Techstrong TV May 29, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey everybody, $8 billion for big Data. You're watching Textron. Hello everybody, and welcome to Techron Gang.
We're gonna be talking about all kinds of exciting things today, including, well, Salesforce is finally buying Informatica for $8 billion. But let me introduce my fellow cohorts here, starting with Terry Robinson, who's down in Louisiana this week. Terry, How you doing?
Good, nice and muggy down here. Um, hope we'll have a cool conversation, little things off a bit. All right.
Well, hopefully it won't rain. It already did that, and of course, John Schwartz already did that. All right.
Well, I, every time I've been in Louisiana, it's rained, so, and it's been a while. John, you, of course, are home in fabulous Northern California still, right? I am.
We're, uh, we're bracing for a heat wave. It's gonna be like 90 degrees here, which for us is, is broiling as you know, you lived here before, you know how 90 degrees, how people freak out when it gets over eight 80 degrees here? Well, you know, it was always two climates for me.
It was one, I worked in San Mateo, so it was 90 degrees every day, and then I drove north, and once I got to like, coma in the cemeteries, it dropped to about 40 degrees, and then I went home. Yeah, With a lot of fog. Yes, exactly.
Yeah. So micro, what they call it microclimates here? Yes.
Well, It was 90 degrees all weekend here. So there you go. Well, between where Terry is and where you are, we're having a tropical heat wave.
There you go. All right, let's jump into this stuff of what's going on with Salesforce, who I guess finally bought Informatica, um, to my way of thinking, this is, uh, an interesting way to go get some data for ai, but John, what's your take? Yeah, you're exactly right, Mike.
Um, it's, so, in a sense, what Salesforce is doing, and they've been doing a lot of acquisitions lately, and this is just the latest, is there kind of in a sense to me, filling out this AI jigsaw puzzle? So they had the data integrity piece with an Informatica. And so for context, you mentioned they have sniffed around Informatica.
They, I believe it was April of 2024, there were rumors, and there may have even been a report that they were, that Salesforce was eyeing Informatica, the market reacted terribly, but that was a year ago, and a lot of things have changed since then. So now we've got this kind of like crazy land rush for acquisitions going on right now. do ai.
So they're filling out their, their docket, and they're looking at data integrity with this acquisition of Informatica. Um, in a sense, mark Benioff issued a statement that kind of alluded to this idea of combining various technologies from companies they bought, uh, MuleSoft, Tableau, Informatica, and, and into this kind of, uh, data management capabilities of Informatica. So these autonomous agents that, that, um, Salesforce has been working on, they want them to be safer, smarter, more scalable.
Um, I talked to Brad Shiman, who's at, uh, the Fu Futurum group, and he had an interesting take on this. He said that Salesforce had previously had this top-down vendor approach for years where they would provide these, um, great business software products built on top of whatever technology was necessary to deliver those workloads. Now, in a sense, they're flipping the script and they're building from the bottom up.
And I think that plays into this other notion that with AI models commoditized, the, the focus has shifted to integrations that connect enterprise data to those AI models. Um, one other thing in terms of context, I know you talked about this yesterday at the ai, or excuse me, the big, bold, beautiful bill, whatever it's called that includes some very favorable, uh, uh, attempts to, to deregulate AI or to keep it regulation free for 10 years. So ai, it's, it's basically, uh, a land rush right now.
And, uh, these deals are going through and there is a very, very high pressure on these companies to fill the gaps and provide as much as they can to make themselves compelling sell. So I think this is all kind of coming into play right now, and I think you're gonna see even more deals from Salesforce. I know they've got some things cooking in terms of AI agents and announcements that they're gonna make in the next week or so.
Um, I just say, just, just get, get used to it. This is gonna be a daily occurrence, literally with m and a activity. Well, the part that always made me scratch my head when it came to Salesforce and anything to do with Gen AI was access to unstructured data.
You know, their CRM is a system of record. It's essentially a glorified database for a particular application. And, um, structured data and feeding that into an LLM is a whoopty, do I need all this unstructured data and all this other stuff that's floating around?
And Informatica has, and I can't help but wonder if all these companies that do data management are now gonna get rolled up into the age of ai. And I don't know, I mean, in the case of Salesforce, just listening to you rattle off all the companies that Benioff is referring to, you know, part of my IT soul starts to think of the phrase, you know, Salesforce time, I gotta stick all these things together and it becomes a monster, and hopefully it works. We'll see, Yeah.
That's, that is, that is good. That, that is a concern. You, you're, you're not the only person who mentioned that to me.
This, this, this whole idea of how do you piece it all together and it's kind of a work in progress. I think the way that Salesforce does things is they, it's, I, it, it's, it's a, it's probably an unfair word, but it's overkill. Like, when they want to try to prove something that they're doing, they will bludgeon you over the head.
And they do that not only with their actions, but with their words and with some of their announcements. So it's a little bit overwhelming, and I think it's, there's a lot of pressure from the top down, especially from Benioff. You know, the interesting context too is that Informatica, a couple of weeks ago laid out their whole AI agent strategy around data integrity and, and, um, data management.
So that, that played a part in, in, in this deal. But this deal has been kind of simmering for a long time. You mean marketing people are saying the same six words over and over again, trying to make a point I'm surprised.
Shocking, actually. Um, I'm kind of wondering what this means though, too. I, one thing that has been touched on is, uh, Salesforce has always been sort of platform agnostic, right?
And so what does this mean when you start taking that bottom up approach? Are you gonna lose a bit of that? And does that matter?
Uh, I, I think that you're spot on in the sense that, um, maybe that top down approach doesn't really kinda work, and the bottoms up doesn't work either. You gotta do it from both ends. And I think that, you know, uh, in the military they say, you know, the best way to take a bridge is from both sides.
So I think that that's what's going on here as well. But, you know, Terry, to your point, I do wonder about the security here. And one of the best parts of informatic is they do have this governance framework for data, and they have done that job really well over the years.
But not only do we now have to secure more data than ever, but now we're gonna put together AI agents and we could barely figure out how to secure the identities of machine software and people. But now let's just add in millions of AI agents. I'm kind of looking at all this as a security recipe for disaster, but I don't Know, what's your thing?
Well, yeah, so of course, obviously that's sort of the first thing that, um, that I, that I thought about. Um, I think, yeah, there, there are a lot of issues here that could come up. I mean, again, with the AgTech ai, um, it's, it's already that issue's already been raised just in general about, uh, security.
And, uh, I also think anytime you create this kind of Frankenstein mishmash of, of things, you open the door, uh, for some real security gaps. So, um, it'll be interesting to see going forward how they integrate and, uh, what kind of enforcement they put sort of across the board, if that makes sense. So, but I definitely worry, uh, about that.
And then we've also done a lot of stuff recently, right, on how AI can be used for good and also can be used for bad. So I think that's, um, it'll, it'll be interesting to see if the, the bad guys get any leverage from a, you know, sort of a deal like this as well. John, I wonder if Salesforce is telegraphing who they're gonna buy when they start putting together these little cliches.
Like for instance, we talked in the show not too long ago about, you know, Salesforce bought convergence and after talking about the fact that they had AI agents, they went out and got a company that has AI agents, and then they talked about trusted AI and Einstein for a long time, and now they went out and bought a company that has the governance tools to implement, said, trusted ai. So what else do you think is gonna be on their acquisition list? Oh, wow.
I just, that's, that's a good question. You know, um, I wonder, I mean, you mentioned security and we mentioned data integrity and compliance, and mish mashing almost, I almost feel as if they have to have some sort of consulting arm or some sort of consulting play or somebody who kind of over, you know what I mean? Like, it manages all these disparate pieces.
Like, like you said, Terry, it's a Frankenstein monster. And one of the things, without, without getting myself in trouble for breaking an embargo, there is a gonna be a survey coming out about shadow AI and about the, um, the unintentional use of AI with all these pieces coming together and how that leads to a lot of different issues. Um, so I think they, maybe they, they look at that, you know, what they almost, and they almost seem to do to me is they, they, they are very, very, um, uh, uh, attentive to what Wall Street says, or how Wall Street reacts, and they almost tend to veer since they're, they seem to have the cash at hand or the stock at hand to kind of auto correct.
They kind of tack their, their, um, their path to what the reaction is. So I I, I really do wonder, um, again and again, I had another analyst I talked to who, who mentioned this, Keith, uh, this idea that, that Terry's, that Terry brought up, approached about kind of piecing it all together and gluing it all together, because right now it's, it's an an overwhelming mess. And I wonder how their customers, I think about Salesforce customers, you're gonna go from one extreme to another.
Now, you know, how do they interpret this? I mean, I, I'd be a little bit, uh, concerned if I were them. I'm a little trying to figure out how they're gonna do that without p*****g everybody off.
I mean, let's think about how do we use this stuff, right? So the average end user is pulling together documents from here, there, and everywhere, and they're not really taking a minute to kind of think about, well, geez, is this doc that I'm about to expose to Jet GBT or Gemini or whatever it is, is this proprietary information that shouldn't be shared outbound that to them they're just trying to build a, you know, some sort of marketing collateral or some sort of sales proposal or whatever it may be. And they're just cutting and pasting stuff and throwing it in there and pressing the button and helping something good comes back.
Um, so, you know, Terry, if, if there's always been this tension between ease of use and security, but at that granular level, how do I get in there and kind of make sure that the right policies are being followed in a way that this doesn't aggravate everybody to the point where they just go home and do it there. If I knew exactly how to do that, we can make a, a mint of money here. Um, you know, I think that takes time.
And I think it also takes some real discipline and it, and, and, and I, I'm gonna say, given who Salesforce is and who they've always been, they've probably got some stuff in place, right? To, to start applying some, some discipline here. Um, I, I can't imagine that they're gonna let it continue to be, uh, you or, or, or foster this giant sort of, I don't, I can't say the word I wanna say, um, uh, about it, but, um, I feel like it's Begins with and ends Exactly.
That's the one. Exactly. And so, um, it's funny how easily that thing wants to come out.
Um, but, um, I, I think it really is gonna take the discipline. I also think there is gonna have to be tremendous oversight, and then you're gonna have to have policy, uh, I guess this is always true with security policy with teeth, you know? Um, otherwise, it, it, it, it's not, it's not really worth anything.
It won't, it won't solve any of the problems and people will continue to abuse data. Um, but, uh, yeah, I, I think that's, it's, it's just the, the discipline thing. It's gonna take some time.
And again, I think they probably have something underway. Y you know, there's, yeah, I was gonna mention, there's, there's a guy, I've, I've talked about this guy before on the show. There's a guy I used to work with who's a consultant to Salesforce, and he was telling me, he's giving me an update on, and what the reaction among the customers is, because he's in a sense, kind of a liaison between the corporate side of Salesforce and a lot of their customers.
And so he goes to their, their trade shows, and he talks to the customers and gets feedback. And even before the last two acquisitions, he said what he was hearing from the customers at Salesforce was a, a high degree of frustration about trying to follow what's, what's going on, and trying to keep pace with what's going on. And, um, they, they, the, the customers felt this urgency to jump into genic ai, yet they also felt there's like a disconnect with Salesforce, and that they're not getting what they want on a very low, low level task, a granular level.
And they're getting, being overburdened with these kind of high flying highfaluting, uh, concepts. So he said they're, they're, they're trying to kind of marry the two. So there is a, there is like a frustration, um, among the, among the customers, and they're trying to kind of thread the needle, so to speak.
And it's not easy. I mean, what they're trying to do is so ambitious, and they're trying to do it incredibly quickly. So it's, you know, there are gonna be lumps or wrinkles in the road.
So, you know, to their, to their, as Terry said, they've probably got mapped out this framework where they kind of try to make it as easy as possible with the customer, or they might find themselves in in trouble. I don't think it's actually too, I think, I think you're right about all of that. I I, but I don't think it's gonna be as quick as maybe they want it to be, or as they, No, it's not that, that was the frustration, the, the, the customers feel like this urgency, they have to move fast.
But, um, it's, it, there's so many factors, right? It's, it's not just the budget. It's like, it's not just the data integrity, it's like the upskilling of the cus of the, of the employees.
They're not ready to use it. They have to be pragmatic in their use. I mean, there's like this whole political jungle that goes on.
There's so many factors that these vendors, I'm sure they're aware of them, but they kind of, kind of paper over them and assume the companies are gonna move like highly efficiently. And these, a lot of these companies are just trying to find their way at this point. I'm wondering, um, I don't know.
I'm, I'm trying to think about that a minute, about the upskilling thing. I'm always interested in that upskilling and reskilling people 'cause it's so important, right? Moving forward in Ady dynamic environment and everything.
I'm, I'm wondering, is that easier, uh, in, in this case? Are there some synergies there, um, that make it easier to maybe, you know, bring people up? I mean, you're not bringing them from these sort of old fashioned kind of processes and ways of doing things.
They're, they're sort of, the employees are sort of on that track anyway, right? Very tech oriented and very, What is this thing called upskilling that you're referring to? In my experience, I've never actually seen upskilling talk about.
I know. It's like, I, I Never, I never wrote that in a story until the last several months. You know?
And I, Journalists don't get upskill, Mike. I'm just saying, I don't think anybody gets upskill. You're on your own.
You gotta go figures, figure it out for yourself. It's, but Look, your, your employees are your brain trust and you know, it's easy enough to, you know, pigeonhole people. And then when you start making cuts because of economic reasons, like, you know, we're going into a very flaky economic, uh, uh, arena now, uh, you know, you typically lay off people and you know, and, and whatever, and then you end up hiring people and having to train them.
It's like, why not take those people that you have that already know your company and already know your process and already know it in, in theory, it's a really good idea, right? To, to upskill and preserve that brain trust. But in, in practice, I'm not sure it happens In theory, it's in theory, it's an awesome idea.
In practice, every company thinks that they're the Yankees of the Dodgers, and they're just gonna go and get a better third base. And turns out that there is no merit third base. So, I mean, you know, it's not funny, but, you know, you see all these companies lay people off and including the federal government, and then they gotta go back and hire 'em again a couple of weeks later.
'cause, you know, whatever they thought was gonna happen isn't gonna happen. But I want to ask John one last question on this topic. 'cause I lived out there, and I am a little nostalgic, but you know, when I see Informatica get acquired, part of my soul wants to wonder, you know, is the old guard of the valley going away?
What's going on, John? Yeah. You know, Informatica is an interesting story because as you know, um, they went public and then they were, they were, they went private, and then they went public again, I think in 2021.
And I think of this, uh, Amit, I mean, they're down the road from where I live. I, I go down there and visit 'em once in a while. And to me, it was like this era, right?
Of all these companies that you mentioned that we, that we, we think of that, that kind of fall within this huge basket that include Informatica. They're just going away. And I think it makes me think of what Alan talks about.
And he, he drives this home in, in the age of ai, like in any way, they're gonna be three or four major players. And I, and my kind of like, it saddens me to think that a lot of the companies that you and I covered, Mike, are just gonna be part of these larger behemoths. And that's just gonna go away.
I hope I'm wrong. And maybe, um, some startups fill the gaps, but there's kind of this era of, of, uh, these, these kind of venerable companies just being snapped up and being absorbed by someone who's bigger. Hard to imagine that all this winds up being the answer in a trivia contest in a pub somewhere.
But that's where we left all guys. We're gonna move on and we'll be back in a minute. com.
There's a story about a research report from our friends over at the Futurum group talking about how it seems like people are actually investing in the technologies we're gonna need to secure our software supply chains. And there's a lot of them. And this whole investment area, frankly, it's a long time incumbent.
I think we have been talking about DevSecOps now for the better part of half a decade, maybe more. Terry, as you look at the numbers and you see this report and you talk to folks out there, are we finally getting it? Are we, are we making Maybe, so like you, I was, I was kind of happy to see this, right?
Um, uh, supply chain security has been a big issue. It was amplified during the pandemic, and it's about time, uh, that, that people started moving on this. Um, I, I thought some of the survey results were interesting.
You're right. I mean, uh, they are investing in, in software supply chain security. Um, they're really aiming at, uh, application security, posture management, and, and DevSecOps.
Those are the two sort of, uh, big ones there. Um, the thing that really stood out to me, um, and, and it's like Fernando Montenegro, uh, at, uh, RUM said, you know, and, and I was really glad to see this, there seems to be, uh, more collaboration, uh, between sort of the app development and, and cybersecurity teams, which is super important. And you used to see, I mean, probably for years, wrote articles and looked at research that showed a real disconnect there that created all sorts of friction and, and tension.
