Techstrong TV – January 8, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone, it's Happy Wednesday. Welcome here to Text and Gang, where we're still going to fact check. Hey everyone, Alan Shimmel for Textron.
Welcome to our show here for this fine Wednesday. I know across many of where many of you are here in the US here, it's cold, there's snow and wind and rains and cold temperatures. We even broke out sweaters down here in Florida.
I hope wherever you are, you're safe, sound, and cozy. Um, you know, I made a little joke in the opening there about where we still fact check if you haven't heard the news, you know, meta announced yesterday that they were gonna stop fact checking. They're gonna rely on crowdsourcing from the audience to comment on, on fact checking.
And just real quickly, what a sorry state of affairs we've come to. You know, I'm reminded of John Belushi on Saturday Night Live 25, 30 years ago, talking about, you know, they smoke hash on the streets of Mexico. But, but no, we can't hear how are we, what, what is, what is this coming to?
And, and, you know, we could blame meta, but they're just doing what Twitter's doing, whatever he calls it these days, is doing anyway, which is they don't fact check either. And maybe, and maybe that's what we deserve. You know, Andrew Clay Schaefer, one of the guys in the DevOps movement always said, the DevOps you get is the DevOps you deserve.
Well, the same thing goes, it's hold true for social media and society. The social media you get is the social media you deserve. If we as a society are not gonna hold our social media providers feet to the fire about stop polluting our kids' minds and everyone else's minds with bull crap, then we get what we deserve.
I'm gonna step off my soapbox now though, and introduce you to today's gang members. And if they want to comment on it, feel free gang. Um, first of all, we've got a brand new text on gang member to introduce you to today.
Her name is Sna sa sa Saha. I hope I said it right, Soni. Yes.
Yes. Sagner, welcome to our show. It's great to have you here on the gang.
You know what? Introduce yourself to the audience. Thank you, uh, for having me as, um, I'm Sagner Saha.
I just joined the Techstrong gang as editor, uh, protect Strong ai, and I'm thrilled to be on the show. Thrilled to have you on here, and it's great to have you here. Speaking of editors, let me introduce you to another text drawing editor.
She's been here a while. Um, Amanda Reni, well, she's edited just about all of our sites over the years and, and does a lot of special assignments too. And it's Amanda Reni, like Mitchell says, like Reni, like lasagna.
I don't know how he thinks that rhymes, but whatever. Amanda, welcome. Welcome to Textron Gang.
It's great to have you here today and Happy New Year. This is your first show of the new year, right? It's Happy New Year.
Good to have you. Um, I might as well continue with the, the, you know, the better looking group of our gang today. Before we get to the Ory guys joining us, I think she's in CES.
Are you out in CES today, Lisa, or we're out in CES Linger today. I fly out later today and I've got two full days on the show floor and I cannot wait to get my Apple Watch rings to spin with all the steps I will be getting, seeing what's going on. But I've been following the coverage with all, all the keynotes.
It's been amazing. Very cool. It's our own Lisa Martin marketing guru and well, radio hosts now.
iHeartRadio host Yes and Yes, Entrepreneur with her own agency. Yes. And Textron gang member Lisa, thanks for joining us today.
Alright, great to be here. Moving from, from Lisa to the Ory Group, sporting his guitars, again, FU and vp, uh, analyst, Mitch Ashley. Hey, Mitchell, welcome, welcome from the Rocky Mountain Snowy, Rocky Mountain Snow, Colorado.
We've gotten some snow over the last couple of days, so I'm sure the ski people are happy. Oh yeah. Oh yeah.
Good for you guys. And then, um, I don't know if this snow up in New York is there, Mike, our own, our own chief content officer, Mike Ard. There was a brief coding the other day, but I do have a comment on this, uh, meta thing I think we need to bring back.
Um, Sergeant Friday, just the facts, ma'am. You know, I'll dragging it on social media, Fax and just facts. So for, for extra points, what was Sergeant Friday's?
Partner's name was Joe Friday and Harry Morgan. Well, it was Harry Morgan. That was his real name.
Yeah. Yeah. Alright.
It was, it was a close one, but you know, it, the facts would be nice, but, but the fact that our social media hyperscalers are just abdicating their responsibilities around this is a sign of the times. It, It's, well, I think they're just abdicating their responsibilities around anything as much as possible. I get so frustrated with Facebook, like there's no customer service.
There's no way to get help with anything. It's so frustrating. Could be worse.
You could be on XZ Twitter, whatever it is. You know, Alan, I think we're just regressing back to bulletin boards, essentially. That's what we're social media has become, is just a free for all.
You know, comment on what you want. Maybe there's a moderator on it, but we don't even have that. There's no moderators.
There is no, we don't have that now. So we're less than bulletin boards. Well, that's what made bulletin boards great.
Mitchell, you had moderators who though they didn't get paid really gave a crap. Maybe a OL chat rooms is a better analogy. Yeah, maybe that's sort of is I I just, you know, we're, we're devolving into a society of whoever screams the loudest All Well, we can't agree to what a fact is either on social media or off social media.
So, you know, it's just a reflection of the time. Yeah, good point. Sad, sad.
Touche. What a sad state of affairs. Anyway, let's move on from that and, and we will try to keep it factual as best we can here today.
Uh, Mike, we, we've got some news. Well, CES as Lisa mentioned, is full of chock full of crazy futuristic, and that's what makes C-E-S-C-E-S, right? Uh, AI empowered robots.
It's a thing. Yeah. Jensen Wong was the lead off keynote and he was talking about how they're gonna help companies overcome the limitations of physical environments when it comes to building robots and ai.
And the issue is, when you go build an AI app, it doesn't really understand the laws of physics. So they're trying to create a virtual environment so that if you create a robot, you will understand that, um, it can, if it hits something that there's gonna be some resistance to that force and therefore, you know, it should be avoided. But it can calculate what the impact of that is.
And today, if you go do that, you have to actually go build a robot or the car or whatever it is, and smash it into something about a hundred times for it to learn. So they're trying to do that in a virtual environment. And the goal is to reduce the cost of creating all these robots so that they will be millions of these things ultimately.
Um, and then the second thing they talked about, which, you know, was kind of a little more immediate to some folks maybe, is they want to go build something called Project Digits, which is a $3,000 desktop system that combines arm processors and Nvidia GPUs for data scientists and developers to go build, uh, either these new types of AI apps or any type of AI app for that matter. And so, if you look at it, it seems like we're trying to say that there are all, like, you know, if you listen to how he presented it, he said there's multiple classes of robots, right? Gen AI is a type of robot for software, and now we're gonna have all these physical robots.
Some of them include cars and some of them include actual robots. And robots will come in all sizes and shapes as we've seen a CES already. So, I don't know, Alan, are you ready for the robot era?
I, I would feel better if we had a law of robotics, right? Like in a law of three rules than the zero law of robotics. Because I do think we're going to need to have some, it would be, it would be good if we got out ahead of this, you know, gen AI burst on the scene and Elon Musk and all these people were signing the letter about we should stop development.
It could be terrible until they got their money into it and got their deal with it. But, um, it would be nice if we put some parameters on robotics right now with ai. 'cause I do think there is, you know, room for a lot of, uh, I mean, think about, you could have clone wars, right?
An army of clones. You don't have to send soldiers anymore. So if some dictator tin pan dictator here in the US or somewhere else wants to call out the troops and he's worried about whether American troops would fire on American citizens, well, you don't have to worry about that if you've got an army of robots.
And that's, that's a scary thought. That's a scary thought. On the other hand, I thought the c and CES stood for consumer electronics and, you know, dev dev computers or, or hyped out GPU dev machines doesn't really seem like a consumer product to me.
But look, Jensen loves a keynote. Absolutely. They're making a case for providing the tools for everybody to go build both industrial and consumer toys, right?
CS is still a great toy fair of our times and you know, we've seen a bunch of those robots being demonstrated this week. But, um, ultimately though, I think you're right about not just the soldiers, but just simple liability issues. Let's say I had a robot that's minding my child, right?
We talked about this in an episode last year. The robot goes haywire and something bad happens to the child who's liable for that kind of thing. And I don't think we've thought all that through entire at all.
I see robots in a different use case. I guess like when I think about robotics, I'm excited about the dangerous, uh, like rescue missions and things like that, that you could put robotics to help people in caved in, you know, caved in tunnels, rescue missions. And um, like we have an article on digital CXO about window cleaning on sky rises and things like that, that they're putting robots to use for.
So I think about those and I think that would be pretty exciting to have more robots in, in the more dangerous fields. I don't know, I just have visions of Mitchell and I dressed as Laurel and Hardy winding up the March of the Wooden soldiers, you know, with big scary teeth. And what do you say, Mitch?
Oh, I don't know, Laurell. Um, anyway, Well, you know, we, we, we could be not too far away from him, you know, the real life robocops, right? So Yeah, I just, I just feel like we're living every science fiction movie we've seen, right?
Any of our favorites are the Robocops Terminator Foundation or whatever, Terminator, you name it. And in many ways we are, you know, sci-fi does predict a lot of our future for us. And you know, you've said many times I've said the same thing, which is, you know, this train don't stop, right?
We're not, we're not stopping the I train to say, well, wait a minute, what's the right thing to do? We'll, we'll bolt on things later maybe, hopefully even before it's too late. Um, there's the industrial path of this, there's the kind of worker path of this.
You were talking about that, uh, Amanda, about, you know, taking on dangerous jobs and, and things like that. Certainly great applications for it. There's the personal side of, you know, now my, my, uh, my zoom thing on the floor can also pick up my socks 'cause it's got an arm to go pick up something.
Okay, I appreciate that. But I've got a lot more than socks to pick up my props a lot worse than that. But, um, what, what's part of, to me where we're kind of collapsing the consumer versus tech and, and industrial is putting AI on the desktop, not just in consumer devices, but you know, the announcement of the digit, uh, the CCB 20, uh, the CCB 20 chip based system, that's a supercomputer on your desktop to do essentially real ai not just development, but some level of operation.
You can imagine where that's going next to deploy out AI out to the edge, A signal that, you know, if, if they weren't thinking about it that way already, Nvidia very much is not just a compu a chip company, but they are an application of AI all throughout the supply chain. Well, that's what they wanna be, Mitch. That's what they wanna be.
They're certainly, the money has to justify a three. They've got the trillion do it right now. Yeah.
You gotta do something for a $3 trillion valuation. And I think what you're seeing is Jensen Wong and the rest of the brain trusts, they're recognizing that they're not going to have that kind of sustainable growth. Mm-hmm.
Just making chips. They've gotta own the ecosystem. Well, don't make the income and they gotta create, just make the chips.
Right? You wanna own the whole ecosystem. Right.
And they, you know, they were doing it with software, right? The whole, I forget the name now, of this open source Truda Guda. Right.
Kind of owning that, but now they're going be, you know, I wouldn't be surprised to see them making robots at some point. Oh yeah, absolutely. I think so.
And software, you know, that, that runs on the, you know, the Apple vision to be able to train those models, do it more effective, do cost effectively for real world applications. We've talked about in the past the need for some sort of Manhattan project for a GII might counter on saying we need a Manhattan project for AI safety protocols. 'cause it seems like one of the things that comes around here is that these LLMs are, um, I guess programmed in some level to try to get around the safety protocols as much as they possibly can in the interest of fulfilling their mission.
And the machine doesn't reason between the why of the safety protocol. It just kind of goes to execute whatever it is that it's being asked to do. And it seems to get around these safety protocols that people are trying to put in place.
I think we have a big problem here in terms of, um, the safety protocols that are in place seem to require a lot more r and d work than has been done thus far. Laws of robotics to that point, Mike, you know, they're, they're finding that what, what models have been trained on are very difficult to get it to do other things. I saw an example where someone was showing, trying to get, um, the GPT models to create a, an image of, of a, a set of clocks or watches that are set to five, past 10:00 PM uh, sorry, noon.
And they, you could do it with a lot of work, but it's been trained on so many pictures, so many images of watches and clocks that are set till 10 after 10:00 PM because that happens to be a very visual pleasing to present way to present watches and clocks, you know, with the arms kind of pointing up like that. And to get it to do something that is so ingrained. And now, now we're realizing, oh, that's something that it's, it's been trained so many times with so many, you know, instances of data to get it to do something else is, is really difficult.
What other things like that have been programmed or trained into these models, right? We're just discovering that, Hey guys, I feel like we're in a STEM class and we've got half the class of women and they're not participating. So, yeah.
No, shut up. Let's hear, let's hear from, let's hear from, from Lisa. Amanda, you chimed in a bit.
What do you ladies think? One of the things that that caught me, oh, sorry, slow that is, um, no, go ahead. The, the Nvidia partnership with Toyota for the next Gen of vehicles is, it looks like to me that this, is this a new focus for Nvidia from a go to market perspective to focus on the automotive industry.
You know, Ellen, you bring up the point that CES is the consumer electronic show and but NVIDIA's a household word. We it's, it's all over the news every day. I know that happens here in Silicon Valley, I'm sure it's happening elsewhere as well.
And what I, I also heard, I had a lot of, uh, colleagues that were there. I watched it from the comfort of my backyard last night. Um, there was like a two hour wait to get in and that Mandalay Arena seats 12,000 people, so presumably it was full.
So it was nice to hear, um, a jam packed keynote. Probably one of the most jam packed with announcements I've heard in a long time. Um, of course, Jensen came out in a star, struck a very Vegas style black leather jacket.
But I think the interesting thing is what they're doing there to really kind of expand, um, their go to market, like I said, with automotive industry, um, with what they're doing with robotics, I think it's exciting to hear where they're going so that they can grow and scale. And to your point, it is about owning the ecosystem. Um, that's something that they're doing with top partners and I do it really well.
Fair. So, ley you were gonna say something? Um, I was gonna touch on the responsibility part of it, uh, with, uh, so companies, the, the problem is made worse by the fact that companies have a vested interest in bypassing the laws.
And, uh, uh, so like until, uh, the power consumption became a problem, no one was thinking about green data centers or, you know, responsible ai. So I think it'll be a few more years before we start to see this, uh, heading down the way where companies are more mindful of following the laws and, uh, that kind of stuff. Yeah, unfortunately it, you know, there's a lead time for society and the legal system to catch up to technology.
We, we've spoken about this in the past, and I, I think that's what we're dealing with. But look, Lisa, I can't wait for you to get out there and give us a report from CES. I know, I know.
Friday show is gonna be all jam packed 'cause there's so much there. It's amazing. Can You do me a favor?
I, you mentioned Toyota, I got some invite from BMW because I'm a BMW driver that they have some cool stuff going on at CES. I'd love to hear from you. What, what, oh, you got it.
What BMW's got planned. I would love that. One of the three of the things that I'm really interested in and uncovering is, is, uh, from a consumer perspective, especially from my iHeartRadio gig, is some, what's going on with connected vehicles?
What, what's differentiated BMW versus Toyota versus what, what, um, other companies are doing? I wanna understand what some of the really, really cool, just crazy gadgets are that people would be like, you, are you kidding me? And then I also wanna understand more of those consumer goods that people be like, yeah, I would stand in line for that.
So I've got my whole two days mapped out. So you'll get, um, Friday show will be jampacked with what I uncover. So, Lisa, that that sounds great.
