Techstrong TV June 26, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone has HPE become just another Nvidia AI factory town. You're watching Text and Game. Hey everyone, happy Thursday.
It's Alan Hummel for Textron Gang. Thanks for joining us today. We've got a lot to go over, including news and a report on the HPE conference happening out in Las Vegas, some of it at the sphere.
Um, let me introduce you to our gang members today as we've been doing lately, not a big introduction, but we're joined by regulars, John Schwartz, who's actually in Vegas. Terry Robinson, Mike Ard out in Denver, still at the, uh, open source conference. And, and yours truly here, though, by the time you're watching this, I'll be in New York at Platform Con.
Um, Mike, I guess we'll go to you and throw it to John h p's put on quite a show out there in Vegas. They first I've heard of a, a conference host using the sphere, which is I think a great idea. But, um, beyond the, the, uh, the optics of that is this really being, you know, are they marionettes on the strings of Nvidia?
What's going on, Mike? Great. It sure seems that way because not only is HPE using the same terminology to describe Yeah, essentially building AI workloads on, on-premise it environments.
But Teradata was out this week saying the same thing, and I've seen Dell use the same terminology. And anybody who kind of builds anything that looks like a server that goes into a local data center is suddenly singing the same tune. And Nvidia kind of seems to have scripted it, which is this notion of an AI factory.
But John, I'm in Denver. You're there. What's your take?
Yeah, so it's interesting. You stole my, you guys are stealing my thunder. I was gonna refer to these, the, uh, Nvidia as the puppeteer and all this, because coming even down to the keynote speech, I'm just looking at something that, uh, the CEO of HPE, Mr.
Neri said, he said, uh, assume it will be it's responsibility to manage a digital workforce. That's like straight out of the NVIDIA playbook. Uh, we all had our, our, uh, Jensen Wang comment as well.
He wasn't in attendance. He was here last year, but, uh, he talked about the same second Jensen Wang didn't Give, was not here. No.
Uh, what they should have done is they should have had an avatar of him that was generated by AI and have 'em appear on stage, because that was about the only thing missing from the presentation. And if I can just be really quick about the presentation at the sphere. You're right, Alan, they used the sphere almost, it almost upstaged the entire announcement.
But it also, I think in a weird way, you have a brilliant stroke because they're, they're showing what you can do with their technology as part of the presentation versus telling you they're showing you. So in a sense, I mean, I'll give them credit for that, but, um, yeah, essentially what they want to do and what they're talking about is making the enterprise, putting it back into the hands, the era of AI into the hands of it. Um, they, they were, were kind of expanding on this previous agreement with Nvidia.
And they were talking about this AI factory solutions with, with, um, composable solutions optimized for service providers, model builders, sovereign entities. Um, they also talked about GreenLake intelligence. And basically they hammered home this idea that through networking and their, they hope soon to be completed acquisition of Juniper through their hybrid cloud, and then through their AI strategy, they are going to be the solution for the enterprises.
Um, Neri made a good point that, that a, in a sense, the enterprise adoption of AI has been business led initiative, and it's not an IT led initiative. So now they wanna make the transition to the IT team and help them in administrative tasks. You know, in a sense, it's, it's pretty vanilla.
It's kind of bland, but it plays into the NVIDIA playbook. And I mean, and, and again, it's, it's sense of deja vu. Um, we get our prerequisite comments from Jensen.
We get the, uh, the hugging or the, the kissing of the ring of Nvidia. But I, in a, in a weird way, I think what HP was trying to articulate, and, and, and I, we talked to Daniel Newman who's here about it, it's in sense they differentiate themselves from their competitors in a sense with the way they presented this, um, with their software strength and the hybrid cloud. So it was overall an effective presentation.
And, you know, you, you're gonna have to start pulling out all the stops. 'cause there's so many of these announcements that are basically tread, treading or trodding over the same ground saying the same thing, the same phrasing. It's almost as if NVIDIA has decided they are going to be part of the presentation of every conceivable enterprise announcement in, in this field.
And it, they're imprints everywhere. Maybe, you know, I look at this stuff and I scratch my head a little bit and I go, you know, they're, they're so busy on the hype and following the thing that they're kind of missing the point. And what seems to be happening is that I would say the first generation of AI platforms were built by data science teams that had their own internal IT infrastructure people attached to that.
And they built a single application that ran on a single set of hardware and servers. It might have been in the cloud, but a lot of times it was in an on-premise environment. As this evolves, it's pretty clear that every application's gonna have some AI capability, and we're gonna need infrastructure that can run multiple AI applications, and it's gonna have to be managed at a level of scale that is highly distributed.
And that requires the traditional IT team to show up and kind of manage all that stuff because the folks attached to the data science team are not gonna be able to do this at scale. And that's why you see HPE and Dell and everybody else showing up saying, you know, we need something that feels more like a little more turnkey, like traditional servers versus all this custom infrastructure that we've been building out for the last couple of years. And in my mind, that's, that's the big shift here.
And everybody else seems to be kind of just, you know, trying to say it's gonna be an AI factory. Frankly, I don't really like that term 'cause who the hell wants to go to work in a factory, but, Well, they, they, well, according, according to our government, we got a lot of work That does that. You know, I know, You know, I have a few other thoughts here.
Look, if it's, if it's Nvidia, who's pulling the strings at all of these shows, does that make Jensen, El, pa Gino the Godfather, right? You kinda like the, the Mario Puzo thing, but Mike, to your point, look, I think the first generation of AI stuff was very much experimentation. It was very much first generation, and it was sort of bespoke, you know, custom kind of thing done for very specific tasks and, and solution sets.
But now we're looking at ai, you know, to do a buzz and woody meme. Look, Woody ai, as far as the eye can see, right? AI for everything.
And in order to do that at scale, you are going to need mega factories like where Elon produces his batteries or wherever, right? You, you're going to need these. And, and, and quite frankly, we so much, at least our focus here at Textron on AI is how AI helps generate code and makes, can make us more secure and can help us build platforms.
And you know, how we use ai and it, well, let's not forget that much of software development today is done in a software factory where we have different teams on the factory. In the factory, we have developers, we have platform engineers, we have DevOps engineers, we have SREs and security folk, right? All working on the factory floor, so to speak.
So now that factory's an AI factory, same people, different name meet the old boss, same as the new boss. Yeah. Yeah.
It's like the, it's, it's, it's the whatever, what did Benioff call it? I always, I always hated that phrase, but it was the fourth industrial revolution, whatever the hell it was. Um, HP and I talked to a couple of the executives here.
They're just hammering home, trying to reach the CIO level, the IT level as the service brokers, the folks who are gonna put this into play. So yeah, we, we can romanticize about, we beginning in the innovation, now we're kind of reaching the mass deployment where things become a little bit more watered down and not as exciting or sexy. They're, there's, they're trying to be more practical.
So we're gonna see, we're gonna get hit in the head with this over and over again. No, I, I think so. I, I think the bigger issue is, so you take your hps and your IBMs and your Amazons and your Googles and your Microsofts and, and all of these other, you know, oracles, you know, the, the big tech players who can, you know, churn out these factories for large enterprises, and how are they, how are they separating themselves, right?
So Nvidia is a tide that's lifting all of these boats, but are they truly interchangeable or will we see, you know, spheres of influence, spheres of, uh, of, of specialization that separate HP from Dell, from IBM? Or if they're all the same and it's a commodity race down the toilet bowl, that doesn't bode well for these companies. I don't know.
It's really the same. But I will also point out that will happen for sure, as CIOs will be getting out their pencils and they'll be grading these AI project bills and there'll be like a bill running through Congress. There'll be so many additional writers and things that they're adding to that, that have nothing to do with AI because they just wanna make sure that they get approval for a hundred other things.
And Yeah, we blame for that either. That's the way of it. Some, as much as things change, they stay the same.
Anyway. John, is is the show over now, or is today? No, It's still going.
There's gonna be a second keynote I talked to. Uh, there's a lady who, who oversee, she came from my, from Intel a couple of years ago. Trish, uh, Dan Kroger, who's gonna be giving, Who applied for asylum or something, or Yeah.
Yeah. I can't get outta here soon enough. Um, but, uh, yeah, no, it's, it's an interesting show.
You know, I, when, when I see these, uh, when I see these things, I'm trying to figure out what is it unique about these companies that they're gonna announce? And for the most part, there really, really isn't much. So I'm always trying to find, and I think we we're all kind of talking about this, this idea of how do you di differentiate yourself and not become part of this morass of, uh, of mediocrity, right?
Where you're just stuck in the, in the middle and in in Foot soldiers in the Nvidia crime family. Yeah, exactly. Wow.
Yeah. I didn't think of it that way, but, um, yeah. Um, yeah, we'll stick with that.
That's more interesting. Yeah. But, uh, yeah, no, I think what they, what they were trying to do is they were using the sphere.
I mean, cynically, they're using the sphere as the star of the show. So they had two events here. They had the keynote, which is pretty effective.
And then they had a concert later. So, uh, they're trying to spend as much time there as they are actually at the convention center. Well, The sphere is spectacular.
Who? Oh, it's play with the concert. Yeah.
Oh, it's Kenny Chesney. Yeah. Well, He's there now.
Yeah. Yeah. Very cool.
I must, yeah, but, So, but I mean, you know, the thing too is I, I wonder if, and the people at HPE were telling me that they actually, that, you know, they admitted to me about off the record, like we're, we know we're considered a dull company, but we think the way we use this venue might influence the way other companies do it. I think they're onto to something I, I Surprised, I would say I think other companies will too. Now, service Now will probably do it.
Adobe definitely should do it here. Um, I can't wait to see what Nvidia does with it. Nvidia would do it in spectacular job.
But, um, y'all see, Alright. I would, I would encourage as many venues as possible to use the sphere so that the Dolans will have enough money to buy a good center for the Knicks. Oh, gosh.
I, you know what, we're gonna end this one. We'll take a break. We'll be right back here on the text.
Hey, folks, we're back on the B block, and we're talking about, well, what's real and what's not real here with these AI coding tools for developers. I mean, clearly there are advances that are being made, but there's always this kind of hype cycle around this stuff. And you hear people talking about, well, we won't need developers.
Developers won't need the code. They'll just review code and we'll get rid of most of the developers and we'll only have architects from here. And there's all kinds of noise in the system all over the place.
So we have this article, and it's a moment in time and it basically outlines what actually works and what may not work so well. And one of the things that works well is anything to do with project management. And it will definitely generate code, but a lot of that code may not know enough about the environment it's gonna run in.
So it lacks a lot of context. So human developers might have to go in there and tweak it and make it work for that environment. But then again, they didn't write it in the first place, so they didn't know how it works.
