Techstrong TV – January 27, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Happy Monday. Can you believe there's controversy surrounding the new administration already?
You are watching Techstar Gang. Hi everyone. Happy Monday.
It's Alan Shimel for Text Strong and you're watching Text Strong Gang. We've got a full, uh, usual gang lineup and some, and you as usual, three different segments here on Text on Gang. We're doing something a little different.
I don't know how you're watching it, where you're watching it, when you're watching it, but we're, we're dividing up the segments so that if you don't have time to watch the whole 40 or 45 minutes show, you can grab just the individual segments up on Techstrong TV and soon on our OTT, uh, app. So, you know, however you want to consume the gang, we'll try to make it consumable. Let me introduce you to who we have of kicking off this wonderful week on the gang with us.
I think first we're gonna go out to see and, and, uh, grab our cybersecurity expert as well as nautical, uh, I don't know, nautical Admiral Chris Pirate, resident pirate, that's a good word for him. One and only crisp blast. Chris, I know it's cold out on the seas today.
I hope, I hope you're staying warm. Uh, we're doing good. My wife Donna is with me.
We've sailed down from Melbourne, Florida. We're down in Riviera Beach and Palm Beach County and about three days sailed from you in Boca Raton. Well, I'm looking, hopefully it'll warm up by then.
Uh, my boat's going in on the 28th, so try to get here before then, if you could. I'm working on it. All right.
It's, uh, it's going in for its annual physical, I guess, um, with Chris. Thanks for joining us. Let me next go out to Colorado, where one of our studies, future VP analyst, Mitch Ashley is hunkered down.
Hey, Mitch, how are you, man? I'm doing well. I'm, I'm a little landlocked co.
So I, I can't volunteer to be on Chris's boat ship, whatever you call it, but I'm, I'm there with you in spirit. Chris, hang tight. All right.
Now you, you're kinda landlocked now for sure. Next, um, let's go from Colorado to the mountains of New Mexico for our, uh, friend Tracy Reagan, CEO of Deploy Hub, uh, c CD Foundation. Is it Tech Leader or, I don't even know the title.
Title. I'm a you are, you are one busy, busy girl. Always.
Yeah. Hey, Tracy, how are you? I'm fine.
We are starting to warm up here after last week being absolutely freezing. Um, and yes, I'm on the board of the Technology Oversight Committee at the CD Foundation and on the open SSF, uh, governing board, uh, around open source securities. Absolutely.
In addition to deploy Hub Aurelius, submitting a whole bunch of speaking proposals and a lot of other great things. Welcome. Uh, next is, is actually, is she still our newest gang member, or has someone come in behind her already?
Mike, I think she's still the newest one so far for now, but you know that that may only be, uh, for a little while. All right. She's is, she also is the editor for Text and ai gestalt it, and really knows her AI stuff as well.
And I'm still working on her name 'cause it usually takes me three months to get people's names right. Langa, Sala Saha. So tell your last name.
Yeah. Yes, it's Soha Saha. Right.
Sona, welcome. It's good to see you. Thank you.
It's good to be on the show. It's, uh, Palm 24 Degrees here in Ohio. Woo.
Which pay a long shot better than the Sub-Zero temperatures we had earlier this week. Yeah, So, well, it was 47 here today, so, wow. It makes me feel a little, it doesn't really make me feel better.
I still feel cold. Um, but I'll talk more about that in a second. But let me introduce our last gang member for today, certainly not least.
He's the chief content officer here at, uh, tech Strong and Mike Ard. Hey, Mike, how are you? I'm well.
I have a question for you and Chris. So like, are you getting ready to put together like a boat race for pinks? Are you gonna, like, you know, Trade for for res right boat?
Race for res? Mm-hmm. I was think we call it a regatta.
I was gonna say yes. Robert Regatta. Yes.
I were off a flotilla. Yeah, we're actually, we're gonna, we're Move, we're a flotilla, or look, we could be a fleet. We're the, uh, AI fleet.
We're about to take in about $500 billion in capital, and we're gonna build out some capital ships here and, uh, we'll go from that. Um, but, you know, an interesting thing about the weather. So I, you know, I, my car is supposed to be an intelligent car, and, you know, down here in Florida, we don't put the heat on.
You know, my car is set, you know, climate control when not driving in today, all of a sudden I notice the, the, um, steering wheel started heating up. I started getting hot air blowing into my neck over here. The seat warmers went on.
I didn't turn anything on it just, you know, it just figured out it was really cold out. You better do something for this guy. Um, and I, I said, now that's ai.
That is what we want out of this thing. I didn't ask for it, but I needed it, and I got it. So, kudos to BMW on their intelligent driving machines.
And that sounded like the story of the frog in the pot, right? Pretty much. Anyway, all right, let's jump into things, Mike.
We're gonna run it over to you. You know, Donald Trump's been in office about a week now, and hard to believe. No one's noticed any kind of controversial actions on any part.
All of a sudden now we've got one. What do we got, Mike? So, there's been some executive orders issued related to cybersecurity, and in particular, they seem to have replaced the people on the cybersecurity review board.
It's not quite clear to me at least that they're getting rid of it, or if they're just gonna put some other folks on there yet. But some folks are saying, this is just political business as usual, and other folks are all upset saying, this is a signal that cybersecurity is being quote unquote politicized. Chris, I know you're closer to this than I am.
What's going on here? So, as, as, as you know, I've been spending the last half a decade or, or a little more, uh, focusing on supply chain, right? And I noticed in the, in the Security Boulevard article, um, in the, in the, in the content, uh, back, back content for this show that, uh, you know, that's, you know, so that's called out, and it's, and it remains 14 0 28 now, 14 0 27 and 14 0 29 are gone.
And when 14 0, 20, uh, eight came out the, the SBO m uh, executive order in May of 2021, I was working with Unisys, I think at the time, and involved with csa. And then the SOM uh, um, activities was Department of Commerce before that actually, and I did a map, uh, across time across presidential administrations. You look at supply chain executive orders, and across the Obama and Trump and Biden at that point, Biden administrations, they lined up remarkably well.
Right? You know, different administrations may have different motivations. I think during the first Trump administration, it was more punitive, nationalistic, let's, you know, punish China, for example, you know, and to, to grossly to typify that.
However, the executive orders about supply chain were not 90 degrees or up, you know, 270 degrees from existing executive orders. So I can't help seeing all of this as, uh, you know, the, the two, uh, executive orders 14 0 28, and the one that just came out recently, uh, that I had heard was going to survive the transition and has as being more artifacts that show that a new administration like a CEO in a huge company can say, I wanna do this. Then you turn to the people who actually work there and say what is possible.
So while we're dealing with decisions coming from this given source, we all are familiar with, they're not really varying as far as you would think, from the existing path down this, down, these, these, these, you know, but in cybersecurity at large, in supply chain, uh, security. So I'm, I I'm relatively okay with, you know, things to date. We'll have to watch this day to day and quarter to quarter, make sure it's guided properly in the efforts to date, you know, you know, continue and move forward, forward.
But I no panic yet, Ellen. I raised my head. I'm trying, I'm trying to, I'm trying to be a rule follower over the next four years.
I don't wanna find myself in a deportation, camper, anything. Um, so I've got a few problems with this on a few different levels, and Chris, I appreciate your myopic view of focusing in on just how this is gonna relate to supply chain security. But I think there are bigger issues here.
First of all, as a political science major, it kind of makes me sick to my stomach to see this current state of the American government. And, and I'm not gonna just blame Donald Trump and the Trump administration. This has been going on, quite frankly, since the Obama administration.
We've substituted democracy for executive orders. Our constitution is pretty clear about what roles the three branches play. And all of a sudden, because of the, the lack of political will, the inability to compromise, the inability to reason, and, and, you know, come to decisions the way this country has been governed for 200 plus years, we've, we've, we've substituted that with these eos, which I really think the Supreme Court will continue, that we, we can't have an imperial presidency, I don't care who the president is.
Eos need to be limited in, in what they can do, because it should be the will of the people. It should be the congress, the legislature who, who is okaying these things. That's their job.
And then, and by them abdicating in their inability to get their act together, we've tossed it into the executive branch and made an imperial presidency. It's wrong, and it's gonna wind up as a bad thing for the American people. So that at a very high level, that that's the secondly, as it relates to cybersecurity in general, yes, they kept some of these in here.
There are plenty of books on the law that they haven't rescinded either. That doesn't mean they're gonna enforce them, that just means they're there. Now, the fact of the matter is, we, I think over the last five, six years, going back to the first Trump administration even, right, uh, Chris, who, who, Chris, who was in charge of csa, Chris, um, he spoke for us at ours, Chris Krebs from Chris Krebs, and those folks through and through the Biden administration.
For the first time in a long time, I really felt the federal government understood how to handle on cyber and what the challenges were and what, how government, 'cause government can't do it alone, how government could work with private industry to make a difference. And I, I felt like we were making progress, even though they were mostly executive orders coming out of the Biden administration. And I wasn't a fan of it.
Then as an eo, I'd rather see Congress act, um, at least there I was hearing the right things. I thought the right people were involved. You know, a week or two ago, we, we were on here and we were talking about the loss of am Uran, right?
Amit Uran from Tenable at 54 years old. And what a shame it was. When you look at Amit's career, he, he scaled great heights in private industry and cybersecurity net witness, RSA, uh, tenable, right?
But really, it, it, some of his best work was, and he worked for the Bush administration setting up, what, what really, in many ways was the precursors to cease c in a lot of our cybersecurity government infrastructure. It was done not in a politicized way. We didn't throw out the old review board or, or, you know, there are people who are experts.
This is should not be politicized, and I appreciate them Not rescinding things doesn't mean they're gonna enforce them, but there are people there doing a good job. And until you show me that they're gonna bring people on to do a good job and not turn the whole world from Twitter into x call, call me, call me doubting Thomas. You know, I want to, Alan, it seems like we've entered this era, and not, not, not just Trump, but all of us have thought about, well, whatever politicians say in the campaigns, we know they can't do most of that, right?
That they don't have the right Congress in place, or they may not, or who knows if they could actually legally do that. Um, and while those things still may be true, the approach now is, I'm just gonna put it all out there. I'll put, we will see what is legal as it goes through.
We'll see what people let go by. Um, but it's a way of, um, you know, promises made, promises kept, doesn't matter whether actually happened, I initiated an action. And in part, a lot of what's happening is just kinda introducing the chaos of we're gonna change all this.
We're getting rid of that. Who knows whether, whether we can or not. So it's this huge, um, you, you remember the, the pickup sticks game where you kind of tossed them all down and then you had to kind of figure out how to pick 'em up without disrupting the whole pile?
Well, we're just disrupting the pile while we're picking 'em up, too. And, uh, yeah. On purpose.
And that's, that's the purpose, is to just shake it up constantly. And, uh, I, you know, it's interesting. Where will we end up with all this, whether it's the cybersecurity rules or, you know, doing, uh, Stargate, uh, whatever might be it.
It's, I'm, I'm just curious where we're gonna end up with, so when, once we see what reality really is, it may take years to find out if that could happen meantime, you know, they've taken some actions that may have been not been allowed. And do they get retrenched or just ignored or what? It's, it's really unsettling.
Well, I feel like it's, it's a frustrating, it's frustrating for me because when I look at something like this, I, I think of a book called The Logic of Failure Making Decisions and not Walking them all the way down as far as you can to see where they're gonna take you. And if we look at the, this one, and, and the one that was, uh, you know, thrown out was in particular around ai. Now, if we look right now at how government writes software, um, they use open source and they probably will use open source LLMs.
Why? Because it would take them years and years and years to write all of the open source and LLMs internally and own that IP themselves. It doesn't happen.
So what we end up with then is a, basically, if we think of Trump being a CEO of the, um, the, you know, the DOD and the DOE for software development, we have somebody who has said, we don't need to regulate ai. We don't need to look at this. We're gonna let open ai, and we're gonna let Meta, and we're gonna let these companies define the processes themselves, which may not be as important as should, as it should be for something like Weapons Systems.
And I can promise you that the software engineers at the Army writing this, uh, their weapons systems, they're not trying to write all of this themselves. So the US government depends heavily on open source and, and, and cots and companies like Open AI and Meta to develop the software that we rely on. And we have a CEO that has said, let's make it a wild west.
We don't care. But they only see it from the perspective of, we don't wanna hinder the growth and the development of ai, which I understand, but it's sort of like when DevOps started hitting the market and everybody started doing it, they was like, oh, this is gonna be too expensive and too time consuming. And then they realized it was the one thing that got their software out the door faster.
So if we take the logic of failure and we walk down this path, what we're seeing is actually we're shooting ourselves in the foot by not regulating and not clearly stating what we need from these companies in terms of protections around this very new technology. Chris. Yeah.
So, you know, I'm trying to think of an analogy here. I'm gonna use climate and weather, right? You know, so, you know, the last three years I've been building in some these boats up and down the coast.
I have 60 years experience in with Florida. And in the last three years, I've both seen myself and spent a lot of time with people who lived their entire lives. Right here can tell you the differences.
I can see it, the climate has changed, but weather is what you deal with every day, right? And, and you have to worry about both at the same time. And, you know, since we're all sort of talking about weather, I'll try to talk about climate a little more.
And just as you know, this, these conditions going on, Alan, right now, you know, this is unusual. Florida January weather, this is not typical, but it is what it's, and I've managed to use those conditions to remove the vessels, achieve goals, and keep things going. And I don't see that ending.
I don't think we're likely to end up in these, you know, desert earth, you know, climate disaster. I think we have a lot of challenges. It's gonna be a mess generations after us.
I, I feel for them. But I think we'll figure it out similar to this, right? You know, I'm not overwhelmingly happy with the current conditions in this space.
