Techstrong TV June 24, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
The US bombed Iran. What's the it Blast Radius You're watching Textron Gang. Hey everyone.
Happy Tuesday. You know, and for those of you who don't know, we, we record these shows one day in advance, but what a difference a day makes, right? We recorded on Friday, it was, it was a very different sort of reality.
Now, here we are recording this show, Monday for Tuesday, and everything we said on Friday, at least, geopolitically might have gone out the window. But, um, as we sit here Tuesday, I can't tell you what's gonna happen tonight or Wednesday every night is, uh, you know, I I try to get up in the middle of the night and check my news sources to see what's going on over in the Middle East, but it's certainly been a, a, a memorable weekend. Uh, lot going on.
I don't, you don't come to us for your news, news like that, but let's jump into the it of it. We got a great gang. We're going to talk about, you know, most of these people.
So I'm not gonna go through a whole thing. We're gonna try to get right to the news today. But let me quickly say, we have on the gang today, the one and only Kimberly Bates, JP Morgenthal, Stephen Foskett, the dean, Mike Ard, Bonnie Schneider, and myself.
Am I the only one that has, uh, flashbacks? So Hollywood Squares, when you do that, Kinda, we're the little corner. So here's the real question.
Are you Paul Lind or Charlie Weaver, or, I'm not Paul. No. I, I love your little Paul lid.
Uh, who, but then who's Charles Nelson Re, right? Charles Nelson Riley. They, Joanne Worley.
There was some great people on there. But anyway, hey, I'm trying to get right to the news today, Mike. It blast Radius.
What do we got? So I think everybody's on Knife's edge kind of waiting to see what happens here. it, Alan talking about some of the concerns ranging from, you know, will there be, you know, budget freezes on it to what are the cybersecurity implications?
But, you know, let's start off with you. And there just seems to be a lot at stake here. A lot more than 48 hours ago, that's for sure.
Oh, yeah. Oh, yeah. So, and dude, check out my article on text from it on this.
Um, you know, generally speaking, there are some people who make a lot of money during war, and there's some people who lose a lot and not just money during war, right? War is not healthy for animals, pets, and other animals, children and other living things, or, so I'm trying to remember that from when I was eight or nine growing up in the Vietnam War era. But, um, you know, generally speaking, when there's chaos in the world, people try to, you know, they, they, they get tight and it budgets generally get tight.
Uh, and so you might expect to see some of that as a result of, of recent events. However, as I wrote in my article, I think with this particular, the, the particulars of, of the Iran Israeli, US Triangle, unless someone else gets involved, what we're seeing is not so much a pullback of IT budgets, but maybe reallocation of it budgets, right? Um, we, we could talk specifically about cyber, but when you've got three of the, of the world's preeminent cyber warfare countries involved here, and make no mistake, Israel, well, the US is in a class by itself, and Israel's probably close behind, and Iran is no slouch, right?
You gotta expect that there will be cyber repercussions here and cyber fallout and cyber attacks. So, as, uh, as Jen is a Pataki, I, I, I, no, Jen Easterly former CER person wrote on LinkedIn this week, Hey, shields up, shields up. Now is the time to put on your maximum cyber type of defenses.
And that may mean spending a little bit more money, immediately getting, you know, whether it's manpower, SaaS based services, whatever. But now now's the time to burst up your, your cyber defenses because stuff's gonna happen. I can pretty much tell you on top of that, I think this is also going to give rise to a big IT sovereignty push.
We've been talking a lot about it sovereignty over the last couple weeks, few months, but this is going to really put some rocket fuel in the tank, right? You don't want to be, you don't want your people stuck in a country where the airspace is shut down. You certainly don't want your data stuck in a infrastructure or internet or play hosting state where it's been shut down or, or, you know, not, not available to you.
So I think it, sovereignty projects, obviously cybersecurity projects, and then everything seems to benefit ai, doesn't it? Um, a lot of people say, Hey, we need to be able to do more with less. We might have less people.
We, we need to have more automation. And so I think you'll see an increased, uh, push into ai, uh, accelerating what we already have on the board. So overall, I, I, I don't think budgets will be frozen.
I think budgets will be reallocated to tremendous time for more digital transformation. But those three areas that I mentioned, and I mentioned them in the, in the article, are, are prime for, uh, for, from spending and, and for activity. Kimberly, do you think that sovereign clouds will get a big boost?
I mean, we've already seen a lot of countries who are normally allies of the United States saying, we had nothing to do with this. So they're already kind of positioning themselves accordingly. But will that get extended out to where workloads are placed?
I think that's just gonna continue the, I don't think it's, uh, we're already on that march. I mean, it's a fa complete, in my opinion, um, with countries creating their own, um, sovereignty environment and wanting the data there. And that goes even beyond this, this blast, you know, that we're in, in the middle or potential war, it goes into all the geopolitical.
Who owns my data? You know, I, I am in a ship of it. I think the biggest thing here, the biggest issue here is the cybersecurity.
Because if you wanna attack and not be seen as directly attacking America, um, which is, you know, where the threat of, of the president has been saying, don't attack, you know, our soldiers don't attack America. That's the way to go. And some way, and somehow we are, we are exposed, many of our, um, infrastructure areas are probably exposed and they don't even know it.
Um, they still have the password of 1, 2, 3 admin or something along those lines. And so, Jen Easterlies, um, posts that I, if you haven't read it, she, she did a great job on a, a short piece that was up on LinkedIn, um, that I, I reposted from her. Um, very good, you know, marching it down that every cyber security, CIO, you know, executive needs to go and, and check their list about where they're at.
And then probably do, um, if they haven't done it recently, probably do a tabletop exercise, um, about where they're at. I mean, it's really because that's, you know, they've been known to, to attack that way, and we've attacked them that way. So we've got, you know, San sand worm and all that kind of stuff that in the history of that.
0. I mean, it feels like we're just getting smaller and smaller and the, the clouds are becoming more disaggregated. So I don't know, is there a fundamental change in the way we think about it, architecture afoot?
Well, you know, it's, it's interesting that, um, to consider the cyber implications. Of course, you know, when people are dying, it's sometimes, um, difficult to think about, you know, the, the implications on business. But I guess if we want to, if we wanna talk about that, if we wanna figure out how this works, um, yeah, I think we need to think about how, um, all of this impacts everything that we do on a daily basis.
So, certainly, um, to your point on the architecture and the design of the global infrastructure that we're deploying, we cannot, as it pros pretend that what we do isn't impacted by global events. As, you know, y'all mentioned just now the involvement of, uh, the US and the attack in Iran, the denial of involvement from other countries, specifically Europe and Australia. Uh, the concern over these state sponsored threat groups, um, you know, as, as Kimberly pointed out, it is very obvious that these threat groups, that's gonna be the vector they're gonna use to strike back.
It seems very obvious to me because what we've taught the world over the last couple of decades of doing, essentially nothing about these advanced persistent threats, at least nothing on a diplomatic front, is that you can attack us and not expect any kind of response. And so, Iranian, um, threat groups, so they've got a PT 33 34, which is probably the same group, um, which has the charming name of Helix Kitten and APT 35, which is the, uh, charming kitten. Um, you know, 33, 34 targets, infrastructure elements 35 has generally targeted, um, businesses, uh, including the famous, uh, election interference, the HBO cyber attack, that sort of thing.
I think that we'll definitely see both of these threat groups active going forward, where they're trying to figure out ways of inflicting some damage on the west. Generally the United States specifically, I know that Israel has been actively under attack for the entire time of the operation since October 7th. But, um, and, and of course before that as well.
Um, so, so yeah, I think that all of us, we need to recognize as, as Kimberly said, that, um, you know, they're coming for us. They're coming for all of us, and, and, and it's going to affect the way that we deploy applications where we deploy those applications, what we can expect from them. And, uh, I think it, it highlights the questions that we've had previously about, um, sovereignty, data sovereignty, and cloud sovereignty.
We have to think about, you know, where are we deploying applications and what is the geopolitical implication of that? So I I, I just would add to that though, yes, we've gotta be wary and put our defenses on high alert, you know, DEFCON five or whatever, but let's not let, let's not forget offensive cyber capabilities that have been put into play here. Right?
And I'm gonna give you two quick examples. One is Israeli, right? Many folks in Iran and and Iran have have said that their internet has been shut down.
Now, there's conflicting reports. I've seen reports that it was, you know, is Israel that shut down Iran's cyber? They've, they've cyber attacked and shut down their, their internet for periods of time.
I've seen other reports that it was the Iranian government themselves that have shut down the internet so that voices of descent can't take advantage of the situation in terms of regime change or, or gathering support or as well as giving out potentially strategic information about where attacks have been, how effective they've been and and so forth. Um, but Israel is an offensive cyber powerhouse, and quite frankly, so is the us We have a cyber command. We have the USA, don't think for a second that as part of this attack over the weekend, that cyber assets were not put into play to suppress Iranian communications.
Because at some level, the Internet's communications, right? And this is a game as old as humans. When you, when you're attacking, you want to suppress communications of the enemies of your enemy.
So I am more than sure that is part of this attack package. Besides the B twos and everything else, the cruise missiles and everything that came with it, there was a cyber blackout zone that, that we laid down there that to thwart command and control at the time of the attack offensive cyber. Absolutely.
Yeah. And, and we seem, and, and you know, I mean, we've, we've heard explicitly in the press, in the press conference after this attack, some of the tactics that they used militarily, the, um, they were using, um, it seems, um, air launch decoy drones that are designed to emulate other types of aircraft. Um, those of us in the hobbyist area, uh, I am a, uh, an A DSB hobbyist.
I have a an A DSB radio receiver in the roof of this building, actually. Um, and we were all used as well as part of the ruse because, um, the A DSB network, they openly broadcast that a bunch of B twos were heading west from, uh, Missouri. They openly broadcast that.
