Techstrong TV January 19, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Welcome back here to Techstrong tv. My next guest is Scott Brighton.
Other, uh, Scott is the co-founder and CEO of a company called Kilo. I believe it's Kilo ai, and we're gonna hear more about that in a second. But let's hear more about Scott.
Scott, welcome to Text Drunk TV man. How are you? I'm good.
How you doing, Alan? Good. Um, before we start, you know, before we talk about Kilo, let's talk a little bit about you, Scott.
You're the co-founder and CEO there. What, what's the story? What's your story?
Well, my story, um, so I am based in the tech hotspot of Washington DC mm-hmm. Um, I guess for former former life, um, my kind of first founding experience, I started a data and analytics consultancy called Brooklyn Data. Um, implementing, uh, data strategies and tools like Snowflake.
DBT kind of built that up from, let, Let me just ask a stupid question. You didn't do Brooklyn data in Washington dc I started in Brooklyn, so, alright. I, I am, I started in Brooklyn too.
Perfect. There, I started in my Brooklyn apartment where I was living at the time, pre COVID. Uh, and then March, 2020 I scoodle down to, to Washington DC to get, um, free babysitting from my parents.
Well, that, that's always, Hey, look at the cost of babysitting. It's, that's a good deal. The, uh, yeah.
So I started, um, Brooklyn data, um, essentially helping companies navigate, you know, the modern data stack, uh, build that company, uh, to about a hundred people and sold it. Um, very cool. And it was, it was a fun experience.
And, you know, after I sold and and left the company, I stepped back. I was like, shoot, was that like the biggest thing I'd ever be a part of? And not just building the company, but just like this, like transformational wave of the modern data stack where everybody, you know, who was working with data, who's kind of like life was transformed.
Um, and that's when I met my co-founder Sid, who, who kind of, we got connected and, um, started talking about Kilo and, and agentic engineering. And I was like, aha, you know, I will be part of something bigger and it will be 10 a hundred times a thousand times bigger. And that's kind of, you know, AI in the agent engineering wave.
And so it's kinda, this is the, the second wave I'm riding. I love it. Um, you know, you're right though.
You, uh, no one wants to hear that they peaked at 32 and it's all downhill from there, you know? Uh, I, I get it. And then of course, you, you referenced your co-founder Sid.
That's Sid ndi. Mm-hmm. Right.
Uh, and our audience knows, well, I haven't had Sid on the show in years, actually, I'll tell you the truth. But of course it, Sid surround was the, uh, founder of GitLab. That's right.
And Sid and I go way back to when he founded GitLab. Actually we used to. Wow.
Yeah. I used to go and we used, I forgot what they used to call it. Not GitLab days, whatever their user conferences were.
Yeah. They were small. We actually did one in Brooklyn together.
Oh, wow. Okay. In Williamsburg at the Williamsburg Hotel.
Cool. Back when Williamsburg was just starting to be cool again. You know?
I remember that. Yeah, man. We did in San Francisco.
I used to have sit on here every other month. com. Yeah.
Early in the DevOps revolution, if you will. Uh, so give Sid my regards. Don't we'll Do, hi, I'm, I'm chatting with him right after this, so, so I'll know you Said, always said hi.
Um, so let's talk about Kilo, right? Kilo ai. What's that about?
Cool. Well, kilo is, um, the most popular open source coding agent. Um, we're an agent engineering platform that helps, um, kind of engineers, uh, you know, move at, you know, what we effectively affectionately call kilo speed.
Um, okay. Which is, you know, I like to, to describe kilo speed as you're driving to work. Uh, and you only hit green lights.
And that's like the feeling that we feel like you should get while coding, especially with ai. And that's kind of our mission is to enable kind of engineers to move at kilo speed. I love it.
What a great way of explaining that. Man. You know, I live down here in South Florida and it's seasoned down here.
All those folks from Brooklyn and Greenwich and everywhere else behind, you're hitting A lot of Red lights. I'm hitting a lot of red lights. 'cause they stop.
If the light looks like it's gonna turn yellow, they start breaking. And, um, yeah. It's crazy.
But anyway, how, you know, 2025 for many of us in the industry was going to be the year where agentic AI kind of takes the spotlight mm-hmm. From generative ai. And as we, as we sit here on the cusp, you know, well, it's not just the cusp, we're, we're in 2026, I think a lot of us realize that our ag agentic experience in 2025 left a lot to be desired to say, agreed.
Yeah. Why is 2026 gonna be better and how does Kilo make that happen? Yeah, I think that's fair because you see all these articles of, you know, you know, people actually moving slower with AI or AI projects failing.
Um, and I think what we've seen when we look around is that, um, the, the promise of AI isn't, isn't kind of clicking because, um, the tools are kind of working against us. And so, you know, if I look at, so say like the, I guess the, I guess the cursors of this world, um, that are essentially mm-hmm. You know, I would say selling, uh, subscriptions for a consumption based product.
And so the dynamics are, the more you use cursor, the more a cursor loses money. And so they're essentially throttling you when you hit a certain limit. And then you kind of go to, you know, what I would say, you know, like the captive, um, agent engineering platforms like Claude Code, which again, great platform, but, um, we kind of feel like it's, it's silly that you would be wanting to kind of anchor yourself to just a set group of models.
Um, and, you know, we're finding that people aren't having the right model for the job. Um, you know, Aquila, we've got 500 models. And then the last thing is, you know, when you've been using VS Code for the last 10 years to develop and you know, your company's saying what and admit It And vs.
Code's great. No, absolutely. Sorry.
And, and You know, sorry. Know when your company says, Hey, you need to switch to this other platform for ai, and you know, you know, of course you're gonna have to learn a new tool. You've been using the same tool for the last year.
And so where Kilo differentiates is, you know, pay as you go, no throttling ever, you're never gonna be working late at night, hit it, you know, be pushing on a deadline and all of a sudden your context, you know, window compresses because you've, you know, used too many premium requests. You can use any model you want from the latest and greatest to kind of open weight models that are much more cost effective. And then you can use any UI you want from VS code to JetBrains to CLI cloud agents App Builder.
Our goal is to kind of meet the engineer where they are not put red lights in front of them. 'cause I, I think that's what the theme of 2025 was. You know, companies kind of, you know, software tools waving, Hey ai, but really just putting a lot of unnecessary friction.
And so, I mean, that's our mission is just to reduce that friction through an all-in-one agent engineering platform. I love it. You know, there's another aspect though, to Kilo and the Kilo mission and it, and it's very, um, very similar to what Sid did with with GitLab because when you look at, and I happen to know this 'cause I've interviewed Sid a lot of times.
Right. But when you look at Yeah. Sid's background, even before he had GitLab, he was all about open and open source.
And that is really kind of woven into the DNA of kilo as well. Exactly. Talk to us about that, Scott.
Yeah, I mean, I think like, um, openness is just so core to who we are at Kilo. And, and, and, and for me it comes down to, I would say three, three main reasons. And I guess the first one isn't even unique to Kilo.
Um, Sid and I are big believers that, you know, when you build in the open, you build better. I mean, and, and frankly, you know, when you talk to kind of founders of, you know, open source, open core code available, um, products, um, they kind of talk about this flywheel of, you know, you know, we get great transparency, great relationship with the community. The community actually becomes our extended engineering team like Aquila.
We're constantly getting contribution from individual engineers and large companies that want to kind of tweak and, and kind of get into Kilo. And so I think, you know, first of all, it's a superpower for any open source company. And, and, um, I've really seen the benefits at Kilo.
Um, I think the second is maybe a little bit more philosophical is AI is is like this amazing transformational technology that, you know, I feel like will impact every single human on this planet. Uh, I'm a big believer that that shouldn't be locked behind like walled gardens or gates. And so, like philosophically, Syd, I Kilo we're big believers that, you know, we should be making AI accessible to people.
And so that's a big mission. Um, and then third is, you know, if, if you look at the pace of development of models, um, you know, like I was saying before, it's like I don't want to commit to one or two or three models or, or labs like, you know, you know, Gemini, GPT, um, Opus Minimax, uh, Z DOIs, GLM, like all these great models have come out in that last three months. The pace of innovation is amazing.
And so I, again, our world is, you know, we view that we're work, we're not kind of working towards a, a world of consolidation of fewer models. We're actually working towards a world where you're having lots and lots of models, specialist models, big models, small models, open weight models, um, and we're big believers that we need to be open to all those models. Um, so that kind of, the engineer can have the, the, the kind of freedom to choose the, the best model for the job.
I think a lot of sense. And you know, Scott, I I think that rides a couple of different waves. Number one, no one, it's the anti-lock in model.
Exactly. No one wants, wants to be locked in. Right.
Number two, we are making tremendous strides like every day it seems. Yeah. But when you look at like, you know, we call 'em frontier models when you look at today's frontier models.
Mm-hmm. I think what a lot of us are learning is they're amazing. I mean, think about if I took someone from 1972 and transported them to today, Marty McFly or someone Right?
Yeah. And said, Hey, just like magic. Right?
It would, they would think, yeah, it was God, they, they would've no idea that there's not a real human in there they're talking to Yeah. Who's super smart or something. That being said, though, I think we're also realizing that these LLMs, these frontier models that are trained on the whole of the publicly available internet aren't necessarily the right tool for every job.
And that sometimes we're better off using a tool that's trained on a subset of things or maybe some information that's not publicly available that sits behind a firewall. It's proprietary, but it's perfect for what I'm looking to do right here. And so I think the future is, you'd say there's 500 models, kilo supports right now.
Yeah. There's gonna be an infinite number of models or, or vectors or whatever you want to call them, that a tool has to be able to plug into. And if we have open standards that allow you to plug and unplug right.
Into different models like that, that's, that's what the developer wants, not only the developer. I think that's what everyone wants. That's what every, everyone, every knowledge worker you, I mean, you, you want to just essentially go down the, the supermarket aisle and grab the right model.
And I think, I think what you're saying on a hundred percent aligns with our philosophy is, you know, we saw in 2025, people are trying to keep you in like a, I know a bar refrigerator style selection of like three models when really there's 500. Now there might be 5,000 in a few years and everybody May have their own model Yeah. In a few years.
And your tool should work for you. You shouldn't have to re-platform move to a different development tool every single time you want to use a no new model. It's like asking the finance team to, you know, every year switch from Excel to a new product.
I mean, you know, our philosophy is like, and we have a saying is, you know, models change. Um, great workflows don't. And so that's what we're really focusing on is building a great workflow so that, you know, an engineer can go from conception to architecture to coding, to debugging, to deployment, to kind of monitoring all in one end-to-end platform using the best AI model for the job.
Yeah. I think that's the beauty of the agentic nature of this, right? Which is, look, if I've got a, an intelligent autonomous agent here, it's going to know enough to switch models as I need to.
Right. But, but you wanna make sure it's switching in your interest. And I think that's a philosophy, you know, we're really, you know, doubling down on is, 'cause like what we've seen in the past is some tools when they're optimizing, they're optimizing so they lose less money kind of subsidizing your usage.
And that's what we kind of see in the curses of this world. But like, you should be able to, you should have an application that intelligently optimizes, but you choose kind of the trade offs that it's optimizing for. You know what I mean?
I think, you know best whether you are kind of wanting to, you know, this is an important complex task and I want to the top of the top or, you know, hey, this is kind of pretty basic and, and I'm all game for, for for saving costs. Yeah. And, and I think cost of model and token charges and all that is one aspect, but I think we're rapidly gonna transform to do I want the one size fits all model or do I want the specialist model?
Yep. And, or I mean, I think you might have a one size fits all model that, you know, hits, you know, 60% of your use cases and you augment it by a lot of specialist models. I, I, I don't think it's, and I think that's what you and I are probably saying and agree on, it's like the main theme is you shouldn't have to choose, you know what I mean?
Right. You, you're right. You have all your options in front of you.
Exactly. Okay. I think people get what kilo's about, Scott, let's transition here, pivot a little bit.
Sure. How do people interact with Kilo? Cool.
Uh, yeah. ai, um, you know, register, give us a download. Um, first of all, we got great resources on Kilo.
Uh, we've got, um, a leaderboard that you can track trends. ai, which is, uh, resources for how you learn kind of a agent engineering, but yet get into Kilo, download it, install in your VS code extension or even use App Builder, which is our kind of low-code, no-code kind of vibe coding type interface. Um, and I think the coolest thing about App Builder, and we launched it very recently, so I'm, I'm very excited about it, um, is you've got that low-code, no-code interface, but it's built on that same kilo backend engine.
And so when you say, Hey, I want to, you know, create this app, um, even me as a non-technical user, uh, what is producing is not some throwaway garbage that I can say. Like, Hey, Alan, look at this. And Alan, you're like, that's great.
Let's put into production. Oh no, we gotta start from scratch. No, it's built at great production quality standards.
And so I can essentially share that code base with my colleague who's kind of a full stack engineer who can open it up in VS code and just keep going without having to, to kind of start from scratch. And I, I think like that's the whole vision is, you know, we've got a lot of bone ramps from kind of those professional engineers who can go to vs. Code jet brains, um, or CLI or kind of the, you know, engineers who wanna do it, or the less technical folks who, who want to kind of get into vibe code mode.
And at the end of the day, you'll always be producing something. Great. Fantastic.
Scott. ai. I want to thank you for coming on Techstrong tv.
What a great conversation. As I said, say hello to Sid. I know there's a few other people I know at Kilo too.
Brendas hello as well. Yes, that's who I was. I didn't wanna mention tell him I said hi.
Perfect. Will do. Um, but keep us posted here on Will Do on Kilo Progress, and I hope to see you soon.
Will Do. Thanks Alan. See ya.
All right. ai here on text, on tv. Stay tuned.
We got more. So, as you, you know, made these decisions, you had certain things, you know, and with your view from an architecture perspective, real requirements to drive real network outcomes and performance outcomes, what are some of the things that ended up on your list of things the new network infrastructure must do? What were some of your key issues that you were addressing through your requirements gathering?
First, you know, we were getting also exposed to, uh, um, public cloud, you know mm-hmm. The automation there. We wanted to drive our on-prem, like we do, like in public cloud, you know?
Sure. Uh, make it more, more consistent automated, and also, uh, simpler to, to manage, you know, simpler, to specify what you wanna do and get consistent results. Um, so we wanted on-prem to look like cloud.
Mm-hmm. But we, we ended up with, even on-prem, I think in a be little bit better state than cloud because Wow. We had more control there.
Sure. We had more control there. We were able to, to control the underlying, um, management platform, uh, where we couldn't do it in, in the cloud, really.
Um, so, um, would You, would you call that, was that, was that an objective or was that a happy side effect? We had it as an objective. We didn't achieve it with our first iteration.
Our first iteration was a few years ago with a different platform. Sure. And we, we didn't really achieve that part.
Okay. But with, with our newest platform, it gave us the, the, uh, it, it's op, you know, being open source. Sure.
And with lots of tooling, it enabled us to put around it the, the, the, the solution that will achieve this objective. Sure. Yeah.
You, uh, I know from previous conversations, the ability to use more open source tooling really gave you more options and gave you more ability to customize. Yes. And, and you, I mean, what we did, I mean, we did a lot of innovative work, really.
And, and we started as a, we were a small team. We were maybe three or four engineers at the beginning. Wow.
And when we started, we really didn't know any of this modern networking techniques, but having an open source tool, you know, then you can, you can put somewhere, you know, you can look on the internet really, or you know, other people would have faced what you are facing. It might be it not be not related to networking, it might be related to something else, but having an open source tool that people have, have, have touched this open source, which is Kubernetes, where our tool is based on Kubernetes, and, you know, millions of people are using Kubernetes and they've built tools that enable it to communicate with this Kubernetes cluster and do interesting things that we have used in our solution. Got it.
I don't want to, um, under count, you know, the, the, the global scope of the network you had. It wasn't just like one data center, pair of data centers. Talk, talk a little more about global topology and, uh, what data center resources you had to bring all in line together.
Okay. So, um, I mean, we've got data centers in all content. Um, Europe, u us, Asia, uh, they're very complex data centers.
They're due dual data centers. And, um, got applica, you know, one is active standby of, of the other. Um, it started with a very flat, flat architecture.
You know, we've inherited a flat architecture and we continued thinking flat, but then we made it to much more interesting, uh, modular architecture mm-hmm. You know, of the data centers where we can add remote data centers together. And we wanted, you know, uh, uh, this flexible architecture, but we wanted a tool that will understand this flexibility Sure.
And enable us to have this modular flexible architecture. So, um, that is, that is what we had in the architecture side. And when you say dual data centers, you mean dual data centers in each geographic location?
Like, you know, like within Yes, we have, it's a dual geo-redundant data center. Yeah. So, so they are, they are in the same region, but, uh, geographically apart to back up each other in case of a disaster, Separate power, um, volcanoes, Et cetera.
Yes, yes, Yes. Not to imply that anything is actually in Iceland, um, but, uh, I know people have had routers taken out in Iceland because of lava. But anyway, Hey everyone, welcome to this future room executive interview series.
We're going inside the AI infrastructure revolution, and today I'm joined by Mohamed Awad from Arm to get the arm perspective. Mohamed, welcome. Great to have you on.
Thanks For having me. Great to be here. Yeah.
So I wanna start off, let's hit the AI inflection, you know, every day, literally every day it feels like there's news massive investments, whether it's more compute, more energy, uh, you know, more mo new models coming out and the leapfrogging effect. Like, you know, I'd like to get your perspective, like what is defining this moment in the compute revolution, and how do you see arms role broadly in that landscape? Yeah, totally.
I mean, I think, I mean, I think the easiest, the easiest way to describe, it's just transformational. I mean, I mean, things are just changing so quickly. The potential is just massive, you know, and we're really kind of shifting gears in a big way in terms of what compute is and how it works, how energy efficient it can be, and sort of the value that it can provide.
I think, you know, the, the world kind of sees that potential. It sees it on the horizon. We're, we're, we're not there yet.
We're kind of early innings. And it's, a lot of it is about, you know, how do we achieve that potential and sort of transform, you know, everything from the, the devices we carry around through to the infrastructure and the, the cloud that, that, uh, that makes it happen. So it's a pretty wild time.
It really is. And, and I speak to so many enterprises every day, and while a lot of us have been really focused on LLMs and how we're using them, and the shift in how we search, I think we're in the very earliest innings. I said something the other day, I said, we're about 1% of the way in to ai.
And while people think it's farther along, it is not. Yeah, we're just getting started. But, you know, in terms of like, in the hyperscaler space, like, you know, in your business, right?
We've seen AWS we're seeing Google, you know, Axion, we're seeing Microsoft, we're seeing, you know, of course Nvidia the grace in, you know, in GB and GH and all those different things. Yeah. Um, it's all on, you know, I think people would love to understand, you know, 'cause we're tracking this very closely too, but the hyperscalers have clearly moved a lot of, a lot of their commitment to arm.
What's, uh, kinda what's driving that? What's the technical reason behind that shift? Yeah, it's, it is, um, you know, we've seen tremendous, tremendous, uh, adoption.
We've seen a lot of, a lot of momentum as of as of recent. And really a couple, a couple of things. I mean, at, at its core, it's about this idea that we enable a level of, you know, flexibility and innovation, uh, while still being able to take advantage of an ecosystem.
So if you think about how data centers were built in the past, you take some off the shelf compute and you would, you know, build up, everybody knows the story about Google, right? Built in the, in the, uh, in the Stanford dorm room. And, you know, they just kind of cobbled together off the shelf hardware, and it was like, let software figure it out.
We're well past that now. The sort of performance demands, the efficiency demands you need, uh, you need these systems built from the ground up and optimized for, uh, for your particular use case. And so, and that, and that's to get the level of efficiency and get the level of performance out there.
And so what you're seeing all these guys, whether it's, you know, whether it's AWS whether it's uh, Google, whether it's Microsoft, whether it's Nvidia, you know, all of them, they're building their own general purpose compute. They're building their own acceleration, they're building their own networking. And arms get a role to play in all of that.
And, and, you know, I think that's really kind of helping, uh, you know, propel us forward, right? Yeah, it's been a great, it's been great to watch the Rise, you know, more competition puts, uh, you know, made the X 86 folks put some effort in to improve what they're doing. I think competition is good.
We always say that, you know, it creates efficiency in the market. It creates, and of course, the TAM is rapidly expanding. A lot of people always wanna do this zero something.
It's like, oh, if they get it, that means everything's lost. It's like accelerated compute market's massive. In fact, you know, I know you probably can't say anything, but I keep saying, I think arm's gonna have a bigger role to play there too, um, pretty soon.
So, um, really quickly though, I think we've seen numbers like at AWS like about 50% now of the, the workloads are now running on arm, you know, we definitely measure market share, kind of where do you see your market share sitting right now? Yeah, so AWS actually just at this past reinvent, and at the reinvent before talked about this past reinvent. They talked about how in the last three years, more than 50% of the compute they deployed was ARM-based.
And it, and it's interesting because, you know, these are guys who are clearly, uh, uh, you know, in front in terms of general purpose compute and what they've done around custom silicon. But if you look more broadly at what's happening with the transition to ai, you know, a lot of these systems that are being deployed are being deployed as full rack solutions. And those racks, those systems, you know, come with a general purpose compute, they come with a, uh, accelerator, and it's all kind of, kind of built together.
So if you're, if you're deploying in NVL 72, if you're deploying Agra, Grace Blackwell of Vera Rubin, um, you know, if you're deploying your own TPU with a head node or you're deploying your own accelerator, you know, the likelihood that that's arm sitting alongside it is actually pretty high. In addition to that, when you start to think about the networking side, whether it's things like Nitro or you know, Bluefield or otherwise, those are all ARM-based CPUs that are driving those. And at the end of the day, those are actually offloading what historically was considered general purpose compute.
So you've got a lot of compute happening there. Um, so, you know, I, we, uh, we talked about at the beginning of this year how we believe that about 50% of the compute that's gonna be deployed at the top, uh, hyperscalers will be arm based this year. Um, you know, and we continue to believe that that's gonna be the case.
Yeah. So, so quickly, you know, in terms of, you know, as your data center presence continues to grow, I'm glad you mentioned the networking, because that's another huge opportunity. We see networking as one of those big, like, I think we were obsessed that compute was the constraint, but now we're seeing networking and memory and storage and everything kind of down the silicon supply chain.
Of course, energy's a whole nother topic. So arm's always been very focused on energy efficiency, which is a, a value there too. But like, what do you see as the big technical eco market related challenges that are gonna, you know, be critical, uh, going forward for the data center?
Yeah, This is an AL'S law game, so you're gonna, you're gonna, you know, accel, you know, your accelerators are gonna get better than, you gotta worry about your networking to connect them. And then you gotta worry about your general purpose compute to supply them. I mean, at the end of the day, what we're seeing right now, where there are a couple of main challenges, first and foremost is power.
If you think about the sort of scale of what we're trying to accomplish, the amount of power required in order to do that is really beyond what the grid can handle. And so there's real, a couple ways to deal with that. You increase performance per watt, that's the number one game.
So I think that's gonna be a big thing, and the sort of race to better and better performance for lower and lower power. The second is, you know, availability of silicon. When you think about, um, you know, the, the, the supply chain, when you think about the cost of building the silicon, the time it takes, and then the sort of capacity available, that's gonna continue to be a bottleneck.
So we gotta, again, look for ways to, to further kind of dry that out. And advanced packaging technologies, et cetera, are gonna help with that. But we gotta bring more capacity online.
I mean, I think at the end of the day, um, you know, there isn't gonna be one particular issue. I think there's a bunch of issues, and this is really gonna be an ecosystem wide effort to kind of, you know, uh, you know, squash those issues as they, as they pop up. It's a, it's a classic on law problem.
Yeah. And I think the market's, a lot of the market is, is grossly underestimating the proliferation, how fast AI's gonna find its way, like I said, I keep using enterprise, but then even like edge and physical. So let's talk about that for a minute.
Like, that's a lot of the, you know, the genesis of of ARM was always, you know, small, low powered, uh, you know, whether it was mobile devices, but of course you have a business in automotive, you have a business in iot, you have a business in, you know, basically all these things. And I think it's a multi-trillion dollar tam sitting out there for that, those markets, you know, talk a little bit about, you know, where's arms edge and, and, you know, strategy going. Yeah, I mean, it's, it's, uh, it's ama I mean, you know, uh, it, it's amazing the sort of potential that we see in the edge and kind of how quickly those devices are adopting ai.
You know, uh, obviously, you know, we've got about 99% market share in the mobile phone space. We've got an incredible pre presence in areas around physical ai, whether that's things like robotics or automotive or otherwise. Um, you know, you look at, uh, mobile, um, you look at like, uh, laptop and PC based platforms, which are now going arm based because they're looking, starting to look more and more like, um, you know, they're starting to look more and more like mobile phones.
In fact, you know, something like 90% of the apps that are are, that are, uh, run on those devices are actually, um, natively written for ARM already. And so, you know, underlying all of that is when folks look to go take those devices and then expand them, add that AI capability as it becomes infused, leveraging that same software ecosystem, leveraging that same platform that is, you know, they've, they've come to, uh, to build this massive, uh, software base on those devices. But then also that is being used in the cloud, leveraging that same software across both of those places.
We're seeing that as a massive tailwind for us. In fact, you know, we think that the Edge can is gonna be an incredible opportunity for us moving forward. And we're already capturing on it on things like our Lumex platform that we just, uh, that we just launched.
Yeah. We expect that to be a really big growth opportunity. We've been obsessing with data Center for some time, but I think what happens outside the data center is gonna be a, a long, you know, across the next 10 years, it's gonna play a massive role in terms of expanding tam, expanding market opportunity, and of course bringing AI into our everyday lives.
So the devices, you know, the last few years it's been all about data center, but I don't think that's gonna stay for the long term. Um, you know, one of the things about ARM that's really interesting is your business model has evolved a lot, was really, you know, a royalty licensing focus. You've gotten more into custom that senior margins grow a little bit.
But just for those out there that are kind of like trying to understand how ARM makes money, how it, you know, goes to market, give us your sort of, the way you explain it, you know, how do you talk about it when you're at the, uh, at the family dinner table and you get past It? Yeah, I mean, I think the way to think about it is we enable innovation and we enable a, an ecosystem that, um, that, that comes together to build amazing products based on whatever the requirements are. Some cases that means ip, some cases that means compute subsystems.
In some cases that means you, you work with one of our partners to get something like a triplet or even a full on SOC. And I think the, the, the thing that really separates us from, from, uh, from other companies is our ability to meet you at whatever integration point makes the most sense for you based on the problem you're trying to solve. So when a world that's advancing very rapidly, you're trying to adapt new technologies into it, you're trying to fight for performance per watt off the shelf isn't good enough, you choose which integration point you want and arm, arm and more broadly, the arm ecosystem is there to kind of make it happen.
Yeah. Yeah, that's a good way to explain it. I think, uh, you avoided the, the trap I put you in of actually trying to break down the how, the, how the different royalty and licensing and subsystem buckets.
But I have, uh, it's been good to see you find ways to expand margin by adding more value. 'cause you obviously, as the company continues to be a critical provider of IP to many of the technologies we use every day, how you evaluate that, it's hard when it's only based on unit volume and you know, when you can get a little more out per unit. It's a, it's a good way to increase the, the, you know, the business's value.
Um, as we wrap up here, you know, you heard me allude to, you know, performance per wat leadership or low power. That's always been a big part of the ethos. Um, you know, what are the other advantages that, you know, you think that really are the big reinforcement points for arm's?
You know, unique value proposition? I mean, I think number one, it's ecosystem. When you look at arm, you know, our ecosystem is second to nut.
And so this idea that you can, you know, you know that it's not just arm, but it's an entire ecosystem standing beside you ready to help you realize whatever your potential is, uh, you know, and whatever the, the problem is that you're trying to solve, I think that is probably, um, one of, one of the greatest values beyond the sort of performance per watt and just the, the technical chops that we've got. And I think that's so important in an environment like, uh, you know, today where, you know, things are changing so rapidly, whether that's software ecosystem, whether it's our hardware ecosystem, whether it's partners in our arm, total design program, you know, we've got this massive, um, you know, uh, ecosystem ready to kind of support you. That's very different, by the way, than other architectures.
You know, other architectures either have a strong ecosystem, whether they'll give you an off the shelf solution and maybe have good software, but you kind of get what you get, or you've got incredible flexibility, but you don't have that ecosystem there to support you. You kind of bring the best of the, those two worlds together. And that's really what sets Us apart.
Mohamed Awad, I wanna thank you so much for joining me on this Futurum executive interview series. It's great to get a little more insight as to what's going on at arm. We're watching you closely.
You can be sure of that. Uh, congratulations on all the progress so far, and let's, uh, catch up again soon. Thank you.
It was great talking to you. Hey guys, thanks for the throw. We're here with Amit Jeps, who's head of product marketing for PS Kognito.
And we're having a little chat about well attack surface management 'cause things are getting a little bit outta control. Emmett, welcome to the show. Yeah, I think getting out of control is, is the right context for, uh, for attack surface management.
Um, and think before we'll start, regardless of attack surface management, I think what we can see is that security teams are still being the same, on the same size. Whether being become smaller or staying in the same size budget are becoming much tighter, and the risk is being bigger. And I want, I would like to say attack surface is here for the sq, but, um, I think we can see definitely a lean on from organization towards attack surface management towards attack, external attack surface management, um, as a mean to reduce the noise, to make that vulnerability management something which is more cohesive and something they can walk with.
And instead of chasing vulnerabilities, actually addressing real risk, it seems like we're dealing with two sets of challenges, and one we're kind of aware of in that the number of platforms that we use and the number of things that we need to secure has increased as we've become more distributed with our applications. And there's more stuff running at the network edge than ever. And at the same time now there's this AI component where we're starting to see agents that are essentially a new type of end user that also needs to be secured.
And so the number of, shall we say, uh, people, whether they're AI agents or actual humans that need to be defended is also exponentially increasing. So from your perspective, yeah, it seems like if I'm the cybersecurity person, the game is a little rigged right now and not in my favor. So how do you see this all playing out and, you know, is there some way to think about managing all of this?
Um, let's start with the first question and then I'll move to, to the ai, the elephant in the womb. So yes, organization become, became much more complex, uh, whether it's, um, many tools, as you said, to secure many things, many domains, many technologies, um, whether it's the size of the organization, if in the past we had, you know, a small office with a data state data center, somewhere, now we have organizations spread across the, the globe and security teams first struggle with visibility, with actually trying to get everything together, uh, whether it's see what mines and actually try to get somehow a unified picture of all the tools that I'm using. So I think the first step that we are seeing is integrations, whether integrating your inventory system to your ticketing system, to your EASN, to, to the exposure systems to create some kind of holistic view.
So in the end of the day, you will be able actually to connect the dots not running after, you know, whether it's a vulnerability or, um, patch in your IT or something which happens somewhere you can actually connect, integrate all of your systems. And now I think you are much in control, which also says, um, sometimes when dealing with, um, incidents or vulnerabilities. So this is for the first, for the complexity.
Now let's talk about the elephant. Um, so AI brings, um, let's say two dimensions to cyber security, as, as I like to play with that. Um, one is ai, what AI is doing for the practitioners.
And the second one is how to secure ai. So both sides of the equations now in terms of securing ai, your tax surface is being now expanded. So you have, I'll say, new toys you need to play with, but you need to secure them.
And I think, uh, you and I in this business long enough to hear, uh, Cisco's complaints about the cloud and marketing team spends a new application, uh, for their new, uh, um, for the new campaign. And the security cannot control the velocity of the cloud. And I think we are going to see it here as well.
Um, whether you expose an NCP or um, an agent, as you said, you need the tools to identify it. Security must keep up with the pace of ai. This is on one hand, so you need the tool.
You need to again, have that AI mindset on your attack surface on the underway round, uh, which is the good stuff is the what AI can do for you. And now, um, I'll call it you have a new assistant, Neil, you, we can actually help you and take a lot of your work. Um, same has happens for instance, in r and d today, or with developers that we see, uh, ai, I don't wanna say replacing, um, developers, but taking some of the, um, tasks of the, so to say, senior, uh, developers and make their life much easier.
