Techstrong TV – January 14, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hi, everyone. Happy Tuesday. I've got nothing funny and witty to say today, situation in Los Angeles is, it's kind of dire and it's a tragedy, and it's nothing to kid around about.
We're gonna talk about it first today here on Text Drug Gang. Hey everyone, it's Alan Shimel here for Techstrong Gang. Happy Tuesday to you.
As I mentioned, we're gonna kick things off with a little bit of coverage of what's going on, the tragedy going on in Los Angeles. And, you know, we have folks here in, uh, tech Strong and Futur who've had to evacuate, who are worried about their family's precious belongings, their very home going to, are they gonna have a home to stay in? So, it, it really is crazy.
We're gonna talk a lot about it today, but let me introduce you to our gang members to discuss that and more today. Um, but before I do that, I wanted to mention one other thing. If you're not watching Predict 2025 today, head on over there.
If you're watching this on Tuesday, head over there. It's on right now. Predict 2025.
You could always catch text on Gang on Demand later. You can watch Predict Later too. But there's some amazing, amazing sessions on Predict, including what with my friend Steven fst.
So let me kick things off with our friend Steven Fst. Of course. Steven is the, uh, founder and CEO of Tech Field Day.
I have Sister Future and business unit here with Techstrong. Steven, it's great to see you. How are you, man?
I'm doing pretty well. Uh, looking forward to a baseball park tour with my friend Jon Swartz. You know, maybe not that late.
I hear Pittsburgh is, is is in Cleveland, are the two best stadiums, right? Steven? Let's hit 'em all, baby.
Let's hit 'em all. They'll just Give, you know, maybe we could do like a show on Textron for that. John and Steven on the road shoot video.
Oh, we could talk for hours. Yeah. Yeah.
That, that would be it from, you know, comedians in Cars. Um, Stephen, welcome. I mentioned Jon Swartz.
He has, he has left the kingdom, his kingdom of Silicon Valley, and he's actually in Pittsburgh today of all things. Yes, I am. I'm, I'm really happy and, and looking forward to seeing some robotics at Carnegie Mellon among other places.
Um, I'm meeting with a lot of folks here and I think it'll be a lot of fun and quite educational and kind of segue into our first segment. Excellent. Thank you, John.
Thanks for joining us. Joining us. Well, she's home it looks like, so No, no.
Great story here, but it's our newest gang member. She was newest gang member. We had announced her last week.
She's actually worked though with Steven and the Tech Field Day and Gestalt it folks for many years. She's working on our tech strong AI site, among other things. It's Sona Soha.
Did I get it right? Saha. Saha.
All right. Pretty close. I'll keep working on it.
Sagner, welcome and thanks for joining us today. Thank you. Good to be back on the show.
Good to have you. Um, joining us, we've got a full house. It's good to have a full house back here in the Boca Studio.
On my far left, the guy with the ponytail in the beard, he's a future VP analyst. He came here to warm up, he says, from Native Colorado, where it's snowing in single digits, and it's supposed to go down to, what'd you say? Minus 1715 minus crazy number over MLK weekend, Mitch Ashley.
Hey, Mitch. Good to have you here, man. It's nice to be in defrost mode.
Yeah, it's, it's visit. It's good for you. I'm glad to have you here joining.
Mitchell and I here, the lady in the middle, she is our sustainability and Echo Insights, uh, editor and analyst, Bonnie Schneider. Hey, Bonnie, how are you? I'm doing well.
Great to be here, Alan. Yes, thanks for joining us and adding a little class to the whole operation. Yes, Mitchell and I here, you know, we need use it for sure.
Yeah. Um, all right, gang members. Let, let's jump into this.
I want, you know, Sona, John, you guys had, uh, an interesting, a little piece about how tech, I want to say, is helping to fight fires, but I don't, I don't want to be that optimistic, but it's certainly being applied to help fight these fires. What do we got? Well, uh, you're right, Alan.
That's a good way of putting it. They're trying to help, um, with drones, uh, robots that are remote controlled that can go into places where humans can't to help fight or at least find out what's going on in certain buildings that are a blaze. Uh, we have sensors that are all around the place in, in, in, and forests in areas that are, that are susceptible to fire.
Um, we've got, actually, there's satellite systems in use a lot, as I mentioned, drones. There's a lot of AppSec. There's one called Watch Duty, which offers updates on active fires and cruise fighting them the weather conditions and push notification alerts.
Uh, there have been efforts by some of the social media companies like Amazon and Meta to team up with government agencies. They have been doing this for a while to help the state anticipate where people will evacuate. So counties and states can provide them with housing, medical supplies and food.
You know, the Department of House, Homeland Security Science and Technology Directorate has been working with state and local fire agencies and private businesses to develop technologies. You know, there's all these efforts, and yet this is something that almost feels, I'm not gonna, I'm not gonna use the word futile, but it's very frustrating because as essential and necessary as this all is, we are really at the mercy of climate change, which has led to these record temperatures around the world. Oceans are, are unusually warm.
I mean, we basically, and Bonnie can go into this much better than I could. We've reached this era, this dangerous era of, of storms, floods and fires. So it is essential that these technologies put be put to use.
But at looking at the scale of where this fire is, why, where these fires are, versus the technology that's in place, it's, it, it seems kind of like a losing battle and, and utterly frustrating. But at least we are making efforts to help people get away from the danger. I'm not sure how effective we will be in the long term in terms of preventing these types of things.
There is technology that preemptively looks, uh, or smells things before they become smoke. Um, there are a number of companies working on this. We've written about this over the last several months, but again, this is a really horrific situation, which we're gonna see more examples of, not just in California, but in other states.
And it's, um, it's just an ongoing battle and something we're gonna have to face in stomach for years to come. Sladi your thoughts? Um, yeah, I, I agree with John.
Uh, tech is definitely playing, uh, small, but, uh, pivotal role in, uh, the wildfire suppression Yeah. Is obviously being used to detect and, uh, protect the fire, um, for any kind analysis and, uh, overall guiding the fault. Um, drone on satellites are used to survey the area, track the fire progression, IOT and AppSec are being used to spread situational awareness and, uh, for fast responders to communicate better and improve response times.
But it actually all comes down to the how effectively we are able to control, uh, the fire. And with climate change taking on and getting worse every day, I, it, it's really a losing battle unless we do some, I wish there was a technology for that, but, uh, unless we can fight that, I think it's going to be pretty harsh for the people living there. Absolutely.
Yeah. I just wanna, I agree with both what you said and with the climate change, you know, some of the issues are that even if a fire is on track, they, they could say, okay, this is where it's located. Fires create their own weather.
And that would, that's one of the reasons that makes them unpredictable, and which they'll, which way they'll go from there and, and how the wind will move the, the embers and flames. But also in terms of climate change, the intensity of these extreme weather events that's been ratcheting up. I was just looking at the records for 2024 versus now.
Um, the problem is every event that we have is amplified and intensified. We saw hurricane force winds with this fire. So, um, unfortunately that's the pattern that we're leaning.
We're moving towards where we're gonna see more intensity with these events. It's a com combination of things, right? It's the w it is the wind intensity.
It's also the amount of fuel available because of climate. Exactly, exactly. Record rains last year, and then a drought this year.
It, it was not a, a good situation for California Reach a, a wind level where the planes can't fly. So now you've lost one of your biggest battles or your, your weapons battling this. Definitely.
The severity is so incredible. I mean, when you look at, there was a chart, I think it was on CNN or, or M-S-N-B-C that showed the number of major fires just in Southern California alone. And that have been tracked since 1937 or thereabouts, and about 80% of them had happened since 2021.
And you, you say with, with, uh, with the events and, and the, the climate change situation that we're in, I think it's just gonna ratchet up. So I guess I, I don't know, Bonnie, is there, I i just curious, is there anything, something like predictive analysis or any type of AI type of tool that Yes. I mean, there definitely is, and I did some reports on it, uh, for Ecotech insights.
Um, we, you know, we talked about the drones. That's one way of, of getting an idea of where these, um, fires may start. And the modeling has improved overall for where a fire I remember going to actually to Boulder, to ncar, uh, where they do a lot of weather, um, prediction and modeling.
And it's improving. But the problem again, is, is that you have to factor in that the, the intensity of climate change. So the, the massive scale of particularly the Palisades fire, I mean, that's why, you know, you're seeing these firefighters come in from multiple different countries and different areas just because it is just so large and so intense.
And unfortunately, as we are looking at Tuesday, Wednesday weather, we're looking at more fire danger with the winds. I wanted to quickly jump in here on one of the tech, um, a one of the AppSec that you guys led with in that story. Uh, the watch duty app.
Um, this thing has been absolutely incredible. Um, you know, kudos to the people who created it. Um, kudos to the people, uh, you know, to making it free.
And it shows, to me, it shows that the power that tech can have to really help people on the ground. So essentially they're crowdsourcing, uh, information from, um, well, basically any source they can, they're organizing it and collecting it into a special purpose application. I mean, it's kind of sad that we need a, a fire, uh, wildfire, um, tracking application.
But, uh, we do. And it's become, uh, as of today the number one free app in the iOS and Google App Store, uh, surpassing something called chat, GPT, which I, I'm not familiar with. But the, uh, you know, the watch duty app has really rocketed to the front.
And from what I'm hearing, my friends in the Bay Area and in LA and in, um, you know, uh, the rest of California are saying that this has become sort of the most, um, well-known app. Uh, everyone has it. Everyone's using it.
Everyone's tracking the progress of the fires and air quality and figuring out whether they need to evacuate. Um, there's even been situations where they've gotten, uh, false reports of fires and they've used, uh, this app to, uh, refute those and, uh, to, you know, make sure that they're getting accurate information. That, to me, shows what tech and what the app economy can do.
5 million times as you, as you mentioned, it's, it's, uh, it's use Stephen, and it's also, anyway, it all comes down to is the people are much more important than the property. Um, I mean, it's, as is as hollow as that might sound, it is true. I mean, in a sense, the safety of, of people above everything else, and what we can do to help them or keep them informed is, is so crucial in these types of situations.
'cause it's, this thing is moving so fast, it's become so large and devastating. And, and the forecast, as Bonnie mentioned, doesn't look like we have much relief in sight. This is where I think, uh, disaster robots are, especially game changers.
They can navigate any terrain. They can douse fires, they can rescue people under dangerous conditions. And that, I think, can save a lot of first responders from harm and risk.
And, uh, many firefighters serving in the state prison too, have been deployed to battle the places. Um, they're paid less than $10 a day and a dollar extra for responding to active emergency situations. So using tech is absolutely imperative.
Uh, and, uh, yeah, helpful. This is one too, where there's an intensity level that you reach in a hurricane, a firestorm, tornado, whatever it is of, or earthquake of what you can't do anything about. Right.
It is just all gonna overtake. So it's as much about response as well as it is prevention. So you have to worry kind of just like security, right?
Yeah. You have to worry about both the same thing earlier. You know, Steve, I think Steven, you mentioned the, the watch duty app.
If you don't, you just wanna go to the website. com. Is that right, Steven?
org. Dot org. But, uh, yeah, and it's actually available as a web app as well.
If you, uh, if you don't have your, your phone handy, that's great. Yeah. Look, I, I wish there was a wand, magic wand we could wave here.
But, you know, one of the biggest problems I think we have as a society is we're always looking for simple solutions to complex problems and climate change and, and its effects on weather and fire and flood and pestilence. And, you know, the four horsemen of the apocalypse are complex issues and problems that there are no simple fixes and answers for. Um, in the meantime, you know, thoughts and prayers sounds hollow, but our hearts go out to everyone in the Southern California area who is dealing with this, uh, calamity.
And will, you know, maybe I, I'm always a big believer in tech could make the world tech can make the world a better place. Maybe there is something that'll pop up that can help them here. Anyway, we're gonna take a break here on Textron Gang.
Today. We're gonna come back and Bonnie has a, a piece on, on promises being made to reduce all that plastic Yeah. That winds up in the ocean and all of that microplastic stuff you're watching.
Textron Gang. Hey everyone, it's Sunny And Cher. Ladies and gentlemen, tech enthusiasts and Future Gazers Gather round the biggest, boldest, most mind blowing predictions for 2025 are coming your way at the Predict 2025 virtual event on January 9th.
Oh, Sonny, you're predicting something. Again, last time you tried this, you said laser dis for the future. How that workout for you.
Hey, hey, Cher. Not every prediction's a hit, you know, but that's why we've got the real experts this time, top analysts, visionaries and tech leaders sharing what's going to rock our world in 2025. So, no sunny predictions this time, no flying Toasters making a comeback.
Very funny share. But seriously, we're talking AI breakthroughs, cybersecurity game changers, the future of DevOps, cloud Innovations, and so much more. And what about my favorite prediction?
A smart mirror that tells you how fabulous you look every morning. That's real innovation. You're already ahead of the tech share, but if you want to hear the really big stories in tech for 2025, you've gotta tune in on January 9th.
The event kicks off at 8:45 AM Eastern and runs until 2:30 PM And the best part, it's all virtual. No stuffy conference rooms, no long commutes. Just grab your coffee, your laptop, and join us from anywhere in the world.
You know what else? It's not just predictions, it's insights, strategies, and a whole lot of fun. 0, predicting your jokes before you tell them.
That's a good one, Cher. But the real joke is if you're missing out on this, so don't miss Predict 2025. That's right.
Mark, your calendars, January 9th, 8:45 AM Eastern. Be there. Or you'll miss the biggest scoop on the future of tech.
See you at Predict 2025. Be there. Hi everyone.
Welcome back to the Techstrong Gang. Will, we're talking about promises made are they, promises kept. It's interesting when you look back over the past few years, the major tech companies targeted 2025 for the year, a hundred percent plastic free.
And some of these companies are already achieving this goal. Like Google, for example, Hey, announced last year, Hey, we're ahead of schedule, we did it, but others still are not quite there. Maybe they're 99%, but, um, all of the big techs says they are on target.
And this is the year we're going to see no more plastic when it comes to packaging, which can make a big difference in, uh, when it comes to fighting the battle of keeping our water clean and, and landfills less filled with plastic. So I took a closer look at three companies and seeing where they, what they promised and where they are now. Hi everyone.
I'm Bonnie Schneider with your Ecotech Analyst Insights 2025. That's the year that all tech giants promise that they'd eliminate all plastic packaging. Well, now that we're here, let's see how they're doing.
Leading the charge is Google, who's already crossed the finish line ahead of schedule their pixel phone. Fitbit and Nest Packaging are now completely 100% plastic free through Google's paper-based material. They've decreased their carbon footprint in transport.
Apple is racing to meet their 2025 target. iPhone packaging has reached 99% plastic-free status. But there is a reason for optimism, fiber-based packaging.
Apple is on track to meet their goal. Meanwhile, Samsung's Galaxy for the Planet Initiative faces its moment of truth. This year, Samsung has already made significant strides.
For example, check out the Samsung Galaxy S 24. It comes in a box lined with a molded pulp tray made of 100% recycled paper. Samsung, though is still working to replace some plastic components in their packaging for Tet Giants.
It's a sprint to the finish line to deliver on their 2025 environmental promises. Though some of the materials that these companies are using really shows that they're implementing their own technological skills and solving problems. For example, one that hasn't completely been implemented, but it's seriously being looked at is seaweed as a substitute.
Yes. So, uh, it'll be interesting to see if that that comes through. What's been happening now is really companies are, like Google is changing the type of paper that they use people using pulp, um, paper.
