Techstrong TV June 9, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey everybody. Happy Monday. AI Agents Rule.
You're watching Text Drum. Hey folks, welcome back and once again, happy Monday. We're talking about some of our favorite topics, DevOps and security.
I wanna introduce our gang members for the day. We'll start with Tracy Reagan, who is, um, the most senior member of the team these days. Tracy, how you doing?
I'm doing fabulous. How are you doing today? Actually, I'm doing really well 'cause we finally don't have rain in New Mexico, which is a weird thing to complain about.
So I might get outside today. All right, well that's awesome. Um, it's a gorgeous 80 degrees here in New York.
Maybe, probably won't get much higher than that, and that's probably the best we'll ever expect Jack Gold. How are you doing? I'm doing well.
And Tracy, you can have some of our rain. We're getting lots today. We have had so much rain for New Mexico.
It's just weird. All right, all Jack Gold Getting dge today with thunderstorms. It's not gonna be fun.
All right, Jack, go. I forget where you are. I'm in the Boston area.
All right, well, uh, I'm just down south of New York, so hopefully that all just went around us. 'cause you know, that seems to happen a lot. We duck and you get hit.
All right, and then finally, Jack Poller. Good to see you again. Jack.
How are you? Uh, doing pretty Good. Good To see you again.
I am actually currently at the Universe Conference in Las Vegas. So, uh, I'm over here in the very hot weather. You know, it's, uh, gonna be 95 to hundred here, so I'm not going outside today.
All right. I don't, I don't think I've been in Las Vegas in months and I'm trying to keep it that way, but I know that record will come to an end sooner than later. Hey guys, let's just jump in here.
io is talking about how they built an observability platform that is designed from the ground up for AI agents. First. Doesn't mean humans won't use it, but it's an interesting premise.
And there's also a startup called, uh, age annuity that is says that we need cloud infrastructure that is designed for AI agents. And both have the same fundamental premise is that the scale at which AI agents are gonna be using infrastructure is much greater than anything humans have done so far. And so therefore, just about everything we have is gonna break.
Tracy, what's your thought on this? Are AI agents suddenly the primary users and we're kind of secondary, uh, supervisors? Uh, I would hope so, to be honest.
Um, this is a perfect application in terms of, in my world, in the DevOps world, uh, for ai. Uh, you know, we've had these observability tools, which have been super, super useful. We need them.
We need to understand transactions. We ha we have to have this data. But the problem is, is that there is so much of it now that it's hard for a human to do everything.
It's hard for a human to address everything, and systems need to be more self-healing. So if we have AI agents being the primary customer of this observability, then we can take it to the next step, which is, okay, we know we have a problem now what do we do Now? I think that there will be a, a bit of a pushback on this, to be honest, because I don't know if the trust in AI is there yet in order to really create these, uh, you know, make, make the observability data actionable.
Uh, I see this in, um, you know, software de bloating. I've been having conversations with people about software de bloating and auto remediation of, uh, DevOps scripts. And this kind of fits into that area where we're using AI in a way that de that developers who have been the, and operations people, DevOps engineers, platform engineers who have been the controllers and making the decisions, we're handing that off to an AI agent and letting the a agent make the decision.
So we will have to change from a cultural standpoint to have trust in these types of systems, but I don't know if we have, uh, another option because these systems are gonna be so big. Uh, we have so many things happening in so many places. We have AI infrastructure, we have Kubernetes.
We will need better monitoring, better observability, but we will need actionable observability and we'll need something to do that action for us. So it's an evolution of this space. Uh, it doesn't surprise me.
com, it doesn't surprise me where this is going because humans can't do it all. It's, it's essential. Mm, Jack gold.
Are we just gonna have to reinvent all of it to accommodate these AI agents? That's a great question. And, and it depends on who you talk to.
Some people will say, yes, I happen to think not. I think it'll be more of a modification. Uh, one of the problems, and, and Tracy this gets to your point, um, is do we trust AI and agentic AI to do the right thing for us all the time?
I think there's still going to be a need for IT folks as overseers, maybe not having to delve down really deep into the, into fine tuning stuff, but I don't think we get to a point anytime in the near future where AI just takes over and we don't need IT folks anymore. So it's really, in my opinion, AI and I, I, I've used this term often in the past. I look at AI as assisted intelligence rather than artificial intelligence.
It's an an advantage for us to use to make us more efficient, but not necessarily to replace us in, in everything we do, Jack Poller. And what's your level of comfort with all this, especially from a security mindset? Uh, I'm actually getting more and more comfortable because I think we're now operating in a scope and scale that humans can't possibly operate at.
Um, and we've already done this. If you think about intent-based configuration, we've already gone from humans at the keyboard logging into each and every individual component in an IT infrastructure to simply say, this is how I want the ID infrastructure to operate, and then having automation go and do it for us. And we've, you know, that's, that's really changed how we can do things.
And that means, rather than a human managing, you know, 10 to hundreds of computers, we've gone to, you know, single humans managing thousands to millions of computers. Uh, you know, when you are a hyperscaler Google or you know, AWS or Microsoft, you can't possibly do these things manually. Uh, nor can you do the observability manually.
So you need tools and automations to do this. And I think what we're doing is maybe conflating automation with artificial intelligence. And, you know, uh, you know, I think Jack Gold's sort of on the right frame of mind is not really artificial intelligence as much as augmented, uh, automation and augmented intelligence.
And that's the only way that we can continue to operate and grow at scale. I guess I wonder how smart we think these things are gonna be. And right now, even some people will tell you that the reasoning capabilities is anywhere from that of a 5-year-old to maybe an intern.
So Tracy, how smart will smart get and how fast? Oh, that's a, that's a, that's a million dollar question or a billion dollar question these days, right? I think it has to do with how much data we have, what does the data look like that we're basing these models on?
How are we training these models? Uh, and I, you know, when it comes to DevOps, I question a lot of it because I don't see a lot of, uh, consolidated data that we can, uh, build these models on. But in this particular, for this particular use case, uh, I don't think you have to have, you know, a million examples.
Probably a hundred thousand is gonna do fine because when it, when it comes to configuring and fixing, um, infrastructure, there are less, there's less options. You have configuration data that you need to, to tweak. And, you know, like even like Kubernetes, it does its own amount of self-healing already.
So we're already used to that. I think the real, the real problem area is going to be in the agents themselves. I am not a fan of agents because I understand how hard they can be to manage.
And when I say manage, I mean all the way from the version that you're using the drift across the agents. Um, we are starting to see AI SBOs that include the version of the LLM that they're using. So we, we'll have to do some additional work to make this happen.
So we're not gonna be managing the data from the, you know, the observability will be able to take care of itself. I think we're gonna have to spend a more, more time making sure that the agents that we del that we're delivering out there, um, are repeatable, they're consistent, and we understand what, uh, what what they're based off of. So that's why I think a IS bombs are gonna become pretty important in these environments.
But even that data we have to do something with, so don't just generate it. We have to start consuming it and have ins, we have to have insights, not just, you know, there's two different things. There's observability and there's visibility.
I, I, I like to separate them. I observability is watching what's happening out there. Visibility is understanding what you put out there that's doing the work.
That is where I believe we're gonna have the most problems because we have the, we don't have a whole lot of tooling around it. And Tracy, one other thing that you said is that, uh, you talked about, uh, the ability repeatability. And I think one of the things that's very important in, uh, AI agent work is understanding that LLMs are designed to be non-deterministic.
And in an environment where you're using them to make decisions about configuration and operations, you want repeatable answers. And therefore, the hard work of the agent is taking a non-deterministic answer from an LLM and making it a deterministic decision. So you always get the same types of decisions, and that's the part, you know, from a security or from a configuration point of view, that's the part that's worrying me, not the fact that it's there.
And there's another piece to it, I think as well that Tracy and, and Jack both brought up. And that is that once you have an agent, how do you know it's doing the right thing for you? And how do you know that it's talking to another agent in the right form?
That, that, that then is passing on perhaps bad information or insecure information, Jack, to your point, from a security perspective. So it's really, it, it becomes much more complex when you're dealing with IT staff. If I don't understand anything, I can go next door and talk to Tracy, or I can talk to Jack and say, you know, I, this is what I think is happening.
Can you back me up? Can you gimme some more additional information? How do we achieve that same kind of capability with AI agents?
Or do we depend on an AI agent is being exclusive and, and whatever that AI agent tells us to do, we do. Mm-hmm. Um, There's a lot to unpack there, folks, but the first thing is, theoretically, I think you're supposed to have AI agents that are monitoring the AI agents and therefore checking on what their work is and, um, governing them.
And who knows, that may or may not work. But the thing that that brings to mind, Tracy, is, um, AI is not cheap. And so at what point am I gonna be using so much compute and resources to automate something in a way that might be less expensive to do using a human Well, just like all technology, it's gonna get cheaper.
It always gets cheaper. Um, and we're at the, the Arterius community, we're doing some work with the Gentech and building a model to, we're not building a model, let me re rephrase that. We're building an MCP server to, uh, do some work in updating, um, DevOps files for, uh, dependency pinning.
And, you know, we thought it was gonna be super expensive, and right now we're up to like $5 a month, something of, of that sort. Now that doesn't, doesn't mean we don't have a ton of data we're putting through it, but I do believe with some of the new technology that's coming out, the, um, you know, the AI PCs that we're gonna have, that it will get cheaper. It will, it will get cheaper and cheaper as we, as we move down this road.
Hmm. Um, Jack, to your point, or not Jack Poller, but Jack Gold to Jack Poll's point, um, so a lot of what we expect is deterministic outcomes. We think that we want it to be managed the same way every time because we need the outcome to be consistent.
And AI agents and gen AI seems to do things differently every time out. So how will we kind of marry up this probabilistic model with the, the deterministic workflows that it kind of lives and dies by? Sorry, which Jack?
Mike. Okay. Sorry.
Um, too many jacks here. Um, so it's going to be a very interesting challenge. I think in the early days, we're going to see a lot of oversight.
Once these AI agents get put in place, we're gonna see a lot of human oversight, uh, until we get much more comfortable with the fact that these agents are getting better, they're getting tweaked by humans to, to be more consistent, hopefully, and they're doing the right thing. I think until we get to that point, uh, we're going to look at agents as, you know, it's, it's, uh, you know, flip a, flip a card or, you know, roll some dice to see what the solution's going to be, because it could be very inconsistent. And I think for most organizations having inconsistency, you know, you talk about cost of ai, the cost of inconsistency, the cost of instability is much greater than we we would ever see for the cost of deploying AI systems.
It just messes up the entire organization. So I think what we really need to look at early, and especially early stages, is a human agent looking over what an agent is doing until we feel comfortable that those agents are actually doing the right thing. But we've already had examples this past week of, of ai, uh, basically blackmailing people trying to shut it down, right?
Um, how do we know something similar isn't going to happen? Or what if an AI agent gets taken over by bad actors and gets inserted into our organization and starts shutting down all our systems? So it's not, it's not a, a trivial issue switching over from humans to, uh, agents to, to run our environment.
Mm-hmm. Jack, Jack Poller. Um, I'm kind of worry about the following scenario, right?
Will there be too many agents popping up all the time that will ask me what to do? It'll be like, you know, a bad version of clippy from Microsoft? Or am I going to like trust the, uh, at some point, do I develop enough trust in these AI agents to where I'm gonna let them run autonomously?
Or how do I strike a balance between those two extremes? Well, I think the big worry is when clippy starts to look like the Terminator, but, um, there Are processes I want to terminate, just Yeah, absolutely. I think, um, I worry, uh, less about the, the security of, uh, an agent, a bad agent, versus the fact that it's really just opening up another attack surface.
It's yet another area where we can be attacked and exposes, you know, uh, it gives more foothold for the bad actors. And there is just, there are just so many ways that we can manipulate AI agents, uh, in, to do things in weird ways. So with model poisoning or with bad inputs, and, uh, that it is a security issue.
Um, but I think until we get it to do the actual working correctly, the determinism problem solved, um, it's less of a security issue than the fact that mo we have, you know, open S3 buckets by default. And a lot of our infrastructure is so insecure that why bother attacking the AI agent when we can attack all the other vulnerabilities that exist that are easy to get to first. Um, so it's, it's gonna be a second order consideration for the attackers until we fix our cybersecurity hygiene problems.
So that exists today, Right? So you're saying things can't get any worse than they already are, so what the, what the heck? And let's not, let's not pretend that humans are perfect, right?
I mean, most of the pro, most of the problems that we find is something that we have caused ourselves, you know, so these are, some of these, some of these configurations are so ob, you know, they're so obscure that you don't necessarily know what you should set them at. So, you know, I, you know, there's something about having it, you know, and we, you know, I come from a, you know, a background of rule-based, uh, compile, uh, managers and in order, and one of the reasons why we wanted it to be rules based is because all the stupid compile flags that people were using that were breaking things in production. So it's kind of similar.