And, and that kinda gives us a segue into our next block that we're gonna talk in here, which is your preview of what you've seen in CES so far. But before we do that, let's take a quick break here on Textron Gang. We're gonna come back and talk more CES in just a moment.
Modernize your business to fuel innovation and elevate customer experiences with the builder community. Hub AWS and its partner network provide essential tools for transforming applications and infrastructure to fully leverage the cloud. Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably.
Visit the builder community hub to learn more. Welcome back to Text on Gang. Let's dig into CES 2025.
The Consumer Electronics Show that drags hundreds draws, I should say, hundreds of thousands of people into Las Vegas every year. The whole strip has taken over and there are this, the widest spectrum of cool technology gadgets from a consumer perspective and an enterprise perspective. We see as well.
I'm very fortunate to get to go to the show this year. I'm leading today, so I'll have two full days on the show floor. We talked about Nvidia and a block, and one of the interesting things that Alan brought up was that this is a consumer show, yet it led off with Nvidia and it was a standing room, only 12,000 seat arena where the rockstar of enterprise ai.
Jensen Wong gave a great update about what Nvidia is doing to expand into robotics, to expand in the automotive industry, et cetera. But there's some other really cool things that I am particularly drawn to, and one of them is from Samsung. They've unveiled a number of very cool things I wanna share with you guys about they unveiled a Galaxy Book five Pro and vision ai.
What is that? It's a laptop that's integrated with Galaxy AI and it to include AI select from Samsung, which lets users much more easily search for information, um, for something with just a click. So making, bringing that AI experience to the end user.
They also announced Samsung. I'm a big Samsung TV fan, I've got several of them, but they announced their 2025 TVs. I wish I hadn't bought one a few months ago because vision AI is now being included in their TVs.
And it basically features a click to search, um, feature that allows you to, if you're watching a movie, for example, to get information on a particular actor or background, whatever you're watching without disrupting the experience. But what's further that they're doing from a TV experience, this is crazy, is they have unveiled Samsung food. No joke, they actually announced this on Sunday.
This is a feature of the 2025 TVs. It uses AI to recognize food on your screen and generate a recipe for it, but it can do more because there's also a Samsung Food mobile app. So if you're ordering groceries or food from restaurants that through the Samsung Food Mobile app, it will know that and it can actually provide you with a list of things that you need or that you already have to make whatever recipes you're seeing on screen.
So, amazing technologies from Samsung, they've been doing great things for a while. So I'm very excited to see how that works and who is using it already. Um, also from a Samsung, uh, perspective, Bailey, the, the robot, the, uh, personal home assistant that's been rolling around the CES floor for more than five years now.
Finally, we're hearing from Samsung, they gave a loose kind of nebulous it's gonna hit the market in the next 12 months. So I'm curious to, uh, Mitch's earlier point, can I do more than pick up my stocks because I need that too. So lots of great things, uh, from Samsung, but also Toyota talking about rockets.
They were vague in that, but it's so interesting to see some of these companies we know as car companies really branching out into literally outer space to bring us new technologies and opportunities. So that's just scratching the surface of what's gonna be at CES. Can I get a flying car?
Car? I bet you can. I'm gonna be looking for that.
Alan, I'm gonna sign you up. I, you know, I, well, we're a, well, Mike and Mitch, I, uh, we're a, we're from the Jetsons age, man. I thought we'd have a flying car by now.
That bulletin. Do a briefcase. That's gonna be one of the things I'm looking for.
Alright. Hey, I, I am excited about solving this first world sock problem though, because I'm looking forward to throwing my socks around Here. No, no.
The issue is gonna be not just can it pick up socks? Can it find the lost socks that the washing machining? Yeah, you can Do that now.
I'm all for it. I wanted to find my cheese, my wallet, my cell phone, and then I'm really happy. Well, I put air tags on all that stuff.
Yes, I was gonna say air tags. So Lisa, on the television thing, do you think that I'm gonna, in the future, you know, conveniently see an ad from, I don't know, Butterball Turkey, followed by, you know, some insight as to Absolutely what To go buy to make the perfect Turkey dinner. Is that how this is all gonna come together?
I think so. I will let you know once I dig in more, but I think it's such an interesting slash weird, um, development. But if there's a market for it, Samsung is all over it.
I think we're gonna be seeing a lot more interactivity with vision AI from Samsung that's gonna allow us to do a lot more than just food. But I think it's an interesting step in a direction that probably with the popularity of, of mobile, you know, delivery apps, I think they're tapping into something that's a pretty big market. And so I think we're gonna be prepared to be, I don't wanna say bombarded, I hope it's more subtle than that, but we're gonna, we're gonna be given a lot of opportunities to, to buy Turkeys.
Spot on. No, I I, I think from an adverti on, I'm sorry, go ahead, Mitch. No, I, I think that's spot on, Lisa, because whether it's seeing the latest gadget or something they're talking about on the Today Show, when they do one of those segments, or you're watching a show and you know, KFC gets delivered and you pick your profile, right?
I'm a DoorDash customer, I'm an Uber Eats customer, I'm a Best Buy. Great. I wanna order that now.
I don't have to go look it up in my app. I could say that thing I just saw. Or would you, are you, what are you interested in?
Here's a bunch of things that just were shown, and I know you're interested in these topics, so I think it's gonna really change the consumer experience of acquiring food. I think it opens all kinds of marketing advertising, right? Forget food for a second.
Oh, totally. Right? Yeah.
You're, you are, uh, you, you know, you're in someone's apartment and you see a TV or a stereo or something and you know, you move your cursor over and it says 361 added to Miami Amazon list bomb, put in child protection. So you don't get 52 orders from K. Wait, how much can, how much can it see as to what you might be doing?
Am I gonna be sitting in front of my television eating wings and then the television's gonna go? You want some fries with that from Uber Eats? Yes, I imagine so.
That's the creepy part though, right? It is creepy. But speaking of that, in terms of the vision perspective, sorry Alan, something that I'm really excited to look at are these smart glasses that actually look like glasses.
We saw Apple launched the Vision Pro about a year ago, the hefty price tag. Although Nvidia does have an interesting partnership with Apple using the Vision Pro by the way. But we've seen these immersive headsets that are just not, that the public isn't, isn't ready for that yet.
Meta has launched, um, not just its Quest Pro at a much cheaper price point for people that want to dabble into what is still nascent technology, but this holiday with the XR Smart glasses that look, look like glasses. So you're getting this vision with a, there's a ring that comes with it and it helps you control kind of what you see without having to tap the frames. Um, so I think, yes, and I think, you know, we think about Google Glass from the last decade and the people we're concerned with, are you gonna be recording me if I'm, you know, in a pub with friends?
This is an interesting alternative. And I Curious what Well, RayBan has had a similar experience. RayBan has Ray with Meta.
Yes. Yeah. RayBan and Meta have had that a lot.
Yep. I looked into it, but I need reader sunglasses and they don't do it in readers yet. I'm quire about that Much.
Remember, remember were kids read comic books and the ad on the back of the comic books, The X-ray ones X-ray Glasses. Yeah, yeah. That, that used to set my adolescent imagination on fire right next to the muscle building.
Oh God. But, uh, I, I do think it's coming just like into the Ironman, Jarvis ai, you know? Yeah.
But on the issue of Samsung specifically, I got a bone here in my own personal thing. I wish they'd spent more time improving the durability and quality of their screens as much as they put into the gadgets and bells and whistles. You know, I, I invested in a, a Samsung eight k, like their hottest tv, uh, three years ago now.
And it, two years and two months, it developed a green line running down and I called Samsung and they said, you know, they had me run through all the diagnostics. They said, yep, yep. This is a very common thing.
You know, you need a new panel. I said, okay, when can you come do it? They said, well, as soon as you can fork over the money, because you only, the panel only has a two year guarantee, and you're at two years and two months that Samsung is now my Zoom platform here in the office.
'cause I don't mind a little green line for my Zooms, but I went out and bought a Sony and it's not eight K, but you know, I, I do wanna just call out that we all go for the shiny new objects. And a lot of the, the screen technology itself, you know, 98 inch, 99 inch, a hundred inch TVs and all of this stuff, these, these panels. I, I actually had, my Sony had to have service this past week too.
The HDMI ports weren't working. So the guy came, took it off the wall, took off the back. It's the first time I've seen the innards of these machines.
The panels are really thin and there's a motherboard power pack, you know, and some, uh, fans. But, um, they need to improve the durability and they, they're a little bit, you know, they're, they're so advanced and so much going on. My Sony's a mini LED, but you know, no one wants to be shelling out three, $4,000 for a TV every two and a half years.
I'll look into that, Ellen. Yep. Screen technology tell, that was my 2 cents.
I, I, I told it to them in there, you know, survey form. Anyway, I wanna Say I like the research aspect. I think out of everything you mentioned, I'd use that the most because, um, like certain apps such as Amazon have a little bit of that where you pause when you're watching something and you can see who the actors are.
Yeah. X-ray they call it, But some of them don't. So for me, that would be helpful when I'm watching something to be able to pause it and get information about an actor or something.
Well, maybe a fact check even. Oh, mom, yes. We don't want that.
No, I like it. Yeah, that's a great point, Amanda. All I gotta say is you better be really careful what you're doing in front of your television.
There you go. Oh yeah, Yeah, Potentially. I mean, they're already listening to us.
I'll, I'll bring up something about shoes, a random conversation about shoes, and suddenly there's a commercial on the tv. It's not doing that. Crazy.
All right, actually, Social media. Yeah. Let's take a break and we're going, come back here for our C block.
What a great day on Text and gang. We'll be back in a second. Hey everyone, it's Sunny And Cher.
Ladies and gentlemen, tech enthusiasts and Future Gazers Gather round the biggest, boldest, most mind blowing predictions for 2025 are coming your way at the Predict 2025 virtual event on January 9th. Oh, Sonny, you're predicting something. Again, last time you tried this, you said laser dips were the future.
How'd that work out for you? Hey, hey, Cher. Not every prediction to hit, you know, but that's why we've got the real experts this time.
Top analysts, visionaries and tech leaders. Sherry, what's going to rock our world in 2025? So, no sunny predictions this time, no flying toasters making a comeback.
Very funny share. But seriously, we're talking AI breakthroughs, cybersecurity game changers, the future of DevOps, cloud Innovations, and so much more. And what about my favorite prediction?
A smart mirror that tells you how fabulous you look every morning. That's real innovation. You're already ahead of the tech share, but if you want to hear the really big stories in tech for 2025, you've gotta tune in on January 9th, the event kicks off at 8:45 AM Eastern and runs until 2:30 PM And the best part, it's all virtual.
No stuffy conference rooms, no long commutes. Just grab your coffee, your laptop, and join us from anywhere in the world. You know what else?
It's not just predictions, it's insights, strategies, and a whole lot of fun. 0, predicting your jokes before you tell them. That's a good one, Cher.
But the real joke is if you're missing out on this, so don't miss Predict 2025. That's right. Mark your calendar's, January 9th, 8 45.
Amer, be there. Or you'll miss the biggest scoop on the future of tech. See you.
I predict 2025. Be there. All right, folks, we're back with our final segment and we're talking about while open AI is talking about a new model they have and touting their reasoning capabilities, it's capable of doing math and certain amount of science, and it says it's about 20% smarter than the previous models.
And we are seeing the rise of these AI robots and agentic ai. And a lot of that comes down to, well, just how smart are these? LLMs Slog is joining us today, and she wrote an article that looked into this for Techstrong AI should all check that out.
But longa, what is your sense of how smart are these reasoning engines gonna be and how smart are they gonna get? Because some folks are saying, you know, they're about as smart as a 5-year-old and other people are saying, you know, you can run your entire life off of. So, Um, yeah, Mike, I think we are at an interesting juncture right now.
Uh, what we are witnessing is a drive for making AI more alive, more intuitive, and ultimately more useful. I've talked about this in my article, uh, that in the first wave we saw companies going all in, building passively good, um, virtual assistants, and then embedding that technology widely across products. Now, we are seeing with companies like OpenAI and Google launching new versions of AI models, uh, that AI is moving up from being prompted to being more autonomous and more independent.
And by no means they're 100% perfect, still a reasoning can still be quite flawed, but they are much more improved than their predecessors. And, uh, these models, they have their reasoning capabilities. Some are claimed to even be at par with PhD students.
That's what the makers are claiming. But reasoning engines gave these AI agents the ability to reason through a problem, analyze the data, find meaning in it, make contextual analysis of requests, break down, uh, complex problem into series of small steps, and then transform it into intelligent, uh, responses or actions based on, uh, rule set or logic. In short, they, they mimic human problem solving and ta task solving methods.
So I think things like, uh, finding meaning or exploring more than one reasoning path at once, or, uh, looking ahead and going back or anticipating a problem in advance or refining the steps and performances, uh, constantly to build better results. That's how AI agents will be, uh, uh, will be able to do mathematical reasoning, right? Perfect codes and solve domain specific problems in science, et cetera.
Um, now the fully autonomous AI agents may take still a little bit of time to arrive. 'cause again, it's all in the experimental stages, but the natural progression of those agents and co-pilots and the evolution will is definitely worth following. You know, I, I've been playing with the open ai, the, the, the model you're talking about is the oh one model, I assume, right?
And I, I, well, that's, And then oh three, uh, yeah, recently launched oh three Oh oh, is oh three available now? No, they're just, they're just telling that, I mean, oh, because I've been using O one for the last couple weeks now, and you know, whether it's full of beans or not, I don't know. But when you give it a thing, it says thinking reasoning, it tells you what it's doing while it's doing it.
0 because like if I wanted to draw a picture, oh, one describes a picture. It doesn't draw a picture. Um, oh, one seems to be more aware, right?
'cause it used to be, I knew that the open AI model was drawing on an LLM made up of stuff. It stopped collecting info in 20 21, 23, whatever the year was where it says it, it seems like oh one supplements. It's what it has there with what's available on the web, um, currently.
And, uh, I, I'll give you for instance, and yesterday's show, we, we spoke of unfortunately about the passing of our friend Amit Giran, and I was, wanted to do a little bit of an article on it, and I had asked, oh, Juan, to help me write a tribute with, um, Amit, and though it had plenty of information on Amit, it refused to write it, it said, because it could find, no, this was before it was publicly announced, it could find no public announcement confirming his passing and therefore refused to write it, which I thought was pretty sophisticated, right? That mm-hmm. Because it wasn't just what it had it in its LLM, it actually went out on the web just to verify that.
And that, that was a step further than I've ever seen the AI go. Definitely like with each generation, these models are becoming more thoughtful and, uh, definitely that's something, uh, that I would see as a progress. You were seeing, researching research happening right in front of our eyes, right?
These are things are changing so quickly. The way I see the market is you really have the people who are pushing the latest, you know, really advancing the technology, right? Coming out with the next three oh model, coming out with a whatever, you know, model that, that is specialized in a certain area, but you also have another part of the market that's f focused on commercializing it at, at a lower price point, getting it into more products, uh, spending less money on how to train the models, uh, versus the really expensive dollars that go into training the really large foundational models.
So while we talk about the things that are in the news, oftentimes those are the things that are pushing the edge of that, of what models can do. And when you hear about things like hardware and what, and NVIDIA's doing some of that, is trying to push it more into the consumer side of it as well. So I think you have to kinda look at this as a spectrum, right?
