Techstrong TV June 30, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
We've got a new trade deal with China. Is it gonna make a difference to you? You're watching Textron Gang.
Hey everyone. Welcome to Techstar gang. Happy Monday.
Hope you had a great weekend. You know, the big news on Friday was, uh, that a, a trade deal. Well, the president of the US announced that he had a trade deal done with China.
Lo and behold, the Chinese actually confirmed that there was some sort of deal done. Um, we're going to get into the particulars of it. I know when I read it, it, I don't know.
I, it was a little less than I was expecting. But Mike, am I just, am I, am I unrealistic in my hopes? What, what's going on?
Well, as is always the case with these things, the devil's in the details and we'll see how the details emerge and hopefully over the coming week. But it would appear that, uh, China's not gonna try to hold its, uh, rare earth metals as hostage anymore. And we in turn are going to, uh, tone down the tariffs on the technology products, which is the part of this thing I think we care about most.
But let's start with Stacy on this one. 'cause it's as much about the psychology of the deals and what it does to everybody's thinking as much as it is the actual, you know, how much am I gonna pay for X, Y, and Z? And I'd love to get your opinion.
It seems to me that for the last six months, it's just been a lot of uncertainty. And everybody who is uncertain winds up, you know, hoping for the best and planning for the worst. And then a lot of bad decisions get made.
So what's your take on, what does this do? Is this just gonna take everybody's temperature down? Yeah, I, I think first off, people have to know what to believe.
And when things like this comp, there's a lot of misinformation, disinformation, is this something that's gonna go through? Will it fall through? And there's just been so much talk going on.
And then once it's determined, okay, yes, this is something I have to move through, there comes the question of what does this look like? Are we managing our supply? What are we, how does this, how are we gonna manage the tariffs?
What programs are we using? What's our, our platform for managing supply chain? And then in amidst that, when you think about cybersecurity, who's thinking about the risk?
And there's, there's research and data that says that, um, cyber terrorism, I mean, this, this is the kind of environment that can be rife for that, because it's a little bit chaotic. And companies are trying to figure out what does this mean for them? Does it mean something?
Is this really what's going to happen? Is this what it looks like? And then what's the process for going through that and going through that securely and responsibly?
And I think that it poses a lot of questions at any time. There's questions, doubt and uncertainty within a business environment, there's always ripples and effect that we all feel from that. So I think when the, when the news came out, I know for me personally, the first question was like, okay, is this real?
Are we really doing this? What's going on? And it was hard, you know, as I'm, as I'm reading the articles and I'm looking at this, I'm like, well, you know, what is my, what is the opinion?
What is the thought? If this is something that's real, what direction are we going in? So in this environment, which it's like getting this sort of news, one would be wondering, how are we gonna do this?
Then add it to this, the climate that we're in and everything. It's like, okay, what does this look like in reality for us? And then how do we do this securely and responsibly?
Lot of questions get asked. And again, with that doubt and uncertainty that can have ripples and effects for everybody, I don't think it matters much. This is, I, I guess I don't really buy rare earth minerals personally, but I did want buy plastic things.
I buy, um, clothing. And I don't think that this is gonna have much of an impact on the data they spend of most Americans. Now that being said, it's great that the rare earth mineral, you know, export agreement is in place.
We need it for our defense. I guess we need it for probably computers and phones, but for the most part, this, this is not gonna impact everybody. You know, Americans going to target in Walmart.
Yeah. So Mike, when, when I first saw the headline that we had a trade deal done with China, silly me, I thought we really had a trade deal done with China. What we really, I mean, and I've read it now over across a half a dozen different sources.
What it seems to me is this is nothing more than the Chinese have been kind enough to allow us to spend our money buying their rare earth minerals and keep us on the heroin. That is our, our our, uh, dependency on China for these minerals. And sometimes you gotta pull the bandaid off and just go co you know, get, go cold Turkey to get the monkey off your back.
We, we need, we need alternative sources for these rare earth minerals. You know, I used to think when I first heard about the rare earth mineral thing that wow, China must be blessed that all these rare earth minerals happen to be in China. Well, no, they're not all in China.
But what China's done is they've gone out and, and financed and, and entered into agreements with countries and, and areas where rare earth minerals are, such as the, uh, the African Republic of Congo and, and so forth and Brazil and, and everywhere else where they basically have the monopoly to get the rare earth minerals where they are, bring them into China for processing, and then export them at a very high profits good business to Dukes like the US who are just going to, you know, stay on the heroin. And what did we give up for, for, you know, getting this right to continue spending a lot of money on rare earth minerals through China? Well, we, we've lowered our tariffs and opened up some techno forbidden technology that we weren't going to give them.
The tariffs are still very high and they're mutually high, right? Going back and forth. Our coming into the US is higher than going into China.
But really, what do we really want in a China, uh, a China trade pack? We want access to Chinese markets. They've got a billion and a half people.
We want to be able to sell our products in there. We want protection for our ip, right? With if things are gonna be made in China, we don't want to see knockoffs of it before it even gets across the ocean in the shipping container, right?
We want protections of our ip. Those are the things that I want in a China deal. This very much to me, sounded, is a, as a preamble deal, but it really doesn't get to the crux of what we need from a China trade policy.
Yeah. I'm trying to look up what chapter and art of the deal that this actually goes with, And it doesn't seem to line up at all. I I, There's a long-term strategic aspect of it and a short-term aspect of it, right?
And I think the, the, what we've given up, you're right Alan, and we've given up a lot for a short term gain. And the real question is, what's the US going to do in the long term? Uh, you know, the US itself is sitting on, um, millions of metric tons, uh, for earth minerals that we are not getting right now for a variety of both economic and political reasons.
And we've just discovered what is believed to be over a billion metric, tons of additional, uh, rare earth deposits throughout the country. And I think we're sort of now where we are with, um, fracking in oil, where if we invest the right amount of, um, know-how and, uh, dollars we can get access to huge deposits that we didn't think exist anymore. That we didn't think exist, right?
And that could change the game. So it's a question of, you know, what do you do between now and opening up the US ability to manufacture, and how long does it take us to do that investment and get the know-how and start producing and become self-sufficient rather than relying on China? Well, you know, I'm a San Bernardino girl.
I was born, raised in San Bernardino, California, and we have the mountain pass mine, and most of what they pull out of that, uh, mountain pass mine goes to China for processing. It's one of the largest deposits of, of, of rare earth minerals in the world. And we send it to China for processing.
So I think Alan's onto something, it shouldn't be a Chinese trade deal. It should be a new way forward for processing these rare earth minerals, because we have them here. We're just not processing, I think China processes probably close to 80 or 90% of the, uh, of the rare earth minerals that we send over there.
So from a, you know, from a perspective, looking at the hood, I, we have the, in San Bernardino in that county, we have pushed for processing for a very long time. And I think Texas actually is start starting to, uh, I think the DOD put some money into, uh, some processing plants into in Texas to address this. You know, thi this is an old, this is a, an old from an old playbook, the British, this is what made Victoria great, right?
They would import raw materials from throughout the empire, from the US and Canada, north America, south America, Asia, Africa, and they would turn those raw materials into finished products, flax, uh, cloth or timber into ships and, you know, uh, steel and, and, and ironed and sold it at huge markups. And that's, that's what made the British Empire what it was. The word You're looking for is mercantilism.
Okay, Mercantil. If I'm a business owner, what I'm, I'm thinking is, I'm thinking, okay, there's this deal, there's the specifics of this deal, but what does this mean for, for China and US relations? And I think, Jack, you're saying like, there's the, the short term and then the long term, and is this the beginning of, of a better trade deal of other opportunities that we can then build upon?
Is this the start of something that we can agree on? Or is this just kind of a, uh, short-term solution to address a short-term issue or placate demands? Well, one, one of the things that Alan said was about intellectual property protection, right?
And if, if China's taking raw materials and, uh, processing and giving back essentially another form of raw materials, there's not a lot of intellectual property there, right? We know how to do that as well. We're just choosing not to do it for a variety, right?
Mostly economic and regulatory reasons. Um, but if we manufacture other goods like chips or clothing or designs, those designs, that intellectual property is where we end up losing big time when the Chinese Communist Party considers doesn't have the concept of intellectual property, everything launched to the state, right? So if we bring those types of manufacturing back to the United States, which is what we're starting to do, we protect that intellectual property.
And that's, I think, very good for the United States in the long run. I also believe we should do the raw material processing here, but I think the intellectual property theft part of it is less risky. And I don't think there was anything in, in this agreement.
In fact, this is only temporary, right? It's only 90 days we have to read, we have to have a discussion again in 90 days in September. So we'll see what happens.
This is the mo here of, of the administration, right? They're, they're long on PR and short on substance. You know, we were supposed to have 90 deals in 90 days.
We've got one with the uk, which is kinda like kissing your sister, um, or your cousin or whatever. Um, you know, so, so they had to have another deal. So they're touting this as a deal.
All right? So in the next election cycle though, the phrase drill, baby drill will be replaced by mine, baby mine, right? Possibly.
They've been saying that in California for a long Time. Well, it's process, it's process baby, process Processing. That's, We've, we've already, we're mining, we're just not processing, right?
That, that's where the issue is. But, but let's also, that they also teased a huge, huge deal on the books, maybe with India. And then if everyone else doesn't line up, we're just going to send letters and put them in buckets.
I, something like that was the quote. And, um, you know, I taco, that's all taco. We'll see how this goes.
I don't know. I'm, I'm waiting to see what the EU does with China. 'cause it'll be interesting to see how all this plays out around the world.
'cause, you know, and there are other trade deals out there that can impact us. And keep in mind, this does not impact most of, most, uh, American consumers. This is not gonna make things cheaper, Not directly, but I think there's that, again, that misinformation, disinformation impact that in that way it affects people, the frustration, the tension.
Like, it's not as tangible as, okay, I'm pulling out my wallet doing it, but like, we're absorbing all of this negative energy. And even if we're looking at this and saying, okay, my business isn't impacted by, by minerals and whatnot, then you're still asking that question of like, what's gonna happen? Where are we gonna go with this?
And that's creating so much anxiety and risk because we don't know what's going on and we don't like sitting in uncertainty. That's not how we're built. Alright, well, we'll see what happens.
You know, this, of course, we recorded this on Friday. The whole thing may blow up by the time you're watching this on Monday. We'll, we'll, we'll see where, where it goes.
Let's take a break here on text John Gang. We're gonna come back and, uh, I'm gonna give a a report about where I, what I did on my summer vacation in New York City this week. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back in. We're talking about platform engineering and specifically, there was an event in New York last week called Platform Con, New York City, I think, and I think there's are also ones in other places around the world, but Alan went to the one in New York City. And, you know, I don't know how many folks showed up there, Alan, but, um, give us a report, give your take on what's going on here because, you know, inquiring minds wanna know what the heck's going on with Platform engineering.
Absolutely. Well, I, I'll mention as, as I think it'll be in the bottom here. Um, we had a, I wrote a nice article on, on my experience at, at Platform Con, uh, New York in person.
Now, Mike, what it is, is this is, I believe the third year for Platform Con. And it went from, I think around 10,000 people to first year, 25,000 the second year to perhaps 40,000 people. Year three.
Now that is, that is a virtual event. So anyone can register and log in, and they have, I forget it was 80 sessions, a hundred sessions. It's been going on all week Monday.
And it wraps up, uh, Friday, Friday morning, it wrapped up. Um, what they did this year for the first time is they, they did some in-person. So sort of a hybrid event, if you will.
Some in-person in London and New York. The one here in New York was at the co convene, uh, convention or conference center. They had about 400 people.
It was sold out. They couldn't fit anymore. 400 people was a great, great turnout.
Um, some of these, well, all of the sessions here were then being live to the entire virtual event audience. The highlights of the sessions that Kelsey Hightower, you know, former Google, everybody I think in the cloud native space, conserv of Kelsey. Um, Kelsey's a real champion for platform engineering.
He, he keyed last year's event, keyed this year's event. And some very interesting takes. You know, if I could sum it up though, he's bullish on platform engineering.
He thinks it solves a lot of what we've, what we've got wrong in our development and deployment, uh, scenarios and security as well. And it was interesting. His daughter actually was in the audience and she asked a question.
I didn't put this in the article, but his daughter was in the audience. She asked a question and it got Kelsey like, I guess right between the, you know, the eyes. It made him shed a tear or two there, it was a moment for him.
So I was happy for Kelsey. Um, they had some other great speakers, though. We had Google and it was interesting.
They had a, a, a gal from Google who's in charge of the, the product of their internal development, a developer platform, their IDP 'cause everyone in Google. And they've been using an IDP for many, many years now that actually runs on Google Cloud, obviously, but Google Cloud runs on Google. So it's a very, you know, incestuous relationship, if you will.
But it was a great, great, uh, insight into how they Google is doing platform engineering and their IDPI also had a chance to speak to folks from ThoughtWorks, uh, Rockel, uh, a bunch of different companies, large and small. But the biggest thing was the enthusiasm of the participants. This is a practitioner event was 400, you know, standing room only people there.
They were, the conversations outside of the sessions were amazing. org community rolled out certification classes now for platform engineering. It kind of reminded me of my DevOps Institute days.
Those were, those courses were, were packed. They had some great hands-on workshops for practitioners that were also packed. Um, lot of great communication.
It, it was, look platform engineering's real, it's arrived. They've got big companies, big and small, kind of, you know, touting it. And, uh, it was a great event.
It was a great event. I would imagine next year you're gonna see more in-person. It'll still be hybrid, but they may go to more cities and they may have bigger, London for one, I understand, was a bigger venue.
It was not sold out as the New York one was close to sold out. And also that same sort of vibe and energy. So I I, I'm bullish on platform engineering.
Uh, hey Alan, what was the, what did the demographics look like? What was the age gr age groups? I felt old.