So that is a real positive that, you know, I see from, um, from, uh, the, the survey results. I mean, I, I, I'm, I'm keen on that. We'll, we'll see in practice if they're really doing it.
And, uh, you know, but for like a little over, I guess 30% of them to say that, that they didn't have that kind of co collaboration and the bulk of them to say that they did. I mean, that's great news. What is that old saying about beating your head against the wall and then expecting a different result?
I think that's called DevSecOps. This is the part that drives me crazy. I mean, so let's get this straight and I'm understand when exactly what's been going on here for the past decade.
Um, security people go look for vulnerabilities and they find them, and then they dump 'em in a spreadsheet and they throw 'em over the wall to a bunch of developers who have maybe, um, about 5% of their time per month, they go fix something. And most of the times it's not vulnerabilities that they're after, they're after other bugs. But if and when they do get around to fixing a bug, it will be the easiest bug they can find to fix, not the one that's most serious, because, well, you know, I got other things to do.
I'm being compensated for building new features and not fixing the crap that I broke or somebody else broke a couple of years prior to that. Then to add, insulting the injury, once I go looking for these bugs that come over from the cybersecurity people, I find that most of the time it's not actually in the code that's running or that the application in question isn't even facing the internet. So I'm kind of like shrugging my shoulders and going, why are I just spending, you know, a day and a half going looking for this stuff in the first place?
This whole thing, this, this whole area of application security has been kind of in the redheaded stepchild of security because the developers assume the security people were doing something about this. And the security people, when you put it to them, were like, well, I'm gonna use the budget for this stuff that I can control, namely network security and endpoint security, but I have no control over software development and application security. So I'm assuming those guys are gonna go fix it.
The thing that I like about this report is it suggests that adult supervision has finally arrived in the room. And that folks are actually talking about, well, maybe we'll co-fund these things together because we have a vested interest in, I don't know if there's fewer vulnerabilities, maybe just, maybe security people will be less stressed out. Call me crazy.
But John, does this amaze you how dysfunctional it is in reality? I was gonna ask you, what, what, what changed what made them decide to, to to kinda become more adult in, in the behavior af since this has been such an issue for so long? I mean, is there like some pressing issue?
Um, I, I feel it's just been one, you know, vulnerability disclosure after another, but it kind of started in my mind with, uh, SolarWinds probably was the first one we kind of brought the power. Did do you, do you, yeah. Do you suppose it gets accelerated by what's happening with CSA and, and what's happening with this government stance towards people like Chris, Christopher Krebs?
I mean, I, I'm just wondering if there's like this kind of, of self-protective, uh, mode that the industry's in because they don't like The government. Yeah. The industry's taking on more of the burden, right?
Of and, and more of the protection because the government's certainly not gonna not gonna do it. And, and the industry's gonna be, you know, vulnerable because if something happens, I mean, it, it's kind of on you, you know? Um, and I, so I, I think you might be right about that, that that they're just taking on more, given the, the ceases stuff.
Um, which is really a shame, you know, I'm just gonna throw that in. I think it's, uh, you know, um, ceases being sort of dismantled or, or destroyed, um, at a time when it's probably even more needed. So I don't think c is saying anything that hasn't been said by managers before, but I think that every manager out there will recognize this other piece of dysfunction that happens in the world, and that I can stand in front of my staff or whatever for two years and say the same thing whatsoever.
And then the minute I bring in an outside expert who says the exact same thing, everybody in the room goes, aha, I get it. That's cisa. Yeah.
Well, that looks like an RSA that one of the themes, or one of the takeaways was, you know, industry, you, you, you watch yourself, you know, you're responsible for yourself. You get together and, and, and figure this out because we're, we're moving on to, to, to, I don't want to sound like, uh, Alan, but you know, we're gonna concentrate on the border and security. I mean, that was kind of like the takeaway, but I also just wonder if this, this, this whole idea of, um, security maybe, is it accelerated, I think perhaps by all these acquisitions and all the kind of, the use of data more so than ever through, uh, a genetic ai.
I was wondering too, if that the AI effect kind of has people scared and, and the possibilities of what could go wrong. You know, when they're in, they're rushed to, to, to, To move format, Be scared, new Platforms, be scared, you know, they should be, and maybe that is a bit of a wake up call. Uh, I look at that question on this from two sides.
One is, yeah, the first generation of these AI tools are probably generating more vulnerabilities than we care to admit. 'cause they were trained on code that was pulled from the internet, and that code was created by, well, humans that wrote flawed code, and then we drove it into production environments and the machine ate it up. Now, theoretically, the next wave of these tools should be trained on code that's better vetted for security vulnerabilities, so they won't be in there in the first place.
So the AI might make a better decision. And then it becomes an interesting question in my mind. So, which is more likely to inject the vulnerability in a piece of code a machine that's trained, or a human who's generally untrained?
So you gotta ask yourself in the, you know, in the short term, it's probably gonna get worse, but I got a feeling it might get better soon. But Terry, am I being overly optimistic? Um, no, I, I think it probably will get better soon.
I also think there's maybe another dynamic here, uh, when it comes to, I'm, I'm looking at that sort of collaboration between app development and cybersecurity, and that friction that used to be there and now seems to be waning, uh, or at a lot of companies. I'm wondering if we're finally sort of shedding our old skin about, you know, the way things were developed in the past, right? You had those, you know, the sort of the old guard that developed in very closed environments and, and a lot of the, um, issues that they had security wise when that was no longer the case, right?
Um, were because they were no longer safe and secure themselves, right? And now you've had all these vulnerabilities, things that, uh, and, and, and issues with code that, that sort of get out there and open servers. I mean, I wrote about a zillion stories on open servers, which didn't seem like, you know, those buckets should be left open under any circumstances, but I'm just wondering if that old guard is going away and there's a new way of thinking, or people who have been more trained sort of a, a again, in, um, more modern development, if you will, and now they're seeing the need for security and the security people are seeing the need to work with them, and maybe, maybe we are shedding that skin, you know?
So I, I mean, I'm a little optimistic myself. I, I read this, this study with, uh, you know, a little bit of happiness in my heart. I think they're getting better tools and people will do the right thing.
I don't think any developer got outta the bed and said, let me go develop some insecure code that said, uh, we allowed a culture to exist where we, you know, we said, well, uh, you know, vulnerabilities are just the cost of doing business, and we hope nothing bad happens. And that is shifting. I think we're moving to a climate now where people are saying, Hey, if you've got a vulnerability that's especially, you know, a low level SQL injection or things that should be routinely caught, and you're, um, application and it finds its way into a production environment and gets exploited, yeah, that's not the cost of doing business or an unfortunate incident that's just lazy.
And I think, you know, as we move along here, we're gonna move from, you know, we're gonna give you the right tools and tell you, you know, hopefully ask you politely to do the right thing to, you know, pretty soon we're gonna start shaming developers for letting stuff go through that. You know, it's one thing if it's a zero day that has some new vulnerability that just got discovered, but it's quite another, if it's just some sort of thing that's been on that oasp list for a decade now, and people are still making the same mistakes over and over again. But I don't know.
So John, as you kind of think about all this for a minute, um, do you feel better or worse? I, you know, so before you, the approach you, you mentioned was almost like triage, right? Let's, let's only address the wounds that we can, we can patch up and then, and send a soldier back into battle.
Uh, and let's overlook the, the big, so I'm actually optimistic at, uh, I think in the short timbers, you said there probably will be, um, some pain, but in the long term, I sometimes have more faith in machines in terms of these types of issues than others. Um, they're be they're working based off of data and they're, they're not biased and they're thinking, I, I hope so. Maybe I'm, I'm a little bit in the short term I'm scared, but in the long term, I'm more optimistic.
So I guess yes, which is for me, a uh, a uh, surprising disclosure because usually I am a little bit skeptical about these things and, and a little bit, uh, nervous about these things. I am still worried though, that if 80% of the code is open source and that original open source code was created by some maintainer somewhere, um, and then it works its way into a downstream piece of software. And then there's an issue where the vulnerability, so let's say, um, you know, Joe's CIO or Gene CIO, and then, um, wanna get that patched, I gotta go get the maintainer to go think that that's important enough to patch and do something about.
And then the maintainer is not getting paid usually for this project. So the maintainer may not think that giving up their weekend to go deal with my issue is worth their time and effort. So there are all these dependencies in these applications Yeah, Terry, that, um, we need to kinda have a better way of thinking about.
And if there's no maintainer, I mean, and you, Or there's only two maintainers, right? And so I, yeah. So yeah, I think you're, I think, I think you're right.
We have to start thinking about it differently. Again, it comes down to some discipline and some expectations and some, you know, some teeth to what your policies are and how, how you're doing things and what, and what you say you're doing matches with what you're actually doing. But I, I do think that it's, uh, I'm still optimistic.
I just feel like it's gonna be complicated. All Right, folks. Application security continues to be a tale of two cities.
It was the best and worst of times we'll be for a long time in the cough, we'll be back in a minute. Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching it, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, you're back.
And we're gonna revisit this whole feud between the President and Apple, which took another turn when I guess Donald Trump revealed that he had previously told Apple CEO Tim Cook, that there would be 25% tariffs on iPhones not made in the US there. Why? Especially if they are moved to India or wherever, or not coming here to manufacture them.
John, I know you looked into this and the first thing that everybody's talking about is, you know, what that would do to a cost to an iPhone would be exorbitant. It'd be ridiculous. I feel, I feel terrible for, for, for poor Tim Cook.
Remember, um, during the first Trump administration, Trump liked him, even though he referred to him as Tim Apple. He really liked him. And you know, he, he, he, he admired the company and, and Cook did a very masterful job of kind of playing to his ego.
But I think, um, and this is gonna sound really juvenile, but I think part of this, what's going on right now, and this was revealed by the New York Times, and a story, I believe was a couple days ago, that Tim Cook turned down the chance to be part of this Middle East trip where Trump and a bunch of tech executives went to, uh, the Middle East, and especially in Riyadh, and, and announced some deals. And, and he kind of, genuflected Cook turned down the opportunity to be part of that. So I think in a sense that hurt him, but it longer term wisely, very wisely in the long term.
'cause he'll be along. I mean, he'll be around longer than than Trump. I, I would think.
But the, this whole idea of threatening Apple with, with tariffs if, unless they start building iPhones in the United States, is so patently absurd. There've been studies done on it. There've been research reports that have come out, first of all would take quite a long time and a lot of money for Apple to build out these type of facilities.
And then to find the labor and then to the, is it put the outlay for equipment. So the, the the opt the, um, I would say the conservative guess is that the iPhone would essentially more than double in price. It would be 3000, $3,500.
No one's quite sure what the price would be. There's also this, here's this other, this other thing that has come into play. Apple has telegraphed this idea that within a decade we may not have iPhones anymore.
We may have some sort of AI device that they're, they are gonna be working on or working on already that would replace the phone. So why would you spend all this time and effort and money to build more iPhones in the US when you're gonna move to possibly another product, and that they've telegraphed that for the last year or so. So there's, it's, it, it just, it, I mean, it just makes, it makes me, it drives me crazy because in a sense he's going after one of the more successful companies that's trying to be reasonable, that has made a commitment of $500 billion to be spent in the US on infrastructure in their own projects.
It, it's, it, it's just, it's just a bargaining chip. You know, when Mike and, and, and, and Terry, he's going, Trump's gonna change his mind again. He'll drop this idea and then he'll move on to something else.
You know, just like with China, I, go ahead. I'm sorry. I, I just don't even think he really wants to bring it, he wants Apple necessarily to bring it over there.
I don't think that's the point. I mean, I think the, the point is to dominate and, and, and control and, and, you know, whatever agenda and narrative he has in, in his mind, um, I'm getting whiplash from this, this whole tariff situation. I'm, uh, you know, but I'm, I'm also looking at the, the market and I'm kind of wondering if the market stopped responding to him doing this too.
It's seemed a lot more even. And it's not 'cause things have gotten better, you know, I just think, you know, maybe people aren't responding anymore, um, to this, this, you know, in, It's just, it's just, it's just absurdity. It's like a, you know, the, the, it was the same time that he threatened the, the, the tariff of against Apple that he threatened the tariff against the eu.
And he had this June 1st, you know, doomsday deadline, which is since, and since he's pushed back, you know, there'll be a 90 day moratorium. Uh, it is just, it's just, it's, it's just like a, he has a bunch of shuffled, a bunch of, uh, index cards in front of him, and he is mixed them up in the wrong order. And he's just kind of, uh, reluctantly plucking one after another, reading something off that will change.
And you're right, Terry, I I, I think that every time this happens or there's a thread, the market just is gonna start shrugging it off because they know that This is cluster and, and companies are gonna make the plans. I mean, listen, I, I've worked with a bunch of economists and they said, you know, the worst thing that could happen when, um, you know, Trump did blanket tariffs and created this uncertainty in, in the market, and people couldn't make their plans, their business plans, right? And prices went wacko and the, the whole bit.
And I think what you're seeing now is that companies, at least privately will be defying him and going on with the business plans that they think that they should have and the conditions that they think that they should be in. And maybe they'll have to adjust, who knows? But they, they will, uh, outlive him, so to speak, you know?
Um, and um, so I, I think, I think you're gonna see a lot more of that. I mean, to me, the thing with Tim Cook a again, is a little bit like his thing against Harvard. Um, I just, I think there's just that, these elements in there that we don't know or care about, you know, I mean, two, two things are gonna happen.
First is, um, Trump's gonna wind up threatening Mexico with additional tariffs because instead of smuggling fentanyl over the border, the people will be smuggling iPhones. That'll be sure, right. That'll become a thriving little business.
And there you go. And then if I was Tim Cook, I'd be like, I got the answer here. I'm gonna build a factory in Florida.
It's gonna make $10,000 gold apple smartphones, and for an extra 5K you can put a Trump logo on it too. Exactly. Yes.
We, yes, we talked about that, right? That He's gonna, He's gonna, you know, that's not out of the, that's, it sounds absurd. It sounds absurd.
That's, that's a potentially, I mean, apple wouldn't do it, but there, there's an idea. He might discuss the idea with him, and then Trump will forget about it. But just, you, you, you appeal to the va, the, the, the vanity.
You know, the one, I think the one thing that may have triggered Trump too though was, uh, during Apple's, I think it was their latest, uh, quarterly earnings call this month, cook said something, I'm gonna read it. He, so cook is, I mean, one of the great operations experts, regardless of the industry in the history of business, in my opinion, and he, he said he expected the majority of iPhones sold in the US will have India as their country of origin. They're gonna, they're gonna do that, and they're already doing it.
They're already expanding. Um, they're, they're diversifying this supply chain because he is smart. Um, but, uh, it, it's something again, he's, he's, he's navigated fairly well in terms of how he's handled Trump.
And, you know, the, the smart thing that, that, that Cook has also done is he's not responded to any of these threats. And if he has, he's only kept it with its executive staff. He's, he's really maintained and controlled the narrative here.
So, um, I think he'll Let, let's be fair to him too. I mean, it, it's a rock and a hard place, right? 'cause on the one hand, there's Trump, but you know, the people running China aren't exactly all that same either.
So he's probably saying, you know what, maybe I will go to India and see if I can put some, Right. He's, he's dealing with two of the most difficult governments in the world, our own in China's. And, um, you know, the other thing that doesn't help cook, and I always think about they have to develop, and we've talked about this before, but I'll say it again.
They have to develop something outside of the iPhone. I mean, the, the, the whole headset didn't just kind of came and went until Apple Intelligence. We've had people leave the company because they're so frustrated with the lack of progress.
Johnny, I have ended up selling his, uh, his project, um, for AI devices to open ai, which is a big black eye for Apple. So Cook is feeling all this pressure. Um, and it's, it's, it's gonna be interesting to see how he fares, because you cannot depend on the iPhone.
And that's kind of put them behind the eight ball here with Trump. And maybe Trump in, in his own weird way, understands that. I don't think he does.
But, um, it, it, Apple's came by one device company and it's all predicated on that device, so it makes them vulnerable. Mm-hmm. So is the future some sort of Star Trek communicator thing that I tap on my chest that's connected to my glasses with my email as I go through?
Or how does that kind of look to you Remember the knowledge navigator? Yeah, I do On Scully era. God, wouldn't that be interesting if we went full circle back to something like that?
Huh? I it was ahead of its time. Yeah.