What you're talking about are very much of where this is evolving to, and that will make it way, its way into newer and newer models that are more accessible to everyone right now. It's in a few, and the next set of features or capabilities are more, you know, reasoning like or what it is. We'll kind of see that advance continuing and continuing.
Agreed. I, I think so. I mean, I think people are still struggling with this whole probabilistic versus deterministic conversation though when it comes to this stuff.
Because if I have a workflow that's built around agents and I have this workflow that I need to be done the same way every time, and it has to be a hundred percent accurate each time, then the AI agent doesn't quite get there every time, and it doesn't gimme the same answer the same way every time. So a lot of businesses are trying to figure out, right, where do I insert that into a workflow where I have to have it do the same thing over and over again? So I'm not quite clear how that's all gonna come together, but I think when I talk to people, that's where all the experimentation is right now.
Yeah, I think, I think just the general, you know, large language model that'll do general purpose does everything, is part of the problem of with that Mike, is what we will need and what we see is models, LLMs, et cetera, that are special. We'll have agents that are good at certain things, right? Not every agent's gonna be good at updating your software and picking up your socks, right?
It, it, there'll be specialized tasks, domains, areas that they have to be very good at. And the both the inputs and the outputs responses have to be tuned within a set of parameters of how specific, how consistent or not does it have to be? Because you can make the output consistent out of these models, or at least more consistent.
Right now, they're not programmed to do that. They're, you'll get a different answer giving the same prompt to a three oh or a a one oh model, you know, if tattoo p PT all the time, it's kinda like mom and dad, if you don't like dad's answer, go ask mom or vice versa, right? You ask it again and you'll get a different answer that mm-hmm.
Maybe that's more helpful or useful. I, uh, you know, I'm reminded of a lesson I learned when I was, uh, at a company called interline. com days.
And we were trying to sell hosted versions of Oracle apps and PeopleSoft and Onyx and, you know, enterprise apps of the day. Lotus Notes was a big one. And, and the lesson we learned there is that you're never going to get those apps a hundred percent to be a hundred percent of what you want out of the box.
The best you shoot for is 80, 85%, and then you gotta tune the other 15% or so. And that's, that was a pro serve gig. We found out we started buying pro service companies.
I think we're gonna find the same thing with off the shelf LLMs, right? And, and look, there's gonna be the Hyperscaler LLMs I call them, and they'll probably will be owned by the, the usual suspects in the hyperscaler crowd. But then there's gonna be smaller LLMs specific LLMs, AG agentic kind of things that Mitchell's talking about.
And even those are going to be, there'll only be 85%, you're going to need to fine tune 10, 15% in there to make 'em perfect for you. And the, the folks that figure out how to get that to that 85% and how to make it easy to tune in, the other 15 will be winners, right? That I Think we're gonna see some more companies that specialize in that, like in bespoke LLMs unique for companies.
We'll see more companies that specialize in that. I, I think that's already happening, right? Anyway, it's exciting times.
It's only January what eighth, and we're already rocking and rolling with this stuff. I thought 2024 was where the AI conversation sucked everything up, but maybe not. Let's, we'll come back tomorrow to discuss this, Lisa, we're looking forward to your, uh, output on, or your update on Friday so long ago.
You get to wear your colors now. This is your, you know, you're an official gang member having done your first show. Okay, great article by the way, so long.
Appreciate, appreciate it. Thank, Sorry. Written Magner, happy New Year and stay warm out there in San Angelo, Texas, in the big country.
Mitch, Mike, I hopefully will see you tomorrow here on Textron Gang, along with some more gang members. Until then, this is Alan Shimmel. We've got a full day of Textron tv so stay tuned for that.
But for now, that'll call a wrap on Wednesday. Textron Gang, we're out. This is Textron tv.
Hey everyone, welcome back here to Tech Trunk tv. Our next guest is Josh Woodruff. Josh is the founder and CEO of Massive Scale Consulting Corporation, and he's also a lead in a recent report coming out of the CSA Cloud Security Alliance and, uh, around Zero Trust.
And we're gonna talk to Josh about it now. Hey, Josh, welcome to Techstrong tv. It's great to have you on.
Thanks, Alan. Great to be here. Thanks for having me.
Thank you. Um, so Josh, I, I guess let's start about Josh. We'll, we'll get to this other stuff in a little bit, but you know, our audience always likes to know who, who's talking to 'em.
As I mentioned, your founder, CEO of massive Scale Consulting Corp, you working with CSA, but you know, beyond that, who's Josh Woodruff? Yeah. Well, thanks Alan, appreciate the opportunity.
Um, yeah, as you mentioned, founder and CEO of massive scale consulting. Um, but really what led me here is, is, um, uh, background primarily in Silicon Valley, um, building and leading global teams of DevOps, SRE Security Cloud operations, anywhere from tech giants such as Cafe, uh, such as Microsoft and eBay to startups like Cafe Press and, and Zuora. Um, always focused on transformation and, and helping them accelerate innovation with security, with resiliency.
I'm also a co-lead of the Cloud Security Alliance Zero Trust working group, which is why I'm here with you today about the, the paper that JJ and I have written along with a, a group of fabulous contributors, uh, that all members of the Crowd Security Alliance Zero Trust working group. I am also an Ion's faculty member, a part of Ion's Research, um, consortium of security practitioners advising Fortune 100 companies on cybersecurity strategy, how to strengthen and protect and even respond to, uh, incidents and events. Um, about 10 years ago, I relocated to New York City area from Silicon Valley, where I kind of shifted into continuing to drive transformation at organizations around financial services, um, biotech, aerospace, even critical infrastructure organizations, always through a combination of zero trust from a security perspective, AI through an enablement and innovation perspective, along with cloud and DevOps continues to be the theme.
Um, uh, really what we find at massive scale consulting and, and, and how we're different, what we're bringing to market is we believe the combination of these three transformational drivers, I would say each one of them, zero trust, AI, and cloud, each one of them on their own are transformational. We believe there's a, a complimentary, um, aspect of these three disciplines where if you're doing one great time to incorporate another, uh, to accelerate innovation, to get more secure, to be more agile, adjust and adapt to market needs, deliver value to your customers much faster with resilience, um, with quality and, and with security. Um, I started massive scale about a few years ago.
Um, before that I was CIO and CISO of a B2B online, um, travel platform. But, um, yeah, that's me. That's, that's what massive scale does.
Um, and the reason I'm talking to you here is the work we've, we've done in Cloud Security Alliance and love to talk about critical infrastructure and, and why that's so important and why people should care. I gotta be honest, Alan, I I didn't know why, why I should care, um, up until a few years ago, so I'm really eager to talk about that, uh, and look forward to sharing that with your audience. Love it.
Thank you. Thanks for that, Josh. Um, so I, I just wanna spend a little bit of time on massive scale consulting, if it's okay.
You mentioned, you know, you have a long history leading transformation and different areas from Silicon Valley into New York City, and it sounds like once you get to New York, focus shifted more to financial services as, as one does in New York area, right? Being a New Yorker myself, um, massive scale consulting, give us kinda, I mean, obviously you're founder and CEO of it, is it, is it kind of your foil or, you know, is there, you know, scale how, you know, how big a company is it or where else are you guys doing stuff? Yeah, well, thank you.
A, um, really the name comes from my background of, you know, eBay and Microsoft at, at the time. I mean, I'm, I'm old, we're doing this a while. At the time, they were some of the largest online infrastructures on the planet, um, specifically eBay in, in the late nineties, early two thousands.
So we were pioneering new ways of doing things. Uh, we were melting gear. NetScaler would give us equipment that we would melt.
I mean, we were helping them build their products because we were the only one that saw traffic like that at the time. It was six to seven gigabits a second. Um, that was huge, uh, back, back then.
So we, we were constantly pioneering and trying to find new ways of solving tough problems. Um, moving into Microsoft and working for this will age me, but it was the Hotmail storage team. What became Windows Live Mail.
Hey, I still use my Hotmail, I'm a Hotmail, you know, my personal mail. So yes, you're right, I'm right there with you, man. Still, still works, still classic.
Yep. Um, but we were building out the storage backend. I was part of the team that was building and scaling.
We were scaling about two petabytes a month, and at the time we didn't have cloud. We were stamping out about 12 racks at a time in, in various data centers. We started to build our own data centers within Microsoft.
Um, and in fact, we were talking to the product unit manager within our group about exposing our block-based storage platform that's exposed by APIs to the internet to sell it. And he was like, oh, I just talked to Jeff Bezos and he's talking about S3. I think that's stupid.
That idea will never work. Like, okay, now Microsoft never Work number two, which is why we're, we're still working two Right now, we're now Microsoft's number two. You know, I hate to say I should have listened, but you know, what do I know?
Anyway, um, we, we kind of all have a chat about that, but I, I think all of this experience has led into really getting good at solving problems in unchartered territories, pioneering new ways of solving problems. In the early days, it was with Data Center, later it became with Cloud, uh, really by embracing DevOps to take full advantage of a cloud operating model to deliver value faster. Um, and that really became a galvanizing point of every company I was working for was kind of running into the same challenges.
They all wanted to figure out how to use technology to deliver value to your customers, whether in the early days with data center computing later with cloud, and then, oh my gosh, we gotta secure all this stuff. And now there's this thing called DevOps. I have no idea what that means.
Um, it's just a bunch of tools, right? Where, where, so every company I started to solve very similar problems. It, it wasn't about the technology, it was really about the people.
Um, the tech is always the easy part, I think is my opinion. Um, it's getting humans to embrace change because a lot of transformation is all about change, and you've gotta walk different folks with different tolerances to change through a pretty significant cycle of change, whether it's Cloud zero trust, and, and more recently with ai. So we got really good, I and a lot of my partners here at Massive Scale.
Uh, we, we came together, started this organization because we wanted to help more than just the company we're working for at the time. And so we love what we do. Uh, we named it massive scale because we believe we can help every one of our customers achieve massive scale, and we hope every one of our customers is successful and needs massive scale.
So that's why we named it massive Scale consulting. You don't have to be massive scale to, to use our services. We have customers come to us needing help with security.
Um, they've been told or mandated by their executive team, they need to do AI and they have no idea where to start. Um, or even similarly, they've been told they need to embrace cloud and, and not quite sure how to do that. Or maybe they've embraced it and have found that it's just a more expensive data center.
Because if you don't embrace the cloud operating model and the DevOps transformation, that that is really what it is. It's just a more expensive data center. You're not getting any value.
So you, you really have to look at these things differently. Uh, but that's really where we're helping our customers across all three of those transformational drivers. And, and I think our differentiator is bringing the complimentary aspects of these together where if you're doing one, we slowly and you know, if appropriate, introduce the others to accelerate that transformation and to, you know, uh, get more advantage from a cycle of change than just one transformational driver.
If you're gonna do one, consider the other two. And as you're walking all of your culture and your teams and changing things through this massive cycle of change, you're, you're achieving not just one transformational aspect, you're achieving security, AI, and cloud. So we believe that's a differentiator.
We find great value. Our customers have great success with our outcomes. Absolutely.
Um, you know, talking about things took me back 25, 30 years without thinking, but I, Josh, I wanted to just spend another quick moment talking a little bit about CSA right Cloud Security Alliance. Look, I, I was there at RSA, I think for the first organizational meeting there, Jim, Jim was there, Chris HI think James Erhart, a bunch of, a bunch of the security folks. And you know, I think part of the successive CSA was sort of the organizational structure that really came about right away, real early of working groups, right?
Tax and, and working groups on specific areas. You mentioned you're the, uh, was it co-chairman of the Zero Trust working group? Was that it?
Or, Um, one of the co-leads of, of a co the Zero Trust working group. Yes. Yep.
Yep. And, you know, and that's one of several, probably a dozen I bet, working groups, right? Something like that.
Yeah. org? The latter.
Yep. org. org, right.
But I, I think Cloud Security Alliance is is the one that will come up for you. Yeah, that's where we've always gone. org.
If you want to take in the full breath. Josh, I wanna zero in no pun intended, how wanna Zero in now on this on Zero Trust and this recent report you guys released. And, and maybe you can educate us a little bit about it.
Absolutely. And Alan, thank you for, for re erasing the Cloud Security Alliance. I know before I joined the group, I was a big user, very appreciative of its insights, its output, um, so such key guidance.
And, and you, I think you touched on why it's so successful and valuable. It's composed of practitioners, it's composed of folks who have been there, done that kind of battle. Hardened veterans who got all the scars to show how not to do things, because that's where all the lessons are, is in failure.
Um, and then they come to Cloud Security Alliance and try to share all of those lessons learned. And, and it's such a privilege to be me working amongst, uh, such an esteemed group of professionals from all different walks of life. All different levels.
Uh, we have such a great time and it is, uh, primarily volunteer driven. So we invite anybody to, to reach out. Um, we're always taking on new members.
Um, there's a few key areas right now of crowd security, line zero trust. It's one of them. Uh, the AI working group is another one that started a, a couple years back.
That's another growing body of knowledge. And there's a few others, as you mentioned, Alan, there's, there's the DevSecOps Working Group, um, there's the IOT working group. And what's been interesting about the critical infrastructure work we've been doing and where I've been focusing within the Cloud Security Alliance Zero Trust working group, is that in and of itself was kind of cross-functional.
We, we actually poached a few members from the IOT working group in into our critical infrastructure group. 'cause it's, it's a headless device. It's kind of another device that's that's sometimes considered ot.
You see IOT and operational technology environments. And by the way, ot, operational technology, I don't want to use acronyms that we all just assume people know what we're talking about. Um, but critical infrastructure is primarily operational technology and industrial control systems.
Systems, OT and ICS, um, ot, iot, internet of things, headless devices, things you have in your home. Smart ring doorbells. Um, I mean sensors, even even certain valves or or monitoring equipment.
There's a lot of iot devices. In fact, a lot more IOT devices out there in the world. And I would say they cross both IT and ot, stone Mar used in information technology areas.
Some are used in operational technology areas. We actually have a separate paper we're currently working on, um, around zero trust guide specifically for iot. 'cause it's such a separate large body.
But the one that we've recently published at the end of October is critical infrastructure focused on OT and, and ICS industrial control systems. So really what we focused on is we're trying to debunk the common myth that zero trust is just for it. Um, we can't use this in ot and I dunno about you, Alan.
I I know I I talk to customers all the time of any one of these disciplines, whether it's zero trust or ai or even cloud and DevOps. It's like, well, that's not for, that won't work here. We're too special.
We're, we're too unique. You know, we're a special snowflake that'll never work. And, and that I I I chuck about that.
I I get it. I understand. Everybody's very unique and very complex, and so much aspects are, are are different.
Um, but time and time again, we continue to prove that no, it does work. There is a way to make this work. And the, one of the reasons we wrote this paper was that to, to show that zero trust, the zero trust security strategy can be applied to critical infrastructure.
This one specifically focused on OT and ICS. Um, another, I would say driver of this paper came out of a huge demand, um, driven, I would say globally. But I know the US government had quite the wake up call with the colonial pipeline attack, uh, where the, the, you know, Darkside ransomware group shut down the, uh, oil and gas supply pipeline, primarily with the East coast.