Um, you know, so again, it, it was a, it was a practitioner event, though. There were plenty of execs there, uh, and managers and so forth. But I, I would say overall, it, it was, you know, twenties and 30 something with a, a sprinkling of 40 fifties and Morse.
Yeah, well, I was at CD Con and I felt young Really well, and that, and that might say something right there, chase. You know what? I know.
That's why I asked the question. And we were, you know, that's, you know, it's, I thought that the group was, you know, represented, uh, DevOps 15 years ago, and they're not changing much. Mm-hmm.
So I think platform engineering is going to kind of sweep them off their feet. And do you notice the types of attendees, whether they were from larger companies or smaller Companies? Both.
That that's what, that's what got me both. 'cause you know, platform engineering is something that you really need when you're scaling, right, when you scale. And so it sense tends to lend itself to larger organizations.
Um, and there were, don't get me wrong, there were a lot of people from household name kind of companies, but there were also, you know, the usual startups and smaller companies that are, you know, staying on cutting edge with technology. If you had to sum it up in like one sentence, what's your key takeaway from platform con? Platform platform engineering is real.
And, and obviously people want to, uh, people wanna know that this is a real problem and they're looking for solutions. And, and these platform engineering seems to be offering them the solutions they're looking for. What, what type of topics were there?
Did they have any topics on, uh, security? Yeah, they had some security. Not enough.
You know, in the article, in my predictions for next year's platform cut, I predicted that they'll have a whole track on, on security because it's too important not to, I guess, you know, one of the things that I'm still wrestling with is, you know, are we seeing jobs posted for platform engineers or, or is this something that software engineers or a subset of them do as a practice, per se? And it's a best practice, but it's not my job title. No, no.
There, so a platform engineer is an in-demand job title. And we've done stories on this, Mike, that on hold, they actually make more money than DevOps engineers. But, um, here, here's an interesting thing.
You know, I, I spoke to this woman, Camille Forer, who just wrote an O'Reilly book on platform engineering. And then I, I spoke to one or two other folks who have been around, you know, they weren't the young people at the show, let's put it that way. They've been around and, and what they told me, they, they all said the same thing.
They've been managing platforms for 20 plus years. I spoke to the SVP of a, of a company. Um, I, darn if I remember the company's name, her name is Hy, uh, tell, tell Something.
Anyway, she had been at Yahoo and she's been at, uh, HashiCorp and, and others. But, you know, all of those, all of those people, similar story, they've been managing platforms for 20 years. We, as the, in the IT industry have had platforms all along.
We just, you know, the, the idea of, you know, putting the name platform engineering on it and calling these people platform engineers, when, when you go underneath that umbrella, there's a lot of different, different disciplines that go into designing and managing, running that platform. I would say that we've had platforms, but not engineering. 'cause every platform's a snowflake in these operations, and they're all somewhat different and tweaked.
And even multiple instances of Kubernetes are not the same. So that's kind of makes the whole issue difficult to scale. Yeah.
I mean, and that's why I think a part, a big part of what this community is, is trying to get like best practices in place. And you, interesting, you mentioned Kubernetes. I think another thing that I heard there yesterday is the platform engineering is maturing.
It used to be, all right, let's install Kubernetes. Okay, we've got our platform move on. But you know, now we're looking at IDPs, we're looking at security, you know, looking at a lot of other things that go beyond just setting up and installing Kubernetes.
Yeah. Alan, what's for, for the neophytes and who are not platform engineers? What's IDP Internal developer?
Internal developer platform. So, you know, they, a, Google creates an IDP for all the Google developers to use. So I'm, I'm kind of smiling to myself that Kelsey Hightower keynote, this thing.
'cause I cannot tell you how many keynotes I've been to over the years with Kelsey. And he is always standing up there saying, Kubernetes is easy. And everybody in the room goes, what's that guy talking about?
Kubernetes is nuts. 0 where we're gonna finally get it right and call it platform engineering. Make it easier.
You mean? It goes beyond FPI goes to the zoo. We, we will see, we will see what happens.
But Kelsey's, Kelsey's definitely bullish on it. So anyway, that's my report. All right, folks.
Well, any final parting phrases, thoughts on this, Alan, before we move on to our Next topic? No, I mean, you know, we will have, in addition to that article I wrote, we did a whole bunch of videos. They'll, they streamed live from the show yesterday.
And, uh, actually by today, they'll probably be up on text TV or or OTT app. com, because that's where we're gonna be, you know, putting more and more of this platform engineering centric news. And, and, And there wasn't any big announcements when any, you know, was there any, any interesting tooling announced, Or it's not, it's not that kind of plat, it's not that kind of conference, right?
It's not a single vendor. It's really not. It's a community led kind of thing.
And it, it hasn't matured to the point, let's say a cube con where all these companies, you know, release their latest versions for Cube Con or something like that. It's still very much more of defining best practices community. It, it reminds me of early DevOps, like DevOps days when that was really rocking.
It's group therapy, right? Yeah. There is a certain amount of that.
Anyway, let's take a break. We'll come back. We've got, uh, our third, third segment lined up.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
security boulevard com to learn more. com. Home of security Bloggers Network.
Hey folks, we're back. And under the heading of Curiouser and Curiouser, the US House of Representatives has banned the usage of WhatsApp. Not quite clear why, but they're saying apparently there's not enough transparency in how WhatsApp works or what's going on.
This is from the same people who seem to be using, you know, a signal left, right, and center. But it's a little perplexing at the very least. But Jack, what's your take on what's going on here?
Well, I'm gonna steal line from Stacy and say this is, uh, a little bit of, uh, misinformation, disinformation, and head scratching all at once. Um, what I understand is they're claiming that there are data security issues and it was banned by the House Chief Information Officer. So let's just start with good thing that the house has a CIO role, I don't think anybody knew existed.
Um, that they're considering the security aspects of the tools they're using is absolutely wonderful. Makes my heart go pitter patter. Uh, but, um, there are a number of tools that are available that they can use for communication that spans signal.
Um, Microsoft Teams, um, uh, even Amazon has a tool, again, another one I didn't know Wicker, um, that is on the approved list. All of the tools that are approved, uh, and, um, WhatsApp all support, end-to-end encryption. So that's a really good security feature.
Uh, apparently WhatsApp, by default does not encrypt the data once it lands on your device. And that is an option that you have to enable. So that may be the sticking point.
It's not clear. All of the other tools, um, encrypt the data as it lands on your device. So when it's at rest, it's still encrypted and you have to authenticate to the device before you can get access to that, uh, data.
The other part that may come into play here is that, um, there is a way to share, uh, to link your WhatsApp stuff with the rest of your meta applications, Facebook, Instagram, some of the others. And that may be part of, it's not clear if that's the issue or not, but that may be part of the sticking point, that by connecting those apps to your Facebook app, there's some leakage in that can occur there, as well as Facebook and, uh, or Meta Now, um, plans on and has released its first ads and is putting ads into the WhatsApp platform. So all of that may come to Bite Meta in the long run and WhatsApp in the long run in terms of its usage.
So Stacy is in your sense that this is something other enterprises should be looking at and say, Hey, if the CIO of the House of Representatives has an issue, maybe we should all have an issue? Possibly. I mean, again, it gets into everything is just so chaotic.
How does anybody know what to believe? Sometimes I feel it's, it's like that, I forget what movie it is, but that scene, you know, a bunch of movies where it's seen, it's like, Hey, look over there. You know, something gets taken from your plate.
Like, I can't tell. And you know, I mean, it's interesting that they're, they're t even looking at this WhatsApp when meanwhile everything that's been going on with Signal, is it a decoy? Like, what is going on?
Right? These are all the questions that people are asking and trying to figure out. So I think it, it, regardless, it's important for all, uh, organizations to be looking at, you know, what programs are being used, what's going on with the data.
You know, I think about how last week we were talking about, um, the EU and their high, uh, standards and expectations for how data is managed, right? And that the fact that they, they're uncomfortable with the US managing their data. So we're, I almost feel like there's a little bit of a parallel, we're looking at this, it's not another country, but we're saying, okay, meta, we're not comfortable with you having the data.
So what are we doing? And that, that's a big question that I think every organization may be asking or, or if they're listening and watching would be asking and trying to look at their policies and trying to look at what makes sense and to try and, and keep up as best that they can. But again, I think we need to see where we land, where are we next week and the week after, and to just try and keep in top and keep, uh, as informed as possible about what's going on.
Because there is a lot that's going on, and there's a lot of things that are changing and moving very quickly. Well, it's interesting that you bring up the uk, um, because the UK in the past has flirted with, sorry, the EU in the past has flirted with this. And the UK is currently contemplating requiring people to break encryption to provide a backdoor for the government.
And so anything that's end-to-end encrypted where the service provider doesn't have access to the encryption keys would not be legal in the uk. And eventually the us, the, the EU has mentioned that they'd like to go that way various times in the past. So that would mean all of these apps wouldn't be valid in, uh, those, those regions.
And it's sort of, there's this schizophrenic or bimodal view of security, which is we want no sharing of personal data unless the government gets access to it. Right. And, um, I, I am, I guess I'm glad that the United States hasn't gone that far and that the, the, the House isn't saying, oh, well we don't have access to the encryption keys, therefore it's not good.
They're actually saying it's not secure enough, rather than it's too secure. Uh, and I wonder how much of this has to do with, uh, uh, tracking this information through the National Archives. 'cause my understanding with these apps, uh, an individual would have to, uh, archive it for them.
It's not something that's done automatically that, so that seems to be a, it, I, I don't know the space at all, but to me that seems to be a, a gap in these types of tools, unlike email servers, right? Exactly. I I wasn't gonna go there, Mike, but I will say that, uh, both WhatsApp and Signal support time limited messages, so they disappear after a certain amount of time.
Um, Microsoft Teams, which is on the approved list, would presumably, and I'm, again, I'm not an expert in that space, but I assume that since it's part of the whole Microsoft Mecca system would actually be able to archive the messages, uh, in a secure fashion. Um, I don't know about w or some of the others, but you're, I think, Tracy, that the, the disappearing aspect of messages is concerning for things that are conducted on government business. You do wanna retain that.
Yeah. So, and, and there are Rules for how long those things should be retained. You know, I, I've always thought that the, the, the, uh, connection between Instagram and Facebook created potential security issues.
'cause you, you can't, like, it's very hard to stop if I post it on one as a show up on the other. I thought they kept WhatsApp purposely sort of isolated from the Facebook infrastructure and all of that for the very reason you brought up Jack or the very reason that the, the, uh, CIO brought up Up, right? Well, it's, it's, my understanding is that by default, it's not integrated.
So if you create, like, if you create an Instagram account, essentially it's part of Facebook. If you create, uh, whatever their, um, I can't remember what they call it, their competitor with Threads, thank you. They better Twitter threads, if you create a Threads account, it's automatically integrated with your Facebook and your Instagram.
WhatsApp is kept separate, but it is, there is still a way to connect it. And I think people do, because there's, you know, from a being part of a greater platform and having all your things talk to each other, I think a lot of people find it useful to connect them all together. I mean, if that's the case, you know, I valid concerns.
I, I wish they'd be a little bit more consistent, you know, across 'em all. But valid concern, well, It'd also be all, could be nice if they got more specific in what the, the lack of transfer, you know, their statement was, there's a lack of transparency in the security. And I'd like to understand, you know, what they mean by that.
What is their, what is the actual concerns from the CIO and you know, is there an opportunity for Meta to fix the, to address those concerns and get back in? Or are they basically just saying, that's it, you're out? Uh, well, you know, I, I have a, you know, when I think about they're using Signal, but they're not using WhatsApp, so why?
Right. And I believe that WhatsApp collects a lot of metadata because I think, um, I think that they want, you know, meta wants that, uh, but I don't think Signal collects that much. So it almost feels, to me it would be the opposite.
You know, WhatsApp's gonna say who you messaged, where you message, and I think you can archive that data off, but Signal, I don't think Signal collects, uh, much of anything. And is that, is that the issue here? They don't want that kind of information, uh, trace anymore.
That's why I was asking about the National Archives, because it seems to me it's the opposite. Seems to me WhatsApp would be easier to archive than Signal. Well, it, it, it could be the metadata, and it could also be the, the, the potential to abuse the metadata or whatever ad data they do have access to for profit or for, right.
That through throughout the Meta Universe. Whereas if you're on Signal, or if you're part of, uh, uh, you know, all of the office, the, the Microsoft teams is part of Office 365. It's part of FedRAMP.
So all of that is, is in a walled garden. It doesn't get shared. A signal is obviously signals like a nonprofit.
It doesn't share with anybody. It's not trying to make money off of this stuff. I don't know the answer for Wicker, uh, Amazon's tool.
And the other ones that are approved is, uh, Apple's, uh, iMessage and FaceTime. But those are also essentially walled gardens. Apple doesn't share that information with anybody else.
Doesn't sell it either. It's really only Facebook that's ever been in the position of saying, well, you give us access to, you know, we basically will take everything we can and leverage it and use it to sell ads against you and to do other things with it. Right?
So I feel like that's kind of the core of the problem here for, uh, WhatsApp, right? Because they're providing a quite a bit of detail about all those government officials and Facebook owns it. I guess, you know what I wanna know, it's like how much potential shadow it is going on in Congress and the government in general, whether you, you know, they have these quote unquote approved apps, but I got a feeling that a lot of them are probably communicating on things that are not quote unquote approved.
And, But that's not new. I mean, Mike, you, you brought up Hillary's emails, that's the perfect example. But it wasn't just Hillary.
They've all, you know, what about cell phones? What about your cell phones? Are they using, you know, lockdown cell phones?
Are they using burner phones? Are they, you know, there's all kinds of craziness going on. So, So let's also be clear here that the ban was on government issued devices.
