, uh, like three different parties that should be involved.
Uh, we will focus on the should, uh, because unfortunately we're not there yet, but first and foremost government, right? Like the governance rely, are reliable to the safety of all of us. So regulation, rule system enforcing and making sure that every company that adopts this technology is in safe and responsible way.
Um, then the leadership of these companies, now, it's very nice to go outside and say, Hey, we have this, we've brought this new AI capability into our system. But what happens when later on you get on the news with someone who committed the suicide due to their interaction with an AI chat box, right? Um, and lastly, yes, as software engineer, as data scientist to actually build these kind of things, it is important to be aware of that, not only from the safety part, but also how you make it reliable.
I think, you know, uh, building something you wanna ensure it works really, really well, it's really accurate. You wanna be proud of it. Um, so having proper guardrails and mechanisms against these edge cases is just, you know, I think mandatory and part of this.
So these are the kind of the, the triangle of government leadership company or corporate leadership with practitioners that should all collaborate together to ensure safety of ai. Ultimately, what will be the relationship between the large language models and the small language models you discussed? Um, will the small ones outnumber the large ones eventually and they'll be the things that we're using to drive the agents we're gonna build.
And I guess if they're smaller and they're more narrowly focused, will they be more accurate? Does that make sense? Yeah, it does make sense.
Um, I think it's not if they're smaller, they're more accurate, it's kind of, if they're smaller, they're cheaper, it, you can more easily fine tune them and you can easily achieve something that works really real well. Uh, while with the large ones until last week, you need to be an o opening the eye or meta right to, to have something like that. Uh, I think the entire game has changed in the last week with dips sake announcement.
Uh, right. And, and as this field is constantly changing, this is actually why you constantly have to have the ability to observe, monitor, and track how this system behave, whether they're small or large language model of their open source or commercial. So you Believe that we are on the cusp of some less expensive way of training these AI models.
There's a lot of controversy around the, how this was all done, but um, and I'm not sure anybody's had any way to validate or test that, uh, claim that's being made by, uh, the folks outta China. But, um, what's your assessment of that whole conversation right now? First, I think that the advancement by dipsy with the R one model is no less than amazing.
And, and great for us as AI community, it takes us really, you know, few steps further, uh, on our way to a GI. With that, I will say I think, um, there's a bit overreaction in the market and the way people perceive it. Um, yes, it is a game changer.
Yes, it is changing the playing field. Um, what I'm actually most excited about is by the fact that the cost to run these models, you know, got produced by 30 times, uh, or so, it suddenly unlocks a lot of potential applications that, you know, a week ago were just considered too expensive to make commercial sense. Um, so I think in general, it's, it's all good news.
Um, how the market is going to react. I think, you know, we we're all set and, and interested to see Regardless of the hardware side of that equation, um, is the victory here for open source. And basically we have now a mechanism where open source can keep pace with commercial developments and um, ultimately bring down the cost and to your point, make it more accessible.
There are definitely advantages for open source in, in general as an approach. Um, but I, I do wanna point out something here, like there's a lot of buzz about the fact that, um, Dipsy is open source and llama is open source. And yes, it does allow us to build on top of these models or, you know, to take them as a base model and further optimize them to something new and even better.
Uh, but we need to remind ourselves that this is not completely 100% open source. It's not like we have all the base data that was used to train these models. Um, so there is a kind of small caveat that we need to remind ourselves, uh, with that.
So is it a huge leap versus commercial models? I think, um, I think it's an interesting question. Uh, I'm not sure yet.
What's your best advice to folks? 'cause I think they understand that they, uh, wanna take advantage of ai, but there are governance issues and they have to figure out how to operationalize it all. How do I get started?
So I think when you start an AI project or multiple AI projects across the organization, it is important one to set clear goal and short milestone. Like what is the first deliverable we wanna produce out to the market? And once you get to these MVP or POC working in your environment, um, really you have an evaluation or observability system in place even before production, just so you can actually test and ensure you are going to, to succeed in production.
Uh, just to share with you, like usually when we meet with different accounts and different enterprises, what we hear is that they have about three hundreds different use cases for ai. When we talk and ask like, Hey, how many of them are actually in the works? The number drops to about a dozen or so.
And then when we ask, interesting, how many of them are actually live in production? This is where you see people literally changing colors with one, two, at most. And, and the reason being is building something became with, with gene AI and elements became quite easy.
But to get to the point from working 80% to 99%, something that I can actually rely upon with my brand, with, with our name in production, there's a huge gap to get there. And evaluation and observability and proper testing is a key to get there. All right, folks, you heard it here.
Just 'cause we have AI doesn't mean that we don't throw out all our fundamental principles of which observability is one of them. And if we want all this AI stuff to work as advertised, we better know how it works. Hey, Lauren, thanks for being on the show.
Thank you very much. All thank you for all watching Love. Latest episode of the Techstrong AI video series.
You can find this episode and others on our website. Until then, we'll see you next time. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hey everyone.
Welcome to DevOps Unbound. I'm Alan Schell, CEO and founder of, uh, tech Strong Group. And DevOps Unbound is a, uh, semi monthly, which means it's twice a month, I think, uh, video series that we've been doing that for about three years.
And we explore every nook and cranny of the DevOps universe. Um, for three years we've been producing and putting on this show in partnership with our good friends at t Tricentis, who I couldn't think of a better partner and a partner on this kind of thing, where they, if you're not familiar with Tricentis worldwide leader in continuous testing and so much more today. Um, and as I said, we do these shows twice a month, and then maybe once a month or once every month and a half, we do what we call a live round table version of these shows where we invite you, our studio audience to come in and participate and kinda lead the discussion.
Unfortunately, this is not a live one. This, this is a, a prerecorded version that we did here at Techstrong Studios. But, um, you should pay attention.
Well, we'll, if you ever go to Tech Drunk, do tv and you can see the schedules of our live events of, of these. And we'd love to see you at the next live round table. We do.
Actually, Mitch, while I'm talking, maybe if you can grab a, a I'm a date and when I come to you, you can even we'll do that. Put a little plug in. But, um, before we come to Mitch though, besides thanking Chiantis, I want to introduce what this particular episode is about and introduce our panel.
Today's episode is API first and API testing. We're going to explore all things around API here. You know, API traffic represents the majority of the traffic on the internet.
I've seen numbers as high as 83%, which is the last one that came out of Akamai. Uh, I've seen Cloud Flare. I think they had it around 70%.
So no matter who's statistic you go with, it's still a majority of the traffic on the internet. Um, we're gonna talk about, you know, API first development, and we are gonna talk about, um, API testing and, and more. Um, our Cracker Jack production team has already gotten me the date of for our next live round table.
And if you're interested in attending this, mark your calendars now. It's on July 24th at 11:00 AM and we're gonna be talking about adopting a DevOps culture for cloud migration success. Is there such a thing as cloud migration success?
We'll talk about that July 24th. Let's stick to APIs today. Um, for now though, let me introduce to you our, our panel panel.
Um, first I wanted, well, he's a, a repeat meaning he's been here before with us. I wanna introduce you to Chris Kmo. I hope I pronounced that right, Chris, Chris, tell, tell our audience a little bit about yourself, if you don't mind.
Thanks, Ellen. Yeah, so I'm Chris Kmo. Um, for the last 12 years I've been working specifically in the API testing and service virtualization space.
Um, joined the Tricentis team recently, kind of tasked with the responsibility of uplifting and modernizing some of the service virtualization, uh, tooling. Um, and as a natural part of that, there's, uh, some API testing, uh, pieces of it. But I've been kind of enjoying that and having fun, imagining what this tooling could look like if we started from fresh.
So happy to be here. Uh, happy to have you on Chris. Thanks.
And welcome back. Next up the kind of queen of the ball here. She, you know what?
I, I just feel like she should move to Florida already. Um, our good friend Tracy Reagan, who's also a CEO of Deploy hub and many other things, cra. Tracy, why don't you introduce yourself?
Well, Alan, thank you for having me here. I always enjoy this. It's, I I feel like I should have a PhD though on some of the topics that you bring me in on.
Uh, well, we do, do exist about sometimes, Sometimes I've kind of blown, I've blown myself away by understanding more than I realized, I guess. I've been in this business for quite some time, to be quite honest. Um, I started at, as a programmer on Wall Street, started a company called Open Make Software at Automated Builds.
And now I am the, um, CEO of Deploy hub, and we're doing an evidence store around security and DevOps data. I've been involved in the Eclipse Foundation, the open SSF, um, and the, the Continuous Delivery Foundation, and have embraced open source for quite some time and have some opinions on API first. And so I'm happy to talk about it.
Doesn't surprise me. You have some opinions. Tracy.
Thanks. And, and welcome. Our third panel member is Chris Lindsay, and this is Chris's first time.
I haven't yet told him of what first time guests have to do when they first come on here, but we'll, we'll tell him in a little bit. Hey, Chris. Welcome.
Introduce yourself to the audience, Alan. Thank you for having me. My name is Chris Lindsay.
I am an application security evangelist over at Mend. My job is just to talk about application security in general. My history, I wrote software for 35 years, so been there and done it in the trenches.
And APIs are near and dear to me, and I've been in security for over 15 and plus. So thank you. Good.
And welcome. Always nice working with the folks at Men. Um, our last panel, well, he's not really a panel member, but our last person I'm gonna introduce is my co-host for DevOps Unbound.
He's our CPO here at techron. He's also a CTA or Futurum Group, which is a company we are in the process of combining with. Mitchell can explain what the CPA role is, but let me introduce you to Mitchell.
Ashley Mitchell. Take it. Good to be here, Alan, and what a, what a group.
Um, what a fantastic group. Yeah, I'll, I'll be your panelists. I'll be your co-host.
I'll be the the chat guy. I'll be the bottle. Watch, whatever you need me to be, Alan.
I'll be So no. Just recently, as part of our, um, acquisition process with Futurum, my role's expanded in addition to the doing the analyst work that I was doing with text run research. It's, uh, I have a new, you know, we had to create new, new title, right?
But I'm one of, uh, five people that are Chief Technology Advisors, which is kind of a, a glorified analyst on steroids doing advisory work and analyst work and, and things like that. So it's, it's a lot of fun that, that, uh, being part of the acquisition and, you know, still both, still working with all my old friends as well as new friends. So it's good to be here with everybody.
And yes, I started as a developer and yes, I've designed some really bad I APIs and a few good ones. So we have some lessons that, that I can bring Learned more on the, on the bad ones. But anyway, um, thanks Mitch.
And welcome. So, as I mentioned, API traffic today represents a clear majority, if not a critical mass of traffic on the internet. And I'm gonna ask someone to explain what that means to the lay folks out there who may not, we don't have that many lay folks, but people who may not understand I'm not, it's, it's either API generated or API to API kind of thing, or, or, you know, somewhere along the line there's an API involvement there, that traffic.
Um, but, you know, the effect that a API first mentality has had on the development process in general on testing and security in particular is, has been pretty profound, right? I remember the first time, like this whole thing became clear to me. I had that eureka sort of moment.
I was at a ca world, so I should should give you an idea of how long ago this was. Um, and, and, uh, they had done an acquisition, a company based in Texas, and the folks from that got up and said, you know, it's an API driven economy. And I was like, wow, an API driven economy.
What, what the heck does that mean? And I, you know, I I, I learned more and I, I dove in with it and I realized it was an API, you know, we were moving into an API driven economy when we talk about, you know, digital transformations and, and stuff like that. And, you know, I think the next logical extension to that was API first, right?
That's the default. And, and of following from that, of course, you, you, if you're gonna have that kind of API footprint, you damn well better be doing API testing, right? To make sure this stuff works and make sure, and then in the last four, five years, API security has become paramount in many ways, right?
API security is replacing web application firewalls and stuff like that because WAFs, that API traffic kind of flows under the radar of the wa right? And so we need something else to kind of make sure our APIs are secure and locked down enough to make your head spin. Um, Chris C, if it's okay, right?
We'll say Chris C and Chris L Chris C why don't you take a crack at explaining in your mind what API first means, what we, when we use it in this context. Absolutely. And, you know, um, to get there, I think I wanna talk, I wanna touch a little bit on that API economy, because that's really like, first and foremost for me, what's driving the API first initiative and just, uh, unironically About an hour ago, I was just talking with ESRI, um, they're the guys that do a lot of the map, the MAP APIs.
Mm-hmm. Um, they were kind of behind MapQuest back in the day, and I was talking to the guy and he was saying that before that, way before that they were the ones that powered the Thomas guides. You remember those things that were under your sheet Sure.
In Your car, right? We Were a logistics company, right? We, we, we, we had a database full of rich maps that we would then compile into a book.
And we were a logistics company. Let's ship them. And then eventually, at some point, that just went away.
And now they are an API first company. They sell their API to Google Maps and to Apple Maps. And so their entire economy is based around their map, API.
Mm-hmm. And so, uh, to me, that's what the API economy really means is, is it build businesses are building their brands. And a lot of what's powering that is the API.
And if that is the critical path to your business, you really have to have an API first mentality when it comes to building them, securing them, testing them, validating them, and really, most importantly, securing them. And so that's to me, what API first kind of means. Jump panel thoughts on that?
If I can jump, I'm gonna jump in on that too. I love how you set it up, Christy. Um, 'cause you think about it, historically, APIs were the things you might add for the exterior of your application or your software to kind of the Ingress and egress.
But everything inside of it was your app, right? And, and A-P-I-A-P-I first is just the opposite. Your app is all run through APIs.
Even if you don't have a gui, your ui use your interface. Um, and matter of fact, if you do have a U ui, the UI talks APIs to your app. So the same APIs that you might share with, um, providers or people that are buying your service.
Matter of fact, your service may be just the APIs like Chris is talking about. Um, and in doing that, I remember APIs just getting kind of unwieldy and getting outta control just 'cause we added them where we needed them here. And how long are they gonna be good?
And do, do, do we, as they evolved, how do we grandfather old versions of 'em? And now we have whole philosophies around the lifecycle A of APIs and how you manage them. And they're, they think of, we think of APIs as the product because almost all, every app now is exposing those APIs either in a, in a microservices world, very heavily API or, or also to the external world, to people that are buying our products and services.
So I, I hope that does justice to what you were talking about, Christy. And while you know that, um, there are, I mean, companies do rely on external APIs. If I'm thinking about what our architecture looks like, we probably have 20% or 25, maybe 30% of external APIs.
But most of what we do is internal APIs. And building internal APIs has a, you know, there is some, um, and when I think of API first, I think about what APIs do we need, let's think about what that looks like. And I like to refer to, uh, you know, I preach often this concept of domain driven design and understanding what are your domains?
What APIs do you need? What are the, you know, what are the, uh, what are the connection points? What does that need to look like before you ever start writing an application?
But for the most part, we, you know, to, to be quite honest, this is not a new, um, concept. We try to do this in, um, c plus plus and common libraries. A lot of companies, uh, when I was working for Discover Card, we did a ton of work around initially defining what that com, those common libraries should be, should look like.
And that's really what APIs are. They're common libraries, what we can reuse. And really taking the time to understand what those high level domains are and what we need to create is super critical in building a, um, a true kind of API burst forward thinking model.
And that's because if you don't do that, and if you don't manage them well, and you don't communicate and collaborate well, everybody writes their own APIs that do the same thing. Mm-hmm. And that's what we don't there.
And that's what generally happens. And we've done, we've made this mistake as developers over and over and over. We constantly make this mistake, you know, everybody has their own login routine.
Everybody has their own error routine processing, everybody Oh. Has their own access to get the customer address. Um, so understanding domains and understanding how APIs should be structured within your organization and how you can break it out and allow ownership of certain domains is critical to an A API first, um, architecture.
I agree. I, yes. So, you know, the other thing I want to just tack onto it is, you know, what, what are your APIs doing?
What, what's the purpose? And in the old days, you would just write your software. You would be in a ui, you would be, you know, either, you know, web-based, where everything's all self-contained, and then you started pulling apart doing the APIs to now when you're developing software, you're thinking about it, there's multiple facets.
You have to think about, are you gonna expose any aspect of it for reporting or par uh, you know, business to business? Or, uh, you know, are you gonna be consumed by other tools internally, um, for, for any reason? Or, you know, what's the UI gonna be?
The UI In today's world, when you're, when you're thinking of an application, if you're thinking of just web, you're, you're being very shortsighted. Do you wanna go web-based? Do you want to go mobile based?
Or, you know, other technologies out there? And as, as Chris said, you know, talking about, you know, you may have an application that is nothing pure, but pure a, a, you know, APIs. And that's okay because it, again, it's, you know, just, it's all about the usage and what you're actually trying to accomplish.
Agreed. You know, when when I hear API first, to me, there's sort of a chicken in the egg question there, right? What comes before the API or is the API the first, the chicken And no, it's not the chicken.
I think first before you, you don't start with the API first. You start with sort of plan of, Hey, I, I want an application that does this, that, or this and this, right? And then we think about, okay, how am I gonna go about doing that?
Right? So I, I think the, the planning and, you know, laying out storyboarding, if you will, or, uh, designing of the app is, is first. But certainly once we get into that design, we start thinking about APIs and potential APIs, I think before we start coding, certainly.
Would you agree that, that that is the essence of API first, right? Before we even start coding, we're thinking about how APIs are going to make or break, or how they're gonna work within the app that we're designing. Yeah.
Because that, that's how APIs are gonna pay for themselves. You know, me as a young developer, I would've loved to had, you know, been a, you know, we talk about feature teams now, you know, instead of application teams, you have feature teams. Well, me as a feature team working on a particular, what would be delivered as an application, I get to go talk to other teams that are doing features, which means I don't have to write all those queries.
I can figure out what they already have, if it's a well organized API structure, and everybody can share those APIs. So that pace is for itself. It's, you know, APIs can save a whole lot of cash when it comes to development because you're reusing objects.
So a hundred percent. And it has to do with money too. Yeah.
Yeah. It, it does do that. If I could double that on that, what's just, just because the plan triggers me, right?
Is it immediately makes me go to the service definition, which I'm sure a lot of the season guys here are gonna roll their eyes, right? Mm-hmm. The service definition is not a plan, but a lot of organizations say, this is the beginning of the process, right?
Let's, let's write our service definition. Let's write our contracts. Let's start putting in place the actual semantics of what this API is going to do.
And what's interesting, if I kind of double click on what Tracy was saying about the domain, and specifically what Mitch was saying about sprawl, this creates a problem because you're not doing that upfront ideation work to say, what is the minimum set of APIs that we need in order to provide the value that will ultimately provide the money to our organization? And this leads to something which I'm seeing a ton right now, which is API and new API is the answer to everything, right? Okay, we got this new functionality, let's just add another API, let's add another API.
And before you know it, you have this massive API sprawl. And so I really do think coming back to the domain of, and the why and the, and, and, and the, the minimum set is super critical to this, to the planning phase before the service definition is even put in place. So you're saying we can replace the phrase, there's an app for that to, there's an API for that.
It's A P for that. Yeah. Yeah.
Well, you know, and, and Chris, the thing that comes to mind when you were talking about that is solid programming principles, right? So, you know, when you create a class, you create a method. The goal is, I've created it, I can add to it, but I cannot change it.
And when you look at APIs, you know, you may run into, I need a little bit more, or a little bit changed, or a little bit something. 2, you know, and and so on and so forth. And then all of a sudden, you know, to to everybody's comment here, all of a sudden you may have started off with, you know, 150, 200 API endpoints, and now you're well over a thousand.