So now they're feeling, well, maybe I should have just wrote this whole thing from the ground up myself, Alan, you know, you hear all the same noises I hear. What's, what's real in your mind here, and where are we on this journey? You know, I, I would say we're still at the beginning of the beginning, not even at the end of the beginning when it comes to AI generated code.
And, and, and, and what I find interesting, Mike, is the proficiency of AI generated code. And, and the progression wave of how it's getting better, I think closely mimics the progression wave of AI generated text writing, right? When, when, when AI first came out, it was very easy to spot something that was written by ai.
It had, it was cold, it was, it, it, it, it just, it was easy to spot. It's gotten much harder, though. I think it's still, for instance, I think this article on Devox was AI assisted, let's call it.
Um, I think it's the same thing with code. You know, the latest version of Claude, what do they call it? Claude code or something like this, is, is supposed to be much, much better at, at generating usable code for the foreseeable future.
And when we're talking in text, foreseeable future six months, right? 12 months at the most. I think AI generated code is still a question of having a co-pilot in the co-pilot chair next to you.
I don't think, except for the most rudimentary kind of apps that you could probably do in no code today anyway. You, you would have, you would be relying on AI generated code for the majority, for the heavy lift, right? I, i, I just don't, I I don't think it's there yet.
It seems like these things get better in, in, in leaps, right? Every six months or so, there seems to be a leap forward. And Terry, I wanna get your opinion on something here.
'cause somebody was telling me this this morning. He said, you know, the leap that we saw at the beginning of this year, the tools actually recognize, you know, SQL injection vulnerabilities, which has been the number one flaw since staying for, for a decade now. And they were saying, Hey, we might get to a point soon where that's no longer gonna be an issue because AI coding tools will actually not generate those types of vulnerabilities.
However, they will generate other types of Vulnerabilities. Well, therein lies the problem because I, I think that's right. I've heard that as, as well.
Um, these, these tools are gonna, you know, really spot the security issues or some things, the SQL injection being one. But, um, and, and that'll be good for security, right? But it's gonna, it's, it's still, uh, can be used equally, um, for bad, I think.
And there are gonna be some things that are missed. And this vulnerable code will be repeated. I mean, there are still all of those issues.
Um, I think what it's really super good for is putting it up for review. You know, putting your code up for review and seeing if there are any issues, um, there. But I think, Alan, you're kind of right.
It has to be there, you know, as a co-pilot, right? Because there has to be this human oversight and this monitoring. Um, otherwise, uh, I think it could be a disaster.
Uh, as far as security is concerned, A a and, and security is though security, I always preach that security be, security should be synonymous with quality. There are other quality issues beyond security with AI generated code. Is it, is it resource the most resource efficient code, right?
Is it run like a pig or is it really optimized? Now, one may say that the, a great use of AI is having the human right to code and maybe asking the AI to optimize it, right? And maybe that's what these seats, but, you know, there's a lot we could do.
But, but Mike, to your point, and what I was saying off the top is, look, this is progressing. You know, this is, this is multiplying faster than triples on Star Trek. And, um, you know, nine months from now, who knows how good a year from now, a year and a half from now, you know, this, we, we will be eating our words.
But as, as we look today, this is, I think, the state of the art. There is an interesting generational divide starting to emerge where the younger developers are saying, well, this is great. It makes me more productive and I can create stuff.
And I think that appeals to maybe the senior level business executives. 'cause they hear that that means that I can use, uh, developers with less experience. But the older developers are saying, conversely, this is great 'cause I don't need any junior developers running around.
'cause I can use AI to do all this stuff. And that they will be the primary beneficiaries thereof, and they will become more efficient. And it will be just harder than ever for your junior developers to break into the field in the first place.
'cause junior developers don't know anything about how that app runs in, say, a retail environment or, or financial services or whatever it is. I don't know how much of this is kinda, you know, just old guard versus new guard, but It's an interesting conversation that's being had Out there. Well, yeah.
And then where does that, I mean, you have to think beyond that a little bit. Where does that put younger developers later on in terms of their trajectory, you know, to develop? I mean, if all of this stuff they're being replaced at sort of the, the lower levels even, um, then we're not really developing a cadre of developers that have the expertise and can move forward.
You know? Um, Well, I I call this the reverse Logan's run. Speaking of generational gaps, Mike, I think I make reference to my Star Trek reference, but it's a reverse slogan's run, right?
If, if we kill everyone when they're 30, we don't have any people over 30. And, and, and it's the same thing. If we don't have junior developers cutting their teeth, we don't, you know, eventually when those senior developers run out, you don't have anyone taking their place other than maybe the ai Okay?
So that, that will be a lost art, Maybe not one that we should lose. I mean, there's some things that I, if you lose them, I absolutely agree we shouldn't lose it. But are we destined for the servo chairs in Wally Voi, whatever the movie was.
I, you know, I don't know. I I, I'm concerned about that. I also get concerned about, and this is going to really make me sound like an old fogey out there somewhere.
I get concerned about developers who then come up in sort of this newer environment and they don't have that sort of experience of way back when development, the environment was locked down and, you know, things were done a certain way and with a lot of attention to, I guess, security, um, as maybe more than today. But I do worry about that, You know. But, so guys, let me just say this though.
We've been doing Text Strong Gang now for, is it 18 months? Something like that. And we've been talking about AI for at least that long, you know, a text strong.
And we've been having the same conversation. Is AI good at coding? Is AI gonna replace my coders?
Is ai, you know, is it in terms Of any type of content creation, will it replace whomever, not just coders, but writers, Editors, editors, tv, video hosts, editors, yes. Could be, you know, am I real or am I in ai? But, um, you know, and we, we've seen progress, as you say, Mike leaps and bounds and progress.
I mean, I don't even think it's every six months. I think it's every couple weeks with that renew release of one of theses, you know, they do better. Do you still, you know, at some point though, does the, does that progression graph curve flatten out, right, where we can't make further, uh, improvements without some hot new chip?
I mean, is there like a wars law kind of thing here where it continues on that upward trajectory? Man, if I knew the answer to that, I probably wouldn't be doing this. Um, so, but, but I think that's really the issue.
Not a question of where we are today, but how fast tomorrow comes. Yeah. And I just feel like right now, too much of this conversation is wrapped around the fear factor, and everybody's trying to kinda, and I don't know, some, you know, you read stuff in the Times and they'll say, you know, see the C level execs are trying to use AI as a boogeyman to, you know, whip the labor force into line.
Um, others would say, you know, the fact of the matter is that it's the labor force that may benefit most. 'cause a lot of that toil that wears them out and kinda makes them cranky at the end of the day might get eliminated. But, you know, it's not, not for the pioneer With your jobs, right?
You know, with the job, it's, it, well, the caveat is, oh, but there'll be better jobs. So there will be better jobs. I don't know what they'll be, but there'll be better jobs.
But it's the thing, you wanna know the truth. None of that matters. None of that matters because we live in a market driven economy and a market driven system.
And if someone could do it better, faster, cheaper, they will, in spite of what the focus in New York City may think. Right? We're not communists, we're not even socialists.
If, if someone could do it, if some, if I could use something to do it better, faster, cheaper, I will, and the market will reward me. That's, that's the bottom line. So we could wr our hands and woes me all we want, but that's the realities of, of the market fair.
I, I would say that it's fair. I just don't think it's gonna reach a point where it, it does not require some sort of human supervision oversight anytime soon. It shouldn't reach that point.
They said the same thing about driving cars, Of, of which, you know, most people are not driving reason Yesterday show about the rob taxis. But anyway, we, we shall see, we shall see. As, As I look out my window, I do not see any self-driving cars going by right now.
I know, but three, four generations. Four generations. Well, yeah, Austin and Phoenix.
Yeah. Three Phoenix or four generations ago, Mike, your grandpa or great-grand, looked out the window and said, I don't see any horseless carriages that, so I mean, there is that. And, and, and, and if he did, he yelled out the window and told the guy to get a horse.
Well, that, but that was a, I I saw a meme on this recently, right? A guy telling a horse, don't worry, something's gonna have to pull these carriages. You know, that we weren't gonna replace the horse after all.
I think horse might like to be replaced, to be honest with you. Let's get awfully tiresome pulling those carriages. Absolutely.
Anyway, all right, let's take a break. We'll come back here on block C four, the Text on gang. Good conversation.
You're watching Textron Gang, Discover Techstrong group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Techron Group. All right, we're back talking about our final block, which is cybersecurity focused in the sense of, well, you know, there are these people out there, bad folks adversaries, and they too have access to ai. And turns out that they've been doing a little innovative work on their side as well.
Terry, you were a story talking about how the bad guys are using Grok and Mistrals mixed troll platform now, and how much of this is gonna continue. 'cause it seems like, you know, from my perspective, they may be doing this faster than the good guys Are. I think the bad guys are always a little bit faster than the, than the good guys.
Um, that's just my opinion. But, um, yeah, so, um, you know, this all centers, our, the conversation starts with warm GPT and you guys might remember, I mean, follow me back to the summer of 2023, and it had its sort of blaze of glory warm GPT for about a month, right? And, um, and then one of the founders actually, I guess shut it down, uh, was getting ready to get in a little bit of trouble.
Um, and that happened. And so, um, I think when I was working on the story, I thought, this is a surprise, but not a surprise, because you expect, uh, uh, generative AI and whatever to, uh, be insinuated into just about everything, uh, uh, these days. Um, and also you don't ever expect that worms and other things go away completely, right?
They always seem to come back and, and, uh, and have a, a new life. And, uh, worm, GPT was kind of interested because while the, the sort of original flavor went away, um, it's been sort of the basis, um, for these, these, uh, these, these worms, uh, that are a, that are AI powered through, I guess the last couple of years. Um, it's, I think somebody called them.
It's like the, the Kleenex of, uh, of, uh, of, uh, of worms. But, and so everybody, you know, it, a lot of these things have been built on, uh, worm, GGPT as sort of ended up, um, happening the stuff for a while. And, um, really, the folks over at Cato Control went back and looked at the last couple of years and found out that, um, a couple of strains, um, had emerged that were powered by gr our, um, mixed trial.
And, um, that's got some interesting implications for security for sure. Do you have a sense of whether these strains are more lethal or less lethal than the strains that humans created? Or, or is it just gonna be, there's a lot more of 'em?
I think there's a lot more of 'em, but I also think that maybe the, the real issue here is it allows, um, attacks to scale. Um, it's, uh, I guess the, the, the breadth and the depth of, um, the problems that it can cause with security is, is just much greater. So in that sense, maybe more lethal.
