Techstrong TV – May 13, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. You ready to get entangled with Quantum Networking? You're watching Text On Gang?
Happy Tuesday, everyone. It's Alan Schl for Techstrong, and you're watching Textron Gang. We've got a good show here with some interesting stuff as this week starts taking off and we've got some interesting people to discuss it with you.
Uh, let me introduce you to our gang for today. First of all, with the fancy background. Mm-hmm.
LLMs ai. I, that's what he, yeah, we've, I had, that's a new one I haven't seen before. He, he's our friend, JP Morganthal.
Jp, how are you man? I'm doing great. How's everybody today?
Well, we'll find out, won't we? But good to have you moving on from jp. We'll go up to he, I think, I guess from the background, he's back in Hudson, the man from Hudson.
Oh, that was the man from Hope. Well, you're the man from Hudson, uh, or uncle the, uh, founder of Tech Field Day, Steven Bosque. Hey, Steven.
How are you doing? Well, you know, it was nice to be down there in the studio, uh, keeping Bonnie's chair warm and the, uh, but, uh, it's nice to be home. There's no place like home.
Yes, There is. Click your heels when you say that. Click those heels.
All right. Welcome Steven. And then also home in Harrison, New York.
Not named for the president, our Chief Content Officer, Mike Ard. Hey, Mike. How are you?
I'll echo Steven. Sentiment. There's no place like home.
It's, and any day you're headed, home is a good Day. That's right, that's right. Speaking of home, we're home here in our book studios and joining the in studios, our resident Echo Insights analyst and, uh, editor Bonnie Schneider.
Hey, Bonnie, how are you? I'm Well. Great to be here.
Alan, great to have you in the studio. I gotta tell you the truth. It's a lot better having you here.
I mean, it's not that I have anything against Steven, but it makes for a better picture. Well, it was rain, honestly. I'd rather have her there too.
Yeah. All right. Let's, um, it is a rainy day here in Boca Ratone, but you can't have sunshine every day.
Wow. It's actually raining in Same, in two different places. Miles apart in Florida.
The same in Florida. Well, we, That's, that's, that's not a Good sign. No, but we needed the rain.
It's been, it's been pretty dry here, Here too. Yeah. We need to rank anyway, so Mike Cisco threw their hat into the quantum race Derby, whatever you wanna call it, but being Cisco, of course, they're talking about quantum networking.
True. That. So yeah, Cisco has revealed that it's working with uc, Santa Barbara, to build something that feels like a quantum networking and entanglement chip.
And I guess, you know, in my mind, a lot of us thought about quantum computers as these big kind of mainframe like things, but maybe they are gonna be a little more distributed. And every time I turn around, somebody in China seems to be building a quantum computer that's smaller and feels more like a general purpose machine. So Alan, I know you follow the space, but what's your take on what's going on here?
You know, I, I think this is the filling out of the ecosystem here, right? But this isn't networking the way you may be thinking of networking. Um, but I just wanna mention, hey, we are planning a virtual event on quantum called of All Things Quantum Leap.
Uh, and it'll be in October. And we're looking for speakers, sponsors. And if quantum's your thing, you should register for it.
I don't think the registration page will be up for another week or two, but, um, I'm looking forward to diving a little deeper into all things quantum there, from quantum to security, to quantum chips, to quantum networking, algorithm, software, everything else. But when, you know, first of all, people have to be familiar with the entanglement principle of quantum, right? Which means you could have two particles or two pieces of matter that are somehow, you know, as crazy as it seems, they could be light years apart even, and still connected entangled, where if one spins, the other spins one, you know, and they, they copy each other's, uh, uh, matter kind of, uh, you know, if, if one's spinning left, the other's spinning, right?
Whatever it is. So they're intrinsically linked, they're entangled. And once you understand that and you have that, and you can manipulate that, well, that allows for all kinds of, of things.
Every, you know, from the craziness of teleport teleportation, you know, star Trek kind of beat me up, Scotty, to networking perhaps, right? And that's what Cisco's talking about here. Now, the interesting thing, it doesn't necessarily have to be networking like from a router to an endpoint or over the internet.
It could just be two quantum chips that are entangled, right? So by using entanglement, you can create sort of a, a parallel type of processing, uh, you know, sequence where you can have multiple quantum chips now working in quantum time, right? Via entanglement.
And so if, if, if a thousand qubits is the holy grail or whatever of one, we could really hit quantum, you know, picture having 10, 100 qubit processors that are network really entangled and, and working like that. Yes. I, I, I just, I wanna address the, uh, Cisco announcement with regard to that, right?
I think what Cisco was pointing out is that we don't have that kind of scale on the horizon right now. We have, well, no, but what we have is a, a limited number of qubits, chips that can, that are created to create a quantum computer. But what the way they're saying that you can scale is by creating, leveraging quantum networking as a way to create multiple quantum computing machines, Right?
That that's what you're gonna have in, right? You're gonna put 'em in parallel the same way we did Linux machines into supercomputers, right? That that's, it's kind of the same kind of thing.
I I I'm interested in how much data can be represented by these entanglements. Because if you, the one thing we've always said is that they, you know, and I've always joked that, you know, ultimately the network owns the s for the in, for the for, for the universe of computing because it's the, it's right now the major limitation, you can only get data to, and so much data to move so fast from point to point, right? So it, it's your, it's your limitation in compute right now is how much data can you move and, and how far can you move it before you see degradation.
So if you, if this thing can carry terabytes of data instantaneously moving it from point to point, it's, that is a, then that's a huge game changer. That is a major game changer. Yeah.
But this is, I mean, the whole idea of quantum networking, I don't know if we could think of it in terms of how much data can I move over a pipe? I, because it's particle to particle. So I think the, the issue then becomes, well, can I do a hundred thousand particles to a hundred thousand particle?
But each particle has this much on it, but, you know, but a hundred thousand of those, nevertheless is a lot. I mean, jp honestly, this is, this has hurt your brain stuff, right? That it's, it's kind of so far out there and so radical to what we know and think of.
Um, because I don't think data is necessarily transported. It's kind of an instantaneous, if this knows it, that knows it. I mean, you know, you gotta, you gotta be on some medicinal marijuana or something to kind of get your head wrapped around this.
So for, So for people who, um, are, are not quantum, uh, oriented, uh, think of it like virtual mapped memory. You have your virtual map on top of your physical disc and your virtual map knows instantaneously, whatever's on the disc data. And then you move your virtual windows around to see different parts of the disc, and it becomes just boom, it's available.
So you're saying the whole universe could be on my thumbnail, I was thinking more like the cat in, uh, men in black around the, the, the, So Steven, it sounds like to me that this is the laws of physics being applied to quantum computing, or is it fundamentally different? Well let, yeah, let's, let's, uh, I, I don't know, get, get down to down to earth here in a little bit. Uh, you know, put down the, the wacky tobacco, if you can for a second.
Uh, yeah. What Cisco's announcing is pretty interesting, and I'll just point out that we actually heard a very similar thing, a similar story from others at our networking field day. In fact, in March, uh, bt the big, uh, telecommunications giant presented a whole section or a whole field day session on quantum networking.
And Cisco's describing a similar application. The idea is, well, number one, Cisco has some pretty cool technology here. They've got a quantum, uh, pro well networking processor, entanglement, chip.
It's not really, this isn't a quantum processor. This is a quantum enabled networking chip that works at room temperature, at very low power and uses the same wavelengths of light that are currently used with optical networking, which is important because otherwise it would not be practical at all. The other thing, like JP was saying, I mean, the interesting thing here is that you can instantly, and, and when I mean instantly, I don't mean just really quickly, I mean, it's there, um, transmit data in a way that cannot be snooped on that is completely, you know, synchronous on both sides.
And that's a really useful tool for things like key public key exchange and encryption, that sort of thing. Another thing Cisco has done is they are using the quantum, this quantum fluctuations as a random number generator. And, and I think that those of you in the security space, I'm sure that you all have experienced this and, and know that random number generators are not very random.
And that's a huge problem. And that's one area that hackers and especially nation state hackers use to exploit systems. Essentially, they will, uh, clone the Pseudorandom number generator and make and, and, and, and generate the same number.
Well, it's awful hard to do that in the quantum space. And Cisco has come up with a quantum random number generator. And, and also they're working with, uh, university researchers to develop future applications that would allow interconnection of quantum systems, but also quantum interconnection of classical systems, which is something that the BT presentation was talking about as well.
There's just a lot of really interesting, um, features in here, including some nuts and bolts ones, not some pie in the sky ones. I mean, honestly, a quantum run random number generator. Sounds great.
Well, you know, it's funny you bring that up, Mike. Wasn't it just yesterday's show? We talked about this issue about some researchers, researchers came out with a report that they explaining and, and being able to anticipate prime numbers, which is, you know, how all of that underlying all of our encryption and, and, and the idea of being able to generate random numbers, you know, is, is this, it's not so random as it turns out, potentially.
Anyway, there was just a research report, whether it was, you know, how true it was, we don't know yet. But, but I, I, I actually, Steven raised an interesting point that I hadn't yet considered. I in the field of intelligence, um, think about a compu two computers in two skiffs.
Those are compartmentalized rooms. Air GAed not connected to any network, not even the high side, low side of the, of the government actually Air gap computers being able to communicate with each other across skiffs, that is an insane intelligence application you would actually have, because the whole idea of the air gap computers, it's not connected to any network, right? It's a standalone computer that a, uh, performs some type of function.
And this would allow those computers to be networked And not have Well, but is that a good thing or a bad thing? Well, from an intelligence application standpoint, it's re it's a, it's critical. Depends on which side of the intelligence equation you are.
If you're trying to protect stuff, it's good. So this comes back to kind of what I'm starting to wonder about here is, so we know that the existing computer architectures we have in place are flawed, and we're using them in ways that are insecure. And to Alan's point, there's prime number issues now that people are figuring out.
It feels like all the money being poured into quantum is an effort to kind of reinvent computing. And it might take a decade or so, but, or is this gonna be some, you know, little sidebar esoteric thing that we're using for some vague computer science project? Like, you know, we're gonna figure out how to use some chemistry application differently.
But, you know, Steven, how big a deal is this ultimately? Well, the proof is gonna be in the pudding, isn't it? Uh, we'll see if they're able to productize this and bring this to market as a friend of the gang, Bob Sutor would say, and as he did say in that Textron article, you know, I mean, there's, uh, there's a lot of uncertainty here in the quantum space.
Yes. Im sorry. I had Yes, there's a principle about that, isn't there?
Exactly. Yeah. The principle says that it's uncertain, um, and we gotta listen to the principle, but, uh, no, the point is, we'll see, right?
I mean, if Cisco can productize this thing, I, I, I can envision a situation where next year, the year after Cisco brings a quantum powered random number generator for encryption tasks to market. And that becomes a very important and useful tool. I could also see a situation where they never talk about this again, and we just continue to move on about our lives.
So ultimately, it's not research that fixes things, it's products, and let's see what Product can, well, what about, what about both of those things happening in parallel universes back to the wacky tobacco, just saying, just saying. But, but seriously, You know, if, if we are going, so I'm a Star Trek Fat, I, I have to, you know, if we are going to go on these adventures where no person's gone before, if we're going to continue pushing the boundaries, right? We, we've spent the last hundred plus years exploring basically the theory of relativity and how that affects everything that we do.
And it's led to the nuclear and hydrogen bombs, fusion bombs, vision, energy, and so many other things. The next breakthroughs that will advance the human condition. We need to understand and harness the power of quantum.
And, and you know, this, um, this is one of those times you're happy to be in tech, right? Because we're kind of leading the charge here a little bit and trying to harness, harness this to recreate what we do. And that's kinda what tech, the tech industry does, right?
We don't use punch cards anymore. We don't use little floppy disc, right? How, you know, so I'm, you know, I, we do it because it's hard.
Not because it's easy, but it's worthwhile. And, and that's my last word on quant. I'm looking forward to the Rung Gang being in two places at one time.
That'll be fine. Well, we're already yet, look, we're in Ohio, two places in Florida, in New York already. We're quantum, But then I, but theoretically I can have two Steven FSTs arguing with each other over a quantum network.
Solar. Solar, I'm sorry, I just had to say it. All right, let's take a break and kinda sober up a bit here.
And, uh, we'll come back and Steven, you can have a report for us on Mobility Field Day. Yeah, I sure will. Fantastic.
You're watching Techstrong Gang. Well, we are, uh, hosting a lot of different field day topics, but as I said last week on The Gang, my favorite tech field day, I mean, my favorite child among, among many is Mobility Field Day. The reason is because as, uh, they were all laughing at me for saying on the gang, they are from another planet.
It is always fun to, to mix and match with people who, uh, know something that is completely alien, that, that are deep experts in a field that you aren't an expert at because you know, you can really kind of soak in it and learn so, so much, so, so quickly. Unfortunately, I wasn't at Mobility Field Day. I was in some place called Boco with a, uh, distinguished man named Shimmy.
But I was, uh, check checking it out remotely as anyone can do, watching some of the presentations. And over the weekend, I checked out some of them as well. It's interesting the takeaways that you get from this group when they do come together.
Uh, one of the things that I predicted going into it was that wifi seven was gonna be a very important topic. Well, the answer to that is a little more mixed. Um, wifi seven sure is important, but some of the key features, especially Multilink operation, are still very much a work in progress.
There are standards, but they're sort of pre standards, and the companies are still working on that technology. Another aspect that we heard quite a lot about was how to bring wifi to the masses at large public venues. If you've been to a baseball game or a football game and tried to use the wifi there, it probably works better than the cellular network.
But unfortunately, that, again, is still a, a, an area that there's a lot of development happening on. Well, fortunately, because a lot of that development is actually going to be able to leverage some of the features of wifi six and seven to really broaden access to public wifi. The other thing that's important is that we're seeing a lot more crossover between wifi and data center technologies.
So things like, uh, VXLAN and so on are actually coming into the wifi space, which again, is one of the things that I love about learning about other fields, because you can take ideas from those fields and bring them into yours. The wifi community was the first to have essentially what we now know of as software-defined networking, or software-defined computing software defined anything. This idea that you have a controller and then you have, uh, basically cattle instead of pets out there as your hardware and the controller, uh, with Zero Touch will activate and configure and, and, and integrate that hardware.
Well, that was a very widespread technology on the wifi side before we ever saw it on networking, let alone on Compute. Now it's everywhere on compute, and that has been a really powerful thing. So it's really cool to see some enterprise networking features and ideas like VXLAN come over into the wifi space as well.
So overall, that, that, that was sort of the takeaways from Mobility Field Day. I do urge you to check out some of those presentations, especially, uh, I just wanna give a little shout out here to, uh, fellow Futurum, uh, analysts, uh, Ron Westfall, who talked a lot about some of the, uh, intelligence research that we've done, uh, internally on the state of, uh, mobility, networking, quantum, those sort of things. Check out the, the Ron presentation.
All those posts are up, um, on the text on tv, but they'll also be up on YouTube very soon. So Steven, every time I turn around, some telco is trying to get me to essentially ditch wifi in favor of using LTE as my primary network. And they're pointing out things like, you know, wifi can get hacked and it's a pain to use.
And you know, you, to Alan's point last week, I think, you know, you gotta stand on one foot to get the connections, right? So, um, is there a case for LTE here or is wifi still the dominant player? But wifi is gonna be used in other things?
Well, when all you have is a hammer, everything looks like a nail. And if you're a telco with a big 5G or LTE network, uh, you might start saying, Hey, we can do that too. I think there is some crossover, but I think that, uh, those of those that I know who've deployed, um, basically LTE as a, as a broadband back haul, many of them are happy with it for the price.
Um, many of them are not happy with it, with it for the performance, especially when when things get busy. Uh, that's not a topic really that the mobility Field Day folks have talked much about. Um, but again, without casting aspersions at anyone on the call, uh, we found that it's sometimes difficult to implement wifi in a way that is reliable and high performing and meets the needs of users.
And I think that the ease of use of mobile networks has really come a long way to the point now where, I don't know about you, but I was at a hotel over the weekend. I never connected to the hotel wifi. I just used my phone, uh, on 5G the whole time, and, and I didn't really suffer for it.
So I think that, uh, many of us may be starting, I don't know, maybe the bloom is off the Rose A. Little bit on wifi. Do you find yourselves doing that as well?
Yeah. Mm-hmm. Yes.
Well, and, and, and to the aspersions around wifi, it helps if people do plug in their wifi access points as we found out one was unplugged here, but, um, who knew? But you know what, I, real life, so at the HOA where I live, I'm, I'm the president of the HOA in Del Boca Vista. Um, but anyway, we are looking at bringing in a broadband provider for the, for the whole development, which is 69 homes.
It's not a big development, and they wanna bring five real fiber to everyone's house, not fiber, and then last mile fiber in everyone's house. And everyone would get two wifi, seven, uh, wi, you know, wifi access points upstairs, downstairs, a whole bunch of other stuff, five asynchronous, 500 meg up, 500 meg down cable tv, and if you want IP phone cheap, like 80 bucks a month for all that, I surveyed the neighborhood to see, is this something we want to do? And I was surprised that there were outta 69 homes, about eight homes that are on this T-Mobile, LTE.
You know, if, if you have a T-Mobile phone, they give it to you for like $30 a month. If you a T-Mobile cell phone customer, they give you a little wifi access point, and for 30 bucks a month, they get, they're streaming, they're streaming tv, they don't have cable, they're streaming video, they're using it, you know, for basic connectivity. Now granted, these are people like all del Bulk of Vista people who are probably in their sixties, seventies, or greater, and are not, you know, I don't think they're uploading any videos or anything.
They're shooting locally, though one never knows in Florida. Um, but it works for them. It works for them.
And so in $80 now, they don't have anywhere near 500 megabits up and down, but for what they need it for, it works. And, you know, 30 something dollars to $80, they'd rather keep their 30 something dollars thing. I don't think that works in an office here, maybe with the amount of devices we'd have connected in our with needs.
Um, and I'll tell you one thing, what I do agree with Steven on is like, I believe, and maybe I'm wrong, but the, I think the LTE connection is more secure than the wifi connection, especially if I'm like bouncing into some sort of restaurant somewhere and I'm trying to use their wifi and god knows when the last time that thing was Updated. Well, Stephen, my friend Jennifer, Jennifer, jj, man, Jennifer Manilla was at your event, wasn't she? Yeah.
And Jennifer is, is fantastic. Yeah. She's the authority on wifi security.
And the truth is, uh, to your point, I don't think there's any intrinsic reason that wifi is less secure than cellular. In fact, I think that it could be more secure. The problem is that wifi is generally misconfigured everywhere.
Um, you know, I, uh, I had to reconfigure the local coffee shops wifi while sitting there, uh, because of, uh, you know, they, they just had the default outta the box configuration from Windstream, and it was just terrible. Um, you know, that sort of thing happens all the, all the time. And I think you're right.
Um, you know, rogue access points and, uh, impersonation attacks and all that stuff, it's, it's, it's not as common maybe as people might think, but it, it does happen. And that can be really bad. Uh, any, I, I dunno, if you wanna be terrified, Google wifi pineapple, and you'll learn all about that.
Um, on the other hand, uh, there are also rogue, uh, LTE cells, uh, Google Stingray, and you'll be terrified as well, and you'll shut off all your phones and throw them in the microwave and, um, and be done with it, because all of this stuff, there's, there's, there's also sorts of hacks here. Yep. Steven, I wanted to talk about another aspect that was discussed, and you mentioned briefly, and that is, you know, stadium level wifi.
So I, I've been covering that basically with my friends from Extreme Networks now for a few years. And they, they have a good business around that. I think they're like the official partner of the NFL or something.
I know the Cisco Stadium, um, where the 49 ERs play in Santa Clara, I don't know if it's still called Cisco Stadium, but with Levi Stadium. Yes. They, they do that, they do a whole bunch of stadiums and, and they have made a ton of progress there.
And I, I've seen it when I go to sporting events now, you know, it used to be you can get on the network, but you wouldn't go anywhere. You couldn't get out. But, you know, most recently I, I've seen absolutely improvements there.
Oh, yeah. Well, it's funny that you mentioned Levi's Stadium. Uh, unfortunately we weren't able to film it because of confidentiality reasons, but we actually had the company responsible for the wifi at Levi's Stadium lead the mobility Field Day delegates through Levi's Stadium to show exactly how they implemented that.
And it is really well done. That's an example of, um, you know, the, the, the, the good aspect of the wifi deployments as opposed to the bad ones that you find, um, mostly everywhere else. Even there though, um, we've caught up with those people over time.
They've had all sorts of interesting edge case kind of failures that they've had to resolve. And again, happily that group has come back to us and spoken with us and told us about the lessons learned and the things that they've done to improve access there. It is incredible what happens, for example, when 50,000 people arrive within a half an hour and connect to your wifi.
Uh, that's not something that most people experience, but it is something that they've experienced. So I think that it's one of those, um, one of those things where expertise really matters. You know, when you go in the office in the morning in those big office buildings and you show up around nine o'clock, you experience the same phenomenon where everybody else logs in at the same time.
Right? Well, you know, it's true. It's true.
And, uh, and you know, it's the same when you have like high volume applications. Your Dropbox is synchronizing, your time machine is backing up, your email is downloading, uh, yeah. And then you're on the meeting on the third floor, but your office is on the ninth floor and they didn't route you back to the right connection point.
So you're trying to access your access points six floors above. Yeah. You're just, he's just making excuses so he could work from home.
Come on. Um, speaking of home though, an interesting thing that came out of this project I'm doing with my HOA is the average house has more than 30 IP addresses right now. 30 connect, 30, 30 connected devices.
You think about it, You know, I mean, US nerds, well, especially with the IOT space, um, IOT is causing a rapid proliferation. 'cause a lot of these devices are using IP networks now. And, um, and that's actually one of the benefits of some of these things, you know, matter and thread and ZigBee and Z-Wave and all those things because they're not on your wifi network.
Yeah. We're seeing a, a huge proliferation. 4 gigahertz wifi, which is increasingly crowded.
4 gigahertz is usually 30, 40, even 50%, which means that basically only about half that bandwidth is even available because there are so many devices on that space. You know, on on that point, I, I was configuring a router in the clubhouse of the, of the HOA and, um, it's a six E router, and for the first time there were three networks. 4, the five and the six.
Yep. Yeah. And six E, that's another benefit of six E is opening up that six gigahertz wifi because it's, uh, you know, there's a lot less contention, a lot faster too.
Six E is great If you have a device that can support it. Yep. Which I have.
There you go. All right. Hey, let's take a break here.
We're gonna come back and Bonnie has an Echo Insights report on AI carbon footprint. Yes. Alright.
You're watching Textron Gang. Join Cruise Con Virtual on May 22nd, 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation here from our keynote speaker, Admiral Michael S. Rogers, former director of the National Security Agency, and an outstanding lineup of industry experts as they navigate emerging threats.
The core principles of crisis management and the evolution of CISO leadership. Register now for free. Welcome back to the Textron Gang.
Well, there's a lot of Talk about AI's carbon footprint. So a carbon accounting firm called Greenley based in Paris. I've actually interviewed them before they came out with, uh, new research, kind of breaking down the carbon footprint of ai.
Not just the training, which we talk a lot about, but the queries everyday use. And they had some interesting findings. I took a closer look at their findings and their research in this video.
AI's carbon cost doesn't stop at training. Every prompt, every task fuels a growing footprint, and it's accelerating fast. That's the conclusion of a new study from Carbon accounting firm greenly, which shows that emissions accumulate from development to deployments.
Building a model like GPT-3 can emit as much carbon dioxide as 112 gas powered cars do in a year. And that's just the beginning. Envision endless queries used billions of times, it all adds up.
Greenleaf's research also shows that not all AI tasks are created equal. 05 kilograms a staggering 60 fold difference. The gap widens further with added complexity.
Supporting additional languages, for instance, typically requires separate rounds of training, compounding the carbon footprint with every expansion. Fortunately though, the study does point to tangible ways to reduce AI's impact, such as training, less often, reusing models, improving hardware and data centers, plus tapping into renewable energy. Combine that with efficient code and emissions could fall sharply.
Reducing AI's carbon footprint isn't about choosing between training and usage. It's about optimizing both. Well, as I mentioned, Greenly had some suggestions for reducing the carbon footprint of a IU, such as training on 70%, uh, use of the model.
That was one of the things that they had listed. And many others like leaning into renewable energy, which is something that we've been talking about for a while that all of big tech is doing. But it was an interesting report because it wasn't just from a regular large research firm, it was from people that are actually doing the carbon accounting for, uh, these types of organizations.
Yeah. You know, look, I'm a big believer in reducing carbon footprint, so I don't want this to be taken the wrong way, but I think we'll reduce the carbon footprint footprint when it's economically, um, incentivized to reduce our carbon footprint. So rather than saying do this to reduce your carbon footprint, we could say, do this to reduce the cost of your compute.
I think at least in today's world, it's it's a better selling point than it is. Do it for the right reasons. Reduce your carbon footprint for Regulation in the case of GreenLake, 'cause they're working with a lot of European green, right?
That's true. Yeah. Eu Yeah.
So at the risk of, you know, confirming, and Alan might have been right about something if you were looking over at, uh, open compute project, I think two weeks ago now, Google, Microsoft, and, uh, AWS, they were all over there talking about ways to build more energy efficient data centers. And they had like whole new approaches where they're pulling out the, uh, the electrical conduits. There's gonna be in a separate cabinet from the compute.
They had all kinds of interesting designs that would be essentially more energy efficient. It might take four or five years to get there in terms of redesigning data centers. But it was interesting that there was a lot of work in this area.
So maybe we will get to the point where we are more efficient in the consumption of the energy to drive these AI models. And then the other thing I would just point out is, um, you know, the folks over at OpenAI we're reminding everybody that you should be rude to your AI model and not type thank you all the time. 'cause it sucks up energy.
No problem. That's good point. You Know, with regard to the video, what I found interesting or a couple things.
One, the comparison of what it takes, uh, energy-wise to produce images versus text. Uh, in the inference side, not even the model side. Uh, the other thing I think is really interesting, uh, didn't get, uh, pointed out because it wasn't directed to any one particular model provider was the impact of deep seq once again on the industry, right?
Because what they recommended, or what Bonnie said was recommended about the reuse of models. I mean, this is Deeps Seq 1 0 1, right? It's like that's a, I mean, they actually now can put themselves in yet another camp, which is with, with a green AI camp, right?
Because we did exactly what Greenley is recommending with regard to how to produce a model and make it available in a economical and, uh, also, uh, ESG efficient manner, right? So really interesting that it, uh, it, it wasn't the place for it to get mentioned, but in another report of similar ilk, you would probably hear deep seek getting mentioned again for its, uh, innovation. But, but Isn't that the way of developing markets and developing technology is as you, as they develop, you bring in efficiencies you would hope.
I mean, if, if there's a reason to, right? I mean, why does, why did automobile manufacturers stop creating, you know, uh, babe from Supernatural, right? The, uh, the, because you know, where are the muscle cars?
The muscle cars are today, right? Not, uh, ecologically friendly, so to speak. Uh, and, uh, you know, they, they become a hobbyists, uh, in invention, but not really practical for every day.
Now, when did that happen? When we hit peak oil, when the cost of fuel and the cost to manufacture gasoline reached a certain point, it became, you know, and then all, and there was some support at one time in this country for, you know, not producing a larger carbon footprint. Of course, now we're probably reversing that because you know, what the heck billionaires run the planet.
But, you know, you're, your analogy is a smart one, I think, because, you know, if you look at cars, I'm a car nerd. Um, one of the reasons I think that we've gotten so much more energy efficient as well is because the technology has improved to such an extent. I was looking at, uh, a recent, uh, just a mainstream car model that a normal person would buy.
3 liter, three cylinder turbo engine. 3 liter, three cylinder turbo powered SUV, they would think I was crazy. But the truth is, the technology has gotten so incredibly good that you can deliver 32 miles per gallon from the Buick, whatever it was.
And, um, that can be a perfectly satisfactory car from somebody who doesn't know anything or care anything about cars. And I think that that's kind of the analogy for deep seeq, right? The deeps seeq was able to basically do the same thing with a lot less.
And if it's good enough, then nobody cares about having a V eight anymore because it's good enough. But to Alan's point about, uh, cost as well, I think one of the challenges, one of the biggest problems with AI right now is that effectively the cost is zero because these things are so incredibly subsidized by people who want to see AI succeed. And so you have these companies, um, raking in VC money and using all that money to build these models and to deploy these systems.
And, and, and they never ever have to stop and say, wait a second, we're using how much power? If that costs me how much dollars? They don't care about the dollars.
If you've got a billion dollars in VC investment, who do you what? You know, what are you gonna do? You're gonna fret about a few watts.
But, But I worry about it. But again, this is the natural way of things. This is the natural way of things.
They will start carrying, the VCs will start carrying the VCs. I mean, it's the market at work. They'll start rewarding companies that are doing it more efficiently, Especially when they have those, um, you know, conflicts with the local power companies and things like that.
And that gets into the news and that's, you Know, yeah, no, it, you know, positive. Look, I re I've said this before. I remember interviewing the two CEOs of two widely successful, no early on no SQL databases.
And I said, there's no sql, Stanford, no security. He said, we'll have security. When our customers demand, we have security.
AI will become efficient when customers and investors demand, it's become more efficient. Well, it actually may be, again, the laws of physics that forced them to do so. Here, there is a cap on how much energy you can actually suck, right?
And, uh, and without nuclear reactors now, you know, as a widely available source of energy, um, you can, I mean, shoot, uh, if I was Texas, if I were a company, I would not look at going near Texas with my, with my data center, right? Because the last two years winner, they've lost power for how much, how long? But yet they building, you know, uh, Amanda, our managing editor says that San Angelo, Texas is on its way to becoming, you know, the data center capital of the world.
My my youngest son's out in Abilene, Texas, they're building huge data center out there, but they're using wind energy because I was gonna say, they're not on the, they're not on The Texas grid. No. In tech.
Well, the biggest, fastest growing energy in Texas is not oil or gas. It's wind and solar in spite of what the root and tootin cowboys may want to tell you. So, Which makes perfect sense.
'cause it's hot, it's sunny, it's dry, and, and It's windy out, and it's plenty out on the planes. It's wide open. So, I mean, you go out to Abilene, Texas, you see wind turbines as far as the eye could see.
And, um, it'll be interesting. And I, I, I'm not counting out nuclear either, jp. I, I think this may be a catalyst to, to revisit that.
And, and you know, we, Steven, we've discussed it on our show before. There's, there's new generations, there's, there's mini ones, the thorium, there's all different kinds of technologies we could bring to bear here. I don't think that, I don't think the fat lady is sung yet on that one.
So it was fantastic. It takes up space. That's the only downside to it, is the amount of real estate it requires, but it, I mean, it can generate entire cities' worth of energy.
Sure. You know, I saw an ad the other day, someone came out now I think what they were Korea from Korea, transparent solar panels. Mm.
You could have every building become selfsustaining with that. I didn't watch the video to, to find out if it was powering the train or not, but they were putting solar panels in between the tracks on trains and, uh, yeah. And they're putting 'em above, uh, parking lots in, in, in France above canals and rivers.
Um, all sorts of incredible ideas. Um, yeah, I don't think solar is the end all be all, but I think that it's just such a promising technology. And, and I agree with you.
I mean, I'm gonna shock you, Alan. I do agree that, that Nuclear, wait a second way. I nuclear you both agree with me in one show.
Wow. I know, I know you're gonna, you're not gonna invite me back. No.
I'm wondering if something's gonna fall on me or something. All right. Must have had a good night's sleep.
Anyway, Bonnie, thanks for a great episode on that. As usual, with all of Bonnie's, uh, videos, they are at Echo Tech, echo Tech insights, and you can get them yes on text, TV text, that's right. Or our text drum tv OTT channel.
If you have nothing to do, you wanna watch that laying in bed at night? How about it? Um, but I think that's gonna call a wrap on today's text.
Strong gang, thank you for watching. Steven, thanks for a great report in participating. Jp, my friend, always a pleasure seeing you.
Hopefully maybe this week in Orlando, Mike, we'll be in touch. Bonnie, thank you. Thank you.
Remember, we've got a full Textron TV lineup immediately following this, so stay tuned for that. And as Steven mentioned, if that mobility field day review, uh, wet your whistle, you can go check them out on Textron tv or the OTT app right now. Until tomorrow, this Allen Schmo for Textron Gang.
We're outta here. Hey everyone, it's Alan Shimmel and welcome here to another Techstrong TV interview. Happy to back on our show, Varun Badir.
Varun is the CEO and co-founder for Indoor Labs. Varun, it's great to see you again. How's everything Alan?
Everything's great moving a thousand miles an hour, but that's what we love to Do as, as are we all it seems, right? Yes. And where have you been lately?
Have you, well, you're in RSA or, Uh, we were at RSA, uh, luckily I came out bug free from RSA, so recovery was more, uh, mental recovery and just, uh, uh, less, less a physical, uh, recovery. You know, a lot of people that got sick as, as ends up being the case. But, uh, yeah, I, I did, I caught a nasty cold out there and I had to do a telehealth and ah, medicine up and everything else.
But, um, it's what happens when you got 40,000 people in one area. No, yeah, it's gonna happen. Yes.
What, what'd you think of this year's show over all Overrun? Look, uh, Alan, every year there's a theme and everybody, every vendor is talking about that. It's no surprise this year it was, uh, AI washing everywhere.
Um, and, you know, I don't think it was surprising or shocking to anybody, but I think it was a great conference. Uh, it's always great to have that many concentration of security folks within a one mile radius. And, you know, the conversations you have are, are deep and broad and, uh, you know, these, these are multi-year relationships that go a long way.