But you know, the funny thing is, everybody's gonna get glasses whether they need 'em or not, right? 'cause you gotta use 'em to get to the computer. So I know, I know.
We didn't just become way more attached to like, whatever that is in technology terms, and then way more distanced from each other, just weirder as a society. I mean, I don't know. What I, what I wanna know is what's the upside of Apple in Trump's mind?
I mean, and I guess I don't wanna explore that his mind too much, but I mean, what's the upside of bringing the manufacturer over here of, of iPhones anyway? What kind of jobs does he really think that would bring? I mean, Howard Lunik said there are a lot of screws to put into the iPhones and what that would be some stimulating work for people, but also how much could Apple possibly pay people over here to, you know, screw in hundreds of screws?
Who wants those? Yeah, it's like, that was a problem. Like in China, the government there understands that they have a shortage of, of workers in manufacturing, they gotta start going to robotics.
You know, they, they're already looking, they're pushing it. They're like, no, we can't fill these jobs. Who wants them?
I'll give you a glimpse of a future is talking to a friend of mine over the holiday, and they're in manufacturing and they have a big operation in Vietnam, and they've been there now five, six years, and they hired 300 people when they started, and they still have 300 people. But that factory is 3000 times more productive because those 300 people have been augmented by robots. And so, you know, over time though, you can see how the math's gonna go, whatever manufacturing is, is gonna be more and more robotic over time.
And there might be a couple of people standing around to be quote unquote in the loop to supervise this thing. 'cause you know, the only thing bad about robotics and AI, of course, is it's one thing to be wrong. It's, it's another thing to be wrong at scale when suddenly there's a million germs of yogurt that suddenly needs to be cleaned up.
But Well, maybe here's a, you know, the, there's a, there's, there you go. We'll come full circle on this. Maybe there's an opportunity for upskilling there.
Um, you know, for people to manage the robots or the robotics. There you go. I'm gonna, yeah.
And there'll be like, degrees of expertise, right? I'll be a first, second or third level robot supervisor. That's something to go home and talk about over dinner.
Thank you. Hey, I know one thing you better is train yourself for that job. 'cause nobody else is Yeah, I, I just, well, I just feel badly for Apple in a sense.
They're, they're, they're the whipping boy for now. Used to, it was Amazon and Jeff Bes Bezos until he made nice, and I'm sure this will pass this, she, this too shall pass. And then Trump will fixate on another company or another executive.
I think the fact that Cook is just kind of laying low is the best strategy. Eventually the Trump will move on to something else, Right? I think, no, I have a name for that job I just described.
You are now officially, you're officially a robot wrangler. You could explain that to people at home. Sounds much better than a robot manager.
So Robot Wrangler, there you go. I like that. Start looking on LinkedIn because you know that that job title's gonna start popping up there, Mike, you Yeah, it is.
And then we're all gonna wind up going to the Robot Wrangler conference. It'll be a fun, it'll be in Las Vegas, of course, at the Venetian, but yeah. And, and right now somebody's typing in that URL to see if they can claim it.
All right. Anyway, guys, enjoyed the chat as always. Thanks for being on the show, and thank you all for watching the latest episode.
You of course, please stay tuned. We have all kinds of exciting content coming up right behind that. And until then, we'll see you tomorrow.
Hi everyone. Welcome back here on Textron tv. If you're watching this on, on our Textron, uh, tv, uh, feed grade, if you're watching it on demand or somewhere else.
Great. Thanks for joining. I'm Alan Hummel from Techstrong, and I've been looking forward to handling this interview for some time.
I want to introduce you to Paul Turner. Paul is VP of products for the VCF division of Broadcom. Hey, Paul, how are you man?
I'm doing great today. Yeah, it's a, a wonderful Thursday here. So What, what could be bad?
You're out in the vineyard probably having a nice glass of I day, Ver day. I wish I was out in those vineyards. So those vineyards are actually, I, I like, I love their Sonoma vineyards.
I love biking up there. It's a phenomenal place. So anytime anyone's around there, go biking, get up, get out in the fresh air, enjoy the vineyards, enjoy the wines.
Absolutely. Well, I mentioned you're VP of VP of products of the VCF division. Uh, most of our audience, look, they know who Broadcom is, they know VMware, but there might be some people who don't.
Talk to me a little bit about what, what VCF stands for and what the VCF division at Broadcom's about. Yeah, so if you think about, uh, you VMware Cloud Foundation and, uh, the main focus, you kind of think back to VMware, right? Providence of us 25 years ago.
What did we do? We didn't just increase, you know, deliver the best virtualization possible to actually get efficiency off servers. We changed the way data center operations worked because data center operations, you could suddenly actually define kind of perfect specs of what your applications, your VMs became, your encapsulation of your applications and your services.
You were able to deliver them onto this IT infrastructure and do it much more efficiently and get density, get cost efficiency. But you look at it today, while that's great server virtualization to actually deliver an agile cloud environment like you can do in the public cloud, you need to deliver more. You need to virtualize your data center.
VMware Cloud Foundation is about virtualizing your data center, your infrastructure. That means your compute, your network, your storage, your automation you need. So you can deliver for any application containers, VMs, you can deliver an application platform surface that they need.
And it's very easy to operate for the big enterprises, or you can deploy it up on a public cloud. We are, we're supported on all of the major public clouds and the set of our service providers. So, so think of it as taking virtualization to the next step.
It's about now delivering a full cloud service to the customer. So you get that agility of operations and that delivery the customers need. Absolutely.
And of course, right. I always like to tell people VMware may not have invented the hypervisor, but they certainly are the people who brought the hypervisor to the market in light, in ways unseen before, and, and really was, it was the, the spark that ignited the whole cloud movement. Yeah, Yeah.
Innovation is all, all, All public Innovation's, all about bootstrapping on top of each other. How do we keep continuing to innovate and build better products? You know, what we are doing now with Cloud Foundation AWS showed us that we could actually build on top of virtualization and deliver a cloud service.
What we're delivering in cloud foundation is really that full encapsulation of a software-defined version of that. So everyone bootstraps. Yeah.
Abso well, a friend, Brad Felds a big vc. He always tells me 99% of what we do in technology is evolutionary, not revolutionary. Yeah.
It's that 1% revolutionary that we all build on top of and bootstrap to your words. Hey Paul, just real quick, be give him a sense of your, how long you've been with VMware, what else have you done? Yeah, Yeah.
So about eight years actually at VMware. And, uh, I actually led, uh, the first integration actually of Kubernetes into VMware and into vSphere, uh, back in version seven. Uh, and so it was, yeah, it's kind of a exciting time.
It's nice to see us actually take that much further. Uh, we've done a lot of work in it recently. Uh, my providence, uh, i storage background, uh, big, you know, originally a software developer at Oracle doing cluster development, uh, way back in the mid nineties.
Uh, that kind of stuff went on into, you know, product management and leadership roles across the, across the industry. But, uh, yeah, glad to, glad to be here. It's nice to, you know, know that, you know, the impact that you can make as VMware.
We've, you know, nearly 400,000 customers and how do we actually deliver cloud platform service to them? It's, it's it exciting to be here. Absolutely.
So Paul, you mentioned, you know, involvement with Kubernetes. Let me tackle this one head on for whatever reason, and I don't know why or how, but there was this perception, or there is this perception, maybe it's ongoing mm-hmm. That when you are, you know, we talk about modernizing applications, hosting applications, you have a choice.
We can go the virtualization hypervisor VMware for all intents and purposes. We could go the VMware route or we wanna go the, you know, the new kid on the block with cloud native, you know, microservice, Kubernetes kind of stuff. But for some reason, the perception, as I say, maybe it's a misperception, was you could do one or the other.
You can't have peanut butter with your chocolate. Now, now people in the know out here, our audience, they've been hosting Kubernetes on hypervisors from day one. So I don't know where, how this whole thing blew up.
But give us, first of all, if you have an answer to that, I'd love to hear your theory. But secondly, let's talk, let's blow that theory out of the sky here. Yeah.
And, and talk about Often, often, uh, often vendors lead to our biases. Uh, and sometimes vi vendors are biased in their view in terms of whether I should drive it on bare metal that may suit certain vendors. At the end of the day, operationally, it's a heck of a lot easier to run it on top of virtualization.
And when you look at, even when you're run up on the cloud and you're running, you know, A-W-S-E-K-S, uh, GKE, you're actually running on virtualized environments. Most of Kubernetes running on virtualized environments. Red Hat, OpenShift, you know, probably 70% of their deployments are running on top of virtualized environments.
It, the pure nature of it is, it's actually very beneficial to combine the two. You get the agility of Kubernetes, the kind of desired state way of managing infrastructure, kind of GI ops led operation. Uh, it's a very, very nice way to actually deliver an application service and to, and for DevOps teams to be able to do what they do, you know, deliver applications.
But the systems teams still need to patch, maintain, update drivers, firmware, all of this kind of stuff means they've gotta do maintenance on servers. And that's what virtualization really helps with. Totally non-disruptive, your applications and your application surface.
You can manage infrastructure, you can increase it, you can scale it, you can dynamically manage it. That's the difference. And, and of course with cloud foundation, you, you know, Kubernetes doesn't just require, you know, virtualization of the compute server.
It requires virtualization of your network. 'cause you actually have to do your CNI adapters, your CNS adapters, you have to integrate your storage in. That means it's all software defined storage that you actually need.
And so it's a, it's a kind of, the virtualization benefit is significant complement. And it's actually a necessary compliment, uh, for running Kubernetes. And it's the same as you would do up on AWS, it's the same as you would do up on Google with GKE.
It's the same as you do with VCF and our integrated service, which is called VKS, uh, uh, the VMware Kubernetes service. You know, the thing I've learned in my 30 plus years nice to haves, not enough. Must have, Must have, is what's I, and there are some must haves of running Kubernetes.
I, there, there, you're right. There's a percentage of the market that wants to run KU coupon bare metal. Mm-hmm.
And they, they have their reasons. But that's really a small minority of the market here. Overwhelmingly, I think the market has voted, you know, with their pocket books and their feet and eyes and fingers that you run, you run Kubernetes in a virtualized environment.
Now, as you mentioned, you can run it on Amazon, on anyone, you know, they have several platforms, the rest of them do. But let's talk, Paul, if you will. What are the distinct advantages, the kind of killer advantages that you get from running cobe in a, in, in a VCF in a VMware environment?
Well, let me, let me touch just a couple of things. So, so, uh, one of them is, is think about running a Kubernetes environment. I have to actually deliver Kubernetes.
Kubernetes has this wonderfully short, uh, uh, support time window for Kubernetes, once every, what is it? 18 months, 16 months, somewhere around there. So you actually naturally need multiple versions of Kubernetes.
So, so we provide multiple versions of Kubernetes, but you don't just need a Kubernetes runtime. You need a, a registry service like Harbor. You need a service mesh.
'cause if you wanna actually do function as a service and integrate kind of, uh, applications together to actually deliver a container application, then you actually need a service mesh like Istio. You need, uh, an identity service, a pin, a pad integration. You need Prometheus for monitoring.
You need Valero for backup service. You need your network integration, CNS and your CNS your, your cloud native in, uh, integration for networking, your CNI or your CNS you of Many customers want to actually manage also VMs, uh, and deploy them. All of these services you have to be able to deploy with VCF, we give 'em all outta bucks dead easy.
We manage all of the long-term support for the Kubernetes platform. We actually manage the delivery of those platform. We run them as services.
So for a DevOps team, we take away the pain. Right. If you think about a, a, there was A-C-N-C-F survey, which I, which I referred to, and I I thought it was a very interesting survey.
It said 46% of the people, and it was actually 2024 survey. I know they just updated their 2025. But 46% of the people running Kubernetes say the biggest challenge is complexity.
Biggest challenge is complexity. And, and, and we as an, an industry should be abhorred by that. We should look at that and say, that's totally wrong.
It's not the way the world should be. I've been yelling about it since the first time I saw it. I came, came back and said, it'll never catch on too hard.
And the people who are fixing the complexity are the most expensive resources. They're the developers. The Developers, The developers who are actually now having to maintain versions of different components.
Like I mentioned, pin, aed, Prometheus, Valero Harbor, Istio, you know, you, you go on. All of these services should just be there. You, you gotta simplify.
You gotta, and, and they become part of the platform. And that platform is just there for you. And, and that's what's so exciting about the work we did.
We delivered the first Kubernetes, uh, in vSphere, uh, way back in version seven, but delivering a full Kubernetes platform runtime with all the services, with the long-term support, that's what's in our BCF nine. And that's what's very exciting. Yep.
So, couple things. First of all, you just made the argument why we need platform engineering. Yes.
Right? Asking the developers to develop their own platform Yeah. Is really, it just doesn't make sense.
It's wasteful. Yeah. Right.
And hence, you, you need platform engineers to put these platforms in, in place. Now look, not everyone is gonna be as familiar with the, uh, VMware nomenclature numbers and all of that. The fact of the matter is VMware has been working with Kubernetes since like 2018 or thereabouts, if I'm not mistaken.
Right. I, I mentioned the first time I saw Kubernetes, probably 2016 or 17. I, I thought it would never catch on, which is why I'm still working and not out in Sonoma.
But, um, it was hard. It's been hard. It's always been hard.
You guys have been working with it since 2018. Yep. Talk to us how that evolution right.
Has evolved over the, from 2018 to today, and you know, where it was then, where it is now. You were just a cube con. You're up on the latest.
Let's hear what, what you've got. Yeah, Yeah. Well, you think about it, right?
2018, I mean, that was the very beginning of Kubernetes. So the, the founders at Kubernetes actually at Google, um, spun off, started a company. Hept Hept actually was acquired by the mware.
Uh, that led to our first integrated Kubernetes, uh, that we actually delivered into vSphere, as I say. Um, and in, in actually a version eight of vSphere. Uh, we actually made it free for everyone.
We included it in it's no extra cost. It's just part of the platform, version nine. It's also part of the platform.
So it's part of that VCF platform. Uh, so, so yeah, it's, it's quite interesting. And then you look at kind of some of the, the open source projects, right?
You look at Andria on the networking side, you look at the Envoy service, you look at Harbor, the registry service, these are kind of core capabilities. They were all projects led and delivered by VMware. So VMware is, is still today one of the most active contributors into, uh, the Cloud Native Compute FO foundation, and into the open source of Kubernetes.
Uh, we're a gold sponsored member, of course, of CNCF. So, you know, we are, we are here to stay. We are here to deliver the best delivered platform for runtime for Kubernetes.
Um, and to make it make it easy, honestly make it easy. And the last thing that I think we can do that's kind of unique is one of the most traditional things that you see in vSphere, which is vMotion. Uh, vMotion is still absolutely amazing.
Uh, it's, it's a kind of cool thing, being able to non-disruptively move workloads around. And you, you'd say in Kubernetes, that doesn't really matter. But Kubernetes, we're running on Kubernetes now.
Big AI applications, right? Gen AI applications. You're running a 70 billion parameter LAMA two model.
Imagine you could take that LAMA two model that's running your PyTorch application, doing your inferencing, and you can magically move that when you're actually doing maintenance mode in a cluster, magically move it without any disruption to the application. That's what vMotion ISS all about. You can do it on top of cloud native infrastructure, which is basically what we deliver with VCF.
So it's your full of Kubernetes runtime, running your most modern applications, egen AI applications. You get all the benefits, of course, of the platform, which gives you all the services, but you get the benefits of the platform and cool features like vMotion, which allows you to do the magic. Um, so that's, that's what, that's what's made, that's why there's not another virtualization vendor that's anywhere near as big with us.
We do cool stuff that, that extend virtualization. Absolutely. Lemme bring up another kinda thing that kind of gets me going.
We live in a very complex world today, right? It would be, you know, if we just kept all our stuff in one data center, or even if we just kept all our stuff on one cloud provider mm-hmm. Life would be so much simpler.
But it's not. We, we, we, we, we have multi-cloud, we have hybrid cloud. We're a little, we're a little in the data center, a little in the cloud, a little here, a little there.
We, we, you know, and every cloud provider has their own hypervisor that don't necessarily play nice with each other. Um, some people want Red Hat there or this one there. And, and the, the people I talk to say enough, we want, I gotta be able to manage it all.
I have to be able to manage it all. I can't manage 12 different platforms. Mm-hmm.
To me, this is, this is what VMware brings to the table. Yeah. Right?