Um, however, I think that there's opportunities even in this to get some things done. As you said, Alan, you know, I've, I've worked with the beltway an awful lot. I respect everybody who works there, but it's got its own problems.
I work with big corporations, respect those folks too. They have their big own problems. Sometimes when it rams into a wall, you put it back together differently.
So there's a certain flavor of that to this, you know, that will crave a lot of bad weather, I think. Uh, but I think we can navigate through it. And 5, 10, 15 years now, we may say, you know, that train wreck actually helped us change the way we were doing things somehow in positive ways.
So that, that's the, let's burn it to the ground, then we'll start and hope it comes back better. Okay? But it's Not that, again, it isn't that bad.
It's an interesting, that's an interesting philosophy. You know, a lot of, a lot of people get hurt when they burn it to the ground, Chris. Oh yeah.
Storms, storms, yell, kill people all the time. But, you know, again, we're talking presidential, uh, policies and so forth and, and, and the beltway, and I've seen 30 years everything develop the national Infrastructure Protection plan. The secretary coordinate councils the information sharing systems around that they're not really going anywhere, right?
Those are good things that are going in the right direction, right? But the, the program that Phil Engler of the healthcare Isec and I have been running in partnership with cisa, is now starting to propagate through the information sharing community, whether or not, you know, Washington does anything. So we always had to be ready for these big powers like the US federal government to be, uh, fickle and transitory and build the things we're building into everything.
So it's not dependent on one massive power, powerful organization to fix everything or screw it up. Alright? So Now, absolutely.
Then go Ahead. Yeah, so I too agree with that. Um, but, uh, I'm glad that, uh, the executive orders that Biden couldn't place some of them, the supply chain, for example, uh, those are still untouched and hopefully we are moving in the right direction.
Where I'm slightly concerned about is, uh, the, uh, the rollback things that are happening with companies going back meta, for example, and also the, uh, the hiring freeze that's happening across agencies. 'cause that is going to impact the staffing. And as a result, probably it'll, uh, halter the investigation that's going on with the hacking incidents that's been happening lately.
And also, Christie Noam said, uh, to DHS that, you know, if she's confirmed that she's going to keep the department, uh, out of the efforts of combating disinformation and misinformation, and that is kind of like, um, I don't know. I'm not sure about that. I don't know, uh, how that is going to pan out, especially with companies already seeing that, you know, they have a free ring to, you know, go back and self-police.
And, uh, that is definitely, and, and mostly they just make it look like they're promoting, um, free speech and stuff like that. But, uh, this can go in a very wrong direction unless, uh, you know, guardrails are put in place. Again, I'm gonna give you a little bit in Nebraska logic here.
Experience, uh, well, I didn't live on a farm, lived around farms. And when you plow over fill, you turn it over, um, the first thing that comes up is weeds. That's the first plant to rise out of the ground.
'cause it's the most hearty and growing. So when you burn things to the ground, you better be planting what you want to come up, because something's gonna arise. It's kinda like culture.
You, whether you, you intentionally derive what you want to have. You have a culture, it's, you get things that are gonna come up. So I think that to me, the, the, what I don't agree with about the, just burn it all down, and let's see what comes back, is you're gonna get a lot of crap, you know, a lot of stuff that shouldn't be there either.
And it, it made worse. That was Heartland knowledge, you know, home fun. I love that, man.
Nebraska, be careful. I wanna, I wanna get to Tracy for a second here though. So, so will the industry respond and fill this void?
Can we do that? Or is it just gonna be chaos? I think that, uh, I think that the European Union will, um, begin to be where we look to, for the, the guardrails around AI in particular.
Um, I believe that we will go through a, a phase of chaos if there's not, uh, clear guidance, uh, from the federal government. Uh, and I don't think it's a, it's a, you know, it's a train that's going as fast as it possibly can. If you look at the amount of money that's going into things like Space Force, which is, you know, Trump's baby, he created Space Force, um, and all of the, think about all the startups that are trying to push, um, you know, AI technology and satellites just in that alone, they are going to be consuming the, um, open source LLMs and the open source supply chain that Trump has said we don't need to regulate.
So it is a big risk. This is a, this is a big risk, but I wanna point out that Trump likes to, he's a, he's a, a hot topics guy. He goes into the hot topic store and he pulls off the shelf all the things that people are really talking about.
And that's why if he had said, we, you know, we're gonna disband the SBO regulation, who would care? Nobody, nobody, none of his voters really understand what an SBO is. But boy, AI is either something really cool that Elon Musk is doing, um, and that's the stuff he's gonna focus on.
He's, When the National Inquirer is the newspaper of record for your country, it says something. Yes. Guys, we gotta take a break though.
We're 25 minutes in here. I gotta jump to the next, uh, segment. Obviously we'll be revisiting this.
I have a feeling over the days, weeks, and months ahead, God help us. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. All right, folks, we're back. And our next story is also cybersecurity related, but the federal government is now issuing sanctions directly against certain cyber criminals that are out there, or at least alleged cyber criminals.
And we've been issuing sanctions for a long time. And Alan, I know you're are resident legal, legal, but is this gonna be an effective way to combat cyber criminals? Does this actually like disturb them or are they just kind of gonna look at it and go, wow, thanks for the notoriety.
You know, look, look what a great job sanctions have done in shutting down the Russian economy, right? You wanna talk about paper tigers? Look, what a great job.
You know, I mean, he, here's the problem with the sanctions. Y after a while, you become like the boy who cried wolf, right? So when, when, what, what gives the bite to our sanctions to make people other, you know, for people to say who gives a flying whatever, right?
It's because generally the world works on the dollar, and generally the world works through the US banking system. So when we put sanctions into place, that's the, that's the teeth of the tiger, right? You can't trade in dollars and you can't go onto our banking system, which controls the world.
But the problem is, the more we do with sanctions and do that, the more other parts of the world say, we gotta get off the dollar. We, we can't be held hostage where the US is the sole, uh, you know, judge of who sanctioned or not. And so you get things like this whole brick alliance, right?
Brazil, Russia, India, China, and everyone else who's joined it. And make no mistake, this isn't the Warsaw PAC taking on NATO when we were younger. This is a, a, a, a organized attempt to get out from US dominance of the financial center sector to get off the dollar, to get away from the US banking system.
So that the, any sanctions we put in, whether it's against an individual, an oligarch in Russia, or a Chinese cybersecurity hacker, or the PLA itself, and they're, you know, hacking, uh, divisions, they will, they will con they will decrease in effectiveness the more we use them. So my advice is use them judiciously, use them where we, where it makes sense, where it's gonna do something. Sanctioning some Chinese individual who, who's a hacker.
And I'm not saying they're not, and I'm not saying we shouldn't do things. I think there are other things to do besides sanctions. I think there's a time and a place for offensive security operations that we don't need to publicize and, and you go do that kind of thing.
Um, but to, to just throw sanctions up to show you did something just weakens our whole ability to, to have these sanctions have, have any kind of teeth. And, and I, so my long answer, Mike, no, they don't make a difference. So in some ways, some ways, so, so this could be just an elaborate plot to get us to standardize on the Trump crypto coin instead of the dollar, right?
Is that where the, I don't know if he's capable of elaborate. He doesn't do elaborate. Well, like Tracy says, he's more of a, a, a national Enquirer or kind guy.
It's either play in three di dimensional chess or checkers, one or the other, which is One or the other. So Chris, is there an effective mechanism for punishing individuals who commit these crimes that live in other countries and places that we can't reach and frankly may not care if they can't get add access to a dollar? Yes.
And since this is a tech show, I've, I've queued up in my head an example from the, uh, the CS a working group, you know, that we're working on right now. So, ISACs information sharing analysis centers are these brokers of sensitive information between public and private sector partners. And there's a whole bunch from dozens and dozens these days.
org is hundreds and hundreds of, of cyber emergency response team to do similar things. And what we've done in the working group is develop a process to help organizations like this develop a control architecture, is what we're talking about here. A control architecture allows you to put some structure around what your defenses are.
And in the, in the s bum sharing space, you know, we have a couple artifacts of, of of definition. We're dealing with the discovery, access or transport three different things of a da bomb, of a software bill material. And each of those, as a different actor, you have different considerations, right?
So we find, uh, organizations saying, I don't know what to do with this. But you walk through it and you say, all right, what I want is to hold the directory, or hold the repository, or have these, and therefore I put these controls around that. So this, you know, we're, we're resuming all the way back, you know, to seeing the earth from orbit Yeah.
Sanctioned in the world. Yeah, no, that's not actually one of those, you know, intelligently sometimes sanctioned, like I was a Reagan Republican, you know, as you my early, you know, free market person. In my early political life, I, I don't like sanctions.
Like, but sometimes you have to say you are not playing fair, do the thing. But to your point, Alan, if you just say that all the time, then in the words of the Great American philosopher Bruce Springsteen, right? You end up like a dog that's been beat too much, right?
Spend half your time just covering up. So yeah. Loses all this effectiveness.
If it's just a spam approach, that's not a control architecture, that's a grenade. Yeah. And we have to acknowledge where we are in the, um, in the world right now.
Our, as Alan pointed out, our sanctions don't really have that. They don't really have teeth anymore. D do people really, really, does an individual really, really care?
I, I don't believe they do. I don't believe that person's well to the us but Tracy, If you were a US citizen or a Western European or European citizen, perhaps they would care. Even maybe someone in the Middle East.
But if you're in China, If you're in China, why would you care? So, I mean, so we have to, I think we have to, we, and the government's not good at pivoting. We all know that.
And maybe to Chris's points, this is trying to be a pivot. Um, but I think we have to look at what other tools that we can use as opposed to just sanctions. We have to broaden our, our scope.
You know, maybe we can build a fortress around them so they can, you know, that particular company, any of their servers are blocked in. That would be a problem. There's gotta be other ways to do this.
There's gotta be more, um, you know, covert ways of, uh, solving this problem as opposed to just sanctions. And, you know, sanctions is a tool. Go ahead and slap 'em on that person or that company, but as it really gonna impact them, it just depends on who they are as you point out.
So to that point, just to take it to your previous comment about the ultimate logic flow, um, do we need to punish the institutions that allow these in individuals to transact in other currencies? And, you know, if you're gonna have a sanction, how far do you go with the enforcement thereof, right? Because there are banks in those countries that are letting these guys, well, you know, for lack of a better phrase, deposit Ill-gotten gains.
So how far do you go with that sanction? Or can you I just think that it's, it's sort of like squeezing the balloon, right? And some something's gonna pop out somewhere there, there's no way to really contain it.
And, and if completely, and if there's anything we've learned over the last 10 years where, you know, sanctions, wherever we've used them as, they only work to a point. And we're only willing to go to a certain point of how far to enforce, enforce them. You know, you could some do something draconian that might be, um, might be more effective, but it also might be intolerable.
So I, I just think we put too much reliance on sanctions. They're, they're more, oftentimes they're just political to send a message the routes around it, whether, you know, getting whatever goods, AI, chips through other paths, they shouldn't be going into a certain country. Country, you know, there, there's black markets, there's always ways people find things, find things ways to what they want or to make money.
And, uh, so it's, it's a, I think it's futile to think this is solves our problem. It's only a, a small part of what we would do. Yeah, we're, you know, we have a shield of a sword.
And right now the sanction sword is a little tiny knife. It's a dagger. And we need to figure out the shield.
It's, yeah, it's a dagger at best. We need to butter knife maybe, but we need to figure out better, better shields. And this goes back to the previous conversation, is what we, you know, when we start taking, um, down regulations around tools that are going to be used by so many different companies and in so many different areas of, uh, of expertise like weapons, um, we're gonna open up ourselves for more of these.
And the shield is better right now than the sword or the butter knife, as we're all I get, All I heard is do something draconian and a picture of Donald Trump just popped into my head, right? Mean, let, Let's end it right there. We're gonna take the Blake, we're gonna come back.
We've got another block to go over here about bit bucket lessons learned as if we haven't learned any lessons yet. Lessons you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back in.
There was yet another outage this time involving Bitbucket and their, uh, CICD platform that's managed by Atlassian out of the cloud. And I'm, I feel like, you know, I don't really want to call out Atlassian and Bit Book just specifically for this, because what I'm trying to drive at here is it seems like these outages are happening more often, or are we just more aware of them? Tracy, we moved everything in the cloud and now it seems like maybe it's not as robust and as reliable as we imagined.
Yes. Um, you know, I feel for all of those folks who had to suffer the outage on the 21st because when last time, um, GitHub had a similar problem, I can promise you I stormed around the office with my hands on my hips and I was so frustrated 'cause I was trying to get some code out the door. And it can be extremely frustrating.
And, you know, we don't think about, um, at least we at Deploy Hub, we don't necessarily think about building redundant systems to GitHub and certainly not to Bitbucket. So as DevOps engineers, we are very reliant on these cloud-based tools, especially version control. Uh, and you know, in all of our work that we're doing now, I think, no, it's still there in all the work we're doing now in, in DevOps, we're talking more and more about pushing DevOps up to the cloud.
SALSA says have a distributed build system, don't have them local. Push everything up, push everything up so it's not local and it can be better controlled. So when these systems go down, it's literally stops development, it stops us in our tracks.
And I don't think we have a good alternative. I really don't, you know, building these redundant systems where you could switch over from the cloud to something local isn't simple. It's extremely difficult because of the fact that we're updating it so often.
Now, I'm always kind of poo-pooing AI and DevOps, but not so much in platform engineering, right? So I feel like this problem, I believe it had to do with a, um, a database, um, being both or something of that sort, could possibly have been caught and stopped using AI in platform engineering. So I think what we have to do as consumers start pushing back on the people who are telling us, we're gonna, you know, pay us the money, we will support you.