Look for me, this was year number 23 in RSA. Wow. It's a long, it's a lot of RSAs, man.
I had a great time though. Anyway, hey, Varun, you, you've been, you know, I say 23 years at RSA give people a sense of your journey, not just at RSA, but you know Sure. In in security in general and stuff.
Yeah, I've been in security for almost 20 years now. Uh, you know, first four years where as a practitioner in the last 16 have been building companies, uh, to solve problems that I saw firsthand. com.
Took my learnings from there to build cloud security companies, uh, one of which was Ru Lock, one of the creators of the cloud security posture management category, sold that to PA Alto Networks, built Prisma Cloud, had a great one there. And then in 2021, my team personally got hit by a number of software supply chain incidents, SolarWinds being one, code, cov being another one. And that kind of took me down a, a deep learning curve of, uh, how software is developed, or frankly, I shouldn't even call it, developed how software is assembled, Assembled.
And, you know, that took us down to creating Indoor labs, which has really been about revolutionizing application security in, in the software development lifecycle. Because the number one problem is the, the what I call the developer productivity tax on engineers. Engineers wanna ship code security tooling is always slowing them down.
And we've wanted to kind of break that barrier and solve it. Well, and happy to report that, you know, we're seeing tremendous success in doing that. Absolutely.
It is. com for 12, 13 years now. And, um, background in security, one, one of the things we've seen come is the rise of platform engineering, right?
To help developer, you know, developers shouldn't have to develop their own platform. And when it comes to security, every developer wants to have secure code, quality code, they need help, they need, you know, but they don't necessarily, the security tools for security people are not the tools that developers are looking for to stick with the Star Wars theme here, right? I mean, they, they want stuff that's more geared to them.
And, and, and it comes out, you know, and, and it works in the environments they work in. You guys over at Indoor Labs and, and we're gonna get into Indoor Labs as, I guess we'll weave it in as we speak here, but you guys recently announced a partnership with GitHub to make it easier for developers. Tell us about it.
Yeah, so we've been working for several years now with GitHub. And, and as you know, like GitHub is eight where 80% of the world's code lives. Um, and, and a lot of their focus has been how do you make security a native experience?
Just like you have bugs and issues. How does security just be an extension to that? So developers don't have to do unnatural things outside of their workflow and go to different security dashboards and A SDM dashboards and try to figure out what is important and how they fix things.
So the idea was for GitHub, if security can be a native experience to developers, things would get fixed a lot faster with very little pain. And we agree with that. And so with the philosophical alignment that the two companies had, we brought very complimentary technologies together.
GitHub has, uh, amazing capabilities for secrets detection and prevention of secrets and code. And then they have great first party code scanning tool in a code ql. All of these things are packaged and sold as GitHub Advanced Security.
But the key part that Endor Labs brings into that conversation is software supply chain security. 80 to 90% of the code is not written by your developers as all of this open source code comes in. How do you vet it?
How do you vet all the models you're bringing in from hugging face and deploying ad hoc in your applications? So for us, all of this has been focused on how do we complement each other with GitHub's powers on securing the first party code and indoors kind of leading capabilities and finding and fixing problems in all of the open source code and now AI generated code, which we'll talk about also. 'cause as you know, you know, AI doesn't write novel code.
It's all written and trained on open source software. So it's just giving you more datis open source software, which are either equally good or equally bad. Depends if you wanna look at glass half full, well, You know what they say crap in is crap out.
Right? And, and that's right. That's Right.
It's only as good as guard Rail you give it. Yeah. So we provide the guardrails and natively both of these products are integrated to give developers an experience, not just to find and report problems, but to actually bring the fixes to them.
And that Alan is a really fundamentally different approach that GitHub and Indoor Labs bring together to the market is where most of the application security testing tools just report problems. And then you send them by Jira tickets to your developers, and it lives in a backlog for months and years. We're just bringing the fixes to them in their workflow, whether it's the copilot, whether it's any other id, they're using whether's in the pull request workflow, but it's completely native.
The developers will never see a different security product experience outside of Got it. Got it. So if they're using copilot, you know, it's funny, we did a thing at RSA we do every year the dev, the DevSecOps Connect event Monday at Moscon Center.
And we, we had an amazing panel. We, it was a full day, but one of the panels we did had the CISO of, uh, open ai, CISO of Anthropic, security Tech lead for Llama and the CISO of Jfr, along with this woman Sol Ro. She's written a lot of books on AI and former AWS and, and stuff like that.
They said something that really resonated with me. The current state of AI is, it's not a pilot, it's a co-pilot, right? We don't expect it to drive the plane or fly the plane.
We expect it to help us fly the plane. And to me, that's very much your mission for developers. You're not writing the code for them, you're not assembling the code for them.
You are helping them do their code. And, and that, you know, in my mind, that's the, that's the proper mission, right? That's the proper place for, for this AI kind of, uh, assistance.
But how do you work within copilot, right? Without stepping on each other or stuff like that? Yeah, it's a great question.
So we essentially become a pair programmer inside of Cursor and Copilot and all of these other ideas. So what's happening essentially is a developer is interacting with the, with these tools to produce software. And we are in there, uh, basically being the pair programmer that's bringing the security lens.
Like imagine an enterprise. If every developer of yours could have a security engineer sitting next to them working together, you just wouldn't have a lot of these problems as depth in the first place. That's what it works like.
So developers asking copilot and cursor to write some code, it gives some code and or is reviewing and inspecting that as it's coming in and saying, listen, what you produce has these problems. Can you please rewrite it with these criteria? We basically have it rewrite and interact and a couple minutes later and or cur circuit copilot and your developer have now produced code that is, that functionally works and is secure, and this happens well before even a pull request is generated.
Love it. Look, there's only about, what, 30 million something GitHub users out there, 40 million Now, um, how can they get their hands on this indoor labs plug? Not, I don't know if plugin's the right word, but, you know, companion, copilot, whatever you want to call it.
com and kind of kick, kick off from there. Also in the marketplace, you can have our GitHub action and our GitHub apps are available. Um, it is a subscription service, so, uh, you know, depending on the number of developers in your enterprise, we can, we can kinda set you up.
But that's the best way to get going. And I always say the, the proof of this is in seeing it in action with your repos. So we're always happy to set you up with an evaluation, connecting into your own code repositories.
Love it. I love it. If you don't mind, Varun, I'd like to turn to something else.
You are getting two for one here today, folks out here, uh, Varun, you got Indoor Labs also. I partnered with like eight other security companies on something called Open gre. Yeah.
What, what's that one about? Yeah, so, you know, it's a good, it's a good segue, right? We've been talking about GitHub and we've been talking about how great GitHub's native capabilities are for, uh, first party code security with static code analysis and such.
But look, not, not a hundred percent of the world is on GitHub or not a hundred percent of the world is ready to pay for a commercial product for security. And so, uh, you know, for, for many, many years, uh, out there in the market has been a, an open source community edition product from a company called crep. The engine is called a CREP engine that essentially allows you to write GRE rules very easily, um, to kind of look for functional issues, security issues and such, right?
It's a, it's basically like a linting tool and you know, there's also a lot of community behind that, but unfortunately for commercial reasons, as a business, EM rep decided to make some changes to their licenses, remove some functionality from the Open Source edition, really forcing people to go think about paying for their, their commercial edition. And we fundamentally believe a grab pool like that is extremely important to keep independent and continue harnessing the community that has trusted it, believed in, and worked around it to scan your custom first party code. And so essentially, um, when in December, SEM rep announced these changes that are licensed, we worked with several other companies to create this independent, essentially an independent framework where no single company now owns the future of this critical open source project for it.
So open grab and essentially the nine companies that we are, have come together and funded full dime engineers to bring back in the functionality that SEM rep took away and continue to expand on that functionality to arguably make it even better than the commercial variant of that engine. And the idea is that we would over time, handout over open grab to a foundation so it continues in its long-term existence, independent without the risk of a single company kind of changing licensing or limiting its use as it is. And where Open Grab comes in is, it's a great LinkedIn tool and a grab tool for, for developers to, um, kind of write rules and customize finding, finding problems in first party code.
Again, like I said, not everybody can, uh, be paying for a GitHub advanced security license. Not everybody lives in GitHub. And so I think it's a great tool for, uh, for the community.
Yeah. First of all, look, anytime you can get eight, nine security companies to gather rally behind a particular open source tool, static code analysis, you know that, that coopetition, whatever you want to call it, right? You, you, I mean, the potential is there to make this a game changing piece of a game changing tool in the quiver of, of AppSec professionals.
So I, I commend you, I commend the other companies involved for, for doing this. It's a great thing. Where can people go get open, grab, It's all, it's a community product.
So, so, you know, you just go, go, go Google, Google search for open grab, it's available, the roadmap is published and you'll, you'll be really impressed. Follow open grab on LinkedIn, I would say, because the velocity at which we are introducing new innovative features is incredible. I haven't seen that before, uh, in many, many, many open source projects that I've, I've and I paid attention to.
And primarily because the nine of us companies are literally Alan writing checks and funding full-time engineers to create this. So this is no longer a best effort of, Hey, community, Not a hobby. It's not anyone's, you know what?
Look, Varun, I've been an entrepreneur 30 plus years. A lesson I learned pretty early on is if it's no one's job, it doesn't get done. It's gotta be someone's job.
Hobbies are nice, passion is great, but it's gotta be, if you want something done, someone's gotta have that job. And so the fact that you're doing it is that's why you're getting the results. You are.
Someone is getting paid to do this and, and open, I love open source. I'm a huge supporter, but the day of the, you know, Richard, Dr. Richard Stallman, and we're doing this for the love of, of software and freedom, people need to get paid.
That's how things get done. Yes. dev, we've, we've put in the values, the mission, the long-term focus of this project, and then you can obviously interact with our development team on, on x, on LinkedIn, on Reddit, wherever you choose to be.
Uh, we are, we are there. And we're really excited for the community, uh, just to use it. You know, we've, we've got, uh, early feedback from people that have moved from SEM rep to open rep that have seen 30% faster scanning.
Um, really, so it's just pretty significant, uh, improvements. And so we're, we're excited to embrace the community as they start moving over. Very cool.
And, you know, with nine companies involved, you don't have to be worried about locking in and, and all of that other stuff. It's great. Thank you.
Thank you guys for doing that. Hey, so I could, you know, so what are you doing in your spare time? It's a busy World.
It's a, it is a busy world besides running around twin boys. We're almost turning five later this month. Um, good for you, man.
I, I think that right now, the biggest software revolution is ahead of us, and it's happening in front of our eyes, which is every enterprise is adopting an AI assistant or co-pilot to write tool. The implications of that are pretty significant. You will have way more lines of code, you will have way more bugs.
So quality engineering, platform engineering, security, engineering all become important, except all these hundreds of millions and billions of dollars are being poured from venture capitalists to create these copilots and create this problem of a lot more code. We need to retool the, the, the kind of defenders of this software, the people that are in charge to make sure this software is shipped securely with confidence to have their set of AI tools to do their jobs at a much faster, more effective pace. So for us, we think there's a entirely new set of problems that emerge, right?
Traditionally in security, we always worry about CVEs vulnerabilities known, and C Ws a lot of companies were addressing the architectural questions and design questions by doing design reviews, thread modeling, security champions programs, security office hours, all of that falls apart, uh, with the velocity of code changes that are coming. And so we announced at RSA, uh, or just before r say, a new, new product and entirely new suite of products that are actually doing security code reviews with ai. So we built a multi-agent framework.
The idea was with Endor for the last four years, we had been building this very deep moat of, um, knowledge on open source software deeper than any other company on the planet. You know, we knew billions of risk factors on every open source projects kind of existence over time. We had the call graphs, we'd done deep program analysis and inspection of the code.
We had built an entire database of that software. So now, when AI starts generating code for you, that's not novel. That's variations of open source.
We have the best insights to be able to secure it. And so Azure developers are writing this code and checking it in. We are now doing code reviews with AI agents that are looking at understanding not just the CD and the tactical stuff, but really architectural problems, design flaws in your application.
Did somebody change a session timeout from four hours to eight hours on an application? Unintentionally? Okay, somebody paying attention to that.
Are they aware that that's something that shouldn't happen? Or they're introducing a secret, a new secret manager, but that's not your enterprise standard of how you store secrets. Who's paying attention to that?
Or somebody's introducing a new API and not putting in the right authentication authorization per your superior coding guidelines. Who's paying attention to that? These are not known vulnerabilities.
These are design flaws and architectural flaws that are getting introduced with AI generating code and invite coders. And we have now built this multi-agent platform that is reviewing every pull request, threat modeling, every pull request, understanding the intentionality of the developer versus the reality of how it affects the architecture, and essentially automating that entire process of code and architectural reviews and bread modeling. I love it.
Did we, did we mention indoor labs? URL? I don't remember it saying it.
Varun. Yeah, it's really simple. com.
Uh, come check us out. There's a lot there. Uh, there's just, I will also say, unlike many companies, most of our technical blogs are written by our engineers.
So, uh, um, you know, we have certainly a marketing team like everybody else does, but our content is very, um, original and authentic by engineers for engineers. And there's one more thing Alan I'll mention is we have a community for application security professionals called Lean AppSec. com, uh, which is really love it, just like open rep.
We're kind of creating this community for application security teams that are typically overworked, understaffed, to come get together as a community, talk about their problems, get recommendations from each other, and we're often doing virtual events and talks that the community is doing, we're facilitating. So, you know, if you're interested in application security, definitely check it out. Fantastic.
Farrun. Hey, man, I think we covered everything. I, I didn't think, you know, we didn't think we'd get it all, but we did continued success.
Keep up the great work. Come back and visit us soon. Varun Badis, CEO co-founder and or labs here on Techstrong tv.
We'll take a break. We'll be back. Hey, everyone.
We're live back here, live at RSA conference today, closing out our Wednesday coverage, uh, day three of RSA. Um, our next guest is from Qualys, a company you all are familiar. I assume all of you are familiar.
We covered them enough here. Um, her name is April Lenhart. And April, first of all, welcome to Tech Drunk tv.
I know it's your first time here with us. It's great to have you on. Great to be here.
You certainly look very different than most other Qualys executives. We've, we've interviewed over the years, so it's fantastic to see you. Um, April, why don't we start with what your present position is at Qualys, and if you wouldn't mind, tell us a kinda little bit of your career path, you know, what your story is.
Yeah, Absolutely. So I'm a principal product manager at Qualys, and my, the main thing I focus on is cyber threat intelligence. So at Qualys, I'm going to be working on really bringing cyber threat intelligence to the fore, working across all of our different products, seeing where we already have cyber threat intelligence and really bringing that out into a new product.
In my past, I've worked as an Intel analyst, and from there moved into cybersecurity, working as a product manager at all different companies each time, really working on kind of nation state level actors and looking at how to bring out cyber threat intelligence across the industry. When you were an Intel analyst, I assume it was for the government, some sort of agency or something, or private Company As a contractor, yeah. And doing kind of the same thing, uh, geopolitical threat analysis.
Um, I was the person who would walk into a metro and say, what is a physical threat and vulnerability analysis look like? So when I then transitioned over to cybersecurity, it was like, oh, hey, this is what red teaming is, right? Yeah.
So I knew it from the physical side and then got to do it on the cyber side. Excellent. What a great story.
And then you're also an adjunct professor at George Washington. Is it Georgetown or Georgetown? George Washington.
George Georgetown. Yeah, Georgetown. George Washington has a great pre-law program.
George Washington University, but so does Georgetown too, actually. Uh, but that's fantastic. And what do you teach there?
It's at the, uh, security studies program, and it's called Cyber Threat Intelligence and National Security. The goal is for students who don't have a really technical software engineering background or computer security background who want to know more about, again, those nation state level actors, those apps, they get to dive into the world of cyber threat intelligence. I love that.
April, I want, if you don't mind, I want to, as I said, most of our audience knows Qualys, worldwide leaders started really out in vulnerability management and vulnerability detection, and now vulnerability remediation, uh, threat intelligence. Uh, there's, there's many facets to the Quali Qualys product line at this point. But let's, let's talk a little bit about cyber threat intelligence.
Now, Qualys, I think they had a research team, a cyber research team for a bunch of years. Yes. But in the last two, three years, they really tried to turn up the threat intelligence knob because they want to integrate it into the, the dashboard view right?
Of, of Quas QBR and everything. Um, as part of your mission, what are you gonna do to the existing offering that raises that bar? So I love that you brought up the analyst team.
The threat research unit at Qualys is over a hundred analysts. It's a very, very big team, and my goal is to really accentuate the work that they're already doing and really just bring it to the forefront so people can really get a better sense of what our analysts are doing on a day-to-day basis and really contextualize that information. So we're going to be able to see really quickly with any vulnerability or with any misconfiguration, um, what are the industries involved?
What are the threat actors involved? What are the locations, uh, both from the victimology side and from the attacker side, really bringing all of that information so it's really quickly and easily, uh, easily accessible. Absolutely.
And I think that is the mission for Qualys, right? It's 'cause I, I remember speaking to them, whether it's Qualys own cyber risk, uh, threat intelligence feed, or even harnessing and plugging in the third party feeds. It's, um, it's a valuable addition to the kinda risk dashboard, if you will, that they're, they're, um, developing.
The other thing I wanted to mention is, you know, we were at the qualis QSC, I wanna say it was in Austin this summer, maybe it was right before summer. And, um, they, you know, they introduced this whole rock Yes. A concept of a rock Yeah.
Outta sock a rock. Yeah. And again, that's another area where the threat intel right, gets, that's how you know, it, it, it makes its way to, to operators, right?
Yeah. Who can use and act on that. Absolutely.
So the risk operations center of rock is the idea that big enterprise threat management, you take all of your intelligence, you take all of your unified asset management, and now on top of that, you're also going to bring in essentially the probability of how does it affect me? How does it affect my business? How does it affect not just kind of overall the industry, but how does it take my business into account?
So you're looking at across all of the different assets that you have as a company, and you're then saying, how does that specific, how does those specific assets that I have, how do those relate to the major CVEs that we're seeing? Um, so you can really stack rank and identify what's important to me, what do I need to patch if I don't, what are the major consequences? And you can even associate it by, you know, specific industries or, sorry, uh, specific, um, parts of your business.
And then within those parts of the business say, okay, if I don't take this specific CVE into consideration, how much is that going to potentially cost me? So it's really think of a risk operations center as not just saying, this is asset management, but also here is how I contextualize it for my own business, which is really taking it a step forward. Got it.
Um, now I, I realize you, you've only been on a few months and there's a lot of things, a lot of plans, a lot of offerings that are still coming together, right, for sure. That aren't public yet. Um, but what do you think to date has been your biggest kind of impact on the, you know, cyber risk intelligence or threat management for, for the Qualys product?
I like to think that right now it's bringing in that contextualization piece. Yeah. So again, just coming in as a, a subject matter expert, being able to lend the lens of this is what, as an analyst, this is what I would want to see.
So very similar to how a rock, uh, brings in that extra layer of contextualization, I also want to come in and to say, this is how it would be relevant to the greater industry. Got it. If you don't mind, I want to turn to RSA this week.
Uh, you know, as usual, RSA is chock full of security people, right? And a lot of security, 600 plus sessions, all kinds of things going on. You were on a panel I hear Monday.
Yes. Tell us about that if you can. Well, honestly, the best part was that since we were the very first session of the very first day, we had first mover advantage.
So anything we talked about was just going to be repeated by everyone else for the rest of the week. That's how these things go. And that was ideal.
So our panel was on AI and GRC governing risk compliance, and it talked about everything from kind of our outlook on AI as a whole to getting a little bit more into GRC where the industry is now, and where we see it going in the future. Um, so tell us about it. I mean, 'cause I mean, look, certainly AI is the talk of this conference as it is the talk of everything in tech today, you know, but one of the things we've been talking about here for the last two, three days is, no doubt it has the potential to be huge, but how real is it, how much of an impact is it making today in, in the field of, of, of governance risk and compliance?
GRC? How big is AI today? Not what it could be, but today For sure, there are a lot of ways that it's already made a major impact in terms of being able to scale up way past what otherwise a human would be able to do, right?
So there's a lot that AI has already been able to contribute to as far as adding in metrics, again, adding in contextualization. However, there are definite, uh, limits to what humans are comfortable with and what companies are comfortable with deploying. For example, we still haven't gotten to the point where you can have age agentic ai.
That is where we're completely comfortable saying, you know, set all of these rules and, um, completely act on your own free will to determine if you see any new threats, block everything. Uh, essentially, like think of like a, a completely automated SOAR where there is no human involved in the process. We have not yet gotten to the stage where we're comfortable with a human completely being removed.
We still want there to be that emergency stop button. So it's fair to say that AI has really significantly contributed to having us grow in this industry, but we aren't completely there. We haven't reached that pinnacle of saying, yeah, we can just set it and forget it now.
Right. Um, well, And, and I don't know if that's a worthy goal, to tell you the truth, maybe may just maybe the, the future of ai, at least near term, short term, is just to enhance the human, not to replace the human right. And I, I, you know, I think that's a good lesson for all of us to look at.
You know, a lot of CEOs and, you know, executives get up there and say, we could cut head count. I could get rid of all my intern junior coders, I could get less security professionals. No, that's not really what it's about.
I think not today anyway. I, I think today it's more about how can I make more my people more effective? Sure.
How can I enhance our security posture that, and it's, and it's AI in conjunction with a human helping a human. I heard someone say at an event we put on Monday, and it really struck me at this point in the day, game AI is a co-pilot, not a pilot. Yes.
I think that's a very apt way to put it. Yep. Uh, AI is a really great tool for augmenting what you already have as a way for thinking of unique solutions to a problem.
If you are able to then correct it, it's not a great way of teaching new solutions to a problem when you don't already see pathways to get there. So, in the same way, um, within GRC, it is a very good way of saying, you know, I already know how to get to the end. Show me different ways to get to that same end.
It's not a good way of saying, show me, show me brand new things where I don't already know what to do. So, Got it. Very similar.
April, I want to wish you success in this new role, fairly new role at Qualys. We'll be watching to see what comes out on threat intelligence. I actually, I'll say it here, we're actually gonna be at the next, uh, QSE Qualis Security Conference, which I think is in Houston.
And we'll be, you know, shooting live there. And we'll catch up there. Thank you so much for having me on today.
I really appreciate it. Nice Meeting you. Okay, great to meet you.
April, Len Hand, uh, Qualis, I, I forgot your title. I apologize. Principal product manager, Principal product manager, Quas here on Tech Drunk tv.
We're gonna take a break. We'll be back. We've got a few more interviews to do today before we wrap up.
Day three, you're watching Textron tv. Hi, everyone, I'm Guy Berger, analyst at FU and Group, and I'm pleased on this text run TV episode to introduce Gary Thornhill. He's the CEO and founder of Pop-Up Mainframe, and we're gonna be talking to him today about pop-up and about Mainframe.
So, hi Gary. Welcome. Hi.
Thanks for having me. As my name is Gary Thornhill. I am the CEO and founder of Pop-Up Mainframe.
And interestingly, we created Popup Mainframe originally in a, through a DevOps consultancy, actually solving directly customer issues around, uh, addressing the shortage of dev test environments. So that's, so that's our popup mainframe was founded, um, addressing a, uh, a particular client problem. And then it wasn't just them that need this, it's, it, it's, there's, there's an issue around the speed of, uh, mainframe change.
So pop-up mainframe accelerates mainframe change, and it does it more cost efficiently than ever by providing mainframe delivery teams with an immediately available fully functioning mainframe. Our product revolutionizes mainframe delivery by removing the most common place of challenges, which is the bottlenecks caused by the shortage of environments, access issues, and quite often too many teams and too much bureaucracy. So we, we, we hit those, uh, directly head on.
So you're providing mainstream environments as a service and hosted in Azure. Correct. And I know you had a product announcement, we're gonna get to that, but, but it, it's popup in the sense of it, you know, with an Azure account, takes you a few minutes and you have a, a mainframe environment, a a Z systems mainframe environment available to you.
Is that right? Yes, and it, but it's not just Azure. We can actually run in any cloud.
So any X 86. Yeah. So any X 86 architecture, so that can be on-prem, it can be Linux based, windows based, and in any, any hyperscaler, we can pop up a mainframe in less than 10 minutes and they can be logging onto their very own, um, mainframe, albeit is running on Linux, not on or not on Z.
Okay. But it's, it's, it's compatible. It's a, you were talking DevOps.
Um, I know that in the mainframe world, um, uh, for many years now, um, there has been an increase in, you know, uh, the cloud integrations or cloud-like behavior, um, for the mainframe, even as it continues to fulfill its core mission of some of the most, um, intense mission critical, um, key applications and, and, and data processing, um, uh, scenarios going on in the world right now. Right. Um, what, what would you say is the, is the current state of the mainframe like today as far as that progress has gone and what sort of uses it's being put to today?
Because it's, it remains a vibrant market. I mean, yes, and interestingly enough, I think the, the mainframe market and, and IBM is selling mainframes with, with 10 digit growth every year now. Um, so it, it is never been more in demand for, its, it, its processing and reliability, but think Reliability is a big thing.
Yeah. Yeah, it is. It's really the only system that has that really true hot failover because of the parallel ciplex, which has been there for years.
Yeah. But one, what, what is, um, what is the challenge is, is to deliver at speed on the mainframe because because of the reliability it does, it does to be a bit of a shrine with the way that cha the way that change happens on it. So if you think about, think about the modern enterprise, you've got so many different platforms, and they're all interlinked, I think, I think the challenge is for organizations is that the mainframe delivery can be slower and more expensive than other areas of the organization.
And, and that is, uh, a big challenge for CIOs because they want the reliability and, and the processing, particularly as AI is, you know, is, is is very rapidly coming on us. Um, but, you know, things still have to happen at pace. Um, and you can't afford to, for projects to take months and months, it's gonna be done quickly with quality.
There's a continuing reliability, and it's not just amongst the biggest firms in finance. There's a continuing reliability in government, actually a number of sectors on the mainframe. But what you're highlighting is that because of the nature of the mainframe, the benefits you get have come with a fair number of controls and operational issues that create those challenges of, you know, moving fast.
Is that, is that a fair characterization? At least, you know, up to this point? Yeah, I mean, I think, I think you, you summed it up well, I, I mean, obviously, uh, the organization wants to have its cake and eat it, right?
It wants to have that reliability and speed, but why can't change be done quicker and, and respond immediately to market demands? Why, why shouldn't a, a mainframe, why can't, why can't you make change in a mainframe? Like you can make, um, in the web or applications?
You should, you should better do it if the process is there. And this is where the mainframe to me, needs to mo to modernize. It needs to modernize more around the process and how it's used just as much as the technology needs to advance Well, being able to spin up the equivalent of a mainframe in any X 86 compatible cloud service providers environment, which is what you described at the beginning.
That sounds like a promising way to address that challenge. But, but, but first, um, I know you just, uh, conducted a market study on this. Um, so why don't you tell us about that?
'cause that seemed to provide some interesting insights into this whole mainframe question. Yeah. Yes, it was, it, it, it was, um, very insightful, and obviously we don't need to tell you guys, but the most important opinion about any market is from the market itself.
And we wanted to learn more about some of the specific challenges facing mainframe delivery teams today. That survey is just finished and we're just publishing the re results. Now, What was the most interesting data you got back?
Um, Paul pointed to, let's go through the whole survey, but Yeah, Yeah, no, no. That, that, that would, that would take us a while. So, funny enough, what, and what we've talked about is what, what was reassuring was the absolute overwhelming loyalty to the mainframe that the clients had.
And also there's, there's very much a demand to use, um, different processes like the Linux, IFL. Um, but there were a number of, of, uh, challenges raised by most respondents. Um, a good example was that 96% said they had challenges developing and testing on the mainframe.
And a third of all responders also said they were in critical need of more mainframe environments. You were talking earlier, you said that pop-up mainframe sort of came out of a, uh, a DevOps engagement that you had. So this is a really interesting contrast to me.
I mean, DevOps is certainly about, you know, uh, rapid builds, uh, rapid promotion, continuous development, you know, that sort of thing. What often gets forgotten is the ops side of it on and operating mainframes is, uh, is, is a thing of its own really important critical element of it. Um, so, so when you're talking about dev and test on a mainframe, and almost all of the survey respondents said that they were, they're, they're challenged in this, and a significant number of them said they're, they're limited by the number of mainframe environments they have.
Um, that really seems to play into this idea of cloud-based mainframe, so to speak, being something valuable provided it's operated correctly. Provided it's maintained correctly. Yeah.
Yeah. Uh, you know, just, just to elaborate on that, I think traditionally, I guess where you have, you know, a very high performing, um, piece of hardware, that hardware has a cost. So environments are generally, um, set in stone, and when there's, and when you need another environment, you are tempted to use an existing one.
So you start getting an interwoven ness of applications and different projects happening. Yeah. And What, what tends to happen is, is that you find, you, you, you find environmental bugs and things don't work.
So if you look at the distributed world, you'll see that typically in with a cloud, for example, if you, if you've got applications running these year, when you want a new one to do something new, you spin it up, do your work, take it down. That's not really a concept that is, is that happens in mainframe, but with popup mainframe, we can do that spin up. So it's about spinning these environments up very quickly, moving the application on there.
And we can do that using, taking it out git and modern ways of doing that. You then do your work in testing. You've got this agility around the popup mainframe where you can forward and rewind it, copy it to another one.
You get all this agility, so you are working analogous to in a distributed world. Um, but it, it is, it is, uh, using a fully functioning mainframe and that, so that's really the power of the solution. Is it, is it running on IFL at that point?
No. So, so we, we originally started with the, what, what, what was the popup mainframe, which ran on X 86 and, but now the X 86 version is known as popup mainframe on X, and now we've got a popup mainframe on Z. And That's the announcement, that's the announcement you just made.
Okay. So yeah, the X and Z, so X is running on X 86, and so is Z running on IFL? Yeah, Z runs on the, the IFL processor on the physical mainframe.
And you can also run it on a Linux one box as well, which is a specific, uh, Linux server, and you can run that as well. And all of this is only development and test you can own. You can never run production workload on a popup mainframe.
So IBM will, will be pleased that I say that out loud to everybody. Okay. So, so, uh, I feel like we, we zipped right past the lead of this interview because a big reason why we're doing this interview is that announcement.
Um, so you now have a popup mainframe, which originated as a way to pop up a mainframe environment for dev test, uh, or dev test, let's say on, on X 86 based cloud. Yeah. As of now, today on, you've launched the Z version, which is actually running on IFL, if not LinuxONE.
That's cool. So you have to, in my mind, my, my, my mind, and I'm always thinking like lifecycle and in this case, and he would mention DevOps many times, this is a way of, of these ways exist, but this is like a more agile way of using the DevOps workflows or mainframe development along with your other application development, right? That's how I'm looking at it.
So I'm seeing this nice progression. There's sandboxing, there's dev test, there's these ways to do mainframe development quickly prior to production use, which would be on, you know, a physical mainframe. Yeah.
Is that correct? Yeah. So I think we've, we gave you X we've given you Z, but the thing we missed out is the Y um, You mean YWHY, don't you?
Yes, Yes, yes. Okay. That's a good one.
That's I, sorry, go ahead. So why yes, why? I just gave why, and maybe I'm wrong.
What's the why? So the reason why we, we also moved to z to, to, sorry, I, I slipped then z um, was because the thing about a popup mainframe, it uses hardware emulation. So it's, you are running exactly the same code base, um, on a popup mainframe.
Then you, as you are on a, on a real physical mainframe, okay, you can match it to the, in IBM terms, it's called A PTF, which is exact fix to a particular subsystem, more what have you. Um, but some of the community and clients do not want any of their mainframe out running on X 86. So the, the mainframe is the mainframe, and in some organizations, no data should ever leave the mainframe.
So for whatever reason, so they would not, they would not buy a popup mainframe on X. So we bought out, um, popup mainframe on Z is to emulate the physical mainframe, but also on the mainframe. So you get, and, and, and here the client can have, can have both.
Their mainframe still stays on the mainframe, but they get all the benefits of the virtual environments. They can, um, take a mainframe, save it to disk, bring it up later, um, put another copy into another, onto another processor for whatever reason. Um, and so, and there's also a scenario where clients can have both X and Z.
So you could, you could build up your goal copy on your IFL, and then you could send copies of that to a hyperscaler cloud. So you could have almost like lpar, fully functional mult multiple users on these large tests, on these powerful test environments. But you could spin up copies for other teams doing smaller bits of work or in feature teams in the cloud.
So you could have you, and you can really benefit from these lower cost, um, dev test environments. So, so what would you say to people who, uh, who are really, like, been doing this sort of work for years just just on the hardware, right? What would you say to them if, if they express concern to you about security or, or, or, you know, uh, um, management, uh, data protection compliance.
Yeah, like that sort of thing. Because I think that although, you know, CIOs certainly and CTOs and IT shops have embraced the cloud, especially in sort of hybrid form as the capabilities have gotten better, I think, um, and that includes the mainstream folks. I think, um, there's a certain, um, there's a certain, uh, uh, guarded nature about using the cloud for these, these workloads even in, um, pre-production environments, mostly 'cause of, of, of data control.
So what would you say to that? Yeah, so it's, it's an interesting question a lot and a lot of it is perception. Um, I think with, with, with the cloud.
So, you know, you, when you look at a pipe popup mainframe, you're securing it a number of wa of ways. You are securing it. You can secure it exactly the same as your physical mainframe with, with the same tooling and the underlying security as, as well as, you know, infrastructure, all the firewalls and what have you.
