Techstrong TV January 9, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. Welcome back here to Techstrong tv. Our next guest has been on with us before.
He is my friend Jonathan Redi. Jonathan is Chief Product Officer at Check Marks, and we'll get into this in a second. Let's first welcome Jonathan to the show.
Jonathan, happy new year. It's great to see you. Happy New Year, Ellen.
Great to see you, and great to be here. So, Jonathan, uh, you know, for people who are not familiar with yourself, I mentioned you're the CPO over at Check marks, but why don't you give them kind of a sense of your journey? Yeah.
Well, as many people know, check marks is in security, and I started in security, uh, many years ago at the beginning of DAST and Sast years ago. And, um, left security for a while. For the past nine years, I've been at PagerDuty delivering solutions to developers.
Um, and there's a lot of similarities between, you know, the urgency of major events that happen and, and the, uh, identification and the, the security vulnerabilities that are found. So, a lot of, a lot of similarities brought me back to security and brought me back to check marks, uh, just at the beginning of this past year. It's been a great journey so far.
Beginning of pa last year. Yeah, the beginning of this past year. Sorry, I know we're 20, 25.
Yeah. Year. Happy.
I just wanna make sure. Happy New Year. It always messes me up, Jonathan and I always need to kind make sure I get it straight.
Um, and of course, we, we knew you had PagerDuty, our, our friend Damon Edwards was there as well. And Covered page. I, I covered PagerDuty, I think from when they launched.
Yeah, right. Yeah. Um, anyway, we're here to talk about check marks.
So Check marks is a company, it really needs no introduction to our audience. We do a lot with check marks, but maybe there's some folks out here, Jonathan, who are not familiar. Yeah.
If you wouldn't mind, give them kind of the check marks story, if you will. Absolutely. Well, check Marks is established really a leadership position over the past many years, uh, in application security.
And we've always been primarily focused on app security, so security before production. Um, we integrate with all the, the CNAP, all the, the production vendors out there, but have been very focused on really two audiences. Um, the application security teams under the ciso that work and partner with development, and over the last two, two and a half, three years, many in the audience may not know.
We've made huge, huge progress in delivering really seamless experiences to developers. As we all know, from the beginning of, uh, security, uh, for developers. If there's any kind of friction out there, developers are gonna resist using a security product.
So it has to be a part of their workflows, has to be a part of what they do. Um, so that's been a journey we've been on and made really great progress there. And additionally, like, who can't talk about whether it's the life cycle and how it's being disrupted or, uh, how applications are being built and how they're being secured than to talk about kind of, um, AI and the disruption it's creating.
And so we've over the past year have delivered, um, a set of agents, uh, that work along the life cycle to augment both development and AppSec. So it's been a really exciting time, a lot of change happening, and a lot of just marquee customers out there who are continuing to use our product and engaging even more, like using the product even more, given kind of the anxiety level going up with ai. Absolutely.
There is an, you know, I was just in the last interview we was with the Cloud Security Alliance. I'm sure you're familiar with Jonathan. Yeah.
They, they have a, a new study out around AI and governance and security, and the, there is a tremendous amount of anxiety, a lack of trust in some cases, uh, just anxiety around the whole thing. Um, now, Jonathan, you know, we've all seen some of these numbers. How much code is actually being generated by AI today?
And, you know, it used to be, oh, it's just in test systems, don't worry. It's just in the dev environment. Well, no, it's in, it's in, it's in production.
There's a lot of code out there. It creates a lot of anxiety. It's scary.
Now, check marks recently made an acquisition, right, to help bring or graft some, let's call it AI security, uh, DNA onto the check marks, you know, uh, organism. Talk to us about that if you can. Yeah.
So we look at, you know, what is happening for all of our customers today in a couple of ways when it, uh, when in the lens of ai, there's AI for security, how can we apply AI to help those using our products, developers and AppSec teams. And then there's security for ai or what many of us refer to as AI security, which means the supply chain of, of applications, how applications are built. There's a lot of new elements out there.
There's models, LLMs that are getting built in. There's agents that are getting built in. There's things called CPS that are, um, you know, getting built in and six months ago who was talking about this.
So things have changed very rapidly to your point of kind of the anxiety level of, of CISOs going up very, very quickly. And I think two things are happening. The dynamic I see, one is development teams due to the promise, you know, with great, um, power comes great responsibility as they say.
And I can generate, I can create more, I can be more productive. But with that comes a responsibility to make sure that's secure. And so the development teams and the leadership are running fast.
The CISOs as, as we talk to them, uh, very much feel that anxiety you're referencing. And we started this plan, uh, and delivered products midpoint of this past year, 2025, uh, with the first set of agents to help, you know, developers and AppSec. We call that the assist family of agents that sit on top of our SaaS platform, check marks one.
And, and that's been very successful. It's, um, delivered a lot of value to our customers today. Uh, changing like from a, a reduction of cost, reduction of time to identify and remediate for developers like upwards of two and a, uh, you know, two thirds.
So 60% of the time that it took before manually using our agents, we can reduce that time. So huge savings, uh, both in time and cost, and then ultimately reduction in risk. Now we launched that, that was really successful.
And then around, uh, November, December, we started talking with some other vendors in the, in the market and, um, decided to join forces and acquire a company by the name of Tromso. So tromso is a pure play a SPM vendor. Uh, we have an A SPM solution that sits on top of check marks one.
And one of the reasons we're attracted to them, actually two of the reasons. One is, um, um, harsh it, uh, PARIC, Harshel Paric, their CEO and co-founder, um, is has been a CISO in the market before he started his company. He's done a great job of building out a set of agents that will help in triage and remediation of issues, which is like at the core of both what deve developers and, um, AppSec teams want to do when they're looking holistically across all the repos.
So a lot of expertise in some of the products to help accelerate our agenda. Um, and then secondly, the, the talent of the team bringing them in. So accelerate our agenda on the products and accelerate our acquisition of talent.
So it's been really, uh, a great marriage so far, and we're ready to start releasing our new set of agents. Love it. And you know what, as we sit here in the new year, Jonathan, you know, 2025 was gonna be the year of agent ai.
In many cases it was. But I, I think a common thing I hear from people is, these agents aren't so great yet, right? They gotta get better if we're gonna be using 'em.
And I think that's gonna be a key piece of 2026, is getting these, and it's not just security related, but agentic AI in general, making these agents easier, more useful, working the way we think they should work. Um, but I, turning back to AI generated code, Jonathan, I, I need to, you know, I I, I've spoken to a lot of people on this subject. I read a lot of surveys, seen a lot of data.
Here's the thing, when we look at the security of human generated code, the line is kind of flat, right? In terms of the, the, the amount of vulnerabilities, you know, per 100 lines or whatever you want to, however you want to judge it, it, it, it's not really going down a lot, but it's not necessarily going up. It, it's kind of flat.
You're getting, I forgot what it was, 30 vulnerabilities for have X lines or whatever. In the case of ai, that line is going down. It's not the hockey stick line, it's the, you know, it's going down pretty drastically as time goes on.
We're seeing less and less vulnerabilities in AI generated code than in generation before gener. And the generations come right after the one, right after the next. From what I've been told is that we're roughly at a point now where we're approaching AI generated code having the same amount of vulnerabilities.
You know, roar, I'm talking now from human generated code. They're, they're roughly equivalent almost now. But the thing about it is the AI code keeps getting better in terms of it.
And the human code is kinda flatlined, as I said, unless you're gonna apply AI to it, to, to kind of goose it up, if you will. Now, are we holding AI generated code to a higher standard than we do human generated code because we trust it less? Or is there something is, you know, are we rooting against AI generated code is, as it, I think, comes out in your own study, 60% of code is generated by AI today, something like this.
Um, it, it, you know, is it only going to get better, meaning more secure? And are we, you know, are we pining to get 100%? Is it even possible to have 100% secure code?
Yeah, it's, it's a, it's an ongoing debate, Alan, in the, in the industry. And, um, one of the, uh, one of the objective, um, websites out there, and a group of experts, um, are testing every new model as they come out. com.
So if you go out and look at that, you'll see, um, testing of every new model from a security lens to see, um, each new model. How secure are they? And to your point, absolutely, um, the models are getting better.
Um, they're learning, uh, and they're still generating insecure code to be sure, like in the 30, 35% range. And, and to your point as well, it's starting to rival the, um, the, the, the amount of vulnerabilities that a human would, um, put into the market. But there's still vulnerabilities there.
I think what's interesting over time is if you take this out to its kind of continuum, like out into the future, um, at some point, will the generation of code and that code being secure be good enough? In some ways it will be. In some ways it will be.
And that's a good thing for all of us. And that's a good thing for developers. Um, I think the nature of the, uh, of the vulnerabilities though that are there is what's interesting.
I, I think that that changes. So, you know, if one of the things that can be and likely will continue to be prevented, avoided, are some of the basic, um, many of the basic type of vulnerabilities that a human would, um, inject into their systems. I think the harder things will be, uh, not the SQL injections and the cross-site scriptings, but the logic challenges that become very transitive, very, you know, kind of, um, one step removed.
Those will be harder and harder and harder to manage. And AI can assist in those areas. Um, uh, but it won't solve all of them.
And so I, I, I think that we will get to a place where generated code is absolutely more secure. But will there be, if you take that to its, you know, kind of final state, uh, will you need application security or testing for security? I know I'm a suspect being a vendor in the space, but a hundred percent yes.
And I can see the nature of that, just like the nature of development is changing, the nature of security is changing. And so maybe the, the, the traditional static rules of the past may not apply, but dynamic becomes very important in this kind of a world dynamic testing. Um, many other aspects, uh, can be, can be added to augmented to make sure, again, with, uh, with more vulnerability and more surface area becomes, uh, way more, way more, uh, threat and risk.
And, you know, it's, we just got everything under control when it comes to the world of supply chain, open source libraries. If you think about how applications are built today, you know, 60, 70, 80% of applications come from components that weren't developed, right? And along comes AI and the new AI supply chain agents and LLMs and models, these need to be secured now.
So, you know, the more things, uh, change, the more they stay the same. There's, there's more threats all the time. Absolutely.
And, and I think the answer here, Jonathan, is we need, we need to improve the security of code no matter who wrote it or what wrote it or how it got here. If we're putting code in production, we should have a high degree of, of belief that it is, or high degree of certainty that it is in fact secure. And that that's really a, whether it's AI or not, you know, when, when AI is generating a majority of the code, this, this artificial distinction between what was generated by machine versus human is just that artificial or code needs to be secure just like all rights and women's rights or whatever Hillary said back in those days, right?
And, and I think that that could be a mantra here. Um, I think we're about outta time, but Jonathan, where can people get more information to stay on top of check marks? Yeah.
Thank you. So, uh, we have a lot of thought leadership, a lot of material that can help, uh, your audience out there. com, but as a part and on that website, uh, we have one of the biggest, most well-known research groups that are constantly figuring out and identifying new vulnerabilities and the best practices of how to address them.
And we freely share that on something called Check Marks Zero. It's kind of a play on words from check marks one, check mark. Zero is before check marks one, that's our research team.
Very cool. Um, and so there's a blog out there for them where everyone can go there. Um, we're trying to, to your point, make sure systems are secure with the kind of the ever-changing landscape.
So we codify that into the product, obviously. But, but that's for the good of all and for the benefit of all. Love it.
Jonathan, it's great to have you here on Text Drug tv. Don't be a stranger. Thank you.
Thanks, Alan. Really appreciate it. And uh, again, happy New Year.
You too. Maybe we'll see out. You're gonna be out at RSA.
I will be there. I'll see you there. All right.
For sure. Jonathan, Randy, chief Product Officer, check marks here on Textron tv. If we're gonna take a break, we'll be back Control.
This is agent dev. I'm in position. Copy that.
Dev. Stand by for Go Standing by. Hey everybody, welcome to the Agents of Dev podcast.
I'm Mitch Ashley, a lead the software Lifecycle Engineering Practice Analyst practice at the Futurum Group. Brad, welcome. Always good.
Be good to be doing this with you, my cohost. Yeah, it's, it's great to be doing the show with you today, Mitch. And, uh, I think, I think we have a, a fun topic, uh, on hand.
Some something that I, I'm sure a lot of people that are listening in are, are exploring and or dealing with right now, which is the idea of how do you use Ag agentic tools to, to actually build code on day two, not day one. Mm-hmm. Mm-hmm.
Listen, when you go beyond the Travel Agent book, my have booked my flight, find me a flight example on every developer blog, how do you use this ID to actually do, do your own work? So, right. We are talking about, but we're gonna probably touch on three of them.
I know we, we've had a lot of the most recent activity with Google Anti-Gravity with AWS Kiro, some announcements at, uh, at, at uh, AWS Reinvent. And of course, Bob. Bob.
Uh, what about Bob from bm? What and what about Bob? Sorry, I'll never tire of that.
What about Bob a a child of the sixties, seventies? So I, I definitely know about Bob and we of course, you know, copilot, no, you know, cursor and windsurf, and there's all, you know, everybody has an IDE these days, which I can't remember if I said this on a previous podcast, but, you know, I, I thought all those developer jobs were going away. We're sure creating a lot of tools for these people that don't, aren't gonna have jobs.
So I don't believe those jobs are going away. They're changing for sure. That's for sure.
Um, yeah. Actually, you know what, I, I think you're right. Yeah, I, I I like the notion that, um, all of this tooling is going into, um, helping people who, uh, do the jobs that they lost there.
You go to basically do, to do the work that you used to do, but do it in a new way. So you're saying this is a retooling to how to get your next job, next job. Is that what it is?
Yeah. Just, just to get a raise. 'cause otherwise you have to quit and come back.
That's right. Well, I think that's, that, that's an axiom of the universe. I think that seems to be universally true in about every That's so true.
It's funny when you give people that advice, how do you get a raise? Well, you should probably go, go somewhere else and then come back, go get a lot more money tends to happen. It does, tends to be true.
Um, of, of, of the, of the ides, have you spent more time with one than the other? I know you do a lot of development, Gemini, um, but of course anti-Gravity is pretty new stuff. Is there anyone you have more familiar with than the other?
Yeah, well, I, I, as you say, I use Gemini CLIA lot 'cause I, I got into computers because of Ask Arts. I will stay in computers because of Ask Art. So do you have that Mona Lisa still on still, you know, on Green Bar in your It was, it was, it was Jerry, Jerry Garcia, uh, believe it or not, was, was my first like, mind blowing ask art experience.
Mm. Um, and so anyway, yeah. So I I, and as you know, I, I have a profound hatred of electrons, so I, uh, don't, don't use many of the electron based tools, which are quite a few of them right now, because so many tools are based on VS code.
And that's great because it has a rich ecosystem and a lot of plugins, et cetera, et cetera. But I've been, I've been using, if I'm not using Zed, uh, which has a Gentech tooling built in, uh, I for, you know, non Gemini, CLII, I've really been gravitating toward Open Code, which has a degree of what we're gonna talk about today, baked into it. And I've noticed this more and more with these tools that, um, you know, they have two modes and you can just toggle them, you know, from the command line because that's why we use a command line so we don't have to reach and click, um, anyway.
So you can basically just toggle to, to thinking mode or planning mode, and then toggle back to coding mode or fixing mode, or whatever you wanna call it. And it can be anything you want actually. 'cause you can customize those to be whatever you want.
All, uh, uh, was it Claude's, um, uh, skills kind of, kind of idea. Mm-hmm. Yeah.
Skills. Yeah. And, and part of what this, this toggling does to planning mode is to help you to, to set up, you know, a very rigorous or supposedly rigorous, um, methodology and framework for doing something.
Be that creating your new find me a flight app or on day two, uh, fixing your flight app because it's throwing a silent error that you can't trace back to, to the source. Mm-hmm. So Uhhuh, if, if, if you go into planning mode and say, wow, I can't find this error, it will say, okay, he doesn't want me to just jump in and fix it.
He wants me to think about what the problem is to find the problem, to find the steps to resolve the problem, and then we can switch back over to execute mode and, and fix it. And that's spec driven development. Mm-hmm.
What we're seeing right now, uh, is sort of a ma maturation of that, where in a lot of these tools are sort of bringing in, uh, purpose-built spectrum tools. Sorry, these IDs are bringing in spectrum tools. So you have, uh, as you mentioned, Bob has it baked in, uh, KIRO from AWS has it baked in?
Um, you can download and use, uh, OpenAI, or is it, sorry, it's GitHub's spec Kit. Mm-hmm. Which you can actually run in pretty much anything you want.
And these tools basically do a couple of things. They'll, they'll let you sort of initialize your projects if you've never run them in there before. And when they do that, they'll, they'll do, actually, I wrote it down because I did this last night with Conductor, which is this plugin they call it, it's the Google, Google calls it an extension.
An extension a different term. We do. Well 'cause 'cause it's really different than just using an MCP server.
An extension is the entire package built into the surrounding, um, tool itself. And so it can itself include MCP servers. So it's like a mod in, you know, Minecraft or something.
Yeah, totally. Right? Yes, yes.
Uh, for those who don't know, Mitch enjoys a bit of the game. I have been known to partake on a few weekends or two counting this last one. And it's, it's, yes.
We must talk about that, by the way, because, uh, I, I, I found that very fascinating because what, what Mitch did this weekend and sort of, uh, asking agent to talk to him or to create for him a, a sort of means of saying, what does Mitch like to play? I found that really, really cool. I ask it, this is with chat gt, just as an aside, I asked it.
I said, so I do a lot of work with you, you know, a lot of my preferences, I've explicitly created artifacts with you about a number of them, none of them about gaming. But I have asked a few questions. So analyze for me what kind of game, what, what kind of games do you think I like?
What kind of games don't you think I like? And why? And it went through and it said, and it was very accurate.
And it's, it's 'cause I, I have such short time windows. I can't do games that are, you know, sit down for, for a weekend and really play the whole thing. Like my No, no Skyrim time for you Skyrim.
Well, you know, I could, so, so it's possible if it's possible and you don't have to step back in and like there's a whole, you know, storyline that you're following that you have to remember that you talked to this person way back when, right. All that kind of stuff. So if you can kind of step in and out of it, it's, uh, much more acceptable.
So, so even like, um, a Civilization Civ six, I'm not a fan of seven yet, um, but it is com gets complex towards the end of the game, the end game. But I, I can pause, I can save and come back, start over, do whatever. That's kind of the games that I like.
Yeah. And this, so when it, I have to ask, do you have memory turned on in chat GPT? Have you, have you had it turned on for a while?
I have. I've had it turned on for quite a while. Probably two, three months at least.
And I think that that actually speaks to the topic of, uh, hand today. Does it not? Because spec driven development is, is really nothing more than treating context like a managed artifact.
Mm-hmm. That sits next to your coat. I was thinking exactly the same thing in, in getting ready for this podcast, is you can see the parallels between the, the, the, let's call 'em retail versions of these products.
The, uh, Chacha BTS of the world, quad, Claude, et cetera, is very much the same thing as they, they're creating what they call artifacts. And, uh, like you open a canvas that's now an artifact that within some context window within a particular tool, that it's gonna remember those things. And so if you want it to remember, one of the things I did was create a little memory system at one point where I wrote out, uh, remember these things out to chase on?
Oh, you didn't, you didn't make a graph database to that b***h. I didn't have that much time that weekend, but it was experimental. Kind of see how would this work and recall.
And so, um, but that, that's what, that's what these kind spec driven, or intent driven, I guess is what Bob calls. It's interesting to me that we're, weren't we doing spectrum driven development all along kind of Yeah. We kind of were, but now we have a actually integrating it into the workflow, you know?
Yes. It was, yeah. I was actually stories and all that before a spectrum driven human in a past life.
Uh, I was a business analyst. Um, and so I would work with the developers to define the project to, to set all of the goals for the project, to define the tech stack we were gonna use, et cetera. And that's, that's really what these tools do.
Mm-hmm. So, to, to jump back to, you know, this conductor extension for Gemini, CLI, I, you know, had a project that was only, you know, 350 lines long. So very tiny.
And it did something. It was, it was basically a research agent. 'cause you know, we're analysts, so always looking for someone to do some work for us.
Right. Not lazy at all. Um, and, and, um, so when I, when I initialized it, it, it did a number of things and it was, it was kind of interesting because it actually opened up and ran within the CLI tool itself, another CLI tool that had a user interface where it, it was basically a, A, B, C, you just would say it would ask you a question and you'd answer a, you know, and then hit return, or you would enter, uh, just a sentence to say, no, this is what I mean.
And it would guide you through the steps of trying to initialize this project for spectrum and development. And, and what it got to at the end of that process was it defined the project goals, it defined the tech stack, you know, by looking at what I had, which is something we should come back to actually, because it's an ongoing pet peeve. And, and spectrum and development doesn't solve the problems that we already have in these tools.
Just everyone that, um, anyway, it code, it, it defined the overall project guidelines. And, uh, importantly, and I've found this really fascinating, is that it, it identified and documented known blockers, uh, to the projects, to, to getting things done. So a blocker is a constraint or missing information or whatever, you know, would keep the agent from completing whatever task you give it.
So finally found a way to constrain the agent from writing code. That's been the problem with the whole vibe coding, is it loves to write more code for you, more code than you want. Yeah.
In all the wrong places. Say some more. In, in, in, in the kero, uh, IDE it very much has phases, right?
It has, um, planning, design, and development. You're explicit. Yeah.
Just like you were talking about, you go into planning mode and it sounds like that constraint is, before I move forward, I need these things because that's part of the spec process, whether you defined that to be yours defined in the tool, which is a good thing. Sounds like, I mean, you can prototype, you can take it so far, black box some things while you're working on the spec to try out ideas, but still contribute to bat. And Okay, put this in the spec.
This goes back in the spec, you know, to, uh, memorialize make that part of the artifact that you're creating. Memorializing memory is, is like such a difficult part and goes back to context as artifact, which is what these do. And prior to this kind of of tooling, um, for me anyway, I, I would demand, you know, I would type forward slash I think it's memory.
Um, my, my memory's that bad. I can't remember. Um, but at any rate, you would, you would use an internal command to say, remember to, um, that remember that I'm using this version of this API.
Mm-hmm. And because, you know, that's kind of critical and is a big problem Yeah. With large language models.
Um, so it would write that to, uh, Gemini MD file in the root of the folder I was working in or for the whole system, you know, for the whole my laptop. And, you know, if you didn't curate that, if you didn't go back in and carefully manage that memory file to, to get rid of things that have been, you know, ob obviated by, you know, discoveries or changes down the road, you really could get wrapped around an axle because it would be like, wait a minute, Brad said that I want use version X, but in the same file he is telling me to use version Y. It's interesting what memory wa it, what things it will save.
Sometimes it's like, that's not when I would've wanted you to save. Right. That's actually not right.
Right. Which, which goes, you, you were talking about the tech stack earlier, and I find this for just using the, you know, using uh, uh, Google Gemini or chat GT when I'm not doing it inside of an IDE or a development tool is, you know, even when you tell it, the tech stack, first of all, you have, you really need to have a running list of what your development environment is, what tech stack you're using for this project is explicitly what versions. Um, because it will either assume things.
I mean, I've had it like say, okay, go download this. Well, that, that doesn't exist anymore. They canceled that, that they deprecate deprecated that actually, right.
Or or worse, they use a diff totally different package manager than what you're using uv, PEX and pip, for example. It's just like Exactly. Toss a coins manager.
So you gotta be very explicit. I mean, I list everything from mm-hmm. You know, the full development environment that I have set up through, you know, through home brew or in, in that environment to, you know, what are the, what are the keyboard, um, memory, um, macros that I use on the Mac, because I might do some things from automations that way, like, and, and have to explicitly tell it.
Do not suggest that I use things that have been deprecated, do not use, suggest things. You are not in the product yet, but may have been mentioned in a product release. So Yeah.
It's, um, yeah, like, you know, if you're not using robots txt, you're already in trouble. You it should already be there. Yes.
Yeah. Ignore it. I'm sorry.
More, more specific to what we're talking about though. Sorry. I was just, I was just thinking about, you know, protection, protecting yourself, but, but, um, requirements, you know, if you don't have a requirements file, you're you asking for, you know, a misunderstandings, like, like you're talking about.
So you gotta start from a good foundation, especially if this is a brownfield, you know, endeavor that you wanna use spec driven development for. Mm-hmm. And, uh, it actually, you know, it, I would add to that, and, and I know we wanna talk about the, um, tech stack a little bit more, but I, I, I felt from my short experience with Kiro and Bob and now Gemini CLI conductor, that, you know, you need to buy into this.
This is not like a, I think I might use a bit of it here or a bit of it there, or, uh, just try it today and not use it tomorrow. You, you know, are basically saying, I want this to be spec driven, and as such, I'm going to be using an internal tech. Uh, what, what do we, what does, uh, conductor call them?
Um, where, where you have a task, they, they call it, uh, hang on, I'll just look it up. Well, what you're describing is opinionated software. It has an opinion about how you have to develop software and you have to buy into that.
It makes it very opinionated, right, man. Mm-hmm. So they, they call them, um, tracks.
So you have a track and I, I should note that, um, it's very just doing the initialization for, for tools at least like this one in that mm-hmm. It read my code base, it asked me what my objectives were, et cetera, to do all those things we were talking about and setting up the spectrum and development, you know, basically a, a file structure, a directory structure filled with markdown files. And I was shocked to see it come up with the first track.
For me. It's like I, I just finished initializing and it said, oh, I really think that you, you want to do semantic search, um, uh, enhancement, because I, I was trying, um, Gemini's Gemini, uh, has a deep research, uh, which is basically you're not calling a model directly. You're calling a, uh, a, a sort of implementation of a model that that is very opinionated.
And like we were talking about Claude, uh, like skills that that's basically built on skills. Mm-hmm. And this thing, which is, if anyone's interested, it's called deep research.
Sorry, these are all hyphens. When I pause deep research pro preview 12, 20, 25, that is a mouthful. And it, it, uh, it said, oh my gosh, why don't you add semantic search to that?
Because I had a different, I have like a, a different sort of, um, mechanism for doing this outline research, either through semantic search or through the deep research. And it said, why aren't you combining them, Brad, you idiot. Mm-hmm.
Mm-hmm. And, uh, so it's specked out that that track with all the requirements, all of those planning steps that you mentioned to build this, it's really fascinating. Well, I, I'm not an expert in, in any of those tools.
We just don't use them, uh, you know, living inside of them doing, doing work in 'em every day. But it seems to me the kero is the one that's bought into the process as much or more than any of them. 'cause yes, it has those planning phases and Bob is architecting, et cetera.
They all have kind of some ver version of that. But Kero really, I mean, it includes specs for, uh, acceptance criteria, traceability testing, um, yeah. Yeah.
User guides. Um, it's really, you know, AWS made a big deal about where we're using this, this is our development environment across the company. You, you could see how that might be because they put so much into not just doing agent development or using agents as part of development, but making it, I dare I say methodology.
I don't wanna start any methodology wars, but, uh, yeah. Some opinion made stream programming. Yes.
Yeah. Well, I lived through a few of those. The agent wars are upon us.
Mm-hmm. But where whereas, um, like with anti-gravity, you can definitely see that they've leaned heavily into the agent first. Uh, ID, you know, using multi-agent orchestration to do work for you.
Right. Yeah. And I don't remember if they explicitly call it spec driven, but a, a, a version of that it doing and screenshots that's like open code and uh, you know, they just have it built in as different modes of work.
Mm-hmm. You know, it's, uh, one of the things I'm curious too is uh, 'cause I think antigravity is supposed to be good at working at much larger code basis, and that's sort of the, one of the, there's lots of challenges and different vendors have taken on parts of it. And when you work with much bigger or multiple code bases Yeah.
