Techstrong TV July 2, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Wanna find out about the latest tool in the quiver of your favorite ice agent? Stay tuned.
You're watching Text On Gang. I. Hey, everyone, happy Wednesday to you.
It's Alan Shimmel here for Textron Gang. We have a great gang show to talk about. We've got some interesting things going on, as usual in the world with some interesting people to talk to them about following our kind of semi new, uh, uh, protocol.
I'm not going to do big do big intros to tell everybody where you're from, but joining us there, regular gang members, Mitch Ashley, Chris Blas, guy Courier, the Dean, Mike Ard, but we do have one new member, and so she gets to be the star today. Kate Scarsella. Kate, welcome to Textron Gang.
It's great to have you on here. Tell people a little bit about yourself. Yeah, so my name's Kate S I've been a cybersecurity architect before cybersecurity was even a thing before it was even popular.
So, uh, did my master's, um, thesis in information security. And I always tell people back in 2006, and there was only four people in my class, so definitely, and, you know, uh, yeah. So I've been doing this for a long time.
Absolutely. And I do remember before it was cyber and there was no, not even a bachelor's in cyber security or an error of concentration, or I remember Mitchell and I doing a survey, it's still secure maybe in 2003 or oh four about where, where did you come from that you're now working in InfoSec? And I think 66% of the people were network people, network helped desk admins, network admins.
They were just too stupid to say no when someone asked them, you know, do you wanna handle security? Anyway, welcome to Textron Gang, and I'm sure you're gonna be a fine addition to our gang. Um, let's jump into it for today, guys.
So our friendly neighborhood ICE officers, officers, if that's not an oxymoron, have come out with something new to help them in their never ending quest to throw out people who may or may not belong here. Um, it's a new face facial immigration recognition tool. Mike, what's this about?
So, yeah, they're not commenting on it, but apparently they have revealed that ICE agents have this mobile fortify smartphone app, which is realtime facial recognition that they're using that help them identify potential illegal immigrants. And on one hand people are saying that it might help them maybe identify the right people, but other folks are saying facial recognition software is a little too shaky these days to be relied on. Guy.
I know you've been kind of following the space a little bit. What is the state of facial recognition and are we likely to see, you know, somebody get deported who shouldn't be deported? Well, I think the, Hmm, well, I think the state of facial recognition in general is pretty good and it's getting better, um, for two reasons.
One is, um, the ai, which wa predates all of this generative AI stuff. Uh, uh, computer vision is what it's called, um, is very well developed in getting better. The second reason is that there is more and more data for it to train on, but also for it to use in reference whether your typical, I don't know, uh, person of interest to ICE has any kind of extensive, uh, facial data, um, in a database somewhere that I have no idea, but I suspect it's less than those of us on this call who live in a privileged class that gets to fly around all the time.
So we've all been through TSA several times, if not dozens of times by now, and had our image taken and used for recognition purposes, I should say, pretty darned accurately. I don't know of any stories about like, inaccuracies in that for citizens and run of the mill travelers. Any, any problems with that?
Nonetheless, I find this one of the most concerning developments I have seen in this whole, um, I don't know what to call it. I hate to use the word immigration, or I hate to use the word deportation or legally speaking. A lot of this doesn't have to do with any of that.
It just has to do with identifying, uh, persons of interest undesirable, singling them out, pulling them out and doing stuff with them, using ICE as the agency for that. And, uh, the idea that, um, as we all know, um, uh, an imperfect tool, um, will be relied on as if it's perfect. Uh, because no matter how good this AI is at facial recognition now, it remains imperfect, even if it's more accurate than the human brain, which is highly doubtful.
The human brain is evolved over a million years roughly to, uh, identify faces almost as one of its primary uses. Um, but even if it's more accurate than that, um, the, the real problem remains in ai, the human problem, that it looks so easy and so quick that people just think it's just doing what it's supposed to do every time, even when it's not. Now, I will add one last thing, which is there still remain in this country legal processes, um, or dealing with things like false identification, but by then the punishment has already even med out.
You even sent you South Sudan been Pulled. Well, even if you're not, Alan, you've just been pulled out, single out, you've gotta reach out to family members, a lawyer, somebody, maybe you're be an inata. The damage has already done.
So I think this is a pretty damn dumb idea on about a thousand levels. Chris, I gotta I gotta go first. I'm sorry.
All right, so I got a few things to say about this. So you're trying to tell me that they weren't doing racial stereotyping and just picking brown people all this time. Let's not.
Oh boy. Because that is one real black hole and facial recognition that still hasn't been patched. Which It's funny, funny you say black hole because it's had a problem with black people.
Mm-hmm. That's your brown, you're right. I'm ashamed I Didn't mention That myself.
So, Yeah. Okay. Mm-hmm.
And there isn't much of a jump from having a problem with black people to having a problem with brown people. And I think that's, that's not where our problem is. Our problem is with the people using it.
Right. A tool is as good as the people who use it. That's all.
I'm, well, actually the Go Ahead. That technical issue remains. It's horrible.
It's based on a thousand, you know, mistakes by the thousands of programmers putting this together over the last decade or so, and it remains so, so that makes it just even worse. Yep. Chris, I know you have some thoughts.
Yeah. This is just a Twilight Zone episode, right? The technology's fine.
Technology does what it's supposed to do, right? You know, this is mi minority report without the precogs, right? We're running facial matches on the street, feeding into a central intelligence grid and calling it AI and, and to the point YI think both of you are making, there's no audit trail, no public accountability, and no verified accuracy.
But other than that, it'll work fine. So I I, we find ourselves in these situations with advanced technologies where we're, we're, we're mirroring flaws in ourselves, right? And you, you touched on this with racial profiling.
You know, we all know this as security people, right? When you're crossing a border or you're, you're, you're as a human sorting through large numbers of people you profile, you're looking for people who look like, I dunno, me, right? You know, long hair, hippie looking, uh, folks or, you know, some other stereotype.
And with humans in the loop, maybe, you know, again, let's not go down that rabbit hole. We haven't been great at this, or we're gonna automate the same systems with no accountability, no audit auditing, and no verifiability. Uh, no, no.
You know, guy, I'm sorry. Go ahead, Kate. No, And, and one of the things that you said Guy, was, um, about, uh, training.
You know, we've had, you know, these models that have been, you know, so many images that we have trained, you know, what about data poison? What about poisoning of, of the, I mean, what are the controls to know that the models that we're training the this facial recognition is, are good models? You know, do we know that, You know that, that's a really good point, Kate.
What I was thinking about is, you know, it's, it's the quality of the tools and put into the quality of the people in the hands that those tools are being used in, right? And, you know, it can be their own training on how to use that. I mean, facial recognition has been, you know, maligned to the point we've talked about of, of, of, of, uh, kind of biasing against, or people of color.
'cause it has been like Indian people, black people, et cetera. Um, but it is an area that is, is got a, I mean, that's been part of AI since I worked in AI in the eighties. And it's all about image recognition.
And it's not generative AI that you use for facial recognition. They use something called a convolutional network model or neural model, which is basically edge detection to determine trying to understand the structures of an image. Um, and it's different when you're looking at a photo or a still image or a semi still video versus somebody walking through an airport, you know, you're trying, like they do on an FBI on tv, right?
Um, so it, I mean, the, the accuracy has gotten much better. I just question is, is this just lipstick on a pig on a, an ice pig that, uh, yeah. Okay.
So they're using facial, but are they using it effectively? Is it really helping? Is it just like, okay, move on.
You know what, we, we don't have a lot trust in the process. Yeah. We don't have any trust in the process of what they're doing.
So this seems more like a pr move than an actual, let's, let's use this to be better at our jobs guy. When you said a privileged class, because we fly a lot, that's not the privileged class, my friend, the privileged classes that we're all white. Yeah, absolutely.
Let's call it what it is. I have a question. I think there's, I think it's Both.
Are we, are we sliding into, um, a surveillance state in the name of security Sliding, how about head first? Um, We're already in a surveillance state that's already go to London and We're accepting it. It's not just London, it's New York.
It's every, it's every city. I I, I seen you remember Ben Franklin when saying something to the effect that if you sacrifice liberty in the name of security, you deserve neither I, with all that, I, I'm gonna, you know, assume my cliche role, you know, I think we're driving through an inflection point that that leads to a positive to, to potential positive ends, right? I see this again in cybersecurity, everywhere in the supply chain, you know, just yesterday, uh, which will be two days ago when the airs.
Yeah, I mean, a bit of a knockdown drag out. Now people who know about whether we really can know everything that's in this, in the software all the time right now, you know, and are we at that point we can actually do that. I think we are, uh, we weren't last year, and we will be at some point in the future.
Same with this, we've been accepting systems without the transparency and visibility, and I forget who mentioned it, but yeah, again, the, the, the penalty, you can get information now if you are really enthusiastic, if you really wanna file the paperwork and get into it and spend the three to six months, you can get the transparency, that's not good enough and never has been. I think we're driving ourselves to a point where we have to decide whether we're gonna accept opaque surveillance states or demand the transparency that we wrote down, you know, 250 so years ago, right? So it's not just the surveillance state.
It's a question of, of, of freedoms of, of living your life free if you, you know, you don't have to be entangled with government and so forth. You know, one of the things they always say about the state of Singapore, the country nation of Singapore city state, whenever is they traded their freedoms for security. They traded their freedoms for prosperity and their constitution, and their society reflects that.
Right? You know, if you throw gum on the ground, you're gonna be in trouble there. Uh, if you do, you bring drugs in, it's a death penalty, right?
That is, that is the trade off they made in Singapore. I think we're coming to a point here in the US where we've gotta decide, are we, do we want to have that kind of trade off? Do we want to give up some freedoms, not some, or at least some freedoms in some of our constitutionally protected rights for maybe a better shot at prosperity, or, I, I don't even know why one would do it, to tell you the truth, but, well, you know, are we willings to do that?
Singapore, as you point, Singapore is a particular case, and I don't, I just, I'll just put it this way, right? It's, it's, uh, isolated city, state, small. It's in a particular part of the world with particular had particular security concerns of its own 'cause It was a majority, uh, uh, Chinese population in the middle of a lot of other populations, and the Chinese population had been there for centuries.
But its particular situation. I, I think I'm optimistic, my saying is, the truth always wins. Um, and the truth is that there is no security crisis in the United States.
The truth is that, um, the, the, the various stories around why we need to do crackdowns or have more security or, or, you know, send Marines into California or whatever, right? They're just, they're invented, they're bedtime stories for people who want to, you know, feel like Or invoke at 20-year-old. So, so the, the question is not when whether reality will win.
'cause the reality is that we don't need this kind of stuff. It's when, when is it going to win? But I'm optimistic that it will win in a reasonable amount of time, or maybe a re there's no reasonable amount of time, but in a certain amount of time, it will not perpetuate surveillance state has particular connotations to it as a phrase.
We already are in a surveillance state, if you wanna look at it one way, because it's just to go take a plane. You're gonna be watched, you know, for a thousand yards on your way to the plane or in other ways. Surveillance states are extremely hard to achieve right now, uh, because, uh, there's so much data, so much information available, but there are still human actors even behind or across next to the AI that is developing that need to actually do stuff in reaction to it.
So I think that it's a dangerous point, and we need to call this stuff out, but that does not necessarily mean we're on that slide. Well, I think of the false dichotomy to say it's a choice of either or, right? You know, I have been, and continue to be a, an absolute believer in the fundamentals of this.
You know, this is, you know, and I'll say it as American, it's America, it's western democracy. It's open source, it's freedom of speech. It's the internet.
You know, it doesn't work because it's good and chewy and hippies like it. It works because it's more effective, more efficient, and it works. And the actual transparency that, that our country is founded on, and this whole internet was founded on all this stuff have founded on, hasn't really been practical, and it hasn't kept it up with the needs of the times.
So it's not about whether cameras are gonna be everywhere. They have always been going to be everywhere. Now they know.
The question is, can you actually tell what other people, like governments who have control over you, that we seed voluntarily control over you? What they know about you when they know it, and what they do do with it. And in this, the case of this piece, the answer is no.
You know, this is not something a free government does, period. The whole system is, you know, does not work. Would it be done in a way that was free and fair by possibly?
This isn't it. I agree. All right, let's leave this alone and let my blood pressure calm down here.
Um, let's take a break here. We're gonna come back and talk a bit. Well, we'll talk about more deep fake regulation coming at you on techron Gang.
Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
We'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back in. Well, I don't know about reduced Allen's blood pressure because, well, we got another interesting topic here, which is regulations that applies to deep, big Ireland has joined Denmark in creating some regulation that grants people the rights over their likeness and their voice, and is pushing for additional controls.
And the whole idea here is that there should be some legal remedy that I can invoke when somebody steals my image and tries to impersonate me in some way that creates mischief or mayhem. Chris, are, are these laws gonna be applied more globally? And frankly, are they enforceable?
Uh, yes, they are gonna be applied more globally, and yes, they're enforceable. Now, these particular ones we'll see, right? But it's absolutely the right step in the right direction.
And as you're saying that, I, I, I know my mind has been so wrapped up with civic ai, canon and all that, but this is specifically rules in, in the civic ai, you know, uh, uh, ethical arch architecture we've created that, that AI are required to obey. You know, you cannot pretend to be somebody else. And if you do pretend to be somebody else, you need to, you know, tell them about it.
And it needs to be situational, and it has to be attested to. And like a lot of things in developing this ethical framework, we're working through things that we find that humans do implicitly without really understanding. So we're having to codify them so the AI understand what it's like to navigating human world, um, at this level on the, on the, this side of the class for humans.
Yes, we have to have rules and regulations like this that say, you know, if you were going to pretend, you have to say you're pretending and you don't get to, you know, free speech is not, you know, any, everything I, I wanna send, uh, in that paragraph with is a cliche, right? But ahead, this is perfect ahead. Let's hear your cliche, you know?
Yeah, you have to. Now I forgot what the heck it was, but, uh, you know, you know, this is classic stuff, right? Your grandmother told you this, you know, don't lie.
If you're gonna lie, say I'm lying. You know, you know, comedy is a wonderful thing. Caricature is beautiful, but you know, no, you don't get to pretend to be other people.
Or it's like, or it's like referencing if you're writing a paper where you know where you got, yeah, we've been doing this, right. For, for years, So, right. You know, and, and you know, as you folks know, I and my ai counterpart co-author all the time, and we have, we have designed into the ethical structure, you know, what that specifically means.
And we do it better than I do with human co-author authors, you know, am I just advising someone on a piece? Are we really writing it together, or are they writing it and I'm, you know, sub or whatever it is. So there are ways to codify this.
And again, as humans, we sort of muddle through it because we haven't written, written it down for AI as we have to. And I think it's a good mirror for human behavior sometimes. Well, you know, I think it also opens up the whole what is a deep fake, because as it as this technology is good enough to make a video of myself, let's say for example, that is a deep fake, it's not actually me talking or me on the video.
I might have created that for myself. I might have to do that. 'cause I don't have time to go shoot videos or whatever.
Is my reason for doing it is that a deep fake, even though I created it for myself. No, no, but that, that's okay. It's Super interesting point.
So hang on, Alan, because, um, my state where I reside state of Texas, um, has actually been a little bit advanced in, you have Good regulations in Texas about this. Yeah, yeah. Well, so, so I looked up, uh, how the phrase deep fake is defined in Texas law.
And part of that definition is the intention to deceive what, what in, in, in the law, if, if I have, you know, uh, that's like race, race or something like that, you need the intention to deceive in order to do it. So, so, so the interesting conundrum here is you're not intending to deceive if you are creating a Mitch Ashley AI video, Well, maybe I do wanna deceive them and make 'em, or maybe really, maybe you're missing a point legally, guys. Okay, well legally need a lawyer guy.
You went to law school too, right? No. Or Lee Lee went to law school.
Sorry, Lee. No, I, I watched Legally Blonde a few Times. Okay, so look, from, from a, from the legal tree, hear me out from the legal tree.
This is an IP issue, an intellectual property issue. Who Has, this is where Mark got it, right? Go on.
This is where this is. Yeah. This is where Denmark got it.
Right? This is an IP issue. This is who has the right to your likeness, to your being, to your image, to your, to your ip.
Your image is part of your ip. Now, here in the us the most famous case that kinda set the mark for this was the estate of Bella Lago. Ja.
Um, his, his, his heirs sued because they were using Lago, you know, for Eular, uh, uh, advertisements all over the place. And the Supreme Court ruled, that's one's likeness is is one's ip. So Mitch, in the case of point that you brought up, you own your ip.
If you wanna make a deep fake, if you want to call it a deep fake, if you wanna make a copy of yourself that you use electronically, it's your ip. You could do what you want with it. When Mike does it, that's a whole nother story.
And if he's doing it and not asking your permission and holding it out there, it's a, it's an IP violation, right? That that is wrong. And, and you're entitled to compensation.
