Techstrong TV – March 6, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Today's episode is from Russia With Love. You're watching Text on Gang.
Hey. Hi everyone. It's Alan Shimo.
Happy Thursday. Welcome to Text Drug Gang. Don't for Donya.
But, uh, anyway, you know what? We live in a crazy world. Once again, I wake up and I'm looking, what has Biff done today?
So, we're gonna be talking about it. We've got a couple of blocks to talk about of some interesting things going on in the world, and we've got some great folks here to talk to. It's kind of Cork Textron gang folks today.
Let me introduce you to 'em. First of all, giving us the, the, uh, 4 1 1 from, I don't even know what the area code is out there anymore, John, but from Silicon Valley. Oh, It used to be.
It used to be 4 1 5. Now it's, it's six five. Oh, Okay.
The 4 1 1 From the six Five. Oh, you're close. Yeah, you're close.
It's our editor at large, John Schwartz. Hey, John. How are you, man?
I'm good. I'm just kinda reeling from a very long speech last night, but, uh Oh, I didn't watch it. You know, we Move on It.
Yeah. There was a speech last lasting. I don't know.
I, I watched, uh, something else. It was, it was, anyway, It was two nights ago Going, going from higher top Silicon Valley to sea level where he's, I think, well, you, you are actually not a Key West anymore, right? You, you're, you kind of turned into the Gulf a bit, Into bit in, in the area, in lower, lower keys.
You know, today's island in the, where is Waldo search is raccoon key. So you can Google map that up. It's a couple miles, miles offshore away from us.
One, I've been edging towards the Gulf Edge, the content keys. I'll get to the next couple of days to check those out. Very cool.
Chris Blas, our security expert, cyber expert, going from there, back up high into the mountains. Rocky Man High, Right? It's our guitar man, Mitch Ashley.
Hey, Mitch. How are you? Very good.
Very good. Just, you know, holding things down at the top of the peaks here in Colorado. All right.
Keeping, keeping the sky up. Yep. Holding, holding the sky.
Yep. Very cool. And then from there, too, Harrison, New York, the seat of tech strong content.
It's our chief content officer, Mike Ard. Hey, Mike, what's going on? Hey, the birds are chirping and there's buds on the trees, and I ain't talking about the kind they sell in Colorado, so, no, No, no.
Spring's coming. All good. And the Yankees keep winning, man.
There you go. The Yankees looked good again. Anyway, it's all pre-season, of course, means nothing, but still.
Um, let's move into today's news, guys. I, I kind of started teased it off in the beginning. You know, pigs fly and, uh, we've decided, or the government, or at least our esteemed Secretary of Defense, I'm not gonna say anything more that I'd like to, um, says that we, uh, should supposedly, 'cause now I'm seeing pushback that we should stop offensive cybersecurity, uh, uh, procedures, operations against our warmest ally, the Russian Federation.
Very good comrade. Mike, what do you say? Well, I say that it's hard to tell what's going on here, and not everybody, as I understand it, who's involved in this might necessarily report up to the Department of Defense.
So there seems to be some confusion as to who's doing what. And of course, you know, the best defense is a good offense. So it's hard to say what an offensive thing is versus a defensive thing is these days.
But Chris, what's your arena? What's going on here? Oh, you know, Kim Zetter and other people that I trust have been reporting on it.
You know, it's like, you know, you said that well enough. I don't know. I haven't talked to sources and so forth.
The fact that it's so matches our expectations, you know, and what we as a nation are communicating, you know, to this, you know, not ally. You know, our, our main adversary in the world right now is China, is Russia. I almost said China, but economic, in a sane world, China would be, uh, our, our real, uh, opposition.
Because Russia is a tiny little country with the economy of Italy, right? Uh, that just happens to be bombing one of our allies and are maneuvering around them. Doesn't make sense.
You know, they are the existential threat. So whether into what extent, you know, this order or directive was given or thought to be given by people who are taking actions on our behalf, the fact that it, that it's not shocking is what we should be shocked about. You know, I I'm disappointed in you guys.
Yeah. I, I, I figured you'd be more savvy and kind of catch on to what's going on here. What's really happening is this is a Marco Rubio and Trump secret plan to partner with Canada and Mexico to give Russia a giant head favor to think that we're, were their friends and China too, right?
In the meanwhile, we're undermining all that stuff. He's ramping up. There He is.
We're playing checkers, and they're playing four D chess. Exactly. You got the attention That makes sense.
Come us that makes sense. Look, let me, let me, let me just throw some stuff in here. Number one, Russia's economy.
I don't know if it equals Italy, Chris, but I, I've heard it's, it's similar to New Jersey and being from New York, you are from Jersey, you know, that's a, but what Russia has and has had beyond their economic footprint is their military footprint, because they are depending who you believe the first, second or third largest purveyor of nuclear weapons in the world, and they're not shy about threatening to use them. We've heard it numerous times during the three year, four years, whatever, of this Ukrainian war, right? And, and that if not for the nuclear weapons, honestly, who, who, who would give two craps about what goes on in Russia, right?
Let's be honest about it. However, not equal to their military footprint, but their hacking footprint has always, has forever since there's been an internet, been a huge footprint, whether it's a wink, wink from the government, letting groups operate openly within the Soviet Union, and then Russia or Russian asset, Russian government assets themselves, what we used to call the KGB. Now it has some truth speak names, time and time again, time and time again, attacks in this country and in the West have been tracked back to groups based in Russia operating under the, the, the cover of the Russian government.
And for us to ignore that and not to, uh, is a terrible dereliction of duty. Pretty much what you'd expect from a guy who never, who shouldn't be the Secretary of Defense to begin with. Well, in a sense too, you, you think back to the 2016 election and Trump benefits again from Russian meddling.
So in a sense, this is part of his reward to them since he no longer has a run for office anymore. And on the flip side, you've got this obsession with China and security in deep seek. I mean, we spent so much time within the government thinking about banning them for probably good use or at least ban limiting the use.
But on the Russia side, as you said, Alan, I mean, there there is great, uh, protagonist antagonist is, is, is, uh, uh, Russia is, and yet we kind of looked, we're looking the other way. And again, I'm not even sure what the hell Heif is doing. I mean, evidently he ordered the US cyber command to halts offensive cyber operations.
And this was supposedly went into effect, or the order went in late February. Yet there's pushback. I mean, it's, you, you can't get a straight answer from these guys, but I think at the very least, I would, I would argue that again, with Russia, they're just gonna look the other way.
They always have. And they, they continue, they will continue to, especially in these asymmetrical warfare front. I mean, read, read your Leo to Tolstoy, right?
You know, this is War and Peace, you know, it's about court posturing and, you know, appearances and whatnot. And, you know, this is, you know, Alan, you're entirely correct. You know, what happened with the Soviet Union collapsed and the, uh, uh, the Russian mafia and the Russian government merged, right?
And what's been going on in cyber operations for, you know, the last decades is that Russian cyber criminals are given free reign to do anything. Like as long as they use KGB slash FSB tools, right? And should they, you know, compromise something of interest, they give that access to, to the government, right?
So it's all the same thing. And I'm sorry, but if you watch Sopranos, I don't want to, you know, force people to go read classic Russian literature, but it's a lot of posturing. And for us to say, even give the impression that we would let the heat off on them.
No, absolutely not. You know, you wanna threaten to hack our grids and turn it off, do it, you know, who will bring your whole, your, your whole infrastructure down. You have to have that posture.
Let me say something about China though, right? We, we, we don't live in a black and white world where I've got Boris and Natasha over here. The bad guys come, we go get squirrel, right?
And then we're, we're, we're the Lone Ranger and Lone Ranger and Tonto here we're the good guys. And, and that's what the world is. No, there's more.
You've got the Chinese, the Chinese are not angels, and they ain't our friends either. And it's always been a little education for Mr. Secretary of Defense.
The United States Defense strategy has always been, we must be able to fight wars on multiple fronts at the same time. We've gotta be able to deal with enemies, mortal, or not on multiple fronts at the same time, just because you want to take it to China or, or thwart Chinese hacking, which is terrible. And it's been terrible.
And I, back in my still secure days, Mitch knows this. We were, we were right on the front lines of that stuff. That doesn't mean Rush is the good guy.
And when Rush is the bad guy, doesn't mean China's the good guy. There's, there's multiple levels of bad guys in this world. It's a big bad world out there.
And for us to, to take the bullets out of our gun, you know, no, the only thing missing is someone to get up on a microphone and say, I've brought us peace in our time. You know, you know, the only reference a couple of nights ago that, that Trump made about defense was this ridiculous Golden Dome idea, which was basically a ripoff or Reba of the Strategic Defense Initiative, or Star Wars. That was the only thing he referenced.
And again, it's just, I mean, it's just like we're in a, in the next segment we're gonna talk about Doge, but just kind of pulling things out of a hat. And the one thing I want to, I wanna foreshadow before the next segment, is this $500 billion figure that keeps coming up in terms, in terms of part of the scam or the schemes. Um, but again, it's, it's, it's, we have multiple enemies.
And the fact that we're, I'm sorry, go ahead. So let's bring this back to the average cybersecurity and business executive out there, Chris, should I expect, you know, and, and a significant increase in the number of attacks coming outta Russia, aligned cyber syndicates aimed at US assets. 'cause they're gonna be basically going, well, we got a free pass, here we go.
I'm trying to be objective about this. Yeah. Because, uh, my, my position of opinion is I, I think are clear, um, maybe not, maybe the op opposite, maybe the direction the Kremlin is, hey, or reward, you know, Trump for his capitulation and go off, you know, let the, let the stats go down a little bit.
That might be a little bit too intelligent for the people in charge. Um, but, you know, short of that, short of some direction from the Kremlin to, you know, reward our misbehavior, you know, I would say, yeah, sure, you know, this is a bit bit more free reign for all the, all the cybercrime operations out there, that they're likely to be more re rewarded. You know, they're a, uh, you know, so much of the ransomware and so much of cyber crime.
Like I say, Alan, this is not about Russia. You know, Russia's actually a, a lovely country. It's just a bit of a train wreck.
Now, this comes from everywhere. But Russia is one of the massive actors, and this does absolutely nothing to slow them down again, unless Putin, you know, wants to wave a, wave a flag at his, at his criminal fleet, you'll to slow down for a minute. All right?
So if you assume that the glass is, uh, half empty rather than half full, I would suggest the key word of the day is incoming. Yeah, Yeah, yeah. Don't pay less Down folks.
You what? Let me, let me go, let me politics aside for a second. And craziness aside for a second.
This, the article that we're talking about that, that spawned this conversation is an article in Security Boulevard, I think, by Jeff Burt. Jeffrey Burt. And he has a ton of really credible friends of ours in the cyber world who, who are talking out about this.
I'll also point out that at least for now, NSA Cs a, uh, you know, some of the other government agencies who are on the front lines of cyber are not necessarily, from what I understand, part of this DOD edict, though, I can't imagine that the Secretary of Defense is allowed to do anything without the okay. From Fearless Leader. And so it probably extends, you know, I, I wouldn't be surprised if it extended in, into the rest of the government, but it doesn't extend to private industry.
So my advice, to your point, Mike, to private industry and my cyber profession, fellow cyber folks out there, stay vigilant. Keep doing your job right? With or without the government or the US government, we still have a mission to, to, to work on here.
And, and the mission remains the same. Keep our infrastructure secure. Keep our businesses secure.
Keep our people secure. I'll leave it at that. Good.
All right. Let's take a break on Text Drunk Gang. We're gonna come back and well, we'll continue the fund.
We're gonna talk about, uh, you know, supposedly how AI is being used by Doge. And you know, that advisory group that really has no official power, uh, to change the government. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Alright, well, as John alluded to, we're gonna have a conversation here about, well, what exactly is going on with Doge and their use of AI and the alleged amount of waste that they are finding. 'cause there's a lot of, uh, people who are calling maybe BS and all of this stuff. But, uh, John, you've got a story up on textual ai talking about a group who's kinda asking for some records to maybe hold folks in trouble.
What's going on? Well, there's a group called Democracy Forward, which has been filing a lot of legal actions against the Trump administration. They've been very busy.
They've done at least two dozen legal actions, including this Freedom of Information Act filing and some other actions. What they're looking into are, um, they, they, they, they want public record requests from several federal agencies on the use of artificial intelligence to make personnel decisions. In other words, the decisions that, um, let, let's, I'll give you some of the, uh, organization.
There's Doge, first and foremost, uh, office of Personnel Management, general services administration, state, uh, defense, treasury departments. And they're, what they're trying to figure out is, and what they think is happening is that Doge in particular is using AI as part of this email campaign. Remember again, where Musk was trying to force government employees to respond to what they did the last week with five things.
And in effect, what the Doge is doing, allegedly, is using some of those responses to figure out who's worthy of staying on in their employment and who they're gonna get rid of. And, uh, in a sense, the executive, the person who's in in charge of Democracy Forward has said that Doge and the administration are operating in this shroud of secrecy, and they're governing by cast tactics, have led to less efficient government and more disruptions to our safety and security. Um, when Trump was talking during his interminable State of the Union address, he mentioned that the initiative to cut back costs had found hundreds of billions of dollars in fraud.
And, um, he, at one point, he, he threw out the number of 500 billion, which I mentioned earlier. That always seems to be a patent number that they were using for everything. Um, he also referred to Musk as the head of dos, which was kind of interesting.
But in any event, allegedly Mocu has talked about using AI for efficiency purposes is being looked into by this organization. It'd be really interesting to find out what they, what they discover. But again, AI is being used to eliminate jobs, which might be a precursor to, to other industries and in other agencies doing the same thing in the future.
I'm a little dubious of the whole use of AI to begin with. 'cause if I look at what seems to have happened is, um, they basically are cutting everybody who was hired in the last year or two as, and those all seem to be hired under the Biden administration. And then the next thing just seems to be flat out, let's go do global search for the term DEI and anything else like climate.
And, you know, we'll just cut those things. And that's about the extent of their effort. So I wouldn't need AI to go do all that.
But Alan, what's your take? Oh, you think I have a tank? Yes.
You in the back of the room raising your hand. Um, well, I, you know, John, good article, by the way, on ai. Oh, thanks.
On text, on ai, on this. I don't know, there's also a Washington Post article that I i I worked that do's AI use in government doesn't add up. And, and quite frankly, it doesn't.
But let's, let's, let's step back for a second. Does anyone else find the irony in let's keep AI safe and not profit? Mr.
Musk using it for these purposes? Elon, the hypocrite strikes again, right? So in other words, you can't use it for all, you shouldn't use it for all those things, but I will, because after all, I, I have money, and therefore, there are no rules that apply to me.
I mean, this is, this is really the crux of it. But he was the guy who went after open AI because it wasn't safe and secure. That's why Exactly on principle.
That's, that's why on principle, he has to leave before he decided he wanted to try to buy them in, in weird, another weird publicity. I mean, the whole, the whole thing is, so this whole, look, I'm telling you, dude, I wake up every day and I'm looking for Biff up in that big tower in that Vegas kind of hotel saying, what kind of craziness is what, you know, what's right is wrong, Knights and white satin breathe in the gathering gloom. Um, what, what goes on in this world?
But nevertheless, it, it's just par for the course of how they are just mashing the federal government. And no, it wasn't the most efficient organization in the world, that's for sure. But it's almost by design not to be efficient.
It's almost by design. But I think Aaron, what we're seeing is, is the Trump effect rolling out to other people? Um, a mess is clearly learned the art of projection, right?
Oh, you shouldn't use AI for those things, and then I'm gonna do it myself. That's just one of, you know, a thousand things as well as if I say it, it's true. Whether it as any meeting in reality.
And we, we, we expect things to tie back to something that makes sense. They don't, nine times outta 10, maybe 10 out of 10. It just doesn't.
So it, it, you know, I I look at it as yeah, but then the next thing is then we're gonna hear, must complain about how someone's using AI against something he Believes. Of course. We'll, but, but the bottom line is what are the repercussions here, guys?
What are the repercussions here? I don't think we're gonna know that for, Oh, I think we're gonna know real soon. You do.
Why? I think they're, I think they're using it in a lot more ways than we know about. Yeah, I, I get the No, no, but I, I think you are going to see the gears of government grinding to a halt, and then all those people who raise their hand, who say, Yee ha, this is what we voted for Until their house burns down.
Um, Watch their house burn down. Yeah. Anymore From Canada.
So, You know, so, so I'm trying to filter out all of this and, you know, and get to the topic, because again, you know, the adversarial goal is to make it impossible to talk, right? This is all, you know, met, you know, cognitive denial of service attacks, right? You know, give, give people so much to talk about that they have no time left to talk about bloody anything else.
And in this particular topic, I don't really know, you know, but I, I look at artifacts like, you know, so you have this, this doji, uh, dodgy operation, you know, thrown together in five days and they get 2 million e email responses. You know, humans aren't even reading through that ever. So there's obviously a, a lot of automation filtering going on, you know, is it oms, ai?
Uh, probably. Right? You know, and that's just so obvious on the surface.
And they couldn't possibly even do anything without just automating everything. So you fire a million people without looking at two of them. But Chris, Let me, let me point out, the emperor has no close.
Do you really think? They, they go through this, and that's what they're making decisions on. Let me tell you something.
They've made their, the decisions on what agencies we're going to get cut, what programs we're going to get cut, were made. This is, you know what I mean? This is a bass awkward situation.
They already know what they want do and what they're doing, and they just use this stuff to keep you guys busy. They're doing what they want. They wanted to, to get rid of the Department of Education.
They wanted to get rid of the USAID thing. They're claiming, I don't know how many people are 150 years old in the world now in our country now, 10,000, 50,000, because that's what cobalt the coding defaults to. They, this is all, this is, this is for consumption.
So he could stand up and bandi about that $500 billion number, and then all, all the haws or deplorables, or whatever the hell you want to call 'em, go on Facebook and say, whoa, we cut $500 billion. And then they find out poor Aunt Mary's Medicare got cut and poor Aunt Mary can't get dialysis anymore. Sorry, aunt Mary, right?
This is, this is the world we're living in, guys. But John, you know, it's kinda, at least I find it kind of weird to watch. It's like, so they make a claim on a savings, then there's this contract that they said they cut, then three days later, the website changes, and that savings wasn't there in the first place.
And so these numbers are bandied about, seem to be, Be, you know, That was part of the post article. The numbers don't End up, that's funny, Mike. I was, I was, I was thinking about that in terms of like the man, all these manufacturing ideas or these deals that they're throwing out there.
So I went back and looked at Foxconn and looked back at the original terms of that, which were like in the tens of billions of dollars. And it ended up being like a $600 million project. They talked back then about foxcon about 30,000 jobs that ended up less than 1500.
And I think the same principle applies to this. You know, Trump also mentioned in his speech, apple and the $500 billion they're gonna spend, which many of those programs were already underway, by the way, it's never gonna reach that level. It, it at least Musk in his, in, in, in Musk's weird way.
You know, he will project the troops once in a while. And he, you know, he'd laughed at the idea of the SoftBank deal, which, which Trump bally, who's, uh, SoftBank during his speech. I used to think all this stuff is, is about flooding the zone, overwhelming us with things that are silly that we fixate on and we never learn as the press.
We never learn. We have to separate, we have to separate the noise from the signal, right? 99, 90 9% is the noise, right?
Ev and us chasing down all that noise is distractions, right? Kinds back yesterday or two years ago or whatever is kind of pointless, right? What are, what are they really after, I think is what, what your point is, Alan, is those decisions have already been made, right?
Here's the agencies we want to cut. This is what we wanna stop doing, and we'll find whether a path to do that. And there'll be a wake of chaos in that process, as well as everything else we pile on to confuse the situation and to track distract everyone for what we're really doing.
You know, the one thing, can I mark the tape on this? I'm, I'm gonna compliment Trump on something I think he does better than anyone I've ever seen. And that is, in a sense, manipulating that too.
Well, two things, uh, manipulating the media and giving, forcing them in a weird way, or tricking them in a weird way to follow a certain path, which they do ad nauseum, and they fall into this trap that he switches gears and moves to the next topic. And I think this is what we're going through again with Doge. I, I, I would really, if you add up the numbers of some of the things he mentioned that they had allegedly saved on, would probably less be less than, uh, $500 million at best.
And yet he's talking about saving $500 billion. Well, you have to give the Democrats credit for their pickleball paddle strategy last night. What an absurd thing.
So, you know, I, I'm gonna find, I'm gonna find a silver lining in this somewhere, right? You know, so, you know, the A the ai the AI in this topic should be used by us, by tech strong, by a, B, C, because the old cliche we're all talking about here, you know, take two seconds to line. It takes two hours to refute it.
By that time, you're lying about something else. One thing AI might be really good at, and maybe media organizations should be specifically deploying it, is not spending the time, you know, everything that comes out have AI filtered out. So we're not sitting there Googling.
We don't have people researching to find out what the stupid lie is last, last time. And, and I am, and you know, I am reaching here, right? We don't have at the national level, you know, our own government is the adversary, right?
You know, we don't have any national defenses, and we are at the public sector level working against having defenses. Maybe this is something that media organizations should invest into. Shorten that loop the rest.
Yeah, I think, I think you're onto something. You, you put a, maybe have you gonna crawl across the bottom of the screen as he's speaking in real time with, with the AI response or the AI fact checking? I don't know, something like that.
Although Americans don't like to read, so maybe that won't work. But, um, They're not interested in facts. People are interested in facts.
When you point out something is nonsense, they move to the next thing. Or what about this, what about that? Take vitamin A for your measles.
I I read a frigging article yesterday. You know, we're, we're recommending vitamin A for measles. And because v vaccinations are a personal decision.
And after all, before we had vaccinations, virtually every child in America had measles. And you know what? Only one out of every 1,250 children who had measles dies.
What's the big deal? Until it's your kid, or your nephew, or your niece or someone you love. Then that 1,250 out of one one out of 1,250 becomes real.
That's what this whole thing is. It, it, the whole, this whole thing is, let's, I'm done. We're going on text Joe, we're taking a break.
Let's come back and talk about, wait, last thing, One last thing. Mark Twain had it right. A lie travels halfway around the world before the truth puts its shoes out.
There You go. That's exactly it. You're watching Textron Gang.
Let's come back and talk about technology. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security Bloggers Network. Hey folks, welcome back. We're gonna geek out a little bit because, well, you know, politics is politics and tech is tech, or at least it's supposed to be.
But, you know, things get intermingled. But Mitch, there's this small little conference that was happening in Europe called Mobile World Congress. You know, a few hundred thousand people show up at that thing.
I think it's one of the largest conferences in the world. And one of the things that leapt out at me was this announcement from Red Hat, where they had lined up, I think a half a dozen telcos or so to deploy their cloud native platform called Red Hat OpenShift. And it seems to me like we're just starting to move a boatload of code out to the network edge here.
What's going on? Well, yes, you're right. Mobile World Congress is the, you know, ginormous con of conference of conferences.
It's quite an experience to go. Um, yeah, I, it, it's interesting. Red Hat is making a really strong play.
I mean, they've already been in the telco industry with OpenShift. That's really where OpenShift kind of got a lot of its functionality. And legs came from working with telcos, and now they're extending that kind of up the stack, if you wanna think of it that way.
In one way is, is capturing as more things go to the edge or more things are considered cloud native, whether that means just containerized or if it means, you know, building it with other things like microservice, et cetera. As more things move to the edge, just like, you know, the ran, the, the, the, the radios have been ized and moved to the network. More software's going there too, that they're, they're deploying and they wanna simplify or at least offer the telcos a way of not just running OpenShift in the big behemoth data centers or cloud centers, but also running it the edge.