Yeah. Alan, The other thing that I'm seeing too, is it seems like the malware as of late is better at evading the defenses that we have. And I got a sneaking suspicion that that may be because somebody's using AI tools to keep generating new variants of the same malware that makes it difficult to detect.
But, Well, Mike, I've heard rumors that a lot of these variants were actually developed in a lab in Wuhan and, and, and they've escaped into the wild. But, um, you know, shades of mRNA. But I mean, here, here's, here's, here's the, all kidding aside here.
Here's the fact. I I had this conversation the other day with the, the CIO of a company called Deep Instinct. They, they, they have an AI that helps with security.
Don't think for a second, for even a millisecond, that the people who propagate worms, the, the bad guys, the black hats, whatever you wanna call them, are not as proficient or maybe even more proficient than some of the best security people we have. And so, of course, they're using AI to polish up and upgrade Uplevel upskill their work. You're seeing it across the board.
Look at the phishing emails you get now compared to what you used to get. You know, phishing emails used to look like they were written by Boris and Natasha, you know, kill squirrel. But now they, I mean, they, you gotta look really close.
They're written really, really well. Well, that's, as you were saying in the earlier segment about ai, you know, generated writing has gotten so much better. It's the same.
Yeah. So why, why wouldn't, why wouldn't these guys be running their worms and, and, and telling the AI to create a variant? Now, this is where you get into this whole issue though, of do you have guardrails on your AI and LLM that if someone says, create a variant of this worm, it says, no, I can't do that.
And then you're gonna have, you know, unlocked ais and LLMs that are only too happy to do that for you. And you set up this whole kind of underground of, of, of, you know, against the Empire Renegade ais turning, turning out this stuff. Um, or if you're a researcher, researchers might have valid reasons for asking an AI to do a variant of some code thing to, you know, similar to fuzzing in, in terms of task and code and everything.
So this is not as a, uh, this is not an as easy thing as, as you would think, Terry. It doesn't look to me like the guardrails that are in place really do much. 'cause from what I'm reading, the, the bad guys figured out how to work their way around those things pretty Easily.
Right? And that's ev just about everybody that I talked to for this story said that, right? The guardrails don't work, which means you're gonna have to rethink what those guardrails might be.
Well, they Don't work today, they don't, but maybe, maybe we got more, more thought into making better guardrails. Well, maybe, maybe so. And, um, is the answer around like, sort of, we, we've talked about this before, maybe limiting AI automation with that, you know, uh, uh, help better monitoring, um, to, to try to, to, to, to spot the problems and then adjust your guardrails accordingly.
Perhaps, maybe guardrails aren't solid, maybe they are a little bit, uh, flexible. Um, I don't, I'm a security person saying that, I'm sorry to say, but I think that's possibly the case. And, you know, um, I, the, but the guardrails clearly aren't holding up at this stage.
No. I mean, again, I, I, you know, guardrails are sort of artificially grafted on to the ai. They're not, maybe we need to design AI guardrails built in from the get go.
And maybe there'll be, I, I don't know what the right answer is, is, is the bottom line. Certainly. Well, that probably Hits on it too, is, you know, it, there's a very, you know, this is stronger evidence that we shouldn't bolt on security any longer.
I mean, and that's what's happened with AI because, uh, generative AI and a particular, because of it's rapid growth and Any topic with every technological innovation for as long as I've been in tech 30 plus Years, no, but this has potential to just explode. So, you know, so quickly. And I think that's, um, so yeah, I'd like to see, um, those guardrails bit built in from the get go.
Well, here's, here's what I think is wrong with the guardrails, is the people who are building 'em are the same people who build the LLMs and they're designing those LLMs to be as useful and as friendly as possible. And well guardrails kind of go against that notion. So maybe the folks who build the guardrails should not be the same people who are building the LLMs.
Yep. 100%. Or they need to at least work In concert, Right There.
Is that? Mm-hmm. Alright.
Um, guys, I think that's gonna wrap up our Textron gang. Mike, you're due home tomorrow, John, you're coming home tomorrow, I take it, uh, I'm coming home tonight or to the SE today. Yes, whatever today is.
Yes, I'll be on dial. I'll be on the gang. I'll be on the Gang from Denver tomorrow, but then I'm hopping on a plane Immediately.
I feel like I need to go someplace so I can come home, Or, yeah, you gotta, we, we, why don't you go to the next Las Vegas AI show, Jerry? I might do it. Maybe they do it at the sphere and talk about a, the sphere.
Have a good time. Alright. Until next time, though.
Wherever you are, enjoy Text drunk TV immediately following our gang show today. And until then, is Alan Shemel. We're out.
Hey, everyone, welcome back here to Text Drunk tv. Happy to introduce you to my next guest. We were talking so much before we got on camera, we almost didn't have time to do this one, but I wanna introduce you to Russell Fishman of the Stanford Fishman's.
He's Stanford Fisher, he's the senior director. Yes, the senior director, global Head of Solutions product Management over at NetApp. Russell, welcome to Tech Drunk tv.
How are you? Very good. And thank you for having me, Alan.
My pleasure. Russell, as I mentioned, your senior director solutions, uh, global Solutions product management over at NetApp, but give people a little bit of a sense of your journey. Yeah, thank you.
Yeah, well, um, based in the northeast of the US and you can tell that by my native accent, my native folks. Yeah, You sound like a Yankee Rocks accent actually Is Yeah, I was gonna say it's a, yeah, it's a Yankee accent, but go ahead. It's A Yankee accent.
Yeah. Yeah. So actually no, I, I started off my, uh, career in the uk, uh, originally an economist, uh, long story how I got into, uh, tech, but worked, uh, started off my career at a company called EDS.
Remember Electronic Data Systems, Rus Perot, That's right. Was was there for about 10 years. Uh, got the opportunity to do lots of different things in lots of different parts of the world.
Really great, uh, sort of foundation for my career. Ended up at HPE as part of the acquisition, moved to Cisco, um, ended up at NetApp. I've been, been in NetApp actually 10 years, which is, you never go into these things thinking you're gonna be there for 10 years, loving it.
And, and NetApp has, you know, has been such a, an organization that's transformed completely during the time I've been here. But it's, it's been super exciting. So, yeah.
Uh, lived all over the world, but now based in the us uh, with family, et cetera, et cetera. Um, yeah, and, uh, look, I'm, um, I'm a product manager, but I have a tech background. I also have a business background, obviously, with the, being an economist by trade.
So, um, you know, I, uh, I always, you know, my, my role at NetApp has always been, and I've always been very focused on, on customer. So what does that mean? Obviously everyone says that, but, but solutions at NetApp really, it, it's the glue that connects our product portfolio with, with customer use cases and customer outcomes.
So I spent all of my time talking to customers, talking to partners, learning latest trends, working with analysts, um, and, and sort of designing the roadmap on what we're gonna do in terms of bringing our portfolio to help customers in a wide range of different areas. AI being of course, probably the most interesting right now. Absolutely.
Well, everybody's interested in ai, right? Um, sure. Fantastic.
What a great story. Russell. A great journey.
So NetApp, everyone in our audience has heard of NetApp, unfortunately a lot, not a lot, but there's a good percentage of them who still think of NetApp as network attached storage, right? And, and you know, that kind of thing. And of course, NetApp has been so much more for so long, um, including write up, you know, the very current AI stuff.
How would you describe today's NetApp? Especially, you're there 10 years, Russell, how would you describe today's NetApp to our audience? Yeah, it's a great question, Alan, and, and there's so many aspects to what NetApp does, but at its really core, we like to think of ourselves as an intelligent data infrastructure company.
Now, that sounds like a marketing blur, but it actually isn't. It really talks about the value that we bring to, to, to, to organizations who are trying to make their data do something for them, right? And we, we, we firmly believe that customers that are organizations that are sitting on essentially goldmines of data and, and we're, we're looking at new workloads like ai, where the fuel is the data.
How do we make that data ready for these new workloads? Where is the data? How do we bring it together?
How do we operationalize it? How do we simplify it? So NetApp, you know, made a bet, I think maybe 10 years ago, maybe a little bit more on, on cloud.
Uh, we, we believed that the future was hybrid. Uh, we went about taking our, our class leading storage os ONTAP and, uh, OEMing it essentially to the hyperscalers. And that turned out to be prescient.
Essentially, what we did is we created these endpoints that allowed us to make it so seamless for organizations to manage their data wherever it needed to be managed. Uh, they didn't have to take it outside of their, uh, you know, their, their own governance domain, their own security domain, that they could make it available for all these new workloads. And of course, that takes us right out to ai.
I've been doing AI for about five years, and, you know, essentially all these bets that NetApp made are just perfect for the world of ai. We have, NetApp has about a hundred exabytes of data stored on us today, right? Um, you know, and you know, our history has definitely been things like unstructured data, but if you look at, we've got a, we, we see a sort of plethora of different data types.
It's unstructured, it's semi-structured, it's structured data, it's, it's file, it's block, it's everything you could imagine on the storage side. But again, the focus is really on the data manageability side. So, yeah, you know, NetApp is not, you know, is not, you know, we, uh, you know, we started off in filers many, many, many years ago, but the company has gone through so many revolutions since then that you could hardly call us that anymore.
Absolutely. I agree with you. A hundred percent crazy.
All right, let's, let's shift gears a little bit. Um, NetApp recently did something called the AI Space Race Survey, Right? Yep.
Yeah. Tell us about it. Yeah, so it was a, it was a report that we, we commissioned and what we wanted to do.
We, we, listen, we're we're at a really interesting juncture in, uh, in AI in particular. Um, you know, we, we've we're coming out of what I, I like to call the POC wave. And I know that's probably an overs simplistic view, but if you, if you think about what's been going on in organizations and the source of organizations that have availed themselves of ai, try to go down that path, um, so many of them have really been trying things out.
So few of those projects have made it into reality, right? But at the same time, what we see is an incredible interest at a nation state level for how important and critical a AI is gonna be to the relative competitiveness of these different economies across the globe, right? So, um, you know, as we've, obviously NetApp's been involved in AI for, you know, seven and a half years we've been building and helping customers.
Ai, we wanted to go out beyond the confines of NetApps install base, but really to the industry as a whole and, and ask, you know, folks, uh, leaders in, in about, uh, in, in four different countries. That's the us, China, India, and the uk, which we thought was a fairly representative set of, of countries economies. So across both CEOs and IT execs to understand how do you perceive your own I AI readiness, how aligned are you within your organizations?
And, and, and really who thinks they're winning the AI race? Who's actually positioned to lead over these next five years and try to understand the role of, of, of, of government and policy in driving this, uh, this huge wave of innovation compared to, of course, the private sector who's obviously seeing a huge opportunity, but maybe thinking about things more through a financial lens. So it, it, it is super interesting, and I hope we get into some of the details about what we learned.