Now, here's where it gets interesting. Obviously, one could say, well, my image is, is part of my ip the case of Laci, uh, the, the state of Laci versus I think it was MCA or something, um, holds that, what about your IP in terms of what you've written that an LLM is then taking? And, and, you know, and when I go into the l into the a EI, and I say, write this in the style of Mitch Ashley, and it writes an article that is in the style of Mitch Ashley.
Does Mitch have ip, you know, does Mitch have an IP claim there? Because it was, it was still your ip, whether it's someone's image or some other form of their intellectual property. How, how far can you, does that extend to letting the AI or, you know, what's the intents?
Yeah, Sarge. So to me, that that's the thing behind these defi regulations. Now, yeah, they're there to stop people from deceiving you, but the underlying, even if they're not deceiving you, you shouldn't be able to use my IP without my permission, without me being compensated.
It's a good point. A public exception. You can even bequeath your, your ip, your likeness.
Einstein did that. Um, absolutely. Salesforce is using Einstein in their AI advertising.
They had to pay you $20 million. Well, the Legi case, university of Jerusalem, the Legi case was his estate, not, he was long debt, long gone. Well, maybe I don't the unless silver thing in his heart, But it, I don't know the legal principle upon which one's, at least in, in, um, uh, the United States one's, uh, uh, image is considered your ip.
It Absolutely, But if it's based, don't say absolute and Supreme Court in the same five minute span. That's all I'm saying. Well, there's A law that's true.
This is what Denmark, this is what Denmark did, um, was codify it as a law. Um, and I don't, I just, that's, I would be cautious about, about Here. We probably don't have a law.
We have, we, we have case law, but the other person saddened, I'm personally saddened a topic or an issue that I would've thought would've been covered by common law. Stretching back to the Don of Time is now has to actually be written down in the age of ai. But what do I know?
I, I wasn't thinking about this from the IP perspective coming into the segment, but I kind of like it, and I, and the end of the, the end of the back and forth, right? This is, you know, when I'm writing something, co-authoring things, you know, musician friends, you know, we talk about this all the time, you know, I tend to write like the last author I've been reading, you know, so is that IP or is that what, you know? So I think rules and regulations we need when we can't avoid them, but they only go so far.
And I think getting past the cases you're, you're talking about, um, it comes down to ethics and that we can navigate personally, we don't hopefully need rules for, but I think we, we need this one now. Yeah. I mean, there have been cases where you heard a, a a, a musician had a jingle in his head and he wrote a song to it, and then it was found out.
I'm sorry. Yeah. And then if that they, you know, that, that, that jingle was someone else's ip.
So Kate, I wanted to ask you, so this attempted deceive side, if I think about it specifically from a risk and insecurity angle, um, I don't think, would there be any argument that, whether it's through social engineering or through, you know, stealing credentials or using, or whatever it is, if somebody impersonates someone else or simulates someone else in order to gain access to a protected resource, is the, but then doesn't do anything. They don't steal anything. They don't copy difference, they don't use it in any way.
It's still, it's still a crime, right? Mm-hmm. I absolutely, personally, I think so, yes.
I think it's still a crime. And because I think what you see, especially when you look at cybersecurity attack methodology, that's what they do, right? They start to look at the steps on how do I get access to resource A, B, or C?
And sometimes they will test to see where they can go. So absolutely. I mean, Right.
Breaking and entering is a crime. Even if you just broke, entered, looked around, he don't Take anything, right? So even If there was no robbery, this, This, this is where like common law, common sense, all those other sort of things, they just all combine because you're sitting here and you're going, how could that be a crime?
And yet whatever deep fake use for whatever, like deep fake as, as defined as an intent to deceive, forget about all the rest. Well, how could that not be, I don't know, inherently criminal, how could that be legal anywhere? But these are resolved through lawsuits, aren't they?
Allen? I mean, I'm thinking about the, um, the Vanilla Ice and the Queen under pressure song that was, they settled that outta court. You had to pay like $4 million to whatever it was.
It's an IP claim. It, it's a resolved outta court. It doesn't get hauled into the judge.
And so you, Chris, you did a felony, you know, IP theft. Well, well here's, That's the difference between civil and criminal. So that's, but here, Here, they're, they're making a criminal is what I'm assuming, but I'm Gonna, yeah, there you go.
I'm gonna bet that there's gotta be a satire exception or something like that, you know, especially for a public figure. Yeah. Like an SN l type of, you know, like Yeah, I'm, you know, the absence of malice, all of that stuff.
So if you have this warning, it's satire or this, you know, a water or whatever, some kind of Marking, I don't know if there's a warning. It's satire, right? I'll, I'll recognize it when sre I see it, it kind of fakes That, that even, even the, you know, the best of the like live real person in makeup, whatever satire that you see, there's enough generally speaking of a clue that it's not the actual person.
Now, does that, does that apply in every single case? No, but in enough of the cases, but now we're talking about where 100% of the time or approaching 100% of the time, it could be very, very difficult for the average person to tell. And so then it goes out in the wild, and here's something that was built and intended as satire expressed as free speech.
That is now off who knows where being used to smear the person in question. We need to, we, which is why we need to separate though, we we're really talking about is media authenticity. Right?
You know, we, you know, IP and, and satire and so forth are real, but, you know, we all understand the issue right now is that nobody trusts the media or has any reason to. Right? And with these sort of simulations, arguably showing up in what we regard as information sources, without any, you know, digital consent system, um, there's no reason to, to have trust in the media we're getting.
So Chris, I label think that's the fine beginning, but you know who people trust less than the media, The government. Yeah. Right?
Yeah. And that's who we gotta be careful about using this. But well See the last I I, But yeah, but I thought You were gonna say lawyers going On.
Well, no, they're killed the lawyers first. Right? Well, but that being said here, here's the other thing.
I, I do believe there's a way out of this rabbit hole, and, and it's, Chris, it's something I read in some of the things you've been publishing, which is we need a better system of identifying what's fake. That, that, you know, whether it's called civic AI or whatever you're calling it, Chris, you know, is there, is there something that people can go to that will tell them this is genuine? That's, and that's the answer is not the first part.
You know, what's fake? Who knows? But we know what some things that are real, and having enough of those that we all reference against allows us to make better decisions about the rest.
And that's how we all get through the life. I mean, literally, you know, that's our brains work. We're not processing all the information.
We focus on what's important and the real things we can pivot off of things that may or may not not be real are, are much more numerous and always will be. Now Here's, here's my belief in this. I think for people, baby boomers, gen Xers, the D is kind of cast, right?
We, we have gotten used to being in a world where we have, you know, a thousand channels of tv nothing on, and, and some of us believe everything that it's on, that we're told. Some of us don't. Some of us just have our own opinion, and that substitutes for facts.
I did believe that Gen y, gen Z millennials being digital natives, have a better true north, a better compass of, of separating, um, fact from fiction, deep fake from reality. I'm not So sure anymore. I'm Mitch's eye roll and Mike Mitch.
Yeah. And Mike, I saw that. I haven't seen any study.
Maybe I haven't seen any studies to that effect. So better. Sure.
Better enough. We'll, we'll find out. But I, I, but I do think there's an answer technically that'll help.
And it, and, and I think, you know, it may be too late for us, but it'll, there'll be in time for that. So you're saying there's hope, it's Gen Z, there's always, it's That's what you're saying. Why's the Optim?
He's the optimist. You're saying Gen, I dunno, I was the optimist. Gen X.
That's pretty Phenomenal. I think we're, I missed that. Everything is untrue and working our way back.
Alright. Alright. Hopefully forwards, Mike, it start started With believing some things are true and build yourself up.
That's a lot easier. Well, Let's take a break here. I don't know what's true or not anymore, but we're gonna come back and talk about gluttony.
Well, we're just on like the 7 cents today, huh? Okay, you're watching. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
Security boulevard com. Home of security bloggers Network. Hey folks, we're back.
And it turns out that open source isn't free after all, and there is a cost in running all the infrastructure to support it, but it turns out that a lot of folks are using it in a way that shall we say, is fundamentally inefficient and not realizing that they're running up the cost of using that infrastructure in a way that might threaten the existence of open source one day. But I'm gonna let Brian Fox, CTO of Sonotype explain here in this little video segment we did at the Open Software Summit last week. We've, we've modernized our practices to the point where all of these open source projects, everything is dependent upon, you know, CICD in the cloud, right?
And GitHub actions, GitHub, you know, sponsors lots and lots of machine and compute time for, for GitHub projects to run their builds. And lots of other companies do it too. You know, Sonatype, we run the Maven Central repository.
We, we pay for the bandwidth and all these things, but I think people have, they don't recognize the underlying cost because all these companies are bearing that, that burden, right? And so it, it's led to this sort of sort of, uh, mentality, you know, the gluttony mentality of it's all free. And so I'm just gonna run my build as many times as I possibly can, every commit.
I'm gonna run a, a pretend release. And, and so what I'm, what I'm seeing when I really look at this is I'm seeing really just, frankly irresponsible consumption by, by, uh, individuals and, and companies. Big trillion dollar companies that really should know better, right?
And are just eating up all of the resources that are causing every company that has to donate this stuff. Alright, we're back. So, Mitch, to Brian's point, is this becoming a larger issue or is it a narrow set of projects and maybe only the smaller projects that this is gonna affect, but it does seem that best practices are not being followed consistently, shall we say?
Well, I was, I was lurking in the background or the side of that video listening to you guys talk about it during the open source summit. It was pretty interesting. I i, it, it's not like a theme or a cause that's bubbling up and people are getting kind of building steam around it and some momentum.
But it does raise the question of are there good practices in, in being considerate of the resources that you're using? The problem with some, when something's free, it's free whether to use it once or pre-use it a thousand times an hour. If it's free like that, then you use it for whatever you want, not really thinking about, well, if everybody does this, then there's resources at Sonotype or at Docker or GitHub or wherever this is suddenly are now responding to a whole bunch of requests that isn't really needed for that and they've gotta start putting limiters and governors in place.
So I, I don't know that it's a rampant problem. Maybe it is, but um, you know, I think Brian was responding to it because he's digging into what they're doing at Sonotype and the resources that are being acquired, and why is somebody hitting, you know, our repositories this, this fast or this quickly, this many times per hour. Do they really using that many build processes or just a gone amuck, Not just somebody, a trillion dollar vet tech company is what he Said?
Yes. Yes, he did. He didn't name any, uh, names, but there's not too many $2 trillion tech companies, right?
Well, in my desk, Dr. Richard Stallman voice pity, pity, I was Gonna mention Stallman. Go ahead.
Pity, pity these poor people who can't make more money off of open source. If it's open source, it's open source, right? We've seen this, Mitch, and I've seen this, Kate, you were around then, so will you, Chris, right?
Look, I remember when Ron Goler and Rena Jason said, oh, everybody's getting rich using Nessus and Nessus is in everybody's scanner and we're not gonna keep it open source anymore. It's free, but it's not that free, right? It's free as in beer, not as in freedom.
And, and, and so they, they took masses out of open source. Marty RA said, well, you could still use the snort engine, but you're gonna have to pay for those rules. The syntax rules, this is if something is open source and you make a decision to open source something, people can use it to the letter of the license.
And if that disagrees or conflicts with your open source business model, then don't have an open source business model. I have a ton of respect for Brian. I have a ton of respect for Sona type, but when you put something out there, you can't cry if people are using it pursuant to the license that you put it out under.
But to that point, Alan, I'm, I'm kind of of the same mind of, is it just, you know, this is a problem, you know, the sky is falling. And I'm not saying Brian is being that, you know, dramatic about it, but on, on the other hand is, of course, people are gonna abuse it and overuse it. Maybe intentionally, maybe not at times.
And if you're gonna provide a resource that you're paying for, you're gonna have to manage it and you'll have to put some limits on it, some governors or whatever, or not. I mean, it's just a cost of you hosting that open source, you providing those servers, those repositories, et cetera. So it, it's part of it, it isn't, you don't get to do get open source because you just provide code.
There's other parts of it you have to support as well. All right, I'm gonna dis I'm gonna disagree with this on a multiple points here. One is we're not talking about open source, whether it's open source or not.
We're just talking about whether or not I need to provide the infrastructure to host that open source project. And I may not be under any obligation to do that just because I made something available as open source. So you could see companies that are making those resources, deciding that, hey, we're gonna continue to give you that open source license.
We're just not gonna continue to fund the infrastructure underneath, underneath it. Sorry. And you know, there's a trillion dollar company out there that might wanna kick in a few bucks to help with this thing.
Secondarily, there is much room for improvement in terms of just making people aware that this is an issue. Because most folks, when they know will do the right thing, I would argue that most of the people who are probably abusing this stuff have no idea. And they're just kind of like using It.
Absolutely do. So here, here's the thing, Mike, you gotta draw a distinction between open source software and open access, right? In, in the case of Sonatype, with all due respect, the 2 trillion pieces of Java code or JavaScript that they've got up there, they weren't written by Sonatype, they were written by people who contributed to a repository.
Now, is all of that code open source? Yes. Does the repository, is the repository itself open source?
I don't think so. I think instead of crying in the beer about what was me, all these trillion dollar companies using my, my open source, they're not really using your open source. They're accessing open source, soft or open source code on your repository.
So say, look, all the code in there is open source, but to use the ingress and egress of my repository, you have to have a paid account. It's a very simple thing. Now, you're gonna p**s off a lot of people because Mike, they're not as naive as you think.
They know exactly what they're doing and it's open source and they can, and you're gonna p**s them off. And you may or may not have a good business after that. And Chris is gonna burst.
Go ahead, Chris. Craig, Chris. Alright.
I I'm gonna go against all precedent and agree with Mike, right? And don't get your expectations up. This is never gonna happen again.
But, uh, you know, Alan, everything I'm hearing from you is, is you know, well-founded cynicism, right? You don't believe the companies, you don't believe what they say, you don't believe their motivations, you don't believe, and there's no reason to believe because you can't tell, right? You know, and I think this, you know, I think this sort of issue, you know, I, I, I watched the, the episode, I don't exactly know how someone type's doing things, and maybe they're right or wrong, but if you, I can see myself being in that position where suddenly I'm, I start up a little company, now it's a big company and I open source everything, and I find out that everybody's clicking on things that I wasn't, I I shouldn't have set up that way.
I wasn't immature. And I'm saying, look, I can't afford another data center to support this, and I have to ask, but there's no way for people to actually believe and see and know that this instead of lack of transparency at every level. But again, I'm asking you what, go ahead, Kate.
I I know, but I have to agree with Alan being, you know, from a true networking background, right? This, you know, you start to see, you know, these, you know, res and, you know, ingress and Yeah, I mean, you know, Alan's coming at it from, I think Alan, from a networking perspective perspective. And you see this.
Yeah. I mean, what, what's, what's Sonatype's open source software here? No, no.
Phototype providing a service. I, okay, so I don't agree with anybody except you, Mitch. 'cause I don't know what you've said.
I can't remember. Um, It was important, whatever it was. I know Here's, here's what's, here's here's what you're, you're all missing open source as a market has changed.
It's changed significantly, maybe even more than like, maybe it's changed radically in just the past, what, three, four years? How so? It has invaded the commercial enterprise space.
And I'm not talking about, you know, it ops software. There's been tons of open source, you know, infrastructure, operations, software and all that stuff going on. I mean, that, that, whether it's delivered through, uh, independent software vendors, software packages, or used by development teams in the enterprise, it has become a really big thing.
And so the terms under which Sonotype and others have created, their repos, made them open are old terms that predate this kind of, you know, accelerated adoption and use. And so that's really, in my sense, what is concerning Brian, even, even if, or sonotype even if, even if he's not stating it, which is we built this thing with a certain expectation, but now something else is happening. Now Sonotype gets something extremely valuable out of making this a free available service, which is they see who all the users are, they have all of those accounts.
I don't know what, what agreement you have in order to set up the account as a repo or whatever. But you are a central market actor, actor, if not a market maker. So I don't cry any crocodile tears for sonotype here.
And I think that they just need to, if they haven't already, they probably have understand the value that they're getting back from doing this. I'm gonna do, I'm gonna do a Mike Ard here. What makes me scratch my head about this one is, isn't this just like, um, why are all, why are these IP addresses hitting our website so frequently?
Why are they, where are they from? Who is it? What are they doing?
Who do we block? Who do we reach out to? We've been dealing with this with networks since Ping absolutely came, came about right?
It it's the same. It's really the same issue. People over accessing a resource, and you have a couple of options about how you manage it, but you gotta manage it.
It's your resource, whether you're giving it away for free or it's part of your core business, um, and you charge for it. You, you're, you see abuse, whether it's intentional or not. You, we've been doing this, Kate.
Yeah. Am I right here? Am I going down the right path as a network person?
Sure. But, but let me, there's another aspect of the open source community that needs to be heard from, and that is the Saints who freely give their code to these, to these companies without any or Crocodile tears coming from me. Continue.
No, No. You know what? There's a lot of people who write Java script snips, Java code snips.
There's a lot of pe I'll give you, let's take, go away from Sonatype for a second. Let's go to GitLab. Open source, CICD every month for the last 12 years, whatever it is, 10 years, eight years.
