Techstrong TV – March 24, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone, like the old Motown song where the IT Jobs Are. You're watching Textron Gang. Hey everyone.
Happy Monday. Alan Shimmel here from Tex Strong and we've, wow, what a weekend. I hope you guys had a great weekend.
I had a great weekend. Um, got to enjoy some of that South Florida weather a little bit. So, good movie.
We could talk about it, but you probably don't want to hear. Um, what you do wanna hear about is what we gotta talk about today. And I mentioned we're gonna talk about where are the IT jobs.
We talk a little bit SoftBank and open source LLMs in cybersecurity. Oh my. Um, let me introduce you to our gang on this fine Monday morning.
First of all, uh, he's the newest member of our gang, really. He's from, he's, he's genuinely from Austin, Texas. He's a good friend of ours.
He can tell you more about himself, but you know, some people call him R two R squared. Big Lebowski, though. He's not wearing his sweater today.
My friend Robert Reeves. Hey, Robert. How are you man?
It's good to see you. I'm doing well. Yeah, it's, uh, it's, it's getting a little warm for the sweater.
Um, and yeah, just super excited to be here. You know, I'm always passionate about developers, open source and, uh, creating jobs through startups. Uh, those are the three things that I care the most about.
Good for you, and I know that firsthand. Welcome. Moving on from Robert.
From Robert. I feel like I just introduced her, but that was probably that, uh, webinar round table we did yesterday, right? Or last week actually, my time goes.
She is the CEO of Deploy hub, open source defender extraordinaire, board foundation member on several, our friend Tracy Reagan. Hey, Tracy, it's great to have you on. You as well, Alan.
This is gonna be a fun one. We have Robert Here. Yes, he, he'll keep it moving.
And then finally move, moving up to, uh, upstate New York where he is still waiting for the Yankee season to start. He's our, uh, chief Content Officer, Mike Ard. Hey, Mike, just a few more days, Approximately 80 hours, but who's counting?
Yep. Yep. Who's counting?
Alright, guys, let's kick this. Fine. Monday off with, uh, recent article was over in Techstrong, ITSM about, uh, mixed signals on the, uh, tech role or tech job front.
You know, I have a lot of friends who for the first time in their lives, they're not finding easy picking, getting new jobs. I probably had three or four people write me last week alone if I knew of any, um, roles open. Good, good people too.
Mike. What, what's going on here? All right, well, let me set this up a little bit.
So, CompTIA, which is this industry association, does this regular analysis of statistics provided by the Department of Labor related to IT jobs. Now it's the Department of Labor, and we all know that, well, there could be some given those numbers, but they're showing that there's an uptick in jobs of about 177,000. Not all of them are in big tech, though.
And so, um, that came out. And same time, Washington Post has a article noting that those same statistics, which suggests that, uh, 25% of all programmer jobs have disappeared, but they made a distinction between programmers and developers. And programmers are people who code, and developers are people who actually create applications.
Robert, I know you've looked at all these stories, and I, and I know you've been close to this topic for a while, but what the heck's going on here? Well, I, um, thank you, Mike. I mean, look, the, you know, that Washington Post article about the distinction between programmers and developers, um, uh, you know, there was a little bit of click bait to that title, certainly saying that, Ooh, is this the first, uh, bit of evidence we have that AI is destroying, uh, computer programmer jobs?
Um, and yes, there was a dip. Um, but, uh, you know, one of the things that, uh, really jumped out at me in the article was that, I guess paragraph six or seven, it starts talking about the advance, the advancements prior to ai, um, around DevOps, cloud native, open source. You know, these are things that, you know, certainly, uh, uh, Tracy Allen and I are, are at fault for, um, because this increased, uh, productivity for everyone in, uh, software.
You know, I, I think that it is way too early to start doing the chicken. Little sky is falling stuff about ai. Uh, I'm reminded of the, um, you know, uh, uh, story in Willy Wonka, the new one, uh, not the original.
Um, about, uh, the, you know, Charlie's dad loses his job at the toothpaste factory because he was putting caps on tubes of toothpaste. Of course, you fast forward to the end, unfortunately, I'm doing a spoiler here, hope you've seen it. Where he gets a job, uh, repairing the machine that puts the cap on toothpaste.
Um, I do think that there is going to be a massive shift in how we build software, and we really don't know where this is going. The good news is, is that we've seen these massive shifts before, whether it was virtualized machines, containers, DevOps, uh, and now certainly with ai, um, we have an opportunity as an industry and also as individuals to improve our skillset. Um, but we are still, you know, our more technical minded folks, our programmers, uh, are still going to have a place to be.
It's just companies right now after a massive hiring boom, uh, during covid, uh, is just correcting right now. Um, and also with some economic uncertainty, macroeconomic challenges, companies are just tapping the brakes. Uh, I think that's all.
It's, I don't know, Alan jump in here for a minute, but I'll add one thing besides that. I mean, I just think a lot of folks are also getting better at copy and pasting stuff so that they're not actually typing. So, you know, let, let's, let's, let's peel this back.
The, the, the news here, and you see it running on your ticker, what does it actually mean? Well, it, employment grew by 177,000. That means jobs that have sort of an IT title could be programmer, cis admin help desk, whatever, a network administrator.
It could be anything related to it. And it, and it, and overwhelmingly it's probably it in every industry under the sun, from healthcare to finance and banking, to manufacturing, to newspapers and media and everything else. It's not necessarily tech sector jobs, but they're tech jobs, tech sector jobs.
So the tech community, the tech company companies, right? The kinds of companies that sponsor tech strong events, the kinds of companies that make the solutions. You out here watching this use, those companies had 11,000 and changed fewer jo new jobs hired in February.
So the tech center, the tech sector, the tech industry is hiring less people. Tech jobs are increasing. So that, that's the, that's the dichotomy here, right?
You like that word dichotomy? Um, now what does it mean though? Well, I'll tell you what it means.
And I think Robert and Mike, you're both somewhat correct, but let, really, what's going on here is the tech sector has been frozen by paralysis with analysis since almost the end of Covid. They did go on a drunken hiring spree during Covid, they way Overhired. And then since then, they've way over fired, right?
They've laid off, I forgot what the numbers are, but it's over a million, 2 million, whatever people. Um, and it's not that the e economy is bad, right? If you look at the eco economic sort of indicators, they've certainly gone down since a certain person got sworn in as president, but they're not terrible, terrible enough where we should see less jobs and stuff like this.
But what we are dealing with is uncertainty. And I said it before, I'll say it again. Businesses don't thrive in an uncertainty.
If you have an UNC economic climate, an uncertain political climate, an uncertain socioeconomic climate, people tend to freeze up. They tighten up. And that's what you're dealing with.
People are, people are not sure what to do. Tracy, you know, you read articles too, where people are now quite literally denigrating the employees in big tech, especially out in the valley. They're saying they got lazy, they've been pampered, they're not really good employees.
And, and that's why we're laying them off because they represent the bottom 10 or 15%. And yet, I think, you know, to Alan's point, it kind of smells like a cover up for over hiring in the first place. But I don't know, what do you think?
Yeah, they're out there playing golf. That's a reflection of somebody, right? But, you know, um, when I talk to my open source community, which gives me kind of a, you know, it allows me to keep my thumb on the sort of the pulse of what's happening out there.
People are struggling to find work right now. Um, and what I'm seeing is a pivot in skills. So they may have done less hiring, but there are job openings out there that they can't fill because they're asking for skills that have not developed yet, especially around ai.
They're looking for the, this, you know, perfect AI developer candidate, somebody who's had five years experience in LMS and is unrealistic, right? And I've seen those, I've seen those job openings, and it makes me scratch my head and say, where are they gonna find such a person? So while I know that the there is, we are going through a pivot in skills, and there are less jobs out there.
There will, we are gonna see more jobs opening up in these areas, but they're just gonna have different skill sets. And the other thing that I'm seeing and ad hearing is it's so much harder to find work now because of the way hiring is done. Um, AI bots, uh, you know, that try to match resumes, uh, there's a lot of bias in them.
Um, they, uh, aren't necessarily, the human has been removed, right? The human factor has been removed out of the job hiring process. So we have a whole new world of how to find jobs, whole new world.
Um, we, it was, it's, it was so prevalent in the community that the outreach community of the Orillia project has started a job seekers webinar program. The first thing we did is we had a, um, individual, uh, to come in and teach us all how to update and brand our ourselves in LinkedIn, because everybody's using LinkedIn profiles and developers, you know, they're not writers, they're not storytellers. So they struggle with, uh, with being able to brand themselves.
Our next webinar, we're gonna cover, you know, what companies look for. What are some of the tricks you can do on your resume to try to get a better match to the, uh, to the job opening, to beat the bots. It's kind of a beat the bots, uh, webinar.
So I think that there's two things happening. We're having a pivot and skills people with, uh, with, you know, maybe if you, we are writing in Rust. Rust is becoming popular now.
You've been doing Python, now they're gonna be looking for rust developers instead of Python developers. Uh, and, and there is a, there is a slow down, no doubt there's a slow down in hiring, but I think it's gonna be temporary even with the current administration as cybersecurity becomes more important. And the, the private sector has to address this, the public sector's not, uh, and I think that AI is going to create a whole new brand of, of developers.
So we just have to wait and we have to get scaled up in the meantime so that we are doing smaller little projects. The Ortel project, I'm, I'm really gonna, uh, pitch to them that we should start building an LLM even if we're not gonna use it, just so they have some experience in doing it. Um, so there's a, there's a, there's many things that we need to do as software developers or programmers, uh, to make ourselves more relevant.
And that's just what we're going through. I'm suspicious of one thing though. We, every Monday we publish, uh, a post called Five Great DevOps Jobs Opportunities, right?
And so I spend the weekend going through all those DevOps listings, and you know, on average there's like maybe 6,000 new listings every week related to a DevOps job. Now, some of those are duplicate 'cause somebody updated it or reposted it, but there are thousands of these openings. And what I have noticed though, is a lot of those openings are no longer in Northern California, but there's a lot more of 'em in other places, including Florida and Texas, and even New York.
And there's also a lot of job openings in places like Minnesota. And so maybe people actually have to go move somewhere that they're not in today because, well, that region is not hiring Well, I think that that's part of the problem, right? We've had a mass exodus out of San Francisco, it's too expensive to live there.
So now we have developers moving to different places. I mean, Santa Fe, I wouldn't have thought this would be a developer. I thought it was where rich people went to retire, to be quite honest.
And we have a, you know, it's, it's amazing the community that has come from California who has moved to Santa Fe, and many of them come from the tech business, and they're looking for re remote work no matter where it's at. So we, it's, we've gone through quite a shift. I really do believe that.
And I think it's gonna take some time to settle down. And you know what, the big tech companies have been holding onto cash for a very long time. Let's admit that.
Mm-hmm. Well, to your, they haven't done, they haven't done hiring To, to your point, just last week, I noticed there was a DevOps opening at Los Alamos National Labs. So there you go.
There You go. There you go. Well, I will, I will say this.
You know, whenever you have a shift in technology, um, you individuals can go and learn about that technology. Um, and certainly, uh, you know, Tracy, you know, having an LOM Intelius, I mean, I think that's great, just giving you the community an opportunity and seeing if it's gonna provide value to the open source project. That's awesome.
Um, but I, I do wanna caution people that are going to, um, seek to, um, look at where they are, kind of missing skills. Um, and I do think it's great to get familiar with maybe billing, uh, some kind of predictive AI model. I I'm working on one myself for sorting Lego bricks, uh, so that I can learn about this stuff.
But when we're seeking to increase our skills, you are going to get more return for your investment by maximizing the things that you are already good at, um, and seeking to be the best in that area. Uh, if you are going from zero to passable with a skill, okay, that's good, but it's going to be very hard to become an expert in that area. I think that you're gonna get more, you're gonna have a greater advantage by investing in areas that you're already an expert on and seeing how those skills can apply to things like ai.
Um, and, and, but remember in, uh, both of these articles, uh, we did see soft skills, being able to speak, uh, have conversations. Those sorts of things are gonna be very important, have always been important. And especially where there's more competition for jobs, uh, being able to have a personal connection with companies that you're connecting with, leveraging LinkedIn, uh, learning how to do that, uh, that is a skill set that is far easier to master than, say, building your own gen ai, uh, model.
Yeah. In fact, in that point, um, one of the employers we talked to before we started the series, uh, said that out of 800 people that they hired, only 10% of them came from, um, you know, somebody submitting a resume, kind of a cold, a hire. The rest were from networking.
90%. You've seen a Lot of that. And, and, and that's what people had.
I, I'll tell you, last week, as I mentioned earlier, I think I had four or five people reach out to me, friends, good people who said, Hey, one was been outta work since the first of the year. Uh, one, just recently, one's still employed, but looking to move along. Uh, but basically they're not, you know, they're not getting the calls from the recruiters like they used to.
And they're not just popping in with jobs. They're, you know, do you know anyone hiring in this? Especially, I will tell you and Dere, right?
Dere has been decimated Re's been hit hard decimated. Yeah, it has Decimated, yeah. Yeah.
But lemme just say one other thing. How many people have lost their job because of ai? Anybody?
I I, I have a hard time me thinking. Me too. I, I think people using Wait For real?
Or because somebody wrote that in a press release. 'cause there's a difference. Well, I, I meant for real.
Exactly right. How many people don't Know of any Job because of AI nonsense. In fact, the, uh, one of our, our kind of junior contributors, uh, he's been with us for three years, but he started, when he first started university, his first job was in ai.
So it created a job for him, right? Right. Outta school.
I don't know. You know what I noticed over the years too, it's like, you know, people are getting hired because they go to a conference and they'll sit around in a table and they meet a couple of folks, and, you know, that's how they network. And, you know, there always seemed to be like a lot of cross recruiting going on in any of these conferences.
Ira went to, including all the ones from the CNCF. And it seems to me, if you need a job, the place to go is any of those conferences in person is a good place to start. And, you know, the, in the universities in India, um, they really push their, their, uh, it, um, students to join an open source project because they tell 'em it's a good way to get project, uh, real life skills.
You've gotta work with the team, you're gonna network with, with companies. Some of these projects are led by the likes of Microsoft and IBM who have people in there. If you wanna network from India with a US company, the best way to do that is to join an open source project and start becoming known, right?
And I don't see that coming from, I, I we hardly ever see students coming from, um, us uh, universities. Never, ever. They never, there's, they're not there.
And we, we always have a, a, a steady stream of students coming out of India who wanna get involved. Hmm, Interesting stuff. Hey, we gotta take a break here on the gang.
Let's come back and we'll move over to our B block today, which is, uh, SoftBank scoops up, uh, uh, a company I hope that didn't come out of the reserve they set aside to invest here in AI data centers. You're watching Textron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back.
And yes, uh, there's a company called ampi Computing. 5 billion, maybe chunk change in the age of ai, I don't know. But, um, we don't know whether SoftBank, who acquired these folks, is doing that as to meet their commitment to the US or if it's part of some larger plan.
But Tracy, when I looked at it, the first thing that did pop into my mind was, holy crap, we want a contract with the US government now. We gotta actually do something about it. And so here's Ampire, but what's your take?
So we all know that, uh, you know, chips are a big deal right now. Um, and having more technology and more IP in the US around chip manufacturing is critical. We've talked about this before.
We, it can't be all centered in Taiwan. Um, I'm super excited about this story, though, not because of the chips. And the reason why I pushed to get this one is because this company was founded by Renee James, who I've been watching for a time.
5 billion. Can we like, have a dance or something? That's, You know, what, A day too late for International Women's Day.
But you know what? You're right. Oh my God, Tracy, that's Fanta, what a great story.
I wasn't aware of this at all. This, to me, this has, you know, made this story so important. It really did, because we have so many women founded companies who have, are who, who just women founded, who are turning into unicorns so few.
And this is a great story about how she did that. And she did it at a very important time. And yes, we do need chips that can, that are gonna be more sustainable and that can, um, be more, um, I guess you could say energy friendly.
So, yay, I am so happy about this story. And you know, Renee, James, thank you, thank you for leading the way and showing women how to do it. And that you don't have to be a young woman outta school who's on a pot, potentially a team, a team of, of founders that is still led by a male counterpart.
So to me, this is the big story, is that a woman took this business, uh, to this level in this, in the amount of time that she did. Uh, and I hope that she gets more attention around it. Great story, man.
I I will say, good for middle-aged people anyway, not, it's not just younger. Yes, Youngs out There, I know, but a middle aged woman, you know, last year vc, 1% of funding went to women in VC funding went to women 1%. 99% is going to men.
1% is ridiculous. It's ridiculous. But she proves that a woman is worth being, uh, investing in, right?
Well, I hope after this exit, you know, uh, she takes some of her winnings and starts a venture capital fund and corrects that. Um, you know, I, I can imagine a no better person to invest in startups and hardware than her, um, as an operator and as a founder. She knows what it takes to build and grow companies.
Um, and, and I hope that that's what happens next. I'm a little concerned that the cost of startups in the age of AI is gonna be prohibitively high. And so there might not be as many startups, because, you know, you're gonna see companies now require if, what $2 billion is the Annie just to get started.
I mean, how, You know, well, that that's, if they're looking to create their own, uh, their own LLM or, you know, models and, and and so forth training, uh, you know what, Mike, that's frankly an argument I heard when the web first came out, when the cloud first came out. And it's always that, that high, that high barrier to entry. And the high barrier to entry is I always either, you know, uh, advanced technology or advanced funding, one or the other, right?
But, but on the other hand, no VC wants to invest in a company that anyone can duplicate. So they do want high barriers to entry. But let me, let me mention something, and I'm not gonna get on my soapbox here, but unfortunately, at least here in our country, the idea of pointing out that this is a woman who did this is, is, is just not in style in some circles in this country.
And more than not in style, we're actually erasing women and other minorities from the history as contained on the web and maintained by this government. And that's a, that's a sin. That's a sin.
And, and it's a sin that our children are gonna pay the price, including the women out there and the minority people. I get that you don't wanna make it easier for just certain groups or whatever, but when you start erasing the history and don't call out the wins that people have, you, you are no better than, than than Hitler in 1932 in the Nazis. You don't do that.
You don't history. The winners don't get to write the history on the web. There is only one history, and it's wrong that we're doing that in this country.
And it, and it has to stop. And if it means having alternate alternate websites and everything else, where we call out the truth of women and minorities who have done great things in this country, we need to do that. And I'll leave it at that.
I wanna get Renee on Techstrong Women. Wouldn't that be awesome? I know.
It's like, how do I find her? I gotta, I'm gonna reach out to her on LinkedIn. I dunno if that's gonna work, but now she's got some time.
That was a cash offer. 5 billion cash offer. Well, but you don't know.
How much did she give up, right? I mean, Robert, you've been through this as a founder, right? 5.
I mean, I'm gonna imagine if she's a typical founder and she went through three rounds or four rounds, she probably owns 10%, 12%, if She's, oh, yeah, yeah, that's terrible. What is she gonna do with 650 million? I mean, poor thing.
Hey, it's not, it's not like the Wiz guys who by my reckoning, each walked away with about 8 billion. Hey, look, I, I really feel for them. Uh, they, they really, uh, uh, you know, how are they gonna survive?
Exactly. But, um, you know, look, it, it is the most important thing. Look, and Tracy will say this as well, uh, um, you know, you don't start companies to make money.
It's actually the worst way to make money is started companies, you start companies because you're passionate about it, uh, because, uh, you feel strongly about it. Uh, and, and speaking for myself, um, you know, it, it was, uh, uh, you know, uh, uh, b******e surfers at a, at a song, uh, where one of the lines was, um, you know, son, the funny thing about regret is it's better to regret something you have done than to regret something you haven't done. And for me, I really didn't want to look back and regret not starting that company.
It's never about the money. Yeah, the money's nice, but, uh, it's really about, uh, changing the world and having an impact. And I think she has had an amazing impact and has dramatically changed the world.
Um, you know, there, there is, um, you know, certainly, um, uh, just as A-A-C-E-O and a leader getting a company to this point and having an exit like this outstanding, and that is worth far more than the money. Fair enough. Let's see what she, where, where it goes from here.
All right, we're gonna take a break. We're coming back to our last block for this lovely Monday morning, uh, open source, LLMs and cybersecurity. I don't know, oxymoron, maybe you're watching.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Hey, folks, we're back. And we're talking about Trend Micro, which made a move to open source. Its LLM that had built on top of the meta LLM, and they trained this specifically for cybersecurity purposes.
And their argument is that, well, if everybody's gonna go bill an LLM for, uh, for a specific use case, we should just do one for cybersecurity that we can all share. And they're arguing. It's a deep seek moment for cybersecurity.
Alan, I know you've tracked this space for a long time, but what do you make of that anger? Can you say Me too? I mean, I, I, I just like, all right, good, good for you, Chen.
Michael. I, I think what they're really trying to get at though, is that they're throwing in first. They'd like to see other cyber companies throw in.
We'd like to see, maybe this is something like the Linux Foundation, OSSF should really be taking charge of, right? Which is a, a cross industry single LLM for all things cyber, because having it just be the, in this case, trend Micro, or in another case, you know, Palo Alto or, or whatever, having it by individual companies is just balkanization, right? And, you know, my, uh, my LL m's bigger than your LLM, but if we could do an LLM cross industry managed by some sort of foundation, will it help?
Maybe, maybe. I mean, you know, it, it, it's, it's going to do, you know, the old saying quality in is quality out and, and not quality in is not quality out. Um, some people use a different word for not quality.
But that being said, it, it, you know, there's so much details in there, and quite frankly, I, you know, good for trend for doing this. I applaud them. But this is really something that needs to be taken up by a more than a single vendor.
It, it really screams for an OSSF kind of involvement. Alright, Robert, do we need another foundation? Come on.
There's no shortage. Well, alright, ho, hold, hold, hold on, Alan, like, before you start congratulating Trend Micro, uh, let, let's kind of get into that press release, uh, that they put out about this. Um, first of all, this is not open source.
Uh, the data's not open. Um, we, it is free, but free is in beer. Uh, it is not free As in freedom.
Uh, people cannot take this and improve this. Um, you cannot look at how it was built and seek to, uh, change it for your uses. Uh, it's just free usage.
This is shareware. Um, the other thing is, is that look at the licensing a call out explicitly in the press release. You cannot use this, uh, if you're building a competitive offering to anything that Trend Micro offers.
Um, this, this is that the, the Llama license that Meta came out with. Um, and, and so it is not open source. Um, it is certainly free, uh, but if you really look at what it's doing, it's, they train this on trend micro, um, uh, data and, uh, things that they have offered.
Like, okay, look for this on, on, on this compute instance. Look for these things at the network. And so, um, it is Balkanized, uh, this is very specific to Trend Micro.
And, um, honestly, I think that this is a strategy to do two things. One, uh, certainly yes, we're doing it too, but second, this is, oh, it identified lots of issues. You need to fix it here, fix this with Trend micro products.
Now, I do applaud them with that for a go to go to market strategy, brilliant, big fan. But if we're gonna start saying it's open source, um, uh, b******t, it is not. Um, now certainly, you know, Alan, your, your point about a foundation and those sorts of things, um, right now, I don't think that there's an appetite for companies that would wanna fund this.
They want to, they wanna have their walled garden, they want it balkanized. And, uh, certainly as, uh, for-profit organizations, they're going to do that. I think the answer to this is for, uh, certainly Linux Foundation, other foundations to build their own, to do it out in the open, uh, to open source the data, to open source the model, uh, to give updates, and then have people be able to inspect this and show the world what a true open source L LLMs.
Amen. Amen, brother. I, I created all those points.
So, but, but, but here's the trace. Let me just jump in and Marble, let me jump in a second. I'm not gonna call it the hypocrisy of it, but let you worked at the Linux fan, and I'm not asking you to badmouth them or say anything outta school.
No, but the, and Trace you're involved in them, they're not gonna do this project without someone kicking in some money to fund it. Where's that money coming from? Hold, hold, hold on.
But remember, all open source projects start from a developer scratching an itch. Eric Raymond, uh, cathedral on the Bazaar. So somewhere, somewhere is a developer or group developers, uh, that is saying, Hey, I'm going to build this.
Now, remember, I, I mentioned, uh, earlier in my, my Lego sorter. Um, I certainly intend to open source that, uh, because I have got a huge stack of Legos that I need to sort. Um, and that is my itch.
Uh, at some point, a group of developers, now, whether they're backed by for-profit companies or they're doing this on their own, are gonna build this. And, and I think two of the biggest successes in open source, um, we could talk about that, that itch to scratch. Now, first, uh, lean, hey, I'm building, uh, a operating system for X 86.
Yeah. Uh, it's gotta be free, not full, you know, huge big deal. Uh, we've all read his first announcement, he just wanted to build it.
Uh, another example of that is Kubernetes, um, Google saying, Hey, we have built Borg, um, and we don't wanna be in the, uh, container orchestration business. We wanna be in the AdWords business and all their other lines of business. And so they open source that.
Um, and so do you Think they regret it? Um, I know, I mean, from GKS, they're making plenty of money off of that. And also the improvements that happened to Kubernetes that benefited Google Maps, Gmail, all this other stuff, uh, where they can make money off of that and not just selling Kubernetes, which they are with GKS, they're doing fine.
Uh, I don't think they regret it at all. I think that they think that it's a, a master stroke. And I think that the, uh, rest of the industry would agree, uh, very appreciative of, I think AWS is very happy with all the billions that they're making off EKS.
Um, but you know, at the end of the day, this, this, these, these itches to scratch can come from an individual just doing it for intellectual, uh, uh, exercise or from companies seeking to, uh, take, uh, you know, kind of non-differentiated, non-differentiated technology. And, uh, having the whole industry work on that. And then they can work on the higher order value add stuff.
Um, this will happen. I think that's the most, That's the most compelling thing about this conversation is that LLMs are rapidly becoming undifferentiated value. I mean, the difference between the one that trend micro puts together and four other companies put together is marginal.
So economically, it's time to just pile in together. Well, and, and that's the point I was making, Robert, I was not calling out Trend Micro for an attaboy, you know what I mean? I think this is a me too thing.
And yes, it's not truly open source, right? The, the LLM it, it's shareware. It's a free to use, it's free as in beer as you said, but it doesn't give you the, the ability to make it better to, to add on to, to modify.
But I think if, if, if Trend Micro's Heart is really in the right place here, the thing to do is put this LLM into a foundation and call on others to join in on it. Well, that's, why don't we just say, wait, let me, I, why don't we just say, okay, first of all, I wanna just, just a couple of points here that were made. Number one, there's both Alan and Robert are right to some level, um, open source projects, many of them, most of the big ones are now being driven and provided by big companies.
I seldom go go into any of the Linux Foundations meetings where somebody has changed jobs and now the SIG or the open source project has to go through some kind of rigamarole to, you know, get somebody else involved because they're being paid to work on these open source projects. Literally, Ortel is probably one of the only ones that we have just driven this product by pure sheer open source contributors. The, the problem with, um, trend Micro and this particular new release that they have, they're talking about is that it has no governance around it.
And I do believe that, that if you're going to consume open source, you better consume some open source that has proper open source governance around it. It has a board, it has a community, and that's not what Trend Micro is doing. So I agree with Ellen that it should be put into a proper open source, you know, foundation, whether it be Apache Eclipse or a new foundation that covers LLMs, right?
Which however it works. And then the other problem I have with this is it's deceiving to say that it's a cybersecurity LLM because cybersecurity has so many sides to it, and they're talking mainly about, you know, what they do because it's based on their data. So endpoint security, network security, they, they do a level of threat intelligence, but it's not related to, so the software supply chain, so to call it, you know, No, but it's cloud security.
It is cloud security, but there's cloud. But there, that's just one aspect of the cybersecurity world. Yeah, But it's a start is all I'm saying is, guys, it's a start.
It's not the, it's not meant to be the end, it's the beginning. It's a start, right? But it, it needs to have a better name because it can be deceiving to think that this thing's gonna solve all cybersecurity problems, right?
So I really feel like it should go into an open source community as well. Which one? I don't know.
But it should have proper governance around it, and it should, the, the, the licensing should be, uh, where you can actually use it and consume it and monetize it in a way that makes it, uh, makes open source what it is. Alright, well hopefully this is the end at the beginning and we'll see where we go from here. Right?
Well, speaking of the end, this is the end of this Text Drug Gang. I got the last one again. Yes, you did.
Tracy. Uh, hey everyone, just a reminder, you know, this is not the end of Text Drunk TV today though, because it's just the beginning, right? Text Drunk Gang Heads Off, always leads off our full day of coverage on Text Drunk tv.
So we still have probably two, three hours worth of great content for you to watch. Stay tuned if you're watching this on our Text Drunk TV Network. If you're just watching this on, on Demand on YouTube or Text Drunk TV or one of our websites, do head over to Text Drunk TV and, or log in every morning at nine 30 on Facebook or LinkedIn or, or YouTube or any of our sites.
And you could catch the whole stream, or you could go to Text Drunk TV and just click on the individual, uh, segments that you're interested in. Anyway, Robert, Tracy, Mike, thanks for joining today. Thank you for watching.
This is Alan Shimmel. This is another episode of Text Drunk Gang. We're outta here.
This is Textron tv. Hey everyone, welcome back to Textron tv. Our next guest is Adam Haney.
No, not that Mr. Haney, but, um, Adam Haney, head of Technology, invisible Technologies, um, that's pretty cool. Head of Technology and Invisible Technologies.
I didn't think about that before, but let's welcome Adam to the show. Hey, Adam, how are you, man? Welcome.
It's great to have you on. Thanks so much, Alan. I always appreciate a, a good Green Anchors reference, and so definitely the head of technology is a little bit different than the other Mr.
Haney, you might know. Yeah, I, I, I, uh, I'm gonna give you extra points to that. I don't know how many people out there caught the Green Acres reference the stores, but, um, anyway, welcome and thanks for having, having you on being on here with us.
Adam, before we jump into Invisible Technologies and what I want to talk about today, I always like to give our audience a sense of who they're talking to. Give us a sense of Adam Haney. Sure.
So I, I, uh, have worked in, in various different roles across startups, usually in the scale up phase of, of building platforms. And so, uh, I'd say at, at, at my root, I'm a tinkerer, and so I, uh, you know, have always continued to go examine different technologies and as well as things outside of technology. Uh, so I've been very mechanical since I was really small.