So you could, you can, you can actually secure it at two levels. You can secure it around the cloud security and Linux security, and then you are securing the mainframe as well, running on Linux. So you can get multiple levels, uh, of security on that and probably make it even more secure than, than say, a physical mainframe, because you, you've got, as I said, multiple levels of security, one on top of each other.
So, you know, I, again, I think quite, quite often there is decisions around security are quite often that, that are patterns more so than what does the organization need? And okay, we've got a way of doing something different. What is the best way of securing it?
So you can look at it differently. Um, but you, you know, there are some organizations that just say, you know, that's not secure having a, a popup running on, on the cloud for, for whatever reason. And, and quite often it's not, it's not being explored.
It's just a, a blanket statement. Uh, and I think, I still think just Gary, I still think there's a fair amount of, uh, misunderstanding of, of security Yes. In the cloud.
Uh, yes. There, there, there have been issues and, and I, I wouldn't want to name names here, but certain of the biggest cloud providers have, um, maybe enabled capabilities and services, but not forced them or required them. So you see continued breaches.
But what I'm leading up to is the fact that that truly some of the best security systems in the world, and again, I'm not gonna name names, have been implemented, are available and in place in these cloud environments. Yeah. And, and with the expertise certainly and, and the right configuration work, um, you know, you, you are quite able to achieve better security than, than, than in most cases you do natively in your own shop 'cause of what's available.
And I don't think that's fully understood even today. It sounds like, um, you might be taking advantage of a lot of those capabilities. Is that, is that true?
Yeah, I mean, you're exactly right. So, you know, we, we, what we can say to clients is, is, is that you can, um, you can run your popup in a variety of different ways, ways you can pretty much secure it exactly the way that you secure your physical mainframe today, the exact security controls. But, you know, would be that, would that be the right thing to do?
Um, and you can run pop up mainframes, depending, so what, you know, the, the first thing that we always do is make sure that the data is, is compliant. So we have lots of masking strategies just about user data itself, and then you're looking at access on the popup mainframe. But you can, you can use all the modern software and approaches for secure securing on the mainframe, and then you can put a cloud S-S-L-V-P-N layer, you know, and you can just keep on adding to this.
And of course, always the weakest point of any security, uh, is someone's own access itself. And that's not going away, is it? Yeah.
So, but we always, when, when, when we start working with clients, we always try and understand what the, what they, you know, what are they doing today, and we can help them improve that, um, nine times out of 10, um, by adding in these different layers. Um, so, so, so that the way that they use it is, is secure. Um, but um, it's, it's having, it's involving the right experts, uh, at all levels, um, to meet, to meet the requirements.
Well, yeah. And you're, you're addressing that question, um, with your, with your product and with your, your announcements of today. So that's this nice, um, dual option of the X and the, the Z additions.
Um, one more emulation, the other one, you know, direct IFL or, or, or LinuxONE on bolts of end for, uh, a quicker, more responsive way to work towards the pull production environment that's gonna be on your mainframe or mainframes. Um, I think everybody should check that out. Um, who, um, is interested in, um, and working on mainframes today?
Um, the, the study, uh, actually, if I remember right, the survey that you did, um, uh, we might be discussing in more depth on a webinar coming up, um, also a Textron uh, in, um, in, in a month or so, I think, um, June 18th. Uh, so, um, I would encourage everyone also to look out for that. Um, uh, Gary, is there, is there any other notes and bits you might wanna mention about the announcement today or about that study to, you know, keep everybody, uh, excited and interested?
The webinar will show that the, the mainframe is a fanta fantastic production engine. So whatever apps you're building, whatever XS box you're on, whatever data you're using, I imagine there are some bottlenecks a day you wish weren't there. And we can show technicians, PMs, and change managers how mainframe dev tests can be approached differently.
We're here to discuss those issues and present an approach which we think will be a game changer for mainframe delivery teams. But in order, in order to move with the times you've got these new technologies, but it's about how we improve delivering change on the mainframe. Um, there's a continuous need and desire to modernize not just what the business process the mainframe runs, but how quickly they can be built and, and, and you can get both benefits, um, from X and z.
I mean, certainly with, with z what is interesting, so that, that, and just of your previous point, they're both, they're both emulation, but, um, on x, on X 86, um, you don't get the full benefits of the mainframe processor. So you are emulating the way the CPU and the disc io, whereas with ZE, the, those are native, Those are Direct process, yes, it goes direct native. Um, but the IO is emulated.
So it, it does work slightly differently, but it's more closer to, uh, the real physical mainframe and, and performance is significantly, um, improved. Um, but they both help clients align with how, you know, how, how you make change in the distributed world and splitting things up and down on demand. And it also has a very important, using popup mainframe, um, massively, um, improves your, the sustainability side of things because Yeah, I was just thinking about efficiency when you were talking about that.
Yeah, go on. Yeah, so I mean, it's one of, one of our clients literally saved half of its Azure costs and, and reduced its carbon footprint by half by just switching off for 12 hours a day when they weren't being used. So that's not a concept you have on a physical mainframe.
And there's always things running not normal. Yeah. But you can just, um, with a popup mainframe, two things.
First of all, you can switch it off when you're not using it. Um, so it doesn't sit there and just, just, um, just using electricity. And the second thing is, is that because we have this unique Ford and Rewind capability, which we'll touch upon is that, um, you can take a checkpoint at any point in time, um, and come back to that.
So just the efficiency gain you get from not having lots of bodies, um, making changes and clearing down logs and resetting tables, DB two tables or other things. Instead, one person can go into, uh, a EY, take a rewind, and then you're ready to repeat a cycle of testing. Now that is a huge efficiency gain.
Um, and mainframe is famously, uh, renowned for being the most sustainable platform anyway. 'cause you've got so many processes running on one piece of tin add pop-up mainframe to the equation where you can reduce the amount of headcount required to do, to do work and at speed has a huge environmental, um, saving for it. And I think that's very important, particularly the advent of ai, which is, um, gobbling up so many resources.
Um, we've gotta always have a, have an eye on, you know, how, how we can be sustainable by the use of it. Well, I look forward to hearing more about that then. Hopefully I'll be on that webinar myself.
This is a fascinating topic and definitely an area of interest and pursuit for many kinds of enterprises that around the world running some of the most important applications, uh, being run right now globally. Uh, so Gary, thank you for joining us. Um, thank you for joining me.
Um, thank you for talking about pop-up mainframes and what's going on in the mainframe market, uh, and mainframe development right now. I'm Guy courier analyst with the FU group and it's been my pleasure to present this to you and I'll see you next time. Hey everyone, we're back here live at RSA conference.
It's Wednesday morning, things are starting to kick up here. We've already had a full day. Of course, we recorded our Textron gang at about eight o'clock this morning.
Then we did a new segment special here for RSA called the Analyst A with uh, three FU analysts and talking about their vibe, not vibe, coding, their vibe from RSA conference. My next guest needs no introduction to our audience here. He is one of our good friends.
One of the, you know, I don't wanna embarrass him, but he's one of the founders of the AppSec movement, right. Early on with Opsis, everything else. Uh, he is also a co-founder, right?
No, you're not. You're C-T-O-C-T-O And founder at Contrast and founder of Contrast Security. Yep.
My friend Jeff Williams. I knew you were co-founder, but I always say CEO and it's Ct. Right?
Right. That's why I wanted to make sure I got it right. Jeff.
CEO's a terrible job. CT CTOs a much better job. Job.
CTO's the job you want. I, I agree with you. Um, but you know what, young kids out there don't know that everyone's gotta find out for themselves, I guess.
Yep. You live and learn. Anyway, Jeff, it's great to see you here.
Good to see you too. What Is this? Maybe seven, eight RSAs maybe more?
Yeah, I've, I've done Yeah, more like probably, Well, I'm saying that you and I have interview Together. Yes. Oh, I've become an organization since 2002.
Right. So Yeah, you're similar kind of thing. Um, you know what, Jeff, let's start off though.
Maybe there are some people out here don't know contrast security. Just quickly. Yeah.
If you don't mind. Yeah. So We're an application security company.
Uh, application security risk is accelerating really quickly now, particularly with vibe coding and, and other things. Mm-hmm. And we take a runtime approach to application security.
So we actually watch the code run, give you real details on what's really exploitable, who's attacking you, what libraries are actually in use. Like it's all measured directly from a running application. So it's real, it's not theoretical results.
Right. And, uh, we do that to keep you safe and more importantly your customers and children safe. Absolutely.
Well, no kidding With children Safe. You know, Jeff, one of the interesting things about contrast, and I've told this to people before and I got this spiel down now, is for much of the AppSec industry you focus on the AppSec industry focuses on the security of the application before the event horizon of deployment. Yes.
Right? And that's like sort of a black hole, right? That deployment event horizon.
Yeah. And all of our, and if we could say all of our AppSec focuses left of that horizon. That's Right.
Traditionally, Traditionally. And, and for good reason, it's supposedly faster, cheaper, more efficient. Well, We should talk about that.
Absolutely. But recently, I know Contrast, what was the movie Interstellar? Remember that movie?
Yeah. You've gone through the event Horizon. That's Right.
The three Event Horizon. We Come out the other side and, and one of the few AppSec vendors that actually have a story about real runtime application security. Right.
Uh, and to me that's what sets you apart. I don't know, as a CTO you have a better handle on this than me, but as an observer, that's what sets it apart. Well, you're exactly right.
Traditionally, we've put a lot of bets down on helping developers write perfect code. Yep. But I, I don't know, do you feel like developers writing perfectly Secure?
I don't think there is such a thing as perfect code is the problem. Yes. And, and it's, I think it's Like a holy grail and It's a moving target.
Yeah. 'cause stuff changes. Um, It's like saying, I'm never gonna publish something that doesn't have vulnerabilities And look, so we've put a lot of bets on that.
Yeah. And it, frankly, it's not delivering. Right.
Right. Like most companies have massive backlogs of vulnerabilities that they're not triaging that that whole approach to the problem just doesn't really work. Mm-hmm.
And so we had, uh, the insight to say, Hey, you know what? In production we can see everything. It's not, you know, in, in development you see pieces of applications.
You see one repo of 20, you see, uh, the libraries, you see the source code, you see the APIs all separately. But in production, they're all assembled together. You analyze the whole thing at once and you can see exactly where it's being attacked.
Exactly. Where it's vulnerable. And you can help companies focus on the, you know, the few percentage points of issues that are real, the ones that have crossed the event horizon that are actually being attacked in production.
Mm-hmm. Those kinds of problems. That's where you wanna spend your, your very limited critical AppSec resources on fixing those problems.
So even though it seems counterintuitive to focus on security to the right, 'cause people like the idea of shifting left. Right. The problem is it just hasn't worked.
It's, it's backfired. com. 'cause I think people realize that you, when you over shift left, what are you saying Your developers, your security guy, I'm not saying developers raise their hand and say, man, do I like to write insecure code?
No. Developer says that. But you don't have developers raising their hand and say, I'm your security guy.
That's Also true. That's who they are. Also true.
And so that I think the whole rise of platform engineering is recognizing we can't ask developers to build their own secure platform in addition to coding their apps. Someone's gotta do it. Yeah.
So the way runtime security works is, is very much like other kinds of detection and response. Mm-hmm. Like EDR and CDR.
Sure. And the one thing to realize those technologies don't stop application layer attacks, right? Yeah.
They see stuff in the kernel layer in the cloud or whatever, but there's a gap, the application layer. Yes. And so into your platform, you install a DR and it instruments the actual running applications and watches it as it runs.
That's how you detect things with full context. And so after that, it, it works just like the rest of the XDR ecosystem. Sure.
You, you know, telemetry gets collected. It, there's a dashboard, but it also goes into your sim and you can correlate it with the rest of your events and so on. But it's, it's a very natural part of operations.
Agreed. It's just missing. Agreed.
Let me ask you a question. You know, I was at Q con in London last month. Observability.
Yeah. Everything's observability. It is.
How does the a DR play in the observability, this new universe of observability? Yeah. It's a very similar concept.
In fact, we call it security observability in a lot of contexts. Fair enough. And observability is interesting.
It's started to the left of boom, like in, in development. Mm-hmm. And companies like New Relic and AppDynamics and so on, you'd monitor development.
And then they realized, Hey, what are we, what are we measuring test systems with? You know, not real data, not real users, not real load. And they're like, well this doesn't, it's not realistic 'cause they didn't have the right context.
So those tools moved into production and they measure real reality in production. Yep. Uh, and that's the same transformation that AppSec is going through.
Yeah. That's, if you measured in test environments, you don't have enough context, you don't have real users, you don't have real threats, you don't have real anything. Yep.
And you get all these theoretical findings. So when you move into production, that's when you're measuring reality and you can focus on what matters. And that's, that's what we're helping Companies do.
You're walking in that same footsteps Here. Exactly. Right.
It's, it's the logical route. It's how stuff evolves. So in our never ending quest for the single plane of glass, be envision a future where security observability and, you know, call it mainstream observability or whatever, can be in the same interface, could be in this, the same platform.
I could imagine that, although I think it's more likely in the short term that we'll see it as part of, uh, CAP and Sure. And sim kinds of integrations that, that data, they're already collecting security telemetry and building a security graph. And our data, you know, we have a graph.
It fits into the other graph. Like that's, that's how that works. Observability is a little bit more of a jump 'cause it's different users, right.
I think today, but ultimately, if we achieve the vision of DevSecOps, that we'll break down those silos and everybody will be working off one model of reality. We call it a digital twin. And, and that's, it's come a long way now too, especially with ai.
It Has. So we're building a digital twin of your application layer. Not one app at a time, but the whole thing.
So That, wait, this is new to me from you now. Yeah, let's start over here. Yeah.
So talk to me. So Imagine you've, you're a big complex enterprise. You've got hundreds of thousands of applications all connected to each other, APIs containers.
Right? We're all confusing it. So when you deploy contrast, you can deploy it across that infrastructure.
Like we got a Kubernetes operator. You just push it out. It's part of platform engineering, right?
Absolutely. You push it out, then the telemetry starts coming in and we take all this telemetry that's coming from all these apps saying, you know, things like, what's the attack surface? Where are the vulnerabilities?
Where are the attacks? Where are the assets? All that's coming together.
And we're building a digital twin. It's, we call it the contrast graph, excuse me. And it's, it's a model of how your application layer works.
It's a lot like the wiz graph except for it's not infrastructure. We're talking about another layer of abstraction, all the, how the application layer works. And with that, you get a lot of benefit.
You can put vulnerabilities in context and say like, oh, well I understand this vulnerabilities in this app, which has this blast radius. And you can really get good risk rating. And you can use that data not just for like vulnerabilities and attacks, but you can use it to feed into your threat modeling process, your Sure.
Pen testing process. Now I'm, I'm a big believer in the digital twinning. I, I think one of the nice things about all the AI buzz that goes on and, and our ability now to kind of get our hands around bigger, uh, infrastructure's, bigger pictures.
Well, that's what we had to do, is it's not easy. Our old, you know, two years ago contrast used, uh, our telemetry flowed into a SQL database. Right.
And that's limited. It doesn't work. Right.
So we moved to a modern streaming data architecture. It's Kafka, it's graph databases. And we're, we've built a massively scalable data collection Platform that's, you can do that.
It's, It's because our news from Splunk Oh, so obviously, Yes. And he came in and said, Hey, you know this, we need to collect more data, not less. And so we've just been en enhancing our telemetry building a a, a awesome Model.
Well, no, once you're able to get your head around or your hands around all that telemetry, now you start applying the AI and stuff. Exactly. When you start seeing insights that you, you, you just couldn't see before.
Runtime security and AI go together like peanut butter and jelly. No doubt. Because runtime is is real.
It's measured directly from running apps. It's not theoretical stuff. It's not No, I tons of false positives.
So yeah, they, they go together really well. Love it. All right.
This camera's on you. Right? Okay.
Tell them how they get, how did they go get this today? You Uh, it's, it's easy. I mean, you can go to our website, you can learn a little more.
com. Right. Okay.
And, uh, there's stuff you can try. If you want to give it a, give it a spin, um, we're happy to come in and do a POV with you. But the, the deployment process is easy.
You get our installer, you push it out to your, your containers or your workloads, wherever they are. Uh, we don't really care whether it's on-prem or in the cloud or whatever, whether it's APIs or applications. Right.
We support all of that. And, uh, almost immediately the telemetry will start flowing. Uh, particularly if you deploy in production.
And that's really where I think you should Yeah. Put it. Then you're gonna see you, you'll get amazing visibility into what's happening.
I will tell you, you're probably in for some surprises. Like there's probably a lot more attacks going on on your application than you, you thought. Yep.
And attackers are probably reaching vulnerabilities that you didn't think that they were able to reach. That's scary. You may find some log for shell that you didn't know about.
By the way, we All, it seems it's all out there still, Jeff. Good stuff. Really good.
I'm really, you know, it's not often I get to hear new stuff like, hey, Application security has, has not been innovating as fast as don't Know it. Uh, you know, with, with the boom coming from AI development, I mean, if you're, if you're Producing gotta, you get our ducks and going 50% more code or a hundred percent more code, I, I don't gotta find to figure abec team is gonna double. So you need technologies to help you scale into that double.
We Don't have enough abec team as it is for what we've Exactly. Three years ago. Anyway.
Hey man, this is great. I love it. You're doing a it a great job, Jeff.
Appreciate man, you're the best. Alright. Jeff Williams, contrast security.
Go check out what he was talking about here because this is the kind of stuff you are going to need. Not three years from now, not two years from now. Now we need it now.
Go check it out. We're live at RSA conference. We'll be back in a minute.
Hey guys, thanks for the throw. We're here with Marco Paladino, who's CTO for Kong, and we're talking about event driven architectures, APIs, and maybe the need for some gateways to simplify this whole thing. Marco, welcome to the show.
Yeah, thanks for having me. As long as I can remember, event-driven applications were among the hardest to build. They're difficult, they require a lot of challenge, uh, and yet in the modern world, just about everything we do has been driven.
Now it seems like we have, uh, processes that everybody wants to run in real time versus batch. And so the nature of the applications that we're building is changing. Is there some way to approach this now that would make it simpler for people to kind of build and deploy and manage event driven architectures?
Uh, there sure, there sure is. Uh, like you just said, events are a critical component, a critical, uh, protocol that organizations are using to build modern applications. You know, of course not everything that we do, it is necessarily service to service.
That's, you know, what, traditionally we think of microservices. Usually we think of service to service connectivity. Some of this connectivity happens asynchronously through events.
So we're publishing events to topics. We're consuming these events. Uh, this is great if we have large batch processing.
If we are lots of data that we need to process at scale, it is great. If we want to pick up events where we left off in case our services are down, it can happen with high availability. So events truly, truly are a very important part on how we're building applications in 2025 and beyond.
And of course, like every other type of connectivity that we're building, whether it's single connectivity, whether it's service mesh, microservices, connectivity, whether it's AI connectivity or not, events also are part of the picture. And so at COG, we believe that events also should not be left outside of the platform that we use to govern our traffic, to secure it, to observe it, uh, to manage it. And we should instead bring events on top of that platform so that the organization has both the ability to control that flow of traffic, apply the right level of security, the right level of governance, but also developers, uh, can start sending and consuming events in a much quicker way without having to build the underlying infrastructure to process these at scale.
So, uh, we believe that, uh, events therefore have an opportunity to be simplified, uh, and there is an opportunity to also allow us to build applications that are built on events a lot faster. So now today you guys launched the your own event gateway. Uh, we've had multiple types of gateways in the past.
Most people are familiar with API Gateways. What exactly is an event gateway and how does it kind of take that concept and make it simpler for everybody else to kinda access? 'cause I feel like maybe it's a higher level of abstraction for events.
Well, the event Gateway effectively gives us the right level of infrastructure to be able to, uh, enforce security observability of events that are in flight from one application to another. And it also gives us the opportunity to implement capabilities like protocol mediation in such a way that we can use events in more and more places. Uh, even the ones that perhaps cannot send a, an event directly by the need to do that only after, uh, providing the right level of authentication, the right level of authorization, only then they can send those events.
Well, we're giving that infrastructure in such a way that events come out of the box within the organization as yet another tool set that they can use. But they don't have to worry about that security, that access tier level of control, uh, about that protocol mediation around that observability, because that effectively comes out of the box from the underlying infrastructure. You know, you may know Kong because, you know, Congo of course started many years ago.
We spoke many years ago, and, you know, we started with our API management solution. But then, you know, as we looked at how to support different types of connectivities, API management is one way to do it. But then there is also service meshes.
We also have announced an AI gateway, uh, recently, and then of course, events are the last missing piece of the overall picture. So in our pursuit of managing all connectivity for the enterprise, of course events where one big remaining component that we didn't support until now, where now all also events, uh, we can give them that unified control plan we're giving to every other API or microservice that we process in the organization. Now, events as well have that level of governance, security, observability, and quite frankly, ease of consumption and ease of publishing in any topic that's backed by technologies like Apache Kafka, for example.
As we think it through for a minute, is there gonna be like one super API gateway or will there be multiple events, gateways, API gateways and multiple different things that I need to kinda to deploy alongside each other and kind of, uh, create something that feels like a fabric? Well, the key is to unify and centralize the governance because if we decentralize the governance, we are adding complexity. We're not reducing complexity.
So centralized governance, but federated run times for managing events, for managing APIs that we can deploy across each team, across each application, across, across each, uh, cloud vendor that we may be using in such a way that although the governance, it is centralized, how we actually process the events or the APIs or the AI traffic that can be federated and decentralized so that we can bring it very close to the applications. Now, that would be very hard to do without the right technology in place. And this is where our platform connect comes into play.
Connect is that unified control plane that allows the organization to create virtual control planes where we can provision event gateways, API gateways, service meshes and AI gateways for our teams. They can also self-service their policies so that the platform team doesn't become the bottleneck, but whatever they're doing, it's still going to report back to this unified control plane, which becomes the source of truth of all of the API connectivity that we're generating across the board. And when you think about API connectivity events, ai, APIs, and microservices, I mean, this is really the foundation that allows us to create new products faster that allows us to expand into new markets that allows us to onboard new partners quicker.
And so effectively owning the these new strategic asset, which is the connectivity that we generate, including events coming with this announcement, while that is going to allow us to build an innovation factory on the business on top of our business, that's going to be much better and more powerful than it used to be before when everything was decentralized and we had no visibility whatsoever on what the developers were doing. So historically, event driven applications were a small percentage of the total number of applications that people were running. Are they now gonna be a much larger percentage?
And, uh, will they eclipse batch oriented or will they be deployed alongside each other? How will this all play out? I believe that they're going to be deployed alongside each other.
I think that we're going to be using different types of connectivity. And organizations are doing this today, by the way. I mean, the organizations are already, if you will look at the top Fortune 500 stock, global 5,000, they have an incredible amount of event traffic that's flying from one place to another within their systems.
And so is it going to be the solution to every connectivity problem? Of course not. It is a another tool in our toolbox where for certain use cases, events, especially at scale, especially when we have batch processing, especially when we want to make sure that we don't miss those events in case our services go down, um, you know, events can be a better technology solution for this type of, uh, high usage, high volume use cases.
Now, of course, events are going to be working alongside all the other types of connectivity that we have service to service, of course, uh, as well as the connectivity that we're now generating using AI models, which is also this new breed of connectivity that now we're infusing in pretty much every business process and application that the organization is creating. You know, all of these have their own place in a modern enterprise architecture that we're developing in 2025 and beyond. So events very important part of a broader picture that also includes other connectivity types and which is why it's important to make sure that we don't treat each one of these different connectivity types, um, as being fundamentally different worlds.
They are all part of one piece, and that is how we manage connectivity across the organization. It's not, um, a siloed concern. It is a different types of connectivity under one concern.
What makes it possible to do all this now? Because we've been kind of talking about these issues for a while. So what's changed that I can now create an event gateway?
Well, I think, uh, that what's changing, it's not just, uh, the products that are getting more mature, but it's also, um, the mindset of the organizations is a little bit changing right now. You see, for many years, organizations have been delegating, uh, to each individual team the choice on how they are going to be managing their connectivity. And then over time what happened was a sprawl of APIs, duplicate APIs.
Many organizations don't even know what these APIs are doing. Every time we need to build a new use case, instead of treating APIs a product that we curate and we make better over time, we keep building new APIs for, you know, specific point to point integrations that we want to build or point to point partnerships that we're developing and so on. And so over time, fast forward, you know, to these days we have like thousands of APIs.
Nobody knows what they're doing, nobody knows why they're needed. Nobody understands why this, the organization has built three or four different, I don't know, KYC systems, you know, for different applications instead of working on one and making sure that they can use that across all of their applications. And what has changed is that these, in these overall increase of complexity over time reached a breaking point.
I mean, organizations, they cannot build fast enough. They cannot ship fast enough because fundamentally they don't know what APIs they can use to assemble into new products, into new customer experience that they want to deliver. And likewise, today, we use one HR system to manage all the employees in the company, or we use one endpoint security system to manage all the, you know, uh, endpoint security across the employees.
Why are we using 50 different technology software, you know, for technologies, for managing our connectivity at the software level? It makes no sense. And so what Kong is doing is unifying this connectivity under one umbrella that is our connect platform that yes, allows us to run gateways and now events and AI and service meshes.
But it allows us to do that by owning this connectivity layer, which arguably it's one of the most important strategic asset that the organization has because it doesn't matter what we build and what we produce, what matters is how we can use it and to use it, we need an API or we need an event. And this is exactly what our vision is. Now with Event Gateway, we're expanding our platform offering to introduce support for events as well.
And with this new capability, we can basically cover 90% of the overall enterprise software connectivity that's being generated across all the applications, all the use cases, whether they are in the cloud on Kubernetes or on virtual machines. Kong can see and manage and govern the traffic. Now, In your point about application connectivity, um, it's never been clear to me at least like who's in charge of that?
Is it the development team or the networking team or somebody else? And now we're hearing about the rise of these platform engineering teams and maybe they'll take responsibility for this. Well, That's a great question you're asking because if you ask many organizations out there who owns this, many will tell you, oh, we don't really know.
Uh, you see, uh, historically this has been owned by the developer teams, but the application teams, you know, are building products, they're building customer experiences. They'll build the connectivity once and then forget about it. And, uh, when there are problems with security, when there are problems with observability, you know, typically these teams are not prepared to address them.
So over time, we have been seeing, you know, we're working with more than, uh, 800, 900 enterprise customers, you know, the largest organization in the world in pretty much any vertical insurance, banking, uh, transportation, retail. And what we're seeing is that the leaders of the organization are taking ownership back of the connectivity and putting it into the platform team, the, the platform team that exposes this type of connectivity as a core service to the other teams in such a way that the other teams don't have to go build infrastructure anymore. They can start using infrastructure and build their products, which allows them to now focus on generating the product outcomes they're building instead of reinventing the wheel with connectivity over and over again.
Now, one of the biggest challenges that prevented this from happening is the fact that typically the platform team would become a bottleneck to every request, which is why it is very important that the teams themselves are being given some degree of self-service to self-serve, their connectivity policies to self-serve how they want their events to be managed, yet at the same time being able to do that without escaping the guardrails, the governance guardrails that the organization can enforce stop down using the platform. And so that combination of, uh, that fine balance between yes, we want them to self serve, but self-serve within these boundaries, it is, uh, what allows them to now fully take ownership back of these critical asset, which happens to be API connectivity. So what's your best advice to folks then about how to approach this whole thing?
'cause um, there's a lot of complexity and there's a lot of organizational issues. How do I get started? Well, the number one, uh, step is understanding, you know, what is that we're trying to do?
And if what we are trying to do is to fully own this connectivity layer, which will allow the organization to move faster, then we need to provide a solution that happens to cover all bases when it comes to connectivity. And of course, events, it is a very important part of it, but it's not just events, it's events, it's AI traffic, API traffic, and being able to then provision that to the teams in such a way that the teams can then slowly migrate to a fully, uh, managed, let's say, solution that the platform team has offered to them, uh, without having to, uh, essentially, you know, manage that connectivity ad hoc every time they're building a new API or they're pushing data to a new event topic. And so certainly there is going to be a transfer of responsibilities, but ultimately what this achieves is a reduction of complexity because now we have one place to manage our connectivity, and we have also an increase of developer efficiency because now developers are doing one less thing that it's very critical, but they shouldn't be doing to begin with.
It's a mistake that they're doing infrastructure work to begin with. They should be building products and applications, uh, and innovate on in that area, whereas the infrastructure is being given to them, almost like electricity always on, always running the platform team makes sure that that elec electricity keeps, uh, being funneled to them, but they don't need to worry about it. So I think that what this requires is the right technology, and this is what Kong, uh, uh, is building as built and it's providing to our customers, but also a shift of mindset where we really want to be committed into making sure the teams are really focused on innovating and not focused on building crosscutting requirements over and over again.
And for that, it is a cultural shift, Guys, you heard it here. There's more applications and types of things in that distributed environment than ever, but the key to it all is finding a way to centralize the governance of it all. Hey Marco, thanks for being on the show.
Thank you. All right. And back to you guys in the studio.
Hi everyone. We're back here. Live at RSA, it's Tuesday.
Well, you know that if you're watching this live, you know, it's Tuesday. If you're not watching this live, take my word for it. We filmed it, we recorded this on Tuesday.
We don't film anything. Um, anyway, let me tell you a quick story. com.
com content March of 2014. In February of 2015, we did our very first DevOps Connect here at the RSA conference. And the idea was to bring together the, uh, security, we didn't call it cyber, the security community and the DevOps tribe.
Yep. Easier said than done. You know, in subsequent subsequent years, we started calling it Dev DevSecOps Connect.
Yep. But there wasn't DevSecOps 10 years ago. Yeah.
The closest thing I could find was something called rugged DevOps. And Rugged DevOps was kind of the term was coined, not by Patrick Dubar, of course, who did DevOps. Yep.
But Rugged DevOps came out of a tall, lanky Texan out of Austin named James Wickett. And here's James 10 years later. There you go.
There you go. And, um, what was rugged DevOps is really what we call DevSecOps. Yeah.
You know, today it was, and um, of course a lot happened in those 10 years, right? DevSecOps became a thing. James, I think back then, this was before you were working with, um, the Signal scientist folks, the signal Yeah.
Before Signal. Mm-hmm. But you were one of the organizers of of DevOps stays Austin, which was like the, for my money, the best DevOps stays in the States.
Let's, let's go, Alan, let's go, let's go. And it's next, next week. What anniversary?
How many years Is that? Yeah, this, this Thursday and Friday. So I'm, I'm flying from here.
You're you're going right there to there. How many years is DevOps Day Austin? Oh, okay.
I think we're on year 12 now. If improbably if I remember right. But right around, that's, This is my fourth day in San Francisco, so I'm sure my math may, you may not check out right now.
I'm chock full of medicine, so I'm all over the place. All right. But anyway, so I've had the pleasure of knowing James for 10 years, 10 plus years now.
And you know, in some ways, as I get older, he does it. And, but I've seen, you're very kind to say that, very kind To say it, but I've seen, I've seen his career, right. Evolve being a, an organizer of it, working for people.
Signal science has came a long way. And then founding his own company, dry Run Security, um, if you're not familiar with Dry Run Security, I'm gonna make James tell you all about it. But he's, he's having tremendous success early on as I knew he would, frankly.
Right. Because he, he just does things the right way, smart guy and, and works. Right.
He's a an example to all of you out there, James. Hey, talk to me. Hey, Alan.
Thanks for, thanks for having me on. Yeah. You know, it is funny you mentioned the rugged DevOps thing.
'cause it's like, I, I feel Yeah, sure I put the words together, but like there was the whole rugged stream going on at the time. Yes. It was the DevOps stream.
And so, you know, I, I don't know. It wasn't, it wasn't rocket science on my end. It was just like, we should connect these things.
And I, I've always loved how you're always trying to get these, these groups connected as well. Mm-hmm. Yeah.
We had a lot of like rugged DevOps DevSecOps days, just trying to like continue to, to bring that conversation, uh, even here at RSA, so. Sure. Yeah.
That's awesome. Um, but, you know, take credit for one credit's due. Yeah.
Okay. Thank you. I will.
A lot of of stuff is evolutionary not revolutionary. Yeah. And so you had this DevOps thing going on.
You had the rugged movement going on. Bringing that together was, was a eureka kind of moment. Right.
And, and look, there were others. We had Josh, if you remember Josh Corman, those first ones. That's right.
Yeah. Josh Corman was there and Gene Kim was there and Yeah. You know, John Willis and, and all of these, I mean the, the folks who, Yeah, we were all just, we were all trying to figure out how to do, how to do this.
Yeah. It's great. Um, I'm, I'm drawing the blank.
Did your LinkedIn DevSecOps course. Oh, with, with Ernest. Ernest Mueller.
Yeah. Another, A lot of the, a lot of the Austin folks, Ernest and Karthik, uh, down there doing stuff. Yep.
There's one guy we're missing. Ernest Karthik, you, who's the fourth guy? We also have, uh, PECO and Bill.
Those are, those are some of the other organizers that have been kind of in the mix down there. So Yeah. Good times.
Good group of people. But anyway, James, enough history. Okay.
Yeah. Let's talk dry run security. Okay.
Assume some of these people have never seen or heard of Dry Run. Yeah. Yeah.
Yeah. Why, why would they have, you know, dry run security? We're very new.
Okay. And, uh, um, we see it as we've developed a new way to do code security. So we call it contextual security analysis.
Um, we, we believe that pattern matching is dead. That, uh, trying to, we've been doing, uh, in like the SAST world, uh, static, uh, code analysis and, and all that space, you know, we've been doing pattern matching and a ST parsing for, for all this time. And it's really kind of generated more or less the same results.