You know, you've probably seen that with packaging. Mm-hmm. So, uh, the innovation is here, it's coming, but I think in the coming years, even after we achieve plastic free 2025, it's gonna get even more, um, interesting and, and different in terms of types of materials.
We wouldn't necessarily think. One of them I mentioned in the piece, or, or maybe I, I didn't mention, but I was thinking about mentioning it, was Dell had tried something with mushroom fiber for packaging. Really?
Now they didn't stick with it because it turned out it was a very expensive, and it was a little bit difficult to massive produce and scale. But look, it shows ingenuity that they're, they're trying to think of, I would think cab Yeah, same easy. Like, but you, we see it in, uh, I think it's in Whole Foods actually, and maybe some of the other stores.
You know, when you buy your fresh produce, you used to get those plastic bags off the roller and you're ripping open it by, by us here. Uh, they're using compostable mm-hmm. Compostable bags now that aren't quite plastic.
They're plastic gly, but much more economically, uh, not economically, environmentally friendlier. Uh, look, I get that Google's doing this, and Google's certainly a big company, but they're not, I mean, in terms of the amount of consumer packaging they put out there, pales pales in comparison to Amazon. Right?
I mean, and, and I, full disclosure, I've been an Amazon Prime member for many years, and I usually get at least a delivery every other day from Amazon. But I've seen a, a tremendous, uh, change in their packaging. Mm-hmm.
Yeah. You know, more smaller, easier, more lightweight, less plastic, more recyclable or recycled ingredients. And so kudos to that.
I, I think Amazon's done a great job with that. Seems like they're in a unique position bonding where they could kind of push those things down their ecosystem partner sellers. Yeah.
Yeah, that's fair. Maybe some incentives to help other people reduce their packaging that uses plastic. And I always think, well, what is the consumer reaction when they, um, open the box?
Like, if you get a new iPhone, is that something that consumer appreciates that they see the I Do. Yeah. But you know, me, I'm, I'm a coastal elite.
When you wind, um, Even an I care, But I, Yeah, I, I, I would say, uh, you know, to Mitch's point, I would love to see Amazon push that further down, because a lot of the things you buy on Amazon, in fact, isn't it, more than 50% of the things you're buying on Amazon now are being fulfilled by others. Um, you know, and a lot of that stuff comes still in terrible plastic, plastic, plastic, you know, um, things are being drop shipped from China. Um, you know, all sorts of, of, of, of really negative environmental impli implications from, from your shopping experience.
And it is so jarring because when you order something in that Amazon frustration free packaging that comes in that nice little cardboard container, and it's easy to open and it's small and lightweight and, you know, it is like night and day, I would love to see them push more. Uh, and I think they will push more to their suppliers. Uh, on the Apple side, it is really obvious.
Uh, I just bought one of the new Mac Minis, um, you know, that's, uh, you know, it's a hundred percent made of recycled materials, uh, the cases and, and, uh, the packaging was all paper. There's no more plastic in there at all. They've even removed the stickers from the package.
Um, you know, and, and, and as a consumer, um, you know, the, uh, the unboxing experience from Apple has always been, um, you know, just bar none at the best. And it still is, you know, I mean, they've moved from, um, plastic to, to paper to, to, to cardboard, but their packaging is still pretty, uh, pretty dense, pretty solid. Uh, I think Apple could maybe, um, even move away from those trademark, um, really expensive, fully printed packaging.
But, you know, we'll see if they do. But at least they've gotten rid of the plastic. I always felt terrible.
You know, you tear open a new piece of electronics, um, and it's just a, just a load of plastic. Another company I'll call out, by the way, Seagate, I buy a lot of storage, you know, storage nerd. Uh, they used to have everything shipped, um, you know, wrapped in plastic and blister packs of plastic, plastic here, plastic there.
Uh, they've moved to a hundred percent cardboard packaging as well, which is really nice to see. Um, you know, you open it up, it's, it's no worse. It's just, you know, not something that's gonna be sticking around in the environment forever.
Just taking the shrimp broth. Shrimp. Sorry, shrink wrap.
I'm in, I'm in Florida. Shrimp. You go with shrimp.
Yes. Might have little breakfast, just dinner lap. No, the, uh, shrimp wrap.
Wrap. You mentioned seaweed, so maybe they got shrimp wrap. Shrimp Wrap.
Shrimp wrap. There you go. The next shrimp innovation shrimp.
That would be a moving to, you know, plastic, but then also using paper kind of sealed to seal the packaging. So you don't need shrink wrap on that extra plastic layer. Just, it can be small, incremental changes.
Doesn't have to be the whole thing. Whole scale. Look, I think overall we're making progress.
I should mention, look, this, if you didn't catch Bonnie's video that preceded this, it's available on Techstrong TV as well as on Echo Tech insights. Bonnie's portal. Mm-hmm.
Site where she has all of her, I don't know. It's dozens and dozens of videos. Hundreds videos, other now Yeah.
On Echo Tech. So this is the kind of stuff that appeals to you. Please go check it out, Bonnie, thank you for that one.
That was great. Great piece. Let's take a break.
We're gonna come back for our third, uh, our third segment today. And, uh, you know, do we have a chip war nation state chip war on our heads, or coming down the pike? You're watching Textron Gang Modernize your business to fuel innovation and elevate customer experiences with the builder community.
Hub AWS and its partner network provide essential tools for transforming applications and infrastructure to fully leverage the cloud. Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably. Visit the builder community hub to learn more.
Hey everyone, we're back. Alright, for our third segment today, it's just a heavy day of segments. Uh, you know, uh, president Biden on the way out the door is, is ready.
And yet another executive order. This one detailing or around, uh, AI chips, GPUs and whatever may come next. And, uh, you know, prohibiting China's, uh, getting their hands on this technology or trying to prohibit China from getting their hands on this technology.
Uh, there's a lot we've discussed over the months and weeks here, whether it's from Taiwan to China or, or what have you. And anyway, Nvidia obvious, for obvious reasons is, is pushing back. And, uh, they want a different sort of plan.
They'd like to see something else. And, you know, quite frankly, there's been reports China is trying to circumvent these, this whole area by buying GPUs through third party countries and bringing them in the back door to the tune of like billions of dollars. Uh, um, incoming administration promises to be tough on China.
Will they extend this? Uphold it, rescind it. Steven, what?
You, you follow this area? What do you think? Well, what precipitated this is a, uh, blog post, uh, by Nvidia, um, where they called, uh, I mean, it's pretty aggressive.
They called the Biden administration rule misguided. Um, and they're trying to preempt this rule by basically saying, Hey, Trump is gonna be president. New administration, new policies, you shouldn't enact policies.
Man, I find this whole thing completely disingenuous. Number one, uh, Biden's still president for another week. And as last thing I heard, until you're the president, you don't get to make foreign policy and, uh, economic policy decisions.
Um, number two, uh, you know, to have Nvidia say that, uh, the Trump administration is gonna have a radically different policy on exports to China, seems like maybe they weren't in the US during the first Trump administration, because Trump was very aggressive on China. And, um, o obviously he didn't stop, uh, ship exporting AI chips to China in 2016, because that really wasn't a thing. But he did, uh, try to block other exports to China.
And so to have them think that, that the policy under, uh, new Trump administration is gonna be radically different is just, just doesn't, uh, ring true to me. But the big thing, as I've said for a long time, I am not a fan of these export restrictions because frankly, they are likely to basically bite in the wrong direction. What's happened is by trying to restrict exports of specific chips, number one, China retaliates by, um, you know, and, and in pretty soon you get yourself into a trade war that's bad for people in both countries and, and around the world.
But number two, what's happened for the US tech industry is that Chinese firms have risen to the occasion and produced their own alternative chips. Um, by all accounts, China's producing, uh, AI processing GPUs at record pace that are actually very, very good. Uh, China maybe has jumped into the lead on high bandwidth memory, and it's very likely that, um, this trade war will actually solidify China's growing, um, importance in the international tech sector.
Uh, we just also got news, uh, yesterday that, uh, the Chinese trade surplus was a record high over $900 billion trade surplus, um, coming out of China. So it, it doesn't seem like these things are working. It doesn't seem like they're having the intended effect.
They're likely to have the exact opposite effect. And frankly, to think that somehow the Trump administration is gonna be any different from Biden on trade policy toward China, I think it is just utterly ridiculous. I think we're in for more tariffs, more trade fights, and frankly, uh, more, uh, success for Chinese, uh, technology.
I Was thinking the same thing. You equate this to a tariff, right? Another form of restricting commerce and, uh, that very much fits the Trump approach.
And is it a negotiating weapon? Is it something that weapon, is this something that, uh, he actually implements? We'll see, but, um, I, I don't, I don't see Trump rushing to save China anytime soon.
What does Elon say? Yeah, hold on. Yeah, I totally agree.
Yeah. Trump's uh, extreme tariff plans is definitely not going to reverse the situation anytime. So, and absolutely it is also not going to have the kind of crushing effect on the Chinese industry as one would expect.
Matter of fact, I think he, Trump can have Biden to thank for this Biden's kind of taken the arrow by implementing this before he gets in office and he can leave it alone and let it, let it go through and not have to pick re Biden did that when he came into office. He didn't rescind many of the tariffs on Chinese products. Exactly.
Exactly. Um, Steven, you mentioned that $900 billion surplus, that wasn't just with us. So that was worldwide.
China's import export. Mm. And I wonder how much of that is them buying Russian energy at below market prices to, so that put and Curry's favor with, with the Chinese Communist Party, and then China turning around and selling Russia needed goods and services for their war machine, uh, at, you know, premium pricing as well.
So there, there's a lot of that. I, I think that goes into those numbers. I'd be interested to see in the US China market, what, what the, the balance was if it's gone up, down, or stayed about the same.
Yeah, I, I don't have the numbers on that, but there were some more details in this. And it's not just energy that, uh, drove this trade surplus. In fact, um, if you look at the, uh, the growth of trade, um, it's been very, very steady since, uh, you know, 2018 essentially, um, in the first, uh, during the, the first Trump administration, the Chinese trade deficit fell, um, and then it rose and rose and rose and has been rising, um, throughout the pandemic and ever since.
So, um, another aspect of this, like we mentioned, this is global. This is not just China, us of course, our audience is global as well. Um, you know, many countries around the world don't share the American administration's viewpoints on tariffs and restrictions on access to technology.
And in fact, many of the, uh, countries around the world are very, very happy to import Chinese goods because, uh, they're increasing in quality. And in many cases, like with solar panels and electric cars, China is in the lead. Um, in fact, uh, the New York Times story about this trade deficit specifically focused on the export of Chinese electric cars around the world, which have been phenomenally successful.
Anyone outside the US is nodding right now because they're buying Chinese electric cars by the handful. Whereas, uh, anybody inside the US is like, what, what is a Chinese electric car? I never saw one because we don't have 'em here, but around the world, they're incredibly successful.
But let me, let me just wrap myself in the flag here a second. If these cars are incredibly successful and being sold at below market or below cost and everything else, because subsidized, I dunno that Anybody's saying you're being told Low cost subsidized, well, but they're being, but the, these companies are being subsidized by the Communist party there, right? I mean, that, that's the, the key to it is that that's been the history.
That's that's the, that's their game plan. That's their model, right? They, they'll subsidize it until they grab enough market share and then, you know, try to squeeze the profits out of it.
So if, now, if you wanna say, I'm not buying, or I'm not gonna allow Chinese electric vehicles in here because it's strategic that the US maintain their own electric vehicle market, that's one thing. I you could agree with this. I also Wouldn't bet on the Trump administration taking that, that tactic.
Mm-hmm. Yeah. But if, if they're being, if the cars are being done with forced labor, child labor or subsidized by the Chinese Communist party, I, I, I can understand why we would wanna do that.
That's all I'm saying. There's a bit of irony here too. Um, you know, and Nvidia stock price isn't hurting these days, as we all know.
No. Well, well, that's what you ask yourself too. Why is Nvidia pushing back here?
Do they just, they don't want to give up that China market? They sure don't. Sure they don't.
But the irony I wanted to point out was this coming on the hills of Jensen Wong saying, uh, the quantum market, their chips 10 to 15 years away, and quantum quantum stocks drop whatever it was. Yeah. With the drop right now he hit the kibosh on quantum.
So, you know, he, he has his own influence on markets too, don't we? It's Also interesting that Jensen is one of the only tech execs who hasn't publicly given to Trump's uh, inauguration. Really?
True. Yeah, That's true. I heard they, they gave out, they ran out of prizes to give to the people who, uh, Steven, you got any of those tech field day coins left?
Maybe we could send those to the people who give a million bucks. Yeah. If, if somebody donates a million dollars to me million, I will make you a special tech field Bitcoin.
Yeah. Funny stuff. Anyway, hey guys, I think that's gonna call a wrap on today's TechOne gag.
Just heads up again, head over to predict 2025. If you're interested in what's gonna happen this year, that's the place to go to. Hey Dick and my top 10 DevOps Mitchell's there with his top 10 development Yes.
Session. Steven has a session. Daniel Newman has a session.
We've got people from, uh, Microsoft, some from some of the other hyperscalers that we're now allowed to mention. Um, just a lot of good people talking. Good stuff there.
Predict 2025, we'll be back tomorrow with a fresh gang. We've also got a ton of great tech, strong TV on here for you today, so check that out. Lots going on at Techron as always.
But for now, this is Alan Shimel on behalf of our gang today. Thank you very much. Have a great day everyone.
We're out. Hey everyone, I'm Alan Shimel. That's Luca Galante and you are watching the Platform Engineering Show.
Hey, Luca, happy New Year. It's great to see you, my friend. How are you?
You too. I'm good. How are you doing?
Happy New Year. Happy year everybody. Yeah.
Happy New Year to everyone. So, Luca, where let's play. Where's Luca?
Where in the world are you today, man? East coast of Sri Lanka, the east coast of Sri Lanka. That's great.
And it's nice and warm there. You're on the beach. Yeah, I freezing, I apparently tour than in Florida, right?
Yeah. Well, winter, winter came to Florida. Right.
But we got this around this time of year, we'll get like three, four days. I was telling you where it, sometimes it'll go down even into the high thirties, low forties, fa night. And then the, the, uh, the iguanas that are, they're not native, but they're invasive here.
They, they get frozen up in the palm trees and they go what they call orpi, like, you know, they just shut down and then they fall outta the trees. And some of these agus are like four feet tall. I mean, they're big, they're big reptiles, so you don't want 'em falling on your head.
You'll get hurt. But, um, this is so fascinating. It's crazy to me.
It's crazy. But, but, but do they recover or are they dead? Uh, it depends how long and how cold they are.
How long, because, you know, with Gus are usually like that nice green color, and then when they're in reading colors, they get red and orange. When they get topi like that, they turn gray. It's like they really Yeah.
It's a good dark. They look like off. Yeah.
Um, crazy. But yeah, we'll see. I mean, no, they're, they're kind of like a nuisance animal here, so people aren't terribly upset that some iguanas die.
Uh, they don't belong here and they just, they're a mess. They're a mess. Right.
Anyway, enough about iguanas. You're in Sri Lanka. There's a lot going on in the world of platform engineering, though.
We got a great topic to cover today. But before we do, I wanted to just go over with you a few things. First of all, we're making plans here to head over to London for Cube ka.
