Techstrong TV September 23, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. We're back here at the, uh, tech Strong Studios. You know, for those of you who know me, I, I always still get a thrill out of people locally being able to come into studio and do interviews with us.
You know, 98% of what we do is remote, but every once in a while we get someone who actually lives down here in South Florida, and that's the case here. I want to introduce you to Rebecca Kroener. That Right at t Yeah, exactly.
Okay. Exactly right. Rebecca Is the, uh, CEO of a company called Q Secure.
That's Q-U-S-E-C-U-R-E. com. Um, I had the pleasure of meeting Rebecca's dad, long story Jewish dad, founder of his daughter.
She's the greatest thing in the world. Wait till you meet her. Um, but all getting aside, I met her dad, Dave, who he is the Chief Commercial officer, chief Revenue Officer, chief, some things Field, CTO, Field, CTO, field CTO.
Um, but he, at one point was the CEO and it first started, or they He was, yeah, we started it together. Yep. And, um, that was at Black Hat in Las Vegas.
Oh. About a month ago now. And that is on Text Drunk tv.
So if you wanna find out more about Q Secure, check out my interview with Rebecca's dad, David. And then, of course, just a couple weeks ago, we had the pleasure of my friend Jennifer Legio is now a, I forget her title with you guys too, but she's basically running, She's running marketing, marketing and revenue Operations, Yeah. And revenue.
Yep. Um, she's also joined, and of course, Jennifer's somewhat, and I know for 20 something years, and she's a rock star, so it's quite, quite a, a, a collection. But, you know, I remembered after interviewing your dad, going to the website, Rebecca, and looking at the, like the board of advisors and the people affiliated with Q Secure, and you've, you've collected quite a, a collection of distinguished folks in the, in the, uh, quantum space that are involved here.
So congratulations on Thank you. Thank you. But you know, it starts at the top.
You're the CEO. So why don't we start with this, if you wouldn't mind, give people a sense of how did you wind up being the CEO of a quantum company working with your dad? That's a great question.
Um, well, thank you, Alan. Uh, I work with my dad, but Jen calls you family, and Jen's a rock star now. She's part of our family.
So I think we're all, we're all family. Yeah. Now we're all part of the, the big Six degrees of separation in the quantum world.
We are. And we aren't, but forget, There you go. There you go.
So, yeah, how did I end up working at a quantum security company with my dad? So, long story short, I, I learned so much from him growing up, and, uh, yeah, he was always very entrepreneurial. So when I was seven years old, I had set up shop outside of my elementary school and was selling little beaded bracelets and things, and Yeah.
First, uh, first business, right? Mm-hmm. But I ended up studying symbolic systems at Stanford, which is kind of this ai, how do you build a thinking thing with a computer?
Mm-hmm. And so I was working for a while in actually building AI solutions for companies. I was the hired gun.
And to make the long short, you, when you're an AI practitioner, you get to this point where you are, you wanna achieve all of those sci-fi dreams. You wanna build a perfect model that could predict the stock market or X, Y, Z. And the reality is that you can't, because there's too many dependencies, too many things you have to take into account that influence, for example, the, the, the price of a stock.
And so I hit that point when I was, when I was working in AI and enter quantum computing, enter this idea of not a bigger, better, faster computer, but a computer that can help make some of these problems that are really, really hard to figure out because they're so complex. A lot more simple. So my dad and I have always been, you know, we take vacations and talk about these big ideas.
How can we, how can we, uh, you know, make the world a better place? And quantum became a thing we started talking about. So we started this, this company together that was working on quantum algorithms.
And this was just before COVID. And we, uh, what happened was we got an initial grant from the US Air Force to start looking at, in addition to these quantum algorithms, the flip side, one of the things that quantum computers will be able to do is break the, uh, traditional, traditional encryption. That's exactly right.
So within that, I was the CEO of this company that was working on quantum algorithms. He then spun out this company working on the security side, and then pulled me over to be the first VP of engineering. So I was running the product technology side.
Here we are now five years later. And, uh, we've, we've built Q Secure into the, the world's first and leading platform in addressing this migration to quantum safe cybersecurity. And yeah, last October, he, he passed the baton.
I went from running the technology side to running Q Secure. And, and yeah, it's, it's a really exciting time for the company. It's an exciting time for, for me, it learning a lot, still learning a lot from my dad.
And it's a, it's a total blessing to, to work with him. I, I can only wish, well, you know, so I'm closer to your dad's age than your age. Obviously your dad and I are about the same age.
Actually, we discussed this, but, um, I will tell you the idea of being able to work with your child and see them kind of fly. Yeah. Is, is every parent's dream?
It's some, well, maybe not every parent, but it certainly makes a parent proud. Um, I wanna go back to the AI thing a little bit. 'cause this is something we've discussed.
You know, this studio we're in right here. I do Textron Gang in every day with a bunch of people. And, and one of the things we've discussed is have we reached maximum ai, or in other words, our ability for our large language modules and just the whole state of it to continue to grow at the pace it's grown.
Because I mean, we've scraped the internet dry. You can talk about synthetic data, you know, and, and Jensen Wang and the, and the, you know, the Nvidia people come out with a new generation of processors twice a year or whatever. But the core kind of problems that we really wanna solve, climate change may be protein folding.
Like really The tough Stuff. The real tough stuff. Yeah.
As good as we can get with ai. Do we hit sort of physical limits of, of how much data there is to make the LLM so good of the processing power of the energy to power those processors of the cooling of, of the bandwidth that, you know, just, I mean, it seems like we're taxing the whole system to the max When technology, it, it doesn't, you've seen, you've seen it, right? We've all seen it.
We, it doesn't grow in a linear way. No. It, it goes like this.
Right? And what we saw with, with LLMs really changing the game for ai, it was one of those hockey stick. It was one of those hockey stick moments.
Yeah. And what you're asking is, are we still on that hockey stick for LLMs or are we not? Right?
Mm-hmm. And I think we're probably somewhere around here. There's, there's probably more that we can do, but when we think about Right, those, those big problems, one of the things that got me so excited about quantum computing is with classical processing, which, which LLMs are ultimately doing, you at a certain point, you can't take in more variables and combine them in an optimal and timely time efficient way to come up with answers to some of these problems.
Probably like protein folding and, um, and, and global warming. For example, there's one problem that quantum in theory can solve for, for global warming in its, uh, it is called the Haber Bosch problem. And it's some basically this, this process that accounts for two or 3% of, of global emissions, you could, in theory, use a quantum computer to, to solve this equation that, that can minimize that really that challenge, right?
So, and you can't do that on a regular computer, even with some of the most advanced ai, the question of whether we're, we're plateauing is a good one. Fundamentally, you can keep using AI to estimate and approximate and do all these things, but some of these problems are just really, really, really outta reach for mm-hmm. For, uh, for regular computers.
Excellent. We're gonna do a part two of this interview, Becca, where we we're gonna get into sort of what everyone needs to know about Quantum, but I wanna focus this part one though on Q secure. So, look, when I, I first became aware of, let's call it post quantum algorithms, I guess is the term that gets pushed around a lot, uh, talking to some of the digital certificate providers, digis mm-hmm.
Mm-hmm. Those folks. And they introduced me to some folks at, uh, MITRE and nist.
Mm-hmm. And you know, and I became aware that, hey, on Q day, and we will get into what Q Day is on the part two, but on the day when con quantum computing becomes real mm-hmm. Not that it's not real now, but it becomes widely available.
All of our RSA encryption and HTML, you know, SSL encryption Mm. Is toast toast, you know, because what would take the bad guys hundreds of years, a quantum computer will do in minutes, maybe. Mm-hmm.
Um, and so this has given rise to this whole, it's really almost post quantum security. So how do we secure stuff that quantum computer quantum computing renders easily breakable, for lack of a better way? I guess that's a good way of describing it.
So talk to us about Q Secure and how it, how it helps us survive. Q Day. Everything you said is spot on.
So the, as data travels over networks S-S-L-T-L-S mm-hmm. It, uh, it's, it's effectively using one type of, of math problem encryption that is vulnerable to a sufficiently powerful quantum computer. And we're not just worried about when QA comes, we're also worried about the, the data harvesting and stockpiling that's happening very actively right now to, to sit on that data for when it can be decrypted.
And some of that will be still be very valuable when it is decrypted, if it's harvested today. My bank account information, my electronic health records, national security, all these things have harvested today are probably still relevant in the next several years. So the question is how do we, how do we make this better?
The, the good news is we know the big bad, we also know the solution. There's a set of algorithms that are written for regular computers to run. So you don't need a quantum computer to fight a quantum computer set of algorithms that, as of last year missed standardized.
And now it is a, it's really just a matter of organizations, private and government adopting these algorithms you pointed to, uh, digital certificate companies. And one of the biggest challenges with adopting these quantum safe algorithms is that it's just very decentralized right now, the way that we've built up mm-hmm. Uh, PKI and, and our current infrastructure.
So an organization is sitting there saying, what, what do I do? What do I do to actually take control of this and make sure that I migrate the things that matter to quantum safe algorithms sooner than later? Do I have to rely on my vendors?
Do I have to, you know, how, where do cts come in? Where do mm-hmm. So what Key Secure does is, uh, and we started working with, with the government to sort of achieve those, those highest level of, of compliance and, and working with the most sensitive stuff.
And now we work a lot with banks, we work a lot with telecommunications companies, work a lot with oil and gas, these critical infrastructure companies to actually centralize and take control, not just of, um, certificates and, and the traditional stuff, but actually centralize the management and deployment across your network of these algorithms. And so we, we have a platform that takes stock, discovers all the encryption going across your network, allows that to be the springboard to migrate to these post quantum cryptographic algorithms. 3 to be ready to adopt post Quantum, but it's Right.
It's addressing that cryptographic debt and then reporting on it. So making it, um, simpler and faster, and in most cases, a lot more affordable for these organizations to, to, to take on this migration or whatever encryption, migration they're getting their hands on. So it's the first time I've heard the term cryptographic debt, crypto debt.
Well, maybe when they're talking about bitcoins and stuff. But I mean, in, in this, in this meeting, um, you know, I remember thinking last year when these new algorithms came out, wow, we're finally out ahead. Well, for what?
Right? Mm-hmm. Because it's rare insecurity we're out ahead.
Um, but, but the fact is, listening to you talk, and, and you know what I'm thinking? There are still organizations out here that are running like Windows Me. Yep.
Windows 95, and Yep. Yep. You know, yes.
The smarter people are gonna jump on this. Use a company like Q Secure. 'cause you can't defend what you don't know you have.
Right. So they're going to use Q Secure, they're gonna find out what their exposure is, where their exposure is. Mm-hmm.
And then do what they need to do to quantum proof it. Right. If that's a word, quantum proof it.
Right. Um, but they're gonna be the laggards who are still running Windows 95. Right.
Who refuse to kinda get with the program until, and then they're the first ones who scream bloody murder when they're a victim. Right. Right.
Of a hack or something of Right. It's terrible. Um, that's gotta be part of your mission accused secure, making sure everyone's aware Yeah.
They gotta do this. I mean, and look, in the security world, we self fudge. Right.
Fear, uncertainty and doubt. I'm not saying you should do that. Right.
I, I had friends who used to, you know, they'd go up to the CEO and say, well, the board and say, if you don't do this, you're gonna wind up in prison stripes. Right. Because you gotta this real important.
Mm-hmm. Mm-hmm. How do you view Q secure's mission and make sure everyone's aware of what they need to do now to get out in front of this train?
Yeah. Again, a great question and one that we think about every day, but I also, look, look, uh, we think two years is a long time. And then two years from now, we'll look back and say, that went so fast.
And one of the first things that we figured out working with our first, our first partner, first customer was the Air Force. We have to meet organizations where they're at. And some of 'em, yeah.
Windows 95 or Internet Explorer. Mm-hmm. And so what we built in is, is fundamentally we're not asking any rip and replace.
Like a lot of, a lot of past migrations, they'll, people are familiar with this, you gotta go find everything and you gotta rip and replace. That's not what we're asking this time. Overlay legacy systems all the way to the most modern systems.
That's what we, that's one of our sort of big things that we offer to organizations. Right. We get, we, uh, a big organization just came to us, said, Hey, we've got 2,500 in-house applications.
3. We know it's a prereq to be quantum ready. Uh, help because we're gonna have to rewrite all this stuff, or we're gonna have to, they were literally quoted close to a hundred million dollars to, to do these migrates, which is absurd.
Yeah, yeah. And many years, right? So that's a perfect use case for us to go and say, well, give us, give us a shot.
Um, it'll be much faster, much cheaper. And you don't have to worry about ripping out everything that you've invested in. Right.
Because yeah, we can, we can try to come up with the perfect solution, but at the end of the day, people have invested millions and millions in their infrastructure, they're not gonna move off it. So that's, that's one answer, right. We gotta meet people where they're at.
The second answer is, there are certain organizations that are gonna prioritize it first and be a leaders. And that's, that's government, that is finance, that is telecommunications and critical infrastructure. And there are a lot that are gonna fall behind.
And one of the forcing functions that's coming up at the end of next year, which sounds to some like a long time, but it's just 15 months away. Mm-hmm. There can be no new acquisitions into national security in the US that do not support post quantum cryptography in 15 months.
Yeah. 0 now mandated by the end of 2026, organizations that plan to sell new technology, international security, have to support post quantum. So that's gonna be a, a wake up call for a lot of people.
Yeah. Well, that, that'll also be the, the beacon. Right?
Right. If you're not with it, you're out. Um, of course, if they don't postpone it or delay it, or as sometimes happens with these things.
Mm-hmm. Um, so a lot of this is US based, but you know, we see in security the EU seems, the EU seems to have more of a political will to get things like this done mm-hmm. Than we do here.
What about any post quantum requirements or post to be clear, post quantum cryptography requirements coming outta the eu? There are, so earlier this year, March and April, we saw across the world a lot of government level timelines being introduced. And so the EU released theirs.
The UK released theirs, Australia released theirs as well. And it's these, these staged migrations for usually starting with government when everything has to be first, when new acquisitions have to be compliant, second when everything that they own has to be compliant. And then, you know, filtering down to, to highly regulated industries and so on and so forth.
Australia, for example, has come out and said, Hey, everything has to be post quantum by 23. Wow. You got five years go.
Um, so it's, it's, uh, generally what we're seeing is by 2030, at least, the most high sensitivity systems have to be migrated. And that's not just the us that is around the world. Around the world, around the world, and a lot of, a lot of organ or a lot of countries are following nist, the NIST standards, the US NIST standards and adopting those.
Hmm. Interesting. Yeah.
Um, you know, we, we look at, I wanna come back to you and your background here. How does ai, 'cause a lot of people think AI and quantum together Oh boy. Trouble squared.
Yes. Right. Um, but how is, how is AI helping us in this post quantum crypto kind of scenarios?
Well, there's, there's the flip side. So what we talk about is we've, the last several decades we've seen one encryption migration after another. And it's because encryption is not meant to last forever.
Mm-hmm. It's a cat and mouse game like any other part of security. It, so the, on the threat side, we talk about the, the, the post quantum cryptography, migration as a catalyst for changing how we manage encryption, that centralization of control, putting control into an organization's hands, not just because of quantum, but not just because of quantum.
It's whatever comes next. And whether it's AI getting more intelligent in its threats to, to encryption, whether it's quantum, we find new quantum algorithms after this one, that's also a threat. You need to be much more agile in how you manage encryption, because we can't take three to seven years to migrate.
Every time something gets broken, you need to be able to push a button and fix it. So we need to get, just as agile as AI is, is becoming. So I guess the answer is it's forcing us to be more intelligent on, on the defense side for one thing, uh, which is good, which is overall good from a, how is it helping in the defense?
There's a whole world of, of capabilities, right? We look at using AI for understanding how, uh, different inventories you end up with all, sometimes all these spreadsheets of here's where my crypto lives. And so making sense of that data for automating migration is, is a really interesting field.
And then also identifying these threats and giving policy recommendations for how you, how you update and you manage your encryption is, is another interesting one. Absolutely. You know, we we're running a little low on time, but I had something, one other topic I wanted to hit.
You mentioned earlier about, you know, the bad guys and say hello to the bad guys, right? Whatever flavor of bad guy you're looking at today. But they're all sort of tar balling, right?
Stolen payloads that are hashed or encrypted waiting for the day when they can turn the quantum beast, the quantum dogs loose on them to un unencrypted, whether it's your bank account information, health records, national security, what have you. Mm-hmm. Uh, wanna make sure people realize that what a big issue this is.
Now, it's funny, it's almost like a radioactive decay. The longer though you're holding that information, the over time the more it decays and becomes useless or less, less valuable. Um, but what, and is there anything we could do around that?
I mean, kind of the horses outta the barn already, but Yeah, I, i, radioactive decay is a, is a good way to look at it. I saw a talk by the now former CTO of the ccia A and he, he looked at everybody in the audience and he said at some point when QA comes, everybody here is gonna have their own WikiLeaks moment. And it's worth thinking about that, whether you run a business or you use any kind of digital communication.
I have a post quantum enabled VPN on my phone. Really? Yeah, I do.
Uh, 'cause I think about that. I think about my data, well Being, being the CEO of qq. I would, if anyone was gonna have it back around, I would expect it to be you.
Right? Right, right. And we, we eat our own dog food.
We use our protections internally as well. And so, uh, the one thing too I wanna make sure to get across is a lot of, there's so much jargon in this, and boards, boards know at this point generally that this is something they have to address. But it's one where you can get caught up in, well, what do I do?
I'm gonna bring in some different partners and, and vendors and think about this and maybe spend a couple years on strategy and a couple million dollars here and there to figure it out. And it's not that complicated. No, it's really not.
And I, I almost think about it like the the bad guy, the bad actor wants organizations to get stuck in the, in the spin cycle rather than fix fix it up. Right. So yeah.
That's, that's my kind of word to, the word to everybody is don't over complicate it. Hey, I just wanna double check. So as part of the product line you get, you offer a quantum proof, uh, VPN or that's a commercial offering?
That's A commercial offer. We, we offer an enterprise VPN. Really?
Mm-hmm. That's quantum proof. That's quantum proof.
Yeah. Very cool. Yeah.
Already out there. Alright. com.
Go check it out. You can ask Rebecca or anything. I think that Dave gave his contact on his video and we'll link to that video in the notes here.
Um, but, but go check out Q Secure. We're gonna come back. There's gonna be a part two here.
It's every man's quantum. So if you're not sure what quantum is and what, or you think you know, but you're not sure, stay tuned for part two. Hey guys, thanks for the throw.
We're here with George Pritchett, who's the vice president of products for swot and we're talking about a new report that they have that shows that there's a lot of malicious insider activity involving files and it seems to be getting worse. George, welcome to the show. Hello Mike.
Hello everyone. Thanks so much for having me. Alright, Walk us through the report a little bit, but, uh, insider threats have always been an issue, but is it getting worse or better?
And, um, what is the fundamental issue with these files? Sure. So maybe we'll break the conversation like three different parts.
But to start with like malware's oil's been a problem. I don't think that's, I don't ever gonna go away. It's always like a cat and mouse activity.
Whatever you measures you put in place, there's new ways to, um, evade the existing ways or there are new ways to get, uh, into the organization, especially like with the consumption of new applications, AI and so on and so forth. And we'll talk ai, it's a huge new world as well discuss with and when it comes to like the risk from the employee side and so on, um, there's a lot more, again, being inside, um, risk or not. Um, I think the important part is that there's a huge diversity, right?
Like regardless how well you're training your organization, you have a very dispersed technology stack that's trying to solve the same problem for each of your entry points, right? So you have a very different thing for from email to web traffic to file transfers to collaboration tools to SA versus OnPrem and so on and so forth. You don't have a unique way of handing those things.
