Techstrong TV June 11, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. I couldn't find my black turtleneck, but it was fun watching the Apple, uh, worldwide Developer Conference, wasn't it? You're watching Text and Gang.
Hi everyone, it's Alan Hummel and welcome here to our Wednesday edition of The Textron Gang. Uh, we've got a great lineup of, of people, gang members to talk with today, as well as some interesting things to talk about. Of course, it was Apple, WWDC day on Monday, and we're going to dive into that.
We're gonna talk a little bit about vibe coding for the enterprise. Hey, it's coming at you. And then lastly, we, you know, as usual, our government continues to just churn.
I don't know if it's churn for churn's sake or just, I don't know what it is, but we'll talk about it, some new executive orders regarding cybersecurity. Let me introduce you to our Distinguished Gang member panel today. First of all, I'm happy I, I missed his debut last week.
I was away on vacation, but he, he's no stranger to the Futurum Group. He's no stranger to people in the Chief Technology Officer role. As a matter of fact, he is the Chief Technology advisor, Keith Townsend.
Keith, welcome. I'm thrilled. I'm thrilled to have you on here on the show with me and thank you.
Good to be here with you, actually on your own show. Yeah, yeah. No, it's, it's, it's good to be back also joining us.
Oh, and by the way, Keith works a ton with the, our friend Steve Foskett over at Tech Field Day, speaking of Tech Field Day. He is a Tech Field Day delegate extraordinaire, as well as a terrific analyst in his own right, really honed in on Cyber, our friend Jack Poer. Hey, Jack, how are you?
Uh, doing great today. Thanks. Pleasure to be here.
I'm wonderful. Thank you. Glad to be back.
I was starting to wonder, was this something I said? No, we, we, you know, you can be on every day if you want. And then lastly, uh, um, you know, our Winter Warrior, one arm Jack there, lefty, the guitar man, he's a Futura analyst.
Mitch Ashley. Hey Mitchell. Just call me Bucky, referring to my shoulder.
Bucky the Winter Soldier. Yeah, I feel like this is A, a, uh, a tech Field Day masquerading as a Textron gang show. Yeah, well then we do have a te distinct tech field day flavor to it, but that's good.
We're all one futur and family, so that's what we're supposed to be doing. Well, I think I've done over 40 full field day events, so Yeah, this is, this is rack between me and Jack. We we're, we're representing Field Day pretty well there.
I'm still in the single digit, so I think I'm like an eight or nine, but It's all good. It's all good. Just a quick plug.
You can watch all the tech field days, right on techstrong tv, on our YouTube channel or on the Techstrong TV OTT channel where we've built up a nice collection of field day podcasts and everything else that's on Apple TV and Roku and Amazon as well as, uh, iOS and Google. Anyway, hey guys, speaking of iOS, I don't know what I wouldn't give to see Steve Jobs walk out in a black turtleneck to a live audience and present. I watched the show, I watched it on my Apple TV last night.
It was so slick. I didn't know if I was watching a Disney show or Apple, or, or what it was. I, I'm, I, I'll be honest, I'm not a fan of the whole prerecorded thing.
Um, I don't know. And you, you, you follow this space closely? Yes.
I'm ex Apple as well. Apple is, is, I was a developer designer in Apple education, enterprise marketing. That is when I stopped being a developer and when I became a marketer, that is the line of demarcation in my career because, And nothing was ever the same.
Nothing was ever the same. I was there as iTunes launched, which will date me pretty hard. Um, and I remember we used to all wear black turtlenecks and jeans on keynote days.
Uh, it was a very special, special experience in my life. I'll never forget. But that being said, I still, I don't look at the company with rose colored glasses.
And I suppose that might be why you thought of me for today. I carry a, a Google Pixel. I also have a, I also have an iPhone I should say.
But my primary phone is an Android for that reason. I think this was a very glossy, yet slightly disappointing, uh, announcement. I mean, some of it made sense, like, let's name the iOS for the years.
Great. Okay. I wasn't really worried.
Wasn't really, it just seems like sort of like maybe an internal thing that became external, um, the, the glass, you know, look and feel cool. Um, I think where a lot of people were left wanting was with the I AI bits. Uh, I think that's where they caught the most flack, because, tell me if I'm wrong here guys, but integrating chat, GPT is not something I think is announcable at this point in the game.
I think they're just catching up. And I, I honestly thought about it this morning. I was like, is Apple essentially a chat PT rapper?
Is this, is this where we are? Is this where they are? I mean, they must be Hi.
They must be hiding something. Awesome is all I could think This felt like, 'cause I've, I've been to some of these events too, actually went to some of the jobs events. 3 update, not a, not a full developer conference event.
Yes. There's a new UI redesigned. Okay.
It looks slick. It actually kinda looks slick. Like the recorded videos look slick, Alan.
Yeah. It, it just, it wasn't, and, and it, you know, I, well, going into it, I was thinking, is Apple gonna resurrect themselves on ai? I kind of doubt it.
'cause they sure haven't led up to it and they didn't, which, which I think is a good thing that they didn't try to fake it until they make it. 'cause people would just pan 'em more so than, you know, for, for what they did. But I think there was a lot of kind of random features, you know, so I get, uh, translation to French on my phone instead of in the cloud, and I can do, you know, more chatty pty things.
Okay. There, there's some new features, there's helpful things. But again, it just made me think like, okay, are we in the John Scully days and we need jobs to come back and kind of resurrect Apple?
Are we headed that way? I like the way you're using the word resurrect with jobs in the same sentence. 'cause that's pretty much what it would take at this.
We'd have to reanimate, but we might have the technology ho Yeah, we'd, I'd be okay with a hologram. Yeah. Um, but let's be honest, this is, this was not that different than Google's recent announcements where they just hit us with a milieu of A lot of features.
50 things that weren't that interesting, but as a whole, we're packaged as something great, but the differences is this is Apple. So they did it with like a cool, fun vibe. Yeah.
So it's really interesting to see a post jobs apple, which is, you know, over well over multi-trillion dollar company. How do you, how do you still stay innovative but not cannibalize your revenue? It is a very good business.
And what happens when you have a very good business and, uh, you're met with quarterly demands, et cetera, et cetera. I don't know. It's, it's, it is a different apple.
It's funny that, you know, we're, I think part of it is half jokingly, but seriously, you know, Apple's dead, but they make billions of dollars a quarter revenues continued continuing to grow ai, you know, we'll get into the conversation around, you know, how real is a GI and all of that coming along with Apple put out a very provocative paper earlier this week. And so the, the question is, how much AI is enough to continue the insane run rate rate that this business has? And it's as, as technologists, we wanna see 'em put, push the envelope as, uh, and I, I'm not, I'm not a big Apple investor, and I'd rather see them, you know, you know, give, give me the next, the what, what does Steve Jobs say?
It is a communications device. It's a, uh, internet device. And I forget what the third one thing.
Give me another one of those moments. But, but has Apple really, is it, is it a computer company anymore? Or is it really a media entertainment company?
I haven't looked lately at, you know, the financials, but I'm gonna guess that a majority of the revenue comes from the media and entertainment and the app store and not from hardware technology design and innovation. And, you know, they're really chasing the majority of their business, which is not innovative. You know, technology innovation.
Well, Look, the opening of the opening of the conference was a plug for the upcoming F1 movie, right? The Brad, which will be In theaters Yeah. In the one the 27th.
Yeah. I'm, I'm gonna go Apple iPhone sales are 51% of their revenue. Yeah.
It, it's still computers, but there is a sizable app store media, you know, component to their revenue. But, but here, here's what I'm hearing from you guys. And we've heard it unfortunately since Steve Jobs untimely death.
Where is the innovation in Apple is, you know, if you are an Apple person, and I get this, I have a lot of friends who are Apple fanboy, they get off on the new ui, was the transplant transparent glass, floating glass, whatever they're calling it, you know, that is it, it's pretty liquid glass. Excuse me. No doubt about it.
It's pretty, and if you are an Apple aficionado, that's the kind of stuff, you know, they get off on, right? Look how pretty it is. Rounded edges.
We went from square edges to rounded. You know, this is a throwback to Johnny Ives. I was expecting to hear more about what font they were using.
They did mention it was the San Francisco font, right? Because it dynamically resizes the clock depending on what background you have. And they said it was the San Francisco, right?
Steve Jobs was fanatical about fonts. That was his thing, right? Fonts.
But where's the, in where's really the innovation here? They, they recapped what they already had in Apple Intelligence and said more coming soon. But Keith Town said, to your point, they tipped their hand when they released that paper that kind of crapped all over, you know, AI's ability to really reason you could have read that paper and said, don't expect to see anything big on AI from Apple, because they wouldn't have released that academic paper on the heels of, you know, just preceding this event, had they had some big AI news.
Yeah. You know, you, you sell what you have on the truck, right? And Apple on the truck has the iPhone reasonably, or any mobile device reasonably can probably do what, a 7 billion parameter model relatively, uh, within the spec of the machine.
And you can do some really interesting stuff with a 7 billion parameter model. Um, I, I think small, large models are the way, but when you're thinking about consumer ai, a 7 billion parameter model just isn't going to get the job done. It will get the job done when you're talking about industry and specific verticals.
But, you know, this lack of ability to do the trillion parameter model and needing to outsource capabilities, like my action button on my phone is to chat GTP. So, you know, and that, that tells you kind of where Apple is at when, when they're, uh, just by design. And I, I know folks like Jack, appreciate the security focus of that, but I'm not a security person and I want, you know, I want chat GTP to have all of my data so I can get the best outcome.
Well, and and to that point, Keith, in years gone in years past, having something that ran on the phone would be very important. You know, having a doing inference on the phone, right? Or on the mobile device with modern connectivity, are we really disconnected enough that we can't leverage inference in the cloud?
Right. And, and in fact, I, you know, part of the issue is the performance of inference in the cloud may actually be better than performance on your phone. And even with latency, you might, you might still have a better user experience running off the cloud, But are we saying they didn't do this for security concerns?
'cause I don't, I don't know if that's necessarily true. No, I think author I'll, I'll be honest, you know what I think of the whole chat GPT Apple relationship is, it reminds me of when they used Intel chips, right? They never used Intel chips, then they went to Intel chips because Intel had something they didn't have, and they used it just long enough until they had their own silicon again, Right?
And their end of lifeing, their end of lifeing updates for those chips now, Which is amazing because if I would've bought a Intel, uh, Mac Pro, uh, just a couple of years ago with these monster Zon chips and 192 gig of ram or 512 gigabytes of ram, and I can't update to the latest OS today, I'd be pretty disappointed that was thousand on a, on a workstation, and I can't get the latest OS just a few years later would be frustrating. Yep, it is. I mean, they were the masters of planned obsolescence.
Yeah, they Really, yeah, but I was gonna say that this is not the first time Apple's pulled this trick, right? This is, this is Apple 1 0 1 stuff. Hey, you know, and that was always a difference.
Microsoft bent over backwards and twisted into a pretzel for backwards compatibility. Apple, not so much. That was never their game.
Actually. I think it's the opposite game as they really want you to always be on the latest and greatest hardware, and they're forcing you to upgrade rather than doing that. You know, you, you call it planned obsolescence.
I call it planned revisionism, right? It's planned upgrades. Although whenever I travel with my de laptop as opposed to my MacBook, and I take a photo during a conference, and then I look towards my Dell laptop and I'm like, wait, where's the image?
So I can tweet it out and put more detail around it. Functionally, I gotta tell you, I'm on the, I'm on that train because from a productivity for, for a creator and from a productivity perspective, that combination is, is Killer. Well, that kind of closed system between hardware and software enables those kind of features, which are very handy.
I agree with you. Uh, you know, the, I think the question is now it isn't, what did they announce yesterday or the day before? It's what's gonna happen next?
Are we gonna see some something credible in terms of the AI coming out later in the year when they do phone announcements and things like that? Or set some something down the road? Are we gonna be in this kind of, um, nuclear winner waiting for waiting, waiting for things to clear before we see some AI coming, or true AI coming out of Apple?
Um, I don't know. It, it seems like they're, they're battling on a lot of fronts, battling tariffs and where things are manufactured. They're trying to catch up on ai.
They're, they're not in a good place right now, making tons of money. Wait, Mitch, you know what this right here is? That's the smallest violin in the world playing hearts and flowers for poor dear old Apple who makes billions of dollars a quarter, let you know, let, let's not quite throw dirt on their, their grave yet right now To keep, yeah, I can predict, I can predict Apple AI announcements for around the iPhone, whatever the next iPhone is.
I bought, I didn't buy my latest iPhone because of their AI announcements from last year. I bought it because the camera's better and I create video content. So you know, that the, and I'm very happy with that.
I bought it for that integration. The, but I am very much looking at Android machines, uh, sim similar to you. And I'm looking at, you know, I, I will probably go out and buy a, uh, some type of Android device.
And I think Apple needs to worry about this as the tech consumer that I am, the functionality that I want out of my mobile AI experience, apple is not providing it. Android is, and it is that important to me. Someone who's fooling in an Android in the Apple ecosystem, that I'm willing to at least for now, get a second device that, that satisfies my AI needs.
It's done. Absolutely. That's, and the last thing I wanna say on this is that Apple xr, apple Vision Pro was very exciting to me at the time.