Right now, almost all of the members of the house and their staff are gonna have a government issued device for government work, and then a personal device for their personal stuff. And will they use the personal device for government work? Even if by accident, which I'm sure anybody who's ever been issued multiple devices, a business device and a personal device has almost always used the wrong device because it's, it's just a pain in the ass, right?
It's a pain in the, took us to deal with that. So yeah, inadvertently you're gonna end up using Shadow it, you know, personal device to do government business. Do some people do it purposefully?
I'm sure It is what it is. Well, It feels like, to me, this is a, a, a discussion about the government's lag in terms of adopting new technology and adjusting to how we now communicate. Um, and maybe the government should have their own version of a signal where we can track, uh, you know, the, the data that's coming from them so we, the National Archives can have a look at it, or at least, you know, track it.
It's, and that's what they're there for. And we don't, we're not doing that with these new, um, solutions. And everybody has a phone and everybody's gonna use their own phone.
Uh, it's just the way we are. So how do we, how does government catch up with that? Well, We Have a long way to go.
There's always a lag between technology and legisl legislature, uh, and, and like society catching up to it. And, you know, and, and the government at some level, we think we hold to a higher standard because they need to have, you know, the, the, the security, I don't want to use the word secrecy, but it, there's definitely a lag. And, and technology's moving forward.
It's such a rapid pace, you know? Well, in, In this case, I don't really think there's a lag. If you think about it, they've given the house members options for seven or eight different communications channels now, you know, in the technology world, we talk very often about, you know, meeting the customers where they are.
And I believe that, and I've got, I don't know how many different communications channels I use on a daily basis simultaneously having communicated right. With Slack and Teams and Signal and WhatsApp and email and, and, and, and, and it goes on. And, you know, it's because I can't dictate to the people I interact with what tools they use, right?
And if you're a House member and your constituency or somebody very important reaches out to you on a particular communications channel, do you tell 'em, no, I can't talk to you on this. You must talk to me on some other channel. Or do you have the conversation you need to have?
If it's a top secret, you tell them it has to be done on another channel. Thank you very much. Yes.
Well, from Top Secret, yes, that's what You do. Yes. For classified Stuff, I mean, that's a whole nother story.
But the House, most house members aren't dealing with classified stuff on their day-to-day basis. Right? They're dealing with just generic issues that, that, for the most part, end up in the public, because that's their job, is to be in the public.
I, I think that now that we know that there's an actual CIO for the house, and I'm assuming there's one for the Senate, maybe somebody should invite these folks to a hearing and ask some interesting questions. I would love that. That'd be great.
Let's do it. I would love that too. Great.
Great suggestion, Mike. Absolutely. All right, on that note, let's wrap up this episode of Textron Gang, Tracy.
Stacy, Jack, Mike, thank you for joining. Thank you for watching. As usual, we have our Techstrong TV schedule right behind this.
Uh, we'll be back tomorrow with fresh content. Um, until then, take care, everybody. We're out.
Hey everyone. Welcome back to Text Drug tv. I'm so glad to have this person.
Usually I see them around RSA or Blackout or one of those, but I haven't. So we've got him here on Text Drunk tv. Let me say hello, please to Ma Maria MedU.
Maria is the Chief Technology Officer. He's a director, as well as co-founder of one of my favorite companies, secure Code Warrior. How are you, my friend?
How's it going? I'm really good. Thank you so much for having me.
Always a pleasure. Where are you in the world today? I'm in British Belgium.
Excellent. What am I? It's a great city, great area.
Um, so Mattias, why don't you give people a little sense of your background, how you came to found Code Secure Code Warrior, and a little bit about Secure Code Warrior. Sounds good. So I, a technologist.
Um, I started my career at Gen University here in Belgium, where I pursued a PhD in application security. Um, I was working with static Analysis solutions, and 20 plus years ago, there was only one company that was trying to do something very interesting with static analysis. And that company was called Fortify.
So I started my career 20 years ago at, at Fortify, because I, I joined in, I finished up my PhD, I moved to the us and I joined them when they were still a, a tiny startup. Um, I've spent seven years at Fortify, um, finding problems in code and saying she at that time, throwing it over the wall to developers and running away as fast as we could. So my philosophy was like, Hey, can we do something for the developers?
Can we help the developers? Can we make sure that developers can create secure code from the start? And that's why we started Secure Code Warrior.
Our vision, our mission is to get those damn security people off the developers back. That's our, that's our goal. In the beginning, I think we were a training company.
We were trying to provide content to developers. I remember hands on content. Yep.
Hands on content, making sure they knew how to code securely. Um, these days we call ourself developer risk management, developer risk management. So we wanna make sure that organizations can control risk, that can potentially be introduced into the code.
So we wanna make sure that the, the CISO has the means to make sure that developers really have the tools and the knowledge to create secure code. That's our philosophy. Um, so ultimately, um, I think the philosophy should be only secure.
Developers can check in code into a repository. You know, only secure developers, only upskill developers should be able to check in code into a repository. And that's how, how we move forward with Secure Code Warrior.
Love it. And I lo, you know, I, so look, I've, I've been following Secure Code Warrior now, I don't know, six years, seven years. Is that about right?
I think so, yeah. We've, we've spoken quite often. Yeah.
And I have, I've seen the metamorphosis from sort of a training company to more of a, a product led or, uh, engagement as well, consulting and everything else. And it, and it's been a great, a great journey. You've also collected some amazing talent at Absolutely.
Code Warrior over the years. Um, but of course, AI is kind of changing all the rules now, right? True.
So all of a sudden it got easier for developers to kind of build security. And because security via AI is being built into the IDE, it's being built in, you know, the rise of platform engineering. Seven years ago, we didn't talk about platform engineering, but the idea of building a platform that has guardrails in place mm-hmm.
That gives these developers, we don't ask the developer to have to build their own platform to develop on, right? They, they're given a platform that hopefully has some security and so forth built into it. But AI is, is certainly changing this secure Code Warrior being who you are, meaning the company, not just you.
Um, you guys are taking advantage of this use, using it, leveraging it to try to make the mission better. You recently came out with, uh, some security rules that are in GitHub that developers now can use. Well, why am I telling the story?
This is your story. Tell us. Sure, absolutely.
So with Secure Code Warrior, we're, we're embracing the new world that we live in, the new world where developers are going to use AI to create codes. Um, so our philosophy is that, um, developers will be replaced, and not with ai, but they will be replaced by developers that are using ai. So we need to make sure that we give every means and tool to the developer to create the best secure code that they can potentially create.
So that's our philosophy. So as Secure Code Warrior, we wanna make sure, um, we guide the developer in writing secure code with AI these days. And we do that in, in different flavors.
So in our platform, we have these new type of challenges where, well, it's, it's like more of a role play. Um, you, if, if you, by the way, if you ask AI a question, if you're a developer and you ask AI a question, you do not get a text answer. You get a diff between the original code and what the AI solution is suggesting.
So then the question is, do you accept that? Do you believe the AI solution? Do you approve essentially, um, the diff and are you going to commit that code into the repository?
Um, and that's our new type of challenges in the platform. So in the platform, we do some role playing, like, Hey, you've asked this to the AI solution, it's proposing this piece of code. Is it, is it secure?
And if they say, no, the AI solution is gonna help you a little bit and say, Hey, well, did you think about this? Do you know about SQL injection? Do you know about, um, uh, uh, cross side scripting?
Like, and it's trying to explain, you know, how to think about these things and how to create secure code and how to work with an AI solution. So that's in our platform. But then at the same time, we also saw that if you give a couple more hints, you know, a couple more ideas to an AI solution, it's actually producing better code.
If you say to an AI solution, well always use parameterized queries. It's gonna essentially avoid creating SQL injection, or it tries to avoid making seql injection. You still need to do code review.
You know, there's hallucinations, there's, there's mistakes that an AI solution can make. But that's what we've released, um, last week. So what we've released is those very simple generic rules that essentially whisper in the AI solution.
Like, Hey, always create secure code, but it, it's a little bit more than that. You know, we make sure that we whisper in the AI solutions ear how to produce that code. Um, so it's essentially very silly that they not always create secure code by themselves, but it it's kind of normal.
They're trained on, on random stuff. So quite often they do not know what to produce. Yeah.
But so what we've released is a very lightweight set of rules that can be added to your, um, cursor to your regular IDE, um, whatever IDE you're using with an AI solution connected to it. You can embed those very simple rules. You can extend those rules, and it is gonna produce better meaning more secure code.
By the way, it's only focused on security. We're, we're a security company. It's only focused on security.
It's not focused on quality or optimizing for whatever. No security. I have a question on that.
Absolutely. Would love to hear. I am sure that the security, it helps making you know that the, that what it does in helping you develop more secure code works.
Mm-hmm. But are we destined to live in a world where the developer's gonna have a security focused ai, a speed focused ai, an optimized of focused ai, uh, on AWS optimized versus a Google Cloud versus Azure, uh, uh, you know, I'm needed to work with Salesforce. It's the same problem I have with Agen ai.
Are we, are we destined for a world where I'm gonna have to deal with dozens of agents with five or six different ais working in my IDE? 'cause it's gonna drive me as a developer, it would drive me crazy, right? Um, maybe so I, I think, or maybe, but for the foreseeable future, I think it's a reality.
I think more and more specialized AI solutions will come into play, um, solutions that help you with fixing code, um, solutions that help you with generating ideas. And if, and some of them are, we actually did a piece of research and we saw that, uh, certain models are better in certain languages than other models. Um, so today, yes.
Um, five years from now, I don't know. I hope it's, it's not the case because as you said, it's gonna be, it's gonna be hard to, to live with. And, but today it, we live in a reality where there's a lot of specialized solutions and, um, I think it's our goal as secure Code Warrior, making sure that people are informed what they can use, how they should use it, and how they can produce the best result.
And today, yes, it's a complex problem. Absolutely. It absolutely is.
I got business kind of question to ask you. Sure. It's in GitHub.
Am I assuming it's free and open? Yep. It's free and open to use.
Um, ev anyone can extend the rule pack. Um, right now we're, we're not allowing new check-ins from, from people outside of Secure Code Warrior. But, so yes, it's free to use, you do not have to be a Secure Code Warrior customer to use the rule pack.
Um, but, um, to do, to use the rules. But you can simply download it, you can optimize them, you can change them, you can do whatever with them. Uh, we would love to hear the feedback.
We would love to hear how it goes. Uh, but yes, um, we thought, you know, for us, it's, it's the first step. So, you know, we said like, Hey, you know what?
Let's, let's do something back for the community and let's figure out who has an interest, who wants to work on something like that. And it's a first step. It's a lightweight rule pack that we just released for free, and we would love to hear the feedback.
I love it. You can get it on GitHub. Do you, you wouldn't happen to know the GitHub address URL off the top of your head, do you?
Uh, not off the top of my head, but I can actually look and, well, so it's got, it's called GI com and cheating. I'm absolutely cheating. com/secure code warrior slash ai dash security dash rules it.
So that's where people can download, um, the rule pack. You could probably get to it off of the, uh, the, uh, secure Code Warrior website too. Can Oh, absolutely, absolutely.
And, and what's the website? com. I love it.
This is a great resource for our developers, our DevOps people out there. Check it out. Even for our security people out there, you need, you got, they, you need to be on top of this stuff so you know what to expect and what's available, how you can help the developers in your organization develop more secure code.
Yeah, it's, it's all text based, so I, I think it, it applies to a lot of, uh, other areas as well. So, um, uh, optimizing to get the, so essentially what we're doing is, is we're, we're helping the AI produce the best results, like it's prompt engineering, but on a continuous basis. So all we're doing is trying to make sure that we get the best results out of the AI solution.
And I think that's what we all want in every field. So what we've done is just a very specific one for developers and to write secure codes. I love it.
Mattias. I, I don't, I don't ever say your name as good as you can. It's just my New York accent.
I apologized, but, uh, maus is how it is. It, it is. Maus.
Thank you so much for coming on text on tv. It's been too long, my friend. Come back soon.
Keep us posted. I'm sure there's a lot more going on with Secure Code Warrior. You guys always have a lot going on.
Will you be a black hat this year? I will be. So, um, would love if people we're there catch up.
Oh yeah. If you're there, let's catch up. If people want to catch up, send me an email or LinkedIn and I'm happy to go for a coffee.
We're doing live video. I expect to see you there. Sounds good.
Happy, I'll I'll you up on that one. Happy. We'll reach out.
Sounds good. Maus, maus, Madu, chief Technology Officer, co-founder, secure Code Warrior here on Textron tv. We'll take a break.
We'll be right back. Hello and welcome back to the Open Source Summit here in Denver. We're talking with Steven Watt, who's the vice president in the office of the CTO, responsible for software engineering.
And we're talking about how this whole pace of change in the land AI is rapid and now it feels like it's becoming more of a traditional IT task rather than just something that some obscure little data science team did on the side. Steven, welcome to the show. Yeah, thanks.
I appreciate being here. Um, got a lot to talk about. I think you're spot on.
I think there's a number of reasons that, uh, necessitate that, uh, cost is one. This is very expensive compute infrastructure. Um, and so, uh, what we're, what a lot of companies are trying to do is get the best use out of their investments, which tends to mean centralize it and then make it available to multiple teams.
Um, so we're seeing that sort of convergence as opposed to each different data science team having their own clusters. Uh, but then there's also like the explosion of generative ai, which, and all the different use cases around that. And then that puts duress on a particular single cluster instance.
And so it needs to be able to have a way to efficiently scale that to meet the internal demand. Mm-hmm. And I gotta scale that, not just up, but back down again because it's essentially a multi-tenant environment.