You have, don't have a very easy way to manage across the board enterprise wide and so on. And the idea of a defense in depth is, uh, implemented or some level is with zero trust and so on, uh, technologies. But at the same time, there are a lot of workloads these days that never touch even an end user.
They actually go into direct application application and then you actually end up being hack because you are relying on the endpoint security product to kick in and do its, uh, job and contain the risk and so on so forth. And when it comes to the AI part, and I think this is the part that's getting more interesting and we've seen that in the report as well, there's a lot of adoption. Everybody's trying to adopt ai.
There's a lot of push for like adopting AI for file security as well, but it's only like 25% actually have like a formal process on how they can handle ai. And 29% are actually banning gen AI as part of the organization. So it, they're like exactly the opposite sides or like less than a third are restricting access to ai but the quarter only have like a formal process out of the 70% that actually are allowing gene AI usage and so on.
So then the risk becomes a lot more work. People are empowered to use gene AI to like simplify their work, right? I can, I easily have a copilot or like have an integration for my email with the likes of open ai, Gemini, like GPT and so on and so forth, right?
But at the same time they're send the data in the emails, they might be like files them uploading to generate a report or representation for me and so on and so forth. And that increases the risk a lot more. So it's a matter of like you are empowering you giving new tools to the organization, what is the risk associated with that one and how efficient are the guards that are put in place on that?
And I think the most important part, I saw like a very good, um, presentation a while ago where there was an entire revolution for cloud, the entire revolution for mobile and so on. The AI is the first one that nobody's pushing back. Almost like everybody on the board organization are saying you need to adopt, need to adopt, right?
But at the same time there, there's a speed of the business that needs to be allowed to grow fast on the AI side and security is trying to find measures to contain the risk there because people are starting uploading even sensitive documents and so on, um, through this. Um, again, chat bots and um, I dunno, AI tools and so on. Mm-hmm.
Hopefully that makes sense. So coming back for a minute, these insider threats, so they actually malicious people who are going out to do something or is it just more accidental because people are not aware and as a result, uh, you know, we don't go looking for that as aggressively as we might, but maybe the bigger issue is the fact that well people are people and they're just gonna do stuff that's the path of least resistance, right? Uh, sure.
So it's a mix of both, right? Like I, I think we've all seen in the news in the last six, 12 months if no longer with like, uh, remote employees that are US based, but they're actually more North Koreans and so on and like how they're bypassing some, um, employment background checks and so on so forth, right? So there are some of those cases like cyber espionage and things like that, but I think a lot of them are, I don't want to call it ignorance, but it's actually trying to work faster, easier, better.
And they don't realize that actually exposing company to a risk, right? So I want to say that a big chunk of them, I want to give them the benefit of a doubt, but yes, there are some inside traders as, uh, sorry, inside risk as well where people have a malicious intent from the beginning. You talked about AI and how do I strike a balance there?
'cause I think we do want people to use AI, but we want it to be done responsibly. And I think the issue is that sometimes they're not thinking through the sensitive information that might be in a file. They're just kinda uploading stuff to get some help from AI to help them write an email or whatever it may be.
But um, is there a way to think about that smarter and maybe make sure that sensitive data isn't going out to the AI model that eventually might wind up using that to train some model down the road? Sure. So two aspects there, right?
Like the organization that do have like, like enterprise licensing and they're making sure they're not uh, uh, using their data. Like the organizations, the, I dunno, the providers not using their data for training and so on, but a lot of people are using their personal accounts, right? A lot of people are even like uploading in free accounts and so on and even paid accounts.
And I think that's where the biggest risk comes to play. Um, yes there are mechanisms to put in place. So like regardless how much you're gonna trade the people, let's start with that.
Like regardless how much you're gonna trade them, someone is gonna sleep, right? Like someone is gonna make a mistake. It's very similar to like don't click a link and someone still in these days are still clicking like phish links and so on.
Same thing here. People are gonna upload. Now there are guard rails you can put in place.
There are measurements, measures that you can put in place to make sure what is getting uploaded doesn't have sense information and so on. DLP market's been a while around for a while, like everybody's repurposing DLP for like AI guard rails, but it's not a one-to-one match, right? And I think it's a matter of like how well this mechanisms are put in place, but also how, what kinda information you allow people to, um, access, right?
And I think it gets back to that common kind of framework on like how you look at these files and their risk associated with that one. Also, how you look at the business from a performance perspective, right? If you're not using, I dunno, AI these days, you're kind of seeing almost like a dinosaur, but at the same time you want to be able to like restrict the risk, right?
So, which it's still like still puzzles me is that we're going, even for us as like an organization when we go and we have like kind of uh, master agreements with very large organizations, there's the team that wants AI and there's the team like the legal AI risk that's restricting in those agreements, like what you can do with AI and so on and so forth. So they're trying to put those guarders from both legal technology perspective, but at the same time they need to have a fast adoption to that as well. So it's a very hard thing to balance.
But I do think that the taking a step back and identifying what, who can have access to what and what tools they are allowed to use as part of that will be, um, a more balanced way of actually approaching this than actually saying you have access to everything, let's say in our CRM and then I don't download the Salesforce database, upload check GPT to generate a new fancy report that can show in the next, I dunno, presentation or something like that, right? Like that will be a really bad thing. But at the end of the day, yes, people can go and like redact some things, simplify the content, anonymize some things, and then generate reports.
But the more work you're asking them to do, the less likely they're gonna do it, right? 'cause the entire idea is to move fast and so on. So, um, I'm not trying to preach now that everyone should go and buy enterprise licenses for this tools, but at the same time there is a risk in allowing people to use their personal or even like free accounts, uh, with that.
Mm-hmm. Um, People are sharing files probably more aggressively than, uh, anyone cares to admit without much care for various uh, regulations. But, you know, do you think the auditors are gonna get savvier about this and start cracking down a little bit more?
And um, and if so, how long might that be? Um, it's still a relatively new thing, right? Like they, and I think this is still, uh, a very hard decision, right?
Like EU adopted like AI risk laws and so on, right? Like us adopted a couple of things and so on. So it's still a little bit of back and forth.
I do think that uh, 'cause we have literally this conversation part of our legal reviews as well with those domestic agreements I was telling you about and so on. I still think like in it should normalize in less than two years, to be honest. Like I've seen, um, a lot of pushback.
There's still some pushback that, but they already start like trying to throw out ways to like, I don't know, align. Um, there've been conversations. For instance, I'll give you a quick example with FS iec, if, uh, the audience familiar with FS iec, um, in financial services, information sharing and so on, there have been discussions on like how they should tackle AI risk and how, what are some recommendations, if not even regulation to put in place on how to use AI as part of financial services and so on.
So all the industries that are trying to look into like I know not necessarily regulate, but normalize how they're using these tools for them to be able to move faster as well. 'cause otherwise these organization, some organizations like Healthcare Financial and so on, have a lot of PIIA lot of information that it's very, I dunno, appealing for threat actors, right? And they don't want to be able to, like, they want to move fast on the ai, they don't want to be the dinosaurs that we talked about.
But at the same time, they want to make sure that there is a guideline, uh, blueprint. Let's say that they're using, that they're gonna reduce the risk and they're gonna get the buy-in from the organization as well. Hmm.
How much of this is something that requires a technology solution versus how much of this is something where, well, we just need to train people better and get them to think about the fact that there is sensitive data in those files and they should be careful. I mean I, I feel like if, let's say if training would work properly, 90% of the cybersecurity industry will not exist. Maybe I'm exaggerating, I'm sorry, but I'm, I don't wanna make like bombastic statements here.
But at the same time, like again, phishing, it's still a thing, right? Like the fact that people are still clicking on links that coming from we, I dunno, random people and so on, or like even spearfishing person co and so on, those mechanisms are still working. It means that training is a checkbox is not fully efficient.
And again, you are as weak as your weakest link, right? Like there's enough one person organization to do it and you're gonna, um, be exposed anyway. So I do think that yes, training is definitely mandatory.
You're gonna probably cover, but let's say 80% or so, but you still need to have a proper measures in place, right? Like you're not gonna eliminate the risk completely just by doing training or relying on people's common sense. It also seems like the bad guys are getting a little more sophisticated in the sense that, um, they're stealing credentials and then they're logging in and hanging out for a while and maybe you starting to look like they're an actual insider that should be trusted and then they start doing stuff that is malicious.
But, um, is it hard to distinguish now between an insider and an external threat? Well, I would like to believe that, um, like we've seen that in the report as well, right? It, it's not an instant detection.
It takes a week. Sometimes it takes even a lot more than a week to actually detect, uh, if you, uh, have a breach. Now, the entire I important part is that once you have access on the network side, you're trying to lateral movement, you don't want to like, I dunno, start dosing left and right.
You'll see what you can get, right? You are slowly moving and try to identify a bit more and so on and trying to see how much access you can get to like what relevant information and so on. They will have the patience, right?
Because you're going after the crown jewel, you're not going for like a, a small bit and so on, right? So I think this is where things become more tricky and again, I don't want to, uh, call like doomsday or not, but um, also the way we're using AI to optimize our workload and so on, there was also report, uh, a report from on tropic, uh, couple weeks back on how they're using um, their cloud solution to actually try to build more malicious content and so on and like optimize their solution and so on. Um, there's also been like a couple of, um, things on the software supply chain instead of for them to try to, uh, get an organization, they're rather just like kind of poison one of the repositories and then they'll walk them in with crypto miners, PE or sniffers or things like that as well.
So there's been a lot more mechanisms where there to some level, like some blind spots for the organization, right? Because for instance, on open source, uh, libraries, the main focus in the past was actually vulnerability. Do I have a critical vulnerability?
I should patch it and so on. But right now, a lot of them you're seeing almost on a daily basis, like this week has been, um, the rapport affected like 2 billion, um, uh, downs and so on. So as you think this through, what's your best advice to folks?
Or what's that one thing that kind of makes you shake your head and go, folks, we need to be a little smarter. I think we need to like take a step back and look at the probably more holistic, right? Instead of saying that, Hey, we have measures in place in for X, Y, and Z.
It's more like, what is the risk for any of these data exchanges either coming in or going out and how we can, um, have a more holistic view on, on that one. Because if we're just relying to have like, I don't wanna call them like point solutions, but there some level there are like point solutions without clear visibility like what they're doing, um, then you're not gonna have a good view. And I think this is the part that we had the, like a good conclusion of the report as well where people are unhappy that they don't trust and certain on how they have this, uh, set up right now and they need to have a better, I dunno, overview let's say on like what happens in the organization and better control over their files as well.
And this is not a data discovery problem. This is more of a threat and, uh, security risk, uh, assessment than anything else. That's how I see it.
Um, the long game, it's still, again, if email be like malicious files on emails, let's say it's no longer that big of a threat, but phishing is everybody's rushing to address phishing, but the threat actors are moving to something else to walk in the organization or like, I know compromise a user and so on and so forth. So again, it's still a moving target, but from that perspective, you kind of like always move your focus from one project toward the other to more or less batch different potholes instead of like looking to like how we can actually build a proper highway. All right, well folks, you're heard in here they saying that sharing is caring, but you need to be careful out there because you don't know what you're sharing and you don't know where it might wind up.
George, thanks for being on the show. Thanks much for having me, Mike. All Right, thanks Everyone.
You guys in the studio, Send me your poor, your huddled masses and bring cash. You're watching Textron Gang. Hey everyone, happy Tuesday and welcome to our Tuesday Textron gang.
We've got a great lineup of topics and a better, even a better lineup of people for this wonderful Tuesday. Let me introduce you to our gang members. We have JP Morgenthal, Wiki Wang, Mitch Ashley, and the dean Mike Ard gang.
It was a bit of a crazy weekend. And Monday, um, it seems we have a new philosophy in the US com, a country that was built on immigrants and immigration. Anybody could come in as long as you have the money, right?
Uh, the H one B visas are now a hundred grand a year, but you could buy the Willy Wonka golden Visa for a million bucks. My goodness, my goodness. But anyway, Mike, you, why don't you take this.
What are, what are we, what are we doing here? So, so here's the deal. So they announced Trump administration that it will cost you a hundred thousand dollars to get an H one B visa a year.
However, if you are already here under set program, that will be grandfathered in essentially, and you won't have to pay this particular fee. So it may wind up that a lot of folks will just wind up staying here for a long period of time. It was kind of a chaotic announcement.
The executive order went out and then everybody flipped out, and then there was clarifications as to what the president really meant to say the usual kind of thing. And these days in the Trump administration, it seems like. Um, but the other thing about this program, it's interesting, this move is getting praised by both the left and the right.
There are people who like this thing, the H one B Visa program itself has been controversial for as long as anybody remembers. Um, 70% of these visas go to folks from one country, primarily from India. And a lot of folks have said this whole program needed to be revamped, maybe tossed in favor of something else.
But, um, I feel like we just kind of doing our usual heavy hammer approach to solving issues. Well, I think what we've got here is President Trump has, uh, said to his tech bro supporters, how do you like me now? Uh, because this is certainly a, a arrow in the heart to the tech world, right?
The tech world is probably the single biggest user of H one B visas and has been forever. Um, and for good reason. You know, I don't care if people are of Indian or Southeast Asian or Chinese or Singapore or Filipino or Eastern Europe or wherever they come from, if they have good talent and skills that helps keep this country preeminent in technology, we need to use them.
We, we should have a mechanism of bringing them in. You wanna attach money to it? A hundred thousand dollars a year.
A year, that's $300,000 over the life of most of these H one B visas, Mike, are three years, I believe. Mm-hmm. So even your point about the grandfather that did, I think it only counts for the rest of their, their three year term when they go to get a new one or renew it, they're on the hundred grand a year system too.
So let, let's say what this really is, this is eliminating the H one B visa as a means of bringing in skilled workers. So we'll be able to get people who went to Utah for a half a semester, dropped out and went to electrical school and ask them to be the next ver generation of coders in this country. Because we don't have enough people who are taking those kind of skilled classes and training.
We don't have enough STEM people. And so what we're really doing here is we're taking what, what the Trump administration itself has set out to be the golden egg, our tech leadership, our tech preeminence and AI and quantum and cloud and everything else, and saying we are gonna cut off the pipeline of fresh blood, of new talent, of skilled workers coming in here. 'cause we want Americans in fly over stamp it with a high school diploma to take these jobs.
I don't think the jobs are going to come to the us. I think most companies who are using these programs are just gonna Move out Back to where there those people are. So it'll just mean more of the development work will move to India because they won't have as many people here working, you know, on the same time zone as somebody who, you know, normally it's somebody working for an outsourcing firm who's working for some, you know, enterprise company and they just wanted somebody in the same time zone.
So they use these visas. But, uh, you know, I think we'll just do more of this quote unquote globalization and just put the workload back to where those people are in the first place, which is probably gonna be somewhere in India. And that's antithesis to what the Trump administration wants, right?
They're anti globalists. It, it, it, it does seem that they are ignorant to the impact long term, right? If you, this is an opportunity to build and build the knowledge here.
And I, I don't think they fully understand or have thought through the impact to the programs and what's going to happen in the US. Now, some will say that perhaps this is part of their underlying plan. I I tend to feel that there is a potential for some chaotic, uh, uh, shift mm-hmm.
In what they're trying to achieve much more isolationism again, uh, you know, like circa in 1940 before World War ii, we were very much in isolation. It's two Thirties. Yeah, but we don't, and the problem is you have a 1940s run the country mentality in a 2000 era technology world.
And so JP Lemme just, it's not the forties. The forties was already World War ii and it was Roosevelt. This is really the twenties leading to something called the stock market crash at 29, right?
It's the tariff bills, the anti-immigration, the isolationism that all happened in the twenties. And as a result, we had the Great Depression, right? By the forties, Roosevelt had already put 10 years of trying to build things back up here.
And, and I'm sorry, I just wanted to correct you on that, but I, It's funny 'cause I always assume, I always associate isolationism with our desire not to enter the war until we were forced into it, right? Mm-hmm. The, the problem is by that, by then we had so shrunk in our military and our industrial capacity that it took us years.
I, I'll tell you, I'll tell you what I hated about this program. It was basically United States government, uh, coming up with a method that would enable companies to depress the salary levels of IT folks artificially, right? Because now suddenly I had somebody else coming in from overseas who is gonna do a gig at a lower cost.
And that might have been maybe good for the end customer if that got passed along to them or not, who knows? But it most certainly depressed the level of salary that could be commanded by other IT professionals in this country. And that's not something the United States government should be involved in.
I think That's been the big criticism of the program, I think historically. I don't know if that's still true. Yeah, I you know what?
India is not the cheapest place to get software engineers anymore. You might be better off going to Eastern Europe or the Philippines or Vietnam or, or something like that. Um, Let's face it, a company's gonna have to really want somebody to pay that kind of money to bring them in per year, right?
So does it bring in the elite of the elite or does it bring in the elite of the family treasure chest to bring you into the state? Probably some of both, but I think that's the main criticism that they're going after. Um, but, but it begs the question of well, why do we even have one anyway?
If that's really the purpose is to keep American jobs, keep American jobs. I'm not saying we should do this. I'm just saying that's it's a bit of a, a counter.
Yeah, I understand that's what you wanna do, but you're now creating an even greater class social system of people who can't afford, or companies who can't afford. So, you know, they're paying good money after, after that a hundred KA year or whatever million dollar the golden ticket is to get these people here. I mean, to be Yeah, I'm sorry.
Have something here, right? Because I'm the first, uh, generation immigration, and I was H one B holder. Um, so I specifically checked this one, uh, when I first heard out.
It's, it's the shock news, right? Um, it end up like this new, this rules only apply for the people who try to apply the H one B overseas. So people within United States still keep the old rules, I think, but it do have some impact for the startup who has a shortage on the technology talent.
If you think back how, why we have H one B, right? There are a class, class of workers like United States has shortage, they don't have enough people, so they offer this kind of feedback. But now if you increase application fee shortage is still shortage, I don't feel it will bring the, the job back to the United States.
But let's see this, this might of wheel, I I I don't, I don't disagree to be clear, the million dollar golden ticket is not an H one B visa for a million bucks. They give you the, the full on, uh mm-hmm. Full on Visa.
I Would, I would just say that, you know, compared to what some folks are commanding for AI salaries these days, a hundred grand is nothing. Well, that's a good point. Yeah.
For someone like that. Sure. They're paying we way over that to get that kind of talent now.
Yeah. Well I, but here, here's the bigger issue guys. What it really is, is we hung a giant for sale sign on the Statue of Liberty, right?
'cause that's, that's America under this administration. Everything's for sale. You want to give 50 grand to the Department of Homeland Security Secretary and he'll get you some influence.
Don't worry, they'll quash that. We're not gonna do that investigation. You wanna find out what's going on with poverty and stuff?
I'm very sorry we canceled that report. We'll let you know when we have something else out. You want to know what the latest job numbers and everything is?
Well, we'll, we'll let you know. It's not important. You don't need to know.
You want something, just write. You got your checkbook, pull it out and you're good. You, you don't have a checkbook.
How about buying some Trump coin, Bitcoin or crypto? And, and you can get your way there too. You want to export some AI chips that are forbidden.
Not a problem. By some more coins. So before you get, this is what this, this is, this is a real problem Before you get too far on that particular soapbox, but there is one thing on this thing that is gonna be problematic.
The administration has a tendency to come up with exceptions. And so somebody's gonna go down to Mar-a-Lago, hang out for a little bit, and suddenly there's gonna be a half price sale on Visa. It's called Taco Tuesday here on the gang.
I Do. Before this all starts. Yeah.
So I mean, and like everything else, right? So when, so there was a time, and, and I'm talking as a government and politics major. Now, you can't rule by fiat, you can't rule by executive order.
There comes a time where the Congress has to, the legislature has to approve these things. Now I get it that they're all in La Goosestep with the fur. But, but when are we gonna have some congressional action on this?
Right? This this is, and, and one of the, I mean, the lower courts all will claim, Hey, you gotta, this is exceeding your power. You gotta go to Congress now.