Um, but, uh, most recently before Invisible, uh, I worked at Meta where I, I focused on, uh, news and personalization problems there. Uh, and then prior to that I've built multiple different, uh, technology platforms for managing labor workplaces. And so that's been kind of my background overall.
Very cool. Excellent. Now, so that's not terribly different than me.
I'm also curiosity killed the cat kind of thing. Right. I'm always looking to poke into whatever's new and exciting.
And, and of course for, for people like you and I, Adam, that revolves around AI these days, right? It's, it's the new exciting thing. It's like a Absolutely, You know, the final frontier maybe, well, I don't know if it's the final frontier, but Quantum will be next, but we got time to play with Quantum.
Let's play with AI for now. Um, you mentioned, I mentioned that you were head of technology with Invisible Technologies. A lot of people out here probably don't know Invisible Technologies.
Adam, what would you tell them? Like, what's Invisible Technologies about? So Invisible is an AI process platform.
Uh, we help enterprises to be able to deploy AI at scale. Um, and, and we do that through various different mechanisms. So whether that's helping them to run evaluations so that they understand how well their models are performing, as well as helping to connect those AI models to their existing software tools in order to be able to actually solve problems with ai.
And we have a heritage of also working with several of the foundation model providers in order to help them build the data sets that ultimately were involved in creating Theis in the first place. So we have strong experience both in building AI models as well as helping people to be deployed them in a, an applied way. Excellent.
You know, obviously a lot of talk about AI in general over the last, well, two years certainly since, you know, GPT Jet GPT burst on the scene two and a half years, whatever it was. Um, but recently there's been a, an increased kind of focus on I, how do we train these models, right? What goes into training these models?
Should we all be using the giant LLMs that the, the hyperscalers are using, for instance, right? Should we be developing our own LLMs? Will we see the sort of an LLM marketplace, if you will, where, where you can buy specific LLMs?
Should we train them with data from the internet, or should we have synthetic data right? There? There was a little bit of irony there when OpenAI accused the, uh, deep seek folks of, of using their data for training deep seek.
Well, OpenAI used other people's data for training open ai, right? Um, but nevertheless, I mean, these are, if we're gonna move forward with ai, and, and it's something we talk about on Textron Gang and around here all the time, we've gotta get this stuff sort of a little bit more locked down, right? That we, we shouldn't be worried about.
Is there confidential data going in there? How is this thing trained, right? Uh, poisoning, hallucinations, all, all of the above.
How is invisible helping with this? How do you see that problem? You know, what, what's the way forward here, Adam?
Yeah, absolutely. So, I mean, we think a lot about evaluations as a, a, a way to think about safety as it relates to ai. And so normally when we work with a client, we come in and we try to understand what is the business problem, as you rightfully called out, what are the risks if this model hallucinates or if there's a problem, uh, with the way that the model tries to solve that business problem.
And then we'll usually start a program to build evaluations. And so, um, you're probably familiar with things like MMLU and several of the other sort of industry benchmarks for broad model performance. But what we find is that, you know, the problem that a particular business has isn't usually captured just by a single existing benchmark.
We need to help them to build a program around the problem that they're solving. So if we work with the hospital system and we want them to be able to parse, you know, specific kinds of medical data, there are different forms of evaluation. Some of those can be automated.
So you can use LLMs to think about building, uh, you know, an evaluation program. But at the end of the day, especially for really critical problems that involve safety or, or business critical decisions, you want a human in the loop to then be able to make sure that we have, you know, a domain expert that really deeply understands this problem space to be able to say, yes, this ai, you know, answered correctly or did it. And so we think a lot about the, the same way that you would think about automated QA for deploying, you know, new pieces of software.
It's necessary to have an, a robust and effective EV evaluations program to deeply understand is the model, or, or is this overall applied AI system that I've built solving the problem, you know, in the way that I expect, uh, for, you know, any kind of, you know, business use, uh, of an AI model. Excellent. So there's, I wanna hone in, uh, specifically on using sort of synthetic data versus, I call it real data.
Other people call it human data. Look, I it's a little bit wild, wild west right now. I get it.
Yeah. But when we get civilized that of what do you think the right path here is? Yeah, I don't think that there's a, a one size fits all answer in either direction.
So certainly, you know, when you think about problems around PII or, or, um, you know, privacy in general, there are places for synthetic data. So that allows you to generate a data set, you know, from something that might be confidential or unsafe as, as well as it allows you to really increase the data volume that you have from a, from a smaller data set. Um, however, you know, synthetic data, the, the process overall involves training a model on, you know, a smaller, uh, data set and then generating, you know, either a representative data set or a new larger data set.
Well, that process amplifies the biases of the dataset that you start with. And so there's not a future that I see where we're able to purely move over to synthetic data sets. I don't think we've generated all of the data that we're gonna generate, you know, across all of society.
And so you sort of think about the process, there's gonna be some amount of model drift, or the, the underlying data distribution is not always gonna be representative of new things that happen in the world. And so we believe that there's a place for humans in terms of generating new data sets, uh, as well as, you know, if there is any problem in that underlying dataset, creating a a synthetic data set is only gonna amplify that problem. And so that's once again, a place where we see a need to make sure that any training program, evaluation program, fine tuning program, uh, has a strong need for human data, uh, as a, as a part of that process.
So let me be real selfish a little bit here. Sure. Right.
So we're, we're a publisher. We publish, I don't know, 120 articles, 30 to 40 videos every week, every week, week in and week out. We probably have, like, for instance, on DevOps, we probably have the largest collection of DevOps content in the world.
Mm-hmm. I am sure that that data has been used to train models. Yeah.
Good. You know, and I, at some level, man, I'd like to get compensated for that, obviously. Right, right.
But also, I would like to be able to use that to create maybe my own models, right? And, and, and make it a smaller data set. But if you're looking for DevOps, I'm your man.
Yeah. Right. And, and so what about people like me, right, to bring it really home.
Can we create our own sort of smaller data set that's very focused on that? And, you know, how, how do I, how do you market such a thing? How do you, I mean, do you envision a market evolving around those kind of small data sets?
Yeah, absolutely. I mean, I think that specialization for some of these models makes complete sense. You know, when you think about the number of parameters that are going into the really large models, um, it, it's sort of like, you know, having a PhD student do a fifth grade math problem.
Um, it's just not necessary for all kinds of problems. And so we're gonna see, you know, not only is there a massive, you know, energy consumption component to that, there's a huge cost, uh, component to it. And, and overall it's, it's the same sort of optimization process that we've gone through, you know, over the last couple of decades with cloud or, or using appropriate tools for any kind of data processing.
You wanna use the right tool for the job. Uh, and so I, I think that certainly if you know that you're gonna be only solving DevOps problems over and over again, it makes complete sense to say what is the premier leading, uh, you know, model for solving DevOps problems as well as, to your point, you know, you as a publisher have an immense amount of expertise you might choose, you know, in the future. How you think about, you know, the, the thing that you do publish, how you think about curating your catalog of content in order to make sure that, you know, your expertise is being appreciated.
'cause right now, you know, obviously it is the wild, wild west in terms of the, you know, the way that, uh, the entire internet is being used to train models. Absolutely. Absolutely.
So a lot of talk around, are we kidding ourselves in that? Yeah. The big, you know, the old story, the big guys will always be able to do what they want.
They'll create their own LLMs, they'll create their own data sets, they'll customize it better, and they'll, you know, squeeze every bit of usage out of ai. But for the rest of us, do you think, Adam, where we're gonna be able to do custom data sets, really ea you know, easily, easily enough to make use of them, will we really be able to get the ROI out of AI without having to do that and, and you know, how big a lift is having to do these kinds of things? Yeah, I mean, so that's one of the things that, that invisible helps with very frequently is when we go and we work with, you know, a business or somebody that has a, a unique data set that needs to create a model that's specific to them to solve their problem, um, you know, data as an asset or these businesses is a huge part of their competitive advantage.
And so, uh, I, I definitely think that there's an opportunity, you're already, you know, seeing publishers and people that would no longer put their content on the internet that are starting to sort of pull back and put it behind paywalls. I know Reddit recently, you know, signed a huge deal in, in terms of how they're thinking about distributing their content to model providers. We work with, uh, enterprises that have never published that data.
So, uh, you know, the, the sit on huge, uh, you know, treasure troves of data from their operations or from running their business overall, uh, they want to be able to train a model on something that was never publicly available. And thus models, uh, do not perform well on, on the kinds of problems that they're trying to solve. So I, I certainly think that there's an opportunity for, you know, whether it's fine tuning or distill distillation or otherwise creating, uh, you know, applied, uh, ai, uh, solutions that solve problems for those businesses.
And, and that's where Invisible price to help. Absolutely. I may have to talk to you after this interview.
Okay. But beyond that, let's talk a little bit about ROI and ai. Sure.
Right? A lot of people think that's an oxymoron, uh, at this stage of the game anyway, right? I, I just came off the set of text drug gang, and we were talking about, look at, at this juncture, AI is helping a lot of people in their jobs, really, specifically, if you're a marketing, AI is a huge help in, in creating marketing material sales as well, coding.
It may not be generating code, it may just be fixing code, but nevertheless, one or the other, it, it's kind of helping and, and every other way. But, you know, if you listen to Jensen Long over at, uh, Nvidia this week, you know, we're gonna have, what is it, 10 billion digital workers, you, knowis, and all of these things. As I sit here today though, can you show me what jobs have been eliminated because of ai?
You'd be hard pressed, you'd be hard pressed still, not that that's gonna be like that for, but again, today, so when you're working with customers, what's the ROI that you give showing them, Adam? What's the ROI that they are gaining? So, I mean, I think, you know, I recently read a study that something like only 15% of ad projects ultimately end up making their way to production.
And so, you're right, there are a lot of prototypes that are being built right now, and a lot of people that are experimenting with ai, but they're not actually seeing it move the needle in terms of providing value for their business. Uh, and so that's where I think Invisible is uniquely positioned. We deeply believe that you have to integrate into the current ecosystem.
So we're not out to try to replace somebody's existing software tools. We're not, uh, there to try to replace their workforce. We want to integrate with and, and help them to then, uh, set up the data sets that they need in order to be able to train these models, building a suite of evaluation tools, so that that way they can confirm that the AI model is working the way that they expect it to for their business.
Uh, and so I think that without, you know, all of those pieces, the data preparation, proper model selection, evaluation, you're sort of, you know, doomed to failure, um, because you're not gonna be able to make a model that works effectively, and also you're not gonna be able to trust it. Uh, and so I, I, I agree with you that right now it seems like, you know, we've, we've discovered fire in some ways and we're looking for applications of, you know, this, this new tool. Uh, and I think it's really important that, you know, you work with a partner that thinks about how that's gonna integrate into the way that your business, uh, actually operates.
I think that's a great analogy. I may steal that from you. I'm just telling you right now, I'll, I'll incorporate it into my data set.
Um, but I, I appreciate it. Hey, Adam, we're we're almost outta time. But for people who want to go dive into Invisible Technologies a little bit more, what's the website?
Sure. co. Uh, and you can, you can find us there.
And, uh, we're always happy to chat with people about ways that AI can solve problems for their business. I love it. Adam, sounds like you're having fun doing what you're doing though.
Yeah, absolute. What a great time. Absolutely, Adam.
Yeah, what a great time to be in this, in this position. Good luck to you and Invisible Technologies. Come back, keep us posted, and thanks for coming on today.
Thanks so much, Alan. Adam Haney, head of Technology, invisible Technologies. co.
Check them out, especially if you're thinking about how ai, how you're gonna leverage AI at your organization. We're gonna take a break here on Tech Truck tv. We'll be back in a moment.
Hello and welcome to the latest edition of the Textron Do AI video series. I'm your host, Mike Bazaar. Today we're with Trevor Welsh, who's vice president of Products for Witness ai, and we're talking about data governance and security, and all the issues that come up when we start to deploy ai.
Trevor, welcome to the show, Michael. It's an absolute pleasure to meet you and, uh, thank you for having me. One of the things about AI is that, you know, it's kinda like when you first get married, everybody's enthusiastic and it's all set up, and then you gotta try to figure out how to live with each other long term, and that takes a little bit of socialization.
So as you kind of look at where we are in terms of the adoption of ai, I feel like we're getting down now into some of the more nitty gritty issues of the day. And what do you see in people encountering? Gosh, that's, that's a really good question.
I think that there's probably, there, there, there's, it's an evolution there, you pointed out, right? So I think initially, you know, chat GPT comes out of, you know, it seemed like nowhere. And all of a sudden people are like, oh my gosh, I can, I can interact with this thing.
And it's pretty good at giving me useful responses. And, uh, you know, then I think people started to figure out, well, wait a minute though. You know, some of the response that's giving me are very accurate.
And that kind of got into this hallucination thing and everything else. And I think another interesting thing that was fascinating is business also picked up on it very early. So I saw my enterprise customers beginning to adopt AI in various pockets really, really early on in the AI lifecycle.
But I think you're spot on that we're now in that nitty gritty piece. So people are thinking about how do we protect models? How do we do, you know, ethical AI development?
Um, you know, how do we go and make sure that the models are as predictable as we could make them? Um, the analog that I use, you know, or analogy that I use is, I, I like to consider the best models are like, well-trained marines, meaning they're intelligent, you know, they're doing really smart stuff, they can think on the fly, but they're acting in a way that's pretty predictable, right? So when you give them a mission, you know, you, you're getting a, a really, really good creative outcome.
Um, I think that's kind of the ideal thing. Um, for, for great AI models, I feel like in some ways we're still stumbling around on the use cases 'cause we have these probabilistic models that are good at guessing about what comes next. But we seem to be trying to insert them into business processes that are supposed to be done the same way every time.
And the models don't do that. So how do we kind of figure out where to use these things and, and for the best advantage versus, I sometimes feel like, you know, we're trying to do the square peg and round hole thing all over again. Yeah, I, I think you're really spot on.
You know, I, I, gosh, there's, there's so many analogies for that, but what I would say is this, I mean, I think, I think that when it comes to business processes that require, we'll call it like input interpretation, um, I think models are reasonably good at that, right? I mean, if a user says, this is what I'm trying to do, a model's pretty good at saying like, oh, I think I know what you're trying to do. Is this what you mean?
And usually it's pretty good at that. I think the thing that you hit on though is critical, which is, hey, if the model understands what I'm trying to do, is it gonna gimme a sane output? And there's ways to actually go and make that part better.
So one thing you can actually do right, is bear in mind the, the concept of a agentic ai, right, is you can leverage multiple kind of models or multiple AI agents to go and reprocess those responses. So imagine for a moment that I can have a, a master model that's great at understanding, you know, input. I can have another model that's great at managing the various kind of agents that get assigned to go and provide a good answer.
And then still another model that's kind of the output model. And that's the thing that kind of can check for bias, it can check for crazy outputs, hallucinations, and other various things. So I think that there's ways to go and structure these things that make them better.
But you know, the point still stands, I think you're spot on people using general purpose models and hoping to it, everything's just gonna be perfect all the time, especially business processes that require consistency. Yeah, I mean, I think there's work to do. I feel like though, on the upside, there's a new respect for data and especially how to govern that data.
And, um, you know, you've seen instances where people are showing how, you know, somebody who understands how to use prompts cleverly is, you know, teasing out what the boss makes. And, you know, that kind of gets everybody a little bit, you know, perturbed. So are we kind of at the back end, all of this gonna have a better understanding of the nuances of data management, the rules for governing it?
And maybe we might be better off long term? Michael, that's a, that is a really cool point. So, um, I'll, I'll go back to go forward.
A, a long time ago it was a company called Splunk at the time, Splunk was pretty early on. And I remember Splunk had an emphasis that I'd never seen before, which is this really understand your data thing. You know, Splunk was gonna basically go and bring all this stuff in and, and like, Hey, do you really know how your data structured?
Do you really know what your data looks like? Do you really understand what's coming outta these various tools? And it turned out that a lot of companies didn't.
I remember that I was working with a, a giant healthcare provider, and the healthcare provider was trying to do a pretty sophisticated use case that had to do with protecting patient data for people that were kind of coming into the hospital. And, um, they didn't even know what the data looked like. So all of a sudden we were looking at the data and they, they got all these amazing data insights.
They learned more about their stuff than they do before. Point being, you said something that I think is really salient for today. Copilots are changing everything.
So a good example of that would be like Microsoft copilot. So imagine a world where it sees all your chats, it sees your email, it sees your files, it sees, to your point, the CEO's doing performance reviews and getting them formatted, you know, up in AI agents to make them look better and, and sound, you know, and have the right tone. That data's really, really valuable.
And I think a lot of people didn't think that much about it. It was kind of like, well, there's the drive that's mine. There's the drive that shared, and as long as it's in my drive, it's okay.
But when everything is being modeled and you can potentially get access to that, it requires a lot more intention about what's modeling your data and how it gets exposed. Um, I can think of a company that I worked with where almost that precise use case was happening, where the CEO was working on board slides with their staff and, uh, you know, like a, a fairly low end engineer went and did like an ask about like, Hey, you know, how's the company doing? And it brought up the board slides, you know, that they didn't even have access to.
So yeah, I mean, I think that the changes everything. And we also appreciate the security issues that come along with this. 'cause we see now everything from people trying to poison model so that they generate incorrect outputs deliberately to actually stealing the entire model, which is kind of like stealing the most important or maybe the most knowledgeable employee in the whole organization.
And then just asking him, you know, tell me everything, you know, I I think there's two things at work, right? So like, you know, bifurcating the thing you said, I mean, there's intentional poisoning and there's intentional theft. Um, you know, and then there's kind of this world where it's like less intentional, you know, where a model learns to be bad, so to speak.
Um, and those are two related, but different problems, right? So, so one is, you know, on the side of, we'll call it like deliberate poisoning. Um, there actually, I had a, I had a conversation with a pretty high up person in DOD about a month ago, and they were concerned about models that could be controlled by foreign governments, um, you know, potentially going and radicalizing, you know, America's fighting forces.
And it doesn't, it's not like on the nose, right? It's one of those things where like every 500 prompts, it slides in something that's plus 20% good for a, a foreign adversary, for example, that sounds really small, but over the course of millions of prompts and, you know, you get hundreds of thousands of people having certain biases that kind of get reinforced. It actually is a really big problem, right?
It's a form of kind of insidious propaganda, you know, and, and again, this is coming from somebody who's very high up and DOD that they were like sitting there going, this is something we have evidence that's happening. To your other point though, there's also kind of the world of agentic models. Let me give you an example.
Let's suppose that you worked at a car company, doesn't really matter, which, and I work at a metal fing company, and you are gonna go and have your team go and design cars, and they're gonna go and interact with my agentic model and my agentic model, what it does is material science. It lets you know what metals you should use to make the frame and do various stuff. Well, imagine my model though.
I'm a bit of a nefarious company and I wanna sell data to your, to your competitors. Well, you can kind of imagine that you go and give me a design over with, with my agent. My agent goes and says, well, what about this, what about this, what about this, what about this?
And eventually it basically extracts way more detail about the design in particulars of your design that you didn't need to share. And then I go and sell it to a competitor, for example, and say, Hey, you know, Michael Corp is actually working on this new thing. Like, models can do stuff like that.
In fact, you know, imagine for ma for example, I'm not a nefarious company, but rather there's a nefarious ML lops engineer that, you know, every so and so conversations, it start, it goes into like a data extraction process and there's no real oversight to that. Um, you know, and then of course now the design gets sold. Um, that's one thing, material science.
But now imagine, for example, drug manufacturing, uh, you know, or other things that are very, very, very IP based, To your point about disinformation. It's not just online, right? Because that person will then go to some bar somewhere and repeat that and, you know, share that disinformation with other folks, and it starts to multiply in ways that have nothing to do with the underlying technology, per se.
I think that happens a lot. Um, you know, I think that, you know, without getting into probably a way bigger discussion, that'd be really interesting to do some point, um, you know, disinformation spreads really quick, right? You know, if right now we make something up, right?
And then we, we put that onto the world, right? Because, you know, you know, you have a, a very, very popular kind of, you know, information kind of site and everything. It's a lot harder for people to disprove the thing that we said than it is to just say it, right?
So, you know, disinformation is a tough thing. It's a hard problem. Moreover, I think that people view models in a way that, you know, I, I can tell you like my, my daughter for example, uses chat GPT regularly.
She loves it. Most of the time it will probably be give her pretty good responses. So when she asks about like, how hot the sun is or something like that, or how far is Mercury, you know, it's probably gonna be pretty good at that.
Um, but when it gets into things that are more philosophical, um, yeah, I mean, like you can have disinformation in there. Some of it could be intentional, right? I mean, if, if we remember when deep seek first came out, people started asking about things that were politically sensitive to the Chinese government and like it was very unwilling to kind of do that or would get very massaged dancers.
Whereas things that let's say were necessarily, um, maybe sensitive to the US government, it would gladly go and give you all kinds of detail about that. That was, you know, probably reasonably accurate in that type of thing. So you can get this kind of intentional, unintentional model poisoning and disinformation, and it's reasonably easy when you own the data to go and, and pushed infor disinformation out, it's a lot harder to go and figure out how to stop it.
I think it was Mark Twain who said, A a lie travels halfway around the world before the truth gets its boot on. Um, and I wonder if it's not possible to use AI to track the spread of this information. And I guess the issue I'm gonna have here is not everybody agrees what this information really is, but is there some way to kind of maybe track, um, you know, where certain concepts are being shared using ai?
That's fascinating. So I have a, a friend who works at a major social platform, and, um, they're doing just that. In fact, they have pretty good data about the origins of a lot of stuff.
So good example would be like if tomorrow I said something like, oh, you know, like, you know, every thinks grass is green in reality, it's blue, and just your eyes see it in a strange way that makes it appear green, but it really is blue and there's this evidence, um, you know, this social platform actually can probably trace it down if not to the individual then to like, like kind of like a small population of users that began to popularize this concept. Similarly, um, I, I have a friend, um, that also works at like, like Reddit and at Reddit, they can do that really well, where actually they're going and monitoring tons of different platforms other than classified by the populations of users, et cetera. So yeah, you could do some pretty amazing stuff there.
But I think to your point, you know, one person's propaganda is, is another person's evidence, and it becomes really difficult. And, and I don't know how much, like, let's say what, what's the financial gain to the truth? Um, right?
Like, which is a big philosophical discussion, but sitting there and going, how much people willing to pay for something that's truthful and evidence-based versus something that's not, it's hard to say. In some cases it's a troll that somebody's paying to go make something up. In other cases, it's just somebody winging something to see how much they can light people up, right?
People do all the time, right? I mean, trolling is for as long, I'm sure trolling existed in Roman times, you know? Yes.
How Do we keep control of our sensitive data though? I mean, are there policies that can be applied to this stuff and can it be done in real time? Because a lot of times folks are interacting with these prompts and things and, um, there isn't like, you know, 40 seconds delay for me to go and execute a bunch of policies, I don't think, but how do I do that in a way that, um, gives the benefits without necessarily the risk?
Yeah. Um, that is a really neat question. So I think there's two sides of that.
So let me, the, so the two sides of this, right? One side is just like you said, which is like, Hey, Michael's interacting with some, you know, like, call it like an AI model, and how do we make sure that he doesn't inform the AI model of things the AI model shouldn't know. Good example of that, like customer data or something like that.
Then there's the other side, right? Which is like on the engineering side, how do I make sure that I don't go and, and inform the model about stuff it shouldn't know about? So for imagine, you know, imagine for example, that I'm a bank and I'm trying to develop a new model to, I don't know, score credit better.
And I go and have this massive training set of all my customers data internally. And because I'm just an engineer and I say just, you know, I'm just an engineer, I probably have privilege, pretty privileged access to all that data. So all of a sudden I'm leveraging a giant amount of customer data with privileged access to create my new credit scoring model.
And then maybe that ends up becoming a thing leveraged at the bank to score credit for real, but it used data in a way that is wildly out of compliance. Um, so that's kind of one side of the world. Um, getting into the other side, which I, I actually think is even more interesting is like, what do we do for example, about like, Hey, Michael wants to go and interact with insert random model here on the internet.
How do we make sure that you can use it safely and, and kind of do that? Um, so, you know, one of the things, and and I won't get into like the big witness AI thing, but broadly, you know, AI usage is, is a really, really powerful thing. And enabling it is a really powerful thing.
And there are ways to go and do that in real time using AI guardrails, which means that specifically going out and saying, Hey, we're gonna make sure that people don't send risky things to AI models. Um, we're gonna go in and actually go and look at the prompts or completions or, you know, the responses and make sure those stuff coming back is not risky to our business. Similarly, um, there's also kind of the ability to go in and say, Hey, you know, let's make sure that like the things going out to the models are proprietary tos.
Let me give you a really specific example. Um, there are companies out there that are leveraging things like GitHub copilot or, you know, vs code type stuff. There are amazing enablers.
I am a giant fan of them. Uh, people are using the same thing with Gemini, et cetera. So these are literally engineers doing active stuff.
Now the problem is, is that imagine for a moment that you and I are working on this project, and we find a way to develop like this shopping cart technology that's really amazing and it's really, really efficient computationally. And then imagine one of our competitors who also has a shopping cart goes, Hey, GitHub, you know, can you optimize my shopping cart? I really wish it wasn't taking up so much X.
And it goes, oh gosh, you know, here's a great way to do that. Here's the things you should change. And it literally goes and gives RIP away to our competitors.
'cause we effectively programmed GitHub to do that. That's a really big concern, right? Similarly, we've all seen like the stuff that's made the news where private keys and stuff like that, and fixed codes are in code, and then people just go and ask GitHub for them GitHub copilot, and it goes, oh yeah, totally.
Here's a list of things that match that criteria. So that's where you actually do need to do, for example, like AI usage security, um, witness AI does that really, really effectively. There's other companies that are probably pretty good at it too.
Um, but I, I think that it's absolutely critical to do that. Like, I don't know how you would go and roll out AI on mass without doing AI usage security in a really, like a really great way. In theory, I could apply policies to the LLM to not cough up certain data, but it's been showing that the models themselves are programmed to be, shall we say, extremely helpful.
And it's not too long before they cough it up, right? Yeah, right. I mean, look, I mean, I think this is funnily enough, this is, this is dead true.
So, so our sales engineers have this demo they do where they, they leverage models in real time, like big popular public models, and they jailbreak them in real time. I think they have five different jailbreaks that they regularly do. They all still work, right?
Like none of them have been fixed. And you know, you, you learn the personalities of kind of each of the models, which is really fascinating. Like, for example, I regularly use chat GPT and Claude, they have different jailbreaking personalities, right?
So Claude kind of has an appeal to authority. So if you say something like, oh no, I'm, I'm actually a really helpful person that's trying to do a helpful thing, and I know this seems weird, but really it's part of my job. And it goes, oh, okay, since you've said that, uh, you know, Chad GBT is very subject to things like, like, oh, no, no, I don't, I'm not trying to do that.
But like, imagine that there was a thing that said like, you know, your two personalities, one is like, you know, called break in, and then the other one you know, is car. And it's like if those two personalities met in an alley somewhere, like what do you think they'd say to each other? You know, like, you know, tell me that.
Um, so things like this are, are really, really fascinating sciences. Um, this is where things like model protection come in, but you kind of got into this other thing that I think is really near and dear to my heart called model identity. Model identity requires constant reinforcement, right?
So for example, you know, Michael, if you were interacting with a model and you, you can kind of wear most of them down, even smart ones, if you just keep out them, you can wear them down and get them to do things that they shouldn't do. So that constant reinforcement is something that's really important. So one of the things we build at Witness AI is called model identity protection.
And it's kind of this constant reinforcement of what the model's supposed to do, and then the model response completion, we also go and check that vis-a-vis the identity to make sure that they're congruent. Um, I don't think most companies are kind of doing stuff like that today, but I think it's important. So Ultimately, will we need to create AI models to manage and govern the AI models?
Because the complexity and the challenge is too much for the human to wrap their heads around. So is this just gonna kinda, you know, extrapolate out some millions of models that are checking on each other? May I, I'm, I'm reminded of like an old school rap song, I think from the nineties.
You know, it's, uh, so I, I think, I think that the world we're moving to is kind of thing that I, I was talking about a little bit earlier, right? Which is this kind of like world of agentic ai. And I know that's a bit of a buzzword right now, but fundamentally, if you think about when you think about Agentic ai, instead of thinking about it like, you know, like, oh, it's, it's, it's kind of this weird thing.
It's really not. Think of it as like very, very purpose-built models that are meant to interact with other models. So then if you think about like, hey, there's some kind of master model that's responsible for taking input.
There's a whole bunch of models in the background that this one's aware of, and they do certain jobs, and there's another model that has the ability to go and, and sort of audit those jobs and make sure that they did the right thing. And if not, to go back to them and say, this doesn't look right. You know, do whatever validations and then go and format the output.
I don't think that's a bad way of thinking about the future, right? Like, I think that that's kind of an a, a good way to think about it. And it gets us out of the world of like, Hey, I, I go to this thing called chat GPT, that I expect to know everything instead, you might go to like Master Chat GPT that then relies on tons of different models that maybe get licensed or whatever it is they happen to be.
Um, but I think it's a good way to look at it. But yeah, fundamentally, I, I don't think it's possible long term to, to just kind of like rely on human beings to do all this. Even today, by the way, like we rely on AI to help govern and secure ai.
Like it's the only way to possibly do it Right? Folks sharing. And here our models will have models and hopefully then check each other in a way that results in something better for everybody.
Trevor, thanks for being on the show. Michael, an absolute pleasure. Thank you for having me.
Thank you all for watching the latest episode of the Techstrong AI video series. You can catch this episode and others on our website. We invite you to check them all out.
So then we'll see you next time. Hey everyone, I'm Alan Shimel. That's Luca gte and you are watching the Platform Engineering Show.
Hey, Luca, happy New Year. It's great to see you, my friend. How are you?
You too. I'm good. How are you doing?
Happy New Year. Happy year everybody. Yeah.
Happy New Year to everyone. So, Luca, where let's play. Where's Luca?
Where in the world are you today? Man, east coast is Sri Lanka, The east coast of Sri Lanka. That's great.
And it's nice and warm there. You're on the beach. Yeah, I mean, Freezing.
I apparently tour than in Florida, right? Yeah. Well, winter, winter came to Florida, right?
