Techstrong TV September 17, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Have you heard about the new Spielberg movie? Saving csa? You're watching Textron Gag.
Hey, everyone. Welcome. Happy Wednesday, man.
It's, you know what Wednesday is right? It's a hump pump pump day. These weeks are going so fast, though it doesn't, it seems to be a little more than a speed bump than a hump.
But happy Wednesday to you. We've got a great lineup, great stuff to talk about today. Let's jump right into it.
Um, let me introduce you to our, our speakers for today, our gang members for today. First of all, sporting a nice city view that, that looks new. Yorky to me.
Um, it's good to be home. He's, uh, Futurum, COO, Dan O'Brien. Hey, Dan.
Good to have you here. Hey, Alan. Good to be here.
Absolutely. Joining. Dan is Kate Scarsella, who we found out is up in the Boston area.
Still got the classic New York, Boston, I think the Yankees of, well, they just played the Red Sox, but Kate, welcome. Thank you. Nice to be here.
And of course, joining us from out in the, my Rocky Mountains, our, uh, futur analyst, Mitch Ashley. Hey, Mitchell. Good day.
Good day. Rocky Mountain. Hi.
Absolutely. Now, it's a little early for that, isn't it? Is it ever?
Okay. Um, anyway, Mitch, let's jump in with you. You know, there was a big to do, a big brewer a couple months ago, whether CAW was gonna be funded.
Of course, they've had some high level departures there. Friends of ours who we knew pretty well. Um, and then the whole thing came up with funding.
CVE. Was Mitre going to get funded? Who's gonna maintain CVE?
Should we maintain CVE? Is it a PRI private company that, or so sort of nonprofit that should maintain, maintain CVE? Well, thesis seems to have found this as its new mission for being that they're gonna save and maintain CVE.
What's the story here? Well, it's a bit of, uh, musical chairs, right? Do we have enough chairs to, for, to find, uh, funding for the CVE or do we need private funding?
Can it still be done by the government? It, it was pretty disruptive when this was announced a few months ago about this is no longer gonna be funded. Uh, we're stepping away from it.
It's gotta be a private thing that the industry takes on. And, and while disruption is never fun, especially something as significant like this, the security industry, it did cause us to kinda re-look at, so what are we gonna do? And is there a better way to do this?
And I think some of the reasons that people thought, should we still be funding it or doing it the way that we're doing CVEs, uh, the common vulnerability definitions and database is how accurate is it? Uh, are we, do we using it the right way in terms of really helping us not only communicate and collaborate on it, but how does it lead to outcomes that help us not only react to, to vulnerabilities, but potentially things that are out in the wild? So, yeah, C has stepped up and said, we're, you know, we're move CVEs into what they're calling the quality area era, excuse me.
Um, where they're focusing, not just communicating and collaboration, but more around accuracy and consistency and, and, um, ensuring trustworthiness in the, in the vulnerability information. I don't know if they're trustworthy, if it was necessarily in question, but that's what they say that they're gonna emphasize. So they put together a plan that they've, uh, set out in a, I guess, a white paper kind of form about strengthening the governance and, and modernizing how the program works and the infrastructure for it, and expanding the community participation, uh, and making sure that, you know, it's maintained, uh, as a vendor neutral kind of oversight.
I don't know that those things, again, were in question necessarily, especially the vendor neutral. I think it was pretty vendor neutral, though. You and I, Alan, we've been in security since, you know, early two thousands.
CVEs themselves have led and spurred, you know, many a startup, including some, um, so it, it, it is an, an engine for, you know, new innovation to be able to use this information as that we take it out to market. So we'll see where this goes next. And, uh, you know, this is a pretty recent thing.
Uh, I, I'm guessing the reaction's gonna be pretty favorable. We just need some consistent, this is gonna happen. It's supported whoever we get behind it.
That's great. Let's move and, and make sure we have this information that we can work from Kate as a security professional, what do you think about this Sort? Well, the, um, I, first of all, from a Mitre perspective, I really had liked that group.
I've always liked that group. I've always respected, um, the techniques and the sub techniques that they had. And so I would get concerned about having to reinvent the wheel.
It doesn't make a lot of sense to me. I don't understand personally, you know, they talk about quantity to quality. And I, while it is so important that right now that we have the right information, and I fear that in this period of transition, that what we can't afford is to have the drop of, of critical information that actually is impacting when I talk about critical, critical infrastructure.
And I worry that oftentimes we are having people who are leading these charges who don't know about cybersecurity, who haven't been around. Like, I mean, I, same here. I've, I've really been doing this since, you know, the early two thousands.
And I continually find people who are jumping into this mix with opinions. And to me, it just continues to look like Groundhogs Day. And if we, there's no building there, there's no like putting, like, we are gonna do this and we are going to move forward as, as we do this with, um, it's almost like a spaghetti strategy.
Like, I'm gonna throw a spaghetti on the wall and whatever sticks we're gonna go towards that I don't feel like we're building. And, and with Mitre, what I saw was that they really looked at the attack methodology and, and how it's happening. And, and I think that that strategy was crucial in helping us understand.
And I'll, I'll just add one more thing that it was in front of, you know, C-level people over and over again. There was a commonality to the attack methodology. And what I would continue to hear is how do we deal with privilege escalation, and how do I deal with lateral movement and how, and, and like, those were the top two that I would continually be asked.
And of course, we understand, we understand that because of the length of time that, that the bad actors are, are able to go undetected and then privilege escalation, which we see over and over again, you know, on gaining access. And I don't, I, I hate that we're messing so much with this personally. I, I do.
So, Absolutely. You know, first of all, consistency in anything this government does is kind of an oxymoron, right? So this is, this is, this is this month's plan.
Yeah, it's true. Next month will be a new plan. Two months ago was a different plan.
But let me, let me take off my journalist hat and put on my security person's hat, right? Because I've been to Mitch, like you said, we've been security people for going on 30 years and CVE, there are a lot of people who have valid concerns. We have too many g*****n CVE numbers.
How can I track 200,000 or 300,000 CVE numbers and, and really try to, you know, fortify my, my infrastructure with it of using that. However, CVEs are a backbone of our security posture, of our security processes, right? Mitchell?
Yes. Startups have been launched around CVE management careers have been made around managing to the CVEs, the Mitre organization, I think was the perfect organization for this. 'cause it was quasi-governmental, right?
You had governmental, um, funding and governmental involvement, but with private as well. And, and they did a heck of a job all these years. Why fix something that's not that broke?
Is it it, and especially fixing something that it in, in that is in and of itself broke, right? When Jen Easterly was shown the door there when our friend Alan Friedman, uh, of SBOs was shown the door there when they purged all of the people at csaw, right? To me, this seems like whoever's left at CSAW is looking for a lifeline.
And the CVE is their lifeline. Hey, we'll be able to get funding. We'll have a reason for being here.
If we say we maintain the CVE database, I am of the opinion that it, this is the perfect opportunity to correct a lot of wrongs and do it right. I would like to see an organization, a not-for-profit organization formed, whether it's under the auspices of the Linux Foundation or Eclipse or Apache or something new altogether that comes out and says, we're gonna do this. Right?
We recognize what some of the issues were around the abundance of CBEs CVEs. You know, there were just too many, but we're gonna do it right. And we're not going to be subject to anyone's beck and call or political whims or, or what have you.
Right? Let's put together a consortium of industry government, and not just the US government. Let's get the EU and some of the other responsible players in here, and let's form a worldwide foundation that manages our common vulnerability database, because it's too important to mess around with.
And until we get to that point, this is all to me, just theatrics. That, that's my point. Yeah, It's a great idea.
I I, I, it's a phenomenal idea. I, you know, So unfortunately, I already have a full-time job, so I, I, I can't be the one doing this. But if any of my security friends are out here watching, we need to do this.
Maybe the, you know what I'm gonna call my friends at RSA conference. This is a good thing for them to get involved. I was just thinking RSA, why not start something up with Yeah.
Let, let's, let's get a hold of them and see what they do. Someone has to do this. It's, it's a good point because I don't think the model is, uh, why fix what ain't broken?
Why break what ain't broken? You know? So, so it's the, uh, Silicon Valley break things, you know, and worry about the details later.
And it'll, it'll shake out one way or another, which is, which is the whole showing people to the door and, you know, for political reasons or whatever the reasons are. It, it never made sense to any of us why you would pull the plug on Mitre, especially for funding this kind of activity. 'cause it's really the lifeblood supporting the industry.
Could we do some new things? Yeah, I'm sure we could. What do we do in the age of ai?
Is there something we can do better? Is something we can do to help with either the accuracy or the, or the response to, uh, CVEs that we do put together. And there's a lot of things I'm sure we can do in, in today's age, if you're gonna not only modernize, but maybe rethink or redesign how we do this kind of a, a process.
But in the meantime, you know, uh, you gotta pay the bills, you gotta protect the network. You gotta protect all the critical infrastructure. You gotta protect all of our, you know, digital assets.
So you just don't shelve that process and then kind of wait and see what, what, what forms, you know, if a new galaxy perform, uh, forms up and starts to work on this problem, it, it's an ongoing threat. So, really, in my view, I think the a the attitude or the approach we took is actually puts us at great risk, great national security risk. Not just for our national infrastructure, but our businesses, wall Street, all of those things.
'cause we rely so heavily on CVEs that said, you want a reason to go out and raise sponsorship funds, Alan, whether it's RSA or somebody else. I think companies would step up in a heartbeat to say, we'll contribute to that. And not just vendors.
You know, I think, uh, financially, No, no. I think end user enterprises would be, Yeah, a lot of companies that would say we want a neutral yes. Yes.
And we want a healthy vendor ecosystem that is, uh, putting the right kind of products. Matter of fact, we'd love to see a, you know, revitalization of that, see some new things happen, some new innovations in industry. So let's use this as a spark to, uh, really create the next era of how we do this.
Agreed. That's a great idea. Yeah.
Love it. Agreed. And this needs public private partnership, right?
I mean, that's really the role for the government to play here is there's a lot of great efforts. There's a lot of folks who wanna be part of a solution. Um, you know, government really is kind of the organizer of last resort here and, you know, the funder of last resort.
Um, but, you know, this is, this is the equivalent of, you know, like getting rid of an FDA or an NTSB, right? You know, it's just a little bit more in the background of, you know, everyday people. Um, and so I think it's not getting the attention that it would if it was some of those more visible things, um, for, you know, things that people feel like they consume more regularly on an everyday basis.
But, um, you know, this is, this is a national and, you know, national security issue at the end of the day, um, really need to step up and get this fixed. I mean, people, people will know about it when, when it hits the fan, I'll tell you that. You know?
Exactly. So, all right, let's take a break here on the gang. We're going to come back and we're going to continue our cyber focus today, talking about Microsoft.
Are they grossly negligent when it comes to security? I dunno. You're watching Techstrong Gang, Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, everyone, welcome back here to Textron Gang. Um, you know, uh, Senator Ron Wide, and I believe he's from Oregon, is asking the FTC to investigate Microsoft's gross cybersecurity negligence as a threat to national security. My goodness, Kate, I'm gonna ask you to kick this one off.
All right. 6 million people. It's a lot.
Um, the entry point for this came from a malicious link and a contractor, you know, clicked on it. And, you know, as typical, um, as we've seen, you know, everything falls, right? So it went over to, um, reached, uh, escalating, you know, that whole privilege escalation, Microsoft Active Directory, privilege management and everything else.
So the technical vulnerability here, um, was a well-known attack, uh, for credentials, uh, via a weakness in, um, kros authentication. And the core part of this was Microsoft continuing, uh, the default support for our C four. And many of us know that one there.
And basically, you know, the argument here is that, you know, why is this continuing when we've known for a very long time that better alternatives exist? Uh, the other question that he raises, um, and I think it's actually good logic here. I don't think we need to, you know, beat up Microsoft, but, but the logic here does make sense to me.
And that is, you know, you talk about, you know, Microsoft talks about, you know, well, you know, for critical infrastructure, you know, we need to keep this open. We need to have backwards, uh, compatibility. 1%, uh, presently.
And, you know, and then going, so, so how does that make sense? 1% of the people who are still using RC four and, you know, but yet critical infrastructure is impacting, you know, it has a possibility of impacting us all. Like, you know, at 90 plus percent.
So does does that make sense? I mean, when do we finally just shut, shut it off? I'm a big proponent of, you know, let's just shut it off and let's, let's see what happens.
Uh, but that's me. So he raises the point about national security and systemic risk. Um, and what can Microsoft do here, uh, to really change, change up this risk that, that he sees that's impacting critical infrastructure?
So Mitch thought, Mitch, you wanna go? Yeah, I, I do. You know, I'm thinking of, uh, a conversation we had earlier on an earlier show about when, uh, some, so there's a quality issue with something coming out of the factory you enjoy.
Just don't fix the item that has poor quality. Go back and fix the factory. I think we have a fundamental issue with security technologies, both the security standards, uh, that we put together, but also how they're implemented.
And here's what I mean, I'll draw an analogy with, um, IOT devices, right? For forever. There was never a way to update IOT software.
It just went out there. It lived out there forever. The vendors didn't have a way to update it.
They didn't really care. They didn't really maintain it. They just knew they were gonna replace it, right?
'cause it was replaceable technology year over year, but it didn't get replaced. It things to live out there for much longer, have much longer life. The same thing happened with security standards.
So what do we see in iot? The vendors start building and upgrade mechanisms to be able to do updates and things like that. The challenge, and I'm not saying it's an easy thing to do, but how could we reassess how we design the standards themselves and also implement them so we can upgrade them in place more easily without it being, you know, a rip and replace a major process.
And this is everything from, you know, uh, PKI hierarchies and keys, uh, to KRO standards, encryption standards. I mean, it's a big effort to go from, uh, Shaw 1 28 to 2, 2 56. You know, it is not a small thing.
Um, and again, maybe this is an area for ai. How could we redesign this process? I, I would invest my effort instead of, you know, trying to rake Microsoft or whoever the next company has crossed the coals for, you know, not making their customers keep up to date with the latest things.
Um, and really let's address the systemic issue. Yeah. So, and I I, oh, Kate.
No, no, Kate, you go. Well, I do absolutely agree with you, Mitch, that we need to, um, I like, and it actually ties to our, our previous story, right? I think we're at a time right now where we really have to rethink what we're doing and going forward.
For many of us who have been doing this for a long time, we understand, we know the building blocks, you know, it's time to build things, right? And, you know, really think about redesigning things, right? And yeah, it's a good, good point there, Mitch, that that's Kind of why I got into DevOps, right?
To, to get security right. Earlier on in, in the process. But let me, so let me take off my journalist hat this time and put on my lawyer hat.
This is not gross negligence, ladies and gentlemen. Yeah, right. There is, there's legal definitions of gross negligence and this ain't it, right?
This is a politician politics Yeah. Making, making hay. Now, could we make things better?
Yeah. Could Microsoft be better about trustworthy computing as Bill Gates called it all those years ago? Yes.
Should we be complaining to the FTC and calling gross negligence on this? Absolutely not. That's slanderous.
I, you know, Kate, I always Yes. 1%, right? 1%, you're yelling bloody murder if, if you're making them change it.
And, and so these things need to get done. The problem we have overall in security is we're always playing catch up. We're always three steps behind.
So now we're gonna try to fix this, well, this morning, 140, uh, packages in NPM from, from no less than, uh, CrowdStrike, I don't know if you guys saw this this morning. 140 CrowdStrike packages are found to contain malware. Some sort of new worm that's able to get into these packages and deposit malware that steals credentials and everything.
It's kind of a new vector. It's a new worm. You, you, you know, that's the problem in security.
You know, we're not the French in World War ii. We can't set up a imaginal line so that the, the tanks come around us and leave us there. Yeah.
You gotta fight tomorrow's war, not yesterday's war. Yeah. And we, and That's what we need to do.
Go ahead. And, and, and that's something that we have said on, on the show before, right, Alan? Like, we're not really planning, um, for tomorrow.
We're fighting yesterday. And the strategy defense in depth, I mean, we've heard this, I've heard this a lot, Right? Really?
Yeah. Our whole life, right? Yeah.
And I feel like, and believe very strongly that it's not a strategy that has been effective. And if it was, we wouldn't be in the position that we were today. And when we talk about offense, a strategy of, of offense, it's so different.
And if we don't start playing the offense strategy, and that doesn't mean, let me start an offensive, let me start to attack countries. It just means that I have the ball. You know, Hey, this is football season.
I have the ball. How am I gonna get down, down the field to, you know, score points? You know?
And we don't think that way. But if we were to think that we have the ball, how does that strategy change with cybersecurity? And that's the question.
I, I think, and it, it's perfect, you know, with CrowdStrike, you know, In the immortal words of Hank Strm, let's matriculate down the field. Just get us an ation, Uhhuh Uhhuh A I think you said it well, I mean, you look at the rhetoric here and it kind of screams of, you know, a politician with an agenda. Now obviously Microsoft has, you know, somewhat been the poster child of create the problem, sell the solution.
Um, but you know, I, I don't think you can really hold the vendor too accountable here, right? I mean, the end user has some responsibility as well. And you know, at what point as a vendor is building a platform that is supposed to serve, you know, almost everyone do the edge cases where, you know, people are kind of falling behind and, you know, building up technical debt and, you know, not, not kind of modernizing at some point, you know, I think it falls back on the end user, not the vendor here.
It's really good, good, good. Uh, example, because, uh, that happened with the crowds script. Not, not the most recent, you're talking packages, but when the outage happened, yeah.
And of course Delta scream bloody murder and sued them. But of course, you know, they were, they were the, the worst of the worst of not being able to go out and actually rebooting their systems. It was like, at, at what point does the consumer have some responsibility?
It's a shared responsibility model at the end of the day. Mm-hmm. Yeah.
I mean, it's like your home, right? You can have locks on your door, but at the end of the day, if you don't lock your door, you know, are we gonna go see this? Yeah.
But then you got the cloud, which adds another element to it. And it's sort of like, well, you just rent a home and what, what responsibility does the landlord have? Right?
You, you put your lawyer hat back on, didn't you? No. Well, yeah, you'd never take the lawyer hat off.
That's the problem with lost lawyer historian Responsibility model a little bit, right? The cloud shifts the responsibility model a little bit more back to the vendor. But, you know, there's a lot of control.
The end user still has, you know, even in how they set up. And that was always the thing about cloud security. Dan, yes, the cloud vendor has capability to do some security there for you, but ultimately it's the end user who bears the responsibility when the stuff hits the fan.
You, they don't want to hear that, oh, AWS didn't do this for me. Well, no, you put your infrastructure on a WSI used you, you are responsible. And, and that that's the, that's the fact.
But, you know, I don't expect anything to happen out of this. You know, Alan, Alan, just to throw one other, not not to to get too, um, futuristic about it, but I've, I've talked for some time about sec, about software being not a static thing anymore. We used to release software, it would live out in production for months, maybe years sometimes.
Uh, but in now live in the world where software gets updated near continuous, not quite continuous, but it's something that is evolving and I describe it, it is, software is not fixed like a rock. It's fluid like water. We have to think about security the same way we have to stop thinking of static security.
I put it out there and it lives until I do something about it. And we live in a world where the doing something about it takes people and resources and money and time, which is why things get lett behind. 'cause it's just not worth it to go deal with the problem.
But isn't a problem yet. Right Now we're a big enough problem. I think we have to think about designing security, not just in zero trust, but continuous zero trust, if you wanna think of it that way.
This Was J Frog's thing Mitch out in Swamp up last week. So, you know, they call it liquid software. Liquid software, exactly.
And it's versionless. Yep. There's No versions.
It's continuous. It's continuous. But it's continuous security too.
Exactly. And that's why, that's I think, the model of what we need to shift to of thinking, because we live in a world where we could do this now. And I know that was part of their AI announcements, and that's part of a way AI can potentially help us, especially, you know, AI is, is going to be writing more and more code for us.
Not just at, at a point in time, but continuously in the background creating new code that it's writing itself to do new things. Now, of course, how we regulate that control that or o other issues. But the same thing can happen in security, right?
So a response may actually be it creating a process or it writing some security protocol adjustments or changes or, or code that responds to an incident because we're at such a volume, nothing can re, you know, I go to this conferences where we're reducing alert fatigue, that's all great, but we, even at that level, we still have alert fatigue. We don't have enough fee people to respond to vulnerabilities and software to attacks on network. This has to be automated.
And the smarter we can make it, the better we protect ourselves. I feel If only we had a, you know, very transparent, trustworthy, central database of vulnerabilities that the agents could pull on, right? Little callback.
And what a great idea, Dan, maybe we can do something. Lemme write that down. Thank you, ma'am.
I, I even got a name for it. AI Needs good data, right? You know what?
But here's the sad part, guys. Kate, you're a security person. Mitch, Dan, you've been around the block enough.
Is anything really gonna change? We sit here, we talk, we pontificate, we ize, if that's a word. Um, we, you know, all of this.
Are we gonna be having the same damn discussions in 2035? Maybe it won't be me discussing it, God willing, but are we gonna have the same damn discussions 10 years from now? Yeah.
It's a game of leapfrog. Continuous game of, yeah. Yeah.
So I, I'm, I, I hate to be the kind of, it's all about money, but it is all about money. As soon as soon as someone finds a way, a way, a model, an innovation, whatever, to make money doing it differently, they'll, they'll do it. They'll jump at it.
And if it is successful, others will jump on that bandwagon. So I've, I've, you know, as long as I've been in security, I feel like we're doing what we did When you and I started, you know, 25 plus years ago. We're like, we're doing the same s**t.
We're just doing it a little differently with a little better technology. And it evolves and it improves and, and it evolves. You know, let's really get some serious innovation happening in security.
Let's really invest not in the latest startup that solves some point little problem that does a little bit better than Cisco does it. And we're gonna sell it back to Cisco. Yeah.
We'll make money at it. Let's really invest creative and innovative ideas that are gonna move the ball, not just 10 yards, but into the end zone and maybe into the next stage. It is all and, and law of diminishing returns, right?
You know, at a certain point, the spending the next bit of money doesn't justify the ex extra bit of risk management that you kind of get. Sorry, Kate, go ahead. No, no.
I, I have to say that, um, in my age, as I grow older, I've become a Pollyanna. And I don't know when that happened. Well, would've sword.
Alright. I Dunno. Well, yourself admitted, that's the first step is admitting the problem.
But I believe that we're gonna change this. I really do. This is my Pollyanna.
Sh you know, like, I believe, I believe that we're gonna do this. I believe that we are gonna solve this problem only because if nothing else, because we have to. And I believe in, you know, I wasn't a big adopter of ai, but now I'm like, man, ai, let's embrace it.
Let's see where we can take this and let's change up this story. So in 10 years, I can't have, I can't do this over and over again. Like in my mind, like, we have to change this narrative where this is going.
So the Pollyanna in me lives on and we are gonna have a different story. And hey, three years, three years. Three years is ambitious.
God bless you. Year two years left to God Here. What more I believing I was gonna ask you to get into politics, Kate.
Amen. I was, I was looking for a church there going on. Alright.
Hey, I believe we need to take a break right here. Uh, we're gonna come back and we're gonna change it up a little bit. Let's talk a little bit about ai.
'cause we don't talk enough about AI and, um, but we're, talk about stock markets and all kinds of good stuff. You are watching text again. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. Hey everyone, welcome back here to Textron Gang.
You know, I, I had an interesting conversation with my friend John Willis today, and he, we were talking about the progression of users of o of AI and of chat GPT, you know, and, and we, we, we tend to, we live in a bubble. We we're tech people and we think everybody's using AI and everybody knows what it is and everyone knows all the history when the fact of the matter is yes, open AI is probably the fastest to a hundred million users of any technology ever. You know, it's pretty, it's cut and dry.
However, a hundred million users plus still pales in comparison in a world of 7 billion people. And so we forget and open ai, the whole open ai, I not-for-profit, the Microsoft involvement, even in the a hundred million users, I bet, you know, a overwhelming majority are not aware of the unique corporate governance and structure that OpenAI had or has. And, you know, you know, absolute money corrupts absolutely.
And with all this money in there, people are trying to figure something out. Dan, I I've laid it out for you. Why don't you finish it up and take us into what's happening now.
Yeah, for sure. Thanks Alan. So, as you mentioned, you know, founded as a nonprofit, the nonprofit controls, you know, the potential, uh, you know, profit entity, a super complex corporate structure and governance model.
Um, you know, let's lay out the facts, right? Microsoft's got 13 billion into open ai. Most of what they've been, you know, kind of, you know, negotiating around is, you know, really the restructuring approval needed, um, to take this thing into the, the for-profit world, you know, the equity stake that micro Microsoft will get, the revenue sharing agreement, the technology access and the a GI clause.
Um, and then all the commitments on safety, right? You know, early on in the partnership it was focused more around model exclusivity. You know, Microsoft being the primary cloud recouping their investment, you know, with profits.
And, um, you know, though, I think, uh, micro open eyes come out and said, you know, probably not profitable until 2029, you know, looking at $44 billion in, in operating losses, you know, between now and that timeframe. But, you know, you take the financial backdrop of this thing, there's an incredible amount of value creation happening there. There's also an incredible need for funding moving forward.
And, you know, ultimately this move, I think is about, you know, securing the capital needed to, you know, kind of meet the CapEx requirements of continuing to drive the business forward, right? You know, the ability to, uh, you know, to tap in, in IPO potentially next year, you know, raise a significant amount of capital. We've already seen this in, you know, some of the talk around the Stargate project with SoftBank and Oracle, you know, numbers like $300 billion being floated.
Um, I think OpenAI is targeting a valuation of about a a half a trillion dollars, right? And, you know, Microsoft seems to come out with, you know, something that's probably on the order of a couple hundred billion. So, you know, something roughly equivalent to, you know, eight to 10% of, you know, Microsoft's market cap, um, is kind of the amount we're talking about here.
So it's, it's not insignificant at all. Um, but ultimately, you know, I think both parties realize that they need to get past this, you know, kind of restructuring effort to really extract the value from it. And, you know, everybody's willing to negotiate on, you know, kind of the terms that need to change moving forward from what they've been, you know, to, to fund the CapEx and really seize the opportunity.
I, I've got a few things here, Dan. First of all, to your point, I just wanna make sure our audience realizes this, that $13 billion Microsoft invested was not your usual investment where they got stock or even options or warrants or anything. It was $13 billion as part of a rev share, right?
And Microsoft was gonna recoup that money in, in rev share and profit. Secondly, my understanding is just last week, Larry Ellison, you know, got about a 34% bump into his net worth because Oracle came out that OpenAI is pledging $300 billion to Oracle alone for, for this AI infrastructure. So Dan, if they're gonna raise a half a trillion, you are talking about giving away 60% of it in one to one customer to one project, one, one transaction.
They need to raise, I think a couple of trillion. Do they need to raise Nvidia kind of money just to, to pay these bill, you know, to pay that Piper, that's a lot of, that's a lot of cabbage. It's a lot of cabbage, right?
Think about what, what you're talking about. The other thing though is I, I'll, I'll mention this and then open it up to the, to Mitch and Kate and Dan, you wanna come back? Here's the fly in the ointment.
Our friend Elon, don't forget, he was a founder there and he was, he supposedly was big into this not-for-profit piece of it. He didn't like what they were do. Well, there's back and forth about why he left, but one of the reasons is he didn't like what they were doing.
He, of course has XAI and gr right? And he's pledged to open source that everybody's pledging to open source everything while they're all running to the trial to feed open ai. Yeah.
So, you know what, what, what I, I can only imagine the lawsuits flying, but I'll, I'll throw it back to the, to the gang. What do you guys think? I, I just relate it to, if it can be related to my own personal experience, having run a for-profit company at a much tiny, tiny, tiny fraction of a fraction of a size of what we're talking about here, owned by a nonprofit company.
And that is e even in that particular relationship, I'm gonna mention the specifics of it, um, but it complicates things when a nonprofit owns for-profit entities. Now, the, the, the hospital systems see, have figured this out. 'cause a lot of the hospital systems are set up that way.
A nonprofit owns all these for-profit companies. But when you start out as with an more of an altruistic nonprofit, that was what originally open AI was about, is doing this with safety and, you know, protect protections built around what we want AI to become. And of course then the for-profit part of it starts pushing it outside of the bounds of that original goal.
I think some of those, those, that fabric of that original mission still complicates the factor here. And at some point you have to say, look, we're not, the, the ownership of this is not about that mission anymore. We are about managing for-profit entities through this nonprofit company, et cetera, in this structure.
And let it be what it's gonna be or, or spin it off and do your own thing as a nonprofit. Just stop the complexities of it. Not saying that this still isn't complex at these numbers of this size.
It's still hard for me to kind of keep those numbers in my head. But I think that is is also an undercurrent of this too. 'cause all, many of us said, what is, what does open AI wanna be when it grows up?
Well, I think it wants to be a company that makes a whole ton of money, is what the market's saying. Yeah. I mean, to me it's like, do you guys remember when Tesla, in the heyday of Tesla, they were the only game in town for EVs?
You know, they had like three x the market cap of Ford and gm and one has to look and say, if that's a car company, and these are car companies, I'm not saying Tesla is not without value, but is it three X of Ford, three x of gm? You know, it, I think we're talking, I mean, correct. I I'm not a stock market expert, but Nvidia is about a $4 trillion market cap, right?
I believe Microsoft's like at a $2 trillion market cap. Yep. Open AI has to be approaching that to, to afford the kind of deals that they're talking about.
And, and, and keep in mind, Dan, as you said, this is a company that's gonna bleed 44 billion red dollars between now and 2029 or something like that, right? 44 billion. Do you know, that's, that's an insane amount of money.
Well, investors are discounting the future, you know, potential profits and cashflow and voting that there's still a lot of money to be made here, right? And I think what they're trying to do is really kind of remain a little bit true to the original mission about really advancing AI safety. Um, and, you know, the nonprofit may end up with, you know, a sizable endowment to drive AI safety priorities while, you know, kind of separating from the for-profit entity.
So I think they're trying to get to the win-win here. Um, certainly, you know, the original investors in open AI are gonna win. Microsoft is gonna win very big.
Um, and it seems like they're trying to maintain, you know, some of that credibility around the other mission, uh, the original mission and, and, you know, really fund that AI safety thing through the equity stake. Do you think, Dan, that that sort of solving that through some kind of a structure funding, that that original mission, if that happened, is that sort of separate the, the conflicting concerns and let's open ai, I be the pro for-profit company, it needs to be, and let open AI that's the nonprofit be what it needs to be and stop complicating the concerns. Do you think that's standing in the way of some of this?
I think it is. I think that end, you know, a fair number of lawsuits are standing in the way of this, but Yeah, I think a fair number of luck. Yeah, for sure.
But let me, let me just, not devil's advocate, but let me give you another spin on this. I was reading a post today by a PhD in stem, A woman who's talking about, you know, they bought Johnny Ives OpenAI bought Johnny Ives, uh, company for about six and a half billion dollars. And supposedly we're gonna start seeing these, uh, consumer business consumer products coming out next year.
And the rumor is, is that one of them, basically, it's not a phone, there's no screen, you know, but it's a device. I don't know if it pins on you or it's in your glasses or wherever, but it's a device that's your constant companion and kinda whispers in your ear and tells you, you know, it, it summarizes conversations you're having and what people are saying. It tells you where you're going and what you have to do.
It reminds you, it, it is your alter ego. And you know, it doesn't have a name yet. I didn't, there's no pictures of it, but that, that's kind of the buzz about what this new device, you know, that Johnny Ives team was working on, is working on.
And Sam Altman says that that alone, that alone is another trillion dollar business for open ai. So I, I'll close it out with this. If they go public, I'm in Friends and family.
I hope so. Alright. Hey, if we have nothing else, we're gonna wrap up this version of the gang.
What a great, great conversation today, guys. Dan, Kate, Mitch, thank you so much for participating. Thank you out there for watching.
As usual, we have a full lineup of text Drunk TV immediately following the gang. If you're watching this Wednesday morning Live. Um, if not, you can go to Text Drunk TV or the Text Drunk tv OTT app where we have not just techron tv, but Tech Field Day.