Um, better UI in some cases, marginally better experience for people. Um, but contextual security analysis lets us, uh, uh, takes a, take a context driven approach that doesn't do pattern matching, but we're trying to find risk in the systems. So, uh, yeah.
So driving security's great. It, it's, um, we're having a lot of fun doing it. I'm doing it.
My co-founder is, uh, Ken Johnson. He ran internal security over at GitHub. Mm-hmm.
And so we, we both have, he wrote, he, and he's the original creator of Rails goat. Okay. And so we've kind of just have always been friends in the AppSec rails, Ruby on Rails.
They used to really love Ruby for some time there, so, yeah. Mm-hmm. Very cool.
Um, you know, it's an interesting time to start a security company. It is, yeah. It's always an interesting time to start a security company, but this is a particularly interesting time.
It's a heck of a time. A lot of people were saying, where's the innovation? Mm-hmm.
A lot of people were saying AI is the greatest thing to happen in security. A lot of people were saying AI is the worst thing to happen in security. Yeah.
AppSec has been kind of where a lot of the action in security is. Yeah. Pipeline security, you know, all, all the software pipeline, security, that's kinda stuff.
What, where was the passion for you, James, that said, this is what I, this is what the world needs. I could somehow make things better Yeah. By doing this.
Yeah. It came outta two streams. One, I, I really felt like, um, the AppSec, the sast world has kind of been the same.
And I, I realized like, uh, you know, I had the whole gauntlet stuff that I worked on many years ago and mm-hmm. And then just like, I care about, uh, developers having a good time with security products. And I felt like we just still really hadn't delivered on that as an organization.
And, uh, two, fortunately whenever I called my buddy Ken, and I tried to convince him to start the company with me, he had been having a really frustrating time with Code ql, uh, their internal, they, they, they acquired that product and were running a GitHub. And so he was, he was ripe to, to do something new. And we knew that, like by looking at the context of what's going on, like how the surface is changing, what kinda language and framework they're using, how the developer decided to write the thing and why they're doing it, what led to that, and how, how it's overall designed and architected, and how that application's actually gonna be used.
All that stuff really, really, really matters. And, um, and that's how you can find real meaningful risk that doesn't match, like SQL injection or cross-site scripting or all the stuff that we've been talking about as an industry for the last, you know, I don't know, it seems like 20 plus years. Absolutely.
Yeah. Absolutely. Now, you know, you, you look at all that.
So I, you know, I've been in this DevSecOps thing now for 10, 12 years. One of the things that I, you know, hindsight's always 2020, right? That's right.
That's right. That's right. Yeah.
But one of the things that, looking back I realized might have not been the smartest move we made, was really emphasizing the whole shift left thing. Mm-hmm. Right.
We're gonna shift left, we're gonna shift left some more, and when we're done there, we're gonna shift left even more than that. We're gonna go as far left as left can go. Yeah.
And I think in retrospect, thinking that developers would be able to use security tools designed by security people was a mistake. Yeah. And maybe we should have been emphasizing shift everywhere, and maybe we should have designed security tools for, excuse me, for security for developers.
Yeah. Not for security people. I, I believe that last point is the, that's a salient one because it's, I mean, the idea of shifting, it's, and, and a lot of the organizations we talked to as we're kind of building the company, and as we, we discovered, we discovered two, two key facts that, like, they felt the penalization of all those security tools being put on them.
So nobody really loved, like the, the alerts and the Christmas tree of lights that they were always given, and developers weren't having a good time with that experience. So the stuff that got shifted either got turned off or got muted or got unshifted. Um, and then we also realized that, uh, security leaders or, or engineering leaders in, in that case too, their, their code is changing constantly.
Like, um, some of our customers have five, 600 developers. Their code changes a thousand times a week. 2000 times a week.
It's, it's e easy like that, that's, that's not unreasonable for them. So now, how do you find risk whenever you have that constantly evolving and, and it's only getting faster? So when those two forces are, are joined, uh, yeah.
The tools that, that we had shifted weren't really Right. They really needed a whole new class of tooling built just for, for developers to kind of solve that, that problem. I agree.
Yeah. Yeah. I agree.
Um, there's been another sort of movement that I think is exerting a gravity pull on, on this whole orbiting thing, and that's platform engineering. Yep. Right.
We've seen it. com Yep. As a, as a result.
Yep. How do you see that playing into this whole EC ops? How does it affect dry run?
Yeah. I Think platform engineering is an interesting group. And specifically like we play in the infrastructure, well, some of the infrastructure is code that people are working on.
Um, can I tell you a story about one of our customers? Sure. We got, uh, I won't, I can't name their name, but, um, they're like a direct to consumer, uh, business.
And they got, um, we'll call it 60, 70 developers. Um, we came in there through the, uh, through the platform or the SRE team who is just trying to like, say, how do we give security tools that work? Mm-hmm.
Well, part of our product is like we, we, we ship traditional SaaS. Like we, we can, we can beat the traditional players of SaaS, but one cool thing that we can do is find risk, um, that, uh, that you can't find. And we, it's through in like traditional patterns, and we call that natural language code policies.
And for every customer, we sit down and we start out, and we will usually build them out a natural language code policy that says something simple like, is this code change? Adding sensitive data to our logs? So every time the developer's making changes, are they like, now emitting customer data or P-I-I-P-H-I or whatever to logging, you know, we've all been in the organization where it's like, you get audited and then like then, uh, somebody, um, somebody says, Hey, look, you got some whatever PII or, or some sensitive data in your logs.
And then you gotta look back for 12 months and now you got an issue, a, a report, and you gotta like, you know, have some sort of disclaimer on your audit or your compliance. And if you have a tick mark on that, um, you also get stuck in a situation where like, now you're trying to triage, like, how, how do we ever stop this from happening again? So I called up our customer, we just, just signed.
I was like, Hey, uh, how's it going? How's, how's it been? You're like, week two or week three.
He's like, that, that PII, that sensitive data logging thing hit last week. And, uh, within 24 hours, the developer I got with 'em and told 'em like, Hey, we can't do that. And they were, but they were dropping data, customer data dumps for this new like LLM like recommendation engine that they were building.
And we said, uh, uh, uh, let's get that fixed. And so we were just, we were just going through like how much that would've cost, uh, to remediate and under like, our traditional lives that we've ever handled before. It's like hundreds of hours, uh, to deal with that problem.
But if we can just deal with it in code before it, uh, gets shipped or gets shipped all the way, or redact it as soon as we can, um, you're able to, you know, do do amazing stuff there. Yeah. Absolutely.
Yeah. But you can't find that with patterns. And that's where our natural language code policies really, really gets into finding new types of risk for folks.
What I find interesting with it though, the platform engineering stuff, James, is, it's kind of like telling the developers, I know you want to build quality code. I know maybe you don't want the Christmas leak tree security thing. Yeah.
We're going to build the environment for you. Yeah. I, I think one of, again, hindsight, 20 20, 1 of the things about DevOps is we told developers, look, you got everything including building your own platform.
That's right. Right, right. Alright.
You live and learn and you adapt. Right. And you, it, that's, that's DevOps.
We iterate, we reiterate and iterate again. Yeah. Um, and it, it is an interesting thing.
I think AppSec is a, is a perfect playground for that. If or not a playground 'cause we're not playing, but a perfect, uh, use case. Yeah.
It's for that, it's natural overlap for that. Yeah. Yeah.
Now you mentioned a few times that you guys are using SAS technology, SAST for our, uh, yeah. Audience out here. That's static code analysis.
Yeah. Or it's Yeah. Static application security testing is the, the acronym.
And yeah. Now there are other kinds of tests there, das and Yep. Some other, there's proprietary kind of, everybody makes a few I Asked and stuff I asked is another One.
There's, But the, the important thing is you recently, and I didn't talk about this with you, but I, you know, I follow you on LinkedIn. Yeah, yeah, yeah, yeah. You recently, you guys recently published a study Yep.
On speed. 'cause speed is important when it comes to scanning on speed and dry runs. Yeah.
And accuracy. And accuracy. Excuse me.
Yeah. Yeah. Tell us about that.
Yeah, So we, we had, we thought, alright, we built these, this really cool platform and we really invested a lot of time building the engine. And then we, uh, created across, uh, four different languages, 26 different, uh, kind of easy to get vulnerabilities, but we wanted to just test effectiveness. And then we, uh, took some of the popular tools like Sim GRP and SonarCube Snyk, uh, code QL from GitHub and, and then ourselves.
And then we just started committing all this code in that had, uh, these problems. And, uh, we were really surprised, uh, to just, uh, at what happened is like we, because our approach is remarkably different, like we were double the effectiveness in accuracy, um, than the next, than the next category of tools. Um, and then even in that category, there's quite a bit of divergence from like, uh, who's kind of coming in, I think outta the next one in like the 40 percentile was like sim gripp, but then like some of the other ones were like in the 10% or 8% percentile.
So, and we dry run was in the 80. We, we got, I think we got an 88% on the, the scoring there. So it's a limited data set.
We have some more, um, languages and stuff we're gonna continue to release, we're really excited about. But we really wanted to show, like, as an industry, we've been really, um, we've been really hooked on the idea of static assessment being like matching patterns and parsing like code trees and looking for source and sink and stuff. But contextual security analysis that does like a more holistic look, uh, building up this code context window, like we talked about.
Um, it's way more effective. You can learn a lot more about your system. Uh, it actually speaks to developers 'cause it's giving them relevant feedback about the stuff they're actually working on.
Um, and we can tell security people like where their hotspots are, where what matters, what, you know, what, what they're seeing in their organization. So Of course, this year's show, like last year, frankly, we're hearing all about ai, agent ai. Yeah.
How's that figure into the dry run kinda strategy? Yeah. I think that, you know, we are, we have a lot of LLMs under the hood that we're using to, to do a lot of our analysis.
Each of our analyzers are tuned to look for their own specific things. Um, our natural language code policies are full ag agentic where they can go find out the real truth about a system. So instead of just saying, we think you have a vulnerability, we can go dig into the code to, to find out if that's, uh, really true.
Uh, customers love it and it's, and it's way more accurate. So that really, really helps on that. So, um, I'm, I'm excited by what, what AI is providing to our, to our industry and like what it's allowing us to do.
And, um, I think the results, it's, the results in that report kind of speak, speak to themselves of like how much more accurate we can be. Um, 'cause And that's really the key. 'cause we need, you know, going fast by in and of itself is not enough.
You need to be fast and accurate. Accurate. Yeah.
I remember, um, I think it was in London at one of Gene's DevOps Enterprise Summit. I was doing a video with John Willis and Damon Edwards. Okay.
You know, it was, it wasn't about security per se, but it was about DevOps. Okay. But fast secure, what were the three things I want to do faster?
Code Resilience. Maybe Resilience. Yeah.
And security. We can, we do want it all. Yeah.
And so having fast results that are not accurate Right. Is having no results. Yeah.
Yeah. And that, that's really The thing in our report, we kind of call that out. Or like, some of the ones that were like, out of our payloads, they only found one or two.
It's like, that's really scary. That means you could check in like legitimate, you know, problems and nobody says anything, but you do it quickly. So, you know, that's, that's, that's, I, you know, gotta watch out For that.
It's, I remember back in the day when endpoint security similar kind of thing. Yeah. Yeah.
Because let's face it, semantic McAfee, back then you installed that on your machine. It was a pig. It would slow your machine down.
Yeah. And so a lot of the AV companies were making their whole bones on, Hey, we're faster and lighter. Yeah.
But faster and lighter. That doesn't catch viruses. Wasn't a great antivirus.
That's that's right. Yeah. Yeah.
Yeah. It's the same thing here. Yeah.
James, what's the website? Okay. So if you just go to dry Run Security, um, and then right on the front page, it just says like, get the 2025 accuracy report and you click that button and, and we'll ship it to you right away.
And how about people maybe wanna try out dry run security? What's their best on-ramp? Yeah.
There's two, two options. So if you want like a self-guided tour, you can go to Dry Run Security and install the GitHub app there. Or GitLab is coming soon.
Um, or you can click, uh, I think there's a button there. This is like, talk to an AppSec expert or whatever. And we'll usually sit down with you for 5, 10, 15 minutes to make sure, uh, write a natural language code policy with you and kind of get, get people up and running, but super lightweight to get to get rolling with it.
Hey Alan. Thanks. Congratulations.
James Wicker, one of the nice guys in this business. security. Check it out.
We're live at RSA. I think we have one more coming up, so stay tuned. All right.
You are watching, listening, or however you're consuming. You could just be reading the transcript of Infrastructure Matters. Episode 81.
I'm here with my good friend Kimberly Bass, who's head of career transition, but is still beating me to joining the stream every time. Kimberly, welcome back to the show. Thank you very much.
Yeah. Um, for those of you who don't know, I've, uh, officially have gone to the, the next side of my other third, the next third of my life. Um, and I'm, I'm not working full-time with, uh, I'm not working with FU Group, but I'm still having the opportunity to participate in this Infrastructure matters, um, podcast, which is a just a great, great fun time, um, with you guys.
And I'm missing Diane. He's, he's, he's someplace we are not sure where he is today. If you know where in the world Diane is.
I know we're about to get into travel season, I'm sure SAP staff fire is coming up quickly. Yeah. And Dion is a staple for SAP Sapphire.
Wow. Uh, which, uh, usually coincides with Click Connect, which, which I'll be at the week that you're watching this program. Uh, I'll be at click Connect.
I'll believe Dion will be at, uh, SAP Sapphire. And then, uh, following that is Dale Tech World. So we're getting into the swing of the enterprise.
It kind of spring early summer schedule. I'm expecting to receive a new toy from Dale today. Actually.
They, they, Dale doesn't like what when US Analyst type show up at their events without a, with a MacBook or hp uh, laptops. So they're sending us all laptops to make sure that we're uniform. And that Dale, They never sent me one, but you know, I've got my, they've Never sent you a laptop.
This is the second laptop I've gotten from Dale in the past six years. So, uh, and, uh, I'm not gonna tell you what I do with the laptop. I don't sell it 'cause it's technically not my laptop.
It, it is a loner, so I can't sell it. But I absolutely keep it and put it to good, good use. Well, what, what we do, uh, maybe they could send me a PowerMax or something.
We'll see. You know what that, that will make up for the years of them not sending you Yeah. A laptop.
Definitely. So, so Let's jump in. Let's do, uh, let's do a quick recap 'cause we missed last week.
Mm-hmm. The team here, uh, at Techron that typically produces these videos was off at RSA. And we'll get into some of the kind of talk of RSA because it, it is a big security conference.
You though e even though me, you nor Diane really cover security. Maybe we need to get Krista on to talk security. But, uh, the week before that you were at Tech Field Day, AI infrastructure day or AI infrastructure, uh, field day.
Any big themes you wanted to share with us coming out of that event? Well, so this is the second AI infrastructure field day we've had. Um, and the first one, we, we more focused on the data side of the house.
And this one, we opened the aperture to, um, various technologies that came in the door. Um, and that included everything FA lot of networking. So there's a lot of fo focus.
Um, Juniper was there, um, even, well, we spent a full day at Google's offices and there's a great video that was put up, um, that Colleen call had done on me. It was really sweet of her. Um, but talking about infrastructure matters, why infrastructure matters, and I, you know, I came away from the Google session, which was an all day session, including the networking and the data and the servers and the storage and a lot on the storage environment saying that they're not trying to put you in one, one box fits all, um, or one cloud fits all or one cloud kind of environment.
They understand that this is a very complex environment, that you're doing different things with data. You're, you know, you're doing LLMs, you're training, you're fine tuning, et cetera. And so that there is a, a myriad of solutions that they're bringing to you.
Um, and it's not for the faint of heart. So I think that having a consultant on board to help you through how you're designing what you're designing is really stupid important. Flip that to the next p One of the other ones that was really interesting, which was Nutanix that came in with what I would call the easy button.
And, um, Nutanix, they're known for easy button, right? You know, HCI stuff, um, hyperconverged. And, um, and what they've done is they've put, they've gone and curated like the hugging face, um, models and selected the top of the models.
There's, you know, thousands and thousands and thousands of models. So you can get buried in there to say, what's the best model for you to be using? And with that curation, you can select a model within the, um, Nutanix box, and then it automatically populates your GPU, your VM environment, all those kind of things for you to kinda get going and get running.
So, you know, there's a bunch of easy buttons they've done with it. It's pretty slick. Um, and, um, I think that it's designed for the companies that say, okay, so I wanna just get going and try this out, get this working.
Um, and yeah, suppo, you know, it scales. I don't know what the performance is. Usually you give a little bit of performance out for those pieces of it.
So that was really interesting as well. So those are a couple of the highlights. Um, we heard from our friends at Soy and, uh, they came in and you can talk again about their, um, their, uh, liquid cooled technology, which had everybody like odd, we were, we were all like in the, the petting zoo.
They were passing around all the, the, the fun toys to us. And it's like, Ooh, ooh, ooh. Yeah, it, it, you know what the delegates really like, uh, when soy presents the back channel, uh, I'll tell a little secret from the field day back channel when the delegates get together and talk.
They said, how is it that a storage company is coming in and, and explaining AI better than some dedicated AI companies? Solid. I does a really great job.
And it's not just a storage company, they're actually the device. I mean, they're making the solid state drive device. It's not like, it's not like they're out there, you know, like a WCA or somebody like that.
I mean, they, they outdo the, the guys that put the storage systems together, um, in terms of their understanding of this entire, the complexity of what it is. And so, and they are building, and the reason why they've done that and gone deep and really good at what they do is they've gone deep to understand what are you gonna need from an IO capability, capacity, capability at every step of the way of delivery. And, um, they've done excellent, excellent job of that.
Yeah, the, it reminds me, I have this saying when I'm mentoring, uh, career professionals, especially independent contributors, you need to understand your value to your organization all the way through the product that the product or services that you deliver. So if you're a DNS administrator, you need to be able to explain to the, uh, CFO why your job exists beyond, you know, doing, making sure DNS runs. Mm-hmm.
Same thing with, uh, basically what Soy did at the presentation, if you haven't watched it, they absolutely understand their value chain. And it's a great just lesson. And not just marketing, but product, you know, product engineering.
Like what, what role do I play ultimately in making AI real? And they did a really great job. So hat tip to the folks at, uh, solid, And one of the other companies that was there, which is also a process company or a, a, um, component company is Fon.
Um, Fon hasn't been really well known. They're, they're almost $2 billion company. Um, but they are the, um, the drives solid state drives behind, uh, a lot of other people that, so they have put other people's names on it for specifically, if you bought solid state through Seagate, it would've been coming from fsa.
Now recently they've gone pub, they've gone public with their name. Um, we hear a whole lot more about 'em. And then what they were there to really talk about was their adaptive, um, software technology that, uh, goes with the drives and enables you to more efficiently use, um, HBM or the, the memory and capability when you're doing the training.
Really, really kind of slick stuff. There's a blog up there that I'll, I'll put that kind of summarizes what it does, um, and the capabilities that it brings to the ai. So it lessens the amount of memory that you have to have, um, in order to train, which is really significant because that's one that's probably the biggest, um, bottleneck right now that we have with training among all the other pieces of it.
Um, so those are a couple of, a few, a few of the folks that, you know, I would like to, you know, highlighting here. That was, uh, really a good session. Um, so I'll turn it back over to you, Keith.
Yeah. And, uh, you mentioned these drive riders, you know, kind of the, um, the big claim of fame was kind of the 122 terabyte drive. Right?
And one of the things that we missed because we weren't on last week, was Dell announcing their latest, uh, AI server. That's not the big 9,000 series, but their 700 or latest 700 series density wise. 9 petabytes of storage in two you of SSDQ of basically QLC storage, which is an amazingly dense package.
Uh, rumors have it that IBM is gonna be, uh, announcing the latest version of their LTO drive, which I think is going to come in around 30 terabytes native. So just give, for us old school, uh, uh, storage administrators and people that these numbers are just insane. The amount of storage you could put into you and the need to be able to archive it is not keeping pace.
And it's, it's just an amazing problem that I, I could not have predicted five years ago, let alone, uh, 10, 15 years ago. So it's, it's an an amazing time to be alive and to be in storage. Yeah.
So, uh, there was, uh, actually news this week. Uh, Nutanix had their next conference, which I haven't been to since, uh, pre pandemic. They had a New Orleans, great food, great music.
What were the announcements coming out of, uh, next? Well, Nutanix next was in Washington, dc Um, we had a couple people from FU term that were there, and I know that, uh, guy Courier was there. Um, a couple things that I came out of that one is they did, Nutanix has been talking a whole lot about the VMware migrations.
You know, they're, they're, they're the alternative or one of the alternatives to Broadcom. Um, and they had clients there talking about those migrations, um, which included people like the US Navy and Moody's. Um, one of the things I highlighted is that in order, in order to win the Moody's business, they had to have external storage.
And so what you're looking at is like, okay, so that's, wait a second. We're, we're, we're integrating all the systems together. But what clients are saying is like, we've already had this investment in storage, and if you want us to move off of, um, if you want us to be able to move off of VMware, we need to be able to enable some of the storage that we're using.
Um, and the second piece of that is, you and I have talked about the Powerflex scale. You know, many, it was last year, DTW we SA had that deep, you know, sat down and had a deep conversation about Powerflex and, um, with, with Nutanix. And, and that has finally been released.
Uh, and maybe you wanna highlight, you know, kind of what your perspective was about why, why they needed to get that out. And, um, it was extremely important to clients that have got, um, very large environments, um, that they need to do a better job of scaling their storage with the servers. Um, and then this is basically what Nutanix is enabling right now.
Yeah. So we've seen this with people who have adopted, whether we're talking about, uh, legacy HPE SimpliVity or their DHCI solution or VxRail, and even in, in, in quote unquote pure Nutanix environments, enterprises don't get rid of their big iron storage array, right? The, these things are critical for mission, uh, critical deployments and just general workhorses, we're not, we're not even talking about just the, the, the big iron.
The, the traditional net followers are still critical to mission critical workflows. So I'd say something pretty provocative like seven or eight years ago when Nutanix has said it's kind of, uh, I would say it's hype level, the greatest hype level that HCI doesn't save money. The reason why is because enterprises don't get rid of these legacy technologies.
If you, uh, adopt all HCI, yes, you do reduce your administrative costs, but no one does that. Even in the VxRail environment, you're gonna see plenty of power scale scale. You're gonna see plenty of Power Max alongside of the, uh, VX R-L-H-C-I Nutanix, if they want a shot at these workloads, if they want a shot at disrupting, uh, or taking, because I don't think they need to disrupt it.
They just need to say, yes, VMware, angry VMware customers will, will take your money. If they want to just take this money, then they need a solution that, uh, integrates with overall environments, uh, and is storage and data landscapes, especially when we talk about ai, because these work, the data sets that people are generating from, uh, for their AI is not necessarily landing on HCI. So if we couple the next announcements, uh, to the announcements around, uh, their AI easy button, it all makes sense for Nutanix, right?
And for customers who are looking to displace or have been displaced by VMware's changes in licensing. So it's, it's critically important that they got ahead of this. They did.
I think the timing is well, uh, for them to start to pick up some of those, uh, VMware enterprise customers who, who are not exactly happy with the company. So on the second, second announcement of the storage piece of it, they announced a, um, relationship with Pure Storage and, um, they have done some deep integration with their software defined networking that's called float. Um, you know, along with the, what they call NCI Nutanix Cloud Infrastructure, they don't call it HCI anyway.
They call it Nutanix Cloud infrastructure. So, or hybrid cloud infrastructure or whatever. Let's, let's get rid of that word.
It's kinda like getting rid of data storage. Ah, we're calling it data infrastructure Like, uh, ai, I mean, uh, development platforms don't like to be called pass anymore. So, um, I was told that, uh, a year or two ago.
So yes, uh, private cloud platforms, Right. There we go. So anyway, so that was, that was another big announcement with, uh, peer storage as being, you know, and so there'll be others, external, external storage companies that will be coming out and, um, probably certifying with this same kind of integration with their, their operating system.
Now on the VM MI migrations, um, one of the other companies that was talked about was Toshiba. And Toshiba is migrating, um, two years to migrate 2000 VMs. Comment on that.
That's what they said. Yeah. So the, the, I think just wrote something about the, that this week, uh, that proved to be pretty popular VM to VM migration solved problem.
We were doing this back in 2008, uh, with products like plate span, VMware, uh, converter, the ability to go from, uh, public cloud, from even private cloud to public cloud and public cloud back from a VM disc format solve problem. Our friends at Veeam do it. I, I, I've done it in the CTO advisor hybrid data center in the six five data center where we wanna run a test, uh, suite on the public cloud or from the public cloud back onto, uh, on premises that's solved.
The problem is everything around the, uh, VM and Broadcom knew this exceptionally well when they bought VMware. The problem isn't, uh, the raw ability to move from VMware hypervisor to KVM Nutanix, A A HV, tho, those, that's routine there, there's tools, plenty of to do that from every provider. The challenge is what happens when I have my security tightly woven into NSX?
What happens when I, my storage policies written and, you know, hardcoded into vsan? What happens when I have, when I'm using the integration between VMware, vSphere and my storage rate for administration, when these things don't exist outside of VMware are not easily mapped one-to-one. You get your two year, you get your two years for 2000 VMs.
Yep, yep. And you know, it's, people don't understand. So something like a, um, data migration, when you're doing a migration from one platform to another platform, it's takes a year of planning.
I mean, a buddy of mine has had a company, that's all they did. Would they go in and do data migrations for companies? And he was, he had a team of full-time people, um, back when he worked for, I believe it was at and t and then he left the left, I think his, uh, his d internationals of the company.
And that is all they do is that migration. Now we've gotten better at it because they have, you know, some seamless migrations where you can plug, you know, plug in the new controller, the new devices, and it'll populate itself. But that's only if it's the same device you know, so like Pure does that, um, NetApp does that, et cetera.
But if you wanna go to somebody else's system, that's long range planning. And how many times have we seen, this is goes back to my comment that, you know, HCI, the, so I'll say this from seven or eight years ago, HCI seven or eight years ago, this story that you would spend money, uh, to, uh, spend less money. How many times have we seen that you, we see a Hitachi big storage array next to a VM max, next to a net NetApp thing, and there's three different generations of boxes.
And it, the plan was always to migrate off one, go to another one. But you get stuck. This, this stuff is complex.
You have low level, your SAP is, uh, directly mapping lungs to the vmac server. And that, uh, you're doing dis to dis replication from your host. And you can't simply just say, okay, I'm going to plug in another, uh, that abstraction of, I'll just plug in another storage provider behind that.
Just, it's not that simple. It doesn't work that way. And you get stuck in a migration.
And this is something Broadcom has depended on, uh, when it, when it comes to, uh, locking customers into VMware and VCF Broad, uh, hot com promoted that VCF has 70% penetration in their enterprise customers. Yes. Because it's the best licensing option of the licensing options that's presented to 'em.
Customers don't want to change because they have so much other stuff going on. Yeah. Yeah.
Well, enough of that. The end migrations, we've talked about that for now. Going on for two years, adding fin item.
So let's go on to something we don't talk about very often. That's ai. Yeah, ai, agent ai.
We're coming outta RSA. Neither you or I cover, uh, security. So for those of you that are insecurity, we are going to really, really murder what happened at RSA, but it is big news and we do need to cover the news.
Uh, basically everything was a GenX ai, a GenX AI and identity while within security. So this whole idea of how do you secure ai, actually we, we've gotten briefed by Dale. We've gotten briefed by all the major OEMs on their strategy around securing the AI data.
Pipeline data is something that me and you know about, and this ability to use a, uh, not use ai, but both use AI in, uh, secure ai. The, the, I think the question that was getting answered or asked at RSA consistently, is AI just another workload that needs to be scanned similar to security? Uh, similar to, uh, how scanners, uh, secure other workloads?
Or is it a different approach to security in general? Any thoughts on this at all? Uh, Kimberly?
Well, okay, so Agen ai, um, and identity security, it makes a whole lot of sense to have, um, AI or some sort of agent work on identity access management, I think is what we're talking about here is are you who you say you are when you're knocking on the door and wanting to access the data? And let's apply those disciplines to there and that, and can we use a ai, uh, tool here to do that work, um, that maybe humans were doing before, or systems were doing before, or can we button it down even further? So, yes, to me, this makes sense.
Um, if that's what we're talking about here, um, I did not attend any of the RSA stuff, so I'm not gonna try to, you know, fake it till I make it here, um, at all. I'll say, I don't know. Um, but what I do know is that we've built, we, most of the data management companies have start, have started to build or have built some sort of hooks into security systems, um, identity security systems for the purposes of DA data management, especially as we get into the data pipeline.
Um, and identifying what, who has what access to what, um, over the time. And then from, as you, uh, connect that to a agentic ai, imagine having, uh, to, you know, most people have disabled micros, uh, for the very reason that we're facing with Agen AI security, this idea that there is these autonomous systems accessing your data and doing work on behalf of your organization that can be hacked. So if I can, uh, if you, uh, if I can, uh, do some type of, uh, phishing or something, some social engineering to that agent that has some, some level of intelligence, which can be fooled, how do I protect against that?
I don't know the answer to that. If you want to learn more, go watch the covers from RSA from the rest of the folks here at rum. Alright, so, uh, well, and now I'm going to do my best impersonation of Dion.
'cause Dion covers open AI much more than I do. But there is a big announcement coming out of open AI for, uh, uh, their country's initiative. Diane felt this was, uh, exceptionally important.
He wrote something on it. The, I, the general idea is a localized AI for an AI infrastructure for countries. If you're in France, V versus Switzerland versus, uh, the us, you need ai.
That's, that's meeting your local re regulatory and legal and democratic standards and open AI specifically going to serve each one of those companies. They announced a $500 billion investment to, uh, to fo to help the US specifically build us, uh, centric ai. Wow, that's big.
That's very, very big. I had not read about that. Um, and this is going beyond the language differences then, where we call it, this is one beyond local versus a boots.
Okay. Yeah. This is getting into the, um, the norms and the, I would imagine some of the norms that people have as well as the mandates that are coming from the government, which we still are evolving.
And, um, yes, we've got, you know, the EU has put their stuff has put out there, um, AI guidelines or AI dictates. Um, we have not as a country yet. Um, we've given the guidelines coming from the, uh, presidents, um, and I multiply that because I know we, we had one from the Biden administration and we're now working on the one coming from the, um, the Trump administration to see what's gonna come out of that piece of it.
But yeah, those things have to be, um, and especially when we get into, I think, well any country, I think that every, we've all experienced that when you go over there, the norms are very, are different. Um, and it's, those nuances is there that can cause problems with people, um, how language is how we express ourselves, et cetera. So yes, this, this is big.
This is really big. Yeah. I, I was shocked when someone from, uh, And is 500 billion enough money for this.
That's kind of my question. Well, the US specifically, the, so, uh, uh, well, I don't know if it's for the us but they're talking about building local data centers, local versions of Check GPT for the regions that they're gonna operate in. So yeah, 500 billion does not seem like enough.
I think Daniel Newman was just saying, uh, that he, uh, moderated a panel in which the notion of $3 trillion of investment in AI by over the next three years is probably a little conservative. The we're, we're gonna see numbers bigger than that. Yeah.
Yeah. Talking about big investments, uh, less, or our friends at IBM had their big show this week, IBM think or one of their big shows, uh, IBM think is one of the more technical shows, and they announced $150 billion investment in the United States over the next five years talking about ai. So, you know, I think, I, I have to agree you with Daniel, uh, based on these two numbers alone, 500 billion over, uh, I, I, I would assume a shorter period of time for OpenAI 150 billion from IBM, we've heard the numbers from TSMC, uh, Intel, apple, et cetera.
That $3 trillion number seems a little bit low. But, uh, over the next five years, they're gonna be investing in ai, quantum and, uh, other manufacturing here in the us. And I think the quantum is the big one is because, you know, IBM Manu, what IBM manufacturers, they manufacture, um, the storage systems, they manufacture, um, the mainframes and they manufacture the, um, the power systems.
This one here is the quantum, the big quantum computing investment that they're gonna be making. So, um, that will make, and they recognize that, you know, we are well on our way, you know, in March. I mean, it's kind of like talking about quantum computing.
It feels like, you know, for 5, 6, 7 years, and we're, we've, it was always seemed like it was 10 years away before it was gonna be ready. Now we're within a planning period that quantum computing will be ready. And when I say a planning period, it's that three to five year timeframe that we can start thinking about how are you gonna actually really use quantum computing to solve some of the big problems.
And one of the things over the past five or 10 years that's changed, that is that Kevin, one of the things that we haven't really thought about is this engagement, this interaction of quantum ai. And I, I haven't really given it enough thought to, uh, to comment intelligently on it. But as we see quantum start starting to, you know, another non-deterministic technology quantum, uh, uh, take on or integrate with a non-deterministic technology such as LLM and in ai, how what will the resulting systems look like really intrigues me, really confuses me.
And, uh, I, I, I, it, it, it's, it's more technology than I thought I'd see in my lifetime. Yep. Whole lot.
All right. With that, we did our best impersonation of security analysts and, uh, AI analysts from the, uh, from, uh, and quantum analysts. Uh, but one thing that both me and Kimberly know is storage and systems, and I think we covered that exceptionally well.
So, a plus on storage and systems, c plus on everything else. If you wanna learn more, uh, tune in next week. 'cause I, I'm serving our good friend Diane, will be back to help pick up the slack and some of this conversation around compliance CIO level stuff.
Remember to follow his, uh, CIO checks, CIO, uh, hashtag CIO checks every Thursday. And, uh, follow my zero to builder series, hashtag zero to builder to learn how to develop code from zero to build in a hundred days, even if you haven't joined. It's a, it's a good opportunity to, uh, catch up.