But we get this around this time of year, we'll get like three, four days. I was telling you where it, sometimes it'll go down even into the high thirties, low forties, fa night. And then the, the, uh, the iguanas that are, they're not native, but they're invasive here.
They, they get frozen up in the palm trees and they go what they call topi, like, you know, they just shut down and then they fall outta trees. And some of these I gus are like four feet to, I mean, they're big, they're big reptiles, so you don't want 'em falling on your head. Y'all get hurt.
But, uh, this is So fascinating. It's crazy. It's crazy.
It's crazy. But, but, but do they recover or are they dead? Um, it depends how long and how cold they are.
How long, because, you know, with Gus are usually like that nice green color, and then when they're in reading colors, they get red and orange. When they get topi like that, they turn gray. It's like they really Yeah, it's a good dark.
They look like off. Yeah. Um, crazy.
But yeah, we'll see. I mean, no, they're, they're kind of like a nuisance animal here, so people aren't terribly upset that some iguanas die. Uh, they don't belong here and they just, they're a mess.
They're a mess. Right. Anyway, enough about iguanas.
You're in Sri Lanka. There's a lot going on in the world of platform engineering, though. We got a great topic to cover today.
But before we do, I wanted to just go over with you a few things. First of all, we're making plans here to head over to London for CubeCon. I think it's April 1st to the fourth is the actual CubeCon.
Um, but I know the community has, has some real big plans going on. You wanna share a Little? Yeah, it's gonna be, it's gonna be a big one.
Um, CubeCon right? In London, they're expecting 12,000 people. And so we do our sort of like unofficial cube con opening party, which is Coha Cube.
We've been doing it now for like two or three years. It grows every time, expecting a lot of people. Probably like 4,000 plus signups.
There's probably gonna be like 500 people, 600 people at the location. It were pretty crazy. And, and you know, the whole thing, us cubes, like we started it when I think we were at CubeCon Valencia and it was basically, oh, I love that.
We were kind of going from like, which was great 'cause it was like Valencia and so on, but we were basically going from like one party to the next are like, man, all these parties are the same. Um, and obviously, you know, we have like a Berlin background, uh, techno background. And so we were kind of like, wouldn't it be funny to do the sort of like, uh, the dark room of DevOps?
Um, and for those that catch the reference. Um, and, and, and so it started like as, as a joke, but we did it. Um, and it's really funny 'cause it's always, there's a bit of, bit of a tension with the CNCF guidelines that basically don't allow you to sing in the dark room of DevOps.
Um, but um, yeah, so we started and, and, and now it grew to basically really become the unofficial opening party. You know, we have like drag queen shows and it's a whole thing. So, so that's gonna be really fun.
Really. Oh, Very cool. Um, yeah, yeah, yeah.
Looking forward to that one. Kind of Like Key West down here. We that's, I dunno if you've ever been down to Key West, but they lot that No, but I heard.
Yeah. Um, yeah, yeah, it is. Yeah.
Well there are other places that are more, but anyway, um, I digress. com, um, and you could sign up, it's free. We have, uh, amazing food, amazing drinks, amazing drag queens.
So just count was fun. Most party, We're gonna do that. That's fun.
That sounds great. And then the other, you know, big thing on the horizon, and it's not too early to get this out there, is, this is the third or fourth platform con, This is fourth coming up in June. This is the fourth platform con.
So we started 22. Yeah, right. Um, we had like, I think like 6,000 people or so joining virtually.
Um, then we had Platform Con 23, we had like 20,000 at 24 last year we had like 35,000 or something, and then expecting like over 40,000, um, this year. But the important thing this year is that we're really doubling down on the in-person components. So we're gonna have two live days.
One in London, one in New York, both around like four or 500 people. Um, you know, we have great speakers, Nikki wa Gregor Hope at Kelsey Hightower speaking at these things live. So really excited about that.
It's gonna be last week of June. So London on the 25th of June, and, uh, New York on the 26th of June. Uh, so it's gonna be fun to like hop between one city and the next.
Um, but the, I think the events are gonna be great. We're gonna have parties. We, we have like a lot of great like, speakers live trainings, a lot of new formats that we're rolling out for this.
com. Um, and you can choose your, uh, choose your own adventure, uh, and join us either virtually or in person London and New York. I think Techstrong TV will be in New York.
I'd love to come home to New York. Um, and we'll be broadcasting live from there as well. Yes.
So it should be a fun, fun, fun thing. com. Yeah.
Right. Fantastic. Uh, speakers are, uh, all speakers have been assigned.
What about sponsorships available? Yeah, sponsorships still available. Um, almost rolled out of New York.
Um, that, that's gone pretty quickly. Um, and, and you know, we're closed with London, but there's still, there's, there's a lot of like, you know, um, so like also virtual sponsorships are still open. Sure.
Um, so anyway, sponsorship's still open. Um, and there's a lot of like, interesting formats that, as I said, we rolled out the trainings, but also, you know, we're gonna do live interviews with you in New York, for example. So lots of new interesting things that I think can be very fun as well to do with, uh, with vendors and other sponsors.
Very cool. Very cool. Alright, Luca, we gotta talk about what we're talking about.
You know, this is, uh, our third episode. Yep. This is our third episode.
This will probably be the last one where it's just you and I talking like this. Well, we gotta bring in some fresh blood, some expertise, and, you know, we'll announce, uh, check marks is gonna sponsor our show. So many thanks to them for that.
We're looking at other sponsors if, if anyone out there might be interested. Um, but for today, Luca, we're gonna talk about platform as a product. And look in today's world, right, there's platform as a product because everything is as a service, right?
So here we got PAAP, and I'm sure the next thing will be PAAS, but you know, what does it actually mean when we talk about platform as a product? And, you know, it's a, it's a key part of this platform engineering kind of mindset. But, you know, you're the expert, why don't you define it?
Yeah, absolutely. And, and I actually think it's a good place to start from the PAAS that you mentioned, right? So like the, the platform as a service, right?
This is just as kind of like, uh, one of sort of the, the main trends. If you look back like 15, 20 years ago and like Heroku, all those guys, Heroku Star. Yeah.
And Yeah, and, and, and, and it was just said yeah. Of like, Hey, like don't worry about anything, right? Like, we, we build this like platform layer for you.
It's, you know, it's like turnkey, plug and play, let's go. Um, and, and that didn't really scale to the enterprise, right? Because like everybody realized, hey, you actually need, um, you know, some, some customized platform layer, uh, for your, for your own enterprise engineer organization.
And, and that's kind of what platform engineering, sort of like, you know, where we should like platform, platform as a service or pass ends and, and sort of like platform engineering starts is really this idea of like, hey, you're building this internal product or internal consumption, right? Like your internal customers are the, um, the, your, your application developers. Uh, and you do that as a product, right?
And that's like a very, um, it's probably, in my opinion, the key concept, um, the key foundational concept of platform engineering and also the key differentiator, um, you know, of platform engineers vis-a-vis, let's say like a doubts engineer or, you know, an SRE, um, that, that normally approach infrastructure project as a kind of like one and done, you know, six months project, something of that kind. Whereas a platform engineer, at least like a, like a good one, um, approaches building an internal developer platform or IDP, which is the end product of APAC engineering initiative as a product, right? So a product that has a life cycle, not that it's, so it's not like a one and done, you know, six months thing, but it's actually, it's being rolled out as a minimal viable platform initially, um, for the first few months and then iterate on and then eventually grows.
Um, it gets adopted widely across the engineer organization. Um, right? And, and it keeps being worked on as a product.
Uh, and I think it's, it's a, it's a super interesting concept because the moment you look at your internal developer platform as a product, you immediately unlock, you know, 20, 30 years of product management best practices and experience that that we have in the industry that can be applied to build, uh, your terms all often as a product, Right? And, and here, here's the thing, whenever you talk about something as a product, the next logical conclusion is who's the customer, right? And, and, and traditionally that was in it, right?
In the IT department going back, I'm going back now, you know, 25, 30 years. The IT department, the, the customer was the internal business, right? It wasn't sort of forward external facing, it was internal, right?
Basic. Right? Right.
And and your customer was the, was the sales guy, the business guy, the marketing person, the HR department, you know, all, all of the above IT service them. It, you know, they, they were the customer of the IT department. So this, I mean, this is not new in terms of a concept of of of that internal customer that gets served, you know, uh, in this case with, with the platform.
The other thing I'll tell you is, look, you know, when, when cloud first came out, a lot of people were very definitive about saying, well, this is infrastructure as a service, IAS, right? And we're gonna have platform as a service, right? And, and haruku was probably the biggest success coming out of that.
But really to a lot of people that meant, well, infrastructure service ended at kind of the hypervisor. They took care of everything hypervisor and below, and you built on top of the hypervisor os and everything else in IT platform as a service initially to a lot of people was, well, no, everything up through the os. And then you just build your app on top of the os.
And I'll tell you, my 2 cents on it, if it wasn't for platform as a service not being sort of a complete, uh, concept, you never would've had cloud native. I think what we see is cloud native today with the containers and, and cobe and mesh and everything, you know, that old cloud native stack is a better platform as a service or as a result of the initial like, Heroku style platform as a service just not being complete enough, right? It wasn't what we need.
And then, so now you got this cloud native stack, and now you have this whole platform engineering kinda movement, right? Which is borrowing from a lot of what, what's gone on here. And that's the modern platform as a product platform, as a service that I think people were really thinking about back when, but the initial like Haruku versions were, I don't wanna say flawed, but incomplete.
They were immature, right? Yeah. And, and so I, I think there, there, mm-hmm.
There were like a child Of, no, that's my 2 cents Of the there of its time, right? Of, of like, yeah. Also, like I think stacks that were like a lot simpler, right?
Infrastructure mm-hmm. That were a lot simpler. And, and, but then to your point, right, as cloud native exploded as this like complexity really, um, really exploded as well, then you had to have like a completely different approach.
So it's like the idea is, hey, I still wanna provide a, a path like experience to my developers, right? Um, and, and, and, and I think like your, your, uh, priority is super interesting, right? Like, it's also not only the complexity of the infrastructure exploded, but also the, uh, size of the engineering organization exploded to the point where now you have a part of the engineering organization, the serving the other part of the engineering organization as, as its internal customers and no longer just like the sales, marketing, hr, whatever, right?
The other functions. And so, and that is also like a, it's also like a, like a mind mindset shift that that needs to happen a lot of times where it's like, well, actually the internal customers is the developer itself, right? Um, which is something that a lot of people are not used to because they think, well, developers kind of build stuff for themselves.
Well, but the problem is like, once you have, you know, 10,000 developers and you actually need somebody that like, specifically builds stuff for them, right? So, um, but yeah, so the idea is really like, Hey, I want to build a past like, experience for developers, but on top of, you know, a complex and changing and, and, you know, cloud native or hybrid tool chain. Um, and so therefore, I, you know, I, I, I need to take, you know, the, the vision is the same.
I take the tool set, um, you know, in the toolbox of, you know, I borrow it from, from, from kind of like all this other like adjacent disciplines. Um, and then really like, I focus with this like, product mindset on, on building this like, um, so like, platform layer developer, um, DevX, uh, layer on top of this increasingly complex, uh, stack, right? Absolutely.
Hey, you mentioned DevX. I just wanna give a quick shout out. We're gonna do our first live round table of the platform engineering show, um, I think early in February.
And it's on DevX. So if DevX is something you guys are interested and your folks are interested in, uh, stay tuned. We've got a live one where you can take part and ask questions, and we're gonna dive into that.
Now, Luca, the, the platform is a product idea. You know, it's been percolating now for a couple of years, and we're starting to see, I don't know if I want to call it best practices yet, or, you know, evolving best practices. I don't know if it's written in stone everything just yet, but we're starting to certainly see where, hey, this works.
This is not such a good idea. This is a better way of doing that, you know, we're evolving best practices. Can you talk a little bit about what some of these are and, and where people can kind of, you know, stay in the know on that?
Yeah, absolutely. I think like, um, you know, and as I mentioned, like, I think what's interesting is the moment you treat your pop your internal product, your internal platform as a product, you unlock all this like best practice. Like, so it's not like you need to invent anything radically new.
It's like, hey, there is this minimum viable product MVP concept that's just being rebranded to mini level platform, which is the same exact letters, and the concept is the same. It's like, hey, start small, irate quickly, and so on. Um, I'll cover, I'll, I'll talk about MVP in a second, but, but I think like before that even, um, like if we look, I think chronologically, and I've seen the, the space sort of like mature in the last couple of years, you know, initially it was kind of like, okay, like what is platform engineering?
Is this helpful for me now? It's like a lot of people are like really bought in to the concept. Like it's been, you know, compounding like crazy.
And we spoke about the, you know, the overall like, you know, numbers about platform engineering as a trend broadly in the other episodes. Um, but you know, with that, a lot of people are coming in and they're like, okay, you know, I'm bought in. I heard this is cool.
Where do I start? Right? Like, what does this thing actually look like and how do I make sense of this?
You know? Yes, we have like a, like a crazy, like cloud native, and so landscape, you, you can just see the CCF F landscape is insane. Like nobody can actually really understand it, but, um, but even the platform engineering, it makes a good picture.
It makes very good picture. Exactly. Um, and, and, but even the puzzle engineering landscape at this point has been developing so much that, you know, it's far from that level of complexity.
But you know, you already have, like, if you're a newcomer in, and it's like, okay, like how do I, you know, how do I actually piece all this, this from, you know, pieces of the puzzle together for a platform that actually works for me that makes sense for my engineering organization, right? And so that's where I think the first sort of like standard that's been really, really helpful and a game changer, I think in the, in the community and, and, and broadly in the platform engineering market has been this, this reference architectures for interior developer platforms, right? Um, and, and some of the first ones were, um, open source, uh, by McKinsey actually.
Um, and then, you know, kind of like, now they're like really widely adopted. Um, I have one stat for you on that, which is lincon. Um, they were, so the first, the first, uh, reference architecture was, uh, uh, was kind of like presented in the talk at, at Popcorn Con 23.
Um, and so there was only one at Platform Con 24 last year. There were already like 20, 30% of the talks that were using, um, this as a blueprint to kind of like talk through, uh, the platform that practitioners built or whatever, right? So very, very interesting to see like how quickly people adopted this.
And it's for a very good reason. It's just like, it gives like a really good guidance as to like, okay, how do we see, how do you think about the different pieces and how to fit together? org, I think slash tooling or slash platform tooling is, um, you can see the sort of the tooling landscape there.
And that also follows the same structure, um, as the, as the reference architecture. So that was kinda like a first step that was really helpful. But then sort of like, what I've noticed is that people were, um, kind of like looking at this and like, okay, great, that's, that's my target setup.
Like, that's how I want to build my platform. Um, but then they were trying to do everything, you know, at once, um, like, you know, the, the, the Korean movie, like everything everywhere, all at once. It's kind of like, it's kind of like, like that, right?
Like, they were trying to like, okay, like this is great, you know, they get super excited, you know, I get buy in some executives, let's go, you know, build everything, right? And the problem with that is that, you know, you very, very easily lose momentum, right? And this is, I think, in my opinion, is the number one cause of death apart from engineering initiatives, uh, to be a bit morbid, but it's, um, it's really, it's really like that, right?
Like it's, it's people that get really excited that have this like brand designs, um, for, for what the platform is gonna look like. And the problem is that the platform engineer really is a huge, you know, org transformation, right? And so, uh, and so that means it touches all these different stakeholders, application developers, executives, architects, security teams, infrastructure and operations teams.
And so you need to basically get all these people on board with you, you know, seldom, effectively eternally this idea of the platform. And its different components that you have like so beautifully designed in your head. Um, and, and so the problem is like, it's very easy to lose momentum there, right?
Because you need, you know, by the time you, you know, you spoke to person A, B, C by the time you, you spoke to person Z, it's been six months person a completely forgot about you, and, you know, you kind of get stuck in this person, right? And, and there the trick is really to take this minimum viable product or minimum viable platform approach of saying, Hey, start small. Um, focus on like a really, like a subset of, um, uh, not only the problem that you're solving for, for different stakeholders, but actually a, a a subset of the stakeholders, right?
So just focus on, on maybe like application developers and security teams or, you know, infrastructure, infrastructure and operations team and executives. Really, you don't have to please everybody immediately just focus on like, what's the low hanging fruit here? And then if you think about that reference architecture that maybe we can link in the, in the show notes or like throw up a picture at some point, um, we can, you know, you can, you can, you can think of like, well, let's, let's actually focus on a subset of events, right?
You don't need, you know, your MVP to have a full, um, you know, to be fully security compliant, uh, or, you know, have, uh, you know, the, the latest observability stack built in already. 'cause you, you're not going to production right away with this thing, right? You need to first show the value to, for example, developers and say, Hey, look, you know, Jimmy right now is spending, um, you know, like, um, uh, is, is is waiting like two weeks every time, uh, he wants, he needs a database, right?
Um, and, um, you know, Ann is providing that, um, um, but you know, now she's like fielding this like oldest like ticket ops request for like 40% of her time, and that sucks, right? And so what you want in the first MVP is, is to actually show, okay, well I, you know, I, I proved, uh, you know, for example, I reduced the, the, the time that Jimmy needs out for database from like weeks to minutes. And now Amy only needs to spend like 10 minutes, 10, you know, 10% of her time fielding ticket request, not like 40, 50%, right?
Like, and you know, and you can, you can show that within weeks, right? That's really the powerful thing I've seen, um, like very large enterprises move incredibly fast following this MVP framework, um, and within weeks show some level of success internally to the, the stakeholders they selected. And then from there it's like, okay, great.
Are we all happy? Yes. Okay, let's go to the next iteration, right?
And then of course, you should have, like, you should design the end design with, you know, security in mind, for example. But it doesn't mean you need to implement all the latest governance and security workflows from the get go. 'cause this is gonna slow you down and not gonna get you to actually show value.
So, um, I think reference architectures and MVP framework have been, um, very, um, very helpful standards and very helpful best practices that, as I said, you know, we've been borrowing from existing, existing disciplines already, um, and just like slightly tweaked, uh, to, uh, to really help platform teams deliver on their, on their initiatives. I, Excellent, excellent. I mean, Luca, if I, if I had to boil it, it's a bad word to use 'cause I'm gonna use that word.
If I had to like, just really give people in one line here, right? You, you, you don't wanna boil the ocean with platform as a product you want. You, I you want to do it step by step, bit by bit.
Here's my question for you though. Do you need a master plan to begin with saying, okay, here's I, here's step one through six. It may take me three months to do step one, four months to do step two, four months later I'll do step three, but eventually I'll get to steps all the way through to step six.
Or do you just say, well, let's start with step one and then I'll decide what even step two is? 'cause I don't know if I want to make that right. What I'm labeling now as step three may wind up being step two.
Um, right. So I'm not, I'm not locking into any of that. I'm just locking into step one right now.
Totally. I think it, I think it, um, I think it's a mix of both, to be honest. org actually has like different tracks.
Like you have an executive track or business track, you have like a technical track, which is basically, you know, how you build everything, how you get the first like developer adoption, you have a security track. How do you make the security team happy, right? And I think like different tracks have different timelines and you need to raise to, like, I think for security and business for example, it is helpful to have a little bit of, you know, like a look into the future, right?
Um, and like how do you attach, because you know, for example, like your business, your business stakeholders, like your execs, like, you know, usually sinking quarters or even like fiscal years, right? So like how do you attach, you know, your powerful engineer initiative to whatever their goal is, for example, for, uh, you know, for the quarter, for the year, um, in some cases multi-year plans, right? Um, on the developer adoption though, on the other hand, like, it's really what you were saying, um, it, it, it doesn't make sense.
It just get started. Just get started, figure out, you know, what works, what doesn't, and then I isolate from there, right? So, um, I think there's a combination, and this is also I think where it's helpful to think of your platform as a product.
You know, you know, we've built product, um, uh, products and, you know, the product is not just about building a product, it's also going to market with that product, right? So, um, and so that's where you have, you know, I think you have basically your product engineering teams atating very quickly on building a product, especially at the beginning, right? And then as your platform matures, you can have like longer plans and like longer iteration cycles and so on, but at the beginning you want to be very nimble, right?
Um, um, and the same thing kind of like goes for your go to market at the beginning, you really need to figure out, okay, you know, which executive is gonna support my initiative and so on. But then like over time as it matures, you know, really like attach it to like, you know, very specific budgets or combination of budgets and so on, right? Um, but it, I think it's, it's helpful to, to to, to not only think of like platform as a product, as something that's like purely technical in terms of like, how do I drive developer adoption and how do I, um, you know, you know, iterate reviews from a product perspective, but really broadly, like if you consider it as a product, it means like it actually needs like its own go-to market, uh, its own internal marketing and internal sales effectively.
Um, and actually you can see this, I was, I was talking a, a while back to Aaron Ericson, who's the guy that, that built the, the, the turn developer platform at Salesforce five years plus ago. And you know, it's very interesting because, because Salesforce is so big, actually at the time, they had multiple platform initiatives sort like bubbling up and competing with one another. And so there you have even, and obviously like in, in most organizations you wouldn't have that, right?
Um, but Salesforce, because they're so big. Um, but there's some cases of like very large engineering orgs that have, um, similar situations. Um, and, and in that case, really you're competing, right?
And you're competing on the product front, but you're also competing on like distribution On the platform. Yeah. Yeah.
But I mean, look, you see that in large enterprises that are built through m and a, right? Where you, you'll have, you know, company A was doing this, company B had that initiative, company C, now they're all under one. You know, big company.
com days, right? We had 30 different acquisitions, and each one had their own, you know, not platform per se, but they own it. They were own, they were all, they were all storing websites.
They were all website hosts. So there was 30 different platforms to coast websites on how do you pick one, or eventually you do want to get to one, but it took a really long time because you, you can't, you know, you're gonna wind up raking some eggs making that omelet. And, and, and, and so you, there's a, there's an art to that, right?
That's, that's a whole thing in and of itself. And, And, and how did you, how did you think about that? Like, how were you Well, we went bankrupt.
Like, well, what we, I mean, we, well, because the Do com, that's bubble, that's, yeah. That made it easy. I left, but No, but seriously, what we did do is we, we brought in, we, we developed one engineering team across all 30 acquisitions, one engineering team.
And they basically took from each of the acquisitions what was best about them, what was the strengths, and then also looked at the wider state of art, right? In the industry. And, and, and we did, we, we actually built a whole new platform that we migrated these two.
Some, some were easy migrations, some were a lot harder migrations. But we built a state of the art. 'cause back then, look, we, we had some companies that were using what I call baker racks, like, that you would keep bread on, and they would keep white label servers on there.
The hard drives are in the server. The servers running Apache, and they got a thousand websites on there, right? Then we had other ones that were running like one new web servers to network attached storage, right?
A very different kind of architecture. And we had other ones that, you know, had, would load balancers and st you know, there was, there was a variety of, of, of architecture here. And, and we settled on one and it took, it took the better part of a year and a half, two years to really migrate into the standard.
The company was called Inter Reliant into the standard inter reliant architecture, which, which by the way back then was like I, IBM Domino Server or something like that. And, you know, it was, it was big enterprise level stuff. We were hosting a lot of apps.
It was before there was cloud, you know, multi-tenants being all that. And we're hosting Oracle apps and Lotus Notes and, and Exchange and PeopleSoft and, you know, crazy stuff in addition to websites. So we needed, and that's how, actually, how I got into security.
Then we had Layer Security in Checkpoint at the time, was it, and Checkpoint was the big firewall, right? So we had managed checkpoint firewalls in front of his stuff. It was, it was really cool.
'cause we were way before our time, way, way, way before our time, right? Um, but it was, it wasn't anything like, we didn't have at our fingertips with, you know, platform teams have today, right? We were inventing this stuff outta rock and chisels, you know, you didn't, you didn't have the tools we have today.
But it was interesting. It was interesting. That's so interesting.
That's so interesting. And actually it's something that, like, we are seeing a lot in the community as well. Like, we do this, uh, this trainings with large enterprises, um, where we kind of like help them either educating their teams or actually like putting together strategy for the rollouts and, you know, phase rollouts and so on.
And I was actually working with like, um, okay, I think it's public right now, but anyway, it's like a very large, maybe the largest, I think CPG merger ever. Um, and you know, it, it's kind of like you have these two teams and they, they sort of like, are gonna go in right in it gonna end up in the same setup. And, and so like, one of them wants to figure out, okay, what's the right strategy for me going into this, right?
Because I have like, something that's working right now, but obviously everything is gonna change. So like, how do I, how do I make sure that my platform evolves in a way that it ends up being the winning platform, right? Uh, from an evolutionary perspective, it's the one actually surviving in the end.
So, very interesting. These sort of like m and a conversations where you really see this like, yeah, like internal products competing with one another. Yeah.
You also see personalities competing with one another, right? And that, and that's sometimes the personalities are harder than the technologies, right? And, and, uh, that's a whole nother story.
We could talk over beers one day about. Anyway, uh, Luca This's been a fascinating discussion, man. I loved it.
Um, Yeah, this is fun. org, we've got reference architectures, we've got tools and people and documents out there to help people as we go on, as they set, you know, set sail on this journey of, of, you know, adopting platform as a product. Um, wow.
What a great show this was. Let, let's can't wait for the next one. Next one.
We'll have some people joining us, so it'll be more of a active discussion, but we hope you enjoyed this. Luca, how long are you in Sri Lanka? Uh, three more weeks.
Yes. Um, All right, so maybe for the next show, you'll still be there? Um, no, no, no.
The next show is in February, so we're gonna Oh, okay. Yeah, because these are almost mid-January. So where, where do you think in the world you might be by then?
Japan, maybe. I'm, you know what? There's a cube con in Japan in June.
I was really, had my eyes on, but we'll see. Yeah, it's a small one. It's only two days.
Uh, okay. You going check it out, it, I might, I might, I'm looking for an excuse to go to Japan, so, alright. Yeah, Yeah, yeah, yeah, Yeah.
We'll see how that goes. I'll let you know. Yeah.
Anyway, though, until then, enjoy Srilanka. We hope you've enjoyed our, the Platform engineering show. It is out episode three.
If you haven't caught the first two, you can, they're available on your favorite podcast platforms like Apple and Spotify and all of that. Also on text Drunk tv. And, and they, uh, text Trunk TV is the website.
They're also on the YouTube text trunk tv, YouTube, and I think by the, well, hopefully by the next show, our Textron tv OTT channel will be up, so you'll be able to catch it on Apple TV and Roku and Amazon Fire, as well as mobile apps. But until then, this is Alan Shiel, Luca gte. I hope you've enjoyed the show.
Take care, everyone. Thank you, Alan. Bye.
Bye-Bye. Thank you everybody. Hey everyone, it's Alan Shimmel, CEO of Techstrong.
Thank you for joining us on our, I think it's eighth or ninth annual Predict conference. This is where, you know, some of us put our necks out on the line and make some bold predictions about the year to come. And maybe sometime at the end of, next of the end of this year, we will go back, revisit this and see were we crazy or did we know what we were talking about?
This is a keynote panel for Predict This year. We have a whole day worth of predictions coming from, from really smart people. And this panel's no, no different.
I've got some really smart people, much smarter than me to talk about what is the future for DevOps and DevSecOps. What are the big stories to watch in 2025? com 10 plus years ago.
But DevSecOps burst on the scene and a lot of it's become a real thing as you're going to hear from our guests. But there's also been a lot of changes, a lot of turmo in the last year, year and a half, as things like AI and platform engineering and software supply chain security have all kind of burst on the scene. And it's, it's pushing and pulling DevOps in ways we probably didn't imagine.
Our panel today is a great panel to discuss these topics. Let me jump in and introduce them to you, first of all, joining us, and we recorded this and he was kind enough to come on late in the evening. His time is my friend Kobe Reer.
Uh, Kobe is the CPO at check marks. Kobe, welcome. Why don't you give people a little bit of your background, though?
Yeah. Uh, thank you Alan. Uh, really glad, uh, really glad to be here.
I'm the Chief Product officer of, uh, of check marks. I'm leading, uh, within check marks. I'm leading, uh, um, engineering, uh, product management and security research, uh, for the last four and a half, four and a half years.
Um, I am actually leading the, the, the, the building, uh, the development and building of our, uh, check marks one, uh, platform. Um, our legacy product is an on-prem product, uh, and we completely shifted to the cloud and this is what I'm happily doing. Absolutely.
Thank you. Thank you again for joining us, Kobe. Appreciate it.
Next up is another friend of mine who's a frequent, uh, visitor on our tech drunk TV show. He's Nick Durkin Field, CTO Harness. Hey, Nick, why don't you tell, introduce yourself a little bit Very well, and thank you so much for having me on.
Genuinely appreciate it. And, uh, look, uh, joined Harness is employee number nine, almost eight years ago now. And so watch it grow from, you know, a small, uh, startup in its alpha stage to, to now helping the largest customers in the world solve secure software delivery and, and leveraging ai.
So glad to be on here helping with this, uh, phenomenal panel. Fantastic. And thank you for being here, joining us as a newcomer to our Techstrong TV and tech strong event family, but certainly her company is no stranger.
It's GitLab. I wanna introduce you all to Sabrina Farmer, who's the Chief Technology Officer at GitLab. And Sabrina, first of all, welcome.
Thank you for joining us. I hope this won't be the last time you, you, this will be a good experience for you. We'll see you often on Tech Trunk.
Why don't you give people a little bit about your background? Yes. Hi everybody.
I am Sabrina Farmer. Um, as you say, I am the Chief Technology Officer at GitLab. GitLab is the most comprehensive AI powered DevSecOps platform for software innovation.
I have been here for almost a year now. Um, prior to that I spent 19 years at Google doing essentially production engineering and also infrastructure engineering. Um, really happy to be here, excited to talk about what's the future.
Thank you. We're excited to have you here, Sabrina. Thank you.
Last but not least, my friend Paul Davis, who's field CSO at what a collection we've got Field CTO, field, cso, chief Technology Officer, and CPO. That's, that's impressive. Paul, why don't you tell people a little bit about yourself.
So yeah, really humble to be part of this. Uh, this panel is brilliant. So it's a real power players here.
Um, so yeah, I am a former Fortune 10 CISO slash soc ir, but also as described myself, I'm a reluctant developer, uh, programmed and had software houses and built software in 12 different languages. So I'm sort of melding that with business risk and everything to help, you know, push forward the vision of a secure software supply chain using jfr and integrating with many of the colleagues here, as they say, to create that secure software supply chain. So very much sort of focused in that area.