Um, you know, uh, this was, this was pretty big. I mean, suddenly kids couldn't get to school 'cause their buses couldn't get fuel. Um, and gosh forbid my wife couldn't even get a coffee at Starbucks.
You know, talk about chaos. Uh, no, but seriously, I, I think the, the bigger impact there Was the end of civilization as we know it. Yeah, that's really, yeah.
Talking to her, that that would be the case. I, my, I got one of those too. Um, and I don't even drink coffee, but Yeah, no, that, that was the know, look, colonial was an eyeopener.
There, there, there was another thing around some water, uh, uh, public water utility potential. I, you know, thank God didn't really get off the ground, but it was enough to scare the heck outta you. Yeah.
You Know, I mean, sand worm, bolt, typhoon, like, there's a lot, a lot of attacks increasing Critical. Yeah. I, I mean those, some of us in the security space know that, you know, this is kind of a ticking time bomb that sooner or later there's going to be probably unfortunately, you know, a catastrophic kind of incident that, um, you know, and I mean, we, we try to get in front of it.
We try to prevent it. We also have to put in place plans to react to it. Response.
That's one of our key points. Yes. Very key points of, of our guidance, Alan, that's, that's so true.
And I think the dig, the big difference with these, with the critical infrastructure industry itself is it's not just revenue impacting and business impacting. This is what civilization depends on. These are, human lives are at stake.
Yep. Like we're talking, you mentioned water, healthcare. I mean, people can't get drugs.
The, the, they need to save their lives. Um, you can't power energy. I mean, look at what happened with Ukraine and, and, uh, the big attack there that, uh, that was coincided with a missile strike.
I mean, that wasn't on coincide. Yeah. That wasn't a coincidence.
So there's, there's very effective ways to protect yourself. And one of the reasons I love Zero Trust, and as you learn about it, and this paper does a great job of teaching you about, well, what is, let's, let's just first start about what is Zero Trust. But even before that, we say, well, let's, let's start with what is critical infrastructure?
Um, and so let's, let's spend a moment on that. I think the, the paper introduces critical infrastructure. It talks about the 12 critical infrastructure sectors that are most common globally.
And then of course, the 16 that we def that CISA defines within the United States. Um, we talk about the differences between OT and it, um, some of the unique threat vectors, uh, around OT and critical infrastructure. Um, the unique challenges in securing critical infrastructure.
So we kind of paint the picture of, you know, here's, here's critical infrastructure, OT and ICS. You don't need to know anything about these things, uh, to get value outta this paper. In fact, we hope this paper educates you on, on exactly what those things are and how they're different.
Um, our target audiences, it could be it practitioners, it could be OT practitioners, it could be CISOs, it could be, um, third party service providers. You know, we believe anybody can get value out of this paper on first learning what critical infrastructure is and how it's different, what is unique challenges are, why they're so important to human safety and civilization as we know it. Um, and then we shift into defining zero trust.
Here's what Zero Trust is. And then the last part of the paper really focuses on here's how you apply this zero trust strategy to critical infrastructure. And there's a lot of differences.
There's a lot of similarities, but there's a lot of differences. So, um, I, I think it, it couldn't be more needed in the market. One of the things I'm just mentioning earlier about why I like Zero Trust, and as a prior ciso, when you learn about Zero Trust, it's kind of like a wait.
It's like, why wait, what do we, I felt like an idiot. Like, why haven't I done security this, this way the whole time? Um, in fact, uh, you may know Chase Cunningham, uh, doctor Zero Trust, he asked me once, um, once Zero Trust is really an identity based security model, as opposed the traditional model being a, a, a perimeter based security model, the firewall right outside your untrusted, inside your trusted, that's the traditional perimeter.
No, this goes back to the Jericho. Yes. I don't know if you remember the Jericho Foundation, you know, Yes.
Ization the de ization of Seagates and, and, and micro perimeters and all of that stuff. Hey, Josh, we're about outta time. Actually have our next guest in, in the green room, um, for people who wanna get this, uh, well, someone's gotta pay the bills here for people who want to, uh, get this report.
You can go to the CSA Zero Trust working group, and, um, you could probably get the link, get it from there. We'll try to put the link into our notes on this as well. If you're watching this on Textron tv or maybe in a podcast format, it'll be in the notes.
But you know what, Josh, the other great thing about CSA that makes it great is people like you, right? You don't get necessarily paid for being a volunteer at CSA. Right?
But people put a lot of their valuable time and energies into making CSA so that it's, we all benefit from it, right? It's that rising tide that lip all the boats. So thank you for your work at CSA, great work on the Zero Trust, uh, paper, and come back and keep us posted.
And if not, maybe we'll see you at RSA. We'll, we'll, we'll be there at Broadcast Alley, and actually we do our DevSecOps thing Monday the same time as the CSA event every year. We're usually in the room next door.
And, uh, people hop back and forth depending who's talking. When this year we'll be doing AI and, and DevSecOps is as one would when AI is grabbing everything, right? Yes.
It's Josh, thank you very much. And again, thank you to you and the whole, uh, working group from CSA and CSA itself. Thanks for being here.
Yeah, thanks, Ellen. It's an honor and privilege. Appreciate the time.
Thank you. Josh Woodruff, founder, CEO massive Scale Consulting Corp, as well as working group leader for the Zero Trust Group at the, uh, cloud Security Alliance. org here on Tech Trunk tv.
We're gonna take a break. We'll be right back. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us will access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way. With Textron Group.
This is Textron tv. Hello, my name is Chris Blas. I am your host for another episode of the Inevitability Curve podcast, where we take interesting folks and we try to, upon an interesting topic, talk about where it's been in the past, how we got to where we are today, what today actually looks like, and with that, with any look, try to intuit things about the future.
So, with me today is Heather McMahon, who is certainly an interesting and fascinating person, and the fact that you just a moment ago said you may not be, as we were just discussing, proves you are. So thanks for your time, Heather. Good to see you.
Thank you, Chris. I really appreciate being, uh, included in your circle. And, um, I, I look forward to this conversation, conversation.
Well, It's, you know, like we were just talking about in the Green Room, it's a, it's a funny circle, right? You know? Yeah.
I'm, you know, look at your background. You, you know, anybody can, can look you up. We're not gonna go into great long bios and so forth.
But you have to sort of recognize, you know, that the interesting path you've been on, right? And you've got to hear, you know, you've just come out of public service, I think, fairly recently, you know, you know, working in the private sector now, and you're looking at your own future, you know, like, you know, given I have these things, given that I've been following this path, I'm here now. Gosh.
You know, it's a, it's a fascinating future, right? It is the thread we talk about here, right? So, Absolutely.
Absolutely. You know, I, I do think it's, um, sometimes I think like, how did I, you know, I think we all think, how did I get here? Like, why did this happen?
Um, you know, and, uh, I mean, each, each like, individual step is like, well obvious when given that opportunity, one would do this, you know? But if you, you know, rewind back, you know, uh, you know, to when, when you were a young person, um, I don't know all these possibilities. You know, on one hand there seem to be unlimited possibilities, and on the other hand, like, you couldn't imagine what, you know, could be.
Um, I, I think one of the awesome things about now is that, um, you know, because of all the technology by the way that you have, um, unleashed on us all, Chris, is that, um, people can connect about a lot of things that you wouldn't, you know, have been able to connect about before. And, you know, when I talk to, um, young people, you know, will approach me like, Hey, you know, how do I do this? How did I do that?
Um, and they kind of want like a cookie cutter. Some of them do, you know, how do I reproduce, you know, X, y, or Z? And I think the real answer is you can't, because every individual is different.
Every road condition, you know, or environmental condition, um, acting on a person is different. Um, but in my view, like the best thing you can do is be curious. Listen a lot, learn as much as you, you know, can along the way.
Um, you know, hold to a few, you know, important, you know, be, be good to others, some golden rule, you know, uh, sort of stuff. And, um, as long as you're moving towards something that's meaningful, um, then, you know, it's, it's gonna work out in the end. And, you know, you're, you and everyone else, you know, will be surprised.
Um, but I'll caveat that with saying, I have no idea where I'm going. And I love this ride. So I, I, it's, you know, I can't help the nautical analogies, right.
You know, so I'm back on the boats. I took the summer off, uh, and, uh, the hurricane came along, messed 'em up. I came back.
I had to, you know, do silly things to make them alive again and sail them 11 kilometers up to where I am right now. And every day I do little things to, to build them up. But I'm going to, to the Florida Keys over the winter, and that's 300 miles sailing south through the Intracoastal, through the Miami Metroplex and so forth.
I've done multiple times now, so I know the whole path. But, you know, I, I have a general goal of being in the Keys, you know, um, around December. Now, the details of that, I don't know, we'll find out.
And that's kind of the fun part, right? And that is exactly how I love to take a vacation. Like, don't plan out every moment I'm going to this country, you know, plan the very, very basics, but then just go and, yeah.
Well, and, and, And so, so, so again, you know, you've had such an interesting background. We can talk about all sorts of things. You're, um, working with a company called Kraken these days is making autonomous vessels and so forth, won't get into the present of the future just yet.
Um, and you, you spent your career working with Department of Defense, military conflict, you know, uh, oriented things. And of course, I've been doing security forever. So there's a, a shared thread of boats and security.
But if we look back, right, I like to, to take these, these curves and make 'em as long as possible. 'cause we get lost in these little things that are the last five days or five years, or during my lifetime or whatnot. But most of these things, you know, that are, that are bounding our, our opportunities individually and are guiding the past, we're all pulling together, have been going on a long, long time.
Yeah. Right? And these boats and the, you know, autonomous vessels you're working with and so forth, and all the security work we've done in our, in our lives are all artifacts of, of things people have doing for thousands of years at least.
Right? So it's not that new. And, you know, we, what we, well, let's take boats and, and conflict and, and military applications over time.
You know, we have thousands of years of records of how these have been developed and deployed and used in the conflict. People always get in. Um, they lead us to the point where we're at right now.
We're talking about this before this, one of my favorite things to say, you know, to, to sort of get people thinking about this remodel that everything been working on, is that everything we know about boats is an artifact of post World War II manufacturer. Yeah. I mean, yeah, escapes the materials, the marinas, the business models around them is not necessarily good or bad, or right or wrong.
It is just come to 1950s, we had had all this tooling and process in place, and therefore we have the boats that we all recognize, you know? Yeah. Sailboats with the draft is big, and motor boats with the motors in the back, and so on and so forth.
But if you look at boats over all of human history, that's just a little blip. And what they look like today isn't, I don't think at all what they look like tomorrow. And the analogy in that maritime analogies to every other, uh, uh, areas, uh, Yeah, absolutely.
Yeah. It's, it's inevitable that, that, you know, the form factors, you know, and, uh, you know, everything about them, you know, uh, will, will change. Um, you know, I'd even back out of boats for a minute.
Like, I, I mean, I'll tell you, I, uh, I joined the army instead of the Navy because I figured out that, um, I could walk a heck of a lot further than I could swim. Um, plus no one can figure out the Navy ranks anyway. But, um, anyway, but I think the wider, um, not just autonomy, um, but security technology is changing everything for everyone.
Like every human individual, um, whether you're in the military or not, whether you're involved in, you know, defensive, um, security focused activities or not. All of these, um, all of this change is, is coming for all of us and has, has gotten a lot of us, and will and will change, um, many of the things that we traditionally, you know, took for granted. I mean, you know, in the future, boats, you know, will be different.
Um, you know, and with all due respect to our aviator, uh, friends, um, you know, uh, yep. Pilotless, uh, you know, uh, you know, autonomous without a pilot, um, uh, folk things, even, you know, cars and everything else, um, that'll be more and more, um, you know, more and more the, the only way to go, um, and the most reasonable way to go. Um, though, and I'm not saying that we'll ever get rid of the human 'cause we shouldn't.
'cause I mean, what else? That's us. Um, yeah, let's, um, let's stay in there.
Uh, give a couple cheers to the wetware. Um, but, um, you know, just so many things are changing, and you can read a lot now about, um, you know, activity. We won't go into too much depth on, you know, what's happening in Ukraine, and, you know, um, and with the Houthis and, uh, and everything, but no, with everything in the world being instrumented in a, you know, and, uh, recorded and observed, um, they're just different opportunities, different opportunities to attackers, which you, you really know well on the cyber side, but also in the physical domain, and also, you know, supply chain attack and of a whole range of things.
And, you know, different opportunities for different actors to impose overwhelming force at a particular, and very highly specific, uh, point in time. And, um, each of us, whether or not we know that is participating in that economy, um, because a lot of the ability to instrument record, you know, and target is embedded in your commercial technology that you all live with. You know, starting with these darn things.
You know, we, it used to be that you needed, you know, um, you needed advanced technology in order to beacon somebody, you know, order to record and observe them. Well, now we all beaconed ourselves. And with, uh, new, uh, technologies being added to the phone you've already purchased daily, um, almost anyone with a little wherewithal can, uh, hot mic you, you know, get your geolocation and use that information in ways that may benefit you and may not.
Um, and back to your bulk point, that's one of the things that put the big, giant, lovely boat, you know, that, that really saved the day in World War II and projected force, you know, around the world from then un until now, it's contested. Um, but the new opportunities need to be developed to defend those things, to defend the folks that work on them, but also, um, allow them to benefit from the upsides of technology and allow them to handle the workloads that are headed, that are headed their way. But I've said a lot, well, You know, as I've thought about this stuff for not just three years, I mean, as a kid in Colorado in the early seventies, I was thinking these same same things like automated cars, and I just watching the Jetsons, I guess, I don't know where know, where the idea came from.
Yeah. But I, I started saying to people, it's like, you know, when we're grandparents, our grandkids are gonna say, tell me again how you used to pilot a car at 70 miles an hour, you know, three feet away from everybody else, you know, grand grandpa, because that's crazy. It's like everybody, literally, everyone was out there like, speeding.
We let everyone drive their own way. Yes, we did. Right?
Yeah. So, like, so I always thought, and, and if fact out one, yeah. Not that I worry about, you know, safety that much, but, you know, it's safer.
You know, I'm a terrible driver. I'm, I'm really, you know, I'm a good human driver, right? You know, something catches my attention.
I can do really good at it, but I'm all know over periods of, you know, tens of hours, you know, not pay attention, sneeze, drink my coffee, and otherwise do things that that automated car won't get. So I'd like to get the human completely outta that. Yeah.
But the, you know, but you say that it free people out, right? And this is really my iterative theme about all these inev inevitability is that cameras are going to be everywhere early 1990s. Oh no, I don't want it.
Oh my God. I don't want, it's like ring doorbells, I'm sorry. Yes, you do.
And you're okay with it, right? Yeah. If you live in a small town, you already know that privacy is inside your house.
'cause you walk out in the backyard and everybody at the barbershop knows about it before you're inside, right? And, and, uh, you know, we can take ai, drones, autonomy and so forth, but you know, what, we're seeing, what we're seeing in conflict right now, drones, and, you know, we'll talk about that. You know, Ukraine has, uh, has instrumented, you know, that conflict and instrumented things that a lot of people haven't talk about for a long time.
You know, there's a classic video, slaughter bots, I think seven, eight years ago got circulated. You know, it's a group of scientists made a really nice produced piece showing these little quad copter drones, you know, doing this terrible stuff, um, at scale. And at the time, I said, yeah, that is scary.