As someone who's spent some time in that industry, and they really have an answer to what's happening next, other than maybe there's a stripped down headset, maybe it's whatever, you know, whatever. I mean, the headset gave my friend black eyes. Like it really was, there was a swing and a miss there, right?
But all they announced in that realm at South by Southwest this year was, Hey, we've got Metallica full length movie. It's an xr. So I have to wonder if the whole virtual augmented reality, uh, move for them is gonna be content.
I, I, I don't know that it's gonna be hardware. I don't think they can compete in that realm. The Oculus, all these other headsets are, you know, the vibe.
They're, they're, they're cheaper and better already. They were so late. And I would hate to see that happen with ai.
It really would. However, being the last AI is not a bad thing because you're learning from everybody else, Right? Especially right in, in a market that's as fast moving.
But that being, so Dan, you just described the real conundrum with Apple, which is where is the next big thing? It's not the AR goggles, okay. Um, the watch, and it's some nice watch features, but is it wearables?
Is it some other sort of wearable, not a watch? Is it, I mean, what, what can they do to the phone? Keith, to your point, they could every, every iteration of the phone and the Galaxy as well, they improve the, you know, the, the lenses and so forth, the, the technology.
But where, what, what can they, what's, what's the next big thing for them, Alan? That's been the question really. Since just Steve Jobs died, unfortunately.
Exactly. That's been the question. That was the sort of test, mis test.
Are they gonna be able to continue to Innovate? And Now I will tell you, they've innovated on silicon, right? I will tell you some of our video team here just got the new Apple, uh, M four Ultra studios.
They're hot, they're hot machines. What he used to do on his M1 took like four hours or six hours, now gets done in one hour on that M four Ultra. So, you know, I don't think they, let's not make it all negative.
They've done a great job innovating on the silicon. So, so Alan, let's, let's think about the sort of the, the elephant in the room, which is Johnny Ivy's departure and going over to, you know, uh, AI and to develop AI products. And I just recently acquired, um, an AI based pin for doing a live meeting recording, right?
So it does, uh, records at a meeting and then does a transcription plus an AI summary. And I found that very helpful because it allows me to immerse myself in the meeting and not focus on actually taking notes so I can have a hundred percent attention on what I'm doing. And that's sort of a, you know, that functionality could be built into a phone or could be built into some other device you have and, and, you know, and that maybe that's the direction Johnny Ivy's going with great industrial design and yada, yada, yada.
Maybe it's not. But those are the areas where AI can be really useful. And it seems like right now, either Apple's taking a wait, you see approach, or they're swinging at the fences and failing with whatever they're doing is, you know, they put a lot of effort into bringing AI in the chips on the phone, but then a no vision maybe for what's they're gonna do with that AI capability.
I think that's the disappointing part. I think combining the two ideas, the m series of processors are flat, amazing. I bought my then video editor one, three years ago, and he still has an M1 and he's still completely happy with it.
Uh, three years later, incredible innovation. Uh, I run O lama on my M two Mac Pro, and it is for local development and insing fine, which I can't say that about my latest deal with an Intel arc processor. The, the, that is I, the ecosystem is there.
Uh, so there's a lot of promising, uh, from the app, apples innovation around silicon and ability to put GPUs on system, on chips, extended battery life. There's a lot of good stuff going there, but not enough to, uh, keep folks like us happy. We want, we're pushing them, I think fa harder and faster than what we would have in the past.
So Let me postulate one thing here, and then we'll move on to our next segment. Someone mentioned it earlier, I'm not sure who. He's are very interesting times for Apple.
They're under a ton of pressure. Tim Cook is not a typical sort of Trump guy, right? He's he's not for a lot of reasons, and I'll leave it at that, they're under a lot of pressure where, you know, whether they can produce these iPhones in India, they certainly producing them in China isn't a great thing.
Big tech, you know, with the must Trump split, who knows how that's gonna go. This may be a time where the smart money at Apple, and there's a lot of smart people at Apple still, no doubt. Say, you know what?
Let's just keep our head down. Let's not try to rise above the crowd and become a target. We'll keep making our billions and keep that multi-trillion dollar, you know, uh, shareholder group happy.
And let's just tread water and see which way the wind blows here, right? And, and that might, and, and that might be the right strategy for, for interesting times that we live in. I think it's, I agree completely.
And I think Apple, under Steve Jobs taught us that computers could be magic, tech can be magic. And I think that we have come to expect that from them. And I think that's why it's so easy to get upset with them when they have announcements like this, because you're, you've been trained to expect watching.
Yes. And this is a time we could use it, and there's a time when there's magic elsewhere. We're seeing it with deep seek and other, you know, the rise of these companies overnight.
And so it feels like they should be at the forefront here, but maybe that's just not where they are anymore. No, I think they're keeping their heads low. I think there's something to be said for that.
Alan, keep your head low. You know, don't turkeys that get shot, the one they raise their head above The law. That's exactly it.
Yep. It's an old saying from our friend in Nebraska. Here go.
All right, Bucky, let's take a break here on Textron Gang. We're gonna come back and we're gonna talk vibe coding, extreme coding too. Enterprise, I don't know, you're watching Textron Gang.
Hey everyone. And we're back here at Techstrong Gang. com written by none other than Keith Townsend about, uh, scaling vibe coding in enterprise it, a CTO's guide in navigating Architectural Complexity, product management and governance.
Hey, throwing all that out, is Vibe coding an enterprise tool? Is that what you're trying to say, Keith? Or what are, what are we talking about here?
So whether or not it's an enterprise tool or not is, you know, kind of going back to our previous conversation. I remember when the iPhone first hidden, I was managing mobile devices in the enterprise, and I question, is the iPhone a mobile is, uh, uh, enterprise mobile device in early iPhone through one through three? Was the answer to that question was no.
Did that stop employees from bringing in iPhones and forcing my hand as the IT director to start supporting iPhones? No, it did not. So we can ask the question, is Vibe coding the Enterprise IT tool?
Uh, no, not today. I think generally speaking, not in the sense that we've looked at it from, you know, if we look at like the nominal sense of vibe coding, uh, me and Mitch did a podcast last week with, uh, E Eric Beke, our CTO of RUM group, and he reminded us that Vibe coding did not, you know, mean what it means today to give someone like me who's not a developer, these tools to develop, but for, uh, seasoned developers to use it. We're talking in a context of giving the tool to people like me and recreating the mess that we had in the early two thousands of Lotus Notes, creating real tools with this low-code, no-code capability that that delivers legit business, um, value, but creates this nightmare for CTOs.
If you remember needing to either maintain Lotus Notes databases, the landscape, or needing to migrate off of Lotus Notes, if you're that old, uh, uh, you, you should probably check your, uh, cholesterol one. And then two, the, uh, you remember the pain of bringing in these low-code no-code tools. And even if you've done recently RPA or uh, rapto, what the, the, these new low-code no-code tools, you have this challenge of how do you maintain all of this new code that are, that's really supporting legit business processes that become mission critical.
So first of all, I gotta tell you, Keith, I helped take a company public that was built on hosted Lotus Notes and we were doing that customer, customer. Uh, and not only that, I will tell you, Microsoft paid us $10 million to try to build a similar platform on top of exchange that would allow you to build those simple apps that everyone was using on top of Lotus Notes, right? And, and we couldn't do it.
'cause Exchange, believe it or not, just wasn't as solid under the covers as Notes was As somebody who had the support exchange. Five, five, a hundred percent there. Uh, it just was not, Lotus Notes was funny, all made simple.
The, the, the, the design that client server architecture for Lotus Notes was rock solid replication, just simply a lot of, of it was just really, it landed itself to the type of capabilities that you could do. So, you know, imagine from a workflow perspective, you can take your, you're an executive and you're on a flight and you need to reconcile some invoices, whatever the business process you do, you replicated your Lotus Notes database offline to your local machine. You made the changes on flight.
Well then when you connected back to you replicate, uh, it, uh, back, uh, to the, uh, to the data center connectivity, it replicated the changes up. So this was, you know, early two thousands before we had, you know, these modern React apps where, you know, you expect to do on the server side, amazingly simple technology that enabled the business via coding or the concept is the same thing. I can just go to cursor AI and write really complex software without knowing how to code.
And if that scares you, it probably should because users are doing it and they are, uh, uh, as I've, uh, kind of talked, talked through what the application I wrote, the CTO scanner, that, that, that was the, you know, that's the, the premise of, to be able to write, you know, pretty extensive code that uses open AI to triage RSS feeds and blog posts and then create reports and then, you know, accelerate my ability to disseminate data. Well, first of all, personal point of privilege. I'm having some serious Lotus Notes, PTSD.
So you guys need to like back off a little bit here. I took over, I took over some really bad situations. Not that I don't like it, but anyway, uh, first of all, Keith, fantastic article, but more importantly, I love what you did here, which is go on one of those journeys of trying something, in this case, vibe, coding, learning a lot from it, sharing it with us, you know, via LinkedIn and social and writing these articles and all of that.
So you're a master at the kind of that storytelling journey and sharing that. So appreciate that very much. I, I think the, the point is here, you, you, one of the things you, that you came, came to I think, tell if I'm correct, is there's really two paths we're talking about around agentic or AI based development.
There's the professional developer, like people that, this is my job, that's what I do. I write code, and then there's the end user, we might call 'em citizen developers and to your po. The, those two things kind of need to invol evolve in their own ways.
And, and you can, you can see that today because when we talk about agentic or AI IDs to throw a bunch of, uh, acronyms at us, the, the, whether it's cursor or it's using copilot inside of, you know, visual Studio or whatever, visual code Studio, it, it's, it's a hybrid interface. One side is your AI stuff that you're chatting with it and you're giving it a command. You're looking at its output, the other side's code and stuff being generated.
And generally they follow this kind of hybrid architecture. That's not something an end user's gonna gonna connect with. And even Firebase that you used, you know, from Google, relatively new, or I guess it's, it's, it's a new version of a technology they acquired.
It's still that model. So vibe coating today is really for professional developers. Not that it can't be used, but when I see articles about, you know, the CEO built an app, you know, using Cursor or built whatever, um, I don't think it's the same kind of app, even the quality of an app we would've built with Lotus Notes in the day that was made to be able to do that.
And I think we're gonna have to evolve that technology along with the professional developer Path. Well, look, there's a parallel here to the low-code no-code stuff, right? If you speak to the low code, no-code vendors Automation Anywhere, it's RPA, um, some of the others, they, they tend to, they tend to develop their product for two different audiences.
One is what we used to call the citizen developer. And some people get freaky when you say that now, but you know, the non-pro developer, Keith, great example. Technically proficient person, but not a professional developer.
And then you have low-code, no-code kind of tools for the professional developer that sort of 10 x their, their productivity. And I think, I think with Vibe coding, it's the same thing. But here's something else that I've observed over the years, and I a hundred percent believe on this.
Many technologies such as vibe coding don't come to the enterprise by knocking on the front door or ringing the doorbell. They get, they come in through the cell or the back door through the backpack, through the backpack, right? That's a good way of putting it, Mitch, I saw it happen with Open Source.
I saw it happen with wifi, right? I remember going to a, I think it was Fort Carson, Mitch out in Colorado, right? With the doum from Fort Carson.
I said, what are you doing for wifi security? And he says, we don't have wifi security problems, we don't allow wifi. And as he's saying that, I'm seeing people unplug their WP and throwing them under the desk, you know, and then soon as he passes, they plug it back in.
You know, the same thing with open source. All of a sudden, what happened to all that Unix? It's all Linux, right?
Same thing with the cloud, the whole shadow IT thing. How the hell did we get all this stuff on Amazon? I put it on my credit card.
So, so Al and I'll, I'll, I'll step in here and say at, at one time I were the head of a professional developer. And, um, you know, a software development tool is a software development tool. And if you're an old guy, uh, like me, sometimes adapting to new tools is easy.
Sometimes it isn't. Uh, I was responsible for dragging Novell kicking and screaming from X 86 assembly into modern compiled languages because the developer sent network of network did not believe that a compiler could generate FAB code that would run faster, would be better than they could. Um, so, you know, and that was still can't, you know, go play in front of your own house, right?
But so, so I look, I look at Vibe in one se sense. I look at Vibe coding as another tool, like a compiler. It's gonna accelerate your work.
Um, if you are a professional developer, you just have to understand the tool and its limitations, just like you have to do any other tool and its limitations, right? And if you accept AI generated code without reviewing it, understanding exactly what that code is doing, uh, particularly on the security side, you are opening yourselves up for a world of hurt in a sometime in the future. net or any of these other low-code, no-code environments, have a, uh, have a platform and an environment that brings with IT security and takes care of the basics so that you don't have to do that.
So you can focus on automating a workflow in one form or another, rather than worrying about how you add, how do you have a user login, or how do you do security? Or do you, you know, how do you connect to the internet and all of those other concerns that we have, the platform takes care of it for you. But I don't believe today, and I could be wrong, but does Vibe Coding actually provide that type of platform and take care of the basic concerns for you?
Y yeah, so Jack, you're, you're hitting kind of the, the cliff that I came to when it came to using via coding in my role. And I don't mind the term citizen developer because, you know, whatever, but, uh, I got to a point where I wanted to have refactored the application from a Python. What was, we essentially started out as a Python, uh, script and had evolved.