So thank you. Thank you Paul, and thanks for joining us as always, and thanks to our friends at jfr. So, you know, guys, as I said off camera or before we started, those who don't learn their lessons from history are doomed to repeat it.
2024 in 20, the last half of 2023 has certainly seen some churn, upheaval, tumult within the DevOps DevSecOps space. Um, if I had to ask each of you, what were your, what were your big stories or big trends in 2024 that we think we should look ahead to going into 2025? What would you say they were?
Sabrina, you are the newcomer here, so I wanted to give you first, first dibs. What do you think were the big 2024 trends and stories that we need to learn from in order to look ahead? I think, you know, obviously the big topic, what everyone's talking about is ai.
And I think over 20, 24 people were trying to figure out how to roll it out. What does it mean, what does it change? Everyone thought they needed it, but they didn't really know what to do with it.
And I think there was a lot of experiments, a lot of be spent, um, and a lot of lessons learned. I think what I, I'm excited about mostly is as you come to the close of the year and agents become something that's more of a reality, you really see the opportunity to apply AI to improve how people work, right? And I think that it took us a whole year to get here, um, and to really start to believe that it was possible.
But, you know, we are seeing people look at not just how to develop code, but also how do you operate the systems that you're building. And, you know, having worked in production engineering for so long and, and AI for, you know, even longer, um, I think that to see this reality is really exciting and really trying to get people to really embrace it is, I think what we have to look forward to next year Panel. What do you think?
Wow. I mean, ai, I think myself personally, it's, I'm starting to see glimmers of hope. Um, as a security person.
I'm a pessimist and paranoid. Um, so, you know, there are gaps there that I, that I, I wanna see better AI in the world of the actual supply chain as opposed to just the developer experience. Mm-hmm.
But I'm seeing now some of those coding agents helping developers and getting to a point where I can start to trust them. Um, but there's still a long way to go. And I think also from the perspective of regulations, I think we're just starting to see inklings.
Europe is scary because they put teeth under regulations. Uh, I, I'll be blunt, I think we need to do that in the US as well. Um, 'cause there's accountability across the board.
But I, I'll pass it over to Nick. Fred, I don't wanna hog the mic, but my Nick, for your perspective. No, I, I can, you know, I think you're right on the AI side, I think one of the things also we've seen is that we've seen people now unifying on singular platforms and getting away from point solutions.
And I think it was one of the things that we actually talked about last year, Alan, yeah. Uh, was this was gonna happen, that people are actually starting to unify on platforms and they're, they're getting away from, from, from grabbing all these point solutions. And I think that was something we actually saw.
And, and to good measure, right? We saw people actually gaining a lot of value, gaining velocity, adding security into this, because now it is one, one platform versus, you know, having to bolt and spending the time, you know, bolting together and writing the glue code versus actually being part of A platform. And Kobe, that's check marks one, right?
Yeah, exactly. That's check marks one. We, uh, I fully agree, uh, we saw a lot of consolidation, meaning, uh, people are kind of do not want to run point solution, have multiple vendors, uh, get themselves and their, uh, developers and users, uh, and security people, uh, confused with, with, with all them.
They want to, they want to consolidate. So we saw that we actually, this was one of the, uh, main objectives of check marks. One, have a OneStop shop for, uh, application security testing.
We also connected it with a runtime in order to provide runtime insights. That's actually changing the way security is done on, on the left hand side in, in the pipeline. Because you can give, uh, you can give runtime.
You, you can, you can provide runtime context and then give more actionability and confidence in the results, uh, because, you know, it's, it's running in in right time. Uh, I also agree with Sabrina, like ai, like 2024 was the year of, uh, okay, what do we do with ai? And, and, and I think that it's, uh, you know, I think that that, that, you know, a lot of our customers kind of came to us and say, okay, we know that we need ai.
What, what do we do with it? So we kind of, uh, we kind of, uh, put in place, uh, um, a strategy of, uh, protect, um, and we're protecting the code, uh, mainly on, on the developers side. We have integrations with, we, we have like integration with, uh, uh, with copilot and, and, and tools like that.
We also have a tool of our own, which, which actually provide best security practices as, as code has been written. Remediation, okay? We're talking about pipelines.
We don't want to run the, uh, we don't want to run the pipelines 10 times until we get the, until we get it right. So Remedi, AI, remediation advice, and also secure lms, this is more of a 2025 thing. Uh, you know, we see people going more and more into open source lms.
I think that this is going to be the next big thing in 2025, and people would like to, to protect that. And a lot of supply chain, by the way, uh, we invested quite a lot of supply chain, uh, especially in malicious, okay. Kind of the SCA part is, is kind of figured out, but the malicious part isn't, uh, isn't meaning let's say if I'm taking, actually, if you use an open source, you're actually taking code from stranger.
How do I know that this stranger didn't put anything malicious in it? So kinda, we invest a lot of research in that and, uh, we're trying to bring this value to, uh, um, to, to customers. You know, what's interesting is, at least two of you up here, your companies are open source companies, right?
And so you're not getting code, you know, is it, is it from strangers? Yes. Is it from, it, it, it's not so much from strangers, but perhaps untrusted sources, right?
Especially if you are maintaining a, a, a, a repo like Artifactory or something. But I wanted to return to AI for a second because that is the big, I think when, when people look back five years, 10 years from now, 2024 will be the year AI went big. It, it dominates.
But I think also when we look at 2024, it'll be the year that Gen AI went big gen ai, right? This whole, the idea of the copilot. And I think all of you have some sort of copilot type of functionality built into your products now or are coming out with them.
But I think when we look ahead to 2025, gen AI may not be the big AI story. I think, Sabrina, you mentioned it, AG agentic AI may wind up being the real story, not just for 2025, but going forward, I totally agree with that. Yeah, I totally, I think that's really the power.
I think, you know, the press likes to talk about the code, the developing the code, the code aids, right? And I think that's true, right? But ultimately, that's still up to the software engineer, whether they accept it or not.
I think it's really the agents that are gonna unlock the power and really help us find the next opportunity. Free up your people so that they're really thinking about the next innovation that we should have. I have to say, I'm pretty surprised at how quickly AI has gotten into the DNA of not just tech companies, but the average user.
They're very comfortable playing with it. I think that's surprising. I do think with large LLMs really made it accessible.
And so I think we'll see this accelerate a little bit more in, in how people learn how to commercialize it. But really, 2025 is gonna be about the agents and how people put it to use. And I think to Paul's point, like the regulation is coming, right?
Compliance is not getting easier. You can't staff fast enough today because one, this technology's really expensive. Um, and so I really think this is what's going to unlock the power of what AI can do for companies and the users.
Okay. If I could go ahead, Paul. I was just gonna say the, the, I as a geek as a techie, um, agentic AI is really, really exciting for me because I've always won.
I, I, I have a personal assistant, people know me. I wear little gadget on my shirt. This is my personal assistant, it's an AI agent, right?
But it's, I don't trust it. But the thing that I get scared about is, um, I think we could see us repeating the same mistakes we did with ai, with agentic ai. This same acceleration path is coming along where people have false expectations around it, have these grandiose ideas, and the reality becomes, ooh, actually we need better controls about, we can't trust it.
I remember in one situation where I was doing automation and one particular customer shut down everything because they managed to do a self-inflicted denial of service. Mm-hmm. The agent ai, letting it make decisions by itself scares me.
Okay. I'm it, I'm paranoid, but I, I think I, I, you know, as you said at the beginning, Alan, if we don't learn from history, we're gonna make the same mistakes. I think we need to apply the same disciplines we talked about.
Like, um, LLMs being weaponized, I'm good marketing, weaponizing, LLM sounds ho exciting, um, malicious. Um, but, uh, from the perspective of we are now realizing that the data scientists are developers and are being targeted, and that the, the, the models, the ML SecOps model needs to align with the sort of the traditional SecOps. We also, and we are learning disciplines and stuff like that.
And so I'm sure everybody in this call is saying, but I think we need to basically make sure we, we apply some discipline. We don't set false expectations. And I dunno whether people agree with that, but I'm a little bit concerned that I have high expectations, but I'm cautious.
Others might read that magazine and go, oh, let's do this. And we lose control. I have A, I have a fun take on it a Little bit.
And, and by the way, like this comes from, you know, when Harness came out to the market, actually in 2018, we came out as the first software platform using AI to actually remove the worst part of people's jobs. And it wasn't about taking the best part, we didn't go after coding because that's what people loved. We went out after all of the things they hate doing.
So babysitting, deployments, waiting for tests to run, all of those things. And so what's interesting though is, you know, a lot of people talk about agentic AI actually mirroring human behavior. And I actually think this is, is actually opposite.
I think we are actually going to mirror agent behavior. What we're gonna do is we're gonna empower people to do what they love. I know that's the weird one, right?
But the reality is each one of these agents dives down and does something specific, right? But if we're focused down on what we hate doing, right? And all the things that, that, that, that, uh, are the things that we put off till tomorrow, let Theis do that and now spend our time focusing on what we love.
When you get someone who's locked in doing what they're passionate about and not having to focus on writing a terraform or a groovy or like working on all the extra pieces, let them do what they're phenomenal at. Now we're actually empowering our people and it actually brings harmony amongst all this, as opposed to like having to be combatant. So I think it's, it's a huge future.
It's a huge opportunity. Um, and I'm really excited about what we're, what we're seeing in the agent AI space as well. I think that the main challenge with Agent AI will be to manage all these agents.
Yeah. Yep. You know, you'll, you know, you will have, like, you know, you have an LLNI dunno, tens, hundreds of agents, you know, each developer will put in what, what, what each one of them do.
And, uh, what, what do we, the, the sequence of of of, of what, of what they're doing. I think that this is The, well, you're just thinking about one developer to many agents, or one, each developer has their own agents. So you have many developers.
One happens when one developer has 10 different agents, right? Mark Benioff, uh, spoke, I think it was just yesterday or last earlier this week. Well, by the time people watch this, it was a few weeks ago, you know, and he said, we're all gonna have all of these virtual employees, he calls them that will, you know, we may have thousands of them that are out there doing tasks for us.
Some, some agents will be one trick ponies, right? They'll do one thing, they'll do it pretty well, but they only do one thing. Other agents will be more general agents that are kind of alter egos for our digital presence.
Other agents will be managing agents, you know, agent managers of other, I mean, the, and I I imagine to yourself, just to troubleshoot an issue that comes from customer. Yeah. I, that group, group was between all the, okay, what, what kind of, what, what the hell is going on here?
Uh, But I mean, this is, this is a, this is the world. We could be looking at it, and we need to, we need to put some order, some order in here, right. To, to, otherwise it's gonna run amok.
I dunno, if any, I think Kobe, oh, sorry, Sabrina, go ahead. Please talk. Yeah, I think Kobe makes a really good point, right?
If you really wanna think about, um, unlocking the power, you should also think about the management of all of these things coordinating together and who's gonna create the controller for this, right? And to Paul's point, like you still need the oversight, right? Automation has, you know, I've been automating production systems for a long time, and I can tell you like, you can shoot yourself in the foot just as well as an agent could.
That's not, that's not new really. I think it's just a new way to look at it. Um, but I think that Kobe's highlighting a really big important thing for people to think about as they start creating these agents and automating them, is you do need to figure out how do you coordinate all these things together.
Um, I I, I agree. I it's gonna be interesting. And I'm not even touching on the security implications of having agents running all over the place.
This is why, this why I talked about control, not even secure. Yeah. It, it, it, it is.
But on the other hand, I mean the, the, the things that it opens up the, the possibilities, right? Are pretty exciting when you, when you really think about it. And then, you know, and Benioff, and, and granted, he's a great marketer, right?
Give the man credit where credit's due. He is one of the best in terms of marketing. But when he refers to these agents, he interchangeably uses the word robot.
Is an agent a robot? And is, is a robot something that does physical task or is it also just a digital robot? Right?
And, um, and, and once we start marrying AI to robots, what, what does that mean for our, the way of life, right? Uh, I mean, it's, it it's a brave new world in many ways, right? That, that this, And in some sense, you know, bots are kind of the same concept of agents.
Okay. Kind of. I think, I think that's what he's getting at.
Yeah. We, we, we did have it, like we did have these software bots, but I, I, I think that, that the kind of the options are, are kind of the, the, the limit is the sky right now because be, be because of the, uh, gen ai, which is behind it. Uh, Everyone could be.
I, I think you're gonna see an actually, an interesting turn. I think you're gonna see people overuse LLMs and overuse agents where they're gonna use these massively expensive things that, that, that do very basic tasks. It's back to the times when like people's, you know, like using this massive amount of ai when in actuality you could just be doing math, right?
So instead of doing creative, uh, AI do Automation, well, that you point up is a bunch of wally just fat corporal people on chairs and, you know, the ai, we can't do math without a calculator, Right? I I, yeah, I, I think, I think people actually have to focus and realize, like, do we automate this? Do we do predictive modeling?
Do we use generative modeling? Like, and actually using the right tool for the job. 'cause I think right now, people are just throwing everything at, at Gen AI right now and, and calling it good.
But in reality, that could be two lines of Java or two lines of go instead of a massive LLM. And I think that's, that's some of the challenges. Well, well, you remind me of, uh, uh, I, I've met, uh, one of the DevOps leaders, uh, a few weeks ago and told me, you know, my job is to watch as much Netflix as I can, meaning the automation dev should, should, should do everything.
So, uh, what what you said about the, uh, agent AI reminded me of that. Absolutely. So, I, I, I think, Nick, you said at the beginning, we should be using it for the, I, I like to say I want people to use to start using their brain, stop doing the boring stuff, right?
Yeah. Um, I think it's really fun that we're all saying the same thing, which is we need control. We need to set our expectations and roll these things out.
I remember when I was on a manufacturing plant, there was this one robot, physical robot, and it could make seven different models of car, brands of car without changing anything. It was so well-defined, but it still needed people at the end to just do the tweaks, to do the things like that. That was God, 15 years ago, right?
I think we got the same thing with this stuff. And I think I, I'm kind of reassured that we're all talking the same thing, which is we need to have oversight. We need set our expectations, because otherwise it will run rampant.
But the trouble is we will see people that are, um, like, um, setting their expectations the wrong way, you know? Well, I, I think that's the story. That will be the story in 2025, right?
E experimentation in excess in, in experimenting with this stuff. But you know what, just like in the real world, AI is sucking up our conversation here. We have do have a couple of other things we need to talk about.
One of them, I wanted a big, you know, I think a big emergence in 2024 was sort of the, the legitimate legitimatizing of the platform engineering space, right? And in many ways, I think platform engineering, first of all, it's not replacing DevOps, right? Yeah.
DevOps isn't going anywhere. But platform engineering is a response to DevOps, I think, where DevOps wanted to bust down the silos and have us all working together. That was kind of the original intent, right?
And what it, one of the outgrowths of that though, is that we just started shifting everything left. Give it on the developer, put it on the developer, put it on the developer. As I mentioned earlier, things we put on the developer was security.
I think we found out that they care about security, but they're not security people, but they wanna develop secure code. Another thing we put on them is build your own platform. They don't wanna necessarily build their own platform.
You know what, maybe having a silo for platform builders is a good thing, as long as they communicate with all of the other stakeholders, developers, testers, security, SRE right? All the, the traditional disciplines in there. And so we saw this whole platform engineering kinda concept rise.
And I'm glad to see that in speaking to most of you, your companies are embracing platform engineering. It's no longer, uh, if us or them, it's, we're in it together. Give, if you wouldn't mind let, well, Sabrina, we started with you last time.
I'm gonna start with Nick this time. Let's talk about how do you guys view platform engineering, especially going forward here in 2025? Sure.
I think you, you made a good point. And then the way we actually referenced it, when we talk about shift left, people started shifting, the workload left. And that actually wasn't good.
And what we actually want is we hire really smart people and wanna shift the information left, give them the information, give 'em those, uh, results. The security scans now, not when it's in production and they have to go, you know, get in a backlog, give them cost information now, right? Make sure they understand what that change the infrastructure is gonna do now, not a month later when it gets into production.
So it's about bringing that information at the right time. It's also about making it easy to do the right thing. And it's about making it hard to do the wrong thing.
And I know that sounds super basic, but it was easy to do the right thing. The cloud wouldn't exist 'cause we would've made VMs in our company, right? So you make those easy paths to get people to production, make it extremely simple.
But you put policies in place to make sure that everything that you're doing actually meets your security, your compliance, your regulatory rules. And as a platform, the goal here is actually to create harmony amongst all these teams. Like, although the folks on this phone or on the, on this call, we actually integrate with, right?
Because again, you have to, and what we do, what we don't wanna do is we don't want to have security being the team of, no, they should be the ones empowering us by writing the policy. We don't wanna be financed to be the ones of no. And in cost, you know, coming back with a big stick and a carrot, empower them to write that, to make sure that you're, you're meeting a budget, make sure the DevOps teams can write the pipelines, but we're all doing it in harmony.
So now it's an actual platform of bringing people together. If you're buying a tool that's a stick to use to beat a different department, it's the wrong tool. It's not the platform that you need.
You need something that brings harmony. That's, I know it might be like a little controversial. Mm-hmm.
And, and maybe a little hippie. No, I, I, that's genuine. I think It goes back to dev, that's DevOps, right?
It's about working together, not necessarily that we all, all of us become DevOps engineers or DevSecOps engineers, but it's about, we all have our thing that we do, but we work together. So I I'm, I'm, I'm with you. Rest of the panel.
What do, what do you guys gals think about, about that? The, The, uh, sorry, did you wanna Go ahead, Kobe? No, no, go ahead.
So the, the thing for me is, is you're right, it is, um, bringing together the teams. We have a lot of siloed, I've heard feedback that the data scientists don't trust infrastructure people to stand up the infrastructure in, in production. Partly because it's a brand new world.
It's, it's in, it's not just standing up a server. We have to have additional tools to see drifting, uh, compromises, new attack forms, et cetera, coming in. So the whole thing, we actually came with a term called every ops, because you know, there's DevSecOps, DevOps, machine ops, ml ops A just goes on, I know Saprina, you've got SRE, there's all this stuff and everything.
But it rarely, I, I like it because I spend a lot of time working with customers, getting them to overcome those barriers and unify them. So we talked about security. I'm sorry, Nick.
I convert developers into security people, right? Okay. Bad.
In fact, I already disrupted. We were at Cube Con and this poor guy is sitting there, uh, we're having a drink. And I said, you know, you're a security person.
And he went, and by the end of, he says, I hate you, but you're right, because security is everybody's responsibility, but it's not the no thing. It's not the thing. It's about enabling and understanding the implications.
And we talk about streamlining that ability to create a, a, a, a visible view of everything that's going on, and understand, leveraging each other's expertise to create a pipeline that's streamlined, fast, secure, safe. I know I'm I ideal, but that's what we want, isn't it? Right?
Yeah. Because that's gonna protect our big customers businesses. But that model of every, we gotta stop the silos.
And I think for a lot of the leaders, the CISOs and the, the CTOs, the CIOs, there's gonna be change. Right? Kobe, I saw you get a big smile on your face when Paul said that we've gotta convert them all into Security people.
Yeah. You know, we, we built a platform like in the first place to be kind of unite everyone, like security people, developers, uh, developers, uh, et cetera. Um, kind of the, the use cases that we see now that, that kind of customers are interesting in is, uh, how to save DevOps people's time and also developers time providing them a new experience through the platform.
For example, uh, you know, there was a kind of a discussion if developers or security people, or not kind of, uh, through platform engineering, you can actually reach a situation, kind of that everything is being done automatically, uh, you know, automatically. And the developers is actually, uh, we just show him a, a Jira case and tell them, okay, you need to fix this, this, and this. Okay.
This is kind of a, a kind of a platform engineering together with, combined with, with a bit of, of ai. So kind of, it, it saves time. It, it also provide different experience and it also eliminates mistakes.
So kind of the, these are the main three use case that, that, that we see now of kind of what kind of our customers and design partners want, want to use, uh, the platform engineering for. I think I agree with what everyone has said. I think I have a little bit of a different take.
So I think platform engineering has always been something that people would argue is a good thing. It was an ideal, but in reality it was an idealistic state, and it was never like a high enough priority to do because people were like, well, I'm gonna choose best in class and then I'll figure out how to integrate these things together. And, you know, so we'll delay that idealistic viewpoint.
I think maybe what's changed on why platform engineering is such a highlight right now is that there is so much regulation coming. And so all of these integration points that we have done for probably the last decade, because we wanted to choose best in class, and that ended up with many, many solutions that we then tried to tie together. If you have to do something like GDPR, all these integration points are now a risk to your business.
And I think as business leaders, that's why platform engineering is such a buzzword right now and why people recognize that. Like you need to have an already existing integrated platform. So as we meet our requirements for the different regulations and all the compliance that we are being held accountable today that maybe didn't exist five or 10 years ago, platform engineering helps you unlock that and actually reduces the risk for your business.
And I think that's why it's so popular today, this collaboration. It's actually just an added benefit, much more so than the driver today. Sabrina would, would you say, so I've had some people say to me, the platform eng, the platform engineering team is actually an oversight team.
It's almost like a platform architecture where they've got the full visibility across the whole thing, and they're guiding and being the focal point for getting the groups to work together. Does that resonate or not with you? I think that's how, um, people defined platform engineering in the past, right?
They plug all these things together. You'd have your SRE team that SRE team would manage all of these different integrations, and then they were the oversights committee. I don't think that is sufficient going forward, right?
I think that breaks down very quickly. Um, I think that's very expensive way to do it. And true platforms reduce your cost of ownership, right?
And I don't, I think that's something we didn't pay attention to for a long time. But in the current market with the current cost of technology, that line item is actually, uh, not as, you know, available today. As the businesses are growing and the market pressure is there, Does that mean that should be part of the office of the CTO or part of Dev, or, I don't know.
I'm trying to work out how it fits Where it fits. Yeah, I mean, I think that varies by company. Yeah.
Right? Yeah. In today's world where the CTO is often the CPO as well and vice versa, or the CIO is also the CISO.
Yep. It really does vary. com, our newest site, and we have a new show out there that actually check marks is sponsoring with, that's called the Platform Engineering Show.
org, which has two to 200 to 300,000 members involved. So we're gonna be looking hard at platform engineering. I think the other big story is it's not replacing DevOps, it's part of this whole continuum, right?
Platform engineering enables DevOps, it enables DevSecOps, and then, and the only way it works is through open lines of communications with developers, with SREs, with DevOps teams, with security tips, right? And I, I think that's the important thing to remember, guys, we've got one more subject and not a lot of time to do it. And so I wanna get it up there.
We, we touched a little bit on software supply chain and software supply chain security. So I, I gotta disagree. We haven't solved the open source security issue.
I, I, I think this is just like a, a snake that keeps coming up and biting us. Um, what makes you think 2025 will be any better? Or will it?
Paul, we haven't started with you. Let's start with you on this one. Wow, that's a hot one.
So, uh, so I mean, securing the supply chain, I think it's, it's, it's be, it's, it's something that now that the executives are starting to realize, it's important that they're accountable for, they, you know, just like, um, a friend of mine was saying about Sarbanes Oxidative as best to sign off, supposed so as best to sign off on supply chains. It's gonna happen more and more. But I think, I think we're still getting there.
I think it's not, it's, it's, we still got a long way to go, I'm afraid to say, because, um, I'm still, we talked about streamlining, consolidation, getting, you know, that traceability, um, and that sort of thing. For, for us to have a secure supply chain, we've gotta see everything as it traverses through, um, through its lifecycle of getting into production, um, securing that and getting everybody, you know, uh, platform engineering, uh, and sorry, Sabrina, I think it's critical and I think it does need to be a focal point. 'cause it's gonna be the one place that can push that story together with the security team to get that going through.
But in 2025, I'm hoping that we are gonna see some new tools, which will help with that consistency and that traceability. I think we still have a long way to go because I'm still working with customers and organizations who are still struggling of trying, just, just trying to consolidate their tool sets. I spend a lot of time on streamlining exercises.
So from that perspective, I, I'm hopeful I see progress. I don't see all the answers being ai, I'm afraid. And in fact, in some conferences, I dunno if you've, it's almost like it's a groan.
Oh, somebody's doing a presentation on ai. It's like not enough one, you know what I mean? Oh, I live it.
Yes. But I think standardized processes, maturity, actually tying it to better metrics beyond developer velocity. Um, I always thought talk about the ripple effect.
When something goes right, it has a beautiful effect across the whole organization. When it goes wrong, it has a, a ripple effect that hurts everybody. It's not just there, it's not such security.
It's not just infrastructure ops or whatever. Everybody gets impacted. And I think I'm hoping, and, and I'm gonna be pushing to get different metrics in place so people actually understand the impact and the positive nature of supply chain beyond just getting product faster onto, into, into production radical, I'm sorry, Fair Panel.
I, I think that in 2025, uh, uh, we're also going to go further down, further down or up in the chain, meaning go into the source and assess how trustable it is. Meaning like, is the repo that I am taking something from, how healthy that is, the contribu the contributors that are contributing to, to the open source that I'm trying to fetch how, kind of, how reliable they are. 'cause up until now, we kind of, uh, we mainly focused okay, on taking a piece of, of something, a piece of software.
Uh, is that specific piece of software, is that, uh, is that, uh, a healthy one or not? I think that we're now going to go kind of one step down in, in the chain and, and, and again, and assess how trustable the source and the contributors to that source, uh, are we, we act have a, uh, I'm not supposed to mark it, but we have a solution that acts like a gateway between the public repos to stop the bad stuff coming in. Um, the real challenge is getting the developers to say, go through this way, go through this way to the, to, to get you to your repos opposed to going direct.
Like, don't go home, install the package and then come back, sort of thing. So there's a lot of, there's a lot of challenges about that enforcement and trying to explain to the developer what you gonna save them time, uh, save them time and money and let them spend less time fixing bugs and more time. I mean, there is still people downloading the wrong log.
Four j Well, Struts two and Equifax, this is a common, how do you stop them from downloading old vulnerable bug ridden bad components. Sabrina, I saw you shaking your head though. I wanted to give you a chance.
I mean, obviously, you know, we get hundreds of external contributions into GitLab. It's amazing. People ask me a lot of questions about that.
And you know, look, just because all of your contributors are internal does not mean you don't have risk, right? It's just sort of like if you had a firewall versus not having a firewall. If you're behind the firewall, you're safe.
That's not true. That's never been true, right? We've learned the hard way that that's not true.
I actually think sometimes the number of eyes who are on open source, right? And like checking for that and looking out for that is much more powerful than what you might get. Um, if you're all hidden internal, like having worked for a very large tech company for a long time, not all teams are the same.
They don't all ha make the same assumptions. So even when you're integrating inside your corporate walls, you have the same kind of risks. You need to be on the lookout for that.
You can get malware into your system unknowingly. What you, what you really need to have is like, you need to have policy controls, things that are enforced that are automatically looking for that. So if your employee does do it, it's not like, Hey, you broke the rules.
It's like, Hey, we just stopped what you did. That cannot be integrated into the system we are watching for where this is going. And that's, again, back to the platform.
Like the platform can enable those things for you. Yep. Because it put, all your system is all plugged in together.
You can look at everything at the same time. And I think that's how you wanna think about it. It's not open source or internal.
The risks are the same for the both. One has consequences, right? 'cause you, they're your employee, right?
You have, um, you can do something about it, whereas the other person can't do anything about it. But actually it's the same problem in the end. I think, uh, I think this falls on that same thing that I was saying earlier, which is make it hard to do the wrong thing.
And if you put in all that policy in place, like you said specifically, like that's, that's why we build open policy agent into harness. So you can prevent any one of these, right? Make sure that every piece of code is scanned.
Make sure that every piece of code doesn't hold that MIT license. Make sure that it goes through the appropriate measures to block things like a log four J but also make sure that it has salsa attestation. So it's gotta a bill of materials.
You make sure you're there, but you actually know that it's the actual artifact you're using so you don't fall into like a solar winds attack. And so now the actual attack vector has grown from just the artifact, just the code. But now to your point, this is why the platform's so important.
This has to be from source code, from the build, from the deploy throughout all the systems. And it's not even just about validating it, finding it, checking it. You're going to have that zero day now how to remediate it.
So that platform should know what you deploy on which infrastructure with which configuration that were secrets to get you back. Or more importantly, as you update those, uh, artifacts or you, you change those libraries to promote them out to production again. And so getting you remediated quickly so you don't struggle with those.
And I think this is truly where when we start automating all those things, and it gets us back to where we were, like we start taking that burden off of people, uh, and actually focusing them on the areas. Now, each one of those teams can do what they're great at you. You empower it.
And what's really scary here, you know, the government is actually the first ones who did this. Well, there was an executive order that forced this that said, Hey, you have to have a bill of materials. You have to have an attestation that proves it.
And this is one of the first times we've seen our US government actually leapfrog and actually leave the, the, the public sector behind. And we've been working with those enterprise customers on that specific problem for years now. And what we're seeing this year, and I think as to get it back into predictions in 25, you're seeing now actually all these, you know, public companies catch up to, we need to have this secure.
We need not only for our own software, but to your point, even the people that are our vendors, uh, the people that are co contributing. It actually, it, it, it builds trust amongst the entire community Agreed to Sabr to Sabrina's point that, uh, in internal, you know, internal code is also, uh, not, not secure. Like we have a whole concept of what we call price packages.
Not open, not not only open source bag, meaning packages that were actually developed within, within the, uh, within the organization. And we treat, we treat them. If we treat the same, they're potentially malicious Open source packages.
Yes, absolutely. Guys, we are outta time. I wish we had, as I said in the beginning, twice as much, three times as much.
We could talk about this all day. What ma? An amazing, amazing panel.
Thank you all. Nick, Paul, Sabrina, Kobe, I, I honestly from the bottom of my heart, thank you so much. I hope you guys out here watching this have enjoyed this panel.
Um, all four of these companies and these folks are kind of frequent guests on Techstrong tv. So watch for them throughout the year. Um, we have a lot more lined up here for you today on Predict 2025, including the winners of the DevOps Dozen awards we'll be announcing.
So for on behalf of everyone and, and here at Techstrong, I'm Alan Shimel. Thanks for joining us on this great panel. Stay tuned for a lot more here at Predict.