Keeping that, that in the context window and the memory working with that know where you're, you know, God forbid you say, you know, Hey, put in that search and whoops, that's not where I wanted it. That was a different project. Right.
Um, but that's part of the complexity too, than being able to take on more complex work, not just coding tasks or types of code to write, but the work of writing code in the environment that you're doing it in. Yeah. That's a big deal, isn't it?
And that, and you can see that reflected similarly to Kiro in IBM Bob in that they have built in using their, what would you say, 50, 60 some odd years of experience with cobalt not to Yeah. Come back to some something called punch cards. I think, wait, D switches on a computer.
I believe those, those exist in their osi. They, they have fine trained, fine tuned. Sorry.
Wow. They have fine tuned, um, their, you know, the models that they use for these specific tasks, like you're talking about in managing a large code base mm-hmm. To, you know, they were early to, to come out with this sort of, let's use LLMs to refactor from one language to another or to trans transcode and, um, with, I think it was COBAL to Java that they did.
And that has grown into Bob and it plays a role in Bob for managing large code bases, not based on what they got off TE stack, sorry. Um, stack overflow or God help us Reddit. Uh, it, it's actual like, you know, IBM you know, professional services, you know, use case number two nine x 94, uh, has a very, you know, distinct solution and pat design pattern that's tested in, you know, some World Bank and now you can enjoy that and use that to solve problems across a complex code base.
Love that. It is, it is interesting. Yeah.
The Bob leaned into the modernization path, right? Helping people modern modernize. And a lot of that is, of course, the l LM that they're using are LLMs, uh, by default.
Um, which pushes that button. You know, the, the other we haven't really talked about, I dunno if you considered an IDE cloud code, you know, is something you plug into your IDE or you can use it very much from the, the command line, but essentially you're doing the same thing instead of them issuing their own VS code version. Um, you do it just like you do with, uh, I guess it's Klein is what it's called.
I've used it for a fair amount on a project I was doing a while back. And then, um, same thing for, for, uh, for open, open AI's models that you, you interface to it either through a window, uh, in the command line on a, in your IDE as well as directly on the command line. So there's sort of these different phases of, seems like so far, anti-gravity is kind of the most opinionated in the user experience of we wanted you to work this way.
AWS kiro is the kind of development process. Opinionated. We want you to work through these design steps, these with these requirements, spectrum and steps.
Bob, on the re-engineering side, we'll see, but Bob was, is pretty early when we saw it, so we'll see where it goes. But the, the tracks that pe different people are going, and you can see part of it is the customers that they serve. Right.
Lean, heavy, heavy into agent development for Google. That makes sense. You could see why IBM would do more of a refactoring and, and helping people modernize code.
Yeah. Because you know how we used to talk about data gravity, we still do. Um mm-hmm.
Data has gravity. It's all designed around locking your data into a platform that you'll pay for you in perpetuity. Um, it's called cement.
Cement boots. Cement. Yes.
Yes. It's very lucrative cement. Um, but it, you know, developer gravity, it means a lot.
It, it always has and it always will. And what I see evolving right now, um, is this sort of, you know, my walled garden, my semi walled garden is better than your semi walled garden either because it has better models in the backend or better tooling on the front end, uh, or better services in the middle of the two. Mm-hmm.
And so, you know, these are all I've said for a long time that the, you know, the frontier models were always meant to be platforms, not just models. And they are absolutely evolving into that. But the tooling, you know, the things like you and I have been talking about today that we decide we like something and, and so we invest time in it.
And if you invest time in it, this thing, you know, that, that we all know and love, uh, called not entropy, but, uh, uh, what, what is it where you build momentum and can't stop the momentum from going, um, can't think of it. It's not brownie in motion. Inertia.
Inertia. Inertia. Yeah.
You need to think about the second thermodynamics that inertia carries forward. And you know, the more in an organization that they get a nerd in these tools, the more likely you are to buy this backend services models that, that are associated with them. And that nails it.
So you see, like, you see like all the, all the investment right now in, in, I think making these enterprise grade is critical and really a, a good step. Um, 'cause this is, we are, we have changed how we think about code, have we not image. Mm-hmm.
Absolutely. It is, this is first time that I can think of that it, we really are buying into, at the very front end of the development tool, the IDE of how we're gonna develop software, right? It's been more of a window into our repository and tools and plug areas.
It's been the Swiss Army knife, right. For development. Um, I call it the, uh, smoking shop.
You know, I I I they're all brands of cigars, but we'd like you to stay here and smoke them here. That's right. We have a lovely room with leather chairs.
Just sit here. Yes, exactly. This is where you should stay.
Not that everybody out there smokes cigars, but, and I don't that much either. But anyway, it, it, it, it, it is an opinion way, opinionated way that organizations, when they sign up, they're gonna use this tool as their IDE, then that's the path they've kind of chosen to go down. So yeah, it's, it's, um, you know, how, whether it's cement boots or walled garden or a lighter touch Mm.
It's to keep you in that environment. Of course, they work really well with their technology and make it easy to do that as well as work with, uh, third party stuff. That's the key with the platform, you know, oriented tools, the hyperscaler oriented tools you see from like Kiro and Bob, like we've been talking about.
Kiro, you know, is steadily surfacing functionality that's been, you know, sitting inside of Bedrock and, um, their broader AI platform, for instance, SageMaker for some time. And that's only going to broaden out, you know, I, I can see all of their analytics tooling, for example, starting to, to be baked in with, you know, headless business intelligence being a part of your application development process. Your spec will have a spec on how you want to visualize data and work with data, for example.
Very good. Well, we've, we've overstayed our welcome here on little long time. Yeah.
Sorry. It's, it's the holidays. It's the holidays.
Mitch, I think, you know, I think we're being watched and, you know, we're being trailed here, so we should, uh, get to our last segment. Last segment is the drop. Okay.
It's time for the drop. Well, you know, it's, it's, uh, end of end of the year for, uh, us going into the, the next year. We're, we're obviously deep in our planning cycle, kind of towards the end of our planning cycle.
What we're working on, there's kind of two areas of focus that I'm looking at right now. One is how are we moving observability, uh, security behavior governance into the development process using agents and, you know, companies like, like New Relic and Dynatrace. And I could go down the list of companies who have been part of announcements with some of the major vendors that they are now part of AWS's security agent or Dev DevOps agent, or pick your vendor.
Um, so other parts of the software develop lifecycle are not waiting, um, not every vendor's doing this, but I think the folks that are wanna make sure they're carving out a path for themselves to be part of this, uh, kind of AI SDL or AI dl. See, um, very much more please. More.
I'm, I'm, I'm warming up for New Year's Eve, I guess I don't know what I'm doing, but anyway, that, that's definitely on my mind going into next year, uh, as well as many other things. How about you, Brad? Uh, yeah, and I'm sorry, the, the longer the acronym, the better, you know, three letter acronyms are aren't even trying.
I can'ts really put some effort. Can't approach the one you gave the, well, that was the name of something, but you know, it was the name, right? Yeah.
Yeah. Um, so I, I think for me, and, and uh, it's interesting, given what you just said, it, it jives with, um, one of the predictions I have for the coming year, which is that data engineers are, are going to morph a little bit into integration engineers and that companies won't be buying their data platform based on, you know, the specs of the platform as much as they will the meet the way that that platform integrates with their investments that might be, you know, with other vendors on other platforms. So it's definitely, you know, changing how, how these age old, these stable jobs that we've had in the industry for so long.
Um, for me, what's on my mind right now that I'm trying to like wrap my head around a little bit is I, I saw a note from one of my colleagues yesterday talking about how, um, age agentic development was going to break the database. And I'm thinking, well, I, I don't know, because we, we built databases when we had very little resource to play with and we built them in order to scale massively and be concurrent as possible across that scale. And, um, so I I, I think the problem isn't so much in doing reads and writes 'cause we, we'd know how to do that and mm-hmm.
Pick your database structure. It doesn't matter if it's, you know, a blob storage or column or NoSQL or, um, you know, KV cache or wide, you know, field wide table, sorry, um, like Cassandra, it doesn't matter. They, they all are pretty darn performant.
Uh, the problem is agents, you know, need instant context. They need, and I, you know, I think you and I chatted about this a while, a while back mm-hmm. With, um, if you're outta sync even a little bits, um, big, big problems can happen.
And so timely access to accurate information is critical. And how do you do that? Well, you certainly aren't doing a query from a, you know, data warehouse to do that.
You certainly are bringing the data closer to the code, to the agents, and, um, you can do that through streaming, uh, which is why we saw IBM pick up confluence. Uh, that's kind of a big deal. And another way is the developer's favorite pastime, which is caching every you and managing cash almost every, yeah, ev almost every problem can be solved with caching.
Um, and uh, and it already plays a big role with the agentic tools we're talking about, like, every time I hang up from a session with Gemini, CLI, it tells me that I saved, you know, 80% because it had that many hits from cash, that percentage of hits from cash. Wow. Like, wow, I really am forging new territory, aren't I overdose to your manager?
You know, you say, you know, it's like they already are you saying two, this, this trip to the grocery because Brad is so boring in what he does. Everyone's doing the same thing, um, in post post. So I trying, trying to think about, you know, how companies can speed up, you know, access to data for, for agents latency, agent latency, waiting for those, for the data, the context that it needs.
Very interesting. Yeah. Well, my friend, it's been fun, um, a lot.
I have so many ideas for, uh, things for us to talk to. I know you, you do too, so we'll keep 'em rolling. com if you'd like to make a suggestion.
Uh, if you're interested in making an appearance, maybe being part of this, we've got some folks that are interested in doing that. And, uh, we're, we're kind of getting the, getting things rolling with Brad and I, and then we'll start to have some guests as we do that. So send us the feedback.
Thanks for following us on your favorite podcast platform. And thanks for coming back to listen to, uh, to US Jawbone for a little while about building software in this new AI agent Agentic era. Uh, behalf of Brad, myself, it's been fun.
We'll see you on the next episode. Control. This is agent dev.
I'm in position. Copy that. Dev.
Stand by for go Standing by. Hey everyone, welcome back to our live coverage day, one of Amazon or AWS Amazon Web Services reinvent. I am really happy to be joined by this guy here.
You may not recognize him. He looks 10 years younger. Sand's the goatee, he's lost weight.
Come, he's in fighting shape. My friends, you know, the Steelers could use some players. Maybe you can help us out here.
You could watch that. That was bad. They would, they would pitiful.
That was, I was proud of Aaron to come up and basically say with no, just say, oh, afterwards We need to do better. And I'm part of the problem. You know, like that's As there's a leadership message there, right?
I mean, I I do, I give them credit. It doesn't make it hurt any less. I think there's a lot of parallels.
AWS they're, they're doing that right now. They know that they sort of missed the first wave of this AI pivot. 0.
And they're recognizing the things they need to do and they're, and I think they're making those pivots this week. They made a really big pivot. I thought you were gonna tell me Matt broke his, had a bloody notes too, but No, um, That was good though, right?
Yeah. That I love track the way you brought that back to you. It's like, I've been here Before.
Absolutely. So if you don't know this gentleman, Daniel Newman, CEO fu group, he's my friend. Um, I love working with him and he always has great insights.
Like this little tidbit you just brought us back to AWS So we, I was talking with Mike Ard this morning. Certainly this is all AI all the time this year at Reinvent. Um, what's your take?
I mean, obviously they're making a pivot. They're going hard at ai. Well, I think they recognize, so we are in the era of AI cloud and, you know, future and we do our signal evaluation.
AWS did not score in top two, did not. It, it has fallen behind both Google and Microsoft in this era. Now, AWS has this massive advantage called a humongous customer base.
They have a huge customer base from the first cloud era. And by the way, anyone that's worked with CIOs as long as you have, I mean maybe as long as I have knows that in the enterprise, it's not the same as the consumer, right? And it's not the same type of pace of sentiment.
There isn't a new thing that comes out and everybody just ditches Google for chat GPT when it comes to cloud. These companies are deeply integrated in AWS And so while this AI pivot maybe has forced some companies to do more multi-cloud and have seen some workloads go to Google and some, the opportunity is still really in place for AWS. So they had a couple of big things they needed to prove this week.
Uh, the first thing they needed to prove is that they really are the place for the enterprise to commit building ai, generative AI applications open up to more developers. com community knows really well. Sure.
Um, that they have infrastructure, that they have an approach both their partnership with Nvidia and making sure the market understood that they have the Nvidia they needed. That was something that early on they maybe rotated a little quick to their homegrown train chips before it was the right answer for a lot of their customers. And then of course, um, you know, they needed to, to show that they could really open their, um, aperture to the developers of the AI era.
You know, and I kind of, I kind of glossed on that, but like, you know, they, they focused on that, what their announcements with Kira with their announcing there. Yeah. Um, agent Core with the ability to build agents, they need to be the place where people are building the applications that run their business.
So they had that mission this week. I think Matt Garmin in his keynote, he always gives a good keynote. He's a real product guy.
Absolutely a real product guy. He really is. He, you could see It, it was a very product kind Of that's the A WSY that is the AWS Y.
And, and of course, you know, I think the one thing that they, in the last 10 minutes they did like a speed round of every other announcement that they had, you know, uh, Kubernetes and all their regular instances and CPU instances and storage buckets and everything else they're doing. Mm-hmm. Um, but like you could tell this was all about being a prove it moment that we are a cloud that's ready for the AI era.
And I think they did a good Job. Absolutely. Couple of, you know, plays off of what you said.
Number one, you're right, this almost wasn't about cloud. We didn't hear as much about S3 and Lambda and Serverless and all these cool things that AWS pioneered. We did hear a lot of ag agentic, ai, you mentioned DevOps actually one of the three main agents that they announced they call the DevOps agent.
Yeah. Which we, you know, I thought, you know, tip of the hat to them for that. Um, another thing they announced though, and I don't know, maybe it didn't register on your radar screen, is, um, what's it called?
The Forge. Nova Forge. Nova Forge.
So I look at that and say, wow, that gets me excited. And, and then I think, well, how many organizations do really want to build their own foundation model? Well, and that's a great point.
And, and that was something I probably should have had on my third thing in the first list. But first of all, Amazon is part of their prove it. So I mentioned, you know, the train and the vertical stack of infrastructure.
They talked a lot about that. But the other part of the prove it is I talked to, uh, investment, uh, bankers. I talked to other analysts.
I talked to media and press regularly of, I talked to enterprise customers. A lot of 'em didn't even know Amazon built models. Right.
So, you know, they had Titan originally they did Titan, and then they really went in with Nova. But like really open the market to understanding that in that business. 'cause that really is the complete, we have all the compute mm-hmm.
And all the infrastructure. We have all the developer tools and frameworks, and then we have the models, right. And being able to say, like, and then of course Bedrock, where you can basically bring all these models, you plug it in, and you, and you deploy the, the, the applications.
That is the full stack story. And you know, you saw last week when people started to get the idea that Google and TPU could be a competitive offering to the sort of open GPU era. Mm-hmm.
Um, specifically Nvidia, but it could be a MD, it could be anything. Um, and despite the fact that I would argue that most of what was presented is not quite factual about that, the thing that's made Google so attractive, the reason it's risen to all time high is it's market cap. So you're saying what was offered by Google?
Not what was offered by AWS or both? No, no. What I'm saying, well, first of all, I'm, I'm eventually gonna get to my parallel.
It just takes me a while. But like, okay, but what Google's doing in the full stack mm-hmm. Has given the market a lot of appreciation for Google.
Yes. Now Google is unique and they were Rewarded. It's corpus of data is unique.
It's a little different. But Amazon has quite a bit too, from its ads, from its commerce business, a lot of very unique data. And of course it has a lot of enterprise data, which is where the majority of data still actually sits.
But Google's finally getting credit for being full stack. They're getting credit for saying, Hey, you built TPU, you've built the networking, you've built compute chips, you've built, uh, they Have the vertical stack. You've built the agent and applications and Vertex and builders.
And of course then the models Geminis proving to be very good. Amazon wants to follow suit. They want to say, Hey, we got Tanium.
Hey, we've got Nova. Hey, we've got Agent Core. Hey, we've got Kira.
Hey, we've got like all the things that you that are required for basically an enterprise to say we can run all our AI in one cloud potentially makes it more valuable. Amazon hasn't gotten all of credit for that. And so this was an important inflection.
Now we had to see how much the market digests that. Yeah. And how much they believe it.
Let me ask you a question, though, at the Traum chips and the Google TV too, is this really a competitor to Jensen and the Nvidia people? Or is Broadcom? Well, Broadcom makes the chips for, for, for Google.
So Broadcom is the full end-to-end design. They do it all. Um, But not for the Amazon tra No, no.
TRA is different. TRA is Marvell. It's all chip.
It's actually sourced through a number of different suppliers. Um, but, but largely Marvell. Um, I think the right question here is are custom AI chips competitive to merchant silicon and specifically the Nvidia ecosystem?
And like I said, to a lesser extent, you could argue the A MD ecosystem. Sure. Well, they, they're the up and calmer.
Yeah. But like, I think the answer is, and I I I think we've talked about this, we've market modeled it. We do believe the custom chips will actually grow faster towards the end of the decade.
And here's the reason why. There are a small subset of companies that are the largest buyers of infrastructure compute. So there's a benefit.
And the reason Google really invested in, and now remember there's seven generations in. It wasn't like they came out with a new chip and everyone's like, oh, it's gonna replace Nvidia. Seven generations in, I think in their six generation, they were able to train a first kind of high performing, large language model, Gemini advanced that was on their own infrastructure, which was a big breakthrough.
'cause obviously before the idea was like, everything has to be trained on Nvidia. So that's, that was a pretty big inflection. But it, but Google, you think about what Google does, it does AI all day.
It's doing massive volumes of infras of, of inference all day long on its own infrastructure. It needs to think about its margins. So a company like Google that's doing that much scale, of course, might look at, Hey, here's three or four specific workloads.
Let's build a custom chip that really works for everything we do for search for recommendation engine. Mm-hmm. We'll build a scale, we'll invest big upfront, but our, our, our cogs will get a lot better than when we don't have to pay that 75% margin to Nvidia.
Having said that, though, like the, they're always, at least as far as we see it gonna be probably one if not two generations behind in terms of the most advanced NVIDIA chips. So token economics, inference, uh, efficiency, uh, performance, memory throughput, all those things that are really critical to training, uh, pre-training to doing large models, um, but also just to scaling tokens in like age. Agentic eras may or may not be as efficient on those, um, on, on the custom chips when you need the flexibility.
And so what I think ends up happening is it's really our, our vision of the AI market is it's all hands on deck. You'll see me say this anytime you see me talk about the bubble. And social is like right now, every single wafer that TSMC can produce a chip on is being sold.
So Nvidia has a certain amount of capacity. Broadcom has a certain amount of capacity. Broadcom can make a certain amount of units, and every one of them is being built these companies.
So you gotta expect, by the way, not just Broadcom, it's others, but Amazon, Google, Microsoft, Oracle, ai, um, they're all meta. They use so much AI that they're gonna use some of their own chips. And by the way, this isn't new.
They've been doing this for a while. We've seen the arm movement with CPUs that moved certain workloads off Intel and off mt. Right.
This is a business decision, but it's not necessarily because they believe it's the most performant of the best technology. They're trying to fill gap, hit margin levels, understanding that not every workload needs to be on the most advanced chip. And, and of course in the end, they're looking at delivering EPS value.
And Absolutely. If they're meta and they're doing ads, can we build a lesser priced high performance chip that just focuses on serving ai, AI slop to us all day long? As we, as we, as we run around our meta Application, there's, there's, there's a world for AI slop, but you know, it it, but this is not a new strategy.
No. Right? It, it, it was always, it reminds me of when I first got into security 25, 30 years ago, Asics, ASIC based security appliances.
Yeah. This was before we had SAS or NY of that Stuff. Just asics too.
Right. And, and that's what, and back, basically, it's the same stuff over, you know, history repeats itself. You just, that that's what we're dealing with.
And you know what, for certain security functions, you know, custom made asics still Penny for penny dollar for dollar gave you the best bang for the buck As long as it was for the right use case. Matt. It it's that narrow use case.
But it's the same thing here. Metas serving ads is, is a particular one. Um, I'd still look, if I was a betting person, I like NVIDIA's, you know, seat maybe better than some of the other players.
Yeah. But if, if they could maintain just one or two generations behind Daniel, that's a lot of value. Freaking market.
They Get a lot of value. There's a lot of need. There's a lot of, um, you know, sort of deprecated workloads, just like on compute.
Like people didn't just throw their last generation, uh, data center server or CPUs away. They, they used them for less important workloads and they would, you know, they would prioritize new workloads and they would upgrade and they would replace, and they would add. Right now most of what's going out is, is is new.
Right. Um, and interestingly enough, like, you know, Nvidia, I say it's three to five years minimum before the custom chips could eat meaningful market share, if ever. And I still think it's more of an and than an or.
And I think there's a lot of kind of, of the, the biggest risk to, to NVIDIA over time is as these big buyers, the ones that are buying so much of their technology, are able to do more and more on their own chip and with their own margin structure, is will that create any margin pressure On Nvidia? On Nvidia? So it's not so much volume.
I think if anything in the risk is more sits in the margin. But then there's other things too, like that Nvidia does. It's just so unique.
Like their, their entire backbone being optical. Yeah. And you know, like, you know, n well, they Don't, And Spectrum acts like, you know, but they, their, the transport that between the GPUs is so efficient and so fast that like, the latency issue is really, when you talk about clusters of this size, it's, it's, it's really meaningful.
Like until we get co packaged optics on, on all the backends of all these, of, of all these spines and everything, it It, look in my day it was the buses. Yeah. Right.
On the, on the motherboards and so forth. It's still your forth. Well, it's still my day.
I've had a long day. It's so hard on yourself. It's been a long day.
But it, it was the buses and that, you know, that latency in there. But what I think the other thing is, you know, necessity's, the mother of invention, it keeps Nvidia on its toes to be constantly innovating, to be constantly staying that one or two generations. And they've been great at that talking about, you know, Blackwell three hundreds are, are now ramping shipping and volume.
Uh, we already know Ruben's coming and we know Feynman's gonna come after that. They're coming out two generations a year, by the way, that's very hard to do with custom. It's very hard to do.
Like I said, there's a few companies in the world that can do it. And then the thing is, is like it's all run in their cloud. Like I will really, like, I've heard Foxconn's ramping up building servers with the Google TPU chip that could be sold outside.
But like, um, I think there's, you know, like NVIDIA's a merchant silicon company, meaning that enterprises can buy it. Neo clouds can buy it. Like, you know, like, is Amazon gonna really buy a volume of Google chips like ever?
You know, of course not. They're probably gonna build their own. I mean, Meta's unique, Meta's not competing with the hyperscalers though.
Meta's slightly different. Well, they have a different, they're not the three hyperscalers, They're not the, they're not the selling cloud services In terms of a cloud, but they're a hyperscaler in and of themselves. But they, like, the net of it is, is like, I just think it's, it's all hands on deck.
I I think that, you know, we're hearing by the way, it was $1 trillion of expected AI infrastructure by like 20, 29, 20 30. You got a fancy game Going. We're getting, we're getting a point thing going on live here.
I don't know, it's ESPN though. So, but, uh, But um, now that number's been risen, possibly two to 3 trillion. So what I'm saying is like, look, we do market sizing.
We look at the market and it's kind of simple. There's market size and overall tam and then of course there's margin in the TAM risk. And so on the, on the market size, it's like the market just keeps getting bigger.
We're building out 65 gigawatts right now of capacity, um, up to 80 here in the us. And I mean, you look at, the numbers are anywhere from 20 to $50 billion of spend per gigawatt on infrastructure. It's massive.
And so, like, they can't build enough TPUs, they can't ramp the supply chain fast enough. And that's another thing is like, we know Intel's on the way up and Intel's going to win, uh, more and more foundry Deals. Some percentage of it has To work.
No, it literally has to because there's No other way. TSM Can't build enough fabs fast enough. So, but what I mean is every wafer is gonna be sold.
And so right now, the point is, is like every wafer and every chip that that Nvidia can build is gonna be sold their backlog where they have half a trillion for next year, half a trillion order of visibility to next year, not including their open AI deals, not including their open AI deals. So a lot of people are like, well, what's open AI risk? Well, this isn't, it's $500 billion of potential sales between now and 13 months from now.
It's incredible. Not every vendor has that cushion though. No, not Everyone does.
But but my point is, is like if, if real realistically A TPU or or a train was a risk to nvidia, you would start to see it show up. They, I Don't think NVIDIA truly has a real risk on the horizon. No, But they're fighting that battle in the market every day.
Absolutely. The market is trying to create the FUD that they do. And what I'm saying is they don't, but it, again, it's not zero sum.
There's so much zero sum thinking. It's not at the cost. Crazy.
Alright, A-A-S-E-C, let's clean that up, um, at the cost of Nvidia. And that's my big problem, is like, look, maybe over three or four or five years, you'll see some maybe Nvidia shed a couple points of market share. Maybe the TPUs and the XPS will gain a few points.
Maybe a MD will get a few points of market share. I expect all these things to happen. Mm-hmm.
I mean, expect I ThinkTel market, Qualcomm and others that are eventually, but the market's huge. There's enough, right? There's enough to lose A few points.
So, so, you know, if you're modeling, and one of my models are all saying is that NVIDIA's gonna be bigger than we thought it was a year ago. It's gonna be bigger than we thought it was six months ago. And even while all this other stuff is starting to take some market share, they're still growing.
Tam, it's a problem that, you know, we wish we had in the research business, you know, that there was that much demand, but like the God's ears, it's, you know, the bottom line is, is that I just don't worry about it. The bottom line is Nvidia, the $10 trillion company could Be, there's no reason it, I think it'll be six next year though. All right.
You heard it here, Daniel. I want to pivot and switch gears a little bit. I want to talk few terms signal.
Okay. Uh, we've been talking about it here on Techstrong TV and in our tech strong stuff. And you know, look, you and I both know, right?
A good percentage of our market is all about up and to the right. It's just, you know, the way we were brainwashed, I guess coming through. Talk signal to our audience a little bit, what makes it so unique and so special and why they, and, and guys, you don't have to buy a subscription for today.
It's available to you right now. You don't need a, you know, all of the other stuff, but Talk. Yeah, I mean, we, we believe there was a fundamental problem with the way technology's evaluated.
You see, uh, models being introduced weekly, monthly with meaningful improvements, scaling laws mostly still intact. But like the improvements you're seeing between GPT-3 and four and five, or Gemini one and two and three, or even just, uh, the, we just talked about Nvidia a whole bunch. Like twice a year, they're able to roll out a major release, upgrade cycle or release of their stuff.
But yet, right now, if you want to evaluate those technologies, you work with an analyst firm, you, you do a year of interviews and meetings and you fill out forms, and then you, you get a report that comes out and it's six months outdated, maybe a year by the time it gets published. And largely by people who can't touch the stuff regularly. So you've got all kinds of just mismatching now in terms of technology and enterprise decision making with technology.
So the simple question is, do we eat our own dog food? Do we drink our own champagne? Are we in the business so we thought we could solve the problem differently?
And so the the reality is, can you build a pervasive, autonomous, uh, evaluation platform that really offers true market intelligence, competitive intelligence, that can look at a, in an important, say, agent platforms, say neo clouds, say, uh, CRM platforms. It can look at it up to the minute, can actually really distinguish, uh, it can look at the voice of the customer. It can look at the market models and growth data.