Now that I'm trying to support multiple workloads, and this is a little challenging, gotta manage this almost like an internal cloud provider. Yes, absolutely. I mean, I think, you know, historically what you've seen with inferencing is Uh, we've had, uh, v lm, which is an open source inference, uh, server that was, uh, came outta uc, Berkeley, their Skylab and, uh, red Hat, um, has acquired Neural magic and, uh, neural magic's, the largest commercial contributor to VLLM.
So that was our initial focus. There is on inference, uh, but essentially, um, the, the cluster needs to scale to sort of maintain, um, the ability to, to continue performing under increased load. And those loads are, um, not just coming from human adoption, but also agentic architecture.
So it's not just people, it's agents, it's other processes that are putting duress on the cluster. And so LLMD was a project that we created that allowed us to disaggregate some of the key steps and inferencing. So specifically pre-fill and decode one, which is GPU bound, another which is memory bound.
And it's sort of a classic move from scale up to scale out. We were able to take certain components, put them on dis uh, different, um, infrastructure and sort of be able to scale performance for that. Mm-hmm.
You know, it's funny, everybody talks about AI agents and we're gonna have thousands of these AI agents and somewhere there's some folks running infrastructure going, come again. How many, what, what will these agents do to the demands for infrastructure, the throughput, the capacity? Are we gonna have to rethink the entire stack to accommodate all these AI agents that are gonna be running 24 7 constantly pinging on infrastructure that wasn't designed for that?
Yeah. Well, the way I reason about this is, um, it's a new class of applications. And what I mean by that is, you know, if you had a, um, especially in like open source and platforms, there's sort of three chapters in the history.
Like there's a chapter one around Linux and a class of applications that run on Linux, a chapter two, as the world move from scale up to scale out a chapter two that runs distributed systems and a whole new class of applications that are, we know is cloud native today. And then now with inference servers and generative ai, there's a new class of applications that are built around essentially, uh, open AI's interface protocol, which has just become the standard for inferencing across the industry. And so for that, you've got multiple uses of that.
One you have like human to interface server, which as we know is the chat bot, right? So sort of open ai, um, and chat GPT made that the Norman helped us understand there's many different instantiations of that and, and internal organizations are using that. But then you have agents to the server and then agents to agents.
And I think you're seeing, uh, an exponential, I think we will see an exponential explosion in the amount of agents as that maturity curve grows. The question is like what your question was specifically, what infrastructure does it, is it served by? And that is like, I think it flows along a very similar trajectory that we had with Cloud Native, where you started with a couple of servers and then as the demand increase, you increase IT.
Projects like LLMD allow you to do that. And they also have auto scalers that are built into that. And so as demand come, um, may come down also for specific components where if you're GPU bound or memory bound, uh, compute bound or memory bound, you're able to scale up discrete components of that.
But it is a new class of infras, uh, applications and like Kubernetes, it required a, a new set of deployments inside IT infrastructures to be able to service these new classes they run on Kubernetes. So in the same way that Kubernetes runs on Linux, LLMD runs on Kubernetes and takes a benefit of all those distributed computing principles. But I think there are some changes and new skills that are gonna be, have to learn to be able to support the explosion of AgTech.
I also feel like we're trying to make an effort to kind of decouple maybe training and inference a little bit where I can now have the inference run anywhere almost on any class of processors and everything doesn't have to be wrapped around A GPU per se, and there's just gonna be a lot more diversity in the ecosystem. So are we creating a level of abstraction that kinda lets us invoke that underlying hardware in a way that's a little more dynamic? Yeah, I think the, the way I reason about this is predictive versus generative ai.
So like predictive like classifiers that we've been using for a long, long time. Um, this work pretty good on CPUs, right? And they're smaller models, uh, able to fit into smaller memory footprints.
Um, the, it's kind of interesting. It's like, I would say there's only like five models that matter, you know, on the generative side, although which five they are tends to change like every month or every two months. There's millions of models, but there's quite a high turnover, um, as to which ones we're going to, uh, this month.
And those are generally addressed by GPUs and you need like the best price performance GPUs to be able to serve those even in inferencing. Um, the challenge though is you can get some heterogeneous infrastructure and so like optionality and being able to use your Nvidia like H one hundreds as well as like your A-M-D-M-I three hundreds, um, together, especially, I dunno, some places I've discovered are a MD shops and some places are Nvidia shops. And so being able to sort of have one project that can address both, uh, is pretty Important, aren't we in danger of locking ourselves into too many things.
And sometimes I feel like, and we've been talking about this forever, but developers are always kind of trying to optimize something and then they write to a lower level API somewhere that doesn't work somewhere else. And then the IT department wakes up in the morning and goes, how come we're locked into this? Yeah.
Is there some way to think about this earlier this time around where we can get this right now as opposed to, you know, trying to undo it later? Yeah, I, I am, I can tell you I'm thinking about it, it keeps me up at night. Um, there's a couple of really interesting projects, but I will say like, it's a hard problem.
Like if you look at our previous open source chapters around like Linux and Cloud Native, like it really was an X 86 world and then it was like an X 86 plus a little bit of arm world. And, uh, those are still true. But in a generative world, we're, which, you know, let's just be frank, is dominated by the Nvidia, um, architectures and the Cuda ecosystem.
The, um, it's a little tricky because you have the ability to light up GPUs inside, um, the inference server. And that is done through a software layer around GPU kernels. Okay.
Um, those GPU kernels, there is an open project called Triton, not to be confused with Triton inference server, um, Triton basically allows you to write those GPU kernels that enable the models in an abstraction layer that works on NVIDIA or A MD or Intel, anything that's a classic GPU architecture. But the world's a bit more complicated than that than it was with the X 86. We have TPUs, we have NPUs, we have inference specific accelerators like CEUs, cereus, and Grok.
And we have to figure out a consistent way to light those all up in PyTorch. And they are very different architectures. And some of them, like for example, A GPU while is really great for, um, supporting generative workloads.
It's also built for gaming and it's useful in cryptocurrency mining. And whereas these other accelerators have different architectures, they consume way less power. They're just as effective for generative but not so on video games.
And, you know, and so trying to figure out how to light up all these hardware architectures in one single GPU kernel programming LA layer is a challenge, uh, that we're going after at Red Hat. Uh, we're starting with the Triton project, but we're looking at ways to increase the scope to be able to create as bigger of an umbrella as possible. Yeah.
I also think we obsess with the large foundational models. Yeah. But in practice, it seems to me anyway, most IT teams are gonna wind up working with smaller models that are kind of being used to drive a, a, a narrow use case for an agent.
And then I'm gonna try to orchestrate all these things. So, uh, are we not paying enough attention to the requirements for smaller models? 'cause we're all obsessed about the big models.
I I think you're correct in that, um, we will have a set of purpose fit models for specific tasks. And Where I think we're gonna see the industry going is smart routing. So we're gonna have a distributed cluster that can servee a variety of models.
Alright? Um, those models will have different strengths. And likely what you're gonna have in front of that is a, some sort of intelligent semantic router that looking at what your prompt is can help you figure out which model to go to.
Like, there's some models that are like really great on physics. So if you have a physics question or a science question, you should go there versus there, right? And being able to understand where to route, and I think that's gonna be hidden from the user.
And you're right in that if you have single purpose models, they don't really need to know arcane details about, you know, who won the ND 500. And at this time, you know, it's, it's literally like science, you know, and that'll allow them to become, it. It also is useful for model shrinking techniques like s ification and quantization for you to be able to prune out the stuff the model doesn't need to allow it to run in smaller memory resource budgets.
So I think we'll see all of that over time. We just need the plumbing to be able to hide that from the user and make it an intuitive experience. Right.
And the paradox of that is the less the model knows, the more accurate it may be. Yes. Yeah.
Yeah, yeah, yeah, yeah. You can, it certainly run into over fitting problems where, you know, you're trying to stuff too much into too small of a brain and it, it's has to use, uh, like trim out what it needs to, uh, what it knows already to be able to fit all the stuff you're trying to put in, uh, is an overheating, simplistic way of describing it. But, um, uh, yes.
And, um, but I think all the plumbing is there on LLMD, it has sort of inference pools that you can host different kinds of models. And, and not only that, um, there's other reasons to use different kinds of models like costs. So you can have policies, for example, of like, let's say, you know, I bought a bunch of GPUs five years, five years ago.
They're not near as powerful as the one I bought this year. Um, still want to get good, good hue out of them. I'm gonna have low priority tasks routed there versus higher priority tasks routed there.
These all capabilities we're putting into the routing, um, in front of the inference engine. Huh. So last question.
What's the new thing that, you know, as you look in your crystal ball or the thing that's got you most excited, you know, the thing you're going, wow, this is the next thing that's gonna be cool. Yeah. Well, I would say, although I don't want to sort of jump on the bandwagon, um, it really is a agentic architectures.
And what I mean by that is I look at it, i, I frame it slightly differently though. It's a new class of applications. And when that happens, the industry has to figure out how to do all kinds of non-functional things.
How do you secure agents if you kick off an agent? Does it have the same permissions that you do when you try and do things? Your permissions are long lived, like your access to some, you know, your Workday reports or something like that is probably valid for as long as you are at the company.
But if you have an agent, do that, is it, does it have those same permissions for multiple days, 45 minutes? You know, we have to figure out identity authorization, all kinds of security aspects around this ecosystem because, you know, like with model context protocol, a lot of these agents sort of run with the implicit authority that that's just assumed they're allowed to do what they're trying to do. And so this is what excites me.
There's all this space in this new class of applications that just we haven't figured out yet. And, um, and so this is something we're doing in office of the CTO, both, um, in our research infrastructure as well as our emerging technologies teams, looking at different spaces like security, identity, um, performance, and trying to figure out how to make this ELOs of applications work. Well, I may be a bad example.
I was trained by Jesuits who's taught me that it's easier to ask for forgiveness than permission. There's permission. I like that E ethos.
I, I live by that too. Yeah. Anyway, thanks for coming back.
Yeah, my Pleasure. It was great chatting to you, Mike. Hey everybody.
We're back at the open source summit in Denver, and we're talking with Christopher Robinson, who's chief architect for open SSF, otherwise known as C Rob. And we're gonna be talking about, well, first of all, the current state of the software supply chain security. We've been at this for a little while and there's a lot of new regulations to sort through putting C Rob, welcome the show.
Thank you very much. Glad to be back. This is great.
Um, we've been talking about this issue for a while now, and, but it's not clear to me if we're making progress or what's your sense of, are, are people actually doing a better job of securing open source software these days? Or is it still in the realm of, you know, we want to, but we still don't have the will to make it happen? I'll give you a hesitant Yes, we're doing better.
There have been some pretty substantial movements forward in helping secure things, uh, things like our SIG store project that allows, uh, any developer to, to have free code signing and you have a publicly available transparency log. So there's things like that, like our SALSA project that focuses in on the how, um, the CICD systems are configured and the artifacts that move through those. So we've seen a lot better bigger adoption of those types of things.
But we still have a lot of challenges where, uh, developers don't have the right training yet. They don't understand, you know, the, uh, you touched on compliance and compliance has been, there's been a whole new set of legal regimes that have come up since we've last talked that complicate things. And most upstream maintainers, it's not a world they live in.
Our members are, you know, large companies, you know, things like, uh, hyperscalers or banks or retailers, they live in that compliance space, so they get it. But the people that create a lot of the software for the world have no idea. Like just new regulations that come up.
And they, and that's where they will complicate the supply chain as we're adding new requirements that the developers might not be aware of. And at least, like in the case of the eu CRA, the developers aren't necessarily required to follow the law. It's the vendor that's selling the product is, And then there's a lot of nuance in that.
And let's just throw in the Trump administration change the wording a little bit in an executive order on making, um, SBOs more of a suggestion for federal agencies rather than a requirement. Yes. And I think a lot of people are confused about, you know, well, what should I do?
What do I have to do? Mm-hmm. And even in the CRA, there were people who were, you know, saying it's overly prescriptive, so there's just a lot of back and forth, so help us sort that.
Yeah. The, the s om the, the recent executive order was disappointing, uh, in some ways because they rolled, rolled back the, uh, NIST SSDF, the Secure Software Development Framework, attestation requirement, and they also kind of weakened, uh, the sbo, uh, asks. And that's something that when we just had an event in Japan, and, um, Medi is the regulatory body over there, and they're really big into SBOs.
So the, you know, the Japanese and in different parts of the world, uh, everyone's kind of looking at, you know, SBOs been around for eight years or so. We were just at the precipice of actually starting to get good SBOs and starting to refine them and understand like, somebody hands me an SBO I know can actually do something with it. And when, uh, you know, with the US being, you know, the, the largest economy around, uh, when you kind of remove that restriction, if a manufacturer is selling products in the States, they're selling it in the eu, they're selling it in Japan, it makes it hard.
You know, they have potentially different requirements in these different geo geographies. And that may, that adds additional burden for the manufacturer as opposed to having, here's an SBO m here's eight things that need be in the SBO m here formats. We wanna see the SBO M in, and if we had more of a unified front, we're gonna be able to drive the quality forward and get those changes so that consumers can actually get the protections from the supply chain we're trying to get put in there.
Not every open source project is Linux with, you know, thousands of people in peer reviews. A lot of it is smaller teams of people, maybe even onesies, twosies. Mm-hmm.
Um, they didn't get sign up to be, you know, the maintenance team for enterprises. Mm-hmm. So when they get a, when there's a zero day or a new vulnerability, they don't get outta bed in the morning and say, let me go rush to fix that.
Right. Because they're like, I have a life and this is my hobby and not my vocation. Mm-hmm.
So how do we kind of bridge that divide a little bit and get those people the help they need or mm-hmm. Ideally even the skills to prevent the vulnerability in the first place, but even if it does exist, who's gonna help them fix that in a timely way? Because everybody else is like banging on the door and they're like, sorry, nobody's home.