I think it's April 1st to the fourth is the actual cube con. Um, but I know the community has, has some real big plans going on. You wanna share a little?
Yeah, it's gonna be, it's gonna be a big one. Um, cube Con, right? In London, they're expecting 12,000 people.
And so we do our sort of like unofficial cube con opening party, which is Coha Cube. We've been doing it now for like two or three years. It grows every time, expecting a lot of people.
Probably like 4,000 plus signups. There's probably gonna be like 500 people, 600 people at the location. We're pretty crazy.
And, and you know, the whole thing, us cubes, like we started it when I think we were at CubeCon Valencia and it was best Oh, oh, I love that. We were kind of going from like, which was great 'cause it's like Vale and so on, but we were basically going from like one party to the next. We like, man, all these parties are the same.
Um, and obviously, you know, we have like a Berlin background, uh, techno background. And so we were kind of like, wouldn't it be funny to do the sort of like, uh, the dark room of DevOps? Um, and for those that catch the reference.
Um, and, and, and so it started like as, as a joke, but we did it. Um, and it's really funny 'cause it's always, there's a bit of, bit of a tension with the CNCF guidelines that basically don't allow you to stay in the dark room of DevOps. Um, but um, yeah, so we started and, and, and now it grew to basically really become the unofficial opening party.
You know, we have like drag queen shows and it's a whole thing. So, so that's gonna be really fun. Really.
Oh, very cool. Um, yeah, yeah, yeah. Looking forward to that one.
Kind of like Key West down here. We that's, I dunno if you've ever been down to Key West, but they lot of that. No, but I heard, yeah.
Um, yeah, yeah, it is. Yeah. Well, there are other places that are more, but anyway, um, I digress.
Let, where can people get more information about House Cube? com. Um, and you could sign up.
It's free. We have, uh, amazing food, amazing drinks, amazing drag queens, and just kind of was fun Post party. We're gonna do that.
That's fun. That sounds great. And then the other, you know, big thing on the horizon, and it's not too early to get this out there, is, this is the third or fourth platform Khan.
This is coming up in June 4th Con, so we started 22. Yeah, right there. Um, we had like, I think like 6,000 people or so joining virtually.
Um, then we had Popcorn Con 23, we had like 20,000 at 24 last year we had like 35,000 or something, and then expecting like over 40,000, um, this year. But the important thing this year is that we're really doubling down on the in-person components. So we're gonna have two live days.
One in London, one in New York, both around like four or 500 people. Uh, you know, we have great speakers, Nikki Wat, Gregor Hope, Kelsey Hightower speaking, uh, this thing's live. So really excited about that.
It's gonna be last week of June. So London on the 25th of June. And, uh, New York on the 26th of June.
Uh, so it's gonna be fun to like hop between one city and the next. Um, but the, I think the events are gonna be great. We're gonna have parties.
We, we have like a lot of great like, speakers live trainings, a lot of new formats that we're rolling out for this. com. Um, and you can choose your, uh, choose your own adventure, uh, and join us either virtually or in person London and New York.
I think Techstrong TV will be in New York. I'd love to come home to New York. Um, and we'll be broadcasting live from there as well.
Yes. So it should be a fun, fun, fun thing. com.
Yeah. Right. Fantastic.
Uh, speakers are, uh, all speakers have been assigned. What about sponsorships available? Yeah, sponsorships still available.
Um, almost sold out of New York. Um, that, that's gone pretty quickly. Um, and, and you know, we're closed with London, but there's still, there's, there's a lot of like, you know, um, so's like, also virtual sponsorships are still open.
Sure. Um, so anyway, sponsor sponsorship's still open. Um, and there's a lot of like, interesting formats that, as I said, we rolled out the trainings, but also, you know, we're gonna do live interviews with you in New York, for example.
So lots of new interesting things that I think can be very fun as well to do with, uh, with vendors and other sponsors. Very cool. Very cool.
Alright, Luca, we gotta talk about what we're talking about. You know, this is, uh, our third episode. Yep.
This is our third episode. This'll probably be the last one where it's just you and I talk in like this. Well, we gotta bring in some fresh blood, some expertise, and, you know, we'll announce, uh, check marks is gonna sponsor our show.
So many thanks to them for that. We're looking at other sponsors if, if anyone out there might be interested. Um, but for today, Luca, we're gonna talk about platform as a product.
And look in today's world, right, there's platform as a product because everything is as a service, right? So here we got PAAP, and I'm sure the next thing will be PAAS, but you know, what does it actually mean when we talk about platform as a product? And, you know, it's a, it's a key part of this platform engineering kind of mindset.
But, you know, you're the expert. Why don't you define it? Yeah, absolutely.
And, and I actually think is a good place to start from the PAAS that you mentioned, right? So like the, the platform as a service, right? This is just as kind of like, uh, one of sort of the, the main trends.
If you look back like 15, 20 years ago and like Heroku, all those guys, Heroku star. Yeah. And yeah, and, and, and, and it was just said you of like, Hey, like don't worry about anything, right?
Like, we, we build this like platform layer for you. It's, you know, it's like turnkey, plug and play, let's go. Um, and, and that didn't really scale to the enterprise, right?
Because like everybody realized, hey, you actually need, um, you know, some, some customized platform layer, uh, for your, for your own enterprise engineering organization. And, and that's kind of what platform engineering, sort of like, you know, where we're sort of like platform, platform as a service or pass ends and, and sort of like platform engineering starts is really this idea of like, Hey, you're building this internal product or internal consumption, right? Like your internal customers are the, um, the, your, your application developers.
Uh, and you do that as a product, right? And that's like a very, um, it's probably, in my opinion, the key concept. Um, the key foundational concept of platform engineering and also the key differentiator, um, you know, of platform engineers vis-a-vis, let's say like a doubts engineer or, you know, an SRE, um, that, that normally we'd approach the infrastructure project as a kind of like one and done, you know, six months project, something of that kind.
Whereas a platform engineer, at least like a, like a good one, um, a approach is building an internal developer platform, or IDP, which is the end product of APAC engineer initiative as a product, right? So a product that has a life cycle, not that it's, it's not like a one and done, you know, six months thing, but it's actually, it's being rolled out as a mini rev viable platform initially, um, for the first few months and then iterate on and then eventually grows. Um, it gets adopted widely across the engineer organization.
Um, right? And, and it keeps being worked on as a product. Uh, and I think it's, it's a, it's a super interesting concept because the moment you look at your internal developer platform as a product, you immediately unlock, you know, 20, 30 years of product management best practices and experience that that we have in the industry that can be applied to build, uh, your internal developer platform as a product, right?
And, and here, here's the thing, whenever you talk about something as a product, the next logical conclusion is who's the customer, right? Right. And, and, and traditionally that was in it, right?
In the IT department going back, I'm going back now, you know, 25, 30 years. The IT department, the, the customer was the internal business, right? It wasn't sort of forward external facing, it was internal Right.
Facing. Right, right. And, and your customer was the, was the sales guy, the business guy, the marketing person, the HR department, you know, all, all of the above IT service them.
It, you know, they, they were the customer of the IT department. So this, I mean, this is not new in terms of a concept of of of that internal customer that gets served, you know, uh, in this case with, with the platform. The other thing I'll tell you is, look, you know, when, when cloud first came out, a lot of people were very definitive about saying, well, this is infrastructure as a service, IAS, right?
And we're gonna have platform as a service, right? And, and haruku was probably the biggest success coming out of that. But really to a lot of people that meant, well, infrastructure service ended at kind of the hypervisor.
They took care of everything hypervisor and below, and you built on top of the hypervisor os and everything else in IT platform as a service initially to a lot of people was, well, no, everything up through the os. And then you just build your app on top of the os. And I'll tell you my 2 cents on it, if it wasn't for platform as a service not being sort of a complete, uh, concept, you never would've had cloud native.
I think what we see as cloud native today with the containers and, and cobe and mesh and everything, you know, that old cloud native stack is a better platform as a service or as a result of the initial like, Heroku style platform as a service just not being complete enough, right? It wasn't what we need. And then, so now you got this cloud native stack, and now you have this whole platform engineering kinda movement, right?
Which is borrowing from a lot of what, what's gone on here. And that's the modern platform as a product platform, as a service that I think people were really thinking about back when, but the initial like Haruku versions were, I don't wanna say flawed, but incomplete. They were immature, right?
Yeah. And, and so I think they, they mm-hmm. There were like a child of, no, that's my 2 cents of the, of its time, right?
Of like, also like I think stacks that were like a lot simpler, right? Infrastructure mm-hmm. That were a lot simpler.
And, and, but then to your point, right, as cloud native exploded as this like complexity really, um, really exploded as well, then you had to have like a completely different approach. So it's like the idea is, hey, I still wanna provide a, a path like experience to my developers, right? Um, and, and, and, and I think like your, your, uh, point is super interesting, right?
Like, it's also not only the complexity of the infrastructure exploded, but also the, uh, size of the engineering organization exploded to the point where now you have a part of the engineering organization, the serving the other part of the engineering organization as, as its internal customers and no longer just like the sales, marketing, hr, whatever, right? The other functions. And so, and there is also like a, there's also like a, like a mind mindset shift that that needs to happen a lot of times where it's like, well, actually the internal customers is the developer itself, right?
Um, which is something that a lot of people are not used to because they think, well, developers kind of build stuff for themselves. Well, but the, the problem is like once you have, you know, 10,000 developers, then you actually need somebody that like, specifically builds stuff for them, right? So, um, but yeah, so the idea is really like, Hey, I want to build a past like, experience for developers, but on top of, you know, a complex and changing and, and, you know, cloud native or hybrid tool chain.
Um, and so therefore, I, you know, I, I, I need to take, you know, the, the vision is the same. I take the tool set, um, you know, in the toolbox of, you know, I borrow it from, from, from kind of like all this other like adjacent disciplines. Um, and then really like, I focus with this like, product mindset on, on building this like, um, so like platform layer developer, um, DevX, uh, layer on top of this increasingly complex, uh, stack, right?
Absolutely. Hey, you mentioned DevX. I just wanna give a quick shout out.
We're gonna do our first live round table of the platform engineering show, um, I think early in February. And it's on DevX. So if DevX is something you guys are interested and your folks are interested in, uh, stay tuned.
We've got a live one where you can take part and ask questions, and we're gonna dive into that. Now, Luca, the, the platform is a product idea. You know, it's been percolating now for a couple of years, and we're starting to see, I don't know if I want to call it best practices yet, or, you know, evolving best practices.
I don't know if it's written in stone everything just yet, but we're starting to certainly see where, hey, this works. This is not such a good idea. This is a better way of doing that.
You know, we're evolving best practices. Can you talk a little bit about what some of these are and, and where people can kind of, you know, stay in the know on that? Yeah, absolutely.
I think like, um, you know, and as I mentioned, like, I think what's interesting is the moment you treat your pop your internal product, your internal platform as a product, you unlock all this like best practice. Like, so it's not like you need to invent anything radically new. It's like, hey, there is this minimum viable product MVP concept, it's just being rebranded to medium level platform, which is the same exact letters, and the concept is the same.
It's like, hey, start small, irate quickly, and so on. Um, I'll cover, I'll, I'll talk about MVP in a second. The, but, but I think like before that even, um, like if we look, I think chronologically, and I've seen the, the space sort of like mature in the last couple of years, you know, initially it was kind of like, okay, like what is platform engineering?
Is this helpful for me now? It's like a lot of people are like really bought in to the concept. Like it's been, you know, compiling like crazy.
And we spoke about the, you know, the overall like, you know, numbers about platform engineering as a trend broadly in the other episodes. Um, but you know, with that, a lot of people are coming in, they're like, okay, you know, I'm bought in. I heard this is cool.
Where do I start? Right? Like, what does this thing actually look like and how do I make sense of this?
You know? Yes. We have like a, like a crazy, like cloud native, and so landscape, you, you can just see the CCF F landscape is insane.
Like nobody can actually really understand it, but, um, but even the al engineering, it makes a good picture. It makes very a good picture. Exactly.
Um, and, and, but even the possible engineering landscape at this point has been developing so much that, you know, it's far from that level of complexity. But you know, you already have, like, if you're a newcomer in, and it's like, okay, like how do I, you know, how do I actually piece all this, this for, you know, pieces of the puzzle together for a platform that actually works for me that makes sense for my engineering organization, right? And so that's where I think the first sort of like standard that's been really, really helpful in a game changer thing in the, in the community and, and broadly in the platform engineering market has been this, this reference architectures for interior developer platforms, right?
Um, and, and some of the first ones were, um, open source, uh, by McKinsey actually. Um, and then, you know, kind of like, now they're like really widely adopted. Um, I have one stat for you on that, which is Platform Con.
Um, they were, so the first, the first, uh, reference architecture was uh, uh, was kind of like presented in the talk at, at Pop Con 23. Um, and so there was only one at Pop Con 24 last year. There were already like 20, 30% of the talks that were using, um, this as a blueprint to kind of like talk through, uh, the platform that practitioners built or whatever, right?
So very, very interesting to see like how quickly people adopted this. And it's for a very good reason. And it's just like, it gives like a really good guidance as to like, okay, how do we see, how do you think about the different pieces and how to fit together?
org, I think slash tooling or slash platform tooling is, um, you can see the sort of the tooling landscape there. And that also follows the same structure, um, as the, as the reference architecture. So that was kind like a first step that was really helpful.
But then sort of like, what I've noticed is that people were, um, kind of like looking at this and like, okay, great. That's, that's my target setup. Like, that's how I wanna build my platform.
Um, but then they were trying to do everything, you know, at once. Um, like, you know, the, the, the Korean movie, like everything everywhere, all at once. It's kind of like, it's kind of like, like that, right?
Like, they were trying to like, okay, like this is great. You know, they get super excited, you know, I get buy in some executives, let's go, you know, build everything, right? And the problem with that is that, you know, you very, very easily lose momentum, right?
And this is, I think, in my opinion, is the number one cause of death apart from engineering initiatives, uh, to be a bit morbid, but it's, um, it's really, it's really like that, right? Like it's, it's people that get really excited that have this like brand designs, um, for, for what the platform is gonna look like. And the problem is that the platform engineer really is a huge, you know, org transformation, right?
And so, uh, and so that means it touches all these different stakeholders. Application developers is executives, architects, security teams, infrastructure and operations teams. And so you need to basically get all these people on board with you, you know, sell them effectively, eternally, this idea of the platform.
And it's different components that you have like, so beautifully designed in your head. Um, and, and so the problem is like, it's very easy to lose momentum there, right? Because you need, you know, by the time you, you know, you spoke to person A, B, C by the time you, you spoke to person Z, it's been six months, person a completely forgot about you.
And, you know, you kind of get stuck in this person, right? And, and there the trick is really to take this minimum viable product or minimum viable platform approach of saying, Hey, start small. Um, focus on like a really, like a subset of, um, uh, not only the problem that you're solving for, for d different stakeholders, but actually a, a, a subset of the stakeholders, right?
So just focus on, on maybe like application developers and security teams or, you know, infrastructure, infrastructure and operations team and executives. Really, you don't have to please everybody immediately just focus on like, what's the low hanging fruit here? And then if you think about that reference architecture that maybe we can link in the, in the show notes or like throw up a pitch at some point, um, we can, you know, you can, you can, you can think of like, well, let's, let's actually focus on a subset of events, right?