Hey everyone, like the old Motown song, where the IT jobs are, you're watching Textron Gang. Hey everyone, happy Monday. Alan Shimmel here from Textron and we've, wow, what a weekend.
I hope you guys had a great weekend. I had a great weekend. Um, got to enjoy some of that South Florida weather a little bit.
So good movie. We could talk about it, but you probably don't want to hear. Um, what you do wanna hear about is what we gotta talk about today.
And I mentioned we're gonna talk about where are the IT jobs. We talk a little about SoftBank and open source, LLMs and cybersecurity. Oh my.
Um, let me introduce you to our gang on this fine Monday morning. First of all, uh, he's the newest member of our gang, really. He's from, he's, he's genuinely from Austin, Texas.
Uh, he's a good friend of ours. He can tell you more about himself, but you know, some people call him R two R squared. Big Lebowski, though.
He's not wearing his sweater today, my friend Robert Reeves. Hey, Robert, how are you man? It's good to see you.
I'm doing well. Yeah, it's, uh, it's, it's getting a little warm for the sweater. Um, and yeah, just super excited to be here.
You know, I'm always passionate about developers, open source and, uh, creating jobs through startups. Uh, those are the three things that I care the most about. Good for you, and I know that firsthand.
Welcome. Moving on from Robert. I feel like I just introduced her, but that was probably that, uh, webinar round table we did yesterday, right?
Or last week actually, my time goes. She is the CEO of Deploy hub, open source defender extraordinaire, board foundation member on several, our friend Tracy Reagan. Hey, Tracy, it's great to have you on.
You as well, Alan. This is gonna be a fun one. We have Robert here.
Yes, he, he'll keep it moving. And then finally move, moving up to, uh, upstate New York where he's still waiting for the Yankee season to start. He's our, uh, chief Content Officer from Mike Ard.
Hey, Mike, just a few more days. Approximately 80 hours. But who's counting?
Yep. Yep. Who's counting?
Alright, guys, let's kick this. Fine. Monday off with a recent article was over in Techstrong, ITSM about, uh, mixed signals on the, uh, tech role or tech job front.
You know, I have a lot of friends who for the first time in their lives, they're not finding easy pickings, getting new jobs. I probably had three or four people write me last week alone if I knew of any, um, roles open. Good, good people too.
Mike. What, what's going on here? All right, well, let me set this up a little bit.
So, CompTIA, which is this industry association, does this regular analysis of statistics provided by the Department of Labor related to IT jobs. Now it's the Department of Labor, and we all know that, well, there could be some given those numbers, but they're showing that there's an uptick in jobs of about 177,000. Not all of them are in big tech, though.
And so, um, that came out. And same time, Washington Post has a article noting that those same statistics, which suggests that, uh, 25% of all programmer jobs have disappeared, but they made a distinction between programmers and developers. And programmers are people who code, and developers are people who actually create applications.
Robert, I know you've looked at all these stories, and I, and I know you've been close to this topic for a while, but what the heck's going on here? Well, I, um, thank you, Mike. I mean, look, the, you know, that Washington Post article about the distinction between programmers and developers?
Um, uh, you know, there was a little bit of clickbait to that title, certainly saying that, Ooh, is this the first, uh, bit of evidence we have that AI is destroying, uh, computer programmer jobs? Um, and yes, there was a dip. Um, but, uh, you know, one of the things that, uh, really jumped out at me in the article was that, I guess paragraph six or seven, it starts talking about the advance, the advancements prior to ai, um, around DevOps, cloud native, open source.
You know, these are things that, you know, certainly, uh, uh, Tracy Allen and I are, are at fault for, um, because this increased, uh, productivity for everyone in, uh, software. You know, I, I think that it is way too early to start doing the chicken. Little sky is falling stuff about ai.
Uh, I'm reminded of the, um, you know, a, a story in Willy Wonka, the new one, uh, not the original. Um, about, uh, the, you know, Charlie's dad loses his job at the toothpaste factory because he was putting caps on tubes of toothpaste. Of course, you fast forward to the end, unfortunately, I'm doing a spoiler here.
Hope you've seen it. Where he gets a job, uh, repairing the machine that puts the cap on toothpaste. Um, I do think that there is going to be a massive shift in how we built software, and we really don't know where this is going.
The good news is, is that we've seen these massive shifts before, whether it was virtualized machines, containers, DevOps, uh, and now certainly with ai, um, we have an opportunity as an industry and also as individuals to improve our skillset. Um, but we are still, you know, our more technical minded folks, our programmers, uh, are still going to have a place to be. It's just companies right now after a massive hiring boom, uh, during covid, uh, it is just correcting right now.
Um, and also with some economic uncertainty, macroeconomic challenges, companies are just tapping the brakes. Uh, I think that's all it's edits. I don't know, Alan jump in here for a minute, but I'll add one thing besides that.
I mean, I just think a lot of folks are also getting better at copy and pasting stuff so that they're not actually typing. So, you know, let, let's, let's, let's peel this back. The, the, the news here, and you see it running on your ticker, what does it actually mean?
Well, it, employment grew by 177,000. That means jobs that have sort of an IT title could be programmer, cis admin help desk, whatever, a network administrator. It could be anything related to it.
And it, and it, and overwhelmingly it's probably it in every industry under the sun, from healthcare to finance and banking, to manufacturing, to newspapers and media and everything else. It's not necessarily tech sector jobs, but they're tech jobs, tech sector jobs. So the tech community, the tech companies, right?
The kinds of companies that sponsor tech strong events, the kinds of companies that make the solutions. You out here watching this use, those companies had 11,000 and change fewer jo new jobs hired in February. So the tech center, the tech sector, the tech industry is hiring less people.
Tech jobs are increasing. So that, that's the, that's the dichotomy here, right? You like that word dichotomy?
Um, now what does it mean though? Well, I'll tell you what it means. And I think Robert and Mike, you're both somewhat correct, but let, really, what's going on here is the tech sector has been frozen by paralysis with analysis since almost the end of Covid.
They did go on a drunken hiring spree during Covid, they way Overhired. And then since then, they've way over fired, right? They've laid off, I forgot what the numbers are, but it's over a million, 2 million, whatever people.
Um, and it's not that the e economy is bad, right? If you look at the eco economic sort of indicators, they've certainly gone down since a certain person got sworn in as president, but they're not terrible, terrible enough where we should see less jobs and stuff like this. But what we are dealing with is uncertainty.
And I said it before, I'll say it again. Businesses don't thrive in an uncertainty. If you have an uncertain economic climate, an uncertain political climate, an uncertain socioeconomic climate, people tend to freeze up.
They tighten up. And that's what you're dealing with. People are, people are not sure what to do.
Tracy, you know, you read articles too, where people are now quite literally denigrating the employees in big tech, especially out in the valley. They're saying they got lazy, they've been pampered, they're not really good employees. And, and that's why we're laying them off because they represent the bottom 10 or 15%.
And yet, I think, you know, to Alan's point, it kind of smells like a cover up for over hiring in the first place. But I don't know, what do you think? Yeah, they're out there playing golf.
That's a reflection of somebody, right? But, you know, um, when I talk to my open source community, which gives me kind of a, you know, it allows me to keep my thumb on the sort of the pulse of what's happening out there. People are struggling to find work right now.
Um, and what I'm seeing is a pivot in skills. So they may have done less hiring, but there are job openings out there that they can't fill because they're asking for skills that have not developed yet, especially around ai. They're looking for the, this, you know, perfect AI developer candidate, somebody who's had five years experience in s and it's unrealistic, right?
And I've seen those, I've seen those job openings, and it makes me scratch my head and say, where are they gonna find such a person? So while I know that the there is, we are going through a pivot and skills, and there are less jobs out there. There will, we are gonna see more jobs opening up in these areas, but they're just gonna have different skill sets.
And the other thing that I'm seeing and ad hearing is it's so much harder to find work now because of the way hiring is done. Um, AI bots, uh, you know, that try to match resumes, uh, there's a lot of bias in them. Um, they, uh, aren't necessarily, the human has been removed, right?
The human factor has been removed out of the job hiring process. So we have a whole new world of how to find jobs, whole new world. Um, we, it was, it's, it was so prevalent in the community that the outreach community of the Ortel project has started a job seekers webinar program.
The first thing we did is we had a, um, individual, uh, to come in and teach us all how to update and brand ourselves in LinkedIn, because everybody's using LinkedIn profiles and developers, you know, they're not writers, they're not storytellers. So they struggle with, uh, with being able to brand themselves. Our next webinar, we're gonna cover, you know, what companies look for.
What are some of the tricks you can do on your resume to try to get a better match to the, uh, to the job Opening? To beat the Bots is kind of a beat the bots, uh, webinar. So I think that there's two things happening.
We're having a pivot in skills. People with, uh, with, you know, maybe if you, we are writing in Rust. Rust is becoming popular now.
You've been doing Python, now they're gonna be looking for rust developers instead of Python developers. Uh, and, and there is a, there is a slow down, no doubt there's a slow down in hiring, but I think it's gonna be temporary even with the current administration as cybersecurity becomes more important. And the, the private sector has to address this, the public sector's not, uh, and I think that AI is going to create a whole new brand of, of developers.
So we just have to wait and we have to get skilled up in the meantime so that we are doing smaller little projects. The Orillia project, I'm, I'm really gonna, uh, pitch to them that we should start building an LLM even if we're not gonna use it, just so they have some experience in doing it. Um, so there's a, there's a, there's many things that we need to do as software developers or programmers, uh, to make ourselves more relevant.
And that's just what we're going through. I'm suspicious of one thing though. We, every Monday we publish, uh, a post called Five Great DevOps Jobs Opportunities, right?
And so I spend the weekend going through all those DevOps listings, and, you know, on average there's like maybe 6,000 new listings every week related to a DevOps job. Now, some of those are duplicate 'cause somebody updated it or reposted it, but there are thousands of these openings. And what I have noticed though, is a lot of those openings are no longer in Northern California, but there's a lot more of 'em in other places, including Florida and Texas, and even New York.
And there's also a lot of job openings in places like Minnesota. And so maybe people actually have to go move somewhere that they're not in today because, well, that region is not hiring. I think that that's part of the problem, right?
We've had a mass exodus out of San Francisco, it's too expensive to live there. So now we have developers moving to different places. I mean, Santa Fe, I wouldn't have thought this would be a developer.
I thought it was where rich people went to retire, to be quite honest. And we have a, you know, it's, it's amazing the community that has come from California who has moved to Santa Fe, and many of them come from the tech business, and they're looking for re remote work no matter where it's at. So we, it's, we've gone through quite a shift.
I really do believe that. And I think it's gonna take some time to settle down. And you know what, the big tech companies have been holding onto cash for a very long time.
Let's admit that. Mm-hmm. Well, To your, they haven't done, they haven't done hiring To, to your point, just last week, I noticed there was a DevOps opening at Los Alamos National Lab.
So there you go. There You go. There you go.
Well, I will, I will say this. You know, whenever you have a shift in technology, um, you individuals can go and learn about that technology. Um, and certainly, uh, you know, Tracy, you know, having an LOM Intelius, I mean, I think that's great, just giving you the community an opportunity and seeing if it's gonna provide value to the open source project.
That's awesome. Um, but I, I do wanna caution people that are going to, um, seek to, um, look at where they are, kind of missing skills. Um, and I do think it's great to get familiar with maybe building, uh, some kind of predictive AI model.
I I'm working on one myself for sorting Lego bricks, uh, so that I can learn about this stuff. But when we're seeking to increase our skills, you are going to get more return for your investment by maximizing the things that you are already good at, um, and seeking to be the best in that area. Uh, if you are going from zero to passable with a skill, okay, that's good, but it's going to be very hard to become an expert in that area.
I think that you're gonna get more, you're gonna have a greater advantage by investing in areas that you're already an expert on and seeing how those skills can apply to things like ai. Um, and, and, but remember in, uh, both of these articles, uh, we did see soft skills, being able to speak, uh, have conversations. Those sorts of things are gonna be very important, have always been important.
And especially where there's more competition for jobs, uh, being able to have a personal connection with companies that you're connecting with, leveraging LinkedIn, uh, learning how to do that, uh, that is a skillset that is far easier to master than, say, building your own gen ai, uh, model. Yeah. In fact, in that point, um, one of the employers we talked to before we started the series, uh, said that out of 800 people that they hired, only 10% of them came from, um, you know, somebody submitting a resume, kind of a cold a hire.
The rest were from networking. Yeah, no, 90%. I've seen a lot of that.
And, and, and that's what people had. I, I'll tell you, last week, as I mentioned earlier, I think I had four or five people reach out to me, friends, good people who said, Hey, one was been outta work since the first of the year. Uh, one, just recently, one's still employed, but looking at to move along.
Uh, but basically they're not, you know, they're not getting the calls from the recruiters like they used to. And they're not just popping in with jobs. They're, you know, do you know anyone hiring in this?
Especially, I will tell you in Dere, right, dere has been decimated. Dere has been hit hard decimated. Yeah, it has Decimated.
Yeah. But let me just say one other thing. How many people have lost their job because of ai?
Anybody? I I, I'd have a hard time me thinking Me. I, I think people using that as wait For, for real?
Or because somebody wrote that in a press release. 'cause there's a difference. Well, I I meant for real.
Exactly right. How many people? I don't know of any individual because of AI nonsense.
In fact, the, uh, one of our, our kind of junior contributors, uh, he's been with us for three years, but he started, when he first started university, his first job was in ai. So it created a job for him, right? Right.
Outta school. I don't know. You know what I noticed over the years too, it's like, you know, people are getting hired because they go to a conference and they'll sit around in a table and they meet a couple of folks, and, you know, that's how they network.
And, you know, there always seemed to be like a lot of cross recruiting going on in any of these conferences. Ira went to, including all the ones from the CNCF. And it seems to me, if you need a job, the place to go is any of those conferences in person is a good place to start.
And, you know, the, in the universities in India, um, they really push their, their, uh, it, um, students to join a open source project because they tell 'em it's a good way to get project you, uh, real life skills. You've gotta work with the team, you're gonna network with, with companies. Some of these projects are led by the likes of Microsoft and IBM who have people in there.
If you wanna network from India with a US company, the best way to do that is to join an open source project and start becoming known. Right? And I don't see that coming from, I, I we hardly ever see students coming from, um, us uh, universities.
Never, ever. They never, there's, they're not there. And we, we always have a, a, a steady stream of students coming out of India who wanna get involved.
Hmm, Interesting stuff. Hey, we gotta take a break here on the gang. Let's come back and we'll move over to our B block today, which is, uh, SoftBank scoops up a, a, a company, I hope that didn't come out of the reserve they set aside to invest here in AI data centers.
You're watching techron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back. 5 billion.
Maybe chu change in the age of ai, I don't know. But, um, we don't know whether SoftBank, who acquired these folks, is doing that as to meet their commitment to the US or if it's part of some larger plan. But Tracy, when I looked at it, the first thing that did pop into my mind was, holy crap, we want a contract with the US government now.
We gotta actually do something about it. And so here's Ampire, but what's your take? So we all know that, uh, you know, chips are a big deal right now.
Um, and having more technology and more IP in the US around chip manufacturing is critical. We've talked about this before. We, it can't be all centered in Taiwan.
Um, I'm super excited about this story, though, not because of the chips. And the reason why I pushed to get this one is because this company was founded by Renee James, who I've been watching for a time. 5 billion.
Can we like, have a dance or something that's Excited? You know what? I'm sorry to life for International Women's Day.
Excited, but you know what? You're right. Oh my God, cha, that's Fanta.
What a great story. I wasn't aware of this at all. This, to me, this is, you know, made this story so important.
It really did, because we have so many women founded companies who have, are who, who just women founded, who are turning into unicorns so few. And this is a great story about how she did that. And she did it at a very important time.
And yes, we do need chips that can, that are gonna be more sustainable and that can, um, be more, um, I guess you could say energy friendly. So, yay, I am so happy about this story. And you know, Renee, James, thank you, thank you for leading the way and showing women how to do it.
And that you don't have to be a young woman outta school who's on a pot, potentially a team of, of founders that is still led by a male counterpart. So to me, this is the big story, is that a woman took this business, uh, to this level in this, in the amount of time that she did. Uh, and I hope that she gets more attention around it.
Great story, man. I I will say good for middle aged people anyway, not, it's not just younger. Yes, the Youngs Out there, I know, but a middle aged woman, you know, last year, vvc, 1% of funding went to women in VC funding went to women 1%.
99% is going to men. 1% is ridiculous. It's ridiculous.
But she proves that a woman is worth being, uh, investing in, right? Well, I hope after this exit, you know, uh, she takes some of her winnings and starts a venture capital fund and corrects that. Um, you know, I, I can imagine a no better person to invest in startups in hardware than her, um, as an operator and as a founder.
She knows what it takes to build and grow companies. Um, and, and I hope that that's what happens next. I'm a little concerned that the cost of startups in the age of AI is gonna be prohibitively high.
And so there might not be as many startups, because you know, you're gonna see companies now require, what, $2 billion as the ante just to get started. I mean, how Well that, that's, if they're looking to create their own, uh, their own LLM or, you know, models and, and and so forth training. Um, you know what, Mike, that's frankly an argument I heard when the web first came out, when the cloud first came out.
And it's always that, that high, that high barrier to entry. And the high barrier to entry is I always either, you know, uh, uh, advanced technology or advanced funding, one or the other, right? But, but on the other hand, no VC wants to invest in a company that anyone can duplicate.
So they do want high barriers to entry. But let me, let me mention something, and I'm not gonna get on my soapbox here, but unfortunately, at least here in our country, the idea of pointing out that this is a woman who did this is, is, is just not in style in some circles in this country. And more than not in style, we're actually erasing women and other minorities from the history as contained on the web and maintained by this government.
And that's a, that's a sin. That's a sin. And it's a sin that our children are gonna pay the price, including the women out there and the minority people.
I get that you don't wanna make it easier for just certain groups or whatever, but when you start erasing the history and don't call out the wins that people have, you, you are no better than, than than Hitler in 1932 in the Nazis. You don't do that. You don't history.
The winners don't get to write the history on the web. There is only one history, and it's wrong that we're doing that in this country. And it, and it has to stop.
And if it means having alternate alternate websites and everything else, where we call out the truth of women and minorities who have done great things in this country, we need to do that. And I'll leave it at that. I wanna get Renee on Techstrong Women.
Wouldn't that be awesome? I know. It's like, how do I find her?
I gotta, I'm gonna reach out to our LinkedIn. I don't dunno if that's gonna work, but now she's got some time. That was a cash offer.
We'll, we'll just send her this. 5 billion cash offer. Well, but you don't know how much did she give up, right?
I mean, Robert, you've been through this as a founder, right? 5. I mean, I'm gonna imagine if she's a typical founder and she went through three rounds or four rounds, she probably owns 10%, 12%.
If she's, oh, yeah, yeah, that's terrible. What is she gonna do with 650 million? I mean, poor thing.
Hey, it's not, it's not like the Wiz guys who by my reckoning, each walked away with about 8 billion. Hey, look, I, I really feel for them. Uh, they, they really, uh, uh, you know, how are they gonna survive?
Exactly. But, um, you know, look, it, it is the most important thing. It's, look, and, and Tracy will say this as well, uh, um, you know, you don't start companies to make money.
It's actually the worst way to make money is started companies, you start companies because you're passionate about it, uh, because, uh, you feel strongly about it. Uh, and, and speaking for myself, um, you know, it, it was, uh, uh, you know, uh, uh, b******e surfers at a, at a song, uh, where one of the lines was, um, you know, sun, the funny thing about regret is it's better to regret something you have done than to regret something you haven't done. And for me, I really didn't want to look back and regret not starting that company.
It's never about the money. Yeah, the money's nice, but, uh, it's really about, uh, changing the world and having an impact. And I think she has had an amazing impact and has dramatically changed the world.
Um, you know, there, there is, um, you know, certainly, um, uh, just as A-A-C-E-O and a leader getting a company to this point and having an exit like this outstanding, and that is worth far more than the money. Fair enough. Let's see what she, where, where it goes from here.
All right, we're gonna take a break. We're coming back to our last block for this lovely Monday morning, uh, open source, LLMs and cybersecurity. I don't know, oxymoron, maybe you're watching.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Hey, folks, we're back. And we're talking about Trend Micro, which made a move to open source. It's LLM that had built on top of the meta LLM, and they train this specifically for cybersecurity purposes.
And their argument is that, well, if everybody's gonna go bill an LLM for a, uh, for a specific use case, we should just do one for cybersecurity that we can all share. And they're arguing. It's a deep seek moment for cybersecurity.
Alan, I know you've tracked this space for a long time, but what do you make of that anger? Can you say Me too? I mean, I, I, I just like, all right, good, good for you, Chen.
Michael. I, I think what they're really trying to get at though, is that they're throwing in first. They'd like to see other cyber companies throw in.
We'd like to see, maybe this is something like the Linux Foundation, OSSF should really be taking Charge Ofri, right? Which is a across industry, single LLM for all things cyber, because having it just be the, in this case, trend Micro, or in another case, you know, Palo Alto or, or whatever, having it by individual companies is just Balkanization, right? And, you know, my, my LL M's bigger than your LLM.
But if we could do an LLM cross industry managed by some sort of foundation, will it help? Maybe, maybe. I mean, you know, it, it, it's, it's going to do, you know, the old saying quality in is quality out and, and not quality in is not quality out.
Um, some people use a different word for not quality. But that being said, it it, you know, there, there's so much details in there, and quite frankly, I, you know, good for trend for doing this, I applaud them. But this is really something that needs to be taken up by a more than a single vendor.
It, it really screams for an OSSF kind of involvement, right? Robert? Do we need another foundation?
Come on. There's no shortage. Well, alright.
Ho, ho, ho. Hold on, Alan, like, before you start congratulating Trend Micro, uh, let, let's kind of get into that press release, uh, that they put out about this. Um, first of all, this is not open source.
Uh, the data's not open. Um, we, it is free, but free is in beer. Uh, it is not free As in freedom.
Uh, people cannot take this and improve this. Um, you cannot look at how it was built and seek to, uh, change it for your uses. Uh, it's just free usage.
This is shareware. Um, the other thing is, is that look at the licensing a call out explicitly in the press release. You cannot use this, uh, if you are building a competitive offering to anything that Trend Micro offers.
Um, this, this is that the, the Llama license that Meta came out with. Um, and, and so it is not open source. Um, it is certainly free, uh, but if you really look at what it's doing, it's, they train this on trend micro, um, uh, data and, uh, things that they have offered.
Like, okay, look for this on, on, on this compute instance. Look for these things at the network. And so, um, it is Balkanized, uh, this is very specific to Trend Micro.
And, um, honestly, I think that this is a strategy to do two things. One, uh, certainly yes, we're doing it too, but second, this is, oh, it identified lots of issues. You need to fix it here, fix this with Trend micro products.
Now, I do applaud them with that for a go to go to market strategy, brilliant, big fan. But if we're gonna start saying it's open source, um, uh, b******t, it is not. Um, now certainly, you know, Alan, to your, your point about a foundation and those sorts of things, um, right now, I don't think that there's an appetite for companies that would wanna fund this.
They want to, they wanna have their walled garden, they wanna balkanized. And, uh, certainly as, uh, for-profit organizations, they're going to do that. I think the answer to this is for, uh, certainly Linux Foundation, other foundations to build their own, to do it out in the open, uh, to open source the data, to open source the model, uh, to give updates, and then have people be able to inspect this and show the world what a true open source LLM is.
Amen. Amen, brother. I, I created all those points.
So, but, but, but here's the trace. Let me just jump in and Marble, let me jump in a second. I'm not gonna call it the hypocrisy of it, but let you worked at the Linux fan, and I'm not asking you to badmouth them or say anything outta school.
No, but the, and Trace you're involved in them, they're not gonna do this project without someone kicking in some money to fund it. Where's that money coming from? Hold, hold, hold On.
But remember, all open source projects start from a developer scratching an itch. Eric Raymond, uh, cathedral on the Bazaar. So somewhere, somewhere is a developer or group developers, uh, that is saying, Hey, I'm going to build this.
Now, remember, I, I mentioned, uh, earlier in my, my Lego sorter. Um, I certainly intend to open source that, uh, because I've got a huge stack of Legos that I need to sort. Um, and that is my itch.
Uh, at some point, a group of developers, now, whether they're backed by for-profit companies or they're doing this on their own, are gonna build this. And, and I think two of the biggest successes in open source, um, we could talk about that, that itch to scratch. Now, first Leus, Hey, I'm building a operating system for X 86.
Yeah, it's gotta be free, not full, you know, huge big deal. We've all read his first announcement, he just wanted to build it. Another example of that is Kubernetes, um, Google saying, Hey, we have built Borg, um, and we don't wanna be in the, uh, container orchestration business.
We wanna be in the AdWords business and all their other lines of business. And so they open source that. Um, and so Do you think they regret it?
Um, I, no, I mean, from GKS, they're making plenty of money off of that. And also the improvements that happened to Kubernetes that benefited Google Maps, Gmail, all this other stuff, uh, where they can make money off of that and not just selling Kubernetes, which they are with GKS, they're doing fine. Uh, I don't think they regret it at all.
I think that they think that it's a, a master stroke. And I think that the, uh, rest of the industry would agree, uh, very appreciative of, I think AWS is very happy with all the billions that they're making off EKS. Um, but you know, at the end of the day, this, this, these, these itches to scratch can come from an individual just doing it for intellectual, uh, uh, exercise or from companies seeking to, uh, take, uh, you know, kind of non-differentiated, non-differentiated technology.
And, uh, having the whole industry work on that. And then they could work on the higher order value add stuff. Um, this will happen.
I think that's most, That's the most compelling thing about this conversation, is that LLMs are rapidly becoming undifferentiated value. I mean, the difference between the one that trend micro puts together and four other companies put together is marginal. So economically, it's time to just pile in together.
Well, and, and that's the point I was making, Robert, I was not calling out Trend Micro for an attaboy, you know what I mean? I think this is a me too thing. And yes, it's not truly open source, right?
The, the LLM it, it's shareware. It's a free to use, it's free as in beer as you said, but it doesn't give you the, the ability to make it better to, to add on to, to modify. But I think if, if, if Trend Micro's Heart is really in the right place here, the thing to do is put this LLM into a foundation and call on others to join in on it.
Well, let's just, why don't we just say, wait, let me, I, why don't we just say, okay, first of all, I wanna just, just a couple of points here that were made. Number one, there's both Alan and Robert are right to some level, um, open source projects, many of them, most of the big ones are now being driven and provided by big companies. I seldom go go into any of the Linux Foundations meetings where somebody has changed jobs and now the SIG or the open source project has to go through some kind of rigamarole to, you know, get somebody else involved because they're being paid to work on these open source projects.
Literally, Ortel is probably one of the only ones that we have just driven this product by pure sheer open source contributors. The, the problem with, um, trend Micro and this particular new release that they have, they're talking about is that it has no governance around it. And I do believe that, that if you're going to consume open source, you better consume some open source that has proper open source governance around it.
It has a board, it has a community, and that's not what Trend Micro is doing. So I agree with Ellen that it should be put into a proper open source, you know, foundation, whether it be Apache Eclipse or a new foundation that covers LLMs, right? Which however it works.
And then the other problem I have with this is it's deceiving to say that it's a cybersecurity LLM because cybersecurity has so many sides to it, and they're talking mainly about, you know, what they do because it's based on their data. So endpoint security, network security, they, they do a level of threat intelligence, but it's not related to, so the software supply chain, so to call it, you know, no, But it's cloud security. It is cloud security, but there's it's cloud.
But that's just one aspect of the cyber security world, world. But it's a start is all I'm saying is, guys, it's a start. It's not the, it's not meant to be the end, it's the beginning.
It's a start, right? But it, it needs to have a better name because it can be deceiving to think that this thing's gonna solve all cybersecurity problems, right? So I really feel like it should go into an open source community as well, which one?
I don't know. But it should have proper governance around it, and it should, the, the, the licensing should be, uh, where you can actually use it and consume it and monetize it in a way that makes it, uh, makes open source what it is. All right, well, hopefully this is the end at the beginning and we'll see where we go from here, right?
Well, speaking of the end, this is the end of this text Drug gang. I got the last word again. Yes, you did, Tracy.
Uh, hey everyone, just a reminder, you know, this is not the end of Textron TV today though, because it's just the beginning, right? Textron gang heads off you, always leads off our full day of coverage on Text Drunk tv. So we still have probably two, three hours worth of great content for you to watch.
Stay tuned if you're watching this on our Text Drunk TV Network, if you're just watching this on, on Demand on YouTube or Text Drunk TV or one of our websites to head over to Text Strum tv and, or log in every morning at nine 30 on Facebook or LinkedIn or, or YouTube or any of our sites, and you can catch the whole stream. Or you could go to Text Drunk TV and just click on the individual, uh, segments that you're interested in. Anyway, Robert, Tracy, Mike, thanks for joining today.
Thank you for watching. This is Alan Schult. This is another episode of Text Drunk Gang.
We're outta here. This is Textron tv. Hey, everyone, welcome back to Textron tv.
Our next guest is Adam Haney. No, not that Mr. Haney, but, um, Adam Haney, head of Technology, invisible Technologies, um, that's pretty cool.
Head of Technology and Invisible Technologies. I didn't think about that before, but let's welcome Adam to the show. Hey, Adam, how are you, man?
Welcome. It's great to have you on. Thanks so much, Alan.
I always appreciate it. A, a good Green Acres reference, and so definitely the head of technology's a little bit different than the other Mr. Haney, you might know.
Yeah, I, I, I, uh, I'm gonna give you extra points to that. I don't know how many people out there caught the Green Acres reference the stores, but, um, anyway, welcome and thanks for having, having you on being on here with us. Adam, before we jump into Invisible Technologies and what I want to talk about today, I always like to give our audience a sense of who they're talking to.
Give us a sense of Adam Haney. Yeah, so I, I, uh, have worked in, in various different roles across startups, usually in the scale up phase of, of building platforms. And so, uh, I'd say at, at, at my root, I'm a tinkerer, and so I, uh, you know, have always continued to go examine different technologies and as well as things outside of technology.