And all of the enthusiasts were able to see those, those bombers taking off and heading west, um, on Saturday in the, you know, Saturday morning, Saturday afternoon, I think a lot of us were like, Hey, what's going on? Why are all these bombers taking off? We were also seeing a whole bunch of, um, refueling tankers taking off from bases all over the United States.
It was a really interesting situation because essentially rather than having these hobbyists snoop in on activities that they're not supposed to see, they use these hobbyists as a way to, uh, broadcast a decoy mission mission going in the opposite direction of the actual bombing group, which headed east. Um, and, and, and certainly, I, I think that, uh, we saw some of this cyber, uh, operation. I think we're still in the early stages of figuring out what was cyber and what was not.
But as you point out with Iran, uh, and their, uh, internet going down, um, I doubt it was the entire country being shut down by their own government. I I have a suspicion that the US was involved in that too. So, Steven, I, I appreciate, I I love, love the, the fact that you guys, you were involved with this.
Yes, unfortunately, I, I was used by this. I was Part of that group, and I was fool by the use as well, because I saw that post, uh, up there when, um, it was like, wow, this is shocking. I think as, and I, and I brought this up several times because our utilities, state and local governments have very often, or particularly state and local governments very often have been underfunded with how they ex, you know, with their IT organizations, money goes elsewhere, et cetera.
And for that reason, those are the areas that are probably most at risk. Um, and since they own a lot of the utilities, um, I, I think about here in Boulder, you know, the utility is, they don't own the electricity, but they do own the water, water system. And so you question and ask, okay, so how much are they doing there?
What, what are we doing in terms of hardening those areas? And, and the other piece of it is that their, uh, their, their groups, their gangs that they have, the, the kittens, um, they have running around all over the place, cute kit, but doesn't Have to be kittens. I don't know how, why it has to be kittens, but the kittens that are running around, you know, anticipating that they have been worming their way into our systems and whether or not they wanna start flipping the switches, now, that's gonna be, you know, there's the option.
So If not now, When Right. If you're not gonna do it now, when are you gonna do it? Because you know, the regime change.
Well, don't say that doesn't, a a anyone who's ever, how, Anyone who's ever watched Star Trek episode right? Knows that before you attack, you raise shields. And I, I, I don't know, but it seems to me lately that, you know, this administration decided let's go into battle and we'll keep shields low so that it costs less money.
And we, uh, and, and you know, it's not as expensive. So I, I just, you know, it's that feeling of like, every other time we've ever gone into any conflict anywhere, right? Cyber defense was a, a, a, a critical factor and, you know, confirmed and managed appropriately.
And in this particular situation, it seems almost like, eh, nothing's gonna happen. Well, I, you know, they, maybe they didn't wanna alert them by by putting it, but, but here's the fact. It's not just state and local governments or critical infrastructure.
Yes, critical infrastructure will absolutely be a target, but what would a lot of the Iranian activist type of activity is more about sowing chaos, discorded go aggravation, attacking healthcare kind of things, trying to bring down a healthcare network, uh, you know, just like, not, not just what you would think of as your typical public utilities critical infrastructure. They, they want to just create chaos and havoc and, and, and, uh, annoyance, if you will. Even.
Um, but you know what, jp, I, I hear where you're coming from and, and you think about, you know, what were the real goals of this u us ventured, were they accomplished? What will be the fallout? And we can debate that on the political spectrum all till the cows come home.
But I gotta believe that there are some smart people in the government who either before this or as soon as it was announced, went to Defcon five, or whatever the level of preparedness is, and, and we're on this. I mean, we, we, it would still bogle my mind if we Did it. We've lost a lot of good people in the government with I I I, I know we have Jen, Jen Easterly being one of them.
I, you know, and Chris Krebs another, but there's still good people there and there, and the NSA are not sleeping at the wheel. So, and I think side the command, The other thing I think that we need to be wary of is sponsored terrorist organizations. Yes.
By Iran. It's not just Iran that is likely to operate. And in fact, if I were Iran, I certainly would play a little bit of, uh, Don Corleone here, and my hands are clean.
I didn't do anything right. No, I, I think you're absolutely gonna see the Houthis and the, the groups in Iraq, right? Because for all intents and purposes, for the billions of dollars we spent in Iraq, rid them of Saddam Hussein, it, it's become somewhat of a proxy state for Iran and the, these private militias and so forth, the Shia Shia militias there, I think they represent the biggest threat, especially the US troops who are in bases throughout the Middle East.
So that will remain to be seen anyway, though. It is, uh, one last aspect, and we don't have a lot of time I wanted to cover was the, the technology for the actual attack itself. You know, could say what you want about America, but we make a damn good weapon.
You know, no one does weapons better than America. No one does these kinds of bombs with stealth bombers. And you know what, even with the, the current f troop in charge of, of the Pentagon and everything, it was an as near as can be told, a flawless execution here with top flight technology.
And, you know, we could probably do a whole segment on that, that the, the tech involved, whether it be the GPS and the, the bombs, and, and, you know, NA shot was fired at these planes from what, what's been said. So kudos to American technology, especially when it comes to making weapons. We may not make the best cars in the world anymore, but g*****n, we make the best weapons.
Um, all right, let's take a break here at text Drunk Guy. We'll come back and talk about an AI land grab. Hey folks, we're back in shifting gears to some more traditional technology coverage, but there is an AI land grab underway, SoftBank mochi.
Maan is pitching a notion called Project Crystal Land, a proposed $1 trillion AI robotic center in someplace in Arizona. I'm not quite clear exactly where, but, um, apparently we also have already seen these things in China, and the Europeans are talking about building their own. So, jp, what's going on here is, is everybody gonna be basically looking for some large amount of land to build some sort of AI complex, and this is the next big thing in real estate, or is this the next big bubble?
It's, um, So the first thing is, it's, it's still undergoing, you know, certain approvals to get a, you know, to pass and become, uh, an actual initiative, right? Uh, it has a certain government, uh, you know, allocations that it's looking for certain waivers, uh, in order to be approved. But the concept is interesting.
They do this in China today. Uh, it is, you know, this concept of a manufacturing center for the most part, where the, they're leveraging the technology for artificial, uh, of artificial intelligence and robotics to build out next generation manufacturing. Now, if we look at what's happening in the us, uh, I I, it, it's a really interesting time.
We, we have, and, and it is attached to our political stature at the moment. We have an administration that's come in that's been, you know, uh, very pro let's bring manufacturing back to the us. Many advocates have said, there's no way you're going to get Americans to work in factories like you did in the old days without creating a product that's too expensive for Americans to buy.
Um, this is an attempt to say, uh, and the interesting thing is, it's not Americans who are building these factories, right? This is not US dollars that are coming in building these areas. But, you know, but it would still benefit a town or an area within, I believe it's Arizona, right?
You're, you're building hundreds of square miles of factory that's gonna need administration. It's gonna need people to, you know, be operations management around this. It can have the effect of building a, uh, community of people and schools and, and other, and businesses around the people that have to go there and live there.
'cause it's in the middle of nowhere right now. Um, if it's electrical base, you would hope they bring with it a, a top-notch energy source, which would drive, uh, uh, electric utility, vehicles, cars, things like that. Everything would be electric.
So it wouldn't be necessarily a gas run. You'd have all that operations around, they, uh, just maybe even supplying the fuel to make this thing run and keep it going, right? So there's a, a tremendous upside to the concept.
Uh, I I, I think the, you know, we, the example that is trying to follow it, it could work. Has Demonstr been demonstrable to work in other areas? I think they have some of the things they need to figure out.
I, you know, we're a, we're a capitalist society. Kind of hard to say that, uh, we're not gonna allow some, a non-American to do this. But I I, you know, if America, if the government wanted to drive with American initiative behind this, uh, they could say, no, you're not an American company.
We're not giving you any dollars to, to fund this, right? If you're an American company or you partner with a large American company to do this, then we might give you that, those dollars. So it's very, very entwined with policy and governance, uh, in order to, to get the, the full ROI to the US that it does.
And then ultimately, it comes down to we raw materials, right? Because now you're still up against that mentality of tariffs and bringing raw materials. We don't have raw materials.
So now you, you know, the, you, if you automate the development building this product entirely, where are you getting the materials to build those products? And what does that cost overhead gonna add to it? So, uh, uh, it's an interesting model to watch.
I I don't know if it's gonna get kickstarted here with this group. He has a great idea. He, maybe he could be one of the partners of a large group that is doing this, but I, I think that certain things need to change if it's gonna become reality.
Steven, can we actually do this? Or is this just a little bit, you know, wishful thinking? It's wishful thinking.
Uh, no, I, I, uh, I always take things about, uh, when, when it comes from SoftBank, I always take them with a bit of a grain of salt. This is a company that makes huge promises and, and made huge promises for an audience of one between 2016 and 2020. And now they're making those huge promises again.
Um, essentially they're saying what the Trump administration, and Trump specifically personally wants to hear, you know, they're using huge numbers, a trillion dollars, uh, as a, uh, a suggestion of what they might do without actually having any kind of prospects or financial backing to make it happen. I mean, uh, as of, uh, right now, soft banks, uh, actual, uh, liquid capital stands at about $23 billion, which by my, uh, calculations is somewhat less than a trillion dollars. Um, you know, they just raised a little bit more money by selling off part of T-Mobile.
Uh, they do have, uh, over a hundred billion dollars in net assets, but not all of that is liquid. And a lot of that is tied up in their ownership of arm, the chip company. Now, The interesting thing about this story is that according to the rumors, and again, this is all rumors, we don't know where it is, we don't know what it is, we don't know how it would be formed.