Yeah, Absolutely. So I mean, it really, APIs, even though they save a lot, um, like microservices, it's complex. 'cause you're decoupling pieces.
And when you decouple pieces, you cram, you know, it's your, your puzzle now is in, you don't have, you don't have the top of the box to tell you what that puzzle's supposed to be. And you have all these components, all these tiny pus of pieces laying on the, you know, on the table. And you gotta figure out what it is that you're creating.
So if you don't Have this, the blast radius gets really large Tracy, right? Yes, it does. Blast radius.
Here we go. Um, But that's an interesting, that's an interesting aspect too, right? And it becomes that yes, I have this giant inventory of APIs and I may want to Chris's point, sort of just add incremental functionality to it and, and change its version number.
But in a lot of cases, the APIs are used by disparate teams. And so they might not know, uh, the, the major difference between the UI and the, and the APIs. The UIs are designed to explicitly tell you what it's doing.
You go to the screen, you get it, okay, I'm logging in, I'm creating an account. APIs will do the same thing, but they're not explicit. And unless you love reading swagger definitions, you can't immediately know what an API is doing.
And so that's where that, I think a part of that sprawl comes through is people go, Hey, I don't think this functionality exists. It's like, well, actually yes it is. It's a subset of this other API that, and, and so I think this is one of the challenges that I think the contracts and service definitions, and definitely to trace, uh, to Tracy's point, the, the conversationing around what exactly are these APIs for becomes paramount to an organization's success, Right?
Well, and as an API matures, then what happens too, just like you were saying, you may have certain aspects of multiple pieces of APIs, Hey, to accomplish this task, I have to hit seven different APIs to get all the data. And one API may take forever to run, and I just need one aspect of its data. However, a lot of it is actually tied to the same background or, you know, the backend.
And so instead, maybe I just create a new endpoint to pull what I need. And the next thing you know, again, sprawl, And it's a collaboration that will prevent the sprawl. Yes.
You have to have the collaboration. You have to be, if you don't know an API exists. And, and there's no way to find out.
You're gonna write it yourself. 'cause you might go, this is gonna take me, oh, it'll take, it'll take me 30 minutes to write it, even though that's not true. We do that as opposed to go hunt down somebody who's already written one.
So the collaboration is essential just across teams, much less really building out a collaborative API structure. Couple things there. First of all, I think that was job one of, in the API security arms race, when API security started becoming a thing.
I think the first thing these API security solutions were doing was saying, you, it's 10 o'clock. Do you know what APIs you have? Right?
Because, you know, the API sprawl gave us so many APIs, APIs, talking APIs, talking APIs, that most organizations really did not have a handle on what APIs were interacting in, in, and within their system or on their system. And let alone what their settings were, their security posture, et cetera. You can't defend what you don't even know is there.
Mm-hmm. And that, that was, you know, that was phase one of API security. I think it's expanded beyond that.
It's matured. But that was certainly the first, the first, you know, kind of thing about it. Um, the, the first part of, of, of API security, I wanna turn, you know, beyond the blast radius of API security of API first And talk about API testing, right?
Because, you know, that's the logical next step. Okay? So now we are going with an API first mentality.
We're gonna have these a APIs that are, you know, in, in the right from the, from the design phase. We, we are designing APIs in. But of course, these APIs need to be tested, don't they?
Um, you hope. And so you have to get into API testing, but yet I, when I hear the phrase API testing, I still think of, oh, I'm using APIs to do my testing, right? I, it, it, it sort of adds a layer of automation to my testing.
But no, that's not really what I think we're talking about. Yeah. I think most, Oh, go, oh, I'm sorry, chase.
No, no. Go Chase. I was, I was just gonna say, I think when we talk about API testing from a developer perspective, I think about functional testing and validation testing.
I don't worry about performance testing or security testing or load balancing or any of those other pieces. I assume somebody's gonna Automate that developer. That's, That's what we do.
Right? I wanna validate my endpoints. I'm gonna do my functional testing if that's good.
I'm going That security testing. Yeah. Um, Chris, Chris LI I'm hoping you have a different attitude towards it.
I do. I'm sorry, Tracy. It's okay.
My attitude is, you know, it's, it's a view into your system. And as such, you need to do multiple things. You know, I, I go to conferences, I see applications.
I talk to people I, I with, with penetration testing software. I enjoy going out and attacking and breaking things. I love seeing, you know, what kind of data I can get back.
You know, some systems, you know, you can easily break simply because improper security and proper logging and proper a lot of things. And so when, when you're looking at APIs from, you know, a, a a standpoint, there's multiple aspects that you have to consider. You know, the, you know, how does it perform?
Because I can come in and do a denial of service attack. If you have a poor performing, performing a PII can call it multiple times from thousands of endpoints simultaneously, if you have an API endpoint that shares data that it shouldn't be sharing, now I can steal data. If you have an API endpoint that is just not well put together, it it, it's very obvious from a security standpoint.
And so, whenever I was actually doing my, my development days and doing senior tech reviews, I would look at, you know, how do they perform? I would look at using tools to look at the payload as it goes in, as it comes out, what kind of things, time to run the time on the backend, on, on the database, all the way down to that level, just to ensure that, you know, is this performing? Is it doing what it has?
And, and beyond that, you know, you also have the security things that you can throw in there, such as SQL injection and, and other various things that can, that can happen. I'll stop. I can keep going, but, No, I get it.
Chris c you're the real tester here. What do you think? Okay, first off, I'm in the vendor space, right?
And so nobody knows less about testing than the actual testing vendors. But I will say this, um, I, I am encouraged that we're talking about development forward API testing. Because quite often in the testing industry, that's put firmly on qa.
And there's these really interesting conversations. Whenever we go to a, a first time API tester where they go, well, whose responsibility is it? Is it, is it the developer?
Is it the tester? Now we all know it's both, but it's at a spectrum. And the notion is that, Hey, I'm a developer.
I created a service definition. I should be able to hand that to the, to the tester. They should be able to ingest that and use it.
And the tester says, Hey, you're a developer. You're building the API, you should test it before you give it to me. And there's this constant back and forth.
And I think to both Tracy and Chris's points, there's different levels of testing that you do as it's maturing through the cycle. And the, and the first one to me is contract testing, right? I wanna make sure that my service that I'm building is not only complying to my business expectations that I've set forth for the, for the function of this API, but also that the consumers of IT are not going to be affected if I change it.
Right? And so, I don't know if anybody's really, um, uh, grasped onto, um, uh, uh, uh, contract testing quite like some companies like PACT have. But it's this, it's this really strong grassroots movement that's happening right now 'cause it's developer forward that basically says, I'm only gonna write into this test from a development coded perspective that are my expectations of an API.
That way I can continue to do what I'm doing and know that if the producer of the API makes a change, they're gonna run my contract and know that they've broken me, which fosters collaboration and communication. Those contracts are the seed for everything. Because you can mature those into greater and greater levels of more complicated functional and integration testing.
And then once you have all of those contracts, you have all the attack vectors that you need for your security testing. So I really think that this whole testing thing starts from the moment that first line of code is written against a contract, write the contract. But again, it's all predicated on whether the service definition exists.
Isn't, isn't also, 'cause I remember us using kind of contract with APIs in a little more general way before this, this movement you're talking about. And really a contract in that sense was here's how you use the API, here's the, here's the expected behavior in terms of how you interface with it, and here's the expected behaviors of what it's going to do when you use it in the specified ways. And I think to your point is if you go wacky and do some SQL ingestion, or you do something else and pass different parameters that aren't part of the API, it's not gonna respond or it's gonna give you an error or some, some definition that's out, out of bounds of the contract, is that still consistent with the movement?
You're talking the developer forward? I, yes. The contract is, um, again, it's an overloaded term as are many things in our industry, but it, to me, the contract of the API is the service definition that defines semantically and logically what this API is supposed to do.
And you can use that both as a human document to read, to understand, but probably more handing it to the business to to, to the, uh, to the appliance so that it can ingest it and create clients to actually communicate with the API. Um, that same, that contract needs to be tested. Is it semantically valid?
Does it, does it follow all of the, the, the spec definitions that we have for service definitions? Has it changed recently, et cetera, et cetera. Um, and then that, that component is then used to test the function of the API in its entirety.
This is a, this is a, uh, a second piece to that, which is I'm using the API in a very specific way, and I have complied to the service definition. I'm doing everything right. I wanna know if anything has changed, um, or if what I'm trying to do and what's critical to my business.
I'm Bank of America, I'm communicating with the PayPal, API, I'm only using like three fields of it. Don't change those three fields and do whatever you want with it, as long as you don't change those three fields. And if you do change those three fields, you gotta talk to me and say, I'm changing the three fields.
What can we do about it? What can we do about it? That's the, that's the difference between those two types of testing.
And there's something that happens when APIs aren't really tested well. Um, there is a trust factor that we have to always keep in mind if you're an API developer, uh, to make sure that you're doing that testing and that you're maintaining those contracts. Because what happens is, in that example that Chris just gave, that consumer may decide not to take on that new version of an API and that causes a DevOps nightmare called Drift, which means you have multiple versions of your API that are out in the world or being consumed internally by many different application teams that you have to support, maintain, and make sure are secure.
So the API testing if is so critical in building that trust so you don't end up with so much drift. You know, we talked about sprawl, sprawls a problem, but drift is as big a problem, if not bigger, when it comes to trying to secure the, the, the environment, Right? And then one of the things that I've seen is a lot of QA departments use automated, uh, regression tools, and their thought is, Hey, my, my tool passed it regression tested.
That must mean the APIs are good. Let's move on and let's, let's, let's, you know, let consider it good. And to both Chris and, and Tracy, you know, their point is, look, the contracts possibly could change internally.
Something could get added, modified a a definition may change. 0, and now you're version 30 and you can't get off of it. And by default, most people who are writing APIs are not logging or doing any metrics.
And when you're not doing any metrics, you're not knowing what API endpoints are being used, how they're being used. You don't know the details. And so the problem becomes, you know, you're sitting there, you're creating drift sprawl, and, and you don't know that, hey, guess what?
Version one is still being used, but versions two through 15 aren't and haven't been for a given time. And so those could be deprecated. So instead at, at a certain point, depending on design and what's going on, you may have to go make 30, 40, 50 changes, you know, spread that same change out across all the API endpoints where if, if you were paying attention and, and doing good development practices, and, and, and analytics would tell you, Hey, you know, you have people that aren't moving off version one, why?
Ask the why, what's going on there? And then determine, you know, can, can they move up? Or is it just a, a breaking code change for them?
And if it is, you know, how do you deal with that? And, and how do you work with that? Because at a certain point you need to move forward.
So, but this, this is, this is a bigger problem. You're touching on Chris, right? This, this is the, the sprawl aspect of it.
We see cloud sprawl, API sprawl, you know, are all developers and IT people hoarders at their core, maybe because none of us seem to want to delete anything. Me, I, I find a certain joy in like cleaning out my closet and throwing out things that, you know, I have a rule in the house. If it hasn't been used in the last year and a half, we're probably not going to use it.
There's better things to do with that space. Do we need to, and that's, by the way, that's something we could automate with APIs. And if that forces people to move off of version one to version five because they've been sleeping through the last four upgrades, or refuse to do it, so be it.
Right? Apple people used to knock Apple for that because they did, they stopped with the backwards compatibility for five years old software. If you didn't have the last version or two back with you, you couldn't run the latest stop.
Mm-hmm. You know, Microsoft stuck to that backwards compatibility thing for too long, in my opinion. Should we, is good API hygiene, meaning adopt something like that?
Wow. That's a, a cultural shift. Because I do think that the developers tend to be a bit order as you explain.
Yes. Mm-hmm. I mean, think about even, um, building a cont a container for an API, you're probably gonna bring in stuff that you don't even need because you don't, you're not sure if there's a dependency on it.
Um, which is part of the, our current security problems, um, is these transit of dependencies and what APIs calls what API, uh, becomes more of an issue. So it would be hard to get folks to start really cleaning house. You think About SBUs, you, you mentioned SBUs.
SBUs. I was not gonna say bombs, but, Well, no, we're not S okay. But I do think that AI could help solve our blast radius.
Okay. Blast radius. It is.
So we're talking about blast radius. So we could use AI to do that. We could use AI to limit the blast radius, but shouldn't we use AI to just limit API sprawl And drift?
Yes. And drift. I mean, it's good security, I think.
Well, and AI is doing so many amazing things today. You know, from a standpoint, when you're looking at using AI against your APIs, you know, it now creates a lot of, you know, background. It, it gives you a lot of visibility in the things that you didn't have before.
It makes it so much easier to, you know, to connect, to get that information, to know what's happening behind the scenes, and to be able to detect anomalies. You know, you may be up and running and, and AI can go, Hey, guess what? I'm noticing something interesting.
Or, you know, if you are doing logging or whatever, AI can also pick, you know, pinpoint and go, Hey, wait a second. Something's happening. Tracy, you know, she, she lives here.
And somewhere on the other side of the globe, Tracy logged in again. Problem. You know, I wanna, one I wanna bring up, Alan, is there, there's also kind of some, we're talking about some challenges with managing this whole ecosystem, right?
Of APIs. One of the things I think's really great about APIs, Tracy, you were talking about c plus plus remembering back in the day of, of stubbing, uh, stubbing off methods. You know, we would like, here's the structure and I don't have time to write that yet, so I'll just put a return in there and pass some data back.
And, and, and now we have such a better way of not just stubbing, but actually creating the API creating some logic behind it. We can have, you know, some tests actually built into that code that isn't fully been written there yet. Um, but maybe it's generating responses, right?
That we wanna to, uh, be able to test with as part of that API as well as we add the, the function, the service of what it is. And so you can, I think you can build software faster through this API first approach. Um, 'cause you're not managing a big structure, you know, a big object structure with parts stubbed out and some parts not.
And who's got what part of that tree? And I'm using this version of this microservice, this, this API, and it's, it is, it's just step there. It's great for building and testing, and I'm gonna replace it with the, with, uh, Chris's, whichever Chris wrote it, Chris, CRL.
And, uh, you know, I can continue to just evolve the app that way. Agree. Don't agree.
Am I, I agree. Fun doing funny stuff in Colorado, or I Gotta, I gotta jump in here. Like, one of the things I said at the beginning with my introduction was that I, I, I am over two products, right?
API testing and service virtualization. I don't get to say this very often, but service virtualization doesn't get the love that it needs, um, in our space. And I think that from an API first perspective, it is massively important for jump starting, you know, any API initiative.
And to kind of wrap this into the sprawl and the drift thing, observability can be a huge benefit here, right? Because what, what we're finding when we're going to a lot of our companies is they're like, we want to do this. We wanna go API first.
We wanna test what we existing, what we currently have. We wanna understand what people are using, but we have no idea what APIs we have anymore, right? Because everybody's kind of cycled out, et cetera.
And, um, observability allows you to not only observe the system under motion to understand the actual APIs that are there. 'cause guess what? A lot of those internal ones that, that Tracy was mentioning earlier, they're not documented.
There's no service definition for them. And the observability is the only way you're gonna pick up on those. And that same traffic can be used to generate those initial service tests, those initial VIR virtual services, which is so much more valuable.
'cause it's not just a dumb stub. It's one that actually simulates the business logic and the, and, and, and, and the expectations of the system under motion. And then you use, and you kind of build your new API scaffolding around that.
And it's a great way to get started is leverage your existing observability for service test and service virtualization Creation. I love that term. Your service under motion.
It's a great visual Service in motion, Under motion. So it's in motion. Yes.
No, no, it's under motion. It's great. Running something, an eighties song, it makes sense, right?
Yeah, it does, it does. There's another part to this too, and that is the API security. API sec, uh, part of security is one of the first things is the API discovery.
So if things are going through a proxy or something that's, you know, flow flowing through, um, whether you call a firewall a proxy, whatever it might be, that's another collection point if you will. Like you're talking about Chrissy, we're in, okay, what is that? You know, there's 25 things that happened today.
Nobody knows what that thing is or didn't know somebody else was using that way. We didn't know that was going externally. So that's another kind of data point you can pull into figuring out what's happening.
Well, hey, I had mentioned that earlier. You can't defend what you don't know. You most people don't know what APIs have.
Well, and, and from the sbo I'm sorry, from the SBO piece of it, you don't know what dependencies that API is calling into play here. Chris, Chris l you got something to say? Go ahead.
Yes, yes. So, you know, when, when you're looking at the APIs and, and the data coming in, it's just like a ui. You have no idea what kind of crap people are gonna throw at it, what length of information people are gonna throw at it.
What kind of information is, is inbound outbound? Because, you know, crafting a good attack, you know, you, you can do things and, and, and skirt under the radar depending on design. And, and I love the, you know, what, what Mitch was saying, you know, the very first thing, if I'm gonna come attack you guys and look at what's going on, you know, I'm gonna figure out what API endpoints you have, I'm gonna figure out what's going on there, and then I'm gonna start, you know, overloading 'em, seeing what I can come up with.
And it's, it's amazing how many people overlook the role-based access. You know, if you get a JWT token, you get in the door, guess what? Now I can do a lot of things that I shouldn't be able to.
Fair enough, guys, we, we try to keep these sessions to 40, 45 minutes, and I think we're up against the clock here. Um, first of all, great conversation, great conversation. I, I think look for our audience at home.
Takeaways three, three things. I always like lean these kinds of things, or three key takeaways. Number one, we absolutely do live in an API economy, right?
APIs are driving the internet, it seems, if we look at traffic loads, number two, an API first mindset in, in how we plan and, and develop our applications is I think the norm, not the exception today, right? Do we all agree with that? And the third thing is, if all of these APIs are out there, you're not doing API testing.
And that includes API security testing. You know, the, the, the, the, what's it, what comes home to Ruth Mitchell? Chickens can loan drew the chickens, come home to Roo.
I knew it some foul. That's the Nebraska boy. That's the Nebraska boy right there.
And of course, it expands, expands your blast radius. Um, I realize we gave nobody any context at the beginning as to why we are doing that, and I love it. No, we have a very, very sharp audience they picked up right away on it, but it's not the first time they've played this drink again.
Um, anyway, Chris and Chris, thank you so much for being our guest today on, uh, DevOps Unbound. Tracy is, as always, it's a pleasure to have you on here. Love having you part of, you know, not just DevOps Unbound, but you're on the, you're one of the gang members, some tech strong gang, and, and of course, uh, tech strong women and everything else you guys do.
So thank you. Thank you, Mitch. As always, you take the last word.
Um, I just part thought is there's an API for that said, fair enough. No doubt. Hey, many thanks to T Tricentis, as I said in the beginning of the show for sponsoring this.
They're a great company to work with. com. Until next time, this is Alan Shimmel for Techstrong.
Quick reminder. July 24th is our next live round table. Don't miss it.
But until then or until our next show here, we're out. Thank you. Bye-bye.
Hey, everyone, happy Monday has, has deep seek, become deep stink. You're watching Textron Gang. Hey everyone, it's Alan Shimmel for Textron Gang, and we're back.
It's a Monday. Happy Monday to you. You know, we, uh, we were last week out in Silicon Valley with a special edition of Textron Gang at Tech Field Day.