You don't have to worry about it. And when it comes down, we need to push back. They should be doing a better job.
Now, there are companies I know that have their local versions of Git. Um, they have everything local and they're not impacted by it. And I think if you're a big company, you probably wanna go down that road.
But for the smaller companies, you know, we're talking, you know, 500 million and less, we're gonna rely on those cloud providers to keep to, to keep us healthy. And I'm really looking forward to seeing how AI can help predict potential failures so that platform engineers can fix it before it, it does fail. You know, it's, it's a, it's a trade off, right?
Um, maybe you wouldn't be able to do all those things for yourself that a provider, like, you know, Bitbucket or whatever service, we're setting that up and maintaining it. And while it's painful when an outage happens, you know, one outage, okay, I get it happens. And, uh, you know, certainly they're, uh, uh, you know, quality organization like Atlassian gonna take measures to figure out not only how do they avoid that, that database overflow condition to, to, uh, you know, be able to scale it further.
You learn from those lessons. That's what your SREs are also, you know, focused on and platform engineering. But I also look at it as, you know, if you had to run all that yourself, you may not have all those services.
So are you trading off, I can get a lot more done or do many more things because I'm using a service in the cloud than I could have myself or, you know, do I go with less and, and do my own thing, which also comes with my own maintenance and all of the other things to it. So, you know, I, yeah, I feel for the providers, you know, when I'm the one affected, like you talk about Tracy, you know, you marsh around the room and I think they, what they should do when there's an outage, they should do the same thing now like they do in a, a sports event. You know, when when the signal feed gets cut off to the Steelers game, they switch over to the Patriots game.
I'm just kidding. And, and I love when they do that, 'cause I'd much rather not watch my Steelers. But, um, and You're right, Mitch, we, as a small company, we couldn't do it.
No. And we couldn't do everything we do. And that's the point.
That was the whole point behind the cloud, right? Atlassian's gonna do a much better job of hosting Bitbucket than you ever will. Way AWS Google and Microsoft, they're gonna do a much better job and they pour and they have many more resources to pour in to building an infrastructure to host your applications and securing your applications and doing everything they do.
But here's the underlying truth that all of us live by and, and we don't acknowledge it. We're all just zebras in the herd. And one day the lion comes for you.
That's it. Alright, I'm gonna wrap up, I'm gonna wrap us up here. We got in on time or about Zebras in Nebraska, but, okay, well, they're on.
No, well, there might be zebras in the lions, but anyway, um, happy Monday everyone. We've got a great lineup of Textron TV behind us, so stay tuned for that. Uh, we'll be back tomorrow with a lot more Textron gang.
And until then, this Alan Shimmel on behalf of our gang here today. Have a great day. We're out.
This is Textron tv. Hi everyone. We're back here at Techstrong TV and you know, I've got a gentleman, I, I never met him until today, so it was, you always like to meet new people.
I want to introduce you to Michael Fanning. Michael is the CSO Chief Information Security Officer at Splunk. And I, I guess we need to say Splunk a Cisco company.
Um, Michael, welcome to Tech Drunk tv. How are you doing? Great, Alan.
How are you? Appreciate you having me on. It's great to meet you.
I appreciate you being on, as I said, I don't understand why I didn't meet you before, but hey, we'll make up for that. Michael, how long have you been CISO over at Splunk? Pretty recent.
Uh, I, I, I took over this role in, in February, or I'm sorry, uh, this past, uh, September I took over the role. So about about five, six months now. Five, six months.
Yeah. Very cool. Well, I guess that begs the question, what were you doing before that?
Give us a sense of your, your journey. Yeah, so I've been at Splunk for, for four years. Uh, I was, uh, I joined in to lead our global security operations organization.
So that's your traditional threat detection and response teams. Um, you know, I was super excited about coming into the role, given my background in detection and response. And so there's no better company to work for in detection and response than a company like Splunk.
So I, I'd used the product in the past and was just very excited to come in and, and be a part of this great company and become a little bit more familiar with the product and the product organization. Um, so it's been a great, great opportunity for me. Um, so I spent some time in, in detection and response here at Splunk.
Um, became deputy CISO for about three years, led our product security organization. Uh, and now I'm in the CISO role. Very cool.
But what you're telling me, I'm reading between the lines, but it sounds like you always weren't a vendor. You were actually a, a real life security person using products like Splunk and out in the real world, huh? Yeah, I've used you've Splunk, uh, quite a bit, uh, prior to my, my time joining the company.
So we've had, we've had a lot of fun with it. Very cool. Um, you know, Michael, I, I, little tongue in cheek, I said Splunk a Cisco company 'cause that's what I always see now come across in my emails or, or, you know, uh, stuff online.
Um, but Splunk is a Cisco company and the integration is ongoing and good stuff coming out of it. As we were talking sort of off camera, you know, there's a lot to Splunk, there's a lot of Splunk in Splunk, right? There's a lot in there.
There's, as you said, there's threat detection and, and you know, that like really sophisticated security. Uh, there's OB observability, right? A lot of people use Splunk.
'cause the observability capabilities, ev you know, for security and outside of security are, you know, superb world class. Uh, people use Splunk for data collection without even sometimes performing analysis. They'll use other third party tools for the, for data analysis or what have you.
It it, Splunk means a lot of different things to a lot of different people and, you know, and now joining into a company like Cisco, right. And so much more give us your view from where you sit, Michael, in, in terms what's Splunk today? It's a great, it's a great question.
So, you know, the way that I try to explain, you know, Splunk to, to those that I know is, is, um, it helps you to answer very complicated questions about data. Um, no matter what that question may be, uh, with a tool like Splunk, you can answer these very complex questions. I like to say it helps you to discover, uh, needles and needle stacks.
And from a security standpoint, you know, that's incredibly valuable, especially when you think about marrying together the value of observable observability data with security data. It can be a very powerful experience for, you know, those in a security operation center and those in a security role. So with our, with our journey into Cisco, it's, it's really about understanding, you know, how can we kind of extend those investigation and response capabilities across, you know, other Cisco products.
Uh, we have a great suite of, of, uh, automation tools with our SOAR platform. And, um, you know, really cool to think about how we can maybe make changes to an infrastructure based on a detection that's fired and you know, that that really helps you kind of ingrain yourselves a little bit more into the Cisco product areas. Sure.
It ties in and, you know, we think Splunk has a lot to it. Cisco obviously has a lot to it as well. Um, we could do a whole interview on that, Michael, but that's not really why we've got you on here today.
Recently, uh, Splunk released their CSO report and, and wanted to dig in today specifically in, in the findings around kind of how CSOs are interacting with board members and where there's agreement disagreement, they see eye to eye interests are aligned or, or maybe not aligned. So I wanted to talk to you about that and get kinda your thoughts and tell us about it. Yeah.
Uh, some really cool insights, uh, from the CISO report. Uh, what I, what I love is that I talk, this is that they talk about kind of the, the perception of the CISO's role of how they interact with the board and what the board is interested in, and then kind of contrast that with actually what the boards, you know, are interested in. And it, and it's, uh, you know, it's just an interesting people dynamic and helping you understand the way that, you know, everyone's thinking about these problems.
But my, I think my favorite takeaways are, um, the boards wanting CISOs to project themselves as business enablers, kind of rather than, you know, throwing these, these tactical metrics such as meantime to detect at a board. I don't think that those are things that the board, you know, really, it's not that they don't care about it, but in that, you know, it's Not their language, That 45 minute window, you know, that's not, yeah, that's not something that's important to them. They wanna understand how is security enabling this company to continue to sell more products and continue to gain more revenue.
Uh, and this is something that I think that we've been very successful at at Splunk. Um, attaching revenue to some of our security goals as an example. Uh, we do SOC tours.
We're a, we're a SOC company. We sell SOC software. Our customers are interested and understanding how we run our sock internally with using Splunk products.
So every time we give a sock tour, we, we attach, you know, a revenue goal, uh, the amount of revenue for that customer, the a RR for that customer, we report on it. And, and it's a great way to showcase to, um, the board like, Hey, you know, this isn't just a soc. We've actually enabled the sale of a, of products to, you know, this group of customers over here.
Um, so I think it's a, it's really interesting and I think each company needs to, and each CISO needs to understand what aligning security and into a business enabling, um, initiatives looks like and how to present that up. Obviously, you know, not every company sells sells SOC software. So what are those other, you know, areas of opportunity?
Is it compliance and new emerging markets? And what is the revenue that is generated because you're a security initiatives helped enable the business to go into a market with data sovereignty requirements. And so I think that's what they care about.
That's what the CISO report shines a light on. Uh, so I think it's super interesting. Absolutely.
You know, I mean, I always wasn't on this side of the camera. I was in security for 25 plus years and security vendor, co-founder of a company. Um, I think the biggest thing is, you, you, you spoke about it right in the beginning, right?
You said the board doesn't care about meantime to remediate. Not only that, they don't even know what the heck meantime re to remediate is, nor do they wanna know, right? And, and that, and that was always one of the big disconnects that I think led to the rise of the CSO role, which is we need someone who translates that, and I'm gonna call it low level, but I don't mean it in a derogatory way, but that low level data, that low level stuff, right?
What the, how, how fast am I remediating? How many vulnerabilities do I have? How many detections did we detect?
How many did we block? They don't give a hoot. What's their risk, right?
At some level, the CISO's job is to translate that low level stuff into some sort of risk discussion. That is something they know and understand in a business way. It's to talk business to the board.
It's a, it's not a security board, it's a business board, right? They're there for the business. And I think one of the big problems, Earl, especially early on, was that CISOs weren't talking business.
They were trying to jam down the meantime to remediate down these guys' throats. It just didn't work. Um, we've come a long way.
CISOs now are business people who talk business to the board. The good CISOs also still talk low level to their security teams under them, right? They don't need a translator there.
But of course, everything is different with AI now. Things are changing and, and the potential for it to be very different is AI and budgets. Because why does this so go to the board?
Well, hopefully it's not to get called on the carpet because you had a breach though. It happens. Um, but you know, we, we need budget, we need alignment on priorities.
AI is putting all of that stuff in flux. Did that kinda show itself in the report? Yeah.
Yeah. I think that it did. Um, and, and you know, the way that we think about AI is there's, there's security for AI and there's AI for security.
And, and you know, Cisco announced, uh, you know, last week this AI defense product that's AI for security. And, and you know, that's something that can really help to, you know, enable, um, enable a company to kind of harness the power of artificial intelligence or harness the power of and protect yourself from, um, um, the risks that may be associated with with ai. Yep.
And then of course, the, the flip side is the bad guys using AI and we've gotta secure against it. That's right. Right.
And, and, and you need, you need, uh, you need product and, and services around that as well. Um, but you know, when it comes to budget, Michael, I, you know, one of the things I, I heard it more last year. It wasn't actually last year.
It was after RSA last year, I started getting, you know, from where I sit, I talked to a lot of different people, right? I, so I started getting sort of information kind of transmissions that a lot of CISOs were hearing from their board. Hey, look, we've been giving you more budget every year for the last eight years, right?
And you've been buying every new shiny trinket that comes down the pike, and yet our security is not measurably better, however you wanna measure it. We're not, you know, measurably better than we were before you spent all this money. So before you come to me for, with the next shiny trinket, which happens to me named AI this year, tell me how you're using what we bought the last three, four years and how's that working for me?
Right? And I, I get it as a business person, I, you as a business person, you get it too. But this is what, this is where the CISOs have to step up and, and make their case, if you will.
How does that, does that play out in the report? What's your experience? Yeah, you know, my experiences is, uh, you know, I'll kind of bash on us a little bit and security is, we're notorious for finding solutions that look for problems.
And that's what, I think that's what happens with, uh, you know, the new shiny object that, that you had, that you had mentioned. Um, there is, you know, one of the things that we talk about is that this tooling sprawl that, that those in the SOC use, and there are statistics around the number of distinct vendors and tools that are being used in a, in a SOC and, you know, up to 30 and how many different dashboards does an analyst have to touch in order to do an investigation. And so, you know, there's really, I think, a lot of rationalization that's happening in the industry to really scrutinize, you know, what are the, what are the third party solutions that we're bringing in and what are the actual problems that we're trying to solve, um, with these solutions that we, that we bring in.
And so, completely agree, you know, with your assertion of, of, hey, we've, we've procured all of the software. We have a great amount of software spend, but how is that actually reducing the risk, uh, and the organization? And I think that's just a great opportunity that we call out of where Cisco's have a, have an opportunity to improve the way they communicate up to the board.
But also, you know, to your point earlier, having these conversations with the, with the leaders and individual contributors in your organization to really scrutinize the procurement decisions that you make of what you're gonna bring into your organization, what you're gonna spend money on. Absolutely. I got a hard question for you.
So you've got the data from the report, specifically the ai, because that is the poster child, right? Agent AI is gonna be huge in 2025. That's what everyone says, right?
Are you seeing, and is the, the, is the data in the report show that wards are actually, I don't know if you wanna say increasing budget or allocating budget to AI security solutions. In other words, security that utilizes AI to be, you know, leverages AI to be better? Are we seeing a, a, a budget line for that in a meaningful way?
Yeah, you know, I think what the report is calling out is, is, um, I think neither the boards think that security is, is funded enough, but the CISOs think even less that it's actually funded enough. So there's a, there's a greater percentage of, you know, board members that say, Hey, we are providing, you know, an adequate budget, not, not a great percentage, but CISOs aren't necessarily, are really in the area of thinking, our budget, you know, is not necessarily adequate for, for security. Um, you know, not necessarily with specific kind of ai, you know, line items.