It can look at CIO decision data and, and it buyer decision data. It can look at the analyst perspective and it can really create this thing on the fly to completely revolutionize how buyers are able to be matched with the right vendors and have the right supporting evidence to make a buying decision. And so we built it and we built it in a way where, look, this thing is completely real time.
This thing has the ability to take every piece of information, hence signal that comes. It could be a S one filing from a acquisition or from any sort of market filing that the company makes a, a report that they put out. It could be earnings, it could be Voice of Customer Day.
We did an exclusive partnership with G two. So every, you know, they have millions and millions of reviews. It could be all the analysts, uh, you know, the fu yeah, the briefings, everyone in Futurum it could be, uh, conversations had with Techstrong.
Uh, it could be Tech Field days where we bring experts in and, and, uh, advisors in to talk about different products. It could be the briefings that we take. It could be events and press releases that come out of these.
Why can't we use all this signal in real time to help evaluate the technology? And by the way, I got feedback today. It was great from, you know, from an enterprise buyer.
And they basically said it was the, they looked at our age agentic report. They said it was the best report they'd ever seen in terms of truly comparing all the age agentic offerings. And then they asked me, they go, how much of that was written by people and how much was ai?
And I said, it was a hundred percent ai, a hundred percent ai, big prompt, all ai. I mean, there's a human in the Loop. There's no, there's a ton of work that went into this, but the actual content was written by ai.
But using all those inputs, that massive corpus of data, and by the way, this is just for this kind of evaluation, but the beauty of this is this can be for everything we do. It could be for economic validations, total cost of ownership reports. It could be for insights and, and reports and research.
And like, the model is slow. It's broken, it's not immediate. Like we have to be as fast as the news cycle every week.
Like two weeks ago, the TPU wasn't a thing this week, it was a thing. The analyst has to be able to look at what does all this noise mean? And if you're a buyer, what should you be considering right now, the current way this is done, you won't have anything meaningful from the market.
12 months, three months, six months, 12 months. 12 months, three months to get a paper. Yeah.
12 months to get an evaluation out. And so we're like, with Signal, what we're really doing is we're saying, Hey, how do we do this faster? How do we make it more accessible?
And what we're doing, by the way, is you, you've only seen the beginning. I mean, you've heard my story in the background, but I truly believe that this is all we're doing right now is the Netflix version of shipping DVDs. Right?
We've created, we've shown the market that we can do this much faster. It can be high quality and it can be a better experience than going into the store and running a video. But realistically, this can be streamed, this can be real time, this can be inter continuous active, continuous, it's continuous.
This can be comparative, this can be so many more things. And why in the world would we want to just continue to settle? And why would we wanna allow this industry to continue to evolve?
It's such a slow pace when the stuff that we're evaluating is evolving at such a fastest Is, is lightning speed? One last subject. I'm gonna let you go, please.
No, Please let me go if you like, if you like what Dan, and you know, Daniel knows a thing or two about the market, about, about the CPU market and, uh, the tech markets in general. You recently launched Futurum equities. Yeah.
Uh, I guess it's been six months already, hasn't it? Yeah. For people who, and there are a lot of you out there who follow the markets who are investing, how, what's the best way to follow you on, on RUM equities?
Yeah, Look, I real quickly, you know, the, the stocks of the tech companies and the technology itself are inextricably linked. Like there's this belief that like industry versus equities is like two different things. It's not, um, the data that feeds decision makers and hedge funds or, or, or, you know, investment banks to buy stocks, uh, is the same data that CIOs are using to decide whether or not to use technology.
I mean, they, they absorb it differently. They read it differently. Maybe the modeling is a little bit more spreadsheet versus a little bit more practitioner.
But like, we basically realized that we have so much insights, so much knowledge, so much signal that we built future equities to basically do the same thing we do for industry. But just put a little bit of a different lens on it. So mm-hmm.
We built a great team. Uh, you know, we've expanded the, the corpus of data. We've taken a lot of the market sizing and modeling that we're doing now to help us sort of assess which companies are, are good investments.
Now, again, we're not advisors, we're not making recommendations. We're providing Signal or Alpha like they like to call it to, to investors. And, you know, we're using that platform and some, you know, platforms like, like Substack and Reddit and, and X where investors sit really heavily and we're kind of taking all the great work we're doing in Signal and in our lab, uh, and in, you know, across our, our, our analysis.
And we're creating content that's really designed for, for that audience. And, and within the next few months, we'll actually be launching True Sell side research that'll help, um, you know, audiences make, you know, we'll have some, some our opinions, uh, not advice, opinions on whether things are are a good buy, what things should be based on models, what the price is. And by the way, we're doing this with just like Signal.
We're building it completely autonomously. We can create these reports based on all the insights and data, everything we have that's publicly available, very clearly firewall. Mm-hmm.
Put them in different S3 buckets by the way. Okay. Uh, totally making sure that we're in, That's our a Ws reinvent kind of hook in there.
There you Go. Um, and basically we believe that the, the markets, the media and the, uh, enterprises all are symbiotic and we're gonna address all of them. I love it.
Daniel, I know you were busy and we pulled you up here. Nothing to do. I appreciate you always, man.
Always. Alright, thank you. Good to be with you.
Futurum Equities, Futurum Signal. We're gonna be, I think this is gonna wrap up our Day one reinvent coverage. We've got a full day tomorrow.
A lot of good stuff. Our friends at Cuse will be back on with us tomorrow too. We've got a lot to cover with them as well as AWS themselves.
But for today, hey man, this is Alan Hummel, Forex Strong tv. We're out. Have a great day.
In the modern security landscape, lists are not the way to get things done. You have to start thinking like the people that you're defending against, and that means lots and lots of graphs. In this episode of the day, podcast Security Needs Graphs.
Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often associated with one of our events. Tech Field Day is a part of the future and group, and this podcast is also published on our sister company's website, tech Strong tv.
On this episode, we're gonna be discussing security specifically around Microsoft. But before we jump into that, lemme introduce our guests for the day, starting with Gerard. What's going on?
Everyone? I hope everyone had a great holiday out there. The tech world and in the real one, Gerard Linas here.
Uh, I'm a network in security engineer for Aqueduct Technologies, and I'm also the founder and creator of Tech House five seven. Oh, you can find me on LinkedIn, Twitter, TikTok, wherever books are sold. Super excited to be here.
Great to be here. So happy to, uh, be a part of this story. I think at this point, uh, you would say I'm the Chief Product Officer at Nexus Tech.
I write a lot of things. org and I'm looking forward to the discussion. Alright.
And my name is Tom Hollingsworth. I'm the event lead for all things related to security here at Tech Field Day. Let's jump into today's episode.
You probably had an opportunity to listen to our special tech Field Day exclusive event with Microsoft back in October where we talked about some of the exciting new updates that were made to Microsoft Sentinel. But as we get closer to the end of 2025 and now into 20 26, 1 of the things that we wanted to do was kind of revisit some of those ideas because I think that there's a lot bubbling under the surface that people really need to understand. And the premise for this episode is that security needs to think in graphs.
Before we jump into that though, I wanna talk a little bit about the data part of this. And you're, you're thinking to yourself, well, Tom, you just talked about why graphs are important. Hold that thought, because we have to build a foundation before we get there.
One of the things that Sentinel has decided to do, I'm sorry, Microsoft has decided to do with Sentinel, is they want to build a giant data lake for, uh, products to be able to reference whenever they're pulling data and things like that. And this was one of those things that I think was mentioned in the event that kind of flew under the radar, is they really are building what I consider to be a, an ocean sized data lake, a great data lake, if you will, because one of the things that Microsoft talked about was the fact that they wanted to be able to let users and, and organizations keep data for up to 14 years in this data lake. I wanna give everybody a frame of reference for that, if you will.
14 years ago, I got my first Mac, it was a MacBook error. I finally convinced the boss, Logan, buy one. If I could keep 14 years of data in a data lake, it would literally be everything I've ever created for this job and then some, and I can search through all of that to find data.
Like is this a thing that's important for people in the, the industry? Like you guys are the ability to keep all of this data for relatively low cost? From what I understand, I mean, I wanna jump in because I think what's really cool about it is, right, as, as an IT professional and working at different layers, you know, from help desk network, you know, infrastructure, all, all my yards, it's like when you have data, how you treat data is imperative.
Especially like, for example, working in a healthcare organization that's kind of numero uno like data and reten retention, re excuse me, re re pretending data, data retention is, is key and imperative, especially when you have records, a lot of important documents, things of that nature. So, you know, back then we didn't have a solution like Sentinel where it was clean, very streamlined. It's like, we're gonna build these, metaphorically speaking four major walls to compound and streamline data, give you much, you know, deeper granular visibility, long-term retention, and the analytics piece, which is really cool.
So I think that working from different, you know, sectors of it, it's really cool to see how we're evolving with data. I think it's certain in certain areas or certain sectors like healthcare and, and, and, you know, maybe, you know, f for financial institutions, it's kind of imperative. Other ones maybe not so much, but I do think that this is a solution that's, that's, that's really key and, and kind of growing and doing that and how we, how we start storing it, how being able to process it and more so being able to sift through the logs and, and really check to see like what's important, what's not.
I think of it like this. You've, you've, if you go back that far in time, uh, you're spanning multiple jump points on my career timeline. And in the early days, I remember when a two terabyte hard drive was, you know, pretty amazing that you could do that, uh, that many years ago.
Um, then, then this progression of like, well, that actually might become how much memory you have access to. And, and then when you think about the retention part of it, I was thinking about, well, your retention policies, um, very common for people to want to discard, uh, you know, data. And sometimes it was, uh, just to make sure it's not part of a discovery process, you know, if it's something related to like, you know, objects, uh, related to documents, things like that.
But in the world of security, uh, the ability, like when you say a, uh, one of those advanced system threats, you know, slow and low, it's been cooking. Maybe it's been in there for, you know, the better part of 10 years. Uh, there, there are obviously some interesting stories in that, but I will always go back to what's the inherent cost of that storage over that period of time.
Um, every CIO of it I've ever been a part of. Uh, certainly the precipitous drop in storage pricing has not been top of mind for CIOs. If anything, it's the ongoing increasing amount of cost to keep track of storage, even with the wonders of cloud, uh, which makes it super easy.
Um, which is another thing too. I I think an important part of this is that this is an inherently, you know, Microsoft story. Um, but I'm very curious to see how the data lake part of it fits into the, oh, you don't need to move your data.
You don't need to rehydrate, dehydrate, move your data, move being a four letter word. So how I actually, uh, how it's actually executed is gonna be interesting. 'cause I I I would also doubt that over that many years, the day would all be in one place.
Yeah. And that's the problem that we've got right now with a lot of this information is the data lake looks a lot more like a bunch of little puddles where we hope that we've got the right data. We think we do.
But where is it? Well, it's in this shelf over here, it's in that drawer over there. It's like when I try to look for things in my office.
And I think that the value of putting it all together is not just that you have a good base to draw from, but it provides opportunities for exploration and honestly for attribution. 'cause one of the things that we've seen with some of these, uh, modern, in 2025, several of the CBEs that were released with like high severities, these were not new problems in a lot of cases. They were problems that had persisted in certain versions of packages for months or in some cases a couple of years.
And you don't know how far back that goes if you don't have access to that data. Because we really do live in a, in a, uh, an enterprise IT culture now where if it's not immediately useful to me, I need to chunk it out. Um, there was a news story at the end of last year.
Somebody discovered a running version of Unix system four on a tape. Why somebody put the tape in the wrong spot. And it wasn't erase like it normally was.
Like, think about how many episodes of DR who got lost because the policy at the BBC at the time was to erase tapes because why would we, this we already aired it, nobody cares about it. Now, 50 plus years later, people want that data. Now I'm not saying that my, that, uh, Azure, the data lake that that Sentinel is using is going to be able to restore, you know, old DR.
WHO films. Although that would be cool if it could. Uh, I'm saying that being able to keep that data and know that you have that data and be able to go back and say, okay, how far back does this exploit run, gives people in an organization a much smaller risk profile and it makes DFIR and auditors very happy when you can say, no, we have not been running a val an invalid version or a a, an exploitable version up until this date.
So we know that everything beyond that is probably safe. So auditors don't have to spend a whole lot of time combing through that. Neither does ZFIR.
And it really makes people happy when they can narrow their focus and, and use their energy for something useful instead of like combing the desert, so to speak. And I think one of the nice, I mean, at least from what I took away from it is having that, that that security, that comfort knowing that Microsoft is behind the platform in the sense that when you have such large amounts of data, it's like where you, you pretty much grow your, your entry point into where a threat could attack, right? Or a CV could attach, and then you start having to pillage through, well, what's the clean data and what's the infected data?
So being able to kind of sort through that have more visibility into it, I think is huge too. I keep coming back to, if, if you tell me that that many logs of, uh, years logs worth of like firewalls, endpoints, things that we're feeding into some kinda a log sink, if you can tell me that the cost associated with that storage is now decoupled, uh, literally set apart from what would've been traditionally. Like, you know, and I'm not gonna pick on any particular vendors today, but I'll just pick on Splunk from it.
Like everything just went into Splunk and Splunk team got their Splunk IT budget and the Splunk IT budget inexplicably compared like the compute and the storage and the network and everything else. Kinda like wrap that into a one little bundle. But now if you can decouple storage over here, you know, which is where the logs go to live forever, if you can tell me that starts to look like what you know for your TBM person technology business management person.
You know, you have your, your traditional IT spend, then you have your, your variable or opex part of it, and you have your, like your, your labor attach when the labor attach, you know, looks like the investment of what would've been that storage cost. But now you're saying instead of it being the one year cost or the one year and a half cost for like, what's the hot tier? If you tell me that starts to look like I can actually do some real comparisons, um, to understand business value for that, you're probably gonna get my attention.
Again, execution matters. Uh, but it does appear that this decoupling, this data lake, uh, concept coming from the, the analytics world and now rushing in to solve, uh, what you clearly call out is like a multi-year span problem in security may maybe that will work out. Um, I'm also very curious to see how many people are going to adopt this, um, because it also sounds like because it's Microsoft, you'd be consolidating your Microsoft expense.
I'm not sure if you get any cost advantages there as opposed to having third party players involved. But, uh, that was my other thinking about this, is you're, you're kind of decoupling the storage costs away from a compute or a query cost. Uh, and, and I think it's important, uh, to, to lay out, uh, especially if you were thinking about this at a very senior level.
So let's talk about why we want all this data, because one of the things that we, we realize now is that the way that security operates is slightly different than we're used to. Um, and, and one of the other things that Microsoft highlighted with Microsoft, uh, Sentinel was this idea of graphs. I'm not talking about, you know, X and y coordinates.
I'm not talking about bars and charts and pies. I want Jay to explain what you explained when we were doing the pre-briefing here about how graphs work to you. Because I think this is one of the more succinct ways to think about graphing.
I I would think of it, everyone loves a list. I love a list. I got list, I got lists on the wall behind me.
I did erase them before this podcast. But, um, the list is great, you know, because I, I can literally, I can, I can see progress. It feels it's very, very satisfying to mark things off my list.
1, 2, 3, 4, 5, 6. The challenge with that now is that, um, if our list for, you know, defense is I start, you know, I focus on one, then two, then three. Uh, a lot of what's happening is, uh, the the bad player, the bad actor might start on item number 14, then jump to 23, come back to the ones and twos.
And that's because they're attacking a graph. Um, they're not attacking a list. And so I think, I think what's good for the goose is good for the gander, you wanna call it spy versus spy, whatever that motif or, or metaphor was.
But by thinking about a graph, it's a, it's a lot of cognitive overhead, frankly, to think about it that way. Because it's like saying, take your, take your todo list and then just make it like a word graph on a page. Now where do you start?
And so I think simplifying that's gonna be important, but that's how I think of this, this transition from like a, a crude list to now thinking about this. Like it's a, it's a web of things or concepts that are interconnected with, uh, mapped dependencies. And, uh, that's unfortunately how the bad guys are gonna think about it.
So how we approach graph and how we can simplify adoption of graph as an approach is, I think gonna be important for the new, uh, realm of defense that we have to enter into in these modern times. It almost sounds to me like a, a choose your own adventure book, right? It's like, you know, if, if you wanna attack the email server, go to page four.
If you wanna try to hack the password database, go to page 12. And if I am a system that's trying to process that serially from page one to page 50, it gets really outta hand real fast because it doesn't make sense as a story. I wanted to say too, and I think it's imperative is like to kind of the flip side of that too, or maybe on the same, you know, discussion, is that how that really helps security teams and soc teams moving forward, right?
Like when they're doing audits or when they're doing, you know, full reviews of an environment, number one, it can kind of focus on like some of the targeted like pain points or areas where, hey, this is where a breach may be susceptible, or this is where a CV could attach itself. Also, when you have that type of data looking at those graphs, it's gonna go, well, let's take a look here at, okay, we have a compromised user account, or that user account is tied to this VM or this container. So again, it gives you full visibility into this is where they're gonna hit, this is how we have to, you know, kind of position ourselves.
And it helps overall better posture, I think from a security assessment, you know, and it gives those teams extra tools and, and, and guides to leverage Not just posture, but I think it actually helps direct the incident response side of things. Yeah. And here's the reason why.
'cause Jay, you bring up a really good point. People don't think in lists. Like, there's not a 10 point checklist of, okay, I I'm on a server, you know, check the user login file, check this, check that.
What do people do? They look at the server, okay, what am I on? I'm an e I'm on an email server, boom.
That immediately shortcuts to this thing down here. I wanna try to expose boxes, I wanna try to get user login information. I wanna see if I can get other information that's maybe held in like group folders and things like that.
Well, but if I'm on a domain controller that is a, you know, and I'm dating myself by saying domain controller, um, like that's a completely different attack chain, right? Because now I have a copy of AD and I can go in and I can do stuff. But more importantly, if I do happen to find myself on a peer domain controller, and I've developed all these attacks, am I going to start looking for a Linux database server?
No. I'm gonna see what I'm connected to that is other domain controllers so that I can see if I can compromise them as well. So by understanding the way that graphs work and being able to hunt down those graphs, I can follow that movement, right?
Like, 'cause that's the other thing too. The, the hacking methodology of land and expand is by its very nature chaotic. Because if I find a good, like, hit over here, I'm gonna follow it because there's, I'm gonna have to put less work in to compromise the system, or maybe it's a better foothold, or you guys weren't dumb enough to leave a Windows 98 machine on the network, were you, were you like that kind of thing.
Whereas in, in Jay's example, the traditional checklist of, you know, we check the firewalls, there's no problem. We checked the IDs, there's no problem. Well, we didn't see anything.
Let's go back to the top. We checked the firewalls. There's no problem like that.
The, the playbook is old, you know, uh, it's, it's every war movie you've ever seen. You got Top gun maverick, good example. This is the natops for the F 18, you know, it back and front funk.
So does your enemy. I'm gonna have to teach you how to do things that are not that, and that's graph theory, right? Push an airplane in ways that it wasn't designed to be used.
Like, and, and I think Microsoft has hit on something here because like, like we've said, hackers don't think in checklists. So what, what, what is the value of having graph for someone in an end user position? Because like, I know what the value is for people who are making these decisions at the boardroom, it's flashy and it, it, it, it is money that can reduce my risk score.
But for you guys, the people who are in the trenches who do this, what is the value of having a system that can do graph? Uh, you get much faster pattern recognition than if you're just trying to correlate, Hey, look an endpoint, talk to another endpoint. Fabulous.
Thank you so much, Einstein. Um, this is the year 2025. Tell, tell, tell me a little more detail than, hey, look, this thing pinged this other thing or this port, you know, got knocked.
I, I think, I think as the patterns, um, you know, we, we almost wanna see, um, the, the orchestrated playbook, uh, being executed against us. Oh, look, that's one of these, um, it's, it's this pattern. We are seeing this pattern as opposed to an alert occurred again, you know, going back to rubbing sticks together with your domain controller.
I, yes, okay, an alert happened, but in the totality, what was the pattern of all of the, you know, call 'em several hundred, several thousand alerts that occurred? What's the emergent pattern? Uh, what does this tell us is happening?
Um, do we, you know, you go back to like even like a, like a CrowdStrike or other type of metaphor, um, um, or, or, or, or, or people try to come up with cute names to describe, uh, the new threats that are out there. Um, animals, insects, you know, where they came from regionally. Uh, that's a pattern.
Um, that's a technique. Um, right now, uh, we, we, we really can't deal with the individual alert. Uh, we we're just not allowed to, I mean, I, I think there was another call, um, or talk around where do you even find junior, uh, uh, security analysts.
There's no junior security analyst jobs anymore, because a lot of that has been, you know, given up to machine learning. Uh, that's doing those very intro level roles. So again, we're, we're thinking in terms of patterns.
And so, uh, once we have the pattern, we may have a counter, uh, you know, to that pattern. But in, if we're still dealing with alerts, we're just, we're so lost in the weeds. Um, so I think graph is about pulling ourselves out of that, you know, one-to-one only view of the world.
I, I love that you brought up that you can sometimes do attribution, seeing how people behave. I think my favorite piece of that was a couple of the groups, the, the fa the bear groups. Um, we knew that they were probably Eastern European or Russian and Origin because they had blacklisted certain places from being infected by their malware.
Um, basically it was, do not poke the Russian bear kind of stuff. And if you can pick up on those little subtleties, then you can figure out, okay, I think this is this group. Like, like if you know that a specific group is, is famous for buying insider access, if you're seeing insider access type patterns, then that narrows it down.
It's probably not this group from the far east, it's this group from Brazil or something like that. And that gives you a more, um, solid place to start from so you're not wasting resources. Gerard, what, what about you, what do you think is, is some of the value of having a a graph type solution available?
Well, like I said, I mean, I a hundred percent agree with, agree with Jay. You know, having, having, my biggest thing too is with this platform, it allows you to blow out what you see as far as from an analytics and from a log perspective. Because from someone, especially for years who, you know, on the network side, it's like, well, we know this packet went to here and this is where the attack, you know, started.
This is where it originated. This is where we need more. We need more to be able to expand upon that.
And I think the cool part is being able to ingest such, such data, but then rip it apart at such a level. Like, I remember during that demo in October, I was really excited to see how it breaks down, not just the time of when the attack happened, this was the attack vector. This was the point.
It, it, it broke down an entire timeline. Um, that really like, gives you a visibility. And especially too, when you're looking at it not just from the technical perspective, but you know, with a lot of CISOs or higher level, you know, individuals, they, they want that data because they wanna know, Hey, what happened here?
Why did this breach occur? Where did it occur? And then how did we stop it?
How do we remediate it? So when you have that all under one package, um, you know, I think graphing and, and, and kind of again, more granular level detailed reporting is, is what we need. So for me, that's how I, at least I, I look at it, it's just, it's, it's a, it's a way to blow out the, the, the initial data point instead of just saying, Hey, this is, this is infected.
We got hit here, that's all we got. No, there's gotta be more. We gotta be able to pull more from the firewall logs.
We gotta be able to pull more from, from, you know, the, the, the Ford manager UI or whatever it may be. We have to be able to get more data and this provides it. And I think that the other thing that's valuable for me, kind of going to something that Jay said was, where are you gonna find a junior engineer?
Now my question is, why aren't you making junior engineers? You, you should take someone, bring them in. But rather than to quote Master Yoda, you must unlearn what you have learned kind of things.
Set them down in front of a graph solution and say, okay, I want you to figure out how this works. Look at the way it thinks when it's building through all of this. Don't worry about the data lake.
Don't worry about all those stuff. We'll get there. Just watch it hits this, it goes here, it does this, it does these things.
Because there you're taking someone who doesn't have a preconceived notion of bastion host firewalls, who doesn't have a preconceived notion of VPN concentrators. Again, I'm dating myself, but it's figuring, helping them figure out how modern stuff works. Like we always talk about this in security because we are so focused on technology solutions, right?
We need to microsegment the network and create zero trust boundaries. And saw an article yesterday where someone on a help desk is selling insider access for like a hundred dollars for an hour to get on and just do whatever you wanted to do, create a foothold, whatever. We still don't think like attackers, we still think like defenders graphs get us, at least to the offense defense side, people that play the, on both sides of the ball, so to speak.
I think it's more valuable for someone to come in and look at that and start their learning there. Yeah, you can give 'em the fundamentals later. Here's how our firewall works.
Here's, here's why we do access lists the way that we do. But letting them kind of have freeform capabilities, almost like a mind map is a much better way to build the next generation of junior engineers. Because if they have to listen to me or any of us that have been doing this for more than five years, they're gonna be like, but why do we do it that way?
Well, back in 2010, when this was state of the art, that's how we built stuff. And, and I know we don't do that anymore, but we still think that way. So I wanna kind of wrap this podcast up and I wanna ask you both, like for people going into 2026 that are examining how things should work and, and if they're ma looking to maybe make some additions to their things, what's one thing that people should be thinking about in regards to data lakes and graphs and that kind of technology, even if it's not Microsoft's solution, what's something that people should be thinking about as they maybe are putting their wishlist together for the boss to say, Hey, maybe it would be good if we investigated these ideas?
Well, you know, I definitely would say one thing to keep in mind is, I know, I know the hot, the the cool word is AI still, it's, it's the thing I know and everybody's like, why? But it's the truth. You know?
I know a platform like this, or any, you know, graphing platform is gonna leverage generative ai, generative AI to really ingest and pull that data in. So, I mean, one thing I would say to keep in mind is we have to be on the other side. We have to start thinking more proactively and stop thinking less like a defender and more like an attacker, or at least find a happy medium or a balance to both.
If we could find a balance to both, it's gonna give us a distinct advantage and a leg up to, you know, being more proactive at CBEs, and then we're gonna start the, the smarter we get, we need to start leveraging these tools to prevent the attacks. You know, I think one thing I had mentioned, and I'm not even gonna go into it, but it was a whole thing that, you know, there's an entire type of threat out there now that could actually freeze an EDR and XDR solution. It could just kill the whole solution right from the inside.
So we need to be able to start leveraging that, and then that way it's, we're gonna see that blanket across the entire industry, and it's gonna help a whole portfolio of next generation tools and suites, especially graphing. Yeah, I would say there's a couple of spaces that you'd want to explore, uh, group, group wise, uh, you know, lunch and learns, um, getting folks that maybe cut their teeth, you know, uh, rub sticks together around like a CIM or a a more of a common information model. And then, you know, bringing them, maybe kicking and screaming into the more advanced security world.
Um, thinking in terms of, okay, well that was, that was great, but, uh, we, we only had a firewall back then. Now we literally are dealing with potentially hundreds if not thousands of individual baby firewalls living everywhere, all trying to log sync to somewhere. Um, so getting people out of that, uh, you know, um, uh, I, I feel like picking on Splunk again, but like, there's the Splunk mindset of how it started and then there's this new world of like, you know, KQL or Cresto, however you say it.
Um, we're, we are, we're literally going, we're deep diving. Um, we're going into the lake. We're gonna explore the, the, the, the bottom and look for surface formations and patterns and see like, ah, this kind of fish, that kind of fish, this kind of eel, that kind of thing.
Um, and so the analogies are gonna be, um, taxing for those that maybe grew up in it and were used to doing it a very specific or one way of doing it. Um, but I would say there's probably some parallels there to the old, uh, storage engineer versus what's now called a cloud engineer. And so that same kind of progression of skill sets and matriculation is important.
You know, so the Tom's point earlier, just you should be creating these folks. Um, you, you, if you have the talent, um, investing in that talent, um, is absolutely on the table of possibility. Um, these, these, these are, uh, folks that have done it once before, and it might've been the one to one thing, but now it's gonna be the one to many or the many to many patterns that we have to think about in the future.