We experiment with these things, right? And, uh, Steve Foskett and John Willis and Mitch Ashley and the gang out there, uh, you know, covered the tech field day event, but there's been so much going on in the world besides that, that we wanted to, glad to be back here to talk about it. But, you know, focus still remains on, on deep seek and the pros and cons and what does it mean for our tech world.
We're gonna get to that and some more good stuff on AI and, and, and more. Uh, but first, let me introduce you to our gang on this fine Monday. First of all, I'm really glad I haven't seen her on the gang with me in a couple weeks at least.
She is our voice in DC and there aren't a lot of voices left in dc uh, our own Trace Bannon. Hey, trace, how are you? I'm just excited to get to talk to y'all.
Today's this gonna Be fun. Good to see you. Thanks and welcome.
So we go from Trace to Tracy, I guess she's our voice in New Mexico, but she's also our voice at the Linux Foundation and on open source of microservices and so much more. She's CEO of Deploy hub, Tracy Reagan. Hey, Tracy, it's good to see you.
Thank you, Alan. Great to be Here. Thanks.
Great to have you. And getting out of his sick bed to join us today, because that's the kind of dedication this guy has. He's future analyst, uh, vi, CTO, co-founder, our friend, guy Courier.
Hey guy. How are you? I'm much better, thanks.
It was a rough week last week. Um, I did manage to, to stay engaged. Um, I heard there was a little bit of news in, in the AI world, so I just checked in real quick.
Didn't seem like a big deal at the time, but There you go. We were gonna talk. Well, the good news is by the time you got better, it wasn't such a big deal anymore.
Or maybe it was, maybe it wasn't. Anyway, and then of course, uh, running the anchor lab. The anchor lab for us, our own four by 100 guy at a Cardinal Spelman high school in the Bronx, Mike Ard.
Hey, Mike, how are you? Good, good To see you. I'm Highing out in my, uh, fallout shelter.
I see that New York to, uh, because, You know, you don't know what the heck's gonna happen with China and this AI stuff, So yeah, no, no windows in that room, right? It's all good. It's all good.
Um, so gang, let's jump right into it. Deep sea has it become deep stink where every day this thing is, is peeling away like a rotten garlic clove or something stinking, uh, you know, the latest Mike, why don't, well, why don't you give us the latest Mike. Yeah.
So things are kind of crazy. On the one hand, we have reports saying that sensitive data is being exposed inside a deep sea because there aren't any guardrails to speak of. And, uh, folks are kind of downloading this thing like crazy and all kinds of havoc could ensue, uh, some countries, Ireland, Italy, and the US Navy also, or, uh, banning usage of this stuff.
But at the same time, much to my personal amazement, at least, uh, AWS Microsoft, Google and now Nvidia are all seem to be embracing this model and making it available to customers. And you gotta ask yourself, like, did we not pay any attention to this TikTok conversation or what's going on here? Alan, from your perspective?
Well, from my perspective, you know, wasn't it Carl Mar Marx who said, or maybe it was ENGs, but I think it was Marx who said that we could sell the capitalist, the rope with which they will hang themselves. This is a great example, right? I I think whether you think the deep seek relearning techniques, breakthroughs in doing it cheaper, faster, I don't know wanna say better necessarily, but certainly cheaper, faster is are real or not.
What, what's for sure that we've seen is they may be able to build an AI engine, they don't know how to secure data. So good. And it may be because in China, you know, people who try to break into stuff get a quick 22 to the back of the head and you don't do it again after that.
Um, that being said, look, the Wiz research has exposed this whole, where supposedly a hundred thousand people's confidential information was, was exposed open on the internet. Um, they, they, you know, I don't believe they were the victims of a cyber attack that took them down. I think they were the victims of too many people hitting inadequate infrastructure and service to handle that kind of traffic.
I, I, I think, you know, it's not ready for pride time. It was an open source experiment by a couple of PhDs backed by a hedge fund who, whether they shorted Nvidia or not, we could discuss another time. That's a whole nother conversation.
Yes, it is. But, but that's what I, I think is here you're dealing with, you know, they, they don't have the infrastructure, processes, policies, cyber place in place. There's, there's so much to unpack with this.
Something that, just to make sure everybody understands kind of the difference here, when it's popping up on Azure, when it's popping up on AWS when it's popping up on perplexity, um, it's not pointed at the deep seek subscription, right? It's not quite good to the Chinese infrastructure, right? It's not, and, but that's what we know when everybody started to download this app and it's suddenly shot higher than chat GPT with its opening, it was pointing there, right?
So there is a, there's a SaaS option that it's that SaaS, right? Software as a service, the subscription that has suffered from that exposure, right? So that, I just wanna clarify.
Yeah, there's a problem because they were not, um, capable or not yet mature, didn't have those things in place to be able to surface something, provide that kind of service. The other thing though is well, they did something unique, right? I, and there's, I would say nearly, almost, they're just shy of the United States in terms of their research publishing.
Like right now, China's a powerhouse when it comes to what they're Doing. Well, they're going into labs and basic research for 20 years. They have, and in this case, they didn't have access to Mary because they didn't have access to all the same things that we have here.
They came up with an ingenious way, right, to look at how they could pair different chip types together to get some interesting performance. But it's not, I don't necessarily think it's a bad thing unless there is some kind of umbilical where every time you instantiate the model that somehow is calling home. But we've got folks like, um, the University of Florida.
They have a massive new super pod. Nvidia has invested something like $70 million. Every student has to take two AI courses before they graduate.
Everybody. You can't graduate without AI courses. It doesn't matter if you're nursing, it doesn't matter if you're business.
But I say that because they are decomposing this model to truly understand, right? They are looking at how the weightings are going, they're looking at all the different layers, and they're seeing some different things. So there's goodness there putting it out there for Alan to install in his environment, in his AWS environment.
Okay. It's up to Alan, right? But he has, doesn't necessarily know what all the risks are yet, but it is a new model.
There is some sexiness to taking a look at it, but they're two very different, different things. I do wanna ask your opinion, Alan, don't you think it's kind of interesting that it popped up when it did in terms of the US change in administration. Like, couldn't they have released it three weeks earlier or five weeks later?
I don't think they bought all their shorts in time. Well, wasn't it also announced? Was it two days after the giant government funded OpenAI, blah, blah, blah, right.
Whatever that was after, right. Project, uh, Stargate Sure took the wind, wind Outta the sails of that one. It did, it, it at least temporary, it tooken the wind out of a lot of different sails.
Allotted it, right? Yeah. Well, yeah.
It's trillion dollars. Lemme let know trick you hit on something here. Let me tie it up.
So for people understand what you're saying is, look, instead of relying on the Chinese infrastructure, a lot of these places that we're seeing carrying it, if you will, are offering it as a self-hosted option. Correct. Now, my understanding with Amazon is just for AWS I'm talking about right now, you can run itself hosted in AWS or you can plug in the Chinese one into, not Broadcom, what do they call their bedrock.
You can plug in the Chinese version in a bedrock if you want, or you could run yourself hosted version. And I think the same goes for a lot of the, the, uh, the, uh, the cloud providers. That being said, you know, I used to sell security software to the federal government.
You sure did. You Sure did. For a long time.
And back, this was in the 2000 4, 5, 6. And even back then, there was a strong prejudice in the federal government about buying checkpoint firewalls and checkpoint uh, hardware, because the rumor was the mo sod had a back door that would allow them to log into these machines remotely or what have you, would allow 'em to get help phone home, whenever you want to say. And that was enough checkpoint, you know, it was a lot easier to sell Cisco firewalls back then, or net screen juniper or whatever.
Um, what makes you think that's not the case here? Well, I actually, uh, am always airing on the side of the caution when it comes to national security, right? Obviously.
So I don't advocate that somebody connect and say, I wanna use the bedrock version that connects to China. Um, I also think about the ITAR, right? Our export controls that we have in place.
So a lot of, I'm not gonna send any of my data over there, just not, but if AWS allows me to instantiate it and I want to experiment with it, and I wanna bet my business or my farm on it, well, that's my business inside the context, right? Inside the confines of the continental, right? So I'm, I'm not farming out my, my data externally, But, so now you've got choice, got unit 42 out of Beijing who rents a small office in San Francisco and, and, and has the back door key into every self-hosted version.
'cause it's built into the source code, but it's open source, of course it's safe. And, uh, I see what you did there. Yeah.
You made a joke and someone, and, and unit 42 logs into your instincts outta San Francisco. No one realizes there's Always gonna be a race. There's always gonna be ways to break into stuff.
It's chaos. And, you know, the faster, the better we can respond to chaos, the better. But I gonna point out here that every technology gets disrupted, right?
We are all disrupted at one at some point. And I feel like this is a disruptive moment. If everything that they say and how they've built this and the cost around it is true, then it's a massive disruption.
And it goes to a bigger question that I keep asking myself. Why are we still putting so much money into one company if in in fact we could have some PhD students create a better solution? Why is OpenAI looking at getting a $40 billion investment?
There is a limited amount of funding available. And, you know, maybe China, I'll tell you why Or democratize them when it comes to funding and research. I, I've been in venture-backed companies most of my career, and here's the rule.
If you're not in the top three, get the hell out. Money Goes to the top three. Well, this company was not the top three.
This company was not in the top three showed Up. They're, they, they, they come from sort of an alien culture, if you will. Right.
Though, truth be told, they're backed by it. And you know, my joke about shorting Nvidia, they're backed by a hedge fund, right? The hedge fund took a, what was it, a $6 million flyer here.
And, you know, if they did short Nvidia, they make that back a hundred times. Uh, I that could be true, but I'm, I'm still gonna push that. We need, I believe that we are hurting ourselves in our, in the United States and our research by believing in one or two people.
But, But that's the Difference. It's either Between government funding and VC funding. When I'm a VC or a PE person, and I've got investors to answer to, I'm not playing Johnny Appleseed and trying to go trees all over the country.
I want to bet on the winner. And you look at like the Andre, Andre Andreessen Horowitz model, the Andre and Mark Justine in, in Horowitz's model is they pick one player in a given market, they pick a market they, they think is gonna be big. They don't care if it's the best player.
They're going to give them that player enough money to bury everyone else and get way out ahead. And so they'll capture a substantial share of that market and their investment pays off. And they became the most successful VC in Silicon Valley on that premise.
And that's, that's, And maybe it doesn't work anymore. Well, No, maybe VCs, you know, a lot of people say VCs are, what's wrong with this whole thing? That's what I'm saying.
You know, it's, we're not democratizing the, the funding to create the disruption ourselves. So we're get disrupted By somebody else supposed to be Democrat. Hold On, hold on.
Go ahead, Tracy. Hey, I'm gonna come back to that guy. You've got something to say.
Well, I, I know, I feel like two topics are being mixed here. Mm-hmm. So I wanted to ask a question of everybody because Alan, the, the, the scenario you described, we went from security to, to funding in VC and competition and all that sort of stuff, sort of seamlessly.
And I think those are really different discussions. I'm gonna get back to the security question. Um, first of all, uh, let me just point out that Nvidia has a NIM for running, uh, uh, a deep seek.
Um, so you can air gap a, a, a, a small system and run it. Yep. Yep, Yep, yep.
But that, put that aside. You described the scenario, Alan, of, of like, you know, using Bedrock one of these services and all that other sort of stuff. You know, that, that it's not fully mature.
Who said that? My question is why run deeps seek why? I think deeps seek proved, not proved, I shouldn't say proved, is demonstrating the possibility of training models.
This is what it a quarter trillion parameters in, in, in R one or two, right. Um, large models, uh, without these giant investments in hardware. Great.
Okay. But I, I've, I'm investigating Deep Sea, I've used it, but I don't know why I wouldn't use that. It's kind a perplexity or copilot or, I, I use a smattering.
So that's my question to everybody. Why use, why, why do other to validate that it works? Why Mor connect to a flame?
Well wanna, so there's so many pieces of this. So I'm wanna answer from a, from a security perspective, it's more than that. Um, I'm jokingly so that umbilical, but Alan brought up a poten, you know, that potentiality of getting into, um, tapping into it, we can't lose track of the site that even our US based models, there's poisoning of the models there.
It's a real thing. And we're working after. How do we get rid of that?
Well, do you really believe, um, you know, taking a step back, being on, you know, yay, go USA, we really believe that China was looking after the types of things that we would want to make sure were secured from that model, from a poisoning perspective. So some of my concerns around it actually have to do with the training data that the actual data itself, which we don't. No worries Then open ai.
Yeah. Well, that's what they're saying. Yeah.
And I don't, I Have gonna get, we're gonna get that. What I'm trying to, what I'm trying to ask is, you're an enterprise, you are an organization, g, novelty, whatever kind of organization you are, It's novelty, right? Well, yeah.
Well, yeah. Yeah. I Mean, I've a novelty.
If you're in, if you're in the tech or r and d, you might wanna take a look at it and you'll pretty quickly find, that's perfectly good model. Uh, that's fine. However, whatever it's prominence and then mm-hmm.
You like, it's not preferable to me. Well, But that, I wanna tie that back to something that Tracy asked about, or Tracy mentioned, um, was about, you know, the fact that open AI is a proprietary model. Why are we putting all of our eczema basket?
So some of the research I did over the last year was looking at hundreds and hundreds of peer reviewed studies. And what blew my frigging mind was how many of them are using a model that has sourced out of OpenAI? But why, why is all the, well, we believe that part of that is free accessibility, right?
The free version, the things that people can get after for free. It isn't, wasn't the necessarily the GI coming from GitHub, it wasn't looking at philanthropic, it wasn't looking at the others. It was around their, their specific models.
So there is, uh, a research domination that we have to think about on the US side of the house, right? On the US side of the house. The other thing that this should really shake up, and I kind of like it, the models that we say are so wonderful, and it may help us, right?
We've built massive industries around this. They're proprietary. I don't get to see inside open AI's model this, shake things, shakes things up a bit, right?
Yes. We're in a capitalist society. Yes.
We wanna make money. It's just like big pharma. Why do they make a, why do they make a a, a new drug?
It's not because they just wanna be altruistic and help the humanity. It's 'cause they're gonna make money off it. Open AI makes a lot of money off their models and on keeping them proprietary.
This kind of shakes things up. Yes, there are open source models, there are, but this kind of takes something that has had in kind results open sourced in kind results to something that is hyper proprietary. So I think I'm, I like that shakeup.
But to guy's point with a little bit of pragmatism, um, you know, it's okay to be excited by the hype and, and and such, but we have to be ready for what's gonna come downstream. Uh, Alan, I, you, you named it, And it's important that we just demystify some of these technologies. And when I, when I read that story, it was like, okay, we're taking some of the mystery out of what Open AI does, right?
So, and I think the more we demystify it, the more we all believe we could go write it as well. And if some college students with $6 million did it, why not? Yeah.
So Mike's dinette aspect question, but I just, I read the white paper. Most of the math is far, far over my head. Mm-hmm.
But, um, for me, yes. The, the, the thing is they're, they're claiming, they're saying they used a different training method. It's not feed forward.
It's, yeah. It's, it's, it's, it's, it's slightly recursive. It's et cetera.
Like, you, you gotta read it. I don't want to get into those wonky details that's of abiding interest to the AI industry in terms of development. Mm-hmm.
Yep. But as far as Does anybody, nobody's talking about that really. Go ahead.
Sorry. Does anybody find that the irony, a little rich here that if I understand this correctly, open AI is saying that they quote unquote distilled their AI models without permission, the very open AI models that were created using a lot of data without permission? Well, yeah, Yeah.
I, well Do is I think we, we all saw that immediately. Do, do as I Do, as I say, not as I do. Yeah.
Anyway, guys, we're, we're, we're over 20 minutes on this one. I'm gonna need to end it off. I wanna end it with this though.
If you wanna get a little more, it, it, it has certainly disrupted permanently or temporarily. It's made a big splash in the AI market. Our friends at Futur have, uh, a little paper.
They put, I think it came out Friday, uh, deep Seek Disrupts AI market. ai. You can check out the article and the link to the paper there.
So go have at it if you'd like. But we're gonna take a break here on Textron Gang. We got more AI to talk about.
But let's talk about AI and testing. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, everybody, we're back and we're talking about AI and testing because, well, last week we saw Perforce has a new tool that eliminates the need for building your own scripts.
Uh, harness is talking about putting an AI agent in front of their chaos engineering tool. And now AWS has extended its platform to include the ability to generate tests. So everybody's kind of going down the same path here.
And one of the things I do like about this is I'm reminded of that, uh, a woman who said, you know, when they were talk, talking to her about AI and its ability to create art and do all these things, she says, I don't want AI to create art. I want AI to clean up the kitchen so I can go create Art Trace. Is this the roughly the equivalent of that?
Are we gonna use AI to create the test because nobody wants to clean up the applications anywhere? Well, gosh, there are two completely divergent topics that I'm not gonna cover, because the first one I'll talk about for just a second, then we'll put it and put a pin in it. If we are helping people to truly write decent software, they're starting out understanding requirements in the first place, right?
Kind of the big R vision of those things. First place that you go is understanding how is it gonna be tested? You don't go straight to code.
So there's that whole thing that we need to talk about. And the, IM the impact of having a, a holistic testing mindset end to end, not just as a Chevron that follows build, right? That's one of the problems with the whole modern DevSecOps, little continuum.
It says that we just test in this one place. So pin in that right over there. I love the concepts.
I love what's happening with moving from, Hey, we're gonna gen code, gen code, gen code to, we're gonna leverage this in a way that can help us to generate some assets. But there's also another really important part of this right there. When you're using generative ai, there are two big buckets of ways that you use it.
Eye roll, you use it to generate things, okay? Eye roll there. But the other thing is augmenting human reasoning.
So it, it really serves this wonderful purpose. I like it better for testing, because there was a report that came out, and I'll have to, uh, find the actual report and send you guys. So we have that in the, the link and available to people.
47% of organizations have automated their testing. So that means 53% have not, that should make jaws drop. So things that we can do to improve it, hell yeah.
Now remember that all tools, no AI augmented tool is immutable and is perfect. But this gets us a, a lot further along the path. One post that I'll say, or one nugget that I'll, I'll share is right now, if you're trying to use it to generate your code, and also trying to use it to generate your tests, if you're actually generating tests from it, you wanna be a little bit careful about that because you have no verification, right?
You've got AI on both sides, and right now, today, six months, it'll be different. But today that's a little bit tenuous. But there's so many awesome ways to set it loose to help, to help the humans with the testing.
It does a lot on its own. But again, at the end of the day, you're gonna have the humans in the loop. So trace, I know that you spend a lot of time and, you know, dealing with this, right?
And every endeavor that you, you go down there, there's testing involved myriad types of testing. And one of the problems with the scripts, so per force is going down the right road. I, you know, I've advocated for getting rid of scripts and the builds process for how long now?
30 years. Mm-hmm. I've been taking, talking about that.
Um, because scripting is very static and it can adapt. Uh, and when you talk about 43% of the companies, uh, have implemented automated testing, uh, it means that they've put a, a a group of, uh, testers who have some development background who can write these test scripts. So, you know, one time I was talking to an individual who really loved his build scripts, by the way.
And I think they're gonna really love their test scripts. And to Mike's description or Mike's analogy of being the artist, they believe their art is in, in the scripts. They really love their scripts.
So we have a cultural problem as well. And I've watched that cultural problem for a very long time. And maybe now that AI is cool.