So you can see, and we can see products today that can investigate, um, incidents. So there are some kind of a junior analyst that sit near you and do and collect the data and make the, so to say, initial, uh, trash, uh, and actually give the, the analyst initial, uh, findings of the incident or whatever he's investigating. AI can actually process data at scale.
So if, if, let's say two years, I mean, it's not that long, but you needed actually to take ev all that data, all that logs all this information and process it. Now, AI will do it very fast for you. And of course it's being, it's, it's being done in your language.
So I think in one way, AI made a little complications to securities and the other way around it's also helped them a lot to deal with these complications. And with the rest of the complexity, I think there's a, a, a third element to this is, is the bad guys are using AI as well. And so it seems like they are discovering and creating exploits for vulnerabilities faster than ever and then launching them at higher levels of scale.
And if that's the case, then, um, you know, is this whole thing moving to something that is, uh, attack and respond is now in real time and it, it is occurring faster than humans can keep track of it. So is the whole nature of the game changing? I agree.
And I think, um, if you look at the hacking methods, I mean, I, I, to be honest, I did a small course. I'm not pretending to be of ethical hacking. So just to understand what is go, what was going over them.
And I think the methods of hacking are now once, once they are being replaced by an agent or, or, um, ai as you said, it actually made every, makes everything more challenging. However, that means that you need to maintain your attack surface much tighter. So you need to identify risks much sooner and then you will be able to prevent these attacks.
Because again, in order to initiate ai, uh, and attack AI is the orchestration tools is the means to the end. At the end of the day, if you will maintain your attack surface, identify, um, identify where you are exposed, where are the exploitable issues, um, then you can prevent, I don't wanna say 100% of these attacks, but you can prevent many of the attacks by being aware to that attack view and then prevent it from happening. So what's your best advice then, the security teams as we kinda look at all this stuff?
'cause it could be, frankly, it's a little overwhelming. And how do they wrap their heads around all this? Because, you know, there's a tendency where, you know, if you think too hard about it, maybe you just wanna run home and scream, but what am I supposed to do?
In one of the webinars that I made in the past, someone um, brought me a, a question, how do I prioritize vulnerabilities where everything is critical? So it is, it is a situation. Um, but I think, and this is where you start off exposure, attack, surface management, um, so external, so taking that attacker view, I think most, I don't, I wanna say most or some, or we see a situation where security teams are currently handing vulnerabilities because of, I don't know, historical reasons, because this is the way that they're working.
And we see also a change in the market where security teams, our customers are taking the attacker view in order to prioritize, in order to understand, um, the essence of these vulnerabilities. So it's being done in two ways. First, uh, are they are reachable from the outside?
Can I, can I see that vulnerability as an attacker outside of modernization? And second, we are also validating the risk. So we are doing it safely, um, without any risk to the business.
So now I have validated risk and I know that it can reach, it's, it's reachable outside of the organization. And now I think we are on the discussion of, from my a hundred, 100% vulnerabilities, I can actually prioritize based on the risk and not based on the number of vulnerabilities. So this actually changed the equation and it's changed the way that security teams operates.
We see that security teams starts to breathe now when they can actually deal or handle the risk rather than, you know, vulnerabilities. So it, it, it's, it's a different story. Um, as we kinda look at all of this stuff, how do I as the security person have this conversation with the business because, um, you know, a lot of times business people are thinking, well, you know, we just spent a boatload of money on security and now you're back telling me we need to spend more because why?
And they're kind of like, you know, saying, why should we increase the percentage of money spent on security? And they're a little dubious 'cause they don't see these threads per se until, well, it hits 'em in the head with an attack. But, um, is that what I gotta wait for or is some sort of catastrophic event before I can get this business people that wrap their heads around this or is there a way to talk to them?
There is always a way to talk to them always. And um, it's funny that you're saying saying that because I think security is always me. There is always that dance between security and business implication, business case and all that stuff.
Um, you cannot come to a person and say, we are exposed or something and expect that he will invest money. However, um, one of the triggers, uh, for security, for security projects is of course compliance. Um, and we can see, I don't wanna say shift, but we can see requirements, um, appearing in, for instance, a MIS two in Europe that actually requires for external monitoring.
So they want to understand if you, uh, if you have, um, assets which are exposed to the internet, uh, your vulnerabilities are, um, reachable from the outside. And I think once you have in the compliance discussion, it's a pure business discussion. So you need to comply with in order to do business.
Um, so this is 1, 1 1 use case. Um, the other use case I think is to show, To move to risk efficient to to, I mean you need to, to discuss in business metrics you need to understand to show the business impact. Um, and in some case what we are doing is we are bringing the business implication of, of issues or findings, I wanna say vulnerabilities because sometimes it's an S3 bucket exposed to the, to exposed to the internet.
So it's, it's not a vulnerability, but it's definitely something you need to, to deal with now. But in many cases, you want to show the business implication. You wanna show, okay, if this server, this application will be hit, will be breached, then what it'll do to our business, that means that one hour our customers will not get any service.
I think this is something that management and business people can understand and in some cases translate it into money. Um, and once you are translating cyber risk into business risk, then I think it meets, um, otherwise you are right, it's a different languages. Mm-hmm.
Um, to your point, are we also therefore moving towards, um, some sort of ability to continuously monitor those environments and activity and we need to, uh, have that level of visibility And so, and, and how do we gain that? And um, 'cause I think, um, people have been talking about this theoretically for a long time and very few have accomplished it. So is it getting any easier to, um, continuously monitor an IT environment with an eye towards preventing something bad from happening?
Is it's getting easier? No. Uh, um, I think, um, complexity is there and, and I think, um, the attacker always like the attackers always like the bigger organization because it's more prestigious is because, you know, uh, it'll get to the news faster.
Um, what we can see and what we in psycho nito is doing is actually trying to imitate the attacker or take the attacker point of view when we are doing the discovery, the, so to say external, it's not inventory, it's actually discovery and actually showing where you are, where you are exposed. And there are two levels. So one is understanding the organizational structure.
We are actually mapping the business organization. And from that point, you, you are going to the technical aspects of physical assets in terms of web apps or IP addresses. So it's not, we are, I mean this is the outside in approach.
So basically looking at the organization the same as the attacker would do. So that provides the visibility, um, that, that match the attackers. So, um, you can actually be certain or be sure that you are actually playing, um, with the right tools against the attackers.
Now once you have that, you can, uh, understand all the elements, all the, I don't wanna say chain of events, but uh, you can understand the vulnerability that he sees, you can understand where he can breach, what he can do, and then you can map it into attack path analysis, uh, and all that stuff. And I think this is where we're leaning back into the inside systems in where we're integrating in combining all this data, as I said before. So you have that full visibility from the outside connected with the internal systems.
I think people kinda are starting to understand that. And you gotta think like your enemy essentially. But one of the things that I do hear from folks is they go down this path is they wind up collecting a massive amount of data and then they don't know what to do with all that data and they can't afford to store it all and they can't figure out what data to keep and what to toss.
'cause there's just, you know, everything is instrumented and it gets overwhelming. So how do I kind of think about security on a certain level has always been a data management problem, but how do I manage the data? I think one of the asked question that we've been asked as well is if I will bring Sonito as an exposure system, external exposure, uh, would it increase the noise?
So am I bringing and yet another solution that will make yet another noise? And the answer is no, um, is no because of two things. Um, we're not replacing real complementing.
So in the end of the day, I wouldn't say that I can give you the internal inventory as, as any other, uh, player in this market. But what I can do is that I can provide my insights to the internal, for instance, we're integrating with armies, with axon use. And what we do provide is, for instance, that holistic view.
So you, you will have that visibility of all the assets of all the external assets and once you are connected it with armies for instance, you can actually create an end-to-end attack path so you can know which of your crown jewels is so to say threatened by attack path, which is can be exper can be initiated from the outside. And I think this is where the noise is actually, um, being diminished. So now instead of 1000 findings, you can focus on that 10, 15 findings that actually show you this attack pass.
All right, well folks you heard in here, Hey, if you can't see what it is you're supposed to defend, I think you're at a serious disadvantage in the first place. So, um, maybe the first step is just understanding what that environment is and then figuring out, well, if you were gonna attack it, how would you do it? 'cause the bad guys are probably doing that as already as we speak or as one wag one said to me, if you can imagine it, somebody's trying it.
Hey Amit, thanks for being on the show. Thank you very much for having me. All right, and back to you guys in the studio Control.
This is agent dev. I'm in position. Copy that dev.
Stand by for go standing by. Hi everybody, thank you for joining us for the first episode of Agents of Dev, our new podcast. My name is Mitch Ashley and I lead the, uh, software lifecycle engineering practice at Futurum, also a product lead CTO product developer kind of in my background, which is a lot of what we're gonna talk about.
And I'm joined by my colleague and, and good Fred, uh, Brad Shiman. Brad, introduce yourself. Thanks, Mitch.
Hi everybody. Uh, so Brad Shiman, I lead our data intelligence, analytics and infrastructure practice here. And, uh, like Mitch, I have a history and fondness for all things development oriented.
And so the two of us are, are very glad, uh, to, to be working together on this. To to talk a little bit about, uh, where we think the, the software development marketplace is going in the enterprise. And uh, you know, I think we have a great venue for that for this, this week?
For that this week. Uh, because we're both in, uh, Las Vegas visiting, uh, AWS, which is putting on its annual, uh, reinvent show, which is somewhat sizable. Yeah, Mitch.
It is. It is. And then, yes, we're working from our hotel rooms.
We don't have similar artwork in our homes. They have the same, no, yes. We're both, uh, different locations in the wind.
It's, so, just a little bit about this podcast, I wanna say just, um, since this is episode one, og, right? What we're about, um, I, I've always wanted to do a more in depth, both as an analyst, but also as a practitioner, career long practitioner of someone who's either done software, database work, network work, security work, um, all of it together to, to create software release products, that kind of thing. The stuff that you and I have in our backgrounds and respective differences in our backgrounds.
But also look, but look at it from an analyst perspective, not just pontificate about it, but pontificate with some, maybe some informed background. If I can be so bold, not that other analysts don't do that too, I don't mean to discourage anyone, but you know what I mean, we're practitioners. We like to talk about the craft of what we're covering and the pain as well.
Oh, my God. And the pain. Yes.
And then, and AI doesn't lessen pain. There are some new pains, I think so I, you know, I think Brad and I have, we, we both like to have fun, so you'll hear us joking around and hopefully some levity will make this even more interesting. Um, talk a little bit about your software background, just like to hear a little bit about it, Brad, so folks know where you're coming from.
Oh, sure. Yeah. So, um, back in the day, which was for me, um, 1990, uh, when I was just, you know, getting a, into working as a, an adult, not as a teenager, but as an adult.
Um, and, uh, I got a job, uh, as a, an admin for a Novell network, uh, network. And, uh, that was painful. Speaking of, if you've ever thought about doing, uh, an upgrade of a system that had over 50, uh, floppy disks, there's your answer X protocol in the background there going on.
Indeed, indeed. No. Yeah.
And in LMS were my friends. Um, still, I still dream about them, but, you know, in that era it was, it was, um, you know, heady times. I, I was trying to teach myself DB two and got involved with, you know, uh, sort of interesting, uh, what would I call this, uh, sort of development paradigms like, uh, Fox Pro, uh, which was, yeah, basically a tool set and an approach to building databases.
And I was hooked, just absolutely hooked. Loved, loved them very much. And, uh, ever since then have been working, um, as I, I actually started working in our, in, uh, this, uh, Atlanta Times Magazine, uh, doing competitive reviews, um, switching reviews, networking reviews, as well as server and software reviews.
And I always raised my hand whenever we had the chance to do anything with software and software development, because it's just al always fascinated me. And so I, I did that for a while. Um, did, uh, some, some work, uh, as an actual, um, uh, in it itself as a business analyst and developer when I was working at, uh, a company called McGraw Hill and CMP and whatever else they were called at the time, publishing houses.
And, uh, for example, we had, uh, an interesting, uh, project where we wanted to take, uh, the databases that people, uh, that we built for each magazine and converge them into one harmonious database. And these, these databases were all the, you know, the cards that people used to fill out back in the days for these massive, you know, and I mean, massive, like the, the page size was about this big. You mean the cards that I made up all the answers on those cards?
Exactly right. Yes, right. Surprisingly, it was, there was a data quality problem involved in that project.
Contribute to that. Yeah. Just, you know, so, uh, I, I've been involved in that for forever.
And, uh, as an industry analyst, um, was on board of, uh, the ai, um, train pretty early and got involved as a practitioner there and, and in doing data science and, um, have, you know, since we entered the ag agentic era, been been working on several projects, uh, that we're, we're doing actually internally here at futurum, uh, making use of some of the new toys that, that we have in the industry right now. Yeah. You undersell yourself on that part of it.
Brad's been leading the development of our signal, uh, project, the signal report, which is all AI create the structured and created sort of the fabric behind it of taking the input from the analyst and creating, creating the structure of what the analysis looks like and sources and kind of directing it, that Brad's done all the work on building it. You've done a fantastic job. I admire what you did on that.
So, nice work, Mike. Thanks, man. Uh, just real quick, kind of where I'm coming from, I've, I've, in my own way, similar kind of path.
I started out a decade earlier than you did in the finance industry doing banking systems, actually rebuilding, modernizing, I guess you would call it now, from one vendor to another, moving, uh, software into IBM mainframes, but I also got into the PC era in college, so was very invested in that and actually ended up getting into database pretty quick. Uh, first IMS and mainframe stuff, and then DB two and ingress and later, uh, Postgres and things like that. Interestingly enough, about six years into my career, I got into AI and was doing a lot of lisp and prologue work.
Cool. I use a lot of these days. But that's what we thought of as, you know, those were, those were the symbolic languages, right.
For, for ai. And actually did some teaching around that stuff. And Well, li Lis is God's language.
It's, you know, isa, everything's about an isa. That's right. Yeah.
So kinda had early hand on that. We thought, you know, AI was just around the corner then, but, uh, not quite. So anyway, long, long story short, got got, went through the SER client server era, went, moved into the, you know, the dotcom bomb era, but also moving into the cloud.
Um, so I was a DBA data architect for a while. I was a system architect developer for a while, and I got into networking kind of by accident in a consulting company that I started, and that got me into security. Ended up doing this, a couple security companies in the early two thousands, sold to the DOD and to corporate enterprises, and, uh, did pretty well in that era.
So I ended up working in security for the last 20 plus years. But anyway, after that, still kept going on and moved into the next era of the cloud and DevOps and things like that, leading product development teams, just so a little bit of hand in development and then started an analyst firm that eventually got bought and then sold again to what's now Futurum. So that's how Brett and I came to work together.
So we both come to this as with prac, strong practitioner background, but also analytic thinking about what we're doing and why we're doing it this way and kind of under wanting to understand it better. And I think that's a lot of what I'm guessing. Similarly, why is this about why is analyst work industry Yeah.
The, uh, the insatiable curiosity is, is a problem, uh, well, you know, within the analyst community. And, uh, it, it does keep us up at nights thinking about, you know, well, wait a minute, think so and so said such and such about this new technology. How does that work?
Exactly? What does that do you say that because there's one, there's one word that's a question and a statement. Whenever I hear something said by someone, especially, you know, because I've been on the vendor side too, when they tell me, this is what we're doing, or we're announcing this, it's either really, which is a statement or really, which is a question really, you know, what I wanna know more.
Right. Exclamation point, followed by a question mark or question mark, followed by an exclamation point or multiple of either, you know, so it's, it's, you know, it's that natural curiosity we have. So let's, let's turn to kind of, we wanna talk about as practical things as, as analysts are gonna talk about, but, you know, kind of dig into the more of the details of what's going on.
We're here at Reinvent. We've had some pre briefings, but frankly we're at before the main keynotes have been kicked off, so we're off. We've had, you know, we've had the preview, we have what they have told us as much as we can digest in that shorter period of time.
Do you wanna kick off on some initial thoughts about what we've heard and what that's saying about teeing up where we're headed into 2026? And then I'll chime in and give my perspective. Yeah, yeah.
So, um, as, as Mitch said, we, uh, actually just a couple of hours ago sat down with, uh, AWS to hear a sort of roundup of where they were heading this week and all of the announcements that we would hear about, uh, for everyone who's, you know, following here or at home. And, um, you know, as you, as you might think, trying to cram all of that into just a couple of hours, not easy or even possible. Um, and so there, there's a lot that they really glossed over, but I think sometimes when you a vendor does that, they actually tell you a lot because what they omit and what they elevate is always, you know, important because that tells you where the investment is going within the company, what they care about the most.
And, and it was, it was interesting to hear, you know, some very familiar refrains from them that we've had for long time. Things like, you know, we're, we're all about working backwards from the, you know, the customer to the problem. And, uh, so that they build software that's built for their customers.
And AWS has always been very good at that, is most vendors I think really try to do it. But, um, what I liked, what I, what I heard, which was a little bit different this year, was they have a focus on what they're, they're calling freedom to reinvent. Um, and that is a, a key go-to-market message for them this year.
And I, I think that what they told, told us about says, does reflect that in some ways, because I just, you know, normally I would say it doesn't, but I do think that AWS um, what they're saying actually is, is very much in line with their go-to market. Um, and lemme give you an example. So, um, they, they talk about how, uh, they think there were going to have a world in which there are billions of AI agents running around, and they, as, as sort of proof of that, they said, well, we're hearing this from our customers, and we're seeing what our partners are building and what, and what we are building AWS internally.
And we see that there, there is a tremendous amount of work being done right now, uh, to build out a, a large swath of agents. And when you build out a large swath of agents, you have to, what, what manage them make might be a good, good thing to do. Orchestrate, that's the word, right?
Yes. Manage, orchestrate. Yes.
Yeah. Right. There are frameworks built specifically to do that with agents.
And, um, that whole idea of freedom to reinvent, you know, what, what, what, the thing that constrains enterprises from really, you know, doing anything is, you know, inertia and technical debts and budget. You know, if you don't have those things, you're, you're gonna have a hard time making headway on new projects and old problems. And so, um, the things that they were telling us during this roundup of what they were working on, I think really kind of speak to that desire that AWS has to help their customers get to those billion of agents, billions of agents, uh, and to do so using, you know, the existing platform they have, like, they have their bedrock platform and they have a, not new, but a, a greatly enhanced, um, orchestration layer that they lovingly refer to as Agent Core.
Um, which does remind Mitch and I both of, uh, a musical movement that involves punk rock, um, that, uh, that's a story perhaps for another day. Uh, I kind of remember that some of those brain cells are still here. But yes, those are, those are, those are heady times.
And, and, uh, if, if you, if you think about what, you know, what they're trying to to get at here is, is being able to, you know, build out very complex systems that involve a large number of semi-autonomous or fully autonomous, um, workloads. And that's not something the enterprise is used to doing. So it's, it's very different.
So I hear when they say freedom to reinvent, and I, I say, okay, we're, we're, we AWS are trying to give our customers the enterprises the tools that they can use to reinvent themselves in this agentic era that we're existing in. What was your, what was your key takeaway from that opening salvo? Definitely agree with your take on things that those thematically, especially, that's what they're, they were building around.
You know, I think it's hard for AWS because I count the number, there's always 800 to a thousand announcement at a reinvent. They're just no doubt, how do you thematically pull that together? But, so you have to look at, so what are the big things that they're talking about?
And you mentioned Agent Core, they have something that they've introduced with that, but also part is the of their kero, I-D-A-I-I-D, which clearly is now becoming sort of the, the working console for development. Think of it as not just an IDE, but they have a spec driven mantra or philosophy about how Keo works rather than just task or prompt, you know, uh, generator, prompt driven kind of development and something that's a little more structured. And I think that's one of the things for us to kind of figure out too.
Sorry, my computer's dinging at me, um, which means our 10 minute bell just, yeah, I guess. Sorry, everyone. Oh, behind the scenes there.
Um, so anyway, jumping into it, they're talking about something called, um, basically frontier agents. Now this is a bit of a mm-hmm. Washing of the frontier, not frontier.
Sorry. Sorry. I just heard your stomach grumble there, Brad.
Yeah, that, that, that, those, those were my eyes rolling back in my head is what you might have heard them hitting the back of your head and rolling back. Yes. So, you know, now Frontier won't mean as much, you know, sort of like agent means everything or whatever, you know, but, so it's gonna get washed too, but that's, it's bound to happen.
Anything that's good will get adopted. Yep, exactly That. So that, but the real, the, the essence of it is, is I, as I understand, and we'll hear more about it as the week goes on, it's really about agents who are more truly agent, meaning they're running on their own.
They don't require as much hu human interaction direction to keep them going on track, keeping on track to accomplish a task. They can be long running. They can be not just hours but days, maybe multiple days going across models using the tools that they have, uh, for them to use.
But I think the idea with the Frontier branding is signaling going to the next step to the kind of work that agents can do on behalf of whatever, uh, what are those tasks are. And then they folded those into a set of kind of predefined agents that they're offering. Um, one of them was a security agent.
Yeah. That was fascinating. Yes, of course.
In Fernando, our, one of our peers. And his first question is the ab, but do I trust it? You know, the farther you write, you go in this software development lifecycle, hire the trust, you know, has to be, because those are the folks that live with it when it breaks, you know, do, do you find, do you find it interesting man, that, um, you know, we, we talk about trust and talk about opacity and wanting transparency and understanding, and yet as an industry, and especially for software development, you know, have we not at every possible moment, uh, added a layer of abstraction to what we're doing to try to make it easier, better, faster, to get to the outcome?
So how, how, how can we even like talk about trust as being some sort of, you know, foundational core that we can ever truly know? Can we ever truly have that? Oh, you know, you hear stories about the, oh, compilers, those are bad things.
'cause I know what I can, I can code everything I need to do in assembly language on 'em, whatever platform, those compilers, I don't trust those things, right. They're magical, but they work. Yeah.
I dunno what to do. And unless, yeah, it is that I have to get past it, it's kind of stage. I went through that with like code generators too.
And you have this point where like, okay, I'm not gonna modify what it does. I'm just gonna use what it does. And if it doesn't do it, I'll either figure out how to make it do it or make a workaround if I need to do until the time, time being that it, it does actually work, and it will, we'll get, we'll get past that point.
So you believe then, oh, I do. If I, if I may, I believe I'm a believer, no, I'm sure you answer your question. You believe that, um, with m's, or, you know, perhaps it's, it could be anything, you know, not just transformers, but other ai, um, that we can ever reach the stage where we are now with compilers that we could look at the, this black box that is a deep learning neural network and see the outcome the same way that we see the outcome from, you know, a compiler in just looking at whatever, you know, Python code that we've written and turning it into actual stuff that the computer can run.
I do. I I do not, not just on faith, because the pattern has been there before. Mm.
Like, we trust machine learning today, right? Because we've gone through this learning curve of how to effectively take, effectively take PyTorch or whatever platform that we're using to figure out the process of, yeah, it's not just about writing the algorithms, it's about grooming the code and creating features. And there's a process to this, right?
It's a different way of creating software. Um, we were that way about DevOps. I'm not automating this stuff, you know, I'm not, okay, I'll, I'll, I'll do a continuous integration, but I'm not gonna do continuous deployment or at least maybe even automated deployment because I'm the one left holding the bag.
If it doesn't work well, you start to make it work and you start to build trust in it. And I think trust is experience as you get experiences. Yeah, I like that.
That's what builds trust. And, and unless it turns out to be a, a Holcomb and, you know, just a, a full full of smoke AI baloney, which I don't think it's, I think that trust will go over now. It's gonna be oversold, it's gonna be overpromised, it's gonna under deliver, it's gonna do all those things that everything goes through a hype cycle does.
But we all know that. So, and even if we want it to work, we know it won't be perfect, and it's gotta go through some maturation. So that's, that's my answer.
Yes. I do believe it's gonna, it's gonna work for us. Yeah.
I, I feel the same way as you and I, and I think that what gives me hope that that's how this will play out, is that we're changing how we measure, you know, rightness, correctness, accuracy, et cetera in the AI era, or just the transformer generative AI era in particular. And it's, it's changing a a little bit about our expectations, because you have the trade-offs of flexibility for accuracy and, um, you know, if you can accommodate, uh, you know, percentage points of, of lack of accuracy in trade for the, uh, ability to adapt to unknowable situations, um, oh goodness. Why wouldn't you do it?
So I I, I think that it's heartening for me to, to see, you know, companies like AWS really trying to push the, and I'm not saying this on purpose, frontiers of how we think about software here. And, and I, I feel like they were very early on, uh, I don't know if they get a lot, a lot of credit for this, and they should, because they were really early to the, um, age agentic orchestration problem, uh, inside of Bedrock. Um, I remember meeting with them two years ago down in New York, and, uh, they walked us through, you know, this very detailed, um, uh, roadmap of how they were gonna build bedrock out to, to accommodate and, and support ag agentic development.
So I feel like they don't get a lot of credit. And, and I do think that they are, you know, if there is a company that understands infrastructure and they understand software as infrastructure, you know, apps as infrastructure, they're, they're in a good spot to do it. Yep.
I agree. You know, I think we're going through, you know, analogies can be useful things. This is analogous to us going through microservices, cloud neighbor Yeah.
Kind of architecture, right? Where picture it thousands, millions, maybe billions of microservices, smaller doing kind of special purpose, you know, more, more axiom kind of functionality. Um, how are you gonna manage that stuff?
Well, right? Something gets invented, Kubernetes comes along, and you know, right. In that case, it's an open source that is the dominant player.
I don't know that we're gonna have that dominant answer, but the orchestration layers of what IBM is doing, uh, uh, Microsoft is doing every, you name it, AWS Google, everybody is working on this. I think we're setting ourselves up for, okay, how does that all sort itself out? Am I gonna live in a world where I've got 25 things trying to control all the agents, or do I live in a world where there's two or three?
We'll see what that looks like. But that's kind of that maturation that we're going through today. We don't think that, Hey, yeah.
Another, another app's been containerized, another app's now starting to use Macroservices. Another one's been Greenfield and built. Okay.
Yeah. Okay. Yeah.
We do, we trust, we do. Now, we didn't in the beginning, but that's part of that process. Well, and we, we also self-correct too, you know, in thinking about containerization and microservices in particular, you know, in that era, uh, the early naughties, we, we were like, yeah, let's, everything's gonna be a microservice.
You're not gonna build monolithic software anymore. And we discovered that, well, you know, there is some truth to it, but not total truth to that idea. And I think we'll see the same thing with ag agentic, you know, development.
I think that we'll, we'll see, you know, places where it makes the most sense and places where it needs other things. You know, for example, rules engines, for instance, if you're, if you're trying to have something that that's a little less probabilistic, um, but that's all, like you said, man, that's all just maturation. Um, and, and I see that reflected in a lot of what, um, AWS is talking about, uh, particularly with the agents that it was built, the ones, um, that you were just mentioning Mitch, about, um, the, the Frontier agents, and also with Kero itself.
And my goodness, um, you, you said that this is, you know, a, a philosophical approach and AWS is actually, you know, committed to building its software on top of Kero or using kiro, which may sound extreme, but it, but it's really not. I mean, it, it is vs code with things that do other things in it. So it's, it's not a complete makeover of how we built software, but I, but I what you're using vs code.
No, yes. Like everyone else. Yes, that's right.
That's right. Everything cursor, it's all, it's all the same. Um, but, you know, it, it is, I think, representative or reflective of, of this sort of changing ideals of how we build software.
And I wanna talk for a second, if you don't mind a little bit about one of those, um, with those long running processes, I remember, and this is actually, you know, a function of frontier scale models, where when, um, OpenAI was talking about long running processes for things like trying to discover a, a new, you know, molecule as, as probably the, the best example is, you know, that's not something that you do a deep, you know, um, what, what the deep research, you know, query for 10 minutes and get your answer on. It's, it's gonna run for a long time. Mm-hmm.
And what AWS shared with us this morning, and what we'll hear a lot about this week is this sort of shift away from, you know, having, uh, just individual, you know, developers solving small problems to perhaps, you know, these long running agentic processes that are solving more complex problems, bigger problems, um, maybe it's, you know, just migrating everything from T net to something else in the company. I dunno. Well, you know, we're, uh, so we're, we're at the beginning of this journey, both on the podcast and also a Ws they're both our long running processes, but, um, we'll, we'll do a, we'll do our episode two and, and do kind of a recap, pick up where we're now, but also what I was text you on some other areas, there's agents for Cure itself, for the development process.
There's an DevOps agent. There's also, um, they're doing now train your own model, uh, using AWS's models in your data. There's a lot of things that, that will come along that we'll talk about as part of the announcements on episode two.
Uh, I think one of the things we wanted to structurally do in the podcast is wrap up with, so what's on your mind for the next week next? What are you thinking about? I, I may have made you go first on these, so I'll, I'll kick things off.
Okay. Go for it. I'll think, I'll think I'll, I'll take one for the team this time.
Um, you know, in the analyst world, I try to look at it as, it's not about any single announcement. It's about, so what, what are these things that a vendor, AWS in this case or anybody else, Microsoft at Ignite, et cetera, what is that setting this up for in the next six to 12 months? Because let's face it, that's looking too far down the horizon of what technically is happening is a bit problematic other than seeing vendors kind of leapfrog each other with the same things, but as they take on new challenges.
So that's what I'm, that's what I'm trying to think of, of, okay, so this is the big event, not for the end of 2025, but the beginning at 2026. And so, well, I'll, I'll try and share some thoughts about that when we get together about what's on your mind. Yeah, I'm, I'm trying to think about, you know, what can, and what cannot be automated with, uh, generative agent ai.
That's what, that's what I am, I am, my mind is, is really trying to wrap itself around right now is, um, as, as you know, you mentioned, um, we're, we're, you know, both practitioners and working on some projects and, and one of those is, um, trying to work out how to do competitive intelligence and what does that look like? And if you, you know, for those of you listening that, that, uh, know anything about this, you know, the analyst in industry itself, competitive intelligence, is this sort of, um, long hated but deeply, you know, respected area of investment within companies that are trying to compete and, uh, you know, generative ai, like with so many, um, areas that involve, you know, how do you take a lot of information and correlate and analyze and, you know, surface value from that information, you know, is really good at it. So, um, I'm trying to think about, you know, what, what would actually be automatable and how far could you, could you take that with, you know, gaining value and how could that be operationalized to, um, work across several disparate, um, competitive areas?
So like, you know, having, how, how does, you know, kiro, you know, line up with Bob, uh, from IBM, you know, how do they, how do they compete? When you talk about things like, um, spec driven developments, you know, what does that mean? It's, you could say they have SPECT driven development, but to really dig into, you know, how it's being implemented, that that's the heart of competitive intelligence and it's not that easy to do, but, but I really feel like we, we can, with the tools we have even now at least, you know, surface enough value to, to make directional statements from us.
So that's, that's what I'm, I'm thinking about it's a good juxtaposition, intent driven development versus spectrum driven the same or they different. What's something, one's got a, a better approach or not, you know, we'll see, you see how that shakes out? Could Yeah.
You think on, you think about big problems. You and I like to do that. Like, what does all this un unsolvable life meaning of life, you know, indeed, deep thought.
Alright, hold so we'll, we'll figure out an email address, folks you can use to contact us. Um, in the meantime, you can read out you, you reach out at m Ashley at futurum group com or be shiman at futurum group com. We're happy to take your ideas on episodes, comment on wherever you listen to this or see us on LinkedIn.
We'd love to hear from you. Let us know if this is interesting or what questions, you know, you have, whatcha thinking about, uh, as either developers or people involved in software development or people architecting solutions, or people building products for the market, especially who, you know, we talk to a lot. We look forward to chatting with you there.
Harding thought before we sign off, Brad? Yeah. Just, um, glad we're doing this, Mitch.
I, I, I think that, um, you know, there's so much going on in our, in this industry right now that is, is I think, very hopeful, uh, in terms of, you know, making better software and more software. 'cause I think you can never have enough software. I think we need more.
There's a self-fulfilling prophecy, if ever. Indeed. Thanks for listening everybody.
Thanks for watching. We'll see you on episode two and stay tuned for more. Appreciate it.
Bye. Bye everyone. This is agent dev.
I'm in position. Copy that. Dev, stand by for, go standing by.