We've got some six five media, some future group stuff. You could get that on iOS, Android, apple tv, Roku, and Amazon. So check out the OTT app.
We'll be back tomorrow with a fresh gang and fresh topics. Until then, on behalf of Tech Trunk Fu and everyone else here, we're out. Hey everyone, it's Alan Hummel.
Welcome back here to Tech Trunk tv. I'm really happy to have my next guest back on. You know, I, I know this gentleman, geez, 15, 18 something years.
We, we shared an office together at early on when previous company Matt had started and I had co-founded, um, Matt, Matt Loberg, CEO markup ai. Matt, did I get everything right there? You did, absolutely.
Very cool. Good to see you. Um, good to see you, Matt.
So, you know, we were just talking off camera and I couldn't believe it was that long ago that we talked. I felt like it was maybe two or three months. You're saying it's six or seven, but it's all good.
Gives us more chance, more to catch up on Matt. I, I mentioned, uh, you know, we know each other a long time. You were a CEO of a company, another company that you had, uh, founded.
And, and you know, actually, why don't, I'm not gonna tell them your story. You tell them your story. Uh, well, yeah, I think you, so you and I met, uh, when I was running Return Path, uh, which yes, uh, uh, which was an enterprise, uh, global enterprise SaaS company in, uh, email data and analytics.
Um, which I started in 1999, uh, last century feels like last century. And, uh, it was, we sold, uh, sold that company in 2019 and I've done a couple other startups before that and after that, and now, uh, very excited to be at the helm of, uh, uh, of, uh, the company formerly known as Acrolinx. And, uh, as of September 17th is now Markup ai.
Very cool. I love it. So, so September 17th, that's fresh.
Um, It's coming up as we, as we, As we record, it's next week as people hear this be probably right after. Yep. Um, so Matt, give us the scoop, why the name change, what's going on?
Yeah, we're very excited about this launch. We, we feel like we're launching a new category as well as a new platform and, uh, a new brand, uh, to go with those two things. Um, the category that we are, uh, so proud to, uh, to spearhead is what we're calling Content Guardian agents.
Uh, so the origin of that name is, um, is actually Gartner, um, you know, a big, uh, analyst group, um, that have increasingly been talking about this concept of guardian agents. And, uh, you know, it's obviously a play on guardian angels and, uh, one, one for the AI ages here. Uh, but the concept of a guardian agent is very simple.
It's an AI system that is designed to oversee another AI system. Uh, so if you think about, if you think about it, AI systems do things so fast and at such volume that it's just not possible, uh, to hire enough humans to oversee every action of the system. So you actually need a different kind of AI system, uh, to oversee, um, an AI system and to kick things out.
So it's sort of this human in the loop, um, motion, um, for things that are aberrations or don't look right. So that's the concept of a guardian agent. And what we are, um, is, uh, what we're calling a content guardian agent.
There will be guardian agents that do other things, for example, things around security, uh, but content guardian agents are really, uh, going to be, uh, critical for sort of the, the whole architecture or scaffolding of generative ai. Um, so if you think about it, companies are adopting generative ai. Most companies are using multiple models, multiple departments are using multiple models, um, to produce more and more content every day.
Um, and our new platform at markup ai, um, we think is gonna be the industry standard for overseeing the quality, uh, and accuracy of content coming out of generative AI systems. So content Guardian, I love it is the category markup is the brand because what do you do when you want to fix a document? You mark it up, lawyers mark things up, editors mark things up, developers use markup languages.
So, uh, we're excited, uh, to bring our, our new brand and our new platform to market. Matt, that's a, uh, you know, this is this, you know, sometimes you hear things Matt and you say, well, welcome. No one voted that before.
You know, that's a good idea. Why didn't I think of that? But, but it, it is, it's, it's just so common sense that, you know, of course we would want this, you know, we were talking off camera and I was telling you I was out in Napa last week or, or this week rather, and I was there for this jfr Swamp up, uh, event.
And, and they, they released something called AI Catalog, which all it does, I mean, all it's, it's still a big thing is it goes through and finds all the ais, all the gen AI models and, you know, running in your infrastructure Okay. Sort of going after the shadow AI problem. Yeah, yeah, exactly.
And then documents and catalogs, and then theoretically you can decide, I want this one, I don't want this one, I Don't want that one. Yeah. And, and that's a value.
I'm not saying that's not valuable, that's a valuable piece of functionality, but what you are doing here is you're going one better, if you will, in saying, Hey, we're going to, you know, people are going to use AI there, there's no, you know, you could lock the door, but they're coming in through the windows. But when you're using ai, we're going to watch the content you're developing with it, we're gonna make sure that that content is okay. It's right, it's not patently false, it's not somehow illegal.
It doesn't violate policy. Yeah, exactly. I mean, again, the, the sort of, the concept of the Guardian agent is that guardian agents do three things, review, monitor, and protect, uh, and kick things out for human in the loop review.
So that's what, uh, the markup, uh, platform, uh, is, uh, is going to do for, uh, for content, um, monitor, review, protect, uh, and help companies really confidently and, and rapidly scale their use of generative ai. Got it. Um, now it works across all of kind of the frontier models, the usual suspects.
It it does, yeah. I mean, it's, um, our system is very easy to use. It's a series of APIs, uh, and, uh, the, the system itself is a good blend of, um, of using large language models ourselves, using the output of whatever the client has, and then blending that with deterministic rule sets.
So, so companies have deterministic rule sets that can be quite complex. They have brand guidelines. Sometimes those run hundreds and hundreds of pages long.
Um, they'll have terminology dictionaries that could have tens of thousands or hundreds of thousands of entries. Um, they'll have policy handbooks, uh, they'll have laws and regulations that they're subject to. And our system is, is very good at instantly ingesting all of those deterministic rule sets and blending that with a large language model so that we can scan and score and then rewrite content instantly.
Um, well if you think of the use case, right? You know, companies produce, um, you know, hundreds of thousands of pages of content a year. They might have millions of pages of content that are active online.
What do you do when you come up with a new policy or change a term or have a brand guideline? How do you fix 6 million pages instantly? You push a button and our system works in batch mode and flags and fixes all the mistakes.
What do you do when you're creating a new piece of content and you want to check it somewhere, but you don't want to have to go send it to a lawyer and then send it to someone on the brand team and then send it to someone else? And then what happens if they don't agree with each other? All that is streamlined through one very easy to access API Got it.
Now I'm assuming you're, you are using some sort of AI on the backend to do all this, obviously We do, yeah. We're, we use large language models in, in conjunction with, uh, deterministic rule sets and a vector database and everything else. That's how our system operates.
But we can obviously work against any other system that sends us content. Excellent. And now, how would, how would you sell this by the amount of agents you deploy, by the amount of content you're monitoring By the token?
Like, like all good native ai ai, Right? That's the way, that's the world. We're moving to the token world.
ai. Uh, you can do a trial for free. You can, you know, our, our entry level package, uh, once you get past a a free trial is $200 a month with a credit card.
So if you're a developer and, uh, you wanna play around with the, uh, the two APIs, one for checking and one for rewriting, it couldn't be simpler. I love it. Sounds great.
Um, and, and you know, Matt, the other thing I wanted to emphasize is, look, if you've got millions of pages of content, hundreds of thousands of pages of content, this is great. But you don't have to have No, you don't. This isn't, you know, just for the, those folks, for those people It isn't.
Yeah. And then that, that's, that's actually why we took the approach of deploying this very simply with APIs. Uh, and there's also low-code, no-code options.
So you can find us on Zapier, you can find us on N eight N. Um, so we're, you know, we wanna make this available to everybody. And you know, pricing is on consumption, so you can, you can use it at small volume.
Look, the reality is, yeah, big companies need a lot of it, but small companies need a lot of it too, or need a little bit of it, and they should be able to get that. So it's, you know, it's the beauty of deploying systems these days, uh, that are built on top of large language models and, and, you know, very, very simple deployment is, uh, it can be used at small scale or at large scale. Excellent.
I lo I love it. Love it. Um, begs the question, what about agentic ai thi is this a form of ag ai, you think?
Yeah, For for sure. Yeah. I mean, the way, the way we're talking about the product we, uh, are launching on September 17th, or launched on September 17th, depending on when you're listening to this, is, uh, that is our, um, our brand guardian agent.
It is agentic ai, it uses generative AI in the background, but it's really an agent, uh, that is, um, the, the brand guardian agent is actually a bundle of individual agents that do very specific tasks, which is kind of the definition of an agent. So there's a terminology agent, a consistency agent, a tone agent, a clarity agent, and a spelling and grammar agent. But all of those operate in one API.
So this is very, very much a agent AI with the power of large language models in the background. I love it. I know you mentioned the website, but mention it one more time.
ai. I love it. Matt, you know what, how long you there?
Seven, eight months. You changed the name of the company, shook up the whole thing, started the Degen ai, uh, product offering. I'd expect nothing less from you.
Well, it, you know, we've been able to do this as quickly as we have, partly because we have a, a superb team and partly because, um, the foundational models and the tools around them are very powerful and easy to build. Yeah. Um, but also because, uh, the history of, um, uh, of our legacy company Acrolinx, um, we have been doing similar things like this for large enterprises for over 20 years.
So there was a tremendous, even though, um, this is new technology, there was a tremendous amount of institutional know-how about how companies interact with content, what their content supply chains look like, what their approval processes are like, what they care about. Um, so that, uh, you know, sort of the, the, the, um, uh, legacy knowledge combined with new technology lets us operate at very, very quick speed. And it's also gonna let us, uh, produce, um, the next set of Guardian agents around content.
So this one is brand, but the, the ones that are coming over the next few months are gonna be policy risk and regulatory. Uh, there'll be, uh, content optimization and accuracy. Uh, there'll be data leakage.
So you can just think about anything that could go wrong with content. Um, you know, we, we will be the one stop shop to make sure that, again, it's this concept of the guardian agent. It's overseeing your AI systems to monitor, review, and protect.
Excellent. Excellent. Hey, Matt, I promised I'd get you outta here on time.
I know you have another meeting. We're about out. Congratulations.
Keep up the great work. Let's not wait five, six months till you're back on though the way you're rocking and rolling here. You're gonna have news next month or something, so happy to talk.
Stay in touch Anytime, Alan. Always A part. All right.
Matt Bloomberg, CEO of markup ai, the newly renamed markup AI launching the Industry First Guardian eight content guardian agents. Stay tuned for that. You're watching Text Drunk tv.
Hey guys, thanks for the throw. We're here with Dave Lewis, who's global advisory CISO for One Password. And we're having a little chat about, well, cybersecurity and mergers and acquisitions, because somehow or other we seem to overlook this issue every time there's a deal.
Dave, welcome to the show. Thank you very much for having me on. All right.
There's always some sort of incident, and I guess as of late, the one that everybody's talking about involves Salesforce applications in a company called SalesLoft, which bought another company, which had some issues with their OAuth tokens. And then the next thing you know, all the bad guys are targeting their stuff. But this is not an uncommon story, and we've seen it before.
And I guess the question, Dave, is like, how come we don't seem to ever think about the security implications of these m and a deals and what needs to be done? A lot of times it's really about business decisions, and they want to make sure they're doing things as quickly as possible. So unfortunately, security historically would often get pushed off to the side.
You know, they're not just business transactions, they're cybersecurity events. So this is one of those things where the gotchas can and will happen. I've lived through them, I've seen other organizations deal with 'em and, you know, obviously their current news as well.
And, you know, the role of the CISO in this particular case is to protect the value of the deal and enable the business. And unfortunately, security historically was seen as that flaming sort of justice and how we could get to the answer of no. When in effect, you know, security is there to make sure that, you know, security is able to operate safely and securely.
Do you think the folks who are doing these deals are aware of the potential security issues? Or is this just something that comes to light after the fact and then they go, wow, I wish we thought of that? Uh, unfortunately, it's a lesson that has to be learned by falling on swords.
Um, unfortunately too many times this is the case, and part of it is, you know, fall squarely on the security practitioners. We have to be better at managing the narrative, making sure that we are inserting ourselves where is net where it's necessary on the business side of the house. They have to alter their thinking and start realizing that in order to make sure that an acquisition is going to be successful or a merger, whatever it happens to be, that security has to be absolutely factored into the equation.
Hmm. Um, how does the CISO kinda inject themselves into that conversation? I mean, do they even know that these deals are going down?
Or should they assume that they are and just start poking around looking for where they might be happening? Well, the really interesting thing there is that the CISO tends to fall in different parts in different businesses as well as different verticals for that matter. So if you are, you know, rolling up to the CIO, then it's really an interesting paradigm because you, the one you're finding fault with is ostensibly your boss.
So it becomes a very difficult and sticky situation for the CISO there. If the CISO has a seat on the executive leadership team that changes things and it provides that visibility, uh, even having the CSO report into the CFO that is responsible for risk and, you know, the fiduciary responsibilities that come with it, you're going to have, again, better visibility. So it's really about communication at this point, because the fundamental piece of any security program is really about the human element.
When you boil it right down to brass tacks and making sure that you're able to communicate, get your message across, not only as a security practitioner, but the people that are responsible for exercising these deals, they have to find a way to listen and hear that message. So part of that is, you know, learning how to speak the business language, you know, saying that revenue's at risk, there could be brand damage, compliance fines. These are the kind of phrases that the business leaders will understand if you run in there and say, oh, we're gonna have a zero day in their environment of blah, blah, blah.
Obviously I'm being facetious there, but get, if you approach it from a security perspective, you're going to get a very different response than if you say, oh, our revenue is at risk. It's going to have a very different response. So shaping the message as a security practitioner in a way that's gonna resonate is absolutely, uh, the key piece of the puzzle there.
Mm-hmm. What, um, should people be doing? Is there some sort of like baseline for forensics, for an acquisition from a cybersecurity perspective that somebody has created under a set of best practices here that should be observed There?
There's all sorts of different best practices. Like one of the ideas is having, you know, security protocols by phase, like doing due diligence of going through and looking at the threat posture and security posture of the organization, how they measure up for compliance, what sort of business, uh, business, sorry, what kind of vendor risks do they have? So for example, if you are connected to a vendor that has a history of security issues, you know, that could really affect the blast radius of how you're doing your calculus, uh, then you have to look at it from the integration perspective of lining to access controls, consolidating your vendors, making sure that you don't have multiple vendors that do the same thing.
I've, I've lived through an organization where we had seven different vendors that were delivering ostensibly the exact same product, and that was because it had been a project driven environment, and at no point did anybody sit down and say, oh, do we already have this in place? And the other piece there is to unify the policies between the acquirer and the acquiree to make sure that everything is lining up properly. And then looking at it from the post deal perspective of, you know, ongoing monitoring audits, remediation where necessary, and making sure you're cataloging any inherited weaknesses and adding that to your risk register so you're making sure that you're tracking it from cradle to grave.
'cause when the auditors come and they will come, they will be asking for those sort of questions. So you wanna make sure that you can demonstrate that you have not only identify it, but you have a plan to remediate. Shouldn't we just assume that the cybersecurity is gonna be flawed in any acquisition because, uh, 90% of them either involve a smaller company that probably didn't have the resources to do it right in the first place.
Or a larger company that's been in distress and maybe probably isn't spending enough on cybersecurity to be in it. As long as you have humans touching keyboards, you're gonna have a risk of something being missed. Um, and, and that's inevitable.
But you can do a very good job of reducing that risk by going through and looking at it like doing a risk assessment of looking at where the gaps are, um, As well as, You know, having a security integration playbook ready before the deal starts. So first, get yourself in front of the, the business leaders to make sure that they are taking into account security has to be there and making sure that you show up as a secure security leader with a plan, how you're gonna deal with it, how you're gonna per deal with, uh, interim controls and all that sort of thing to make sure that you are showing up prepared. Mm-hmm.
Do you think that the bad guys out there are tracking these types of deals? 'cause for them it's just like basically a, a red light signal that says, yeah, there's probably weaknesses here to be exploited. I can guarantee that.
Because again, back to the human element, anytime you have a deal happening, you have people on either side of the equation are saying, am I gonna still have a job? And the attackers know this, and they will pray upon this. If we look back to, uh, the pandemic as a great example, there, all sorts of emails started going out about, oh, if you don't complete this questionnaire, you're gonna lose your healthcare coverage and things like that.
And that was really a horrible approach, but it was extremely effective from the attacker's perspective because people genuinely concerned they didn't know how things were gonna unfold. I know I didn't. Um, so when the, when a, an event like this comes up where there's a merger, uh, that, you know, leaks out into the news, you have the chaos element that is introduced and the law of unintended, unintended consequences where not each side of the house knows who is on what company.
And so it prov, you know, really does give an opportunity for an attacker to even fashion. Like if you're at Widget Co, you could do, you know, widget Co with an extra letter in there. All of a sudden that email address looks like the same thing, even though it's a different thing entirely.
And this is where the problems really can unfold because, uh, you know, the attackers will prey on this sort of chaos to be able to, you know, steal data effect, change, uh, cause havoc if they want. Right. And to your point, they may just impersonate people at the other company 'cause I don't know who they are.
And if somebody shows up and says that they're from the finance team and the company that's acquiring me, I'm kind of likely just to trust that. Right? Yep.
Mm-hmm. Um, will AI kind of exacerbate this? And I, and, and it seems like on the plus side, I maybe should be able to use AI to discover what my issues are faster, but the bad guys are also gonna be using AI to also discover what my issues are faster.
So is is the window of time when I get to actually review that security kind of narrowing to zero? It is really getting sweeped down to a fine point. And, you know, the attackers have been using, uh, artificial intelligence and LLMs now for quite some time.
If you look at Worm GPT and fraud, GPT, there are already tools that have been around for at least a year. Um, it's not outta the realm of possibility to say that they're gonna be using some sort of AI tool to be able to breach systems. And then if you flip it on his head and look at it from not only managing credentials for an organization, but looking at it, the agentic AI aspect of things where you have agents and environments from the acquirer and inquiry that they need credentials, they need to be able to manage access within environments to APIs, to accounts, whatever it happens to be.
How are you managing those credentials? Making sure that, you know, they are not leaking out of the environment, they're not being compromised. Because unfortunately, a lot of times these, uh, agent ai, um, accounts have more permissions than the individual human might.
So those could be a real potential for problems there. Mm-hmm. Ultimately, there's also regulations involved in a lot of these m and a activities.
So are the auditors getting smarter about what to look for as well? And maybe it's not just so much about the fact that I'm gonna get attacked as much as I just might get fined. Well, yeah.
So the AI piece now really is the equivalent of running with scissors, um, because it may seem like a really neat idea because you like to flirt with danger until you find that little bump in the rug, and next thing you know, you got a problem. Um, and when the, and the auditors know this, they're gonna come looking and the AI aspect of things, it's just a different hammer within your tool set. So you have a red hammer, green hammer, blue hammer.
This particular hammer is just an another tool. And we really have this bad habit of anthropomorphizing. We think of it as being far more elevated than it is, but when it boils right down to it is just yet another, uh, technology, and it'll be obviated by something else that comes down the road in a couple years.
But yes, it is getting faster. The auditors are getting wise to this. They're understanding that a lot of times we're getting ahead of our skis with the implementations of various AI projects and security is being left by the wayside.
So we have to make sure that we're getting better at that. And, you know, really fundamentally getting our arms around the security perspective so that the auditors don't do it on our behalf. And it goes from being a simple project to a rather massive remediation project.
CSOs, of course, have multiple challenges, as it is, is there maybe somebody on an m and a team who should be the security specialist? And maybe that's brought in by a third party or somebody who kind of does this over and over again because well, CISOs aren't doing acquisitions every day the week either, so it's not maybe core to their function. Well, yeah.
So you like, whether it's an acquisition, true merger, a divestiture spinoff, um, there are all sorts of different ways this this can be presented. If you had the budget available and the time to be able to bring in an external security person, by all means do it. But realistically, it ends up being a matrix type of approach within an organization where the security person internal to the organization of the acquirer in this, uh, acquire you acquirer.
Yeah, sorry. Acquiring aspect, uh, can be brought into the conversation. So these, um, security professionals, this may not be their core competency, but they'll be very good as security.
The, the idea here is just to approach it as a rather a sev one type of approach, because m and a activity usually is very strictly time boxed. There's rather significant implications to things going wrong, and sometimes it's okay to say no. Um, I, I have been through, uh, m and a activity in the past where we literally just walked away from the table.
This was at a previous organization, and it was just, there was too much risk involved. And there's other times where we've seen organizations are going through m and a activity and something was unearthed during the process that caused the deal to drop by hundreds of millions of dollars. So making sure that security is in at the beginning is, uh, absolutely non-negotiable.
That has to be part of the equation. 'cause otherwise you could be introducing undue risk into the organization that could have material impact, uh, from a stock perspective as an example, um, credibility within the industry. There's all sorts of different ways that we can approach that.
Hmm. So last question, but what's that one thing you see folks doing as it relates to m and a and security that just makes you shake your head and say, folks, we should be a little bit smarter than that? Oh, it's a twofold thing.
Not managing the accounts, uh, correctly, because I've been interactivity in the past where we inherited all sorts of super user accounts that belonged to people that were no longer the organization and had not been there in years. That was a rather significant piece. And the other piece of that, which is the flip side that is often integrated is, it's okay, we accepted the risk.
That is not a good answer, because usually what that means is a piece of paper was signed off by someone who had no authority to accept the risk shoved into a back of a drawer and off they go. Hey folks, you heard in here when those m and a deals come around, make sure you take a good long look before you leaped. Hey, Dave, thanks for being on the show.
Thanks for having me. All right. And back to you guys in the studio.
Hey, everyone, welcome back here to our day two coverage of, uh, swamp Up Jay Frog's, uh, conference out here in beautiful Napa Valley this year. We're happy to be back. Uh, we're continuing with some of the people we've been meeting.
I wanna introduce you to a frog right now. His name is Yossi Shaul. Yossi is the SVP of DevOps, right?
Which is a great job when you're working for a DevOps company, right? So first of all, Yossi, welcome to Tech Drunk tv. I, you know, in all the years that I've been interviewing frogs, I don't think I've had the chance to sit down and talk with you before.
So it's great to have you on. Um, if you don't mind, share with the audience a little bit about kinda your journey, how you got to be here. Okay, thank you.
So I'm Yoi and I'm in this business for, um, I would say for most of my career. I started with, uh, jfo about 16 years ago. 16, right from the beginning.
Long time. Yeah. Yeah.
Uh, we were working, uh, at the beginning of Artifactory, creating the, this new domain before DevOps was a term even. Mm-hmm. Uh, so I've been working on Artifactory since the beginning.
I managed the, the team and the, and the product for quite some time. Uh, then I shifted a little bit to do some more, um, architectural, uh, leadership inside jfo. Okay.
And in the last, uh, three years, I'm, uh, back to leading the entire DevOps organization in, in jfo, uh, both product and engineering. Product And engineering. Yeah.
So that's, uh, that's really challenging. Really interesting. Yes, it is.
And very, very interesting times. So yeah. Glad to be here with you.
You know, it's funny you say that. It's, it is interesting times. Look, I, you know, I've, I'm in tech 30 years, 30 something years, okay?
Mostly cyber was in infrastructure then security. We didn't call it cyber, then we called it info side. And then when, when DevOps first around 2012 maybe mm-hmm.
I, I said, wow, what a great thing for security, right? DevOps is right. Is going to be.
And that's when I started really getting involved. com in, uh, 2013. And you know, I will sit here as you sit here, the DevOps we were talking about and doing and, and working on.
Then today it's a different animal, a little bit, right? Today, it's, it's not radical. We don't have to explain what DevOps is.
We don't have to fight on whether it's real or not. But on the other token, you know, people become too familiar with it. They take it for granted.
Mm-hmm. Right? Ah, yeah.
It's DevOps, right? It's just DevOps. What, I mean, I see this as a challenge.
Okay. com, what do you see from where you sit? Yossi is, are people like, just shrug their shoulders, like DevOps is built into the table here and it's, or do they, you know, they continue to explore.
They continue to evolve. Okay, great question. So I am, as I said, I'm long time in this, and I remember myself, uh, explaining absolutely.
I, Artifactory is a thing, Uhhuh, okay. And arguing with people why they should not, uh, store their binaries in subversion, for instance. Mm-hmm.
So we've, we've been a long way, uh, Stumbled a long way. And, um, and while I think that many organization, um, discovered and now maybe even think that they know what DevOps is, the world keeps shifting and keeps changing, and it never ends. Okay.
The, uh, we are the first revolution, then another one with Docker, then with Kubernetes, and now we are what we are doing with ai. It's keep shifting, keep changing. Mm-hmm.
And also the security is a big part of it. Yes. And while I think we also discussed it in one of the keynotes, that it's not a, so it's not a solved, um, issue.
Okay. No. Not DevOps and definitely not, Not DevOps, and definitely not with, uh, new regulation, new, uh, things that AI brings with it.
So I think that we, we've come a long way, as you said, but, uh, I, I wouldn't say that, um, we nail it. Okay. There's still lots of things to, to discover to, Well, the, the thing is, and, and I tried to explain this to someone the other day.
I was talking to a younger person wanted to be in tech. Mm-hmm. And, you know, they were making it like, you know, like, uh, like tech is done.
Not, not that it's over, but that there's nothing new. You know? And what I try to explain to them is no, we, it reinvents itself.
It's constantly changing. It's constantly evolving. Yes.
AI is what we're all I crazy with right now. Right. It's, it's kind of the biggest revolution in my, I think, almost as big as the internet itself maybe.
Right? I agree. Um, but every little piece of it, whether it's DevOps or or, or agile or cloud native as you, you mentioned mm-hmm.
It's all still evolving. Right. And, and we learned this now.
You did a keynote yesterday. True. Here at Swamp Up, you know, most of the people watching this were not here.
Mm-hmm. Obviously that's why they're watching. Um, tell them what you spoke about.
Alright. So yesterday we introduced a new product, a new solution, uh, in the J four platform. It's called UP trusts.
Yes. And I think this is another big step of the evolution that actually shows that DevOps is not yet done. Right.
Um, we are, uh, offering now solution that allows, uh, development teams to manage their applications inside the platform with a clear lifecycle and policies that controls it. So, as you all know, we all manage in one way or another, a lifecycle for software development lifecycle, it's called like that. Yeah.
Uh, but we used to code it, and still it is coded and scattered in many, many places inside the CI where there's no, um, one location that you can control it and visualize it. Um, and this is what we are offering now. So the APTA solution is, uh, built upon three different pillars.
One of them is the concept of an application. So we are releasing applications. All of us application can be a library, it can be a full blown application.
Um, so that's one thing. Now it has a representation inside the j foc platform that you can, uh, you can fully control. The second, the second pillar is evidence.
Evidence is basically assigned metadata or an attestation that you can attach to a binary, to an artifact. Um, now this can be, uh, internal, uh, evidence that the jfo platform generates, and it can be, uh, things that we are partnered with GitHub, like attestations from GitHub that are attached. And it can be any other, uh, evidence.
I can talk about it a bit more later. So that's the second pillar. And the last pillar is the actual lifecycle that you can predefine.
That's my lifecycle. It can be as simple as dev, qa, staging, production, and it can be much complex than than that. And you can customize it per each team.
Now, besides, um, having a clear visual lifecycle, you can put gates, what can get in and out of these gates based on the evidence that I just mentioned. And this, I think it's a big, big change that we are bringing, uh, uh, to the table. Absolutely.
It's a huge change. It, it's a huge change. And you know what's funny?
Is it, it's, it's almost common sense. It makes sense when you explain it. We sit here and say to ourselves, why did it take this long?
That's true. Like, you know what I mean? We, we kind of knew this was what to do.
So you've put good words around the titles, right, right. To the, to the process. But, but this is why when we talk about why things don't are, it's never done.
It's just like we're constantly things that we were apparent but not apparent. Do you know what I'm saying? I agree.
Yeah. It was there, but we never kind of wrapped around. Definitely takes time.
And even for us, it's the second iteration that, uh, we, we tried to nail it and we did a lot of improvement. And that's the second iteration, But that's DevOps. Yeah.
Iterate, reiterate, learn feedback, loop, iterate. Right. Exactly.
And, and that, that's what it's about. I wanna talk AI with you a little bit though. Okay.
So, as I said, I think this could be as big or bigger even than what the internet was mm-hmm. When it first came out. Um, I mean, it's had a profound, if you were on the, you know, I reported yesterday on from the keynotes and everything, it was a lot of ai.
Right. I think Shlomi said, said, if you're not using AI now, you might want to step out. Mm-hmm.
Right? Correct. How is, how are you leading the DevOps team mm-hmm.
Sort of eating your own dog food? How are you using AI to make Jfr better? Okay.
Great question. So definitely, um, JFR was always, um, a company where we had a lot of innovation and a lot of, um, adoption new technology. So we are doing it for quite some time.
Um, like many other companies, we are doing it to increase our productivity, and it's internal, and we are doing a lot of it. And it's very, very interesting. Um, there are also, we are also serving this audience, uh, whether it's the data scientist or the new lops audience.
So we also, uh, providers of solution, uh, to this area. Now, the third pillar is how do we actually integrate AI inside our products? So some of it you heard about, um, when, uh, staff, uh, leader from, uh, security Yes.
Um, mentioned how, how we can provide a mediation based of data formal, uh, catalog. That's, that's one, one offering. The other one was the AI catalog that was also announced yesterday, spoke about it.
And this is amazing. And, and even asked GI folk, we are not huge company. It's very, and we want, as I mentioned, we want to adopt new technology.
We want to adopt ai, but we don't to do it in responsible manner, and we need to help our legal and compliance team to help us. Sure. And AI catalog is one of those solution that, that can help us promote it internally.
So you have one location where you can see all of the models, all of the services, external APIs that you, you want to use. And this is where you can approve it and you make sure it's secured and you can know who's using it. And so I'm very excited, uh, about it, both as offering the Solution I was Too, but also using it.
I, I think this will wind up being one of the big compliance tools because Right. You know, what's this is like, remember when cloud first came out, every developer had whipped out his credit card and, and spinning up instances. Mm-hmm.
They weren't shutting him down, and then they'd submit the expense. Right. And all of a sudden someone would add up and say, oh my God, we got, you know, how much cloud instances running.
Right. I think at some point, what, what's going on now is everybody's experimenting. Right.
It doesn't seem a, like, you pay $20 a month here, $20 a month there, it comes with my Google over here. Mm-hmm. You know, you know, we don't recognize the full scope of, of how much AI we're actually using at the, at the company wide.
Even a small, we're smaller than you. Right. Yeah.
But I see every single one of these people have their own $20 a month accounts. And that's just the foundational models. Then they got video editing, ai, uhhuh, graphics, ai, and marketing ai.
You know, sooner or later something's gotta blow up. Right. Hopefully we'll be there to control.
Well, Unless we do something like this Exactly. Right. That can controls, so we know at least what we're doing.
But here's the other side of that. I know as, as you know, the manager of my team as the CEO of Textron Uhhuh, I don't wanna stifle experimentation. I don't want to crimp their style.
Right? Right. I want them to use AI figure, show, figure out new ways of doing things, how to leverage this to be better.
Mm-hmm. So I gotta balance, right? I don't want to be like the, oh, you can't use that.
'cause it's not in the catalog. Mm-hmm. I wanna say use what you want, just put it in the catalog.
Okay. Got It. Right.
Make sure we know about it. So when something happens, we, we have something to point to. Mm-hmm.
Is what do you see? You have a bigger team than me. What do you see with that?
Let, let me give you an example, which is, um, the reality. So in my keynote yesterday, uh, I mentioned that we have, uh, controls gates to make sure that you, you pass through what we think. I, as a development manager, wanted my team to go through uhhuh testing, coverage, quality, et cetera.
Uh, so for this demo, I asked the team, Hey, I'm going to use Cursor and I'm not going to click a button to, to release it. I'm going to do it like you are doing it. I'm going to tell it, Hey, release it to production.
Um, and they got panicked. Really? Yeah.