'cause that's, that's where the action is, and that's where more software's moving. So yeah, the, the, the companies we would recognize in the US here were like Orange and Fujitsu and, uh, T-Mobile, I believe there were I think four or five others. Symphony, some others I'm not that familiar with.
Um, we're talking about, uh, what moving more applications and supporting, supporting OpenShift is part of their infrastructure. Now, that's a migration process, right? If they're not already doing that at the edge, there'll be some work to this.
So this, this is directional, but you know, that Red Hat is really making a strong play, not just on the infrastructure, but also on the development side of things. We're seeing more and more announcements come that are directed at AI and at software development. I think AI is gonna kickstart this thing in a bigger way because we need to process and analyze more data closer to the point where it's being created and consumed than these round trips to the cloud.
And all the network latency that goes with that doesn't really work all that well. So my question therefore is, um, you know, is this gonna wind up in a situation maybe where we have some more software at the edge than we have in the cloud one day Possibly, or at least wider spread for sure. I mean, they bought Neuro Magic back in November, which was all about deploying ai, right?
Not just to the core, but also to the edge. So yeah, it's, it's moving that direction. Yes.
The gentleman in the back of the room is raising his hand. I think he had a question. You, yes, you, um, You know, I I, thanks Mitch.
Um, I, I think it's important not to lose the cloud native aspect of this, right? Cloud native doesn't necessarily have to live at the Hyperscaler Cloud Center. It could exist on bare metal at your data center.
It could be on the edge, it could be everywhere and anywhere, which is a good plug for an event we're going to plug at the end of this. But, um, what it does do well in greenfields, it's, it's proven to be a pretty big task to transform your existing apps and infrastructure from monolith to, to cloud native, right? Um, and, and cloud native in all of its glory and flavors, right?
So, so you're talking about, uh, not multi-threaded. I always mix up the thread well, distributed, but no, from an architectural point of view, not multi-threaded, but it's multi-threaded microservices, right? So you talk, when you talk about moving from monolith to microservices, you talk about distributed core edge data center, that's a lot easier to do on a, with a blank piece of paper to start than it is to take something that people is mission critical or people are using already and, and convert it.
And to me that that's a huge piece of this, right? I, I, I saw an article last week. They estimate that for new applications, 85% will use microservice architecture, cloud native technologies, but transforming, and there's a lot of applications out there that need to, you know, will be transformed.
That's a much heavier lift, a much, much heavier lift. I think as we get closer to the end of the decade though, we'll hit a tipping point where the amount of cloud native code will have reached a point where it just becomes simpler and easier to containerize the legacy app, including the virtual machine, and run that on Kubernetes alongside the cloud native stuff to have one single set of platforms to manage. But Mitch, you know, is that wishful thinking or what?
I, I don't think at all, Mike, because we think about OpenShift is kind of the infrastructure management of it, if you will. But right on top of that is, you know, even the co container services that you run in OpenShift that's Kubernetes underneath all of that. So I think our definition of cloud native needs to expand.
Yes. I mean, today we kind of think of it as microservices, et cetera. We're also thinking about it as you containerized and run things on Kubernetes, whether it be legacy systems or things that are partially modernized.
But on the other end, the spectrum is also agents ai, right? That that is also being deployed. And, and we have data from a survey that's coming out here in the next few days about how much of the workload people are putting of AI in Kubernetes, which makes a lot of sense.
So cloud native really means kind of distributed computing anywhere at the edge at the core, and with, uh, with workflow management Kubernetes, or if there's something else someday that takes its place, that's, that's where we're evolving to now think of it more broadly, not just rebuilding it one way with microservices. 'cause it may not be that, it may be a combination of multiple things that it's built in. Alright.
Hey Chris, you know, I don't know if this has been lost on you or not, but I think, you know, if you listen to what we just said and we, uh, extended the attack surface that needs to be defended by a factor 20 and Or contracted it, I don't know. Right? You know, this is the whole cloud argument, right?
You know, if we just, if we just do all our own security ourselves, we're better than outsourcing that to some company that lives and dies by their platform being secure. Um, yeah, it's a very simple view. I mean, these are complex issues and so forth, but even security companies, you know, the time you have to do your own network administration much less, you know, deep dive security, you know, I've seen it over and over again, right?
We're a security vendor, obviously we do this well, it's like, yeah, maybe, maybe not, right? Yeah. So, and those, I if it gets doing an awesome job on security, man, Well, you have to, you have to kinda live in a world where, you know, everything is changing all the time.
Otherwise, you're gonna be catatonic with the, the amount of change that's happening in the, the attack surface getting so broad. And it, you know, to Alan's point he's made about the adoption of ai, the, it's, it's a train nobody's stopping. And the same thing is true to moving to cloud native to the edge distributed workloads.
You know, we think about what it looks like now, it'll look even a much greater, bigger attack service than surface in five years from now. I, yeah, the, the all cloud stuff, you know, SSPs, you know, outsourcing your security operations, you know, you know, like everything, it's been, you know, more than 30 years I've been following this along. And in that one of the best marketing pieces, maybe sums all this up, is IBM they had those blue and blue ads, God, I don't know, not maybe 20 years ago, but it's this great one, is this, you know, frantic little, little office conference room.
And these people are there and the, the big boss comes in and he, and he is like, okay, are are production down? No, no. Production's fine.
You know, is our, you know this down. I said, no, no, we're fine. Why are we here?
You know, it's like we're, we're a shirt company. Uh, we make shirts, you know, as you know, not a database company, not an I company. Yeah.
Even like, even technology security companies make security technology to sell. That doesn't necessarily mean they are network security, information security implementation companies. So at a certain point, you know, the adversary and security has, along with everything else, been evolving from script kitties to nation states.
And, and, and, you know, I've always thought at a certain point, not just the security, but yeah, the, the whole IT infrastructure needs to get out of the most companies. Agreed. You know, just a quick plug here.
Uh, cube Con London Cloud Native Con is, its alter ego name is in London, April 1st to the fourth, we will be there live, live streaming from London and replaying here on text on tv. Mitch, I think you'll be there, Mike, you'll be there. I'll be there.
We'll, we'll be reporting from there. And also, I think it's in July, our own Tech strong virtual event that we do every year on the state of cloud Native, cloud native now, which is also our website for Cloud native will be in July. This year's theme is one for the road, right?
Meaning we're taking cloud native on the road to the edge, the endpoint and everything else. Um, it's a bit of a Blues Brothers theme. And, uh, stay tuned for that.
So, and that of course is virtual, so be able to watch that on demand or live, and that's in July. But for now, Mike, Mitch, Chris and John, thanks for joining us today on Gang Thank you out here for listening to our rancid therapy session on, on getting it off our chest of, of, of the world we live in. Who was it?
He said, what a revolting, uh, development this is. But anyway, um, stay tuned. We have all Text Drunk TV following today's gang.
We'll see you tomorrow to end out the week here on this, uh, March week, first week of March. For now, though, that's it. It's Alan Humma.
We're outta here. This is Techstrong tv. Hey everyone, we're back here at Techstrong tv.
My next guest is Mr. Sterling Chin. Sterling is the senior developer advocate at Postman.
We're gonna get into what a senior developer advocate is and what Postman is. We're gonna talk a little bit about AI agents, but first, let's talk a little bit about Sterling and welcome, welcome him to the show, Sterling. Hey, man, how are you?
Welcome. Hey, Alan, it's great to be here. Thanks for inviting me.
Uh, my pleasure. So I'm looking at your background there. I'm glad to see this isn't one of those fake ones.
Looks like we got rockets, maybe. Is that what that is there? Oh, yeah.
I am a huge space nerd. Uh, I've been a space nerd my entire life. So, uh, when I moved into tech and started to, you know, be able to explore more, I mean, you can see all the rockets I've got back there.
I've got te I've got a Saturn five rocket tattoo. Oh, Very cool. It, it space is, I, I I'm a huge trekkee, and so space is always the final frontier for me.
Absolutely. Have you, have you made it down to Canaveral ca, Cape Canaveral, the Kennedy Space Center? I have not.
I live in Houston though, so I spend a lot of time. Oh, so you're in Houston? It's close, yeah.
Okay. If you get a chance, they, they actually have a standard five there. Yeah, they've got one here in, uh, the, in the Houston, uh, spa, the Space Center Houston, Yeah.
If you get do Canal. So I did this with my kids when they were younger, and they had this thing where you could have lunch with an astronaut and Wow. And our astronaut for lunch was, um, Cory Musgrave.
Is it? He, he flew like three or four shuttle. He repaired the Hubble twice.
Wow. He was like the Hubble repair man, and you wanna talk about the right stuff. This guy had a law degree, a medical degree, a physics degree, PhD.
I mean, he was, my kids didn't know who he was. They didn't care me. I was sitting there like, I, you know, I couldn't talk.
I, I, you know, you want me to sign your picture? They didn't care. I got the side pictures.
I was all for it. So I'll have to make my way down the Canaveral soon. Yeah, If you can't do the lunch with a natural, I mean, they have space camp there and everything, but you gotta talk to your kids or you gotta adopt a kid or someone bring with you so it, you don't feel embarrassed, you know, go with yourself.
Um, but good stuff, man. Good stuff. And, and it's also great you, I mean, if you can go there and time it around when they have a lunch, you know, it's nice, especially at nighttime launch.
I, I've And where we live, yes. From where I live sometimes you could see the nighttime launches, right. And I'm, I'm three hours south of there by car, so that's how visible they are.
Anyway, we went down that rat hole pretty quick. Let's stop talking about space for a second. Talk to us about your career.
What did, how did you wind up being your senior developer advocate? A postman? Wow.
Uh, yeah. So I have a fairly winded and, uh, non-traditional way of getting into tech. So I worked in the movie industry, uh, for 10 years, built sets, uh, out of college, uh, did transportation logistics.
And then eventually my best friend, uh, he was a developer, and he is like, look, you've got an I knack for this. You should look into it. I ended up going to a dev bootcamp back in, this was 20, uh, 2016, got into tech, and I spent, uh, quite a few years as a developer.
Went from junior engineer all the way up to senior, eventually became a tech lead that led me into, uh, engineering management. And I came here at To Postman as an engineering manager. And eventually I started doing more and more stuff online.
And the marketing team said, Hey, we like what you're doing. Why don't you give a shot at, uh, being a senior developer advocate? And now this is what I get to do.
I get to talk to the developer community, uh, explain, you know, you know, talk to, talk to 'em about tough, uh, problems and problems we're facing, and kind of try to be a thought leader in this, in this space. I love it. Good stuff.
That's a great story, man. So, Sterling, I don't want to, you know, say anything outta school, but there are people out here who don't know who Postman is. You know, if you had to explain it to 'em, what, what, what's Postman?
What do you guys do? In one sentence, I could say the postman is, uh, the API collaborators, or it's a way to collaborate when you're building APIs, it's a platform for building APIs. That said, it is significantly larger than that.
We have a massively large suite of tools that are gonna help developers in every step of the way, whether they're, you know, building an API from the ground up. So using, you know, the various specs to deploying, uh, your APIs, to also mocking your cert, mocking your APIs, testing them, uh, and everything in between. And now with the, the advent of ai, we now have a new suite of tools, uh, that we're calling the AI agent, uh, builder suite of tools.
And this is, these are a set of tools that are specifically designed to help developers build AI agents. Um, whether they're learning and or testing out an API or an AI for the first time, or they're actually building agents themselves and integrating with their own services and third party APIs. Fair enough.
You know, I, I first became aware of Postman a number of years ago, so you guys have done a great job, right? As you know, we live in the API economy, 57% or something like that, of all the traffic on the internet is actually API to API kind of traffic. So it is, you know, there's a big market.
It's the VCs like to say it's a big market. And, you know, helping facilitate that is, is a, is a major job. Now.
Everything is AI today, right? And now in 2025, more than just where last year was more generative ai. This year we're talking agentic ai, AI agents will do everything for us.
We'll have all these alter egos running around and we'll need an agent orchestrator and AI orchestrator or orchestrate our AI agents. But how do they actually communicate and do things probably via API, right? They'll, they'll be talking to ais and what's the difference between an AI agent and an API?
We could debate that, but you know, unfortunately, there's so much, maybe fortunately, unfortunately, there's so much hype and there's so much nonsense out there. You know, AI agents are going to replace developers. Uh, Zuckerberg says it may replace mid-level developers.
Bezo says it may replace low-level developers. I don't know what, you know, the next oligarch says, but they're all looking to cut developers and use agents. Other people say, Hey, don't believe that hype.
This will be your best friend. It's gonna make you 10 XA developer. Then you are Now tell us, you know, what's your take on this?
And why, why do you think you're right? Oh, man. Well, there, there are a few things to that you, that you talked about there that I think we could unpack.
One is, go ahead. I, I, I've, I've talked about this a lot. I, um, that you can't do AI without quality APIs.
So one of the things that you, you mentioned earlier in this is there's like, AI is reliant on APIs to actually become agentic. You know, generative AI with last year was great, but that's nothing more than having a massively large encyclopedia that can kind of plan and be prepared to, or can, can create, uh, new content for you. But in the era of ag agentic ai, this is where the rubber meets the road.
When it, when in my belief, you're gonna have APIs that are going to pass you information to another ai, and that AI is gonna then take action on your behalf. Now, to get to your big question, which is, are AIS or agents going to going to replace us? Yes.
However, I want to be a big caveat on that. I believe that AI is not going to replace us. It's as much as it's going to replace a lot of the menial tasks that we didn't want to do to begin with, right?
I, you know, I, when I was a developer, the last thing I did, the last thing I wanted to do was write tests. I hated, I was so bad. My, my senior engineers, uh, I, I regret, well, knew one of the senior engineers that was a senior when I was a junior.
And listening to this, I apologize right now, like the edge case testing, all that was so difficult for me to wrap my head around and, and I shipped more bugs as a junior and mid-level engineer in the future. And what I, and where I think we're gonna be getting to is we're going to empower junior and mid-level engineers to be 10 to a hundred X better than what they are now, and solve a lot of those menial tasks, those problems that we don't want to solve on our, or we don't want to do ourselves. So it's less about actually replacing us.
It's going to replace portions of us and allow us to do what we do best, which is being creative. You know, why, why, the reason I got into developing, and it's not a huge transition from my background in, uh, set construction in that is because I'm a builder at heart, and it's something that is just, it's innate in us. We want to build things.
And so being able to remove that, that remove some of those, those roadblocks of building is gonna be something that agent agentic AI is going to take, is gonna replace for us. Okay. Um, what about the testers though?
Are we gonna replace testers with agents? I don't think so. Uh, I think we're gonna empower testers to be even stronger in being, being better, right?
Uh, when I was, you know, one of the last companies I was working for, we had a amazing QA team, and we used puppeteer to, you know, do some end end testing. What we're gonna see with like, the likes of a, of operator or, uh, other ag agentic or other computer use is that a, a qa who's is, who's going to, who's going to use these tools, are going to be able to immediately come up with the, here's the work, here's the user flow through the my and the user journey through my app, and it's just gonna be able to write the test and then do that over and over and over again, and then test it multiple in, in various forms. So again, I don't think we're gonna be getting rid of them.
I mean, every, every large company has hundreds, or in some cases, thousands of engineering jobs still available. It's gonna help startups grow faster, and it's gonna help large companies, uh, fill some of those gaps where we don't have engineers right now. I think the, the last, the last census was that we've got around four 40 million to 42 million developers in the world.
I Don't, that's GitHub accounts, I think. Okay. Actual real developers, about 27 million is the latest number I saw.
Yeah. So if we're looking at 27 million, we have a lot more software to build, and so we're gonna need to empower those engineers to do more. So let me, let me flip that on you.
Okay. Right. Another thing, another numbers I've heard is, well, with AI doing coding for us, we're gonna go within the next seven to eight years, from 27 million, call it 30 million developers to 500 million developers, because everyone becomes a developer when you don't have to code, when the AI's doing your code and another AI checks it and tests it for you, and another ai, you know, publishes it for you.
Everybody's a developer and well, that's a great, what does that mean for the world? Oh, I, I think we're gonna have to face that fact. Uh, and I don't know what totally what that means, but let me give you a really great example.
My sister is starting a cottage bakery and mm-hmm. She pinged me. She's like, Hey, Sterling, you, can you make me a website?
She doesn't know how to make a website. And all I did was I, I got on a call with her, had her explain, you know, the color palette, what she was looking for, um, and, you know, kind of like the vibe of, of the, of the website. And I said, who's your, who's your customer gonna be and what's the goal?
Right? 7 was Released, came out. Yeah.
I just, I put that in and it spit out a website and within 30 minutes I was shipping a next JS app for her. Now I'm the middleman. And for her to be able to go in and describe what she wants and then iterate on that, absolutely.
Like this, I think what AI is really going to be good at is democratizing technology. It's gonna make small business owners who are interested in getting into tech, it's gonna make, it's gonna empower them, and it's not gonna be a cost, uh, you know, cost prohibitive. On the other hand, large, large scale organizations, enterprises are going to be able to do a hundred x of what they were, what they could even write, like, what they could even dream of.
You know, they thought, well, 20 years ago, or 10 years ago, or even three years ago, these weren't possible. Now it's all possible. Uh, and it, it's gonna be really, really amazing to see what happens.
I, I don't, I don't, I agree with you a hundred percent. I I think what's gonna happen though, Sterling is like that use case you just said with your sister, your sister becomes a developer, she'll develop her own site. 'cause once she sees what you did, it's not going to be very long where she could go on to Claude herself and do it, right?
Yeah. And there you go. You're out of your job, out of your job with your sister, right?
But, um, you're no longer the middleman and there go your cookies. But beyond that, you know, that does free up quote unquote, you know, professional developers to do things maybe that aren't that easy, that aren't just, you know, quickly typed in those, a prompt and off you go. And, you know, and then there's, it's one thing to say, here's your website.
It's another thing to say, okay, go deploy that I, I'm using GoDaddy host thing. Go put it up on my servers and, and, uh, oh, and get the domain for me too, right? While you're there.
That's what AI agents promise, right? It's that. Mm-hmm.
Okay, here's, here's this code I did for you. I want you to go use it, and I want you to go deploy it, I want, right? And that, at, at a company level, think about that, right?
Hey, I just finished this app, run it through agen AI testing, put it in my CICD pipeline, and if, and if the parameters are all there, let it go. Well, I think when, especially when you're in a large, when you're in a largest enterprise and you've got sometimes dozens of branches all trying to ship at the same time, I mean, we have, you know, we have these, these these dev teams who their only job is to look at deployment and can, and make sure all the branches that are coming from all the other, all the other teams are all working together with an agent that can do a lot of that, that's gonna free up those teams. We're gonna be able to ship 10 XA hundred x more.
You know, imagine instead of, you know, these, these Fortune 500 companies that have, you know, sometimes tens of thousands of developers, they're gonna ship not weekly, not, you know, monthly, or not quarterly. They're gonna ship daily and 10 XA day, man. Yeah.
It, John Hopkins said with DevOps, 10 x. Yep. It is gonna be interesting to see with DevOps, I, again, I don't think this is gonna replace anyone in DevOps, but it, but I think something that, uh, there was a podcaster, I can't remember what he, um, his name, I was just listening to it the other day.
He said, in reality, we're gonna become managers of agents. And that might be what it is. It's still that we need to know how to write code.
We still need to know how to, how to ship code, how to deploy it, how to do all of that. We may just be managing these large scales or, or large teams of, or armies, as someone else put it, of, of agents clone wars. Well, yep.
So I got some thoughts on it. So you're talking to someone who's from a generation where you weren't allowed to bring calculators into the test with you. Right.
You had to know the math. Now, today, you're allowed to bring your calculators into the test. A lot of kids can't do math without a calculator anymore.
They can't read cursive writing. 'cause we don't do that anymore. Does all of these agentic AI coding task, does it quickly turn to maybe not first gen, second gen managers of them no longer have, have that ability to code because the agents do it so Well, we don't have to worry about that.
I just gotta worry about how to manage 'em better. We may get to that point. I mean, I know Sam Aman said that, you know, 2035 is gonna look completely different than it is today.
What that future holds, I, I don't know. I maybe it might be that second gen managers who are doing this are going to have, are not gonna have as much code underneath them. At the same time, just like any other innovation, any other, any other time in our, in our history, whether it's, you know, horse and buggy to cars, whether it's, you know, the first flight to jet engines, to rockets, everything is just, uh, an iteration.
We'll, we will find new jobs, we'll find new ways of doing more. It might be that we're no longer coding. I don't know.
We'll see. But what I do know is for the, for the short term future, which is I think two to three years, I think we're going to, I think we will continue tore, like, we'll, we'll continue to see what this path holds. I have faith in the developer community that will take the right path.
So, All right. You know, let me bring this full circle as we end it. Maybe what we're headed for as a Star Trek universe, where humans just do what they feel like doing and, you know, and, and contributing to society.
We don't worry about money, jobs, or coding. Uh, you know what, that's as, as a huge longtime treche. It's something that I have actually thought of is like the Utopian Star Trek.
Mm-hmm. You know, instead of, we, instead of going down the Terminator route where, you know, we've got, you know, robots with that are AI that are killing us, uh, maybe we go down the Utopian Star Trek route where we have, we've overcome the need and the necessity for money. But I don't know, that's, I think those are, those are things that we'll have to face in the next, well, 10 to 20 years Live longer.
Prospered, dude. Alright, Sterling, thanks very much for coming on Text Drug tv. This was a great conversation.
Postman, what's the website? com. Check it out.
Sterling Chin, senior Developer Advocate Postman here on Tech Drug tv. We'll take a break. We'll be back in a moment.
Hello and welcome to the digital CXO podcast. I'm Amanda Ani, and I'm so excited to be here today with Joe Warn. He is a security expert at Hosting Advice.
How are you doing? Hi, Amanda. I'm good.
Oh, how are you? Thanks for having me. Thank you for coming on our show.
So, can you share a little bit about hosting advice? What do y'all do over there? com.
And, uh, it's a website where we simplify web hosting decisions through expert reviews, industry insights, and, and lots of, lots of educational content. Um, so we help millions of business owners and IT professionals each month make informed decisions about their digital presence, um, from selecting the right hosting provider to understanding security implications of just building a website. Uh, so, you know, recently we conducted this, this sort of eye-opening survey on Americans attitudes towards digital footprints and end of life planning, which, which isn't usually thought of when, when, uh, when you're planning about things that, that may be involved at the end of your life, such as, you know, a trust or a will or anything like that.
Um, so it revealed, uh, just so much, uh, information and these significant gaps in how people prepare for managing their digital assets after death. So, you know, I'm really excited to talk about it with you and, uh, yeah, thanks for having me on. Absolutely.
This is a very important topic that I feel a lot of people will be tuned into today. So first of all, tell me what were some of the results, the really eye-opening results that you can share from this survey? Yeah, so I guess the key point, the, the, the one that really stood out to me is that, uh, about 80% of Americans recognize the importance of a digital afterlife plan, but only about 57% create one.
And that shows, to me, at least that end of life planning is, you know, it's hard enough as it is. And, uh, digital assets are often overlooked. Uh, so, you know, it, it's, it's sort of a morose topic that, that most people don't really wanna talk about, or they, they just, you know, push it off and push it off through, uh, through, over years and years.
But considering how, how vast our digital presences are these days, uh, this should especially be part of that planning and we should talk about it more. We should become more comfortable with the idea of, you know, what, what should happen with my, my Facebook account or my business website or, uh, my Fidelity account or, you know, an investing or banking account. All of those, those elements online, uh, there are thousands of, or hundreds to a thousands of accounts that you and I both have control of over our lives.