You know, who knows what the Supreme Court will do? Well, we all know what the Supreme Court will do. They know they're just, you know, the latest, uh, kangaroos.
But it there, this is not the way we're supposed to. This government's supposed to work. I'm sorry.
The interesting thing about it too, Alan, is that with this, the outcomes are measurable, right? How many, how many, if we're not issuing those jobs or visas, how many people are we hiring overseas to stay overseas if we're not issuing those visas? How many people, how many people fill those jobs from the American side, from the US citizens side of the, of the equation?
Yeah, but let me, let me give you the, so that's the moderate response. Let me give you the extreme response. How many companies are made overseas in China, in France, in, in name the countries mm-hmm.
Who now say, Hey, don't bother with those crazy Americans in their a hundred thousand dollars visas. Come work for me. Come work for me.
We're doing exciting things. We're investing more in r and d. The rest of the world doesn't wanna play with them anyway.
They wanna, here you'll be able to play with the rest of the world. And before you know it, your preeminence in tech is, is up in smoke. I mean, we already see it with the, with the, uh, with the, uh, digital sovereignty.
Yeah. Actions that companies are taking to all European companies. Yeah.
Wrote an Article. So she just signed a Euro stack, which is, you know, an agreement to create a European technology stack. And, uh, that's not, that's just one of many, right.
Seuss just came out with a, a, an offering in it as well. Mm-hmm. Um, you're gonna see more and more of this.
Yeah, I totally agree with you. Right. Um, I normally do not like to talk about politic part or I like tech.
Right. But it's kind of interesting, you see all those series of way people treat like how to manage country, like how to manage p and l, right? I feel like those are totally different systems.
Yeah. No, they, they really are. Alright.
Hey, I think we've made our point. Let's take a break here and come back and talk about, uh, what's Google doing with Chrome First? They were selling it.
Now they're not selling it now. Now what you're watching, Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back.
And as Alan was talking about, yeah, Google's now at least foreshadowing what they intend to do with AI and the Chrome browser. And I guess maybe this is a little bit of an exercise in trying to freeze the market somewhat, jp I mean, it seems to me like a lot of these features I looked at in here seem pretty cool, but it doesn't seem like they're gonna show up anytime soon. Well, I mean, they're already starting to show up.
I, I actually like the direction overall from an architecture. I think it's, uh, I think it's really, I think it's happening already, except people are now having to cut and paste in order to enable, uh, this kind of activity. So they will do a search, they'll find some additional information, then they probably will deep research it in a, uh, LLM uh, application.
And so all this is doing is saying, um, you know, let's integrate the two steps right into one activity, which is what I think people want. They want user experience. Now the question is, is because, you know, with Google Chrome is how long is it before, um, somebody steps up and, and says, you know, this is a monopolistic, uh, you need to open it up and make it pluggable.
I mean, we, this, I'm surprised they even didn't do that from the get go based upon what we learned from Microsoft and IE years ago, right? And it's like, do you really? Yeah.
Are you, are you really gonna force us to go to court and you're gonna get, you know, and waste, you know, hundreds of thousands if not millions of dollars on, uh, legally being told that, yeah, you need to open up the APIs so that open AI can plug in their LLM into this functionality. Right? Or, or maybe we just end up with the browser wars again.
Oh, you don't wanna let me in your door, fine, I'll create my own. Because hey, chromium is free by the way. I, um, Microsoft's edge is already based on it, right?
Uh, it's not difficult to take the Chromium based and build your own browser. So are we gonna see the Anthropic browser or are we gonna see the open AI browser? So we either end up either, you know, Google gets sued, uh, and they get told naked and open api, so everybody can plug users can make the choice what, uh, engine they want to use as part of this functionality or, uh, ever.
Or we see ano a new browser war emerging because everyone's like, fine, if, if that's what Google's gonna do, then I'll just create my own chromium for my LLM. Uh, I, I, I think both are really, I, I would like to see the more open one, obviously, right? Plug in the one that I like best.
Um, perhaps even allow multiple, like, ooh, you know, for this particular search, I would like to use sonnet, but for this other one I'd like to use Gemini and, uh, and have that option, right? So that, um, I get different responses. I can see the alternatives, uh, and, and in, we all know that different LLMs respond differently anyway.
So isn't that part of the, the research effort? I I, but overall I, let's take away the, um, politics, if you will, of the industry, right? And, and, and the, uh, maneuvering and just look at what it is technologically.
I think it, it, it's a phenomenal, you know, it makes the browser much more useful. Plus I think it starts to reduce the fears that people will have that browsers are going away. Everything is gonna become LLM searches, right?
It's, you know, so it doesn't even matter anymore. We don't see search, we don't see the, the search returns anymore. Uh, it all gets analyzed by an LLM and then you just see the results.
So this is a way of saying, no, you still gonna do search, but you're integrating in this intelligence to help expand and understand that information better. And I like that model. I like that.
I think that's a good model for the general user. So, jp, I, I agree and disagree. First of all, the courts today aren't what the courts were when Internet Explorer was kind of, you know, hogtied.
The only way a court is going to come down on Google and force them to do things on, on uh, Chrome is if the suit's over in the eu. I, I, I agree with that. Yeah, that's number one.
But that, but that's where it's likely gonna happen, is, Oh, that's the only place that it'll have any teeth. But secondly here, here's how I see it. Google, Google got a get outta jail free card with Chrome.
They got away with being a monopoly, but they're still allowed to keep Chrome. They may open some stuff up, great. But what they do see is that there is a new generation of browsers that are going to throw the cards in the air, and we'll see who the new winner is.
You've got the perplexity one. OpenAI is coming out with one. I'm sure the rest of them are, are not far behind.
And so, you know, this was an arms race. Google had to go, had to up their game to compete with these up and coming, you know, new generation of browsers. And if you are Google, what's your biggest ace in the, in the hall that you are already the dominant browser.
So you don't, you're not going to give that up, right? And so you're just going to kind of build power willingly. No, you're gonna have to pry it outta their cold dead hands.
But, so they're going to, they're going to make Chrome an AI browser to compete with this next generation. Now, here's the thing I where I really disagree with you. This ain't about search.
This is not about search. I think AI search is gonna overtake Google search. It already is growing three and a half times faster.
I see it on our, uh, Google Analytics for all of our websites. Mm-hmm. Mm-hmm.
How much search is coming from AI and perplexity and so forth. What it really becomes is this AI browser becomes the new UX to do your work, not your search, your apps live in there, your work in there, it becomes the new desktop. And that's what Google, you know, you've got Google, the whole Google What, what's the Google office called Mitch?
I forget. Workspace. Workspace.
But they've already done that. It's already embedded in workspace. It's already, yes, It's, but workspace may not be the dominant workspace.
If I've got a, let's say open AI comes out, or perplexity has a, a, an AI powered workspace that I Think the way you think about it, Alan, I, I agree with what you're saying. We've talked about this, you and I, um, you know, Atlassian even bought a browser, the browser company, right? Yeah.
Atlassian In anticipation of this, which is the expectation is that browsers shift from searching content on the internet to actually managing, directing and consuming what AI does for you, right? Whether you're managing the bots and the, the tasks and the things that happening, what's going, what's going on across the different tabs on your browser. You're not switching between them, um, but doing searches for maybe doing tasks for you, all that kind of thing.
But the application kind of providers, the people writing code see that this is a threat. Because if Google now controls what you can present to the end user for their apps, then they lose, right? And they may not put in the functionality that an Atlassian or whoever else wants.
And that's the threat about this, which is, do you want Google to win that war? Do you want Microsoft to win that board? Do you want a perplexity to win that war?
Mm-hmm. So instead of SaaS, we have bass browser as a service. Where, where, and that's your front end, Ricky, I, Mike, go ahead.
I think it's already happened. I'm sitting here on Google Chrome as we record this. And I'm looking around all my little apps, and I think I can see this in Iny, tiny little Microsoft store icon somewhere on the lower left hand side.
And that's about all I see of Microsoft on the screen right now. And I think the apps guys are gonna use browsers just to really park Microsoft as a backend, uh, client enabling technology. And then, to your point, everything on the backend is just gonna wind up being a, a service, because I don't need a gooey to go access the CMS.
It's all gonna come through the browser. I think it, it makes it much more difficult to determine is pick your poison, pick a Google or Microsoft, whoever is the browser, the new new AI browser, is it favoring that provider's content? 'cause it's no longer the list and the order and what shows up in a search result, right?
Search it, it, it's the Gemini interface to start with. That's at least what it looks like today. It'll look different over time, but I think it, it sort of obfuscates what's happening behind the scenes.
Well, don't forget on the back end, there are now, um, like robots dot text, which used to tell the browser what you can and can't take. There are now files that tell AI what you can and cannot take. Uh, and this is a lot more, this is a lot more strict than the robots that text was, because actually it benefited people to have their content show up in a search.
But they know that when AI is the middleman, that their content is often masked, and the source of that information is not necess, even if it is transparency may not even get recognized, right? Because the reader doesn't actually care where it came from so much as the content itself. So people are going to be much more strict about what they allow these ai, you know, engines, the l LMS to go and see on their sites.
And, and so I mean, the question, you know, go, if you go down that path, you end up with less content being able to, to actually fulfill the, the requests that are being made. I think about it this way too. JP does pick a, pick a company, does Salesforce and Slack when Google to know what their bots, what their AI is doing within the browser workflow is all part of that.
Yes, they can track some of that today with browsers, but not to the degree I think you could in the next generation, Mitch. So they're more comfortable with perplexity tracking it. Well, well maybe.
And Today until perplexity becomes a threat. Well, They can, at least my perplexity guys Wiki had something to say earlier. I don't, Sorry, Wiki, I didn't mean to cut you ahead.
I totally agree with you guys, right? Like the browser actually is to agent as well, right? Because there are, I believe there are several threes like in filter, you can integrate with AI agent and make it to a gate for the AI agent, and louder is one of them.
And that's what important company, they try to have the broader product so they can control the future of the AI agent as well. Mm-hmm. So I'm a little, I'm concerned about the following scenario, right?
So more and more AI slop gets created using Gemini, and then Gemini starts to rank that stuff higher because, well, Gemini created it, so therefore Gemini must think it's okay. And then at the end of the day, we wind up with this, you know, unvirtuous cycle of slop that's popping up in there. Well, That's all part of the balkanization of the internet, right?
Because then Croatia is better than Serbia, which is better than Montenegro, which is better than Casso vo. I forgot all my little parts of Yugoslavia. But, um, you know, this is what happens is when you go to Google Land, or maybe a better analogy is, uh, water the rinks, when you go to Google Land, Google search rules.
But when you are on perplexity, you have a different algorithm for searches. Forget algorithm, you have a different favorite for searches and open AI and, and everyone else has it. So it's, um, I want, I want jps thing, but I want like, maybe if I can figure out how to do it, I'd like to have two or three of them go in at the same time so I could see what they were generating and compare.
Well, but you know, this reminds me of, was it Einstein? Is is, was it Salesforce was doing Einstein? Mm-hmm.
Where you could plug like any LLM into the back end of it? Mm-hmm. Yeah.
Cover broker for the LLMs. Yeah. Right.
Maybe, maybe that, and maybe if these guys don't play nice, some new company we don't know of yet comes out with an open chromium based browser that does have sort of an Einstein layer and, and people who, who care about these things go out and and adopt that. Or there's a memo from the EU on its way Yeah. On the investment side as well.
I see a lot of great startups recent come up in this area. Yeah. Very interesting.
Yeah, Absolutely. Alright, let's take a break. We're going to come back here and talk about our C Block data center court bottles, the NIMBYs Hire Lawyers, and now the, the Empire Strikes Back.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com. Home of security bloggers network. All right.
This may come as a surprise to you, but there are lawsuits being generated now around all these data center projects. And there's one in Michigan that's kind of interesting because the people who are proposing to build a data center are now suing the township that passed some, uh, a vote, essentially among their leadership of the council that said that they could not zone this area to run data centers. And now it's gonna become a, a court battle, I guess, for as long as we can go.
And Alan, you know, and I'll go to Mitch on this first, but I'll come back to you in a minute for your legal opinion, but Mitch, are we gonna see more and more of these things? And I am reminded of, in my own town, some developer built a house that was far exceeded the, uh, zoning laws, and then they built it anyway, and then they dared the town to sue them, and the town didn't have a whole lot of money. So that house still sits there.
Well, I can kind of relate to this one. Maybe that's why you're coming to me as the Nebraska boy. Do I want, uh, you know, that nice green farmland right behind my house or behind my, if I live out in the country, do I want that overtaken by a data center?
And that's essentially what the case is here in, in, in Saline Michigan. You're welcome to the, to the Textron gang. We're talking about you folks.
The, the, the claiming, the the data center building, uh, builder related digital is claiming that the, the council did something illegal in changing the zoning laws. Us not letting them build their, their, uh, 250 acre plushy plus hyperscaler data center. Not the first, not the first lawsuit.
We're gonna see about this. There's a lot of legal lawyer legals gonna get being paid to do these kinda lawsuits. I think.
And, and we'll see, the problem is, you're, you're talking about local jurisdiction, local rules. This is, isn't just some, you know, national, uh, uh, threat or national lawsuit, excuse me. Um, that you can kind of say, well, if it worked there, we can go after and do the same thing in all these other locations.
No, they all have their own laws and jurisdictions and rules and councils and all that kind of thing. So that sounds kinda like a big mess to me. Yeah, I mean, well, you know, Mike, you asked for a legal opinion.
Look, towns are free to make zoning their own zoning laws. And, and there's nothing more local than zoning, right? You don't have federal zoning laws.
Well hub a hub zone or something like that, a economic development zone. But, you know, building zoning laws are really the epitome of, of local ruling. However, my only point is, and I don't know enough about this case enough, is this a, an ex post facto law?
In other words, did they, did they enact the law after everything was all set and approved and done, and then kind of pulled the rug out from under up, right? That, that you, that will not stand you, you can't go ex expose facto on this, right? You can't say today you can do it, and then you rely on that and spend money and do everything and then say, oh, changed our mind jk.
Right? And we changed our mind. So absent of that, I, I think you're gonna see a lot of towns doing this.
I mean, who wants a Manhattan sized data center in, in, in the middle of your greenfield? Um, and, and you know, I, again, I, I have, I've written a few articles, some might still be in the queue on this for tech strung it, but you know, this data center, boom, it's, it's driving up our electric rates. You and I and everyone out here are paying more money in electricity because the utilities have to increase their ba their capacity to, to, you know, pay to, to light up these data centers.
Um, a a liquid water cooled data center uses like, something like can use up to 2 million gallons a day of water, right? So if you're water in a water challenged area, you've, you've got that. Like, and, and Phoenix wants to be the head of, you know, the big data center capital.
Where do they have the water for this? So you are going to see local townships and local legislatures and local governments say, Hey, it's not worth it. It's not, it doesn't create that many jobs.
It's, it would, we were sold the bill of goods, it's not worth it, and they're gonna try to change things. Is this the right way? By doing it as a zoning thing after the fact.
If it was after the fact, I don't know. I did check different S will have different reactions, though. El Paso last week just approved the data center project on narrowly, but If you were in El Paso, you would too.
I did check. And they, uh, this, this, this part of the country, this township or whatever, had, did have a master plan. This area was apparently designated as as agriculture.
Oh, okay. Agricultural. Now, I don't know, I didn't quite see how a data center is agricultural.
Um, but of course, is it an industrial, is that the kind of zoning you need to do? I think what's gonna happen is that we'll see townships, et cetera, explicitly stating whether data centers can be built. So there's either black and white, you can or can't do it, or if you could do it, but you could do it in these areas.
Otherwise, now you're talking about, you know, interpretation of the law and on, you know, kind of, right. So Data centers are gonna have a particular zoning designation, not just industrial, not agricultural, not residential, not retail data center. Mm-hmm.
Will be a thing. But let me, let me throw something else out at you guys to just ponder and chew on. Historically with these kinds of things.
You know, what happens? Well, off people don't have data centers in their developments or in their neighborhoods or in their areas. And let's put the data center in, in those people's neighborhoods.
They don't have souls anyway to quote the Godfather, right? And so you're gonna have data centers, if you see a data center, you're gonna say to yourself, Ooh, must be a low income neighborhood, because they didn't have the wherewithal to keep it outta here. And so it glows at night or, or whatever.
So, you know, jp, you're smiling. We grew up in that. Oh, No, because I mean, two of the biggest data center, one of the biggest data center areas with two huge facilities is Ashburn, Virginia, Northern Virginia, which is a well to do area Very well to do a lot of money.
Yeah. And they, I mean, what they did was they stuck them right on the side of a highway. And, um, you know, they're out of the way.
They're really not part of the neighborhood, but, you know, they're accessible. Um, and they're, you know, where, I mean, if anything, they probably keeping volume of traffic, you know, sound, uh, down because they're fi it's filtering off of the highway there. Um, and it's not letting it come out onto the street.
I mean, it, it it's agriculturally or ecologically. It's, it's a good mix, right? It where they located it, but it's also, it's not indicative of a low income at all.
The fact that it's there. No, but that's a different data center to be, to be honest, right? You're talking about the, like when I helped do inter reliant, we had a data center in Tyson's Corner.
It was the old a OL headquarters. And it was just what you're saying, it was a non-descript brick building right off the highway. And I forget how many, if we had 20,000, 30,000 square feet of data center space there, something like that.
It was a nice size little data center. Wasn't the biggest, wasn't the smallest. That's not these AI factories that we're talking about, though.
These AI factories that they're building are literally the size of Manhattan. That's awful. Hard to hide, you know, behind some green curtain or something.
And the environmental impacts a lot bigger. This is today's the, the 2025 version of the high power megawatt overhead power lines. Yeah.
Right? Do I want those running through my neighborhood? Do I want, now do we want a data center at the end of those?
Yeah. So do you think these are always gonna be in rural places, or will they like try to build a data center in, I don't know, some part of the Bronx where they just wanna level everything and they're just gonna use it as an excuse? Mike?
I I would never, I would never suggest that they do anything bad to the Bronx, you know, that. But, but think about it, building it in a rural area in Nebraska, to Mitch's point, not only do I gotta bring the, the electricity there, the cooling there, the bandwidth there, whatever few jobs it brings, I gotta have bring the people there, right? That's a lot of theirs.
Versus if I built it, you know, in a somewhat more suburban urban area, we Can, sorry. Good with you. Jump in There.
No, I totally get it. Why people try to build up the data center on the ocean. Right?
And last year I saw there's a, like, uh, startup, they try to build up the data center, something under the, under the ocean within the, within the water. Now I totally get it. Yeah.
Well that would, There's actually, there's actually a lot of good e evidence that that is a smart direction. One, you get you, they use the waves, uh, for energy. Yep.
They use the, the temperature to keep the cooling. So a lot of, a lot of what you need to run a data center is free when you go down a certain depth into the, into the water, into the, a large body of the water And there's no, no lawsuit, right? I guess, Yes, somebody will sue somebody, for sure.
However, I would also point out that, you know, as soon as we figure out that we don't need all these data centers, it'll be great for the coral. So there you go. There you go.
That can become artificial reefs. That's some Things, yeah. Artificial place to live.
Yeah. Okay. Dual, uh, that they call that a dual use in the business.
But, um, anyway, guys, we're about outta time. What a, some interesting, some interesting topics to discuss here today. I, I enjoyed it.
I hope you did. I hope all of you did as well. Hey, listen, uh, today is Tuesday and we, we actually recorded this a day early, but I wanna say happy Rosh Hashanah to my, my, uh, Landsman and all those who celebrate.
I also want to remind you that this week we are going to be live on tech UNK TV for a tech field day, uh, cybersecurity Tech Field Day. And I believe that plays on, uh, is it Tuesday and Wednesday or Wednesday and Thursday, Mitch? Something That I don't know, but, but it's days, I would say days this week.