Hello everyone. In this session, let's take a look at OpenShift virtualization, the why, what and how we can run VMs, uh, alongside containers. I'm an a RI managed OpenShift black filter, red Hat.
Uh, first the reasons why one should consider this, right? Uh, obviously the, the main reasons that stand out, one, when one wants to use the cloud are, uh, generally you want to exit out of your data center. You know, or you would like to use the cloud as an extinction of, uh, your on premises data center.
Uh, you know, you wanna burst to the cloud when needed. And of course, application modernization. Uh, you would like to modernize your applications to take upon digital's, uh, cloud native technologies, right?
And amongst these, the most important of, of these is to ensure that you have a clear path to, uh, modernize your infrastructure. And, um, obviously no, uh, organization out there has, um, ever successfully and conveniently done a big bang approach to modernization. So it is always best to, to, to go for an approach, um, that suits your pace, um, you know, so that you modernize what makes sense to your organization first.
Um, at the same time taking on the, the VMs or the, um, the legacy in a way that lets you, uh, to make it as close to your end target as possible. Um, which means, you know, to, to be cloud native all the way, right? So obviously no big bank approach there, as I mentioned, modernize what you can, uh, step by step, uh, bring in your VMs, uh, this to the same platform and take on your, uh, modernization efforts from there, right?
Um, and what do organizations ask for? Uh, they, they need a comprehensive platform that can, um, provide for all these capabilities. We out here, be it, um, let's pick out a few self servicing capabilities.
Um, CSCD, you know, s st and software defined networking out of the box load balancing multi-class management for, you know, uh, our comprehensive, uh, uh, management and control and observability aspects, um, cost management and, and minimal, right? And if you, if you dig a bit, uh, into the, the benefits, uh, on, on such a platform, right? What could it give an organization?
There are plenty, right? Uh, a single platform to, to begin with, right? For all kinds of your workouts, right?
Um, uh, the Bernet style of orchestration capabilities, DevOps and, and GitHub tooling out of the box operational consistency, you know, be it on premises cloud number one, cloud number two, right? So the, the, the feel, uh, the, the look, the skill set is all the same. That's what operation consistency essentially means, right?
And most so importantly, easy, uh, modernization path for, for your VM workloads too, right? And, and many more in terms of security aspects, multi-tenancy aspects, you know, uh, lower TCEO, et cetera, et cetera, right? Another why is the need to reduce your cloud spend, right?
If, if you look at the number of hours in a year and, uh, the number of business hours, uh, it's something similar to what is shown here. The question is how PC are your VMs across all these, uh, hours, right? In a on-premises, uh, land, your virtualization solution allowed co committee, which is, um, to take advantage of, uh, the generally low average utilization, right?
Uh, of VMs, right? So all committing lets, uh, you take advantage of the, the generally low average utilization and, and, um, this is system may not cost to be on cloud, right? A quick examine, um, is, you know, if there are a hundred VMs senior, um, on VMware estate, each of it is assigned for VP status.
A so 400 vcps in total. It doesn't mean that, you know, the underlying the actual hardware, the physical hardware is given you 400 vcps, right? It is overcommitted, you know, basic, basic, essentially you're running on somewhere between a hundred to 200, uh, vcps of ware.
So when, but when you move these a hundred vcps or, or a hundred VM CG cloud, you end up configuring, uh, 400 vcps, uh, for, for all of your VMs together, right? And the customer pays, uh, the cloud pro provider for all these 400 vcps 24 by seven. Uh, it, it's observed that BM utilization on, on cloud especially is, is on average less than 15%, means a huge chunk of that capacity is unused, but paid for, and customers are not usually happy with their cloud spend because of this, right?
That's where virtualization and OpenShift cloud services can help by reintroducing, um, overcoming capability as part of the platform, thereby, um, helping reduce your cloud VM spend by 50% or more. So this is another area why one would want to seriously look at virtualization on OpenShift, uh, especially on flower, and of course, the bit ask us to avoid a multitude of bad forms, right? One each for each kind of your workload.
What better than a single comprehensive platform for all or all your workload means speed, ai, your vm, your containers, everything, your applications, everything right? Now, those were some of the whys, the reasons why, what one would wanna have, uh, such a platform. Now, let's look at what exactly is, uh, open virtualization.
It's, it's an a PA on runtime, built on qver, a technology called qver, um, to run and manage your VMs in a QS native way, in a sense, and to be able to run VMs as codes, right? Red, red has been having a, um, a long history of involvement in virtualization technologies, right? Right.
From, um, the tradition of, uh, KVM in 2007, um, and in 2016, Q Bird project was launched, you know, um, to, to enable VM management on Kubernetes, right? And, and its performance and scale has been proven. An example here is, is the popular game Fortnite and the sheer numbers given here, right?
Eight runs QT under the hood, um, essentially, um, set operated OpenShift virtualization is a self-managed operator that runs, um, in an OpenShift cluster. Uh, it preserves the traditional VM behavior. Its administrative, uh, capabilities like live migration, for example, to support your business critical applications.
Um, it's built on KVM, um, which is the technology, uh, used by Red Hat and most of the cloud providers for, for 10 to 15 years, right? The, the upstream project cube word, um, is, is the, the, the, the capability used, uh, technology used, which combines the KVM layer with, uh, OpenShift manageability and its ecosystem. Um, one thing to note here is also that, you know, you could print your windows, uh, guest, um, windows operating system, um, through Microsoft server utilization validation through grammar SQP, right?
So the goal ultimately is to run, uh, your, the ability to run your VMs and containers together in a single platform, co-located for easy management, low latency video services when talking to, you know, in these services and VMs and continuously talking to each other. Um, same platform also means low skillset gap, right? Because the tool set the ecosystem, the technology is the same.
And, and, uh, this also comes with a state-of-the-art, uh, GOI console to, to manage everything under the, um, you know, including VM and containers and applications, everything in a single state-of-the-art go. Um, and now let's look at some of the, the, the platform aspects that helps virtualization itself, right? For example, networking aspects.
Um, internally the platform let's you create multiple networks to isolate workloads, uds, or user defined networks. Um, lets adminis administrators to do this. Uh, workloads that needs to be separated and isolated can be run across, um, different namespace and connect across different networks for added security and control when it comes to, uh, load balancing, for example, right?
Um, it is similar to load balancing of containers. You know, everything is built into the platform outta the box, so no hassle of having to configure and together networking tools and external load banks are separately, right? Um, same with, you know, exposing VMs, um, or VM applications to outside users and to client applications outside, right?
Um, and everything is built in, uh, as mentioned, right? Using Kubernetes technology. Um, another capability is a service mesh, uh, using, you know, HTO for your fine-grain traffic control between mediums and services.
You know, if you want to have rate limiting or fire balling, circuit breaking, you know, observability of traffic, how traffic is distributed, recur response times, et cetera, et cetera, right? Um, storage, um, you know, storage solutions such as where it had ODF, OpenShift, uh, data foundation or any of the, the, our growing partner, uh, solutions can be used with OpenShift ization, uh, depending on the kind of workload and use case here, we can also see that the partner, uh, ecosystem is vast and growing to, to, uh, offer you flexibility and choice for, for various capabilities such as, you know, for example, backup and, uh, success recovery, networking, et cetera, right? Um, essentially OpenShift virtualization offers all the core virtualization capabilities that your current virtualization tool, um, offers or has.
And then beyond that, it also offers everything you need for modernizing and future proofing your workloads, as you've seen in the previous slides. Now, when it comes to services, you get the same consistent and flexible, um, enterprise bernet experience of open shared, uh, plus, um, managed for you by a team of global, um, SREs, right? The, um, advantage being the, the, the, the core compute storage, networking, several of the complexity of, of managing these aspects are uploaded from the application teams and platform administrators.
Um, the upgrade, for example, you know, the management management of core, uh, platform capabilities are all managed. Uh, the heavy lifting around on those things are, are managed for you, right? Availability of these, uh, elements, monitoring and quality of services are taken care of for you by our s um, thereby customer teams get to focus on, you know, what matters most for them, that is building and managing their applications and, and not to spend much on the, the, you know, the boring and like, uh, mundane complexities, right?
Um, when it comes to, um, when it comes to, um, cloud services, um, uh, a lot of the, uh, the, um, the, the essential service, service deployment, for example, uh, in terms of how managed clusters can be spun up in, in a matter of minutes that you get, since it's in cloud, um, you get consumption based pricing. 95% financially backed SA and, and 24 by seven joint support between Red Hat and your cloud provider. Uh, and, and, and a lot of, um, you know, benefits being on cloud plus managed service, right?
Um, and, and our goal is to allow our customers to move from a 24 by seven operations to, to a nine by seven, a nine by five innovation. You, you focus on your building of applications and deploying and running and managing them, rather than having to maintain and manage the underlying, uh, platform, core, core, uh, platform elements itself, right? Um, so all the cloud benefits like it mentioned, you know, um, and in, even in terms of payment pay as you go, um, we serve instances, private offers, all kinds of payment flexibility and, uh, in terms of availability, uh, on demand, scalability, GPUs, for example, in these days, right?
Where AI is, is critical. So this is essentially cloud benefits that you get out of the box, you know, when you're moving to cloud and to a managed service. Uh, when it comes to running VMs in managed cloud, uh, managed OpenShift, right?
How, where are, where are, where are these VMs running? What's, what's the underlying, um, hardware, right? So in A-W-S-G-C-P and IBM Cloud, um, you, um, use bare metal insights offered by, um, by the cloud provider.
And in Azure you use, um, uh, boost instance types, right? So, uh, that's how you take, take advantage of the platform, um, and, and through UN online, uh, hardware to run your VMs on. Now we saw why and what now, let's, let's take a quick look at how you can, you can bring your VMs in, right?
So migration tool, tool toolkit for virtualization is, uh, is an easy way to get started, uh, with OpenShift virtualization, it helps you migrate your VMs into OpenShift, uh, from your source, uh, uh, you know, um, virtualization solutions for, be it VMware or red air virtualization or OpenStack, right? It, it also gives you, as you migrate your VMs, it also gives you, um, provide feedback on, in any identified issues while migrating, uh, VMs, right? Um, and then, and easy to use gui, uh, in with, well, within your OpenShift console, which I will be able to show you in a a few minutes.
Um, VMs can also be created and managed using the inbuilt OpenShift tooling, you know, DevOps and GI tops tooling that comes with OpenShift. Um, and, and if a customer has a large, uh, virtualization nested with thousands of VMs, right? Then what makes sense is to, to automate them, um, uh, using, um, redhead automation platform, which is a good solution to consider, you know, if you have caught such kind of mass migration or commerce, right?
This will also help drive efficiency in the near migration process. Um, and not only it, it helps you migrate, but also takes care of your automation of day two operations of not just, uh, you know, VMs, but your entire OpenShift, um, workloads tool, right? Um, so it, it, it offers a lot of capabilities, you know, right from configuring the Bastian BM to, to kick off all those process to doing, to, to setting up the networking and storage and everything, right?
So Ansible automation platform is a, is a mature congruency automation tool that you can take care of all your, um, hardware and software, I mean, um, your year, um, OpenShift ecosystem, uh, in, in, in a holistic manner, right? And, uh, red hat, a CM or advanced cluster management tool is it turned way for, um, for not really creating and managing areas, but, you know, due to manage your entire, um, fleet of clusters, uh, across on premises or cross cloud, and, and not, not just for VMs, right? It takes care of life cycling of VMs, your containers, your applications, and, um, clusters also across electrical, right?
And it also gives you a single pane of, uh, of glass with, uh, deep level observability dashboards to, to monitor the clusters, DVMs and, and everything that runs inside your, uh, your, uh, OpenShift cluster, um, BM cloud or, and or anywhere, right? Um, and from from the ac CM console console, you can drill, drill down, you know, double flick into, um, you know, the specifics of a BM to see, uh, how it's performing, what the metrics looks like, cetera, et cetera. And yet, another way is to approach your cloud provider who also might be offering, you know, different, um, ways to migrate, uh, VMs to OpenShift base.
So in this example, um, in this case, it's, it's a no cost to low cost migration, uh, offered by, uh, river middle, um, with, with a ps. So there are different means to, to get, uh, you know, to your VMs across the OpenShift. Now, coming to, um, customer success stories, you know, here we can see, um, s and beauty, which is one of the biggest banks in Dubai, or probably Middle East, migrating more than 9,000 VMs in, uh, across using MTV migrating virtualization forward.
Another example of, uh, global investment max. So a lot of customers out there right now, finally to, to, to go to the next steps, right? So if you, if you are intending to migrate your VMs across to OpenShift virtualization, um, red Hat experts will work with you in a program through a program for virtualization migration assessment program.
You know, they'll work with your teams, uh, over a series of onsite RAC workshops across one to two weeks, um, where the migration strategy architecture, um, uh, design the path forward will be discussed, um, agreed upon and documented in your report, um, following that, a high level executive presentation can be delivered. And then from there, the mass production migration can be kicked off right Now that, that's, uh, that's a cute look at, you know, why, uh, what and how, and the next steps, if you really wanna start off, uh, now I have a, uh, a bunch of, uh, prerecorded demos too that, uh, we can take a quick look at how, uh, to see how things look for real, right? Alright, let's take a quick look at how things look for real.
So this is an OpenShift concern, um, in this specific case, this isn't, this is in a cluster that's deployed on a WS red OpenShift service on AWS. So, um, let's take, let's take a look at what, um, operators are installed for the virtualization capabilities, right? So here it see the operators, uh, section.
So through the operator hub, you install the operators that you need to get things working. So in this case, the, the operators have been pre-installed. So if you go here and see here is the OpenShift virtualization, um, operator that's been installed.
And for the migration toolkit for iation that we spoke about, you know, that's also installed. That gives you the, the virtualization virtual machines view as well, right? So, mm-hmm.
Now, very quickly, so we've got a bunch of, uh, VMs that is already running here. Now, if you drill down into each, we see, uh, a lot of options here, for example, to see the metrics, to see how these are performing, which can be imported into or exported to, to the format that you want. Now.
Now let's take a look at some of the, you know, management aspects. Right now, if we go to the virtual machines section, again, to one of the windows VMs that's running here, uh, we can access the VNC console from here directly from the OpenShift console. And let's look at the number of cores that are running here in following in this vm.
And as you can see, it is using a single core. Now, if you'd like to increase that two, just an edit of the animal file, as you can see here, save, and then go ahead and repo your machine to take effect in a, in a while of what you see is it is gonna start automatically and in a few seconds, you, you can see that once it is, put it back up, the number of course have been increased to now, how can version machines be created? So, again, in the em, uh, the version machines action f notification link, we can click on create, which will give you, uh, a number of options in this case, I see is, uh, the creation to a YAML file.
We copy pasting a template and frame the configuration, the detailss are entered, and that's high plus that is right now, now a VM is running, right? So, you know, if you wanna delete the vm again, go back to actions and just click to free. And the resources, right?
Now, we meant, we spoke about low balancing, right? Let's take a quick look at how that works. So one of the name spaces where the, the, uh, in missions of running, we're gonna take the act label, which can be used to create the service, which is, uh, the Kubernetes server source that helps you load balance between services.
So you can create a service, keep the same label that we copied from so that it goes and both SBMs. And since it's a Windows machine, the service stack here, broadband same as a T, and now the two VMs have been broadbands by that service. Now to expose the service or that application outside, let's do that by creating a route, right?
We are creating a, a route which helps you expose the application to the outside. So we are creating a, um, a route to which we are giving the service, uh, the ELA service that we created, um, in the previous chapter, and then giving the board mapping and that secure, he is staying air route, which means the key estimation happens at the ingress controller, and in case ht, it'll be redirected to HT PS. Now a route has been created.
Now that's that how always it is we access the application, right? So likewise, a lot of capabilities out there, managing outbound traffic, uh, in you saying network policies, right? Um, okay, look at how things again, Right?
So here we see that, you know, um, when we access this, um, service, it is accessible because getting a a GP 200, okay, now we're gonna create an enter policy to block that, uh, access, right? So we created a network policy here, locking the res. Now, let we test that From the console.
com, which worked earlier. Uh, 'cause we got 200 earlier. Now, because we have calling a truck policy, uh, we have, they're blocking TXL traffic, right?
So likewise, and a lot of, um, management aspects that you get out of, um, the virtualization, um, options in your week. Now, what do your administrators see? Uh, is, you know, once, once your VMs are running, they get a, a topology view where a graphical presentation of how VMs are, are running, um, how in, um, in, in call container surrounding there.
So it's all given to you in a, in a graphical representation in your topology view right? Now. Let's also look at how live migrations work right now, these are some of the VMs that are running here in your, as VMs in your OpenShift cluster.
Let's take a look at how, um, live migration can happen, right? So here, if you see the VM is running on a, a node that has current name, but in three. Now, here is by going to the three dots at the end of uh, line, you click on, uh, the micro option and the VM is going to be more to another node, right?
Right. So it's not in running status. Now, if you go back and look at the, the node that's, it's now running on, there's changed to, uh, a node name that run in suite two and by how it used to be.
So that's a kit. Look at some of the migration, um, capabilities, um, migration capabilities and how management aspects block here. Uh, now to look at, let's also look at how the, the MTV, um, helps you migrate VM spec.
So this is your, we send a little static. So here's where, you know, the source D mware estate is where a couple of VMs are running, you know, um, the names are ending with dash demo one third and Linux, they in running status TBMs are on, yeah, this one has a Windows vm right Now let's look at how we can get them migrated to the open station. So, so that we are ensuring that the applications running on our, all the VMs are indeed intact and working.
Now on, on the tab, let's go to the OpenShift console. In the migration, um, left navigation section, we can create, uh, we can first set the providers. So in this case, the, the local host provider, which is nothing but the, the, the, the cluster itself.
And you've got, uh, VMware also as, uh, one of the providers. And what we have to do is to go and create a plan. We wanna create a plan to and select VMware as the source where the VMs that we intend to migrate exist.
Now. Now we, we are filtering the VMs by the name that ends with timal. So we got couple of them that we solve in the center earlier there.
They in, uh, our own status. Now let's create a plan to migrate them right here. So we give them a name and then the networking storage mapping set down and then currently become a create.
Now by default it is, uh, cold migrations enabled, but then let's edit that to, to, um, configurate one migration so that can, there is no disruption to existing application running, although on those VMs, um, why there're being migrated. So let's start the migration, right? So as you can see, the migration process has been initiated.
So we've got two vs that we are expecting to be completing migrated off through here. Now on the BM section, we can see that the, the pipeline processes initiated, we've got a, a list of items to go through before the complete migration can happen. So, right, so the pro, the migration is pro progressing.
See, most of the time that it takes us in the disc crisis because, you know, storage has to be transferred, Which is going on. And then we skipped around an hour and a half fast forward, and we see that it has reached the space that we have to now allow for a cado, right? So it is paused there.
So we can go ahead and, and improve for the cutover, right? So we still go back to, um, DB Center. We can see that the VMs are still working.
No, um, impact to, to the application running there. Now, let's do the over to bring them here, right? We can either do it now or we can schedule it for a future time and date.
But list here right now, right? So the pipeline processes, 'cause you have approved to cut over. Now in a, in a while, we can see that the entire process, the last bit of data is also copied.
And we've got, uh, the VMs completely running here, right? If we go there, we can see that the, the pipeline is completed. Now, if we go back to the V center and check Chicago status of those VMs, now they're in part of status, right?
Because that those have been migrated all the lower. And now, now in the mid of ization tab, here we go, injectable VMs under the namespace that we imported those VMs into, we can see that those are here and running status, Right? So both VMs are up and running here.
So that's a cute look at how migration, um, can be made possibly using MTV, right? So, um, that's about what I wanted to, um, show to you today. So I hope, uh, that the session and the demos bear useful.
Um, feel free to reach out to your, um, local Red Hat account teams in case, uh, you want to, uh, try this out and, and want to take advantage of the open consumerization, uh, for your organization. Yeah, thank you. Thank you for inviting me.
Uh, glad to meet everyone here. Um, so what I like to do is, you know, when I used to go to conferences and I've probably, I've done over a hundred assessments by probably going over 10,000 conferences. Um, I like to go once where I can take something back and make my, you know, like I learned something, you know.
Um, so when I've been doing presentations I like to do, here's what I've learned. So, I've, I've actually done, I don't know, 150, uh, different assessments since I retired of government agencies. Um, I worked with the Ukraine government for a while, getting ready for a war.
We kept telling them what was gonna happen and they kept saying, no, it's not gonna happen. Um, and, uh, NATO and other organizations helping them do cybersecurity. I know some of these Russians, the bad guys, AP PT 28, APT 20, I know 'em by name.
Um, and I know what they do. I know what they like. I know what they find.
I know what they look for. I know what they don't like. And that's what we're gonna talk about today a lot.
Uh, so I said, well, all right, I'll put a presentation together on, uh, things I think are working okay, and then I'm gonna talk about some things. Frankly, I don't think really working out. I used to say they, they suck.
Now they're underachieving. It's where, you know, um, oh, that's just who I am. I have my own company to be secure.
After I retired, I came up with the name to be secure. Two days after I got a, uh, email from a guy from Mossad, he says, Hey, I love that name. We're setting up a company too called to be secure.
Lovely, um, agenda. Um, so after a hundred odd assessments, you know, you get to learn a little bit about what a good program looks like. Uh, so just some general observations.
When I go into a company, if I see these things, you know, I said, all right, we might have a chance here When that happens, by the way, I'll let you know, just, just kidding. Um, cybersecurity capabilities that are frankly underachieving. Uh, and that's kind of, this is, I'll be honest with you, I get a lot of controversy, uh, on this one.
A lot of people don't like me pointing out their favorite program. Uh, and then I'm gonna talk about, there are many, but I'm just gonna talk about 11. I just chose, um, more from recent experiences and recent incidents involving some of the a PT groups, uh, that the hackers don't like to see.
You know, if they're gonna drop a payload on your network, if they see these things, oh, Christ, you know, they gotta work harder or they just leave. Okay? So what does a good cybersecurity program look like?
Uh, it should be no surprise here, by the way. Okay? So the CISO is independent from the CIO ct, should have no relationship with them.
However, from a reporting organization, they should be separate. They have their own organization. They're on par with the CIO or CTO, okay?
But they represent security, alright? Two different disciplines altogether. It is not security, and security is not it.
Um, security function is included in everything. You know, you don't work for the CIO, but you work next to the CIO and they don't make decisions without the CISO being involved in everything. Um, no shadow it.
The bad guys. I'm telling you, one of the biggest, most expensive databases to get access to is your Shadow IT database, which eight, which is run by a group. Um, shadow dancers.
Um, hiding and deception is part, oh, none of you come from the intelligence. Well, IRA does, but none of you come from the intelligence community and you've never really, well, let me ask anyone else from, okay. And there we go.
Very good. And, um, we, part of our program in security and encounter intelligence is deception, right? I go into these companies and, you know, before I go in, I know everything about 'em.
I've gone in and handed them their admins for their Azure account. I said, where's this guy today? Um, okay, uh, no one hides anything.
Uh, here's the key one, and this is true. Cybersecurity hygiene is optimal. This is what you spend your day on.
It's not sexy, but the patches have to all be made, all all the, it has to be known. All has to be visible. All has to be it.
It all has to be, you have to really secure your admin accounts down. The all I'm not gonna go through this is not presentation on hygiene, but I'm telling you, I'll tell you again, I know Iris told everyone this a thousand times. It's all about hygiene.
Mm-hmm. There's no toll. There's no product, there's no toll that can replace good cybersecurity hygiene.
And, and frankly, it's, it's probably the least expensive one. Uh, by the way, um, no users have administrator accounts or access, no users right? Now, admins also have user accounts, right?
Mm-hmm. And that's what they use. But no admins, no users have any admin.
They're not members of any local admin privilege groups. Any, uh, domain privilege access groups, no cloud access groups, okay? Um, privilege, user accounts and software secured and monitored.
I'm gonna talk about that a little bit later. How, where that's important. But that's what their, that's their target.
That's what the bad guys make the big money off of. That's what they sell. Those credentials represent admins, makes their lives a lot easier.
Um, only provision and managed devices are allowed on the corporate network. The cloud and SaaS is not your network unless you own it. It's to be untrusted.
It is the playground for the A PT groups. In fact, I'll be honest with you, I won't know who it is, but they own one pretty much and go anywhere they want. Um, IIC networks, ICS networks, your industrial control networks are physically separate than neurological.
I can, I go into all these industrial control companies all the time and they talk about how great they are at isolating their networks. And I say, well, show me where they're isolated. And they're never isolated.
They say, well, we got these V lands where we got the, I said, oh my God, please stop with the VLANs. Um, you talking In isolation, like with one way dial. Yeah, you can play the one way diode game.
And that, that's, that works okay. Yeah. But, uh, they, yeah, they work.
Okay. Alright. Um, and all administrators are subject, oh, no one, the financial industry is replete with this problem.
They don't know who their admins even are as people, right? There is an active program right now from the Chinese Intelligence Service in New York City where they're recruiting people with admin privileges on, on Azure. They're walking around looking for 'em.
Well, they already got the names and everything, but they're, they're looking for 'em and they're recruiting them. And they have been successful, thank God. Finally, the FBI is onto it after a lot of us told them for a long time, Hey, you look at this thing.
Alright? Anyways, okay. So that's what a good program looks like.
Kind of a quick overview. Uh, let's jump on. Alright, so now to the controversy.
What's not working? Cyber threat intelligence. Completely useless.
Completely useless. First of all, it's not intelligence. Intelligence is something that's covertly collected that the bad guy doesn't know you have and you can use operationally against them.
What you all get is called cyber threat information. In fact, when it first came out back in the late eighties, early nineties companies, they called the cyber threat information, but they decided, Hey, hey, I know what to call it. 'cause they don't know.
We'll call it intelligence. It's not intelligence, it's information. The bad guys get it too.
In fact, there's a group in St. Petersburg, I still call it St. Petersburg, um, that make it, they actually produce it and push it out there.
And all these companies are ingesting it and they're feeding it and they're putting it in formats. Um, data encryption, you don't do it right? People, you know, you know the old standard, you have to do encryption and data in rest and data in transit, okay?
It's, you might as well not do it because what they do is you turn the damn thing on and then you make the group, everyone's in the group. It's an access control mechanism. It's supposed to be used as an access.
We used it in the intelligence community and we did not give the keys to people. We did not want to have access to the information. Alright?
That's the way you should be using encryption, uh, credential vaults. Complete waste. Complete waste.
I've never talked to a hacker who said, oh, that company's got got a credential vault, we're on to the next one. They don't care what's in your vault. They care what's in your cash, right?
They're not going after. And by the way, I don't know if it was a black hat or yeah, I think it was black hat, or maybe, no, it was def com. Um, someone did an operation, a test where they tried to break into the various, uh, open source and I, I forget which commercial one it was, maybe CyberArk, I might be wrong.
Um, they got in 20 minutes, owned it. It's not like they're written in some secure programming language. One guy, one of the guys who I wrote his report said, you know, they're using open source libraries from 10 years ago that are unpatched that they haven't patched.
And this is where you're putting, this is where you're putting all your secrets in. Oh God. Um, oh, alright.
Badgering employees with, listen, you wanna test them fine. Firing them, badgering them, showing them, dragging them out in public in front of everyone else. No.
Uh, that's enough already. Okay? It's your job to protect them against the bad guys.
It's not Alma in accounting. It's not her job. She doesn't know what the hell she's doing.
She doesn't know what the different browsers are. And you're telling, and you're badgering her about, you know, Hey, that's a potential fish. Don't click on that link.
Tell them once, tell them twice. Okay? But please enough with the, with the, you're not making friends, by the way.
And I'm telling you, cybersecurity organizations, I think that work well are the ones who truly partner with the employees and, and have a relationship. You don't wanna be seen as the ones who, oh, those are the guys who I get an email every once in a while. I have no idea what the hell it's doing.
Um, data loss prevention products. It's not that they're necessarily bad, but there's so many ways of moving data outta your network. Absolutely.
Right? You know, again, you talk to the hackers and they said, you know, do you, does these things stop you? No.
No. And their answer is, what are they exactly? And they said, no, we just put 'em in dn.
We just, you know, put it in a DNS label and ship the stuff out. I don't care about their, you know, in fact, the more you encrypt things, the less you make itself visible to you. Right?
They love their favorite thing. Now, in fact, the Russians, this was a campaign. There's this thing called DNS over h TT PS created by who?
APT 28. And it became a standard. And companies are going around sewing.
We've got DNS over http s now. Oh, good. Now you can't see what the hell is going on in your DNS.
Um, okay, boy, this is the one I used to teach a course on this cybersecurity complaint compliance frameworks. Um, yeah, I was on the 853 initial meeting group that, you know, had the first discussions what we wanted, right? We wanted a race horse.
What we got was a camel, a a 75-year-old camel with humps going onto the left and to the right and couldn't walk straight. And I mean, we didn't get what we want. These, these frameworks.
My number, I have a lot of complaints about 'em, but my number one complaint is they all judge cybersecurity controls as the say, you gotta do all the following. No, you don't. You have to do the ones that stop the bad guys first.
It's all, in fact, by the way, I can say this, this in the cybersecurity framework, you know how protect is second. It used to be fourth. And we, we argue, we, we just said, no, that can't be.
We wanted it first. And they said, no, you can't have it first. So we got it second.
Um, but I have other concerns about, oh, third party security questionnaires. Guess what? They lie mostly they don't know.
They don't know. You're asking them questions about their network. They're like the last people to ask.
They don't know who's connected to them. Right? And that's, that's the the problem you should be asking the questionnaires of the least secured company that they're connected to and that they're in it.
So having a fellow questionnaire, is it auditors, compliance, police, they all like those things, but it's completely way useful. You your job. I'm gonna talk a little bit about, I think, how to better secure that relationship.
And sims, let's go on to the next one. Wow. Um, again, you can't get good quality index data quickly.
You can get one, you can get the other. You're not gonna get both. Um, application layer firewalls, again, because a lot of encryption being used.
Um, data encryption, application layer encryption, network encryption. They've increasingly been unable to, and as an industry, I don't know, you probably don't even read about 'em. And people don't even talk about them anymore.
It was one, it was one time the, uh, AI topic of, of cybersecurity. But they've proven to be really unuseful and, and, and, and slow, by the way. Um, okay, so that's my list of, there's actually a longer list, but I, I, I wouldn't emphasize.
But here's some things here. Here's 11 tricks I'll call them, uh, that you ought think about. If you're not already doing them, you ought think about doing.
'cause these are things, as I said, you know, the A BT groups don't like certain things. These are some of them. Next SMB signing, they hate it.
SMB signing and what's the other one? Extended protection for authentication. 'cause that basically ensures every session connection.
And then every cookie passed, or every credential passed is unique. Alright? And that keep, that's where they like to get into their, when they say you, they moved laterally.
Think SMB. Okay? That's the protocol of choice.
Make it hard for them to do. Now the problem is, when I go into a lot of organizations, they tell me they've got SMB signing turned on because in Windows 11 to H two two, I think release, it was turned on by default. But guess what, when Microsoft, Microsoft does the patch Tuesdays, they turn it off sometimes to turn to be able to make some patches, then they turn it on, on the way out.
Well, I was talking to someone from Microsoft, he says, sometimes maybe the turn back on didn't work. So I, I don't know what that means. But anyways, you really gotta check and make sure both SMB and um, extended, uh, enhanced protection are both, are both active all the time.
Just doing that, you know, you, you are gonna reduce your, uh, exposure. About 11%, 11, 12%. Next K and TLM it was created by someone in 1988 who had, Microsoft had no kind of, uh, Novell like authentication token that they can use.
So they came up with this thing, uh, and it became a standard and it's not secure. And it's been abused time and time again. Um, it is also off by default in 11 and I think server 2025.
But again, every time I go to places, it's like they have to run it because this application needs it. Well, as long as that protocol's on in your network, you're dead. They're gonna, they're gonna get you and they're gonna exploit it.
Um, and then protected users group, the reason why I like it is this is a group, this is a, um, windows policy group. I think you do it in, uh, GPOs or in, uh, Intune protected users. Uh, and with protected users group, it makes it harder for things like ransomware to run because certain folders, system folders and users folders are protected from access.