Um, we, you know, the rumor says it's in Arizona, okay? Um, where, uh, according to the rumors, the way that they would make this happen, that's the interesting part. They would make it happen the same way that we do infrastructure projects in the US by introducing and selling municipal bonds to fund this.
Now, that is an interesting aspect. And so if you combine the fact that essentially this is a company that's out there, um, saying what the administration wants to hear, and then asking for municipal bonds, suddenly this thing might be a little more real, because that's something that the administration has the power to, um, perhaps bring to reality. And that would be a way to make this thing happen.
But as JP says, it's probably that this would be a very, very, uh, automated system. It would not provide a huge number of jobs. What it would do is bring, uh, some sort of manufacturing of some sort of something here, um, in the us and that would appeal to the administration's demands to reshore, uh, production.
So I imagine that all of this is gonna be very attractive to Washington. Um, all of it is gonna create a lot of economic activity that SoftBank can take advantage of. I don't know what real benefits it's gonna create, um, if any, if, if it's really gonna come to fruition.
I wanna say, oh, just one thing about the, the location of Arizona, which is so interesting for this project, because the tremendous, we're talk more about water in the next block, but specifically when it comes to, for, to this process, the amount of pure water that would be needed to do intermittent cleanings, you know, throughout this production process is immense. Arizona's facing an ongoing drought, and it's obviously, uh, water is an issue. So it's just interesting to me.
That's where they chose to do it. Desalinization. But you know what I, I do, I do like Steven's representation of this is what the Trump administration wants to hear.
It's very much like telling him how wonderful he is. Oh, trillion, all you have to mention is the match works. Trillion dollars.
It's trillion dollars. Well, no, JP, a trillion here. A trillion there.
Before you know it, you're talking about real money. Um, but, but guys, let, let, let's, let's look at this couple of different aspects. Number one, as someone mentioned, this is not a new concept.
This has been done in China, right? Shenzhen has, has this AI robotic kind of thing. And, and in some ways, oh, But a lot of their manufacturers are not actually robots.
They're actually people. Uh, I, I think that was true. It's becoming less true every day.
I think when you go to their most modern factories and everything else, they're, they're using robotics. Steven, we, you know, let's not kid ourselves or fool ourselves into thinking they're not. But here's the point.
A project like this doesn't get done in a month or even a year. This is a multi-year project where you need to invest that trillion dollars over five years, 10 years, seven years, and you've got it. And you gotta understand, you may not see the benefits, you may not reap the benefits for seven to 10 years.
And when you're running a centrally managed economy, such as the Chinese Communist Party runs, you can afford to make those kinds of bets because you don't worry about your stock, you don't worry about, you know, the consumer price index. You don't worry about a lot of things we worry about here in the West and in a capitalist society. And so they're, they may be better suited to do this maybe kind of project, but is Don Barini and Godfather part two sets?
After all, we are not communists. Okay? So we have the ability to do things, maybe not that kind of 10 year out scope, but, but Steven, I think you're right.
You're onto something with municipal bonds. Those would be tax free municipal bonds at a locality, not necessarily at the federal level. Um, and, and that could be something like Barney, to your point, I don't know if Arizona's the right place.
What is the best place to build data centers and research for these kinds of things? We've got an article in Techstrong It on it. Yeah, it's supposed to be North Dakota, right?
Natural cooling couldn't be any of that. But here's, hold on, Mike, I wanna point out one other thing. The notion that you're gonna have all these foreign companies come in and do it.
Hey, let's be clear in the us bring your money, leave the people out there, but bring your money, right? But the whole thing that we've been talking about with Sovereign, it runs against that. What the same way, why would foreign companies wanna put that payload, that capital into American projects that could be nationalized or that they could be shut out of, or they could be tariffed on or these other things.
And ultimately that could be what winds up killing this? 'cause I don't know if we could do this without foreign companies. I think this is gonna be great for Arizona tourism.
'cause right after you go to see Tombstone, the town that was too tough to die, you can go over and visit the AI ghost town that's gonna be there in about five years. Very cool. With the dinosaurs.
Well, what I also think that, you know, when you talk about Arizona, and I, I understand the water issue, definitely. I mean, a Colorado, and they, they like our Colorado River, so do a lot of other states, but, you know, they have a, a trending there of developing manufacturing. And, um, they also have with that, they also have the college educated people that are, that are that, that, that, that, that they're building that strength.
So when you're looking at the placement, you're looking at, yes, I'm looking at, you know, the, who's gonna put the money in? And Arizona has been embracing these type of tech type of build outs. Um, they wanna see that and, and grow there.
No, Look, they built out Phoenix, Right? And, uh, and they're looking at, you know, and they've been pretty wise about how they use the water. They've got much like Vegas, um, they have developed systems for water, for water management, and maybe not all the purification, because I'm not up to snuff on that, kind of, that, that area.
But then you also look at, one of the beauties of Arizona is they're pretty well disaster free. They don't have earthquakes, you know, hurricanes, they don't have hurricanes, dust storms. Yeah, no, they don't have any of those.
So They don't have fires. There's nothing to burn. Right.
In fact, They do a big, they do a big sandstorm though, that, Yeah. Yeah. But it's there, there there's a, unless the dam one of the dams broke, you know, a meter lake Powell, you know, the water, there's not gonna be a, there's no, no real, real, real there.
So all of those things make it a positive place to go. Um, and that is, the weather is decent if outside of May, through September, I think. Um, so you can attract, It's kinda hotter than hell.
Yeah. Well, this message was brought to you by the Arizona Board of Commerce. There you, have you.
Well, a part of this is because I worked with a company that I, I did, I did a turnaround with a company that was a colo, um, you know, MSP kind of fun company. And one of the co several big, one of the big pitches we had was going to California and tell 'em, relook your your data center, your stuff into, into Arizona, because we don't have earthquakes. And we did, we, we managed DR sites, you know, for people in, uh, this is so many years ago, it Remains to be seen of water cooled data centers.
Yeah. Would be quite as attractive there. Here.
Fried water. Mike, you had a point. And then we gotta wrap this one up.
This project is so important and can't go to Arizona. It needs to be right outside. Mar-a-Lago where the president can keep an eye on it.
He thinks so with the hurricane. Yeah, because we have a large college educated group down here. Um, okay, let on that note, let's take a break.
As I said, this segment was brought to you by the Arizona Chamber of Commerce. If you're looking to relocate, speak to Kimberly. Uh, we'll be back here in Textron gang.
We're gonna talk a little bit about it. Staying on point, AI water crisis. Stay tuned.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Welcome back to the Techron gang. Well, we've been talking about AI and we even talked a little bit about water.
But for water utilities, AI is only one of the issues that they're facing. There's been a rising, a threat of cyber attacks, especially last year in 2024 for large and small utilities. New research shows that these two dual challenges are really posing a problem for water utilities in the short term and in their long-term planning.
Let's take a look. Water utilities are facing a dual challenge, the rise of digital threats, along with surging demand as AI reshapes infrastructure needs. These compounding pressures are reflected in black and veatch's 2025 water report, which finds that 95% of utilities now list cybersecurity as a critical investment priority.
There's been a sharp rise in cyber attacks on water systems last year. Cyber incidents targeted both small and large providers according to the US intelligence community. But it's not just attacks disrupting operations.
A single 100 megawatt data center can consume up to 2 million liters of water per day, equivalent to the daily water needs of over 6,000 homes. When it comes to quantifying the future water needs of ai, research shows that water utilities grapple with uncertainty in long-term planning. That's because data centers size and locations depend on private decisions.
Cooling needs also vary based on hardware, climate, and designs that companies rarely disclose. Success will depend not only on resilience, but also on clear cybersecurity protocols, coordination with data centers and infrastructure planning that accounts for evolving water needs. You know, it's interesting, we talk a lot about the grid and the surge that AI is going to have on demand, but water is also crucial as we were just discussing, because sometimes it's not just water, but it's also purified water, which might mean more water to, uh, to produce for these facilities.
So I think that there's a big question mark looking forward, uh, for these utilities. Absolutely. Bonnie and I, you know, back to our first block about potential, uh, critical infrastructure, you know, there was that attack on the water system.
Was it in New York or is somewhere in the northeast potential attack on a water system? Water is, our water is probably one of the most vulnerable of our critical infrastructure, uh, delivery, uh, systems. You know, I, I don't want to even say anything to give people ideas out there, but it, it is, it's, it's scary when you think about it.
So mon, where is the water gonna come from? Because having visited places like Arizona Water is a ongoing debate, and there's fights over who owns the Colorado River, and people are trying to redirect the river, and Southern California wants it to grow almonds and all kinds of stuff. But where are, there's only so much water, so where's it gonna come from?
You know, that's a great question. I think a lot of, um, a a lot of it's looking towards the climate tech solutions that I often talk about and ways of, um, creating more opportunities for water. But once you start getting into those political battles, that, that is a tricky one.
And I don't, I don't have the answer for that, but the water utilities themselves are not only dealing with that, but, but with this rising threat of cyber attacks, it's, it's a lot for them to take on plus the regulations. So, um, it's something to keep, keep watch on, especially as we keep talking about new data construction, you know, for data centers as Water, as much as new data centers, it's water cooled data centers. Yeah.
You could know these AI data centers that are being built cannot be cooled by air alone. And so the water demands there become exorbitant. Um, me, you know, look to Israel, look to Saudi Arabia, companies that have put a lot of money into desalinization technologies, especially when you're talking about non-potable type of watered uses, such as in an AI data center.
Um, I, I believe, you know, tech necessities, the mother of invention and politics isn't the answer here. Technology is, Well, that's, that's an interesting aspect too because, um, Mr. Solar here, I gotta say it.