Let's, you're talking about taking the complexity out of things. This, this is the real con complexity. Yeah.
Talk to me how, how you helped there. Yeah. Yeah.
Well, well, first off, I think customers will wanna run across multiple clouds. Um, yes, They will. They, they absolutely do.
I think even in the data center, right? I'm, I'm gonna have, am I gonna bet on just one server platform? No, I'm gonna have two.
I want to have arbitrage between my vendors and you're gonna have arbitrage between your cloud vendors. So, but the problem is, is yeah, if, if you've gone and built the, where the platform service and the platform experience is different, and it's, the problem is it's, it's a different platform experience now between the different cloud vendors. That's not good for you.
That's why you're seeing us look at the infrastructure and say, we can build that common VCF infrastructure that can run in any cloud. We actually support it up on Google, support it on Amazon, we support it on Microsoft Azure. We support it on-prem, same operating experience.
You get complete motion of your applications and services that you need. Same operating experience. Uh, and I think customers love that.
So that's, that's one part of it. But the other side of it is you've got to then get behind Kubernetes open source and allow the developer and the application platform to be fully CNCF compliant, fully portable, so that it can work across any platform. If you wanna move your applications and services and run them up in GKE Native versus on top of our platform as, uh, an A VKS native, uh, you can do that.
Uh, that's very important. And for us, we are committed to open source and maintaining complete compliant open source. And we hope all vendors do the same.
Because we saw what happened with Java, we ended up with this kind of mishmash, and everybody had to go and build applications per platform because it didn't give us the platform independence that we need. We can't let that happen Kubernetes. It must remain open source compliant and cloud native.
And, uh, and then we can allow the portability, the application there. 'cause that's where the main complexity, but they're two different layers. How do I manage the infrastructure policies and governance rules?
And IT rules. That's what we do with VCF. So we get it everywhere, but maintaining the application developer experience, that's why Kubernetes is so important to us.
It's why we built it into the platform. Hey, we've gone on here 20 minutes or more. We haven't really talked about ai.
You mentioned it kind of in passing, but AI's too important today to mention in passing mm-hmm. What's happening with VCF and ai? How is it, how is that affecting what's coming down?
What you guys are doing? Yeah. What the market is wanting.
So It's kind of interesting, you know, again, I'll, I'll split things into infrastructure first and then into actually the developer kind of experience for ai. But, but if you think about the infrastructure for ai, we're kind of like where CPUs were, uh, 20 years ago. We are running utilization on GPUs, which are super expensive, but GPUs, server eight GPUs in a server loaded up, you're going to spend, you know, it's H 200, nvidia, you know, latest, latest kind of processors.
It's gonna cost you about 300, $400,000 for that server. And those servers are running utilization rates somewhere in the 20 to 22% range. That's back in the days when we used to do physical dedicated servers per application.
Mm-hmm. Right? It's a, it's begs for virtualization.
And, uh, so that's one of the core things is why we've done all our work actually with Nvidia on something called VGPU. And with version nine, we actually just had done the testing on DGPU testing with vMotion, like I said, being able to non-disruptively move workloads, 344% improvement in performance. Totally non-disruptively.
Wow. Yeah. You can run wow GPU as a service.
So now I can virtualize, now I can start moving applications around. I can look at balancing so that I'm optimizing the amount of memory usage that's on that GPUI can move workloads if I find that I can't, you know, cookie fit them into the GPU memory properly, I can move 'em and rebalance them elsewhere in that cluster so I can truly run GPU as a service. So that's what we do in the core is, is we think the whole market's gonna move to, it must be virtualized, um, because it's what happened in the server market.
The same will happen in the AI market. The other side to it though, is the application ecosystem. And a, and a big part of it, like all AI applications are actually built as container ready applications.
That's the way we deliver application services. We've worked very closely with NVIDIA on, uh, what we call private AI foundation, and that means all of the Nvidia GPU, uh, capabilities. So everything that's available on NGC Cloud is actually available as runtime services and inference engines on top of our Kubernetes infrastructure.
And we deliver with that, uh, you know, a, a rag ready database so that you get that outta box, uh, and delivered with the platform. So, so that, I think it, it extends our VCF, it makes it much more capable, but it gives them all that application service that you need, and you can deploy it now onto a Kubernetes ready infrastructure just outta box. So, so kind of cool.
I think on the AI side of things, it's very exciting. We're seeing more and more of our service providers deliver, uh, AI services, uh, as a service. Um, because what you're seeing is more concern around, uh, data provenance and data locality, and it's leading to, uh, you know, kind of concerns around, um, uh, sovereignty.
Um, yeah. The more, let's all more sovereign AI services are getting built by our service providers and by our big customers, particularly when you look outside of the US region and, and as close as Canada and Mexico, but also of course, Europe and, and Asia Pacific Asia. Sure.
I was just about in Europe. And you're seeing more and more ai, uh, services delivered in region, uh, as sovereign ai. Yeah.
I, I think that's gonna be a huge piece of it. Yeah. You know, Paul, in the, in the, in the tech world, we always focus on the latest, greatest shiniest and, and if only the world were full of green fields.
But you know what, not every app is gonna be an AI app. Not every app is gonna be a microservice architected app. Not every app is modernized, optimized for Kubernetes, and it's not gonna be that way probably for as long as you and I are working, there's always, there's gonna be legacy equipment and that the same, the same way.
We don't wanna have 12 different platforms that I gotta manage 12 individually. I don't wanna have one platform for the cool apps and one platform for the old apps. I need a platform.
Talk to me, why VMware's my best choice For that? Yeah. Well, think, I'll go back and think about what you do often in the, uh, AWS cloud, you have, uh, uh, VMs, that's what you get from, uh, as you deploy, uh, your images and your, your, your VMA images.
Those are, those are VMs. And you've got a container service, right, which is the EKS service. That's exactly what we do.
You want a platform that does both. And actually in the VCF platform, you get VMs, you get container services, the container service, you can deploy basically what we call a cluster. It's a set of set of nodes.
That cluster actually has, like I said, all the Kubernetes services that you need. So you can have a cluster, which is actually your Kubernetes runtime cluster, just like you get up on Google, GKE, and you can have a set of VMs as a set of services that you run. Uh, and those two can even coexist.
You can actually run VM services. We've got something called VM service to allow you to do a full, uh, cuddle kind of, uh, desired state way of deploying VMs and services through Kubernetes as well. So yes, I think developers want one platform because they have applications that are VMs and container-based, uh, and you need both.
Uh, but also on the infrastructure side, they want to be able to manage that as one single. The, the idea of having some separate silos, kind of container based application, separate from the way you manage the rest of the infrastructure, separate from your, your ai, bare metal service that you may have it, it's kind of a silly way to go. Um, uh, I shouldn't say that to the IT people out there, but I think they know it.
Um, uh, I think, I think unification of it will, will happen. It's inevitable because everything comes down to cost. And the most cost efficient way to do that is to unify and simplify.
Absolutely. One other area I want to bring up, I know we're running low on time. We, we were talking off camera about RSA.
You mentioned you hadn't been there in a while. It's huge this year. Mm-hmm.
It was huge because security and compliance is really no kidding around become top of mind for everyone can't afford not for it to be pro a long time. VMware, one of their selling points has been, we're going to give you the most secure hypervisor, you know, virtualized environment. We have that security and compliance built in equally is true, I think, for Cloud native.
Mm-hmm. Right. Kubernetes and stuff.
If you can enunciate what some of those security and compliance advantages are from hosting your Kube K eights on, on a, on a, uh, a VMware based platform. Yeah. Well, you think it just the infrastructure side of things.
We take care of everything from, you know, secure runtime on the CPU, you know, with our integration in with a MD and Intel in terms of a MDS. So you can run kind of full confidential compute and runtime, uh, encryption of over the network encryption of the storage. So the entire platform is actually built as a secure platform.
Uh, and you've got the, you know, that that's the providence of the way we build our platform too. We're actually very careful of our supply chain. So we make sure that this is actually the most secure, trusted platform that you have.
So, so the platform you can believe and trust in it. We also go a lot further though, at operational runtime, you actually want to kind of continuously monitor and check for anything that may be go wrong. So because we virtualize the network, we can do some pretty cool things around, of course, firewalling.
So you can start segmenting your network, get isolation. That's a very good way to actually get, uh, but to, to get protection in your network. But we can also do, uh, kind of smart and intelligent discovery of attack vectors that are happening within the network.
Uh, and that's the I-D-S-I-P-S capability. And so we're continuously monitoring for what could go wrong, uh, in the network, in your operations. And then if things do go wrong, we've actually got the ability, I don't know if you're aware of this, but because we can do these kinda rapid snapshots, we can actually go back in time and unwind anything if you had a ransomware attack and actually bring back a clean version of things.
So we are, I think, the most secure platform that you can run your application on. It's, it's a critical part of, it's what, as you said, what we've always been known for, and it's what's something that, uh, we deem as, uh, you know, you always have your top three things that you must do, right? It is always your top three as product management.
Uh, security is always one of those three. It's, it has not changed for VMware, it was the same in version seven when I was doing planning for that. It was the same in version nine when we were doing planning for that.
Um, uh, we'll, we watch this one really carefully. We do fun stuff like going off and doing, you know, red teams out there to go and attack our product and see what's wrong with it. Uh, uh, we're gonna keep it as secure as possible.
Thank you. Hey, Paul, one last thing. How can people stay on top of what's going on?
What's the latest, greatest around VCF? Yeah, around VMware. Yeah.
Well, probably the best is, uh, two things I would say. Watch our blogs. Um, VMware is probably the most, uh, blog proficient company you'll get out there.
That's how we communicate lots of stuff. Like, yeah, just, just get to know us. Uh, but otherwise, I would say VM mugs, every place in the country, every place in the world has V UG chapters.
Uh, we've more than 120,000 members that are actually part of VM mugs. It's a, it's a wonderful community. It's a place for you to, it's completely, you know, free all of these community events.
You can actually just go learn in the local region. You'll learn about the latest updates of the product. You can see what they have, but you'll also learn from each other, right?
These are run by, these are user communities that are actually sharing experiences back and forth. So, so get involved, get to know the VM mugs. All the training is available, you know, for, for our customers, uh, for free.
So that's a great way to do it. So you can, you can become a proficient VCF expert, uh, as, as part of that. Um, and then the last thing that I would just say is, and, and also you get licenses by the way, uh, uh, if you, if you're trained in that way, uh, but get involved in that way, and then come join us at Explore.
You know, we've got Explorer coming up in August for those in the us. Um, we're gonna actually run Explorers across the world, you know, watch it in London, in Frankfurt, in, uh, Paris, in Tokyo, in, uh, in Australia, uh, in, in India. Um, so, you know, watch that second half of this year, you're gonna see us on the road a lot.
Um, but I'd say most importantly, look for your VM mug. Uh, find your, find your chapter and get involved. I love it.
Paul Turner, thanks so much for coming on here today. I know we took a lot of your time. I appreciate it.
I know time's not easy. We're all scrambling. Continued success with VCF.
Do keep us appraised though of what's happening. Our audience is interested in this. Thank you so much.
I'm Alan Shimmel for Techstrong. Hey guys, thanks with Throw, we're here with Chris Chapman, who's CTO for MacStadium, and we're talking about well, max and DevOps, because, well, it may be a little bit different than we think about it elsewhere, but we still need to figure out how to accelerate the development of these applications. Chris, welcome to show.
Thanks for having me. It's good to be here. Yeah, Mac is different and, uh, we've been doing it a long time, so excited to talk to you about it.
So what does making applications in the land of Apple different and where do you see people adopting DevOps? Because, you know, I mean, when I think about Apple, I think about all the different frameworks, but I'm not sure how any of that stuff actually gets deployed. Yeah, so, you know, kind of the biggest thing from an Apple ecosystem perspective is they need applications compiled on Apple genuine hardware to be deployed in their ecosystem, which means somewhere along your development lifecycle, you're using a Mac, whether that's for your ID that you start with, or whether that's for the Deploy machine that actually builds it and sends it up to the app store for approval.
So it means you're gonna have to deal with Apple in your, your supply chain. Um, and that's where, when you talk about true enterprise development, it can get pretty complicated because it's a sort of a individual desktop view of the world. And from a sophistication perspective, Apple's not the first choice.
People choose to use their cloud scalable DevOps practices. So it gets tricky pretty fast when you scale. So are there Apple specialists in, in the DevOps ecosystem?
Is there a new class of people who are kind of adept at figuring out how to apply best practices to Apple? Yeah, I mean, I think in fairness to the ecosystem, people have caught up pretty fast. Uh, apple also released an Xcode cloud, which sort of introduced ci cd principles to people who used Xcode.
Um, but past that beyond, uh, sort of CI as a service clouds where it's just sort of a, you know, a, a bit rise or a GitHub actions or something where you can kind of go and do your dev work and there might be something on the backend that can help you out with that. There's not a lot of expertise or skill in that area. It, it, it really is sort of a, a purple squirrel when it comes to infrastructure and development.
So, MacStadium Hass been around for, for 13 years plus, and, and that's kind of been our sweet spot. 'cause you know, hosting Apple is an interesting thing in and of itself in the primary use case is application build and development, or at least historically now in the new world, it's rapidly changing into other things with AI and all of that. But, uh, build and development has been the sweet spot.
For folks that don't know who MacStadium is, where do you fit in the DevOps ecosystem? So we're, we're a cloud provider, uh, akin to an Amazon or anyone else. Uh, we have about 30,000 max globally.
Um, and where we fit is private, secure, dedicated cloud. So that can be physical or we have a flagship product we call orca. And that's really where we made a big splash, uh, no pun intended, but in the sort of ecosystem there, because it is the unification of Kubernetes, which is a more traditional DevOps and data center software management tool, uh, with Apple.
So we sort of figured if we could bring Apple into DevOps practices and tooling, it would make DevOps easier for Apple. So Oracle of virtualizes and Orchestrates and containerizes and does all the Kubernetes type things. So what it really does for the Apple developers lets 'em get a tool like GitHub actions or Jenkins or anything they're used, used to, and drive it with a development tool.
And also lets a DevOps engineer use the Kubernetes that they know and love to actually control this Apple hardware that's been normally a under the desk in the IT cloud, that kind of asset, that's been a secondary concern for true operations people. So how many of these applications are completely running in the cloud, or are they more likely to be hybrid where there's a piece running on a client somewhere, but they're invoking some sort of services in the cloud? Um, yeah, that's a great question.
Typically, apple has been about Apple platforms. So mobile, you know, your iPhone, your iPad, the, uh, desktop. So once the build happens, they're often deployed out from the app store and end up on end user compute.
Uh, on that said, there are databases, there are, uh, application updates that take place on the backend. We see in the Mac ecosystem that those can often be separated from the Apple hardware. So they don't necessarily run Apple hardware in the cloud side for the backend.
They might, they might use an AWS database or they might use some other cloud provider there, but the application front end or the application on device is, uh, an Apple centric application. There are use cases where that changes. Um, and those typically range from things that are very specific to Apple.
So like image processing and, uh, graphics capability and things that are very Apple centric. We do see backend systems that also run in the cloud with those. Um, when you think about that, I mean, we, in the, I guess I don't want to call it the, the mainstream DevOps community, but there's a lot of conversations about platform engineering these days.
Is that a concept that can get applied to the way we build and deploy back applications? Oh, absolutely. And again, that was sort of the purpose fit goal of Orca was Apple should, you should be able to build different in the way they made it from a positive perspective, meaning the best applications in the world with the coolest software, but you shouldn't have to build different from a DevOps perspective.
So again, meshing Apple technology into mainstream DevOps tooling like Kubernetes, like, you know, mainstream hyperscale clouds, um, was the goal all along because you want your DevOps practitioners, your DevOps engineers, um, those guys to be able to control Apple as efficiently and effectively and securely as they do anything else, but still give the Apple developer the flexibility to use the cool parts of Apple that they like, that are very different from Linux and Windows. Of course, you can walk down the street these days without somebody leaping out to tell you about their great new AI thing. But how might AI get applied to, uh, software engineering in the context of an Apple environment?
Yeah, it is a great question, and you are right. It is the light guys these days, of course. But, um, uh, we, we actually see a really interesting momentum shift because there is all things AI from the, you know, Nvidia and from open AI and from these giant clouds.
But there's, there's still the problem of what are you going to do with AI and how are you gonna run it? There's still a growing concern about power efficiency and scale and accessibility of resources to even generate the workload that AI is creating. Um, we've actually partnered, uh, with some Apple centric folks.