Why? Listen, you are going to do a live demo and this agent is not predictable. We are telling you sometimes it works, sometimes, sometimes it doesn't Work.
That's AI today. So my answer was, okay. But that's exactly what we are building.
We are building gates that if it doesn't work, we stop it, we detect it, we stop it, and then we tell it how to do it the right way. Uh, so it's actually was exactly what we needed for the demo. And it's actually what happened.
It Didn't work. Yeah. We till it didn't work.
Like I expected it not to work. Okay. Um, we told it to release something to production, and this is how we want to work.
Right. Future. Yeah.
Release something to production. And guess what? It actually tried to take, uh, from the development, the release from the development stage, and put it right into production, no testing, no coverage, no security scanning, oid.
And this is what he tried to do, and it failed. And that's exactly what I wanted to demonstrate. That's so it was So it actually worked.
Yeah. The failure was a good thing. Yeah.
So that's one example. And then I told it, Hey, make sure you run the test. It figured it out.
And I guess that if we train it more, it'll know how to do it. This is how our team will work. Uh, but that's one example of, of how those controls and the things that we are bringing with the new solution are making us, making it easier for our customers and Taking from the risk gap.
Yeah. That really, because that's what it, you know, it's all about the risk. Um, so I gotta ask you the hard question.
You're probably hearing it from your team. I know I hear it from my team. Mm-hmm.
Are their jobs safe? Is this gonna replace them? Should they start looking for a new career?
What do you think? Uh, so no one knows the future. Okay.
And I think the, the, there are going to be, and there are already happening, a lot of changes in the way that we work. Uh, and some jobs or some roles will either disappear or change completely. Uh, I think that, uh, we are still not there.
Okay. I think that, uh, and, and again, we are adopting it a lot and it helps with productivity. Yeah.
Mainly, uh, it helps also taking the mundane parts of the walk, uh, to someone who doesn't care. Uh, but I don't see it yet replacing, uh, junior developers. I don't see it increasing, uh, uh, 10 times the productivity of the, it's still not there.
Yeah. Um, and I still don't see it happening. However, look at how it looks like two years ago.
So who knows? The advancements are really, really fast, but it's still not there. It's, it's a, now it's a valuable tool, but it's still not replacing, uh, definitely not experienced developers.
But I think it'll always be a tool. Right. And we, and we're humans.
That's what separates us. We're tool users by definition. Right.
Right. That's part of being human. I, I, I think the, like, in my mind, it's going to get better.
'cause you see it gets better week to week, it gets better. Definitely. Right.
I mean, I use it with writing and it's, it's a, it's really getting better every day. However, I think at the end of the day, it's always will be a tool. Mm-hmm.
And it won't replace the spark of creativity that makes a human. Do you know what I mean? I agree.
You'll come up with an idea and it'll help you bring that idea to reality. Mm-hmm. I don't know if it'll ever come up with the idea itself.
Do, do you follow that spark? I, I follow. Yeah.
We'll see. And, and I, you know, I, I wanna believe that anyway. We'll see.
That's exactly, we'll see. Um, I wanna emphasize something we, I asked a few people yesterday, we spoke about, which is all of the stuff you showed yesterday, it's available now. This isn't pie in the sky coming next year.
It'll be continually improved with feedback and everything else, but all of the things that we've been talking about here for two days now, people could go on Jfr right now and go play with it, see it, use it, test it, whatever they want. Yeah. So, So the concept in, uh, swamp up is that, uh, we arrive here, we are ready.
Right. Okay. It's, we're not showing you anything that's pie in This.
Exactly. It's there. Or it's coming in in several weeks.
Right. That's it. So APTA is there.
AI catalog is there. We also spoke about, uh, solution for ID extensions. It's there.
Mm-hmm. Uh, identical remediation is there. Yeah.
Um, I also demonstrated, uh, yesterday on stage we have a new partnership with ServiceNow. Yes. I saw, Uh, this is where we, we are connecting the two words of, uh, it sm Yeah.
ITSM management processes things, amazing things that are done on service now with the evidence and lifecycle management that the DevOps guys are doing. So this is something that we started working, uh, a few months ago after the feedback we got in the LEAP event. Uh, and this one is coming.
This one is in development, or we wanted to announce it to put it on the table because our customers are really excited, really ask for it. And we are working on it. This is coming, uh, later this year, or probably at the beginning of the next year.
Other than that, all there, all the things that we announced are out there. Yeah. Well, Yoi 16 years.
16 years ago, do you think you'd be sitting here at something like this? You never know. You never know, man.
You never know. Hey, congratulations. Thank you.
You've done a great job. It's really fun. Yoi Shaul, uh, SVP DevOps here at, uh, JFR.
We're gonna continue our day two coverage today. We've got more coming. So standby here on Tech Drunk tv.
Let me introduce you to our next guest. His name is Harry Hara. Ragman.
Ragman. Thank you. We're gonna call him Harry?
Yes. Okay. Harry, Harry's a technologist.
He's here, you know, as he's not a frog. He's not part of J Rog, but he's here as a, a technologist with a keen interest in things. And I, I wanted to introduce him to you and give him a chance to talk a little bit about what he's really finding interesting here and, you know, kinds of things he wanted to mention, uh, that he's here at Swamp Up.
So first of all, Harry, welcome. Thank You so much for having me. Yeah, it's my pleasure.
Yeah. Talk to us about what you're doing here at Swamp Up. So, uh, my first swamp up experience was in 2023 when it was hosted back in San Jose.
Remember? We were there. Yes.
I think it was a complete pleasure. I really enjoyed it, and I had the opportunity to, uh, work with, uh, and interact with a lot of jfr, uh, employees and, and to know more deep about Jfr products. And I always asked by to, you know, speak at J Rog.
So this year, actually, I spoke with Jfr on one of the frameworks that I had developed. Um, it was about, uh, optimizing, uh, infrastructure deployments and bringing in both, uh, uh, accessibility, security and speed to them, um, such that, uh, you know, it, the overall time it takes to bring a service to production is rapidly reduced. Oh, yeah.
Yes. So, so you actually took the Jfr platform Yes. And developed sort of your own framework.
That Is correct. That is improving security, quality and Accessibility. Accessibility, yes.
And you did that at your, we're not here talking about where you work or anything like that, but you did that at the place you were working and Yeah. Uh, and, and like what I'm trying to say is you did it in a, a commercial setting. It wasn't just a science experiment.
Yeah. So I think, uh, in one of the previous places I had worked at, uh, it start, we were trying to solve a problem where, uh, we were trying to sell, uh, unified different pipelines, uh, software pipelines. Because in general, what happens is when very large organizations, pipelines can get really fragmented.
So unifying pipelines, uh, is very essential both for traceability and also cost. But at the same time, um, uh, we should also ensure that security is not an afterthought, right? So, uh, we wanted to ensure that like if you take a typical software, uh, infrastructure pipeline, you have the curation process, create creation process, the build, deploy, and then the run.
So when that happens, uh, we wanted to sort of impregnate each of those boxes and ensure that security is embedded in each of, each of each of those layers, uh, while unifying the various pipelines. And, uh, that was done in a very commercial setup, and then I decided to take it forward by also. And that was a time when, you know, open, uh, you know, all the ai, It was just coming Up a all the AI stuff was just coming up.
And so I decided to, uh, integrate NLP based frameworks into that architecture. So very cool. By using, uh, JFR X-Ray and, uh, uh, JFR Artifactory, uh, that helped in optimizing the overall time it took to deploy infrastructure.
So I realized that by, uh, uh, inculcating AI frameworks within into your DevSecOps pipelines, you not only make, uh, AI the whole pipeline safe and secure, but you also make it more accessible to not just engineers, but also people from, uh, other forms of interest. Because, uh, when you have an NLP framework, uh, up in front onto your service, uh, all the requests can be in plain simple English. So that, that's, that, that probably sums it up and paints a picture.
Yeah, No, that, that, you know, and look, and, you know, the beautiful thing as we saw here at this year's swamp up. Yeah. Every day we're seeing more and more AI innovation, more and more AI capability.
True. So, you know, though, you've, so in essence, the framework is never done. Correct.
I think, uh, that's a, that's a great question. I think, uh, it, it's definitely an evolving architecture. In fact, the future directions that we want to take the framework is, um, for example, the, the current framework currently just focuses on ensuring that you, uh, uh, you know, export in software bill of materials and unify the various pipelines.
To put it in very simple terms. Uh, software bill of materials is more about like, you know, imagine like a cake. A cake can have different layers.
Mm-hmm. Each, each layer can have, uh, different ingredients and each of those in ingredients can be sourced from different places. So the, once we unified the pipelines and we were able to generate a software bill of materials, we kinda knew what our software contains.
But then, uh, we, we can extend it to like, potentially like SALSA frameworks that can tell you like what it's made of. And, uh, we could also take it forward by, you know, ensuring that zero trust is embedded into this framework. I mean, zero, when I say zero trust, I mean the five pillars of zero trust being, um, identity transport, authorization, uh, gateway and visibility.
So one way, one way of possibly extending the, uh, framework would be to integrate zero trust in a much more closer fashion. Because when you look at security as a first class citizen, you're looking at it, you can look at it from both, uh, top down and bottom up. Top down is more about ensuring that you use all the latest tools, AI, and ensure that, you know, your software is super secure and does not have any vulnerabilities.
But when you do take a bottom up approach, you take, you put in a lot of attention to ensure that the APIs will develop, are secure by design. Sure. So, yeah.
I love it. If I had to ask you to look into your crystal ball and say, all right. Swamp up 2026.
Yes. And I don't know if you saw, but they announced New York, I think for next year, That, uh, that is true. Yes.
Yes. They had a, they had a, they had a raffle that, that helps us to select which location, but then I think it was New York. Yes.
Yeah. Yes. Um, Where do you see your framework being a year from now?
Uh, yeah, that's a pretty deep question. I think, um, one, we do want to embed zero trust much more closely as I just mentioned. Yes.
Two, we also want to, uh, we had, we had benchmarked our, uh, uh, our framework and architecture with the then available open source AI models. We would probably do, uh, another round of benchmarking to see which it works well with three. Um, we would also do a lot of like domain specific tuning to it, because I've realized lately that uh, there's a lot of power to small language models, uh, as well, because they have a lot more context than, And I, I think we're gonna see more SML Yes.
Over the next year as people realize LLMs are good. But yes, you need the SMLs for some very specific domain expertise. Yes.
So that's what I see the architecture evolving into. Yes. Good.
You know what we didn't mention? Yes. If someone wants to go see this framework for themselves, how did they do that?
Oh, uh, so it's actually, uh, we did have the opportunity to publish this framework, uh, in a conference in an IP conference that happened in Indonesia. So the work actually is public, so, uh, Where can they go? So, I mean, if you follow me on LinkedIn, uh, it's our like Google Scholar that's fairly, uh, easy to find.
Is it on GitHub or anything? No, Uh, it's on GitHub. It's on the IEE explore page.
Uh, okay. That people can, could go and reference. Yes.
Well now you mention your LinkedIn page. How do people follow you on LinkedIn? Just, is it under Harry or, that's Correct.
Yeah. Yeah. Just my first name and last name.
It's ma, easy to find. Alright. There you go.
Thank you Harry. Thank you for covering on Text Drunk tv. This wasn't so hard.
Thank You so much. It was a complete pleasure. Yeah, Absolutely.
Hey, we're going to continue our coverage here at, uh, JFR Swamp Up. Stay tuned. You're watching Tech Drunk tv.
Thank you. Atlassian in the cloud at last T-Mobile's Sky high wifi under the Red Sea Salesforce's lofty hack. Cisco and VAs are gonna team up, is Midjourney at an end and we take a closer look at Google's shiny new Chrome case in this episode of the Tech Field Day rundown.
Hello everyone and welcome to the rundown for September the 10th. My name is Tom Hollingsworth and I hope you're enjoying some Turkey and what are allegedly croutons for lunch because it's national TV dinner day. That's right.
All of your friends at Swanson would like to remind you that those are in fact croutons. If there was ever any doubt in your mind, uh, what there is no doubt in my mind about is the wonderful thing that we have going on today. We call the Rundown.
Uh, it is also National Swap Ideas Day. I didn't swap any ideas though. I swapped my co-host this week because the al's out at uh, AI Infrastructure Field Day.
But joining me instead is Mr. Ned Bevan. Ned, welcome back to the show.
Oh, thank you Tom. It's great to be here. And I had no idea that those were croutons and they sure don't eat like it.
Yeah, I think that's the thing. Is it according to the package they are, but according to my taste buds, they are in fact not. And, uh, the other other thing that I wanna make sure that everybody knows is that the stories that we have are probably even crunchier than those croutons because they are some of the highest quality pieces of news that we could find this week.
And I want to jump in and talk about everyone's favorite company Atlassian, because they've announced that they're retiring their data center products. Yes. That includes Jira, confluence, and Bamboo in favor of something they're gonna be calling Atlassian Cloud with Bitbucket, of course being exception through a hybrid license because of some very sensitive, so source code issues sales of new data center subscriptions end in March of 2026.
Your existing licenses will be expired in 2028 and everything is gonna be done by 2029. So there's your signpost folks, get it done soon. Organizations can migrate using self service tools for smaller teams or using the fast shift program for larger ones.
Some customers, particularly those pesky US government users that have something that they're supposed to comply with called FedRAMP are gonna face a lot more challenges. Atlassian, of course, highlights potential cost savings with the cloud. If you talk to experts though, they're gonna say that most customers could see up to 28% or more on an increase.
The announcement has of course, frustrated users who previously transitioned from server to data center and now they're gonna have to migrate to the cloud again. Ned, do you think ending this in favor of doing cloud stuff is going to be a boon for Atlassian? Or do you think customers are gonna get mad?
Yes and yes. Yeah, I mean, like you said, they'd already end of life their server offering in favor of data center, and it was really just a matter of time till they also end of Life Data Center. They were clearly moving to a cloud only model.
And their claim is that currently almost every customer, new customer, they get signs up for cloud only. So obviously that's what everybody wants. There are two big benefits that Atlassian gets out of this.
The first one is a vastly simpler support model. They no longer have to maintain a version of the software that runs OnPrem and deal with all the weirdness that people have in their on-premises environment. So that's a big boon to them.
I think it's something that Microsoft would love to copy with their, uh, exchange software. They'd love to stop supporting that on-prem and they probably will at some point. The other thing they can do is charge more for features nobody wants.
And that's a pretty common tactic across all of the SaaS companies that are out there. And now that they'll have everyone locked in to the cloud only platform, they can force whatever features they want on those people and say, Hey, we're charging an extra $2 for our new AI widget, whatever that widget might be. I look through some of the subreddits if for Atlassian people are not happy about this, predictably, some were talking about the fact that they literally just finished a migration from server to data center and now they are going to have to undertake that migration all over again.
And if that's the case, maybe it's easier to migrate to a completely different platform. But I think all Atlassian has to do is make the migration to their cloud platform slightly less painful than migrating to another product. And people are just going to deal with the change.
The big question is, can they support FedRAMP? They're promising to have an Atlassian government cloud available in the near future. We'll see how that goes.
That is, um, easier said than done. Let's say Southwest Airlines and T-Mobile announced a partnership to offer free unlimited wifi for all Southwest Rapid Rewards members starting October 24th, 2025. Ooh, so close to my birthday.
Well, they know they could gimme a present. Southwest will become the largest US airline to provide free wifi on every flight available to all members regardless of their wireless carrier. Both companies emphasize their commitment to customer experience with Southwest investing in reliable in-flight connectivity and T-Mobile expanding its history of free in-flight services to millions more travelers.
Customers can sign up for a free rapid rewards account before or during their flight to access the benefit, no word on whether they need to queue up in line to see who gets the best wifi first. Do you have some thoughts on this, Tom? Uh, we're way past that down, Ned.
We don't do that. We're like everybody else. We get on the plane and 19 boarding groups.
And if you're double elite super unobtainium, you get to go on first. And all Southwest people that I I talk to are, are cringing a little bit right now. Um, I I actually welcome this.
Uh, one of the reasons why is because I am now of the belief that why free wifi should be something that is being offered as a perk to get people to wanna use your airline. For those who are not familiar, um, a-list preferred, uh, status members and above have already had the opportunity to get free wifi on planes. This effectively is saying T-Mobile is paying to allow a-list, which is their, their first tier of status to get, um, uh, free wifi.
Uh, yes, it's available to all rapid rewards members. Why would they want to do that? Oh wait, I know they want to collect all your information.
Yeah, so, so you guys know that that's, that's the reason why they want you to sign up for the account, right? Is because they wanna be able to track you and to be able to do all these things. Because it turns out that most people who fly Southwest don't have a status program that they belong to because up until about six months ago, they didn't care because they were using Southwest as a low cost carrier.
They're not Frontier and they're not, uh, you know, um, oh Spirit. Uh, they are slightly better than that. They're Spirit Plus, or at least they were.
And now Elliot Capital Management, the bane of everybody's existence, uh, believes that they should be more than that. But the problem is, is that in order for that to happen, Elliot either needs to nickel and dime everybody to death, or they need to create value somewhere. Well, how would I do that?
I know I'll get T-Mobile to pay us a small fortune to be able to offer free wifi. And because you have to have a rapid rewards account to be able to access it, we're gonna be able to collect data, send you ads through the portal and email you stuff all the time. Oh wait, that's right.
I just booked a Southwest flight today and whenever I clicked finish, I got one of those fun little post-purchase prop popups. Hey, would you like to try two free months of clear on us? Hey, do you know that you can get 50% off of a Sam's Club membership?
Folks, the handwriting's on the wall and it has nothing to do with free wifi. It has everything to do with Southwest continuing to try to, to create customer stickiness in order to get people to stay with them because they're starting to see the customers are leaving. Those of us who have been flying Southwest for a very long time or who have a corporate mandate to use Southwest, I don't know that things are gonna change.
I do like the fact that I can now check my wifi, but the problem is, is now that everybody else on the plane can check their wifi, they're gonna have to do a little bit more on upgrading those things. So we'll see what happens. But until then, bring me uh, the non peanut snacks and a ginger ale and I'll be ready to go.
Undersea cable breaks in the Red Sea disrupted internet traffic in the Middle East and South Asia, slowing some of Microsoft Azure and other services on Asia to Europe routes. Microsoft was able to reroute traffic to keep their services online. But higher latency could continue until repairs on the key cables are finished.
That could take a few weeks while the cause is unclear. Similar incidents have happened before. And if you know that the Red Sea area, you can probably guess where those cable breaks happen.
Most businesses aren't heavily affected, but if you're one of those companies that has latency sensitive services, you should probably check on your systems. They're not okay. This event underscores the importance of network redundancy to keep the internet running during outages.
But I think as we've talked about in the past, it also underscores the fact that some of our infrastructure is uniquely vulnerable to anchors being dragged across the sea floor or, um, unfriendly people in certain countries deciding to just destroy those cables. Ned, do you think Azure could survive a hit like this again or do they need to get that thing fixed really quick? I think they absolutely need to get it fixed pretty quick.
But Microsoft, along with the other major cloud providers have built out their own backbone of fiber all across the world. So they could probably stand to lose a few more cables and still be okay routing traffic. But I think you bring up a good point.
The fact that it does increase latency because now you're packing instead of going to point A to B is now gonna go to point A, C, D, F, G, and then maybe B. So it does have to pass through a lot more routers and in effect travel farther than it did before. And when everybody has to do that, the overall latency of the internet suffers.
That's the sort of thing you can see on net blocks. Who confirmed the outages initially that happened, uh, impacting Microsoft as well as everybody else who was using those cables. Now Microsoft does have some cables that are private to itself, and in those cases, if that cable breaks, it only impacts Microsoft, but it's gonna have to route that traffic somewhere and that somewhere might end up being the dumping ground of the public internet.
So being aware of that and having regional presences that won't get disrupted if your cross region traffic gets cut off or is highly latent. And also having edge presences might be something that you might want to look into as a company, especially if you have satellite offices or customers that are remote to you, and especially around this region, having an edge data center that's close by that's not affected by a cable cut like this would probably be a wise investment moving right along in August. Google's threat intelligence group reported that a hacker group known as UNC 63 95 stole OAuth tokens from the SalesLoft Drift apps, Salesforce integration to bypass authentication, including MFA.
Ooh, that's not good. And they used it to extract large amounts of data from hundreds of Salesforce customers. That's worse.
The attackers deleted query job records to hide their activity and targeted sensitive credentials such as AWS, keys, passwords, and snowflake tokens with the stolen data. But of course, everybody is using dynamic credentials these days that expire after a few minutes or hours, right? Tom?
Ha ha ha. No, no, that's not the case at all. Uh, also, props to the, uh, the hacking group for almost being the USS Thunder, thunder Child from Star Trek.
You, your, your registration number was almost there. I I don't actually know what you were going for on it. Um, this is going to be the biggest, uh, area that we're gonna start seeing A lot of these, uh, breaches happening yet is not kicking in the front door.
It's tailing the, uh, contractors in through the smoker's door, if you will. Um, one of the things that we saw with the Snowflake problems is that a lot of companies were having data breaches, and I use the Quoing fingers there because what was actually occurring was, is that Snowflake wasn't secured, right? Well then it was not incumbent upon these companies to, uh, you know, secure themselves.
'cause they couldn't because it was Snowflake that was causing the problem. So now what we've got is a third party add-on to Salesforce that was breached, that was able to connect back into the system and start harvesting this data. And yeah, this is, is one of the things that we know that these companies love.
Things like, uh, you know, AWS uh, API, keys, uh, passwords, any kind of tokens. I mean, I used a token harvesting attack to get in. Those are very valuable because even if they are following practices and expiring them quickly, it does not take me long to get a foothold.
In fact, as we learned at, uh, one of the presentations all the way back at security Field day one from CyberArk, um, if you accidentally paste an A-W-S-A-P-I key into the wild, anywhere on GitHub or anything like that, just assume it's compromised because those things are gone almost instantaneously. And that's what we're probably gonna be seeing here, is that a lot of these tokens are gonna be attempted to be reuse. Don't assume that these things are valid, just expire them and move on.
But I will tell you that the reason why I know this is a thing is because a friend of mine sent me a text message and it basically said, this was my weekend. How was yours? And it was dealing with the fallout from this because all of these systems being as tightly integrated as they are, whether it is, you know, upselling them into a new license class or my other favorite thing, uh, hey, let's, uh, let's see what AI can do with all of this.
We just need access to the entire system to be able to munch all this data. Uh, we're now starting to see the limits because if, uh, if your AI agents can go do this, guess what else can too? The secret dirty KGB agents of the attackers or something like that.
So, uh, change your passwords, expire all your tokens, um, uh, do not pass. Go trade all your tickets in it, Chuck E. Cheese, whatever you've gotta do, just go out there and fix this because your life will be significantly less miserable if you do.
My friends over at Cisco are partnering with Vast Data and NVIDIA to make it easier for IT teams to run AI applications at scale. By adding Vasts Insight Engine and shared everything storage to Cisco AI pods with Nvidia GPUs, the platform enables fast real-time data access for advanced AI agents. Of course, this is what helps organizations standardize their AI infrastructure.
But challenges like legacy systems, skill gaps and high costs still remain That's gonna be pushing IT leaders to balance cloud fees with a new expense of on-premises hardware net. I know that you have probably immersed yourself in all of the wonder that is ai, but I have a question. Will being able to add these features to AI Pods really encourage people to start investigating ai?
Or is this just another thing that a few people wanted and they figured they'd put it on the truck? Hmm, good question. I'm not sure.
I'll ask chatt PT and let you know. Seriously though, I think that if you are an enterprise that's championing, championing, that's a word, AI right now, one of the things that you're trying to do is supplement the existing models with the information that exists inside your organization. And that's usually done through RAG or retrieval augmented generation.
That is something that makes AI notoriously data hungry. It wants to vacuum up all these data sources, but it can't, you can't just point it at a file share or a database or a repository of objects and say, go look through all this and tell me what you find. It actually needs to transform that data into something that AI is able to incorporate into its existing model.
And that's done through Vector databases. What Vast is offering here is not just a storage platform, but also the data pipelines to do that transformation of structured and unstructured data into vectorized databases that can then be incorporated into the AI model. And so it's this tight coupling between Vasts storage, it's operating system, they call it an AI operating system.
And its insight engine tying back into the GPUs, the Nvidia GPUs that are gonna be inside these UCS chassis supplied by Cisco. So I think Vast is the, is the secret sauce here. I'm not gonna say that Cisco doesn't make cool hardware 'cause they do, but it's really like Nvidia and Vast and Cisco supplying the box that they get to party in.
That's what we're looking at here. If you're in the market for this integration of your enterprise data into AI models to try to surface some additional intelligence or something along those lines, this might be very attractive to you, especially if you're already a Cisco customer. Dell and HP already have similar products that implement similar features, and I think the big thing is probably the GPU and, and the storage, and less so the compute that sits behind it.
Warner Brothers, speaking of ai, Warner Brothers has sued Midjourney joining Disney and Universal in accusing the AI company of profiting from image models that generate copyrighted characters. The complaint claims midjourney let users recreate characters like Superman, Batman, wonder Woman, Scooby-Doo, bugs Bunny and Rick and Morty in any scene violating their intellectual property rights. No word about scrappy do though Warner Brothers argues that Midjourney knowingly removed copyright protections, continues to produce countless infringing images and must face a permanent injunction injunction to stop the studio also seeks profits Midjourney allegedly earned by exploiting its characters, following the infringements, intentional and ongoing.
As someone who has managed to use various AI tools to create copyrighted material, this is definitely a thing that you can do. I'm not sure that Midjourney is unique in this regard. Tom, do you have any experience with it?
Yeah, actually I do. I'm gonna take you back 21 years. Oh dear.
There was this Multiplayer online role playing game called City of Heroes, near and dear to my heart. You could log in and you could be a superhero. As I told our good friend Ethan Banks one time, the way that I like to relax after a long day of doing it is throwing fireballs at people's face.
And he goes, I never thought about it like that. You had a character creation system. It was one of the most impressive character creation systems that it was available at the time and you could do pretty much anything you wanted.
So what was the first thing that everybody did? They logged in and they made a character that wore blue with red underwear on the outside and the Long Red Cape. Or they made a gigantic character who was bright green and liked to smash things.
Now notice that I didn't say any of the names associated with those characters, right? That's because you could make something very similar to a man who is potentially very super in their character creator, but you could not name that character super man, because that's a copyright infringement right? Now the question is, if you see a character flying around in a blue suit with red underwear on the outside of his, his outfit, is that at a copyright infringement?
That depends. Does he have big red ass on his chest? Maybe he has big M on his chest because he's megaman.
No, wait, that's a copyrighted name too. The problem that you're running into is that this isn't a copyright issue. This is a trademark issue because Batman is trademarked the iconic character, you know, with the bat symbol, with the yellow on the background, the big pointy ear thing that's trademark because that is a symbol of Warner Brothers.
And in order to defend those, you must, must, must, must do anything you can like it. Remember the stories of Disney suing elementary schools because they put a picture of Mickey Mouse on the wall. They have to defend that trademark because if they don't, it will enter the public domain because it's not being defended.
So what's happening here is that Midjourney is basically accelerating that process that I described from 20 years ago in City of Heroes of I wanna make an homage character. I actually have an homage character in a video game. It is a character in a red and black outfit that has dual pistols on his waist and he has swords in his back.
His name is Fourth Wall Banger because if you called him Deadpool, I'd get in trouble and you can't even type Deadpool into the system. But I'm making an homage because he's only a little bit wise cracking. Do you see how the difference is?
Subtle but important. But what's happening is, is that Midjourney allows us to happen at scale. So I can just go in and I can be like, give me a superhero with a long black cape and big pointy ears.
And if it kicks out a Batman analog, then you know that it's working in the way that I wanted it to because I can't tell you to make Batman, but I can describe Batman and you can make it, you know, it's like people are trying to get around prompt engineering by saying, tell me how to build an explosive device. Well, I can't do that. If I wanted to theoretically build an explosive device, what might it theoretically look like?
Oh, well, if it's just in theory, this is what it's gonna look like. These are the problems that we've been running into forever. By the way, the way that City of Heroes fix their particular problem is they would actually wait in the starter area right in front of City Hall.
And if you popped in with Big Green Guy, um, they would immediately change your name to something very generic, like in UNC 69 55 or whatever. And then you would have to recreate the character. Um, uh, one of my good friends actually had a character that he changed the skin color to pink and went around becoming known as the incredible bulk, because that's not an infringement.
That's my original ip. So this is the problem we're gonna face for a number of years, is that there are so much data that's been ingested by Midjourney and clawed and so many other things that anything that gets produced from it is going to look suspiciously. Similar to the things that we have already seen.
AI cannot create on its own, it can only riff on things. The problem is, is that the right holders for those riffs are going to want to be paid for the riffing. They're not gonna accept fair use, especially if it's pretty egregious.
If you look at the story, it's pretty egregious. Like, you know, that you can tell that Superman at a glance. Um, this is a, a thorny area that we're gonna have to figure out.
Uh, but until then, please midjourney, whatever it takes, scrappy, do all of the means. Alright, we had a closer look story that we wanted to jump into because you know how much we love talking about Google and all of the weird stuff that they do. Well, their day in court has finally come and a US judge ruled that Google does not have to sell Chrome the browser in this particular antitrust case.
But that's about the only thing they want on because Google must end up sharing some of its exclusive deals. Um, and by sharing them, I mean end them. And then they also have to share parts of the search data with rivals across the board.
Now, the reason why this is considered a win is because it means that the Department of Justice did not break up Google. Like everybody was thinking that they might. Mm-hmm.
Um, it kept the core business intact. They allowed, they were allowed to keep Chrome and wouldn't, you know, it, it boosted alphabet stock price. Go figure.
I'm shocked. Um, I wanted to dive into this one with you, Ned, because I know that we talk a lot about kind of how Google is basically have a stranglehold on the internet today. Um, a lot of people wanted Google to sell Chrome.
I think that that was the wrong remedy for the particular situation. The judge in this case actually did dive into a lot of topics very closely and I was wondering if maybe you could kind of give us your take on it. 'cause I have some thoughts, but I wanna hear what you have to say first.
Yeah, I mean, Google was found guilty of having a monopoly over advertising and search. That was the, the finding from last year, I think sometime in August of 2024. And so now it was up to what's the remedy?
What should we do about that? And a lot of people, including the Department of Justice, were pushing that Google have to divest from Chrome and Chromium and also potentially Android. The judge who was looking over what we should actually do said, while that is a potential remedy, they did not feel that it was necessary and that it would have the intended effect of breaking up Google's monopoly and allowing other entrants into the search.
Although search is driven through Chrome and Google does set up Google search engine as the default search engine on Chrome, forcing them to divest from Chrome wouldn't necessarily change that fact. And it would also force a worse user experience on the customers who are using Chrome today. And generally the yardstick that's been used for Monopoly is what is the impact to customers, not the market as a whole.
If you're negatively impacting customers by the presence of your monopoly, then then something needs to change. But if you have a nice monopoly and your customers are doing great, then the Department of Justice has mostly turned a blind eye to it. And so the finding was stripping them of Chrome that's not gonna do anything in terms of this monopoly.
Instead they went for other remedies like barring them from having exclusive arrangements for search and advertising. Now that doesn't mean that Google is barred from making payments or offering other consideration to their distribution partners or even preloading the placement of their Google search. They're still able to do all of that.
It just can't be exclusive in the contract. It can be exclusive in practice, but it won't be exclusive in the contract. Do I think that this is enough to actually end Google's monopoly on search?
Not even close. I don't think anything that they're doing in this decision is actually going to materially hurt Google in the long term. 'cause it has extended such a lead in terms of search monopoly terms.
There would have to be a sea change for that to occur. And I'm curious what your thoughts are on what would actually need to be, need to happen as a remedy for this situation. I think the judge realized that the remedy to fix Google searching problems is already happening and she can't do anything about it or he can't do anything about it.
I forget who, who the judge in this case was. So I absolutely agree with you. Chrome is not the problem.