They, they released on the 22nd of the month a new version. And that version has new code in it. And not a lot, but some of that new code is code that was developed by members of the community and contributed to the project.
So Harvard Business Review did a study of this last year and found that like something like 96% of enterprises are using open source, but only about 35% are contributing to It. Yes, it's the parasite problem, but I'm talking about the people who do contribute code guy, they contribute that code without any expectation of being compensated. They do it because they want it to be available to everyone.
Now, when they, when they contribute to a repo, It's more complicated than that, Alan. But yeah, when they contribute, go ahead. When they contribute this code, they're doing it under a license with the expectation that it's free and open and, and not an expectation that everybody's gonna contribute.
I'm not gonna contribute. Right? They know every know piece of Lin knows code running on my server.
I mean, look, I, I've, I've covered the open source business models for 20 Mitchell knows 25 years. The fact of the matter is, if you're very lucky, 3% of the people who play with your code and open source will at least report a bug, right? Most open source projects you could count on two hands may be one foot.
The amount of people who actually contribute code to an open source project except the biggest, biggest, biggest open source projects that that's the nature of this beast. Plain and simple. And so, and, and you're okay with it.
I guess that's how it is. And, and I'm okay with it because these are passion projects for people or they are building the name for themselves, or they are practicing or they're getting something out of it. They're definitely paying, they're paying in their time at least time.
Sweat and toil, if not in money. Well, a lot of people have mo case Contribution. Yeah.
Mm-hmm. I mean, You know, and the only reason I said it's more complicated, Alan, is because, uh, public institutions as well as lots of private commercial ones are paying salaries if, maybe not bonuses or things like that, but they're paying salaries for people to spend all of their time contributing to open source. And so those people's jobs and their salary and their career advancement Is based on well, so that, that's a relatively recent, so I, I've spoken about it before, but here's the deal.
You had To, so I'm saying it's changed. Yeah, Go ahead. No, it hasn't.
So under Richard Stallman in that era of open source, kind of the cathedral and the bizarre, like the book, it was, it was very much wild westy and more power to the man down with the pigs, all that stuff. Then you had this big brother era of open source where you had like IBM supporting some great projects and you know, basically an open source project had a benefactor. It was kinda like Renaissance Europe, right?
Every artist had a benefactor who paid and really managed that open source project, but also did it for their own material benefit. And in many of those cases, the code contribution was by paid employees at an IBM or, or what have you. Then we moved into like the foundational era of open source, which is kind of where we are now.
We have like Linux Foundation, CNCF, eclipse Foundation, you know, who they have coopetition between competitors who are all contributing to that open source and it, and it kind of makes it an even C and then you jump off from there, right? Um, there are plenty of companies who contribute full-time and not all IBMers too. I mean, you look company like Linker DA big mesh in CNCF, they, they, they support that project with full-time people.
They also have a better, a commercial business built around it. I think Sauna types the same kind of situation. So there's two ways to think about this.
One is they could just give this to some consortium and let them figure out the cost of hosting all this. Aaron b maybe they just need a better tax attorney to write this thing off, You know, Sonatype. So look, so, so Sonatype is a PE owned company.
They're, they're a private equity owned company. Yeah. There go, I think got good tax accountants.
There you go. And that's why they're watching the pennies too. But I, I think that the key here is they probably need to put a toll booth at the door of the repo.
Well, so, so one, one second. Now just one, uh, fly in that ointment, let's say, which is this trillion dollar company. There's no reason they can't do, you know, uh, um, fire firewall like inside the DMZ or DMZ based caching, right?
They're just, they're not doing that. Who this is carrying, so You mean No, no, not Sonatype's. A trillion dollar company that's doing a thousand.
Why? Okay, What my point is that, um, uh, that is a, a different, so there, there, I think the fear here, I've been wanting to say this, the fear here is that rapacious capitalists are gonna go in and just say, wow, free stuff. Go grab it, make a few twiddles, and then, you know, hey, it was open source.
You know, know that's capitalism. Yeah, that's been true. No, No, no, I agree.
I agree. Change, change in the market, change in the user base. Change in how open the, the open source market is gonna have a reaction.
We just haven't reached that point. You know what, my political science teacher in St. John's University told me something probably close to 40 years ago.
Now, communism's a great system. If you have a society of atheistic saints, we're not communist, nor are we a society of atheistic saints. If people can get away doing something legally, they will.
Mm-hmm. Here's the flip side of it, you know why Sonotype doesn't put a toll booth in on that repository? Because if they did, someone else will start a new repository And, and be a new center of gravity for Jala.
Yes. And there you go. New center of gravity open source job.
I think they should try the pro model 9 99 a month per user premium access. There you go. I, I'll just, I'll just say, you know, we're not obviously not gonna solve this one right here, but I think Guy, you know, you, you, you know, I we wanted to say the same thing.
Like, we need to recognize what people want and what they're trying to get out of it. And, and, you know, I write open source because I feel like it, I want a dopamine rust. I wanna get some experience.
I want to get my name out there. I wanna get paid, whatever it is, and actually reflect that the systems we have right now, the problems we're having is because we're not always reflecting that, which, you know, Alan, you know, may, you know, may allow certain mechanisms like the normal capitalist, uh, impact to highlight the flaws of the system we're using. So if that stays that way for long term, then I guess that's fine.
But I don't think it is. I think it's a combination of these things that, you know, to, to sound like a broken record allows transparency or for every involves, you know, the consumer and the producer and the, you know, the open source contributors so they can see whether or not it's being handled ethically and make their own choices. And that doesn't exist yet.
Alright, we gotta end, wrap it up, but let me just end it with this thing. What could be next? Socialized medicine You are watching Texture and Guy, we're gonna be back tomorrow with a lot more.
We hope you've enjoyed this, this, uh, episode. As usual, stay tuned for Text Drunk tv. Thank you for joining us on behalf of Gaia Mitchell and Chris and Mike and Kate on her first show.
We hope we didn't scare away with this one. You'll see more of her. This is Alan, we're out.
Hey everyone. Welcome back here to Text Drug tv. I am really happy to be joined by my next guest.
As he pointed out, I don't think we've spoken for a year, a year and a half, maybe more even. Manoj Nir, who I understand is now a neighbor of mine. He's the Chief Innovation Officer at Snyk.
I'm excited to welcome you to the Sunshine State, as they call it. And in the future, Manoj will be doing these in person here with me in the studio. So look forward to that.
Manoj welcome man. How are you? Good, good, Alan, really good to be back talking to you and yes, definitely in person next time.
Good, good, good. So, Manoj, chief Innovation Officer, everybody mixed up a title these days, but we've heard chief innovation Officer before. What's your take, what's your role there at Snyk?
Uh, great question Alan. So I came, I've been here at Snyk for three years, and I came in as the chief product officer. First two years it was all about, you know, the hypergrowth company now getting used by the biggest enterprises in the world.
And so that was the mission. Um, you know, we went from a portfolio, products or platform that Fortune One Down can use us and, and at scale. And so, you know, going back to my entrepreneurial roots, uh, this innovation officer mission is very connected to a lot of the conversations we'll have as we saw this Gen AI wave take off.
What we have done is, you know, we, the, we're gonna talk about our acquisitions, but we have a lot of entrepreneurial CEOs at our company. And so we're incubating, you know, future bets and products, uh, and working very closely with those really big customers as design partners and some of the strategic partners that are investors in Snyk. So we've got this very interesting, you know, triangulation going on between technology partners of the likes of Google, Atlassian, uh, Salesforce, ServiceNow for all investors in Snyk, but now we're getting buil with them.
And then really large customers who are, you know, helping us incubate startups within Snyk to solve some of these next generation of problems. So that's my role. I love It.
Love it. We mentioned snyk. Look, I think most of our audience is familiar with snyk, but you know, this goes out on the internet to a, to the whole tech strong network.
It's on LinkedIn and Facebook and X and YouTube. There might be people watching this that are not familiar with ny. How would you describe NY to them?
Ny. Um, so now, you know, and you'll know soon, it's really simple and it's genesis, you know, for people who spend time in security and have been engineers, they'll understand this, uh, comment I'll make, which is computer science is one of the few engineering professions where safety is not required in the curriculum. And so we're very surprised when there's a lot of vulnerabilities in everything that we're building, and open source and first party code and AI generated code.
They're all kind of feeding off from that foundational issue. The SNYs mission's, very simple, empowered developers with context automation and education right at the moment, right? And so that's been branded with terms like shift left that I think, you know, if you like it, you can credit us.
If you don't like it, don't blame us. But you know that that's the mission we started. Let's move this problem from being a runtime problem that you are always, you know, tall walls and moats around castles.
And instead of that, just go to the root of the problem and imagine the productivity improvement when you're not chasing issues. What if you can prevent issues? So this has been our mission.
We're focused on any company that is building software and applications, which is basically every company now. And, you know, now with our new platform, we're also focused on companies are building their AI software. And so that's the mission.
We are being every layer of an application, all the way from code to open source, to container, to infrastructures code, to the AI stack. We are securing that, but by doing it right at the spot that I think it needs to be done, I love it. So now, you know, I remember that from years and years ago.
Um, so Manoj, I have a confession to make. You're not the only person at NY I talked to, uh, I've developed a relationship with my friend Danny Allen, who's now the CTO there. We've been lucky enough to have Danny come on the show a few times, and he's been telling us a little bit about what's happening at Snyk.
Just I think about two weeks ago, maybe less, he came on and we spoke about this new AI trust platform that Snyk put out there. And it's really, you know, uh, I mean, it it cutting edge, right? Industry leading type of use of AI to help developers to help organizations deploy secure code, secure applications, be more secure using ai.
Mm-hmm. How are on the heels of this, you guys announced today an an acquisition? Tell us about it.
Yeah, I think great. Uh, um, you know, uh, a great connect there and, uh, to what Danny just talked to recently about the Irus platform. And, you know, just think about AI adoption for a second before we even get into snyk.
And, and, and the platform. We see like various stages, uh, of AI adoption, and it depends on organizational maturity. But, you know, just like, uh, you know, but, uh, some 10, 20 years ago, uh, I think Mark Andries said, software is gonna eat the world.
We believe AI is gonna eat software. And it is doing that. We're seeing that, but how does it do it in phases, right?
And so the first phase of AI adoption, especially in the software, um, development realm, seems to be in the use of copilots and various, you know, it's Microsoft GitHub copilot, or the hot new agent AI coding assistance like Windsurf and cursor and codes being generated using these LLMs and Gen ai. But a lot of that code is trained on, you know, vulnerable code. That's basically what most of the open source code out there between that and the nature of hallucination of, you know, which is part of the magic of LLMs.
There's also security issues with these. And so our first starting point was, I would call it the, the, this January after the chat GPT December, 2023, we started. And, and some of these very large organizations started calling us saying, can you be the guardrail?
Those who knew about this? Now everyone does. Now there's a Georgetown study that says there's 40% of the code is insecure, or Stanford, or all these organizations have studied and researched this so much more well-known problem.
And so the pillar one was really about how do we make sure that the guardrails are put? Because you cannot just be productive without security. In fact, it'll, it'll have an opposite effect that you're just generating a lot of insecure code and it's going out and, um, you know, we are having to fix it after the fact is the opposite of productivity.
So that's one of the pillars. And the next pillar now that we're seeing is organizations are going, you know, those who have successfully done that phase are about to go about building AI native software. They're building AI software themselves.
It could be a, a front end, you know, agent if you're a hotel or a bank, these agents are now showing up in external facing applications to drive a lot more productivity for these companies. And so that's that next pillar in our AI trust platform that we launched was across all these pillars, it was us using AI to accelerate our original mission. DevSecOps, how can we automate actually fix issues?
So we have AI fix, we have an assisted agent fix. Uh, we were doing things like prioritization and reachability using our AI techniques. So it was just accelerating that DevSecOps mission.
Well, we started talking about this next phase. We showed examples, demos, things like our AI security, posture management were directly targeted at that next pillar. And that next pillar, you have to start with visibility.
I've been in conversations, you know, you sit down with the CISO and go, you know, how many, uh, um, apps are you using? Uh, or how many models and agents are you using? And the answer is, you know, not many.
And then you talk to the engineering teams and they'll go thousands. And so CISOs and security professionals, you know, if they're not able to see what's there, they're not able to give instructions and guardrails and governance. So we started with visibility, and then we started looking at what else could be done.
And that brings us to the acquisition, right? What we saw with the visibility phase was a lot of, you know, what do I do next questions. So I found people using agents, is this secure or is it insecure?
And so that's the context. We've been working on it as part of that launch. And today we're able to announce to, to the world that we acquired in Variant Labs, that's really going to accelerate that AI trust platform.
So hopefully that journey on this whole AI mission, you know, now gives you more context. Absolutely. Absolutely.
com days. I was part of a, I helped build a company that we did 30 acquisitions in 36 months, almost one a month. We got good at it after a while.
But, you know, all kidding aside, acquiring a company is sometimes just the first step, not the last step. Learning how to integrate that company, how to not have brain drain, how to take the IP and, and make it sneak aerify it, if you will, right? Is is a talent and skillset unto itself Very much.
Now, as I said, this is your 12th acquisition. It's not like you haven't done this before, but when do you think the invariant know-how IP expertise finds its way onto this AI trust platform? Great question.
Um, we have, uh, something as part of our AI trust platform also launched something called Snyk Labs. io, what we started is started doing our incubations in a very public design partnership mode that we show, here's what we're building, here's the research. We're also doing research on these new threats because, you know, the problems with AgTech AI and, uh, you know, gen ai, I can say non-deterministic till I'm blue in the face, but you know, that doesn't mean people understand that.
So part of what we will do is bring in variant into that SNE Labs umbrella and start, and then, you know, they're very much research minded. They're the leading researchers, I would say, as we looked around in this very specific domain about what security risks exist for AgTech AI usage. And so we'll continue that research mode.
So there's immediate value that customers and the world actually gets us. We will amplify their research and accelerate those research findings because we're still, the world's still figuring out what these risks are. For example, in Variant Labs team was the one who found this term called tool poisoning.
You know, how do you use agent AI and model context protocol to go and poison that gives the AI supply chain risk now? And so those kinds of research is super important, so that that continues without a pause. In fact, it gets amplified under the Snyk Labs umbrella, and then there's technology solutions that they started building.
Part of what we're doing with Labs is, as I've mentioned, these very large design partner customers of ours, we actually talk to them as part of the acquisition process. So these are very trusted customers. We'll tell them, look, what pain points are you having?
We're seeing this. We think this is important. Are you deploying agents in, in production?
So they're already expecting to now try out some of this tech and harden it and get it ready for the enterprise? And so we think all of that is the, by the end of this year, you know, these customers would've given their feedback, and now we would've incorporated that sneaky fight it. I love that.
I think you've been talking to Danny Allen. So, uh, uh, we do that too in parallel and get it in the hands of customers, you know, sometime later this year. Fantastic.
But no, we're about outta time 15 minutes ago, so quickly here, but I am, uh, first of all, congratulations to you and the whole Snyk team as well as to the Inva Labs team as well. com the, the chairman of the board was this gentleman, Len Fassler. He was the mentor to a guy named Brad Feld.
Brad's a very well known venture back guy, one of the co-founders of, uh, Techstars and stuff like that. But Len used to say something to every company, I'd go with him when we'd close, you know, handshake on the deal, and he'd say, look, be very proud of yourself if you built something that someone's willing to write you a check. 'cause they value what you built like that, you, you should be very proud of yourself.
So congratulations to the Invariant Labs people as well. Next time my friend, we're here in person talking about these things. Maybe we'll invite Danny, maybe we won't.
Who knows if he'll be here. But, uh, thank you for coming on and, and telling us about this key acquisition building on this whole AI trust platform. You, you reminded me one last thing, Alan, this I, you know, this is probably my 20th m and a in my career on either side of it, being acquired, Uhhuh requiring, and you know, absolutely Mark and Luca and then Variant Labs team and the research professors that they spun out backing them.
Major kudos to them. This is probably the most hotly contested acquisition in, in, in my entire career. We had come the trillion dollar plus market cap, you know, trying to chase these guys.
So partly they also picked Sneak for all the things we talked about. And that is very, very, And that's what makes a good fit. Yes, sometimes it's not, you know, the early money isn't the smart money sometimes when it comes to these things.
I, I, like you, I've been on both sides. I've been lucky enough to been acquired, you know, had a few, uh, exits like that and then done acquisitions. That's what keeps it interesting.
What can I tell you? Osh again, thank you. Thank you.
We'll be in touch. Good luck to sneak in every, all our, all our friends there. Thanks, Alan.
Talk soon. Alright, Manoj, NIR, chief Innovation Officer, sneak here on Tech Drunk tv. We're gonna take a break.
We'll be back. Hey, everybody. We're back at the Open Source summit here in Denver, and we're talking about, well, WordPress.
And there's this whole initiative called Fairness. It's, um, I guess a package that we're gonna use to kind of bring the notion of open source more fully and deeply into that community. It's always been open source driven, but we have Yost and Kareem here, and they're gonna explain what's going on.