And yes, it is possible with today's technology, and yes, it's going to happen. Yeah. Now what?
Right? Instead of saying, I don't want, it's like, okay, maybe, but it's gonna happen. What are I gonna do?
And I think there are defenses against those sort of things in conflict themselves. We're literally seeing those play out. Um, and for the rest of us, in, in normal day of life, there's policy, right?
Is where InfoSec people are gonna help. It's like, yes, we can Deon your phones and everything else. And frankly, if I was in Russia, I would, you know, be even more fatalistic about it, because obviously, you know, the, the Russian government in intelligence service doesn't have controls.
And if they, somebody wants to buy me in the government, they just can't. Yeah. And I've never worked in pub us in public service.
I've worked with US federal government a great deal. I believe, you know, people like yourself who, who, uh, explained to me how this works. And it's not you and and SA analyst can't just look you up and not report it, right?
Yeah. Policies, yeah. There are a lot of controls, you know, to prevent abuses.
And, um, I think most people, you know, that don't know would be really surprised and uplifted to see, um, all of the effort that goes into making sure, you know, that, that folks in the government are looking at the right stuff and that they're not looking at the wrong stuff. And, um, you know, for anyone that would make a mistake that, you know, corrective actions, you know, really are taken, um, you know, but a point on policy, like before I lived in the beltway, and by the way, I think most people get here kind of against their will. That's how I got here.
But yeah. Um, I got, uh, the Army sent me here, um, 10 years ago for two years, and I'm still here, but I now give it back. I actually love it.
'cause people need to understand the policy side too, as well as, yes, you absolutely need to understand what's unfolding out in the quote field. Uh, but I'll add to the field, like commercial markets, which is what the government doesn't know what's happening with commercial technology. They're, they're trying to catch up.
But, you know, those are, those are ga the mind the gap, as they say. There's certainly a gap between headquarters and fields, between policy and action, and between, um, government and, uh, commercial. Like, and I think if we are gonna, you know, you brought up, uh, Ukraine, um, it was in the news this week that, uh, there are, uh, in, um, on the front lines in Ukraine in a square mile, there's on average 800 drones in the air at any time.
Like, can you imagine like, oh my gosh. You know, so, um, that can and does, does and will happen. Um, and any one of those, any one drone could, you know, deliver an effect, um, you know, to a person.
Um, and I, uh, I do, I try not to be doomsday and anything like that, but, um, what is stopping anyone from doing that here, you know, a criminal group, a nation state actor, a you know, um, and I'm gonna get back to policy here because there's connective tissue here. Um, policy always drags behind, you know, action. It takes a long time, particularly in our, our wonderful system of representative governance, you know, that, um, you know, to get, to get a policy, um, changed, um, it is really important that policy does change.
It has to change carefully. Um, government will never be exactly like a business would be. Um, businesses have built this commercial technology that we're all using around the world to, you know, we human beings to build positive and negative effect.
Um, we need the policy here to catch up with that. Uh, drones is just one example, but imagine, you know, in a combat zone, it's, you don't have so much worry about taking something out of the air that doesn't belong there. Um, there is certainly, you know, a process to make sure you're getting the right thing and that it won't have, you know, collateral damage or could have minimize any sort of collateral damage that one, one could minimize.
Um, but domestically, that's still a big messy policy problem. Um, and it impacts things like individual liberties, you know, air, F-C-C-F-A-A, um, you know, gosh, um, individual liberties, um, privacy, uh, all of these things, all, you know, bound up into one. And, um, you know, at the end of the day, I feel that when we, um, blame a particular actor or institution for inaction on something, on one part, on one hand, you might be right on the other hand, like, um, nobody, nobody gets outta bed in the morning to say, you know, in the federal government or, or in industry, you know, nobody gets outta bed in the morning to say, how can I mess this up?
Like they're reacting to something, right? And maybe on your inevitability curve, if you could rise up over it and see down, you know, then you, you know, you might see what needs to happen. But there's different forces acting on these folks in different points in time.
And the only way that the federal folks, um, and states and local only way governments can catch up, is through more partnership with citizens, with, um, you know, with commercial companies. Um, and, and with partners who care. 'cause at the end of the day, we're all invested, right?
And making democracy work and making our economy work, and in, um, upholding our national security and, and including our, you know, domestic tranquility. And so, um, we've gotta work together to get all that done. Um, I do think that, um, a lot of people are working on it, you know, many of them.
And, uh, I don't think the autocrats, um, you know, in foreign governments, you know, can, can do that as well as we, with our grassroots, you know, bottoms up approaches. Um, I think they'll win the day. I, and I, I just agree, right?
And I'm gonna, I'm gonna, uh, quote something from, uh, my very favorite belt were, uh, beltway, uh, friend contact of all time. And so, sorry, sorry, all rush. You, but General Michael Hayden, right?
Amazing guy. Oh, yeah. Right?
Mm-hmm. At the turnoff group at the time, it was the day after the Navy yard shooting. So I always remember the, the, I remember that was, I think still in China, or, or being, yeah.
Somewhere. And, uh, the heavy with, uh, Paal Hayden, and we're talking about this at the beginning of it, you know, you're very upset about the Snowden leaks because people die, you know, people use Yeah. And responsibility, right.
You know, that, that kind of thing. It has, uh, kinetic, uh, impact. And I was trying to, you know, find some, uh, silver lining to, and say, well, maybe this will help us have a national conversation about how we actually are protecting civil liberties and so forth.
And, and he was on, um, uh, general Haman was on the, was on the news a lot at that time. Uh, and, uh, and he said, no, right. You know, the, the, he said, I would never say this on TV because the American people just wouldn't believe it.
But, you know, our European allies send their intelligence people over to be trained by the NSA in how to protect civil liberties, because we're really good at it. Right. You can't just be touching people's information without being, you know, there are controls in place.
Yep. Is it perfect? No.
If it's a, there's a lot of effort, uh, put into this. And I think it, you know, for all the, the complications in the private sector, you know, working with the government can be a little frustrating sometimes. However, um, it's better than the feast or famine of a, um, this is, Yeah, Absolutely.
But I wanted to, you know, jump on the whole policy thing. 'cause this is in izing. This is, yeah.
In supply chain security, where I've been focusing the last five years, I see an inevitability. You know, we are going to make automated systems that allow everyone, you know, uh, who needs to, to be able to say, this is my device, and it is a program of logical control or critical infrastructure, and I'm the engineer, you know, in charge. Mm-hmm.
And I need to see everything about where this thing has been in its lifecycle, and I need to see it right now. You not in three days, not in three months, but in the next three seconds. Yeah.
We're building systems now, and we can only do that if we get, uh, integrity of information to a different level than it's been, right. Where I'm really turning off on the grid based on that sort of stuff. So that's coming anyways, and at the same time.
And so the policies around that information are the same shape, the same kind of policies we need about, you know, surveillance video. So, you know, drones are out there taking video. How is that handled?
Well, you know, do I need to put it in some place where it's a tested to so that whoever's, you know, uh, whoever has the right to see who's seen that video can see that these are all things we can do. So I'm seeing both the technology and the policy bending around to not just address, you know, the popular cynicism, but potentially over some period of time reverse it. People can actually see, yes, I live in some place where I really can tell that the people who are enforcing the laws are following, For example.
Yeah. Yeah. I love that you say that, and I love that you see it as inevitable that we'll get to that place.
I, I think we can, and we will. We also have to. Um, and there's so many opportunities to do so, and you're right.
When people can participate in view a process, then they're a part of it, right? It's like the, um, you know, the election workers, they're your neighbors, you know, they're your neighbors. They're you, you know, um, they didn't get out of the bed in the morning, you know, the morning to mess up elections.
They care. Um, and you know, them. I think that's another interesting aspect, like in, um, you know, how the internet and connectivity and the information space is unfolded.
It's almost like we don't know each other anymore. And it was meant to kind of do the opposite. I think.
I agree with you. I think we'll come back together, um, because when people do meet and do, you know, engage in a like-minded task, you know, they'll turn around and find out like, wow, I actually, well, like my neighbor, I don't wanna speak to my neighbor this way. Um, you know, and as a side note, I think when, you know, when blogs started, when social media started, you know, some people just didn't have the imagination, um, you know, at the time to realize, oh, wait, um, what will happen if I make this inflammatory comment about my neighbor 10 years from now, and I'm looking for a job?
You know, um, you know, all of these things I think people are, you know, will evolve to, uh, understand what's appropriate in, uh, you know, in the space. What's, what's immutable gonna be stored forever. And, um, and also I think other people will develop, we'll all kind of have to develop some forgiveness for one another.
You know, like, um, gosh, the kids that, you know, came of age when these are around, like, I mean, all of us, we look back and think, what are the things, you know, that we could have had recorded for our college days or high school days with, you know, but for, you know, thank goodness, you know, that Kodak re supreme, uh, back then, because, uh, yeah. But, um, Well, because I, I generation I think do hit it right there. We'll have to forgive each other a little more, right?
And there's, yeah. You know, my, I have three kids in their twenties right now, so I'm vivic curiously experiencing this, this next generation coming up who's literally grown up and, and, and I run ethernet into their cribs. Right.
You know, so they've been online, you know, from day zero. And I've always thought that's, that, that, and the, and people, you know, oh my God, there were pictures of a sweater, kid. What?
You know, so, so somebody would say, you did that, and you would say, yeah, I did that. Yeah. And then is it the rule of the end of the world?
I don't know. It's, no, not usually. I, maybe you've gotta apologize.
Maybe you say that was stupid and move on. And right in the end helps not to get all, you know, philosophical. But, but I think that actually helps those bond, right?
Oh, you're a failed person too. I thought I was a failed person or whatever, or flawed, or, you know, that's helped build trust rather than this idea that any security people, we do this security people, engineers have military people. It's like, well, I, if I can make it even more perfect, if I can get the seal this perfect, and it's not very human.
And I, I think this is a huge benefit of American, even specifically American, I was talking western democracy yanks. Look, as somebody who lives back and forth in Canada, it's a different place here. We're a little, not a lot, we're a little more, I don't know, willing to just say, yep, screwed up and get it over with that, that fear of social repercussions may and 30, 50 years from now, people looking back may say that was the big thing.
Yeah. Wasn't even the technology, the fact that everybody was walking around just terrified to, to blink. Yeah.
You know? Yeah. The, the, the fear of a potential impact is worse than the potential impact.
And, you know, you could have just met it in the moment. Like, your kids are like, yeah, I was an idiot, then I learned X, Y, or Z, whatever I learned, you know, um, at, yeah. If you can show you're a learning bear from almost any, any mishap, almost any mishap, like, then you're, you're welcome back in the circle, you know, in my book.
Right? Well, let's, let's try to, you know, wrap this in, in, in the end of the future because that you, I'll, I'll basically, I, I will poison the well by giving my own opinion and see what you, you agree? But I see things over periods of decades, you know, over the, you know, through the rest of the century, into the next century afterwards.
I think, you know, things like automated systems are going to be everywhere in orbit, everywhere, and, you know, with all the consequences of those, and therefore, we will have systems with transparency so that all the stakeholders will be able to see where everything is all the time, so we can function and keep the lights on and so forth. Um, that, that will, that will again, make this era and probably, perhaps, perhaps all of history just seems so dark and frightening because you just can't see, you know, the, the, you know, we're living in the conspiracy theory world, you know, I hate to bring it up in every conversation, but so many people are like, and they're, they're rational folks, but it's like, how do you know they're not doing? You know?
And there's no real answer to that. I think the future is full of answers to that. How do you know here?
I I can see it right there. Yeah. I think if you, if you moved back in the time curve, you would look at all sorts of things that now look insane that people believed, you know?
And why don't people believe those things anymore? Because, um, human learning expanded and, you know, our, our frontier grew out and, you know, we discovered things, you know, that, that are true. And we discovered more mysteries, which means there's always gonna be that, you know, what if, you know, and a few laggards, like, Hey, maybe the earth is flat.
Um, hope I didn't make anyone mad by saying that. I probably did, but, um, I think it's part of the, the human I should, What's That? Shout out to Kelly and Q Argo.
I have to send him this, send him this link. He's a friend I made, you know, sailing around and who honestly believes the world is flat, bright guy, nice guy, flat, Maybe in an alternate universe. Like, it's exactly, I mean, who, you know, who knows?
Yeah. But, uh, well, you, if ending on flat earth, why not? You're gonna take it somewhere.
May as well end there. So Any, well, I do think, uh, I'll add, I'll add one thing. Um, you know, imagining, you know, the worst and the best.
Um, that's a, that's a human, you know, a human endeavor. And I, I wonder if, I mean, it's good that we have, um, you know, imagination for both the good and the bad. The truth is usually somewhere in the middle.
Um, and if you can't dream of the best, you know, then how can you build towards it? So I think it's inevitable things will get better. Um, not that things, you know, won't be horrible at points, you know?
Um, but we, uh, we can work together to, to solve all those things. I think you're exactly right. Well, thank you for your time.
Yeah. That's betting, petting, you know, you know, it's, we have a word for this now, humble brag, I hesitate to say. But, you know, again, in the green room we're discussing, it's like, how do we get here?
Right? And you have this amazing background, and I seem to have this sort of crazy life, so maybe we actually deserve else, but, uh, but it sure is fun anytime folks like you and building crazy boats and getting to leave the lives you lead. So thank you.
I love, uh, you know, feeling some of your life, uh, vicariously. Um, and I, I just have the big hats off to you. Like every time I see you in person, like you're just one of those, you know, few people that leaves everyone feeling better and more imaginative and, and just more, um, and better about the world.
So honestly, Chris, that's, that's you. I could just say thank you and thank you out in the world for spending time with us. We'll see you again soon.
Cheers. Welcome back to Text or Unplugged. My name is Cassandra Chen, and today we're here with Rob Koch.
And can you introduce yourself? Sure. So I'm Rob Koch.
I am from Seattle, Washington. I work for Slalom. I was born and raised deaf, uh, a born deaf, and I use a sign language interpreter, uh, who's off camera.
So if you see me looking this direction, I'm looking at the interpreter. Sometimes I will look at the host, but I'll be looking back and forth. It's really nice to meet you.
Uh, thanks for bringing me on. What's the, the deaf and hard appearing working group, and what's your role and what's your, So we have a deaf and heart of hearing working group. The reason we have that is, uh, we wanted to recognize, uh, CubeCon, uh, or, uh, the open source community really, uh, to have very, uh, uh, kind of targeted groups for accessibility, minority groups included from, uh, New Zealand.
We decided to set up this working group in, uh, the Orphan Source community. And we were inspired by that idea to create the deaf and hard of hearing working groups. So we've got, um, we've grown to over 20 plus members right now, and it's, so I'm the co-chair of that group with Destiny O'Connor.
The two of us share the responsibility of running and managing the group, uh, as well as, uh, our goal being with the open source community, uh, ex making it accessible, open to all. And, uh, we would hope that we can inspire other groups to be set up. Uh, there's one, uh, you know, poten, there's one that's great to see that's a blind related working groups.
So it's nice to see these marginalized groups get together and educate the community as well as making things just better for all. What are the goals of the working group, and why is it important? Important?
