Techstrong TV September 12, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Big yawn yesterday from Apple. Huh?
You're watching Textron Gang. Hey folks. We're back.
And we are talking about some weird stuff because, well, a software supply chain involving the cryptographic community or the folks that make all that lovely funny money kind of just went crazy and wild. And, uh, there was a maintainer of a, what's known as the node package manager, and they were fished, and then, uh, they wound up putting code into all these different tools that these folks were using. And before you knew it, this malware was everywhere, and it seemed to just happen accidentally and instantaneously.
And fortunately, I think they got it back under control. But, um, IRA is this kind of like a, a, a sign of things to come because all these interdependencies in our software supply chain, it just seems to take one mistake and it takes everything down. This is a sign of what has been going on for a long, long time, because at the end of the day, this was a phishing attack.
You know, what happened at a high level appears to be that, you know, somebody went ahead and phished a lot of developers and basically went ahead and all these developers, you know, like change your, reset your password, like all these phishing messages do. And basically all these developers changed their passwords. There was a man in the middle compromise of multifactor authentication.
But the reality of the situation is we've seen these attacks time and time again. Ironically, in this case, the end result from what I read was that it was essentially an option to try to steal crypto, you know, crypto coins and everything like that, which we have seen many times before in supply chain attacks. I think one of the more notorious ones, I, I don't, I, I don't, not sure I think it's bit wallet or something.
I am not positive about that, but there was an incident where a major crypto wallet, basically what happened was they were compromised, not because they were compromised, but because they took a library program in an open source library program and somebody basically hacked, or I don't even think they hacked the developer of this one piece of open source software that then got pulled into the application, whatever it happened to be. And then the criminal had full control over the crypto wallets and stole lots of money. And this happened four or five years ago, I think, right now.
So what we're seeing now is essentially why do criminals do this? That's where the money is. In this case, we saw it for spec, very specifically a crypto theft.
The reality though is we have seen these phishing attacks time and time again. And to see these major developers, especially with software supply chains being able to be compromised so simply, you know, and so quickly without any verification of the software, this is where the problems become. And this has been going on for a while, and this will go on.
As long as people still want open source software, common tool sets, without verifying and doing the analysis of the software, it's probably much more efficient to keep allowing these things to happen than to invest in all the checking that would have to go on. But we need to have much more of a rapid response going forward. We need to have more of a verification process.
And I never ever want to hear anyone's talk about stupid users being phished when this is an example of some of the top software developers in the world being phished. I'll, I'll leave it there. Yeah.
The, yeah. The, the challenge is, is that you have, when we think about just security in general, when we hear about a lot of these breaches, it's always a very simple and common breach, right? We always think that, oh, it must be some sort of sophisticated hacker that created this devastating scheme that's going to, you know, extract, you know, millions and billions of dollars of these companies.
And if you think about it just within corporate America, when they have every employee go through this, how you understand cybersecurity in your company, it's how you understand phishing scams. It's easy because you end up ignoring that thinking, ah, it's never gonna happen to me. I can detect that.
So just attack the, the smart guys and you see what happens, right? Because like I said, this is, this was a very simple way of doing this. This wasn't anything super sophisticated and they're able to just, you know, um, basically reach, you know, transfer a lot of this, um, a lot of this money within the, within the crypto space.
So I think what we're seeing is that simplicity with a lot of these issues when it comes to tech and cybersecurity and breaches, is always something very simple and less sophisticated than we think. Well, Let me just say, oh, sorry, just one quick point though. The attack itself was pretty simple and straightforward, done a lot, but there is sophistication in the targeting that went in, the research that went in, and this is where criminals are putting effort in.
But you're right, the fundamental technology is simple, but don't downplay the amount of research criminals will do. So, um, sorry, Go ahead. No, I totally agree with that.
A hundred percent. A hundred percent. But I think, think what typically happens is we think about what type of attack this is what's going to happen.
We don't think, oh, developer's gonna hit with a phishing attack. The average, anyone in the software industry would say, I doubt that would actually ever happen to these top tier developers. But yeah, there definitely was a lot of planning and sophistication, right?
Simply, like I said, the best plans are the simplest in terms of how you do it. So the amount of research, like you said, um, that they put into this was very well calculated and very well planned. Well, I think Ira hit on like, what I was gonna say.
So they, these gangs, 'cause they like to call them gangs, whatever, it's not necessarily that A lot of times it's nation states and it's big business, and they're run like big businesses. And if, if you're a small business wanting to get into the ransomware gang, you can go and subscribe to a SaaS service and they will provide you with the codes you need. They'll provide you with, um, with the marketing that you need.
Because literally phishing is marketing and it has to be done very well. So it will trick people like these top tier developers. So it will look authentic and, and you have to figure out who your target is.
You have to figure out how to reach them, what their email address is. So the people that are doing this, and, and actually the attack was pretty sophisticated. It was pretty interesting that, that the code was obfuscated.
They figured that out right away, but then it did things like it, it changed what you typed in and what they actually decided to capture and, and the output looked, uh, normal when it came back. So they did a lot of pretty neat tricks that were very elegantly done. But those, when it looks that simple, it's never that easy.
So I think the thing we miss on a lot of times when we talk about ransomware is that this is big business because there's big money behind it, and they have sophisticated, um, marketing, sophisticated coding. And by the way, generative AI is helping that mu be much easier for them to do. Absolutely.
Right? I mean, it's, yeah. I mean, fundamentally, like I've seen these attacks again for decades.
Is there sophisticated? The problem is, I don't necessarily think the coding sophisticated, I look at this as professional. I wrote a book called Advanced Persistent Security, making fun of the concept of advanced persistent threat.
Because the concept is, you know, whether these are criminals or nation state, frankly doesn't matter if there's money, they will put it like North Korea is very much on the money raising. Maybe I've ran to a little bit. But you know, generally the, there's a lot of well-resourced criminal people who know exactly what these software programs are supposed to do.
And this is their profession. And frankly, yes, these people are good at what they do, but if I take off the street a bunch of good developers, I don't wanna say out of Apple 'cause all the Silicon Valley's cliche, but I'm in the DC area, I could go find a lot of good developers who could develop this quality of software with this sophistication if I just say, this is your job, and they would be that good. It's about, it is the persistence.
They are perent. It's, it's the persistence and it's doing it with style, you know, it's like falling with style, I guess if you wanna another movie reference, but we've gotta expect this. But again, I don't, you know, phishing is phishing, but I still don't fundamentally say, oh, I was tricked into divulging my two-factor authentication and saying, these are people, and the fundamental part is these people should theoretically know better that they are not all of a sudden gonna be locked out of their accounts.
So we give way too much credit to technology people, especially developers and companies like the people who maintain NPM are gonna start, have to be a lot more, expect their people to be as stupid as the stupid users. They keep blaming for misusing their software that they're developing. Absolutely agree with That.
All right, I gotta pull the plug on this one, guys. We're about outta time. Hey, before we go off today though, I, I, I feel compelled to just say a few things.
First of all, we're recording this show on nine 11, right? It's the 24th anniversary of, um, nine 11. And you know, I was in New York last week with my wife and we went to make a reservation 'cause my wife's up in the city today, and we asked a young girl to hostess at a restaurant about a reservation, and we said, you know, it's nine 11, it might be different.
She said, oh yeah, that's right, nine 11. Isn't that some kind of holiday like Veterans Day or something? Well, we've done a terrible job, I guess, of keeping our young people aware of, of, you know, of what happened on nine 11.
But what it really represents that we live in a very dangerous world, and if we need any reminder of it, yesterday, nine 10 was a great reminder where, you know, whether you agree or disagree, and I'm not gonna get into it, uh, someone was shocked for their beliefs for, for stating their beliefs at the same day. Three people were killed in a high school with gun violence. We have a serious problem in this country, right?
We don't solve things with guns. It shouldn't be solving with guns. And, and we, and people, we should never have to resort to violence to silence someone.
I, I don't care whether what side of this argument you are on, it's wrong. It's, it's not American. It's wrong and it's not healthy.
So, you know, on this Friday, take this weekend, remember the victims of nine 11. Remember how it brought us together as a country, as Americans. And, um, that's all I got to say.
Have a great weekend, everyone. Bye-bye. Hey everyone, welcome back here to Text Drunk tv.
Really excited to have my next guest on here. Well, it's a couple of reasons, but always, it's always a pleasure to have another Allen on, on the show with me, especially when it spells it the right way. Let me introduce you to Dr.
Allen Becker. Uh, Allen is the co-founder and CEO of a company called E Self. And we're gonna find out about eHealth and what they do in a second.
But let's first welcome Dr. Becker. How are you?
I'm it. I can call you Alan, right? Well, yeah.
Uh, Alan, it's, it's great. Thank you, Alan, for having me. It's a pleasure to be here today.
Uh, I was looking forward to, to be here for a long time. Absolutely. Uh, it's a pleasure to have you on.
So before we talk about e self and, and AI avatars and so forth, let's talk a little bit about you. You, you know, it's, it's Dr. Allen Becker.
I'm gonna assume you have a little education behind you there, and there's a story involved. Let's hear, let's hear the Dr. Allen Becker's story.
Yes. Uh, so I, I would say I started my, my career as a engineer, computer scientist. But, uh, when I graduated, um, I completely, by mistake, I would say I went to a course named Introduction to Machine Learning.
It was in 2012. And, uh, I was married since then. So I told my wife, Lisa, uh, I think I know what I wanna do when I grow up.
I was already 23. Um, so instead of, you know, going to the industry and start working as a, as an engineer, I spent many years in the university, in the academy, uh, pursuing my PhD in, um, machine learning and deep learning. And I published many papers, 10 papers in the field of, uh, speech technologies, uh, computer vision, natural language processing, kind of, uh, multimodal machine learning, uh, products.
And my passion was, you know, always about, uh, creating the machines, uh, AI software that can interact with the human as in the most, uh, human-like manner. Uh, and when I started my journey as an a PhD, you know, the, the world was so different as of today. I mean, we, we couldn't believe that the, the technology that exists today, uh, would actually exist a few years ago when I was a, a, you know, a junior researcher back then.
But anyhow, when I finished, uh, my PhD, I decided to, to be an entrepreneur. Uh, I, um, founded a company named Voca ai. Voca was all about having voice to voice conversations between humans and machines.
Uh, it was in 2018, we were probably one of the first, uh, companies, uh, out there doing, uh, uh, voice conversations, uh, between humans, uh, and ai. And we built, uh, I would say, uh, great technology in-house, uh, for speech to tech technologies, text to speech technologies, everything running in real time. Lms, the language models didn't exist back then, so that it, it did, has some limitations.
But anyhow, we managed to reach a huge scale in, uh, two to three years from the inception of the company, and eventually got acquired by Snapchat at the end of 2020. Uh, uh, after three years of Think af after the inception of the company, uh, I joined Snapchat as the head of, uh, conversational ai, leading the conversational AI efforts, the voice efforts, the, the language model efforts within snap. And it was, it was an amazing journey because, uh, we managed to, you know, to reach a huge scale of, uh, hundreds of million of daily active users that were using our, uh, voice technologies.
So it was, you know, it's beautiful to see that the baby that we built at voca it scale up, uh, that fast at Snap. And obviously it was a very nice out financial outcome for, uh, for, uh, the share shareholders of the company as well. Uh, uh, that's pretty much about, uh, um, my previous company, after Snap, after a few years, uh, that I spend on Snap, I decided to actually, to build, uh, the next generation of my previous company of voca and, uh, to create video experiences, real time video experiences between humans and ai.
I Avid experience. It's, it is something that like, like we have right now, Alan, we are having a Zoom conversation. Uh, you can see me, I can see you.
We are interacting real time. I can share my screen with you, you can share your screen with me. It's a fully interactive video experience, and that's exactly what we do at, at tso.
We created, uh, uh, avatars platform that allows to every creator to be video experiences. The video experiences, it, it, uh, it has a, an avatar obviously, that you can choose, a voice that you can craft. And, uh, I would say, uh, uh, prompt based, textual way to control the behavior of this avatar, to control the capabilities of those avatars.