Um, one of the nice uses of solar power, whether it's photovoltaic, solar, electricity, or just heat, is desalinization. And, um, one of the reasons for that is because it's, it's an asynchronous, um, use, uh, or, or load. In other words, you don't really need batteries because you could essentially run desal, um, on whenever the sun is shining and just let it stop when the sun isn't shining, because the water will just sit there and wait to be used.
So yeah, desalinization actually works really, really well. There's a, there's been some really interesting, um, approaches to this using barges, uh, for example, um, with offshore water tanks. Um, also, uh, water is nice because it is extremely, um, you, you can move it really easily.
You can pump it in these magical devices called pipes that have been invented, uh, a little while ago. And, um, and, and you can store it in these incredible storage tanks called lakes. And all of these things, um, are very appealing from an environmental perspective, but also because they solve a lot of problems.
Well, as the ice melts, right? We, we could actually use it. It's a good thing we're shipping, it's a good thing we're shipping, you know, billions of gallons of water around in plastic bottles.
'cause you know, that really helps. Well, one of the curious things, okay, so we talk about, you're talking about water cooled, but we also talk about liquid cooled because there's other Yeah, Those are two different, two different things. Yeah.
Right. And when I was at, when I was at, um, the HBC conference, um, supercomputing last year, I met with the CTO of Lene. They had a big, huge booth there.
And, and the reason why I met with them is like a, he asked for, asked for the meeting. I'm like, going, I'm game. What the heck is Vaseline doing here?
And, and part of the premise of what they've been doing, they've been cooling engines forever. And, you know, they have a lot of technology that's been involved with the F ones and everything else that goes along with so specialized technology that they're applying to this market. So, ingenuity, creativity, expansion, you know, where do we go?
And it's not just, yes, the lakes and that kind of thing, but, and we will see what happens with, you know, desalinization. So I think there's a lot there that US has in terms of our creativity of how we tackle pro tackle problems like this. Absolutely.
Interesting stuff. Great report, Bonnie. Thank you.
Hey, we've gotta pull the plug on this one. We're over time. What a great text showing gang for this wonderful Tuesday.
Who knows what we'll have for tomorrow, for Wednesday, but, uh, keep our fingers crossed that all is well in the world. We do have a full text drunk TV lineup as usual following. So stay tuned for that.
You know, just a quick thing, a quick, uh, mention, we are now doing Text Drunk Gang deconstructed on YouTube. And I believe on Text Drunk TV in the OTT channel where you don't have to watch all three blocks. If, if that's not your thing though, why you wouldn't is beyond me.
But if you just want to catch one of these blocks, 'cause you only have a short amount of time, take your pick, watch one now. Watch one later, save one for tomorrow. But watch it.
Until next time, this is Alan Shimmel on behalf of Bonnie and Mike and Kimberly and jp, and of course Steven FoST. Have a great day, everyone. We're out.
Hey everyone. We're back here on Techstrong tv. You know, I've been, couldn't wait to get this guy on.
As soon as we announced what's going on at Futur, I kind of immediately reached out and said, Hey, we gotta talk. Um, let me introduce you to Shai Bolo Shai, welcome to Text Drunk tv. Welcome to Futurum Group.
Thanks for coming on here, man. Thanks for having me, Alan. I'm, uh, super excited to start this new chapter in my life.
Uh, honestly couldn't be a better partnership, um, than futurum. And, uh, I'm super happy to be here. Very cool.
So we're gonna talk about Futurum Equities, which is this new business unit you're heading up there. But before we do, I wanted to kind of give people a sense of your story. Obviously a big LA sports fan behind you there.
Um, but beyond that, give people, you know, your journey and how you wound up being involved here in future equities. Yeah, so, uh, it's an interesting one because I started my TII started my Twitter page just two years ago. Stock Savvy, shy.
And I, mainly, my initial goal from that was to create a, um, environment where I can communicate my thoughts. Uh, my whole career has been corporate strategy. So I've worked in, uh, fortune 500 companies in healthcare, entertainments, uh, tech.
And my whole job has always been digesting data, creating a narrative, and communicating it to the C-suite so they don't have to do the work. So I was like, all right, well, I feel like I've been a fin wood follower. I go on Twitter for over five years ago to get my information on what to do with my investments.
I saw that there was a niche missing there. It was either too much data vomit, too technical, or it was just hard on the eyes. They didn't, there wasn't really a signal, any kind of messaging.
And I was like, oh, I think I could fit, fit that little gap right there. Let me try it out. And also, at the time, my girlfriend, at the time fiance now, she was sick of me talking about stocks, like completely.
I was like, uh, I kept telling her like, oh, uh, the, it was 2022 every month. I was like, it's gonna bottom now. The market, the bubbles, it's gonna burst.
It's, it's, it burst, it's gonna bottom. So I use, um, Twitter as essentially as stock savvy, shy, as like a great place to journal, share my charts that I create on my own, my Excel modeling. And then it just blossomed just something so much more.
And I think a lot of times now where my account is, uh, a hundred, I'm looking at right now, 184,000 followers. I get over 50 million, uh, impressions a month. Wow.
I just did not think it would blossom to this. And I just turned 32 this past weekend. So I actually did have somewhat of a self every year, um, every birthday.
I think it's very common for a lot of people that they reflect, uh, it's a great time to close a chapter, begin a new one. And at this one, this birthday was one I was really proud of to close that chapter because it got me reflecting, uh, not just on where I am, but how I got here. I mean, this was supposed to be a side project for me.
Uh, just me, the love of research and a belief that if I stayed focused long enough that maybe just, maybe it could, something could come of it. And now I'm partnering up with an incredible, uh, company like rum. Um, the reach, the platform that they offer and the access that they have gave me the freedom, uh, to not be shackled to the W2 Life corporate ladder.
Just the ability to turn my, uh, ideas and the conversations and turn my momentum that I had on X and what I built for myself into a real opportunity. And I'm just super excited to be working alongside a great, incredible team with, uh, purpose, clarity, and honestly zero ceiling. That's something I just have not experienced ever in my career.
And I'm excited to see where I go next now at my 33rd birthday. Wow. Well first of all, man, happy birthday.
Good for you. That's a great thing. Then I think back at 32, I was, I was doing crazy things though, um, but it was a different time.
Anyway, I wanna talk a little bit about Futur equities. We announced it when it was announced just last week, um, exciting. It, it's kind of a new branch of, of the futuri model, if you will.
But for people out here maybe who didn't see the announcement or not familiar with equities, how would you describe it? Shy. Yeah, so, uh, it's a great question.
I think the reason it's hard to describe because it doesn't exist out there. Anything that's comparable. Uh, a lot of people think about the modern investor or just retail investor.
You could call it dumb money if you want, but really they have been scoring a lot better than the smart money past couple years. Either way, it's, there's been a renaissance on where the volume of retail of investors are coming from. It's coming from retail.
Unfortunately, though the model hasn't been beneficial for retail. It's been a lot of crowdsourcing where, for me specifically, like I was able to get into Palantir under 10 bucks, CrowdStrike under a hundred rock, 11, five ion Q under 10, like et cetera. Mainly because I'm able to digest data and create a narrative.
See what's, what's noise and what's the signal due to my corporate experience. A lot of investors don't have that luxury. They don't have that time to gain those skillset.
Like part of, like, my journey when I started five years ago was, uh, Malcolm Gladwell the outlier book. I was like, if I put 10,000 hours in, like I'll feel comfortable being in a room for people who've been doing this for decades. So I put the time in.
Uh, but even then, like I stick my finger out and just see where the wind's blowing. 'cause I'm just guessing at this point, but for decades, institutional investors, like they've been winning. And it wasn't because they're brighter than me.
They weren't, it wasn't because they're smarter than me, it was because they were closer to the data, to the decision makers, to the signals before they hit the tape or the earnings reports. And that's when retail saw it. So I was like, Daniel and I have been friends for, uh, a while and we internet friends, uh, and we were just like, we noticed that there was a gap missing on what the modern investor needed.
Robinhood disrupted the whole brokerage business by creating 0% commission. And now every legacy broker followed suits. I think there's a disruption to be had on research, especially access to research.
There's a high institutional wall right now attached to actual data and, and research that will move the needle. And if it's a good investment, it's not a good investment. And where the puck's heading, and I think virtual at rum equities are trying to close that gap with air.
And by air I mean access insights, research. I think every investor, modern retail investor needs air in order to catch up for the institutional whales out there. So that's the pil, that's the three pillars of the install institutional edge that us at TUM equities are trying to build for the modern investor.
And again, like we're not doing it alone. We have some great partnerships like in Stock TWIs. Uh, we have a daily rip morning show that it's a pla and Stock TWIs is a platform that has 3 million active users daily to talk market.
So as part of that partnership, we have that daily RIP Live show. And I do think that it's one of the most watched live financial shows 'cause we get up to, uh, 10 to 12,000 daily viewers for that one hour every morning. So I think there was, um, essentially a long-winded answer on, there was a gap out there on access and providing a signal of where the puck's heading.
And right now it's probably the first time in the stock market history. We're experiencing multiple super cycles at the same time, ai, quantum space, electrification like this never been happening before with all of these things are happening at once. And because of that, things are moving really quickly.
And if you're a retail investor, like you have a difficult time of what's, what's noise and what's an actual signal. And we're trying to provide the guardrails for that to give the, uh, fut and daily signal on what people should focus on and what they should maybe, uh, that's noise. 'cause unfortunately, 90% of the, uh, information out there is just noise.
But it could really dictate your future, uh, livelihood based on what kind of investments you make today. Yeah. You Know, I I, I really think that that's one of the biggest problems in civilization today is most people just can't separate signal from noise.
Whether it's financial information, political information, just daily news or anything else. You know, we went from having, you know, three channels of tv, the infinite numbers of channels mm-hmm. Of information.