They're only accessible by certain applications. The other thing it does is it clears the credential cache of that session. When that session ends.
Uh, that's what you want to do. You don't want to leave cash credentials around Next. Oh, how many people actually really turn on and use Microsoft's virtualization based security VBS?
Um, you should, When it first came out, it didn't work very well. But everything, Microsoft first, you know, any company comes out first has its issues. And a lot of people turned it on and found that this application went load as in a virtual machine.
And HyperV didn't work on that computer 'cause it didn't have enough memory overall. They kept dropping and leaking memory. You know, those days are pretty much over virtualization based.
Security is one of the key things. It's when, when the, when the, um, when 28 a PT 28 drops a payload, there's a list of things they look for. This is number two.
Okay? They look to see if VBS is turned on. 'cause if it's turned on, that means to go find the credentials.
You have to break into the credential cast. That means a kernel call. That means your EDR might catch it.
Okay? Now they're thinking, oh Christ, oh, what do I do? Uh, they might go on to the next one, but they don't like having to go down these steps.
Of course, most people don't turn it on. Um, or they turn it off. If it was, if it was on by default, uh, no, you should be using all VBS functions by default.
Now, there are some apps, older apps that people run locally that you can't virtualize 'cause they need real memory calls to the real address. And, um, but that, again, this was now 10, 10 years ago. I have people, I have a big, big client.
They've got VBS running across their entire network of over 80,000 machines. Not one problem. Next, Oh, remember I mentioned you all don't think about deception and hiding.
Mm-hmm. Here's one. I know I had one in the presentation.
Um, you can hide your domain admins from discovery. Most of the bad guys' tolls and they haven't figured this out. Well, there, there's no reason to figure it out.
'cause it always works. All they do is list objects, okay? And if their reconnaissance program list doesn't, you know, tries to list object and nothing comes back, and that's what this would do, right?
Then they don't have any admin names. They don't have any credential. They don't know where to go.
They're not good. Not, it's not that they're not good enough. They don't have the time or energy, frankly.
'cause they're very, very lazy to dig deeper and go in and turn it back on and then find out, you know, they, if it's a real target, yes, this is just a, just a small little block in the road. But for, for 99% of your malware, this blocks them from being able to go further and watch for, if they do try, they're gonna hit event ID 4 6 6 2, which is an action against an admin, uh, account. Like what raising the privilege Next, uh, how many people use UB key?
So I said before the number, the number two thing a PT works looks for was, um, whatever I said A PT number two was, this is number three UB key. If it, if it requires UBK, not for the administrator to log on, but for the administrator to issue commands, administrator commands, okay? Which you can also use UB key for which no one does.
Um, now you're stuck. Now you're stuck. Because if I'm trying to change an object's A or change an administrator account and that thing comes up, you gotta insert your UB key or you gotta put your pin for your UB key in.
If it's already in now you're stuck. Now. Now they, they don't like that.
Um, anytime you're modifying a registry or any type of system, um, object and, uh, they always have the administrators have to use a UB key next. Yeah, I'm sorry. Is there any or specifically UB?
Uh, I like the u bt fair enough. But yeah. Uh, here's one.
Don't use the Chinese made ones. There is, there are, there are companies who make, um, there's, let's say there's more than one key in the YubiKey. Um, but I did have a company that went out and said, well, why do we need to buy the YubiKey one?
We can buy these at, you know, 40% less. Um, okay, the cloud's not what you think it is. I always thought, I thought over these slides when I was flying out here thinking, how do I present this one?
The cloud's not what you think it is. Um, the bad guys are all over Azure. They have to be.
'cause that's where you're putting, that's where everyone's putting their data in now. Uh, right? Um, everyone's moving to Azure or AWS, um, but they're especially focusing in on Azure.
Um, Well, I work with companies and help them build cloud-based environments. Uh, there's a couple things I mentioned that, uh, I want them to do that frankly, most times they don't. But one of them is to use a physically dedicated host in Azure for their ad.
If you can't be confident of the machine your ad is working on, you can't be confident of anything. It's all about ad that's the target. Okay?
So if you're putting your ad on a machine that's being also used by someone, let's say, who is less security conscious and they've got, I don't know, some application running in there, um, and the bad guys know how to do reconnaissance within Azure to figure out what's running where. I've seen spreadsheets with elaborate, uh, labels from the infra from the virtual machine. Who owns it?
What's running? How long does the process run? What is it?
You know, uh, where are they getting that information? They've got penetrations in Azure. Physical, personal, and technical.
I, it is, it is more expensive to run your own physical environment. And I'm saying you have to do it for everything. Although I, I might.
Um, but certainly for your key databases and your and your uh, ad, um, next, Okay, I don't know. But a lot of times when I've been called in in the last, I'd say two years, it's all about this issue. This whole third party access issue has got boards of directors all upset.
It's got CIOs all upset. No one knows what to do with it. How do I handle it?
How do I make my company work with still allowing people access? Um, I came up with an, uh, an idea, actually one of my clients kind of came up with it and I helped them implement it. Um, where what we did was we got all the goal, I'm sorry, the goal was to get them completely off of the, their network.
Some of them had VPN access, some of them had gateway access through these crazy kind of remote zero trusts, gateway servers things. And, but the point was they eventually got an H-T-T-P-S connection into the network. That was the problem.
Okay? Because the bad guys are on the other network, right? And all they're waiting for is for someone to make a connection into the network.
The protocol frankly doesn't really matter that much. Um, so our goal here was get them off the network completely. No direct access into the network.
And what we did, and this kind company had some money where they could spend on these things that I'll, I'll grant you that this is not the cheapest way of doing it. Uh, we built another Azure Forest that this company came up with. And by the way, we didn't name it by the name of the company.
That's another thing you all do. They go out and they build you, you go out and you go into Azure or you buy a cloud and you call it by your own company name. Yeah, that makes a lot of sense.
Let's tell everyone who builds a catalog about Azure, where I'm at and who I am. No, don't do that. Anyways, so we built this other forest.
Every third party has to go into that forest. Some of them use the, um, in this case, because we had some concerns with the company in, at many levels at, with the third parties, we gave them, uh, Azure Remote Desktop, that they can't come in from their own physical. They have to come in virtually.
They connect to the third parties cloud that this company runs. Alright? And most of the resources they need to work on are either put in that cloud for them to work on or from that cloud they can get access not on a, not on a Forest Trust relationship, but they have to log into the company cloud and and only get, and they can only see that application.
That's the only thing they get access to. They never see the underlying network address. And that cloud is not an extension, obviously, of the corporate network.
It's a really, truly a separate network. I can't say it's physically separate, but it is truly separate. And basically that was the only way.
This is, this is a big engineering company globally around the world. They do support for the US government some very sensitive, um, uh, development and engineering work. Um, and they were just getting hacked to death by all their smaller third parties, engineers, architects, designers, everyone, you know, small companies who have access.
So this is what we did. Uh, and their hacking of their own internal network was went like this. Right?
Right, right off the table. Next DNS. Yeah.
Uh, it's always underappreciated as a security, as an attack, uh, vector. Um, it is the primary way Most groups xFi by the way, it's also now the primary way a PT 28 infills. Uh, so you gotta monitor it really, really well.
Most of the gateway DNS services, they'll eventually get, uh, updated signatures to mo monitor for misuse, but they're extremely slow. And because of the way the AI algorithms are working where they can do fast fluxing and automatic domain name conversions, um, there's no way these they can keep, they can keep up. So, um, you have to monitor yourself inside your own network for DNS misuse.
And that's, to be honest with you, that's the way you're going to most organizations I've worked with, and I talked to people at Mandiant, uh, I was meeting with them last month on a shared client. That's really what they focus on. They, they go back through the, the very first thing they do is go back.
They go the DNS records. They don't really know how people get in. And I'll be honest with you, there's a lot of times I don't really real think, how the hell did they get in here?
Uh, but they gotta get out. Right? Right.
They still got even the best intelligence service in the world has gotta get the data out somewhere. Okay, next. Oh, how many people are doing this Windows hot patching?
They don't, they don't tell this, tell people about this. The Microsoft sales and support people don't talk about this very much 'cause they frankly are a little nervous about it. I have a client, not, not the same one I I mentioned before, but another one smaller of about 2000.
They've now have both their Windows servers and clients are all being hot patched, which is really nice is it takes that whole bureaucratic discussion between the CIO and the CISO and the it and the data owner. And it just basically blows it up and it says, we're going directly into memory, putting the patch in, it's gonna, it's gonna eventually take place. Right?
You know, right as you need it. And that's it. And you know, no one's gonna have to turn things off and turn things on.
No windows, you know, we're gonna be closed. It's Christmas. And, um, hot patching is the way to do that.
You have to move slow. You need modern operating systems and, you know, uh, uh, devices. Um, but, and, and it was a little cranky at first.
Um, but Microsoft, to their credit, has spent a lot of time on this. And eventually this is gonna become their default. You're not gonna have a choice.
If you want patches, it's gonna go hot for, for a certain critical, like all the ones we've been seeing lately. No, I'm just kidding. Um, okay, next.
Yeah. How would you deal from the, from the business side where, you know, you, you buy a patch and then it starts breaking stuff all their application. And that's usually the, you know, the complaint that I get from, uh, Yeah.
So this, this company, it Broke. And, and sometimes it does, this Company I mentioned before, uh, they're not the most progressive company it wise. And they do have some, uh, they're an inside the beltway DIB contractor.
And, um, but they were getting hacked right and left. And I said, you gotta try this. Yeah, there might be something to break.
Nothing broke. Nothing broke. And again, their speed to catch bad it, they don't even measure it anymore.
'cause they're, they're patched. They are patched all the time. Okay.
Um, I'm not gonna spend a lot of time on this, but, um, in addition to the two ones I mentioned, earliers, this is what you're seeing ought to be doing. Analyzing the hell out of these events. 'cause these are the ones that I and other analysts and consultants look at.
Um, also, by the way, I noticed I had put this in, if you want advance auditing now, I'm just the messenger you have, you have to buy purview. Sorry, uh, what the two have to do in relation to each other. You can ask someone from Microsoft.
And then lastly, uh, this is a favorite of the, uh, next, this is a favorite of the intelligence community. Um, I think we were probably one of the first at CIA we wrote our own, um, to do this. But now you can actually go and buy one, uh, content.
You, you wouldn't believe how many, How much malware still gets delivered in PDFs and macros and VB script. I mean, a lot of them because they're getting better at obscuring the executable content, right? And tricking eds, uh, into thinking that they already check this label.
I mean, they're really good at it. There's lots of different ways. Um, I've been towing companies.
Anything that comes into your company has to be flattened. And it's, again, one of those measures that the bad guys will look for. You know, when they drop ACON package is, and is there any content disarming going on here?
'cause eventually I need to deliver them, uh, phishing emails or some type of way of moving files into their network. Um, and they don't like to see, you know, the CDR. Um, and the way it works is they both basically consider everything malicious.
I like the way they work. They consider everything malicious. Whether they, whether they can find something or not.
They flatten the file, which means it's, it's an image. It's truly an image. Now, everything in the, in the file is an image.
Um, and by the way, one of my clients who uses it consistently, I have a lot of other clients who've been calling me about AI poisoning and AI injection. And, you know, they're all worried about that. I talked to these guys and they said, what is that?
What we don't, we don't have any problem with that. We flattened in. It all comes in, it's all flattened.
We don't, we don't care. Um, okay. Uh, hopefully I left some time for questions.
I leave five questions. I think I did a few minutes, five minutes. Oh, thank you.
I missed you. Yes. So you were talking about the third party approach.
Yeah. It sounded like a jump box to a degree, but it also sounded like a jump box plus like some type of ZTNA. So is that the goal is to give 'em just direct access to the application, but never to the underlying server?
Yeah, it's, it's not really a jump box in the sense that the jump box itself is a computer that makes a connection on your behalf. Remember like the two card thing roll use, but it's still in the same computer. This is happening at a different abstraction layer altogether.
This is happening up in the cloud. Okay. And if you play your game, if you play it right and use the ACLS as to where they can go, once they're in their own cloud, you can tightly control what applications they get access to, uh, in your network.
When you do the gateway kind of thing, you're still establishing a lower level network connection between the devices. I don't want you to do that. But what if you have a cyber physical system and it requires a server, something that you have to get into, because that's the only way the vendor can access the equipment.
Oh yeah. They had some of those. So it wasn't, it it's not a hundred percent.
Okay. Yeah, they had some basically who needed native access with the native protocol into the network. That is true.
Um, but they also put them on notice and said, this is going away. So for the next contract, um, you have to figure out how to do this remotely from a cloud. Oh, Bob, can you repeat the questions So that, oh, I'm sorry.
So the question was, um, the solution where you bring the third parties into a, their own cloud environment that you run for them, you know, is this the same thing as a Bastion gateway? And there's some similarity, but actually it's, it's not because the Bastion gateway directly connects your network. I'm trying to keep you off the network.
I don't want them to see, here's what I don't want them to see. I don't want them to see the switch and routing infrastructure, because then they'll understand what to do. I'm trying to keep them so they don't even see the underlying network infrastructure.
And by the way, please, if you've done this the second you get back home, undo it. If you've made the cloud network an extension of your private address space, oh God, do not do that. I don't care.
It's Google. I don't care if it's AWS do not do that. Hopefully no one's done that.
Right. Good. So you've gone through a lot of windows.
Do you have any, uh, suggestions for Linux and container based? Yeah, well, my only container suggestion for Linux, and I was gonna like this, is you gotta turn on SE Linux deeper than the default, which I think is currently, uh, block mode maybe. Okay.
You need to have SE Linux covering all applications that make kernel calls. If you do that, go on to your next issue because SE Linux, the US government funded project works and works very, very well. And don't use App Armor.
App Armor, it's the first word is app. It's an app. Okay.
Yes. What about for organizations that are about 90% mad? Yeah.
Um, um, the trusted Mac TCB and the feature that they call, um, lockdown mode helps a lot. The problem is, it's still, it's a Linux, you know, it's native Linux, it's actually native Unix kernels and some of it's not very good. Um, but again, the notion is to keep them off, keep them away from, if you limit your admin exposure, you know, if you limit your network exposure, keep them out so they don't see your network, you're, you're gonna probably be okay.
Um, but it's, it's, it's hard. It is harder. It is harder to do, believe it or not.
I think we have time for one more. Yes. I noticed on neither one of your list included multifactor authentication, but you did bring up Beauty Key or all other image forms FA No longer.
I just assume everyone's using That's a good point. I probably shouldn't assume that. I just assume people are using FMA either application based applic, you know, uh, MFA, but, um, again, they'll, they'll work hard if they want to, to wait.
You know, what they do is they have code, uh, actually I saw this with Scattered Spider recently. Um, they actually have code that WA waits and watches for the MFA response to occur. Okay.
That's when they load the mod after, after you are a authenticated, it's when they load the, uh, malware module. So they know they've got a certain amount of time, uh, to use your session token to connect to ad. Um, so the fact that you have MFA is wonderful, um, but it doesn't really stop them.
You be key works at the hardware, kind of works down at the layer because it's exposed to the TPM. Right? And if you command, if you make them have to use it, that that, they're not sure how they're going to do that.
And number one, that session token that the UBQ uses is fully inside of it in the encrypted session itself. So, so they haven't broken that yet. Okay.
Yep. Okay. Oh, yeah.
Now We gotta start. Yeah. Okay.
And we're done, right? Yeah. Okay.
Thank you. Sure. Hey everyone, welcome to our special MLK Martin Luther King Day Special edition of Techron Gang.
I'm hoping a lot of you aren't working today. I saw a recent survey in Tech, 50% of the folks aren't working today. 25% are kind of on a light day and 25%.
It's sort of a normal day. I hope you're in those 50%, but you're taking time outta your day off to tune into the gang here and share a little, uh, special edition where we're gonna look at, you know, in many ways, Martin Luther King, what he was talking about in, in the 1960s is no different than what we were talking about in today, right? And a lot of what he said back then is just as applicable today.
So we're dedicating today's show to, to Martin Luther King. Let me, uh, introduce our, uh, gang members though, who are gonna be joining us for this special MLK edition. We've got out in the West Coast looking very dean like himself today, our man in the valley, John Swartz.
We've got our late car, he just got in, in here under the wire. Steven Foskett, Uh, where's that wire? It's right above your nose.
And then joining us is our friend, hope Lynch. Hope it's great to have you on and up in New York. Mike Ard gang, welcome.
So, as I said, this is about Martin Luther King Day and celebration of, of, uh, of his life, his legacy. And, and as I said in the beginning, it, it's kind of crazy when you think about it, but there was no internet, there was no cell phones. The tech industry wasn't anything like the tech industry is today.
But yet, a lot of what he spoke about is as true today as it was then. And, um, you know, Mike, I'm I'm gonna ask you to kind of kick off our first segment here, and then I have some quotes of MLK that I'd like to, to go with that. But why don't you kick it off, Mike.
So the first thing that kind of comes to mind is, you know, where are the ethics in this age of AI that we've been talking about for a while? And people are wondering if we're moving a little too fast, and, uh, are we gonna leave a lot of folks behind? And it's becoming a, not a technology conversation, almost a society conversation.
So, um, Alan, I know you've been kind of writing a lot about this over the last few months, but I would put it to you, uh, where is that line between what is just something that is technology and it gets used and well, it can be used for good or for evil, or is there some sort of moral obligation that goes with the usage and the adoption of new technology? It's a thin line, that's for sure. You know, let me, let me give a quote from, from, uh, Martin Luther King on this.
He said, our scientific power has outrun our spiritual power. We have guided missiles and misguided men. Now, as I say, you wanna substitute extreme wealth and power for, for guided missiles, because today so much more power is projected by, by wealth and technology than it is by pure military might.
But you're right, Mike, I have written a lot about this, and it bothers me in that I, i, I don't think we are always following the most ethical course. And we, we put profit above all else. Um, but I, I'm not the only one.
Steven. I know I have a kindred spirit there in you as well. So what do you think?
Yeah, I think that if Dr. King were still alive and it's too bad, isn't because it would be, uh, phenomenal to have a voice like that in modern times. I think he'd have a quite a lot to say.
I mean, if, if we want to turn this toward the tech industry, um, you know, the, the incredible, uh, inequality of, uh, technology both internationally as well as, you know, domestically and in developed countries, is it's pretty astonishing the ways that, um, this is being deployed. The ways that it is changing society, the attention or lack of attention being paid to various groups is just, uh, kind of mind-boggling. It's like nobody was listening.
Um, and the ways that this technology could be used to improve people's lives, but isn't, is another thing I think that he would have a lot to say about Agreed. John, you're out in the valley, and I don't wanna point fingers too hard, but there is this mindset out in the valley that says, you know, just tear down everything and yep, we'll be damned, and let's not worry about the consequences kind of vibe that seems to be coming outta, um, I don't know, Palo Alto and Sandhill Road and all those VCs are kind of banging that drum. And then there's, you know, almost, I don't wanna call it a cult, but there's definitely a mindset out there that kind of says, you know, this is the way we're going and society can figure it out later, but Right, right.
Build things as fast as Yes, exactly. Build things as fast as possible. They break, fix 'em later, worry about the consequences later.
You know, it's funny. Um, so Mark, mark Zuckerberg famously has always talked about that principle and essentially worked out for him pretty well. Well, um, maybe Apple's an exception, but apple's an exception to a lot of things that go on here.
But there is like that kind of mentality of, uh, grab as much as you possibly can. Don't worry about the consequences. And I think that has predated back even 10 years when Jesse Jackson had a, uh, famous push out here in the Valley for, um, addressing the digital divide.
Uh, DEI, in fact, when I was working at USA today, we did a panel with him at Stanford where we had a, uh, executives from Apple, Google, Twitter, and I believe I wanna say Facebook, and all of them were just hired. All these folks were just hired to address all these issues. And I gotta be really blunt with you, um, within a couple of years.
And they were all gone. They all had left on bad terms. And it was interesting because the timeframe I'm talking about is when they did this push, it was 2014 when Obama was in office by 20 16, 20 17, they were all gone because somebody else was in office.
And, um, we've been there since. And I, and I remember getting in arguments with Mark Andreessen about this. He just dismissed this.
But then again, he has a long history of saying really racially insensitive things. And I, I will, I will say that over and over again, it's been proven. Um, it's, it, it's too bad, but you're right, Mike, you point the finger here and it's, it's something that people here have to look at.
But again, they're still obsessed with making money as fast as possible and grabbing powers fast as possible. Everything else is secondary. John, I have a, a question since you are, you know, the West Coast correspondent, um, so California passed, um, AB three 16, right?
I think it took effect January 1st. That says, you can't argue in court any court that something that AI does is just the AI and that the organization itself is not responsible. Right.
So I, I just wonder how, how sticky will that actually be? Yeah, that's a good, that's such a great point. Hope, because I was thinking about this as well.
We, I think on a show last week, we were talking about whether AI is a person or a machine, and I think Like corporations are considered people. Exactly. You just read my mind.
Exactly. And I'm wondering, is there going to be a case that involves this law where in a sense, the person behind the AI or the AI itself is gonna be blamed? And I think that's gonna be such a precedent setting event.
Um, and it's gonna happen. Uh, it is. But I'm glad you brought that up because I had, I was thinking about that before we went on.
Well, I, I question whether that's superseded by the executive order that, uh, states can't legislate anything with ai, that it's being carved out for the only federal, Right? Yeah. So Let me, let me tell you a story that, about that, because it turns out that neither party is very good in this issue, no matter how you look at it.
'cause mm-hmm. I was talking to a consultant here in New York last Friday, it'll be on a future episode of Textron ai, and she was pointed out like we in New York passed this LT called the RAISE Act that had all these stipulations for the usage of ai. Mm-hmm.
And then the governor signed, said bill three months later, but she pointed out chapter by chapter, the bill that signed did not resemble anything that was actually passed by the state Senate. And basically all of it had been gutted because there was all this backroom lobbying going on, and basically a democratic governor signed a raise act, took credit for trying to protect people for ai, and then it turns out that, you know, the ACT itself is now virtually meaningless. And it just seems we have a total absence of political leadership on the left or the right when it comes to this stuff.
One of the things, Mike, I'm sorry to interrupt. Um, one of things No, go ahead. Is that the, both of these parties don't understand tech.
They never have. That's why they're so bad at, at passing legislation or, or even passing it, period. On a federal level, forget it on a state level, there are some pockets of folks who know what they're talking about, but by the time the lobbying efforts are over the laws, the the bills are watered down.
Um, a very strong lobbying effort by by tech. It's, they're very effective at this. And the politicians really don't understand, in a sense, I think they are sometimes compromised.
I'm not, I probably shouldn't go into that, but I think they're compromised based on where they're based and who their constituents are and whether they have investments in some of these companies, which is a real thing. So I'll, I'll pass it. Yeah, no, we, we need reform in that.
But let, let's get back to Dr. King and, and the root of the issue here, and it's around ethics mm-hmm. Around doing the right thing mm-hmm.
To quote Spike Lee. Right. Um, you know what, let me go.
I'm gonna give you some law school stuff. And law school, they have the concept of mens rea, right? What your mind, do you have a guilty mind?
Do you have a mind? In other words, did you do this on purpose willfully? Mm-hmm.
Or was it negligent? You didn't realize it. A reasonable person may not have done that, but it was, it was just negligent.
It wasn't sorta purposeful, willful fault. It's very, you know, at this point, we've sold the guardrails and told ourselves it'll be okay. This isn't, you know, something is going to give, when we talk about income disparity and security around ai, which we're gonna talk about and, and some of the other things that are ailing us as a society and a civilization today with our latest tech.
But the point of it is, is when the stuff does hit the fan at this point, it's very hard for this tech bro culture. And John, you talked about what's going on, Mike, you referenced it. Hope you referenced it.
It's a tech bro culture, right? They overwhelmingly support a lot of what the administration wants and does. It's this tech bro culture.
Are they gonna have the nuts to stand up and say, this one's on us. Yeah, we were wrong. You know, can I, can I, um, so when you mention the tech bro culture, I think of them also as politically expedient.
They do whatever benefits them. So there's the infamous photo, and I brought this up before. There's the infamous photo of, um, Obama being flanked by Jobs and Zuckerberg where he is in their, in their realm.
He is one of their advocates. He is very strong on the tech side, and they, and, and they played it, they played it really well. And then you flash forward to Trump and they're doing the same thing.
And I think to them, it really doesn't matter. They're with the exception of perhaps Tim Cook. And I even start, I'm having my doubts about him too now, is they just play whatever the, whatever the party in office, the office, the, the, the, the party that's in Power wants, and they play the game and they manipulate these guys so well, and they are manipulated in turn.
And I think that's what's happening. So for instance, if we fast forward to a couple of years to a new administration, perhaps it's a democratic administration, you're gonna change your tune again and try to whitewash the past. Yeah.
Steven, what would Dr. King say about the tech bros and, and this headlong rush, you know, damn the torpedoes and damn the common guys? Well, I not sure I can put, uh, words into his mouth.
Uh, though it seems in our current culture of carelessness, people do often, uh, put words into others' mouths. Uh, but I think that if we study what he had to say about things, I think that he would have some pretty big questions about what we're doing with AI and with technology. Um, you know, he would question, I think whether, uh, AI serves human dignity, um, whether, as you said, whether our scientific power has outrun our spiritual power, I think he would ask what it means for marginalized people and inequality.
Uh, you know, he talked about what he called the giant triplets of racism, materialism, and militarism. I imagine that he would have quite a lot to say, maybe even a, a fourth triplet when it came to sort of our techno, uh, utopian world. And I think the biggest thing that he would wonder is about, uh, justice, because I think it's important to remember that King wasn't about equality per se.
He was really about justice. This was a religious person as well as a philosopher, and he would ask whether the current sort of techno, uh, utopianism focused on, um, efficiency above all else, and maybe objectivity, which is how they like to phrase it, is really, um, going to serve the needs of justice, or whether it's going to be something that would be more, um, you know, anti, you know, anti justice moving us further away from that. So I, I think that, uh, these are all things that we here, but as I said, I feel like our current culture is, um, just anti thoughtful.
You know, it's like we have this, uh, focus on, in the name of objectivity and in the name of, you know, efficiency. We, we don't want to ask ourselves these questions, and in fact, we want not to ask ourselves these questions. Hey, Steven, let me give you a shout out here.
So while you were doing that, I, uh, actually went up to, uh, Gemini, and I asked it, what would Dr. King say about ai? And sure enough cited, you know, while it said that Dr.
King wasn't around for this AI stuff, he probably would've equated it to militarism and materialism. So 10 points for you. Well, uh, there we go.
There's a great example of, uh, ai, uh, confidently putting words into someone's mouth. I'm sure that if you ask, we'll create video of him saying that. What, you know, since you say that, I don't, I don't know if any of you recall, but when OpenAI released soa, right?
Mm-hmm. Everyone started making, everyone making videos, AI videos of various people including Martin Luther King, uh, some with him eating, uh, seafood with Malcolm X, other things. But his daughter put out a statement that says, you know, please stop doing this.
So OpenAI, um, they responded and said, you know, we're gonna pause MLK generations while we strengthen guardrails. But this actually is an example of how ethics around this are working in practice today. In certain cases, they ship the product without the controls deploy first, right?
Then, uh, harmful or disrespectful content went viral. No one intervened harm occurred even, you know, as it wasn't a living person, but to, um, his, his children and his descendants. And then the controls were only added after there was, you know, an outcry and a complaint.
Right? Right. No, Because we living a running man.
Did you ever watch the movie The Running Man? Yes. We live in a Running Man society, right?
Yeah. If everyone's going to get the best TV ratings or the highest popularity in the polls, right? Mm-hmm.
That's what gets, that's what gets their attention. I don't know if it's the Hu Hunger game it Running, man, one of these things, it's Subsequently open OpenAI, uh, signed the deal, uh, with Disney around Soar, isn't that correct? Yeah.
Their content, they learned their lesson, I guess, didn't they? But, But the guardrails that they put in place aren't worth the damn, I mean, they're just easily end run. They're not rail guardrails.
Right. It depends on how you ask sometimes. Exactly.
But we, we need, we need to keep moving guys. We're, we're 18 minutes into this one and we gotta jump to the next one. Our, our next segment is really about the ai, the so-called AI economy.
And make no mistake, it's an AI economy where we're spending trillions in CapEx, trillions in CapEx that are generating maybe thousands of jobs. That seems like a disconnect. We've spoken about that here, right?
2 billion data center that generates 37 full-time jobs. Um, again, this is the kind of thing Dr. King wrote a lot about, spoke a lot about right.
Income disparity, the dignity of having a job, the dignity of being able to earn a living. Right? Not everyone maybe is going to, you know, be in the top 1% or even top 5%, but where it, it just seems, and I think, and I'll, I'll say it and you guys can disagree.
I think that's the, this is the single biggest issue confronting everyday folks when they hear the term ai, they cringe. Mm-hmm. They equate it to a loss of jobs.
When you Think about does favor capital over labor, though, I mean, um, the IMF, they did a study and they said, um, based on their study, AI adoption increases wage and wealth in inequality, right? And the returns flow to a very small group of high capital investors. You know, when they, when we looked at, uh, the, the difference between the everyday worker and the CEO of the company they work for maybe even a couple of decades ago, that there, there was a, there was a big gap.
I don't know. I, there was a number I, I think I, I read in a book recently where it was something like five times, now we're up, we're talking about 40, 50, a hundred times, and it's just gonna get wider and wider. And I think that when they start building these data centers, and they will, and we create these choice of dollars, and when this happens and few jobs are merited, there's gonna be even more outcry, especially among the people who voted in this administration thinking they were gonna be getting manufacturing jobs and having a more affordable life.
I think it's just gonna be more pronounced than them. So I have friends who are worried about that, but at the same time, they also have 4 0 1 Ks that are heavily invested in Nvidia, and they kinda look at that and they go, wow, I'm making money on this. This is great.
And I'll come full circle on this. 'cause there is this conversation going on about whether we're gonna need this, uh, universal basic income thing, which oddly enough is something that Dr. King speculated on many, many decades ago.
But how to fund that. Well, the only way to fund that in my mind is for the US government to become a bigger shareholder in the technology companies that are creating all this stuff to, so at that point, then everybody's kind of an owner of these companies. But, you know, if you look at that, that's a form of socialism.
So, I don't know how this goes, but Alan, what do you think? You know, Mike, I don't disagree with you. I, I, you and, and people you know, who are more popular than Mike Azar and Alan Shimel have speculated on this one.
No, There's nobody Like that. Yeah. There's a few, a handful at most, Steven, but, you know, like Elon Musk, right?
Elon Musk says, with AI and robotics and everything, it's gonna be the end of poverty, right? The end of poverty. We're all not gonna have to work.
So let me get this straight. We're not gonna work, but we're gonna end poverty. And it'll be like, you know, heaven on earth, it sounds like, you know, we should be looking for Jesus in Jerusalem or something.
Is He also, is he also talking about creating these jobs that we still don't know what these jobs will be, these AI related jobs that are gonna create this new nirvana? He, he is just saying, there's no jobs, man. Everybody's just, No, he's saying there's no jobs.
It's like a Star Trek. You know? It'll, it'll be the current state, right?
It'll be a releveling of what it means to not have a job. Well, in that case, maybe it's right, but, but it, you know, it begs for it like a basic income and you could go pursue your, your higher ambitions. But you, you know, what's interesting is, during Dr.
King's time, he very clearly, and I have the quote here, the problem of race is inseparable from the problem of economic injustice. Because to be, to be, and no disrespect to anyone, but to be black in 1950s America or sixties, America made it triply as hard, 10 times as hard to be economically empowered. I don't think we're quite as bad as we were then, though.
We're far from perfect today. There's no doubt about it. Right?
But today, I think that line cuts across race. And we also gotta talk about gender, right? We gotta talk about where you live, even within just the US itself.
Um, I, I think we more than ever, and and AI is accelerating this, the, the income disparity and the, the gap between the have and the have nots is, could ultimately ripped this country apart. Well, you know, and sadly, what brought Dr. King to Memphis in April of 1968, was the garbage worker strike.