For my part, I'll say this, if you are even considering any of these solutions, all you've gotta do is go to the current providers that you have right now and simply ask, what are your plans to support advanced threat detection? And, and if you wanna say the G Word graph, say it, one of two things are gonna happen. They're gonna look at you and go, what's that?
Then you get to educate them, send them the episode of this podcast. We would love that. But more importantly, um, if they do have plans in the pipeline, they can say, well, that's something we're looking at.
Then that can give you an idea. Is this six to 12 months out? Is this 12 to 18 months out?
If this is something that you and your organization need to investigate, either because you fear you're about to be breached, or your, um, stakeholders really need some kind of insurances here, then that means, do I, do I stick with who I've got or do I make an investigation? Um, and if you do make an investigation, I'm sure friends over at Microsoft would love to hear from you because they put a lot of effort into Microsoft Sentinel and they'd love to sell it to some people. And, uh, you know, we, we appreciate them partnering with us on all the things that we've been doing.
So, uh, thanks again to them for that. Um, before we go, I'd like to let our, uh, guests kind of plug their stuff. Uh, Gerard, if people wanna check out what you're working on, where can they go to find that out?
They can find me all over the internet at Tech House Five seven. Oh, I'm, as I said, I'm on LinkedIn, Twitter, TikTok. I make short long form content.
I'm all over the place. I'll probably have some new videos coming, uh, on Sentinel, and, uh, it's gonna be a great time today. You can find me anywhere.
Books are sold and I'm all over the internet Tech House. Five seven, oh. org.
I'm on LinkedIn, I'm on Blue Sky. I'm using Go to Social now 'cause I had tried using a standard Mastodon server, but my Fed Averse is now on Go to Social. So, uh, look forward to, uh, anyone reaching out to me there as well.
Thanks, of Course. com. You can also check out more of our great security conversations over at our Security Boulevard podcast.
com for more information there. We wanna thank you for listening to this episode of the Tech Field Day podcast. And as always, if you enjoyed this discussion, do us a favor, subscribe on YouTube.
Use your favorite podcast application. We don't want you to miss any of these episodes, especially around the holidays when things are coming out, um, on a maybe less than regular schedule. Well, not for us, because Corey is amazing.
Uh, but if you do enjoy the content that you hear, let us know. Give us a rating, give us a review, leave a comment. We'd love to hear what you have to say.
This podcast is brought to you by Tech Field Day, which is the home of IT experts from across the enterprise. We're a part of the Futurum group. com.
You can also check out the website, tech field com slash podcast for all of our episodes, or listen to us over on Tech tv. Thanks for tuning in. We will see you all next week.
AI isn't just changing jobs, it's creating entirely new ones from building habitats on distant worlds to designing art at the speed of imagination, to crafting living materials, guiding drones through uncharted terrain. Hey, everyone, happy New Year. We're a little late getting started this week.
I've been busy in the studio here on some of the other sets at Techstrong Studios. But, um, happy New Year. I'm glad you're here for our very first Shimmy says of the year.
And for this year, uh, for this week, to kick off the year, I wanted to talk about something that's probably near and dear to you, as it is to all of us, including myself, I guess. And that is what exactly are all these new AI jobs that we're talking about anyway? You know, if I had a nickel for every time I've heard someone say, AI is going to take away jobs, AI can cost you your jobs, I'd be well on my way to buying my own AI factory or data center.
Ah, who am I kidding? The, these things are a trillion dollars, billions of dollars, but at least maybe I'd have a good down payment. Um, but you know what I've found, and you've probably seen this too, everyone who says, well, AI's gonna cost a lot of jobs.
It's immediately followed by, but don't worry, it's gonna create a lot of jobs too. And, you know, for a long time, I, I think that was just the mantra. When someone tells you their relative died, you tell 'em that, Hey, you have my condolences.
But no one really thinks about what exactly are all these new jobs AI's gonna create? And when I started asking people, what do you think these new AI jobs are gonna be? I didn't get a lot of answers.
I'll tell you the truth. I got a lot of fun free. So I figured, let me go to the source.
Let me ask ai, what are some of these new AI jobs that it's gonna create? And you know what? It, it kicked back.
It, it spit back some decent, some decent things. Um, and then of course, you know, I I've also read a lot of things from the so-called AI architects. Uh, you know, the people who are running the Sam Altman's, the Elon Musk, the Googles, the Perplexities, the Anthropic people.
Where do they think these AI jobs are? And, you know, an interesting thing, a lot of them talked about space, and we're gonna come back and talk about jobs in space a little bit. But before we jump into this whole thing, I wanted to just clear some BS out of the way.
A lot of people say, oh, I can tell you what some of these jobs are, and they give you these buzzwords or kind of shiny stuff that we've used before. And, and we're polishing off things like, I'm gonna be an AI evangelist, I'm gonna be a prompt engineer, and I'm gonna be a prompt a cybersecurity prompt engineer. Come on that, that's, we're all gonna be prompt engineers, that's for sure, right?
And we're all gonna be coworkers and managers of our digital alter egos and our digital agents. But I mean, what are the real new jobs? What are the careers?
You know, I remember when the internet first started coming out, and I first started, I, I, I'm trying to think when it was, it was probably 1997, maybe late 96. And I heard the term web designer. Now, I will tell you that most of my friends at the time, whether they were lawyers or doctors or construction workers, firemen, policemen, if I told them, you, your children were gonna be a web designer, they would've looked at me like, I'm crazy.
Like, do I think they're growing up to be a spider? Is this something outta Charlotte's Web? But no web designer became a job.
Internet engineers, right? People who, who really, you know, were behind the, the internet became a thing. UX designers, UI designers and everything else.
So that's the one of the biggest lessons I learned through this exercise is for everything AI spits out to me about the new kinds of jobs that it's going to spawn. Um, it really doesn't know. None of us know yet what these new jobs will be, but, you know, there will be some old jobs with new labels.
But I, I don't think that's really where it's at. Here's something else. What I'm really kind of afraid of is in the, in the rush to make sure this isn't so disruptive.
We make busy work jobs. You know, back in the depression, I, I wasn't alive then, though. I'm old.
I'm not that old. Um, back in the Depression, they had things like the Tennessee Valley Authority where they gave people shovels and sent them out into the Tennessee Valley, for instance, to dig ditches and make dams and build roads. And the, the roads were a good thing.
And the dams of course, were a good thing. But a lot of the jobs were just like on the dole. Government created jobs where people can go at least put in an honest day work and make an honest wage, even if the work product coming out of it was not very productive or useful to society.
What was useful is people actually working and earning a living. And we may see some of that in this, in this cycle. We may see some busy jobs, if you will, if you want to call it that.
But let's be honest, no one wants to just have a busy job, busy job, just for the sake of being busy. No one wants to raise their hand and say, I wanna have a career of babysitting the AI or babysitting a machine. So, you know, and that's the kind of stuff that AI was originally spitting out.
And I asked her, what are these new jobs? So I asked it, and, and this is a good lesson. Never take the first AI response.
Always ask it for more. Quantify it, qualify it, it reiterate it. And so I started asking it, what else be what, what's the real jobs?
What are, what are our, give me, you know, three distinct kind of careers? And if we can make my teleprompter a little bigger here, I can't see it, um, you know, be more precise. What are, tell me first, what are the jobs that are gonna disappear, right?
And then what are the, what are the jobs it's going to make? What are the jobs it's going to change if we can go forward? Um, you know, I, and I'm looking for jobs that honestly didn't even exist before ai.
Um, now I know a lot of us have anxiety about this, but I think knowing that there are real jobs that are gonna be created here is gonna make all the difference in the world. So I wanna start with tech jobs. 'cause look, most of you watching this are all pack.
Um, so let's start with developers. Look, 60%, I saw a number this week. 60% of code being generated today is being coded by ai.
So yeah, there's some panic in there among developers. And yes, AI can generate code. And increasingly it's good code.
Speaking to my friends in security, we've kind of crossed the Rubicon where the code being generated by AI continues to have less and less vulnerabilities where it's or below the level of vulnerabilities that human generated code is at right now. And if that's the case, what does that mean for security as well? At some level, humans are worse, are generating worse code quality than, than AI is.
So does that mean developer roles disappear? Absolutely not. I think we're, we're shifting from developers being code writers to system composers.
And that word composer's a great word. I'm gonna come back to it. We're, we're moving from people who produce syntax to people who design, orchestrate, and govern complex systems that now include autonomous components.
And dare I say, digital coworkers, same thing's happening in DevOps and platform engineering ops in general. Cloud AI doesn't eliminate the need for reliability engineers, performance tuning, cost control, observability. If anything, it raises the stakes and makes it more important than ever.
Someone not the AI has to decide how the AI workloads are deployed when, how monitored throttled roll back when things go sideways. 'cause they are gonna go sideways. There's gotta be a human there.
And by the way, that's not babysitting work. It's not junior work. It's judgment work, right?
A lesson we learned in cloud security, we can move stuff to the cloud and say, the cloud provider's gonna do so with the security for us, that doesn't release us, release us of the responsibility when stuff hits the fan in a cyber incident. Well, the same thing happens when we allow AI to get involved in our cybersecurity. The respon, the buck still stops here in terms of responsibilities.
AI systems do not execute decision instruct instructions. They make decisions that fundamentally change the threat model. We're no longer just predicting endpoints and networks.
We're securing these agentic systems, model pipelines, training, data design, logic, et cetera. This gives rise to roles focused on ai, threat modeling, model abuse, poisoning, de detection, keeping the human in the loop oversight. Not to mention governance, as always, audibility policy enforcement.
So look, there's plenty of cyber jobs that are gonna exist here in this ai. Here's the paradox for this one, though, guys, industry doesn't want to admit this, but as machines become more autonomous, human accountability increases, not decreases. It's counterintuitive, but it's true.
Someone owns the outcome. Someone's neck is on the line for what the AI does. That responsibility doesn't vanish just because a model made the call any more than advantage because the cloud provider was doing it.
That responsibility becomes the job. Let me move away from tech though, and talk about something else. You may haven't thought about blue collar work.
Hey, in the age of robotics, physical ai, I don't care what you want to call it, a lot of these blue collar jobs are going away. And they're not the traditional blue collar jobs. I, I'm talking, you may be thinking of, yes, the UPS worker history, the, the, the truck driver toast, train engineers, conductors, toast.
But what about the surgeon? Are these AI robots gonna do surgery better than people? They already are in some cases.
The idea behind it though, is when I say toast, they're not necessarily eliminated. They're augmented AI and robots. And by the way, CES was this week in, in, um, Vegas, if you saw some of the demos of the next gen robots out there, it's scary stuff.
You gotta go check it out. The things these robots are doing is just scary. But they're already, these robots are already working in our warehouses, our factories, our hospitals, construction sites and utilities.
But they're not just replacing humans in mass. What instead is emerging is a hybrid human machine collaboration. And that right there represents the future.
So if you're a worker in these fields, right? Remember these robots, they need to be trained. They need to be maintained.
They need to be calibrated and supervised. AI systems operating in the physical world are notoriously bad at edge cases. And edge cases pop up all the time.
The reality is they probably are gonna get better at it. They need us. This creates demands for skilled RO roles, robotics technicians, AI existed tradespeople, AI enhanced tradespeople, safety supervisors.
Field work is augmented with diagnostics and predictive tools on what's going to happen next with our row ro robots. Robots, this is not the elimination of blue collar, excuse me, blue collar work. It is an upgrade that blends physical skill with digital fluency and makes for a, a, uh, integrated workforce of humans working alongside robots.
Also, we're gonna have new frontiers, and this came out from the ai, uh, uh, architects, if you will. But some of the most interesting job creations aren't gonna come from replacing existing industry. It's enabling entirely nuance.
And the, as I said, the a AI architects came up with really pointed to this and it's space. You know, we've been talking about space, the final frontier since I was a little boy watching Star Trek in 1968. The, but the fact of the matter is, we have played with space.
We've got, I don't know, 10,000 satellites up there, but we're not really working space. We're not mining asteroids. We don't have permanent, uh, stations, bases on the moon or Mars or anywhere else.
But in the age of AI with autonomous machines, mining, remote construction and industrialization and hostile or hard to reach environments is gonna be a real thing, right? And it's gonna create an awful lot of jobs. These hard to reach environments aren't gonna be impossible to reach with AI and robotics.
And that's gonna spawn, you know, something outta Star Wars or Star Trek, a whole new ecosystems of work. So we don't, I can't, as I sit here today, I can't tell you exactly what those space jobs are gonna be, but there's a good chance that, um, there's going to, your kids are gonna be working in space. And that's not unusual, by the way, that we don't know what they are today, because we never do at the beginning of a new frontier.
But if history has taught us anything, it tells us that when reach expands, industries follow, and so does work. So sit tight on that. Another thing, another area I want to talk about is the creative arts.
You know, I have a, a one of my fellas who work in our, uh, AV team here, Brian showed me something he's been working on last week. Brian's a Grammy award-winning sound engineer, and he's a musician. But he showed me his music and characters, singers, digital singers and music videos he's created.
This is music. He composed using ai. And I, I gotta tell you, it was crazy good music.
It was a, you know, and he had this, it looked like a real person, except she had some sort of hologram on her cheek or whatever. But she was singing this song that Brian composed in ai, and it was this whole music video and space and everything around it. And it was really beautiful.
And, and Brian showed me what other people like him, what other artists are doing. And it made me realize that yeah, AI does great videos. You probably saw the Sora video that led this off, you know, but in the hands, excuse me, in the hands of a creative person.
This gets real creative guys. I cannot wait to see what people can do when their imaginations run wild. And instead of relying upon maybe their own hand to eye coordination or their own ability to compose music, we're using AI to do these things.
I think it is gonna ignite creativity. So for things like arts and music and creative kind of, of, of, of film, well, it's obviously not film, it's video and stuff like that. I think AI is gonna set the world off fire here.
We're gonna see so much coming at us, right? It takes the blank page. Humans still have to bring taste and intent and context.
But between the, the collaboration between them is amazing. So this isn't replacement, it's leveraging it. What makes jobs worth doing though?
And that really is the crux of it, guys. We could, you know, you want to go get a job that pays your bills and puts food on the table. Look, humans have been doing that for a really long time.
It's few of us who, as I always say, if you do something you love, you never work a day in your life. Very few of us actually get the opportunity to do something that we really find rewarding, exciting, and we would do truth be told, even if we weren't getting paid. Um, but with ai, we, each and every one of us has the ability to pick some sort of job, some sort of doing something stewing, something, some responsibility to master, to create the best ai era.
Jobs are not gonna push humans out of the loop. They'll move us to where we are most valuable, where we're most happy, and where it's most rewarding, setting boundaries, making decisions, but nevertheless owning outcomes. That is fulfilling work.
And it's work machines are not particularly good at, but humans excel at. So what's the real question we should be asking? Yeah, AI's gonna eliminate some jobs.
I'm not gonna sugarcoat that for you. Some of them probably needed to go anyway, quite frankly, right? But the more uncomfortable truth is this, the future of work is not about competing with machines.
It's about whether we're willing to move up the value chain and work hand in hand, arm in arm, brain to brain with these machines. Machines because these jobs are coming. They just won't look like the ones we used to, but they'll be there.
And that's not something to fear. That right there, my friends, is opportunity knocking. This is Shimmy and I'm out for the week.
We're back here with some more, uh, coverage from our AWS reinvent recent, uh, video stand. Uh, if you haven't seen some of our other AWS reinvent, uh, coverage, you know what, at this point, most of the videos are up. You can catch 'em on text, drunk tv, on the text, drunk tv, YouTube channel, or on our text Drunk TV OTT app.
If you've got Amazon Fire or Roku or Apple tv, or even iOS or Google Play, I, you can get the OTT app there. Um, but let me introduce you to our guest here. His name is Robert Cilla.
Cer Cilla. Yes. Close.
Rob, I was close. I left the S out. Robert Cilla, first of all, Robert, welcome to Text on tv.
Thanks for having, it's the first time he's been on, so glad to have him on. Robert, you're with suse is, unless you just took the shirt, it is a great Shirt. Possible shirt.
It is a great shirt, but I am with susus. Okay. And tell us what, what's your role at suse?
So I am the Director of Technical and Community Marketing. So I handle our community efforts around, mostly around our consumer community. And we, 'cause we have multiple communities, um, it's like that with any tech company.
So direct to consumer kind of stuff versus, uh, No, when I say consumer, it's people who consume our technology Okay. Is the primary focus. And then our secondary focus is people who can contribute.
And on the open Ssus side, their focus is slightly different. Where they focus on contributions, less on people adopting, you know, it, they, you know, they kind of build it. They will come over on that side.
So they cater to making sure the project package maintainers are taken care of. Um, and the needs of these two communities, don't, they overlap, but they're not the exact same. I love it.
You know, we've, over the course of AWS reinvent, I bet you I interviewed a half a dozen to 10 SUSE people. Mm-hmm. Not one of them really spoke about the, they mentioned the community, but they never really spoke about the community.
And so let's start right there if we can. When we talk about the SUSE community, and you mentioned there are different facets, aspects of the community, but how do you define this community? Can you give us sizes?
Give us, you know, I don't even know how you would define it. We, I, I define our community as a large group of practitioners who enjoy the technology. And that is the binding glue that brings them together in our community.
Um, to count it, it's hard, um, because you people are in certain channels and they're not in others. And we estimate anywhere between, you know, 45 to 65,000 people, um, who are active, who, um, they participate in Rancher Academy, which is a LMS platform. We put out, we want people to learn about our projects that, that are out there, or they're in our Slack channel, or they're engaging with us on social media and we understand there's crossover.
So that's why it's an estimation 'cause Right. I don't, we don't track exactly who's who. That's just kind of creepy.
We just want you to show up for it. Well, but that's, that's part of that open source mantra, right? We, we don't track, you know, we're not looking for your blood type or DNA samples like that.
We don't wanna know what Your kids' names are. We don't exactly Like that. Or even your birthday.
Yeah. But, um, so a lot of it is online, it sounds like. But then, like in an event at AWS reinvent, are there any kinda suse community activities tied to it?
We Do a few videos that we post out the community, um, does crossover with AWS slightly, um, when it comes to some of the projects, AWS does have a, a large user community, and there's, there's some crossovers there with that. And we see it more so on the consumer side, very little on the con contribution. Um, for us here, it's just, you know, showing what's the latest and greatest on AWS because we understand that commu there are community users who, you know, they're not customers, but they use our, our projects in AWS and we wanna make sure that we, I don't wanna say meet their needs, but know we acknowledge that that's where they're at.
And you know, That's portal they, and they matter. They, they matter. I get that.
What about in-person events in the community? Not just at AWS three event, but, So when we have any large event that, that we try to attend, that piggybacks where, what our comm, where our community's at, whether it's here at Reinvent or Coup Con or Open Source Summit, we like to engage with our community, let 'em know that we're there. Um, we always have community team members on staff at these events to ensure that, you know, like they can meet the people that they talk to online.
Like these, these are kind, I don't wanna say they're, they're rock stars in my mind because they're, they're great individuals on our community team. But I, I wanna make sure that they can connect, you know, in person just 'cause, you know, it's post COVID world. You know, having that interpersonal connection is, is nice sometimes.
Sure. Absolutely. Let me, um, I, I, I, one of the companies I had started was called the DevOps Institute.
We sold it about three, four years ago. Mm-hmm. But we had a, a nice community.
It was very simple. It was very easy. Well, it wasn't that easy, but one, one part of the community, the people who actually had taken our certification classes and our courses mm-hmm.
And those, we did know their children's name and their date of birth and all that. 'cause we knew who they were. They had a, you know, they took classes and they were certified.
The bigger part of the community though, were just people who maybe, you know, didn't take a, a real certification class, but somehow consumed our content or, or what have you. And it was always the discussion we always had at the exact level is why would those people want to be in our community? What would, like, what, what's the advantage of being in a community, if you will?
Uh, Well, I, I'd like to, I will speak, I mean it in any community, but I wanna speak towards the, the technical community. 'cause you know, it's what we're talking about and it's fairly relevant, is that individuals have to take some of these skills to work. Yeah.
And they don't want to know that. They don't want people to know. They don't know.
So being anonymous, being able to go and adopt, learn and grow outside of your normal work environment, to come back in and say, I, I, I don't, I know this so I can talk to it. I'm, I'm participating in it. And I think that's where you see it.
And it does cross over to non, I'm a, I'm an avid cook. I love cooking. I love cutlery.
I'm in, you know, community about, you know, cooking and so, you know, new knife skills or something like that. 'cause I want to learn and grow and not think, my wife thinks I don't know what I'm doing in the kitchen. But that's just the same thing.
It's the same adoption that you want to have. And it's not judgemental. Someone comes to the community, they don't know.
It's like, can we point 'em in the right direction? People love to come in and answer questions for them, and they take that back to work, or they take 'em back to school. Absolutely.
So there is the, the, the help you grow, and especially from a work related mm-hmm. Point of view. There, there, look, there are plenty of people who are hobbyists when it, especially things like open source and Linux Yep.
And, and so forth. Um, but it is, it, it, it's a way to advance your personal career path. Let's, let's call it that way.
I, I, you know what else I, and this is me talking now. I don't have anything to back it up. Sure.
But I think it's part of human nature to, to want to feel part of something, part of a community. And, and as you said, it could be cuddly, it could be cooking, it could be anything. But you always wanna feel like, I'm not the only one who feels this way, who has this problem, who, you know, is working on things, solutions to a particular issue.
I, I think there's, there's something intrinsic to humanity that wants us, that, you know, drives us to be part of community. Yeah. It's a, it it's a sense of belonging.
Yeah. So when you, you, you talk to people like we have our regulars in the community, and you talk to 'em and sometimes they will just wanna say hi. Yeah.
And, you know, and or they will bring you something that they did and they want, they wanna show it off. And I love that because you're seeing someone who has the same type of passion and it, it makes me feel better. 'cause it's not me going, like, I'm just a nerd here.
There's, there's other nerds like me out there. Absolutely. Look, I built my whole business here on those nerds.
Right? I mean, they're, they're the people who watch our stuff and, and consume this. But it, it's, it's part of being in a tribe.
Yeah. Right? It's tribal at, at its very nitty gritty.
It's tribal. Right. These are people who are in my tribe.
It, it, it may not be a tribe that I live with or, or something like that, but we share that common bond, that common interest and, and they become part of your tribe. And It goes down, it goes even down further where it's like, I, I only like Linux. I don't like Cloud native.
Yeah. And, and that's okay. And we have a lot of people who are like that.
And that's, and it kinda, and you know, there's always rivalries in any type of community, so, you know, we're better than you kind of thing. Mm-hmm. And it's, I it's akin to sports fans.
Right. And then as a Cleveland Browns fan, you know, I don't really fully understand what it's like from a sports perspective, but I'm sure like Eagles fans or someone else out there, you know, with, you know, a better team behind them would understand that level of, you know, rivalry that you have with the technology. Yeah.
My sympathies to you by the way. Thank You. Okay.
Looks like you can have a good pick at a quarterback. Again, though, this I'm only, let's not get into football. Let's, I'm a Steelers fan.
I have my own trouble. But, um, and I, I actually, my, when my brother who's is, he's a one of a fire toing guys, and I say, Hey, be careful what you wish were, 'cause look at the Cleveland Browns, right? Mm-hmm.
But it's all relative. But it is, we are, we're tribes. It, it, football fans are definitely community and tribal.
We, we still love, it's in that crossovers. We, we each love our teams, the Steelers and Browns. We would, we would love our teams.
And we have those rivalries and we can say, oh, we do this better. And you have, we even have it in the Linux communities where, you know, they don't, there's, there's certain schisms that you have and sometimes they get toxic because, you know, we're in an online community. Right?
Yeah. And when you don't have the interpersonal things go get, they get dark, but they usually recover the, and that's what the beauty of a community, it, it like naturally recovers. I I think part of that though is, is, and, and you hit on something when you have a virtual community mm-hmm.
You know, it's easy for people to sit behind a computer and say something that they would never say in person. Yep. And it's easy to misinterpret what someone else wrote and may not, they may not be the greatest written communicator, and they, maybe you're taking it the wrong way, or they just wrote it the wrong way.
And, and this le look, I've been in online communities for a long time, maybe 40 years. And, um, well You also for, you didn't mention, but you know, we're international. Right?
Right. And you Right. You guys are, And so there's, there's language things.
There's language. I really, barriers, but, you know, this is No, no, but there's, there's miscommunication All the time. And sometimes I come into Slack and I'm like, what's going on?
Why is there a dumpster fire today? And I'm like, oh guys, he missed, he meant this. Right.
Like, that's not that word that you think, But it doesn't take, It doesn't take longs much. Nope. It does not.
There's people over the edge, Robert, let me, we're running lower on time. But for people out here who say, you know what? I've been a Sousa fan.
I, or I've been a Rancher fan. Mm-hmm. Both or, or what have you.
I'd like to be more involved in the community. Sure. What's the best on-ramp farm?
io, you can go sign up and you, you get dumped into our general chat and people, and we see, we see people who get put in there and just say hi. And someone from the community team or someone from the community will do, and explore what they have going on in there. There's, there's a lively chat.
Um, there's random stuff that people, you know, post, there's technical checks. So, you know, if they wanna learn more about K three s or rancher specifically, um, those, that's generally the, the best way. And, you know, I am, I'm in that slack more than our work Slack.
So really, that's my world. Well, that is, that is, that's your work. That's My world.
So, uh, I come, I go back to work. It's your tribe. I get it's Yes.
And I go back to the work one when I have to, but that's where I, I you'll catch me. Um, is that, that's probably the best way. And again, this is for the consumer side.
When you're getting started in a community, uh, you don't have to come and contribute right away. I always tell people that just come and say hi and, you know, find where you want to connect. You know, and it doesn't have to be contributions right away.
It doesn't have to be consuming right away. It's just showing up and just being, just taking part. Excellent.
Is this your last show of the year? This is my last show. Me too.
Um, I'm getting, uh, a very busy with a, and I'm gonna do a shameless plug on Scon coming up April 20th through 23rd in Prague chea. Um, that's what's consuming most of my time now is the planning for that, um, on the CFP committee. So I'm going through, um, uh, me and a group of individuals, atsa going through a ton of talks with a lot of great topics.
So if anyone is in Europe can make it. I do. Well, I hope to see you there.
I'm hoping to be there as well. I'm thinking maybe I should submit something. Has anyone submitted anything on AI yet?
Oh, I'm kidding. Kidding. That one right there is, uh, I think, I think that's the, the vast majority.
And I think when I saw, I saw one that wasn't AI related, I was excited. I was like, wow, I, I get that way too. It Was brave enough to put that one in.
Something in not with It's crazy time to be alive. I know. It is.
Everything's ai. But yes, if anyone can make it, I would love to see you there. com, find out more information about that.
I love it. Rob, thanks for coming on. Thanks.
Talking with us today, man. This is great. Hey, go check out the rest of our AWS reinvent videos.
Scon is coming, I believe it's April 20, the 23rd, as Rob mentioned in Prague, which is a great city. You don't have to be in Europe to go to that, though. They do have planes that come from here to there.
Yep. And, and, uh, it might be worth your while. It's, uh, I've done sko actually, the last Scon I did was in Orlando near our house.
Yep. But it was a great event as well. So highly, highly recommend it.
But that's it for here. I hope you've enjoyed our AWS Reinvent coverage. This is Alan Shimmel for Text on tv.