Yeah, I would guess Wednesday, Thursday. But I'll, we'll double check. We'll post it.
So do, do follow along with that, of course, we will have gang episodes. Mike Ard will be running the show. And, uh, and of course we have text Drunk TV immediately following as usual.
com, cloud native now, or digital CXO or the Futurum group as well. I know, Mitch, you've got a lot going on there, jp. I see you time to time on LinkedIn publishing lately.
Yes. Uh, it happens to be probably my biggest source, uh, is publishing on LinkedIn. It just, you know, you, you spread the content out in too many different places.
It's, it's difficult to, uh, to get, uh, the attention you want. So yeah, LinkedIn's become a primary source, and then I just link to that elsewhere. Excellent.
All right, Alan. The, uh, tech Field day, or security field day is Wednesday, Thursday. It is Wednesday, Thursday, yeah.
And the companies are folks like One Password, HPE info blocks, Nile Square X, some great, great companies to, so it'd be very interesting. Stay Here. Absolutely.
So check, check that out. All right. Hey, everyone, Wiki, jp, Mike.
Mitch, thanks for joining. Thank you for watching. This is Alan Shimmel.
We're out. Hi everyone. We're back here in Napa Valley.
Uh, it's Swamp up. J Rog Swamp Up event. It's been a great two days.
We're kinda winding down, but we saved some of the best for last. If you take a look at this guy, you've seen him on Tech Drunk TV before. Um, we've been working with Steven Chin for four or five years, maybe more.
We've seen him when he first came to Jfr, coming from the Java community, leaving Jfr, Neo four J and now back. Well, you're not, you're not a frog, but you're, You're well, But presenting, I'm bringing the best of both worlds. 'cause now we can use Graph intelligence, uhhuh plus DevOps, and solve some real security challenges, supply chain challenges.
So can I call that dev graph Intel ops, Because Yeah, yeah. Let's call that, let's call that, yeah. Yeah.
That'll be holds off. Let me keynote next year. I'll next year Dev graph Intel ops.
Yeah. If You can get up to say that you really are a magician. Okay.
Um, but seriously, Steven, it's great to have you on, you presented this year here at, at, uh, swamp Up. But before we get into your presentation, you are a swamp up veteran as much as I am, or more even. What'd you think?
It's nice to be back in Napa. Yeah. So the first swamp up was actually here at the Meritage right resort in 2015.
Um, and I remember like super casual, but all of the thought leaders in what probably didn't, wasn't even called DevOps at the time, but like, like people actually doing real world deployments and infrastructure, dealing with security issues, dealing with challenges, getting to deployment. Now, you fast forward 11 years from now, we're back at the Meritage humongous event sold out. Yeah.
Full audience. And now we're looking at the same problems, but with the lens of how we use ai right. To solve and to automate and to really like, streamline your DevOps processes, because that's the biggest challenge with AI that nobody's talking about, is getting AI outta production, releasing ai.
Everybody has amazing prototypes, amazing applications. They have this humongous value, but the quality's not there. Those are humongous investment.
Let's, in Investment investment, the quality is not there. It's, it's not providing business stakeholder value. It's not production ready.
It's not secured. No. I mean, this came out, there was a recent study you probably saw from MIT, there was another one I think from, I wanna say from Deloitte, though it might have been Accenture.
One said 95% of, uh, AI apps have not affected the bottom line or been classified as not successful. Another one said 80%. So depending who you wanna believe, neither one of them a good picture.
But, but you know what, I remember when they said the same thing about DevOps. I remember when they said the same sort of things about cloud. This is, you know, it take, the thing about AI is it's so much a victim of its own success that the hype meter went so sky high, you know, Um, Defying gravity to Well, well, you said, you said that in past tense.
It's still going up. You think It going up the, the hype meter? I, no, I, you know, I'm starting to see a lot of people say, you know, already going down to that trow of disillusionment, right?
Y you know, like, so, so when you look at AI in aggregate mm-hmm. Like, like a lot of the early things like LMS and, and models and inferencing, like those, those are more stable. Like the, the progression is more incremental.
But when you look at what people are doing with AI on top of that, where they're building agent systems, they're incorporating like different knowledge sources in their organization, um, they're taking advantage of, of data science and different like layer techniques. Those are still new buzzwords every six months. New techniques for doing it, like new advancements and what the capabilities you're able to bring.
And, um, what start out with chatbots, which are kind of, you know, passe now is turning into business intelligence and, and dashboards and like insights into customers. And there's a whole bunch of real use cases which, um, if, if they were production ready, if they were accurate, if they could provide explainable audible results, it would be amazing. But there's just a gap in getting to production and, um, I think swamp up in like a conference like this, which is so focused on releasing.
And DevOps is a really good, um, litmus ground for the latest in getting to production because it's, it's just focused on professionals who do this for a living. And they're, they're the ones who all the apps and the companies feed into, and they have to make sure they meet the quality bar. They're actually like at a level where you can release them and maintain them and support them.
Agreed. Agreed. All right.
Let's pivot. Let's talk about your talk here at Swamp Up. Yeah.
So what, what I did here, because it's, it's an audience of people dealing with security issues with software bill materials, with like releases is I used Artifactory as the system of record exported a bunch of SBO M and VEX files and Cyclone DX format. Um, you could also do SBDX. Mm-hmm.
And I fed those into a knowledge graph system where now you're using an LM to take all that information and construct a knowledge graph, pull in a bunch of insights from the data, and then create these connections. And so when you, when you ask like an LM let's say you're like a security scenario, you're like, well, you know, in this library, what, what secure security vulnerabilities are they? How exposed am I, yada yada.
It will, it will tell you a wonderful story, very, very long-winded. And like, like it'll find similar things, similar security exploits, like similar production issues, but it's not very relevant to your system. No.
Like, is it a library you use? Do you even call the API which matters for it? Um, so what knowledge graphs are really good at is grounding.
And so they take that information, they encode it into a, a knowledge graph and a knowledge system. And then what you do is you tell the LM answer from this knowledge graph, and I, I did it two different ways. One is, um, uh, it's called, um, doing a, a, a graph vector search with graph enhancement.
Mm-hmm. And you first ask a vector database, um, NEO four J also has a vector store for the answer, and it does similarity searches. So it gives you back related information, but not very pertinent at all times.
And then you then pull some of those nodes out and you say, what nodes are similar to this? So like, if you find the particular security exploit by the first search, now you'll pull in all the libraries that's nested in the authors of those libraries, the systems that's deployed in, you pass that as context to the lm and it does a ver a more precise job of answering. And it's also very fast because the vector search returns immediately, the graph look ups quick, and you get back a very quick response.
The second thing I did, and this was, um, new this year, and I think this is the future and why people are investing in some of the new AI technologies, is I stood up an MCP server. Um, so I used cloud desktop. I deployed the MCP server as a DXT file to the local desktop.
So super easy. We have an open source, um, cipher. Cipher is a query language for graph to, um, um, text decipher MCP agent.
And I gave it the same database, the same knowledge graph, but then asked it to solve the question. And this time it wasn't doing a vector lookup at all, but the agent was using the tool to help answer the question. So first it retrieved the schema of the database, and I saw, okay, well, you know, you're asking about a library now I see like that's a package.
Now I'm gonna ask about all the vulnerabilities which relates to that package. So I did a query. I was like, okay, well you asked about the, how the vulnerability applies to my application.
So then it dug in deeper which applications were deployed that used it. And after a couple round trips where it was querying the knowledge graph and building it out, and without any, I didn't need to write queries, I didn't need to optimize the flow. It it navigated this.
So Yeah, It came up with basically a very detailed report on, you know, this is your application, this is the risk areas, this is the things you should investigate, here's all the information I know about it. And it's, it's the same sort of research like we would do as security researchers. Yep.
So let me ask a question though. 'cause one of the beauties of a m is that they're not static as the release you are using or the, the component that's in this piece of software as that component we find out about vulnerabilities in it. The, there's a new version of the component, whatever sbo M'S are supposed to be telling us all that.
Does that kind of, um, not portability, but automated updating, does that live in the graph as well, Doug? Yeah. So the, the nice thing about graphs and, and like graph database technology is, it's been around for a long time.
So like doing updates of the graph, like doing transformation of the graph is all a pretty solved problem. Yep. Um, so you can continually update the graph, you can use, Does it continually update itself?
I guess? Well, my question, my demo didn't, well, This is just a demo. I mean, yeah, Yeah, yeah.
But you, you, you can basically set up an automated system where as you make changes, it'll update and it'll pull, pull the entities out, update the graph, and then the other thing, which, um, graphs are very commonly used for is removing data silos across the organization. So my, my use case was, um, all the data was an artifactory. So theoretically, like this could be a product capability and artifactory, but what if you also need to cross reference those security vulnerabilities and the, the applications against like another database, which is our, you know, our known mitigations for different vulnerabilities.
Maybe you have like a another application list, which is our, where all the applications are deployed to different environments, what hardware they're running on. And now you can use the graph to pull all this information together, have it be the system of record, which gets, you know, updated and managed from all these different systems. And then you can directly derive value by building dashboards, by building query interfaces and things on top of the graph database.
Absolutely. Um, exciting times, huh? Exciting times.
How do people, the regular people, and keep in mind our audience are not regular people. Our audience are our people, right? They're, they're techie people, they're developers, they're DevOps engineers, they're platform engineers and security folk and, and so forth.
Is this beyond them, Steven, can they do this themselves? Is someone gonna come along and wrap this into a product or SAS or something? Yeah.
So that's, that's interesting. Now, I think the point we're at in AI evolution is anybody who tries to sell you a, like a platform or a package solution, it's, it's never gonna provide the business value you need for, for your system and your use case. Now, on, on the flip side, it's never been easier to raw your own.
And I, I'm not even talking about vibe coding. So literally my demo was, um, I created a knowledge graph using an LLM, and I used a prototype web application or knowledge graph builder, it's open source, it's free. I threw the documents in it, connected to a free or a database that's our cloud database.
And I have my knowledge graph built without writing a single line of code. That's what people want to hear. And then for the MCP server, so of course you could, you could do it, you know, a docker deployment.
Yeah. Like do all the infrastructure and do all the port configuration, yada yada. I didn't bother with that.
I downloaded cloud desktop, took the open source MCP server, which is, you know, in a packaged format, and I edit it as an MCP tool to Claude configured a few like URLs and usernames and passwords for the database, and then I could query it. So this is something anybody can do, and it's really lowered the bar for, um, people who are technically skilled. Mm-hmm.
Right? They, they understand the business domain, they understand the requirements, they understand even like, like how to architect systems, but you just don't have the time to, to build and maintain a, a large code base to do a specialized application. The, the tooling's got to the point where you can take off the shelf MCB tools, you can take some technologies like graph databases, and you can compose a very custom tailored and productive system for use cases and scenarios you have internally with, you know, in a, in a quick hackathon project, you know, 24 hours a few days with a team, and you have like a, like a working system.
Fantastic. But you gotta love, I mean, it's an in, you know, they say you may, you live in interesting times. It's crazy times to be living in crazy times.
Hey man, we're about outta time. We're gonna bring on, I think it's gonna be our last, uh, swamp up. Steven, it's a pleasure seeing you.
Say hello to Cassandra. Check out Steven's just, he's almost the precursor, but you know, chin two oh is Cassandra. Check her out.
She's doing amazing things too. We're here at Swamp Up. I think we've got one more great one for you and we'll be back.
Hey everyone, it's Alan Shimmin. We're back here and we're back live at Swamp Up in the beautiful Napa Valley. You couldn't ask for a better location.
The sun has come out, you know, it's good for the grapes. They say it gets a little cooler, a little warmer, the sun, the rain, you get good grapes, good wine. But we're here with really maybe the highlight of our panel today.
Um, three, three of the VITs of, of the, uh, event the Man to my immediate le Actually, I'm gonna let you go last. Okay. Let me start to my far left, I wanna introduce you to Rahul ti.
Rahul is the GVP and GM of the ITSM, something I'm a little familiar with business unit at ServiceNow. Rahul, welcome to Tech Trunk tv. Thank you.
Thanks for having me here. Give our audience needs no introduction to ServiceNow, but give them a little bit of your background maybe and a little bit of what you're doing at ServiceNow. Yeah, so I'm relatively new to ServiceNow.
I joined little over four months back, uh oh, really? New. And, and I'm running ITSM, which is the bread and butter, the largest business ServiceNow does.
That's where ServiceNow was founded. My background has been building products for a long time for large enterprise companies, but the interesting bit is I switched midway to being a practitioner myself. So I was running DevOps teams in the cloud space in my last startup before I came to ServiceNow.
So I've been on both sides of the equation, building products and consuming products. That's, and that, that's missing in too many of our vendors. As someone who speaks to vendors all the time, you, it's good to have that practitioner side to see what it is they, they're actually feeling.
As that goes by, let's introduce Justin Boitano. Justin is VP of Enterprise AI at Nvidia. Justin, welcome.
Thanks for being on text on tv. Thank you for having us today. Give us a little, maybe a little bit of your background.
Yeah, well, I've, I've been in Nvidia now actually for 13 years, I guess. Wow. A little bit of everything over that time, but, uh, You've seen it come, it's been go, Huh?
It's been, it's been, you know, quite a fun ride, uh, you know, watching us really reinvent how computing is done. Um, you know, from really the ground up. Uh, and I think it was, uh, when I first joined in 2008, we had just invented Cuda.
Nobody knew what it was. We were going around library by library, trying to port applications onto GPUs. People, you know, thought we were crazy, I guess in the early days, but eventually, you know, every, uh, overnight success is, is 10 years in the making.
Right. And so we've been working Hard. That's exactly the biggest secret in tech, the 10 year overnight success.
Yeah. You know, we had Avalon earlier and we were talking about so many people think of Nvidia and they think GP and the hardware, but the real secret sauce here is Cuda and the software and the ecosystem with partners like ServiceNow and Jfr. And, and we had Sonar CEO here as well.
Um, and that's really the, the key that's driving all of this is as much as the GPUs do Agreed To my immediate left, immediate left, this man needs no introduction to our audience either. I've had the pleasure of interviewing him for, um, 10 years, 12 years, something long time. He's the CEO co-founder of Jfr Shlomi, Ben Hay Shlomi, welcome.
Pleasure being here again. Again, you, thank you very much for having me. So, look, I was in the keynotes this morning.
It was an amazing keynote. And as one would expect this year in tech, AI was front and center. We've been talking about it all day here.
The thing about this is, look, all of us have been around the block. We've seen technology waves calm and go flow and flow up and down. We've never seen something this disruptive across the entire breath of, of our industry, right?
I, I think Satya Nadella maybe said it best, or the best that I've seen in that we are moving from becoming, you know how Mark Andreessen said every company's a software company. Yeah. We, were all software companies, but we're moving from software companies to intelligence engines.
Right? And what, that's a profound change in our business. Show me if it's okay, I'm gonna ask you to kick it off.
What does that intelligence engine bring that to some of what we talked about today here at Swamp Up, agen, ai, the whole ecosystem, dev gov, ops, all of it kick us off. So Ellen, I, I, I think we will need two days to cover this, uh, And then some. But, uh, but I, I will touch the immediate things that we see in the market.
And this is a, across the board, it goes beyond sectors. It goes beyond, um, company size. It goes beyond, uh, geographies.
What we see is a revolution, a disruption, uh, that changes everything we knew about the day-to-day practice. And a company like Jfr, we are not the native AI company. We are the infrastructure company.
We are the providers of the peak and shovels. We are not the gold miners, and therefore we have the privilege to see from below the changes that are happening. So one thing that we see happening across, uh, our portfolio is that consolidation happens not only in terms of technology, but also the inner organization, the CIO and the ciso, the compliance managers, the audit managers, all of them must collaborate in over to overcome the chasm, to bridge it and to eliminate silos.
Otherwise, they will stay behind. The second thing that we see is that developers that used to build called, it used to be called, used to deliver software, and then few years ago, they started to be security expert. And now they have to be release expert, and they also have to be AI experts.
0. They are changing the world for everyone. And the last thing that, uh, we see is that if we are not looking at the, uh, opportunity as coexisting, uh, providers, one of us will stay behind.
If we go together, we will change the world together. This is not a race. And, uh, and therefore I'm privileged, I'm honored to walk with companies like ServiceNow and Nvidia, um, to give my customers a better experience and experience that they expect a one platform experience.
Absolutely. Rahul, I'd like to come to you, right? So you think ITSM, is there any sector of our tech world that is more rule bound that you would think needs a little shaking up maybe, or, or maybe doesn't need a shaking up, but is certainly getting a shaking up with ai?
If you don't mind, share with our audience a little bit of the profound impact that AI's having in the world of ITSM. Yeah. So I think it's getting shaken up.
And honestly, we, being the leaders in that segment, we would like it to shake up. Because if, the way I look at it is, it of yesterday has have changed. Now it is tru truly a broker of services, right?
They're managing SaaS assets, they're managing cloud assets. So go on is the IT of yesterday. The service has changed from IT providing services to I want my self service, right?
So when Jensen was on stage on knowledge, he is like, his main thing thing was, I want my service now, right? That was his mantra. So people want their service now and management is no longer like, top down, let me tell you what to do, what not to do.
People are not used to that kind of thing. So we are kind of reinventing it. Service management and AI actually helps you really create that agility on top of the more fixed workflows, because now you can do more with AI to create value out of the workflow.
So workflows can still exist. Like the example we gave this morning, compliance and regulation is still required because who wants to have an application that is going to be breached tomorrow? Right?
That's at the same time. Does it take, should it take a week to get approval? No.
Right. So I think we are reinventing those ITSM processes and kind of integration with jfr, looking at the AI patterns and everything else because the speed has gone whatever, 10 XA hundred x, right? So things that were taking weeks or taking seconds.
So that's where our head is at from an ITS perspective. Absolutely. It's velocity.
It's velocity. Yeah. You know, talking about the profound change, if we, if I asked a hundred people watching this live right now, what is the AI company?
98 of them are gonna tell us Nvidia, but Justin, you know, this, and even Nvidia, I want to know who are the other two, who the other two, they, they're living somewhere who knows on a, on an island somewhere talking to a volleyball. But, but Justin, even Nvidia knows that as great as Nvidia is, and as they've led the charge help lead the charge here, you can't do it alone. You need partners like Jfr, like ServiceNow, like sonar, like, you know, so many.
You, I mean, one of the, the real strengths here is NVIDIA's ecosystem. Talk to our audience a little bit about that. Yeah, I mean, I, I think that's, uh, well, a, a great point.
Um, you know, Nvidia forever, honestly, has been an ecosystem led company. And I think honestly it's, it, it comes top down at Nvidia. Like Jensen realizes the power of an ecosystem for selling our physical hardware through OEMs and ODMs globally, uh, through infrastructure companies, uh, you know, uh, plumbing, the runtimes of these accelerators, uh, up to the AIOps applications and into the GSIs.
So we work across the entire ecosystem to try and provide acceleration to, uh, I'll call it, uh, key, you know, workloads that we know are gonna deliver a lot of productivity or performance gains or, um, you know, really kind of transform the, the business, uh, if you would. Right? Um, and, uh, you know, this, this latest version of it, I mean, for a long time we did it in high performance computing to, to, uh, deal with F-E-F-E-A and, uh, you know, CAE and like the simulation, uh, of the physical world.
0 where it's the, the reality is it's a probably a $3 trillion industry, you know, a a trillion dollars in, uh, pure software that gets bought per year across enterprises and $2 trillion in services. That entire industry is being rethought now through this, uh, this new way of building software where you've got agentic systems that can break down problems, try and solve the problems on their own, and then reflect on the answers. And so there's, there's a, a tremendous opportunity, I'd say, for all vendors in this space really to, to ride that wave with us, uh, in the era of ai.