Our good friend Steven Floki said, Hey, Keith would be great if you put a web interface in front of this. And that sent me down this horrible journey of needing to create a backend, uh, the, and then, you know, it went from a simple, uh, Python flash-based architecture to me now needing to look at React. And now I'm bringing in Firebase because there's all these backend decisions that you have to make, and you could easily go down this route, route route of saying, okay, I'll, I'll deploy a Kubernetes cluster for a, uh, for a, uh, a scanner that's meant to run on my laptop.
So it is, and when you're not a knowledgeable developer, if you're not a knowledge, you can be a knowledgeable front end developer and just not know backend stuff. Like, I want to use Google authentication for this. I want to use, uh, some type of, you know, what am I gonna use per persistent storage?
How am I going to secure that persistent storage? All of these decisions that you have to make on the backend, there's no plat those, there's no given platform out the gate for Vibe coders. If you're knowledgeable and you say, oh, I can use Heroku, I can use Firebase, I can use all of these past platforms to make these decisions for me.
And they're still decisions that need to be made that's beyond the skillset a of a non-developer. So you're saying we're gonna have citizen Kubernetes, is that what we're gonna have? No, you're you both that some bad is the name Vibe coding Mitch?
Yeah, no, you're, you're both are are spot on on this point. Uh, there are two parallel paths. Um, uh, different Keith, Keith Kirkpatrick and I are analyst at Futurum and I are working on a project together of talking to the, the low-code, no-code vendors about their path of how they are, uh, moving to a vibe, coding or whatever you want to call it.
But they're introducing AI driven capability for building apps. And to your point, Jack, it's very much, I have a platform that we do these things. I have constructs of, here's a, whatever we're gonna call it a method or a, a connection thing or some functionality that that's packaged in a, in a piece of capability that they put together in the UI that they used to build the applications.
That's a different way of coding, if you wanna think of that. You can call it coding still. That's a different way of constructing software.
And there are a lot of things that come with it. The security that comes with it, the backend connection to the data, whatever it might be. You still may have to work with a professional developer IT person to get some of those other things done with you, but you could do most of it yourself.
And so they're, they're taking a different path. 'cause they've gotta preserve that customer base and their skills as they move into more AI based development or driven development. Software development is different for software developers.
They're using development tools there. There's a reason why the code window sits right beside the AI window. It's because you'll look at the output to see if you like the output.
You believe it. And in your experience, Keith, of Yeah, but there's a whole bunch of other stuff I have to take care of to really build and deploy an app and, and your, your app, you know, you didn't take on building a massive enterprise app. You took on kind of a practical good example of what does it take to build an app.
So when you had all those decisions to, to make, so it's, right now it's two different paths. Maybe they converge someday, but I don't see them intersecting anytime soon. But, but here's, let me give you a shims law for this one.
Shimmy's Law, you know, we used to think about internet time, right? Time crunch that the internet brought on. We, we, we live in an AI time crunch now, right?
And, and so look, it was just two months ago, three months. When did you first hear the term vibe coding with ai? Was it three months ago, four months, months ago?
It was in, it was Invented in January. It wasn't that long ago when we first started talking about it, it was a bit of a joke. Hey man, feel the vibes.
You know, we were doing that hippie dippy weatherman thing. Yeah. And no one thought you could do anything with it because AI turns out crappy code.
They said, and now here we are having a, a legitimate discussion about what we're gonna see at the enterprise level with Vibe code from January to June. Where are we gonna be in December? Well, so it's, it's that internet time that always bothers me in that from a professional for professional coders there, and I've maintained this for years, that one of the reasons we don't have good security in our applications is because professional coders are compensated on feature functionality and schedule, and they're not compensated on building secure apps.
And this vibe coding and the desire to move fast, you know, uh, go fast and break things means go fast, break things in the security sense more than anything else. And until developers are compensated on building secure applications and the tool support building secure applications, we're gonna have a, you know, we keep, me and Mitch and others successfully employed for many, many years talking about the lack of security in every application that comes out. You know what, I used to think that way too.
Two, right? Then I got a seven step program, because here, here's the deal guys. Have any of you ever met a developer who raises their hand and says, I like producing s****y quality code.
I don't really care about security, I don't care about quality, I don't have pride. You are right, Jack. The compensation is keyed into how many lines of code they develop, how fast they got stuff that's releasable.
But I think with the advent of DevOps and DevSecOps, the, we don't call it security per se, we call it quality, but the advent of quality code that has fewer bugs, fewer security issues, is something that developers take pride in and that organizations are moving forward with in terms of saying, that's the code we want, right? Because it's a lot cheaper for us to fix it there than later on. It's a lot better for us if we have better quality.
We gotta, maybe it's the testing has gotta improve, but I think we've done a good job where we no longer are in the world where, where we can say, developers don't give a crap about security or quality. They do. I, I, I, I don't, it's not that they don't give a crap about it, but it's that because of how companies operate, given a choice between taking longer to add or to validate the security or meeting schedule and adding new features, they tend to be forced into adding new features and meeting schedule and not to focusing on how do I validate the security?
And it's not a developer issue, it's a, it's a, it's A system. It's a system and a compensation that value it's cost relevant values completing, you know, like I said, schedules and functionality over security. And so my, you know, my concern is that vibe coating reinforces that issue of accelerating the schedule and doesn't be.
And because this is all LLM based, it's non-deterministic. So it's not easy to, to gen repeatedly generate high quality, high security code. Let me ask you a question though.
Can we get another bite at the Apple by somehow making vibe coding develop more secure code? Maybe we could build something into the model there, Keith. So vibe coating can create, uh, and if we're thinking about vibe coating from like putting it in the professional's hands, vibe coating absolutely can result in more secure code.
Both talking to every Eric that key who uses vibe coding in his everyday software development, um, uh, lifecycle. I talked to Brian Lau, who's a principal, uh, engineer, or, uh, principal architect software architect at AWS. They're creating hundreds of unit tests to test their code.
So, and that's from using quote unquote vibe coding to do this. So they're able to test their software more than they could be than before, than when they were using Vibe coding. So this is an example, are we thinking about these tools?
So, you know, we uplevel to the CTO conversation, are we thinking about these tools the right way? Are we using it to accelerate our processes to, uh, uh, write more secure code to improve our CICD processes so that these unit tests are created automatically and then are testing our code and, and putting more rigor to the, to the process? So these are, you know, things that were just, again, the term was just coined in January to both you and Mitch's point that we are in a place that we're not quite sure where we should be using via coding in our software development lifecycle.
Whether or not we should be getting, giving these tools directly to, uh, end users or if we should be using this to improve our own software development, um, processes. I seem to remember this conversation happening a long time ago in the late nineties, early two thousands, and we called it Extreme Coding. It was a, it was a predecessor to Agile, but the difference was that it was focused on teamwork, para programming, and rigorous adherence to standards.
It was all about a team doing things and think about how many developers it took to do what it takes to do one today, right? But the similarity to me, to vibe coding is the sort of excitement and the way people talk about it, you know, that it's like, we're not just coding. It's a vibe.
It's a, there's a buzz to it, and it's like, we're doing more than just coding here, guys. We're extreme coding. And so I remember it being used because I was working in startups then, and I was a developer then.
And I remember it being used as sort of a way to like, put guardrails on for certain developers that maybe weren't as good, or maybe there was an issue with performance or language barrier, whatever it was, they were coupled together with teams. And I can see this happening with Vibe coding. I can see it being used as almost like a guardrail of, well, check this, check this.
It's gonna be like a babysitter in, in, in a way. But I, I mean, it just, to me conceptually is, is so fine. It's not really the same, but just this sort of buzz about it that we're doing something new and really we're, it Is the future, the productivity's there.
All right guys. We are, we are extremely late on this segment though, so I gotta pull the plug on it. If you wanna read it.
Mitch mentioned great article by Keith. com. Go check it out.
We're gonna take a quick break. We're coming back for our C block. It looks like we've got some new executive orders, undoing some security stuff.
Jack, I'm sure has some opinions on it. You're watching techron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients, let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey everyone, we're back here on Textron Gang. It's been an interesting show.
It's gonna wrap up with our C block for today, and that is a couple of, uh, a new executive order came out of the White House. I guess it wasn't signed by a robed, but anyway, uh, this one takes aim at some previous policies and executive orders. I dunno if any of 'em were congressional actual laws under, uh, the Obama and, uh, Biden administrations around some site, uh, cybersecurity regs and, and some enforcement around hacking and especially around elections and stuff like that.
Jack, what's your take on it? Well, I think, uh, you know, this is not a brand new order. It's really just tweaking the, uh, the previous orders and, you know, the last order that came out was by the Biden administration, but it was just four days before he left office.
Um, so I'm sure it was long in the making, but it, it was sort of like, let's throw this out there and, you know, at the very last minute. So I think that sort of raised a few eyebrows. This executive order appears to tweak some of those things in there, one of which is related to digital IDs.
And given the Trump administration's focus on illegal immigrants, there's a desire to ensure that, uh, digital IDs aren't being used, you know, aren't being encouraged to be used by people who are, aren't legal residents of the country. Um, so that was one area. And then another area had to do with reducing, um, essentially the administrative burden by removing the, uh, requirements to go through the whole, um, sec uh, process of documenting that you go through a secure software development process.
And I, I, I tend to look at that one as similar to the old ISO 9,001, um, documentation requirements when SO 9,001 originally came out, um, it was touted as something that increased your reliability and your quality of production, but really all it was was documenting that you had a process, process could be absolutely horrible and could be, hey, if the, you know, Joe Blow puts his, you know, tongue on the battery and sees if the battery struck, not if it is, but goes out the door if it doesn't, you know, so the bat, the, the quality, the, the process didn't have to be good. You just had to have a documentation for it. And I think right now, that's where we are with a lot of the, um, requirements by the government on software security.
And so I'd like to see us really focus in more on producing, understanding what it means rather than just documenting our existing processes. So for me, the big thing was around the, uh, removing sort of sanctions and teeth from non nation state threats. So certainly, right?
We need to be vigilant from Russian, Chinese, north Korean, Iran, whoever the enemy of the day is threats. But we need to be equally vigilant about any threats to the integrity of our electoral system, to the functioning of our government critical infrastructures and so forth. I think when you start saying we have one set of rules, if it's coming from a nation state versus not a nation state, that that's nonsense because the nation states generally, when they make these sort of attacks, they're not flying flags, right?
The PRC has groups in Beijing that, you know, they're not officially government, but there, there's a wink and a and a handshake, and there are groups that do these kind of things. Same thing for Russia. So, and you know, and, and when sometimes we have a hard time, it's more speculation than fact about how much support certain groups do get from a particular nation state.
Here. Here's my concern about it, Alan, is that given it's tied to not all, but, but in part election security, we all know that's a highly charged political issue. It could derail the focus on cybersecurity in other areas while were these maturations around, you know, is the next election secure or not?
And did we do the right things, whether we knew what the right things to do or not, when really there are, are, are other areas that equally, if not more need attention. So it, it in some ways, to me was just a way that this could become even more, um, Chris Krebs kind of situation, politically charging, you know, cybersecurity around the election part of it and masking over issues in other areas. Well, Speaking of our friend Chris Krebs, Mitch, that was my initial take on this, was this simply undertaken just to poke Biden and Obama at regular error regulation.
I think that may have been part of the motivation, but there's also another way to look at, which is a number of cybersecurity researchers doing valid research to understand the lack of security and the security issues in some of our tools and applications. And government services could be caught up and treated as nation state actors and treat. And this does provide the government more flexibility to separate out semi legitimate or legitimate activities from illegitimate activities and not bring the hammer down.
Yep. Guys, I need to pull the plug on this. I apologize, Keith, Jack and Mitch, it was a great discussion.
Today. We, we come back to the eo, we'll see how that plays out, but we're at the, we're at time. Thank you all.
Thank you for watching. Stay tuned for Text Drunk tv. We've got a full text drunk TV schedule following.
Until next time, this is Alan Shimo for the Gang. We're out. Hi everyone, I'm Alan Shimo from Techstrong and welcome back to our continuing series discussing Software Insecurity with our good friends at Adobe.
My guest for this episode is Brian Payne. Brian is the VP of product and software security at Adobe, and let's welcome him. Hey Brian, how are you?
Doing well, thank you. Thanks for coming on here. Brian, VP product and software security.
Sounds like an awesome job, but tell us a little bit about kind of your journey and how you view your role. Sure, absolutely. So my role here at Adobe is to oversee the security of all the software we produce, and that's our products and all of our in-house software tools as well.
Um, and I'd say, you know, I got here throughout my career just focusing on security and software over the years. Um, I've been with the government, I've been in academia doing research, and, uh, I've spent the last 15 years or so in the private sector here. Excellent.
So Brian, you know, a lot of people say Adobe, they're not a security company. Well, you know, to, to paraphrase Mark Andreessen, every company's a security company in today's world, right? 'cause we all, we're all potential targets, but when you're Adobe, you have a particularly big target on your back because you represent such a wealth.
It is a company that, you know, probably 99% of the global 2000, if not more use Adobe products in one form or another. And, you know, in a, a, a case of kind of eating your own dog food, Adobe Pie has pioneered many, uh, security innovations and things today that we kind of, you know, take for granted or is just, you know, best practices really kind of found their way out from adobe's own internal practices on securing your software that everyone uses. Yeah, so we do a lot of work in-house without being a security company, of course.