And a lot of people, you know, they're all the same and they can't differentiate between them. So it is, that is a problem today. Separating signal from noise.
You mentioned air. I want to, I wanna reemphasize that access. What, what's Air Stand for a IR Yeah.
Access Insights Research. Yeah. Access Insights and Research.
Right? Yeah. And that's what Future Equities is bringing.
Now you mentioned the Daily Signal. I signed up for day one, but tell our audience what, what is the future in Daily Signal? Yeah, so, uh, if you guys aren't aware on the institutional sides, there's usually, uh, some kind of institutional grade research note that gets sent out every morning.
You probably have seen it with the Dan Ives out there. The Tom Lees like essentially, uh, there's so much news that happens every day that it's good to give a pulse track of like, this is the big rock for today. For example, today, uh, this morning's Futureum Daily Signal was about, is open AI gonna be disrupting talent here?
'cause OpenAI is landing at $200 million, do Defense Department of Defense contract. And that's the first major like AI software contract since Palantir. So a lot of fun was getting generated overnight.
I like is does Palantir ever moats? Is that monopoly kind of cracking a bit with this open ai? And I was like, we have to send them a signal ASAP before this materializes into something that it isn't.
And our ethos on this morning's note was it's not, it's, to be honest, it's amplifying it. Because what Palantir does is it makes all these LMS operational. So when Open AI lands these major deals, it's just providing the intelligence layer for the DOD but doesn't really provide the control layer.
That control layer is what Palantir does. And nobody can do what Palantir does in that segment of what AI's gonna be. So that's just noise and that we went into deep depth on what that is.
But every single morning we're creating a 500, 600 word, uh, thought of the day, uh, daily, uh, some signal of like what caused a ruckus the day that day, uh, of, or day before that we're trying to help guardrail you through that fog of, uh, FUD essentially. And that's what, uh, we were aiming to do. And I'm glad you signed up, hopefully like, and maybe give some feedback since we're only us two weeks into it.
So open to whatever, uh, whatever narrative you want to tell us about Helping. I'm just sucking it all in right now. But here's the great thing for people watching out there, right?
It doesn't cost anything. This isn't up behind some broker wall, right? And anyone can sign up for this and get it in their email box every morning.
Well that, that was like the major, major component when Daniel and I are orchestrating what future equities is gonna be, it was, we have to make this free because there's a real subscription exhaustion among retailers. Like a lot of people have just like, do I pay this, that, this, like I started with streaming wars where like now I, I swear I pay more than what the cable cable bill was probably going to be back in the day. Now I have eight different, uh, streams that I pay for it.
And same thing for newsletters, subscription, like people like in order to get that signal, like you have to pay up for it. And even then it's really not much of a signal. This is, that's why it's becoming disruptive, where like we could probably monetize this pretty quickly right off the gates.
We don't want to, that's not the purpose. We're truly trying to provide the signal for retail investors to play catch up and have a chance to have an apples to apples fight into this beautiful game of capitalism that we all love because we're participating in it to better ourselves and we don't wanna wanna monetize that. We just don't, we're just really, truly trying to help out, um, a lot of retail investors and that's where of following a similar ethos of what Robinhood did back in the day on disrupting their brokerage business.
It's very one A, one B. Absolutely. Hey, just real quick before I forget, for people who do wanna sign up for it, where do they go?
com. We also have our, uh, Twitter page, rum equity, uh, equities. It is, um, a, uh, Twitter account that I, we post in every single day about like specific one-liners on stocks that we love.
We also just last week created a Futurum AI 15 list on non max seven names that we believe are early disruptors in what they do. Because guess what? AI is not just big tech semiconductors.
There's, or Nvidia, there's a lot of companies under the sta uh, lowering the stack that will be massive disruptors, uh, the Palantir of the world. So we sent out that list last week, uh, got great feedback. It's uh, we've gone on tv, talked about it a couple times and it's gained some traction.
And yeah, we, we create these kind of lists on a monthly basis on top of the daily signals every morning. So uh, yeah, check Twitter account, sign up, uh, for that free a it's not gonna hurt you. And my, the worst thing is just another email in your inbox.
But I really do hope that people take uh, one to two minutes every day just to read up on it 'cause it keeps you on top on your toes. com? Yes.
Yes. Yes. com.
Alright. Just wanna make sure we get that right. Shai, I don't wanna take up too much of your time, but man, I'm excited.
I, everyone at Futurum is excited about to see where this goes because there's another element, we don't have time to maybe jump into it today, but that is marrying retail investor needs to the needs of the typical FUTURUM customer, which a large tech companies where public venture backed, what have you. But what you find is information is the global currency, right? And the same information that that retail investor needs is the same information that the chief strategy officer at public tech company needs, right?
They want to know what's going on and what, what's the big story and how do they separate the noise from, from signal. So though it may, on its surface seem like, well that's really a B2C play and there's a B2B play. The fact of the matter is what underlies them both is information, right?
Yeah. The advisory services. And, and so that's where I think rubber meets the road here.
And it's gonna be really, really cool to watch to see how this takes off. One feeds the other. Yeah, totally.
I'm very excited and, uh, we're just getting started. I, I'm sure that, uh, once when we succeed, others will fall suit and that institutional wall will get taken down. Like bring back, bring down that wall.
Uh, yeah, it's gonna be a thing. I remember that. Alright man.
Hey Shai, welcome to the family. Keep up the great work. Looking forward to hearing more and seeing more of what you guys got going on at Future of Equities.
Thank you. Thanks for having me on All. What's gonna take a break here on Tech Drunk tv.
We're gonna be back in a minute. com, sign up for the Daily Signal Newsletter as a lot of other research all free for you. Hey guys, thanks to Throw.
We're here with rinky. SIE is newly appointed chief Security officer for Upwind, and we're gonna have a little chat about what's going on with cloud security. Rinky, welcome to the show.
Thanks for having me. Michael, You've been around the block a couple of times. Uh, from your resume, it appears that you've been at Twitter and a few other places over the years.
Um, from your perspective right now, it seems like we're having some sort of seminal moment here in the transition cloud security, but what's going on and what attracted you to join the company? I just joined Upwind Security. Um, it's been about four months.
Um, and it's interesting, I met Upwind back in 2022 when they were just getting started. Um, and it was the very first time, um, that I had heard the word runtime security. Um, and I thought it was gonna be another buzzword or something like that.
Um, and it was when the CEO Ami Ramad shared with me, like, rinky, you can't do security, right unless you're in runtime. And up till that point, like a lot of cloud security, I feel was driven because of compliance requirements that you needed to have in the cloud that you need to make sure that you have some kind of tooling that's gonna ensure that your configurations are right, that you're getting the right kind of reporting out of it. And you are still seeing that there were massive attacks happening in the cloud.
Um, and now having gone through many, many cloud secure, uh, cloud transformations that companies, um, it, it becomes really noisy as you're implementing tools and yet you're still not able to catch the tax as they're happening. And I became a true believer of you can't get security, right unless it's at runtime. Unless you have something in runtime.
You need to understand how, what is happening within your applications at real time. Um, and so I heard this the first time back in 2022, kind of followed the company and followed the product. Um, one of the products that we were using at the time ended up getting acquired by another company.
The quality went down and it was time for us to go do a POC and look at different solutions. And so of course upwind was in the running in addition to a lot of other, um, products. And the tech just blew me away.
Uh, and um, when the opportunity came to join the company to help them build, it was a no brainer. And so here I am and, um, I think cloud security is shifting, um, quite a bit. And, and you have to be there, um, in runtime.
And I think when we think about what's gonna happen with AI being introduced and kind of this future where we're gonna have agents talking to agents within the security, um, uh, security vertical, you are gonna be reliant and be absolutely dependent on having tooling and runtime to be able to have then those agents have access to that to be able to make better decisions. It also seems that cloud security environments are getting more complex. We're seeing so-called cloud native technologies, containers and Kubernetes alongside virtual machines and serverless and who knows what else is in there.
And to your point now we'll see AI workloads, have we reached some sort of inflection point here where the complexity is just greater than what our legacy platforms can keep up with? It's it's so true. Um, and you know, when we think about like securing cloud native AI workloads and like you said, it's like how do you secure containers and data pipelines and models and then how do you be like, how are you do, are you dynamic in terms of ensuring that you have monitoring of your runtime behavior?
And so it's security to a whole different level and environments are be becoming highly complex. And just because you have these ephemeral systems or that you have these instances that are coming up and down, it doesn't mean that you just ignore security around them. 'cause we've seen time and time again that the attacks are still happening and, and they're able, since the attackers are now leveraging ai, um, and have more complexity in what they're able to leverage, they're able to then get in really quickly, learn your environment quickly and, and behave accordingly.
One of the things about UPW is it's an early adopter of this transition to EBPF, um, which is kind of core to the whole runtime story. How much of that EBPF is out there because I, as I understand it, it requires kind of the latest versions of Linux and maybe we'll see it on Windows one day soon. But, um, where does that fit in the overall strategy?
I Think upwind was really an ear. Uh, it, in fact, I had not, again, I had not heard about EBPF until I met upw. And Upwind was a really early adopter of eeb EBPF, um, using it to deliver like really, really deep runtime visibility without trading off any kind of performance or context.
Um, and it actually made it such that they could build these sensors that were extremely lightweight. Um, and so I think it's like super. Um, and then, you know, you saw like after that, um, more companies started leveraging EBPF to build their tech and it kind of now has become a little bit of a buzzword, but really it's kind of changed the way that sensors behave.
Um, like how they do system calls, um, how they just, uh, monitor container behavior in real time. And it's, um, really changed kind of, uh, how agents work because agents and sensors had like a very, it's almost a bad word with security practitioners because of the heavy weight nature of it. But with eeb PF it's just, um, it's, it's changed the way that sensors behave.