It's similar. So I think this is a really good application for it. I really do.
For, for AI and for AI to be more agentic in DevOps, There's an entire Cybersecurity category of, uh, posture management and configuration management dedicated to checking that your configurations match your security policies. And so I think, you know, if we start doing AI based, uh, observability and management, then we're gonna have another security category to validate that what the AI is doing is doing correctly. Hmm.
Tracy, there's this emerging debate about whether or not we're gonna just add AI to our existing platforms, or when we need these kind of more AI agent native platforms that will replace the existing platforms. I mean, do you think we're looking at a wholesale migration, or is this gonna be more of a, you know, an evolution of platforms and over time we'll see what happens? I think companies will, most organizations will take it more of a, as an evolution.
I think that we've been burned in the past, uh, from, uh, you know, a technical debt perspective in trying to do this wholesale. So I think it will be an evolution, but I think there will be bumps in the road where we have to make big changes. I don't think it's going to be completely an evolution, um, but I think that one of the first steps is having those a IPCs brought into, you know, where all your developers are sitting.
All right, Jack, go. Last question. A lot seems to be riding on MCP to integrate all these AI agents and well, other folks are talking about the agent to agent protocol to integrate these things.
Um, how much of that is practical at this point? And how much of that is kind of wishful thinking for orchestration? But we get a long way to go?
Well, this is an evolutionary process, right? Anytime we talk about these kinds of standards, it takes a while for all of them, for them to all settle down and for everyone to adopt them and make sure that your MCP is the same as my MCP is the same as Tracy's or Jack Poll's. Uh, and so I think it's probably going to be a six to 12 month effort to get this all stabilized.
But in the end, if we don't have some sort of real interface capability that we'd be able for agents to have agents talk to each other and interact with each other, all of this just goes down the tubes. You, you can't make it happen. So MCP is, is very important, you know, whether ultimately turns into something else, it's possible.
But as the industry starts to adopt this, it becomes a way for, you know, it's, it's the lingua f Frank of, of ai. And if we don't have that, we're in real trouble. There you have it.
Hey folks, I think we're on the AI agent journey, whether we like it or not. So the only question now is to what degree we're gonna manage these things and, um, and how much do we trust them? We'll be back in a minute.
Hey folks, we're back with our next block, and it's about a company that was based in India who said that they were an AI company and they had some neural network or building software, and then it turned out to be, well, just tons and tons of Indian engineers working on projects that had been sent over. Um, they were back mi, Microsoft at some point. So it's kind of embarrassing some folks, but they have now filed for bankruptcy Jack goal.
Is this gonna be an issue going forward? Will a lot of companies kind of say their ai, but not really ai? Uh, absolutely.
Mike. Look, there's a lot to impact here. Number one is from the VC perspective, the amount of money that's available out there to invest in ai.
If I put a shingle out on my front door tomorrow that said I'm an AI company, I'd probably be able to go out and get a couple of billion dollars. It's just that kind of money flowing into the marketplace. So anyone who can put together a, a, a, a viable, i, I wouldn't even say viable, but something that looks viable, a marketing plan or, or business plan is gonna go get money.
So that's what happened here. And, and, and the, the company fooled a whole bunch of really big investors. As you said, Microsoft and others are in that space.
So that's number one. Number two is how do we know that an AI company is really generating stuff with ai? How do we know if we're not back there?
You know, if we were to design, let's, like, let's take another example. If we were to design a, if you were, you know, Mike Dard, uh, AI company, and you needed a new chip, you'd have your engineers at, you know, wherever the design company is, cadence and TSMC and everyone else, making sure that everything looked good and everything worked before you invested, you know, $2 billion in that space, why weren't people looking at what this company was doing and where that code was actually coming from, uh, when they were investing and actually asking them to do things? They were asking to build apps.
You know, it was supposed to be all AI based apps when they were really having, as you said, hundreds and thousands of engineers working in the background, building this code, uh, you know, was done cheaply in Indian labor is relatively inexpensive. But how do we know what someone is sending us, is what they claim it to be? And the third piece I think, which is really critical here, is that I think companies, uh, were so enamored with getting AI coding done, or coding via AI done, that they weren't really worried so much about how it was being done, as being able to stand up and say, see, my IT group, my DevOps folks just got all of this code for next to nothing 'cause AI did it, and I don't have to go out and hire 34 e 50 more engineers.
So there's a whole series of things that go, that are, that are going on behind the scenes with this. I think it's really concerning that we don't have a better understanding, a better handle. And, and this is a failure of both Wall Street and, uh, enterprise IT departments not understanding what's really going on behind the scenes before we invest all kinds of capabilities, all kinds of energies in these kinds of companies.
Tracy Ring, and is there a way to test this and discover this, or we just kinda have to take people's words for it? Uh, well, I'm baffled by it. I'm so baffled by it considering, you know, um, some of the, the, the journey I've been on in terms of getting, uh, the attempt to get funding, um, I honestly, folks, they look at me and they go, some blonde chick from California, I don't think she can do this.
Um, so it can be really frustrating to hear the story, to be quite honest. Um, and it doesn't, it, it doesn't surprise me that it occurred. I don't think that there's a way you can test it.
I would think that if there was a way to test if Microsoft would've figured that out or to at least looked at their code base, right? Why, why did they not take the next step? It sort of reminds me of Elizabeth Holmes and her company that was gonna do the blood testing.
Uh, Theramos. Yeah, Theramos, they said, what on Earth, right? I mean, that's a cool dream.
And Walgreens bought, you know, into it, hook, line and sinker, and so did a lot of other investors. Uh, so yeah, it would be great if we could have blood testing machines in at Walgreens, or if there was this really cool app that was building applications for us and really customized. Uh, but, you know, sometimes it's too, if it's too good to be true, maybe it's not.
You know, what about logic? Putting logic behind it first? So, um, yeah, it's a, this, these stories frustrate me, um, horribly to be honest.
And I, I think it, I felt sometimes it's like the ai ba, everybody got so excited about AI that there's probably more than one company that's out that, that's out there doing stuff like this. There's no doubt, Right? Jack Poller, it may not just be in the land of DevOps that this is occurring, right?
It could be occurring in just about every vertical industry. There may be somebody out there who's doing fake ai. Not only is it probably occurring, it has occurred in the past.
I mean, there's a meme out there about the being named to the Forbes 30 under 30 list where, you know, something like, I don't know, a third half of the people there have been fraudulent actors, right? It's not just, uh, Theranos, there's a long list of companies including Sam Bankman Free, who were, you know, uh, all named as 30, under 30 who were fraudulent people. Uh, and many VCs have been snowed under on this because they're not technical people.
They're investment bankers, and a lot of them just don't understand the technology. What I find surprising about this one is we have lots of examples, uh, from Microsoft with GitHub, from chat, GPT, from all the popular, uh, chat AI interfaces of how quickly they can operate and generate code. And they can, you know, you can say, give me a, you know, give me a wire frame or create an app and, and they'll give you something back in two to three minutes, which has gotta be much quicker than an Indian engineer is doing it, typing it in by hand.
So how did it pass the sniff test? That's what I don't understand, is yeah, what person at Microsoft said, well, give me a demo, or I want to type my own query into the chat bot. And it didn't come up with an answer in five seconds.
It took 25 minutes for an Indian engineer to go type it and get it back to me. And they said, yeah, this is cool. Let's go throw, you know, a hundred million dollars at, or whatever they invest in it.
I just don't get that part of it. It just doesn't, I don't kidding either. When I was reading it, I was like, how on earth did they do this?
How, how, right now, You know, there's so much money out there right now seeking returns, right? That people are just investing in pipe dreams, and, and I think we're gonna see a lot more of it. Uh, there's just too much money chasing, basically, too little technology.
Well, that, and the other part of it is that I think, Jack, you hit on this at the beginning, which is that companies saw this, the, the, the consumer of the product or the service saw this as a way to get very inexpensive design help and, right. And so that creates an artificial demand for a non-existent product. So, a again, Tracy, as you said with the Theranos, it's like, if we could get this, you know, this pipe dream of a, of a very cheap and expensive, very tiny blood test machine in, in Walgreens, why wouldn't we do it?
Of course, we have to try. I mean, that we, we look at XI mean, you know, space X, they're trying and trying and trying their dream may never really completely come true. We may never go to Mars.
I mean, come on there. There's a lot of money being invested in these particular areas. But to say that you already have the technology, instead of saying, I want investment to do research on the technology, that's the mistake.
That's, that's where these companies are, are missing it. Because I, I, I believe that there is a big enough demand for these types of solutions, a blood test at Walgreens, that, that saying you wanna in investigate and you wanna put research money towards it in order to, to potentially build that solution is a valid, uh, pitch. So why are they not pitching that?
Why are they saying they have a solution if they don't? And how come we can't see that? Part of it is the consumer side, right?
The, the enterprises, the IT departments, they are being pressured in a lot of organizations to go do something in ai just because it's a hot new cool technology. CEOs don't wanna get left behind. People are trying to figure out what's the best way for me to implement ai, even though in many instances in organizations, you know, we, they found that 60, 70, 80% of AI projects aren't successful.
But there's so much pressure within organizations now to try and find these kinds of companies that will give us a leg up against the competition that people are just not doing their homework. They're going out and investing and, and saying, boy, this is great. I'm gonna, I'm just gonna go do this.
It, it's same with, you know, it's same idea with, with Theranos. It was, it's gonna gimme a leg up in the competition. This thing has to succeed.
I'm just gonna go invest in it. So there needs to be a lot more backend. Does this really work?
Is there really something behind it? Tracy? I think the difference with between this and with X is SpaceX is that we know there's still experimenting, right?
They're not promising to do this tomorrow. Uh, these guys are saying we can do this now. And I think that's a real, a really problematic statement, right?
We have all kinds of evidence of what SpaceX is up to in the bottom of the Gulf of America, right? So, um, I would ask Tracy one last question though. Um, somebody I talked to says, you know, you can telco that's written by a machine versus a human, and that there are certain things that machines will do that humans will not.
Do you think that's a, a viable sniff test or no? Oh, a hundred percent. A hundred percent.
I mean, you could even see that. Just have it write a paragraph, right? If you don't, even if you're not a programmer, just have it write a paragraph for you and then have, and then ask a different questions and have it write a different paragraph.
And you can see it has a cadence to it. So the co code looks the same way. There's a particular cadence to the code, so you can see that it's generated by ai, which to me is not a bad thing.
There is some consistency in how it's generating the code or the, or the, or the, um, the content. Um, but yeah, that should have been a good valid test. But as Jack Poller said, you know, or maybe it was Jack Gold, how come he didn't say, here, go write this, this application.
It didn't come back in 15, you know, in five minutes it had to go, you know, take maybe an hour to come back with an answer. There's that was the, that was the smell test on, on that test. I mean, that was easy.
That was just a really complex application with a huge context window that would take two hours to Right, Right, right. No, no. It was went through qc.
QC is what took the time. It wasn't writing the code. Yeah, right.
But there's definitely a format that it generates on everything. It does. There's definitely a format.
You can see the format it uses. There's a syntax. All right, well, hey folks, if you get something back from somebody and it feels like it's written by a human, chances are it was not a machine.
So double check the quality of the code and how it's created. 'cause the cadence is a dead giveaway. We'll be back in a minute.
Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, we're gonna have another little conversation about a different kind of security, but it's invasive spyware. I'm not quite clear that it's actually spyware, but that's what people are calling it.
Meta and y Yandex have been exploiting Android browser features to covertly track users. And now Meta says they've turned that off. Now, somebody pointed out that they're in violation of Google policies.
Um, Jack, we're all getting Jack Poller. We're all getting a little paranoid about, uh, what's happening on our devices and who's tracking us. And the devices feel like they're getting a little creepy every time I talk about something.
Suddenly there's an ad unit that goes with that somewhere. This doesn't bode well for that. I mean, how concerned about all this should we be?
Well, let, let, let's start with getting the internet memes outta the way first, is that you're, you know, you're not paranoid if they really are out to get you. And, um, well, you know, we, we can't possibly be shocked that either Russia, China, or Meta is spying on us, right? Uh, this is, you know, all three have a very long history of doing this.
Um, apparently what they're doing is they're using, uh, the applications that the, the application that, that the native application that you install on your Android phone to have a backdoor communication channel to your web browser, and therefore being able to access and spy on what your web browser activity is doing. So if you are trying to be anonymous and use the private mode of the web browser, or even if you're not, it doesn't matter because the, a native application or Yex or for Meta Facebook, so Facebook or Instagram or, um, WhatsApp, I, and I don't know if specifically which app is doing this, but they had the ability to go and look at your browser, talk a back channel to the browser and say, show me what, what websites you're looking at, how you were interacting with. So that was sort of the technology behind this, this ability to go talk to the browser and have this back channel communication was never meant for this.