Those avatars can, as I said, can analyze you how how you look like can analyze your screen. For example, if you have an, uh, it support issue, if you're, if you're struggling to log in to some page, you can show your screen with the avatar, and the avatar will guide you how to solve a problem step by step. If you are trying to solve a math problem and your, uh, LMS and your learning management, uh, uh, um, school, you have some equations, you can show your screen with the avatar and it can guide you step by step how to, as the same way as a private teacher would do, the avatar can do for you.
And the other way around, if you want to consume information, if you are intrigued, intrigued to learn a new subject, you can ask the avatar. And the avatar can not only respond to you in real time with a human-like face and everything, but he can actually present you videos in real time. He can generate images and content in real time to you to explain you the different concepts that, uh, uh, you're interested in.
So, for example, in education, we have tons of use cases in which are the students that are using esol. Uh, the AI avatars can, um, they have a board, they can write the equations for you. They can guide you step by step how, how to solve math problems.
They can, if you ask history questions, then they won't only answer to you, but they will illustrate those, uh, the history with images they will generate in real time images for you in order to illustrate the history. Because we believe that is of, that's the, the, I would say the, the, the most updated way to communicate between humans is through a video experiences. A video experience is an emerging experience that is, uh, quite different from chatting or voice because it, because it has the visual, uh, uh, aspect on top of it.
And visual helps for learning, helps for engagement. So all the use cases that we do at ISSO are around visual interactions. Love it.
What a great story. You know, Alan, I'm sitting here listening and really, and I mean, if you could go back to your 23-year-old self and say, Hey, keep doing what you're doing. 'cause this is what the world's gonna look like in 2025, you probably, and, and it wasn't that long ago, right?
It was, what, 12 years ago And towards the T now, correct. 12 years. I mean, I look over my career, right?
When I was 23, I actually had just taken the bar exam and become an attorney in New York. And, um, I didn't know anything about computers. I got into computers, never took a computer class.
I got into computers after I went to law school. After I started practicing law, I learned how to use word perfect and how to do networking. 'cause no one knew how to do it in my office.
And I, I became the expert. But what you did, a lot of the things you were studying are really sort of the precursors, the foundational like proteins, if you will, that we built the DNA of, of AI and, and generative and machine learning on, right? We, without the, the text to voice and the voice to text and, and all of these things, you, you, you didn't have that interaction that we, now we, you know, a lot of people think about your kids or my kid, you know, or my kids are done with college already, but, you know, kids coming out today, they take it for granted, right?
There'll be a time when you, maybe you don't use a keyboard and the mouse, right? Which is, you know, the whole, the whole system of the mouse and the windows is, you know, comes outta Xerox spark Yeah. In the seventies or even those sixties.
Um, so it, it's interesting to, you know, to, to be how that all comes together. Now, I don't know if you're old enough to remember a TV show called Max Headroom. Probably not.
It was here in the us It was, it was so far ahead of its time. So Max Headroom was a newscaster, but he, he wasn't real. He was an avatar.
He was a, an AI avatar. And, you know, this is before this ai, there is, you know, there's real, it was really ahead of its time. But it, it, I remember the discussions back then, and one of the big discussions, and it repeats itself, it repeats itself in robotics today, is how realistic do we want our avatars to be?
Do we want them to be indistinguishable? Like, if I'm doing a video like this, is it a real person, not a real person, but is it photorealistic of a person? Or is it obvious that the person's not real?
Right? Like, I'm not fooling anyone. I'm not trying to make you think I'm a real person.
I am an AI avatar, but I can engage with you, answer your questions, help you do everything. Um, just curious, where where are you on that side of the, of the debate? Um, so I think it's a great question.
And we, we are being asked a lot about this topic, so obviously have tons of things to say about it. It, so first of all, you know, from my passion point of view, my dream is to create the perfect ai just as a, as a nerd, I would say that, right? Uh, regardless what is the correct way or not, but we, we discuss it in, uh, for, uh, uh, shortly, don't worry.
But from my personal point of view, the dream to create the perfect machine that is as human as possible, being able to pass a during test is a dream is that dream that, uh, is coming true, right? So why is a dream? I mean, it goes way behind of, uh, being a geek or not.
It goes maybe to some philosophical questions about, uh, what is to be human? What is, what does it mean to be human? What is a human?
But some, to give some sense, if you can create a machine that is, uh, like human, you kind of, uh, maybe understand maybe a bit more what is a human, because you created it, uh, you know, it goes way behind the u the the best ux, but more like, uh, from a personal perspective that the fact that we created something that, uh, is in indistinguishable from humans, it's like an, uh, something that we achieved as a humanity. Okay? That's one thing.
But, but referring to, to, to your main question, I believe as humans, we, we love to interact with sim similar person, right? That, that that's our nature, right? Uh, the, the reason why there are people that they're racist is because there's someone that looks different, some different, and behaves differently.
And we are kind of, uh, intuitively we, we, we are afraid from people that look and sound different than, than ourselves. So, uh, the human nature is to to to to, to be, to be in interaction with similar people, right? Uh, and the same way it goes to technology, I mean, uh, I believe that people will feel more comfortable and will use, uh, um, more frequently technology that adapts to humans and not the other way around.
I mean, the fact that today we use the, the arm on our computers the way it does, like with the keywords and, uh, uh, and the mouse, right? And, and, and the screen. It's not meant to be, it's the, the only, it's, it's just the way that the computers works today.
But if we could interact with an, uh, machine, with a computer the same way we, we, you know, we are used to interact with other person that would probably would make more comfortable. And, and, and in order. Sure.
And in order to interact with other machines, they need to understand me the same way you understand me right now, right? For example, like moving my heads, uh, my, my hands. And you, you understand way more than the words that are coming out of my mouth, right?
You understand? You know, who is Allen by singing on, on the camera. So, so if I want to you to understand me and I want the machine to understand me, I need also to, to to, to be seen by the machine, and then be the machine to be able to, to interpret what the machine is seeing right now.
And the other way around. If, if I want to understand you better, I will need not only to, or, or to chat with you through text, because then we are losing a lot of information. I would like to see your voice to, sorry, to hear your voice, see your face gestures, see your, the whole island to understand who is Allen.
And if I like the machine to understand me so he can help me somehow, and we can interact, I need to be seen and I need to be able to see the other way, the the other, the other party. So back to your question, I believe that, uh, uh, as humanity, we need to create, uh, an interface that is comfortable to the end user, to the humans. And it should be as human as possible because that's the most comfortable way to interact with.
So, so besides being, uh, my personal geeky dre dream, I think the, if we want those machines, The right thing It to serve us and, and to help us, they need to be similar to us because that's the way that we will feel comfortable to, to interact. Absolutely. You know, I, I was having this discussion just the other day, actually yesterday, that someone was complaining that when they get the transcript from a video and then give the transcript to an AI and say, okay, write an article, a synopsis of, of this video from the transcript, it, it, it misses so much.
'cause it misses the inference, it misses the tone, it misses the gestures. And, and so, you know, just taking a transcript of a video is, is only like half the story, right? I think it's, people need to realize that, that it's very important if you wanna capture, you know, how do humans communicate?
We don't communicate just with words, we communicate with, with expressions and gestures and, you know, cans and signals and, and, you know, inflections in voice, right? You know, I could say a word three different ways, it's the same word, but you, it could convey different emotion behind it. And I, I think that is sort of a, a missing piece in, in how we are today, kind of taking these, you know, human to human interactions, human evok to machine interactions and trying to like, uh, analyze them and, and record them, you know, for posterity.
But Alan, I, I wanna turn to e self a little bit. Mm-hmm. So this sounds like just such a great no-brainer, really a no-brainer.
Like, who wouldn't want this for their company to be doing things like this? And you, you're helping in, in things like industry and banking and real estate. I mean, it, you know, this has been a dream for a really long time to have this sort of intelligent avatar that you can interact with and, and, you know, help in your business.
Did at ES self, have you created sort of templates that people pick from? Or is each one sort of a bespoke, you know, from scratch for that particular job? That's a great question.
So the vision behind, uh, EO, uh, was kind of taken from, uh, companies like, uh, weeks, if you know them. Do you know Wix? The Sure, Yeah.
The website. A website company. So if, if, if, if you think thoroughly what they've done there, they created templates of website.
Mm-hmm. 'cause eventually they ma the world, the web world into categories. And there are eventually, uh, uh, a small number of templates.
It might, it might be hundreds, but it's not millions. There are eventually small hu small numbers, maybe a few hundreds of templates that define the different websites that are possible in the world. So you have like, uh, maybe, uh, um, law firms, uh, templates, accounts.
You have, uh, e-commerce, you have many templates, right? So what, what we built, and it came out also from, you know, the experience that they had in a previous company. We understood that even that we have Gene AI today and, and, uh, and, uh, the LMS are very smart and, and powerful, and they don't need to have pre-built templates of the, the conversation graphs because the, they can go that's, it's not, uh, um, closed ended solution that there can be open ended questions, but still, you need to be able to, to limit those LMS and provide some guard, guard race to those LMS to, to give some goals to those agents that they will solve specific problems.
So, for example, atisa, we have se uh, uh, AI based sales representatives. We have customer service representatives, sorry, AI based customer service representatives. We have AI teachers, we have, uh, financial based, uh, AI based financial advisors.
So we do have templates because we created templates the same way, the same way that we weeks created templates for the, uh, the web of the world. We created templates for the possible type of interactions that human will have with our avatars. So if you reach our, our, if you go to our website and you sign up to a studio, you'll see, uh, many templates, prebuilt avatars, prebuilt agents that are tailor made for specific industries.
And then the same way that, uh, you can do at Wix, you can give, use the a template and modified to your needs, but you don't need to be technical. You can, you can, you can easily modify it with a bit of prompting. So that's the way, the same thing we did at at Esof, when you clone an existing AI avatar, you already had all the integrations, all the, I would say the heavy lifting was already done behind the screens.
So the only thing that you need to do right now is to, with a bit previous, uh, small effort of prompt engineering, you, you can customize your avatar to your business to the solution that you're looking for. And, uh, that's it. It, uh, basically takes a few minutes to integrate with your existing business and to customize and fine tune the existing solution for, for you.
Love it. I'm not asking you to give out pricing per se here, but, you know, ballpark, what does it cost for an Esso sort of avatar to, you know, for, for a person's business? What should they expect to be paying for something like this?
So, so the, the move that we're taking with Esso, we created a freemium model, which means that if you sign up to your studio, you will get a few free calls, free interactions that you can do with the avatar without paying us. And then you have different plans. You, you can start with, uh, basic plans of, uh, uh, and then going up to, to, to, uh, growth plans and so on.
Uh, and then if you are like a big enterprise, and you did an enterprise based based solution with deeper integrations and maybe some other features that, that are not available in the self service studio, uh, they usually, in the customers, they reach out to us, to our sales representatives, and they, they, they give us specific quotes. But for the self service studio, the prices varies from, uh, uh, $10 a month to $200 a month. That really, sorry, the prices.
So, so we have, uh, tons of cell service clients that we never spoke with them. Uh, and they are, because we created a weak style templates, they're self-serving their themselves in the studio. So they, they create, uh, the, their avatars, they can embed it to their websites, to application by their own.
They don't really need us. So they only pay per, uh, a monthly, uh, payment, uh, per usage. That's basically the way it works.
I love it. Alan, we're about out time for people who want to get more information on Es self, what's the website? ai.
Es self is e Ai. It's ESEF ai. I love it.
I'm gonna play with it myself. And maybe we'll have you back on, and we could talk more about this. I have ideas.
I'd like to have an avatar member of our news team. We, we, we do a show every morning. As a matter of fact, I'm going to record it right after I'm done with you.
I have to move to the next set in my studio. It's called Textron Gang. And we have like four or five people on every day talking about the big stories of the day, three big stories every day.
Uh, maybe we could have an avatar be part of the gang and, and join in. That would be, oh, it's, that would be an interesting experiment. I'll, I'll reach out offline to you and see what we could do.