Yost, what exactly is the fairness package and, and what are we trying to achieve here? org. org to get updates of WordPress itself, themes, plugins, translations, whatever you get in your, in your site that is dynamic.
org with another system, our federated and independent repositories, FAIR Fair. Um, these repositories can be hosted by anyone, by a host, by a large company that wants it to run one internally by a university that wants to run one, because they're, they wanna be nice to the world. Um, by doing that, we basically change how we distribute WordPress by getting it instead of from one source.
We get it from a lot of sources. And by federating those sources together, we make sure that if WordPress the org were to decide to block a host from accessing WordPress org, which unfortunately happened in the end of last year, we can then route around that and, and basically prevent that from happening. Kind of sounds like a peer network in some level.
It, It is very much like the internet. It needs to route around anything that breaks. Yeah.
Yeah. Kareem, explain to the folks at home, what's the backstory and why do we need this? What's going on?
'cause not everybody is deeply immersed in the WordPress. You'd be surprised. Yeah.
So what a lot of people don't realize is WordPress is 22 years old and powers more than 40% of the websites on the internet. So that is pretty long in the tooth. And what ends up happening is this infrastructure that Yos was just talking about serves so many things, not just updates, but also the things that extend WordPress.
And over the last years, this system has been neglected, and it hasn't been kept up to date as it should. And it's a centralized one point of failure system that was already a technical problem that at some point was gonna be needing to be addressed. org decided to block one of their major competitors from being able to get access to any of these updates.
And to be clear, WordPress won't work long term without being able to be updated and without being able to have these extensions and themes plugged into it. So that was already one spot where it's like, okay, maybe two commercial open source project companies are going to have a little bit of a commercial fight. Fine, we all took a step back and just waited a little while.
org decided to actually replace one commercial module with another one and fork it replacing somebody else's code. So you have a classic supply chain security issue. My day-to-day job is working with Enterprise f Fortune 50, fortune 500 clients.
And those clients were saying, this is unacceptable. org didn't announce that they were gonna change out the code and just did it. You'd have changes on 40% of the word, uh, of the possible internet without anybody knowing anything.
No check and balance, no transparency. org, try to see if we could work together, and they decided they wanted to sort of not work with us at the moment and see where they could go in a different direction. Um, so a group of groups got together and started thinking about how to solve the second problem.
And then the second problem is that the distribution for all of WordPress is done by hosting companies. org, by putting up their own independent mirrors, what ends up happening very quickly is architectural drift. And then you have the entire ecosystem starting to segment and fall apart.
Alright, so this was basically, we started writing code in January. This was a six month sprint to get out a proof of concept that could show that we could federate this like an old peer-to-peer network, so to speak, but using the at protocol and, and Blue Skies system, because the alternative would be the balkanization of WordPress Then. Is that what would happen?
Well, it's not just balkanization. I think there's a, there, there are quite a few things that play into each other here. On the one hand, we have one entity controlling WordPress, Oregon using it to how he sees fit and, and, and his whims.
Um, on the other hand, we have a wider ecosystem that needs to rely on on that and actually needs to rely on it for corporates, but also for hosts wanting to install new WordPress sites. And if that site goes down for 10 minutes, then 10 minutes long, they can't sell any new WordPress sites. It's as stupid as that.
And this honestly happened too much and too many. And so a lot of people in the ecosystem were saying, okay, we're not happy with how all of this is going. Let's fix that.
And then we came up with fair and we started building. And then as we started building, we also realized that there was way more that we could do in what we were fixing. So FAIR doesn't just federate these repositories and remove that supply chain security risk.
It actually also adds more tech new technology to improve the security of the supply chain. So we've never had code signing and WordPress for plugins and themes, and now we do. org.
If they were hosted elsewhere, you could not find them by searching in the WP admin. Now you can. So there is a lot that we can do for the betterment of the wider ecosystem that actually allows us to, to make the ecosystem more resilient.
And it allows us to allow for more innovation and economic growth in that ecosystem. And all of that combined led us to, Hey, this, this feels like a very good idea. So we were talking it through and then we were like, okay, the next step is now we need governance for this idea because we are replacing one entity.
We can't replace them with one other entity. Um, and that's when we came to the Lennox Foundation. Mm-hmm.
And they were actually very helpful. WordPress Has famously been very independent and in their own little community, and they haven't really, the entire community there hasn't really interacted with a lot of other open source projects. So the idea of how the Lennox Foundation creates checks and balances and has transparent governance is something that's new to the WordPress ecosystem.
Mm-hmm. So how much of this is about, uh, money and commercialization, and how much of this is about egos and, and, and So I, I think on our side, it is very much about wanting to make sure that WordPresses is, remains the best c open source CMS available for the next 20 years. Um, I've founded a company myself, uh, called Yost, uh, Yost, SEO plugin for WordPress, sold that in 2021, I've made my money, I feel sort of obligated to the community to make sure that I help keep it alive and, and, and help it stay healthy.
Um, And there's a, there's a history in open source of content management systems, e-commerce systems of them starting out in the best possible idea of open source. But then the companies behind them get into the same old necessary bell curve of funding where they have to start privatizing certain things and creating choke points. And we're at a point with the WordPress ecosystem with 40% of the web, with how many, what, 20,000 new sites a day that we're at a point where it needs to evolve to be truly open source, where not any one company can steer it, because that's gonna just end up killing it.
Like I could name five other CMSs or e-commerce systems that have died in the last 10 years because of the same trajectory. Can a federation succeed? 'cause there are those folks who say, you know, by definition, open source requires a benevolent dictator.
I don't believe that for a minute. Mm-hmm. Um, one of the things that surprised me as we went into this process was we were talking to all these hosts and I was asking of them, why aren't you contributing to the WordPress project more?
And their reply was because nobody asked us. And it turns out that most of them are very willing. I've started drawing the comparison to ICAN, where pretty much all hosts do a lot of work for and, and pay pay for ICAN and WordPress is just as important to their business.
And they're very willing to do things there. They just don't know how. They just, they don't even know that it's necessary.
There's no process And there's no process. And I think we can fix that. And, and then actually, yes, I do believe that we can make this federation work.
Mm-hmm. Full disclosure, all of the tech strong sites are running on WordPress. Um, and we're in that almost every day.
And we all go home with the same feeling. We enjoy the CMS and it does what it does. But sure, it feels manual and it feels like there's a lot of heavy lifting and a lot of, and a a lot more could be automated.
So, you know, for all the people out there who work in WordPress every day, what can we look forward to to kind of streamline this experience? Well, that's, that's one of the big things that needs to be worked on. Next is onboarding and the ease for the end and the end users.
It's been a little bit of a inside baseball, sort of WordPress centric, um, way of thinking of what the roadmap could be. And frankly, it's been only planned a year at a time besides the, the block editor that they've been working on for the last seven years. 3, and we've already got code in that changes how you're looking at your plugin repository.
I have a, what plugins you have in your site, we're looking at making sure that you can see which plugins, um, no longer being updated. We like, there's no automation, there's no, there's no notification. And WordPress, if somebody's abandoned a plugin you're using, and that needs to be fixed because the last thing you and your sites wanna do is spend your time trying to figure out why something isn't working any longer and what happened to that plugin.
We also used Yost, by the way. Um, one of the other questions that comes up though, is a lot of people have built their careers around WordPress and, and, and they are cautious about any kind of dissension. Or they'll look at it and they'll go, is is the thing I based my career on fragmenting underneath my feet?
Or can they continue to do what they do? But all of this will be happening in a way that is transparent to them. I, we did this the way we did it precisely for that, for that group because we didn't want to fragment a community and because we wanted to offer them an, a view of what could be and also offer a path forward for everybody, including automatic WP engine, all the, all the people that are, that are sometimes at war, um, where we could all together move forward.
Whether we succeed at that, I dunno, I honestly don't know. I would like to, to hope so, but it's gonna be a challenge. But I, but the whole, the whole plan is to bring all of those people along and to make it easy for everyone to see that this can happen and do it transparently for the end, for the end user.
Because honestly, if we installed fair in your site, if you looked at your plugin screen, you'd see it, and otherwise you probably wouldn't see it. Um, this morning, um, during the keynotes, Steven from, uh, I believe Harvard Business School, the Economist was saying on his way to MIT yeah, on his way to MIT, um, was saying that we need to focus on collaborating on the core and competing around the edges in the WordPress ecosystem, the core has been the domain of one company and one individual. And you could volunteer your time as long as you did it around that roadmap and around the edges where we should all be competing.
It was basically trying to figure out what's going to be next. This is an opportunity to collaborate on the core and then be able to focus on creating a wider edge, because we've got 70,000 plugins that are for free in the repository right now. There's at least five, 10,000 plugins that are paid that are very good out there.
And the ecosystem has a space to evolve with the, the latest hottest trends of AI and anything else you wanna talk about in technology. But we need to create the room for that ecosystem to evolve and grow. Folks, I'm not gonna tell you who's right or who's wrong, but I will tell you this, I have noticed a trend over the years.
Anytime there's more companies than entities contributing to something, the pace of innovation's a whole lot faster. Gentlemen, thanks for being on the show. Thank you.
Thank you for having Us. Thanks again. Hey, everybody.
We're back at the Open Source software summit in Denver, and we're talking with two folks from Amazon Web Services. We have Dave Nally, who's the head of developer advocacy for AWS, and Anja Bart, who's the lead developer advocate for AWS. And we're having a little chat about what's going on at the show, and there's been some big news around the Linux Foundation has now set up a project around the agent to agent protocol, and that seems to be complimentary to MCP and AWS is kind of in the lead in both of these.
But Dave, start us out here. What's going on here and, and why are you guys involved in this project? You know, so first of all, uh, I think it's really interesting that we're in this period of, uh, a agentic ai, uh, SRA was telling me earlier that she read someone who had said that we're now in the decade of ag agentic ai.
And, and so as we think about agents starting to work, uh, they need ways to connect, hopefully programmatic, uh, protocols to use to connect to both tools and to connect to other agents, uh, so that they can share work and they can pass work off, uh, one another. So we look at, uh, we look at things like the A two A announcement today, and we think that that's actually showing us a maturation, uh, both around the protocol itself, but also that the industry at large is, uh, recognizing a need to have, uh, to have a standardized protocol for communication. So I think this is a, a necessary step in one of those foundational pieces of technology that helps us drive innovation faster.
Uh, we're, we, were super excited to see the announcement and we, we of course participated and we've got folks, uh, we've got employees who are set up to contribute to the project. We have a member of the steering committee, uh, employed at AWS as well. Uh, but we see a two A is one of the, one of the future standards that's going to come to play as agents have to talk, uh, between other agents.
You might have some insights into this, but there's a little confusion about what to use A two A for and what to use MCP for. And so in your mind, how should developers be perceiving these things, Right? And as developers, you're gonna start out building an agent, right?
So you're gonna start, and then the first thing you do usually is like connecting the agent to, let's say, a tool. And this is like at the core where MCP started, right? Like connecting the models with tools that could be like either data sources in your company that could be specific APIs or systems to call actions to take.
So this is where MCP started out. And then once you're building another agent and you want the agents to kind of, you know, act in a multi-agent system, then there's the need to have those communicated. And this is where a two A comes into place.
We do see potential in both protocols to do, solve a lot of those tasks. And this is, I think, exciting to see where the community will get involved and where those protocols will evolve as well. And we're excited to be part of that community as well and help drive.
I feel like when I've put those two things together, I'm kind of looking at, uh, pieces of a, of a larger orchestration framework for agents and how I interact with tools. So as, as this whole area evolves, how should developers be thinking about all of this? And how do I orchestrate not just the tools that I need to invoke for one agent, but also how agents talk to each other to automate a task on an end-to-end basis, if that makes sense?
Yeah, I, So I, I think back to the Unix philosophy of having one tool, small tool that does one job really, really well. And that resonates a lot with me, mainly because I'm old and I, I remember doing lots of things with unes, uh, but I, I think today, uh, you know, we've got MCP, which is a really simple way to connect tools, uh, to agents. And then we've got a two a when you need to do things like discovery of what capabilities an agent might have so that you can figure out where to pass, what kind of work off too.
Uh, and I think, you know, some of that's forward looking, but, uh, you know, they're still very, uh, very separate workloads at the moment. I also think back to the early days of the web, right? So to actually load a webpage on your local web browser, you need more than HTTP, right?
The hypertext transport protocol does allow you to ship bits and, and render, uh, render a page, uh, onto a browser. But you also need HTML as a standard, as the market language, as H TT P is your transport protocol. You need DNS in there, uh, to, to get you to the point.
And so I, I think we're probably going to see multiple tools. I don't, my personal belief is I'm not sure that there's going to be one tool to rule them all for all of these agent interconnections, uh, both agent to agent and agent to tool at at least I don't see that on the horizon today. How will the nature of the job of a developer change in this era?
Because I wonder, you know, we've been building artifacts forever, are agents the new artifact and they talk to the lower level artifacts, and it's another level of abstraction. How should I think about this as a developer, Right? I think like, to, to add what David said, we've been working in, in the technology space and we're building microservices, we're building web services, right?
For, for the past decade. And this is kind of moving those services into agent services. And not all of that is brand new, right?
Like, especially around how do we deploy those in a serverless fashion, how to deploy those, you know, in a secure API endpoint fashion. So I think there's a lot of things we can learn from the work we've done and then also learn the new skills. So as a developer starting in the field, definitely it's, it's important to kind of understand how agentic systems work and then also apply the knowledge you might already have from things you've been building before, right?
So I think it all will come and converge together in a way. At AWS we released, for example, um, the strands agents, SDKA few weeks ago, which is an open source SDK to build agents really, really easy. And we're doing that very, looking at the models that have become so capable, the reasoning capabilities that can perform a lot of things.
So as you're starting building agentic systems, look at those tools available and then combine them with the knowledge you have to help move from, you know, building your applications from the traditional microservices way into kind of the agentic way. Mm-hmm. Can I argue with you for a minute?
Sure. Why not? So, uh, I, I'm old, uh, and, and I remember lots of conversations talking about how software development was gonna change, uh, four Gls baby.
Yeah. I, I, I mean, I'm not quite old enough to remember punch cards, but I, I remember mainframes and I remember people writing an assembly and, uh, we don't do that anymore. And that most of us don't do that anymore, I should say.
There, there are still people doing that. We've had tools that have sped us up, and one of those was, we actually got programming languages that abstracted away, uh, then we got higher level programming languages like Java that would automate garbage collection for us. Uh, and so we, we stopped having to do one class of work, which was memory management effectively.
Uh, then we got, uh, we got runtime and object-oriented languages that again, sped us up. Uh, I see, I see all of this changing the developer's lifecycle in that it's going to speed them up, and it's probably going to abstract away a lot of the work that they're doing. But I don't think developers are going away.
Uh, I, I, I think that they are going to end up working much faster than they could when they were writing assembly. But, uh, at the end of the day, this is just another obs abstraction layer. Some folks would say that we're gonna spend a lot less time writing code and more time reading code that might be created by a machine, and that will change the nature of the developer's job.
And some folks are, um, they, they have a, they're a little anxious about that, and other folks are like, great, 'cause I hated writing code in the first place. But, so, you know, as, as my day-to-day experience as a developer, how will that change, do you think? I think developers will still write code because this is what excites us, right?
We wanna build things, we wanna break things, we wanna test out things. So I think that part will still be there. But I do think that AI in general and energetic AI will help us be more, you know, kind of, for some people they don't wanna write documentation, others might, might be excited about it, right?
So I think each of us will find ways where they can use AI to just, you know, tap into the parts they enjoy doing and automate the parts they don't necessarily enjoy doing. So I think it's more of an augmentation, but it's new skills I think that every one of us has to learn, like how to work with those tools efficiently and then effectively as well. And then I think it's really becoming this kind of a team effort, right?
Like you have your AI that helps you do things also like maybe researching things, right? You, you send the AI agent out, maybe you wanna explore a new language to learn, and you're using the AI as kind of, you know, kind of a peer to help you learn the coding, learn the new language. So it's, it's tapping into, yes, automating some parts, which I might not wanna do every day, but also helping me to learn and be much faster in, in learning new things as well.
I remember a quote, I forgot the woman's name, but they interviewed her and she said, I don't want AI that creates art. I want AI that cleans the kitchen so I can create art. And to your point, will each person kind of approach this somewhat differently?
'cause there are things that I don't like doing and others do like doing, and each person and each developer will find the right mix for themselves as to what they wanna do and not do. I, I, I certainly think that is, uh, the way this is going to at least initially shake out. Uh, I think, I think there are still folks who, for instance, enjoy writing C code.
A number of those might happen to be at this conference, and that's still a valuable skill. Uh, there are other folks who can't imagine managing memory for themselves and don't want the fact that it's so error prone to, to enter in. And so I, I fully expect that we will see a lot of folks gravitate towards the things that they enjoy doing and accelerate the things that they don't, or automate away the things that they don't.
I, the, the core tenant of most developers is that they're lazy. And, and I don't say that pejoratively like, I am lazy. I want things to just work as efficiently as possible.