Um, we focus on the security of what we build. And so, um, while our, our customers are focused on the creativity and the, the amazing things they can produce using our products, uh, we wanna make sure that all of their information continues to stay secure and they don't even have to worry about the security elements. It's just in the background for them.
And a lot of that requires us to innovate along the way. Absolutely. Now, Brian, of, of course, we've, you know, we've entered into the age of ai Sounds like a, an old song.
It's not Aquarius though. Um, and it, you know, whether you buy into the whole AI hype or not, it certainly is changing the way things are being done here, you know, from in every aspect. It, it promises all kinds of disruptions.
Um, and, and ai, quite frankly, those of us in the security world, world, it, it's kind of a shield and a sword, if you will. Right? Unfortunately, it is for the bad guys too, you know, that's always the case in security.
Um, so, but you know, the topic of our short discussion today is maximizing opportunities as well as minimizing risk ways to leverage AI for security. If you wouldn't mind, again, without giving up trade secrets, or let's not get us ourselves in trouble, talk to us about, you know, lessons learned at Adobe, some of the things you're doing, some of the things you're trying, some of the things you're thinking about along these lines. Yeah, so you're absolutely right that AI can be used by, by anyone.
Uh, it's a tool and you can use tools for, for good and for bad. And I think, you know, in the security world, we're keenly aware of that, that history. That's always been the case with tools.
And so, um, one of the things that I see is that it's important for us to, uh, be able to understand how to use them and stay ahead of the curve so that, uh, the, the attackers are not getting the edge, right. Um, at the end of the day, we find that it's very useful to help us scale. Um, I've rarely run into a security person who just feels like they have so much extra time in the day.
Um, and so, so the ability to, um, take care of some contextual generation, uh, help us learn faster, help us get to the key points faster, and then let people do what they're best at, right? Using their brains to solve those security problems. Um, that's really the key for us.
And, uh, and it comes out in many, many ways throughout our work. Absolutely. Um, so if you don't mind, Brian, let's, if we could dive, peel that onion back a layer or two, how, how does this manifest itself?
What are some of the ways you're leveraging AI to make the Adobe product line secure? I'm sorry, go ahead. You know, we look at different code bases all the time.
If you think about the number of software projects happening at Adobe, it's a common thing where a security engineer needs to look at a code base that they've never seen before, and then come up with an assessment of what security work might need to happen around that code base to make it even stronger. And, um, that can be a challenging pro process to wrap your head around this, but AI has proven very useful. Um, you can just ask at things like, what end points are gonna stand up when I start this code base, right?
Uh, which functions receive untrusted user input? Um, it can help you navigate the code in a way that gets you to a destination much more quickly, um, which is fantastic. It doesn't mean that it's, it's necessarily replacing the human in these things, but it augments them and helps them work much faster, which is really wonderful for, for our threat modeling work especially.
Um, some other examples of things that we've done, um, think about network scanners. Uh, you often need to stay up to date on the latest CVEs, the latest, um, proof of concept code to be able to make those scan templates and to know, you know, which systems on your edge might be vulnerable to the latest vulnerabilities. Um, so we have found that AI is especially effective if you can point it at, um, you know, public information about these things.
Um, it can turn around and create those cancel puts rapidly for you, allowing you to more rapidly find those places in your ecosystem and ultimately more rapidly solve the problems of fixing them. We also use it, um, internally for developers. Uh, we like to give them as much information as we can around the security problems that we find in code and help them to fix them quickly.
And, um, we have found that it's much better to provide some context around this is how we think it should be fixed. Um, this is the best practices around fixing it and those things as opposed to just saying, here's the problem. And in those situations, um, uh, gen AI is actually pretty powerful at being able to, um, put together some of those recommendations so it can actually go into our Jira tickets and augment them, um, so that people can get additional context around the best practices for their fixes and, um, and ultimately get to a, a faster conclusion on them.
Excellent. Brian, everyone today is talking about agentic AI and AI agents. Oh, yeah.
So Adobe, we're, we're definitely looking at, um, different ways that this can play out. Um, we have, uh, been exploring code generation, um, using some Magen AI systems. And one of the interesting things in this space is that, uh, you, you can ask it to help you make code, um, and sometimes it does it in a way that's very secure and sometimes it will miss a few things like, um, like path reversal vulnerabilities or SQL injection.
Maybe it doesn't quite do the right filtering on that input. Um, but what you can do then is you can actually tell those systems, here's some additional guardrails I'd like for you to consider before you generate that code. And then all of a sudden the code that it generates, it's the bar is raised in terms of the security quality of the output.
Um, and a world where more and more code is likely to be generated by a I year over year. If we can get ahead of that curve, and if we can actually, um, ensure that that code is more securely written than what a human would've done, then we can actually move the needle on security over time. So I'm very excited about, about that space and where that's heading.
Um, we're also using it in, um, more of a chat bot situation, right? So, um, someone can come into our team and ask questions around, Hey, what's the best way to protect my password? Right?
Or, um, you know, any sort of question they might have. And a lot of these things are actually written up as internal policy here at Adobe. And so it's pretty straightforward for AI to be familiar with all those policies, look at the question, match it, and then respond for them.
And, um, that allows us to get answers back to the workforce much more rapidly than, uh, than having a human in the channel all the time. And we can go back and, of course, double check do we think it gave the right answer and then kind of train it over time in the cases where maybe it missed. Got it.
Um, Brian, look, you and I have both been around the software world for you many years, and we're all familiar with the hype cycle. What about for my doubting promises out here who say, you know what, yes, there's a lot of promise, but today not so much. If I had to, you know, kind of put your, your finger to the, to the thing and say, Hey, Brian, are you really using AI for security today at Adobe?
Is it really helping you? How would you answer that? So I've seen many people doubting in this space.
I think I am a bit of a healthy skeptic myself, but I will say that, um, I have seen the results as we have played into this space. Um, it's, it's not magic, right? You can't, um, completely replace what humans are doing in the security space because the very creative endeavor, as we all know, at the same time, the the kinds of things that it can help you with and the way it can, uh, can get there faster.
Um, we can't ignore that, right? It is happening on the ground today. And so for anyone that's, that's maybe a little bit skeptical, I would just say go spend some time playing with it.
Maybe talk with some others that are having some success and see, um, why are others excited when maybe you're not? And and I think you're gonna start to realize there are, you know, if you find the right use cases, there are places where this is extremely valuable even today. One last question for you.
Based upon what you've said, would you say that AI is critical to Adobe security strategy go today and going forward? I, I think it's critical in so much as the fact others are gonna be using it against us. We talked about the attacker element earlier, and so, you know, security has always been this cat and mouse game, this back and forth, and I think we would be naive to continue forward using all of the techniques of yesteryear while attackers continue to progress.
And so, yeah, I think it's very important that we use this to keep up. Um, and also, you know, like I said, to, to scale out the, the work we can do, if you can touch more of the surface area of, of the company, then you can keep it all a little more secure, which is obviously a great outcome. Ai, the newest weapon in the security Cold War, huh?
Crazy. Bob. Uh, excuse me, Brian, thank you so much for, for, uh, coming on here today For people who maybe just want to find out a little bit more about Adobe security in general and maybe about how Adobe's using ai, uh, you know, for security, where, where can they get more information?
So I would say definitely, uh, you know, enjoy these episodes where we're gonna talk a little bit more in depth about our work. Um, we also do often speak at conferences, uh, in the, you know, the technical conferences throughout the community. Um, probably too numerous to list, but I would just say keep an eye out for, for Adobe at your favorite security conference.
We are quite often there, so Absolutely. Brian Payne, VP product and software security of Adobe here. Thank you for joining us, Brian, and keep up the great work.
Thank you, Alan. It's been great. Alrighty.
Hey guys, thanks to the throw, we're here with Dane Sheret, who's staff innovation architect for Hacker One. And we're talking about a new report that they have about, well, just how secure are all these AI platforms out there? And well, you might surprise you, but it varies.
Hey, Dane, thanks for coming to the show. Glad to be here, Michael. So walk us through the high points of the reports a little bit and kind of call out the things in here that you know, leaped out at you.
Yeah, happy to. So, uh, for your, as many your listeners may know, hacker One's been a bug bounty platform for over, uh, over a decade now in helping, uh, organizations manage their cybersecurity risk. Uh, but obviously AI being as disruptive and important as it is, more and more organizations are starting to adopt AI tools and make, uh, AI applications available to customers.
So what we've been noticing is an uptick in the types of vulnerabilities and, um, and things that can happen when, uh, and it kind of risks that type of, uh, uh, those types of applications introduced. So some of the key takeaways is just how much of a, uh, uplift that AI can be for organizations that are using it to, to manage their risk, but also the types of vulnerabilities it might introduce, right? So types of, um, uh, it opens up new types of attack vectors, and what we've seen is a, uh, so we've seen 171% increase in AI assets being added into scope, and, but that also includes, uh, increase of data leaks and unauthorized, uh, AI use.
Uh, and, uh, only 62% of organizations feel confident in their deployment of AI risks from their deployment of AI applications. What constitutes an actual bug versus when I look at a lot of these tactics and techniques being used, it almost seems like, you know, people are kinda abusing credentials and identities to gain access to them, but I don't really consider that a bug as much as I do just a flawed implementation or a misconfiguration. So how, how do I draw a line between those things?
Yeah. Well, so I'll give you an example. There's, like, I would say, I would sort of bucketize the two types of customers that are using Hacker one to test their AI systems.
Uh, one is probably the most common, which is organizations that are using, um, that are basically just building on top of existing AI models, right? So they might have an AI powered chat bot or AI powered assistant, and that AI powered assistant is able to, uh, read information in the backend of the sy of the, of the services, or maybe it's able to take action on behalf of a user, uh, an AI issue. There could be, if I as a malicious actor, actor or attacker could get the AI system to change your password, or I could get it to give me information about your, um, about your accounts, or I can use it to exfiltrate data from the backend or, or run code on the backend.
So those are the types of like security vulnerabilities that we see. But we also work with leading, uh, frontier Labs like anthropic and helping them actually make their models safer. So, as an example, uh, we do a lot of public work with helping philanthropic test their model against, uh, CBRN risk.
So what I mean by that is, uh, they put in a lot of guardrails and protections to make sure you cannot go ask Claude, how do I make a bio weapon, right? CBRN standing for a chemical, biological, radiological, or nuclear, they put a lot of protections to make sure you can't get that type of information out. So we actually host, um, bug bounty programs or red teams to go test these models and see if those, how those protections fold up and if someone is able to use a jailbreak to get that, that kind of harmful information out of those.
So I I I, I would say diff different buckets, right? So we have, uh, the customers that we helping just secure against standard security risks, right? And the AI is just sort of like a new technology that's on the backend that has new attacks, and we're helping customers sort of navigate that landscape.
And then also helping customers that are trying to navigate like the safety aspect of things and making sure they're not, you know, uh, putting out, uh, dangerous information about bio weapons, or maybe they might be concerned about reputational or legal risk, uh, based on having a, a external facing AI model, um, putting things out into the world. So how susceptible are these AI models to the same vulnerabilities and flaws that we see in regular software? Because last time I checked all these models were built using the same kind of core components that we used to build other applications.
So, um, frankly, won't the same issues just exist and we'll just have a higher level of risk attached to 'em? Not great answer, but I would say yes and no. So the, the way, the way I like to think of it is, um, you know, 10, 20 years ago, people were building applications with SQL databases and you had to worry about an attacker performing a SQL injection, right?
Is someone able to put malicious comments that could be confused as SQL commands or malicious, uh, code or input that could be confused as SQL commands and could, could hurt the application? Today, increasingly, we're seeing people put, um, build applications with LLMs in, in the backend. And now instead of SQL injections, you have to be worried about prompt injections, and you have to be worried about malicious actors, uh, putting in inputs that could be confused as a, uh, prompts, uh, to the, uh, to the backend.
So in some of those ways, it's very, very similar. And some of the same principles for mitigations apply, uh, just as with SSL injections, you need to make sure you sanitize input. Same thing with prompt injections.
You need to make sure that you're, you're sanitizing input, you're, you're preventing people from executing code on the backend, making the, the backend system behave in a way that's not desired. All, all that kind of stuff, um, where it's slightly different. Uh, and, and the new sort of fun frontier that we find ourselves in is the, uh, these AI systems are aren't deterministic, right?
Like, you know, with, with most code traditionally you put in one thing, you always get out, you put in x you always get out y with LLMs or these, these, uh, types of systems, uh, it's probabilistic. So you put an X, you, you're, you'll probably get Y, but you might get Z, you might get w you, you don't actually know 100%. And that makes, um, the, the securing aspect a little bit more tricky.
Uh, and then there's also, again that, uh, what I, what we, we kind of call like the safety risk, like the, the types of reputational or illegal harms that might come from these types of applications being out in the wild. Uh, famous example, uh, everyone's probably familiar with is, uh, air Canada, right? They had one of these ai, uh, chatbots that pe that, that their users could, could use to ask questions about or be informed about policies.
And the, um, the chat bot hallucinated to one user, a, uh, bereavement policy that didn't exist, said they could get a refund when they really couldn't, uh, user was understandably upset, sued, and the court found that the, that Air Canada was liable for what this chat bot said, right? And they, I, I forgot what the, the final case was, but didn't have having to pay money to that user. Um, so that I think is a good example of like sort of the reputational or legal risk that could happen.