And it does violate, uh, Google claims that violates the Android and prone terms of service. And so Meta says, well, we've stopped while we investigate whether we really did violate the terms of service, whether or not they violated terms of service. This is really creepy behavior, and it is a big, um, both cybersecurity concern as well as a privacy and anonymity concern.
And it just makes me immediately want to destroy all of my accounts with these, you know, you know, when I, I dropped, uh, Facebook, I never found a lot of value in Facebook, but I have an Instagram account because so many of my relatives and friends are on Instagram. But now I don't even wanna have that because there's no reason Facebook should ever want that data, let alone have access to that data. And there's no reason that Yandex or anybody else should want or have access to that data unless it's for nefarious purposes.
So, I mean, this, the, the, the, the creepy factor of this is just really huge and really bothers itself. Um, then there's also, it, it is really ugly. And then from a pure cybersecurity concern, this is something that Google should think about.
Do we really need these types of features? And not making it a terms of service issue, but a preventative issue in the first place? Does, does anybody really need to be able to get access to that type of data?
And from a cybersecurity concern, my feeling is no. And why should anybody be surprised about this? You know, uh, seriously, from, from both perspectives.
One is that that's how Meta makes its money, right? Knowing everything about you so they can sell you the, or send you the right ads so they, you can sell stuff. Uh, the other piece of this is, frankly, most people on phones, when they install an app, never read the terms of service.
They just click, yeah, okay, share whatever you want. You know, the, it's an open book. I, I mean, look at, it's scary.
My, my kids are older now, but look at what kids actually share on their devices. So is Meta really getting anything that they couldn't get any other way? And finally, Jack, I fully agree with you.
Why is this available in Android and Chrome browsers to begin with? What, what's the purpose? Why did, why did Google put this in place?
So it's a multifaceted problem. No one should be surprised about this. Um, and I'm not sure that it's ever gonna get fixed.
You know, if it's not this, it's gonna be some other exposure. Well, didn't Google do it first? I thought I was running everything in Incognito, and I'd be fine.
And then we find out, well, incognito didn't rock anything. But I think what we have to remember is data is the new gold. It's the new gold.
And so these companies, mining for it is not, should not surprise us, but we should, you know, when it comes to, you know, I don't like the idea of somebody, you know, watching what I'm doing. I used to didn't care. That's the weirder part.
But in our new political climate, I do care. I do want more privacy because now I'm worried about, you know, big Brother watching is kind of, you know, it, we're getting to that point. Um, but I have to say that we, if if, if you're in the public sector, you, you think you'd be listening to this very carefully.
We're doing all this work in the public sector to have, you know, zero trust policies. And then we have some of our people in the highest parts of our government using their own, their phones and, and, and things like, you know, signal to, to, to do all their, their work. This is a huge problem because again, data is the new gold.
And, you know, why wouldn't you want to take this? If you can, you want this information because it's worth a lot of money. You could sell it to China, you could sell it to Russia, you could do something else with it.
Maybe nefarious, maybe may, maybe not, uh, could be creating a better end user experience. But I don't think that's the, the, the ultimate goal. It's to make money.
And it is, is it's something that we have to be forever vigilant. Data breaches, you know, this is kind of a data breach in my, in my world, a data breach that, that we, yeah, it's a data breach. Data breaches are costing $10 trillion a year, globally, $10 trillion a year globally.
And for companies that, you know, as we've pointed out, Google kind of, can we turn this stuff off? It, it, they don't address it because there is so much money in the data. There's another piece of this that's I think really critical for our enterprise listeners, and that is that about 80%, depending on which industry you look at, about 80% of enterprise users have phones as their secondary, or in some cases primary methodology of accessing corporate apps.
And many of those are done through a browser interface. So if you also have WhatsApp, Instagram, whatever, running on your phone, not only is meta knowing what you're doing personally, you know, which restaurant you ate at yesterday, but knowing what person you visited on your sales call yesterday, because they're, they're gathering that information as well. So it's not just, it's certainly a privacy issue, but it's not just, this is not just a consumer issue.
This is also an enterprise security issue, which is really concerning. Well, Jack, this is why I was just gonna say, this is why there's now the rise of the enterprise browsers with companies like Islands and some of the others that are making their own version of the browser. And I bet every single one of those companies right now is going into their code base and patching it and saying, we're gonna remove this capability from the browser and issue a new version of the browser.
If they don't, they should be doing that today, right? Well, we've Had, we've had private browsers, Jack for years, right? Yeah.
Like The Blackberry, they're not using it. Yeah. And no one uses them, Right?
Yeah, they don't. And keep in mind, I know, uh, I know young developers just out of, uh, university that they code on their phone with two thumbs, kind of blows me away. It's like, well, that's a whole new world, but, so they're actually doing work.
Yeah, it's a PC to them. They're actually doing work on the, on all kinds of different edge devices. So there's a, that's a lot of private enterprise data getting out.
I'm kind of getting to the point where Jack Gold was talking about, I mean, there is no notion of real privacy out on the internet and all these places, you know, so meta is basically like going down to the local mall. Everything you do in the mall is seen by everybody else. And it's the same thing that goes on at Meta, right?
If I go in the mall and I go into some store, everybody knows it. And so too, will they know what website I went to from Meta? And I think we just should stop having this illusion that somehow or other of these companies are gonna do anything about data privacy.
And if you want privacy, you gotta take that on for yourself. Is that just where we are, Jack Gold? Yeah.
The, the only difference is that in other countries, certainly not in the US but in other countries, they're starting to realize this and regulate against it and, you know, can they completely stop it? Europe is a great case in point, right? Can they completely stop this kind of thing?
Probably not. But if you're found out, meta is gonna get fined, you know, billions and billions of dollars. And so there's some disincentive for them to do it.
Certainly Russia doesn't care. North Korea, China doesn't care, right? They're, they're gonna use this stuff.
But the only way this gets solved, in my opinion, is not through technology necessarily. It's through government regulation, privacy records. I mean, remember the old days where people used to be able to, to share your medical data when you went to the doctor, uh, and then HIPAA came along and they couldn't do that anymore.
It's not perfect, but it's better than nothing. I think that's the only way this, uh, ultimately gets resolved. And frankly, I don't see it happening in the US anytime soon given the current administration.
Yeah, we're not, we're going exact opposite direction. I mean, even the, uh, the, the big beautiful Bill, um, has a, has a clause in there that says you can't regulate AI for the next 10 years, which would be disastrous. Mm-hmm.
Well, To be very bad for us to, To be clear, it says states can't, but the federal government can't can't. But the federal government just won't. So that's where Yeah, Exactly.
Yeah. It's because we know how responsible states are. Yeah.
There you go. So, So Jack Poller, do you think Google will go fundamentally fix this issue? Or are they just gonna sweep it all under the rug and just rang their finger about you violated my policy?
I think right now they're taking the, you violated my policy approach, um, because there are legit, there are some legitimate uses for the technology that they, you know, for the sort of backdoor way of doing things, you know? And so the question is, can they put some guardrails around it, whether it's terms of use or some technical guardrails around it to prevent, uh, the types of data leaks we're talking about while still making it useful for its intended purpose. And, uh, that's, I think what they're gonna struggle with.
Companies like Meta and Gex and the, the, you know, they're gonna continue to, to find any way they can to get the data they need. I mean, this is not the first time Meta has done this, you know, for years and years and years. They've used, uh, a tracking pixel, an image with one pixel in it to track you as any website that has it on it, it re you know, has to call to Facebook to load that image that you never see on your screen.
'cause it's one pixel wide. And that was another way they've tracked you. So it's, it's a desirable technique that, uh, sorry, it's a desirable feature that go, that, uh, meta wants is to be able to track you, you know, that data, as Tracy said, that data is gold for them, that they live and die on that data.
So if Google turns this off, then they're gonna just keep investigating and find other ways to do it. There is another interesting aspect to this, and that is that this plays right into Apple's iOS message. You know, the more secure browser, everyone should have a a, an iPhone because Android is unsafe.
Uh, whether it's true or not is, is a whole different discussion, but that's really what's going on. What's gonna happen here, I think, and I think Google is gonna feel a lot of pressure. Maybe if they feel the pressure, they'll turn it off.
Um, we'll see how long this is actually in the news cycle. Uh, and it won. It doesn't, to be honest, the, the average person who's not in tech won't even understand what this discussion's about.
I don't wanna say that they're dumb 'cause they're not. That's just not their area. What they want us to be able to be on, uh, Facebook.
And they, it's cool to say, Hey, there's these restaurants that are near you, or here's where your friends are. And that's the kind of the reasons why we have that, uh, those features as Jack Poer, uh, just described. So I, will it be something that a private person might take in a lawsuit?
Probably not. And will there be regulation that says you're gonna get fined billions of dollars? Probably not.
There could be regulations. You're gonna get fined 40, $50 million, which is simply a cost of doing business. So it's, yeah.
Yeah. So we don't see those kinds of massive, uh, you know, penalties for being a, uh, doing bad things in tech. We just don't.
So I don't, there's not an easy answer for this. This is a massive data breach that we cannot solve. And, and let's also be clear as it's not really an Apple versus Android issue, it's a who, who is actually getting your data.
Because if you're on a, an Apple phone, your data goes to Apple. And there is, right? It's a so, and there's a lot of, there's a whole lot of issues we wanna explore here of Apple getting the data versus meta getting the data.
No, I, I, I agree. And the only reason I use that example is because from a marketing perspective, this is gold for those guys, Right? Well, speaking, speaking from a marketing perspective, should I just go out and download like duck, duck go?
Is that gonna solve my problem? Uh, yeah, until I find a way into that one. All right, well, hey, we Can, I, I don't think Mike, honest, the honest answer is given.
We're all dependent on this technology. All of the technology we use at some point is gonna have a hole exposed to it. And the, and the, I was gonna say the bad guys, I, I wouldn't exactly call them bad guys, but the guys that can make money exposing those holes do so.
All right, well, folks, you heard it here. Any data that's not on your own machine, that you probably, and you probably should lock it down on your own machine as well, you might wanna consider the fact that it's probably been exposed to somebody with or without your permission. And maybe you wanna start thinking about modifying your behavior as a result.
I want thank all our guests for being on the show today, as always sharing their insights. That was awesome. I wanna thank you all for spending 45 minutes or so with us today.
Once again, please stay tuned for all the techron that TV content coming up right behind us, and we'll see you next time. Hey guys, thanks for the throw. We're here with Nick Hoecker, who's head of market strategy and business development for cribble.
And we're talking about AI ops and how it's evolving in this new age of gen ai. And well, there's a lot happening. Hey, Nick, welcome to show.
Great to speak with you again. Thanks for having me. We've been talking about AI ops for a while, and I think for the most part, it was always in the context of machine learning algorithms and predictive stuff.
And these things were going to learn our environments and surface some interesting insights in a way we went, now it feels like we're moving past Gen AI into two phases. One was the co-pilot phase, and then there's the rise of the agent phase, which has a little more reasoning and is a little more autonomous as you kinda look at this. Where are we on the journey for AI ops?
Well, I, I think AI ops, it really turned into, you know, you, you're seeing that more from AI ops into, you know, what analyst firms are calling event intelligence solutions, right? AI ops is kind of, it, it really turned into a zero billion dollar market. Um, there was a lot of, of, of hype there.
There was a lot of ambiguity about what an AIOps solution was supposed to do. Um, and I think, you know, just calling it AIOps, right? People really focused on the AI and they got into that hype and they didn't focus on the value.
And so now that we actually have some AI out there, uh, people are realizing, you know, the AIOps story didn't quite deliver, and now it's time for a bit of a rethink. Gene AI is gonna be part of that, agent is gonna be part of that, but, you know, let's foc let's call it something new, right? Let's focus on the value that this can provide, um, and move forward from there, right?
So I think you're seeing kind of a new, a new type of category emerge that hopefully allows IT leaders to focus on, you know, solving their actual problems, not chasing this kind of mythical hype beast of AI when trying to resolve their IT operations issues. And how tailored are these solutions gonna be? And I asked the question because every IT environment I've ever been in is pretty much a snowflake and doesn't really have a lot of commonality with different things.
And how do I kind of take all that and expose it to something that looks like, you know, multiple kinds of AI models to get something interesting? I, I think you're, you're gonna have a lot of training periods that, that take a while depending on how diverse your IT environment is. Right?
At cribble, we work with really large organizations. You ask them what technologies they have in house, they say yes 'cause they have everything. Um, two or three of the same things that, that are very identical.
Uh, some older, some newer. And so you're exactly right. Like there's gonna be a huge training phase, uh, as these agents learn the environment, um, the new systems that are coming out, right?
Or this new category of EIS, they're gonna have to figure out what the topology is. So they're gonna need really clean, accurate data that is going to delay. I think a lot of the advantages that, uh, companies hope they're going to get out of these new, you know, age agentic systems, the companies that are going to deliver on the best solutions are the ones that already control that data.