And so we tend to, we tend to automate away the boring things, and I think people are absolutely going to use AI to automate away the things that board them. I have talked to a number of younger developers and older developers, and it's funny to listen to them because the younger developers will say, this is great. I don't have to become an expert in that, and I can get this done and I'll do it myself, and this will be awesome.
And the OLA developer saying, this will be awesome. I don't need all these young kids to assign 'em stupid little things to do, and I'll just do it myself. Are they both right?
I think it's playing into the same thing, right? I think on one hand, AI enables also so many more people to build that might not necessarily have that software engineering background, right? And, and put ideas into life, and like startups being much more like quickly in developing prototypes and experimenting with things.
So I do think there, there is space of, for both, right? Like the younger generations might explore things faster and, and, and might like to the point, like they will do what excites them. And similarly, you know, for people that have been coding and they happen in the industry for some, some time they find different spaces and maybe they, they wanna tap into a different area, they wanna automate some things.
But I think it all converges to, to what David said, right? Like, they will find the space where they see the value of ai. And I, I'm convinced, um, this will shake out.
Yeah, To her point, we've been talking about the rise of citizen developers for a long time now, and, um, you know, the criticism has been, well, you know, on the one hand it's great, they can build software and they don't need all that interaction with a professional developer. On the other hand, it says, you know, the UI experience is usually limited. It won't scale, and it's perfectly insecure.
But other than that, it's great. Um, what will be the dividing line between citizen developers and professional developers in the age of ai? And how do you think that that will all come together?
Well, I, I do think that there remains no shortcut for experience, and that there are a lot of lessons learned that, uh, that we will have to, um, continue to learn by actually running things and operating things. I, I don't think that's going away. Uh, I, I do think though that this is, again, another one of those abstraction layers.
And you know, we, we've had this before. There are a number of folks who never learned, uh, assembly, they never learned c maybe they started out with their first language being PHP or Visual Basic. They still delivered value.
And I think at the end of the day, we, we tend to gate keep quite a bit and say, you know, if you're a visual basic developer, you're not a real developer. A real developer uses bi or maybe they use emax and they, they write and see. And if, if you're not one of those, then you're not a real developer.
Uh, so, you know, in many ways this is not new. Uh, there are things, they're definitely going to be challenges with scaling. There's definitely gonna be challenges with resilience, and there is no shortcut for being able to learn those regardless of the language or the tools or the AI that you're using.
Um, and, and so I don't, I don't think that AI is necessarily going to solve all of those problems, but it will make you faster at learning them. This is a theoretical conversation, but there are some folks who say, well, we invented Java and all these other languages to provide a way for humans to talk to machines. But if AI is gonna develop software in the future, won't wanna programming language that is tuned more for AI and not for humans, and then all we need to do is just find a way to explain what the machine did to humans, rather than using something like Java, which was built for another construct in another era.
Is that a possibility? It's hard to look into the future. Of course, right now it will happen.
I think at this point in time where we are, we're, we're taking a step, like we're optimizing a lot for, for the user right now, like being able to use natural language to work with systems. I think it's hard to tell on the systems part. I, I do think there is still some formal logic needed also.
Like, you know, we will have human in the loop. We will have people reviewing code still. So I do think there is still this value in, in learning programmatic languages and then developing ways to, you know, have humans verify and have a human in the loop for specific things.
So I dunno, I I actually think, do you have, I I actually think it's changed the, uh, the constraint a little bit. Uh, I think, uh, you were talking earlier about, uh, being able to recode being a very valuable, uh, talent. And I think that that's probably true.
I think the constraint has moved a little bit from, uh, how fast can we, can we produce code to how fast can we review code? And certainly in the open source ecosystem, and we've got, we've got maintainers who are drowning in their responsibilities to review the code that's coming in. And, uh, in many ways I think that's, that's the struggle and the problem that we've gotta solve next is how do we get people confident to review the code that's being produced and able to, to sign off on it and, and keep up with the flood of code that's being created so quickly, Which hopefully another AI agent will have revered before I reviewed it.
So then that way at Least maybe so, yes. Okay. Yeah.
So they say, and we will build more software in the next two to five years than we have built in the past decade by several orders of magnitude. Is that what's gonna happen? I mean, is the volume of software that we're about to create gonna be that exponentially greater?
Or, you know, are there still fundamental constraints that have to be worked through? Because, you know, there's more to building software than just writing code, Right? I do think we will see an explosion in this first step of like, people trying out ideas, building prototypes, experimenting really fast.
But as we move those projects that are successful into the production stage, I do think this will still shake out most likely like we see today, right? Like we need to productionize software. But I do think there will be a larger amount of like just experimentation, which is exciting, which potentially plays out, you know, like we have some really great projects then that are moving into, you know, this world being like maybe complete new ways of doing things, right?
We see a gen AI being applied to, to new ways, like doing research for us and, and kind of coming up with new ways of doing things versus, you know, type of like the first wave where it's kind of automating internal business processes, et cetera. So I do think there's a fair mix of that, but I do think there is gonna be an explosion and really kind of the diversity of ideas to try out where we see this code grow. So you have become the spokesman for the older generation by self-appointed.
Um, what is your best advice to those developers who have been at this for a while and they have certain biases about how they build code and a certain amount of pride for that matter, and as, as they approach the AI era, what should they be thinking about? Well, I, I think number one, I would say be experimenting. There's a lot of cool tech out there right now.
Uh, you know, if I were, if I were going to be prescriptive about it, I'd say you need to be thinking not just about AI and generative ai, but right now you should go look at agents. You should try and build an agent. Uh, I personally, I know I'm biased.
com, uh, to, to go build your first agent. And, uh, I think that's a simple, really, uh, low effort way to build something that will work. And so build an agent, go use MCP to connect that to some data sources.
Uh, and there's, there's scores or hundreds of MCP servers to connect to virtually any tool you can imagine. So figure out how to, how to use your agents to get access to tools, uh, and to data sources. And then start looking at A two A and connect your first agent to a second agent and figure out how they communicate and how they discover about each other.
Uh, I don't think that people are well-served by ignoring, uh, all of this change that's going on around. I think the change is coming and, and it's moving really fast. There's some really fun technology to play with.
And I say start playing with it. You know, you may not, you may not, uh, you may not find everything works for your particular personal style, but I bet you'll find something that actually makes, uh, your life a little bit better along the way. Same question, but you get to represent the younger generation.
What's your best advice to them in terms of how they approach this whole thing? Listen To the experience developers too, right? No, I think it's really about also learning from each other, right?
I do think people that are excited about this space, not just generational, but like people that might just be more hesitant and not necessarily immediately seeing value for themselves. Let's have a conversation, right? Let's all come together in the community, let's share what we're building, what we're working on, and keep the dialogue.
I think this is important to just, you know, show the rest that might still be looking at where to start. Show them ways, invite them in, and let's build together and learn together. All right, folks, you heard in here, Hey, at the end of the day, building software, it's about solving problems.
So go find an interesting problem and solve it. Thanks guys for being on the show. Thanks for having us.
Thank you so much for having us. All right, we'll be back in a minute. Hey guys.
Thanks Withrow. We're here with Scott Ts, who's general manager for the Infrastructure Solutions Group at Lenovo. And we're talking about how new regulations are being applied to the way energy is consumed in data centers, most notably in California and probably New York, and heck and a lot of other places around the world.
Scott, welcome to show. Thank you very much, Mike. It's really good to be here with you.
Thanks for having me. Data center folks like things to be consistent and when they're not, they get a little boogie and well, there's change in the air and there's a lot of requirements now around energy, and it's not always clear to me that that was always at the top of everybody's mind, no matter how much we talked about sustainability and ease recent years, but now increasingly it's gonna be a compliance mandate. How do the folks who run data centers kind of wrap their heads around that and get prepared for that?
Because there's slightly different nuances, I imagine, in all these different regulations. Yeah, You know, we're, we're talking about New York and California 'cause we're, you know, we're here based in the us but this is not new. We've been seeing these kinds of rules come out.
The European union's been working on it for quite some time. Germany probably one of the leading, you know, players around the world that's been focused on how you drive a more energy efficient infrastructure for, for around it. Uh, so we're, you know, we're catching up here a little bit, so I, I kind of welcome like some of this new rulings outta New York and California because look, um, all this power that these data center use, um, to generate all that power, it does it, it's burning fossil fuel.
That means we're, we've got a carbon impact on the environment. Uh, so it, it does have, you know, a direct impact on the planet. Um, in addition to that though, it's also a big part of the, a company's bottom line.
Um, power is getting more and more costly every single year. And if you can save on power and save on your energy bill while simultaneously making a big impact in a, in a good way on the environment, it's goodness. And I think that's good behavior that we should try to, you know, we should try to push as much as we can.
It seems like there's three aspects to this. One is a lot of the folks are running older servers that probably are not nearly as energy efficient as they could be and certainly don't perform as well as they probably could. So, um, how many folks are kinda kind of upgrading server and storage systems because of these regulations and for that matter, are they running a little behind schedule?
Yeah, you know, I, I think Mike, what's, what's driving a lot of the focus, let's start with the focus, if you don't mind, on why we're seeing these rules. It's like, you know, all the new IT that's going into place that's running high performance computing and artificial intelligence is doing amazing things. I mean, when I think of some of the goodness that we get out of our HPC systems like hurricane prediction, things like that, knowing where hurricane's gonna land five days in advance, you know, that was unheard of a decade ago.
We can do that now thanks to it. But it is power intensive. It's very power consuming and, you know, AI is, is driving a great deal of power.
As we're building out these initial kind of AI systems, we're sort of brute forcing all this advancement we're making in ai. And it's, it's meaning a lot of power consumption and it's put a lot of local towns who, municipalities that have limited amounts of power resources, it's kind of put 'em back a little bit and they're trying to figure out how they react to it. So it's not only the companies themselves, but it's the local, it's the local areas, you know, data centers.
Everyone would like to have a data center, you know, in their area, but it does consume a great deal of power, making sure we're managing the powers efficiently as we possibly can. It's, it's a really big deal. And if you think about most data centers today, most of 'em are aircooled about half the power that goes to that data center is, is, is likely not going to running the it itself, it's going to running things like air conditioning and air handlers and these inefficient devices that we can make big improvements on.
So again, we, we sort of welcome the, the increased focus and I view it as a necessity for the future 'cause we're just not generating enough power and we're definitely not generating enough green power for the demands that we see coming down the, coming down the road. And to your point, it would seem like there's opportunities to improve the distribution of electricity within the data center as well to make that more efficient. Is that something we're need to be thinking about?
Yeah, I think, you know, we're gonna have to rethink a little bit of everything of how the data center, how the data center functions. You know, today the, you know, we, we bring in traditional high voltage power, we convert it down to something more like we're used to in our homes and try to distribute it that way. There's more efficient ways to do it distributing at, at higher voltages.
That's a, you know, a way to take out a few percent of, you know, losses from energy efficiency losses we see there. I think the bigger, the bigger consumer of power in the data center is just movement of air. Our server environment, our storage device, they all, they all like run on moving of air.
I've gotta get heat away from parts and to do that, I've gotta put fans in my servers. Those fans consume power, then I move the heat out of the server into the data center room and I've gotta get it away from the racks before they overheat the racks that takes air movement. Um, the thing that I think is hidden from most people is how power intensive moving air is.
It's just incredibly power intensive just to move a bulk of air and imagine a data center is moving air constantly 24 hours a day. It adds up to a lot, a lot of power consumption just moving that hot air around, chilling it off, and then pumping it back to those fronts of those racks again. Uh, you look at things like our, our liquid cooling, our Neptune, Lenovo, Neptune liquid cooling.
It's, it's, it's primary focus is to replace all that air movement. And instead of moving massive amounts of air around the building, let's move a small amount of liquid liquid's, much, much better at heat transference. So let's use that medium to get rid of the heat rather than air.
And I think that's our, that's our biggest area that we can really make a big improvement in how data centers operate is rethinking that whole cooling infrastructure. So I'm old enough to remember when data centers were water cooled and there was pipes everywhere. So is this kind of back to the future?
Yeah, it's, uh, kind of funny. I, you know, we like to think we're reinventing the wheel all the time, but maybe it's just a better looking wheel. Uh, you, the mainframes had been doing water cooling for the long, long time, to be honest, when we started doing liquid cooling back in 2012, believe it or not, we did our very first warm water cool supercomputer, um, oh, you know, 13 years ago now, believe it or not, um, the engineers that did that for us all came from the mainframe.
Uh, we were all at IBM at the time, and it was IBM mainframe engineers. We borrowed some of 'em, and they helped us design out that first warm water cooling system, because most of the rest were engineers that we were working with at the time. They'd come out of PCs.
And the concept of water and electricity in a PC environment was kind of scary. But for the mainframe folks, it was like, you know, the normal way of doing business. So it, it's kind of a return to, I guess a return to the, to the smart way we started with mainframe.
Mainframe. Are there also things that we can be thinking about to improve the grid itself? 'cause all these data centers are hooked up to some grid somewhere, and the grids are hardly the same everywhere.
There's a lot of uneven distribution here, but it seems like we haven't really upgraded the grid infrastructure in quite sums up. Yeah, that's a man, that's a really, that's a really fun topic to explore, and that one would take us to full time just to talk through that one. But, you know, you think of the complexity of the grid is not only about getting power to where you need it, but it's also the mix of power that customers wanna see today.
So, you know, getting all your, our, your power from coal today, for most, most companies, not an acceptable way to get it. They wanna see a mixture of different types of power. I want, I want renewables as a percentage of that.
I'm fine with some nuclear, I'm fine, a little bit of fossil fuel type fuel, um, power, power generation. But I wanna be able to have predictability in what I'm able to get and what I'm able to access. And then as I start looking towards regulations, a big part of how we're gonna meet those carbon initiatives in that is knowing that we're using some renewable power sources.
Um, that that's gonna be a big way that we're gonna re reduce carbon, even if our power consumption doesn't go down for at least generating that power with a green source like hydro or, or solar. It, it at least minimizes the impact environmentally. And that, that's, I think that's one of the big aims that these, uh, local municipalities are trying to drive, is just making sure as we put these data centers in, they're good for the community, they're good for the environment, and they're good stewards of the limited amount of power that these, uh, these local areas can actually produce and get ahold of.
Do we also need to look at the software that we're running on these machines? Because, you know, at least in my experience, a lot of it isn't very efficient, and it certainly wasn't written with an eye towards reducing the amount of energy that might be required to run it. But I feel like it's overlooked area.
Oh, without a doubt. We are, we're in a pretty magical time, especially when it comes to ai. I mean, we're, we're at the beginning of something really amazing that we're gonna be able to do with this new kind of, it, this new kind of technology.
But there's no doubt whatsoever that we are in the brute force, uh, portion of like the development curve. We're just throwing hardware at these problems. And, you know, it's all in an effort to go build something that we've never been able to build before, but it's not as efficient as as it's gonna be or as it can be.
Um, and, you know, we're, we're doing all we can to kinda lower that barrier of entry so that you can run real powerful AI on any kind of device. You know, one of the things we're, we're, we're big on here at Lenovo is, uh, you know, technology for all, uh, bringing AI to all. Um, and a big part of that is making sure that not everything that runs on AI has gotta be on some super power intensive, you know, uber expensive machine that it can run on things like my Motorola phone right here, or my think pad.
Um, it can run in very lightweight devices, and I can still get super powerful AI out of those devices, even though they're not, you know, massively power consumptive. A big part of that is gonna be the software, the software environment, the ecosystem, the, all the goodness that we get. You know, as you mature, you know, you mature like an it, an IT space.
High performance computing 15, 20 years ago was the same exact way we were throwing hardware at problems not being very, uh, smart about it, not being very elegant in the way we solutioned it out. Now, that's come a long way. We get a lot of work out of very small amount of power and high performance computing environments, and we're gonna see the same thing from ai, but it's gonna take a little while.
It could take as long as a decade actually to really feel good that we've, we've started to be as efficiently as we we could possibly be on the software side. And also, we seem to be a little obsessed with GPUs these days, but I think there's other classes of processors that might be able to run some of those AI workloads a little more energy efficiently, shall we say, or at the very least, maybe even less costly. But, um, do we all understand that or are we still kind of thinking, you know, GPUs was the answer.
What was the question? Yeah, that's, I like the way you put that. It's definitely, yeah, there, there's no doubt GPUs have taken center stage on it because they, they are the devices that have unlocked this potential in.
They're gonna continue to be part of the really big AI that we do, the foundational model creation, you know, that that tier one kind of stuff that the really big players like, like Microsoft, like AWS like, you know, Facebook are doing, that's gonna be at the forefront of what they do as they build out those core models. Now, as we get those models, especially when they're open source pri privatizing those, adding our personal data to them is a much, much lighter weight functionality. In fact, a lot of that can run not only on like a Zon or a Epic processor, but can run on stuff that's much lighter weight than that, an arm ship, something like that.