It really, the, some of the data we got back was intriguing. Well, that sounds like a setup if I ever heard one. Yes.
Right? Do tell, Do tell Russell. Yeah, Yeah, yeah, yeah, yeah.
So, so, I mean, I'll, I'll give you, I'll give you a sort of an interesting, one interesting example of some of the data points we're gonna talk about, right? So, uh, you know, I talked about this idea of the CEOs and IT execs, and we asked both of them. And, and the reason for that is because, you know, the perception of the CEOs and the reality of the IT execs aren't necessarily the same thing, right?
And sure enough, that's exactly what we found. So in the US for example, both CEOs and IT leaders found themselves around the same percentage of readiness. So 61% of both CEOs and IT leaders in the US found themselves ready for ai.
Now, of course, you know, that's, that's their own perception, but, but it was, it was stark that both sets of these groups said 61%. About 61% said they were, they were ready. But then we looked to China, the, the, an extreme here, 92% of CEOs in China believed that they were rep or actually deploying ai.
They were deploying ai, but only 74% of the IT leaders believed they were deploying ai. So, just to be clear, CEOs believe that they all, essentially, 92%, the vast majority were deploying ai, were only actually less than three quarters actually, were actually doing that, that those deployments today. So, you know, I, I think that, you know, this is one of the things what we'll talk about as we go through it, you know, um, it turns out that this idea that, that that intelligent data infrastructure I mentioned, which is kind of scalable and it's secure data, actually turns out to be one of the biggest and most important, the most decisive factors in whether AI ambitions translate into lasting advantage.
And, and, and we, you know, you wouldn't think that, I've gotta tell you this one thing, Alan, you know, the, um, if you, if you go out in, in the industry and you go to a bunch of folks, a bunch of customer organizations that haven't started the area AI journey yet, right? They're, they're just getting started. They've read what they've read, they think there's opportunity there, there's potentially money to go do, to go and do something.
Most of these folks think that the problem is a, what we call an accelerated compute problem, like GPUs, essentially, right? Mm-hmm. And, and listen, uh, so much credit to Nvidia for doing what they've done, right?
They have, they have made this all about GPUs and God bless, that's a fantastic thing for them. And by the way, our GPUs are not insignificant part of the problem, right? But it's quite telling that, um, you know, in the last GTC, which is NVIDIA's public conference, what we heard was that their CEO Jensen talk about data for about 40, 45% of his time.
Just to think about that. This is a company that doesn't sell data solutions, right? They sell AI GPUs, but more importantly, they sell an incredibly rich framework and software stack to make AI real.
And they were talking about their data management partners. Why do we think that is? It's because About the data, what's holding Them back is the data, right?
That's how important it's become to them. So anyway, yeah. Well, we should dig into a, a few more things, uh, around the report, but I just thought I'd give you that background.
Yeah, no, it is very interesting. Russell, a couple of thoughts on it. It is, first of all, you know, the AI is as good as the LLM it was trained on, and the LLM is as good as the data that, that it's made up of, right?
And, you know, the, the first L in LLM is large, Right? And, and the, the larger, you know, at some level, the larger the better. Though there's also people saying, no, let's go for small language modules, right?
That are more keyed in, into a very specific narrow field, if you will. But here's what I really find interesting. Russell and I actually spoke about this last week on a LinkedIn post or video I put up, which is, I agree with your findings.
Hmm. I think most companies have sort of, they're either dipping their toes in the water or talking about dipping their toes in the water, but here they are, and some of the biggest companies, you know, doing announcing layoffs and saying, oh, well, it's due to we're gonna, we're gonna replace some of these workers with ai. We may very well replace some of these workers with ai, but not today.
I, I don't think today, I'd be interested to see if your survey found that We, we, you know, that wasn't an area we, we, we focused on massively. But, but, but let me give you a couple of things that might help sort of talk about that to get into a little bit more detail. So I, one thing that was, I, I thought was really interesting was you, you've heard a lot about, um, particularly geopolitical tension where obviously that's very, you know, that that's a big topic for, for right now.
And obviously there's been a lot of conversations about, you know, um, you know, what, GPUs, for example, accelerated computes gonna be a made available in which countries, et cetera, et cetera. So one thing that we, we found that was pretty interesting was that, um, you know, in terms of how people, how different countries rate themselves, again, looking at the two extremes, so in a, you know, asking who is going to win the AI race? So we asked that question, who is gonna win the AI race?
We asked these IT execs, we asked these CEOs, and two thirds of them in the US thought they were gonna win, right? Right. But, but only about 40% in China thought they were gonna win win, right?
And it, that, that, that was, that we found that really interesting because we, we've actually seen is a huge drive in places like China towards very fast scaling of their, uh, operational capability. Actually, that's one of the questions we asked. We asked, um, you know, what is the, what is the most important capability as you go and build that AI in China?
35% of their leaders ranked scalability as the top capability that they're going after versus less than a quarter globally. So, so what that tells us is that China has a focus on rapid deployment and early impact, whereas I think there's much more development going on in other places. So that's places like the us, the UK and India, essentially the, they're taking a, a sort of a more integration approach as in how do we integrate this with existing systems rather than trying to get, making some big bangs, uh, really early.
And by the way, you know, that comment you made about whether it's gonna replace AI is gonna replace workers. You know, what we've seen, and this wasn't necessarily directly in this report, but I think it was, was supported by this report, was that, um, very few of these, uh, productivity enhancements that we hear in ai, the ones that you would've heard more in the predictive and generative AI wave, actually delivered much in terms of real world savings for customers. It definitely gave people more time in the day.
It didn't necessarily mean they needed less workers. But that is changing. That is changing.
We're seeing AgTech in particular being a huge driver of fundamental shifts in the, uh, the, the sort of ratio between capital and so sort of physical capital and human capital, right? We, you know, so, so, so we are absolutely seeing that with AG agentic, but AG agentic has a whole other range of challenges around it, and we're just really getting started on that. Excellent.
Let's dive a little deeper. Tell me some other findings in the survey that you found very interesting. Yeah.
Um, so one of the other things that we, we found pretty interestingly interesting was around, uh, cloud. Um, so, so we, we, you know, NetApp has long since believed that AI is probably the most hybrid workload that we've ever seen as, as a, as an industry. And it, there's a lot of reasoning for that.
Uh, you know, it, it, the, the, the primary reason is that the amount of investment is going on in the hyperscalers. Their ability to, to, to provide quickly scalable, but also burstable workloads, but also the very rich, not just ias, but PAs and SaaS services that the hyperscalers have built. It means that, uh, cloud, um, it, the ability to seamlessly leverage cloud services as part of an overall AI workflow is becoming a, a, a significant, uh, uh, opportunity, uh, for customers.
Now, um, what's interesting of course is that yes, we have the, the, the big hyperscalers, but they're American, right? To be clear, they're American, right? And I just mentioned, I, we, we, we, this, this, uh, survey covered four countries, right?
Covered China, it covered India, it covered the uk, us now UK and us, probably UK doesn't have quite as much concern about using US cloud services. But if you go to other places, obviously with some of the recent, uh, trade disputes that we've seen, we, we have seen a lot of nationalism come into this, you know, can I run this locally? And suddenly the overall basically con considered over alliance on, on US based cloud services is starting to become a problem.
So we're starting to see nations, uh, uh, build their own cloud capabilities, not just rely Yeah, absolutely. I, it see sovereignty is, is the buzzword over the day, and whether it's check or Not, saw Alan, you saw deep, I mean, that was the Yeah. You know, that was the shot across the bow if there were, if ever was one, right?
Sure. Was. It was a Sputnik kind of moment, but Yes.
Yeah. You know, but it, this is not, I would posit that this is not just limited to, let's say, China, you know, in the obvious economic tensions with the us given today's Balkanized world, and given the administration and and outlook here in the us there are many, many countries looking to have sovereignty over their data, over their IT resources, over their infrastructure. And I think this is a huge, a huge driver of, is going to be a huge driver of, of budgets in, in the coming cycles.
And I, I think the recent Iran, US Israel triangle of, of violent of war has, is only gonna drive that accelerate A hundred, a hundred percent. And I think that obviously, you know, what, what the, what the survey was showing us was that it was a combination of different factors. One of it is one of those factors is absolutely not wanting to be over reliant on, on US services.
And some of that's because will those services be, you know, will they be a lever that's used in trade negotiations? Um, there, there's issues around, you know, just, just kind of, uh, where the money's flowing. But actually one of the biggest challenges isn't any of that.
It's actually to do with the fact that you mentioned LLMs and you mentioned data and, and just predominantly English. I mean, you know, all the big lms, all the lot of the investment was in, it was in English. And of course, you're going to countries where English isn't necessarily the first language or the only language, and suddenly you're seeing, uh, significant investments now from a range of different countries in, in, including China in particular, but also India, which has a lot of regional, uh, um, obviously regional languages, uh, to, to build out LMS that can communicate in, in, in, in, in native tongues.
So, so that's another reason I think we think that's actually driving, uh, um, this investment. But, you know, there, there is one thing I thought was, was super interesting. Um, the perception of, of most of these organizations is that they're ready.
So, so this, I found this absolutely fascinating, right? So 88% of the organizations that we surveyed felt that they were mostly or fully ready for ai, and we were just like, we were like blown away by that number, right? Because, you know, I, I, you know, that that is so far from what we are seeing in the real world.
I'll, there's another number that's interesting about this. The number of AI projects. We asked how many projects were failing, right?
How many projects were failing. And the, uh, what we found is that 79% of these organizations felt that they were lacking the risk mitigation and ethical practices required. So About the same number who said they were ready.
Because I, and I think, I think again, it's back to, you know, do I have physical boxes that can run AI workloads versus do I have the environment necessary to actually run that, that those workloads, those work, and it, you know, the, it's all about, you know, having, ensuring that you have clean, secure, and auditable data pipelines that can feed those AI systems with trustworthy, traceable, bias aware data. Because if you don't have that, I mean, to be clear that at a society level, the trust level for AI is, is, is not clear, right? That the society is still struggling with how much they're willing to trust ai.
And the reality is, is you can only, you can only fault AI for doing something wrong when the data is corrupt and it makes a mistake. But most of the time that's not the issue. The issue is it's being fed bomb data and you get fed bad data, and that's all, you know, Bad in it's bad out Then it's bad out.
So, so there is a, you know, I think as a, not just as, uh, as organizations, as, as NetApp obviously has a huge role to play in creating a data environment that does all those things really, really well, that's a huge focus for the company. We can do that on a hiring basis. So, so, so, so we love that, right?