Uh, web AI is the name of this company. Um, and we're working with them in Apple that, that are building AI specific to Apple Resources, which is kind of interesting because it's high power, low cost, very private, very secure. So it's a little bit of the antithesis of the hyper scaled AI that you're hearing about on all the news feeds.
But we're finding that it's creating a really interesting use case for the practical business specific. Like, your company owns its own AI to do its own thing, use case, and all the benefits of low power and, you know, somewhat commoditized hardware that you can get anywhere very easily, but has some of the best AI engine and circuitry built into it in the world. So it's an, it's an interesting, it's an interesting evolution for Apple.
Like I said, it's kind of starting to drag us well outside of DevOps and CICD into, honestly, apple is a mainline platform. 'cause now the ai, the database, the business rules, the processing, the can all happen on Apple based resources. So it's pivoting us into more of a Mac ops sort of worldview, because now you need to have not just DevOps practices, but overall system operational practices for Apple hardware and Apple Software, and how do you do it like Windows does, and how do you do it like Lend does.
Um, one of the things that I think people look at this and they kind of like the idea of it, but there's a lot of moving parts and they get overwhelmed. So what's your best advice to folks about, well, where to get started with introducing DevOps to Apple software development? Yeah, That's a great question.
I mean, as a biased opinion, I like our ARC software, and I think that's an awesome way to start. We have, it's an ecosystem of tools, actually. So it's not just one thing, but, uh, we have a free desktop tool and it, it, it, it lets you put it on a, a Mac and experience sort of virtualization, containerization.
It uses OCI compression, which is an open standard outside of Mac in general. But what that lets you do is, uh, check your, your build into something like GitHub and pass it around amongst your team. So it starts to take a person that's just, again, used to a singular desktop environment and get them used to code sharing and image building and pipeline building and tool using.
And that's a, a, a nice way to sort of start down the trail of the DevOps ecosystem. And then, you know, our company and AWS also make it super easy to start to consume Mac as compute in the cloud. So Mac Stadium, you can go on a portal and you can click it and you can get a Mac, uh, Amazon, you can get an EC2 Mac, and we're buddies also.
So you can actually go to Amazon and get ORCA on EC2 Mac and Amazon, nothing but net. So there's a, there's a couple of different ways, but we provide easy integrations off of that too. Again, you kind of wanna meet the developer where they live.
So people are really familiar with GitHub tooling and Jenkins and all these sort of traditional build tools. And those plug right into these tools that we're talking about today and make it sort of an easy way to start. You can write your code and press go, it hits the pipeline, and then this software takes care of the rest.
So, which is easier, is it easier to teach a Mac developer things like CI and Kubernetes, or is it easier to teach the software engineers that know that stuff already about how to support Mac developers? I, I also, great question. I, I would tell you, I mean, from an opinionated perspective, get convincing the DevOps engineer that Mac's not scary is somewhat, it, it, it's, uh, a harder first conversation, but much easier once you get 'em to believe you because it's plugged right in.
I think with, and the, I think the only reason that's an easier go is that, um, with the CI on the Apple side, from a pure Apple developer perspective, they really are used, they're about to work in the development. So it's teaching them, you know, broader philosophical, what is DevOps, what is ci? And that's just, that's just a learning curve that they, you know, typically have to do.
So they'd rather stay in their dev world. Well, folks you heard in here, hey, it's kind of like peanut butter and jelly. We had both of them before we put them together, but once we put 'em together, people are eating a lot more peanut butter and drilling sandwiches.
Hey, Absolutely. Absolutely. I like it.
Orcas peanut butter is, is a, is a good sandwich for me. So There you, there you go. Hey Chris, thanks for being on the show.
Yeah, absolutely. I appreciate it. All right.
And back to you guys in the studio. This is Textron tv. Hello and welcome to another episode of the Inevitability Curve.
My name is Chris Blak and I will once again be your host. And with me today is a good friend, Mike Dugin. Hello, Mike.
How are you? I'm doing fantastic, Chris. How are you?
I am good. There is, I don't know if I told, we had actually had a, a work call a week or two ago. I dunno if I mentioned this to you, but, uh, uh, before I left the boat center in Florida, I had a, a drink of the, uh, the bourbon.
You, you left on board. Nice. Nice.
So that is appreciated. Where in the world are you? I am based in Lugano, Switzerland.
So we could tell from the accent originally from the Philadelphia area, but six years here. Now You stole my joke. I was gonna say, I can tell from the accent you're from Switzerland, but I got preempted every time.
Right. So six years, I, in fact, I remember, I think we had met at a DHS event somewhere, the ICS Joint working group. Yeah.
It was weird actually. We met, uh, not actually even at the event itself. It was, uh, we met at Detroit Airport or the Detroit Airport Marriott or something like that, sitting at a bar.
Do you remember that? Oh my God, yes. Yes, that's right.
Yeah. That, that's that small world thing. We think it's, you know, you, you know, when you start narrowing it down, how many people would actually likely be at that.
Yeah. It's not that unusual, but it's still, it is still a thing. Yeah, right.
This is way back, this is probably, you know, I was working for Industrial Defender at the time, so this is probably 20 12, 20 13, somewhere in there. Yeah, Yeah, certainly before you moved that, that was your first movie. I don't think you'd even done a whole lot of international travel at the time.
So since then, you know, the world has, has, Yeah, no, at the time I was, uh, I was really focused south engineering United States. Um, uh, I started working more globally a few years after that. Uh, and then I joined the zombie networks in 2017 and moved here in 2019.
So, Neat world. It's been a while. Well, and hand roll underwear, you know, from my, you know, I, I, I was in Switzerland once back in the day and ran out of, you know, uh, uh, fruit of Loos and in the, uh, hotel, they, they sold hand roll underwear, which I realized is one of the great gifts to life and mankind.
So, uh, thank you. And your, your compat. I have never seen that, but that is a fun story.
Oh, yeah. Hand roll boxers. I mean, seriously, not to get too, too dark into, but it has to be said in the, in the green room.
We can, we might go as far as you, you could imagine on this. And, and we're talking about risks that today, right? Which is a great general topic, and, uh, we can apply it to all sorts of things.
And you and I have different career, you know, our specific career paths in this space, and we'll discuss that, that throughout this. But it's this wonderfully generalistic con concept that we all deal with. Right.
And, and as I say, just just a moment ago in the green room, the, I literally just came out of a working group meeting where we're talking about supply chain security, and we finished up some working groups. We're looking at the next working groups and someone bring up, you know, how do we bring in risk analysis all of the, you know, all of this. And I, I jokingly say, you know, my, my brain's short circuit because Oh, hold my coffee.
You know, what, what does that even mean? How do we quantify that? Yeah.
How, how do we put that in scope? And, you know, to, to perhaps get us started, you know, look at the way back machine. How have we done that, you know, since prime evil, you know, times, you know, they have the eye spot that helps you lower your risk because you can see a predator, you know, above you, between you and the light source.
You know, and in human evolution, obviously, you know, that, that, you know, we've been, our ancestors, you know, have been really good at figuring out risk by definition. Having lived, lived long enough to give rise to us and all of our iterations and technology, you know, for all that, you know, what you and I have seen in our careers and what happened before that we've apparently done well enough. We're here, we're here, how the heck did we get here?
Right. Do you have, what's your, what are your thoughts, you know, in your, in your career or wherever you wanna start with looking back, you know, actually putting quantification to risk in a practical way? Yeah.
I think, you know, I've, I've been blessed to have spent, uh, pretty much the entirety of my career, career in cybersecurity for operational technology, iot, that space. I really didn't spend a lot of time on the IT side, right? Um, and when I started this is, this is prest stocks net.
This is 2007, 2008 timeframe. Um, you know, risk wasn't something that was, that was even in the, you know, the, the, the top of mind. You're thinking about ot, iot, cybersecurity, and iot really wasn't even a thing at that time.
It was really just ot. Um, you know, at that point when we're talking about IT, cyber risk, um, the, the OT environments were, you know, completely segmented from that. So I, you know, spent a lot of time, I, you know, I did technical work, firewall engineering, uh, intrusion detection analysis on process control networks at the time.
Most of them were, you know, pretending to be air gap. They were never really that air gap, but, um, you know, segmented well enough, right? That they were kind of kept outta that framework.
And what I've enjoyed over my time working in this industry is, is that evolution now is, you know, you start to see the, the concepts of operational technology, cybersecurity, and the concepts of iot, cybersecurity start to get up to the board level. Um, they're, you know, they're starting to be accounted for in those overall risk frameworks that organizations are dealing with. And, um, you know, it brings a lot of questions.
It brings questions around what are we doing from a connectivity and a segmentation perspective? Uh, are the, you know, what are we doing from a, you know, how, how, what's the life cycle of bringing these devices in? Are we putting effort into, um, you know, checking where they come from, you know, what, how they can communicate, what they can communicate with?
And we're seeing a lot of these questions start to get to get asked up at the board level and working its way down to the executive team. And, you know, I've really enjoyed being involved in that, uh, that process of, okay, we, we need to account for the potential outcomes of, uh, it, it doesn't have to be cyber threat related, right? But the potential outcomes of, um, you know, if something goes wrong with one of these devices, how does it impact the, the overall risk of an organization?
And, um, you know, now that I've been four or five years focused, you know, more on the, the IT organizational side of operational technology and IT devices, building management systems, all the, you know, tangential devices connected to building management systems, you know, it's, it's really something that's, that's being looked at everywhere that's being looked at everywhere. And it's, it's been an interesting progression. Well, I'm glad you, glad you brought in ot, the operational technology side of this, because I've appreciated that as well, you know, throughout my career.
Because in the IT space, we go, oh my God, someone could, okay, let's be clear. What steal my information, you know, send an email that looks like it came from me as opposed to the OT world where, oh my God, someone could tell us all right? Literally, right.
You know, like, open all the flood gates or close the flood gates or whatever made the damn break or turn the lights off or, and, and, and, and enact, right? You know, one, one of my presentations in all these years, oh, I got blank on the names, uh, I'm sorry, I have to come back to it. Uh, but, but it was, but it was, it was, uh, somebody went amongst us, had gotten the job as the CISO at a big rail railroad, and the requirements going in was that you will give me these things and I would get physical access to a locomotive and access to all these things and basically turn my friends loose on it.
And they put together, um, what in the presentation they gave was called the hillbilly barbecue, where they hacked the, the train scheduling system to put together train cars with all the contents they wanted, and they couldn't get a beer car, but they couldn't get wine cars. Right. You know, apparently, you know, it's like, uh, so wine and combustibles, right?
You know, and beef and various other things you need to barbecue and then hack the, the, uh, locomotive itself so you could take control and make it go too fast around a corn corner through this one actual tunnel, um, to roll it over on the far side and pile it all up and, and actually create the barbecue. Um, and you can do that in ot, right? That's an actual thing.
And the, you know, in, in the theme of looking back, and that's why I always liked ot. I like OT by its own self, but with it, people explaining, look, we've been doing this for a long time, you know, where standards and guilds come from and so forth. That's from the people who built infrastructure several a thousand years ago, because not the first ones, but the ones who came later.
Um, because when the famine or the flutter, whatever happened, whoever built that first in infrastructure, they were killed by the survivors, right? You know, they were like, and you kind of only explain about weather cycles and so forth, you know, as far as everybody knows you're the one who made the thing that, you know, was supposed to feed our water or keep us safe, and it killed us all. Um, so we literally looked back through human history and we see these guilds and so forth, and not, not lit, not even just in our standards, but in our popular fiction.
Like, you go, hi, ho, hi, go. You know, off, off to work we go, because I'm not going to build, I'm not going to agree to the, the, the retirement of the time to build a 10,000 foot tower out of Lego block blocks, because you may as well kill me now. You know, I can't let anybody, any of my peers say that they'll do it, either.
They'll kill all of us, right? Except OT takes risk and makes it personal because it's either the risk of, you know, the, the bridge collapses, or they built the bridge, it collapsed. Like Paul really, really angry at me.
It makes people thoughtful. So we start putting in together processes and programs, and it, it's really, I, sorry, I'm taking that one all over the, the landscape. But you know, in ot, again, it just feels so new.
Oh, we're getting, we're creating all these new things. I like, you know, saying, have we done this before? And risk you t we talk about safety, right?
The risk is, you know, the, the safety will be bad and you hurt people. And the risk to the, the motivating risk to, to the people responsible, even if they don't like people, is that things will happen to you, right? There is a risk to you, there's a risk to your business in business terms.
You know, your customers won't like you anymore, you'll get sued, um, because you didn't have the same processes that mature industries just have. Um, so I, I know if I can even weave a question outta that myself, but, but, uh, but that it, that OT iot thing, right? It, it's, it expanded as you like on that, that value of that in the IT world.
Yeah. And, and, and, uh, you know, I've seen a lot of efforts now and, and I haven't decided whether I like them or not, but the, you know, combining the concepts of OT and IOT and some other devices into this concept of cyber physical systems. But, um, you know, you kind of hit the nail on the head that, that the, you know, the operation of this type of technology has some type of impact on a physical process or a physical thing.
It's not, you know, something that's, that's predicated towards user, you know, interaction or user use. So, um, yeah, the risk is different. And, um, as we digitalize and the world's digitalizing very, very rapidly, um, you know, there's more and more of these devices that are, that are interacting with some type of physical process, uh, uh, across the board.
And, um, you know, quantifying how that impacts risk of any organization or even your personal day-to-day life is a, is an interesting challenge. Um, but it's, uh, it's, you know, growing very, very rapidly. Let, let's, that's part of take, take this into the present because, uh, yeah.
Um, again, you know, before this, this all started, uh, a couple, couple minutes ago, we were talking about AI and so forth. And, you know, the fact that I'm, I'm just, you know, I, I'm one of these people, I'm not really an early adopter, you know, I'm an early ponder. I start thinking about things before people start using them.
Sometimes I use it myself a little bit and stop, and I'll watch everybody else use them. And if they really stick around, I'll use it myself. And I've installed chat GPT on iPhone a month and a half, two months ago, and now already I'm like, I can go to Google and type in three words that I really can't think of right now, or I can just hit voice of text and randomly speak poorly to this thing, and I'll come up with a pretty good summary.
And there's that scale of ability in the present time. I'm, I'm trying to get into the present. So we have that right now and, and things all across the entire secu security spectrum.
You know, when I think about supply chain, I have this time to transparency problem. All of the information between me and every single point is there. You know, nobody, it be 17, you know, different organizations in my supply chain on a given op, uh, object, all the information is in their hands already, and all the relationships is already, are already codified in contracts and regulations.
And if I had the time, I could get any, any one of those pieces of information, I don't have the time. I'm not going to have the time. But with things like a ai, I suddenly have the time and I can just say, farm me all that thing and be done with it.
And I don't think we've got our heads around that yet. That's where we are right now. So at Nozomi right now, where, where you're day jobing these days and have, have been doing all sorts of, you know, neat things is a perfect example, right?
This isn't that situation where we're in a space that I've been obsessing with the last 15 or so years, right? You know, as we get more aware of our surroundings, the value of that awareness itself is the defense, or is the value and this acceleration of, you know, again, what we are currently calling AI changes our ability to, to understand what our risk is today. I mean, so how much does that change, like in current, last 12, 24, 36 months?
Yeah, I mean, I, I, what I love to think about, not just, it's almost like we have two, uh, converging, um, converging di digital, uh, explosions, I guess you could say the same. You've got the, the artificial intelligence piece you keep touching on, right? We have all this capability now to, uh, to parse through massive amounts of data and drive context from it and, and, you know, drive efficiencies out of it.
Uh, while we are also seeing this process of digitalization with millions and billions of new devices that are collecting data and sending data and transmitting data, um, you know, creating more opportunities for artificial intelligence to be able to do some insanely interesting things in our lives. You just separate the cybersecurity piece of it. Um, you know, I, I love, actually, we were talking about it a bit where we're on, do I call it boat?
Chris? What, what do we call the, the boat, the marine living quarters, The terrains, the solar powered boats, the, the, that some of my backgrounds are on the boats now. It's a snowbird thing.
It's the, like the, the sparrow, the CAPAs ano was, you know, my showing up in Canada, you know, it was a sign of, uh, warming weathers, but yeah. Down boats. Yeah.