I think it's just collectively for the overall security budget and then making strategic decisions on how you're gonna protect yourself, you know, against, against ai. I think conceptually, you know, the attacks that we've face are, are still the same. The attacks are just getting better and faster.
And so your ability to detect and respond, you know, really needs to continue to improve and keep up with the pace of what, um, one of those AI generated attacks, like a phishing campaign, a more complex phishing campaign, better grammar, um, more like, you know, lifelike reproduction of a real phishing, like the concepts behind detecting that are still the same. It's just the adversary is using AI to attack you quicker, uh, and better, more realistic than before. I, I agree that there, there is that, um, Michael, I, I wonder if this shines itself in the report or if you have any other knowledge on it.
Are the boards going sort of like line item, veto line by line saying, spend this much on ai, this much on intrusion, this much on threat protection, this much on intelligence. Or they saying, Hey, Mr. Ciso, you're looking for a budget of X amount of dollars, how you're gonna allocate and you're gonna cover these areas.
How you allocate it in these areas is kinda your call, because we are not, we don't pretend to know enough to, to make that decision. Yeah, Yeah. Haven't seen, you know, where they're being very specific about their, where they want to call out for different functional areas.
I think you're, you're offered a, you know, a dollar amount budget and discretionary, you know, that had the way that you choose to spend that budget, I think is kind of up to the ciso. But, but, um, it, it's, again, you know, we talked about the way that we communicate to the board. It's that the way that we're actually articulating that spend is what is what really matters.
Very cool. Hey, you know what? I, shame on me.
This report is available to the public. Yes. How, how, how can someone get their hands on it?
Yeah, it's hanging off of our, our Splunk website. Uh, we'll send out the URL that for anyone to, to grab. And, um, it's a super interesting report.
It, it pulls, I think up to 500 CISOs and a hundred board members and kind of really some super interesting insights for everyone to take a look at. And is, is this the, the Splunk report, is it annual that you're doing this now? Or It's In fact, I believe the, the new report is just released today.
Really? Yep. Fantastic.
Great timing. com. It's probably front and center.
Um, you could get it right there and we'll try to put it in the notes as well. Hey, Michael, thank you for making your first appearance as, as EL at Splunk here on Text Drunk tv. I'm, I'm hoping it won't be the last, we'll, we'll hear more about it.
And I assume you'll be at RSA in just a few months, right? Uh, we'll be there live all week doing, uh, you know, what do they call it? Broadcast Alley is in, you know, usually Moscone West over there.
We'll be there live as well as at our DevSecOps event. So maybe we'll meet up in person. Yeah.
Appreciate it, Alan. It was great to meet you and thanks again for having me on. Alrighty.
Michael Fanning, chief Information Security Officer at Splunk here on Tech Drunk tv, talking about Splunk's new CSO report, which just came, it just came out. com. Um, we'll gonna take a break here on Tech Drunk tv.
We'll be back in a moment. This is Textron tv. Hey guys, thanks for the throw.
We are here with Spike Curtis, who's principal engineer for Coder Technologies, and we're having a little chat about the state of open source software security because there's a lot of gnashing of teeth lately around this subject Spike, welcome to show. Yeah, thanks for having me. What is your take on what's going on here?
Because, well, not all open source projects are the same, but in theory we're supposed to have peer review and that results in better security, but we certainly hear a lot about of instances where that's not necessarily the case. Maybe it's just the projects are too small, but what should we be thinking about here? Well, um, there's like you said, a really big sort of range of, uh, kinds of projects that, you know, qualify as open source from these little kind of passion projects as like one developer in their free time to these big massive projects like the Linux kernel or, uh, Kubernetes.
That's, that are backed by multiple companies and have, you know, hundreds or thousands, um, of contributors. So like the, the state of security, you know, in, in open source is, is one that's pretty varied. Um, and the, uh, kind of dashing your teeth that I've heard lately is around like, uh, software supply chain.
So we've had these like high profile attacks, um, that, uh, was actually more of a near miss, like the, um, XE util, uh, thing that happened last year, um, where, um, a very committed attacker, um, found a popular but relatively under-resourced open source project, kind of went in, made friends with everybody, became a committer, and then, um, introduced some malicious commits into, um, the repository and sort of pressured this, uh, popular, um, library to get included in Linux distributions. And then, um, trying to use it to launch attacks on SSH. Um, but uh, it was actually near Biss because other open source people noticed weird stuff happening and, um, basically caught the, the issue before it made in itself kind of widely, uh, distributed and things like that.
So, um, like I said, a a really big kind of, kind of range of things, but, but my perspective on, on open source software is that, um, you know, it's not a time where things are getting worse and scary. Um, the, the community is, is, um, supporting more and more projects. We have people paying attention.
Um, and I think open source software as, as a place to, to go for, um, se secure, uh, things is still, uh, a good, um, option for people. I don't think people are walking away from open source. I think that would be too problematic.
But there has been some discussion about maybe not using passion projects and not letting that into our enterprise environments 'cause there isn't enough resources behind it to make sure that whatever patches or updates need to be made or made in a timely way. I think that that's right. That, like, you have to look at at things at an individual level, like lumping everything together as like, oh, this is open source, open source is great, or this is not, um, or open source is bad, is is the wrong way to to think about it.
And like a, a sort of, uh, table stakes for, for using open source well is to do your due diligence on the projects, right? Understand, um, who's building this thing, um, what kind of support you're gonna get. Um, this focus on, on supply chain, I think also is, is this sort of really narrow focus on probably a minority problem.
Like the bigger issue in software in general, um, is, uh, just vulnerabilities that are put in not maliciously just by mistake. Um, there are are some high profile instances of, of people deliberately inserting back doors, but it's very, very rare compared to the kind of random vulnerabilities that you see, right? There's, there's thousands and thousands of CVEs that are issued every year, and only a tiny fraction of them are like, you know, the supply chain, uh, kind of problems or deliberately targeted attacks.
What is your take on AI as it relates to improving or reducing the number of vulnerabilities? I'm asking the question because some people will say that they're seeing more vulnerabilities, at least in the short term, using these tools. Um, but longer term, might we not just reduce the number of vulnerabilities that we're a, creating and b, fix 'em faster?
Well, I think that, you know, it's reasonable to expect that automated tools, uh, will get better over time. That's not a new thing, right? Like, um, static analysis of software looking for security vulnerabilities is something that we have had and something that should be part of your toolkit.
Um, and, uh, I don't think that there have been convincing demonstrations of the current, like generation of generative ai, you know, your copilots and, um, oh chat EPT and things like that. There's not been any convincing generation of those models, uh, finding security problems in a, in a systematic way. But, um, it's very early days for this sort of thing, right?
If you actually sat down and said like, I'm gonna train, um, a model that's gonna look at software and find common problems, um, you could probably, um, have, have some success with that. But it, it's very early days. I think that it sort of remains to be seen whether, um, AI is gonna be able to build us tools that help us, uh, find vulnerabilities.
Um, I will say that like the current state of the world of like having, um, chat GPT and copilot and these things write code for you does worry me a little bit around security vulnerabilities because, you know, you have people, um, putting a bunch of code into the system really fast, um, generated by, by some ai. Um, and, uh, it can, I think, accelerate, you know, the, the rate at which you're making these, these sort of, uh, introducing these vulnerabilities and things like that because you are not sitting down there carefully analyzing things. You're using this thing as a speed boost to sort of get more code into your editor faster.
There's always criticism level that the enterprises that are consuming open source software for not contributing enough to the community to help resolve some of these issues. And, uh, I'm not quite clear how reasonable an expectation that is or is that just something we kinda wish would happen, but it is never gonna happen. Yeah, I mean, I think that like there are companies out there that like, uh, are absolutely pulling their weight and probably pulling other people a along with them in terms of how much support they they give to open source, what they release, what their, their people sort of do for the, the open source ecosystem.
And then there are other companies that sort of sit on the sidelines and, and consume open source. And like the whole idea of an open source license is you're saying like, I am giving you permission to use this. And so I don't think that it's at all fair to, to sort of have a permissive license and then criticize somebody for using that.
But there is, um, you know, some open source maintainers have had issues with, with people, um, being very imposing on them, right? That, that if you're in this project and you're doing, you release this open source license and then somebody like wants a feature done or finds a bug or something like that, they kind of come at you with this expectation that it's your job to, to fix it. Um, and I think that that's the thing that, that sort of puts people off.
I think most open source, uh, contributors are not worried about a company, um, using the software and not contributing it back. You sometimes get a little bit of, uh, soreness around somebody forking it, doing something and then not contributing that back. But again, the licenses don't say or don't always say that you have to do that.
So I, I don't think it's that's necessarily fair, but, but when you sort of get into these interpersonal relationships and get put upon, that doesn't feel fair and that doesn't feel good. And I think that that, um, that's something that, that people definitely need to be aware of as they interact with open source communities. The other thing is, is like, um, like this XC u util, um, project, it, it became way more popular than, um, was sort of really able to be handled by, by a single contributor.
And there are other projects that, that sort of fall into that category where, um, there started by a small team or started maybe by a large team, but then people sort of peel off and do other things and there isn't enough people left around to really handle the, um, maintenance of, of software as vulnerabilities are discovered and things like that. And that puts everyone in a really awkward position. Um, and I think that if you are, are a company that's using open source and you find yourself in that situation where you depend on a package, but you don't think that that package is being, um, uh, being taken care of the way that it really needs to, then I, I do think, you know, it is, uh, a good idea for for companies to step on, let's say, you know, look, we'll dedicate some of our engineering time to maintaining this package because it's important to us, it's important to other people.
And, and we can sort of see that, um, while maybe at one point it was really well, uh, maintained, um, you know, uh, unpaid or people, people aren't necessarily being paid to, to, uh, work on these things. And so, um, somebody has to step up it or you have to sort of get out of it and say, look, look, too dangerous. I have to find a replacement package or something like that.
There's also a lot of talk about, well, we need to compensate these folks that are creating this open source code and they'll respond better. 'cause compensation drives behavior, but it's not clear to me that that's gonna work either because, well, it's a passion project and some folks have a life, right? Yeah.
I don't think that that, that the idea of like, we'll just compensate them is necessarily that sustainable of a model. Like sometimes it is where, where people are working on something and, and they, they just have a little tip jar and that's kind of enough to, to sort of keep them going. But, um, the sort of, uh, short term like, oh, I had this problem.
Let me, like, you know, dump $10,000 on you or whatever, um, is, is not gonna sustain things in in the long run. It might grab somebody's attention for a while, but there's not really anywhere in the world where, um, well-trained software engineers, um, don't have like better prospects, um, than, uh, than that to, to be able to grab their attention. So, um, you know, the, the model that I think does work is, um, one that we've had for, for a number of years where, um, people are working at companies, um, full-time, you know, maybe building proprietary software for that company or maybe building only open source, but also part of their time is spent building and maintaining open source, um, projects.
Um, so that, that these things get maintained, um, and you sort of benefit from, from people coming together where, where the, the project itself is not some sort of, um, competitive lever for a company. Um, being able to contribute it, open source, um, allows everybody to kind of share in, in, in that value. And that's, I think, a sustainable, um, way to go about it, right?
It's the way that the Linux kernel, um, has kind of been sustained over the years. You have companies like, um, Ubuntu and Red Hat and all these other, um, downstream distributions. They have people on their staff that are working on those projects.
Um, day in and day out For a while, people were kicking around the notion of creating a, uh, quote unquote SWAT team that would be responding to these crisis whenever there was an issue with an open source project. But it doesn't seem like that's panned out all that well, what's the challenges? And kinda maybe having some sort of collective response team.
It's kind of like the fire department, but I guess if the fire only happens every once every three years, it's hard to keep everybody on call. Yeah. I mean, it would be like having a, a fire department for the entire world, right?
Like, there's just a huge variety, right? You've got people who, um, are living, you know, in bungalows and people who are living in high rises and, and you know, people who are just like living in yurts in the, um, uh, in the desert or whatever. Like, um, you can't just have like a SWAT team that's gonna like jump in when, whenever there's, there's a problem because the sort of scale of problems and the range of different projects and stuff is just, it's just too big, right?
So, um, the, yeah, the, the idea of like, you know, some sort of short term, uh, kind of thing is, is I think, pretty pretty out there, right? Like even if you had this SWAT team that was like ready to go and you had a, a project that found a vulnerability, um, and, uh, needed to be patched quickly, it's not like you could sort of just sort of parachute some new engineers in, um, that haven't been trusted by the project and like, are gonna go in with the maintainers, like maintainers of these projects are not gonna like just accept randos from, from wherever kind of coming in, um, who don't necessarily know the, the code well and, and are up to speed. You know, it, it really doesn't work like that with software.
You can't just sort of jump in and, um, and fix a, a major problem and then, and then run off. I fear that this issue may get worse before it gets better because the band guys are discovered AI tools as well, and they're using that to scan for vulnerabilities that then they're gonna have like a zero day exploit for, um, because they didn't analyze the code in ways that previously was, took a lot longer. So, you know, what's your sense of going into this coming year?
What should we expect? I don't get the sense that AI enables bad actors, particularly more than it enables, uh, good actors in, in open source software. Certainly.
Like, um, if you were like, uh, worried about AI tools being used in bad ways, there are lots of interesting examples of like, you know, voice impersonations and like stealing, you know, calling up people and sounding like their mother and, you know, asking for personal information and stuff like that. That's the kind of stuff that worries me. But, but in terms of, of, uh, software vulnerabilities and stuff like that, you know, we've had script kitties and, and like automated, uh, vulnerability scanning, um, for, for decades now.