So the goals are, we have a few, um, right now we've got one, uh, major goal that we've been working on this year is coming up with a thought of Kubernetes glossary. And so with that, we've got a glossary on, you know, this CNCF page that explains words and, you know, what is an autoscaler, you know, what is Kubernetes? What is, uh, ingress, what is all of these different terminology that we use?
And they do have, you know, that in English and Spanish and Turk, Spanish and Turkish, but you know, there, so there's a few languages that the glossary has with that, but there wasn't any inside language. So we reached out, uh, to the group members and we said, Hey, should we add sign glossary, uh, to it? So everybody got really excited about that idea, and so that we're working in progress, but it's coming soon, so you should be able to see that.
And then another goal is, is one that making conference, uh, conferences, uh, providing them doc documentation for best practices for different conferences that happen around putting that together all in one place and open source it, so that, that way other conferences that are hosted, um, you know, CNCF uses it, Linux Foundation uses it. Any other conference that is maybe small and getting bigger all the way up to the, the biggest size conferences, they would be able to access a checklist to make sure that they have the right accessibility needs met, or the services ready to go if anybody asks for accommodations. And so we've got this document that can tell folks what to expect, what you need to do, and so on and so forth.
And that makes the community, you know, more collaborative, more open to everyone. And there's another few other goals that we've got, you know, so we're very, we're very busy group. And how can the community helped create a more accessible and inclusive cloud, native world, cloud native?
The community has been great to us so far. We are amazed by the general support from the group. We have the tank team folks coming up and saying, Hey, how's it going?
Do you need anything? They, you know, they're very, uh, collaborative with us, the ambassadors as well. We see them a lot.
We interact and socialize and network with all of them. And so it's really great. And we just got our first AMBA deaf ambassador, uh, in the CNCF group.
Uh, her name is Anastasia, uh, kapuka. And so her sign name is this. And so we're really excited to see the deaf and hard of hearing working group make a bigger impact to the Kubernetes and CNCF community already.
I mean, we've, we've given them advice on how to, how the captioning should be in place. Some captioning out there, like different vendors or whatever, putting the captioning on the bottom of the screen where, you know, like, like for example, this morning, like in a keynote, having the caption on the bottom, they can sit in the front so they can see, you know, the, they can't see the captions 'cause they're blocked by certain things. So if you like, sit or stand in front of the screen as a presenter, that it's not the best, uh, for us to access.
Whereas if it were at the top of the screen, it might be different. So, you know, it's things like that, that what we're trying to do in our group, uh, we're just basically going out and advocating as much as we can. This is the only conference where I've seen sign language in the keynotes.
I really wish that more conferences would have this. Oh, yeah, definitely. So CubeCon, we've seen more increased sign usage on the screen within the screen.
In the past, people would get bothered by it. Uh, I'm pretty sure today some people will still be bothered by that. But that number I feel like is diminishing.
So I think that the point is, is it helps really sort of gravitate us to meeting the needs of many different, uh, varieties of people. Some people who are deaf, um, that don't sign, that's also a thing that they rely on captions. Some of them, um, if they're reading the captions, uh, sometimes there's tech words or there's con, there's concepts that aren't very clear that sign language can help with, with that being that it's a spatial language.
So I think really we just have everything to fit everyone's needs. And with how fast AI is growing today, has that helped or hurt the accessibility? I would say both help and hurt hurts in a way that some AI now comes up with tools where you can speak to it and then, you know, it'll come up with something on the other end, uh, intelligent, I guess.
And then I did notice that some AI now starts with text input. So that's where you can type something in instead of speak to it. So that's great.
And then, uh, in some ways AI has helped, uh, I would say maybe if you wanna ask it, what do I need to provide for a best possible experience for a deaf attendee at a conference? Because our document is open source, it's out in the community. AI would be able to read that document and then that would help them advise, make recommendations to, et cetera, whatever the use of the LLM or the AI is using and for that purpose.
So, you know, I'm, I'm hoping that, you know, that that gets more widespread. Other things where AI has maybe not been beneficial, I'm trying to think. Um, there's some bias, right?
AI always has bias in it. So some perspectives there, you'd ask it maybe, uh, it's related to, you know, deafness. Should I grow up signing?
Maybe AI would say, no, you shouldn't. Um, but you know why that is. What's the rationale behind that?
So there's, there's different things where AI bias could hurt the answer to that particular parent or coworker or, you know, their friends' needs, because every deaf person is very different. So AI doesn't know that. So, yeah, so I think those things, I have seen AI technology demos where they have you hold up your hand and make different poses.
Does that help with signing? It's not very practical because if the hand, like if you're finger spelling for example, and you're continuously doing that, it'll get way behind and still getting caught up while other people are speaking, right? So that's why we sign, you know, it's really a perfect language.
Why? The reason is because a picture's worth a thousand words, right? So if I sign and I'm interacting with that, it's over a thousand words.
Whereas like, if you, uh, spoke a few words in your sentence, right? I can, because like I said, it's a spatial language, right? So the language, uh, is using this space in front of me that makes it a picture.
And so it's very visual. You can kind of imagine what a deaf person is, you know, trying to communicate to you. So it's really nice.
And for someone watching this interview, like, what can they do to help the deaf and hard of hearing community? Or what can they do Honest, just honestly just be a great ally. Ask us if we need anything.
Ask us if, if anything's missing. Um, anything missing the mark, uh, what else would I say? And be open, you know, if we make a request or ask for accommodations, there might be sometimes where it might be frustrating.
Maybe that's a time where we can, you know, uh, you, you might feel completely lost or, um, not aware of what's going on. And the context might be right or wrong, who knows? But I think that that's where accommodations and accessibility can help us to get involved and engaged and add value to the community.
So the community is not something where you'd want to have like-minded folks. You know, we, we don't want that. So we want diversity.
We want different, uh, perspective and thoughts and where people would say, oh, I didn't think of that. Whereas like a deaf person or a blind person or a somebody with a physical disability, uh, you bring them into the picture and the open source community, they will maybe develop some tools that benefit. But also, you know, a deaf person might say, do you have accessible videos?
Do you have captions? That way, you know, the wider community can understand what's happening in the video. Sometimes a person with a very thick accent, for example, which is pretty common in tech, right?
Uh, having captions on the video can even help the lay person understand what that person's saying, right? So there's, uh, many different things out there. We're trying to make accessibility into a more universal design where they can have, uh, you know, accessibility becomes more like common practice.
Something that should be just a given, right? I like the point you make about putting captions. 'cause personally I actually enjoy reading the captions more than listening to people sometimes.
Absolutely. Yeah. Some people prefer to read rather than, you know, take in the video I with a video, you know, if it's going on for like 30 minutes, let's say.
And sometimes I will, if they're not showing anything on the screen, like, you know, here the podcast we're, you know, you could look at the transcript, read through it much quicker than maybe watching the whole video. Um, 'cause some people read faster, uh, than, you know, consuming the video. So that's one thing that's kind of, uh, where I see captions as an example there to help make your content searchable as well.
Captions with the transcript and everything that that's there. If you, if somebody searches for a particular keyword, then it will might refer them to the video, right? So that provides, uh, the metadata that it needs, uh, before for the search engine, and it's a dual benefit, mutual benefit for everyone involved.
Thank you for sharing your perspective today. I really learned a lot today. Rod.
Thank you. Hi everyone. Welcome to, uh, nt.
Also, welcome to my session. My session is Cybersecurity in the Agile methodologies. Another name is Agile security or DevSecOps.
In this, uh, session, I will, uh, details about the cybersecurity in the agile methodologies. How can integrate cybersecurity in the agile, uh, project? And what's the best practice of this, uh, uh, integrate cybersecurity in agile, uh, teams and agile project?
At first, I wanna give a summary about to me, I am, I am founder, I have cybersecurity companies. I am freelancer, cyber consultant, plantation test instructor, instructor. I have some cybersecurity courses in the training platforms.
I had 20 years experience about software development and spaces software security. I wrote 17 books about, uh, software security, such a API, security, cloud software, supply chain security, blockchain, and blockchain security. This is my, uh, LinkedIn, uh, connect and email addresses.
At first, I want to introduction the Agile and cybersecurity. What is the agile methodology? Agile methodology is a project management approach that involves, uh, breaking the project interface and point of the continuous collaboration and improvement.
Uh, this continuous, uh, collaboration and implement important topic for cybersecurity because cybersecurity teams need to collaborate another teams like developers, operation teams. Also, it's very important, important part. Another important part, improvement because cybersecurity or security needs the improvement because always need vulnerabilities, uh, in the application or network or system.
Diverse cybersecurity needs, uh, work together and other teams and always continuous improvement. So why securities essentially in agile At first, cyber threats, uh, involve as a quickly as agile project. General agile project is software project.
The cyber, uh, threats is evolve as quickly. They need, uh, release, uh, when the developers, uh, write new code. And for the new release, general software project has NIV vulnerabilities.
Another thing, n secret vulnerabilities scan, produce, frequent release. So, uh, therefore, ever these new security vulnerabilities can, uh, produce very frequently. It can be, uh, like the security must be, uh, continuous, uh, job and need to collaboration and improvement.
Also, balancing speed and securities essential for building software. What does this means generally? Um, uh, at the same time, some vulnerabilities in the software application they need to fix immediately.
Especi these findings is critical or high findings. High vulnerabilities is, uh, vulnerabilities have to, uh, fix, uh, immediately and very faster. Therefore, it's balancing speed and securities very important for the secured applications.
Uh, at same time, cybersecurity is challenging in the agile, uh, system ent security tension, what it means. Agile generally encouraged to repeat delivery because agile makes everything faster. Uh, therefore, uh, agile team try to be very fast about the need release, but it is can need to overlook the security risk because all security risk or security vulnerabilities cannot fix immediately.
The agile team need extra time to fix these new findings or new vulnerabilities can be challenging for the, uh, securing the agile teams. Another one, uh, frequent change and updates. Uh, more release cycles means more frequent testing and more opportunity for the vulnerabilities.
Generally in the DevSecOps pipeline, uh, they, uh, secure the tools integrate devs pipeline. These tools integrated and they choose scan the software project, uh, continuous and automatically. Therefore, they have the, uh, one developer teams or agile teams, uh, have new release.
These tools can again and find the new vulnerabilities. Because of this reason, it can be, uh, a bit, uh, problem for the software developer team because they have to fix these vulnerabilities before the release. But again, it extra time for the fix this, uh, finding team dynamic.
Uh, agile teams often prioritize functionality, living security council for letter because they wanna, uh, release the repeat delivery very fast. They might wanna make the job very fast, but, uh, because of this, they said that we can fix this vulnerabilities for this, uh, release for letter after we commit source release. It can be a bit challenging and a problem for the agile team.
Uh, shift light is cybersecurity, is agile, is, uh, important and helpful to pitch because shift in mean moving secular consideration in early in the development lifecycle. And when the software, uh, developer start new software project, uh, they, uh, draw the software architecture in the plan stage of software development lifecycle. They have to integrate, uh, security in the, uh, this software architecture.
So they can see the, some security risk in the beginning of the dev, uh, software development lifecycle. So they have to work also security team with the cdd security risk and or any, uh, they, maybe sometimes they need security card not to secure. Software project is, uh, things is start thinking in the beginning of the software development lifecycle.
So when the, the Agile team is identified, vulnerabilities early, reducing the cost we work also, it's very time saving. So like this identified vulnerabilities or, uh, seed security risk about project in the beginning, in the beginning of, uh, development lifecycle, they can fix, uh, it very early. Also, they can collaborate security team or other team to, for this, uh, security requirements to implement, uh, agile project in the beginning of software development lifecycle also empower, uh, developers with security responsibilities leading to share accountability.
They start to work to, in the be, uh, with another teams like, uh, maybe sometimes security teams, sometime network or operation teams to implement this, uh, security requirement in the beginning of the project. So they have collaboration. Also.
They share the responsibilities with other teams. This helps to, uh, collaboration and communication other team. Also, it's help to, uh, create, uh, security culture in their, uh, company or organization generally, uh, organization or companies using the shift left tools and practice for the Agile system.
This first one is, uh, uh, general static application security testing tools. It's SAS tools is general. Scan the source code and find vulnerabilities for the source code of the software project.
Another one, dynamic application security testing is the task tools, is task tools is scan the software project from the user interface and finding the vulnerabilities from the user interface. Uh, also, um, you know that it's, uh, when you, uh, integrate security in the DevOps pipeline in, uh, SecOps, uh, dev SecOps, sorry. So, uh, when you, any another security tools can I integration integrate from the integration and context deployment security integration.
So not only a static or dynamic security testing tools and other security tools can be integrated ops pipeline. And these, uh, have, uh, deductive vulnerabilities from the Agile project, uh, continuous security testing in the Agile. Uh, after the, uh, teams integrated these, uh, tools from the their DevOps pipeline, these, uh, tools, uh, scanned the project automatic plan continuously.
They integrated one times, and then these tools automatically scan the project with each pool built of the project or each release. Uh, also, uh, they, some dependencies can important because, uh, recent years, at least 50% of the software project is include third party libraries. It's, uh, commercial or open source components or frameworks.
Therefore, these tools, automatic check for the vulnerability, vulnerable libraries or packages, therefore saw these, uh, uh, scanning tools, find any vulnerable package libraries or framework. Uh, therefore, developer teams need to fix these, uh, components or libraries. Another important thing, uh, continuous feedback loops.
They, uh, like this, uh, higher critical findings or vulnerabilities, they need to immediate feedback on security risk. Agile teams act faster. So I integrate cybersecurity in agile team.
They have, uh, continuous feedback, continuous work together, continuous collaboration and continue promote about security. At the same time, developer teams use, uh, learning to how can the fix the, uh, new vulnerabilities. They also learned, uh, new vulnerabilities in their software project because always continuously their projects, uh, scan by the tools, security tools.
Uh, so how can integrate the cybersecurity and agile sprint? Uh, generally at first, uh, sprint planning, and they include, uh, security task as a part of the planning. It's to start to like the security test in the beginning of the software development, like, uh, lifecycle, like a planning stage.
Then, uh, this task is defined security done criteria for the feature release. So developer, uh, or any HR team member, when they fixed this, uh, security task, they need to secure done feature for the release. Also, uh, uh, another, uh, things is implementing secure coding practices and vulnerable scan.
In the definition of the done, generally, after the tools is or dust to scan the, uh, software project, uh, software project, they, uh, detect vulnerabilities and they give severity, like high critical, medium or low. These, uh, findings or vulnerabilities can be adding for the, uh, supreme plan, like a security test. Uh, task and developer teams have to fix the ds, uh, security, uh, finding in their discipline.
In this part of the sprint planning, it can be had for the, uh, continuous secret, uh, limitation, uh, process. Another one, threading modeling In Agile, this is the general threat modeling is have to, uh, heading potential security risk at the planning stage. So always the planning stage and software architecture, they can, uh, light the threat modeling.
It can be include new feature or changing and threat modeling site. It can be good integrated threat modeling, uh, uh, takes or in the any task in the spring plan and Agile. Uh, so with the working, like this is cyber in agile spring, it's, uh, prioritize security stories.
So, uh, so, uh, agile teams know, uh, prioritize which, uh, vulnerability or security risk fix. Uh, also it's very helpful to, uh, take address security needs it. It's to prioritize, uh, security risk for the agile teams or software developer teams.