Sounds great. Dar, sounds like, All righty, thank you. Keep doing what you're doing.
It's fascinating. Fun work. You know, they say if you do what you love, you never work a day in your life.
Exactly. It's, and, uh, We are not working at this software. We, it's 100% fun.
That's the, the, that's the truth. Absolutely, man. Keep it up.
Dr. Allen Becker, very much co-founder, CEO of Esof. Thank you for being on Textron tv.
Thank you, Alan. Alright, we're gonna take a break. We'll be back here on Tech Truck TV in a little bit.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insights series. I'm your host, Mike Bazaar. Today we're with Christian Canberra as the C-E-O-S-P-L-X.
And we're talking about, well, just how much progress are we making in securing AI models because, well, the theory at least was as we go along, they'll get more secure, but that may not be the case. Christian, welcome to show. Thank you, Mike.
Pleasure to be here. Alright, What's your assessment of what's going on here? And some folks are saying that tests would show that chat GT five, for example, is not more secure than chat GT four.
And is this just the nature of the particular beast, or are we just not paying attention to security? Again, I Think security is not the main topic of probably open ai. Other folks are, um, currently focused on, it's just more data, it's just more capacity, it's multimodality and other features.
So I guess it's coming back to the topic, why security matters and why hallucination matters and why accuracy matters. I think it's security is a pretty wide topic, and I think what we found out through our research is that, um, the company was not paying attention to hallucinations and I would say fake URLs and, uh, any type of other, um, fake news and bias, uh, biases, uh, which can happen and predominantly, uh, also fill into the security bucket as well. So, and, uh, obviously, um, alman took it, uh, from a production, I think over the week and was apologizing that the team was tired.
So I think we're now going back big time to, um, security and security testing, I guess. And it's not only models, of course, I think, um, we see, uh, a pattern in, uh, domain specific application when big companies are billing those agents. Uh, the attack surface is way bigger than just testing the model itself.
The model's just the underlying model is just the base you start with. Mm-hmm. Are you perceiving that people are kind of encountering these issues during testing and this is what's holding them up from deploying in production?
Or are they just kind of ignoring it and hoping for the best? I think a lot of companies are ignoring that. Uh, we don't, we, we don't hear a lot of things in the public, but I guess there are some, some, uh, examples with custom ba uh, customer facing applications.
But I think what we see currently is like big corporations use it internally for AI workflows and, uh, agents. And I think, uh, they haven't been paying that much of, um, attention to testing. But as we do more, uh, work more with their own data and, uh, basically fine tune their own data and incorporate into those models together, it's gonna be a massive thing.
And it's already a massive thing. And I think, um, yeah, we're just at the beginning. So we work, for example, with one company then 48 RSLA to deploy, to use a model in production.
The pressure is huge from the business to deploy and use models at scale because it's not a winner takes it all market. And, um, I guess, um, we need more people and we need more skills, um, predominantly more scale than beside any type, any kind of automation orly. Um, is it always gonna be the responsibility of the people using the models to figure out how to secure them?
It doesn't seem like the providers of the models themselves are normally gonna be too focused on that. They might provide some maybe rudimentary guardrails, but I feel like we're basically saying the responsibility for securing them lies with the organization using them. That's a good question.
I think the responsibility for the plane model should be definitely with the builder of the model. But, um, the guardrails are not really knowing exactly what the user is supposed to use the model for. So if you take, I don't know, uh, logistics healthcare, you're gonna train the model, you're gonna fine tune a bit, you're gonna have your own rag.
So it's, um, it's not easy to use any type of default, um, guardrail. And that's why we always say there, no matter, it doesn't matter who does the guardrail and the lightweight guardrail to be custom built, custom policies for, for example, bias and off topic and I don't know, competitive checks and business alignments even, I don't know, profanity, those kind of things as that can be only done with insights into the domain of the, of the user. So that's why the user in this case, is the company who's putting those models of wrap models somewhere in the, in production towards the customers, the users.
Um, and this is definitely the liability of the end user in this, in this, in this topic. Yeah. Aren't we making a conscious decision about the risk or we just kind of rushing in head long?
Because I can see some business users saying, well, it's good enough, it's right, you know, 95 out of a hundred times, and that other five times is just part of the risk factor that we're taking into account for the benefit of increased productivity. It depends on the business. Um, we've been seeing use cases in healthcare where models were hallucinating and recommending you to take the pill before the breakfast or after the breakfast, or clean the needle twice, reuse it with alcohol and stuff.
This can have cause, uh, this can cause massive, uh, massive, uh, issues. Uh, not only health issues, but legal issues. So it depends which kind of business you are.
If you have a, if you are a car seller and you don't care if people are just buying a car for, uh, for a buck, then it's a different topic. So, um, you can put always a disclaimer and you just basically can say, Hey, you know what? I'm not liable for anything.
The model spins out and you can build guides, but those are basically then limiting your user, uh, to a certain number of use cases. And then you're just going back to the machine learning model itself, it has been a few years ago. So I think we should enhance gen AI and we should let gen ai, uh, be the automation tool and help help us to, as, as you said, have more productivity.
But I think security testing and specifically AI security and safety testing becomes essential. Why while you're building more AI models and more, more use cases, it all started with customer pacing chats. But meanwhile, as I said before, we have AI workflows.
We have, um, ai, uh, AI agents internally, communication tools, wrappers any type of ai, uh, usage in the company, which is going above a hundred or a thousand in some fortune fifties. Yeah. Mm-hmm.
So are we therefore just waiting on some sort of cataclysmic event to occur before everybody kind of wakes up and takes a look at all this stuff? Or is there a way of thinking about this maybe in a more proactive manner? I think, uh, the legislation or I think compliance framework should definitely make a step.
Uh, a lot of companies don't really know, A lot of businesses don't really know what to comply with. There is some standards like os and this framework, but it's not really, um, giving or it's not really a mandate for CISO to secure the business, right? They can use it, but they're not like liable for anything in this case.
Like they can secure themselves with saying, Hey, we're not liable for a PC. We can put a disclaimer. I think, uh, once we're getting to the step, like having heavy usage of AI anywhere, uh, there should be a legal framework or at least the kind of, uh, industrywide framework, which gives a mandate to the, to the CSOs and their businesses to be liable, uh, to be, um, to be compliant to comply with.
Mm-hmm. And this will, this will trigger the usage because in, in, in Europe we've seen AI and it was a mess. People are just scared of deploying ai.
That's a totally, totally different story. I think people are just scared. But AI does not build for, for, for AI security.
It's just legislation. It's just a, it's just a thing saying, Hey, you should secure your ai, but how do you do it? There's many ways from offensive security to defensive security to governance controls, compliance controls.
I think those measurements, uh, measures should be, should be implemented anywhere. And then on domain, and I think this is the, this is the real future. I think we'll have several frameworks for domain specific applications and industries.
And then also, um, yeah, secur, uh, variations on how to secure those. I can't help but wonder if we're also just ignoring some of the existing regulations we have that should apply, whether it's HIPAA in the United States or GDPR in Europe. Don't these things assume that there's some level of privacy and security being applied in the first place and it should apply to ai?
Yeah, absolutely. And they should. Uh, but they have, they should have a, at least a section which is, uh, covering AI security, let's say, um, data exfiltration, rec poisoning, data poisoning, so many new attacks which are coming out.
It's just the only proper objection on jailbreaks, right? Every attacker goes first with the contact leakage or the jailbreak. But if you don't succeed, what you're gonna do, you're gonna do some patent code execution, enter the source, co uh, enter the, the, the server files.
Like a lot of things can happen. And I think this should be written down somewhere and this should be secured somewhere or to have at least a guideline. Because what happens is security teams are now entering the space, but a lot of people in cybersecurity don't really understand that non administered behavior of LLMs and AI models.
So what needs to be done in big corporations is like a lot of AI engineers and data science need to help them out because it's gonna be a whole totally different new animal. And what I would say smart businesses do is they create standalone AI security teams, which are reporting directly to the CSUN in this case and just taking care of this manner. 'cause it's a totally different animal that's uncomparable to cloud security.
We've, we've seen before, and I would say from timeline perspective, we're like in 2007 or 2008, uh, when cloud security just came out, and this is the infancy situation we have right now with AI security. We've seen this debate before, but people will say, well, there's not enough cybersecurity folks who know anything about ai and therefore we need to train the data science teams more about security. Or you don't seem particularly interested either.
Yeah, I mean, we have 30 people and I think, um, 25 people are just data scientists. Never. They've never done cybersecurity before, never.
We have a CISO and she's out of the cybersecurity space and I think she's helping us out with those acronyms and stuff. But at the end of the day, while we do continues, uh, AI security testing is, we've seen on our, like we've started the first manual pen testing, like, and we saw, we saw, oh wow, this can't be fixed, fixed. Uh, and then just, and, and, uh, this can't be fixed in one time and let it go like for six months.
Like we did that for w or whatever. It's impossible. You need, you need do it continuously because your day text to text capabilities tomorrow, you text to speech, you will document upload CSP files, whatever, and enhance new system prompts.
So I think, uh, every two, three weeks and looking at model and, uh, specifically at the domain specific application with a model and several models, if we talk about a gen agent to agent communication, it's massive. It just can't do it one half and just let it go. So in addition to the data science teams, we also need the auditors to be aware of what the security issues might be as it relates to ai.
And yet they too are not trained. So how would they even recognize what an issue is? Uh, they have the biggest business right now.
I always say AI is a services business. It's not a product business. It can be a product business in the B2C face and where our kids and teenagers and my grandma is using Chad GPT, but the use case productization and big firms and companies and corporations is still not there.
We're pre-production. That's why we work with a lot of auditors. And as they are at the core, they're at the core and they see what's happening and they actually switch to a lot of, I would say, penetration testing services and AI testing services and have their own own AI frameworks.
I think we have KMG with their own AI framework, which is already going very deep into, towards how to secure AI pre-production and in runtime. So, um, you're totally right. The auditors are super important in this case.
I also wonder if the bad guys, AKA cyber criminals might be a little more AI literate than the rest of us at this point. 'cause they're like, Hey, this is the greatest thing since sliced bread, or are they still trying to figure it out themselves? A lot of things can happen by accidents.
And I think we, uh, we just had a a an example on the west coast with a student, uh, guy, like a student who was, um, doing an internship in the company and was like doing like, um, text to text communication with another employee. And we've seen some day exfiltration of Google workspace to g run Confluence out of this chat. So everyone who has access to this kind of chat, internal company chat, and you work with customer data, internal data and type of PI data, it's, it's, it, the attack surface is huge.
Uh, we're talking about 95% un un undetected, uh, uh, tech surface still. Mm-hmm. Long term.
I mean, I feel like we've been talking about the need to secure our data forever, but might the rise of AI just finally shine a spotlight on this issue as a, both a data management and a data security crisis that people will finally address? Yeah, I think we all, what we all need is visibility. I think currently we're having a huge, uh, ton of AI usage, which we can't, uh, assess and can't address.
I think it's, uh, from the user perspective, but from the application perspective. And I think what companies are currently trying to do is like uncover the AI assets and try to understand what's happening where have at least a kind of an overview and then they can build policies around that. I wouldn't be too strict about it.
I think what I like about the US is that people are just super positive about the AI usage and trying to use that as much as possible. But I would just say when we're dealing with sensitive data, we should be always sensitive. And this starts with healthcare, going back to banking and insurance.
Um, it, we just need to educate the market and the users as well. What can happen. And this can't be just sold, put a disclaimer or just, I don't know, quick questionnaire or, or whatever.
So this is the thing, but I wouldn't be that much of the pessimistic or negative. Uh, it's just part of a wider ai, uh, cybersecurity space, uh, which AI security will play. What's your best advice to folks about how to go after that particular task or issue?
Because I think a lot of them will look at it and just say, wow, this is just so overwhelming. I have no idea where to get started. I think, as I said before, I think AI repository, ai, AI code analysis, um, scanning analysis, I think the shift left approach makes sense.