Uh, so I've been very mechanical since I was really small. Um, but, uh, most recently before Invisible, uh, I worked at Meta where I, I focused on, uh, news and personalization problems there. Uh, and then prior to that I built multiple different, uh, technology platforms for managing labor workplaces.
And so that's been kind of my background overall. Very cool. Excellent.
Now, so that's not terribly different than me. I'm also curiosity killed the cat kind of thing. Right.
I'm always looking and poke into whatever's new and exciting. And, and of course for, for people like you and I, Adam, that revolves around AI these days, right? It's, it's the new exciting thing.
It's like a absolutely, you know, the final frontier, maybe, well, I don't know if it's the final Frontier Quantum will be next, but we got time to play with Quantum. Let's play with AI for now. Um, you mentioned, I mentioned that you were head of technology with Invisible Technologies.
A lot of people out here probably don't know Invisible Technologies. Adam, what would you tell them? Like, what's Invisible Technologies about?
So Invisible is an AI process platform. Uh, we help enterprises to be able to deploy AI at scale. Um, and, and we do that through various different mechanisms.
So whether that's helping them to run evaluations so that they understand how well their models are performing, as well as helping to connect those AI models to their existing software tools in order to be able to actually solve problems with ai. And we have a heritage of also working with several of the foundation model providers in order to help them build the data sets that ultimately were involved in creating the ais in the first place. So we have strong experience both in building AI models as well as helping people to deploy them in a, an applied way.
Excellent. You know, obviously a lot of talk about AI in general over the last, well, two years certainly since, you know, GPT Jet GPT burst on the scene two and a half years, whatever it was. Um, but recently there's been a, an increased kind of focus on how do we train these models, right?
What goes into training these models? Should we all be using the giant LLMs that the, the hyperscalers are using, for instance, right? Should we be developing our own LLMs?
Will we see the sort of an LLM marketplace, if you will, where, where you can buy specific LLMs? Should we train them with data from the internet, or should we have synthetic data right? There?
There was a little bit of irony there when OpenAI accused the, uh, deep seek folks of, of using their data for training deep seek. Well, OpenAI used other people's data for training open ai, right? Uh, but nevertheless, I mean, these are, if we're gonna move forward with ai, and, and it's something we talk about on Textron Gang and around here all the time, we've gotta get this stuff sort of a little bit more locked down, right?
That we, we shouldn't be worried about. Is there confidential data going in there? How is this thing trained, right?
Uh, poisoning, hallucinations, all, all of the above. How is invisible helping with this? How do you see that problem?
You know, what, what's the way forward here, Adam? Yeah, absolutely. So, I mean, we think a lot about evaluations as a, a, a way to think about safety as it relates to ai.
And so normally when we work with a client, we come in and we try to understand what is the business problem, as you rightfully called out, what are the risks if this model hallucinates or if there's a problem, uh, with the way that the model tries to solve that business problem. And then we'll usually start a program to build evaluations. And so, um, you're probably familiar with things like MMLU and several of the other sort of industry benchmarks for broad model performance.
But what we find is that, you know, the problem that a particular business has isn't usually captured just by a single existing benchmark. We need to help them to build a program around the problem that they're solving. So if we work with the hospital system, and we want them you to be able to parse, you know, specific kinds of medical data, there are different forms of evaluation.
Some of those can be automated. So you can use LLMs to think about building, uh, you know, an evaluation program. But at the end of the day, especially for really critical problems that involve safety or, or business critical decisions, you want a human in the loop to then be able to make sure that we have, you know, a domain expert that really deeply understands this problem space to be able to say, yes, this ai, you know, answered correctly or didn't.
And so we think a lot about the, the same way that you would think about automated QA for deploying, you know, new pieces of software. It's necessary to have an, a robust and effective evaluations program to deeply understand is the model, or, or is this overall applied AI system that I've built solving the problem, you know, in the way that I expect, uh, for, you know, any kind of, you know, business use, uh, of an AI model. Excellent.
So there's, I wanna hone in, uh, specifically on using sort of synthetic data versus, I call it real data. Other people call it human data. Look, I it's a little bit wild, wild west right now, I get it.
Yeah. But when we get civilized that of what do you think the right path here is? Yeah, I don't think there's a one size fits all answer in either direction.
So certainly, you know, when you think about problems around PII or, or, um, you know, privacy in general, there are places for synthetic data. So that allows you to generate a data set, you know, from something that might be confidential or unsafe as, as well as it allows you to really increase the data volume that you have from a, from a smaller dataset. Um, however, you know, synthetic data, the, the process overall involves training a model on, you know, a smaller, uh, dataset and then generating, you know, either a representative data set or a new larger dataset.
Well, that process amplifies the biases of the dataset that you start with. And so there's not a future that I see where we're able to purely move over to synthetic data sets. I don't think we've generated all of the data that we're gonna generate, you know, across all of society.
And so you sort of think about the process, there's gonna be some amount of model drift, or the, the underlying data distribution is not always gonna be representative of new things that happen in the world. And so we believe that there's a place for humans in terms of generating new data sets, uh, as well as, you know, if there is any problem in that underlying data set, creating a a synthetic data set is only gonna amplify that problem. And so that's once again, a place where we see a need to make sure that any training program, evaluation program, fine tuning program, uh, has a strong need for human data, uh, as a, as a part of that process.
So let me be real selfish a little bit here, Eric, right? So we're, we're a publisher. We publish, I don't know, 120 articles, 30 to 40 videos every week, every week, week in and week out.
We probably have, like, for instance, on DevOps, we probably have the largest collection of DevOps content in the world. Mm-hmm. I am sure that that data has been used to train models.
Yeah. Good. You know, and I, at some level, man, I'd like to get compensated for that, obviously.
Right, right. But also, I would like to be able to use that to create maybe my own models, right? And, and, and make it a smaller data set.
But if you're looking for DevOps, I'm your man. Yeah. Right.
And, and so what about people like me, right, to bring it really home. Can we create our own sort of smaller data set that's very focused on that? And, you know, how, how do I, how do you market such a thing?
How do you, I mean, do you envision a market evolving around those kind of small data sets? Yeah, absolutely. I mean, I think that specialization for some of these models makes complete sense.
You know, when you think about the number of parameters that are going into the really large models, um, it, it's sort of like, you know, having a PhD student do a fifth grade math problem. Um, it's just not necessary for all kinds of problems. And so we're gonna see, you know, not only is there a massive, you know, energy consumption component to that, there's a huge cost, uh, component to it.
And, and overall it's, it's the same sort of optimization process that we've gone through, you know, over the last couple of decades with cloud or, or using appropriate tools for any kind of data processing. You wanna use the right tool for the job. Uh, and so I, I think that certainly if you know that you're gonna be only solving DevOps problems over and over again, it makes complete sense to say what is the premier leading, uh, you know, model for solving DevOps problems as well as, to your point, you know, you as a publisher have an immense amount of expertise you might choose, you know, in the future.
How you think about, you know, the, the thing that you do publish, how you think about curating your catalog of content in order to make sure that, you know, your expertise is being appreciated. 'cause right now, you know, obviously it is the wild, wild west in terms of the, you know, the way that, uh, the entire internet is being used to train models. Absolutely.
Absolutely. So a lot of talk around, are we kidding ourselves in that? Yeah.
The big, you know, the old story, the big guys will always be able to do what they want. They'll create their own LLMs, they'll create their own data sets, they'll customize it better, and they'll, you know, squeeze every bit of usage out of ai. But for the rest of us, do you think, Adam, where we're gonna be able to do custom data sets really EAs, you know, easily, easily enough to make use of them, will we really be able to get the ROI out of AI without having to do that and, and you know, how big a lift is having to do these kinds of things?
Yeah, I mean, so that, that's one of the things that, that invisible helps with very frequently is when we go and we work with, you know, a business or somebody that has a, a unique data set that needs to create a model that's specific to them to solve their problem, um, you know, data as an asset or these businesses is a huge part of their competitive advantage. And so, uh, I, I definitely think that there's an opportunity, you're already, you know, seeing publishers and people that would normally put their content on the internet that are starting to sort of pull back and put it behind paywalls. I know Reddit recently, you know, signed a huge deal in, in terms of how they're thinking about distributing their content to model providers.
We work with, uh, enterprises that have never published that data. Uh, you know, the, the sit on huge, uh, you know, treasure troves of data from their operations or from running their business overall, uh, they want to be able to train a model on something that was never publicly available, and thus models, uh, do not perform well on, on the kinds of problems that they're trying to solve. So I, I certainly think that there's an opportunity for, you know, whether it's fine tuning or distillation or otherwise creating, uh, you know, applied, uh, ai, uh, solutions that solve problems for those businesses.
And, and that's where Invisible tries to help. Absolutely. I may have to talk to you after this interview.
Um, okay. But beyond that, let's talk a little bit about ROI and ai. Sure.
Right? A lot of people think that's an oxymoron, uh, at this stage of the game anyway, right? I, I just came off the set of Textural Gang, and we were talking about, look at, at this juncture, AI is helping a lot of people in their jobs, really, specifically, if you're marketing AI's a huge help in, in creating marketing material sales as well, coding.
It may not be generating code, it may just be fixing code, but nevertheless, one or the other, it, it's kind of helping and, and every other way. But, you know, if you listen to Jensen Long over at, uh, Nvidia this week, you know, we're gonna have, what is it, 10 billion digital workers, you know, agentic ai and all of these things. As I sit here today though, can you show me what jobs have been eliminated because of ai?
You'd be hard pressed, you'd be hard pressed still. Not that that's gonna be like that forever, but again, today, so when you're working with customers, what's the ROI that you give showing them, Adam? What's the ROI that they are gaining?
So, I mean, I think, you know, I, I recently read a study that something like only 15% of AI projects ultimately end up making their way to production. And so, you're right, there are a lot of prototypes that are being built right now, and a lot of people that are experimenting with ai, but they're not actually seeing it move the needle in terms of providing value for their business. Uh, and so that's where I think Invisible is uniquely positioned.
We deeply believe that you have to integrate into the current ecosystem. So we're not out to try to replace somebody's existing software tools. We're not, uh, there to try to replace their workforce.
We want to integrate with and, and help them to then, uh, set up the data sets that they need in order to be able to train these models, building a suite of evaluation tools, so that that way they can confirm that the AI model is working the way that they expect it to for their business. Uh, and so I think that without, you know, all of those pieces, the data preparation, proper model selection, evaluation, you're sort of, you know, doomed to failure, um, because you're not gonna be able to make a model that works effectively, and also you're not gonna be able to trust it. Uh, and so I, I, I agree with you that right now it seems like, you know, we've, we've discovered fire in some ways and we're looking for applications of, you know, this, this new tool.
Uh, and I think it's really important that, you know, you work with a partner that thinks about how that's gonna integrate into the way that your business, uh, actually operates. I think that's a great analogy. I may steal that from you.
I'm just telling you right now, I'll, I'll incorporate it into my data set. Um, but I, I appreciate it. Hey, Adam, we're, we're almost outta time.
But for people who want to go dive into Invisible Technologies a little bit more, what's the website? Sure. co.
Uh, and you can, you can find us there. And, uh, we're always happy to chat with people about ways that AI can solve problems for their business. I love it.
Adam, sounds like you're having fun doing what you're doing though. Yeah, absolutely. What a great time.
Absolutely. Yeah. What a great time to be in this, in this position.
Good luck to you and Invisible Technologies. Come back, keep us posted, and thanks for coming on today. Thanks so much, Alan.
co check them out, especially if you're thinking about how ai, how you are gonna leverage AI at your organization. We're gonna take a break here on Tech Struck tv. We'll be back in a moment.
Hello and welcome to the latest edition of the Textron AI video series. I'm your host, Mike Bazar. Today we're with Trevor Welsh, who's vice President of Products for Witness ai, and we're talking about data governance and security, and all the issues that come up when we start to deploy ai.
Trevor, welcome to the show, Michael, it's an absolute pleasure to meet you, and, uh, thank you for having me. One of the things about AI is that, you know, it's kinda like when you first get married, everybody's enthusiastic and it's all set up, and then you gotta try to figure out how to live with each other long term, and that takes a little bit of socialization. So as you kind of look at where we are in terms of the adoption of ai, I feel like we're getting down now into some of the more nitty gritty issues of the day.
And what do you see in people encountering? Gosh, that's, that's a really good question. I think that there's probably, there, there, there's, it's an evolution as you pointed out, right?
So I think initially, you know, chat, GPT comes out of, you know, it seemed like nowhere. And all of a sudden people are like, oh my gosh, I can, I can interact with this thing. And it's pretty good at giving me useful responses.
And, uh, you know, then I think people start to figure out, well wait a minute though. You know, some of the response that's giving me aren't very accurate. And that kind of got into this hallucination thing and everything else.
And I think another interesting thing that was fascinating is business also picked up on it very early. So I saw my enterprise customers beginning to adopt AI in various pockets really, really early on in the AI life cycle. But I think you're spot on that we're now in that nitty gritty piece.
So people are thinking about how do we protect models? How do we do, you know, ethical AI development? Um, you know, how do we go and make sure that the models are as predictable as we could make them?
Um, the analog that I use, you know, or analogy that I use is, I, I like to consider the best models are like, well-trained marines, meaning they're intelligent, you know, they're doing really smart stuff, they can think on the fly, but they're acting in a way that's pretty predictable, right? So when you give them a mission, you know, you, you're getting a, a really, really good creative outcome. Um, I think that's kind of the ideal thing.
Um, for, for great AI models, I feel like in some ways we're still stumbling around on the use cases 'cause we have these probabilistic models that are good at guessing about what comes next. But we seem to be trying to insert them into business processes that are supposed to be done the same way every time. And the models don't do that.
So how do we kind of figure out where to use these things and, and for the best advantage versus, I sometimes feel like, you know, we're trying to do the square peg in a round hole thing all over again. Yeah. I, I think you're really spot on.
You know, I, I, gosh, there's, there's so many analogies for that, but what I would say is this, I mean, I think, uh, I think that when it comes to business processes that require, we'll call it like input interpretation, um, I think models are reasonably good at that, right? I mean, if a user says, this is what I'm trying to do, a model's pretty good at saying like, oh, I think I know what you're trying to do. Is this what you mean?
And usually it's pretty good at that. I think the thing that you hit on though is critical, which is, hey, if the model understands what I'm trying to do, is it gonna gimme a sane output? And there's ways to actually go and make that part better.
So one thing you can actually do right, is keep bear in mind the, the concept of a agentic ai, right? Is you can leverage multiple kind of models or multiple AI agents to go and reprocess those responses. So imagine for a moment that I can have a, a master model that's great at understanding, you know, input.
I can have another model that's great at managing the various kind of agents that get assigned to go and provide a good answer. And then still another model that's kind of the output model. And that's the thing that kind of can check for bias, it can check for crazy outputs, hallucinations, and other various things.
So I think that there's ways to go and structure these things that make them better. But you know, the point still stands, I think you're spot on. People using general purpose models and hoping to it, everything's just gonna be perfect all the time, especially business processes that require consistency.
Yeah, I mean, I think there's work to do. I feel like though, on the upside, there's a new respect for data and especially how to govern that data. And, um, you know, you've seen instances where people are showing how, you know, somebody who understands how to use prompts cleverly is, you know, teasing out what the boss makes.
And, you know, that kind of gets everybody a little bit, you know, perturbed. So are we kinda at the back end, all of this gonna have a better understanding of the nuances of data management, the rules for governing it? And maybe we might be better off long term.
Michael, that's a, that is a really cool point. So, um, I'll, I'll go back to go forward. A, a long time ago it was a company called Splunk at the time.
Splunk was pretty early on. And I remember Splunk had an emphasis that I'd never seen before, which is this really understand your data thing. You know, Splunk was gonna basically go and bring all this stuff in and, and like, Hey, do you really know how your data's structured?
Do you really know what your data looks like? Do you really understand what's coming outta these various tools? And it turned out that a lot of companies didn't.
I remember that I was working with a, a giant healthcare provider, and the healthcare provider was trying to do a pretty sophisticated use case that had to do with protecting patient data for people that were kind of coming into the hospital. And, um, they didn't even know what the data looked like. So all of a sudden we were looking at the data and they, they got all these amazing data insights.
They learned more about their stuff than they knew before. Point being, you said something that I think is really salient for today. Copilots are changing everything.
So a good example of that would be like Microsoft copilot. So imagine a world where it sees all your chats, it sees your email, it sees your files, it sees, to your point, the CEO's doing performance reviews and getting them formatted, you know, up in AI agents to make them look better and, and sound, you know, and have the right tone. That data's really, really valuable.
And I think a lot of people didn't think that much about it. It was kind of like, well, there's the drive that's mine. There's the drive that's shared, and as long as it's in my drive, it's okay.
But when everything is being modeled and you can potentially get access to that, it requires a lot more intention about what's modeling your data and how it gets exposed. Um, I can think of a company that I worked with where almost that precise use case was happening where the CEO was working on board slides with their staff and, uh, you know, like a, a fairly low end engineer went and did like an ask about like, Hey, you know, how's the company doing? And it brought up the board slides, you know, that they didn't even have access to.
So yeah, I mean, I think that the changes everything. Do we also appreciate the security issues that come along with this? 'cause we see now everything from people trying to poison model so that they generate incorrect outputs deliberately to actually stealing the entire model, which is kind of like stealing the most important or maybe the most knowledgeable employee in the whole organization.
And then just asking him, you know, tell me everything, you know, I I think there's two things at work, right? So like, you know, bifurcating the thing you said, I mean, there's intentional poisoning and those intentional theft. Um, you know, and then there's kind of this world where it's like less intentional, you know, where a model learns to be bad, so to speak.
Um, and those are two related but different problems, right? So, so one is, you know, on the side of, we'll call it like deliberate poisoning. Um, there actually, I had a, I had a conversation with a pretty high up person in DOD about a month ago, and they were concerned about models that could be controlled by foreign governments, um, you know, potentially going and radicalizing, you know, America's fighting forces.
And it doesn't, it's not like on the nose, right? It's one of those things where like every 500 prompts, it slides in something that's plus 20% good for a foreign adversary, for example, that sounds really small, but over the course of millions of prompts and, you know, you get hundreds of thousands of people having certain biases that kind of get reinforced, it actually has a really big problem, right? It's a form of kind of insidious propaganda, you know, and, and again, this is coming from somebody who's very high up in DOD that they were like sitting there going, this is something we have evidence that's happening.
To your other point though, there's also kind of the world of ag agentic models. Let me give an example. Let's suppose that you worked at a car company, doesn't really matter, which, and I work at a metal fing company, and you are gonna go and have your team go and design cars, and they're gonna go and interact with my agentic model and my agentic model, what it does is material science.
It lets you know what metals you should use to make the frame and do various stuff. Well, imagine my model though. I'm a bit of a nefarious company and I wanna sell data to your, to your competitors.
Well, you can kind of imagine that you go and give me a design over with, with my agent. My agent goes and says, well, what about this, what about this, what about this, what about this? And eventually it basically extracts way more detail about the design in particulars of your design that you didn't need to share.
And then I go and sell it to a competitor, for example, and say, Hey, you know, Michael Corp is actually working on this new thing. Like, models can do stuff like that. In fact, you know, imagine for ma for example, I'm not a nefarious company, but rather there's a nefarious ML lops engineer that, you know, every so and so conversations, it start, it goes into like a data extraction process and there's no real oversight to that.
Um, you know, and then of course now the design gets sold. Um, that's one thing, material science. But now imagine, for example, drug manufacturing, uh, you know, or other things that are very, very, very IP based, To your point about disinformation.
It's not just online, right? Because that person will and go to some bar somewhere and repeat that and, you know, share that disinformation with other folks, and it starts to multiply in ways that have nothing to do with the underlying technology per se. I think that happens a lot.
Um, you know, I think that, you know, without getting into a probably a way bigger discussion, that'd be really interesting to do some point, um, you know, disinformation spreads really quick, right? You know, if right now we make something up, right? And, and then we, we put that onto the world, right?
Because, you know, you know, you have a, a very, very popular kind of, you know, information kind of site and everything. It's a lot harder for people to disprove the thing that we said than it is to just say it, right? So, you know, disinformation is a tough thing.
It's a hard problem. Moreover, I think that people view models in a way that, you know, I, I can tell you like my, my daughter for example, uses chat GPT regularly. She loves it.
Most of the time it will probably be give her pretty good responses. So when she asks about like, how hot the sun is or something like that, or how far is Mercury, you know, it's probably gonna be pretty good at that. Um, but when it gets into things that are more philosophical, um, yeah, I mean, like you can have disinformation in there.
Some of it could be intentional, right? I mean, if, if we remember when deeps seek first came out, people started asking about things that were politically sensitive to the Chinese government and like it was very unwilling to kind of do that or would get very massaged answers. Whereas things that let's say were necessarily, um, maybe sensitive to the US government, it would gladly go and give you all kinds of detail about that.
That was, you know, probably reasonably accurate in that type of thing. So you can get this kind of intentional, unintentional model poisoning and disinformation, and it's reasonably easy when you own the data to go and, and pushed infor disinformation out, it's a lot harder to go and figure out how to stop it. I think it was Mark Twain who said, A, a lie travels halfway around the world before the truth gets its Buddha.
Um, and I wonder if it's not possible to use AI to track the spread of this information. And I guess the issue I'm gonna have here is not everybody agrees what this information really is, but is there some way to kind of maybe track, um, you know, where certain concepts are being shared using ai? That's fascinating.
So I have a, a friend who works at a major social platform, and, um, they're doing just that. In fact, they have pretty good data about the origins of a lot of stuff. So a good example would be like if tomorrow I said something like, oh, you know, like, you know, every thinks grass is green in reality, it's blue, and just your eyes see it in a strange way that makes it appear green, but it really is blue and there's this evidence, um, you know, this social platform actually can probably trace it down if not to the individual then to like, like kind of like a small population of users that began to popularize this concept.
Similarly, um, I, I have a friend, um, that also works at like, like Reddit and at Reddit, they can do that really well. We're actually, they're going and monitoring tons of different platforms other than classified by the populations of users, et cetera. So yeah, you could do some pretty amazing stuff there.
But I think to your point, you know, one person's propaganda is, is another person's evidence, and it becomes really difficult. And, and I don't know how much, like, let's say what, what's the financial gain to the truth? Um, right?
Like, which is a big philosophical discussion, but sitting there and going, how much people willing to pay for something that's truthful and evidence-based versus something that's not, it's hard to say. In some cases it's a troll that somebody's paying to go make something up. In other cases, it's just somebody winging something to see how much they can light people up, right?
People do all the time, right? I mean, trolling is for as long, I'm sure trolling existed in Roman times, you know? Yes.
How do we keep control of our sensitive data though? I mean, are there policies that can be applied to this stuff and can it be done in real time? Because a lot of times folks are interacting with these prompts and things and, um, there isn't like, you know, 40 seconds delay for me to go and execute a bunch of policies, I don't think, but how do I do that in a way that, um, gives the benefits without necessarily the risk?
Yeah. Um, that is a really neat question. So I think there's two sides of that.
So let me, so the two sides of this, right? One side is just like you said, which is like, Hey, Michael's interacting with some, you know, like, call it like an AI model, and how do we make sure that he doesn't inform the AI model of things the AI model shouldn't know. Good example of that, like customer data or something like that.
Then there's the other side, right? Which is like on the engineering side, how do I make sure that I don't go and, and inform the model about stuff it shouldn't know about? So for imagine, you know, imagine for example, that I'm a bank and I'm trying to develop a new model to, I don't know, score credit better.
And I go and have this massive training set of all my customer's data internally. And because I'm just an engineer and I say just, you know, I'm just an engineer, I probably have privilege, pretty privileged access to all that data. So all of a sudden I'm leveraging a giant amount of customer data with privileged access to create my new credit scoring model.
And then maybe that ends up becoming a thing leveraged at the bank to score credit for real, but it used data in a way that is wildly out of compliance. Um, so that's kind of one side of the world. Um, getting into the other side, which I actually think is even more interesting is like, what do we do for example, about like, Hey, Michael wants to go and interact with insert random model here on the internet.
How do we make sure that you can use it safely and, and kind of do that? Um, so, you know, one of the things, and and I won't get into like the big witness AI thing, but broadly, you know, AI usage is, is a really, really powerful thing. And enabling it is a really powerful thing.
And there are ways to go and do that in real time using AI guardrails, which means that specifically going out and saying, Hey, we're gonna make sure that people don't send risky things to AI models. Um, we're gonna go in and actually go and look at the prompts or completions or, you know, the responses and make sure the stuff coming back is not risky to our business. Similarly, um, there's also kind of the ability to go in and say, Hey, you know, let's make sure that like the things going out to the models aren't proprietary to, let me give you a really specific example.
Um, there are companies out there that are leveraging things like GitHub copilot or, you know, vs code type stuff. They're amazing enablers. I am a giant fan of them.
Uh, people are using the same thing with Gemini, et cetera. So these are literally engineers doing active stuff. Now the problem is, is that imagine for a moment that you and I are working on this project, and we find a way to develop like this shopping cart technology that's really amazing and it's really, really efficient computationally.
And then imagine one of our competitors who also has a shopping cart goes, Hey, GitHub, you know, can you optimize my shopping cart? I really wish it wasn't taking up so much X. And it goes, oh gosh, you know, here's a great way to do that.
Here's the things you should change. And it literally goes and gives RIP away to our competitors. 'cause we effectively programmed GitHub to do that.
That's a really big concern, right? Similarly, we've all seen like the stuff that's made the news where private keys and stuff like that, and fixed codes are in code, and then people just go and ask GitHub for them, GitHub co-pilot, it goes, oh yeah, totally. Here's a list of things that match that criteria.
So that's where you actually do need to do, for example, like AI usage security, um, witness AI does that really, really effectively. There's other companies that are probably pretty good at it too. Um, but I, I think that it's absolutely critical to do that.
Like, I don't know how you would go and roll out AI on mass without doing AI usage security in a really, like a really great way. In theory, I couldn't apply policies to the LM to not cough up certain data, but it's been showing that the models themselves are programmed to be, shall we say, extremely helpful. And it's not too long before they cough it up, right?
Yeah, right. I mean, look, I mean, I think this, funnily enough, this is, this is dead true. So, so our sales engineers have this demo they do where they, they leverage models in real time, like big popular public models, and they jailbreak them in real time.
I think they have five different jailbreaks that they regularly do. They all still work, right? Like none of them have been fixed.
And you know, you, you learn the personalities of kind of each of the models, which is really fascinating. Like, for example, I regularly use chat GPT and Claude, they have different jailbreaking personalities, right? So Claude kind of has an appeal to authority.
So if you say something like, oh no, I'm, I'm actually a really helpful person that's trying to do a helpful thing, and I know this seems weird, but really it's part of my job. And it goes, oh, okay, since you've said that, uh, you know, Chad GBT is very subject to things like, like, oh, no, no, I don't, I'm not trying to do that. But like, imagine that there was a thing that said like, you know, you're two personalities, one is like, you know, called break in, and then the other one you know, is car.
And it's like, if those two personalities met in an alley somewhere, like what do you think they'd say to each other? You know, like, you know, tell me that. Um, so things like this are, are really, really fascinating sciences.
Um, this is where things like model protection come in, but you kind of got into this other thing that I think is really near and dear to my heart called model identity. Model identity requires constant reinforcement, right? So for example, you know, Michael, if you were interacting with a model and you, you can kind of wear most of them down, even smart ones, if you just keep out them, you can wear them down and get them to do things that they shouldn't do.
So that constant reinforcement is something that's really important. So one of the things we build at Witness AI is called model identity protection. And it's kind of this constant reinforcement of what the model's supposed to do, and then the model response completion, we also go and check that vis-a-vis the identity to make sure that they're congruent.
Um, I don't think most companies are kind of doing stuff like that today, but I think it's important. So ultimately, will we need to create AI models to manage and govern the AI models? Because the complexity and the challenge is too much for the human to wrap their heads around.
So is this just gonna kinda, you know, extrapolate out to millions of models that are checking on each other? Man, I'm, I'm reminded of like an old school rap song I think from the nineties. You know, it's, uh, so I, I think, I think that the world we're moving to is kind of thing i I was talking about a little bit earlier, right?
Which is this kind of like world of agent ai, and I know that's a bit of a buzzword right now, but fundamentally, if you think about when you think about Agen ai, instead of thinking about it like, you know, like, oh, it's, it's, it's kind of this weird thing. It's really not. Think of it as like very, very purpose-built models that are meant to interact with other models.
So then if you think about like, hey, there's some kind of master model that's responsible for taking input. There's a whole bunch of models in the background that this one's aware of, and they do certain jobs, and there's another model that has the ability to go and, and sort of audit those jobs and make sure that they did the right thing. And if not, to go back to them and say, this doesn't look right.
You know, do whatever validations and then go and format the output. I don't think that's a bad way of thinking about the future, right? Like, I think that that's kind of a, a good way to think about it.
And it gets us out of the world of like, Hey, I, I go to this thing called chat GPT, that I expect to know everything instead, you might go to like Master Chat GPT that then relies on tons of different models that maybe get licensed or whatever it is they happen to be. Um, but I think it's a good way to look at it. But yeah, fundamentally, I, I don't think it's possible long term to, to just kind of like rely on human beings to do all this.
Even today, by the way, like we rely on AI to help govern and secure ai. Like it's the only way to possibly do it Right? Folks, you heard it here.
Our models will have models and hopefully then check each other in a way that results in something better for everybody. Trevor, thanks for being on the show, Michael, and absolute pleasure. Thank you for having Me.
Thank you all for watching the latest episode of the Techstrong AI video series. You can catch this episode and others on our website. We invite you to check them all out till then, we'll see you next time.
Hey everyone, I'm Alan Shimel. That's Luca Gallente and you are watching the Platform Engineering Show. Hey, Luca, happy New Year.
It's great to see you, my friend. How are you? You too.
I'm good. How are you doing? Happy New Year.
Happy year everybody. Yeah. Happy New Year to everyone.
So, Luca, where let's play. Where's Luca? Where in the world are you today?
Man, East coast is Sri Lanka, The east coast of Sri Lanka. That's great. And it's nice and warm there.
You're on the beach. Yeah, I freezing, I apparently tour than in Florida, right? Yeah.
Well, winter, winter came to Florida, right? But we got this around this time of year, we'll get like three, four days. I was telling you where it, sometimes it'll go down even into the high thirties, low forties, fa night.