Um, so like there, there's this constant, uh, sort of battle of, um, find the vulnerabilities, fix the vulnerabilities. So where you want to invest is security researchers, um, going out there, finding vulnerabilities in important packages, and then, um, investing in software developers being able to maintain those important packages, actually when the vulnerabilities are found, be able to patch them issue, um, a an update and let people know that, that they need to upgrade. Um, the war will go on basically between, between attackers and defenders, um, in, in software, um, and AI changes things, but it, there's no particularly strong bias between attackers and defenders in, in software that I've seen so far.
Hey folks, you heard it here. Yes, there are things to be concerned about, but I don't think there's any need to panic just yet. Little common sense will go a long way still.
Spike, thanks for being on the show. Yeah, thanks for having me. Thanks, Mike.
And back to you guys in the studio. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Hello, and welcome to digital CXO. I'm Amanda Ani, and with me today I have Renee Prabu.
He is the director of product at grapht. How are you doing? Good, Amanda.
Thank you for having me. Happy to have you on the show. So today's topic is data assurance, but before we get into the topic, can you share a little bit about grapht and what services do you help provide?
So, graphene, uh, network has a service platform, and what I mean by that is we provide con any to any connectivity, whether it's from your private space to the private domain, the private space to the cloud or, or, or the public domain and the services that you can consume. So it's a consumption based model, so, uh, you don't have to worry about the network itself that's built out for you. So we provide our graph and backbone, uh, as a service.
You consume bandwidth on that, uh, backbone to get you from point A to point B, and we get you to the cloud. We provide you B2B connectivity. We provided, uh, provide you the data assurance service, uh, all on top of it.
And we, uh, provide you the SD-WAN capabilities that, uh, uh, are already prevalent in the industry. So we have a bunch of services that we provide on top of this backbone. All right, wonderful.
Well, so let's talk about data. And I wanna share, first of all, um, your stance is that data in motion has become one of the biggest, uh, security risk in the enterprise today. Can you explain a little bit more about that and why you think that?
So, data lives in three states. Like, uh, you mentioned data in motion. The data is addressed, the data is in processing, and then the data is most vulnerable when it's set in motion, because for the first time, it moves out of your private domain into the public domain.
So data address is sitting still in your domain, in your, within your parameter data. And processing is still within your parameter. It's when it exits your parameter and into the ether of the internet, that's when it's most vulnerable.
And hence, we think that, that, that's the most critical aspect from a security point of view of where data needs the most protection. With the industry going into the AI world today, the data is getting a lot more disaggregated. It's no longer just your data.
You need to share this data with your B2B partners, with LLMs, with GPUs, so on and so forth. So, uh, you are almost extending your parameter beyond your boundary with, uh, places where you're exchanging this data and graphene a data exchange platform. So with that in mind, we need to really protect this disaggregated data and extend your security posture and your risk appetite beyond just the perimeter, uh, into the business domain of things as well.
So that, that, that's where our data assurance story, uh, begins. Okay. So can you share some of the top vulner vulnerabilities and risks associated with data and motion that business leaders should be concerned about?
So, data and motion. There, there are, uh, a bunch of things that they need to worry about, right? One, uh, is it encrypted?
Is it, uh, there's a spatial component and, uh, there's a temporary component to every conversation. So contextualizing data is first, uh, the first pillar that's key to protecting your data. So knowing what the intent of the data is, and then really plotting it on a map, right, of a, of space and time.
Am I consuming the data where it's supposed to be consumed? So let's say, Hey, I need to, uh, my servers, uh, are located globally, but if I'm authorized to only access servers in North America within sovereign boundaries, then that's the spatial component of where I should be consuming that data from and not going beyond those sovereign boundaries. There's a time component of it.
If I'm allowed to au uh, access data, I need to access it during workers. If I'm accessing it out of workers, that might be ano. So you need to really contextualize when you are accessing it, where you're accessing it and how you're accessing it.
So those are the three pieces of the puzzle that A, any CIO cso, uh, of an enterprise or a service provider would be looking out for in terms of how to protect and what to protect, uh, your data and motion for. Are there any tools or technologies that you recommend that, um, would help safeguard this data in motion Graph? I, I would recommend graph and the, the data assurance offering itself.
Uh, what we've try, try to do for the first time is get security to govern routing, extending your security parameter into the network space. Uh, so what I mean by that is data is your most sovereign asset and giving that, uh, the treatment like any sovereign asset, uh, deserves, uh, data should stay within data embassies that extend your sovereign boundaries from point A to point B. So let's say you, you have GDPR data that's critical to you.
Uh, GDPR states that this data needs to stay within boundaries or within trusted entities that extend those boundaries. So keeping that kind of risk posture within your network of where this data travels from Point A to point B, who's the producer, who's the consumer, and those are entities that are GDPR compliant is key. Uh, and that's the control, uh, graph brings to give you, uh, with a click of a button, uh, of where your data moves, how it moves, and who produces it and who consumes it.
So would you think that corporate boards play a role in shaping policies for data protections? And, um, if so, how? Uh, both, uh, uh, corporations, uh, influence, uh, compliance, uh, needs as well as governments, right?
And these constantly keep adapting and changing. So, uh, having your enterprise ready and your network ready to adapt to these flex, uh, or these modifications on, uh, data governance and compliance is key, right? It's hard to, uh, rip and replace infrastructure, say, uh, a government changes in a region, the compliance and regulation or encryption regulations change.
It's hard to rip cables apart and reroute around that region if it's not compliant to your, your enterprise. So having a programmable network that can really just add a click of a button reroute that, uh, path around that region is what's key. Uh, so it, it's a mix of both.
Uh, the regulations are the compliance needs of an enterprise. Example, financial in institutions have PCI, kind of regulations. Governments may have the GDPR and HIPAA kind of regulations.
So, uh, but, uh, businesses have to comply to both. So the, it's a mix of both and giving you that adaptability is key and giving you that control back is key. Wonderful.
Well, um, out of all this, what is, um, what is, say one key takeaway that you could leave our audience with today? The key take takeaway is, uh, just protecting your perimeter isn't enough. Having a network that extends your segmentation from your boundaries, from your edge, uh, really getting your business, uh, traffic, the business internet.
Uh, so the internet was inherently built for, uh, open communication, but enterprises need a different kind of internet. That's the business internet and Raffin aims to provide you that with its, uh, uh, backbone as a service offering, allowing you to program the business internet based on how you are consuming and producing, uh, data and how you govern that data is key. So I, I, I would really encourage folks to focus on how security can really govern the routing, uh, in, in the age of the business internet.
All right. Well, thank you so much for coming on and sharing your insights today. Thanks.
Thanks for having me, Amanda. All right. And thank you to our audience.
Stay tuned. There's more. Welcome back to Textron Unplugs.
My name is Cassandra Chen, and today we have Margarita Mescal. Yeah. Hello, Cassandra.
Nice to be here. Hi, can you introduce yourself? Yeah, my name is, uh, margarita Cassandra told you I am currently a software engineer at Sonar, mostly working on static code analysis in, uh, GVM, like Java Coline.
And recently I switched a little bit to mobile and helped to, uh, prepare the analyzer for DAR and Flatter. And I'm also a mom and a woman in tech, so that's probably me. How did you get into technology?
Um, that's interesting story because I was, uh, when I was a kid, I was studying in school that was mostly, uh, like language specific. So we learned English, a little bit of French, and, uh, I was interested in this technology, in this, uh, subjects. However, math was always like my, uh, passion and always, uh, liked it pretty much.
And my parents didn't practice this. At, at the time when I wanted to go to the university, I decided to make math my profession. So I went to cybernetics faculty, and initially I thought I would be scientists, uh, in some inventions and some, uh, exploration in math.
Uh, but then I discovered that programming is my much bigger passion than math. And, uh, this is how I started, like doing my pet projects, working with other students. Uh, we had some startups then eventually had my first, second, third job.
And, uh, I realized that I love programming much more than doing math for the sake of math. And, uh, this is why I'm here. Yeah.
Look, it's interesting that you like programming more. Yes. I actually don't like math even, so I've been programming, no, yeah, that's, uh, interesting because my, uh, my childhood, when I thought about math, uh, the fact that I like was not like solving some equations or some tests.
My, my passion was mostly problem solving. And apparently math was the only subject that gives you this. Uh, then when in the university you realize that math is less about problem solving, but programming is like, software engineering is about more about problem solving.
So I don't like just to like, uh, create equations, uh, and looking at the beauty of math, while others, uh, could be really passionate about this. I really like to see the problem and to see that I can make a machine to fix it for me. And, uh, that's like probably different mindsets.
Um, 'cause the university, sometimes you're given some assignment you need to solve some, uh, you know, complex equations, complex tasks. And I could definitely see that there are two group of students. One group, they just took a paper pencil and they sold it with their hands.
Another group, they spent much more time asking computer to do it for them, like writing the program to solve it, because they were too lazy to solve this equation or solve this, uh, problem on the, on the paper. Uh, but they were like curious enough to make the computer do it. However, when you ask the, uh, like want to program the solution, you still have to, uh, like solve it on paper because you need to test that everything works properly and you do the work, you know, three or five more times than the person in equations.
But the beauty that in the end, you'll have the program that works and then you can solve it on 100 more equation than, uh, like a person who decided to go for a paper solution. But that's like two different mindsets, two different passions. And I think like in the world, we need both.
That's just, uh, you per, that's what you personally prefer. Yeah, I think what's interesting, I mean, maybe we could even have both parties work together. Yeah.
Um, how, what's your opinion on like being a woman in tech? Um, that's a very like, uh, complex opinion because when I was really young, based on my, uh, like background being, uh, like being grown up in, uh, Slavic country, I was really, uh, like keen on, uh, fighting on the same level with men. Like, I, I don't trust them, like women in tech.
I want to be, uh, like on the same level as men in terms that I don't want any positive discrimination. I don't wanna like have this, uh, any special treatment because I, I'm a woman. Like everything should be the same, should be equal.
And everybody who fights for like better conditions for women are like just lazy to fight on the same level as men. That was like when I was probably 16, 17 years old. And that worked, like, because I was thinking if I can have my first job, if I can have my first like salary negotiations, if I can do it, probably other women can do it and uh, they just are too lazy or, uh, like pretend that or not smart enough.
But then once you face your first problem, it could be harassment, it could be some problems with getting a high promotion, getting higher salary. Then you realize that no matter how hard you try, the industry is still not working for you. The industry is still designed for men.
And, uh, um, once they started facing it, that they could not get promotion, they could not get higher salary. And, uh, if there is a male and female candidate, for some reason, they choose male. Like with no obvious explanation, uh, I found that it hurts.
And, um, I remember I had a conversation with my friend who she was, uh, a startup founder. They had a startup with her partner. And she told me that every time on every business meeting, nobody wants to shake hands with you, with her, everybody shake hand with her, uh, partner.
Nobody wanted to have negotiations with her. Everybody like tried to have negotiations with his, with her partner. And like, here and there, there are small details while still, uh, the world is designed for men.
And I think there is like a really, um, nice book about like, uh, the data behind this. It's called Invisible Women. I don't know if you heard about it.
That's a book that probably changed a lot in my, um, how I perceive being women in tech, women in industry, and in general, being women in this world, to see that how much we're underrepresented and in data, that there are a lot of problems. For example, car seats, car safety is not designed for, for women. The women are much more likely to die in car crashes.
The same for some pills, some drugs about migraine because they're tested more on men than on women. And here and there are small things that tells out that this world is designed for men. And the same, like being the same applies to the, your career and especially in tech where like, let's be honest, there are much more men.
And, uh, recently, like few years ago, I become a mom. And for women working like mothers in tech, everything is even worse. Like if you ask an ordinary speaker at a tech conference, if they have kids, they're so proud or that they have kids, but they never take them with with them because there is a mom who is taking care of their kids.
And how many speakers, female speakers who have kids are here. Like, I do see that as a problem. Like I think I'm fortunate that my dad's a speaker and he has been taking me to conferences these past few years.
But I see like other speakers who have kids and like, I really wish they would come here too. Yeah. Uh, I think there is a problem first, uh, because, uh, like currently me and a lot of female speakers, they had to choose which conference they have to go and they should not go because they have some obligations at home.
And for me, I'm very lucky to have, uh, um, supporting partner who is like going with me everywhere. And currently we are given a joint talk sometimes like, uh, we try to not make the kid ruin our career, so we try to balance everything. But anyway, because we have a kid, because we have some obligations, we still like choose which conference we go, which conference with dot go, definitely our life changed than it was before the kid.
And, uh, I wish like, uh, this problem was more recognized. For example, I was a year ago, it was at Devox Belgium. I go there with a kid alone because my husband had a different travel and we had overlap.
And like, he was a kid. The conference was nice, everybody was like nice with me, with my baby, help me with a stroller, but there was no elevator there in the venue. And there were two levels of venue.
So I, in order to give my talk, had to go up in order to visit my company booth, I need to go down. And it was with a stroller. So thankfully it was not such a big problem because my son walks.
But it was still a problem because I like had to either like, put the stroller down or up by myself or ask for help, because that's kinda heavy. And, and uh, that's like one of the things of accessibility that could be improved. And it's not just for parents with strollers, it's also for, uh, disabled people who need the same.
And the conference menu was not like really designed for this. So are you giving a talk here? Uh, yes.
Actually here we are giving a talk together with my partner because he's maintaining a code coverage library for Java, like Java Jayco. So, and, uh, we are giving a talk about MythBusters, about code coverage because there are a lot of like myth around code coverage that you need to have 100% of code coverage or you need to be like, um, to aim for 100%. Or for example, that code coverage guarantees you test quality or quality of your software.