Companies like, like IBM or ServiceNow, right? They, they know what's in your environment. They have access to the ticketing systems if they don't already run them.
Um, configuration management databases, all of these things are gonna, you're gonna need access to that. You're gonna need, um, really clean contextualized data to make these things work. How will the role of IT people, DevOps people and all the folks that make up the communities that we have been around for years change as we kinda get to this new way of thinking about applying AI to IT operations, no matter what we call it.
I think that's gonna take a while to really flesh out, right? Like, there's been a lot of conversations happening in, in social spaces around, you know, IT operations managers, IT operations leaders as well as like software engineers. The one theory is they're gonna be running networks of agents, right?
They'll be managing these agents that are doing this work for them. Maybe that feels a little optimistic. Um, but I think it's going to be, you know, a lot of augmentation, right?
Me, as an IT operations leader, I'll be relying on AI to tell me what's important. I will still make the final decision. 'cause I don't wanna outsource, you know, potential downtime or other operational costs or opex to an agent without me blessing that.
Uh, so I think you're gonna see like a mixed model for quite a while, right? Where you've still got very much human in the loop, uh, for the next few years at least. Um, and then over time that may get more and more automated.
As these agents get smarter, the models get better, and frankly, the models get cheaper, right? One thing that people don't really consider is these models in, in an operational context have to process a ton of data in real time. The economics don't really support that yet.
So we're not quite there. Even if I wanted to go full autonomous, whether it's my security operation center, my IT operation center, the money's just not there, right? You're still incurring huge costs to operationalize these models.
So I think there's a lot of things that have to happen, but I think over the short run, it's going to be, you know, I'll augment my teams with some of these automated solutions. Um, but I'm always gonna have a human in the loop. And over time it's anybody's guess, we'll have to wait and see what happens.
But ultimately it does sound like people will be supervising AI agents that are performing tasks on their behalf. And some of those AI agents may communicate with each other to complete some tasks, but ultimately they gotta report back to somebody. They do, they do.
Somebody's like a, a human is ultimately responsible, right? You can, you can delegate the authority, but you can't delegate the responsibility. And so you're always gonna have to have someone who's approving or, you know, validating what these models are doing in the enterprise.
And that's a, it's a really different kind of role than a lot of IT folks I think are used to. So they're gonna have to ramp up on, on what that really means. How will AI keep pace with the rapid pace of change that we see in our environments?
Right? I could argue that one of the issues there with AIOps was the machine learning algorithms were supposed to learn your environment, but you were constantly changing the environment. So they were constantly learning and not actually doing something.
Um, we can see that issue getting, starting to get even more complicated when we're using AI coding tools to create more code and update environments faster than ever. How do I keep pace on the other side where the AI models are supposed to be trained and updated on a regular basis? Is that gonna become continuous or how do we think about that?
I don't think enterprises can really adapt to kind of continuous, like, you know, you may, you may be deploying code, you know, 20, 30 times a day. You understand what that process looks like. You know, kind of what the splash damage is going to be.
But if AI is going to be running your entire environment, it can be difficult to really understand what the second and third order effects of this is going to be. So I think you're going to see like kind of staged rollouts of these updates. And then, you know, AI will continually learn and understand that topology, whether you're in the cloud on-prem or some kind of hybrid solution.
So you're always, this is another kind of instance of this is where human in the loop makes the most sense, because you still want, like, you, you don't want the AI to kind of make a mistake for something new that it maybe hasn't seen or hasn't trained on before. That then leads to downtime. One of the issues too, you hear people talking about is like a lot of the gen AI stuff especially is probabilistic and that, you know, it's guessing with getting better at guessing, but a lot of the IT tasks or, um, well they're, they're basically need to be done the same way every time.
And I can't have an AI agent that does it differently every time. It has to be precise. And how do I marry those two things because they're not quite perfectly aligned.
Yeah. It's, it's the, the 95% use case where AI's really gonna be useful here, right? The things that it sees all the time, it understands those environments, it understands what the impact is going to be.
It's gonna be that 5% where the AI calls for help and says, alright, I've never seen this before. My models maybe aren't better than what a human would do. Or, you know, a, a linear regression.
So, you know, I can, I can defer that to a human and that's where that human's gonna be stepping back in to make those decisions on behalf of the ai. Maybe that becomes a pattern that the AI can then learn from, and then that 95 turns into 96 over the course of years. Um, but it's gonna be, you know, the idea that I'm just gonna flip a switch and I've got HAL 9,000 running my data center, my cloud environment, that's still very much the realm of sci-fi.
One of the things that, you know, as you described that that comes to mind though, is most of these ais are trained to be overly helpful, shall we say, and they kinda wanna come up with an answer no matter what. So are you sure they're gonna kinda raise their hand and say, I don't know. Uh, so it's interesting that you say that because in our own, um, AI capabilities within K'S products, we, you have to instruct the model, like, do not hallucinate, right?
If you don't know, say something, right, or, or don't, don't try and guess don't make something up. Uh, and we've seen, you know, even recently, right? Instances where, you know, citations don't exist in reports that were released.
Um, so I think you can, if you take that into account, right? Like, I don't want you just making things up on the fly, that will be, you know, something that these systems have to have as part of, you know, their overall operation as well as, you know, very good governances over who can instruct the AI as well as, you know, what else is it allowed to do versus not. So you definitely boundaries here.
And I think that that's, that's an area that has not been discussed enough, right? People are looking at this as a magical future, but you still need guardrails and those guardrails, right? Why do you have brakes on a car so you can go faster, right?
You have to have governance in the AI domain so that you can really take advantage of these things. You have to know where the guardrails are. Well, isn't this ultimately becoming a massive data management challenge, especially with telemetry data that is, you know, unique in its own attributes?
And do we really have the mechanisms in place to kind of manage that? So, And you're hitting on my sweet spot here, right? Mm-hmm.
I'm a a longtime data management person, right? I, I view every problem as a data integration issue. Um, and so for our customers managing telemetry data, they don't think of themselves yet as data managers, but they are.
And so, you know, they are, they don't, maybe don't use the right terms, but they're thinking about metadata, they're thinking about data structure, they're thinking about data integration. Um, and yes, these AI systems are going to need huge amounts of data that is clean, that is contextualized, that is enriched. And so, yeah, this fundamentally comes down to a data management issue.
The algorithms, the models are not that interesting, right? What's interesting about them is the data that they train on and then operate on. So how do you manage petabytes of telemetry data a day?
Uh, you need very dedicated solutions for that, whether that's simply getting data in from a variety of sources and normalizing it, uh, or storing that for long-term retention or using that in a variety of operational scenarios. So, yeah, I, I agree. This, this does fundamentally come down to a telemetry data management problem, and there's a lot of elements to that.
Yeah, it's funny, I think if I went back to AI ops and originally there was a lot of skepticism and a lot of people didn't believe it. Now we seem to have pivoted over the other side of the world where there's a lot of hype around all things ai, but are we getting to the point now where maybe I just don't wanna do this IT job without some help from AI because, well, it's getting too damn hard. Why not?
I mean, you know, it budgets are not increasing. So I'm not getting head count in many cases. Um, maybe I'm being advised to consolidate tools or reduce the number of vendors I'm working with, right?
Doing all of that work, managing all this data. If I'm not getting people I need something. And so it's, it's easy to see why there's a lot of interest in ai, you know, both for SREs, DevOps, IT operations, cybersecurity.
There's just too much to do. There's too many alerts, there's too many things that, you know, require human intervention. So yeah, AI seems like a, at least at present, AI seems like a really interesting way to bridge some of these, uh, staffing gaps and capability gaps.
So, yeah, whether we'll get there or not, um, remains to be seen, but certainly there's a lot of VC money, um, interested in finding out. So among your customers, what do you see them doing to get ready for this kind of transition into the AI era that you kinda wish everybody else would pay more attention to? Yeah, so what we're seeing, it's, it's really interesting 'cause you know, we see, um, you know, companies using that, companies that are, that have embraced AI ops, you know, before it became event intelligence solutions.
Uh, and even today they're using our solutions to normalize data, to add additional context to it so they have a better idea of like, where this data came from, where is it going, uh, what other additional payload elements can I interrogate before I land this data? Either in, um, some kind of event processing solution or long-term storage. So on, on the cripple stream side, we're seeing kind of the data preparation, uh, happening upfront.
And then on, on some of our other products, we're seeing companies create dedicated data lakes for data they're gonna use to train AI models. Uh, they're integrating lots of different data sources together from a variety of sources and linking destinations together in order to get a better idea of like, alright, here's what I can train on. Here's where I can turn the data scientists loose.
Here's where I can, uh, let the models go crazy, uh, and, and train those. So what we are seeing is like people preparing, right? They're starting to think about data as a, as a, as a strategic asset, not just as something that like, eh, I gotta, I gotta store this for seven years.
But they're starting to think more broadly. They're starting to thinking value, not just cost, which is really interesting to see. And we're doing a lot of advisory work with our customers to help them get there.
Hey folks, you heard it here, no matter what era it is, guess what it always was about the data and always will be. Hey Nick, thanks for being on the show. Thanks a lot.
All right, and back to you guys in the studio. Hey guys, thanks with, we're here with Tim Chang, who is vice president of application security for TAUs, and we're talking about a report they put together on bots who now apparently are counting for more traffic than humans on the internet. And a lot of those bots, maybe not for good, but, uh, you know, we don't know which ones are bad and which ones are evil until we go investigate.
Tim, welcome to show. Thanks for having me, appreciate the conversation. So what is going on here with these bots?
Because some people will swear there are good bots and others will say just about every bot is bad. But the one thing I think we can all agree on is there's a lot more of 'em lately, and they all seem to be tapping into ai. So if it's already half, at what point does it become three quarters?
Will it become all of it someday? Where are we? Yeah.
Right. And first, let's just like, you know, level set on, you know, this concept above bot. And I think, you know, it's this automated software that's built to do, you know, automated things.
And so, like you said, some are good and some are bad. And what we've seen in the, in the last report is, you know, now more than half the internet are these automated programs that are just out there doing things. And so of that traffic, 37% are really malicious, and they're trying to do things like, you know, break into your bank account or scrape data from your website or buy sneakers before humans do and sell them on the, you know, alternative markets.
And so, yeah, we think, you know, that this problem will probably get worse as these bot operators, the ones that are creating these bad bot programs, uh, get more comfortable with, you know, artificial intelligence, where it's really easy nowadays to create a bot that will scrape a website and or, you know, take some data or understand your defenses and, you know, then put that into another bot that will navigate your, uh, defenses. So, you know, we anticipate that the rise of this automated traffic will continue and that even the, the bad bots will, will, will continue as well. Is it gonna get harder to detect that traffic?
I mean, 'cause you know, from what I see, the AI stuff is getting smarter and smarter, and frankly, it seems to be helping the bad guys a little bit more than good guys right now. Yeah. You know, the every year the tables turn, and, you know, I think right now, um, at least here at Tallis, you know, we still have a good grasp on how to detect the, you know, the, everything from the simple bots to the more sophisticated bots, or even the ones that are polymorphic, the ones that change constantly.
Uh, we still have, you know, a really good, uh, sense of how to detect them. But yeah, over time it's gonna get more sophisticated and more challenging. And that's why, you know, you know, companies like us that just study this problem, um, you know, are set up well to, you know, help in the future when things get, uh, very complicated.
How does that work exactly? How do I detect bots and then how do I thwart them if I don't want them falling on my website or wherever else they may be going? Yeah, it comes down to how much data that you can get about that particular type of bot and, um, you know, so for example, you know, we have, you know, hundreds of ways to fingerprint a bot and track its lifecycle over, you know, its kind of attack attempts.
And so that really helps with determining, you know, what is the intent of that, you know, piece of software and is it normal or is it bad? And if it's bad, then we have different ways to, you know, protect against those types of, uh, nefarious or malicious activities that they're trying to, trying to conduct. Um, so it comes down to how much do you know about this particular type of threat?
And that is a game about, you know, collecting data, analyzing threats, uh, looking at patterns over time. And, um, that in itself is also a very, you know, much of a machine learning AI type of, uh, defense strategy too. Are each of these bots targeted to a specific task and function, or are they essentially services that are being rented out and people are using them for different use cases?
And it's a whole business empire? Uh, it really depends. It really depends, and it's kind of in both categories.
So if you think of a DDoS attack, there's definitely DDoS as a service sites, and those are just automated pieces of software that are launching DDoS attacks. And then there are ones that are purpose built to, you know, conduct specific activities, uh, against specific websites or properties. And, um, and so yeah, it, it kind of ranges depending on what type of bot attack or, uh, malicious bot that you're trying to to, to address.
Do you think we will create good bots to go battle the bad bots? Where might that fight actually take place? Yeah, yeah, it's happening right now.
It's happening right now. I mean, every day when you go to like a website, for example, you don't see it, but there's a, you know, a battle of bots, you know, happening behind the scenes. And, uh, we certainly have our own.