Thanks everyone. Have a great week. Hey, everyone, you ready to get entangled with quantum networking?
You're watching Textron Gang. Happy Tuesday, everyone. It's Alan Shival for Text Strong and you're watching Text on Gang.
We've got a good show here with some interesting stuff as this week starts taking off and we've got some interesting people to discuss it with you. Uh, let me introduce you to our gang for today. First of all, with the fancy background.
Mm-hmm. LLMs ai. I, that's what he Yeah, we've, I had, that's a new one I haven't seen before.
He's our friend, JP Morgenthal. Jp, how are you, man? I'm doing great.
How's everybody today? Well, we'll find out, won't we? Yeah, but good to have you moving on from jp.
We'll go up to he, I think, I guess from the background, he's back in Hudson, the man from Hudson. Oh, that was the man from Hope. Well, you're the man from Hudson, uh, Oracle, the, uh, founder of Tech Field Day, Steven Squi.
Hey, Steven. How you doing? Well, you know, it was nice to be down there in the studio, uh, keeping Bonnie's chair warm and the, but, uh, it, it's nice to be home.
There's no place like home. Yes, there is. Click your heels when you say that.
Click those heels. All right. Welcome Steven.
And then also home in Harrison, New York, not named for the Presidents our chief content Officer, Mike Ard. Hey, Mike, how are you? Echo Steven's sentiment.
There's no place like home. It's, and any day you're headed, home is a good day. That's right, that's right.
Speaking of home, we're home here in our book studios and joining the in studios, our resident Echo Insights analyst and, uh, editor Bonnie Schneider. Hey, Bonnie, how are you? I'm well.
Great to be here. Alan, great to have you in the studio. I gotta tell you the truth.
It's a lot better having you here. I mean, it's not that I have anything against Steven, but it makes for a better picture. Well, it was really, honestly, I'd rather have her there too.
Yeah. All right. Let's, um, it is a rainy day here in Boca Ratone, but you can't have sunshine every day.
Wow. It's actually raining in sa in two different places, miles apart in Florida. The same back in Florida.
Well, we, That's, that's not a Good sign. No, but we needed the rain. It's been, it's been pretty dry here, Here too.
Yeah. We need the rain. Anyway, so Mike, Cisco threw their hat into the quantum race derby, whatever you wanna call it, but being Cisco, of course, they're talking about quantum networking.
True. That. So yeah, Cisco has revealed that it's working with uc, Santa Barbara, to build something that feels like a quantum networking entanglement chip.
And I guess, you know, in my mind, a lot of us thought about quantum computers as these big kind of mainframe like things, but maybe they are gonna be a little more distributed. And every time I turn around, somebody in China seems to be building a quantum computer that's smaller and feels more like a general purpose machine. So Alan, I know you follow the space, but what's your take on what's going on here?
You know, I, I think this is the filling out of the ecosystem here, right? But this isn't networking the way you may be thinking of networking. Um, but I just wanna mention, hey, we are planning a virtual event on quantum called of All Things Quantum Leap.
Uh, and it'll be in October. And we're looking for speakers, sponsors. And if quantum's your thing, you should register for it.
I don't think the registration page will be up for another week or two, but, um, I'm looking forward to diving a little deeper into all things quantum there, from quantum to security, to quantum chips, to quantum networking algorithm, software, everything else. But when, you know, first of all, people have to be familiar with the entanglement principle of quantum, right? Which means you could have two particles or two pieces of matter that are somehow, you know, as crazy as it seems, they could be light years apart even, and still connected entangled, where if one spins, the other spins one, you know, and they, they copy each other's, uh, uh, matter kind of, uh, you know, if, if one's spinning left, the other's spinning, right?
Whatever it is. So they're intrinsically linked, they're entangled. And once you understand that and you have that, and you can manipulate that, well, that allows for all kinds of, of things.
Every, you know, from the craziness of teleport teleportation, you know, star Trek kind of beat me up, Scotty, to networking perhaps, right? And that's what Cisco's talking about here. Now, the interesting thing, it doesn't necessarily have to be networking like from a router to an endpoint or over the internet.
It could just be two quantum chips that are entangled, right? So by using entanglement, you can create sort of a, a parallel type of processing, uh, you know, sequence where you can have multiple quantum chips now working in quantum time, right? Via entanglement.
And so if, if, if a thousand qubits is the holy grail or whatever of one, we could really hit quantum, you know, picture having 10, 100 qubit processors that are network really entangled and, and working like that. Yes. I, I, I just, I wanna address the, uh, Cisco announcement with regard to that, right?
I think what Cisco was pointing out is that we don't have that kind of scale on the horizon right now. We have, well, no, but what we have is a, a limited number of qubits, chips that can, that are created to create a quantum computer. But what the way they're saying that you can scale is by creating, leveraging quantum networking as a way to create multiple quantum computing machines, Right?
That that's what you're gonna have, right? You're gonna put 'em in parallel the same way we did Linux machines into supercomputers, right? That that's, it's kind of the same kind of thing.
I I I'm interested in how much data can be represented by these entanglements. Because if you, the one thing we've always said is that they, you know, and I've always joked that, you know, ultimately the network owns the s for the in, for the for, for the universal computing because it's the, it's right now the major limitation, you can only get data to, and so much data to move so fast from point to point, right? So it, it's your, it's your limitation in compute right now is how much data can you move and, and how far can you move it before you see degradation.
So if you, if this thing can carry terabytes of data instantaneously moving it from point to point, it's, that is a, then that's a huge game changer. That is a major game changer. Yeah.
But This is, I mean, the whole idea of quantum networking, I don't know if we could think of it in terms of how much data can I move over a pipe? I, because it's particle to particle. So I think the, the issue then becomes, well, can I do a hundred thousand particles to a hundred thousand particle?
But each particle has this much on it, but, you know, but a hundred thousand of those, nevertheless is a lot. I mean, jp honestly, this is, this has hurt your brain stuff, right? That it's, it's kind of so far out there and so radical to what we know and think of.
Um, because I don't think data is necessarily transported. It's kind of an instantaneous, if this knows it, that knows it. I mean, you know, you gotta, you gotta be on some medicinal marijuana or something to kind of get your head wrapped around this.
So Four people who, um, are, are not quantum, uh, oriented, uh, think of it like virtual mapped memory. You have your virtual map on top of your physical disc and your virtual map nose instantaneously, whatever's on the disc data. And then you move your virtual windows around to see different parts of the disc, and it becomes just boom, it's available.
Right? So you're saying the whole universe could be on my thumbnail, I was thinking more like the cat in, uh, men in black around the, the, the, So Steven, it sounds like to me that this is the laws of physics being applied, the quantum computing, or is it fundamentally different? Well let, yeah, let's, let's, uh, I, I don't know, get, get down to down to earth here in a little bit, uh, you know, put down the, the wacky tobacco, if you can for a second.
Uh, yeah, what Cisco's announcing is pretty interesting, and I'll just point out that we actually heard a very similar thing, a similar story from others at our networking field day. In fact, in March, uh, bt the big, uh, telecommunications giant presented a whole section or a whole field day session on quantum networking. And Cisco's describing a similar application.
The idea is, well, number one, Cisco has some pretty cool technology here. They've got a quantum, uh, pro well networking processor, entanglement, chip, it's not really, this isn't a quantum processor. This is a quantum enabled networking chip that works at room temperature at very low power and uses the same wavelengths of light that are currently used with optical networking, which is important because otherwise it would not be practical at all.
The other thing, like JP was saying, I mean, the interesting thing here is that you can instantly, and, and when I mean instantly, I don't mean just really quickly, I mean, it's there, um, transmit data in a way that cannot be snooped on that is completely, you know, synchronous on both sides. And that's a really useful tool for things like key public key exchange and encryption, that sort of thing. Another thing Cisco has done is they are using the quantum, this quantum fluctuations as a random number generator.
And I think that those of you in the security space, I'm sure that you all have experienced this and, and know that random number generators are not very random. And that's a huge problem. And that's one area that hackers and especially nation state hackers use to exploit systems.
Essentially, they will, uh, clone the pseudorandom number generator and make and, and, and, and generate the same number. Well, it's awful hard to do that in the quantum space. And Cisco has come up with a quantum random number generator.
And, and also they're working with, uh, university researchers to develop future applications that would allow interconnection of quantum systems, but also quantum interconnection of classical systems, which is something that the BT presentation was talking about as well. There's just a lot of really interesting, um, features in here, including some nuts and bolts ones, not some pie in the sky ones. I mean, honestly, a quantum run random number generator.
Sounds great. Well, you know, it's funny you bring that up, Mike. Wasn't it just yesterday's show?
We talked about this issue about some researchers, researchers came out with a report that they explaining and, and being able to anticipate prime numbers, which is, you know, how all of that underlying all of our encryption and, and, and the idea of being able to generate random numbers, you know, is, is this, it's not so random as it turns out, potentially. Anyway, there was just a research report, whether it was, you know, how true it was, we don't know yet, But I, I, I actually, Stephen raised an interesting point that I hadn't yet considered in the field of intelligence. Um, think about a compu two computers in two skiffs.
Uh, those are compartmentalized rooms. Air gapped not connected to any network, not even the high side, low side of the, of the government actually air gapped computers being able to communicate with each other across skiffs. That is an insane intelligence application you would actually have, because the whole idea of the air gap computers, it's not connected to any network, right?
It's a standalone computer, a performs some type of function, and this would allow those computers to be networked well, But is that a good thing or a bad thing? Well, from an intelligence application standpoint, it's re it's a, it's critical. Depends on which side of the intelligence equation you are.
If you're trying to protect stuff, it's good. So this comes back to kind of what I'm starting to wonder about here is, so we know that the existing computer architectures we have in place are flawed, and we're using them in ways that are insecure. And to Alan's point, there's prime number issues now that people are figuring out.
It feels like all the money being poured into quantum is an effort to kind of reinvent computing. And it might take a decade or so, but, or is this gonna be some, you know, little sidebar esoteric thing that we're using for some vague computer science project? Like, you know, we're gonna figure out how to use some chemistry application differently.
But, you know, Steven, how big a deal is this ultimately? Well, the proof is gonna be in the pudding, isn't it? Uh, we'll see if they're able to productize this and bring this to market as a friend of the gang, Bob Sutor would say, and as he did say in that Textron article, you know, I mean there's, uh, there's a lot of uncertainty here in the quantum space.
I'm sorry, I had do point. Yes, there's a principle about that, isn't there? Exactly.
Yeah. The principle says that it's uncertain, um, and we gotta listen to the principle, but, uh, no, the point is, we'll see, right? I mean, if Cisco can productize this thing, I, I, I can envision a situation where next year, the year after Cisco brings a quantum powered random number generator for encryption tasks to market.
And that becomes a very important and useful tool. I could also see a situation where they never talk about this again, and we just continue to move on about our lives. So ultimately, it's not research that fixes things, it's products, and let's see, see what Product can, well, what about, what about both of those things happening in parallel universes back to the wacky tobacco, just saying, just saying.
But, but seriously, You know, if, if we are going, so I'm a Star Trek Fat, I, I have to, you know, if we are going to go on these adventures where no person's gone before, if we're going to continue pushing the boundaries, right? We, we've spent the last hundred plus years exploring basically the theory of relativity and how that affects everything that we do. And it's led to the nuclear hydrogen bombs, fusion bombs, visions, energy, and so many other things.
The next breakthroughs that will advance the human condition. We need to understand and harness the power of quantum. And, and you know, this, um, this is one of those times you're happy to be in tech, right?
Because we're kind of leading the charge here a little bit and trying to harness, harness this to recreate what we do. And that's kinda what tech, the tech industry does, right? We don't use punch cards anymore.
We don't use little floppy disc, right? How, you know, so I'm, you know, I i, we do it because it's hard. Not because it's easy, but it's worthwhile.
And, and that's my last word on quantum. I'm looking forward to the Rung Gang being in two places at one time. That'll be fine.
Well, we're already yet, look, we're in Ohio, two places in Florida in New York already we're quantum, But then I, but theoretically I could have two Steven FSTs arguing with each other over a quantum network. Solar. Solar, I'm sorry, I just had to say it.
Alright, let's take a break and kinda sober up a bit here. And, uh, we'll come back and Steven, you can have a report for us on Mobility Field Day. Yeah, I sure will.
Fantastic. You're watching Techstrong Gang. Well, we are, uh, hosting a lot of different field day topics, but as I said last week on The Gang, my favorite tech field day, I mean, my favorite child among, among many is Mobility Field Day.
The reason is because as, uh, they were all laughing at me for saying on the gang, they are from another planet. It is always fun to, to mix and match with people who, uh, know something that is completely alien, that, that are deep experts in a field that you aren't an expert at because you know, you can really kind of soak in it and learn so, so much, so, so quickly. Unfortunately, I wasn't at Mobility Field Day, I was in some place called Boco with a, uh, distinguished man named Shimmy.
But I was, uh, check checking it out remotely as anyone can do, watching some of the presentations. And over the weekend I checked out some of them as well. It's interesting the takeaways that you get from this group when they do come together.
Uh, one of the things that I predicted going into it was that wifi seven was gonna be a very important topic. Well, the answer to that is a little more mixed. Um, wifi seven sure is important, but some of the key features, especially Multilink operation, are still very much a work in progress.
There are standards, but there sort of pre standards and the companies are still working on that technology. Another aspect that we heard quite a lot about was how to bring wifi to the masses at large public venues. If you've been to a baseball game or a football game and tried to use the wifi there, it probably works better than the cellular network.
But unfortunately, that, again, is still a, a, an area that there's a lot of development happening on. Well, fortunately, because a lot of that development is actually going to be able to leverage some of the features of wifi six and seven to really broaden access to public wifi. The other thing that's important is that we're seeing a lot more crossover between wifi and data center technologies.
So things like, uh, VXLAN and so on are actually coming into the wifi space, which again, is one of the things that I love about learning about other fields, because you can take ideas from those fields and bring them into yours. The wifi community was the first to have essentially what we now know of as software-defined networking, or software-defined computing software defined anything. This idea that you have a controller and then you have, uh, basically cattle instead of pets out there as your hardware and the controller, uh, with Zero Touch will activate and configure and, and, and integrate that hardware.
Well, that was a very widespread technology on the wifi side before we ever saw it on networking, let alone on Compute. Now it's everywhere on compute, and that has been a really powerful thing. So it's really cool to see some enterprise networking features and ideas like VXLAN come over into the wifi space as well.
So overall, that, that, that was sort of the takeaways from Mobility Field Day. I do urge you to check out some of those presentations, especially, uh, I just wanna give a little shout out here to, uh, fellow futurum, uh, analysts, uh, Ron Westfall, who talked a lot about some of the, uh, intelligence research that we've done, uh, internally on the state of, uh, mobility, networking, quantum, those sort of things. Check out the, the Ron presentation.
All those posts are up, um, on the text on tv, but they'll also be up on YouTube very soon. So Steven, every time I turn around, some telco is trying to get me to essentially ditch wifi in favor of using LTE as my primary network. And they're pointing out things like, you know, wifi can get hacked and it's a pain to use.
And you know, you, to Alan's point last week, I think, you know, you gotta stand on one foot to get the connections, right? So, um, is there a case for LTE here or is wifi still the dominant player? But wifi is gonna be used in other things?
Well, when all you have is a hammer, everything looks like a nail. And if you're a telco with a big 5G or LTE network, uh, you might start saying, Hey, we can do that too. I think there is some crossover, but I think that, uh, those of those that I know who've deployed, um, basically LTE as a, as a broadband back haul, many of them are happy with it for the price.
Um, many of them are not happy with it, with it for the performance, especially when when things get busy. Uh, that's not a topic really that the mobility Field Day folks have talked much about. Um, but again, without casting aspersions at anyone on the call, uh, we found that it's sometimes difficult to implement wifi in a way that is reliable and high performing and meets the needs of users.
And I think that the ease of use of mobile networks has really come a long way to the point now where, I don't know about you, but I was at a hotel over the weekend. I never connected to the hotel wifi. I just used my phone, uh, on 5G the whole time and, and I didn't really suffer for it.
So I think that, uh, many of us may be starting, I don't know, maybe the bloom is off the Rose A. Little bit on wifi. Do you find yourselves doing that as well?
Yeah. Mm-hmm. Yes.
Well, and, and, and to the aspersions around wifi, it helps if people do plug in their wifi access points as we found out one was unplugged here, but, um, who knew? But you know what, I, real life, so at the HOA where I live, I'm, I'm the president of the HOA in Del Boca Vista. Um, but anyway, we are looking at bringing in a broadband provider for the, for the whole development, which is 69 homes.
It's not a big development, and they wanna bring five real fiber to everyone's house, not fiber, and then last mile fiber in everyone's house. And everyone would get two wifi, seven, uh, wa you know, wifi access points upstairs, downstairs, a whole bunch of other stuff, five asynchronous, 500 meg up, 500 meg down cable tv, and if you want IP phone cheap, like 80 bucks a month for all that. I surveyed the neighborhood to see, is this something we want to do?
And I was surprised that there were outta 69 homes, about eight homes that are on this T-Mobile, LTE. You know, if, if you have a T-Mobile phone, they give it to you for like $30 a month. If you a T-Mobile cell phone customer, they give you a little wifi access point and for 30 bucks a month, they get they streaming, they're streaming tv, they don't have cable, they're streaming video, they're using it, you know, for basic connectivity.
Now granted, these are people like all del Boca Vista people who are probably in their sixties, seventies, or greater and are not, you know, I don't think they're uploading any videos or anything. They're shooting locally, though one never knows in Florida. Um, but it works for them.
It works for them. And so an $80 now they don't have anywhere near 500 megabits up and down, but for what they needed for it works and, you know, 30 something dollars to $80, they'd rather keep their 30 something dollars thing. I don't think that works in an office here, maybe with the amount of devices we'd have connected in our bed with needs.
Um, and I'll tell you one thing, what I do agree with Steven on is like, I believe, and maybe I'm wrong, but the, I think the LTE connection is more secure than the wifi connection, especially if I'm like bouncing into some sort of restaurant somewhere and I'm trying to use their wifi and god knows when the last time that thing was Updated. Well, Steven, now my friend Jennifer, Jennifer jj, Jennifer Manila was at your event, wasn't she? Yeah.
And Jennifer is, is fantastic. She's the authority on wifi security. And the truth is, uh, to your point, I don't think there's any intrinsic reason that wifi is less secure than cellular.
In fact, I think that it could be more secure. The problem is that wifi is generally misconfigured everywhere. Um, you know, I, uh, I had to reconfigure the local coffee shops wifi while sitting there, uh, because of, uh, you know, they, they just had the default outta the box configuration from Windstream and it was just terrible.
Um, you know, that sort of thing happens all the, all the time. And I think you're right. Um, you know, rogue access points and, uh, impersonation attacks and all that stuff, it's, it's, it's not as common maybe as people might think, but it, it does happen.
And that can be really bad. Uh, any, I, I dunno, if you wanna be terrified, Google wifi pineapple and you'll learn all about that. Um, on the other hand, uh, there are also rogue, uh, LTE cells, uh, Google Stingray, and you'll be terrified as well, and you'll shut off all your phones and throw them in the microwave and, um, and be done with it because all of this stuff, there's, there's, there's all sorts of hacks here.
Yep. Steven, I wanted to talk about another aspect that was discussed, and you mentioned briefly, and that is, you know, stadium level wifi. So I, I've been covering that basically with my friends from Extreme Networks now for a few years.
And they, they have a good business around that. I think they're like the official partner of the NFL or something. I know the Cisco Stadium, um, where the 49 ERs playing Santa Clara, I don't know if it's still called Cisco Stadium, but with Levi Stadium.
Yes. They, they do that, they do a whole bunch of stadiums and, and they have made a ton of progress there. And I, I've seen it when I go to sporting events now, you know, it used to be you can get on the network, but you wouldn't go anywhere.
You couldn't get out. But, you know, most recently I, I've seen absolutely improvements there. Oh, yeah.
Well, it's funny that you mentioned Levi Stadium. Uh, unfortunately we weren't able to film it because of confidentiality reasons, but we actually had the company responsible for the wifi at Levi's Stadium lead the mobility Field Day delegates through Levi's Stadium to show exactly how they implemented that. And it is really well done.
That's an example of, um, you know, the, the, the, the good aspect of the wifi deployments as opposed to the bad ones that you find, um, mostly everywhere else. Even there though, um, we've caught up with those people over time. They've had all sorts of interesting edge case kind of failures that they've had to resolve.
And again, happily that group has come back to us and spoken with us and told us about the lessons learned and the things that they've done to improve access there. It is incredible what happens, for example, when 50,000 people arrive within a half an hour and connect to your wifi. Uh, that's not something that most people experience, but it is something that they've experienced.
So I think that it's one of those, um, one of those things where expertise really matters. You know, when you go in the office in the morning in those big office buildings and you show up around nine o'clock, you experience the same phenomenon where everybody else logs in at the same time. Right?
Well, you know, it's true. It's true. And, uh, and you know, it's the same when you have like high volume applications.
Your Dropbox is synchronizing, your time machine is backing up, your email is downloading, uh, yeah. And then you're on the meeting on the third floor, but your office is on the ninth floor and they didn't route you back to the right connection point. So you're trying to access your access points six floors above.
Yeah. You're just, he's just making excuses so he could work from home. Come on.
Um, speaking of home though, an interesting thing that came out of this project I'm doing with my HOA is the average house has more than 30 IP addresses right now. 30 30, 30 connected devices. You think about it, You know, I mean, US nerds, well, especially with the IOT space, um, IOT is causing a rapid proliferation.
'cause a lot of these devices are using IP networks now. And, um, and that's actually one of the benefits of some of these things, you know, matter and thread and ZigBee and Z-Wave and all those things because they're not on your wifi network. Yeah.
We're seeing a, a huge proliferation. 4 gigahertz wifi, which is increasingly crowded. 4 gigahertz is usually 30, 40, even 50%, which means that basically only about half that bandwidth is even available because there are so many devices on that space.
You know, on on that point, I, I was configuring a router in the clubhouse of the, of the HOA and, um, it's a six E router, and for the first time there were three networks. 4, the five and the six. Yep.
Yeah. And six E uh, that's another benefit of six E is opening up that six gigahertz wifi because it's, uh, you know, there's a lot less contention, a lot faster too. Six E is great If you have a device that can support it.
Yep. Which I have. There you go.
All right. Hey, let's take a break here. We're gonna come back and Bonnie has an Echo Insights report on AI carbon footprint.
Yes. All right. You're watching Textron Gang.
Join Cruise Con Virtual on May 22nd, 2025 for breakthrough strategies to address advanced threat intelligence, proactive incident response, exclusive bonus material and regulatory adaptation here from our keynote speaker, Admiral Michael S. Rogers, former director of the National Security Agency, and an outstanding lineup of industry experts as they navigate emerging threats, the core principles of crisis management and the evolution of CISO leadership. Register now for free.
Welcome back to the Techron Gang. Well, there's a lot of talk about AI's carbon footprint. So a carbon accounting firm called Greenly based in Paris.
I've actually interviewed them before they came out with, uh, new researched, kind of breaking down the carbon footprint of ai, not just the training, which we talk a lot about, but the queries everyday use. And they had some interesting findings. I took a closer look at their findings and their research in this video.
AI's carbon cost doesn't stop at training. Every prompt, every task fuels a growing footprint, and it's accelerating fast. That's the conclusion of a new study from Carbon accounting firm greenly, which shows that emissions accumulate from development to deployment.
Building a model like GP GT three can emit as much carbon dioxide as 112 gas powered cars do in a year. And that's just the beginning. Envision endless queries used billions of times, it all adds up.
Greenleaf's research also shows that not all AI tasks are created equal. 05 kilograms a staggering 60 fold difference. The gap widens further with added complexity.
Supporting additional languages, for instance, typically requires separate rounds of training, compounding the carbon footprint with every expansion. Fortunately though, the study does point to tangible ways to reduce AI's impact, such as training, less often, reusing models, improving hardware and data centers, plus tapping into renewable energy. Combine that with efficient code and emissions could fall sharply.
Reducing AI's carbon footprint isn't about choosing between training and usage. It's about optimizing both. Well, as I mentioned, Greenly had some suggestions for reducing the carbon footprint of a IU, such as training on 70%, uh, use of the model.
That was one of the things that they had listed and many others like leaning into renewable energy, which is something that we've been talking about for a while that all of big Tech is doing. But it was an interesting report because it wasn't just from a regular large research firm, it was from people that are actually doing the carbon accounting for, uh, these types of organizations. Yeah.
You know, look, I'm a big believer in reducing carbon footprint, so I don't want this to be taken the wrong way, but I think we'll reduce the carbon footprint footprint when it's economically, um, incentivized to reduce our carbon footprint. So rather than saying do this to reduce your carbon footprint, we could say, do this to reduce the cost of your compute. I think at least in today's world, it's it's a better selling point than it is do it for the right reasons.
Reduce your carbon foot For, for regulation in the case of GreenLake. 'cause they're working with a lot of European That's true. Yeah.
Yeah. So at the risk of, you know, confirming that Alan might have been right about something if you were looking over at, uh, open compute project like I think two weeks ago now, Google, Microsoft, and, uh, AWS, they were all over there talking about ways to build more energy efficient data centers. And they had like whole new approaches where they're pulling out the, uh, the electrical conduits.
There's gonna be in a separate cabinet from the compute. They had all kinds of interesting designs that would be essentially more energy efficient. It might take four or five years to get there in terms of redesigning data centers.
But it was an interesting that there was a lot of work in this area. So maybe we will get to the point where we are more efficient in the consumption of the energy to drive these AI models. And then the other thing I would just point out is, um, you know, the folks over at Open AI reminding everybody that you should be rude to your AI model and not type thank you all the time.
'cause it sucks up energy. No Problem. That's good point.
You know, With regard to the video, what I found interesting were a couple of things. One, the comparison of what it takes, uh, energy wise to produce images versus text. Uh, in the inference side, not even the model side.
Uh, the other thing I think is really interesting, uh, didn't get, uh, pointed out because it wasn't directed to any one particular model provider was the impact of deep seek once again on the industry, right? Because what they recommended, or what Bonnie said was recommended about the reuse of models. I mean, this is deep seq 1 0 1, right?
It's like that's a, I mean, they actually now can put themselves in yet another camp, which is with, with a green AI camp, right? Because we did exactly what Greenley is recommending with regard to how to produce a model and make it available in a economical and, uh, also, uh, ESG efficient manner, right? So really interesting that it, uh, it, it wasn't the place for it to get mentioned, but in another report of similar ilk, you would probably hear deep seek getting mentioned again for its, uh, innovation.
But, But isn't that the way of developing markets and developing technology is as you, as they develop, you bring in efficiencies You would hope. I mean, if, if there's a reason to, right? I mean, why does, why did automobile manufacturers stop creating, you know, uh, babe from supernatural, right?
The, uh, the, because you know, where are the muscle cars? The muscle cars are today, right? Not, uh, ecologically friendly, so to speak.
Uh, and, uh, you know, they, they become a hobbyists, uh, in invention, but not really practical for every day. Now, when did that happen? When we hit peak oil, when the cost of fuel and the cost to manufacture gasoline reached a certain point, it became, you know, and then all, and there was some support at one time in this country for, you know, not producing a larger carbon footprint.
Of course, now we're probably reversing that because you know, what the heck billionaires run the planet. But, you know, your, your analogy is a smart one, I think because, you know, if you look at cars, I'm a car nerd. Um, one of the reasons I think that we've gotten so much more energy efficient as well is because the technology has improved to such an extent.
I was looking at, uh, a recent, uh, just a mainstream car model that a normal person would buy. 3 liter, three cylinder turbo engine. 3 liter, three cylinder turbo powered SUV, they would think I was crazy.
But the truth is, the technology has gotten so incredibly good that you can deliver 32 miles per gallon from the Buick, whatever it was. And, um, that can be a perfectly satisfactory car from somebody who doesn't know anything or care anything about cars. And I think that that's kind of the analogy for deeps seek, right?
That deeps seek was able to basically do the same thing with a lot less. And if it's good enough, then nobody cares about having a V eight anymore because it's good enough. But to Alan's point about cost as well, I think one of the challenges, one of the biggest problems with AI right now is that effectively the cost is zero because these things are so incredibly subsidized by people who want to see AI succeed.
And so you have these companies, um, raking in VC money and using all that money to build these models and to deploy these systems and, and, and they never ever have to stop and say, wait a second, we're using how much power? And that costs me how much dollars. They don't care about the dollars.
If you've got a billion dollars in VC investment, who do you what? You know, what are you gonna do? You're gonna fret about a few watts, But, but I worry about it.
But again, this is the natural way of things. This is the natural way of things. They will start carrying, the VCs will start carrying the VCs.
I mean, it's the market at work. They'll start rewarding companies that are doing it more efficiently, Especially when they have those, um, you know, conflicts with the local power companies and things like that. And that gets into the news and that's, you know, yeah, No, it, you know, positive.
Look, I re I've said this before. I remember interviewing the two CEOs of two widely successful, no early on no SQL databases. And I said, there's no sql, Stanford, no security.
He said, we'll have security. When our customers demand, we have security. AI will become efficient when customers and investors demand, it's become more efficient.
Well, It actually may be, again, the laws of physics that forced them to do so. Here, there is a cap on how much energy you can actually suck, right? And, uh, and without nuclear reactors now, you know, as a widely available source of energy, um, you can, I mean, shoot, if I was Texas, if I were a company, I would not look at going near Texas with my, with my data center, right?
Because how the last two years winner, they've lost power for how much, how long? But Yet they, they're building, you know, uh, Amanda, our managing editor says that San Angelo, Texas is on its way to becoming, you know, the data center capital of the world. My my youngest son's out in Abilene, Texas, they're building huge data center out there, but they're using wind energy because I was gonna say, they're not on the, they're not on The Texas grid.
No. In tech, well, the biggest, fastest growing energy in Texas is not oil or gas. It's wind and solar in spite of what the root and toot and cowboys may want to tell you.
So, Which makes perfect sense. 'cause it's hot, it's sunny, it's dry, and It's windy out, and it's plenty out on the planes. It's wide open.
So I mean, you go out to Abilene, Texas, you see wind turbines as far as the eye could see. And, um, it'll be interesting. And I, I, I'm not counting out nuclear either, jp.
I, I think this may be a catalyst to, to revisit that. And, and you know, we, Steven, we've discussed it on our show before. There's, there's new generations, there's these mini ones, the thorium, there's all different kinds of technologies we could bring to bear here.
I don't think that, I don't think the fat lady is sung yet on that one. So it was fantastic. It takes up space.
That's the only downside to it, is the amount of real estate it requires, but it, I mean, it can generate entire city's worth of Energy. Sure. You know, I saw an ad the other day, someone came out now I think what they were Korea from Korea, transparent solar panels.
You could have every building become self sustaining with that. I Didn't watch the video to, to find out if it was powering the train or not, but they were putting solar panels in between the tracks on trains and, uh, yeah. And they're putting 'em above, uh, parking lots in, in, in France above canals and rivers.
Um, all sorts of incredible ideas. Um, yeah, I don't think solar is the end all be all, but I think that it's just such a promising technology. And, and I agree with you.
I mean, I'm gonna shock you, Alan, I do agree that, that nuclear Has space. Wait a second. Wait.
I, I believe that Nuclear ed, you both agree with me in one show. Wow. I know, I know you're gonna, you're not gonna invite me back.
No. I'm wondering if something's gonna fall on me or something. All right.
Must had a good night's sleep. Anyway, Bonnie, thanks for a great sure episode on that. As usual, with all of Bonnie's, uh, videos, they are at Echo Tech, echo Tech insights, and you can get them yes on text tv.
That's right. Or our text strong TV OTT channel. If you have nothing to do, you wanna watch that laying in bed at night?
How about it? Um, but I think that's gonna call a wrap on today's text on gang. Thank you for watching Steven, thanks for a great report and participating jp, my friend, always a pleasure seeing you.
Hopefully maybe this week in Orlando, Mike, we'll be in touch. Bonnie, thank you. Thank you.
Remember, we've got a full text trunk TV lineup immediately following this, so stay tuned for that. And as Steven mentioned, if that mobility field day review, uh, wet your whistle, you can go check them out on Text Trunk TV or the OTT app right now. Until tomorrow, this Allen Schmo for Textron Gang.
We're outta here. Hey everyone, it's Alan Shimmel and welcome here to another Techstrong TV interview. Happy to back on our show, Varun Badis.
Varun is the CEO and co-founder for Indoor Labs. Varun, it's great to see you again. How's everything Alan?
Everything's great. Moving a thousand miles an hour, but that's what we left to Do as, as are we all it seems, right? Yes.
Where have you been lately? Have you, you in RSA or, Uh, we were at RSA, uh, luckily I came out bug free from RSA, so recovery was more, um, mental recovery and just, uh, uh, less, less a physical, uh, recovery and a lot of people that got sick as, as ends up being the case. But, uh, yeah, I, I did, I caught a nasty cold out there and I had to do a telehealth and ah, medicine up and everything else.
But, um, it's what happens when you got 40,000 people in one area. No. Yeah, it's gonna happen.
Yes. What, what'd you think of this year Show over all overrun? Look, uh, Alan, every year there's a theme in everybody, every vendor is talking about that.
It's no surprise this year was, uh, AI washing everywhere. Um, and, you know, I don't think it was surprising or shocking to anybody, but I think it was a great conference. Uh, it's always great to have that many concentration of security folks within a one mile radius.
And, you know, the compensations you have are, are deep and broad and, uh, you know, these, these are multi-year relationships that go a long way. Look for me, this was year number 23 at RSA. Wow.