And I, I'm a true believer that you do need to have sensors or agents in your infrastructure to have full context and um, even though that's like a hurdle sometimes to get through with engineering teams because you are sitting in their production environment. So, um, I think like this is this kind of a game changer. We've been debating this whole thing around application security now with a hard tilt towards the notion of shifting left and maybe getting developers to take more responsibility for application security.
But I can't help but wonder how practical that really is. So what's your take on this whole shift, left versus shift right kind of conversation that we're trying to have these days? I think you need a little bit of, um, I, I like it's, it's, it's hard for me because like shifting left, um, is is always been res like important.
Even when we're thinking about things like cloud security, it's like how do you, how do you uh, get closer to DevOps to how do you get closer to engineers to do the right things upfront? How do you actually make it easier such that it's kind of like just built into, um, securities built into the infrastructure and security's baked in. And so we've been working really hard at that pushing developers to take on more security responsibility earlier in the life lifecycle.
Um, but without the right tools and support, we've seen that like this can really backfire too. Um, and so to me, I think like it's not optional. We do still have to fix f we still do have to shift left.
Um, but you can't like just dump security onto engineering without guardrails. Um, so I think that's really important. Um, but then on the shift right side too, um, it gives you context.
Um, and so you're, you're shifting left. You're giving more to developers, more tooling to make sure that you're thinking about security, but then you still wanna be scanning and doing the right things on the right side. Um, so I don't think it's like, and it's like remember back in the day we was like, it's prevention versus detection and then we started going back to, well, detection is a form of prevention actually.
And so like you can't, it's not one or the other. I do really think you have to think about both. One of the other things that's also come up is, um, how much authority should security people be given to fix vulnerabilities?
'cause developers will argue, well we should fix the vulnerability. 'cause you might break things. However, the developers will then say, we don't have time to actually fix the vulnerabilities.
So, um, is there a role for security people to be more proactive about taking responsibility for maybe fixing some of the vulnerabilities without any help from a developer? It's, uh, it's funny because it really depends on where I think security teams sit and what the accountability levels are. Um, and so if you have a sec and, and again we have um, like division of access for a reason, right?
And so if you're gonna now gonna have the security teams that are governing the systems also have access to fix it, is that gonna be the right separation of duties that you need? Um, that's question number one for me. But also I think a lot of times securities teams don't have, we're you we're doing the scanning, we know we can even provide them now with AI product products we can provide back to the developers that have access to that infrastructure and system.
And here's exactly what you need to do to fix this. A lot of the tooling actually has, now they have the capabilities to auto remediate and nobody wants to do it. So like can security teams just press a button and say go fix it?
And then who's responsible if the infrastructure falls down as a result because there wasn't proper testing and things that were done. Um, and so I think there is a process and a lot of change control that goes into remediation. Um, and that's why it takes companies so long sometimes to fix some of these vulnerabilities is because there's other, you need to test it in the right way.
If something falls over, you need to go fix those issues before you go fix the vulnerability. And so, um, I mean, can teams do it? Sure.
But then is your infrastructure so resilient and is it built in a way that it's not gonna fall over? Um, so I do, I do think there's a maturity that needs to happen and I hope we move to this world where, yeah, like we just press a button and things can remediate. So what's your best advice to organizations as they kind of look at all this in the age of cloud security?
'cause even 10 years out, I feel like they're still struggling. A lot of them, it's not even the tech, it's the processes that seem to be different and they're trying to move things that they did on premise in the cloud, but it doesn't really work. So how do I get to something that feels like truly cloud secure?
'cause people still list as their top a number one issue for not moving the cloud secured. Yeah, I think that when you're thinking about cloud security, you do have to bring a different mindset, right? Completely.
Because you're now putting like the spin up of infrastructure in your developer's hands. It's no longer the same way that we used to architect applications. And so you do have to think about cloud just security in a completely different way.
Um, I think that the number one thing that you wanna focus on, yes, you build things with guardrails and you kind of set the right, um, standards, but at the end of the day you have to be in runtime. It's why I'm at upwind right now is because they're the ones that focus on runtime first. Um, and it was a hard decision at the time to make right, because you still do have to solve for regulation, regulatory requirements and compliance.
You do have to have the posture management piece, um, which all the products have now, but it's the runtime security piece of it I think is focus on like where the attacks are happening. And I think like from there, build out your program around cloud security. That's the only way I think we're gonna stay ahead.
It's the thought leadership and like how people are thinking about this needs to change. Um, there's still, I think it it, this is why I love being here too because I think there's still a lot of education that needs to happen around what is runtime, why do you need to care about what's happening right now, right this second in your infrastructure. Um, and so I think that's a really, really important piece.
And then like what we talked about earlier, I actually like the way you asked the question too. I think it's a shift left plus shift shift, right? When you stop having the versus it's like you do need to think about end to end how you're securing your cloud.
Is there something securing people should be doing about having a conversation with software development teams about security and will change their mindset? 'cause a lot of times they're like, well, security is a, maybe somebody else's job. B I'm in a hurry.
I gotta do all this thing c you send me a bunch of vulnerabilities to go fix, I go look for them. And turns out they're not running in memory or the application's not internet facing. And there's this tension that exists between developers and security people and has been there for a long time.
How do we kind of get beyond that? You ha we have to reframe security as, as a dev, like this is a dev problem. Um, and that you have to secure code when it's being written, not weeks later, not to review, not post breach.
Um, I think you have to make it personal as well. Um, and so, and what I mean by make it personal is like I think if you just say, oh, look like that company was breached or this is what happened, like, they'll be like, oh yeah, yeah, but we're better than that. And so the best way to do this is bring the data to them, like do a red team attack and show them how easy it was to get into the code.
Like into their, you know, to have an attack or to have a breach or show them that a data exposure that can happen with the code that they've written or the infrastructure that they've stood up. And I think then it's like, oh my gosh. And it's like, how long did that take?
And it's like five minutes from a red teamer. Um, or that you found it through a pen testing. 'cause a lot of times we do, what we do is we do these pen tests, then we look at all the issues, we file tickets and have people fix 'em.
There's a missed opportunity there on saying like, if this was done by an attacker, like going and driving the education on what could have happened to the company and why this could have been prevented so, so easily. And so I think winning the hearts and minds of a developer starts with kind of like show them what an attacker could have done with the work that they've done. Um, actually it's, it's interesting you asked that because like right outta college, I was trying to find my passion into cyber and it was exactly that.
I I, I was a developer, I was a computer science engineer and I was like, I can't, I can't figure out why I am in cybersecurity. And where I found it was my, one of my first roles was to go and train developers on cybersecurity. And I realized like reading the oasp top 10 to them wasn't resonating.
Their eyes were glazing over. And it was like, how do we teach security and win the hearts and minds of developers early on to understand? And um, I brought a company in that was like thinking about that differently at the time on saying like, let's just have 'em ha hands on, teach them how to hack and like teach them how to like break their own stuff.
And it, it immediately people were like, oh my gosh, I get it right. Can we have a unified approach to cloud security? 'cause a lot of folks are convinced that each of these platforms are fundamentally different and I can't really translate the things that I know for Google over to Amazon and vice versa.
Or can we really centralize this? 'cause there's people out there who are dubious, Ideally, I wish we could centralize it. And I think that a lot of companies are working, uh, towards like building a platform that can give you very, uh, b basically give you the same thing that you would see in in go GCP or AWS or your on-prem environment.
Um, unfortunately we're hearing about like some of these companies being acquired by other large companies and there's a question on is it gonna be like, are they gonna bias us more heavily towards that particular cloud? Um, I do think there's, uh, you know, like right now tools are fragmented, right? And so you have like all these acronyms, CMAP and CSPM and CM or DSPM, um, and every company is trying to say like, let's try to build this into one platform.
I know like up when we have a platform that covers everything. Um, and I think it's like really important again, like UPW started with runtime security, um, and realized very quickly we need to go build CSPM. We need to go understand identities across workloads and data and network.
And without that, people are gonna have all these fragmented solutions, which is what exists today. And so now companies are trying to say like, we have to build this into one product so that companies don't operate this way. And I know as a practitioner how I had to have it that I cared about runtime security, I went with upw, I needed other products to like help really kind of scale out.
And then, oh, now you're like stitching products together to understand your security, um, posture. And that's actually why I joined UPW is because I wanna like change this dynamic with customers and like, how do we really go and build the platform that people need or security leaders need where it is one platform because I think it is chaos today, Was that one thing you see organizations still doing out there that from a cybersecurity professional perspective just makes you shake your head and go, folks, we need to be better than that. When ai, I, I forget it was like early last year, it's been, it's been a while now, but like it was like the start of everybody talking about AI and then every security leader was like freaking out, including myself, and you're like, okay, they're gonna ask me what we need to do around safety and security.
And then the buzzwords came out like every security vendor lock came out and like was using, um, security LMS and like, here's how we're doing like AI security. And it's like, wait, are you solving for security using ai? Are you solving AI security?
What is going on? Is this LL like, and there was all these questions and you saw these like security leaders that went and like bought these niche solutions and made some vendors like really, really successful. And then you realize like that's actually a feature in a product.
And I think this is why the chaos exists. We as security leaders need to go and like push to actually have products that are solving big problems. Otherwise we have these chaotic environments where, uh, oh, now we have this feature, somebody else is building it into their platform.
Um, and we're just like creating this environment then that like needs to be stitched together. And I, I think that things are changing right? Quite rapidly.
Um, and I would say like one thing we need to look at as security leaders, um, and is that let's re-look at our programs completely today such that like, how is AI gonna impact what the future of this team looks like? Because we want our practitioners to make sure that they're going to have incredible roles and careers in the new AI world. And that, are we making sure that we're investing in the right tech and then in the right training and skills for our teams?