Agreed. If I may add, add to it, uh, Alan, look at, uh, what Nvidia did, um, in, in the history of software, the first thing that they act was, uh, community native company. They released their software as open source.
Yeah. Um, today, uh, uh, Justin and his team presented on stage, like everything they build in order to optimize GPU with software is open source available. That's right.
For the community. Open source is not only we build it for you, but we build it with you with the community. So I think it's really speaks for itself, uh, ab absolutely.
But we are looking at the improvement that software brings to the world of ai. Yeah. com today, my mom that all used to always tell me, show me your friends, I'll show you who you are.
Right? You probably all heard that. Or similar thing from your mom's, I'm gonna ask, you already said it Justin, but Rahul, and then I'll come to you.
Shlomi. What's the importance of your partner ecosystem in this brave new world of ai? So, I think any, anyway, at the core of it, if you look at ServiceNow, it is only about workflows data.
So that's what we have built our business on, right? Because enterprise has front office data, back office data, asset data. And if you don't unify the data, then you can be disparate systems on top of it.
You tie it with a workflow. So now the third leg of this tool is AI for us, because AI helps you do your workflows better and faster, and there is no way we can own all the pieces of the workflow anyway. Right?
There is the software supply chain that multiple players, including Jfr, are there from a hardware perspective or from a software infrastructure perspective. Then we have cloud vendors, there are model vendors. So at the very heritage of the company, we believe that partner ecosystem is critical to it because that's what our customers want.
They cannot rely on a platform that is closed, monolithic does not allow for partnerships. So I think it's the DNA of the company. That's why we are so excited to partner with.
We call it like any model, any industry, any infrastructure is what our ethos is from. Excellent. Yeah.
Shlomi, I, I believe that, uh, um, what our customers are telling us is the, uh, the honest, true and the pain that they experience. And they also know how to put the volume on this pain. Is it a major pain or something that we can handle?
And, uh, every time that, uh, that the technology company is coming with a piece of innovation, the second question should be, what's my ecosystem? And uh, some people immediately ask the opposite question of asking, am I overlapping? Am I competing?
The, we are running a platform. We have, I dunno, thousands and thousands of thousands of logos in, in our joint portfolio. For sure there will be some overlap, but if the one plus one equals more than two and our customers, um, actually ask for it, how can you go wrong?
And when we presented apras the, um, the um, dev gov ops solution we discussed today, we didn't present it as an ecosystem tool yet. It was just an idea in the beginning of the year. And our enterprise customers stopped us right there and said, listen, the people who need to use appt trusts the application owner.
They're not coming to jfr, they're going to service now. And uh, when we started to, to walk with Rahul team, um, and we spoke with the customers, they actually echo that. And, uh, and what we've built together and presented on stage here today is just a representation of our, uh, of our customer's voice.
Uh, I'm, I'm very proud to be part of a company that instead of coming as an arrogant vendor, telling them what is right for them, is asking the, the customers, what will be better? How can I make your life better? I love it, guys.
I gotta bring up a difficult one. It's not on our list, but I've gotta ask you. I talked to a lot of people about ai, as you would imagine, it's almost impossible to live up to the hype.
The hype, the hype cycle is the right, and there are a lot of people out here who are starting to, you know, the ankle biters. It's not everything we thought it was gonna be. It's not.
This is a lot harder than we thought. It's gonna take longer than we thought, I think was the expect we set such expectations of it changing the world so quickly. I, and I said this, even if we stop developing AI right now, and we just said, okay, let's digest what we have, it would take seven years to fully integrate it into all of our ecosystems.
But what do you say to the naysayers who are saying, we're not going fast enough. It's not good enough yet, we may never get to the holy land to the promised land. Justin, you're, you're Nvidia, I'm laughing and you're gonna go walk A day in my shoes.
It's moving really quickly. Yeah. Is all I can say.
And I think, you know, in the, the early days of generative ai, uh, you know, people were kind of dabbling. They, they treated it like Java. It was a new technology.
They wanted to upscale themselves, but they didn't know how to apply it to their most pressing business problems. Um, you know, and, and we see now every enterprise really focusing on like, how do I reinvent the core of my business? Honestly, at Nvidia, we've done it ourselves too.
Like Jensen gave us the challenge, you know, double the number of chips that you produce, uh, every other year. So instead of doing a chip every 18 months, do it every year with a design cycle in between. And the only way to innovate at that pace without obviously exploding your workforce, is by using AI and infusing it into the, the business process of the organization.
So we're applying it, you know, to reinvent how we design chips, how we develop software, uh, how we engage customers, you know, through every business function of the company. And we're starting to see that in, in a big way, happen really across every vertical industry, from retail to telecommunications, to healthcare. Um, and so I, I think it's moving faster than you might think.
I think, uh, you know, en uh, enterprise in some regard has always been a slow beast. Um, it's always moved. The transitions have happened, you know, more slowly than than we would like.
Um, but in my conversations with CIOs, I think what they realize now is it's time to make that shift. Instead of reinvesting CapEx in standard data center infrastructure, take the leap to accelerated computing and, you know, and focus on building agents that address your core business. And, uh, people are seeing, you know, huge, uh, productivity gains and huge improvements to margins that way.
Excellent. Guys, I got one more question, and it's for Rahul and Shlomi. I want each of you to answer this question looking into this camera.
Rahul, you're gonna go first for all my friends in ITSM, and I'm very good friends with the folks at ile, my, my friends at People Cert and, uh, Demetrius, and they're out in Greece watching this. But talk to all of the ITSM people out there who were worried, is this gonna take my job? Am I gonna have a career?
I just got into this profession five years ago. What is AI gonna do to my job? So I think my thinking is the train has left the station.
If you get on the train, you will have a job. If you don't get on the train and start kind of on the side, kind of okay with nay saying, I think you may actually lose your job. The reason is when I've seen the successes, people who have embraced, they are having AI do the job they did not want to do in the first place.
Like summarization after closing every incident, really going after knowledge base updates. Who wants to do it? I've seen people who have started going that direction, then they realize, oh, I have not submitted that knowledge.
Why can't I have agent tech do it for you? So slowly they are getting on the train, and the train has gone to the next station. People who are left behind, is it not good enough and all that?
Sorry, that is not gonna work. So let me talk to the software developers out there. First of all, whatever Raul said, I'm in, uh, no, no, no, nothing to add.
Software developers, if you remember the days of CICD that you doubted building software with some tools and automation, if you remember the days that, uh, you said that developers in order to be faster, they need to be a bit dirty and not secure. Those who didn't, uh, um, jumped on the train left behind, and they are not software developers anymore. You have more responsibility and the next generation trusts you to build it, right?
Because we are changing everyone's world. Absolutely. I'll end it with this.
I said it before, I'll say it again. You're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than you.
Right? And amen to that. We've gotta learn.
It's a tool. It doesn't replace the spark, the spark that's in now all of our brains, right? That cre the creator, but it's a golden age for creators.
Absolutely. And we're lucky to be here. Rahul, Justin Shlomi, thank you.
Thank you for watching. We've got, we've got two more. Oh, another day after this.
Another half a day here of, uh, uh, JFR Swamp Up coverage. So check it out. We're on Techstrong tv.
We'll be right back. Carbo tosses their data centers. Broadcom is powering open AI now.
Microsoft is making more deals, lapses, scatters. A rolling stone summarizes no moss. Claude is a criminal.
And we're gonna take a look at all of the big AI cloud news of the week in this episode of the Tech Fuel Day rundown. Hello everyone. It is time for the Tech Fuel Day rundown.
I am your host, Tom Hollingsworth, and I'm on location this week. But joining me as always is Al and Al, I have a question for you. How do you feel about Deep Fried Club sandwiches with a side of Sweet Jam?
I'm sorry, it's gonna take me a moment to three to process that. Um, not something I've really come across. Deep fried Mars bars in England is the nearest thing I've come across.
Well, luckily for you, it is Monte Cristo Day, which is not just an, a novel by Alexander Duma, but in fact is probably one of the most decadent sandwiches you're ever going to eat. But, uh, if you feel somewhat ill after that, don't worry because it's World Patient Safety Day, uh, along with a whole other host of things. Uh, but what we are definitely making sure we're taken care of this week is the news, because we are thrilled to have a lot of interesting things going on.
And we are gonna be bringing you all of that news as we go forward. 4 billion data center. That was proposed by energy storage solution.
The reason, resource and community concerns, although be shocked to learn that the company is going to be challenging that decision in court, the ruling based on legal criteria rather than public opinion reflects broader tensions in North Carolina over rapid AI driven data center growth and its impact on local communities and utilities. Al do you think that this, uh, tenant is gonna be to able to overcome city Hall? Well, I think there's a couple of fun things in here.
4 billion. Uh, they're even in North Carolina companies. So it's not like big business coming in from out of state trying to ruin our, our local, uh, city of, of tbo.
And the concerns are the usual concerns about having a big data center built next to, uh, noise, uh, water consumption. 'cause the data center was going to use a huge amount of water for cooling. Uh, and then also the cost and cost of power.
The proposal itself was primarily that the power generation was gonna be on site. And so there shouldn't have been a grid impact or cost of power consumption impact. But the, the locals were a little concerned around that as often happens when these big data center projects are turning up.
This particular one was interesting because the, the, um, area was already zoned for heavy industrial. So it didn't require a, um, council decision to allow heavy use of what maybe was previously farmland. And this was already zoned for, for heavy industrial.
Uh, and that rezoning process is what you normally see in a council of very open meetings and lots of submissions from the community. The interesting thing for this one is that they had a special use permit application where the council, instead of taking public consultation, looks more at the science of what's gonna go on than the public feeling. And that caused a little bit of a challenge in here, and that's the opening that a SS has to challenge this.
Uh, the mayor even recused himself because he didn't feel he would be able to be independent in the decisions. And that's definitely an opening for a SS to say the whole council couldn't be independent and no swayed by public opinion, which isn't supposed to matter in this special use permits. This is a weird one.
Um, but it is, it does carry on with themes, uh, that we see around concerns for power costs, water consumption in, in these communities where there's massive AI data centers are being built out. Uh, it won't be the last time that we see it. I think there'll be some changes to how councils operate as a result of, of these challenges.
So in particular, the special use permits, uh, processes are gonna need to be tightened up and, uh, made much more judicial looking rather than consultative looking, uh, in order for these these things to have the rulings here. And it was an overwhelming, it was a six to one ruling here, uh, this overwhelming ruling to, to actually stand up to further review. They need to be more judicial in their processes there.
Uh, it's gonna continue to see more of these big data centers being built, and they'll be built in places where power is abundant or can be developed, and where cooling is either latent inherent in the, uh, geography or is something that can be managed easily, of course, North Carolina, uh, and pretty high humidity and pretty warm at times. And those aren't good things for free year and, and low cost calling. So I can imagine the, the concerns from the locals open AI plans to launch its own AI chip next year, co-designed with Broadcom, uh, to meet the soaring demands for computing power and also to mitigate that single source supply chain issue from the Nvidia that plagues many of the AI companies.
Chip will be used internally to run the, uh, run and train AI models. Uh, following the, the same sorts of trends we've seen from some of the other hyperscale, uh, vendors. Google, Amazon Meta.
Uh, Broadcom confirmed a major new customer with a $10 billion of an orders. Broadcom didn't say that it was open ai, but that's what we all believe, uh, move comes as OpenAI tries to bring in more resources to compete, uh, with products like chat, GPT and particularly GPT five that's coming. Uh, we're seeing huge growth in AI data centers.
Tom, does this mean huge growth for Broadcom as well? It should. And I think this is an area that Broadcom has been particularly worried about, because when you look at where all the growth has been happening in the industry, it has been happening around these AI accelerators and Broadcom powers a lot of the AI infrastructure that's going in on the backend, but not the actual GPUs themselves.
And I think that that's something that they really wanna be a part of. Plus, they haven't exactly been on the best of terms with Nvidia over the years. I, I remember there was a kerfuffle that involved Melanox and Cumulus Linux and Broadcom API access that, that happened many, well, I say many a few years ago.
But realistically speaking, Broadcom is giving open AI something that they couldn't get from Nvidia. Essentially, they're getting custom silicon. Uh, that's not exactly the way that this is being portrayed, but hear me out, Nvidia is gonna make Nvidia silicon and you're gonna run your stuff on Nvidia, right?
But so is everybody else. And that's part of the problem is that if you can optimize your models to run on Nvidia silicon a little bit better than everybody else's, then you have an obvious advantage. That's one of the things that we've seen from some of the, you know, AI platforms that shoot to the top of the App store, uh, for a little while, was that deep seek, I think was one they just figured out how to run a little bit faster.
So what's open AI to do? Because if they're trying to optimize their code to run on the same thing that everybody else is using, there may not be a way to win. Well, what if the manufacturer was optimizing their hardware to take advantage of the way that you do things, but in a way that makes it so that not everybody has that same chance?
Now, I'm not saying that there's any kind of a deal here that Broadcom is giving open AI to make them kind of dominant in that space. I'm just saying that when you look at the handwriting on this wall, Broadcom really wants open AI to be one of their biggest customers when it comes to purchases, right? And the only way to really make that happen is to play ball with them to give them something they can't get from Nvidia, which is a little bit more inside into the design process.
So I think what we're probably going to see is, you know, a large purchase, what was the, the number, $10 billion in order, you know that that's a pocket change anymore. What it is though is an opportunity for open AI to really kind of innovate around these new chips and possibly get people chasing those performance gains. And how do you do that?
Well, if you're writing your software to take advantage of what open AI offers, why not go buy the hardware from the same group up to see what happens with this one? Speaking of open ai, they and Microsoft have signed a new non-binding agreement that's going to allow open AI to restructure itself into a for-profit company and potentially go public down the road. That means that Microsoft gets to secure continued access to their AI technology.
Open AI's nonprofit parent would of course retain oversight and a $100 billion equity stake, you know, pocket change. There are some regulatory hurdles, and of course, there's that lawsuit from somebody that owns a social media platform that complicates the process. The move supports open AI's, growth plans, partnerships with cloud providers and long-term revenue goals.
But of course, the other elephant in the room is that open AI is continuing to project losses all the way through 2029. The agreement comes amid rising tension between open AI and Microsoft as both pursue competing AI initiatives. Alistair, do you think that this non-binding agreement is going to give open AI the flexibility that it needs to really start making money?
Yeah, it is making money really the point, you know, we're transforming society and building a better world for the fu. Uh, no, I can't do it. Um, yeah, profitability is, has gotta be somewhere in the path along the way here for open ai.
There's an awful lot of money has been invested. Um, the investors are gonna want their money back sometime. Currently, uh, open AI is valued at half a trillion dollars, $500 billion.
And, uh, that's an awfully high valuation for a company that is supposedly not-for-profit. Uh, the transition across from being not-for-profit restructure to having a for-profit part and maybe retaining a not-for-profit, that's gonna be the complex bit. And that's the bit that, um, is, is under a little bit of attack in the, uh, in the courts with, uh, yeah, Mr.
Mr. Musk, uh, suing, uh, along with, uh, ex AI is, uh, his AI company suing open AI around this, uh, move from its original nonprofit agenda. Uh, there's a lot of money at stake, and so of course it goes to the courts.
Uh, OpenAI does need to focus on some point becoming profitable, uh, unless they're gonna stay true to their nonprofit, uh, route. I mean, they've been nonprofit so far, but, uh, that's not in a good way. And yes, there's a whole lot of stories and we'll, we'll cover this a little bit later around the longer or medium term plans for all of these AI vendors and AI platforms from Microsoft all the way through, uh, definitely com sort of commitments to multiple vendors.
And again, we've, we've seen this in the other stories, uh, having open ai, not just dependent on Microsoft, but having also just done a big deal with Oracle to put a whole bunch of workloads, $300 billion worth of workloads into Oracle's cloud over time. I think, uh, OpenAI doesn't want to be stuck to just one partner with Microsoft, uh, particularly when they're looking to do very big deals and be, uh, reducing their risk from single supplier. That again, is a theme we are seeing in the AI infrastructure world, is, uh, recognizing some risks around Nvidia and, and other single source suppliers.
The recently formed Scattered Lapses Hunters, a merger of scattered spider lapses and shiny hunters announced that they're disbanding after they managed to compromise Angular Land Rover. Apparently these, uh, attackers, these hackers have decided that they'd like to enjoy their ill got gains and they're gonna retire. But really we think what's gonna be retired is the brand scattered lapis hunters, and that in fact, these, uh, people who are skimming money around, uh, are gonna want to continue to do that.
Probably there's somebody at the top who financed it, who's pulling all of the money out, and the people doing the real work who are only getting pennies on the dollar, are probably gonna continue to want to do that real work and continue to attack, uh, various companies along the way. Uh, Tom, do you think the solution to this is for the, uh, attackers themselves, the people who do the real work to be getting a larger proportion of the money? Do we need to renegotiate contracts in this, uh, malware business?
Are are you saying that the, the criminals need to unionize? I mean, it's not the craziest idea that I've heard now. I think what you're seeing here is the results of Icarus flying too close to the sun.
Again, because this isn't even the first time we've seen this out of either of any of these component groups, right? They, uh, the, you know, the, when they came together, everyone was like, oh, yeah, you know, maybe you're combining resources for something. And, and I'll admit hacking Land Rover is not a bad hit, but this is like that scene at the end of Oceans 11 when they all kind of walk away and tend like they don't know each other, but they're not gonna stop being criminals.
Like thi this ultimately comes back to they need to let the heat die down for a little bit until people kind of forget about them. Some other nation state backed team or some other group does something, and then we'll hear about them again probably six or seven months when, when we least expect it. Uh, especially the Lapsis group, they, they kind of thrive on this notoriety.
They want people to know who they are. It's, it's not about the money for them. I, I don't get me wrong, if if I had millions of dollars just sitting around that I'd purloined from things, I, I would probably be spending it on random stuff too.
But it's more about everybody knowing their name, knowing who they are, knowing that they were behind it, right? It's, it's the credibility thing. It's like tagging a website back in the nineties.
So I I, I wouldn't put too much stock into this retirement. It's like a professional wrestling retirement. Give it a month, and I'm sure they'll be back at it.
Before you know it. Penske Media Corporation, which is a company that owns Rolling Stone Variety and Billboard has sued Google. And why would they be doing that?
Well, they're accusing it of illegally using its content to train AI models and power. Google's AI overviews in search. Penske argues that Google is abusing its monopoly by forcing publishers into a deal that they didn't agree to.
While Google claims that the feature helps users and drives more traffic to publishers, the case marks one of the very first major lawsuits by a media company against Google over ai, which is of course, adding to fuel to the fire against growing copyright and antitrust challenges that the Czech giant faces in US and Europe. Al that was an awful lot for me to read. Can you give me a summary but don't use Google for it?
Yeah, I'm, I might get you a, uh, natural intelligence or natural stupidity based, uh, answer to this. Um, what's going on here is that Google is starting to use AI to generate articles that summarize what, what's being published elsewhere. Uh, so when you get a search result that points to maybe an article that's on Rolling Stone, Google Wolf's, uh, offer to summarize that for you, rather than suggesting you go and read the original article that Penske Media Corporation paid to have somebody write either with or without ai.
And that's the core of it. But Penske, uh, but, um, Penske Media says, yeah, we're perfectly happy for Google to go and, uh, crawl through all of our content and direct interested parties, interested users to come and visit our site. But we put a line where you take that information you've gathered from our site and use it to generate what's essentially your own article on your own site.
And therefore we don't get that connection. Of course, Google says, yeah, you'll get the, the link coming through. People will just read the summary, and then they'll want to go and read the real thing.
Uh, tldr r yeah, I'm gonna read the summary if it's any good. Your summary is terrible. I'm probably not gonna read the original article either, because the summary has put me off the whole thing.