I mean, open makes, open make, uh, Meister was a rules base, not, it was a knowledge base that we generated all build scripts for Ant or whatever you needed to build a script for. But people would, like, we wanna, you know, we, we we're the shoemakers. We wanna make perfect shoes and we love our scripts.
So we'll see how, how developers embrace this, this kind of technology. 'cause I feel, I, I really feel like it, it, they will feel it takes something away from what they do, but it's the only way to go because there's so much more stuff to write than a test script. And in terms of the stuff that, um, you know, testing, I generated code, uh, I, you know, I keep in touch with my niece who took her first job and she told me she could generate 6,000 lines of code a day, which I think is insane.
But she said she wouldn't, couldn't really use it because she didn't have the time to debug and test it. And when it's generated, it's a lot harder. So if we have more AI doing that kind of work, it will make it easier to use these tools.
So, you know, yay for perforce to talk about getting rid of scripts. Thank God, thank God. Let's do more of that.
And I'm happy after, you know, this whole last year I talked about where's AI at DevOps, we're finally starting to see something come up. Well, I also thought you'd be happy, happy Tracy with, uh, harness getting in the game here because mm-hmm. I know you're a, you're, you're a, I love chaos engineering.
I do. I think it's fascinating and I think it should be applied to so many other things, including security. So yeah, I was, uh, you know, I'm, I'm glad that harness is going down that road because most companies are really struggle with putting, setting up game days for doing chaos engineering.
And this will help a lot. And I, you know, it's an, it's an area that I think companies should really focus on. How do you, how do you stand up a system if something broke and bring it back to health in a few minutes?
Not an hour, not two hours, not a day, and not even 20 minutes, but instantly Limo you, you bring up the idea of what's the developer impact. We're seeing some pretty interesting stuff. I think I've, I've chatted a little bit with, uh, uh, with Mike about this before.
Right now we're in that point, where're in a, I'm not gonna say a transformation, I'm gonna say a transition where developers are creators, right? We create things, software engineers, we create things, even test and just create things. And we're going from being creators to being reviewers editors.
And here's where it gets just a little bit dicey with newer incare. If you've just learned the English language, I probably won't give you a formal journal publication to peer review. Not yet.
'cause you need more practice with the human language. We're seeing that with earlier in career. Don't care what their age are just earlier in career folks, because they're not getting to decompose in the same way.
So that's just something, whether it's test scripts or any other thing that's being generated where we don't get to practice that, that decomposition that we, that we did before. So I think that's just a, an interesting nugget to, to throw out there and to keep involved in this conversation. Yeah, it's like losing the ability to navigate through a command line.
Mm-hmm. How many, mm-hmm. How many developers know how to do that?
Well, it's coming back, it's vote now I know. Oh, gosh. Know What, what do, what do our students do?
Right? It's, it's kind of the, I mean, what's the core sensibility of, of software development? Is it, I mean, there's, there, of course, it's abilities.
Maybe I don't even from, you know, back when all we had was cli there's something, there's, there's this user experience aspect to it. There's also this sort of functional, you know, in backend front end is what sort of call it now. Um, but I'm not sure the core sensibility is your, your, your passionate belief that Python is the, or g or whatever is the future.
And yet, that seems to be so much of the, the culture and the discussion is the, the tools, the tricks, the languages and so forth. I think that, that, when AI can start to do a lot of these things, then it, they, it, I I, my answer to Mike's question is yes, it's doing the dishes so that the, you know, editing, supervising, whatever of like, how do you put, how do you put together good, you know, good piece of software, good app module, good service, whatever it is, um, uh, with understanding how the whole stack works. Um, you can, you know, pay more attention to that and less attention to, uh, the, how, I guess am I, I'm Really starting to disagree with myself saying that, but Yeah.
Well, sorry. It gets into, so we're going to be, it's not, I understand that we're saying that we're gonna automate the, the tedious stuff away, but there's going to be a point where we're creating, I call this digital platform. We're creating these digital platforms where anybody can walk up to it.
Uh, I'm, I'm a, I'm a sailor. I'm a nurse, and I can say, these are the things that I need. I need some software that will do this.
500 billion, 500 million developers by 2030. Exactly. Exactly.
And they're not going to be, we're not going to see development in the same way that we're seeing it now. We're going to see software engineering. We're going to be at the intersection of the data scientists are plugged in with the data.
Engineers are plugged in with the software engineers who are creating that middleware, right? So that the humans can generate the software that they need. We'll get into the software flywheel, but you guys brought up a whole bunch of different things here.
I wanna, I wanna track back something you said, guy, uh, about, you know, the, and, and Tracy had foot stomped this as well about getting rid of the test scripts and how great it is to get rid of the test scripts. Again, transition. I think we're going to see in highly regulated industries, whether it's government or whether it's, we're going to see that lag a bit because of the auditability.
So they're going to need those tools that aren't using scripts. They're gonna need to see the auditability of that test. And if, and so I think we have a little bit of a challenge on that front can be solved, but a little bit of a challenge.
But I was having a, actually, I was on the phone this morning with my buddy Pat DUIs and we were talking about what, how, where things are going, talking about agents and age agent and what's gonna happen in the future. And we talked about the big, everything is going to track back to the spec. Now, we didn't talk about what the spec is 'cause it could be dozens and dozens of different things.
Our software developers are software professionals are gonna have, have, need to be heavily invested in, in that part of it. And that's also going to feed those tests, right? It's also gonna feed harness, it's gonna feed the other tools that are being improved with this stuff.
So there's just so much amazingness out there right now, but yeah, so much amazingness that's out there right now here. Here's, here's kind of a take on it though. Um, I personally think that when we look at AI and good uses of AI app testing is probably one of the best in the whole software supply chain, you know, life cycle.
There's no reason we shouldn't maximize a use to, uh, to do testing. I think it, it just lends itself, I think the same way a human could render a script. The AI will render a script too, and it'll be fine from a compliance point of view, but at this transitionary moment where we are right now, I am hesitant to let AI generate code and then let AI test that code.
I won't Right? Without, without having some human in there at some point, especially if it's anything mission critical or really valuable, Um, that's a strong recommendation, Alan, that I make constantly over the last year do one or the other. But, but don't do Both.
Or now? Right Now. For now.
Right. For now, because we don't have that verification, right? We don't have verification and validation.
Well, We don't have the confidence is what we don't have. Right. Trust it because we know it's not, it's not at that level yet.
Right? Okay. Can't that be in the pipeline?
I mean, I don't, I don't isn't You can have both, but not without the human intervention. You don't wanna just release, right. Even even release it to qa, honestly, like, like no developer involved.
So, so, Oh, come on guy. What's the answer? It depends.
Yes, it depends. It depends. It depends on your industry, it depends on your context, it depends on your workforce, it depends on the maturity, it depends on how old the software is and the quality of the existing software.
All these things. So, yes. Mm-hmm.
And right now, if somebody says, we're starting on our journey, where should we go? I actually say your documentation. What's the qual?
That's, that's you have enough documentation that's low hanging flute. And then let's go to testing, and then we can go backwards from there. Because when you focus on testing, especially if you're focusing on you humans being involved, and I'm not talking about this completely automated tools, which are awesome, right?
The autonomous tools. But if you talk about helping humans to get better at using the tools themselves, have them focus on testing, it still is sexy, right? It's still is sexy even to a developer to say, Hey, can you evaluate this code base?
Can you tell me where I have testing? Plus, can you help me understand unit tests and the end tests, right? As it sees the bigger, brighter context.
Yeah. Start with testing. Absolutely.
Tracy, those words. Well, you know, as they say, the more, the more things stay that, that change, the more things stay the same. Isn't that what they say?
Um, It's the French French saying that my French wife says is stupid. So I'm, so We've, we've, software has changed and changed and changed over time, but we still are writing software the same, to be quite honest. We are, we still code it, we still, you know, manage it.
We still test it. We still, you know, go through all of the same steps and those steps aren't going away. So while develop, it might be scary to think that a developer AI would generate code and then test code.
The reality is, is that when, as right, right? Today, developers still want control. I have faith that they will continue to want control.
They're gonna generate code, just like we might generate a document and they're gonna go through and they're going to read it, they're gonna learn it, they're gonna understand what they just generated because they have to deliver it. This is what I'm hearing from the developers, the new developers that I'm talking to. Um, so yeah, testing would be a good place.
And things like scripting, the problem is with those test tools, scripting can be a bit challenging. And not all testers are developers. And so that's why we have a gap in how much automation's being done.
So, and I really don't, you know, I hate to use the term AI to say we're generating scripts. You can generate scripts without, Oh shoot, we've been generating stuff for 20 years. I was generating my Joe's 20 years Ago.
So it's nice to put them two letters in front of it, but it doesn't mean that's what it's doing. So let's just realize that we still have to go through the same dev process no matter what happens. And we for won't always catch things.
All right. So for now, for now, the, we're Gonna take break here. Not changing.
We gonna Wait, Wait, wait, wait, wait. The script hugger's unite meeting will be next month. Georgia.
Colorado. Okay. We are, we're gonna take a break right here.
We're gonna come back and let's talk about conflicts of interest. Is there such a thing anymore? com is the number one online destination for DevOps education and community building.
com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com where the world meets DevOps. All right, folks, we're back with our final topic of the day, and I think there was so much noise in the world that nobody noticed, but Elon Musk is now partnered with Visa, so you can conduct transactions across the X platform. And magically Donald Trump came up with a similar idea for his, uh, social media platform.
I'm not sure if those two are discussing these things as they go along, but it all came together in the same week. Guy. What could possibly go wrong with it?
That's the word that allows you to conduct any type of transaction. Wow. Where to begin?
So, uh, this, there's so many, there's so much context here. I I don't even know what to pick first. Like, first of all, um, when Elon took over x Twitter at the time, uh, he almost immediately, uh, made it known that he wanted x to be the platform for everything.
Just like Mark wanted Facebook to be the platform for everything. And one of those things was payments. It it, it's kind of a natural in some ways you would think, like these are communications media and, uh, uh, one-to-one and one to many and all that other sort of stuff.
So talking about a guy who made his first fortune in PayPal. Exactly, yes. I, Let's, let's not lose sight of that.
So this is An old idea. It's an old idea. And I think that that the track of Twitter half blown up and losing a lot of its, you know, participation and all that sort of stuff for political reasons that I'm not gonna get into here.
Um, you know, it's sort of comfortable circle a little bit with the arms rise to political power in a sense. He, he has the, the political muscle right now to, to help get the kind of deal he he wants from a visa or from anybody. Um, similarly to the president of the United States, having the political muscle to find somebody to back, uh, what is it, truth do truth fi or something, truth have five Also payment or no, an investment platform.
Um, so what could possibly go wrong? I, I think, um, similar. It's what's really funny, the other piece of context is, um, we get, uh, the, uh, AI announcement followed by, uh, uh, Elon saying that's never gonna work.
So, you know, you have sort of, sort of, you know, pairs of like parallel paths here from the president and from Elon Musk. I, I wonder what's next? That said, these two are really different animals, really different.
Um, the partly because one is a sort of payment and communications, like I said, it's an, it, it's a plausible extension to both Elon's background as well as to, uh, you know, the kind of medium that XX Twitter is. Uh, and Visa itself is also a, a certain kind of a communications network as well, verified and so forth. Who's gonna use it?
X users are gonna use it. Who are X users at this point? A lot of them are Elon fan people.
Uh, that's just kind of how it shook out. Uh, blue Sky came in. There are other methods for communication and so forth, but are people gonna migrate into X because of this?
There's lots of ways to, to, you know, to pay. And There's a nugget that came out this morning, guy that you'll like, it just, there's just an article that was posted. I just put it into the, the chat for us to be able to share with folks that says Bezos is boosting his ad ads on X.
So are there gonna be followers? What other kinds of interesting things are gonna happen? They lost people, but they're been starting to gain people back.
This is the echo political environment. We're in the United States right now. Oh yeah, Yeah.
This has nothing to do with, So we really haven't had a president of the United States before, even Trump's first term, who was, who was actively an openly engaged in business. Oh, B******t. Trump has been doing this sort of thing.
Okay, you'll explain which, which other presidents have done this, but Trump the, to me, truth do Phi is the same as going back to Trump shuttle, you know, uh, Trump Towers, Trump branding, Trump vodka, Trump, you know, like all these sort of things. A new line of business where people who are attracted to him and to his brand, no judgment, just saying, attracted to him and his brand, they can do the same kinds of investing that they do elsewhere. Only now they can do it within this culture and within this mil, and gets his take from it.
As does his partner Schwab, who's essentially using Truth Social as a channel partner as Schwab uses, or TD Warehouse uses other channel partners to gain business. Alan, I would love to hear your perspective as well. You and I and Mike, we are old New Yorkers.
We've known Trump forever since he was, you know, the son of, we started Real estate times in quarters before we moved up to a hundred dollars bills and stiffing contractors. Yeah, sure, sure. But that, that being the case, I'm not even gonna talk about it as a New Yorker, I wanna come at this.
You know, I was a political science major, history major in college, spent a lot of time looking at and learning about the American system and, you know, the Federalist papers and the founding fathers and the separations and different levels of government. A a bedrock belief in our government is it was a good government principle. We weren't here to enrich the monarch and, and make his treasure room bigger.
Wait, can I get a clarification? When you said b******t, you were saying what's happening is b******t or you're saying what I Think No, I'm saying in his first term, he, he, uh, he did what? No, resident private.
It wasn't, wasn't open in this way. That's the only difference. It was, It wasn't open in this way.
Everybody, you came to Washington had to pay the Trump hotel tax. Did you forget if you didn't stay at the Trump Hotel, you didn't get a meeting. That's pretty damn open.
There's not pre-social or Brand, but I'm not, I'm not even gonna argue that. Let me, let me get back to this. A bedrock of our government is number one, we're not here to enrich the monarch.
There is no monarch. Number two, everybody is equal under the law. Everybody's equal.
There are that, that means that we don't discriminate against anyone. But no one is above the law. And no one should have the, to wield the power of the office for their own private enrichment.
That is, that used to be in the America. I grew up and loved that that was, even if sometimes it didn't necessarily work that way, at least on its surface, that was a given. When a president or anybody came into office, you know, they had to set up a blind trust.
They weren't allowed. They weren't, you are not allowed. When, when the King of Saudi Arabia comes and gives you a gold plated knife or dagger, you're not allowed to keep that gift that goes, that belongs to the people of the United States of America.
All of a sudden, in addition to everything else, and we could talk about everything else till the cows come home, we've decided it's okay to allow this, whenever it is, come into office and enrich himself at our expense. And make no mistake, it's at our expense. Now.
You're right Guy. You and I are never gonna go on true social and US Schwab file or whatever the heck it's called. As a matter of fact, if I had had any money in Schwab, I'd pull it out just because they did this.
But what Trace just said about Bezos is a perfect example. Everybody wants to Curry favor. And Elon Musk is in a position where he's gonna decide what gets spent on this government.
And, and AWS and Amazon and Blue Origin, or whatever his space thing is called, is all very near and dear to Jeff Bezos. So of course he's going to suck up to Elon Musk. And of course Schwab and his daughter or granddaughter, whoever the heck it is, is an assistant treasury secretary surprise, is gonna suck up to Donald Trump.
As a matter of fact, All of Big Tech has, Now we can call them our first American oligarchs. Right, right. That's what this Is.
And the question really? Yeah, that's what this is. And the real question is, why are we not, um, making Bigger issue?
Why are we riot in the streets? Why aren't we out? Why is Congress standing up and saying, no, this is wrong, because this issue 'cause of Republicans, they're sucking on the same tee.
Yeah. That's why, Yeah. The Republicans have become okay with this.
And he, he was very vocal in that re in early Part of December's the Democrats. Well, everyone should be up in arms With, in early December. In early December, he, Trump was interviewed, I think on Meet the press.
And he said he could not diverse, he could not diversify his investments. He said he couldn't do ITT Trust divest it. He couldn't divest it.
Well, Because he, and He said he wouldn't even know to divest it. No. He said there's no way he could divest it.
He just said, no, you don't to digs. You could put it in a blind trust. I don't think he's gonna even try to do that this time.
Like he said, it's very open. Open. He said he would not Tracy, he was lying.
He was lying. He can do it. There are ways to do it.
Of course he can. He was lying about the 2025 project. He is lied about.
So, you know, the d and ID and I, people who are in the, you know, the TSA, he lies all the time. But watch what he does. What he does is he's not going to do it.
So, so mark me on this. All that crap that happens on the Silk Road and all those illicit transactions is moving over to these platforms and people are gonna start using these things to do all kinds of things that are illegal. And they're just gonna be out in the open.
'cause nobody's gonna be tracking who's selling what, where and when on these things. I think that's right. And I think, Alan, my response to, to, to what you're saying is that I, I I agree with you a hundred percent about, um, the need for a, a minimum, the appearance of, of, of neutrality and objectivity, but also separation, like you say, good government separation.
I believe in that completely. I I think that I, well, I don't, I know that the level of cynicism, um, in general in the electorate of the United States is very high. And that the general response that I've gotten to making statements like that is, well, everybody's done it.
Yeah, I know. Biden and his, What about Obama are even worse? They're worse.
Not just 'cause they do it more, but because they lie about it. And at least we have men gone to jail. Honesty and openness about it.
Now that's men gone 11. You know what, so again, I'm a history major. Lemme tell you something.
In the 1880s, 1890s after the Civil War, right? The robber barons, the van, the Gilded Age. The Gilded Age.
Well, it was a little before, it's the beginning of the Gilded Age, before it got really guilted. But there was a time not just where people were making tons of money, but that government got really, I mean, started with Andrew Johnson who came in after Lincoln. Everything was for sale under Andrew Johnson.
And, and it didn't get, you know, grant did a decent job, but he was a junk. And then it, it went pre progressively downhill from there. And until the first time we, well, it, it wasn't the first time 'cause we've had third parties, but a third party president won the election.
The, I mean Teddy Roosevelt Party, Teddy Roosevelt, you know what he ran on? Clean up government, good government. Mm-hmm.
Clean up government put In, you know who, who had that message before him was Democrat, Grover Cleveland. Yes. The former New Yorker.
He, he ran once then was out. So it was like a 30 year movement. The culminated the presidency in the beginning of Antit Belt, cleaned it up.
Now, the best we can hope for as Americans is that the stench of this becomes so rotten and stinky that we wake up, come to our senses, and we get some sort of good government movement here. It may start at a local level and work its way to the federal where, you know, what I would like to see any member of Congress has to put their stocks in blind trust. Let's take the insider trading out of this.
They cannot go chase, you know, this being in the beltway, you can't go work for a contractor with, for three years after you leave government. You can't be running commercial entities while you're serving this government. And you can't have quasi people like what Elon is right now, have any kind of say in things and access to top secret and everything else while he has commercial business going on with the US government.
And until we do that, this whole thing is a farce. All right. Sold.
I think, I think we're gonna have to close this out guys, but, alright. Danny Roosevelt speaks softly and carry a big stick, Right? Absolutely.
Good old Teddy Roosevelt, the hero of, was it San Juan Hill? Yes. Uba.
Yep. The Rough Riders. The Rough Riders.
Spanish American War. I was not a history major, but I did stay at a Holiday Inn Express recently. So Mike loves the history though.
All right. We gave you a little history, a little of this, a little of that. But we're done here on Text and Gang for this wonderful Monday.