Yeah. And that was his concern over jobs. And that was what happened.
And you know what part of the, Sorry. Well, part of the reason that we're not seeing as much outrage just yet is that a lot of these jobs that are gonna be eliminated in the short term in people's minds, they're white collar jobs. They're kind, I like the tech is gonna wipe out, you know, clerks and all this other stuff, or whatever it is.
But if you look at where this is going with robotics and with speech interfaces, the next big wave of jobs being wiped out by AI will be blue collar jobs. And so will become a much bigger issue. I was talking to this company about, you know, all the people who take your orders at Starbucks are gonna be replaced by speech interface with ai.
Oh, it, it's happening at, it's happening at fast food places. They go to livestock, good places. They, Hey, you know what?
In Amazon, in Amazon, I hate, hate to break this to you, but Amazon's looking at robotics on a massive scale within their warehouses and manufacturing and delivery. And they're starting to lay people off. So it's happening.
Microsoft do the same. Hope you, you were gonna say something? Oh, just that I think, I think it's hit a a point in society where more people are concerned about AI now, because it's more visible.
People are seeing how you can create art. You can write, you can do all of these things that are more tangible and more relatable to more people. But AI has been causing harm for multiple years.
Right? Um, uh, AI takes on the ethics of the people who build it, right? There is not really much voy around that in many organizations, but people who have been denied loans, been denied housing, been denied jobs for many, many, many years into the past.
This, this cuts across everyone. But now it has reached a point where it feels to more people, like it touches them. It's not as invisible as it as it once was.
So perhaps that will cause change. But again, you know, how much, how much pain do we all endure before that change happens? I, if AI takes on the ethics of the people who built it, hope, um, that doesn't sound like a very optimistic projection.
Um, Right. I'll point out that one. Um, one of the great modern theorists on AI is not, is Tim Ni Gabriel, who actually was involved early on mm-hmm.
With the creation of this technology and now is outspoken. In fact, she's one of the people I think that most closely mirrors, uh, Dr. King's concern about the, the fact that AI is causing, uh, job loss.
Uh, she's spoken about the invisible labor, you know, the third world content moderation problem, that sort of thing. You know, the issues of, uh, lack of access and exploitation of people in the south, uh, job displacement. All of these things I think that Dr.
King would've had a lot to say about, but to the point that Mike made earlier, why aren't people saying this? Well, to quote, uh, Upton Sinclair, one of my famous or fa favorite quotes out there, uh, it's difficult to get a man to understand something when his salary depends on him not understanding it. And I think that that's the, the situation that we are in, in a bubble economy when so many people are economically motivated mm-hmm.
To get on board. Because as Mike pointed out, so much of our money is dependent on the success of this project, that we aren't willing to have these conversations. Now, some people are, but many people are not willing to have these conversations.
And I think that that's, uh, detrimental and concerning for all of us. I'll go one step further. It's not the algorithm.
It's the data itself reflects the biases and the injustices that have been going on for decades. And the algorithm is just surfacing it in a way that we can all see it and experience it more readily. But, you know, if, uh, it's not the AI that came up with the recommendation to say that, let's not give this, uh, person alone because they live in this neighborhood.
It was, that's been redlined into the loan process for decades. It's just been automated. Well, you know, who would agree with you on that is Elon Musk, which is why he created an alternative set of facts to train the new gro on, because he felt exactly the same way that this core information was biased against what he saw was the worldview.
And in his point of view, the bias was leftward. Yeah. There you go.
Are, you know what they say? Fact History is written by the winners that lovely, you know, know who, who's, who's writing this history would remain still to be seen. So let it be written.
Um, look, it, it, we could argue about this and talk about it all day, but the fact is, as we sit here, that disparity gap continues to grow. And in a country where we have mass men pulling people over because maybe they speak with an accents or their skin's brown and people are protesting by the thousands, this, this isn't something that's going away. I I just, you know, I feel like we probably are closer now to what Dr.
King faced in the sixties than we have been in. What for me, was the whole, my, the entirety of my life, right? I was a very young boy when Dr.
King was assassinated. And I, I always felt like the arc we were making progress, positive progress in this. And, and, um, I'm not so quite sure we are anymore.
I'm just not, not to be pessimistic, but, You know, can I, maybe, maybe there is a silver lining in all this fear of ai. Maybe it, it's lighting a fire under people and bringing to bear some of the things they've been thinking is subconsciously now it's affecting them directly. And so they're acting.
I mean, there, there is a, there is a very thriving protest movement now. And I wonder if that kind of, in a sense, fuels the anger, the anxiety that, That I think it fuels anger and anxiety. And that brings up another issue that we can talk about during this segment, which is, you know, technology was supposed to bring us closer.
All of us tech folk, we talk about community, we love community, yet we're more alone than ever. We have no one to talk to. But some ai right?
Talks back to us if maybe tells us what we want to hear or whatever. It tells us what to do, right? What No, what we should be doing.
Right? So is that another failure of our technology that in instead of building communities, we we're, we're more islands than ever. Yeah, it is, it is sad, isn't it that, um, the technology that, you know, when I first got onto this train, I was excited to finally find peers, people who were excited about, I don't know, uh, German industrial music and lemurs and role-playing games.
And now, uh, people have communities of people who believe that the world is flat and birds have been replaced by robots. Um, you know, there's, I guess there's a community for everyone. Um, and unfortunately that amplifies and makes, you know, really unusual, uh, beliefs seem maybe mainstream.
Okay. You know, that, that's why my job, I remember when, when the Macintosh came out, it was the computer for the rest of us, this whole idea that we're, we're gonna be inclusive. And this is kind of like this Hindu LSD vision that jobs had from his wanderings.
You know, he kind of tried to apply it to technology, and we thought the same about the internet, and may maybe edit early time when we, in our naive stage, we thought social media would connect us to people and drive a deeper relationship. And in a sense, what has done, I think is isolated, is more than ever Driven a wedge instead of, uh, driven connection. But it is, but it is partly, um, maybe diverging, but maybe on point.
It's partly due to the easy amplification, right? One person can make a post on threads, someone who is not famous, no one has ever known, but it can generate thousands of comments, thousands of likes. And that person, no one knows what they do for a living, who they are, whether they are who they say they are, but everyone engages with it, gets angry or inspired or whatever, right?
There is an, an, an outside influence now of, of one voice for good or bad. Agreed. Hey, we, we need to hop into the next segment here.
And, and you know, we, calling this one, security is a civil right? I, I did some shimmy quotes on this, right? You know, we've gotta stop lying to ourselves.
Real security on, on an organizational basis seems to be only affordable by the Fortune 500. And that doesn't make cybersecurity protection. It's a country club, right?
Because we're build, if we're building a safer digital world, or we just building a gated community with better firewalls for those who can afford 'em. And, and you know what security, to paraphrase, Hillary Security is a human right, or could, should be a human right. And we all should be entitled to some modicum of digital security as well as perhaps physical.
Steven, I'll throw it to you first. Sorry, I am woefully unprepared To, okay, you know what, think about it. We'll come back to Mike.
He's got his hand up, Mike Hand up. I'll pause with the following. So the original sin was the creation of the internet protocol without any consideration for security.
So we wound up wrapping around all this additional gateways and everything else around it to make it secure because bad people were using it to attack us. But now we're also using those same security protocols and the same concepts to, well, and for some level of, what do you wanna call it? Privacy or censorship or whatever it is.
But that's how we create these little guardian communities around things, communities. And then that's how we wind up not talking to each other and building a global community because, well, we have the great firewall of China all because we didn't think through the fact that we needed maybe better security when this whole thing started. So let me get this straight.
The Irish Catholic is blaming it on original Sid. There you go. Boy, somewhere in Cardinal Spelman.
They're really, they're saying that's our, that's our Mike Baard, that's our Mike Baard. All those years were not wasted. Sister Thomas Regina's very happy.
Uhhuh Sean. Hope. What do you think about security as a civil right?
Um, I think we are at a point now that that is, I feel it's, it's not really considered as one. And it's, and by the powers that be right, it's, it's impinged on more than ever because, um, CISN, right? Cisa, their budget was cut.
That money was shifted over to ice. Ice is using that money to buy in part cell phone tracking data so that they can follow people, find people, they're scraping social media. Um, so basically private citizens are being stalked by the government just in case you are someone that, that they want to target, right?
So me being stalked by my government does not feel like, um, security is a civil right. You know, there are more, the more, more cameras in, in, in, um, operation now than ever before where ba basically, this is like a surveillance state. Mm-hmm.
I mean, I think we're all considered data and the companies want to get as much, they wanna squeeze as much data out of us as possible. So therefore, I feel as if I'm a target. I think we all are targets, not in a nefarious way, but in fact they're trying to get inside our heads to try to sell more product to us, or try to exploit us.
I mean, this, it's, I mean, it's, it's, it's, it's so strange. I mean, we're, we're, it's like 1984 on steroids and AI's gonna just accept, accentuate things. And, um, How Do you reconcile the following though?
So, common law says, you know, your house is your castle, and everything that goes on in there should be private. But everything that goes on outside your door is in the public domain. So if someone, if you're on the internet, a public resource, and you are, uh, you know, bouncing around on this public recourse thing, your neighbors can see it.
And so can the local city officials and everybody else. What makes that, um, any more illegal than I, I, I I going to disagree, Mike. Your right to privacy doesn't end at your front door.
All Right? Now, the current Supreme Court has real issues with right to privacy, right? We've seen that in their finding in their recent case law.
But there was one time in, on a place, in a place called Camelot, there was a constitutionally recognized right to privacy. And that right to privacy was extended beyond the four walls of your domicile. It it was inherent in your humanity as a person.
You have a right to privacy. So you're gonna, you're wrapping that up under what life, liberty, and the pursuit of happiness. 'cause last time I checked the founding fathers didn't say squat about privacy specifically.
Well, the, you know, uh, I'm not gonna play law school professor, but there's a, there is a long lineage of case law around a right to privacy as being in, in included within your basic human rights, you know, life, liberty, and pursuit of happiness. Yes. Un unfortunately, we live in the Truman Show.
This is, that's really happening. That movie was so prescient. True.
Show everything we do or say. That's why, in a sense, I mean, almost, I almost kind of, uh, create a, a, a walls around myself sometimes in social media. I almost go outta my way to, to not share many, many things I do anymore.
It's like a tracking system. And I have friends who post things about what they do every day, so I know exactly where they are, what they're doing at that very moment. And, uh, there was a time where I probably wouldn't objected to that.
But given the circumstances and the times in which we live in now, I, I think I should err on the being careful about, And I, and I will also say that, um, as with, as with all things speaking, only as a person who lives in and the rules of the United States, right? 2018 Supreme Court, um, carpenter, the United States, getting historical cell phone records from carriers requires a warrant. Court recognized that everybody was like, okay, so now that, and a loophole is being exploited, there is a data broker industry, $300 billion a year.
Um, there are companies that aggregate location signals and will sell them. So, as some people have said, if there's a particular crime you want to commit, you probably need to drive an old car and not take your cell phone with you because everything is connected to something. And those, those violations of privacy are often tied back to, um, federal government, local government and precedent, not necessarily to corporations that are accessing and selling the information.
But, you know, I think, so I'm a big believer in the social contract theory mm-hmm, mm-hmm. Of, you know, modern civilization. I think people by their actions have accepted that acquiesce to it.
And to me, it's a case. I forget to quote Benjamin Franklin, if you are willing to trade something for something, you have neither Mike, you probably know this one. It is, Um, if you're willing to trade liberty for security, you have neither Right.
And or security for liberty. You have neither. And I, I think there is some of that certainly going on.
Steve, we gave you, Steven, we gave you a chance to stew for a while. Any thoughts you want to add? Thank you.
Uh, yeah, I would just want, I would just want to kind of respond to some of the things that hope said and kind of amplify them, because I feel like that's, that's really the, the key here. Um, I think it's ironic that we don't have an explicit right to privacy in the United States. In fact, um, we have legal rights to security that are far stronger than our legal rights to privacy.
Um, you know, that there are specific, uh, national and state laws relating to information security, and there are not relating to, uh, general personal privacy. Um, but, you know, getting back to the whole, you know, Martin Luther King subject here, um, you know, one of the things that he famously said, uh, was that a a right delayed is a right. Denied.
And I think that what he was trying to tell us there, and I think that maybe this is applicable to the state of security as a right, is that essentially, if we are willing, as you say, to give these things up, then we are, you know, or to delay them or to say it's not expedient to enforce copyright when we're trying to build ai, or if it's not expedient to, uh, keep, uh, bad actors from, um, accessing our information or to keep data brokers from sharing information, then, um, we've essentially given up those rights. You know, we've essentially said we don't have a right. If we're willing to allow things, you know, as to your point about liberty.
And if we're willing to allow things to happen, then we are giving those things up. Yeah. Yep.
Guys, we gotta keep it moving and wrap this one up. I, I want to, this is not on our script, but I'm gonna throw it out to the panel and interested in your thoughts. You know, the, when you look back over the history of the United States, it's remarkable.
Small group 13 colonies, ragtag army took on the greatest power of its time and won their independence. And it was because whether you believe in God or some other deity, or no di deity at all, uh, men emerged, men of their time emerged to lead the founding fathers, George Washington, right? Extraordinary men.
Abraham Lincoln at the time of the Civil War, uh, uh, Teddy Roosevelt, Franklin Roosevelt, right? We, we have been a blessed nation in the sixties, Martin Luther King, the Kennedys, though, you know, all three of them lives ended too short. Where's the next Dr.
King, where's the next Abraham Lincoln? Where's the next great American leader? You know, I Think, or do we not need one?
I don't, I think those people, I think those people don't go away. I think those people do exist, but in today's attention economy, it's harder for those people to surface. Yeah.
And exert the type of influence that there was. Then, there were th maybe three channels on television then. Yeah, everyone had a newspaper and magazines and reading.
Actual reading was, was more of a pastime. But now, if you don't capture someone within the first few seconds, they may not hear the rest of anything you are saying. So getting a platform that is large enough and durable enough for that person to make an impact, I think is a lot harder.
Yeah, absolutely. The European Union, Fair enough. Enough.
What hope that, what hope said is like that. There, there are more. There are just as many of these folks, we just dunno who they are.
They're on a grassroots level. They're not on a huge national breakout level. I mean, like, as you said there before, there were three major networks.
Now there are thousands of channels. There are opportunities. They're out there, they're doing podcasts, they're doing substack, they're out in the field, they're, they exist.
We just don't see them on a large mega scale. And each to Kate hope's point as well, I mean the, the, the, the eco information economy is so fragmented that I think people would say that there are great theorists out there and great leaders out there who are saying, you know, great things. And unfortunately, though, the information bubbles mean that some people are out there saying, you know, uh, somebody like, um, Donald Trump is a great philosopher and leader who's, you know, driving Worthy of no, no peace prize.
Somebody might say, you know, no, no, no, it's, uh, you know, a OC or it's maybe Bernie Sanders or somebody like that. Um, you know, some people who are extremely plugged in, uh, like me might say, no, no, no. I mean, I love what Ken White is doing with Pope Hat.
You know, I mean, things like that, you know, we got all these, these people that are influencing us, but there's just not that sort of breakthrough ability to pop all these bubbles and get us all on board. And that's challenging. Is that gonna get any better or worse going forward?
'cause it seems like we're seeing more centralization of the communication channels. Oh, I, I think that even with, even with that, I think, you know, let's go back to the, to the AI topic, the algorithm, um, what you engage with, you get more of, right? Um, years ago, it wasn't about engagement, it was just, this is the discourse, right?
And, and you hear it. Maybe if you, if you want, or if you don't want it, it's there. Whereas now, it is easy to turn away and find a perspective that echoes your own.
You don't have to change unless there is just some immovable force that is going to force change on you. I'm waiting for the move. I'm waiting for the anonymous moment.
Remember when the book anonymous? No. Yeah.
Those, those, those guys have given up. Yeah. I'm expecting, I'm expecting somebody to, through AI to create a book that's a major breakthrough, and everyone's gonna wonder who did it.
And it's gonna circle back to some sort of weird AI voice. I don't know. I think that the six digital representations of myself will engage with the world while I'm sitting in my backyard watching the two channels I can still get with my rabbit ears.
You know, he might be AI right now. Alan, you might be. He might already be.
He's a plant A plant. Hey, gang, thank you for joining us here on, on this holiday. We appreciate, I know it's a, it's a day you want, maybe you wanna spend with family or enjoying or reflecting, but I'm glad you came on here to reflect.
We hope you've watched oh, you've enjoyed this reflection and kind of juxtaposition a bit of what MLK would do if he were here today and what it means. Um, we, I don't know if we're gonna have, I think that's all we have today. We're not publishing on any of our sites, so there's no new news up there.
I don't think we have a text on TV feed going today. But Stephen hope, John, Mike, thank you. Thank you for watching.
We'll be back tomorrow live at 10:00 AM for regular Textron Gang, if there is such a thing as a regular Textron gang. Um, but until then, enjoy your holiday and, uh, you know what, you've gotta respect even after all these years, he's still relevant. Uh, Dr.
King, bye-bye everyone. Hey everyone. Welcome back here to Techstrong tv.
My next guest is Scott Brighton. Other, uh, Scott is the co-founder and CEO of a company called Kilo. I believe it's Kilo ai, and we're gonna hear more about that in a second.
But let's hear more about Scott. Scott, welcome to Text Drunk TV, man. How are you?
I'm good. How you doing, Alan? Good.
Um, before we start, you know, before we talk about Kilo, let's talk a little bit about you, Scott. You're the co-founder and CEO there. What, what's the story?
What's your story? Well, My story, um, so I am based in the tech hotspot of Washington dc Um, mm-hmm. I guess for former former life, um, my kind of first founding experience, I started a data and analytics consultancy called Brooklyn Data, um, implementing, uh, data strategies and tools like Snowflake.
DBT kind of built that up from, Let, let me just ask a stupid question. You didn't do Brooklyn data in Washington DC I started, Started in Brooklyn, so, alright. I, I am, I started in Brooklyn too.
Perfect. Born there. I started my Brooklyn apartment where I was living at the time, pre COVID.
And then March, 2020 I scoodle down to, to Washington DC to get, um, free babysitting from my parents. Well, that, that's always, Hey, look at the cost babysitting. It's, it's a good deal.
The, uh, yeah. So I started, um, Brooklyn data, um, essentially helping companies navigate, you know, the modern data stack. Um, built that company, uh, to about a hundred people and sold it.
Um, very cool. And it was, it was a fun experience. And, you know, after I sold and and left the company, I stepped back, I was like, shoot, was that like the biggest thing I'd ever be a part of?
And not just building the company, but just like this, like transformational wave of the modern data stack where everybody, you know, who was working with data, who's kind of like life was transformed. Um, and that's when I met my co-founder Sid, who, who kind of, we got connected and, um, started talking about Kilo and and agentic engineering. And I was like, aha, you know, I will be part of something bigger and it will be 10 a hundred times a thousand times bigger.
And that's kind of, you know, AI in the agentic engineering wave. And so it's kind, this is the, the second wave I'm riding. I love it.
Um, you know, you're right though. You, uh, no one wants to hear that they peaked at 32 and it's all downhill from there, you know? Uh, I, I get it.
And then of course, you, you referenced your co-founder Sid. That's Sid Subandi. Mm-hmm.
Right. Uh, and our audience knows, well I haven't had Sid on the show in years, actually, I'll tell you the truth. But of course it, Sid surround was the, uh, founder of GitLab.
That's right. And Sid and I go way back to when he founded GitLab, actually we used to. Wow.
Yeah. I used to go and we used, I forgot what they used to call it. Not GitLab days, whatever their user conferences were.
Yeah. They were small. We actually did one in Brooklyn together.
Oh wow. Okay. In Williamsburg at the Williamsburg Hotel.
Cool. Back when Williamsburg was just starting to be cool again, you know, and, Uh, I remember that. Yeah.
And we did in San Francisco. I used to sit on here every other month. com.
Yeah. Early in the DevOps revolution, if you will. Uh, so give Sid my regards.
Don't myself. Hi. We'll, I'm chatting with him right after this, so, so I'll let him know.
You said well, alright. I said hi. Um, so let's talk about Kilo, right?
Kilo do ai. What's that about? Cool.
Well, kilo is, um, the most popular open source coding agent. Um, we're an agent engineering platform that helps, um, kind of engineers, uh, you know, move at, you know, what we effectively affectionately call kilo speed. Um, okay.
Which is, you know, I like to to describe kilo speed as you're driving to work. Uh, and you only hit green lights. And that's like the feeling that we feel like you should get while coding, especially with ai.
And that's kind of our mission is to enable kind of engineers to move at kilo speed. I love it. What a great way of explaining that.
Man. You know, I live down here in South Florida and it's seasoned down here. All those folks from Brooklyn and Greenwich and everywhere else you're Hitting a lot of red Lights.
I'm hitting a lot of red lights. 'cause they stop. If the light looks like it's gonna turn yellow, they stop breaking and, um, yeah.
It's crazy. But anyway, how, you know, 2025 for many of us in the industry was going to be the year where Agen AI kind of takes the spotlight mm-hmm. From generative ai.
And as we, as we sit here on the cusp, you know, well, it's not just the cusp, we're, we're in 2026, I think a lot of us realize that our agentic experience in 2025 left a lot to be desired to say Agreed. Yeah. Why is 2026 gonna be better and how does Kilo make that happen?
Yeah, I think that's fair because you see all these articles of, you know, you know, people actually moving slower with AI or AI projects failing. Um, and I think what we've seen when we look around is that, um, the, the promise of AI isn't, isn't kind of clicking because, um, the tools are kind of working against us. And so, you know, if I look at, so say like the, I guess the, the cursors of this world, um, that are essentially mm-hmm.
You know, I would say selling, uh, subscriptions for a consumption based product. And so the dynamics are, the more you use cursor, the more a cursor loses money. And so they're essentially throttling you when you hit a certain limit.
And then you kind of go to, you know, what I would say, you know, like the captive, um, agen engineering platforms like Claude Code, which again, great platform, but, um, we kind of feel like it's, it's silly that you would be wanting to kind of anchor yourself to just a set group of models. Um, and, and you know, we're finding that people aren't having the right model for the job. Um, you know, Aquila, we've got 500 models.
And then the last thing is, you know, when you've been using VS Code for the last 10 years to develop and you know, your company's saying what and Admit it S codes great. No, absolutely. I'm sorry.
I'm sorry. And you know, when your company says, Hey, you need to switch to this other platform for AI and you know, you know, of course you're gonna have to learn a new tool. You've been using the same tool for the last year.
And so where Kilo differentiates his, you know, pay as you go, no throttling ever, you're never gonna be working late at night hit, you know, be pushing on a deadline and all of a sudden your context, you know, window compresses because you've, you know, used too many premium requests. You can use any model you want from the latest and greatest to kind of open weight models that are much more cost effective. And then you can use any UI you want from VS code to JetBrains to CLI cloud agents App Builder.
Our goal is to kind of meet the engineer where they are not put red lights in front of them. 'cause I, I think that's what the theme of 2025 was. You know, companies kind of, you know, software tools waving, hey ai, but really just putting a lot of unnecessary friction.
And so, I mean, that's our mission is just to reduce that friction through an all-in-one agent engineering platform. I love it. You know, there's another aspect though, to Kilo in the Kilo mission and it, and it's very, um, very similar to what Sid did with, with GitLab.
Mm-hmm. Because when you look at, and I happen to know this 'cause I've interviewed Sid a lot of times. Right.
But when you look at Yeah. Sid's background, even before he had GitLab, he was all about open and open source. And that is really kind of woven into the DNA of kilo as well.
Exactly. Talk to us about that, Scott. Yeah, I mean, I think like, um, openness is just so core to who we are at Kilo.
And, and, and for me it comes down to I would say three, three main reasons. And I guess the first one isn't even unique to Kilo. Um, Sid and I are big believers that, you know, when you build in the open, you build better.
I mean, and, and frankly, you know, when you talk to kind of founders of, you know, open source, open core code available, um, products, um, they kind of talk about this flywheel of, you know, you know, we get great transparency, great relationship with the community. The community actually becomes our extended engineering team like Aquilo. We're constantly getting contribution from individual engineers and large companies that one do kind of tweak and, and kind of get te kilo.
And so I think, you know, first of all, it's a superpower for any open source company and, and, um, I've really seen the benefits at Kilo. Um, I think the second is maybe a little bit more philosophical is AI is is like this amazing transformational technology that, you know, I feel like will impact every single human on this planet. Uh, I'm a big believer that that shouldn't be locked behind like walled gardens or gates.
And so, like philosophically, Syd, I Kilo we're big believers that, you know, we should be making AI accessible to people. And so that's a big mission. Um, and then third is, you know, if, if you look at the pace of development of models, um, you know, like I was saying before, it's like I don't want to commit to one or two or three models or, or labs like, you know, you know, Gemini, GPT, um, Opus Minimax, uh, Z AI is GLM, like all these great models have come out in that last three months.
The pace of innovation is amazing. And so I'm, our world is, you know, we view that we're work, we're not kind of working towards a, a world of consolidation of fewer models. We're actually working towards a world where you're having lots and lots of models, specialist models, big models, small models, open weight models, um, and we're big believers that we need to be open to all those models.
Um, so that kind of, the engineer can have the, the, the kind of freedom to choose the, the best model for the job. I think that makes a lot of sense. And you know, Scott, I I think that rides a couple of different waves.
Number one, no one, it's the anti-lock in model. No one wants Exactly. Wants to be locked in.
Right. Number two, we are making tremendous strides like every day it seems. But when you look at like, you know, we call 'em frontier models when you look at today's frontier models.
Mm-hmm. I think what a lot of us are learning is they're amazing. I mean, think about if I took someone from 1972 and transported them to today, Marty McFly or someone, right?
Yeah. And said, Hey, just like magic, right? It would, they would think, yeah, it was God, they, they would've no idea that there's not a real human in there.
They're talking to who super smart or something. That being said though, I think we're also realizing that these LLMs, these frontier models that are trained on the whole of the publicly available internet aren't necessarily the right tool for every job. And that sometimes we're better off using a tool that's trained on a subset of things or maybe some information that's not publicly available that sits behind a firewall.
It's proprietary, but it's perfect for what I'm looking to do right here. And so I think the future is, you'd say there's 500 models, kilo supports right now. Yeah.
There's gonna be an infinite number of models or, or vectors or whatever you want to call them, that a tool has to be able to plug into. And if we have open standards that allow you to plug and unplug right into different models like that, that's, that's what the developer wants, not only the developer. I think that's what everyone wants.
That's what every, everyone, every knowledge worker you, I mean, you, you want to just essentially go down the, the supermarket aisle and grab the right model. And I think, I think what you're saying on a hundred percent aligned with our philosophy is, you know, we saw in 2025, people are trying to keep you in like a, I know a bar refrigerator style selection of like three models when really there's 500. Now there might be 5,000 in a few years and everybody May have their own model Yeah.
In a few years. And your tool should work for you. You shouldn't have to re-platform move to a different development tool every single time you want to use a new model.
It's like asking the finance team to, you know, every year switch from Excel to a new product. I mean, you know, our philosophy is like, and we have a saying is, you know, models change. Um, great workflows don't.
And so that's what we're really focusing on is building a great workflow so that, you know, an engineer can go from conception to architecture to coding, to debugging, to deployment, to kind of monitoring all in one end-to-end platform using the best AI model for the job. Yeah. I think that's the beauty of the agentic nature of this, right?
Which is, look, if I've got a, an intelligent autonomous agent here, it's going to know enough to switch models as I need to. Right? But, but you wanna make sure it's switching in your interest.
And I think that's a philosophy, you know, we're really, you know, doubling down on is 'cause like what we've seen in the past is some tools when they're optimizing, they're optimizing so they lose less money kind of subsidizing your usage. And that's what we kind of see in the curses of this world. But like, you should be able to, you should have an application that intelligently optimizes, but you choose kind of the trade offs that it's optimizing for.
You know what I mean? I think you know best whether you are kind of wanting to, you know, this is an important complex task and I want to the top of the top or, you know, hey, this is kind of pretty basic and, and I'm all game for, for for saving costs. Yeah.
And, and I think cost of model and token charges and all that is one aspect, but I think we're rapidly gonna transform to do I want the one size fits all model or do I want the specialist model? Yep. And, and, or I mean, I think you might have a one size fits all model that, you know, hits, you know, 60% of your use cases and you augment it by a lot of specialist models.
I I, I don't think it's, and I think that's what you and I are probably saying and agree on, it's like the main theme is you shouldn't have to choose, you know what I mean? Right. You, you're right.
You have all your options in front of you. Exactly. Okay.
I think people get what kilo's about, Scott, let's transition here, pivot a little bit. How do people interact with Kilo? Cool.
Uh, yeah. ai, um, you know, register, give us a download. Um, first of all, we've got great resources on Kilo.
Uh, we've got, um, a leaderboard that you can track trends. ai, which is, uh, resources for how you learn kind of a agent engineering, but yet get into Kilo, download it, install in your VS code extension or even use App Builder, which is our kind of low code, no code kind of vibe coding type interface. Um, and I think the coolest thing about App Builder, and we launched it very recently, so I'm, I'm very excited about it, um, is you've got that low-code, no-code interface, but it's built on that same kilo backend engine.
And so when you say, Hey, I want to, you know, create this app, um, even me as a non-technical user, uh, what is producing is not some throwaway garbage that I can say like, Hey Alan, look at this. And Alan, you're like, that's great. Let's put into production.
Oh no, we gotta start from scratch. No, it's built at great production quality standards. And so I can essentially share that code base with my colleague who's kind of a full stack engineer who can open it up in VS code and just keep going without having to, to kind of start from scratch.
And I, I think like that's the whole vision is, you know, we've got a lot of on ramps from kind of those professional engineers who can go to VS. Code JetBrains, um, or CLI or kind of the, you know, engineers who wanna do it, or the less technical folks who, who want to kind of get into vibe code mode. And at the end of the day, you'll always be producing something.
Great. Fantastic. Scott.
Uh, again, it's Kilo do ai. I want to thank you for coming on Text Strong tv. What a great conversation.
As I said, say hello to Sid. I know there's a few other people I know at Kilo too. Probably was Brenda s hello as well.
Yes, That's who I was. I didn't wanna mention tell him I said hi. Perfect.
Will do. Um, but keep us posted here on Will Do on Kilo Progress and I hope to see you soon. Will do.
Thanks Alan. See ya. All righty.
ai here on text, on tv. Stay tuned. We got more.
So as you, you know, made these decisions, you had certain things, you know, and with your view from an architecture perspective, real requirements to drive real network outcomes and performance outcomes, what are some of the things that ended up on your list of things the new network infrastructure must do? What were some of your key issues that you were addressing through your requirements gathering? First, you know, we were getting also exposed to, uh, um, public cloud, you know mm-hmm.
The automation there. We wanted to drive our on-prem, like we do, like in public cloud, you know? Sure.
Uh, make it more, more consistent automated, and also, uh, simpler to, to manage, you know, simpler, to specify what you wanna do and get consistent results. Um, so we wanted on-prem to look like cloud. Mm-hmm.
But we, we ended up with, even on-prem, I think in a be little bit better state than cloud because we had more control there. Sure. We had more control there.
We were able to, to control the underlying, um, management platform, uh, where we couldn't do it in the cloud. Really. Um, so, um, would You, would you call that, was that, was that an objective or was that a happy side effect?
We Had it as an objective. We didn't achieve it with our first iteration. Our first iteration was a few years ago with a different platform.
Sure. And we, we didn't really achieve that part. Okay.
But with, with our newest platform, it gave us the, the, uh, it's op, you know, being open source. Sure. And with lots of tooling, it enabled us to put around it the, the, the, the solution that will achieve this objective.
Sure. Yeah. You, I, I know from previous conversations, the ability to use more open source tooling really gave you more options and gave you more ability to customize.
Yes. And, and you, I mean, what we did, I mean, we did a lot of innovative work really. And, and we started as we were a small team, we were maybe three or four engineers at the beginning.