Chrome is the most visible, um, expression of what goes on because we use it all the time. But I see this problem on Firefox, on Safari, on edge, whatever The problem is not that Google has control of the browser, the problem is is that the browser effectively uses Google services for everything else, right? Gmail, search, web ai, there's your problem.
The way to unseat Google is the king of search is not to break up their monopoly. It's to find a different way to search. 'cause if you go back in time long enough, Google was not the king of search.
I have used Alta Vista, I've used Ask Genes, I've used tons of things. What ended up happening was is that Google got better than all of them. It was only when Google was in the front that had decided to use that power for their own ends.
The only way to break that is to find a different paradigm, a sea change, if you will. And I think that's what AI is because that's one of the reasons why Google is scared right now. They're seeing dropping ad revenues because people aren't clicking six pages deep into a Google search anymore.
They're not even clicking on it. They're going to that box and saying, typing in their question. And AI is returning the result at the top.
So nobody sees these ads, nobody sees this product placement. And the judge said, well, I'm not gonna slap your hands for paying $20 billion to be the default search engine for an iPhone. What I'm gonna say is, is that that can only be the case if you continue to pay.
There has to be a way for other people to be a part of that. And I'm gonna try to level the playing field. This goes back to a story we talked about, uh, it was either last week or the week before where uh, a certain um, uh, rocket ship maker and electric car manufacturer was very mad that, um, oh, his competitor AI Pro platform was the one that was the default in iOS.
And my response was, well then why aren't you paying to be on the list? That's basically what they're saying is you can be on the list if you're willing to pay. And if you remember from my rant from back then, my rant was Internet Explorer in and of itself was a really crappy browser.
It just so happened it was on the desktop in Windows 98. That's why it became the dominant browser. When you had to go out and download Netscape Navigator by using Internet Explorer to find it, it kind of became a no-brainer.
One of the reasons why I still use Safari on my Mac is because it's included in the operating system. Yeah, I use Chrome for a lot of other things too, but I am a person who's gonna switch back and forth to use what I need. Most people don't.
They pick one and they go with it. When I install my mother-in-law's computer for the 45th time, I'm gonna put Chrome on it because it's what she's familiar with. Google is not the enemy.
What Google did to the services on the backend is the problem. And like you said, monopolies are only useful if they benefit society. Google monopolizing ads, you can argue it didn't really benefit society, but you can't break that up legally.
The legal remedy just means they're gonna find a way to transform what they're doing. And then the two pieces are gonna become competing companies that are just gonna get bought again later. Don't believe me.
How many phone companies do we have in the US right now? How many phone companies do we have in the US In 1982, all of the baby bells are reassembling to become Bell Voltron again. And Ma Bell is getting back together sooner or later because that's how all of these things work.
That is how capitalism works. We reward the people who find the best way to make the most money and Google did. And now everybody's mad because they don't have $20 billion to pay Apple or Google to be the top search engine result.
So I don't know how we're gonna fix this, but I also don't know that it needs to be fixed because the paradigm shift is happening as as we speak. And I think AI is the way that is. That whole thing is gonna be broken up.
I think the problem with the monopoly was they didn't really address the core issue is the fact that Google owns both sides of the ad business. There's the selling ads to those who want to present them, and then there's the presentation of ads. The, the auction that happens every time a page loads that has Google ads on it.
Those are two separate products, two separate offerings. They used to be separate companies that Google bought and brought in-house and then they were able to set up this agreement between the two businesses basically locking everybody in and punishing those who tried to go outside of their walled garden. I think the Department of Justice could have forced Google to break up those two portions of the business and saying these two portions now just need to spin off and become their own distinct organizations.
Kinda like breaking up Ma Bell into the baby bells. It would've been extremely disruptive and the court basically said, breaking up or hurting Google might harm customers. And since the court cannot predict the future, it is opposed to making these sweeping changes that would disrupt the market, the market, which is still currently a monopoly.
So if you think monopolies are bad, if the court didn't go far enough because it failed to break up the monopoly, if your perspective is, are customers going to be more hurt by this disruption in the short term? I'd say probably would there be a bigger benefit in the long term? I can't say for sure, but I generally don't think monopolies are good for capitalism, the free market or for customer experiences over the longer tail of, of a particular service.
Fortunately, I think you're right. Slowly we're gonna see search replaced by Gen AI once it gets at least a little bit better. And the way that they choose to serve up ads is going to have to change along with it.
Right now chat GPT doesn't serve me up ads. There's good, they'll, they will find a way to monetize it, but right now it does not. And I'm one of those weirdos who pays to, uh, coy for my searching.
So I'm actually paying for a search product anyway. So I don't see the Google ads as much, but I think yeah, Google's gonna have to fundamentally shift the way that they make money within the next 10 to 15 years. But it's gonna be a slow shift as the new generation comes into its own and adopts these other ways of searching the internet for whatever it needs.
I think we're gonna be talking about this story for a few more months to come. 'cause we haven't heard the end of this. No, but you also haven't heard the end of tech Field day yet either, because as I mentioned at the top of the show, my regular co-host, Mr.
Alistair Cook, is out in Silicon Valley right now doing AI infrastructure Field Day. com for the next couple of days to learn all about the cool stuff that he's talking about. Then you get to hear from me in just a couple of weeks because I'm gonna be out in Silicon Valley doing Security Field Day.
We have a great lineup of presenters including first time presenters, one password and Square x. Make sure you head over to Tech build do com to see a lineup of who's gonna be a part of that. Then I have a special event coming up on October the ninth.
We're gonna be doing a special exclusive event with Microsoft where we're gonna be doing a virtual discussion about Microsoft Sentinel, which is, uh, you know, exciting, uh, security, kind of focused in the cloud, doing some other cool stuff. Um, they're gonna be talking about it on September 30th at one of their events, and then we're gonna get them the next week to talk more about it. So make sure you stay tuned and be ready for that.
Then Cloud Field Day is taking place October 22nd and 23rd. Um, Alistair's gonna be talking to some great cloud companies and having a lot of fun. And then at the end of the month, get your costumes ready and all of those spooky things because Steven is gonna be talking AI at AI Field Day on October 29th and 30th, and I can't wait to see what he has in store for that.
I'm sure it's going to be scary. We're not scary though, because we're always here for you on the rundown. And we wanna thank you very much for watching today.
Catch our episodes every Wednesday on YouTube on our website if you wanna read the show notes or in your favorite podcast application of choice. The rundown is also being streamed on Techstrong tv and you can catch us on other Techstrong or future group programs. I'm now happy to say that I'm gonna be on Techstrong gang, uh, you offering my perspective on things and maybe an opinion here or there.
You you never know. Uh, don't worry about us though. We're gonna be back next Wednesday with all of the great IT news that happened in the past week until then for myself, Tom Hollingsworth, Al Cook, and for Ned Bevan today, thank you very much for tuning in.
We sincerely appreciate it and we hope that everyone of you out there has a great time as almost a great time as we had making the rundown today. We'll see you next week. Hi, my name is Kina Brookfield and I'm part of the technical marketing team in the VC of division at Broadcom.
And in this session we'll be talking about VMware Cloud Foundation nine and how we've built a private cloud that is made for all of your applications, whether those are running in virtual machines or in container, and what you need to really support all of your workloads with Beware Cloud Foundation nine. We have promised you that we will deliver a private cloud, but what does that actually mean for your workload? Well, when you think about it, it's not simply just about deploying virtual machines or maybe deploying some Kubernetes clusters and applications running in containers, but it's really about emulating that cloud experience on your premises in your private cloud.
And in order to do that, we needed to build something more robust, something that gives you services that you need to support your workloads. So whether you're talking about cloud services, infrastructure services, or any kind of additional functionality, that's the kind of experience you would expect from a cloud, especially from the perception of a consumer that is coming into the cloud to deploy their applications and have everything self service and on hand. And that's what we will focus on, uh, in the following slide.
So mainly in order to unlock this cloud experience for all of your workload, whether those are virtual machines or containers, containers running in Kubernetes clusters, we had to come up with a unified way of controlling everything that's running in the ecosystem. And the way we've done that in VCF F nine is by embedding this declarative API, which is called V four supervisor, which exposes a desired state ecosystem with an API and a set of services that you can use to support your workload. So whether you are deploying virtual machines, Kubernetes clusters, containers, or any other services that you would need, because for your applications, you may need a load balancer.
So we do have a network service that comes in the platform. We also have volume service if you need to be deploying any persistent volumes, but also additional services. For example, if you want to store your containers in a private image registry, deploy harbor on a platform.
But the main idea of this ecosystem is that it is extremely plugable. And what does that mean? While we know that there are some core services that we need to offer out of the box, we give you the power to choose and select what capabilities you want to bring into your ecosystem by selecting services from our catalog and an easy way of introducing new functionality onto the platform.
But the best thing about this extensibility is that having the same target and the same ler API guarantees that you will have the same consumption experience as well. So we're no longer talking about integration points, but the native deployment of functionality into one location. And also importantly, especially from the consumer experience and again, a cloud experience on your platform, we are extracting away all of the underlying infrastructure.
So a consumer really doesn't need to know anything about, uh, about compute or storage or networking in order to be able to fully self sufficiently deploy applications, uh, and any services that they need. And in order to see this, um, I will guide you through a set of demos. So at first we will look at some basic workflows like deploying a virtual machine or deploying a Kubernetes cluster.
What I really want to highlight here are mainly the new things that we have introduced in VCF nine. Then we'll look at how we can update some of these services and how does this lifecycle of, um, these Kubernetes service, for example, specifically work. And then we'll talk about something that brand new, uh, just recently introduced and very exciting.
And that is our own GI op service. What we have done is we have introduced Argo CD service into the platform to give you that continuous delivery. And we'll end with a little demo about updating the supervisor itself because I want to show you how you can unlock this new functionality really easily on your platform.
So here we'll start in my lab environment, uh, where I will show you how a setup of VCF nine would look like. So from a consumer perspective, I'm accessing VCF nine through our automation portal, which is brand new and fully changed. And all I have to do is define my organization name that I have here and a username and password that was given to me to access.
And as soon as I enter, I can see everything that I need to see as a consumer. I can see, uh, overview of services that are available to me. I can see utilization of the space, but I can also see all the projects that, um, I'm member of namespace that have been created here and any users that are part of this.
So let's use this single user interface to deploy workloads and we'll start with a virtual machine. Under services, you will see the main services that are exposed to you, one of them being the virtual machine service. So here we're going to go ahead and create a virtual machine.
And here we can choose whether we're deploying a virtual machine from an OVS template or now also with VVCF nine. We can deploy directly from an iso. I will give my virtual machine a name and I can also select this zone where I want this to sit, and an image that will be used as a base.
So in this example, I will be deploying buntu. I will then configure hardware resources of this virtual machine by selecting a VM class. And I can continue, I I, since we're showing this from a consumer level, I take what we're seeing is like a curated view, uh, set up by an admin or something so that the services that this user can provision and administer are, are limited to whatever they has been decided they have access to.
Kind of like how we have public cloud governance, now we have it for private cloud. That's absolutely correct. Everything I'm showing you now is the consumer experience.
So the user who is deploying the workload, what I will show you as well is the other side, what's in the background. And that's the part that the cloud admin would set up because exactly, we need to have the governance and policies to select what can be deployed on the platform, what is available to the users. So absolutely that is controlled by the admin.
Thank you. Uh, so in this flow, if I wanted to, I could also directly access some of those other services I was mentioning. So for example, if I wanted a persistent volume, I can directly, uh, request it in this flow.
And similarly, if I would want the load balancer to maybe open up some ports on this virtual machine and from them by a load balancer, I can do this in this flow. So it really shows the nice integration of the platform. Again, completely abstract it for me as a user, but the part that is the most exciting one is always the full customization of the virtual machine I am deploying.
Because I'm not just creating a Shell virtual machine. I have the possibility to pass through cloud in IT and do a full configuration of my vm. If I would be deploying Windows, I will be also using spr.
And one of the new things that we have introduced as well is to give you a little bit more guided inputs into cloud in it in case you don't have a full configuration at hand. So this is really simple. For example, what I can do here is I can create a new user.
So what I will do, I'll create a new user that's called DevOps. I will enable the user to log in with SSH, and then I can add comments that I want to run during this first boot of the virtual machine. So for example, here I will show how I can deploy A-C-L-I-V-M and install all of the tools that I will be using later on.
So for example, our brand new V-C-F-C-L-I that I will show you a bit later with all of my command set there, I can continue with the configuration. The avenue thing that we have introduced, and this is really exciting as well, is the ability to do more network configuration during the deployment phase. And especially because with our new integration with VPC, we have much more control over networking.
So as a consumer, again, I may decide to create my own VPCs when a public subnet allowing me to access this virtual machine on an external IP address, because normally everything would be deployed by default into private subnet. So I will show you how to switch this into public. And then again, we have few more options we can do.
So we can pass through configuration, like for example, the host name, domain information and DNS and the full configuration of this virtual machine. Because keeping in mind this is all, these are state has been written fully automatically for me on this right hand side, not just for the virtual machine, but for any objects that I will be requesting in this flow. So I don't have to know the structure of this YAML file.
Um, I don't need to know how to, uh, um, how to add all of the options. It is done nicely for me. Do we have any place, uh, to keep a centralized secret management or we have the secrets in some files, um, just storing our own solution.
So we have just introduced again and VCF nine, our own secret store where you can create secrets, um, and store them centrally, uh, manage them with policies and governance and then inject them into any workloads we're deploying. So whether that's virtual machines, um, containers running down, uh, vs clusters or in these per port. So there is a brand new service, um, that is available on the platform, again, can be introduced.
And then within the services there would be a special, um, tap for secret management. So we will now, um, download these files and just continue to deploy this virtual machine. Once it is deployed, uh, we can see it was given, uh, an IP address as well.
And we can see some basic things in the, uh, user interface, like the opening remote console or for example, we could do some data operations. For example, if you want to recharge the virtual machine, you can change the VM class to, uh, maybe give it a bit more CPU or memory. But what I'm going to do now is grab that external IP address and just directly SSH onto this box using the user that I have created during the guest customization phase.
So we can see that that's working fine. Now I can show the versions of the commands that, or of the utilities that I have installed in here. So we can see that the full configuration that I've passed through has worked well, but there was a virtual machine.
And the topic here is we're talking about this unified platform for everything. So now we're going to use the same experience, the same user interface to deploy Kubernetes cluster. And in here when we deploy a new one, we can select default.
I'll get to that in a minute, or a custom configuration, which can show you, um, uh, more options. I'm going to give my cluster name and then I can select a release that I'm going to use to deploy my cluster. So for this demo, we're going to go with version one 30 team.
Following this, there are more configuration options that we have added to the user interface. So for example, if you want to control your certificate workation, you can do it directly here, um, or some advanced networking options. Uh, during standard configuration, we continue with the configuration of a control play, where we can choose from photon or Ubuntu operating systems.
And then moving on to our workload, uh, to our work, no work note. So in here I'm going to create a note pull. I can select an operating system.
So as I mentioned, for example, in here, I'll switch to TU if I wanted to. I can also follow our processes to deploy, uh, or create my custom image for Windows. If I would have any Windows containers, then I will be able to deploy Windows-based work noes.
The control plane of the cluster would still stay, uh, Linux-based. And some of the new things we've added here, for example, if you want to add any labels to your nodes, you can do it directly. Uh, again, in the user interface, which is really neat.
With VKS, we really try to give you and give the consumers a service that is really easy to operate, but also has a lot of functionality. And it's really up to you how you want to create your clusters. If you want to create clusters of different versions, what kind of sizing you want to do?
Small clusters, big clusters, depending on your need. So for example, if I wanted to, I could mix and match the operating systems. For example, I could add another note pool with different configuration or maybe different operating system.
So that's always, uh, available to me. And again, the full customer's, uh, full specification has been created for me with all of the fields. But always keep in mind that this is just a subset of what is available in the actual API.
So, uh, for example, one of the use cases I do all the time, it's also great if you need to create a structure of your cluster to have the base. If you then want to go on and add some advanced features that are not exposing the ui, you can do that directly by, um, uh, using, for example, the CLI to apply this, um, and add the configuration that you need. But again, same as we did with virtual machines, I'm going to download this because we'll get to that later.
And now I can just wait few minutes until my cluster is ready. Once it's done, I can download its cube config file if I want to, um, to have access to that directly. I could also do some data operations on this cluster.
For example, if I wanted to add any persistent volumes as an addition, I could do it as a data operation. If I wanted to do any scaling, it's extremely simply to do it with simple to do it with VKS, all I have to do is edit. For example, my note pools, same, the number of replicas, scale out my cluster.
Very, very simple to manage, um, and operate. And what's also really helpful is that, again, in the same view, I can see all the resources that were deployed for my cluster. So for example, every Kubernetes cluster needs, um, needs a load balancer, uh, that is fronting the fronting the control plane.
Um, and we can see that the network service here has automatically created that for us, and we can see the external ip. Good question about, um, the, uh, east, west, um, traffic between cluster. Is there any service mesh or something similar, um, implementing or in this ui?
So it's, is it difficult to bring those, um, one or more cluster with service? Meh, you know, and, uh, is this, uh, uh, UI solving this problem or, uh, just reduce the complexity to manage, for example, uh, uh, meh, a measured cluster? Mm-hmm.
Uh, so I have, uh, several answers to that. Um, maybe depending on what exactly, um, is the end goal when it comes to service mash. What we did introduce in, um, in the latest release is support for Istio, um, which we deliver as a VAS, uh, standard package.
Okay. Um, that you can install on the clusters. As far as the user interface, uh, in this particular place, um, it will allow you to deploy Kubernetes clusters.
It does not give you user interface directly into the cluster if that is what you are referring to. However, we also have our case cluster management, which is bringing a lot more functionality for the kind of multi-class management policies, um, and things like that. Yeah.
Um, yeah. Thank you. Um, yeah.
So, uh, within the, uh, uh, user interface, what I just wanted to show you, because our vks clusters are deployed as virtual machines in the background using VM service. So the platform is using itself. You can see those listed as well on the virtual machines.
If you want to, you can filter them out. So we can see our clusters here. And now we can use our new CLI that we have introduced called V-C-F-C-L-I to work and manage, uh, work with and manage this cluster using this cluster plugin.
So the first thing I, I will do is I will register my cluster and I will get its cloud config using the CLI, and then I can create a context, uh, for this cluster. This will allow me then to switch back and forth between my vSphere known space context, where I'm deploying the cluster and the cluster itself. Um, so in here, uh, we have added the new context, then we can just switch into that.
And once we switch into the context of the cluster itself, we can use our standard QCTL commands to, for example, list the note, uh, regarding those packages that I've mentioned previously. The way we, uh, do package management on our Kubernetes clusters deployed with VKS is again integrated with this V-C-F-C-L-I. So all we have to do is add a package repo or package repository that we, um, continuously update and add new functionality into.
So I have added the latest, and then I can list all of the packages that are available for me to install in my B Cs cluster. So as you can see, there's, um, there's packages we've had for a while, but some of the new things I'd like to mention, for example, with autoscaler, we now have support for, um, uh, scale down to zero on worker. No.
Um, and one of the new, uh, packages, as I've just mentioned, is Istio coming, um, into this. So you can go and, um, deploy that. But what I wanted to show you now is, uh, as, as we have seen, uh, in this demo, we have deployed a cluster.
We've deployed the latest version that was available to me as a consumer, but the version that we have deployed was Kubernetes version, um, one point 32. 4, which supports Kubernetes release one point 33. So what I can do as a consumer is I've switched my context back to my namespace, and I can list all of the Kubernetes releases that are available in this space.
And what I will see here is that I do see one do 33 listed, however, it is marked as false, which means that it is not compatible. And this is because the version of the service needs to match, uh, and unlock this functionality. So from a consumer perspective, I can see it's available.
I can ask my cloud admin to update this for me if they haven't already done it. Uh, but I do have a full visibility of all of the releases that are available. This is because we distribute all of our v Kubernetes releases, VK using a subscribed content library that we create by default.
So the images are already there and ready to use. We just need to make sure that the version of the service is updated. So in order, I'm sure I heard you're right, uh, you said that if I, as the consumer want to get to that latest version, I have to ask the admin to, to upgrade, and I cannot do it myself.
That is correct. And that is by design, because as, as we've mentioned, uh, the cloud admins are the ones who have the actual access to the infrastructure. As a consumer, it's completely abstracted for me.
So I do not see it. And also, I may not know what the policies are. Maybe there's a reason why certain, uh, versions would not be allowed or maybe, uh, this, there may be multiple organizations using, um, using the service and, uh, need to align on the version.
So it's the governance of it stays with the cloud admin. Would the same be true for deploying a new application on a new Kubernetes cluster? Like, Hey, I wanna deploy a new one.
I want to, uh, cluster with the latest version. I, I need to request that through the admin as well, Uh, application onto the Kubernetes cluster. Specifically, If, if I am deploying a new an application and I want a new Kubernetes cluster at the latest version, is that also a request to the admin for me as the consumer?
Um, as as far, um, as soon as the, uh, cloud admin, uh, uh, updates the service version, which I will show you now how simple that is, we will see that you will immediately see, uh, 1 33 listed, and you can then go ahead and deploy clusters, uh, as you, as you want to. So from the cloud admin perspective, now I switched over to the kind of vSphere view. Um, we will see our namespace with the resources, and then we can go into our supervisor services, which is, which is our, uh, which are services which have their own lifecycle management.
This is what gives us that ability to release new versions of VKS so fast and so rapidly to be able to give you access to new versions of Kubernetes really quickly. 4. So all admin has to do is go and grab a definition file, uh, that defines the version of the service.
This is now located on our support portal. So all they have to do is go in and download this simple file, save that, and now within the service, they can just grab that file, upload it, they don't have to do any changes to it. We finish.
And this will add additional version that will be available for installation. So we will see the active versions zone two, three, and now if we go to manage, we can select the version we want to install. 4.
So they just select the version, select the supervisor, and then, uh, uh, continue the operation without having to do any changes. That's all they have to do. So it's really simple for the admins to, uh, manage this.
And as soon as the services configured, we can go back to the command line, and now we can see that the status has changed to true. And if we go back to our user interface, so again, you can see we've already have that version 1 32 there. But now when I go to deploy a new cluster, I can immediately see that version 1 33 is available.
I have selected a default configuration because that automatically selects the latest version that is available in here. So we can see it in here. We can also see it in the spec.
So this is happening at the same time. The admin has updated the service as soon as the service is updated, because I already have the images available anyway, uh, they are now unlocked, I can straight away go ahead and deploy this latest version. So I'm just going to click finish and deploy this.
So again, the service does not affect all of the clusters that are in the infrastructure. It just gives you the ability to use those versions and also brings new capabilities. Uh, for VKS itself, Uh, when I'm, uh, from the user perspective, uh, can I update this cluster?
When you add this version, uh, to this, to the pool, let's say I can update the older cluster to the newer version by myself, or still I need to ask the, uh, let's say administrator, provider administrator. No, no, no. Uh, as soon as the version is available for you to use mm-hmm.
As a consumer, you can use it. So yes, you can update all your clusters straight away. Use it.
Nice. So, so it's, it's really just that governance of the service, because as a consumer, I don't have access to that infrastructure and that by design, that's why the cloud admins do that, do the task. But as a consumer, as soon as that's done and that's done once, as soon as that's done, I can go deploy new clusters, update my existing clusters.
Um, that's fine. One thing I would mention though, which is, uh, also important is that we have changed the way we do our cluster class, which is, uh, defining the cluster, uh, setup. Uh, and it's now version.
So we will not trigger and update automatically to give you more, you know, more, um, control over this because you may not want to update everything, uh, by default. So your existing clusters will not be, uh, updated unless you specifically select to do that. So in here we have an overview of everything we have deployed so far, but the really interesting thing, and this is completely brand new, is the possibility of doing some more advanced GI UPS patterns.
So what I want to do, uh, in this section is show you how we can work with Argo City Service that we have just introduced. The first thing that I'm going to do is I'm just going to create an additional, uh, namespace or test, um, in this project just to have a separate space where we will deploy the same workloads that we have done, uh, previously. That's the reason why I was downloading all of those yamo files.
You'll see that will completely reuse them. So what I do here, again, from a consumer perspective, there's, there's things that have been configured for me. So the namespace are defined by a namespace class, which dictates which VM classes are available to me if there are any CPU memory limits, for example, reservations, access to storage and, and, um, everything like that.
So back in our CLI, we can now check what is available in terms of I cd because again, this full ecosystem is, um, Kubernetes based clarity of API, which means that all I can do is just list all of the CRDs that are available to me and really specific, uh, information about, um, all the APIs, uh, as a consumer correctly. And then I can see what's in there. For example, here I can see that Argo CD service has been added and the version that has been deployed.
So all I have to do now is to deploy an instance for me because the service itself is operator, uh, model. So the, for example, the cloud admin would deploy Argo cd, uh, service, which is an operator allowing consumers to deploy their own instances of Argo C. So I have a very, very basic, um, definition of an instance just to show you how simple it is.
You don't really need, um, any major configuration files. It's pretty much just name and, uh, version, which we've seen. And I'll apply that and just wait a little while for these bots to get deployed.
Once everything is running, I will check the service to get the IP to access, um, the server or the instance that I have deployed. 'cause again, that's a load balancer that's providing the external IP address for access. And then by default, when you deploy something like Argo cd, it has a default admin user and its password is stored in a secret while I'm just getting that out of there.
And with that, I can just test that. I can now access there. So using that ip, and as I said, the default user here is admin.
So I'll just take that, the account and, um, directly in, but that's not all because we are also providing, um, uh, during our, your download, you can also get the I-C-D-C-L-I to be able to manipulate it, um, using CLI, if you prefer that over the, the web user interface. So I'm just going to install that on this box and I have it fully available to me. I'm just going to grab the secret and the service again, because what I'm going to do now is use that Argo C-D-C-L-I to log in to that instance.
So I'm just going to give that the name and again, the password, so that's successfully logged in. And just because I don't want to be remembering the password, I can update it. So I'm just going to very quickly do that.
So again, you can see I'm doing all of this as a consumer completely, uh, by myself. So now what I'm doing in this, uh, section is just, just adding, uh, the two namespace, uh, into, uh, into Argo CD as a destination cluster. Uh, I'm adding the namespace where I've deployed Argo City, but also the test namespace that we have just created because I will be deploying my workloads into that.
So you will see that it creates some service account and role bindings to have necessary permissions to work with that. And back in our, uh, browser, I have a very, very simple GitHub repo that I have created for this purpose. And I'm going to grab those YAML files that I have downloaded during the initial deployment demos.
And I'm just going to place them here. And what we will see here is that I'm combining both my Kubernetes cluster and a virtual machine, because again, I'm targeting a single API on a unified platform. So when I create an Argo CD application, not going into too many details, very simple, just gave it a name, giving it a source, which is the GitHub repository, uh, path, which is root.
And then the destination, which is supervisor that we have added, and the name space that we have created. And all I do here is make sure it goes into any sub folders, if there would be any, and create that. And this will then start doing continuous delivery.
So it will match the state that is requested, the desired state in my yama files, in the GitHub repo, and match it with the actual current state on my platform. So you will see it'll start deploying all of the resources that are required. So that's not just the actual vm, for example, we see.
But all of the things that are in the background as well, uh, that are required. And after a while, as we will see it has deployed everything in our platform. So we have repeated what we have deployed, uh, manual through the user interface in the, in the first part of the demo.
Now we have reused those same files to deploy them, uh, again, in a different location. But again, this is just the tip of the iceberg because kid ops is about much more, but it's really showing the idea of defining everything as code. So whether that's your infrastructure, whether that's your, you know, your, the, the, the workloads, the policies, networking, storage, everything defined in code allows us to store that and get, and then use tools like Argo cd, for example, to do that continuous delivery for us.
So if I would then decide to make changes to these workloads, make maybe, um, deploy more resources, add a load balancer, I could do that, uh, by just introducing the new files, um, into that repository and having Argo cd, um, take care of that, um, and make sure that, that this new desired state is matched for me. So this is, as I mentioned, completely brand new, um, wasn't even there during the GA or VCF nine. So how do we get there?
And that's the last section that I really want to cover because I did talk about the way we deploy, uh, or update VKS. And the reason why we do that and have this independent lifecycle is that we can do it independently, which means we can give you new versions, new functionality really, really quickly, and you don't have to upgrade everything to get there. And what we have introduced in VC of nine, it's the same kind of decoupling for the actual supervisor layer as well.
So that's the last part of this quick demo that I want to show you. Um, and again, it's very simple, would be done by the cloud admin. So we need to differentiate between the kind of personas.
The easiest way, uh, to think about it is the cloud admin is the person that actually has access to vCenter and the v uh, the v VCF layer, and does all of that configuration of infrastructure. The consumer is really just having that cloud experience, so requesting services, deploying workloads, deploying apps, not, uh, caring about what's underneath all of that. So in order to update a supervisor, what we have to do is we have to assign a content library.
Uh, we again, created a, um, um, library, which you can subscribe to, or we will be releasing all of the new images for supervisor. So if you would check it now, there's already one that we have just released. So I've added that content library.
And now under my management, I can see that I have a new version available. 5. You can see that we have a new version, one 30 point 10.
And with these updates, I'll just continue with this, just apply this. And what this again allows me to do, updating supervisor not having to update vCenter, not having to, uh, update anything in VCF. It's completely separate.
So we can just proceed with these tasks and it will go ahead and, and, and do a rolling update. If you, um, if we will go into the configuration, we will see that it's actually deploying a, a second control plane VM with, uh, the latest version. So we'll just let it do its thing, match the desired state, and after a while, this will finish and we'll see that the version has been updated in here.
So the current version is here. And also if we go into the supervisor itself, we will see that it has been updated. So this was the first async release of supervisor.
There will be more coming. And one of the most exciting things that this, uh, particular update has unlocked is that access to Argo CD service. I have a question here.
Um, do we have a rollback function? Rollback function of the supervisor? Yeah.
Or we can call back to the older version even in case something happened. You know, Uh, to be completely honest, I will have to check whether there's a rollback function in the user interface directly. However, uh, what, uh, you can definitely do is, um, and would be advised as well, is to take a backup of the configuration before you proceed with any updates.
Um, and you can always do a restore of the supervisor itself, just of the supervisor itself to re uh, recover, uh, or restore the functionality. However, uh, that's a very interesting question. Uh, I'm not quite sure I have the answer, but let me, let me have a look, maybe ask, um, just to double check.
And, um, I can come back to you on that, whether it's directly in the user interface to go back. Thanks. And we're coming to the end anyway.
Uh, but what I really wanted to show you with this is that we have created this unified platform for all of your workloads. It doesn't matter what you are deploying, it's all there for you. But most importantly, it's all managed with a single API on a single platform.
And with all of these services that you can pick and choose and introduce into a platform, so if your container images will be stored in Harbor, you can deploy that, as we discussed, if you want to do secrets management, you can deploy a Secret service, which is one of the new ones. But there are plenty of services for you to choose from our catalog and implement on or introduce into the platform, but still guaranteeing that your consumers will still have the same experience, whatever they are deploying. And, uh, these features are available when you implement automation, right?
It's, uh, not just coming with, uh, when you set up the pure VCF nine plus automation or just come out of the box, how it, how it looks like when you get those. So, um, let me answer it maybe from the perspective of why you would want to introduce VC of automation. First of all, in VC of nine, VCM automation is not just a new version of Aria Automation.
It has really been completely restructured to act as a single point of entry for the consumers to get this full experience and to really utilize the, the capabilities of the cloud with, um, a single entry point. Having said that, the functionality of supervisor is a functionality that can be deployed, managed, and added, um, within the supervisor itself. So within the, the vSphere client, however, not all of the, uh, integration, maybe not access to all of the services would be available.
So we would definitely strongly recommend that in this new world and this new way of VCF nine VCF automation should be the primary entry point into this ecosystem to get the best cloud experience. And to hear that, especially that it's just there, right? So it's not like you need something additional and you just tap a button and they're gonna be VCF automation.