It's a long, it's a lot of RSAs, man. I had a great time though. Anyway, hey, Varun, you, you've been, you know, I say 23 years at RSA give people a sense of your journey, not just at RSA, but you know Sure.
In in security in general and stuff. Yeah, I've been in security for almost 20 years now. Uh, you know, first four years were, as a practitioner in the last 16 have been building companies, uh, to solve problems that I saw firsthand.
com. Took my learnings from there to build cloud security companies, uh, one of which was Red Lock, one of the creators of the cloud security posture management category, sold out PA Alto Networks, built Prisma Cloud, had a great one there. And then in 2021, my team personally got hit by a number of software supply chain incidents, SolarWinds being one, Coca being another one.
And that kind of took me down a, a deep learning curve of, uh, how software is developed, or frankly, I shouldn't even call it developed how software is assembled. Assembled. And, you know, that took us down to creating indoor labs, which has really been about revolutionizing application security in, in the software development lifecycle, because the number one problem is that the, what I call the developer productivity tax on engineers.
Engineers wanna ship code security tooling is always slowing them down. And we've wanted to kind of break that barrier and solve it. Well, and happy to report that, you know, we're seeing tremendous success in doing that.
Absolutely. It is. com for 12, 13 years now.
And, um, but background in security, one, one of the things we've seen come is the rise of platform engineering, right? To help developer, you know, developers shouldn't have to develop their own platform. And when it comes to security, every developer wants to have secure code, quality code.
They need help, they need, you know, but they don't necessarily, the security tools for security people are not the tools that developers are looking for to stick with the Star Wars theme here, right? I mean, they, they want stuff that's more geared to them. And, and, and it comes out, you know, and, and it works in the environments they work.
And you guys over at Indoor Labs and, and we're gonna get into indoor Labs as, I guess we'll weave it in as we speak here, but you guys recently announced a partnership with GitHub to make it easier for developers. Tell us about it. Yeah, so we've been working for several years now with GitHub.
And, and as you know, like GitHub is eight, where 80% of the world's code lives. Um, and, and a lot of their focus has been how do you make security a native experience, just like you have bugs and issues. How does security just be an extension to that?
So developers don't have to do unnatural things outside of their workflow and go to different security dashboards and A SPM dashboards and try to figure out what is important and how they fix things. So the idea was for GitHub, if security can be a native experience to developers, things would get fixed a lot faster with very little pain. And we agree with that.
And so, with the philosophical alignment that the two companies had, we brought very complimentary technologies together. GitHub has, uh, amazing capabilities for secrets detection and prevention of secrets in code. And then they have great first party code scanning tool in a code ql.
All of these things are packaged and sold as GitHub Advanced Security. But the key part that Indoor Labs brings into that conversation is software supply chain security. 80 to 90% of the code is not written by your developers as all of this open source code comes in.
How do you vet it? How do you vet all the models you're bringing in from hugging face and deploying ad hoc in your applications? So for us, all of this has been focused on how do we complement each other with GitHub's power on securing the first party code and indoors kind of leading capabilities on finding and fixing problems and all of the open source code and now AI generated code, which we'll talk about also.
'cause as you know, you know, AI doesn't write novel code. It's all written and trained on open source software. So it's just giving you more derivatives, open source software, which are either equally good or equally bad.
Depends if you wanna look at glass half full, Well, you know what they say crap in is crap out. Right? And that's right.
That's Right. It's only as good as the guard rail you give it. Yeah.
So we provide the guardrails and natively both of these products are integrated to give developers an experience, not just to find and report problems, but to actually bring the fixes to them. And that Alan is a really fundamentally different approach that GitHub and Indoor Labs bring together to the market is where most of the application security testing tools just report problems. And then you send them by Jira tickets to your developers, and it lives in a backlog for months and years.
We're just bringing the fixes to them in their workflow, whether it's the copilot, whether it's any other ID they're using, whether it's in the pull request workflow, but it's completely native. The developers will never see a different security product experience outside of GitHub. Got it.
Got it. So if they're using copilot, you know, it's funny, we did a thing at RSA we do every year, the dev, the DevSecOps Connect event Monday at Mocon Center. And we, we had an amazing panel.
We, it was a full day, but one of the panels we did had the CISO of, uh, open ai CISO of philanthropic security tech lead for Llama and the CISO at Jfr, along with this woman Sol Roosh, who's written a lot of books on AI and former AWS and, and stuff like that. They said something that really resonated with me. The current state of AI is, it's not a pilot, it's a co-pilot, right?
We don't expect it to drive the plane or fly the plane. We expect it to help us fly the plane. And to me, that's very much your mission for developers.
You're not writing the code for them, you're not assembling the code for them. You are helping them do their code. And, and that, you know, in my mind, that's the, that's the proper mission, right?
That's the proper place for, for this AI kind of, uh, assistance. But how do you work with co-pilot, right? Without stepping on each other or stuff like that?
Yeah, it's a great question. So we essentially become a pair programmer inside of Cursor and Copilot and all of these other ideas. So what's happening essentially is a developer is interacting with the, with these tools to produce software.
And we are in there, uh, basically being the pair programmer that's bringing the security lens. Like imagine in enterprise, if every developer of yours could have a security engineer sitting next to them working together, you just wouldn't have a lot of these problems as depth in the first place. That's what it works like.
So developers asking co-pilot and cursor to write some code, it gives some code and or is reviewing and inspecting that as it's coming in and saying, listen, what you produce has these problems. Can you please rewrite it with this criteria? We basically have it rewrite and interact and a couple minutes later and or cur circuit copilot and your developer have now produced code that is, that functionally works and is secure, and this happens well before even a pull request is generated.
Love it. Look, there's only about, what, 30 million something GitHub users out there, 40 million Now, um, how can they get their hands on this indoor labs plug? Not, and I don't know if plugin's the right word, but, you know, companion, copilot, whatever you want to call it.
com and kind of kick, kick off from there. Also in the marketplace, you can have our GitHub action and our GitHub apps are available. Um, it is a subscription service, so, uh, you know, depending on the number of developers in your enterprise, we can, we can kinda set you up.
But that's the best way to get going. And I always say the, the proof of this is in seeing it in action with your repos. So we're always happy to set you up with an evaluation connecting into your own code repositories.
Love it. I love it. You don't mind.
Varun, I'd like to turn to something else. You are getting two for one here today, folks out here, uh, Varun, you got and or Labs also. I parted with like eight other security companies on something called Open gre.
Yeah. What, what's that one about? Yeah, so, you know, it's a good, it's a good segue, right?
We've been talking about GitHub and we've been talking about how great GitHub's native capabilities are for, uh, first party code security with static code analysis and such. But look, not, not a hundred percent of the world is on GitHub or not a hundred percent of the world is ready to pay for a commercial product for security. And so, uh, you know, for, for many, many years, uh, out there in the market has been a, an open source community edition product from a company called SEM Rep.
The engine is called a STEM rep engine that essentially allows you to write GRE rules very easily, um, to kind of look for functional issues, security issues and such, right? It's a, it's basically like a linting tool. And, you know, there's also a lot of community behind that.
But unfortunately, for commercial reasons, as a Business M Rep decided to make some changes to their licenses, remove some functionality from the Open Source edition, really forcing people to go think about paying for their, their commercial edition. And we fundamentally believe a GR pool like that is extremely important to keep independent and continue harnessing the community that has trusted it, believed in, and worked around it to scan your custom first party code. And so, essentially, um, when in December, EM rep announced these changes that are licensed, we worked with several other companies to create this independent, essentially an independent framework where no single company now owns the future of this critical open source project, forked it, it's open grab.
And essentially the nine companies that we are, have come together and funded full-time engineers to bring back in the functionality that SEM GRP took away and continue to expand on that functionality to arguably make it even better than the commercial variant of that engine. And the idea is that we would over time, hand out, over open grab to a foundation, so it continues in its long-term existence, independent without the risk of a single company kind of changing licensing or limiting its use as it is. And where Open Grab comes in is, it's a great LinkedIn tool and a grip tool for, for developers to, um, kind of write rules and customize finding, finding problems in first party code.
Again, like I said, not everybody can, uh, be paying for a GitHub advanced security license. Not everybody lives in GitHub. And so I think it's a great tool for, uh, for the community.
Yeah. First of all, look, anytime you can get eight, nine security companies to gather rally behind a particular open source tool, static code analysis, you know, that, that coopetition, whatever you want to call it, right? You, I mean, the potential is there to make this a game changing piece of a game changing tool in the quiver of, of AppSec professionals.
So I, I commend you, I commend the other companies involved for, for doing this. It's a great thing. Where can people go get open grab?
It's all, it's a community product. So, so, you know, you just go, go, go Google, Google search for open wrap, it's available, the roadmap is published, and you're, you'll be really impressed. Follow open grab on LinkedIn, I would say, because the velocity at which we are introducing new innovative features is incredible.
I haven't seen that before, uh, in many, many, many open source projects that I've, I've and I paid attention to. And primarily because the nine of us companies are literally Allen writing checks and funding full-time engineers to create this. So this is no longer a best effort of, hey community, it's Not a hobby, it's not anyone's, you know what, look, Varun, I've been an entrepreneur 30 plus years.
A lesson I learned pretty early on is if it's no one's job, it doesn't get done right? It's gotta be someone's job. Hobbies are nice, passion is great, but it's gotta be, if you want something done, someone's gotta have that job, right?
And so the fact that you're doing it is that's why you're getting the results. You are, someone is getting paid to do this and, and open, I love open source. I'm a huge supporter, but the day of the, you know, Richard, Dr.
Richard Stallman, and we're doing this for the love of, of software and freedom, people need to get paid. That's how things get done. Yes.
And that's why if you go to open GR dev, we've, we've put in the value, the mission, the long-term focus of this project, and then you can obviously interact with our development team on, on x, on LinkedIn, on Reddit, wherever you choose to be. Uh, we are, we are there. And we're really excited for the community, uh, just to use it.
You know, we've, we've got, uh, early feedback from people that have moved from re to open wrap that have seen 30% faster scanning. Um, really, so it's just pretty significant, uh, improvements. And so we're, we're excited to embrace the community as they start moving over.
Very cool. And, you know, with nine companies involved, you don't have to be worried about locking in and, and all of that other stuff. It's a great, thank you.
Thank you guys for doing that. Hey, so I could, you know, so what are you doing in your spare time? It's a busy world.
It's a, it is a busy world besides running around twin boys. We're almost turning five later this month. Um, good For you, man.
I, I think that right now, the biggest software revolution is ahead of us, and it's happening in front of our eyes, which is every enterprise is adopting an AI assistant or co-pilot to write tool. The implications of that are pretty significant. You'll have way more lines of code, you will have way more bugs.
So quality engineering, platform engineering, security engineering all become important, except all these hundreds of millions and billions of dollars are being poured from venture capitalists to create these co-pilots and create this problem of a lot more code. We need to retool the, the, the kind of defenders of this software, the people that are in charge to make sure this software is shipped securely with confidence to have their set of AI tools to do their jobs at a much faster, more effective pace. So for us, we think there's a entirely new set of problems that emerge, right?
Traditionally in security, we always worry about CVEs vulnerabilities known and cws. A lot of companies were addressing the architectural questions and design questions by doing design reviews, threat modeling, security champions programs, security office hours, all of that falls apart, uh, with the velocity of code changes that are coming. And so we announced at RSA, uh, or just before RSA, a new new product, an entirely new suite of products that are actually doing security code reviews with ai.
So we built a multi-agent framework. The idea was with Endor for the last four years, we had been building this very deep moat of, um, knowledge on open source software deeper than any other company on the planet. You know, we knew billions of risk factors on every open source projects kind of existence over time.
We had the graphs, we'd done deep program analysis and inspection of the code. We had built an entire database of that software. So now, when AI starts generating code for you, that's not novel, that's variations of open source.
We have the best insights to be able to secure it. And so Azure developers are writing this field and checking it in. We are now doing code reviews with AI agents that are looking at understanding not just the CD and the tactical stuff, but really architectural problems, design flaws in your application.
Did somebody change a session timeout from four hours to eight hours on an application? Unintentionally? Okay, somebody paying attention to that.
Are they aware that that's something that shouldn't happen? Or they're introducing a secret, a new secret manager, but that's not your enterprise standard of how you store secrets. Who's paying attention to that?
Or somebody's introducing a new API and not putting in the right authentication authorization per your superior coding guidelines. Who's paying attention to that? These are not known vulnerabilities.
These are design flaws and architectural flaws that are getting introduced with AI generating code and VI coders. And we have now built this multi-agent platform that is reviewing every pull request, threat modeling, every pull request, understanding the intentionality of the developer versus the reality of how it affects the architecture, and essentially automating that entire process of code and architecture reviews and threat modeling. I love it.
Did we, did we mention indoor labs? URL? I don't remember it saying it.
Varun. Yeah, it's really simple. com.
Uh, come check us out. There's a lot there. Uh, there's just, I, I will also say, unlike many companies, most of our technical blogs are written by our engineers.
So, uh, um, you know, we have certainly a marketing team like everybody else does, but our content is very, um, original and authentic by engineers for engineers. And there's one more thing Ellen I'll mention is we have a community for application security professionals called Lean AppSec. com, uh, which is really love it, just like open rep.
We're kind of creating this community for application security teams that are typically overworked, understaffed, to come get together as a community, talk about their problems, get recommendations from each other, and we're often doing virtual events and talks that the community is doing, we're facilitating. So, you know, if you're interested in application security, definitely check it out. Fantastic.
Varun. Hey man, I think we covered everything. I, I didn't think, you know, we didn't think we'd get it all, but we did continued success.
Keep up the great work. Come back and visit us soon. Varun, CEO co-founder Indoor Labs here on Techstrong tv.
We'll take a break. We'll be back. Hey, everyone, we're live back here, live at RSA conference today, closing out our Wednesday coverage, uh, day three of RSSA.
Um, our next guest is from Qualys, a company you all are familiar with. I assume all of you are familiar. We covered them enough here.
Um, her name is April Lenhart. And April, first of all, welcome to Tech Drunk tv. I know it's your first time here with us.
It's great to have you on. Great to be here. You certainly look very different than most other Qualis executives we've, we've interviewed over the years, so it's fantastic to see you.
Um, April, why don't we start with what your present position is at Qualis, and if you wouldn't mind, tell us a kinda little bit of your career path, you know, what your story is. Yeah, absolutely. So I'm a principal product manager at Qualys, and my, the main thing I focus on is cyber threat intelligence.
So at Qualys, I'm going to be working on really bringing cyber threat intelligence to the fore, working across all of our different products, seeing where we already have cyber threat intelligence and really bringing that out into a new product. In my past, I've worked as an Intel analyst, and from there moved into cybersecurity, working as a product manager at all different companies each time, really working on kind of nation state level actors and looking at how to bring out cyber threat intelligence across the industry. When you were an Intel analyst, I assume it was for the government, some sort of agency or something, or private Company As a contractor, really?
Yeah. And doing kind of the same thing, uh, geopolitical threat analysis. Um, I was the person who would walk into a metro and say, what is a physical threat vulnerability analysis looked like?
So when I then transitioned over to cybersecurity, it was like, oh, hey, this is what red teaming is, right? Yeah. So I knew it from the physical side and then got to do it on the cyber side.
Excellent. What a great story. And then you're also an adjunct professor at George Washington.
Is it Georgetown or Georgetown? George Washington. Georgetown, Yeah, Georgetown.
George Washington has a great pre-law program. George Washington University, but so does Georgetown too, actually. Uh, but that's fantastic.
And what do you teach there? It's at the, uh, security studies program, and it's called Cyber Threat Intelligence and National Security. The goal is for students who don't have a really technical software engineering background or computer security background who want to know more about, again, those nation state level actors, those apps, they get to dive into the world of cyber threat intelligence.
I love that. April, I, if you don't mind, I want to, as I said, most of our audience knows Qualys, worldwide leaders started really out in vulnerability management and vulnerability detection, and now vulnerability remediation, uh, threat intelligence. Uh, there's, there's many facets to the Quali Qualys product line at this point.
But let's, let's talk a little bit about cyber threat intelligence. Now, Qualys, I think they had a research team, a cyber research team for a bunch of years. Yes.
But in the last two, three years, they really tried to turn up the threat intelligence knob because they want to integrate it into the, the dashboard view right? Of, of Quas QBR and everything. Um, as part of your mission, what are you gonna do to the existing offering that raises that bar?
So I love that you brought up the analyst team. The threat research unit at Qualys is over a hundred analysts. It's a very, very big team, and my goal is to really accentuate the work that they're already doing and really just bring it to the forefront so people can really get a better sense of what our analysts are doing on a day-to-day basis and really contextualize that information.
So we're going to be able to see really quickly with any vulnerability or with any misconfiguration, um, what are the industries involved? What are the threat actors involved? What are the locations, uh, both from the victimology side and from the attacker side, really bringing all of that information so it's really quickly and easily, uh, easily accessible.
Absolutely. And I think that is the mission for Qualys, right? It's 'cause I, I remember speaking to them, whether it's Qualys own cyber risk, uh, threat intelligence feed, or even harnessing and plugging in the third party feeds.
It's, um, it's a valuable addition to the kinda risk dashboard, if you will, that they're, they're, um, developing. The other thing I wanted to mention is, you know, we were at the qualis QSC, I wanna say it was in Austin this summer, maybe it was right before summer. And, um, the, they, you know, they introduced this whole rock Yes.
A concept of a rock. Yeah. Not a sock.
A rock. Yeah. And again, that's another area where the thread intel right, gets, that's how you know it, it makes its way to, to operators, right?
Yeah. Who can use and act on that. Absolutely.
So the risk operations center of rock is the idea that unique enterprise threat management, you take all of your intelligence, you take all of your unified asset management, and now on top of that, you're also going to bring in essentially the probability of how does it affect me? How does it affect my business? How does it affect not just kind of overall the industry, but how does it take my business into account?
So you're looking at across all of the different assets that you have as company, and you're then saying, how does that specific, how does those specific assets that I have, how do those relate to the major CVEs that we're seeing? Um, so you can really stack rank and identify what's important to me, what do I need to patch if I don't, what are the major consequences? And you can even associate it by, you know, specific industries or, sorry, uh, specific, um, parts of your business.
And then within those parts of the business say, okay, if I don't take this specific CVE into consideration, how much is that going to potentially cost me? So it's really think of a risk operations center as not just saying, this is asset management, but also here is how I contextualize it for my own business, which is really taking it a step forward. Got it.
Um, now I, I realize you, you've only been on a few months and there's a lot of things, a lot of plans, a lot of offerings that are still coming together, right, for sure. That aren't public yet. Um, but what do you think to date has been your biggest kind of impact on the, you know, cyber risk intelligence or threat management for, for the Qualys product?
I like to think that right now it's bringing in that contextualization piece. Yeah. So again, just coming in as a, a subject matter expert, being able to lend the lens of this is what, as an analyst, this is what I would want to see.
So very similar to how a rock, uh, brings in that extra layer of contextualization, I also want to come in and to say, this is how it would be relevant to the greater industry. Got it. If you don't mind, I want to turn to RSA this week.
Uh, you know, as usual, RSA is chockfull of security people, right? And a lot of security, 600 plus sessions, all kinds of things going on. You are on a panel I hear Monday.
Yes. Tell us about that if you can. Well, honestly, the best part was that since we were the very first session of the very first day, we had first mover advantage.
So anything we talked about was just going to be repeated by everyone else for the rest of the week. Um, that's how these things go. And that was ideal.
So our panel was on AI and GRC governing risk compliance, and it talked about everything from kind of our outlook on AI as a whole to getting a little bit more into GRC where the industry is now, and where we see it going in the future. Um, so tell us about it. I mean, 'cause I mean, look, certainly AI is the talk of this conference as it is the talk of everything in tech today, you know, but one of the things we've been talking about here for the last two, three days is, no doubt it has the potential to be huge, but how real is it, how much of an impact is it making today in, in the field of, of, of governance risk and compliance?
GRC? How big is AI today? Not what it could be, but today For sure, there are a lot of ways that it's already made a major impact in terms of being able to scale up way past what otherwise a human would be able to do, right?
So there's a lot that AI has already been able to contribute to as far as adding in metrics, again, adding in contextualization. However, there are definite, uh, limits to what humans are comfortable with and what companies are comfortable with deploying. For example, we still haven't gotten to the point where you can have age agentic ai.
That is where we're completely comfortable saying, you know, set all of these rules and, um, completely act on your own free will to determine if you see any new threats, block everything, essentially. Like, think of like a, a completely automated SOAR where there is no human involved in the process. We have not yet gotten to the stage where we're comfortable with a human completely being removed.
We still want there to be that emergency stop button. So it's fair to say that AI has really significantly contributed to having us grow in this industry, but we aren't completely there. We haven't reached that pinnacle of saying, yeah, we can just set it and forget it now.
Right. Um, Well, and, and I don't know if that's a worthy goal, to tell you the truth, maybe may just maybe the, the future of ai, at least near term, short term, is just to enhance the human, not to replace the human right. And I, I, you know, I think that's a good lesson for all of us to look at.
You know, a lot of CEOs and, you know, executives get up there and say, we could cut head count. I could get rid of all my intern junior coders, I could get less security professionals. No, that's not really what it's about.
I think not today anyway. I, I think today it's more about how can I make more my people more effective? Sure.
How can I enhance our security posture that, and it's, and it's AI in conjunction with a human helping a human. I heard someone say it at an event we put on Monday, and it really struck me at this point in the day, game AI is a copilot, not a pilot. Yes.
I think that's a very apt way to put it. Yep. Uh, AI is a really great tool for augmenting what you already have as a way for thinking of unique solutions to a problem if you are able to then correct it.
Yep. It's not a great way of teaching new solutions to a problem when you don't already see pathways to get there. So in the same way, um, within GRC, it is a very good way of saying, you know, I already know how to get to the end.
Show me different ways to get to that same end. It's not a good way of saying, show me, show me brand new things where I don't already know what to do. So, Got it.
Very similar. April, I want to wish you success in this new role, fairly new role at Qualys. We'll be watching to see what comes out on threat intelligence.
I actually, I'll say it here, we're actually gonna be at the next, uh, QSE Quas Security Conference, which I think is in Houston. And we'll be, you know, shooting live there. And we'll catch up there.
Thank You so much for having me on today. I really appreciate it. Nice meeting you.
Okay, great to meet you. April, Len Hand, uh, Qualis, I, I forgot your title. I apologize.
Principal Product manager, Principal product manager, Qualis here on Tech Drunk tv. We're gonna take a break. We'll be back.
We've got a few more interviews to do today before we wrap up. Day three, you're watching Textron tv. Hi, everyone, I'm Guy Berger, analyst at FU and Group, and I'm pleased on this text on TV episode to introduce Gary Thornhill.
He's the CEO and founder of Popup Mainframe, and we're gonna be talking to him today about popup and about Mainframe. So, hi Gary. Welcome.
Hi. Thanks for having me. As my name is Gary Thornhill.
I am the CEO and founder of Popup Mainframe. And interestingly, we created Popup Mainframe originally in a, through a DevOps consultancy, actually solving directly customer issues around, uh, addressing the shortage of dev test environments. So that's, so that's how Popup Mainframe was founded, um, addressing a, uh, a particular client problem.
And then it wasn't just them that need this, it's, it, it's, there's, there's an issue around the speed of, uh, mainframe change. So popup mainframe accelerates mainframe change, and it does it more cost efficiently than ever by providing mainframe delivery teams with an immediately available fully functioning mainframe. Our product revolutionizes mainframe delivery by removing the most common place of challenges, which is the bottlenecks caused by the shortage of environments, access issues, and quite often too many teams and too much bureaucracy.
So we, we, we hit those, uh, directly head on. So you're providing mainframe environments as a service and hosted in Azure? Correct.
And I know you had a product announcement, we're gonna get to that, but, but it, it's pop up in the sense of it, you know, with an Azure or account takes you a few minutes and you have a, a mainframe environment, a a Z systems mainframe environment available to you. Is that right? Yes, and it, but it's not just Azure.
We can actually run in any cloud. So any X 86. Yeah.
So any X 86 architecture, so that can be on-prem, it can be Linux based, windows based, and in any, any hyperscaler, we can pop up a mainframe in less than 10 minutes and they can be logging onto very own, um, mainframe, albeit is running on Linux, not on or not on Z. Okay. But it's, it's, it's compatible.
It's a, you were talking DevOps. Um, I know that in the mainstream world, um, uh, for many years now, um, there has been an increase in, you know, uh, the cloud integrations or cloud-like behavior, um, for the mainframe, even as it continues to fulfill its core mission of some of the most, um, intense mission critical, um, key applications and, and, and data processing, um, uh, scenarios going on in the world right now. Right.
Um, what, what would you say is the, is the current state of the mainframe like today as far as that progress has gone and what sort of uses it's being put to today? Because it's, it remains a vibrant market. I mean, yes, and interestingly enough, I think the, the mainframe market and, and IBM are selling mainframes with, with 10 digit growth every year now.
Um, so it, it's never been more in demand for, its, it, its processing and reliability, but I think Reliability is a big thing. Yeah. Yeah.
It, it is. It's really the only system that has that really true hot failover because of the parallel plex, which has been there for years. Yeah.
But one, what, what is, um, what is the challenge is, is to deliver at speed on the mainframe because, because of the reliability it does, it tends to be a bit of a shrine with the way that cha the way that change happens on it. So if you think about, think about the modern enterprise, you've got so many different platforms and they're all interlinked, I think, I think the challenge is for organizations is that the mainframe delivery can be slower and more expensive than other areas of the organization. And, and that is, uh, a big challenge for CIOs because they want the reliability and, and the processing, particularly as AI is, you know, is, is is very rapidly coming on us.
Um, but you know, things still have to happen at pace. Um, and you can't afford to, for projects to take months and months, it's gonna be done quickly with quality. There's the continuing reliability, and it's not just amongst the biggest firms in finance.
There's a continuing reliability and government, actually, there are a number of sectors on the mainframe. But what you're highlighting is that because of the nature of the mainframe, the benefits you get have come with a fair number of controls and operational issues that create those challenges of, you know, moving fast. Is that, is that a fair characterization?
At least, you know, up to this point? Yeah, I mean, I think, I think you, you summed it up well, uh, I mean, obviously, uh, the organization wants to have its cake and eat it, right? It wants to have that reliability and speed, but why can't change be done quicker and, and respond immediately to market demands?
Why, why shouldn't a, a mainframe, why can't, why can't you make change in a mainframe? Like you can make, um, in the web or applications? You should, you should better do it if the process is there.
And this is where the mainframe to me, needs to mo to modernize. It needs to modernize more around the process and how it's used just as much as the technology needs to advance Well, being able to spin up the equivalent of a mainframe in any X 86 compatible cloud service providers environment, which is what you described at the beginning. That sounds like a promising way to address that challenge.
But, but, but first, um, I know you just, uh, conducted a market study on this. Um, so why don't you tell us about that? 'cause that seemed to provide some interesting insights into this whole mainframe question.
Yeah. Yes, it was, it, it, it was, um, very insightful, and obviously we don't need to tell you guys, but the most important opinion about any market is from the market itself. And we wanted to learn more about some of the specific challenges facing mainframe delivery teams today.
That survey is just finished and we're just publishing the results. Now, What was the most interesting data you got back? Um, Paul point to Let's go through the whole survey.
Yeah, No, no. That, that, that, that would take us a while. So funnily enough, what, and what we've talked about is what, what was reassuring was the absolute overwhelming loyalty to the mainframe that the clients had.
And also there's, there's very much a demand to use, um, different processes like the Linux, IFL. And, but there were a number of, of, uh, challenges raised by most respondents. Um, a good example was that 96% said they had challenges developing and testing on the mainframe, and a third of all responders also said they were in critical need of more mainframe environments.
You were talking earlier, you said that popup mainframe sort of came out of a, a, a DevOps engagement that you had. So this is a really interesting contrast to me. I mean, DevOps is certainly about, you know, uh, rapid builds, uh, rapid promotion, continuous development, you know, that sort of thing.
What often gets forgotten is the ops side of it. Um, and operating mainframes is, uh, is, is a thing of its own really important, a critical element of it. Um, so, so when you're talking about dev and tests on a mainframe, and almost all of the survey respondents said that they were, they're, they're challenged in this, and a significant number of them said they're, they're limited by the number of mainstream environments they have.
Um, that really seems to play into this idea of cloud-based mainframe, so to speak, being something valuable provided it's operated correctly. Provided it's maintained correctly. Yeah.
Yeah. Uh, you know, just, just to elaborate on that, I think traditionally, I guess where you have, you know, a very high performing, um, piece of hardware, that hardware has a cost. So environments are generally, um, set in stone, and when there's, and when you need another environment, you are tempted to use an existing one.
So you start getting an interwoven ness of applications and different projects happening. Yeah, Yeah. And what, what tends to happen is, is that you find, you, you, you find environmental bugs and things don't work.
So if you look at the distributed world, you'll see that typically in with a cloud, for example, if you, if you've got applications running this year, when you want a new one to do something new, you spin it up, do your work, take it down. That's not really a concept that is, that happens in mainframe. But with popup mainframe, we can do that spin up.
So it's about spinning these environments up very quickly, moving the application on there. And we can do that using, taking it outta GI and modern ways of doing that. You then do your work and testing, you've got this agility around a popup mainframe where you can forward and rewind it, copy it to another one.
You get all this agility, so you are working analogous to in a distributed world. Um, but it, it is, it is, uh, using a fully functioning mainframe. And that's, so that's really the power of the solution.
Is it, is it running on IFL at that point? No, so, so we, we originally started with the, what, what, what was the popup mainframe, which ran on X 86 and, but now the X 86 version is known as popup mainframe on X, and now we've got a popup mainframe on Z. That's the announcement, that's the announcement you just made.
Okay. So you have the X and Z, so X is running on X 86, and so is Z running on IFL? Yeah, Z runs on the, the IFL processor on the physical mainframe.
And you can also run it on a Linux one box as well, which is a specific, uh, Linux server, and you can run that as well. And all of this is only development and test you can own. You can never run production workload on a popup mainframe.
So IBM will, will be pleased that I say that out loud to everybody. Okay. So, so, uh, I feel like we, we zipped right past the lead of this interview because the big reason why we're doing this interview is that announcement.
Um, so you now have a popup mainframe, which originated as a way to pop up a mainframe environment for dev test, uh, or dev test, let's say on, on X 86 based cloud. Yeah. As of now, today on, you've launched the Z version, which is actually running on IFL, if not LinuxONE.
That's cool. So you have to do my mind, my, my, my mind, and I'm always thinking like lifecycle. And in this case, and he would mentioned DevOps many times, this is a way of, of these ways exist, but this is like a more agile way of using the DevOps workflows or mainframe development along with your other application development, right?
That's how I'm looking at it. So I'm seeing this nice progression. There's sandboxing, there's dev tests, there's these ways to do mainframe development quickly prior to production use, which would be on, you know, a physical mainframe.
Yeah. Is that correct? Yes.
So I think we've, we gave you X we've given you Z, but the thing we missed out is the Y, Um, you mean YWHY, don't you? Yes, yes, yes. Okay.
That's a good one. That's why I Go ahead. So Y yes, YI just gave y maybe I'm wrong.
What's the Y? So the reason why we, we also moved to z to, to, sorry, I, I slipped then z um, was because the thing about a popup mainframe, it uses hardware emulation. So it's, you are running exactly the same code base, um, on a popup mainframe then, as you are on a, on a real physical mainframe, okay, you can match it to the, in IBM terms, it's called A PTF, which is exact fix to a particular subsystem or what have you.
Um, but some of the community and clients do not want any of their mainframe out running on X 86. So the, the mainframe is the mainframe, and in some organizations, no data should ever leave the mainframe. So for whatever reason, so they would not, they would not buy a popup mainframe on X.
So we bought out, um, popup mainframe on Z is to emulate the physical mainframe, but also on the mainframe. So you get, and, and, and here the client can have, can have both. Their mainframe still stays on the mainframe, but they get all the benefits of the virtual environments.
They can, um, take a mainframe, save it to disk, bring it up later, um, put another copy into another, onto another processor for whatever reason. Um, and so, and there's also a scenario where clients can have both X and Z. So you could, you could build up your goal copy on your IFL, and then you could send copies of that to a hyperscaler cloud.
So you could have almost like lpar, fully functional mult multiple users on these large tests, on these powerful test environments. But you could spin up copies for other teams doing smaller bits of work or in feature teams in the cloud. So you could ha you, and you can really benefit from these lower cost, um, dev test environments.
So, so what would you say to people who, uh, who are really, like, been doing this sort of work for years just just on the hardware, right? What would you say to them if, if they express concern to you about security or, or, or, you know, uh, um, management, uh, data protection compliance. Yeah, like that sort of thing.
Because I think that although, you know, CIOs certainly and CTOs and IT shops have embraced the cloud, especially in sort of hybrid form as the capabilities have gotten better, I think, um, and that includes the mainstream folks. I think, um, there's a certain, um, there's a certain, uh, uh, guarded nature about using the cloud for these, these workloads even in, um, pre-production environments mostly 'cause of, of, of data control. So what would you say to that?
Yeah, so it's, it's an interesting question a lot and a lot of it is perception. Um, I think with, with, with the cloud. So, you know, you, when you look at a pipe popup mainframe, you're securing it a number of wa of ways you are securing it.
You can secure it exactly the same as your physical mainframe with, with the same tooling and the underlying security as, as well as, you know, infrastructure, the firewalls and what have you. So you could, you can, you can actually secure it at two levels. You can secure it around the cloud security and Linux security, and then you're securing the mainframe as well, running on Linux.