And that's another, uh, aspect of, um, something we're helping, uh, customers, uh, deal with and, and test for. So on the B bounty programs that people are creating different than the traditional bug bounty programs, 'cause it sounds like the, the issues are slightly different. And so how are they going after this, or how are they encouraging that community to kind of pay attention to this space in a way that scales?
Yeah. Well, so bug bounty is a magical thing, right? It's essentially there's people with the skills that are out there, and it's, it's more of a matter of like, how do you properly incentivize them to use those skills or to learn those skills or to develop those skills in a, in a way that's beneficial to you.
Uh, so there are all, again, a lot of similarities and just a couple of key differences. So for organizations that wanna launch these, that want to include these types of, um, assets in scope, which again, is, we've seen 171% increase in, uh, organizations adding these types of, um, these types of assets into their existing bug bounty programs. Uh, you know, you obviously want to indicate to hackers that you're accepting these types of vulnerabilities, uh, indicate how, how, what the, um, amount you're willing to pay and like what you expect, what a hacker could expect to receive if they find a critical issue, versus a if medium or low severity issue, that kind of thing.
Um, where I would say there's like some key differences is, uh, I'm increasingly encouraging customers to take a more of a white box approach versus a gray box approach, or take more of a gray box or white box approach versus a black box approach. What I mean by that is instead of just saying, Hey, here's the AI system, go see what you can find, uh, for your bug bounty programs, I think it's increasingly helpful to actually tell hackers, tell security researchers, Hey, here's our AI system, here's what it's connected to. Here's what we have going on in the backend.
Um, here's what would be like the most impactful for us. Here's what our threat model is essentially, and help to really guide researchers because each of, like the, a AI LLM chat bot that's used internally for generating code has a drastically different threat model than a, uh, image gen generating, um, content generating, uh, LLM or content generating AI that's used in like a social media platform, right? Totally different users, totally different threat model, totally different, uh, harms that could happen.
So you wanna make sure your accountant for that and how you, uh, present it to the security researcher community. Well, we use AI models and agents to go discover bugs in AI models and agents and where, what will be the role of the human hacker in that equation? Yeah, well, so we're actually starting to see that more and more, uh, more researchers are, uh, increasingly using AI to help them with, like automate some of the toil.
Uh, and there was a, a blog post recently about a, uh, a researcher that just found a zero day, uh, using, um, just chat GPT outta the box. So I think what there's, what we'll see in the short term, and then there's what we'll see in the long term, uh, short term, I think we're gonna increasingly see, uh, security researchers use these tools to make them more efficient, to help them, um, do some of the, maybe like not as sexy sounding things, but like help them understand large lines of code, help them, um, develop proof of concepts, help them better communicate the impact, help them. Um, again, I identify key targets and things they need to, to look for.
And again, sort of sift through a lot of the, the noise that might be out there in their data, uh, and their, their kind of reconnaissance they're doing when they're, uh, picking a target and really distill down to what they should, uh, what they should really focus on, um, long term. You know, it's, I feel like it's sort of dangerous to make long-term predictions about it, about ai, but I will say, I think, uh, in the long term, it might very well be possible that, that a lot of the most bugs are now are then found by ai. And then there's just a very small subset that, uh, of zero days or very, very novel and elusive types of bugs that you sort of need the human creativity elements that's able to, um, again, still probably leveraging AI to some extent, but is, um, largely I think that the, for security researchers and just people in general, uh, this kind of work will look more like a, like orchestration than, um, than today where it's someone doing the, the security research end to end.
So how good are the bad guys getting at kind of discovering vulnerabilities in these AI models? And, um, how often might we encounter something that feels like, you know, a zero day vulnerability versus something that we've kind of known about, whether it's prompt injection or SQL injection to your example. Um, 'cause it seems like this is all, you know, undiscovered country.
So is every vulnerability kind of a zero day vulnerability? I don't know. Well, yeah, so I think, I think, you know, we're, cybersecurity is almost always sort of a cat and mouse game, and I think we are increasingly seeing, um, seeing malicious actors make use of these tools, right?
Uh, specifically when it comes to things like social engineering or writing incredibly, um, incredibly, uh, uh, convincing phishing emails, right? So like, now everything can be a, a spear phishing campaign, right? Because you have the ability to just constantly generate very bespoke types of content and the native language that you're, you're targeting.
Uh, I think there also, this will be an uplift in capabilities or, so everything I said about like ethical security researchers also applies to unethical, um, folks doing security research and, and their ability to quickly understand code quickly, uh, develop proof of concepts quickly, uh, iterate on things. Um, and there there have been reports of, uh, of, of various threat actors sort of using these tools, again, for things that don't sound that sexy, but really are like impactful with, um, with, with distilling down information, with writing phishing, uh, emails with, um, with regard to like helping understand targets better. So I think it's gonna be uplift for attackers, but the good news is it's also a, uh, uplift for, for defenders.
So I think it's, again, it's just gonna be sort of that continuous cat and mouse game we've seen for, for decades. All right. Otherwise known as the proverbial alarms race.
Yeah. So what's your best advice to folks as they kinda invest in ai? I, I kind of feel like we're seeing the same thing over and over again where we have an emerging technology and security is once again, an afterthought With any emerging technology or any technology in general.
Uh, if, if you're charged with securing it and, and, and, and making sure it's deployed safely, uh, I think all risk management starts with the inventory, right? So the fir the best thing, first thing you need to do is actually sit down and jot, jot down a list of your, uh, concerns of what your threats are of all the possible things that could go wrong, right? This sounds very simple, but it's, I, I see enough organizations maybe, um, not thinking about this.
And, and, and in particularly this way, I think starting that, starting and making your, your list and making your threat model and then starting to implement mitigations that would, uh, hopefully protect against the threats that you've written down, right? Actually implement things that could help you make sure that those, those nightmare scenarios don't happen. And then once you have that go test those mitigations, go kick the tires on everything that you've implemented to prevent those nightmare scenarios, and then you will hopefully and likely find flaws and things you missed and, uh, like gaps, and then you go plug those gaps.
And then I think it's just a matter of rinse and repeat. So this is true of ai, this is true of, uh, you know, crypto, Web3, quantum, uh, any kind of new databases, whatever I think it is, some of these same principles still apply. All right, folks, I heard it here.
Even in the age of AI fundamentals still matter. How about that? Hey, Dane, thanks for being on the show.
Thank you, Michael. Great talking you. And back to you guys in the studio, to you.
Hey, everyone, welcome back here to Techstrong tv. Um, we've got two guests for you today, not just one, two guests here to talk a little bit about Anchor and SBOs and Lions and Tigers and Bears. Oh my.
Um, let me introduce you to Neil Levine, who's SVP of Product at Anchor, and Alex Reback, director, product Management at Anchor. Hi, Alex Neil, welcome to Textron tv. It's great to have you both on here.
Thank you for having us. Yep. So, Alex, if you don't mind, let's start with you.
You're Director of Product Management at Anchor, but, uh, give us a little bit of kind of your, you know, your journey, how you came to be, uh, here at Anchor in this position. Yeah, absolutely. And, and I'm, I'm a newbie here.
I've different at Anchor for about four months now. Um, but I've been in the space for almost 20 years. Um, started off in the early two thousands when I was just kinda starting my career and got pulled into a team who was looking at these things called open source components that nobody really understood.
And what are you allowed to use, what are you not allowed to use? Uh, security really wasn't a thing yet that people were concerned about, is mainly, you know, are we gonna have a GPL violation? Is somebody gonna prevent us from selling software?
So this was 2002, 2003, somewhere around there. Uh, then left that startup and joined a company called Palomita back in 2006. Uh, black Duck and US were the first two to market in this new space called Software Composition Analysis.
And I've kind of run the gamut on roles. I worked in services for a while, so I was actually using our product to do audits for customers back when, you know, our library had 10,000 components and code bases were in the tens of megabytes. Um, and I've kind of gone from services, did some pre-sales work, and landed in product management, uh, around 2009.
And I've been focused on the space ever since. Uh, so EDA got acquired back in 2016. So I got an opportunity to work at Flexera where it was a much, uh, bigger company, um, much more different challenges, right?
So I got to start up an open source program office, got to set our policies around licensing and security. So I got to experience a lot of what our customers experience and the challenges they had, which, you know, allowed me to feel a little bit of pain for what our customers do, um, and then bring it back into product and improve the product there. So, um, I came to Ancor just a few months ago, really, because I spent most of my time on the dev side of SEA, so focusing on software producers, whereas ancors Strength was really around the scanning things as they're making their way through Lifecycle, and then ma um, monitoring and then production.
So it was interesting to switch more into the container world and, uh, cloud security from kind of, you know, the dev side and as developers are building software. So, so it's, You, you, you did the, uh, salmon against stream, swimming against upstream. They're shifting, right?
Oh, yes. When other people are looking shift left, Yes, we shifted for without leaving the left. So yeah, right here, we got both.
Good For you. Love it. Neil, let's turn to you.
What, give us a little sense of your journey. Uh, so 10 years as a sort of a, doing technical roles as a CTO of a, a large service provider in Europe. Um, you know, this is back in the mid nineties when you did everything right.
You did systems administration, is what it was called then network engineering coding. There wasn't really much of a distinction back in the back in the glory days of the internet. And then I shifted into the, uh, vendor, uh, world in the mid two thousands.
I worked, uh, for Canonical, uh, you know, the sponsors of the Ubuntu project, uh, looked after a TU server and Ubuntu Cloud, um, then moved over to the Bay Area, did some startups, one of which was acquired by Red Hat. So I spent a number of years at Red Hat in, uh, one of their, uh, divisions and, um, you know, got to see open source done at scale in a, you know, one of the most successful sort of commercial models around. And then joined Ancor, uh, almost six years ago.
Um, so, you know, have, have was drawn to the, the security space and what they were doing particularly around cloud native. So I've been using and working with open source, I mean, really since the mid nineties I was always deploying it and using it. And I know back in those days, nobody really cared about security too much.
And so it's been interesting to see the evolution of open source go from this sort of curiosity to this incredibly exciting, uh, industry, um, to now what I think everybody is kind of frightened of it. 'cause they sort of feel it's everywhere and it's filled with security holes. So that was kind of what attracted me to an was to sort of show maybe clear up some of the mess that had been left behind for the past 20 years of breakneck, um, uh, development and use of, uh, open source.
Yep. So interestingly, you know, my background is security and open source as well, and I've also been in it, Alex, I'm a little older than you, so I've been in it a little bit longer. But, you know, I remember when SCA first became a thing, right?
All of a sudden we had a separate scanner just for the open source components. Yeah. But, um, it, it was really filling a hole that we all knew was there for some time already that, you know, I I, when I first got involved in software, the prevailing attitude was, well, of course open source is more secure than commercial or closed source because it had a thousand sets of eyes on it, right?
And, and that was a bit of a fallacy. Yes, there might have been a thousand sets of eyes, but it's like the old searing, the old saying, you could hear, but you don't listen well, you might be able to see, but you don't watch, right? And, and so even though the open source soft, uh, the open source code was there for everyone to look at, how many people really looked at it, especially from a security point of view, um, you know, and then as often things do happen in our, unfortunately, in the security world, takes a good few breaches and incidents for everyone to get religion, and then all of a sudden, you know, there really is a God and we had to do something about it.
Um, let's talk about Anchor though, because both of you have taken slightly different paths to the same place. And obviously there must be something about the anchor story that have attracted you both in here. Many people in our audience are familiar with, at least have heard Anor.
I don't know if they know it well, but they've heard the name. Um, but Neil, if you don't mind your title outranks us. So we're gonna let you kind of take the baton here and run.
Tell our audience what, what's anchor about and why, why would it attract both you and Alex, you know, in into the fold here, Joe? So, you know, anchor was founded in 2016 by the, um, original, uh, founder of Ansible, which was, you know, very successful automation product, which is also acquired by Red Hat, red Hat. And, um, so this, you know, back in the mid, uh, you know, sort of 20 15, 20 16, this is when containers and Cloud native really was exploding and the company was founded to sort of try and address the, one of the biggest concerns and, uh, barriers to adoption, which was security.
Uh, you know, containers made, um, uh, developers the sort of stewards of what software would be going into an application, and it was pretty opaque to everybody else after the developer had made the choice. And so an was trying to give a little bit of transparency to that, and then do the security analysis of the, of the software going into the container. So at the time, um, they were creating what were called analysis artifacts, um, which much later on than we, uh, you know, everyone started recording SBOs, which is like, can you build this super transparent set of data around everything that's going on with every commit to every, build every deployment around the software stack, and then allow users to ask those questions of, do I have insecure components, or am I still using this?
Or who brought this in? When do they bring it in? How long was it in production?
All these kind of questions. So Ancor seemed to be having a very, um, seemed to bring a very novel approach to, um, the cloud native, um, uh, uh, sort of driver behind open source software and really helping sort of security teams answer, answer very practical questions. And I was drawn to the, the team because, you know, it had an open source background, as I said, you know, like me came from Red Hat and other open source companies and projects.
And so there's a real sense of understanding sort of the, the, the challenges that Open Source was bringing to, to organizations and, you know, security being, um, top of that. And, you know, we've seen that now really grow, uh, massively. And the other part of it was also that, you know, we actually have open source projects ourselves.
Um, you know, part of the success of our company has been, uh, we're sponsors of two projects, uh, one called Sift and one called, uh, gripe One is, the first one is for generating an S bond. The second one is for analyzing it. It's just for a, you know, a single piece of content you give it.
