Techstrong TV – March 18, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hi, everyone. St. Patty's Day is over.
We're back at it. Is there an AI chip crisis? We've got AI in Margaritaville.
You're watching Textron Gang. Hi everyone, it's Alan Shimmel here for Textron Gang. Happy Tuesday to you.
We hope you had a fantastic St. Patrick's Day. If, if you celebrate St.
Patty's Day, everyone likes to celebrate St. Patty's Day, it seems. But um, anyway, it's Tuesday.
It's back to work time, and we've got work to do and, and you know, there's lots of good stuff going on out there to talk about, and we've got some great people here to talk about it with. We, we've got a Core four for today. Lineup first.
Uh, we have the guitar man out in Colorado there. He's a Futur vp DevOps analyst, Mitch Ashley. Hey, Mitch.
How are you? Good. Good.
I'm gonna adopt a new theme song, inferencing Away Again in Margaritaville. Okay. I like that.
Rich. I like that. You didn't use AI to write that, did you?
No, I did not. Oh, because I figured AI just stole the tune from somewhere or something. I don't, It wasn't that good.
Yeah. Movie movie from Colorado to Hudson, Ohio in the world, in the data center world. Uh, it's Steven Foskett.
Uh, Steven of course is CEO, founder of Tech Field Day Fu Company, and a bonafide gang member here. Yeah. Hey, Steven.
How are you? Pretty good. Pretty good.
Um, local Mexican restaurant here had, uh, corn, beef and cabbage tacos, if you can believe it, for, uh, St. Patrick's Day. Uh, so, um, I, I didn't, didn't partake In that.
Couldn't do it. Huh? I had, um, uh, corn beef and cabbage egg rolls over at Miller's Alehouse.
Sounds good. Will they? Sounds good.
Fed, middling. You gotta put a lot of mustard on them. Um, but anyway, yeah, so I'm glad to see though, at least you had a little bit of the spirit and then You got the spirit.
You know, I, I should mention that our, our head, St. Patrick's Day, grand Marshall, I guess, had a lot of the spirit and couldn't make it today, so we'll, we'll see him tomorrow. Um, but joining us here in our Boca headquarters is our, uh, sustainability, echo Insights analyst and editor Bonnie Schneider.
Hey, Bonnie, how are you? I'm Doing well. And you know, my subject matter is green, so it works for St.
Pat's. Absolutely. This is, this is kind of your big holiday, right?
It's a green holiday. Good for you. Anyway, we're not gonna discuss a lot of green, but we are, let's kick it off with our first, uh, story for today.
And that is this. I don't know if it's real or not, but some people are talking about an AI chip crisis, right? Uh, all of a sudden, I don't know, someone woke up from there, St.
Patty's Day hung hangover and said, oh my God, we, we don't, we don't have enough AI chips. We're not gonna be able to make enough AI chips. It's like a, a reoccurring nightmare for the AI crowd.
Maybe we had two stories over in Gestalt it, which is part of the tech strong, uh, site, a family of sites. Um, Mitch, you wanna dive in on this with us? Yeah.
Happy, happy to do it. You know, like me, things we kind of feast or famine, we don't need any more chips 'cause we got, uh, deep seed has changed the whole model. Well, now we're back to, oh no, we don't have enough chips.
Um, both, uh, OpenAI and Meta were saying, look, we're, we're saturated. Our current GPUs that we have in supply are busy doing training and being used for customer services, and we can't buy enough of 'em. They're not available.
Uh, and of course, meta is working on its own, uh, chip. It's got something that's using in training, uh, though it's not an into production type systems, but we're back in the, we don't have enough of these and there's no bubble. 'cause we still need more chips.
And whether any of those services are profitable yet, and making, you know, making lots of positive income on top of expenses is yet to be seen. But we're back in the, we need more chips. You know, I guess it isn't, uh, we don't need my MTV.
We need a, my GPU. We'll get dire Straits to rewrite that song. Or AI.
Or ai. There you go. You got the guitars to do it, man.
You could do it yourself. I, I, let's feel for it. I believe in you.
There we go. We, we'll put a little, you know, uh, Irish Day spin on it or something. I dunno, what would do for Mike?
There's A lot of spin on this stuff, but like, on the, on the spin topic, um, I think the one that is really gonna be telling is, you know, kind of where rubber meets the road with the businesses and OpenAI is saying that they actually, um, that they're able to rent out access to their GPUs at a profit. Um, you know, if, if that's true, if Microsoft and OpenAI are saturated with, uh, GPU bound workloads and they're able to make a profit on it, well then I guess it's all true. Um, and I guess the whole deep seek thing, you know, it's interesting they optimized their model, but again, that was just one model.
There's a lot of other AI models out there, a lot of things beyond LLMs that are being developed. And, um, those are all gonna need, uh, GPUs as well. And then of course, there's the whole inferencing world, and, and yeah, maybe deep seek showed us that we can inference on the cheap, but, uh, it doesn't mean that we have enough.
No, and, and, you know, look, the whole deep seek thing is still sort of, I don't wanna say controversial, but it is controversial, right? It, let's say it's not, it's still theory. Mm-hmm.
And we're still trying to prove all that out, whether it's because of paranoia regarding it being, it it's from China or something else with it. Jury's still out on, on the deep seek stuff there though. There's obviously something there.
They did a little cheaper. Uh, but here's, here's a couple of things. I'm a little confused with the open AI message.
On the one hand, it's, oh my God, I don't have enough GPUs to do training and inferencing and, and to, to fulfill our business plans. But on the other hand, hey, you know what? I've got an extra GPU capacity that I could rent out at a profit.
Well, what's it gonna be, Bob one or the other? 'cause it, I don't know if those are, those are kind of mutually exclusive, right? Because if renting it out for a profit is a better outcome for you than filling out your business model that you don't have enough GPUs to do with.
What is that telling me? Number one? Well, To keep in mind, there's a difference between, uh, having, making a profit on a service versus the company being profitable.
7 billion. I thought it was five In 2024. Um, that's what I Maybe a 5 billion Something.
What? That's a couple's A Among US Americans. Exactly.
Now they're forecasting to be, I think it's like 11 billion this year, 214% growth increase, something around that range. Um, so we'll see, you know, did they turn that corner? They didn't, I don't think they made any statements about profitability on that, but we'll see.
They just took what, another 65 billion in funding round was their last round. So there's a lot of money being thrown around. And so for some, for anybody to say, oh, yes, we can operate that as at a profit, well, I can get, you know, a thousand miles to the gallon on my car by sitting in my driveway too.
Mm-hmm. You know, it's, it's all depends on what conditions we're talking about. I, um, look, I I say, wait three to five years for the American foundries to come online and you'll have all the chips you want.
If they can do it that fast. Yeah. If they do it that fast and the rest of the world stops moving forward, That's the whole thing, isn't it?
I mean, and, and we might hear that, oh, I don't know, maybe in this next block of stories too, it's not enough to say we can maybe in the future do something. It's enough to, you know, we gotta be, we gotta be actually doing it. And again, like I said, the rubber meets the road when you're actually, when a company is buying stuff and selling stuff to customers, and customers are paying for it.
And if that's happening, then awesome. I guess the question is, do we, how much do we trust, um, open ai? But despite how much you trust open ai, I can't wait to see Microsoft's and Google's and Amazon's financials.
I can't wait to see Core Weave. When they go IPO and they start having to release financials, then we'll really know the state of this industry. Because, you know, you can say what you want when you're a private company, but when you're a public company and investors are watching, and, uh, the SEC is watching, well, then it's gonna get real interesting really quick, uh, whether this is really a, um, uh, an AI boom or just another AI bubble.
Agreed. Agreed. Here's another interesting thing, though.
You know, Mitchell, Steven, we grew up in the era of dedicated companies that made chips. They either had their own foundries where they produced those chips, or they designed the chips and, you know, and had companies like TSMC, uh, do the, make the chips for them. But there was clearly a distinction of labor between chip companies and then companies who use those chips for software applications, computing, all, all of that, right?
So in my time growing up, look, Intel was pretty much a monopoly, right? The old Wintel monopoly. And of course, a MD came in there and, and kinda, you know, tried to rock the boat.
But let's face it, for a long time they were just a, a nice half to stop the government from, you know, prosecuting Intel from Monopoly. Um, but then with mobile chips, and then of course with arm and that, you know, apple started, went back to making their own chips. We, we've seen this move over the last, let's say, 15 years of companies making, or at least designing their own silicon.
The chips still made a silicon, they still made a silicon, uh, you know, of designing their own silicon. Now, with the advent of AI and, and the advent of, well, not the advent, but I don't wanna say the demise, but the sun setting of intel from what it was, we're seeing a move away from doing business with chip designers and makers to a lot of these big tech companies designing their own chips. Is it because designing chips has become that easy?
Is it that cheap? Like, why, why, why do you think we're seeing the sunset of the, of the pure play chip designers, if you will? Is there, where are we, is there Like a, a geopolitical issue involved with the too relying, you know, wanting to be more self-sufficient?
Well, in, in the case of, of fabricating chips, clearly China and Taiwan have, you know, a, I don't wanna say a stranglehold, but a, a, a dominant position. But Mitch, we never saw companies designing their own chips like this before. No, it was, it was Apple, Motorola, you had, you know, you mentioned a MD arm, really, arm really kind of opened things up.
'cause now you have an architecture that's reusable and many people, but this is, this has happened in several areas. I know even in the, in the cable industry, um, Comcast moved from just buying product from vendors to really designing their own hardware and having people build it for them, of which the subset of that came from some of their other suppliers. Um, I don't know if they did their own chips or not, but I, I think the capability is so much easier to do today that you can outsource the fab of it, uh, to A-T-S-M-C and the skills.
There are a lot of people who, uh, know how to design chips these days. It's not sort of cornered in the market of a few companies. And I think it, it, what it does is it ends the reliance on expensive general purpose chips, like the Intel platform, which was always the biggest complaint of, you know, why is $450 of the $1,500 computer going to Intel, right?
That's a lot of money that, that you're giving away to sell a product to a customer. So I think there's a lot of incentive here. I think it's a strategy to diversify and, and have multiple supply chains, right?
You know, meta is doing, had this chip idea, kind of struggle with it, focused it on training and, uh, you know, it's, it's, they're using it to combat the, the lack of chips, at least for training purposes right now. So I think it's a, it's the wave of the future. All the kids are doing it right.
I think that we're gonna see this more and more commonplace, And I think we're gonna really see it on the inferencing side. Um, you know, the developers of the models, uh, you know, they really want to use Nvidia. They really, um, are all about that.
I, I like these moves that we're seeing from companies like, uh, RIS and, um, Microsoft and, uh, Google and so on, deploying custom chips as a service in the cloud for inferencing tasks. Because I think that that may be where the Nvidia, I don't wanna say monopoly necessarily, but the Nvidia lock gets broken. If you can do things as a service, then you can start really, um, arbitraging the cost of electricity and the efficiency of the chips and so on in order to really see gains, you know, financial gains instead of just pouring everything into bigger and bigger clusters of Nvidia GPUs.
I, I look to the future where the, the move to custom silicon becomes a, um, sort of a, a custom silicon as a service world, where it becomes that much more beneficial to have more efficient custom silicon because people are able to quickly jump on it as a service instead of, uh, just thinking of, of these things as something that you, you, you buy as a capital expense. Agreed. Well, I, I, I'll tell you this, chips have never been sexier, right?
Than they, than they are in today's market. And in conjunction with that, you know, both of the articles in today's that are referenced in today's segment here come from Gestalt it, which of course, Steven, you started as part of Gestalt It Tech Field Day and Gestalt, it's, you know, been a site here for, what, about 14 years or something like this, right? Yeah.
A little longer than that. Um, yeah, we're getting up toward 20, if you can believe it. And, um, you know, as part of the FU combination, we are working very closely with Steven and team.
And, and as I mentioned, gestalt is part of the Tech Techstrong umbrella of sites. And, uh, I don't want to say too much, but we have plans, we have plans for Gestalt it and, and, and along with some of the other Techstrong sites. But the, the, the important thing I want to mention though, is that will be where you are, where we are going to, we are going to cover the chips scene, the semiconductor scene.
So if you are a semiconductor fan and you find all of this custom silicon stuff fascinating, or dare I say sexy, stay tuned to Gestalt it and what comes there. And, uh, we're gonna, we're gonna cover that beat. We've got some interesting folks ready to start writing on it, and it's gonna be a, it's gonna be a swell time, so stay tuned more for that.
Let's take a break here on Textron Gang. We're gonna come back and, uh, play the latest multiplayer role game Quantum Quest. Um, you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way.
With Textron Group. Hey, everyone, we're back here on Textron Gang. Um, you know, we, we've all been following the, the, uh, quantum story now for years.
I, I don't even remember when I wasn't following the quantum computing story, I guess really since the first time I saw my very first quantum computer at an IBM Think conference. I think it was in Las Vegas. It looked very much like a cappuccino machine.
I'll be honest. It was the copper machine with all these kind of tubes and stuff. But anyway, um, but we always felt, I always felt anyway that Quantum would probably not be during my career, maybe during my lifetime, but not hopefully, you know, I'd be retired.
But I gotta tell you that in the last two or three months, I am seeing just a ton of news around quantum and, and all of a sudden the, the forecast for quantum went from like 2035 to 2028 or 29. Now I've seen 2026. I don't know if that's real or not, but you know, Stephen, why not you?
I mean, there's so much news coming out. Is it, was there smoke, there's fire, or is this just smoke? Hmm.
Well, I, I'm not gonna bet against technological progress because what I've learned, and, um, fun fact, I actually studied the history of technology as my major in college. And what I've seen is that technology tends to advance in, in un in surprising leaps. And what people bet on is based on their mindset, their current mindset, and it's hard to move people forward.
And quantum, I think, is one of those things like nuclear fusion, like, frankly, electric cars. Uh, a lot of the technologies that, you know, you look at and you say that is so incredibly promising, and there's so many people working on it, and there's so many cool advances happening, it's gotta be right around the corner. But we just can't, we can't guess.
We can't say that that's right around the corner because like every technology, it only matters when it matters. It only matters when it's real. And so you see these announcements, like Microsoft made so much, so many waves, uh, last week with their, um, majorana, um, with, with, with new physics, a new state of matter.
Um, and, and there was a lot of excitement about it. There was also a lot of skepticism about it. Anytime I hear about new physics, I say, that is not a product because it's gonna take a while for new physics to get somewhere.
Now, that doesn't mean it's not gonna get anywhere, it doesn't mean that this is all nonsense, but it does mean that, again, what really matters is when there's a real product with real customers that's really being used for some kind of productive use. And we're trying to get there with Quantum. So if you look at these articles in here, and so, so there's actually a new one that was, uh, just announced.
Uh, Zong Xi, I believe is a, uh, Chinese, uh, quantum, uh, computer that, uh, apparently is running, um, a specific test, uh, much, much faster than, than conventional computers. Now that makes great headlines. Uh, you know, this one headline I'm seeing here, China, China achieves quantum supremacy one quadrillion times faster than the fastest supercomputers Yes.
In a single specific task designed to demonstrate how good quantum computing can be, but not a productive task necessarily. Not something that's actually going to, you know, invent a new medicine or figure out some new thing. No, it's, it's a, it's a theoretical task still.
And we're still theoretical in terms of where we're at with quantum computing. That doesn't mean it's not real, it doesn't mean, you know, there's a lot of skepticism about Microsoft's claims, and in fact, some of the people involved in the Microsoft, um, effort, their quantum computing chip effort have, have received some, um, withering glances from those in the know who've said, wait a second, these guys have fooled me before and it didn't come out right. Why should I believe them now?
And, and, and I think that that's the kind of attitude we should take for all of these things. Why should I believe you? Is this really real now?
We should cheer it, we should be excited about it. We should prepare for it. I'm all for the quantum resistant encryption initiative, for example, because if it's real, it's gonna change everything.
But until it's real, it's not gonna change anything. And unfortunately, that's kinda where I'm at with quantum computing. You, it's the, the quantum topic has been on sort of our topic list in, because in, in, uh, security we've been talking about quantum safe algorithms and things from quick encryption for some time not knowing is it gonna come in our lifetime?
When's it gonna come? You know, things have changed significantly in the last three to four years. And I think about what you were saying about, you know, the, the advances of technology being very unbalanced, you know, peaks and troughs, and when it's here, it moves fast type of thing.
It's kinda re reminiscent of William Gibson's quote of the future's already here. It's just very unevenly distributed right now. It's just distributed into a few labs, right?
That's where Quantum is. And, and I agree with you, uh, Steven, how many places are we gonna get to near absolute zero to run these machines, to be able to get that kind of performance that's not sitting on my desktop anytime soon. Or even in, in the data center of a corporation.
Not saying it's not common, it will, but I think it's, it's, we, we at least are getting an eye into the future of what it, what it possibly can do, what opportunities and threats might be with it. Again, it's got the whole geopolitical angle of, well, we don't want China to be the dominant quantum Got a quantum gap, They get too far ahead. Yeah.
It's sort of the nuclear arms race. Again, same race we're doing with ai. So we're, we're in this because information is so easily accessible and announcements get made, you know, proselytized of, we've done this, and yes, it's under these narrow conditions under this, you know, particular set of test conditions.
Okay? By the way, anything that is, uh, it involves, um, a new state of matter and multiple dimensions, I'm all for it. So that's what sounds like a positive advancement to me.
But anyway, it's, it's, it's, uh, it's here, but it's not very evenly distributed yet. And also, I'm sorry, I just wanna say about the interest level and it, I was, um, last year I covered this very big tech conference in Miami, emerge Americas, and I'm likely gonna be covering it next week. And I was looking at the sections and I interviewed someone, uh, who as a quantum computing company out of, uh, new England last year, small company.
And it was just one interview I did. Well, looking at the site now, one of the largest sections that they're featuring this, this year is quantum computing just from one year's time. So the, the interest level is really skyrocket just from this anecdotal experience.
But You, but you know, guys, look, I'm not ready to say there's a quantum gap, but what you've got, this is a replay of the Cold War, right? We, I mean, back in the day, the Soviet Union in the US competed on everything, right? Uh, and, and now, so today it's China and the us but it's that same thing.
And you know what, A little healthy competition's a good thing, it's a good thing. But to your points, yes, there's always a, a lull a gap from when you first, you know, pure scientific research r and d and breakthroughs in technology to productizing these things. So I don't know if Microsoft's new states of matter and dimensions are going to lead to a product anytime soon, but here's what I do know, pure r and d, when you pour money into r and d, you may not see the results immediately, but you do see results because si so much of what we do today is not easy, right?
You've gotta, nuclear fusion is not easy. Quantum is not easy. AI is not easy.
We in this country are reaping the benefits for the AI research that we did in the fifties and the sixties and the seventies and the eighties. Sometimes it's that long until you'll see product from it. And unfortunately, we are shutting down our research right now when we need it most.
And you may not see the results of this in the next 2, 3, 4 years, but you will see the results of this in the next five to 10 years and 15 years when it may no longer be the China us it may be China and EU or China and other countries. Because without basic research, you don't move the ball forward unless you're just steal problem too. The problem with that too, Ellen, is when you wanna start a backup, it's not turn on the spigot.
Nope. It's multiple years to back up to, I mean, it's, it's maybe the level they're Something off know, it's all these PhD students that are at our universities, and it's all the basic research that gets done at our universities, Right? We, you were talking about how long kind of show takes for things to really mature and appear in market from research.
So pick autonomous driving. I'm, I'm not autonomous cars. We, we talk, that's all we talked about for a while.
You know, when Tesla was fairly new and everything is gonna be autonomous, we won't need any, anymore Uber or taxi drivers. YYYY There is some autonomous driving happening in a few cases, but it's not co anywhere far stretched from commonplace yet. No, maybe that's gonna happen three, four years, maybe it's 10 years.
I don't know gonna be A big Trust level with that. But it takes a while for things to really be perfected enough to put it out into the wild when it is that impactful AI is that way, quantum's that way, et cetera. And that's, that's a great example because that shows, again, if you look at the history of technology, what you find is that technology affects us in unexpected ways, almost never in the way that you expect and is.
And if you look at the development of material science and the development of, you know, semiconductors and, and all these other things, it, it comes at us in an unexpected direction. And so we think, and, you know, to extrapolate it to now, we think that we're gonna have big quantum chips that are gonna be like super CPUs that are gonna have a new kind of math, and they're gonna solve all these problems in a completely different way. And yet what's actually coming to market may be something entirely different.
Maybe it benefits us in a completely different way that we're not ready to see. technology that amplifies the lights, the, the photonics that connect our computers together use quantum effects. And if it wasn't for basic research, we wouldn't have had those that are actually real technologies that are actually benefiting us.
I, I would not put my money on any of the sci-fi predictions coming true for any technology, whether it's autonomous driving or flying cars, or quantum computers or, you know, superconductors. But I would put my money on all of those technologies benefiting us in an unexpected way. Hmm.
Yeah, I'll take autonomous cars for 300, Alex. Mm-hmm. But you know, here's the story there.
The leading autonomous driving work was being done at Carnegie Mellon University in Pittsburgh for many, many years now. Uber went in, I think it was Uber and Google were in a bidding war and basically privatized that whole project, moved them out to outta Pittsburgh and out to the Valley or to California. And, you know, now all of a sudden it became a very commercial project, and quite frankly, the progress that was being made kind of stalled.
And I think that's a perfect example where, when things are being done for basic research without a necess, without, without necessarily a product at the end of the line, but just research for research sake and then see what falls out of it. To your point, Steven, right? As in terms of commercial applications, you're doing science for science sake, not, not science to make this particular product.
I think it's much harder to do science for a particular project than to do science for science sake and see what comes from it. And it's a lesson that we un unfortunately, will probably learn the hard way here now with, with all the cuts and, and, and stuff going on here. But nevertheless, quantum is out of the bag, right?
It's out there. We're seeing it. Companies will, you know, Google's Willow and, and, uh, and Microsoft's chip and, you know, we're, we're seeing continued progress in, in, in Quantum.
And I, I am bullish on it, bullish enough that I think next fall here at Textron, we're gonna do our first virtual event on quantum blind up a few speakers already, and we're very excited by it. Right now. The working title is Quantum Leap.
Mm-hmm. I, I don't know, Mitch. I I see, I see a promo between you and I here.
That was a show in the nineties. That right? Isn't That the trademark?
Well, that's what I got a look at. Can we get away with this? It's LEEP.
We're spelling it differently. Well, it's satire. It's satire.
It's True. Oh, satire is protected by the Constitution Pon today, I think maybe. Um, but anyway, stay tuned for more we will be covering Quantum.
And by the way, quantum will also be on the gestalt Tagt tech Strong It, so you, you could check out the latest developments there. But let's take a break. We're gonna take a little quantum break and we'll be back here on Techron Gang with AI and Margaritaville.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers network.
Welcome back to the Techstrong Gang. Well, for over 55 communities, there's lots of different modern conveniences that might be offered. There's one community called Latitudes, margarita and Water Sound, that's in Panama City, Florida.
And they're offering a lot of tech along with the amenities that you typically find and leaning into the Samsung Smart Technology. These smart homes don't just turn the lights on or change the temperature to make you more comfortable. They do some efficiency items like leaning into solar energy, for example.
But this is where it gets interesting. They're helping seniors and potentially people at risk for health issues with medication management, um, monitoring if they are doing their exercises that they should be doing, what happens if they fall? Is there a video monitoring system that can quickly determine the person is, is injured and needs help?
So the, this goes beyond what we would typically see in a smart home, really geared towards health and wellbeing and safety for seniors. But of course, it comes with some controversy because that's a lot of personal data that's, uh, that's being admitted through, through the process. Yeah.
Anybody wanna jump in? Before I do, I'll jump in. I Just want, I just wanna first note that this was in Florida, by the way.
Of course, Course, Yeah. Have send him off. Of course.
It's, I'll just leave it there, but, okay. Sorry. Mm-hmm.
Steven, go ahead. So I, I was really interested in this story, so I, um, well, first off, I'm on the board of a, uh, company developing a special needs community with here in Ohio. And, um, one of the things that weve been discussing, you know, I'm the tech and security guy, surprise, uh, chairman, uh, is that, uh, this, this, this question of privacy.
Because on the one hand, you know, people with special needs, whether they are the elderly or they have health concerns, or they are developmentally disabled in some way, or physically disabled in some way, many of them can have tremendous benefits from technology. It is beautiful to see what can, what a, a, a person can do, for example, with a talker device that allows them to communicate with the world. It is beautiful to see what somebody with a physical disability can do with augmented, augmented, uh, technology, robotic technology with, um, AI technology, with, with recognition and, um, and speech.
This is amazing stuff. But at the same time, we are deeply concerned with our community as well as in a situation like this Mar Margaritaville community, deeply concerned about the privacy implications here because, you know, people with special needs and people who are aging, um, you know, they don't necessarily want everybody to know all the details of their health and, and their demands. And, and, you know, this is an easily exploited community.
And so my first thought when I saw this was, whoa, whoa, whoa. Do I want my, my parents, um, you know, senior assisted living center connected to the smart things cloud? If you Google it, you'll see that there have been hacks, there have been data leaks, there have been exposures with this smart things platform that Samsung acquired in 2014.
I am not entirely mollified by the claim that no data goes into the cloud because they're using smart things. I don't understand how data doesn't go into the cloud in this situation. Um, and similarly, it's not all about like data in the cloud.
In many cases it's exposure via the cloud, uh, via APIs. So for example, you know, we're looking at things like cameras and motion sensors and, um, you know, face detection, video, all of those things. Yeah.
They may be stored in the cloud as in the case with, you know, the popular, you know, ring and Nest and, and platforms like that. But they may not be ex, they, they may actually be local, but if they're exposed via API or via a, um, you know, some kind of security exploit or something over the internet, then it kind of doesn't matter whether it's in Amazon's cloud or in, you know, your own private server sitting in Margaritaville in Florida, it's still exposed. And so I'm a little nervous when I hear about a whole community that's gonna be deploying the same platform for all of these things.
I don't want somebody hacking into my mom's, uh, wheelchair. Yeah. So I, I, I get it, Steven.
I, and I think those are valid concerns, but to me, this is, you know, you gotta do your pros and cons and, you know, for a lot of these people, a lot of these commun, you know, the, the, the over 55 crowd, I'm in the over 55 crowd, right? But I don't really consider myself fragile or anything yet. But the fact of the matter is, Bonnie lives down here in Florida with me.
She could tell you a lot of these over 55 communities are closer to over 75 communities, right? Or 90, or, you know, over 80 and, and so forth. And again, a lot of these people don't have the resources to have home health aides constant, you know, uh, help supervision, helping, you know, not, not necessarily nursing care, but maybe some of them do have some slight memory issues, or they just need help with mobility, right?
And, and it's such, the quality of life is such a huge part of their, whatever years God gives them left. It's such an important part to have that quality of life. And at the same time, speak to people that age.
You know, the last thing they wanna be is a burden, a burden on their children, on their loved ones, on their grandchildren. They wanna be independent as best they can. They don't wanna be wards of the state or the family.
And this program right here offers a real helping hand, a real helping hand. Now, there's two aspects, and Steven, you hit 'em both. One is, all right, they could collect your data so they're gonna know how many bowel movements you have a week and sell that to the Metamucil people.
Well, honestly, anyone who talks to my parents would know that too. Well, that, and I was just gonna say, I don't think many seniors make that a, uh, secret confidential data. Yeah.
Now your son in India, and I can talk to, yeah. But, you know, so, all right. So maybe someone could hack that kind of data.
The, the scarier part, Steven, is what you mentioned, where they can hack your medical devices, right? We've seen this at black hats. You can hack into a pacemaker.
Can you imagine that? Terrible. Imagine that, right?
And, and so how do you safeguard against that? But I would rather see us safeguard against that than take this away from the people who, who this could make a, a huge quality of life improvement. Because, you know, a life worth living is, is the kind of mantra here.
And if this could help them with that, I, I'm all for it. And I'm not, I'm a security person. I'm usually on the side of, of the security.
But, you know, I, I've seen this firsthand down here. These people could really use this. I can really, this is a, and at a time where people are worried about, I can't, I, I, I'm not gonna have a helper with me, right?
Because that was a big, what a big thing down here was immigrants doing home health aide, right? Helping older people, taking them to the supermarket, to the mall, right? You didn't necessarily have to be a, a practical nurse or a registered nurse, but just helping an old person get to get out.
Mm-hmm. I see that all the time Here, drive their car, right? It's such, it's a huge, otherwise they're trapped in their apartment.
It's huge. It, And it is amazing to see what these technologies can do for people. Um, one of the big, um, things, I don't know if you guys have have seen this yet, but, um, there's, uh, basically teleservices mm-hmm.
Where essentially you've got kind of an iPad like thing, and, um, you know, you can basically call a person anytime for any reason. So it's not like my doctor, it's every morning when I get up, I can, I can call that person and just say like, what am I supposed to do? Mm.
Or I hear a beep. Yeah. What's that beep?
Yeah. And, and, and this person on the other end is, is a real human who's there to try to help you. That's great.
And you know, you mentioned things like autonomous driving that could be incredibly valuable to bring, um, freedom and mobility to these people. Yeah. Um, all sorts of sensors could be lifesaving.
Uh, all sorts of, you know, assistive devices, think technologies that we take for granted, like, you know, IOT lights and locks and things like that could be just a tremendous benefit to these people. What I'm trying to say is, I, I, I'm, I'm just also worried that we have to make sure that we're balancing the security and the privacy protection, a aspects of those, and that we're making sure that these people aren't dependent on companies or technologies that could just go away because they don't think that this is a productive or profitable market anymore. Don't worry.
The federal government will ensure that for you, Steven. Yeah. Yep, yep.
Nothing is gonna happen to Social Security or Medicaid. No way. No.
How, You know, I think there's a, we've touched on the security part of it, which I agree with, with all of you on that. There are, there are other parts when you talk about putting things at the edge. 'cause you usually don't have that much compute power in these devices.
Um, you might have some decent network bandwidth, but you may not. But you also have to design things to say, well, what happens when the power goes out? What happens when, when the network is congested or maybe even not available, or they need to take this technology with them to the grocery store in, in the, in the bus that, you know, picks it up on Thursdays to go shopping, whatever it might be.
So there's a lot of thing, a lot of factors that go into things at the edge. 'cause they're very good at, at being sensors. They're very, they're, you can cost effectively build sensor sensors into devices.
It's hard to build AI and build a lot of processing at the edge, at least right now, cost-wise. So, you know, I, I'm all, I'm all for in innovating and trying new ideas and see what can be of help. You have to worry about all the edge conditions when you talk about, so, But, but this is why this, this particular one in Florida in general, I think is a good proving ground because Mitch, the edge here could be the community, right?
You could build a data center in the clubhouse, Have your own private wire wireless Network. No, you, they do it. I mean, I, I know I, you know, you build the data center server closet in the clubhouse that serves the community and, and you are on the edge.
But when I go to see literally my daughter, What I have done is build a data center in the clubhouse in my community. Exactly that. There you go.
But even in that scenario, when you, you know, you hop on the plane or get in the car and go see your granddaughter in Milwaukee, how dependent upon those things are you, what can you take with you? How does that work? Well, that, that's, yeah, that's another thing.
I mean, So even though you can build infrastructure all around you, well, The answer there is tell your granddaughter to take the plane from Milwaukee down here. The weather's better anyway. Um, anyway.
Hey, we, we've gotta call Araf on this version of Textron Gang. Before I do though, we got a lot, we got a busy week as usual. We, we have our, uh, uh, Textron TV show, you know, line up immediately following the gang like we do every day on today's show bar, we have, uh, one of your videos.
Yeah. Yeah. I did a video on the big tech leaning into nuclear energy.
Um, I know you guys discussed it. I took a a little bit more extended look at it. And that's on Tech Drunk tv.
You know what? Do check that out. Go.
You could go look at, uh, last week's, uh, gang, where we did discuss, you know, what's happening in the nuclear energy world. But do check out Bonnie's video on that. Also, we have playing some of our Scon interviews that I did last week in Orlando with some great stuff up there.
And then I think, not today, but Wednesday and Thursday, Steven, right? We have, uh, a Tech Field Day. Is it Networking Tech Field Day?
Is that it? That's right. Uh, yeah.
Networking tech field. And actually to the point of the stories on this episode, uh, at nine on th on what Wednesday, uh, March 19th, we're gonna be live streaming a session with BT British Telecom. They're talking about the quantum, the impact of quantum technology on telecommunications.
And they're specifically gonna be diving into a lot of the questions that we discussed here today on the Gang. Uh, we're also gonna have some community sessions from, uh, Jason Gird and Scott, uh, Roon, the Field Day delegates. Um, we're gonna have, uh, versa Networks, uh, talking about, uh, services at the edge.
And then on Thursday, we're gonna welcome, uh, back Selector, which is a company that recently presented at, uh, cloud Field Day as well, to talk about the way that they're using AI to manage, uh, networks, to improve network administration. com to learn a little more about that. Excellent.
Excellent. And we have, uh, we have Kon coming up in a couple of weeks too. Yes.
We will be live in London at Cube Con. Mitch, you'll be there with me, Mike Ard, hopefully. Can I go in your suitcase?
Sounds exciting. Come, come right along. You are more than welcome.