Yes, what you will, what you will see, the two main portals, let's call it that you will see, depending on your role, will be VCF automation, VCF operations. But it's really all about a unified platform, which is VCF. Have you heard about the new Spielberg movie?
Saving csa? You're watching Textron gag. Hey, everyone, welcome.
Happy Wednesday, man. It's, you know what? Wednesday is right?
It's a hump pump pump day. These weeks are going so fast, though it doesn't, it seems to be a little more than a speed bump than a hub. But happy Wednesday to you.
We've got a great lineup, great stuff to talk about today. Let's jump right into it. Um, let me introduce you to our, our speakers for today, our gang members for today.
First of all, sporting a nice city view that, that looks new, Yorkie to me. Um, it's good to be home. He's, uh, Futurum, COO, Dan O'Brien.
Hey, Dan. Good to have you here. Hey, Alan, good to be here.
Absolutely. Joining Dan is Kate Scarsella, who we found out is up in the Boston area, still got the classic New York, Boston, I think the Yankees of, well, they just played the Red Sox, but Kate, welcome. Thank you.
Nice to be here. And of course, joining us from out in the Ma Rocky Mountains, our, uh, Futura analyst, Mitch Ashley. Hey, Mitchell.
Good day. Good day. Rocky Mountain.
Hi. Absolutely. Well, it's a little early for that, isn't it?
Is it ever? Okay. Um, anyway, Mitch, let's jump in with you.
You know, there was a big to do, a big brewer a couple months ago, whether CAW was gonna be funded. Of course, they've had some high level departures there. Friends of ours who we knew pretty well.
Um, and then the whole thing came up with funding. CVE. Was Mitre gonna get funded?
Who's gonna maintain CVE? Should we maintain CVE? Is it a PRI private company that, or so sort of nonprofit that you maintain, maintain CVE?
Well, thesis seems to have found this as its new mission for being that they're gonna save and maintain CVE. What's the story here? Well, it's a bit of, uh, musical chairs, right?
Do we have enough chairs to, for, to find, uh, funding for the CVE or do we need private funding? Can it still be done by the government? It, it was pretty disruptive when this was announced a few months ago about this is no longer gonna be funded.
Uh, we're stepping away from it. It's gotta be a private thing that the industry takes on. And, and while disruption is never fun, especially something as significant like this, the security industry, it did cause us to kinda re-look at, so what are we gonna do?
And is there a better way to do this? And I think some of the reasons that people thought, should we still be funding it or doing it the way that we're doing CVEs, uh, the common vulnerability definitions and database is how accurate is it? Uh, are we, do we using it the right way in terms of really helping us not only communicate and collaborate on it, but how does it lead to outcomes that help us not only react to, to vulnerabilities, but potentially things that are out in the wild?
So yeah, CI has stepped up and said, we're, you know, we're move CVEs into what they're calling the quality area era, excuse me. Um, where they're focusing, not just communicating and collaboration, but more around accuracy and consistency and, and, uh, ensuring trustworthiness in the, in the vulnerability information. I don't know if the trustworthy it was necessarily in question, but that's what they say that they're gonna emphasize.
So they put together a plan that they've, uh, set out in a, I guess, a white paper kind of form about strengthening the governance and, and modernizing how the program works and the infrastructure for it, and expanding the community participation, uh, and making sure that, you know, it's maintained, uh, as a vendor neutral kind of oversight. I don't know that those things, again, were in question necessarily, especially the vendor neutral. I think it was pretty vendor neutral, though you and I, Alan, we've been in security since, you know, early two thousands.
CVEs themselves have led and spurred, you know, many a startup, including some, um, so it, it, it is an, an engine for, you know, new innovation to be able to use this information as it, we take it out to market. So we'll see where this goes next. And, uh, you know, this is a pretty recent thing.
Uh, I, I'm guessing the reaction's gonna be pretty favorable. We just need some consistent, this is gonna happen. It's supported whoever we get behind it.
That's great. Let's move and, and make sure we have this information that we can work from Kate as a security professional. What do you think about this one?
Well, the, um, I, first of all, from a Mitre perspective, I really had liked that group. I've always liked that group. I've always respected, um, the techniques and the sub techniques that they had.
And so I would get concerned about having to reinvent the wheel. It doesn't make a lot of sense to me. I don't understand personally, you know, they talk about quantity to quality.
And I, while it is so important that right now that we have the right information, and I fear that in this period of transition, that what we can't afford is to have the drop of, of critical information that actually is impacting when I talk about critical, critical infrastructure. And I worry that oftentimes we are having people who are leading these charges who don't know about cybersecurity, who haven't been around. Like, I mean, I, same here.
I've, I've really been doing this since, you know, the early two thousands. And I continually find people who are jumping into this mix with opinions. And to me, it just continues to look like Groundhogs Day.
And if we, there's no building there, there's no like putting, like, we are gonna do this and we are going to move forward as, as we do this with, um, it's almost like a spaghetti strategy. Like, I'm gonna throw a spaghetti on the wall and whatever sticks we're gonna go towards that I don't feel like we're building. And, and with Mitre, what I saw was that they really looked at the attack methodology and, and how it's happening.
And, and I think that that strategy was crucial in helping us understand. And I'll, I'll just add one more thing that it was in front of, you know, sea level people over and over again. There was a commonality to the attack methodology.
And what I would continue to hear is how do we deal with privilege escalation, and how do I deal with lateral movement and how, and, and like, those were the top two that I would continually be asked. And of course, we understand, we understand that because of the length of time that, that the bad actors are, are able to go undetected and then privilege escalation, which we see over and over again, you know, on gaining access. And I don't, I, I hate that we're messing so much with this personally.
I, I do. So, Absolutely. You know, first of all, consistency in anything this government does is kind of an oxymoron, right?
So this is, this is, this is this month's plan. Yeah, it's true. Next month will be a new plan.
Two months ago was a different plan. But let me, let me take off my journalist hat and put on my security person's hat, right? Because I've been to Mitch, like you said, we've been security people for going on 30 years and CVE, there are a lot of people who have valid concerns.
We have too many g*****n CVE numbers. How can I track 200,000 or 300,000 CVE numbers and, and really try to, you know, fortify my, my infrastructure with it of using that. However, CVEs are a backbone of our security posture, of our security processes, right?
Mitchell? Yes. Startups have been launched around CVE management careers have been made around managing to the CVEs, the Mitre organization, I think was the perfect organization for this.
'cause it was quasi-governmental, right? You had governmental, um, funding and governmental involvement, but with private as well. And, and they did a heck of a job all these years.
Why fix something that's not that broke is, and especially fixing something that it in that is in and of itself broke, right? When Jen Easterly was shown the door there when our friend Alan Friedman, uh, of SBOs was shown the door there when they purged all of the people at csaw, right? To me, this seems like whoever's left at CS a is looking for a lifeline.
And the CVE is their lifeline. Hey, we'll be able to get funding. We'll have a reason for being here.
If we say we maintain the CVE database, I am of the opinion that it, this is the perfect opportunity to correct a lot of wrongs and do it right. I would like to see an organization, a not-for-profit organization formed, whether it's under the auspices of the Linux Foundation or Eclipse or Apache or something new altogether that comes out and says, we're gonna do this. Right?
We recognize what some of the issues were around the abundance of CBEs CBEs. You know, there were just too many, but we're gonna do it right? And we're not going to be subject to anyone's beck and call or political whims or, or what have you, right?
Let's put together a consortium of industry government, and not just the US government. Let's get the EU and some of the other responsible players in here, and let's form a worldwide wide foundation that manages our common vulnerability database, because it's too important to mess around with. And until we get to that point, this is all to me, just theatrics that, that's my point.
Yeah, It's a great idea. I I, I, it's a phenomenal idea. I, you know, So unfortunately, I already have a full-time job, so I, I, I can't be the one doing this.
But if any of my security friends are out here watching, we need to do this. Maybe, you know what? I'm gonna call my friends at RSA conference.
This is a good thing for them to get Involved. I was just thinking RSA, why not start something up with Yeah. Let, let's, let's get a hold of them and see what they do.
Someone has to do this. It's, it's a good point because I don't think the model is, uh, why fix what ain't broken? Why break what ain't broken?
You know? So, so it's the, uh, Silicon Valley break things, you know, and worry about the details later. And it'll, it'll shake out one way or another, which is, which is the whole showing people to the door and, you know, for political reasons or whatever the reasons are.
It, it never made sense to any of us why you would pull the plug on Mitre, especially for funding this kind of activity. 'cause it's really the lifeblood supporting the industry. Could we do some new things?
Yeah, I'm sure we could. What do we do in the age of ai? Is there something we could do better?
Is something we can do to help with either the accuracy or the felony or the response to, uh, CVEs that we do put together. And there's a lot of things I'm sure we can do in, in today's age, if you're gonna not only modernize, but maybe rethink or redesign how we do this kind of a process. But in the meantime, you know, uh, you gotta pay the bills, you gotta protect the network.
You gotta protect all the critical infrastructure. You gotta protect all of our, you know, digital assets. So you just don't shelve that process and then kind of wait and see what, what, what forms, you know, if the new Galaxy perform, uh, forms up and starts to work on this problem, it it's an ongoing threat.
So, really, in my view, I think the a the attitude or the approach we took is actually puts us at great risk, great national security risk. Not just for our national infrastructure, but our businesses, wall Street, all of those things. 'cause we rely so heavily on CVEs that said, you want a reason to go out and raise sponsorship funds, Alan, whether it's RSA or somebody else.
I think companies would step up in a heartbeat to say, we'll contribute to that. And not just vendors. You know, I think, uh, financial, No, no, I think end user enterprises would be A lot of companies that would say we want a neutral yes.
Yes. And we want a healthy vendor ecosystem that is, uh, putting the right kind of products. Matter of fact, we'd love to see a, you know, revitalization of that and see some new things happen, some new innovations in industry.
So let's use this as a spark to, uh, really create the next era of how we do this. Agreed. That's a great idea.
Yeah. Love it. Agreed.
And this needs public private partnership, right? I mean, that's really the role for the government to play here is there's a lot of great efforts. There's a lot of folks who wanna be part of a solution.
Um, you know, government really is kind of the organizer of last resort here and, you know, the funder of last resort. Um, but, you know, this is, this is the equivalent of, you know, like getting rid of an FDA or an NTSB, right? You know, it's just a little bit more in the background of, you know, everyday people.
Um, and so I think it's not getting the attention that it would if it was some of those more visible things, um, for, you know, things that people feel like they consume more regularly on an everyday basis. But, um, you know, this is, this is a national distance and, you know, national security issue at the end of the day, um, really need to step up and get this fixed. I mean, people, people will know about it when, when it hits the fan, I'll tell you that.
You know? Exactly. So, All right, let's take a break here on the gang.
We're going to come back and we're going to continue our cyber focus today, talking about Microsoft. Are they grossly negligent when it comes to security? I dunno.
You're watching techron Gang. Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, everyone, welcome back here to Text and Gang.
Um, you know, uh, Senator Ron Widen, I believe he's from Oregon, is asking the FTC to investigate Microsoft's gross cybersecurity negligence as a threat to national security. My goodness. Okay, I'm gonna ask you to kick this one off.
All right. 6 million people. It's a lot.
Um, the entry point for this came from a malicious link and a contractor, you know, clicked on it. And, you know, as typical, um, as we've seen, you know, everything falls, right? So it went over to, um, reached, uh, escalating, you know, that whole privilege escalation, Microsoft Active Directory, privilege management and everything else.
So the technical vulnerability here, um, was a well-known attack, uh, for credentials, uh, via a weakness in, um, kross authentication. And the core part of this was Microsoft continuing, uh, the default support for RC four. And many of us know that one there.
And basically, you know, the argument here is that, you know, why is this continuing when we've known for a very long time that better alternatives exist? Uh, the other question that he raises, um, and I think it's actually good logic here. I don't think we need to, you know, beat up Microsoft, but, but the logic here does make sense to me.
And that is, you know, you talk about, you know, Microsoft talks about, you know, well, you know, for critical infrastructure, you know, we need to keep this open. We need to have backwards, uh, compatibility. 1%, uh, presently, and, you know, and then going, so, so how does that make sense?
1% of the people who are still using RC four and, you know, but yet critical infrastructure is impacting, you know, it has a possibility of impacting us all. Like, you know, at 90 plus percent. So does does that make sense?
I mean, when do we finally just shut, shut it off? I'm a big proponent of, you know, let's just shut it off and let's, let's see what happens. Uh, but that's me.
So he raises the point about national security and systemic risk. Um, and what can Microsoft do here, uh, to really change, change out this risk that, that he sees that's impacting critical infrastructure? So, Mitch, have some thoughts?
Mitch, you wanna go? Yeah, I do. You know, I'm thinking of, um, a conversation we had earlier on an earlier show about when, uh, some, so there's a quality issue with something coming out of the factory you enjoy.
Just don't fix the item that has poor quality to go back and fix the factory. I think we have a fundamental issue with security technologies, both the security standards, uh, that we put together, but also how they're implemented. And here's what I mean, I'll draw an analogy with, um, IOT devices, right?
For forever. There was never a way to update IOT software. It just went out there.
It lived out there forever. The vendors didn't have a way to update it. They didn't really care.
They didn't really maintain it. They just knew they were gonna replace it, right? 'cause it was replaceable technology year over year, but it didn't get replaced.
It things to live out there for much longer, have much longer life. The same thing happened with security standards. So what do we see in iot?
The vendors start building and upgrade mechanisms to be able to do updates and things like that. The challenge, and I'm not saying it's an easy thing to do, but how could we reassess how we design the standards themselves and also implement them so we can upgrade them in place more easily without it being, you know, a rip and replace a major process. And this is everything from, you know, uh, PKI hierarchies and keys, uh, to KRO standards, encryption standards.
I mean, it's a big effort to go from, uh, Shaw 1 28 to 2, 2 56. You know, it is not a small thing, small. Um, and again, maybe this is an area for ai.
How could we redesign this process? I, I would invest my effort instead of, you know, trying to rake Microsoft or whoever the next company has crossed the coals for, you know, not making their customers keep up to date with the latest things. Um, and really let's address the systemic issue.
Yeah. So, and I I, oh, go ahead, Kate. No, no, Kate, you go.
Well, I do absolutely agree with you, Mitch, that we need to, um, I like, and it actually ties to our, our previous story, right? I think we're at a time right now where we really have to rethink what we're doing and going forward. For many of us who have been doing this for a long time, we understand.
We know the building blocks, you know, it's time to build things, right? And, you know, really think about redesigning things, right? And yeah, it's a good, good point there, Mitch, that That's kind of why I got into DevOps, right?
To, to get security right. Earlier on in, in the process. But let me, so let me take off my journalist at this time and put on my lawyer hat.
This is not gross negligence, ladies and gentlemen. No. Right.
There is, there's legal definitions of gross negligence and this ain't it. Right? This is a politician politics Yeah.
Making, making hay. Now, could we make things better? Yeah.
Could Microsoft be better about trustworthy computing as Bill Gates called it all those years ago? Yes. Should we be complaining to the FTC and calling gross negligence on this?
Absolutely not. That's slanderous. I, you know, Kate, I always Yes.
1% of people or organizations are using that protocol. 1%, right? 1%, you're yelling bloody murder if, if you're making them change it.
And, and so these things need to get done. The problem we have overall in security is we're always playing catch up. We're always three steps behind.
So now we're gonna try to fix this, well, this morning, 140, uh, packages and NPM from, from no less than, uh, CrowdStrike, I don't know if you guys saw this this morning. 140 CrowdStrike packages are found to contain malware. Some sort of new worm that's able to get into these packages and deposit malware that steals credentials and everything.
It's kind of a new vector. It's a new worm. You, you, you know, that's the problem in security.
You know, we're not the French in World War ii. We can't set up imaginal line so that the, the tanks come around us and leave us there. Yeah.
You gotta fight tomorrow's war, not yesterday's war. Yeah. And, and We, and that's what we need to do.
Go ahead. And, and, and that's something that we have said on, on the show before, right, Alan? Like, we're not really planning, um, for tomorrow.
We're fighting yesterday. And the strategy defense in depth, I mean, we've heard this, I've heard this a lot. Yeah.
Our whole life, Right? Yeah. And I feel like, and believe very strongly that it's not a strategy that has been effective.
And if it was, we wouldn't be in the position that we were today. And when we talk about offense, a strategy of, of offense, it's so different. And if we don't start playing the offense strategy, and that doesn't mean, let me start an offensive, let me start to attack countries.
It just means that I have the ball. You know, Hey, this is football season. I have the ball.
How am I gonna get down, down the field to, you know, score points? You know? And we don't think that way.
But if we were to think that we have the ball, how does that strategy change with cybersecurity? And that's the question. I, I think, and it, it's perfect, you know, with CrowdStrike, you know, In the immortal words of Hank Strm, let's matriculate down the field.
Just get us an ation. Uhhuh. Mm-hmm.
Alan, I think you said it well, I mean, you look at the rhetoric here and it kind of screams of, you know, a politician with an agenda. Now, obviously Microsoft is, you know, somewhat been the poster child of create the problem, sell the solution. Um, but you know, I, I don't think you can really hold the vendor too accountable here, right?
I mean, the end user has some responsibility as well. And you know, at what point as a vendor is building a platform that is supposed to serve, you know, almost everyone do the edge cases where, you know, people are kind of falling behind and, you know, building up technical debt and, you know, not, not kind of modernizing at some point, you know, I think it falls back on the end user, not the vendor here. It's really good, a good, good, uh, example because, uh, that happened with the crowds script.
Not, not the most recent, you're talking packages, but when the outage happened, yeah. And of course the Delta extreme bloody murder and sued them. But of course, you know, they were, they were the, the worst of the worst of not being able to go out and actually rebooting their systems.
It's like, at what point does the consumer have some responsibility? It's a shared responsibility model at the end of the day. Mm-hmm.
Yeah. I mean, it's like your home, right? You can have locks on your door, but at the end of the day, if you don't lock your door, you know, are we gonna go see this?
But then you got the cloud, which adds another element to it. And it's sort of like, well, you just rent a home and what, what responsibility does the landlord have? Right?
You, you put your lawyer hat back on, didn't you? No. Well, yeah.
You never take the lawyer hat off. That's the problem with lost lawyer historian Responsibility model a little bit, right? The cloud shifts the responsibility model a little bit more back to the vendor.
But, you know, there's a lot of control. The end user still has, you know, even in how they set up. And that was always the thing about cloud security.
Dan, yes, the cloud vendor has capability to do some security there for you, but ultimately it's the end user who bears the responsibility when the stuff hits the fan. You, they don't want to hear that, oh, AWS didn't do this for me. Well, no, you put your infrastructure on a WSI used, you are responsible and, and that that's the, that's the fact.
But, you know, I don't expect anything to happen out of this. You know, Alan, Alan, just to throw one other, not not to to get too, um, futuristic about it, but I've, I've talked for some time about sec, about software being not a static thing anymore. We used to release software, it would live out in production for months, maybe years sometimes.
Uh, but now live in a world where software gets updated near continuous, not quite continuous, but it's something that is evolving. And I describe it, it is, software is not fixed like a rock. It's fluid like water.
We have to think about security the same way we have to stop thinking of static security. I put it out there and it lives until I do something about it. And we live in a world where the doing something about it takes people and resources and money and time, which is why things get left behind.
'cause it's just not worth it to go deal with the problem. That isn't a problem yet. Right?
Now we're a big enough problem. I think we have to think about designing security, not just in zero trust, but continuous zero trust, if you wanna think of it that way. You, this Was J Frog's thing Mitch out in Swamp up last week.
Exactly. They call it liquid software. Liquid software.
And it's versionless. Yep. There's No versions.
It's Continuous. It's continuous. But it's continuous security too.
Exactly. And that's why, that's I think, the model of what we need to shift to of thinking, because we, we live in a world where we could do this now. And I know that was part of their AI announcements, and that's part of a way AI can potentially help us, especially, you know, AI is, is going to be writing more and more code for us.
Not just at, at a point in time, but continuously in the background creating new code that it's writing itself to do new things. Now, of course, how we regulate that control that or o other issues. But the same thing can happen in security, right?
So a response may actually be it creating a process or it writing some security protocol adjustments or changes or, or code that responds to an incident because we're at such a volume, nothing can re, you know, I go to these conferences where we're reducing alert fatigue, that's all great, but we, even at that level, we still have alert fatigue. We don't have enough people to respond to vulnerabilities and software to attacks on network. This has to be automated.
And the smarter we can make it, the better we protect ourselves. I feel If only we had a, you know, very transparent, trustworthy, central database of vulnerabilities that the agents could pull on, right? Little callback.
I what a great idea. Dan. Maybe we can do something.
Lemme write that down. Thank you, Dan. I, I even got a name for it.
AI Needs good data, right? But here's the sad part, guys. Kate, your security person, Mitch, Dan, you've been around the block enough.
Is anything really gonna change? We sit here, we talk, we pontificate, we ize, if that's a word. Uh, we, you know, all of this.
Are we gonna be having the same damn discussions in 2035? Maybe it won't be me discussing it, God willing, but are we gonna have the same damn discussions 10 years from now? Yeah.
It's a game of leapfrog. Continuous leapfrog. Yeah.
Yeah. So, I, I'm, I, I hate to be the kind of, it's all about money, but it is all about money. As someone, as soon as someone finds a way, a way, a model, an innovation, whatever, to make money doing it differently, they'll, they'll do it.
They'll jump at it. And if it is successful, others will jump on that bandwagon. So I've, I've, you know, as long as I've been in security, I feel like we're doing what we did.
When you and I started, you know, 25 plus years ago. We're like, we're doing the same s**t. We're just doing it a little differently with a little better technology.
And it evolves and it improves and, and it evolves. You know, let's really get some serious innovation happening in security. Let's really invest not in the latest startup that solves some point little problem that does a little bit better than Cisco does it.
And we're gonna sell it back to Cisco. Yeah. We'll make money at it.
Let's really invest creative and innovative ideas that are gonna move the ball, not just 10 yards, but into the end zone and maybe into the next stage. It's all about, and, and law of diminishing returns, right? You know, at a certain point, the spending the next bit of money doesn't justify the ex extra bit of risk management that you kind of get.
Sorry, Kate, go Ahead. No, no. I, I have to say that, um, in my age, as I grow older, I've become a Pollyanna.
And I don't know when that happened. Would've saw, Well, you're self admitted. That's the first step, is admitting the problem Thought.
I believe that we're gonna change this. I really do. This is my pollyannish.
You know, like, I believe, I believe that we're gonna do this. I believe that we are gonna solve this problem only because if nothing else, because we have to. And I believe in, you know, I wasn't a big adopter of ai, but now I'm like, man, ai, let's embrace it.
Let's see where we can take this and let's change up this story. So in 10 years, I can't have, I can't do this over and over again. Like in my mind, like, we have to change this narrative where this is going.
So the Pollyanna in me lives on, and we are gonna have a different story in, Hey, three years. Three years. Three years is ambitious.
God bless. Two years. Two years to God.
What I believeing, I was gonna ask you to get into politics, Kate. Amen. I was, I was looking for a church.
Derek, going on. Alright, Hey, I believe we need to take a break right here. Uh, we're gonna come back and we're gonna change it up a little bit.
Let's talk a little bit about ai. 'cause we don't talk enough about AI and, um, but we're gonna talk about stock markets and all kinds of good stuff You're watching. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security Bloggers network. Hey everyone, welcome back here to Techstrong Gang.
You know, I, I had an interesting conversation with my friend John Willis today, and he, we were talking about the progression of users of o of AI and of chat GPT, you know, and, and we, we, we tend to, we live in a bubble. We we're tech people and we think everybody's using AI and everybody knows what it is, and everyone knows all the history when the fact of the matter is yes, open AI is probably the fastest to a hundred million users of any technology ever. You know, it's pretty, it's cut and dry.
However, a hundred million users plus still pales in comparison in a world of 7 billion people. And so we forget and open ai, the whole open AI not-for-profit, the Microsoft involvement, even in the a hundred million users, I bet, you know, overwhelming majority are not aware of the unique corporate governance and structure that OpenAI had or has. And, you know, you know, absolute money corrupts absolutely.
And with all this money in there, people are trying to figure something out. Dan, I I've laid it out for you. Why don't you finish it up and take us into what's happening now.
Yeah, for sure. Thanks Alan. So, as you mentioned, you know, founded as a nonprofit, the nonprofit controls, you know, the potential, uh, you know, profit entity, a super complex corporate structure and governance model.
Um, you know, let's lay out the facts, right? Microsoft's got 13 billion into OpenAI. Most of what they've been, you know, kind of, you know, negotiating around is, you know, really the restructuring approval needed, um, to take this thing into the, the for-profit world, you know, the equity stake that micro Microsoft will get, the revenue sharing agreement, the technology access, and the a GI clause.
Um, and then all the commitments on safety, right? You know, early on in the partnership it was focused more around model exclusivity. You know, Microsoft being the primary cloud recouping their investment, you know, with profits.
And, um, you know, though, I think, uh, my open eyes come out and said, you know, probably not profitable until 2029, you know, looking at $44 billion in, in operating losses, you know, between now and that timeframe. But, you know, you take the financial backdrop of this thing, there's an incredible amount of value creation happening there. There's also an incredible need for funding moving forward.
And, you know, ultimately this move, I think is about, you know, securing the capital needed to, you know, kind of meet the CapEx requirements of continuing to drive the business forward, right? You know, the ability to, uh, you know, to tap in, in IPO potentially next year, you know, raise a significant amount of capital. We've already seen this in, you know, some of the talk around the Stargate project with SoftBank and Oracle, you know, numbers like $300 billion being floated.
Um, I think OpenAI is targeting a valuation of about a a half a trillion dollars, right? And, you know, Microsoft seems to come out with, you know, something that's probably on the order of a couple hundred billion. So, you know, something roughly equivalent to, you know, eight to 10% of, you know, Microsoft's market cap.
Um, is, is kind of the amount we're talking about here. So it's, it's not insignificant at all. Um, but ultimately, you know, I think both parties realize that they need to get past this, you know, kind of restructuring effort to really extract the value from it.
And, you know, everybody's willing to negotiate on, you know, kind of the terms that need to change moving forward from what they've been, you know, to, to fund the CapEx and really seize the opportunity. I, I've got a few things here, Dan. First of all, to your point, I just wanna make sure our audience realizes this, that $13 billion Microsoft invested was not your usual investment where they got stock or even options or warrants or anything.
It was $13 billion as part of a rev share, right? And Microsoft was gonna recoup that money in, in rev share and profit. Secondly, my understanding is just last week, Larry Ellison, you know, got about a 34% bump into his net worth because Oracle came out that OpenAI is pledging $300 billion to Oracle alone for, for this AI infrastructure.
So Dan, if they're gonna raise a half a trillion, you are talking about giving away 60% of it in one to one customer to one project, one, one transaction. They need to raise, I think a couple of trillion dollars. They need to raise Nvidia kind of money just to, to pay these bill, you know, to pay that Piper, that's a lot of, that's a lot of cabbage.
It's a lot of cabbage, right? Think about what, what you're talking about. The other thing though is I, I'll, I'll mention this and then open it up to the, to Mitch and Kate and Dan, you wanna come back?
Here's the fly in the ointment. Our friend Elon, don't forget, he was a founder there and he was, he supposedly was big into this not-for-profit piece of it. He didn't like what they were do.
Well, there's back and forth about why he left, but one of the reasons is he didn't like what they were doing. He of course has Xai and gr right? And he's pledged to open source that everybody's pledging to open source everything while they're all running to the trial to feed open ai.
Yeah. So, you know what, what, what I, I can only imagine the lawsuits flying, but I'll, I'll throw it back to the, to the gang. What do you guys think?
I, I just relate it to, if it can be related to my own personal experience, having run a for-profit company at a much tiny, tiny, tiny fraction of a fraction of a size of what we're talking about here, owned by a nonprofit company. And that is, even in that particular relationship, I'm gonna mention the specifics of it, um, but it complicates things when a nonprofit owns for-profit entities. Now, the, the, the hospital systems see and have figured this out 'cause a lot of the hospital systems are set up that way.
A nonprofit owns all these for-profit companies. But when you start out as with an more of an altruistic nonprofit, that was what originally open AI was about, is doing this with safety and, you know, protect protections built around what we want AI to become. And of course then the for-profit part of it starts pushing it outside of the bounds of that original goal.
I think some of those, those, that fabric of that original mission still complicates the factor here. And at some point you have to say, look, we're not, the, the ownership of this is not about that mission anymore. We are about managing for-profit entities through this nonprofit company, et cetera, in this structure.
And let it be what it's gonna be or, or spin it off and do your own thing as a nonprofit. Just stop the complexities of it. Not saying that this still isn't complex at these numbers of this size.
It's still hard for me to kind of keep those numbers in my head. But I think that is is also an undercurrent of this too. 'cause all, many of us said, what is, what does open AI wanna be when it grows up?
Well, I think it wants to be a company that makes a whole ton of money, is what the market's saying. Yeah. I mean, to me it's like, do you guys remember when Tesla, in the heyday of Tesla, they were the only game in town for EVs?
You know, they had like three x the market cap of Ford and gm and one has to look and say, if that's a car company, and these are car companies, I'm not saying Tesla is not without value, but is it three X of Ford, three x of gm? You know, I think we're talking, I mean, correct. I I'm not a stock market expert, but Nvidia is about a $4 trillion market cap, right?
I believe Microsoft's like at a $2 trillion market cap. Yep. Open AI has to be approaching that to, to afford the kind of deals that they're talking about.
And, and, and keep in mind, Dan, as you said, this is a company that's gonna bleed 44 billion red dollars between now and 2029 or something like that, right? 44 billion. Do you know, that's, that's an insane amount of money.
Well, investors are discounting the future, you know, potential profits and cashflow and voting that there's still a lot of money to be made here, right? And I think what they're trying to do is really kind of remain a little bit true to the original mission about really advancing AI safety. Um, and, you know, the nonprofit may end up with, you know, a sizable endowment to drive AI safety priorities while, you know, kind of separating from the for-profit entity.
So I think they're trying to get to the win-win here. Um, certainly, you know, the original investors in OpenAI are gonna win. Microsoft is gonna win very big.
Um, and it seems like they're trying to maintain, you know, some of that credibility around the other mission, uh, the original mission and, and, you know, really fund that AI safety thing through the equity stake. Do you think, Dan, that that sort of solving that through some kind of a structure funding, that that original mission, if that happened, is that sort of separate the, the conflicting concerns and let's open AI be the pro for-profit company it needs to be, and let open AI that's the non-profit be what it needs to be and stop complicating the concerns. Do you think that's standing in the way of some of this?
I think it is. I think that, and, you know, a fair number of lawsuits are standing in the way of this, but Yeah. Yeah, I think a fair number of lawsuits, yeah, sure.
But let me, let me just, not devil's advocate, but let me give you another spin on this. I was reading a post today by a PhD in stem, a woman who was talking about, you know, they bought Johnny Ives open AI bought Johnny Ives, uh, company for about six and a half billion dollars. And supposedly we're gonna start seeing these, uh, consumer business consumer products coming out next year.
And the rumor is, is that one of them, basically, it's not a phone, there's no screen, you know, but it's a device. I don't know if it pins on you or it's in your glasses or wherever, but it's a device that's your constant companion and kind of whispers in your ear and tells you, you know, it, it summarizes conversations you're having and what people are saying. It tells you where you're going and what you have to do.
It reminds you, it, it is your alter ego. And, you know, it doesn't have a name yet. I didn't, there's no pictures of it, but that, that's kind of the buzz about what this new device, you know, that Johnny Ives team was working on, is working on.
And Sam Waltman says that that alone, that alone is another trillion dollar business for open ai. So I, I'll close it out with this. If they go public, I'm in Friends and family.
I hope so. Alright. Hey, if we have nothing else, we're gonna wrap up this version of the gang.
What a great, great conversation today, guys. Dan, Kate, Mitch, thank you so much for participating. Thank you out there for watching.