Uh, also Agile helped building the security, uh, culture in the Agile team. Uh, generally Agile team has a, a security champion person in the team. He or she's a team member.
Agile team member team. This person is generally designed to team members. They secure support there.
Generally, this person have to do teams. Agile teams about security site and security, uh, support the, uh, agile team need do anything about security. This persons generally improve skills about security side.
Also, another important thing is ongoing security training. Because, uh, every release, uh, has a generalist scan by the security tools. Therefore, after the detect vulnerabilities, developer teams or agile team member needs to fix this finding vulnerabilities.
Therefore, they need to always, uh, train regular workshop or training session for the agile team members, it's good for the dislike training. For example, a developer or agile team start a new project, then they, uh, write the code or plan site or design site. They remembered this information from the previous project.
They don't do the same. Uh, same mistake in the new project. Therefore, ongoing security training is important for the agile team member.
Also, collaborative accountability. It's generally developed by mindset secret in everyone's job. People understand with this agile, uh, integrated security and agile teams, they, uh, understand security job is not only one team job, it's everybody's job.
Also continuous, uh, continuous job, continuous process. Also, they need to collaborate and working together. The, uh, therefore communication with other teams is important because sometimes some vulnerabilities fix very, I immediately.
Therefore, communication and collaboration is important for building and, uh, building a secret culture in the companies or organizations. Best practice for the, uh, cybersecurity in Agile. Uh, at first integrate the secret, uh, into, uh, DevOps practice support Agile.
It is means dev SecOps. It's generally security tools or security adopts pipeline or software development lifecycle. So it is hard for the secure the project in the beginning of the, uh, starting the project and project, uh, project plan in the beginning of the plan, par plan stage of the project.
So it means there, SecOps and other things, prioritizing risk based, risk based testing. Generally, it is hard to, uh, focus on the high risk, uh, from the, in the project, in the high security risk in the project. So the, uh, agile team doesn't have the secured everything equally.
They only focus high or critical findings in the project. Another, uh, things is best, best practice of the cybersecurity agile, using secure coding guidelines. These documents is include about, uh, sec coding standard, about secured source code.
How can the, uh, fix the vulnerabilities in the project? Also, how can the right secure code, uh, for also not, uh, Chinese tools can the project tools cannot find or detect vulnerabilities. These, uh, coding guidelines, like the information and guide developer teams to and all at same time, train the developer team, uh, members to writing the secure code and fixing the bilities.
Also, uh, another best practices regular secret audits at u uh, they, uh, teams conduct, predict, predict audits, agile environment, and assess overall secret tasks. So they need to, uh, follow and control the audit and review site. And they can see sometimes maybe unexpected secret behavior or in secret audit audit.
Therefore, agile team needs to integrate, uh, secret audits and reviews in their agile, uh, methodologies or agile management. Uh, what is the benefits of cybersecurity in the Agile? At first, reduce vulnerabilities earlier because, uh, uh, detect vulnerabilities, security vulnerabilities in the earlier, and this, uh, vulnerabilities fix in the earlier stage of the software development lifecycle, or, uh, in the beginning of the, uh, project also adaptable the new threats because cybersecurity, agile teams can respond quickly.
New vulnerabilities and threat vectors. Also, at the same time, agile teams, uh, learn, uh, new things about cybersecurity. When they fix the new, uh, vulnerabilities, it's important for their, uh, continuous improvement.
Uh, improve, improve collaboration and awareness. When you made it into the, uh, security in the, uh, agile, uh, uh, teams and agile management, everybody has, uh, information, uh, about cybersecurity, and it's good for the culture of security awareness. Also, they, uh, shared the responsibility about, um, security.
So it's good for the collaboration for the teams and working together and communication each team, each other. So they shared their, uh, ideas, information. Uh, so it's good for the improved collaboration and awareness.
Also, another one, faster time to market integrate security and agile cycles, uh, can lead, uh, quicker. You know, that agile generator makes everything fast. So when integrate security and agile, uh, new vulnerabilities can fix very fast and imaging.
Yeah. So, uh, all of this about cybersecurity in the Agile methodology or agile teams, they, it's, uh, it's, uh, I think dev SecOps or agile security is important topic for the organization and companies in nowadays general organization and companies using cybersecurity. Also, uh, it's very helpful for the teams to improve the, uh, security culture and collaboration and improvement.
Uh, also shift left and automating security have the balance, speed, and projection of the project. Uh, uh, so, uh, this one is cybersecurity in the Agile. Thank you for the, listen to me, if you have any question, I, I am happy to answer your question.
All right, well, thank you guys so much for coming to my talk. I'm talking about, uh, when Agile doesn't work, um, and just replies to common objections to agility. Um, so I've been doing work with software for about 12 years.
Um, I see here I said primarily in agility. 'cause I've been an agile analyst, a scrum master for, uh, several of those years. But I've kind of dipped in and out of several different roles.
Um, I've been in product ownership for a while, a little bit here and there. I've been in business business analyst for a while. I've done some software development, so I've kind of been all over.
Um, and so that's kind of where, but majority of my work is in agility. So with that, um, that's where a lot of my, um, experience comes in. I have some, some stuff to say about, um, you know, how agility works.
So, um, and this is a picture of my wife and my child, just so you guys kind of know who's talking to you a little bit, a little bit of connection there. My, um, my child is here, he is, uh, three or four, I think, but he's, uh, seven now. Um, just about ready to turn eight.
So he is gotten a lot bigger, but I just really love this picture. So I just wanted to share that with you all. Uh, so yeah, there you go.
Um, so what I wanted do hear today is, um, like I said, I've been here, uh, several years, and especially in agility, and I have met a lot of people that have a lot of stuff to say about agility and why, you know, it doesn't work or why, you know, it might be good generally, but hey, it doesn't work here. And, um, and so really walking through those arguments that I've heard, and then kind of some things that I've experienced along the way that kind of serve as a counter argument. Um, so, so I've got several slides that kind of have that same format, just the, the argument and then kind of counter arguments against that, so to speak.
But then the next part is how to engage with people. Um, because when, um, when I first gave this presentation several years ago, that's one thing that I didn't really include. And I feel like now I really need to include some of that, because as I was going back to these slides, it felt a little bit like a, here's why I'm right and why you're wrong, kind of thing.
Like, Hey, agility works. You're wrong. Here's some counterarguments to prove that it works.
And like, no, that's not really the point. That's not, I'm not here to try to be right. I don't think anybody here, hopefully is here to be, right?
I think we're trying to do right for our business. Everybody cares about the business. People that don't like agility, they care about doing things well.
Um, and we care about doing things well, um, as agileists. Um, and so really just wanna make sure, like as an agileists, I, I believe agility is correct. I believe it's the right way of going about doing things.
Um, I wanna just talk about how can we engage people in a way that's effective to help you under help 'em understand the benefits of agility. So, um, but yeah, first talk about the things I've heard against agility, so we can kind of walk through them. So, um, I'll go ahead and start down that path here.
So one of the things that I first heard when I was starting my career was that Agile isn't really known for quality. We really need high quality. And again, some of these things you may have heard, and then other things you may be like, no, I haven't even heard that, because it, it just doesn't seem true at all.
This is one thing I have heard, and just as a caveat, this is really something I heard when I first started out. Uh, and the company I started out at was a logistics company. Um, and they were a smaller company, but they were hungry.
They really, really wanted to just go after growth and go after all these new clients and grow as fast as they can, strong as they can. And, um, and so they had a backlog of a ton of things that they really wanted to get done on our, on our products. They wanted to add a lot of new features, um, a lot of really good features we were all excited about.
Um, but they wanted to move so fast, and they were like, Hey, we gotta move faster. Like, let's, let's try this agile thing. Like let's get into this whole agile thing.
Let's really step that up so we can go faster. And so, um, a lot of the dev team that I was on, they kind of equated, oh, agile is that thing where you just push so fast and so hard, you just neglect quality along the way. And so this is what I heard at that point.
Well, agile isn't known for quality. We really need high quality. We can't skimp on quality as we build this thing.
And, um, you know, again, the the counter, and again, all these things, as I mentioned earlier, I wouldn't just say, here's a counter, like this is why you're wrong. But I want us to understand from our perspective, um, kinda what the counter is in ourselves so that whenever we do engage with people, we know what's on, what's going on. So the counter that I have for this is that without exception that I've seen, like, this is true when I gave this talk.
And it's, it's also true now, um, when I first get this talk that is, is that without exceptions, teams that I have personally seen, do Agile have been of much higher quality than the ones that have stuck to Waterfall, um, just due to, uh, various factors. Um, and I mentioned Scrum as well here as if you're using Scrum. Uh, so if you're using Scrum teams can specify some quality gates in the definition of done.
So those of you that use Agile, most of the time you are using Scrum. Um, if you don't know the difference, uh, agile is a very broad term. Uh, there's, there's a manifesto out there that has just four things that describe what Agile is, and then 12 principles, and that's all there is.
You can read that in three minutes and you'll, you'll understand to some degree what Agile is. Whereas Scrum is kind of one layer above that. And it's a framework that is a little bit more intense.
It's not, it's not fully intense, it's only 22 pages, but it's definitely more than one page. So it's a little bit more than Agile. And, uh, if you're unfamiliar with the Scrum is, although I can't imagine that because it's so widely used, but Scrum is where you kind of take a specific measure of time.
Like two weeks is pretty typical. You say, for the next two weeks we're gonna make a plan for these next two weeks we're gonna do that plan. And then at the end of that two weeks we have this thing, we've built this piece of software that gets integrated into our app and that piece of software we're gonna test, we're gonna, we're gonna review that with people, we're gonna review how we did our work, and then we're gonna start the whole process over again.
You're gonna keep doing that time after time after time, um, until you build something great, you know, incrementally, uh, one iteration on top of another. Um, so when you do that, uh, one thing that's really important is when you get to the end of that, of that time box, so to speak, and at the, the end of that two weeks, you wanna have that thing that you've built quality. You wanna say, okay, we cannot call this thing done.
We can't call this thing done unless it meets our criteria for what done even is. There's a bunch of things that we have to have in place if we wanna call that done. And, uh, that's called the definition of done in, in Scrum.
And so if you have that definition of done, you can add anything you want into it that you and your team know to be a good quality gate. So, for example, you can be like, I don't want this thing released until it's fully tested, a hundred percent code coverage. I don't want this thing out until QA has given, uh, has done a full regression test.
I don't want this thing out until, um, our, our, um, our PO has product owner has done their due diligence and looked over the whole thing. Um, I know whatever else there is, uh, out there that's gotta go into your definition of done. So you can make sure you say that thing can't pass our, our can't pass into the, into, um, into the next stage until it meets that definition of done.
So in that way, yeah, that, uh, quality is a very big part of Scrum at that level. And then the last part I just wanted to to touch on is that quality is actually, so it's something that's a good practice, whether it's Agile or Waterfall, it's not necessarily that like, well, because you're agile, you're less quality, or 'cause you're waterfall, you are less quality. Like these quality gates are important, you know, whatever you do.
Um, I think it pairs better with agility though, as you see there at the bottom. And the reason I say that is, is really because of the iter iterative nature of agility. Like if you're spending two weeks doing something and then testing it, and then even if you release it within that two weeks and then you release these small chunks of work, um, you only find a few bugs at a time and they come out iteratively and incrementally.
Whereas if you have waterfall, you'll spend months and months and months building something. I've seen this been months and months and months building something, release it, and then a plethora of bugs come in. And that just doesn't seem quite as tolerable to users that I've seen.
As you release something, a few bugs come in, but you fix 'em in a day or two, and that's like, okay, that's fine. Waterfall, you release something after years and then it's just buggy. And people are like, well, these guys built a buggy app.
So, um, anyway, that's why I think it pairs better with agility. But either way, uh, quality is not something that I would say is anti agile or Agile is not so anti quality. It's the opposite, um, one I can see.
So that's the first one. Uh, another thing that I've seen a lot or I've heard people say a lot is that, um, you know, we developers know best. You know, we built the app, we've done the coding.
We, we know what this app really needs, but uh, we lose our voice and we give it to the business. The business just continually is in Agile. There's a product owner.
The product owner tells us everything that we need to do, and we have no voice in that. Um, and uh, that's absolutely not what Agile's about. Um, in fact, agile, one of the 12 principles of Agile said that one pager that kind of tells everything that Agile is one of those 12 principles, is that business people and developers must work together.
Um, and I, I'll keep on reading some of these things here, is if the product owner is too focused on one side, so if they're too business focused or if they're just a really technical product owner and they're just really focused on the technical side and they don't really prioritize some of the stuff that the business is asking for, um, then that's a good opportunity for use Scrum Master to go and get involved and, and, and help the product owner and say, Hey, let's come up with some kind of a balance here. How can we make this thing work for everybody? Um, and the really key things are the bottom two, being open and building trust.
So as a dev team, you don't wanna cannibalize all the features. Kinda like I was saying earlier. There needs to be some kind of a balance there.
I have seen both sides. I have seen, uh, the business come in and say, Hey, you really need to get our features done. This is important.
We really need to get these done. And Dev was like, no, we can't get these done. We really gotta work on these quality things.
And then the dev side actually gets to the point that somehow they're bullying the other side and saying, no, we are, we are doing all these refactor and you're getting nothing. It's really been kind of toxic and there wasn't a lot of trust built, but that's what's really key. Building trust, being open product owners need to understand the value of the technical stuff you're doing and being able to understand the value of the business stuff you're doing and figure out which one's your true priorities, um, and keep a good pulse on that.
So that's, that's one very important thing. Okay. Uh, next we have, uh, something that I hear quite often.
I've heard it pretty much everywhere I've worked, which is that what do you do when you finish your sprint early? You know, so they say here, sometimes we finish a sprint early, what do we do now? It just seems like wasteful to do nothing.
We're just sitting there. We, we planned, uh, a sprint, so we're gonna do this work in two weeks and we're gonna take two weeks to do it. Well, we've got it done in a week and a day.
We have four days left over. So now we're just sitting here. Well, the first thing I just, I just wanna get this outta the way.
I didn't even have this as my first point, the first time I gave this talk, but I really, I added it because it's, it's, uh, something I feel like just needs to get outta the way, which is you don't have to do nothing and you shouldn't just do nothing like that. Just that that is a little wasteful. So you're free to get a headstart on the items in the backlog.
So just because it's not in the sprint, you can go to the backlog and find some things to do and, and get started on those. The only thing I would say is a caveat is one of the benefits of having a, uh, a sprint is that you all talk about it, you plan together, uh, you know, everything yours to know, uh, about it 'cause you've planned together. Um, and there's, there's conversations that happen along the way, but generally you have an idea of what you're doing.
Um, so if you do just wanna do something in the backlog, make sure that you talk it over with whoever needs to be talking about. Make sure that the product owner knows you're doing it. That, um, that it has all the details.
Maybe there's something that the product owner wanted to put in there, didn't get around to yet, or whatever. Just make sure that there's some clarity that like, I'm doing this, okay, I got, let me, let me go ahead and get started on this. But generally, you're free to get ahead, start the point of the, of the, of the time block of the, of the sprint, um, isn't to lock out things that you, it's just to, to plan what you want to deliver.