Because I think everything's gonna change in the future here. All right folks, you heard to hear there's more change than ever in the land of cloud security and for that matter, security in general. The only issue is how proactive are you gonna be about responding to it?
Hey Rinke, thanks being on the show, Michael, thank you so much. It was a pleasure. All right, I'm back to you guys in the studio.
In the world of high stakes data protection security is paramount and there's no more secure system than one that's air gapped. But what does air gapped mean and are we changing the definition of the way the word is used? In this episode of the Tech Field Day podcast, virtual networks are air gapped.
Welcome to the Tech Field Day podcast, where each episode we bring together a group experts from across the enterprise IT space to discuss a single topic or a premise related to enterprise it. The Tech Field Day podcast is often recorded in association with one of our tech field day events. This week we're at Networking Field Day.
Tech Field Day is a part of the FU room group and we are excited to be bringing you some of the brightest folks in the IT industry. I'd like to take a moment for our panelists to introduce themselves before we jump into today's episode. Hi, I am Carol Warner ese.
I've been in networking for 30 some years and happy to be here. Um, I'm Jason Ginner, been in in networking for uh, 20 some years and uh, also very happy to be here. John Osmond from, uh, consultant from Albuquerque, New Mexico.
Uh, most of the work I'm doing right now is working to the state of, uh, the state office of broadband and I've been doing this type of stuff for the whole now of 30 years or so. My name is Tom Hollingsworth and I'm a practice lead for Tech Field Day here at the Futurum Group. Let's jump into the premise for today's episode.
It's an iconic movie scene, an aging movie star dangling from a rig attached to the ceiling trying to hack into an unhackable computer with lights and sensors everywhere. The black vault at Langley is the most air gapped system we have ever seen on a movie or TV set, but today I'll just put it in a different VLAN and nobody able to get to it. Right?
This episode we are gonna unpack whether or not air gap networks, I'm sorry, we are going to unpack whether or not virtual networks are air gap networks. And the reason why we brought that up is because during this event here at uh, networking Field Day, we had a number of companies who told us that their solution was air gapped, which, um, created some Problematic questions from the delegates because they're like, well, what do you mean? Like it's completely isolated, right?
Like, I have to walk over with a floppy disc in order to upload information and there's an armed guard with poison chiri darts that will shoot me if I don't have the right, uh, passphrase of the day and that I don't match my photo. And everyone's like, uh, no, we're, we're, we're just, uh, sending the traffic down in a different wire. Like that's air gapped, right?
So I'm gonna, I'm gonna open this up to my, my panelists here because I'm sure that they have a strong opinion about this. Why can't a network be air GAed as long as the traffic channels are just separated? Uh, I think the, the term itself, air gapped implies there's air in between.
You know, it's that it's a, the physically separate environment, not just virtually separate. You, you've been buying those vacuum sealed CAT five cables 'cause there's air in those things. Very true.
Uh, i, I just, I just feel as though the, the term implies the, a degree of security where there's, there's a physical isolation from, from, uh, uh, the other things that, that that, uh, you know, uh, uh, that, that could, uh, result in, uh, exposure from breach. So I think a virtual environment doesn't really, I don't think it meets that criteria. Well, I'm not sure.
Um, there are some instances where you can use virtual networks and have air gap. So if the routing process doesn't know how to get to a sub done, if you can't get to the network from, um, say the enterprise has a storage network that they don't want anyone to reach. And if you can't get there from anywhere in the, in the network, then it is air gap, even if it's on the same infrastructure.
I, I just think go back to the days of ER cap and things like that. You can confuse this equipment to actually let it drop things from each of these virtual contracts into another one. So I don't think we can actually say that an air gap is an air gap unless it's physically has air.
I mean, my good friend John Pros, who was my Novell, uh, maj, was able to hide an entire Novell server on a network by e uh, changing ethernet frame types. Four workstations on the network could talk to that server. Yes, it was plugged into the network, but we considered that air gap because literally no one could talk to it if you weren't on one of those workstations.
And it was because a principal was absolutely paranoid that one of the students was going to hack into the database to change their grades. 'cause I guess he watched TCE Bueller's day off. So would, would you consider something like that where we do protocol trickery to hide things as being sufficiently air capped?
Or do we actually need to unplug the machine and run it across the room to isolate it? I think there's so many other terms for, for virtualization of network. Um, there, you know, we've got VRSI mean, you mentioned VLANs.
I think that there's already terms for that, that level of separation. Uh, and, and again, I feel like air gap implies a physical separation, uh, a a secure, uh, environment. The, a physically secure environment for, for that.
Then why do we keep using the term? Because I feel like isolated or secured or those words are way better to describe what we're offering. Why are we so hung up on air gap?
So, So when I was talking about the air gap storage network, it's truly a isolated storage gap. I use the term wrong and I think it's because a lot of terms sometimes are, um, sexier current or we want say marketing, right? Right.
And so when, when a vendor gets up and says, we are air gaped and then shows connections to the clouds and connections into the internet and collections from here and there and here and back to them, it's like, yeah, no, that's not area gap. And so there's a kind of a definition, and like in a car, there's a firewall, there's a space between the engine and the compartment where people sit. And that's an near gap.
And we expect the sort of same thing in a network. And so a network, a real air gap is a separation. You can't get between the two sort of A DMZ, All of the, all of these separations, you know, we're networking, we've been doing these things for years and years.
It's all tunneling of some type. I don't care if it's a different frame. Encapsulation on anl network.
It, I mean two secure shell sessions from one person's laptop to the same router. Do you call that Air gap connections? Because I mean, they've got two connections.
They don't, they don't run on top of each other. Um, I think that, you know, when you wanna look at it that way, I'll, I'll change my mind. That's air gap.
I mean, you've got, you've got the ability to keep things away from each other. We've got separate channels. There's no way for things to bleed through them.
So A lot of it too is, uh, level of risk you're willing to accept. So what's my definitive definition of air gap? Depends on who my customer is or who's trying to get an air gap.
Says what do you need an air gap when you say you want an air gap? And they might come and say, I wanted air gap says, do you want this? Do you want, no way ever anyone could get between things, even me when I'm built your network.
So if you wanted so that the person who designed your network can't get to some other piece on your network without walking to another room, that's a true air gap. But if you wanna say, well, you're an exception, um, it's okay if this under these circumstance of that can happen. So you have to really sort of define what do you want, what level of air gap do you mean?
Is it close? Is it like a centimeter, a millimeter, A yard? What, what about the folks that are, you know, the, the, the always theoretical, and I don't think it's theoretical anymore, the attack where you actually use air as the medium and you actually use sound to transmit things at that point.
Even an air gap isn't sufficient for these types of things. It's how do you build these channels and what, uh, you know, what modalities are there for them to actually move information from one place to another? And how, you know, is it tunneled there, is it tunneled here?
Um, where is, where is the wrapping mechanism to get the data from one point to another? And what is it, what physical medium, what protocol, medium things of those nature. I guess the question then comes up if, if we're building these ridiculously ultra secure networks, who, who needs them?
But like that's the thing. If you give me enough money and enough resources, I can make a network so secure, nobody will ever be able to get into it. You Might as well turn it off.
And that's usually what we end up saying is, is the only way this computer can be more secure is if you only powered on to do certain things with it. But then that comes back to, well, how useful is that system? And what kind of data are you storing on there that can never be observed by another human being who isn't like hooked into the borg hive mind?
I mean, we, we know that the ultimate answer is gonna be someone in the Department of Defense who has secrets that are so secret that if I even knew they existed, let alone what they were, my brain would explode into a thousand pieces. Right? I don't know that outside of maybe three things, there's any data that, that is that secure.
Well, it maybe not, it's not secure, but it's valuable. And so if I came up with a next AI algorithm that's going to someone's example this week, create a ton of fertilizer for a penny, and then just sort of change the world, change the market things, that information is totally very important to someone, right? And so that information I might wanna protect 'cause I have a vested interest in it, I built it, I can monetize it, I can make a lot of money, or I wanna change the world and feed people, hungry people everywhere.
And there will be actors that don't want that getting out. So it's sort of how valuable is the information? It's not necessarily just security information that has to be separated and isolated.
It's, um, just intrinsically valuable information. Maybe It comes down to, it comes to value, whether it's, whether it's intelligence or if it has monetary value. And then the piece that I start thinking about on this is what are the mechanisms you use to keep these things apart?
Is it, you know, is encryption ability to, is it a way to do air gaping? Can you actually say this thing is encrypted from this point to that point? So we've effectively got an air gap that no one can get into this for a given amount of time.
So what about quantum encryption, which we were talking about earlier this week. Can we use quantum encryption where someone tries to listen and it changes the data so they know it's it's an alarm and it's there. I mean, like, do we need that?
Well, but you, I think you guys are kind of, you're, you're, you're moving past an obvious problem here. Um, John, you bring up a good point. Yes.
This, this system needs to be air gaps so nobody ever can touch it. Uh, you enabled file vault, right? You've enabled login, uh, challenges, you've disabled all of the USB ports.
Uh, my good friend Edward Heke just pour super glue into the USB ports on his systems so that nobody can ever access them. Uh, you've made it so that the, uh, their sound deadening equipment, so nobody can analyze your keystrokes to figure out your password. The monitors all have those, um, polarizing grills so that you can only see them when you're dead on, right?
I've just named off a whole bunch of things that will infinitely raise the security of your network without having to isolate that machine. But what's the first thing that everybody wants to go to? Oh, this has to be air GAed.
Think about the number of laptops that are currently running a program that if they're out of contact from a main control server for more than a week, they automatically wipe. To me that's just as secure as having an air gap system because if I'm not checking in regularly, data's gone. And, but yet we get back to Tom Cruise dangling from the ceiling trying to hack the knock list out of a hacker bell 4 86.