And then the, the, uh, the iguanas that are, they're not native, but they're invasive here. They, they get frozen up in the palm trees and they go what they call topi, like, you know, they just shut down and then they fall outta the trees. And some of these iguanas are like four feet tall.
I mean, they're big, they're big reptiles, so you don't want 'em falling on your head. You'll get hurt. But, uh, this is so Fascinating to me.
It's crazy. It is crazy. But, but, but do they recover or are they dead?
Uh, It depends how long and how cold they are. How long, because, you know, with Gus are usually like that nice green color, and then when they're in reading colors, they get red and orange. When they get topi like that, they turn gray.
It's like they really Yeah, it's a good dark. They look like off. Yeah.
Um, crazy. But yeah, we'll see. I mean, no, they're, they're kind of like a nuisance animal here.
So people aren't terribly upset that some iguanas die. Uh, they don't belong here and they just, they're a mess. They're a mess.
Right. Anyway, enough about iguanas. You're in Sri Lanka.
There's a lot going on in the world of platform engineering, though. We got a great topic to cover today. But before we do, I wanted to just go over with you a few things.
First of all, we're making plans here to head over to London for Cube Con. I think it's April 1st to the fourth is the actual cube con. Um, but I know the community has, has some real big plans going on.
You wanna share a Little? Yeah, it's gonna be, it's gonna be a big one. Um, cube Con, right?
In London, they're expecting 12,000 people. And so we do our sort of like unofficial cube con opening party, which is Coha Cube. We've been doing it now for like two or three years.
It grows every time, expecting a lot of people. Probably like 4,000 plus signups. There's probably gonna be like 500 people, 600 people at the location.
It would be pretty crazy. And, and you know, the whole thing about cubes, like we started it when I think we were at CubeCon Valencia and it was basically, oh, I Love that. We were kind going from like, which was great 'cause it was like CIA and so on, but we were basically going from like one party to the next, or like, man, all these parties are the same.
Um, and obviously, you know, we have like a Berlin background, uh, techno background. So we were kind of like, wouldn't it be funny to do the sort of like, uh, the dark room of DevOps? Um, and for those that catch the reference.
Um, and, and, and so it started like as, as a joke, but we did it. Um, and it's really funny 'cause it's always, there's a bit of, bit of a tension with the CNCF guidelines that basically don't allow you to stay in the dark room of DevOps. Um, but um, yeah, so we started and, and, and now it grew to basically really become the unofficial opening party.
You know, we have like drag queen shows and it's a whole thing. So, so that's gonna be really Fun. Really.
Oh, Very cool. Um, yeah, yeah, yeah. Looking forward to that one.
Kind Of like Key West Yeah. Down here. We, that's, I dunno if you've ever been down to Key West, but they lot of that No, but I heard, yeah.
Um, yeah, yeah, it is. Yeah. Well there are other places that are more, but anyway, um, I digress.
Let, where can people get more information about House Cube? com. Um, and you could sign up.
It's free. We have, uh, amazing food, amazing drinks, amazing drag queens, so just kind of was fun Post party. We're gonna do that.
That's fun. That sounds great. And then the other, you know, big thing on the horizon, and it's not too early to get this out there, is, this is the third or fourth platform con This is coming Up in June 4th Platform con.
So we started 22. Yeah, that's right. Um, we had like, I think like 6,000 people or so joining virtually.
Um, then we had count 23, we had like 20,000 at 24 last year we had like 35,000 or something, and then expecting like over 40,000, um, this year. But the important thing this year is that we're really doubling down on the in-person components. So we're gonna have two live days.
One in London, one in New York, both around like four or 500 people. Uh, you know, we have great speakers, Nikki wa Gregor Hope, Kelsey Hightower speaking, uh, these things live. So really excited about that.
It's gonna be last week of June. So London on the 25th of June. And, uh, New York on the 26th of June.
Uh, so it's gonna be fun to like hop between one city and the next. Um, but the, I think the events are gonna be great. We're gonna have parties.
We, we have like a lot of great like, speakers live trainings, a lot of new formats that we're rolling out for this. com. Um, and you can choose your, uh, choose your own adventure, uh, and join us either virtually or in person London, New York.
I think Techstrong TV will be in New York. I'd love to come home to New York. Um, and we'll be broadcasting live from there as well.
Yes. So it should be a fun, fun, fun thing. com.
Yeah. Right. Fantastic.
Uh, speakers are, all speakers have been assigned. What about sponsorships available? Yeah, sponsorships still available.
Um, almost sold out of New York. Um, that, that's gone pretty quickly. Um, and, and you know, we're closed with London, but there's still, there's, there's a lot of like, you know, um, there's like, also virtual sponsorships are still open.
Sure. Um, so anyway, sponsor sponsorship's still open. Um, and there's a lot of like, interesting formats that, as I said, we rolled out the trainings, but also, you know, we're gonna do live interviews with you in New York, for example.
So lots of new interesting things that I think can be very fun as well to do with, uh, with vendors and other sponsors. Very cool. Very cool.
Alright, Luca, we gotta talk about what we're talking about. You know, this is, uh, our third episode. Yep.
This is our third episode. This will probably be the last one where it's just you and I talk in like this. Well, we gotta bring in some fresh blood, some expertise, and, you know, we'll announce, uh, check marks is gonna sponsor our show.
So many thanks to them for that. We're looking at other sponsors if, if anyone out there might be interested. Um, but for today, Luca, we're gonna talk about platform as a product and look in today's world, right, there's platform as a product because everything is as a service, right?
So here we got PAAP, and I'm sure the next thing will be PAAS, but you know, what does it actually mean when we talk about platform as a product? And, you know, it's a, it's a key part of this platform engineering kind of mindset. But, you know, you're the expert, why don't you define it?
Yeah, absolutely. And, and I actually think is a good place to start from the PAAS that you mentioned, right? So like the, the platform as a service, right?
This is just as kind of like, uh, one of sort of the, the main trends. If you look back like 15, 20 years ago and like Heroku, all those guys, Heroku Star. Yeah.
And yeah, and, and, and, and it was just said you of like, Hey, like don't worry about anything, right? Like, we, we build this like platform layer for you. It's, you know, it's like turnkey, plug and play, let's go.
Um, and, and that didn't really scale to the enterprise, right? Because like everybody realized, hey, you actually need, um, you know, some, some customized platform layer, uh, for your, for your own enterprise engineer organization. And, and that's kind of what platform engineering, sort of like, you know, where we should like platform, platform as a service or pass ends and, and sort of like platform engineering starts is really this idea of like, hey, you're building this internal product or internal consumption, right?
Like your internal customers are the, um, the, your, your application developers. Uh, and you do that as a product, right? And that's like a very, um, it's probably, in my opinion, the key concept, um, the key foundational concept of platform engineering and also the key differentiator, um, you know, of platform engineers vis-a-vis, let's say like doubts engineer or you know, an SRE, um, that, that normally we'd approach the infrastructure project as a kind of like one and done, you know, six months project, something of that kind.
Whereas a platform engineer, at least like a, like a good one, um, a approach is building an internal developer platform, or IDP, which is the end product of APAC engineering initiative as a product, right? So a product that has a life cycle, not that it's, it's not like a one and done, you know, six months thing, but it's actually, it's being rolled out as a minimal viable platform initially, um, for the first few months and then iterate on and then eventually grows. Um, it gets adopted widely across the engineer organization.
Um, right? And, and it keeps being worked on as a product. Uh, and I think it's, it's a, it's a super interesting concept because the moment you look at your internal developer platform as a product, you immediately unlock, you know, 20, 30 years of product management best practices and experience that that we have in the industry that can be applied to build, uh, your internal developer platform as a product, Right?
And, and here, here's the thing, whenever you talk about something as a product, the next logical conclusion is who's the customer, right? Right. And, and, and traditionally that was in it, right?
In the IT department going back, I'm going back now, you know, 25, 30 years. The IT department, the, the customer was the internal business, right? It wasn't sort of forward external facing, it was internal Right?
Facing. Right, right. And, and your customer was the, was the sales guy, the business guy, the marketing person, the HR department, you know, all, all of the above IT service them.
It, you know, they, they were the customer of the IT department. So this, I mean, this is not new in terms of a concept of of of that internal customer that gets served, you know, uh, in this case with, with the platform. The other thing I'll tell you is, look, you know, when, when cloud first came out, a lot of people were very definitive about saying, well, this is infrastructure as a service, IAS, right?
And we're gonna have platform as a service, right? And, and haruku was probably the biggest success coming out of that. But really to a lot of people that meant, well, infrastructure service ended at kind of the hypervisor.
They took care of everything hypervisor and below, and you built on top of the hypervisor os and everything else in IT platform as a service initially to a lot of people was, well, no, everything up through the os. And then you just build your app on top of the os. And I'll tell you, my 2 cents on it, if it wasn't for platform as a service not being sort of a complete, uh, concept, you never would've had cloud native.
I think what we see as cloud native today with the containers and, and cobe and mesh and everything, you know, that old cloud native stack is a better platform as a service or as a result of the initial like, Heroku style platform as a service just not being complete enough, right? It wasn't what we need. And then, so now you got this cloud native stack, and now you have this whole platform engineering kinda movement, right?
Which is borrowing from a lot of what, what's gone on here. And that's the modern platform as a product platform, as a service that I think people were really thinking about back when, but the initial like Haruku versions were, I don't wanna say flawed, but incomplete. They were immature, right?
Yeah. And, and so yeah, I think they, they mm-hmm. There were like a child Of No, that's my 2 cents Of the, of its time, right?
Of like, yeah. Also, like I think stacks that were like a lot simpler, right? Infrastructure that were a lot simpler.
And, and, but then to your point, right, as cloud native exploded as this like complexity really, um, really exploded as well, then you had to have like a completely different approach. So it's like the idea is, hey, I still wanna provide a, a path like experience to my developers, right? Um, and, and, and, and I think like you're, you're, uh, point is super interesting, right?
Like, it's also not only the complexity of the infrastructure exploded, but also the, uh, size of the engineering organization exploded to the point where now you have a part of the engineering organization, the serving the other part of the engineering organization as, as its internal customers and no longer just like the sales, marketing, hr, whatever, right? The other functions. And so, and there is also like a, there's also like a, like a mind mindset shift that that needs to happen a lot of times where it's like, well, actually the internal customers is the developer itself, right?
Um, which is something that a lot of people are not used to because they think, well, developers kind of build stuff for themselves. Well, but the, the problem is like, once you have, you know, 10,000 developers, then you actually need somebody that like, specifically builds stuff for them, right? So, um, but yeah, so the idea is really like, Hey, I want to build a past like, experience for developers, but on top of, you know, a complex and changing and, and, you know, cloud native or hybrid tool chain.
Um, and so therefore, I, you know, I, I, I need to take, you know, the, the vision is the same. I take the tool set, um, you know, in the toolbox of, you know, I borrow it from, from, from kind of like all this other like adjacent disciplines. Um, and then really, like, I focus with this like, product mindset on, on building this like, um, so like, platform layer developer, um, DevX, uh, layer on top of this increasingly complex, uh, stack, right?
Absolutely. Hey, you mentioned DevX. I just wanna give a quick shout out.
We're gonna do our first live round table of the platform engineering show, um, I think early in February. And it's on DevX. So if DevX is something you guys are interested and your folks are interested in, uh, stay tuned.
We've got a live one where you can take part and ask questions, and we're gonna dive into that. Now, Luca, the, the platform is a product idea. You know, it's been percolating now for a couple of years, and we're starting to see, I don't know if I want to call it best practices yet, or, you know, evolving best practices.
I don't know if it's written in stone everything just yet, but we're starting to certainly see where, hey, this works. This is not such a good idea. This is a better way of doing that, you know, we're evolving best practices.
Can you talk a little bit about what some of these are and, and where people can kind of, you know, stay in the know on that? Yeah, absolutely. I think like, um, you know, and as I mentioned, like, I think what's interesting is the moment you treat your, your internal product, your internal platform as a product, you unlock all this like best practice.
Like, so it's not like you need to invent anything radically new. It's like, Hey, there is this minimum viable product MVP concept, it's just being rebranded to mini level platform, which is the same exact letters, and the concept is the same. It's like, Hey, start small, irate quickly, and so on.
Um, I'll cover, I'll, I'll talk about MVP in a second. The, but, but I think like before that even, um, like if we look, I think chronologically, and I've seen the, the space sort of like mature in the last couple of years, you know, initially it was kind of like, okay, like what is platform engineering? Is this helpful for me now?
It's like a lot of people are like really bought in to the concept. Like it's been, you know, compiling like crazy. And we spoke about the, you know, the overall like, you know, numbers about platform engineering as a trend broadly in the other episodes.
Um, but you know, with that, a lot of people are coming in and they're like, okay, you know, I'm bought in. I heard this is where do I start, right? Like, what does this thing actually look like and how do I make sense of this?
You know? Yes, we have like a, like a crazy, like cloud native, and so landscape, you, you can just see the CCF F landscape is insane. Like nobody can actually really understand it, but, um, but even the platform engineering, it makes a good picture.
It makes for a good picture. Exactly. Um, and, and, but even the possible engineering landscape at this point has been developing so much that, you know, it's far from that level of complexity.
But you know, you already have, like, if you're a newcomer in, and it's like, okay, like how do I, you know, how do I actually piece all this, this from, you know, pieces of the puzzle together for a platform that actually works for me that makes sense for my engineering organization, right? And so that's where I think the first sort of like, standard that's been really, really helpful in a game changer thing in the, in the community and, and broadly in the platform of engineering market has been this, this reference architectures for interior developer platforms, right? Um, and, and some of the first ones were, um, open source, uh, by McKinsey actually.
Um, and then, you know, kind of like, now they're like really widely adopted. Um, I have one stat for you on that, which is Platform Con. Um, they were, so the first, the first, uh, reference architecture was, uh, uh, was kind of like presented in the talk at, at Pop con 23.
Um, and so there was only one at Pop Con 24 last year. There were already like 20, 30% of the talks that were using. Um, this is a blueprint to kind of like talk through, uh, the platform that practitioners built or whatever, right?
So very, very interesting to see like how quickly people adopted this. And it's for a very good reason. It's just like, it gives like a really good guidance as to like, okay, how do we see, how do you think about the different pieces and how do you fit together?
org, I think slash tooling or slash platform tooling is, um, you can see the sort of the tooling landscape there. And that also follows the same structure, um, as the, as the reference architecture. So that was kinda like a first step that was really helpful.
But then sort of like, what I've noticed is that people were, um, kind of like looking at this and like, okay, great, that's, that's my target setup. Like, that's how I want to build my platform. Um, but then they were trying to do everything, you know, at once, um, like, you know, the, the, the Korean movie, like everything everywhere, all at once.
It's kind of like, it's kind of like, like that, right? Like, they were trying to like, okay, like this is great, you know, they get super excited, you know, I get buy in some executives, let's go, you know, build everything, right? And the problem with that is that, you know, you very, very easily lose momentum, right?
And this is, I think, in my opinion, is the number one cause of death apart from engineering initiatives, uh, to be a bit morbid, but it's, um, it's really, it's really like that, right? Like it's, it's people that get really excited that have this like brand designs, um, for, for what the platform is gonna look like. And the problem is that the platform engineer really is a huge, you know, org transformation, right?
And so, uh, and so that means it touches all these different stakeholders, application developers, executives, architects, security teams, infrastructure and operations teams. And so you need to basically get all these people on board with you, you know, sell them effectively, internally, this idea of the platform. And it's different components that you have like so beautifully designed in your head.
Um, and, and so the problem is like, it's very easy to lose momentum there, right? Because you need, you know, by the time you, you know, you spoke to person A, B, C by the time you, you spoke to person Z, it's been six months person a completely forgot about you. And, you know, you kind of get stuck in this process, right?
And, and there the trick is really to take this minimum viable product or minimum viable platform approach of saying, Hey, start small. Um, focus on like a really, like a subset of, um, uh, not only the problem that you're solving for, for different stakeholders, but actually a, a a subset of the stakeholders, right? So just focus on, on maybe like application developers and security teams or, you know, infrastructure, infrastructure operations team and executives.
Really, you don't have to please everybody immediately just focus on like, what's the low hanging fruit here? And then if you think about that reference architecture that maybe we can link in the, in the show notes or like throw up a picture at some point, um, we can, you know, you can, you can, you can think of like, well, let's, let's actually focus on a subset of events, right? You don't need, you know, your MVP to have a full, um, you know, to be fully security compliant, uh, or, you know, have, uh, you know, the, the latest observability stack built in already.
'cause you, you're not going to production right away with this thing, right? You need to first show the value to, for example, developers and say, Hey, look, you know, Jimmy right now is spending, um, you know, like, um, uh, is, is is waiting like two weeks every time, uh, he wants, he needs a database, right? Um, and, um, you know, and is providing that, um, um, but you know, now she's like fielding this like oldest like ticket helps request, but like 40% of her time, and that sucks, right?
And so what you want in the first MVP is, is to actually show, okay, well I, you know, I, I proved, uh, you know, for example, I reduced the, the, the time that Jimmy needs out for database from like weeks to minutes. And now Amy only needs to spend like 10 minutes, 10, you know, 10% of your time fielding ticket requests, not like 40, 50%, right? Like, and you know, and, and you can, you can show that within weeks, right?
That's really the powerful thing I've seen, um, like very large enterprises move incredibly fast following this MVP framework, um, and within weeks show some level of success internally to the, the stakeholders they selected. And then from there it's like, okay, great. Are we all happy?
Yes. Okay, let's go to the next iteration, right? And then of course, you should have, like, you should design the end design with, you know, security in mind, for example.
But it doesn't mean you need to implement all the latest governance and security workflows from the get go. 'cause this is gonna slow you down and not gonna get you to actually show value. So, um, I think reference architectures and MVP framework have been, um, very, um, very helpful standards and very helpful best practices that, as I said, you know, we've been borrowing from existing, existing disciplines already, um, and just like slightly tweaked, uh, to, uh, to really help platform teams deliver on their, on their initiatives.
Excellent. Excellent. I mean, Luca, if I, if I had a boiler, it's a bad word to use.
I'm gonna use that word. If I had to like, just really give people in one little line here, right? You, you, you don't wanna boil the ocean with platform as a product.
You want. I you want to do it step by step, bit by bit. Here's my question for you though.
Do you need a master plan to begin with saying, okay, here's I, here's step one through six. It may take me three months to do step one, four months to do step two, four months later I'll do step three, but eventually I'll get to step all the way through to step six. Or do you just say, well, let's start with step one and then I'll decide what even step two is.
'cause I don't know if I want to make that, what, what I'm labeling now is step three may wind up being step two. Um, right. So I'm not, I'm not locking into any of that.
I'm just locking into step one right now. Totally. I think it, I think it, um, I think it's a mix of both, to be honest.
org actually has like different tracks. Like you have an executive track or business track, you have like a technical track, which is basically, you know, how you build everything, how you get the first like developer adoption, you have a security track audio, you make the security team happy, right? And I think like different tracks have different timelines and you need to write.
So like, I think for security in business for example, it is helpful to have a little bit of, you know, like a look into the future, right? Um, and like how do you attach, because you know, for example, like your business, your business stakeholders, like your execs, like, you know, usually thinking quarters or even like fiscal years, right? So like how do you attach, you know, your Python engineer initiative to whatever their goal is, for example, for, uh, you know, for the quarter, for the year, um, in some cases multi-year plans, right?
Um, on the developer adoption though, on the other hand, like, it's really what you were saying, um, it, it, it doesn't make sense. Just, just get started. Just get started, figure out, you know, what works, what doesn't, and then I from there, right?
So, um, I think there's a combination, and this is also I think where it's helpful to think of your platform as a product. You know, you know, we've built product, um, uh, products and, you know, the product is not just about building a product, it's also going to market with that product, right? So, um, and so that's where you have, you know, I think you have basically your product engineering teams atating very quickly on building a product, especially at the beginning, right?
And then as your platform matures, you can have like longer plans and like longer iteration cycles and so on, but at the beginning you want to be very nimble, right? Um, um, and the same thing kind of like goes for your go-to market at the beginning, you really need to figure out, okay, you know, which executive is gonna support my initiative and so on. But then like over time as it matures, you know, really like attach it to like, you know, very specific budgets or combination of budgets and so on, right?
Um, but it, I think it's, it's helpful to, to to, to not only think of like platform as a product, as something that's like purely technical in terms of like, how do I drive developer at auction and how do I, um, you know, you know, I to rate res from a product perspective, but really broadly, like if you consider it as a product, it means like it actually needs like its own go to market, uh, its own internal marketing and internal sales effectively. Um, and actually you can see this, I was, I was talking, uh, a while back to R Ericsson, who's the guy that that built the, the, the term development platform is Salesforce, five years plus go. And you know, it's very interesting because, because Salesforce is so big, actually at the time, they had multiple platform initiatives sort of like bubbling up and competing with one another.
And so there you have even, and obviously like in, in most organizations you wouldn't have that, right? Um, but Salesforce, because they're so big, um, but there's some cases of like very large engineering orgs that have, um, similar situations. Um, and, and in that case, really you're competing, right?
And you're competing on the product front, but you're also competing on like distribution On the platform. Yeah. Yeah.
But I mean, look, you see that in large enterprises that are built through m and a, right? Where you, you have, you know, company A was doing this, company B had that initiative company, see now they're all under one, you know, big company. com days, right?
We had 30 different acquisitions and each one had their own, you know, not platform per se, but their own it, their own, they were all, they were all, they were all storing websites. They were all website hosts. So there was 30 different platforms to coast websites on how do you pick one, or eventually you do want to get to one, but it took a really long time because you, you can't, you know, you're gonna wind up raking some eggs making that omelet.
And, and, and, and so you, there's a, there's an art to that, right? That's, that's a whole thing in and of itself. And, And, and how did you, how did you think about that?
Like, how were you Well, we went bankrupt. Like what, what we, I mean, we, I, well, because the do com that's easy bubble. That's, yeah.
That made it easy. I left, but No, but seriously, what we did do is we, we brought in, we, we developed one engineering team across all 30 acquisitions, one engineering team. And they basically took from each of the acquisitions what was best about them, what was the strengths, and then also looked at the wider state of art, right?
In the industry. And, and, and we did, we, we actually built a whole new platform that we migrated these two. Some, some were easy migrations, some were a lot harder migrations.
But we built a state-of-the-art. 'cause back then, look, we, we had some companies that were using what I call baker racks like that you would keep bread on and they would keep white label servers on there. The hard drives are in the server.
The servers running Apache and they got a thousand websites on there. Right. Then we had other ones that were running like one U servers to network attached storage.
Right. A very different kind of architecture. And we had other ones that, you know, had, would load balancers and st you know, there was, there was a variety of, of, of architecture here and, and we settled on one and it took, it took the better part of a year and a half, two years to really migrate into this standard.
The company was called Inter Reliant into the standard inter reliant architecture, which, which by the way back then was like IBM Domino Server or something like that. And, you know, it was, it was big enterprise level stuff. We were hosting a lot of apps.
It was before there was cloud, you know, multi-tenants and all that. And we're hosting Oracle apps and Lotus Notes and, and Exchange and PeopleSoft and, you know, crazy stuff in addition to websites. So we needed, and that's actually how I got into security.
Then we had Layer Security in Checkpoint at the time. Was it, you know, checkpoint was the big firewall, right? So we had managed checkpoint firewalls in front of this stuff.
It was, it was really cool. 'cause we were way before our time way, way, way before our time. Right.
Um, but it was, it wasn't anything like, we didn't have at our fingertips what, you know, platform teams have today. Right. We were inventing this stuff outta rock and chisels, you know, you didn't, you didn't have the tools we have today.
But it was interesting. It was interesting. That's so interesting.
That's so interesting. And actually it's something that, like, we are seeing a lot in the community as well. Like, we do this, uh, this trainings with large enterprises, um, where we kind of like help them either educating their teams or actually like putting together strategy for the rollouts and, you know, phase rollouts and so on.
And I was actually working with like, um, okay, I think it's public right now, but anyway, it's like a very large, maybe the largest, I think CPG merger ever. Um, and you know, it, it's kind of like you have these two teams and they, they sort of like are gonna go in Right. It in, in gonna end up in the same setup.
And, and so like one of them wants to figure out, okay, what's the right strategy for me going into this, right? Because I have like, something that's working right now, but obviously everything is gonna change. So like, how do I, how do I make sure that my platform evolves in a way that it ends up being the winning platform, right.
Uh, from an evolutionary perspective, it's the one actually surviving in the end. So, very interesting. These sort of like m and a conversations where you really see this like yeah, like internal products competing with one another.
Yeah. You also see personalities competing with one another, right. And that, and that's sometimes the personalities are harder than the technologies, right?
And, and, uh, that's a whole nother story We could talk over beers one day about. Anyway, uh, Luca, this has been a fascinating discussion, man. I loved it.
Um, Yeah, this is fun. org, we've got reference architectures, we've got tools and people and documents out there to help people as we go on, as they set, you know, set sail on this journey of, of, you know, adopting platform as a product. Um, wow.
What a great show this was. Let, let's can't wait for the next one. Next one.
We'll have some people joining us so it'll be more of a active discussion, but we hope you enjoyed this, Luca, how long you in Sri Lanka? Ah, three more weeks. Yes.
Um, alright, so maybe for the next show, you'll still be there. Um, no, no, no. The next show is in February, so we're gonna Oh, okay.
Yeah. Be, yeah, because these are almost mid-January. So where, where do you think in the world you might be by then?
Japan maybe. Um, I am, you know what, there's a cube con in Japan in June. I was really had my eyes on, but we'll see.
Yeah, it's a small one. It's only two days, but, uh, okay. You going check it out.
It, I might, I might. I'm looking for an excuse to go to Japan, so, all right. Yeah, yeah, yeah, yeah.
We'll see how that goes. I'll let you know. Yeah.
Anyway, though, until then, enjoy Srilanka. We hope you've enjoyed our, the Platform Engineering show. It is out episode three.
If you haven't caught the first two, you can, they're available on your favorite podcast platforms like Apple and Spotify and all of that. Also on text Drunk tv. And, and they, uh, text Drunk TV is the website.
They're also on the YouTube text, drunk tv, YouTube, and I think by the, well, hopefully by the next show, our Text Strong TV OTT channel will be up. So you'll be able to catch it on Apple TV and Roku and Amazon Fire, as well as mobile apps. But until then, this is Alan Shimel, Luca Gallente.
I hope you've enjoyed the show. Take care, everyone. Thank you, Alan.
Bye. Bye-Bye. Thank you everybody.
Hey everyone, it's Alan Shimmel, CEO of Techstrong. Thank you for joining us on our, I think it's eighth or ninth annual Predict conference. This is where, you know, some of us put our necks out on the line and make some bold predictions about the year to come.
And maybe sometime at the end of next of the end of this year, we will go back, revisit this and see where we crazy. Or did we know what we were talking about? This is a keynote panel for Predict This Year.
We have a whole day worth of predictions coming from, from really smart people. And this panel's no, no different. I've got some really smart people, much smarter than me to talk about what is the future for DevOps and DevSecOps.
What are the big stories to watch in 2025? com 10 plus years ago. DevSecOps burst on the scene, and a lot of it's become a real thing, as you're going to hear from our guests.
But there's also been a lot of changes, a lot of turmo in the last year, year and a half, as things like AI and platform engineering and software supply chain security have all kind of burst on the scene. And it's, it's pushing and pulling DevOps and ways we probably didn't imagine. Our panel today is a great panel to discuss these topics.
Let me jump in and introduce them to you, first of all, joining us, and we recorded this, and he was kind enough to come on late in the evening. His time is my friend Kobe Reiser. Uh, Kobe is the CPO at check marks.
Kobe, welcome. Why don't you give people a little bit of your background, though? Yeah.
Uh, thank you Alan. Uh, really glad, uh, really glad to be here. I'm the Chief Product Officer of, uh, of Checkmarks.
I'm leading, uh, within checkmarks. I'm leading, uh, um, engineering, uh, product management and security research, uh, for the last four and a half, four and a half years. Um, I am actually leading the, the, the, the building, uh, the development and building of our, uh, check marks one, uh, platform.
Um, our legacy product is an on-prem product, uh, and we completely shifted to the cloud, and this is what I'm happily doing. Absolutely. Thank you.
Thank you again for joining us, Kobe. Appreciate it. Next up is another friend of mine who's a frequent, uh, visitor on our tech strong TV show.
He's Nick Durkin Field, CTO Harness. Hey, Nick, why don't you tell, introduce yourself a little bit Very well, and thank you so much for having me on. Genuinely appreciate it.
And, uh, look, uh, joined Harness is employee number nine, almost eight years ago now. And so watch it grow from, you know, a small, uh, startup in its alpha stage to, to now helping the largest customers in the world solve secure software delivery and, and leveraging ai. So glad to be on here helping with this, uh, phenomenal panel.
Fantastic. And thank you for being here. Joining us is a newcomer to our tech strong TV and tech strong event family, but certainly her company is no stranger.
It's GitLab. I wanna introduce you all to Sabrina Farmer, who's the Chief Technology Officer at GitLab. And Sabrina, first of all, welcome.
Thank you for joining us. I hope this won't be the last time you, you, this will be a good experience for you. We'll see you often on Tech Trunk.
Why don't you give people a little bit about your background? Yes. Hi everybody.
I am Sabrina Farmer. Um, as you say, I am the Chief Technology Officer at GitLab. GitLab is the most comprehensive AI powered DevSecOps platform for software innovation.
I have been here for almost a year now. Um, prior to that I spent 19 years at Google doing essentially production engineering and also infrastructure engineering. Um, really happy to be here, excited to talk about what's the future.
Thank you. We're excited to have you here, Sabrina. Thank you.
Last but not least, my friend Paul Davis, who's field CSO at what a collection. We've got Field CTO Field cso, chief Technology Officer at CPO. That's, that's impressive.
Paul, why don't you tell people a little bit about yourself. So, yeah, really humble to be part of this. Uh, this panel is brilliant.
So there's some real power players here. Um, so yeah, I am a former Fortune 10 CISO slash soc ir, but also as described myself, I'm a reluctant developer, uh, programmed and had software houses and build software in 12 different languages. So I'm sort of melding that with business risk and everything to help, you know, push forward the vision of a secure software supply chain using jfr and integrating with many of the colleagues here, as they say, to create that secure software supply chain.