And, um, and, uh, obviously the bot operators have theirs. And so it just becomes this, um, situation that's becoming very interesting and, you know, um, you know, and, uh, there's also a human element to it all as well. So while you still have these automated programs that are fighting each other there, there's always humans behind that, that are taking in data and trying to manipulate each other's, uh, you know, software programs.
And so it's a very interesting field right now in terms of, you know, what's happening with, with bots and how to deal with them. What does a good bot gonna look like in the future with ai? Is that's any different than what we historically have had?
Yeah, yeah. I mean, when you look at the rise of agentic AI and how, you know, you're going to have agents that are operating on your behalf and, you know, performing functions, um, you know, those are the good ones that you want to be able to allow to perform those actions and functions. And then, but then it becomes interesting, how do you distinguish now between that and something that's been, you know, now doing something, you know, that's not supposed to be done?
And so, um, you know, still, again, it becomes a, a question of, you know, how much can you learn about the identity and the intent of that, uh, bot? And how quickly can you address the problem that, uh, will surface from the bad ones? So on the side of the good guys, am I gonna have multiple AI bots that I'm gonna try to manage and orchestrate or assign different tasks to?
And this becomes more of a game of orchestration taking place in real time than a human leads, but the work is done by the bot. Yeah, it, it could, it could, it could. Right now, the way, for example, we operate is, you know, we have a system that, you know, can perform different types of functions like a bot, uh, you know, automatically and detect and, you know, mitigate, you know, certain types of, you know, malicious bots.
And so, you know, in the future, maybe we do have an army of, of good bots that are working on our behalf, and they're there controlled in a centralized manner. And essentially, you know, that's, um, you know, what we're doing with our policies and, you know, our security rules to really, you know, detect and mitigate that type of actions. But who knows down the road it could, it could all change.
And, and you know, that's the interesting part of what we do, is we're always trying to keep in the forefront of, you know, new defenses and new techniques to towar these types of, uh, advanced, uh, threats. So collaboration in the history of cybersecurity has always been challenging, but can you envision a world where, let's say that one organization has a bunch of good bots that they have created to go fight the fight, and another organization has good bots to go fight the fight. Can these bots collaborate more and kind of know about each other to go after the bad guys together?
I mean, how smart can we get? Yeah, that's a great question. I mean, we're not there yet, possibly in the future.
It's kind of like, um, threat intelligence, threat intelligence. You know, we, we, we share data, you know, we tap into each other's systems and we kind of help each other improve, uh, each other's, you know, defenses, um, through kind of a threat intelligence, uh, ecosystem. And so, who knows, maybe down the road there's a similar thing for bots and there's a, there's a way to share the good bots that are working and that we can all kind of, you know, help each other, uh, defend against something that's, you know, very, very complicated.
But we're not there yet. But that's a interesting idea. So one of the best practices that people are putting in place to defend against the bad bots, what are you seeing the smart folks doing that you wish everybody else would kind of do more of?
So it's, um, yeah, it's a good question. It's, it comes down to a matter of best practices. I think.
Uh, the first thing is you have to assess your entire landscape, not just, um, web applications, kind of like what I've been implying here. But they're also APIs, uh, APIs or ways for applications to speak with other applications or other ways for programs to speak to other programs. And these APIs represent a very large attack surface robots.
And so when you consider kind of how to build up some defenses, you have to take kind of the cell stick approach and consider all the ways that a bot can actually attack your type of, um, you know, digital ecosystem. And then once you have that kind of assessment done, then you start to implement, uh, different techniques and you have to observe kind of behavior. And our suggestion is, is always, you know, when kind of defending against bot, don't always put all, play all your cards at once.
Um, 'cause then that kinda reveals your defenses, uh, right away. So start to, you know, defend in simple ways and determine how does a bot respond to that, and then, you know, deploy another defense. And so as you layer on the defenses and becomes even more complicated for a bot to navigate around that or understand how you're playing defense, uh, and so that's always a great way to kind of manage, you know, these types of attacks.
Some would say that API security has been their redheaded stepchild for security as long as anybody can remember. Will the rise of bots and AI kind of drive people to look at this more seriously and kind of think through what their defenses actually need to be for an API endpoint? Oh yeah, definitely.
I think, um, at least what we see is certainly more interest in API security, and we really believe that's due to, you know, how automated traffic is leveraging these APIs where nowadays, you know, we're seeing a lot more API traffic than, uh, web traffic. And so a lot of that is, uh, automated traffic in itself and a lot of sensitive data flowing through APIs. So, you know, first having better visibility into, you know, where APIs are and then understanding how they're being used and then detecting threats and then defending against them that entire governance and security is, uh, really important.
Uh, for, for a really mature API security program. Is there anything that telco should be doing that they're not doing these days to help in this fight? Because, well, a lot of these bots are accessing some sort of network somewhere and somebody should be able to see something, but, um, what kind of conversations can be had there?
Yeah, you actually, you know, bring up a good point, right? We, we work with a lot of telcos actually in kind of this space, and it's very similar, you know, it starts with just understanding what your attack surface is. So being able to detect, you know, any type of attack against either your website or API, uh, whether that's a technical technical attack or volumetric attack or something more sophisticated, you have to have that complete, uh, understanding and, um, almost like visibility into everything.
And then especially for telcos, they have to understand like how that, you know, attacks are being kind of where they're coming from. Is it better to, you know, protect it, uh, you know, where it is or understand kind of like, you know, the properties of it before you start to put some protections in. So, you know, we work with a lot of telcos on, on this type of problem, and, um, the techniques are actually very the same, but the, the scale of the problem is, is, uh, much larger, especially in the telco world.
Last question, but it seems like more organizations are putting in place what amount of bots they're AI agents to do various tasks. Have we thought through what it will require to secure those AI agents? Because it seems to me the level of risk is higher because the AI agent is running an entire process or could run a process and that entire process could be hijacked by another bad bot you that's attacking the good bot.
So is this whole game getting elevated? Yeah, I think for us, it, it comes down to identity and having to understand what is the identity of that application, that agent, that bot that's trying to perform a specific type of action. And so at Tallis, actually, we do have, um, different parts of our portfolio that are geared towards application security, like my business as well as identity and access management and data security.
And so the actual, you know, solution to identifying these agents that are either trying to do, you know, good things or bad things could be solved actually by not just one solution, but a combination of solutions to kind of put together a really compelling way to detect these types of, you know, agents and, you know, be able to address, you know, various use cases, not just, you know, are they logging in and doing something malicious, but are they now accessing information that they shouldn't do or haven't accessed that information before? And so, uh, because of, I guess where Tallis is positioned, it's, it's very interesting how, um, you know, kind of this new AI security use case is evolving and how, um, you know, one solution may not be enough. And so we're keeping an eye on it.
Um, it's all evolving really fast, but I think, uh, it's all very exciting at the same time. All right, folks, you heard it here. Well, exciting is one word for it, but at the very least, the cybersecurity threat landscape is evolving once again, and so too will our defenses.
Hey Tim, thanks for being on the show. Thanks very much. All right.
And back to you guys in the studio. Storage software running on Modern Hardware can deliver incredible performance in capability to support AI applications. This episode of utilizing Tech wraps up our season with a discussion of CCAs data platform for AI with Alan mc of cca, as well as Scott Shaley of Soy and myself learn how Modern Hardware is transforming storage for AI in this episode.
Welcome To Utilizing Tech, the podcast about emerging technology from Tech Field Day part of the Futurum Group. This season is presented by soy and focuses on AI at the edge and related technologies. I'm your host, Steven Foskett, organizer of the Tech Field Day events series, and joining me from Soy for this final episode of our season once again as my co-host and old friend Scott Shaley.
Welcome to the show, Scott. Hey, Steven, it's great to have fun doing this season with you. And it, it's sad and, and also great to know that we've, uh, made it through another season of these, uh, wonderful, uh, episodes and some amazing conversations that we've had over the last few episodes.
Uh, and working with you guys has always been so much fun. So Yeah, it's, it's been really great. Uh, you know, it's been great welcoming you as a co-host.
I I knew you could do it. Uh, glad to have you. Yeah, you know, I like to talk about things, you know, that kind of stuff.
So when it comes to talking tech, it's, it's a lot of fun and, uh, the guests and yourself make it a lot of entertaining, so. Well, that's what I was just gonna say. I mean, the guests are incredible.
Um, you know, we get so much great insight from them and just so much perspective on how, uh, this AI thing is being implemented around the world. Uh, you know, I think that people have this feeling that AI is somehow kind of a big iron thing, that it's some supercomputer in a, in a big data center that's sucking down gigawatts of power. And it is, it is, but it's more than that.
A AI is being implemented outside the data center in smaller environments at the edge, um, you know, maybe, uh, let's say, uh, interesting venues, entertainment venues, all sorts of things. Exactly. It's not just a, the, the, the home of, of Big Iron, right?
Yeah. That, that's the wonderful thing about this is this is kind of the convergence of a whole bunch of different technologies at once, and the ability to generate data in the way that we can generate data and then actually do something with it in a more meaningful way, uh, as we talked about in a couple of the previous episodes, of what people are doing to go back in time and bring that forward with the, the technologies that we have available today. So today's a, a fun one too, because we have a, a literal convert, uh, joining us today from, uh, being a customer to an employee.
And so that's kind of fun as we bring Alan from WCA along. Hi, I'm Alan Ney. I'm the field CTO for media and Entertainment, uh, and related ai, uh, at wca.
Um, I, I recently joined only in, in December, but I, I was a customer of CCAs for four years prior to that, uh, in a, uh, a cloud-based visual effects studio. Um, most of my, my career has been related to creative industries. Um, actually I was a professional musician for the first 10 years of my life and really enjoyed marrying, um, creativity and, and technology and really pushing the boundaries of what could be done with technology back when actually audio and music was a quite a challenging thing you could do on a computer as opposed to now where you can run an entire studio on a laptop.
Um, but transitioned out of there into visual effects world and large scale playback systems. Um, and that, that's been an immensely rewarding career. Um, just using technology and being able to push boundaries has really been, uh, a place where I'm kind of happy.
Well, it's interesting that, um, in audio, yeah, audio visual. Yeah. Old Atari st.
Guy here. So I know a little thing about using personal computers for music. Um, you know, what happened there was, you know, basically specialized hardware gave way to software running on commoditized hardware.
And the same thing Scott and I, in our career in enterprise storage, have seen the same thing happen where, uh, what was once the domain of literally special boards, special processors, special, everything has now become the domain of software. And that's really the story of wca too. I mean, my understanding is that essentially the, uh, the, the founding team and the origin of the product was what if this was done in software, and what if we took advantage of the latest, um, you know, incredible advances in more commodity hardware, especially NVME, but also all the things that you can do now on the processor.
And, and, and it worked, you know, I mean, this has been, uh, something where the software based storage solution from CCA has literally become the bedrock of, of ai, right? Yeah. I mean, the, the marriage of three things really allowed CCA to, to become, uh, not just the product, a vision in the first place, which was someone sold during an SSD onto A-P-C-I-E cap, um, someone coming up with the concept of containerization, and then the network teams out there far surpassing everyone's expectations and blowing away what anybody considered could be achieved both network performance.
Um, so you put those three things together, and now you can access, uh, NVME storage across an array of servers all over network while orchestrating all of this through containers. That that is essentially what WCA is. Um, gives you a huge expandable data platform, uh, that is all NVME based, that is addressable over network that will at times not only outperform local NVME within, uh, a client, but sometimes even dram.
It's, it's a creative innovation where you guys are literally transforming that ecosystem to allow the underlying hardware that, you know, comes from someone like ourselves into something that people just see as right next door. It, it's kind of unique that the software platforms and the data platform you guys have has that ability to transition data from point A to point B as if it were just sitting there and not have to worry about all that transition time. 'cause to your point about networking, what we keep seeing networks go up and down and faster and slower, and we start getting further away from the, the main processing.
That ability to see that localized data is something unique that you guys are working on. Yeah, I mean, there's a bottleneck always somewhere, right? And it, you know, every, every so often it gets moved to somewhere else.
But, um, network performance today, um, is astonishing. You know, we're, we're seeing ethernet networks up to, you know, you know, 400 gigabit. Um, we're able to push data into a single host at hundreds of gigabytes a second.
It's not something I, I thought we would see, uh, so quickly, but this is where we are today. Um, I think you're right, the, the idea of having data local to whatever your processes are, whether it's on a laptop or, um, on whatever compute you're using, and then expecting to have to transfer that someplace and there'll be some penalty or some time spent or some transfer process, that would just make you sigh. Um, it is most of our, most of our collective experience and history, um, today, that is just far from the case.
Uh, actually having all data centralized and accessible or network can be more performant than having it local. And that's one of the challenges I think when it comes to ai. 'cause this, this hardware is incredibly capable, but I don't know that every system can take advantage of those capabilities in order to, uh, you know, kind of move the bottlenecks out of the way.