So I can absolutely see the point for the media publishers here. Uh, people writing good content as we know at Tech Field Day, is something that's really vital to us having good content that's been thought out and delivered by a human. And it's not just more of, well, maybe AI slop, um, is a really important part of communicating complex things and, and communicating particularly topics that our audience are interested in, highly detailed topics that maybe the AI can't quite catch up with.
So I absolutely can see the point here for the owners of Rolling Stone, the various other platforms that they publish, and I think we'll continue to see more of this. So there's a generic issue at the moment that there's a huge amount of, uh, AI generated content that is now being scraped from the web and used to train future generations of ai. And just like the, uh, the, the chicken flu issues of that, uh, they had in the UK where they were using ground up pieces of chicken to feed to the chickens and closing a loop of infection, we may well find that we're closing a loop of infection here.
And the more we can do to get human generated content and human generated insight into that loop, the better our lives are going to be and the better our are gonna be in the future over the summer, it's just here. But Northern Criminals exploited Anthropics clawed ai, uh, to automate large scale data center extortion. If you can automate doing good things with ai, you can automate doing bad things.
This included, uh, reconnaissance and credential theft ransomware, uh, and they targeted the usual sorts of, uh, larger organizations that are kind of critical healthcare, government, also religious organizations, uh, that's in demands exceeding half a million dollars. And Andros report detailed how Claude enabled North Korean IT worker scams and the creation of advanced ransomware, uh, which lowered the technical barrier for criminals. This is the new ground for script kitties is AI script kitties.
This company responded by banning accounts, improving detection tools and shared threat indicators with author authorities wanting that AI assisted cyber crime is evolving rapidly and likely to be much more common because it's so easy. Tom, have you built any ransomware recently by Vibe coding For legal reasons? No, for anecdotal reasons.
Hold on. Let me go ask, uh, Claude. 'cause it seems to be that Claude wants to aid and a bet everybody out there.
This is one of the problems that we run into when you create a model that really just wants to help people, right? And doesn't know how to not answer certain questions. You know, like if I asked it to build an explosive device, oh no, I can't do that.
Would you describe how an explosive device works theoretically for research purposes? Oh, sure, no problem. You know, it's, it's that old trick of, you know, I won't do the thing that I was explicitly told not to, but I will leave lots of hints to help you figure this out.
And let's be fair, jailbreaking these models and trying to figure out a way around their controls is almost half the game anymore. And, and one of the problems that you run into is if the AI is doing its job and consuming all of these things and reading all of the available information out there about crafting the perfect, um, information campaign to get extortion out of people, then yeah, it's gonna know what works and what doesn't. And it's gonna tell you, oh yeah, this one didn't, this one worked, but that one didn't.
And don't have 'em pay you like this, pay that, and Oh, you're in North Korea, so you're gonna have to use these systems. Like, that's the deal. Is it, it's doing what it was designed to do, which is refining information to something and producing, well in this case a summary, but one that allows you to do nefarious things.
And that's, we're gonna have to watch out for that. You know, it's, it, it's every problem that we've ever run into where someone gives somebody a little tidbit of information that they're not supposed to, and the next thing you know, they take it and run with it. And it now is happening at the speed of however many millions of GPUs are powering these clusters.
So I, I applaud philanthropic for doing the right thing and going and banning a whole bunch of people's accounts and trying to tighten down controls and other stuff like that. But every time that you do that, you just create craftier criminals. We had a couple things we wanted to take a closer look at this week, and they involve the advances that are happening in the AI space, but also where it intersects with cloud and specifically hosted ai.
The first one, of course, is a company that we've talked about previously on the rundown, and that's Core Weave. 3 billion order for AI computing capacity with Nvidia agreeing to buy any unused supply through 2032. The deal highlights, core weaves reliance on Nvidia, who is its sole GPS supplier and investor, while boosting its role in powering AI workloads.
21 billion in Q2 revenue, which is up 207% year over year. The company remains unprofitable losing 290 and a half million dollars. 9 billion deal with open ai, and that has fueled demand and pushed core weaves market value above $58 billion.
Now, Al we've got a story. We're also gonna be talking about Microsoft, but I wanna kind of get your thoughts on Core Weave and the fact that they seem to be getting a lot of sales, but not making a lot of money, and they are almost entirely dependent upon Nvidia to make that happen. Why would Nvidia agree to buy all of their supply for the next seven years?
Well, I think having long-term commitments for Nvidia helps 'em deal with the risk that there is an AI bubble, and that all of a sudden there may be excess, uh, GPUs in the market the way there were when the cryptocurrency bubble went pop. And, uh, we needed to find a new use for all of these GPUs because Nvidia was lucky. 'cause a long come generative AI and Nvidia GPUs are vital, uh, having that continued long-term relationship.
I think this is very much a trend we've seen in the last couple of months in the coverage we've had here on the, the rundown. We've talked about some of the deals around long-term electricity supply, building out new data centers and long-term supply of new GPUs. Of course, you always want the newest GPUs because they give you more performance for consuming less power.
And these kinds of deals are, are really vital for that continued supply. It should also mean that call Weavers even further at the front of the queue to get those new GPUs when they're first shipped. And meaning that call, weve can then sell more services to companies like Open AI to, to run their infrastructure.
So, uh, the general theme we're looking at in this close look is around that long-term commitments between the various partners, but with a little overtone of how many of these partners are actually making money. Because we talked earlier, open AI is on a track to make money. Well, not this year, not next year, not the year after.
Hmm. Cool. 3 billion will buy back.
What you don't sell doesn't seem like a big risk for Nvidia with the massive profitability they've had from these GPUs. Of course, another element in here is the neas group. 4 billion.
Uh, the Amsterdam based company will provide AI computing power from a New Jersey data center through 2031, and again using a video chips, uh, Microsoft, Hmm. Already working with Cool Weave is another investor. Uh, and the whole deal sort of fits together that Microsoft is using NE's cloud, uh, platform and Nvidia chips in here.
Uh, does it seem like it's gonna be hard to differentiate, differentiate yourself as a provider, uh, of these cloud platform, these cloud AI platforms? You know, honestly, I don't know the answer to that because they're all running the same stuff on the back end, right? They're all running Nvidia.
And so why would Microsoft want to use this other platform and Core Weave? Well, the only reason I can think of is they want, you know, diversity, they wanna make sure that a core weave outage or or weave acquisition doesn't cause problems for them. So I, you know, and you're basically funding this company to do this build out, which of course puts you at the front of the line when you need to, you know, increase capacity or something like that.
So I don't think it's a bad move on Microsoft's part. I think that they're investing smartly if they've got some money in a lot of different pots as opposed to kind of tripling down on using one like Core Weave. Uh, I don't think customers are gonna care one way or the other because one of the things that we've seen over the years is this idea of multi-cloud, right?
You know, we're, we're using things like cloud arbitrage to, to make it make sense financially. And, and I don't necessarily know that that's born out over the years. I think people just like the idea of saying that if we need to, we can cut and run to Azure over AWS And it's funny that AWS is kind of at the front of my thoughts there, because there's another company that was unprofitable seemingly forever.
Amazon couldn't make money to save its life until it started selling cloud computing, and then all of a sudden they were making money faster than they could figure out how to spend it. And I think that maybe that's the hope is that these companies, core Weave and MEUs are effectively riding the wave right now of what's hot in the hopes that they can hold on long enough to either make it, make money or find that thing that Amazon did that allowed them to start raking in the money as crazy as possible. I guess my next question is, can these companies hold out from being acquired long enough to make that happen?
Or do they need to hold out from being acquired? They need to be attractive to be acquired as an exit. But I think one of the things that we've been hearing a little bit is that this is still very much the early days of generative ai and the, the game will be played out over five or 10 years from now, not over one or two years.
And often our horizon is, is much shorter. Um, one of my delegates at our, our infrastructure field day last week was talking about as being like when, uh, PCs were brand new and everybody was buying up PCs with no particular plan of how they were gonna use them. And the predictions were that this PC bubble was gonna burst and everybody would be back on their mainframes for everything.
Many systems plays out. No, there's just, as you say, a little more innovation required before you get to the point. We needed, um, service systems to go with our, our desktops, um, that that suited the, the desktops use case and in particular, client server computing became the thing that made desktops really valuable to us.
I think that same idea of having some innovation, uh, some more artwork is, is still required. And that's why we're seeing so much change in the AI infrastructure and the AI models and AI applications. What this isn't done yet, this isn't even, uh, it might be the the end of the beginning, but it's definitely not even the, the middle, let alone the end here.
So we, even though we talk up a little bit, the feeling that this is a bit of a bubble, you know, was if if the actual natural growth in of value being delivered catches up with the spend, that would stop this being a bubble and make it actually a simple growth. And I think that brings us to the end of the, the news of the week. But of course there is more coming up in the following weeks.
Uh, say I had AI infrastructure Field day last week in Santa Clara. And Tom, when you are finished in New York, you also have travel next week. Yeah, you're right.
I'm gonna be right back out in Silicon Valley for Security Field Day. We have a wonderful lineup of companies, including new presenter, square X and One password, uh, and Alan Shimel from Security Boulevard and Textron TV is gonna be joining us as a delegate. You know, Alan's opinionated when it comes to security.
You wanna know exactly how opinionated, make sure you tune in. And then I'm gonna be right back again about a week and a half later because we're gonna be having a special exclusive event with Microsoft Security talking all about Microsoft Sentinel. That's gonna be happening on October the ninth.
I just got a look at the schedule. There's some really good conversations that are gonna be going on. You can join some of my closest security friends from around the globe as we listen in, ask questions and discuss all of the cool stuff going on.
And then the end of October, right before all of the Candy, you've got something sweet coming up, Al. I do. I have, it's a beautiful Tasty Cloud Field Day returning, uh, we have HPE Fortinet and Oxide computing presenting, and we a few more who'll be joining the roster as well to entertain and delight my delegates as well as you viewing.
That'll be October 22nd and 23rd. And right after that, the following week is AI Field Day, where Stephen Foster will be back in, uh, the, uh, Silicon Valley area October 29th and 30th with his own focus on what you can actually do with AI rather than the infrastructure, which was my focus. com.
And of course, if you missed any of the past events, tech Field Day YouTube channels, a great place to find all of the videos. Thanks for watching the Tech Field Day rundown. You can find new episodes every Wednesday as a YouTube video or on your favorite podcast application.
The Rundown is also streamed on text on tv, and you can often catch up with us on other text, strong or FU and group programs. We'll be back next Wednesday to talk about the IT news and the week that was. And then until then for myself, for Tom Hollingsworth and for all of us here at Tech Field Day, we're wishing you and yours an absolutely beautiful day.
Send me your pour your huddled masses and bring cash. You're watching Textron Gang. Hey everyone, happy Tuesday and welcome to our Tuesday Textron gang.
We've got a great lineup of topics and a better, even a better lineup of people for this wonderful Tuesday. Let me introduce you to our gang members. We have JP Morgenthal, Wiki Wang, Mitch Ashley, and the dean Mike Ard gang.
It was a bit of a crazy weekend. And Monday, um, it seems we have a new philosophy in the US com, a country that was built on immigrants and immigration. Anybody could come in as long as you have the money, right?
Uh, the H one B visas are now a hundred grand a year, but you could buy the Willy Wonka Golden Visa for a million bucks. My goodness, my goodness. But anyway, Mike, you, why don't you take this?
What what are we, what are we doing here? So, so here's the deal. So they announced Trump administration that it will cost you a hundred thousand dollars to get an H one B visa a year.
However, if you are already here under said program, that will be grandfathered in essentially, and you won't have to pay this particular fee. So it may wind up that a lot of folks will just wind up staying here for a long period of time. It was kind of a chaotic announcement.
The executive order went out and then everybody flipped out, and then there was clarifications as to what the president really meant to say the usual kind of thing. And these days in the Trump administration, it seems like. Um, but the other thing about this program, it's interesting, this move is getting praised by both the left and the right.
There are people who like this thing, the H one B Visa program itself has been controversial for as long as anybody remembers. Um, 70% of these visas go to folks from one country, primarily from India. And a lot of folks have said this whole program needed to be revamped, maybe tossed in favor of something else.
But, um, I feel like we're just kind of doing our usual heavy hammer approach to solving issues. Well, I think what we've got here is President Trump has, uh, said to his tech bro supporters, how do you like me now? Uh, because this is certainly a, a arrow in the heart to the tech world, right?
The tech world is probably the single biggest user of H one B visas and has been forever. Um, and for good reason. You know, I don't care if people are of Indian or Southeast Asian or Chinese or Singapore or Filipino or Eastern Europe or wherever they come from, if they have good talent and skills that helps keep this country preeminent in technology, we need to use them.
We, we should have a mechanism of bringing them in. You wanna attach money to it? A hundred thousand dollars a year, A year, that's $300,000 over the life of most of these H one B visas, Mike, are three years, I believe.
Mm-hmm. So even your point about the grandfather that did, I think it only counts for the rest of their, their three year term when they go to get a new one or renew it, they're on the a hundred grand a year system too. So let, let's say what this really is, this is eliminating the H one B visa as a means of bringing in skilled workers.
So we'll be able to get people who went to Utah for a half a semester, dropped out and went to electrical school and asked them to be the next ver generation of coders in this country. Because we don't have enough people who are taking those kind of skilled classes and training. We don't have enough STEM people.
And so what we're really doing here is we're taking what, what the Trump administration itself has set out to be the golden egg, our tech leadership, our tech preeminence and ai and quantum and cloud and everything else, and saying we are gonna cut off the pipeline of fresh blood, of new talent, of skilled workers coming in here. 'cause we want Americans in fly over stamp with a high school diploma to take these jobs. I don't think the jobs are going to come to the us.
I think most companies who are using these programs are just gonna Move out Back to where there those people are. So it'll just mean more the development work will move to India because they won't have as many people here working, you know, on the same time zone as somebody who, you know, normally it's somebody working for an outsourcing firm who's working for some, you know, enterprise company and they just wanted somebody in the same time zone. So they use these visas.
But, uh, you know, I think we'll just do more of this quote unquote globalization and just put the workload back to where those people are in the first place, which is probably gonna be somewhere in India. And that's antithesis to what the Trump administration wants, right? They're anti-global.
Is It, it, it, it does seem that they are ignorant to the impact long term, right? If you, this is an opportunity to build and build the knowledge here. And I, I don't think they fully understand or have thought through the impact to the programs and what's going to happen in the US Now, some will say that perhaps this is part of their underlying plan.
I I tend to feel that there is a potential for some chaotic, uh, uh, shift mm-hmm. In what they're trying to achieve much more isolationism again, uh, you know, like circa in 1940 before World War ii, we were very much in isolation. It was two Thirties.
Yeah. But we don't, and the problem is you have a 1940s run the country mentality in a 2000 era technology world. And So, so JP lemme just, it's not the forties.
The forties was already World War ii and it was Roosevelt. This is really the twenties leading to something called the stock market crash at 29, right? It's the tariff bills, the anti-immigration, the isolationism that all happened in the twenties.
And as a result, we had the Great Depression, right? By the forties, Roosevelt had already put 10 years of trying to build things back up here. And, and I'm sorry, I just No, no.
Wanted to correct you on there. But I, it's funny 'cause I always assume, I, I always associate isolationism with our desire not to enter the war until we were forced into it, right? Mm-hmm.
The, The problem is by that, by then we had so shrunk in our military and our industrial capacity that it took us years. I, I'll tell you, I'll tell you what I hated about this program. It was basically United States government, uh, coming up with a method that would enable companies to depress the salary levels of IT folks artificially, right?
Because now suddenly I had somebody else coming in from overseas who was gonna do a gig at a lower cost. And that might have been maybe good for the end customer if that got passed along to them or not, who knows? But it most certainly depressed the level of salary that could be commanded by other IT professionals in this country.
And that's not something the United States government should be involved in. I think That's been the big criticism of the program, I think historically. I don't know if that's still true.
Yeah, I you know what? India is not the cheapest place to its software engineers anymore. You might be better off going to Eastern Europe or the Philippines or Vietnam or, or something like that.
Um, Well, let's face it, a company's gonna have to really want somebody to pay that kind of money to bring them in per year, right? So does it bring in the elite of the elite or does it bring in the elite of the family treasure chest to bring you into the state? Probably some of both, but I think that's the main criticism that they're going after.
Um, but, but it begs the question of well, why do we even have one anyway? If that's really the purpose is to keep American jobs, keep American jobs. I'm not saying we should do this.
I'm just saying that's it's a bit of a, a counter. Yeah, I understand that's what you wanna do, but you're now creating an even greater class social system of people who can't afford, or companies who can't afford. So, you know, they're paying good money after, after that a hundred KA year or whatever million dollar the golden ticket is to get these people here.
I mean, to be, yeah, I'm sorry. I have something here, right? Because I'm the first, uh, generation immigration, and I was H one B holder.
Um, so I specifically checked this one, uh, when I first heard of it's, it's the Shock news, right? Um, it end up like this new, this rules only applying for the people who try to apply the H one B overseas. So people with in United States still keep the old rules, I think, but it do have some impact for the startup who has a shortage on the technology talent.
If you think back how, why we have H one B, right? There are class, class of workers like United States has shortage, they don't have enough people, so they offer this kind of feedback. But now if you increase application fee shortage is still shortage, I don't feel it will bring the, the job back to the United States.
But let's see, this, this my kind of bill, I I I don't, I don't disagree. To be clear, the million dollar golden ticket is not an H one B visa for a million bucks. They give you the, the full on, uh mm-hmm.
Full on Visa. I would, I would just say that, you know, compared to what some folks are commanding for AI salaries these days, a hundred grand is nothing. Well, that's a good point.
Yeah. For someone like that. Sure.
They're paying we way over that to get that kind of talent now. Yeah. Well I, but here, here's the bigger issue guys.
What it really is, is we hung a giant for sale sign on the Statue of Liberty, right? 'cause that's, that's America under this administration. Everything's for sale.
You want to give 50 grand to the Department of Homeland Security secretary and he'll get you some influence. Don't worry, they'll quash that. We're not gonna do that investigation.
You wanna find out what's going on with poverty and stuff? I'm very sorry we canceled that report. We'll let you know when we have something else out.
You want to know what the latest job numbers and everything is? Well, we'll, we'll let you know. It's not important.
You don't need to know. You want something, just write. You got your checkbook, pull it out and you're good.
You, you don't have a checkbook. How about buying some Trump coin, Bitcoin or crypto? And, and you can get your way there too.
You want to export some AI chips that are forbidden. Not a problem. By some more coin.
So before you get, this is what this, this is, this is a real problem Before you get too far on that particular soapbox, but there is one thing on this thing that is gonna be problematic. The administration has a tendency to come up with exceptions. And so somebody's gonna go down to Mar-a-Lago, hang out for a little bit, and suddenly there's gonna be a half price sale on Visa.
It's called Taco Tuesday here on the gang. I Do heard, though, before this all starts. Yeah.
So I mean, and like everything else, right? So when, so there was a time, and, and I'm talking as a government and politics major. Now, you can't rule by fiat, you can't rule by executive order.
There comes a time where the Congress has to, the legislature has to approve these things. Now I get it that they're all in La Goosestep with the fur. But, but when are we gonna have some congressional action on this?
Right? Thi this is, and, and one of the, I mean, the lower courts all will claim, Hey, you gotta, this is exceeding your power. You gotta go to Congress now.
You know, who knows what the Supreme Court will do? Well, we all know what the Supreme Court will do. They know they're just, you know, the latest, uh, kangaroos.
But it there, this is not the way we're supposed to. This government's supposed to work. I'm sorry.
The interesting thing about it too, Alan, is that it, with this, the outcomes are measurable, right? How many, how many, if we're not issuing those jobs or visas, how many people are we hiring overseas to stay overseas if we're not issuing those visas? How many people, how many people fill those jobs from the American side, from the US citizens side of the, of the equation?