Do you remember, I mean, we were, we were drinking a beer and we were talking about, you know, if, if there's a, a fleet of these, uh, marine living quarters with, uh, sensors in the water, you know, we're, we're tracking water pollution, water movement, you know, uh, you looking at marine life activity, you'd be looking at air quality and you're putting thousands or hundreds of thousands of those out there, getting those into an artificial intelligence, you know, processing capability. You know, can you imagine the potential outcomes of that? Right.
Um, so I'm thinking about it in a lot of ways, you know, in my, in my current role, both, you know, with my organization and in general because I'm fascinated by this stuff of, you know, how that's applicable to, um, to risk how that's applicable to cybersecurity. And, uh, you know, there's a lot of different ways to look at it. You know, I enjoy, uh, thinking about the potential challenges of taking AI to all of the, um, you know, the interesting, you know, the process data.
You can go to all of the event logs and, you know, ease the concepts or ease the process that analysts take to find out, you know, look at the things that they need to respond to or, you know, uh, if you think about it from a risk perspective, you know, I, I like to think of risk and it helps that this is how we're looking at it from a zomi perspective of, you know, there's different ta, there's different stages of risk management. There's the identification of risk, there's the evaluation of, uh, the steps that you can take to reduce risk. There's the, the actual mitigation process and the ongoing monitoring.
And if you can simplify that risk identification process and simplify the process of, um, uh, prioritizing where you want to put your efforts from a mitigation perspective, you know, you can apply this to any one of these different challenges that we talked about. Um, you know, artificial intelligence can help, you know, really ease the burden of reducing risk in our day-to-day lives in every fashion. But I think about it a lot from the cybersecurity perspective.
Well, yeah, glad to mention the boats because, you know, I love that analogy because the way we get data right now, you as I've sailed these boats up and down the Florida coast through, you know, uh, thousands, you know, hundreds and thousands of miles of, of water that is, we read about all the time because the sea grass or the manatees or the, or the, you know, agricultural, agricultural runoff or whatever, it's, and to be clear, when we get the data, you know, we get data because somebody, some group of public and private organizations will decide we should have a data collection point at some point in this body of water. And it's, after some period of time usually been measured in months and years, somebody will spend some amount of money probably in tens of thousands of dollars, at least to put a buoy in, Right? Right.
And now we have a data point, right? You know, title, you know, title is something everybody can understand. You would think there'd be millions of tidal sensors around Miami and so forth.
No, there's like 12, right? You know, because it's just, you know, big and cumbersome and slow. And one of the pushbacks that I've gotten to this whole idea, uh, that you're describing Mike, is, is well not, you know, it's too many, too much, right?
Every boat on the water, you know, is a data platform that's producing temperature and salinity. And I mean, oh my God, if there's so much data, what do we do with it? And my, my, this is a very inevitability curve thing.
You know, I look out in the future and I think we will do these things. So the problem, any problem you can think of, we will have solved by that point. You know, and this is one of the, so much data, everything we're talking about now, it's like, well now, and it's funny in, you know, 'cause you and I, that that conversation is like, at least two years ago, right?
And that Years ago, yeah. Like four or five, six years. And the beginning of that, people would just look at me like, I'm crazy.
But on this one right here, I think right now, if you, if I frame the conversation, most people just nod and agree. It's like, oh yeah, that's not a problem at all. You know, Hoover up all that data.
Of course you do. But it's, and it, you, I was smiling as, as you were saying, the last bit too, because it struck me that, that, and maybe this is a characteristic of when something becomes emergent, because the big problem I have right now is deciding what questions even to ask. You know, my little, you know, AI friends, right?
Because, and, and they're all questions that I wouldn't have asked before. I couldn't have asked them. Maybe I could ask them, you know, it's like, you know, I, you know, there's, nobody's gonna answer them.
And there's so many of them. But just in casual, casual conversation, y you know, with the, you know, this talking about risk, right? You know, with like, like you and like all of us, you know, we're not just faces on tv.
We're not just corporate creatures. We live in worlds. We know people, right?
And I, and among my friends and family and so forth is the entire range. Including people who are, as we speak on the street, living there, not doing well. Very, very hard.
And in, in, just in the last month or so, I have hooked up at least two of those folks with chat GPT, because if they have one thing, they have a phone. And for that sort of situation, when life is really hard, very moment by moment, having anyone to talk, just ask a question. Just the, you know, just to be able to say, how do I get to the, where is the, you know, and maybe the big difference.
And it's, it's, you know, you know the risks you take. Well, you know, as opposed to finding out there's some way you can get a bite to eat without committing a crime. They'll put you in jail where you do to get a bite to eat, put you're in jail again, right?
Um, that's the kind of benefits then risk analysis we're talking about at every scale, you know? And that sounds sort of melodramatic perhaps in a corporate context, but No, it's not. It's literally the same stuff.
Perfectly applicable. Yeah. So, so this, you know, so the question I, you know, sort of had in my head about that is, is yeah, this prompt engineering is not just how to, how to frame the questions.
That's important. But I think as decision makers or the, the kind of people that watch shows like this, it's, it's now we have to not ask a bunch of questions. 'cause there's an infinite number we could ask, and you get fascinating answers that would occupy all our time.
But we don't have time for that. You know, what solutions can I get visibility into right now? Right.
Is that too simplistic? No, I mean, I, I, I can think about this a lot of ways. You know, I, I, you know, back to your chat, GPT example, you know, some of the selfish ways that I use it is just how do I make my day-to-day life easier?
And, you know, think about it from the context of the, the type of work that I do. Okay. I, I have an RFPI need to respond to.
And, you know, a lot of the data I would be responding is on the internet. I just put the questions in and chat GPT and I'll get answers out. And of course I wanna rephrase it, things like that.
Recommendation letters, emails, you know, I, I think the challenge I have is just being careful as to, you know, what information I'm putting in there, especially if you're logged into it, is gonna be used in some other way and use the train engine. And, you know, privacy concerns is something I'm really worried about. But yeah, I do, I mean, I, I spend a lot of time thinking of ways to properly prompt, uh, an AI system in order to make my day-to-day life easier to get things accomplished, uh, in, in seconds or minutes that used to take me hours or days, right?
Um, you know, I think when I think about, uh, using AI in the same context, from a cyber perspective, going back to, you know, what I've been doing from a career perspective, uh, you know, we're, we like to suck up a lot of data around, um, you know, asset information, how they're communicating, who they're communicating with, um, you know, where each of those individual devices is set from a segmentation perspective, um, what devices they should be communicating with, what, you know, logs we might be gathering from that data. And there's some really cool, again, we gotta think about the ways to ask the questions and ways to drive how those questions are being asked. But if you can say, um, you know, if every individual one of those, um, you know, we could say A-A-P-L-C, we know who should be communicating with, it should be one master station that's controlling that.
And then there's everything underneath of it that should be communicating with and specific protocols and specific function codes within those protocols. And if there's anything outside of that, you know, you can, you can really start to make an investigation. Or if you've got A-A-C-C-T-V camera somewhere, uh, that is, uh, you know, typically only supposed to be communicating with, you know, wherever's controlling that camera over, it's sending the video feed and it starts communicating with a building system or a phish tank.
You know, that's maybe not something that's easy to pinpoint in the logs, but that's something that AI can, you know, really pick up and say, let's mitigate that. Or even, you know, in a simp in a much simpler fashion, if you have every little piece of asset data and full software bill of materials and hardware, bill of materials, and, uh, you know, something's being actively, you know, exploited or some new vulnerability and, uh, that's been discovered in any of that, and you can just, you don't have to type anything. If it's an automated process to say you have, you know, 300 servers that are running this piece of software, that there's a new vulnerability that's actively an exploited, why don't you go to those 300 servers and, you know, turn that surface off or update it in some way.
You know, AI can make that whole process much, much simpler. Again, it's about asking the right questions and putting the right context to it. That's the, the, you know, the thing I'm excited to be working on with my, with my current organization is Zomy Networks.
I'm, I'm blessed actually. Our organization, we have, we're at the four AI PhD, so it's, you know, I'm not completely relying on the chat GPT thing. I'm getting, um, you know, learn a lot about the under the covers artificial intelligence pieces, and that's been great.
Well, you know, I'm glad you touched that part of it, because, you know, and again, this is not just about AI or, you know, it's not, you know, again, we're just calling something else, AI again, so we'll just keep using the acronym, but, you know, because we all know what we're saying, but it's not artificial and it's not intelligent. It's good, but it's very cool. Right?
Right. Yeah. And, and, and, and, you know, one of these things we do is like, well, I'm sure it's not perfect and you can't trust it.
It's like, nothing's perfect. You know, I have a, I'm, we pretty, we're pretty good at, and again, we're talking about risk here. We're have an innate ability to tell, you know, when something's just terrible, you know, or, or, or let me put, put it this way, we have innate, innate distrust of the things that seem really authoritative, right?
Yeah. You know, it's a, no, we're not gonna all believe what Chatt BD says or what these AI tells us, but I'm not gonna believe what, you know, an intern I hired for the summer tells me either, but I've asked 'em to go out and, and create a summary report. They came back with the summary report, you know, I'm mostly gonna look at it and see if there's anything I didn't know already.
I'll see if they missed anything. And I'll, you know, and again, you know, my point, use that for things and, and the, you know, it's, it's still on my screen over here, you know, so it's sort an interesting example of it because in this last, um, uh, uh, working group, and there's, we know, I think most people watch show like this, know the acronyms, but let me spell it all out. So the Department of Homeland Security, uh, cybersecurity Infrastructure Security Agency, DHS csa and the Department of Commerce on, uh, national telecommunications in, uh, infrastructure administration, any N-T-I-A-A-A, I'm missing an A anyways, a, um, non-agency administration.
Anyways, um, the, the Department of Commerce, NCIA is where the software bill of material, the SBO m uh, um, work inside the federal government began, and then it moved over to the Department of Homeland Security cesa. So was, wasn't in that, you know, which is geeky sort of stuff, right? You had to be following to, you know, have no other good hobbies to even know these things.
Um, but I was sitting in this CISA working group, uh, looking at, you know, uh, potential next, next efforts. And one of 'em was, you know, SBO M repository, defining an SBO M repository. And as there was a half dozen of us who, who, you know, literally, you know, five of the best people in the world plus me, well, God knows why, you know, so we're, we're trying to figure this stuff out, and none of us know.
The answer to a silly question is like, is there a, a current definition of an SBO repository? And I can think of at least one of their document that really is current and canon, you know, that it could be in. And if I was a better person, I would've read it by now, but I haven't.
Um, so instead of saying, I don't know, during the last call or trying to make a note in my head, because I'm talking at the same time and I've write it down, I can't, you know, I'll forget what I'm saying. And trying to remember, go read that document later, maybe next week, come back with something, you know, to, to the point that I'm not getting to here. I put myself on mute while somebody else was talking, and I asked Chad, TPT, you know, is there, you know, definition for an s bomb repository?
And it said, no, there isn't. And, you know, and back, you know, back in the call, I said, no, there isn't. Right.
You know, and somebody else was talking. Again, I'm scanning back down through it, and I see us at the bottom of the response, you know, where it says, you know, the Department of Commerce, NCIA, the DH SSA working groups, you know, have discussed this in the past, but have not come up with a definitive and hold down to the camera. It's like, it's talking about us, right?
How first, if can you get right? It just did again, the, the college intern level of, of research, but still good research of the entire internet and fed back into the working group, the knowledge of the working group's own environment, which is just, what does that mean? So, I mean, everything you were saying just now are like, you know, and for people who are not familiar with all this, you might say, well, were you doing that already?
Can't you just have someone look at that? It's like you're missing the point. And and many of us have been looking at this point all along the way for, for, for years and years now, because you say, you know, 10 and 15 and 20 and 30 years ago, this someday we're, we're gonna do is we're gonna take all the events from every device.
Oh, and we're gonna have a thousand times more devices per square foot, and they'll be a thousand times faster. And we're gonna take all the events from those, gonna hook from them all up all at the same time, and compare all that together so we can see how our risk profile is actually being actuated out in the real world. And people just say, you're nuts.
And everything you just said is premised on the fact that we basically do that now. We're already doing all that. Now we're up at this mental level where you're saying you actually need humans or something human-like to stare at this to get the nuance out of it.
But if you did, oh, and we do, what does that even mean? Right? So let me, you know, looking at time, okay, so we'll try to get in the future here.
So are, are you and I just too close to this, you know, and fascinated by this shiny thing and say, oh, we're just about to hit this next crux and this changes everything, or does it, or if not, how long does it take to get to that next level of where everything new we're talking about now is just built in? Yeah. Uh, I mean, I've, and I've, and I've got my worries about, you know, you, you touched on a good point there about the recursive nature of ai, and it's sometimes only as good as the, the data that it's being fed and, and who's doing the searching, right?
Um, and it can be trained in wrong ways. I, you know, I'm interested sometimes by that context of, uh, the decreasing accuracy of some of the AI engines as more people put data into them and, and feed it potentially with incorrect data or that, or that, that, you know, algorithms are pulling from incorrect data. So there's, there's challenges there, of course.
And, um, you know, I love the concept of, you know, just basic anomaly detection functions with it or, or prioritization functions and, and not just in a cyber context. Uh, you know, the anomaly detection capabilities of machine learning and AI have been great for, you know, things like cancer research. You know, I love seeing stories like that where, you know, speeding up the time to parse through big pieces of data to, you know, make quicker or more predictive, um, you know, predictions there.
Um, yeah, I, I, I don't know. That's a really tough question. You know, I, when I, again, when I think about it from a cyber perspective, I like to think about, um, you know, can we reach a potential where we're not just, uh, finding problems and making recommendations around mitigations, but are, you know, can, can we use our automated process to automate the mitigation processes?
Right? Okay. Now we see, you know, back to the earlier example I used, you know, we see that there's, um, there's a known vulnerability or a new vulnerability.
We see active exploitations, we see you have, um, you know, so many instances of this specific, uh, software or hardware that's actively being exploited. Is there something that you can automate to, to protect yourself from that, um, you know, from that, that risk? You know, can we go and update that software or, or drop connections to that individual system that's got the, you know, vulnerable hardware?
Um, or maybe we're automating things like, you know, I've seen some cool technologies recently. I like to look at a lot of startup technologies. I've seen things like, um, you know, can we automate, uh, machine to machine authentication and key exchanges?
We're not doing certificate management anymore. Can we automate, uh, and this, you know, become interesting? We get, you know, to, to dealing with, uh, you know, how all this, uh, AI and quantum computing impacts encryption and things like that.
But, um, yeah, I, I'm, I'm interested in how can we automate the, the mitigation side of things and how can we automate the process of reducing risk, uh, you know, not just from cyber perspective, but maybe in our day-to-day lives. If you think about, um, you know, really basic things like pollution, censoring, traffic controls, all of that, that data can be fed to tools that can potentially, you know, do active mitigation in our lives. So that's the next steps.
Um, that's what, or at least in my perspective, that's what I'm interested in, in seeing where that's going. Well, I, I think that one's short term. Let me lay, you know, I'll, I'll, you know, I'll take the risk, you know, so I hope I'll see, yeah.
Seven years from now when you're watching this. I was wrong, but one word I don't think I am. Um, I think seven years from now, you're walking around with a lot of this built in, right?
You know, because everything from, you know, it's funny, I hesitate, you know, when I say this, but, which is, which is a, a lesson all by itself, but toilets, you know, since I was a child, I thought, oh, one day toilets will be doing medical diagnostics all the time, right? Obviously, because that's what we test Sense. And we every produce samples constantly, right?
I would like to know when the first cancer precursor cursor shows up, not when I get my first annual checkup a year after that starts, right? And it, and, and environmental smoke in the air, you know, gluten, ev, anything, right? You know, why not?
You have these devices, you just pick that up and just let me know about it. Why not have AI systems that will say sleep not reading, given where you are, and your context and everything else is something you should actually know about, because the information's all around us already. You know, the, the, you know, the, I gotta try to leave this with a question.
I, I make no promises because, you know, one of the things that, you know, as, as a Apollo or a kid staring up in the sky and thinking, all right, if I'm writing, I'm lucky with get faster and light transport by the time I'm like 35, and I'll be able to go to these places. No, you can't. Um, and, and I never would've thought, um, at the time that if we just stared harder at that star and stared really hard and stared really, really, and stayed really hard.