So that's a big focus that we've got here, is right sizing the IT itself. So that one, it can run the AI the customer needs, but it can also fit where they need it. You know, a lot of the data that we're processing is not in the cloud somewhere.
It's not out in a data center somewhere. It's here in this building like around me. I wanna be able to process that data right here, not have to ship it off some distant data center or some distant cloud, but actually process it right here.
What's being created, um, to do that, I need that. I need that device to fit in the environmentals that I've got, the power envelope that I've got, and I need it to be affordable. And that's a big part of the focus we've got here at Lenovo, is just making that the reality.
So you get powerful ai, but it's, it's, it's achievable and attainable for everybody. So what is your best advice to folks as we look at all these regulations? What should they be thinking about?
How do I kind of future proof my environment? Yeah, I think the first thing is get a good baseline. Uh, that's the biggest guidance I give people all the time.
Our customers is baseline where you're at today, where's your power coming from? How much are you using? Um, start that as a baseline.
There's no magic magic trick. There's no magic bullet that's gonna solve this problem. It's gonna be incremental improvement over and over again.
Uh, but it, but together they can make a pretty significant impact on the amount of power you consume. Uh, so good baselines, a start managing, you know, kind of step by step, how you take it lower and what steps you take is number two. I would say rethink how that data center works.
Don't be afraid to rethink that old air data center. Um, a lot of times we can retrofit ancient data centers with water cooling and make 'em last longer than customers ever thought possible. Instead of like building a brand new data center, let's talk about what we can do with what you've got by converting it from an air cold center to a water cold center.
And people are really surprised how simple it is, how inexpensive it is, and what, how long we can make an older data center infrastructure go. Uh, so I think that's a big part of it. And the last thing I'd say, Mike, is keep in mind that when you do something that's good environmentally, most likely, you're going to also see a business positive impact.
Again, power consumption has CO2 impacts reduce it. Your CO2 goes down, but your power bill also goes down. And power, power costs per kilowatt are not coming down.
They're only going, they're only going higher. So whatever steps you take these days in, in the market, whatever you're paying for your power, it's only gonna get better as we, as we go into the future. Alright.
I think the equation that they came up with back in the day was, uh, energy equals mc squared. Well, I think that m stands for money. Hey Scott, thanks for being, I like it.
I like it. Scott, thanks for being on the show, Mike. Thank you so much.
Take care. All right. And back to you guys in the studio.
Hey everyone. I hope you've enjoyed our coverage over here today at our platform Con in person, uh, live coverage. Everything we've done will be available on demand, probably in a day or two.
We, because even though we stream it live here, we do edit up, uh, the, the individual pieces when we, we put 'em up. And as usual, they'll be available on text, drunk tv, text, drunk tv, YouTube channel, text, drunk tv, OTT, uh, app, which is, uh, iOS, Android, apple tv, Roku, and Amazon Fire. So do check that out.
Let me introduce you to where I think is gonna be our last guest of the day. His name is Ricky Zachary. Ricky.
Sometimes people call him Flash around here 'cause he went from London to New York. Appeared in both conferences. I think one of only two or three people who were at both.
Yes. Have you done anything on the virtual side the rest of the week, or is that enough? That was enough for me.
This platform con, it was enough for me. Yeah. Um, so Ricky, welcome to Text Drunk tv.
It's great to have you on here. Nice, nice to be here. Really appreciate it.
So besides, uh, besides Globe trotting, tell us a little bit about your life journey. Yeah. So, um, I, I graduated from, um, a school in Georgia.
Oh, I graduated from school in Georgia. I'm from Atlanta. Grew up there and immediately started doing technology and engineering.
So I worked at, um, NCR doing point of sales terminal. Sure. Uh, development.
So I'm working at CC plus plus, those types of things. And then I only did that for a little bit because I had to go to Beaver Creek, Ohio, and as a Southerner, uh, I couldn't survive that first winter. No, That's a tough place for Whitham.
I got, they make good quarterbacks there though. Great quarterbacks. Yes, yes, yes, of course.
Um, I did that for, um, the, the six months. Uh, and then I actually went over to Northrop Grumman, a defense contractor, and I worked there for, um, a little bit over 15 years working Wow. In a bunch of different locations on a ton of different projects.
Worked on COBOL programming, uh, kicked COBOL at the Social Security Administration. Um, and then near the end of my career there, really got focused on platform engineering, DevOps on, uh, kind of automation, leading those types of teams, and then providing the best value to developers and developer experience, uh, from a developer experience standpoint. Then took a little bit of a break, and then now I'm at ThoughtWorks, and I've been there for about four years doing a lot, lot of different things, um, doing, uh, working with startups, um, working with large VC and PE firms.
And now in my current role, I'm the global lead of platform engineering for ThoughtWorks. And so I get to travel around globally talking to extremely large enterprises, mid-size companies, small companies about platform engineering, how can we advance the craft? How can we help developers get the most value out of their platforms?
And then just how can we do platform engineering better? What a great gig that is, Man. It's, it's the best I get to talk about what I love, what I'm passionate about with some of the biggest companies in the world.
Some's great, Ricky, good for you. Good for you. It's a lot of fun.
Um, so how, how long you been doing that at ThoughtWorks? So, I've been doing this, uh, this particular role I've only been doing since November Okay. Of last year.
So formally since November of last year. Um, and it's been a whirlwind, um, Imagine so far. Imagine, You know, because one, one of the themes we've kind of hit on today speak to a lot of people out here and, you know, the term platform engineering may be new to them.
Oh yeah. It's been around a couple years, but I've interviewed people who've been managing platforms for 20, 25 years here today. Right.
Yeah. The lady a a few people, and, you know, so you know what they say in, in technology, right? It's more evolutionary than revolutionary.
And, you know, a a lot of what we see today as best practices have evolved over the last 10, 20 more years. And, and, and, you know, and then, but then you mix in fresh technology like AI and, and these kinds of things. So stuff is always fresh and changing.
Mm-hmm. But it is based on like solid principles. Anyway.
I know you spoke in London. Yes. Yes, I did.
Did and and here. Yes. Yes.
So tell us what you spoke about. So in, so some of those foundational elements actually. So the, um, I was on a both a panel with, uh, Nikki Watts and Cornelia Davis, uh, from Cornelia.
Yeah. Cornelia Davis. She's A good friend of mine.
Yes, yes. I didn't realize. Yeah.
Is she here? Or no? No, she was in London.
She's in London. Okay. Yes.
So, um, the panel that we had was actually about what does great platform engineering look like? So we talked a lot about those foundational principles, the foundational elements, particularly beyond just the tech, right? The processes, product, platform thinking.
Um, how do you organize your team so that your, uh, platform team is successful? A lot of those foundational elements are, are the things that we talked about, those foundational principles. And then I followed that up by doing one of the keynote talks there, where I really dove into the changes that we've seen from 2018 when platform engineering really hit like the seminal moment in, in the kind of technology zeitgeist till now.
And what are some of those e uh, the, some of the things that have evolved, right? Uh, some of the things that have changed really around the technology stack, which is extremely volatile, right? Kelsey and his, uh, keynote showed that CNCF diagram where there's like 400, 500 different technologies there, which makes it really difficult to manage.
But then also the other things around measurement. How do you measure the impact of the platform engineering teams, um, you know, the things that they're doing, and how do you organize the team in a successful way? Um, how do you interact with the developers, right?
Because you were mentioning, you know, the evolution of platform engineering at the heart, it was, Hey, we wanna do more for the developers. It started with automation. Okay, we'll automate some of these things.
We'll, we'll script things out. And then that moved over to DevOps. And now to do DevOps at scale in a consistent way to really help developers and organizations of a thousand or 2000 or 20,000, you, you have to start thinking about platforms and platform engineering as an actual practice and a set of capabilities.
Yeah. And that's where it's not just automation. It's not automation.
That's something I wanna reemphasize. Yep. A lot of people say, oh yeah, we're gonna sprinkle a little AI on it, it's gonna automate stuff.
And what a great, we made life easy on developers. Yeah. There's a couple of things.
Number one, you know, developers have achieved this apex predator in our food chain kind of space. And everything we do, we do for them. Well, yes and no.
Everything we do is to make our organizations better, more profitable. Yes. More efficient, more secure.
Yes. Agreed. Right?
And, you know, yes, developers are important, but they're not, not the only thing, number one. Number two really isn't about automating editing. Six, i i I say I was on a, you know, we do this text on gang show every Monday to Friday.
I'm gonna invite you on one day. You'd love to do this. It's a bunch of pundits just talking.
One of the lessons I learned in my life, in, in, in technology is just because you can, doesn't mean you should. Exactly. Yes.
I've, And so there are some things that we really don't need AI on, or that we don't, we should not automate. Mm-hmm. Right.
There are things we should Yes. And knowing when, when to do or not to do is, is really a, a key piece of that. That's interesting that you said that because yesterday, um, prior to the panel that we did, uh, yesterday, it was the question was, okay, how much are we gonna talk about ai?
And we instinctively said, kind of eye roll, uh, can we not talk about it that much? Mainly because we wanted to focus on those fundamental e uh, uh, elements. Because if you get those right, and you do AI afterwards, you're gonna get tremendous more impact on that then if you just are throwing AI at a random problem.
Just AI for AI's sake, I think we were calling it, uh, strategy by fomo. Right? Right.
Yeah. Everyone's so afraid of missing out on the AI Hike and it sucks the air out of every conversation Exactly. As a result.
Exactly. I get it. I, i, believe me, I get it.
ai, figured we'd move all the AI there so that we could talk about security and DevOps and platform engineering and all the stuff we cover on our other sites. And we sometimes people are just oblivious. Yeah.
And, um, you know, we can't do that. But anyway, it's still seeps seep to everything we do. Yep.
So now let's get this, so you, you did your keynote, you did Your, your panel did keep today I did a panel. You Ran over the Heathrow. Yep.
Ran over the Heathrow, took the, took the Elizabeth line over to Heathrow Uhhuh, took a late night flight, got here in New York at about midnight, uh, last night, this morning, got a quick nap, and then showed up today. And, uh, coincidentally led the panel on how AI is changing platform theory. Oh, God.
Well, some things just go like that, right, man. Right. It seeps into everything.
So, um, but, but led that panel with, uh, three incredible, incredible, uh, panelists that were there. Um, Asha from Google, um, um, uh, the CTO of, um, of, uh, Rutley, who, I'm forgetting his name. Uh, uh, s Silvan.
Yeah. Yeah. Sine ine.
He's free. He lives in Fort Lauderdale. Oh, yeah, He does.
He does. He does. We mentioned that.
We talked about that. And then Aaron, uh, Copeland from Nvidia. Sure.
And that, the three of them did a wonderful job, uh, really shepherding me through what are some of the things that we should be thinking about as AI continues to seep into platform engineering, kinda really across three or four different dimensions. And so, yeah, that, that was a very, um, eyeopening panel for me. As someone that's talking about platform engineering all the time, and talking about AI all the time with, um, a lot of my clients through ThoughtWorks.
It was a ton of extremely informative information that they were giving, and I learned a lot that I'm gonna start taking back and talking to my clients about as Well. I love it. Hey, Ricky, that camera's on you.
Oh, yes. People who are watching this live right now, they're not here. Why should they come to next year's platform engineering show?
Oh, I, I would say if you're a platform engineer and you weren't here this year, and you need to come next year because of two reasons in particular. One, this is really the only conference, um, that I've seen and attended. We actual platform engineers are talking to platform engineers.
Any of the other conferences that are out there, it's a lot of data. People talking to platform engineers, and, um, a lot of cloud people talking to platform engineers and why that's important. This is the only area where we've got actual platform engineers talking to real platform engineers.
And the second, uh, one is, is that it's the greatest platform engineering conference that's out there right now. So Absolutely, Really big reasons why they should be attending next year, year. For people who wanna follow you and what you're doing around platform engineering, what's the best thing to tell 'em to do?
They should, uh, follow me on LinkedIn. Um, just look up my name, Ricky, Zachary, Zach, And they'll find me. I'm doing a ton of stuff on there, um, putting out even more content about platform engineering and subsequently, because it seeps into everything, AI and how we can kind of accelerate and mature the platform engineering practice with, with AI and platform.
I love It, man. Hey, thank you for all you're doing for the community. Thank you so much for having me on the Textron.
You deserve a well deserved rest, my friend. I'm Gonna be trying to get, I'm on Saturday. All right.
We'll see you then. Yes. Um, I think that may wrap up our live coverage here Platform Con.
Of course, the conversations will continue. com. We do a great platform engineering show podcast with my friend Luca and I, and occasional webinars, um, or on Techstrong TV where we're talking about this stuff all the time.
Ricky, thank you. Thank you for joining us. We're out.
Take care everyone. Hello and welcome to the latest edition of the Techstrong AI Leadership Series. We're here with Joes Knuckle, who is, um, lead for the Amazon Cube business, which is their whole effort around AI agents.
And we're talking about the latest updates to the platform, including integrations with Zoom. Hey, welcome to the show. Hey, thank you, Mike.
Very happy to be here. Bring us up to speed, if you would. I think it's been a little bit more than a year since the initial formal launch, and, um, there's been a lot of integrations including this latest offering with Zoom.
But, um, what else is going on here? Well, We've got, uh, you know, we've got a fair bit going on. I think maybe I'll touch on a few different integrations and updates that have happened.
Um, one of the key things is that Q Business has continued to be adopted by a number of organizations, and I think we, we had a very large, um, uh, uh, uh, rollout with NFL, which was part of their draft iq. So, um, that, that was interesting. And then we've got a couple of other, um, integrations like you mentioned.
So there's Zoom, which we launched in April, and we also just launched PagerDuty Advance, so that just launched in the last week. So maybe we can, we, we can talk about a few of these just so you get a flavor for the different ways in which people are using Q Business. Well, let's start with Zoom's.
I think more people are using that in general, but, um, how has this changed in the way we think about working ourselves and with each other? Because it, it seems like on the face of it, a lot more data's gonna be literally available at our fingertips. Oh, that, that's very true.
So I think one of the biggest challenges that, uh, users have is looking at data, which rec resides in multiple applications, and how do you get the context of what you want to do when you need it without having to browse, you know, like having that application overload. So, um, well, if you, if you just think about how Q Business works, Q Business provides a way for an enterprise to bring together multiple sources of information while making sure that you have the permissions in place so that each user sees the data that they are supposed to see, and then they are able to search and get those insights as and when they need them. So what, what we've done with the, uh, with partners like Zoom, is that Zoom now integrates with the Q Index, which is the index that underlie Q Business.
And as you are using Zoom's custom AI companion, so that's their, the AI offering inside Zoom, it is able to pull together insights that are relevant to the, the activity that you're doing. So, for example, if you're in a meeting and you're asking a question of custom AI companion, that can now be kind of enriched with data from the Q index, which where the data can be from, you know, your SharePoint or from your Outlook, it can be from a number of sources, but you have that sort of fingertip and Zoom's able to present that. So the biggest thing is it is taking away that notion of information overload, where you have to, you know, flip to the next step and the next step to get that.
But you're getting it all together, uh, in the, in the places where you work. Is this kind of an example of how multiple agents from different providers are gonna interact, operate with each other, and to create some sort of greater good, but this is just the beginning. Oh, definitely.
I think, I think you, you should expect that multiple agents from different providers are going to work together to make sure that the user is able to ultimately achieve what they want. So like you said, this is a good beginning where you're seeing that Zoom and Q business. Right.
So Zoom's kind of tapping into the data from, uh, Q Business, uh, in order to get this out to the user, but we are also looking at how this can act in many different circumstances. So I mentioned the PagerDuty example right now, which was, which is something we just launched in the, uh, last week. Uh, now with PagerDuty Advance, um, Users, technical users are able to look at incidents and then understand what is needed to resolve them.
Now, with the integration with the Q index, PagerDuty Advance now has the intelligence of other information that might be relevant to them from the enterprise. And the, the Q Index can be used to share that information securely with PagerDuty users. And so definitely, you know, you've got these multiple, uh, agents and agent tech systems working together now so that they can, uh, interoperate to get you the best results.
In fact, one of the things about the PagerDuty, uh, launch was according to PagerDuty's, um, kind of internal studies, they've seen that incident response rates have improved by over 30% as they have this additional context so that, you know, in the middle of an incident, you don't have to run to, uh, go check on another system, get that information. It's right there. The same thing with Zoom, right?
So you are, you are in a meeting, we are in this meeting, and then you are, you are trying to find something. You can get that right from a custom AI companion without having to run to that other system and ask for those pieces of information. Do you think that this is changing the way we work in an interesting way?
Because, uh, I don't think we always appreciate how much toil we go through to actually go get a piece of data, usually after the fact, after a meeting, or in the case of PagerDuty and some incident that takes forever to com to investigate and complete. So, so will we kinda wake up one morning, it's kind of like that back ache you had for 10 years and suddenly it goes away and you, you learn to live with it, but you now you appreciate the fact that you had this pain. I, I think, I think what you just called out learn to live with it is probably the key here because the way we've all been working is across, you know, many, many applications.