And those tools have been incredibly successful. They're more or less a defacto tools in this space now around SBO m analysis. And, you know, I still like giving to community as much as open source is a, a source of concern.
It still provides a huge, huge amount of benefits to, um, you know, the, the community in general. A couple of thoughts on that. com, I believe Cloud Native now was actually called Container Journal back then, but we had already launched that.
And Ancor was one of the first companies that specifically said, Hey, we're about Cloud Native Security, right? Up until that point, there was cloud security obviously, and, you know, other types of security, but Anchor was one of the first ones that said we're about cloud native security. 'cause there was some specific challenges around, you know, container containerization, uh, and, and architecting Kubernetes was, was hard then.
It was harder then than it is now. If you can, you know, obviously you guys would know, um, you know, that whole, the whole piece of it, right, was just the whole getting away from the monolith and, and you know, multi-threaded kind of thing. Uh, it it, it represented a new, a new piece of it, but I don't know if we truly recognized, well we certainly didn't call it SBOs then, but already the idea of, let's call it a manifest of what was supposed to be in a container payload, right, was, was already kind of percolating in people's mind, especially when we started moving to like, uh, uh, con containerized archives or, or depots, right?
Where you could download, uh, uh, a uh, uh, a repo of, of different container images. And lo and behold, some of those, we, you know, we started running into like container images that one letter was off in the name. So if you weren't careful, you downloaded the wrong container package and stuff like that.
And, and, you know, but let's be real. It wasn't until, again, we had a few security interest incidents in the, in the software supply chain that all of a sudden everyone started clamoring for what became known today as SBO software bill of materials. And then, you know, it became like the rallying cryo for an Alan Friedman, right?
And working in, in the federal space, the, the US federal, you know, the US government actually kind of took a lead there saying, Hey, SBAs mandatory, right? They should be mandatory. Um, but then an interesting problem happened on the way to Sbam Nirvana is not all SBAs talk the same language.
Not all s bombs use the same nomenclature, if you will. Not all s bombs updated the same way, and how do you integrate, right? It reminded me how old I am when we came out with the web two oh, and there were all these different RSS formats, right?
So just because you were syndicating didn't mean I was able to actually read your syndication because I might have been using a different RSS reader or something. We needed to standardize. We, it was desperate if, if SBOs were gonna be successful, we had to kind of talk the same language.
We had to come outta that Tower of Babel kind of period of SBOs. Neil, it, it, it sounds like that's where anchor anchor really shines here. Um, yeah.
So there is, um, there is no doubt that, you know, the quality, the SBOs is a, is an ongoing, uh, concern from any organization. So the reason for SBOs as, yes, Alan's been a great proponent to this, is that that transparency and allows you to see, look, what do I have so I can ask questions? And principally being, am I affected by the latest supply chain concern or what have you?
Uh, getting good quality data to be able to answer those questions is critical. And, you know, certainly look, part of our business is saying, we think we generate some of the best quality data to allow you to sort of get the best security, um, answers available. But there is, yeah, there are, you know, there are still, as you expect in every part of the IT industry, does people have arguing over different standards and what information can be represented in the standard?
Is it enough and who is it for? And so, you know, the, the two main standards we see in the SBO space are, um, SPDX, which came out the Linux Foundation originally, very much about license management and license transparency, which Alex, you know, is Alex's background. Um, then it was a Cyclone DX standard, which came out of oasp, which is much more security focused, and it's in reality, most products, including ours and others in the market, they'll support both tools.
And it's, it's all, both standards and it's, it's less about the standard and what is the data you're putting into the standard? Have you got sufficient insights? Have you got sufficient quality of data to be able to give you the most accurate answers to the questions that you're asking?
So that's still the challenge is like generating the data and making it easy to query these things to find out, um, you know, whether you're, you are, you are exposed to a security issue. Alex, you're a little bit more technical perhaps than Neil and I give a, you know, peel that back a little bit for our more technical friends in the audience. Yeah, it, it's interesting.
So when, you know, I've been in some way involved with producing bills and materials since in the mid two thousands. We didn't call 'em SBOs, they were called inventory lists or, um, you know, your, the panel list of packages and so forth. But if you think about it, I mean, software is the only industry where it's really difficult to recall something because you have no idea who whom to reach out to, right?
If something goes wrong with a car, a plane, you know, food that you can trace the providence of every ingredient, you can understand where there is, you know, something done wrong in the supply chain, you know, which vendor is built, which is subassembly. So anytime something goes wrong with other products, you can figure out who to go to and how to fix it and what the standards were. Uh, software's always kind of in the wild west, so it's always been difficult to understand even in a well-managed component, you know, who's the developer?
Where do they live? You know, what kind of education do they have? Do they have they had security training?
'cause you, you have so many hands in the pod building it, right? So SBOs, were really an attempt to try to at least tease out as much information about every line item as possible, put it into a standard machine readable format, and, uh, you know, ingest and try to normalize it. Uh, one of the challenges with the two formats is, as Neil mentioned, s SP DX kind of grew out of file level licensing data.
So it's more of a bottom up type of view, which says that every single file has some sort of ownership claims, some sort of copyrights Yeah. And legal terms. And it's very much a bottom up, uh, kind of verbose licensing, um, document, right?
Cyclone DX is the exact opposite. It's more of a top down security document, right? It doesn't even get to files in most cases.
So they've both evolved at their own pace, and they're now kind of come to a, a common definition of fields and common requirements where the two can be for the most part, interchangeable and can be converted from one to the other. So the real challenge lies in how do you tease out all the nuances of each one, put it into a normalized data space, and make that data actionable. And not just informational, but you know, use to prioritize things and make decisions on how do you best address the security issues in some sort of rational, uh, order versus just top to down, top to bottom.
Right. Absolutely. Now, we, I, I, I, you know, hinted I didn't hint at, I said it bluntly, one of the issues we've had with SALM is, is competing formats.
Neil, you mentioned Anchor has two different open source projects out there that have somewhat helped standardize this in this space. Um, let, let's talk about the one that kind of not that normalizes this so that you, you get one tool that reads SBOs across. Yeah, so we have a tool called Sift, um, which has sort of become a defacto tool for generating SBOs in this space.
It can take any file system, um, you know, whether it's in a container or a virtual machine or running host or, um, or a Git Tree is also a file system and it generates the sbo. We, you know, sis function is just to get as much data as possible. So, you know, the most well-known case of of a supply chain attack is still logged for J it's not really a supply chain attack, but supply chain concern where suddenly it was like, oh, we have this incredibly compute software that's everywhere.
We've now discovered a security hole in it, where is it? And so Sift was very, very good at finding it. Um, so a lot of other tools will just look at the file system or they'll just look at a package index and see, right, what's declared, what, what's a formally status being present.
Whereas sift will, you know, unzip archive, uh, unzip zip files or open up jars or un you know, go into archive files and look around to see what, um, you know, where Log four J is already recured down into the detail. So N'S goal is just get as much good quality data as possible and really analyze as much of the artifact that's being given as possible, then generates that data. Now we have our own way of representing that information.
There's a sift, you know, JS om document, which is produced that can then be converted into Cyclone DX or S spdx, these two formats, which, um, Alex and I have been discussing here. So they're just ways of describing the information and up, sometimes you lose information because of the standard, as, you know, limits in terms of what you can say. Um, but in all instances, we keep the data, right?
We generate the data. So independent of what standard you're trying to produce it to, to give to somebody else, we have the data there ready for you. So particularly with our product, you know, it's about if you even independence of the, of the data, which is really just a means of passing, you know, the standards just a means to pass things from one person and one organization to the other.
We just wanna make sure we have all the data possible, we've got as high fidelity information about the SBO m as we possibly can. And then it's a secondary question of like, what format do you want and who are you gonna give it to, um, as a next step in the process. Yeah, and I think that enough that, um, that's been interesting for me to learn is, I mean, ancor is somewhat unique in kind of the wrinkle of how they manage SBOs because, um, the way ancor does it is whatever document comes into the system, whether it's produced by ancor or coming in through the import functionality, that immutable SBO M document is persistent, right?
So the idea being that we don't know what features we're gonna have three years from now, or what, where the SBO M standard's gonna go. So we wanna control and contain and store all that data that's available at the time of ingestion and not necessarily fitted to our schema at that point in time. So what that allows us to do is, as you go forward and you start looking at things like cryptography or export controls or something you hadn't considered today, well, that data is available and it's persisted and it can be, uh, looked at again and brought forward to whatever the current scheme of the product is or whatever the needs are of customers.
So you're not just looking at what we did with the data at a point in time. We've got all the history stored and, and available for future use. So that's a bit of an unique approach because a lot of vendors will convert the SBO m into whatever internal schema they have, and then they lose the ability to go back and do something new with it.
And that, that is kind of the tower babbled issue, right? Once you, once you lose that connection back Yeah, Can't go back. It's a point in time kind of thing.
And, you know, it it, it's hard going forward. Um, of course we've had changes in SSA's mission. I don't know if you guys were at RSA, but it was announced it CIS is going back to its roots and, and these other things.
How, how is that if you know, SCA is here to stay, right? SCA is kind of one of the, the legs of the three legs of the stool of software scanning in my mind. But what do we need, here's a better way of saying it.
Do we need government big stick kind of compliance in order to keep the SBO M standard or SOM is mandatory for our, for our own security and sanity? Or do you think it's, you know, so firmly implanted in best practices of software development today that it really makes no difference? Yeah, So I don't think it is established as best practice yet.
I think we're, we're still a long way off. Um, it's certainly the case that more, um, progressive companies are sort of embedding SBOs as part of their approach, and it really is a different approach to security. Um, you know, just to sort of repeat what Alex said, you know, before security tools would, we've generated or we've scanned it, here's your security information, off you go user security information as opposed to, no, we have all the information about the software.
What security question do you have today? Maybe it's changed from the one that you had last week. So I think some, some larger new organizations sort of aware that this is a new approach, which is, um, very, very useful and makes it easier to respond to security issues.
So I don't think it's quite, uh, best practice yet. So compliance in this space, I think it is actually being incredibly useful. Um, especially with, you know, we had the, the executive order a few years ago, um, which has sort of percolated down and look, even now we see that the US Department of Defense still articulating, articulating SBOs as being, uh, a very core component of, you know, the ability to get authority to operate and to be able to purchase, um, uh, you know, from third party vendors, then they still want to get these SBOs.
So I think compliance has been really useful just to ram home the point that Alex made, which is every other industry expects transparency between suppliers and, you know, with vendors, software should be no different. And the government's got such huge purchasing power that they're able to sort of force that expectation. And so it is really about rewiring the, you know, the expectations around selling software, which has been a long time coming.
It's amazing. We've got this far with, you know, managing to avoid the liability for a lot of software gets produced. So, you know, whether it's CISO or other, you know, individual agencies or, you know, it's, it's, I think this is, it's the way to do it.
Um, it can be painful as we know, governments don't always do things the most efficient way, can be a lot of paperwork involved, but just establishing this as a best practice, I think it's great that the, um, not just the US but now do u do, European Union are also starting to really drive ESP bonds as a core part of, um, uh, regulations. And I do think one, I mean, one thing that's important is not making it too siloed geographically, right? So yes, it's great that cis a you know, is worried about us, you know, you know, you got the EU at the, the CRA, but there's lots of emerging regulations in India and Asia Pacific.
So it would be great to get a worldwide body of experts to kind of drive this as opposed to each country driving their own. 'cause at the end, I mean, it's the same challenge. We're trying to accomplish the same thing.
So it's, it'll be much easier than trying to comply region by region. Yeah, we, uh, every year at the RSA conference, we put on a, we, it's Dev DevSecOps Connect is the official name. I do it in partnership with the RSAC in Moscone Center on Monday.
Uh, we'd do it at 10 years, I think it was about three years ago. We actually focused a lot on, on software supply chain security and SBOs. And we did have Alan Friedman, we had a great lady from Intel, and I don't remember her name and PhD, Dr.
Someone. But anyway, it, it to me, after coming out, and that was three years ago, I really thought that by now SBOs would be the defacto standard, the best practice that we wouldn't have resistance. Of course, you want to do this, right?
It's obvious why Neil, I'm, I'm hearing from you though, well, if we didn't have that government big stick yet, whether it's the EU or the US or various other jurisdictions, you know, we all live in the world of sovereign software today, you know, the balkanization of everything. But if we didn't have these government mandates, people wouldn't toe the line, so to speak, where it just seems like, Hey guys, this just makes all the sense in the world we need to do this. Yeah, it's, I mean, it's the, it's the common challenge of everything that's security related.
It's the what's the business value for doing it. If you're not asked, um, you know, security teams, um, certainly probably would like to do this, but I think it's, you know, the, the mind is willing, but the flesh is weak. It's like if you don't have the resources to do it, and you know you're being pressured to do, um, other things, you know, it's security issues do get dropped, um, like this.
And so I think, you know, for the people produce for the organizations producing a content, there's not a immediate sense of value or benefit from it compared to other things where, you know, they could be, uh, investing their time. The main benefit is for the person receiving the document. And again, it's only valuable to them if there's an issue that they have to respond to.