And, you know, we need to, uh, understand what happens to them afterwards. Absolutely. And I think when people do try to plan, they are thinking more on that financial side and less about all the social media pages that they're a part of, the apps that they're a part of.
And these days, I don't know about you, but I have like a hundred apps all organized on my phone. So, but I don't think we think about things like that when it comes to afterlife planning. Right.
And that's absolutely true. Um, I've experienced it a few times, uh, with my, my grandparents. My dad has gone through a lot of it where he, he has to manage, uh, you know, if someone, uh, is to pass away, you have to manage all of these accounts and you don't realize that there is such a burden afterwards, um, to some of your love loved ones who might have to, um, go through some, some legal action just to get access to your accounts.
And, uh, that's, you know, it's a bit scary. Uh, there are, there are many common security issues that people face with digital assets after they pass away, such as like, uh, unauthorized access, den identity theft and emotional distress. That's the one that I always tend to focus on because we don't realize, you know, our loved ones might really struggle just to get access to, um, a banking account.
You know, something that you might think, well, my, my spouse or, uh, my kids or other loved ones, they might of course have access to my bank account after I pass away, or, uh, or my investment account or my social media account, or, or perhaps a small, a family business website or a domain name, anything like that. Um, but it's not as clear cut as that. Uh, you know, it, it, you, you might find out that it's much more difficult.
You have to go through a lawyer. You might have to prove that one, you're related to this person, and two, that that person actually wanted you to have access, uh, to these accounts. Uh, so there is, yeah, there's a lot that goes into it, and that's why it's, it's, it's very important to, to, to have some sort of plan.
One thing I've noticed, I do know that's a big concern on Facebook when someone passes away, I've seen accounts get hacked, you know, those stagnant accounts that are sitting there, and somebody will take over those accounts and try to use their identity to manipulate individuals. But aside from that, what are some, from a cybersecurity standpoint, what are some of the negative implications of not having access to any of those social media accounts or apps after someone passes away? Yeah.
Um, like I said before, there, there are, uh, you know, plenty of, of issues when it comes to emotional distress. But, uh, I would say the, the, the real, uh, tangible implications would be like unauthorized access. So if a hacker were to target an inactive account in a fraud scheme, uh, you know, that could happen when you're alive.
But it's, it's also, uh, you know, there are all these, these stagnant accounts when, when people pass away that are just kind of, of sitting there to be, uh, taken advantage of in, in, uh, fraud schemes and scams and all sorts of things. Uh, if, if you are not, uh, controlling the, the logging credentials. And then there's also identity theft, again, something that we think about when we're alive.
Um, and many of us fall victim to identity theft, but it can also happen afterwards where a deceased individual's personal data, uh, can be exploited. Um, so those would be, yeah, the two main things. And then of course, the emotional distress, uh, would be a core implication that I've always seen as, as something that people don't often think of.
Absolutely. Having to go in and handle someone's Facebook account after they've passed away and filtering through all the messages. And how do you respond to all those individuals?
I, I imagine it could definitely take a toll emotionally. So what advice do you have for people when they're planning for, um, their afterlife plans? What advice do you have?
Um, well, I would start with trying your best to not feel overwhelmed by it. Um, and I think conversations like this can be helpful to, to realize that, you know, it's normal. This is something that all of us have to go through.
Um, one of the key stats that we found is that 57% of, of the respondents in the survey, they felt overwhelmed by the digital afterlife planning, which often leads to inaction. And that's the worst thing that could happen. Um, so I would say that my four, uh, key steps that anyone can take right now to make it much easier, and, you know, you could just follow it step by step is, is to one, uh, choose a dig digital executor, uh, someone you can trust to manage your online accounts.
And often this is, um, a professional, so like a, like a lawyer, or it could be someone you trust, uh, uh, one of your relatives or one of your kids. Um, but it, it often ha is a combination as well. So it would be be something more official like a lawyer and then, uh, uh, someone in your family.
And then of course, I would say create an inventory. So list all accounts and passwords in a secure location. My preference for that would be, uh, a digital password manager.
So something that I can, uh, control myself digitally and then pass on to someone else with one, like master password. Um, but there's also the potential, I know my dad, he just put it all in a binder, but it was very nicely organized all the accounts and passwords for every single one of his financial accounts, um, that, that, uh, we, as you know, his, his, uh, his, uh, kids could look at and easily identify, you know, what are, what are the account that we need to either shut down or the accounts that might be, um, might require maintenance, or the ones that might require us to, to manage Yeah. In the future, because they have money in them where they have, uh, sensitive information.
Um, and then the third I would say is to communicate your wishes. So decide whether account should be deleted, uh, should they be memorialized or should they be transferred? Because many times, uh, the next of kin won't know what to do.
Do you know I, is there an account? Uh, or is there an old small business websites, uh, that could potentially have value? And did that person, uh, want it to be deleted or memorialized or something like that?
Um, there's more personal decisions than there are definitely more practical, uh, official decisions that you might need to make. Uh, but lastly, I would say, and this is something everyone can do it, you could also bump this up to number one, and that you should review the platform settings. And that is very easy.
You could do it right now, you could do it tonight. Uh, some sites allow you to designate a legacy contact, and that is one of the, the easiest ways to streamline the process. So, you know, if you went onto your, uh, uh, brokerage account or, uh, where you have your IRA or where you have just your regular checking account, um, you can, you know, write in there where, who you want to have access to your account next.
And, uh, you know, it might not grant you total access. Uh, you might still have to go through some sort of legal process, but it at least gets the ball rolling and shows that, you know, the person who owned that account before made a very, uh, direct action to, to identify the person they want to, uh, to access that account. Absolutely.
So if somebody doesn't take these steps and do this pre-planning, and they're left trying to gain access into all these various apps and social media platforms, how difficult is it at that point? Are they even able to? Uh, yeah.
I mean, they are, they just have to get legal permission, and that's something that, that no one really wants to deal with, especially after someone has passed away. Um, family members often struggle to access accounts without legal permission. So, uh, and there's other things too.
So it's like, if there are unpaid subscriptions or digital assets, uh, one of my favorite examples is, uh, like a domain name. If you had, uh, a family business that had a website with a domain name, uh, that could be lost or exploited forever, um, because you could, it could, uh, become expired and then there could be a, uh, digital squatter that purchases that domain, and then you never have access to it, and you totally lose that, that, uh, that branding whatever value behind the domain there is. And then, uh, just, I don't, I guess the legacy, uh, behind having, uh, a family business like that.
Um, and then of course, old accounts can't also linger online. Uh, so I, I covered some of, uh, the, the things that could happen with that leading to potential misuse. Uh, but yeah, you definitely don't wanna be leading, uh, certain accounts online just for anyone to, to, to scrape.
Absolutely. There's so many things to think about just from what you've mentioned that I would not have considered. I'm sitting here thinking, okay, what do I have online?
You know, and there's a lot. So it really is important to think about. So now we have this new technology, AI has come on the scene, now there's even more to think about mm-hmm.
The implications of AI use from different threat actors. Um, where are your thoughts on ai? Uh, well, in terms of, uh, the digital afterlife, uh, I guess it's, it's really no different that, like, if are, are you asking if, you know, you were to sign up for like a chat GPT account or, uh, Well, I know that now we have DeepFakes ai, you know, being used to still images, um, turn, you know, turn into different stories about people that look real, that aren't, Right.
Right. And yeah, that kind of opens up a whole nother can of worms. Uh, you know, these could be digital assets that you, um, never really owned in the first place because they were either manipulated or they were stolen from you, or maybe you did own them in the first place and they were taken, um, or they were just created out of, out of an air, uh, almost.
Um, so yeah, we're gonna have to, uh, see hopefully some sort of regulations or oversight to, to figure out, you know, let's say, yeah, there, there is some sort of deep fake, or, or a video or an audio clip or a picture that is created, uh, using your persona or your likeness. Um, how would that play into the, the, the equation? Uh, you know, would you be able to claim ownership of it and have it shut down?
Um, the issue is that it's already difficult to do that when you're alive. Um, so yeah, I mean, there's still a lot to be discussed and, and you know, like we all know we're in the wild west when it comes, uh, to ai, but, um, in terms of protecting yourself, uh, yeah, there, there's, there's, uh, a lot to be said, but it, it, it's still, we're, we're still kind of waiting to see, uh, what happens with all that. Most definitely.
Well, if there was one key takeaway you could leave our audience with today, what would that be? Um, I would say that, uh, don't feel overwhelmed when it comes to the digital afterlife. Um, I pushed it off for a very, very long time.
Uh, not even just digital afterlife, but creating a will and testament and, uh, you know, trying to figure out what's best for my family if I, if something were to happen to me today or in 30, 40 years, you know, whenever that may be. Um, but I, you know, I just think everyone should know that, uh, the world is, is becoming a little bit more complicated with AI and all of that. Uh, and it can feel overwhelming and it can feel like you have a lack of knowledge.
Um, but you have the most control over your digital identity. Um, and there often is this false sense of security that many assume that their family can access accounts easily. Uh, but that's not really the case.
There are legal barriers that exist. So I would, uh, try your best to, to know that, that you're in control of all of it. And even if you have a lack of knowledge, there are people that can help you out.
There are lawyers, reputable lawyers who, um, uh, uh, so, you know, you can consult with an, a state deter, uh, a state lawyer and, uh, you know, they can be really helpful and just walk you through the entire thing and essentially write it up for you completely. Um, so that, that lowers that, that level of overwhelmingness, uh, that I think a lot of people really struggle with. Um, but yeah, I, I just want people to be confident and, and know that this is the best for their future and the future of their family going forward.
Well, thank you for coming on the show. It's certainly something I'm gonna have to put on my to-do list now. So thank you so much, and thank you to our audience.
Stay tuned. There's more. This is Textron tv.
Hey guys, thanks for the throwaway here with Tamim Ani, who is founder of Rap Dev, and we're talking about how to maintain this blameless culture that's kind of at the core of our philosophy of DevOps. Even though the volume of software continues to increase, things are more complex than ever, and there's more dependencies than ever. So we seem to be working at maybe opposite goals here in some ways, but we'll see how we go.
To me, welcome to the show. Thanks for having me, Mike. Uh, good to be on.
So what do you tell people about how to kinda maintain their sanity when a thousand things can go wrong at any given moment? Do, do go wrong, right? Um, I think it's important to understand that things will break and, um, nobody wakes up, uh, one morning and says, today's a good day to break something.
And, uh, I think figuring out how to enable, if you enable a true blame culture or as close to it as possible, I think you get the most outta your engineers. A lot of it comes down to understanding how to enable that, right? And, um, when we say blameless culture, um, if something breaks, you don't wanna find the person that broke it.
Uh, it's generally, um, a proxy of a system that isn't resilient enough. And that's the theme around a blameless culture from an engineering perspective, is making sure you build a system resilient enough so that if mistakes happen, if bad deploys go out, um, you can quickly identify what the problem is and how to roll it back. And there's kind of a few different segments to that.
It's, um, historically we've always done a really slower, uh, command and control prevent changes. That's how the industry tended to work 10, 15 years ago, even five years ago, right? Change is bad and you're always looking at these metrics of 90% of outages are due to change.
And well, yeah, great, but if you don't change, you're not improving. You not building product, you're not innovating. Um, so how do we balance the two?
And I think we're starting to see things swing over to promote change. Um, more change is better as long as you have the right boundaries and the right, um, culture is one of them. Uh, I hate process, but as checklists in place to make sure when changes break your systems, you can, uh, make them better the second time around.
In theory then, if we're trying to make sure that the systems are resilient, maybe we should celebrate the fact that somebody broke something to highlight the Fact identify Resilient. You got it. Abso after you fixed the problem.
Yes. Uh, don't celebrate until, until you rolled it back. But that's, that's kind of the, that's kinda the point, right?
So like you go, there's like the first version of hit this is, how do I make sure that no matter what it is that's been deployed, can be rolled back, can be rolled by quickly. You get into different things around ab deploys, blue green deploys, uh, feature toggles. There's n number of ways to put the right tech in place to prevent outages from lasting too long.
They will happen, uh, a five minute outage is better than an hour outage, and a one minute outage is better than a fi five minute outage. Um, how quickly you can put those systems in place and use them becomes super important. And then the second thing is, yes, once you've used that system to prevent or to roll back an outage, how do we make that system better?
Why did it break in the first place? Is it bad code? Is it bad testing?
Is it, uh, a some part or some, uh, outlying component of our platform that doesn't behave the way we expect it to? Uh, is it a capacity? Is it a a scale, auto scale issue?
There's n number of things that could go wrong, but once you've found a problem, you make sure that it's, uh, identified, resolved before your next deploy goes out. I feel like though rolling things back is harder than people like to admit. And maybe that's also part of the resiliency issue.
So how do we make things easier to roll back so that we can feel confident in experimenting with things? Well, Ro rolling back can mean a mul multiple different things, right? Um, rolling back doesn't mean you have to literally roll back the package you deployed.
Uh, that's where the different deploy methodologies come into place. But feature toggs is a great example. Um, I'm not, I'm not sure, uh, how, how granular you wanna get, but essentially you select what percentage of traffic goes to the new code, and you start with 5%.
Um, and you have both, both versions of your codes deployed in production, and you can slowly start to send traffic over. Uh, and that's a great test. That's a great, um, business test as well.
You're, you're measuring the business impact of the CodeDeploy. A super simple example I like to use is you change the color of the checkout button from green to red. Do you lose people?
Do people stop seeing red? Uh, do people see red more? 'cause they're colorblind and green's harder to see.
All these things come into play, but you do them with a very small percentage of traffic. So if that percentage of traffic is negatively impacted, all you gotta do is toggle it back to zero. You're not really going in and rolling back your code.
You're just saying don't send any more users that way. That's one method of, uh, toggles of, sorry, of directing traffic. Same concept applies at the whole package level.
So you've got two different clusters running your application or running your service. You just start to send users from one cluster to another, that that's ab deploys. Um, and then you can, you can roll through so many different variations, but to your point, actually moving that, uh, that package or that block of code out of production is so much harder than just moving the direction of your traffic from one subset of, uh, service to next to the next, or pods or name spaces or whatever.
It's, It sounds like I need to be able to orchestrate that. So what is the, for lack of a better phrase, a, a control plane that enables me to kind of manage that traffic flow and make sure that the components are, aren't overloaded? 'cause somewhere along the line, I need some way to manage this thing Totally there.
This, we, I mean, obviously wrapped up, we're gonna have a bias, right? We work with ServiceNow Datadog, um, and both are super important. ServiceNow from a, um, a kind of record perspective.
So what is going on? What is happening? Let me keep track of all this stuff so that once this, uh, blast radius is sorted, I can go back out and look at everything that's happened.
Uh, so that's kinda one piece of it. Um, on the record keeping, on the actual control of, uh, traffic and where it's going. We use Datadog extensively.
Um, uh, Datadog is a really good indicator of the health of your traffic, the health of your application. Um, every time a deploy goes out, am I seeing an impact in response codes, access logs, uh, HGTP codes, right? Um, and at the same time, that's coupled with some sort of feature toggle tool could be launched darkly, uh, could be homegrown.
We've, we've done a lot of homegrown custom feature toggle tools with some really solid caching that accomplish the same thing, right? It's not really that hard, but measuring the impact is what's important. And that's where observability comes into play.
That's where Datadog comes into play. Um, anytime something blows up, everyone's gonna say, it's not my fault, right? It's that team.
It's that team, it's not me. And that's the, that's the opposite of blameless culture, right? You're trying to say, Hey, let's figure out technically what broke so we can technically improve our systems.
And that's where really solid observability comes into play. Do you think that some of these challenges might get worse in the age of ai? 'cause we are now generating more code than ever, and a lot of that code, um, maybe suspect 'cause it was created using models that were trained using code that was probably flawed, Worse and better.
Um, I think even just because you're using, uh, some sort of models to generate code, it doesn't mean you should circumvent all your automated testing and automated, uh, uh, scanning security scans. That should all still happen. Um, you're not saying I'm generating code through some sort of co-pilot, therefore this is safe code.
Uh, another kind of layer on top of that is even though you're using a third party to generate code cursor, et cetera, um, a human is still behind the screen watching what's going, what's being merged, what's getting prd. So on that front, um, it's helping you get faster. It's helping you get more eff more efficient.
It's not replacing the need for anything that's currently in place on the production side or on the deployment side. You can actually generate code to fix your bugs. So if you do detect something in production, you do know what merge went out, you do see a slew of alerts coming in through observability tools.
Um, instead of having a human review and determine what's going on, you could use models to say, Hey, here's my error log, here's the commit that broke it. Um, what do I need to modify in that commit? So you could actually generate, and we're, we're doing this, uh, for customers already.
We generate a whole new PR with the fix as a commit in the PR to essentially resolve the outage that's happening. And that can save a ton of time, right? That goes back to, um, do I want to turn my toggle off and go back and look at it as a human and take a week to come back?
Or do I just wanna look at what my agent, right, or whatever buzzword you wanna use from for LLMs is suggesting the solution is, and that could very well be your fix. I mean, as a human, you look at it, you say, oh, duh, I should've thought of that. Um, but when it's, when it's generated on the fly, it does save a lot of time.
So you could use, you could use AI on both the, the dev side and the production side, uh, pretty effectively. So in effect, I am using AI to help heal the ai. Yes.
Um, and I always use, yes. Uh, ironically, I always say we use AI to generate, uh, a 70 page deck to mail to someone to use AI to summarize the 70 page decade to three bullets. There's a lot of that going on.
Um, it still makes you go faster, right? At the end of the day, if it helps, if it helps you go faster, if it helps build momentum, if it helps with velocity on the engineering side, I hate PowerPoint. I don't think there should ever be a world where we're using AI to generate 400 pages of PowerPoints.
And I think that's one of the areas in business that will get impacted very quickly, very heavily. But with, from an engineering perspective, you're building features, you're putting features on your platform. You can do that five times faster and maybe take a hit every now and then, but you can resolve that hit faster, then why not?
Um, nobody's gonna be able to, no human is gonna consume 400 pages of slides. It doesn't matter how good you are, you're gonna summarize them. That brings you back to square one.
How is this gonna evolve as we go forward? We hear a lot about AI agents, and I can imagine a world where what you just described, some of those tasks are being handed off to an AI agent that's got a member of the DevOps team, as it were. Um, I wouldn't think of them that closely as like, I wouldn't, I wouldn't translate an agent to a human.
I think an agent is a subset of functions or methods that will execute. Um, and re and like agents are essentially, you make a prompt, you get a response, you run that prompt through another prompt, and you try to, you try to improve upon the response you're getting from a model. It's just three or four steps instead of one.
Um, it's very unlikely that you're gonna get a very accurate response from a model on the first prompt you send it. Um, so I think of agents as a refined, uh, kind of conversation, if you will, with a given model. Uh, but yes, there definitely is a world where, especially on the kind of the lower end skills, things like password resets, things like add me to an ad group, things like really low, low level help desk is, I think is gonna be very impacted by this.
Uh, call centers will be our, we're already seeing, um, tens of thousands of people being put out of call centers because that's a very easy thing, uh, to manipulate and to move over to generative AI models, right? Or, uh, generative audio, just not lot language models or audio models or video models, um, that can be very easily done in real time, uh, especially with voice tokens instead of text tokens. So you can start to run things in parallel.
Um, but all that is to say absolutely all the low level stuff, um, that's historically been, uh, offshore near shore model. 'cause it doesn't cost as much when it gets offshore, will be replaced with, um, a lot of different AI models in the next two to three years. And anybody that's not saying that, um, I think is crazy.
Uh, we're definitely gonna start to see that. So let me bring this full circle a little bit. If we think about blameless as a culture, it was always kind of the, the high end of the DevOps h mark.
Yep. It, it was in the sense that, you know, I had to be pretty mature in my DevOps workflows to get to that kind of blameless mindset and kind of feel that if I have AI and I'm starting to automate more stuff, well, more organizations get to that level of, let's call it DevOps nirvana, because they're gonna understand that the system itself is designed in a way that enables them to maybe stop pointing fingers at Each other, be resilient. Yeah.
I don't know if it, you don't have to be super mature to how I blame this culture. I think it's probably the opposite. You can be very mature, but the way you approach your have to maturity could be very wildly different between a blameless organization and non non-believer organization.
And what I mean by that is you can work somewhere with a ton of bureaucracy and red tape and be immature. Um, but the way you try to become more mature in your platform, your code base, your microservices, your application, whatever it is, is very much, Hey, every time something breaks, we're gonna sit in a room and we're gonna meet and we're gonna find out who wrote that code and why they didn't take their training and because they didn't take their training, we're gonna blame them for writing bad code versus a a, a platform in the same maturity stage. But every time something breaks, you're gonna say, Hey, what can we, what guardrails or what tech can we put in place that prevents this from happening a second time?
Both of those are immature, and both of those will find their way to maturity, one through a different culture, faster culture than the other. Um, historically the tech industry has very much been a world of slow down, don't go fast. Don't break stuff, don't work, work, let's do everything on weekends.
Let's do everything on Friday night. If you break something on the weekend, it's gonna take you eight hours to get the right team on board. If something breaks at one o'clock on a Monday, everyone's already online, you can fix it a lot faster.
And that's just the mind shift in, uh, in that culture. So AI being a benchmark sure is gonna help, but you can still very much, uh, accomplish that benchmark without having, um, without having to leverage AI to get to that blameless culture regardless of maturity of your platform, maturity of your team, organization, et cetera. So thinking this through a little bit, um, you know, you hear the phrase over the years software factory.
Yeah, I understand the concept, but I also feel like, you know, it winds up taking people out to that woodshed every time there's a problem. And that necessarily doesn't necess create their culture you're looking for. So what is the balance between art and science and the world of software engineering?
It's a, it's a very open and, and question and also just software factory is everything Factory, right? Is let's build a factory, let's build a t-shirt size factory, let's build if, if things are that simple and that, um, reproducible, you wouldn't need that many people working on whatever project you're trying to build a factory for, um, chances are they're very low likelihood of things being that, um, uh, repeatable, right? In an environment where you need to migrate thousands of VMs or get out of a data center or refactor from a monolith to microservices, there's no factory model.
Um, I do think the higher up, the higher the, the more complex engineering problems require a little more art. I think that's where you start to differentiate between what a copilot can do and what a very experienced, um, software engineer can do regardless of, I'm not gonna say someone of the bachelor's or masters in any of that, 'cause that's also kind of irrelevant, but it's how much have you seen, right? And the difference between, uh, uh, a software architect or somebody with a ton of experience that knows how to design patterns or how to design libraries or frameworks is gonna be a lot more relevant in two, three years than somebody who just knows how to write a function that will very quickly be replaced by copilot.
So I think we're gonna see a push to really force engineers to become a lot more, just, just think a lot more, uh, creatively in the way they write their code versus just write a prompt that gets the job done. Um, and then performance comes into play and scale comes into play. Those are the things that it's gonna take a little longer for some of these models to catch up to.
Uh, versus a human that has seen this for a long time, that'll become the differentiator in my opinion. So what is that one thing you see DevOps teams doing over and over again that just makes you shake your head a little bit and say, folks, we can be better than that? Um, that's a good question.
I think a lot, there's a, there's a really, really big misconception that, um, infrastructure patterns, infras as code are gonna solve all your scale problems. Uh, that's not true, right? Uh, just because you got, just 'cause you moved to Terraform or you're writing Ansible playbooks, um, you still gotta think about the way you're scaling up and scaling down your services.