And we've all learned to, you know, it's a routine, like you said, after an incident, you go and, you know, do the things that you're supposed to do. Whereas what you're gonna find is that as these systems start to work together, it becomes simpler. And that means that you are able to do these things faster and often, you know, spend more time, you know, thinking about the, the things you really want to achieve.
And, uh, you're just taking away a lot of the toil. I think you use the right words there. You're just a able to eliminate a lot of that in order to do things faster.
There's a lot of obsession these days with all things related to productivity, and I get that AI will improve productivity, but I'm not quite sure it's going to do this in, uh, leaps and bounds as much as it's just gonna make the, the average work life more tolerable for people and we will improve. But I, I'm not too sure robots are taking over the world, but to, you know, how do you view the future work? Uh, well, I, I look at it similar to what you said, which is, I think it's gonna improve the way we work.
It's gonna help us do things better and easier, take away a lot of the to, but you, you still want, the way, you know, you still want to achieve something the way you want. You don't just want output that is just produced and given to you. So in one of the previous discussions, I think we talked about one of the features in QuickSight, an agentic feature called scenarios that we, um, launched earlier this year.
Now that again, is doing data analysis using agentic approaches on the backend, but the, the user is able to actually define the plan, tell the system what it, what needs to be done, and to kind of pull it all together. So when you know, somebody is sitting there and then saying that, Hey, I want to investigate what happens if, uh, I have 20% more sales, right? Will I need more inventory?
Would I need more, more, you know, uh, uh, distribution locations, if you have the data, you're able to create a plan and then have the system execute on it. And so you're making it simpler for the user to do some of these things, but you, you are giving people the control of how these systems work. So in a, in a similar fashion, I think you're gonna find that when, when you are able to, you know, in whether in Zoom or whether in PagerDuty, you're able to get the information right there, you are taking away a lot of the toil and becomes easier for people to kind of operate with those systems.
Well, multiple agents start working together across people and teams, because I can envision a world where I may have, I don't know, I randomly pick a number, but 10 agents that I regularly use, and you might have 10 agents that you regularly use, and we'll assign them tasks that require them to collaborate with each other. And that's kinda also gonna be the future of work in terms of a team setting. Definitely.
I think those are some of the, the things that we are thinking through as we are thinking about the, the future of, you know, the various pieces that we have. So if, if, if you think about, you know, our own offerings, we've got Q Business, which is allowing you to bring together data from, uh, unstructured sources. So essentially like, you know, files, SharePoint, all these different sources where you have all of those written notes and communications, and then you've got QuickSight, which has, uh, information about structured data, so more databases, metrics, and so on.
And then you've got these different pieces all coming together. So we are thinking about, uh, how do these agents, or how do these systems interoperate? And that ex extends definitely to the, the, you might be using 10 agents, and then how do my agents interoperate this questions about, you know, security, identity, all of those pieces that we are, um, kind of thinking through.
But that is definitely a, a, a, a major area for us to all think about In a lot of ways. We're also looking at essentially a business process, re-engineering at a different level of scale. Are there things that you're seeing organizations doing right upfront that you kind of wish other organizations would, uh, cribb a little bit as we enter this age of agent ai, I, I think, um, one of the foundational pieces, and I think many people in the, in the industry talk about it, is making sure you have the right data.
So what we are seeing is that when we work with, um, you know, customers like Nasdaq or Principal Financial Group who are adopting, you know, Q Business as an example, and putting it out there to tens of thousands of their users, they also have to make sure that the data that goes in is the relevant data. So, uh, making sure that you have the right data that is being, uh, input into these systems and making sure that is cleaned and managed in the right ways. That's definitely something that is top of mind as you start to think about what are the systems and what are you trying to get them to do, because otherwise, you know, you end up with a situation of just having a lot of data and then not knowing, you know, what the, the system should pick on.
So that's definitely something I've seen, uh, companies think about, be very deliberate about it as they're rolling this out. And the other part of this would be, you know, how do you roll this out? What sort of users, what's the use case?
And then making sure you are aligned in terms of both the technology and the, the data and the, the user pieces. So which do you think will be the bigger challenge going forward? Is it the technology or is it really gonna be the culture within the organizations?
Well, I think technology is going to keep evolving at a fast clip. And, you know, we, we are all in this AI space, and you can see how quickly it's evolving, I think, um, making sure that you are, uh, helping people in the ways that they want and not just, um, you know, presenting quick, uh, experiments or, you know, uh, shiny objects that people can't really use in their day-to-day. That's going to be the, the trick here, meaning every company has to think about how do they make sure that these technology, um, advancements are being utilized in the best way that users can take advantage of it, rather than being a shiny object in the room that looks good, but doesn't really, you know, work in every, uh, or work in the different scenarios that people do work.
That that's key. So that's why many of the, uh, the advancements that we've made in the last, you know, year have been focused very much on where do people do work and how do we help them. So if you think about the, the Zoom and the PagerDuty integrations that we talked about, that is about how Q business can really help you in the moment that you're in a meeting or you're trying to resolve, uh, uh, an issue.
And at the same time, we also have things in Q business, like we have a browser extension, so that as you're browsing the internet, you can look at, uh, a page and then quickly ask Q to summarize that page. We've got a Slack integration, we've got integrations into NM 365. So we are building these integrations so that you can take those technology advantages and make sure that they are really beneficial to users as, and when they do work rather than just be, you know, like a, a great thing, but that's, uh, disconnected from the user.
So definitely a big focus area, uh, for us, and I think it should be for every organization. How do, how do they users come across technology advances and how are they being used? A lot of these AI agents are becoming increasingly autonomous as the reasoning capabilities of the LLMs continue to improve.
But if they work together, how will they kind of negotiate humans? All the, we negotiate all the time, every time we're in work scenarios with somebody, we're basically having a constant series of negotiations. How will a AI agents negotiate amongst themselves on our behalf?
I think those are some of the areas of, um, you know, essentially I'd say, uh, not research, but areas that we are working through in terms of how do you, how do you set the, the boundaries of what you're willing to negotiate with. Like, if you or me were to have that conversation, those would be in our heads, right? We would have, you know, I'm not gonna, it's like when you, when you try to make a sale or a purchase, you, you know what your limits are, you know how comfortable you are with certain numbers, but, uh, you do want to make sure that the AI agents that are doing work on your behalf have that ability, or it's really the, the guardrails and the, the knowledge that you impart or you prescribe.
And so, as a result, many of the things that, uh, we are looking at is also how do you provide that control to business users so that these, um, agents, when they work on your behalf, you are giving them the, you know, essentially your thinking. How do you get them to do work on your behalf rather than just behave like autonomous systems. So definitely an area that we are looking at, like, you know, how do you make this simpler for business users to manage control and to use many of the, the pieces that are out there.
The scenarios work that I talked about, uh, earlier is a, is a great example because you're not asking the system, Hey, tell me what happens if sales go 20%? You're actually asking that as the system, the system's giving you a plan. You are modifying the plan.
You are basically putting in your, you know, prescriptions as a user and then saying, you know, what, um, you know, constrain sales to, you know, the North America region. And then think about what happens so that it's not just doing like an autonomous run about some fictitious, uh, object, but you are giving it the controls. And that's, again, something that we are looking at how that expands to other parts of our system.
So we, you know, we've got QuickSight Q business, so how do you just expand some of that? So taking out your crystal ball a little bit, where are we gonna be a year from there? The rate of which technology is advancing, that's gonna be a very interesting question, but I do hope that, um, just seeing all the, the work that you know is going on in the industry, we are able to provide users which much more AI in the context of their, of their business and their work.
A lot of what you see today is in the context of standalone applications, right? You've got, you've got all these applications where you can go do things on the site, come back to your application, do something, and what, what I, I think in a year from now, if we are in a stage where people are able to use more of the, you know, AI genetic technologies in the context of their work as they're doing things, and, um, that would be, that would be a great thing. All right, folks, you heard in here, Hey, maybe we're all evolving past being just mere knowledge workers to being knowledge managers.
And we'll do that with the help of some AI agents and maybe even, hopefully be less stressed out someday. Hey buddy, thanks for being on the show. Of Course.
Thank you, Mate. All right. And thank you all for watching the latest edition of the Techstrong AI series.
Catch this episode and others on our website. We invite you to check them all out. Until then, we'll see you next time.
Welcome To the Tech Field Day podcast, where each episode we bring together a group of IT experts from across the enterprise IT landscape to discuss a topic, a premise, if you will, related to any one of a number of IT disciplines. Tech Field Day is a part of the Futurum group, and this podcast is often recorded in association with one of our tech Field day events. We're here today at Security Field Day, but before we jump into the premise for today's episode, I'd like to take a moment for our guest to introduce themselves, starting with Fernando.
Um, I'm Fernando Montenegro. I lead, uh, Futurum, uh, uh, research practice as part of a futurum research. And, uh, I am still in the clouds here about what a joy it is.
It was to be here at Security Field Day, Tony. Very good. I'm Tony ais, uh, networking.
Networking Security is my focus. And Karen, I'm Karen Lopez. I'm data check everywhere.
And, um, I'm a data security person, but I'm more of a data person. And my name is Tom Hollingsworth. I'm the event lead for security events here at Tech Field Day.
Let's jump into the premise for this episode of the Tech Field Day podcast. No doubt, when you got up this morning, you had to log onto a website in order to access your favorite newsfeed or perhaps, uh, buy a ticket to take a vacation. But did you think about your password before you typed it in?
Is it saved on your laptop somewhere? Or maybe you're one of those people that has one of those fancy pass keys. Do you have two-factor authentication enabled everywhere?
How do you know that people aren't stealing your information when they log into your account? The world of passwords has become a lot more complicated in the last few years, but the premise for this episode is that we are a long past passwords. So let's kind of introduce this because yes, one of the things that we've kind of just accepted in our lifetime is that we are going to have to remember tons and tons of passwords.
It used to be a time where we didn't even have to worry about that. The idea of typing something on a keyboard to be able to do anything was kind of weird. And now, you know, my Netflix account has a password.
My email account has a password. Uh, no matter what I do, I like, I have a pin code on my coffee maker. So why do we have to protect everything?
Why, why do we need so many passwords, folks? Those, the, there's a concept in economics called an externality, right? Which is that the, you somebody doesn't pay the full cost of a transaction.
What I mean by this is that it, uh, you don't bear the cost of something, right? That's, that, that's the, the, the way to think about this in the context of passwords is that, uh, individually it's easier for a developer to say, you know what? I'll just throw a password here for this little application.
It's just a simple password, right? They are not for them, it's just, we'll just implement this password. But as you very well said, we now live in a world where we have 153, uh, different systems that we access at different times.
So that's 850 passwords, right? The burden of managing all that falls on us, it doesn't fall on that, on that individual developer. So the reason we have this is because it's easier for, it's very easy to implement, but it's, it's kind of like the, the we're, we we're chatted about some your time, like free as in a puppy, right?
It's a, it's, it's something that just grows on you. What, what I think passwords, right? That fundamentally, in my opinion, passwords are used for authentication, at least initially, that was the design.
Um, we need to give multiple users access to a single computer system. How do we make sure someone can't just walk up and access it? We need them to type in a password.
Mm-hmm. Simplistically it was for authentication purposes. I tell you what, I, I love password managers, but I, I don't like the concept of having passwords for everything.
I like a, a lot of the alternative authentication mechanisms, such as like someone, I think you said when you logged into Netflix or when you logged into Netflix, I just type in my email address and then it emails me a code and it assumes that I have access to that email. I, I find that much easier, you know, than having to manage unique passwords, unique accounts in a password manager and everything else. I like the alternatives to Passwords.
Yeah. I think passwords need to die. Um, because of that, the number of them, like if you have a password manager like I do, you realize how many passwords you have.
Um, and that just has gotten, and now I can have, like, I don't know what my passwords are. Mm-hmm. Yes.
I might, if my password manager dies, I might be outta luck and I need some way to recover it, but I'm lazy. I hate typing long, complex passwords. I always get it wrong.
So I think the pass, whether it's pass keys or the emailing, the only thing I have, the issue that fear I have with the it, you email me something, of course your email probably relies on a password. Mm-hmm. And now everything is available because someone, because you've given your password to someone.
'cause that's what happens to people or people do to themselves. But, But in, in, in defense of the authentication mechanism Yep. That I spoke of.
Yep. Normally when it's a, a, not a password transaction, I put in my email address on a website, they email me. Yep.
A one time code. Exactly. So even if someone gets access to my email mm-hmm.
In your example mm-hmm. Doesn't mean they get access to all my other accounts. 'cause that one time code can be used only once and for a, a very short window.
Yeah. I was just say keep control. So I'm favor of it's, I want what you said more than passwords.
It's, It's just better. It's, it's just an alternative. But fundamentally, when I think about what passwords are for, it's for authentication.
Yep. And I think it was a great first step, but here we are in 2025, you know, authentication has been around for 45 years. Mm-hmm.
Uh, let's move beyond passwords. Yeah. I, I think that there is a, that every mechanism there is a, there's a gradient of options.
We have options for things. Right? I think that passwords have their uses as a, as a, there's some characteristics to them that I think they're helpful for resiliency.
Right. You know, it's easier to remember a password, a single, uh mm-hmm. Password.
A a break glass scenario mm-hmm. That people talk about. Yeah.
Fine. I, I, I get that. I think that's where, where things blew up is what, what I mentioned that, hey, I want the pass.
So one site gives me a password, another site gives you another password, and pretty soon I have 853, and I don't say it 8 53 by number. I I, I had to port my passwords from password management. Another, it wasn't the 800 range, But, but were there really 850 passwords or were there 10?
Yeah, No, no, there were, okay. There were not 850, but there may have well been 600 and something. But this is one of the problems that we've run into.
And part of the reason why we've started looking beyond using just simple codes for system access. And I will, I will tell on my good old coworker, pat from IBM 25 years ago, um, one of the things we had a problem with is that we had passwords that were set to expire at certain times. Right.
So we had a password that was gonna last three months, we had a password that was gonna last six months. And one of the systems that Pat was logging into had a password that lasted 30 days. So Pat made all of his passwords the same mm-hmm.
So that he only had to remember one password to log into everything. But the problem was is that with the different expiration dates, the only way that he could keep things consistent was whatever the, the youngest password was, the 30 day password every 30 days he had to go change his passwords. Mm-hmm.
So in a way, he had created more security by frequent credential rotation, but in a way that the way he chose to implement it was bad because he used the same password. Yep. And that's what we're seeing now Yep.
Is with things like, have I been pod Yep. We can tell you if your passwords were leaked and if their passwords are consistent tied to those email addresses, we're starting to see people that are using that as a way to, to impact systems. Right?
Yep. And as more and more of our information, whether it be, uh, PII or payment information are stored by these systems, we have problems where now those systems can be, um, hacked or, you know, honestly, you're just logging into a system with a correct username and password, but I can't verify your identity. And that's why we've seen the rise of two factor authentication.
And, and to your point, Tony, getting a one time use pin code is a two factor because you have to know the password and email to the system, and you have to have control of the account in order to get that email. So this is creating a barrier to entry and honestly a compliance and liability boundary for the company. Well, we sent the password to the account that was on file.
If it wasn't you that was in control of it, we have nothing to do with that's, so is the, is the moving away from passwords something that we're doing to make people's lives easier? Or are we doing it to protect our, our businesses from being sued for exposing things that they shouldn't? The, the, the moving away from passwords is because people are in the equation, are bad password managers themselves.
I won't deny That. Okay. That, that's why is because if you give a person an opportunity to create the same password for every account because it's easy to remember and it's quick to type, then they will, because we're, we're animals and we need to find the, the, the most efficient way to do something.
That's what we seek. That's bad for security. So, oh, so it's, it, yeah.
It's great to be maturing beyond that. I don't think it's, uh, uh, industry companies or vendors trying to pass the buck of responsibility. I don't think so.
I Love hip optimism. I think it, I think it's a, a wonderful step in the maturity. There's a line that I, I'm going to butcher it a little bit, but, um, I think it was Edward Wilson, sociologist biologist.
They have the, the problem with mankind is that we have lytic emotions, medieval institutions, and God-like technologies. That's Good. That's fair.
Right? And the, the, the, the exactly I think he nailed it is that the idea is that we are bad at this. Our brains were not built for this.
Right. And, and we need to, we need to account for that. Now, that brings into the picture an entire other discipline of do we have the right user experience, uh, uh, tools available to make it easy for people to migrate to password live and, and multifactor authentication and, and all those other things.
And I would argue that we as security professionals, uh, and IT professionals, we are actually failing as a non-trivial part of this popul of, of our human population when we create these systems that make assumptions about how people are with technology, right. In the context that Oh yeah. It's just, just use a password manager.
Mm-hmm. Guess what? There is a cost, there is a cognitive cost to that password manager.
I, I, I'll, I'll go on record as saying I am a huge fan of those little password books that you see on, on the, the printed ones. Right. Oops.
Disrupted because they account for a threat. They are actually excellent for a threat model of password leaks off of a have I been pound or, or something. Anyway, I can, I can go on a rant.