We'll be back tomorrow with more gang members, more news, more discussion, and more fun. Until then, this is Alan Humma. We're out.
This is Textron tv. Hey everyone, welcome back here to Techstrong tv. Our next guest is Mr.
Trevor Deering. Trevor is Director of Critical Infrastructure Solutions over to lumio. Let's welcome him.
Trevor, welcome. Thanks for coming on our tech strong TV today. How are you man?
I'm very well, and thank you, Alan. Thanks for having me on. My pleasure.
So, Trevor, director of Critical Infrastructure Solutions. That's a mouthful. Tell us a little bit about kinda what your job role is, what your duties are, and then if you don't mind, tell us a little bit about yourself, how you came to be the director of critical, uh, infrastructure solutions here.
Yeah, so, so I, I've, I guess, worked in cybersecurity now, 37 years, probably in this, in the IT industry, 43 years. Um, right back to sort of installing some of the first firewalls in, in uk working with some of the early AV technologies. I was an engineer primarily.
Mm-hmm. Um, and then I suppose sort of worked my way through, you know, through various roles within the, within the industry. And one of the, you know, one of the key things that I guess in started to interest me was what was happening in some of our more critical environments.
So, you know, electricity, grids, healthcare, all of those sort of things. And I've worked for a number of vendors that everyone knows throughout the years. Um, and about five years ago, an opportunity to join lumio came up and it just fitted in with, you know, with a lot of the things that I was interested in at the time around, you know, protecting those, those parts of critical infrastructure.
Absolutely. And look, you know, I, I think especially during covid, um, the whole idea of our critical infrastructure being vulnerable and also the whole definition of critical infrastructure, right? I, I've been in security 25 plus years myself, I tech 30 plus years.
It used to be critical infrastructure US was the electrical grid. You mentioned it right here in the us we've got NERC and FERC and all of that. I've worked with that.
And um, you know, certainly public utilities was thought of as critical infrastructure, but we found out during covid healthcare, our healthcare system is critical infrastructure, our, our supply chain, right? For things as these, as simple as toilet paper at some level is critical infrastructure, right? Protecting those supply chains.
And, and so to me, the mission has, ooh, mushroomed in when we talk about, you know, protecting critical infrastructure, where it is, what it is, what it does, and, and what do we have to do to protect it. Um, I'm cur we're gonna jump back into that in a second. Yeah.
'cause I want to hear how Illumio views, you know, the definition of what's critical infrastructure. But first I guess we should define Illumio, right? Many people out here probably know, but Go ahead.
Yeah. So, so Illumio, gosh, we've been around 12 years now, and what, you know, what we're fundamentally, you know, trying to do is to, is if there is an attack, is making sure it doesn't become a disaster. And this, you know, this really is again, fits into the whole critical infrastructure.
So, you know, our major customers are banks, government manufacturers, utility companies, et cetera, et cetera. And so, you know, we focus on really the resilience of an organization, how to understand where the risks are, how to contain any attacks that when they happen, basically to, to keep organizations working when there is an attack. So, you know, we'll, we'll, we'll look at when we, when we dive into the numbers, we'll see how, why that's important.
Absolutely. And, and really, you know, what illumio's know for in the, in the market is, is kind of, they, they, they achieve this using a lot of, kinda like microsegmentation, right? And being able to, I want to use the term wall off, but segment, you know, so if you do get attacked, and, and a lot of times it's not due, it's when you get attacked, you can limit the, the, the blast radius as they used to stay, right?
Yeah. Correct. Um, so before we jump in, you guys just did your, uh, cost of ransomware report.
We're gonna jump onto here in a minute, but what's critical infrastructure to you, Trevor? It's actually, um, it's actually pretty well sort of defined now within a lot of compliance and regulations around the world. And so it, it is what we've mentioned, it's, you know, primarily at the top end, it's power, it's utilities, it's water, it's all of those sort of things.
But as you said, it's, it's food, it's transport, it's, um, you know, modern days, it's the internet, um, and mobile phones. Mm-hmm. And, you know, all of those sort of areas.
Banking, for instance, because nothing happens without those. So, you know, we started to see, uh, regulations all around the world now coming in focusing on, on the, the resilience aspect of critical infrastructure. So, you know, it's not, it's, it's, it's become a thing I I guess in its in its own right?
Absolutely. Absolutely. And, and I think it, you know, it's kinda like trying to define DevOps, right?
The more you put your finger on it, the more it kind of squishes, you know, away it critical infrastructure. Something could be critical to you and not critical to me for whatever reason, right? I live in a cave and the internet's not important or what have you, right?
But I, I think we agree there. We all agree there, there are critical pieces of our lives today, and that's increased as we become more digital that gonna fall into this. So I mentioned this ransomware report you guys did the global cost of, of ransomware.
Um, is this the first year you've done this? Have you guys been doing this report now for a while? So we actually were, we worked with the Ponemon Institute on this, and it's something that they've done before, but this is the first time that Yeah.
That we've, we've, I involved in didn't realize. Yeah. He's actually right down the road from us.
You we're here in Boca Raton, Florida PO is also in it, not a tech center. Right. People don't come to Boca Ol Florida for the tech, but for the most part I wish they did.
But anyway, just coincidentally, he's, they're nearby here, so Interesting. Yes. I'm, we're, I think we're familiar.
Pokemon has been doing this report a while. So for this year before we jump into the, uh, findings, when was the surveying done? When, you know, how fresh is the data here?
So the, the, the data basically is, has was released yesterday. So the, the research, the research was done just at the end of the tail end of last year. Obviously, it's all being analyzed and consolidated and turned into a report, which you can, you know, which you can retrieve.
com, there's a banner on the front page, click and download it. So you know it, and it's, it's actually full of roots and quite surprising numbers in, on a, on a positive and a negative note, really. Well, that's, that's the way life is, right?
Yeah. Go ahead. Let's, let's, you know, you, let's, before we jump into surprising even, let's go to key findings.
How's that? What, you know, what are, what are the key takeaways our audience should, should do on take on this? I think, I think one of the, you know, one of the interesting findings was that, that people are actually very confident about their ability to prevent and stop ransomware.
So, so compared to three years ago, which was the last time they did it, the, the sort of where people are saying, yep, I've, I've got more confidence. I don't believe that we're a target for ransomware. I've got more confidence in my supply chain.
I believe that we are better at, at, um, at stopping ransomware. All of those numbers have improved, so people are more confident. But then on the flip side, numbers, like we had to shut down for a period, have leapt from 45% to nearly 60%, or, um, our brand was damaged, has grown, or we lost significant revenue has grown, or the number of, um, attacks we had has grown.
So, so there's a sort of a, a, a weird dichotomy between those Two. They don't jive. Yeah, yeah, yeah.
The numbers don't really, Or, or unless you're telling me because I was a victim, I feel like I won't be a victim again. Right? So the lion ate this zebra once.
He's not gonna eat the same zebra twice. Uh, you've been in security longer than I have even, and I've been in it a long time. I don't believe it.
I, I, I think, not that I don't believe people said this, but I think this is false confidence in, in what they've got here, right? Um, I think everyone is a target. I think, you know, there are certainly strategic targets when it comes to ransomware.
There's something that you have that is very dear, near and dear to me that I want right? Strategically, but I think for the most part, like a lot of cyber crime, you become a target when the bad guy walks down the hall of the hotel and your door happens to be a little more jiggly than the next door, right? And it's easier to break in.
And so I, I don't, I don't buy that. I think people are misguided if they feel that way. I also think with AI and everything, the phishing attacks that people, that the, the bad guys are using the, to get in and, you know, implant their malware that leads to the ran, you know, the encryption and the ransom.
I think they're better than ever. Trevor, you've gotta be seeing this too, right? Yep.
Yeah, I mean, it's, there was, I was at a, a conference a couple of days ago and there was a big discussion on deep fake, and some deep fakes are less deep and less obvious than than others. But some are very, very good and they will only get better over, over time. And to a certain extent, you know, the, the primary attack vector is still phishing.
Yeah. And it's becoming more and more difficult to detect that. But there is, you know, better AI tools are trying to detect DeepFakes and, and that battle will go, you know, will go on or not.
But you know, the reality that we, that we face is that over these, you know, over that 37 years, we've got much better at reducing the probability that an attack is gonna be successful probably by, you know, over 99%. But that still means that at some point something is gonna get through and there's probably not enough focus on what happens when the attack gets in. And there's some, you have, there's some real, real things where they talk about, um, uh, uh, like what was the, you know, what was the primary movement for, uh, for ransomware and what was the, you know, what were the things that caused lateral movement?
And it's, and it's still numbers like RDP, weak passwords, unpatched systems. So, so there's a lot of work just on the basics of security that isn't being done, that's allowing those, um, those attacks to have a, have an impact to cause that shutdown down for a period. So, so I think there's two things in there.
One of which is a focus on make sure you do the basic things properly, but also how do you then, you know, again, how do you then contain and control that attack? And I think we're seen sort of an improvement and a, a, a sort of a drive towards incident response. And, you know, some of that, that sort of technology that's, that's starting to help and a hopefully a shift in culture within organizations to move away from, you know, I muster everything to stop every attack, to how do I make my organization more resilient?
So I I do, I agree with you there on the resiliency. I think where we have made progress with ransomware is understanding how do we, how do we, again, limit the blast radius? How do we have copies of our data that are not subject to being, you know, encrypted here, right?
Yeah. That there's some sort of wall between them. It, it is about incident response.
This is why, frankly, Illumio with microsegmentation is, is a great ransomware kind of fire. I, I don't wanna use the word firewall 'cause it has a different meaning in security, right? But it's a, it literally is a block, right?
Because it, it can limit what, what data gets attacked here. Um, and that, that is where I think we have made progress. People understand that with the best of intentions and the best of processes and policies, stuff's gonna happen, right?
They're going to, it, it, the phishing gets through, you know, and it, it only takes one knucklehead click and something they shouldn't click. And that's, you know, where you go from there. But how you respond to that attack and how you use a, an illumio and or how you have architected your data, you know, storage to, to insulate if you will, is a good word, I guess is, is key to it.
Let's talk any, what other kind surprising results that kind of stood out to you? I think, yeah, I think the obvious thing of, you know, ransomware is not going away. So, you know, so that beca that became an obvious thing that, you know, whatever, whatever we say there is a shift towards more disruptive attacks as opposed to, you know Yeah.
As opposed to sort of traditional sort of things. And there was some, and again, there was some interesting research into security controls and, you know, the top ones are MFA and patching and all that sort of stuff. But some of those, the numbers of people that are using those technologies was surprisingly small.
So out of, out of the population, only 37% said they're using M ffa, which Really Yeah. Is, Was actually Quite, quite surprising in itself. So, and then, you know, and that was the most popular.
So, so I think there's still a lot of, I think what they call security poverty in a lot of organizations where, you know, if you are not a top bank or a, you know, a multinational that's got a big organization that the challenges of, of trying to secure your, your company, if, you know, you may have still have a, a multimillion dollar company, but if you've got four security guys and a limited budget, you've still got a problem. So, so again, there's, there's the whole piece about, you know, making sure you do the basics properly and, you know, put the, you know, put the, the good prevention control measures in before, before going mad on spending too much on some sophisticated AI tools. So, so I think that, you know, some of these, some of these things are still, you know, are still, uh, sort of really interesting in there.
Um, and so it gives you that, It gives you that sort of view of the, again, the culture within organizations and, you know, and, and where some of that responsibility lies and, you know, and what the impact then of some of those, you know, some of those attacks are on people. So, so I think, you know, any of these reports, you're sort of look at 'em and go, well, actually, it, it's then interesting to do another 10 questions on, on that particular subject. So, so I think it gives you that, you know, when you look at this in income in sort of alongside some of the other research, so you look at it against like the World Economic Forum cybersecurity report, and you look at it against some, you know, some of the sort of other reports that are coming on there, there is a picture out there that, that sort of says, there's, you know, all the things that are off it, there's not enough people that, you know, there's a shortfall in, in, in people you can recruit.
The, the things that we've done over the last few years have got more and more expensive, but we're getting less and less return from them. So there has to be a, there has to be this shift in, in culture and attitude within organizations to stop saying, you know, if we get attacked, the CISO gets fired, we've gotta get to the point where let's all work together to make sure that if we are attacked, we stay in business. Absolutely.
AG agreed. And that is, so I think that's been a big shift in the security world over the last even maybe seven to 10 years, is, uh, the, the, the, you know, the, the response versus prevention aspect. You know, we're, we're over over time and at time here, I'd love to talk to you more about this because Trevor, especially when you're talking about mid-level enterprises, you know, the, the fact is a lot of these people are relying on third parties for their, they're all SaaS.
No one has a server closet anymore where they're running the exchange server, right? Or, or something. They're all using Google or Office 365.
All of those emails have two factor authentication, almost by default, you gotta like shut it off not to use it. Yeah. So why only 37% is because people think it's a paint pain in the butt and they, they decide not to use it.
com, I-L-L-U-M-I-O, they can go get it right off the front page. Trevor, thanks for coming up here on Techstrong TV today. I appreciate it.
And best of luck, man. You know, it's, it's a hard job, right? But you know, how do what they say it's security is when nothing happens, you've done your job.
So, Absolutely. Absolutely. Alright, keep It up.
Thanks, Alan. All right. And, uh, hope to meet you again.
Thank You. Bye-bye. Alrightyy.
Trevor Dearing, director of Critical Infrastructure Solutions at Illumio here on Tech Drunk tv. We're gonna take a break. We'll be back with another interview in just a moment.
Hello and welcome to the Techstrong AI podcast. I'm Amanda Ani, and with me today I am happy to have Steve D'Angelos. He is the founder and CEO of Interra Solutions.
How are you doing today? I'm doing well, Amanda. How are you?
Doing well. Can you share a little bit about Interra Solutions? What services do you provide?
Sure. Interra Solutions is a artificial intelligence and applied mathematics company that performs, um, uses artificial intelligence to perform end-to-end value chain optimization and decision making for, uh, mid-size and large corporations. Wonderful.
Well, our topic of the day is AI as a job creator. So that's a, that's an interesting topic because, you know, we hear a lot of people, they're afraid about incorporating AI because they're worried it's going to take over their jobs and they're gonna be without jobs. Or, um, recently, um, someone came out and talked about AI was gonna reduce the wages of everyone.
Um, so what are your thoughts on this and, and why do you think that it is in fact, um, going to be a, a job creator? Well, look, you know, with any transformative tech technology, some jobs are, are created and sub jobs are lost. But like with the first wave of, of technology in the 1970s and eighties, um, certain classes of jobs went away and many more classes of jobs were opened up.
And I, I'm actually very, very encouraged by AI and a particular generative AI's ability to act as a net job creator, and quite frankly, act as a net middle class job creator. Um, and lemme tell you a little bit about why I think that, you know, as you think about large, um, tech firms like Open AI and NVIDIA and others, you know, creating data centers that are going to power the, that are gonna be used to, to create generative ai, large language models, those data centers have to consume electricity. Those data centers have to, um, build infrastructure to, to support that work.
So if you think about OpenAI, um, and Microsoft investing $120 billion in one data center in Texas, right? It's the amount of jobs that are created in that field, um, that are both infrastructure creation. Like we have to build a new power plant to have that power plant, uh, power, the, the, uh, factory that's going to manufacture the chips to then power the data centers that are going to, that are going to create the large language bottles and all the jobs that are incumbent with that, whether it be the construction jobs or the raw materials used in the, in the construction process, the real estate that gets purchased, the housing that gets purchased around the, the data centers and others.
It creates a massive amount of infrastructure and, um, construction and development related jobs that attend to the industry, creating a whole new set of AI jobs, right? So whether it be, you know, people at the top of a pyramid who are kind of like PhD scientists who conceive of how the should be manufactured or conceive of how the, the large language model should be designed and, and structured to the software engineers, to the coders, to the people that generate prompts. There's a, you know, sort of a think about a pyramid of jobs that, you know, you don't have to be a PhD scientist from a leading university to, to, um, play in the generative AI space.
So I think there's a whole class of, of jobs that can be built that can be replacing, quite frankly, middle class jobs that over the last several decades were offshore to other countries, right? So you used to be able to earn a middle, middle class living by working at the US steel plant. Those jobs largely went away in the 1970s, eighties and nineties, right?
And they haven't been replaced. This is a way of replacing really good wage jobs, right? Where you don't have to have the same level of education as the PhD mathematician would, but you're, you can earn a great living by, um, getting trained on ai, um, generative AI skills that would allow you to, um, you know, put your kids through college, establish a great life for yourself.
And, you know, so I, so I'm really bullish about AI being a net job creator. So what are some of the degree plans that you would recommend for people getting outta high school or younger adults looking to further their education? What, what would you recommend would be the, the best degree plans to look at?
Well, it depends. If you want to go to college, then there's a set of college related plans in computer science, college related plans, and artificial intelligence applied mathematics, right? And then there are likely vocational jobs that you can learn to be a prompt engineer, you can learn to do to, um, to build AI related applications on top of the foundational AI model.
So, for example, there will be likely an entire class of job that are creating, you know, anywhere from sort of micro applications to much bigger applications that are used that are gonna be, um, uh, developed to have people generate prompts, to have people utilize the generative AI tools that the large tech firms are going to create or have created. And those kinds of jobs, you can learn vocationally. You don't need a college degree in computer science to be a prompt engineer, right?
You can, you can learn a, a, a skill and a craft to do that very well. And those jobs are in high demand right now, there isn't a trained army of people that can do those jobs, say. So if I was a young person and I was not inclined to go to college, but I wanted to get involved in the high tech industry, right?
I can go out and get a, a, I could go get vocational training in learning how to use open AI or NVIDIA platform, or IBM Watson's platform, I could learn those, those, uh, tools and I could perform work that the more, um, skilled I get, I could keep rising up the, the food chain of, of jobs in the gen AI space. Likewise, if I wasn't inclined to go to college and I wanted to become an electrician, you know, that is a highly skilled job today that there are not enough electricians in the market to do all the electrical work necessary to fuel the AI community, right? So if you think about the, the increase in in size and scope of our electrical grid that's gonna be needed to, um, be upgraded in order to handle all of this AI growth, there's gonna be a, a ton of jobs that are gonna be created both vocationally in the, in the construction related trades and, um, vocational training for generative AI and AI tools.
And then as you go up the food chain in terms of jobs that would require a computer science training or would require an a, you know, advanced AI training or applied mathematics training, right? Then, you know, those jobs could be consumed with people who are interested in per pursuing, um, you know, um, college and, and, and, and graduate school, uh, degrees, right? So, so there's a, you know, wide range of jobs that are gonna be created that can, you know, power this, this AI driven economy.
Those are such great points to bring up. And I think you may be one of the first ones to talk about it, creating other jobs outside of just like near ai, the fact that there are all those other components. So, and I was just recently reading about, um, the data centers and, and the amount of electricity that's needed there, and how, uh, even my city is getting some new data centers coming here because the big cities can no longer support, they don't have enough electricity.
So that is opening a lot of data centers around in different, different parts of the country and the world. I mean, I think it's gonna look, I think it will create a huge amount of jobs that are, you know, traditional manufacturing related con construction related electrical, plumbing, you know, all this sort of construction trade related jobs. It will create this, this new class of jobs for folks that can, like I said, earn a middle class living, have a cool coming edge job.