As usual, we have a full lineup of text Drunk TV immediately following the gang. If you're watching this Wednesday morning live. Um, if not, you can go to text on TV or the text on TV OTT app where we have not just text on tv, but Tech Field Day.
We've got some six five media, some future group stuff. You could get that on iOS, Android, apple tv, Roku, and Amazon. So check out the OTT app.
We'll be back tomorrow with a fresh gang of fresh topics. Until then, on behalf of Techron Futur and everyone else here, we're out. Hey everyone, it's Alan Schimmel.
Welcome back here to Tech Drunk tv. I'm really happy to have my next guest back on. You know, I, I know this gentleman, geez, 15, 18 something years.
We, we shared an office together at early on when previous company Matt had started and I had co-founded, um, Matt Loberg, CEO markup ai. Matt, did I get everything right there? You did, absolutely.
Very cool. Good to see you. Um, it's good to see you, Matt.
So, you know, we were just talking off camera and I couldn't believe it was that long ago that we talked. I felt like it was maybe two or three months. You're saying it's six or seven, but it's all good.
Gives us more chance, more to catch up on Matt. I, I mentioned, uh, you know, we know each other a long time. You were a CEO of a company, another company that you had, uh, founded.
And, and you know, actually, why don't, I'm not gonna tell them your story. You tell them your story. Uh, well, yeah, I think you, so you and I met, uh, when I was running Return Path, uh, which yes, uh, uh, which was an enterprise, uh, global enterprise SaaS company in, uh, email data and analytics.
Um, which I started in 1999, uh, last century feels like last century. And, uh, it was, we sold, uh, sold that company in 2019 and I've done a couple other startups before that and after that, and now, uh, very excited to be at the helm of, uh, uh, of, uh, the company formerly known as Acrolinx. And, uh, as of September 17th is now Markup ai.
Very cool. I love it. So, so September 17th, that's fresh.
Uh, It's coming up to as we as Right as we record, it's next week as people hear this, it'll be probably right after. Yep. Um, so Matt, give us the scoop, why the name change, what's going on?
Yeah, we're very excited about this launch. We, we feel like we're launching a new category as well as a new platform and, uh, a new brand, uh, to go with those two things. Um, the category that we are, uh, so proud to, uh, to spearhead is what we're calling Content Guardian agents.
Uh, so the origin of that name is, um, is actually Gartner, um, you know, big, uh, analyst group, um, that have increasingly been talking about this concept of guardian agents. And, uh, you know, it's obviously a play on guardian angels and, uh, one, one for the AI ages here. Uh, but the concept of a guardian agent is very simple.
It's an AI system that is designed to oversee another AI system. Uh, so if you think about, if you think about it, AI systems do things so fast and at such volume that it's just not possible, uh, to hire enough humans to oversee every action of the system. So you actually need a different kind of AI system, uh, to oversee, um, an AI system and to kick things out.
So it's sort of this human in the loop, um, motion, um, for things that are aberrations or don't look right. So that's the concept of a guardian agent. And what we are wow, um, is, uh, what we're calling a content guardian agent.
There will be guardian agents that do other things, for example, things around security. Uh, but content guardian agents are really, uh, going to be, uh, critical for sort of the, the whole architecture or scaffolding of generative ai. Um, so if you think about it, companies are adopting generative ai.
Most companies are using multiple models, multiple departments are using multiple models, um, to produce more and more content every day. Um, and our new platform at markup ai, um, we think is gonna be the industry standard for overseeing the quality, uh, and accuracy of content coming out of generative AI systems. So, content Guardian, I love it, is the category markup is the brand because what do you do when you wanna fix a document?
You mark it up, lawyers mark things up, editors mark things up, developers use markup languages. So, uh, we're excited, uh, to bring our, our new brand and our new platform to market. Matt, that's a, uh, you know, this is this, you know, sometimes you hear things, Matt, and you say, well, why come no one thought of that before?
You know, that's a good idea. Why didn't I think of that? But, but it, it is, it's, it's just so common sense that, you know, of course we would want this, you know, we were talking off camera, and I was telling you I was out in Napa last week, or, or this week rather, and I was there for this Jfr Swamp up, uh, event.
And, and they, they released something called AI Catalog, which all it does, I mean, all it's, it's still a big thing is it goes through and finds all the ai, all the gen AI models and, you know, running in your infrastructure Okay. Sort of going after the shadow AI problem if You'll Yeah, yeah, exactly. And then documents and catalogs, and then theoretically you can decide, I want this one, I don't want this one, Don't want that one.
Yeah. And, and that's a value. I'm not saying that's not valuable, that's a valuable piece of functionality, but what you are doing here is you're going one better, if you will, in saying, Hey, we're going to, you know, people are going to use AI there, there's no, you know, you could lock the door, but they're coming in through the windows.
But when you're using ai, we're going watch the content you're developing with it. We're gonna make sure that that content is okay. It's right.
It's not patently false. It's not somehow illegal. It, it doesn't violate policy.
Yeah, exactly. I mean, again, the, the sort of, the concept of the Guardian agent is that Guardian agents do three things, review, monitor, and protect, uh, and kick things out for human in the loop review. So that's what, uh, the markup, uh, platform, uh, is, uh, is going to do for, uh, for content, um, monitor, review, protect, uh, and help companies really confidently and, and rapidly scale their use of generative ai.
Got it. Um, now it works across all of kind of the frontier models, the usual suspects. It, it does.
Yeah. I mean, it's, um, our system is very easy to use. It's a series of APIs, uh, and, uh, the, the system itself is a good blend of, um, of using large language models ourselves, using the output of whatever the client has, and then blending that with deterministic rule sets.
So, so companies have deterministic rule sets that can be quite complex. They have brand guidelines. Sometimes those run hundreds and hundreds of pages long.
Um, they'll have terminology dictionaries that could have tens of thousands or hundreds of thousands of entries. Um, they'll have policy handbooks, uh, they'll have laws and regulations that they're subject to. And our system is, is very good at instantly ingesting all of those deterministic rule sets and blending that with a large language model so that we can scan and score and then rewrite content instantly.
Um, well, if you think of the use case, right? You know, companies produce, um, you know, hundreds of thousands of pages of content a year. They might have millions of pages of content that are active online.
What do you do when you come up with a new policy or change a term or have a brand guideline? How do you fix 6 million pages instantly? You push a button and our system works in batch mode and flags and fixes all the mistakes.
What do you do when you're creating a new piece of content and you want to check it somewhere, but you don't want to have to go send it to a lawyer and then send it to someone on the brand team and then send it to someone else? And then what happens if they don't agree with each other? All that is streamlined through one, very easy to access API Got it.
Now, I'm assuming you're, you are using some sort of AI on the backend to do all this, obviously. We do, yeah. We're, we use large language models in, in conjunction with, uh, deterministic rule sets and a vector database and everything else.
That's how our system operates. But we can obviously work against any other system that sends us content. Excellent.
And now, how would, how would you sell this by the amount of agents you deploy, by the amount of content you're monitoring By, by the token? Like, like all good native ai Ai, right? That's the way, that's the world.
We're moving to the token world. ai. Uh, you can do a trial for free.
You can, you know, our, our entry level package, uh, once you get past a a free trial is $200 a month with a credit card. So if you're a developer and, uh, you wanna play around with the, uh, the two APIs, one for checking and one for rewriting, it couldn't be simpler. I love it.
Sounds great. Um, and, and you know, Matt, the other thing I wanted to emphasize is, look, if you've got millions of pages of content, hundreds of thousands of pages of content, this is great. But you don't have to have No, you don't.
This isn't, you know, just for the, those folks, for those people, no, certainly isn't. Yeah. And, and that's, that's actually why we took the approach of deploying this very simply with APIs.
Uh, and there's also low-code, no-code options. You can find us on Zapier, you can find us on N eight N. Um, so we're, you know, we wanna make this available to everybody.
And, you know, pricing is on consumption, so you can, you can use it at small volume. Look, the reality is, yeah, big companies need a lot of it, but small companies need a lot of it too, or need a little bit of it, and they should be able to get that. So it's, you know, it's the beauty of deploying systems these days, uh, that are built on top of large language models and, and, you know, very, very simple deployment is, uh, it can be used at small scale or at large scale.
Excellent. I lo I love it. Love it.
Um, begs the question, what about ag agentic ai thi, is this a form of ag ai, you think? Mm-hmm. Yeah, For for sure.
Yeah. I mean, the way, the way we're talking about the product, we, uh, are launching on September 17th, or launched on September 17th, depending on when you're listening to this, is, uh, that is our, um, our brand guardian agent. It is agentic ai, it uses generative AI in the background, but it's really an agent, uh, that is, um, the, the brand guardian agent is actually a bundle of individual agents that do very specific tasks, which is kind of the definition of an agent.
So there's a terminology agent, a consistency agent, a tone agent, a clarity agent, and a spelling and grammar agent. But all of those operate in one API. So this is very, very much agentic AI with the power of large language models in the background.
I love it. I know you mentioned the website, but mention it one more time. Yeah.
ai. I love it. Matt, you know, what, how long you there?
Seven, eight months. You changed the name of the company, shook up the whole thing, started the Degen ai, uh, product offering. I'd expect nothing less from you.
Well, it, you know, we've been able to do this as quickly as we have, partly because we have a, a superb team, and partly because, um, the foundational models and the tools around them are very powerful and easy to build. Yeah. Uh, but also because, uh, the history of, um, uh, of our legacy company, Acrolinx, um, we had been doing similar things like this for large enterprises for over 20 years.
So there was a tremendous, even though, um, this is new technology, there was a tremendous amount of institutional know-how about how companies interact with content, what their content supply chains look like, what their approval processes are like, what they care about. Um, so that, uh, you know, sort of the, the, the, um, um, legacy knowledge combined with new technology lets us operate at very, very quick speed. And it's also gonna let us, uh, produce, um, the next set of guardian agents around content.
So this one is brand, but the, the ones that are coming over the next few months are gonna be policy risk and regulatory. Uh, they'll be, uh, content optimization and accuracy. Uh, there'll be data leakage.
So you can just think about anything that could go wrong with content. Um, you know, we, we will be the one stop shop to make sure that, again, it's this concept of the guardian agent. It's overseeing your AI systems to monitor, review, and protect.
Excellent. Excellent. Hey, Matt, I promised I'd get you outta here on time.
I know you have another meeting. We're about out. Congratulations.
Keep up the great work. Let's not wait five, six months till you're back on though the way you're rocking and rolling here. You're gonna have news next month or something, so happy to talk.
Stay in touch. Any anytime, Alan. Always.
All right. Matt Bloomberg, CEO of markup, ai, the newly renamed markup, AI launching the Industry First Guardian, a content guardian agents. Stay tuned for that.
You're watching Text Drunk tv. Hey guys, thanks for the throw. We're here with Dave Lewis, who's global advisory CSO for One Password.
And we're having a little chat about, well, cybersecurity and mergers and acquisitions, because somehow or other we seem to overlook this issue every time there's a deal. Dave, welcome to the show. Thank you very much for having me on.
Alright. There's always some sort of incident, and I guess as of late, the one that everybody's talking about involves Salesforce applications and a company called SalesLoft, which bought another company, which had some issues with their oof tokens. And then the next thing you know, all the bad guys are targeting their stuff.
But this is not an uncommon story, and we've seen it before. And I guess the question, Dave, is like, how come we don't seem to ever think about the security implications of these m and a deals and what needs to be done? A lot of times it's really about business decisions, and they want to make sure they're doing things as quickly as possible.
So unfortunately, security historically would often get pushed off to the side. You know, they're not just business transactions, they're cybersecurity events. So this is one of those things where the gotchas can and will happen.
I've lived through them, I've seen other organizations deal with 'em and, you know, obviously their current news as well. And, you know, the role of the CISO in this particular case is to protect the value of the deal and enable the business. And unfortunately, security historically was seen as that flaming sort of justice and how we could get to the answer of no.
When in effect, you know, security is there to make sure that, you know, security is able to operate safely and securely. Do you think the folks who are doing these deals are aware of the potential security issues? Or is this just something that comes to light after the fact and then they go, wow, I wish we thought of that?
Uh, unfortunately, it's a lesson that has to be learned by falling on swords. Um, unfortunately too many times this is the case, and part of it is, you know, fall squarely on the security practitioners. We have to be better at managing the narrative, making sure that we are inserting ourselves where is net where it's necessary on the business side of the house.
They have to alter their thinking and start realizing that in order to make sure that an acquisition is going to be successful or a merger or whatever it happens to be, that security has to be absolutely factored into the equation. Hmm. Um, how does the CISO kinda inject themselves into that conversation?
I mean, do they even know that these deals are going down? Or should they assume that they are and just start poking around looking for where they might be happening? Well, the really interesting thing there is that the CISO tends to fall in different parts in different businesses as well as different verticals for that matter.
So if you are, you know, rolling up to the CIO, then it's really an interesting paradigm because you, the one you're finding fault with is ostensibly your boss. So it becomes a very difficult and sticky situation with the CISO there. If the CISO has a seat on the executive leadership team that changes things and it provides that visibility.
Uh, even having the CISO report into the CFO that is responsible for risk and, you know, the fiduciary responsibilities to come with it, you're going to have, again, better visibility. So it's really about communication at this point, because the fundamental piece of any security program is really about the human element. When you boil it right down to brass tacks and making sure that you're able to communicate, get your message across, not only as a security practitioner, but the people that are responsible for exercising these deals, they have to find a way to listen and hear that message.
So part of that is, you know, learning how to speak the business language, you know, saying that revenue's at risk, there could be brand damage, compliance fines. These are the kind of phrases that the business leaders will understand if you run in there and say, oh, we're gonna have a zero day of in their environment of blah, blah, blah. Obviously I'm being facetious there, but get, if you approach it from a security perspective, you're going to get a very different response than if you say, oh, our revenue is at risk.
It's going to have a very different response. So shaping the message as a security practitioner in a way that's gonna resonate is absolutely, uh, the key piece of the puzzle there. Mm-hmm.
What, um, should people be doing? Is there some sort of like baseline for forensics, for an acquisition from a cybersecurity perspective that somebody has created under a set of best practices here that should be observed There? There's all sorts of different best practices.
Like one of the ideas is having, you know, security protocols by phase, like doing due diligence of going through and looking at the threat posture and security posture of the organization, how they measure up for compliance, what sort of business, uh, business, sorry, what kind of vendor risks do they have? So for example, if you are connected to a vendor that has a history of security issues, you know, that could really affect the blast radius of how you're doing your calculus, uh, then you have to look at it from the integration perspective of lining to access controls, consolidating your vendors, making sure that you don't have multiple vendors that do the same thing. I've, I've lived through an organization where we had seven different vendors that were delivering ostensibly the exact same product, and that was because it had been a project driven environment.
And at no point did anybody sit down and say, oh, do we already have this in place? And the other piece there is to unify the policies between the acquirer and the acquiree to make sure that everything is lining up properly. And then looking at it from the post deal perspective of, you know, ongoing monitoring audits, remediation where necessary, and making sure you're cataloging any inherited weaknesses and adding that to your risk register so you're making sure that you're tracking it from cradle to grave.
'cause when the auditors come and they will come, they will be asking for those sort of questions. So you wanna make sure that you can demonstrate that you have not only identify it, but you have a plan to remediate. Shouldn't we just assume that the cybersecurity is gonna be flawed in any acquisition because, uh, 90% of them either involve a smaller company that probably didn't have the resources to do it right in the first place.
Or a larger company that's been in distress and maybe probably isn't spending enough on cybersecurity to be in it. As long as you have human touching keyboards, you're gonna have a risk of something being missed. Um, and, and that's inevitable.
But you can do a very good job of reducing that risk by going through and looking at it like doing a risk assessment of looking at where the gaps are, um, as well as, you know, having a security integration playbook ready before the deal starts. So first, get yourself in front of the, the business leaders to make sure that they are taking into account security has to be there and making sure that you show up as a security leader with a plan, how you're gonna deal with it, how you're gonna per deal with, uh, interim controls and all that sort of thing to make sure that you are showing up prepared. Mm-hmm.
Do you think that the bad guys out there are tracking these types of deals? 'cause for them it's just like basically a, a red light signal that says, yeah, there's probably weaknesses here to be exploited. I can guarantee that.
Because again, back to the human element, anytime you have a deal happening, you have people on either side of the equation are saying, am I gonna still have a job? And the attackers know this and they will prey upon this. If we look back to, uh, the pandemic as a great example, there, all sorts of emails started going out about, oh, if you don't complete this questionnaire, you're gonna lose your healthcare coverage and things like that.
And that was really a horrible approach, but it was extremely effective from the attacker's perspective because people genuinely concerned they didn't know how things were gonna unfold. I know I didn't. Um, so when the, when an event like this comes up where there's a merger, uh, that, you know, leaks out into the news, you have the chaos element that is introduced and the law of unintended, unintended consequences where not each side of the house knows who is on what company.
And so it prov, you know, really does give an opportunity for an attacker to even fashion. Like if you're at Widget Co, you could, you know, widget co with an extra letter in there, all of a sudden that email address looks like the same thing, even though it's a different thing entirely. And this is where the problems really can unfold because, uh, you know, the attackers will prey on this sort of chaos to be able to, you know, steal data effect, change, uh, cause some havoc if they want.
Right. And to your point, they may just impersonate people at the other company 'cause I don't know who they are. And if somebody shows up and says that they're from the finance team and the company that's acquiring me, I'm kind of likely just to trust that.
Right? Yep. Um, will AI kind exacerbate this?
And I, and, and it seems like on the plus side, I maybe should be able to use AI to discover what my issues are faster, but the bad guys are also gonna be using AI to also discover what my issues are faster. So is is the window of time when I get to actually review that security kind of narrowing to zero? It is really getting tweaked down to a fine point.
And, you know, the attackers have been using, uh, artificial intelligence and LLMs now for quite some time. If you look at Worm GPT and fraud, GPT, there are already tools that have been around for at least a year. Um, it's not outta the realm of possibility to say that they're gonna be using some sort of AI tool to be able to breach systems.
And then if you flip it on his head and look at it from not only managing credentials for an organization, but looking at it, the agentic AI aspect of things where you have agents and environments from the acquirer and the inquiry that they need credentials, they need to be able to manage access within their environments to APIs, to accounts, whatever it happens to be. How are you managing those credentials? Making sure that, you know, they are not leaking out of the environment, they're not being compromised.
Because unfortunately, a lot of times these, uh, agent ai, um, accounts have more permissions than the individual human might. So those could be a real potential for problems there. Mm-hmm.
Ultimately, there's also regulations involved in a lot of these m and a activities. So are the auditors getting smarter about what to look for as well? And maybe it's not just so much about the fact that I'm gonna get attacked as much as I just might get fined.
Well, yeah. So the AI piece now really is the equivalent of running with scissors, um, because it may seem like a really neat idea because you like to flirt with danger until you find that little bump in the rug, and next thing you know, you got a problem. Um, and when the, and the auditors know this, they're gonna come looking and the AI aspect of things, it's just a different hammer within your tool set.
So you have a red hammer, green hammer, blue hammer. This particular hammer is just an another tool. And we really have this bad habit of anthropomorphizing.
We think of it as being far more elevated than it is, but when it boils right down to it, it is just yet another, uh, technology. And it'll be obviated by something else that comes down the road in a couple years. But yes, it is getting faster.
The auditors are getting wise to this. They're understanding that a lot of times we're getting ahead of our skis with the implementations of various AI projects and security is being left by the wayside. So we have to make sure that we're getting better at that.
And, you know, really fundamentally getting our arms around the security perspective so that the auditors don't do it on our behalf. And it goes from being a simple project to a rather massive remediation project. CSOs, of course, have multiple challenges, as it is, is there maybe somebody on an m and a team who should be the security specialist?
And maybe that's brought in by a third party or somebody who kind of does this over and over again because well, CISOs aren't doing acquisitions every day of the week either. So it's not maybe core to their function. Well, yeah.
So you like, whether it's an acquisition, true merger, a divestiture spinoff, um, there are all sorts of different ways this this can be presented. If you had the budget available and the time to be able to bring in an external security person, by all means do it. But realistically, it ends up being a matrix type of approach within an organization where the security person internal to the organization of the acquirer in this, uh, acquire acquirer.
Yeah, sorry. Acquiring aspect, uh, can be brought into the conversation. So these, um, security professionals, this may not be their core competency, but there'd be very good as security.
The, the idea here is just to approach it as a rather a sev one type of approach. Because m and a activity usually is very strictly time boxed. There's rather significant implications to things going wrong.
And sometimes it's okay to say no. Um, I, I have been through, uh, m and a activity in the past where we literally just walked away from the table. This was at a previous organization, and it was just, there was too much risk involved.
And there's other times where we've seen organizations are going through m and a activity and something was unearthed during the process that caused the deal to drop by hundreds of millions of dollars. So making sure that security is in at the beginning is, uh, absolutely non-negotiable. That has to be part of the equation.
'cause otherwise you could be introducing undue risk into the organization that could have material impact, uh, from a stock perspective as an example, um, credibility within the industry. There's all sorts of different ways that we can approach that. Hmm.
So last question, but what's that one thing you see folks doing as it relates to m and a and security that just makes you shake your head and say, folks, we should be a little bit smarter than that? Oh, it's a twofold thing. Not managing the accounts, uh, correctly, because I've been through activity in the past where we inherited all sorts of super user accounts that belonged to people that were no longer the organization and had not been there in years.
That was a rather significant piece. And the other piece of that, which is the flip side that is often integrated is, it's okay, we accepted the risk. That is not a good answer, because usually what that means is a piece of paper was signed off by someone who had no authority to accept the risk shoved into a back of a drawer and off they go.
Hey folks, you heard in here when those m and a deals come around, make sure you take a good long look before you leap. Hey Dave, thanks for being on the show. Thanks for having me.
All right. And back to you guys in the studio. Hey, everyone, welcome back here to our day two coverage of, uh, swamp Up J Frog's, uh, conference out here in beautiful Napa Valley this year.
We're happy to be back. Uh, we're continuing with some of the people we've been meeting. I wanna introduce you to a frog right now.
His name is Yossi Shaul. Yossi is the SVP of DevOps. Right?
Which is a great job when you're working for a DevOps company, right? So first of all, Yossi, welcome to techron tv. I, you know, in all the years that I've been interviewing frogs, I don't think I've had the chance to sit down and talk with you before.
So it's great to have you on. Um, if you don't mind, share with the audience a little bit about kind your journey, how you got to be here. Okay, thank you.
So I'm Yoi and I'm in this business for, um, I would say for most of my career. I started with, uh, J for about 16 years ago. 16, right from the beginning.
Long time. Yeah. Yeah.
Uh, we were working, uh, at the beginning of Artifactory, creating the, this new domain before DevOps was a term even. Mm-hmm. Uh, so I've been working on Artifactory since the beginning.
I managed the, the team and the, and the product for quite some time. Uh, then I shifted a little bit to do some more, um, architectural, uh, leadership inside jfo. Okay.
And in the last, uh, three years, I'm, uh, back to leading the entire DevOps organization in, in jfo, uh, both product and engineering. Product And engineering. Yeah.
So that's, uh, it's really challenging. Really interesting. Yes, it is.
And very, very interesting time. So yeah. Glad to be here with you.
You know, it's funny you say that. It's, it is interesting times. Look, I, you know, I've, I'm in tech 30 years, 30 something years, Mostly cyber was in infrastructure then security.
We didn't call it cyber, then we called it InfoSec, right? And then when, when DevOps first around 2012 maybe mm-hmm. I, I said, wow, what a great thing for security, right?
DevOps is right. Is going to be. And that's when I started really getting involved.
com in, uh, 2013. And you know, I will sit here as you sit here, the DevOps we were talking about and doing and, and working on. Then today, it's a different animal, a little bit, right?
Today, it's, it's not radical. We don't have to explain what DevOps is. We don't have to fight on whether it's real or not.
But on the other token, you know, people become too familiar with it. They take it for granted. Mm-hmm.
Right? Ah, yeah. It's DevOps, right?
It's just DevOps. What, I mean, I see this as a challenge. Okay.
com, what do you see from where you sit? Yossi is, are people like, just shrug their shoulders, like DevOps is built into the table here and it's, or do they, you know, they continue to explore. They continue to evolve.
Okay, G, great question. So I, I'm, as I said, I'm long time in this and I remember myself, uh, explaining Iif facto is a thing, Uhhuh and arguing with people why they should not, uh, store their binaries in subversion, for instance. Mm-hmm.
So we've, we've been a long way, uh, come A long Way. And, um, and while I think that many organization, um, discovered and now maybe even think that they know what DevOps is, the world keeps shifting and keeps changing, and it never ends. Okay.
The, uh, we had the first revolution, then another one with Docker, then with Kubernetes, and now we are what we are doing with ai. It's keep shifting, keep changing. Mm-hmm.
And also the security is a big part of it. Yes. And while I think we also discussed it in one of the keynotes, that it's not a, so it's not a solved, um, issue.
Okay. No. Not DevOps and definitely not, not DevOps, And definitely not with, uh, new regulation, new, uh, things that AI brings with it.
So I think that we, we've come a long way, as you said, but, uh, I, I wouldn't say that, um, we nailed it. Okay. There's still lots of things to, to discover to, Well, the thing is, and I tried to explain this to someone the other day.
I was talking to a younger person who wanted to be in tech. Mm-hmm. And, you know, they were making it like, you know, like, uh, like tech is done.
Not, not that it's over, but that there's nothing new, you know? And what I tried to explain to them is, no, we, it reinvents itself and it's constantly changing. It's constantly evolving.
Yes. AI is what we're all crazy with right now. Right.
It's, it's kind of the biggest revolution in my, I think, almost as big as the internet itself maybe. Right? I agree.
Um, but every little piece of it, whether it's DevOps or or, or Agile or cloud native as you, you mentioned mm-hmm. It's all still evolving. Right.
And, and we learned this now. You did a keynote yesterday at Swamp Up, you know, most of the people watching this were not here. Mm-hmm.
Obviously that's why they're watching. Um, tell them what you spoke about. Alright.
So yesterday we introduced a new product, a new solution, uh, in the Jfor platform. It's called UP trusts. Yes.
And I think this is another big step of the evolution that actually shows that DevOps is not yet done. Right. Um, we are, uh, offering now solution that allows, uh, development teams to manage their applications inside the platform with a clear lifecycle and policies that controls it.
So, as you all know, we all manage in one way or another, a lifecycle for software development lifecycle, it's called like that. Yeah. Uh, but we used to code it, and still it is coded and scattered in many, many places inside the ci where there's no, um, one location that you can control it and visualize it.
Um, and this is what we are offering now. So the APTA solution is, uh, built upon three different pillars. One of them is the concept of an application.
So we are releasing applications. All of us application can be a library, it can be a full blown application. Um, so that's one thing.
Now it has a representation inside the GFO platform that you can, uh, you can fully control. The second, the second pillar is evidence. Evidence is basically assigned metadata or an attestation that you can attach to a binary to an artifact.
Um, now this can be, uh, internal, uh, evidence that the jfo platform generates, and it can be, uh, things that we are partnered with GitHub, like attests from GitHub that are attached. And it can be any other, uh, evidence. I can talk about it a bit more later.
So that's the second pillar. And the last pillar is the actual lifecycle that you can predefine. That's my lifecycle.
It can be as simple as dev, qa, staging, production, and it can be much complex than than that. And you can customize it per each team. Now, besides, um, having a clear visual lifecycle, you can put gates, what can get in and out of these gates based on the evidence that I just mentioned.
And this, I think it's a big, big change that we are bringing, uh, uh, to the table. Absolutely. Yeah.
It's a huge change. It, it's a huge change. And you know what's funny?
Is it, it's con it it's almost common sense. It makes sense when you explain it. We sit here and say to ourselves, why did it take this long?
That's true. Like, you know what I mean? We, we kind of knew this was what to do.
So you've put good words around the titles Right. To, to the process. But, but this is why when we talk about why things don't are, it's never done.
It's just like we're constantly things that we were apparent but not apparent. Do you know what I'm saying? I agree.
Yeah. It was there, but we never kind of wrapped around. Definitely takes time.
And even for us, it's the second iteration that, uh, we, we try to nail it and we did a lot of improvement. And that's the second iteration, But that's DevOps. Yeah.
Iterate, reiterate, learn feedback, loop, iterate. Right. Exactly.
And, and that, that's what it's about. I wanna talk AI with you a little bit though. Okay.
So, as I said, I think this could be as big or bigger even than what the internet was mm-hmm. When it first came out. Um, I mean, it's had a profound, if you were on the, you know, I reported yesterday on from the keynotes and everything, it was a lot of ai.
Right. I think Shlomi said, if you're not using AI now, you might want to step out. Mm-hmm.
Right? Correct. How is, how are you leading the DevOps team mm-hmm.
Sort of eating your own dog food? How are you using AI to make Jfr better? Okay.
Great question. So definitely, um, JFR was always, um, a company, well, we had a lot of innovation and a lot of, um, adoption of new technology. So we are doing it for quite some time.
Um, like many other companies, we are doing it to increase our productivity, and it's internal, and we are doing a lot of it. And it's very, very interesting. Um, there are also, we are also serving this audience, uh, whether it's the data scientist or the new mops, uh, audience.
So we also are providers of solution, uh, to this area. Now, the third pillar is how do we actually integrate AI inside our products? So some of it you heard about, um, when a staff, uh, leader from, uh, security Yes.
Um, mentioned how, how we can provide a mediation based of data from our, uh, catalog. That's, that's one, one offering. The other one was the AI catalog that was also announced yesterday, spoke about it.
And this is amazing. And, and even asked, we are not huge company. It's very, and we want, as I mentioned, we want to adopt new technology.
We want to adopt ai, but we don't to do it in responsible manner, and we need to help our legal and compliance team to help us. Sure. And AI catalog is one of those solutions that, that can help us promote it internally.
So you have one location where you can see all of the models, all of the services, external a PS that you, you want to use. And this is where you can approve it and you make sure it's secured and you can know who's using it. And so I'm very excited, uh, about it, both as offering the solution I was too, but also using it.
I, I think this will wind up being one of the big compliance tools because Right. You know, what's this is like, remember when cloud first came out, every developer had whipped out his credit card and, and spinning up instances. Mm-hmm.
They weren't shutting him down, and then they submit the expense. Right. All of a sudden someone would add up and say, oh my God, we got, you know, how much cloud instances running.
Right. I think at some point, what, what's going on now is everybody's experimenting, right. It doesn't seem like you pay $20 a month here, $20 a month there.
It comes with my Google over here. Mm-hmm. You know, you know, we don't recognize the full scope of, of how much AI we're actually using at the, at the company wide.
Even a small, we're smaller than you. Right. Yeah.
But I see every single one of these people have their own $20 a month accounts. And that's just the foundational models. Then they got video editing, ai, uhhuh, graphics, ai, and marketing ai.
You know, sooner or later something's gotta blow up. Right. Hopefully we'll be there to control.
Well, Unless we do something like this. Yeah, exactly. Right.
That can controls. So we know at least what we're doing. But here's the other side of that.
I know as, as you know, the manager of my team as the CEO of Textron Uhhuh, I don't wanna stifle experimentation. I don't want to crimp their style. Right?
Right. I want them to use AI figure, show, figure out new ways of doing things, how to leverage this to be better. Mm-hmm.
So I gotta balance, right? I don't want to be like the, oh, you can't use that. 'cause it's not in the catalog.
I wanna say use what you want. Just put it in the catalog. Okay.
Got it. Right. Make sure we know about it.
So when something happens, we, we have something to point to. Mm-hmm. Is what do you see?
You have a bigger team than me. What do you see with that? Let, let me give you an example, which is, um, the reality.
So in my keynote yesterday, uh, I mentioned that we have, uh, controls gates to make sure that you, you path through what we think I, as a development manager wanted my team to go through mm-hmm. Testing, coverage, quality, et cetera. Uh, so for this demo, I asked the team, Hey, I'm going to use Cursor and I'm not going to click a button to, to release it.
I'm going to do it like you are doing it. I'm going to tell it, Hey, release it to production. Um, and they got panicked.