And so we can get a planet transiting around it and get, you know, with the spectrum, do a spectrum analysis of the atmosphere of that planet, you know, 130 light years away, right? And be able to detect and, and, and, and, and Dan, right? So we, I guess my point is that our ancients ancestors had that same information washing down onto them, you know, all the time.
Anyone could have picked that informa, you know, out of the information that was already available. And everything we're talking about now is information that's basically already always been available. And it's just getting to that crux.
So I think, yeah, so I, I, I think I am overly optimistic. Uh, I mean, I'm joking. I think I'm optimistic about the future, and I think I'm right.
I think this has way more impact than we can really get into our heads yet. I agree. Uh, yeah, I don't know if there's quite a question there, but I do agree.
Um, yeah, I know who said that. Um, I'm, I'm optimistic about the future. I'm optimistic about, you know, there's, there's things we gotta do to protect ourselves, of course, but I'm optimistic about, um, you know, the things that we see evolving every day, and I, I, I'll see maybe again, no problem, but more likely to find a question in this one.
So, so the, one of the nice things about this, I think what we're doing is collapsing a lot of risks that have been around forever, you know, that, that people might have been saying, you know, you should do something about this 20 years ago, but he shouldn't have, because that risk did not realize. Um, but, you know, one of, you know, in security context, the bad guys have these tools too. So, you know, a lot of, a lot of things that have always been impossible, but have really haven't been, you know, uh, used against us so far are being used and will continue.
And that will drive the, the optimism side of this is, is my question that'll drive companies who like staying in business and making money to come up with the resources in it to come up with better, more reliable, built in, uh, um, uh, uh, uh, solutions. So do you think, you know, following that optimistic path that this actually will drive us, perhaps, you know, to accelerate reaching some of these long-term, you know, and, and maybe even, you know, commonly I, I believe to be un achievable goals and security? I, I think so, and, and the optimist in me, I think, uh, artificial intelligence, automation, you know, these things are going to be, uh, a greater advantage for the defenders than they're gonna be for the bad guys.
Right? I really do believe that. Um, yeah, there's, there's, there's risks in future technology that, that, um, that may have a bigger impact for attackers.
I think the one I worry about the most is, you know, the impact on encryption via quantum computing. Um, yeah, I think about all the people at, like the Bitcoin network, for example. Um, you know, I won't go, I won't go down that rabbit hole right now, but, uh, but yeah, but I think in general though, I do think that, uh, AI and automation are going to be, uh, an advantage for the defender over the attacker if we properly utilize it and harness it and make it available.
Yeah, I think that's a, you know, that, that's a good note to, to, to end on as any, because I didn't think that's true. Right? You know, because the, the, and, and this is that ratcheting effect, we always get the wild west, you know, before the, the, the civilized urban infrastructure, which has its own problems, but in the end, you know, is very efficient and, and, and security and risk management is not an infinite field.
You know, we've just been dealing for, you know, tens of thousands of years for tens of years, and in the it space with the understanding that you can never see at all. So therefore, we'll do these things and maybe we can see it all. Yeah.
And I mean, and I think for me, uh, you know, I, I, I think I was talking more in the context of security when I gave that answer, but in general, I think it, the, the benefits of automation and artificial tongue, I know, you know, we hear a lot about the risks and, and, and, and how much, you know, how much regulation do we need? And, you know, how much oversight do we need in all of the efforts that we're making, artificial intelligence and automation and digitalization. But I think in, in general, just like I was on that path for cybersecurity, I think for humanity in general, that the, the positives are gonna far outweigh the negatives.
Um, gotta put the effort in. Yep. So I, I'm afraid of me go any further.
We'll, we'll, uh, dive back into the darkness. So I, we will leave it at that. And thank you, Mike, for everything you've done.
You know, thanks for your friendship. You know, I know your family, you, you, you're one of four or five people that have that has ever sailed that, that's at this helm of my boats, right? So, and, uh, yeah, It's been same, Chris, it's been, it's been great to know you all these years.
I appreciate the, the multiple invitations now to, uh, to visit you there in Florida and, uh, and have a beer or two talking about these exact same topics and concepts. It's been enjoyable. Thanks, man.
And thank you all out in the world for spending your time with us today. As always, we'll see you around on the, on the show and be good to each other. Hey, everyone, it's Alan Shimmel for Techron, and welcome to the first episode in a series we're doing that we call Schiff Left Shift, right Shift Everywhere.
I am really happy to be here. I'm really happy to have these two guests I'm gonna introduce you to in a moment. You know, we're doing this series with our good friends at Adobe, and I know everyone out here has heard of Adobe, and many of you use Adobe products, but I don't know how many of you know how influential Adobe has been in the world of security over the years.
When you, when people are trusting you with, with the, their files and their work, like millions around the world do with Adobe, they don't have a choice. But to take security seriously. And as we were talking with my guest offhand, off camera, you know, a lot of security innovation has come out of Adobe.
Um, Adobe of course, is all about you, the technical people out there who are working in all of their products for graphics and documents and applications and everything else. And they have for a long time. This whole series is gonna be focusing on sort of what's Adobe's view of security, about what's some of the frontiers, some of the, you know, areas of security that we, we want to shine a light on.
And, and specifically, as I said right in the title shift, left Shift, right Shift everywhere. Where do we put our focus on security? Look, I've got two great folks from Adobe to introduce you to who are gonna be talking about this with me.
Let me introduce them to you now. First I want to introduce you to Pelli. Yuli.
I hope I got it right. I've got, I'm doing the best I can on names, but Pella's name is actually not that hard. Pellis is the lead security strategist at Adobe, and we're thrilled to have him on Pelli.
Welcome. Welcome to our podcast series here. Share with our audience a maybe a little bit about your journey.
Um, sure. So I've been in the security industry for 25 years. Um, I started out working for a company called Anonymizer, which was sort of a commercial version of tour way back when.
Mm-hmm. Uh, I worked in security consulting for a while. I've had Stake and Symantec, and I've been at Adobe for 17 years now, working in all sorts of areas of security.
And, uh, when we brought, uh, Florian into the team, I decided to go and focus, uh, mostly on shift right type projects. So I'll be representing the shift right aspect of it. So you're the right hand.
Yes. I hope it's still right on your, this is my right hand. I sometimes it mirrors.
I know, but that's funny. You know, at stake, of course is legendary, right? Chris w Ball and, and the folks there, they went to semantics.
So it sounds like you were involved in, in all of that, you know, and the, and I've also been to security business 25, 30 years, legendary, legendary folks there. It's still doing great things. Um, but thank you for joining us.
Sure. Next, let me introduce you to, uh, Florian nut netting note noting, I know you gotta curl your tongue, and in New York, we just don't curl it so well. But Florian, nerding, Florian, pronounce it correctly.
And tell us a little bit about yourself. D you've me, rescue me, difficult Name, my name's, uh, Florian Luing, or if you want to use the German ation, because I'm originally from Germany and it's Floridian, which is even more difficult. But let me also talk a little bit about, about my background.
I started my professional career in, uh, 2000 and, and 10 at a small startup, which built, um, network firewall, the devices with a focus on being very, very user friendly so that anyone without networking or security ex expertise could actually set some up and have a secure net network for their, their office or their, their home. Even after a couple years working as a software engineer there, I joined at, at Adobe, and I've been with Adobe by now for 11 years, and, and or most of the, or a bit more than half of, of the time I, I spend in software engineering. I am, and it's still what I, I'm at heart.
I'm a software engineer. I want to make the lives of, of developers better and really focus on pragmatic security solutions. About six years, I, ago I joined the security org, started working to together with, with Palace, and I'm taking care of all things Shift left.
And so the cutoff point is basically when software gets deployed to the cloud or otherwise released to our customers. So in, in my scope is, is a lot of stuff from security training, security, awareness, code analyzers, and various aspects around secure by, by design, and especially memory safety. Excellent.
So you're the left hand? Yes. Got the left and the right.
Okay. I feel like the Pope, um, anyway, He's home from the hospital, so that's good. Anyway, um, let, let us, let us talk a little bit about history.
com in 20 November of 2013, published March of 2014. A big reason that I personally felt compelled to do this was because I thought that DevOps offered us the best hope of, of getting security, right, of, of correcting a lot of wrongs, right? I, I, I grew up, or I, or my career in security, probably much like you, Pellis was on the right side, right?
AF post-deployment, I helped found a company, intrusion prevention network, access control, vulnerability management, you know, all the traditional network security stuff. And the problem was we were, we were always the caboose on the engine, right? The end of the train, the engine got pulled by the developer or, or someone else, right?
It was too late. By the time we got involved, it was too late often to fix a lot of the wrongs that were there. And I always felt if we move further up the food chain further left, if you will, we would be able to fix these things.
And what a perfect opportunity DevOps was, right? Ops and Dev working together, let's get security in there and we're going to move security to the left. And, you know, the, at the time, the notion was, and I don't know if you believe it, I'll ask you both, that it was a fraction of the cost to fix a vulnerability or a defect far left than it was to try to fix it in product production in the right hand, right?
So it was cheaper, it was more efficient. It was, it was just everything was better doing it to the left. And why start just left of deployment?
Let's push it all the way left. Now, like both of you, we, we have friends who are developers, but the average security person said those developers, they don't care about security. They just want to push out code, right?
They get paid to upon how many lines of code they publish. But an interesting thing I learned when I got into this DevOps thing, a lot of the developers, and not only the developers, all the people on that left side really felt that the security people were like an anchor that was dragging them down. They were slowing us, we were slowing them down.
We were the people who say, no, no, no, nope. Go back, go back, go back. No.
And I found it incredibly difficult to bring together what I used to call the, the, the cybersecurity, or we didn't even call it cyber back then, but the security tribe with the DevOps community, it was sort of oil and water. I was trying to make chocolate and peanut butter pellis, you've been around if you were at at stake. You've been around a while.
I know. Yeah. What, give us your take on that.
What do you, you know, was, was it an impossible mission to begin with? Uh, I I don't think it's an impossible vision. I mean, part of, even as a shift, right person, right?
Like my job isn't just to find as many bugs as I can. My, I'm a feedback loop into the florian, right? So, you know, we go and we try to look at patterns of, in within the vulnerabilities and say like, okay, are the developers having this consistent class of problems?
If they're having this consistent class of problems, you know, what can, you know, Florian and I coordinate on, and what can, uh, Florian help build to address that class of problems? Like how can we shift the company to using a framework that's maybe a little bit, um, more secure by default, so they don't have to think about security as much. Uh, maybe it's a pipeline problem.
Maybe, you know, it's they're, they're having trouble keeping their amis up to date in, in the cloud. So, uh, it's, I I found that developers tend to want to do security. Well, they, they, some, a lot of times they do find it sort of an interesting topic, but they're, they're just constrained by the realities of, of their situation, right?
They, they have so much time and, um, to get things done. So, uh, from my perspective, you know, I'm not just looking to find as many bugs as I can to get as many points on the board as I can. You know, everything's a feedback loop.
Even if you're doing red teaming, the, the goal of a red team isn't to go N or Nina, or we got in the goal of the red team is to then talk to the blue team and say, look, this is how we got in this, this is where we have gaps. Um, if you wanna catch this the next time we do this, here's how you can improve. And so there's always a feedback mechanism in, in from shift, right?
To, to make the shift left team, uh, more knowledgeable and enable them to make better plans, to make things just smoother for the developers overall. Absolutely. com for and did all this DevSecOps, to tell you the truth.
Give us your, you know, what, what's been your experience at Adobe primarily? 'cause that's where you've been to all these years, but is what I describe, was it true then? Is it true now?
What, what's changed? What's gotten better? So there are multiple perspectives on, on that.
Certainly DevOps, the, the ideas is fantastic. We have a group of people who really focus on, on the engineering aspects of building working software and operations. People will then run it in production and take care of all, all the problems that happen in production there.
We have a feedback loop too. And if we now add security to, to, to that mix, both sides need to, to do some of the work. But the challenge with shifting too far left is we, security people should not move all security work to the en engineers operators of systems because they are not experts.
We are the experts. So we need to make it as simple as possible for them to find these issues. And there are many different approaches of shifting left.
For example, you might shift left and say, well, let's do threat modeling at design time, because obviously it's cheaper to change the design that hasn't been implemented yet. Then while you have a architectural complete, um, system on, on stage ready to be deployed to production now, and architecture change is very hard. It's, it's too, too late.
So shifting left in that sense, it's very, IM important giving all kinds of feedback in an IDE on, on the other hand. Well, now you need to balance different aspects. Do you want to send all the findings to, to the developers only the sets that you care most about?
What is this the set, what, what security aspects really matter? And with my background as a software ENG engineer, I, I wanted to always help other software engineers make pragmatic security decisions and ideally reduce security decisions. So the recent trend in shifting left is secure by design solutions that's, for example, started for cross scripting issues, um, with libraries such as React, where it's really hard to accidentally have, um, injection vulnerabilities because the framework by design prevents it.
And that is a very, very powerful concept that I want to see much more of. Yeah, the, the, the secure by design, that whole concept of secure by design does not get enough light, right? I mean, we, we all, for instance, Pelli, I'm sure on the right side of things, right?
Uh, zero trust networks, zero. The, the idea of zero trust security, right? Everybody kind of wraps their head around that talks about it.
It's, it's very, you know, very, uh, everyone, you know, buys into it, so to speak, the secure by design. I think people shake their head, but they don't necessarily drink the Kool-Aid, if you will, right? In that.
'cause at the end of the day, they're not quite sure what secure by design means, right? Y yes, of course we want to design secure software and we want to try to put in frameworks that take out your buffer overflow SQL injection, you, the OO os top 20 or whatever, right? That hasn't changed in 17 years, but, you know, but actually implementing that is hard.
It's hard. And without, again, some ground rules, we, let's not let out state secrets and get us all in trouble. But how does Adobe do secure by design?
Yeah. Let me talk a little bit about memory safety in, in this context because it, uh, showcases the fundamental challenges that we have have to deal with many of Adobe's products, like any company that that is more than 10 years old, probably has lots of CNC plus plus code. You know, operating systems are written and c and mostly c maybe some in CC plus plus desktop apps.
See, foundational libraries are all CNC plus plus desktop apps themselves. CNC plus plus look at any network d device at code running on others than the apps on on your mobile mobile phone. Whether iOS or Android doesn't matter.
The foundations is all c and c plus plus it's all memory unsafe. And unfortunately we have learned that humans are not capable of reliably writing memory safe code just too hard. So we need a, a system so solution, and that is memory safe programming languages where a smaller group of of people is just focused on, on designing a system where it is very, very hard to have accidents like, like that.
If you use Java, Python, well, these are not systems programming languages. You don't deal with memory safety issues. If you need to write highly performant code, well then you have rust or may maybe swift, uh, the two most common choice.
They're certainly more than these two programming languages. But if you now look at, um, the ecosystem where you have memory safety issues, it's CNC plus plus. You can't just rer a an entire application in a memory safe programming language.
There's no business case to ever make that happen. Even if we had a way to automatically transform, uh, tens of millions lines of code base into to rust wouldn't be interesting because the team that maintains the c plus plus code base couldn't maintain the rust code code base. They wouldn't understand the structure if we used AI to transform it, if that would be possible.
So we need a much, much smarter approach to memory safety. And the first step is, again, feedback loops. We need to identify which parts of, of, um, the system are most vulnerable to this kind of vulnerability and does this vulnerability matter at, at all?
And that is where the shift right testing comes in. And I'll hand it over in a moment to palace to speak about fuzzing and what we do there. And once we've identified these spot that are safety critical, we will recognize a recurring pattern that, especially areas that do, um, passing and decoding of file formats are risky.
And it doesn't matter if it's an image file format, an audio and, and, and video or a complex document or even an archive, it doesn't really matter. That is the key functionality that we need to protect because an adversary is that sends you a file via email phishing via phishing, which is very targeted phishing. And with one click, you open the attachment and then open it with an application, and then the adversary achieves remote code execution.
That is really the thing we want to avoid. So figuring out which code is executed during this one click attack that is most, most important, and it's file PAing decoding and maybe a little bit of running logic, then you can take different mitigations strategies instead of rewriting everything in a memory safe programming language, maybe rewrite one safety critical component in a memory safe programming language. Palace.
Can you talk a bit about fa Yeah, sure. So, so this is one of the areas where like you, the goal isn't necessarily always just to find as many bugs as you can. It's to do things strategically.
And this is where shift left and shift, right? Collaborate. So yeah, when we're trying to decide what to fuzz, we could do like just generic fuzzing and try to go after the entire application all at once.