Well, and, and that's honestly ours and other foundation's biggest concern about like the EU Cyber Resilience Act. There's a lot of really strict, really harsh requirements that an enterprise probably is already doing or they should be doing. Um, but it's the, it's all like the last 30 years of application security kind of codified into law, but because the onus is on the manufacturers and not the developers, which is good, but we fear that all these manufacturers exactly as you said, are gonna start harassing the developers saying, Hey, you know, knocking on the door, getting them up out of bed at three in the morning saying, I need this fixed today.
And the developer is like, that's not my problem. You know, I didn't sign up for this. I'm not your employee.
I'm writing software because I love to, I'm solving my own problems. I like the community, or whatever the reason is. And it's not because large bank or, you know, large hyperscalers on me about harassing me to get this fixed for a, a problem.
And that's where, uh, we hope the CRA, there's a clause in there where the manufacturers are unfortunately encouraged to contribute back to the projects that they consume. I, I wish that wording had been a little stronger, more of a, a must instead of a should. Uh, but ideally, and, and some of the bigger organ, some of our members especially, are really taking this to heart where they're analyzing what components they use, and they are reaching out to those projects and saying, you know, what can I, I use you, thank you for your work.
What can I do to help support you? What is it code contributions? Is it infrastructure?
Is it helping out with testing? You know, what, whatever the, the project might need? So ideally, the CRA helps influence the manufacturers to start contributing back and lessening that burden.
And then on the flip side, we're also working with our friends in LF education where we just released a global cybersecurity, uh, skills matrix. So we have 14 job families, and we divide that up over kind of three levels of maturity, beginner and intermediate, and an expert. And we list core cybersecurity skills these job types should have.
So if you're a developer, if you're a project manager, if you're a DBA, if you're an AI data scientist, we like talk about these are the core skills you should have to be able to cyber correctly in your space. And then we're right now, uh, taking that, the matrix is done, it's published, uh, a couple weeks ago, and now we're in the process of trying to identify training so that if we say, uh, architect needs threat modeling or attack surface analysis skills, we're trying to identify whether it's an LF course or maybe it's something over its sands or oasp that, you know, they have a really good class and kind of routing people to those so that we can upskill people, um, from large organizations are small. Hmm.
And part of that, at least my understanding of it too, is that it just helps enterprises define the roles they need. Exactly. 'cause a lot of times they don't even know, like there's a security team Yep.
But they don't have any, you know, particular mission or job assigned to them. So do we just need a little more clarity on the expertise and skills we require? And That's absolutely being a failing of my vocation.
I'm a trained cybersecurity professional for, you know, three decades. Uh, and, you know, we have done a really good job of training, making more prob clones, but we haven't done a really good job of teaching developers here's how to do, how to avoid doing input validation or not coding cross-site scripting errors or a DBA. Here are things you need to think about, like, here's how to correctly configure your infrastructure and how to use access control.
So Absolutely. And now we're finally to the point where we're trying to actually teach people how to do their jobs better within kind of their understanding. And so it leads into the larger security program.
One of the things I noticed here is that there seems to be a significant cottage industry of vendors who are emerging to kind of be the intermediaries between the maintainers and the consumers of those software packages. Mm-hmm. And they're promising the harden them and deliver updates and vulnerabilities.
Is that kind of part of the new ecosystem that companies should have? Or is that, um, a temporary aberration given, uh, the challenges at hand? It, it's definitely not temporary, uh, because, uh, with the CRA especially, and Europe is the first place to enact this law, uh, we are aware that China and India and Australia and Britain are all considering similar legislation.
And here in the states, um, we generally go through executive orders or procurement rules, but basically everyone's kind of putting these rules into place. So the requirement to have fixed software is not going away. And the CRA's kind of accelerating it because if, for example, if your product is found to have an exploited vulnerability, you have 24 hours to notify the European Commission that you're aware of this and get that notice out to your consumers.
And then you've got really tight timelines to have a fix or a workaround. Um, that's about, I think it's, uh, maybe, uh, two, three days. I don't remember the specifics.
It's in Article 14. And then you have to have a final fix with, uh, under a month. And that's, that's tough.
And that's where these, the vendors you talk about kind of potentially can fill that. And, you know, I'm, I'm of two minds. If a maintainer is not interested in doing security, and they're okay with a third party kind of acting on their behalf, or, and they get some kind of benefit from that, great.
But if this company's kind of like, potentially aggressively forking something and not contributing those fixes back to the main project, I, I think that kind of leads us to the, uh, state where we're gonna have so many forks you're not gonna know, uh, which is the right code branch. And you know, when the authoritative source, the project is updating the code, how do we know that this kind of smaller, this subcontractor, are they getting all those fixes? Are they in sync or are they still, are they missing features or other vulnerabilities?
Are we Here 'cause they're not participating in the project. Yeah. To your point about overseas, at least you see countries are leading this at a national level.
We have made some attempts to require federal agencies to behave in a certain way and then walk that back. Will individual states then take up the mantle and have different regs and rules and, uh, you know, we could have as many as 50 different requirements. I, yes.
We've already seen that with like data privacy laws. Mm-hmm. But the current administration is making moves to, uh, disallow states from doing some of that, especially like in the AI space.
So I believe, I think California was also thinking about a new AI security, right. Role a law. And I believe that on a federal level, they're trying to block states from doing that.
So I know, yes, that is a potential, but I think it's gonna get stopped. But I, I'm not involved with it. So I don't know specifics.
Can we close this loop? I feel like most of our focus historically has been on helping people identify vulnerabilities, and that's a good thing. Mm-hmm.
But can we automate the remediation of that? And there's tension, right? Because the security people would be like, yes, let's automate the remediation.
And the developers are like, no, you're gonna break my app. And so can we get, is there a middle ground there somewhere? Absolutely.
Well, and that's where if you, if there's software that you care about, the, one of the best ways you could help a project is write test harness for it. If there's use cases that you need to have tests for, contribute those back to the project. And that's where the, the big problem is anytime you make a change to software, there's a potential for regressions it.
That's just a fact of how things work. How complex this, this, uh, community developed kind of a composite applications work is it's, you can't understand all the variables of all the different parts. And so if there's things you care about as a user, you can contribute that code back to the project, and hopefully it gets adopted into their CI systems that will help speed that automation so that eventually that could get there.
But there's always a potential anytime you change a line of code that there's unintended consequence. And that's where, that's where the, the developers especially get fidgety about. If you're automated too much, There are folks out there that are deeply concerned about application security at all levels.
Mm-hmm. How do they engage with the open SSF and how do they, because a lot of times they're like, well, I care 'em, but I don't know who to call. I don't know where to begin.
And so where, what is the point of entry into that ecosystem and how do they get involved? And, And that's the, I personally feel is the beauty of foundations like the Oakland SSF for organizations like oasp or Eclipse. Generally, all of us are focused on different aspects of security or different pieces of software, but all of us hold 100% open meetings.
And we also take open meeting notes so that if you can't make a call, it's eight o'clock at your time. Well, generally that call's recorded. So you could watch a video or you could read the notes.
They'll have a public, uh, source code repository. We use GitHub. Other people use other systems, but everything's tracked.
It's issues and pull requests so that there's a way that you can observe and kind of learn what's going on, and if there's something that you're interested in. So if you care about AI security or you care about NPM package repository type stuff, there's ways that you can onboard very easily, very minimally. And then if you wanna step in, you could start participating in the meeting, raise your hand, ask a question, or propose an idea, propose a patch or a project like, Hey, have we thought about scanning this?
Or we thought about this feature and the communities, all, all these. And what I love about open source is that we, not everybody, but generally, everybody is very open and welcoming to newcomers. And we love, we thrive and grow on new ideas and contributions and contribution could just be feedback.
I think that's a bad idea. I you should make the button blue, not red. Uh, or it's actually, I'm gonna contribute some code.
Maybe I'm gonna contribute a test harness. Maybe I'm gonna put some engineers on the project to help develop it, because strategically, this is important to me, and I wanna make sure that, you know, my use case, my user stories are considered as the strategy of the project goes forward. Last question.
We talk a lot about AI security, and there's a lot of concerns about that and legitimately so, but I can't help but wonder if maybe we're finally paying enough attention to software development and security in the context of ai. And that may benefit the quality of the software we're building down the pike all the way down to the bottom of the stack. I hope my, my biggest complaint about just the AI space in general is that they have been, uh, they feel that they're a delicate, unique snowflake.
What they're doing is so amazing and different than everything else that no one could possibly understand it. And there's not no standard or tool that would work for them, uh, except AI development is development. And we have over 30 years of documented methodology and best practices that that space could benefit from.
Yes, some of the nuances are different that you're using accelerators and GPUs and just kind of, the system architecture's different, but it's not that much different than like a telecommunications network or other things. It's a, it's complex, but there's a way that you can kind of break that complexity down into digestible problems and, uh, solve it with existing tools or improving those existing standards, and you're kind of participating in a bigger community instead of kind of spin off on your own. All right.
Folks, you heard in here, so the software supply chain is getting more secure and it may even get better in the age of ai, but we all gotta participate. Mm-hmm. Hey, brother, thanks for being on the show.
Thank you for Having me. All right. And we'll be back in a minute.
Hey guys, thanks for the thrill. We're talking with George Hans, who's associate general counsel and VP of Compliance for Archive 360. And we're gonna be talking about, well, how do we turn all that archive data that we have into something that feels like a business asset, maybe using a little ai.
George, welcome to show Thanks, uh, for having me again. Alright. We seem to have a massive amount of data that people have archived over the years, and it's not clear to me that even had a purpose.
They were just kind of doing it, um, almost outta habit. It's kind of a just in case kind of thing. Um, is, is there now an opportunity to go back in and look at that data, maybe surface some patterns and insights that create actionable intelligence that we're ignoring right now?
Yeah, for sure. And, and maybe to, to go back a little bit and try and explain, you know, where is a lot of this data that's, that, um, has been saved historically? A lot of it often actually isn't even in a, in an archive yet.
A lot of it's sitting in legacy systems, um, that have been retained because the data needs to be kept. People want to access that, but they're keeping the old applications and the old systems to actually access or maintain that data. Um, and so that is inaccessible, it's very difficult to use.
The systems are often not supported, um, you know, from a, uh, not just a recency perspective, but certainly it's inaccessible to AI and analytics tools. So that's, that's the first problem. And then the second piece was a lot of the archives that were being used, or the extent people were using backups, um, and backup systems to archive data, that data was also inaccessible because it, they were proprietary formats.
Again, they weren't really designed, the data wasn't kept in a form that was easily consumed by AI or analytics. So really all you were doing was keeping that data and maybe keeping that data, obviously for compliance and regulatory purposes. And that's it, it was very difficult to access and use anywhere else.
Mm-hmm. Do I now need to normalize all that data before I can expose it to an AI agent? 'cause that sounds like a lot of work.
So, um, you know, one of the things that we look at is, um, we, as we bring data into our platform, obviously we're, we're classifying that data, um, each class of data. What's, what's unique about how we approach it and what other companies really need to think about is you, you can't take all that data that's sitting in many different places and then try and create one giant ontology out of it, or one giant schema or structure is all gonna look quite a bit different. It needs to look very different.
It's coming from many different places. It originated in different forms. So what you're trying to do is to take the data in, in its kind of native view or native form, um, and then, um, take that and map that into your, into our platform as an example.
And so we're trying to retain the structure. Um, we're trying to retain the uniqueness of that data from its original source, you know, as we archive it for obviously the regulatory and compliance purposes. But then now, uh, we can take that data in the way we do keep it and maintain it, and it is completely available to AI and analytics, um, solutions.
Uh, and so I don't know if it necessarily means you have to recreate that data or you have to do a lot of data shaping for that data. Um, but if you do this upfront and you do this once, and you, you have a modern approach to how you want to govern this data long term, then, then you're gonna be fine, um, to plug it into your broader data ecosystem. Mm-hmm.
So is it your mission to expose that data to all those different AI agents? Or, and maybe, and, um, are you gonna build your own AI agents to kinda accomplish that task and, and then they will share whatever information is interesting with other AI agents? Yeah, so the first thing is to make that data available to, you know, again, we look at things as, um, fitting within a broader data ecosystem.
So if you think about a data estate or data ecosystem in an enterprise, there's lots of different, uh, tools and different sources of data and different AI and analytics tools that are gonna be used. And so we're trying to fit within that and to be able to serve up this data to any number of different downstream AI or analytics tools. Um, now that, that also means that we can take and selectively get data to these tools.
So it's not, we don't have to expose the a hundred percent of our archives. You may not want to, um, you might not want to take five petabytes of data and push it to ai. Um, and that's the whole value.
And actually being able to be selective, entitled, and make sure that you're bringing secure and entitled data, um, to those tools separately within the platform. We are also then creating and using and building out agents, right? So think about complex or highly repetitive, um, functions that today you, you would execute through an interface setting retention, conducting a discovery request, conducting a search for an FOIA request.
Those are things that today you do through an interface, but agents are able to do that as well. Um, and then agents also are taking over a lot of the analytics functions, uh, as well. So, um, just doing the, the, the basic analysis of data, uh, is something else that you'll be able to do through, uh, an ag agent interface.
Do you think we're finding an a, a new respect for data management? I think we took it for granted all these years, but in the age ai, it seems to me nothing much happens unless we figure out how to manage the data first. A hundred percent.
And, you know, Gartner talks about, uh, AI ready data. There's a lot of other, obviously discussions around AI ready data. And so much of it gets back to, again, do you have a good data governance, data management construct that allows you to manage the data in a way that meets all your regulatory and security and compliance requirements, but at the same time easily allow these downstream applications and, and AI and analytics tools to consume it.
Uh, and that layer is critical. Uh, and again, there's so much writing out there and, and I don't wanna, um, you know, try to recreate the wheel here. But again, garner has a lot of data and a lot of research around what does AI ready data mean.