Yeah, but let me, let me give you the, so that's the moderate response. Let me give you the extreme response. How many companies are made overseas in China, in France, in, in name the countries mm-hmm.
Who now say, Hey, don't bother with those crazy Americans in their a hundred thousand dollars visas. Come work for me. Come work for me.
We're doing exciting things. We're investing more in r and d. The rest of the world doesn't wanna play with them anyway.
They wanna, here you'll be able to play with the rest of the world. And before you know it, your preeminence in tech is, is up in smoke. I mean, we already see it with the, with the, uh, with the, uh, digital sovereignty Yeah.
Actions that companies are taking to All European companies. Yeah. Wrote an Article.
So she just signed a Euro stack, which is, you know, an agreement to create a European technology stack. And, uh, that's not, that's just one of many, right? Seuss just came out with a, a, an offering in it as well.
Mm-hmm. Um, you're gonna see more and more of this. Yeah, I totally agree with you.
Right? Um, I normally do not like to talk about politic part or I like tech, right? But it's kind of interesting.
You see all those series of way people treat like how to manage country, like how to manage p and l, right? I feel like those are totally different systems. Yeah, no, they, they really are.
Alright. Hey, I think we've made our point. Let's take a break here and come back and talk about, uh, what's Google doing with Chrome?
First? They were selling it. Now they're not selling it now.
Now what you're watching Techron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back. And as Alan was talking about, yeah, Google's now at least foreshadowing what they intend to do with AI and the Chrome browser.
And I guess maybe this is a little bit of an exercise in trying to freeze the market somewhat. Jp I mean, it seems to me like a lot of these features I looked at in here seem pretty cool, but it doesn't seem like they're gonna show up anytime soon. Well, I mean, they're already starting to show up.
I, I actually like the direction overall from an architecture. I think it's, uh, I think it's really, I think it's happening already, except people are now having to cut and paste in order to enable, uh, this kind of activity. So they will do a search, they'll find some additional information, then they probably will deep research it in a, uh, LLM uh, application.
And so all this is doing is saying, um, you know, let's integrate the two steps right into one activity, which is what I think people want. They want user experience. Now the question is, is because, you know, with Google Chrome is how long is it before, um, somebody steps up and, and says, you know, this is a monopolistic, uh, you need to open it up and make it pluggable.
I mean, we, this, I'm surprised they even didn't do that from the get go based upon what we learned from Microsoft and IE years ago, right? And it's like, do you really? Yeah.
Are you, are you really gonna force us to go to court and you're gonna get, you know, and waste, you know, hundreds of thousands if not millions of dollars on, uh, legally being told that, yeah, you need to open up the APIs so that open AI can plug in their LLM into this functionality, right? Or, or maybe we just end up with the browser wars again. Oh, you don't wanna let me in your door, fine, I'll create my own.
Because hey, chromium is free by the way. I, um, Microsoft's edge is already based on it, right? Uh, it's not difficult to take the chromium base and build your own browser.
So are we gonna see the Anthropic browser? Are we gonna see the open AI browser? So we either end up either, you know, Google gets sued, uh, and they get told naked an open api so everybody can plug users can make the choice what, uh, engine they wanna use as part of this functionality or, uh, ever.
Or we see ano a new browser war emerging because everyone's like, fine. If, if that's what Google's gonna do, then I'll just create my own chromium for my LLM. Uh, I, I, I think both are really, I, I would like to see the more open one, obviously, right?
Plug in the one that I like best. Um, perhaps even allow multiple, like, ooh, you know, for this particular search I would like to use sonnet. But for this other one I'd like to use Gemini and, uh, and have that option, right?
So that, um, I get different responses. I can see the alternatives, uh, and, and in, we all know that different LLMs respond differently anyway, so isn't that part of the, the research effort? I, I, I, but overall, I, let's take away the, um, politics, if you will, of the industry, right?
And, and, and the, uh, maneuvering and just look at what it is technologically, I think it, it, it's a phenomenal, you know, it makes the browser much more useful. Plus I think it starts to reduce the fears that people will have, that browsers are going away. Everything is gonna become LLM searches, right?
It's, you know, so it doesn't even matter anymore. We don't see search, we don't see the, the search returns anymore. Uh, it all gets analyzed by an LLM, and then you just see the results.
So this is a way of saying, no, you still gonna do search, but you're integrating in this intelligence to help expand and understand that information better. And I like that model. I like that.
I think that's a good model for the general user. So, jp, I, I agree and disagree. First of all, the courts today aren't what the courts were when Internet Explorer was kind of, you know, hogtied.
The only way a court is going to come down on Google and force them to do things on, on, uh, Chrome is if the suit's over in the eu. I, I, I agree with that. Yeah, that's number.
But, but that's where it's likely gonna happen, is, well, That's the only place that it'll have any teeth. But secondly here, here's how I see it. Google, Google gotta get outta jail free card with Chrome.
They got away with being a monopoly, but they're still allowed to keep Chrome. They may open some stuff up, great. But what they do see is that there is a new generation of browsers that are going to throw the cards in the air.
We'll see who the new winner is. You've got the perplexity one. OpenAI is coming out with one.
I'm sure the rest of 'em are, are not far behind. And so, you know, this was an arms race. Google had to go, had to up their game to compete with these up and coming, you know, new generation of browsers.
And if you are Google, what's your biggest ace in the, in the whole, that you are already the dominant browser, so you don't, you're not going to give that up, right? And so you're just going to kind of build powerly. No, you're gonna have pry it outta their cold, dead hands.
But, so they're going to, they're going to make Chrome an AI browser to compete with this next generation. Now, here's the thing I where I really disagree with you. This ain't about search.
This is not about search. I think AI search is gonna overtake Google search. It already is growing three and a half times faster.
I see it on our, uh, Google Analytics for all of our websites. Mm-hmm. Mm-hmm.
How much search is coming from AI and perplexity and so forth. What it really becomes is this AI browser becomes the new UX to do your work, not your search, your apps live in there, your work in there, it becomes the new desktop. And that's what Google, you know, you've got Google, the whole Google, what, what's the Google office called Mitch?
I forget workspace. But they've, we've already done that. It's already embedded in workspace.
It's already, Yes, it's, but workspace may not be the dominant workspace. If I've got a, let's say open AI comes out, or perplexity has a, a, an AI powered workspace that I think the way you think about it, Alan, I, I agree with what you're saying. We've talked about this, you and I, um, you know, Atlassian even bought a browser, the browser company, right?
Yeah. Atlassian. The anticipation of this, which is the expectation is that browsers shift from searching content on the internet to actually managing, directing, and consuming what AI does for you, right?
Whether you're managing the bots and the, the tasks and the things that are happening, what's going, what's going on across the different tabs on your browser. You're not switching between them, um, but doing searches for maybe doing tasks for you, all that kind of thing. But the application kind of providers, the people writing code see that this is a threat.
Because if Google now controls what you can present to the end user for their apps, then they lose, right? And they may not put in the functionality that an Atlassian or whoever else wants. And that's the thread about this, which is, do you want Google to win that war?
Do you want Microsoft to win that war? Do you want a perplexity to win that war? Mm-hmm.
So instead of SaaS, we have bass browser as a service. Where, where not your front end, Mike, go ahead. I think it's already happened.
I'm sitting here on Google Chrome as we record this, and I'm looking around all my little apps, and I think I can see this in Iny, tiny little Microsoft store icon somewhere on the lower left hand side. And that's about all I see of Microsoft on the screen right now. And I think the apps guys are gonna use browsers just to really park Microsoft as a backend, uh, client enabling technology.
And then, to your point, everything on the backend is just gonna wind up being a, a service, because I don't need a gooey to go access the CMS. It's all gonna come through the browser. I think it, it makes it much more difficult to determine, is pick your poison, pick a Google or Microsoft, whoever is the browser, the new new AI browser, is it favoring that provider's content?
'cause it's no longer the list and the order and what shows up in a search result, right? It it, it's the Gemini interface to start with. That's at least what it looks like today.
It'll look different over time, but I think it, it sort of obfuscates what's happening behind the scenes. Well, don't forget on the back end, there are now, um, like robots dot texts, which used to tell the browser what you can and can't take. There are now files that tell AI what you can and cannot take.
Uh, and this is a lot more, this is a lot more strict than the robots that text was, because actually it benefited people to have their content show up in a search. But they know that when AI is the middleman, that their content is often masked, and the source of that information is not necess, even if it is transparency may not even get recognized, right? Because the reader doesn't actually care where it came from so much as the content itself.
So people are going to be much more strict about what they allow these ai, you know, engines, the l lms, to go and see on their sites. And, and so I mean, the question, you know, go, if you go down that path, you end up with less content being able to, to actually fulfill the, the requests that are being made. I think about it this way too.
JP does pick a, pick a company, does Salesforce and Slack when Google to know what their bots, what their AI is doing within the browser workflow is all part of that. Yes, they can track some of that today with browsers, but not to the degree I think you could in the next generation AI with Mitch. So they're more comfortable with perplexity tracking it.
Well, Uh, maybe I'll Today until perplexity becomes a threat, well, At least my perplexity Guys Wiki had something to say earlier. I don't Know. Sorry, Wiki, I didn't mean to cut you off.
I totally agree with you guys, right? Like the BLO accurate is to agent as well, right? Because there are, I believe there are several three ways, like in filter, you can integrate with AI agent and make it to a gate for the AI agent.
And cloud is one of them. And that's what important company, they try to have the broader product so they can control the future of the AI agent as well. Mm-hmm.
So I'm a little, I'm concerned about the following scenario, right? So more and more AI slop gets created using Gemini, and then Gemini starts to rank that stuff higher because, well, Gemini created it, so therefore Gemini must think it's okay. And then at the end of the day, we wind up with this, you know, unvirtuous cycle of slop that's popping up in there.
Well, And that's all part of the balkanization of the internet, right? Because then Croatia is better than Serbia, which is better than Montenegro, which is better than Kosovo. I forgot all my little parts of Yugoslavia.
But, um, you know, thi this is what happens is when you go to Google Land, or may maybe a better analogy is, uh, water, the rinks, when you go to Google Land, Google search rules. But when you are on perplexity, you have a different algorithm for searches. Forget algorithm, you have a different favorite for searches and open AI and, and everyone else has it.
So it's, um, I want, I want jps thing, but I want, like, maybe if I can figure out how to do it, I'd like to have two or three of them go in at the same time so I could see what they were generating and compare. Well, but you know, this reminds me of, was it Einstein? Is is, was it Salesforce was doing Einstein?
Mm-hmm. Where you could plug like any LLM into the back end of it? Mm-hmm.
Yeah. Cover broker for the LLMs. Yeah.
Right. Maybe, maybe that, and maybe if these guys don't play nice, some new company we don't know of yet comes out with an open chromium based browser that does have sort of an Einstein layer and, and people who, who care about these things go out and, and adopt that. Or there's a memo from the EU on its way Yeah.
On the investment side as well. I see a lot of great startups recent come up in this area. Yeah.
Very interesting. Yeah, Absolutely. All right, let's take a break.
We're going to come back here and talk about our C Block data center court bottles, the NIMBYs Hire Lawyers, and now the, the Empire Strikes Back. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com. Home of security bloggers network.
All right. This may come as a surprise to you, but there are lawsuits being generated now around all these data center projects. And there's one in Michigan that's kind of interesting because the people who are proposing to build a data center are now suing the township that passed some, uh, a vote, essentially among their leadership of the council that said that they could not zone this area to run data centers.
And now it's gonna become a, a court battle, I guess, for as long as we can go. And Alan, you know, and I'll go to Mitch on this first, but I'll come back to you in a minute for your legal opinion, but Mitch, are we gonna see more and more of these things? And I am reminded of, in my own town, some developer built a house that was far exceeded the, uh, zoning laws, and then they built it anyway, and then they dared the town to sue them, and the town didn't have a whole lot of money.
So that house still sits there. Well, I can kind of relate to this one. Maybe that's why you're coming to me as the Nebraska boy.
Do I want, uh, you know, that nice green farmland right behind my house or behind my, if I live out in the country, do I want that overtaken by a data center? And that's essentially what the case is here in, in, in Saline, Michigan. You're welcome to the, to the Textron gang.
We're talking about you folks. The, the, the claiming, the the data center building, uh, builder related digital is claiming that the, the council did something illegal in changing the zoning laws. Us not letting them build their, their, uh, 250 acre plushy plus hyperscaler data center.
Not the first, not the first lawsuit. We're gonna see about this. There's a lot of legal lawyer legals gonna get being paid to do these kinda lawsuits, I think.
And, and we'll see, the problem is, you're, you're talking about local jurisdiction, local rules. This is, isn't just some, you know, national, uh, uh, threat or national lawsuit, excuse me. Um, that you can kind of say, well, if it worked there, we can go after and do the same thing in all these other locations.
No, they all have their own laws and jurisdictions and rules and councils and all that kind of thing. So that sounds kinda like a big mess to me. Yeah, I mean, well, you know, Mike, you asked for a legal opinion.
Look, towns are free to make zoning their own zoning laws. And, and there's nothing more local than zoning, right? You don't have federal zoning laws.
Well hub a hub zone or something like that, a economic development zone. But, you know, building zoning laws are really the epitome of, of local ruling. However, my only point is, and I don't know enough about this case enough, is this a, an ex post facto law, or another words, did they, did they enact the law after everything was all set and approved and done, and then kind of pulled the rug out from under up, right?
That, that you, that will not stand you, you can't go ex expose facto on this, right? You can't say today you can do it, and then you rely on that and spend money and do everything and then say, oh, changed our mind jk, right? And we changed our mind.
So absent of that, I, I think you're gonna see a lot of towns doing this. I mean, who wants a Manhattan sized data center in, in, in the middle of your greenfield? Um, and, and you know, I, again, I, I have, I've written a few articles, some might still be in the queue on this for tech strung it, but you know, this data center, boom, it's, it's driving up our electric rates.
You and I and everyone out here are paying more money in electricity because the utilities have to increase their bad, their capacity to, to, you know, pay to, to light up these data centers. Um, a a liquid water cooled data center uses like, something like can use up to 2 million gallons a day of water, right? So if you're in a water challenged area, you've, you've got that.
Like, and, and Phoenix wants to be the head of, you know, the big data center capital. Where do they have the water for this? So you are going to see local townships and local legislatures and local governments say, Hey, it's not worth it.
It's not worth, it doesn't create that many jobs. It's, it would, we were sold the bill of goods, it's not worth it, and they're gonna try to change things. Is this the right way?
By doing it as a zoning thing after the fact, if it was after the fact, I don't know. I did check different terms, Will have different reactions, though. El Paso last week just approved the data center project on narrowly, but If you were in El Paso, you would too.
I did check. And they, uh, this, this, this part of the country, this township or whatever, had, did have a master plan. This area was apparently designated as as agriculture.
Oh, okay. Agricultural. Now, I don't know, I didn't quite see how a data center is agricultural.
Um, but of course, is it an industrial, is that the kind of zoning you need to do? I think what's gonna happen is that we'll see townships, et cetera, explicitly stating whether data centers can be built. So there's either black and white, you can or can't do it, or if you could do it, but you could do it over these areas.
Otherwise, now you're talking about, you know, interpretation of the law and all, you know, kind of, right? So Data, data centers are gonna have a particular zoning designation, not just industrial car, not agricultural, not residential, not retail data center, right? Mm-hmm.
Will be a thing. But let me, let me throw something else out at you guys to just ponder and chew on. Historically with these kinds of things.
You know, what happens? Well, off people don't have data centers in their developments or in their neighborhoods or in their areas. And let's put the data center in, in those people's neighborhoods.
They don't have souls anyway to quote the Godfather, right? And so you're gonna have data centers, if you see a data center, you're gonna say to yourself, Ooh, must be a low income neighborhood, because they didn't have the wherewithal to keep it outta here. And so it glows at night or, or whatever.
So, you know, jp, you're smiling. We grew up in that. Oh, I, no, because I mean, two of the biggest data center, one of the biggest data center areas with two huge facilities is Ashburn, Virginia, Northern Virginia, which is a well to do area Very well to do a lot of money.
Yeah. And, uh, I mean, what they did was they stuck them right on the side of a highway. And, um, you know, they're out of the way.
They're really not part of the neighborhood, but, you know, they're accessible. Um, and they're, you know, where, I mean, if anything, they probably keeping volume of traffic, you know, sound, uh, down because they're, it's filtering off of the highway there. Um, and it's not letting it come out onto the street.
I mean, it, it, it's agriculturally or ecologically. It's, it's a good mix, right? It where they located it, but it's also, it's not indicative of a low income at all.
The fact That, that it's there. No, but that's a different data center to be hon to be honest, right? You're talking about the, like, when I helped do inter reliant, we had a data center in Tyson's Corner.
It was the old a ll headquarters, and it was just what you're saying, it was a nondescript brick building right off the highway. And I forget how many, if we had 20,000, 30,000 square feet of data center space there, something like that. It was a nice size little data center.
Wasn't the biggest, wasn't the smallest. That's not these AI factories that we're talking about, though. These AI factories that they're building are literally the size of Manhattan, and it's awful hard to hide, you know, behind some green curtain or something.
And the environmental impacts a lot bigger. This is today's the, the 2025 version of the high power megawatt overhead power lines, right? Do I want those running through my neighborhood?
Do we want now, do we want a data center at the end of those? Yeah. So do you think these are always gonna be in rural places, or will they like try to build a data center in, I don't know, some part of the Bronx where they just wanna level everything and they're just gonna use it as an excuse?
Mike? I would never, I would never suggest that they do anything bad to the Bronx, you know, that. But, but think about it, building it in a rural area in Nebraska, to Mitch's point, not only do I gotta bring the, the electricity there, the cooling there, the bandwidth there, whatever few jobs it brings, I gotta have bring the people there, right?
That's a lot of theirs. Versus if I built it, you know, in a somewhat more suburban, urban area, we Good with you. Jump in there.
No, I totally get it. Why people try to build up the data center on the ocean, right? And last year I saw there's like, uh, startup, they try to build up the data center, something under the, under the ocean within the, within the water.
Now I totally get it. Yeah. Well that would, There's actually, there's actually a lot of good e evidence that that is a smart direction.
One, you get you, they use the waves, uh, for energy. Yep. They use the, the temperature to keep the cooling.
Yeah. So a lot of, a lot of what you need to run a data center is free when you go down a certain depth into the, into the water, into the, a large body of the water, and There's no, no lawsuit, right? I guess, Yes, somebody will sue somebody, for sure.
However, I would also point out that, you know, as soon as we figure out that we don't need all these data centers, it'll be great for the coral. So there you go. There you go.
That can become artificial reefs. That's Yeah. Artificial place to live.
Yeah. Okay. Dual, uh, that they call that a dual use in the business.
But, um, anyway, guys, we're about outta time. What a, some interesting, some interesting topics to discuss here today. I, I enjoyed it.
I hope you did. I hope all of you did as well. Hey, listen, uh, today is Tuesday and we, we actually recorded this a day early, but I wanna say happy Rosh Hashanah to my, my, uh, Landsman and all those who celebrate.
I also want to remind you that this week we are going to be live on Tech Shrunk TV for a tech field day, uh, cyber Security Tech Field Day. And I believe that plays on, uh, is it Tuesday and Wednesday or Wednesday and Thursday, Mitch? Something That I don't know, but, but it's two days.
I would say you two days this week. Yeah, I would guess Wednesday, Thursday. But I'll, we'll double check.
We'll post it. So do, do follow along with that, of course, we will have gang episodes. Mike Ard will be running the show.
And, uh, and of course we have Techstrong TV immediately following as usual. com, cloud native now, or digital CXO or the Futurum group as well. I know, Mitch, you've got a lot going on there, jp.
I see you time to time on LinkedIn publishing lately. Yes. Uh, it happens to be probably my biggest source, uh, is publishing on LinkedIn.