Um, but to do a more strategic approach, you would look at your adversary intelligence, right? Like in, in the wild, what file format types are attackers currently using to go and exploit things? You can look at bug bounties and you know, the people that you have in your, your bug bounty community who are contributing crashing bugs and looking at the techniques that they're using because they're often also emulating what they are seeing, uh, in the adversary intel community.
And then you can go work with the product teams and go, okay, who are the teams that actually are responsible for this code? We can go and you send a specific team to there. We can work to set up fuzzing around that specific section of code and it can actually make the developer experience a little, uh, more predictable.
'cause you're, you're directly working with the team, you're working with one team at a time or two, maybe two or three teams at a time, uh, to do this type of work. They understand what, they understand the bugs, they're not context switching. Um, like if you're just fing the overall application, you're hitting different teams all the time and they're context switching versus, you know, working with a team directly where they're like, okay, we're gonna focus on this problem for, for this quarter, and we'll, we'll work with you.
We'll set up the fuzz, we'll, we'll give you insights. And then, uh, they can start to see the patterns in the bugs. And if they see the patterns in the bugs, they can say like, okay, well you, you can quite rank the fuzz.
We, we know this paradigm that exists in the code, so we're just gonna go tackle that overall. And then we'll come back to the f once we've, we've addressed that. So, uh, you know, with with Shift Wright, you know, I'm always looking for ways not only just to, to find the bugs, but also ways, uh, to do it effectively and ways to empower the teams to move faster.
You know, I remember the first time I was exposed to fuzzing, I think it was black hat around 2006, maybe, something like that. And, and what a, what a fantastic development that was for what the time, I don't even know if we called it AppSec ps I don't know if you remember, but did we call it AppSec then? No, not really.
It was still, I guess vulnerability management. I don't know. But I mean, what a, you know, the whole idea of fuzzing the code and looking for, you know, the, the zero days before the bad guys found them, if you will, was, was just, you know, what a concept like, duh, why didn't I think of that?
Right? And I wouldn't be working here today. But, um, it, it, it, it really did help us a lot and it helped the developers fix code, right?
Not in real time, but much earlier in, in, in the, uh, in the process. But, you know, I I also, I feel almost like duty bound to say we have made a lot of pro progress on memory overflows and, and, you know, memory vulnerabilities in, in our code at Adobe as well as, you know, all applications we're, we're better at finding those kinds of, of, uh, of defects of vulnerabilities now than we were 10 or 12 years ago. We, we, we have, and we also have new, you know, you mentioned, yes, the world's full of Brownfield, not greenfields, unfortunately, we have a lot of legacy code written in c and c plus and even C Sharp, but you know, we're seeing this at the Linux Foundation now, right?
Linus, Linus says we should be using rust. Yeah, there's, there's definitely been a shift and you've seen it across the industry, so there has been progress, right? Like Microsoft's done a lot of work to introduce secure compiler flags.
Yeah, that can help secure code at scale. Um, Microsoft themselves have been playing with rust in, uh, in their code and they've been putting rust into the kernel. They've written a, a couple blogs about that.
So things are getting better, but, um, at, at the same time, it's always a race, right? So, you know, you're, you're always, they're always gonna find one more way or one more tactic. So it, it's always gonna be a bit of a progression, You know, it's good.
I'm sure It's finding in, you know, security is always constrained by the EE economies of building software and selling it. So if you can't make money with it, well, even if it's perfectly secure and turning something off is usually more secure than running it. So we need to find an acceptable risk threshold, and for example, for our products, abit and and reader, the addition of sandboxing to really isolate the memory, unsafe parts.
And yes, we have active content. And, and, and that too from the rest of this system allowed us even before we had secure by design solutions like memory safe programming language, as for systems use to reduce zero days and vulnerabilities in, in, in this area by a large degree. So there are many, many different techniques.
And, and the key thing to always figure out is what is the best way, the most cost efficient way to mitigate risks at scale? And as security professionals, we always have a pretty large toolbox available, and we need to help the software engineers understand what are the options and tell them about the different pros and, and, and cons, both short term and, and long, long term. A sandbox doesn't fundamentally remove the vulnerabilities and libraries that it protects.
So we still have to, to fix any bug we might find. Whereas in a memory safe programming language, you have eliminated or reasonably eliminated a class of, of vulnerabilities. Yes, the rust you can use unsafe, but all then you better know what you're doing.
Yeah. And we're, we're sort of, uh, you talk about the industry changing, we're, uh, at a place where, you know, like when I first started, like finding a bug was super cool kind of thing, right? And now, uh, you know, and in a large enough company, you, you have, you have tons of bugs, right?
So there like RSA coming up and there'll be a ton of vendors on the floor who are gonna be marketing, application security, posture management tools. Sure. Which are, you know, take into account that you've got vulnerability feeds from all sorts of places.
You've got your internal pen test, external pen test, bug bounties, das SaaS, Kev list, um, cloud security, posture management tools, et cetera, right? So you have vulnerability. You, you now have a wealth of vulnerability information available to you.
And, uh, part of working together with shift left and shift right, is being able to look at that data and look at that information and say, how can developers most effectively spend their time to, to knock down as many vulnerabilities, uh, with as little effort as possible? Is it updating their baseline images? Is it, uh, as Florian mentioned earlier, switching language to like react or rust?
Is there some sort of tool in the pipeline that we can build that makes, you know, keeping these things up to date more, uh, easier, uh, for the developers? Um, you know, managing third party libraries, you know, since right now we're like at almost at the other end of the spectrum where it's, we, we have a wealth of information. And now the question is, is how did, how do we use that information effectively?
Well, we're almost a half hour in and we haven't mentioned ai. It's time. You know, is AI the answer to that question, Bella?
Uh, AI definitely helps. Like AI is, is another tool in the toolbox, right? Uh, so you know, you can use on the shift right side, there, there are places to use it.
And I'll let four and talk about, uh, places in shift left, um, in, in the shift right side, like, because you have all these different tools, you'll have the same bug finding for multiple tools. And the a common, uh, AI function is document similarity search. So you can do, you can do deduplication, make sure that you're not double filing bugs against teams.
Uh, there are tools, uh, to make reproduce, uh, the reproduction of tool, uh, the reproduction of a vulnerability, uh, easier. So they can take a bug report and translate it into a nuclei template, which, uh, utilize an open source tool for, uh, doing scanning. Yes.
That, that helps the development team in terms of reproducibility, uh, when they get a bug report. So there's definitely places where, where it can help. And we've seen, uh, places where it helps and also places where it expands, you know, the attack surface that I have to monitor as well.
Yeah, Expanding the attack surface is a good, good keyword. We are living in a world where more and more code will be authored or at least core authored by AI systems. And these large language models, which writes this code for us, have been trained on publicly available source code, which of course has been written by humans and has sometimes a lot of security issues.
So you might find that AI generated code is not substantially better and maybe not substantially worse either then human written code. But since much more code will be generated than humans can produce in the same amount of time, we should probably think about, uh, addressing these concerns at the root cause. So can we get into the space where, um, AI is generate code for us to directly influence how the code is generated and take care of security recommendations at code generation time?
That is as far left as we can, can go in in, in the process. Um, at least for, for code, we can could also use AI to auto generate code fixes. So if you understand a, a pattern well enough have AI after it was somehow detected, have AI rewrite the code and so that it's, um, vulnerability free, for example, from using string conation to create SQL statements to parameterize queries.
That is, especially Im important when queries need to be dynamically con constructed because in that's the edge case that humans often get, get one. We are also running other AI experiments, for example, on all block, you can, can find a post about how we think of AI for use and, and threat modeling. That is an, an experiments that, that we are still con continuing to, to this day, to, to see can we recommend something where humans truly excel at with AI use to scale it across the entire company.
Because, well, economics, again, you can't threat model every tiny feature by a security specialist, but AI could, is it good enough? And the answer's still still open, but let's, let's see how, how these space e evolves. I don't think it's good enough today, but it's getting better every day.
Certainly. And an interest thing we hear from security companies and developers is that today anyway, AI might be better at fixing bugs than it is writing code. So in other words, if you give a code that a human wrote, it could find and fix vulnerabilities, bugs, whatever you want to call it.
And it does a better job than that. And then if you just ask it to write code for an application, then of course a human or someone else has, you know, something else has to look at that code. Um, but certainly we're not at the point where, where I think we can trust it to just write the code for us, us and, and, and security is, is, is, is at the top of that list.
Very much so. Um, but you know, you mentioned something before about third party components, and this has really been a bane of shift left and shift right of shift everywhere. 'cause we have to be in the repos.
I mean, today software is assembled on an assembly line, like cars are, I assume it's the same at Adobe. You're not a right. Most of that code inside of these applications represents components that come, they're open source perhaps, or they, you know, they come from repos, container repos or, or or whatever.
And, and a lot of the security incidents that we read about or hear about are the result of third party vulnerabilities that made their way into code, not from the developer actually writing that code at the company, but from the third party component that was assembled into that code. This the software supply chain, this whole issue of SBOs software biller materials, right? And that's a left and right issue because you know what, when you're assembling the code, integrating it prior to deploying, yes, you wanna make sure your s om is, is up to speed.
But that SOM has to almost be a dynamic document that, you know, as things change, it changes and then pelli you on the right side of the house have to be able to reference that SO to say, Hey, does this thing need an update? Or is is a component here out of, out of, uh, you know, they found a vulnerability, we need to upgrade that component. Are you already starting to rely on SBOs to help fix or to help secure the software supply chain?
Yes. We, we do. That is one of the projects i, I lead, so, okay.
Yeah. And the basic idea is first you need to figure out where do is your visibility into the software composition limited, especially with cloud native applications, things that are developed in modern programming languages. Any one of these Python, Java, ruby, JavaScript doesn't really matter.
Usually has a good package manager. So it's relatively easy to introspect a GIT repository or a repository for the packages that, um, software depends on and figures that out even at deployment time. Uh, cloud native security tooling can figure that out too.
But there are gaps in older systems, especially CNC plus plus, again, just like memory safety is a, a problem there. The software composition is hard to determine automatically. So we are working on, uh, on improving the ability, especially in these areas, to understand which dependencies to have, uh, CNC plus plus based products, how do they relate to internally and to external components.
And that of course, this visibility then enables us to, to have a more standardized approach to vulnerability management. And Palace mentioned earlier things such as the catalyst that is CSARs list of the known exported vulnerabilities, things that have been exported in the world, so we can prioritize the remediation of these issues and a whole lot more. Yeah.
And this is also a place where, you know, secure coding often gets talked about separately from just standard coding practices. And this is like an area too where, you know, teams that have good development practices, that have the ability to do automated, uh, testing in their environment to confirm, confirm patches, uh, the work that they invest into that actually benefits security. Uh, it's a mutual win for both teams because the more, uh, testing they have that's automated and can confirm something and, and get you closer to a continuous deployment model, the easier it is for them to test these third party libraries.
Like one of the things that a lot of developers, uh, have a challenge with, with testing these things is that occasionally there's, you know, breaking change where you have to go and re-architect your code to, to deal with the new version, and they're always scared of that. And the longer that goes on, the higher the probability of that occurs. And so, uh, a lot of times, you know, when we're partnering with developers, we'll look for opportunities where the thing that they want is also something that we want.
And you know, so if we see them like, Hey, we wanna do initiative to improve testing, just normal testing, like unit testing within the organization, you know, we'll go and we'll back that and say, yeah, the security team believes that would be a good investment as well. So there's opportunities to look for, uh, partnering with, with organizations on that. And then from a shift right perspective, yeah, we have to keep track of all the feeds and when CVEs and, uh, um, which ones are relevant.
You know, are they on the KEB list, making 'em a higher priority, uh, those types of things. So it is definitely something that we would monitor on the shift right side. Great, guys, I've got one more topic area I want to jump in on and that actually brings us full circle back to the beginning.
I said the name of our episode here is Shift Left Shift, right Shift Everywhere. It's not enough to have one hand shifting right? And one hand shifting left.
Those are two hands, they act independently and they're not necessarily coordinated. Right? Video directors say, don't stick your hands out too far.
You go out of camera, so I gotta keep 'em here. But so your hands are not necessarily coordinated. The idea behind Shift everywhere is coordination left and right working together, right.
Not in. Absolutely. Yeah.
Talk to me about how Adobe, other than having you both on the show with me, how Adobe is, is putting left and right together to truly shift everywhere. Uh, sure. I I can start that one.
Um, so one of the things you have to keep in mind too is we talk about shift left and shift, right? And that's important to the security team, but when you're working with the product team, they, they just know the security org, right? So, right.
You know, the reason why we wanna collaborate and work together and, and come up, you know, make sure that we're coming up with like unified solutions and looking for patterns and looking for higher ROI activities for 'em is they wanna hear from a security team from a single with a single voice, right? They, they just need to know what they need to get done, um, and what needs to, to happen, uh, to get there. And so, you know, with Florian and I, we we're in constant communication with each other every day, every day of the week, um, about some topic or another where there we're trying to collaborate so that when we go to development teams, there is a unified voice and I can say like, Hey, these group of bugs don't deal with them individually.
It'd be better for you to do this thing. And Florian can help you. Florian and his team can help guide you through that.
And that makes, you know, just a better relationship between the security team and, and the development teams too, to, to know that we're not just coming up with work for them to, you know, busy work for them to do to, you know, prove we can find bugs, but that we're trying to actively work with them to, uh, get the most security from, from the limited time that they have. Um, and, and Florian, do you have anything you wanna add to that? Yeah, um, we have so many different tools and as PE said, speaking with one voice is, is most important.
So telling the engineering and operations teams what exactly is the most efficient and effective way to reduce their security burden, that is really important. And this problem feel might feel simple if you only deal with one product, but at Adobe I'm dealing with many different products. So I need to rely on multiple teams that help both PE and and me send this message and amplify it at scale to many, many en en engineering teams that use different tech stacks, have different products, have different business cases, are facing different kinds of threats.
So in really identifying what are the key things from a risk perspective to protect our crown jewels, and this might vary by byproduct, certainly is very I important. And then PE and I work closely together to figure out what are these risks. We work with our security partners to amplify our message, and we work with the security partners to pull in the specialized functions of our security organization to affect positive change.
And a part of that is certainly also evangelizing for security to create awareness because, um, not all business leaders might be aware of the security threats a product is, is facing. So really having a holistic perspective is super important. And there is a model that I use, how, how to think about the, kind of the maturity of, um, the security that that we have.
And I found it on, uh, Colin Green's block. See basic, I I am, when you classically think about shifting left, you start with the development process. So design, right code, build test, deep deploy and, and, and so on.
And then left is at the beginning of the process. But instead you can, can have a different model that Colin Green called sees in six buckets of security risk. And the rightmost one, where I start is exploited.
That is the thing we want to avoid. Then we have the bucket of unfound. And most risks probably stay there.
If you now add investments, you can shift things further left to found externally, for example, via bounty program, further left, found internally, but manually, manual testing, pen testing thing, red teaming, oh, you can decide if that's external or internal, doesn't matter too much. Even further left, found automatically with an automated code analyzer. So solution and even further left to prevent it.
Then ask your safety question, what is your maturity? Where do you prevent risks? Where have your only capabilities to find them automatically or manually?
And that is much more, more expensive. Then the economical question is not, can I do this at this time and moment, find a security issue, but how can I address the root causes of issues instead of only fixing symptoms? So it's a whole different way of thinking about a vulnerability management program and using all the tools you have at hand to make it better.
That was excellent. Thank you, Florian. Guys, as I promised you when we started, I was gonna try to keep this under 45 minutes.
We're, we're hitting right up against it. I feel like we've barely scratched the surface, though we have a lot more to go over and I look forward to continuing our discussions in, in subsequent episodes of, of this series. But I think we've laid a great, a great foundation here and, and defined a lot of these things.
And what's nice is sometimes we talk about this in such an abstract way because we don't have a real live company who's actually living and breathing this every day. Adobe is living and breathing this every day. And, and that brings a, a, a reality show, if you will, aspect to things where, hey, this is, this is what we're doing and this is what works for us.
So thank you both for coming on. Thank you to Adobe for participating in this series. Thank you for watching this.
I hope you found it interesting. Um, if you're watching a summary of this, click through, go watch the full, the full 45 minute version. It's great.
Until next time, this is Alan Shimel for Techstrong. Thanks for what, what being with us today.