You just said hack. How did that, how does that, how has the word hacker changed throughout the years from somebody that was clever in doing something neat to something that was kind of nefarious? So is air gap gonna change so that it's from, it's not talking about a physical air gap between things or is it some construct that we build that stops the immediate passing of data?
And the irony is, is that the original hacker Captain Crunch, whistled DTMF tone in through the air into a phone receiver to hack long distance. So not even a phone receiver is safe from hacking, but you're right. What we have gone from is people who are investigating technology to understand how it works and make it work better to, um, individuals who wanna be famous and deface things to now like highly commercialized nation state backed criminal gangs that are looking, they're rifling through executive emails trying to uncover new product releases.
They're, they're getting into like, you know, uh, business Newswire pr Newswire databases the day before something happens so they can make money off the stock so that they can turn it into Bitcoin so that they can then, uh, back a nation state government that's isolated from the world by sanctions and things like that. That's a long way from a whistle in a box of cereal. So in a world where we think that as long as we unplug the machine from the network, we're safe, is it even possible that that's not enough anymore?
You still have to worry about EMF and can you, I mean, you might have to be in a magnet, uh, enclosed space. A a a skiff, a secure compartmentalized information Yeah. Uh, center where basically it's, it's shock isolated and surrounded on all sides by deadening equipment and like, you can't bring your phone in there.
Although we've seen pictures of, uh, uh, members of Congress who just love to bring their phones into skiffs and, and the intelligence people who roll their eyes because you're not supposed to do that. And that was actually one of the things that I was thinking about was, uh, when you look at a lot of the way that information has been disseminated from supposedly secret systems as of late, you're right, this paper is colored fuchsia and has stripes all over it that says do not copy. And then I reach into my pocket and I grab the greatest, you know, uh, little minox camera that ever existed and like, and then I can upload it to my iCloud account.
So we've already found ways to get past that. I mean, look at someone like, uh, Edward Snowden or, uh, Chelsea Manning who basically plugged their iPod into their computer at work and was able to download files because it turns out iPods can store PDFs just as well as they store MP threes. And they were able to sneak a lot of information out there.
And that system for all we know could have been air gapped. So are we, are we overblowing this, are we, are we holding companies to a standard that is unrealistic by saying, you can't call it air gapped unless there's air in the middle when what we're really saying is you should change the terminology to refer to it as an isolated system or change it to a compartmentalized system. Yeah, I think it's become an overused and maybe nebulous term, kinda Like military grade encryption, right?
Yeah. Like that Military intelligence Or cloud, you know, just nebulous could mean a bunch of different things to, to different people. And uh, you know, I feel like in the modern context of marketing teams have probably, you know, latched onto it to imply a certain degree of security.
Um, but it doesn't really, I don't really think it fits the, the original context. It was, it was, you know, meant to, meant to have, Yeah. So maybe it's sort of, um, we need to hold the vendors or the people who say my system is air gapped a little more accountable and say, I accept when you say my system is isolated, my system can be secured, my system is this.
But when you say air gap and I look up the dictionary, what does air gap mean? I expect isolation and so, and physical isolation and no possible, and you can't just say, well, it's air gap because the only people who can get to it are, uh, on your own site. I, I would agree with you.
Will you look up the word literally in the dictionary and tell me what it means? Um, no. 'cause if I get up again, I'll break my knife.
Well, the thing is, is literally now literal, it literally means its own antonym because we have redefined what the word literally means. It means something that actually happened, but also something that figuratively happened. I mean, let's be fair, the name of this podcast used to be something that in the entire tech industry said, oh, when I'm talking about something happening in a physical location, it's on premise.
No, it's not, it's on premises. However, we have redefined terminology over the years, right? So why can't we just roll with that?
What's the harm in letting them say that it's air gapped when we all really know that it's not really air gap, but we really can't change what they're wanting to say. Um, may maybe, uh, folks who just be wary of the term and, and really get more information about what that means to the, you know, when they hear air gat find out what precisely does that mean? Because again, I think that the term's a little too ne ne nebulous to assume, uh, anything.
Or when you hear the term Avenger says, my technology is air gat, you just look at 'em in the face and say, you know how you tell when a vendor is lying, they move their lips. And when you say the word air gap in your lips, you're lying. But at the same time, we're practitioners, right?
Our job is to make all of the sales lives come true. No kidding. That's actually what one of my sales guys told me in my old career.
How can we increase the security level of these, uh, systems that they say are air gapped to make them more air ga? Like what, how can we as networking and security professionals, I mean I I remember stories of snort sensors that had their transmit wires clipped so that they couldn't accidentally reveal their location to people that were trying to evade the IDS. I mean, it's a little extreme.
I I don't need to carry wire cutters, but like, what, what can we do to help make this a better place so that maybe it's not air gapped, but it's ultra secure That's gonna come down to, do you wanna do it in a physical layer? You just talked about clipping wires. I mean, conceivably you could, if you knew where people were going, you could add a packet level, route everything to a dead end and a black hole someplace so that only the traffic you want going is some going to the right place.
You can do the same thing at any level in the stack. And, um, when, as I keep telling, every, every single one we're doing is a tunnel of some type, it's an as tunnel from, you know, your keyboard into that router. If you in some point in tunneling, circumvent traffic to black hole or die or go someplace where it's, where it's being assimilated and watched in any of those pieces so that you can keep track of it and air gaps.
Do you want, is an air gap gonna be something you want to look at the data? Or do you just want to throw it away so it can't be used at all? Because there's a lot of information that, you know, the stuff you would normally throw away knowing it exists is a very good in, you know, might be pertinent to you as well.
So maybe air gapping isn't the right thing you wanna do. Maybe it's, I want to corral the data I don't want so that I have it as as an intelligence source. And it might be just a discussion point.
So if my customer comes to me and says, I got this technology because it can be air gap, make it so, and I'll, I'll talk to them and say, okay, what do you mean by air gap? How isolated do you want it? How much effort do you want to separate your information?
How hard you want it to be to upgrade your devices when new patches come in? How hard you want it to be for anyone in the universe to reach it, anyone in your organization to reach it, anyone in a department to reach it. And it, it sort of, uh, will we'll, uh, open discussions.
So let's have some more discussions about what you want to say. So if the vendor might have told you it's air gap, eh, yeah, it's possible I can make it air gap, but you will never use it. I can make it this, I can make it that how I make it so it works for whoever bought it.
So it become a more general term that implies a high degree of security, but you shouldn't really dig into A potential for a high degree of search. Yeah, although it could be air gap. It doesn't have to be, and it might never be air gap.
And then when they say, oh, well I bought it 'cause it was cool, but I don't really want that. Well, all right, let's figure out the mess stuff you got, how we can build what you need. Tom pointed out words change, we still dial our phones.
How many people have had a dial on their phone for, Well, I mean, think about password complexity requirements, right? Every CEO on the planet wants the, the highest degree of password complexity so that I can't get hacked until they have to change your password every 30 days and it has to be 15 characters long with four special characters, no repeated characters and no repeats of your password for the last seven years. And then they immediately go turn it off Or network access control and It, it, yeah, I can't see the server anymore, turn it off because I wanna be able to see this.
But you don't need to see that ZTNA says you're not authorized to, doesn't matter. I'm the boss. And that's usually where we start getting into those compromising situations, right?
Is I've created a policy and everybody has to follow that policy except for me, because I'm different and special, I can totally run as root on my own box. I know I'm not supposed to, but I know what I'm doing. How bad can it be?
And we all know what happens at the end of that because that, just like every other story, the reason why those things exist, the reason why those policies are in place is to prevent careless mistakes from becoming massive disasters. And you know, something as simple as accidentally publishing the wrong API key in a GitHub repo and now all of a sudden you have a $12,000 AWS bill next month. Well what if that API key was, I don't know, the IP address of a satellite imaging, uh, system that was, uh, flying over a terrorist camp in, in Africa.
Now the DOD knows how to prevent that from happening, but does you know the contractor that just, it's getting paid $12 an hour to work on this stuff? I don't have a good answer for that. Words mean things according to one of our great delegates, Justin Warren, and he's absolutely right.
When we use a specific term to refer to some kind of a policy construct or physical security, we have to be sure that what we're doing is accurately describing the situation as it is. And look, you've been listening to the on-premise it roundtable for years, so I will be the first person to argue with that, but sometimes we actually have to take a step back and ask what we're doing. And as I've said to a number of people, if you use a better term, an isolated network, a virtually isolated network, you're gonna get the point across.
But unfortunately, that's talking to tech people who are very critical of poor word choices. A lot of people who buy technology want to hear something cool. Military grade, um, advanced AI, quantum, you name it, whether or not it actually is, is inconsequential.
If it has the right buzzword, people are gonna buy it. And so the next time someone comes into your office and starts talking about air gapping something, my recommendation is to hook them up to a harness and dangle them into your server room. And if they can actually manage to hack into your servers, you probably need to have something that's air gapped.
You should also call Tom Cruise because he's probably gonna find a new stunt person that will just about do it for this episode of the Tech Field Day podcast. I wanna thank everybody for tuning in. Uh, before we go, uh, people wanna find out more information about where you guys create content and share your things.
Where can they go, Carol? Uh, LinkedIn for me. Okay.
LinkedIn and Blue Sky. LinkedIn will work fine for me and we'll have, uh, links to their, uh, LinkedIn profiles and Blue Sky information and everything down in the show notes. Uh, we want to thank you all for tuning in.
com/podcast. com as well as on our sister site Tech Strongs tv. We'll be back next week with another great episode.
Until then, thank you so much for tuning in and make sure that you're sticking to the premise.