You don't need, you know, your MVP to have a full, um, you know, to be fully security compliant, uh, or, you know, have, uh, you know, the, the latest observability built in already. 'cause you, you're not going to production right away with this thing, right? You need to first show the value to, for example, developers and say, Hey, look, you know, Jimmy right now is spending, um, you know, like, um, uh, is is waiting like two weeks every time, uh, he wants, he needs a database, right?
Um, and, um, you know, Ann is providing that, um, um, but you know, now she's like fielding this, like all this like ticket ops request for like 40% of her time. And that sucks, right? And so what you want in the first MVP is, is to actually show, okay, well I, you know, I, I proved, uh, you know, for example, I reduced the, the, the time that Jimmy needs out for database from like weeks to minutes.
And now Amy only needs to spend like 10 minutes, 10, you know, 10% of her time fielding ticket request, not like 40, 50%, right? Like, and you know, and, and you can, you can show that within weeks, right? That's really the powerful thing I've seen, um, like very large enterprises move incredibly fast following this MVP framework, um, and within weeks show some level of success internally to the, the stakeholders they selected.
And then from there it's like, okay, great. Are we all happy? Yes.
Okay, let's go to the next iteration, right? And then of course, you should have, like, you should design the end design with, you know, security in mind, for example. But it doesn't mean you need to implement all the latest governance and security workflows from the get go.
'cause that's gonna slow you down and not gonna get you to actually show value. So, um, I think reference architectures and MVP framework have been, um, very, um, very helpful standards and very helpful best practices that, as I said, you know, we've been borrowing from existing, existing disciplines already, um, and just like slightly tweaked, uh, to, uh, to really help platform teams deliver on their, on their initiatives. Excellent.
Excellent. I mean, Luca, if I, if I had a boiler, a bad word to use, 'cause I'm gonna use that word. If I had to like, just really give people in one line here, right?
You, you, you don't wanna boil the ocean with platform as a product. You want. I you want to do it step by step, bit by bit.
Here's my question for you though. Do you need a master plan to begin with saying, okay, here's I, here's step one through six. It may take me three months to do step one, four months to do step two, four months later I'll do step three, but eventually I'll get to step all the way through to step six.
Or do you just say, well, let's start with step one and then I'll decide what even step two is. 'cause I don't know if I want to make that, what, what I'm labeling now is step three may wind up being step two. Um, right.
So I'm not, I'm not locking into any of that. I'm just locking into step one right now. Totally.
I think it, I think it, um, I think it's a mix of both, to be honest. org actually has like different tracks. Like you have an executive track or business track, you have like a technical track, which is basically, you know, how you build everything, how you get the first like developer adoption, you have a security track, audio, make the security team happy, right?
And I think like different tracks have different timelines and you need to, right? So like, I think for security and business, for example, it is helpful to have a little bit of, you know, like a look into the future, right? Um, and like, how do you attach, because you know, for example, like your business, your business stakeholders, like your execs, like, you know, usually sink in quarters or even like fiscal years, right?
So like, how do you attach, you know, your powerful engineer initiative to whatever their goal is, for example, for, uh, you know, for the quarter, for the year, um, in some cases multi-year plans, right? Um, on the developer adoption though, on the other hand, like, it's really what you were saying, um, it, it, it doesn't make sense. Just, just get started.
Just get started, figure out, you know, what works, what doesn't, and then I can from there, right? So, um, I think there's a combination, and this is also I think where it's helpful to think of your platform as a product. You know, you know, we've built product, um, uh, products and, you know, the product is not just about building a product, it's also going to market with that product, right?
So, um, and so that's where you have, you know, I think you have basically your product engineering teams atating very quickly on building a product, especially at the beginning, right? And then as your platform matures, you can have like longer plans and like longer iteration cycles and so on. But at the beginning, you want to be very nimble, right?
Um, um, and the same thing kind of like goes for your go to market at the beginning, you really need to figure out, okay, you know, which executive is gonna support my initiative and so on. But then like over time as it matures, you know, really like attach it to like, you know, very specific budgets or combination of budgets and so on, right? Um, but it, I think it's, it's helpful to, to to, to not only think of like platform as a product, as something that's like purely technical in terms of like, how do I drive developer adoption and how do I, um, you know, you know, irate reviews from a product perspective, but really broadly, like if you consider it as a product, it means like it actually needs like its own go to market, uh, its own internal marketing and internal sales effectively.
Um, and actually you can see this, I was, I was talking, uh, a while back to our Ericsson, who's the guy that that built the, the, the turn development platform is Salesforce five years plus ago. And you know, it's very interesting because, because Salesforce is so big, actually at the time, they had multiple platform initiatives sort of like bubbling up and competing with one another. And so there you have even, and obviously like in, in most organizations you wouldn't have that, right?
Um, but Salesforce, because they're so big, um, but there's some cases of like very large engineering orgs that have, um, similar situations. Um, and, and in that case, really you're competing, right? And you're competing on the product front, but you're also competing on like distribution on the platform.
Yeah. Yeah. But I mean, look, you see that in large enterprises that are built through m and a, right?
Where you, you have, you know, company A was doing this, company B had that initiative, company C, now they're all under one. You know, big company. com days, right?
We had 30 different acquisitions, and each one had their own, you know, not platform per se, but their own it, their own, they were all, they were all storing websites. They were all website hosts. So there was 30 different platforms to coast website side.
How do you pick one, or eventually you do want to get to one, but it took a really long time because you, you can't, you know, you're gonna wind up breaking some eggs, making that omelet. And, and, and, and so you, there's a, there's an art to that, right? That's, that's a whole thing in and of itself.
And, and, and how did you, how did you think about that? Like, how were you Well, we went bankrupt. Well, what we, I mean, we, I, well, because the do com's bubble, that's, yeah.
That made it easy. I left, but no, but seriously, what we did do is we, we brought in, we, we developed one engineering team across all 30 acquisitions, one engineering team. And they basically took from each of the acquisitions what was best about them, what was the strengths, and then also looked at the wider state of art, right?
In the industry. And, and, and we did, we, we actually built a whole new platform that we migrated these two. Some, some were easy migrations, some were a lot harder migrations.
But we built a state of the art. 'cause back then, look, we, we had some companies that were using what I call baker racks, like that you would keep bread on, and they would keep white label servers on there. The hard drives are in the server.
The servers running Apache, and they got a thousand websites on there, right? Then we had other ones that were running like one U web servers to network attached storage, right? A very different kind of architecture.
We had other ones that, you know, had, would load balancers and st you know, there was, there was a variety of, of, of architecture here. And, and we settled on one and it took, it took the better part of a year and a half, two years to really migrate into the standard. The company was called inter reliant into the standard inter reliant architecture, which by the way back then was like IBM Domino server or something like that.
And, you know, it was, it was big enterprise level stuff. We were hosting a lot of AppSec. This was before there was cloud, you know, multi-tenants and all that.
And we're hosting Oracle AppSec and Lotus Notes and, and Exchange and PeopleSoft and, you know, crazy stuff in addition to websites. So we needed, and that's actually how I got into security. Then we had Layer Security in Checkpoint at the time.
Was it, you know, checkpoint was the big firewall, right? So we had managed checkpoint firewalls in front of this stuff. It was, it was really cool.
'cause we were way before our time, way, way, way before our time, right? Um, but it was, it wasn't anything like, we didn't have at our fingertips what, you know, platform teams have today, right? We were inventing this stuff outta rock and chisels, you know, you didn't, you didn't have the tools we have today.
But it was interesting. It was interesting. That's so interesting.
That's so interesting. And actually it's something that, like, we are seeing a lot in the community as well. Like, we do this, uh, this trainings with large enterprises, um, where we kind of like help them either educating their teams or actually like putting together strategy for the rollouts and, you know, phase rollouts and so on.
And I was actually working with like, um, okay, I think it's public right now, but anyway, it's like a very large, maybe the largest, I think CPG merger ever. Um, and you know, it, it's kind of like you have these two teams and they, they sort of like, are gonna go in, right? It in, in gonna end up in the same setup.
And, and so like, one of them wants to figure out, okay, what's the right strategy for me going into this, right? Because I have like, something that's working right now, but obviously everything is gonna change. So like, how do I, how do I make sure that my platform evolves in a way that it ends up being the winning platform, right?
Uh, from an evolutionary perspective, it's the one actually surviving in the end. So, very interesting. These sort of like m and a conversations where you really see this like, yeah, like internal products competing with one another.
Yeah. You also see personalities competing with one another, right? And that, and that's, sometimes the personalities are harder than the technologies, right?
And, and, uh, that's a whole nother story. We could talk over beers one day about. Anyway, uh, Luca, this has been a fascinating discussion, man.
I loved it. Um, yeah, it is fun. org, we've got reference architectures, we've got tools and people and documents out there to help people as we go on, as they set, you know, set sail on this journey of, of, you know, adopting platform as a product.
Um, wow. What a great show this was. Let, let's can't wait for the next one.
Next one. We'll have some people joining us, so it'll be more of a active discussion, but we hope you enjoyed this. Luca, how long are you in Sri Lanka?
Uh, three more weeks. Yes. Um, alright, so maybe for the next show, you'll still be there?
Um, no, no, no. The next show is in February, so we're gonna Oh, okay. Yeah, because these are almost mid-January.
So where, where do you think in the world you might be by then in Japan? Maybe? Um, you know what, there's a cube con in Japan in June.
I was really had my eyes on, but we'll see. Yeah, it's a small one. It's only two days, but, uh, okay.
You going check it out, it, I might, I might, I'm looking for an excuse to go to Japan, so, alright. Yeah, yeah, yeah, yeah, yeah. We'll see how that goes.
I'll let you know. Yeah. Anyway, though, until then, enjoy Sri Laka.
We hope you've enjoyed our, the platform engineering show. It is our episode three. If you haven't caught the first two, you can, they're available on your favorite podcast platforms like Apple and Spotify and all of that.
Also on text Drunk tv. And, and they, uh, text Drunk TV is the website. They're also on the YouTube text, drunk tv, YouTube, and I think by the, well, hopefully by the next show our Textron tv OTT channel will be up.
So you'll be able to catch it on Apple TV and Roku and Amazon Fire, as well as mobile AppSec. But until then, is Alan Shimel Luca Galante. I hope you've enjoyed the show.
Take care everyone. Thank you Alan. Thank you everybody.
Hi everybody. Welcome. We're glad that you've joined us today for another episode of the latest greatest cloud transformation late great cloud transformation.
We're talking about really sort of the next generation of how we think about the cloud and the things that we're doing with it. We're talking about security today, about safeguarding innovation and, uh, strengthening that security. Well, we can jumping into app, uh, app security and lot of things here.
But, uh, before we get too far down the road, thank you for joining us for this video series. Uh, the, the last Great cloud transformation is sponsored by CloudFlare. We're glad to have them, uh, on board with, with us working on this, uh, helping input with some topics and things like that.
And obviously participating on, on our, uh, live editions, which we do on a monthly basis, as well as these recorded episodes. So thank you for being here with us. My name is Mitch Ashley, I'm VP and practice lead with futurum Group, analyst firm, uh, heading up the analyst area for DevOps, DevSecOps, application development, AppSec, et cetera.
So kind of right in, in vain with this, uh, my co-host Alan Shimel is, uh, unintendedly, uh, de detained or whatever the word is the phrase is. And, uh, so I'll be, I'm, I'm hosting both parts of the chair today. Uh, you know, it's a little bit of a coup, but he'll be back next time.
We'll see him on our next episode, I'm sure. So let's get to our conversation, to our topic. Um, let's first start by doing some introductions.
I know Chris has been with us on a few episodes here on some different topics. We've been on other, other webinars with me and talking a lot about application security and, and, uh, cloud Chris Blask, introduce yourself. Oh, I've been in for company my way through the security industry for 30 something years.
Uh, I inflicted an early firewall on the markets and they called Border Ware, uh, in the early nineties and ran Cisco's firewall business, the turn of the century. I've been following this inevitability curve and my new series on here on Textron, um, from one spot to another, from firewalls into, uh, sim and network management. From that, you know, the obvious next step is threat intelligence.
So I, uh, chaired an IAC for a while, and, uh, supply chain has been my focus the last five or six years, you know, so, you know, software, bill of materials, hardware, bill of materials. How do we connect all these things, which, and, and currently, so currently I'm, my main role is I'm vice president of Strategy for sebe, which is involved in yes BU space. And I've been, uh, co-chairing several, uh, cisa uh, working groups on SBO sharing.
So we're currently have a group looking at ISACs, um, as SBO distributors. How does that know in the middle start taking this information and propagating SBOs software bill materials? Absolutely.
Great. Thank you Chris. Um, Katherine, Katherine, welcome.
Glad to have you on, I think first time we had you on the show. Catherine Newcomb with CloudFlare. Please introduce yourself.
Yeah, great to be here. I'm excited to talk about application security. Um, my name's Catherine Newcomb.
I live in Denver right now. Um, I've been in cybersecurity for about five years at this point. Um, and I started in the network firewall space, um, in encryption.
And now I'm a product marketing manager for CloudFlare, um, for their application security business, uh, where I focus on their web application firewall product, um, our software supply chain product, as well as our encryption and certificate lifecycle management products. Very nice. And, and I do like to say full disclosure, Textron is a customer of CloudFlare.
We do use their services. Enjoyed very much. So thank you Catherine, and team for that.
Uh, last but not least, another newcomer to our show, Kurt Handle, who's with, uh, Teradata. Tell us about yourself, Kurt. Yep.
So I've been working in security probably eight or nine years at this point, uh, but in the software industry for close to 15 years now. Anywhere from development, uh, into business analysis, product management, even, uh, doing a little bit of red teaming myself. But, uh, I am currently the chief security architect at Teradata.
And so I've been focused on architecture mostly for the past six, seven, possibly eight years, and really kind of a generalist. So AppSec is where I spend the least amount of my time where we focus on the architecture, the requirements, threat modeling, um, especially compliance. We do a lot of the, the major compliance frameworks at Teradata.
So we've been pushing that recently. Um, and I'm based in the Pacific Northwest, up in the Seattle area, and happy to be here. Very nice.
All the weather and fires and it's cold and I'm just glad we all made it. Maybe it's 'cause we didn't have to travel anywhere, so, so I hang tight. I'm glad we're all here.
And you know, our, our thoughts go our, our hearts go out to the folks dealing with the fires and, and, uh, some weather down south and southeast, et cetera. So, um, let, let's kind of jump in this way. Um, it, it's a big topic when we talk about sort of the kind of current state of the cloud and where it's moving to.
Um, but I don't think it's too much news to everyone that application and app APIs, API first kind of design into applications, you know, it isn't just things that sit at the edge anymore. We think about also the security of the AppSec and the kind of, uh, software we're creating, the innovation that we're making, um, as maybe as part of the cloud. 'cause sometimes application lives within it, you know, like a, like a provider like CloudFlare or certainly at the edge or at the core as well.
Maybe Catherine, if you wanna start us out with, how do you, you're, you're, you're managing, doing product management in this space. How do you look at this, uh, sort of this problem or this space and define it? Um, so looking at application security, um, when we're talking about this at cloud, we're mostly talking about web application and API security.
So if you're an OSI person, layer seven model, um, and you know, when people are accessing these external facing web applications, they're doing it from a ton of different devices and in a ton of different ways. So they're accessing from things like mobile, uh, desktop, laptop, and they're accessing these AppSec that could be hosted anywhere. So on-prem, in public clouds, private clouds, hybrids.