So we try to like dispel all this common beliefs that we are wrong by like doing some live coding and showing some examples where it's not actually true. And, um, can you talk a bit, what's this? Uh, coverage, uh, code coverage, yeah, actually like when you write your software, you try to cover it with tests, like to know that, understand that it works correctly.
I see. And uh, in order like to assess how good are your, your tests are, you need some metrics, code coverage shows you, uh, like which part of your code was executed when you run your test. So for example, if you like test some function that calculates some like A plus B, you can, uh, call this function with some real data, like to, for example, past two and the check that the sum is for.
And like once you execute this, the cut coverage tool will show you that your function was executed. If you didn't test this, the cut coverage tool will show that the, it was not executed. But the interesting thing that it's not enough just to like execute your code, sometimes you also, you need to put assert that it worked correctly, that you didn't forget something that you tested.
Corner cases and code coverage like can lie to you this terms because it's sometimes say that everything is okay, but if you go deeply, you can understand that now you haven't tested some more co coronary cases or you forgot to test some, uh, other states. And, uh, this is what we try to discover, like to show in our code, uh, in our talk to, uh, to show people where it works, where it does not. I think that's an interesting technology.
Yeah. It's, do you recommend that all developers use it or? Yeah, I think, uh, while in our talk we say that it's not ideal, we still believe that it's sort of a must have to assess the quality of your software.
Because like for now, that's what we have. We can, uh, that can show you cut coverage. We can also like for, uh, mutation coverage, it's like another technique.
And the more, uh, like qualities, the more of, uh, metrics around your code and tests you have the better, uh, you the bit, the better picture you have about your software, about your tests and, uh, in finally the better software you produce. So hope you improve your code. Yeah, I think we've had a really good talk today.
So thank you. Thank you very much and thank you for what you are doing. Hey everyone, it's Alan Shimo for Techstrong and I am really happy to introduce my friend Luca Ante.
Luca and I are kicking off a brand new series here on Techstrong. That'll be a TV series, but it'll also be a podcast that'll be available on everything from LinkedIn to Facebook, to Instagram to Apple Podcasts and Spotify. And wherever, wherever you consume media, the platform engineering show will be there.
So, and, and by the way, that's the name of the show, right? The Platform engineering show. If you don't know Luca, I'm going to introduce you to him right now and he's gonna tell you all about himself.
Hey Luca, welcome and man, I'm looking forward to doing this show. I am here really excited. Um, and, uh, yeah, I mean, let's, let's get, let's get right in.
Um, the, you know, I think well can people, you know what people in platform engineering know you, right? org, key person at Humana Tech Key per, you know, key company in the platform engineering ecosystem. But for people who don't, you know, our cyber audiences, our cloud native people who may not be familiar, give them a little bit of your background, Luca.
Yeah, absolutely. So I mean, I got into Humani and platform engineering, um, you know, six plus years ago. Um, this is when, and, and, you know, when we first set out to build this product, which is, as you said, it's one of the leading solutions and platform engineering, we kind of figured out, well, actually there's really no conceptual framework around the problems that we solve as a product.
Um, and there was really no clear idea in people's heads of like, okay, how do I, you know, how do I think about this problems? How do I think about the challenges, um, that, you know, we're gonna talk about today and throughout the podcast, you know, that, that DevOps generates at scale and the platform engineering addresses, we're gonna get into all of that. But essentially that's why we set out to build this community.
Um, you know, it was really to, and it's not like we invented anything, right? Like people had already been doing platform engineering for a good part of a decade at least. Um, but they weren't just, they just weren't calling that right?
And there were no clear definitions, there were no clear best practices, no standards, no nothing, no community for people to gather. And that's kind of what we started doing five years ago. And that quickly grew to the number one community out there.
It has over 35 meetup groups all over the world. Um, we do, which is the biggest, uh, annual event in the space with over 35,000 people this year. We have a, a Slack that has 25,000 people in there.
We run Platform Weekly that has over a hundred thousand subscribers. So there's really probably like around 200,000 people if you, if you kind of like add it all up across the different community destinations that meet every week, webinar, our, you know, weekly webinars and, and, and meetups. Um, the, the consume the newsletter, the come to Platform Con.
And it's, it's really exciting. We, we now started rolling out, you know, courses and certifications and trainings and a bunch of other things that we can talk about and, and that keeps, keeps on growing. Um, and this is also where we've decided then to really formally split that, you know, the entity from Humanity Tech as a product.
Um, and, and so, uh, you know, humanity is just its own thing at this point is, is one of the leading solutions in the space, but it's, it's at this point, uh, really separate from, from the community, um, that, that, that at this point is, you know, self-sustaining. And, um, you know, our mission there is really to make platform engineering as big as possible in the cloud native industry, um, while also keeping a very tight focus on, you know, making sure that there are clear standards, clear definitions. Um, I really want to avoid platform engineering ending up like a lot of other treads before it that, um, you know, where sort of like all vendors kind of like jumped on the, on the, on the bandwagon and kind of tried to like, you know, Merk, uh, definitions, uh, because the, it benefited them a little bit more.
And then eventually you end up in a place like GitHubs that kind of like means everything and nothing, nobody really knows actually what it is. And so I really wanna make sure that we avoid that faith. Um, and I think so far we had a, a really good focus on standards and blueprints and frameworks and, and so I think we're on good track to, to keep growing while, while, you know, keeping everything clear and everybody on the same page.
You know, it's interesting. So in the old days, Microsoft used to describe what you're talking about as embrace and extend, right? They would embrace and extend things and still it until it didn't look like anything that it originally looked at, right?
It looked like what Microsoft wanted it to look like. But, you know, but this is the way of, we, we've seen this over and over in technology, right? If vendors see money, basically if vendors see market, they, they jump on it.
And, but the way to, the way to control it, if you can control it, the best you can is, is to have some very tight definitions from the, and to embrace the, the idea of like technical oversight committees and working groups that work on different things so that the innovation stays in the organization, not outside the organization. org and, and you know, there's a place in the world for vendors, right? We're gonna have sponsors here on this show.
You have sponsors there now. So it's not like we're anti vendor or anti absolutely companies, right? But you, you know, it just, you can't just let it run wild.
I, you know, looking back on DevOps, for instance, right? And I've spoken to the, the people behind this decision, you know, Patrick dubois and Damon Edwards, John Willis and Andrew Clay Schaeffer and so forth. And, um, you know, they purposely didn't define, they didn't want to, uh, try to box and not box it in, but you know, clearly define what was in the box and what was out of the box.
And, and even like when we, when I, you know, my co-founders and I started the DevOps Institute for instance, you know, they were very upset initially that, Hey, how can you be certified in DevOps, for instance? How, how can you have a course in DevOps? DevOps is what you want it to be.
The DevOps you get is the DevOps you deserve. But that doesn't work in, in the real world. People need boundaries, they need roadmaps, they need guide Barkers, you know what I mean?
They need a pass a hundred percent. I mean, that's, that's what people come to the community for, right? They're like, Hey, either what is platform engineering?
Right? Um, and, and then, you know, really like on that initial discovery or, uh, what can it do for me, right? And, and really what they're looking for is a recipe is not a kind of, you know, find your own adventure and you know, and, and struggle through all of these things, uh, that actually other people have already figured out.
But actually they, what they're looking for is like, okay, what have other people already figure it out? What can I learn from them? Right?
Um, and ideally packaged in something that's feasible, that's easy to consume, right? Whether it's like a, like a rough architecture or blueprint, whether it's like a framework to do things, whether it's a course, you know, a training, that's, that's what people really want. Yeah.
And ab absolutely. So you said people were doing platform engineering 10 years ago. I'll put forth the proposition.
They were doing the things that make up platform engineering a lot longer than that, right? Platform. One of the interesting things about platform engineering from where I look at it is it's taken, it, it's sort of putting a wrapper on a lot of ops type of, of, you know, motion a lot of different motions that we've been doing in it for a long time and grouping it and saying, okay, this, this is platform engineering.
Yeah, you've been doing some of this over here. You did some of that over there. We, we put it all together and say this is platform engineering.
Now, of course, there, there's still people who say, well, how does, how does platform engineering relate to DevOps? Right? Is it like this, is it like this?
Is it like this? Give them your take. Yeah.
Not, and, and, and, and before I get into that, like I think your, your, your initial point is, is, is a hundred percent spot on, right? Like, if you really zoom out the whole software engineering is, is, you know, like a, a history basically of building a platform on top of one another, like mm-hmm. And progressively obstruct more and more.
So if you really like squint and zoom out, it's like everything is platform engineered. But if we, if we focus on like, you know, what we mean on this podcast, um, is the, um, you know, I think it's helpful to understand where it comes from and, and, and so, you know, if you take a, like a not too short walk down memory lane, and you kind of go back to, let's say, you know, 20, 30 years, like the way software was developed, right? It was this typical, okay, you have the developers, the application developers developing something, and then you had this like, mythical figure of the, of the CIS admin somewhere, usually in the basement of the same building.
Like actually, and the crazy thing is they weren't, they were responsible for, you know, real networking, right? Like buying servers and slowing server, networking them and so on. And then they're also responsible, obviously, for running these applications that the, that the developers were building and just, you know, famously throwing over the fence.
And so everybody was like, okay, you know, this doesn't work. We need something better. And, and then, you know, few people came, you know, with this, with the DevOps solution, right?
Of like, Hey, let's, um, you know, the way we align incentives here is actually by saying, Hey, if you build it, you also need to run it, which is one of the core tenets of DevOps. And that's, and you know, that was famously yelled on stage also by, uh, Wener fog when they launched AWS, um, sorry, dogs. And, um, and, um, and, and, and, you know, conveniently also Vanner at the same time launched the, the console that allowed you to do that, right?
To, to build and run everything. But I think the, the world when this happened was a very different world than it is right now. Even Amazon itself, I believe it was like 300, 500 engineers.
I mean, nobody, don't quote me on this, but like, it's, it, it was like merely orders like two orders of magnitude smaller than it is right now as an engineer organization. So this is really what's changed ever since this, um, I think great idea of like, Hey, if you build it, you run it. Like the, the idea in theory is, is fantastic.
Um, the problem is you have two trends that happen ever since. So since the early two thousands, one engineer organizations, you know, exploded in size, um, and then the entire ecosystem exploded in complexity, right? So while Amazon had 300 people, now, uh, 300 developers, now they have, I don't know, like 20, 30, 60,000, I don't know how many engineers they have a lot.
While maybe the, the large enterprises used to have like a shop somewhere outsourced. Now, they all became, to some extent, you know, tech or engineer organizations, you know, McDonald's, Fords, they all have like huge, um, huge footprints. Um, and, and at the same time you have, um, you know, this entire cloud thing that started and then quickly exploded.
Uh, and obviously, you know, you've, you've witnessed all of that, right? With, with, with this, uh, you know, uh, Kubernetes infrastructure is code and the different, like iterations of infrastructures, code, like all these different things that all of a sudden while if I, you know, in 20 early two thousands, I had to, you know, just like run a script, touch a couple of tools to you, you know, if I build it, I run it to like deploy my code. Um, you know, fast forward like 10, 15 years now, it's like super complex tool chains, um, in, um, in very fast growing companies.
And so the first ones that realize that, hey, this is not really working. Were the really, the tech companies actually like the, you know, leading engineering organizations effectively. So think of the Googles, the Airbnbs, the Spotifys of the world that were literally adding tens or hundreds of developers every month, maybe to their orgs, and they quickly realized, Hey, I can't expect every single new junior developer to be familiar and understand this increasingly complex tool chain that I'm running on.
Um, uh, that's just not working. It's not, it's not gonna scale. So I need to build some sort of platform layer in between the developers and my infrastructure operations teams, right?
Um, and, and that's really where platform engineering started, right? It is about building this, this obstruction layer on top of your existing cloud native slash actually most cases just a hybrid right? Setup.
Because that's the reality. You know, like 10 years ago I was like, oh, let's go to the cloud, and then like off way is like, ah, maybe not everything. And so, like, you know, the reality of platform engineering is it's usually run on a combination of, you know, cloud, multi-cloud and on-prem stuff.
Um, but it's really about building that layer that enables developer self service, right? Like that's really the key thing. Um, while, you know, driving standardization and driving automation across different teams, across different, um, uh, you know, different workflows.
And, and so if you then take a step back again and look at this, well, actually what platform engineering does is really, uh, it actually enables DevOps, right? It enables DevOps, um, at scale in the cloud native era, um, for, for very large, uh, enterprise organizations. And so through that lens for me, but from engineering is really an evolution.
I was trying to think like how to show this with the hands like you did, but yeah, it's really, its like an evolution of, um, of, of DevOps. Um, and you know, there, there, there have been, um, you know, controversial, uh, kind of like debates in the past about like, Hey, is DevOps dead? Is, you know, platform engineering the de killer?
And, um, you know, while, um, I was definitely part of some of those conversations in the past, um, it really like what I believe is, and, and I think there have been like very helpful conversations as well, um, to, to really wake up the industry as to like what was not working about DevOps. But I think ultimately it's also incorrect to say, you know, platform engineering replaces DevOps is, is really just, it's really just an evolution, um, that enables DevOps at scale. So that's really how I think about it.
That that's, I think the right word. It enables DevOps. Mm-hmm.
Here, here's my take on it. And look, I, I don't pretend to be what I'm not, right? I'm not a DevOps engineer, nor am I a platform engineer.
I'm not an engineer really. Period. At the end of the day, right?
I'm more of an entrepreneurial business person, but I've been here watching and involved in it from, from early on. I, I think one of the mistakes, not a mistake, but you know, it's like, do you ever watch, you ever see those things about how humans evolved and there's all these dead ends, the Neanderthals to this one, to that one, you know? And then eventually we got to homo Sapien with DevOps because we experimented a lot.