So whether it's data integrity or data lineage, trustworthy infrastructure, data infrastructure is a huge part of what we do and what we've been building. Uh, honestly, for, for the last, you know, uh, certainly since the inception of AI has been a huge, uh, focus for us. But, um, I, I think that, um, in general, uh, society, um, you know, we're, we're right.
We're walking this tightrope, and we, there's two ways this can go down. You know, we, we can really focus on making AI trustworthy or we can focus on speed. I, I don't know that it's easy to do both.
I think NetApp is probably your best bet to do both if you, if you wanted to go do both. But I think what we're seeing is, is that China's trying to get ahead. Some of the other countries are taking a much more reserved position.
Regulation has a lot to do with this, right? So we're seeing the AI Act in the European Union come out, you know, uh, some folks that seem to think it's a data privacy thing. It really isn't.
It's really trying to explain what is acceptable in terms of the use and reliance on AI in, in society. I think it's a good thing. I, I, most folks tend to think of regulation as holding stuff back.
Um, I actually have a completely o opposite view of, of this, right? When I go out and talk to customers, I'll tell you this, Alan, when I go out and talk to customers, I hear one thing consistently, which is that lack of certainty about what is okay, what is acceptable, what will society bear is actually holding organizations back. If society states through, through regulation, Hey, this is acceptable, and you've got clear lines, you know what, that gives me carte blanche.
I, I now understand what the context is. I don't have to second guess myself. As long as I know what those, the, those, uh, requirements are, I can stay within them.
So, so we're seeing a lot of that sort of, uh, I think that's a, a natural sort of next level of maturity that we're starting to see in the market. I love it. Hey, Russell, we're, we're probably over time, but, um, for people who wanna maybe go have a look at the survey, is there a place on the NetApp website they can go get the, the, uh, survey results or report?
Yeah, I'm sure we'll add it as a, as a, as a link to the, uh, to, to, to this video? Yes. com where people can go, go read the, uh, report site, which I highly recommend.
Um, it, it has got full of really interesting, really interesting data, but at the end of the day, if I was just to kind of, kind of wrap it up from my perspective, right? So there, there are roadblocks to making AI impact meaningful, right? And, and most of it's relating to data, right?
And, you know, if you can build a, a, a, a, an intelligent data infrastructure that manages that data, that also secures it, um, ensures it is trustworthy, makes it seamless on-prem and in the cloud, then you are in a really fantastic position to take advantage of whatever's coming at you. Because that's the last thing I'll tell you, Alan, anyone that tells you they know what's gonna happen in AI in two years, no, no one knows. So all you can do at this point is take advantage of what's in front of you and build an environment that is adaptable and agile so that when things come at you, you are quick and able to take advantage of them before your competition is.
So that, that would be my, my key recommendation to your, to your listeners, your viewers. Um, uh, but yeah, go, go read the report. I think it's, it's really an interesting report and, uh, it's definitely worth your time.
Absolutely. Look, if you're like me and you don't like to go through the notes on the videos, you could probably just google NetApp's AI space race survey and get it from there as well. I, I, I, most people just start on Google.
Fair enough. Yep. Russell, thank you so much for coming here on Text Junk tv.
Come back anytime and keep us posted. All right, Thanks Alan. Appreciate it All.
Good luck. Russell Fishman, senior director, global head of Solutions product management at NetApp here on Tech Drunk tv. We'll take a break.
We'll be back in a moment. Hey, everybody, we're back at the Open Source summit in Denver, and we're here with Mol Kanick, who's director of the Open Search Foundation, and we have all kinds of new and interesting things to talk about. Welcome to the show.
Hey, thanks Mike. Thanks. Great to be here.
Yes, a lot of really exciting things to talk about. 1, and, uh, it's a continuing evolution of, um, you know, the powerful search and log analytics capabilities that open search has. And we have some exciting announcements, um, on, in both search and log analytics, but also in, uh, the agent space.
And so really exciting, uh, like summit and a day. Well, so let's go through that a little bit, because when people hear open search, they're like, okay, search engine, I get it, full stop. But this is really a family of things that you guys have put together, and they have different use cases.
So kind of walk us through a little bit of what you're seeing as some of the use cases, including the AI ones, but there's also observability and all kinds of stuff going on here. So it's almost, we're seeing it almost everywhere. Yeah.
Yeah. Great, great point. You know, yes, open search, great search engine, as you said, and, you know, used in wide variety of use cases, but also really powerful observability use case, because if you think about it, when you're so trying to solve an observability problem at the core of it, you need search.
And if you have a powerful search and analytics capability, you can get to your root cause very quickly, which is what you need to do for observability. And so really good observability platform, also an emerging security analytics kind of use case, but largely search and observability platform. And then on the AI side, well, we have vector databases, but we also need search to kind of make those applications work as well.
What's the relationship? Great, great question. You know, like open search, really powerful at search, but also, uh, we have a lot of really powerful vector database capabilities.
And you think those two are independent things, but in some ways, um, like the search, think of it as like a keyword search, uh, right where you're typing and you like, get back research results that are based on the keywords. What vector, uh, uh, search or vector database lets you do is do, uh, use the more semantic understanding of the words to be able to find, um, the results that are more seman related. So the combination of like the keyword search and the semantic search gives you more powerful search.
Like it helps you answer the questions that you're asking more precisely and, uh, and more, more quickly. So the paradox in my mind is that we're using open search to create AI agents and apps, which in turn will be the things that we use to drive observability, invoking the rest of the capabilities of the platform. So is there some sort of like symmetrical loop occurring here?
That's great observation. I, a lot of people miss that, but I, you're right. Like open search is a, you know, great search and a knowledge base if you think about it, right?
And for getting your observability and understanding the root cause correctly, what you need is a good knowledge base. I mean, we as DevOps engineers, you know, uh, have that knowledge base within us, but it's also there in the runbooks it's there in, you know, different, uh, wikis and different places, right? And so all of that knowledge base exists in something like an open search.
Then you can really make your observability debug in even faster because you can now under like, uh, open search and the agents can understand the root cause much w because the data is there. Yeah. So among the new features that are being rolled out, you know, are there any of your favorites?
I know that's asking you to pick your favorite child, but are there things that you know are a little more important than others? Well, I think there's several very, uh, very, like, yeah, so it's hard to say which one is favorite, but I'll walk through couple. Um, so we, uh, open search, as I was saying, you know, leading vector database, one of the challenges we heard from users is, uh, in like, indexing can take time.
And so we built this GPU based acceleration on, uh, on the indexing side where you can, you know, index four or five, sometimes even more, like four or five times faster, even sometimes more. Uh, and so you can get all of that data into open search much more quickly to be able to start serving, you know, requests. And so that's one really nice innovation, which has really good application for a lot of, uh, users in the community.
Uh, we are also building, um, ability to have, uh, like load graphs partially, and that gives you, again, ability to, uh, respond to results quickly. So it, it's making gene AI more real time, if you think about it, like at a high level, and that that is really powerful. The other, uh, set of capabilities is more on the analytic side and the observability side.
Um, we've introduced, you know, more richer analytical capabilities and analytical functions. You know, your documents that you index into open search, like these are logs, right? Uh, could have any kind of structure and JSON format.
And so we've introduced nested, you know, js ON support and really a lot of rich analytical capabilities, um, into open search. Um, as we kind of move along here, it seems like the Linux Foundation itself has multiple AI initiatives. There's the PyTorch folks we just talked about, the A two A folks.
Will there be cross pollination between all these groups? And how does that all come together in your mind? I mean, in general, uh, in the, I, I think in the open source community, there's a lot of cross pollination that happens, uh, because I think innovations happening in each of the projects, um, benefit, like I think, uh, other projects like you can kind, uh, tag team in some ways, right?
I mean, um, being able to, uh, leverage, like in, for example, I'll pick, uh, open search right in, within open search. We are, uh, leveraging, uh, Apache Cal site as a, uh, uh, planning layer for open search. And then we are leveraging other projects to be able to then, uh, power some of the capabilities in open source.
So it just, that synergy exists between different open source open source projects within the Lin Foundation. We are also working on several, um, like, you know, there are other, uh, uh, like, you know, gen AI and ai, uh, capabilities and, uh, and as, as a community, we are looking at, you know, all the innovation that's already happened and leveraging that to benefit the users and community of open stage. One of the things I think of observed is that we used to kind of have developers over here, and then the data managed over here, and it was kinda separate in the age of ai, that all seems to be converging.
And I see more and more developers, you know, discovering data management fundamentals. So, um, do we need to kind of focus a little bit on skills and training there and, and, and what are you guys doing about all that? I think skills and training, definitely.
I think, uh, I think there's that, like, as I think, uh, a critical part of any of the gene applications is the data, as, as your observation is. And I think, uh, understanding, you know, quality of the data and, you know, the capabilities of the tools that access the data is really important. I think the other important thing is also governance of the data and like, you know, being able to make sure that you can, uh, track where the data is coming from and like permissioning and all of that plays a big role in this world because as these tools, you know, um, become more powerful and can access different things, you wanna make sure that the go, like there's a good, like all of these projects such as within search, uh, are focusing on the data governance part of it.
Like, Alright, so you just got the new release out the door and I'm sure everybody's asking you the same question, what's next and when's it coming? Lot of really exciting things. 1 release.
0 in April, and just within a short span of like two or three months, we have some amazing new things. Our pace of innovation is growing. I mean, if you like, um, just we, we transitioned to Lenox Foundation, uh, in September and since then we've seen about 46% jump in our active contributors.
And so that's driving all of this innovation. And so we'll see a lot more features come out. Um, and continuing to innovate in this, you know, in the space of, uh, search vector databases, um, agent tech now with all the MCP support that we have, and then also in the observability space where, um, a lot of the rich analytical capabilities, uh, making it more accessible to all these agent tools.
All right, folks, you heard it here. If you wanna stay close to what's happening in ai, keep your eye on the Open Search Foundation. 'cause I think they're closer to it than just about anybody else.
Hey, thanks for coming by. Thanks Mike. Great to talk to you.
All right, and we'll be back in a minute. Hey guys, thanks to throw, we're here with Aaron Costello, who's head of SaaS threat research for App Omni. And we're talking about, well, there's been a spate of, uh, issues that have arisen, shall we say.
We don't know if there's been some actual breaches yet, but maybe there has, but Aaron probably knows better than we do. But we're gonna talk about is this whole area being overlooked from a security perspective. Aaron, welcome to show.
Thank you so much for having me. It's great to be on. So just recently we saw that Salesforce fixed a lot of issues.