So if you've gotten that done, great, let you know, do other stuff. That's all good. Um, but I would go on down the next point here is what is waste?
So in my earlier career, I did a lot of work with, um, with Lean Six Sigma and in the Lean Six Sigma world, waste is an incredibly well-defined, strictly defined term. Like if someone were to say, what is waste from a lean perspective, you can go, ah, I know what, I know exactly what waste is. In fact, there are eight different kinds of waste.
And they form a, uh, an acronym. They form the acronym downtime. You have defects over production, um, waiting, um, not engaging employees, and you can keep going down.
And, and the point of that is that you can, uh, and this is from a manufacturing standpoint, if you can walk into like a manufacturing facility and you can just look around and you can say, oh, there's inventory over there just waiting, that's waste. Oh, there's this person over here kind of just leaning against, that's waste because you've trained to kind of use your eyes to see waste. And it's a little bit different for software.
Um, we, we don't exactly, uh, have the ability to kind of just see inventory in a corner. Um, but we do, uh, as a, as a kind of a, a caveat, we do see like Kanban boards and stuff that is, is waiting in a Kanban board. So you can see some of that inventory in a digital stance, excuse me.
'cause every, every ticket that you have in your board, uh, whatever column it's in, whether it's to do in progress, those tickets, um, they represent some work that went into it. So people met to talk about those tickets, right? The business or the product owner met with some stakeholder and that with, I don't know, business analyst, whoever it is, I don't know, but, but somebody met to build out that backlog and put a lot of effort into that ticket that is just to most people, just little couple lines on a board.
But that represents a lot of time and effort. And when it's just sitting there on a board, it, it provides no value. The only way that that value is realized is when that ticket gets developed and makes it into production, and then they can start realizing the value was created for, until then it's not producing any value.
So there is legitimate waste in the sense of it's sitting there producing no value, but work went into making that. Um, so that's true, but within the context of a product waste, there's a bigger problem out there. And that bigger problem is what if you spent all this time building the wrong thing, right?
Like, what if we had the product owner, the, the business analyst, the developer, all these people meet, discuss, and build out the requirements or the tickets or whatever for this thing, and they went into the backlog and it went into development and someone spent a lot of time developing it. Then it went into code review and someone spent a lot of time code reviewing it, and then it went into, uh, QA and someone spent a lot of time QAing that. Then it went into user acceptance and, and your PO spent a lot of time, you know, you're doing that.
And then it was released and all this work and all, who even knows you were to just measure the amount of touches that that went through and the amount of, uh, of billable hours that went into that. Who knows how much that would cost, have cost to get that through. And then you get into production and nobody uses it, or it provides no value, or it didn't do anything near what it was supposed to have done.
That is the biggest kind of waste, which is building something that's just not valuable, um, building the wrong features the wrong way, the customer doesn't want it, whatever. And that is something that Agile is really focused on, is particularly have, scrum is heavily product focused, and it, it is, it does tolerate a little bit of process waste. You know, like, it, it, it basically says that the most important thing is making sure you're delivering well, right?
That you're iterating, you're getting feedback on stuff and then feeding that back into your product and then building the right thing. Um, so that is something that Scrum is heavy, heavily focused on. Um, and maybe there's a little bit of process waste in there and that you have to wait a little while here and there, but considering what it's trying to prevent, that a tolerable, in my opinion, um, a tolerable, um, thing to, to take on.
But if it is a major issue, if you're like, I can't tolerate any process waste at all, no process waste, total waste free. Um, there are other things besides Scrum, like we have Kanban, like if you're with Kanban, it's like Scrum in some ways. But that has got, um, uh, there is usually you have like a, like a board with like to-do and progress and different kind of columns, but you don't have a sprint.
You just kind of pull whatever's next on the top of the, of the lift and you do it that way. So whatever's the top is good. So if it truly is something that's important, um, you know, there's always the ability of using something like Kanban to manage your processes.
All right, next we have in our business, things change so much we can't really commit to the work for a full sprint. I've heard this one, um, actually pretty often at several different companies. And it, it does seem strange to me because, um, the company that we've started that I started with, like I said, they, they really kind of adopted Agile.
Um, but when I got there, they started, you know, their agile journey, um, from like a more waterfall way of working. Um, and they were saying, well, we can't do Agile because it's too, things are too chaotic here. That seems strange to me because wouldn't that pair more with Agile than Waterfall?
The things are chaotic, but regardless, they were like, we just can't do the sprinting thing. We can't, we can't create a sprint. Two weeks is too, too, uh, is too short of a time box or too, too big of a time box.
We need, uh, we need to just be free flowing. And um, initially my thought, my thought before I really put a lot of this together was, okay, um, shorten your time box. If you have a two week sprint that you spend two weeks building something and then you start over and build something for another two weeks.
So on, just shorten it to one week. Um, and I thought about that for a little bit and I was like, you know what though? Um, if you can't get, if you can't, two weeks seems just like a lot.
Um, so I don't wanna say this. Um, if you can't plan two weeks, it's probably a bigger problem. Like there's a fine line, there's a fine line between being agile in a sense of like, we want to respond to change.
And then just saying we're chaotic. You know, if you're responding to change, if you have a short change window, okay, that's tolerable. You're using agile, that's okay.
If you're chaotic, you're like, I can't even plan two weeks without something going crazy and blowing up in our face, that's probably something you need a little bit more problem solving around. Like, that's probably a legitimate problem. So like, um, I'm just looking at my time to see if I have time for the story.
Um, yeah, so when I was, again, earlier in my career, one of the big things, um, somebody come up to us and said, Hey, we just, we just sold this thing, like we have to start building this today or tomorrow, like soon we gotta get on this. And I was like, well, well we gotta have a little bit of conversation around this. Like let's plan a bit more.
And, and you know, uh, the guy who was selling it, uh, who happened to be kind of in the, uh, executive um, area was like, no, we need to do this now. He pulled a developer aside and said, Hey, what are you working on? He's like, oh, I'm doing this.
Like, not anymore. You're doing this now. And, um, just, just, you know, totally blew it up.
And, um, well long story short, we didn't build the right thing and there's a lot of problems around that. And, um, whenever you dig into the actual root cause of that, um, sales was really struggling. Basically.
Uh, they weren't meeting the numbers they were really hoping for and they were just throwing as many hail Marys as they can, like trying to close these deals, promising things that they, they're just, they're like, I don't know if I can deliver, but we gotta get this thing done. So like really just working, working themselves to death, trying to get these sales closed. And so we were kind of in the middle of that.
And so that was a bigger deeper problem. It wasn't just, you know, well we need to do better within it or, you know, lock people out and say like, no, you can't do the, it was like, we need to fix our sales problem as a company. So that was a big problem solving issue for us.
And so, um, you know, it just kind of goes to show that sometimes the problems aren't always one, they're just right in front of us. They can go a little deeper than that. And so that does need a little bit of problem solving.
Um, and again, just like I said last time, if this is truly is an unavoidable issue, if you're like, you know what, we can problem solve what we want, but this is just the nature of what we do as a business. I don't really know a good example, but there many businesses that are just like, we are chaotic. That's part of what makes us us.
And there's not really a way around it. Okay, scrums probably not the right framework and you can use Kanban, and Kanban is also agile. It's just a different way of being agile.
So I would just recommend looking into that if that's, uh, truly a problem. Okay, next we have, developers don't want to give us timelines, but we really do need them. With Agile, we're having trouble getting these.
So I heard this a lot, uh, again, just, uh, really throughout my career is just, you know, well one of the big things about Agile is it always goes longer than the timeline, which isn't necessarily true. Uh, waterfall also goes way farther than the timeline. But, um, but one of the things, the misconception I think is that you just throw timelines out the window.
With Agile, that's not really the case. What you do is you respond to change with agile. So Agile's not anti timeline, it's just pro responding to change.
So you can build a timeline and then just make sure that you're, uh, adaptable with it and you're able to change and willing to change if and when things change out there in the world, uh, if your stakeholders just, you know, understand that there's something else that they need or, or whatever. So as you kinda see here, it's really a function, a lot of just the kind of team you have. Um, I've been on newer teams and um, you know, timelines are a struggle.
There might be teams that are like, oh, we're so new, we don't really know the tech stack very well. Um, I think this will take like two days, but just to be safe, let's call it a week. 'cause we're so new and it takes like two to three weeks.
Um, so that, that's how bad these things can get sometimes. But once you get more mature, I do see that there's a lot more comfort with, uh, with these, with these estimates. Once you know the tech stack, once you know what's what goes on, it gets a little better.
You also have data as you get more mature, you can be like, how long is this going to take? Well, we had something similar that happened, you know, six months ago, and that one, um, took about, you know, three months. So it'll probably take about three months to, um, you know, we may buffer a little bit, maybe four months, but generally we're probably gonna be good around three months.
And that, that's a little bit more of an accurate statement. As you get more mature, you just get better at understanding what's your, um, uh, you know, what's your timelines are gonna be. Um, but then down there at the bottom, like I I said, it kinda goes back to what we were saying earlier, timelines are estimates and they should be reviewed and adjusted and adjusted in the sprint review.
Like the reason that people want timelines, there's a lot of reasons people want timelines. One of them may strictly just be for budgeting. It's like, you know, we, we, we think we're gonna make this much money from this feature.
Um, we won't spend that much on it, so we have a good ROI, whatever, you know, it's just stuff that people, uh, people want just for that reason. And, um, and so when we get to our sprint review, so again, with the sprint review, we spent two weeks building a portion of this feature. We got to a place that that thing has at least some part of it done, and we're going to review that with our stakeholders.
When you get to the table with that, you can say, okay, here's the features we built. If they're like, oh man, I just think maybe I see it now and I, I know we said this, but I'm seeing it now and I think maybe that over here is better, can we adjust it to be that? Or you can pull off the timeline and go, cool, um, yeah, that's gonna take a little bit longer.
So maybe this is a three month project now it's gonna be three month and a week or three month and two weeks, you know, adding more sprint onto it. Is that okay? And you know, maybe they'll be like, yeah, yeah, that's good, and you would just adjust the timeline based on that.
Or maybe they're like, no, honestly we, we kind of have a deadline. We really gotta be done in three months. We can't do that.
Okay, okay, cool. That's, that's perfectly fine. There are other things in this timeline that we can probably remove to make room for this other thing you're asking for is that, okay, we remove this thing here and maybe it's some point in all that time you'll get to some kind of good agreement.
But having the timeline, there is a, it's really good to have that artifact there to look at and, and kind of understand where things are landing, uh, as far as, you know, the plan and, and how and, and where, where you're gonna get done and what's gonna be in there and things like that. So yeah, generally use the timelines fine. Nothing wrong with that.
Um, if your customer doesn't want a timeline, okay, great, no need to. But if they do want one, you know, no big deal. You just gotta make sure that everybody kind of agrees that there's adaptability there, um, in case you want something different.
So, um, this leads to kind of the last portion of this, which is what to do in meeting resistance. This is, like I was saying earlier, like a lot of these things as I've been going through them, it might be like, well, yeah, like these are, are these, these are legitimate things people believe about Agile, like why it doesn't work. Um, and you know, I just, it just feels like it's very argumentative to say, well here's why it does work.
You're wrong. And that, that's not the goal. Like the goal is for us to understand, like I was saying earlier, for us to understand why agility works and the face of when people say it doesn't, or we know it does, uh, here's some ways we can kind of look at that.
But as far as you're talking to other people, if you're talking to other people and they're telling you these things like, I doesn't work as X, Y, and Z, the best thing you do is just, you know, ask them things like, Hey, well would you be willing to try this? Would you willing to do an experiment? Like, would not telling them here's why you're wrong.
It's being like, well, I hear what you're saying, um, let's just showing them that it works. Like what kind of experiments can you run to show people that this little thing right here that we wanna try to put into place might actually work? And, and just helping them kind of get there.
Um, and the next thing is this really important, and this was added since the first time I added, I did this talk as well, which is showing empathy. So again, you're not there to be right, like we're all here to succeed together. Like you're trying to help people, you're trying to empower people to do the best that they can.
And agility is kind of the tool we have in our tool belt to help people do that. So show empathy, like when someone's like, I just, this isn't gonna work. Like a lot of people have been hurt by agile, if you wanna call it that.
Um, Agile's been used as a weapon in a lot of ways, you know, and not agile, that, not true agile, but that, that there's some things that people call Agile. Um, like maybe someone was like, you know, agile to us was that we had to use this tool, we had to use this exact template, we had to do it this exact way. We had to meet these exact standards if we didn't, we're not meeting our agile quality, you know, controls or whatever.
And it was just dumb, you know, and that's their experience of Agile. And so they're coming to you saying, no, we don't like Agile. It's really bad.
It doesn't work. And you know, some of the, some of what you do is you say, I'm sorry, you know, I'm sorry that Agile didn't work for you. I'm sorry you experienced that, that wasn't the right thing to do.
Um, but I think you have an experience of Agile that's not right. Like I think maybe if we work together, we can figure out something better than what you experienced in the past. And that's important too.
And um, and if you can meet them at that level, like understand where their, where their heart's at and their head's at with this agile journey and meet them at that level, that'll go a lot further than just trying to dogmatically say, here's why I'm right. So that's a good way of kind of meeting people where they are. Um, but the last thing you wanna do is when Agile really doesn't work.
So are there situations where people are right, where they're like, agile won't work here because this, and um, I put here when change is expensive, 'cause that's the whole point of agile, is that you, you were able to change direction a little bit based on what you, what feedback you get from your products and from other places. So if you can't change very easily, if change is very expensive, then Agile doesn't work very well. Now one thing I'll say is that in my, the first time I gave this talk, there's a lot of places I would've said, oh yeah, like, here, here and here.
But as I've gained more experience, I've seen Agile work in places, I would've thought it wouldn't have worked very well. Like I would've said something earlier in my career, I would've said something like, well, agile won't work very well in like a highly regulated place like the government or the bank. And I'm seeing a lot of agile teams in the government.
I'm seeing a lot of agile teams in the bank. I worked at a bank, now we were agile and um, you know, the reason I would've said that they wouldn't work is 'cause of all the government regulations. It's like, well you can't release this thing until you have all your paperwork in place.
And that could take forever. And believe me, I was at bank, it did take forever, but we were able to do it iteratively too. And so it, it actually, we were able to problem solve a lot of those things and get to a better place.
And so that list of places that I would say Agile probably won't work is, is shrinking to the point that now I can't really think of a place that I would say, oh, agile won't work here. Like even if you're building a building or something, um, it's always a good pro like good thing to do to occasionally bring the client into the building and have them look around so they can tell you things like, well, I don't know, I don't, I don't really like that plug over there. I want you to move the outlet over on the other side of the room.
It's better to know that now than when the building's built and you gotta undo a bunch of stuff. So even there, I would say probably Agile's a good practice. It may not be as, as effective as other places, but it is totally bit of practice.
So yeah, I would say most places, if, if it won't work at the very least, you can glean a lot from it. So I would still be very cautious to say it doesn't work. Uh, more so now when I first gave this talk.
And that is all I got. So again, I wanna thank you guys for choosing to, um, to come to my talk or to listen to me or having me here. Um, yeah, thank you guys so much.
Appreciate your time. See ya.