There's a lot of companies out there, um, we're going that direction. Even, um, classic SaaS and desk companies. Um, we call it AI bomb AI develop material.
I think having the first visibility of your AI workflows, um, as a CISO and as an organization helps you actually to uncover, oh, uh, is this in production? Is this in pre-production where it's connected to what MCP server is needs to be whitelisted and where this is the first step I would do. And then I would think about guard and then I would think about security testing.
And so, because anything which is anything which is not uncovered, you can't even know what's behind. And then later on you would understand and you would need to assess is this of a high risk or if this is something in pre-production, I'm just playing with around if this is a high risk, then of course we need do some, uh, governance controlled security testing, control, uh, security testing measurements and thes measurements. But I would, I would go first with the discovery, um, with the ai, uh, AI inventory discovery.
I think part of the issue that people are trying to determine as well is you mentioned that most AI projects today are led by what I might call a TIGER team, and it should have some sort of security person involved in that. But folks are also saying, well, maybe only a matter of time before AI is pervasive and maybe I just have to figure out how to extend my existing security workflows and processes to include ai. Is that where, is that the curve that we're on and how long might it take to get there?
Or is that just never gonna be feasible? Yeah, I think both ways are, um, realistic. Uh, it depends what the company does.
If we're talking about a bank which is completely transforming its business and having a kind of a low touch business with the customer and client and user, um, having a chat interface or having some, uh, AI automation and, and talking and discover and talking with the customer and, and, and, and companies, I think, uh, a team is needed, right? A specific team is needed. Call it tiger team or call the I security team, whatever.
But if your business is not that, I would say, uh, that much of, um, affected by any type of cybersecurity risks and specifically I security risks and a lot of small business do that enterprise, midlevel enterprise do that, I think, um, I would go always first with, uh, with full risk or with a lot of risk to try to see what's happen, what's happening. Because we never protected insecurity something which is unknown. We always try to fix something or protect if we know the threat, right?
Sometimes you just don't know the threat, right? And you can't anticipate it, uh, because you don't know how you users will reactive how, how they gonna use it in that way. But if we're talking about highly sensitive businesses, um, going to healthcare and biomedicine and, and, and drug production, whenever it's, it's necessary we have this steam, I would say Ultimately we talked about that skill shortage, but might not, we one day see AI models that are trained to help protect AI models and therefore, you know, that's how we're gonna kind of narrow that skills gap.
Yeah, we talk about that a lot. Agent to agent communication or, uh, gentech, uh, LLM based create attacks. I can, I can only say that the number of false positives still high 'cause those models hallucinate and stuff.
So how we do it, we have a lot of 11 AR researchers. Every test we see out there and every prompt injection we see out there, we retest them with human and loop before embedding it anywhere. It, this just doesn't make sense because if you have a security team, let's say, and you mentioned in a question before with the cybersecurity teams, a lot of AI security components being right now embedded in cybersecurity controls in SaaS and das in firewalls and DLP functionalities.
And if you are just bringing some kind of software, which should secure this model and use LMS for that only, um, the companies will not use it that much. 'cause the number of fault spots is still high, right? So I would say a kind of number of expertise retesting human in the loop, having a kind of some controls in place already is something which, which I see as realistic as of current.
Yeah. And not a hundred percent protection is, is is not guaranteed even with you. Pardon the system prompt, which we always recommend wood rack without rack and then try to put some lightweight guardrails.
5%. I, all right, well, folks, you heard it here, AI security, it's not easy. But the one thing was for certain is the longer it takes you to address it, the harder it will become.
Christian, thanks for being on the show. Thank you, Mike. Pleasure to be here.
All right. Thank you all for watching the latest episode of the Techstrong AI Leadership Insight series. You can find this episode, others on our website.
We invite you to check those out. Until then, we'll see you next time. Howdy.
My name's John Nicholson. I work at Broadcom here, do technical marketing for vsan and work within the storage area and as it pertains to the VMware Cloud Foundation stack. So today we're gonna talk a little bit about, um, what's new on the storage side within VMware Cloud Foundation.
Nine. So going over some of the areas. Um, I want to go over some of the operation tooling, start at kind of the strategic capabilities that we've brought out within nine, as well as help you understand some of the tactical tooling.
We have to answer the question of why is this slow? We'll talk about some of the key capabilities within VSAN nine, um, and other capabilities that are brought out. So going over kind of at a high level, there's four major themes of improvement.
Um, we've got improving the, the cost of operations. This is gonna be driven primarily by the new global deduplication. We also are adding additional disaster recovery capabilities vs a N vs a n replication and integrations with live recovery.
And then we also have, um, new performance capabilities and general security improvements across the platform. And this last area that we'll actually start with a demo on is going over some of these new operational consoles and abilities to understand what's going on across your estate. And now I'm gonna transition over to the, uh, demo.
So looking at these multi-site operations, if you've got one cluster, it's great that you're gonna work with NV Center normally, but in a larger environment, we're gonna use operations and we have these new capabilities. We can see all the alerts in the environment, we can see all the clusters I have here. I can also see their configuration.
I can see the health scores that are rolling up. So if there were environments that were having performance problems or other capabilities that would get surfaced. I can see what kind of vs a n cluster they are, whether they're the new express storage architecture.
I can also see compute clusters, which are clusters that are just consuming vs a n storage. And then on the right here, I can also see those cluster performance capabilities. And I can see not only how many iops I'm being delivering an environment, but also what that latency looks like.
Um, across this environment, we have this new diagnostics capability. So I can actually go look into clusters and troubleshoot and see what's going on, and I can pick a time window and trying to understand, you know, is there's something wrong in this environment, in this cluster. The initial cluster I have, if I go look at this and run this troubleshooting, um, I may discover, you know, across a specific time I don't have issues.
'cause my cluster obviously isn't no great performance issues, but if I did, I might see other capabilities. Now, if I wanna look deeper into what's going on with the workload, we have a capability native to the vCenter server called IO Insight. This is actually gonna run something called a V scuzzy trace.
It's gonna like a DVR for the entire, uh, storage io path of that virtual machine. Now we're gonna select which virtual machines we wanna run this for. So if you're trying to understand a workload and maybe you're migrating a workload, um, into a new environment, and you wanna get a better picture of what's going on, this is gonna help give us a lot of visibility into what the actual IO path is doing on a virtual machine.
Traditional monitoring often works on a random sampling or polling basis. Um, this is kind of nifty in that this is actually gonna capture all of the io, um, that's going on in that environment and actually trace through what the actual performance, um, demands are that we're running during that period. And if I have it also within an environment, I'm able to capture these and create these, um, instances and go through.
Now, if we go look at the actual performance that's been captured on these workloads, we can see the amount of iops that have been, um, that are being from a top talker's perspective. So we can see the, the top VMs in my cluster in terms of what, uh, performance demands are being made in the environment. And since I've had these, uh, these captures running, I can now go view them.
So I've got a logs appliance I'm gonna go look at, and this is gonna break down on a perm DK basis. I can see exactly what the, um, performance, the throughput, but if I scroll down here, I can actually see the distribution on the block size and the latency distribution. So rather than get a simple average, which may hide some outliers, um, in this case, I can see on my high side I'm one to five milliseconds.
But on my low side, the microseconds, um, on my block size, I see that I've got a couple very large blocks, but most of this is 4K. One of the challenges a lot of times is if you look at a lot of just general performance capability gathering, it'll often average this out. But with this we can get the exact requirements of what a it's running on.
Now this other tool I'm using here is called Trip analyzer, and this is gonna show the end-to-end io path of that, uh, virtual machine and the discs and where they're located. Now, if I was having performance problems in an environment, this will actually surface in red the individual component, but I can also drill quickly in. And so if I'm trying to trace down where Latency's coming from, this is gonna help me map it end to end.
So I can see I'm looking at the individual devices, I'm looking at actually the raw firmware latency coming off that device. So if the, that drive was either overloaded or had a problem, I can also look into the network hops. Now, historically, as a storage admin, if I wanted to do end-to-end troubleshooting of an IO path, I might have to log into my fabric switches.
I might have to log into my hosts and go look at ES xtop. I might have to go log into a raise themselves. I'd have potentially to look at multiple places to understand that iPath end to end.
But here we're able to capture what the, what the actual performance impact of every single hop is, because we are both, so to speak, the client and the storage platform. We are both sides of this. Oh, I noticed that this is using an a, um, ESA, uh, architecture for the storage.
Is this also available with the OSA, the original storage architecture? Um, the IO Tripp analyzer. So the, um, these bits, um, IO Tripp analyzer's been out for a while.
So yeah, I believe that also was, um, uh, available with OSA, the, uh, the V CZ trace capabilities, those are, those have also been available, um, in regards to that. Okay. And Second question on that is, what's the overhead, like if we are putting these VCA traces on, is this, uh, u use it briefly while you are troubleshooting an issue or planning for a performance upgrade?
Or is this a more general purpose monitoring tool that we might use more widely? So The last time I talked to engineering on this, I think it added it's about 1% CPU load to a host. Um, it's not something that we generally run 24 7, but you can, uh, schedule those to run and people do, if there's a specific virtual machine, um, on the overhead is relatively low, but it is there, it's not, that's why it's not on, uh, 24 7, uh, currently.
That said, the general performance service is running 24 7, um, and it is capturing that data, that performance service, by the way, has been improved where the current poll, uh, poll interval is now 30 seconds. However, if you really want to go nuts, um, if you go into the cluster settings, you can actually turn on what's called network diagnostic mode. And for 24 hours, we will run a one second poll interval specific on the network stack, which if you're trying to, um, identify microburst related performance issues or maybe things like you are concerned on switch buffers or on a leaf spine link or being oversaturated, um, that one second granularity is really nice.
Hey, hey, John, I noticed in the demo that you started out, uh, in the ops console, but then a lot of it it looked like was in the vSphere console, unless I was Yes. Wrong. So do you expect the storage admin to spend more time in the, in one console versus the other?
Or is some of that functionality, the new functionality showed within vSphere to make its way into ops to give it that single pane of glass to or use cliche? Uh, yeah, It's, it's always about pain or at least trying to avoid it again. Um, so some of those things that actual storage diagnostic that actually was originally a vCenter only feature.
Um, and we've moved it to ops and a couple things have happened there actually under the hood, one that previously required a, a cloud connection to run. Um, and we've removed the need to go use the cloud, the ops is your cloud, so to speak, for that functionality. Also, it used to be limited only to diagnosing HCI bench performance benchmarking runs now.
It just works for general troubleshooting. So that's an example of something that started in vCenter and we moved over. The other thing though, from a general where I expect a, an admin to be is I expect if I'm looking holistically across my fleet, if I want, if I've got multiple clusters sprawling out, you know, tens, hundreds of these things, or I'm looking at general capacity trends, I'm gonna probably spend my time in ops.
If I have a specific virtual machine that a specific someone is asking me about, and I'm trying to drill into the tactical why that's slow, I'm probably gonna wander back into my vCenter server. However, obviously there's links between the UIs to hop between them. Um, that said, the general trend is trying to move as much end to end to hops as possible.
Yeah, from that standpoint, I remember back in the day, it's been a while since I've been a vsan admin having to hop through the vCenter console various places. If I lost something in my vsan cluster, uh, an entire host, a single drive, whatever, and I wanna view resync status, affected objects, stuff like that, I knew where to find that. Is that gonna make its way into ops at some point?
Is it still gonna be, uh, you know, you have to know the right place to click within vCenter? What's that gonna look like? So What's driving a lot of that from a UI simplicity is actually, when you click on health alerts and things like that, um, it, it tries to drive you into that.
And some of that stuff I showed you there, like with the IO Tripp analyzer is there's all these different performance dashboards and they're scattered across all the hosts and the VMs. But if you're using that view and it identifies a red area, it'll let you drive straight to it. So kind of our, our designing goal here is to try to make it to where you don't have to memorize the 14 clicks, uh, to go understand things.