Like you could be part of the, the AI revolution, and you don't have to go to Princeton or MIT to figure it out, right? You can go and get a, a set of very, very practical skill training, and then you can evolve into that. You know, a lot of the people that were at the early stages of the computer, um, you know, the pc, um, um, wave in the, in the late 1970s and early 1980s also didn't have college degrees.
They were a class of, of tinkerers and hobbyists, right? In, in electrical engineering, you know, men and women who would, you know, were technically inclined and who would play with circuit boards and do things, you know, as a hobby, they evolved into an entire class of people that were the early computer science, um, folks, right? And those were in addition to the people that were more classically trained at the university.
But you know, like in any new industry, people who are willing to self-educate themselves and to be lifelong learners right, can learn the skill. It's now very hard, right? You can learn it by focusing and taking classes online.
I mean, one of the things that has happened since the first wave of the tech evolution is, you know, previously in the eighties and nineties, you didn't have the internet. So you couldn't take courses online, you couldn't get free training, you know, online today, you can take courses at Harvard, at MIT, you can take courses anywhere. Um, of course Arrow offers courses that are relatively inexpensive.
You can take these, you know, these, this training, educate yourself and go out and apply it at a time where there's a market gap for this, for the skill that you have self-educated yourself on. Right? So I think that, you know, as we look to building up a, you know, a set of middle class jobs for younger people, they, you know, they, they, this will be the replacement, I believe, for a lot of the manufacturing jobs that have been offshore over the last several, um, decades.
Right? So, so I think it's a really, you know, great opportunity. Absolutely.
We're in an age where we can get so many opportunities for education at our fingertips. I consider myself a certification junkie of sorts. Mm-hmm.
And you mentioned, you mentioned, um, Harvard, they have free classes. I I enrolled in one of their free classes a while back. Uh mm-hmm.
So it, it's amazing all the opportunities that are there. And also, it makes me wonder, so as these jobs shift and the, the companies replace certain, uh, tasks with ai mm-hmm. Do you think that these companies should incorporate some sort of skill up programs where they cover the costs for their employees to skill up, um, in areas that are needed so they can keep those employees and shift them to other departments or tasks?
Absolutely. We do that today at interra. We take people who are, you know, we people who have a certain skill and they wanna evolve that skill into something else.
We will invest in the employee to become, you know, trained in a, in an adjacent skill area. Also, people are just curious if they wanna do that. You know, you know, companies will and should encourage people to upskill them themselves, right?
And I think companies themselves will create internal certification programs, right? So let's say for example, you are a data database engineer and you're really interested in gen ai, right? You, rather than lose a known good performer, you because that person wants to do something else, it is invariably less expensive to retrain that person into a job that, that, that they are super interested in, right?
Because they will then think, wow, the company invested in me to get this new skill. I'm working on stuff that I'm aspirational to work on. I get the skill that I'm excited about it.
I'm gonna do a great job. 'cause I'm all psyched up about what I'm working on, right? And so I, so I think it's a win-win, but I also think it's a way for companies to build the, you know, to build a huge amount of loyalty with their employee base.
Wonderful. Well, if there was one key takeaway you could leave our audience with today, what would that be? I really think that you should not, people should not be afraid of a, of ai.
Look, there could be very potentially difficult things with AI when artificial and general intelligence starts to take off. And we don't know exactly how that's gonna work. No, people don't know all the rules of the road.
We don't know how to potentially regulate it effectively, right? But ai, like any other technological, um, fundamental technological evolution, right, has the potential. And it will, in my opinion, fundamentally change the way that everything is, is, is done.
Like, it'll change the way corporations operate. It'll change the way that governmental agencies operate. And my net takeaway is don't be afraid of it.
It will be a net job creator. Don't worry about it, eliminating all these jobs, and we're gonna have, you know, robots doing all the work and pe it'll, it's gonna be a net job creator and po potentially a huge boom for the economy. All right.
Well, thank you so much for coming on the show and sharing your insights with us today. Thank you. And thanks to our audience.
Stay tuned. There's more. This is Textron tv.
Hey guys, thanks. The throw, we're here with David Weissman, who's vice president of Secure Communications for Blackberry. And well, we're talking about the need to secure not just our communications, but in particular the new administration communications.
'cause well, a lot of folks around the world are trying to listen in to conversations they probably shouldn't. And that's probably lessons for all of us to learn now that we think about it. But David, welcome the show.
Thanks, uh, glad to be here, Mike. Glad to talk with you and your audience. The administration of the United States is always a target for Eves dropping and all kinds of malware and stuff that goes on.
But what do we need to be concerned about? And is it any more this time around than it was in any other administration? Yeah, I actually think, um, it's something we need to be more concerned about right now.
And it actually started about six months ago. Uh, this higher level of concern because of some of the bad actors got a jumpstart on new administration, and they actually, it's been in multiple Wall Street Journal, Washington Post, all across the press, salt, typhoon attacks. So, um, people have actually infiltrated into all of the US telecom networks, and they specifically were targeting the presidential candidates from both parties and their staff listening into the phone calls, reading their text messages.
So, you know, the fact that we're going to admit new administration, uh, is an important aspect in terms of always sitting down and reviewing, you know, what your policies are around communications. But in this case, we know, you know, there's already an aggressive effort in place. Do you think that, I mean, a lot of this salt stuff is pointed towards China and, and allegedly anyway, but I feel like this goes on everywhere and every country's trying to do it to every other country, and maybe the US is no exception.
So, and maybe this is just something that's getting a little outta hand, or is this just the way the world is? I I think it's the way the world is, and it is obviously been going on for a long time. Uh, you know, the US everyone's always trying to collect valuable information.
Um, I, I think what's different now is that, you know, everything's done on mobile. You know, go back 15, 20 years ago, you know, that wasn't necessarily the case. And so that's expanded the attack vectors.
So it's easier for people. You don't have to be as sophisticated to do these type of attacks before, you know, it was a very expensive endeavor, very complicated endeavor. And you typically were targeting very specific people.
You know, they call it tapping the lines, right? Uh, now what we've seen with the salt typhoon type of attack is you can target everyone in mass. And then the other thing that's different now is a lot of times people would take data and retroactively analyze it.
You, you know, Hey, we'll go grab all the call records from this country for the past year and go see who's communicating with whom. Now that it's embedded in the network. It's more real time.
So you, you can know, hey, this party is calling this party right this minute. And you can know that pattern. And then since you can collect voice data, you can collect message data, you can really target deep fakes and the identity spoofing at the right point in time.
And with the other thing that's changed is kind of the emergence of all the AI tools, the level of expertise needed for a particular person, a particular entity to launch very sophisticated attacks is come down. So, in other words, the cost of doing this is a lot lower, and so therefore, you know, the volume of these type of attacks, you know, becomes higher and the breadth of them becomes a lot wider. So what do we need to do to prevent these types of attacks?
I mean, is it just a matter of increasing the level of encryption we have? Or is there more to it? There's more to it.
And, you know, the first thing I would say is, you know, there's a lot of effort on, Hey, how do we better strengthen the telecom networks? You know, how do they get this stuff out of their networks? Uh, my answer is, that's a good activity, but it's never actually gonna be fully successful.
Uh, 'cause fundamentally, telecom networks are designed for connectivity. That's the number one goal. Any phone can reach any other phone.
And in that, an ease of connectivity, low burdens on that. And therefore, you know, security while important, it's, it's always gonna be secondary to that design code. So if you look at, uh, cisa, the US Cybersecurity Agency, uh, they put out a report in mid-December with some very specific guidance, what people should think about, you know, in this environment.
The first is a, everyone should use end-to-end encrypted communications. So that's a solid first step. They, you know, they mentioned there's things such as signals such as WhatsApp, you know, popular consumer apps that have end to end encrypted communications.
The second thing they mention is that you need to start to lock down some core security features on your devices. And this doesn't mean your devices had to be managed, uh, but there's things you can do to configure your iOS, your Android devices to better protect yourself. And they give specific guidance.
And then the other topic they talk about is, you know, identity attacks. And I actually think this is, you know, the biggest risk now, particularly with the deepfake technology. And, and they give some guidance on things.
I think this is where it becomes more complicated for the individual citizen to respond to that guidance. Uh, it's, it's not as simple as just download this app and use it. Um, but they do give guidance of, Hey, be aware of this type of thing, be suspicious.
But when I talk with cisa, they, you know, I say, Hey, this is great advice for the general public. Hey, if you're a government agency, you're a corporation. You're someone in a sensitive role.
It's really just a starting point. And, and, and they agree with that. And, and, and so, you know, end-to-end encryption, think of it as important, but it's just a starting point.
The other things that become very critical are more around control and the metadata. If you're using a consumer type application, somebody's mining that for business purposes to pay for the system, right? So that's a, you know, consideration.
A business or a government agency has to take into account as well as whenever you have a public registration system, like a WhatsApp, like a signal, it's kinda like the phone network. It's for ease of connectivity, but that introduces additional attack vectors. So, you know, you need to look at not just end, end encryption, but how do I protect the metadata associated with that communication?
And how do I really have high levels of confidence in who I'm communicating with? At any point? Are we reaching a point where maybe I don't trust who it is on the phone or 'cause of these deep fakes, and do I need some other way of verifying who is on that call for that matter?
You know, like, I know it's you because there's two other people in the background here who say so, so, yeah. Yeah. I, I, I think we're already at that point, right?
It's, you know, what do you call it? Trust, but verify, I believe is the phrase. But, you know, that's where, you know, crypto cryptographic identity validation techniques and things like that, you know, come into play.
But the other thing is, I think we might be moving away for, you know, very sensitive communications. We might have to move away from the model of using systems that are broadly designed for anyone to connect to 'em, to more closed down systems. So it's kind of a, it's kind of a step backwards from the relentless d uh, uh, you know, drive of connectivity ev everywhere and to anyone.
And to kind of come back to more, some more closed communication systems, I think this president has some specific preferences for devices that he likes to use. And how does that factor into people's thinking about security? 'cause uh, not all these devices are equally secure.
So there are some folks who would say, you know, back in the day you had to have a Blackberry phone because that was a more secure mechanism, but now everybody's got all kinds of different phones. What role does hardware play in this conversation? So I think hardware and operating systems, you know, do play an important role because, you know, what we've been talking about with salt typhoon and this type of thing are network based attacks, but you still have attacks on the devices, people trying to put malware on the devices, that type of thing.
So, you know, I think couple of things. One, supply chain becomes very critical. You know, is this truly a, a trusted supplier?
Um, you know, is, is the way that you got that phone, do you know, you know, the chain of custody? And so obviously if you're the president, you know, that type of thing is being looked at on a regular basis. But also, you know, device management, you know, whether it's self-management of, you know, set these policies, which, you know, depending on your attention span may or may or may not be effective, or whether it's some, you know, may a mobile device management type of systems that automatically set those.
But that, that's important because without those type of protections and policy checks on the device, even a device that you totally trust the vendor, you totally trust the supply chain is, you know, vulnerable to external attacks. Is AI gonna play a role for the defenders? We're clearly seeing that the attackers are harnessing it, but how should the defenders think about maybe using AI to help themselves?
Yeah, absolutely. So I think one is, you know, there are AI tools that can analyze video, that can analyze audio and tell you if you're more susceptible to, you know, a deep fake. Um, and, and so, you know, building some of these type of tools into the networks, into the communication systems is an effective approach.
Uh, the other way is just as I mentioned, the bar is lower for launching, uh, you know, broad scale attacks on the communications network. The bar is also lower for being able to analyze what's going on, is detect patterns that could indicate that attack. So I think the AI tools can allow a lot of automation to, uh, you know, counter the offensive attacks.
But it's always gonna be, you know, cat and mouse, right? It's you, the models learn, they change, they evolve, but you, you have to use it on both sides of the equation. As we look at all of this, it seems like to your earlier point, um, if the cost of launching these types of attacks continues to drop, yeah.
Are smaller countries and smaller organizations gonna start doing this? I mean, where does it end? I, I think at the end of the day, we, we'll get to the point where almost everybody needs to do this, you know?
Um, but, but from an organizational viewpoint, you know, we're already getting a lot of inquiries from, you know, relatively small companies. You have dozens of people type of companies saying, Hey, I don't have all the tools that a large company or government would have, but, you know, how can I, you know, what can you do to help me? And so I think there's awareness of that.
And some of the work that CIS is doing is they're trying to find, provide pragma pragmatic enough guidance that even an individual on the street can do some self level protection. So what's your sense of the probability that sometime in the next four years, there's gonna be some rather embarrassing information leak because somebody hacked into somebody's phone? Oh, About 100%.
In fact, I think that data's already out there. Someone's just waiting for the right time. And you, The, the other thing I would mention is we should keep in mind that this data is already being collected in mind.
And, you know, they, and people don't change phone numbers very often. You know, you, you usually, you'd have a phone number for decades, often 'cause it's a hassle to change. So the data's already out there.
And if different people come into different roles, now that data can be put to use in a negative manner. I mean, we hear a lot about quantum computers, but right. Those folks are already harvesting encrypted data that they intend to someday decrypt.
And I'm sure it may not be as valuable as it is today, but it could still be rather embarrassing, right? Uh, absolutely. You know, store harvest is, you know, a well known technique.
I think it's already been going on for a while. Um, you know, don't know the exact timelines on, you know, when somebody actually would be able to, uh, break that encryption. But that's one of the reasons that, um, particularly for communications encryption, uh, quantum resistant algorithms are being applied now for, uh, key exchanges specifically to, uh, mitigate the store and harvest challenge.
And NIST has put out algorithms for that. Um, NSA and other agencies have, uh, put out guidance to the, um, tech community and to the government about, you know, when you need to start doing this stuff. I'm still trying to figure out a little bit about what's the tail and what's the dog here, and is it gonna be the end customers that drive the carriers to put better technologies to encrypt things and protect them in?
Or is it gonna be the carriers who are driving that 'cause they're sick of, um, getting hacked and then having all these difficult conversations with government officials. I mean, I'm trying to figure out which dog is the lead in the sled. Uh, it's, it's gonna be the consumer.
'cause there's, the carriers are never gonna be able to put enough security in place in a way that's unintrusive enough that it doesn't defeat kind of the purpose of their networks. Plus that's very, to be very costly. So it's gonna be the consumer saying, okay, we've got this network.
I need to use the network, but I need to assume any data I put over that network is at risk. So I need to protect that myself To that end. Does that make this whole thing more expensive?
Are we willing to pay that cost? Or is there some way to get at this without necessarily increasing our costs? There's different ways to look at cost.
So, so one is what's the cost of, you know, of losing that information? The other is, well, what's just the cost of, you know, protecting my communications? So I think as, as a just an everyday citizen, an everyday person, it's very low cost for you to adopt an encrypted messaging app.
And that's gonna move you pretty far along, uh, as an organization. Um, there, there's cost to setting up higher levels of protection, but I think those costs are relatively minor, uh, when you consider the cost and the implications of large data leaks. All right, folks, you heard in here data leaks are coming, they're gonna be embarrassing and it might be something of a train wreck, but hey, the very least, we'll learn some valuable lessons.
Hey David, thanks for being on the show. Thanks. All right, I'm back to you guys in the studio.
Hello and welcome to the latest edition of the Techstrong AI video series. I'm your host, Mike Zer. Today we're with Lauren Hassan, who is AI officer for CoreLogics, and they just bought a company called Core, and he's gonna explain the relationship between these things.
But the new company is called CoreLogics ai, which is an arm of CoreLogics. Lauren, welcome to show. Thank you, Michael.
Thank you for having me. Alright, So explain to us how this acquisition came about and how did these pieces all fit together? Absolutely.
Um, so what we've done in por, you know, we started actually before AI was called back in 2019. Um, and we sat on a mission, like we realized that on one hand AI is extremely powerful. We all know that by now.
Um, and with that we also know that it's very, very risky. So we realized there has to be some human oversight and control so that we, you know, human beings, society companies can actually rely on it. Uh, and that's how we started aporia.
And over the time we built our platform to provide full observability for AI systems and AI applications as well as guardrails for this system. So the companies that are using these technologies can do it in a responsible way. I don't think a lot of people understand what observability is and how it applies to ai.
And then, you know, we can then connect the dots back to, you know, how these things might then be used to govern this stuff. So walk us through it a little bit. Absolutely.
So we've all been using applications and software, right? And we all know that sometimes, sometimes, um, it might not work. It might have a bug or something could break down for the companies who develop these applications that need some way to identify these issues, you know, as soon as possible so they can mitigate any, you know, potential negative outcome.
Um, so observability is really providing the means and tools for these developers to constantly be in control. Things like the monitor, um, in an ICU room, right? Like he can see there's always a heartbeat.
So essentially observability systems give you a heartbeat for software. Now what we've built is this heartbeats monitoring system, but not for traditional software, which already, you know, there are quite, um, wide variety of companies that, uh, provide solutions for that. But rather for AI applications that could hallucinate make up facts, um, you know, um, um, perform or act in an irresponsible manner or unethical way.
Um, so this is what we've done. And then how does that get used to build the guardrails? That is, are those guardrails just code that I'm writing or are they themselves AI agents that are trained specifically to protect other AI models and agents?
So it's a tricky question, right? Like on one hand, I, I, I wanna, I wanna tell you that yes, there's 100% deterministic, no AI involved. Um, and honestly like when, when we started, you know, that was our main approach.
We will make it as deterministic as possible. Uh, but as time went by and as we worked with more use cases and processed more data, we realized, okay, we have to include ai. Um, and the way we do it is really, we built a very unique detection engine that is built on small language models or s SLMs.
So if chat GPT is like this massive hundreds of billions parameters language model, we've built an engine that is built of multiple small language models, each one's specialized in the specific area of issues or challenges in the ai. So you've come to the heart of the challenge that I think a lot of people are having is so many of the processes, especially in it, are deterministic and the AI models are probabilistic. And so there's a chance that the AI model is not gonna pursue, present the same result the exact same way every time.
And people are expecting that it will do exactly that. So how do we kinda incorporate something that is probabilistic and adds value, but into a deterministic workflow so that we can figure out, you know, what's reliable and what may be the best guess, Right? So I think it's all about kind of aligning expectations with the users and with us as society, as users of these apps, right?
Uh, because if we do expect, you know, che and this kind of a applications to be 100% correct, even in the cost of, you know, they would make up something, then I don't think it's realistic to get there. But if we kind of limit the boundaries, right? So the way I like to think about it, AI is like this crazy machine or crazy monster, um, that moves around and is doing all sorts of things we need to have and draws some boundaries in which we say in these areas our, under these subjects, for example, the A, we trust the AI to provide a reliable trustable answer.
Okay? So let's take an example. Um, let's say we have a customer chat support, right?
That aims to support customers when they have an issue. Um, and let's take an example company. com, right?
So it's okay for that chat bot to answer on the subject that's relate to purchasing an item with Amazon, um, I don't know, maybe refund policy and so on and so forth. But as we get kind of further away from this main subject, the chances that this AI agent is going to provide a correct answer is reducing. Now without any proper guardrails mechanism, the air will operate, it'll continue to output something, even if it's completely far off, right?
Even if you'd ask, Hey, should I buy Nvidia stock? Right? Like, I think today is, becomes a very, very interesting question.
It would answer it even though it shouldn't, right? So providing doorbell guardrail is kind of, for us human beings is how do we limit it to a known region or a known, um, list of subjects that we feel more confident with, if that makes sense. Mm-hmm.