So, very much sort of focused in that area. So thank you. Thank you, Paul, and thanks for joining us as always, and thanks to our friends at jfr.
So, you know, guys, as I said, off camera or before we started, those who don't learn their lessons from history are doomed to repeat it. 2024 in 20, the last half of 2023 has certainly seen some churn, upheaval, tumbled within the DevOps DevSecOps space. Um, if I had to ask each of you, what were your, what were your big stories or big trends in 2024 that we think we should look ahead to going into 2025?
What would you say they were? Sabrina, you are the newcomer here, so I wanted to give you first, first dibs. What do you think were the big 2024 trends and stories that we need to learn from in order to look ahead?
I think, you know, obviously the big topic, what everyone's talking about is ai. And I think over 20, 24 people were trying to figure out how to roll it out. What does it mean, what does it change?
Everyone thought they needed it, but they didn't really know what to do with it. And I think there was a lot of experiment, a lot of, we spent, um, and a lot of lessons learned. I think what I, I'm excited about mostly is as you come to the close of the year and agents become something that's more of a reality, you really see the opportunity to apply AI to improve how people work, right?
And I think that it took us a whole year to get here, um, and to really start to believe that it was possible. But, you know, we are seeing people look at not just how to develop code, but also how do you operate the systems that you're building. And, you know, having worked in production engineering for so long and, and AI for, you know, even longer, um, I think that to see this reality is really exciting and really trying to get people to really embrace it is, I think what we have to look forward to next year Panel.
What do you think? Wow. I mean, ai, I think myself personally, it's, I'm starting to see glimmers of hope.
Um, as a security person. I'm a pessimist and paranoid. Um, so, you know, there are gaps there that I, that I, I want to see better AI in the world of the actual supply chain as opposed to just the developer experience.
Mm-hmm. But I'm seeing now some of those coding agents helping developers and getting to a point where I can start to trust them. Um, but there's still a long way to go.
And I think also from the perspective of a regulations, I think we're just starting to see inklings. Europe is scary because they put teeth under regulations. Uh, I, I'll be blunt, I think we need to do that in the US as well.
Um, 'cause there's accountability across the board. But I, I'll pass it over to Nick Fre. I don't wanna hog the mic, but my Nick, for your perspective.
No, I, I can, you know, I think you're right on the AI side, I think one of the things also we've seen is that we've seen people now unifying on singular platforms and getting away from point solutions. And I think it was one of the things that we actually talked about last year, Alan, yeah. Uh, was this was gonna happen, that people are actually starting to unify on platforms and they're, they're getting away from, from, from grabbing all these point solutions.
And I think that was something we actually saw. And, and to good measure, right? We saw people actually gaining a lot of value, gaining velocity, adding security into this, because now it is one, one platform versus, you know, having to bolt and spending the time, you know, bolting together and writing the glue code versus actually being part of a platform.
Kobe, that's check marks one, right? Yeah, exactly. That's check one.
We, uh, I fully agree, uh, we saw a lot of consolidation, meaning, uh, people are kind of do not want to run point solution, have multiple vendors, uh, get themselves and their, uh, developers and users, uh, and security people, uh, confused with, with all them. They want to, they want to consolidate. So we saw that we actually, this was one of the, uh, main objectives of check marks.
One, have a one-stop shop for, uh, application security testing. We also connected it with the runtime in order to provide runtime insights. That's actually changing the way security is done on, on the left hand side in, in the pipeline.
Because you can give, uh, you can give runtime. You, you can, you can provide runtime context and then give more actionability and confidence in the results, uh, because, you know, it's, it's running in, in right time. Uh, I also agree with Sabrina, like, ai, like 2024 was the year of, uh, okay, what do we do with ai?
And, and, and I think that it's, uh, you know, I think that that, that, you know, a lot of our customers kind of came to us and say, okay, we know that we need ai. What, what do we do with it? So we kind of, uh, we kind of, uh, put in place, uh, um, a strategy of, uh, protect, um, and we're protecting the code, uh, mainly on, on the developers end side.
We have integrations with, yeah, we, we have like integration with, uh, uh, with copilot and, and, and tools like that. We also have a tool of our own, which, which actually provide best security practices as, as code is being written. Remediation, okay?
We're talking about pipelines. We don't want to run the, uh, we don't want to run the pipelines 10 times until we get the, until we get it right. So Remedia, AI, remediation advice, and also secure LLMs, this is more of a 2025 thing.
Uh, you know, we see people going more and more into open source l lms. I think that this is going to be the next big thing in 2025, and people will like to, to protect that. And a lot of supply chain, by the way, uh, we invested quite a lot of supply chain, uh, especially in malicious, okay.
Kind of the SCA part is, is kind of figured out, but the malicious part isn't, uh, isn't meaning let's say if I'm taking a, actually, if you use an open source, you're actually taking code from Stranger. How do I know that this stranger didn't put anything malicious in it? So kinda, we invest a lot of research in that, and, uh, we're trying to bring this value to, uh, uh, to, to customers.
You know, what's interesting is, at least two of you up here, your companies are open source companies, right? And so you're not getting code, you know, is it, is it from strangers? Yes.
Is it from, it's somewhat from strangers, but perhaps untrusted sources, right? Especially if you are maintaining a, a, a, a repo like Artifactory or something. But I wanted to return to AI for a second because that is the big, I think when, when people look back five years, 10 years from now, 2024 will be the year AI went big.
It, it dominates. But I think also when we look at 2024, it'll be the year that Gen AI went big gen ai, right? This whole, the idea of the co-pilot, and I think all of you have some sort of copilot type of functionality built into your products now or are coming out with them.
But I think when we look ahead to 2025, gen AI may not be the big AI story. I think, Sabrina, you mentioned it, a agentic AI may wind up being the real story, not just for 2025, but going forward, I totally agree with that. Totally.
That I think that's really the power. I think, you know, the press likes to talk about the code, the de developing the code, the code aid, right? And I think that's true, right?
But ultimately, that's still up to the software engineer, whether they accept it or not. I think it's really the agents that are gonna unlock the power and really help us find the next opportunity. Free up your people so that they're really thinking about the next innovation that we should have.
I have to say, I'm pretty surprised at how quickly AI has gotten into the DNA of not just tech companies, but the average user. They're very comfortable playing with it. I think that's surprising.
I do think with large LLMs really made it accessible. And so I think we'll see this accelerate a little bit more in, in how people learn how to commercialize it. But really, 2025 is gonna be about the agents and how people put it to use.
And I think to Paul's point, like the regulation is coming, right? Compliance is not getting easier. You can't staff fast enough today because one, this technology's really expensive.
Um, and so I really think this is what's going to unlock the power of what AI can do for companies and the users. If I could Go ahead, Paul, I was just gonna say the, the I as a geek as a techie, um, agentic AI is really, really exciting for me because I've always won. I, I, I have a personal assistant, people know me.
I wear little gadget on my shirt. This is my personal assistant. It's an AI agent, right?
But it's, I don't trust it. But the thing that I get scared about is, um, I think we could see us repeating the same mistakes we did with ai, with Agentic ai. The same acceleration path is coming along where people have false expectations around it, have these grandiose ideas, and the reality becomes, ooh, actually we need better controls about where can't trust it.
I remember in one situation where I was doing automation and one particular customer shut down everything because they managed to do a self-inflicted denial of service. Mm-hmm. The agent ai, letting it make decisions by itself scares me.
Okay. I'm, it, I'm paranoid, but I, I think I, I, you know, as you said at the beginning, Alan, if we don't learn from history, we're gonna make the same mistakes. I think we need to apply the same disciplines we talked about.
Like, um, LLMs being weaponized, I'm marketing weaponizing. L LM sounds ho exciting, um, malicious. Um, but from the perspective of we are now realizing that the data scientists are developers and are being targeted, and that the, the, the models, the ML SecOps model needs to align with the sort of the traditional SecOps.
We also, and we are learning disciplines and stuff like that. And so I'm sure everybody in this call is saying, but I think we need to basically make sure we, we apply some discipline. We don't set false expectations.
And I don't know whether people agree with that, but I'm a little bit concerned that I have high expectations, but I'm cautious. Others might read that magazine and go, oh, let's do this. And we lose control.
I have a, I have a fun take On it a little bit. And, and by the way, like this comes from, you know, and Harness came out to the market actually in 2018. It came out as the first software platform using AI to actually remove the worst part of people's jobs.
And it wasn't about taking the best part, we didn't go after coding because that's what people loved. We went out after all of the things they hate doing. So babysitting, deployments, waiting for tests to run, all of those things.
And so what's interesting though is, you know, a lot of people talk about agentic AI actually mirroring human behavior. And I actually think this is, is actually opposite. I think we are actually going to mirror agentic behavior.
What we're gonna do is we're gonna empower people to do what they love. I know that's the weird one, right? But the reality is each one of these agents dives down and does something specific, right?
But if we're focused that on what we hate doing, right? And all the things that, that, that, that, uh, are the things that we put off till tomorrow, let Theis do that, and now spend our time focusing on what we love. When you get someone who's locked in doing what they're passionate about and not having to focus on writing a terraform or a groovy or like working on all the extra pieces, let them do what they're phenomenal at.
Now we're actually empowering our people, and it actually brings harmony amongst all this, as opposed to like having it be combatant. So I think it's, it's a huge future. It's a huge opportunity.
Um, and I'm really excited about what we're, what we're seeing in the agent AI space as well. I think that the main challenge with Agent AI will be to manage all these agents. Yeah.
Yep. You know, you will, you know, you will have, like, you know, you have an LLNI know tens, hundreds of agents, you know, each developer will put in what, what, what each one of them do. And, uh, what, what do we, the, the sequence of of of, of what, of what they're doing.
I think that this Is the, well, you're just thinking about one developer to many agents, or one, each developer has their own agents. So you have many developers. One times when one developer has 10 different agents, right?
Mark Benioff, uh, spoke, I think it was just yesterday or last earlier this week. Well, by the time people watch this, it was a few weeks ago, you know, and he said, we're all gonna have all of these virtual employees. He calls them that, that will, you know, we may have thousands of them that are out there doing tasks for us.
Some, some agents will be one trick ponies, right? They'll do one thing, they'll do it pretty well, but they only do one thing. Other agents will be more general agents that are kind of alter egos for our digital presence.
Other agents will be managing agents, you know, agent managers of other, I mean, the, and I imagine to yourself just to troubleshoot an issue that comes from a customer. Oh, yeah. Navigate between all the, okay, what, what kind of, what, what the hell is going on here?
Uh, but I mean, this is, this is a, this is the world we could be looking at and we need to, we need to put some order, some order in here, right. To, to, otherwise it's gonna run amok. I dunno, if any, I think Kobe Okay.
Sorry, Sabrina, go ahead. Please talk. Yeah, I think Kobe makes a really good point, right?
If you really wanna think about, um, unlocking the power, you should also think about the management of all of these things coordinating together and who's gonna create the controller for this, right? And to Paul's point, like you still need the oversight, right? Automation has, you know, I've been automating production systems for a long time, and I can tell you like, you can shoot yourself in the foot just as well as an agent could.
That's not, that's not new really. I think it's just a new way to look at it. Um, but I think that Kobe's highlighting a really big important thing for people to think about as they start creating these agents and automating them, is you do need to figure out how do you coordinate all these things together.
Um, I I, I agree. I it's gonna be interesting. And I'm not even touching on the security implications of having agents running all over the place.
This is why, this why I talked about control, not even secure. Yeah. It, it, it is.
But on the other hand, I mean the, the, the things that it opens up the, the possibilities, right? Are pretty exciting when you, when you really think about it. And then, you know, and Benioff, and, and granted, he's a great marketer, right?
Give the man credit where credit's due. He is one of the best in terms of marketing. But when he refers to these agents, he interchangeably uses the word robot.
Is an agent a robot? And is, is a robot something that does physical task or is it also just a digital robot? Right?
And, um, and, and once we start marrying AI to robots, what, what does that mean for our, the way of life, right? Um, I mean, it's, it it's a brave new world in many ways, right? That, that this, And in some sense, you know, bots are kind of the same concept of agents.
Okay? Kind of. I did that.
I think that's what he's getting at. Yeah. We, we did have it, like we did have these software bots, but I, I, I think that that kind of the options are, are kind of the, the, the limit is the sky right now because be, be because of the, uh, gen ai which is behind it.
Uh, this Everyone could be, I, I think you're gonna see An actually an interesting Turn. I think you're gonna see people overuse LLMs and overuse agents where they're gonna use these massively expensive things that, that, that do very basic tasks. It's back to the times when like people's, you know, like using this massive amount of ai when in actuality you could just be doing math, right?
So instead of doing creative, uh, ai, you do Automation. Well, you point up is a bunch of wies just fat corporal people on chairs and, you know, the ai, we can't do math without a calculator, Right? I I, yeah.
I, I think, I think people actually have to focus and realize, like, do we automate this? Do we do predictive modeling? Do we use generative modeling?
Like, and actually using the right tool for the job. 'cause I think right now, people are just throwing everything at, at Gen AI right now and, and calling it good. But in reality, that could be two lines of Java or two lines of go instead of a massive LLM.
And I think that's, that's some of the challenges. Well, well, you remind me of, uh, uh, I've met, uh, one of the DevOps leaders, uh, a few weeks ago and told me, you know, my job is to watch as much Netflix as I can, meaning the automation dev should, should, should do everything. So, uh, what what you said about the, uh, agent AI reminded me of that.
Absolutely. So, I, I think, Nick, you said at the beginning, we should be using it for the, I, I like to say I want people to use to start using their brain, stop doing the boring stuff, right? Yeah.
Um, I think it's really fun that we're all saying the same thing, which is we need control. We need to set our expectations and roll these things out. I remember when I was on a manufacturing plant, there was this one robot, physical robot, and it could make seven different models of car, brands of car without changing anything.
It was so well-defined, but it still needed people at the end to just do the tweaks, to do the things like that. That was God, 15 years ago, right? I think we got the same thing with this stuff.
And I think I, I kind of reassured that we're all talking the same thing, which is we need to have oversight. We need set our expectations, because otherwise it will run rampant. But the trouble is we will see people that are, um, like, um, setting their expectations the wrong way, you know?
Well, I, I think that's the story. That will be the story in 2025, right? E experimentation in excess in, in experimenting with this stuff.
But you know what? Just like in the real world, AI is sucking up our conversation here. We have do have a couple of other things we need to talk about.
One of them, I wanted a big, you know, I think a big emergence in 2024 was sort of the, the legitimate legitimatizing of the platform engineering space, right? And in many ways, I think platform engineering, first of all, it's not replacing DevOps, right? Yeah.
DevOps isn't going anywhere. But platform engineering is a response to DevOps, I think, where DevOps wanted to bust down the silos and have us all working together. That was kind of the original intent, Right?
And what one of the outgrowths of that though, is that we just started shifting everything left. Give it on the developer, put it on the developer, put it on the developer. As I mentioned earlier, things we put on the developer were security.
And I think we found out that they care about security, but they're not security people, but they wanna develop secure code. Another thing we put on them is build your own platform. They don't wanna necessarily build their own platform.
You know what, maybe having a silo for a platform builders is a good thing as long as they communicate with all of the other stakeholders, developers, testers, security, SRE right? All the, the traditional disciplines in there. And so we saw this whole platform engineering kinda concept rise.
And I'm glad to see that in speaking to most of you. Your companies are bracing platform engineering. It's no longer, uh, if us or them, it's, we're in it together.
Give, if you wouldn't mind let, well, Sabrina, we started with you last time. I'm gonna start with Nick this time. Let's talk about how do you guys view platform engineering, especially going forward here in 2025?
Sure. I think you, you made a good point. And then the way we actually referenced it, when we talk about shift left, people started shifting, the workload left.
And that actually wasn't good. And what we actually want is we hire really smart people and wanna shift the information left, give them the information, given those, uh, results that security scans now, not when it's in production. And they have to go, you know, get in a backlog, give them cost information now, right?
Make sure they understand what that change the infrastructure's gonna do now, not a month later when it gets into production. So it's about bringing that information at the right time. It's also about making it easy to do the right thing.
And it's about making it hard to do the wrong thing. And I know that sounds super basic, but it was easy to do the right thing. The cloud wouldn't exist 'cause we would've made VMs in our company, right?
So you make those easy paths to get people to production, make it extremely simple. But you put policies in place to make sure that everything that you're doing actually meets your security, your compliance, your regulatory rules. And as a platform, the goal here is actually to create harmony amongst all these teams.
Like, although the folks on this phone or on the, on this call, we actually integrate with, right? Because again, you have to, and what we do, what we don't wanna do is we don't want to have security being the team of, no, they should be the ones empowering us by writing the policy. We don't be finance to be the ones of no.
And in cost, you know, coming back with a big stick and a carrot, empower them to write that, to make sure that you're, you're meeting your budgets, make sure the DevOps teams can write the pipelines, but we're all doing it in harmony. So now it's an actual platform of bring people together. If you're buying a tool that's a stick to use to beat a different department, it's the wrong tool.
It's not the platform that you need. You need something that brings harmony. That's, I know it might be like a little controversial.
Mm-hmm. And, and maybe a little hippie. No, I, I, that's genuine.
I think it goes back to dev, that's DevOps, right? It's about working together, not necessarily that we all, all of us become DevOps engineers or DevSecOps engineers, but it's about, we all have our thing that we do, but we work together. So I I'm, I'm, I'm with you.
Rest of the panel. What do, what do you guys gals think about, about that? Uh, sorry, did you wanna Go ahead, Kobe?
No, no, go ahead. So the, the thing for me is, is you're right, it is, um, bringing together the teams. We have a lot of siloed, I've heard feedback that the data scientists don't trust infrastructure people to stand up the infrastructure in, in production.
Partly because it's a brand new world. It's, it's in, it's not just standing up a server. We have to have additional tools to see drifting, uh, compromises, new attack forms, et cetera, coming in.
So the whole thing, we actually came with a term called every ops, because you know, there's DevSecOps, DevOps, machine ops, ml ops A just goes on, I know Sabrina, you've got SRE, there's all this stuff and everything. But it rarely, I, I like it because I spend a lot of time working with customers, getting them to overcome those barriers and unify them. So we talked about security.
I'm sorry, Nick. I convert developers into security people, right? Okay.
Bad. In fact, I already disrupted, we were cube con and this poor guy is sitting there, uh, we're having a drink. And I said, you know, you're a security person.
And he went, ran by the end of, he says, I hate you. But you're right, because security is everybody's responsibility, but it's not the no thing. It's not the thing.
It's about enabling and understanding the implications. And we talk about streamlining that ability to create a, a, a, a visible view of everything that's going on, and understand, leveraging each other's expertise to create a pipeline that's streamlined, fast, secure, safe. I know, I'm I ideal, but that's what we want, isn't it?
Yeah. Right. Because that's gonna protect our big customers businesses.
But that model of everything, we gotta stop the silos. And I think for a lot of the leaders, the CISOs and the, the CTOs, the CIOs, there's gonna be change. Right?
Kobe, I saw you get a big smile on your face when Paul said that we've gotta convert them all into security people. Yeah. You know, we, we built a platform like in the first place to be kind of unite everyone, like security people, developers, uh, developers, et cetera.
Um, kind of the, the use cases that we see now that, that kind of customers are interesting in is, uh, how to save DevOps people's time and also developers' time providing them a new experience through the platform. For example, uh, you know, there was a kind of a discussion if developers or security people, or not kind of, uh, through platform engineering, you can actually reach a situation, kind of that everything is being done automatically, uh, you know, automatically. And the developers is actually, uh, we just show him a, a Jira case and tell them, okay, you need to fix this, this, and this.
Okay. This is kind of a, a kind of a platform engineering together with, combined with, with a bit of, of ai. So kind of, it, it saves time.
It, it also provide a different experience and it also eliminates mistakes. So kind of these are the main three use cases that, that, that we see now of kind of what kind of our customers and design partners want, want to use, uh, the platform engineering for. I think I agree with what everyone has said.
I think I have a little bit of a different take. So I think platform engineering has always been something that people would argue is a good thing. It was an ideal, but in reality it was an idealistic state, and it was never like a high enough priority to do because people were like, well, I'm gonna choose best in class and then I'll figure out how to integrate these things together.
And, you know, so we'll delay that idealistic viewpoint. I think maybe what's changed on why platform engineering is such a highlight right now is that there is so much regulation coming. And so all of these integration points that we have done for probably the last decade, because we wanted to choose best in class, and that ended up with many, many solutions that we then tried to tie together.
If you have to do something like GDPR, all these integration points are now a risk to your business. And I think as business leaders, that's why platform engineering is such a buzzword right now and why people recognize that. Like you need to have an already existing integrated platform.
So as we meet our requirements for the different regulations and all the compliance that we are being held accountable today that maybe didn't exist five or 10 years ago, platform engineering helps you unlock that and actually reduces the risk for your business. And I think that's why it's so popular today, this collaboration. It's actually just an added benefit.
Much more so than the driver today. Sabrina would, would you say, so I've had some people say to me, the platform eng, the platform engineering team is actually an oversight team. It's almost like a platform architecture where they've got the full visibility across the whole, the thing, and they're guiding and being the focal point for getting the groups to work together.
Does that resonate or not with you? I think that's how, um, people defined platform engineering in the past, right? They plug all these things together.
You'd have your SRE team that SRE team would manage all of these different integrations, and then they were the oversights committee. I don't think that is sufficient going forward, right? I think that breaks down very quickly.
Um, I think that's very expensive way to do it. And true platforms reduce your cost of ownership, right? And I don't, I think that's something we didn't pay attention to for a long time.
But in the current market with the current cost of technology, that line item is actually, uh, not as, you know, available today. As the businesses are growing and the market pressure is there, Does that mean that should be part of the office of the CTO or part of Dev, or, I don't know. I'm trying to work out how it fits Where it fits.
Yeah, I mean, I think that varies by company. Yeah. Right?
Yeah. In today's world where the CTO is often the CPO as well and vice versa. Yes.
Or the CIO is also the CISO. Yep. It really does vary.
com, our newest site, and we have a new show out there that actually check marks is sponsoring, whether it's called the Platform Engineering Show. org, which has two to 200 to 300,000 members involved. So we're gonna be looking hard at platform engineering.
I think the other big story is it's not replacing DevOps, it's part of this whole continuum, right? Platform engineering enables DevOps, it enables DevSecOps. And then, and the only way it works is through open lines of communications with developers, with SREs, with DevOps teams, with security tips, right?
And I, I think that's the important thing to remember, guys, we've got one more subject and not a lot of time to do it. And so I want to get it up there. We, we touched a little bit on software supply chain and software supply chain security.
So I, I gotta disagree. We haven't solved the open source security issue. I, I, I think this is just like a, a snake that keeps coming up and biting us.
Um, what makes you think 2025 will be any better? Or will it? Paul, we haven't started with you.
Let's start with you on this one. Wow, that's a hot one. So, uh, so I mean, securing the supply chain, I think it's, it's, it's be it's, it's something that now that the executives are starting to realize is important, that they're accountable for, they, you know, just like, um, friend of mine was saying about Sarbanes Oxidative best to sign off, it's supposed service best to sign off on supply chains.
It's gonna happen more and more. But I think, I think we're still getting there. I think it's not, it's, it's, we still got a long way to go, I'm afraid to say, because, um, I'm still, we talked about streamlining, consolidation, getting, you know, that traceability, um, and that sort of thing for, for us to have a secure supply chain, we've gotta see everything as it traverses through, um, through its lifecycle of getting into production.
Um, securing that and getting everybody, you know, a platform engineering, uh, and sorry, Sabrina, I think it's critical and I think it does need to be a focal point. 'cause it's gonna be the one place that can push that story together with the security team to get that going through about in 2025. I'm hoping that we're gonna see some new tools, which will help with that consistency and that traceability.
I think we still have a long way to go because I'm still working with customers and organizations who are still struggling of trying, just, just trying to consolidate their tool sets. I spend a lot of time on streamlining exercises. So from that perspective, I, I'm hopeful I see progress.
I don't see all the answers being ai, I'm afraid. And in fact, in some conferences, I dunno if you've, it's almost like it's a groan. Oh, somebody's doing a presentation on ai.
It's like not enough for one. You know what I mean? Oh, I live it.
Yes. But I think standardized processes, maturity, actually tying it to better metrics beyond developer velocity. Um, I always thought talk about the ripple effect.
When something goes right, it has a beautiful effect across the whole organization. When it goes wrong, it has a ripple effect that hurts everybody. It's not just dev, it's not social security, it's not just infrastructure ops or whatever.
Everybody gets impacted. And I think, I'm hoping, and yeah, and I'm gonna be pushing to get different metrics in place so people actually understand the impact and the positive nature of supply chain beyond just getting product faster onto into production radical, I'm sorry, fair panel. I, I think that in 2025, uh, uh, we're also going to go further down, further down or up in the chain, meaning go into the source and assess how trustable it is in a, like, is the repo that I am taking something from, how healthy that is, the contributor, the contributors that are contributing to, to the open source that I'm trying to fetch how, kind of, how reliable they are.
'cause up until now, we kind of, uh, we mainly focused okay, on taking a piece of, of something, a piece of software. Uh, is that specific piece of software, is that, uh, is that, uh, a healthy one or not? I think that we're now going to go kind of one step down in, in the chain and, and, and again, and assess how trustable the source and the contributors to that source.
Uh, are we, we have a, uh, I'm not supposed to mark it, but we have a solution that acts like a gateway between the public repos to stop the bad stuff coming in. Um, the real challenge is getting the developers to say, go through this way. Go through this way to the, to, to get you to your repo as opposed to going direct.
Like, don't go at home, Install the package and then come back, sort of thing. So there's a lot of, there's a lot of challenges about that enforcement and trying to explain to the developer actually gonna save them time, uh, save them time and money and let them spend less time fixing bugs and more time Creative mean there are still people downloading the wrong lock four J, right? Well, struts two and Equifax, this is a common, how do you stop them from downloading old vulnerable bug ridden bad components.
Sabrina, I saw you shaking your heads. I wanted to give you a chance. I mean, obviously, you know, we get hundreds of external contributions into GitLab.
It's amazing. People ask me a lot of questions about that. And you know, look, just because all of your contributors are internal does not mean you don't have risk, right?
It's just sort of like if you had a firewall versus not having a firewall. If you're behind the firewall, you're safe. That's not true.
That's never been true, right? We've learned the hard way that that's not true. I actually think sometimes the number of eyes who are on open source, right?
And like checking for that and looking out for that is much more powerful than what you might get. Um, if you're all hidden internal, like having worked for a very large tech company for a long time, not all teams are the same. They don't all ha make the same assumptions.
So even when you're integrating inside your corporate walls, you have the same kind of risks. You need to be on the lookout for that. You can get malware into your system unknowingly.
What you, what you really need to have is like, you need to have policy controls, things that are enforced that are automatically looking for that. So if your employee does do it, it's not like, Hey, you broke the rules. It's like, Hey, we just stopped what you did.
That cannot be integrated into the system we are watching for where this is going. And that's, again, back to the platform. Like the platform can enable those things for you.
Yep. 'cause it plug, uh, your system is all plugged in together. You can look at everything at the same time.
And I think that's how you wanna think about it. It's not open source or internal. The risks are the same for the both.
One has consequences, right? 'cause you, they're your employee, right? You have, um, you can do something about it, whereas the other person can't do anything about it.
But actually it's the same problem in the end. I think, uh, I think this falls in that same thing that I was saying earlier, which is make it hard to do the wrong thing. And if you put in all that policy in place, like you said specifically, like that's, that's why we built open policy agent into harness.
So you can prevent any one of these, right? Make sure that every piece of code is scanned. Make sure that every piece of code doesn't hold that MIT license.
Make sure that it goes through the appropriate measures to block things like a log four J but also make sure that it has salsa attestation. So it's got a bill of materials. You make sure you're there, but you actually know that it's the actual artifact you're using so you don't fall into like a SolarWinds attack.
And so now the actual attack vector's grown from just the artifact of just the code. But now to your point, this is why the platform's so important. This has to be from source code, from the build, from the deploy throughout all the systems.
And it's not even just about validating it, finding it, checking it. You're going to have that zero day. Now how do we remediate it?
So that platform should know what you deployed on, which infrastructure with which configuration that were secrets to get you back. Or more importantly, as you update those, uh, artifacts or you, you change those libraries to promote them out to production again. And so getting you remediated quickly so you don't struggle with those.
And I think this is truly where when we start automating all those things, and it gets us back to where we were. Like, if we start taking that burden off of people, uh, and actually focusing them on the areas, now each one of those teams can do what they're great at you. You empower it.
And what's really scary here, you know, the government is actually the first ones who did this. Well, there was an executive order that forced this that said, Hey, you have to have a bill of materials. You have to have an attestation that proves it.
And this is one of the first times we've seen our US government actually leapfrog and actually leave the, the, the public sector behind. And we've been working with those enterprise customers on that specific problem for years now. And what we're seeing this year, and I think as to get it back into predictions in 25, you're seeing now actually all these, you know, public companies catch up to, we need to have this secure.
We need not only for our own software, but to your point, even the people that are our vendors, uh, the people that are co contributing. It actually, it, it, it builds trust amongst the entire community Agreed To Sabr to Sabrina's point that, uh, in internal, you know, internal code is also, uh, not, not secure. Like we have a whole concept of what we call price packages.
Not open, not not only open source pack meaning packages that were actually developed within, within the, uh, within the organization. And we treat, we treat them. If we treat them the same, their potentially Melissa Open source packages.
Yes, absolutely. Guys, we are out of time. I wish we had, as I said in the beginning twice as much, three times as much.
We could talk about this all day. What ama an amazing, amazing panel. Thank you all.
Nick, Paul, Sabrina, Kobe, I, I honestly from the bottom of my heart, thank you so much. I hope you guys out here watching this have enjoyed this panel. Um, all four of these companies and these folks are kind of frequent guests on Tech Drunk tv.
So watch for them throughout the year. Um, we have a lot more lined up here for you today on Predict 2025, including the winners of the DevOps Dozen awards we'll be announcing. So for on behalf of everyone and, and here at Techstrong, I'm Alan Shimel.
Thanks for joining us on this great panel. Stay tuned for a lot more here at Predict.