And if you have a health check or an alarm that's going off in ops, it should take you straight to where that is. Um, and some of that's you'll, you've seen previously with the vsan Health to where if there's an issue, you can click the troubleshoot button or you can click the, okay, what's the relevant KB for this? Uh, we try to make sure all those health alarms and roll ups that go into OPS and the vsan Health Service have those capabilities.
Uh, looking at historical data, how far can they go back in time? So operations can hold data for years, I believe. Um, the vsan performance, uh, service tends to hold about 90 days on its own, but that data is gonna get rolled up into ops.
So for your longer term retention, you're still looking at ops. Um, it is worth noting that the vsan Health Service, I believe has at least 90 days. And you can also, uh, there isn't actually an option within the UI to say, show me what previous alerts have gone off.
And I can see the historical track for those, those alerts. So the other thing that we're, we're bringing kind of back in a way to vsan is deduplication. So we had deduplication with the original storage architecture, but it had a lot of limitations.
Um, and we've brought now with vsan ESA, when initially launched, we just had compression. We wanted to make sure we refactor deduplication really got it right. And so we have this capability today, um, and we're calling this cluster wide global deduplication.
Uh, this is launching with limited availability, um, with nine, um, there's gonna be a request for technical approval. Basically, you fill out a form and you can get access to it. Um, some things that have, that are definitely improved.
With this, we are using a 4K fixed block granularity. I see quite a few, uh, storage people on this call. So I know that may mean some things to you, which is generally pretty, uh, granular in terms of that.
We also are going to ddu across the entire cluster domain. Previously with originals for architecture, it was on a per disc group basis. And so if you had three disc groups and a host and you had five hosts, you could have 15 DDU domains.
Um, we are going to run this asynchronously. This is not sitting in the right IO path, so it will not impact right performance, and it's gonna adaptively, throttle and run based on, uh, being available performance resources in the cluster for it to run on. Um, this does integrate with some of our other capabilities, snapshots, compression and so forth.
Um, and we're looking to expand this out, um, from a under the hood, kind of how this works is we're doing a post process. We're gonna go through, we use a secure cryptographic hash, that's Shaw 2 56, so we're not really worried about collisions, um, in regards to that. And we will create DDU meta metadata objects, um, that as we find that we single instance that data out in grovel, that, um, if we obviously find no no matching, um, we are going to do some sharding across the cluster for scalability and performance and make sure this gets balanced, um, and try to keep large reads contiguous and, and not cause excessive fragmentation across the environment.
So I, I'm sure like every customer's gonna know, okay, how much can I save with ddu? And that's an impossible question to answer. I love that question.
Yeah, But I guess my, my follow up is like if I enable it, how do I know if I'm seeing the full effects of it yet? Or if that async process is not yet done running and I should hold my horses to look at my own stats to see how well it's working for me, What we expect is most people are gonna set it up for initial cluster setup, um, in regards to that and just set it across the array. So as you copy data in, you will get more benefit.
Now, one challenge with ddo, as you say, uh, you know, how much, how much data will I get? Ddo is the great question of life. You know, how many roads must a man walk down?
The answer must be 42 I guess. But, um, trying to do that one, one thing to keep in mind is two things will impact this. So one, the more data you put in, obviously the fuller, the more data you put in, this will scale it.
The other thing also is you can keep growing that deduplication domain. And so, you know, as you grow that cluster, the more opport and you add more data, the more opportunity for duplicate data. Um, some people have tried to create various, you know, workflows over the years and say, oh, let's have a Grover agent, or let's pre-scan data, or let's do things.
Uh, there's, there's kind of madness in that. I, I would, you know, anecdotally expect maybe a forex, you know, between compression and ddu. But again, if you're doing full CL VDI, that dedupe ratio can go to the moon.
If you have encrypted video data, obviously that doesn't de-dupe well. 'cause it's high entropy. One of the things to think about though is you're from a vsan density.
Um, you know, from the scale of this, if you've got one U pizza box servers with 20 in VME drive slots and you're putting 16 terabyte drives in those, and you've got maybe six of those hosts, that's gonna be about the same capacity as the median third party array out there. But you can keep expanding that vsan cluster out. And these things can grow quite large.
I mean, you can have many, many petabytes of raw vsan within a cluster. So these DUP domains we expect to get rather large in capability. Um, and from a perspective of, you know, sizing that should be able to produce some pretty good deduplication as opposed to the older architecture we have with original storage architecture where that DUP was limited not just even to per host, but purchase group, um, or a per array based.
You do. And again, comparing that per ESA, if you looked at that, we had those relatively small, um, the original search architecture also ran inline. It was during the cache de staging, and that could be a bottlenecks, a sustained rights.
It was performance negatively impacting. Um, and in regards also with resynchronization, um, if you worked with the old V-C-N-E-S-A, if you had a drive fail, it would fail that entire disc group. So now you could potentially have multiple drives that needed to resync with V-C-N-E-S-A one drive failure is just one drive failure.
So that that data just needs to be Rey elsewhere across the cluster in a many, many actions. So we are seeing significantly faster resync operations with this architecture. Um, and the compression, by the way, does still happen before first, right?
And so that actually is partly to help us with network usage efficiency. We compress before we hit the network. Um, so from a activity of this, this is, this feature is coming out with patch one.
We are doing some initial, uh, limitations on this request for product qualification. Um, we're gonna require, we want people to have phone home on. And we're also limiting cluster sizes to 16 nodes initially.
We're also wanting to see 25 gig networking at a minimum, which you really should be at in the year 2025. Um, and then we've got some other limitations on features. We're doing additional QA testing.
Any questions on ddu there? I see a higher and higher request for encrypted, uh, destroyed. And in that case, DDU DOT doesn't make, uh, much sense.
So it's there. Compliance is requiring encryption storage. Uh, you are correct.
If people encrypt at the application level, then that effectively does break deduplication. That's, um, an inherent limitation of it. However, we do offer data at REST encryption and we do offer data in transit encryption.
So vsan, um, ESA by default actually encrypts before it hits the wire. But we will actually apply an additional rotating cipher, much like vMotion encryption, so we can meet the highest of compliance requirements by doing encryption on our side. Again, if you're doing app level encryption, that obviously is gonna have impacts.
Um, but we can meet a lot of those compliance requirements using our encryption where possible and hopefully keep that data to where we can still run compression in ddo, but compliance will differ. Um, some other things to keep in mind is, um, VCF in general, its support of how we do vsan n um, and broader support of capabilities. Uh, we are now supporting, um, multiple different vs a n deployment types.
So we can do single site cluster, we can do what are called disaggregated or storage clusters. This is the artist formerly known as VSAN Max. So we can have these, um, clusters that basically act as a storage array.
And we can also import clusters that are stretch node and import two node cluster. So historically, VCF, um, it's been a great platform. We've had it for a very long time, but adoption historically was low because we had a very, you know, it was greenfield only.
You had to deploy it a very specific way, your existing workloads, you would have to, you know, basically repay, vMotion everything in and repay that stuff over. We now have pretty broad support to import your clusters as they are and meet customers where they are on those capabilities and bring them into the VCF, um, lifecycle workflow. And so we have these ability to do these converge and import these clusters and capabilities.
Hey John, quick question on the previous slide, as probably a little detailed that means nothing, but I noticed that we've got a workload domain that has a stretch cluster in it in here, but the management domain does not appear stretched. I thought those were, you know, co-dependent on each other in the past, and maybe that was just a detail that wasn't left in the slide. That you must have a stretched management cluster, uh, to support stretch workload domains.
Unless that has changed with VCF nine. You know, I'll have to defer to my VCF team on that, but I believe you can actually import a stretch cluster that is independent of the management being stretched. I believe that was the case, but, um, I'll have to refer you to docs, so sure.
But you're right, that's the kind of like weird rigidity that we've had historically. And, and in general as a directional, we're trying to move away from that. We obviously have strong opinions on architecture and things like that, but we also understand that waiting for someone to depreciate servers for seven years and recycle them in order to adopt BCF, that's gonna take too long.
We've gotta meet people where they are. So speaking of storage clusters, um, when I go talk to customers historically, you know, we pitch vsan and say, Hey, look, we've got hyperconverged architecture, um, this is great. And then they'd say, well, you know, I, I have this asynchronous storage workload, or I want to disaggregate, I wanna have very small client clusters, maybe for a workload for licensing and other reasons, something like Oracle.
Um, and so we came out with a system to be where we can have these storage clusters and segment these. Um, one of the limitations we've had in the past is that all of usan would hear panel traffic through a single VM kernel port. We now have the ability to disaggregate this.
We can, we can just run separate networking. And so you can go build this storage cluster, hopefully using modern 25, or really at this point, a hundred gig topex switches. But then you can have a separate VM kernel port that talks out to the existing, um, hosts over their existing networking.
And what, what you can do here is let's, you've got a legacy environment, it's got 10 gig, you could have one connection that goes into that network, and then you could have a separate backend network used for the vsan N network and spread this out. And what this looks like in the ui, um, is we have an additional VM kernel port now for that storage cluster, uh, traffic that backend traffic. Um, and as you can see here, if you've followed VMware for a while where I've, we've actually added quite a lot of kernel ports over the years.
These things are kinda like Pokemon. We've gotta collect 'em all here. Um, at some point I probably do deserve, uh, for everyone to have a blog.
That way we create that just explains, again, reminds everyone of what all these things do. Um, but we also have the vsan witness also is another one that you can split out. Um, and when you do your cluster setup and you're setting up a storage cluster, you'll want to, um, you'll need to set this up.
Uh, so use the split networking. It's just a single slider that will then prompt you, uh, if you've already assigned those zoom kernel ports. Um, do you know if there's other settings here like already MA support and at rest encryption you'd set up at the same time?
So from an architecture, what this looks like, um, these storage clusters, we've got the traditional HTI, this is great, but people may not want to do this for many reasons. Sometimes it may just be personal beliefs. They really like having separate storage.
We have data source sharing, um, that we released back with, I think it was seven update two to where you can basically borrow capacity between clusters if you have some stranded computer storage. And then we also have fully disaggregated storage. And this allows you to have discreet compute clusters and build out those storage clusters.
And some people may want to go really big with this. I see people create multi petabyte storage clusters. Sometimes they just wanna have an eight node cluster and they just wanna run three nodes here, five nodes here, six nodes here for compute.
They split that out. Um, it really is up to the customer in terms of their needs, their applications, their workloads. Um, it is worth noting that with VCF, the customers are entitled to one, uh, tibby byte raw, uh, per VCF entitlement.
So, you know, if a customer has a thousand cores, they have one petabyte of VSAN ns. There's for a customer who maybe is transitioning this new licensing, they may suddenly discover they have a lot of vsan. This is an opportunity maybe where they just go build out a storage cluster and take care of that storage, um, refresh need that they currently have while their existing compute clusters.
Maybe they're blades, maybe they're still depreciating them, maybe they just have enough compute, um, they can go run that as they see fit. I did want to talk a little bit about data protection. Um, so we have a new, um, vs n to vsan N replication capability.
This is something that's been asked about for a while. We initially launched a vs n data protection capability in the eight train. And this was a built-in snapshot and snapshot retention engine.
Um, but as everyone has always said about backups since the beginning of time, um, it's great that you have a copy of that data, but unless that copy is copied somewhere else, a snapshot it by itself is not a backup. Um, it's definitely been a hill that many people, um, wanna stick to. So going through these capabilities, we've extended the vs a n data protection, um, which is included in the base vsan n that's definitely there.
You can create those, uh, GFS schedules, you can create those snapshot retentions. You can set immutability on those. But we now have the ability to combine this with the VMware live recovery add-on and VMware live recovery for those following along at home is, um, it incorporates, incorporates the product formally known as site recovery manager.
We can now replicate those VMs. And so we can set that replication interval. We can get a, uh, a one minute, uh, recovery point objective.
And we can keep not only, you know, a set of, um, you know, GFS on the source side. We can also keep an an X number of snapshots on the target side and that capability. And we can also set protection groups.