Some of them were fairly high, severe severity, at least in terms of vulnerabilities. But, um, I don't hear a lot about this issue. And so my question to you is, you know, is this just flying under the radar and it's a bigger threat than we realize?
Yeah, absolutely. So when we look at my research and it's tackling the suite of Salesforce industry cloud products, tens of of thousands of organizations are using these products, right? We look at Arrow internal telemetry.
We protect 25% of the Fortune 100 over at App Omni. And nearly one third of our customers are using one of the Salesforce industry clouds. So the potential blast radius for this research is, is quite big.
I don't always like to beat up on a particular vendor because I sometimes think of error for the grace of God goes as everybody else. But is this problem endemic to all the SaaS platforms? So it's endemic to the Salesforce industry Cloud Suite, a product specifically.
So Salesforce industry clouds, I encompass, I believe 11 individual. Um, we say verticals, uh, or products. So industry clouds encompass a platform for the public sector, uh, financial solutions, uh, communications and telecommunications and insurance, and also health.
So there are 11 individual products within that suite, and each one of those products is affected. Hmm. Um, who's in charge of this?
'cause the SaaS apps are usually bought by somebody in a business unit lead or maybe at the C level somewhere. But, um, it's not clear to me that cybersecurity people are always involved and there's probably not a lot of processes in place for checking how things are configured. Yeah, absolutely.
And that's something that we see that's quite endemic across, uh, the majority, the vast majority of, of SaaS customers. It's really whose responsibility is this to configure security and, and use correctly. And that can vary from organization to organization.
So in some cases it may be the responsibility of the, uh, platform administrator. So these would be your kind of SaaS SME experts, uh, of Salesforce or whoever. Um, internally, it could also be the responsibility of the individual security teams.
These could be your standard, um, application security teams, for example. But often they can vary from organization to organization. And that's part of the problem tackling these issues is finding who is really responsible within your organization for securing these things.
Is there some way to holistically secure them? Because counting on mere mortals who are administrators of the Salesforce platform or whatever else it is to do the right thing, uh, is almost a zero sum game, right? The odds of winning that are low.
So is there some way to kind of put controls in place that don't make me dependent upon somebody who has no cybersecurity training to do the right thing? Yeah, absolutely. So when we look at, uh, my research as a whole, um, there was, or in 20 findings, right?
And 15 of those security risks are the responsibility of the customer to secure. And these are all things that can be secured from within the platform. So these are items such as enabling certain security guardrails, like settings and configuration settings that may enforce a access control, for example, across the entire organization to, to lock it down.
Or it could be, uh, to do with custom and development. So on these platforms, if things are being built in Salesforce industry cloud, um, ensuring that the, those components are built, um, adhering to development best practices is, is something that organizations need to, uh, need to be doing. Alright.
Um, we talk a lot about shared responsibility in the age of the cloud, and I think everybody nods their heads, but it's not clear to me everybody knows what exactly what's entailed or what's required there because well, we seem to get it wrong a lot. Yeah, absolutely. That is, um, something that we still get, uh, queries about to this day from, from customers especially with respect to, to this research.
Um, so generally speaking, once a organization purchases a product or software, a south software switches Salesforce, the software is inherently secure out of the box. So all of the configuration settings and the properties and the access controls are generally speaking completely fine and you are at no risk. But as organizations start to build on these platforms and add their own customizations, those customizations and those changes that they're making to that software or to the configuration of that software is their own responsibility.
So typically what we like to say is if the, a security issued is a problem or a risk in the software itself, and so it affects all Salesforce customers out of the box on brand new deployed instances, that is the responsibility of the vendor of Salesforce to fix. Whereas if the issue has arisen because of a change that was made by your organization to a configuration within the platform or through development on the platform, then that is the responsibility of your organization, the customer, to fix Time is usually of the essence in these matters. And what you just described sounded like it takes a long time to figure out who's responsible for what, whenever there's an incident or an issue.
So is there some way to narrow that gap? Well, really it's just establishing, and this is really the dream, it's establishing the security process from the very beginning. And as I'd mentioned earlier on this, is this can differ from organization to organization.
So for example, one organization, it may be a, a scenario in which the platform owner, the Salesforce expert, maybe they'll want to take it on themselves to perform these audits, uh, either manually or through an automated tool like app Omni, um, to ensure that their access controls and configurations are secure because these individuals have that Salesforce knowledge. And so they're familiar with the security concepts of the platforms. However, in other organizations, the security teams are the ones who, um, are responsible for resolving these issues and hunting for these issues on the platforms.
And that's another viable solution, um, for responsibility because these are security minded individuals. They kind of know the general concepts and risks and what to look for in the platforms. The issue with that may be that they do not have the platform specific knowledge to tackle the problems effectively.
So all in all, I would recommend that the security teams and the platform owners, these system administrators of the SA platforms work together to tackle these issues. Do you think that maybe someday soon we'll have an AI agent that will help us sort all this out? Because it seems like a lot of this is just simply having enough bandwidth to consume all the configuration data and then validate it.
Yeah, absolutely. Absolutely. So we're already seeing a lot of, uh, LMS AI agents analyzing code for examples.
Uh, for example, and that's not different when looking at security configurations also. So all of this that this data is stored on the platform, so if we're feeding an ai, an AI agent, a, an image of what secure looks like and what good looks like, then that agent can be responsible for ensuring that the confi, the security configurations stay secure because it has that visibility into the platform. So potentially we, we don't know, something such as agent force on Salesforce may be leveraged, um, in the future for ensuring the secure, the maintenance of, of security controls on the platform.
What's that one thing you see customers doing over and over again that just makes you shake your head a little bit and go, folks, we need to be a little bit better than that. Taking the fastest, quickest route to solve a problem is 99% of the time the reason that these security issues arise because it's the easiest solution. So if they're building or writing some code to pull some data, it's very quick and easy to just say, Hey, pull this data and give it to the person.
And they're not putting in security best practices when developing that code, because then you need to start thinking about, okay, well are the end users using this code? Do they have the permissions? Do I need to assign the permissions?
Do I need to analyze the permissions? And while that's the best practice, naturally that takes longer. So it's really a matter of trying to get a solution built in the quickest timeframe possible is leading to these kind of then an endemic of, of security issues on the SaaS platforms.
Hmm. Do you think that the compliance regulations are stringent enough or are they still a little too loose? And so everybody will say, yeah, I complied, but they're not really secure?
That's a great question. Generally speaking, what I've noticed is it's very difficult to apply a lot of these compliance frameworks like NIST to SaaS products specifically because they were not built specifically for SaaS products. And so there isn't really a one size fits all solution to ensuring that your Salesforce instance or your ServiceNow instance is compliant with SOC two or, or NCSF or any of these, these frameworks.
So personally I would really like to see, um, something like scuba. So SCUBA was recently mandated by, um, CSA and it's effectively a framework, a government framework that government bodies in the US need to apply to their Microsoft instances. And it describes a whole manner of security controls that need to be in place.
And so I would really like to see that expanded on not just for the public sector, but also for the private sector. Yeah, I don't hear much about this, but are people and organizations being fine because of SaaS security issues or are the regulators just not even on this? 'cause there's so many other things they gotta worry about?
That's a great question. I would imagine it's, it's the latter more than anything else. Um, typically SaaS is a bit of a blind spot, which is strange considering your organization's most sensitive data is typically stored in the cloud on these SaaS platforms.
But I think with the relatively recent upsurge in attacks over the past, uh, couple of years, we look at um, like midnight blizzard and more threat actors targeting SaaS platform specifically, I think the importance of of SaaS security and regulation of, of SaaS security is something that we'll see, um, implemented, uh, a bit more stringently over the next couple of years. Alright. So ultimately, what's your best advice to folks who are in charge of this whole area?
'cause I don't think anybody deliberately gets up in the morning and says, let's not bother with securing these applications, but I got a feeling they're a little overwhelmed and just don't know where to get started. That's the the golden question really. Um, I love to provide an answer that that could apply to all organizations of, of all shapes and, and, and sizes.
But really starting from the ground up when it comes to even just procuring the SaaS applications is when I believe organizations need to do the, the most amount of due diligence. So when procuring a SaaS application, ensure that while it must fit your business use cases, it also is compliant with your own security policies internally. So does the SaaS application, um, allow for various forms of MFA, are there adequate access control, um, solutions built in the platform?
Are we able to ingest activity logging? Is that made available by the SaaS platform? And can we have visibility into potential breaches and attacks?
So that's really step one in my opinion, ensuring that, uh, it's complied from a security perspective to what your organization typically needs. And then from that point onwards, delegating the responsibility when it comes to security and maintaining the security of the platform. So maintaining what I was speaking about earlier on those configurations, um, delegating that to either the platform owner, whether it's the AppSec teams or if they're kind of working together more holistically, um, is another viable solution.
So delegating that responsibility in my opinion, is step two, secure by default and building everything with security in mind. Step three. So apply the same stringent level of auditing of scrutiny from a security, security perspective to everything that you build on these SaaS platforms.
Imagine it's a custom solution that your organization is built because typically if an building their own website or their own CRM, it goes through A-C-I-C-D DevSecOps process and is heavily scrutinized by the internal security teams. And I would love to see the same approach apply to the SaaS platforms. And then in addition to all of this, I won't sugarcoat it.
If you are a large enterprise organization, maintaining all of these security controls and all of these best practices manually is really not gonna be that feasible. If you are a very large organization that's heavily using a SaaS product like Salesforce. If you've got thousands of users logging in every single day, people building things consistently, manually, auditing permissions, access controls and configurations and ensuring that they stay up to date is just not very, very feasible.
Not all all organizations will have the budget or the headcount to build an automated solution to maintain those security controls. So look into getting an SSPM tool and, and I am biased naturally like App Omni that will routinely and regularly assess those security controls and also provide you insight into the activity that's happening on, on your SaaS platform so that you can be both preventative from risks. So identify risks and lock them down before attackers take advantage of them.
And the worst case scenario, if there is a breach in progress, it can be retroactive and use an SSPM like app Omni to identify these attacks as they're happening and show them down. All right, folks, you heard in here, Hey, there's a lot of SaaS platforms now being used by everybody and it's not gone unnoticed by the bad guys who have become a lot more adept at just stealing credentials and logging in rather than actually breaking in. And well, the best place to log in is usually a SaaS application.
Hey Aaron, thanks for being on the show. Thank you so much, Mike. I appreciate it.
All right, and back to you guys in the studio. The world is filled with promises of the next best thing just around the corner. And wireless is no different.