Welcome. You know, I'm Gonna hide in the, the, the, the, the landing gear of the plane That didn't work out so well for the general. Yeah.
Um, anyway, hey, this has been a great show. We'll be back tomorrow, but do check out everything here we're talking about. We hope you enjoy today's text on gang.
Have a great Tuesday, everyone. Stay tuned for more text on tv. We're out.
This is Techstrong tv. Hey, everyone. We're back here at Techstrong tv and we're at sussan in sunny Orlando.
What a great couple days it's been. We've met so many different people from suse, from their partners, from their customers, attendees. It's been a great time.
I hope you've enjoyed some of these videos. Let me introduce you next to Ben osha. Ben is with a company called Ossi Broadband.
And Ossi Broadband was, is here as a SUSE customer partner. And they, uh, Ben was actually up on the keynote stage yesterday talking about some of the use cases they've been, uh, using, uh, or deploying with suse. But let's first welcome Ben.
Ben, welcome. It's great to have you here. Thank you.
Yeah, Great to be here. Thanks for having me. Thank you.
So, Ben, before we jump in, you know, you are a rockstar on stage, but before we jump into that, our audience, a sense of, of who, you know, what you do and, and they may not know Aussie Broadband. Yeah. Um, and you know, about the company.
Yeah, Sure. So, uh, for me, uh, Ben, osha, I am general manager of transformation and cloud platform, uh, at Aussie Broadband. So, uh, my remit is looking after transformation of our technology function, so how we're starting to modernize our systems and our processes.
Uh, and also I have cloud platforms, which involves, uh, we have a customer facing cloud, uh, and also our internal cloud and hosting platforms, which is where suse obviously comes into the equation. Sure, Sure. Yeah.
So let's talk about Ossie Broadband a little bit, though. You know, here in the US we hear Ossie Broadband, we think, oh, it's an ISP. It is an we're we are an Ip.
Yeah, yeah, yeah. But you guys also are in the data center business. Yeah.
And, and, and the cloud business. Uh, yep. So yeah, Aussie Broadband, um, you know, we primarily are a residential internet services provider.
Uh, so that's our, our bread and butter and the biggest contributor of revenue, uh, to the business. Um, you know, we are 21 years old now. Mm-hmm.
So, started out providing broadband services into regional, uh, places in Australia, um, where the bigger telcos, like your Telstras and your Optus, uh, didn't really wanna touch because they didn't see the return on that investment. Uh, that was incredibly successful. Uh, and then with the launch of the National Broadband Network, uh, we built out connectivity into that infrastructure, uh, and, uh, and now a, a, a reseller of, of those services as well.
Yeah. So we had incredibly great success, uh, on the back of our exceptional customer service and our exceptional network, uh, in their residential broadband space, uh, which sort of gave us the ability to enter new markets. And we acquired a company called Over the Wire, which, uh, gave us capability in the enterprise and government market.
Uh, it gave us a cloud capability, uh, private cloud capability, and it also gave us a tier one voice network. Uh, we grew from, I think, 500 employees to about 1200 employees overnight. Yeah.
Uh, and then more recently we acquired a company, another voice company called Symbio, uh, which gave us another tier one voice network, and it gave us an international presence. Uh, so what A great story. Right.
But you, you know, you're operating private cloud out of data centers. Yes. Primarily in Australia.
Yeah. Do you over in, uh, uh, in New Zealand as well? Uh, private cloud's mostly in Australia.
We've got a national, uh, private cloud that hosts, uh, enterprise and government type customers. Like A sovereign Yeah. Yeah.
It's all just happens to be an Australian based cloud. Yeah. Yeah.
So, got it. Yeah. For, for, for government.
Um, So you, and I've been talking to a bunch of people here. It's an interesting time for cloud and data center space, right? Yeah.
It, it's one of these convergence stories where, look, there are licensing changes coming, you know, from VMware that have people saying, Hey, maybe this is a time to go move to the cloud. Yeah. Right.
Re-architect my applications modernization. There's, there's ai, there's quantum's a little further off, but, you know, there's so many different kind of catalysts for change right now that a lot of organizations are saying, Hey, maybe now's the time that we make a change, right? Yeah.
Been through the covid, uh, pandemic and, you know, we, we need to digitize. We did digitize, but we really need to finish that transformation. And I'm wondering how much of that is driving what you guys are seeing?
Yeah, I mean, we are going through that exact same, I guess, set of problems ourselves at the moment. You know, an organization that has grown as rapidly as we have. We've got this, uh, you know, legacy of, of technology that we've acquired, right?
Uh, or we've, you know, built up, you know, in startup phase, we've done something to serve a particular need and we've done something else to serve a need. And we've got essentially an amount of, you know, technology debt that we need to, to now consolidate, right? We've, it's grown us into a billion dollar company, but to set ourselves up for the next billion dollars of growth, we need to start thinking about, all right, well, how do we bring all of these disparate systems together?
Uh, how do we, I guess, do that in a scalable, uh, efficient, cost-effective manner? And also, uh, you know, doing things at telco scale, uh, the hyperscaler becomes very, very quickly cost ineffective. So what is the cloud hosting platform that we are gonna have that we host all of those workloads internally on?
And that's again, where, you know, the, the, the cloud platform project that I've been talking about while I'm here, uh, and the CSA solution comes into play. So, you know, building that, um, that national infrastructure for our internal use cases, providing hyperscaler like features and functionality for our internal customers, our software development teams to consume, you know, in the same way that they would, you know, if they were building in AWS or Azure. Uh, but in our data centers, uh, backed by certified validated solutions from suse, uh, and our other key partners, uh, that give us, I guess a sense of, um, security.
And with that, we able to meet our compliance obligations, uh, and deliver those services cost effecti. That's Why I think, yeah. It's about resting your head on the pillow I sleeping a little easier, right?
It's this stability Yeah. That, that comes with that. It's interesting.
It's almost like eating your own dog food kind of story, right? Yeah. Because what you're, what you're asking your customers to do, you do it yourself, your sell.
Yeah. Right? And, and that's an important kind of thing that people want to hear, right?
Don't, yeah. Don't just sell me a solution. What, what are you doing?
Yeah. Well, we're doing the same thing. Amazon started AWS hey, if you want Amazon infrastructure Yeah.
Use AWS, right? And, and that's where that came from. Yeah.
I Mean, there's a lot to be said for an approach like that. Like often, you know, you are your best reference customer. Absolutely.
If you, if it's good enough for you, you know, if Mikey likes it, everyone likes it, as they say on that commercial. Anyway. You were, you were up on the keynote stage yesterday.
Most people watching this, unfortunately, we're not here. Okay. So give them a, a flavor of what you, you spoke about.
Yeah. So, uh, again, we've touched on it a little bit already. So just talking about obviously the digital transformation that we are going through, uh, internally.
So, you know, we have a number of, um, different, uh, cloud hosting stacks. We have a number of different operational support stacks. We have a number of different business support stacks and systems of record for things like customer, uh, and service.
And those all come from the different companies that we've acquired, plus what we sort of had originally for ourselves. And, you know, we've got two paths that we can go down. We can either continue to maintain these bespoke systems or, and, and integrate them and try and, you know, smash you know, the records from one to, to talk to the other together.
Or we can sort of go, all right, now's the time to, you know, think about what does, uh, a single consolidated set of O-S-S-B-S-S, uh, and cloud hosting platforms, uh, look like. So those are, I guess the, the three prongs of our digital transformation strategies to build common core platforms across those, those three domains. Yep.
Now you guys partner with suse Yeah. Customer as well though. And, um, you know, a lot of people out watching this, and I hope we've educated them over the last couple of videos.
It's more than just running their Linux. You want to do cloud native, you wanna do observability, cloud native Security, you know, it, it is a, it's a platform. Yeah.
Right? Suse presents a platform, but it's, yet it's open. Yeah.
It's, I I think that's another big thing that companies like Ossi Broadband need to, are worried about, which is, I don't want to be locked in. No, we don't. And it's, it's, it's the balance.
And we've, you know, been talking about this a fair bit, you know, over the last couple of days, uh, as we've been taking different meetings, you know, with Susa and, and other partners is, you know, what's the, what's the right amount of choice? You know, there are, you know, the incredibly, uh, closed, um, more commercial type, you know, you must do it this way. And you know, you get the feature when we say you get the feature, which is, you know, I mean, that's, that's good for some people, but it's, it's not, it's not, it's not where we are.
It's not what we need. Uh, but there's also the, you know, the other end of the spectrum where, you know, you can go and piece together everything yourself, but I guess you then take on all of the, the risk around responsibility. Yeah, yeah.
Maintaining it. You run the risk of, you know, um, perhaps one of the, the projects stalling and no longer becoming maintained. And then you've gotta work out how to, you know, make, well keep the environment current, right?
So It is one of the problems with open source, right? If you put two of your, two your eggs in that basket, you better, nah. Be sure you have some say, or at least you have some visibility.
Yeah. It's one of the nice things about using like cloud native infrastructure from CNCF, you know that you've got the Linux Foundation behind it. That's right.
They've got 200 projects and so forth. But you're right. From a, a company like, you know, Aussie broadband, you, you've gotta kind of steer the middle there.
You don't wanna be Yeah. Too far one way or the other. That's right.
We wanna have, you know, an amount of choice and flexibility, but we also want, uh, an amount of someone going, Hey, I know these components work together and I will guarantee you that they will continue to work together for a long time. And you can take that, you go to the board and you can, you know, tick that off on your wrist, register Uh, and it's like I said, putting your head on that pillow. Yeah, that's Right.
That's And sleeping soundly. Yeah. And, and you know, at the end of the day, you know, we're, we're a telco, right?
We are in the business of providing, you know, telco and ISP services to our customer. Uh, we want our internal infrastructure to just hum. Right?
So, Agreed. Yeah. Agreed.
Hey, Ben, I want to thank you for coming on here. For people wanna find out more about Ossi Broadband, maybe even some folks down under watching this. Yeah.
What's the website? com au. And, uh, I love it.
Yeah. Thank you so much, Man. Thank you so much.
Thanks for having Me. Don. No, she Aussie broadband Keith.
So a partner customer here at Scon. Hey, don't go anywhere. We've got a lot more videos that we've been doing here in Orlando, so stay tuned.
This Is Textron tv. Hi everyone, it's Alan Shimel for Techstrong TV back here at Scon. My next guest is someone actually I know of long time before SUSE even entered the picture.
He's my friend, Andreas Prince. I first met Andreas. She's, it wasn't Amsterdam, it was before Amsterdam.
I Think it was Zia lapse At Zia. Yeah. CICD.
No, it was Jenkins wrote in Niche where we were sitting in the glass. Bought a trip that Nice. I had that goldfish gold.
You remember? I know, I know. And nice, nice.
What a great place to do. It was, oh yeah. I brought my wife with me to that one.
And we still talk about that trip. We did Monte Carlo. I did con look.
We're stuck here in Orlando. There's worse places to be than Orlando, but it's not nice. Um, it's nice.
Yes. Andreas, why don't we start, what's your current role at Seuss? Yeah, So after the, uh, acquisition of Stack State eight months ago, uh, obviously we focused very much on integrating the companies.
And I'm currently transitioned to a role in the suse Cloud Native business unit, if you like. Really much focused on product marketing. So we have great engineering, great products management, but the kind of the missing gap was product marketing.
And that's important. Hey, if you have great products, how do you bring the value alive for your customer? And then product marketing is what you need to do.
So go to market strategies, a lot of enablement work, um, and a lot of marketing towards customers, prospects. Absolutely. Yeah.
And you mentioned Stack State. You were the CEO of Stack State before you were CEO, you ran product there as well, right? Yeah, Yeah.
So long background in in products and engineering leadership roles. Yes. Uh, in, in many startup and scale ups.
And then lately before becoming the CEOI run product for Stack State and now known as Souse Observability. Excellent. And to me last night, well, we're gonna talk about what you, I saw at the, excuse me, in the solution showcase last night, you, you gave us a, a demo and a look called it sort of a peek into the near term future.
And it was the first time that I saw, let's call it the whole picture of the SUSE strategy. And I was, I was with Mitchell Ashley, who, who you know, and I, I walked outta there and I said, Mitchell, I never realized SUSE had the A to Z of this whole stack. Yeah.
It, it, and I don't think a lot of our people out there know, you know, a a common thing, Andreas, that I hear from people, whether it's in cloud native or security, not so much technology in general take 'cause AI's changing everything. But they all say, where's the innovation? I don't see any new innovation.
I, you know, I learned a long time ago that 99% of what we do in tech is evolutionary. Exactly. Exactly.
Only 1% at best Yeah. Is revolutionary. So if you wanna see it, innovation, sometimes you gotta do it in stop frames, you know what I mean?
And look at it over the breadth of a year or two Yeah. To see that innovation happening. I had a moment like that last night when, when you were showing me, uh, the diagrams and everything in there.
Um, some may look at it and say, well, what's innovative about it? Well, I don't, you know, what's innovative about it is it's, it's not making new parts, but it's combining it's harness. Exactly.
Yeah. In a way that haven't been combined before under one roof. Yeah.
One easy to use thing. They may think I'm crazy. What is he talking about?
Yeah. Jim's just rambling again. Explain to our audience what you showed me last night.
Yeah. So what we launched here at suzuko is what we call DevX validated designs. DevX referring to the developer experience.
Because what we, uh, if you think about innovation or not, but platforms are a commodity, right? Kubernetes established around for more than 10 years. CICD tools, very saturated market.
Everyone applies it. Uh, s code practices, decorative nature, standardized practice. So from a platform or technology perspective, well, what's the innovative that you can add there?
But what is super important is if you think about larger enterprises, you really wanna focus on adding business value innovation. And what we thought about here at suse Cloud Native is really, okay, if we have this rich set of capabilities that support cluster management, that support private registry, that has a rich curated set of application containers, how can we level that up and really focus on helping out software developers get their application from commit to cloud, or actually from code to cloud, if you like, really in minutes. And that's what we're launching with the DevX validated design.
So what whatso developer experience and the validated designs is we really try to, so what I like here, just a side step, the philosophy of SUSE is choice. And you could argue that's a positive thing. And I'm, I'm warm heartedly agreeing there, right?
Because a lot of open source is coming less open, uh, it's closing up. Uh, right? There are hard connections required, but what the beauty is of choice is you can, you can pick the downside, you could argue is that the time to value might be a little longer.
So we don't have a lot of, or had a lot of opinionated stacks, right? That say, Hey, if you use these tools in this way together, you can get from code to cloud to literally a minute. And that's what we've launched with our first validated design, a a blueprint, a architecture that articulates how to use the various cloud native solutions we provide, but more important, a description on how to do that.
And a installation script if you like, to get to these tools very, very quickly. And that helps platform engineering teams more important businesses to not focus so much on the platform, but on the innovation that's happening on top of the platform. I wanna dive into pieces of this, but before I do, I'm afraid I'll forget for people who wanna see this, the diagrams of DevX that you showed me yesterday, where on the suse?
Is it on the Sousa website yet? Yeah, definitely. So it's, uh, it's published in our documentation open source community, right?
Open. So it's, it's out there in the open. We've launched our first, um, validated design, and we're really looking forward for partners to start contributing to that.
There's a code repository behind, uh, we'll share the link on, on blog post and, and socials pretty soon. Yeah. Excellent.
Alright. So you brought up these repositories. Our audience is familiar with repositories, whether we're talking about Artifactory or Maven or, or docker, uh, uh, container pository, et cetera.
You guys took a different take on repositories because to me, repositories are like fishing in a sewer, you know, you don't want to eat the fish that you catch outta that water, but you guys are taking a different take on it. Yep. Explain what you're doing.
Yeah. Yeah. So what we, uh, what we did about a year ago is we launched what we call suse application collection.
And, um, that is a rich library of applications, single containers or helm yards that are fully curated. And the curated part or the nature effectively means we take an open source project, um, and we allow customers to use that in a safe, compliant way in the organization. And to do that, that needs to, a lot of stuff needs to happen.
And what we do is actually we rebase them to souse Linux images, very small footprint images. And that's powerful. Uh, because if you spread, let's say a Prometheus or a project 2,005,000 times, right?
And the container is only half the size, well, you save a lot, uh, but smaller also means the smaller attack surface. Um, right. So if we throw out libraries and other stuff, we don't need, right?
It's, it's also less attack surface. So that's, that's one part, rebase it. Then second of what we do is we make sure that it's, it has a software bill of materials.
We know exactly what are the libraries in there, what is the version, as well as what is the license. Because if you're just open source and imagine an enterprise with high co compliancy rules, pulling in a container with the wrong license type, you're liable. Um, and we, we put that all together in an sbo, a software bill of material.
And that is important because then other solutions can actually query that and say, Hey, I don't wanna have a Apache to the zero licenses. Well, you can articulate a policy and it's then no longer possible to pull in that container. And then probably the last piece is all these containers, uh, images are continuously scanned for security, uh, important.
So you know exactly, hey, how many vulnerabilities there're in. And if there's a new upstream version released that's being, uh, curated again through our pipeline, sometimes in minutes, most of the time under two hours, a new version available. And then engineering teams, again, don't need to focus on continuously updating the base images.
They will just pick what is in application collection and put their CICD, their build pipelines on top of that and use every time a kind of the latest test it and push that into the org. And, and this comes with using suse. This isn't like end user organizations don't have to do this anymore.
It's all sort of automated. Automated in there. Yes.
Yeah. Big time. It's A beautiful thing, isn't it?
Yeah. Yeah, Absolutely. You mentioned a little bit about security.
It's more than just scanning containers though, as part of this whole DevX talk a little bit about security and then let's talk about something you don't know a lot about observability. Yeah. It's still did.
Difficult point. Yeah. So if we more and more we start to realize that security is not, so we have a solution called SUSE security focused on container and network scanning.
Um, but that's not only security. We have solution application collection providing you great co compliancy type of elements. But what we really start to realize is many of our capabilities, they have portions of the security and the compliance puzzle.
So think about your airbox settings, right? Where you say, Hey, I have a team and the team only has access to, to this namespace. Well, that's an element of compliance.
If you then not only do that in your cluster management, but you propagate it into your observability solution, the team managing the app in the namespace only have access to see that data because there might be confidential data in the logs or in trace or whatever. Um, so we start to realize that security is everywhere, right? In all the distinct capabilities.
Um, and that is also in the devex validated designs. You really start to benefit from the building blocks around security and compliance in that single flow. That way you can push from code to cloud, uh, all the way through.
And then at the end, so SUSE application collection really, I would say contributes at the start of a process. Hey, where an engineering team picks a particular container and starts to develop on that, whereas SUSE security does container scanning and network security at runtime really contributes at the end. So then imagine you detect something, right?
The vulnerability or whatever that is. Then again, kind of closing the loop, the DevOps principle, right? And you start over again.
You pull a new version, you build it, you deploy it, you run it in production. And by doing so, reducing it. So, I mean eight months.
Uh, but the more, I mean, the more I start to understand that it's really the combination of all these capabilities that will help enterprises, uh, increase security, uh, measures. So you're only here eight months. It seems longer.
It feels long. That's Anja. It's it, um, you know what?
You haven't mentioned ai though. Everybody's talking about ai. What can we expect near term, little longer term maybe of, of incorporating some AI elements, maybe agentic type AI to make this even better.
Yeah, yeah. Well, I'm definitely a, a big thing. Don't say anything that's gonna get us in trouble though.
Please. No, No, no. So one, I do think too, one element I wanna touch upon in particular is, uh, the observability aspects.
Oh, that's right. Of, uh, of ai. And I feel most comfortable speaking about that.
So Seuss observability, um, as it is, is a platform for observing almost anything. Uh, we're very much focused on that, but the rancher can manage suse, observability can observe, but we've learned in the last few months that it's actually a platform to do much more with. So we're launching also SUSE observability for ai, a very prepackaged, um, integration, right?
An extension, I could argue of SUSE's observability that is focused on AI workloads, giving insights on energy consumption, GPU, uh, workload distribution, and all these type of elements. And that is in particular important because right, it's massive from a footprint perspective. Um, and you really wanna observe that in a, in a very detailed way.
So that's what I love, right? That a platform is useful for more than just single technology being Kubernetes or a different flavor. Absolutely.
But you, you, you hit on something there, Andrea, that I think is important for the audience, right? At the end of the day though, you don't operate data centers. Seuss is very much in the data center business.
Definite. And the data center business is crazy right now, right? Everybody's pledging hundreds of billions of dollars to build AI data centers.
I don't know where we're going to get the energy to run all of these AI data centers or to cool them down or whatever. But the fact of the matter is, we need to be more efficient. Yeah.
Right? We need to be able to do more with less when it comes to data centers, data center space is at a premium, more so in the private data center than even in the public cloud. Yeah.
How's suse kinda working in that, or how, you know, I mean, it plays into your strengths. Yeah, Definitely. So there, there are a couple ways of, of how we approach that.
So many people take the cloud very much from a finops perspective, right? So they take it from a costing perspective, but down the line, it's not about cost, right? It's actually about the utilization degree of your clusters and your namespace.
And we do actually two things already in there. So through the application collection, you can get to a curated version of open cost, right? So really assessing your entire landscape, what's running, where, what are the costs, et cetera.
So that's a way more finops oriented, right? You would scale it down for financial reasons. The other element I would articulate, I would say is probably even more interesting is that what we do with SUSE observability, so think about massive clusters that you're operating with very low, uh, utilization degrees, right?
So overprovision, uh, elements with SUSE observability out of the books, we provide you straightaway insights, uh, on how that is at the cluster level, how that is at the namespace level, how that is at the surface level. So although we don't have automated actions to remediate, we do provide insights on, um, on CPU, on disc memory utilization. And that is where it starts.
And where suse observability takes a slightly different angle, we not only answer, say, Hey, this is how it's utilized. What we do is we demonstrate, you say, Hey, in this cluster, these are the business applications or the namespace that, that are operating, because scaling something down always has a business risk attached. Uh, because yeah, there might be an app that needs to scale up every night, right?
So you don't see that in the window of six hours, but before that six hours, it does that every time. Um, so we really try to let the business understand what it is you have running and how that's utilizing it so you can take conscious decisions to scale it down or to, to shuffle workloads around, um, et cetera. And Yes, we Should, and that's applicable just on, on normal applications, but equally applicable to AI space.
Yeah. Andreas, you've got a great stage to play on here. Good for you, man.
I'm happy for you. So congratulations. Keep up the great Work, definitely To you and all of the people here at Sussan.
We're gonna take a break. Hey, we've got more videos from Sussan coming at you, so stay tuned. This Alan Shimmel, we'll be back.
Hello and welcome to the latest edition of the Textron AI video series. I'm your host, Mike Bizur. Today we're with one mesh Karney, senior vice president for generative AI at trades, and we're talking about the rise of AI agents.
They seem to be everywhere, all of a sudden or soon will be. Esh, welcome to Shah. Thank you.
Glad to be here. We've been experimenting with generative AI for a while now, and people have been playing our prompts, and some people are better at it than others. But how far does AI agents take us to another level?
I mean, how automated will automated get? Yeah, it's a great question, Michael. And you know what I see?
It is not a brand new technology that came out of the blue, but really the evolution of how we have been working with AI for the last two, three decades, right? We had the statistical models that led to deep learning and machine learning, and then, you know, large language models with generative ai. And really, agents are now the defacto means to actually consume all of these AI agents and work with all of the IT backend systems that we have today.
So a lot of automation to come, and I believe this is the next wave, but we are fairly at the beginning of this next wave right now. Um, how many AI agents might there ultimately be in an enterprise? Because if there's an AI agent for every task, well, there are thousands of tasks.
So does every one of them need an AI agent? Or eventually, will AI agents handle multiple tasks? How do you think that might come together?
Yeah, I, based on the agent t AI implementations that we have done at ence, and we are, uh, a very specialized data AI services provider. So we have been actually very, very focused on generative ai, doing some key agent TI implementations. What we have seen is the best practice to think about AI agents is to not think of them as a task agent, right?
Think of them as a, as a role agent. So you may have an agent for your software developer, right? An agent that helps you, quality assurance engineer or your data scientist, right?
So that's for IT and engineering. But on the business side, you may have an agent role that manages your supply chain or looks at your inventory and logistics, right? And these agents are actually going to work together, just like we form teams of, you know, people in our companies to actually perform functions.
I see this evolving into teams of agents working together to actually perform tasks and really propel the human teams that are performing these tasks today. So many, many agents, but agents not mapping to tasks, but to roles in the organizations that you have today. How will those activities therefore be orchestrated across an end-to-end workflow?
Because, well, some outcome usually involves multiple applications, multiple processes. So how will I organize that in a way that creates the desired outcome? Yeah, fantastic question.
And I think that question is at the crux of why agents are so much more powerful than a lot of the technology that we have seen come out in the last 10 years, right? So agents have, they're not just large language models, right? They actually have reasoning capabilities.
A lot of that reasoning comes out of the language models or the prompts that we provide to the, to the models. But agents are able to think, Hey, what am I specialized at? What are my tasks?
What is the desired outcome? And when I say think it is still us prompting and, and setting up and configuring these agents, but now think of these agents then saying, okay, if I want to perform this task, how do I actually plan about doing the tasks? Large language models, just think of next word or the next token.
But agents think about long-term outputs, they think of the goals for them, and then they come back and say, okay, now I have a plan to get there in five steps, and I also need to work with this other agent, or I need to get input from the human expert in this case. And that's how they are much more powerful in actually making things happen. Because yes, these agents will then very, very dynamically be able to collaborate with one another, get back to humans, or give feedback to humans, or collect feedback from humans, and then collectively process these tasks for automating a lot of common work.
And I, I see this more as a productivity gain right now, the, the currently being, Hey, let me actually make the human expert, you know, 20, 30, 40, 50% faster by automating and taking care of a lot of the run of the mill things that you and I do on jobs today on, on a daily basis. Mm-hmm. And of course, everybody's talking about, you know, whether their job will be impacted into what degree, and everybody has a certain sense of, uh, fear of somebody moving their cheese, as it were.
But as I look at it, a lot of these tasks are things that maybe we don't like doing in the first place, and in the second place, we don't do them all so well anyway. Yeah. And that is clearly the goal.
I I do feel that today there is little bit of uncertainty and it's fair for people to be, you know, concerned. And I, I think there are some indications that some of the routine low-end tasks will be taken away by, by agents and will be done by agents. But if you look at the history of technology, haven't we be be doing this all the while, right?
There are cars that kind of do a large, large part of driving today, but has autonomous driving replaced the human who needs to go somewhere, right? Has, does the car decide where you go? No.
Right? So it's a human that still needs to take the agent system and say, what do I need to do with it today? Right?
How do I guide it the right way? So we, we, as, as, as experts in the industry or as leaders in organizations, we need to be very careful about how we message the rollouts of ai. I think we need to start thinking human first.
We need to start thinking of how AI can actually aid our companies move faster, how to set the right goals. And that those are all human tasks. The, the ability to communicate, the ability to understand and perceive, right?
The ability to make key decisions is still going to be a, a very much, uh, a human domain, a human endeavor in for a long time to come. So I'm not worried about the jobs, but if you are doing run of the mill regular tasks all day long, I think you should be worried. And the way to get out of it is to really upskill yourself to really use the human wisdom, the human decision making powers that we are all kind of bond with, right?
And can develop further. And then AI doesn't become a substitute for us. AI actually becomes something of a tailwind for us to do what we want to do in a much, much faster way.
Now, I've seen some early implementations, and one of the things that strikes me is sometimes there's too much of a good thing and there's too many of these agents popping up asking to handle a certain task, and, um, and is they wind up getting in the way as much as they are helpful or they're trying to be helpful. So how do I kinda tamper down the enthusiasm of these AI agents? 'cause every time I'm doing something, one of them seems to pop up and say, can I help?
Yeah, I do that. Yes. Uh, I, I actually feel that's a good problem to have, right?
When any new technology blossoms, you are going to have a little bit of exuberance, right? You're gonna have just a little bit of too much of enthusiasm all around too many products trying to do stuff, and they're not doing it exactly the way you want. And, you know, when mobile came up, it was similar.
When cloud came up, it was similar. When computers came out, it was similar. So it's fine, right?
We are gonna come out of that phase. It's, it's perfectly okay. What I feel is, is gonna happen is there will be, um, a a lot of these trials, let the thousand flowers blossom or whatever, and then we are gonna see some ecosystems emerge, right?
And that's happening with, like, for example, Google kind of really consolidating a lot of what they did with Gemini, with what, what they call now as agent space, right? How do we actually build around manage agents, right? Microsoft has been doing a lot of interesting with copilots and auto gen and, and TIC frameworks, right?
So there are these frameworks evolving, which will now also form ways of interacting with each other, right? And then a lot of the complexity will go away. And yes, still that time you will have these agents power up.
You just have to figure out what works for you and also keep a watch on where the industry is going. So you're not left with some of the laggards, you're actually moving where there is the critical mass or development and, and further progress and, and traction, particularly on the market side. Um, these agents are based on those reasoning engines that we find in the LLMs.
How smart are those reasoning engines getting? And at what rate? Because, um, it seemed like initially at least some of the ones I saw had the roughly the reasoning capabilities of a five-year-old.
But now they seem to be, I don't know, college students. What, where are we on this adventure? Yes.
I, I think most of the language models are, you know, late teenage kind of capabilities in my view. But one way to think about them is a very, very smart teenager who has learned a few tricks, right? And still doesn't have the experience or the wisdom for how to apply, um, those skills, right?
So that's where I said human orchestration is still, still very critical. I'll give you a few examples, right? So kinda just ground it in some facts.
We have, um, an a benchmark called SWE Bench that stands for Software engineering, SWE Software Engineering Benchmark. And it, it has hundreds of really complex software engineering tasks that need to be performed. You can give these two software agent tick systems and agent tick system is fairly reliably able to solve 50 to 60% of those tasks.
Today, when we started, we were at 2%. Now we are not, well not of 50% already, right? The agent tick systems are able to collect information from all your database table structured data.
They can merge the information from documents and unstructured data and make sense out of it, right? I, I have obviously you probably heard of this PhD agent that's gonna charge be be, you know, coming out for $25,000 a year, right? So there will be agents which will cost tens of thousands of dollars and potentially have the ability in a narrow field, presumably to actually go fairly, go deep and do deep research into areas.
But I don't think we are at a PhD level yet, although there are some benchmarks that say, oh, these language models themselves are able to solve fairly complicated math problems to going to the level of, let's say, an American Math Olympiad or, um, American Invitational Math. But that, again, is a very, very specific narrow field in terms of the ability to do concrete work. Think of it as a bunch of interns that are available to you, if you can guide them, they're very committed.
They work 24 7, they're diligent and they love to work. So how can you guide them? That's the, that's the right mindset in, in my experience.
Um, as we kind of move forward all of this, um, how will we insert these AI agents that are based on probabilistic outcomes or guesses, as they might say, and they get better over time, but the workflows tend to be deterministic, and they're supposed to be done the same way every time a hundred percent of the time. And the AI agent's gonna do it maybe differently every other time. So how do I kind reconcile those things?
I am laughing because we had exactly the opposite problem asked a few years back. I was the head of AI and automation at a, at a public, uh, company that did customer engagement. And obviously customer engagement is where like agents, human agents in contact centers are talking to their customers, right?
But the problem was those hardcoded workflows didn't work because humans cannot be bossed into standard workflows, right? So when we build those software systems, humans would always go and ask a question that the system didn't know how to answer. So we actually wanted more flexibility.
Now people are saying, Hey, is it too flexible? And how can I, so there is a little bit of balance there, and we will go a little bit from guardrail to guardrail. There are ways for enterprise systems to be fairly become deterministic and reliable.
For example, within language models, you can set temperature settings, you can do top K, top K, top p and there are different ways to kind of really lock down certain things. You can also actually build a lot of reliability in the way you build those agents. The way you define the prompts, you define the roles and the job descriptions of the agents.
You can instruct the agents to follow steps or to come back clean and say, I don't know. Right? But these are not, I believe, very, very different problems than fundamentally what we deal with with humans.
Sometimes we humans tend to not actively say, I don't know, right? We try to figure things out. And language models are similar, right?
So you can actually build those systems to avoid those problems of hallucination. We can do what's called grounding, which actually tracks you back to where does the data come from. Give me a concrete reference of where you pick this data point from, right?
So those approaches are where kind of professionals actually go. When we build these systems, we make sure that the systems are not hallucinating. That if they are hallucinating, there is detection and confidence scores that the user gets back, right?
Or the answer does not ever reach the human. So there are ways to, to mitigate the problem. And we are getting better every week in terms of how we can drive a much more reliable deterministic automation outta the systems.
But the bottom line still is that flexible workflows are better, especially when you're dealing with humans at the other end. Mm-hmm. Um, you mentioned hallucinations.
Do you think we have a new appreciation for data that despite 40 or 50 years of computing, we never really had, and now in the age of ai, we're starting to realize that, you know, the way we manage the data, describe the data store, the data matters. Yeah. Now, um, it is interesting that many of our projects, Michael, we we start obviously with, okay, here is the ROI and ROI is now proven, right?
It's not like, if it is, how can I do this right now? The question has moved to, okay, do I have the right data in terms of the, the quality? And by quality, I don't, I don't mean like, does ca stand for California or Canada?