Wow. And when we started, we really didn't know any of the modern networking techniques. But having an open source tool, you know, then you can, you can put somewhere, you know, you can look on the internet really, or, uh, you know, other people would have faced what you are facing.
It might be it not be not related to networking, it might be related to something else, but having an open source tool that people have, have, have touched this open source, which is Kubernetes, where our tool is based on Kubernetes and, uh, you know, millions of people are using Kubernetes and they've built tools that enable it to communicate with this Kubernetes cluster and do interesting things that we have used in our solution. Got it. I don't want to, um, under count, you know, the, the, the global scope of the network you had.
It wasn't just like one data center, pair of data centers. Talk, talk a little more about global topology and, uh, what data center resources you had to bring all in line together. Okay.
So, um, I mean, we've got data centers in all content. Um, Europe, U us, Asia, uh, they're very complex data centers. They're dual data centers.
And, um, got applica, you know, one is active standby of, of the other. Um, it started with a very flat, flat architecture. You know, we've inherited a flat architecture and we continued thinking flat, but then we made it a much more interesting, uh, modular architecture mm-hmm.
You know, of the data centers where we can add remote data centers together. And we wanted, you know, uh, uh, this flexible architecture, but we wanted a tool that will understand this flexibility Sure. And enable us to have this modular flexible architecture.
So, um, that is, that is what we had in the architecture side. And when you say dual data centers, you mean dual data centers in each geographic location? Like, you know, like within Yes, we have it's dual geo-redundant data centers.
Yeah. So, so they are, they are in the same region, but, uh, geographically apart to back up each other. Yeah.
In case of a disaster, Separate power, um, volcanoes Separately, et cetera. Yes, yes. Yeah.
Yes. Not to imply that anything is actually in Iceland, um, but, uh, I know people have had routers taken out in Iceland because of lava. But anyway, Hey everyone, welcome to this futurum executive interview series.
We're going inside the AI infrastructure revolution, and today I'm joined by Mohamed Awad from Arm to get the arm perspective. Mohamed, welcome. Great to have you on.
Thanks for having me. Great to be here. Yeah.
So I wanna start off, let's hit the AI inflection, you know, every day, literally every day it feels like there's news massive investments, whether it's more compute, more energy, uh, you know, more mo new models coming out, the leapfrogging effect. Like, you know, I'm not gonna get your perspective. Like what is defining this moment in the compute revolution and how do you see arms role broadly in that landscape?
Yeah, totally. I mean, I think, I mean, I think the easiest, the easiest way to describe, it's just transformational. I mean, I mean, things are just changing so quickly.
The potential is just massive, you know, and we're really kind of shifting gears in a big way in terms of what compute is and how it works, how energy efficient it can be, and sort of the value that it can provide. I think, you know, the, the world kind of sees that potential. It sees it on the, the horizon.
We're, we're, we're not there yet. We're kind of early innings. And it's, a lot of it is about, you know, how do we achieve that potential and sort of transform, you know, everything from the, the devices we carry around through to the infrastructure and the, the cloud that, that, uh, that makes it happen.
So it's a pretty wild time. It really is. And, and I speak to so many enterprises every day, and while a lot of us have been really focused on LLMs and how we're using them and the shift in how we search, I think we're in the very earliest innings.
I said something the other day, I said, we're about 1% of the way in to ai. And while people think it's farther along, it is not. We are just getting started.
But, you know, in terms of like in the hyperscaler space Yeah. Like, you know, in your business, right? We've seen AWS we're seeing Google, you know, Axion, we're seeing Microsoft, we're seeing, you know, of course Nvidia the grace and you know, and GB and GH and all those different things.
Yeah. Um, it's all on, you know, I think people would love to understand, you know, 'cause we're tracking this very closely too, but the hyperscalers have clearly moved a lot of, a lot of their commitment to arm. What's, uh, kinda what's driving that?
What's the technical reason behind that shift? Yeah, it's, it is, um, you know, we've seen tremendous, tremendous, uh, adoption. We've seen a lot of, a lot of momentum as of as of recent.
And really a couple, a couple of things. I mean, at, at its core, it's about this idea that we enable a level of, you know, flexibility and innovation, uh, while still being able to take advantage of an ecosystem. So if you think about how data centers were built in the past, you take some off the shelf compute and you would, you know, build up, everybody knows the story about Google, right?
Built in the, in the, uh, in the Stanford dorm room. And, you know, they just kind of cobbled together off the shelf hardware and it was like, let software figure it out. We're well past that now.
The sort of performance demands, the efficiency demands you need, uh, you need these systems built from the ground up and optimized for, uh, for your particular use case. And so, and that, and that's to get the level of efficiency and get the level of performance out there. And so what you're seeing all these guys, whether it's, you know, whether it's AWS whether it's uh, Google, whether it's Microsoft, whether it's Invidia, you know, all of them, they're building their own general purpose compute.
They're building their own acceleration, they're building their own networking. And arm's got a role to play in all of that. And, and, you know, I think that's really kind of helping, uh, you know, propel us forward.
Right? Yeah, it's been a great, it's been great to watch the Rise, you know, more competition puts, uh, you know, made the X 86 folks put some effort in to improve what they're doing. I think competition is good.
We always say that, you know, it creates efficiency in the market. It creates, and of course the TAM is rapidly expanding. A lot of people always wanna do this zero something.
It's like, oh, if they get it, that means everything's lost. It's like accelerated compute market's massive. In fact, you know, I know you probably can't say anything, but I keep saying, I think arm's gonna have a bigger role to play there too.
Um, pretty soon. So, um, really quickly though, I think we've seen numbers like at AWS like about 50% now of the, the workloads are now running on arm. You know, we definitely measure market share.
Kind of where do you see your market share sitting right now? Yeah, so AWS actually just at this past reinvent and at the reinvent before talked about this past reinvent. They talked about how in the last three years, more than 50% of the compute they deployed was arm based.
And it, and it's interesting because, you know, these are guys who are clearly, uh, you know, in front in terms of general purpose compute and what they've done around custom silicon. But if you look more broadly at what's happening with the transition to ai, you know, a lot of these systems that are being deployed are being deployed as full rack solutions and those racks, those systems, you know, come with a general purpose compute, they come with a, uh, accelerator and it's all kind of, kind of built together. So if you're, if you're deploying in NVL 72, if you're deploying Agra, Grace Blackwell, a Vera Rubin, um, you know, if you're deploying your own TPU with a head node or you're deploying your own accelerator, you know, the likelihood that that's arm sitting alongside it is actually pretty high.
In addition to that, when you start to think about the networking side, whether it's things like Nitro or you know, Bluefield or otherwise, those are all ARM-based CPUs that are driving those. And at the end of the day, those are actually offloading what historically was considered general purpose compute. So you've got a lot of compute happening there.
Um, so, you know, I, we, uh, we talked about at the beginning of this year how we believe that about 50% of the compute that's gonna be deployed at the top, uh, hyperscalers will be arm based this year. Um, you know, and we continue to believe that that's gonna be the case. Yeah.
So, so quickly, you know, in terms of, you know, as your data center presence continues to grow, I'm glad you mentioned the networking, because that's another huge opportunity. We see networking as one of those big, like, I think we were obsessed that compute was the constraint, but now we're seeing networking and memory and storage and everything kind of down the silicon supply chain. Of course, energy's a whole nother topic.
So arm's always been very focused on energy efficiency, which is a, a value there too. But like, what do you see as the big technical eco market related challenges that are gonna, you know, be critical, uh, going forward for the data center? Yeah, this is an AL'S law game, so you're gonna, you're gonna, you know, Excel, you know, you accelerators are gonna get better than worry about your networking to connect them, and then you gotta worry about your general purpose compute to supply them.
I mean, at the end of the day, what we're seeing right now are, there are a couple of main challenges. First and foremost is power. If you think about the sort of scale of what we're trying to accomplish, the amount of power required in order to do that is really beyond what the grid can handle.
And so there's real, the couple of ways to deal with that, you increase performance per watt, that's the number one game. So I think that's gonna be a big thing and the sort of race to better and better performance for lower and lower power. The second is, you know, availability of silicon.
When you think about, um, you know, the, the, the supply chain, when you think about the cost of building the silicon, the time it takes, and then the sort of capacity available, that's gonna continue to be a bottleneck. So we gotta, again, look for ways to, to further kind of dry that out. And advanced packaging technologies, et cetera, are gonna help with that.
But we gotta bring more capacity online. I mean, I think at the end of the day, um, you know, there isn't gonna be one particular issue. I think there's a bunch of issues, and this is really gonna be an ecosystem wide effort to kind of, you know, uh, you know, squash those issues as they, as they pop up.
It's a, it's a classic BELS law problem. Yeah. And I think the market's, a lot of the market is, is grossly underestimating the proliferation, how fast AI's gonna find its way, like I said, I keep using enterprise, but then even like edge and physical.
So let's talk about that for a minute. Like, that's a lot of the, you know, the genesis of of ARM was always, you know, small, low powered, uh, you know, whether it was mobile devices, but of course you have a business in automotive, you have a business in iot, you have a business in, you know, basically all these things. And I think it's a multi-trillion dollar TAM sitting out there for that, those markets, you know, talk a little bit about, you know, where's arms edge and, and, you know, strategy going.
Yeah, I mean, it's, it's, uh, it's ama I mean, you know, it, it's amazing the sort of potential that we see in the edge and kind of how quickly those devices are adopting ai. You know, uh, obviously, you know, we've got about 99% market share in the mobile phone space. We've got an incredible pre presence in areas around physical ai, whether that's things like robotics or automotive or otherwise.
Um, you know, you look at, uh, mobile, um, you look at like, uh, laptop and PC based platforms, which are now going arm based because they're looking, starting to look more and more like, um, you know, they're starting to look more and more like mobile phones. In fact, you know, something like 90% of the apps that are are, that are, uh, run on those devices are actually, um, natively written for ARM already. And so, you know, underlying all of that is when folks look to go take those devices and then expand them, add that AI capability as it becomes infused, leveraging that same software ecosystem, leveraging that same platform that is, you know, they've, they've come to, uh, to build this massive, uh, software base on those devices.
But then also that is being used in the cloud, leveraging that same software across both of those places. We're seeing that as a massive tailwind for us. In fact, you know, we think that the Edge can is gonna be an incredible opportunity for us moving forward, and we're already capturing on it on things like our Lumex platform that we just, uh, that we just launched.
Yeah. We expect that to be a really big growth opportunity. We've been obsessing with data Center for some time, but I think what happens outside the data center is gonna be a, a long, you know, across the next 10 years, it's gonna play a massive role in terms of expanding tam, expanding market opportunity, and of course bringing AI into our everyday lives.
So the devices, you know, the last few years it's been all about data center, but I don't think that's gonna stay for the long term. Um, you know, one of the things about ARM that's really interesting is your business model has evolved a lot, was really, you know, royalty licensing focus. You've gotten more into custom that senior margins grow a little bit, but just for those out there that are kind of like trying to understand how ARM makes money, how it, you know, goes to market, give us your sort of, the way you explain it, you know, how do you talk about it when you're at the, uh, at the family dinner table and you Get past it?
Yeah, I mean, I think the way to think about it is we enable innovation and we enable a, an ecosystem that, um, that, that comes together to build amazing products based on whatever the requirements are. Some cases that means ip, some cases that means compute subsystems. In some cases that means you, you work with one of our partners to get something like a triplet or even a full on SOC.
And I think the, the, the thing that really separates us from, from, uh, from other companies is our ability to meet you at whatever integration point makes the most sense for you based on the problem you're trying to solve. So in a world that's advancing very rapidly, you're trying to adapt new technologies into it, you're trying to fight for performance per watt off the shelf isn't good enough. You choose which integration point you want, and arm's, arm and more broadly, the arm ecosystem is there to kind of make it happen.
Yeah, yeah, that's a good way to explain it. I think, uh, you avoided the, the trap I put you in. I've actually trying to break down the how the, how the different royalty and licensing and subsystem buckets.
But I have, uh, it's been good to see you find ways to expand margin by adding more value. 'cause you obviously, as the company continues to be a critical provider of IP to many of the technologies we use every day, how you evaluate that, it's hard when it's only based on unit volume and you know, when you can get a little more out per unit. It's a, it's a good way to increase the, the, you know, the business's value.
Um, as we wrap up here, you know, you heard me allude to, you know, performance per watt leadership or low power. That's always been a big part of the ethos. Um, you know, what are the other advantages that, you know, you think that really are the big reinforcement points for arm's?
You know, unique value proposition? I mean, I think number one, it's ecosystem. When you look at arm, you know, our ecosystem is second to nut.
And so this idea that you can, you know, you know that it's not just arm, but it's an entire ecosystem standing beside you ready to help you realize whatever your potential is, uh, you know, and whatever the, the problem is that you're trying to solve, I think that is probably, um, one of, one of the greatest values beyond a sort of performance per watt and just the, the technical chops that we've got. And I think that's so important in an environment like, uh, you know, today where, you know, things are changing so rapidly, whether that's software ecosystem, whether it's our hardware ecosystem, whether it's partners in our arm, total design program, you know, we've got this massive, um, you know, uh, ecosystem ready to kind of support you. That's very different, by the way, than other architectures.
You know, other architectures either have a strong ecosystem where they'll give you an off the shelf solution and maybe have good software, but you kind of get what you get, or you've got incredible flexibility, but you don't have that ecosystem there to support you. You kind of bring the best of the, those two worlds together. And that's really what sets us apart.
Mohamed Awad, I wanna thank you so much for joining me on this Futurum executive interview series. It's great to get a little more insight as to what's going on at arm. We're watching you closely.
You can be sure of that. Uh, congratulations on all the progress so far, and let's, uh, catch up again soon. Thank you.
It was great talking to you. Hey guys, thanks for the throw. We're here with Amit Sheps, who's head of product marketing for Incognito, and we're having a little chat about well attack surface management 'cause things are getting a little bit outta control.
Amit, welcome to the show. Yeah, I think getting out of control is, is the right context for, uh, for attack surface management. Um, and I think before we'll start, regardless of attack surface management, I think what we can see is that security teams are still being the same on the same size.
Whether being become smaller or staying in the same size budget are becoming much tighter, and the risk is being bigger. And I want, I would like to say attack surface is here for the sq, but, um, I think we can see definitely a lean on from organization towards attack surface management towards attack, external attack surface management, um, is a mean to reduce the noise, to make that vulnerability management something which is more cohesive and something they can walk with. And instead of chasing vulnerabilities, actually addressing real risk, it seems like we're dealing with two sets of challenges, and one we're kind of aware of in that the number of platforms that we use and the number of things that we need to secure as increased as we've become more distributed with our applications.
And there's more stuff running at the network edge than ever. And at the same time now there's this AI component where we're starting to see agents that are essentially a new type of end user that also needs to be secured. And so the number of, shall we say, uh, people, whether they're AI agents or actual humans that need to be defended is also exponentially increasing.
So from your perspective, it seems like if I'm the cybersecurity person, the game is a little rigged right now and not in my favor. So how do you see this all playing out and, you know, is there some way to think about managing all this? Um, let's start with the first question and then I'll move to, to the ai, the elephant in the womb.
So yes, organization become, became much more complex, uh, whether it's, um, many tools, as you said, to secure many things, many domains, many technologies, um, whether it's the size of the organization, if in the past we had, you know, a small office with a data state data center, somewhere, now we have organization spread across the, the globe and security teams first struggle with visibility, with actually trying to get everything together, uh, whether it's see what minds and actually try to get somehow a unified picture of all the tools that I'm using. So I think the first step that we are seeing is integrations, whether integrating your inventory system to your ticketing system, to your EASN, to, to the exposure systems to create some kind of holistic view. So in the end of the day, you will be able actually to connect the dots not running after, you know, whether it's a vulnerability or, um, patch in your IT or something which happens somewhere you can actually connect, integrate all of your systems.
And now I think you are much in control, which also says, um, sometime when dealing with, um, incidents or vulnerabilities. So this is for the first, for the complexity. Now, let's talk about the elephant.
Um, so AI brings, um, let's say two dimensions to cyber security, as, as I like to play with that. Um, one is ai, what AI is doing for the practitioners. And the second one is how to secure ai.
So both sides of the equations now in terms of securing ai, your tax surface is being now expanded. So you have, I'll say, new toys you need to play with, but you need to secure them. And I think, uh, you and I in this business long enough to hear, uh, Cisco's complaints about the cloud and marketing team spends a new application, uh, for their new, uh, um, for the new campaign.
And the security cannot control the velocity of the cloud. And I think we are going to see it here as well. Um, whether you expose an NCP or um, an agent, as you said, you need the tools to identify it.
Security must keep up with the pace of ai. This is on one hand, so you need the tool. You need to, again, have that AI mindset on your attack surface on the underway round, uh, which is the good stuff is the what AI can do for you.
And now, um, I'll call it you have a new assistant near you, which can actually help you and take a lot of your work. Um, same has happens, for instance, in r and d today, or with developers that we see, uh, ai, I don't wanna say replacing, um, developers, but taking some of the, um, tasks of the, so to say, senior, uh, developers and make their life much easier. So you can see, and we can see products today that can investigate, um, incidents.
So there are some kind of a junior analyst that sit near you and do and collect the data and make the, so to say, initial, uh, trash, uh, and actually give the, the analyst initial, uh, findings of the incident or whatever he's investigating. AI can actually process data it scale. So if, if, let's say two years, I mean, it's not that long, but you needed actually to take ev all that data, all that logs, all this information and process it.
Now, AI will do it very fast for you. And of course it's being, it's, it's being done in your language. So I think in one way, AI made a little complications, the securities and the other way around.
It's also helped them a lot to deal with these complications. And with the rest of the complexity, I think there's a, a, a third element to this is, is the bad guys are using AI as well. And so it seems like they are discovering and creating exploits for vulnerabilities faster than ever and then launching them at higher levels of scale.
And if that's the case, then, um, you know, is this whole thing moving to something that is, uh, attack and respond is now in real time and it, it is occurring faster than humans can keep track of it. So is the whole nature of the game changing? I agree.
And I think, um, if you look at the hacking methods, I mean, I, I, to be honest, I did a small course. I'm not retaining to be of ethical hacking. So just to understand what is go, what was going over them.
And I think the methods of hacking are now once, once they are being replaced by an agent or, or, um, ai as you said, it actually make every, makes everything more challenging. However, that means that you need to maintain your attack surface much tighter. So you need to identify risks much sooner.
And then you will be able to prevent these attacks. Because again, in order to initiate ai, uh, an attack, AI is the orchestration tools is the means to the end. At the end of the day, if you will maintain your attack surface, identify, um, identify where you are exposed, where are the exploitable issues, um, then you can prevent, I don't wanna say 100% of these attacks, but you can prevent many of the attacks by being aware to that attack of view and then prevent it from happening.
So what's your best advice then, the security teams as we kinda look at all this stuff? 'cause it could be, frankly, it's a little overwhelming. And how do they wrap their heads around all this?
Because, you know, there's a tendency where, you know, if you think too hard about it, maybe you just wanna run home and scream, but what am I supposed to do? In one of the webinars that I made in the past, someone um, brought me, um, a question, how do I prioritize vulnerabilities where everything is critical? So it is, it is a situation.
Um, but I think, and this is where you start off exposure, attack, surface management, um, so external, so taking that attacker view, I think most, I don't, I wanna say most or some, or we see a situation where security teams are currently handing vulnerabilities because of, I don't know, historical reasons, because this is the way that they're working. And we see also a change in the market where security teams, our customers are taking the attack of you in order to prioritize, in order to understand, um, the essence of these vulnerabilities. So it's being done in two ways.
First, uh, are they are reachable from the outside? Can I, can I see that vulnerability as an attacker outside of modernization? And second, we are also validating the risk.
So we are doing it safely, um, without any risk to the business. So now I have validated risk and I know that it's can reach, it's, it's reachable outside of the organization. And now I think we are on the discussion of, from my hundred 100% vulnerabilities, I can actually prioritize based on the risk and not based on the number of vulnerabilities.
So this actually changed the equation and it's changed the way that security teams operates. We see that security team starts to breathe now when they can actually deal or handle the risk rather than, you know, vulnerabilities. So it, it, it's, it's a different story.
Um, as we kinda look at all of this stuff, how do I as the security person have this conversation with the business because, um, you know, a lot of times business people are thinking, well, you know, we just spent a boatload of money on security and now you're back telling me we need to spend more because why? And they're kind of like, you know, saying, why should we increase the percentage of money spent on security? And they're a little dubious 'cause they don't see these threads per se until, well, it hits 'em in the head with an attack.
But, um, is that what I gotta wait for or is some sort of catastrophic event before I can get this business people to wrap their heads around this? Or is there a way to talk to them? There is always a way to talk to them always.
And, um, it's funny that you're saying saying that because I think security is always mean. There is always that dance between security and business implication, business case OI and all that stuff. Um, you cannot come to a person and say, we are exposed or something and expect that he will invest money.
However, um, one of the triggers, uh, for security, for security projects is of course compliance. Um, and we can see, I don't wanna say shift, but we can see requirements, um, appearing in, for instance, at least two in Europe that actually requires for external monitoring. So they want to understand if your, uh, if you have, um, assets which are exposed to the internet, are your vulnerabilities are, um, reachable from the outside.
And I think once you have the compliance discussion, it's a pure business discussion. So you need to comply with in order to do business. Um, so this is 1, 1 1 use case.
Um, the other use case I think is to show, To move to risk efficient to to, I mean you need to discuss in business metrics you need to understand to show the business impact. Um, and in some case, what we are doing is we are bringing the business implication of, of issues, of findings, I wanna say vulnerabilities because sometimes it's an S3 bucket exposed to the, exposed to the internet. So it's, it's not a vulnerability, but it's definitely something you need to, to deal with now.
But in many cases, you want to show the business implication. You wanna show, okay, if this server, this application will be hit, will be breached, then what it'll do to our business, that means that one hour our customers will not get any service. I think this is something that management and business people can understand and in some cases translated into money.
Um, and once you are translating cyber risk into business risk, then I think it needs, um, otherwise you are right, it's different languages. Mm-hmm. Um, to your point, are we also therefore moving towards, um, some sort of ability to continuously monitor those environments and activity and we need to, uh, have that level of visibility?
And so, and, and how do we gain that? And um, 'cause I think, um, people have been talking about this theoretically for a long time and very few have accomplished it. So is it getting any easier to, um, continuously monitor an IT environment with an eye towards preventing something bad from happening?
Is it getting easier? No. Um, I think, um, complexity is there and, and I think, um, the attacker always like the attacker always like the bigger organization because it's more prestigious is because, you know, uh, it'll get to the news faster.
Um, what we can see and what we in psycho is doing is actually trying to imitate the attacker or take the attacker point of view when we are doing the discovery, the, how to say external, it's not inventory, it's actually discovery and actually showing where you are, where you are exposed. And there are two levels. So one is understanding the organizational structure.
We are actually mapping the business organization. And from that point, you, you are going to the technical aspects of physical assets in terms of web apps or IP addresses. So it's not, we are, I mean this is the outside in approach.
So basically looking at the organization the same as the attacker would do. So that provides the visibility, um, that, that match the attacker. So, um, you can actually be certain or be sure that you are actually playing, um, with the right tools against the attackers.
Now, once you have that, you can, uh, understand all the elements, all the, I don't wanna say chain of events, but uh, you can understand the vulnerability that he sees. You can understand where he can breach, what he can do, and then you can map it into attack path analysis, uh, and all that stuff. And I think this is where we're leaning back into the inside systems in where we're integrating and combining all this data, as I said before.
So you have that full visibility from the outside connected with the internal systems. I think people kinda are starting to understand that. And you gotta think like your enemy essentially.
But one of the things that I do hear from folks is they go down this path is they wind up collecting a massive amount of data and then they don't know what to do with all that data and they can't afford to store it all and they can't figure out what data to keep and what to toss. 'cause there's just, you know, everything is instrumented and it gets overwhelming. So how do I kind of think about security on a certain level has always been a data management problem, but how do I manage the data?
I think one of the asked question that we've been asked as well is, if I will bring psycho and exposure system external exposure, uh, would it increase the noise? So am I bringing yet another solution that will make yet another noise? And the answer is no, um, is no because of two things.
Um, we're not replacing real complementing. So in the end of the day, I wouldn't say that I can give you the internal inventory as, as any other, uh, player in this market. But what I can do is that I can provide my insights to the internal, for instance, we're integrating with arm with axons.
And what we do provide is, for instance, that holistic view. So you, you will have that visibility of all the assets of all the external assets. And once you are connected it with armies for instance, you can actually create an end-to-end attack path so you can know which of your crown jewels is, so to say threatened by attack path, which is can be exp can be initiated from the outside.
And I think this is where the noise is actually, um, being diminished. So now instead of 1000 findings, you can focus on that 10, 15 findings that actually show you this attack path. Alright, well folks you heard in here, Hey, if you can't see what it is you're supposed to defend, I think you're at a serious disadvantage in the first place.
So, um, maybe the first step is just understanding what that environment is and then figuring out, well, if you were gonna attack it, how would you do it? 'cause the bad guys are probably doing that as already as we speak or as one wag one said to me, if you can imagine it, somebody's trying it. Hey Amit, thanks for being on the show.
Thank you very much for having me. All right, and back to you guys in the studio Control. This is agent dev.
I'm in position. Copy that. Dev.
Stand by for Go Standing by. Hi everybody, thank you for joining us for the first episode of Agents of Dev, our new podcast. My name is Mitch Ashley and I lead the, uh, software lifecycle engineering practice at Futurum, also a product lead CTO product developer kind of in my background, which is a lot of what we're gonna talk about.
And I'm joined by my colleague and, and good friend, uh, Brad Shiman. Brad, introduce yourself. Thanks, Mitch.
Hi everybody. Uh, so Brad Shiman, I lead our data intelligence, analytics and infrastructure practice here. And, uh, like Mitch, I have a history and fondness for all things development oriented.
And so the two of us are, are very glad, uh, to, to be working together on this, to to talk a little bit about, uh, where we think the the software development marketplace is going in the enterprise. And, uh, you know, I think we have a great venue for that, for this this week, for that this week, uh, because we're both in, uh, Las Vegas visiting, uh, AWS, which is putting on its annual, uh, reinvent show, which is somewhat sizable. Yeah, Mitch.
It is, it is. And then yes, we're working from our hotel rooms. We don't have similar artwork in our homes.
It's don't worry. Why do they have the same mark? No, yes, we're both, uh, at, uh, different locations in the wind.
It's, so just a little bit about this podcast, I wanna say just, um, since this is episode one, og, right? What we're about, um, I I've always wanted to do a more in depth both as an analyst, but also as a practitioner, career long practitioner of someone who's either done software, database work, network work, security work, um, all of it together to, to create software release products, that kind of thing. The stuff that you and I have in our backgrounds and respective differences in our backgrounds.
But also look, but look at it from an analyst perspective, not just pontificate about it, but pontificate with some maybe some informed background. If I can be so bold, not that other analysts don't do that too, I don't mean to discourage anyone, but you know what I mean, we're practitioners. We like to talk about the craft of what we're covering and the pain as well.
Oh my God. And the pain. Yes.
And then, and AI doesn't lessen pain. There are some new pains. So I, you know, I think Brad and I have, we both don't like to have fun, so you'll hear us joking around and hopefully some levity will make this even more interesting.
Um, talk a little bit about your software background, just like to hear a little bit about it, Brad, so folks know where you're coming from. Oh, sure. Yeah.
So, um, back in the day, which was for me, um, 1990, uh, when I was just, you know, getting, uh, into working as a, an adult, not as a teenager, but as an adult. Um, and, uh, I got a job, uh, as a, an admin for a no network, uh, network. And, uh, that was painful.
Speaking of, if you've ever thought about doing, uh, an upgrade of a system that had over 50, uh, floppy disks. There's your answer protocol in the background there going on indeed, Nobel Yeah. And N LMS were my friends.
Um, oh, still, I still dream about them, but you know, in that era it was, it was, um, you know, heady times. I, I was trying to teach myself DB two and got involved with, you know, uh, sort of interesting, uh, what would I call this, uh, sort of development paradigms like, uh, Fox Pro, uh, which was a, a yeah, basically a tool set and an approach to building databases. And I was hooked, just absolutely hooked.
Loved, loved them very much. And, uh, ever since then have been working, um, as I, I actually started working in our, in, uh, this, um, Atlanta Times Magazine, uh, doing competitive reviews, um, switching reviews, networking reviews, as well as server and software reviews. And I always raised my hand whenever we had the chance to do anything with software and software development, because it's just al always fascinated me.
And so I, I did that for a while. Um, did, uh, some, some work, uh, as an actual, um, uh, in it itself as a business analyst and developer when I was working at, uh, a company called McGraw Hill and CMP and whatever else they were called at the time, publishing houses. And, uh, for example, we had, uh, an interesting, uh, project where we wanted to take, uh, the databases that people, uh, that we built for each magazine and converged them into one harmonious database.
And these, these databases were all the, you know, the cards that people used to fill out back in the days for these massive, you know, and I mean, massive, like the, the page size was about this big. You mean the cards that I made up all the answers on those cards? Exactly right.
Yes, right. Surprisingly it was, there was a data quality problem involved in that project. Contribute to that.
Yeah. Just, you know, so, uh, I, I've been involved in that for forever. And, uh, as an industry analyst, um, was on board of, uh, the ai, um, train pretty early and got involved as a practitioner there and in, in doing data science and, um, have, you know, since we entered the age agentic era, been been working on several projects, uh, that we're, we're doing actually internally here at futurum, uh, making use of some of the new toys that, that we have in the industry right now.
Yeah, you undersell yourself on that part of it. Brad's been leading the development of our signal, uh, project, the signal report, which is all ag agentic ai create the structured and created sort of the fabric behind it of taking the input from the analysts and creating the structure of what the analysis looks like and sources and kind of directing it. Brad's done all the work on building it.
You've done a fantastic job what you did on that. So nice work, Mike. Thanks, man.
Uh, just real quick, kind of where I'm coming from, I've, I've, in my own way, similar kind of path. I started out a decade earlier than you did in the finance industry doing banking systems, actually rebuilding, modernizing, I guess you would call it now from one vendor to another, moving, uh, software into IBM mainframes, but I also got into the PC in college, so was very invested in that and actually ended up getting into database pretty quick. Uh, first IMS in mainframe stuff, and then DB two and ingress and later, uh, Postgres and things like that.
Interestingly enough, about six years into my career, I got into AI and was doing a lot of lisp and prologue work. Ooh. Which I don't use a lot of these days, but that's what we thought of as, you know, those were, those are the symbolic languages, right.
For, for ai. And actually did some teaching around that stuff. And well, li Lisp is God's language.
It's, you know, isa, everything's about an isa. That's right. Yeah.
So kinda had early hand on that and we thought, you know, AI was just around the corner then, but, uh, not quite. com dot bomb era, but also moving into the cloud. Um, so I was a DBA data architect for a while.
I was a system architect developer for a while, and I got into networking kind of by accident in a consulting company that I started, and that got me into security. Ended up doing this, uh, couple security companies in the early two thousands, sold to the dod into, into corporate enterprises, and, uh, did pretty well in that era. So I ended up working in security for the last 20 plus years.
But anyway, after that, still kept going on and moved into the next era of the cloud and DevOps and things like that, leading product development teams, just still a little bit of hand in development and then started an analyst firm that eventually got bought and then sold again to what's now Futurum. So that's how Brett and I came to work together. So we both come to this as with prac, strong practitioner background, but also analytic thinking about what we're doing and why we're doing it this way and kind of under wanting to understand it better.
And I think that's a lot of what I'm guessing similarly wires us about why is analyst work in industry. Yeah. The, uh, the insatiable curiosity is, is a problem, uh, what, you know, within the analyst community and, uh, it, it does keep us up at night thinking about, you know, well, wait a minute, they so and so said such and such about this new technology.
How does that work? Exactly. What does that do you say that because there's one, there's one word that's a question and a statement whenever I hear something said by someone, especially, you know, because I've been on the vendor side too, when they tell me this is what we're doing, or we're re announcing this, it's either really, which is a statement or really, which is the question, really, you know, what I wanna know more.