Um, so as we're securing, we need to think about how can we secure, um, all of these users and the end servers as they're sort of accessing these web AppSec, right? So how do we make sure that, um, mobile traffic is protected, user data is protected, um, and sensitive data is not, you know, leaving an app. And then how do we make sure that a web app server itself is protected?
Um, so at a very high level, that's about what I think, that's what I think about when it comes to application security. Um, some new things we're thinking about in this space. Um, I talked about software supply chain.
This is increasingly becoming, um, an area of interest as people create more complex AppSec with more third parties in them. Of course, API first development has also meant we've had to adjust our thinking a little bit around application security as well. I, Kurt, how about you as a, as an architect, security architect.
May, maybe you don't get into the innards of applications per se, application security, but traffic over there. Obviously our networks are heavily API driven. Um, you know, when you think about the security architecture, where does this fit into your purview?
I think it, it fits in really everywhere, right? So we're, we're building these huge applications, sometimes small applications. We, we do all sorts of scale at Teradata.
And in my previous roles, I've, I've worked with pretty simple AppSec all the way to super complex microservices architectures. And so, like Catherine could have said, you have the mobile aspect, you have the server, there's application code literally everywhere, including on the person's device. And so how do you secure it as best you can, um, within reason, right?
Because if it's too secure, it doesn't work. If it's not secure enough, well, you end up in the Wall Street Journal and you're in trouble. Um, so we, from an architecture standpoint, we really try to focus on all different aspects of it, where the biggest threats lie, um, and then implement controls and use technologies to, to simplify the implementation and streamline it without making it overly complex.
And so it's, it's just becoming more difficult given that, um, the, the kind of classic perimeter is gone. Right? I'm sure you can relate to that, Chris.
Oh yeah. Well, it was easy back in the day, right now. You had to get on the internet and you needed a firewall.
Get a firewall, right? And I'm thinking as Kurt and Catherine, you your co remind me of these transitions we go through, like there was the mainframes before our time. But you know, I, I'm old enough to have seen the end of that where all of your capabilities are just to keep one computer running and run terminals and printers and things off that.
And then we get into, or where I came in, where we're starting to build networks fractally more complicated, just yeah, how do we do that with, when all of our resources were just keeping one computer running, we figured it out, you know, now we're here, we're talking about web APIs, Catherine, you know, you know, the data going in and out on with being stored 30 years ago, you couldn't have that conversation. Now we're saying, alright, what do we do in this case? And it's very complicated.
And I think in, and Catherine mentioned the supply chain, this is, I think we're filling in the dots. Security has been, is not, i i is not new, right? People have been saying you should know your inventory for a long, long time.
And we've gotten away with not knowing it. Now we're starting to fill it in, need to actually know where the software is, where the data is, and we're working through that. So it's exciting times, but it's not different in type than other transitional periods.
Certainly is an evolution, right. Of what we've gone through. And to think about, you know, from the bas and host days, early, early on, free firewall, um, well, Firewalls used to be a million dollars a year.
I think about I got involved, you know, at least as I tell the story, there were a hundred in the world and they typically were seven computers and a team of people. And my argument at the time was my mom needs one. Yeah.
You know, and so we're at this stage where what used to take so much time in here in the API, uh, world has to take less time a lot. It, it, so let me, let me throw out this hypothesis here. I think it may be pretty obvious, but maybe it isn't, is I think we live in a world, you know, now we we're thinking about things as zero trust, right?
Of of, you know, anything is susceptible, being compromised and could compromise other things. How do you protect all parts of the network applications, the infrastructure? But we're also living in a world where if so much is determined by what our applications do, not just connecting users to AppSec, but applications really utilizing the network, being part of the network.
It's a dynamic world, right? It, it isn't a good set of firewall rules and an application firewall and we're all good kind of set that up. And it isn't the old days of I've got a pizza box in, in my rack for every function that I need, and they're all doing their thing.
I'm good, right? We need it. It's a much more dynamic environment.
So I'm not saying we're reconfiguring our security all the time, but a security has to adapt to, you know, what's happening in the application. 'cause we may distribute it to a different part of the edge tomorrow with Kubernetes, or we may, you know, uh, acquire business and suddenly a network has looked much different than it did, you know, three weeks ago. I'm, I'm curious, Kurt, as a practitioner, you know, how do you think about that of, you know, you mentioned microservices and all the things that are being created, you know, in the groups that you're working with.
Um, we, we hate for security to be sort of the last thing to be thought of, but you wanna be in the conversation so you can prepare as well as react when you need to react. I think what you just said is, is really important. You wanna be in the conversation.
You don't wanna be doing this retroactively. And so when you're, when you try to tackle security retroactively, it is infinitely harder to accomplish than if you do it from the beginning. So I have, I do it both ways.
I have teams that we work with proactively where they bring us in at the very start and we're building the design with them shoulder to shoulder, drawing the picture in doing security by design or by default as we like to say now. Or we have legacy applications, which you're doing retroactively and they're quite a bit higher in terms of risk because they've been neglected for so long. Or we find out about something after the fact and it's like, well, how did this get out there?
Well, there's shadow IP in a lot of the world. And so it's, it's hard to, to really kind of put a, a recipe together that successfully achieves it. And then with the, the rapid pace of technology today and how the cloud has just kind of blown this wide open where people can deploy new applications in a hundred different ways faster than ever.
How do you keep up? So you have to implement tooling within reason without doing, without having too much sprawl. You have to have the right personnel partnering with these teams, uh, to ensure that you have coverage and that you, you're really architecting things from the start.
Um, and not just kind of using bandaids in bubble gumm per se, to, to secure your environment later on. Catherine, appreciate your thoughts on this because, you know, I remember the days of networks for speeds and feeds and points of presence and connecting A to B and kinda looked like this nice diagram that you stitched together and that was a network and you secured it, now it's overlay on top of overlay and it's changing and mm-hmm. You know, it's, it's multiple pieces that, uh, much more complex to, to secure.
How do you, how do you have this conversation with people? Yeah, definitely. So as you were sort of talking about this, you know, obviously there's a need for responsiveness and customizability and security, but I actually also wanna make the argument for unified policy management in application security.
This is something that I've seen actually, for example, um, we have some customers who have protected their SaaS AppSec, like what is traditionally more of a network firewall or zero trust type use case with the same policy they're using for their web applications. And by doing this, they're able to do things like make sure that zero day exploits aren't able to exploit their SaaS AppSec, you know, as well as their, um, web AppSec. And we see a lot of value out of these unified policy managements.
I was talking earlier about, you know, how we have all these AppSec hosted in different places. We see a lot of customers, for example, will host, um, you know, an app across multiple clouds for like a resiliency use case. If they're worried about outages, you'll, you'll certainly see that, um, for example.
But then how do you have to, you know, actually secure an app that's stored in multiple places? Do you write different policies for, for wherever those are stored? Um, do you write different policies for APIs versus, you know, traditional AppSec?
Um, so we see a lot of benefit out of like a unified policy for all of those disparate sort of endpoints and all of those disparate, um, locations that they're stored. Uh, for CloudFlare in particular, how this sort of works out is our WAF is like the backbone, the architectural backbone of the rest of our application, um, security portfolio. And this works out really well because you can do things like have a WAF and an API like positive security model protecting your APIs.
Um, so you could do things like detect zero days and volumetric attacks, which are, you know, APIs can also be susceptible to as well as, you know, do the things like Ebola and, and all those API specific attacks all within sort of one, um, control plane, which we find a lot of people get a lot of value out of because of this really, really disparate environment. Okay. Chris, I saw a lot of hand waving head nodding you about jumped outta your chair on this one.
And so I kind of have a feeling you might resonate with this. No, um, I, I gotta throw out there, I was gonna, uh, before Catherine got into the, the policy thing, ask swearing, it's been a my time, but yeah, the concept of an SBO om the software bill of material for the current release version of Adobe Acrobat as opposed to an SBO OM four as we're look talking about here, some ephemeral web app that one time for five seconds exists in the cloud. You know, think about that.
How do we, how do we deal with that? And I, and, but I think policy is, is the answer all hacking? All hacking is policy hacking.
I will figure out how you do things and I will figure out where the gaps are and I'll engineer that gap. And we live in a world right now where we generally have no idea what policy applies to any of us anywhere, with few exceptions. And in this topic, and because I'm used to the supply chain topic, imagine I needed to get the, the SBO M or custody information about a piece of software on his phone right now.
I could get it in between five days and six months today I need to get it in half a second. That means I need to read the policies between me, the person who bought the phone and the first type, the company I bought it from, and the, their relationship, their contracts, their policies, you know, upstream all the way. And we have to get that done in the next decade.
So without unified and, and, and adaptable, you know, transparent policy frameworks, none of this technology is gonna make a difference. So I think we, we will do that. And there's interesting things going on down that path.
It's kinda interesting in a way, just connecting dots between what you said, Catherine and you were talking about Chris, there's your own unified policy management, right, of what you're doing. So you know, you're, you, what you're applying where and how you're applying it, and then that's how that interconnects or interrelates with the people you connect with, work with, use their service product, whatever that is too. And I, and I appreciate what you said Chris, about, think about just serverless technology, like a lambda kind of service, right?
That, you know, it's there now, it's gone tomorrow may not be the same thing. It was a second ago when it, when it ran. Um, so it in, in some ways, Catherine, it's all sort of a dynamic unified policy management, right?
It can't be a static thing. Am I, am I on base here? Yes, of course.
You know, you do have to be responsive to the environment, um, you know, a threat landscape. Um, this is one, one area where I strongly advocate for actually ML driven, um, detections and policy. Uh, this is a thing where, for example, if you have a really large data set, uh, you can train your ML models.
Um, how we do this at CloudFlare, just 'cause I think it's a little easier if I give an example and it's, uh, we will score each request on a scale of like one to 99. And if something is less than 30, that means like it is very likely to be an attack. And because we have, um, hundreds of terabytes of requests, or sorry, hundreds of millions of requests every single day, um, we have so much data we could train this on and say a little blog in Malaysia gets attacked by a new attack we've never seen before.
Suddenly because that tiny blog in Malaysia got attacked that gets feed and fed into our ML model, we don't have to rely on a security engineer to like go and find and analyze that attack and turn it into a regular expression like firewall rule. Um, the ML will basically just say, okay, like since it matches something like this, um, we will just automatically block it. And this is why I'd say ml um, sort of combined with that traditional, um, you know, security analyst looks at the traffic and writes a rule that matches it and then blocks traffic.
Um, you gotta combine I think these types of approaches. So ML is a really, really great application, um, when it comes to being responsive to the threat landscape. And we have some data around this as well.
Um, we recently, not that recently, like half a year ago released our annual application security trends report. Um, and we found out that, uh, for example, like zero day vulnerabilities, um, we probably wouldn't have been able to find this out with just security engineers analyzing it. But with our ml, we were able to detect, um, and exploit 22 minutes after the, uh, proof of concept was posted online.
So, um, really, really great applications there. A lot of interesting stuff going on for sure. Well, if that doesn't make the case for dynamic security, what does, right?
Um, I, I'm curious, Kurt, how do you, is, is someone, you know, applying these things, applying security, are you, are you looking at things like ml are you doing in via yourself? That's something you look for in the vendors, the partners that you work with. How do you leveraging either that or the kind of technologies to help shorten that cycle between when things change and how you can account for it and secure it?
Right. The, I think the ML piece of it is, is hugely important because I mean, humans, we're slow. The, the technologies we use, the, the computers and I, each servers process all of this far faster than the human brain and I ever could.
And so we need to augment ourselves with this technology. So anytime we're evaluating new solutions and bringing them in, like I'm currently in the process of implementing a big one right now that focuses on platformization and ai, ml, it's all part of it because in humans with eyes on glass, like it's great to have those guys in the sock, but they'll get overwhelmed very easily with the speed at which things happen today. And so we need to leverage technology and machine learning enables us to do this faster than ever, and it's only getting better, right?
And so augment the human with that technology and you can very quickly pare down all of that information to what matters most and focus on real attacks like Catherine was just talking about. I wonder, you know, there's so much activity around ai, of course, a lot of it because of gen generative ai, um, Chris to, to security engineers have to become machine learning experts to be able to do this stuff. What does it take to really leverage it?
No, but knowing, knowing something isn't gonna have, um, uh, causing any problems. But, uh, I, I just couldn't agree more with, with both, uh, with Kurt and Catherine. 'cause you know, and, and you're point, point Kurt, it's all about time, time the transparency.
How, how long, and again, I've seen this over and over in my career where we get to these points where what we're mostly doing is sharing the war stories. You know, I have no idea was 72 hours, none of us slept. There was caffeine.
And, and my my question always is, okay, if there was twice as much, what would you do? Because obviously that we're at the limit, we can't possibly work any harder to stay awake any longer. And, and this, yeah, ai, ml, Oracles, whatever we call it.
This, uh, my a big, been a big part of my, uh, my focus on supply chain before it would, you know, AI became, you know, uh, a general, um, uh, generative, what the hell do we call it? I'm sorry, I forgot. Yeah.
Ative ai. Yep. Generative ai.
Yes. Uh, too many terms to throw around. Yeah, because again, we need to, you know, just for supply chain things, I need to read the contracts.
I mean, I can literally call someone up, you know, it's not a security engineer, but it's some administrative person of the company and I had to get them on the phone and get them to pull A-A-P-D-F and read the contract and find out if the clause allows me to get the information I need. That's not worth the human's time. I mean, that's the kind of stuff that computers can do really well, and they're just beginning, but that's obviously the direction we're going.
And if you can't see your policy environment five years from now, by various definitions, your competitors will be so much faster than you are that it won't matter anymore. Cur, I'm, I'm curious, without giving us too many specifics about Teradata, I'm not asking you for that, but what's your sense of, what are the, what are the new priorities that are on your Yeah, on your horizon or things you're dealing with now and that you've kind of added in the last year or so? What's changed about how you're thinking about security and that you've gotta address now?
I think there's, there's always classic problems that we, we have to deal with and tackle. Like, we can't forget things like identity and network security and the rest of it. But the, the prevalence in the emergence of generative AI and putting AI and machine learning in everyone's hands has meant that security teams have to be hyper aware more so than ever because these new technologies, people are latching onto them without considering the risks.
They're like, that's awesome. I can speed up everything I'm doing. And suddenly you see a news story about, well, what was it like Samsung engineers leaked their code through regenerative AI solution or whatever.
So you're, you can quickly lose intellectual property or put it at risk. And so we have to think about securing our environment for those solutions, or putting the guidance out for people to use AI and machine learning. Um, and I mean, getting visibility of all of this, and another big one that's been getting pretty popular and we're seeing a lot from different vendors and acquisitions and whatever, is data security, posture management.
Where is my data? Where is it moving? How secure is it?
Because at the end of the day, that's what the attackers want. They don't wanna sit in your network and use your resources to, to launch attacks as much as they used to. They wanna grab your data, steal it, monetize it.
So need, we're, we're focusing on data security big time in, in the more recent years, especially, um, forward looking because we have more data than ever. Interesting. Catherine, from your perspective, you know, communicating with so many companies, what are some of the changing priorities from your, from your viewpoint?
Yeah, I mean certainly the gen ai, um, piece is something we're seeing a lot. Um, everybody wants to put an an LLM on their web application. Um, and of course that means that you have to think of that as like a data security concern as well.