Right? Those, those problems have been largely kind of solved. But I, I think the world is world of data is excluded because we are now bringing in the, the 70% of untapped, unstructured data sources into the mix, right?
So the structured data with data warehouses, lake houses is the, that world seems to be under control. There's still a lot of work of to be done with data engineering, but we have now added complexity with documents, images, videos, right? So more and more content is now available to extract business value out of.
And yes, that does create interesting challenges, interesting pre-work, where before you can start extracting value, you may have to do some data engineering work. The good thing is you don't have to wait for all your data to be in one place in your lakehouse or whatever to, to kind of get started. You can get started with a fairly small amount of structured and unstructured data, start ruling out your agent systems, and then add more and more data sources to get richer insights, recommendations, and actions over a period of time.
So it's a journey. It's not one and done. And you can start expecting business ROI from from D one, which which means in, in about a few weeks from, from the, from the time you start.
Mm-hmm. Um, so if we play this out to the nth degree, we keep talking about AI and agents as a technology problem, but how much of this is really almost a sociology cultural challenge as we go forward together? Yeah.
I am not sure I'm that expert to kind of really talk about the sociology angle of it. But let me give you my 2 cents. I, I do feel it is a fairly pervasive big, big issue that all of us really need to, to look at, right?
And it does mean, just like Industrial Revolution did quite a few social changes, right? In terms of the way we work, the way we interact, the way we actually go to work and do stuff every day, right? And that does require, um, a a lot of adjustments from our side.
And I see two bookends, right? There are people who buddy their head in the sand and say, I'm not gonna even allow chat GT in my organization, right? And then there is like, let's go and do, you know, let, let's open up all the, um, all, all the taps and just run multiple projects.
I think there is a fine balance that particularly the CIOs, the CDs of the world have to kind of reach in their organizations and they have to figure out how to roll out the AI solutions with governance, with data safety, with security. And that's where I think professional help, like someone like NCE coming in or getting your people trained in the right technologies helps. On the other side of the coin, as individuals, especially, I was at a, a career fair last weekend volunteering, and a lot of like high schoolers and college kids came to me and said, how should I think about my careers?
Because I'm thinking software engineering will not be as attractive or should I be doing X or Y, right? And I, I do feel we have to start thinking about some of the core skills that will survive, that will actually flourish and be in demand five, 10 years from now. Especially if you are early in your career, you have to pause, give it some thought, and not rush into what was hot four years back.
We have to really think through the, the change is as a society come together and, and think through it All. Folks, shanan here, change is a coming as the song says. And who knows, they might be entirely new careers that no one ever thought of, but it's gotta be nice to figure out how to absorb all this stuff.
Hey Umesh, thanks for being on the show. Thank you. It's my pleasure.
And thank you all for watching the latest episode of the Techstrong AI video series. You can find this episode and others on our website. We invite you to check them all out.
Until then, we'll see you next time. Hey everyone, I'm Alan Shiel and this is Jonathan Singer, and you are watching The DevSecOps Show Cracking the Code. You've never heard of that show.
Well, for good reason, this is the very first episode of it. We're just starting it. And thanks for joining in.
Um, we're going to take today's show to just kinda give you a what to expect and what's coming here and introduce a whole concept to you. Uh, DevSecOps Show Cracking the code is a joint production between us here at Techstrong Group, tech Strong tv, as well as check marks, our partners check marks. We partnered with check marks for many, many years.
They've been a leader in the AppSec space. DevSecOps coming now into platform engineering as well. So I'm thrilled to have check marks co-producing this with us.
And my co-host I mentioned, his name is Jonathan c Jonathan's with check marks. Hey, Jonathan, nice to have you co-hosting with us. Welcome.
Um, thank you. You know, you are the new guy on the block. Tell people a little bit about you.
Sure. So, uh, it's nice to virtually get my face out in front of everyone, and thanks again for the warm welcome. I am very much looking forward to doing this series with you.
Uh, my background, I've been with check marks for a couple years now, and, uh, I've spent a lot of the last 20 plus years, sadly. But yeah, it's been, it's been a long time. You don look adult.
Uh, well, uh, you know, I'll, I'll take it. I'll take it. Look good living.
Yeah. Where can I say good skincare? It's, it's great.
Mm-hmm. Uh, but I've been in cybersecurity and, and some adjacents work in telecom for the last 20 plus years. Uh, and mm-hmm.
I, uh, I'm current in my current role at Checkmarks. I'm doing a lot to help the organization shift our focus into the realm of developers. And we've done a lot of work, uh, as a company over the last four years.
Like really making our platform developer friendly, good for developer teams, good for huge like development organizations. And so we wanna take an opportunity to sort of get the word out, uh, as a company. Um, and I am, I'm sort of leading that effort, so that's why I'm here.
We've got a lot of fun topics to talk about. I've been talking a lot recently about DevSecOps maturity and, uh, about what that really looks like and, and how you advance as an organization. So lots, lots to dig into.
Absolutely. I want to dig into some of those topics, kind of pre-announce them here today. I'd like to go into a little bit more about check marks and their history, though.
You know, like you, I've been in security, well, probably longer than you to tell you should, I've been in security now about 30 years, and, um, yes, I've seen a lot of water under that bridge, right? I've seen us move from a predominantly network security type of world where we put big boxes, you know, at the, at the drawbridge with the moat surrounding the castle to the advent of the cloud, to the advent of DevOps ai now platform engineering, SRE, so many, you know, subsequent waves. And each wave has brought new innovation, new techniques, new best practices.
So over that time, I would say one of the biggest Innova, not innovations, but shifts in security was the shift to AppSec, right? Even before DevSecOps, the shift to AppSec, the idea of we are going to secure the applications, whether they're in the cloud or in a data center or on your phone. We need to make sure our application code is secure.
It's free of buffer overflows and cross site scripting and SQL errors and, you know, all of those kind, kind of common things. You know, obviously, uh, top 20 kind of, you know, uh, of, of, uh, vulnerabilities. And that's when I first became aware of check marks, right?
Check marks was a pioneer in AppSec, right? And we, you know, the idea of, of static code analysis, dynamic code analysis. Then of course, later on came, um, uh, open source scanning and I always forget what we call it now.
Secure code analysis, SCA, right? Basically scanning our open source code. Um, all of these things really, I think they made a huge difference in the quality of the code that gets released.
And, you know, that's in our applications. At the same time, things like DevOps and agile man change the way we develop software. The biggest change is what, you know, I call the shift to a software factory, right?
Where it, it's not, I used to think of software as like, you know, like mid 18 or mid 18 hundreds Germans, craftsmen, fine craftsmen making furniture or iron metal workers or, you know, the guild where you had apprentices and, and lifelong, you know, that real craftsman kind of role. But I think we sort of shift to the factory, right? Much like we did in automobile production, right?
From bespoke automobiles to assembly line. And we saw the same shift in software. Uh, we also saw the advent of repos and open source software where people, I, I, you know, it's like Frankenstein software people stitch together a whole bunch of different components right?
From different places. And that's 85% of the code in today's applications. Um, these are all big changes.
And then of course, the biggest one for us here on this show is the whole start of DevSecOps, right? All of a sudden it became cool to say, Hey, did you know, hey, developer, we know you want to develop quality code even though we're not those old, you know, mid 1800 craftsmen anymore. We still have pride in our work.
We still have pride in the code. We're publishing. We want, no one raises their hand and says, Hey, I feel like putting out some crappy code today.
No, everybody likes good code. And, and so that was a revelation for security people, Jonathan, right? We, we, we spent 20 years, we always said, nah, no one cares about security but us, we're the only people.
But no, they care about security. Let's give them the tools to do it. And, and again, check Marks led the way there, I think, right?
With, uh, well the most recent is the advent of check marks one, that whole platform. So that was a long-winded intro for you to discuss check marks one and what that is. Well, uh, there were a lot of things in there that I'd love to address, but since you asked me directly about what check marks one is, I mean, uh, you know, I I think check marks one is our response to everything that you said.
And yeah, like, I mean, we can go back to the Toyota production system and, uh, and, and, and, you know, KBO and, and how that's, you know, grown up and influenced agile development and, and the kind of march from DevOps to somewhat argue back to DevSecOps. Um, and, and I'll say that I was, I was talking to someone recently and he said, you know, I spent years as a DevOps leader, and I always thought DevSecOps was just a marketing term by security vendors, because we always knew that DevOps had to, it was, it was supposed to be everything, and security was a part of it. Yeah.
So, you know, as, as a guy who's out there now talking about DevSecOps, I think I'll, I'll at least, uh, say yeah, like we're, we're, we know. But, uh, check marks one is still the response to this, right? It's the response to that need that, uh, maybe security folks felt like, uh, well that's nice that you included it, but we're not talking about it enough.
Um, and you know, your reference to, you know, coders a and developers as originally kind of craftspeople, I, I think they still are. And I think that what all the open source stuff and the kind of Franken code that people put together is because we're trying to refactor people's time on doing the craftsman stuff where it's really, really important. Uh, and we want security to still be a part of that, right?
So we want security to be a part of your software supply chain. So everything that you pull down from the internet, we wanna make sure that, you know, that code is secured when you build new code and you get time to do that. Craftsman, like work, we wanna be there.
Uh, you know, doing the analysis of that code before it gets into production and, and check marks. One is the response to those needs of taking all of these different types of analysis, right? Fast, SCA das, API security, uh, container security, and, and building those engines, not separately, but so that they work together and that they can fit into your production pipelines, right?
Because if you're gonna do this effectively at scale, which is, which is really what large businesses need, they're trying to get all these developers, all these craftsmen who, you know, work on these little individual things to really, to make a big outsized impact. Um, we wanna fit into all of those production lines, integrate with everything that you need, and make sure that we're securing as much early as possible so that when things get to production, there are, you know, there are as few critical vulnerabilities as, as there need to be. So that's check marks one, is the response to that need for that to happen in the cloud for that, to make it easy for everyone.
Love it. So you opened this can of worms. Let's go back to the birth of Jeff SecOps.
com in, uh, when we first published it in March of 2014. We started in 2013, you know, planning in getting everything done like September, October, 2013. And, um, let's be clear back then.
So I came from the security world. I thought what a tremendous opportunity DevOps represents for security. There wasn't a thing called DevSecOps.
There was, there were proto like proto humans, you know, not Neanderthal, but Africas and some of the proto humans. There were things like Rugged DevOps, my friend James Wickett, who is now, uh, runtime or drive run securities, his new company, uh, he started something called the Rugged DevOps Movement, right? And it was, you know, ruggedized DevOps, making it resilient.
org. Maybe we'll have Shannon on a show going forward. I have a good friend of mine, um, and she actually wrote the Manifesto for DevSecOps, right?
10 years ago, this May was the very first DevOps DevSecOps Connect that I did at the RSA conference in partnership with my friends at RSA. Um, and the idea then was when we first did this 10 years ago, again, DevSecOps, it was funny, the security people thought it was full of crap. John Jonathan, right?
'cause they said, oh, nonsense, no one cares about security. And the, and the developers thought it was full of crap too, which is a marketing term, the true DevOps people like my friend John Willis and, and Patrick dubois, who coined the term DevOps and, you know, uh, uh, Andrew Clay Schafer, and, you know, the Damon Edwards, the, the, the founders of DevOps. They felt, of course, security was part of DevOps.
DevOps encompassed all of that. But what kind of needy, whiny individuals or security people that they feel it necessary to stick check right in the middle of the dev and the ops, and they resisted it, right? And when we first started doing these events at RSAI, that was my mission, to bring the security community to the, and the dev ops tribe together, kind of mixing peanut butter and chocolate.
And there was a lot of resistance. Go ahead. Yeah.
And I mean, let's, let's be honest. 'cause we're, we're gonna talk, we're gonna have a, a whole conversation on culture later. But like, yep.
From my perspective, that what you just said, oh, well, everyone thought it was, everyone thought it was bs. Like both sides kind of. That's, that's kind of part of the problem, right?
And that's why we needed to have it in there in the first place is because you can say DevOps always included security, okay? But DevOps started in 2009. It is 2025, and there is still a massive culture clash between security organizations and development organizations.
I was talking to my friend who, uh, you know, she was recently a senior staff engineer at an Amazon based company. And, and, and now she's often a, um, uh, in a, in a startup again, uh, you know, but, but they were saying like, you know, the security people want it so secure that like, well, we're just gonna unplug everything, right? Right.
And developers like, well, I still need to do my work. And that requires things to be turned off, right? And, and if we're still there where we have this, this big culture clash, which is fine.
And again, and I say this all the time, like, developers move fast to break things. Security people don't ever let anything break. And if we can't start coming together as, as distinct disciplines and working towards the goals of the business, not just our own individual metrics of like, I've tracked this many vulnerabilities so that I can buy more of this software and secure this, right?
And developers saying, well, I'm not meeting my development milestones, so I'm gonna skip this step and I'm gonna mute my development milestones. If, if we can't work together and have the business align us on goals of what producing secure software at a rapid pace looks like, then we still need to be talking about DevSecOps and talking about DevSecOps maturity and where you are. 'cause like that the, the cultures have to find a way to come together.
We can't just have security being the department of No. And we can't have developers being like, oh, they're all 20-year-old yahoos. And it's like, they're not like, these people have been doing this for 30 years.
Like, come on. So Absolutely. So let me, let me give, let me spread the good news today.
Like it's Sunday and I'm selling Watchtower or something. Um, the good news is we've made a t tremendous amount of progress Agreed Over the 10 years I'm doing this thing in RSA, which we're doing again this year in RSA in May. Check Marks is a sponsor of it.
They'll be there, I think they're on one of the panels even, uh, uh, uh, Toby, the chief product officer at Check Marks is, is on one of the panels, um, co. But anyway, people recognize that DevSecOps is a real thing that you need. The second DevSecOps even more than that, when you look at the leading DevOps platforms in the world today, companies like GitLab and Jfr and Harness and CloudBees to name a few, they don't even call themselves DevOps platforms.
They call themselves DevSecOps platforms because they recognize how important security is. So we have made progress, I have a more nuanced view of it today than maybe you, Jonathan, or what you've said so far in that I think what we're seeing is under the maturation of DevSecOps, we've learned some lessons. Developers are not against developing quality code, but they're never gonna be security professionals.
A hundred percent agree. Yep. And I think one of the mistakes that I, DevSecOps industry has made is giving security tools to developers.
We need to give developer tools to developers that help them do better security, right? Because they're never gonna truly understand the, the nuances of the CVSS rating system or something like, you know what I mean? One of these kinds of things.
Yeah. And that, so again, we talk about check marks one, bringing it back to that. That's one of the beautiful things about that is, right, creating a, a platform that developers can use and feel comfortable in without having to be a security pro, but also having an aspect of it that the security pro can use to get their job done as well.
And again, these are things we're gonna explore. I wanna explore shift left. Have we over shifted?
I want to explore how platform engineering has kind of come in on top here and said, Hey, let us work with security to set up the guardrail so that those developers can just go faster. We, we do do the platform engineering show, right? Of which you, you've been a guest on there and Check Mark's sponsor.
We'll be discussing more of that on there. But we, you know, we'd be wrong if we didn't include it in, in here too. Um, and I think, here's the other thing.
This whole, uh, software pipeline security, right? Software supply chain security, that's part of DevSecOps too, right? It's a huge part.
The SBOs, everything else. And here's another thing I'm seeing, John, and I'm wondering if you see this too. We're starting to see people say, Hey, we gotta extend, extend DevSecOps past the deployment horizon, right up till now.
DevSecOps, it was like it hit a black hole when we deployed, right? No light escaped to the other side. Well, no, there's life after deployment, right?
For apps, and there's security after deployment, and that has to be tied into your DevSecOps too. So I, another thing that I'd like to see us discuss, what else would you like, think we're gonna cover, Sean? Well, um, let's see.
We're gonna talk about culture. We're gonna talk a lot about security education, because, you know, while you said that, so look, everything you said about making security tools into developer tools, I completely agree with you. I think I even said it at Techstrong Predict, uh, that, you know, that's, that's the goal.
Um, but I wanna talk about security education. I wanna talk about how it's working, uh, because it is, we just did a survey of 1500 developers Yeah, sure. Working or not, but at least the developers who are out there seem to feel like it's working, and maybe security needs to change the way that it speaks to the market, and stop complaining that they don't teach security and secure coding in as part of, you know, a university degree and say, okay, well we're, we're, we're doing it.
So let's start speaking differently to developers about security. Right? I agree a hundred percent That that ties back to culture.
So like, I think that the overarching conversation that we're gonna have across every single one of these meetings is the culture. And it's gonna be like the culture around integrating properly, around metrics, around security education, around matching the velocity of security to the velocity of development. Um, you know, about security champions programs, all of these things that we're gonna wanna talk about throughout the course of this show.
Uh, I, I think it's, it's all gonna tie back into culture and how we learn to continue working together and, and agreed, you know, security goes beyond deployment. That's why check Marks one partners with, uh, with folks like Wiz and, and, and with Cystic right Runtime partners. So agree.
Like we need to be looking at the whole software life lifecycle as developers look at the software lifecycle. Agreed. Agreed.
Hey, you know, what else though, for people watching this, are you a ops person? Are you a DevOps person? Are you a developer?
Are you a security? Would you like to be involved? Perhaps be a guest?
You have a point of view. It's not just going to be you and I talking every week, Jonathan. We're gonna have hopefully a panel every week of at least 3, 4, 5 people.
Not every week, every other week I think we do this. Um, but every show, and we're looking for people. So if you have some thoughts and opinions, everybody has an opinion on, uh, DevSecOps and DevOps, write to us.
com or reach out on LinkedIn or wherever you can reach me. I'm pretty accessible, so you could reach out to us there and we'll, we'll entertain any and everyone who'd like to come on here and, you know, have a thought on, on, on what we're gonna say. You know, what else, John?
I'm really proud of us. We're on now. Oh, a good 15 0, 25 minutes.
We haven't mentioned ai. What about ai DevSecOps? We'll, we'll talk about ai.
And you met, you mentioned, uh, Patrick Debar earlier, but he and I had a, had a long conversation about AI that you can find somewhere online, probably on our website, uh, as well. Um, but yeah, you know, ai, uh, we're gonna talk about AI in a bunch of different ways, right? 'cause there are, there are lots of different ways of looking at, which is like, how does it help developers code faster?
How does it help them do security faster? How does it help se security engineers to, you know, tune their products faster? Um, and then what does it mean for the software supply chain?
You, you, earlier you were talking about, uh, code and, um, and, and downloading other people's code and how that needs to be scanned. Well, but now there's hugging face and there are all these LLM models. And, you know, we've got a guy on at our company, ez, who's one of our lead researchers, and he's done a demo of like, here's how you poison an AI model, and here's what it looks like, right?
Gimme a recipe for, you know, pasta Alfredo. And one of the ingredients that gives you is rat poison, right? When he, when he does that right, he's like, poisoned this model.
So there's, you know, if, if, if companies are building their own LLM or they're looking to build off of an open source, LLM, what's the security of that? Who's gonna scan that? Who's gonna know whether or not your model is poisoned?
So like, there's, and, and I don't mean to ramp up the fear factor 'cause that's obviously what security folks typically are, are known for doing, or at least accused of doing. But it's, it's a concern. AI is now a supply chain concern in addition to all of the ways that can be helpful.
So let's totally talk. I like everything else. It's the duality, right?
Light and darkness. Uh, it's always there, man. Every technology, you, you get it, it's new.
It does something cool, and there are risks, and that's just life. I always say this is why we can't have nice things on the internet. Um, but we do have nice things on the internet in spite of all.
And, and, and, you know, again, I I I want to take a positive view of this as a result of DevSecOps. Our code today is much more secure, like the apps you're using today. And even though you may be updating them daily, weekly, monthly, whatever, they're much more secure today than they were before DevSecOps.
I, I think we have made tremendous strides in, in releasing much more secure code. Yeah, so, Agreed. That agreed?
Mm-hmm. All right. Hey, that's gonna wrap up our very first version here of the DevSecOps Show.
Cracking the code. We're gonna be back in two weeks with a full on panel. Jonathan, let's tackle culture right outta the bat and talk about the DevSecOps culture on that show.
Um, you can catch this show on Text Drunk TV and the Techstrong TV network. So it'll play on Tech drunk tv. It'll be streamed to LinkedIn and Facebook and x and YouTube to our text trunk tv, YouTube channel.
tv website. com, security Boulevard, cloud native, now, tech Strong, AI tech, strong it, and digital CXL. Um, additionally, audio versions of this will be available on Apple Podcast, uh, uh, Spotify podcast, Stitcher, and all of your favorite podcast platforms.
So if you prefer listening to audio while you're running, exercising, whatever, driving, they'll be there for you too. Um, Jonathan, I'm, I'm pumped. I can't wait to get cooking with this.
Yeah, I'm, I'm excited too. I think it's gonna be a great series, and I appreciate you and the organization for hosting it. Looking forward to it.
Absolutely. Absolutely. All right, until next time, then that's a wrap on episode one of the DevSecOps.
So DevSecOps show, little tongue twisted there. DevSecOps Show cracking the code. We're out everyone.
Thanks very much. Thank you. Hey everyone, it's Alan Shimmel here from Techron Group, and you're watching another episode of the CD Pipeline.
The CD Pipeline is a, uh, partnership between the CD Foundation of the Lennox Foundation, and here us here at Techstrong, where about about once a month we try to bring you some of the latest topics regarding or germane to the CDF audience, to the CD Foundation. For those of you who're not familiar with the CD Foundation, we usually have someone here from the CD Foundation. Um, but for those not familiar, the CD Foundation, as I mentioned, is a daughter foundation of the Linux Foundation, but it's responsible actually for the management upkeep running of several of the largest tools in the CD universe, CICD universe, including Jenkins, uh, Spinnaker, um, jc, one of yours, Orus Orus.
Um, I think there's eight or nine different pro programs that fall under the auspices of the CDF, but it's more than just managing those, it's, it's working groups around the security of them, of operating them best practices. It is the community for CICD. And so this show, CD Pipeline tries to capture that.
Um, this week's show is challenges and wins in integrating security tooling into CICD workflows. Let me introduce you to our panel for today, and then we can jump right into the topic. First of all, I think it's a first time on, and if I am mistaking right, Kate, it is your first time?
Yes, my First time. Very cool. And I'm gonna try not to mess up her name, but I forget things from one second to the next.
Uh, Kate Scar, Well, almost Scarcella Scar. If my eyes were better, I'd be able to read it up there, because my, they didn't put it on my prompt here for me like they're supposed to, but they try. All right, Kate, beyond Scarcella, what else can we learn, learn about you here today?
So I am a cybersecurity architect. Uh, I got my Master's of Science and Information Security and did my thesis on securing the electrical grid in North America. And I graduated way back in 2006.
And I tell people this because there was only four people in my graduating class, so nobody was really talking about cybersecurity, even though it was coming up in, um, in some products. You know, you had av, you had networking, security, and dare I mention the start of identity and Nexus management, which was like, ah, but anyway, so that's my background, and I did it for Very cool. Yeah.
So very Long. That was the electrical grid without Texas. Very good.
Mm-hmm. So, um, I'm not gonna touch that one again, but I, I've been in security about 25 years, myself more now. And, and you're right.
Back then it was, it was network security or endpoint secure host security as we called it. And, uh, it certainly has changed over the years, though. It's become more important than ever, obviously.
Are you still working in the security field today? I am. I took a short sabbatical for about a year, and I'm just, uh, coming back out of that sabbatical, um, connected with Tracy, who has, um, who has, you know, full speed here this year.
So, yes. Um, well, It's great to have you on here. Thank you.
Thank you. I'm, I'm very happy. Appreciate it.
Looking forward to, to hearing more. Um, next up we've got Ryan Ware, as in software. Brian, welcome to CD Pipeline.
Tell us about yourself. Hey, thanks, Alan. Uh, I'm really happy to be here my first time as well.
Uh, uh, I, I appreciate Tracy dragging me, uh, uh, to come on here. Um, so, uh, I've been doing security in one way or another for 27 years, uh, or so, uh, I'm a software developer by, by nature. But, uh, uh, you know, early in my career, uh, I first started at Intel doing, uh, implementing security features into digital rights management stacks.
Uh, later I did offensive security research into, uh, Intel's products. Uh, later I was more of a security architect and then, uh, worked in, uh, the realm of open source for quite some time, uh, on one. Uh, how do, uh, uh, product teams incorporate open source in a secure way, as well as how do you securely, uh, uh, make and contribute to open source externally?
Uh, Intel has a, a, a a, a large presence in the open source community, uh, these days. Uh, I work for Carrier, where I am Deputy Chief Product Security Officer, uh, focusing on security tooling, uh, CICD training, uh, secure development practices, uh, and, uh, I'm also in the, the Open Source Security Foundation where I am the chair for the security tooling working group in that organization. Very cool.
And you mentioned Intel's commitment to open source. I think it's very fashionable today to, to crap on Intel, right? They're not, they're not Nvidia and you know, how the mightier fall, but I, I think people have never given Intel enough credit for their commitment to open source, open source communities, open standards, and, you know, kudos to them for the work they do.
I know they work very closely with the Linux Foundation, C-N-C-F-O-S-S-F, you know, a lot of the, the foundation. So Absolutely shout out. They do, they do an amazing job with that and still do even, uh, with all the troubles they're having right now.
com/intel. So, Absolutely. So shout out to them.
All right. Our last panel member today is our friend, Tracy Reagan. Tracy, of course, CEO of Deploy hub, uh, Aurelius, one of the products under the CD Foundation came out of Deploy Hub and, and their, their efforts.
Tracy's also, I mentioned she's a host on our Textron gang, and, you know, she works, she has a hand in a lot of different Linux Foundation, open source, uh, projects and, and boards, including OSSF, open Source Security, OSSF, and the, uh, ED Foundation among others. Tracy, great to have you on today. Well, thank you.
Yes, I am, um, a busy girl. I kind of have one foot in the security world and one foot in the DevOps world. I am on the board of the Technology Oversight Committee at the CD Foundation.
I've, uh, served in that role now for, uh, several years. And I'm also on the board of the open SSF. Um, so I'm keeping kind of my thumb, um, on the heartbeat of both sides.
And we re at the CDF, we recently started a, um, special interest group called CICD Cybersecurity, which, which Kate is the chairperson of. Uh, and it, the reason we, I felt we needed to start it was because there isn't a strong enough handshake between what the security side of the business is doing and what the dev, what the DevOps side of the business is doing. So it's time that we have that, uh, conversation.
It's a really critical one. Um, most DevOps engineers, you know, even just putting in, uh, the scanning of a SBO m is a major undertaking, and there's so much more to do. So it makes me a little nervous that we are so far behind the eight ball.
Uh, I wanna remind everybody that it takes us about a hundred days to respond to a vulnerability. It takes a attacker less than 10 days to exploit it. So we are, um, at a major disadvantage here, and there has to be a discussion on how to improve that time.
And so we're hoping that we can do that with this, uh, the, the new SIG at this, uh, CD foundation. So I'll use CDs out there, which I call you, please. CDs.
I want you to join the, uh, the CICD cybersecurity SIG and start helping us with really defining what that looks like in the pipeline. And I hope we can have a deeper conversation around that, considering we have two security experts on the call today. Absolutely.
So, as I mentioned, I've been in security 25 plus years, right? com was I felt that DevOps and the whole CICD pipeline model was a way to get like a second bite at the Apple for security. We could correct a lot of past wrongs by moving further left, shifting left into the development pipeline to fix security problems that by the, by the time we saw them pop up in production, they were a lot harder to fix.
It would be much easier to fix them further left. It sounded great, right? com devs, the whole rise of DevSecOps, as we call it, right?
Uh, we made a lot of progress over those 10, 11, 12 years, but most recently there's been a pushback where have we shifted left too far? And by that, have we put too much of the onus on security on the developer who's not a security person, right? And, but nevertheless, you know, we, we've made them the, the focal point for our security efforts and, you know, pre-deployment security where instead of, let's say, maybe building it holistically into the whole pipeline process right from left to right.
And, and so, you know, there's been pushback. Hey, instead of shift left, we should shift everywhere. We, we, we need to build security into testing.
We need it built into the pipe, not onto the developer's shoulders. Now, Kate, you've got your master's degree in, in all of these things, and, and you're, you're the head of the sig. What can we do to it?
It can't just be, let's make the developer our security or make the dev our security person. He's, he or she is not. What, what can we do?
What are we doing? What should we do, you think, in, in terms of integrating security into this workflow? Well, I think, and when you, um, go out, uh, to the specific page that, that we have, one of the areas, security is very complex, as you know.
Um, cybersecurity is very complex, and it has becomes, the complexity in itself has, is also a vulnerability. So we need to make things simple. So yes, are we putting too much on the developer and should we have it throughout the pipeline?
Absolutely. But we also need to have, um, bite size, you know, these, these, you know, Lunchable type of, of packages that we can say we're gonna do, you know, we're gonna secure in the, in the, you know, free deployment phase, and how, what does this look like? And I think this, the more simple that we have the tools, because as, you know, to introduce a new tool, um, is, is just a headache for our developers, and yet another tool, and another tool and another tool.
And so I think we need to have, um, tools that are, and they're very expensive. So tools that are, you know, open source that can be used, that can be used easily, and so that it doesn't take a master's degree to go out to try to figure out, well, how am I gonna secure this? I think that's, you know, something that we have talked about, um, with the sig.
Um, and just, it's so important to keep it simple. I mean, it, it sounds it know ridiculous, but we have made it so hard. We have made cybersecurity so difficult to consume and so expensive.
I mean, think about the tools that we have developed. I worked with IBM for over 20 years, and it's not just, you know, it wasn't just one tool. It wasn't just, you know, um, static, you know, analysis, coding, it became, I mean, you just, everything just grew and grew and grew, and we just would keep adding and adding.
So I think we need to do more with less. So, you know, the one tool can take on this pipeline from left and throughout. I know Tracy and Ryan, what, what do you guys think?
Well, I, you know, I, I preach simplicity all the time. Um, part of the problem with the CD pipeline, if I just put my DevOps hat on and not my security side, um, the problem with the, the, the CD pipeline is, it's so brittle. Um, everything's based on, uh, a script.
So we have to go update all those scripts. And that is not an easy task, folks. It is really not easy to manually update so many thousands of scripts, thousands and thousands of workflows.
Um, so it becomes a challenge because we don't wanna touch those workflows. They break easily. So then maybe we have to have a security workflow that the, that our workflow calls.
So, Kate, as you pointed out, we've made everything so complex. Everything, not only just not security's complex, but so is our workflows. They're complex too.
So we've dug ourselves in a bit of a hole, and we're behind the eight ball. So how do we get out of it? Now, many people know from my discussions that I have been a big fan of CD events.
Let's rebuild and redefine how this, the, the pipeline works. But that e, even though IBM has done a great job, and that some of the team on that project has done a great job of defining what those events look like. And even, uh, Jenkins has an event, has a CD events plugin.
We, I don't see, uh, the, what I like to call the giants, the Microsofts, and the, um, the intel, even though they've been doing a great job in some areas, I don't see them understanding why events are important, why it's important to re uh, to disrupt how we do pipelines. So as long as we have this, uh, this difficulty updating pipelines, I think we'll have difficulty implementing tools. So what we have to be able to do is define the low hanging fruit.
Let's at least get started with getting a, uh, a software bill material generated, and make that a, a, a common mantra that we can really expose to the DevOps pipeline and the DevOps engineers to say, this is one way we can get started. At least let's start there. So, simplicity, I think, will be critical.
Yeah, I, I agree with that, Tracy. Um, I, I would like to go back, uh, uh, uh, to what Alan was saying for a minute though, and, and just push back slightly on the idea that developers need to be security experts. I, I don't, I don't think developers need to be security experts, but developers do need to be capable of writing quality code.
If, if, if we don't think that there's an expectation on them to, to write quality code, uh, um, then I, I, I think there's something fundamentally broken in, in the system as, uh, they're the ones that are writing the code. Uh, and security in a lot of ways is, uh, you know, the many, many security vulnerabilities are just engineering 1 0 1 quality issues, uh, buffer, overflows, uh, uh, uh, null point or de references, things like that. Um, that said, I, I, I do, uh, uh, like what you were just saying, Tracy, uh, about events, I, I, I think one of the, the problems with how we have incorporated tooling into, uh, pipelines is, you know, it's all about, okay, how do we get this tool in here and get results out of it?
And, and that's not the focus it should be on, it should be on what's the activity that the developer is doing right now, and what's the information that we can get from our tools that would be helpful for the developer to have during this activity? A great example is pull requests with, with, uh, on gi. Uh, for example, uh, uh, you know, a lot of, a lot of organizations use, uh, uh, static application security testing tools, uh, traditionally called static code analysis.
Um, which by the way, uh, there's open source tools that have been making great strides in this area. G CCC fourteens, uh, static analyzer, uh, functionality is, is way improved over previous versions. Um, that's said, you know, the right time to be able to show a developer about flaws in their coal code using a SaaS tool is during poll request time.
And, and ensuring that, that, you know, when a developer needs the information about the quality and security of their code, it's important for 'em to have it at the right time. Uh, traditionally we've told developers, Hey, yeah, you have to go over to this of the place over here where, where, uh, the results for, for all the scans are stored. Developers hate doing that.