One of the kind of, not a dead end, but one of the, we, we took a detour was, was shift left, right? That idea of yeah, if you develop it, you build it. If you develop it, you deploy it.
If you develop it, you secure it. If you develop it, you test it. It's really shift left, right?
Yeah. We shifted all of these things onto the developer who was already the highest paid, most probably overworked person in terms of, Hey man, I gotta get code out. And what do developers like to do?
Develop, they like to write code. They're not security pros, they're not QA testing pros. They're not platform necessarily pros.
So I think and especially now. So that's one developer. Now go to these hyperscalers, the Googles, the Airbnbs, the Twitters, and well before Elon Musk and all those things, right?
You, you, you take that problem and multiply it by 10, 20, 30,000 developers and you got chaos. Yeah. And I don't mean chaos engineering.
You've got real chaos. Right? Um, and, and so in my mind, platform engineering is trying to make sense of that chaos.
Give these developers a stable platform. A, I don't know if you wanna call it an abstraction layer, because I think sometimes Yeah, it's more than an abstraction, right? Um, that they can build on.
That's one less thing that allows them to do what they want to do, which is code. And that's, that to me is the, and that's why it enables the whole DevOps thing, right? Oh, I got, I got a nice base to build on.
I got a foundation here. It's not like shifting. And it's not on me as the developer to do that while I'm coding, while I'm securing ed test.
Yeah. And oh yeah, I'm gonna deploy too. Well, and this is, I think this is, to me is very interesting, right?
And, and I love to hear, 'cause obviously again, you witnessed it from very close. Um, like what, what was the, you know, were there, you know, conversations about this like shift left and like, Hey, is this actually the right thing? Thing?
Oh, absolutely. Because, you know, if, if I think about, okay, if you look at virtually like every industry in, you know, modern Western civilizations since the 18 hundreds, and the Indus Industrial Revolution, basically, every single industry has gone towards a trend of specialization, right? It's like from the assembly line, you just like, go and like, specialize more and more and more, except for, um, ironically, you know, software engineering.
Uh, and, and, and, and sort of like how it's, you know, the, how, you know, everything runs, um, which is DevOps, which is ironically is also the thing is also the, the, you know, the really the layer that actually enables all this other industry to keep, to keep, like going towards visualization, but then this, this, this, you know, and maybe it's because the industry's still so young relative to all the other industries, right? And so, like, I don't know, less than a hundred years old. Um, and, but, but where at some point we thought, okay, it was a great, it's a great idea to have everybody do everything, you know?
Um, and it's so the opposite of everything that's worked everywhere else, it's like, why would d also the thing that's very curious. Yeah. You know, so if someone were gonna write the history of IT and software development, I think they would look at the, let's call it the DevOps period, starting in let's say 2011, around there, 2012.
Um, and, you know, as sort of a, like how people view the Russian revolution almost of 1917, right? Which was sort of a, a revolt against the silos, right? Right.
Because there, that's a good analogy actually, right? It was a revolt against the silos. We, everybody was in a silo because it was so specialized.
But the problem was there was no communication, right? Each silo was doing their thing and there was no coordination, no communication, no cooperation, right. In the silos.
So at its core, that's all DevOps is. Yeah. Let's break down the silos.
Now, breaking down the silos doesn't mean that the ops guy becomes the developer, or the developer becomes the ops guy, or the security guy becomes the testing guy, or the testing guy becomes the developer too. To me, what, what DevOps is working, right? You don't, you still have all of those people, but they're all part of a cross-functional DevOps team where people do their thing.
'cause they're specialists, but there's just tighter communication and coordination in the team so that, you know, everyone does their thing in time and, and in coordin it's not thrown over a wall and said, oh, it worked on my machine, right? And it worked on my job. Which, which works really well, right?
As long as you're as more team of people that are more or less on the same level, right? Like right. When you, to your point earlier, when you start having like 20,000 and you have like very senior people that are, you know, really experiencing this whole, this whole stack that you're running on and like the the new junior frontend developer, then that's where it breaks, right?
Yeah, it is. And so, and again, busting down silos, it, it's not just a silo of you are a tester, I'm a security guy. It's a silo of I got 15 years here, you got six months, right?
Yeah, yeah, yeah. Exactly. You can't expect that guy with six months to, to have the wherewithal that the guy who has 15 years does.
And I don't mean just guys, there's women, there's everybody involved here. Yeah. So I think that's another piece of the platform engineering, which is again, about giving everyone that level foundation of this is where you build on this is, you know, it's all there for you, whether you just got here or you've been here a long time, it just standardize it.
Yeah. Yeah. Absolutely.
And, and you need that, especially if you're gonna go at scale, right? Yeah. It, if you're a little startup with five engineers, you guys could run as fast as you want, right?
And everybody Exactly. Is, is involved. But when you're at scale, you need scalable specialization.
Yeah, yeah. Separation of concerns. I agree.
Absolutely. But I really like your, um, your analogy on, um, it was basically like a revolution, really, right? It was like a, a, a rebelling against like the status quo and ended up in this maybe, maybe not anarchy, you know, but like something then, and then now it's like, you know, the, the pendulum kinda like swings back, right?
Yeah, it does. Well, I, I think people realized, 'cause the answer to all of those things was shift left. That, that really, you know, and I, I, and guilty, I, let me just raise my head guilty initially, I thought it, like, for instance, DevSecOps, I thought it was a great idea to move security all the way to the developer, right?
Because we're finally gonna have more secure code. We're gonna have, it's, it's gonna, by the time it's deployed, it's already been tested and patched than secured. And it, and that's a good, that's good.
We should do that. It's just don't expect a developer to do that, right? The developer wants, I've never met a developer Luca who raises his hand and says, oh, I wanna, I wanna develop insecure code.
I, I, I see. Yeah. You know what I mean?
I don't care about the security. They all want, they have pride. Yeah.
These are, you know, in my mind, the developers, the software developers of today are like the old like German craftsmen who took a lot pride in everything they built. Right? Totally.
Top stuff. I think most software developers are like that. They take pride in what they built.
Well, it's, it's, it's very interesting you say that. Like I, I recently actually wrote a, um, a piece on, on, you know, basically you can think of platform engineering as the industrialization or commodification of, of, of, of software engineered, um, right? And, and how, um, to your point, I think the way software is still built in a lot of even like large engineer organizations is in this craftsman's way, right?
The, if you think about like a craftman that, like a real craft, like a real carpenter, right? Like the, they knew how to, um, you know, what tree to pick for this specific, uh, you know, chair. And so like, they, they knew the entire thing vertically integrate it right from like the tree to the thing to the nail.
And, and, and what you really want is somebody that's like, Hey, can just chop down the tree, somebody that can make the chair and then throughout that provide them with standards like screwed, right? Where, you know, like, I can open this, uh, you know, this drawer or this drawer, but like, there's always this like M three screw that's like 30 millimeters long or whatever. And, and it's, it's always gonna fit in this type of hole.
And, and, and, you know, so that's, I think that's really, um, where we are. And I think that's what makes the whole part from engineering space so exciting and, you know, this podcast and, and everything that comes with it. Um, because we're, we're still at the beginning of, of this basically industrialization of, uh, of software engineer and, and understand why, you know, to your point, some people are pushing back to it because people like being, uh, artisans, right?
Um, it, it, it, they, they, it, it, they, you know, they find pride in that and so on. Um, but ultimately, um, you know, you can, you can think of, of of, you know, what happened, right? And, and you are gonna have a few artisans that have much more, much higher leverage, I think.
Um, and, um, you know, and, and probably like more, you know, more things that are just gonna be automated. Um, and, and that's the thing, that thing that we to go through. Well, that's, yeah.
I mean, we'll discuss that on a, on a, the upcoming show, the whole saying and AI thing. 'cause I mean, that's gonna have a huge effect. But it, it really, you know, if you take that craftsman, you had sort of master craftsmen, journeyman craftsmen, and then you had apprentices, right?
That was the old guild model that, that a lot of Europe and even here in the us, uh, who used to have, whether it was everything from electricians and plumbers to carpenters, you know, you had masters kind of just regular journeymen who, you know, did their work and were getting better. And then apprentices, and I think to a certain degree software today, it, it, we have the same kind of thing. But like you said, if you standardize on stuff, it makes it a lot easier.
Luca, we we're almost outta time. I wanted to just circle back. You know, we're gonna be doing this every other week, right?
And then like, once a month or once every six weeks, I forget the, uh, cadence. We're gonna do a live version of this with a full on panel. You and I are doing the first show or two, but we're gonna start bringing guests on, and we're gonna delve into some of these great topics.
So, um, for people watching this, this is just the first episode. It's just Luca and I warming up. Yeah, but there's a lot more coming, man.
It's gonna be a great show. Yeah. I can't wait.
And we have so many, you know, insights and, you know, stuff that we do in the community that I really wanna bring here and surface for everybody to consume. So, super excited to be doing this together. All right.
org is, is the mainstay for the community, right? Any other, and Humana, we, we might as well give human tech a plug. What, what's their website?
com, you know, that's where you can go and find the, the best, uh, platform or shooter in the market. Um, but other, other, I think community destinations that might be interesting. com.
Uh, the, the event for 2025 is already live. People can go sign up for free, uh, or buy the tickets for our live days. We have a live day in New York, very cool and live in London.
Very excited about that. And, um, you know, platform Weekly dot Rommels, if you wanna sign up for the newsletters, there's a lot more, but we'll stop there for now. Well, we'll start there.
Yeah. com. org and, and these other sites as well.
Luca, thanks so much, man. I think we're off to a great start. This is gonna be a lot of fun.
This will be fun. Thank you, Alan. Thank you, everybody.
The next thank you, everyone have a great, well, we'll do one more show before Christmas. Yeah. Oh, yeah, yeah, yeah.
Next week we'll do one. All righty, everyone. Until then, this is Alan Shemel, Luca gte, you've just watched the very first platform engineering show.
Take care. Hello, and welcome everyone to the 5G Factor. I'm Ron Westfall, research director here at the Futurum Group, and I'm joined here today by my noted colleagues, certainly, uh, known throughout the, uh, mobile ecosystem.
Tom Hollingsworth, who is the networking nerd, and the event lead at Tech Field Day here at the Future and Group. And in fact, I believe that I mentioned it on our last episode, that we are basically looking at a, an incredible lineup for Tech Field Day, uh, throughout, uh, the first half of 25 and, uh, beyond naturally. Uh, today, naturally we'll be focusing on what's going on in the 5G ecosystem specifically.
But before we dive into it, I want to note that we have, I think, some pretty good, um, ideas for, uh, mobility Field Day, which is gonna happen in May, May 7th and eighth of 2025 specifically. And I'll hold there and say, Hey, Tom, uh, how are things coming along? And, you know, what else can he say about the upcoming Tech Field Day events?
Well, I can tell you that Mobility Field Day is gonna be super exciting because I've already heard a lot of companies that are gonna be interested in that, but I know that a lot of our listeners out here, uh, they have other interests, right? So maybe you're more into something like Cloud or ai. com and check out the schedule, because we do have some events coming up very soon that deal with those subjects, and I think that you might be interested in some of the presenters there.
Right on. And I'd, I'd be remiss not to note that we're, uh, slated for Networking Field Day 37. It goes to show you just how much pedigree is behind this, and that's gonna be in March 19th and 20th.
So please, uh, pay attention to that one as well as Tom and I will be partaking in that particular event. And so, with that, what is really going on in the 5G ecosystem that jumped out at us and warrants conversation today? Well, first of all, I would like to start with a, a recent blog, uh, that I saw, and that is, uh, related to Cisco and Boost Mobile, spotlighting, how they're multi-year collaboration is well making progress.
And so I think what's gonna be important here is, uh, provide a little background and, uh, framing. And that is, uh, boost Mobile is, uh, has Nile, uh, DNA at, at its roots, uh, that, you know, is from like over 20 years ago. But today it is owned by Dish Wireless, which is in turn a subsidiary of EchoStar.
And that's after o undergoing server ownership changes, you know, over the years now, today, uh, boost is the fourth largest, uh, wireless carrier here in the United States, and it's serving approximately 7 million subscribers as of, at least, you know, toward the end of 24, and operates a 5G network that's covering over 73% of the US population. So I think that speaks to its credentials. And you know why this is important to, uh, look at now in terms of, uh, network and Services Boost is providing, you know, both prepaid and postpaid mobile services.
And also on the Coopetition side, boost is using its own 5G network and also provides services through T-Mobile at least until 2027, as well as at and t at least through 2031. And in the meantime, though, it's positioning itself, as you know, a fourth major, uh, alternative to the big three, uh, began T-Mobile at and t as well as Verizon. So, you know, there's some, you know, subtle, uh, positioning and marketing going on here.
But I think, uh, what was a key takeaway from, you know, the refresh that Cisco and Boost provided is the key role that automation has played in terms of making Boost Mobile's 5G Network a reasonable success, uh, to begin the test automation framework, or TAF from Cisco, uh, proved pivotal, uh, in testing new services and activating the cell sites. In fact, uh, TFAs capabilities we're able to generate test cases and execute them across thousands of devices within minutes. And so this is something that can't be underestimated.
Again, this is something that could not have been accomplished with, you know, pre automation manual approaches. And so this is showing that automation, uh, I believe is making progress and how mobile networks are designed, built, and tested and so forth. So this is good news really for, you know, not just the cause of automation, but in terms of, hey, getting more 5G Network out there for, you know, the us uh, populace as well as, uh, you know, beyond plus.
Uh, another key factor was the SDN controller that Cisco provided called the Cisco Crosswork Network controller. And that basically provided that what can be dubbed zero touch provisioning to automate the deployment and activation of all these cell sites. Now, these are the positive aspects of the relationship.