So I think it's a question of incentives here, which is, you know, there's, there's no short term incentive for organizations to produce this content to give the third party is it doesn't necessarily benefit, um, you know, sales or reduce costs. You know, potentially quite the opposite here. So again, I think this is why compliance is, is often needed to sort of overcome those incentive challenges to say, no, this is important for everybody.
Let's, let's, you know, let's not make it the, the, the responsibility of individual organization, individual organizations decide they wanna do that as an industry, we now set an expectation, you know, as, as the same reason, you know, food companies have to produce ingredient lists on the side. You know, if they didn't have to produce these lists, they wouldn't want to. It takes time and effort to go and track down your suppliers and make sure your accounting for whether something's got nuts in it or you know, it's got, um, uh, various ingredients.
So, you know, it's compliance is definitely, I think, needed to overcome some of that, that that incentive challenge around that. No, no immediate benefit to the generator of the content. Fair enough.
Guys, I'd love to talk to you about this whole day. I'd like to jump into, you know, why the very wise open source seemed to be the whipping child for this versus, you know, other software. It's a lot, but unfortunately we're outta time.
Maybe we can continue this conversation another time. Yeah, I'd Love to, to been great chatting with you. Thank you Alan.
Absolutely. Alex Neil, thank you both for coming on here. I hope you've enjoyed this conversation out there.
Well, we will, I promise we're gonna do our best to get 'em back on and we'll continue. But for now, for Alan Shimel, this or for Tech tv, I'm Alan Shimmel. We'll be back in a moment.
AI application delivery. Victoria has a big secret inferring at the edge. VMware's partner purge Walmart using AI for automation.
Quantum might break RSA faster than we thought. And we're gonna take a closer look at the impact on tariffs and cloud computing, and this week's episode of the Tech Field Day Rundown. Hello everyone, and welcome to the Tech Field Day rundown.
Today is Wednesday, June the fourth. My name is Tom Hollingsworth, and I'm very glad to be back from Super Secret Security Field Day. Uh, and it's a very important day.
It's a national hug your Cat Day, also known as why is this Queing arc trying to kill me? Um, you know, it's, you take the good, you take the bad, right? Um, hugging a cat is always an exercise in restraint on somebody's part.
Uh, but luckily I am not restrained in welcoming my new co-host for this episode. Mr. Brad Gregory.
Brad, welcome to the show. Tom, great to see you again. It's been a while.
Good to see you. It is, and we're very glad to have Brad joining us on National Cheese Day. But I promise you the only thing cheesy around here is the day the news is very important, and we've got some great stories coming up.
The first one that I wanna launch into is about AI and inferencing, because AI inferencing and networking isn't about using AI to manage the network, it's about delivering AI workloads with the same precision, scalability, and resilience that we apply to modern application delivery. Inferencing is really just another demanding workload that thrives on optimized load balancing, latent sensitivity, routing, and secure edge delivery. And Brad, this is something that I know is near and dear to your heart.
So why don't you give us a little bit of background into why you think that AI is really just another workload and not something super special that's gonna revolutionize the way that networking packets are sent? Yeah, thanks, Tom. Because in fact, that's what it is, right?
Uh, I think we've spent so much time in, in, uh, talking about training, talking about how, you know, we knew the Alteryx and that consortium and how we have to do all these things different for training. Uh, it's totally different networks. We have to learn new things, um, uh, and, and rightly so, right?
I mean, you gotta train it before you can put it out there for everybody to, to consume. Um, and then, and then we move to inferencing, right? Uh, inferencing is still kinda like, uh, old networking, but, but with a few tweaks, right?
The, the network's gonna have to behave function a little differently. Um, so there, there's a lot to learn in the inferencing, uh, in the training space. There's some to learn in the inferencing space, but I would argue there's not a whole lot to learn in the application delivery space, right?
We've been talking so much about training, so much about inferencing, but even at that inferencing is just the front door, right? I, I've gotta have, uh, just like a web server was the front door for applications, right? You, you, you've, you gotta have something to serve, uh, the, the trained models up.
So, uh, once I started digging into it, uh, more, uh, and trying to figure out, okay, what does the application delivery look like? It became pretty obvious that it looks like what it's always looked like, right? I, I've got a load balance to it.
Um, I, I've gotta look at the context of what I sent to it, to load balance on the backend. You know, when load balance was first starting many, many years ago, they were pretty rudimentary load balancers. Then, uh, they started getting a lot more sophisticated, uh, and then they became application delivery controllers.
So when I look at, uh, how we, um, offer up AI applications to users, it's simply application delivery. You have to, you know, think about a couple little tweaks. You know, in the old days it was SQL injection, uh, attacks that got you in trouble.
Now it's prompt injection that'll get you in, uh, attacks that will get you in trouble. Um, you wanna load balance to different models based on the, what the prompt sent, right? So if you type in, um, you know, how do I write some something in Python, then maybe load balance me to llama instead of, you know, claw, for example, right?
So I think just the, the, uh, the availability, the contextual information, sending me to the correct, uh, resource on the backend, uh, how do I secure? It sounds a lot like what we've been doing for the last 25 years, right? Since low balance really, really came to the fore.
So, um, so not a lot. Think, think old, old is new again, and just apply those same principles. And I think, uh, the application delivery aspect for AI will be easier to understand and easier to wrap your hands around.
Not so much for training and kind of, kind of for inferencing. You, you, you know, a lot of the old still applies with inferencing, but, uh, but a lot of the old really applies for, um, application delivery. Uh, Victoria's Secret, I heard they had a pretty long weekend last week.
They spent a lot of time fighting, uh, security incident, took their website offline for almost, uh, four days. Uh, customers were, uh, taping the shop, were greeted with a pink screen telling 'em the site was offline due to an issue that was being addressed. Details surrounding the event have been dis disclosed, but there were some communications issues between the website team, the PR team, as the website at one point disclosed the nature of the security breach, while the PR team released a statement said it was an upgrade gone wrong.
Your thoughts. So there's two things to think about here. The first thing, which is kind of the important thing is always make sure that your PR team and security team are on the same page when they talk about what's going on.
Because if the PR team is like, oh yeah, we tried to, you know, fix PHP and something broke, sorry, no big deal. And the website team this that's working with security team is like, oh yeah, it was a breach. Like, one of those things is no big deal.
Although it would've really been hard to justify it being an upgrade that was, you know, took your website off for four days. Um, but security thing is gonna get everybody's attention. And that's kind of what happened last week, was that everybody noticed that this was, it, it actually started happening kind of like Sunday, but it wasn't until we got into the hours of Monday that, that everything went offline.
Here's the second thing though. You've gotta read between the lines a little bit because of course, they're not ready to disclose exactly what happened. And they may not tell us the exact story, but they took the website offline and you couldn't order anything.
And I've heard from some sources, according to Reddit and other places, that a lot of what was going on in the stores was also offline. It's like you couldn't order things that were not already on the shelves and stuff like that. That to me says there was a breach of the ordering system, and they probably got some PII of the users probably credit card data.
That's what my worry is. Um, the only reason you would not immediately disclose what was going on is if it involves something that's massively PII, in this case, P-C-I-D-S-S, um, impacts. Uh, you got credit cards, that's a problem.
Why are you even storing credit card data? Well, I know because you click little box that says, remember this for, for future stuff. But, um, you know, they're gonna have to sort this whole thing out.
There's probably gonna be some impacts with their customer base. Um, realistically speaking, I don't know if this is gonna be huge impact or not, because one of the things we've seen over the last few months and years is that ultimately, uh, customers are brand loyal. So they're gonna probably come back to buy things here.
I mean, it's not like you have a ton of options to shop for, um, especially ones that have local storefronts. Uh, you know, like I can ship it to the store or whatever, especially if you feel uncomfortable having things like that shipped to your home. But I think that, that they're gonna have to actually come out and say what it was like, they, they can't play this game anymore.
I think really what they're doing is they're trying to get their ducks in a row so that they know if there's going to be, you know, um, charges filed or some kind of a class action lawsuit, um, that they're ready to fight it. Um, so sorry if you couldn't buy some fun stuff last week, uh, but, you know, as Marshall Stacker, Pentecost always says, you know, reset the clock because it's just gonna be another breach before you know it. And, and next time it might not be something nearly so fun.
Brad, there's some new reporting out that discusses the likelihood that AI inferencing is gonna be huge for Edge computing, uh, per this report. Doing inferencing on the edge reduces time and costs for transferring data in and out of cloud storage, as well as lowering latency for decision making. And by doing all of the work on the compute edge, you can reduce huge cloud overhead costs.
I know how much it costs to spin up and Amazon instance, and it ain't cheap anymore. Um, also one of those little side benefits to all those of us in the security space is the fact that you can be relatively certain, you know, where that data is, so you don't have to worry about data sovereignty issues. Uh, I guess the question that I have for you, Brad, is should we be looking at moving all of our AI inferencing data out to the edge instead of loading it all in the cloud?
Yes, probably. Um, you know, I think for the longest time we've been looking for that Edge killer app, right? The, um, and the edge has been kind of a nebulous term, but I think, um, uh, inferencing could be the killer app that, uh, that the edge is looking for for a couple reasons.
One is, you know, um, users' a lot more dispersed than they used to be. You know, not everything happens around the major major metros. Uh, and then two, um, their, uh, just from a, a, a standpoint of space power cooling, you know, uh, you can't really build that many ash, uh, data centers around Ashburn anymore.
So, um, you'll see training can be done anywhere, and inferencing needs to be pushed out closer to the, to the users that are, are literally anywhere now, right? So, um, and then two, um, it's hard to do everything in the cloud because you've got a lot of data that means a lot to you that's proprietary or the sovereign that you want, you know, you know, you wanna keep close to the vest. So, um, you know, I think you'll start seeing things like, uh, rag retrieval, augmentation generation, uh, federated AI things where that, that, uh, that the trained data or the data that will be presented back to you will be a combination of, uh, a foundational public model, uh, with your own individual tailored data, you know, for, uh, or, or your own data that's tailored to your, to your needs.
Uh, you know, that's the retrieval augmentation generation, right? I'm gonna, I'm gonna send a query out there. Some part of it will come from the foundational model that's more public.
Some part of it will become, uh, will come from your data that that's more private. Put those two together and, you know, I've got an automated, uh, or augmented response, it comes back to you. So, um, that's one great use case where I think, uh, inferencing at the edge as it as it applies to ai, specifically in the rack context, in the federated AI context, might be the killer app that the Edge has been looking for for quite a few years.
Now, if you're a registered partner of VMware by Broadcom, we've got some bad news. The company's eliminating the lowest partner tear completely. Existing partners have 60 days to either move up or move on.
According to Laurie Falco head of Global Partner programs, the vast majority of these partners are inactive and lack capabilities to support customers. This means VMware by Broadcom has three partner tiers, pinnacle, premier, and select. These tiers will now have increased requirements to maintain the relationship, including dedicated sales and support personnel.
Analysts are suggesting that the move could force smaller customers away from VMware in the future. So here's my problem with this. Um, we just got through with this whole big bruhaha about VMware's partner program, right?
They wanted to take their top thousand or 2,500 accounts private inside of VMware. They've been slowly pushing everyone to be selling only VMware Cloud Foundation. Um, there's no essentials bundles anymore.
What did they think the natural outcome of this was going to be Like? I know a lot of people who were registered as VMware partners that really only resold to a couple of places, like, you know, maybe themselves and a couple of other local partners. Well, if you don't have a foundations bundle to sell anymore, like, like if that was the reason why you registered, this makes total sense, right?
We're cutting out the people on that low end to the comment by Lori Falco. Yes. If there's nothing for them to sell, then they're all gonna be inactive, right?
Like we, we've been doing this dance for the last year and change of, you know, what's, what's gonna be available? How can we do this? And any partner program worth its salt is gonna say that you have to have people who are trained on the solutions that are trained in the way that they need to be sold and to go out there and do it.
And I think that this could potentially be the carrot for some of those larger organizations that are trying to look to differentiate themselves to be able to offer these solutions, right? It's like if you go out and you dedicate personnel to being able to do this, if you kind of follow our guidelines for selling VMware Cloud Foundation, if you, you know, have a high attach rate, you know, maybe we'll toss you some of these bigger partners so that you know, you can continue to maintain the relationships you have with them. 'cause I have a funny feeling what's happened is that a lot of those large partners, uh, had really good relationships.
And when VMware came knocking without the partner, the companies were like, well, I'd rather deal with the people that I know. And so I think this is kind of pushing back on the partners. However, I I, I do agree with some of the analysts talk.
If you're cutting people out completely, then the first thing they're gonna wanna do is say, screw you. And they're gonna go sell somebody else. Now, I don't necessarily know that that's gonna work the way that you think it's gonna work.
Um, I think ultimately what's gonna end up happening is that Amazon and Nutanix are gonna gain, and then the rest of everybody is going to, um, you know, they're gonna be picking up the pieces. I don't know what this means for VMware customers, but I promise you it's probably time to start thinking about what your migration strategy is gonna be. 'cause you're either gonna be moving to Cloud Foundation, or you're gonna be moving to something that's not VMware, right?
Walmart is using a new approach to AI by focusing on small tasks, specific agents instead of large all-in-one platform systems. These AI agents handle specific jobs like data entry or even speeding up product design, which is leading to clear improvements in how the company runs. Uh, Walmart also combines multiple agents to manage much more complex tasks like their smart shopping assistant, which uses both in-house and external AI models.