So you can get multiple levels, uh, of security on that and probably make it even more secure than, than say, a physical mainframe, because you, you've got, as I said, multiple levels of security, one on top of each other. So, you know, I, again, I think quite, quite often there is decisions around security are quite often that, that are patterns more so than what does the organization need? And okay, we've got a way of doing something different.
What is the best way of securing it? So you could look at it differently. Um, but you, you know, there are some organizations that just say, you know, that's not secure having a, a popup running on, on the cloud for, for whatever reason.
And, and quite often it's not, it's not being explored. It's just a, a blanket statement. Uh, and I think, I still think just Gary, I still think there's a fair amount of, uh, misunderstanding of, of security in the cloud.
Uh, yes, there, there, there have been issues and, and I, I wouldn't want to name names here, but certain of the biggest cloud providers have, um, maybe enabled capabilities and services, but not forced them or required them. So you see continued breaches. But what I'm leading up to is the fact that that truly some of the best security systems in the world, and again, I'm not gonna name names, have been implemented, are available and in place in these cloud environments.
Yeah. And, and with the expertise certainly and, and the right configuration work, um, you know, you, you are quite able to achieve better security than, than, than in most cases you do natively in your own shop 'cause of what's available. And I don't think that's fully understood even today.
It sounds like, um, you might be taking advantage of a lot of those capabilities. Is that, is that true? Yeah, I mean, uh, you're exactly right.
So, you know, we, we, what what we can say to clients is, is i, i, is that you can, um, you can run your popup in a variety of different ways. You can pretty much secure it exactly the way that you secure your physical mainframe today, the exact security controls. But, you know, would be that, would that be the right thing to do?
Um, and you can run pop up mainframes, depending, so what, you know, the, the first thing that we always do is make sure that the data is, is compliant. So we have lots of masking strategies just about user data itself, and then you're looking at access on the popup mainframe. But you can, you can use all the modern software and approaches for secur securing on the mainframe, and then you can put a cloud S-S-L-V-P-N layer, you know, and you can just keep on adding to this.
And of course, always the weakest point of any security, uh, is someone's own access itself. Yeah. And that's not going away, is it?
So, but we always, when, when, when we start working with clients, we always try and understand what the, what they, you know, what are they doing today, and we can help them improve that, um, nine times out of 10, um, by adding in these different layers. Um, so, so, so that the way that they use it is, is secure. Um, but um, it's, it's having, it's involving the right experts, uh, at all levels, um, to meet, to meet the requirements.
Well, yeah. And you're, you're addressing that question, um, with your, with your product and with your, your announcements of today. So that's this nice, um, dual option of the X and the, the Z additions.
Um, one more emulation, the other one, you know, direct IFL or, or, or LinuxONE on both of them for, uh, a quicker, more responsive way to work towards the full production environment that's gonna be on your mainframe or mainframes. Um, I think everybody should check that out. Um, who, um, is interested in, um, and working on mainframes today?
Um, the, the study, I actually, if I remember right, the survey that you did, um, uh, we might be discussing in more depth on a webinar coming up, um, also at Textron, uh, in, um, in, in a month or so, I think, um, June 18th. Uh, so, um, I would encourage everyone also to look out for that. Um, uh, Gary, is there, is there any other notes and bits you might wanna mention about the announcement today or about that study to, you know, keep everybody, uh, excited and interested?
The webinar will show that the, the mainframe is a fanta fantastic production engine. So whatever apps you're building, whatever Xeros box you're on, whatever data you're using, I imagine there are some bottleneck a day you wish weren't there. And we can show technicians, PMs, and change managers how mainframe dev tests can be approached differently.
We're here to discuss those issues and present an approach which we think will be a game changer for mainframe delivery teams. But in order, in order to move with the times you've got these new technologies, but it's about how we improve delivering change on the mainframe. Um, there's a continuous need and desire to modernize not just what the business process the mainframe runs, but how quickly they can be built and, and, and you can get both benefits, um, from X and z.
I mean, certainly with, with z what is interesting, so that, that, and just of your previous point, they're both, they're both emulation, but um, on x, on X 86, um, you don't get the full benefits of the mainframe processor. So you are emulating the way the CPU and the disc io, whereas with z it, the, those are native, those are direct process, yes, it goes direct native. Um, but the IO is emulated.
So it, it does work slightly differently, but it's more closer to, uh, the real physical mainframe and, and performance is significantly, um, improved. Um, but they both help clients align with how, you know, how, how you make change in the distributed world and splitting things up and down on demand. And it also has a very important using pop-up mainframe, um, massively.
Um, IM, IM improves your, the sustainability side of things because Yeah, I was just thinking about efficiency when you were talking about that. Yeah, go on. Yeah, so I mean, it's one of, one of our clients literally saved half of its Azure costs and, and reduced its carbon footprint by half by just switching off for 12 hours a day when they weren't being used.
So that's not a concept you have on a physical mainframe and there's always things running normal. Yeah. But you can just, um, with a popup mainframe, two things.
First of all, you can switch it off when you're not using it. Um, so it doesn't sit there and just, just, um, just using electricity. And the second thing is, is that because we have this unique forward and rewind capability, which we'll touch upon is that, um, you can take a checkpoint at any point in time, um, and come back to that.
So just the efficiency gain you get from not having lots of bodies, um, making changes and clearing down logs and resetting tables, DV two tables or other thing. Instead, one person can go into, uh, a gui, take a rewind, and then you're ready to repeat a cycle of testing. Now that is a huge efficiency gain.
Um, and mainframe is famously, uh, renowned for being the most sustainable platform anyway. 'cause you've got so many processes running on one piece of tin add, popup mainframe to the equation where you can reduce the amount of head count required to do, to do work and at speed has a huge environmental, um, saving for it. And I think that's very important, particularly the advent of ai, which is, um, gobbling up so many resources.
Um, we've gotta always have a, have an eye on, you know, how, how we can be sustainable by the use of it. Well, I look forward to hearing more about that then. Hopefully I'll be on that webinar myself.
This is a fascinating topic and definitely an area of interest and pursuit for many kinds of enterprises around the world running some of the most important applications, uh, being run right now globally. Uh, so Gary, thank you for joining us. Um, thank you for joining me.
Um, thank you for talking about pop-up mainframes and what's going on in the mainframe market, uh, and mainframe development right now. I'm Guy Courier analyst with the future of group and it's been my pleasure to present this to you and I'll see you next time. Hey everyone, we're back here live at RSA conference.
It's Wednesday morning, things are starting to kick up here. We've already had a full day. Of course, we recorded our tech Strong gang at about eight o'clock this morning.
Then we did a new segment special here for RSA called the Analyst Stark with, uh, three Futur analysts and talking about their vibe, not vibe, coding, their vibe from RSA conference. My next guest needs no introduction to our audience here. He is one of our good friends.
One of the, you know, I don't wanna embarrass him, but he's one of the founders of the AppSec movement, right. Early on with swa, everything else. Uh, he is also a co-founder, right?
No, you're not. You're C-T-O-C-T-O And founder at Contrast and founder of Contrast Security. Yep.
My friend Jeff Williams. I knew you were co-founder, but I always say CEO and it's CT. Right?
Right. That's why I wanted to make sure I got it right. Jeff.
CEO's a terrible job. C CTO's a much better Job. Job.
CTO's the job you want. I, I agree with you. Um, but you know what, young kids out there don't know that everyone's gotta find out for themselves, I guess.
Yep. You live and learn. Anyway, Jeff, it's great to see you here.
Good To see you too. What is this? Maybe seven, eight RSAs maybe more?
Yeah, I've I've done Yeah, more like Probably 12. Well, I'm saying that you and I have IED together. Yeah, it's a lot.
Oh, oh, I've become an RSS a since 2002. Right. So yeah, you similar kind of thing.
Um, you know what, Jeff, let's start off though. Maybe there are some people out here don't know contrast security. Just quickly.
Yeah. If you don't mind. Yeah.
So we're an application security company. Uh, application security risk is accelerating really quickly now, particularly with vibe coding and, and other things. Mm-hmm.
And we take a runtime approach to application security. So we actually watch the code run, give you real details on what's really exploitable, who's attacking you, what libraries are actually in use. Like it's all measured directly from a running application.
So it's real, it's not theoretical results. Right. And, uh, we do that to keep you safe and more importantly your customers and children safe.
Absolutely. Well, no kidding with children Safe. You know, Jeff, one of the interesting things about contrast, and I've told this to people before and I got this spiel down now, is for much of the AppSec industry you focus on the AppSec industry focuses on the security of the application before the event horizon of deployment.
Yes. Right? And that's like sort of a black hole, right?
That deployment event horizon. Yeah. And all of our, and if we could say all of our AppSec focus is left of that horizon.
That's right. Traditionally, Traditionally. And, and for good reason, you it's supposedly faster, cheaper, more efficient.
Well, we should talk about that. Absolutely. But recently, I know Contrast, what was the movie Interstellar, remember that movie?
Yeah. You've gone through the event Horizon That's Right. Through the event Horizon, where They come out the other side and, and one of the few AppSec vendors that actually have a story about real runtime application security.
Right. Uh, and to me that's what sets you apart. I don't know, as a CTO, you have a better handle on this than me, but as an observer, that's what sets it apart.
Well, you're exactly right. Traditionally, we've put a lot of bets down on helping developers write perfect code. Yep.
But I, I don't know. Do you feel like developers writing perfectly Secure code? I don't think there is such a thing as perfect code is the problem.
Yes. And, and it's, I think it's like a holy grail and It's a moving target. Yeah.
'cause stuff changes. Um, it's Like saying, I'm never gonna publish something that doesn't have vulnerabilities. And the, so we've put a lot of bets on that.
Yeah. And frankly, it's not delivering. Right.
Right. Like, most companies have massive backlogs of vulnerabilities that they're not triaging that that whole approach to the problem just doesn't really work. Mm-hmm.
And so we had, uh, the insight to say, Hey, you know what? In production we can see everything. It's not, you know, in, in development you see pieces of applications.
You see one repo of 20. You see, uh, the libraries, you see the source code, you see the APIs all separately. But in production, they're all assembled together.
You analyze the whole thing at once and you can see exactly where it's being attacked. Exactly. Where it's vulnerable.
And you can help companies focus on the, you know, the few percentage points of issues that are real. The ones that have crossed the event horizon that are actually being attacked in production. Mm-hmm.
Those kinds of problems. That's where you wanna spend your, your very limited critical AppSec resources on fixing those problems. So, even though it seems counterintuitive to focus on security to the right, 'cause people like the idea of shifting left Right.
Problem is, it just hasn't worked. It's, it's backfired. com.
'cause I think people realize that you, when you over shift left, what are you saying? Your developers, your security guy, I'm not saying developers raise their hand and say, man, do I like to write insecure code? No.
Developer says that. But you don't have developers raising their hand and say, I'm your security guy. Also.
True. That's not who they are. Also True.
And so that, I think the whole rise of platform engineering is recognizing we can't ask developers to build their own secure platform in addition to coding their apps. Someone's gotta do it. Yeah.
So the way runtime security works is, is very much like other kinds of detection and response. Mm-hmm. Like EDR and CDR.
Sure. One thing to realize, those technologies don't stop application layer attacks. Right?
Yeah. They see stuff in the kernel layer or in the cloud or whatever. But there's a gap, the application layer.
Yes. And so into your platform, you install a DR and it instruments the actual running applications and watches it as it runs. That's how you detect things with full context.
And so after that, it, it works just like the rest of the XDR ecosystem. Sure. You, you know, telemetry gets collected, there's a dashboard, but it also goes into your sim and you can correlate it with the rest of your events and so on.
But it's, it's a very natural part of operations. I, it's just missing. Agreed.
Let me ask you a question. You know, I was a Q con in London last month. Observability.
Yeah. Everything's observability. It Is.
How does the a DR play in the observability, this new universe of observability? Yeah. It's a very similar concept.
In fact, we call it security observability in a lot of contexts. Fair enough. And observability is interesting.
It started to the left of boom, like in, in development. Mm-hmm. And companies like New Relic and AppDynamics and so on, you'd monitor development.
And then they realized, Hey, what are we, what are we measuring test systems with? You know, not real data, not real users, not real load. And they're like, well, this doesn't, it's not realistic.
'cause they didn't have the right context. So those tools moved into production and they measure real reality in production. Yep.
Uh, and that's the same transformation that AppSec is going through. Yeah. That's, if you measured in test environments, you don't have enough context.
You don't have real users, you don't have real threats, you don't have real anything. Yep. And you get all these theoretical findings.
So when you move into production, that's when you're measuring reality and you can focus on what matters. And that's, that's what we're helping companies Do. You're walking in that same footsteps here.
Exactly. Right. It's, it's the logical route.
It's how stuff evolves. So in our never ending quest for the single plane of glass, be you envision a future where security observability and, you know, call it mainstream observability or whatever, can be in the same interface, could be in this, the same platform. I could imagine that, although I think it's more likely in the short term that we'll see it as part of, uh, CAP and Sure.
And sim kinds of integrations that, that data, they're already collecting security telemetry and building a security graph. And our data, you know, we have a graph. It fits into the other graph.
Like that's, that's how that works. Observability is a little bit more of a junk. 'cause it's different users, right.
I think today, but ultimately, if we achieve the vision of DevSecOps, that we'll break down those silos and everybody will be working off one model of reality. We call it a digital twin. And, and that's, it's come a long way now too.
It has, especially with ai. It has. So we're building a digital twin of your application layer.
Not one app at a time, but the whole thing. So that, wait, this is new to me from you now. Yeah.
Let's start over here. Yeah. So talk to me.
So imagine you've, you're a big complex enterprise. You've got hundreds of thousands of applications all connected to each other. APIs containers.
Right? Now we're all confusing. So when you deploy contrast, you can deploy it across that infrastructure.
Like we got a Kubernetes operator. You just push it out. It's part of platform engineering, right?
Absolutely. You push it out, then the telemetry starts coming in, and we take all this telemetry that's coming from all these apps saying, you know, things like, what's the attack surface? Where are the vulnerabilities?
Where are the attacks? Where are the assets? All that's coming together.
And we're building a digital twin. It's, we call it the contrast graph, excuse me. And it's, it's a model of how your application layer works.
It's a lot like the wiz graph, except for it's not infrastructure. We're talking about another layer of abstraction, all the, how the application layer works. And with that, you get a lot of benefit.
You can put vulnerabilities in context and say like, oh, well I understand this vulnerabilities in this app, which has this blast radius and mm-hmm. You can really get good risk rating. And you can use that data not just for like, vulnerabilities and attacks, but you can use it to feed into your threat modeling process, your Sure.
Pen testing process. No, I'm, I'm a big believer in the digital twinning. I, I think one of the nice things about all the AI buzz that goes on and, and our ability now to kind of get our hands around bigger, uh, infrastructure or, or bigger Pictures.
That's what we had to do, is it's not easy. Our old, you know, two years ago contrast used, uh, our telemetry flowed into a SQL database. Right.
And that's limited. Doesn't work. Right.
So we moved to a modern streaming data architecture. It's Kafka, it's graph databases. And we're, we've built a massively scalable data collection Platform.
That's what you can do that. It's, It's because our new CEO from Splunk Oh. So obviously, Yes.
And he came in and said, Hey, you know this, we need to collect more data, not less. And so we've just been en enhancing our telemetry, building a a, a awesome Model. Well, no, once you're able to get your head around or your hands around all that telemetry, now you start applying the AI and stuff stuff.
Exactly. When you start seeing insights that you, you, you just couldn't see before. Runtime security and AI go together like peanut butter and jelly.
Like no doubt they're, because runtime is is real. It's measured directly from running apps. It's not theoretical stuff.
It's not because of false positives. So yeah. They, they go together really well.
Love it. All right. This camera's on you.
Right? Okay. Tell them how they get, how did they go get this today?
Yeah. Uh, it's, it's easy. I mean, you can go to our website, you can learn a little more.
com. Right. Okay.
And, uh, there's stuff you can try. If you want to give it a, give it a spin, um, we're happy to come in and do a POV with you. But the, the deployment process is easy.
You get our installer, you push it out to your, your containers or your workloads, wherever they are. Uh, we don't really care whether it's on-prem or in the cloud or whatever, whether it's APIs or applications. Right.
We support all of that. And, uh, almost immediately the telemetry will start flowing. Uh, particularly if you deploy in production.
And that's really where I think you should, yeah. Put it. Then you're gonna see you, you'll get amazing visibility into what's happening.
I will tell you, you're probably in for some surprises. Like there's probably a lot more attacks going on on your application than you, you thought. Yep.
And attackers are probably reaching vulnerabilities that you didn't think that they were able to reach. That's, you may find some log for shell that you didn't know about. By the way, we Always, it seems it's all out there still, Jeff.
Good stuff. Really good. I'm really, you know, it's not often I get to hear new stuff like, Hey, application security has, has not been innovating as fast as Do even know It.
Uh, you know, with, with the boom coming from AI development, I mean, if you're, if you're producing Get our ducks in going 50% more code or a hundred percent more code, I don't find way to EC team is gonna double. So you need technologies to help you scale into that double. We don't have enough abec team as it is for what we were doing three years ago.
Anyway. Hey man, this is great. I love it.
You're doing a great job, Jeff. And man, you're the best. Alright.
Jeff Williams, contrast security. Go check out what he was talking about here, because this is the kind of stuff you're going to need. Not three years from now, not two years from now.
Now we need it now. Go check it out. We're live at RSA conference.
We'll be back in a minute. Hey guys, thanks for the throw. We're here with Marco Paladino, who's CTO for Kong.
And we're talking about event driven architectures, APIs, and maybe the need for some gateways to simplify this whole thing. Marco, welcome to the show. Yeah, thanks for having me.
As long as I can remember, event driven applications were among the hardest to build. They're difficult, they require a lot of challenge. Uh, and yet in the modern world, just about everything we do is event driven.
Now it seems like we have, uh, processes that everybody wants to run in real time versus batch. And so the nature of the applications that we're building is changing. Is there some way to approach this now that would make it simpler for people to kind of build and deploy and manage event driven architectures?
Uh, there sure, there sure is. Uh, like you just said, events are a critical component, a critical, uh, protocol that organizations are using to build modern applications. You know, of course not everything that we do, it is necessarily service to service.
That's, you know, what traditionally we think of microservices. Usually we think of service to service connectivity. Some of these connectivity happens asynchronously through events.
So we're publishing events to topics. We're consuming these events. Uh, this is great if we have large batch processing.
If we are lots of data that we need to process at scale, it is great if we want to pick up events where we left off in case our services are down. It can happen with high availability. So events truly, truly are a very important part on how we're building applications in 2025 and beyond.
And of course, like every other type of connectivity that we're building, whether it's s connectivity, whether it's service mesh, microservices, connectivity, whether it's AI connectivity or not, events also are part of the picture. And so at COG, we believe that events also should not be left outside of the platform that we use to govern our traffic, to secure it, to observe it, uh, to manage it. And we should instead bring events on top of that platform so that the organization has both the ability to control that flow of traffic, apply the right level of security, the right level of governance, but also developers, uh, can start sending and consuming events in a much quicker way without having to build the underlying infrastructure to process these at scale.
So, uh, we believe that, uh, events therefore have an opportunity to be simplified. Uh, and there is an opportunity to also allow us to build applications that are built on events a lot faster. So now today you guys launched, um, your own event gateway.
Uh, we've had multiple types of gateways in the past. Most people are familiar with API gateways. What exactly is an event gateway and how does it kind of take that concept and make it simpler for everybody else to kinda access?
'cause I feel like maybe it's a higher level of abstraction for events For, well, the event gateway effectively gives us the right level of infrastructure to be able to, uh, enforce security observability of events that are in flight from one application to another. And it also gives us the opportunity to implement capabilities like protocol mediation in such a way that we can use events in more and more places. Uh, even the ones that perhaps cannot send a, an event directly by the need to do that only after, uh, providing the right level of authentication, the right level of authorization, only then they can send those events.
Well, we're giving that infrastructure in such a way that events come out of the box within the organization as yet another tool set that they can use. But they don't have to worry about that security, that access tier level of control, uh, about that protocol mediation around that observability, because that effectively comes out of the box from the underlying infrastructure. You know, you may know Kong because, you know, Congo of course started many years ago.
We spoke many years ago, and, you know, we started with our API management solution. But then, you know, as we looked at how to support different types of connectivities, API management is one way to do it. But then there is also service meshes.
We also have announced an AI gateway, uh, recently. And then of course, events are the last missing piece of the overall picture. So in our pursuit of managing all connectivity for the enterprise, of course events were one big remaining component that we didn't support until now.
Were now also events. Uh, we can give them that unified control plan we're giving to every other API or microservice that we process in the organization. Now, events as well have that level of governance, security, observability, and quite frankly, ease of consumption and ease of publishing in any topic that's backed by technologies like Apache Kafka, for example.
As we think it through for a minute, is there gonna be like one super API gateway or will there be multiple events, gateways, API gateways and multiple different things that I need to kinda deploy alongside each other and kind of, uh, create something that feels like a fabric? Well, the key is to unify and centralize the governance because if we decentralize the governance, we are adding complexity. We're not reducing complexity.
So centralized governance, but federated run times for managing events, for managing APIs that we can deploy across each team, across each application, across, across each, uh, cloud vendor that we may be using in such a way that although the governance, it is centralized, how we actually process the events or the APIs or the AI traffic that can be federated and decentralized so that we can bring it very close to the applications. Now that would be very hard to do without the right technology in place. And this is where our platform connect comes into play.
Connect is that unified control plane that allows the organization to create virtual control planes where we can provision event gateways, API gateways, service meshes and AI gateways for our teams that can also self-service their policies so that the platform team doesn't become the bottleneck, but whatever they're doing, it's still going to report back to these unified control plane, which becomes the source of truth of all of the API connectivity that we're generating across the board. And when you think about API connectivity events, ai, APIs, and microservices, I mean, this is really the foundation that allows us to create new products faster that allows us to expand into new markets that allows us to onboard new partners quicker. And so effectively owning the these new strategic asset, which is the connectivity that we generate, including events coming with this announcement, while that is going to allow us to build an innovation factory on the business on top of our business, that's going to be much better and more powerful than it used to be before when everything was decentralized and we had no visibility whatsoever on what the developers were doing.
So historically, event-driven applications were a small percentage of the total number of applications that people were running. Are they now gonna be a much larger percentage? And, uh, will they Eclipse Spa joined or will they be deployed alongside each other?
How will this all play out? I believe that they're going to be deployed alongside each other. I think that we're going to be using different types of connectivity.
And organizations are doing this today, by the way. I mean, the organizations are already, if you will look at the top Fortune 500 stock, global 5,000, they have an incredible amount of event traffic that's flying from one place to another within their systems. And so is it going to be the solution to every connectivity problem?
Of course not. It is a another tool in our toolbox where for certain use cases, events, especially at scale, especially when we have batch processing, especially when we want to make sure that we don't miss those events in case our services go down. Um, you know, events can be a better technology solution for this type of, uh, high usage, high volume use cases.
Now, of course, events are going to be working alongside all the other types of connectivity that we have service to service, of course, um, as well as the connectivity that we're now generating using AI models, which is also this new breed of connectivity that now we're infusing in pretty much every business process and application that the organization is creating. You know, all of these have their own place in a modern enterprise architecture that we're developing in 2025 and beyond. So events very important part of a broader picture that also includes other connectivity types and which is why it's important to make sure that we don't treat each one of these different connectivity types, um, as being fundamentally different worlds.
They are all part of one piece, and that is how we manage connectivity across the organization. It's not, um, a siloed concern. It is a different types of connectivity under one concern.
What makes it possible to do all this now? Because we've been kind of talking about these issues for a while. So what's changed that I can now create an event gateway?
Well, I think, uh, that what's changing, it's not just, uh, the products that are getting more mature, but it's also, um, the mindset of the organizations is a little bit changing right now. You see, for many years, organizations have been delegating, uh, to each individual team the choice on how they are going to be managing their connectivity. And then over time what happened was a sprawl of APIs, duplicate APIs.
Many organizations don't even know what these APIs are doing. Every time we need to build a new use case, instead of treating the API as a product that we curate and will make better over time, we keep building new APIs for, you know, specific point to point integrations that we want to build or point to point partnerships that we're developing and so on. And so over time, fast forward, you know, to these days we have like thousands of APIs.
Nobody knows what they're doing, nobody knows why they're needed. Nobody understands why this, the organization has built three or four different, I don't know, KYC systems, you know, for different applications instead of working on one and making sure that they can use that across all of their applications. And what has changed is that these, in these overall increase of complexity over time reached a breaking point.
I mean, organizations, they cannot build fast enough. They cannot ship fast enough because fundamentally they don't know what APIs they can use to assemble into new products, into new customer experience that they want to deliver. And likewise, today, we use one HR system to manage all the employees in the company, or we use one endpoint security system to manage all the, you know, uh, endpoint security across the employees.
Why are we using 50 different technology software, you know, for technologies, for managing our connectivity at the software level? It makes no sense. And so what Kong is doing is unifying this connectivity under one umbrella that is our connect platform that yes, allows us to run gateways and now events and AI and service meshes.
But it allows us to do that by owning this connectivity layer, which arguably it's one of the most important strategic asset that the organization has because it doesn't matter what we build and what we produce, what matters is how we can use it and to use it, we need an API or we need an event. And this is exactly what our vision is. Now with the event gateway, we're expanding our platform offering to introduce support for events as well.
And with this new capability, we can basically cover 90% of the overall enterprise software connectivity that's being generated across all the applications, all the use cases, whether they are in the cloud on Kubernetes or on virtual machines. Kong can see and manage and govern the traffic. Now, In your point about application connectivity, um, it's never been clear to me at least like who's in charge of that?
Is it the development team or the networking team or somebody else? And now we're hearing about the rise of these platform engineering teams and maybe they'll take responsibility for this. Well, that's a great question you're asking because if you ask many organizations out there who owns this, many will tell you, oh, we don't really know.
Uh, you see, uh, historically this has been owned by the developer teams, but the application teams, you know, are building products, they're building customer experiences. They'll build the connectivity once and then forget about it. And, uh, when there are problems with security, when there are problems with observability, you know, typically these teams are not prepared to address them.
So over time we have been seeing, you know, we're working with more than, uh, 800, 900 enterprise customers, you know, the largest organization in the world in pretty much any vertical insurance, banking, uh, transportation, retail. And what we're seeing is that the leaders of the organization are taking ownership back of the connectivity and putting it into the platform team, the, the platform team that exposes this type of connectivity as a core service to the other teams in such a way that the other teams don't have to go build infrastructure anymore. They can start using infrastructure and build their products, which allows them to now focus on generating the product outcomes they're building instead of reinventing the wheel with connectivity over and over again.
Now, one of the biggest challenges that prevented this from happening is the fact that typically the platform team would become a bottleneck to every request, which is why it's very important that the teams themselves are being given some degree of self-service to self-serve, their connectivity policies to self-serve how they want their events to be managed, yet at the same time being able to do that without escaping the guardrails, the governance guardrails that the organization can enforce stop down using the platform. And so that combination of, uh, that fine balance between yes, we want them to solve serve, but self-serve within these boundaries, it is, uh, what allows them to now fully take ownership back of these critical asset, which happens to be API connectivity. So what's your best advice to folks then about how to approach this whole thing?
Because, um, there's a lot of complexity and there's a lot of organizational issues. How do I get started? Well, the number one, uh, step is understanding, you know, what is that we're trying to do?
And if what we are trying to do is to fully own this connectivity layer, which will allow the organization to move faster, then we need to provide a solution that happens to cover all bases when it comes to connectivity. And of course, events, it is a very important part of it, but it's not just events, it's events, it's AI traffic, API traffic, and being able to then provision that to the teams in such a way that the teams can then slowly migrate to a fully, uh, manage, let's say solution that the platform team has offered to them, uh, without having to, uh, essentially, you know, manage that connectivity ad hoc every time they're building a new API or they're pushing data to a new event topic. And so certainly there is going to be a transfer of responsibilities, but ultimately what these achieves is a reduction of complexity because now we have one place to manage our connectivity, and we have also an increase of developer efficiency because now developers are doing one less thing that it's very critical, but they shouldn't be doing to begin with.
It's a mistake that they're doing infrastructure work to begin with. They should be building products and applications, uh, and innovate on in that area, whereas the infrastructure is being given to them, almost like electricity always on, always running the platform team makes sure that that electricity keeps, uh, being funneled to them, but they don't need to worry about it. So I think that what this requires is the right technology, and this is what Kong, uh, uh, is building has built and it's providing to our customers, but also a shift of mindset where we really want to be committed into making sure the teams are really focused on innovating and not focused on building crosscutting requirements over and over again.
And for that, it is a cultural shift, Guys, you heard it here. There's more applications and types of things in that distributed environment than ever, but the key to it all is finding a way to centralize the governance of it all. Hey Marco, thanks for being on the show.
Thank you. All right. And back to you guys in the studio.
Hi everyone. We're back here. Live at RSA, it's Tuesday.
Well, you know that if you're watching this live, you know, it's Tuesday. If you're not watching this live, take my word for it. We filmed it, we recorded this on Tuesday.
We don't film anything. Um, anyway, let me tell you a quick story. com.
com content March of 2014. In February of 2015, we did our very first DevOps Connect here at the RSA conference. And the idea was to bring together the, uh, security, we didn't call it cyber, the security community and the DevOps tribe.
Yep. Easier said than done. You know, in subsequent subsequent years we started calling it Dev DevSecOps Connect.
Yep. But there wasn't DevSecOps 10 years ago. Yeah.
The closest thing I could find was something called rugged DevOps. And Rugged DevOps was kind of the term was coined not by Patrick Dubar, of course, who did DevOps. Yep.
But Rugged DevOps came out of a tall, lanky Texan out of Austin named James Wickett. And here's James 10 years later. There You go.
There you go. And, um, what was rugged DevOps is really what we call DevSecOps. Yeah.
You know, today it was, and um, of course a lot happened in those 10 years, right. DevSecOps became a thing. James, I think back then, this was before you were working with, um, the Signal scientists folks, the Yeah.
Before Signal. Mm-hmm. But you were one of the organizers of of DevOps Days, Austin, which was like the, for my money, the best DevOps stays in the States.
Let's states, Let's go, Alan, let's go, let's go. And it's next, next week. What anniversary?
How many years Is that? This, this Thursday and Friday. So I'm, I'm flying from here to Oh, You're going right there to there.
How many years is DevOps Day Austin? Oh, okay. I think we're on the year 12 now, if I, if I remember right.
Probably. Yeah. Right Around that's, This is my fourth day in San Francisco, so I'm sure my math may, I may not check out right now.
I'm chock full of medicine, so I'm all over the place. All right. But anyway, so I've had the pleasure of knowing James for 10 years, 10 plus years now.
And you know, in some ways, as I get older, he does it. And, but I've Seen you're very kind to say that, very kind to say That. But I've seen, I've seen his career, right.
Evolve being a, an organizer of it, working for people. Signal science has came a long way. And then founding his own company, dry Run Security, um, if you're not familiar with Dry Run Security, I'm gonna make James tell you all about it.
But he's, he's having tremendous success early on as I knew he would, frankly. Right. Because he, he just does things the right way.
Smart guy and, and works. Right. He's a an example to all of you out there, James.
Hey, talk to me. Hey Alan. Thanks for, thanks for having me on.
Yeah. You know, it is funny you mentioned the rugged DevOps thing. 'cause it's like, I, I feel Yeah, sure I put the words together, but like there was the whole rugged stream going on at the time.
Yes. It was the DevOps stream. And so, you know, I, I don't know.
It wasn't, it wasn't rocket science on my end. It was just like, we should connect these things. And I, I've always loved how you're always trying to get these, these groups connected as well.
Mm-hmm. And yeah, we had a lot of like rugged DevOps DevSecOps stays, just trying to like continue to, to bring that conversation, uh, even here at RSA, so. Sure.
Yeah. That's awesome. Um, but, you know, take credit for when credit's due.
Yeah. Okay. Thank you.
I will. A lot of of stuff is evolutionary not revolutionary. Yeah.
And so you had this DevOps thing going on. You had the rugged movement going on. Bringing that together was a, was a eureka kind of moment.
Yeah. And look, there were others. We had Josh, if you remember Josh, those first ones.
That's right. We had Josh Corman was there and Gene Kim was there and you know, John Willis and, and all of these, I mean the, the folks who Yeah, we were all just, we were all trying to figure out how to do, how to do this. Yeah.
It's great. Um, I'm, I'm drawing the blank. Did your LinkedIn DevSecOps course.
Oh, with, with Ernest. Ernest Mueller. Yeah.
Another, A lot of the, a lot of the Austin folks. Ernest and Karthik, uh, Austin down doing stuff. Yep.
There's one guy we're missing. Ernest Karthik, you, who's the fourth guy? We also have, uh, PECO and Bill.
Those are, those are some of the other organizers that have been kind of in the mix down there. So Yep. Good Times.
Good group of people. Yeah. But anyway, James, enough history.
Okay. Yeah. Let's talk dry run security.
Okay. Assume some of these people have never seen or heard of Dry Run. Yeah.
Yeah. Yeah. Why, why would they have, you know, dry run security?
We're very new. Okay. And, uh, um, we see it as we've developed a new way to do code security.
So we call it contextual security analysis. Um, we, we believe that pattern matching is dead. That, uh, trying to, we've been doing, uh, in like the SAST world, uh, static, uh, code analysis and, and all that space, you know, we've been doing pattern matching and a ST parsing for, for all this time.