Um, autoscale groups and helm charts, uh, are not the final end all be all. Um, you can, you can get pretty far with a lot of the kinda standard auto scaling stuff, but that starts to incur a ton of cost and being able to balance those two, um, you're not done when you've moved everything to, uh, to infrastructures code. You're still a lot of work to tune that down to make sure cost is under control and you don't have long lived, um, workloads that don't need to exist.
Uh, scaling back tends to be where things get a little more hairy. Um, and that's, I think I've seen that over and over again. That's, that's not something, security is another interesting one.
We're starting to see a lot of, um, SEC secure. I mean, I think we will see more of this, but we're already starting to see more security shift into DevOps teams. Um, and you're really self-servicing your security needs through, uh, infrastructures code versus having to go to security team to do what, what, what we historically used to do, right?
Gimme access, gimme firewall rules, gimme traffic patterns, that'll continue to move, uh, in the, in the way of, uh, kind of shifting to the developer, just the same way infrastructure shifted to the developer of the past five years. I think security will follow. The security team then will just be focused on policies, um, procedures, making sure, um, guardrails are in place, but the way they get implemented and changed will definitely move, uh, more into the gi GI ops model.
So things are clearly pretty fluid and we hear a lot of phrases like platform engineering being one of them in the final analysis. How do you see DevOps kind of evolving from here? I think we're gonna see more.
Uh, I mean, DevOps kinda means DevOps is used for a lot of different things. I think generally thematically we'll see more infrastructure being managed by developers as things continue to scale out. And as a lot of the infrastructure management tools and platforms, uh, become more, um, stateful and code focused, I think there, there will be a layer underneath for shared services, which is platform engineering, which is, uh, you're caching your DNS, your, uh, traffic patterns, your network layer.
That stuff doesn't really need to be managed by developers. But I think a lot of the infrastructure stuff, the auto-scaling, we will see more and more of that shift over. Um, I don't know if that's exactly what DevOps is gonna be in five years.
The, the, the term DevOps is frankly just morphed. Uh, and we'll continue to morph. DevSecOps is now a thing, right?
And GI ops is a thing, and all those things continue to change. Um, but I think we'll see more, more control, uh, in the hands of developers, uh, than we have in the past. I don't think that pattern is gonna change, Right folks, Aaron, and here, one way or another, we wanna deploy more software safely, faster than ever.
Each organization may get there slightly differently, but that's where we're all going. Tamim, thanks for being on the show. Thanks for having me, Mike.
All right, and back to you guys in the studio. Hi everybody. Welcome.
We're glad you've joined us today for another episode of the latest greatest cloud transformation, late great cloud transformation. We're talking about really sort of the next generation of how we think about the cloud and the things that we're doing with it. We're talking about security today, about safeguarding innovation and, uh, strengthening that security where we can, jumping into app app security and a lot, a lot of things here.
But, um, before we get too far down the road, thank you for joining us for this video series. Uh, the, the last great cloud transformation is sponsored by CloudFlare. We're glad to have them, uh, on board with, with us working on this, uh, helping input with some topics and things like that.
And obviously participating on, on our, uh, live editions, which we do on a monthly basis, as well as these recorded episodes. So thank you for being here with us. My name is Mitch Ashley, I'm VP and practice lead with futurum Group, analyst firm, uh, heading up the analyst area for DevOps, DevSecOps, application development, AppSec, et cetera.
So kind of right in, in vain with this, uh, my co-host Alan Shimel is, uh, unattainable, uh, de detained or whatever the word is the phrase is. And, uh, so I'll be, I'm, I'm hosting both parts of the chair today. Uh, you know, it's a little bit of a coup, but he'll be back next time.
We'll see him on our next episode, I'm sure. So let's get to our conversation, to our topic. Um, let's first start by doing some introductions.
I know Chris has been with us on a few episodes here on some different topics. You've been on other webinars with me and talking a lot about application security and, and, uh, cloud. Chris Blas, introduce yourself.
Oh, I've been for company my way through the security industry for 30 something years. Uh, I inflicted an early firewall in the markets, something called border wear, uh, in the early nineties and ran Cisco's firewall business, the turn of the century. I've been following this inevitability curve, uh, my new series on here on Textron, um, from one spot to another, from firewalls into, uh, sim and network management.
From that, you know, the obvious next step is threat intelligence. So I, uh, chaired an ISAC for a while, and, uh, supply chain has been my focus the last five or six years, you know, so, you know, software, bill of materials, hardware, bill of materials. How do we connect all these things, which a and, and currently, so currently I'm, my main role is I'm vice president of strategy for sibe, which is involved in the SBO M space.
And I've been, uh, co-sharing several, uh, cisa uh, working groups on s om sharing. So we're currently have a group looking at ISACs, um, as s bond distributors. How does that know in the middle start taking this information and propagating it As bomb software bill of materials?
Absolutely. Great. Thank you Chris.
Um, Katherine, Katherine, welcome. Glad to have you on, I think the first time we've had you on the show. Katherine Newcomb with CloudFlare, please introduce yourself.
Yeah, great to be here. I'm excited to talk about application security. Um, my name's Katherine Newcomb.
I live in Denver right now. Um, I've been in cybersecurity for about five years at this point. Um, and I started in the network firewall space, um, and encryption.
And now I'm a product marketing manager for CloudFlare, um, for their application security business, uh, where I focus on their web application firewall product, um, our software supply chain product, as well as our encryption and certificate lifecycle management products. Very nice. And, and I do like to say full disclosure, Textron, you as a customer of CloudFlare, we do use their services.
Enjoyed very much so thank you Catherine, and team for that. Uh, last but not least, another newcomer to our show, Kurt Handel, who's with, uh, Teradata. Tell us about yourself, Kurt.
Yep. So I've been working in security probably eight or nine years at this point, uh, but in the software industry for close to 15 years now, anywhere from development, uh, into business analysis, product management, even, uh, doing a little bit of red teaming myself. But, uh, I am currently the chief security architect at Teradata.
And so I've been focused on architecture mostly for the past six, seven, possibly eight years, and really kind of a generalist. So AppSec is where I spend the least amount of my time when we focus on the architecture, the requirements, threat modeling, um, especially compliance. We do a lot of the, the major compliance frameworks at Teradata.
So we've been pushing that recently. Um, and I'm based in the Pacific Northwest, up in the Seattle area, and happy to be here. Very nice.
All the weather and fires and it's cold and I'm just glad we all made it. Maybe it's 'cause we didn't have to travel anywhere, so, so I hang tight. I'm glad we're all here.
And you know, our, our thoughts go, our hearts go out to the folks dealing with the fires and, and, uh, some weather down south and southeast, et cetera. So, um, let, let's kind of jump in this way. Um, it, it's a big topic when we talk about sort of the kind of current state of the cloud and where it's moving to.
Um, but I don't think it's too much news to everyone that application and app APIs, API first kind of design into applications, you know, it isn't just things that sit at the edge anymore. We think about also the security of the apps and the kind of, uh, software we're creating, the innovation that we're making, um, as maybe as part of the cloud. 'cause sometimes application lives within it, you know, like a, like a provider like CloudFlare or certainly at the edge or at the core as well.
Maybe Catherine, if you wanna start us out with how do you, you're, you're, you're managing, doing product management in this space. How do you look at this, uh, sort of this problem or this space and define it? Um, so looking at application security, um, when we're talking about this at cloud, we're mostly talking about web application and API security.
So if you're an OSI person, layer seven model, um, and you know, when people are accessing these external facing web applications, they're doing it from a ton of different devices and in a ton of different ways. So they're accessing from things like mobile, uh, desktop, laptop, and they're accessing these apps that could be hosted anywhere. So on-prem, in public clouds, private clouds, hybrids.
Um, so as we're securing, we need to think about how can we secure, um, all of these users and the end servers as they're sort of accessing these web apps, right? So how do we make sure that, um, mobile traffic is protected, user data is protected, um, and sensitive data is not, you know, leaving an app. And then how do we make sure that a web app server itself is protected?
Um, so at a very high level, that's about what I think, that's what I think about when it comes to application security. Um, some new things we're thinking about in this space. Um, I talked about software supply chain.
This is increasingly becoming, um, an area of interest as people create more complex apps with more third parties in them. Of course, API first development has also meant we've had to adjust our thinking a little bit around application security as well. Kurt, how about you as a, as an architect, security architect, you may, maybe you don't get into the innards of applications per se on application security, but traffic over there, obviously our networks are heavily API driven.
Um, you know, when you think about the security architecture, where does this fit into your purview? I think it, it fits in really everywhere, right? So we're, we're building these huge applications, sometimes small applications.
I mean, we do all sorts of scale at Teradata. And in my previous roles, I've, I've worked with pretty simple apps all the way to super complex microservices architectures. And so, like Catherine could have said, you have the mobile aspect, you have the server, there's application code literally everywhere, including on the person's device.
And so how do you secure it as best you can, um, within reason, right? Because if it's too secure, it doesn't work. If it's not secure enough, well, you end up in the Wall Street Journal and you're in trouble.
Um, so we, from an architecture standpoint, we really try to focus on all different aspects of it, where the biggest threats lie, um, and, and implement controls and use technologies to, to simplify the implementation and streamline it without making it overly complex. And so it's, it's just becoming more difficult given that, um, the, the kind of classic perimeter is gone, right? I'm sure you can relate to that, Chris.
Oh yeah. Well, it was easy back in the day, right now, you had to get on the internet and you needed a firewall. Get a firewall, right?
And I'm thinking as Kurt and Catherine, your co remind me of these transitions we go through, like there was the mainframes before our time, but you know, I, I'm old enough to have seen the end of that where all of your capabilities are just to keep one computer running and run terminals and printers and things off that. And then we get into, you know, sort where I came in, where we're starting to build networks. Fractally more complicated.
Just, you know, how do we do that with, when all of our resources were just keeping one computer running, we figured it out, you know, now we're here, we're talking about web APIs, Catherine, you, you know, the data going in and out and with being stored 30 years ago, you couldn't have that conversation. Now we're saying, alright, what do we do in this case? And it's very complicated and I think in, and Catherine you mentioned the supply chain.
This is, I think we're filling in the dots. Security has been is not, i i is not new, right? People have been saying you should know your inventory for a long, long time, and we've gotten away with not knowing it.
Now we're starting to fill it in, need to actually know where the software is, where the data is, and we're working through that. So it's exciting times, but it's not different in type than other transitional periods. Certainly is an evolution, right, of what we've gone through.
And to think about, you know, from the bas and host days early, early on from free firewall, um, Well, firewalls used to be a million dollars a year. I think about it, I got involved, you know, at least as I tell the story, there were a hundred in the world and they typically were seven computers and a team of people. And my argument at the time was my mom needs one.
Yeah. You know, and so we're at this stage where what used to take so much time in here in the API, uh, world has to take less time a lot. It, it, so let me, let me throw out this hypothesis here.
I think it may be pretty obvious, but maybe it isn't, is I think we live in a world, you know, now we were thinking about things as zero trust, right? Of, of you, you know, anything is susceptible, being compromised and could compromise other things. How do you pro protect all parts of the network applications, the infrastructure?
But we're also living in a world where if so much is determined by what our applications do, not just connecting users to apps, but applications really utilizing the network, being part of the network. It's a dynamic world, right? It, it isn't a good set of firewall rules and an application firewall and we're all good, kind of set that up.
And it isn't the old days of I've got a pizza box in, in my rack for every function that I need, and they're all doing their thing. I'm good, right? We need it.
It's a much more dynamic environment. So I'm not saying we're reconfiguring our security all the time, but a security has to adapt to, you know, what's happening in the application. Because we may distribute it to a different part of the edge tomorrow with Kubernetes, or we may, you know, uh, acquire business and suddenly a network has looked much different than it did, you know, three weeks ago.
I'm, I'm curious, Kurt, as a practitioner, you know, how do you think about that of, you know, you mentioned microservices and all the things that are being created, you know, in the groups that you're working with. Um, we, we hate for security to be sort of the last thing to be thought of, but you wanna be in the conversation so you can prepare as well as react when you need to react. I think what you just said is, is really important, but you wanna be in the conversation.
You don't wanna be doing this retroactively. And so when you're, when you try to tackle security retroactively, it is infinitely harder to accomplish than if you do it from the beginning. So I have, I do it both ways.
I have teams that we work with proactively where they bring us in at the very start and we're building the design with them shoulder to shoulder, drawing the picture in doing security by design or by default, as we like to say now, or we have legacy applications, which you're doing retroactively, and they're quite a bit higher in terms of risk because they've been neglected for so long. Or you find out about something after the fact and it's like, well, how did this get out there? Well, there's shadow IP in a lot of the world.
And so it's, it's hard to, to really kind of put a, a recipe together that successfully achieves it. And then with the, the rapid pace of technology today and how the cloud has just kind of blown this wide open where people can deploy new applications in a hundred different ways faster than ever. How do you keep up?
So you have to implement tooling within reason without doing, without having too much sprawl. You have to have the right personnel partnering with these teams, uh, to ensure that you have coverage and that you, you're really architecting things from the start, um, and not just kind of using bandaids and bubble gum per se, to, to secure your environment later on. Catherine, appreciate your thoughts on this because, you know, I remember the days of networks for speeds and feeds and points of presence and connecting A to B and kinda looked like this nice diagram that you stitched together and that was a network and you secured it.
Now it's overlay on top of overlay and it's changing and mm-hmm. You know, it's, it's multiple pieces that, uh, much more complex to, to secure. How do you, how do you have this conversation with people?
Yeah, definitely. So as you were sort of talking about this, you know, obviously there's a need for responsiveness and customizability and security, but I actually also wanna make the argument for unified policy management in application security. This is something that I've seen actually, for example, um, we have some customers who have protected their SaaS apps, like what is traditionally more of a network firewall or zero trust type use case with the same policy they're using for their web applications.
And by doing this, they're able to do things like make sure that zero day exploits aren't able to exploit their SaaS apps, you know, as well as their, um, web apps. And we see a lot of value out of these unified policy managements. I was talking earlier about, you know, how we have all these apps hosted in different places.
We see a lot of customers, for example, will host, um, you know, an app across multiple clouds for like a resiliency use case. If they're worried about outages, you'll, you'll certainly see that, um, for example. But then how do you have to, you know, actually secure an app that's stored in multiple places?
Do you write different policies for, for wherever those are stored? Um, do you write different policies for APIs versus, you know, traditional apps? Um, so we see a lot of benefit out of like a unified policy for all of those disparate sort of endpoints and all of those disparate, um, locations that they're stored.
Uh, for CloudFlare in particular, how this sort of works out is our WAF is like the backbone, the architectural backbone of the rest of our application, um, security portfolio. And this works out really well because you can do things like have a WAF and an API like positive security model protecting your APIs. Um, so you could do things like detect zero days and volumetric attacks, which are, you know, APIs can also be susceptible to as well as, you know, do the things like Ebola and, and all those API specific attacks all within sort of one, um, control plane, which we find a lot of people get a lot of value out of because of this really, really disparate environment.
Okay. Chris, I saw a lot of hand waving head nodding you bud jumped outta your chair on this one. And so I kind of have a feeling you might resonate with this.
No, um, I, I gotta throw out there, I was gonna, uh, before Catherine got into the, the policy thing I was wearing, it's been a long time, but yeah, the concept of an SBO m the software bill of material for the current release version of Adobe Acrobat as opposed to an SBO M four as we're look talking about here, some ephemeral web app that one time for five seconds exists in the cloud. You know, think about that. How do we kind of deal with that?
And I, and, but I think policy is, is the answer all hacking? All hacking is policy hacking. I will figure out how you do things and I will figure out where the gaps are and I'll engineer that gap.
And we live in a world right now where we generally have no idea what policy applies to any of us anywhere, with few exceptions. And in this topic, and because I'm used to the supply chain topic, imagine I needed to get the, the SBO M or custody information about a piece of software on his phone right now. I could get it in between five days and six months today I need to get it in like half a second.
That means I need to read the policies between me, the person who bought the phone and the first time the company I bought it from, and like their relationship, their contracts, their policies, you know, upstream all the way. And we have to get that done in the next decade. So without unified and, and, and adaptable, you know, transparent policy frameworks, none of this technology is gonna make a difference.
So I think we, we will do that. And there's interesting things going on down that path. It's kinda interesting in a way, just connecting dots between what you said, Catherine, and you were talking about Chris, there's your own unified policy management, right, of what you're doing.
So you know, you're, you, what you're applying where and how you're applying it, and then that's how that interconnects or interrelates with the people you connect with, work with, use their service product, whatever that is too. And I, and I appreciate what you said Chris, about, think about just serverless technology, like a lambda kind of service, right? That, you know, it's there now, it's gone tomorrow may not be the same thing.
It was a second ago when it, when it ran. Um, so in, in some ways, Catherine, it's all sort of a dynamic unified policy management, right? It can't be a static thing.
Am I, am I on base here? Yes, of course. You know, you do have to be responsive to the environment, um, you know, threat landscape.
Um, this is one, one area where I strongly advocate for actually ML driven, um, detections and policy. Uh, this is a thing where, for example, if you have a really large data set, uh, you can train your ML models. Um, how we do this at CloudFlare, just 'cause I think it's a little easier if I give an example and it's, uh, we will score each request on a scale of like one to 99.
And if something is less than 30, that means like it is very likely to be an attack. And because we have, um, hundreds of terabytes of requests, or, sorry, hundreds of millions of requests every single day, um, we have so much data we could train this on and say, a little blog in Malaysia gets attacked by a new attack we've never seen before. Suddenly, because that tiny blog in Malaysia got attacked that gets feed in fed into our ML model.
We don't have to rely on a security engineer to like go and find and analyze that attack and turn it into a regular expression like firewall rule. Um, the ML will basically just say, okay, like, since it matches something like this, um, we will just automatically block it. And this is why I'd say ml um, sort of combined with that traditional, um, you know, security analyst looks at the traffic and writes a rule that matches it and then blocks traffic.
Um, you gotta combine I think these types of approaches. So ML is a really, really great application, um, when it comes to being responsive to the threat landscape. And we have some data around this as well.
Um, we recently, not that recently, like half a year ago released our annual application security trends report. Um, and we found out that, uh, for example, like zero day vulnerabilities, um, we probably wouldn't have been able to find this out with just security engineers analyzing it. But with our ml, we were able to detect, um, and exploit 22 minutes after the, uh, proof of concept was posted online.
So, um, really, really great applications there. A lot of interesting stuff going on for sure. Well, if that doesn't make the case for dynamic security, what does, right.
Um, I, I'm curious, Kurt, how do you, is, is someone, you know, applying these things, applying security? Are you, are you looking at things like ml? Are you doing it via yourself?
That's something you look for in the vendors, the partners that you work with. How do you leveraging either that or other kind of technologies to help shorten that cycle between when things change and how you can account for it and secure it? Right.
The, I think the ML piece of it is, is hugely important because, I mean, humans, we're slow. The, the technologies we use, the computers and I, each servers process all of this far faster than the human brain and I ever could. And so we need to augment ourselves with this technology.
So anytime we're evaluating new solutions and bringing them in, like I'm currently in the process of implementing a big one right now that focuses on platformization and ai, ml, it's all part of it because it humans with eyes on glass, like it's great to have those guys in the sock, but they'll get overwhelmed very easily with the speed at which things happen today. And so we need to leverage technology and machine learning enables us to do this faster than ever, and it's only getting better, right? And so augment the human with that technology and you can very quickly pare down all of that information to what matters most and focus on real attacks like Katherine was just talking about.
I wonder, you know, there's so much activity around ai, of course, a lot of it because of gen generative ai, um, Chris to, to security engineers have to become machine learning experts to be able to do this stuff. What does it take to really leverage it? No, but knowing, knowing something isn't gonna have, um, uh, causing any problems.
But, uh, I, I just couldn't agree more with, with both, uh, with Kurt and Catherine. 'cause you know, and, and your part point, it's all about time, time the transparency. How, how long, and again, I've seen this over and over in my career where we get to these points where what we're mostly doing is sharing the war stories.
You know, I have no idea it was 72 hours. None of us slept. There was caffeine.
And, and my my question always is, okay, if there was twice as much, what would you do? Because obviously that we're at the limit. We can't possibly work any harder, stay awake any longer.
And, and this, yeah, ai, ml, Oracles, whatever we call it, this, uh, my, a big has been a big part of my, uh, my focus on supply chain before it would, you know, AI became, you know, uh, a general, um, uh, generative, what the hell do we call it? I'm sorry, I forgot. Yeah.
Generative ai. Yep. Generative ai.
Yes. Too many terms that throw around. Yeah.
Because again, we need to, you know, just for supply chain things, I need to read the contracts. I mean, I can literally call someone up, you know, it's not a security engineer, but it's some administrative person of the company, and I had to get them on the phone and get them to pull A-A-P-D-F and read the contract and find out if the clause allows me to get the information I need. That's not worth a human's time.
I mean, that's the kind of stuff that computers can do really well, and they're just beginning, but that's obviously the direction we're going. And if you can't see your policy environment five years from now, by various definitions, your competitors will be so much faster than you are that it won't matter anymore. Cur, I'm, I'm curious, without giving us too many specifics about Teradata and not asking you for that, but what's your sense of, what are the, what are the new priorities that are on your, yeah, on your horizon or things you're dealing with now and that you've kind of added in the last year or so?
What's changed about how you're thinking about security and that you've gotta address now? I think there's, there's always classic problems that we, we have to deal with and tackle. Like, we can't forget things like identity and network security and the rest of it.
But the, the prevalence in the emergence of generative AI and putting AI and machine learning in everyone's hands has meant that security teams have to be hyper aware more so than ever because these new technologies, people are latching onto them without considering the risks. They're like, that's awesome. I can speed up everything I'm doing.
And suddenly you see a new story about, well, what was it like Samsung engineers leak their code through a generative AI solution or whatever. So you're, you can quickly lose intellectual property or put it at risk. And so we have to think about securing our environment for those solutions, or putting the guidance out for people to use AI and machine learning.
Um, and I mean, getting visibility of all of this, and another big one that's been getting pretty popular and we're seeing a lot from different vendors and acquisitions and whatever, is data security, posture management. Where is my data? Where is it moving?
How secure is it? Because at the end of the day, that's what the attackers want. They don't wanna sit in your network and use your resources to, to launch attacks as much as they used to.
They wanna grab your data, steal it, monetize it. So need, we're, we're focusing on data security big time in, in the more recent years, especially, um, forward looking because we have more data than ever. Interesting.
Catherine, from your perspective, you know, communicating with so many companies, what are some of the changing priorities from your, from your viewpoint? Yeah, I mean, certainly the gen ai, um, piece is something we're seeing a lot. Um, everybody wants to put an an LLM on their web application.
Um, and of course that means that you have to think of that as like a data security concern as well. Um, because you wanna make sure your LLM is not gonna like accidentally leak somebody else's social security number, because that's certainly happened before. Um, and so at, at CloudFlare we're thinking about this of like, basically how could you basically just put a WAF in front of an LLM, um, from that perspective, how could you prevent it from exposing sensitive data to the end user?
Um, but then, you know, you gotta think about these more complex issues as well. Like, how do you prevent somebody from poisoning the model? How do you prevent, um, you know, some of these other, like, how do you prevent it from hallucinating?
Uh, these are all, you know, sort of adjacent to security concerns. But, um, but nonetheless, we see some security teams focusing on this, um, increasingly. Um, additionally we also think about, you know, the, the LLM sort of security use case is a little bit of a just, um, increased API security use case since a lot of times, um, people are not building these LLMs themself and hosting them themselves.