Right. Ex exclamation point, followed by a question mark or question mark, followed by an exclamation point or multiple of either, you know, so it's, it's, you know, it's that natural curiosity we have. So let's, let's turn to kind of, we wanna talk about as practical things as, as analysts are gonna talk about, but, you know, kind of dig into the more of the details of what's going on.
We're here at Reinvent. We've had some pre briefings that frankly we're at before the main keynotes have been kicked off. So we're, we've had, you know, we've had the preview, we have what they have told us as much as we can digest in that shorter period of time.
Do you wanna kick off on some initial thoughts about what we've heard and what that's saying about teeing up where we're headed into 2026? And then I'll chime in and kind of give my perspective. Yeah, yeah.
So, um, as, as Mitch said, we, uh, actually just a couple of hours ago sat down with, uh, AWS to hear a sort of roundup of where they were heading this week and all of the announcements that we would hear about, uh, for everyone who's, you know, following here or at home. And, um, you know, as you, as you might think, trying to cram all of that into just a couple of hours, not easy or even possible. Um, and so there, there's a lot that they really glossed over, but I think sometimes when you a vendor does that, they actually tell you a lot because what they omit and what they elevate is always, you know, important because that tells you where the investment is going within the company, what they care about the most.
And, and it was, it was interesting to hear, you know, some very familiar refrains from them that we've had for a long time. Things like, you know, we're, we're all about working backwards from the, you know, the customer to the problem. And, uh, so that they build software that's built for their customers.
And AWS has always been very good at that, is most vendors I think really try to do it. But, um, what I liked when I, what I heard, which was a little bit different this year, was they have a focus on what they're, they're calling freedom to reinvent. Um, and that is a, a key go-to-market message for them this year.
And I, I think that what they told, told us about says, does reflect that in some ways because I just, you know, normally I would say it doesn't, but I do think that AWS um, what they're saying actually is, is very much in line with their go to market. Um, and lemme give you an example. So, um, they, they talk about how, uh, they think that we're going to have a world in which there are billions of AI agents running around, and they, as, as sort of proof of that, they said, well, we're hearing this from our customers and we're seeing what our partners are building and what, and what we are building AWS internally.
And we see that there, there is a tremendous amount of work being done right now, uh, to build out a, a large swath of agents. And when you build out a large swath of agents, you have to, what, what manage them make might be a good, good thing to do. Orchestrate, that's the word, right?
Yes. Manage, orchestrate. Yes.
Yeah. Right. There are frameworks built specifically to do that with agents.
And, um, that whole idea of freedom to reinvent, you know, what, what, what, the thing that constrains enterprises from really, you know, doing anything is, you know, inertia and technical debts and budget. You know, if you don't have those things, you're, you're gonna have a hard time making headway on new projects and old problems. And so, um, the things that they were telling us during this roundup of what they were working on, I think really kind of speak to that desire that AWS has to help their customers get to those billion of agents, billions of agents, uh, and to do so using, you know, the existing platform they have, like, they have their bedrock platform and they have a, not new, but a, a greatly enhanced, um, orchestration layer that they lovingly refer to as Agent Core.
Um, which does remind Mitch and I both of, uh, a, a musical movement that involves punk rock, um, that, uh, that's a story perhaps for another day. Uh, I kind of remember that some of those brain cells are still here. But yes, those are, those are, those are heady times.
And, and, uh, if you, if you think about what, you know, what they're trying to to get at here is, is being able to, you know, build out very complex systems that involve a large number of semi-autonomous or fully autonomous, um, workloads. And that's not something the enterprise is used to doing. So it's, it's very different.
So I hear when they say freedom to reinvent, and I, I say, okay, we're, we're, we AWS are trying to give our customers the enterprises the tools that they can use to reinvent themselves in this agentic era that were existing in. What was your, what was your key takeaway from that opening salvo de definitely agree with your take on things. No, thematically, especially that's what they're, they were building around.
You know, I think it's hard for a Ws because I count the number, there's always 800 to a thousand announcement at a reinvent. Just no doubt. How do you thematically pull that together?
But, so you have to look at, so what are the big things that they're talking about? And you mentioned agent Core, they have something that they've introduced with that, but also part is the of their kero, I-D-E-A-I-I-D-E, which clearly is now becoming sort of the, the working console for development. Think of it as not just an ID but they have a spec driven mantra or philosophy about how Keo works rather than just task know, uh, a generator, prompt driven kind of development and something that's a little more structured.
And I think that's one of the things for us to kind of figure out too. Sorry, my computer's dinging at me, um, which means our 10 minute bell, sorry, everyone. Oh, behind the scenes there.
Um, so anyway, jumping into it, they're talking about something called, um, basically frontier agents. Now this is a bit of a mm-hmm. Washing of the frontier name, not Frontier.
Sorry. Sorry. I just heard your stomach grumble there, Brad.
Yeah, the, the, those, those were my eyes rolling back in my head is what you might've heard them hitting the back of your head and rolling back that. Yes. So, you know, now Frontier won't mean as much, you know, sort of like means everything or whatever, you know, so it's gonna get washed to, but that's, it's bound to happen.
Anything that's good will get adopted. Yep, exactly. That change.
So that, but the real, the, the essence of it is, is I, as I understand it, we'll hear more about it as the week goes on. It's really about agents who are more truly agent, meaning they're running on their own. They don't require as much who human interaction direction to keep them going on track, keeping on track to accomplish a task that can be long running.
It can be not just hours but days, maybe multiple days going across models using the tools that they have, uh, for them to use. But I think the idea with the Frontier branding is signaling going to the next step to the kind of work that agents can do on behalf of whatever, what are those tasks are? And then they folded those into a set of kind of predefined agents that they're offering.
Um, one of them was a security agent. Yeah. That was fascinating.
Yes, of course. In Fernando, our, one of our peers. And his first, first question is, yeah, but do I trust it?
You know, the farther you're right, you go in this software development lifecycle, the higher the trust, you know, has to be because the, those are the folks that live with it when it breaks, you know, do, do you find, do you find it interesting man, that, um, you know, we, we talk about trust and talk about opacity and wanting transparency and understanding, and yet as an industry, and especially for software development, you know, have we not at every possible moment, uh, added a layer of abstraction to what we're doing to try to make it easier, better, faster, to get to the outcome? So how, how, how can we even like talk about trust as being some sort of, you know, foundational core that we can ever truly know? Can we ever truly have that?
Oh, you know, you hear stories about the, oh, compilers, those are bad things. 'cause I know what I can, I can code everything I need to do in assembly language on 'em, whatever platform, those compilers, I don't trust those things, right? They're magical, but they work, I dunno what to do.
And unless, yeah, it, it's that I have to get past it. This kind of stage. I went through that with like code generators too.
And you have this point where like, okay, I'm not gonna modify what it does. I'm just gonna use what it does. And if it doesn't do it, I'll either figure out how to make it do it or make a workaround if I need to do until the time, time being that it, it does actually work and it'll we'll get, we'll get past that point.
So you believe then, oh, I do. If I, if I may, I believe I'm a believer. No, I'm sure you do believe that.
Um, with LMS or, you know, perhaps it's, it could be anything, you know, not just Transformers, but other ai, um, that we can ever reach the stage where we are now with compilers that we could look at the, this black box that is a deep learning neural network and see the outcome the same way that we see the outcome from, you know, a compiler in just to looking at whatever, you know, Python code that we've written and turning it into actual stuff that the computer can run. I do. I I do not, not just on faith, because the pattern has been there before.
Like we trust machine learning today, right? Because we've gone through this learning curve of how to effectionately take, effectively take PyTorch or whatever platform that we're using to figure out the process of, yeah, it's not just about writing the algorithms, it's about grooming the code and creating features. And there's a process to this, right?
It's a different way of creating software. Um, we were that way about DevOps. I'm not automating this stuff, you know, I'm not, okay, I'll, I'll, I'll do a continuous integration, but I'm not gonna do continuous deployment or at least maybe even automated deployment because I'm the one left holding the bag.
If it doesn't work well, you start to make it work and you start to build trust in it, you know, I think trust is experience as you get experiences. Yeah, I like that. That's what builds trust.
And, and unless it turns out to be a, a Holcomb and, you know, just a, a full full of smoke AI baloney, which I don't think it is, I think that trust will go over now. It's gonna be oversold, it's gonna be overpromised, it's gonna under deliver, it's gonna do all those things that everything goes through a hype cycle does. But we all know that.
So, and even if we want it to work, we know it won't be perfect and it's gotta go through some maturation. So that's, that's my answer. Yes.
I do believe it's gonna, it's gonna work for us. Yeah. I, I feel the same way as you and I, and I think that what gives me hope that that's how this will play out, is that we're changing how we measure, you know, rightness, correctness, accuracy, et cetera in the agentic AI era, or just the transformer generative AI era in particular.
And it's, it's changing a little bit about our expectations because you have the trade-offs of flexibility for accuracy and, um, you know, if you can accommodate, uh, you know, percentage points of, of lack of accuracy in trade for the, uh, ability to adapt to unknowable situations, um, oh goodness. Why wouldn't you do it? So I I, I think that it's heartening for me to, to see, you know, companies like AWS really trying to push the, and I'm not saying this on purpose, frontiers of how we think about software here.
And, and I, I feel like they were very early on, uh, I don't know if they get a lot, a lot of credit for this, and they should, because they were really early to the, um, ag agentic orchestration problem, uh, inside of Bedrock. Um, I remember meeting with them two years ago down in New York, and, uh, they walked us through, you know, this very detailed, um, uh, roadmap of how they were gonna build bedrock out to, to accommodate and, and support ag agentic development. So I feel like they don't get a lot of credit.
And, and I do think that they are, you know, if there is a company that understands infrastructure and they understand software as infrastructure, you know, apps as infrastructure, they're, they're in a good spot to do it. Yep. I agree.
You know, I think we're going through, you know, analogies can be useful things. This is analogous to us going through microservices, cloud neighbor Oh yeah. Kind of architecture, right?
Where picture it thousands, millions, maybe billions of microservices, smaller doing kind of special purpose, you know, more, more axiom kind of functionality. Um, how are you gonna manage that stuff? Well, right?
Something gets invented, Kubernetes comes along, and you know, right. In that case, it's an open source that is the dominant player. I don't know that we're gonna have that dominant answer, but the orchestration layers of what IBM is doing, uh, uh, Microsoft is doing, you name it, AWS Google, everybody is working on this.
I think we're setting ourselves up for, okay, how does that all sort itself out? Am I gonna live in a world where I've got 25 things trying to control all the agents, or do I live in a world where there's two or three? We'll see what that looks like.
But that's kind of that maturation that we're going through today. We don't think that, hey, yeah, another, another app's been containerized, another app's now starting to use microservices. Another one's been Greenfield and built.
Okay. Yeah. Okay.
Yeah. We do, we trust, we do. Now, we didn't in the beginning, but that's part of that process.
Well, and we, we also self-correct too, you know, in thinking about containerization and microservices in particular, you know, in that era, uh, the early naughties, we, we were like, yeah, let's, everything's gonna be a microservice. You're not gonna build monolithic software anymore. And we discovered that, well, you know, there is some truth to it, but not total truth to that idea.
And I think we'll see the same thing with ag agentic, you know, development. I think that we'll, we'll see, you know, places where it makes the most sense and places where it needs other things. You know, for example, rules engines, for instance, if you're, if you're trying to have something that that's a little less probabilistic, um, but that's all, like you said, man, that's all just maturation.
Um, and, and I see that reflected in a lot of what, um, AWS is talking about, uh, particularly with the agents that it was built, the ones, um, that you were just mentioning Mitch, about, um, the, the Frontier agents and also with Kiro itself. And my goodness, um, you, you said that this is, you know, a, a Phil philosophical approach and AWS is actually, you know, committed to building its software on top of Kiro or using kiro, which may sound extreme, but it, but it's really not. I mean, it, it is vs code with things that do other things in it.
So it's, it's not a complete makeover of how we build software, but I, but I think what you're using vs code No, yes. Like everyone else. Yes, that's right.
That's right. Everything cursor, it's all, it's all the same. Um, but, you know, it, it is, I think representative or reflective of, of this sort of changing ideals of how we build software.
And I wanna talk for a second, if you don't mind a little bit about one of those, um, with those long running processes, I remember, and this is actually, you know, a function of frontier scale models, where when, um, OpenAI was talking about long running processes for things like trying to discover a, a new, you know, molecule as, as probably the, the best example is, you know, that's not something that you do a deep, you know, um, what, what a deep research, you know, query for 10 minutes and get your answer on. It's, it's gonna run for a long time. Mm-hmm.
And what AWS shared with us this morning, and what we'll hear a lot about this week is this sort of shift away from, you know, having, uh, just individual, you know, developers solving small problems to perhaps, you know, these long running agentic processes that are solving more complex problems, bigger problems, um, maybe it's, you know, just migrating everything from T net to something else in the company. I don't know. Well, you know, we're, uh, so we're, we're at the beginning of this journey, both on the podcast and also AWS they're both our long running processes, but, um, like, um, we'll, we'll do a, we'll do our episode two and, and do kind of a recap, pick up where we're now, but also what I was text you on some other areas, there's agents for Cure out itself for the development process.
There's an a Ws DevOps agent. There's also, um, they're doing now train your own model, uh, using AWS's models in your data. There's a lot of things that that will come along that we'll about as episode.
Uh, I think one of the things we wanted to structurally do in the podcast is ra or wrap up with. So what's on your mind for the next week? What are you thinking about?
I, I may have made you go first on these, so I'll, I'll kick things off. Okay. Go for it.
I'll think I'll, I'll take one for the team this time. Um, you know, in the analyst world, I try to look at it as, it's not about any single announcement. It's about, so what, what are these things that a vendor, a WS in this case or anybody else, Microsoft at Ignite, et cetera, what is that setting this up for in the next six to 12 months?
Because let's face it, that's looking too far down the horizon of what technically is happening is a bit problematic other than seeing vendors kind of leapfrog each other with the same things, but as they take on new challenges. So that's what I'm, that's what I'm trying to think of, of, okay, so this is the big event, not for the end of 2025, but the beginning of 2026. And so, well, I'll, I'll try to share some thoughts about that when we get together about what's on your mind.
Yeah, I'm, I'm trying to think about, you know, what can, and what cannot be automated with, uh, generative agent ai. That's what, that's what I am, I am, my mind is, is really trying to wrap itself around right now. Is, um, as, as you know, you mentioned, um, we're, we're, you know, both practitioners and working on some projects and, and one of those is, um, trying to work out how to do competitive intelligence and what does that look like?
And if you, you know, for those of you listening that, that, uh, know anything about this, you know, the analyst in industry itself, competitive intelligence, is this sort of, um, long hated but deeply, you know, respected area of investment within companies that are trying to compete and, uh, you know, generative ai, like with so many, um, areas that involve, you know, how do you take a lot of information and correlate and analyze and, you know, surface value from that information, you know, is really good at it. So, um, I'm trying to think about, you know, what, what would actually be automatable and how far could you, could you take that with, you know, gaining value and how could that be operationalized to, um, work across several disparate, um, competitive areas? So, like, you know, having, how, how does, you know, KIRO, you know, line up with Bob, uh, from IBM, you know, how do they, how do they compete?
When you talk about things like, um, spec driven developments, you know, what does that mean? It's, you could say they have spec driven development, but to really dig into, you know, how it's being implemented, that that's the heart of competitive intelligence. And it's not that easy to do.
But, but I really feel like we, we can, with the tools we have even now at least, you know, surface enough value to, to make directional statements from us. So that's, that's what I'm, I'm thinking about. It's a good juxtaposition.
Intent driven development versus spec driven the same or they different. What's something one's got a, a better approach or not, you know, we'll see, you see how that shakes out? Yeah.
You think on, you think about big problems. I think you and I like to do that. Like what does all this unsolvable like meaning of life, you know?
Indeed, indeed. Deep thought. Alright, hold reference.
So, we'll, we'll figure out an email address, folks you can use to contact us. com or be shiman at futurum group com. We're happy to take your ideas on episodes, comment on wherever you listen to this or see us on LinkedIn.
We'd love to hear from you. Let us know if this is interesting or what questions, you know, you have, whatcha thinking about, uh, as either developers or people involved in software development or people architecting solutions, or people building products for the market, especially who, you know, we talk to a lot and we look forward to chatting with you there. Parting thought before we sign off, Brad?
Yeah, just, um, glad we're doing this, Mitch. I, I, I think that, um, you know, there's so much going on in our, in this industry right now that is, is I think, very hopeful, uh, in terms of, you know, making better software and more software. 'cause I think you can never have enough software.
I think we need more. There's a self-fulfilling prophecy, if ever. Indeed.
Thanks for listening everybody. Thanks for watching. We'll see you on episode two and stay tuned for it.
Bye. Bye everyone. This is agent dev.
I'm in position. Hello everyone. In this session, let's take a look at OpenShift virtualization, the why, what, and how we can run bms, uh, alongside containers.
I'm Anish, I managed OpenShift Black filter, red Hat. Uh, first the reasons why one should consider this, right? Uh, obviously the, the main reasons that stand out when, when one wants to use the cloud are, uh, generally you want to exit out of your data center.
You know, or you would like to use the cloud as an extinction of, uh, your on premises data center. Uh, you know, you wanna burst to the cloud when needed. And of course, application modernization.
Uh, you would like to modernize your applications to take upon digital's, uh, cloud native technologies, right? And amongst these, the most important of, of these is to ensure that you have a clear path to, uh, modernize your infrastructure. And, um, obviously no, uh, organization out there has, um, ever successfully and conveniently done a big bang approach to modernization.
So it is always best to, to, to go for an approach, um, that suits your pace, um, you know, so that you modernize what makes sense to your organization first, um, at the same time taking along the, the VMs or the, um, the legacy in a way that lets you, uh, to make it as close to your end target as possible. Um, which means, you know, to, to be cloud native all the way, right? So obviously no big bang approach there.
As I mentioned, modernize what you can, uh, step by step, um, bring in your VMs at this to the same platform and take on your, uh, modernization efforts from there, right? Um, and what do organizations ask for? Uh, they, they need a comprehensive platform that can, um, provide for all these capabilities.
We out here, be it, um, let's pick out a few self servicing capabilities. Um, CSC ding, you know, SD and software defined networking out of the box load balancing multi-class management for, you know, uh, our comprehensive, uh, uh, management and control and observability aspects, um, cost management and, and minimal, right? And if you, you dig a bit, uh, into the, the benefits, uh, on, on such a platform, right?
What could it give an organization? There are plenty, right? A single platform to, to begin with, right?
For all kinds of your workloads, right? Um, uh, the cunet style of orchestration capabilities, DevOps and, and GitHub tooling out of the box operational consistency, you know, be it on premises cloud number one. Cloud number two, right?
So the, the the feel, uh, the, the look, the skillset is all the same. That's what operation consistency essentially means, right? And most so importantly, easy, uh, modernization path for, for your VM workloads too, right?
And, and many more in terms of security aspects, multi-tenancy aspects, you know, uh, lower TCEO, et cetera, et cetera, right? Another why is the need to reduce your cloud spend, right? If you, if you look at the number of hours in a year and, uh, the number of business hours, uh, it's something similar to what is shown here.
The question is how PC are your VMs across all these, um, hours, right? In an on-premises, uh, land, your virtualization solution allowed co committee, which is, um, to take advantage of, uh, the generally low average utilization, right? Uh, of VMs, right?
So all committing lets, uh, you take advantage of the, the generally low average utilization and, and, um, this is, this may not possible on cloud, right? A quick examine, um, is, you know, if there are a hundred VMs in your, um, on premises VMware estate, each of it is assigned for VCP status as a, so 400 vcps in total. It doesn't mean that, you know, the underlying the actual hardware, the physical hardware is given you 400 VVC ps, right?
It is overcommitted, you know, basic. Basically, essentially you're running on somewhere between a hundred to 200, uh, vcps of hardware. So when, but when you move these a hundred vcps or, or a hundred VMCG cloud, you end up configuring, uh, 400 VVC ps, uh, for, for all of your VMs together, right?
And the customer pace, uh, the cloud pro provider for all these 400 bcps 24 by seven, uh, it, it's observed that VM utilization on, on cloud especially is, is on average less than 15%, means a huge chunk of that capacity is unused, but paid for, and customers are not usually happy with their cloud spend because of this, right? That's where virtualization and OpenShift cloud services can help by reintroducing, um, overcoming capability as part of the platform, thereby, um, helping reduce your cloud VM spend by 50% or more. So this is another area why one would want to seriously look at virtualization on OpenShift, uh, especially on Flo.
And of course, the, we ask us to avoid, uh, multitude of bad forms, right? One each for each kind of your work, your, uh, what better than a single comprehensive platform for all or all your workload needs be ai, your VMs, your containers, everything, your applications, everything right? Now, those were some of the whys, the reasons why, what one would want to have, uh, such a platform.
Now, let's look at what exactly is, uh, open virtualization. It's, it's an a PA on runtime, built on qver, a technology called qver, um, to run and manage your VMs in a Q and it is native way, in a sense, in to be able to run VMs as pods, right? Whether has been having a, um, a long history of involvement in virtualization technologies, right?
Right. From, um, the tradition of, uh, KVM in 2007, um, and in 2016, Q Bird project was launched, you know, um, to, to enable VM management on Kubernetes, right? And, and its performance and scale has been proven.
An example here is this popular game, Fortnite, and the sheer numbers given here, right? It runs Q Guard under the hood, um, essentially, um, set operated OpenShift virtualization is a self-managed operator that runs, uh, in an OpenShift cluster. Uh, it preserves your traditional VM behavior.
It offer's administrative, uh, capabilities like live migration, for example, to support your business critical applications. Um, it's built on KVM, um, which is the technology, uh, used by Red Hat and most of the cloud providers for, for 10 to 15 years, right? The, the upstream project cube word, um, is, is the, the, the, the capability used, uh, technology used, which combines the KVM layer with, uh, OpenShift manageability and its ecosystem.
Um, one thing to note here is also that, you know, you could print your windows, uh, guest, um, windows operating system, um, through Microsoft server utilization validation through grammar SQP, right? So the goal ultimately is to run, uh, your, the ability to run your VMs and containers together in a single pack platform, co-located for easy management, low latency video services when talking to, you know, in these services and VMs and containers are talking to each other. Um, same platform also means low skillset gap, right?
Because the tool set the ecosystem, the technology is the same. And, and, uh, this also comes with a state-of-the art, uh, GOI console to, to manage everything under the, um, you know, including VMC containers and applications, everything, a single state of the art go. Um, and now let's look at some of the, the, the platform aspects that helps virtualization itself, right?
For example, networking aspects. Um, internally the platform let's you create multiple networks to isolate workloads, UDLs, or user different networks. Um, let's administ administrators to do this, uh, workloads that needs to be separated and isolated can be run across, um, different namespace and then across different networks for added security and control when it comes to, uh, load balancing, for example, right?
Um, it is similar to load balancing of containers. You know, everything is built into the platform out of the box, so no hassle of having to configure and wire together networking tools and external load bags or separately, right? Um, same with, you know, exposing VMs, um, or VM applications to outside users and to client applications outside, right?
Um, and everything is built in, uh, as mentioned, right? Using Kubernetes technology. Um, another capability is a service mesh, uh, using, you know, HTO for your fine grain traffic control between VMs and services, you know, if you want to have rate limiting or firewalling circuit breaking, you know, observability of traffic, how traffic is distributed, recur response times, et cetera, et cetera, right?
Um, storage, um, you know, storage solutions such as where it had ODF, OpenShift, uh, data foundation or any of the, the, our growing partner, uh, solutions can be used with open vascularization, uh, depending on the kind of workload and use case here, we can also see that the partner, uh, ecosystem is vast and growing to, to offer you flexibility and choice for, for various capabilities, such as, you know, for example, backup and, uh, success recovery, networking, et cetera, right? Um, essentially OpenShift virtualization offers all the core virtualization capabilities that your current virtualization tool, um, offers or has. And then beyond that, it also offers everything you need for modernizing and future proofing your workloads, as you've seen in the previous slides.
Now, when it comes to radar tower services, you get the same consistent and flexible, um, enterprise Bernet experience of OpenShift, uh, plus, um, managed for you by a team of global, um, SREs, right? The, um, advantage being the, the, the, the core compute storage, networking, several of the complexity of, of managing these aspects are uploaded from the application teams and platform administrators. Um, the upgrade, for example, you know, the management management of core, uh, platform capabilities are all managed, uh, the heavy lifting around down those things are, are managed for you, right?
Availability of these, uh, uh, elements, monitoring and quality of services are taken care of for you by our sre. Um, thereby customer teams get to focus on, you know, what matters most for them, that is building and managing their applications and, and not to spend much on the, the, you know, the boring and like, uh, mundane complexities, right? Um, when it comes to, um, when it comes to, um, Manus Cloud services, um, uh, a lot of the, uh, the, um, the, the essential service, service deployment, for example, uh, in terms of how managed clusters can be spun up in, in a matter of minutes that you get, since it's in cloud, um, you get consumption based pricing.
95% financially backed s la and, and 24 by seven joint support between red a and your cloud provider. Uh, and, and, and a lot of, um, you know, benefits being on cloud plus managed service, right? Um, and, and our goal is to allow our customers to move from, uh, 24 by seven operations to, to a nine by seven, a nine by five innovation, right?
You, you focus on your building of applications and deploying and running and managing them, rather than having to maintain and manage the underlying, uh, platform, core, core, uh, platform elements itself, right? Um, so all the cloud benefits like it mentioned, you know, um, and in, even in terms of payment pay as you go, um, we serve instances prior to offers, all kinds of payment flexibility and, uh, in terms of availability, uh, on demand, scalability, GPUs, for example, in these days, right? Where AI is, is critical.
So this is essentially cloud benefits that you get out of the box in a way, you're moving to cloud and to a managed service, uh, when it comes to running VMs in managed cloud, uh, managed OpenShift, right? How, where are, where are, where are these VMs running? What's, what's the underlying, um, hardware, right?
So in A-W-S-G-C-P and IBM Cloud, um, you, um, use bare instance stack offered by, um, by the cloud provider. And in Azure you use, um, uh, post instance text, right? So, uh, that's how you take, take advantage of the platform, um, and, and through unline, uh, hardware to run your VMs on.
Now we saw why, and what now, let's, let's take a quick look at how you can, you can bring your VMs in, right? So migration tool, tool toolkit for virtualization is, uh, is an easy way to get started, uh, with OpenShift virtualization, it helps you migrate your VMs into OpenShift, uh, from your source, uh, uh, you know, um, virtualization solutions for, be it VMware or Red Air visualization, or OpenStack, right? It, it also gives you, as you migrate your VMs, it also gives you, um, provide feedback on, in any identified issues while migrating, uh, VMs, right?
Um, and an an easy to use gui, uh, in with, well, within your OpenShift console, which I will be able to show you in a a few minutes, um, VMs can also be created and managed using the inbuilt OpenShift tooling, you know, DevOps and GitHubs tooling that comes with OpenShift. Um, and, and if a customer has a large, uh, virtualization nested with thousands of VMs, right? Then what makes sense is to, to automate them, um, uh, using, um, redhead automation platform, which is a good solution to consider, you know, if you have got such kind of mass migration or require, this will also drive efficiency in the near migration process.
Um, and not only it, it helps you migrate, but also takes care of your automation of data operations, of not just, uh, you know, VMs, but your entire OpenShift, um, workloads too, right? Um, so it, it, it offers a lot of capabilities, you know, right from configuring the bastion BM to, to kick off all those process to doing rendering, to, to setting up the networking and storage and everything, right? So Ansible automation platform is, uh, to sure con automation tool that you can take care of all your, um, hardware and software, I mean, um, your year, um, OpenShift ecosystem, uh, in, in, in a holistic manner, right?
And, uh, red hat, a CM or advanced cluster management tool is it turned the way for, um, for not really creating and managing your vs. But you know, to, to manage your entire, um, fleet of clusters, uh, across on premises or across cloud, and, and not, not just for VMs, right? It takes care of life cycling, your VMs, your containers, applications, and, um, clusters also across electrical, right?
And it also gives you a single pane of, uh, of glass with, uh, deep level observability dashboards to, to monitor the clusters, DVMs and, and everything that runs inside your, uh, your, uh, OpenShift cluster, um, BM cloud or, and or anywhere, right? Um, and from from the c console console, you can drill, drill down, you know, double flick into, uh, you know, the specifics of a VM to see, uh, how is performing, what the metrics looks like, et cetera. And yet, another way is to approach a cloud provider who also might be offering, you know, different, um, ways to migrate, uh, VMs to OpenShift base in this example.
Um, in this case, it's, it's a no cost to low cost migration, uh, offered by, uh, river middle, um, with a PS. So there are different means to, to get, uh, you know, to your VMs across to OpenShift. Now, coming to, um, customer success stories, you know, here we can see, um, EMS and beauty, which is one of the biggest banks in Dubai are probably Middle East, migrating more than 9,000 VMs you across using MTV virtualization.
Florida is another example. Uh, uh, global investment max. So a lot of customers out there right now, finally to, to, to go to the next steps, right?
So if you, if you are intending to migrate your VMs across to OpenShift virtualization, um, red Hat experts will work with you in a program through a program for virtualization migration assessment program. You know, they'll work with your teams, uh, over a series of onsite in factory workshops across one to two weeks, um, where the migration strategy architecture, um, uh, design the path forward will be discussed, um, agreed upon and documented in your report, um, following that, a high level executive representation can be delivered. And then from there, the mass production migration can be kicked off right Now that, that's, uh, that's a cute look at, you know, why, uh, what and how, and the next steps, if you really wanna start off, uh, now I have a, uh, a bunch of, uh, prerecorded demos too that, uh, we can take a cute look at how, uh, to see how things look for real, right?
Alright, let's take a quick look at how things look for real. So this is an OpenShift concern, um, in this specific case, this isn't, this is in a cluster that's deployed on AWS Red OpenShift service on AWS. So, um, let's take, let's take a look at what, um, operator as are installed for the virtualization capabilities, right?
So here you'd see the operators, uh, section. So through the operator hub, you install the operators that you need to get things working. So in this case, the, the code operators have been pre-installed.
So if you go here and see, here is the OpenShift virtualization, um, operator that's been installed. And for the migration toolkit for isolation that we spoke about, you know, that's also installed. That gives you the, the virtualization virtual machines view as well, right?
So, mm-hmm. Now, very quickly, so we've got a bunch of, uh, VMs that is already running here. Now, if you drill down into each, we see, uh, a lot of options here, for example, to see the metrics, to see how these are performing, uh, which can be imported into or exported to, to the format that you want.
Now. Now let's take a look at some of the, you know, management aspects, right? And if you go to the virtual machines section, again, to one of the windows VMs that's running here, uh, we can access the VNC console from here directly from the OpenShift console.
And let's look at the number of cores that are running here in following in this vm. And the, as you can see, it is using a single core. Now, if you'd like to increase that at two, it's just an edit of the Amal file, as you can see here.
Save, and then go ahead and repu your machine to take effect in a, in a while of what you see is it is going to start automatically and in a few seconds. He, you can see that once it is put back up, the number of course have been increased to. Now, how can version machines be created?
So, again, in the e uh, the version machines section, if notification link, we can click on create, which will give you, uh, a number of options in this case, I see is, uh, the creation to a yamo file. We copy pasting a template and frame the configuration, the details are entered, and that's high. And plus that is right now, not a VM is running, right?
So, you know, if you wanna delete the vm, again, go back to actions and just click become delete free. And the resources, right? Now, we meant, we spoke about low balancing, right?
Let's take a quick look at how that works. So one of the namespace where the, the, uh, in this machines are running, you're gonna take the app label, which can be used to create the service, which is, uh, the Kubernetes server source that helps you load balance between services. So you can create a service, keep the same label that we copied from so that it goes and load SBMs.
And since it's a Windows machine, the service that here load balancing SAT, and now the two Vs have been broadbands by that service. Now to expose the service or that application outside, let's do that by creating a route, right? We are creating a, a route which helps you expose the application to the outside.