They won't do it, and we're never gonna win by share doing It that way. So let me weigh in here. I bet you if we did a survey of developers and said, how many of you wanna develop low quality code?
Not a lot of them are raising their heads. Every software developer I've ever met just about has a tremendous amount of pride in, in what they do and the code they develop. You know, it used to be, before we got into the age of DevOps and pipelines and the software factory that we have today, software development was very much sort of like a, a guild, right?
Ancient, uh, not ancient, but you know, like old German guilds where there was a lot of pride in craftsmanship and, and stuff like that. When I was a security guy, I used to think, boy, those people don't give a hoot about security. And if they did, we'd be better off.
But then when I, the more I got into DevOps, the more I learned that they do give a hoot about security and quality, right? Because security is synonymous with quality, and they do give a hoot. And then early on in DevSecOps, a lot of security companies said, you give a who to bet security, Mr.
And Mrs. Developer, here's a tool to use, use our tool. Use our tool, use our tool.
And you know what? And that's where it went off the rails. You, they don't, they're not going use a security tool.
When you start telling a developer, Hey, wait a second, we want to do a static analysis scan of your code. And that's not enough. Hold on.
I wanna do a dynamic scan analysis of your code. Wait, there's more. I see you've been using a lot of that open source stuff.
We're gonna do an SCA software composition analysis scan of your code, and whatever the, and I just bought this latest company's greatest new, you know, ICAS or whatever the heck, they're calling the next one to the developer. They just, Hey, can you just tell me if there's bugs in my coat so I could fix it? That's all they wanna know a hundred percent.
Right? And, and we've, I think we lose sight of that. And, and in a perfect world, that's where, and along this pipeline, these things get done and it makes its way back there, right?
And the code gets fixed. And look, here's the good news. We live in a wild time right now with AI and automation and everything.
A lot of these things could be fixed on the fly like that, right? I mean, you know, stuff we dreamed about Yeah. In 2006, right?
The, the ability to do automated remediation. I, I was selling vulnerability management in 2006. You know, no one wanted it, it, it took 90 to 120 days to remediate code that was code in production, not code in, in, in de development.
So, okay. Have We gotten any better at that? And still that?
No. We, we have, because I'm gonna tell you, the problem I had back then is we were able to identify vulnerabilities, and we built workflow into our product that pointed to the patch, and we had the ability, 'cause we also developed a NAC product network access control. We had the ability to remediate on the fly.
No one would let us, yeah, yes, no one would let us because they were afraid to patch without first testing to make sure that it didn't break something else. It might break your stuff, Right? We can't, I'd rather be insecure than have broken stuff.
I don't necessarily agree with that logic, but nevertheless, that was the prevailing logic. Have, have we changed? Ryan?
You've been around. We're Trying. Yeah, we're trying.
But did that means we haven't changed? Is that what you're saying? Yes.
I, I would, I would say there, there are areas in the industry where, where it hasn't changed and change is hard. Uh, um, and, and to be honest, I I work in one of those industries right now. Uh, um, one of the things that blew me away when I came to work for Carrier is the support life for some of our products.
I, I mean, I, I used to work on automotive stuff where they're talking about support life of eight to 10 years. Uh, we have to support software stacks in our products for 25 to 30 years. And, and because of that, the interesting legacy implications of some of the software we have, uh, uh, just are, are an interesting challenge for us in, in the new ecosystems.
And, and a lot of people are resistant to change because of that. Agreed. Right?
You're talking about critical infrastructure. I mean, right, Brian? I mean, you know, You, you know about it.
Kate, Windows xp, baby know. Good luck. Um, good.
You know, the one thing that I think would help us, and it's the antithesis of when we think about cybersecurity, but you know, the, the bad actors are doing this. And that is, you know, when we talk about open source, you know, they actually, that the bad actors actually do it, right? They collaborate, right?
The reason they're able to get their stuff done so quickly is they have such huge collaboration tools. And I actually think they're doing it right. I mean, it's a, you know, crazy idea.
But I think we need that, you know, that the, that those who are trying to make things better, that we really need to, to be, you know, have open source, you know, from, so from, you know, coming from all these, you know, companies that were, you know, doing proprietary stuff, you know, I've been like this new open source, you know, let's collaborate. Let's, I think it's gonna be one of the most important things because when we have this discussion about, you know, the pipeline and can it just be on, on, you know, the, the, the shoulders of, of the very beginning person, you know, when we talk about cybersecurity, one of the things that we would talk about is, is everybody's, you know, everybody has to know about cybersecurity. Everybody has to understand it from the user with their, you know, digital user interface with their, um, mobile phone, uh, which has become a human machine interface to so much to, um, you know, to, to the worker, because we are one in the same, right?
You know, that the, the home user is also the one who's going into the office, who's also working with a, you know, we all need to think about cybersecurity differently, um, in order to help things to become, I mean, it, it sounds, you know, somewhat esoteric, but we really, we need to, to do it. So it's not so scary, right? Because we sell based on people being scared.
And we need to, we need to really back up from that and think, what are we gonna do to make it better? I think, and, you know, to, to Tracy's point about, you know, low hanging fruit, boy, how much can we, I I, how much can we do with just getting the low hanging fruit? You know?
I mean that, I, I think I, I think it could be like a 70% type of thing. And, you know, maybe that's a crazy percentile, but, you know, long hanging fruit, I mean, that's a, it's a great idea. There's definitive Wins there.
Absolutely. There's a whole bunch. If you could just, you know, just take those, you know, we've got a few minutes left.
Let me bring up another kind of push pull that I think really affects us. And that is, and this has been going on, bro, as long as I'm in security, which is what's my tolerance for security slowing things down? Yeah.
Well, that's a good question. That's, that's that a little question, You know, because that same survey where I asked the developers, do you like making low qual or, you know, crafting low quality clo uh, code. The next question is, you know, why don't you do security better?
And it's always because the pressure is on, and I get paid based upon how many lines of code I publish, and I don't have enough time to write and test. We don't have enough time to write and test the code thoroughly, because we have deadlines to meet. And so when security becomes the people who say no, and puts the brake on going faster, we very quickly get kinda shoved out to the side, pushed to the back, you know, stay outta the way of this.
You're, you're standing in the way of progress. Um, how do we, and, and again, this was one of the things about Def SecOps that I thought we would do better. How do we overcome that perception and move it to speed of business?
I like to say moving at the speed of DevOps, Right? Okay. Moving at the speed of DevOps.
So we have a weird, there's a, you know, there's a, the cultures between the DevOps people and the culture between the security people could not be more different. Um, if we think about v uh, a new vulnerability that's been found in production, the mindset of security is don't tell anybody. Go through a, uh, event management process.
Notify the people, only the people that should know. Because if we, uh, tell everybody and let the development team who's being impacted know that they may have, we may have some kind of internal attack to it. So there is a hold this, you know, hold the cards close to the chest mentality inside the inside on the security side.
It just is there. They don't, they lack the trust. They want the control of managing it.
This slows everything down. The, the, our, our culture there has, is, is just wrong. Now remember, it may have started back in the, in 2000, Alan, when you were trying to solve the problem.
And what they were doing is they were, you know, if a, a, a bug was found, uh, uh, if a hacker found a vulnerability that impacted Microsoft or IBM or the government, or Hewlett Packard or anybody else, they got, they were purchased. So we had a zero day market and nobody told anybody about them. So that's where we begin our story in security.
Now, on the other side, we have DevOps engineers who have been preaching agile development and releasing fast for the last 10 years. And we have gotten really good at it. And on top of that, we have Kubernetes, which means everything's decoupled.
Everybody use, it builds their own container. So that one production vulnerability could be living in hundreds of containers across our endpoints. So now we find ourselves having to fix some really big problems with a culture that doesn't want anybody to know about it.
And another culture who says, you guys are way too slow. We need to continue pushing new innovation across the pipeline, because that's what we're being told to do, and we're trying to build the best quality code we can. And we're trying to manage DevOps pipeline so that they're getting code out as quickly as possible.
Because that's what the business demands and security sitting there and saying, well, we don't want anybody to really know about this. Let us try to mitigate it and go through the process and only tell the teams that need to know that this problem happens. It doesn't work.
Those two cultures are, are conflicting. So somehow we have to create that handshake is kind of what I began this conversation. Security has to be more willing to open up the door and let more people know about it.
Security has to be willing to have those fixes pushed across. And Alan, you were just way before your time. In our world, what we're trying to do, you know, for Intelius and to play up, we or we, Orillia has the information right now to be able to push out a remediation.
So we have discussions about discovery and how to remediate. We wanna shift the focus to how does DevOps fix it? How can we use DevOps information to at least create, update a, a helm chart or a, a Docker file, and at least create a pull request for a high security vulnerability that's impacting certain teams and get it to them as quick as possible so they can make a decision if they want to move it forward, they can do the analysis and they can accept or reject that pull request.
But to do that, we have to get the security teams to say, yeah, that would work. That would be okay. But at the moment, they may not be saying that.
'cause they're saying, no, we wanna manage that response ourselves, and it slows everything down, and the world just keeps turning while security figures out what they need to do. I, I think that's beautiful. Uh, you're right on.
Yeah. I, I mean, we, we, in the cybersecurity, um, Alan and Ryan, I mean, right? I mean, we, it we need to change this mindset that we have, and I really do believe that we need to be more open about the vulnerabilities that we have, or we're not, we're not making it the way we were doing it.
We know that. So it's about time that we switch things up and say, okay, let's try something different. Yeah, I, I, I agree with, with what both Tracy and Kate were saying.
Uh, I, I'd also just add to, uh, uh, taking a, a, a little bit of a, uh, uh, uh, perspective change. I, I think security folks, a lot of times new sites of what developers really need, uh, to, to do their jobs right, and, and do their jobs the way security folks think they should do their jobs, uh, uh, uh, and, and a lot of the things that, that security professionals ask teams to do without thinking about it, uh, uh, dramatically slow development down. 5 times the build time.
And building the Linux kernel is not a, a small event anyway. So you can't ask dev teams to, to wait for, for 2, 3, 4, 5 hours for results on tools until a pull request before they can go accepted. Uh, uh, you, you know, you, you have to figure out what's the right balance, uh, uh, to be able to, uh, uh, bring the bar up from where teams are doing it right now, to, to, uh, doing it in a way that, that they feel is acceptable use of, of their bandwidth and their time.
Agreed. Agreed. Hey, guys, we're, we're about outta time here, unfortunately, you know, we didn't mention the CDF.
You mentioned the, uh, STIG that you guys started. org, isn't it? foundation, Excuse me, CD Foundation.
CD Foundation, yes. And the SIG is new. It just started in January.
And our first exercise is we're going through the, um, secure software development framework. We're looking at every single task that relates to the pipeline, and we're associating open source tools that can be used to, to accomplish the task. I love it.
Can you get to the sig off of CD Foundation page? Yes, We should be able to go to the, um, uh, community page and find it. Alrighty, Kate, congratulations on leading the SIG there and getting your hand into this open source security world.
It's going to, we, we can all use the help. So thank you for your, for your efforts there, Ryan, same to you, right? It sounds like you've been involved in this for a while now, whether it through Carrier or Intel, what have you.
And thank you for all you are doing. Thank you. I appreciate it all.
I just have one more, I just have one more thing before we sign off. I wanna shout out. Shout out to Sasha, uh, Wharton, who is one of our, uh, top or like Ortel contributors, and he was recently nominated to the, uh, the CDF, uh, governing board as a open source representative.
So we're super proud of him. Congratulations to Sasha as well. All righty.
That's it for CD pipelines. foundation. Until then, is Alan Shimmel for Techstrong.
Thanks everyone. Bye-bye. Okay.
Glen Sullivan, senior director of products here at Infoblox, gonna talk to you about Universal Asset Insights now, and we're gonna jump right into it. What are the problems that we're, we're looking to solve here from a challenge perspective? Right?
So, asset insights is really, uh, network discovery, right? It's network discovery for on-prem, it's network Discovery cloud. It is the way to reconcile what you've designed from an IPAM and DNS infrastructure standpoint to your as-built environment, right?
You know, as network engineers, we have a picture that we like to draw and say, this is the way the network looks. Uh, asset insights is a way to figure out if it's the way that it actually looks. So we know that managing networks is difficult, right?
Especially if you're managing on-prem and cloud, especially in multi-cloud or multi-tenancy. Um, you have limited visibility as a network team for what has been allocated and used by the cloud team. So depending on how siloed you are, this, this problem can get worse.
Um, but in general, even in very integrated teams, we find all the time, the, the use, the primary use case of, Hey, I gave a slash 16 to the AWS team. They started carving it up into slash 20 fours for their VPCs. I have no idea how they're being used.
They come back to me two weeks later, they say, Hey, I've run out of ips. And I say, as a network engineer, I gave you 65,000 IP addresses. What did you do with them?
And they're like, we don't know, because they don't speak ip. They speak applications. So there's this primary disconnect with how networks are planned and managed and how networks are used in the cloud.
We see this back and forth all the time. So there's no centralized visibility for the network team on the allocations they make. And even in the cloud ops teams, there's no centralized place where they're seeing all of the ips across the board and how they're being managed across the different cloud environments.
So what is this? What happens, right? This can cause, uh, overlapping ips, right?
This can cause outages because maybe that VPC that was isolated last week now needs to talk on-prem. So either I've gotta come up with some, you know, fancy nat solution for translating the ips, or I have an eye conflict because I didn't realize that there was an overlap between, you know, on-prem and, uh, the cloud. The other problem is IP exhaustion, right?
So, you know, what can happen frequently is, is I'm either running out or I'm using too many, right? So the cloud team gets, uh, you know, a slash 16 or slash 24, and maybe they, the, uh, the network team needs to reconcile some of those ips or reclaim some of those ips for other parts of the environment, right? So it's, it's not just overlaps, it's also wasting ips that you've been given.
So this for this fragmented deployment causes, you know, lots of concerns and lots of issues with trying to find, you know, what's deployed in the environment. And, uh, there's, there's not a lot of tools out there for seeing things that are visible across the board. So this is what we've done with Universal Asset Insights.
Uh, we've, we've had network discovery in our, in our products for a long time, because we firmly believe that the way to reconcile as-built environment with what's designed is to scan on a regular basis what's in the network and see, you know, how are the IPS being used or, or how, um, you know, how, how are the assets in your environment deployed, right? So we've had an on-prem solution for years, and we've also had a cloud solution that relied on servers. Well, obviously servers are, are an, an allergy to cloud ops teams deploying a server and an appliance, no matter if it's virtual or not, they don't want to do it.
They want you to pull the data that you can pull with APIs. So what we've done is we've said, okay, so anywhere where there has to be something deployed, because I have to speak network protocols, and these are kind of, you know, old school network discovery protocols, but these are the ways that you have to interface with a lot of networking gear. S-N-P-C-L-I, uh, you know, ICMP, all of the kind of old school protocols for getting, you know, data added network devices, we call it interrogating network devices, which sounds terrible, but it's really what you're doing, right?
Seeing an access point. Tell me about everything that's attached to you. So we do that OnPrem through NI OS X, we deploy a server, it runs the discovery protocol and the discovery jobs, it pulls the data in.
And the nice thing about the solution that we have now is the consolidation all happens in the cloud. So previous solutions, you would have to deploy a lot of probes and condensers and a lot of things on-prem to be able to reconcile all of the assets, right? If I have a laptop that's seen on one access point in one building, and then later on in the day it's seen in another access point in another building somewhere, I have to consolidate that into a single asset.
I typically would have to deploy a decent amount of, you know, either virtual or physical hardware or appliances on-prem to do that reconciliation. Now, I have a very, very lightweight probing infrastructure, and all the consolidation happens in the cloud. The other thing that we take advantage from a cloud to cloud perspective is now, uh, any, all of the cloud, uh, discovery that happens from a AWS Azure and GCP standpoint all happens direct API to API.
So there's no need to deploy a server or physical or virtual to do that. The other thing it allows me to do, and we're, we're actually, you can see it's an orange, we're adding this now, uh, is the ability to speak with cloud controllers, right? So the last thing I want to do as a, you know, network engineer is deploy something to talk to a Meraki or talk to a mist, right?
I have the cloud services for a reason. I want to interface with those directly. So we're not gonna deploy, you know, a server on prem to speak.
SNMP to a Meraki controller. Doesn't make any sense. We'll talk to the Meraki controller directly via the cloud cloud APIs.
The last thing I want to touch on from an integration standpoint is third party, uh, agent integration, right? So we, there's a tremendous amount of data in your environments that are inside of CrowdStrike or inside of ServiceNow or other third party, uh, you know, uh, solutions that run agents on top of laptops, right? So what we do is we actually pull the data from those third party environments, and we integrate them and consolidate it into our asset information so that when you're looking at the, the, you know, the laptop here as it's scanned on-prem from whatever, you know, uh, network device it's talking to, we can enrich the data from, uh, what we're getting from, you know, CrowdStrike and or ServiceNow.
Not to mention, because we're anchored in DNS and DHCP, we know a heck of a lot of this asset as it's in the environment because it's doing DNS queries. We know those queries. We are the ones that gave in an IP address from A-D-H-C-P perspective.
So, uh, there's a lot of data that we can pull, especially since we're anchoring in DDI as the primary source of information for all of, for everything to do with this asset. And then you could see that we're, uh, consolidating all of this into, into a, into a work, uh, workspace here, which Jason will get into and show you a little bit about. But what's providing insights on the data, right?
Primary use cases is reconciling IPM and DNS, but there's some secondary use cases, uh, pulling insights into your asset inventory as well. I have a question, please. In terms of what's an asset?
Asset, is anything in your environment, um, that you're tracking as a, uh, it, it can have an IP or it cannot have an ip, but it's typically a, a workstation like this, an ELB, an NLB, um, an S3 bucket in, you know, in AWS. Uh, so it's anything that you're, uh, tracking at that level in your environment. So it may have an ip, most of them have ips, but some of them do not.
What about, say, containers running it on, uh, a node, would, would you consider each of those containers an asset or just the node an asset, or is that kind of up to you to make that The node right now is an asset. We are looking at doing Kubernetes level insights to provide even more detail to you, but right now it would be at the node level or at the, at the pod level. Um, applications aren't assets yet.
Uh, users will be assets soon. When you say at the pod level, uh, you're saying that Infoblox can do that now or That's horizon? No, Kubernetes insights is on the horizon.
It's on the horizon. So we would see the instances or the VMs that that is running on, but we do not go into the Kubernetes layer yet. Okay, got it.
So if you were to go into the Kubernetes layer, like let's say we were talking about pods, does that mean like, let's say you have a sidecar container running, right? Mm-hmm. The containers both have the same IP address, just different ports.
Mm-hmm. Is, is it theoretical that you'd be able to go in and pull mm-hmm. The information from each of those containers?
Yeah. And, and this is where things get a little tricky, because if I was kind of not intelligent about it and I said, well, every IP in your environment goes into ipam, then we're gonna run into overlaps because, right? And what, as I talk to more and more cloud admins, they say, I don't actually care if you track who has what ips inside of the pod.
What I actually want to know is the pod running out of ips. So that's the level of insight. Like maybe we gave the, or maybe it has too many, right?
Maybe the default size of that cluster is 20 slash 24 and it's only got 30 ips, so they're wasting, you know, a couple hundred and maybe they should go in and adjust it to a 27. Those are the level of insights that most of the, uh, cluster admins that I talk to want. Okay.
So, uh, asset insights here, uh, you can, you can see from, uh, from this output, we're gonna get into some details on it a little more. It's pulling in all of the discovery information. It's providing the insights and recommendations based on, based on the findings that we have, based on the data that we're pulling.
It's not just a flat inventory, it's also some insightful information about that inventory. It's a single place to see, you know, hybrid and multi-cloud environments. And for everything that you see, you can drill in and see all of the assets that fit that classification and all of the data that we're pulling, you know, from that provider, right?
So it's important that we show you an insight, let you go into the insight, show you about it, and then show you even more details that are based on the source information, right? So we're pulling all of the information, uh, that would come from the cloud environment for that Couple of use cases that I wanted to, uh, talk about from our customers, right? From a customer standpoint perspective on asset insights.
Um, the, the one that I comes up over and over and over again is m and a, right? So we had, in our early access program, we had a major media conglomerate company. They buy companies all the time.
They buy little media companies like on a quarterly basis. And the number one thing is they say is, we don't know what we're getting when we buy a company. And, and sometimes you talk to 'em and they're like, Hey, we, we figure this out when they sign the contract.
And sometimes they figure it out, the network team is the last team to know. And it's like, no, no, this is a done deal. You've got three months to integrate their environment.
And it's like, well, we don't even know what IPS overlap. We don't even know, you know, how many Azure accounts they have. So we provide this visibility to them very early on in the process, and we can show them data in a matter of, you know, in a matter of minutes.
Uh, a couple of, a couple of use cases real quick. We have a power, uh, company that's using us, a international power company, um, and they have over 7 million assets in the cloud, and they didn't know that they had over 7 million assets in the cloud. So we were able to show them insights based 7 million assets.
I also have an insurance conglomerate who has over 4 million assets in the cloud. Um, and that was definitely a wide-eyed moment for these guys when they started putting in all of the, the different, uh, you know, credentials and, and connected all the, to all the clouds, and they saw they had over 4 million assets. A big surprise.
Uh, so these are the kind of insights that we can provide. And then we obviously can drill into the details about what those assets are, but sometimes just the number itself is surprising with that. This is the easier product to show you rather than talk about.
So I'm gonna hand this over to, to Jason so that he gives, gets you guys up to speed. And we would think, like, it's always like, oh, you've got a class A private. So of course we all choose the same first one, right?
Everybody has a 10 slash eight always, right? Everybody has 10 slash eight. Okay?
So I'm Jason Marketing at Infoblox. And then this next demo, we're gonna look a bit at Asset Insights that Glen was talking about. Uh, so I'm starting off here, back on the, um, the, the IP space or address spaces page, right?
Because kind of the, um, the backbone of asset insights is the discovery engine and actually getting all of these assets and all of this data into, into the system. Uh, and we do that through different discovery jobs, right? So we configure discovery jobs for cloud providers for on-prem environments, uh, and for, you know, in the future Kubernetes and other things like Glen was talking about, right?
And then we pull in, um, all of that basic data. So for, for example, we'll just, uh, we'll jump into a, um, an Azure vnet here, right? So this is, this is an Azure vnet, um, not one that I created through our portal, but I, but this was existing in Azure.
I set up that, uh, that asset insights job, and it pulls in this vnet so we can see it gets, you know, the base vnet container, uh, underneath that we're gonna see, see all the subnets, um, and then we get utilization on, on each one, right? And that's, uh, not the one I meant to go into, uh, inside of any of those individual subnets. We'll start picking up on any of the anything that that was discovered in it, right?
And so this gives us that single plane of glass or that kind of source of truth of IAM of, of knowing what's in our Azure environment. Um, my environment here, we've got, I've got a private endpoint, I've got a load balancer, I've got a vm. Um, but you can, you can imagine basically anything with an IP address, anything that's got a network interface in this Azure subnet, I'm gonna see it in here.
Even if it's just a network interface, somebody left behind and it's sitting there, it's still using up an IP address. So I need to get that into the system. So that's, that's kind of the basics.
And we could go and look through other ones and we're gonna see the same for other clouds. But in, instead of doing that, um, what I'd like to look at is kind of some of the, some of the stuff we start to do once we have that data, right? Um, before I even get into the insights, I just want to show you a couple functions just on our, our IPAM page here.
I'm gonna turn on what we call flat view. And, and what Flat View does is it pulls it out of those unique ips, pulls all our addressing out of those unique IP spaces and lets us work with the data set as a whole, right? So I have a, a, a ton of networks in my environment, IPV six, IPV four.
Um, and, and by, by turning on this flat view, I can actually look at those and, and work with them as a whole. So, first thing on this page that's, uh, that's really useful is just overlap, right? So a very common thing to find, um, in, in networks is overlap thinking.
Um, you know, we talk about cloud environments and we've got cloud teams kind of, kind of running wild and deploying their own stuff. Network team comes back and it's time to get that under control, get it back into the, you know, into the network. We do a discovery like this, and we may run across overlap.
So we provide some easy identification for that, uh, where I can just literally click on that yes, in any of these columns next to my networks, and it's gonna help me identify all of the other, uh, all of the other networks that this is overlapping with. Now, again, we talked, you know, some about like action versus, versus data. This is one of those things where there's not necessarily a one specific action I want to take.
So I, I'm getting this data and this insight for the customer to be able to make that choice. Does, does this overlapping network need to be corrected? Do I need to re IP this, you know, these networks or is this behind that?
And so that's perfectly acceptable that I'm reusing this IP space, right? Uh, but either way, getting it, making it visible and getting an understanding of that is, uh, is a great thing. Then we can do some, uh, some really cool filtering, right?
So I really like this IPV four utilization. Um, and I can just take this neat little slider here, and let's say I landed on 77, so I wanna see all of my networks that are 77% utilized in ips, right? I'm starting to run outta IP space.
May need to think about either, um, expanding those networks or moving some devices off of them. Uh, so a quick, quick apply here, and I'm gonna wind up right with, with all of those networks, I can do the opposite too. If I wanna see, say, my underutilized networks, networks where, um, like Glen was talking about with the Kubernetes, maybe we're, we've started, we're not using the IP space, or in my case, I've just handed it off to my, um, to my cloud guys and they're under, you know, my, my cloud guy's asking me for another slash 16.
I said, well, what did you do with that last slash 16? This is an easy way for me to come in here and see if he's actually utilizing that, right? So I can do that zero to 25%, and here I'm gonna see all those networks that are potentially underutilized and allow me to, to work with those, um, make some decisions based on that.
A lot of other, a lot of other filters and stuff we can do here. But I'm gonna move to, uh, the workspaces that, that Glen mentioned as well. And this is where, um, we go from taking that, that raw data and start, you know, running it through, through our system and providing some of those, uh, those actual insights, uh, on the information, right?
Um, so things like, since, since our IPAM and our, our asset insights is fully integrated with, uh, the DNS system, I can do things like identify, um, devices that have popped up on my network that don't have valid DNS records, right? Uh, my network actually, uh, I got a, I got a problem with that. I got a lot of devices on my network that have an ip, they're in my system.
Uh, but I don't, I don't know exactly what they are in DNS. Um, we can do things like here just a, you know, analyzing them by type. Uh, we can look at like idle or orphaned assets, right?
Think like, um, elastic IP address that's not attached to anything in AWS, it's just costing me a buck 50 every month and doing nothing, right? So we could see that, um, and get that information in here. I'm gonna jump though.
Yep. Go ahead, please. Can you explain the terminology of some of those?
I see zombie Sure. Ghost. Yeah.
Yeah, absolutely. Yep. So, so a a zombie scared like it is, it's supposed to be, it's supposed to be terrifying, but, uh, Yes.
It's, that's what we call the network team people. There you go. No, No.
Um, so, so zombies overall are basically, um, they're resources that exist in my environment, but they're, they're not managed, not utilized in, in some way. Um, not doing what, what we necessarily think they should be doing, right? Um, so, so take for example, we have the category categorizations under there of say, orphan or idle, right?
Um, so an idle could be that IP address I talked about. That's, that we would consider that a, a zombie asset because it's, it's out there, it exists, but it's not, it's not working for us, right? Um, it could also be something like a load balancer in, in Azure or AWS, we can even go into like idle here.
Um, and we would see like load balancers or things like that where we're not seeing any traffic passing through. So again, like, here's a load balancer in Azure. Uh, we're, we're seeing no, you know, no traffic, nothing passing through it.
So it's, it's, you know, it's, it's there, it's not doing, it's not working for us, right? Mm-hmm. Um, and then we get down to, to some of those other, uh, types.
So a ghost asset is actually gonna have to do with, um, kind of the next screen. I'm gonna show you where we go into some, um, some of the other insights on DNS records. Um, and a ghost asset is gonna be an asset we, we actually think should be here, but it's not for whatever reason.
And I'll, and I'll, I'll tie that in in just a second. Um, yeah. So let me actually go right over there.
I'll go over to, to our, our network screen here. Um, so this, this monitor here is talking about those DNS record classifications, right? And we have a few different types.
So we have, um, abandoned, and an abandoned is going to mean, um, like A-A-D-N-S record that that was pointed to something that, that used to exist in our inventory. Um, but, but doesn't anymore, right? So it could be like a public IP address, for example, right?
If I look in here, uh, one of the top ones I'll see here is a record for, here we go. We got a record for, uh, for a public IP address. However, I no longer see this public IP address in my asset inventory.
And so we think, okay, this, this is an abandoned record, right? Somebody else could potentially pick up that, that, um, that public address, use it. Now they've got a record with my system, right?
And we start getting into those, uh, those reputational things like we discussed earlier. Um, the other ones that we have here, uh, let's see, we'll go When you say abandoned, yes. And I, I, I think of meaning that you're pinging it or you're checking it, that it's valid or something like that.
It's being utilized Or No, it's, it's more, it's more the tie into assets. So, so in, in this case, it would be that, like that that public IP that we looked at, uh, doesn't exist in my asset inventory. So I don't know whose public IP that is necessarily.
What if It's, uh, a vendor or a provider that you're pointing towards that it Should be, yep. And there, and it, and it's a possibility. And that's why we're, you know, we are, we are providing this, um, as an insight here, but, but there's not, you know, the action is, we have Suppression as well.
So if you, if you validate that this is valid, we, you can, you can suppress it and say, oh, this is, this is something that I expect to see. What about reserved or DR ones that you're, you're placing, whether they're not being utilized at this point in time, they will potentially be used if they do come up or needed. Sure.
And I think we want to, we'd want to do the same thing, right? We want to, we'd want to suppress that, that record. Yeah.
These are, these are legitimate records. Are they suppressed for a period of time or completely suppressed and that I should be reevaluating them from periodic? Both.
Both options. Both. Can you like suppress by tagging or some, like, some way that we can just basically identify it, say, yeah, these are Dr.
So let's, not yet, but that's a great idea. Yeah. One question as well.
Do you, do you by chance present this in any way as a graph to the outside? 'cause you actually really have a really good mapping of what the application flow looks like. But I know it smile Because, because the, because the answer is not yet, right?
And, uh, but, but yeah, that is definitely, um, something, something working on for the future, right? Is some graphical representation of these networks. 'cause you're right, we could really tie together how the, how are these networks connected in the clouds, all that different stuff, right?
Yeah, absolutely. Uh, so, so the last record type I will show you here. And I, I think that's a really good example.
And this is, um, this will go back to the answer the ghost asset question as well, right? Dang. Um, so there's dangling record type.
And so, so this is, this is, again, some, some type of record that that basically points to nowhere. Um, and what I had here is, is I, I had an S3 bucket. I had it turned on, you know, I had it set up for static website hosting, right?
Uh, so A AWS gives me a nice URL to use for that hosting, but I don't want to use that URL. So I created a C name in one of my zones, uh, for that, for that, that S3 bucket. However, I've since deleted that S3 bucket.
It's served its purpose, it's no longer needed, but forgot to clean up that record, right? And so now I can see that here as that dangling record. So like Glen was saying, this is potentially dangerous because someone, someone else could now go out and create an S3 bucket, reusing this name since I'm no longer using it.
And they've now got, uh, you know, got a clean record from my environment pointing into whatever, whatever they may be doing. Probably not something good if they're trying to, uh, mask themselves as me. Uh, and so I wanna take care of that.
And so we would also show this, this bucket as a ghost record in our asset insights. Meaning, Hey, this was here before. We still have DNS records for it.
Uh, but this asset is no, is no longer here. And that that's our ghost as Well. Can you apply ops policies in here where you could say, I'm not allowed to create a resource unless it has a minimum of one tag.
Or like, is there a way to create behaviors of how to ensure that that's going on? It's a bit of an edge case, but, you know, I just find people, I used to do this with us. Like, if I see someone no tag in 24 hours, I'm gonna delete this, whatever it is.
Yeah. And there nothing, um, nothing native built in for, you know, for, for like tagging policies. Um, so that would, you know, be something that you'd have to educate and enforce.
Um, and of course You can actually, we could pull a view from the, the, and say like, find all non-ag resources and we could at least see the, the view from the top inside info blocks, right? Glen just added it to the roadmap, right? There we go.
Good idea. Now that's, see, see that one fast to Action, right? That's a great idea.
One more operational challenge. Well, maybe rare, what do you do around collisions of changes? So if somebody goes into AWS Route 53, if somebody goes in my fine Fred Net goes into Terraform and, and does some magic, and I go into Infoblox ni Os and I make a change.
So three changes are actively happening to the same resources within the five minute discovery window. What happens? So there's, so there's, yeah, but, but there's also the ownership on the zone, right?
So, so yeah, there's also a concept of federation, which we are not gonna get into here. We, there's some, we have some blogs published on that. Um, we had to invent a protocol for creating consistency of ownership across ipam.
DNS kind of has it built into the protocol, but IAM doesn't. So we had to create something called IPAM Federation. And we have this thing called realms that basically says in the, here's the realm with all the participants, and then there's different owners of different zones, and the zone owner matters in the context of who writes last.
So we have some material out there published on that. Yeah. Nice.
Great. Thanks. Hi, everyone.
St. Patty's Day is over. It's, we're back at it.