They're often, you know, bringing in LLMs from third parties, which, uh, necessitates, um, APIs, right, for integration. So how can you make sure that these APIs are staying secure and not leaking them back to the host and whatnot. Um, so that's definitely something we're seeing as well.
Um, I would say additionally, one thing I've been hearing a lot lately is, uh, software supply chain security. Um, I think Kurt mentioned the beginning, um, sort of securing code that lives on the client device as well. Um, this is something that we've been hearing a lot about, especially as it comes with the PCI four, um, compliance, which is gonna be mandated at the end of March, um, and a couple months.
Um, PCI four has a new compliance requirement around client side security and securing, um, the client side, like software supply chain. Um, so this is something we've been getting a lot of questions and inquiries lately. Um, you know, how much are organization's responsible for, um, the code that loads on their end user's devices, uh, when they visit their websites?
Um, this is something we're seeing a lot of people trying to actually actively get control over, um, and make sure that they're not, you know, serving, uh, code to the client devices that could do things like download a crypto mining software onto their phone, which, um, believe it or not, we have seen somebody's trying to make, you know, personal laptops part of a crypto mining network, which is pretty crazy. But, um, so yeah, I would say the client side component is, is something I've been hearing a lot lately as well. I, I just have to say, I, I love living in a world where we can use the term, uh, you know, hallucinating artificial intelligence in a conversation like this.
Seriously, just great. We, we understand about that. It's not a sci-fi movie.
It's real. Oh, It's, it's real. Yeah.
Hey, so I've, I've kind of a left field question for you, Chris. So if this, if I throw you too far off the track, I'm guessing you're thinking about this though, is, is there an SBO m in our future for LLMs and s SLMs and all of these things? 'cause in a way, this is a whole nother part of the software supply chain, right?
We're handing off to something that's doing inferencing, either on a chip on our handset or in the cloud, all of the above. How does that fit into, do we need to be thinking or at least wondering how we're gonna solve this problem And not only not left field, and that's, that's right in the middle of the, the, the tracks. So in short, yes.
You know, there's ano there's another assistant working group, um, Dmitri Rayman, uh, my colleague CTO at at SBE is, uh, uh, co-chairing now on, on AI bomb, right? AI bomb has been talked about for a long time. So what does that even mean?
You know, so AI is code, so there's this, you know, same sort of standard SBO stuff about that, but it was also the training data and the models are produced, right? And this sort of goes back to my last comment about ephemeral ephemeral SBOs. You know, we start with the idea that I am a software provider, and every 16 years I release new code and I carve a new SBO m you know, on purist graphite.
Um, but we live in a world where code gets compiled and used all over the place. You know, how do we even look forward and say that I can commit to a policy that says I will, if asked, provide the contents of this code without, um, actually going out and printing or saving or producing quadrillions of SBOs forever, you know, in, in exabyte storage. Uh, so this AI is, you know, what we're currently calling AI is just another forcing function of the level of complexity we're at.
So we need to be able to provide the answers to live up to the policies that we've agreed to, um, which is, you know, you know, in the SOM case we're talking about a software inventory that I will be able to tell you what code that was running or you know, what data set was used, and we have to get there. And, and, and it's, it is reasonable progress down that path. It's a, it's a complicated one that is very similar patterns to how we'll do other things of similar complexity.
Um, Kurt is, is that on your radar yet at all, kind of thinking about security of, from a supply chain for LLMs and AI and ML algorithms and all that kind of stuff? No, I mean, it's, it's certainly jumped up on the radar, especially since the whole SolarWinds thing happened. Um, as Chris was talking, it got the wheels turning in mind of, well, if we're gonna be kind of, we're moving towards leveraging a AI in the sense and dynamically generating SBOs and things, is this another attack vector we potentially have to watch out for?
Is how do you weaponize that and, and protect against it? Because I mean, as we see attackers evolve their tactics and techniques faster than ever, they're coming up with new creative ways that defeat the traditional approach in microseconds. And so how, how do you stay ahead of that curve now?
And so I obviously, I don't have the answer right now, but it's, it's really interesting as Chris talked to start thinking about this, this new sort of problem that we're facing. And again, it all falls back to the rapid evolution of technology. Yeah.
Speaking of that evolution, uh, just in the last week or so, uh, Satya Nadal, the head of, uh, Microsoft was talking about the death of SaaS, meaning that's kinda the clickbait one liner that what I think he was really talking about is evolving nature of software architecture that I would describe it as Today's microservices or backend code are tomorrow's AI agents, right? We'll see more and more parts of apps built through, you know, with or through or maybe completely with AI agents. And it reminds me of going into the, uh, cloud native era of, oh, how do we secure microservices now that we're gonna do that kind of thing?
That's kind of the, that's the next edge that we're, we have to work on and think about how, uh, there are different things we have to do for securing AI agents. How are they orchestrated? Is it Kubernetes or it, some other thing that's managing all those things.
And, uh, given that we're putting AI agent building capabilities in everybody's hands, in many cases, it, uh, could make for interesting. I use that in a nice way, uh, interesting environment to try to secure and manage. So in some ways, the future is bright, but it may be a pretty intense at the same time, same time.
Well, and I think kind of building on that too is the, the technology behind ai, it's backed by machine learning. Like you're, you're making technology autonomous, right? So it's not as predictable anymore.
So how do you secure what, when you don't exactly know what turn it's gonna take next, Non-deterministic, right. Well, I, I gotta add a note, a note of hope, though, because it's easy, you know, to your point, uh, Kurt, the short answer is yes, there's a new attack vector. Oh, yeah.
Um, but, you know, throughout my career I've been arguing this one, it's like, we'll probably keep the lights on. It's like, no, no, if we don't do this and that, then you, we will, you know, we're on this, we're doing this call right now. We've managed to figure out everything else up to this point.
And not only that, but I think that we're, we've been mowing the lawn. I think, you know, what we need to do, generally speaking in cybersecurity has been known maybe forever, certainly 50 years, but we haven't gone around to doing the vast majority of it yet. 'cause we haven't had to.
But as we do, and I, I will take a risk and, and put a lot of my, my faith in policy, you know, in, in real policy transparency, you know, in, again, in this decade, it gets harder to be an adversary because, you know, these are the happy World War II fans out there, you know, or know fans, you know, but the, the ubo wars, right? There was the happy days when you could just have a U-boat and sink shipping all day long. You know, that's kind of most of the world, most of the, the history of the internet to date.
It's not necessarily gonna stay that way that long forever, where there's always a new attack service, and there's always a, a, a new way when the last one is, is blocked. I think we will, we'll keep it running. We will all be fine.
And I think over, you know, at least over a period of decades, being an attacker will become much, much more difficult. I mean, I might argue it already is becoming more difficult. It 'cause the, while, while the, the technologies we use as practitioners are getting more advanced, that helps make it more difficult for the adversaries of the world.
But that's not to say that they can't employ similar technologies, right? So now we're kind of, we're creating that chicken and egg problem all over again and playing a game of cat and mouth. It's kind of the next arms race, if you will, as technology of olives.
Everybody has access to it. Well, let's do this. I appreciate all the conversation, and we brought up a number of topics, um, just as a kind of concluding thought.
Uh, we, we've been talking about what are the things we need to be thinking about? Maybe they're new, maybe they're on the horizon, maybe we're already working on this today. Um, if you had to say, there's one thing you'd really want to emphasize this, if you were, you know, somebody who's listening to this and maybe making a few notes, the thing that sort of stands out to you as something really important to be thinking about in the next, let's say, six to 12 months, if not today.
Um, Kurt, do you want to give us your thoughts? And then Kathleen, if you would, and Chris, you can wrap it up for us. Sorry, did I say Kathleen?
I mean Catherine, excuse me. Kathleen. I work with a Kathleen.
Sorry. I've been doing that. All good.
Okay. Yeah, I, go ahead, Kurt. I mean, it's, we wanna avoid that situation where everything is a priority, so nothing's a priority, right?
I think we, throughout this conversation, we've highlighted the importance of SMOs. We've highlighted the importance of application security and how it's, it's becoming more important than ever because our application code is, is literally going everywhere. And that's, that's kind of the gateway for a lot of the attacks we're seeing in the world today.
And so I think the, the emphasis is on application security, but it's also to say, let's not forget the rest of it, because all of the, the other parts of cybersecurity are hugely important. And we still need that visibility. We still need the coverage, and we need to be thinking about ease of use as well, and avoiding the sprawl.
So I know these aren't necessarily specific cybersecurity things, but they, they help you simplify your approach and, and focus on what matters. And that depend that that changes everywhere you go. Every enterprise or company has different priorities.
And so I think focusing on those things help enable us to, to focus on what matters for where we're at currently. Good. Catherine?
Yeah, so I mean, like Kurt said, you know, we wanna make sure that we're not making everything equal priority. So I think when it comes to application security, which is of course, my area, what I would say is most important in this space is visibility. Um, the attack surface is getting more complex, applications are getting more complex.
Um, you know, where they're hosted is getting more complex. So how do we actually have visibility into our, at entire, entire application attack service? How do we have visibility into the APIs developers are creating so we can actually secure them?
How do we have visibility into the software they're adding, um, to these apps? Uh, that I would say is probably the most important thing for application security and also one of the most challenging things. Excellent.
Chris, You know, Kurt and Catherine both want exactly where I'm going, so I'll just build on that. You know, do do things that save you time to transparency. You know, if you, you know, don't panic, nothing's on fire.
And, and when things are on fire, panic less, right? Just take your time and, uh, getting visibility, you know? Yeah.
Look at how long it takes you to figure out. And anytime you find a, a, a way, you know, in this, in this topic we're talking about here, to spend less time to figure things out, you have all that time back to do things. And it's easy to just, you know, particularly in transitional periods, you just do more and more and more of what you've been doing, you know, but, uh, understanding the environment you're in so you can apply your resources appropriately is, is everything.
And there are lots of ways to do that these days. You know, there's, there's a lot of Russian panic and there are a lot of you, you know, say it, AI and things like that out there who will actually make your life easier, give you some of your time back. Mm-hmm.
And you'll point, feel better knowing what's going on, make, make, and make better plans, have better strategy, Uh, to that point. Exactly. Chris, and, and Catherine mentioned it around, uh, ml, you, some of the things that I'm really excited about AI is actually just the understandability of what's happening.
You know, Kurt mentioned about as things ramped up or, or you did, uh, uh, in, in the, if the tax doubled, right, how would we handle that if we're already maxed out? So some of it is just handling the volume of things that are happening. But I think one of the things that I think is most exciting about generative AI is it's also so complex.
No one person can understand the full system, right? Or maybe even understand truly what's going on in a case of an attack or where you have vulnerabilities. And generative AI is starting to make some inroads and help us understand systems and, and giving us some insights to some of the complexity.
We may not be able to fully get into our head all at once. So, for example, I've been doing some work around how do you modernize mainframe applications? Well, nobody was around that built those things.
Well, maybe people that built the network aren't even around, right? So help us understand what really is happening with all this data that we've collected. And the natural language interface through that is, is a great aid, and I think it's just a real practical thing that we can start to begin to use today.
So don't think of AI as just as the next, you know, it's gonna replace all of our software and it's all gonna be different. And what do we do? There's things today that is already helping us with.
So, you know, there's some real things too, not just what's on the horizon. Well, thanks to all of you. It's been great, Catherine.
Uh, we appreciate your perspective, and Kurt, you're bringing, um, your experience and perspective. And of course, Chris, always good to be chatting with you and your connections into the security world. And some of the folks are working, collaborating together, which by the way, is another superpower we have in security.
And that's the fact that we work together and collaborate on, on these things. We're not going at it alone. So thank everybody for the good work that we're doing to help advance.
We hope this has been a helpful conversation for you, thinking about the, the last great cloud transformation, what we're doing differently and thinking about, uh, as we move forward. So as we've got our heads down, getting stuff done, getting our priorities done, getting our plans in place, and executing for 2025, but also kind of thinking a little bit about what's next and what we might be considering and learning from others that are working in our space. So thanks to all of you.
Thanks for everybody for joining us today, and thank you to the Cloud four team for, uh, for sponsoring, um, our show today. And we look forward to joining us either on another recording or be sure and check the calendar for one of our live events where folks can ask questions and engage with us in a similar kind of conversation. We have many of those coming up.
We'll talk to you again soon. Take care, everybody. All right.
Welcome everybody. To my predictions for platform engineering in 2025. I'm Luca from the platform engineering community.
I actually see a lot of platform engineering initiatives, um, throughout the year. And so I've put together three predictions that are really rooted into trends and things that I've seen this year in 24, um, and that I think are very interestingly developing into 2025. And so that's kind of what I, what I want to talk to today.
Um, really just like cover this, the three things going into next year. Um, and because they are sort of, you know, rooted into 2024, I wanted to, before we get to the predictions, just quickly kind of take a look at 2024, what happened? Um, you know, we released this data apart from Engineering report, uh, just a month ago.
Um, that has a lot of interesting data, and we're gonna look at some of that data as well. Um, but in general, um, you know, we've seen the community really exploding in terms of size. You know, this thing keeps compounding at insane rate platform calling.
This year we had over 800 talk submissions. Um, we had, you know, the, the YouTube subscribers, uh, for the platform engineering YouTube are keep, you know, doubling or tripling year over year. Um, the Slack now has 25,000 members in it.
So there's a lot of stuff that's happening. Um, and the community and, and I think Platform Con, because it's been around, you know, every year since 22, is actually a really good also meter of that. We had a hundred thousand, over a hundred thousand views just in the first couple of weeks, um, since of recon.
And, and that's, you know, forecast to keep growing next year at Recon 25 as well. Um, so again, this really speaks to the fact that I think platform engineering is really going mainstream at this point. These numbers are really quite impressive.
Um, and you know, we, we, we, we speak about this in the community, we speak about this in the platform engineering show with Alan on the podcast that we recently launched about, uh, you know, how platform engineering really is sort of the new DevOps and is kinda taking over the software engineering, DevOps industry, cloud native industry, and so on. Um, and I think, you know, this growth, this compounding is a, is a good proof of that. But you don't have to just take my wording, kind of the community numbers for it.
I think it's also interesting to see how, you know, very established analysts like Garner are also sort of, you know, talking about platform engineering in a very concrete way. Um, they named it a top strategic technology trend, both in 23, and this year in 24, they forecast that by 2026, 80% of enterprises will have some sort of platform engineer initiative either rolled out or rolling out. Um, and I think what's really interesting to see is, you know, I've obviously was talking very active to a lot of the Gartner analysts all this years.
Um, and I was very, um, happy when they finally put platform engineering on the hype cycle that the general software engineering hype cycle back in 22. You can see up here on the left, and you can see how, you know, platform engineering was kind, they, it was out on the hype cycle, but it was, it was still sort of like at the beginning of that hype curve that they, that they designed, um, in 23 last year, you can see the, the, the red arrow, uh, moves up. So it was kind of like peaking.
And now what's interesting is this year they actually released an own hype cycle for platform engineering specifically. And you can see stuff, for example, internal developer platforms, uh, which is one of kinda the key concepts that we push in the community. org, which is one of the, so like key, um, websites that, that people have been, um, looking at for the last really, like five plus years at this point.
And you can see that on the, on the, on its own hype cycle. Very interesting. Also, what's very interesting is that, um, a subcategory, effectively a platform engineer, which is infrastructure platform engineering, and we're gonna talk a little bit more about that later in the predictions, um, actually has been been named seven times of seven different hype cycles, whether it was the hype cycle for S-R-E-I-N-O teams, uh, it, and so on, right?
So very, very interesting, I think, um, to see just how this, the, the, the space keeps compounding, keeps maturing. Um, and, and that's kind of one of the things that I, uh, that's really, I think that the, the common thread of these predictions that I want to go into, which is really the space is maturing, is waking up to a lot of best practice and blueprint that we can either, uh, sort of borrow from outer, you know, adjacent verticals and industries, um, or really finally understand, okay, hey, this is actually what best practice looks like for platform engineering. Um, and so without further ado, let's jump into the, uh, predictions.
This is the first one, backstage backlash, uh, which sounds very, uh, very interesting. Uh, but what it means, um, effectively is that, and, you know, this was very obvious to me. Um, for example, at CubeCon this year, if you look back at CubeCon last year in 23, um, uh, the North America one especially, so like, literally like, you know, basically, uh, you know, 12, 13 months, um, ago ago, uh, portals were really the big hype, right?
Like everybody at Q Con's kinda like, oh, apart from engineering and internal developer portals, portals, portals, portals. Um, I think, um, Q con this year, you could see the tune has really started to change. Where, again, as this phase is maturing, a lot of people are realizing, Hey, actually, you know, I spent all this time in installing backstage, which can take up to like, you know, 12, 18 months in a lot of cases for large enterprises.
And then I actually have no adoption. I have no usage, right? Um, and, uh, and this is something that, you know, not only we're seeing, you know, in, in our community, but really talking to people like Garner talking to people like ThoughtWorks that implement a lot of these, uh, portals, um, you know, across many, many enterprise accounts.
Um, we are, we're getting the same sort of message, right? And I mentioned earlier the, the sort of the data platform engineering report, you know, it's backstage still has by far the, the biggest market share. I would even say this is actually our own data, and it's still very, very conservative from, you know, uh, other data points.
When I talk to, like, you know, this Garner and other partners of the community, actually, the figure is over 80, 90% in some cases in terms of backstage market penetration. But while there is a lot of, um, sort of penetration by the tool, um, that actually doesn't, it's not reflected in terms of usage, right? Um, and why is that?
Well, if you look again at, um, sort of the, the, you know, this definition by Garner, uh, internal developer portals are, you can really think of it as the, the sort of like the front end of your platform, right? It's something that developers, but also executives, for example, use to discover and access the underlying internal developer platform capabilities, right? So this is really, really important to understand that effectively, you know, building an a, building a platform is like building an application.
You have a backend, you have a front end, and you know, ideally, um, you, you, you really need both, right? And I think the mistake that a lot of, uh, platform engineering teams have been making, and again, the thing that a lot of teams, a lot of organizations are not waking up to is this idea of like, Hey, my portal is my platform. It's not, your portal is just a UI basically interface to your platform.
Um, but if you just do a portal, um, you're not actually gonna address the underlying sort of challenges. Um, you're not gonna enable developers sales stories. Ultimately, you're not gonna achieve what platform engineering is really designed to help you achieve as an organization, right?
Um, and, and this is the thing is what a lot of teams, a lot of organizations have been realizing now where it's like, Hey, I spent all this time building, you know, installing backstage thinking that that's my sort of like NBO sort of solution to platform engineering. Um, well, actually now I have, you know, very low adoption. I don't, um, I don't, I don't, I just don't see this, um, this thing really making a big difference for me, right?
Um, and again, um, this is something that, um, I think a lot of people are now realizing, but, um, you know, experts, uh, so that, you know, being there done that a few years ago had already been calling this alpha for a while, right? org, uh, which is our, our community side, um, I think like four or five years ago. Uh, this is from Aaron Erickson who, um, uh, uh, guess wrote it, uh, for the, for the blog.
Um, and where he drew and Ericson, by the way, is the guy that, uh, built the, uh, the sort of the main enterprise grade platform at Salesforce. So he definitely knows one or two things about adoption, um, and enter platform engineering. And he draws this very helpful ngel thing where he basically compares, um, you know, platform engineering and building an, an internal developer platform or IDP for short to building a house, right?
Where it's like, Hey, you know, if you were to build a house, you would obviously start from definition and then, you know, add your walls, add a roof, add the windows, add the doors, add the end. You wouldn't start from a door, a door first, and then kinda like build everything around it, right? That'd be silly.
And that's a little bit, actually, you know what a lot of people's, a lot of people have been doing, right? A lot of platform teams, you know, maybe new platform teams, young platform teams that had a recent mandate to do platform engineering. Were trying to get and understand why this happens, right?
They're trying to get usually a, a quick win under their belt, right? And so it's like, Hey, you know, let's just put a platform on top of our existing setup, and off you go, we're doing platform engineering. Um, and the problem with that is that, again, if you think about building a platform as effective, building any other application, you have a backend, your front end, you know, you, we've learned a few things in the last couple of decades of building these applications, of building, for example, microservice applications, right?
So you a, you have a single responsibility principle, um, which is really the idea that like, one of these modules should only do one thing, um, and that you don't want to misuse a module to do something that is not supposed to, right? And so, an example, a perfect example is this, is, well, if you start from the front end, right? You then maybe, you know, have a pretty dashboard that you can show executives after like a few weeks.
Um, but actually that actually doesn't have a lot of substance underneath it, right? Um, and then what happens is when you know, maybe they're even impressed, then you, then you need to actually build this, you need to start building the real platform. And then what people do, what platform teams do is they start shoehorning business logic into the front end of the platform, which again, if there's anything that we've learned from application architectures, you really want your business logic in the backend because you don't wanna expose business logic.
You don't wanna expose, you know, potential vulnerabilities. But more importantly, the certainly the front, uh, kind of modules are not built to handle that type of logic, right? Like the reality is that, you know, backstage, for example, or any portal is really just a UI on top of that, that, you know, visualizes things, it gives you access again, to the underlying platform capabilities.
It's, it doesn't provide you with the actual capabilities underneath it, right? It doesn't let you orchestrate, um, sort of the, uh, you know, logic underneath it doesn't let you orchestrate your workflows, your infrastructure and so on, which is ultimately really where the pain from a developer experience is, and from an infrastructure operations team as well, and where a lot of the value is that can be unlocked with your platform engineering initiative. So that's, I think, really, really important.
And so, again, I I, I've seen a lot of an increasing amount of people, especially in the second half of 2024, really come, you know, come to realize like, Hey, you know, portals are, are okay, they're cool, but I really need some sort of like API orchestrating stuff underneath them. That's really where a lot of the value lies. And, and so I predict that, that, you know, more and more enterprises will figure that out going into 2025.
And this will actually become a very established, you know, hopefully best practice of like, Hey, you need to start from the backend and then add your front end later. Um, because your front end can just be interchangeable, right? You can change your doors, you can repaint your doors, um, you know, it's much harder to kind of like, uh, rip your, your, your foundation off and, and rebuild it every time, right?
So, so I think that's prediction number one. Number two, um, developers will lose direct access to infrastructure. What do I mean by that?
I think a lot of teams, um, and here again, you know, not to pick too much on backstage, but this can really be done through any interface, can also be just a CLI or, uh, and, you know, a, a code-based interface, an API based interface to your platform. It doesn't matter. The point is there are, you know, cloud consoles, there are, um, sort of, um, you know, so, but mostly, let's be honest, mostly it's either through portal, through product console that developers can play this fun, you know, what I call infrastructure teris of just like, you know, choosing different sort of like pieces of infrastructure.
Uh, in this case it's an EKS class to wrap, but you can have posters, you can have DNS, you can have all sorts of, um, you know, fun, uh, stuff that you need because you wanna, you know, test the code, change, deploy something and so on, and keep adding them into, um, you know, into the, the void, right? Into, into the, the sort of like the, the enterprise ether of, um, uh, of your infrastructural setup, right? And the problem with that is like, while developers are very happy, you know, they're just like, click around and they cradle these things and they're, you know, everything is provided, you know, this creates, um, a nightmare for operations colleagues to maintain, right?
Um, it's really, really hard. Um, a a and this doesn't really create, you know, costs in terms of, um, you know, obviously you end up, and I think we're all very familiar with this, um, story of a lot of sort of, um, you know, idle resources that are being created. They're not really being used.
They're not really being optimized, but more importantly, I think it creates a lot of overhead, uh, maintenance, um, and scalability issues on infrastructure and operation side of things, right? And, and it creates a lot of friction between developers, operations and so on, right? Um, and so I think a lot of teams are now waking up to that and to understand, they're like, Hey, your platform can really be thought of as a effectively, like, if it's a vending machine layer, right?