Hey everyone, welcome back here to Techstrong tv. Our next guest has been on with us before. He is my friend Jonathan Redi.
Jonathan is Chief Product Officer at Check Marks, and we'll get into this in a second. Let's first welcome Jonathan to the show. Jonathan, happy New year.
It's great to see you. Happy New Year, Ellen. Great to see you and great to be here.
So Jonathan, uh, you know, for people who are not familiar with yourself, I mentioned you're the CPO over at Check marks, but why don't you give them kind of a sense of your journey? Yeah. Well, as many people know, check marks as insecurity.
And I started in security, uh, many years ago at the beginning of DAST and Sast years ago. And, um, left security for a while. For the past nine years, I've been at PagerDuty delivering solutions to developers.
Um, and there's a lot of similarities between, you know, the urgency of major events that happen and, and the, uh, identification and the, the security vulnerabilities that are found. So a lot of, a lot of similarities brought me back to security and brought me back to check marks, uh, just at the beginning of this past year. It's been a great journey so far.
Beginning of pa last year. Yeah, the beginning of this past year. Sorry.
I know. 20, 25. Yeah.
I just wanna make sure Happy be New Year. I always messes me up, Jonathan and I always need to kind of make sure I get it straight. Um, and of course, we, we knew you had PagerDuty, our, our friend Damon Edwards was there as well.
And Covered page. I I covered PagerDuty, I think from when they launched. Yeah.
Right. Yeah. Um, anyway, we're here to talk about check marks, though.
Check Marks is a company they really needs no introduction to our audience. We do a lot with check marks, but maybe there's some folks out here, Jonathan, who are not familiar. Yeah.
If you wouldn't mind give them kind of the check marks story, if you will. Absolutely. Well, check Marks is established really a leadership position over the past many years, uh, in application security.
And we've always been primarily focused on app security, so security before production. Um, we integrate with all the, the CNAP, all the, the production vendors out there, but have been very focused on really two audiences. Um, the application security teams under the CISO that work and partner with development.
And over the last two, two and a half, three years, many in the audience may not know. We've made huge, huge progress in delivering really seamless experiences to developers. As we all know, from the beginning of, uh, security, uh, for developers.
If there's any kind of friction out there, developers are gonna resist using a security product. So it has to be a part of their workflows, has to be a part of what they do. Um, so that's been a journey we've been on and made really great progress there.
And additionally, like, who can't talk about whether it's the life cycle and how it's being disrupted or, uh, how applications are being built and how they're being secured then to talk about kind of, um, AI and the disruption it's creating. And so we've over the past year have delivered, um, a set of agents, uh, that work along the life cycle to augment both development and AppSec. So it's been a really exciting time, uh, a lot of change happening and a lot of just marquee customers out there who are continuing to use our product and engaging even more, like using the product even more.
Given kind of the anxiety level going up with ai. Absolutely. There isn't a, you know, I was just in the last interview we was with the Cloud Security Alliance.
I'm sure you're familiar with Jonathan. Yeah. They, they have a, a new study out around AI and governance and security, and the, there is a tremendous amount of anxiety, a lack of trust in some cases, uh, just anxiety around the whole thing.
Um, now, Jonathan, you know, we've all seen some of these numbers. How much code is actually being generated by AI today? And, you know, it used to be, oh, it's just in test systems, don't worry.
It's just in the dev environment. Well, no, it's in, it's in, it's in production. There's a lot of code out there.
It creates a lot of anxiety. It's scary. Now, check marks recently made an acquisition, right, to help bring or graft some, let's call it AI security, uh, DNA onto the check marks, you know, uh, organism.
Talk to us about that if you can. Yeah. So we look at, you know, what is happening for all of our customers today in a couple of ways when it, uh, in the lens of ai, there's AI for security, how can we apply AI to help those using our products, developers and AppSec teams.
And then there's security for AI are what many of us refer to as AI security, which means the supply chain of, of applications, how applications are built. There's a lot of new elements out there. There's models, LLMs that are getting built in.
There's agents that are getting built in. There's things called CPS that are, um, you know, getting built in and six months ago who was talking about this. So things have changed very rapidly to your point of kind of the anxiety level of, of CISOs going up very, very quickly.
And I think two things are happening. The dynamic I see, one is development teams due to the promise, you know, with great, um, power comes great responsibility as they say. And I can generate, I can create more, I can be more productive.
But with that comes a responsibility to make sure that's secure. And so the development teams and the leadership are running fast. The CISOs as, as we talk to them, uh, very much feel that anxiety you're referencing.
And we started this plan, uh, and delivered products midpoint of this past year, 2025, uh, with the first set of agents to help, you know, developers and AppSec. We call that the assist family of agents that sit on top of our SaaS platform, check marks one. And, and that's been very successful.
It's, um, delivered a lot of value to our customers today. Uh, changing like from a, a reduction of cost, reduction of time to identify and remediate for developers like upwards of two and a, uh, you know, two thirds. So 60% of the time that it took before manually using our agents, we can reduce that time.
So huge savings, uh, both in time and cost, and then ultimately reduction in risk. Now we launched that, that was really successful. And then around, uh, November, December, we started talking with some other vendors in the, in the market and, um, decided to join forces and acquire a company by the name of Tromso.
So tromso is a pure play a SPM vendor. Uh, we have an A SPM solution that sits on top of check marks one. And one of the reasons we're attracted to them, actually two of the reasons.
One is, um, um, harsh, uh, PARIC, Harshel Paric, their CEO and co-founder, um, is has been a CISO in the market before he started his company. He's done a great job of building out a set of agents that will help in triage and remediation of issues, which is like at the core of both what dev developers and um, AppSec teams want to do when they're looking holistically across all the repos. So a lot of expertise in some of the products to help accelerate our agenda.
Um, and then secondly, the, the talent of the team bringing them in. So accelerate our agenda on the products and accelerate our acquisition of talent. So it's been really, uh, a great marriage so far, and we're ready to start releasing our new set of agents.
Love it. And you know what, as we sit here in the new year, Jonathan, you know, 2025 was gonna be the year of agent ai. In many cases it was.
But I, I think a common thing I hear from people is these agents aren't so great yet, right? They gotta get better if we're gonna be using 'em. And I think that's gonna be a key piece of 2026 is getting these, and it's not just security related, but ag agentic, AI in general, making these agents easier, more useful, working the way we think they should work.
Um, but I, turning back to AI generated code, Jonathan, I, I need to, you know, I I, I've spoken to a lot of people on this subject. I read a lot of surveys, seen a lot of data. Here's the thing, when we look at the security of human generated code, the line is kind of flat, right?
In terms of the, the, the amount of vulnerabilities, you know, per 100 lines or whatever you want, however you want to judge it, it, it, it's not really going down a lot, but it's not necessarily going up. It, it's kind of flat. You're getting, I forgot what it was, 30 vulnerabilities for X lines or whatever.
In the case of ai, that line is going down. It's not the hockey stick line, it's the, you know, it's going down pretty drastically as time goes on. We're seeing less and less vulnerabilities in AI generated code than in generation before gener.
And the generations come right after the one, right after the next. From what I've been told is that we're roughly at a point now where we're approaching AI generated code having the same amount of vulnerabilities. It is, you know, raw.
I'm talking now from human generated code. They're, they're roughly equivalent almost now. But the thing about it is the AI code keeps getting better in terms of it.
And the human code is kinda flatlined, as I said, unless you're gonna apply AI to it, to, to kind of goose it up, if you will. Now, are we holding AI generated code to a higher standard than we do human generated code because we trust it less? Or is there something is, you know, are we rooting against AI generated code is, as it, I think comes out in your own study, 60% of code is generated by AI today, something like this.
Um, it it, you know, is it only going to get better, meaning more secure? And are we, you know, are we pining to get 100%? Is it even possible to have 100% secure code?
Yeah, it's, it's a, it's an ongoing debate, Alan, in the, in the industry. com. So if you go and look at that, you'll see, um, testing of every new model from a security lens to see, um, each new model.
How secure are they? And to your point, absolutely, um, the models are getting better. Um, they're learning, uh, and they're still generating insecure code to be sure, like in the 30, 35% range.
And, and to your point as well, it's starting to rival the, um, the, the, the amount of vulnerabilities that a human would, um, put into the market. But there's still vulnerabilities there. I think what's interesting over time is if you take this out to its kind of continuum, like out into the future, um, at some point, will the generation of code and that code being secure be good enough?
In some ways it will be. In some ways it will be. And that's a good thing for all of us.
And that's a good thing for developers. Um, I think the nature of the, uh, of the vulnerabilities though that are there is what's interesting. Uh, I think that that changes.
So, you know, if one of the things that can be and likely will continue to be prevented, avoided, are some of the basic, um, many of the basic type of vulnerabilities that a human would, um, inject into their systems. I think the harder things will be, uh, not the SQL injections and the cross-site scriptings, but the logic challenges that become very transitive, very, you know, kind of, um, one step removed. Those will be harder and harder and harder to manage, and AI can assist in those areas.
Um, uh, but it won't solve all of them. And so I I I think that we will get to a place where generated code is absolutely more secure. But will there be, if you take that to its, you know, kind of final state, uh, will you need application security or testing for security?
I know I'm a suspect being a vendor in the space, but a hundred percent yes. And I can see the nature of that, just like the nature of development is changing, the nature of security is changing. And so maybe the, the, the traditional static rules of the past may not apply, but dynamic becomes very important in this kind of a world dynamic testing.
Um, many other aspects, uh, can be, can be added to augmented to make sure, again, with, uh, with more vulnerability and more surface area becomes, uh, way more, way more, uh, threat and risk. And, you know, it's, we just got everything under control when it comes to the world of supply chain, open source libraries. If you think about how applications are built today, you know, 60, 70, 80% of applications come from components that weren't developed, right?
And along comes AI and the new AI supply chain agents and LLMs and models, these need to be secured now. So, you know, the more things, uh, change, the more they stay the same. There's, there's more threats all the time.
Absolutely. And, and I think the answer here, Jonathan, is we need, we need to improve the security of code no matter who wrote it or what wrote it or how it got here. If we're putting code in production, we should have a high degree of, of belief that it is, or high degree of certainty that it is in fact secure.
And that that's really a, whether it's AI or not, you know, when, when AI is generating a majority of the code, this, this artificial distinction between what was generated by machine versus cumin is just that artificial all code needs to be secure just like all rights and women's rights or whatever Hillary's said back in those days, right? And, and I think that that could be a mantra here. Um, I think we're about outta time, but Jonathan, where can people get more information to stay on top of check marks?
Yeah, thank you. So, uh, we have a lot of thought leadership, a lot of material that can help, uh, your audience out there. com, but as a part and on that website, uh, we have one of the biggest, most well-known research groups that are constantly figuring out and identifying new vulnerabilities and the best practices of how to address them.
And we freely share that on something called Check marks Zero. It's kind of a play on words from check marks one, check mark Zero is before check marks one, that's our research team. Very cool.
Um, and so there's a blog out there for them where everyone can go there. Um, we're trying to, to your point, make sure systems are secure with the kind of the ever-changing landscape. So we codify that into the product, obviously.
But, but that's for the good of all and for the benefit of all. Love it. Jonathan, it's great to have you here on Text Drug tv.
Don't be a stranger. Thank you. Thanks Alan.
Really appreciate it. And uh, again, happy New Year. You too.
Maybe we'll see out. You're gonna be out at RSA. I will be There.
I'll see you there. All right. For sure.
Jonathan, Randy, chief Product Officer, check marks here on Textron tv. We're gonna take a break. We'll be back Control.
This is agent dev. I'm in position. Copy that.
Dev. Stand by for Go Standing by. Hey everybody, welcome to the Agents of Dev podcast.
I'm Mitch Ashley. I lead the software Lifecycle Engineering Practice Analyst practice at the Futurum Group. Brad, welcome.
Always good. Be good to be doing this with you, my co-host. Yeah, it's, it's great to be doing the show with you today, Mitch.
And, uh, I think, I think we have a, a fun topic, uh, on hand. Some something that I, I'm sure a lot of people that are listening in are, are exploring and or dealing with right now, which is the idea of how do you use ag agentic tools to, to actually build code on day two, not day one. Mm.
Mm-hmm. Listen, so when you go beyond the travel agent book, my, have booked my flight, find me a flight example on every developer blog, how do you use this ID to actually do, do your own work? So right, we are talking about, well, we're gonna probably touch on three of 'em.
I know we, we've had a lot of the most recent activity with Google, Anti-Gravity with AWS Kiro, some announcements at, uh, at, at, uh, a Ws reinvent. And of course, Bob. Bob.
Uh, what about Bob, what about Bob? I'll never tire of that. What about Bob?
I'm a, a child of the sixties, seventies, so I, I definitely know about Bob and we have of course, you know, copilot and all, you know, cursor and windsurf, and there's all, you know, everybody has an IDE these days, which I can't remember if I said this on a previous podcast, but, you know, I, I thought all those developer jobs were going away. We're sure creating a lot of tools for these people that don't, aren't gonna have jobs. And so I don't believe those jobs are going away.
They're changing for sure. That's for sure. Um, yeah.
Actually, you know what, I, I think you're right. Yeah, I, I I like the notion that, um, all of this tooling is going into, um, helping people who, uh, do the jobs that they lost. Hmm.
There you go to basically do, to do the work that you used to do, but do it in a new way. So you're saying this is a retooling to how to get your next job. Next job.
Is that what it is? Yeah, just, just to get a raise. 'cause otherwise you have to quit and come back.
That's right. Well, I think that's, that, that's an axiom of the universe. I think that seems to be universally true in about every That's so true.
It's funny when you give people that advice, how do you get a raise? Well, you should probably go, go somewhere else and then come back. Go get a lot more money tends to happen.
It does, tends to be true. Um, of, of, of the, of the ides, have you spent more time with one than the other? I know you do a lot of development, Gemini, um, but of course anti-gravity is pretty new stuff.
Is there anyone you have more familiar with than the other? Yeah, I, well, I, I, as you say, I use Gemini CAIA lot 'cause I, I got into computers because of Ask Art. I will stay in computers because of Ask Art.
So do you have that Mon Lisa still on still, you know, on Green Bar in your It was, it was Jerry, Jerry Garcia, uh, believe it or not, was, was my first like, mind blowing Askie art experience. Mm. Um, and so anyway, yeah.
So I I, and as you know, I, I have a profound hatred of electrons. So I, uh, don't, don't use many of the electron based tools, which are quite a few of them right now, because so many tools are based on vs code. That's great because it has a rich ecosystem and a lot of plugins, et cetera, et cetera.
But I've been, I've been using, if I'm not using z uh, which has a Gentech tooling built in, uh, I for, you know, non Gemini, CLII, I've really been gravitating toward Open code, which has a degree of what we're gonna talk about today, baked into it. And I've noticed this more and more with these tools that, um, you know, they have two modes and you can just toggle 'em, you know, from the command line. 'cause that's why we use a command line so we don't have to reach and click, um, anyway.
So you can basically just toggle to, to thinking mode or planning mode and then toggle back to coding mode or fixing mode, or whatever you wanna call it. And it can be anything you want actually. 'cause you can customize those to be whatever you want.
All, uh, uh, was it Claude's, um, uh, skills kind of, kind of idea. Mm-hmm. Yeah.
Claud Yes. The skills. Yeah.
And, and part of what this, this toggling does to planning mode is to help you to, to set up, you know, a very rigorous or supposedly rigorous, um, methodology and framework for doing something. Be that creating your new find me a flight app or on day two, uh, fixing your flight app because it's throwing a silent error that you can't trace back to, to the source. Mm-hmm.
So mm-hmm. If, if, if you go into planning mode and say, wow, I can't find this error, it will say, okay, he doesn't want me to just jump in and fix it. He wants me to think about what the problem is to find the problem, to find the steps to resolve the problem, and then we can switch back over to execute mode and, and fix it.
And that's spec driven development. Mm-hmm. What we're seeing right now, uh, is sort of a ma maturation of that, where in a lot of these tools are sort of bringing in, uh, purpose-built spectrum tools.
Sorry, these IDs are bringing in spectrum tools. So you have, uh, as you mentioned, Bob has it baked in, uh, KIRO from AWS has it baked in? Um, you can download and use, uh, OpenAI, or is it, sorry, it's GitHub's spec Kit.
Mm-hmm. Which you can actually run in pretty much anything you want. And these tools basically do a couple of things.
They'll, they'll let you sort of initialize your projects if you've never run them in there before. And when they do that, they'll, they'll do, actually, I wrote it down because I did this last night with Conductor, which is this plugin. They call it Google.
Google calls it an extension. An extension, yes. A different term.
We do. Well because, 'cause it's really different than just using an MCP server. An extension is the entire package built into the surrounding, um, tool itself.
And so it can itself include MCP servers. So it's like a mod in, you know, Minecraft or something. Yeah, totally.
Right? Yes. Yes.
Uh, for those who don't know, Mitch enjoys a bit of the game. I have been known to partake a few weekends or two counting this last one. And it's, it's, yes.
We must talk about that, by the way, because, uh, I, I, I found that very fascinating because what, what Mitch did this weekend in sort of, uh, asking agent AI to talk to him or to create for him a, a sort of means of saying, what does Mitch like to play? I found that really, really cool. This is with chat GPT.
Just as an aside, I asked it, I said, so I do a lot of work with you, you know, a lot of my preferences, I've explicitly created artifacts with you about a number of them, none of them about gaming. But I have asked your questions. So analyze for me what kind of game, what kind of games do you think I like?
What kind of games don't you think I like? And why? And it went through and it said, and it was very accurate.
And it's, it's because I, I have such short time windows. I can't do games that are, you know, sit down for, for a weekend and really play the whole thing. Like my No, no.
Skyrim for you Skyrim. Well, you know, I could, so, so it's possible, if it's possible and you don't have to step back in and like, there's a whole, you know, storyline that you're following that you have to remember that you talked to this person way back when, right. All that kind of stuff.
So if you can kind of step in and out of it, it's, uh, much more accept. So, so even like, um, a Civilization C six, I'm not a fan of seven yet, um, but it is com gets complex towards the end of the game, the end game. But I, I can pause, I can save and come back, start over, do whatever.
That's kind of the games that I like. Yeah. And this, so when it, I have to ask, do you have memory turned on in chat GPT?
Have you, have you had it turned on for a while? I have. I've had it turned on for quite a while.
Probably two, three months at least. And I think that that actually speaks to the topic of, uh, hand today. Does it not?
Because spec driven development is, is really nothing more than treating context like a managed artifact. Mm-hmm. That sits next to your code.
I was thinking exactly the same thing in, in getting ready for this podcast, is you can see the parallels between the, the, the, let's call 'em retail versions of these products. The, uh, Chacha BTS of the world, quad, Claude, et cetera, is very much the same thing as they, they're creating what they call artifacts. And, uh, like you open a canvas that's now an artifact that within some context window within a particular tool, that it's gonna remember those things.
And so if you want it to remember, one of the things I did was create a little memory system at one point where I wrote out, uh, remember these things out to chase on. Oh, you didn't, you didn't make a graph database? No, I, I didn't have that much time that weekend.
It was experimental. Kind of see how would this work and recall. And so, um, but that, that's what, that's what these kind of spec driven, or the intent driven, I guess is what Bob calls.
It's interesting to me that we're, weren't we doing spec driven development all along kind of. Yeah. We kind of were, but now we have way of actually integrating it into the workflow, you know?
Yes. It was, yeah. I was actually stories and all that before a spectrum driven human in a past life.
Uh, I was a business analyst. Um, and so I would work with the developers to define the project, to, to set all of the goals for the project, to define the tech stack we were gonna use, et cetera. And that's, that's really what these tools do.
Mm-hmm. So, to, to jump back to, you know, this conductor extension for Gemini, CLI, I, you know, had a project that was only, you know, 350 lines long. So very tiny.
And it did something. It was, it was basically a research agent. 'cause you know, we're analysts, so always looking, it's for someone to do some work for us, right.
Not lazy at all. Um, and, and, um, so when I, when I initialized it, it, it did a number of things and it was, it was kind of interesting because it actually opened up and ran within the CLI tool itself, another CLI tool that had a user interface where it, it was basically a, A, B, C, you just would say it would ask you a question and you'd answer a, you know, and then hit return, or you would enter, uh, just a sentence to say, no, this is what I mean. And it would guide you through the steps of trying to initialize this project for spectrum and development.
And, and what it got to at the end of that process was it defined the project goals, it defined the tech stack, you know, by looking at what I had, which is something we should come back to actually, because it's an ongoing pet peeve. And, and spectrum in development doesn't solve the problems that we already have in these tools. Just everyone note that.
Um, anyway, it, it would define the code style, uh, for it, the style guide, uh, PEP eight for me. Uh, and it, it defined the overall project guidelines. And, uh, importantly, and I found this really fascinating, is that it, it identified and documented known blockers, uh, to the projects, to, to getting things done.
So a blocker is a constraint or missing information or whatever, you know, would keep the agent from completing whatever task you give it. So, so you finally found a way to constrain the agent from writing code. That's been the problem with the whole vibe coding, is it loves to write more code for you, more code than you wanted.
Oh, it does. Yeah. In all the wrong places.
Say some more. In, in, in, in the kero, uh, IDE it very much has phases, right? Has, um, planning, design, and development, you're explicit.
Yeah. Just like you were talking about, you go into planning mode, and it sounds like that constraint is, before I move forward, I need these things, because that's part of the spec process. But if you defined that to be yours defined in the tool, which is a good thing, sounds like, I mean, you can prototype, you can take it so far, black box some things while you're working on the spec to try out ideas, but still contribute to bat.
And, okay, put this in the spec. This goes back in the spec, you know, to, uh, memorialize make that part of the artifact that you're creating memorializing memory is, is like such a difficult part. And goes back to context as artifact, which is what these do.
And prior to this kind of of tooling, um, for me anyway, I, I would demand, you know, I would type forward slash I think it's memory. Um, my, my memory's that bad. I can't remember.
Um, but at any rate, you would, you would use an internal command to say, remember to, um, remember that I'm using this version of this API. Mm-hmm. And because, you know, that's kind of critical and is a big problem with Yeah.
Large language models. Um, so it would write that to, uh, Gini MD file in the root, the i working in for the, and you know, if you didn't curate that, if you didn't go back in and carefully manage that memory file to, to get rid of things that have been, you know, ob obviated by, you know, discoveries or changes down the road, you really could get wrapped around an axle because it would be like, wait a minute, Brad said that I want to use version X, but in the same file he is telling me to use version Y. I'll, it's interesting what memory wa it, what things it will save.
Sometimes it's like, that's not when I would've wanted you to save. Right. That's actually not right.
Right. Which, which goes, you, you were talking about the tech stack earlier, and I find this for just using the, you know, using, uh, uh, Google Gemini or, or chat GT when I'm not doing it inside of an IDE or a development tool is, you know, even when you tell it, the tech stack, first of all, you have, you really need to have a running list of what your development environment is with tech stack you're using for this project is explicitly what versions, um, because it will either assume things. I mean, I've had it like say, okay, go download this.
Well, that, that doesn't exist anymore. They canceled that, that they deprecate deprecated that actually nothing or worse, they uses d totally different package manager than what you're using uv, PEX and pip, for example. It's just like Exactly.
Toss a coin and package manager. So you gotta be very explicit. I mean, I list everything from mm-hmm.
You know, the full development environment that I have set up through, you know, through home brew or in, in that environment to, you know, what are the, what are the keyboard, um, memory, um, macros that I use on the Mac, because I might do some things in automations that way. Like, and, and I have to explicitly tell it. Do not suggest that I use things that have been deprecated, do not use, suggest things.
You are not in the product yet, but may have been mentioned in a product release. So Yeah. It's, um, yeah, like, you know, if you're not using robots txt, you're already in trouble.
You, it should already be there. Yes. Yeah.
Ignore it. I'm sorry. More, more specific to what we're talking about though.
Sorry. I was just, I was just thinking about, you know, protection, protecting yourself, but, but, um, requirements, you know, if you don't have a requirements file, you're, you're asking for, you know, a misunderstandings, like, like you're talking about. So you gotta start from a good foundation, especially if this is a brownfield, you know, endeavor that you wanna use spec driven development for.
Mm-hmm. And, uh, it actually, you know, it, I would add to that, and, and I know we wanna talk about the, um, tech stack a little bit more, but I, I, I felt from my short experience with Kiro and Bob and now Gemini, CLI conductor, that, you know, you need to buy into this. This is not like a, I think I might use a bit of it here or a bit of it there, or, uh, just try it today and not use it tomorrow.
Use you, you know, are basically saying, I want this to be spec driven, and as such, I'm going to be using an internal tech. Uh, what, what do we, what does, uh, conductor call them? Um, where, where you have a task, they, they call it, uh, hang on, I'll just look it up.
Well, what you're describing is opinionated software. It has an opinion about how you have to develop software and you have to buy into that. It makes it very opinionated, right, man.
Mm-hmm. So they, they call them, um, tracks. So you have a track, and I, I should note that, um, it's very agentic doing the initialization for, for tools at least like this one in that mm-hmm.
It read my code base, it asked me what my objectives were, et cetera, to do all those things we were talking about and setting up the spectrum and development, you know, basically a, a file structure, a directory structure filled with markdown files. And I was shocked to see it come up with the first track. For me.
It's like, I, I just finished initializing and it said, oh, I really think that you, you want to do semantic search, um, uh, enhancement, because I, I was trying, um, Gemini's Gemini, uh, has a deep research, uh, which is basically you're not calling a model directly. You're calling a, uh, a, a sort of implementation of a model that that is very opinionated. And like we were talking about Claude, uh, like skills that, that's basically built on skills.
Mm-hmm. And this thing, which is, if anyone's interested, it's called deep research. Sorry, these are all hyphens.
When I pause deep research pro preview 12, 20, 25, it, it, uh, it said, oh my gosh, why don't you add semantic search to that? Because I had a different, I have like a, a different sort of, um, mechanism for doing this outline research, either through semantic search or through the deep research. And it said, why aren't you combining them, Brad, you idiot.
Mm-hmm. Mm-hmm. And, uh, so it specked out that that track with all the requirements, all of those planning steps that you mentioned to build this, it's really fascinating.
Well, I, I'm not an expert in, in any of those tools. We just don't use them, uh, you know, living inside of them doing, doing work on them every day. But it seems to me the kiro is the one that's bought into the process as much or more than any of 'em.
'cause yes, it has those planning phases and Bob has architecting, et cetera. They all have kind of some ver version of that. But kiro really, I mean, it includes specs for, uh, acceptance criteria, traceability testing, um, yeah.
Yeah. User guides. Um, it's really, you know, AWS made a big deal about where we're using this, this is our development environment across the company.
And you, you could see how that might be because they put so much into not just doing agent development or using agents as part of development, but making it, I dare I say methodology. I don't wanna start any methodology wars, but, uh, yeah. Some opinion made stream programming.
Yes. Yeah. Well, I lived through a few of those.
The agent wars are upon us. Mm-hmm. But where whereas, um, like with anti-gravity, you can definitely see that they've leaned heavily into the agent first.
Uh, ID, you know, using multi-agent orchestration to do work for you. Right. Yeah.
And I don't remember if they explicitly call it spectrum driven, but a, a, a version of that. You, you can, it's doing that plans and screenshots, that's like open code and uh, you know, they just have it built in as different modes of working. Mm-hmm.