I mean, the entire history of technology is all about moving bottlenecks. It's, it's, it's, you know, this, you know, we, we eliminated this one and then it pops up over here. We eliminated that one, it pops up over there.
And if you look at this kind of classic computer system hierarchy with processors and memory and storage, uh, you know, storage for a long time was just the ultimate bottleneck with SSD that has been, um, dramatically reduced, as you say, with things like NVME and now with, uh, you know, ethernet networking, uh, a lot not to mention proprietary networks, it's been reduced further, but the demand for data from these AI processors is just absolutely off the charts. It's insatiable. And, you know, one of the things we've heard about repeatedly on this season and the last here on utilizing tech is the, basically the need to feed the beast.
If you are not keeping your expensive GPUs fed, then you're essentially wasting money every minute, every hour, uh, that they're, that they're not working at maximum capacity. That's pretty much what companies are looking at CCA to solve with software, right? Yeah, I mean, the, the limiting factor with, uh, a large data center enterprise scale GPU today is memory capacity.
Um, the amount of parallel compute available in, uh, a cutting edge GPU is mind blowing, but the, the memory footprint on each card is just not where the processes that are running today, um, needs to be. And our aim is to be able to augment that memory with a place where essentially you can tier the data that should be in memory off to WCA at such a data rate, that it can also be retrieved so fast that it becomes practical to, to now scale your memory footprint into petabytes, uh, of space. Um, there's obviously, you know, we're talking tiers of performance here, but when we're able to outperform in some cases what DRAM could provide to GPU memory, um, at that type of scale, you know, hundreds of petabytes if you like.
Um, it really starts to be a paradigm change. The, um, the amount of, the amount of time spent, for example, in LLM processes, during pre-fill calculating, uh, key values and creating KV cash data. A lot of the time this will either just be cached to, uh, DRAM or to local NVME as KV cash, but this could only be used by other GPUs inside the same server within, or within the same, uh, ENV link.
And now we can drop all of that KV cash out to, to WCA and make it available not just to other GPUs in the same server, but to every single GPU in the entire data center. Um, and at rates where, for example, to calculate around 105,000 tokens, uh, of prefilled takes around 25 seconds on GPU, we've able to, we've been able to take that same KB cache, place it back into GPU memory in around half a second. So we're talking for a more than four a almost 50 x, uh, speed up in some cases.
Um, and, and every time there's any query that's performed on an LLM and this KB cache is generated, we can just keep that for as long as that model is around. Um, so it never has to be recalculated again. So the more and more and more that queries are common across, um, multiple processes or customers, we just don't ever have to calculate it again.
Um, and then the GPU can get on with the, the meaty part, which is, um, deco. Yeah, you bring up an interesting point about the, the idea of the tiering, right? Because we, we all looked at it as kind of, if you think of the hype cycle and all this kinda stuff, I brought this up with some of the other examples that we've gone through in this season, but we're at the point now where people realize they need more of something, and that something is really being able to offload and, and shift the performance tier into an aspect of a larger footprint.
Like, for example, the, the massive drives that we can provide give you those petabytes of storage that can look like that fast memory just because if you overload the memory, again, moving bottleneck to bottleneck to bottleneck, the, the eliminating of those bottlenecks is really kind of the key here. And, you know, fast delivery to your point. Um, it's really cool, you guys have had the, the ability to highlight the performance characteristics in real time, which you guys are up to with some of the work you've done in some of the recent venues that have come to light.
So it, it's really interesting to see how you guys have been able to transform the idea that it's really more about the data and not where the data is sitting and being able to ma let the user maximize their hardware configuration by way, what you can do with your software. Yeah, Right. For example, the, probably the most prominent place that WCA could be seen in action would be the Las Vegas sphere, right?
So it, it feeds data to, to that screen. It's involved in rendering, it's involved in carving, um, at this point it's touching pretty much every aspect of, um, content creation and, uh, and delivery to the screen. Um, and, and we, we've seen enough interest off this where other large scale venues are, are looking to, to do the same.
Um, it's just being able to deliver this type of performance over a network is, I mean, I don't wanna say that we don't have any competition, but there's, there's nothing else right now that is able to hit these numbers that, um, that are also built that can scale up to the correct size, not just in performance, but in capacity. Um, this is obviously the trade off, right? I mean, you look at systems that historically have been extremely performant.
They're usually direct attached. If you want 'em to be a little bigger, you would switch to something like San, um, that's not, was never quite as performant as direct attached storage, but it could be much bigger. And then you could go bigger still and reduce some of the complexity by deploying Nest, which would be slower still, but could go larger.
And then if you wanted stupid scale, you could go to object. And also your performance goes through the floor. So the place where WCA sits really is beating the director type storage performance and also scaling all the way up to object.
Um, and customers that have these massive high performance requirements and large scale, um, are coming and trying our product. We just can't really find anything else that can head with those metrics. So, um, I'm sure people will catch up, but today it's a good place to be.
If, if I can provide a little background in there from a long time storage nerd. Um, you know, it's funny that people talk about, uh, you know, what you just talked about San and Nas and object, the, the, the scalability and performance of those is really a, a function not of the intrinsic element or nature of the storage or the storage protocol. It's about basically the modernization of the, uh, delivery mechanism and the software that's being, that's constructed to build, to, to deliver those.
Um, and I think that that's sort of the insight that some of these companies recently have had is that, you know, the reason that, uh, direct attached storage was high performance was because it was dedicated. Uh, and the reason that, uh, object storage scaled so, so, so well was because it was distributed. And the idea that you could build a massive scale solution that would kind of combine the best of all possible worlds with, uh, with software is really the reason that so many of these modern systems are able to scale.
Frankly, it reminds me a lot of Kubernetes and the cloud, and frankly, AI itself. I mean, the reason that ai, uh, processing is so incredibly power consuming and high performing is because of this whole idea of distributing it, breaking it up into small tasks and distributing it massively among multiple nodes and parallel. That's exactly what's been going on in the leading, uh, software for storage.
And, and that's the reason I think that CCA is able to scale the way it does. It's not because, um, of some, you know, specialized little trick in there, it's simply because the system scales to just incredible levels, just like the cloud does, just like AI does. And I think that that makes it uniquely suited for this AI application because it's such a scalable platform because everything is just completely distributed.
There aren't, there isn't some, some, you know, monolith somewhere that says, you know, this is only how fast it can run. Everything is distributed, everything is run in software. I think that's how people think that things work, but not everything works that way.
And, and, and yours certainly does. Yeah, I mean, you touched on one technology that has been instrumental in achieving planetary scale in anything, and that's Kubernetes. Um, and the, the ability to orchestrate containerization in, in a way where as long as you can provide the resources behind it, you can scale horizontally in a, in an extremely resilient and redundant fashion, um, is, is phenomenal.
Um, so WCA released, released recently, uh, its own WCA operator where you can actually provision an entire WCA cluster or multiple w clusters, uh, deployed fully in Kubernetes. So if, if a Kubernetes based, um, has compute that already has NVME available in it, and that is all siloed per server, installing, installing WCA via Kubernetes now allows you to bundle all of this NVME in a one giant file system that is available to every single server. Um, and if you, if you're in a multi-tenancy environment, you could actually compose more than one cluster in this environment shared across that, that infrastructure with each customer having its own, um, its own entire dedicated cluster with cluster admin privileges per custom, um, I dunno, another product that's doing that to date.
But it's, it's pretty wild. I mean, normally, normally you would treat storage like, um, like pets and everything else could be treated like cattle. Um, but today actually, actually being able to run, uh, storage in a cattle ranch is, um, pretty interesting.
It's pretty wild. I really do appreciate that you're, uh, putting some focus on storage. I mean, we've been the overlooked, uh, you know, pet, uh, for quite some time.
I'm not sure if I like being a pet or on the cattle w Ranch, but at least maybe I'm the, the dog managing the cattle. I like that idea. Uh, but it's interesting because you, you talk about these ability to shift, uh, access to information across multiple points of physical location, which plays well into our conversations of this kind of season around edge, how far away some of those platforms can be from the user or the operator, right?
Because we all have this different definition of the word edge, and we've talked about those definitions all season. Uh, but realistically, I mean, how far out there are you guys seeing that the future of what would be classified as your ability to reach closer and closer to where the data generation point is? Are there certain platforms or, or solutions that you're kind of investigating or already working on?
Yeah, it's funny. Uh, I think the, uh, the definition of edge moves probably more often than the bottleneck moves, right? Is, um, you know, and also one, one person's, uh, edge infrastructure could be larger than another's core infrastructure.
Um, and certainly some organizations, the amount of edge infrastructure they may have, uh, can vastly outweigh what they have as core. Um, but I think, I think as we see more robotics, uh, appearing in the world, as we see more, um, more healthcare being more tech driven, um, the, the ability to feed data to all of these compute processes that are literally out there in the world, not, um, not not sitting in a data center, is gonna become more important. Um, that will require different, different stages, different tiers, fantastic data movement between all these tiers.
Um, so yeah, I mean, edge Network is gonna be really important. Uh, edge data centers, um, edge storage within them, data tiering from there, back to much larger data centers. All the orchestration of this is, um, you know, it's an intense focus for, for cca.
And, uh, you know, we, we wanna make sure that as that whole we world gets more complex, that we, we stay at the forefront of it. And I, I think the nature of the solution too, kind of matches the needs there too, be because, because it's built up of sort of this parallel architecture, you can scale up and scale down very effectively. So you can use it at smaller scale in, well, comparatively smaller scale, uh, for, you know, AI processing outside the, the, the data center.
And then you can ramp it right up, uh, to massive scale, and then you can use your tools to enable data to make that leap from, you know, location to location from size. And I think that that's, again, ma that, that matches the way that people wish that software worked, but it doesn't always work that way. Yeah, I mean, so we have, um, we have customers right now, for example, running, um, autonomous vehicles all around the world who are generating massive amounts of metrics, um, and trying to send all that home, um, is not very efficient.
So deploying WCA in many, many different data centers all around the world that can be as close to these vehicles as possible to collect all their metal, um, clean them and, you know, reduce their size and then set all of that, um, back to a, back to a core for additional research, for additional training and modeling is, um, is a place where Weck has been really successful. As, as, uh, that type of autonomy moves into additional places within the edge, um, with more robotics, I think we're gonna see, we're gonna see a lot, a lot more of that. Another place that we've been successful is within media entertainment as well, where the edge can serve to, to provide, uh, tool sets to talent that can be all around the world, because talent is something you can't really scale.
You know, you have to find talent where it resides. Many, many companies have to set up infrastructure where you might, um, you might make a, a tool set available to, to people for either a permanent or a temporary amount of time, but they need huge performance within the, the compute, within the storage, within rendering. Um, and all of this has to be able to seamlessly communicate with all of the other parties that are participating in the same project workflow, for example.
Um, so we've, we've had great success there. Um, particularly in cloud, we've, we've watched customers being able to deploy temporary setups in different countries where you wouldn't even have normally any footprint, um, employ talent in that area, tear it all down when the project's finished, and while you're bringing up more someplace else for a, for another project. Um, that's been, there's bit of a game changer actually, When people think of ai, especially nowadays.
Uh, I think a lot of them are just focused on chatbots and chatbots and more chatbots. But of course, there's a lot more being done with this technology, whether it is using AI and ML in different ways or using HPC, uh, for other related applications. I know that you all are involved in some of that.
Can you, can you tell us a little bit about some other, uh, applications for this technology? Yeah, I mean, for example, we have, um, few companies in, in, in health and life sciences who are trying to solve some of the, the hardest problems in the world here that really matter to people. Uh, Memorial Sloan Kettering, for example, deployed WCA to help speed up their, their modeling, um, in the pursuit to solve many cancers.
Um, and they have managed to massively contract the time it takes to coherence for a model and massively reduce energy footprint in the same time just by being able to achieve more miles per gallon on the exact same hardware in a shorter time. Um, so this, this is gonna be a game changer if, if Memorial Sloan Kitten can actually achieve what they think they can in the next few years, um, which really excites me. I mean, it's fun to work on media entertainment, it's fun to work on, uh, cars, you know, many things, but when you actually see life changing, um, work being done, it's quite humbling.
Absolutely. And, um, and it's always fun to hear about technology, as I said, that's not just, um, you know, not just the same old thing that people are, that people are thinking of and, and using AI in, in new and exciting ways. Um, thanks so much, uh, for this incredible conversation.
Um, Scott, this is our last episode of the season. com, they'll find both of those seasons along with, uh, six other seasons, uh, previously. Um, I, I guess before we go, Scott, uh, sum up a little bit about season eight ai, uh, AI data infrastructure, AI at the edge.
How exactly, um, should people be thinking about, uh, data infrastructure and storage for ai? Yeah, I appreciate that, and it has been a, it's been a lot of fun this season, and I know Janice has had fun over a couple of seasons as well as my coworker Ace. Um, from our perspective and from my personal perspective, it's just AI is, is a shiny object, right?