Is there something of a paradox here in the sense that for years, companies that operated in regulatory frameworks that required a lot of structure complained vociferously about the cost, and yet here we are, if you look at it now, they might be more AI ready than anybody 'cause their data's in better shape. It, it is ironic, right? If you look at the regulated, uh, a lot of the regulated companies, um, they have had to spend so much time getting their data into an archive, getting their data into operational systems that were highly secure, highly structured, well tested, and all those things high, you know, strong entitlements around who can access the data, how that data can be accessed and consumed and used.
The other thing that a lot of these big regulated companies are really good at his data movement within the enterprise. Um, you know, they have data integration capabilities. They're always moving data from an operational system to an archive or to a governance platform.
Um, or they're, they're integrating obviously with exchanges, they're integrating with, um, clearing houses and, uh, all those other things. And so the data movement piece, which is taking data from one source and getting it to somewhere else, is something else these, these big regulated companies are actually really quite good at. Mm-hmm.
Um, as we think this through for a minute, do you believe that the volume of data may overwhelm us? Because I think a lot of folks are starting to wonder, are we gonna need new infrastructure and everything to go with that? Because we are now gonna be routinely looking at, I don't know, petabytes of data?
Well, so, um, I, the sure answer is, you know, these tools are voracious, right? They want almost as much data as you can give 'em. Um, I think there's a little bit of, of a, you've seen a little bit of a movement around being a little bit more selective in the data that you feed into these AI and analytics tools so that you're, you're a more targeted, uh, you're building more fine tuned models.
Um, and the other piece of that is you, you wanna make sure that you're bringing data that is also not just secure and trusted and, and all of those things, but, um, a little bit more selective. And so, like I said, we, we may have petabytes of data for some customers, um, but the way we're looking at this is to select sets of data that would be responsive to a potential, you know, uh, whatever agent, um, that you're building or model. Um, and instead of taking five petabytes of data and try to, you know, have that consumed, uh, it's, you know, take these te terabytes of data or hundreds of terabytes or gigs or whatever it might be, um, to, to respond to that use case, Does that also mean that things will be happening in more real time?
'cause the LLM is dynamic and maybe the art of this becomes getting the right data at the right place at the right time. Absolutely. Um, and you know, currency is one of the other things that's important.
Uh, uh, you know, if you, you look at, uh, the value of information, right? Decays over time, um, it tends to decay over time. And so there's a currency that's important in a lot of the responses that you have to be able to provide, um, and in the data you want to provide.
And so, um, even though, you know, you think of us from an archiving perspective, we have customers who take operational data that's created right now today, it comes into the archive for the re regulatory use cases and the compliance use cases. But now that data is immediately available also now to be consumed by these other tools. Um, and that creates, you know, again, you've satisfied your regulatory piece, you got that checked off, and that's a really important piece.
But now you have current data that now is also easily available to, um, AI tools. Mm-hmm. There's also, uh, a little bit of a security aspect to this, but folks are talking about, um, bad actors are stealing encrypted data and they hope to crack it someday with quantum, and then they're gonna use AI to, to run some patterns against it to identify some trends.
Is that, are people talking about this issue, or what's your take on what's going on here? So what, where we see it first, again, if you go back to a lot of, uh, uh, legacy systems that people are trying to deal with, there's a, a huge amount of, uh, legacy systems and technical debt, right? It's a, again, another large topic that enterprises are dealing with.
And when you look at those systems in particular, they actually present a lot of risks. They're, they're often not up to date. You can't keep them up to date.
It's hard to get them into your security and your control planes 'cause they're just not designed for it. Uh, and so one of the reasons you see people moving out of those systems is not just inaccessibility and legacy, you know, cost. It's the security component of that as well.
Um, so that's the first piece. Um, so then the data, you know, gets into a better governance platform or an archive like ours, and that provides a higher level of security. Um, but, you know, bad actors are out there as you point out.
Uh, and so everything you can do to try and tighten down the entitlements to that data, everything that we do work with is encrypted. Often it's double encrypted. We, we often get data that's encrypted before we get it except for the metadata that we need, obviously to govern it.
Um, and then we encrypt it again. And so we're actually, for some customers it's double encrypted. Um, now does that mean some quantum computer five years from now, you know, can crack all this stuff in the world?
Who knows? You know, that's a little bit outside my probably wheel wheelhouse, but those are the steps that we obviously take to try to maintain as much security as we can. Right.
Who's in charge of all of this these days? I mean, we saw for a while the rise of a chief data officer and then AI came along and now CIOs wanna be in charge, and then we are seeing the odd, you know, chief AI officer, um, there's no shortage of chiefs here, but who are you seeing kind of taking the lead on all this? Uh, yes, it's probably the answer, right?
Um, it's, uh, you're right. Uh, you know, it's interesting in the government, um, all the agencies now are supposed to have identified a Chief AI officer for all the different agencies now. And so, you know, where does that really sit in an organization?
It might be in the C-D-O-C-D-A-O world, it might be in the CIO world, it might be in whatever this new AI office is. Um, if you look at the investments that are being made in AI and analytics, uh, you know, you see basically the C-suite, right? Investing, you know, the, the amount of money that's pouring into this, that's a, that's at a c-suite at a board level, right?
So they've got a seat, um, at the table as well. Um, you know, you see the data management and infrastructure people playing at least this core role also in, all right, I gotta maintain huge volumes of data now in a way that can be consumed, consumed by all the stuff that people wanna use. Yeah.
We've also seen the AI community kind of get worried about the fact that they think that they've absorbed all the data they can find in a public space. So is the great untapped potential, all this enterprise data that sits behind some sort of firewall somewhere. But that ultimately is what's gonna make an AI model, um, not just perform an action, but do it in a way that's trusted.
Do it in a way that's trusted, do it in a way that's a little bit more useful and targeted for what you had, and also do it in a way that might be, you know, provide a little bit more, um, value to the organization, right? Because, you know, if, if everybody is operating off the same LLM, what's the differentiator really? Then if you're able to then take, you know, your own data and tweak your own models or, you know, build your own rags or do all the other things that, that make it unique or make it a little bit more effective for your industry, for your company, uh, for your customers, for your employees, that's the value differentiator, right?
There you go. Well, folks, you're heard to hear, hey, no matter what era it is, it always seems to come back to one thing. It's about the data.
Hey George, thanks for being on the show. Thanks Mike. All right, and back to you guys in the studio.
Hey guys, thanks for the throw. We're here with Steven Manley, he's the CTO for dva, and we're talking about zero trust in the age of ai. Steven, welcome to show.
Ah, it's great to be here. Thanks for having me. We've been talking about Zero Trust for a while now, and we've implemented it with, you know, mixed successes, a work in progress as they say.
But do you think that the rise of AI and maybe AI agents specifically is gonna really force the issue? I do. Uh, but I also think, you know, one nice thing is on the zero trust initiatives, we've always had this challenge that we're kind of retrofitting, uh, systems and architectures that weren't built for a zero trust world.
Whereas the nice thing is as we go into AI and especially agent ai, it's pretty new, so we've actually got a chance to get it right this time. Um, but, but it's really important, uh, that, that we think it through before we start. Because if you think about it, you know, we're gonna end up with hundreds, thousands, tens of thousands of agents, and they're going to be accessing data and, you know, looking at your information in, in ways that even individuals couldn't do in the past.
And so if, if you aren't going in with a plan right at the beginning, it's gonna be really hard to, again, retroactively come in and, and, and bring zero trust in afterwards. There could be, I don't know, thousands, millions of these AI agents are trying to do that retroactively would be damn near impossible. Absolutely.
And, and, and, and, and you're right, right? I mean, that, that's the cr the both the cool and the crazy thing about agents is as we've been playing with the Gentech ai, you know, each time you think, okay, there'll be a handful of agents here, by the time you're done with the implementation, you're up into the dozens. And that's just for early sort of small starter apps.
So imagine as this thing matures, uh, it it's gonna be like, you know, serverless code or, or containers or microservices. You're gonna have so many more than you expected. And, and yeah, there's, there's just gonna be no way to, to sort of bring those cat herd those cats in unless you have that plan to begin with.
If we think about that whole process, then, um, can't, aren't these richer targets essentially. I mean, I'm not just hacking into something and stealing some data. I can be taken over an entire process that this AI agent has been trained to execute, and it may as well be integrated with other processes.
And the next thing you know, I'm like running the whole company. You know, it's interesting for, for me, because you've like, like microservices, there's gonna be a lot of agents that if we're gonna be honest, if you compromise them, it won't be that big a deal, right? Imagine you've got an agent whose entire job might be, I don't know, rendering some small thing on the ui, that'll be annoying, but it wouldn't necessarily compromise you.
But there are going to be agents and, and again, I think specifically the agents that access data, those are the ones that we're really gonna have to secure. 'cause, 'cause think about it, this can go two ways, you know, one is obviously if you compromise that agent and it has access to the data, and especially say your master data things in your, your CRM like Salesforce or, or some of your critical ip, well, it could just exfiltrate that and you'd never know. Or if it wants to be even more nefarious the way you're talking about, I could simply modify or generate that data so that the rest of the agents start to act as if, well frankly, the data you fed them is correct.
How would they know otherwise? And at that point, you could make an entire large agent ecosystem go, go completely rogue because you're feeding it the data you want to feed it. So, so to me, again, not all agents are gonna be equal in terms of, of the level of security and zero trust you're gonna need to apply.
But those that are closest to your data, those are gonna be the most powerful ones. Those are the ones that you're gonna have to really keep an eye on. Have we seen a set of best practices yet for zero trust for AI agents?
Are people talking about that and what might it look like? Yeah, so, so some of the, some of the early days on this, um, you know, not, not surprisingly mirror some of what we've been doing in terms of humans or in terms of non-human actors. So things like, you know, constantly authenticating that, that, that becomes important.
That's one of the, the, the, the key zero trust principles is you should be constantly validating that this thing is who, who we think it is. Uh, the next one that, that we should be doing is, is also, again, very similar to if you live in the cloud, IAM roles or access permissions, if you're in a data center, you know, you should be creating these agents trying to minimize, you know, each of them the, the access that they have. And so, so that's another zero trust principle that we've already started to pull in.
And, and so you can see this in, in some of the, some of the tooling that people are creating. Um, so for example, going back to those data agents, uh, ensuring that I don't have an agent that has effectively root access, they can simply look at all the data that agent should authenticate the, you know, very similar to how a person should, they, it only has access to this particular set of data or these records. And so even if it got compromised, it wouldn't be able to to expand beyond that.
And then I think, uh, in, in, in terms of then the interaction with one another, we're seeing more and more being, you know, this, this, this notion that your agent has to constantly validate who it is. And then we're also seeing higher level systems being built to say, I'm monitoring your behavior to detect if, if the agent is acting in any anomalous sort of way. So a lot of what we've learned in terms of humans and also in terms of the non-human, uh, actors working with APIs, were already pulling those into best practices around how to manage your, your agent ai.
Do you think that as we go along here, um, am I gonna have to, I mean, are they passwordless solutions or are they, I don't know, do they have passwords or are there different kinds of ways of thinking about authenticating AI agents as a non-human identity that might be different than human identity? And will we have different authentication kind of schemes for each? That's a, that's a really good question and, and it's one that, uh, I know we've talked about inside of, of Druva quite a bit, right?
Because again, as we're adopting agent AI to help our customers and we protect their data, right? We protect them from cyber attacks, we protect them from, from, from all the worst things that could possibly happen. So security is first and foremost for us.
And so a lot of what we talk about is absolutely you need some sort of password or token, or you need some sort of authentication and authorization that's not gonna go away even for agents. But, you know, starting to create a, a, you know, a signature, uh, and, and again, this is, this gets back to that anomalous behavior. My agent should have a certain behavior signature, and each agent as we develop it does have a certain, you know, sort of behavior pattern that we expect from it that we associate with it.
A storage access agent is going to have a different be behavior pattern than say, a historical memory or context agent, which is gonna have a different pattern than let's say a UI generate UI generating agent. And so if you can create that profile now, I'm also then monitoring and making sure, is this agent, does it look like it's going rogue? Because even if it can authenticate and it looks like it's going rogue, I still wanna step in and stop it.
And so to your point, it's almost, it's almost like having biometrics for your agent E except it's defined by, its, its, its behavior patterns as opposed to by, say, fingerprints or, or, or, or irises or those sorts of things. So a hundred percent with you, it's gonna have to be more than just our traditional sort of token password, uh, authentication and authorization. Do you also think that, you know, we've been talking about the notion of agents being hacked, but won't the bad guys make use of AI to create what amounts to fake agents that will look and act like the agents that you think that you're working with?
And how would you know the difference? Yeah, so this is, this is, this is really to, to me, the, the, the unseen scary threat that I think a lot of organizations are just starting to wake up to now, uh, is, you know, so many software engineers today, uh, still pull code from somewhere else. And, and so, uh, in a lot of cases, this used to be fears about open source package.
There's, uh, which is why, you know, companies like Druva are constantly validating to make sure that any open source package we use is clean, is good. Uh, we, we check it more, more thoroughly than even our own code. We're gonna have to do the same with these agents.
Um, because, you know, the bad guys are going to be publishing agents, and it's gonna be very tempting for engineers to say, Ooh, that agent does what I want. Let me pull it down. For example, that agent has great interfaces into my Salesforce or my Workday, or my ServiceNow.
Instead of having to write my own, I can just pull that in. Well, okay, that could be infected. Uh, that could be, that could be malware.
And so it's gonna be really critical that, that people have the appropriate, you know, sort of secure lifecycle development processes, because if you don't have that, you'll end up infecting yourself. The bad guys won't even have to get in. They won't have to compromise you, uh, through social engineering.