Who should Be in charge of the guardrails and observability? 'cause sometimes I feel like if I ask the data science team to go do this, am I not essentially asking the proverbial fox to guard the hen house because you know, they're gonna have a biased opinion in the first place. So do we need like a third party here to kind be the, the overseer of the observability, as it were?
I, I think we have in, in total, uh, like three different parties that should be involved, uh, will focus on the should, uh, because unfortunately we're not there yet. But first and foremost government, right? Like the governance rely, are reliable to the safety of all of us.
So regulation, rule system enforcing and making sure that every company that adopts this technology use it in safe and responsible way. Um, then the leadership of these companies, now, it's very nice to go outside and say, Hey, we have this, we've brought this new AI capability into our system. But what happens when later on you get on the news with someone who committed the suicide due to their interaction with an AI chat bot, right?
Um, and lastly, yes, as software engineer, as data scientists who actually build these kind of things, it is important to be aware of that, not only from the safety part, but also how do you make it reliable. I think, you know, uh, building something you wanna ensure it works really, really well, it's really accurate, you wanna be proud of it. Um, so having proper guardrails and mechanisms against these edge cases, it just, you know, I think mandatory in part of this.
So these are the kind of the, the triangle of government leadership company or corporate leadership with practitioners that should all collaborate together to ensure safety of ai. Ultimately, what will be the relationship between the large language models and the small language models you discussed? Um, will the small ones outnumber the large ones eventually?
And they'll be the things that we're using to drive the agents we're gonna build. And I guess if they're smaller and they're more narrowly focused, will they be more accurate? Does that make sense?
Yeah, it does make sense. Um, I think it's not, if they're smaller, they're more accurate, it's kind of, if they're smaller, they're cheaper, it, you can more easily fine tune them and you can easily achieve something that works real, real well. Uh, while with the large ones until last week, you need to be an op opening the eye or meta right to, to have something like that.
Uh, I think the entire game has changed in the last week with dipsy announcement, uh, right. And, and as this field is constantly changing, this is actually why you constantly have to have the ability to observe, monitor, and track how this system behave, whether they're small or large language model of they're open source or commercial. So you believe that we are on the cusp of some less expensive way of training these AI models 'cause a lot of controversy around the, how this was all done.
But, um, and I'm not sure anybody's had any way to validate or test that, uh, claim that's being made by, uh, the folks outta China. But, um, what's your assessment of that whole conversation right now? First, I think that the advancement by dipsy with there R one model is no less than amazing and great for us as AI community.
It takes us really, you know, few steps further, uh, on our way to a GI. With that, I will say I think, um, there's a bit overreaction in the market in the way people perceive it. Um, yes, it is a game changer.
Yes, it is changing the playing field. Um, what I'm actually most excited about is by the fact that the cost to run these models, you know, got reduced by 30 times, uh, or so it suddenly unlocks a lot of potential applications that, you know, a week ago were just considered too expensive to make commercial sense. Um, so I think in general, it's, it's all good news.
Um, how the market is going to react. I think, you know, we we're all set and, and interested to see Regardless of the hardware side of that equation, um, is the victory here for open source. And basically we have now a mechanism where open source can keep pace with commercial developments and um, ultimately bring down the cost and to your point, make it more accessible.
There are definitely advantages for open source in, in general as an approach. Um, but I, I do wanna point out something here, like there's a lot of buzz about the fact that, um, Dipsy is open source and LAMA is open source. And yes, it does allow us to build on top of these models or, you know, to take them as a base model and further optimize them to something new and even better.
Uh, but we need to remind ourselves that this is not completely 100% open source. It's not like we have all the base data that was used to train these models. Um, so there is a kind of small caveat that we need to remind ourselves, uh, we've that.
So is it a huge leap versus commercial models? I think, um, I think it's an interesting question. Uh, I'm not sure yet What's your best advice to folks?
'cause I think they understand that they, uh, wanna take advantage of ai, but there are governance issues and they have to figure out how to operationalize it all. How do I get started? So I think when you start an AI project or multiple AI projects across the organization, it is important one to set clear goal and short milestone.
Like what is the first deliverable we wanna produce out to the market? And once you get to these MVP or POC working in your environment, um, really have an evaluation or observability system in place even before production, just so you can actually test and ensure you are going to, to succeed in production. Uh, just to share with you, like usually when we meet with different accounts and different enterprises, what we hear is that they have about 300 different use cases for ai.
When we talk and ask like, Hey, how many of them are actually in the works? The number drops to about a dozen or so. And then when we ask, interesting how many of them are actually live in production?
This is where you see people literally changing colors with one, two at most. And, and the reason being is building something became with, with gene AI and elements became quite easy. But to get to the point from working 80% to 99%, something that I can actually rely upon with my brand, with, with our name in production, there's a huge gap to get there.
And valuation and observability and proper testing is a key to get there. All right folks, you heard it here. Just 'cause we have AI doesn't mean that we don't throw out all our fundamental principles of which observability is one of them.
And if we want all this AI stuff to work as advertised, we better know how it works. Hey Lauren, thanks for being on the show. Thank you very much.
All right, thank you for all watching level latest episode of the Techstrong AI video series. You can find this episode and others on our website. Until then, we'll see you next time.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security Bloggers Network.
Hey everyone, welcome to DevOps Unbound. I'm Alan Shimel, CEO and founder of, uh, tech Strong Group. And DevOps Unbound is a, uh, semi monthly, which means it's twice a month, I think, uh, video series that we've been doing now for about three years.
And we explore every nook and cranny of the DevOps universe. Um, for three years we've been producing and putting on the show in partnership with our good friends at Tricentis, who I couldn't think of a better partner and a partner on this kind of thing, where if they, if you're not familiar with Tricentis worldwide leader in continuous testing and so much more today. Um, and as I said, we do these shows twice a month and then maybe once a month or once every month and a half, we do what we call a live round table version of these shows where we invite you, our studio audience to come in and participate and kinda lead the discussion.
Unfortunately, this is not a live one. This, this is a prerecorded version that we did here at Tech Trunk Studios. But, um, you should pay attention.
Well, we'll, if you ever go to Textron TV and you can see the schedules of our live events of, of these, and we'd love to see you at the next live round table. We do actually, Mitch, while I'm talking, maybe if you can grab a, a time and date and when I come to you, you can even we'll do that with a little plugin. But, um, before we come to Mitch though, besides thanking Chiantis, I want to introduce what this particular episode is about and introduce our panel.
Today's episode is API first and API testing. We're going to explore all things around API here. You know, API traffic represents the majority of the traffic on the internet.
I've seen numbers as high as 83%, which is the last one that came out of Akamai. Uh, I've seen Cloud flare. I think they had it around 70%.
So no matter whose statistic you go with, it's still a majority of the traffic on the internet. Um, we're gonna talk about, you know, API first development and we are gonna talk about, um, API testing and, and more. Um, our Cracker Jack production team has already gotten me the date of for our next live round table.
And if you're interested in attending this market calendars now, it's on July 24th at 11:00 AM and we're gonna be talking about adopting a DevOps culture for cloud migration success. Is there such a thing as cloud migration success? We'll talk about that July 24th.
Let's stick to APIs today. Um, for now though, let me introduce to you our, our panel. Um, first I wanted to, well, he's a, a repeat meaning he's been here before with us.
I wanna introduce you to Chris Kal. I hope I pronounced that right, Chris, Chris, tell, tell our audience a little bit about yourself, if you don't mind. Thanks Ellen.
Yeah, so I'm Chris Kmo. Um, for the last 12 years I've been working specifically in the API testing and service virtualization space. Um, joined the Tricentis team recently, kind of tasked with the responsibility of uplifting and modernizing some of the service virtualization, uh, tooling.
Um, and as a natural part of that, there's uh, some API testing, uh, pieces of it. But I've been kind of enjoying that and having fun, imagining what this tooling could look like if we started from fresh. So happy to be here.
Uh, happy to have you on Chris. Thanks, and welcome back. Next up the kind of queen of the ball here.
She, you know what, I, I just feel like she should move to Florida already. Um, our good friend Tracy Reagan, who's also a CEO of Deploy hub and many other things. Crazy.
Tracy, why don't you introduce herself? Oh, a Alan, thank you for having me here. I always enjoy this.
It's, I feel like I should have a PhD though on some of the topics that you bring me in on, Uh, what we Do about, uh, sometimes, sometimes I've kind of blown, I blow myself away. I understanding more than I realize, I guess. I've been in this business for quite some time, to be quite honest.
Um, I started at, as a programmer on Wall Street, started a company called Open Makes software that automated builds. And now I am the, um, CEO of Deploy hub, and we're doing an evidence store around security and DevOps data. I've been involved in the Eclipse Foundation, the open SSF, um, and the, the Continuous Delivery Foundation, and have embraced open source for quite some time and have some opinions on API first.
And so I'm happy to talk about it. Doesn't surprise me. You have some opinions JC Thanks and, and welcome our third panel member.
It's Chris Lindsay, and this is Chris's first time. I haven't yet told him of what first time guests have to do when they first come on here, but we'll, we'll tell him in a little bit. Hey, Chris, welcome.
Introduce yourself to the audience, Alan. Thank you for having me. My name is Chris Lindsay.
I am an application security evangelist over at Mend. My job is just to talk about application security in general. My history, I wrote software for 35 years, so been there and done it in the trenches and APIs are near and dear to me, and I've been in security for over 15 and plus.
So thank you. Good and welcome. Always nice working with the folks at Men.
Um, our last panel, well, he's not really a panel member, but our last person that we're gonna introduce is my co-host for DevOps Unbound. He's our CPO here at techron. He's also a CTA or Futurum Group, which is a company we are in the process of combining with.
Mitchell can explain what the CTA role is, but let me introduce you to Mitchell. Ashley Mitchell. Take it.
Good to be here, Alan, and what a, what a group. Um, what a fantastic group. Yeah, I'll, I'll be your panelists.
I'll be your co-host. I'll be the the chat guy. I'll be the bottle.
Watch whatever you need me to be, Alan. I'll be so no. Just recently, as part of our, um, acquisition process with Futurum, my role's expanded in addition to the doing the analyst work that I was doing with Textron Research.
It's, uh, I have a new, you know, we had to create a new, new title, right? But I'm one of, uh, five people that are Chief Technology Advisors, which is kind of a, a glorified analyst on steroids doing advisory work and analyst work and, and things like that. So it's, it's a lot of fun that, that, uh, being part of the acquisition and, you know, still, but still working with all my old friends as well as new friends.
So it's good to be here with everybody. And yes, I started as a developer and yes, I've designed some really bad I APIs and a few good ones. So we have some lessons that, that I can bring Learned more on the, on the bad ones.
But anyway, uh, thanks Mitch. And welcome. So, as I mentioned, API traffic today represents a clear majority, if not a critical mass of traffic on the internet.
And I'm gonna ask someone to explain what that means to the lay folks out there who may not, we don't have that many lay folks, but people who may not understand I'm not, it's, it's either API generated or API to API kind of thing, or, or, you know, somewhere along the line there's an API involvement there, that traffic. Um, but, you know, the effect that an API first mentality has had on the development process in general on testing and security in particular is, has been pretty profound, right? I remember the first time, like this whole thing became clear to me.
I had that eureka sort of moment. I was at a CA world, so I should give you an idea of how long ago this was. Um, and, and, uh, they had done an acquisition that company based in Texas, and the folks from that got up and said, you know, it's an API driven economy.
And I was like, wow, an API driven economy. What, what the heck did that mean? And I, you know, I I, I learned more and I, I dove in with it and I realized it was an API, you know, we were moving into an API driven economy when we talk about, you know, digital transformations and, and stuff like that.
And, you know, I think the next logical extension to that was API first, right? That's the default. And, and of following from that, of course, you, you, if you're gonna have that kind of API footprint, you damn well better be doing API testing, right?
To make sure this stuff works and make sure, and then in the last four, five years, API security has become paramount in many ways, right? API security is replacing web application firewalls and stuff like that because WAFs, that API traffic kind of flows under the radar of the wac, right? And so we need something else to kind of make sure our APIs are secure and locked down enough to make your head spin.
Um, Chris, see if it's okay, right? We'll say Chris C and Chris l Chris C why don't you take a crack at explaining in your mind what API first means when we, when we use it in this context. Absolutely.
And, you know, um, to get there, I think I wanna talk, I wanna touch a little bit on that API economy, because that's really like, first and foremost for me, what's driving the API first initiative and just, uh, unironically About an hour ago, I was just talking with ESRI. Um, they're the guys that do a lot of the map, the MAP APIs. Um, they were kind of behind MapQuest back in the day, and I was talking to the guy and he was saying that before that, way before that they were the ones that powered the Thomas guides.
You remember those things that were under your sheet? Sure. You Were in your car, right?
Mm-hmm. We were a logistics company, right? We, we, we, we had a database full of rich maps that we would then compile into a book, and we were a logistics company.
Let's ship them. And then eventually it some point that just went away. And now they are an API first company.
They sell their API to Google Maps and to Apple Maps. And so their entire economy is based around their map, API. Mm-hmm.
And so, uh, to me, that's what the API economy really means is, is it build businesses are building their brands. And a lot of what's powering that is the API. And if that is the critical path to your business, you really have to have an API first mentality when it comes to building them, securing them, testing them, validating them, and really, most importantly, securing them.
And so that's to me, what API first kind of means. Jump panel thought on that jump. Go Ahead.
If I can jump, I'm gonna jump in on that too. I love how you set it up, Christie. Um, 'cause you think about it, historically, APIs were the things you might add for the exterior of your application or your software to kind of the ingress and egress.
But everything inside of it was your app, right? And, and A-P-I-A-P-I first is just the opposite. Your app is all run through APIs.
Even if you don't have a gui, you UI use your interface. Um, and matter of fact, if you do have a u ui, the UI talks APIs to your app. So the same APIs that you might share with, um, providers or people that are buying your service, matter of fact, your service may be just the APIs like Chris is talking about.
Um, and in doing that, I remember APIs just getting kind of unwieldy and getting outta control just 'cause we added 'em where we needed 'em here. And how long are they gonna be good? And do, do, do we, as they evolved, how do we grandfather old versions of 'em?
And now we have whole philosophies around the life cycle of APIs and how you manage them. And they're, they think of, we think of APIs as the product because almost all, every app now is exposing those APIs either in a, in a microservices world, very heavily API or, or also to the external world, to people that are buying our products and services. So I, I hope that does justice to what you were talking about, Christy.
And while you know that, um, there are, I mean, companies do rely on external APIs. I, if I'm thinking about what our architecture looks like, we probably have 20% or 25, maybe 30% of external APIs. But most of what we do is internal APIs.
And building internal APIs has a, you know, there is some, um, and when I think of API first, I think about what APIs do we need? Let's think about what that looks like. And I like to refer to, uh, you know, I preach often this concept of domain driven design and understanding what are your domains?
What APIs do you need? What are the, you know, what are the, uh, what are the connection points? What does that need to look like before you ever start writing an application?
But for the most part, we, you know, to, to be quite honest, this is not a new, uh, concept. We tried to do this in, um, c plus plus and common libraries. A lot of companies, uh, when I was working for Discover Card, we did aton of work around initially defining what that com, those common libraries should be, should look like.
And that's really what APIs are. They're common libraries, what we can reuse. And really taking the time to understand what those high level domains are and what we need to create is super critical in building a, um, a true kind of API burst forward thinking model.
And that's because if you don't do that, and if you don't manage them well, and you don't communicate and collaborate well, everybody's writes their own APIs that do the same thing. Mm-hmm. And that's what we don't there, and that's what generally happens.
And we've done, we've made this mistake as developers over and over and over. We constantly make this mistake, you know, everybody has their own login routine. Everybody has their own error routine processing.
Everybody has their own access to get the customer address. Um, so understanding domains and understanding how APIs should be structured within your organization and how you can break it out and allow ownership of certain domains is critical to an API API first, um, architecture. I agree.
I, yes. So, you know, the other thing I want to just tack onto it is, you know, what, what are your APIs doing? What, what's the purpose?
And in the old days, you would just write your software. You would be in a ui, you would be, you know, either, you know, web-based, where everything's all self-contained, and then you started pulling apart doing the APIs to now when you're developing software, you're thinking about it, there's multiple facets You have to think about, are you gonna expose any aspect of it for reporting or part, uh, you know, business to business or, uh, you know, are you gonna be consumed by other tools internally, um, for, for any reason? Or, you know, what's the UI gonna be?
The UI In today's world, when you're, when you're thinking of an application, if you're thinking of just web, you're, you're being very shortsighted. Do you wanna go web based? Do you want to go mobile based?
Or, you know, other technologies out there? And as, as Chris said, you know, talking about, you know, you may have an application that is nothing pure, but pure a, a, you know, APIs. And that's okay because it, again, it's, you know, just, it's all about the usage and what you're actually trying to accomplish.
Agreed. You know, when when I hear API first, to me, there's sort of a chicken and the egg question there, right? What comes before the API or is the API that first?
The chicken, chicken, and no, it's not the chicken. I think first before you, you don't start with the API first. You start with sort of plan of, Hey, I, I want an application that does this, that, or this and this, right?
And then we think about, okay, how am I gonna go about doing that? Right? So I, I think the, the planning and, you know, laying out storyboarding, if you will, or, uh, designing of the app is, is first.
But certainly once we get into that design, we start thinking about APIs and potential APIs, I think before we start coding, certainly. Would you agree that, that that is the essence of API first, right? Before we even start coding, we're thinking about how APIs are going to make or break, or how they're gonna work within the app that we're designing.
Yeah. Because that, that's how APIs are gonna pay for themselves. You know, me as a young developer, I would've loved to had, you know, been a, you know, we talk about feature teams now, you know, instead of application teams, you have feature teams.
Well, me as a feature team working on a particular, what would be delivered as an application, I get to go talk to other teams that are doing features, which means I don't have to write all those queries. I can figure out what they already have, if it's a well organized API structure, and everybody can share those APIs. So that pace is for itself.
It's, you know, APIs can save a whole lot of cash when it comes to development because you're reusing objects. So a hundred percent. And it's has to do with money too.
Yeah. Yeah. It, it does do that.
If I could talk on that, what's it just, just because the plan triggers me, right? Is it immediately makes me go to the service definition, which I'm sure a lot of the season guys here are gonna roll their eyes, right? The service definition is not a plan, but a lot of organizations say, this is the beginning of the process, right?
Let's, let's write our service definition. Let's write our contracts. Let's start putting in place the actual semantics of what this API is going to do.
And what's interesting, if I kind of double click on what Tracy was saying about the domain, and specifically what Mitch was saying about sprawl, this creates a problem because you're not doing that upfront ideation work to say, what is the minimum set of APIs that we need in order to provide the value that will ultimately provide the money to our organization? And this leads to something which I'm seeing a ton right now, which is API and new API is the answer to everything, right? Okay, we got this new functionality, let's just add another API, let's add another API.
And before you know it, you have this massive API sprawl. And so I really do think coming back to the domain of, and the why and the, and, and, and the, the minimum set is super critical to this, to the planning phase before the service definition is even put in place. You're saying we can replace the phrase, there's an app for that to, there's an API for that.
There's an a p For that. Yeah. Yeah.