Wifi seven promises to be the fastest thing that you've ever seen, but unfortunately, one of the pieces that is promising that isn't ready just yet. In this episode, we're gonna talk about MLO is a lie. Welcome to the Tech Field Day podcast, where each episode we bring together a group of experts from across the enterprise IT space to debate a number of topics and theories in enterprise IT Tech Field Day is a part of the RUM group, and each episode is usually recorded in conjunction with one of our tech Field day events.
We're here at Mobility Field Day this week. But before we introduce the topic or premise for this episode, I'd like to take a moment for our guests to introduce themselves. Alan, I'm Alan Crow.
I'm a principal engineer at nexo. Hey to Mackenzie from the uk and I've been a wireless nerd for 25 years now. Chris Reed, principal consultant at Verizon focusing on wifi.
And I'm Tom Hollingsworth, practice lead for Mobility at Tech Field Day. Let's jump into the premise for this episode. No doubt you've seen lots of coverage of something called wifi seven.
You don't know what it is, but you know that you need it because the number is bigger. That means that it must be better. But the primary feature that everyone is looking for in wifi seven is something called multilink operation or MLO.
But unfortunately I have news for you. MLO is a lie. Okay, let's jump into that because I can hear people typing about how I'm wrong, and Lord knows I love to be wrong on the internet.
But gentlemen, what is Multilink operation and why is it something that so many people are clamoring for in this latest revision of wifi? Yeah, So get off Chris. Setting the stage first, uh, MLO is the ability for a client to send or receive, um, frames to two different radios, either the same frame or different frames staggered, um, or to two different aps at the same time.
Um, so fundamentally that's, uh, that's what it is. And the benefit is supposedly both speed increases as well as reliability increases of those, those same transmissions. Um, it's been the, the primary seller of the wifi seven.
It's been the, the, the hotness for it. Um, but I, I don't know that at least to start with it's going to work at all. We had enough problems with O-F-D-M-A, even now, getting it to work in the real world, um, and having a real benefit from it has been a problem.
And that was a technology that was already in use. It was already on radios. They already understood the behavior for it.
We just adopted it into wifi and it still had that problem. Now you're telling me that we're expecting this to work across multiple aps at the same time. Uh, I, I have real concerns about that happening in the real world, at least in the, the short to midterm.
We have enough problems roaming between two aps, let alone talking to two aps at the same time. Yeah, I I think that's right. And I think that the other thing to be said about Multilink operation is it's not just all, all those benefits, better reliability, increased speed, that you don't actually get all of those, there's driven flavors of multilink operation and depending on which flavor you implement, depending on what benefit you get, and I don't think that's, people already talk about that as much right.
With it as well. And I guess one question I've got is which flavor is actually going to bring a, a tangible benefit that we'll actually see in, in enterprise class networks? Well, I wanna back up a little bit here because one of the things that I think we might want to explain also to our audience out there, why do we need Multilink operation?
Because I can think of a time back in my formative years when I was studying how to create Ether channels and LACP trunks between switches, and at no point was this ever sold to me as, you know, double the bandwidth. In fact, usually the way that it was described was it was redundancy, right? So if one of my cables goes out that it's still one link and all the traffic's going back and forth between one.
In fact, anybody who ever told me, oh, well if you lag two Ether channels together, you're gonna get two gigabits per second. They obviously didn't know what they were doing because there was a preference for it to pick one channel. Why do we need MLO?
Is it going to increase speeds for wifi? Is it gonna increase reliability for wifi? Who, who do we wanna listen to though?
Well, I, we wanna listen to the marketing people who tell us it automatically makes it faster. Is it the practitioners that talk to us more about, you know, it is gonna add reliability, it's gonna add survivability and some of the rest of it. I think that's some of what, at least from my perspective we run into these days is, especially with wifi being driven very heavily on the consumer side, everything's all about faster, faster, faster.
Mm-hmm. You said it, you know, in the intro, it's, it's, why do I need wifi seven because the number's bigger. Yeah.
Um, and I think that's really what we, a lot of cases, especially in the s and b market, we suffer from, from a technology standpoint, what are we looking to get out of MLO is a great question. Yeah. And to Peter's point earlier, we have to talk about the separate flavors and the benefit that comes with that flavor.
So, so let's talk about the benefit of reliability. So in, in that scenario, it'd be sending the same frame to two different radios. That way if it does, if one doesn't get there, the other one is going to, you're getting reliability there, but at the expense of you're, you're using double the bandwidth, um, because you're using the other radios bandwidth as well, um, at the same time.
And, And that for normal, and that's just one flavor, isn't it? Right. Of reliability.
This is a problem with amlo. There's so many different flavors. So sending the same frame to two radios requires you to have a multi radio scenario.
Yeah. Whereas I think most clients are just single radio. So they're gonna be doing what they call single radio, um, where, where they're gonna be able to establish a connection with say, a five gigha and a six gigha radio of the same ap.
Um, but they'll only have ability to use one of those connections at any one time. So does that increase the reliability? Well, potentially, yeah.
So one of the problems with wifi is, um, sometimes con congestion channels getting congested. You've, if you've ever been on a zoom call on a con congested channel, you end up sometimes getting jitter delay. 4 gigaherz actually, that's why we see it a lot, right?
If you've got the ability to go per packet, actually I want to choose which link is the least congested I'm going to send on that link. And if something that link becomes congested or interference, which was what one of the presenters talk about it, um, I can then use the link. I think that that does potentially give us a benefit for real time applications like video and streaming.
Um, but so, so I see that as potentially a real benefit all the them MLO benefits I'm not sure about, but It's a lot of, it's a lot of complication for a slightly niche use case because outside of realtime applications, like do, do kinda standard TCP transmissions, does that need that? Or is it only UT UDP realtime protocols that we, we care about using that for? But, But, but they're becoming more important now then like, and, and now we use, so in wifi design in rate, do you want to do vo We, we never ask that question anymore, right?
Because TE teams zooms calls are a daily norm in, in the enterprise office environment. So everyone is doing realtime voice and video now on wifi. So I think they, if we can increase reliability, but I think that can be a benefit.
I'm not, but in, in terms of all benefits of MLO, I'm, I'm not convinced. 4, right? 4 and five, maybe some five and six.
4, yeah, we'll do it, but how much do we rely on it to be available and ready to take video calls? 4 network in a state that's ready for a video call, it's, it's not gonna get better. 4 gigha away from your carport network.
I disable it, right? Yeah. 4 and five gig, so you can do mlo, drift SSIDs, right?
So I do think the real benefit will come with five and six. Yeah. 4.
Yeah. But then we need a wider deployment, not six gig radios to do Up, which brings into all the fun that we need for to deploy this, right? It's not just MLO that we've gotta deploy now, right?
As much as, as much as we would love to say everybody's doing WPA A three, how many people are doing WPA A three? And and what does that bring into the folks that aren't doing it? And, and where do we go there?
Well, I think that's a good answer because MLLO requires wifi seven. Yeah. And now, and wifi seven requires WPA three.
4 and you want to en enable MLO or WIFI seven at all, sure. 4 or five gig won't able to connect. And I don't think that's been quite fought through, um, as much so, so in the six giga has been That's great.
That's all fret, it's new. Mm-hmm. Uh, yeah.
So if you've got a legacy right now, uh, let's, let's just talk, uh, pretty sure key only. 4 and five gigahertz radio, uh, it's WPA two PSK. Yeah.
You swap that out for your fancy new wifi seven ap, in order to use this, you have to migrate to WPA three. Mm-hmm. Your clients have to support beacon protection.
Uh, your clients al also have to support, uh, management frame protection, which is, is required for WPA three. But, uh, in, in, uh, legacy WPA two, when we enabled it, we did have a lot of client problems. Uh, so there's a, there's a few steps that we have to get to in order to even start to play with this much less use it and see a real world benefit.
And I, I'd say luckily, at least for those people who are running a WPA two with a PS K and that's it, it's easier for them, right? It's, it's the enterprises that are on WPA two with EPE or something like that, where they've gotta make that jump to ETLS for and certificates and the PKI that comes with it and all those things to get to WPA three to then get to, you know, wifi seven to then get to MLO. 4 and five only, but they're wifi seven aps, right?
So now we've got a, okay, I've got a, I can't buy these aps because I want to get to five and six, but I can't because that AP is wifi seven but doesn't have six Yah. Hertz Go for it. Uh, no, but I, I think that's good though that it's good that wifi seven supports all the bands.
4. Yeah. For, for Specific I think it's got to for MLR too.
Yeah. It be a thing. Oh yeah.
Um, I, I think though, here's a question. We, we've talked a bit about reliability and some of the issues do we need, and if you are using it for throughput, so that's when you gonna send split your data over two leads. Sure.
Do we need it? Do we need more throughput? Always.
Well, we always need more throughput, But obviously you, you must have watched the lead the previous episode of this podcast where we talked about the fact that wifi seven is fast enough. Because most of the time that we run into these problems where people are complaining that the wifi is down or that we're not getting enough bandwidth, it has absolutely nothing to do with the underlying infrastructure. And it has more to do with the fact that the application that you're using has bad coding that won't allow it to take advantage of multiple links, or that your AP is only uplinked at one or two gigs at most.
And then your internet connection is a hundred megabits or 400 megabits. So it doesn't matter how fast we can get the wifi to run, unless you're transferring a movie from your laptop to your Plex server. But even then, I'm not totally convinced you need multilink operation, um, multi radio.
I, I'm just not convinced we need it. I, I think there's a few niche cases potentially in the home when you talk about, you know, doing, um, via gaming and you want to have, I don't know, 20, 30 people all in some sort of immersive BI game that's gonna be all connected as the wifi. There, there is those type of scenarios, right?
But in a standard enterprise, um, I'm, I just don't think users require, I I still say today, if you gave me, um, a, a AC access point, I could probably design it for any, uh, a wireless network to meet any enterprises requirements today. Oh yeah. Absolutely.
And I, I mean, we saw the same thing when we started sticking multi gig interfaces and 10 gig interfaces in our aps and people were like, we're not even using a gig interface. Why are we doing those higher level up lengths? Well, it's some of the same questions.
Yes. When we're talking the radio side, six Year hertz low power indoor is kind of the first time that we've really been able to see it, uh, start to push that one gig limit, right? So, so now I think it makes a little more sense to, to have them, uh, in those radios.
But, but remember, remember that's relatively recent as well. Yeah. So we're talking about do we need extra bandwidth?
We just went from 25 channels on five gigahertz. If you're using all of them, we got that extra 1200 megahertz spectrum. So now we can do wider channels.
We're getting more speed from that. Do we now need additional speed on top of it? Sure.
I don't know how many people at their house are running 320 megahertz channels and have the latest gear that allows them to do some form of MLO because they're, um, I don't know, downloading weather data sets. But I remember, uh, even in my house, my, my limit is my internet backhaul connection. Mm-hmm.