It, it is something that's very real. It's very true. But the fact that we're combining AI and now where we're generating the data and we're generating so much data nowadays, it, it's unique to think that people don't tend to realize as much that you have to put that data somewhere.
And a lot of this season, it, whether we intentional or not, has been focused on the advent and benefit of storage. And so it's kind of cool as a, as a long time storage guide to see the value and the benefits of what we see in our daily lives coming through to everyone else's as something of value. Because you, you spend so much time working on data, and that data always seems to be, you know, the, the star of the show in certain different processing and things like that.
But as you saw through the season, if you go back and look at it, we've talked to a whole bunch of different ways of looking at managing data, focusing on data, and all of that revolves around where the data sits. And the data doesn't always just sit in a CPU or dram, which are wonderful toys and tools, but it does have to, you know, have a long time, uh, placement of that. So I, I see that as kind one of the bigger nuts of this whole season, is just, it's, it's cool to know that storage is really getting a, a play in the space, and all these companies are doing so many cool innovations to again, shift those bottlenecks and, and talk about it, whether it's the industry standards bodies, the software platforms, the hardware platforms, a combination of all that.
So it's been a great season. I've had a lot of fun, and I've learned a lot myself. Well, thanks a lot.
Yeah, it, it has been a great season for me as well. Uh, obviously an old time storage nerd here. It's fun to see where this, uh, industry is headed.
And, and it is fun to see just how all of those things that we wished we could do have, in many cases come true with modern software. So just, just incredible overall. Um, Alan, again, thank you for joining us and representing WCA here on Utilizing Tech.
Um, as we wrap up this episode, where can people connect with you and continue this conversation? So actually, uh, this week, um, 18 to the 19th, WCA will be presenting, um, at the three big AI conferences, uh, San Francisco, London, and Singapore. So yeah, if you can make it down to those, please, uh, comment in, hear what we're all about.
Great. Uh, Scott, uh, I guess going forward, uh, where can people continue speaking with you and your colleagues and, and learning more about Soy? Yeah, for Soy, it's pretty straightforward.
com/ai/ai and uh, also you can find me on LinkedIn, blue Sky, and, uh, Twitter, formerly known as or ex, formerly known as Twitter at SM Shaley, uh, I tend to spend a lot of time having fun, sharing insights and just being a little bit social. So, Yep. And you'll find me as s foskett on most of the socials, including, uh, blue Sky and Mastodon as well, uh, and of course on LinkedIn.
Thanks for listening to this episode of Utilizing Tech. Uh, you can find this podcast in your favorite podcast application as well as on YouTube as mentioned. This is the last episode of season eight.
Uh, yes, that's right. There are eight seasons of this, and you can go back and listen to those, uh, all the way back to, to the pre-chat GPT era. If you enjoyed this discussion, please do leave us a rating and review.
It's really nice to see those. This podcast was brought to you by soine this season, as well as Tech Field Day, which is now part of the Futurum Group. com or find us on X Twitter, blue sky, or Mastodon at Utilizing Tech.
Thanks for listening, and we catch you next season on Utilizing Tech. Hey everyone, welcome back here to our live coverage of RSA conference 2025. We are in Moscone West on what they call Broadcast Alley, and we've been doing mostly the interviews of people here at the show, and we're gonna do that today.
But really this is a special edition of our DevSecOps Show, cracking the code, which we do like every other week. Anyway, um, cracking the codes available on your favorite podcast, uh, platform, whatever that may be. Exelon, Textron tv, YouTube's Textron TV channel.
And by the time you watch this, probably our Textron TV OTT channel. So you could watch this on Apple TV or Roku or Amazon or whatever you'd like. The important thing is to watch it on cracking the code, we explore the frontiers of DevSecOps.
Um, and just yesterday we had our 10th annual DevSecOps event here at the RSA conference, and it was about ai, AppSec and app dev. Great, great show. We have actually some of our speakers here today, were there yesterday.
Um, but let me introduce you to today's panel for this episode of Cracking the Code. I'm gonna start to my far right, this gentleman here, Aaron. Yeah.
Kranzberg. Yes. Aaron is, um, with Check Marks, who of course is the sponsor of our Cracking the Code show, our partner in producing it around.
It's great to have you on in person across the table from me. Yeah. Thank you for having me.
Uh, thank you. Uh, I run the product marketing for check marks and, uh, excited about the show. We are hearing ama hearing amazing things, uh, at, uh, RSA so far.
Good, happy to share them with you guys. Absolutely. It's great to have you on.
I've said this before, Iran and I go back a little while, even before check marks and everything else, so it's great to be working with him again next to Iran. This little lady right here is a firecracker. She came to our show yesterday and lit it up at the, on the stage there.
And she was up, she was in the panel with the CIO, the CISO CSOs of Open AI and anthropic and senior security people from Meta But she had the most to say. Her name is Morran. Ashkenazi Morran, welcome and thank you.
Thank You, Aaron. Pleasure to be here. Thank you for having me.
Pleasure. Yesterday was amazing panel. Super interesting to get everyone's thoughts, so excellent, happy, happy to be here.
I from tell people a little bit about you. Yeah. So I'm Jfr, chief Security Officer.
I'm within Jfr for five and a half years. It's amazing because we're doing our own journey into the security and we're at a DevOps company and out DevSecOps company that's providing a whole solution for the supply chain insecure with ai, uh, everything they simple built. Absolutely.
Of course, our audience is no stranger to check marks or j Rog for that matter. Well, let me introduce you to our third, third guest. Tyler, I blanked on your last name, Egypt.
I apologize. Egypt. It's all right.
How do you pronounce it? Egypt. Egypt.
Mm-hmm. Tyler, Egypt. Tyler, why don't you introduce yourself?
I appreciate it. Thanks for having me here. So, my name is Tyler Egypt.
I'm our Vice President of Global Enablement at check marks. So I work closely with, uh, enabling, uh, not only the field at check marks, but also our customers and partners bringing awareness around AppSec, uh, and the great capabilities that we have and offer. So, very excited to talk about DevSecOps and some of the advancements we've seen and, uh, especially at this event of, uh, learning more and more about trends across the products.
Absolutely. So let me kick things off. You know, as I mentioned yesterday was our 10th annual DevSecOps Connect here.
I remember 10 years ago, it was like having a wedding where the in-laws didn't get along. Right. So a one side of the audience at the security people on one side of the audience sat the DevOps people.
And I like, I could build a wall in the middle. Yeah, right? True.
You could. They just wouldn't come together. A lot's happened in 10 years.
They have come together. DevSecOps is real. We all realize that we all want to have better code, more secure code.
I've never met one developer who raised their hand and said, I, I don't care about the security of my code. They all care. It's quality.
They have pride in what they do. Security people, they're the old, and I'm a security person, I should say. We used to say no one cares about security, but us, excuse me, only we can care about security.
But we realize now everyone cares about security from the highest levels of our companies on down. So we made a lot of progress, but we've also made some mistakes. I think one of those mistakes was like we do with everything else.
We, we took our security tools designed by security people and said, here, developer, Good luck. Good Luck. Enjoy.
Yeah. Well, that, that didn't work out so well. Did it.
Right. And and the reason is is they're not security people. So a lot of DevSecOps companies died on the side of the road with that.
Right. And it's interesting because we got two different companies here, check Marks. You are an AppSec company from the day you were FI remember when Check Marks was founded.
Yep. Mm-hmm. Jfr, you weren't No, you were a developer company and, and a Artifactory.
Right? Right. But you've come, you know, parallel evolution to the same point of what do we need to make developers successful?
Yeah. And so I I'll ask all of you Yeah. What, what is this magic formula?
What's the secret sauce to enabling developers to develop more secure code? And please don't tell me it's ai. No, it's not.
Okay. It's who wants, who wants not today anyway. Yeah.
Who wants to go first? Tyler, we're gonna make you go first. Absolutely.
So we, like you said, developers take pride in their work. Uh, they want to deliver code on time, uh, with security in mind, but they need to be empowered to, uh, understand the risk that's involved. And they need to be guided and helped with, uh, how they address those, the risks that's created.
So we found understanding that developer experience, uh, working in their existing workflows within their existing tool set, um, is extremely important. So we're not disrupting their flow. We're giving them the right information at the right time.
So they're the catalyst to change, uh, and, and improve their DevSecOps footprint at the company. So we know they're a key part of DevSecOps and the ones that are gonna be driving the majority of the fixes. So really meeting them where they work, a common theme.
We've seen, um, more codes being generated by AI and productivities going through the roof right now. We're seeing, but that also adds layers of complexity, uh, uncertainty. Um, so we need to really understand, again, how they're writing modern code with modern applications, what risk that presents them, and then let's empower them to, uh, address that risk with the right kind of information and guide us.
So that's kind of where we've seen that collaboration come together. And, uh, yeah, both parties need to work together to make a, you know, advancements within software delivery. So it's, it's their need more on, I think that, uh, we learn from mistakes.
That's, uh, that's something that both humans and We learn more from mistakes than we do from success sometimes. And absolutely. And I think that both side understand that we depends on each other.
We cannot do that independently. Security cannot do anything without the right partners to drive it. We can bring the product, but it's a banner of, uh, uh, democratization.
Developers need to have the platforms and choose the right tools that will accelerate their day to day and not like find them, like we're, we're talking about like the shift left. So it need to be like in their IDE, something very natural, very native, not go to a different interface, try to find a CVE, try to vulnerability, try to fix it, go back to the code, go back to the malicious package, go back. It need to be very na natively, not extra work, and need to be very effective.
'cause by the end of the day, they want to like focus on releasing a product, a perfect product and innovative feature. And that's it. They don't care about security.
Yeah. But on the other hand, they do need to like implement that. They need to really secure software.
Right. Because it's their, it's your code. You, you own it, you own it.
So both side need to come together. So that's the thing that, that's the point. I, I agree.
They, they do need to come together and they have let, let's, I don't want to give a false narrative. Right. We've made a tremendous amount of progress.
If you were out there yesterday, you couldn't tell who was who, where they were sitting. They're all mixed in. So we've made progress there.
I wonder, it's funny. So you come from the security side, you come from the developer side. When you are talking to security folks, did they say, but you're not a security company, right?
And vice versa. Well, you are not a developer tools company. You're a security company.
How do you get credibility across the aisle, Aaron, around any thoughts? Of course. Uh, so I think, uh, and you mentioned like 10, 10 years ago and now, okay.
I think that today you're no longer working in silos. Okay? So it's not, you're a developer, you security, they all have the same objectives of releasing high quality software highly secured.
And what is changing is the scale. Okay? More pipelines, more development teams, higher, higher sized developer teams.
Uh, and these guys need to trust what they're using. Okay? So the word trust here, I think is a key word because these guys, whether it's they were the head of a security or developer or quality engineer or platform engineering leader, they need to have the trust in their tools that will get them towards their objectives.
And their objective are the same. Zero fibers in production, higher security. Because we know that these guys are dealing with, I dunno, 60, 70, 80, sometimes 90% of open source code.
Most of the code that they're using is not even theirs. Okay. So if they, maybe they don't trust the code that they're using coming from others, they should trust the tools that we are giving them with check marks, with j fog that will get them towards, you know, uh, the finish line successfully.
And another keyword is trust and continuously, right. Okay. What you see today is not what you see tomorrow.
Every, like, the minute, the minute I'm speaking with you here, Ellen, someone is working on a new malicious package. Right? Right.
So, uh, it's a moment in time if you like Morran. Any thoughts on that? Yeah, I think that, uh, totally agree with you.
It's about the speed is just, uh, something that we cannot control anymore. It just, it's, it's there. It's running super fast and you need to have like, automation as part of it.
So that's the part of the lifecycle need to go grow and fast. Therefore, it's like different motivations. I want the security, I want the product to be super secure and r and d want it to be fast and we need to collaborate to make it, to make it happen.
So it's different motivation, but single target to get this done. Uh, and it's okay to have like different motivation in order to, to make it happen. Definitely.
Yeah. I want to talk about another dev ecop principle that I think has undergone a big change. Yeah.
com 20 14, 20 13, actually shift left. Everything was shift left, right? I gotta tell you the truth.
I'm of the opinion now, you gotta shift everywhere. Mm-hmm. But what do you think about shift left as it was, let's say eight, 10 years ago versus today?
I think it has been changed because we understand that it's not just the shift left, it's also shift right to the runtime shift up to the cloud. Yeah. It's like, like Shift out to the earth, Turn around and around.
It's all over. That's the it every wrap. Yeah, it is.
And that's the security Yeah. Mission. Now Every chain in the, the lifecycle Agree.
Right? So I think we've recognized these things and, and they've manifested themselves into tools, security tools that are easier for the developers to use. Built into the IDE for your instance, I know check marks they made, I think you made an announcement here at RSAI got the, uh, yes.