You know, it's one of the things I'm curious too is uh, 'cause I think at Gravity's supposed to be good at working at much larger code basis, and that's sort of the, one of the, there's lots of challenges and different vendors have taken on parts of it. And when you work with much bigger or multiple code bases Yeah. Keeping that, that in the context window and the memory working with that know where you're, you know, God forbid you say, you know, Hey, put in that search and whoops, that's not where I wanted it.
That was a different project. Right. Um, but that's part of the complexity too.
Them being able to take on more complex work, not just coding tasks or types of code to write, but the work of writing code in the environment that you're doing it in. Yeah. That's a big deal, isn't it?
And that, and you can see that reflected similarly to Kiro in IBM Bob in that they have built in using their, what would you say, 50, 60 some odd years of experience with cobalt. Yeah. Something called punch cards, I think.
Anyway, D switches on a computer. I believe those, those exist in their repository. They, they have fine trained, fine tuned, sorry.
Wow. They have fine tuned, um, their mo you know, the models that they use for these specific tasks, like you're talking about in managing a large code base mm-hmm. To, you know, they were early to, to come out with this sort of, let's use LLMs to refactor from one language to another or to transcode and, um, with, I think it was COBAL to Java that they did.
And that has grown into Bob and it plays a role in Bob for managing large code bases, not based on what they got off TE stack, sorry. Um, stack overflow or God help us Reddit. Uh, it, it's actual like, you know, IBM you know, professional services, you know, use case number two nine x 94, uh, has a very, you know, distinct solution and pat design pattern that's tested in, you know, some World Bank and now you can enjoy that and use that to solve problems across a complex code base.
Love that. It's, it is interesting. Yeah.
The Bob leaned into the modernization path, right? Helping people modern, modernize. And a lot of that is of course the LLM that they're using our LLMs, uh, by default.
Um, which pushes that button. You know, the, the other we haven't really talked about, I dunno if you considered an IDE cloud code, you know, is something you plug into your IDE or you can use it very much from the, the command line, but essentially you're doing the same thing instead of them issuing their own vs code version. Um, you do it just like you do with, uh, I guess it's Klein is what it's called.
I've used it for a fair amount on a project I was doing a while back. And then, um, same thing for, for, uh, for open, open AI models that you, you interface to it either through a window, uh, in the command line on a, in your IDE as well as directly on the command line. So there's sort of these different phases of, it seems like so far, anti-gravity is kind of the most opinionated in the user experience of we wanted you to work this way.
AWS kiro is the kind of development process. Opinionated. We want you to work through these design steps, these, these requirements, spec driven steps.
Bob, on the re-engineering side, we'll see, but Bob was, was pretty early when we saw it, so we'll see where it goes. But the, the tracks that people, different people are going, and you can see part of it is the customers that they serve, right. Lean, heavy, heavy into agent development for Google.
That makes sense. You could see why IBM would do more of a refactoring and, and helping people modernize code. Yeah.
Because you know how we used to talk about data gravity, we still do. Um mm-hmm. Data has gravity.
It's all designed around locking your data into a platform that you'll pay for, you know, in, in perpetuity. Um, but I, it's called cement cement boots. It's cement.
Yes. Yes. It's very lucrative cement.
Um, but it, you know, developer gravity, it, it means a lot. It, it always has and it always will. And what I see evolving right now, um, is this sort of, you know, my walled garden, my semi walled garden is better than your semi walled garden either because it has better models in the backend or better tooling on the front end, uh, or better services in the middle of the two.
Mm-hmm. And so, you know, these are all I've said for a long time that the, you know, the frontier models were always meant to be platforms, not just models. And they are absolutely evolving into that.
But the tooling, you know, the things like you and I have been talking about today that we decide we like something and, and so we invest time in it. And if you invest time in it, this thing, you know, that, that we all know and love, uh, called not entropy, but, uh, uh, what, what is it where you build momentum and can't stop the momentum from going, um, can't think of it. It's not brown in motion inertia.
It's inertia. Inertia, yes. Yeah.
Need, need to think about thermodynamics that inertia carries forward. And, you know, the more in an organization that they get a nerd in these tools, the more likely you are to buy this backend services models that, that are associated with them. And that nails it.
So you see, like, you see like all the, all the investment right now in, in, I think making these enterprise grade is critical and really a, a good step. Um, 'cause this is, we are, we have changed how we think about code, have we not, Mitch? Mm-hmm.
Absolutely. It is, this is first time that I can think of that we really are buying into, at the very front end of the development tool, the IDE of how we're gonna develop software, right? It's been more of a window into our repository and tools and plug areas.
It's been the Swiss Army knife, right. For development. Um, I call it the, uh, smoking shop.
You know, I I I, we all brands of cigars, but we'd like you to stay here and smoke 'em here. That's right. We have a lovely room with leather chairs.
Just sit here. Yes, exactly. This is where you should stay.
Not that everybody out there smokes cigars, but, and I don't that much either. But anyway, it, it, it, it is an opinion way, opinionated way that organizations, when they sign up, they're gonna use this tool as their IDE, then that's the path they've kind of chosen to go down. So yeah, it's, it's, um, you know, how, whether it's cement boots or walled garden or a lighter touch, it's to keep you in that environment.
Of course, they work really well with their technology and make it easy to do that as well as third party stuff. That's the key with the platform, you know, oriented tools, the hyperscaler oriented tools you see from like Kiro and Bob, like we've been talking about. Kiro, you know, is steadily surfacing functionality that's been, you know, sitting inside of Bedrock and, um, their broader AI platform, for instance, SageMaker for some time.
And that's only going to broaden out, you know, I, I can see all of their analytics tooling, for example, starting to, to be baked in with, you know, headless business intelligence being a part of your application development process. Your spec will have a spec on how you want to visualize data and work with data, for example. Very good.
Well, we've, we've overstayed our welcome here a little long time. Sorry. It's, it's the holidays.
It's the holidays, Mitch, you know, we're being watched and, you know, we're being trailed here, so we should, uh, get to our last segment. That segment is the drop. Okay.
It's time for the drop. Well, you know, it's, it's, uh, end, end of the year for, uh, us going into the, the next year. We're, we're obviously deep in our planning cycle, kind of towards the end of our planning cycle.
What we're working on, there's kind of two areas of focus that I'm looking at right now. One is how are we moving observability, uh, security behavior governance into the development process using agents and, you know, companies like New Relic and Dynatrace. And I could go down the list of companies who have been part of announcements with some of the major vendors that they are now part of AWS's security agent or Dev DevOps agent, or pick your vendor.
Um, so other parts of the software development lifecycle are not waiting, um, not every vendor's doing this, but I think the folks that are, wanna make sure they're carving out a path for themselves to be part of this, uh, kind of ai SDL or ai DL c um, very much part of more letters Please. More. I'm, I'm warming up for New Year's Eve, I guess I don't know what I'm doing.
But anyway, that's, that's definitely on my mind going into next year, uh, uh, as well as many other things. How about you, Brad? Uh, yeah.
And I'm sorry, the, the longer the acronym, the better, you know, three letter acronyms are aren't even trying. I can't, that's really put some effort. I can't approach the one you gave then.
Well, that was the name of something, but you know, it was a, right. Yeah. Yeah.
Um, so I, I think for me, and, and, uh, it's interesting, given what you just said, it, it jives with, um, one of the predictions I have for the coming year, which is that data engineers are, are going to morph a little bit into integration engineers and that companies won't be buying their data platform based on, you know, the specs of the platform as much as they will the meet the way that that platform integrates with their investments that might be, you know, with other vendors on other platforms. So it's definitely, you know, changing how, how these age old, these stable jobs that we've had in the industry for so long. Um, for me, what's on my mind right now that I'm trying to like wrap my head around a little bit is I, I saw a note from one of my colleagues yesterday talking about how, um, agentic development was gonna break the database.
And I'm thinking, well, I, I don't know, because we, we built databases when we had very little resource to play with, and we built them in order to scale massively and be concurrent as possible across that scale. And, um, so I I, I think the problem isn't so much in doing reads and writes, 'cause we, we know how to do that and mm-hmm. Pick your database structure.
It doesn't matter if it's, you know, a blob storage or column or NoSQL or, um, you know, KV cache or wide, you know, field wide table, sorry, um, like Cassandra, it doesn't matter. They, they all are pretty darn performant. Uh, the problem is agents, you know, need instant context.
They need, and I, you know, I think you and I chatted about this a while, a while back mm-hmm. With, um, if you're outta sync even a little bits, um, big, big problems can happen. And so timely access to accurate information is critical.
And how do you do that? Well, you certainly aren't doing a query from a, you know, data warehouse to do that. You certainly are bringing the data closer to the code, to the agents, and, um, you can do that through streaming, uh, which is why we saw IBM pick up Confluence, uh mm-hmm.
Because that's kind of a big deal. And another way is big deal, the developer's favorite pastime, which is caching every you and managing cash almost every, yeah. Ev almost every problem can be solved with cashier.
Um, and, uh, and it already plays a big role with the age agentic tools we're talking about, like, every time I hang up from a session with Gemini, CLI, it tells me that I saved, you know, 80% because it had that many hits from cash, that percentage of hits from cash. Wow. Like, wow, I really am forging new territory, aren't I?
You're supposed to overdose to your manager. Yeah. Say, you know, it's like they, you 72, this, this trip to the Brad is so boring in what he does.
Everyone's doing the same thing. Um, post, post it unread. So trying, trying to think about, you know, how companies can speed up, you know, access to data for, for agents latency, agent latency, waiting for those, for the data, the context that it needs.
Very interesting. Yeah. Well, my friend, it's been fun, um, a lot.
I have so many ideas for, uh, things for us to talk to. I know you, you do too. So we'll keep 'em rolling.
com if you'd like to make a suggestion. Uh, if you're interested in making it appearance, maybe being part of this, we've got some folks that are interested in doing that. And, uh, we're, we're kind of getting the, getting things rolling with Brad and I, and then we'll start to have some guests as we do that.
So send us the feedback. Thanks for following us on your favorite podcast platform. And thanks for coming back to listen to, uh, to us JobOne for a little while about building software in this new AI agent era.
Uh, behalf of Brad, myself has been fun. We'll see you on the next episode. Control.
This is agent dev. I'm in position. Copy that.
Dev. Stand by for go Standing by. Hey everyone.
Welcome back to our live coverage day, one of Amazon or AWS Amazon Web Services, reinvent. I am really happy to be joined by this guy here. You may not recognize him.
He looks 10 years younger. Sand's the goatee, he's lost weight. Come on.
He's in fighting shape. My friends, you know, the Steelers could use some players. Maybe you can help us out here.
You could watch that. That was bad. They would, they would pitiful.
That Was, I was proud of Aaron to come up and basically say with the no, just say, Oh, afterwards We need to do better. And I'm part of the problem. You know, like that's As there's a leadership message there, right?
I mean, I I do, I give him credit. It doesn't make it hurt any less. I think there's a lot of parallels to AWS they're, they're doing that right now.
They know that they sort of missed the first wave of this AI pivot. 0. And they're recognizing that things they need to do, and they're, and I think they're making those pivots this week.
They made a really big pivot. I thought you were gonna tell me Matt broke his, had a bloody notes too, but No, um, That was good though, right? Yeah.
That was Way to get back on, on track. I loved the way you brought that back in, into, it's like I've Been Here before. Absolutely.
So if you don't know this gentleman, Daniel Newman, CEO fu group, it's my friend. Um, I love working with him and he always has great insights. Like this little tidbit you just brought us back to AWS So we, I was talking with Mike Vard this morning.
Certainly this is all AI all the time this year at Reinvent. Um, what's your take? I mean, obviously they're making a pivot.
They're going hard at ai. Well, I think they recognize, so we are in the era of AI cloud and, you know, future, and we do our signal evaluation. AWS did not score in top two did not.
It, it has fallen behind both Google and Microsoft in this era. Now, AWS has this massive advantage called a humongous customer base. They have a huge customer base from the first cloud era.
And by the way, anyone that's worked with CIOs, as long as you have, I mean maybe as long as I have knows that in the enterprise, it's not the same as the consumer, right? And it's not the same type of pace of sentiment. There isn't a new thing that comes out and everybody just ditches Google for chat.
GPT when it comes to cloud. These companies are deeply integrated in AWS And so while this AI pivot maybe has forced some companies to do more multi-cloud and have seen some workloads go to Google and some, the opportunity is still really in place for AWS. So they had a couple of big things they needed to prove this week.
Uh, the first thing they needed to prove is that they really are the place for the enterprise to commit building ai, generative AI applications open up to more developers. com community knows really well. Sure.
Um, that they have infrastructure, that they have an approach both their partnership with Nvidia and making sure the market understood that they have the Nvidia they needed. That was something that early on they maybe rotated a little quick to their homegrown TRA chips before it was the right answer for a lot of their customers. And then of course, um, you know, they needed to, to show that they can really open their, um, aperture to the developers of the ai, you know, and I kind of, I kind of g glossed on that.
But like, you know, they, they focused on that, what they're announcments with Kira, what they're announcing there. Yeah. Um, agent Core with the ability to build agents, they need to be the place where people are building the applications that run their business.
So they had that mission this week. I think Matt Garmin in his keynote, he always gives a good key. He's a real product guy.
He's a real product guy. He really is. He, you could see it, It was a very product kind of That's the AWS way that is the AWS way.
And, and of course, you know, I think the one thing that they, in the last 10 minutes they did like a speed round of every other announcement that they had, you know, uh, Kubernetes and all their regular instances and CPU instances and storage buckets and everything else they're doing. Um, but like you could tell this was all about being a prove it moment that we are a cloud that's ready for the AI era. And I think they did a good job.
Absolutely. Couple of, you know, plays off of what you said. Number one, you're right, this almost wasn't about cloud.
We didn't hear as much about S3 and Lambda and Serverless and all these cool things that AWS pioneered. We did hear a lot of Agent ai, you mentioned DevOps actually one of the three main agents that they announced they call the DevOps agent. Yeah.
Which we, you know, I thought, you know, tip of the hat to them for that. Um, another thing they announced though, and I don't know, maybe it didn't register on your radar screen, is, um, what's it called? The Forge.
Nova Forge. Nova Forge. So I look at that and say, wow, that gets me excited.
And then I think, well, how many organizations do really want to build their own foundation model? Well, and that's a great point. And, and that was something I probably should have had on my third thing in the first list.
But first of all, Amazon is part of their prove it. So I mentioned, you know, the train and the vertical stack of infrastructure. They talked a lot about that.
But the other part of the prove it is I talked to, uh, investment, uh, bankers. I talked to other analysts. I talked to media press regularly of, I talked to enterprise customers.
A lot of 'em didn't even know Amazon built models. Right. So, you know, they had Titan originally.
They did Titan, yes. And then they really went in with Nova. But like really opening the market to understanding that they are in that business.
'cause that really is the complete, we have all the compute mm-hmm. And all the infrastructure. We have all the developer tools and frameworks, and then we have the models, right.
And being able to say like, and then of course Bedrock, where you can basically bring all these Models And plug it in and you, and you deploy the, the, the applications. That is the full stack story. And you know, you saw last week when people started to get the idea that Google and TPU could be a competitive offering to the sort of open GPU era.
Mm-hmm. Um, specifically Nvidia, but it could be a MD, it could be anything. Um, and despite the fact that I would argue that most of what was presented is not quite factual about that, the thing that's made Google so attractive, the reason it's risen to all time high is it's market cap.
So You're saying what was offered by Google, not what was offered by AWS or both? No, no. What I'm saying, well, first of all, I'm, I'm eventually gonna get to my parallel.
It just takes me a while. But like, okay, that what Google's doing in the full stack mm-hmm. Has given the market a lot of appreciation for Google.
Yes. Now Google is unique and they were rewarded. It's corpus of data is unique.
It's a little different. But Amazon has quite a bit too from its ads, from its commerce business, a lot of very unique data. And of course it has a lot of enterprise data, which is where the majority of data still actually sits.
But Google's finally getting credit for being full stack. They're getting credit for saying, Hey, you built TPU, you've built the network networking, you've built compute chips, you've built, They have the vertical stack, You've built the agent and applications and Vertex and builders. And of course then the models Geminis proving to be very good.
Amazon wants to follow suit. They want to say, Hey, we got Traum. Hey, we've got Nova.
Hey, we've got Agent Core. Hey, we've got Kira. Hey, we've got like all the things that you that are required for basically an enterprise to say we can run all our AI in one cloud potentially makes it more valuable.
Amazon hasn't gotten all of credit for that. And so this was an important inflection. Now we had to see how much the market digests that.
Yeah. And how much they believe it. Let me ask you a question though, at the train chips and the Google TVs too.
Is this really a competitor to Jensen and the Nvidia people? Or is Broadcom? Well, Broadcom makes the chips for, for, for Google.
So Broadcom is the full end-to-end design. They do it all. Um, But not for the Amazon tra No, no.
TRA is different. TRA is Marvell. It's all chip.
It's actually sourced through a number of different suppliers. Um, but, but largely Marvell. Um, I think the right question here is are custom AI chips competitive to merchant silicon and specifically the Nvidia ecosystem?
And like I said, to a lesser extent, you could argue the A MD ecosystem. Sure. Well they, they're the up and calmer.
Yeah. But like, I think the answer is, and I I I think we've talked about this, we've market modeled it. We do believe the custom chips will actually grow faster towards the end of the decade.
And here's the reason why. There are a small subset of companies that are the largest buyers of infrastructure compute. So there's a benefit.
And the reason Google really invested in it, now remember, there's seven generations in, it wasn't like they came out with a new chip and everyone's like, oh, it's gonna replace Nvidia. Seven generations in, I think in their sixth generation, they were able to train a first kind of high performing, large language model, Gemini advanced that was on their own infrastructure, which was a big breakthrough. 'cause obviously before the idea was like, everything has to be trained on Nvidia.
So that's, that was a pretty big inflection. But it, but Google, you think about what Google does, it does AI all day. It's doing massive volumes of infras of, of inference all day long on its own infrastructure.
It needs to think about its margins. So a company like Google that's doing that much scale, of course, might look at, Hey, here's three or four specific workloads. Let's build a custom chip that really works for everything we do for search for recommendation engine.
Mm-hmm. We'll build it at scale. We'll invest big upfront, but our, our, our cogs will get a lot better than when we don't have to pay that 75% margin to Nvidia.
Having said that, though, like the, they're always, at least as far as we see it gonna be probably one if not two generations behind in terms of the most advanced NVIDIA chips. So token economics, inference, uh, efficiency, uh, performance, memory, throughput, all those things that are really critical to training, uh, pre-training to doing large models, um, but also just to scaling tokens in, like agent errors may or may not be as efficient on those, um, on, on the custom chips when you need the flexibility. And so what I think ends up happening is it's really our, our vision of the AI market is it's all hands on deck.
You'll see me say this anytime you see me talk about the bubble. And social is like right now, every single wafer that TSMC can produce a chip on is being sold. So Nvidia has a certain amount of capacity.
Broadcom has a certain amount of capacity. Broadcom can make a certain amount of units, and every one of them is being built these companies. So you gotta expect, by the way, not just Broadcom, it's others, but Amazon, Google, Microsoft, Oracle, OpenAI, um, they're all meta.
They use so much AI that they're gonna use some of their own chips. And by the way, this isn't new. They've been doing this for a while.
We've seen the arm movement with CPUs that moved certain workloads off Intel and off mt. Right. This is a business decision, but it's not necessarily because they believe it's the most performing of the best technology.
They're trying to fill a gap, hit margin levels, understanding that not every workload needs to be on the most advanced chip. And, and of course in the end, they're looking at delivering EPS value and you know, absolutely. If they're meta and they're doing ads, can we build a lesser priced high performance chip that just focuses on serving ai AI slop to us all day long?
As we, as we, as we run around our meta Application, there's, there's a world for AI slop, but you know, it it, but this is not a new strategy. No. Right?
It, it, it was al always, it reminds me of when, when I first got into security 25, 30 years ago, Asics, ASIC based security appliances. Yeah. It was before we had SA or y of that Stuff.
ASIC too. Right. And, and that's what, and back basically it's the same stuff over, you know, history repeats itself.
You just, that that's what we're dealing with. And you know what, for certain security functions, you know, custom made ASIC still penny for penny dollar for dollar gave you the best bank for the buck as Long as it was for the right use case map. It's, It's that narrow use case.
Yeah. But it's the same thing here. Metas serving ads is, is a particular one.
Um, I'd still look, if I was a betting person, I like NVIDIA's, you know, seat maybe better than some of the other players. Yeah. But if, if they could maintain just one or two generations behind Daniel, that's a get a lot of value.
Freaking market. They Get a lot of value. There's a lot of need.
There's a lot of, um, you know, sort of deprecated workloads, just like on compute. Like people didn't just throw their last generation, uh, data center server or CPUs away. They, they use them for less important workloads and they would, you know, they would prioritize new workloads and they would upgrade and they would replace and they would add.
Right now most of what's going out is, is is new. Right. Um, and interestingly enough, like, you know, Nvidia, I say it's three to five years minimum before the custom chips could eat meaningful market share, if ever.
And I still think it's more of an and than an or. And I think there's a lot of kind of the, the biggest risk to, to NVIDIA over time is as these big buyers, the ones that are buying so much of their technology, are able to do more and more on their own chip and with their own margin structure, is would that create any margin pressure On Nvidia? On Nvidia?
So it's not so much volume. I think if anything, the risk is more sits in the margin. But then there's other things too, like that Nvidia does.
It's just so unique. Like their their entire backbone being optical. Yeah.
And you know, like, you know, n well, they Don't, they And Spectrum acts like, you know, but they're, they're the transport that between the GPUs is so efficient and so fast that like the latency issue is, is really, when you talk about clusters of this size, it's, it's, it's really meaningful. Like until we get co packaged optics on, on all the backends of all these, of, of all these spines and everything, it It, look in my day it was the buses. Yeah.
Right. On the, on the motherboards and forth. It still your day, so forth.
Well, it's still my day. I've had a long day so hard on yourself. It's been a long day, but it, it was the buses and that, you know, that latency in there.
But what I think the other thing is, you know, necessity's, the mother of invention, it keeps Nvidia on its toes to be constantly innovating, to be constantly staying that one or two generations. And they've been great at that talking about, you know, Blackwell three hundreds are now ramping shipping and volume. Uh, we already know Reuben's coming and we know Feynman's gonna come after that.
They're coming out two generations a year. And by the way, that's very hard to do with custom. It's very hard to do.
Like I said, there's a few companies in the world that can do it. And then the thing is, is like it's all run in their cloud. Like I will really, like, I've heard Foxconn's ramping up building servers with the Google TPU chip that could be sold outside.
But like, um, I think there's, you know, like NVIDIA's a merchant silicon company, meaning that enterprises can buy it. Neo clouds can buy it. Like, you know, like, is Amazon gonna really buy a volume of Google chips like ever?
You know, of course not. They're probably gonna build their own. I mean, Meta's unique, Meta's not competing with the hyperscalers though.
Slightly different. Well, They have a different, they're not the three hyperscalers, They're not the, they're not the selling cloud services In terms of a cloud, but they're a hyperscaler in and of themselves. But they, like, the net of it is, is like, I just think it's, it's all hands on deck.
I, I think that, you know, we're hearing by the way, it was $1 trillion of expected AI infrastructure by like 20, 29, 20 30. You got a fancy game Going. We're getting, we're getting a got thing going on live here.
I don't know. It's ESPN though. So, but, uh, But um, now that number's been risen, possibly two to 3 trillion.
So what I'm saying is like, look, we do market sizing, we look at the market and it's kind of simple. There's market size and overall tam and then of course there's margin in the TAM risk. And so on the, on the market size, it's like the market just keeps getting bigger.
We're building out 65 gigawatts right now of capacity, um, up to 80 here in the us. And I mean, you look at the numbers are anywhere from 20 to $50 billion of spend per gigawatt on infrastructure. It's massive.
And so, like, they can't build enough TPUs, they can't ramp the supply chain fast enough. And that's another thing is like, we know Intel's on the way up and Intel's going to win, uh, more and more foundry deals, some percentage of work. It has to, no, it literally has to because there's no other way.
T tsmc, you can't build enough fabs fast enough. So, but what I mean is every wafer is gonna be sold. And so right now the point is, is like every wafer and every chip that that Nvidia can build is gonna be sold their backlogged where they have half a trillion for next year, half a trillion order of visibility to next year, not including their open AI deals, not including their open AI deals.
So a lot of people are like, what's open AI risk? Well, this isn't, it's $500 billion of potential sales between now and 13 months from now. It's incredible.
Not every vendor has that cushion though. No, Not everyone does. But, but my point is, is like if, if real realistically A TPU or or a train was a risk to nvidia, you would start to see it show up.
They have deals. I don't think NVIDIA truly has a real risk on the horizon. No, But they're fighting that battle in the market every day.
Absolutely. The market is trying to create the FUD that they do. And what I'm saying is they don't, but it, again, it's not zero sum.
There's so much zero sum thinking. It's not at the cost. Crazy.
Alright. A SEC. Yep.
Let's clean that up, um, at the cost of Nvidia. And that's my big problem is like, look, maybe over three or four or five years you'll see some, maybe Nvidia will shed a couple points of market share. Maybe the TPUs and the XPS will gain a few points.
Maybe a MD will get a few points of market share. I expect that all these things to happen thinks. Mm-hmm.
I mean that's, I think that the market, Qualcomm and others that are playing exponentially, but the market's Huge. There's enough, right? There's enough to lose A few points.
So, so, you know, if you're modeling, and one of my models are all saying is that NVIDIA's gonna be bigger than we thought it was a year ago. It's gonna be bigger than we thought it was six months ago. And even while all this other stuff is starting to take some market share, they're still growing.
Tam it's a problem that, you know, we wish we had in the research business, you know, that there was that much demand, but like to God's ears, you know, the bottom line is, is that I just don't worry about it. The bottom line is Nvidia, the $10 trillion company could Be, there's no reason it, I think it'll be six next year though. All right.
You heard it here, Daniel, I want to pivot and switch gears a little bit. I want to talk fu term signal. Okay.
Uh, we've been talking about it here on Text Strong TV and in our tech strong stuff. And you know, look, you and I both know, right? A good percentage of our market is all about up and to the right.
It's just, you know, the way we were brainwashed, I guess coming through. Talk signal to our audience a little bit, what makes it so unique and so special and why they, and, and guys, you don't have to buy a subscription for today. It's available to you right now.
You don't need a, you know, all of the other stuff, but Talk. Yeah, I mean we, we believe there was a fundamental problem with the way technology's evaluated. You see, uh, models being introduced weekly, monthly with meaningful improvements, scaling laws mostly still intact, but like the improvements you're seeing between GPT-3 and four and five, or Gemini one and two and three, or even just, uh, the, we just talked about Nvidia whole bunch, like twice a year they're able to roll out a major upgrade cycle or release of their stuff.
But yet, right now, if you want to evaluate those technologies, you work with an analyst firm, you, you do a year of interviews and meetings and you fill out forms and then you, you get a report that comes out and it's six months outdated, maybe a year by the time it gets published. And largely by people who can't touch the stuff regularly. So you've got all kinds of just mismatching now in terms of technology and enterprise decision making with technology.
So the simple question is, do we eat our own dog food? Do we drink our own champagne? Are we in the business so we thought we could solve the problem differently?
And so the the reality is, can you build a pervasive, autonomous, uh, evaluation platform that really offers true market intelligence, competitive intelligence that can look at a, in an important, say, agent platform, say neo clouds, say, uh, CRM platforms. It can look at it up to the minute, it can actually really distinguish, uh, it can look at the voice of the customer. It can look at the market models and growth data.