It's not my wifi. Yeah. I can be, I can max out my, I get, I think get 200 meg at home, but I max out my 200 meg of 220 over the wifi mm-hmm.
And I was doing that with AC equipment. Yeah. Um, so yeah, I can have Meg, but my wifi go faster.
But, But there's still that push to home that still that push in consumer, that consumer gets seven first. There's bigger, better massive aps with, you know, porcupine antennas coming every which direction, you know, and I can go faster. They're gaming routers, right.
That kind of thing. But yeah, we're still hitting that limit. I mean, we are starting to see higher adoptin of gig to the home.
Um, and so, you know, it, it is coming. But yeah, I think on the enterprise side, No. So could it be that the reason why consumers get it first, other than the fact that they're more than willing to pay for it, is that they're never gonna hit the head limits of what wifi seven can provide.
So for them it feels faster because of the placebo effect without all of the features that are actually necessary to make it go faster. And I think it's that, I think the other piece is a lot of home wifi is terrible. And so if you're gonna take, and, and we have, let's say it's a gig channel on, on our, you know, on the wifi right?
If we, if we say it's a gig theoretical and it's deployed horribly and they're only getting 500 meg, well if I make that, you know, if I make that gig theoretical, two gig theoretical and they're only getting gig, it is faster for them. They're still hitting that limit when they hit the internet. Yeah.
But, uh, home use home in the middle of the field is kinda the only place that those super wide channels make any sense. Yeah. 'cause as soon as you get into a neighborhood or you get into an apartment building, there's already enough contention around that, that you're not getting the advantage of those water.
But they're still deploying 'em. Yeah. Yeah.
Out, out of the, out of the box. Like all over the place. Yeah.
These, uh, these home devices are, are shipping and coming up with 160 megahertz wide channels by default, 320 megahertz wide. I'm expecting 320 megahertz wide channels by default for the wifi seven products as well. Yeah.
But it goes back to one of the things that Sam Clemons wrote years ago about drag racing school buses. Why do we ship them by defaults? Because that way when they get tested, they run as fast as possible, and I don't have to deal with the fallout of what happens when they're broken.
You have to call support and figure out why your neighbor keeps dropping your wifi connection. Mm-hmm. But it comes back to bigger number better.
And, and we've been dealing with that in it for years. Yeah. But when you get into the nuance of what actually makes it better and why this isn't ready for prime time yet, how can we approach the stakeholders in an organization who may be hell bent on deploying this and then hell bent on seeing massive performance increases and being sorely disappointed with their investment when bigger number not so much bigger.
I, I think that's a really key point. And that I see this all the time, and I've done deployments, um, saw it with ax, we deployed some new ax aps and I ended up having to turn off most of the AX features. Um, and it was just because of all the, so, so you think I multi user MIO, um, the, the channel sounding and the overhead associated to it actually made them have less air time.
Mm-hmm. So, and when I turned off all the features, it worked better than the royal system. But they went, but our business unit said we have to turn those features on because that's what we've been sold on.
Mm-hmm. And there was, and I was like, you turn them on, they won't work. You know, you, you're gonna see let's performance.
I I've got it optimized. But they just Yeah. But from, from a business point of view, they said, no, we spend, spend money on aax, we want the Aax feature stand on, and if they don't work, we want the vendors to go and fix it.
Yeah. But before we even get to whether we can use it, uh, whether we can use it, if it all works perfectly, the problem is gonna be on the manufacturer chip sets, uh, and, and drivers as well as the, the client, uh, chip sets of drivers. Are they going to implement it properly?
Is it all gonna work correctly? Are they gonna make the calculations to actually have it happen? Or is that calculation gonna come up with, I'm never gonna try this?
Uh, 'cause even if you enable it in the infrastructure, if the client device isn't participating in it doesn't matter. And that goes back to the other problem of this is a two-pronged problem. I can go to my favorite big box store or my favorite online retailer and order a brand new porcupine AP that supports every cool feature set of wifi seven.
And if my iPad from 2019 still goes as fast as it was going, I'm going to rant and rave and scream and leave bad reviews. Not realizing that the wifi client chip set in my device is nowhere near ready to support this. And how do we communicate that to users that Oh yeah, we can definitely support MLO if you're willing to buy everybody in the building new laptops And even those new laptops.
The right laptops. Yeah. You have to buy the right new laptops.
'cause a lot of them aren't shipping with wifi seven chip setss yet. Are, are we getting back to this problem with 8 0 2 point 11 in when Belkin shipped a pre-standard version that only worked with one card? Because I can tell you what it felt like deploying that to the owner of the company and him wondering why his brand new laptop didn't work with his brand new ap.
And I'm like, well, you gotta use the card that came with it. And then it is not just the card, it's, there's, there's the operating system support it as well. Mm-hmm.
So with Windows, you've got to be Windows 11 and you've gotta have a certain patch mm-hmm. Installed. Yep.
Or you're not doing, or you're not spotting wifi, you're not doing wifi seven features. And maybe that's why Microsoft is forcing all The new updates, right? Yeah.
But then it comes back to, well, why should it only Windows 11 do it? 0. So why can't you make this work on Windows 10?
Yep. And then someone's gonna come out with a software program that you install on Windows 10 to enable this feature, and it's actually malware and mm-hmm. You know, you, you've compromised your machine, but people will do just about anything to be faster.
Yep. So how can we educate the wider populace about the nuances of about YY five seven really is better, but what better actually means? So I, I don't think it's anything that we can really do.
We as practitioners can really, uh, do, this is a, a tale as old as time problem. This is marketing, uh, coming out with statements that are technically true but not accurate. Um, we ran into this with, with, uh, the wider channel IT and, um, and ax and ac and the speeds that they could do.
And that you, you need five gig ports on it. You didn't, uh, you absolutely didn't. We come out with, um, data sheets that say this AP can supports a thousand clients.
Yes. They can associate no one's doing anything if it's at a thousand clients. Um, and it's not just, uh, it's not just wifi, it's across other, um, kind of other technologies as well.
We look at firewall data sheets and the amount of throughput that they say yes, but if you enable any feature whatsoever, it's half of that throughput. This is all just marketing. It's not a technology problem.
Yeah. And I, I love my friends in marketing, but at the same time, we've gotta figure out a way that our data sheets, that our communications, that those kind of things are realistic numbers. Not the theoretical max.
I mean, we could talk about 4K quo, right? I mean, Nobody talks about 14. I know why, because we know it's not realistic.
Um, I think that's the, the, we as practitioners, the only way that we can do this is, is continuing to push that, that talk track of here's the realistic numbers. I've had that conversation with clients. They're like, well, this data sheet says it can support 500, you know, 500 users.
Why do you need five of them in this area? It's like, well, because it can't, you know, realistically we have to bring them back. Uh, I think another thing that's worth maybe mentioning, um, and again, I dunno how we educate people like this, but I, there's some, some that, one of the chips that manufacturer said to me is that they will, when they bring out let's say a wifi seven chip set, that the, the first chip sets out the door are not going to be, there's gonna be problems with it.
It's not gonna work very well. Same with the first, but the next chip set they bring out will be wifi eight. They're not gonna bring out a, Hey, our fixed wifi seven one.
But if you want to get good wifi seven ap, you probably need to buy wifi eight. Right. A AP if you wanted to buy, have a good AC access point.
Actually, the what? The aax aps were probably the best AC ones. And then wifi seven aps are probably really good aps.
So you've got to not think. So that's why when the event there's a selling us on all these new features, you've gotta say, well actually no, this is a really good AX ap. Mm-hmm.
Um, because it's actually the new that they've actually improved a lot of the features of AX in the wifi seven ship sets. Mm-hmm. And then all the new features that have probably, that's not gonna work very well.
Yeah. So how We communicate that, I dunno, It's the first pancake problem, right? No matter what you do, the first pancake is never gonna look or taste right.
And by the time you get to the last pancake, you figured everything out. But except for AC wave one and wave two, we're never gonna see a wifi seven wave two. No, we're not.
We're gonna see wifi eight wave one where we, we really worked our butts off to make this reality. So I guess you're just gonna have to go with it. And, and we've seen that from the vendors saying, yeah, here's all the things that are in even six E, right?
And seven, here's all the things that are in the spec, but we've only implemented these. And yeah, you may see a wave too. And then it's like, no, no, no, because the speed we're Going because they're optional, not required.
Yeah. And, and I think that's the, some of those same communication points that we continuously run into As well. You're, you're, when you're a customer and you're buying this, you're, you're, and you're buying a wifi seven ap, the future proofing that you get from wifi seven isn't wifi seven, it's it's six gigahertz.
Yeah. It's not, it's not even six E it's just, it's the spectrum. And you've got that in that radio.
That's what gets you the benefits now. Yep. Whether It's AI intelligence or autonomous driving, or even a foldable phone, we're being sold on the promise of something great that's just around the corner and it's not quite ready yet.
But if you stick with me for a little bit longer you're gonna see something amazing until you have to go buy something completely different. 'cause it turns out we didn't know how to make that work in the first place. And I feel like that's kind of where we are with MLO.
Everyone keeps hearing about how important it is and how much better it's gonna make things, and they're ignoring all of the other things that have been included that improve what's going on. I mean, we've been fighting this battle for years. 4 other than removing congestion.
So we have to be realistic about what we're actually looking for, and we have to be ready to do the hard work to take advantage of those solutions. And maybe that means upgrading our hardware. Maybe that means leaning on our software vendors to be more supportive of what we're trying to accomplish.
But it also means that maybe we have to be realistic about what we're actually needing instead of just hoping that the speedometer goes all the way to the other side and I can claim that it's faster. That'll just about do it for this episode of the Tech Field Day podcast. Before we leave, I'd like to let our guests let you know whether you can find more of what they like to talk about.
Alan. Yep. Uh, Alan Crow.
You can find me on LinkedIn or hit me up at Nets Stack Plumber because I'm the plumber at a security company. Um, yeah. Peter Mackenzie.
com is my website and at Mackenzie wifi on LinkedIn, Twitter, blue Scott Sky and YouTube. Um, Chris Reed. You can find me on Blue Sky, uh, at the CM Reed, uh, or you can find me on LinkedIn or occasionally in the woods.
com/podcast. You can also subscribe to our newsletter and check out all of the events that we have coming up. com.
We release a new episode of this podcast every week, so make sure that you're subscribed or that you're following along in your favorite podcast application of choice. Just look for the Tech Field Day podcast. While you're out there, leave us a rating and a review so everybody knows the kind of fun that we like to have around here with technology.
We'll be back next week with another great episode. Until then, take care.