Um, and so we can auto automatically create these groups based on things like VM names. So like kind of everything with prod and the title, get a specific policy or everything with finance or hr, get a specific policy. Um, but this allows us to, to do replication, um, and do disaster recovery.
And then using the other capabilities of live recovery, the orchestration capabilities, the, the runtime, the testing capabilities, um, we can bring this up. And so this also is helping give us some additional protection, not only from traditional disasters, but also things like ransomwares. Remember that additional cluster replicating to that can be in a separate SSO to remain separate authentication environment and and so forth.
To help simplify this deployment, the OVA that's used for VS N data protection that's used for V four replication. And that is used for, uh, VMware live recovery. That's actually all one appliance.
Now. We've, we've de-duped the appliance, so to speak, to where you now have one appliance that is serving those multiple functions. Okay, so you answered a question I had John, which was, would this replace the v replication appliance that V-L-R-S-R-M customers know and love in the past when they needed to replicate data between vs a n data stores?
And the answer is kind of 'cause it's on the same appliance, but it's different functionality. Is that right? Yeah, it's a different functionality.
So in order to, uh, have those scheduled snaps retained on the other side and using the vsan, we are gonna require that license and that capability. But for just basic replication that it's still the same OVA, um, and when you log into it, uh, and, you know, 54 80, you'll actually, or the admin portal, you'll see basically that it, it does call out that those three services are basically set up there. Um, but the goal also is if you are going and creating a workflow, um, you can go through, and I apologize, I don't have a demo for this.
I was just getting this up in my lab last week. Um, but when you're creating the, you're setting up this workflow and you create the, the snapshots and then you say, oh, by the way, also we're replicated and keep this number of replicas, it can also go ahead and pre-populate that into that live recovery console. Um, so that way it's ready for your run books and those capabilities are there.
And I, I will say, again, apologies not having a a UI demo here. The UI is really well thought on this and it, it shows that there's, there's really trying to simplify these workflows and make it easy to protect things and those capabilities. And what I expect some customers to do is combine some things here, um, potentially using the vsan, um, uh, storage clusters and maybe create like a giant, you know, just storage, um, uh, disaster recovery target in a central location and then maybe fan and, uh, um, replicates from multiple environments in.
We're also just improving, uh, some of the capabilities across this. Um, in terms of, we now have, within VCF, there is stretch cluster support, uh, for running stretch clusters on top of VCN stretch clusters. Uh, we also have a new capability to do site-based maintenance mode.
So you can basically put an entire site into maintenance mode. This has come up, um, I get this a lot from European customers just 'cause there's so much stretch cluster activity. They may have a site that they want to extend maintenance and proactively handle that.
Um, a third improvement that's come up is, well, we have stretch clusters and those automatically fail over 'cause the witness site manages that quorum. Uh, we have some customers who are concerned about a, a kind of a, a an outer scenario where the witness site fails and then one of the site fails. Historically, we would, uh, demote the surviving site because split brain protection kicks in.
Um, people want to be able to do a forced recovery takeover. And that is something we actually are now going to extend in. So again, uh, stretch cluster capabilities.
This is a true synchronous active active, those virtual machines run on both sides. Uh, they're being replicated, um, in terms of those workflows, in, in terms of those capabilities, um, those virtual machines. And you can select a subset of VMs to replicate and do kind of an asynchronous if you wish.
Um, but we, we are now giving you the ability to basically put one of these sites completely into maintenance mode and initiate that. Um, and so from we've got these fault, uh, domains, we can, uh, select one of these that we want to put into maintenance that will initiate a proactive evacuation. So DRS will initiate, uh, the motions off of that.
And then all of this hosts can go into maintenance. There's different reasons. A lot of this is physical maintenance.
People are maybe doing power or other infrastructure maintenance or maybe they're mi migrating one of those two sites or things like that. Um, we do have a lot of pre-checks that, so we will, we'll basically tell you anytime you're putting hosts in a maintenance mode or you're putting assigned to maintenance mode, we'll tell you what the impact will be. How much data, uh, potentially has to move.
If there were, um, if that that action's happening, and this is available also by API, so that can be, uh, fired off. If a customer wants to use that as a way of testing their DR plan, is that an acceptable use case for that or would you recommend a different kind of workflow? So that is that, that will, because you know, that will basically limit you to running everything from one side.
And that makes sure there's a healthy copy of data on the other side. Um, I mean a true DR plan, at the end of the day, some people really are just gonna want to, you know, throw the breaker to the PDU on one side. Um, and I respect that some people will just wanna say, okay, we don't actually wanna product.
'cause that will trigger that triggers an HA event. Um, yeah, this is, this is definitely a way to do that is do that proactive evacuation and of emotional work and then you'll test your applications and that'll give you awareness. If there's something wrong with networking, maybe someone forgot a VLAN or BGP ISS not pure on the other side or things like that.
And that's the nice thing about a true active active, you know, you can, you can do that. You're not having to initiate a failover. Those da that data store's globally available on all sites.
Um, the other thing also is this exception case where you have a site failure where the witness fails and then a site failures. Um, we basically have the ability to go initiate that, that takeover, um, and it, it will run pre-check, it will update the metadata object hierarchy and, and basically crowbar the quorum system to do that. That is a manual intervention.
Um, just because again, we don't want a scenario we're, you know, because of perceived outages from network inconsistently. Um, we don't want to challenge cap theorem to a dual and end up with both sides active, active. Um, but this is something that we, um, support and what customers have asked the for this.
Um, generally this is a pretty extreme scenario. Um, and this isn't something I normally see happen, but it's one of those tabletop exercises we wanna make sure people feel covered in. Um, VCF does have the ability.
Now also, as I said earlier, we have the ability now to support not only vsan, um, stretch clusters for storage clusters, but also be able to present those out. And so we can have these, uh, stretch clusters that are providing act, basically acting as a stretch storage platform that then can provide that to stretch compute clusters. And we will have full ha working and site aware and we will optimally, um, route that data so we don't end up doing a lua pathing on the enter site link between the sites.
Um, uh, this is something that is always been a real benefit of vsan is, uh, stretch clustering and metros type capabilities has always been really complicated. Um, and, and, and not to throw shade, you know, it's just, it is complicated historically, but VS. NS made it really easy to configure and it's just baked into the licensing.
There's not additional licensing. Uh, you don't have to use things like FCIP gateways. Um, you, you also get to, you know, you from a quorum device, you've just got a single witness VM that you, you can stand up that's really easy to deploy and it scales down and up.
You can build a two node stretch cluster, um, you know, you can also build a giant stretch cluster. So it's, it's a system that's really scalable and it's, it's interesting, um, just how much adoption on stretch cluster we have. It's, it's very broadly deployed.
Um, very cost effective, easy to do. And remember, you can do rate and by default you will, you'll do raid within a site. So you can do that raid five, raid six protection within a site, and then mirror between from a data protection standpoint.
So I wanted to level set. So we've talked about the capabilities, but I also just wanna talk a little bit about where we are at in the year 2025 on storage and the ecosystem and what vsan looks like. So the drives that we're certifying today are T-L-C-N-V-M-E drives, and we do support the read intensive drives.
So these are drives with one drive right per day. Um, the street price I'm seeing on these drives is about 18 cents. If you're buying from a server OEM who has some margin and markup, I'm generally seeing in the low twenties, and this is again before deduplication and compression and unap and thin provisioning and things like that.
Um, so NVME, you know, I know some customers were, were kind of confused when we made Visa. N-E-S-A-N-V-M-E only the drives actually don't really cost more than SaaS drives. And when you remove the need for a RAID controller or an HBA, um, NVME effectively is, you know, the same price or cheaper in many cases at this point from a density basis.
I'd also encourage you to go look at some of these new hardware form factors. Um, we're seeing one U pizza boxes with 20 drives supported. Um, there's even some out there are now starting to come out with more drive slots.
So if you start looking at 16 terabyte drives and you start putting 20 of these in a host, you know, you're 256 terabytes raw, 40 DUP and compression stack 30 hosts in a cluster, you know, that's seven point something petabytes raw before data reduction. The amount of scale that we can get into a host is incredible. Um, and I remind everyone to go look at form factors.
5 inch drives for the past 10 years and they want to keep buying those. Uh, we do have these new form factors, um, that are fun and they are supported. And this is how you get 20 of these drives in a one U pizza box.
Um, and the density on these drives is, is pretty incredible in terms of capability. So, you know, I've had customers say that HDI, well, it doesn't scale to my needs. If you can put, you know, again before data reduction over seven petabytes in rack, you can, that's, that's quite a lot of storage.
In fact, some people are starting to become uncomfortable with just the density, you know, from a blast soon, uh, of, of where all this does. But from a cost basis. Um, you know, if costs, if the, if customer already has VCF and you view it as a sunk cost, your effective cost, you're getting, you know, very, very low.
Um, this isn't something that I, um, I I view as, you know, a, a, a weak area or a concern, um, in regards to that. I think we're gonna be really for, for existing VMware customers who invest in the ecosystem, we're gonna be really one of the lowest cost storage options. And that's just what the drive choice is today.
So I just want to end on a note here of reminding everybody that vsan is the built-in storage option that comes with VMware Cloud Foundation. And really we're expecting to see a lot of adoption. We're excited about where this is going, and encourage you to check out all the other videos as part of the VCF nine series.
Thank you. Thanks John. Just further integration together in the package.
I think that's one of the things we're seeing across all of the VCF nine release is a consolidation of tooling and simplification of access to the things that you need to get your job done. Of course, it's all very well getting your job done, but if the environment isn't properly secured, you're probably gonna have some nasty things that are clean up and, uh, maybe find yourself in the newspaper as well. So to help you avoid being in the newspapers, uh, here's Bob Planker, a longtime tick field day friend and, and delegate at my very first event.
Hello, good afternoon. My name is Gary Thornhill. I'm the, uh, founder and CEO of Popup Mainframe.
And today we'll be, uh, introducing popup mainframe and then giving you a demo of the latest and greatest. So lemme just make a start. The mainframe market is several thousand large successful organizations and institutions across the globe.
The mainframe appeal is universal and prevalent across many sectors. This includes financial services, insurance, retail, logistics, government and transportation. What these sectors and organizations have in common is that it infrastructure is some of the busiest processing billions of transactions as a primary instrument of the global economy.
These are systems to critical to fail, too important to use commodity technology. They rely on the IBM mainframe because of its credentials of being the most powerful resilient machine available on the market. And that's never been truer since the release of the, the Z 17 with all its AI capability and new processes.
Yet mainframe change can be highly challenging still for organizations today. We commissioned an independent survey earlier this year from a market research agency called Vanson Bourne. And the market came up with these results and I'm sure some of these hard truths of the mainframe world will resonate with you and your own experience.
Nearly all respondents experience challenges in Devon test when using the mainframe. Nine outta 10 had concerns around the availability of main mainframe environments, and a third said it required four or more teams to get mainframe deliveries done. And eight out of 10 of those respondents think that staffing and tooling is limiting and hindering the business.
It's evident all organizations have challenges. Availability is an issue, and siloed organizations are very much a problem in the world of mainframe and tooling and skills are getting in the way despite there being exactly the same tools available for the mainframe. It's just just difficult for those to be used.
Um, and, uh, we'll highlight today how that can be addressed anyway. This is not a positive situation for many decision makers. There's too many bottlenecks and this is getting in the way of, um, organizations delivering.
So what is the solution to that? Well, here at Popup Mainframe, we think that provisioning a popup mainframe is the way forward. You can relieve these bottlenecks without having to invest in new tin by installing popup mainframe on adjacent Linux platforms.
And this can be Linux on z LinuxONE, um, on-prem X 86, and we can run popup mainframe in any cloud server. And now with our fast track capability, which I'll talk about in a while, we can combine them and you can move between those different environments based on your use case and need. 'cause you can, you, you can use a, uh, floating license model.
So you only need to to have, um, as many licenses in use if you've got, as you've got mainframes up. So what this means is you can have other mainframes, um, that are actually dormant and down and you can use 'em for use cases later on and, and use them on an and a need to need basis. So ju just to just to, I know you're gonna get into it, but just Sure to, to set the stage Yeah.