Well, you know, and, and Chris, the thing that comes to mind when you were talking about that is solid programming principles, right? So, you know, when you create a class, you create a method. The goal is, I've created it, I can add to it, but I cannot change it.
And when you look at APIs, you know, you may run into, I need a little bit more or a little bit changed or a little bit something. 2, you know, and and so on and so forth. And then all of a sudden, you know, to to everybody's comment here, all of a sudden you may have started off with, you know, 150, 200 API endpoints, and now you're well over a thousand.
Yeah, Absolutely. So I mean, it really, APIs, even though they save a lot, um, it like microservices, it's complex 'cause you're decoupling pieces. And when you decouple pieces, you cra you know, it's your, your puzzle now is in, you don't have, you don't have the top of the box to tell you what that puzzle's supposed to be.
And you have all these components, all these tiny puzzles of pieces laying on the, you know, on the table. And you gotta figure out what it is that you're creating. So that's, you don't Have this when the blast radius gets really large Tracy, right?
Yes it does. Okay. Blast radius.
Here we go. Um, But that's an interesting, that's an interesting aspect too, right? And it becomes that yes, I have this giant inventory of APIs and I may want to Chris's point, sort of just add incremental functionality to it and, and change its version number.
But in a lot of cases, the APIs are used by disparate teams. And so they might not know, uh, the, the major difference between the UI and the, and the API is the UIs are designed to explicitly tell you what it's doing. You go to the screen, you get it, okay, I'm logging in, I'm creating an account.
APIs will do the same thing, but they're not explicit. And unless you love reading swagger definitions, you can't immediately know what an API is doing. And so that's where that, I think a part of that sprawl comes through is people go, Hey, I don't think this functionality exists.
It's like, well, actually yes it is. It's a subset of this other API that. And, and so I think this is one of the challenges that I think the contracts and service definitions and definitely the trace, uh, to Tracy's point, the, the conversationing around what exactly are these APIs for becomes paramount to an organization's API success, Right?
Well, and as an API matures, then what happens too, just like you were saying, you may have certain aspects of multiple pieces of APIs, Hey, to accomplish this task, I have to hit seven different APIs to get all the data. And one API may take forever to run, and I just need one aspect of its data. However, a lot of it is actually tied to the same background or, you know, the backend.
And so instead, maybe I just create a new endpoint to pull what I need. And the next thing you know, again, sprawl And it's a collaboration that will prevent the sprawl. Yes.
You have to have the collaboration. You have to be, if you don't know an API exists. And, and there's no way to find out.
You're gonna write it yourself. 'cause you might go, this is gonna take me, oh, it'll take, it'll take me 30 minutes to write it, even though that's not true. We do that as opposed to go hunt down somebody who's already written one.
So the collaboration is essential just, um, across teams, much less really building out a collaborative API structure. Couple things there. First of all, I think that was job one.
Um, in the API security arms race, when API security started becoming a thing. I think the first thing these API security solutions were doing was say you, it's 10 o'clock. Do you know what APIs you have?
Right? Because, you know, they're API sprawl give us so many APIs, APIs, talking APIs, talking APIs that most organizations really did not have a handle on what APIs were interacting in, in and within their system or on their system. And let alone what their settings were, their security posture, et cetera.
You can't defend what you don't even know is there. Mm-hmm. And that, that was, you know, that was phase one of API security.
I think it's expanded beyond that. It's matured. But that was certainly the first, the first, you know, kind of thing about it.
Um, the first part of, of, of API security, I wanna turn, you know, beyond the blast radius of API security of API first And talk about API testing, right? Because, you know, that's the logical next step. Okay?
So now we are going with an API first mentality. We're gonna have these a APIs that are, you know, in, in the right from the, from the design phase. We, we are designing APIs in.
But of course, these APIs need to be tested, don't they? Um, you hope. And so you have to get into API testing, but yet I, when I hear the phrase API testing, I still think of, oh, I'm using APIs to do my testing, right?
I, it, it, it sort of adds a layer of automation to my testing. But no, that's not really what I think we're talking about. Yeah.
I think most, Oh, go, oh, I'm sorry, chase. No, no. I was just gonna say, I think when we talk about API testing from a developer perspective, I think about functional testing and validation testing.
I don't worry about performance testing or security testing or load balancing or any of those other pieces. I assume somebody Automate that. Like developer.
That's what We do, right? I wanna validate my endpoints. I'm gonna do my functional testing if that's good.
I'm going That security testing. Yeah. Um, Chris, Chris l I'm, I'm hoping you have a different attitude towards it.
I do. I'm sorry, Tracy. It's Okay.
My attitude is, you know, it's, it's a view into your system. And as such, you need to do multiple things. You know, I, I go to conferences, I see applications.
I talk to people I, I with, with penetration testing software. I enjoy going out and attacking and breaking things. I love seeing, you know, what kind of data I can get back.
You know, some systems, you know, you can easily break simply because improper security, improper logging, and proper a lot of things. And so when, when you're looking at APIs from, you know, a, a a standpoint, there's multiple aspects that you have to consider. You know, the, you know, how does it perform?
Because I can come in and do a denial of service attack. If you have a poor performing, performing a PII can call it multiple times from thousands of endpoints simultaneously. If you have an API endpoint that shares data that it shouldn't be sharing, now I can steal data.
If you have an API endpoint that is just not well put together, it it, it's very obvious from a security standpoint. And so whenever I was actually doing my, my development days and doing senior tech reviews, I would look at, you know, how do they perform? I would look at using tools to look at the payload as it goes in, as it comes out, what kind of things, time to run the time on the backend, on, on the database, it all the way down to that level just to ensure that, you know, is this performing?
Is it doing what it has? And, and beyond that, you know, you also have the security things that you can throw in there, such as SQL injection and, and other various things that can, that can happen. I'll stop.
I can keep going, but No, I get Chris c you other real tester here. What do you think? Okay, first off, I'm in the vendor space, right?
And so nobody knows less about testing than the actual testing vendors. But I will say this, um, I, I am encouraged that we're talking about development forward API testing. Because quite often in the testing industry, that's put firmly on qa.
And there's these really interesting conversations. Whenever we go to a, a first time API tester where they go, well, whose responsibility is it? Is it, is it the developer?
Is it the tester? Now we all know it's both, but it's at a spectrum. And the notion is that, hey, I'm a developer.
I created a service definition. I should be able to hand that to the, to the tester. They should be able to ingest that and use it.
And the tester says, Hey, you're a developer. You're building the API, you should test it before you give it to me. And there's this constant back and forth.
And I think to both Tracy and Chris's points, there's different levels of testing that you do as it's maturing through the cycle. And the, and the first one to me is contract testing, right? I want to make sure that my service that I'm building is not only complying to my business expectations that I've set forth, uh, for the, for the function of this API, but also that the consumers of IT are not going to be affected if I change it.
Right? And so, I don't know if anybody's really, um, uh, grasped onto, um, uh, uh, uh, contract testing quite like some companies like PACT have. But it's this, it's this really strong grassroots movement that's happening right now 'cause it's developer forward that basically says, I'm only gonna write into this test from a development coded perspective that are my expectations of an API.
That way I can continue to do what I'm doing and know that if the producer of the API makes a change, they're gonna run my contract and know that they've broken me, which fosters collaboration and communication. Those contracts are the seed for everything. Because you can mature those into greater and greater levels of more complicated functional and integration testing.
And then once you have all of those contracts, you have all the attack vectors that you need for your security testing. So I really think that this whole testing thing starts from the moment that first line of code is written against a contract, write the contract. But again, it's all predicated on whether the service definition exists.
Isn't, Isn't also, 'cause I remember us using kind of contract with APIs in a little more general way before this, this movie you're talking about. And really a contract in that sense was here's how you use the API, here's the, here's the expected behavior in terms of how you interface with it, and here's the expected behaviors of what it's going to do when you use it in the specified ways. And I think to your point is if you go wacky and do some SQL ingestion, or you do something else and pass different parameters that aren't part of the API, it's not gonna respond or it's gonna give you an error or some, some definition that's out, out of bounds of the contract, is that still consistent with the movement?
You're talking the developer forward? I, yes. The contract is, um, again, it's an overloaded term as are many things in our industry, but it, to me, the contract of the API is the service definition that defines semantically and logically what this API is supposed to do.
And you can use that both as a human document to read, to understand, but probably more handing it to the business to to, to the, uh, to the appliance so that it can ingest it and create clients to actually communicate with the API. Um, that same, that contract needs to be tested. Is it semantically valid?
Does it, does it follow all of this? The, the spec definitions that we have for service definitions, has it changed recently, et cetera, et cetera. Um, and then that, that component is then used to test the function of the API in its entirety.
This is a, this is a, a, a second piece to that, which is I'm using the API in a very specific way, and I have complied to the service definition. I'm doing everything right. I wanna know if anything has changed, um, or if what I'm trying to do and what's critical to my business.
I'm Bank of America. I'm communicating with a PayPal, API, I'm only using like three fields of it. Don't change those three fields and do whatever you want with it, as long as you don't change those three fields.
And if you do change those three fields, you gotta talk to me and say, I'm changing the three fields. What can we do about it? What can we do about it?
That's the, that's the difference between those two types of testing. And there's something that happens when APIs aren't really tested well. Um, there is a trust factor that we have to always keep in mind if you're an API developer, uh, to make sure that you're doing that testing and that you're maintaining those contracts.
Because what happens is, in that example that Chris just gave, that consumer may decide not to take on that new version of an API and that causes a DevOps nightmare called Drift, which means you have multiple versions of your API that are out in the world or being consumed internally by many different application teams that you have to support, maintain, and make sure are secure. So the API testing if is so critical in building that trust so you don't end up with so much drift. You know, we talked about sprawl, sprawl is a problem, but drift is as big a problem, if not bigger, when it comes to trying to secure the, the, the environment, Right?
And then one of the things that I've seen is a lot of QA departments use automated, uh, regression tools, and their thought is, Hey, my, my tool passed regression tested. That must mean the APIs are good. Let's move on and let's, let's, let's, you know, consider it good.
And to both Chris and, and Tracy, you know, their point is, look, the contracts possibly could change internally, something could get added, modified a a definition may change. 0, and now you're version 30 and you can't get off of it. And by default, most people who are writing APIs are not logging or doing any metrics.
And when you're not doing any metrics, you're not knowing what API endpoints are being used, how they're being used. You don't know the details. And so the problem becomes, you know, you're sitting there, you're creating drift sprawl, and, and you don't know that, hey, guess what?
Version one is still being used, but versions two through 15 aren't, and having been for a given time. And so those could be deprecated. So instead, at c at a certain point, depending on design and what's going on, you may have to go make 30, 40, 50 changes, you know, spread that same change out across all the API endpoints where if you were paying attention and, and doing good development practices, and, and, and analytics would tell you, Hey, you know, you have people that aren't moving off version one, why?
Ask the why, what's going on there? And then determine, you know, can, can they move up? Or is it just a, a breaking code change for them?
And if it is, you know, how do you deal with that? And, and how do you work with that? Because at a certain point you need to move forward.
So, but this, this is, this is a bigger problem. You're touching on Chris, right? This, this is the, the sprawl aspect of it.
We see cloud sprawl, API sprawl, you know, are all developers and IT people hoarders at their core, maybe because none of us seem to want to delete anything. Me, I, I find a certain joy in like cleaning out my closet and throwing out things that, you know, I have a rule in the house. If it hasn't been used in the last year and a half, we're probably not going to use it.
There's better things to do with that space. Do we need to, and that's, by the way, that's something we could automate with APIs. And if that forces people to move off of version one to version five because they've been sleeping through the last four upgrades, or refuse to do it, so be it.
Right? Apple people used to knock Apple for that because they did, they stopped with the backwards compatibility for five years old software. If you didn't have the last version or two, the heck with you, you couldn't run the latest stop.
Mm-hmm. You know, Microsoft stuck to that backwards compatibility thing for too long, in my opinion. Should we, is good API hygiene, meaning adopt something like that?
Wow. That's a, a cultural shift. Because I do think that, uh, developers tend to be a bit order as you explain.
Yes. Mm-hmm. I mean, think about even, um, building a cont a container for an API, you probably gonna bring in stuff that you don't even need because you don't, you're not sure if there's a dependency on it.
Um, which is part of the, our current security problems, um, is these transit of dependencies and what APIs calls what API, uh, becomes more of an issue. So it would be hard to get folks to start really cleaning house, I feel Like. And do you think about SBUs?
You, you mentioned SBUs. SBUs. I, I was not gonna say SBUs, but, Well, no, we're not Thinking about about SBUs.
I, okay. But I do think that AI could help solve our blast radius. Okay.
Blast radius. It is. So we're talking about blast radius.
We could use AI to do that. We could use AI to limit the blast radius, but shouldn't we use AI to just limit API sprawl And drift? Yes.
And drift. I mean, it's good security, I think. Well, and AI is doing so many amazing things today.
You know, from a standpoint, when you're looking at using AI against your APIs, you know, it now creates a lot of, you know, background. It, it gives you a lot of visibility in the things that you didn't have before. It makes it so much easier to, you know, to connect, to get that information, to know what's happening behind the scenes, and to be able to detect anomalies.
You know, you may be up and running and, and AI can go, Hey, guess what? I'm noticing something interesting. Or, you know, if you are doing logging or whatever, AI can also pick, you know, pinpoint and go, Hey, wait a second.
Something's happening. Tracy, you know, she, she lives here. And somewhere on the other side of the globe, Tracy logged in again.
Problem. You know, I wanna, I wanna bring up ball. Is there, there's also kind of some, we're talking about some challenges with managing this whole ecosystem, right?
Of APIs. One of the things I think is really great about APIs, Tracy, you were talking about c plus plus remembering back in the day of, of stubbing, uh, stubbing off methods. You know, we would like Harris's the structure and I don't have time to write that yet, so I'll just put a return in there and pass some data back.
And, and, and now we have such a better way of not just stubbing, but actually creating the API creating some logic behind it. We could have, you know, some tests actually built into that code that isn't fully been written there yet. Um, but maybe it's generating responses, right?
That we wanna to, uh, be able to test with as part of that API as well as we add the, the function, the service of what it is. And so you can, I think you can build software faster through this API first approach. Um, 'cause you're not managing a big structure, you know, a big object structure with parts stubbed out and some parts not.
And who's got what part of that tree? And I'm using this version of this microservice, this, this API, and it's, it is, it's just stuff there. It's great for building and testing, and I'm gonna replace it with the, with, uh, Chris's, whichever Chris wrote it, Chris CL.
And, uh, you know, I can continue to just evolve the app that way. Agree. Don't agree.
Am I, I agree doing funny stuff in Colorado, or I gotta, I gotta jump in here. Like, one of the things I said at the beginning with my introduction was that I, I, I am over two products, right? API testing and service virtualization.
I don't get to say this very often, but service virtualization doesn't get the love that it needs, um, in our space. And I think that from an API first perspective, it is massively important for jump starting, you know, any API initiative. And to kind of wrap this into the sprawl and the drift thing, observability can be a huge benefit here, right?
Because what we, what we're finding when we're going to a lot of our companies is they're like, we want to do this. We wanna go API first. We wanna test what we existing, what we currently have.
We wanna understand what people are using, but we have no idea what APIs we have anymore, right? Because everybody's kind of cycled out, et cetera. And, um, observability allows you to not only observe the system under motion to understand the actual APIs that are there.
'cause guess what? A lot of those internal ones that, that Tracy was mentioning earlier, they're not documented. There's no service definition for them.
And the observability is the only way you're gonna pick up on those. And that same traffic can be used to generate those initial service tests, those initial vir virtual service says, which is so much more valuable. 'cause it's not just a dumb stub.
It's one that actually simulates the business logic and the, and, and, and, and the expectations of the system under motion. And then you use, and you kind of build your new API scaffolding around that. And it's a great way to get started is leverage your existing observability for service test and service virtualization creation.
I love that term. Your service under motion. It's a great visual Service in motion, Under motion.
So it's in motion. Yes. No, no, it's under motion.
It's great. Just running something, An 80 song, It makes sense, right? Yeah, Yeah, it does.
It's, it does. There's another part to this too, and that is the API security. API sec, uh, part of security is one of the first things is API discovery.
So if things are going through a proxy or something that's, you know, flow flowing through, um, whether you call a firewall a proxy, whatever it might be, that's another collection point, if you will. Like you're talking about Chrissy, where okay, what is that? You know, there's 25 things that happened today.
Nobody knows what that thing is or didn't know somebody else was using that way. We didn't know that was going externally. So that's another kind of data point you can pull into figuring out what's Happening.
Well, AI had mentioned that earlier. You can't defend what you don't know. You most people don't know what APIs have.
Well, and, and from the sbo, I'm sorry, from the SBO piece of it, you don't know what dependencies that API is calling into play here. Chris, Chris l you've got something to say. Go ahead.
Yes. Yes. So, you know, when, when you're looking at the APIs and, and the data coming in, it's just like a ui.
You have no idea what kind of crap people are gonna throw at it, what length of information people are gonna throw at it. What kind of information is, is inbound outbound? Because, you know, crafting a good attack, you know, you, you can do things and, and, and skirt under the radar depending on design.
And, and I love the, you know, what, what Mitch was saying, you know, the very first thing, if I'm gonna come attack you guys and look at what's going on, you know, I'm gonna figure out what API endpoints you have, I'm gonna figure out what's going on there, and then I'm gonna start, you know, overloading 'em, seeing what I can come up with. And it's, it's amazing how many people overlook the role-based access. You know, if you get a JWT token, you get in the door, guess what?
Now I can do a lot of things that I shouldn't be able to. Fair enough. Guys, we, we try to keep these sessions to 40, 45 minutes, and I think we're up against the clock here.
Um, first of all, great conversation, great conversation. I, I think look for our audience at home. Takeaways three, three things.
I always like to leave these kinds of things, or three key takeaways. Number one, we absolutely do live in an API economy, right? APIs are driving the internet, it seems, if we look at traffic loads, number two, an API first mindset in, in how we plan and, and develop our applications is I think the norm, not the exception today, right?
Do we all agree with that? And the third thing is, if all of these APIs are out there, you're not doing API testing. And that includes API security testing.
You know, the, the, the, the, what's it, what comes home to roost? Mitchell Chickens can hoan drew The chickens, come home to roost? I knew it was some foul.
As the Nebraska boards come, that's the Nebraska boy right there. And of course it expands, expands your blast radius. But I realize we gave nobody any context at the beginning as to why we are doing that.
And I love it. We have a very, very sharp audience. They picked up right away on it, but it's not the first time they played this drinking yet.
Um, anyway, Chris and Chris, thank you so much for being our guest today on, uh, DevOps Unbound. Tracy is, as always, it's a pleasure to have you on here. Love having you part of, you know, not just DevOps Unbound, but you're under, you're one of the gang members.
I'm Textron Gang and, and of course, uh, tech strong women and everything else you guys do. So thank you. Thank you, Mitch.
As always, you take the last word. Um, I just party thought is there's an API for that. I said, fair, fair enough.
No doubt. Hey, many thanks to T Tricentis, as I said in the beginning of the show for sponsoring this. They're a great company to work with.
com. Until next time, this is Alan Shimmel for Techstrong. Quick reminder, July 24th is our next live round table.
Don't miss it. But until then or until our next show here, we're out. Thank you.
Bye-bye.