Um, because you wanna make sure your LLM is not gonna like accidentally leak somebody else's social security number because that's certainly happened before. Um, and so at, at CloudFlare we're thinking about this of like, basically how could you basically just put a WAF in front of an LLM, um, from that perspective, how could you prevent it from exposing sensitive data to the end user? Um, but then, you know, you gotta think about these more complex issues as well.
Like how do you prevent somebody from poisoning the model? How do you prevent, um, you know, some of these other, like how do you prevent it from hallucinating? Uh, these are all, you know, sort of adjacent to security concerns.
But, um, but nonetheless, we see some security teams focusing on this, um, increasingly. Um, additionally we also think about, you know, the, the LLM sort of security use case as a little bit of a just, um, increased API security use case since a lot of times, um, people are not building these LLMs themself and hosting them themselves. They're often, you know, bringing in LLMs from third parties, which, uh, necessitates, um, APIs, right, for integration.
So how can you make sure that these APIs are staying secure and not leaking them back to the host and whatnot. Um, so that's definitely something we're seeing as well. Um, I would say additionally, one thing I've been hearing a lot lately is, uh, software supply chain security.
Um, I think Kurt mentioned the beginning, um, sort of securing code that lives on the client device as well. Um, this is something that we've been hearing a lot about, especially as it comes with the PCI four, um, compliance, which is gonna be mandated at the end of March, um, in a couple months. Um, PCI I four has a new compliance requirement around client side security and securing, um, the client side, like software supply chain.
Um, so this is something we've been getting a lot of questions and inquiries lately. Um, you know, how much are organizations responsible for, um, the code that loads on their end user's devices, uh, when they visit their websites? Um, this is something we are seeing a lot of people trying to actually actively get control over, um, and make sure that they're not, you know, serving, uh, code to the client devices that could do things like download a crypto mining software onto their phone, which, um, believe it or not, we have seen somebody's trying to make, you know, personal laptops part of a crypto mining network, which is pretty crazy.
But, um, so yeah, I would say the client side component is, is something I've been hearing a lot lately as well. I, I just have to say, I, I love living in a world where we can use the term, uh, you know, hallucinating artificial intelligence in a conversation like this. Seriously, just, we, we understand about that.
It's Not a sci-fi movie. It's real. Oh, It's, it's real.
Yeah. Hey, so I've, I've kind of a left field question for you, Chris. So if this, if I throw you too far off the track, I'm guessing you're thinking about this though, is, is there an SBO m in our future for LLMs and s SLMs and all of these things?
'cause in a way, this is a whole nother part of the software supply chain, right? We're handing off to something that's doing inferencing, either on a chip on our handset or in the cloud, all of the above. How does that fit into, do we need to be thinking or at least wondering how we're gonna solve this problem?
And not only not the left field, and that's, that's right in the middle of the, the tracks. So in short, yes. You know, there's, there's another CI working group, um, Dmitri Rayman, uh, my colleague CTO at at SBE is, uh, a co-chairing now on, on AI bomb, right?
An AI bomb has been talked about for a long time. So what does that even mean? You know, so AI is code.
So there's this, you know, same sort of standard SBO stuff about that, but it is also the training data and the models that produced. Right. And this sort of goes back to my last comment about ephemeral ephemeral SBOs.
You know, we start with the idea that I am a software provider and every 16 years I release new code and I carve a new SBO m you know, on purist graphite. Um, but we live in a world where code gets compiled and used all over the place. You know, how do we even look forward and say that I can commit to a policy that says I will, if asked, provide the contents of this code without, um, actually going out and printing or saving or producing quadrillions of SBOs forever, you know, in, in exabyte storage.
Uh, so this AI is, you know, what we're currently calling AI is just another forcing function of the level of complexity we're at. So we need to be able to provide the answers to live up to the policies that we've agreed to, um, which is, you know, you know, in the SOM case we're talking about a software inventory that I will be able to tell you what code that was running or you know, what data set was used, and we have to get there. And, and, and it's, it is reasonable progress down that path.
It's a, it's a complicated one that is very similar patterns to how we'll do other things of similar complexity. Um, Kurt is, is that on your radar yet at all, kind of thinking about security of, from a supply chain for LLMs and AI and ML algorithms and all that kind of stuff? No, I mean, it's, it's certainly jumped up on the radar, especially since the whole SolarWinds thing happened.
Um, as Chris Blask talking, it got the wheels streaming my mind of, well, if we're gonna be kind of, we're moving towards leveraging ai, AI in the sense and dynamically generating SBOs and things, is this another attack vector we potentially have to watch out for? Is how do you weaponize that and, and protect against it? Because I mean, as we see attackers evolve their tactics and techniques faster than ever, they're coming up with new creative ways that defeat the traditional approach in microseconds.
And so how, how do you stay ahead of that curve now? And so I obviously, I don't have the answer right now, but it's, it's really interesting as Chris talked to start thinking about this, this new sort of problem that we're facing. And again, it all falls back to the rapid evolution of technology.
Yeah. Speaking of that evolution, uh, just in the last week or so, uh, Satya Nadal, head of the Microsoft was talking about the death of SaaS, meaning that's kinda the click bait one liner. The, what I think he was really talking about is e evolving nature of software architecture that I would describe it as today's microservices or backend code or tomorrow's AI agents, right?
We'll see more and more parts of AppSec built through, you know, with or through or maybe completely with AI agents. And it reminds me of going into the, uh, cloud native era of, oh, how do we secure microservices now that we're gonna do that kind of thing? That's kind of the, that's the next edge that we're, we have to work on and think about how, uh, there are different things we have to do for securing AI agents.
How are they orchestrated? Is it Kubernetes or it's some other thing that's managing all those things. And, uh, given that we're putting AI agent building capabilities in everybody's hands, in many cases, it, uh, could make for interesting.
I use that in a nice way, uh, interesting environment to try to secure and manage. So in some ways, the future is bright, but it may be, uh, pretty intense at the same time, same time. Well, and I think kind of building on that too is the, the technology behind ai, it's backed by machine learning.
Like you're, you're making technology autonomous, right? So it's not as predictable anymore. So how do you secure what, when you don't exactly know what turn it's gonna take next, Non-deterministic, right.
Well, I, I gotta add a no, a no of hope though, because it's easy, you know, to your point, uh, Kurt, the short answer is yes, because there's a new attack vector. Oh, yeah. Um, but you know, throughout my career I've been arguing this one, it's like, we'll probably keep the lights on.
It's like, no, no, if we don't do this and that, then, you know, we will, you know, but the, that we're on this, we're doing this call right now. We've managed to figure out everything else over this point. And not only that, but I think that we're, we've been mowing the lawn.
I think, you know, what we need to do, generally speaking in cybersecurity has been known maybe forever, certainly 50 years, but we haven't gone around to doing the vast majority of it yet. 'cause we haven't had to. But as we do, and I, I will take a risk and, and put a lot of my, my faith in policy, you know, and in real policy transparency, you know, in, again, in this decade, it gets harder to be an adversary because, you know, these are the happy World War II fans out there, you know, or no fans, you know, but the, the ubo wars, right?
There was the happy days when you could just have a U-boat and sink shipping all day long. You know, that's kind of most of the world, most of the, the history of the internet to date. It's not necessarily gonna stay that way that long forever, where there's always a new attack service, and there's always a, a, a new way when the last one is, is locked.
I think we will, we'll keep it running, we'll all be fine. And I think over, you know, at least over a period of decades, being an attacker will become much, much more difficult. I mean, I might argue it already is becoming more difficult.
It 'cause the, while, while the, the technologies we use as practitioners are getting more advanced, that helps make it more difficult for the adversaries of the world. But that's not to say that they can't employ similar technologies, right? So now we're kind of, we're creating that chicken and egg problem all over again and playing a game of cat and mouth.
It's kind of the next arms race, if you will, as technology evolves, everybody has access to it. Well, let's do this. I appreciate all the conversation, and we brought up a number of topics, um, just as a kind of concluding thought.
Uh, we, we've been talking about what are the things we need to be thinking about. Maybe they're new on, maybe they're on the horizon, maybe already working on this today. Um, if you had to say, there's one thing you'd really want to emphasize this, if you were, you know, somebody who's listening to this and maybe making a few notes, the thing that sort stands out to you as something really important to be thinking about in the next, let's say six to 12 months, if not today.
Um, Kurt, do you want to give us your thoughts and then Kathleen, if you would, and Chris, you can wrap it up for us. Sorry, did I say Kathleen? I mean Catherine, excuse me.
Kathleen. I work with a Kathleen. Sorry.
I've been doing that. Oh, good. Okay.
Yeah, I, go ahead, Kern. I mean, it's, we wanna avoid that situation where everything is a priority, so nothing's a priority, right? I think we, throughout this conversation, we've highlighted the importance of SMOs.
We've highlighted the importance of application security and how it's, it's becoming more important than ever because our application code is, is literally going everywhere. And that's, that's kind of the gateway for a lot of the attacks we're seeing in the world today. And so I think the, the emphasis is on application security, but it's also just say, let's not forget the rest of it, because all of the, the other parts of cybersecurity are hugely important.
And we still need that visibility. We still need the coverage, and we need to be thinking about ease of use as well, and avoiding the sprawl. So I know these aren't necessarily specific cybersecurity things, but they, they help you simplify your approach and, and focus on what matters.
And that depends, that, that changes everywhere you go. Every enterprise or company has different priorities. And so I think focusing on those things help enable us to, to focus on what matters for where we're at currently.
You're good, Catherine. Yeah. So I mean, like Kurt said, you know, we wanna make sure that we're not making everything equal priority.
So I think when it comes to application security, which is of course, my area, what I would say is most important in this space is visibility. Um, the attack surface is getting more complex, applications are getting more complex. Um, you know, where they're hosted is getting more complex.
So how do we actually have visibility into our entire, entire application attack surface? How do we have visibility into the APIs developers are creating so we can actually secure them? How do we have visibility into the software they're adding, um, to these AppSec?
Uh, that I would say is probably the most important thing for application security and also one of the most challenging things. Excellent. Chris, You know, Kurt and Catherine both want exactly where I'm going, so I'll just build on that.
You know, do do things that save you time to transparency. You know, if you, you know, don't panic, nothing's on fire. And, and when things are on fire, panic less, right?
Just take your time and, uh, getting visibility, you know? Yeah. Look at how long it takes you to figure out.
And anytime you find a, a, a way, you know, in this, in this topic we're talking about here, to spend less time to figure things out, you have all that time back to do things. And it's easy to just, you know, particularly in transitional periods, to just do more and more and more of what you've been doing, you know? But, uh, understanding the environment you're in so you can apply your resources appropriately is, is everything.
And there are lots of ways to do that these days. You know, there, there's a lot of Russian panic and there are a lot of, and you know, I will say it, AI and things like that out there who will actually make your life easier, give you some of your time back. Mm-hmm.
And you, to that point, feel better knowing what's going on, make and make better plans, that better strategy. Yeah. To that point.
Exactly. Chris, and, and Catherine mentioned it around, uh, ml, you, some of the things that I'm really excited about AI is actually just the understandability of what's happening. You know, Kurt mentioned about as things ramped up or, or you did, uh, uh, in, in the, if the tax doubled, right, how would we handle that if we're already maxed out?
So some of it is just handling the volume of things that are happening. But I think one of the things that I think is most exciting about generative AI is it's also so complex. No one person can understand the full system, right?
Or maybe even understand truly what's going on in a case of an attack or where you have vulnerabilities. And generative AI is starting to make some inroads and helping us understand systems and, and giving us some insights to some of the complexity. We may not be able to fully get into our head all at once.
So for example, I've been doing some work around how do you modernize mainframe applications? Well, nobody was around that built those things. Well, maybe it's people that built the network aren't even around, right?
So help us understand what really is happening with all this data that we've collected. And the natural language interface through that is, is a great aid. And I think just a real practical thing that we can start to begin to use today.
So don't think of AI as just as the next, you know, it's gonna replace all of our software and it's all gonna be different. And what do we do? There's things today that it's already helping us with.
So, you know, there's some real things too, not just what's on the horizon. Well, thanks to all of you. It's been great, Catherine.
Uh, we appreciate your perspective and Kurt, you're bringing, um, your experience and perspective. And of course, Chris, always good to be chatting with you and your connections into the security world. And some of the folks are working, collaborating together, which by the way, is another superpower we have in security.
And that's the fact that we work together and collaborate on, on these things. We're not going at it alone. So thank everybody for the good work that we're doing to help advance.
We hope this has been a helpful conversation for you, thinking about the, the last great cloud transformation, what we're doing differently and thinking about, uh, as we move forward. So as we've got our heads down, getting stuff done, getting our priorities done, getting our plans in place and executing for 2025, but also kind of thinking a little bit about what's next and what we might be considering and learning from others that are working in our space. So thanks to all of you.
Thanks for everybody for joining us today. And thank you to the Cloud four team for, uh, for sponsoring, um, our show today. And we look forward to joining us either on another recording or be sure and check the calendar for one of our live events where folks can ask questions and engage with us in a similar kind of conversation.
We have many of those coming up. We'll talk to you again soon. Take care everybody.
This is Textron tv. Hey guys, thanks for the throw. We're here with Nati Tal, who's head of research for Guardia, and we're talking about a new novel type of attack that's affecting e-commerce companies and that are making use of Google ad search capabilities.
But Naty will explain that in better detail than I will. Naty, welcome to the show. Hey, thank you.
Nice to be here. So walk us through this attack vector a little bit. 'cause it seems like it's a little something new and different, and of course the bad guys are always changing their tactics and techniques, but what's going on here?
Well, it's huge, huge story, ma mainly focusing on sponsor results on Google, but not only, so let's start with a simple example. Um, you search for an application, you want to install something that you're used to, that's the, let's say Slack or some something else, a notion and so on. And you are used to search on Google and click on the first result, as always.
And sometimes it's a sponsored result. Sometimes it's the real SEO style result. Uh, but you are kind of used to that.
And you also want to, to imagine that you, the results from Google, legit. So you click on the first one and you go to a site that looks and feels like Slack, for example, and you install the application and everything sounds legit and looks great, but in the meantime, you got Slack installed, but also a small segment of an application that is, was installed with it, which is a Steeler. And this kind of campaign is targeting all users, all people, and is more common for people that are looking for those kinds of applications, let's say Slack, meaning that those user, those computers are in most cases part of a company or an enterprise.
And eventually the data that is being stolen and is precious and valuable. And from that moment on, threat actors have full access to that company's network. And this kind of example is something that we see in the past year.
And so even more, uh, and the mo the more and more you, so you see those kinds of campaigns in Google ads, for example. There are also other vectors like ads on Facebook and social and so on. But in Google, Google specifically, it's actually quite too easy to create a campaign and name it after another brand like Notion Slack or any other kind of, uh, software that you are used to, to install target specific audiences, because this is what Google Ads does.
Target specific countries, cities type of people, high tech workers and so on, and get your malicious software installed exactly where you wanted it to. You see that a lot lately. Yeah, unfortunately.
How difficult or easy is it for cyber criminals to kind of create and launch this type of attack, and how prevalent is it gonna be? Well, at first, when we saw that, like a year ago, and we try to understand how exactly it passed all the, the testing and authentication that Google does for the advertisers. Uh, and what we realized is that it's not always this straightforward, meaning you are not going and advertising a software that is called after another one's brand and, and use domains that are similar in a, in a sense like Slack with two C or stuff like that.