Set the stage, um, that, that middle option pretty obvious mm-hmm. Mm-hmm. Emulator on X 86, et cetera, et cetera.
Right. Roughly speaking, um, I don't wanna put words in your mouth. The left and the right.
Mm-hmm. Okay. Um, I understand the right, yes, I don, I'm, I I think that I would like you to distinguish between the right and the, the left there or for a Sure.
For a both mainframe and let's say a mainframe interested audience. Yeah, for sure. So, um, I'm gonna start with the right Linux on Z.
So, um, an IFL 'cause not everybody knows. Yeah. An IFL is, um, an integrated Linux facility.
Um, and that is, uh, a specific processor that runs on the, uh, on the mainframe itself. It's IBM facilities. IBM language for processor.
Yes. Yes. It's a, it's a, it's a, it's a processor, um, that is not a general processor for running, um, z workload or um, say Z workload, but, um, an actual regular LAR.
So, um, on the IFL you're running effectively the same chip, but it's, it's, it's adjusted for Linux workloads and it's, it is completely isolated from the general processes. So you can run the run popup mainframe on that. So while it's, it can reside on the same physical machine, it's completely separating.
Doesn't use any of the resources that that chip uses for production workload or regular Devon test. So that's, That's a Z system with this Linux capability. Yes.
Now the left. Yeah. And so then popup mainframe, you'd be running virtualized mainframe on, on the IFL next door.
Now LinuxONE you can run exactly the same, um, operating system could be, um, Z Linux, KVM, whatever. And you can run those Linux operating systems on a Linux one so you can run, so Linux one is a, is a different hardware. Um, and you would, you can, you would run popup mainframe exactly the same way on Linux one as you would on Linux one Z.
So Feel free that covers it. Yeah. So my take on this, yeah, please correct me if I'm wrong, including you Steven.
Um, please. Um, is that, um, your customers have a lot of different environments that they use. Most of them are using X 86, but that's almost practically a different team.
Um, but they're also, they may be using z they can use, they, they may have Apple systems, they may not, they may have Lin Linux one systems, they may not. So you popup is, um, doing the, the, the tricky technical engineering. So they have choice and don't have to move into some kind of new box or hardware Correct.
In order to take advantage Of it. And that's exactly right. So we don't, you know, if you wanna stand up a popup mainframe environment quickly, you don't wanna have to get in the business of procuring hardware.
Yeah. What can you use? You've already got to get it up and running.
So that's, so now we, before we just had it on X 86, now we've got it on that left and right option. Carried. The way I would see that, and maybe to pile onto guys' question is optionality, yes.
If you've got X 86 kitten, you as a mainframe team are comfortable with doing dev test on X 86 popups got you covered. If you're a mainframe team and you're not comfortable with X 86 popups got you covered, you can run that on as your mainframe box with an IFL or if you've got a Linux one box in your environment, you can run it there. The way I take that away is, and am I thinking about, and I'm getting to a question, am I thinking about that as optionality and you'll meet them wherever they are from a hardware point of view, there's no restriction.
Is is that the way am I hearing about it? Right? That's exactly, that's exactly correct, Steven.
I mean it's, it's just that some organizations and we've seen this, do not want to have any mainframe running on X 86 at all. They want it, they want it on, uh, something like Linux on Z, which is the same as running the same hardware and under control of the same team. So that, that's right.
We've got options, and I don't wanna spoil it for everyone, but we can talk about moving between those environments later with our technology so that perhaps you've got, um, an lpar like a production like LPAR on a, on a Linux on Z for example, and then you can push that to the cloud and you could provide that environment to, um, incumbent, um, uh, outsourcers or someone running A POC and you've got that flexibility. Well, I did give the game away now, so you you you took it outta me. But anyway, I I have, I have another question for you.
Yes, Yes. Steven, maybe you're gonna get to this, but Yeah, Steven, that's 'cause there's multiple, you Could just say that to any of us. Yeah, I'll just Say that.
So now that popup has been, you know, so, so you're not new new anymore. You've got customers, you've got, you know, you're out there doing this. Um, are people coming to you more for the flexibility, more for the application development lifecycle, more for the, I guess, hardware savings or to run it on cloud?
I mean, what is the, what is the, the real customer demand that you're starting to see? Because this product can do a few different things. Yeah, that's right.
And you know, there's, there's so many use cases you can do with this. I think fundamentally, um, most of our customers are wanting popup 'cause there's a shortage of environments and they're just, and and it could be for multiple reasons. It could be contractually, um, they could be doing a data center move or they just want to have the full, what's in a popup included outta the box.
That is, because we can install it in less than 10 minutes, all of that's available to start new things without the, I dunno, the overhead of trying to work on the existing lpar, which could be, you know, you wouldn't, you might not have the, the, the MSU is available to do the work you want. So popup is the answer. Um, If, if you look at it the other way.
Okay. Yeah. So if, if Steve came to me and said, mark, I need a test LPA to do some development and test it myself as the techie have to go and make hardware configuration changes, clone the operating system, restore it all, configure it, get it up and running, that's four to five days work.
Yeah. If you're gonna do it on real Yeah. Z processor.
Yeah. This stuff gives you, as Gary said, 10 minutes. Well That's, that's how I saw it.
So last year when we talked about this, I was seeing it sort of analogous to like a docker container or something like that. Like, oh, I need a web server, I could build it or I could just, you know, Docker composed, bam. Now I got a web server and it sounds like this is exactly the same thing except for the mainframe.
Yeah. I mean, and we can, we can run these in containers. You can run 'em so many different ways now, particularly as, as we move across onto the Z environment, which actually gives us greater flexibility.
Um, but um, anyway, let me, let me continue on. Um, and just to be clear, one thing, so the license restricts from running any production workload. It's just dev test only.
Um, and uh, you know, that's, that's important. I can hear IBM in the back of my ear just asking me to say that to everybody. Yes.
But let me, so so is it, just to be really clear, is it a license that restricts for dev test or, or restricts out of production because, um, I mean I can't, it's hard for me to imagine someone doing, say QA two anywhere but in a very similar production environment. But QA one, they might want to. Yeah, exactly.
Yeah. So as long as you're not, as long as you're not running production workload, but we've got many different, um, partners, um, and consultancies taking popups now and they could just be doing, uh, you know, pre-work before they take it to their clients. Yeah.
Just I just Developing their own products. But yeah, you, nothing stops running ut On dev test and feel like that, that that's the restriction. It's More not at all.
Not production. Not production. Exactly.
Right. So you could be doing production fix for example. It's just, yeah.
And it's a really, that's a really good use case. Yeah. To do product production fix.
'cause you can match a pop-up to any LPAR PTF and you've got that film flexibility. So that is a great use case. Um, anyway, so we've designed popup mainframe to ensure it's compatible and therefore credible as a solution.
Um, data compliance is a really important part of our offering and, um, we, we, we can talk about how we can use advanced masking technology to help bring that compliant data in and now we can ensure that data never leaves z And we've got a couple of of ways architecturally how we, how we do that, how we do the masking and provision downstream environments, um, key. We integrate with all of the existing mainframe environments and tools. Um, we also have the added advantage that we have, um, the I-B-M-B-M-C along with third party and open source tools already pre-installed and pre-configured.
So when you install that popup, you've got all that other software available that you can use straight out the box and start doing work with. Um, and I think that's, that's a huge advantage of, of the product. So yeah, just just to reiterate, we're compatible with anything zero s that organizations are running and we've got all sorts of weird and wondrous things, um, running in, uh, strange Legacy Bespoke Co.
We've got it all working on a popup. So that's, that's a really important, um, point to make and all form, you know, some, some of the older ca databases, IDMS and Alibabas as well, we can run those so it doesn't hold anything back at all. Um, and we're delighted with, uh, what we're seeing with our clients.
Um, this is just a, a short summary. We can use their existing environments to accelerate dev tests and protect those production mips. Um, we can flexibly initiate, um, dev test training, um, training environments at any time.
Um, and uh, that, that is really important, um, to start any form of r and d projects. And we have an existing client that have managed to quadruple their mainframe, uh, delivery velocity, um, and just through efficient resource usage and, um, as well as ensuring that for the first time they can get proper compliant data into, into their test environments. Um, importantly and increasingly to all CIOs, popup improves, uh, sustainability reduces emissions and power usage because you can unplug unused environments and we've actually got automation built in.
So if you don't use it for two hours, because a flag, obviously it will switch itself off in a clean fashion. So you can just start it back up again as and when you need to. Sorry, Just go back Sure.
On those. What do you think, like of your customers, what's the top three, um, things that your customers are using? Yeah, that's What I was curious about too.
Uh, Yeah, I mean definitely, um, probably the top three. Um, it's just if you having run, um, uh, mainframe delivery teams myself, um, you know, you might wait a week to get a DB two change made in a, in a, in a set environment because that might be done by another outsourcer. Um, and it's on a queue.
There might not be any, um, uh, there might not be an SOW available, so it has to be signed up before that, that DB two environment is, is created and the dev teams just stop or do something else. It's things like that. Um, so putting it, yeah, giving it in the hands of the developer that this can be done themselves and not relying, I mean it still will go to a formal environment, but so much can be driven out in the earlier stages of development and testing.
So Mostly an open source person. So, okay. Let me ask you a Big, we love open source.
We do loads of that. Okay. So like basic baby question.
Mm-hmm. If, well, open systems is what I meant to say. So baby, baby question, if, if, if you get your dev team, uh, popup mainframe and they're able to start working on something while you're waiting for all of the business side stuff to be checked off, you know, t's crossed i's dotted, what happens to, uh, the data that, that are the things that they develop?
Do they have to then replicate those in, in the environment or the data? Are they able to transfer what they've done? Yes, that's right.
Well, that's right. So we have, um, and I I think that's, I might move on to the next slide to answer that question. That a pretty good diagram with that.
Here's, here's some, uh, foundational, um, architectural elements. So, um, we work with this, we work with this concept, um, of a gold copy that acts as the master instance that you can see there. And so we have, we've developed our own IP and approach to move, uh, data and config across to the gold copy.
Um, so that the environment that they're familiar with is replicated onto a, into a popup. Um, and I'll, I'll get into the masking of the data in a while, but once we've, once we've created that gold copy and that obviously, um, you know, we might, we might approach it and we might be 90% working and then we can just toggle it, refine it, go back, look at the physical system, maybe make a tweak. Um, but once we've established that and, and it's been tested out, then we can push that goal copy, um, to other instances for whatever use cases you want.
So when you've got one, you can then have as many as you like. And it literally takes, so, um, on the IFL, we can create a copy of, you know, two or three terabyte gold copy, and then it's another virtual machine in five minutes for another use case. So that is, you know, pretty powerful once, once you've invested in the first one.
And some organizations know their environments better than others, but, um, we have experts to really unpick that and get it, get it established. So there's No additional configuration when you take it from a Z 17 to something else? No.
Um, for, well it's the, the most important thing is, is the version of ZOS. 5, then we would provide the same version of Z os on the popup. Okay.
And then which case of moving over? Um, probably load libraries and, um, and doing some, doing some binds and things like that. Kicks.
Kicks. So The hard the hardware then has to be the same then, right? Um, well, I mean, this is hardware emulation, so, um, there are, there, there are certain, um, parts of the, depends on the load library, but that all the hardware is, is emulated onto, um, using the underlying IBM technology Okay.
To establish on the popup. So it doesn't, it doesn't really matter. It's less about Z 15 16 17.
It's more about the, the level of ZOS because I was thinking, you know, you have the Z 17 in the office and then you create a home lab just for testing environment. Um, and of course you don't have a Z 17 at home, so No, most people don't. May may, maybe Ross Murray has if he's fortunate enough.
Yeah, yeah. No, but, um, yeah, that, that's the, that's the idea. We're not, um, it's about getting, um, you know, providing production production-like environments to, to test early.