Really? Yeah. Why?
Because the, listen, you are going to do a live demo and this agent is not predictable. We are telling you sometimes it works, sometimes, sometimes it doesn't Work. That's AI today.
So my answer was, okay. But that's exactly what we are building. We are building gates that if it doesn't work, we stop it, we detect it, we stop it, and then we tell it how to do it the right way.
Uh, so it's actually was exactly what we needed for the demo. And it's actually what happened. It Didn't work.
Yeah. We tell it didn't work. Like I expected not to work.
Okay. Um, we told it to release something to production, and this is how we want to work. Right.
Future. Yeah. Release something to production.
And guess what? It actually tried to take, uh, from the development, the release from the development stage, and put it right into production, no testing, no coverage, no security scanning, oid. And this is what it tried to do, and it failed.
And it's exactly what I wanted to demonstrate. So it Was, so it actually worked. The failure was a good thing.
Yeah. So that's one example. And then I told it, Hey, make sure you run the test.
It, it figured it out. And I guess that if we train it more, it'll know how to do it. This is how our team will work.
Uh, but that's one example of, of how those controls and the things that we are bringing with the new solution are making us, making it easier for our customers to Adopt it and taking some of the risk out. Yeah. That's really, because that's what it, you know, it's all about the risk.
Um, so I gotta ask you the hard question. You're probably hearing it from your team. I know I hear it from my team.
Mm-hmm. Are their jobs safe? Is this gonna replace them?
Should they start looking for a new career? What do you think? Uh, so no one knows the future.
Okay. And I think the, the, they are going to be, and there are already happening a lot of changes in the way that we work. Uh, and some jobs or some roles will either disappear or change completely.
Uh, I think that, uh, we are still not there. Okay. I think that, uh, and, and again, we are adopting it a lot and it helps with productivity.
Yeah. Mainly, uh, it helps also taking the mundane parts of the walk, uh, to someone who doesn't care. Uh, but I don't see it yet replacing, uh, junior developers.
I don't see it increasing, uh, uh, 10 times the productivity of the, it's still not there. Yeah. Um, and I still don't see it happening.
However, look at how it looks like two years ago. So who knows? The advancements are really, really, really fast, but it's still not there.
It's, it's, uh, now it's a valuable tool, but it's still not replacing, uh, definitely not experienced developers. But I think it'll always be a tool. Right.
And we all, and we're humans. That's what separates us. Yeah.
We're tool users by definition. Right. Right.
That's part of being human. I, I, I think the, like, in my mind, it's going to get better. 'cause you see it gets better week to week, it gets better.
Definitely. Right. I mean, I use it with writing and it's, it's a, it's really getting better every day.
However, I think at the end of the day, it's always will be a tool. Mm-hmm. And it won't replace the spark of creativity that makes a human.
Do you know what I mean? I agree. You'll come up with an idea and it'll help you bring that idea to reality.
Mm-hmm. I don't know if it'll ever come up with the idea itself. Do, do you follow that spark?
I, I follow. Yeah. We'll See.
And, and I, you know, I, I wanna believe that anyway. We'll see. That's exactly.
We'll see. Um, I wanna emphasize something we, I asked a few people yesterday, we spoke about, which is all of the stuff you showed yesterday, it's available now. This isn't pie in the sky coming next year.
It'll be continually improved with feedback and everything else, but all of the things that we've been talking about here for two days now, people could go on Jfr right now and go play with it, see it, use it, test it, whatever they want. Yeah. So, so the concept in, uh, swamp up is that, uh, we arrive here, we are ready.
Right. Okay. We're not showing you anything that's pie in this.
Exactly. It's there. Or it's coming in in several weeks.
That's it. So APTA is there. AI catalog is there.
We also spoke about, uh, solution for ID extensions. It's there. Mm-hmm.
Uh, identical remediation is there. Yeah. Um, I also demonstrated, uh, yesterday on stage we have a new partnership with ServiceNow.
Yes. I saw, uh, This is where we, we are connecting the two words of, uh, it TSM. Yeah.
ITSM management processes things, amazing things that are done on service now with the evidence and lifecycle management that the DevOps guys are doing. So this is something that we started working, uh, few months ago after the feedback we got in the LEAP event. Uh, and this one is coming.
This one is in development, or we wanted to announce it to put it on the table because our customers are really excited, really ask for it. And we are working on it. This is coming, uh, later this year, probably at the beginning of the next year.
Other than that, all there, the things that we announced are, are there? Yeah. Well, Yossi 16 years.
16 years ago, do you think you'd be sitting here at something like this? You never know. You never know, man.
You never know. Congratulations. Thank, thank you.
You've done a great job. It's really fun. Yossi Shaul, uh, SVP DevOps here at, uh, JFR.
We're gonna continue our day two coverage today. We've got more coming. So stand by here on Tech Drunk tv.
Let me introduce you to our next guest. His name is Harry Hara Ram Ragman. Ragman.
Thank you. We're gonna call him Harry? Yes.
Okay. Harry, Harry's a technologist. He's here, you know, as he's not a frog.
He's not part of J Rog, but he's here as a, a technologist with a keen interest in things. And I, I wanted to introduce him to you and give him a chance to talk a little bit about what he's really finding interesting here and, you know, kinds of things he wanted to mention, uh, that he's here at Swamp Up. So first of all, Harry, welcome.
Thank You so much for having me. Yeah, It's my pleasure. Yeah.
Talk to us about what you're doing here at Swamp Up. So, uh, my first form up experience was in 2023 when it was hosted back in San Jose. Remember?
We were there. Yes. I think it was a complete pleasure.
I really enjoyed it, and I had the opportunity to, uh, work with, uh, and interact with a lot of jfr, uh, employees and, and to know more deep about Jfr products. And I always ask by to, you know, speak at Jfr. So this year, actually, I spoke with Jfr on one of the frameworks that I had developed.
Um, it was about, uh, optimizing, uh, infrastructure deployments and bringing in both, uh, uh, accessibility, security and speed to them, uh, such that, uh, you know, it, the overall time it takes to bring a service to production is rapidly reduced. Oh, yeah. Yes.
So, so you actually took the Jfr platform Yes. And developed sort of your own framework. That is correct.
That is improving security, quality and Accessibility. Accessibility, yes. And you did that at your, we're not here talking about where you work or anything like that, but you did that at the place you were working and Yeah.
And, and like what I'm trying to say is you did it in a, a commercial setting. It wasn't just a science experiment. Yeah.
So I think, uh, in one of the previous places I had worked at, uh, it start, we were trying to solve a problem where, uh, we were trying to sell, uh, unify different pipelines, uh, software pipelines. Because in general, what happens is when very large organizations, pipelines can get really fragmented. So unifying pipelines, uh, is very essential both for traceability and also cost.
But at the same time, um, uh, you should also ensure that security is not an afterthought, right? So, uh, we wanted to ensure that like if you take a typical software, uh, infrastructure pipeline, you have the curation process, create creation process, the build, deploy, and then the run. So when that happens, we wanted to sort of impregnate each of those boxes and ensure that security is embedded in each of, each of each of those layers while unifying the various pipelines.
And that was done in a very commercial setup. And then I decided to take it forward by also. And that was a time when, you know, open, you know, all the aa It was just coming up, All the AA stuff was just coming up.
And so I decided to, uh, integrate NLP based frameworks into that architecture. So very cool. By using, uh, JFR X-Ray and, uh, uh, JFR Artifactory, uh, that helped in optimizing the overall time it took to deploy infrastructure.
So I realized that by, uh, uh, inculcating a frameworks within into your DevSecOps pipelines, you not only make, uh, AI the whole pipeline safe and secure, but you also make it more accessible to not just engineers, but also people from, uh, other forms of interest. Because, uh, when you have an NLP framework, uh, up in front onto your service, uh, all the requests can be in plain simple English. So that, that's, that, that's probably sums it up in paints a picture.
Yeah, no, That, that, you know, and look, and, you know, the beautiful thing as we saw here at this year's swamp up. Yeah. Every day we're seeing more and more AI innovation, more and more AI capability.
True. So, you know, though, you've, so in essence, the framework is never done. Correct.
I think, uh, that's a, that's a great question. I think, uh, it, it's definitely an evolving architecture. In fact, the future directions that we want to take the framework is, um, for example, the, the current framework currently just focuses on ensuring that you, uh, uh, you know, export and software bill of materials and unify the various pipelines to put it in very simple terms.
Uh, software develop of materials is more about like, you know, imagine like a cake. A cake can have different layers. Mm-hmm.
Each, each layer can have, uh, different ingredients and each of those in ingredients can be sourced from different places. So the, once we unified the pipelines and we were able to generate a software develop of materials, we kinda knew what our software contains. But then, uh, we, we can extend it to like potentially like SALSA frameworks that can tell you like what it's made of.
And, uh, we could also take it followed by, you know, ensuring that zero trust is embedded into this framework. I mean, zero, when I say zero trust, I mean the five pillars of zero trust being, um, identity transport, authorization, uh, gateway and visibility. So one way, one way of possibly extending the, uh, framework would be to, I integrate zero trust in a much more closer fashion.
Because when you look at security as a first class citizen, you're looking at it, you can look at it from both, uh, top down and bottom up. Top down is more about ensuring that you use all the latest tools, AI, and ensure that, you know, your software is super secure and does not have any vulnerabilities. But when you do take a bottom up approach, you take, you put in a lot of attention to ensure that the APIs you develop are secure by design.
Sure. So, yeah. I love it.
If I had to ask you to look into your crystal ball and say, all right. Swamp up 2026. Yes.
And I don't know if you saw, but they announced New York, I think for next year. Oh, that, oh, that is true. Yes.
Yes. They had a, they had a, they had a raffle that, that helps us to select which location. But then I think it was New York.
Yes. Yeah. Yes.
Um, where do you see your framework being a year from now? Uh, yeah, that's a pretty deep question. I think, um, one, we do want to embed zero trust much more closely as I just mentioned.
Yes. Two, we also want to, uh, we had, we had benchmarked our, uh, uh, our framework and architecture with the then available open source AI models. We would probably do, uh, another round of benchmarking to see which it works well with three.
Um, we would also do a lot of like domain specific tuning to it, because I've realized lately that uh, there's a lot of power to small language models, uh, as well because they have a lot more context. And I, I think we're gonna see more sml Yes. Over the next year as people realize yellow LMS are good.
But yes, you need the SMLs for some very specific domain expertise. Yes. So that's what I see the architects evolving into.
Yes. Good. You know what we didn't mention?
Yes. If someone wants to go see this framework for themselves, how did they do that? Oh, uh, so it's actually, uh, we did have the opportunity to publish this framework, uh, in a conference in an IE conference that happened in Indonesia.
So the work actually is public, so, uh, Where can they go? So, I mean, if you follow me on LinkedIn, uh, it's our like Google Scholar. It's fairly, uh, easy to find.
Is it Our GitHub or anything? No, uh, It's on GitHub. It's on the IE explore page.
Uh, okay. That people can, could go and reference. Yes.
Well, now you mentioned your LinkedIn page. How do people follow you on LinkedIn? Just, is it under Harry or, that's Correct.
Yeah. Yeah. Just my first name and last name.
It's ma, easy to find. Alright. There you go.
Thank You Harry. Thank you for covering on text on tv. This wasn't so hard.
Thank You so much. It was a complete pleasure. Yeah, Absolutely.
Hey, we're going to continue our coverage here at, uh, JFR Swamp Up. Stay tuned. You're watching Textron tv.
Thank you. Atlassian in the cloud at last T-Mobile's, Skyhigh wifi under the red c Salesforce's lofty hack. Cisco and Vast are gonna team up is Midjourney at an end and we take a closer look at Google's shiny new Chrome case in this episode of the Tech Field Day rundown.
Hello everyone and welcome to the rundown for September the 10th. My name is Tom Hollingsworth and I hope you're enjoying some Turkey and what are allegedly croutons for lunch because it's national TV dinner day. That's right.
All of your friends at Swanson would like to remind you that those are in fact croutons. If there was ever any doubt in your mind, uh, what there is no doubt in my mind about is the wonderful thing that we have going on today. We call the Rundown.
Uh, it is also National Swap Ideas Day. I didn't swap any ideas though. I swapped my co-host this week because Al's out at uh, AI Infrastructure Field Day.
But joining me instead is Mr. Ned Bevan. Ned, welcome back to the show.
Oh, thank you Tom. It's great to be here. And I had no idea that those were croutons and they sure don't eat like it.
Yeah, I think that's the thing. Is it according to the package they are, but according to my taste buds, they are in fact not. And uh, the other thing that I wanna make sure that everybody knows is that the stories that we have are probably even crunchier than those croutons because they are some of the highest quality pieces of news that we could find this week.
And I wanna jump in and talk about everyone's favorite company Atlassian, because they've announced that they're retiring their data center products. Yes. That includes Jira, confluence, and Bamboo in favor of something they're gonna be calling Atlassian Cloud with Bitbucket, of course being exception through a hybrid license because of some very sensitive, so source code issues sales of new data center subscriptions end in March of 2026.
Your existing licenses will be expired in 2028 and everything is gonna be done by 2029. So there's your signpost folks. Get it done soon.
Organizations can migrate using self service tools for smaller teams or using the fast shift program for larger ones. Some customers, particularly those pesky US government users that have something that they're supposed to comply with called FedRAMP are gonna face a lot more challenges. Atlassian of course, highlights potential cost savings with the cloud.
If you talk to experts though, they're gonna say that most customers could see up to 28% or more on an increase. The announcement has of course, frustrated users who previously transitioned from server to data center and now they're gonna have to migrate to the cloud again. Ned, do you think ending this in favor of doing cloud stuff is going to be a boon for Atlassian?
Or do you think customers are gonna get mad? Yes and yes. Yeah, I mean, like you said, they'd already end of life to their server offering in favor of data center.
And it was really just a matter of time till they also end of Life data center. They were clearly moving to a cloud only model. And their claim is that currently almost every customer, new customer, they get signs up for cloud only.
So obviously that's what everybody wants. There are two big benefits that Atlassian gets out of this. The first one is a vastly simpler support model.
They no longer have to maintain a version of the software that runs on-prem and deal with all the weirdness that people have in their on-premises environment. So that's a big boon to them. I think it's something that Microsoft would love to copy with their uh, exchange software.
They'd love to stop supporting that on-prem, and they probably will at some point. The other thing they can do is charge more for features nobody wants. And that's a pretty common tactic across all of the SaaS companies that are out there.
And now that they'll have everyone locked in to the cloud only platform, they can force whatever features they want on those people and say, Hey, we're charging an extra $2 for our new AI widget, whatever that widget might be. I looked through some of the subreddits for Atlassian. People are not happy about this.
Predictably. Some were talking about the fact that they literally just finished a migration from server to data center, and now they are going to have to undertake that migration all over again. And if that's the case, maybe it's easier to migrate to a completely different platform.
But I think all Atlassian has to do is make the migration to their cloud platform slightly less painful than migrating to another product. And people are just going to deal with the change. The big question is, can they support FedRAMP, their promising to have an Atlassian government cloud available in the near future?
We'll see how that goes. That is, um, easier said than done. Let's say Southwest Airlines and T-Mobile announced a partnership to offer free unlimited wifi for all Southwest Rapid Rewards members starting October 24th, 2025.
Oh, so close to my birthday, not they know they could gimme a present. Southwest will become the largest US airline to provide free wifi on every flight available to all members regardless of their wireless carrier. Both companies emphasize their commitment to customer experience with Southwest investing in reliable in-flight connectivity and T-Mobile expanding its history of free in-flight services to millions more travelers.
Customers can sign up for a free rapid rewards account before or during their flight to access the benefit, no word on whether they need to queue up in line to see who gets the best wifi first. You have some thoughts on this, Tom? Uh, we're way past that down, Ned.
We don't do that. We're like everybody else. We get on the plane and 19 boarding groups.
And if you're double elite super unobtainium, you get to go on first. And all Southwest people that I I talk to are, are cringing a little bit right now. Um, I I actually welcome this.
Uh, one of the reasons why is because I am now of the belief that wi free wifi should be something that is being offered as a perk to get people to wanna use your airline. For those who are not familiar, um, a-list preferred, uh, status members and above have already had the opportunity to get free wifi on planes. This effectively is saying T-Mobile is paying to allow a-list, which is their, their first tier of status to get, um, uh, free wifi.
Uh, yes, it's available to all rapid rewards members. Why would they want to do that? Oh, wait, I know they want to collect all your information.
Yeah, so, so you guys know that that's, that's the reason why they want you to sign up for the account, right? Is because they wanna be able to track you and to be able to do all these things. Because it turns out that most people who fly Southwest don't have a status program that they belong to because up until about six months ago, they didn't care because they were using Southwest as a low cost carrier.
They're not Frontier and they're not, uh, you know, um, oh Spirit. Uh, they are slightly better than that. Their Spirit Plus, or at least they were.
And now Elliot Capital Management, the bane of everybody's existence, uh, believes that they should be more than that. But the problem is, is that in order order for that to happen, Elliot either needs to nickel and dime everybody to death, or they need to create value somewhere. Well, how would I do that?
I know I'll get T-Mobile to pay us a small fortune to be able to offer free wifi. And because you have to have a rapid rewards account to be able to access it, we're gonna be able to collect data, send you ads through the portal, and email you stuff all the time. Oh, wait, that's right.
I just booked a Southwest flight today and whenever I clicked finish, I got one of those fun little post-purchase prop popups. Hey, would you like to try two free months of clear on us? Hey, do you know that you can get 50% off of a Sam's Club membership?
Folks, the handwriting's on the wall, it has nothing to do with free wifi. It has everything to do with Southwest continuing to try to, to create customer stickiness in order to get people to stay with them because they're starting to see the customers are leaving. Those of us who have been flying Southwest for a very long time or who have a corporate mandate to use Southwest, I don't know that things are gonna change.
I do like the fact that I can now check my wifi, but the problem is, is now that everybody else on the plane can check their wifi, they're gonna have to do a little bit more on upgrading those things. So we'll see what happens. But until then, bring me, uh, the non peanut snacks and the ginger ale and I'll be ready to go.
Undersea cable breaks in the Red Sea disrupted internet traffic in the Middle East and South Asia, slowing some of Microsoft Azure and other services on Asia to Europe routes. Microsoft was able to reroute traffic to keep their services online, but higher latency could continue until repairs on the key cables are finished. That could take a few weeks while the causes unclear.
Similar incidents have happened before. And if you know that Red Sea area, you can probably guess where those cable breaks happen. Most businesses aren't heavily affected, but if you're one of those companies that has latency sensitive services, you should probably check on your systems.
They're not okay. This event underscores the importance of network redundancy to keep the internet running during outages, but I think as we've talked about in the past, it also underscores the fact that some of our infrastructure is uniquely vulnerable to anchors being dragged across the sea floor or, um, unfriendly people in certain countries deciding to just destroy those cables. Ned, do you think Azure could survive a hit like this again?
Or do they need to get that thing fixed really quick? I think they absolutely need to get it fixed pretty quick. But Microsoft, along with the other major cloud providers, have built out their own backbone of fiber all across the world.
So they could probably stand to lose a few more cables and still be okay routing traffic. But I think you bring up a good point. The fact that it does increase latency, because now your packet, instead of going to point A to B is now gonna go to point A, C, D, F, G, and then maybe B.
So it does have to pass through a lot more routers and in effect travel farther than it did before. And when everybody has to do that, the overall latency of the internet suffers. That's the sort of thing you can see on net blocks.
Who confirmed the outages initially that happened, uh, impacting Microsoft as well as everybody else who was using those cables. Now, Microsoft does have some cables that are private to itself, and in those cases, if that cable breaks, it only impacts Microsoft, but it's gonna have to route that traffic somewhere and that somewhere might end up being the dumping ground of the public internet. So being aware of that and having regional presences that won't get disrupted if your cross region traffic gets cut off or is highly latent.
And also having edge presences might be something that you might want to look into as a company, especially if you have satellite offices or customers that are remote to you. And especially around this region. Having an edge data center that's close by that's not affected by a cable cut like this would probably be a wise investment moving right along in August.
Google's threat intelligence group reported that a hacker group known as UNC 63 95 stole OAuth tokens from the SalesLoft Drift apps Salesforce integration to bypass authentication, including MFA. That's not good. And they used it to extract large amounts of data from hundreds of Salesforce customers.
That's worse. The attackers deleted query job records to hide their activity and targeted sensitive credentials such as AWS Keys, passwords, and snowflake tokens with the stolen data. But of course, everybody is using dynamic credentials these days that expire after a few minutes or hours, right?
Tom? Ha ha ha. No, no, that's not the case at all.
Uh, also props to the, uh, the hacking group for almost being the USS Thunder, thunder child from Star Trek. You, your, your registration number was almost there. I I don't actually know what you were going for on it.
Um, this is going to be the biggest, uh, area that we're gonna start seeing. A lot of these, uh, breaches happening in is not kicking in the front door. It's tailing the, uh, contractors in through the smoker store, if you will.
Um, one of the things that we saw with the Snowflake problems is that a lot of companies were having data breaches, and I use the Quoing fingers there because what was actually occurring was, is that Snowflake wasn't secured, right? Well then it was not incumbent upon these companies to, uh, you know, secure themselves 'cause they couldn't because it was Snowflake that was causing the problem. So now what we've got is a third party add-on to Salesforce that was breached, that was able to connect back into the system and start harvesting this data.
And yeah, this is one of the things that we know that these companies love. Things like, uh, you know, a Ws a keys, uh, passwords, any kind of tokens, I mean, get in, those are very valuable because even if they are following practices and expiring them quickly, it does not take me long to get a foothold. In fact, as we learned at, uh, one of the presentations all the way back at security Field day one from CyberArk, um, if you accidentally paste an A-W-S-A-P-I key into the wild, anywhere on GitHub or anything like that, just assume it's compromised because those things are gone almost instantaneously.
And that's what we're probably gonna be seeing here, is that a lot of these tokens are gonna be attempted to be reuse. Don't assume that these things are valid, just expire them and move on. But I will tell you that the reason why I know this is a thing is because a friend of mine sent me a text message and it basically said, this was my weekend.
How was yours? And it was dealing with the fallout from this because all of these systems being as tightly integrated as they are, whether it is, you know, upselling them into a new license class or my other favorite thing, uh, hey, let's, uh, let's see what AI can do with all of this. We just need access to the entire system to be able to munch all this data.
Uh, we're now starting to see the limits because if, uh, if your AI agents can go do this, guess what else can too? The secret dirty KGB agents of the attackers or something like that. So, uh, change your passwords, spiral all your tokens, um, uh, do not pass.
Go trade all your tickets in it, Chuck E. Cheese, whatever you've gotta do, just go out there and fix this because your life will be significantly less miserable if you do. My friends over at Cisco are partnering with Vast Data and NVIDIA to make it easier for IT teams to run AI applications at scale.
By adding Vast Insight Engine and shared everything storage to Cisco AI pods with Nvidia GPUs, the platform enables fast real-time data access for advanced AI agents. Of course, this is what helps organizations standardize their AI infrastructure, but challenges like legacy systems, skill gaps and high costs still remain that's gonna be pushing IT leaders to balance cloud fees with a new expense of on-Premises hardware. Ned, I know that you have probably immersed yourself in all of the wonder that is ai, but I have a question.
Will being able to add these features to AI Pods really encourage people to start investigating ai or is this just another thing that a few people wanted and they figured they'd put it on the truck? Hmm, good question. I'm not sure.
I'll ask chat GPT and let you know. Seriously though, I think that if you are an enterprise that's championing, championing, that's a word, AI right now, one of the things that you're trying to do is supplement the existing models with the information that exists inside your organization. And that's usually done through RAG or retrieval augmented generation.
That is something that makes AI notoriously data hungry. It wants to vacuum up all these data sources, but it can't, you can't just point it at a file share or a database or a repository of objects and say, go look through all this and tell me what you find. It actually needs to transform that data into something that AI is able to incorporate into its existing model.
And that's done through Vector databases. What Vast is offering here is not just a storage platform, but also the data pipelines to do that transformation of structured and unstructured data into vectorized databases that can then be incorporated into the AI model. And so it's this tight coupling between Vast Storage, it's operating system, they call it an AI operating system, and it's insight engine tying back into the GPUs, the Nvidia GPUs that are gonna be inside these UCS chassis supplied by Cisco.
So I think Vast is the, is the secret sauce here. I'm not gonna say that Cisco doesn't make cool hardware 'cause they do, but it's really like Nvidia and Vast and Cisco supplying the box that they get to party in. That's what we're looking at here.
If you're in the market for this integration of your enterprise data into AI models to try to surface some additional intelligence or something along those lines, this might be very attractive to you, especially if you're already a Cisco customer. Dell and HP already have similar products that implement similar features and I think the big thing is probably the GPU and and the storage and less so the compute that sits behind it. Warner Brothers, speaking of ai, Warner Brothers has sued Midjourney joining Disney and Universal in accusing the AI company of profiting from image models that generate copyrighted characters.
The complaint claims midjourney let users recreate characters like Superman, Batman, wonder Woman, Scooby-Doo, bugs Bunny and Rick and Morty in any scene violating their intellectual property rights. No word about scrappy do though Warner Brothers argues that Midjourney knowingly removed copyright protections, continues to produce countless infringing images and must face a permanent injunction injunction to stop the studio also seeks profits Midjourney allegedly earned by exploiting its characters following the infringements, intentional and ongoing. As someone who has managed to use various AI tools to create copyrighted material, this is definitely a thing that you can do.
I'm not sure that Midjourney is unique in this regard. Tom, do you have any experience with it? Yeah, actually I do.
I'm gonna take you back 21 years. Oh dear. There Was this multiplayer online roleplaying game called City of Heroes, near and dear to my heart.
You could log in and you could be a superhero. As I told our good friend Ethan Banks one time, the way that I like to relax after a long day of doing it is throwing face. And he goes, I never thought about it like that.
You had a character creation system. It was one of the most impressive character creation systems that was available at the time, and you could do pretty much anything you wanted. So what was the first thing that everybody did?
They logged in and they made a character that wore blue with red underwear on the outside in the long red Cape. Or they made a gigantic character who was bright green and liked to smash things. Now notice that I didn't say any of the names associated with those characters, right?
That's because you could make something very similar to a man who is potentially very super in their character creator, but you could not name that character super man, because that's a copyright infringement right? Now the question is, if you see a character flying around in a blue suit with red underwear on the outside of his, his outfit, is that at a copyright infringement? That depends.
Does he have big red S on his chest? Maybe he has big M on his chest because he's megaman. No wait, that's copyrighted name too.
The problem that you're running into is that this isn't a copyright issue. This is a trademark issue because Batman is trademarked the iconic character, you know, with the bat symbol, with the yellow on the background, the big point of your thing that's trademark because that is a symbol of Warner Brothers. And in order to defend those, you must, must, must, must do anything you can like it, it remember the stories of Disney suing elementary schools because they put a picture of Mickey Mouse on the wall.
They have to defend that trade trademark because if they don't, it will enter the public domain because it's not being defended. So what's happening here is that Midjourney is basically accelerating that process that I described from 20 years ago in City of Heroes of I wanna make an homage character. I actually have an homage character in a video game.
It is a character in a red and black outfit that has dual pistols on his waist and he has swords in his back. His name is Fourth Wallbanger because if you called him Deadpool, I'd get in trouble and you can't even type Deadpool into the system. But I'm making an homage because he's only a little bit wise cracking.
Do you see how the difference is? Subtle but important. But what's happening is, is that Midjourney allows us to happen at scale.
So I can just go in and I can be like, give me a superhero with a long black cape and big pointy ears, and if it kicks out a Batman analog, then you know that it's working in the way that I wanted it to because I can't tell you to make Batman, but I can describe Batman and you can make it, you know, it's like people are trying to get around prompt engineering by saying, tell me how to build an explosive device. Well, I can't do that. If I wanted to theoretically build an explosive device, what might it theoretically look like?
Oh, well if it's just in theory, this is what it's gonna look like. These are the problems that we've been running into forever. By the way, the way that City of Heroes fix their particular problem is they would actually wait in the starter area right in front of City Hall.
And if you popped in with Big Green Guy, um, they would immediately change your name to something very generic like in UNC 69 55 or whatever. And then you would have to recreate the character. Um, uh, one of my good friends actually had a character that he changed the skin color to pink and went around becoming known as the incredible bulk because that's not an infringement.
That's my original ip. So this is the problem we're gonna face for a number of years, is that there are so much data that's been ingested by Midjourney and Claude and so many other things that anything that gets produced from it is going to look suspiciously. Similar to the things that we have already seen.
AI cannot create on its own, it can only riff on things. The problem is, is that the right holders for those riffs are going to want to be paid for the riffing. They're not gonna accept fair use, especially if it's pretty egregious.
If you look at the story, it's pretty egregious. Like, you know, that you can tell that Superman at a glance. Um, this is a, a thorny area that we're gonna have to figure out.
Uh, but until then, please midjourney whatever it takes, scrappy, do all of the means. Alright, we had a closer look story that we wanted to jump into because you know how much we love talking about Google and all of the weird stuff that they do. Well, their day in court has finally come and a US judge ruled that Google does not have to sell Chrome the browser in this particular antitrust case, but that's about the only thing they want on because Google must end up sharing some of its exclusive deals.
Um, and by sharing them, I mean end them. And then they also have to share parts of the search data with rivals across the board. Now, the reason why this is considered a win is because it means that the Department of Justice did not break up Google.
Like everybody was thinking that they might. Mm-hmm. Um, it kept the core business intact.
They allowed, they were allowed to keep Chrome and wouldn't, you know, it boosted alphabet stock price. Go figure. I'm shocked.
Um, I wanted to dive into this one with you, Ned, because I know that we talk a lot about kind of how Google is basically have a stranglehold on the internet today. Um, a lot of people wanted Google to sell Chrome. I think that that was the wrong remedy for the particular situation.
The judge in this case actually did dive into a lot of topics very closely and I was wondering if maybe you could kind of give us your take on it because I have some thoughts, but I wanna hear what you have to say first. Yeah, I mean, Google was found guilty of having a monopoly over advertising and search. That was the, the finding from last year, I think sometime in August of 2024.
And so now it was up to what's the remedy? What should we do about that? And a lot of people, including the Department of Justice, were pushing that Google have to divest from Chrome and Chromium and also potentially Android.
The judge who was looking over what we should actually do said, while that is a potential remedy, they did not feel that it was necessary and that it would have the intended effect of breaking up Google's monopoly and allowing other entrants into the search. Although search is driven through Chrome and Google does set up Google search engine as the default search engine on Chrome, forcing them to divest from Chrome wouldn't necessarily change that fact. And it would also force a worse user experience on the customers who are using Chrome today.
And generally the yardstick that's been used for Monopoly is what is the impact to customers, not the market as a whole. If you're negatively impacting customers by the presence of your monopoly, then then something needs to change. But if you have a nice monopoly and your customers are doing great, then the Department of Justice has mostly turned a blind eye to it.
And so the finding was stripping them of Chrome that's not gonna do anything in terms of this monopoly. Instead they went for other remedies like barring them from having exclusive arrangements for search and advertising. Now that doesn't mean that Google is barred from making payments or offering other consideration to their distribution partners or even preloading the placement of their Google search.
They're still able to do all of that. It just can't be exclusive in the contract. It can be exclusive in practice, but it won't be exclusive in the contract.
Do I think that this is enough to actually end Google's monopoly on search? Not even close. I don't think anything that they're doing in this decision is actually going to materially hurt Google in the long term.
'cause it has extended such a lead in terms of search monopoly. There would have to be a sea change for that to occur. And I'm curious what your thoughts are on what would actually need to be, need to happen as a remedy for this situation.
I think the judge realized that the remedy to fix Google searching problems is already happening and she can't do anything about it or he can't do anything about it. I forget who, who the judge in this case was. So I absolutely agree with you.
Chrome is not the problem. Chrome is the most visible, um, expression of what goes on because we use it all the time. But I see this problem on Firefox, on Safari, on edge, whatever The problem is not that Google has control of the browser, the problem is is that the browser effectively uses Google services for everything else, right?