This focus strategy makes AI a lot easier to scale and a lot more cost effective, and it could serve as a model for other businesses looking to improve automation. Um, Brad, does Walmart's approach to maybe smaller discrete AI agents instead of one big behemoth? Make a lot of sense considering that Walmart is kind of the behemoth in the retail space.
Uh, yeah, it does. You know, a lot of agents are a good thing. A lot of agents can be a bad thing too, right?
That, that's a lot of, uh, that's a lot of crosstalk that's gonna happen. That needs to be secured. It needs to be, um, you know, probably thought about in a little different way, and it kind of goes back to the discussion we were having a minute ago, right?
This is just another way to talk about, um, you know, it's, it's just retrieval augmentation generation on a grand grand scale, right? Instead of having, you know, one master model talking to a, a tailored model, you can have all these models talking to each other, right? You know, what in the future, what would dictate a model?
Is it one agent? You know, is it what is a small language model at some point, right? Um, so I think once, uh, yes, that's the power, right?
I mean, you get a lot of intelligence out there and a lot of data points, and they all come together and they start, um, you know, the, the collective power of all those data points to come together to give you one, um, one retrieval. Augmented generated AI output is really the power of any system, right? It's kinda like met law in motion.
You know, the, the power of the system is, is vastly, exponentially more powerful. The more agents are talking to each other, the more, you know, connections are talking to each other. So I think this might, um, you know, agents talking to each other will be the what interconnection has been for the last, you know, decade or 15 years, right?
The, the power of getting people to talk directly to each other, peer-to-peer, you know, I think the agents is just the agents. Uh, AI agents are just the next iteration of that, and it's powerful, also dangerous, uh, new study from Google quantum AI shows that breaking the 2048 bit RSA encryption may require far fewer quantum resources than once thought. Instead of 20 million cubics, the task could now be done with under a million noisy cubits in about a week.
While today's quantum computers aren't powerful enough, yet, this major drop in requirements highlight just how quickly quantum computing is advancing. Since RSA is widely used to secure data, the finding express the urgent need to switch to quantum safe encryption to protect against future threats. Your thoughts, This is the same old problem that we know we've had ever since sneakers came out, right?
Is we know that eventually someone will create a computer that is strong enough to instantly factor primes and, and be able to figure out these keys. And honestly, even in a million cubits, you're still looking at days to break any one specific RSA encrypted key. And the problem that I have with this is, yes, it's an attention grabbing headline, but you have to understand something.
The most powerful quantum computer on the planet right now from Google has about 1100 qubit capacity. You need a million to even consider this. And notice that it said a million noisy cubits.
So for those of you who may not have seen my conversation about this, one of the problems that we have with quantum computing is just the amount of noise that's generated. You have to have lots of cubits to solve every potential permutation of the equation, and then you have to find that equation. That's why error correction is so important to quantum computing.
And if you can get the right amount of error correction, you can significantly reduce the number of qubits that you need to brack break any particular key. The problem is, even with the leaps and bounds that we've had over the last few years, we're still nowhere near as powerful as we need to get, even with exponential growth, we've still got several more years before we get there, but we already have candidate keys that are quantum resistant, that use lattice based encryption technologies, which is really difficult for quantum computers to break. And for those of you out there who are on the crypto chain, you don't have to worry about Bitcoin being broken anytime soon because that whole proof of work thing and elliptical curve technology make it a lot harder to break than, than just if it was just a simple, and I say simple, uh, RSA 2048 key.
The, the issue is, is that we really do have to be looking at what the likelihood is, is that we either are gonna need to re-encrypt the data that's already at rest that is insecure, or that we're gonna need to basically remove it and then move on to these more resistant keys. But I'll tell you, this is not the first time, the second time or the 15th time we solve this problem, I can go back to just about any hashing or encryption algorithm that was weak in the past, that is effectively broken today. And we saw we've had these problems forever.
The, the key is that we always have to be one step ahead of where we're at. And we did that whenever we submitted those candidate keys to the, uh, to NIST to be, um, authorized. I mean, I, I don't remember what they got named, they're just numbers now, but you know, it was di lithium and, uh, cber and all the rest of them because they're solving the problem that we have, and they're doing it early enough that we're not like falling all over ourselves to implement fixes that will eventually cause problems.
See, also the Y 2K problem, like that was admittedly a herculean effort, but it was very late. We should have been way ahead of that. And here I think we are, and what we're seeing out of this is people that are starting to ask the right questions, not just how can I encrypt this data, but is this data that I should be keeping, that I'm going to need to encrypt?
And I think that that is a better question to be asking because if we can, if we can stop storing so much data, then it's less likely that the encryption that we're using is gonna be broken. Alright, we had a story we wanted to take a closer look at. And undoubtedly, if you have been watching the news at all, you are familiar with tariffs because they are the thing that has been dominating the economic talk.
Well, new global tariffs are making it more expensive and complicated for enterprises to manage their cloud services across regions changes are causing wildly unpredictable costs and creating challenges for organizations that wanna adopt a global cloud strategy. And in order to stay ahead of that, companies are gonna need to improve visibility. They're gonna need to automate processes, and they're gonna tailor their governance to each region.
Now, what I think is funny is, is that we've been talking about data sovereignty issues for years, right? Where is my data located? How is it being accessed?
And those are security questions. So they're not that big of a deal, right? We'll solve them.
But now that we're seeing that those data sovereignty issues are coupled with economic considerations such as the price of certain resources in, uh, in instances being wildly higher because of additional, uh, tariffs not just, uh, demand. Uh, now suddenly the people who didn't care about data sovereignty care about their pocketbook. So, Brad, I'm gonna let you start off on this.
Um, what is it about this that's causing people consternation? Is it just the fact that there's a tariff on cloud computing, uh, incidentally, or is it more that they're worried that this could create asymmetrical demand? You know, that's a good question.
I, I think what's causing all of us consternation is you don't know what it's gonna be, right? If, if, if a tariff rate was locked in at X percent over the next 12 months, 18 months, and that was the new agreement, then you could say, okay, we, we have some certainty. We know how to work around it, right?
I think what's frustrating is, uh, is just the whiplash of the tariff rate itself. Do I refactor applications? Do I, do I adopt as a service instead of, you know, or, or do I adopt, uh, opex instead of CapEx?
It, it's the unknown. Um, just like everybody else, the the, uh, it industry's not insulated from it because to your point, we're all, uh, you know, economics is driving everything behind the scenes. So I think, I think just the unknown, not knowing what to do is very, very frustrating.
If you had something to deal with, like, we dealt with supply chain issues and, uh, during COVID, right? You knew it was gonna take quite a while to, you know, to, to get, you know, whatever piece of hardware you were working with. So you, you figured out ways around it.
You, you figured out a way to get to the other side of the supply chain problem. Um, what is the other side of this problem? I don't think anybody knows yet.
'cause nobody knows what the rates are gonna be. Nobody knows, you know, um, what agreements are gonna be signed. Nobody knows who's gonna be at the table, who won't be at the table, who's gonna pay a bigger price, uh, you know, than the others.
So the uncertainty, it manifests itself in so many ways, right? It just paralyzes everything It does. And, and I'm gonna say two words that I think everybody gets tired of hearing is chilling effect, right?
But this is absolutely something that you need to take into account when you look at what's going on. People don't make decisions on the spur of the moment, even when it comes to something admittedly as ridiculous as spot pricing for cloud instances, right? Like, that is the number one thing that I've always heard that people wanna use multi-cloud for is arbitrage.
Um, this, AWS instance is expensive for the next three and a half hours. So I'm gonna move it over to, to Azure, and I'm gonna run it in Azure because they've got a discount on storage or whatever. Who knows what it's, you're, you're playing around with the money.
But what you're doing that's more important is, is you are forcing people into making specific decisions for their workloads that exclude other areas. So for example, if there is a tariff on importing cloud computing workloads into a specific country, then I'm gonna craft my policy so that I don't import those into that country no matter what. And it's one thing if, if the tariffs are asymmetrical, right?
Like one country has higher tariffs for certain things, but lower tariffs for other things, the problem ultimately is going to be that companies are just gonna throw their hands up in the air and say, I'm gonna go where it makes the most sense, where it's the most stable and I'm going to stay there. Because that's the other thing. If this was just a blanket tariff across the entire organization and we didn't have to worry about things moving too much, then I can maybe see like, maybe I'll raise the prices to my customers.
I'll eat some of this. But what we're seeing is whiplash, right? One day we have a tariff, the other day we don't, but maybe we might have another one in the future.
We don't know yet. It's up to the whims of whoever's putting the tariff in place. I can't plan my organization around how somebody wakes up in the morning and decides that they want to do things.
And this goes against every classical economic definition of a tariff that you've ever seen, right? Tariffs are considered to be protectionists, and that's why I don't understand why this is happening, right? Like, why would you put a blanket tariff on everything?
Like, if you're trying to be protectionist about things like industry, you'd put a tariff on finished goods, but not on raw materials to encourage people to import raw materials into your country and produce finished goods. Here, it's a little bit different when it comes to cloud computing, which is why I don't understand it. It'd be like saying, I, I'm gonna put a, a tariff on storage but not compute because I want you to do the work but not save the data.
And by putting a blanket on everything, then they're just gonna say, okay, well we're gonna stay in this instance over here. And if cloud computing companies like Amazon, Microsoft, Google, Oracle, IBM, whomever are really smart about this, what they're gonna do is they're gonna offer instances that are local, but are not impacted by this. And that is gonna cause a lot of these global organizations to realign a little bit differently.
And what you're gonna get out of it is effectively islands of data out there in the cloud that can never move. So you're gonna have to be more robust in the way that you build your applications because you can't just migrate from Reston to Corvallis and hope that US East or US West one is up instead of us East one. And I don't know that that's something that developers are really prepared to do right now.
Well, and then you're, everything you're we're talking about is in the context of hardware, you know, physical asset. What about when tariffs, you know, they've talked about applying tariffs to services, right? So if, if you have services, if you wanna buy services to refactor rewrite applications to get around a hardware tariff, right?
Or, or an asset tariff, what, what does that look like? You know, it, so it's almost like this matrix of tariffs that you have to apply in, you know, this three dimensional chess, uh, matrix. And it's like, I don't know how people are gonna gonna figure it out.
You know, again, certainty, bad certainty is better than no certainty, right? And I, I just, we, we don't even have bad certainty right now. It's just uncertainty on top of uncertainty, it changes date.
I don't, you know, yeah, a very, very tough time on so many levels to try to, to figure out what you wanna do with your org and what you wanna do with the technology based on the, the way this stuff is coming at you in so many directions. Well, there may not be a lot of certainty around that, but I can tell you one thing that I am absolutely certain of, and that is Tech Field Day, because we have great events that are coming up over the next couple of weeks that you're gonna want to tune in for. One of them is happening now.
com, you can check out Cloud Field A 23 where we're talking about some of the very same things that we just discussed in this episode. Uh, Alistair Cook is out in San Francisco. He's talking to some great companies.
com. You can tune in for the live stream, but you can also check out the list of presenters. Uh, you're not gonna wanna miss that.
And then I am gonna be winging my way to California at the end of the week because I am gonna be at Cisco Live next week. com for more details and the presentation schedule. And then I'm gonna take like a week off and maybe enjoy the weather, okay?
I'm not, it's, I'm kidding. It's summer. I'm not gonna enjoy the weather, but I'm gonna be back in July after Independence Day.
We're gonna be back with Networking Field Day 38. We've signed some really great companies. In fact, we just signed a couple of them this week.
com and learn more details about who's gonna be there presenting, who's gonna be there as a delegate, uh, I encourage you to do that. But I also encourage you to check out some of Brad's stuff. So Brad, if people wanna learn more about what you do and see some of your writing, where can they go to do that?
Yeah, thanks. Uh, LinkedIn's a good sp uh, place. I'll put 'em all on LinkedIn.
com, which is, uh, my consulting company. So yeah, I would love to get people's feedback. Um, and if, if there's a subject you wanna delve into, uh, let me know.
I'd be glad to research and write a blog out there for the, for the larger community to, to consume. So thanks Tom. Absolutely.
And we want to thank each and every one of you for watching this episode of The Tech Field Day Rundown rumor that we post new episodes every Wednesday. Uh, we post them on YouTube. So if you wanna subscribe to the Tech Fill Day plus YouTube channel, you can check that out.
You can also subscribe to us in your favorite podcast application of choice. Just look for the Tech Fill Day rundown, and we're streaming it on Techstrong TV as well. Don't forget that there is now a Techstrong TV app for your tablet phone, and your set top box.
So if you want to have us up running in the background or maybe program it at your dentist's office, we would love to, uh, bore the kiddos with all of this great tech talk. I mean, they may not even need, uh, laughing Gas anymore. Uh, don't forget that we can, you can also catch us on your other tech strong and future and group properties, um, because we always pop up and we always have fun things to say.
We're gonna be back next Wednesday. We, somebody will be, because I'm gonna be in San Diego. I'm gonna be out there with a, a beach chair and, and trying to avoid the sun, actually.
Uh, but there will be great co-hosts here for the rundown. And, um, we will be talking about all of the great IT news that has come out over the last week. Until then, for myself, Tom Hollingsworth, and for my great co-host, Mr.
Bragg Gregory, thanks for tuning in For the rundown. Go eat some cheese and give that cat a hug for us. We'll see you next week.