It can look at CIO decision data and an IT buyer decision data. It can look at the analyst perspective, and it can really create this thing on the fly to completely revolutionize how buyers are able to be matched with the right vendors and have the right supporting evidence to make a buying decision. And so we built it and we built it in a way where, look, this thing is completely real time.
This thing has the ability to take every piece of information, hence signal that comes. It could be a S one filing from a acquisition or from any sort of market filing that the company makes a, a report that they put out. It could be earnings, it could be Voice of Customer Day.
We did an exclusive partnership with G two. So every, you know, they have millions and millions of reviews. It could be all the analysts, uh, you know, the rum, yeah, the briefings, everyone at fu It could be, uh, conversations had with Techstrong.
Uh, it could be Tech Field days where we bring experts in and, and, uh, advisors in to talk about different products. It could be the briefings that we take. It could be events and press releases that come out of these.
Why can't we use all this signal in real time to help evaluate the technology? And by the way, I got feedback today. It was great from, you know, from an enterprise buyer.
And they basically said it was the, they looked at our age agentic report. They said it was the best report they'd ever seen in terms of truly comparing all the age agentic offerings. And then they asked me, they go, how much of that was written by people and how much was ai?
And I said, it was a hundred percent ai, a hundred percent ai, big prompt, all ai, big prompt. I mean, there's a human in the loop. There's No, there's a ton of work's that went into this, but the actual content was written by ai.
But using all those inputs, that massive corpus of data, and by the way, this is just for this kind of evaluation, but the beauty of this is this can be for everything we do. It could be for economic validations, total cost of ownership reports. It could be for insights and, and reports and research.
And like, the model is slow. It's broken, it's not immediate. Like we have to be as fast as the news cycle every week.
Like two weeks ago, the TPU wasn't a thing this week, it was a thing. The analyst has to be able to look at what does all this noise mean? And if you're a buyer, what should you be considering right now, the current way this is done, you won't have anything meaningful from the market.
12 months for three months, six months, 12 months. 12 months, three months to get a paper. Yeah.
12 months to get an evaluation out. And so we're like, with Signal, what we're really doing is we're saying, Hey, how do we do this faster? How do we make it more accessible?
And what we're doing, by the way, is you've only seen the beginning. I mean, you've heard my story in the background, but I truly believe that this is all we're doing right now is the Netflix version of shipping DVDs, right? We've created, we've shown the market that we can do this much faster.
It can be high quality, and it can be a better experience than going into the store and running a video. But realistically, this can be streamed, this can be real time, this can be continuous. Active is continuous.
It's Continuous. This can be comparative, this can be so many more things. And why in the world would we want to just continue to settle?
And why would we wanna allow this industry to continue to evolve at such a slow pace when the stuff that we're evaluating is evolving at such fast pace? Is, Is lightning speed? One last subject.
I'm gonna let you go, please. No, please Let, if you like, if you like what Dan, and you know, Daniel knows a thing or two about the market, about, about the CPU market and, uh, the tech markets in general. You recently launched Futurum equities.
Yeah. Uh, I guess it's been six months already, hasn't it? Yeah.
For people who, and there are a lot of you out there who follow the markets, who are investing, how, what's the best way to follow you on, on future equities? Yeah, Look, I the real quickly, you know, the, the stocks of the tech companies and the technology itself are inextricably linked. Like there's this belief that like industry versus equities is like two different things.
It's not, um, the data that feeds decision makers and hedge funds or, or, or, you know, investment banks to buy stocks, uh, is the same data that CIOs are using to decide whether or not to use technology. I mean, they, they absorb it differently. They read it differently.
Maybe the modeling is a little bit more spreadsheet versus a little bit more practitioner. But like, we basically realize that we have so much insight, so much knowledge, so much signal that we built future equities to basically do the same thing we do for industry. But just put a little bit of a different lens on it.
So mm-hmm. We built a great team. Uh, you know, we've expanded the, the corpus of data.
We've taken a lot of the market sizing and modeling that we're doing now to help us sort of assess which companies are, are good investments. Now, again, we're not advisors, we're not making recommendations. We're providing Signal or Alpha like they like to call it to, to investors.
And, you know, we're using that platform and some, you know, platforms like, like Substack and Reddit and, and X where investors sit really heavily and we're kind of taking all the great work we're doing in Signal and in our lab, uh, and in, you know, across our, our, our analysis. And we're creating content that's really designed for, for that audience. And, and within the next few months, we'll actually be launching True Sell side research that'll help, um, you know, audiences make, you know, we'll have some, some our opinions, uh, not advice, opinions on whether things are, are a good buy, what things should be based on models, what the price is.
And by the way, we're doing this with just like Signal. We're building it completely autonomously. We, we can create these reports based on all the insights and data, everything we have that's publicly available, very clearly firewall put them different S3 buckets by the way.
Okay. Uh, totally making sure that we're in, that's I ws reinvent kind of hook in there. There you go.
Um, and basically we believe that the, the markets, the media and the, uh, enterprises all are symbiotic and we're gonna address all of them. I love it. Daniel, I know you were busy and we pulled you up here.
Nothing to do. I appreciate you, you always, man. Always.
Alright, thank you. Good be with you. Fu of Equities, Futurum Signal.
We're gonna be, I think this is gonna wrap up our Day one reinvent coverage. We've got a full day tomorrow. A lot of good stuff.
Our friends at Cuse will be back on with us tomorrow too. We've got a lot to cover with them as well as AWS themselves. But for today, hey man, this Alan Shemel for Techstrong tv.
We're out. Have a great day. In the modern security landscape, lists are not the way to get things done.
You have to start thinking like the people that you're defending against, and that means lots and lots of graphs in this episode of the Tech Field Day podcast, security Needs Graphs. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often associated with one of our events.
Tech Field Day is a part of the future and group, and this podcast is also published on our sister company's website, tech Strong tv. On this episode, we're gonna be discussing security specifically around Microsoft. But before we jump into that, let me introduce our guests for the day, starting with ard.
What's going on? Everyone? I hope everyone had a great holiday out there in the tech world and in the real one.
Gerard Kalina here. Uh, I'm a network and security engineer for Aqueduct Technologies, and I'm also the founder and creator of Tech House five seven. Oh, you can find me on LinkedIn, Twitter, TikTok, wherever books are sold.
Super excited to be here. Great to be here. So happy to, uh, be a part of this story.
I think at this point, uh, you would say I'm the Chief Product Officer at Nexus Tech. I write a lot of things. org and I'm looking forward to the discussion.
Alright. And my name is Tom Hollingsworth. I'm the event lead for all things related to security here at Tech Field Day.
Let's jump into today's episode. You probably had an opportunity to listen to our special tech Field Day exclusive event with Microsoft back in October where we talked about some of the exciting new updates that were made to Microsoft Sentinel. But as we get closer to the end of 2025 and now into 20 26, 1 of the things that we wanted to do was kind of revisit some of those ideas because I think that there's a lot bubbling under the surface that people really need to understand.
And the premise for this episode is that security needs to think in graphs. Before we jump into that though, I wanna talk a little bit about the data part of this. And you're, you're thinking to yourself, well, Tom, you just talked about why graphs are important.
Hold that thought, because we have to build a foundation before we get there. One of the things that Sentinel has decided to do, I'm sorry, Microsoft has decided to do with Sentinel, is they want to build a giant data lake for, uh, products to be able to reference whenever they're pulling data and things like that. And this was one of those things that I think was mentioned in the event that kind of flew under the radar, is they really are building what I consider to be a, an ocean sized data lake, a great data lake, if you will, because one of the things that Microsoft talked about was the fact that they wanted to be able to let users and, and organizations keep data for up to 14 years in this data lake.
I wanna give everybody a frame of reference for that, if you will. 14 years ago, I got my first Mac, it was a MacBook error. I finally convinced the boss to lemme buy one.
If I could keep 14 years of data in a data lake, it would literally be everything I've ever created for this job and defend some, and I can search through all of that to find data. Like is this a thing that's important for people in the, the industry? Like you guys are the ability to keep all of this data for relatively low cost?
From what I understand, I mean, I wanna jump in because I think what's really cool about it is, right, as, as an IT professional and working at different layers, you know, from help desk network, you know, infrastructure, all, all nine yards, it's like when you have data, how you treat data is imperative. Especially like, for example, working in a healthcare organization that's kind of numeral UNO like data and reten retention, excuse me, re re tending data, data retention is, is key and imperative, especially when you have records, a lot of important documents, things of that nature. So, you know, back then we didn't have a solution like Sentinel where it was clean, very streamlined.
It's like, we're gonna build these, metaphorically speaking four major walls to compound and streamline data, give you much, you know, deeper granular visibility, long-term retention, and the analytics piece, which is really cool. So I think that working from different, you know, sectors of it, it's really cool to see how we're evolving with data. I think it's certain in certain areas or certain sectors like healthcare and, and, and, you know, maybe, you know, fi financial institutions, it's kind of imperative.
Other ones maybe not so much, but I do think that this is a solution that's, that's, that's really key and, and kind of growing and doing that and how we, how we start storing it, how being able to process it and more so being able to sift through the logs and, and really check to see like what's important, what's not. I think of it like this. You've, you've, if you go back that far in time, uh, you're spanning multiple jump points on my career timeline.
And in the early days, I remember when a two terabyte hard drive was, you know, pretty amazing that you could do that, uh, that many years ago. Um, then, then this progression of like, well, that actually might become how much memory you have access to. And, and then when you think about the retention part of it, I was thinking about, well, your retention policies, um, very common for people to want to discard, uh, you know, data.
And sometimes it was, uh, just to make sure it's not part of a discovery process, you know, if it's something related to like, you know, objects, uh, related to documents, things like that. But in the world of security, uh, the ability, like when you say, uh, one of those advanced persistent threats, you know, slow and low, it's been cooking. Maybe it's been in there for, you know, the better part of 10 years.
Uh, there, there are obviously some interesting stories in that, but I will always go back to what's the inherent cost of that storage over that period of time. Um, every CIO event I've ever been a part of, uh, certainly the precipitous drop in storage pricing has not been top of mind for CIOs. If anything, it's the ongoing increasing amount of cost to keep track of storage, even with the wonders of cloud, uh, which makes it super easy.
Um, which is another thing too. I I think an important part of this is that this is an inherently, you know, Microsoft story. Um, but I'm very curious to see how the data lake part of it fits into the, oh, you don't need to move your data.
You don't need to rehydrate, dehydrate, move your data, move being a four letter word. So how I'd actually, uh, how it's actually executed is gonna be interesting. 'cause I I I would also doubt that over that many years, the day would all be in one place.
Yeah. And that's the problem that we've got right now with a lot of this information is the data lake looks a lot more like a bunch of little puddles where we hope that we've got the right data. We think we do.
But where is it? Well, it's in this shelf over here, it's in that drawer over there. It's like when I try to look for things in my office.
And I think that the value of putting it all together is not just that you have a good base to draw from, but it provides opportunities for exploration and honestly for attribution. 'cause one of the things that we've seen with some of these, uh, modern, in 2025, several of the CBEs that were released with like high severities, these were not new problems in a lot of cases. They were problems that had persisted in certain versions of packages for months or in some cases a couple of years.
And you don't know how far back that goes if you don't have access to that data. Because we really do live in a, in a, uh, an enterprise IT culture now where if it's not immediately useful to me, I need to chunk it out. Um, there was a news story at the end of last year.
Somebody discovered a running version of Unix system four on a tape. Why somebody put the tape in the wrong spot. And it wasn't erased like it normally was.
Like, think about how many episodes of DR who got lost because the policy at the BBC at the time was to erase the tapes because why would we wanna keep this stuff? We already aired it, nobody cares about it. Now, 50 plus years later, people want that data.
Now I'm not saying that my, that, uh, Azure, the data lake that that Sentinel is using is going to be able to restore, you know, old DR. WHO films. Although that would be cool if it could.
Uh, I'm saying that being able to keep that data and know that you have that data and be able to go back and say, okay, how far back does this exploit run, gives people in an organization a much smaller risk profile and it makes DFIR and auditors very happy when you can say, no, we have not been running Aval an invalid version or a, a, an exploitable version up until this date. So we know that everything beyond that is probably safe. So auditors don't have to spend a whole lot of time combing through that.
Neither does ZFIR. And it really makes people happy when they can narrow their focus and, and use their energy for something useful instead of like combing the desert, so to speak. And I think one of the nice, I mean, at least from what I took away from it is having that, that that security, that comfort knowing that Microsoft is behind the platform in the sense that when you have such large amounts of data, it's like where you, you, you pretty much grow your, your entry point into where a threat could attack, right?
Or a CV could attach and then you start having to pillage through, well, what's the clean data and what's the infected data? So being able to kind of sort through that have more visibility into it, I think is huge too. I keep coming back to, if, if you tell me that that many logs of, uh, years logs worth of like firewalls, endpoints, things that we're feeding into some kinda a log sink, if you can tell me that the cost associated with that storage is now decoupled, uh, literally set apart from what would've been traditionally.
Like, you know, and I'm not gonna pick on any particular vendors today, but I'll just pick on Splunk from it. Like everything just went into Splunk and Splunk team got their Splunk IT budget and the Splunk IT budget inexplicably compared like the compute and the storage and the network and everything else. Kinda like wrap that into a one little bundle.
But now if you can decouple storage over here, you know, which is where the logs go to live forever, if you can tell me that starts to look like what you know for your TBM person technology business management person. You know, you have your, your traditional IT spend, then you have your, your variable or opex part of it, and you have your, like your, your labor attach when the labor attach, you know, looks like the investment of what would've been that storage cost. But now you're saying instead of it being the one year cost or the one year and a half cost for like, what's the hot tier?
If you tell me that starts to look like I can actually do some real comparisons, um, to understand business value for that, you're probably gonna get my attention. Again, execution matters. Uh, but it does appear that this decoupling, this data lake, uh, concept coming from the, the analytics world and now rushing in to solve, uh, what you clearly call out is like a multi-year span problem in security may maybe that will work out.
Um, I'm also very curious to see how many people are going to adopt this, um, because it also sounds like because it's Microsoft, you'd be consolidating your Microsoft spend. I'm not sure if you get any cost advantages there as opposed to having third party players involved. But, uh, that was my other thinking about this, is you're, you're kind of decoupling the storage costs away from a compute or query cost.
Uh, and, and I think it's important, um, to, to lay out, uh, especially if you are thinking about this at a very senior level. So let's talk about why we want all this data, because one of the things that we, we realize now is that the way that security operates is slightly different than we're used to. Um, and, and one of the other things that Microsoft highlighted with Microsoft, uh, Sentinel was this idea of graphs.
I'm not talking about, you know, X and y coordinates. I'm not talking about bars and charts and pies. I want Jay to explain what you explained when we were doing the pre-briefing here about how graphs work to you.
Because I think this is one of the more succinct ways to think about graphing. I I would think of it, everyone loves a list. I love a list.
I got list, I got list on the wall behind me. I did erase them before this podcast. But, um, the list is great, you know, because I, I can literally, I can, I can see progress.
It feels it's very, very satisfying to mark things off my list. 1, 2, 3, 4, 5, 6. The challenge with that now is that, um, if our list for, you know, defense is I start, you know, I focus on one, then two, then three.
Uh, a lot of what's happening is, uh, the the bad player, the bad actor might start on item number 14, then jump to 23, come back to the ones and twos. And that's because they're attacking a graph. Um, they're not attacking a list.
And so I think, I think what's good for the goose is good for the gander, you wanna call it spy versus spy, whatever that motif or, or metaphor was. But by thinking about a graph, it's a, it's a lot of cognitive overhead, frankly, to think about it that way. Because it's like saying, take your, take your to-do list and then just make it like a word graph on a page.
Now where do you start? And so I think simplifying that's gonna be important, but that's how I think of this, this transition from like a, a crude list to now thinking about this. Like it's a, it's a web of things or concepts that are interconnected with, uh, mapped dependencies.
And, uh, that's unfortunately how the bad guys are gonna think about it. So how we approach graph and how we can simplify adoption of graph as an approach is, I think gonna be important for the new, uh, realm of defense that we have to enter into in these modern times. It almost sounds to me like a, a choose your own adventure book, right?
It's like, you know, if, if you want attack the email server, go to page four. If you want to try to hack the password database, go to page 12. And if I am a system that's trying to process that serially from page one to page 50, it gets really outta hand real fast because it doesn't make sense as a story.
I wanted to say too, and I think it's imperative is like to kind of the flip side of that too, or maybe on the same, you know, discussion, is that how that really helps security teams and soc teams moving forward, right? Like when they're doing audits or when they're doing, you know, full reviews of an environment, number one, it can kind of focus on like some of the targeted like pain points or areas where, hey, this is where a breach may be susceptible, or this is where a CV can attach itself. Also, when you have that type of data looking at those graphs, it's gonna go, well, let's take a look here at, okay, we have a compromised user account, or that user account is tied to this VM or this container.
So again, it gives you full visibility into this is where they're gonna hit, this is how we have to, you know, kind of position ourselves and it helps overall better posture, I think REO security assessment, you know, and it gives those teams extra tools and, and, and guides to leverage Not just posture, but I think it actually helps direct the incident re response side of things. Yeah. And here's the reason why.
'cause Jay, you bring up a really good point. People don't think in lists. Like, there's not a 10 point checklist of, okay, I I'm on a server, you know, check the user login file, check this, check that.
What do people do? They look at the server, okay, what am I on? I'm an e I'm on an email server, boom.
That immediately shortcuts to this thing down here. I wanna try to expose boxes, I wanna try to get user login information. I wanna see if I can get other information that's maybe held in like group folders and things like that.
Well, but if I'm on a domain controller, that is a, yeah, and I'm dating myself by saying domain controller, um, like that's a completely different attack chain, right? Because now I have a copy of AD and I can go in and I can do stuff. But more importantly, if I do happen to find myself on a peer domain controller, and I've developed all these attacks, am I going to start looking for a Linux database server?
No. I'm gonna see what I'm connected to that is other domain controllers so that I can see if I can compromise them as well. So by understanding the way that graphs work and being able to hunt down those graphs, I can follow that movement, right?
Like, 'cause that's the other thing too. The, the hacking methodology of land and expand is by its very nature chaotic. Because if I find a good, like, hit over here, I'm gonna follow it because there's, I'm gonna have to put less work into compromise the system where maybe it's a better foot holder.
You guys weren't dumb enough to leave a Windows 98 machine on the network, were you, were you like that kind of thing. Whereas in, in Jay's example, the traditional checklist of, you know, we check the firewalls, there's no problem. We check the, the IDS, there's no problem.
Well, we didn't see anything. Let's go back to the top. We checked the firewalls.
There's no problem like that. The, the playbook is old. You know, it's, it's every war movie you've ever seen.
You got Top gun maverick, good example. This is the natops for the F 18, you know, it back and front funk. So does your enemy.
I'm gonna have to teach you how to do things that are not that, and that's graph theory, right? Push an airplane in ways that it wasn't designed to be used. Like, and, and I think Microsoft has hit on something here because like, like we've said, hackers don't think in checklists.
So what, what, what is the value of having graph for someone in an end user position? Because like, I know what the value is for people who are making these decisions at the boardroom, it's flashy and it, it, it, it is money that can reduce my risk score. But for you guys, the people who are in the trenches who do this, what is the value of having a system that can do graph?
Uh, you get much faster pattern recognition than if you're just trying to correlate, Hey, look an endpoint, talk to another endpoint. Fabulous. Thank you so much, Einstein.
Um, this is the year 2025. Tell, tell, tell me a little more detail than, hey, look, this thing pinged this other thing, or this pork, you know, got knocked. I, I think, I think as the patterns, um, you know, we, we almost wanna see, um, the, the orchestrated playbook, uh, being executed against us.
Oh, look, that's one of these, um, it's, it's this pattern. We are seeing this pattern as opposed to an alert occurred again, you know, going back to rubbing sticks together with your domain controller, right? Yes.
Okay. An alert happened, but in the totality, what was the pattern of all of the, you know, call 'em several hundred, several thousand alerts that occurred? What's the emergent pattern?
Uh, what does this tell us is happening? Um, do we, you know, you go back to like even like a, like a CrowdStrike or other type of metaphor, um, um, or, or a or, or, or people try to come up with cute names to describe, uh, the new threats that are out there. Um, animals, insects, you know, where they came from regionally.
Uh, that's a pattern. Um, that's a technique. Um, right now, uh, we, we, we really can't deal with the individual alert.
Uh, we're, we're just not allowed to. I mean, I, I think there was another call, um, or talk around where do you even find junior, uh, uh, security analysts. There's no junior or security analysts jobs anymore, because a lot of that has been, you know, given up to machine learning.
Uh, that's doing those very intro level roles. So again, we're, we're thinking in terms of patterns. And so, uh, once we have the pattern, we may have a counter, uh, you know, to that pattern.
But in, if we're still dealing with alerts, we're just, we're so lost in the weeds. Um, so I think graph is about pulling ourselves out of that, you know, one-to-one only view of the world. I, I love that you brought up that you can sometimes do attribution, seeing how people behave.
I think my favorite piece of that was a couple of the groups, the, the fa the bear groups. Um, we knew that they were probably Eastern European or Russian and Origin because they had blacklisted certain places from being infected by their malware. Um, basically it was, do not poke the Russian bear kind of stuff.
And if you can pick up on those little subtleties, then you can figure out, okay, I think this is this group. Like, like if you know that a specific group is, is famous for buying insider access, if you're seeing insider access type patterns, then that narrows it down. It's probably not this group from the far east, it's this group from Brazil or something like that.
And that gives you a more, um, solid place to start from so you're not wasting resources. Gerard, what, what about you, what do you think is, is some of the value of having a a graph type solution available? Well, like I said, I mean, I a hundred percent agree with, agree with Jay.
You know, having, having, my biggest thing too is with this platform, it allows you to blow out what you see as far as from an analytics and from a log perspective. Because from someone, especially for years who, you know, on the network side, it's like, well, we know this packet went to here and this is where the attack, you know, started. This is where it originated.
This is where we need more. We need more to be able to expand upon that. And I think the cool part is being able to ingest such, such data, but then rip it apart at such a level.
Like, I remember during that demo in October, I was really excited to see how it breaks down, not just the time of when the attack happened, this was the attack vector. This was the point. It, it, it broke down an entire timeline.
Um, that really like, gives you a visibility. And especially too, when you're looking at it, not just from the technical perspective, but you know, with a lot of CISOs or higher level, you know, individuals, they, they want that data because they wanna know, Hey, what happened here? Why did this breach occur?
Where did it occur? And then how did we stop it? How do we remediate it?
So when you have that all under one package, um, you know, I think graphing and, and, and kind of again, more granular level detailed reporting is, is what we need. So for me, that's how I, at least I, I look at it, it's just, it's, it's, it's a way to blow out the, the, the initial data points instead of just saying, Hey, this is, this is infected. We got hit here, that's all we got.
No, there's gotta be more. We gotta be able to pull more from the firewall logs. We gotta be able to pull more from, from, you know, the, the, the Ford manager UI or whatever it may be.
We have to be able to get more data and this provides it. And I think that the other thing that's valuable for me, kind of going to something that Jay said was, where are you gonna find a junior engineer? Now my question is, why aren't you making junior engineers?
You, you should take someone, bring them in. But rather than to quote Master Toyota, you must unlearn what you have learned kind of things. Set them down in front of a graph solution and say, okay, I want you to figure out how this works.
Look at the way it thinks when it's building through all of this. Don't worry about the data lake. Don't worry about all those stuff.
We'll get there. Just watch it hits this, it goes here, it does this, it does these things. Because there, you're taking someone who doesn't have a preconceived notion of bastion host firewalls, who doesn't have a preconceived notion of VPN concentrators.
Again, I'm dating myself, but it's figuring, helping them figure out how modern stuff works. Like we always talk about this in security because we are so focused on technology solutions, right? We need to microsegment the network and create zero trust boundaries.
And I saw an article yesterday where someone on a help desk is selling insider access for like a hundred dollars for an hour to get on and just do whatever you wanted to do, create a foothold, whatever. We still don't think like attackers, we still think like defenders graphs get us, at least to the offense defense side, people that play the, on both sides of the ball, so to speak. I think it's more valuable for someone to come in and look at that and start their learning there.
Yeah, you can give 'em the fundamentals later. Here's how our firewall works. Here's, here's why we do access lists the way that we do.
But letting them kind of have freeform capabilities, almost like a mind map is a much better way to build the next generation of junior engineers because they have to listen to me. For any of us that have been doing this for more than five years, they're gonna be like, but why do we do it that way? Well, back in 2010, when this was state of the art, that's how we built stuff.
And, and I know we don't do that anymore, but we still think that way. So I wanna kind of wrap this podcast up and I wanna ask you both, like for people going into 2026 that are examining how things should work and, and if they're ma looking to maybe make some additions to their things, what's one thing that people should be thinking about in regards to data lakes and graphs and that kind of technology, even if it's not Microsoft's solution, what's something that people should be thinking about as they maybe are putting their wishlist together for the boss to say, Hey, maybe it would be good if we investigated these ideas? Well, you know, I definitely would say one thing to keep in mind is, I know, I know the hot, the the cool word is AI still, it's, it's the thing I know and everybody's like, why?
But it's the truth. You know? I know a platform like this, or any, you know, graphing platform is gonna leverage generative ai, generative AI to really ingest and pull that data in.
So, I mean, one thing I would say to keep in mind is we have to be on the other side. We have to start thinking more proactively and stop thinking less like a defender and more like an attacker, or at least find a happy medium or a balance to both. If we could find a balance to both, it's gonna give us a distinct advantage and a leg up to, you know, being more proactive at CBEs.
And then we're gonna start the, the smarter we get, we need to start leveraging these tools to prevent the attacks. You know, I think one thing I had mentioned, and I'm not even gonna go into it, but it was a whole thing that, you know, there's an entire type of threat out there now that could actually freeze an EDR an XDR solution. It could just kill the whole solution right from the inside.
So we need to be able to start leveraging that, and then that way it's, we're gonna see that blanket across the entire industry, and it, it's gonna help a whole portfolio of next generation tools and suites, especially graphing. Yeah, I would say there's a couple of spaces that you'd want to explore, uh, group, group wise, uh, you know, lunch and learns, um, getting folks that maybe cut their teeth, you know, uh, rub sticks together around like a CIM or a a more of a common information model. And then, you know, bringing them, maybe kicking and screaming into the more advanced security world.
Um, thinking in terms of, okay, well that was, that was great, but, uh, we, we only had a firewall back then. Now we literally are dealing with potentially hundreds if not thousands of individual baby firewalls living everywhere, all trying to log sync to somewhere. Um, so getting people out of that, uh, you know, um, uh, I, I feel like picking on Splunk again, but like, there's the Splunk mindset of how it started, and then there's this new world of like, you know, KQL or Cresto, however you say it.
Um, we're, we are, we're literally going, we're deep diving. Um, we're going into the lake. We're gonna explore the, the, the, the bottom and look for surface formations and patterns and see like, ah, this kind of fish, that kind of fish, this kind of eel, that kind of thing.
Um, and so the analogies are gonna be, um, taxing for those that maybe grew up in it and were used to doing it a very specific or one way of doing it. Um, but I would say there's probably some parallels there to the old, uh, storage engineer versus what's now called a cloud engineer. And so that same kind of progression of skill sets and matriculation is important, you know, so to Tom's point earlier, just you should be creating these folks.