Embargo. Yes. You're building, uh, into IDE.
Correct. So we've had, uh, integration in the IDE on understanding risk, whether it's the custom code you wrote, your open source software, infrastructures, codes, that's all been available. What we recently announced was, uh, our application security, posture management right.
View of those results. So now not only do you have this large, uh, list, hopefully that's reducing over time, but this large list of findings, but we're helping the developers prioritize on which actions to take on which items are most critical. So that's, this goes back to balance.
If you look at what we're asking modern developers to do today, their responsibilities have grown. So they need to be understanding way more, you know, whether it's new languages and frameworks, whether it's, uh, cloud native development and understanding how, uh, the application will be deployed. That's, we're getting faster, but we're also adding more complexity as a result of it.
Um, so what we introduced in the, uh, IDE is giving them the, a very, uh, condensed and focused view so we're not overwhelming them and to what you were alluding to earlier, um, meeting them in the IDE. So it's, there's no context switching. So as a developer, I'm doing my day-to-day activities trying to produce quality, cook quality code quickly.
Um, and this allows me to address risk along that process. So it's not switching to different products or different views logging into different systems. And we've seen as a result of this, that developer time to fix is drastically decrease.
So now we're helping in, uh, not only prioritize, but the speed to fix is a new concern that we're addressing as well. Yeah. Fair, fair.
Now, Maran, I, I know, I know j Frog's history and story, right? You didn't just make a developer tool friendly for security people. You j Frog's actually acquired several right.
Security vendors, correct? I think you come For one we acquired Yeah. Vision that became jfr Advanced Security, which I, I'll talk about it.
And also Qua that became J froog. Ml. Ml.
Yeah. And going back to the shift left, the, the reason that we're, I super like support that it's because it's about efficiency of the software development lifecycle. When it's shift lab, when you identify the true issues that you need to focus on, that will really save the time, right?
So be effective with that and understand the full lifecycle, but as, as, as soon as possible, if it's like malicious package or there is like malicious even model in LLM now. So think about the full dimensions that is, is operating in order to create a new application and try to push it as soon as possible. So it'll be like time, it's time consuming.
So if you can do that as fast as you can, it's a plus for everyone. And developers want it, but it must be very focused and not like spam, uh, different tools on the ID plugin, but consider everything, prioritize that, make sure that it's, validate that it's applicable and save time. Yeah, Agreed.
If I can just add on top of that, I think, uh, what Tara and Moran was saying, it's exactly, you know, we are seeing today, uh, with the advancements of technology, uh, developers being overwhelmed with so much findings, okay? They don't know where to start. Okay?
There is too much noise in some cases, a lot of false positives, okay? At the end of the day, they need to get the job done, okay? They have a feature that they need to fix, they have a bug they need to fix, they need to manage their pipelines.
The more you reduce the noise on their end and walk within, of course the ID like serving them where, where they are, you are actually talking, going back to the trust, right? You are building the trust into the workflow of software development. And that, in my mind, can transform developers into security champions because we know developers are not security champions by definition.
Right? But if you feed them with the right amount of security training, security, findings, prioritization, risk management, right? Uh, with this A SPM, the idea, we actually also introduced protocol, uh, a very, uh, modern scoring, uh, algorithm.
So it's not just that you're prioritizing that based on, you know, the severity of any findings, but actually what matters most to the developers so they can actually get their only unique report that they need to take, take care of the most unique CV that they need to take care of and whatever. So, uh, dev experience, user friendly, reduction of noise, these are the things that in my mind matter and allows developers to adopt more user security tools. Yeah.
And, uh, the tools. And that's the power of platform. I think that is, we're talking about like platform engineering.
Yes. That's the power of platform to unify and give a context. So it'll be very clear, very like, precise.
We're gonna jump into platform engineering in a moment, but I want to focus just on platform for a second. Yeah. I, I did an interview, I did a few interviews over the last couple of days, and this whole concept of platform came up.
I've been in security 30 plus years. One thing I've learned about the security business is small companies, little fish, they make what they call products, then medium sized companies, they look at those products as features. Mm-hmm.
And they buy the little fish and they roll those products up as features into their products. And they think they have the product and we sell point products, but then the bigger fish, they say, no, we don't want products, we want platforms. Yes.
And my platform has multiple products in it, not just my products. We plug in, we connect API, whatever, we connect to other products into this holistic platform. Yeah.
And that's really where companies want to be. And not only vendors. Yeah.
But end user companies. Yeah. Consumers.
Yeah. Consumers. They don't want 27, 36 integrations point products.
Yes. They want a platform that handles this mission for them. And so I think it behooves all of us, you know, of course everybody wants to be the platform.
You're a platform, you're a plat, we're all a platform, right? That doesn't work either. Right.
But we want these tools to work together better. And that's, I think a, a, a key piece of it. I want to turn to platform engineering.
Sure. com about, uh, eight months ago now. org.
Very big. He's A great guy. Yeah.
200, 300,000 members there. Luca and I, and the check marks people do our platform engineering show every other week. Yeah.
And round tables and stuff. And we've spoken about this on that show, right? That if we could give the developers a platform that is both secure, tested, stable, scalable, and just say, developer, do what you like to do.
Exactly. Develop, focus on That. Look, just Develop go code, go as fast as you could go.
Yeah. That's what we need. Right?
That's, and that's, I think at, at the Nugget, that's the appeal of platform engineering. Yeah. I know how check marks is working with them.
How does J Rog view that platform engineering? That's the, that's J Rog story. It's about DevSecOps for real, right?
Come from a company that did like DevOps and get into security world, but in a very natural way for the developers. It's bring developers into the security and and really connect, be the glue that connect between them. And that's exactly the power of the, of the platform.
Because you don't need to go to a different, you just got everything on a single place. And that's trusted releases. Um, combine those two together.
Yeah. Alright. So I think within platform engineering and what we call an IDP, right?
An internal developer, uh, platform portal, everyone is using the p in a different way, by the way. Uh, so I think if you give these guys the developers, uh, a centralized portfolio, if you like, of the best of breed platform for security, for, uh, I know for cloud, for whatever they need to get the job done. Uh, that's also how you build trust.
But also that's how you take, um, people look at platform engineering as the next level or next evolution of DevOps. Okay? It doesn't replace DevOps.
It's kind of built on top of DevOps to optimize these pipelines to optimize the software development life cycle. But also, I've spoken with one of the analysts the other day also to put some safeguards on the tools that are being used, uh, and governed and controlled within the, the, you mentioned earlier, Alan, these different point solutions, right? Right.
So with so many platforms, so many different tools, especially when you're dealing with enterprises, you need a governed approach to different tool chains within, uh, the organization. And when you're dealing with, I know, 100 dev teams with thousands of pipelines, what you don't, you do want to give them, uh, the freedom of choice of tools and platforms, but you also want to control that. And platform engineering brings this governance into the software development lifecycle.
Yeah. I think that they're not, you know, dedicated as the knowledge, the right knowledge to do. They can accelerate that and give them that as a platform.
They don't need to be security expert. They don't need to be, uh, even like a legal expert or privacy expert, especially in ILLM. But they do need to, to just consume it, consume it as a service.
And that's the change I think that we are going To see. I think the service that's the right, the right word here, Right? The service and application, which is like, it's the higher level.
It's not just the DevOps, it's just application that combine everything together. The security of the DevOps. Agreed.
Let me turn now to another topic. 'cause we are going low on time. But look, we're here at RSA.
You can't walk more than five feet without tripping over ai. There's AI agents, there's generative ai, there's that ai, there's ml, there's everything. Both of your companies at Jfr and Checkmarx have news around ai Yep.
And have put big bets, right? Uh, J Jfr ml, Right? You have AI agents.
Yes. I just spoke to Sandeep, the, uh, CEO about. Yeah.
How real, how big is ai? So is AI taking any jobs away here, or is AI making us better? If not, when will it, is it more talk at this point than real thoughts?
So I, I can start. So ai, uh, serves a specific use case, okay? And each, let's say agent serves a specific use case for the developers, for the security engineers, whatever persona is using that.
So a AI is not going to replace anyone's or take anyone's job. I think that what we're going to see eventually, and we, we need to just put it on the table. AI or people that are using AI are going to replace people that are not using ai.
Okay? So if you are today in the software development lifecycle, doing anything like from QA to dev to security, production monitoring, observability, I'm coming also from a previous observability space, they are all looking at ai. So if you're not going to start getting used to the fact that AI is kind of your co-pilot, your, uh, supporter in everything that you need to do, someone that uses AI will replace you.
So AI is going to be driven by engineering, okay. By engineers, uh, as part of the software development life cycle. Okay?
But it's not going to replace jobs for people in my mind that are just going to aid, uh, you know, bottlenecks or whatever challenges that these guys have and support them, uh, through their journey. So that's a, a short answer. I think they will replace humans in a lot of, uh, manual work.
People that are, that they're doing it today. It'll get into every position, not just like engineering. It'll replace in every, like, uh, every job in a company.
We're going to see, um, displacement, uh, for sure in support, uh, chat bot, replace support, you know, humans. So think about what AI will do, uh, about related to documentation. So many different aspects of service providers that will be totally improved and accelerate.
But I said it yesterday, I do think that the human factor is still very strong. And this is like our responsibility to make sure that we're doing the right thing. We're using it carefully, we're putting the right guardrails, putting the right foundations.
Yeah. Um, and it's in every several dimensions. Like the infrastructure need to be like aligned.
We have to put the right skeleton, the right model, um, due diligence, the models to make sure there won't be like data exfiltration and data poisoning. And then it's continue with AI agents understand what are their guard drills, what is the identity and access management, if it's like something that we implemented, reduce the, the actions that they can do, especially for various critical service and critical commands and operation or with sensitive data limit that align with the regulation. Make sure that we are aligned with the law.
Um, if, if autonomous AI agent will share data between us and, and, and, and uk, what about GDPR? How can I confirm that this identity is doing what it need to be done from legislation perspective? And that's a lot of things to do, or different dimension that we'll need to take care of them.
So we are going to focus on control them, manage it, do it the right thing, take it slowly, but it'll run fast. That's what I think. Fair.
Yeah. Fair. Tyler, what about you?
Yeah, I'll just add, so it's gonna, the jury's still out. It's obviously, uh, AI's here to stay. So that ship has sailed, but how it's being used, I think we're still waiting to see what's truly, uh, impactful in making a difference.
There's a lot of noise around adding AI to certain product capabilities, but it goes back to what problem are we actually trying to solve, and how is it really, uh, empowering, especially in our case, the developers and security teams to work better together and remove a lot of what they call like developer toil or those mundane tasks that can be easily replaced by something like an agent ai. So, uh, we're excited to see and uh, we, we've launched a, a concept that we're working with our customers to really fit into their needs and understand their workflows. But it'll be, uh, I think pretty groundbreaking, exciting to see how that plays out.
And then, uh, if, if I could boil down, you know, the DevSecOps movement and, and focusing on the people and the processes, uh, AI's really gonna focus on the processes and I think that's a good movement for understanding, uh, the model of DevSecOps. Everybody's kind of singing off the same sheet of music and there's alignment as far as how the processes work together and what everybody's role in that is. So, uh, yeah, definitely exciting times and seeing how it plays out though.
Fair enough. So one last question, we'll wrap up as we sit here today, really the first full day of RSAC in terms of keynotes and sessions, expo hall, are you bullish on DevSecOps? Do you think the best is yet to come?
Or do we, is there another direction we need to go in? What's your thought? Uh, I think it's evolutionary.
So it, it will build on what we are doing today. We're learning from what works and where we failed and where we can improve. I think we're only getting faster with the new, uh, AI capabilities and really having us look internally on what is working and what isn't.
Um, so I think, uh, it's exciting to see a lot of the consolidation around what's happening in our space. Um, and a lot of the great insights or context that we can derive from that. Uh, so I do think anytime you can get people together to solve the same types of problems, it's a powerful thing.
So I think, uh, I don't think there's a way around it and I think it's the right trend. It just will grow and, uh, evolve over time. Well, I don't, I'm gonna give you the last phrase.
Yeah. I don't think we are bullish, but I think we are reacting to the trends for sure. 'cause uh, just like cloud, it just started and everyone just start, you know, seen up and, and, and that, uh, same goes with ai.
So everyone are talking about MCP right now, right? Because it just started and then it's like a storm. Everyone are doing it.
So I do think that we're reacting to new trends and new technology and that, that makes sense. So reacting to that, just focus on doing the right thing and do and provide an holistic solution to drive that. Yeah.
Love it. Alright, that's gonna wrap us up here. You've just watched another episode of cracking the Code, the DevSecOps Show.
We'll be back live with more RSA conference coverage in just a moment. If you're not watching this live, you catch it on Apple or Spotify or YouTube or something. I'm sorry you weren't here to see it live, but we're doing our best to bring it to you.
I'm Alan Shimel. We're out.