Is there an AI chip crisis? We've got AI in Margaritaville. You're watching Textron Gang.
Hi everyone, it's Alan Shimmel here for Techron Gang. Happy Tuesday to you. We hope you had a fantastic St.
Patrick's Day. If, if you celebrate St. Patty's Day, everyone likes to celebrate St.
Patty's Day, it seems. But, um, anyway, it's Tuesday, it's back to work time, and we've got work to do and, and you know, there's lots of good stuff going on out there to talk about, and we've got some great people here to talk about it with. We, we've got a Core four for today.
Lineup first. Uh, we have the guitar man out in Colorado there. He's a FU vp, DevOps analyst.
Mitch Ashley. Hey Mitch. How are you?
Good. Good. I'm gonna adopt a new theme song, inferencing Away Again in Margaritaville.
Okay. I like that. I like that.
You didn't use AI to write that, did you? No, I did not. Oh.
Because I figured AI just stole the tune from somewhere or something. I don't dunno. It was that good.
Yeah. Mo Moving, moving from Colorado to Hudson, Ohio in the world, in the data center world. Uh, it's Stephen fst.
Uh, Stephen of course is CEO, founder of Tech Field Day Fu Company, and a bonafide gang member here. Yeah. Hey, Steven, how are you?
Pretty good. Pretty good. Um, local Mexican restaurant here had, uh, corn, beef and cabbage tacos, if you can believe it, for, uh, St.
Patrick's Day. Uh, so, um, I, I didn't, didn't partake In that. Couldn't do it, huh?
I had, um, uh, corn beef and cabbage egg rolls over at Miller's Ale house. Sounds good. Good fed, middling.
You gotta put a lot of mustard on them. Um, but anyway, yeah, so I'm glad to see though, at least you had a little bit of the spirit and then You got the spirit. You know, I, I should mention that our, our head, St.
Patrick's Day, grand Marshall, I guess, had a lot of the spirit and couldn't make it today, so we'll, we'll see him tomorrow. Um, but joining us here in our Boca headquarters is our, uh, sustainability, echo Insights analyst and editor Bonnie Schneider. Hey, Bonnie, how are you?
I'm Doing well. And you know, my subject matter is green, so it works for St. Pat's.
Absolutely. This is, this is kind of your big holiday, right? It's a green holiday.
Good for you. Anyway, we're not gonna discuss a lot of green, but we are, let's kick it off with our first, uh, story for today. And that is this, I don't know if it's real or not, but some people are talking about an AI chip crisis, right?
Uh, all of a sudden, I don't know, someone woke up from there, St. Patty's Day hung hangover and said, oh my God, we, we don't, we don't have enough AI chips. We're not gonna be able to make enough AI chips.
It's like a, a reoccurring nightmare for the AI crowd. Maybe we had two stories over in Gestalt it, which is part of the tech strong, uh, site, a family of sites. Um, Mitch, you wanna dive in on this with us?
Yeah. Happy, happy to do it. You know, like me, things we kind of feast or famine, we don't need any more chips.
'cause we got, uh, deep seed just changed the whole model. Well, now we're back to, oh no, we don't have enough chips. Um, both, uh, OpenAI and Meta were saying, look, we're, we're saturated.
Our current GPUs that we have in supply are busy doing training and being used for customer services, and we can't buy enough of 'em. They're not available. Uh, and of course, meta is working on its own, uh, chip.
It's got something that's using and training, uh, though it's not an into production type systems, but we're back in the, we don't have enough of these and there's no bubble. 'cause we still need more chips. And whether any of those services are profitable yet, and making, you know, making lots of positive income on top of expenses is yet to be seen.
But we're back in the, we need more chips. You know, I guess it isn't, uh, we don't need my MTV, we need a, my GPU. We'll get dire Straits to rewrite that song.
Or AI. Or ai. There you go.
You got the guitars to do it, man. You could do it yourself. I, I, let's for, I, I believe in you.
There we go. We, we'll put a little, you know, Irish Day spin on it or something. I dunno, what would for Mike, there's A lot of spin on this stuff, but like, on the, on the spin topic, um, I think the one that is really gonna be telling is, you know, kind of where rubber meets the road with the businesses.
And OpenAI is saying that they actually, um, that they're able to rent out access to their GPUs at a profit. Um, you know, if, if that's true, if Microsoft and OpenAI are saturated with, uh, GPU bound workloads and they're able to make a profit on it, well then I guess it's all true. Um, and I guess the whole deep seek thing, you know, it's interesting they optimized their model, but again, that was just one model.
There's a lot of other AI models out there, a lot of things beyond LLMs that are being developed. And, um, those are all gonna need, uh, GPUs as well. And then of course, there's the whole inferencing world, and, and yeah, maybe deep seek showed us that we can inference on the cheap, but, uh, it doesn't mean that we have enough.
Yeah. And, and, you know, look, the whole deep seek thing is still sort of, I don't wanna say controversial, but it is controversial, right? It, let's say it's not, it's still theory.
Mm-hmm. And we're still trying to prove all that out, whether it's because of paranoia regarding it being, it it's from China or something else. We, it jury's still out on, on the deep seek stuff there, though.
There's obviously something there. They did a little cheaper. Uh, but here's, here's a couple of things.
I'm a little confused with the open AI message. On the one hand, it's, oh my God, I don't have enough GPUs to do training and inferencing and, and to, to fulfill our business plans. But on the other hand, hey, you know what?
I've got an extra GPU capacity that I could rent out at a profit. Well, what's it gonna be Bob one or the other? 'cause it, I don't know if those are, those are kind of mutually exclusive, right?
Because if renting it out for a profit is a better outcome for you than filling out your business model that you don't have enough GPUs to do with. What is that telling me? Number one?
Well, to keep in mind, there's a difference between, uh, having, making a profit on a service versus the company being profitable. 7 billion. I thought it was five In 2024.
Um, that's what I, maybe couple Billion Something That's couple what's A couple among, among US Americans. Exactly. Now they're forecasting to be, I think it's like 11 billion this year, 214% growth increase, something around that range.
Um, so we'll see, you know, did they turn that corner? They didn't, I don't think they made any statements about profitability on that, but we'll see. They just took what, another 65 billion in funding round mm-hmm.
Was their last round. So there's a lot of money being thrown around. And so for some, for anybody to say, oh yes, we can operate that as at a profit, well, I can get, you know, a thousand miles to the gallon on my car by sitting in my driveway too.
Mm-hmm. You know, it's, it's all depends on what conditions we're talking about. I, um, look, I I say wake three to five years for the American foundries to come online and you'll have all the chips you want If they can do it that fast.
Yeah. If they do it that fast and the rest of the world stops moving forward, That's the whole thing, isn't it? I mean, and, and, and we might hear that, oh, I don't know, maybe in this next block of stories too, it's not enough to say we can maybe in the future do something.
It's enough to, you know, we gotta be, we gotta be actually doing it. And again, like I said, the the rubber meets the road when you're actually, when a company is buying stuff and selling stuff to customers, and customers are paying for it. And if that's happening, then awesome.
I guess the question is, do we, how much do we trust, um, open ai? But despite how much you trust open ai, I can't wait to see Microsoft's and Google's and Amazon's financials. I can't wait to see Core Weave.
When they go IPO and they start having to release financials, then we'll really know the state of this industry. Because, you know, you can say what you want when you're a private company, but when you're a public company and investors are watching, and, uh, the SEC is watching, well, then it's gonna get real interesting really quick, uh, whether this is really a, um, uh, an AI boom or just another AI bubble. Agreed.
Agreed. Here's another interesting thing, though. You know, Mitchell, Steven, we grew up in the era of dedicated companies that made chips.
They either had their own foundries where they produced those chips, or they designed the chips and, you know, and had companies like TSMC, uh, do the, make the chips for them. But there was clearly a distinction of labor between chip companies and then companies who used those chips for software applications, computing, all, all of that, right? So in my time growing up, look, Intel was pretty much a monopoly, right?
The old Wintel monopoly. And of course, a MD came in there and, and kinda, you know, tried to rock the boat. But let's face it, for a long time they were just a, a nice half to stop the government from, you know, prosecuting Intel from Monopoly.
Um, but then with mobile chips, and then of course with arm, and then, you know, apple started, went back to making their own chips. We, we've seen this move over the last, let's say, 15 years of companies making, or at least designing their own silicon. The chips still made a silicon, they're still made a silicon, uh, you know, of designing their own silicon.
Now, with the advent of AI and, and the advent of, well, not the advent, but I don't wanna say the demise, but the sun setting of intel from what it was, we're seeing a move away from doing business with chip designers and makers to a lot of these big tech companies designing their own chips. Is it because designing chips has become that easy? Is it that cheap?
Like, why, why, why do you think we're seeing the sunset of the, of the pure play chip designers, if you will, there? Or are we, is There like a, a geopolitical issue involved with the two relying, you know, wanting to be more self-sufficient? Well, in, in the case of, of fabricating chips, clearly China and Taiwan have, you know, a, I don't wanna say a stranglehold, but a, a, a dominant position.
But Mitch, we never saw companies designing their own chips like this before. No, it was, it was Apple, Motorola, you had, you know, you mentioned a MD arm, really Arm really kind of opened things up. 'cause now you have an architecture that's reusable and many people, but this is, this has happened in several areas.
I know even in the, in the cable industry, um, Comcast moved from just buying product from vendors to really designing their own hardware and having people build it for them, of which the subset of that came from some of their other suppliers. Um, I don't know if they did their own chips or not, but I, I think the capability is so much easier to do today that you can outsource the fab of it you to A-T-S-M-C and the skills. There are a lot of people who, uh, know how to design chips these days.
It's not sort of cornered in the market of a few companies. And I think it, it, what it does is it ends the reliance on expensive general purpose chips, like the Intel platform, which was always the biggest complaint of, you know, why is $450 of the $1,500 computer going to Intel, right? That's a lot of money that, that you're giving away to sell a product to a customer.
So I think there's a lot of incentive here. I think it's a strategy to diversify and, and have multiple supply chains, right? You know, meta is doing, had this chip idea kind of struggle with IT folks did on training and, uh, you know, it's, it's, they're using it to combat the, the lack of chips, at least for training purposes right now.
So I think it's a, it's the wave of the future. All the kids are doing it right. I think that we're gonna see this more and more commonplace, And I think we're gonna really see it on the inferencing side.
Um, you know, the developers of the models, you know, they really want to use Nvidia. They really, um, are all about that. I, I like these moves that we're seeing from Cru companies like, uh, Seuss and, um, Microsoft and, uh, Google and so on, deploying custom chips as a service in the cloud for inferencing tasks.
Because I think that that may be where the Nvidia, I don't wanna say monopoly necessarily, but the Nvidia lock gets broken. If you can do things as a service, then you can start really, um, arbitraging the cost of electricity and the efficiency of the chips and so on in order to really see gains, uh, you know, financial gains instead of just pouring everything into bigger and bigger clusters of Nvidia GPUs. I, I, I look to the future where the, the move to custom silicon becomes a, um, sort of a, a custom silicon as a service world, where it becomes that much more beneficial to have more efficient custom silicon because people are able to quickly jump on it as a service instead of, uh, just thinking of, of these things as something that you, you, you buy as a capital expense.
Agreed. Well, I, I, I'll tell you this, chips have never been sexier, right? Than they, than they are in today's market.
And in conjunction with that, you know, both of the articles in today's that are referenced in today's segment here come from Gestalt it, which of course, Steven, you started as part of Gestalt It Tech Field Day and Gestalt, it's, you know, been a site here for, what, about 14 years or something like this, right? Yeah. A little longer than that.
Um, yeah, we're getting up toward 20, if you can believe it. And, um, you know, as part of the Futurum combination, we are working very closely with Steven and team. And, and as I mentioned, gestalt, it is part of the tech strong umbrella of sites.
And, uh, I don't want to say too much, but we have plans, we have plans for Gestalt it and, and along with some of the other Techstrong sites. But the, the, the important thing I want to mention though, is that will be where you are, where we are going to, we are going to cover the chipsy the semiconductor scene. So if you are a semiconductor fan and you find all of this custom silicon stuff fascinating, or dare I say sexy, stay tuned to Gestalt it and what comes there.
And, uh, we're gonna, we're gonna cover that beat. We've got some interesting folks ready to start writing on it, and it's gonna be a, it's gonna be a swell time, so stay tuned more for that. Let's take a break here on Textron Gang.
We're gonna come back and, uh, play the latest multiplayer role game Quantum Quest. Um, you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way. With Textron Group.
Hey, everyone, we're back here on Techron Gang. Um, you know, we, we've all been following the, the, uh, quantum story now for years. I, I don't even remember when I wasn't following the quantum computing story, I guess really since the first time I saw my very first quantum computer at an IBM Think conference.
I think it was in Las Vegas. It looked very much like a cappuccino machine. I'll be honest.
It was the copper machine with all these kind of tubes and stuff. But anyway, um, but we always felt, I always felt anyway that Quantum would probably not be during my career, maybe during my lifetime, but not hopefully, you know, I'd be retired. But I gotta tell you that in the last two or three months, I am seeing just a ton of news around quantum and, and all of a sudden the, the forecast for Quantum went from like 2035 to 2028 or 29.
Now I've seen 2026. I don't know if that's real or not, but you know, Stephen, why not you? I mean, there's so much news coming out.
Is it, was there smoke, there's fire, or is this just smoke? Well, I, I'm not gonna bet against technological progress, because what I've learned, and, um, fun fact, I actually studied the history of technology as my major in college. And what I've seen is that technology tends to advance in, in un in surprising leaps.
And what people bet on is based on their mindset, their current mindset, and it's hard to move people forward. And quantum, I think, is one of those things like nuclear fusion, like frankly, electric cars. A lot of the technologies that, you know, you look at and you say that is so incredibly promising, and there's so many people working on it, and there's so many cool advances happening, it's gotta be right around the corner.
But we just can't, we can't guess. We can't say that that's right around the corner because like every technology, it, it only matters when it matters. It only matters when it's real.
And so you see these announcements, like Microsoft made so much, so many waves, uh, last week with their, um, majorana, um, with, with, with new physics, a new state of matter. Um, and, and there was a lot of excitement about it. There was also a lot of skepticism about it.
Anytime I hear about new physics, I say, that is not a product because it's gonna take a while for new physics to get somewhere. Now, that doesn't mean it's not gonna get anywhere, it doesn't mean that this is all nonsense, but it does mean that, again, what really matters is when there's a real product with real customers that's really being used for some kind of productive use. And we're trying to get there with Quantum.
So if you look at these articles in here, and so, so there's actually a new one that was, uh, just announced. Uh, Zong Xi, I believe is a, uh, Chinese, uh, quantum, uh, computer that, uh, apparently is running, um, a specific test, uh, much, much faster than than conventional computers. Now that makes great headlines.
Uh, you know, this one headline I'm seeing here, China, China achieves quantum supremacy one quadrillion times faster than the fastest supercomputers Yes. In a single specific task designed to demonstrate how good quantum computing can be, but not a productive task necessarily. Not something that's actually gonna, you know, invent a new medicine or figure out some new thing.
No, it's, it's a, it's a theoretical task still. And we're still theoretical in terms of where we're at with quantum computing. That doesn't mean it's not real, it doesn't mean, you know, there's a lot of skepticism about Microsoft's claims, and in fact, some of the people involved in the Microsoft, um, effort, their quantum computing chip effort have, have received some, um, withering glances from those in the know who've said, wait a second, these guys have fooled me before and it didn't come out right.
Why should I believe them now? And, and, and I think that that's the kind of attitude we should take for all of these things. Why should I believe you?
Is this really real now? We should cheer it, we should be excited about it. We should prepare for it.
I am all for the quantum resistant encryption initiative, for example, because if it's real, it's gonna change everything. But until it's real, it's not gonna change anything. And unfortunately, that's kinda where I'm at with quantum computing.
It's the, the quantum topic has been on sort of our topic list because in, in, uh, security we've been talking about quantum safe algorithms and things from quick encryption for some time not knowing is it gonna come in our lifetime? When's it gonna come? You know, things have changed significantly in the last three to four years.
And I think about what you were saying about, you know, the, the advances of technology being very unbalanced, you know, peaks and troughs, and when it's here, it moves fast type of thing. It's kind of reminiscent of William Gibson's quote of the future's already here. It's just very unevenly distributed right now.
It's just distributed into a few labs, right? That's where Quantum is. And, and I agree with you, uh, Steven, how many places are we gonna get to near absolute zero to run these machines, to be able to get that kind of performance that's not sitting on my desktop anytime soon.
Or even in, in the data center of a corporation. Not saying it's not common, it will, but I think it's, it's, we, we at least are getting an eye into the future of what it, what it possibly can do, what opportunities and threats might be with it. Again, it's got the whole geopolitical angle of, well, we don't want China to be the dominant quantum got a quantum gap, they can get too far ahead.
Yeah. It's sort of the nuclear arms race. Again, same race we're doing with ai.
So we're, we're in this because information is so easily accessible and announcements get made, you know, proselytized of, we've done this, and yes, it's under these narrow conditions under this, you know, particular set of test conditions. Okay? By the way, anything that is, uh, it involves, um, a new state of matter and multiple dimensions, I'm all for it.
So that's what sounds like a positive advancement to me. But anyway, it's, it's, it's, uh, it's here, but it's not very evenly distributed yet. And also, I'm sorry, I just wanna say about the interest level in it.
I was, um, last year I covered this very big tech conference in Miami, emerge Americas, and I'm likely gonna be covering it next week. And I was looking at the sections and I interviewed someone, uh, who as a quantum computing company out of, uh, new England last year, small company. And it was just one interview I did.
Well, looking at the site now, one of the largest sections that they're featuring this, this year is quantum computing just from one year's time. So the, the interest level is really skyrocket just from this anecdotal experience. But you, but you know, guys, look, I'm not ready to say there's a quantum gap, but what you've got, this is a replay of the Cold War, right?
We, I mean, back in the day, the Soviet Union in the US competed on everything, right? Uh, and, and now, so today it's China and the us but it, it's that same thing. And you know what, a little healthy competition's a good thing, it's a good thing.
But to your points, yes, there's always a, a lull a gap from when you first, you know, pure scientific research r and d and breakthroughs in technology to productizing these things. So I don't know if Microsoft's new states of manner and dimensions are gonna lead to a product anytime soon. But here's what I do know, pure r and d, when you pour money into r and d, you may not see the results immediately, but you do see results.
Because science, so much of what we do today is not easy, right? You've gotta, nuclear fusion is not easy. Quantum is not easy.
AI is not easy. We in this country are reaping the benefits for the AI research that we did in the fifties and the sixties and the seventies and the eighties. Sometimes it's that long until you'll see product from it.
And unfortunately, we are shutting down our research right now when we need it most. And you may not see the results of this in the next 2, 3, 4 years, but you will see the results of this in the next five to 10 years and 15 years when it may no longer be the China us it may be China and EU or China and other countries. Because without basic research, you don't move the ball forward unless you're just problem steal problem too, Too.
The problem with that too, Ellen, is when you wanna start a backup, it's not turn on the spigot. Nope. It's multiple years to spin back up to, I mean, it's maybe the level or Something off.
It's all these PhD students that are at our universities, and it's all the basic research that gets done at our universities, Right? You were talking about how long kind of show takes for things to really mature and appear in market from research. So pick autonomous driving.
I'm, I'm not autonomous cars. We, we talk, that's all we talked about for a while. You know, when Tesla was fairly new and everything is gonna be autonomous, we won't need any, anymore Uber or taxi drivers.
YYI, there is some autonomous driving happening in a few cases, but it's not co anywhere far stretched from commonplace yet. No, maybe that's gonna happen three, four years, maybe it's 10 years. I don't know.
It's gonna be a big trust level with that. But it takes a while for things to really be perfected enough to put it out into the wild when it is that impactful AI is that way, quantum's that way, et cetera. And that's, that's a great example because that shows, again, if you look at the history of technology, what you find is that technology affects us in unexpected ways, almost never in the way that you expect.
And, and if you look at the development of material science and the development of, you know, semiconductors and, and all these other things, it, it comes at us in an unexpected direction. And so we think, and, you know, to extrapolate it to now we think that we're gonna have big quantum chips that are gonna be like super CPUs that are gonna have a new kind of math, and they're gonna solve all these problems in a completely different way. And yet what's actually coming to market, maybe something entirely different, maybe it benefits us in a completely different way that we're not ready to see.
technology that amplifies the lights, the, the photonics that connect our computers together use quantum effects. And if it wasn't for basic research, we wouldn't have had those that are actually real technologies that are actually benefiting us. I, I would not put my money on any of the sci-fi predictions coming true for any technology, whether it's autonomous driving or flying cars, or quantum computers or, you know, superconductors.
But I would put my money on all of those technologies benefiting us in an unexpected way. Yeah. I'll take autonomous cars for 300, Alex.
Mm-hmm. You know, here's the story there. The leading autonomous driving work was being done at Carnegie Mellon University in Pittsburgh for many, many years now.
Uber went in, I think it was Uber and Google were in a bidding war and basically privatized that whole project, moved them out to outta Pittsburgh and out to the Valley or to California. And, you know, now all of a sudden it became a very commercial project, and quite frankly, the progress that was being made kind of stalled. And I think that's a perfect example where, when things are being done for basic research without a necess, without, without necessarily a product at the end of the line, but just research for research sake and then see what falls out of it.
To your point, Steven, right? As in terms of commercial applications, you're doing science for science sake, not, not science to make this particular product. I think it's much harder to do science for a particular project than to do science for science sake and see where comes from it.
And it's a lesson that we un unfortunately will probably learn the hard way here now with, with all the cuts and, and, and stuff going on here. But nevertheless, quantum is out of the bag, right? It's out there.
We're seeing it. Companies will, you know, Google's Willow and, and, uh, and Microsoft's chip and, you know, we're, we're seeing continued progress in, in, in Quantum. And I, I am bullish on it, bullish enough that I think next fall here at Textron, we're gonna do our first virtual event on Quantum lined up a few speakers already, and we're very excited by it.
Right now. The working title is Quantum Leap. Mm-hmm.
I, I don't know, Mitch. I I see, I see a promo between you and I here. That was a show in the nineties.
Isn't That the trademark? Well, that's what I gotta look at. Can we get away with this?
It's LEEP. We're spelling it different. Well, it's satire.
It's satire. It's true. Oh, satire is protected by the Constitution, I think maybe.
Um, but anyway, stay tuned for more we will be covering Quantum. And by the way, quantum will also be on the gestalt It Techstrong It, so you, you could check out the latest developments there. But let's take a break.
We're gonna take a little quantum break and we'll be back here on Techron Gang with AI and Margaritaville. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Welcome back to the Techstrong Gang. Well, for over 55 communities, there's lots of different modern conveniences that might be offered.
There's one community called Latitudes, margarita and Water Sound, that's in Panama City, Florida. And they're offering a lot of tech along with the amenities that you typically find and leaning into the Samsung Smart Technology. These smart homes don't just turn the lights on or change the temperature to make you more comfortable.
They do some efficiency items like leaning into solar energy, for example. But this is where it gets interesting. They're helping seniors and potentially people at risk for health issues with medication management, um, monitoring if they are doing their exercises that they should be doing, what happens if they fall?
Is there a video monitoring system that can quickly determine the person is, is injured and needs help? So the, this goes beyond what we would typically see in a smart home, really geared towards health and wellbeing and safety for seniors. But of course, it comes with some controversy because that's a lot of personal data that's, uh, that's being emitted through through the process.
Yeah. Anybody wanna jump in? Before I do, I'll jump in.
I Just want, I just wanna first note that this was in Florida, by the way. Of Course, course. Yeah.
Have To send 'em off. Of course. It's, yeah, I'll just leave it there, but, okay.
Sorry. Mm-hmm. Steven, go ahead.
So I, I was really interested in this story, so I, um, well, first off, I'm on the board of a, uh, company developing a special needs community with here in Ohio. And, um, one of the things that we've been discussing, you know, I'm the tech and security guy, surprise, uh, chairman, uh, is that, uh, this, this, this question of privacy. Because on the one hand, you know, people with special needs, whether they are the elderly or they have health concerns, or they are developmentally disabled in some way, or physically disabled in some way, many of them can have tremendous benefits from technology.
It is beautiful to see what can, what a, a, a person can do, for example, with a talker device that allows them to communicate with the world. It is beautiful to see what somebody with a physical disability can do with augmented, augmented, uh, technology, robotic technology with, um, AI technology, with, with recognition and, um, and speech. This is amazing stuff.
But at the same time, we are deeply concerned with our community as well as in a situation like this Mar Margaritaville community, deeply concerned about the privacy implications here because, you know, people with special needs and people who are aging, um, you know, they don't necessarily want everybody to know all the details of their health and, and their demands. And, and, you know, this is an easily exploited community. And so my first thought when I saw this was, whoa, whoa, whoa.
Do I want my, my parents, um, you know, senior assisted living center connected to the smart things cloud? If you Google it, you'll see that there have been hacks, there have been data leaks, there have been exposures with this smart things platform that Samsung acquired in 2014. I am not entirely mollified by the, that no data goes into the, because they're using smart things.
I don't understand how data doesn't go into the cloud in this situation. Um, and, and similarly, it's not all about like data in the cloud. In many cases it's exposure via the cloud, uh, via APIs.
So for example, you know, we're looking at things like cameras and motion sensors and, um, you know, face detection, video, all of those things. Yeah, they may be stored in the cloud as in the case with, you know, the popular, you know, ring and Nest and, and platforms like that. But they may not be ex, they, they may actually be local, but if they're exposed via API or via a, um, you know, some kind of a security exploit or something over the internet, then it kind of doesn't matter whether it's in Amazon's cloud or in, you know, your own private server sitting in Margaritaville in Florida, it's still exposed.
And so I'm a little nervous when I hear about a whole community that's gonna be deploying the same platform for all of these things. I don't want somebody hacking into my mom's, uh, wheelchair. Yeah.
So I, I, I get it, Steven. I, and I think those are valid concerns, but to me, this is, you know, you gotta do your pros and cons and, you know, for a lot of these people, a lot of these commun, you know, the, the, the over 55 crowd, I'm in the over 55 crowd, right? And, but I don't really consider myself fragile or anything yet.
But the fact of the matter is, Bonnie lives down here in Florida with me. She could tell you a lot of these over 55 communities are closer to over 75 communities, right? Or 90, or, you know, over 80 and, and so forth.
And again, a lot of these people don't have the resources to have home health aides constant, you know, uh, help supervision, helping, you know, not, not necessarily nursing care, but maybe some of them do have some slight memory issues, or they just need help with mobility, right? And, and it's such, the quality of life is such a huge part of their whatever years God gives them left. It's such an important part to have that quality of life.
And at the same time, speak to people that age. You know, the last thing they wanna be is a burden, a burden on their children, on their loved ones, on their grandchildren. They wanna be independent as best they can.
They don't want to be wards of the state or the family. And this program right here offers a real helping hand, a real helping hand. Now there's two aspects, and Steven, you hit 'em both.
One is, all right, they could collect your data so they're gonna know how many bowel movements you have a week and sell that to the Metamucil people. Well, honestly, anyone who talks to my parents would know that too. Well, That, and I was just gonna say, I don't think many seniors make that a, uh, is that a secret confidential data?
Yeah. Now you're saying an NDA and I can talk to that. Yeah.
But, you know, so, all right, so maybe someone could hack that kind of data. The, the scarier part, Steven, is what you mentioned, where they can hack your medical devices, right? We've seen this at black hats.
You can hack into a pacemaker. Can you imagine that? Terrible.
Imagine that, right? And, and so how do you safeguard against that? But I would rather see us safeguard against that than take this away from the people who, who this could make a, a huge quality of life improvement.
Because, you know, a life worth living is, is the kind of mantra here. And if this could help them with that, I, I'm all for it. And I'm not, I'm a security person.
I'm usually on the side of, of the security. But, you know, I, I've seen this firsthand down here. These people can really use this.
They can really, this is a, and at a time where people are worried about, I can't, I, I, I'm not gonna have a helper with me, right? Because that was a big, a big thing down here was immigrants doing home health aide, right? Helping older people, taking them to the supermarket, to the mall, right?
You didn't necessarily have to be a, a practical nurse or a registered nurse, but just helping an old person get to get out. Mm-hmm. I see that all the time There drive their car, right?
It's such, it's a huge, otherwise they're trapped in their apartment. It's huge. It, And it is amazing to see what these technologies can do for people.
Um, one of the big, um, things, I don't know if you guys have have seen this yet, but, um, there's, uh, basically teleservices mm-hmm. Where essentially you've got kind of an iPad like thing and, um, you know, you can basically call a person anytime for any reason. So it's not like my doctor, it's every morning when I get up, I can, I can call that person and just say like, what am I supposed to do?
Mm. Or I hear a beep. Yeah.
What's that beep? Yeah. And, and, and this person on the other end is a, is a real human who's there to try to help you.
That's great, BEC And you know, you mentioned things like autonomous driving that could be incredibly valuable to bring, um, freedom and mobility to these people. Yeah. Um, all sorts of sensors could be lifesaving.
Uh, all sorts of, you know, assistive devices, think technologies that we take for granted, like, you know, IOT lights and locks and things like that could be just a tremendous benefit to these people. What I'm trying to say is, I, I, I'm, I'm just also worried that we have to make sure that we're balancing the security and the privacy protection, a aspects of those, and that we're making sure that these people aren't dependent on companies or technologies that could just go away because they don't think that this is a productive or profitable market anymore. Don't Worry.
The federal government will ensure that for you, Steven. Yeah. Yep, yep.
Nothing is gonna happen to Social Security or Medicaid. No way. No.
How, You know, I think there's a, we've touched on the security part of it, which I agree with, with all of you on that. There are, there are other parts when you talk about putting things at the edge, 'cause you usually don't have that much compute power in these devices. Um, you might have some decent network bandwidth, but you may not.
But you also have to design things to say, well, what happens when the power goes out? What happens when, when the network is congested or maybe even not available, or they need to take this technology with them to the grocery store and in the, in the bus that, you know, picks it up on Thursdays to go shopping, whatever it might be. So there's a lot of thing, a lot of factors that go into things at the edge.
'cause they're very good at, at being sensors. They're very, they're, you can cost effectively build sensors, sensors into devices. It's hard to build AI and build a lot of processing at the edge, at least right now, cost-wise.
So, you know, I, I'm all, I'm all for in innovating and trying new ideas and see what can be of help. You have to worry about all the edge conditions when you talk about, so, But, but this is why this, this particular one in Florida in general, I think is a good proving ground because Mitch, the edge here could be the community, right? You could build a data center in the clubhouse, Have your own private why wireless network.
No, you, they do it. I mean, I, I know I, you know, you build a data center, a server closet in the clubhouse that serves the community and, and you are on the edge. But when I go to see literally my daughter, what I have done is build a data center in the clubhouse in my community.
Exactly that. There you Go. But even in that scenario, when you, you know, you hop on the plane or get in the car and go see your granddaughter in Milwaukee, how dependent upon those things are you, what can you take with you?
How does that work? Well, that, that's, yeah, that's another thing. I mean, So even though you can build infrastructure all around you, well, The answer there is tell your granddaughter to take the plane from Milwaukee down here.
The weather's better anyway. Um, anyway. Hey, we, we've gotta call Araf on this version of Textron Gang.
Before I do though, we got a lot, we got a busy week as usual. We, we have our, uh, uh, Textron TV show, you know, lineup immediately following the gang like we do every day on today's show. Bonnie, we have, uh, one of your videos.
Yeah, yeah. I did a video on the big tech leaning into nuclear energy. Um, I know you guys discussed it.
I took a a little bit more extended look at it. And that's on Tech Drunk tv. You know what, do check that out.
Go. You could go look at, uh, last week's, uh, gang, where we did discuss, you know, what's happening in the nuclear energy world. But do check out Bonnie's video on that.
Also, we have playing some of our Ichan interviews that I did last week in Orlando with some great stuff up there. And then I think, not today, but Wednesday and Thursday, Steven, right? We have, uh, a Tech Field Day.
Is it Networking Tech Field Day? Is that it? That's right.
Uh, yeah. Networking Tech Field Day, and actually to the point of the stories on this episode, uh, at nine on Thur, on Wednesday, uh, March 19th, we're gonna be live streaming a session with BT British Telecom. They're talking about the quantum, the impact of quantum technology on telecommunications.
And they're specifically gonna be diving into a lot of the questions that we discussed here today on the Gang. Uh, we're also gonna have some community sessions from, uh, Jason Gird and Scott, uh, Robbo, the Field Day delegates. Um, we're gonna have, uh, versa Networks, uh, talking about, uh, services at the edge.
And then on Thursday we're gonna welcome, uh, back Selector, which is a company that recently presented at, uh, cloud Field Day as well to talk about the way that they're using AI to manage, uh, networks, to improve network administration. com to learn a little more about that. Excellent.
Excellent. And we have, uh, we have Kon coming up in a couple of weeks too. Yes, we will be live in London at Cube Con Mitch, you'll be there with me, Mike Ard, hopefully.
Can I go in your suitcase? Sounds Exciting. Come over.
Come right along. You are more than welcome. You know, I'm Gonna hide in the, the, the, the, the landing gear of the plane That didn't work out so well for the, um, anyway, hey, this has been a great show.