So we are creating a, um, a route with, to which we are giving the service, uh, the ALI service that we created, um, in the previous chapter, and then during the board mapping. And that secure here saying air, which means the keyless estimation happens, and the re controller, and in case HTPs, it'll be redirected to HT ps. Now, a route has been created.
Now that's, that's how it is. We access the application, right? So likewise, a lot of capabilities out there, managing outbound traffic, uh, in you saying network policies, right?
Um, click, look at how things again, Right? So here we see that, you know, um, when we access this, um, service, it is accessible because getting HGP 200, okay, now we're gonna create a natural policy to block that, uh, access, right? So we created a natural policy here, blocking the egress.
com, which worked earlier. Uh, 'cause we got 200 earlier. Now, because we have calling network policy, um, we have, they're blocking TX traffic, right?
So, likewise, and a lot of, um, management aspects that you get out of, um, the virtualization, um, options in new week. Now, what do your administrators see? Uh, is, you know, once, once your VMs are running, they get a, a topology view where a graphical or ion of how VMs are, are running, um, how in, um, in, in cloud containers running there.
So it's all given to you in a, in a graphical representation in your topology view right? Now. Let's also look at how live migrations work right?
Now, these are some of the VMs that are running here in your, as VMs in your OpenShift cluster. Unless take a look at how, um, live migration can happen, right? So here, if you see the VM is running on a, a node that has current name, but in three, now, here, going to the three dots, at the end of, uh, three line, you click on, uh, the micro option and the VM is going be moved to another node, right?
Right. So it's now in running status. Now, if we go back and look at the, the node that's now running on, there's changed still, uh, a node name that run in suite two, and by, you know, how it used to be.
So that's a good look at some of the migration, um, capabilities. P um, migration capabilities and how management aspects blocks here. Uh, now to look at, let's also look at how the, the MTV, um, helps you migrate VM spec.
So this is your v send a little static. So here's where you know the source. Now, VMware estate is where couple of VMs are running, know, um, the names are ending with Dash demo one, fedora and Linux.
They're in, in running status. TBMs all on, yeah, this one has a Windows vm right? Now, let's look at how we can get them migrated to the open station.
So, so that we are ensuring that the application running on all the VMs are indeed intact and working now and on the tap, let's go to the OpenShift console. In the migration, um, left application section, you can create, uh, we can first set the providers. So in this case, the, the local host provider, which is nothing but the, the, the, the cost for itself.
And you've got, uh, VMware also as, uh, one of the providers. And what we have to do is to go and create a plan. We're gonna create a plan to and select VMware as the source where the VMs that we intend to migrate exist.
Now. Now we, you are featuring the VMs by the name that ends with demo. So we got a couple of them that we saw in the cent earlier.
They're in our own status. Now, let's create a plan to migrate them right here. So you give them a name, and then the networking storage mappings are done.
And then currently become a clear migration plan. Now, by default, it is, uh, cold migrations enabled, but then let edit that to, to, um, configurate one migration so that you, there is no disruption to existing application running, although on those VMs, um, while they're being migrated. So let's start the migration, right?
So as you can see, the migration process has been initiated. So we've got two VMs that we are expecting to be completing Microsoft through here. Now on the VM section, we can see that the, the pipeline processes initiated.
We've got a, a list of items to go through before the complete migration can happen. So, right, so the pro, the migration is pro progressing. See, most of the time that it takes us in the disc crisis because, you know, uh, the storage has to be transferred, Which is going on.
And then we skipped around the hard and a half fast forward, and we see that it has reached the space that we have to now allow for a cado, right? So it is paused there. So we can go ahead and improve for the cado, right?
So we still go back to, um, the V center. We can see that the VMs are still working. No, um, impact to, to the application running there.
Now, let's do the control to bring them here, right? We can either do it now or we can schedule it for a future time and date. But let's take right now, right?
So the pipeline purposes, 'cause you have approved to cut over. Now in a, in a while we can see that the entire process, the last bit of data is also copied. And we've got, uh, the VMs completely running here, right?
If we go there, we can see that the, the pipeline is completed. Now, if we go back to the V and check out the status of those VMs, now they're in powered off status, right? 'cause that those have been migrated all the lower end.
Now, the, the customization tab here, fico, injectable VMs under the inch place that we imported those VMs into, we can see that those are here and running status, Right? So boths are up and running here. So that's a cute look at how migration, um, can be made possibly using MTV, right?
So, um, that's about what I wanted to, um, show to you today. So hope, uh, that the session and the demos were useful. Um, feel free to reach out to your, um, local Red Hat account teams in case, uh, you want to, uh, try this out and, and want to take advantage of the open ization, uh, for your organization.
Yeah, thank you. Thank you for inviting me. Uh, glad to meet everyone here.
Um, so, uh, what I like to do is, you know, when I used to go to conferences, and I probably, I've done over a hundred assessments, but I've probably gone over 10,000 conferences. Um, I like to go once where I can take something back and make my, you know, like I learned something, you know? Um, so when I've been doing presentations I like to do, here's what I've learned.
So I've, I've actually done, I don't know, 150, uh, different assessments since I retired of government agencies. Um, I worked with the Ukraine government for a while, getting ready for a war. We kept telling them was gonna happen, and they kept saying, no, it's not gonna happen.
Um, and, uh, NATO and other organizations helping them do cybersecurity. I know some of these Russians, the bad guys, a PT 28, APT 20, I know 'em by name. Um, and I know what they do.
I know what they like, I know what they find. I know what they look for. I know what they don't like.
And that's what we're gonna talk about today a lot. Uh, so I said, well, all right, I'll put a presentation together on, uh, things I think are working, and then I'm gonna talk about some things. Frankly, I don't think really working out.
I used to say they, they suck. Now they're underachieving. We, you know, um, oh, that's just who I am.
I have my own company to be secure. After I retired, I came up with the name to be secure. Two days after I got a, uh, email from a guy from mosad, he says, Hey, I love that name.
We're setting up a company too, called two be Secure. Lovely. Mm-hmm.
Um, agenda. Um, so after a hundred odd assessments, you know, you get to learn a little bit about what a good program looks like. Uh, so just some general observations.
When I go into a company, if I see these things, you know, I said, all right, we might have a, a chance here when, when that happens, by the way, I'll let you know, just, just kidding. Um, cybersecurity capabilities that are frankly underachieving. Uh, and that's kind of, this is, I'll be honest with you, I get a lot of controversy, uh, on this one.
A lot of people don't like me pointing out their favorite program. Uh, and then I'm gonna talk about, there are many, but I'm just gonna talk about 11. I just chose, um, more from recent experiences and recent incidents involving some of the a PT groups, uh, that the hackers don't like to see.
You know, if they're gonna drop a payload on your network, if they see these things, oh Christ, you know, they gotta work harder or they just leave. Okay? So what does a good cybersecurity program look like?
Uh, it should be no surprise here, by the way. Okay? So the CSO is independent from the CIO ct, should have no relationship with them.
However, from a reporting organization, they should be separate. They have their own organization. They're on par with the CIO or CTO, okay?
But they represent security, alright? Two different disciplines altogether. It is not security, and security is not it.
Um, security function is included in everything. You know, you don't work for the CIO, but you work next to the CIO and they don't make decisions without the CISO being involved in everything. Um, no shadow it, the bad guys.
I'm telling you, one of the biggest, most expensive databases to get access to is your Shadow IT database, which eight, which is run by a group. Um, shadow dancers. Um, hiding and deception is part, oh, none of you come from the intelligence.
Well, IRA does, but none of you come from the intelligence community and you've never really, well, let me ask anyone else from, okay? And, and there we go. Very good.
And, um, we, part of our program in security and encounter intelligence is deception, right? I go into these companies and, you know, before I go in, I know everything about 'em. I've gone in and handed them their admins for their Azure account.
I say, where's this guy today? Um, okay, no one hides anything. Uh, here's the key one, and this is true.
Cybersecurity hygiene is optimal. This is what you spend your day on. It's not sexy, but the patches have to all be made, all, all the, it has to be known.
All has to be visible. All has to be it. It all has to be, you have to really secure your admin accounts down.
All I'm not gonna go through, this is not presentation on hygiene, but I'm telling you, I'll tell you again, I know Iris told everyone this a thousand times. It's all about hygiene. Mm-hmm.
There's no tool, there's no product, there's no tool that can replace good cybersecurity hygiene. And, and frankly, it's, it's probably the least expensive one. Uh, by the way, um, no users have administrator accounts or access, no users right?
Now, admins also have user accounts, right? Mm-hmm. And that's what they use.
But no admins, no users have any admin direct members of any local admin privilege groups. Any, uh, domain, uh, privilege access groups, no cloud access groups, okay? Um, privileged user accounts and software secured and monitored.
I'm gonna talk about that a little bit later. How, where that's important. But that's what their, that's their target.
That's what the bad guys make the big money off of. That's what they sell. Those credentials represent admins, makes their lives a lot easier.
Um, only provision and managed devices are allowed on the corporate network. The cloud and SaaS is not your network unless you own it. It's to be untrusted.
It is the playground for the A PT groups. In fact, I'll be honest with you, I want them who it is, but they own one pretty much and go anywhere they want. Um, IIC networks, ICS networks, your industrial control networks are physically separate.
The neurological, I I, I go into all these industrial control companies all the time and they talk about how great they are isolating their networks. And I say, well, show me where they're isolated and they're never isolated. They said, well, we got these VLANs where we got the, I said, oh my God, please stop with the VLANs.
Um, you're talking An isolation like with one way dial. Yeah, you can play the one way diode game. And that, that's, that works okay.
Yeah. But, uh, they, yeah, they were okay. Alright.
Um, and all administrators are subject, oh, no one, the financial industry is replete with this problem. They don't know who their admins even are as people, right? Mm-hmm.
There is an active program right now from the Chinese Intelligence Service in New York City where they're recruiting people with admin privileges on, on Azure. They're walking around looking for 'em. Well, they already got the names and everything, but they're, they're looking for 'em and they're recruiting them.
And they have been successful, thank God. Finally, the FBI is onto it after a lot of us told them for a long time, Hey, you want to look at this thing? Alright, anyways, okay.
So that's what a good program looks like. Kind of a quick overview. Uh, let's jump on.
Alright, so now to the controversy. What's not working? Cyber threat intelligence.
Completely useless. Completely useless. First of all, it's not intelligence.
Intelligence is something that's covertly collected that the bad guy doesn't know you have and you can use operationally against them. What you all get is called cyber threat information. In fact, when it first came out back in the late eighties, early nineties companies, they called it the cyber threat information.
But they decided, Hey, hey, I know what to call it. 'cause they don't know. We'll call it intelligence.
It's not intelligence, it's information. The bad guys get it too. In fact, there's a group in St.
Petersburg, I still call it St. Petersburg, um, that make it, they actually produce it and push it out there. And all these companies are ingesting it and they're feeding it and they're putting it in formats.
Um, data encryption, you don't do it right? People, you know, you know the old standard, you have to do encryption and data in rest and data in transit, okay? It's, you might as well not do it because what they do is you turn the damn thing on and then you make the group, everyone's in the group.
It's an access control mechanism. It's supposed to be used as an access. We used it in the intelligence community.
So, and we did not give the keys to people. We did not want to have access to the information. Alright?
That's it. The way you should be using encryption, uh, credential vaults. Complete waste.
Complete waste. I've never talked to a hacker who said, oh, that company's got got a credential vault word onto the next one. They don't care what's in your vault.
They care what's in your cache, right? They're not going after. And by the way, I don't know if it was a black hat or yeah, I think it was black hat or maybe, no, it was def com.
Um, someone did an operation, they test where they tried to break into the various, uh, open source and I, I forget which commercial one it was, maybe CyberArk, I might be wrong. Um, they got in 20 minutes, owned it. It's not like their written in some secure programming language.
One guy, one of the guys who I wrote his report said, you know, they're using open source libraries from 10 years ago that are unpatched that they haven't patched. And this is where you're putting, this is where you're putting all your secrets in. Oh God.
Um, oh, alright. Badgering employees with listen, you wanna test them Fine. Firing them, badgering them, showing them, dragging them out in public in front of everyone else.
Now, that's enough already, okay? It's your job to protect them against the bad guys. It's not Alma in accounting.
It's not her job. She doesn't know what the hell she's doing. She doesn't know what the different browsers are.
And you're telling, and you're badgering her about, you know, Hey, that's a potential fish. Don't click on that link. Tell them once, tell them twice.
Okay? But please enough with the, with the, you're not making friends, by the way. And I'm telling you, cybersecurity organizations I think that work well are the ones who truly partner with the employees and, and have a relationship.
You don't wanna be seen as the ones who, oh, those are the guys who I get an email every once in a while. I have no idea what the hell it's doing. Um, data loss prevention products.
It's not that they're necessarily bad, but there's so many ways of moving data outta your network. Absolutely. Right?
You know, again, you talk to the hackers and they said, you know, do you, does these things stop you? No. No.
And their answer is, what are they exactly? And they said, no, we just put 'em in dn. We just, you know, put it in a DNS label and ship the stuff out.
I don't care about their, you know, in fact, the more you encrypt things, the less you make itself visible to you. Right? They love their favorite thing.
Now, in fact, the Russians, this was a campaign. There's this thing called DNS over H-T-T-P-S created by who? A PT 28.
And it became a standard. And companies are going around selling. We've got DNS over HTT PS now.
Oh good. Now you can't see what the hell is going on in your DNS. Um, okay, boy, this is the one I used to teach a course on this cybersecurity complaint compliance frameworks.
Um, yeah, I was on the 853 initial meeting group that, you know, had the first discussions what we wanted, right? We wanted a race horse. What we got was a camel, a a 75-year-old camel with humps going onto the left and to the right and couldn't walk straight.
And I mean, we didn't get what we want. These, these frameworks. My number, I have a lot of complaints about 'em, but my number one complaint is they all judge cybersecurity controls as the say, you gotta do all the following.
No, you don't. You have to do the ones that stop the bad guys first. It's all, in fact, by the way, I can say this in the cybersecurity framework, you know how protect is second, it used to be fourth.
And we, we argue, we, we just said no, that can't be. We wanted it first. And they said, no, you can't have it first.
So we got second. Um, but I have other concerns, Bob. Oh, third party security questionnaires.
Guess what? They lie mostly they don't know. They don't know.
You're asking them questions about their network. They're like the last people to ask. They don't know who's connected to them.
Right? And that's, that's the problem. You should be asking the questionnaires of the least secured company that they're connected to and that they're in it.
So having a fellow questionnaire is that auditors compliance, police, they all like those things, but it's completely way useful. You your job. I'm gonna talk a little bit about, I think how to better secure that relationship.
And sims, let's go on to the next one. Wow. Um, again, you can't get good quality index data quickly.
You can get one, you can get the other. You're not gonna get both. Um, application layer firewalls again, because a lot of encryption being used.
Um, data encryption, application layer encryption, network encryption. They've increasingly been unable to and as an industry, I don't know, you probably don't even read about 'em and people even talk about them anymore. It was one, it was one time the, uh, AI topic of, of cybersecurity.
But they've been proven to be really unuseful and, and and slow by the way. Um, okay, so that's my list of, there's actually a longer list, but I, I, I wouldn't emphasize. But here's some things here.
Here's 11 tricks I'll call them that you ought think about. If you're not already doing them. You wanna think about doing.
'cause these are things, as I said, you know, the A BT groups don't like certain things. These are some of them. Next SMB signing, they hate it.
SMB signing and what's the other one? Extended protection for authentication. 'cause that basically ensures every session connection.
And then every cookie passed, or every credential passed is unique. Alright? That keep, that's where they like to get into their, when they say you, they moved laterally.
Think SMB. Okay? That's the protocol of choice.
Make it hard for them to do. Now the problem is when I go into a lot of organizations, they tell me they've got SMB signing turned on because, and windows those 11 two H two two I think release, it was turned on by default. But guess what, when MFI Microsoft does the patch Tuesdays, they turn it off sometimes to turn to be able to make some patches.
Then they turn it on on the way out. Well, I was talking to someone from Microsoft, he says, sometimes maybe the turn back on didn't work. So I don't know what that means.
But anyways, you really gotta check and make sure both SMB and um, extended, uh, enhanced protection are both, are both active all the time. Just doing that, you know, you are gonna reduce your, uh, exposure. About 11%, 11, 12%.
Next, Kerberos and TLM was created by someone in 1988 who had, Microsoft had no kind of, uh, novel like authentication token that they can use. So they came up with this thing, uh, and it became a standard and it's not secure and it's been abused time and time again. Um, it is also off by default in 11 and I think server 2025.
But again, every time I go to places, it's like they have to run it because this application needs it. Well, as long as that on in your network, you're dead. They're gonna, they're gonna get you and they're gonna exploit it.
Um, and then protected users group, the reason why I like it is this is a group, this is a, um, windows policy group. I think you do it in, uh, GPOs or in, uh, Intune protected users. Uh, and with protected users group, it makes it harder for things like ransomware to run because certain folders, system folders and users folders are protected from access.
They're only accessible by certain applications. The other thing it does is it clears the credential cash of that session. When that session ends.
Uh, that's what you wanna do. You don't wanna leave cash credentials around Next. Oh, how many people actually really turn on and use Microsoft's virtualization based security VBS.
Um, you should, When it first came out, it didn't work very well. But everything Microsoft first, you know, any company comes out first has its issues. And a lot of people turned it on and found that this application went low as in a virtual uh, machine.
And Hyper V didn't work on that computer 'cause it didn't have enough memory overall. They kept dropping and leaking memory. You know, those days are pretty much over virtualization based.
Security is one of the key things. It's when, when the, when the, um, when 28 a PT 28 drops a payload, there's a list of things they look for. This is number two, Okay?
They look to see if VBS is turned on. 'cause if it's turned on, that means to go find the credentials. You have to break into the credential cast.
That means a kernel call. That means your EDR might catch it. Okay?
Now they're thinking, oh Christ, oh, what do I do? Uh, they might go on to the next one, but they don't like having to go down these steps. Of course, most people don't turn it on.
Um, or they turn it off. If it was, if it was on by default, uh, no, you should be using all VBS functions by default. Now, there are some apps, older apps that people run locally that you can't virtualize 'cause they need real memory calls to the real address.
And, um, but that, again, this was now 10, 10 years ago. I have people, I have a big, big client. They've got VBS running across their entire network of over 80,000 machines.
Not one problem. Next, Oh, remember I mentioned you all don't think about you deception and hiding. Here's one.
I know I had one in the presentation. Um, you can hide your domain admins from discovery. Most of the bad guys tolls and they haven't figured this out.
Well there, there's no reason to figure out 'cause it always works. All they do is list objects, okay? And if their reconnaissance program list doesn't, you know, tries a list object and nothing comes back.
And that's what this would do, right? Then they don't have any admin names. They don't have any credential.
They don't know where to go. They're not good. Not, it's not that they're not good enough.
They don't have the time or energy, frankly. 'cause they're very, very lazy to dig deeper and go in and turn it back on and then find out, you know, they, if it's a real target, yes, this is just a, just a small little block in the road. But for, for 99% of your malware, this blocks them from being able to go further and watch for, if they do try, they're gonna hit event ID 4, 6 6 2, which is an action against an admin, uh, account like raising the privilege.
Next, uh, how many people use UB key? So I said before the number, the number two thing a PT works looks for was, um, whatever I said A BT number two was, this is number three, UB key. If it there, if it requires UBK not for the administrator to log on, but for the administrator to issue commands, administrator commands, okay?
Which you can also use UBK for which no one does. Um, now you're stuck. Now you're stuck.
Because if I'm trying to change an object's A or change an administrator account and that thing comes up, you gotta insert your UB key or you gotta put your pin for your UB key in. If it's already in now you're stuck. Now.
Now they, they don't like that. Um, anytime you're modifying a registry or any type of system, um, object and uh, they always have the administrators have to use a UB key next. Yeah, I'm sorry, Is it any fido sue or specifically UB key?
Uh, I like the UB key. Fair enough. Yeah.
Uh, here's one. Don't use the Chinese made ones. There is, there are, there are companies who make, um, there's, let's say there's more than one key in the UB key.
Um, but I did have a company that went out and said, well, why do we need to buy the UB key one? We can buy these at, you know, 40% less. Um, okay, the cloud's not what you think it is.
I always thought, I thought over these slides when I was flying out here thinking how do I present this one? The cloud's not what you think it is. Um, the bad guys are all over Azure.
They have to be. 'cause that's where you're putting, that's where everyone's putting their data now. Uh, right?
Um, everyone's moving to Azure or AWS, um, but they're especially focusing in on Azure. Um, Well I work with companies and help them build cloud-based environments. Uh, there's a couple things I mention that, uh, I want them to do that.
Frankly, most of the times they don't. But one of them is to use a physically dedicated host in Azure for their ad. If you can't be confident of the machine your ad is working on, you can't be confident of anything.
It's all about ad that's the target. Okay? So if you're putting your ad on a machine that's being also used by someone, let's say, who is less security conscious and they've got, I don't know, some application running in there, um, and the bad guys know how to do reconnaissance within Azure to figure out what's running where.
I've seen spreadsheets with elaborate, uh, labels from the, in, from the virtual machine. Who owns it? What's running?
How long does the process run? What is it? You know, uh, where are they getting that information?
They've got penetrations in Azure, physical, personal, and technical. Um, it is, it is more expensive to run your own physical environment. And I'm saying you have to do it for everything.
Although I, I might. Uh, but certainly for your key databases and your and your uh, ad, um, next, Okay, I don't know. But a lot of times when I've been called in in the last, I'd say two years, it's all about this issue.
This whole third party access issues, got boards of directors all upset. It's got CIOs all upset. No one knows what to do with it.
How do I handle it? How do I make my company work while still allowing people access? Um, I came up with an, uh, an idea, actually one of my clients kind of came up with it and I helped them implement it.
Um, where what we did was we got all the goal, I'm sorry, the goal was to get them completely off of the, their network. Some of them had VPN access, some of them had gateway access through these crazy kind of remote zero trusts, gateway servers things. And, but the point was they eventually got an H-T-T-P-S connection into the network.
That was the problem. Okay? Because the bad guys are on the other network, right?
And all they're waiting for is for someone to make a connection into the network. The protocol frankly doesn't really matter that much. Um, so our goal here was get them off the network completely.
No direct access into the network. And what we did, and this company had some money where they could spend on these things. I, I'll, I'll grant you that.
This is not the cheapest way of doing it. Uh, we build another Azure Forest that this company came up with. And by the way, we didn't name it by the name of the company.
That's another thing you all do. They go out and they build you, you go out and you go into Azure, you buy a cloud and you call it by your own company name. Yeah, that makes a lot of sense.
Let's tell everyone who builds a catalog about Azure, where I'm at and who I am. No, don't do that. Anyways, so we built this other forest.
Every third party has to go into that forest. Some of 'em use the, um, in this case because we had some concerns with the company in, at many levels at, with the third parties, we gave them, uh, Azure Remote Desktop, that they can't come in from their own physical. They have to come in virtually.
They connect to the third parties cloud that this company runs. Alright? And most of the resources they need to work on or either put in that cloud for them to work on or from that cloud, they can get access not on a, not on a Forest trust relationship, but they have to log into the company cloud and and only get, and they can only see that application.
That's the only thing they get access to. They never see the underlying network address. And that cloud is not an extension, obviously, of the corporate network.
It's a really, truly a separate network. Can't say it's physically separate, but it is truly separate. And basically that was the only way.
This is, this is a big engineering company globally around the world. They do support for the US government some very sensitive, um, uh, development and engineering work. Um, and they were just getting hacked to death by all their smaller third parties, engineers, architects, designers, everyone, you know, small companies who have access.
So this is what we did. Uh, and their hacking of their own internal network was went like this, right? Right off the table.
Next DNS. Yeah. Uh, it's always underappreciated as a security, as an attack, uh, vector.
Uh, it is the primary way most groups xFi by the way, it's also now the primary way a PT 28 infills. Uh, so you gotta monitor it really, really well. Most of the gateway DNS services, they'll eventually get, uh, updated signatures to mo monitor for misuse, but they're extremely slow.
And because of the way the AI algorithms are working where they can do fast flexing and automatic domain name conversions, um, there's no way these, they can keep, they can keep up. So, um, you have to monitor yourself inside your own network for DNS misuse. And that's, to be honest with you, that's the way you're gonna, most organizations I've worked with, and I talked to people at Mandiant, uh, I was meeting with him last month on a shared client.
That's really what they focus on. They, they go back through the, the very first thing they do is go back. They go the DNS records.
They don't really know how people get in. And I'll be honest with you, there's a lot of times I don't really real think, how the hell did they get in here? Uh, but they gotta get out.
Right? Right. They still got, even the best int intelligence service in the world has gotta get the data out somewhere.
Okay, next. Oh, how many people are doing this Windows hot patching? They don't, they don't S ma tell this, tell people about this.
The sale. Microsoft sales and support people don't talk about this very much 'cause they frankly are a little nervous about it. I have a client, not, not the same one I I mentioned before, but another one smaller of about 2000.
They've now have both their Windows servers and clients are all being hot patched, which is really nice is it takes that whole bureaucratic discussion between the CIO and the CISO and the it and the data owner. And it just basically blows it up and it says, we're going directly into memory, putting the patch in. It's gonna, it's gonna eventually take place.
Right. You know, right as you need it. And that's it.
And you know, no one's gonna have to turn things off and turn things on. No windows, you know, we're gonna be closed. It's Christmas and hot patching is the way to do that.
You have to move slow. You need modern operating systems and, you know, uh, uh, devices. Um, but, and, and it was a little cranky at first, um, but Microsoft, to their credit, has spent a lot of time on this.
And eventually this is gonna become their default. You're not gonna have a choice. If you want patches, it's gonna go hot for, for certain critical, like all the ones we've been seeing lately.
No, I'm just kidding. Um, okay, next. Yeah.
How would you deal from the, from the PE side where, you know, you, you buy a patch and then it starts breaking stuff all application. And that's usually the, you know, the complaint that I get from, uh, Yeah. So this, this company, it Broke and sometimes it does, This company I mentioned before, uh, they're not the most progressive company it wise.
And they do have some, uh, they're an inside the beltway DIB contractor. And, um, but they were getting hacked right and left. And I said, you gotta try this.
Yeah. There might be something to break. Nothing broke.
Nothing broke. And again, they're speed to catch. Bad it, they don't even measure it anymore.
'cause they're, they're patched. They are patched all the time. Okay.
Um, I'm not gonna spend a lot of time on this, but, um, in addition to the two ones I mentioned, earliers, this is what you're seeing ought to be doing. Analyzing the hell out of these events. 'cause these are the ones that I and other analysts and consultants look at.
Um, also, by the way, I noticed I had put this in, if you want advance auditing now, I'm just the messenger you have, you have to buy purview. Mm-hmm. Sorry.
Uh, what the two have to do in relation to each other. You can ask someone from Microsoft. And then lastly, uh, this is a favorite of the, uh, next, this is a favorite of the intelligence community.
Um, I think we were probably one of the first at CIA, we wrote our own, um, to do this. But now you can actually go and buy one, uh, content. You, you wouldn't believe how many, How much malware still gets delivered in PDFs and macros and VB script.
I mean, a lot of them because they're getting better at obscuring the executable content. Right. And tricking eds, uh, into thinking that they already check this label.
I mean, they're really good at it. There's lots of different ways. Um, I've been towing companies.
Anything that comes into your company has to be flattened. And it's, again, one of those measures that the bad guys will look for, you know, when they drop ACON package is are, and is there any content disarming going on here? 'cause eventually I need to deliver them, uh, phishing emails or some type of way of moving files into their network.
Um, and they don't like to see, you know, the CDR. Um, and the way it works is they ba basically consider everything malicious. I like the way they work.
They consider everything malicious. Whether they, whether they can find something or not. They flatten the file, which means it's, it's an image.
It's truly an image. Now, everything in the, in the file is an image. Um, and by the way, one of my clients who uses it consistently, I have a lot of other clients who've been calling me about AI poisoning and AI injection and, you know, they're all worried about that.
I talked to these guys and they said, what is that? We don't, we don't have any problem with that. We flatten, it all comes in itself flattened.
We don't, we don't care. Um, okay. Uh, hopefully I left some time for questions.
Did I leave time for questions? I think I did. A few minutes.
Five minutes. Oh, thank you. I missed you.
Yes. Uh, So you were talking about the third party approach. Yeah.
It sounded like a jump box to a degree, but it also sounded like a jump box plus like some type of ZTNA. So is that the goal is to give 'em just direct access to the application, but never to the underlying server? Yeah, it's, it's not really a jump box in the sense that the jump box itself is a computer that makes a connection on your behalf.
Remember like the two card thing roll use, but it's still in the same computer. This is happening at a different abstraction layer altogether. This is happening up in the cloud.
Okay. And if you play your game, if you play it right and use the ACLS as to where they can go, once they're in their own cloud, you can tightly control what applications they get access to, uh, in your network. When you do the gateway kind of thing, you're still establishing a lower level network connection between the devices.
I don't want you to do that. So What if you have a cyber physical system and it requires a server, something that you have to get into, because that's the only way the vendor can access the Equipment. Oh yeah.
They had some of those. So it wasn't, it it's not a hundred percent. Okay.
Yeah, they had some basically who needed native access with the native protocol into the network. That is true. Um, but they also put them on notice and said, this is going away.
So for the next contract, um, you have to figure out how to do this remotely from a cloud. Oh, Bob, can you repeat the questions So that, oh, I'm sorry. So the question was, um, the solution where you bring the third parties into their own cloud environment that you run for them, you know, is this the same thing as a Bastion gateway?
And there's some similarity, but actually it's, it's not because the Bastion gateway directly connects your network. I'm trying to keep you off the network. I don't want them to see, here's what I don't want them to see.
I don't want them to see the switch and routing infrastructure because then they'll understand what to do. I'm trying to keep them so they don't even see the underlying network infrastructure. And by the way, please, if you've done this the second you get back home, undo it.
If you've made the cloud network an extension of your private address space, oh God, do not do that. I don't care. It's Google.
I don't care if it's AWS do not do that. Hopefully no one's done that. Right.
Good. So you've gone through a lot of Windows. Do you have any, uh, suggestions for Linux and container based?
Yeah, well, my only container suggestion for Linux, and I was gonna like this, is you gotta turn on SE Linux deeper than the default, which I think is currently, uh, block mode maybe. Okay. You need to have SE Linux covering all applications that make kernel calls.
If you do that, go on to your next issue because SE Linux, a US government funded project, works and works very, very well. And don't use App Armor. App Armor, it's the first word is app.
It's an app. Okay. Yes.
What about for organizations that are about 90% Mac? Yeah. Um, Um, the trusted Mac TCB and the feature that they call, um, lockdown mode helps a lot.
The problem is it's still, it's a Linux, you know, it's native Linux, it's actually native Unix kernels and some of it's not very good. Um, but again, the notion is to keep them off, keep them away from, if you limit your admin exposure, you know, if you limit your network exposure, keep them out so they don't see your network, you're, you're gonna probably be okay. Um, but it's, it's, it's hard.
It is harder. It is harder to do, believe it or not. I think we have time for one more.
Yes. I notice on neither one of your list included multifactor authentication, but you did bring up Beauty Key. Are all other coins of M FFA no longer?
I I just assume everyone's using I that's a good point. I probably shouldn't assume that. I just assume people were using FMA either application based applic, you know, uh, MFA, but, um, again, they'll, they'll work hard if they want to, to wait.
You know, what they do is they have code, uh, actually I saw this with Scattered Spider recently. Um, they actually have code that WA waits and watches for the MFA response to occur. Okay.
That's when they load the mod after you are a authenticated is when they load the, uh, malware module. So they know they've got a certain amount of time, uh, to use your session token to connect to ad. Um, so the fact that you have MFA is wonderful, um, but it doesn't really stop them.
UB Key works at the hardware kind of works down at the layer because it's exposed to the TPM. Right. And if you, if you make them have to use it, that that, they're not sure how they're gonna do that.
And number one, that session token, that the UB key uses is fully inside of an encrypted session itself. So they haven't broken that yet. Okay.
Yep. Okay. Oh, yeah.
Now We gotta switch. Yeah. Okay.
We're done. Right? Yeah.
Okay.