For, uh, your developers where developers can, you know, select the infrastructure, but following a very precise predefined set of, uh, templates and, uh, sort of like guardrails that the platform engineering team designs as a product for them, right? So it's very, very important, I think, to understand that like, hey, platform engineering is this multiplayer game where yes, developers is your end user, but you need to make everyone happy, right? You need to, to make your developer happy and, and, and let themselves serve things, but not at the cost of sort of like infrastructure and operations teams, sort of a mental health, right?
Where hey, um, you know, and, and, and, and also I think it's very, very important. This is one thing that I'm seeing top performing organizations, top performing platform engineering teams realize it's like, Hey, I cannot only over-optimize on the developer. I need to get the infrastructure and operations team on board with the platform too.
And how do you do that? Well is by selling to them effectively, right? This idea, they're like, Hey, you're, you know, you can look at this platform engineer initiative as a kind of like a, a layer that not only shields developers from the complexity of the underly underlying infrastructure, but also the shields you from, you know, this, this basically infrastructure te that a lot of developers like to play, uh, a little bit too often, right?
Um, and, and so, um, I think it's, I I'm seeing this, um, you know, good platform teams realize, Hey, this is how I get everyone on board and, and really, you know, having, using this mental model of a golden path and of this kind of, these guardrails for developers, um, that are really, really essential. Um, and I think if you zoom out, um, you really realize that like, you know, um, there is this, this, this, this word that is almost like a bad word in our industry and it shouldn't be, which is silos, right? Um, I think, you know, we had a very interesting conversation, uh, Casper, um, from, uh, from human tech.
Casper from Gumma did, had a really interesting conversation with Kelsey Hightower, apart from Hir, um, where basically Kelsey at some point said, Hey, you know, the reality is that silos are a good thing, right? And you should have seen the q and a later because a lot of people got really mad. Um, and I think is is for not for no good reason, right?
Um, the reality is that if you look back 20, 30 years ago, we had, um, we were, we were too silent, right? You had this, you know, application developers, this admin throwing, um, kind of like code over the fence and like, really a way too solid. But I think, um, and this is, uh, something again that, that we were talking about the other day with Alan on the podcast.
Uh, you know, Devox was really this like swing of the pendulum all the way on the other side where it's almost this kind of like anarchy of like, Hey, let's shift everything left in the developer now so that we align all the incentives. But that is kind of missing the point, which is really what other, every other industry in the, you know, in the last 200 years plus since the industrial revolution have, has, has been trending towards, which is, um, progressive specialization, comm comm com commoditization, right? And really industrialization.
And I think, um, you know, the, the pendulum is now swinging back into the middle, which is really the sweet spot where we wanna be. We don't wanna have, you know, silos that really never talk to, to each other and, and, you know, inefficiently don't communicate. But we also, I don't wanna, um, you know, kind of remove this idea of like, people need to specialize, right?
Um, and, and so I, I think that silos are coming back in a good way with an a PIA platform layer in between them that lets you communicate the right way. Um, and, um, and I think this is really what a lot of people, a lot of engineer organizations around the world are waking up to. Um, and I think it's gonna make a huge difference going into 2025.
So that's pretty true. Number two, last but not least, platform engineering initiatives need to be pato optimal. Um, and so obviously I think a lot of people are familiar with this pato principle d or, or kind of like 80 20 rule, right?
Which is really you wanna optimize for the, uh, majority of use cases, right? But I think, um, the important thing to, to, to realize here is, is I was saying, um, platform engineering is, you know, very kinda like complex multi multiplayer game, um, with where you have a lot of different stakeholders, right? You have like application developers, you have infrastructure and operations team, we talked about them, but you also have security teams, you have architects, you have executives, right?
And the point is that you kind of need to get everybody on board with this thing because with your platform initiative, I mean, because, you know, um, it's gonna affect every one of them. Um, the platform initiative kind of touches all the different parts of your engineering organizations, so you need to get everybody on board. And the problem is that it's very easy to kind of lose momentum, right?
Because you're talking to person A, B, C, but it per, by the time you get to person Z, um, you know, it's been six months person a completely forgot about you, and you kind of lost momentum. And this is where, you know, blueprints and, and you know, frameworks that we talk a lot about in the community, like mini revival platform, MVP framework, uh, and others can really be helpful in making sure that you, you know, not lose the momentum and you keep it. But I think it's also very, very important that you realize, hey, while the platform should, uh, you know, really make, have like a 10 x uh, improvement, provide a 10 x improvement to, for example, you know, usually developers or the main users, it is very, very important that it doesn't, um, sort of detract from anyone's, right?
So I think the point here is really is like, Hey, you wanna make some people really happy, but you definitely don't wanna make anyone unhappy, right? Um, and I think, um, you know, this is an, an essential part of driving, uh, apart platform engineering industries forward. Um, again, you know, you can think of, um, I think this, this, this sort of a multiplayer game, uh, analogy of you have developers, you have infrastructure and operations team, we looked at them, you know, you kind of want to drive automation and standardization as kind of the key value drivers for both of those stakeholder groups.
And ultimately that affects, you know, uh, basically it lets you move faster without breaking things, right? That's, uh, one way I think about it, which is really, you know, you cut your time to market, your innovation cycle goes up, um, uh, but you do that in a way where you're still like reducing costs, you're being more compliant, you're being more secure and so on, right? Um, and, and, and so it's very, very important that you have clear ways of kind of, you know, get everyone on board with you on this journey.
Um, and a big part of that is, yes, following clear frameworks and blueprints, but also really, um, you know, making sure that, um, everyone is, has at least a sort of like net neutral to net positive, um, kind of outcome from the apart platform engineer initiative. And obviously in some cases, like developers, you're gonna have a ta you, you need to provide, so like AAN X, right? But it's really making it, it's really important, I think, to make sure that, um, nobody is, um, sort of, you know, against your platform engineer initiative for, for no reason, right?
Because the, the reality is a lot of platform engineering initiatives kind of like end up dying and losing steam, um, because they don't get the, the right, the right support internally. And it's really a tragedy of the commons. That's really what happens, right?
Where, you know, ultimately platform engineering initiatives are a net positive from an organizational perspective always. But it might be that from the selfish perspective on individual stakeholder or stakeholder group, you know, they're kind of like, well, this is actually a bit annoying. It doesn't really do too much for me, and so on.
And they're gonna block that, right? And so it's very, very important that we, you know, have a, a, a, a good strategic approach and tactical approach to get everybody on board. And I think following, making, you know, following the parade of principle A 20 rule, I think is a very good, um, sort of way of thinking about that.
Um, and by the way, if you are, um, and so that was my third, um, and, and kind of last prediction. I think a lot of people are also waking up to this, again, as the space is maturing. Um, I think, uh, organizations are starting to do platform engineering on a whole other level, which is super exciting for me to see.
Uh, and, and, um, something that we talk a lot about in the community. Um, if you're not familiar with the platform engineering community, it's really the largest out there. We have, give or take, probably 200,000 practitioners, um, across the different community destinations.
We have Pop from Weekly, which is a newsletter that goes out to over a hundred thousand people every week. We have the Slack, which is really the beating heart of the community. You can go in there, like jump on conversations right away.
There's already 25,000 people in there. We have 35, uh, meetup groups all over the world that meet every week. Um, you know, there's Platform Con that I talked about, of course.
Um, and we have a lot of, um, sort of courses and trainings and certifications that we've now rolled out where we do speak about a lot of these frameworks that you see here, where we provide you with the blueprints, um, and sort of like the past practice that we see from top performing platform engineering teams, top performing engineering organizations, um, and kind of making sure that they trickle down to mainstream, uh, as efficiently as possible. Um, and so come join the community, come join the courses, come join the events as well. We're gonna host, um, not one, but two live days this year.
One in London on the 25th of June, um, and one in York on the 26th of June. This slide is wrong. Um, but this is where, um, I'm really excited because actually the trainings that I was mentioning earlier, we're gonna bring them to in in Live, in person, um, uh, in, in, in both locations.
We're gonna have great speakers like Kelsey that you just looked at earlier on the slide at Gregor Hope, and Nikki Wat a lot more. And so, um, I think I'm personally very, very excited. I see every time, you know, I go to Platform Con, I go to CubeCon.
I just see this crazy, you know, compounding every six to 12 months of the platform engineering space. The first CubeCon I've been to, um, like four or five years ago, you know, I had to explain to everybody, okay, what is Platform engineering? Who's a platform engineer?
Um, then I think a couple of years ago, uh, it really exploded. Everybody was talking about it. Um, and now the space is really maturing.
They're, you know, it's not just about the hype any longer, but they're really figuring out, okay, what can it do for me? And how is real Platform engineering at Enterprise Scale being done? How do we follow best practice?
And I see, you know, more and more of that happening in the community. I see people really waking up to what works and what doesn't, uh, and then sort of like come and talk in the community at the, uh, platform Con about, um, you know, the best practices that they're, that are figuring out. So I'm very, very positive, um, of, of all the changes, all the improvements that I keep seeing in the, in the community in this space.
And I'm very excited about, um, what 2025 has in store for us. So, um, looking forward to next year. Um, and those are my three predictions.
Um, and with that, thank you. Happy New Year. See you on the other side.
Hey, everyone, today's episode is from Russia With Love, you're watching On Gang. Hi everyone, it's Alan Shimo. Happy Thursday.
Welcome to Text Drug Gang, those for Donya. But, uh, anyway, you know what? We live in a crazy world.
Once again, I wake up and I'm looking, what has Biff done today? So we're gonna be talking about it. We've got a couple of blocks to talk about of some interesting things going on in the world, and we've got some great folks here to talk him to.
It's kind of Cork Textron gang folks today. Let me introduce you to 'em, first of all, giving us the, the, uh, 4 1 1 from, I don't even know what the area code is out there anymore, John, but from Silicon Valley. Oh, It used to be, it used to be 4 1 5.
Now it's, it's six five. Oh, Okay. The 4 1 1 from the six Five.
Oh, it's, you're close. Yeah, you're close. It's our editor at large, John Schwartz.
Hey, John. How are you, man? I'm good.
I'm just kinda of reeling from a very long speech last night, but, uh, Oh, I didn't watch it. You know, we Move on It. Yeah.
There was a speech last night. I don't know, I, I watched, uh, something else. It was, it was, anyway, two nights.
It was two nights ago Going, going from high top Silicon Valley to sea level, where he's, I think, well, you, you are actually not a Key West anymore, right? You, you're, you're kind of turned into the Gulf a bit In, in the area in lower, lower keys. You know, today's island in the, where is Waldo search is raccoon key.
So you can Google map that up. It's a couple miles, miles offshore away from the US one. I've been edging towards the Gulf Edge, the content keys.
I'll get to the next couple days to check those out. Very cool. Chris Blas, our security expert, cyber expert, going from there, back up high into the mountains.
Rocky Man, high, Right? It's our guitar man, Mitch Ashley. Hey, Mitch.
How are you? Very good. Very good.
Just, you know, holding things down at the top of the peaks here in Colorado. All right. Keeping, keeping the sky up.
Yep. Holding, holding the sky. Yep.
Very cool. And then from there, too, Harrison, New York, the seat of tech strong content. It's our chief content officer, Mike Ard.
Hey, Mike, what's going on? Hey, the birds are chirping and there's buds on the trees, and I ain't talking about the kind they sell in Colorado, so No, no, no. Spring's coming.
All good. And the Yankees keep winning, man. There, you Yankees looked good again.
Anyway, it's all preseason, of course, means nothing, but still, um, let's move into today's news, guys. I, I kind of started teased it off in the beginning. You know, pigs fly, and, uh, we've decided, or the government, or at least our esteemed Secretary of Defense, I'm not gonna say anything more that I'd like to, um, says that we, uh, should supposedly, 'cause now I'm seeing pushback that we should stop offensive cybersecurity, uh, uh, procedures, operations against our warmest ally, the Russian Federation.
Very good comrade. Mike, what do you say? Well, I say that it's hard to tell what's going on here, and not everybody, as I understand and who's involved in this, might necessarily report up to the Department of Defense.
So there seems to be some confusion as to who's doing what. And of course, you know, the best defense is a good offense. So it's hard to say what an offensive thing is, versus a defensive thing is these days.
But Chris, what's your arena? What's going on here? Oh, you know, Kim Zetter and other people that I trust have been reporting on it.
You know, it's like, you know, you said it well enough. I don't know. I haven't talked to sources and so forth.
The fact that it's so matches our expectations, you know, and what we as a nation are communicating, you know, to this, you know, not ally. You know, our, our main adversary in the world right now is China, is Russia, you know, I almost said China, but economic, in a sane world, China would be, uh, our, our real, uh, opposition. Because Russia is a tiny little country with the economy of Italy, right?
Uh, that just happens to be bombing one of our allies and are maneuvering around them. Doesn't make sense. You know, they are the existential threat.
So whether into what extent, you know, this order or directive was given or thought to be given by people who were taking actions on, on our behalf, the fact that it, that it's not shocking is what we should be shocked about. You know, I I'm disappointed in you guys. Yeah.
I, I, I figured you'd be more savvy and kind of catch on to what's going on here. What's really happening is this is a Marco Rub, Rubio and Trump secret plan to partner with Canada and Mexico to give Russia a giant head favor to think that we're, were their friends and China too, right? In the meanwhile, we're undermining all that stuff.
He's ramping up. There he Is. We're playing checkers, and they're playing four D chess.
Exactly. You got the attention that makes sense. Come tell us.
That makes sense. Look, let me, let me, let me just throw some stuff in here. Number one, Russia's economy.
I don't know if it equals Italy, Chris, but I, I've heard it's, it's similar to New Jersey and being from New York, you are from Jersey, you know, that's a, but what Russia has and has had beyond their economic footprint is their military footprint, because they are depending who you believe the first, second, or third largest purveyor of nuclear weapons in the world, and they're not shy about threatening to use them. We've heard it numerous times during the three year, four years, whatever, of this Ukrainian war, right? And, and that if not for the nuclear weapons, honestly, who, who, who would give two craps about what goes on in Russia, right?
Let's be honest about it. However, not equal to their military footprint, but their hacking footprint has always, has forever since there's been an internet, been a huge footprint, whether it's a wink, wink from the government, letting groups operate openly within the Soviet Union, and then Russia or Russian asset, Russian government assets themselves, what we used to call the KGB. Now it has some truth speak names, time and time again, time and time again, attacks in this country and in the West have been tracked back to groups based in Russia operating under the, the, the cover of the Russian government.
And for us to ignore that and not do, uh, is a terrible dereliction of duty, pretty much what you'd expect from a guy who never, who shouldn't be the Secretary of Defense to begin with. Well, in a sense too, you, you think back to the 2016 election and Trump benefits again from Russian meddling. So in a sense, this is part of his reward to them, since he no longer has a run for office anymore.
And on the flip side, you've got this obsession with China and security and deep seek. I mean, we spent so much time in within the government thinking about banning them for probably good use or at least ban limiting the use. But on the Russia side, as you said, Alan, I mean, there is great, uh, protagonist antagonist is, is, is, uh, uh, Russia is, and yet we kind of, look, we're looking the other way.
And again, I'm not even sure what the hell HEGs is doing. I mean, evidently he ordered the US cyber command to halts offensive cyber operations. And this was supposedly went into effect, or the order went in late February.
Yet there's pushback. I mean, it's, you, you can't get a straight answer from these guys, but I think at the very least, I would, I would argue that again, with Russia, they're just gonna look the other way. They always have.
And they, they continue, they will continue to, especially in these asymmetrical warfare front. I mean, read, read your Leo to Tolstoy, right? You know, this is War and Peace, you know, it's about court posturing and, you know, appearances and whatnot.
And, you know, this is, you know, Alan, you're entirely correct. You know, what happened with the Soviet Union collapsed and the, uh, uh, the Russian mafia and the Russian government merged, right? And what's been going on in cyber operations for, you know, the last decades is that Russian cyber criminals are given free reign to do anything.
Like, as long as they use KGB slash FSB tools, right? And should they, you know, compromise something of interest, they give that access to, to the government, right? So it's all the same thing.
And I'm sorry, but if you watch Sopranos, I don't want to, you know, force people to go read classic Russian literature, but it's a lot of posturing. And for us to say, even give the impression that we would let the heat off on them. No, absolutely not.
You know, you wanna threaten to hack our grids and turn it off, do it, you know, who will bring your whole, your, your whole infrastructure down and, and you have to have that posture. Let me say something about China though, right? We, we, we don't live in a black and white world where I've got Boris and Natasha over here.
The bad guys come, we go get squirrel, right? And then we're, we're, we're the lone Ranger and lone Ranger and Tanto here we're the good guys. And, and that's what the world is.
No, there's more. You've got the Chinese, the Chinese are not angels, and they ain't our friends either. And it's always been a little education for Mr.
Secretary of Defense. The United States Defense strategy has always been, we must be able to fight wars on multiple fronts at the same time. We've gotta be able to deal with enemies, mortal, or not on multiple fronts at the same time, just because you want to take it to China or, or thwart Chinese hacking, which is terrible.
And it's been terrible. And I, back in my still secure days, Mitch knows this. We were, we were right on the front lines of that stuff.
That doesn't mean Rush is the good guy. And when Rush is the bad guy, doesn't mean China's the good guy. There's, there's multiple levels of bad guys in this world.
It's a big bad world out there. And for us to, to take the bullets out of our gun, you know, no, the only thing missing is someone to get up on a microphone and say, I've brought us peace in our time. You know, you know, the only reference a couple of nights ago that, that Trump made about defense was this ridiculous Golden Dome idea, which was basically a ripoff or Reba of the Strategic Defense Initiative, or Star Wars.
That was the only thing he referenced. And again, it's just, I mean, it's just like we're in a, in the next segment we're gonna talk about Doge, but just kind of pulling things out of a hat. And the one thing I want to, I want to foreshadow before the next segment is this $500 billion figure that keeps coming up in terms, in terms of part of the scam or the schemes.
Um, but again, it's, it's, it's, we have a multiple enemies. And the fact that we're not, I'm sorry, go ahead. So let's bring this back to the average cybersecurity and business executive out there, Chris, should I expect, you know, an, an a significant increase in the number of attacks coming outta Russia, aligned cyber syndicates aimed at US assets.
'cause they're gonna be basically going, well, we got a free pass, here we go. I am trying to be objective about this. Yeah.
Because, uh, my, my position opinions I, I think are clear. Um, maybe not, maybe the op opposite, maybe the direction for the Kremlin is, hey, or reward, you know, Trump for his capitulation and go off, you know, let the, let the stats go down a little bit. That might be a little bit too intelligent for the people in charge.
Um, but, you know, short of that, short of some direction from the Kremlin to, you know, reward our misbehavior, you know, I would say, yeah, sure, you know, this is a bit bit more free reign for all the, all the cybercrime operations out there, that they're likely more rewarded. You know, they're a, uh, you know, so much of the ransomware and so much of cyber crime. Like I say, Alan, this is not about Russia.
You know, Russia's actually a, a lovely country. It's just a bit of a train wreck. Now, this comes from everywhere.
But Russia is one of the massive actors, and this does absolutely nothing to slow them down again, unless Putin, you know, wants to wave a, wave a flag at his, at his criminal fleet, you'll to slow down for a minute. All right? So if you assume that the glass is, uh, half empty rather than half full, I would suggest the key word of the day is incoming.
Yeah, Yeah, Yeah. Don't pay less your Guard down folks. That's you.
What, lemme let me go, let me politics aside for a second. And craziness aside for a second. This, the article that we're talking about that, that spawned this conversation is an article in Security Boulevard, I think, by Jeff Burt.
Jeffrey Burt. And he has a ton of really credible friends of ours in the cyber world who, who are talking out about this. I'll also point out that at least for now, NSA Cs a, uh, you know, some of the other government agencies who are on the front lines of cyber are not necessarily, from what I understand, part of this DOD edict, though, I can't imagine that the Secretary of Defense is allowed to do anything without the okay.
From Fearless leader. And so it probably extends, you know, I, I wouldn't be surprised if it extended in, into the rest of the government, but it doesn't extend to private industry. So my advice, to your point, Mike, to private industry and my cyber profession, fellow cyber folks out there, stay vigilant.
Keep doing your job right? With or without the government or the US government, we still have a mission to, to, to work on here. And, and the mission remains the same.
Keep our infrastructure secure. Keep our businesses secure. Keep our people secure.
I'll leave it at that. Good. All right, let's take a break on Text Drug Gang.
We're gonna come back and well, we'll continue the fund. We're gonna talk about, uh, you know, supposedly how AI is being used by Doge. And you know, that advisory group that really has no official power, uh, to change the government.
You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Alright, well, as John alluded to, we're gonna have a conversation here about, well, what exactly is going on with Doge and their use of AI and feel a legend amount of waste that they are finding? 'cause there's a lot of, uh, people who are calling maybe BS and all of this stuff.
But, uh, John, you've got a story up on text, drawing AI talking about a group who's kinda asking for some records to maybe hold folks trouble. What's going on? Well, there's a group called Democracy Forward, which has been filing a lot of legal actions against the Trump administration.
They've been very busy. They've done at least two dozen legal actions, including this Freedom of Information Act filing and some other actions. What they're looking into are, um, that they, they, they, they want public record requests from several federal agencies on the use of artificial intelligence to make personnel decisions.
In other words, the decisions that, um, let, let's, I'll give you some of the, uh, organization. There's Doge, first and foremost, uh, office of Personnel Management, general services administration, state, uh, defense, treasury departments. And there, what they're trying to figure out is, and what they think is happening is that Doge in particular is using AI as part of this email campaign.
Remember again, where Musk was trying to force government employees to respond to what they did the last week with five things. And in effect, what the Doge is doing, allegedly, is using some of those responses to figure out who's worthy of staying on in their employment and who they're gonna get rid of. And, uh, in a sense, the executive, the person who's in in charge of Democracy Forward has said that Doge and the administration are operating in this shroud of secrecy, and they're governing by cast tactics, have led to less efficient government and more disruptions to our safety and security.
Um, when Trump was talking during his interminable State of the Union address, he mentioned that the initiative to cut back costs had found hundreds of billions of dollars in fraud. And, um, he, at one point, he, he threw out the number of 500 billion, which I mentioned earlier. That always seems to be a patent number that they were using for everything.
Um, he also referred to Musk as the head of dos, which was kind of interesting. But in any event, allegedly Mocu has talked about using AI for efficiency purposes is being looked into by this organization. It'd be really interesting to find out what they, what they discover.
But again, AI is being used to eliminate jobs, which might be a precursor to, to other industries and, and other agencies doing the same thing in the future. I'm a little dubious of the whole use of AI to begin with. 'cause if I look at what seems to have happened is, um, they basically are cutting everybody who was hired in the last year or two as, and those all seem to be hired under the Biden administration.
And then the next thing just seems to be flat out, let's go do global search for the term DEI and anything else like climate and, you know, we'll just cut those things. And that's about the extent of their efforts. So I wouldn't need AI to go do all that.
But Alan, what's your take? Oh, you think I have a tank? Yes.
You in the back of the room raising your hand. Yeah. Um, well, I, you know, John, good article by the way, on ai.
Oh, thanks. On text, on ai, on this. I don't know, there's also a Washington Post article that I i I worked that do's AI use in government doesn't add up.
And, and quite frankly, it doesn't. But let's, let's, let's step back for a second. Does anyone else find the irony in let's keep AI safe and not profit?