But I think as I get through the presentation, more and more will will be revealed. Um, what I was gonna say here, and the other thing that we can do is we can install any SCM onto the popup. So you could just use it as a node and then, and move virtual popups your, into your end-to-end SDLC and promote members up to say UAT, um, and then do testing back on the physical mainframe.
So there's, there's lots of different ways of, of, of how you would use popups end-to-end. And you might just use them individually for, say, testing new functions of DB two, once you've created your goal copy with a full application on, it's an ideal opportunity to try and, um, use those versions of DB two that you might never get to do on a regular physical environment. So, so, So to pull on that a little bit that, 'cause that was gonna be my question.
Yeah. You, you're fitting within, um, a software development lifecycle manager that, that, uh, that a customer might be using with these features so that they can, they can, you know, manage that gold copy and it's, It's deployment and implementation within their SDLC? Yes.
Um, again, it depends on, we're trying to, we can understand how the client's working today. There could be a, some of them might want to work exactly the same way they did before and just create pop over as an lpar, but we're trying to encourage them to work new ways and just, I'm just gonna use the bottom end of this, this slide here to show that. So, uh, with popups you can get regular refreshes of data, um, into the popup goal copy, and then you can push those copies down to, to different environments.
So it's up to them if they want to take those refreshers or not. Mm-hmm. So that could be a new way of, of working.
Um, but uh, with this fast track facility that we've developed, and, uh, this allows us to refresh popup instances, but it also allows us to create multiple snapshots of different popups. And that could be on different versions of code, different versions of subsystems. Looks like I've got a question mark.
No. So I, I, and this is the bit that got me the last time because to try and do this in a real mainframe environment mm-hmm. It's, it's, it's now impossible because the amount of, the amount of hoops you would have to go through to make sure you've got a backup of the data and then restore it.
And what I liked about this, you might have a 12 hour testing window and you get four hours into it and it breaks and you think, oh, so you can roll it back to the last snapshot, do the little fix that you've gotta do, then roll it forward another eight hours, break something else, roll that back a couple of hours, or go through the whole thing and it works, and then quickly reset it and then do it again to do that on, in the real mainframe space, because this is obviously em emulated disc onto the covers. This is so much more efficient. Yeah.
And with the Z it's going five times faster than the X products as well on the, on the IFL. Um, but, and, and just to add to that, we, we are showing this today, but, So Gary, I'm gonna, okay. 'cause you said something really fascinating, but you went quickly.
Yeah. And I think it's worthwhile capturing. So you mentioned you've now ported popup to the IFL.
Yes. You said is it fast five times faster? That fast, faster.
So It's on average five times faster. Some of it's 10 times faster. It's all about where the disc IO is because as you know, with, with with on Z, the CPU is not emulated, goes straight to the chip and, but the disc is still emulated.
So depending the balance between IO and CPU, but on average we're seeing five times average performance. So The advantage isn't just mainframe team, you don't have to deal with X 86, you can stay dealing with said mm-hmm. That's one advantage.
The other advantage is it'll run five times faster than running on IFL. Yeah. So you've got optionality, you can run it on X 86, but there is an advantage to run it on the I ffl It is.
And really we didn't have any complaints from, from, uh, clients around performance, but it, it would just allow us to, um, it to be more efficient. So sometimes you need a multiple, you need to multiple to license multiple CPUs. So it is a more cost efficient option, but you are running it on obviously slightly more expensive hardware than some of the eight x 86.
It's more, it's more expensive hardware and Steve's be more knowledgeable about, you know, if you, if you, if you have normal processes. Yeah, yeah. We cap 'em.
So I'll use a car analogy. I've got, I've got four general purpose engines at a thousand cc, but the actual processes could probably go up to 5,000. Yeah.
Ifls are full stack, so you get the whole thing no matter if the other ones are capped, you get the full stack of the IFL. So you get the full power of the IFL when you do the math, it's not that expensive. No, no, no.
I agree. These shops may have spare IFL capacities hanging around anyway. Yeah, you, your, I'd imagine the footprint of this is pretty small and an IFL as you say is pretty big.
Yeah. They're tall. This, this system, the, the, the wider point is you're probably not having to buy FLS to run popup.
You're probably able to operate on the ifls you've already got. Yeah, No, that, that's, that's what we're hoping a Really point. And this, and this is where this, this capability that we're talking about now on the IFL to me is a complete game changer for how, uh, environments are managed in dev and test.
Yeah. It's always, it's a little DevOpsy to be honest, like very DevOps, you know, like, but absolutely. But without having to use Silicon Valley lingo, which really appeals Oh, my famous don't like that very much.
Yeah, well, I, I, I'm, I'm with them on that. Yeah, that's wonderful. Yeah.
But, um, and the great thing is, so we, we've talked about the benefits of the IFL and I'm running, running it. So we could, um, we could, uh, build a gold copy in a secure zone on the IFL master data there, and then we could push out copies, exact same copies to, um, cloud systems if we wanted. And that, and that could be to partners, you don't wanna have access to your mainframe.
They could be testing out POC. So you start getting, you start getting all the benefits, but control as well. Um, in fact, I'm gonna go back to that slide in a minute, uh, just, just to show it here.
So this is what we're talking about. So we could, you could run whole full dev test environments on, on the IFL, have that capability with Fast Track being able to rewind checkpoint branch, um, publish out, um, and create copies. Um, and then some of those could be in the cloud if you wanted, and you wouldn't have to do anything to them to run them there.
So I, I, you know, I think that shows great flexibility based on use case. And you know, if you've got some you want, you want something in Azure, then you can have it. Um, if you need the power in, in the, on the rfl, you, you've got that.
But let me skip back. Yeah, sorry. Just because It's kind of open the door since we're talking about putting these, um, these snapshots every place.
Um, are you gonna talk about security and like how these are secured? And if they're secured, We don't go too much into that because you can just, you've got all of the security that's available you would have on the regular mainframe, and you can as well as you've got full raef security that you would put on. So the application level, and then you've got the full, uh, Linux layer capability of security so you can, you know, there's so, there's so much to the whole security.
Well, we're not trying to address that in this presentation, but, um, But generally, if I put this in the cloud, is it like me having a database that's wide open in the cloud that maybe, no, I'm just not clever enough to, to change the password. That's a, is there, Well, you would have, you would, you could use cloud level securities to access to the servers. You've got that level, you've got the security of the, of the Azure V say for the zero or AWS virtual machine, and then you've all the regular zero OS, um, securities, it's exactly the same emulated, it's just emulated as well.
So you've actually got multi-layers of security that you can, you can implement and with whatever, you know, authentication. So I'm not an expert at security, but I know is anything, whatever an organization is, is how they're working today, they can reproduce that onto the popup in multiple ways. Yeah.
The most, the most important thing though is masking the application data, masking the business data. 'cause all the other controls we've got there, multifactor authentication or all that kind of stuff, that's you just out the box. But the fact that they mask the data, that's the, that's the good part.
Even if you get Access to it. Yeah, if you could get, yeah, if you could get access to it and the chances getting access to it through all those layers, you know, you, you, So the chances are that it's locked down when you emulate it. Yeah.
Okay. So, so When the snapshot is em emulated, it's not, it's, is it like an is ISO or is it like a It's using, it's using ZFS under the covers. So it's using, um, read The, The Z file system in, in American English.
Okay. Yeah. It's using, it's using read write technology.
And the good thing is is that it's just measuring the, it's just using pointers to the changes. So the downstream copies here, the three on the side, they've actually worked with 90% compression. So you've, you're not using dsd, you're using commodity disc and that's 90% compressed.
Okay. As well. So if you've got a terabyte footprint of the gold copy instance, then These Popups call them that they're a hundred Gig.
So you get, you get huge amounts of Pointing what he said around DDIs, what mainframe is called direct thrust storage device equals expensive bit of storage. Yeah. Yeah.
It's much better than it used to be, but still versus Of magnitude more expensive than your NetApp filer would be. I was trying to figure out if it was going, if it did sector by sector, uh, copy or if it does, like It just made Anything like third party, uh, programs get loaded on after the fact Or No, they're, they're just already there. It snapshots the whole image Okay.
Of everything. And I'll, I'll show you that. Okay.
Like a be snapshot. So just let me, let me quickly introduce to you just the Concept for the mainframe, The, um, delivery pipeline we'll be using today. This is just an example of how we set up a popup to support a modern mainframe delivery environment.
Um, this is a modern mainframe delivery, um, DevOps setup. And it's using new tools like VS code I-B-M-I-D-Z and open source, including GSA and Coble check for using test automation. Um, if we zoom into the build and test part of the lifecycle, and just to reiterate, this is just one example, um, we can plug in whatever clients are already using.
So whatever they're using in the enterprise is much better to reuse it. So it's, but this is just one example. Obviously we have to go with something, but it's very flexible how you can move between different technologies.
But this is what we're gonna show you in the demo. Oh, cool. And any tools can be swapped in at any stage.
Cool. Oh good. Yeah, we don't, we don't.
It's just Reinforcement, not a question. Good, good. We don't insist on you use this or that apart from just using a popup.
Okay. Gary, you mentioned IBM and BMC. Yes.
There's Rocket and there's Broadcom. Yes. Are they supported as well?
Completely. Um, everyone, everyone's supported. Um, I'm using Endeavor as a source code management.
That's, I can use that. Yeah. We've got clients, we've got Endeavor installed on the popup.
No issue in multiple, multiple clients. It's just what we have here is pre-installed and ready to go. So there's options.
Trying to have every combination would be very difficult. Oh, So that's a good point. So IBM and BMC and some open source or pre-installed, yes, I've got the flexibility to use Rocket and Broadcom, but it's not pre-installed.
It's not just pre-installed, otherwise it's just trying to, trying to keep up because we are releasing popups and up updates, just trying to update and release all that software. We'd be quite a big overhead. So we, we've, we've gone with two, um, I'm sure we're doing more as we grow and, and, um, more successful with our clients.
But, um, you can run anything on there, but we, we have those two choices. Um, just in case main framers are scared of DevOps pipelines, um, there's still loads of value, um, using a popup just to have a clean environment, um, to test against. And one of the most obvious use cases is to provision a pop-up.
So upstream systems can test against the mainframe quite often, um, upstream applications on different platforms, they're struggling to find a, a mainframe environment to test against. So this is a key, key use case Can be expensive and uh, and it can take a while to get the, uh, mainframe team up, up to Gively. Yes.
Reassuringly expensive indeed. Yep. And, uh, just to go back to, I think we've covered data, um, compliance a bit.
So again, to help our clients, we've got a pre-installed offering now, data vantage, this has been around, uh, since the late seventies. And um, it makes it very easy to use ISPF to do, um, data compliance and, and do that masking. So if clients need to test things out and are worried about, um, uh, their data being insecure, then we can mask it for them, um, very quickly using this technology.
Of course you can use others, but this is just on a pre-installed as well. Um, So you are partnering with somebody for a data masking capability? Yes, that's right.
Um, we've got existing partnerships as well, but this is just one that, this goes in with our whole keep everything on Z. So if the masking software's on z, um, running on pop-up, which is also running on a IFL on Z, then ni then, then no data doesn't ever leave the mainframe. And that's very important to tier ones that, um, data, data.
They shall never leave the ma leave the mainframe. So we are meeting them by working this way. Um, just to quickly, um, uh, summarize, uh, the two versions we have available, um, we renamed our original product exhibition, uh, running on X 86 on my sleeve there, and we've got Z on the other side over here.
Um, So what are you, the top upon that said is new Yes. Since you were here last time, what are you seeing as that reaction? Has that unlocked demand for you guys?
Um, it, it very much does. So because, um, before, um, when we presented, uh, to some big banks, they loved the product, they loved the flexibility and what the product did. But some of the, the, the larger mainframe teams I think saw running, uh, mainframe into the cloud as an existential threat.
And so maybe put off, but where if it's actually running on the, on the mainframe then, and they, they see that as a more secure option. Their, their SecOps teams, um, mandate that data shouldn't go to the cloud, for example. So it solves that problem.