You're gonna be pulling it in yourself. And so, so you're right, the bad guys are off BA making these agents. And so this is, this is where, again, we, we really remind people and validate anything you're putting into your environment and trust no one going back to the zero trust, uh, kind of principles as we pull all that together, though, um, all these AI agents, they're software and aren't they built using the same components that we use for every other piece of software?
And as such, won't they have the same vulnerabilities and dependencies that we don't understand? And so the issues that we have securing our software supply chains will be just exponentially increased. Is that fair?
I, I, I think, yeah, I think, I think what you'll find is the, the level of, of complexity in this will continue to grow, right? So, so the challenges all of us have with thousands of open source packages now become, like you said, exponentially greater as I get tens to thousands to hundreds of thousands of agents. Uh, and how am I gonna be able to monitor that?
Now, at the same time, there will be tools that are built that are gonna help try to at least maintain that, uh, that, that supply chain and, and monitor what's going on, help generate, uh, software bills and materials so that we can track everything that's in an environment. And, and it, it's gonna, that escalating arms race is going to continue between the bad guys and the good guys. Mm-hmm.
But the thing that we always remind people, uh, here at Druva is, and at some point, as awful as it's going to be, something will go wrong. Whether that's something going wrong once upon a time was, uh, a piece of hardware breaking, or it was one of your users getting socially engineered and getting phished, or now getting some bad software in your environment, it doesn't matter. Uh, it, the bad thing is gonna happen.
And so you do everything you can to try to prevent it, because you don't want to be an open door. But when that bad thing happens, you have to be ready to then recover. And if you don't have a plan for how you're going to rebuild your environment, how you're going to make sure your data's safe, how you're gonna be able to get your business up and running again, if you don't have that recovery plan, well, you know, trying to come up with it after the bad thing has happened is way harder than trying to come up with it before.
So you're right. You know, the, the, the challenges are just gonna continue escalating. You always need that safety net in place.
You always need, you know, sort of a, a, a cyber resilience, a protection and recovery plan for, for when, when the walls get breached. The other thing that I was thinking about is, what's your best advice to the security people who once again, kind of find themselves, you know, going be wary, be safe at a time when everybody and his brother is like, yay, Asian software, and then running it everywhere, and it's like, you're like the only one in the room who's kind of like, good, we should be careful. No doubt.
Yeah. So, so, so I, I, I, uh, I give, I give security teams three pieces of advice. Um, so, so the first one is, uh, frankly, you get friendly with your IT teams.
Um, because, you know, in, in cloud and agent ai especially, these are two areas that when I meet CISOs, one of the, one of the wild things they, they ask me is, oh, drew, you're protecting all our data, especially in the cloud. Could you tell me what we're running in the cloud? Because those, those, those, those, those business people who are moving a million miles an hour pulling in agent AI and running stuff in the cloud, they don't want to tell us about it because they know we're going to say, slow down, let's think this through.
And so teaming up with the IT team, specifically the backup team, just so you can get a sense of what's running, is really, really useful, because it's really hard to secure what you don't know about. So that's one is we've gotta break these silos. We've gotta team up if we're really gonna keep these environments safe.
The second piece of advice I give them is, is always, you know, you're all great. You're fabulous at working on the perimeter. You have fantastic tools, processes, people.
But again, think about what are you gonna do when the bad thing happens? Because it is just statistically it's going to happen. How are you gonna recover?
Make yourself part of that process. Make sure you know what you're gonna do when the bad thing happens. And then the third piece of advice we give them is, pick your battles.
Right? Uh, you know, like I said, not all the agent threats are gonna be the same. Not all data accesses are gonna be the same.
If you try to fight everything equally, then the organization will tune you out. So there are times where you have to say, okay, look, you know, everybody that, that, that's using AI with their OneDrive or their, their Google Drive. All right, here's some standardized tools, whether it's Microsoft copilot, Google Gemini, have at it, you know, u use these standardized tools and focus your energy again on a lot of that master data, whether it's your CRM data, your, your, your sensitive ip.
Pick your battles, because you're not gonna be able to fight everywhere every time. And if you do that, people will understand, oh, well, they're, they're, they're really focusing here for a reason, and that reason is this matters a little bit more. And they're not just being, you know, sort of the sky is falling, the sky is falling.
So, so those are my three is one, work with your IT team. Uh, two, think about how you're gonna recover when the bad thing happens. And then three, pick your battles.
Focus on the things that matter most, which is usually your master data management systems. Okay, folks, the AI agents are coming, but once again, we need a little adult supervision. Hey Steven, thanks for being on the show.
Oh, appreciate it. Thanks for the time, everybody be safe out there. All right.
And back to you guys in the studio. Get ready for an exciting 2025 as Edge AI takes center stage with companies like texa and Orbital Studios delivering groundbreaking applications, powered by high performance storage, verge io, wca, and Veeam driving innovations in virtualization, data management and data protection. The Edge is where the action is from mobile data collection, transforming core HPC applications to national labs like Los Alamos, pushing the boundaries of Edge computing.
This season of utilizing Tech will showcase how next gen AI infrastructure is setting the stage for applications far beyond today's generative AI systems. Welcome to Utilizing Tech, the podcast about emerging technology from Tech Field Day now part of the Future Group. This season of Utilizing Tech is presented by soy and focuses on AI at the Edge and other related topics.
I'm your host, Steven Foskett, president of Tech Field Day for the Futurum Group and organizer of the Tech Field Day events series. Joining me this season from Soy are two old friends and co-hosts Janice Roski. And, uh, Scott Shaley.
Welcome to the show. Uh, let's, let's start with just a quick introduction. Uh, Janice, uh, you were on our, our previous season.
Tell us a little bit about yourself. Yes, thank you, Steven. Thank you so much for having us back.
Uh, we had an amazing season last season, and, uh, we wanna do this again. Uh, we'll have a little bit of a different focus. Um, but before we dive into that, I'll reintroduce myself.
Uh, Janice Roski, uh, head of Influencer Marketing for Soy. I've actually been, uh, in the industry now for 14 years, focused on storage, so I've got some, some knowledge under my belt. But what I am really excited about in doing this season is talking to more of our ecosystem vendors and partners and, uh, you know, seeing what, what they're up to with, uh, edge and ai.
It's an ever evolving thing. You know, I mentioned I've been here 14 years, but every day is a new day, so I'm ex really excited about this season. Excellent.
Well, it's great to have you back. We enjoyed, uh, talking to you, uh, in 2024. And, um, also joining us this time around is an old friend of mine from the, from the industry as well, Mr.
Scott Shaley. Scott, uh, tell us a little bit about yourself. Hey, Steven.
It's good to be back on camera with you again. Uh, so I've been doing this a little bit longer than Janice, and I won't say how many years 'cause it's starting to sound like too many. Uh, right now, I'm, I'm focused on what we'd call evangelism.
My goal in life right now is to help produce, uh, content and valuable added information related to how solid is helping, uh, our customers in the industry grow. So it's not necessarily just about revenue, it's about making sure people know how to use the technology that we have. And that's kind of a focus for me now, but been excited.
Uh, as you mentioned, we've been friends. I think 2011 is when we officially kicked off this relationship, so it's been a few years. Absolutely.
And, um, I'm so happy to see you at Solid ime. I'm so happy to get you involved in some stuff. Uh, you know, Scott, you, you've also done some, some other field-based stuff with us and, and, and, um, and, and join me as well on the Gestalt rundown.
So, absolutely, it's really neat to, to have you here. Um, I am Steven Foskett, as I mentioned, I'm the organizer of the Tech Field Day series. I'm also specifically focused on Edge and AI Field Day.
And wouldn't you know it, that's what we're gonna talk about here. So this is a topic that has come up repeatedly at Edge Field Day. You know, ai, the importance of AI at the edge and at AI Field Day, the importance of the edge for AI and the, the growing aspect of, uh, AI becoming, and specifically AI applications and AI inferencing becoming increasingly important at the edge.
We have talked about this on previous episodes of utilizing a, utilizing tech focused on ai. Um, we heard about it from companies presenting at AI Field Day. Essentially, uh, once all the training and, and all that sort of backroom stuff is done, all of these applications are gonna be deployed at the edge, and that results in special requirements for Edge servers in order to meet this need.
Now, I myself am doing this. I actually have, um, uh, AI inferencing running on a go Google Coral, TPU, on an Intel nook at an edge location as an experiment myself. Um, it's really cool to see what you can do with these chips, but it has driven home the importance of having, uh, high performance storage, uh, high performance, uh, networking, uh, you know, the kind of bandwidth that, that that's happening.
All of this stuff is, is really being rolled out. And that, I think is what, what is so exciting about this season, because SOY is a very partner centric company. It's a company that has lots of important, uh, basically friends in the industry that all need what you got, which is, you know, high performance storage layer that can go with the rest of the application that they're building, whether it's a storage company or a completely different company.
And that's, I think, what we're gonna look at this, uh, this season on utilizing tech for utilizing AI at the edge. So Janice, what are the main, um, edge applications and edge use cases that you are concerned about and that are, are demanding the kind of performance that you can bring? Yeah, I think, you know, if you take a look at it, there's so many things you could go after, right?
So many different verticals. Um, but I think where we're seeing some of the largest opportunity in, in an area that I'm really passionate about is healthcare, right? It's, it's AI is revolutionizing healthcare and specifically edge computing, where you're getting those boxes closer to the physician and the patient being able to collect that data instantly and feed that data back to the doctor and not have to wait, you know, two to three weeks for your results.
So that's one of 'em. Um, I think another area we're seeing, um, innovation is, if, you know, of course in the HPC space, right? When you think about high performance computing, you know, looking at the, uh, Earth's crust, if you will, through, you know, the, the middle of the Pacific Ocean, putting those boxes on large vessels like a ship, right?
And being able to collect that data instantaneously, similar to the, you know, hospital organizations, right? I think is another big one for us. Um, and, you know, it wouldn't be smart of us if we weren't going after, say, like financial services, right?
The FSI market is ripe for the edge, as well as, um, we have a whole team dedicated to this is even, um, automotive, right? And we do have some really good examples from, you know, the past few years where we're seeing organizations like internet, right? Um, collecting data at the edge to train their cars to be more efficient and safer on the road.
Um, we have some also with some bigger deals, right? With some other, uh, automakers that I, I can't necessarily name here, um, but he's a very well known, uh, individual, if you will, and you probably drive, some of you guys might be driving their cars. Um, uh, but those are just a few examples that we see.
And, and sure there's more. Um, and some of the solutions we're building are, are really dedicated to some of those examples. Yeah, I mean, it's, it's interesting to your point about, you know, the, the exploration of the edge.
And, and one of the things I find most interesting that look forward to participating in this, uh, this series on is what does that really mean? Uh, like the edges, what, there are so many different definitions by all the different people near edge, far edge endpoint, whatever the case may be. And, and the markets continue to evolve, right?
Uh, there's even things like the energy market, and we start talking about the recent issues that happened down here in or down in la you know, with the, uh, fires that took place in January. There's always this opportunity for AI at the edge to solve even greater problems in unique environments like the energy space, and there's opportunities for stuff like that to occur as well. So, um, overall, the, the idea that putting storage closer to where you generate the data, right?
Because one of the biggest things about AI is it needs data. And the data currently today is all about memory feeding, uh, some form of a pu an xp, you know, GPU, ccp, whatnot. But really that data has to sit somewhere too.
And that's really the, the key cornerstone of where I look at where soy comes into play, whether it's the high performance, the high capacity, whatever you look at, that's where we're gonna see a lot of, uh, effort put into the edge with AI and or storage as we, uh, progress through 2025. And I think, you know, I'll add to that, Scott, you know, some of the examples, you know, it's all about, you know, where are you gonna put that storage and all about the data, but also about the software, right? And, and how does all of this work, you know, more effectively at the edge.
And I'm excited about this series because we do have a couple of partners we're gonna bring on that can really speak to that, you know, how are they, how is the hardware being optimized with the software to really take advantage of, of the solution at the edge? And, you know, that is texa. Um, TEXA runs some pretty cool workloads in media and entertainment.
I, I don't wanna misspeak on this, but I think they have, and actually I can say this, they have done some work with the Las Vegas sphere and, you know, providing that really rich media entertainment experience. Um, so that's a really good edge solution. And then we also have some work that we're doing, um, with a visual special effects studio in Los Angeles, um, working together with Dell and an organization called Orbital Studios.
And, uh, ultimately what they're doing is, you know, how can we do these special effects faster, more in a more collaborative fashion? Um, and they're deploying, you know, uh, a unique edge solution to do that with both, um, solid and doubt. So hopefully we'll be able to bring those guys on and, and get the, the download on that.
Yeah, to it, it is interesting when, when we did our Edge Field Day events and, and when we've done edge as a topic here on utilizing tech, the Scott's question does come up. And I think that the examples that you just gave Janice, are really illustrative of the fact that Edge really, you know, it's defined more by what it's not than by what it is. Um, you know, what we said at Edge Field Day recently was essentially Edge is everything that's not data center and not cloud.
Um, in other words, it's, it's, it's things that are not confined. And whether that is, as you mentioned, uh, fighting fires or collecting geo data in the field, or deploying amazing graphics to the inside of a crazy, uh, landmark in, in Las Vegas, or, you know, working in movie studios, there's so many aspects to this, and there are so many companies that are doing just incredible things to, as Scott said, move applications, move storage, move processing closer to the source of the data. And that was something that came up actually way back in season one of utilizing tech where one of our guests suggested, and it was really kind of a, a, a mind bending moment for me, where one of our guests said, you know, it's not that we're collecting less data, it's that processing closer to the data collection means that we can connect, collect more data, lots more data, and that transforms the applications that can be done with that data.
So essentially, if you're limited in terms of, of collection to whatever you can ship back to the core, then that's all the processing you can do. But if you're not limited anymore, if you can collect an incredible amount, whether it's a high volume or a high throughput of data, then you can really open the doors to new applications. And if you can process that data in place as well, which increasingly we're seeing happening, it, it, it really is transformative in a way that I think people don't recognize because you think, oh, storage, great, we're gonna store more data.