We also talk about, uh, using different types of encoding instead of general letters. So it looks like it's the real domain, but it's not. But in many cases, they're using other kinds of approach to not all, not only, um, abuse the ad network itself and to target us, but also in a sense target Google and try to mitigate their, uh, testing and their authentication.
And they do that in many different ways. One of those is what we call cloaking. They create a campaign for some basic websites, some standard service.
We saw different examples for plumbers in Minnesota and stuff like that. They create a website that looks legit of some kind of a plumber, mostly by the way, AI generated just one click and you have a website to advertise it. But once the campaign is live, and once it is going and running and you gain the reputation of Google, in this case, they just switch it to another website.
And once you go to this website form a click on any kind of sponsored result, you end up in a different website. The Target website, the malicious website. In this case, uh, this way moderators at Google can see it if they go to the CRL, the CL legit website.
But once it a, it is active and ongoing, victims of this campaign are going to their malicious website. Um, so this is one way to do that. But there are others as well.
Uh, one, one example we saw in the last few days was for another service, uh, called Triple Whale. And when you search, even today, by the way, you search for Triple Whale on Google, you get the first results, PON sponsored result for this site, and then another one sponsored for the same website, same service. The first one looks exactly like the second one, but the advertiser is different.
One is actually the company behind the web, and the first one is a different company. Something, I don't remember exactly the name from a Chinese or Taiwan Taiwanian company that does that for other brands as well. com, but the t is a bit, if you look closely, it's a bit different.
It's a t form, another language, another encoding that looks exactly like the original with a different, with like small line on top of that. Uh, and this is a different domain, different website, and it goes to a different target in the end, not the actual triple way. Uh, and, and for some reason it's first in the results in Google.
And the reason for that is because it's a market. Advertising is a market. You place more money for this ad placement, you will be first, and you, and you, if you buy this keyword triple way for less money, you will be second or not even there at all.
Uh, and here comes also the, the, the, the way that Google does this business, after all ad ad networks like Google, in this case, it's like the main business. It's more than 50% of their annual revenue, if not even more, I think. And they're obligated for their advertisers.
They are their users, their customers. And it's not easy for them to just take down this kind of advertising because again, they've legit advertisers that do this business. And the entire ecosystem is based on this.
And it's a bit problematic for them to check each and every advertiser and also make sure that there are no such abuses of their network. I I'm not saying that they are not obligated to do that or have the responsibility to do that, but I can realize why it's hard for them to do that as well. So who's responsible for mitigating all this?
Is it the e-commerce companies that have gotta go look for all this stuff? Or is it Google or is there some sort of like shared responsibility model we need to navigate? Yeah, yeah.
And this is exactly what also the threat actors are abusing as well, who is responsible. And because the chain is so long and you have the, they have Google and the Advertis and the companies themself and, and other ad companies and creative companies, they in the middle of this chain. So who is responsible at the end to all this malicious advertising, not only in Google as well.
Uh, and this is one, one, I don't know, like the main, uh, reason why it's so easy. So it's quite easy today to use advertising to propagate malicious content because this ecosystem is so complicated. And in, you know, in a, in an, in the, in the world where you wanted, everything will be safe and everything will be great.
You could say that, okay, Google, you, you cannot do that. You can't give a permission for some, someone with malicious intents to advertise something like that on the top list of your search results. After all people have, you have the reputation of Google, of being the gateway for the internet.
People are used to just click on something or look for something and click on the first one. They're getting the search results. You can't break this reputation.
It's your obligation to do that. So this is Google, but again, there are different elements that can also harm them in doing so. In this case, they will harm main revenue vector.
Uh, uh, and on the second step of that, those are the users that actually use Google and want to give them the, the reputation they deserve in this case and use in the internet free without worrying about every click they do. So you have Google or any other gateway or ad network that have the responsibility to fix that or be more in focus for those kinds of attempts. 'cause they're all over the place.
It's easy for me just to create one simple search and I found at least three post advertiser on, on the Google network. So I guess it's easier for them to do that as well. And there are also the companies that advertise themself, let's say triple one in this case, they need to realize they need also to check out Dell Posture is on the internet, relates to those kinds of false advertising.
Not only using Dell brand name in efficient page, but also in search results. Something that I'm not sure everybody's looking for as well. And Google, by the way, provides those kinds of tools to search for advertisers and advertisements and like with full visibility to any kind of advertising.
So just as, as a company look for others that try to abuse your brand in this vector as well. Mm-hmm. And of course our as users, we need to realize it's not that simple just to click search something and, and click on that.
We need to be more cautious in what we are doing. It almost seems like this is a variation of an attack where, um, you know, they're basically changing the name of their company by one letter. So you don't realize that you're clicking on something and this kind of feels like the next iteration of those types of attacks.
So are we gonna see a lot more of these types of things? Yes, yes, unfortunately. Uh, and, and we see brand abuse being more and more easy for threat actors in, in a means of buying those different types of new TLD domains that can look and feel like the real website or the real brand.
We can see more and more vectors for propagation like social media and Google search and Google Edwards. And, and you, you, you, you start to realize that everywhere where you get content in today's internet is a place where threat actors will try to find the content you're looking for first and be there first. Be the first one in the search resort, be the first one in your social feed because this is where you are looking for content and they want you to reach them.
So when we get to a point where people just won't click on anything, 'cause they won't trust it, and you know, the whole system is based on that trust factor. So is this kinda just, you know, the beginning of something where people might decide that, well, I'm just not gonna pay any attention to any advertising at all. 'cause it's might be more trouble than it's worth?
Yes and no. And of course I don't want it to be yes, because if we break this model of advertising, we want to have internet, we want to have all this, the good stuff, we have the internet, because eventually this entire ecosystem is based on advertising and we get free products because we are the product. So, and we love that eventually because we use those products, we are so used for to those products and we dissolve those products.
So we just need to be more cautious and more, uh, and to realize how threat actors work and to be more aware of those different types of, of attempts and vectors and even more complex vectors because awareness is like the first thing we need to do. And we, we are more aware, we, it'll be like easier for us to skip over those kinds of attempts. And again, it's not 100% word proof.
You can be aware on any, on everything all the time. And I'm saying that as well as like, like one that have more than 20 years of, of experience in cybersecurity. I, I talk to about myself.
I can be 100% safe just by being aware. Uh, and I can also sleep and click on something that I didn't realize because, you know, the world is so crazy and everything is going on at the same time. You get like, handle notifications a minute in your phone and something can slip, slip over this kind of awareness.
Uh, this is why we really need different tools, automated tools that will help us, uh, if it's a buzz was in protection or any kind of other protection. Just like enterprises have all the cybersecurity tools, you also need one as their person, as a regular person. Oh, cool.
Hey folks, you heard in here the bad guys. They're just getting clever all the time and they're really getting into the content. It's not just kind of the the old style attacks that you may have seen in the past.
And if you're an e-commerce vendor, you gotta protect your brand because well, Google will help, but they can't do everything themselves. Hey, Nadi, thanks for being on the show. Thank you.
Thank you. All right. And back to you guys in the studio.
Welcome back to Textron Unplugged. My name is Cassandra Chin, and today we have Christine Spang. Hey, Cassandra, it's nice to meet you.
Can you introduce yourself? Sure. So my name is Christine Spang.
Um, I am the founder and CTO of a company called Nylas. Um, I've been working in tech startups for really been building this company for 11 years at this point, which is a long time. Um, I actually graduated from college in 2010, so I've been sort of building my career for about 15 years at this point.
And, um, uh, I was born in Canada, um, but I grew up in, in the United States of America, in, um, in the state of New York, sort of in the suburbs. Um, and, uh, uh, that's who I am. So what inspired you to get into technology?
Yeah, so, you know, growing up like my, my family sort of, I, I feel like I came from a, a family of engineers, um, though, you know, a lot of time growing up I did normal kid stuff. I was just like playing outside climbing trees. My, um, my grandma and grandpa had sort of like a, a farm out in the countryside.
And, um, I have a lot of really happy memories. I used to go there in the summer. Um, and one thing, so this was sort of like a, where my grandparents retired too.
My grandpa was a chemical engineer, but he sort of had this like, um, he, he couldn't stop building stuff. So like, on this farm, which was sort of his retirement hobby, he built, uh, barns. I remember like as a kid, like helping, um, helping put up the, the struts for like a new barn.
So like when you do like a barn raising, it's um, you know, they're really big, so it's like 40 feet tall or 50 feet tall. And, um, you like build, um, the sides of the barn and then you sort of like haul them into place and then you like attach them via sort of the spine of the building. And so, um, I remember helping with this, like they, they would let me sort of climb up and like hammer and nails and stuff like that.
And, um, so I feel like I sort of had this culture of building things, so it was just like a part of my family. Um, and doing like crazy experiments too, like, um, my uncle who, uh, is a software engineer, he, I remember this one time where we decided to see if we, we could build like the biggest possible kite that would still fly. And my, my grandparents had been sort of re insulating the side of their house.
So we had all this house wrap and it's made of this material called Tyvek, which is like really strong and it doesn't rip very easily. Um, so we like built like a kite frame from wood and used the Tyvek to make like a height that was like, I don't know, six feet long or something like that. And then, and then we had, um, uh, like, um, uh, a, uh, they had, um, bailing twine, like sort of twine that comes in, these big rolls that you'd use for all sorts of things on farm, but specifically for like making hay bales.
So we had like a big roll of that, and that's what we used as the kite string. And so like, we like got the kite flying in the hay field and we were like sort of letting out this, um, the baling twine and it, it got like way up high and we were flying the kite and it was working. Um, and then eventually, like some sort of draft came and, uh, we were like pulling in the string and trying to keep the kite up, but the kite crashed, like, I don't know, it must have been like a kilometer away or something like that.
And, um, it crashed over the, the hydro electrical wires. And, uh, I remember, uh, my uncle saying like, you know, we were like going through sort of the, the bushes to go and find the kite, but he's like, don't touch the, the string because if it's wet at all and it's like over the electrical wires, it can conduct electricity. And it's like those, you know, hydro wires are super high voltage, and so could have been like a really dangerous thing with the wire being, or the, the kite being down over the electrical wires.
Um, so those are just like some examples of like, things that were like kind of normal, um, in, in my childhood. And so I really felt like I, I wanted to build things. I wanted to be an engineer.
Um, and uh, how that sort of turned into me going into software was, um, uh, in, must have been in high school. Uh, I I started getting into computer games with my brother and, um, you know, we didn't really have any money, so we were like downloading all these like, old games from the internet and like playing them on my computer. And eventually I started exploring these things called, uh, multi-user domains, which is like if you played like Dungeon and Dungeons and Dragons or like, um, sort of like RP G style games, it's like text-based RPGs that are played online and then like people will go and sort of like build a world and sort of construct the rules for the world too.
And then people log in from all over and sort of make a character and play within that world. Um, so, uh, I was like really into the Lord of the Rings and I started playing, um, on a Lord of the Rings themes, uh, mud is what they call 'em for short. Um, and I got so into this game that I actually started helping build it.
So they had folks, um, and you know, it was all volunteer created. It was just like people in their spare time. And so first I started out by sort of using the in-game tools to like build parts of the world and sort of run storyline plots.
Um, but, uh, eventually I was like really curious. There was like this one guy who was part of the people that, no, there was two guys actually that were part of the people that ran this game who, uh, who could write code. And to me it was like they had like magic powers because they could like change the rules and create new game mechanics and sort of, um, alter things in a way that was much less prefabricated and like any sort of idea that you, you thought up, like it had to go through the people who could code, um, in order to make that into a reality.
So, um, I started being interested in learning to program and, um, started learning to code when I was in high school. And pretty much from then on I was like, I wanna be a software engineer. I wanna build things from software because, um, it seemed like that was like the people that had the magic powers.
Um, and uh, it really sort of narrowed my focus in terms of like taking my interest in building and math and science and turning that into some what I wanted to do for a career. I think gaming's a fun way to like get into coding. Yeah, it's pretty common.
I'm actually have a, a cousin who, um, went from a just like love of like playing games to like, he started studying like game design and learned to program through that. And then, you know, I think he has a job that's completely unrelated to gaming at this point. But, um, I think games really show the magic and the power and they're really engaging, um, and sort of draws people into the world of what you can do with computers.
That is one of the ways I got into computers. Oh yeah. Gaming like Minecraft.
Okay. Through Minecraft. Yeah.
Any other games or just Minecraft? I think it's mainly Minecraft 'cause it's written in Java. Okay.
There's plugins so you can kind of hack it. Yeah. And right in Minecraft it has like all these sort of in world tools where you can like kind of build stuff in the game, right?
Yeah. Mm-hmm. I've heard a lot of good things about that.
Like, people like to, I, sorry, I'm like identifying myself as old, but like, I have friends who have kids who, who play Minecraft and they think it's great. I love it. It's like a creative platform.
Mm-hmm. Yeah. It's not just, it's, it's not just a game.
It's like really, uh, a cool thing where you can like build stuff and, um, get engaged beyond sort of like going through a preform storyline. Like for me that was like something that was really important. I didn't wanna have to like follow this one specific path I wanted to explore.
And so I went from like playing games that had more of a defined path, almost like being an interactive movie to like things that were more freeform and that allowed you to like, choose the direction that you wanted to go and, uh, and explore. Yeah, I think that's really unique to coding. Mm-hmm.
Mm-hmm. Um, can you talk a little bit about what you're doing now? Yeah.
So, um, basically what happened from me getting interested in computer programming, um, you know, I I ended up going to college to to study computer science, uh, at, at this school called MIT. Um, and, uh, yeah, I was definitely like kind of like a nerd and an outcast in, um, in grade school. Uh, I would say like, I sort of found a crowd of people who are, or sort of like music nerds, uh, who played like in band and stuff like that.
Um, but basically the minute I arrived at MITI just like sort of felt like at home, like people really excited that I worked on open source software in my free time and like publish code on the internet. Um, and I guess I had gone from like the building the game to, um, the game ran on this operating system platform called Linux. And then I just sort of followed my curiosity of how does this operating system work that's like, built by people all over the world.
That's pretty cool. Um, so I started contributing to Linux and then, um, I ended up going to college to study computer science. And um, actually through that I ended up sort of by accident in the world of entrepreneurship because, um, some folks that I knew at MIT had started a company and, um, I ended up working for them part-time during college.
And so it wasn't something that I'd rather really like imagined for myself, like going into like, like starting a business. Um, like I think that like a lot of people who identify as like builders sort of feel like allergic to the, this idea of like business. 'cause there's like, you know, finance and there's like all these, um, people and sort of culture, uh, around corporations that seems like sort of the antithesis of like the ethos of just like building and going and doing stuff yourself.
But, um, discovering startups actually ended up being a really cool thing for me because it allowed you to like bring that builder mindset and then learn how do you like, create an organization that, um, can sort of take what you build and use that to like, uh, help other people do something. Um, and um, so I, I basically joined a startup that I was started by some friends of mine through college and I was there for a couple years. Um, and then after that I ended up starting my own company, which is this company called Nylas.
And I've been building and running that company for 11 years at this point. It's been a long time. Do you still do a lot of coding as an entrepreneur?
I used to. Um, I don't right now for sure. Um, my company is like over a hundred people in terms of the number of people who work there.