I can go on a rant. It's hard to steal a password out of a book that's offline Exactly. Until you leave it on a Bus.
Is it air gapped? Yeah. Because there's error around, But, and, and that's a good point.
We used to decry, you know, the little password books that you could buy at every Walgreens back in the early two thousands. You know, why are you writing your passwords down? Well, if it's too complex for me to remember and there's different permutations for different systems, I would rather have it put somewhere where I have to go reference it every time.
Because kind of to your point, I don't know what the passwords are for some of my sites, and I want it that way because then I have to be forced through a specific authentication mechanisms, you know, how to do that. And, and a lot of it comes back to, yes, we are investing a lot of faith in the way that people access systems mm-hmm. Because we're also investing a lot of faith in their ability to do their job.
Yeah. This isn't a situation of like, oh, somebody's on my Netflix account and they're watching things without my permission. It's if I get Fernando's password to the exchange server, I can delete everyone's email because he has admin rights.
So I wanna restrict that capability to people that I can trust aren't going to abuse it. But the only way to do that is to ensure that I know who's logging in with which user IDs. Yeah.
Funny you should mention just the, the, the, the exchange, uh, example. Like we just published research, like the, the, um, the decision maker survey we just did. One of the critical use cases for on the identity management side was, uh, that came up on, on, on the survey was exactly how do we control privileged access.
Mm-hmm. Or, or privileged accounts, right? So it's one of those things to, it's all about balancing the, our exposure.
What is it that we are concerned about? Am I concerned about my Netflix account? Fine.
We'll, we'll, we'll use one mechanism. Am I concerned about my exchange server? Is it okay?
Then I'll, then I'll do something else. But it's about balancing, Right? And you've brought up a good point about the human side of it.
So we all know that if there weren't humans involved in this, we'd probably be easier to cure things. So like, so a story I have is like, so we started doing multifactor pain in the butt. Every business user hated it.
It was another step. And I'd be on a meeting where we're on, like a teams meeting and there's someone showing something, and all of a sudden I'd see this pop up, you know, on their screen to enter an SMS code or something like that. And the person would be like, hold on.
And they're entering in the s you know, the code. And off they go. And I'm like, were you logging into something?
I don't know. I just put the code in there. Well, that multi, that's a multifactor fail because they don't understand what they just did.
Yeah. And then you go forward, so then they made it easier. So what I loved about my Apple Watch the first time was that with Microsoft Authenticator, it would just pop up.
Was that you? And I'd go, yep. Two seconds.
They got rid of that because it was too easy for people to go. Yep. Now you have to go on your phone and type in these two numbers from your screen.
I get that. But I also have these things. I had a CIO come to me as I was a database administrator, go and set every customer's password to the same password.
We're spending too much money resetting passwords. And I said, then we might as well not have passwords. But to, to this point, and I think this is something that people need to understand, is when you think about the history of multi-factor, multi-user authentication, it didn't come from a world of business, it didn't come from a world of technology, it came from military applications.
The original multi-user authentication is nuclear missiles. It's two keys on opposite sides of a room that can only be turned by two different individuals. And the reason why it exists is concept that I think a lot of people might be familiar with is friction.
We want it to be hard to launch a nuclear missile. Mm-hmm. So that we do not do it on accident.
Because if we do Stanislav Petra, you are my hero. Mm-hmm. Um, we could literally kill everyone in the world because of an accident.
Mm-hmm. So we have introduced friction. We've introduced, you have to pull out your RSA token and look at the, the key code.
We want you to stop and think about it. But now it's a whole lot easier to do that. And people are counting on it because look at the way that phishing emails are, are formatted now look at, they're, they're counting on you not reading things before you go click on a box and log in somewhere, not knowing that that is the moment where you have been compromised.
I, I, I agree completely. And this is where I think that the onus is on us as security professionals, as, uh, uh, it admins to design systems and mechanisms that take this human behavior into account, right? Mm-hmm.
We are not robots. That's right. Most of us, most of us are not robots.
Right. So I I I like to say that if your entire company, if you have a massive security breach, that was because a user failed a phishing, usually that that is your, that that is not on the user. Right.
That is on the architecture that led to that problem. Right. Because you have to account for human failure.
Yep. Or, or, I, I shouldn't say failure. You have to account for human behavior.
Yep. Humans are going to get wrong with the passwords. I love your example, by the way.
The, the, the ai. It's just happened both. Keep going.
Yeah. I see it all the time. All the time.
But sometimes we create friction where we don't intend to because we're trying to be too secure. Personal example, when I migrated my iPhone last year, I needed to log into all my new accounts. So I went through, and of course, you know, some of them automatically logged me in 'cause they had cash credentials and things like that until I went to log into my Google account and my Google account said, oh, um, you're logging in from a new device.
You need to, uh, answer the challenge. And there were options. It was authenticated on a device or be in, uh, be sent a one-time code.
Well, the device that I was trying to use, like, I'm like, well, I turned it off, so I don't know. I don't want to do that, so I'll just have a one time code. So I hit the button and hit go and it goes, mm-hmm.
There is a more secure method available. You can't use this. And so I ended up, after 10 minutes, starting my old phone, logging into Google from there, and then shutting it back down so that I could erase it later.
We create these stumbling blocks and then work ourselves into a corner. I mean, I can remember when moving from one phone to another on signal was one of the hardest tech challenges that you could possibly, because signal by its very design, is to prevent those things to prevent impersonations. So we think of all these crazy scenarios where things could possibly happen, and we build these protections into them, and then we're left with situations where people are gonna, like Karen said, just do whatever they need to do to circumvent the control.
It's no different than propping open the smoker door at a building and you've circumvented physical security controls. No, no identity cards or, or, um, you know, security guard checks or things like that if someone can slip through Right. The back door.
So how can we prevent users from circumventing the security controls that we put in place? Because I feel like that, like Tony said, the the, the lizard brain just wants to go. Like, it doesn't, it doesn't care.
Like they don't think of the, it doesn't say, oh, well yeah, if someone gets a hold of my Apple ID password, they could charge $9,000 worth of in-app purchases in Fortnite. And I'd never know and Log Into my bank account as well. Well, I, I, I think, um, I think it's important to look at the whole spectrum and, and, uh, the spectrum of, uh, why do we need the authentication?
Because we want to protect access to data. Okay. What is that data?
Okay. Like I said, the example I gave of, of logging into a Netflix account and having it just send you an email code and you just type it in. Okay.
That's for access to a streaming platform. Mm-hmm. I wouldn't recommend that for the admin credentials in my enterprises active directory.
Right. It's not the same thing. We're protecting access to different kinds of data.
Yeah. And so I don't think there's a silver bullet. We're gonna replace passwords with this thing.
I, I don't think that's ever going to exist. We're an entire population, you know, of however many billions or trillions of people on the earth, forgive me for not knowing. Um, We have 8 billion different, And we're not all IT professionals or IT or security professionals.
We don't need, and we're not all protecting nuclear secrets. So we don't need the most secure thing. It should be based on, um, security and convenience.
You know, and what is the data we're trying to protect access? Well, what is the data you're trying to protect on your Netflix account? Uh, actually nothing.
It's just mandatory. No, No. They can mess with your algorithm.
That would be Pain. False. No.
There, there. I Bet you not choosing shows for me to watch. Yeah, You're violating.
There's one reason why you won't tell me your Netflix password right now. Well, I would tell you the reason is because I don't know it. But the reason why is because you pay for Netflix, don't you?
I do. So if I had access to your Netflix account, I could get your credit card info. You Can't because they don't store that info available to the user.
It doesn't Matter. And, and that's a, a thing that we have done because of regulation to say, I will not store this information in the event of a data breach that I, I can't be penalized for it. And that's one of the things that we've started to work around is we know what sensitive data is important.
Let's be fair, if there was, if there's no credit card data stored in Netflix, nobody cares. What they care about is fact. Oh, you can watch Netflix for free kind going back to, to Fernando's, you know, you are not bearing the full cost of this.
Like my, my kids, I don't mind that they're not bearing the full cost 'cause they don't have jobs. But I don't want anybody else watching my Netflix, because if you have a Netflix account, you can do it. But to your point about, um, we need to create, we can't create one solution that solves everybody's problems because there's different classifications of security we are actually approaching that You haven't noticed.
There are, uh, multiple popups on websites now to log in using your Google account. Mm-hmm. Um, you can create a pass key in most accounts now, which requires the use of an authenticated device.
And when you think about it, for example, my LinkedIn account has a two-factor authentication code on it, but I never see it because I only ever logged into LinkedIn on my laptop, which is a trusted device. And so it creates a pass through of my identity to get in there. So I've removed the need for a password through other authentication mechanisms that I didn't have access to 20 years ago.
One of the most, so one of the, my most rewarding professional experiences was I worked for a few years in anti-fraud. Right. It's a phenomenal space.
And amongst the many things, uh, I learned there was, uh, first of all this notion of, of a, a better sense of, of the risk management of which solutions gets chosen. But there is the notion of, uh, above the line fraud controls and below the line fraud controls. Right.
The below the line fraud controls is the stuff that is happening, quote unquote in real time. You just don't see, to your point about LinkedIn, what LinkedIn is actually doing is that, look, we are checking the IP address where, where he is logging firm, we're checking the browser f uh, fingerprint that his logging firm, it looks consistent with what he, what he's doing. Let's not ask him to re-authenticate, but I can guarantee you that he open up a new, uh, open up a new session that looks just different enough.
Mm-hmm. And yeah, it'll ask you to do. So designing systems that can do this kind of, of more, uh, aligned, uh, risk-based authentication, right.
Is youthful, But that puts the onus on the companies creating the system when all I have to do is tell you to type in a password and now it's your problem, not mine. Which Goes back to my very first point about economic externalities. Mm-hmm.
So I have a question for you then. Why, why has credit card fraud gone down in the last two years in the us? Uh, I, I have two reasons, But tell us.
Well, you, you probably know one of them, we changed the way that we do credit card transactions, chip and pin versus magstripe. Yeah. Do, do you know why credit card fraud has fallen significantly and it has everything to do with technology, but it's actually a policy, the least secure portion of that transaction chain is the responsible party should fraud or theft occur.
Mm-hmm. And that's one of the reasons why you're seeing that why it seemed to happen overnight was a regulation was passed. That said, if your point of sale terminal doesn't take chips and somebody fraudulently uses a card, you are responsible for paying the merchant, the, the, the transaction fees.
Suddenly every terminal within a week was replaced with a chip and pin terminal, and now you're starting to see, oh, and, and they're getting more and more creative. If you ever used a virtual credit card number like an an Apple wallet, um, that idea is even if my card number is stolen, it can be instantly regenerated. And that that particular piece of PII can be eliminated forever so that I know that if somebody's using it, I, I know where the data breach came from.
We are creating more and more things technologically to solve these problems, but we're only doing it because we're shifting the boundaries of where the fraud could happen. So for example, maybe a corporation says we're totally fine changing everybody's username to be the same. Awesome.
If all of the financial information for our customers get deleted, then the CEO gets fired and arrested. Suddenly the CEO wants to make absolutely certain that everybody has the most secure password possible, that nobody could possibly ever do this. And it seems like a harsh mechanism, but that's sometimes what we have to do.
And I quote my good, uh, friend and database professor, Dr. Tracy cart, if you can't motivate people by greed, you have to do it by fear. And I think that passwords have become a fear institution of, if you forget your password, if you don't use this secure authentication mechanism, it's your fault if something bad happens.
So is that why we feel like users are trying to do everything they can to avoid using them, is because they're afraid it's gonna be their fault if they screw up? Y you know, I, I don't think they know. I, I, I, I'm gonna misquote it.
I, I wish I, I wish I had my computer to look it up, but I think it was the NIST standard a few years ago. They redacted. Mm-hmm.
It was last year actually, The need of doing a six month password rotation, whatever the, whatever the recommendation was, don't rotate. Because when you rotate, again, we are humans. We are trying to find easiest number, the increment a number or a season or whatever the month, and they actually found that passwords become simpler Yep.
And predictable. Yep. It, it's better to have, it's better to have a very secure password that lasts a long time than have insecure passwords that change frequently.
Yep. I loved when that happened, by the way. Yeah.
Everyone did. Yeah. I've worked at companies where it was every 14 days, Actually, I think we did a tech fill day round table about that right after it happened.
And all of the security people were like, that was awesome. Thank you for making that change. I Think, I think we've, so there's one other thing when I talk about like, you're basically saying cost benefit and risk of how much, how hard we make passwords or identity happen.
The one exception to that is like almost every home user is like, no one's gonna attack my pc. There's nothing on it except that we know that our smart devices are P PCs are now being hacked not to get to the data, not to get to your bank account, but to turn them into zombie bots Yep. To do criminal things.
Very awful criminal things. And right now, I've never heard of a case where home users whose devices got, or even a company's devices got compromised that way where they ever had to suffer any consequences of it. But, but they, that comes back to we can prove that it wasn't us that did this.
Right? Yet when the webcams got hacked because of a hardcoded backdoor password, you are still responsible for sending that traffic. And I'm pretty sure that your ISP is still gonna want you to pay the traffic bill.
So it, it kind of, I'm worried about what's in the traffic that's going. Right. Right.
And, and it, it's a challenge, right? Mm-hmm. Because we, we know we need to make sure that there are simple controls in place, but we also need to make sure that we've limited our liability as much as possible.
That's a good point. Because at the end of the day, we still, there has to be, someone has to be responsible for it. Right.
And that, that's like the credit card transaction. It, it, the least responsible person is responsible for covering the fraud. The fraud still happened.
We're, you know, this is not the Star Trek utopia of, you know, we don't need money anymore. However, I will point out that the enterprise d had two factor authentication for the self-destruct code. You had to have your own personal authentication code, and it was a voice print match, which is why Commander Data had to impersonate Captain Picard in order to lock out the computer.
Yep. Speaking of voice match, let's not ignore biometrics. Yep.
But I, I know that probably all of our foot people in here have modern phones with some sort of fingerprint unlocked mechanism base or face base. We're, uh, the people aren't even using pins anymore. Mm-hmm.
You know, for that. And, uh, I, I guess I'm, I guess a lot of modern computers probably do have a fingerprint sensor, but not all do. Mm-hmm.
I would love to see that being more used and it would be okay if it was used in conjunction with something else. That's okay. Mm-hmm.
But, but it's so simple and fast. Yeah. But Tony, use one finger to log into something.
It takes one second than it does to, But Tony, everybody tells me that it's super insecure because I can't change my finger or my face. Well, That that's why you need something else. Yeah.
Something else, right? That's why you need something else who Yeah. It goes, it goes back to the multifactor part of it.
Yeah. It's not that who I am is important. It's that that particular piece of information in conjunction with other things creates a situation where I am safer.
Mm-hmm. I think it's one of the things I, I go that, that fraud, uh, so I, I have this, this running, uh, joke, not joke, but I, I have this, this, uh, line that I says that go back to high school calculus, right? I think that the limit for cybersecurity as time approaches infinity, as time goes to infinity, the limit of cybersecurity isn't a fraud.
Right. And what in the context that as technology gets abstracted away, we focus more on the business problems. Right.
And one of the beautiful things about one of the things that, that in, in fraud teams understand better than security teams is that we just have to lower the risk enough or the residual balance it. Yeah. It's a balance, right.
Security teams, we tend to be much more absolutist about this. And I think that in this conversation, uh, uh, we, we, we've all been touching the, the topic, the idea that it has to be just enough for what we're trying to do. So the, the the fingerprint, the, the, the, the face, is it perfect?
No, but you know what? It reduces enough of the problem. No matter what we do in our modern world, we have information that we want to protect.
And let's be honest, even a simple password is better than not having any passwords at all. However, there are better solutions out there. There are more secure solutions that create less friction with your users and it works better with what they're doing.
And we're never gonna get away from the days of somebody guessing a simple password or having you text them the login code that your phone just got as a way to, uh, backdoor into your account. But we're creating environments where it is less likely for those things to happen. Which of course means that the people who are trying to do them are going to have to get better at stealing those things.
Just like every computer now runs a form of antivirus, whether we like it or not, realistically speaking, everything we do is gonna be relying on passwords whether we want to or not. It's just the way that those passwords look to the end user will change in the future. That will just about do it for this episode of the Tech Field, a podcast.
Before we go, I'd like to ask our guests to let you know where they can find more information about anything that they create. Fernando. com.
I'm also relatively active on social media, primarily LinkedIn and Blue Sky. So Fernando Montenegro, you can find me on any of those. Tony.
Yep. I'm Tony a Infantis. Uh, you can find me on my personal blog blog.
com. com. And also as Data Chick most places.
And Karen Lopez is all 10,000 of them on LinkedIn. com/podcast for the latest episode. You can also follow us on social media.
We're active on LinkedIn, blue Sky and X. Just look for Tech Field Day. We'll be back next week with another great episode.
com for information about our upcoming, uh, research projects and other great things that we do in conjunction with the future and group, as well as, uh, techron tv. We'll be back with the next week with another great episode. Until then, stay safe and don't forget that password.