And it's really kind of generated more or less the same results. Um, better UI in some cases, marginally better experience for people. Um, but contextual security analysis lets us, uh, uh, takes a, take a context driven approach that doesn't do pattern matching, but we're trying to find risk in the systems.
So, uh, yeah. So driving security's great. It, it's, um, we're having a lot of fun doing it.
I'm doing it. My co-founder is, uh, Ken Johnson. He ran internal security over at GitHub.
Mm-hmm. And so we, we both have, he wrote he, and he's the original creator of Rails goat. Oh, okay.
So we've kind of just have always been friends in the AppSec rails, Ruby, on Rails. I used to really love Ruby for some time there, so, yeah. Mm-hmm.
Very cool. Um, you know, it's an interesting time to start a security company. It is, yeah.
It's always an interesting time to start a security company, but this is a particularly interesting Time. It's a heck of a time. A lot of people were saying, where's the innovation?
Mm-hmm. A lot of people were saying AI is the greatest thing to happen, is security. A lot of people are saying AI is the worst thing to happen, is security.
Yeah. AppSec has been kind of where a lot of the action in security is. Yeah.
Pipeline security, you know, all all the software pipeline security. That's what I'm kind, kinda stuff. What, where was the passion for you, James, that said, this is what I, this is what the world needs.
I could somehow make things better Yeah. By doing this. Yeah.
It came outta two streams. One, I, I really felt like, um, the AppSec, the SAS world has kind of been the same. And I, I realized like, uh, you know, I had the whole gauntlet stuff that I worked on many years ago and mm-hmm.
And then just like, I care about, uh, developers having a good time with security products. And I felt like we just still really hadn't delivered on that as an organization. And, uh, two, fortunately whenever I called my buddy Ken and I tried to convince him to start the company with me, he had been having a really frustrating time with Code ql, uh, their internal, they, they, they acquired that product and were running a GitHub.
And so he was, he was ripe to, to do something new. And we knew that, like by looking at the context of what's going on, like how the surface is changing, what kinda language and framework they're using, how the developer decided to write the thing and why they're doing it, what led to that, and how, how it's overall designed and architected, and how that application's actually gonna be used. All that stuff really, really, really matters.
And, um, and that's how you can find real meaningful risk that doesn't match, like SQL injection or cross-site scripting or all the stuff that we've been talking about as an industry for the last, you know, I don't know, seems like 20 plus years. Absolutely. Absolutely.
Now, you know, you, you look at all that. So I, you know, I've been in this DevSecOps thing now for 10, 12 years. One of the things that I, you know, hindsight's always 2020, right?
That's Right. That's right. That's right.
Yeah. But one of the things that, looking back I realized might have not been the smartest move we made, was really emphasizing the whole shift left thing. Mm-hmm.
Right. We're gonna shift left, we're gonna shift left some more, and when we're done there, we're gonna shift left even more than that. We're gonna go as far left as left can go.
Yeah. And I think in retrospect, thinking that developers would be able to use security tools designed by security people, it was a mistake. Yeah.
And maybe we should have been emphasizing shift everywhere. Mm-hmm. And maybe we should have designed security tools for, excuse me, for security for developers.
Yeah. Not for security people. I, I believe that last point is that that's a salient one because it's the idea of shifting.
It's, and, and a lot of the organizations we talked to as we're kind of building the company, and as we, we discovered, we discovered two, two key facts that like, they felt the penalization of all those security tools being put on them. So nobody really loved, like the, the alerts and the Christmas tree of lights that they were always given, and developers weren't having a good time with that experience. So the stuff that got shifted either got turned off or got muted or got unshifted.
Um, and then we also realized that, uh, security leaders or, or engineering leaders in, in that case too, their, their code is changing constantly. Like, um, some of our customers have five, 600 developers. Their code changes a thousand times a week.
2000 times a week. It's, it's easy like that, that's, that's not unreasonable for them. So now how do you find risk whenever you have that constantly evolving and, and it's only getting faster?
So when those two forces are, are joined, uh, yeah. The tools that, that we had shifted weren't really Right. They really needed a whole new class of tooling built just for, for developers to kind of solve that, that problem.
I agree. Yeah. Yeah.
I agree. Um, there's been another sort of movement that I think is exerting a gravity pull on, on this whole orbiting thing, and that's platform engineering. Yep.
Right. We've seen it. com as a result.
Yep. How do you see that playing into this whole dev stack ops? How does it affect dry run?
Yeah, I think platform engineering is an interesting group. And specifically like we play in the infrastructure, well, some of the infrastructure is code that people are working on. Um, can I tell you a story about one of our customers?
Sure. We got, I won't, I can't name their name, but, um, they're like a direct to consumer, uh, business, and they got, uh, we'll call it 60, 70 developers. Um, we came in there through the, uh, through the platform or the SRE team who was just trying to like say, how do we give security tools that work?
Mm-hmm. Well, part of our product is like we, we, we ship traditional SaaS. Like we, we can, we can beat the traditional players of SaaS, but one cool thing that we can do is find risk, um, that, uh, that you can't find.
And we through in like traditional patterns, and we call that natural language code policies. And for every customer we sit down and we start out, and we will usually build them out a natural language code policy that says something simple like, is this code change? Adding sensitive data to our logs?
So every time the developer's making changes, are they like, now emitting customer data or P-I-I-P-H-I or whatever to logging, you know, we've all been in the organization where it's like, you get audited and then like then, uh, somebody, um, somebody says, Hey, look, you got some whatever PII or, or some sensitive data in your logs. And then you gotta look back for 12 months and now you got an issue, a, a report and you gotta like, you know, have some sort of disclaimer on your audit or your compliance. And if you have a tick mark on that, um, you also get stuck in a situation where like, now you're trying to triage, like, how, how do we ever stop this from happening again?
So I called up our customer, we just, just signed. I was like, Hey, uh, how's it going? How's, how's it been?
You're like, week two or week three. He's like, that, that PII, that sensitive data logging thing hit last week. And, uh, within 24 hours, the developer I got with him and told him like, Hey, we can't do that.
And they were, but they were dropping data, customer data dumps for this new like LLM like recommendation engine that they were building. And we said, uh, uh, uh, let's get that fixed. And so we were just, we were just going through like how much that would've cost, uh, to remediate and under like our traditional lives that we've ever handled before.
It's like hundreds of hours, uh, to deal with that problem. But if we can just deal with it in code before it, uh, gets shipped or gets shipped all the way, or redact it as soon as we can, um, you're able to, you know, do do amazing stuff there. Yeah.
Absolutely. Yeah. But you can't find that with patterns.
And that's where our natural language code policies really Yep. Really gets into finding new types of risk for folks. What I find interesting with it though, the platform engineering stuff, James, is, it's kind of like telling the developers, I know you want to build quality code.
I know maybe you don't want the Christmas leak tree security thing. Yeah. We're going build the environment for you.
Yeah. I, I think one of, again, hindsight, 20 20, 1 of the things about DevOps is we told developers, look, you got everything. Yeah.
Including building your own platform. That's Right. Right, right.
Alright. You live and learn and you adapt. Right.
And you iterate. That's, that's DevOps. We iterate, we reiterate and iterate again.
Yeah. Um, and it, it is an interesting thing. I think AppSec is a, is a perfect playground for that.
If or not a playground 'cause we're not playing but a perfect, uh, use case. Yeah. It's For that, it's natural overlap for that.
Yeah. Now you mentioned a few times that you guys are using SAS technology, SAST for our uh, yeah. Audience out here.
That's static code analysis. Yeah. Or it's Yeah.
Static application security testing is the, the acronym and Yeah. Now there are other kinds of fest there, das and Yep. Some other, there's proprietary kind of, everybody makes a few I Asked and Stuff I asked is another one.
Yep. There's, But the, the important thing is you recently, and I didn't talk about this with you, but I, you know, I follow you on LinkedIn. Yeah, Yeah, yeah, yeah.
You recently, you guys recently published a study Yeah. On speed. 'cause speed is important when it comes to scanning on speed and dry runs.
Yeah. And accuracy. And accuracy.
Excuse me. Yeah. Tell us about that.
Yeah, So we, we had, we thought, alright, we built these, this really cool platform and we really invested a lot of time building the engine. And then we, uh, created across, uh, four different languages, 26 different, uh, kind of easy to get vulnerabilities, but we wanted to just test effectiveness. And then we, uh, took some of the popular tools like sim Grab and Sonar Cube, Snyk, uh, code QL from GitHub and, and then ourselves.
And then we just started committing all this code in that had, uh, these problems. And, uh, we were really surprised, uh, to just, uh, what happened is like we, because our approach is remarkably different, like we were double the effectiveness in accuracy, um, than the next, than the next category of tools. Um, and then even in that category, there's quite a bit of divergence from like, uh, who's kind of coming, I think outta the next one in like the 40 percentile was like re but then like some of the other ones were like in the 10% or 8% percentile.
So, and we dry run was in the 80. We, we got, I think we got an 88% on the, the scoring there. So it's a limited data set.
We have some more, um, languages and stuff we're gonna continue to release, we're really excited about. But we really wanted to show, like, as an industry, we've been really, um, we've been really hooked on the idea of static assessment being like matching patterns and parsing like code trees and looking for source and sink and stuff. But contextual security analysis that does like a more holistic look, building up this code context window, like we talked about.
Um, it's way more effective. You can learn a lot more about your system. Uh, it actually speaks to developers 'cause it's giving them relevant feedback about the stuff they're actually working on.
Um, and we can tell security people like where their hotspots are, where what matters, what, you know, what, what they're seeing in their organization. So Of course, this year's show, like last year, frankly, we're hearing all about ai, agent ai. Yeah.
How's that figure into the dry run kind of strategy? Yeah, I think that, you know, we are, we have a lot of LLMs under the hood that we're using to, to do a lot of our analysis. Each of our analyzers are tuned to look for their own specific things.
Um, our natural language code policies are full ag agentic where they can go find out the real truth about a system. So instead of just saying, we think you have a vulnerability, we can go dig into the code to, to find out if that's, uh, really true. Uh, customers love it and it's, and it's way more accurate.
So that really, really helps on that. So, um, I'm, I'm excited by what, what AI is providing to our, to our industry and like what it's allowing us to do. And, um, I think the results, it's, the results in that report kind of speak, speak to themselves of like how much more accurate we can be.
Um, 'cause and that's really the key. 'cause we need, you know, going fast by in and of itself, it's not enough. You need to be fast and accurate.
Accurate. Yeah. I remember, um, I think it was in London at one of jean's, uh, DevOps Enterprise Summit.
I was doing a video with John Willis and Damon Edwards. Okay. You know, it was, it wasn't about security per se, it was about DevOps.
Okay. But fast secure, what were the three things I want to do faster? Code Resilience.
Maybe Resilience Yeah. And security. We can, we do want it all.
Yeah. And so having fast results that are not accurate Right. Is having no results.
Yeah. Yeah. And that, that's really The thing in our report, we kind of call that out.
We're like, some of the ones that were like, out of our payloads, they only found one or two. It's like, that's really scary. That means you could check in like legitimate, you know, problems and nobody says anything, but you do it quickly.
So, you know, that's, that's, that's, I, you know, you gotta watch out for That. It's, I remember back in the day when endpoint security similar kind of thing. Yeah.
Yeah. Because let's face it, semantic McAfee, back then you installed that on your machine. It was a pig.
It would slow your machine down. Yeah. And so a lot of the AV companies were making their whole bones on, Hey, we're faster and lighter.
Yeah. But faster and lighter. That doesn't catch viruses.
Wasn't a great antivirus. That's right. That's right.
Yeah. Yeah. Yeah.
It's the same thing here. Yeah. James, what's the website?
Okay. So if you just go to dry run, do security, um, and then right on the front page it just says like, get the 2025 accuracy report and you click that button and, and we'll ship it to you right away. And how about people maybe wanna try out dry run security?
What's their best on-ramp? Yeah. There's two, two options.
So if you want like a self-guided tour, you can go to Dry Run Security and install the GitHub app there. Or GitLab is coming soon. Um, or you can click, uh, I think there's a button there.
This is like, talk to an AppSec expert or whatever. And we'll usually sit down with you for 5, 10, 15 minutes to make sure, uh, write a natural language code policy with you and kind of get, get people up and running, but super lightweight to get to get rolling with it. So, Hey Alan.
Thanks. Congratulations. James Wicker, one of the nice guys in this business.
Dry run, do security. Check it out. We're live at RSA.
I think we have one more coming up, so stay tuned. All right. You are watching, listening or however you're consuming.
You could just be reading the transcript of Infrastructure Matters. Episode 81. I'm here with my good friend Kimberly Bass, who's head of career transition, but it's still beating me to joining the stream every time.
Kimberly, welcome back to the show. Thank you very much. Yeah.
Um, for those of you who don't know, I've, uh, officially have gone to the, the next side of my other third, the next third of my life. Um, and I'm, I'm not working full-time with, uh, I'm not working with Futurian Group, but I'm still having the opportunity to participate in this Infrastructure matters, um, podcast, which is just a great, great fun time, um, with you guys. And I'm missing Dion.
He's, he's, he's someplace we are not sure where he is today. If you know where in the world Diane is. I know we're about to get into travel season up, I'm sure SAP Sapphire is coming up quickly.
And Diane is a staple for SAP Sapphire. Wow. Uh, Which, uh, usually coincides with Click Connect, which, which I'll be at the week that you're watching this program.
Uh, I'll be at click Connect. I believe Dion will be at, uh, SAP Sapphire. And then, uh, following that is Dell Tech world.
So we're getting into the swing of the enterprise. It kind of spring early summer schedule. I'm expecting to receive a new toy from Dale today.
Actually. They, they, Dale doesn't like w when us Analyst type show up at their events without a, with a MacBook or hp uh, laptops, or they're sending us all laptops to make sure that we're uniform and the Dale. Mm.
They never sent me one, but you know, I've got my, they've Never sent you a laptop. This is the second laptop I've gotten from Dale in the past six years. So, uh, and uh, I'm not gonna tell you what I do with the laptop.
I don't sell it 'cause it's technically not my laptop. It, it is a loaner, so I can't sell it. But I absolutely keep it and put it to good, good use.
Well, what, what we do, uh, maybe they could send me a PowerMax or something. We'll see, You know what that, that will make up for the years of them not sending you Yeah. A laptop.
Definitely. So, So let's jump in. Let's do, uh, let's do a quick recap 'cause we missed last week.
The mm-hmm. The team here, uh, at Techron that typically produces these videos was off at RSA. And we'll get into some of the kind of talk of RSA because it, it is a big security conference.
You though e even though me, you nor Diane really cover security. Maybe we need to get Krista on Yeah. To talk security.
But, uh, the week before that you were at Tech Field Day, AI Infrastructure day Yeah. Or AI infrastructure, uh, field day. Any big themes you wanted to share with us coming out of that event?
Well, so this is the second AI infrastructure field day we've had. Um, and the first one, we, we more focused on the data side of the house. And this one, we opened the aperture to, um, various technologies that came in the door.
Um, and that included everything, A lot of networking. So there's a lot of fo focus. Um, Juniper was there, um, even, well, we spent a full day at Google's offices and there's a great video that was put up, um, that Colleen call had done me, was really sweet of her.
Um, but talking about infrastructure matters, why infrastructure matters, and I, you know, it came away from the Google session, which was an all day session, including the networking and the data and the servers and the storage and a lot on the storage environment saying that they're not trying to put you in one, one box fits all, um, or one cloud fits all or one cloud kind of environment. They understand that this is a very complex environment, that you're doing different things with data. You're, you know, you're doing LLMs, you're training, you're fine tuning, et cetera.
And so that there is a, a myriad of solutions that they're bringing to you. Um, and it's not for the faint of heart. So I think that having a consultant on board to help you through how you're designing what you're designing is really stupid important.
Flip that to the next p One of the other ones that was really interesting, which was Nutanix that came in with what I would call the easy button. And, um, Nutanix, they're known for easy button, right? You know, HCI stuff, um, hyperconverged.
And, um, and what they've done is they've put, they've gone and curated like the hugging face, um, models and selected the top of the models. There's, you know, thousands and thousands and thousands of models. So you can get buried in there to say, what's the best model for you to be using?
And with that curation, you can select a model within the, um, Nutanix box, and then it automatically populates your GPU, your VM environment, all those kind of things for you to kinda get going and get running. So, you know, there's a bunch of easy buttons they've done with it. It's pretty slick.
Um, and, um, I think that it's designed for the companies that say, okay, so I wanna just get going and try this out, get this working. Um, and yeah, suppo, you know, it scales. I don't know what the performance is.
Usually you give a little bit of performance out for those pieces of it. So that was really interesting as well. So those are a couple of the highlights.
Um, we heard from our friends at soddy and, uh, they came in and you can talk again about their, um, their, uh, liquid cooled technology, which had everybody like odd, we were, we were all like in the, the petting zoo. They were passing around all the, the, the fun toys to us. And it's like, oh, ooh, ooh.
Yeah, it, it, you know what the delegates really like, uh, when soy presents the back channel, I'll, I'll tell a little secret from the field day back channel when the delegates get together and talk, they said, how is it that a storage company is coming in and, and explaining AI better than some dedicated AI companies, solid Im does a really great job. And it's not just a storage company, they're actually the device. I mean, they're making the solid state drive device.
It's not like, it's not like they're out there, you know, like a WCA or somebody like that. I mean, they, they outdo the, the guys that put the storage systems together, um, in terms of their understanding of this entire, the complexity of what it is. And so, and they are building, and the reason why they've done that and gone deep and really good at what they do is they've gone deep to understand what are you gonna need from an IO capability, capacity, capability at every step of the way of delivery.
And, um, they've done an excellent, excellent job of that. Yeah. The, it reminds me, I have this saying when I'm mentoring, uh, career professionals, especially independent contributors, you need to understand your value to your organization all the way through the product that the product or services that you deliver.
So if you're a DNS administrator, you need to be able to explain to the, uh, CFO why your job exists beyond, you know, doing, making sure DNS runs. Mm-hmm. Same thing with, uh, basically what soy did at the presentation, if you haven't watched it, they absolutely understand their value chain, and it's a great just lesson.
And not just marketing, but product, you know, product engineering. Like what, what role do I play ultimately in making AI real? And they did a really great job.
So head tip to the folks at the solid, And one of the other companies that was there, which is also a process company or a, a, um, component company is Fon. Um, Fon hasn't been really well known. They're, they're almost $2 billion company.
Um, but they are the, um, the drives, solid state drives behind, uh, a lot of other people that, so they have put other people's names on it for specifically, if you bought solid state through Seagate, it would've been coming from fsa. Now recently, they've gone pub, they've gone public with their name. Um, we hear a whole lot more about 'em.
And then what they were there to really talk about was their adaptive, um, software technology that, uh, goes with the drives and enables you to more efficiently use, um, HBM or the, the memory and capability when you're doing the training. Really, really kind of slick stuff. There's a blog up there that I'll, I'll put that kind of summarizes what it does, um, and the capabilities that it brings to the, so it lessens the amount of memory that you have to have, um, in order to train, which is really significant because that's one that's probably the biggest, um, bottleneck right now that we have with training among all the other pieces of it.
Um, so those are a couple of, a few of, a few of the folks that, you know, I would like to, you know, highlighting here. That was, uh, really a good session. Um, so I'll turn it back over to you, Keith.
Yeah. And, uh, you mentioned these drive riders, you know, kind of the, um, the big claim of fame is kind of the 122 terabyte drive, right? And one of the things that we missed because we weren't on last week, was Dell announcing their latest, uh, AI server.
That's not the big 9,000 series, but there's 700 latest, 700 series density wise. 9 petabytes of storage in two you of SSDQ of basically QLC storage, which is an amazingly dense package. Uh, rumors have it that IBM is gonna be, uh, announcing the latest version of their LTO drive, which I think is going to come in around 30 terabytes native.
So just give, for us old school, uh, uh, storage administrators and people that these numbers are just insane. The amount of storage you could put into you and the need to be able to archive it is not keeping pace. And it's, it's just an amazing problem that I, I could not have predicted five years ago, let alone, uh, 10, 15 years ago.
So it's, it's an an amazing time to be alive and be in storage. Yeah. So, uh, there was, uh, actually news this week.
Uh, Nutanix had their next conference, which I haven't been to since, uh, pre pandemic. They had in New Orleans, great food, great music. What were the announcements coming out of, uh, next?
Well, Nutanix next was in Washington, dc Um, we had a couple people from that were there, and I know that, uh, guy Courier was there. Um, a couple things that I came out of that, one is they did, Nutton has been talking a whole lot about the VMware migrations, and they're there, they're the alternative or one of the alternatives to Broadcom. Um, and they had clients there talking about those migrations, um, which included people like the US Navy and Moody's.
Um, one of the things I highlighted is that in order, in order to win the Moody's business, they had to have external storage. And so what you're looking at is like, okay, so that's, wait a second. We're, we're, we're integrating all the systems together.
But what clients are saying is like, we've already have this investment in storage, and if you want us to move off of, um, if you want us to be able to move off of VMware, we need to be able to enable some of the storage that we're using. Um, and the second piece of that is, you and I have talked about the POWERFLEX scale. You know, many, it was last year at DTW.
We had that deep, you know, sat down and had a deep conversation about Powerflex and, um, with, with Nutanix. And, and that has finally been released. Uh, and maybe you wanna highlight, you know, kind of what your perspective was about why, why they needed to get that out.
And, um, it was extremely important to clients that have got, um, very large environments, um, that they need to do a better job of scaling their storage with the servers. Um, and then this is basically what Nutanix is enabling right now. Yeah.
So we've seen this with people who have adopted, whether we're talking about, uh, legacy HPE SimpliVity or their DHCI solution or VxRail, and even in, in, in quote unquote pure Nutanix environments, enterprises don't get rid of their big iron storage array, right? The, these things are critical for mission, uh, critical deployments and just general workhorses, we're not, we're not even talking about just the, the, the big iron, the, the traditional net fowlers are still critical to mission critical workflows. So I'd say something pretty provocative like seven or eight years ago when Nutanix has said it's kind of, uh, I would say it's hype level, this greatest hype level that HCI doesn't save money.
The reason why is because enterprises don't get rid of these legacy technologies. If you, uh, adopt all HCI, yes, you do reduce your administrative costs, but no one does that. Even in the VxRail environment, you're gonna see plenty of power scale scale.
You're gonna see plenty of Power Max alongside of the, uh, VxRail, HCI Nutanix, if they want a shot at these workloads, if they want a shot at disrupting, uh, or taking, 'cause I don't think they need to disrupt it. They just need to say, yes, VMware, angry VMware customers will, will take your money. If they want to just take this money, then they need a solution that, uh, integrates with overall environments, uh, and storage and data landscapes, especially when we talk about ai, because these work, the data sets that people are generating from, uh, for their AI is not necessarily landing on HCI.
So if we couple the next announcements, uh, to the announcements around, uh, their AI easy button, it all makes sense for Nutanix, right? And for customers who are looking to displace or have been displaced by VMware's changes in licensing. So it's, it's critically important that they got ahead of this.
They did. I think the timing is well, uh, for them to start to pick up some of those, uh, VMware enterprise customers who, who are not exactly happy with the company. So on the second, second announcement of the storage piece of it, they announced a, um, relationship with Pure Storage.
And, um, they have done some deep integration with their software defined networking that's called float. Um, you know, along with the, what they call NCI Nutanix Cloud Infrastructure, they don't call it HCI anymore. They call it Nutanix Cloud Infrastructure.
So, or hybrid cloud infrastructure or whatever. Let's, let's get rid of that word. It's kinda like getting rid of data storage.
Ah, we're calling it data infrastructure, Uh, ai, I mean, uh, development platforms don't like to be called pass anymore. So, um, I was told that a a year or two ago, so yes, uh, private cloud platforms, Right. There we go.
So anyway, so that was, that was another big announcement with, uh, peer storage as being, you know, and so there'll be others, external, external storage companies that will be coming out and, um, probably certifying with this same kind of integration with their, their operating system. Now on the VM MI migrations, um, one of the other companies that was talked about was Toshiba. And Toshiba is migrating, um, two years to migrate 2000 VMs.
Comment on that. That's what they said. Yeah.
So the, the, I think just wrote something about the, that this week, uh, that proved to be pretty popular VM to VM migration solved problem. We were doing this back in 2008, uh, with products like plate spin, VMware, uh, converter, the ability to go from, uh, public cloud, from even private cloud to public cloud and public cloud back from a VM disk format solve problem. Our friends at Veeam do it at, I, I've done it in the CTO advisor hybrid data center and the six five data center where we wanna run a test, uh, suite on the public cloud or from the public cloud back onto, uh, on premises that's solved.
The problem is everything around the, uh, VM and Broadcom knew this exceptionally well when they bought VMware. The problem isn't, uh, the raw ability to move from VMware hypervisor to KVM Nutanix, A HV tho, those, that's routine there, there's tools, plenty of to do that from every provider. The challenge is what happens when I have my security tightly woven into NSX?
What happens when I have my storage policies written, you know, hardcoded into vsan? What happens when I have, when I'm using the integration between VMware, vSphere and my storage rate for administration, when these things don't exist outside of VMware, are not easily mapped one-to-one. You get your two year, you get your two years for 2000 VMs.
Yep. Yep. And, and it's, people don't understand.
So something like a, um, data migration, when you're doing a migration from one platform to another platform, it's takes a year of planning. I mean, a buddy of mine has had a company that's all they did. Would they go in and do data migrations for companies?
And he was, he had a team of full-time people, um, back when he worked for, I believe it was at t, and then he left the left, I think his, uh, his dag internationals of the company, and that is all they do is that migration. Now we've gotten better at it because they have, you know, some seamless migrations where you can plug, you know, plug in the new controller, the new devices, and it'll populate itself. But that's only if it's the same device, you know, so like Pure does that, um, NetApp does that, et cetera.
But if you wanna go to somebody else's system, that's long range planning. And how many times have we seen, this is goes back to my comment that, you know, HCI, the, so I'll say this from seven or eight years ago, HCI seven or eight years ago, this story that you would spend money, uh, to, uh, spend less money. How many times have we seen that you, we see a Hitachi big storage array next to a VM max, next to a net NetApp thing, and this three different generations of boxes.
And the plan was always to migrate off one, go to another one. But you get stuck. This, this stuff is complex.
You have low level, your SAP is, uh, directly mapping lungs to the Vmax server. And that, uh, you're doing dis to dis replication from your host. And you can't simply just say, okay, I'm going to plug in another, uh, that abstraction of, I'll just plug in another storage provider behind that.
Just, it's not that simple. It doesn't work that way. And you get stuck in a migration.
And this is something Broadcom has depended on, uh, when it, when it comes to, uh, locking customers into VMware and VCF Brock, uh, hot to promoted that VCF has 70% penetration in their enterprise customers. Yes. Because it's the best licensing option of the licensing options that's presented to 'em.
Customers don't want to change because they have so much other stuff going on. Yeah. Well, enough of that, the migrations, we've talked about that for now, going on for two years, adding finit.
So let's go on to something we don't talk about very often. That's ai. Yeah, ai, agent ai.
We're coming outta RSA, neither you or I cover, uh, security. So for those of you that are in security, we are going to really, really murder what happened at RSA, but it is big news and we do need to cover the news. Uh, basically everything was a GenX ai, a GenX AI and identity, uh, within security.
So this whole idea of how do you secure ai, actually, we, we've gotten briefed by Dell. We've gotten briefed by all the major OEMs on their strategy around securing the AI data. Pipeline data is something that me and you know about, and this ability to use a, uh, not use ai, but both use AI in, uh, secure ai.
The, the, I think the question that was getting answered or asked at RSA consistently, is AI just another workload that needs to be scanned similar to security? Uh, similar to, uh, how scanners, uh, secure other workloads? Or is it a different approach to security in general?
Any thoughts on this at all? Uh, Kimberly? Well, okay, so agen ai, um, and identity security, it makes a whole lot of sense to have, um, AI or some sort of agent work on identity access management, I think is what we're talking about here, is are you who you say you are when you're knocking on the door and wanting to access the data?
And let's apply those disciplines to there and that, and can we use a ai, uh, tool here to do that work, um, that maybe humans were doing before or systems were doing before, or can we button it down even further? So, yes, to me, this makes sense. Um, if that's what we're talking about here, um, I did not attend any of the RSA stuff, so I'm not gonna try to, you know, f fake it till I make it here, um, at all.
I'll say, I don't know. Um, but what I do know is that we've built, we, most of the data management companies have start, have started to build or have built some sort of hooks into security systems, um, identity security systems for the purposes of DA data management, especially as we get into the data pipeline. Um, and identifying what, who has what access to what, um, over the time.
Yeah. And then from, as you, uh, connect that to agen ai, imagine having, uh, to, you know, most people have disabled micros, uh, for the very reason that we're facing with Agen AI security, this idea that there is these autonomous systems accessing your data and doing work on behalf of your organization that can be hacked. So if I can, uh, if you, uh, if I can, uh, do some type of, uh, phishing or something, some social engineering to that agent that has some, some level of intelligence, which can be fooled, how do I protect against that?
I don't know the answer to that. If you want to learn more, go watch the coverage from RSA from the rest of the folks here at rum. Alright, so, uh, well now I'm going to do my best impersonation of Dion.
'cause Dion covers open AI much more than I do. But there is a big announcement coming out of open AI for, uh, uh, their country's initiative. Diane felt this was, uh, exceptionally important.
He wrote something on it. The, I, the general idea is a localized AI for an AI infrastructure for countries. If you're in France, V versus Switzerland versus, uh, the us, you need ai.
That's, that's meeting your local re regulatory, illegal and democratic standards. And open AI is specifically going to serve each one of those companies. They announced a $500 billion investment to, uh, to fo to help the US specifically build us, uh, centric ai.
Wow, that's big. That's very, very big. I had not read about that.
Um, and this is going beyond the language differences then where we call this is beyond low 40 Trump versus of boots. Okay. Yes.
This is getting into the, um, the norms and the, I would imagine some of the norms that people have as well as the mandates that are coming from the government, which we still are evolving. And, um, yes, we've got, you know, the EU has put their stuff, has put out their, um, AI guidelines or AI dictates. Um, we have not as a country yet.
Um, we've given the guidelines coming from the, uh, presidents, um, and I multiply that because I know we, we, we had one from the Biden administration and we're now working on the one coming from the, um, the Trump administration to see what's gonna come out of that piece of it. But yeah, those things have to be, um, and especially when we get into, I think, well any country, I think that every, we've all experienced that when you go over there, the norms are very, are different. Um, and it's, those nuances is there that can cause problems with people, um, how language is how we express ourselves, et cetera.
So yes, this, this is big. This is really big. Yeah.
I was shocked when someone from, uh, And is 500 billion enough money for this. That's kind of my Question. Well, that's the US specifically, the, so, uh, uh, well, I don't know if it's for the US but the, they're talking about building local data centers, local versions of chat GPT for the regions that they're gonna operate in.
So yeah, 500 billion does not seem like enough. I think Daniel Newman was just saying, uh, that he, uh, moderated a panel in which the notion of $3 trillion of investment and AI by over the next three years is probably a little conservative. The we're, we're gonna see numbers bigger than that.
Yeah. Yeah. Talking about big investments, uh, Les or our friends at IBM had their big show this week, IBM think or one of their big shows, uh, IBM think is one of the more technical shows, and they announced $150 billion investment in the United States over the next five years talking about ai.
So, you know, I think, I, I have to agree you with Daniel, uh, based on these two numbers alone, 500 billion over, uh, I, I, I would assume a shorter period of time for open ai, 150 billion from IBM, we've heard the numbers from TSMC, uh, Intel, apple, et cetera. That $3 trillion number seems a little bit low, but, uh, over the next five years, they're gonna be investing in ai, quantum and, uh, other manufacturing here in the us. And I think the quantum is the big one is because, you know, IBM Manu, what IBM manufactures, they manufacture, um, the storage systems, they manufacture, um, the mainframes and they manufacture the, um, the power systems.
This one here is the quantum, the big quantum computing investment that they're gonna be making. So, um, that will make, and they recognize that, you know, we are well on our way, you know, in March. I mean, it's kind of like talking about quantum computing.
It feels like, you know, for 5, 6, 7 years, and we're, we've, it was always seemed like it was 10 years away before it was gonna be ready. Now we're within a planning period that quantum computing will be ready. And when I say a planning period, it's that three to five year timeframe that we can start thinking about how are we gonna actually really use quantum computing to solve some of the big problems.
And one of the things over the past five or 10 years that's changed that is that Kevin, one of the things that we haven't really thought about is this engagement, this interaction of quantum and ai. And I, I haven't really given it enough thought to, uh, to comment intelligently on it. But as we see quantum start starting to, you know, another non-deterministic technology quantum, um, uh, take on or integrate with a non-deterministic technology such as LLM and, and ai, how what will the resulting systems look like really intrigues me, really confuses me.
And, uh, I, I, I, it, it's, it's, it's more technology than I thought I'd see in my lifetime. Yep. Whole lot.
All right. With that, we did our best I impersonation of security analysts and, uh, AI analysts from the, uh, from, uh, and quantum analysts. Uh, but one thing that both me and Kimberly know is storage and systems, and I think we covered that exceptionally well.
So a plus on storage and systems, c plus on everything else. If you wanna learn more, uh, tune in next week. 'cause I, I'm asserting our good friend Diane will be back to help pick up the slack and some of this conversation around compliance CIO level stuff.
Remember to follow his, uh, CIO checks, CIO, uh, hashtag CIO checks every Thursday. And, uh, follow my zero to builder series, hashtag zero to builder to learn how to develop code from zero to build in a hundred days, even if you haven't joined. It's a, it's a good opportunity to, uh, catch up.
Thanks everyone. Have a great week.