We'll be back tomorrow, but do check out everything here we're talking about. We hope you enjoy today's text on gang. Have a great Tuesday, everyone.
Stay tuned for more text on tv. We're out. This is Techstrong tv.
Hey everyone. We're back here at Techstrong tv and we're at Suan in sunny Orlando. What a great couple days it's been.
We've met so many different people from suse, from their partners, from their customers, attendees. It's been a great time. I hope you've enjoyed some of these videos.
Let me introduce you next to Ben osha. Ben is with a company called Aussie Broadband, and Ossi Broadband was, is here as a SUSE customer partner. And they, uh, Ben was actually up on the keynote stage yesterday talking about some of the use cases they've been, uh, using, uh, or deploying with suse.
But let's first welcome Ben. Ben, welcome. It's great to have you here.
Thank you. Yeah, great to be here. Thanks for having me.
Thank You. So, Ben, before we jump in, you know, you were a rockstar on stage, but before we jump into that, give our audience a sense of, of who, you know, what you do and, and they may not know OIE Broadband. Yeah.
Um, and you know, about the company. Yeah, Sure. So, uh, for me, uh, Ben Oshe, I am general manager of transformation and Cloud platform, uh, at Aussie Broadband.
So, uh, my remit is looking after transformation of our technology function, so how we're starting to modernize our systems and our processes. Uh, and also I have cloud platforms, which involves, uh, we have a customer facing cloud, uh, and also our internal cloud and hosting platforms, which is where suse obviously comes into the equation. Sure, Sure.
Yeah. So let's talk about Ossie Broadband a little bit, though. You know, here in the US we hear Ossie brand broadband.
We think, oh, it's an ISP. It is an we're we're an ip. Yeah.
Yeah. But you guys also are in the data center business. Yeah.
And, and, and the cloud business. Uh, yep. So yeah, Aussie Broadband, um, you know, we primarily are a residential internet services provider.
Uh, so that's our, our bread and butter and the biggest contributor of revenue, uh, to the business. Um, you know, we are 21 years old now. Mm-hmm.
So, started out providing broadband services into regional, uh, places in Australia, um, where the bigger telcos like your Telstras and your offices, uh, didn't really want to touch because they didn't see the return on that investment. Uh, that was incredibly successful. Uh, and then with the launch of the National Broadband Network, uh, we built out connectivity into that infrastructure, uh, and, uh, are now a, a, a reseller of, of those services as Well.
Yeah. So we had incredibly great success, uh, on the back of our exceptional customer service and our exceptional network, uh, in the residential broadband space, uh, which sort of gave us the ability to enter new markets. And we acquired a company called Over the Wire, which, uh, gave us capability in the enterprise and government market.
Uh, it gave us a cloud capability, uh, private cloud capability, and it also gave us a tier one voice network. Uh, we grew from, I think, 500 employees to about 1200 employees overnight. Yeah.
Uh, and then more recently we acquired a company, another voice company called Symbio, uh, which gave us another tier one voice network, and it gave us an international presence. Uh, so what a Great story. Right.
But you, you know, you're operating private cloud out of data centers. Yes. Primarily in Australia.
Yeah. Do you over in, uh, uh, in New Zealand as well? Uh, Private cloud's mostly in Australia.
We've got a national, uh, private cloud that hosts, uh, enterprise and government type customers. Like a Sovereign Yeah. Yeah.
It's all just happens to be in Australian based cloud. Yeah. Yeah.
So, got it. Perfect. Yeah.
For, for, for government. Um, So, and I've been talking to a bunch of people here. It's an interesting time for cloud and data center space, right?
It, it's one of these convergence stories where, look, there are licensing changes coming, you know, from VMware that have people saying, Hey, maybe this is a time to go move to the cloud. Yeah. Right.
Rearchitect, my applications modernization. There's, there's ai, there's, uh, quantum's a little further off, but, you know, there's so many different kind of catalyst for change right now that a lot of organizations are saying, Hey, maybe now's the time that we make a change. Right?
Yeah. Been through the covid, uh, pandemic and, you know, we, we need to digitize. We did digitize, but we really need to finish that transformation.
And I'm wondering how much of that is driving what you guys are seeing? Yeah, I mean, we are going through that exact same, I guess, set of problems ourselves at the moment. You know, an organization that has grown as rapidly as we have.
We've got this, uh, you know, legacy of, of technology that we've acquired, right? Or we've, you know, built up, you know, in startup phase, we've done something to serve a particular need and we've done something else to serve a need. And we've got essentially an amount of, you know, technology debt that we need to, to now consolidate, right?
We've, it's grown us into a billion dollar company, but to set ourselves up for the next billion dollars of growth, we need to start thinking about, all right, well, how do we bring all of these disparate systems together? Uh, how do we, I guess, do that in a scalable, uh, efficient, cost-effective manner? And also, uh, you know, doing things at telco scale, uh, the hyperscaler becomes very, very quickly cost ineffective.
So what is the cloud hosting platform that we are gonna have that we host all of those workloads internally on? And that's again, where, you know, the, the, the cloud platform project that I've been talking about while I'm here, uh, and the CA solution comes into play. So, you know, building that, um, that national infrastructure for our internal use cases, providing hyperscaler like features and functionality for our internal customers, our software development teams, to consume, you know, in the same way that they would, you know, if they were building in AWS or Azure.
Uh, but in our data centers, uh, backed by certified validated solutions from suse, uh, and our other key partners, uh, that give us, I guess a sense of, um, security and com. With that, we, we able to meet our compliance obligations, uh, and deliver those services cost SI Think, yeah. It's about resting your head on the pillow I sleeping a little easier, right?
There's the stability Yeah. That, that comes with that. It's interesting.
It's almost like eating your own dog food kind of story, right? Yeah. 'cause what you're, what you're asking your customers to do, you're do it Yourself, your sell.
Yeah. Right? And, and that's an important kind of thing that people want to hear, right?
Don't, don't just sell me a solution. What, what are you doing? Yeah.
Well, we're doing the same thing. Amazon started AWS saying, Hey, if you want Amazon infrastructure Yeah. Use AWS.
Right? And, and that's where that came from. Yeah.
I Mean, there's a lot to be said for an approach like that. Like often, you know, you are your best reference customer. Absolutely.
If you, if it's good enough for you, you know, if Mikey likes it, everyone likes it, as they say on that commercial. Anyway. You were, you were up on the keynote stage yesterday.
Yeah. Most people watching this, unfortunately, were not here. Okay.
So give them a, a flavor of what you, you spoke about. Yeah. So, uh, again, we've touched on it a little bit already.
So just talking about obviously the digital transformation that we are going through, uh, internally. So, you know, we have a number of, um, different, uh, cloud hosting stacks. We have a number of different operational support stacks.
We have a number of different business support stacks and systems of record for things like customer, uh, and service. And those all come from the different companies that we've acquired, plus what we sort of had originally for ourselves. And, you know, we've got two paths that we can go down.
We can either continue to maintain these bespoke systems or, and, and integrate them and try and, you know, smash you know, the records from one to, to talk to the other together. Or we can sort of go, all right, now's the time to, you know, think about what does, uh, a single consolidated set of O-S-S-B-S-S, uh, and cloud hosting platforms, uh, look like. So those are, I guess the, the three prongs of our digital transformation strategies to build common core platforms across those, those three domains.
Yep. Now you guys partner with suse Yeah. Customer as well though.
And, um, you know, a lot of people out watching this, and I hope we've educated them over the last couple videos. It's more than just running their Linux. You want to do cloud native, you wanna do observability, cloud Native Security, you know, it, it is a, it's a platform.
Yeah. Right? Suse presents a platform, but it's, yet it's open.
Yeah. It's, I I think that's another big thing that companies like Aussi Broadband need to, are worried about, which is, I don't wanna be locked in. No, we don't.
And it's, it's, it's the balance. And we've, you know, been talking about this a fair bit, you know, over the last couple of days, uh, as we've been taking different meetings, you know, with Susa and, and other partners is, you know, what's the, what's the right amount of choice? You know, there are, you know, the incredibly, uh, closed, um, more commercial type, you know, you must do it this way.
And, you know, you get the feature when we say you get the feature, which is, you know, I mean, that's, that's good for some people, but it's, it's not, it's not, it's not where we are. It's not what we need. Uh, but there's also the, you know, the other end of the spectrum where, you know, you can go and piece together everything yourself, but I guess you then take on all of the, the risk around responsibility.
Yeah, Yeah. Maintaining it, you run the risk of, you know, um, perhaps one of the, the projects stalling and no longer becoming maintained. And then you've gotta work out how to, you know, make well the environment current.
Right? So It is one of the problems with open source, right? If you put two of your two your eggs in that basket, you better Nah.
Be sure you have some say, or at least you have some visibility. Yeah. It's one of the nice things about using like cloud native infrastructure from CNCF, you know, that you've got the Linux Foundation behind it.
That's right. They've got 200 projects and so forth. But you're right.
From a, a company like, you know, Aussie broadband, you, you've gotta kind of steer the middle there. You don't want to be Yeah. Far one way or the other.
That's Right. We wanna have, you know, an amount of choice and flexibility, but we also want, uh, an amount of someone going, Hey, I know these components work together, and I will guarantee you that they will continue to work together for a long time. And you can take that, you can go to the board and you can, you know, tick that off on your wrist register.
Uh, and it's like I Said, putting your head on that pillow. Yeah, That's right. And sleeping soundly.
Yeah. And, and, you know, at the end of the day, you know, we're, we're a telco, right? We are in the business of providing, you know, telco and ISP services to our customer.
Uh, we want our internal infrastructure to just hum. Right? So, Agreed.
Yeah. Agreed. Yeah.
Hey, Ben, I want to thank you for coming on here. For people who wanna find out more about Aussie broadband, maybe even some folks down under watching this. Yeah.
What's the website? com au. And, uh, I love it.
Yeah. Thank you so much, Ben. Thank you so much.
Thanks for having me. No, No. Shay Aussi broadband, Keith.
So a partner customer here at Scon. Hey, don't go anywhere. We've got a lot more videos that we've been doing here in Orlando, so stay tuned.
This is Textron tv. Hi everyone, it's Alan Shimmel for Textron TV back here at Scon. My next guest is someone actually I know a long time before suse even entered the picture.
He's my friend, Andreas Prince. I first met Andreas. Geez, it wasn't Amsterdam, it was before Amsterdam.
I Think it was Zia laps At Zia. Yeah. See, I the, no, it was Jenkins wrote in Nice.
Where we were sitting in the glass Box. What a trip that. Yes.
Nice. I had that goldfish gold. You remember.
I know, I know. And nice, nice. What a great place to do.
It was, oh, yeah. I brought my wife with me to that one. And we still talk about that trip.
We did Monte Carlo. I did con look, we're stuck here in Orlando. There's worse places to be than Orlando, but it's not nice.
Um, it's nice. Yes. Andreas, what, why don't we start, what's your current role at suse?
Yeah. So after the, uh, acquisition of Stack State eight months ago, uh, obviously we focused very much on integrating the companies. And I'm currently transitioned to a role in the suse Cloud Native business unit, if you like, really much focused on product marketing.
So we have great engineering, great products management, but the kind of the mission gap was product marketing. And that's important. Hey, if you have great products, how do you bring the value alive for your customer?
And then product marketing is what you need to do. So go to market strategies, a lot of enablement work, um, and a lot of marketing towards customers, prospects. Absolutely.
Yeah. And you mentioned Stack State. You were the CEO of Stack State before you were CEO, you ran product there as well, right?
Yeah, yeah. So long background in in products and engineering leadership roles. Yes.
Uh, in, in many startup and scale-ups. And then lately before becoming the CEOI run product for Stack State, and now known as Souse Observability. Excellent.
And to me, last night, well, we're gonna talk about what I saw at the, excuse me, in the solution showcase last night. You, you gave us a, a demo and a look called it sort of a peek into the near term future. And it was the first time that I saw, let's call it the whole picture of the Susa strategy.
And I was, I was with Mitchell Ashley, who, who you know, and I, I walked outta there and I said, Mitchell, I never realized Susa had the A to Z of this whole stack. Yeah. It, it, and I don't think a lot of our people out there know, you know, a a common thing, Andreas, that I hear from people, whether it's in cloud native or security, not so much technology in general take 'cause AI's changing everything.
But they all say, where's the innovation? I don't see any new innovation. I, you know, I learned a long time ago that 99% of what we do in tech is evolutionary.
Exactly. Exactly. Only 1% at best Yeah.
Is revolutionary. So if you wanna see it, innovation, sometimes you gotta do it in stop frames, you know what I mean? And look at it over the breadth of a year or two Yeah.
To see that innovation happening. I had a moment like that last night when, when you were showing me, uh, the diagrams and everything in there. Um, some may look at it and say, well, what's innovative about it?
Well, I don't, you know, what's innovative about it is it's, it's not making new parts, but it's combining it's Artists. Exactly. Yeah.
In a way that haven't been combined before. Yeah. Under one roof.
Yeah. One easy to use thing. They may think I'm crazy.
What is he talking about? Yeah. Jim's just rambling again.
Yeah. Explain to our audience what you showed me last night. Yeah.
So what we launched here at SUSE is what we call DevX validated designs. DevX referring to the developer experience. Because what we, uh, if you think about innovation or not, but platforms are a commodity, right?
Kubernetes established around for more than 10 years, CICD tools, very saturated market. Everyone applies it. Uh, s code practices, decorative nature, standardized practice.
So from a platform or technology perspective, well, what's the innovative that you can add there? But what is super important is if you think about large enterprises, you really want to focus on adding business value innovation. And what we thought about here at suse Cloud Native is really, okay, if we have this rich set of capabilities that support cluster management, that support private registry, that has a rich curated set of application containers, how can we level that up and really focus on helping out software developers get their application from commit to cloud, or actually from code to cloud, if you like, really in minutes.
And that's what we're launching with the DevX validated design. So what whatso developer experience and the validated designs is we really try to, so what I like here, just a step, the philosophy of SUSE is choice. And you could argue that's a positive thing.
And I'm, I'm warm heartedly agreeing there, right? Because a lot of open source is coming less open, uh, it's closing up. Uh, right?
There are hard connections required, but what the beauty is of choice, you can, you can pick the downside, you could argue is that the time to value might be a little longer. So we don't have a lot of, or had a lot of opinionated stacks, right? That say, Hey, if you use these tools in this way together, you can get from code to cloud to literally a minutes.
And that's what we've launched with our first validated design, a, a blueprint, a architecture that articulates how to use the various cloud native solutions we provide, but more important, a description on how to do that. And a installation script, if you like, to get to these tools very, very quickly. And that helps platform engineering teams more important businesses to not focus so much on the platform, but on the innovation that's happening on top of the platform.
I want to dive into pieces of this, but before I do, I'm afraid I'll forget for people who wanna see this ve diagrams of DevX that you showed me yesterday, where on the Susa, is it on the Susa website yet? Yeah, definitely. So it's, uh, it's published in our documentation open source community, right?
Open. So it's, it's out there in the open. We've launched our first, um, validated design, and we're really looking forward for partners to start contributing to that.
There's a code repository behind, uh, we'll share the link on, on blog post and, and socials pretty soon. Yeah. Excellent.
Alright. So you brought up these repositories. Our audience is familiar with repositories, whether we're talking about Artifactory or Maven or, or docker, uh, uh, container repository, et cetera.
You guys took a different take on repositories, because to me, repositories are like fishing in a sewer, you know, you don't want to eat the fish that you catch outta that water, but you guys are taking a different take on it. Yep. Explain what you're doing.
Yep. Yeah, so what we, uh, what we did about a year ago is we launched what we call suse application collection. And, um, that is a rich library of applications, single containers or helm yards that are fully curated.
And the curated part, or the nature effectively means we take an open source project, um, and we allow customers to use that in a safe, compliant way in the organization. And to do that, that needs to, a lot of stuff needs to happen. And what we do is actually we rebase them to souse Linux images, very small footprint images.
And that's powerful. Uh, because if you spread, let's say a Prometheus or a project 2,005,000 times, right? And the container is only half the size, well, you save a lot, uh, but smaller also means the smaller attack surface.
Um, right. So if we throw out libraries and other stuff, we don't need, right? It's, it's also less attack surface.
So that's, that's one part, rebase it. Then second of what we do is we make sure that it's, it has a software bill of materials. We know exactly what are the libraries in there, what is the version, as well as what is the license.
Because if you're just open source and imagine an enterprise with high co compliancy rules, pulling in a container with the wrong license type, you're liable. Um, and we, we put that all together in an sbo, a software bill of material. And that is important because then other solutions can actually query that and say, Hey, I don't wanna have a pet to the zero licenses.
Well, you can articulate a policy and it's then no longer possible to pull in that container. And then probably the last piece is all these containers, uh, images are continuously scanned for security, uh, important. So you know exactly, hey, how many vulnerabilities there're in, and if there's a new upstream version released that's being, uh, curated again, so our pipeline sometimes in minutes, most of the time under two hours, a new version available.
And then engineering teams, again, don't need to focus on continuously updating the base images. They will just pick what is in application collection and put their CICD, their build pipelines on top of that and use every time a kind of the latest test it and push that into the org. And, and this comes with using suse.
This isn't like end user organizations don't have to do this anymore. It's all sort of automated. Automated in there.
Yes. Yeah. Big time.
It's A beautiful thing, isn't it? Yeah. Yeah.
Absolutely. You mentioned a little bit about security. It's more than just scanning containers though, as part of this whole Dev x.
Talk a little bit about security and then let's talk about something you don't know a lot about observability. Yeah, that's still did. Difficult point.
Yeah. So if we more and more we start to realize that security is not, so we have a solution called SUSE security focused on container and network scanning. Um, but that's not only security.
We have solution application collection providing you great co compliancy type of elements. But what we really start to realize is many of our capabilities, they have portions of the security and the compliance puzzle. So think about your Airbus settings, right?
Where you say, Hey, I have a team and the team only has access to this namespace. Well, that's an element of compliance. If you then not only do that in your cluster management, but you propagate it into your observability solution, the team managing the app in the namespace only have access to see that data because there might be confidential data in the logs or in trace or whatever.
Um, so we start to realize that security is everywhere, right? In all the distinct capabilities. Um, and that is also in the devex validated designs.
You really start to benefit from the building blocks around security and compliance in that single flow. That way you can push from code to cloud, uh, all the way through. And then at the end, so suse application collection really, I would say contributes at the start of a process.
Hey, where an engineering team picks a particular container and starts to develop on that, whereas SUSE security does container scanning and network security at runtime really contributes at the end. So then imagine you detect something, right? The vulnerability or whatever that is.
Then again, kind of closing the loop, the DevOps principle, right? And you start over again. You pull a new version, you build it, you deploy it, you run it in production.
And by doing so, reducing it. So, I mean eight months. Uh, but the more, I mean, the more I start to understand that it's really the combination of all these capabilities that will help enterprises, uh, increase security, uh, measures.
So you're only here eight months. It seems longer. It feels longer.
Does Andre, it does. Um, you know what, you haven't mentioned ai though. Everybody's talking about ai.
What could we expect near term, little longer term maybe of, of incorporating some AI elements, maybe agentic type AI to make this even better. Yeah, yeah. Well, I'm definitely a big, Don't say anything that's gonna get us in trouble though.
Please. No, No, no. So one, I do think too, one element I wanna touch upon in particular is, uh, the observability aspects.
Oh, that's Right. Of, uh, of ai. And I feel most comfortable speaking about that.
So seus observability, um, as it is, is a platform for observing almost anything. Uh, we're very much focused on that the rancher can manage, Seus observability can observe, but we've learned in the last few months that it's actually a platform to do much more with. So we're launching also SUSE observability for ai, a very pre-packaged, um, integration, right?
An extension, I could argue of SUSE observability that is focused on AI workloads, giving insights on energy consumption, GPU, uh, workload distribution, and all these type of elements. And that is in particular important because right, it's massive from a footprint perspective. Um, and you really wanna observe that in a, in a very detailed way.
So that's what I love, right? That a platform is useful for more than just single technology being Kubernetes or different flavor. Absolutely.
But you, you, you hit on something there, Andrea, that I think is important for the audience, right? At the end of the day though, you don't operate data centers. Seuss is very much in the data center business.
Definitely. And the data center business is crazy. Right now.
Everybody's pledging hundreds of billions of dollars to build AI data centers. I don't know where we're going to get the energy to run all of these AI data centers or to cool them down or whatever. But the fact of the matter is, we need to be more efficient.
Yeah. Right? We need to be able to do more with less when it comes to data centers, data center space is at a premium, more so in the private data center than even in the public cloud.
Yeah. How's suse kinda working in that, or how you, I mean, it plays into your strengths. Yeah, Definitely.
So there, there are a couple ways of, of how we approach that. So many people take the cloud very much from a finops perspective, right? So they take it from a costing perspective, but down the line, it's not about cost, right?
It's actually about the utilization degree of your clusters in your namespace. And we do actually two things already in there. So through the application collection, you can get to a curated version of open cost, right?
So really assessing your entire landscape, what's running, where, what are the costs, et cetera. So that's a way more finops oriented, right? You would scale it down for financial reasons.
The other element I would articulate, I would say is probably even more interesting is that what we do with SUSE observability, so think about massive clusters that you're operating with very low, uh, utilization degrees, right? So over provisions, uh, elements with suse observability out of the box, we provide you straightaway insights, uh, on how that is at the cluster level, how that is at the namespace level, how that is at the surface level. So although we don't have automated actions to remediate, we do provide insights on, um, on CPU, on disc memory utilization.
And that is where it starts. And where suse observability takes a slightly different angle, we not only answer, say, Hey, this is how it's utilized. What we do is we demonstrate, you say, Hey, in this cluster, these are the business applications or the namespace that, that are operating, because scaling something down always has a business risk attached.
Uh, because yeah, there might be an app that needs to scale up every night, right? So you don't see that in the window of six hours, but before that six hours, it does that every time. Um, so we really try to let the business understand what it is you have running and how that's utilizing it so you can take conscious decisions to scale it down or to right, to shuffle workloads around, um, et cetera.
And we should, and that's applicable just on, on normal applications, but equally applicable to the AI space. Yeah. Andreas, you've got a great stage to play on here.
Good for you, man. I'm happy for you. So congratulations.
Keep up the great work. Definitely to You and all of the SUSE people, Andreas Prince here at Sussan. We're gonna take a break.
Hey, we've got more videos from Sussan coming at you, so stay tuned as Alan Shimel, we'll be back. Hello and welcome to the latest edition of the Textron AI video series. I'm your host, Mike Bazar.
Today we're with one mesh Karney, senior vice president for generative AI at Tradings, and we're talking about the rise of AI agents. They seem to be everywhere, all of a sudden, or soon will be. Esh, welcome to Shah.
Thank you. Glad to be here. We've been experimenting with generative AI for a while now, and people have been playing our prompts, and some people are better at it than others.
But how far does AI agents take us to another level? I mean, how automated will automated get? Yeah, it's a great question, Michael.
And you know what I see? It is not a brand new technology that came out of the blue, but really the evolution of how we have been working with AI for the last two, three decades, right? We had the statistical models that led to deep learning and machine learning, and then, you know, large language models with generative ai.
And really, agents are now the defacto means to actually consume all of these AI agents and work with all of the IT backend systems that we have today. So a lot of automation to come, and I believe this is the next wave, but we are fairly at the beginning of this next wave right now. Um, how many AI agents might there ultimately be in an enterprise?
'cause if there's an AI agent for every task, well, there are thousands of tasks. So does every one of them need an AI agent? Or eventually, will AI agents handle multiple tasks?
How do you think that might come together? Yeah, I, based on the agent TI implementations that we have done at treatments, and we are, uh, a very specialized data AI services provider. So we have been actually very, very focused on generative ai, doing some key agent TI implementations.
What we have seen is the best practice to think about AI agents is to not think of them as a task agent, right? Think of them as a, as a role agent. So you may have an agent for your software developer, right?
An agent that helps your quality assurance engineer or your data scientist, right? So that's for IT and engineering. But on the business side, you may have an agent role that manages your supply chain or looks at your inventory and logistics, right?
And these agents are actually going to work together, just like we form teams of, you know, people in our companies to actually perform functions. I see this evolving into teams of agents working together to actually perform tasks and really propel the human teams that are performing these tasks today. So many, many agents, but agents not mapping to tasks, but to roles in the organizations that you have today, How will those activities therefore be orchestrated across an end-to-end workflow?
Because, well, some outcome usually involves multiple applications, multiple processes. So how will I organize that in a way that creates the desired outcome? Yeah, fantastic question.
And I think that question is at the crux of why agents are so much more powerful than a lot of the technology that we have seen come out in the last 10 years, right? So agents have, they're not just large language models, right? They actually have reasoning capabilities.
A lot of that reasoning comes out of the language models or the prompts that we provide to the, to the models. But agents are able to think, Hey, what am I specialized at? What are my tasks?
What is the desired outcome? And when I say think it is still us prompting and, and setting up and configuring these agents, but now think of these agents then saying, okay, if I want to perform this task, how do I actually plan about doing the tasks? Large language models, just think of next word or the next token.
But agents think about long-term outputs. They think of the goals for them, and then they come back and say, okay, now I have a plan to get there in five steps, and I also need to work with this other agent, or I need to get input from the human expert in this case. And that's how they are much more powerful in actually making things happen.
Because yes, these agents will then very, very dynamically be able to collaborate with one another, get back to humans, or give feedback to humans, or collect feedback from humans, and then collectively process these tasks for automating a lot of common work. And I, I see this more as a productivity gain right now, the, the current play being, Hey, let me actually make the human expert, uh, 20, 30, 40, 50% faster by automating and taking care of a lot of the run of the mill things that you and I do on jobs today on, on a daily basis. Mm-hmm.
And of course, everybody's talking about, you know, whether their job will be impacted into what degree, and everybody has a certain sense of, uh, fear of somebody moving their cheese, as it were. But as I look at it, a lot of these tasks are things that maybe we don't like doing in the first place, and in the second place, we don't do them all so well anyway. Yeah.
Um, that is clearly the goal. I I do feel that today there is little bit of uncertainty and it's fair for people to be, you know, concerned. And I, I think there are some indications that some of the routine low-end tasks will be taken away by, by agents and will be done by agents.
But if you look at the history of technology, haven't we be be doing this all the while, right? There are cars that kind of do a large, large part of driving today, but has autonomous driving replaced the human who needs to go somewhere, right? Has, does the car decide where you go?
No. Right? So it's a human that still needs to take the agent, take system and say, what do I need to do with it today?
Right? How do I guide it the right way? So we, we, as, as, as experts in the industry or as leaders in organizations, we need to be very careful about how we message the rollouts of ai.
I think we need to start thinking human first. We need to start thinking of how AI can actually aid our companies move faster, how to set the right goals. And that those are all human tasks.
The, the ability to communicate, the ability to understand and perceive, right? The ability to make key decisions is still going to be a, a very much, uh, a human domain, a human endeavor in for a long time to come. So I'm not worried about the jobs, but if you are doing run of the mill regular tasks all day long, I think you should be worried.
And the way to get out of it is to really upskill yourself to really use the human wisdom, the human decision making powers that we are all kind of bond with, right? And can develop further. And then AI doesn't become a substitute for us.
AI actually becomes something of a tailwind for us to do what we want to do in a much, much faster way. Now, I've seen some early implementations, and one of the things that strikes me is sometimes there's too much of a good thing and there's too many of these agents popping up asking to handle a certain task. And, um, and as they wind up getting in the way, as much as they are helpful or they're trying to be helpful, so how do I kinda tamper down the enthusiasm of these AI agents?
'cause every time I'm doing something, one of them seems to pop up and say, can I help? Yeah. A little bit.
Yes. Uh, I, I, I actually feel that's a good problem to have, right? When any new technology blossoms, you are going to have a little bit of exuberance, right?
You're gonna have just a little bit of too much of enthusiasm all around too many products trying to do stuff, and they're not doing it exactly the way you want. And, you know, when mobile came up, it was similar. When cloud came up, it was similar.
When computers came out, it was similar. So it's fine, right? We are gonna come out of that phase.
It's, it's perfectly okay. What I feel is, is gonna happen is there will be, um, a lot of these trials, like the thousand flowers blossom or whatever, and then we are gonna see some ecosystems emerge, right? And that's happening with, like, for example, Google kind of really consolidating a lot of what they did with Gemini, with what, what they call now as agent space, right?
How do they actually build around manage agents, right? Microsoft has been doing a lot of interesting with copilots and auto gen and, and TIC frameworks, right? So there are these frameworks evolving, which will now also form ways of interacting with each other, right?
And then a lot of the complexity will go away. And yes, still that time you will have these agents power up. You just have to figure out what works for you and also keep a watch on where the industry is going.
So you're not left with some of the laggards, you're actually moving where there is the critical mass or development and, and further progress and, and traction, particularly on the market side. Um, these agents are based on those reasoning engines that we find in the LLMs. How smart are those reasoning engines getting?
And at what rate? Because, um, it seemed like initially at least some of the ones I saw had the roughly the reasoning capabilities of a five-year-old. But now they seem to be, I don't know, college students.
What, where are we on this adventure? Yes. I, I think most of the language models are, you know, late teenage kind of capabilities in my view.
But one way to think about them is a very, very smart teenager who has learned a few tricks, right? And still doesn't have the experience or the wisdom for how to apply, um, those skills, right? So that's where I said human orchestration is still, still very critical.
I'll give you a few examples, right? So kinda just ground it in some facts. We have, um, an a benchmark called SWE Bench that stands for Software engineering, SWE Software Engineering Benchmark.
And it, it has hundreds of really complex software engineering tasks that need to be performed. You can give these two software agent tick systems and agent tick system is fairly Reliably able to solve 50 to 60% of those tasks. Today, when we started, we were at 2%.
Now we are not, well, not of 50% already, right? The agent systems are able to collect information from all your database table structured data. They can merge the information from documents and unstructured data and make sense out of it, right?
I, I have obviously, you've probably heard of this PhD agent that's gonna charge B be, you know, coming out for $25,000 a year, right? So there will be agents which will cost tens of thousands of dollars and potentially have the ability in a narrow field, presumably to actually go fairly good deep and do deep research into areas. But I don't think we are at a PT level yet, although there are some benchmarks that say, oh, these language models themselves are able to solve fairly complicated math problems to going to the level of, let's say, an American math o mpi or, um, American Invitational Math.
But that, again, is a very, very specific narrow field in terms of the ability to do concrete work. Think of it as a bunch of interns that are available to you, if you can guide them, they're very committed. They work 24 7, they're diligent and they love to work.
So how can you guide them? That's the, that's the right mindset in, in my experience. Um, as we kind of move forward all of this, um, how will we insert these AI agents that are based on probabilistic outcomes or guesses, as they might say, and they get better over time, but the workflows tend to be deterministic, and they're supposed to be done the same way every time a hundred percent of the time.
And the AI agent's gonna do it maybe differently every other time. So how do I kind of reconcile those things? I'm laughing because we had exactly the opposite problem asked a few years back.
I was the head of AI and automation at a, at a public, uh, company that did customer engagement. And obviously customer engagement is where like agents, human agents in contact centers are talking to their customers, right? But the problem was those hardcoded workflows didn't work because humans cannot be bossed into standard workflows, right?
So when we build those software systems, humans would always go and ask a question that the system didn't know how to answer. So we actually wanted more flexibility. Now people are saying, Hey, is it too flexible?
And how can I, so there is a little bit of balance there, and we will go a little bit from guardrail to guardrail. There are ways for enterprise systems to be fairly become deterministic and reliable. For example, within language models, you can set temperature settings, you can do top grade, top K, top p.
There are different ways to kind of really lock down certain things. You can also actually build a lot of reliability in the way you build those agents. The way you define the prompts, you define the roles and the job descriptions of the agents.
You can instruct the agents to follow steps or to come back clean and say, I don't know. Right? But these are not, I believe, very, very different problems than fundamentally what we deal with with humans.
Sometimes we humans tend to not actively say, I don't know, right? We try to figure things out. And language models are similar, right?
So you can actually build those systems to avoid those problems of hallucination. We can do what's called grounding, which actually tracks you back to where does the data come from. Give me a concrete reference of where you pick this data point from, right?
So those approaches are where kind of professionals actually go. When we build these systems, we make sure that the systems are not hallucinating. That if they are hallucinating, there is detection and confidence scores that the user gets back, right?
Or the answer does not ever reach the human. So there are ways to, to mitigate the problem. And we are getting better every week in terms of how we can drive a much more reliable deterministic automation out of the systems.
But the bottom line still is that flexible workflows are better, especially when you're dealing with humans at the other end. Mm-hmm. Um, you mentioned hallucinations.
Do you think we have a new appreciation for data that despite 40 or 50 years of computing, we never really had, and now in the age of ai, we're starting to realize that, you know, the way we manage the data, describe the data store, the data matters. Yeah. Now, um, it is interesting that many of our projects, Michael, we we start obviously with, okay, here is the ROI and ROI is now proven, right?
It's not like, if it is, how can I do this right now? The question has moved to, okay, do I have the right data in terms of the, the quality? And by quality, I don't, I don't mean like, does ca stand for California or Canada?