Mr. Musk using it for these purposes? Elon, the hypocrite strikes again, right?
So in other words, you can't use it for all, you shouldn't use it for all those things, but I will, because after all, I, I have money, and therefore, there are no rules that apply to me. I mean, this is, this is really the crux of it. But he was the guy who went after open AI because it wasn't safe and secure.
That's why exactly. Principle. That that's why on principle, he has to leave before he decided he wanted to try to buy them in in weird, another weird publicity Study.
I mean, the whole, the whole thing is, so this whole, look, I'm telling you, dude, I wake up every day and I'm looking for Biff up in that big tower in that Vegas kind of hotel saying, what kind of craziness is what, you know, what's right is wrong, Knights and white satin breathe in the gathering gloom. Um, what, what goes on in this world? But nevertheless, it, it's just par for the course of how they are just mashing the federal government.
And no, it wasn't the most efficient organization in the world, that's for sure. But it's almost by design not to be efficient. It's almost by design.
I think Aaron, what we're seeing is, is the Trump effect rolling out to other people? Um, a mess has clearly learned the art of projection, right? Oh, you shouldn't use AI for those things and then I'm gonna do it myself.
That's just one of, you know, a thousand things as well as if I say it, it's true. Whether it has any meeting in reality, kinda, we, we, we expect things to tie back to something that makes sense. They don't, nine times outta 10, maybe 10 out of 10.
It just doesn't. So it, it, you know, I I look at it as yeah, but then the next thing is then we're gonna hear, must complain about how someone's using AI against something he believe Course we will. But, but the bottom one is what are the repercussions here, guys?
What are the repercussions here? I don't think we're gonna know that for Oh, I think we're gonna know real soon. You do.
Why? I think they're, I think they're using it in a lot more ways than we know about. Yeah.
I, I Get Mitch. No, but I, I think you are going to see the gears of government grinding to a halt, and then all those people who raise their hand, who say, yeha, this is what we voted for Until their house burns down. Um, Watch their house burn down.
Yeah. Anymore. I'm from Canada, So it's, I, you know, so, so I'm trying to filter out all of this and, you know, and get to the topic because again, you know, the adversarial goal is to make it impossible to talk, right?
This is all, you know, met, you know, cognitive denial of service attacks, right? You know, give, give people so much to talk about that they have no time left to talk about bloody anything else. And in this particular topic, I don't really know, you know, but I, I look at artifacts like, you know, so you have this, this doji, uh, dodgy operation, you know, thrown together in five days and they get 2 million e email responses.
You know, humans aren't even reading through that ever. So there's obviously an auto, a lot of automation filtering going on, you know, is it oms ai? Yeah, probably.
Right? You know, and that's just so obvious on the surface. And they couldn't possibly even do anything without just automating everything.
So they fire a million people without looking at two of them. But Chris, Let me, let me point out, the emperor has no close. Do you really think?
They, they go through this and that's what they're making decisions on. Let me tell you something. They've made their, the decisions on what agencies we're going to get cut, what programs were going to get cut, were made.
This is, you know what I mean? This is a bass awkward situation. They already know what they want to do and what they're doing it, they just use this stuff to keep you guys busy.
They're doing what they want. They wanted to, to get rid of the Department of Education. They wanted to get rid of the USAID thing.
They're claiming, I don't know how many people are 150 years old in the world now in our country now, 10,000, 50,000, because that's what cobalt the coding defaults to. They, this is all, this is, this is for consumption. So he could stand up and bandi about that $500 billion number, and then all, all the haws or deplorables, or whatever the hell you want to call 'em, go on Facebook and say, whoa, we cut $500 billion.
And then they find out poor Aunt Mary's Medicare got cut and poor Aunt Mary can't get dialysis anymore. Sorry, aunt Mary, right? This is, this is the world we're living in, guys.
But John, you know, it's kinda, at least I find it kind of weird to watch. It's like, so they make a claim on a savings, then there's this contract that they said they cut, then three days later, the website changes. And that savings wasn't there in the first place.
And so these numbers they bandied about seem to be, you know, That was part of the post article that the numbers don't add up. That's funny, Mike. I was, I was, I was thinking about that in terms of like the man, all these manufacturing ideas or these deals that they're throwing out there.
So I went back and looked at Foxconn and looked back at the original terms of that, which were like in the tens of billions of dollars. And it ended up being like a $600 million project. They talked back then about foxcon about 30,000 jobs.
It ended up less than 1500. And I think the same principle applies to this. You know, Trump also mentioned in his speech, apple and the $500 billion they're gonna spend, which many of those programs were already underway, by the way, it's never gonna reach that level.
It, it at least Musk in his, in, in, in Musk's weird way. You know, he will project the truth once in a while. And he, you know, he'd laughed at the idea of the SoftBank deal, which, which Trump bally, who's, uh, SoftBank during his speech.
I used to think all this stuff is, is about flooding the zone, overwhelming us with things that are silly that we fixate on and we never learn as the press. We never learn. We have to separate, we have to separate the noise from the signal, right?
99, 90 9% is the noise, right? Ev and us chasing down all that noise is distractions, right? Kinds back yesterday or two years ago or whatever is kind of pointless, right?
What are, what are they really after, I think is what, what your point is, Alan, is those decisions have already been made, right? Here's the agencies we want to cut. This is what we wanna stop doing, and we'll find whether a path to do that.
And there'll be a wake of chaos in that process, as well as everything else we pile on to confuse the situation and to track distract everyone for what we're really doing. You know, the one thing, can I mark the tape on this? I'm, I'm gonna compliment Trump on something I think he does better than anyone I've ever seen.
And that is, in a sense, manipulating that too. Well, two things, uh, manipulating the media and giving, forcing them in a weird way, or tricking them in a weird way to follow a certain path, which they do ad nauseum and they fall into this trap. Then he switches his gears and moves to the next topic.
And I think this is what we're going through again with Doge. I, I, I would really, if you add up the numbers of some of the things he mentioned that they had allegedly saved on, it would probably less be less than, uh, $500 million at best. And yet he's talking about saving 500 billion.
Well, you have to give the Democrats credit for their pickleball paddle strategy last night. What an thing. So, you know, I, I'm gonna find, I'm gonna find a silver lining in this somewhere, right?
You know, so, you know, the A the ai, the AI in this topic should be used by us, by tech strong, by a, B, C, because the old cliche we're all talking about here, take two seconds to lie, and it takes two hours to refute it. By that time, you're lying about something else. One thing AI might be really good at, and maybe media organizations should be specifically deploying it, is not spending the time, you know, everything that comes out have AI filtered out.
So we're not sitting there googling. We don't have people researching to find out what the stupid lie is last, last time. And, and I am, and you know, I am reaching here, right?
We don't have at the national level, you know, our own government is the adversary, right? You know, we don't have any national defenses and we are at the public sector level working against having defenses. Maybe this is something that media organizations should invest in to shorten that loop the rest.
Yeah. I think, I think you're onto something. You, you put a maybe gonna crawl across the bottom of the screen as he's speaking in real time with, with the AI response or the AI fact checking.
I don't know, something like that. Although Americans don't like to read, so maybe that won't work. But, um, They're not interested in facts.
People are interested in facts. When you point out something is nonsense, they move to the next thing. Or what about this, what about that?
Take vitamin A for your measles. I I read a frigging article yesterday. You know, we're, we're recommending vitamin A for measles and 'cause v vaccinations are a personal decision.
And after all, before we had vaccinations, virtually every child in America had measles. And you know what? Only one out of every 1,250 children who had measles dies.
What's the big deal? Until it's your kid or your nephew, or your niece or someone you love. Then that 1,250 out of one one out of 1,250 becomes real.
That's what this whole thing is. The whole, this whole thing is, let's, I'm done. We're going on text.
We're taking a break. Wait, let's come back and talk about, wait, last thing, One last thing. Mark Twain had it right.
A lie travels halfway around the world before the truth puts its shoes out. There you Go. That's exactly it.
You're watching Text on Gang. Let's come back and talk about technology. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security Bloggers Network. Hey folks, welcome back.
We're gonna geek out a little bit because well, you know, politics is politics and tech is tech, or at least it's supposed to be. But, uh, you know, things get in intermingled. But Mitch, there's this small little conference that was happening in Europe called Mobile World Congress.
You know, a few hundred thousand people show up at that thing. I think it's one of the largest conferences in the world. And one of the things that leapt out at me was this announcement from Red Hat where they had lined up, I think a half a dozen telcos or so to deploy their cloud native platform called Red Hat OpenShift.
And it seems to me like we're just starting to move a boatload of code out to the network edge here. What's going on? Well, yes, you're right.
Mobile World Congress is the, you know, ginormous con of conference of conferences. It's quite an experience to go. Um, yeah, I, it, it's interesting.
Red Hat is making a really strong play. I mean, they've already been in the telco industry with OpenShift. That's really where OpenShift kind of got a lot of its functionality.
And legs came from working with telcos, and now they're extending that kind of up the stack, if you wanna think of it that way. In one way is, is capturing as more things go to the edge or more things are considered cloud native, whether that means just containerized or if it means, you know, building it with other things like microservice, et cetera. As more things move to the edge, just like, you know, the ran, the, the, the, the radios have been ized and moved to the network.
More software's going there too, that they're, they're deploying and they wanna simplify or at least offer the telcos a way of not just running OpenShift in the big behemoth data centers or cloud centers, but also running it the edge. 'cause that's, that's where the action is and that's where more software's moving. So yeah, the, the, the companies we would recognize in the US here were like Orange and Fujitsu and, uh, T-Mobile, I believe there were I think four or five others.
Symphony, some others I'm not that familiar with. Um, we're talking about, uh, what moving more applications and supporting, supporting OpenShift is part of their infrastructure. Now that's a migration process, right?
If they're not already doing that at the edge, there'll be some work to this. So this, this is directional, but you know, that Red Hat is really making a strong play, not just on the infrastructure, but also on the development side of things. We're seeing more and more announcements come that are directed at AI and at software development.
I think AI is gonna kickstart this thing in a bigger way because we need to process and analyze more data closer to the point where it's being created and consumed than these round trips to the cloud. And all the network latency that goes with that doesn't really work all that well. So my question therefore is, um, you know, is this gonna wind up in a situation maybe where we have some more software at the edge than we have in the cloud one day Possibly, or at least wider spread for sure.
I mean, they bought Neuro Magic back in November, which was all about deploying ai, right? Not just to the core, but also to the edge. So yeah, it's, it's moving that direction.
Yes. Gentlemen in the back room is raising his hand. I think he had a question.
You, yes, you, um, You Know, I I, thanks Mitch. Um, I, I think it's important not to lose the cloud native aspect of this, right? Cloud native doesn't necessarily have to live at the Hyperscaler Cloud Center.
It could exist on bare metal at your data center. It could be on the edge, it could be everywhere and anywhere, which is a good plug for an event we're going to plug at the end of this. But, um, what it does do well in greenfields, it's, it's proven to be a pretty big task to transform your existing apps and infrastructure from monolith to, to cloud native, right?
Um, and, and cloud native in all of its glory and flavors, right? So, so you're talking about, uh, not multi-threaded, I always mix up thread well distributed, but no, from an architectural point of view, not multithreaded, but it's multithreaded microservices, right? So you talk, when you talk about moving from monolith to microservices, you talk about distributed core edge data center, that's a lot easier to do on a, with a blank piece of paper to start than it is to take something that people is mission critical or people are using already and, and convert it.
And to me that that's a huge piece of this, right? I I, I saw an article last week, they estimate that for new applications, 85% will use microservice architecture, cloud native technologies, but transforming, and there's a lot of applications out there that need to, you know, will be transformed. That's a much heavier lift, a much, much heavier lift.
I think as we get closer to the end of the decade though, we'll hit a tipping point where the amount of cloud native code will have reached a point where it just becomes simpler and easier to containerize the legacy app, including the virtual machine, and run that on Kubernetes alongside the cloud native stuff to have one single set of platforms to manage. But Mitch, you know, is that wishful thinking or what? I, I don't think at all, Mike, because we think about OpenShift as kind of the infrastructure management of it, if you will.
But right on top of that is, you know, even the co container services that you run in OpenShift that's Kubernetes underneath all of that. So I think our definition of cloud native needs to expand. Yes.
I mean, today we kind of think of it as microservices, et cetera. We're also thinking about it as you containerized and run things on Kubernetes, whether it be legacy systems or things that are partially modernized. But on the other end, the spectrum is also agents ai, right?
That that is also being deployed. And, and we have data from a survey that's coming out here in the next few days about how much of the workload people are putting of AI in Kubernetes, which makes a lot of sense. So cloud native really means kind of distributed computing anywhere at the edge of the core and with, uh, with workflow management Kubernetes, or if there's something else someday that takes its place, that's, that's where we're evolving to now think of it more broadly, not just rebuilding it one way with microservices.
'cause it may not be that, it may be a combination of multiple things that it's built in. Alright. Hey Chris, you know, I don't know if this has been lost on you or not, but I think, you know, if you listen to what we just said and we, uh, extended the attack surface that needs to be defended by a factor 20 and Or contracted it, I don't know.
Right. You know, this is the whole cloud argument, right? You know, if we just, if we just do all our own security ourselves, we're better than outsourcing that to some company that lives and dies by their platform being secure.
Um, yeah, it's a very simple view. I mean, these are complex issues and so forth, but even security companies, you know, the time you have to do your own network administration much less, you know, deep dive security, y you know, I've seen it over and over again, right? We're a security vendor, obviously we do this well, it's like, yeah, maybe, maybe not, right?
Yeah. So, and those, I if it gets anywhere Doing an awesome job on security, man, Well, you have to, you have to kinda live in a world where, you know, everything is changing all the time. Otherwise you're gonna be catatonic with the, the amount of change that's happening in the, the attack surface getting so broad.
And it, you know, to Alan's point he's made about the adoption of ai, the, it's, it's a train nobody's stopping. And the same thing is true to moving to cloud native to the edge distributed workloads. You know, we think about what it looks like now, it'll look even a much greater, bigger attack service than surface in five years from now.
I, yeah, the, the all cloud stuff, you know, SSPs, you know, outsourcing, security operations, you know, you know, like everything, it's been, you know, more than 30 years I've been following this along. And in that one of the best marketing pieces, maybe sums all this up, is IBM they had those blue and blue ads, God, I don't know, not maybe 20 years ago, but it's this great one. It's this, you know, frantic little, little office conference room.
And these people are there and the, the big boss comes in and he, and he is like, okay, are our production down? No, no. Production's fine.
You know, is our, you know this down. I said, no, no, we're fine. Why are we here?
You know, it's like we're, we're a shirt company. Uh, we make shirts, you know, as you know, not a database company, not an IET company. Yeah.
Even like, even technology security companies make security technology to sell. That doesn't necessarily mean they are network security, information security implementation companies. So at a certain point, you know, yeah, the adversary and security has, along with everything else, been evolving from script kitties to nation states.
And, and, and, you know, I've always thought at a certain point, not just the security, but yeah, the, the whole IT infrastructure needs to get out of the most companies. Agreed. You know, just a quick plug here.
Uh, cube Con London Cloud Native Con is, its alter ego name is in London, April 1st to the fourth, we will be there live, live streaming from London and replaying here on text on tv. Mitch, I think you'll be there, Mike, you'll be there. I'll be there.
We'll, we'll be reporting from there. And also, I think it's in July, our own Tech strong virtual event that we do every year on the state of cloud Native, cloud native now, which is also our website for Cloud native will be in July. This year's theme is one for the road, right?
Meaning we're taking cloud native on the road to the edge, the endpoint and everything else. Um, it's a bit of a Blues Brothers theme and, uh, stay tuned for that. So, and that of course is virtual, so be able to watch that on demand or live, and that's in July.
But for now, Mike, Mitch, Chris and John, thanks for joining us today on Gang Thank you out here for listening to our rancid therapy session on, on getting it off our chest of, of, of the world we live in. Who was it? He said, what a revolting, uh, development this is.
But anyway, um, stay tuned. We have all text drug TV following today's gang. We'll see you tomorrow to end out the week here on this, uh, March week, first week of March for Fornando.
That's it. It's Alan Shum. We're outta here.
This is Techstrong tv. Hey everyone, we're back here at Techstrong tv. My next guest is Mr.
Sterling Chin. Sterling is the senior developer advocate at Postman. We're gonna get into what a senior developer advocate is and what Postman is.
We're gonna talk a little bit about AI agents, but first, let's talk a little bit about Sterling and welcome, welcome him to the show, Sterling. Hey man, how are you? Welcome.
Hey, Alan, it's great to be here. Thanks for inviting me. Uh, my pleasure.
So I'm looking at your background there. I'm glad to see this isn't one of those fake ones. Looks like we got rockets, maybe.
Is that what that is there? Oh, yeah. I am a huge space nerd.
Uh, I've been a space nerd my entire life. So, uh, when I moved into tech and started to, you know, be able to explore more, I mean, you can see all the rockets I've got back there. I've got te I've got a Saturn five rocket tattoo.
Oh, Very cool. It, it space is, I, I I'm a huge trekkee, and so space is always the final frontier for me. Absolutely.
Have you, have you made it down to Canaveral, Cape Canaveral and the Kennedy Space Center? I have not. I live in Houston though, so I spend a lot of time.
Oh, you're in Houston? It's close. Yeah.
Okay. If you get a chance, they, they actually have a standard five there. Yeah, they've got one here in, uh, the, in the Houston, uh, spa, the Space Center Houston.
Yeah. If you get, do Canaveral. So I did this with my kids when they were younger, and they had this thing where you could have lunch with an astronaut and Wow.
And our astronaut for lunch was, um, Cory Musgrave. Is it? He, he flew like three or four shuttle.
He repaired the Hubble twice. He was like the Hubble repair man, you wanna talk about the right stuff. This guy had a law degree, a medical degree, a physics degree, PhD.
I mean, he was, my kids didn't know who he was. They didn't care me. I was sitting there like, I, you know, I couldn't talk.
I, I, you know, you want me to sign your picture? They didn't care. I got to sign pictures.
I was all for it. So I'll have to make my way down the Canaveral soon. Yeah, If you can't do the lunch with the national, I mean, they have space camp there and everything, but you gotta talk to your kids or you gotta adopt a kid or someone bring with you so it, you don't feel embarrassed, you know, go with yourself.
Yeah. Um, but good stuff, man. Good stuff.
And, and it's also great you, I mean, if you can go there and time it around when they have a lunch, you know, it's nice, especially at nighttime launch. I, I've heard and where we live. Yes.
From where I live sometimes you could see the nighttime launches. Right. And I'm, I'm three hours south of there by car, so that's how visible they are.
Anyway, we went down that rat hole pretty quick. Let's stop talking about space for a second. Talk to us about your career.
What did, how did you wind up being your senior developer advocate? A postman? Wow.
Uh, yeah. So I have a fairly winded and, uh, non-traditional way of getting into tech. So I worked in the movie industry, uh, for 10 years, built sets, uh, out of college, uh, did transportation logistics.
And then eventually my best friend, uh, he was a developer, and he is like, look, you've got an I knack for this. You should look into it. I ended up going to a dev bootcamp back in, this was 20, uh, 2016, got into tech, and I spent, uh, quite a few years as a developer.
Went from junior engineer all the way up to senior, eventually became a tech lead that led me into, uh, engineering management. And I came here to Postman as an engineering manager. And eventually I started doing more and more stuff online.
And the marketing team said, Hey, we like what you're doing. Why don't you give a shot at, uh, being a senior developer advocate? And now this is what I get to do.
I get to talk to the developer community, uh, explain, you know, you know, talk to, talk to him about tough, uh, problems and problems we're facing, and kind of try to be a thought leader in this, in this space. I love it. Good stuff.
That's a great story, man. So, Sterling, I don't want to, you know, say anything outta school, but there are people out here who don't know who Postman is. You know, if you had to explain it to 'em, what, what, what's Postman?
What do you guys do? In one sentence, I could say the postman is, uh, the API collaborators, or it's a way to collaborate when you're building APIs, it's a platform for building APIs. That said, it is significantly larger than that.
We have a massively large suite of tools that are gonna help developers in every step of the way, whether they're, you know, building an API from the ground up. So using, you know, the various specs to deploying, uh, your APIs, to also mocking your cert, mocking your APIs, testing them, uh, and everything in between. And now with the, the advent of ai, we now have a new suite of tools, uh, that we're calling the AI agent, uh, builder suite of tools.
And this is, these are a set of tools that are specifically designed to help developers build AI agents. Um, whether they're learning and or testing out an API or an AI for the first time, or they're actually building, uh, agents themselves and integrating with their own services and third party APIs. Fair enough.
You know, I, I first became aware of Postman a number of years ago, so you guys have done a great job, right? As you know, we live in the API economy, 57% or something like that, of all the traffic on the internet is actually API api, I kind of traffic. So it is, you know, there's a big market as the VCs like to say, it's a big market.
And, you know, helping facilitate that is, is a, is a major job. Now, everything is AI today, right? And now in 2025, more than just where last year was more generative ai.
This year we're talking agen ai, AI agents. We'll do everything for us. We'll have all these alter egos running around, then we'll need an agent orchestrator, an AI orchestrator, or orchestrate our AI agents.
But how do they actually communicate and do things probably via API, right? They'll, they'll be talking to ais and what's the difference between an AI agent and an API? We could debate that, but you know, unfortunately, there's so much, maybe fortunately, unfortunately, there's so much hype and there's so much nonsense out there.
You know, AI agents are going to replace developers. Uh, Zuckerberg says it may replace mid-level developers. Bezo says it may replace low level developers.
I don't know what, you know, the next oligarch says, but they're all looking to cut developers and use agents. Other people say, Hey, don't believe that hype. This will be your best friend.
It's gonna make you 10 XA developer than you are Now. Tell us, you know, what's your take on this and why, why do you think you're right? Oh, man.
Well, there, there are a few things to that you, that you talked about there that I think we could unpack. One is, go ahead. I, I, I've, I've talked about this a lot.
I, um, that you can't do AI without quality APIs. So one of the things that you, you mentioned earlier in this is there's like, AI is reliant on APIs to actually become ag agentic. You know, generative AI with last year was great, but that's nothing more than having a massively large encyclopedia that can kind of plan and be prepared to, or can, can create, uh, new content for you.
But in the era of ag agentic ai, this is where the rubber meets the road. When it, what, in my belief, you're gonna have APIs that are going to pass you information to another ai, and that AI is gonna then take action on your behalf. Now, to get to your big question, which is, are AIS or agents going to going to replace us?
Yes. However, I want to be a big caveat on that. I believe that AI is not going to replace us.
It's as much as it's going to replace a lot of the menial tasks that we didn't want to do to begin with. Right? I, you know, I, when I was a developer, the last thing I did, the last thing I wanted to do was write tests.
I hated, I was so bad. My, my senior engineers, uh, I, I regret, well, any one of the senior engineers that was a senior when I was a junior, uh, and listening to this, I apologize right now, like the edge case testing, all that was so difficult for me to wrap my head around and, and I shipped more bugs as a junior and mid-level engineer in the future. And what I, and where I think we're gonna be getting to is we're going to empower junior and mid-level engineers to be 10 to a hundred X better than what they are now, and solve a lot of those menial tasks, those problems that we don't want to solve on or, or we don't want to do ourselves.
So it's less about actually replacing us. It's going to replace portions of us and allow us to do what we do best, which is being creative. You know, why, why, the reason I got into developing, and it's not a huge transition from my background in, uh, set construction, and that is because I'm a builder at heart and it's something that is just, it's innate in us.