Um, you, you, if you have the talent, um, investing in that talent, um, is absolutely on the table of possibility. Um, these, these, these are, uh, folks that have done it once before, and it might have been the one-to-one thing, but now it's gonna be the one to many or the many to many patterns that we have to think about in the future. Uh, for my part, I'll say this, if you are even considering any of these solutions, all you've gotta do is go to the current providers that you have right now and simply ask, what are your plans to support advanced threat detection?
And, and if you wanna say the G word graph, say it, one of two things is gonna happen, they're gonna look at you and go, what's that? Then you get to educate them, send them the episode of this podcast. We would love that.
But more importantly, um, if they do have plans in the pipeline, they can say, well, that's something we're looking at. Then that can give you an idea. Is this six to 12 months out?
Is this 12 to 18 months out? If this is something that you and your organization need to investigate, either because you fear you're about to be breached, or your, um, stakeholders really need some kind of insurances here, then that means do I, do I stick with who I've got or do I make an investigation? Um, and if you do make an investigation, I'm sure friends over at Microsoft would love to hear from you because they put a lot of effort into Microsoft Sentinel and they'd love to sell it to some people.
And, uh, you know, we, we appreciate them partnering with us on all the things that we've been doing. So, uh, thanks again to them for that. Um, before we go, I'd like to let our, uh, guests kind of plug their stuff.
Uh, ARD if people wanna check out what you're working on, where can they go to find that out? They can find me all over the internet at Tech House Five seven. Oh, I'm, as I said, I'm on LinkedIn, Twitter, TikTok.
I make short long form content. I'm all over the place. I'll probably have some new videos coming, uh, on Sentinel and uh, it's gonna be a great time today.
You can find me anywhere. org. I'm on a LinkedIn, I'm on Blue Sky.
I'm using Go to Social now 'cause I had tried using a standard Mastodon server, but my Fed Averse is now on Go to social. So, uh, look forward to, uh, anyone reaching out to me there as well. Thanks, Of course.
com. You can also check out more of our great security conversations over at our Security Boulevard podcast. com for more information there.
We wanna thank you for listening to this episode of the Tech Field Day podcast. And if, as always, if you enjoyed this discussion, do us a favor, subscribe on YouTube, use your favorite podcast application. We don't want you to miss any of these episodes, especially around the holidays when things are coming out, um, on a maybe less than regular schedule.
Well, not for us, because Corey is amazing. Uh, but if you do enjoy the content that you hear, let us know. Give us a rating, give us a review, leave a comment.
We'd love to hear what you have to say. This podcast is brought to you by Tech Field Day, which is the home of IT experts from across the enterprise. We are part of the Futurum group.
com. You can also check out the website, tech field day com slash podcast for all of our episodes. Or listen to us over on Techstrong tv.
Thanks for tuning in. We will see you all next week. AI isn't just changing jobs, it's creating entirely new ones from building habitats on distant worlds to designing art at the speed of imagination, to crafting living materials, guiding drones through uncharted terrain.
Hey everyone, happy New Year. We're a little late getting started this week. I've been busy in the studio here in some of the other sets at Techstrong Studios.
But, um, happy New Year. I'm glad you're here for our very first Shimmy says of the year. And for this year, uh, for this week to kick off the year, I wanted to talk about something that's probably near and dear to you, as it is to all of us, including myself, I guess.
And that is what exactly are all these new AI jobs that we're talking about anyway? You know, if I had a nickel for every time I've heard someone say, AI is going to take away jobs, AI can cost you your jobs, I'd be well on my way to buying my own AI factory or data center. Ah, who am I kidding?
The, these things are a trillion dollars, billions of dollars, but at least maybe I'd have a good down payment. Um, but you know what I've found, and you've probably seen this too, everyone who says, well, AI's gonna cost a lot of jobs. It's immediately followed by, but don't worry, it's gonna create a lot of jobs too.
And, you know, for a long time, I, I think that was just the mantra. When someone tells you their relative died, you tell 'em that, Hey, you have my condolences. But no one really thinks about what exactly are all these new jobs AI's going to create?
And when I started asking people, what do you think these new AI jobs are gonna be? I didn't get a lot of answers. I'll tell you the truth.
I got a lot of thumbing. So I figured, let me go to the source. Let me ask ai, what are some of these new AI jobs that it's going to create?
And you know what, it, it kicked back. It, it spit back some decent, some decent things. Um, and then of course, you know, I've, I've also read a lot of things from the so-called AI architects.
Uh, you know, the people who were running the Sam Altman's, the Elon Musk, the Googles, the Perplexities, the Anthropic people. Where do they think these AI jobs are? And, you know, an interesting thing, a lot of them talked about space, and we're gonna come back and talk about jobs and space a little bit.
But before we jump into this whole thing, I wanted to just clear some BS out of the way. A lot of people say, oh, I can tell you what some of these jobs are, and they give you these buzzwords or kind of shiny stuff that we've used before. And, and we're polishing off things like, I'm gonna be an AI evangelist, I'm gonna be a prompt engineer, and I'm gonna be a prompt a cybersecurity prompt engineer.
Come on that, that's, we're all gonna be prompt engineers, that's for sure, right? And we're all gonna be coworkers and managers of our digital alter egos and our digital agents. But I mean, what are the real new jobs?
What are the careers? You know, I remember when the internet first started coming out and I first started, I, I, I'm trying to think when it was, it was probably 1997, maybe late 96, and I heard the term web designer. Now, I will tell you that most of my friends at the time, whether they were lawyers or doctors or construction workers, firemen, policemen, if I told them, you, your children were gonna be a web designer, they would've looked at me like, I'm crazy.
Like, do I think they're growing up to be a spider? Is this something outta Charlotte's Web? But no web designer became a job.
Internet engineers, right? People who, who really, you know, were behind the, the internet became a thing. UX designers, UI designers and everything else.
So that's the one of the biggest lessons I learned through this exercise is for everything AI spits out to me about the new kinds of jobs that it's going to spawn. Um, it really doesn't know. None of us know yet what these new jobs will be, but you know, there will be some old jobs with new labels.
But I, I don't think that's really where it's at. Here's something else. What I'm really kind of afraid of is in the, in the rush to make sure this isn't so disruptive.
We make busy work jobs. You know, back in the depression, I, I wasn't alive then, though. I'm old.
I'm not that old. Um, back in the Depression, they had things like the Tennessee Valley Authority where they gave people shovels and sent them out into the Tennessee Valley, for instance, to dig ditches and make dams and build roads. And the, the roads were a good thing.
And the dams of course, were a good thing. But a lot of the jobs were just like on the dull. Government created jobs where people can go at least put in an honest day work and make an honest wage, even if the work product coming out of it was not very productive or useful to society.
What was useful is people actually working and earning a living. And we may see some of that in this, in this cycle. We may see some busy jobs, if you will, if you want to call it that.
But let's be honest, no one wants to just have a busy job, busy job, just for the sake of being busy. No one wants to raise their hand and say, I wanna have a career of babysitting the AI or babysitting a machine. So, you know, and that's the kind of stuff that AI was originally spitting out.
And I asked it, what are these new jobs? So I asked it, and, and this is a good lesson. Never take the first AI response, always ask it for more, quantify it, qualify it, it reiterate it.
And so I started asking it, what else be what, what's the real jobs? What are, what are our, give me, you know, three distinct kind of careers? And if we can make my teleprompter a little bigger here, I can't see it, um, you know, be more precise.
What are, tell me first, what are the jobs that are gonna disappear, right? And then what are the, what are the jobs it's going to make? What are the jobs it's going to change if we can go forward?
Um, you know, I, and I'm looking for jobs that honestly didn't even exist before ai. Um, now I know a lot of us have anxiety about this, but I think knowing that there are real jobs that are gonna be created here is gonna make all the difference in the world. So I wanna start with tech jobs.
'cause look, most of you watching this are all pecks. Um, so let's start with developers. Look, 60%, I saw a number this week.
60% of code being generated today is being coded by ai. So yeah, there's some panic in there among developers. And yes, AI can generate code and increasingly it's good code.
Speaking to my friends in security, we've kind of crossed the Rubicon where the code being generated by AI continues to have less and less vulnerabilities where it's at or below the level of vulnerabilities that human generated code is at right now. And if that's the case, what does that mean for security as well? At some level, humans are worse, are generating worse code quality than, than AI is.
So does that mean developer roles disappear? Absolutely not. I think we're, we're shifting from developers being code writers to system composers.
And that word composer's a great word. I'm gonna come back to it. We're, we're moving from people who produce syntax to people who design, orchestrate, and govern complex systems that now include autonomous components.
And dare I say, digital coworkers, same things happening in DevOps and platform engineering ops in general. Cloud AI doesn't eliminate the need for reliability engineers, performance tuning, cost control, observability. If anything, it raises the stakes.
It makes it more important than ever. Somewhat not. The AI has to decide how the AI workloads are deployed when, how monitored throttled rolled back when things go sideways.
'cause they are gonna go sideways. There's gotta be a human there. And by the way, that's not babysitting work.
It's not junior work. It's judgment work, right? A lesson we learned in cloud security, we could move stuff to the cloud and say, the cloud provider's gonna do so with the security for us, that doesn't re release us, release us of the responsibility when stuff hits the Fed and a cyber incident.
Well, the same thing happens when we allow AI to get involved in our cybersecurity. The respon, the buck still stops here in terms of responsibilities. AI systems do not execute decision instruct instructions.
They make decisions that fundamentally change the threat model. We're no longer just predicting endpoints and networks. We're securing these agentic systems, model pipelines, training, data design, logic, et cetera.
This gives rise to roles focused on ai, threat modeling, model abuse, poisoning, de detection, keeping the human in the loop oversight. Not to mention governance, as always, audibility policy enforcement. So look, there's plenty of cyber jobs that are gonna exist here in this ai.
Here's the paradox for this one though, guys, industry doesn't want to admit this, but as machines become more autonomous, human accountability increases, not decreases. It's counterintuitive, but it's true. Someone owns the outcome.
Someone's neck is on the line for what the AI does. That responsibility doesn't vanish just because a model made the call any more than it vanished because the cloud provider was doing it. That responsibility becomes the job.
Let me move away from tech though and talk about something else. You may haven't thought about blue collar work. Hey, in the age of robotics, physical ai, I don't care what you want to call it, a lot of these blue collar jobs are going away, and they're not the traditional blue collar jobs.
I, I'm talking, you may be thinking of, yes, the UPS worker history, the, the, the truck driver toast, train engineers, conductors, toast. But what about the surgeon? Are these AI robots gonna do surgery better than people?
They already are in some cases. The idea behind it though, is when I say toast, they're not necessarily eliminated. The augmented AI and robots.
And by the way, CES was this week in, in, um, Vegas, if you saw some of the demos of the next gen robots out there, it's scary stuff. You gotta go check it out. The things these robots are doing is just scary, but they're already, these robots are already working in our warehouses, our factories, our hospitals, construction sites and utilities.
But they're not just replacing humans in mass. What instead is emerging is a hybrid human machine collaboration. And that right there represents the future.
So if you're a worker in these fields, right? Remember these robots, they need to be trained. They need to be maintained.
They need to be calibrated and supervised. AI systems operating in the physical world are notoriously bad. At edge cases.
And edge cases pop up all the time. The reality is they probably aren't gonna get better at it. They need us.
This creates demands for skilled RO roles, robotics technicians, AI existed tradespeople, AI enhanced tradespeople, safety supervisors. Field work is augmented with diagnostics and predictive tools on what's going to happen next with our roles, ro, we're robots. This is not the elimination of blue collar, excuse me, blue collar work.
It is an upgrade that blends physical skill with digital fluency and makes for a, a, uh, integrated workforce of humans working alongside robots. Also, we're gonna have new frontiers, and this came out from the ai, uh, uh, architects, if you will. But some of the most interesting job creations aren't gonna come from replacing existing industry.
It's enabling entirely nuance. And the, as I said, the AI architects came up with really pointed to this and it's space. You know, we've been talking about space, the final frontier since I was a little boy watching Star Trek in 1968.
The, but the fact of the matter is, we have played with space. We've got, I don't know, 10,000 satellites up there, but we're not really working space. We're not mining asteroids.
We don't have permanent, uh, stations, bases on the moon or Mars or anywhere else. But in the age of AI with autonomous machines, mining, remote construction and industrialization and hostile or hard to reach environments is gonna be a real thing, right? And it's going to create an awful lot of jobs.
These hard to reach environments aren't gonna be impossible to reach with AI and robotics. And that's gonna spawn, you know, something outta Star Wars or Star Trek, a whole new ecosystems of work. So we don't, I can't, as I sit here today, I can't tell you exactly what those space jobs are gonna be, but there's a good chance that, um, there's going to, your kids are gonna be working in space.
And that's not unusual, by the way, that we don't know what they are today because we never do at the beginning of a new frontier. But if history's taught us anything, it tells us that when reach expands, industries follow and so does work. So sit tight on that.
Another thing, another area I want to talk about is the creative arts. You know, I have a, a one of my fellows who work in our, uh, AV team here. Brian showed me something he's been working on last week.
Brian's a Grammy award-winning sound engineer, and he's a musician, but he showed me his music and characters, singers, digital singers and music videos he's created. This is music. He composed using AI and I, I gotta tell you, it was crazy good music.
It was a, you know, and he had this, it looked like a real person, except she had some sort of hologram on her cheek or whatever. But she was singing this song that Brian composed in ai and it was this whole music video and space and everything around it. And it was really beautiful.
And, and Brian showed me what other people like him, what other artists are doing. And it made me realize that, yeah, AI does great videos. You probably saw the Sora video that led this off, you know, but in the hands, excuse me, in the hands of a creative person.
This gets real creative guys. I cannot wait to see what people can do when their imaginations run wild. And instead of relying upon maybe their own hand to eye coordination or their own ability to compose music, we're using AI to do these things.
I think it is gonna ignite creativity. So for things like arts and music and creative kind of, of, of, of a film, well, it's obviously not film, it's video and stuff like that. I think AI is gonna set the world off fire here.
We're gonna see so much coming at us, right? It takes the blank page. Humans still have to bring taste, intent, and context.
But between the, the collaboration between them is amazing. So this isn't replacement, it's leveraging it. What makes jobs worth doing though?
And that really is the crux of it, guys. We could, you know, you want to go get a job that pays your bills and puts food on the table. Look, humans have been doing that for a really long time.
It's few of us who, as I always say, if you do something you love, you never work a day in your life. Very few of us actually get the opportunity to do something that we really find rewarding, exciting, and we would do truth be told, even if we weren't getting paid. Um, but with ai, we, each and every one of us has the ability to pick some sort of job, some sort of doing, some st doing something, some responsibility to master, to create the best ai era.
Jobs are not gonna push humans out of the loop. They'll move us to where we are most valuable, where we're most happy, and where it's most rewarding, setting boundaries, making decisions, but nevertheless owning outcomes. That is fulfilling work.
And it's work machines are not particularly good at, but humans excel at. So what's the real question we should be asking? Yeah, AI's gonna eliminate some jobs.
I'm not gonna sugarcoat that for you. Some of them probably needed to go anyway, quite frankly, right? But the more uncomfortable truth is this, the future of work is not about competing with machines.
It's about whether we're willing to move up the value chain and work hand in hand, arm in arm, brain to brain with these machines. Machines because these jobs are coming. They just won't look like the ones we used to, but they'll be there.
And that's not something to fear. That right there, my friends, is opportunity knocking. This is Shimmy and I'm out for the week.
Are back here with some more, uh, coverage from our AWS reinvent recent, uh, video stand. Uh, if you haven't seen some of our other AWS reinvent, uh, coverage, you know what, at this point, most of the videos are up. You can catch 'em on Textron tv, on the text, on tv, YouTube channel, or on our text drug TV OTT app.
If you've got Amazon Fire or Roku or Apple tv, or even iOS or Google Play, I, you can get the OTT app there. Um, but let me introduce you to our guest here. His name is Robert Cilla.
Cilla. Cilla. Yes.
Close. Rob, I was close. I left the S out.
Robert Cilla, first of all, Robert, welcome to Text on tv. Thanks you for having, it's the first time he's been on, so glad to have him on. Robert, you're with suer as unless you just took the shirt.
It is a great shirt. Possible shirt. It is a great shirt, but I am with sus.
Okay. And tell us what, what's your role at Suse? So I am the Director of Technical and Community Marketing.
So I handle our community efforts around, mostly around our consumer community. And we, 'cause we have multiple communities, um, it's like that with any tech company. So direct to consumer kind of stuff versus, Uh, no, when I say consumer, it's people who consume our technology Okay.
Is the primary focus. And then our secondary focus is people who contribute. And on the open SU side, their focus is slightly different.
Where they focus on contributions and less on people adopting, you know, it, they, you know, they kind of build it, it they will come up on that side. So they cater to making sure the project package maintainers are taken care of. Um, and the needs of these two communities, don't, they overlap, but they're not the exact same.
I love it. You know, we've, over the course of AWS reinvent, I bet you I interviewed a half a dozen to 10 Sosa people. Mm-hmm.
Not one of them really spoke about the, they mentioned the community, but they never really spoke about the community. And so let's start right there if we can. When we talk about the SUSE community, and you mentioned there are different facets, aspects of the community, but how do you define this community?
Can you give us sizes? Give us, you know, I don't even know how you would define it. We, I, I define our community as a large group of practitioners who enjoy the technology.
And that is the binding glue that brings them together in our community. Um, to count it, it's hard, um, because you people are in certain channels and they're not in others. And we estimate anywhere between, you know, 45 to 65,000 people, um, who are active, who, um, they participate in Rancher Academy, which is a LMS platform.
We put out, we want people to learn about our projects that, that are out there, or they're in our Slack channel, or they're engaging with us on social media and we understand there's crossover. So that's why it's an estimation. 'cause I don't, we don't track exactly who's who.
That's just kind of creepy. We just want you to show up for it. Well, but that's, that's part of that open source mantra, right?
We, we don't track. Yeah. You know, we're not looking for your blood type or DNA samples like that.
We don't wanna Know what your kids' names are Exactly. We don't exactly Like that. Or even your birthday.
Yeah. But, um, so a lot of it is online, it sounds like. But then like in the event AWS reinvent, are there any kinda suse community activities tied to it?
We do A few videos that we post out the community, um, does crossover with AWS slightly. Um, when it comes to some of the projects, AWS does have a, a large user community and there's, there's some crossovers there with that. And we see it more so on the consumer side, very little on the con contribution.
Um, for us here, it's just, you know, showing what's the latest and greatest on AWS because we understand that commu there are community users who, you know, they're not customers, but they use our, our projects in AWS and we wanna make sure that we, I don't wanna say meet their needs, but know we acknowledge that that's where they're at. And the They and they matter. They, they matter.
I get that. What about in-person events in the community? Not just at AWS re event, but, So when we have any large event that, that we try to attend, that piggybacks whether what our comm, where our community's at, whether it's here at Reinvent or COU Con or Open Source Summit, we like to engage with our community, let 'em know that we're there.
Um, we always have community team members on staff at these events to ensure that, you know, like they can meet the people that they talk to online. Like these, these are kind of, I don't wanna say they're, they're rock stars in my mind because they're, they're great individuals on our community team. But I, I wanna make sure that they can connect, you know, in person just 'cause you know, it's post COVID world, you know, having that interpersonal connection is, is nice sometimes.
Sure. Absolutely. Let me, um, I, I, I, one of the companies I had started was called the DevOps Institute.
We sold it about three, four years ago. Mm-hmm. But we had a, a nice community.
It was very simple. It was very easy. Well, it wasn't that easy, but one, one part of the community, the people who actually had taken our certification classes and our courses mm-hmm.
And those, we did know their children's name and their date of birth and all that. 'cause we knew who they were. They had a, you know, they took classes and they were certified.
The bigger part of the community though, were just people who maybe, you know, didn't take a, a real certification class, but somehow consumed our content or, or what have you. And it was always the discussion we always had at the exact level is why would those people want to be in our community? What would, like, what, what's the advantage of being in a community, if you will?
Uh, Well, I, I'd like to, I will speak, I mean it in any community, but I wanna speak towards the, the technical community. 'cause you know, it's what we're talking about and it's fairly relevant, is that individuals have to take some of these skills to work. And they don't want to know that.
They don't want people to know. They don't know. So being anonymous, being able to go and adopt, learn and grow outside of your normal work environment, to come back in and say, I, I, I don't, I know this so I can talk to it.
I'm, I'm participating in it. And I think that's where you see it. And it does cross over to non, I'm a, I'm an avid cook.
I love cooking, I love cutlery. I'm in, you know, a community about, you know, cooking and so, you know, new knife skills or something like that. 'cause I want to learn and grow and not think my wife thinks I don't know what I'm doing in the kitchen.
But that's just the same thing. It's the same adoption that you want to have. And it's not judgmental.
Someone comes to the community, they don't know. It's like, can we point 'em in the right direction? People love to come in and answer questions for them, and they take that back to work, or they take 'em back to school.
Absolutely. So there is the, the, the help you grow and especially from a work related mm-hmm. Point of view.
There, there, look, there are plenty of people who are hobbyist when it, especially things like open source and Linux Yep. And, and so forth. Um, but it is, it, it, it's a way to advance your personal career path.
Let's, let's call it that way. I, I, you know what else I, and this is me talking now. I don't have anything to back it up.
Sure. But I think it's part of human nature to, to want to feel part of something, part of a community. And, and as you said, it could be cuddly, it could be cooking, it could be anything.
But you always wanna feel like, I'm not the only one who feels this way, who has this problem, who, you know, is working on things, solutions to a particular issue. I, I think there's, there's something intrinsic to humanity that wants us, that, you know, drives us to be part of community. Yeah.
It's a, it's a sense of belonging. Yeah. So when you, you, you talk to people like we have our regulars in a community, and you talk to 'em and sometimes they will just wanna say hi.
Yeah. And, you know, and or they will bring you something that they did and they want, they wanna show it off. And I love that because you're seeing someone who has the same type of passion.
And I, it, it makes me feel better. 'cause it's not me going, like, I'm just a nerd here. There's, there's other nerds like me out there.
Absolutely Love it. Look, I built my whole business here on those nerds. Right?
I mean, they're, they're the people who watch our stuff and, and consume this. But it, it's, it's part of being in a tribe. Yeah.
Right? It's tribal at, at it's very nitty gritty. It's tribal.
Right. These are people who are in my tribe. It, it, it may not be a tribe that I live with or, or something like that, but we share that common bond, that common interest and, and they become part of your tribe.
And it goes down, it goes even down further where it's like, I, I only like Linux. I don't like Cloud native. Yeah.
And, and that's okay. And We have a lot of people who are like that. And that's, and it kinda, and you know, there's always rivalries in any type of community, so, you know, we're better than you kind of thing.
Mm-hmm. And it's, I it's akin to sports fans. Right.
And then as a Cleveland Browns fan, you know, I don't really fully understand what it's like from a sports perspective, but I'm sure like Eagles fans or someone else out there, you know, with, you know, a better team behind them would understand that level of, you know, rivalry that you have with the technology. Yeah. My sympathies to you by the way.
Thank You. Okay. Looks like you're can have a good pick at a quarterback again, though, this let's not get into football.
Let's, I'm a Steelers fan. I'm my own trouble. But, um, and I, I actually, my, when my brother who's is, he's a one of a fire toing guys, and I say, Hey, be careful what you wish were, 'cause look at the Cleveland Browns, right?
Mm-hmm. But it's all relative, but it is, we are, we're tribes. It, it, football fans are definitely community and tribal.
Yeah. We, we still love, we in that crossovers. We, we each love our teams.
It's Steelers and Browns. We would, we would love our teams and we have those rivalries and we can say, oh, we do this better. And you have, we even have it in the Linux communities where, you know, they don't, there's, there's certain schisms that you have and sometimes they get toxic because, you know, we're in an online community.
Right? Yeah. And when you don't have the interpersonal things go get, they get dark, but they usually recover the, and that's what the beauty of a community, it like naturally recovers.
I I think part of that though is, is, and, and you hit on something when you have a virtual community mm-hmm. You know, it's easy for people to sit behind a computer and say something that they would never say in person. Yep.
And it's easy to misinterpret what someone else wrote and may not, they may not be the greatest written communicator, and they, maybe you're taking it the wrong way or they just wrote it the wrong way. And, and this le look, I've been in online communities for a long time, maybe 40 years. And, um, well You also for, you didn't mention, but you know, we're international.
Right? Right. And you Right.
You guys are, there's, And so there's, there's language things. There's language. I really barriers, but, you know, this is No, no, but there's, there's miscommunication All the time.
And sometimes I come into Slack and I'm like, what's going on? Why is there a dumpster fire today? And I'm like, oh guys, he missed, like, he meant this.
Right? Like, that's not that word that you Think, but it doesn't take, It doesn't take long's too much. Nope.
It does not. There's people over the edge, Robert, let me, we're running lower on time. But for people out here who say, you know what?
I've been a Sousa fan. I, or I've been a Rancher fan. Mm-hmm.
Or both or, or what have you. I'd like to be more involved in the community. Sure.
What's the best on-ramp farm? io, you can go sign up and you, you get dumped into our general chat and people, and we see, we see people who get put in there and just say hi. And someone from the community team or someone from the community will do and explore what they have going on in there.
There's, there's a lively chat. Um, there's random stuff that people, you know, post, there's technical checks. So, you know, if they wanna learn more about K three s or rancher specifically, um, those, that's generally the, the best way.
And, you know, I am, I'm in that slack more than our work Slack. So Really, because that's my world. Well, that is, that is, that's your work.
That's my world. So, um, I come, I go back to work. It's your tribe.
I go, it's yes. And I go back to the work one when I have to, but that's where I I you'll catch me. Um, is that, that's probably the best way.
And again, this is for the consumer side. When you're getting started in the community, uh, you don't have to come and contribute right away. I always tell people that just come and say hi and, you know, find where you want to connect.
You know, and it doesn't have to be contributions right away. It doesn't have to be consuming right away. It's just showing up and just being, just taking part.
Excellent. Is this your last show of the year? This is my last show.
Me too. Um, I'm getting, uh, a very busy with a, and I'm gonna do a shameless plug on Scon coming up April 20th through 23rd in Prague chea. Um, that's what's consuming most of my time now is the planning for that, um, on the CFP committee.
So I'm going through, um, uh, me and a group of individuals at SUSE are going through a ton of talks with a lot of great topics. So if anyone is in Europe can make it. I do.
Well, I hope to see you there. I'm hoping to be there as well. Okay.
I'm thinking maybe I should submit something. Has anyone submitted anything on AI yet? Oh, I'm kidding.
Kidding. That one right there is, uh, I Think, I think that's the, the vast majority. And I think when I saw, I saw one that wasn't AI related, I was excited.
I was like, Wow, I, I get that way too. He Was brave enough to put that one in, Put something in, not with Its crazy time to be alive. I know.
It is. Everything's ai. But yes, if anyone can make it, I would love to see you there.
com, find out more information about that. I love it. Rob, thanks for coming on.
Thanks. And helping with us today, man. This is great.
Hey, go check out the rest of our AWS reinvent videos. Scon is coming, I believe it's April 20 to 23rd, as Rob mentioned, in Prague, which is a great city. You don't have to be in Europe to go to that though.
They do have planes that come from here to there. Yep. And, and, uh, it might be worth your while.
It's, uh, I've done sko actually, the last scon I did was in Orlando near our house. Yep. But it was a great event as well.
So highly, highly recommend it. But that's it for here. I hope you've enjoyed our AWS Reinvent coverage.
This is Alan Shimmel for Textron tv.