Right? Those, those problems have been largely kind of solved. But I, I think the world has, world of data has excluded because we are now bringing in the, the 70% of untapped, unstructured data sources into the mix, right?
So the structured data with data warehouses, lake houses, is the, that world seems to be under control. There's still a lot of work of to be done with data engineering, but we have now added complexity with documents, images, videos, right? So more and more content is now available to extract business value out of.
And yes, that does create interesting challenges, interesting pre-work, where before you can start extracting value, you may have to do some data engineering work. The good thing is you don't have to wait for all your data to be in one place in your lakehouse or whatever to, to kind of get started. You can get started with a fairly small amount of structured and unstructured data, start rolling out your agent systems, and then add more and more data sources to get richer insights, recommendations, and actions over a period of time.
So it's a journey. It's not one and done. And you can start extracting business ROI from from day one, which which means in, in about a few weeks from, from the, from the time you start.
Mm-hmm. Um, so if we play this out to the nth degree, we keep talking about AI and agents as a technology problem, but how much of this is really almost a sociology cultural challenge as we go forward together? Yeah.
I am not sure I'm that expert to kind of really talk about the sociology angle of it, but let me give you my 2 cents. I, I do feel it is a fairly pervasive big issue that all of us really need to, to look at, right? And it does mean, just like Industrial Revolution did quite a few social changes, right?
In terms of the way we work, the way we interact, the way we actually go to work and do stuff every day, right? And that does require, um, a, a lot of adjustments from our side. And I see two bookends, right?
There are people who bury their head in the sand and say, I'm not gonna even allow Chad g PT in my organization, right? And then there is like, let's go and do, you know, like, let's open up all the, um, all, all the taps and just run multiple projects. I think there is a fine balance that particularly the CIOs, the cd, aos of the world have to kind of really reach in their organizations and they have to figure out how to roll out the AI solutions with governance, with data safety, with security.
And that's where I think professional help, like someone like NCE coming in or getting your people trained in the right technologies helps. On the other side of the coin, as individuals, especially, I was at a, a career fair last weekend volunteering, and a lot of like high schoolers, college kids came to me and said, how should I think about my careers? Because I'm thinking software engineering will not be as attractive, or should I be doing X or Y, right?
And I, I do feel we have to start thinking about some of the core skills that will survive, that will actually flourish and be in demand five, 10 years from now. Especially if you are early in your career, you have to pause, give it some thought, and not rush into what was hot four years back. We have to really think through the, the change is as a society come together and, and think through it.
All right? So shanan here, changes are coming as the song says. And who knows, they might be entirely new careers that no one ever thought of, but it's gotta be nice to figure out how to absorb all this stuff.
Hey, you mesh. Thanks for being on the show. Thank you.
It's my pleasure. And thank you all for watching the latest episode of the Techstrong AI video series. You can find this episode and others on our website.
We invite you to check them all out. Until then, we'll see you next time. Hey everyone, I'm Alan Shiel and this is Jonathan Singer, and you are watching The DevSecOps Show Cracking the Code.
You've never heard of that show. Well, for good reason, this is the very first episode of it. We're just starting it.
And thanks for joining in. Um, we're gonna take today's show to just kinda give you a what to expect and what's coming here and introduce a whole concept to you. Uh, DevSecOps Show Cracking the code is a joint production between us here at Techstrong Group, tech Strong tv, as well as check marks, our partners check marks.
We partnered with check marks for many, many years. They've been a leader in the AppSec space. DevSecOps coming now into platform engineering as well.
So I'm thrilled to have check marks co-producing this with us. And my co-host I mentioned his name is Jonathans, Jonathan's with check marks. Hey, Jonathan, nice to have you co-hosting with us.
Welcome. Um, thank you. You know, you are the new guy on the block.
Tell people a little bit about you. Sure. So, uh, it's nice to virtually get my face out in front of everyone, and thanks again for the warm welcome.
I am very much looking forward to doing this series with you. Uh, my background, I've been with check marks for a couple years now, and, uh, I've spent a lot of the last 20 plus years, sadly, but yeah, it's been, it's been a long time. You don't look at old, uh, well, uh, you know, I'll, I'll take it, I'll take it, but Good living.
Yeah. Where can I say good skincare? It's, it's great.
Mm-hmm. Uh, but I've been in cybersecurity and, and some adjacents work in telecom for the last 20 plus years. Uh, and mm-hmm.
I, uh, I'm current in my current role at Checkmarks. I'm doing a lot to help the organization shift our focus into the realm of developers. And we've done a lot of work, uh, as a company over the last four years, like really making our platform developer friendly, good for developer teams, good for huge like development organizations.
And so we wanna take an opportunity to sort of get the word out, uh, as a company. Um, and I am, I'm sort of leading that effort, so that's why I'm here. We've got a lot of fun topics to talk about.
I've been talking a lot recently about DevSecOps maturity and, uh, about what that really looks like and, and how you advance as an organization. So lots, lots to dig into. Absolutely.
I want to dig into some of those topics, kinda pre-announce them here today. I'd like to go into a little bit more about check marks in their history though. You know, like you, I've been in security, well, probably longer than you, to tell you the truth.
I've been in security now about 30 years, and, um, you know, I've seen a lot of water under that bridge, right? I've seen us move from a predominantly network security type of world where we put big boxes, you know, at the, at the drawbridge with the moat surrounding the castle to the advent of the cloud, to the advent of DevOps, ai now platform engineering, SRE, so many, you know, subsequent waves. And each wave has brought new innovation, new techniques, new best practices.
So over that time, I would say one of the biggest Innova, not innovations, but shifts in security was the shift to AppSec, right? Even before DevSecOps, the shift to AppSec, the idea of we are going to secure the applications, whether they're in the cloud or in a data center or on your phone. We need to make sure our application code is secure.
It's free of buffer overflows and cross site scripting and SQL errors and, you know, all of those kind, kind of common things. You know, obviously, uh, top 20 kind of, you know, uh, of, of, uh, vulnerabilities. And that's when I first became aware of check marks, right?
Check marks was a pioneer in AppSec, right? And we, you know, the idea of, of static code analysis, dynamic code analysis. Then of course, later on came, um, uh, open source scanning, and I always forget what we call it now.
Secure code analysis, SCA, right? Basically scanning our open source code. Um, all of these things really, I think they made a huge difference in the quality of the code that gets released.
And, you know, that's in our applications. At the same time, things like DevOps and agile man change the way we develop software. The biggest change is what, you know, I call the shift to a software factory, right?
Where it, it's not, I used to think of software as like, you know, like mid 18 or mid 18 hundreds Germans, craftsmen, fine craftsman making furniture or iron metal workers or, you know, the guild where you had apprentices and, and lifelong, like, you know, that real craftsman kind of role. But I think we saw a shift to the factory, right? Much like we did in automobile production, right?
From bespoke automobiles to assembly line. And we saw a, the same shift in software. Uh, we also saw the advent of repos and open source software where people, I, I, you know, it's like Frankenstein software people stitch together a whole bunch of different components right?
From different places, and that's 85% of the code in today's applications. Um, these are all big changes. And then of course, the biggest one for us here on this show is the whole start of dev SecOps, right?
All of a sudden it became cool to say, Hey, did you know, hey, developer, we know you want to develop quality code, even though we're not those old, you know, mid 1800 craftsmen anymore. We still have pride in our work. We still have pride in the code.
We're publishing. We want no one raises their hand and says, Hey, I feel like putting out some crappy code today. No, everybody likes good code.
And, and so that was a revelation for security people, Jonathan, right? We, we, we spent 20 years, we always said, no, no one cares about security but us, we're the only people. But no, they care about security.
Let's give them the tools to do it. And, and again, check Marks led the way there, I think, right? With, uh, well the most recent is the advent of check marks won that whole platform.
So that was a long-winded intro for you to discuss check Marks one and what that is. Well, uh, there were a lot of things in there that I'd love to address, but since you asked me go ahead directly about what check marks one is, I mean, uh, you know, I I think check marks one is our response to everything that you said. And yeah, like, I mean, we can go back to the Toyota production system and, uh, and, and, and, you know, KBO and, and how that's, you know, grown up and influenced agile development and, and the kind of march from DevOps to somewhat argue back to DevSecOps.
Um, and, and I'll say that I was, I was talking to someone recently and he said, you know, I spent years as a DevOps leader, and I always thought DevSecOps was just a marketing term by security vendors, because we always knew that DevOps had to, it was, it was supposed to be everything, and security was a part of it. Yeah. So, you know, as, as a guy who's out there now talking about DevSecOps, I think I'll, I'll at least, uh, say yeah, like we're, we're, we know.
But, uh, check marks one is still the response to this, right? It's the response to that need that, uh, maybe security folks felt like, uh, well, that's nice that you included it, but we're not talking about it enough. Enough.
Um, and you know, your reference to, you know, coders a and developers as originally kind of craftspeople, I, I think they still are. And I think that what all the open source stuff and the kind of Franken code that people put together is because we're trying to refactor people's time on doing the craftsman stuff, where it's really, really important. Uh, and we want security to still be a part of that, right?
So we want security to be a part of your software supply chain. So everything that you pull down from the internet, we wanna make sure that, you know, that code is secured when you build new code and you get time to do that. Craftsman, like work, we wanna be there.
Uh, you know, doing the analysis of that code before it gets into production and, and check marks. One is the response to those needs of taking all of these different types of analysis, right? Sas, SCA, das, API security, uh, container security, and, and building those engines, not separately, but so that they work together and that they can fit into your production pipelines, right?
Because if you're gonna do this effectively at scale, which is, which is really what large businesses need, they're trying to get all these developers, all these craftsmen who, you know, work on these little individual things to really, to make a big outsize impact. Um, we wanna fit into all of those production lines, integrate with everything that you need, and make sure that we're securing as much early as possible so that when things get to production, there are, you know, there are as few critical vulnerabilities as, as there need to be. So that's check marks one, is the response to that need for that to happen in the cloud for that, to make it easy for everyone.
Love, love it. So you opened this can of worms. Let's go back to the birth of Jeff SecOps.
com in, uh, when we first published it in March of 2014. We started in 2013, you know, planning and getting everything done like September, October, 2013. And, um, let's be clear back then.
So I came from the security world. I thought what a tremendous opportunity DevOps represents for security. There wasn't a thing called DevSecOps.
There was, there were proto like proto humans, you know, not Neanderthal, but Africas and some of the proto humans. There were things like Rugged DevOps. My friend James Wickett, who is now, uh, runtime or drive run Securities is new company.
Uh, he started something called the Rugged DevOps Movement, right? And it was, you know, ruggedized DevOps, making it resilient. org.
Maybe we'll have Shannon on a show going forward. I, a good friend of mine, um, and she actually wrote the Manifesto for DevSecOps, right? 10 years ago.
This May was the very first DevOps DevSecOps Connect that I did at the RSA conference in partnership with my friends at RSA. Um, and the idea then was when we first did this 10 years ago, again, ops, it was funny, the security people thought it was full of crap. John Jonathan, right?
'cause they said, oh, nonsense. No one cares about security. And the, and the developers thought it was full of crap too.
Just a marketing term. The true DevOps people like my friend John Willis and, and Patrick dubois, who coined the term DevOps and, you know, the, uh, Andrew Clay Schafer and, you know, the Damon Edwards, the, the, the founders of DevOps. They felt, of course, security was part of DevOps.
DevOps encompassed all of that. But what kind of needy, whiny individuals or security people that they feel it necessary to stick check right in the middle of the dev and the ops, and they resisted it, right? And when we first started doing these events, the RSAI, that was my mission, to bring the security community to the, and the DevOps tribe together.
It's kind of mixing peanut butter and chocolate. And there was a lot of resistance. Go ahead.
I, Yeah, and I mean, let's, let's be honest. 'cause we're, we're gonna talk, we're gonna have a whole conversation on culture later. But like, yep.
From my perspective, that what you just said, oh, well, everyone thought it was, everyone thought it was bs, like both sides. That's kind of, that's, that's kind of part of the problem, right? And that's why we needed to have it in there in the first place is because you can say DevOps always included security, okay?
But DevOps started in 2009. It is 2025. And there is still a massive culture clash between security organizations and development organizations.
I was talking to my friend who, uh, you know, she was recently a senior staff engineer at an Amazon based company. And, and, and now she's often a, um, uh, in a, in a startup again. Uh, you know, but, but they were saying like, you know, the security people want, it's so secure that like, well, we're just gonna unplug everything, right?
Right. And developers like, well, I still need to do my work. And that requires things to be turned off, right?
And, and if we're still there where we have this, this big culture clash, which is fine. And again, and I say this all the time, like, developers move fast and break things. Security people don't ever let anything break.
And if we can't start coming together as, as distinct disciplines and working towards the goals of the business, not just our own individual metrics of like, I've tracked this many vulnerability so that I can buy more of this software and secure this, right? And developers saying, well, I'm not meeting my development milestones, so I'm gonna skip this step and I'm gonna meet my development milestones. If, if we can't work together and have the business align us on goals of what producing secure software at a rapid pace looks like, then we still need to be talking about DevSecOps and talking about DevSecOps maturity and where you are.
'cause like that the, the cultures have to find a way to come together. Absolutely. We can't just have security being the department of No.
And we can't have developers being like, ah, they're all 20-year-old yahoos. And it's like, they're not like, these people have been doing this for 30 years. Like, come on.
So, absolutely. So let me, let me give, let me spread the good news today. Like it's Sunday and I'm selling Watchtower or something.
Um, the good news is we've made a tremendous amount of progress, Agreed. Over the 10 years I'm doing this thing at RSA, which we're doing again this year at RSA in May. Check Marks is a sponsor of it.
They'll be there, I think they're on one of the panels even, uh, at, uh, Toby, the chief product officer, uh, check marks is, is on one of the panels, um, co. But anyway, people recognize that DevSecOps is a real thing that you need. The second DevSecOps even more than that, when you look at the leading DevOps platforms in the world today, companies like GitLab and Jfr and Harness and CloudBees to name a few, they don't even call themselves DevOps platforms.
They call themselves DevSecOps platforms because they recognize how important security is. So we have made progress. I have a more nuanced view of it today than maybe you, Jonathan, or what you've said so far in that I think what we're seeing is under the maturation of DevSecOps, we've learned some lessons.
Developers are not against developing quality code, but they're never gonna be security professionals. A hundred percent agree. Yep.
And I think one of the mistakes that our DevSecOps industry has made is giving security tools to developers. We need to give developer tools to developers that help them do better security, right? Because they're never gonna truly understand the, the nuances of the CVSS rating system or something like, you know what I mean?
One of these kinds of things. Yeah. And that, so again, we talk about Check Mark Swan, bringing you back to that.
That's one of the beautiful things about that is, right, creating a, a platform that developers can use and feel comfortable in without having to be a security pro, but also having an aspect of it that the Security pro can use to get their job done as well. And again, these are things we're gonna explore. I wanna explore shift left.
Have we over shifted? I wanna explore how platform engineering has kind of come in on top here and said, Hey, let us work with security to set up the guardrails so that those developers can just go faster. We, we do do the platform engineering show, right?
Of which you, you've been odes on there and Check Mark's sponsor. We'll be discussing more of that on there. But we, you know, we'd be wrong if we didn't include it in, in here too.
Um, and I think, here's the other thing. This whole, uh, software pipeline security, right? Software supply chain security, that's part of DevSecOps too, right?
It's a huge part. The SBOs, everything else. And here's another thing I'm seeing, John, and I'm wondering if you see this too.
We're starting to see people say, Hey, we gotta expend extend DevSecOps past the deployment horizon, right up till now. DevSecOps, it was like it hit a black hole when we deployed, right? No light escaped to the other side.
Well, no, there's life after deployment, right? For apps, and there's security after deployment. And that has to be tied into your DevSecOps too.
So I, another thing that I'd like to see us discuss, what else would you like, think we're gonna cover, Sean? Well, um, let's see. We're gonna talk about culture.
We're gonna talk a lot about security education, because, you know, while you said that, so look, everything you said about making security tools into developer tools, I completely agree with you. I think I even said it at Techstrong Predict, uh, that, you know, that's, that's the goal. Um, but I wanna talk about security education.
I wanna talk about how it's working, uh, because it is, we just did a survey, 1500 developers, yeah, sure. Working or not. But at least the developers who are out there seem to feel like it's working.
And maybe security needs to change the way that it speaks to the market. And stop complaining that they don't teach security and secure coding in as part of, you know, a university degree and say, okay, well we're, we're, we're doing it. So let's start speaking differently to developers about security.
Right? I agree a hundred percent That that ties back to culture. So like, I think that the overarching conversation that we're gonna have across every single one of these meetings is the culture.
And it's gonna be like the culture around integrating properly, around metrics, around security education, around matching the velocity of security to the velocity of development. Um, you know, about security champions programs, all of these things that we're gonna wanna talk about throughout the course of this show. Uh, I, I think it's, it's all gonna tie back into culture and how we learn to continue working together and, and agreed, you know, security goes beyond deployment.
That's why check Marks one partners with, uh, with folks like Wiz and, and, and with Cystic right Runtime partners. So agree. Like we need to be looking at the whole software life lifecycle as developers look at the software lifecycle.
Agreed. Agreed. Hey, you know, what else though, for people watching this, are you a DevSecOps person?
Are you a DevOps person? Are you a developer? Are you a security?
Would you like to be involved? Perhaps be a guest? You have a point of view.
It's not just going to be you and I talking every week, Jonathan. We're gonna have hopefully a panel every week of at least 3, 4, 5 people. Not every week, every other week.
I think we do this. Um, but every show, and we're looking for people. So if you have some thoughts and opinions and everybody has an opinion on, uh, DevSecOps and DevOps, write to us.
com, or reach out on LinkedIn or wherever you can reach me. I'm pretty accessible. So you could reach out to us there and we'll, we'll entertain any and everyone who'd like to come on here and, you know, have a thought on, on what we're gonna say.
You know, what else, John? I'm really proud of us. We're on now.
Oh, a good 15 0, 25 minutes. We haven't mentioned ai. What about ai DevSecOps?
We'll, we'll talk about ai. And you met, you mentioned, uh, Patrick Debar earlier, but he and I had a, had a long conversation about AI that you can find somewhere online, probably on our website, uh, as well. Um, but yeah, you know, ai, uh, we're gonna talk about AI in a bunch of different ways, right?
'cause there are, there are lots of different ways of looking at, which is like, how does it help developers code faster? How does it help them do security faster? How does it help se security engineers to, you know, tune their products faster?
Um, and then what does it mean for the software supply chain? You, earlier you were talking about, uh, code and, um, and, and downloading other people's code and how that needs to be scanned. Well, but now there's hugging face and there are all these LLM models.
And you know, we've got a guy on at our company, ez, who's one of our lead researchers, and he's done a demo of like, here's how you poison an AI model, and here's what it looks like, right? Gimme a recipe for, you know, pasta Alfredo. And one of the ingredients that gives you is rat poison, right?
When he, when he does that right, poison this model. So there's, you know, if, if, if companies are building their own LLM or they're looking to build off of an open source, LLM, what's the security of that? Who's gonna scan that?
Who's gonna know whether or not your model is poised? So like, there's, and, and I don't mean to ramp up the fear factor 'cause that's obviously what security folks typically are, are known for doing, or at least accused of doing. But it's, it's a concern.
AI is now a supply chain concern in addition to all of the ways that it can be helpful. So we'll totally talk. And like everything else, it's the duality, right?
Light and darkness. Uh, it's always there, man. Every technology, you, you get it, it's new.
It does something cool, and there are risks, and that's just life. I always say this is why we can't have nice things on the internet. Um, but we do have nice things on the internet in spite of all.
And, and, and, you know, again, I I, I want take a positive view of this as a result of DevSecOps, our code today is much more secure, like the apps you're using today. And even though you may be updating them daily, weekly, monthly, whatever, they're much more secure today than they were before DevSecOps. I, I think we have made tremendous strides in, in releasing much more secure code.
Yeah. So, Agreed. That agreed?
Mm-hmm. All right. Hey, that's gonna wrap up our very first version here of the DevSecOps Show.
Cracking the code. We're gonna be back in two weeks with a full on panel. Jonathan, let's tackle culture right outta the bat and talk about the DevSecOps culture on that show.
Um, you can catch this show on Text Drunk TV and the Techstrong TV network. So it'll play on Tech Strunk tv. It'll be streamed to LinkedIn and Facebook and x and YouTube to our tech Drunk tv, YouTube channel.
tv website. com, security Boulevard, cloud native, now, tech Strong, AI Tech, Techstrong it, and digital CXL. Um, additionally, audio versions of this will be available on Apple Podcast, uh, uh, Spotify podcast, Stitcher, and all of your favorite podcast platforms.
So if you prefer listening to audio while you're running, exercising, whatever, driving, they'll be there for you too. Um, Jonathan, I'm, I'm pumped. I can't wait to get cooking with this.
Yeah, I'm, I'm excited too. I think it's gonna be a great series, and I appreciate you and the organization for hosting it. Looking forward to it.
Absolutely. Absolutely. All right, until next time, then that's a wrap on episode one of the DevSecOps.
So DevSecOps show, little tongue twisted there. DevSecOps Show cracking the code. We're out everyone.
Thanks very much. Thank you. Hey everyone, it's Alan Shimmel here from Techstrong Group, and you're watching another episode of the CD Pipeline.
The CD Pipeline is a, uh, partnership between the CD Foundation of the Lennox Foundation, and here us here at Techstrong. We're about, about once a month we try to bring you some of the latest topics regarding or germane to the CDF audience, to the CD Foundation. For those of you who're not familiar with the CD Foundation, we usually have someone here from the CD Foundation.
Um, but for those not familiar, the CD Foundation, as I mentioned, is a daughter foundation of the Linux Foundation, but it's responsible actually for the management upkeep running of several of the largest tools in the CD universe, CICD universe, including Jenkins, uh, Spinnaker, um, Tracy, one of yours, Orillia Orillia. Um, I think there's eight or nine different pro programs that fall under the auspices of the CDF, but it's more than just managing those, it's, it's working groups around the security of them, of operating them best practices. It is the community for CICD.
And so this show, CD Pipeline tries to capture that. Um, this week's show is challenges and wins in integrating security tooling into CICD workflows. Let me introduce you to our panel for today, and then we can jump right into the topic.
First of all, I think it's her first time on, and if I am mistaken, right, Kate, it is your first time. My First time. Very cool.
And I'm gonna try not to mess up her name, but I forget things for one second to the next, uh, Kate Scar, Uh, almost Scarcella Scar. If my eyes were better, I'd be able to read it up there, because my, they didn't put it on my prompt here for me like they're supposed to, but they try. All right, Kate, beyond Scarcella, what else can we learn, learn about you here today?
So I am a cybersecurity architect. Uh, I got my Master's of Science and Information Security and did my thesis on securing the electrical grid in North America. And I graduated way back in 2006.
And I tell people this because there was only four people in my graduating class. So nobody was really talking about cybersecurity, even though it was coming up in, um, in some products. You know, you had av, you had networking security, and dare I mention the start of Identity Nexus management, which was like, ah, but anyway, so that's my background, and I did it for very cool.
Yeah, so very, For long, that was the electrical grid without Texas. Very good. Mm-hmm.
So, um, I'm not gonna touch that one again, but I, I've been in security about 25 years, myself more now. And, and you're right. Back then it was, it was network security or endpoint secure host security as we called it.
And, uh, it certainly has changed over the years, though. It's become more important than ever, obviously. Are you still working in the security field today?
I am. I took a short sabbatical for about a year, and I'm just, uh, coming back out of that sabbatical, um, connected with Tracy, who has, um, who has, you know, full speed here this year. So, yes.
Um, Well, it's great to have you on here. Thank you. Thank you.
I'm, I'm very happy. Appreciate it. Looking forward to, to hearing more.
Um, next up we've got Ryan Ware, as in software. Brian, welcome to CD Pipeline. Tell us about yourself.
Hey, thanks, Alan. Uh, I'm really happy to be here my first time as well. Uh, uh, I, I appreciate Tracy dragging me, uh, uh, to come on here.
Um, so, uh, I've been doing security in one way or another for 27 years, uh, or so, uh, I'm a software developer by, by nature. But, uh, uh, you know, early in my career, uh, I first started at Intel doing, uh, implementing security features into digital rights management stacks. Uh, later I did offensive security research into, uh, Intel's products.
Uh, later I was more of a security architect and then, uh, worked in, uh, the realm of open source for quite some time, uh, on one. Uh, how do, uh, uh, product teams incorporate open source in a secure way, as well as how do you securely, uh, uh, make and contribute to open source externally? Uh, Intel has a, a, a a, a large presence in the open source community, uh, these days.
Uh, I work for Carrier, where I am Deputy Chief Product Security Officer, uh, focusing on security tooling, uh, CICD training, uh, secure Development practices, uh, and, uh, I'm also in the, the Open Source Security Foundation where I am the chair for the security tooling working group in that organization. Very cool. You mentioned Intel's commitment to open source.
I think it's very fashionable today to, to crap on Intel, right? They're not, they're not Nvidia, right? And you know, how the mighty have fall, but I, I think people have never given Intel enough credit for their commitment to open source, open source communities, open standards, and, you know, kudos to them for the work they do.
I know they work very closely with the Linux Foundation, C-N-C-F-O-S-S-F, you know, a lot of the, the foundation. So Absolutely shout out to them. They do, they do an amazing job with that, and still do even, uh, with all the troubles they're having right now.
com/intel. So, Absolutely. So shout out to them.
All right. Our last panel member today is our friend, Tracy Reagan. Tracy, of course, CEO of Deploy hub, uh, Aurelius, one of the products under the CD Foundation came out of Deploy Hub and, and their, their efforts.
Tracy's also, I mentioned she's a host on our Textron gang, and, you know, she works, she has a hand in a lot of different Linux Foundation, open source, uh, projects and, and boards, including OSSF, open Source Security, OSSF, and the, uh, ED Foundation among others. Tracy, great to have you on today. Well, thank you.
Yes, I am, um, a busy girl. I kind of have one foot in the security world and one foot in the DevOps world. I am on the board of the Technology Oversight Committee at the CD Foundation.
I've, uh, served in that role now for, uh, several years. And I'm also on the board of the open SSF. Um, so I'm keeping kind of my thumb, um, on the heartbeat of both sides.
And we re at the CDF, we recently started a, um, special interest group called CICD Cybersecurity, which, which Kate is the chairperson of. Uh, and it, the reason we, I felt we needed to start it was because there isn't a strong enough handshake between what the security side of the business is doing and what the dev, what the DevOps side of the business is doing. So it's time that we have that, uh, conversation.
It's a really critical one. Um, most DevOps engineers, you know, even just putting in, uh, the scanning of a SBO m is a major undertaking, and there's so much more to do. So it makes me a little nervous that we are so far behind the eight ball.
Uh, I wanna remind everybody that it takes us about a hundred days to respond to a vulnerability. It takes a attacker less than 10 days to exploit it. So we are, um, at a major disadvantage here, and there has to be a discussion on how to improve that time.
And so we're hoping that we can do that with this, uh, the c the new SIG at this, uh, CD foundation. So I'll use CDs out there, which I call you, please. CDs, I want you to join the, uh, the CICD cybersecurity sig and start, he helping us with really defining what that looks like in the pipeline.
And I hope we can have a deeper conversation around that, considering we have two security experts on the call today. I Absolutely. So, as I mentioned, I've been in security 25 plus years, right?
com was I felt that DevOps and the whole CICD pipeline model was a way to get like a second bite at the Apple for security. We could correct a lot of past wrongs by moving further left, shifting left into the development pipeline to fix security problems that by the, by the time we saw them pop up in production, they were a lot harder to fix. It would be much easier to fix them further left.
It sounded great, right? com devs, the whole rise of DevSecOps, as we call it, right? Uh, we made a lot of progress over those 10, 11, 12 years, but most recently there's been a pushback where have we shifted left too far?
And by that, have we put too much of the onus on security on the developer who's not a security person, right? And, but nevertheless, you know, we, we've made them the, the focal point for our security efforts and, you know, pre-deployment security where instead of, let's say, maybe building it holistically into the whole pipeline process right from left to right. And, and so, you know, there's been pushback.
Hey, instead of shift left, we should shift everywhere. We, we, we need to build security into testing. We need it built into the pipe, not onto the developer's shoulders.
Now, Kate, you've got your master's degree in, in all of these things, and, and you're, you're the head of the sig. What can we do to it? It can't just be, let's make the developer our security or make the dev our security person.
He's, he or she is not. What, what can we do? What are we doing?
What should we do, you think, in, in terms of integrating security into this workflow? Well, I think, and when you, um, go out, uh, to the specific page that, that we have, one of the areas, security is very complex, as you know. Um, cybersecurity is very complex, and it has becomes, the complexity in itself has, is also a vulnerability.
So we need to make things simple. So yes, are we putting too much on the developer and should we have it throughout the pipeline? Absolutely.
But we also need to have, um, bite size, you know, these, these, you know, Lunchable type of, of packages that we can say we're gonna do, you know, we're gonna secure in the, in the, you know, free deployment phase, and how, what does this look like? And I think this, the more simple that we have the tools, because as, you know, to introduce a new tool, um, is, is just a headache for our developers, and yet another tool, and another tool and another tool. And so I think we need to have, um, tools that are, and they're very expensive.
So tools that are, you know, open source that can be used, that can be used easily, and so that it doesn't take a master's degree to go out to try to figure out, well, how am I gonna secure this? I think that's, you know, something that we have talked about, um, with the sig. Um, and just, it's so important to keep it simple.
I mean, it, it sounds, you know, ridiculous, but we have made it so hard. We had made cybersecurity so difficult to consume and so expensive. I mean, think about the tools that we have developed.
I worked with IBM for over 20 years, and it's not just, you know, it wasn't just one tool. There wasn't just, you know, um, static, you know, analysis, coding, it became, I mean, you just, everything just grew and grew and grew, and we just would keep adding and adding. So I think we need to do more with less.
So, you know, the one tool can take on this pipeline from left and throughout. I don't know, Tracy and Ryan, what, what do you guys think? Well, I, you know, I, I preach simplicity all the time.
Um, part of the problem with the CD pipeline, if I just put my DevOps hat on and not my security side, um, the problem with that, the CD pipeline is, it's so brittle. Um, everything's based on, uh, a script. So we have to go update all those scripts.
And that is not an easy task, folks. It is really not easy to manually update so many thousands of scripts, thousands and thousands of workflows. Um, so it becomes a challenge because we don't wanna touch those workflows.
They break easily. So then maybe we have to have a security workflow that the, that our workflow calls. So, Kate, as you pointed out, we've made everything so complex.
Everything, not only just not security's complex, but so is our workflows. They're complex too. So we've dug ourselves in a bit of a hole, and we're behind the eight ball.
So how do we get out of it? Now, many people know from my discussions that I have been a big fan of CD events. Let's rebuild and redefine how this, the, the pipeline works.
But that e, even though IBM has done a great job, and that some of the team on that project has done a great job of defining what those events look like. And even, uh, Jenkins has an event, has a CD events plugin. We, I don't see, uh, the, what I like to call the giants, the Microsofts, and the, um, the, the intel, even though they've been doing a great job in some areas, I don't see them understanding why events are important, why it's important to reef, uh, to disrupt how we do pipelines.
So as long as we have this, uh, this difficulty updating pipelines, I think we'll have difficulty implementing tools. So what we have to be able to do is to find the low hanging fruit. Let's at least get started with getting a, a, a software bill of material generated and make that a, a common mantra that we can really expose to the DevOps pipeline and the DevOps engineers to say, this is one way we can get started.
At least let's start there. So, simplicity, I think, will be critical. Yeah, I, I agree with that, Tracy.
Um, I, I would like to go back, uh, uh, uh, to what Alan was saying for a minute though, and, and just push back slightly on the idea that developers need to be security experts. I, I don't, I don't think developers need to be security experts, but developers do need to be capable of writing quality code. If, if, if we don't think that there's an expectation on them too, to write quality code, uh, um, then I, I, I think there's something fundamentally broken in, in the system as, uh, they're the ones that are writing the code.
Uh, and security in a lot of ways is, uh, you know, the many, many security vulnerabilities are just engineering 1 0 1 quality issues, um, buffer, overflows, uh, uh, uh, null point or de references, things like that. Um, that said, I, I, I do, uh, uh, like what you were just saying, Tracy, uh, about events, I, I, I think one of the, the problems with how we have incorporated tooling into, uh, pipelines is, you know, it's all about, okay, how do we get this tool in here and get results out of it? And that's not the focus it should be on, it should be on what's the activity that the developer is doing right now, and what's the information that we can get from our tools that would be helpful for the developer to have during this activity?
A great example is pull requests with, uh, on gi. Uh, for example, uh, uh, you know, a lot of, a lot of organizations use, uh, uh, static application security testing tools, uh, traditionally called static code analysis. Um, which by the way, uh, there's open source tools that have been making great strides in this area.
GCC fourteens, uh, static analyzer, uh, functionality is, is way improved over previous versions. Um, that said, you know, the right time to be able to show a developer about flaws in their coal code using a SaaS tool is during poll request time. And, and ensuring that, that, you know, when a developer needs the information about the quality and security of their code, it's important for 'em to have it at the right time.