You know, but that data would be lost. It would never have been created if, if it wasn't for the ability to store it at the edge. And I think that that's really what comes out of some of these things and, and why so many companies are looking at trying to figure out how to deploy AI and advanced data processing applications at the edge.
Is that, is that what you're seeing as well? Absolutely. I mean, I, I totally agree with you on that.
I, it's one of those things also that you have to think about. There's a, there's a beautiful transportation issue that we're trying to deal with too. And you think about, for example, in Ohio, the, the freeways are four lanes and still have some traffic, but maybe you can get around a little easier and things like that, because I know you're near and dear to Ohio, but down here in LA I've got 16 lanes of freeway and I can still only go five miles an hour.
And that's literally a direct representation of trying to move the data we're generate in an edge to a course. So not even do we get the data there, how long does it take to get there? And there's, you know, partnerships we have with like Los Alamos National Labs that will be able to talk about how they're even looking at how the massive amounts of data they generate in microseconds and nanoseconds can be captured and managed appropriately.
And that's, you know, an epitome of being able to track down and, and manage data, whether it be in a core high performance system or all the way out at an edge. So lots of opportunity from that perspective. To your point, So we, we are gonna be talking a lot about AI because, you know, it's 2025, everything's about ai.
Um, but that's not really the end of the discussion either. AI and, and especially if we wanna zoom in on, on really like practical applications, uh, generative ai, large language models, that's not the whole world. It's not even the whole world of ai.
And my position is that in 2025, we are going to see very different types of AI models being developed because we've proven now that we can create convincing text input, output text processing with large language models. We've proven that we can do some incredible things with computer vision and sensors using ai. The door is open, and now everyone is gonna be looking at that and thinking, okay, if it's good for text and if it's good for cameras, then what else can I do with it?
If, if it's good at generating text, if it's good at generating data from, uh, unstructured, arbitrary data, what else can I do with it? Building that kind of infrastructure, I think is the, is what a lot of these companies in the industry are working on. They're trying to figure out ways of basically making a platform that makes things possible and that gives people new ideas.
Um, what elements of that platform are, um, requiring this kind of high performance storage? And what new ideas do you think are gonna come on the, the, the, the based on the availability of that infrastructure at the edge? You know, I think when you look at, uh, you know, text, audio, and then video, right?
Thinking about it in terms of as, so it's, you know, small, medium, large, right? I think just the parameters around those things are gonna beg for new types of innovation and, uh, from the software and, and how does all this work? I, I also think that to, in, in 2025, people are like, okay, we 2024 deployed this.
We, you know, we tested it, we hired some engineers, we tried to make this AI thing work. We're just figuring it out. Prior to 2024 was 2023, it was like when the big boom started to happen, everyone was like a frenzy around it.
But I think 2025 is really about where is the value? What value am I seeing? Uh, I know how to deploy this, but where can I really get the value and drive business?
And I think that's where we're gonna start to see organizations come up and develop. To your point, Steven, um, new ways of looking at this and new and new applications. Well, I, I think when you look at it from an infrastructure point of view, right?
And we start looking as we go further out to the edge, uh, the idea that, you know, you've got these, uh, ability to generate information and do something with it, whether you call it AI or data transformation, data prep, pick your, your acronym or, or phrase for it. The architecture of those systems is unique, right? You can't put a rack anywhere you want.
If it, even if you could, is it durable enough? Can you get the power to it? For example, there's a big story about one of the large data centers going up in the Midwest and they've got this grand plan to make this massive facility, but they've only been able to power a quarter of it, and they have nose line of sight to powering up the other three quarters.
Think about that kinda scale problem at an edge environment where I don't even get a half rack or I get, you know, to your point, a nook or something similar is all I've gotta available to work with. So we've gotta start realizing that as we push this further into the edge, these architectures and these footprints are gonna change drastically. And being able to adapt to what's necessary for those is kind of key.
So gathering that data quickly and storing a large amount of it so you can funnel it off nice and slow is imperative as much as anything else. And then doing things like data protection and how you get there. So we have some plans to talk about, you know, data recovery and data protection with some partners as well.
So there's great opportunities to see, you know, the edge infrastructure evolved where it can get to, and I hate to necessarily throw out, you know, the, the, uh, hype cycle if you will. But, you know, there's this whole thing, we've spent a ton of money now it's like, okay, now we gotta figure this out for real, and how can we sustain it long term? And I think that's where you're gonna see a little bit of an inflection point towards the end of 25 around that kinda stuff.
And I'll say a little spoiler alert here, so I can't get too deep into it, right? 'cause I'm not sure if the timing will be right when we, you know, um, really push things out. But we do have an environment that we're setting up, which is gonna allow people to come in and test, right?
Allow organizations and some of our ecosystem partners and customers and, and even some that aren't on our list yet to come in and, uh, test some of their workloads with, um, some of our SSDs in the, in a lab, in a remote lab. Um, so we haven't really fully pushed this out the gate, but, you know, stay tuned. 'cause as we start rolling out these episodes, uh, we may be, we may be talking about how some of these partners are, are thinking about tapping into this new lab.
Uh, and you know, Scott, there's a couple of things you said. It was like, okay, you're right. It's, it's about being able to scale.
And we didn't talk about this yet, but we're gonna continue to build on our 1 22, right? We launched our 1 22, there'll be something bigger coming out in the near, very near future. You have to do the math.
Everyone's like, okay, that's around the 2 56 range. 1 22 refers to, you're not gonna believe this if you're not familiar, terabytes of storage on one SSD. Yep.
That is a big number. Still shocks me, um, still shocks me to this day. And, uh, it's, it's not stopping, right?
And I think there'll also be other types of innovation where it's not just about the capacity. Some of the things Scott was alluding to was, you know, software's gonna be there at the edge, the, the capacity of the drive, but hey, there's gonna be a world where we're maybe able to do a little more compute at the edge than we, than we used to. Uh, so can't say much more about that, but there's some new innovation coming down, um, from soy and the industry.
Yeah, last season we talked about the, the 60 terabyte, uh, breakthrough and, um, what that enabled. And the fact that it's not just about terabytes either. It's about delivering that with performance and with reliability.
Uh, anyone could throw together. Uh, well, I don't know about a 60 terabyte ess a pretty big SSD, but it's awful hard to put one together that's actually enterprise reliable in, in adverse conditions, because of course, we've gotta think about, you know, at the edge, you've got heating concerns, you've got vibration concerns, you've got all sorts of things that might come up. You know, these things have to be built because at the end of the day, if you don't have the data, then you don't have ever have anything.
It's like, you know, storage is the foundation for all the applications on top of it, and data management. And that's another thing you mentioned there, scalability. We've gotta think about elements of the stack.
Like, you know, how are these things, uh, scaled? How is data moved? How is data presented to applications?
And so the, you know, one of the companies that we're talking about bringing on here would be wca, which of course is a leader in, um, scaling storage and performance, all the way from well storage devices up to actually truly presenting data to applications, which I think is in an incredible move for our whole storage industry. And, uh, you know, you mentioned data protection. Well, we're talking about Veeam, right?
I mean, they are an incredible company as well. Um, who have I I think they're the biggest data protection company in the, in the, in the planet right now, aren't they? I think So.
I think that's where they're headed. Yes, absolutely. So, So that's pretty cool.
And then of course, you know, you've got other, um, alternative things that we've gotta think about with the platform as well, like, like virtualization, and that whole market has really been shaken up with Broadcom purchasing VMware. Um, we've been talking a lot about that, uh, at at Edge Field Day. But, uh, you know, what are you seeing in terms of, of building platforms, these building blocks?
Yeah, I mean, uh, you mentioned all the cloud examples, Steven, right? Um, and we'd be remiss if we didn't talk about that. But, you know, um, organizations like ver io who are just coming in and, um, I wouldn't say they're just, you know, taking away market share from, from VMware, but that's, it's still such a growing market that there's room, right?
Um, for the more nimble companies to kind of come in and, um, make some, make it a little more simple, right? So it'll be interesting to hear, um, how Verge differentiates themselves, um, in this ever evolving market, um, versus say, you know, a vsan solution. Um, you know, likewise, there are a couple of others that aren't, you know, on our list that we haven't talked about.
But, um, organizations like, um, you know, core Weave. I mean, core Weave is a really good example of, you know, not just a, a cloud provider, right? But you know, somebody who's, you know, really, uh, done an effective job with taking advantage of the, you know, GPUs and a lot of those GPUs that people can't even get their hands on, right?
Um, but they've also leaned into storage as well, and, and, you know, that's been a very important ingredient to their success and their solution. Yeah. And I think kind of leaning back to the virtualization piece of it and things like that, another aspect of it where, um, soy sees the need when you talk about something like a 1 22 terabyte dry, right?
Massive capacity, but how do I split it up or shared effectively? And so we actually participate quite heavily in a lot of the standards works that are being done around that. You know, kind of shifting gears a little bit from customer partnerships, but industry, industry driving things like NVME or NVM Express and SNA and those other organizations, OCP, we, we help put things in those platforms and those projects in those specs revs, whatever you wanna call them, that help people be able to utilize the technology more to allow us to spread the wealth virtualize more, do this, do that with the technology, which are things you just simply can't do with other forms of storage.
I have to say, public service announcement once again, that Scott Shaley sits on a lot of the boards of those organizations. So, um, we're really lucky to have you, Scott, for that reason. But you do have a, a wealth of knowledge there.
So just so the audience knows, if they have questions, they can go to you. Absolutely. And, and, uh, you know, Scott, that's I think one of the, the coolest things as well about having a company like Soy that is not, you know, I don't know, you know, you basically, it's a friendly company to the whole industry.
It really helps because it means that you can participate very openly in activities like that, that, that help us all. Because ultimately, I guess that's really what's happening here is, is, you know, the previous years for Edge and for AI have been about building foundations and building foundational technologies, and now we're seeing what happens when those things are brought together and when they're put into production. And that is what we're gonna see at AI Field Day.
That's what we're gonna see at Cloud Field Day, and that's what we're gonna hear about on, uh, on utilizing tech this season. Um, I guess let's wrap up this e preview episode of, uh, of this season of utilizing Tech. Um, what's one thing that you're really excited to be able to share with the audience this year?
Maybe it's a guest, maybe it's a company, maybe it's a solution. Maybe it's just an idea. What's one thing that you think is gonna be really, uh, you know, gonna knock their socks off this season of, of utilizing tech?
Uh, Scott, I'm gonna pick on you and, and make you go first. You know, um, I see from that perspective, to your point, is the ability to educate people on what the edge really is and what it means to deploy these types of technologies at the edge. There's been so much emphasis on Core, core, core and what these massive data centers are gonna look like.
People need some help realizing what it means to be at the edge. And I, I look forward to that. And one of my, um, favorite things is, you know, looking at presentations I get to do down the road, are you a leming?
Are you gonna fall off the edge of the ledge? You know, the ledge of the edge. And that's part of the key of what I think is gonna be fun this season, is just helping people realize that there's a, there's a mind shift that needs to actually take place here.
Yeah. Well said, Scott. Um, I don't know, I can't think I can one up that one, but, uh, at all, but I agree, I agree.
I think one of the most exciting things that we're gonna do this year as soy is do this episode series, right? Be a part of utilizing tech, uh, for the Edge and AI, and give, uh, our partners and our customers and ecosystem vendors a voice and an opportunity to do so in a way that isn't just high level, but really deep diving into the, you know, technical details. And that's what we really appreciate, um, about you, Steven, and, and the work you do and, and your team.
So I'm, I'm really excited, honestly, about the opportunity to bring our partners to the, you know, forefront and get a chance to work with you guys to, to get those messages out. Well, it's, it's gonna be great. Um, I can't wait to bring this to everyone.
Um, if you are excited by some of these things as well, you might wanna listen back, uh, the previous season of utilizing Tech, we talked to a lot of similar companies, uh, you know, we had a lot of similar conversations and, um, really heard from a diverse, uh, platform of companies that are doing incredible things with storage. Uh, we're gonna hear about that again this year, um, and this season, uh, we'll bring you a new episode every Monday, uh, starting now. So please do, uh, tune in, subscribe, enjoy.
And, uh, I hope that, uh, each of these episodes is interesting and exciting. So, uh, Janice and Scott, thank you so much for joining me today. Um, really looking forward to this, uh, recordings of these episodes.
Really looking forward to hearing what the audience has to say. Before we go, um, please, uh, let us know again, who you are and where can we connect with you, where can we continue this conversation? Uh, let's start with you, Janice.
Sure. Uh, so again, Janice Naroski and I can be found on LinkedIn, so please feel free to just reach out. com, uh, slash ai, and you'll see some really interesting pieces there.
And, um, happy to circle back with any questions you have. Thank you. And I'm Scott Shaley, uh, also on LinkedIn.
Uh, pretty easy to find me there. com/ai. And as for me, uh, Steven FoST, you'll catch me on the socials at S FoST, uh, pretty much everywhere.
You'll also see me, uh, most Tuesdays on the Techron Gang. Most Wednesdays on the Gestalt it rundown, and of course, uh, right here on the Utilizing Tech podcast on Mondays. Thank you very much for listening to this episode, this first episode of a new season of Utilizing Tech.
You'll find this podcast in your favorite podcast applications, as well as on YouTube if you wanna see our smiling faces. If you enjoyed this discussion, please give us a rating, give us a nice review. We would love to hear from you.
This podcast was brought to you by Soy and Partnership with Tech Field Day of, uh, part of the RUM Group. com, or find us on X Twitter, uh, mask it on, and hey, maybe Blue Sky at Utilizing Tech. Thanks for listening, and we will catch you next week.