We want to build things. And so being able to remove that, that remove some of those, those roadblocks of building is gonna be something that agent agentic AI is going to take, is gonna replace for us. Okay.
Um, what about the testers though? Are we gonna replace testers with agents? I don't think so.
Uh, I think we're gonna empower testers to be even stronger in being, being better, right? Uh, when I was, you know, one of the last companies I was working for, we had a amazing QA team and we used puppeteer to, you know, do some end-to-end testing. What we're gonna see with like, the likes of a, of operator or, uh, other ag agentic or other computer use is that a, a qa who's is, who's going to, who's going to use these tools, are going to be able to immediately come up with the, here's the work, here's the user flow through the my and the user journey through my app.
And it's just gonna be able to write the test, and then do that over and over and over again. And then test it multiple in, in various forms. So again, I don't think we're gonna be getting rid of them.
I mean, every, every large company has hundreds, or in some cases, thousands of engineering jobs still available. It's gonna help startups grow faster, and it's gonna help large companies, uh, fill some of those gaps where we don't have engineers right now. I think the, the last, the last census was that we've got around four 40 million to 42 million developers in the world.
I Don't, that's GitHub accounts, I think. Okay. Actual real developers, about 27 million is the latest number I saw.
Yeah. So if we're looking at 27 million, we have a lot more software to build. And so we're gonna need to empower those engineers to do more.
So let me, let me flip that on you. Okay. Right.
Another thing, another numbers I've heard is, well, with AI doing coding for us, we're gonna go within the next seven to eight years, from 27 million, call it 30 million developers to 500 million developers, because everyone becomes a developer when you don't have to code, when the AI's doing your code and another AI checks it and test it for you. And another ai, you know, publishes it for you. Everybody's a developer and Well, that's a great, what does that mean for the world?
Oh, I, I think we're gonna have to face that fact. Uh, and I don't know what totally what that means, but let me give you a really great example. My sister is starting a cottage bakery and mm-hmm.
She pinged me. She's like, Hey, Sterling, you, can you make me a website? She doesn't know how to make a website.
And all I did was I, I got on a call with her, had her explain, you know, the color palette, what she was looking for, um, and, you know, kind of like the vibe of, of the, of the website. And I said, who's your, who's your customer gonna be? And what's the goal?
Right? 7 was released, Came out. Yeah.
I just, I put that in and it spit out a website and within 30 minutes I was shipping a next JS app for her. Now I'm the middleman. And for her, I came able to go in and describe what she wants and then iterate on that.
Absolutely. Like this. I think what AI is really going to be good at is democratizing technology.
It's gonna make small business owners who are interested in getting into tech, it's gonna make, it's gonna empower them, and it's not gonna be a cost, uh, you know, cost prohibitive. On the other hand, large, large scale organizations, enterprises are going to be able to do a hundred x of what they were, what they could even write, like, what they could even dream of. You know, they thought, well, 20 years ago, or 10 years ago, or even three years ago, these weren't possible.
Now it's all possible. Uh, and it, it's gonna be really, really amazing to see what happens. I, I don't, I don't, I agree with you a hundred percent.
I I think what's gonna happen though, Sterling is like that use case you just said with your sister. Your sister becomes a developer. She'll develop her own site.
'cause once she sees what you did, it's not going to be very long where she could go on the Claude herself and do it. Right? Yeah.
And there you go. You're out of your job, out of your job with your sister, right? But, um, you're no longer the middleman and there go your cookies.
But beyond that, you know, that does free up quote unquote, you know, professional developers to do things maybe that aren't that easy, that aren't just, you know, quickly typed in those, A prompt and off you go. And, you know, and then there's, it's one thing to say, here's your website. It's another thing to say, okay, go deploy that I, I'm using GoDaddy hosting.
Go put it up on my servers and, and, uh, oh. And get the domain for me too, right. While you're there.
That's what AI agents promise, right? It's that mm-hmm. Okay, here's, here's this code I did for you.
I want you to go use it and I want you to go deploy it. I want, right? And that, at, at a company level, think about that, right?
Hey, I just finished this app, run it through agen AI testing, put it in my CICD pipeline, and if, and if the parameters are all there, let it go. Well, I think when, especially when you're in a large, when you're in a large enterprise and you've got sometimes dozens of branches all trying to ship at the same time, I mean, we have, you know, we have these, these these dev teams who their only job is to look at deployment and can, and make sure all the branches that are coming from all the other, all the other teams are all working together with an agent that can do a lot of that, that's gonna free up those teams. We're gonna be able to ship 10 XA hundred x more.
You know, imagine instead of, you know, these, these Fortune 500 companies that have, you know, sometimes tens of thousands of developers, they're gonna ship not weekly, not, you know, monthly or not quarterly. They're gonna ship daily and 10 XA day, man. Yeah, John, It's gonna make John Hopkins said with DevOps 10 x.
Yep. It, it is gonna be interesting to see with DevOps. I, again, I don't think this is gonna replace anyone in DevOps, but it, but I think something that, uh, there was a podcaster, I can't remember what he's, um, his name, I was just listening to it the other day.
He said, in reality, we're gonna become managers of agents. And that might be what it is. It's still that we need to know how to write code.
We still need to know how to, how to ship code, how to deploy it, how to do all of that. We may just be managing these large scales or, or large teams of, or armies as someone else put it, of, of, of agents clone wars. Well, so I got some thoughts on, so you're talking to someone who's from a generation where you weren't allowed to bring calculators into the test with you.
Right? You had to know the math. Now, today, you're allowed to bring your calculators into the test.
A lot of kids can't do math without a calculator anymore. They can't read cursive writing. 'cause we don't do that anymore.
Does all of these agentic AI coding task, does it quickly turn to maybe not first gen, second gen managers of them no longer have, have that ability to code because the agents do it so, well, we don't have to worry about that. I just gotta worry about how to manage 'em better. We may get to that point.
I mean, I know Sam Alman said that, you know, 2035 is gonna look completely different than it is today. What that future holds, I, I don't know. I maybe it might be that second gen managers who are doing this are going to have, are not gonna have as much code underneath them.
At the same time, just like any other innovation, any other, any other time in our, in our history, whether it's, you know, horse and buggy to cars, whether it's, you know, the first flight to jet engines, to rockets, everything is just, uh, an iteration. We'll, we will find new jobs, we'll find new ways of doing more. It might be that we're no longer coding.
I don't know. We'll see. But what I do know is for the, for the short term future, which is I think two to three years, I think we're going to, I think we will continue tore, like, we'll, we'll continue to see what this path holds.
I have faith in the developer community that will take the right path. So, All right. You know, let me bring this full circle as we end it.
Maybe what we're headed for is a Star Trek universe where humans just do what they feel like doing and, you know, and, and contributing to society. We don't worry about money, jobs, or coding. Uh, you know what, that's as, as a huge longtime trekky.
It's something that I have actually thought of is like the utopian Star Trek. Mm-hmm. You know, instead of, we, instead of going down the terminator route where, you know, we've got, you know, robots with that are AI that are killing us.
Maybe we go down the utopian Star Trek route where we have, we've overcome the need and the necessity for money. But I don't know, that's, I think those are, those are things that we'll have to face in the next, well, 10 to 20 years Have longer prospered, dude. Alright, Sterling, thanks very much for coming on.
Text Drug tv. This was a great conversation. Postman, what's the website?
com. Check it out. Sterling Chin, senior developer Advocate Postman here on Text Drug tv.
We'll take a break. We'll be back in a moment. This is Textron tv.
Hey guys, thanks for the throw. We're here with Tamim Ani, who is founder of Rap Dev, and we're talking about how to maintain this blameless culture that's kind of at the core of our philosophy of DevOps. Even though the volume of software continues to increase, things are more complex than ever, and there's more dependencies than ever.
So we seem to be working at maybe opposite goals here in some ways, but we'll see how we go. Tamin, welcome to the show. Thanks for having me, Mike.
Uh, great to be on. So what do you tell people about how to kind of maintain their sanity when a thousand things can go wrong at any given moment? Do, do go wrong, right.
Um, I think it's important to understand that things will break and, um, nobody wakes up, uh, one morning and says, today's a good day to break something. And, uh, I think figuring out how to enable, if you enable a true blameless culture or as close to it as possible, I think you get the most outta your engineers. A lot of it comes down to understanding how to enable that, right?
And, um, when we say blameless culture, um, if something breaks, you don't wanna find the person that broke it. Uh, it's generally, uh, a proxy of a system that isn't resilient enough. And that's the theme around a blameless culture from an engineering perspective, is making sure you build a system resilient enough so that if mistakes happen, if bad deploys go out, um, you can quickly identify what the problem is and how to roll it back.
And there's kind of a few different segments to that. It's, um, historically we've always done a really slower, uh, command and control prevent changes. That's how the industry tended to work 10, 15 years ago, even five years ago, right?
Change is bad and you're always looking at these metrics of 90% of outages are due to change. And well, yeah, great, but if you don't change, you're not improving building product. You're not innovating.
Um, so how do we balance the two? And I think we're starting to see things swing over to promote change. Um, more change is better as long as you have the right boundaries and the right, um, culture is one of them.
Uh, I hate process, but I checklists in place to make sure when changes break your systems, you can, uh, make them better the second time around. In theory then, if we're trying to make sure that the systems are resilient, maybe we should celebrate the fact that somebody broke something to highlight the Fact identify resilient. You got it.
Abs after you fix the problem, yes. Uh, don't celebrate until, until you rolled it back. But that's, that's kind of the, that's kinda the point, right?
So like you go, there's like the first version of hit this is, how do I make sure that no matter what it is that's been deployed, can be rolled back, can be rolled back quickly. You get into different things around ab deploys, blue green deploys, uh, feature toggles. There's n number of ways to put the right tech in place to prevent outages from lasting too long.
They will happen, uh, a five minute outage is better than an hour outage, and a one minute outage is better than a fi five minute outage. Um, how quickly you can put those systems in place and use them becomes super important. And then the second thing is, yes, once you've used that system to prevent or to roll back an outage, how do we make that system better?
Why did it break in the first place? Is it bad code? Is it bad testing?
Is it, uh, a some part or some, uh, outlying component of our platform that doesn't behave the way we expect it to? Uh, is it a capacity? Is it a a scale auto scale issue?
There's a number of things that could go wrong, but once you've found a problem, you make sure that it's, uh, identified, resolved before your next deploy goes out. I feel like though rolling things back is harder than people like to admit. And maybe that's also part of the resiliency issue.
So how do we make things easier to roll back so that we can feel confident in experimenting with things? Well, Ro rolling back can mean a mult multiple different things, right? Um, rolling back doesn't mean you have to literally roll back the package you deployed.
Uh, that's where the different deploy methodologies come into place. But feature toggs is a great example. Um, I'm not, I'm not sure, uh, how, how granular we wanna get.
Uh, but essentially you select what percentage of traffic goes to the new code and you start with 5%. Um, and you have both, both versions of your codes deployed in production and you can slowly start to send traffic over. Uh, and that's a great test.
Uh, that's a great, um, business test as well. You're, you're measuring the business impact of the CodeDeploy. A super simple example I like to use is you change the color of the checkout button from green to red.
Do you lose people? Do people stop seeing red? Uh, do people see red more?
'cause they're colorblind and green's harder to see. All these things come into play, but you do them with a very small percentage of traffic. So if that percentage of traffic is negatively impacted, all you gotta do is toggle it back to zero.
You're not really going in and rolling back your code. You're just saying don't send any more users that way. That's one method of, uh, toggles of, sorry, of directing traffic.
Same concept applies at the whole package level. So you've got two different clusters running your application or running your service. You just start to send users from one cluster to another, that that's ab deploys.
Um, and then you can, you can roll through so many different variations, but to your point, actually moving that, uh, that package or that block of code out of production is so much harder than just moving the direction of your traffic from one subset of, uh, service to next to the next, or pods or name spaces or whatever. It's, It sounds like I need to be able to orchestrate that. So what is the, for lack of a better phrase, a a control plane that enables me to kind of manage that traffic flow and make sure that the components are, aren't overloaded?
'cause somewhere along the line, I need some way to manage this thing Totally there. This, we, I mean, obviously wrapped up, we're gonna have a bias, right? We work with Service Now Datadog, um, and both are super important.
ServiceNow from a, um, a kind of record perspective. So what is going on? What is happening?
Lemme keep track of all this stuff so that once this, uh, blast radius is sorted, I can go back out and look at everything that's happened. Uh, so that's kinda one piece of it. Um, on the record keeping, on the actual control of, uh, traffic and where it's going.
We use Datadog extensively. Um, uh, Datadog is a really good indicator of the health of your traffic, the health of your application. Um, every time a deploy goes out, am I seeing an impact in response codes, access logs, uh, HGTP codes, right?
Um, and at the same time, that's coupled with some sort of feature toggle tool. Could we launch darkly? Uh, could be homegrown.
We've, we've done a lot of homegrown custom feature toggle tools with some really solid caching that accomplish the same thing, right? It's not really that hard, but measuring the impact is what's important. And that's where observability comes into play.
And that's where Datadog comes into play. Um, anytime something blows up, everyone's gonna say, it's not my fault, right? It's that team.
It's that team. It's not me. And that's a, that's the opposite of blameless culture, right?
You're trying to say, Hey, let's figure out technically what broke so we can technically improve our systems. And that's where really solid observability comes into play. Do you think that some of these challenges might get worse than the age of ai?
'cause we are now generating more code than ever, and a lot of that code, um, may be suspect 'cause it was created using models that were trained using code that was probably flawed, Worse and better. Um, I think even just because you're using, uh, some sort of models to generate code, it doesn't mean you should circumvent all your automated testing, automated, uh, uh, scanning, security scans. That should all still happen.
Um, you're not saying I'm generating code through some sort of copilot, therefore this is safe code. Uh, another kind of layer on top of that is even though you're using a third party generate code cursor, et cetera, um, a human is still behind the screen watching what's going, what's being merged, what's getting prd. So on that front, um, it's helping you get faster.
It's helping you get more, more efficient. It's not replacing the need for anything that's currently in place on the production side or on the deployment side. You can actually generate code to fix your bugs.
So if you do detect something in production, you do know what merge went out, you do see a slew of alerts coming in through observability tools. Um, instead of having a human review it and determine what's going on, you could use models to say, Hey, here's my error log, here's the commit, the broke it. Um, what do I need to modify in that commit?
So you could actually generate, and we're, we're doing this, uh, for customers already. We generate a whole new PR with the fix as a commit in the PR to essentially resolve the outage that's happening. And that can save a ton of time, right?
That goes back to, um, do I want to turn my toggle off and go back and look at it as a human and take a week to come back? Or do I just wanna look at what my agent, right, or whatever buzzword you wanna use for, for LLMs is suggesting the solution is, and that could very well be your fix. I mean, as a human, you look at it, you say, oh, duh, I should've thought of that.
Um, but when it's, when it's generated on the fly, it does save a lot of time. So you could use, you could use the on both the, the dev side and the production side, uh, pretty effectively. So in effect, I am using AI to help heal the ai.
Yes. Um, and I always use, yes. Uh, ironically, I always say we use AI to generate, uh, a 70 page deck to mail to someone to use AI to summarize the 70 page deck into three bullets.
There's a lot of that going on. Um, it still makes you go faster, right? At the end of the day, if it helps, if it helps you go faster, if it helps with momentum, if it helps with velocity on the engineering side, I hate PowerPoint.
I don't think there should ever be a world where we're using AI to generate 400 pages of PowerPoint. And I think that's one of the areas in business that will get impacted very quickly, very heavily. But with, from an engineering perspective, you're building features, you're putting features on your platform.
You can do that five times faster and maybe take a hit every now and then, but you can resolve that hit faster, then why not? Um, nobody's gonna be able to, no human is gonna consume 400 pages of slides. It doesn't matter how good you are, you're gonna summarize them.
That brings you back to square one. How is this gonna evolve as we go forward? We hear a lot about AI agents, and I can imagine a world where what you just described, some of those tasks are being handed off to an AI agent that's been a member of the DevOps team, as it were.
Um, I wouldn't think of them that closely as like, I wouldn't, I wouldn't translate an agent to a human. I think an agent is a subset of functions or methods that will execute. Um, and re like agents are essentially, you make a prompt, you get a response, you run that prompt through another prompt, and you try to, you try to, uh, improve upon the response you're getting from a model.
It's just three or four steps instead of one. Um, it's very unlikely that you're gonna get a very accurate response from a model on the first prompt you send it. Um, so I think of agents as a refined, uh, kind of conversation, if you will, with a given model.
Uh, but yes, there definitely is a world where, especially on the kind of the lower end skills, things like password resets, things like add me to an ad group, things like really low, low level help desk is I think is gonna be very impacted by this. Uh, call centers will be our, we're already seeing, um, tens of thousands of people being put out of call centers because that's a very easy thing, uh, to manipulate and to move over to generative AI models, right? Or, uh, generative audio.
Just not, not wireless language models or audio models. They video models. Um, that can be very easily done in real time, uh, especially with voice tokens instead of text tokens.
So you can start to run things in parallel. Um, but all that is to say absolutely all the low level stuff, um, that's historically been, uh, offshore near shore model. 'cause it doesn't cost as much when it gets offshore, will be replaced with, um, a lot of different AI models in the next two to three years.
And anybody that's not saying that, um, I think is crazy. Uh, we're definitely gonna start to see that. So let me bring this full circle a little bit.
If we think about blameless as a culture, it was always kind of the, the high end of the DevOps h entry mark. Yep. It was, it was in the sense that, you know, I had to be pretty mature in my DevOps workflows to get to that kind of blameless mindset and kind of feel that if I have AI and I'm starting to automate more stuff, well, more organizations get to that level of, let's call it DevOps nirvana, because they're gonna understand that the system itself is designed in a way that enables them to maybe stop pointing fingers at Each other, be resilient.
Yeah. I don't know if it, you don't have to be super mature to how I blame this culture. I think it's probably the opposite.
You can be very mature, but the way you approach your path to maturity could be very wildly different between a blameless organization and non blameless organization. And what I mean by that is you can work somewhere with a ton of bureaucracy and red tape and be immature. Um, but the way you try to become more mature in your platform, your code base, your microservices, your application, whatever it is, is very much, Hey, every time something breaks, we're gonna sit in a room and we're gonna meet and we're gonna find out who wrote that code and why they didn't take their training and because they didn't take their training, we're gonna blame them for writing bad code versus a a, a platform in the same maturity stage.
But every time something breaks, you're gonna say, Hey, what can we, what guardrails or what tech can can we put in place that prevents this from happening a second time? Both of those are immature and both of those will find their way to maturity one through a different culture, faster culture than the other. Um, historically the tech industry has very much been a world of slow down, don't go fast, don't break stuff, don't work.
Let's do everything on weekends. Let's do everything on Friday night. If you break something on the weekend, it's gonna take you eight hours to get the right team on board.
Something breaks at one o'clock on a Monday, everyone's already online. You can fix it a lot faster. And that's just the mind shift in, uh, in that culture.
So, uh, AI being a benchmark sure is gonna help, but you can still very much, uh, accomplish that benchmark without having, um, without having to leverage AI to get to that blameless culture regardless of maturity of your platform, maturity of your team, organization, et cetera. So thinking this through a little bit, um, you know, you hear the phrase over the years software factory. Yeah, I understand the concept, but I also feel like, you know, it winds up taking people out to that woodshed every time there's a problem.
And that necessarily doesn't necess create their culture you're looking for. So what is the balance between art and science and the world of software engineering? And so it's a very open and, and question.
And as also just software is everything factory, right? Is let's build a factory. Let's build a t-shirt size factory, let's build if, if things are that simple and that, um, reproducible, you wouldn't need that many people working on whatever project you're trying to build a factory for, um, chances are they're very low likelihood of things being that, um, uh, repeatable, right?
In an environment where you need to migrate thousands of VMs or get out of a data center or refactor from a monolith to microservices, there's no factory model. Um, I do think the higher up, the higher the high, uh, the more complex engineering problems require a little more art. I think that's where you start to differentiate between what a copilot can do and what a very experienced, um, software engineer can do regardless of, I'm not gonna say someone with a bachelor's or masters, any of that.
'cause that's also kind of irrelevant, but it's how much have you seen, right? And the difference between uh, uh, a software architect or somebody with a ton of experience that knows how to design patterns or how to design libraries or frameworks is gonna be a lot more relevant in two, three years than somebody who just knows how to write a function that will very quickly be replaced by copilot. So I think we're gonna see a push to really force engineers to become a lot more, just, just think a lot more, uh, creatively in the way they write their code versus just write a prompt that gets the job done.
Um, and then performance comes into play and scale comes into play. Those are the things that it's gonna take a little longer for some of these models to catch up to. Uh, versus a human that has seen this for a long time, that'll become the differentiator in my opinion.
So what is that one thing you see DevOps teams doing over and over again that just makes you shake your head a little bit and say, folks, we can be better than that? Um, that's a good question. I think a lot, there's a, there's a really, really big misconception that, um, infrastructure patterns for as code are gonna solve all your scale problems.
Uh, that's not true, right? Uh, just because you got, just 'cause you moved to Terraform or you're writing Ansible playbooks, um, you still gotta think about the way you're scaling up and scaling down your services. Um, autoscale groups and helm charts, uh, are not the final end all be all.
Um, you can, you can get pretty far with a lot of the kind of standard autoscaling stuff, but that starts to incur a ton of cost and being able to balance those two, um, you're not done when you've moved everything to, uh, to infrastructure's code. You're still a lot of work to tune that down to make sure cost is under control and you don't have long lived, um, workloads that don't need to exist. Uh, scaling back tends to be where things get a little more hairy.
Um, and that's, I think I've seen that over and over again. That's, that's not something, security is another interesting one. We're starting to see a lot of, um, SEC secure.
I mean, I think we will see more of this, but we're already starting to see more security shift into DevOps teams. Um, and you're really self-servicing your security needs through, uh, infrastructure as code versus having to go to security team to do what, what, what we historically used to do, right? Gimme access, gimme firewall rules, gimme traffic patterns that'll continue to move, uh, in the, in the way of, uh, kind of shifting to the developer, just the same way infrastructure shifted to the developer of the past five years.
I think security will follow the security team. Then we'll just be focused on policies, um, procedures, making sure, um, guardrails are in place, but the way they get implemented and changed will definitely move, uh, more into the gi GI ops model. So things are clearly pretty fluid and we hear a lot of phrases like platform engineering being one of them in the final analysis.
How do you see DevOps kind of evolving from here? I think we're gonna see more. Uh, I mean, DevOps kinda means DevOps is used for a lot of different things.
I think generally thematically we'll see more infrastructure being managed by developers as things continue to scale out. And as a lot of the infrastructure management tools and platforms, uh, become more, um, stateful and code focused, I think there, there will be a layer underneath for shared services, which is platform engineering, which is, uh, you're caching your DNS, your, uh, traffic patterns, your network layer essentially. That stuff doesn't really need to be managed by developers.
But I think a lot of the infrastructure stuff, the auto scaling, we will see more and more of that shift over. Um, I don't know if that's exactly what DevOps is gonna be in five years. The, the, the term DevOps has frankly just morphed.
Uh, and we'll continue to morph. DevSecOps is now a thing, right? And GI ops as a thing and all those things continue to change.
Um, but I think we'll see more, more control, uh, in the hands of developers, uh, than we have in the past. I don't think that pattern is gonna Change. Alright folks.
Aaron in here, one way or another, we wanna deploy more software safely, faster than ever. Each organization may get there slightly differently, but that's where we're all going. Tamim, thanks for being on the show.
Thanks for having me, Mike. All right. And back to you guys in studio.