Gmail, search, web ai, there's your problem. The way to unseat Google is the king of search is not to break up their monopoly. It's to find a different way to search.
'cause if you go back in time long enough, Google was not the king of search. I have used Alta Vista, I've used Ask Genes, I've used tons of things. What ended up happening was is that Google got better than all of them.
It was only when Google was in the front that had decided to use that power for their own ends. The only way to break that is to find a different paradigm, a c change, if you will. And I think that's what AI is because that's one of the reasons why Google is scared right now.
They're seeing dropping ad revenues because people aren't clicking six pages deep into a Google search anymore. They're not even clicking on it. They're going to that box and saying, typing in their question.
And AI is returning the result at the top. So nobody sees these ads, nobody sees this product placement. And the judge said, well, I'm not gonna slap your hands for paying $20 billion to be the default search engine for an iPhone.
What I'm gonna say is, is that that can only be the case if you continue to pay. There has to be a way for other people to be a part of that. And I'm gonna try to level the playing field.
This goes back to a story we talked about, uh, it was either last week or the week before where uh, a certain um, uh, rocket ship maker and electric car manufacturer was very mad that, um, oh, his competitor AI Pro platform was the one that was the default in iOS. And my response was, well then why aren't you paying to be on the list? That's basically what they're saying is you can be on the list if you're willing to pay.
And if you remember from my rant from back then, my rant was Internet Explorer in and of itself was a really crappy browser. It just so happened it was on the desktop and Windows 98. That's why it became the dominant browser.
When you had to go out and download Netscape Navigator by using Internet Explorer to find it, it kind of became a no brainer. One of the reasons why I still use Safari on my Mac is because it's included in the operating system. Yeah, I use Chrome for a lot of other things too, but I am a person who's gonna switch back and forth to use what I need.
Most people don't. They pick one and they go with it. When I install my mother-in-law's computer for the 45th time, I'm gonna put Chrome on it because it's what she's familiar with.
Google is not the enemy. What Google did to the services on the backend is the problem. And like you said, monopolies are only useful if they benefit society.
Google monopolizing ads, you can argue it didn't really benefit society, but you can't break that up legally. The legal remedy just means they're gonna find a way to transform what they're doing. And then the two pieces are gonna become competing companies that are just gonna get bought again later.
Don't believe me. How many phone companies do we have in the US right now? How many phone companies did we have in the US in 1982?
All of the baby bells are reassembling to become Bell Voltron again. And Ma Bell is getting back together sooner or later because that's how all of these things work. That is how capitalism works.
We reward the people who find the best way to make the most money and Google did. And now everybody's mad because they don't have $20 billion to pay Apple or Google to be the top search engine result. So I don't know how we're gonna fix this, but I also don't know that it needs to be fixed because the paradigm shift is happening as as we speak.
And I think AI is the way that is. That whole thing is gonna be broken up. I think the problem with the monopoly was they didn't really address the core issue is the fact that Google owns both sides of the ad business.
There's the selling ads to those who want to present them, and then there's the presentation of ads. The, the auction that happens every time a page loads that has Google ads on it. Those are two separate products, two separate offerings.
They used to be separate companies that Google bought and brought in-house and then they were able to set up this agreement between the two businesses basically locking everybody in and punishing those who tried to go outside of their walled garden. I think the Department of Justice could have forced Google to break up those two portions of the business and saying these two portions now just need to spin off and become their own distinct organizations. Kinda like breaking up Mob bell into the baby bells.
It would've been extremely disruptive and the court basically said, breaking up or hurting Google might harm customers. And since the court cannot predict the future, it is opposed to making these sweeping changes that would disrupt the market, the market, which is still currently a monopoly. So if you think monopolies are bad, then the court didn't go far enough because it failed to break up the monopoly.
If your perspective is, are customers going to be more hurt by this disruption in the short term? I say probably would there be a bigger benefit in the long term? I can't say for sure, but I generally don't think monopolies are good for capitalism, the free market or for customer experiences over the longer tail of, of a particular service.
Fortunately, I think you're right. Slowly we're gonna see search replaced by Gen AI once it gets at least a little bit better. And the way that they choose to serve up ads is going to have to change along with it.
Right now chat GPT doesn't serve me up ads. There's good, they'll they will find a way to monetize it, but right now it does not. And I'm one of those weirdos who pays to, uh, coy for my searching.
So I'm actually paying for a search product anyway. So I don't see the Google ads as much, but I think yeah, Google's gonna have to fundamentally shift the way that they make money within the next 10 to 15 years. But it's gonna be a slow shift as the new generation comes into its own and adopts these other ways of searching the internet for whatever it needs.
I think we're gonna be talking about this story for a few more months to come. 'cause we haven't heard the end of this. No, but you also haven't heard the end of tech Field day yet either, because as I mentioned at the top of the show, my regular co-host, Mr.
Alistair Cook, is out in Silicon Valley right now doing AI infrastructure Field Day. com for the next couple of days to learn all about the cool stuff that he's talking about. Then you get to hear from me in just a couple of weeks because I'm gonna be out in Silicon Valley doing Security Field Day.
We have a great lineup of presenters including first time presenters, one password and Square x. com to see a lineup of who's gonna be a part of that. Then I have a special event coming up on October the ninth.
We're gonna be doing a special exclusive event with Microsoft where we're gonna be doing a virtual discussion about Microsoft Sentinel, which is, uh, you know, exciting, uh, security, kind of focused in the cloud, doing some other cool stuff. Um, they're gonna be talking about it on September 30th at one of their events, and then we're gonna get them the next week to talk more about it. So make sure you stay tuned and be ready for that.
Then Cloud Field Day is taking place October 22nd and 23rd. Um, Alistair's gonna be talking to some great cloud companies and having a lot of fun. And then at the end of the month, get your costumes ready and all of those spooky things because Steven is gonna be talking AI at AI Field Day on October 29th and 30th, and I can't wait to see what he has in store for that.
I'm sure it's going to be scary. We're not scary though because we're always here for you on the rundown. And we want to thank you very much for watching today.
Catch our episodes every Wednesday on YouTube on our website if you wanna read the show notes or in your favorite podcast application of choice. The rundown is also being streamed on Techstrong tv and you can catch us on other tech strong or future and group programs. I'm now happy to say that I'm gonna be on Techstrong gang, uh, offering my perspective on things and maybe an opinion here or there.
You you never know. Uh, don't worry about us though. We're gonna be back next Wednesday with all of the great IT news that happened in the past week until then for myself, Tom Hollingsworth, Al Cook, and for Ned Bevan today, thank you very much for tuning in.
We sincerely appreciate it and we hope that everyone of you out there has a great time, has almost a great time as we had making the rundown today. We'll see you next. Hi, my name is Cina Brookfield and I'm part of the technical marketing team in the VC of division at Broadcom.
And in this session we'll be talking about VMware Cloud Foundation nine and how we've built a private cloud that is made for all of your applications, whether those are running in virtual machines or in container and what you need to really support all of your workloads with Beware Cloud Foundation nine. We have promised you that we will deliver a private cloud, but what does that actually mean for your workload? Well, when you think about it, it's not simply just about deploying virtual machines or maybe deploying some Kubernetes clusters and applications running in containers, but it's really about emulating that cloud experience on your premises in your private cloud.
And in order to do that, we need to build something more robust, something that gives you services that you need to support your workloads. So whether you're talking about cloud services, infrastructure services, or any kind of additional functionality, that's the kind of experience you would expect from a cloud, especially from the perception of a consumer that is coming into the cloud to deploy their applications and have everything self service and on hand. And that's what we will focus on, uh, in the following slide.
So mainly in order to unlock this cloud experience for all of your workloads, whether those are virtual machines or containers, containers running in Kubernetes clusters, we had to come up with a unified way of controlling everything that's running in the ecosystem. And the way we've done that in VCF nine by embedding this declarative API, which is called these four supervisor, which exposes a desired state ecosystem with an API and a set of services that you can use to support your workload. So what are you are deploying virtual machines, Kubernetes clusters, containers, or any other services that you would need because for your applications, you may need a load balancer.
So we do have a network service that comes in the platform. We also have volume service if you need to be deploying any persistent volumes, but also additional services. For example, if you want to store your containers in a private image registry, deploy harbor on our platform.
But the main idea of this ecosystem is that it is extremely palatable. And what does that mean? While we know that there are some core services that we need to offer out of the box, we give you the power to choose and select what capabilities you want to bring into your ecosystem by selecting services from our catalog and an easy way of introducing new functionality onto the platform.
But the best thing about this extensibility is that having the same target and the same ler API guarantees that you will have the same consumption experience as well. So we're no longer talking about integration points, but the native deployment of functionality into one location. And also importantly, especially from the consumer experience and again, a cloud experience on your platform, we are extracting away all of the underlying infrastructure.
So a consumer really doesn't need to know anything about, uh, about compute or storage or networking in order to be able to fully self sufficiently deploy applications, uh, and any services that they need. And in order to see this, um, I will guide you through a set of demos. So at first we will look at some basic workflows like deploying a virtual machine or deploying a Kubernetes cluster.
What I really want to highlight here are mainly the new things that we have introduced in VCF nine. Then we'll look at how we can update some of these services and how does this lifecycle of, um, vSphere Kubernetes service, for example, specifically work. And then we'll talk about something that brand new, uh, just recently introduced and very exciting.
And that is our own GI up service. What we have done is we have introduced Argo CD service into the platform to give you that continuous delivery. And we'll end with a little demo about updating the supervisor itself because I want to show you how you can unlock this new functionality really easily on your platform.
So here we'll start in my lab environment, uh, where I will show you how a setup of VCR nine would look like from a consumer perspective. I'm accessing VCF nine through our automation portal, which is brand new and fully changed. And all I have to do is define my organization name that I have here and a username and password that was given to me to access.
And as soon as I enter, I can see everything that I need to see as a consumer. I can see a overview of services that are available to me. I can see utilization of the space, but I can also see all the projects that, um, I'm member of namespace that have been created here and any users that are part of this.
So let's use this single user interface to deploy workloads and we'll start with a virtual machine. Under services, you will see the main services that are exposed to you, one of them being the virtual machine service. So here we're going to go ahead and create a virtual machine, and here we can choose whether we're deploying the virtual virtual machine from an OVS template or now also with VVCF nine.
We can deploy directly from an iso. I will give my virtual machine a name and I can also select this zone where I want this to sit, and an image that will be used as a base. So in this example, I will be deploying BOOM two.
I will then configure hardware resources of this virtual machine by selecting a VM class. And I can continue, I I, since we're showing this from a consumer level, I take of what we're seeing is like a curated view, uh, set up by an admin or something so that the services that this user can provision and administer are, are limited to whatever they has been decided they have access to. Kind of like how we have public cloud governance, now we have it for private cloud.
That's absolutely correct. Everything I'm showing you now is the consumer experience. So the user who is deploying the board cloud, what I will show you as well is the other side, what's in the background.
And that's the part that the cloud admin would set up because exactly we need to have the governance and policies to select what can be deployed on the platform, what is available to the users. So absolutely that is controlled by the admin. Thank you.
Uh, so in this flow, if I wanted to, I could also directly access some of those other services I was mentioning. So for example, if I wanted a persistent volume, I can directly, uh, request it in this flow. And similarly, if I would want the load balancer to maybe open up some ports on this virtual machine and from them by a load balancer, I can do this in this flow.
So it really shows the nice integration of the platform, again, completely abstracted for me as a user, but the part that is the most exciting one is always the full customization of the virtual machine I am deploying because I'm not just creating a Shell virtual machine. I have the possibility to pass through cloud in IT and do a full configuration of my vm. If I will be deploying Windows, I would be also using S Prep.
And one of the new things that we have introduced as well, it's to give you a little bit more guided inputs into cloud in it in case you don't have a full configuration at hand. So this is really simple. For example, what I can do here is I can create a new user.
So what I will do, I'll create a new user DOT's called DevOps. I will enable the user to log in with SSH and then I can add comments that I want to run during this first boot of the virtual machine. So for example, here I will show how I can deploy A CLI VM and install all of the tools that I will be using later on.
So for example, our brand new V-C-F-C-L-I that I will show you a bit later with all of my commands set there, I can continue with the configuration. The other new thing that we have introduced, and this is really exciting as well, is the ability to do more network configuration during the deployment phase. And especially because with our new integration with VPC, we have much more control over networking.
So as a consumer, again, I may decide to create my own VPCs with a public subnet allowing me to access this virtual machine on an external IP address because normally everything would be deployed by default into private subnet. So I will show you how to switch this into public. And then again, we have few more options we can do.
So we can pass through configuration, like for example the host name, domain information and DNS and the full configuration of this virtual machine. Because keeping in mind this is all these desired state has been written fully automatically for me on this right hand side, not just for the virtual machine, but for any objects that I will be requesting in this flow. So I don't have to know the structure of this YA file.
Um, I don't need to know how to, uh, um, how to add all of the options. It is done nicely for me. Do we have any place, uh, to keep a centralized secret management or we have the secrets in some files, um, just storing our own solution.
So we have just introduced again and VCF nine, our own secret store where you can create secrets, um, and store them centrally, uh, manage them with policies and governance and then inject them into any workloads you're deploying. So whether that's virtual machines, um, containers running down, uh, vks clusters or in these per port. So there is a brand new service, um, that is available on the platform, again, can be introduced.
And then within the services there would be a special, um, tab for secret management. So we will now, um, download these files and just continue to deploy this virtual machine. Once it is deployed, uh, we can see it was given, uh, an IP address as well.
And we can see some basic things in the, uh, user interface like opening remote console or for example, we could do some data operations. For example, if you want to recharge the virtual machine, you can change the VM class to uh, maybe give it a bit more CPU or memory. But what I'm going to do now is grab that external IP address and just directly SSH onto this box using the user that I have created during the guest customization phase.
So we can see that that's working fine. Now I can show the versions of the commands that, or of the utilities that I have installed in here. So we can see that the full configuration that I've passed through has worked well, but there was a virtual machine.
And the topic here as we're talking about this unified platform for everything. So now we're going to use the same experience, the same user interface to deploy Kubernetes cluster. And in here when we deploy a new one, we can select default.
I'll get to that in a minute, or a custom configuration, which can show you, um, a more options. I'm going to give my cluster name and then I can select a release that I'm going to use to deploy my cluster. So for this demo, we're going to go with version one to 30 team.
Following this, there are more configuration options that we have added to the user interface. So for example, if you want to control your certificate workation, you can do it directly here, um, or some advanced networking options. Uh, during standard configuration, we continue with the configuration of a control play where we can choose from photon or Ubuntu operating systems.
And then moving on to our workload, uh, to our work, no work note. So in here I'm going to create a note pull. I can select an operating system.
So as I mentioned, for example, in here, I'll switch to Ubuntu if I wanted to. I can also follow our processes to deploy, uh, or create my custom image for Windows. If I would have any Windows containers, then I would be able to deploy Windows-based work noes.
The control plane of the cluster would still stay, uh, Linux-based. And some of the new things we've added here, for example, if you want to add any labels to your notes, you can do it directly. Uh, again, in the user interface, which is really neat.
With VKS, we really try to give you and give the consumers a service that is really easy to operate, but also has a lot of functionality. And it's really up to you how you want to create your clusters. If you want to create clusters of different versions, what kind of sizing you want to do?
Small clusters, big clusters, depending on your need. So for example, if I wanted to, I could mix and match the operating systems. For example, I could add another note pool with different configuration or maybe different operating system.
So that's always, uh, available to me. And again, the full customers, uh, full specification has been created for me with all of the fields. But always keep in mind that this is just a subset of what is available in the actual API.
So, uh, for example, one of the use cases I do all the time, it's also great if you need to create a structure of your cluster to have the base. If you then want to go on and add some advanced features that are not exposing the ui, you can do that directly by, um, uh, using, for example, the CLI to apply this, um, and add the configuration that you need. But again, same as we did with virtual machines, I'm going to download this because we'll get to that later.
And now I can just wait few minutes until my cluster is ready. Once it's done, I can download its cube config file if I want to, um, to have access to that directly. I could also do some data operations on this cluster.
For example, if I wanted to add any persistent volumes as an addition, I could do it as a data operation. If I wanted to do any scaling, it's extremely simply to do it with simple to do it with VKS, all I have to do is edit. For example, my note pools change the number of replicas, scale out my cluster.
Very, very simple to manage, um, and operate. And what what's also really helpful is that, again, in the same view, I can see all of the resources that were deployed for my cluster. So for example, every Kubernetes cluster needs, um, needs a load balancer, uh, that is fronting the fronting the control plane.
Um, and we can see that the network service here has automatically created that for us and we can see the external ip. Good question about, um, the, uh, east, west, um, traffic between cluster. Is there any service mesh or something similar be implementing or in this ui?
So it's, is it difficult to bring those, um, one or more cluster with service mesh, you know, and, uh, is this, uh, uh, UI solving this problem or, uh, just reduce the complexity to manage, for example, our, uh, me a measured cluster? Mm-hmm. Uh, so I have, uh, several answers to that.
Um, maybe depending on what exactly, um, is the end goal when it comes to service mesh. What we did introduce in, um, in the latest release is support for Istio, um, which we deliver as a VAS, uh, standard package, okay. That you can install on the clusters as far as the user interface, uh, in this particular place, um, it'll allow you to deploy Kubernetes clusters.
It does not give you user interface directly into the cluster if that is what you are referring to. However, we also have our case cluster management, which is bringing a lot more functionality for the kind of multi cluster management policies, um, and things like that. Yeah.
Um, yeah. Thank you. Um, yeah.
So, uh, within the, uh, uh, user interface, what I just wanted to show you, because our vks clusters are deployed as virtual machines in the background using VM service. So the platform is using itself. You can see those listed as well under virtual machines.
If you want to, you can filter them out. So we can see our cluster is here, and now we can use our new CLI that we have introduced called V-C-F-C-L-I to work and manage, uh, work with and manage this cluster using this cluster plugin. So the first thing i, I will do is I will register my cluster and I will get its cloud config using the CLI, and then I can create a context, uh, for this cluster.
This will allow me then to switch back and forth between my vSphere namespace context where I'm deploying the cluster and the cluster itself. Um, so in here, uh, we have added a new context, then we can just switch into that. And once we switch into the context of the cluster itself, we can use our standard cube CTL commands to, for example, list a note, uh, regarding those packages that I've mentioned previously.
The way we, uh, do package management on our Kubernetes clusters deployed with VKS is again integrated with this V-C-F-C-L-I. So all we have to do is add a package repo or package repository that we, um, continuously update and add new functionality into. So I have added the latest, and then I can list all of the packages that are available for me to install in my BCAS cluster.
So as you can see, there's, um, there's packages we've had for a while, but some of the new things I'd like to mention, for example, with autoscaler, we now have support for, um, uh, scale down to zero on worker node. Um, and one of the new, uh, packages, as I've just mentioned, is Istio coming, um, into this. So you can go and, um, deploy that.
But what I wanted to show you now is, uh, as, as we have seen, uh, in this demo, we have deployed a cluster. We've deployed the latest version that was available to me as a consumer, but the version that we have deployed was Kubernetes version, uh, one point 32. 4, which supports Kubernetes release one point 33.
So what I can do as a consumer is I've switched my context back to my namespace, and I can list all of the Kubernetes releases that are available in this space. And what I will see here is that I do see 1 33 listed, however, it is marked as false, which means that it is not compatible. And this is because the version of the service needs to match, uh, and unlock this functionality.
So from a consumer perspective, I can see it's available. I can ask my cloud admin to update this for me if they haven't already done it. Uh, but I do have a full visibility of all of the releases that are available.
This is because we distribute all of our v Kubernetes releases, VK using a subscribed content library that we create by default. So the images are already there and ready, need to use, we just need to make sure that the version of the service is updated. So in order, I'm Sure I heard you're right, uh, you said that if I as a consumer want to get to that latest version, I have to ask the admin to, to upgrade, and I cannot do it myself.
That is correct. And that is by design, because f as we've mentioned, uh, the cloud admins are the ones who have the actual access to the infrastructure. As a consumer, it's completely abstracted for me.
So I do not see it. And also, I may not know what the policies are. Maybe there's a reason why certain, uh, versions would not be allowed or maybe, uh, this, there may be multiple organizations using, um, using the service and, uh, need to align on the version.
So it's the governance of it stays with the cloud admin. Would the same be true for deploying a new application on a new Kubernetes cluster? Like, Hey, I wanna deploy new one.
I want to, uh, cluster with the latest version. I, I need to request that through the admin as well, Uh, application onto the Kubernetes cluster. Specifically, I, if I am deploying a new an application and I want a new Kubernetes cluster at the latest version, is that also a request to the admin for me as the consumer?
Oh, as, as for, um, as soon as the, uh, cloud admin, uh, uh, updates the service version, which I will show you now how simple that is, we will see that you will immediately see, uh, 1 33 listed, and you can then go ahead and deploy clusters, uh, as you, as you want to. So from the cloud admin perspective, now I switched over to the kind of vSphere view. Um, we will see our namespace with the resources, and then we can go into our supervisor services, which is, which is our, uh, which are services which have their own lifecycle management.
This is what gives us that ability to release new versions of VKS so fast and so rapidly to be able to give you access to new versions of Kubernetes really quickly. 4. So all admin has to do is go and grab a definition file, uh, that defines the version of the service.
This is now located on our support portal. So all they have to do is go in and download this simple file, save that. And now within the service, they can just grab that file, upload it.
They don't have to do any changes to it. We finish. And this will add additional version that will be available for installation.
So we'll see the active versions, zone two, three. And now if we go to manage, we can select the version we want to install. 3.
4. So they just select the version, select the supervisor, and then, uh, uh, continue the operation without having to do any changes. That's all they have to do.
So it's really simple for the admins to, uh, manage this. And as soon as the services configured, we can go back to the command line, and now we can see that the status has changed to true. And if we go back to our user interface, so again, you can see we've already have that version, do 1 32 there.
But now when I go to deploy a new cluster, I can immediately see that version 1 33 is available. I have selected a default configuration because that automatically selects the latest version that is available in here. So we can see it in here.
We can also see it in the spec. So this is happening at the same time. The admin has updated the service as soon as the service is updated, because I already have the images available anyway, they are now unlocked.
I can straight away go ahead and deploy this latest version. So I'm just going to click finish and deploy this. So again, the service does not affect all of the clusters that are in the infrastructure.
It just gives you the ability to use those versions and also brings new capabilities. Uh, for VKS itself, uh, When I'm, uh, from the user perspective, uh, can I update this cluster? When you add this version, uh, to this, to the pool, let's say I can update the older cluster to the newer version by myself, or still I need to ask the, uh, let's say administrator, provider administrator.
No, no, no. Uh, as soon as the version is available for you to use mm-hmm. As a consumer, you can use it.
So yes, you can update all their clusters straight away. Use it. Nice.
So, so it's, it's really just that governance of the service, because as a consumer, I don't have access to that infrastructure and that by design. That's why the cloud admin do that, do the task. But as a consumer, as soon as that's done and that's done once, as soon as that's done, I can go deploy new clusters, update my existing clusters.
Um, that's fine. One thing I would mention though, which is, uh, also important, is that we have changed the way we do our cluster class, which is, uh, defining the cluster, uh, set up. Uh, and it's now version.
So we will not trigger and update automatically to give you more, you know, more, um, control over this because you may not want to update everything, uh, by default. So your existing clusters will not be, uh, updated unless you specifically select to do that. So in here we have an overview of everything we have deployed so far.
But the really interesting thing, and this is completely brand new, is the possibility of doing some more advanced GI ops patterns. So what I want to do, uh, in this section is show you how we can work with Argo City Service that we have just introduced. The first thing that I'm going to do is I'm just going to create an additional, uh, namespace or test, um, in this project just to have a separate space where we will deploy the same workloads that we have done, uh, previously.
That's the reason why I was downloading all of those yamo files. You'll see that will completely reuse them. So what I do here, again, from a consumer perspective, there's, there's things that have been configured for me.
So the namespace are defined by a namespace class, which dictates which VM classes are available to me if there are any CPU memory limits, for example, reservations, access to storage and, and, um, everything like that. So back in our CLI, we can now start what is available in terms of I cd because again, this full ecosystem is, um, Kubernetes based at clarity of API, which means that all I can do is just list all of the CRDs that are available to me and really specific, uh, information about, um, all the APIs, uh, as a consumer directly. And then I can see what's in there.
For example, here, I can see that Argo CD service has been added and the version that has been deployed. So all I have to do now is to deploy an instance for me because the service itself is operator, uh, model. So the, for example, the cloud admin would deploy Argo cd, uh, service, which is an operator allowing consumers to deploy their own instances of Argo City.
So I have a very, very basic, um, definition of an instance. Just to show you how simple it is. You don't really need, um, any major configuration files.
It's pretty much just name and, uh, version, which we've seen. And I'll apply that and just wait a little while for these bots to get deployed. Once everything is running, I will check the service to get the IP to access, um, the server or the instance that I have deployed.
'cause again, that's a load balancer that's providing the external IP address for access. And then by default, when you deploy something like Argo cd, it has a default admin user and its password is stored in a secret. So I'm just getting that out of there.
And with that, I can just test that. I can now access this. So using that ip, and as I said, the default user here is admin.
So I'll just take that, the account and, um, directly in, but that's not all because we are also providing, um, uh, during our, your download, you can also get the Argo C-D-C-L-I to be able to manipulate it, um, using CLI, if you prefer that over the, the web user interface. So I'm just going to install that on this box and I have it fully available to me. I'm just going to grab the secret and the service again, because what I'm going to do now is use that Argo C-D-C-L-I to log in.
So that instance, so I'm just going to give that the name and again, the password. So that's successfully logged in. And just because I don't want to be remembering the password, I can update it.
So I'm just going to very quickly do that. So again, you can see I'm doing all of this as a consumer completely, uh, by myself. So now what I'm doing in this, uh, section is just adding, uh, the two name spaces, uh, into, uh, into Argo CD as a destination cluster.
Uh, I'm adding the, the namespace where I've deployed Argo City, but also the test namespace that we have just created, because I will be deploying my workloads into that. So you will see that it creates some service account and role bindings to have necessary permissions to work with that. And back in our, uh, browser, I have a very, very simple GitHub repo that I have created for this purpose.
And I'm going to grab those YAML files that I have downloaded during the initial deployment demos. And I'm just going to place them here. And what we will see here is that I'm combining both my Kubernetes cluster and a virtual machine, because again, I'm targeting a single API on a unified platform.
So when I create an Argo CD application, not going into too many details, very simple, just gave it a name, giving it a source, which is the GitHub repository, uh, path, which is root. And then the destination, which is supervisor that we have added, and the namespace that we have created. And all I do here is make sure it goes into any sub folders, if there would be any, and create that.
And this will then start doing continuous delivery. So it will match the state that is requested, the desired state in my YAMA files, in the GitHub repo, and match it with the actual current state on my platform. So you will see it'll start deploying all of the resources that are required.
So that's not just the actual vm, for example, we see, but all of the things that are in the background as well, uh, that are required. And after a while, as we will see it has deployed everything in our platform. So we have repeated what we have deployed, uh, manual through the user interface in the, in the first part of the demo.
Now we have reused those same files to deploy them, uh, again, in a different location. But again, this is just the tip of the iceberg because GI ops is about much more, but it's really showing the idea of defining everything as code. So whether that's your infrastructure, whether that's your, you know, your, the, the, the workloads, the policies, networking, storage, everything defined in code allows us to store that and get, and then use tools like Argo City, for example, to do that continuous delivery for us.
So if I would then decide to make changes to these workloads, make maybe, um, deploy more resources, add a load balancer, I could do that, um, by just introducing the new files, um, into that repository and having Argo cd, um, take care of that, um, and make sure that the, this new desired state is matched for me. So this is, as I mentioned, completely brand new, um, wasn't even there during the GA or VCF nine. So how do we get there?
And that's the last section that I really want to cover because I did talk about the way we deploy, uh, or update VKS. And the reason why we do that and have this independent life cycle is that we can do it independently, which means we can give you new versions, new functionality really, really quickly, and you don't have to upgrade everything to get there. And what we have introduced in VCF nine, it's the same kind of decoupling for the actual supervisor layer as well.
So that's the last part of this quick demo that I want to show you. Um, and again, it's very simple, would be done by the cloud admin. So we need to differentiate between the kind of personas.
The easiest way, uh, to think about it is the cloud admin is the person that actually has access to vCenter and the v uh, the VC layer, and does all of that configuration of infrastructure. The consumer is really just having that cloud experience, so requesting services, deploying workloads, deploying apps, not uh, caring about what's underneath all of that. So in order to update a supervisor, what we have to do is we have to assign a content library.
Uh, we again, created a, um, um, library, which you can subscribe to, or we will be releasing all of the new images for supervisor. So if you would check it now, there's already one that we have just released. So I've added that content library.
And now under my management, I can see that I have a new version available. 5. You can see that we have a new version, one 30 point 10.
And with these updates, I'll just continue with this, just apply this. And what this again allows me to do, updating supervisor not having to update vCenter, not having to, uh, update anything in VCF. It's completely separate.
So we can just proceed with these tasks and it will go ahead and, and do a rolling update. If you, um, if we will go into the configuration, we will see that it's actually deploying a, a second control plane VM with, uh, the latest version. So we'll just let it do, its stink, match the desired state, and after a while, this will finish and we'll see that the version has been updated in here.
So the current version is here. And also if we go into the supervisor itself, we will see that it has been updated. So this was the first async release of supervisor.
There will be more coming. And one of the most exciting things that this, uh, particular update has unlocked is that access to Argo CD service. Mm-hmm.
Okay. I have a question here. Um, do we have a rollback function?
Rollback function of the supervisor of, uh, the supervisor? Yeah, or we can call back to the older version even in case something happened. You know, Uh, should be completely honest, I will have to check whether there's a rollback function in the user interface directly.
However, uh, what, uh, you can definitely do is, um, and would be advised as well, is to take a backup of the configuration before you proceed with any updates. Um, and you can always do a restore of the supervisor itself, just of the supervisor itself to re uh, recover or, or restore the functionality. However, uh, that's a very interesting question.
Uh, I'm not quite sure I have the answer, but let me, let me have a look, maybe ask, um, just to double check and, um, I can come back to you on that, whether it's directly in the user interface to build Back. Thanks, And we're coming to the end anyway. Uh, but what I really wanted to show you with this is that we have created this unified platform for all of your workloads.
It doesn't matter what you are deploying, it's all there for you. But most importantly, it's all managed with a single API on a single platform. And with all of these services that you can pick and choose and introduce into a platform, so if your container images will be stored in Harbor, you can deploy that.
As we discussed, if you want to do secrets management, you can deploy a secret service, which is one of the new ones. But there are plenty of services for you to choose from our catalog and implement on or introduce into the platform, but still guaranteeing that your consumers will still have the same experience, whatever they are deploying. And, uh, these features are available when you implement automation, right?
It's, uh, not just coming with, uh, when you set up the pure VCF nine plus automation or just come out of the box, how it, how it looks like when you get those. So, um, let me answer it maybe from the perspective of why you would want to introduce VVC Automation. First of all, in VCF nine, VCM automation is not just a new version of RE automation.
It has really been completely restructured to act as a single point of entry for the consumers to get this full experience and to really utilize the, the capabilities of the cloud with, um, a single entry point. Having said that, the functionality of supervisor is a functionality that can be deployed, managed and edit, um, within the supervisor itself. So within the, the vSphere client, however, not all of the, uh, integration, maybe not access to all of the services would be available.
So we would definitely strongly recommend that in this new world and this new way of VCF nine VCF automation should be the primary entry point into this ecosystem to get the best cloud experience. Good to hear that, especially that it's just there, right? So it's not like you need something additional and you just tap a button and they're gonna be VCF automation.
Yes. What you will, what you will see, the two main portals, let's call it, that you will see, depending on your role, will be VCF automation, VCF operations, but it's really all about a unified platform, which is VCF.