Uh, traditionally we've told developers, Hey, yeah, you have to go over to this of the place over here where, where, uh, the results for, for all the scans are stored. Developers hate doing that. They won't do it, and we're never gonna win by share doing it that way.
So let me weigh in here. I bet you if we did a survey of developers and said, how many of you want to develop low quality code? Not a lot of them are raising their heads.
Every software developer I've ever met just about has a tremendous amount of pride in, in what they do and the code they develop. You know, what used to be, before we got into the age of DevOps and pipelines in the software factory that we have today, software development was very much sort of like a, a guild, right? Ancient, uh, not ancient, but you know, like old German guilds where there was a lot of pride in craftsmanship and stuff like that.
When I was a security guy, I used to think, boy, those people don't give a hoot about security. And if they did, we'd be better off. But then when I, the more I got into DevOps, the more I learned that they do give a hoot about security and quality, right?
Because security is synonymous with quality, and they do give a hoot. And then early on in DevSecOps, a lot of security companies said, you give a who to bet security, Mr. And Mrs.
Developer, here's a tool to use, use our tool. Use our tool, use our tool. And you know what?
And that's where it went off the rails. You, they don't, they're not gonna use a security tool when you start telling a developer, Hey, wait a second, we wanna do a static analysis scan of your code. And that's not enough.
Hold on. I wanna do a dynamic scan analysis of your code. Wait, there's more.
I see you've been using a lot of that open source stuff. We're gonna do an SCA software composition analysis scan of your code, and whatever the, and I just bought this latest company's greatest new, you know, ICAS or whatever the heck they're calling the next one. And the developer, they just, Hey, can you just tell me if there's bugs in my coat so I could fix it?
That's all they wanna know A hundred percent. Right? And, and we've, I think we lose sight of that.
And, and in, in a perfect world, that's where, in along this pipeline, these things get done and it makes its way back there, right? And the code gets fixed. And look, here's the good news.
We live in a wild time right now with AI and automation and everything. A lot of these things could be fixed on the fly like that, right? I mean, you know, stuff we dreamed about Yeah.
In 2006, right? The, the ability to do automated remediation. I, I was selling vulnerability management in 2006, you know, no one wanted it, it, it took 90 to 120 days to remediate code that was code in production, not code in, in, in de development.
So, okay. Have we Gotten any better at that? It's still that, No, we, we have, because I'm gonna tell you, the problem I had back then is we were able to identify vulnerabilities and we built workflow into our product that pointed to the patch, and we had the ability, 'cause we also developed a NAC product network access control.
We had the ability to remediate on the fly. No one would let us, yeah, yes, no one would let us because they were afraid to patch without first testing to make sure that it didn't break something else. It might break your stuff, Right?
We can't, or rather be insecure than that broken stuff. I don't agree necessarily agree with that logic, but nevertheless, that was the prevailing logic. Have, have we changed?
Ryan? You've been around. We're trying.
Yeah, we're trying. But did that means we haven't changed? Is that what you're saying?
Yes. I, I would, I would say there, there are areas in the industry where, where it hasn't changed and change is hard. Uh, um, and to be honest, I I work in one of those industries right now.
Uh, um, one of the things that blew me away when I came to work for Carrier is the support life for some of our products. I, I mean, I, I used to work on automotive stuff where they're talking about support life of eight to 10 years. Uh, we have to support software stacks in our products for 25 to 30 years.
And, and because of that, the interesting legacy implications of some of the software we have, uh, uh, just are, are an interesting challenge for us in, in the new ecosystems in, and a lot of people are resistant to change because of that. Agreed. You're talking about critical infrastructure.
I mean, right, Brian? I mean, you know, You, you know about it. Kate, Windows XP baby, you know, good luck.
Um, you know, the one thing that I think would help us, and it's the antithesis of when we think about cybersecurity, but you know, the, the bad actors are doing this. And that is, you know, when we talk about open source, you know, they actually, the, the bad actors actually do it, right? They collaborate, right?
The reason they're able to get their stuff done so quickly is they have such huge collaboration tools, and they actually think they're doing it right. I mean, it's a, you know, crazy idea. But I think we need the, you know, the, the, the, those who are trying to make things better that we really need to, to be, you know, have open source, you know, for, so from, you know, coming from all these, you know, companies that were, you know, doing proprietary stuff, you know, I've been like this new open source, you know, let's collaborate.
Let's, I think it's gonna be one of the most important things because when we have this discussion about, you know, the pipeline and can it just be on, on, you know, the, the, the shoulders of, of the very beginning person, you know, when we talk about cybersecurity, one of the things that we would talk about is, is everybody's, you know, everybody has to know about cybersecurity. Everybody has to understand it from the user with their, you know, digital user interface with their, um, mobile phone, uh, which has become a human machine interface to so much to, um, you know, to, to the worker, because we are one in the same, right? You know, that the, the home user is also the one who's going into the office, who's also working with it.
You know, we all need to think about cybersecurity differently, um, in order to help things to become, I mean, it, it sounds, you know, somewhat esoteric, but we really, we need to, to do it. So it's not so scary, right? Because we sell based on people being scared.
And we need to, we need to really back up from that and think, what are we gonna do to make it better? I think, and, you know, to, to Tracy's point about, you know, low hanging fruit, boy, how much can we, I I, how much can we do with just getting the low hanging fruit? You know?
I mean that, I, I think I, I think it could be like a 70% type of thing. And, you know, maybe there's a crazy percentile, but, you know, long hanging fruit, I mean, that's a, it's a great idea. There's definitive whips there, absolutely.
But there's a whole bunch. If you could just, you know, just take those, you know, we've got a few minutes left. Let me bring up another kind of push pull that I think really affects us.
And that is, and this has been going on, bro, as long as I'm in security, which is what's my tolerance for security slowing things down? Yeah. Well, that's a good question.
That's, that's not a little question, You know, because that same survey where I asked the developers, do you like making low quality or, you know, crafting low quality clo uh, code, the next question is, you know, why don't you do security better? And it's always because the pressure is on, and I get paid based upon how many lines of code I publish, and I don't have enough time to write and test. We don't have enough time to write and test the code thoroughly because we have deadlines to meet.
And so when security becomes the people who say no, and puts the brake on going faster, we very quickly get kind of shoved out to the side, pushed to the back, you know, stay outta the way of this. You're, you're standing in the way of progress. Um, how do we, and, and again, this was one of the things about DevSecOps that I thought we would do better.
How do we overcome that perception and move at the speed of business? I like to say moving at the speed of DevOps, Right? Okay.
Moving at the speed of DevOps. So we have a weird, there's a, you know, there's a, the cultures between the DevOps people and the culture between the security people could not be more different. Um, if we think about v uh, a new vulnerability that's been found in production, the mindset of security is don't tell anybody.
Go through a, uh, event management process. Notify the people, only the people that should know. Because if we, uh, tell everybody and let the development team who's being impacted know that they may have, we may have some kind of internal attack to it.
So there is a hold this, you know, hold the cards close to the chest mentality inside the inside on the security side. It just is there. They don't, they lack the trust.
They want the control of managing it. This slows everything down. The, the, our, our culture there has, is, is just wrong.
Now remember, it may have started back in the, in 2000, Alan, when you were trying to solve the problem. And what they were doing is they were, you know, if a, a, a bug was found, uh, uh, if a hacker found a vulnerability that impacted Microsoft or IBM or the government, or Hewlett Packard or anybody else, they got, they were purchased. So we had a zero day market and nobody told anybody about them.
So that's where we began our story in security. Now, on the other side, we have DevOps engineers who have been preaching agile development and releasing fast for the last 10 years. And we have gotten really good at it.
And on top of that, we have Kubernetes, which means everything's decoupled. Everybody use, it builds their own container. So that one production vulnerability could be living in hundreds of containers across our endpoints.
So now we find ourselves having to fix some really big problems with a culture that doesn't want anybody to know about it. And another culture who says, you guys are way too slow. We need to continue pushing new innovation across the pipeline because that's what we're being told to do, and we're trying to build the best quality code we can.
And we're trying to manage DevOps pipeline so that they're getting code out as quickly as possible. Because that's what the business demands and security sitting there and saying, well, we don't want anybody to really know about this. Let us try to mitigate it and go through the process and only tell the teams that need to know that this problem happens.
It doesn't work. Those two cultures are, are conflicting. So somehow we have to create that handshake.
Is, is kind of what I began this conversation. Security has to be more willing to open up the door and let more people know about it. Security has to be willing to have those fixes pushed across.
And Alan, you were just way before your time. In our world, what we're trying to do, you know, w for Intelius and to play up, we or we, Ortel has the information right now to be able to push out a remediation. So we have discussions about discovery and how to remediate.
We wanna shift the focus to how does DevOps fix it? How can we use DevOps information to at least create, update a, a helm chart or a, a Docker file, and at least create a pull request for a high security vulnerability that's impacting certain teams and get it to them as quick as possible so they can make a decision if they want to move it forward, they can do the analysis and they can accept or reject that pull request. But to do that, we have to get the security teams to say, yeah, that would work.
That would be okay. But at the moment, they may not be saying that 'cause they're saying, no, we wanna manage that response ourselves, and it slows everything down and the world just keeps turning while security figures out what they need to do. I, I think that's beautiful.
Uh, you're right on. Yeah. I, I mean, we, we in the cybersecurity, um, Alan and Ryan, I mean, right?
I mean, we, it we need to change this mindset that we have, and I really do believe that we need to be more open about the vulnerabilities that we have, or we're not, we're not making it the way we were doing it. We know that. So it's about time that we switch things up and say, okay, let's try something different.
Yeah, I, I, I agree with, with what both Tracy and Kate were saying. Uh, I, I'd also just add to, uh, uh, taking a, a, a little bit of a, a, a, a perspective change. I, I think security folks a lot of times lose sight of what developers really need, uh, to, to do their jobs, right?
Uh, and, and do their jobs the way security folks think they should do their jobs. Uh, uh, uh, and, and a lot of the things that, that security professionals ask teams to do without thinking about it, uh, uh, dramatically slow development down. 5 times the build time.
And building the UX kernel is not a, a small event anyway. So you can't ask dev teams to, to wait for, for 2, 3, 4, 5 hours for results on tools until a pull request before they can go accepted. Uh, uh, you, you know, you, you have to figure out what's the right balance, uh, uh, to be able to, uh, uh, bring the bar up from where teams are doing it right now, to, to, uh, doing it in a way that, that they feel is acceptable use of, of their bandwidth and their time.
Agreed. Agreed. Hey, guys, we're, we're about outta time here, unfortunately, you know, we didn't mention the CDF.
You mentioned the, uh, STIG that you guys started. org, isn't it? Chay, the website for the CD f uh, CD do foundation, Excuse me, CD Foundation.
CD Foundation, yes. And the SIG is new. It just started in January.
And our first exercise is we're going through the, um, secure software development framework. We're looking at every single task that relates to the pipeline, and we're associating open source tools that can be used to, to accomplish the task. I love it.
Can you get to the sig off of CD Foundation page? Yes, we should be able to go to the, um, uh, community page and find it. All righty, Kate, congratulations on leading this Zig there and getting your hand into this open source security world.
It's going to, we, we can all use the help. So thank you for your, for your efforts there, Ryan, same to you, right? It sounds like you've been involved in this for a while now, whether it through Carrier or Intel, what have you.
And thank you for all you are doing. Thank you. I appreciate it all.
I just have one more, I just have one more thing before we sign off. I wanna shout out, shout out to Sasha, uh, Wharton, who is one of our, uh, top or like Ortel contributors, and he was recently nominated to the, uh, the CDF, uh, governing board as a open source representative. So we're super proud of him.
Congratulations to Sasha as well. Alrighty, that's it for CD pipelines. We'll be back next month with more, but until then, you can get all of your CD information at CD Foundation.
Until that is Alan Shimmel for Techstrong. Thanks everyone. Bye-bye.
Okay. Glenn Sullivan, senior director of products here at Infoblox, gonna talk to you about Universal Asset Insights now, and we're gonna jump right into it. What are the problems that we're, we're looking to solve here from a challenge perspective?
Right? So, asset insights is really, uh, network discovery, right? It's network discovery for on-prem, it's network discovery for cloud.
It is the way to reconcile what you've designed from an IPAM and DNS infrastructure standpoint to your as-built environment, right? You know, as network engineers, we have a picture that we like to draw and say, this is the way the network looks. Uh, asset insights is the way to figure out if it's the way that it actually looks.
So we know that managing networks is difficult, right? Especially if you're managing on-prem and cloud, especially in multi-cloud or multi-tenancy. Um, you have limited visibility as a network team for what has been allocated and used by the cloud team.
So depending on how siloed you are, this, this problem can get worse. Um, but in general, even in very integrated teams, we find all the time, the, the use, the primary use case of, Hey, I gave a slash 16 to the AWS team, they started carving it up into slash 20 fours for their VPCs. I have no idea how they're being used.
They come back to me two weeks later, they say, Hey, I've run out of ips. And I say, as a network engineer, I gave you 65,000 IP addresses. What did you do with them?
And they're like, we don't know, because they don't speak ip. They speak applications. So there's this primary disconnect with how networks are planned and managed and how networks are used in the cloud.
We see this back and forth all the time. So there's no centralized visibility for the network team on the allocations they make. And even in the cloud ops teams, there's no centralized place where they're seeing all of the ips across the board and how they're being managed across the different cloud environments.
So what is this? What happens, right? This can cause, uh, overlapping ips, right?
This can cause outages because maybe that VPC that was isolated last week now needs to talk on-prem. So either I've gotta come up with some, you know, fancy nat solution for translating the ips, or I have an eye conflict because I didn't realize that there was an overlap between, you know, on-prem and, uh, the cloud. The other problem is IP exhaustion, right?
So, you know, what can happen frequently is, is I'm either running out or I'm using too many, right? So the cloud team gets, uh, you know, a slash 16 or slash 24 and maybe there the, uh, the network team needs to reconcile some of those ips or reclaim some of those ips for other parts of the environment, right? So it's, it's not just overlaps, it's also wasting ips that you've been given.
So this for this fragmented deployment causes, you know, lots of concerns and lots of issues with trying to find, you know, what's deployed in the environment. And, uh, there's, there's not a lot of tools out there for seeing things that are visible across the board. So this is what we've done with Universal Asset Insights.
Uh, we've, we've had network discovery in our, in our products for a long time because we firmly believe that the way to reconcile as built environment with what's designed is to scan on a regular basis what's in the network and see, you know, how are the IPS being used or, or how, um, you know, how, how are the assets in your environment deployed, right? So we've had an on-prem solution for years, and we've also had a cloud solution that relied on servers. Well, obviously servers are, are an, an allergy to cloud ops teams deploying a server and an appliance, no matter if it's virtual or not, they don't want to do it.
They want you to pull the data that you can pull with APIs. So what we've done is we've said, okay, so anywhere where there has to be something deployed, because I have to speak network protocols, and these are kind of, you know, old school network discovery protocols, but these are the ways that you have to interface with a lot of networking gear. S-N-M-P-C-L-I, uh, you know, ICMP, all of the kind of old school protocols for getting, you know, data added network devices.
We call it interrogating network devices, which sounds terrible, but it's really what you're doing, right? Seeing an access point. Tell me about everything that's attached to you.
So we do that OnPrem through NSX, we deploy a server, it runs the discovery protocol and the discovery jobs, it pulls the data in. And the nice thing about the solution that we have now is the consolidation all happens in the cloud. So previous solutions, you would have to deploy a lot of probes and condensers and a lot of things on-prem to be able to reconcile all of the assets, right?
If I have a laptop that's seen on one access point in one building, and then later on in the day it's seen in another access point in another building somewhere, I have to consolidate that into a single asset. I typically would have to deploy a decent amount of, you know, either virtual or physical hardware or appliances on-prem to do that reconciliation. Now I have a very, very lightweight probing infrastructure and all the consolidation happens in the cloud.
The other thing that we take advantage from a cloud to cloud perspective is now, uh, any, all of the cloud, uh, discovery that happens from a AWS Azure and GCP standpoint all happens direct API to API. So there's no need to deploy a server or physical or virtual to do that. The other thing it allows me to do, and we're, we're actually, you can see it, it's in orange.
We're adding this now, uh, is the ability to speak with cloud controllers, right? So the last thing I want to do as a, you know, network engineer is deploy something to talk to a Meraki or talk to a mist, right? I have the cloud services for a reason.
I want to interface with those directly. So we're not gonna deploy, you know, a server on-prem to speak. SNMP to a Meraki controller.
Doesn't make any sense. We'll talk to the Meraki controller directly via the cloud cloud APIs. The last thing I want to touch on from an integration standpoint is third party, uh, agent integration, right?
So we, there's a tremendous amount of data in your environments that are inside of CrowdStrike or inside of ServiceNow or other third party, uh, you know, uh, solutions that run agents on top of laptops, right? So what we do is we actually pull the data from those third party environments and we integrate them and consolidate it into our asset information so that when you're looking at the, the, you know, the laptop here as it's scanned on-prem from whatever, you know, uh, network device it's talking to, we can enrich the data from, uh, what we're getting from, you know, CrowdStrike and or ServiceNow. Not to mention, because we're anchored in DNS and DHCP, we know a heck of a lot of this asset as it's in the environment because it's doing DNS queries.
We know those queries. We are the ones that gave in an IP address from a D HT P perspective. So, uh, there's a lot of data that we can pull, especially since we're anchoring in DDI as the primary source of information for all of, for everything to do with this asset.
And then you can see that we're, uh, consolidating all of this into, into a, into a work, uh, workspace here, which Jason will get into and show you a little bit about, but what's providing insights on the data, right? Primary use case is reconciling IPM and DNS, but there's some secondary use cases, uh, pulling insights into your asset inventory as well. I have a question, please.
In terms of what's an asset? Asset, is anything in your environment, um, that you're tracking as a, uh, it, it can have an IP or it cannot have an ip, but it's typically a, a workstation like this, an ELB, an NLB, um, an S3 bucket in, you know, in AWS. Uh, so it's anything that you're, uh, tracking at that level in your environment.
So it may have an ip, most of them have ips, but some of them do not. What about, say, containers running it on, uh, a node, would, would you consider each of those containers an asset or just the node an asset, or is that kind of up to you to Make that? The node right now is an asset.
We are looking at doing Kubernetes level insights to provide even more detail to you, but right now it would be at the node level or at the, at the pod level. Um, applications aren't assets yet. Uh, users will be assets soon.
When you say at the pod level, uh, you're saying that Infoblox can do that now, or That's on horizon? No, Kubernetes insights is on the horizon. It's on the horizon.
So we would see the instances or the VMs that that is running on, but we do not go into the Kubernetes layer yet. Okay, got it. So if you were to go into the Kubernetes layer, like let's say we were talking about pods, does that mean like, let's say you have a sidecar container running, right?
Mm-hmm. The containers both have the same IP address, just different ports. Mm-hmm.
Is, is it theoretical that you'd be able to go in and pull mm-hmm. The information from each of those containers? Yeah.
And, and this is where things get a little tricky, because if I was kind of not intelligent about it and I said, well, every IP in your environment goes into ipam, then we're gonna run into overlaps because, and what, as I talk to more and more cloud admins, they say, I don't actually care if you track who has what ips inside of the pod. What I actually want to know is the pod running out of ips. So that's the level of insight.
Like maybe we gave the, or maybe it has too many, right? Maybe the default size of that cluster is 20 a slash 24, and it's only got 30 ips, so they're wasting, you know, a couple hundred and maybe they should go in and adjust it to a 27. Those are the level of insights that most of the, uh, cluster admins that I talked to want.
Okay. So, uh, asset insights here, uh, you can, you can see from, uh, from this output, we're gonna get into some details on it a little more. It's pulling in all of the discovery information.
It's providing the insights and recommendations based on, based on the findings that we have, based on the data that we're pulling. It's not just a flat inventory, it's also some insightful information about that inventory. It's a single place to see, you know, hybrid and multi-cloud environments.
And for everything that you see, you can drill in and see all of the assets that fit that classification and all of the data that we're pulling, you know, from that provider, right? So it's important that we show you an insight, let you go into the insight, show you about it, and then show you even more details that are based on the source information, right? So we're pulling all of the information, uh, that would come from the cloud environment for that couple of use cases that I wanted to, uh, talk about from our customers, right?
From a customer standpoint perspective on asset insights. Um, the, the one that I comes up over and over and over again is m and a, right? So we had, in our early access program, we had a major media conglomerate company.
They buy companies all the time. They buy little media companies like on a quarterly basis. And the number one thing is they say is, we don't know what we're getting when we buy a company.
And, and sometimes you talk to 'em and they're like, Hey, we, we figure this out when they sign the contract. And sometimes they figure it out, the network team is the last team to know. And it's like, no, no, this is a done deal.
You've got three months to integrate their environment. And it's like, well, we don't even know what IPS overlap. We don't even know, you know, how many Azure accounts they have.
So we provide this visibility to them very early on in the process, and we can show them data in a matter of, you know, in a matter of minutes. Uh, a couple of, a couple of use cases real quick. We have a power, uh, company that's using us, a international power company, um, and they have over 7 million assets in the cloud.
And they didn't know that they had over 7 million assets in the cloud. So we were able to show them insights based 7 million assets. I also have an insurance conglomerate who has over 4 million assets in the cloud.
Um, and that was definitely a wide-eyed moment for these guys when they started putting in all of the, the different, uh, you know, credentials and, and connected all the, to all the clouds, and they saw they had over 4 million assets. A big surprise. Uh, so these are the kind of insights that we can provide.
And then we obviously can drill into the details about what those assets are, but sometimes just the number itself is surprising with that. This is the easier product to show you rather than talk about. So I'm gonna hand this over to, to Jason so that he gives, gets you guys up to speed.
And we would think it's always like, oh, you've got a class A private. So of course, we all choose the same first one, right? Everybody has a 10 slash eight, right?
Everybody has 10 slash eight. Okay? So I'm Jason, manager of Marketing at Infoblox.
And then this next demo, we're gonna look a bit at Asset Insights that Glen was talking about. Uh, so I'm starting off here, back on the, um, the, the IP space or address spaces page, right? Because kind of the, um, the backbone of asset insights is the discovery engine and actually getting all of these assets and all of this data into, into the system.
Uh, and we do that through different discovery jobs, right? So we configure discovery jobs for cloud providers for on-prem environments, uh, and for, you know, in the future Kubernetes and other things like Glen was talking about, right? And then we pull in, um, all of that basic data.
So for, for example, we'll just, uh, we'll jump into a, um, an Azure vnet here, right? So this is, this is an Azure vnet, um, not one that I created through our portal, but I, but this was existing in Azure. I set up that, uh, that asset insights job, and it pulls in this vnet.
So we can see it gets, you know, the base vnet container, uh, underneath that we're gonna see, see all the subnets, um, and then we get utilization on, on each one, right? And that's, uh, not the one I meant to go into, uh, inside of any of those individual subnets. We'll start picking up on any of the anything that that was discovered in it, right?
And so this gives us that single plane of glass or that kind of source of truth of IAM of, of knowing what's in our Azure environment. Um, my environment here, we've got, I've got a private endpoint, I've got a load balancer, I've got a vm. Um, but you can, you can imagine basically anything with an IP address, anything that's got a network interface in this Azure subnet, I'm gonna see it in here.
Even if it's just a network interface, somebody left behind and it's sitting there, it's still using up an IP address. So I need to get that into the system. So that's, that's kind of the basics.
And we could go and look through other ones, and we're gonna see the same for other clouds. But in, instead of doing that, um, what I'd like to look at is kind of some of the, some of the stuff we start to do once we have that data, right? Um, before I even get into the insights, I just want to show you a couple functions just on our, our IPAM page here.
I'm gonna turn on what we call flat view. And, and what Flat view does is it pulls it out of those unique IP pulls all our addressing out of those unique IP spaces and lets us work with the data set as a whole, right? So I have a, a, a ton of networks in my environment.
I PV six, IPV four. Um, and, and by, by turning on this flat view, I can actually look at those and, and work with them as a whole. So, first thing on this page that's, uh, that's really useful is just overlap, right?
So a very common thing to find, um, in, in networks is overlap thinking. Um, you know, we talk about cloud environments and we've got cloud teams kind of, kind of running wild and deploying their own stuff. Network team comes back and it's time to get that under control, get it back into the, you know, into the network.
We do a discovery like this, and we may run across overlap. So we provide some easy identification for that, uh, where I can just literally click on that yes, in any of these columns next to my networks, and it's gonna help me identify all of the other, uh, all of the other networks that this is overlapping with. Now, again, we talked, you know, some about like action versus versus data.
This is one of those things where there's not necessarily a one specific action I want to take. So I, I'm getting this data and this insight for the customer to be able to make that choice. Does, does this overlapping network need to be corrected?
Do I need to re IP this, you know, these networks or is this behind that? And so that's perfectly acceptable that I'm reusing this IP space, right? Uh, but either way, getting it, making it visible and getting an understanding of that is, uh, is a great thing.
Then we can do some, uh, some really cool filtering, right? So I really like this IPV four utilization. Um, and I can just take this neat little slider here, and let's say I landed on 77, so I wanna see all of my networks that are 77% utilized in ips, right?
I'm starting to run outta IP space. May need to think about either, um, expanding those networks or moving some devices off of them. Uh, so a quick, quick apply here, and I'm gonna wind up right with, with all of those networks, I can do the opposite too.
If I wanna see, say, my underutilized networks, networks where, um, like Glen was talking about with the Kubernetes, maybe we're, we've started, we're not using the IP space, or in my case, I've just handed off to my, um, to my cloud guys and they're under, you know, my, my cloud guy's asking me for another slash 16. I said, well, what did you do with that last slash 16? This is an easy way for me to come in here and see if he's actually utilizing that, right?
So I can do that zero to 25%, and here I'm gonna see all those networks that are potentially underutilized and allow me to, to work with those, um, make some decisions based on that. A lot of other, lot of other filters and stuff we can do here. But I'm gonna move to, uh, the workspaces that, that Glen mentioned as well.
And this is where, um, we go from taking that, that raw data and start, you know, running it through, through our system and providing some of those, uh, those actual insights, uh, on the information, right? Um, so things like, since, since our IAM and our, our asset insights is fully integrated with, uh, the DNS system, I can do things like identify, um, devices that have popped up on my network that don't have valid DNS records, right? Uh, my network's actually, uh, I got a, I got a problem with that.
I got a lot of devices on my network that have an ip, they're in my system, uh, but I don't, I don't know exactly what they are in DNS. Um, we can do things like here just a, you know, analyzing them by type. Uh, we can look at like idle or orphaned assets, right?
Think like, um, elastic IP address that's not attached to anything in AWS, it's just costing me a buck 50 every month and doing nothing, right? So we could see that, um, and get that information in here. I'm gonna jump though.
Yep, go ahead, please. Can you explain the terminology of some of those? I see zombie Sure.
Ghost. Sure. Yeah, yeah, absolutely.
Yep. So, so a a zombie scared like it is, it's supposed to, it's supposed to be terrifying, but that, Yes, that's what we call the network team people. There you go.
No, No. Um, so, so zombies overall are basically, um, they're resources that exist in my environment, but they're, they're not managed, not utilized in, in some way, um, not doing what, what we necessarily think they should be doing, right? Um, so, so take for example, we have the category categorizations under there of say, orphan or idle, right?
Um, so an idle could be that IP address I talked about. That's, that we would consider that a, a zombie asset because it's, it's out there, it exists, but it's not, it's not working for us, right? Um, it could also be something like a load balancer in, in Azure or AWS, we can even go into like idle here.
Um, and we would see like load balancers or things like that where we're not seeing any traffic passing through. So again, like here's a load balancer in Azure. Uh, we're, we're seeing no, you know, no traffic, nothing passing through it.
So it's, it's, you know, it's, it's there, it's not doing, it's not working for us, right? Mm-hmm. Um, and then we get down to, to some of those other, uh, types.
So a ghost asset is actually gonna have to do with, um, kind of the next screen. I'm gonna show you where we go into some, um, some of the other insights on DNS records. Um, and a ghost asset is gonna be an asset we, we actually think should be here, but it's not for whatever reason.
And I'll, and I'll, I'll tie that in in just a second. Um, yeah. So let me actually go right over there.
I'll go over to, to our, our network screen here. Um, so this, this monitor here is talking about those DNS record classifications, right? And we have a few different types.
So we have, um, abandoned and an abandoned ISS going to mean, um, like A-A-D-N-S record that that was pointed to something that, that used to exist in our inventory. Um, but, but doesn't anymore, right? So it could be like a public IP address, for example, right?
If I look in here, uh, one of the top ones I'll see here is a record for, here we go. We got a record for, uh, for a public IP address. However, I no longer see this public IP address in my asset inventory.
And so we think, okay, this, this is an abandoned record, right? Somebody else could potentially pick up that, that, um, that public address, use it. Now they've got a record with my system, right?
And we start getting into those, uh, those reputational things like we discussed earlier. Um, the other ones that we have here, uh, let's see, we'll go When you say abandoned, yes. And I, I I think of abandoned meaning that you're pinging it or you're checking it, that it's valid or something like that is being utilized or No, it's, it's more, it's more the tie into assets.
So, so in, in this case, it would be that like that that public IP that we looked at, uh, doesn't exist in my asset inventory. So I don't know whose public IP that is necessarily. What If it's a vendor or a provider that you're pointing towards that it Should be Yep.
There. And it's a possibility. And that's why we're, you know, we are, we are providing this, um, as an insight here, but, but there's not, you know, the action is, we have Suppression as well.
So if you, if you validate that this is valid, you can, you can suppress it and say, oh, this is, this is something that I expect to see. What about reserved or DR ones that you're, you're placing, whether they're not being utilized at this point in time, they will potentially be used if they do come up or need. Sure.
And I think we want to, we'd want to do the same thing, right? We want to, we'd want to suppress that, that record. Yeah.
These are, these are legitimate records. Are they suppressed for a period of time or completely suppressed and that I should be reevaluating them from periodic? Both.
Both options. Both. Can you like suppress by tagging or some, like some way that we can just basically identify it, say, yeah, these are Dr.
So let's, not Yet, but that's a great idea. Yeah. One question as well.
Do you, do you by chance present this in any way as a graph to the outside? 'cause you actually really have a really good mapping of what the application flow looks like. But I Know smile, Because, because the, because the answer is not yet, right?
And, uh, but, but yeah, that is definitely, um, something, something working on for the future, right? Is some graphical representation of these networks. 'cause you're right, we could really tie together how the, how are these networks connected in the clouds, all that different stuff, right?
Yeah, absolutely. Uh, so, so the last record type I will show you here. And I, I think that's a really good example.
And this is, um, this will go back to the answer the ghost asset question as well, right? Dang. Um, so there's dangling record type.
And so, so this is, this is again, some, some type of record that that basically points to nowhere. Um, and what I had here is, is I, I had an S3 bucket, I had it turned on, you know, I had it set up for static website hosting, right? Uh, so A AWS gives me a nice URL to use for that hosting, but I don't want to use that URL.
So I created a C name in one of my zones, uh, for that, for that, that S3 bucket. However, I've since deleted that S3 bucket. It's served its purpose, it's no longer needed, but forgot to clean up that record, right?
And so now I can see that here as that dangling record. So like Glen was saying, this is potentially dangerous because someone, someone else could now go out and create an S3 bucket, reusing this name since I'm no longer using it. And they've now got, uh, you know, got a clean record from my environment pointing into whatever, whatever they may be doing.
Probably not something good if they're trying to, uh, mask themselves as me. Uh, and so I wanna take care of that. And so we would also show this, this bucket as a ghost record in our asset insights, meaning, Hey, this was here before, we still have DNS records for it, uh, but this asset is no, is no longer here.
And that that's our ghost As well. Can you apply ops policies in here where you could say, I'm not allowed to create a resource unless it has a minimum of one tag, or like, is there a way to create behaviors of how to ensure that that's going on? It's a bit of an edge case, but you know, I just find people, I used to do this with lot of, like, if I see someone with no tag, you have 24 hours, I'm gonna delete this, whatever it is.
Yeah. And there nothing, um, nothing native built in for, you know, for, for like tagging policies. Um, so that would, you know, be something that you'd have to educate and enforce.
Um, and of course you can Actually, we could pull a view from the, the V and say like, find all nont tagged resources and we could at least see the, the view from the top inside info blocks, right? Glen just added it to the roadmap, right? There we go.
Good idea. Now that, see, see that one Fast to action, right? That's a great idea.
One more operational challenge, well, it may be rare. What do you do around collisions of changes? So if somebody goes into AWS Route 53, if somebody goes in, my fine, Fred Ned goes into Terraform and, and does some magic, and I go into Infoblox ni Os and I make a change.
So three changes are actively happening to the same resources within the five minute discovery window. What Happens? So there's, so there's, yeah, but, but there's also the ownership on the zone, right?
So yeah, there's also a concept of federation, which we are not gonna get into here. We, there's some, we have some blogs published on that. Um, we had to invent a protocol for creating consistency of ownership across I-A-M-D-N-S kind of has it built into the protocol, but IAM doesn't.
So we had to create something called IAM Federation and we have this thing called realms that basically says in the, here's the realm with all the participants, and then there's different owners of different zones, and the zone owner matters in the context of who writes last. So we have some material out there published on that. Yeah.
Nice. Great. Thanks.