However, as analysts, we have to look at the full picture and need to keep a close eye on that EchoStar dish mothership, uh, dimension that I mentioned. And so, at that, Tom, from your perspective, I guess, you know, there are a couple of things going on here looking at this specifically. You know, how, what is Boost Mobile's prospects and, you know, being a part of, uh, EchoStar Dish and also, you know, what is going on with automation, at least in terms of mobile networks.
So I, I like this partnership that, that, uh, boost Mobile has worked out with Cisco. And here's the reason why. If you go out on the internet and you look for Boost Mobile, uh, you'll learn, originally they were an MVNO, and if you're not familiar with MVNO is basically I ride on somebody else's network.
If you've seen a Mint mobile commercial, you kind of know that they don't build out their own stuff, they're riding on somebody else's network. However, after the acquisition by Dish Network Boost really started building their own network out. And so I think it's exciting to see, you know, the fourth largest carrier in the market starting to kind of get on their own network.
And it's a non-traditional one, right? Because it's being mostly built out by Dish Network. So I think that they're gonna need expertise, right?
Because you've got at and t, you've got Verizon, you've got T-Mobile, they have network expertise. They've been doing this for years. When you're coming up, you don't have that capability.
You don't have a large dedicated group of people that are built out to do these kinds of things. Well, how can I get there? Well, thankfully you have access to, uh, companies that have software and hardware that can make that happen.
And that's really what Boost is looking for here. And of course, Cisco wants to kind of get this 5G technology out as much as possible to get into new market spaces because this isn't a place that they've played historically. They do not have a, an industry leading private 5G or even really any kind of telecom backbone on that side of the house.
Now, there, as I'm sure somebody's typing a comment right now, but Cisco's in every ISP, you're right, they are, but that's because they are a network layer. When you look at the way that telecom worked up until 5G, there really wasn't a lot of room for the Ciscos of the world. You sure you had the Ericksons, you had the Nokia's of the world that kind of had dedicated hardware.
But now that we're working with, you know, these virtualized layers that use more off the shelf hardware, Cisco has an opportunity to play in that market. And I think that this is kind of them jumping in saying, well, if we can't be first or second or third in the market, we can very well partner with four during their build out so that we can use them as a reference case and prove that we have what it takes to make that happen. Right on.
And I think, um, uh, to the point about, okay, boost Mobile is looking, uh, like, uh, has momentum here, and certainly the Cisco relationship is proving a factor. And, uh, I mentioned, you know, the EchoStar, um, the fact that it, it's really the, uh, owner of, um, booze through, you know, the, uh, dish wireless, um, uh, assets. And I think it's important to note that the FCC, uh, did agree to allow them to extend their build out goals that is, you know, EchoStar dish in terms of going from, uh, mid 25 to late 26 in terms of that, uh, overall 5G network bill.
And so, uh, that also includes, uh, all, I think, uh, of notably moving final construction goals from 26 to, uh, 2028. And as a part of it, this is also including deploying 24,000 towers by, uh, June of, uh, this year, as well as ensuring its network is 3G PP release 17 compliant also by June of 25. So there's a fair amount of homework that's going on in the background, at least in terms of, you know, the obligations of, uh, EchoStar.
Now, there has been concern, you know, that's been shared by the financial community, or at least a part of it, that, uh, EchoStar could face some serious financial challenges, including potential bankruptcy by early 26 without securing, you know, more funding or funding arrangements. However, as we just saw, uh, or saw very recently, the e EchoStar successfully completed a, uh, what readily as a debt swap deal, uh, back in November of 24, defying really the more doer expectations of, you know, the detractors out there. And so the FCC also is backing up, you know, EchoStar efforts to really come out with what, again, it can be dubbed the fourth pillar or a fourth major competitor within, you know, the US mobile, um, competitive landscape, certainly on the 5G side.
And again, that is using, you know, new technologies, uh, basically from its inception, you know, cloud native capabilities and so forth to really, you know, make it a, a differentiated and I think, uh, exciting, uh, network as it becomes, you know, more firmly built out and EchoStar as well as boost continue meeting deadlines and so forth. So that I think is really, you know, the net takeaway from here. Yes, you know, there are some rough seas.
It wasn't unique to, uh, you know, EchoStar dish, uh, but I think things are clearing up more. In fact, uh, at 25, we're seeing indicators that there'll be more spending by the telcos overall, at least in the us and that's due to factors such as, you know, new interests in ai. But also, you know, what we touched on right here now, automation capabilities, just taking advantage of new technology that makes, you know, the deployment and the operation of these networks more efficient and so forth.
And so with that, now let's turn to, I think another important factor here that's always been important, but certainly 25 will be no exception. And that's the role of 5G in cybersecurity. And specifically what I'm looking at is that Nokia recently, uh, touted that it's collaborating with the National Institute of Standards and Technology, or NIST on its National Cybersecurity Center of Excellence.
I'm not even gonna bother trying to pronounce that acronym, but the, uh, main takeaway here is that it underscores Nokia's commitment to addressing security and privacy challenges across the mobile networks. Well, that seems like, okay, uh, that's table stakes. Of course, they have to do that.
But what is distinct here that's coming out of, you know, showing a spotlight on this collaboration? Well, with 5G new standards require regular reallocation or refreshing of temporary identifiers. And what that means is that temporary IDs are constantly on, automatically reassigned, making it significantly harder for unauthorized parties to use tracking mechanisms to compromise user locations or identities.
And that sometimes has caused, you know, headline news. So what is different here, it's a clear advance over 4G capabilities. That is 5G is definitely built to not only minimize it, but potentially eliminate it.
And so with that, using, you know, defined intervals, uh, for refreshing temporary IDs, 5G is a better position to protect the privacy of user information. Also, 5G networks are built to enable wider range of capabilities, especially for sectors as defense and public safety that rely on, again, rapid decision making and really data protection and so forth. And with 5G autonomous operations, which we touched on with the, uh, boost, um, Cisco, uh, collaboration, these operations, uh, can better support things such as unmanned drones and robots and automatic surveillance that are really, uh, critical for mission critical, uh, mission capable, uh, assignments, as well as just increasing the reliability all around.
And so with that, Tom, uh, what are you taking away from, you know, okay, what's going on with 5G and improving, you know, security capabilities as well as, you know, Nokia putting a spotlight on it here. I think it's important for Nokia to kind of lead the charge on this. And the reason why is, I was having this conversation with a friend of mine the other day.
If you have the, any kind of identification for a mobile device, you can effectively own someone without ever knowing who they are. Uh, think about some of the platforms that we've seen that leverage wireless technology, where like, they can track you through a store and they know how long you were standing in front of a specific section of shelving and what you were looking for to the point where if you have the store's app downloaded, they can push coupons to you. Like, Hey, go back and take a look at that tv.
We'll give you 10% off, gets scary, right? And that's on wireless. Imagine if they could do that on your handset no matter where you are.
And that's what we're talking about here. Apple already put this in place with their wifi radios by being able to randomize the MAC address. We can't do that on a mobile phone because we have an IMEI, they can't be changed without a whole lot of problem.
And so Nokia basically saying, this needs to be randomized. Nobody outside of us, and whoever your provider is, needs to know it. And I, I like this idea.
You are effectively anonymous to in certain points, and, and it's absolutely necessary in a security world because our lives, our Phones Are who we are. Like, and, and in the US we're actually lagging a lot behind a lot of other places in the world. When you think about a place like China, like you literally live in WeChat.
Your, your subway pass is there, all of your paychecks are delivered there. Like if, if they want to cut you off from the, the world, they just disable your access to WeChat for a day or a week. And, and that fixes the problem.
But even now, you know, I can, all of my loyalty cards, all of my bank cards are in my iPhone, uh, pretty soon my driver's license will be there. And then what do I need to carry a wallet for again? Oh, cash.
Oh, how 19 hundreds of you. Uh, so I, but I think it's important that we have to start putting more protections in place because we can't rely on the device manufacturers to do that for us. We have to have the carriers also looking out for us and trying to keep us more secure as opposed to, I don't know, hoping that we'll eventually fix the problem.
Yeah. And I think those are all salient, uh, salient and very outstanding points. And what I think is also important here is also I think underlining, you know, why 5G and that is when you talk about say, 5G connectivity or say a 5G laptop, 5G can provide that extra layer of built-in security that might not be present in some implementations of wifi, for example.
And that certainly is, uh, something that has plagued, you know, small businesses and consumers. But when you're talking about the federal government or any, you know, government entity out there, including the military, then yes, you know, you definitely want to have, I would say that built-in 5G uh, security mechanisms. And that I think is part of the reason, uh, when we touched on it last week, is that now the US Defense Department is mandating that their military base is used private 5G as their primary, uh, way of wireless communication.
And so with that, I think, uh, we can now turn to, okay, how's this being implemented? Well, we just saw that again, the US Department defense has appointed Federated Wireless to, uh, subcontract JMI, excuse me, JMA wireless for RAN infrastructure and HPE for core network software to deploy its first commercial private 5G uh, network. And at least it's, you know, being characterized that way.
Certainly, uh, federated Wireless is keen on, you know, being at the forefront here. And what the 6 million, uh, uh, dollar Deal is doing is it's part of a 42 month sustainment contract, and it's to make good on a large scale private 5G network at the Marine Corps logistics command base at its Albany hub in Georgia. And so I think this is again showing okay, why, uh, not just 5G, but why private 5G well, uh, certainly in the military is, uh, putting its money in this direction.
And, uh, so Tom, from your perspective in terms of, you know, okay, why 5G security or five G's role in overall security, how about, you know, what's going on with private 5G and why is the military so keen on it? I'm actually excited for this for a couple of reasons. Um, first of all, I, I, I have to say this, if you ever hear the term military grade encryption, that's how I know you don't know what you're talking about.
Because it turns out that most of the radio comms that the military uses are, are purpose built and very, very specific. Usually they lag behind technology quite a bit because military builds for reliability, not cutting edge, but they also have this other problem. They have a lot of contractors.
In fact, I'll go so far as to say more than 50% of the people who work on a military base are not actually military personnel. They're military contractors. Uh, the member may not be 50%, but it's, it's really close and it, you've got a lot of moving parts there.
You've got a lot of things that you need to keep in mind. And now think about the fact that a lot of the communications infrastructure that we've been using as of late has moved away from purpose-built networks to using cellular capabilities. If you want an example of that, walk up to anyone that works in a department store like a Walmart and ask them to look up an item.
It used to be that they had a specialized wireless scanning tool to do that. Now they pull out a phone, probably their own personal device, and they look up through an app to see if that, that item's in stock, right? Well, that works in a department store, but not on a military base.
So imagine if you walk onto a military base and they give you a device and it's, okay, this is how you're going to, I don't know, scan equipment in, or this is how you are going to do inventory reports, or here's the tablet that you're gonna use for whatever reason. Do you want that information writing over a public network up to a tower to come back down into a DOD safe, um, data center? Well, I can tell you what the DOD answer's gonna be.
Oh, no, we do not want that. So what we do now is we hand out these devices, we use private 5G to connect them directly into the databases and into the servers that are located on base or within DOD facilities. And that never goes out on the public internet, which makes everybody a lot happier, but it means that we're finally starting to transform the technology away from these purpose-built networks into something a little bit more, I don't know, useful.
Because when you think about it, you're, you've got people who are joining these, um, you know, military forces who are in their late teens and early twenties. By and large, these are the folks who are doing the legwork. Do, do you think that they know how to use some of this old school technology or do you think that you can just hand them a tablet and they can figure it out?
This is meeting the new recruits where they're at while also still being able to provide the same types of communications and technology that the contractors need to keep those forces meshed together. Yeah, I think those are very important insights. You know, why is the military keen on this?
And, uh, a couple other, I think, uh, notes about, uh, this particular deal. You know, the first, you know, commercial private 5G network on a military base is that it's covering, uh, 1 million square feet. So, you know, this is something that if you were relying say, heavily, uh, on wifi, it would be required quite simply, more investment, more equipment to, you know, co cover that amount of area.
Also, I think it's interesting that HPE now providing, you know, the core software, uh, this provides more warrant as to why they acquired ANet. And so this clearly, I think was a smart bet on HP e's part to, you know, play a more integral role in, you know, private 5G alongside. It's, uh, certainly well proven, uh, Aruba, uh, wifi assets and, uh, getting to the details, I think, uh, the deal spotlighted, okay, why is the military keen on it again?
Well, it includes 98% accuracy and inventory, uh, rewarding as well as a 65% increase in goods velocity and a 55% reduction in labor costs. And so while we could quibble, okay, maybe we will necessarily be across the board for all the implementations, or they, you might come up short at a, as the real world, uh, implementation kicks in. But these numbers, I think speak for themselves that, you know, they clearly the military kick the tires on this, and it's not just about, okay, uh, more secure communications always important, but also improved de efficiencies in terms of inventory and, you know, the speed of things getting delivered and so forth.
And so we'll definitely be talking more about this as we get closer to Mobile World Congress, which, uh, is again, the first week of March as well as, you know, during the course of 25. And so with that note, I wanna say again, thank you Tom, for coming on and joining the 5G Factor, always most welcomed. And it is a pleasure to join you again, Ron, and have these great conversations about where the 5G technology landscape is headed.
Right on. And with that, don't forget to, uh, bookmark us. That is, uh, the future and group that includes naturally Tech field day, as well as the 5G factor.
And again, we appreciate everyone joining us and, you know, listening to our thoughts and insights on what's going on in the 5G ecosystem. And with that, everyone please have a good private 5G and secure 5G Day. Thank you again at.