And, um, uh, I mean, when I started the company I was like two, two or three years outta college really. Um, I guess it was three years. Um, and so I, I built a lot of the original version of the product, but then we sort of grew and scaled a lot that ended up hiring a whole team.
And so, um, honestly, every, everybody on the team who is like in charge of building the product today is like much more experienced than I was when I started the company. And so I think being an entrepreneur you have to like, learn a lot of different skills and do a lot of different things, but it, it's not really conducive to specializing. Um, so sometimes I write some code to get to get something done, but I also like, um, you know, work with our marketing team to like produce content that will help people discover us and like help translate what does this piece of technology mean for, you know, people who ought to be, you know, using the product.
Um, but it's a, it's a developer product, so we actually make a, like a platform that, uh, is sort of tooling for developers. So, um, I feel like I don't code every day, but it is still like very much like, like a, almost like a, it's a programming related job. It's interesting how you still need coding skills To be an entrepreneur.
Yeah. And like almost everybody at my company, they don't necessarily know how to code, but you have to be familiar enough with technology and programming to be able to talk about h how you would use our product and how it relates to, um, to other technology out there because, um, it's something that people use when they're building software. So, uh, you kind of have to be able to talk about it.
It's like a foundation. Mm-hmm. Yeah.
That's like a synonym for the word platform for sure. Um, I think we've had a really good chat today. Cool.
Well thank you Christine. It was nice getting to know you a little better and telling you about, um, about how I got to where I am. Yeah, I think I learned a lot today just from like your own experiences.
Cool. Thanks for having me on. Hi, I'm Vejesky and I'm here to talk about observability.
I really love to talk about this topic because I start my career work with observability. And one thing that we would discuss today is the observability integrated with the qr. Let's start.
So our agenda will be for talks I added in the slide. And let's start to talk about the revolution of the observability as engineer. I will start with the definition.
What is observability? It's very important we understand that in the engineering world we have the definition, the observability term start in the engineering field. But today, the marked see the observability not only as a technical definition, the marked see observability as a full picture.
Okay? And I added here why the vs rely in observability. So I think everybody here is technical and we know the importance to be proactive and find errors, detect the things, uh, before, uh, outage happens.
So this is very important in our business, not only technical specs, let's talk about business. We are technicals, but if our systems talk, what happen, our business talk. So if I have a good observability in place, and I will talk about the two and the, uh, the third, if we have a good observability in place, we can reduce the, uh, the time to, uh, resolve the things we have a of things that we can improve.
Okay? So observability, again, technically we have the definition that came, uh, is pro, uh, started in the engineering world, but our, uh, technical, uh, word see observability as the cap, uh, the capability to see all the things that we have in the environment. We need to understand the data that our machines, our applications, they're provide to us.
So the observability I compare as, uh, exam that we do, so we can see everything that exists in our body. For example, if we do exam, the, the doctor will request. And okay, we have the foot panorama, imagine that we are doctors of our applications, our environment, our system.
So, but let's continue observability. In the past, uh, the companies, uh, they always try to say, oh, observability no. But today they understand that observability something so fundamental to to have in place that is not a luxury.
Okay? We need to invest money, time, resourcing observability. Because again, if you have outage, imagine that we, you have a application, you are you, you are in the middle of the black Friday.
Imagine if this stop. So imagine the, uh, the money that will stop to be received in your company. Observability is the capability to see technically what's happening in the business.
I'm trying to be as simple here because technically if you go, oh no, observability is composed by, uh, trace logs, um, um, and metrics. This is technical. We need to, as engineers act as, uh, dev people, we need to start to talk the business language to including, uh, receive more power.
That means money to have more people work with observability and mark those. So why is that revolution? Because we are in the moment that we are in the digital world.
Our world is digital, everything is going to the cloud. Everything now is application. They stores everything.
So observability, uh, are the eyes of this new digital world. So we as observability professionals, we are so special here we are the eyes, we are, we are helping the business understand what they have in place and the strategy that they need to build. They are the leadership are using that, this data, our data, okay?
And the innovation starts here. So, uh, I thought here about the this, uh, beautiful thing that's observability. Observability, but we have a lot of challenge.
Yes. Challenge because the word is not perfect. Okay?
So let's talk about the observability challenge now. So if you work with observability, probably you understand what I'm trying to communicate here. In observability world, we have a lot of challenge and I try to classify in three.
So the first one is the technical, okay? We know that observability the tools. Let's talk starting, uh, talk.
Let's talk, talk, talk about the tools. We know that we have a lot of tools that can provide, uh, the data. Can we have a lot of APMs in the market?
So we have challenge associated with the level of data that I you extract from the system. Okay? We have challenge when we have a big company, when we have different, uh, tools added, you know, when this team has the use, the two A, when this team use the two B, how to integrate, you know, um, in more data is better to us.
And when we talk about data, we are talk about is some case extra license, uh, storage, et cetera. So in the technical specs, we have the challenge of the two. Okay?
The, the tools, okay? We have the challenge of the silos because the companies, uh, they are organized in silos. So how to integrate areas that are totally splitted, but they are using the same, I would say application K or the infra.
So we have this kind of challenge. We have the challenge of mindsets because if you don't provide training, okay, uh, the people maybe can think that observability is the same thing as the monetary. Sure, the two works together, but we need to have the mindset to avoid silos in the monitoring world.
This is common. Okay? Share, I will not go deep here, but exist a difference between monitoring world only monitoring world, and the, the word that combine monitoring observability.
So technical aspects, aspects, well, it's a big challenge. The other aspect that's a challenge, it's money. Okay?
Because sometimes we are so technical that the, the leadership, hmm, why I need, explain why I need to invest in this tool. Sure. Today we have a new generation of cos that understand more technically the reason, but we need to explain that we need to have investment in training because change the mindset.
We need to explain that the tool is not expensive, okay? We need to explain that the tool we collect, the data that we create, a way that we can understand the business. Imagine the simple case of, uh, associated with I commerce.
So if we observe, well the commerce, we can see the how the application, the website, everything's flowing. And if we have out Asia problem, we can say, Hey, leadership, if we, if we don't fix this and one hour, the company will, uh, will not receive this money, stop the business, et cetera. So, uh, always it's good to have a plan, a strategy to present to sta uh, to the stakeholders why they need to invest in tooling and not only tooling, but in people that knows how to work with observability.
Okay? So I talked about technical, um, the money aspects and now future cultural aspects. Why?
Because, uh, in the, I will say old mindset, the people, at least some people that I know, maybe you are in the perfect world, but I'm not in the perfect world. So the people think, okay, I will buy this tool and the tool will do everything. Okay?
We have smart tools. Yes, we have. But um, imagine that you have, uh, a company that you have a lot of teams, ah, this team use the, the two, a other team two B, the other team two C.
Okay? First you have a lot of C not in the observability area, you have silence in the company. So it's hard to consolidate things that are not talking in the business level, organizational level.
It's, it's complicated to unify great, uh, a single, uh, visualization. So, and when we implement, uh, observability project, we need to talk with the people. Hey, team A, team C.
Now we have, uh, uh, observability tool. Can you adjust your data? Can you send me your data?
You know, you need to go to the people and start to, to demonstrate the value of the observability. Again, sometimes we need to go there and talk, Hey, it's not ob it is not the monitoring and, and explain, okay? We will see the full picture and, and create sometimes the bridge, bridge, the connection between two teams is a little.
So again, if you, if the future of the company is in silos, sorry, what you say here, you can have the best tool in place. It's very hard. You create some KPIs that you provide good results to the business.
One thing is the technical aspect that yes, we need to have the amazing observability to doing the monitoring of, um, the applications and the entire food cycle, et cetera. But, but if we want to have a good money in our area, we need to, uh, uh, create the future help to create the future. Okay?
So I added here the observability challenge in my, uh, based on my experience because sometimes we have companies with the best team, with amazing tools, okay? But the, when we start to configure the amazing features in the amazing tool, okay, you don't have money to pay the tool, okay? The technical team goals, they implement amazing thing, et cetera, but the areas are not integrated enough to, uh, receive in a good way what the observability tool our, uh, team is designing.
Okay? Ah, why you need my data. So, so these three things needs to work together, okay?
Uh, no, I would like to talk here about the observability in the product world. So, uh, always we think about observability in traditional, in traditional aspects, okay? If I am a dev guy, I use the good, um, observability tools to monitor my CI/CD, blah, blah, blah.
So the Bernet set, but, uh, I'm bringing here a different perspective for some guys. I know that he, we have a lot of webinars that will go in a deep level technically, but this often the observability products that happen in the marketing that is so is interesting, interesting. So, uh, the first thing, uh, what means products?
Okay? Uh, I will try, I try to explain here in simple words, okay? But is, um, operational excellence of the products, okay?
They, they want to, to have, uh, a way or, um, output that everything that is in associated with a product is good, is consistent, et cetera. So observability in the scenario, what I'm seeing, observability, uh, is now the heart of products. When you are telling this because work with, uh, products, no, no, no, no.
I'm telling this because the behavior of the good products leaders, the engineers that works with products, they are seeing that observability is, um, is, um, how can I say, is that the light that will guide then in Antonio? So I'm adding here, uh, some image from the, uh, the products YouTube channel, okay? com VR is Brazilian side, but it's the production university that the, the people that works with, uh, this proops area, what they are talking observability.
We have a lot of disciplines when we talk about products, but the observability start to be so important that they are adding in the beginning of a planning when they start a project, project, okay? Why, why they are doing this? Because everything now is associated with journeys.
Journeys, uh, and the observability will provide the data and the insights that the thing that are defining create the product. Think about everything needs. So here it's the phrase that I added.
Observability graphs gives products, the data insights required to all align the customer experience with the operational goals, driving both performance innovation, think, uh, in this way we have a product. And you need to start to observe what your current imagine, uh, a new product not make sense. You create the observability definitions, what you observe after the end of your entire product definition.
So observability needs to start in the beginning of the, the project. Okay? I return this slide, and this is based on the experience of the professionals that are working in this world.
And as a observability person, I totally agree, how many times you think, oh my god, they create everything, but nobody had an observability tool to know what's happening. And after that, when you transfer the application or to another area that's responsible to, uh, to, how can I say my keep the environment safe, you have problems. So align observability since the beginning, okay?
Uh, and here, uh, I start to talk about the journeys, and that's the point in observability, in the products word, sure. I about this framework, this products model I, uh, is new for, okay, it's new, but you go to product, we achieve, you can see the pictures, what the market is doing, okay? And have a different view, okay?
But product bring here the top observability, observability. So important that, that in some, um, uh, companies, they are working as a bubble to, not a bubble, but I think to provide, uh, answers to the product delivery team. To the product operation team to keep the continuous discovery.
Because think Ima you have a product, you deliver it, okay? How you can innovate your product if you are not observing well, the things, if you don't define the, the KPIs that can help you in your know, to innovate. Because in the, in the end, we are talking about innovation, okay?
I'm not reading these slides. You, you have my slides, okay? And this slide is basically what I said.
Observability is became more and more important in the products area, okay? And sure, when you create, uh, application, et cetera, you have the traditional, traditional, the, the dev are a psycho, et cetera, um, flowing. So I talked here about the observability, um, revolution because again, sometimes we are so technical and I'm engineer, I assume, I'm so technic that when someone talks about observability, observ, it came from engineering, blah, blah, blah, that is the capability to see what exists.
Okay? But observability for the marketing now, um, it's the cap is the eyes of the, the, the people to see what's happening with the environment. Applications, okay?
I'm simplified, but observability, when I, I talk, oh, I work with observability. Ah, when it, so you know what's happening in this environment, you know what's happening in this application, yes. And because I know sometimes, okay, but I think your application, uh, sometimes needs to, to receive some investment.
Why I I start to talk about this because I know the data, you know? And more and more we are in this tech technical world, we understand that, oh, you need to buy innovate, okay? Name, this is a leg, okay?
This is another conversation. I talked about the chance, and I talked about observability in the products work. So let's talk, uh, about the part that sometimes the technical people forget.
That's the Strat thing from the technical to the business, okay? Again, if your boss match that your boss don't know nothing about observability, ask, um, I dunno. Now your name is John.
John, why I need observability in my business. Okay? John, you have data that you can transform decisions because if you go and explain, no, observe a bit, you provide metrics logs, they tell no, no, no, John will, uh, your boss John will say, no, no, no.
But if we use our expertise and we request help from our colleagues in the company and create a good dashboard, we can say that we are supporting the business. And this, I'm talking here ways to do this, but in the end, it's a culture that needs to be built in a company to have this collaboration between the areas. Again, a good observability to IPM that isn't is blah, blah, blah, blah, blah, lead there, blah, blah, blah.
And the gardener, they have a lot of features. Open source or a internal dev that was created by the guru in your company, okay? But if we, we don't have this approach to talk with the boss, okay?
The stakeholder, well, sometimes it, it's complicated to have the investments. And again, when we talk about money, okay, I'm technical, I like to talk about money. We need to talk about operational cost reduction, okay?
We know that good observability tools will help us to detect the problems we know technically you can test do A-P-O-C-P-O-V if you don't have a observability tool, okay? We'll help if we have good observability tools, good observability tools configured by good people. You have resource optimization.
You can detect things that you are not using in the cloud, for example, ah, this a kind of infra data can I'm not using. So are you, uh, activate or reduce? So you have this, this impact that flows, uh, flows no goals to the leadership with a good message to investing in observability.
The data always will provide us things to improve. Think in the products. Imagine we returning for the guy that's defined the product.
Hey, your product's here, but based on in the observability KPIs metrics, what you define the, the product that you created needs to prove this. Man, this is amazing. Okay?
This is a, is more than technical, and observability empowers us to understand, uh, the connection between the business and operationals, et cetera. Share, uh, customer satisfaction. Everything that I added in the last, uh, bullet needs to be combined with other things.
For example, when we talk about, uh, customer succession, we need to talk about other things. Okay? I have the observability tool.
Do, uh, monitor monitoring, observing this part. I have these KPIs and share, if you combine this observability data with, um, a survey with, uh, other KPI is more associated with, uh, with sentimental, but analysis, you'll be good. You know, because sometimes the customer are answer surveys, oh, I don't like this application, blah, blah, blah.
And okay, it's only the heart of the customer talking. Imagine you combine the heart of the customer talking crying. Oh, I don't like this application with you, the observability data.
Why? Uh, I, I say, Paul don't like the the application. Oh, always.
When the, the customer send a survey, he, he cries. Okay. So let's see what the experience that PO is having in the application.
Observability data. We need to combine again, it's future, okay? It's future.
You talk with the areas associated. So, uh, observability is not just about how your system works, okay? I know that we are technical, but the observability word became, uh, I'll say a, a monster, but in a good expect because, okay, to, I was in a, a me lemme talk one thing with you.
I was in a, a secured event and the security guys now observability in the middle. Observability, observability. Years ago, the secured world was totally isolated.
Years more than 10 years, okay? I'm not so young. But understand the point.
Everybody start to understand the, the importance of the observability in other areas. So we need to create the connection, the future, talk with the people more than technical, and I'm finishing my presentation. But again, your company is ready to change the future, to work integrated, to transform the, not only the DevOps world, but the business using the power of the observability.
That's a question that I, you keep here to finalize my presentation. But again, if you don't go and talk with other areas or forget to change the mindset of your team, well, well, well, well, you'll not, you'll not achieve good results. So mic complete.
My name is Van Es. My contacts are here. So I hope that you enjoy this session and see you next time.