It just, you know, you, you spread the content out in too many different places. It's, it's difficult to, uh, to get, uh, the attention you want. So yeah, LinkedIn's become a primary source, and then I just link to that elsewhere.
Excellent. All Right, Alan, the, uh, tech Field Day, or security field day is Wednesday, Thursday. It is Wednesday, Thursday, yeah.
And the companies are folks like One Password, HPE info blocks, Nile Square X, some great, great companies to, so it'd be very interesting. Stay tuned. Absolutely.
So check, check that out. Alright. Hey, everyone.
Wiki, jp, Mike. Mitch, thanks for joining. Thank you for watching.
This is Alan Shimmel. We're out. Hey, everyone.
We're back here at the, uh, TechOne Studios. You know, for those of you who know me, I, I always still get a thrill out of people locally being able to come into studio and do interviews with us. You know, 98% of what we do is remote, but every once in a while we get someone who actually lives down here in South Florida.
And that's the case here. I want to introduce you to Rebecca Kroener. That's right.
At nette. Yeah, exactly. Okay.
Exactly right. Rebecca is the, uh, CEO of a company called Q Secure, that's Q-U-S-E-C-U-R-E. com.
Um, I had the pleasure of meeting Rebecca's dad. Long story Jewish dad, proud of his daughter. She's the greatest thing in the world.
Wait till you meet her. Um, but all getting aside, I met her dad, Dave, who he is the chief commercial officer, chief revenue Officer, or chief of some things field, CTO Field, CTO, field, CTO. Um, but he, at one point was the CEO when it first started, or they He was, yeah, we started it together.
Yep. Yep. And, um, that was at Black Hat in Las Vegas, oh, about a month ago now.
And that is on Text Drunk tv. So if you wanna find out more about Q Secure, check out my interview with Rebecca's dad, David. And then, of course, just a couple weeks ago, we had the pleasure of my friend Jennifer Gio is now a, I forget her title with you guys too, but she's basically running, She's running marketing, marketing and revenue operations Yeah.
And revenue. Yep. Um, she's also joined, and of course, Jennifer's somewhat, I know for 20 something years, and she's a rock star, so it's quite, quite a, a collection.
But, you know, I remembered after interviewing your dad, going to the website, Rebecca, and looking at the, like the board of advisors and the people affiliated with Q Secure, and you've, you've collected quite a, a collection of distinguished folks in the, in the, uh, quantum space that are involved here. So congratulations on Thank You. Thank you.
But you know, it starts at the top. You're the CEO. So why don't we start with this, if you wouldn't mind, give people a sense of how did you wind up being the CEO of a quantum company working with your dad?
It's a good question. Um, well, thank you, Alan. Uh, I work with my dad, but Jen calls you family and Jen's a rock star now.
She's part of our family. So I think we're all, we're all family. Yeah.
Yeah. Now we're all part of the, the big Jewish Six degrees of separation in the quantum world. We are.
And we aret, but go, there You go. There you go. So, uh, yeah, uh, how did I end up working at a quantum security company with my dad?
So, long story short, I, I learned so much from him growing up, and, uh, yeah, he was always very entrepreneurial. So when I was seven years old, I had set up shop outside of my elementary school and was selling little beaded bracelets and things, and Yeah. First, uh, first business, right?
Mm-hmm. But I ended up studying symbolic systems at Stanford, which is kind of this ai, how do you build a thinking thing with a computer? Mm-hmm.
And so I was working for a while in actually building AI solutions for companies. I was the hired gun. And to make the long short, you, when you're an AI practitioner, you get to this point where you are, you wanna achieve all of those sci-fi dreams.
You wanna build a perfect model that could predict the stock market or X, Y, Z. And the reality is that you can't, because there's too many dependencies, too many things you have to take into account that influence, for example, the, the, the price of a stock. And so I hit that point when I was, when I was working in AI and enter quantum computing, enter this idea of not a bigger, better, faster computer, but a computer that can help make some of these problems that are really, really hard to figure out because they're so complex, a lot more simple.
So my dad and I have always been, you know, we take vacations and talk about these big ideas. How can we, how can we, uh, you know, make the world a better place? And quantum became a thing we started talking about.
So we started this, this company together that was working on quantum algorithms. And this was just before COVID. And we, uh, what happened was we got an initial grant from the US Air Force to start looking at, in addition to these quantum algorithms, the flip side, one of the things that quantum computers will be able to do is break the, uh, Traditional, Traditional encryption.
That's exactly right. So within that, I was the CEO of this company that was working on quantum algorithms. He then spun out this company working on the security side, and then pulled me over to be the first VP of engineering.
So I was running the product technology side. Here we are now five years later. And, uh, we've, we've built Q Secure into the, the world's first and leading platform in addressing this migration to quantum safe cybersecurity.
And yeah, last October, he, he passed the baton. I went from running the technology side to running Q Secure. And, and yeah, it's, it's a really exciting time for the company.
It's an exciting time for, for me and learning a lot, still learning a lot from my dad. And it's a, it's a total blessing to, to work with Him. I, I can only wish, well, you know, so I'm closer to your dad's age than your age.
Obviously your dad and I are about the same age, actually, we discussed this, but, um, I will tell you the idea of being able to work with your child and see them kind of fly. Yeah. Is, is every parent's dream?
It's some, well, maybe not every parent, but it certainly makes a parent proud. Um, I wanna go back to the AI thing a little bit. 'cause this is something we've discussed.
You know, this studio we're in right here. I do Textron Gang in every day with a bunch of people. And, and one of the things we've discussed is have we reached maximum ai, or in other words, our ability for our large language modules and just the whole state of it to continue to grow at the pace it's grown.
Because I mean, we've scraped the internet dry. You can talk about synthetic data, you know, and, and Jensen Wang and the, and the, you know, the Nvidia people come out with a new generation of processors twice a year or whatever. But the core kind of problems that we really wanna solve, climate change, maybe protein folding, like really The tough stuff.
The real tough stuff. Yeah. As good as we can get with ai, do we hit sort of physical limits of, of how much data there is to make the LLM so good of the processing power of the energy to power those processors of the cooling of the bandwidth that, you know, just, I mean, it seems like we're taxing the whole system to the max When technology, it, it doesn't, you've seen, you've seen it, right?
We've all seen it. We, it, it doesn't grow in a linear way. No.
It, it goes like this. Right? And what we saw with, with LLMs really changing the game for ai, it was one of those hockey stick.
It was one of those hockey stick moments. Yeah. And what you're asking is, are we still on that hockey stick for LLMs or are we not?
Right? Mm-hmm. And I think we're probably somewhere around here.
There's, there's probably more that we can do, but when we think about Right, those, those big problems, one of the things that got me so excited about quantum computing is with classical processing, which, which LLMs are ultimately doing at a certain point, you can't take in more variables and combine them in an optimal and timely time efficient way to come up with answers to some of these problems. Probably like protein folding and, um, and, and global warming. For example, there's one problem that quantum in theory can solve for, for global warming.
And it's, uh, it's called the Haber Bosch problem. And it's some basically this, this process that accounts for two or 3% of, of global emissions, you could, in theory, use a quantum computer to, to solve this equation that, that can minimize that really that challenge. Right?
So, and you can't do that on a regular computer, even with some of the most advanced ai, the question of whether we're, we're plateauing is a good one. Fundamentally, you can keep using AI to estimate and approximate and do all these things, but some of these problems are just really, really, really outta reach for mm-hmm. For, uh, for regular computers.
Excellent. We're gonna do a part two of this interview, Becca, where we we're gonna get into sort of what everyone needs to know about Quantum, but I wanna focus this part one though. Want Q secure.
So, look, when I, I first became aware of, let's call it post quantum algorithms, I guess is the term that gets pushed around a lot, uh, talking to some of the digital certificate providers, digic mm-hmm. Mm-hmm. Those folks.
And they introduced me to some folks at, uh, mire and nist. Mm-hmm. And you know, and I became aware that, hey, on Q day, and we will get into what Q Day is on the part two, but on the day when con quantum computing becomes real mm-hmm.
Not that it's not real now, but it becomes widely available. All of our RSA encryption and HTML, you know, SSL encryption is toast toast, you know, because what would take the bad guys hundreds of years, a quantum computer will do in minutes maybe. Mm-hmm.
Um, and so this has given rise to this whole, it's really almost post quantum security. So how do we secure stuff that quantum computer quantum computing renders easily breakable, for lack of a better way? I guess that's a good way of describing it.
So talk to us about Q Secure and how it, how it helps us survive. Q Day. Everything you said is spot on.
So the, as data travels over networks S-S-L-T-L-S mm-hmm. Uh, it's, it's effectively using one type of, of math problem encryption that is vulnerable to a sufficiently powerful quantum computer. And we're not just worried about when QA comes, we're also worried about the, the data harvesting and stockpiling that's happening very actively right now to, to sit on that data for when it can be decrypted.
And some of that will be still be very valuable when it is decrypted, if it's harvested today. My bank account information, my electronic health records, national security, all these things have harvested today are probably still relevant in the next several years. So the question is how do we, how do we make this better?
The, the good news is we know the big bad, we also know the solution. There's a set of algorithms that are written for regular computers to run. So you don't need a quantum computer to fight a quantum computer set of algorithms that as of last year missed.
Right. Standardized. And now it is a, it's really just a matter of organizations, private and government adopting these algorithms you pointed to, uh, digital certificate companies.
And one of the biggest challenges with adopting these quantum safe algorithms is that it's just very decentralized right now, the way that we've built up mm-hmm. Um, uh, PKI and, and our current infrastructure. So an organization is sitting there saying, what, what do I do?
What do I do to actually take control of this and make sure that I migrate the things that matter to quantum safe algorithms sooner than later? Do I have to rely on my vendors? Do I have to you?
How, where do sorts come in? Where do mm-hmm. So what Key Secure does is, uh, and we started working with, with the government to sort of achieve those, those highest level of, of compliance and, and working with the most sensitive stuff.
And now we work a lot with banks, we work a lot with telecommunications companies. We work a lot with oil and gas, these critical infrastructure companies to actually centralize and take control, not just of, um, certificates and, and the traditional stuff, but actually centralize the management and deployment across your network of these algorithms. And so we, we have a platform that takes stock, discovers all the encryption going across your network, allows that to be the springboard to migrate to these post quantum cryptographic algorithms.
3 to be ready to adopt post Quantum, but it's Right. It's addressing that cryptographic debt and then reporting on it. So making it, um, simpler and faster, and in most cases, a lot more affordable for these organizations to, to, to take on this migration or whatever encryption, migration they're getting their hands on.
So it's the first time I've heard the term cryptographic debt, crypto debt. Well, maybe when they're talking about bitcoins and stuff. But I mean, in, in this, in this meeting, um, you know, I remember thinking last year when these new algorithms came out, wow, we're finally out ahead.
Well, for what? Right. Because it's rare insecurity we're out ahead.
Um, but, but the fact is, listening to you talk, and, and you know what I'm thinking? There are still organizations out here that are running like Windows Me. Yep.
Windows 95 and Yep. Yep. You know, yes.
The smarter people are gonna jump on this user company like Q Secure. 'cause you can't defend what you don't know you have. Right.
So they're going to use Q Secure, they're gonna find out what their exposure is, where their exposure is. Mm-hmm. And then do what they need to do to quantum proof it.
Right. If that's a word, quantum proof it. Right.
Um, but they're gonna be the laggards who are still running Windows 95. Right. Who refuse to kinda get with the program until, and then they're the first ones who scream bloody murder when they're a victim.
Right. Of a hack or something of. Right.
It's terrible. Um, that's gotta be part of your mission accused secure, making sure everyone's aware Yeah. They gotta do this.
I mean, and look, in the security world, we self fud. Right. Fear, uncertainty and doubt.
I'm not saying you should do that. Right. I, I had friends who used to, you know, they'd go up to the CEO and say, well, the board and say, if you don't do this, you're gonna wind up in prison stripes.
Right. Because you gotta, this is real important. Mm-hmm.
Mm-hmm. How do you view Q secure's mission and make sure everyone's aware of what they need to do now to get out in front of this train? Yeah.
Again, a great question and one that we think about every day, but I also, look, look, uh, we think two years is a long time. And then two years from now, we'll look back and say, that went so fast. And one of the first things that we figured out working with our first, our first partner, first customer was the Air Force.
We have to meet organizations where they're at. And some of 'em, yeah. Windows 95 or Internet Explorer.
Mm-hmm. And so what we built in is, is fundamentally we're not asking any rip and replace. Like a lot of, a lot of past migrations, they'll, people are familiar with this, you gotta go find everything and you gotta rip and replace.
That's not what we're asking this time. Overlay legacy systems all the way to the most modern systems. That's what we, that's one of our sort of big things that we offer to organizations.
Right. We get, we, uh, a big organization just came to us, said, Hey, we've got 2,500 in-house applications. 2 to 1 0 3.
We know it's a prereq to be quantum ready. Uh, help because we're gonna have to rewrite all this stuff, or we're gonna have to, they were literally quoted close to a hundred million dollars to, to do these migrates, which is absurd. Yeah, yeah.
And many years, right? So that's a perfect use case for us to go and say, well, give us, give us a shot. Um, it'll be much faster, much cheaper.
And you don't have to worry about ripping out everything that you've invested in. Right. Because yeah, we can, we can try to come up with the perfect solution, but at the end of the day, people have invested millions and millions in their infrastructure, they're not gonna move off it.
So that's, that's one answer, right. We gotta meet people where they're at. The second answer is, there are certain organizations that are gonna prioritize it first and be a leaders.
And that's, that's government, that is finance, that is telecommunications and critical infrastructure. And there are a lot that are gonna fall behind. And one of the forcing functions that's coming up at the end of next year, which sounds to some like a long time, but it's just 15 months away.
Mm-hmm. There can be no new acquisitions into national security in the US that do not support post quantum cryptography in 15 months. Yeah.
0 now mandated by the end of 2026, organizations that plan to sell new technology, international security, have to support post quantum. So that's gonna be a, a wake up call for a lot of people. Yeah.
Well That, that'll also be the, the beacon. Right, right. The, if you're not with it, you're out.
Um, of course, if they don't postpone it or delay it, or as sometimes happens with these things. Mm-hmm. Um, so a lot of this is US based, but you know, we see in security the EU seems, the EU seems to have more of a political will to get things like this done mm-hmm.
Than we do here. What about any post quantum requirements or post con, to be clear, post quantum cryptography requirements coming outta the eu? There are, so earlier this year, March and April, we saw across the world a lot of government level timelines being introduced.
And so the EU released theirs. The UK released theirs, Australia released theirs as well. And it's these, these staged migrations for usually starting with government when everything has to be first, when new acquisitions have to be compliant, second when everything that they own has to be compliant.
And then, you know, filtering down to, to highly regulated industries and so on and so forth. Australia, for example, has come out and said, Hey, everything has to be post quantum by 23. Wow.
You got five years go. Um, so it's, it's, uh, generally what we're seeing is by 2030, at least, the most high sensitivity systems have to be migrated. And that's not just the us that is around the world.
Around the world, around the world, and a lot of, a lot of organ or a lot of countries are following nist, the NIST standards, the US NIST standards in adopting those. Hmm. Interesting.
Um, you know, we, we look at, I wanna come back to you and your background here. How does ai, 'cause a lot of people think AI and quantum together Oh boy. Trouble squared.
Yes. Right. Um, but how is, how is AI helping us in this post quantum crypto kind of scenarios?
Well, there's, there's the flip side. So what we talk about is we've, the last several decades we've seen one encryption migration after another. It's because encryption is not meant to last forever.
Mm-hmm. It's a cat and mouse game like any other part of security. So the, on the threat side, we talk about the, the, the post quantum cryptography, migration as a catalyst for changing how we manage encryption, that centralization of control, putting control into an organization's hands, not just because of qu but not just because of quantum.
It's whatever comes next. And whether it's AI getting more intelligent in its threats to, to encryption, whether it's quantum, we find new quantum algorithms after this one, that's also a threat. You need to be much more agile in how you manage encryption, because we can't take three to seven years to migrate.
Every time something gets broken, you need to be able to push a button and fix it. So we need to get, just as agile as AI is, is becoming. So I guess the answer is it's forcing us to be more intelligent on, on the defense side for one thing, uh, which is good, which is overall good from a, how is it helping in the defense?
There's a whole world of, of capabilities, right? We look at using AI for understanding how, uh, different inventories you end up with all, sometimes all these spreadsheets of here's where my crypto lives. And so making sense of that data for automating migration is, is a really interesting field.
And then also identifying these threats and giving policy recommendations for how you, how you update and you manage your encryption is, is another interesting one. Absolutely. You know, we we're running a little low on time, but I had something, one other topic I wanted to hit.
You mentioned earlier about, you know, the bad guys and say hello to the bad guys, right? Whatever flavor of bad guy you're looking at today. But they're all sort of tar balling, right?
Stolen payloads that are hashed or encrypted waiting for the day when they can turn the quantum beast, the quantum dogs loose on them to un unencrypted, whether it's your bank account information, health records, national security, what have you. Mm-hmm. Uh, wanna make sure people realize that what a big issue this is now, it's funny, it's almost like a radioactive decay.
The longer though you're holding that information, the over time the more it decays and becomes useless or less, less valuable. Um, but what, and is there anything we could do around that? I mean, kind of the horse is outta the barn already, but Yeah, I, i, radioactive decay is a, is a good way to look at it.
I saw a talk by the now former CTO of the CIA and he, he looked at everybody in the audience and he said at some point when QA comes, everybody here is gonna have their own WikiLeaks moment. And it's worth thinking about that whether you run a business or you use any kind of digital communication. I have a post quantum enabled VPN on my phone.
Really? Yeah, I do. Uh, 'cause I think about that.
I think about my data, well being, Being the CEO of qq. I would, if that anyone was gonna have it back around, I would expect it to be you. Right.
Right, right. And we, we eat our own dog food. We use our protections internally as well.
And so, uh, the one thing too I wanna make sure to get across is a lot of, there's so much jargon in this, and boards, boards know at this point generally that this is something they have to address. But it's one where you can get caught up in, well, what do I do? I'm gonna bring in some different partners and, and vendors and think about this and maybe spend a couple years on strategy and a couple million dollars here and there to figure it out.
And it's not that complicated. No, it's really not. And I, I almost think about it like the the bad guy, the bad actor wants organizations to get stuck in the, in the spin cycle rather than fixing fix it up.
Right. So yeah, that's, that's my kind of word to, the word to everybody is don't over complicate it. Hey, I just wanna double check.
So as part of the product line you get, you offer a quantum proof, uh, VPN or that's a commercial offering? That's A commercial offer. We, we offer an enterprise VPN.
Really? Mm-hmm. That's quantum proof.
That's quantum proof. Yeah. Very cool.
Yeah. Already out there. Alright.
com. Go check it out. You can ask Rebecca or anything.
I think that Dave gave his contact on his video and we'll link to that video in the notes here. Um, but, but go check out Q Secure. We're gonna come back.
There's gonna be a part two here. It's every man's quantum. So if you're not sure what quantum is and what, or you think you know, but you're not sure, stay tuned for part two.
Hey guys, thanks for the throw. We're here with George Pritchett, who's the vice president of products for ops swat and we're talking about a new report that they have that shows that there's a lot of malicious insider activity involving files and it seems to be getting worse. George, welcome to show.
Hello Mike. Hello everyone. Thanks much for having me.
Alright, Walk us through the report a little bit, but uh, insider threats have always been an issue, but is it getting worse or better? And um, what is the fundamental issue with these files? Sure.
So maybe we'll break the conversation like three different parts, but to start with like malware's oil's been a problem. I don't think that's, I dunno ever gonna go away. It's always like a cat and mouse activity.
Whatever new measures you put in place, there's new ways to um, evade the existing ways or there are new ways to get, uh, into the organization, especially like with the consumption of new applications, AI and so on, so forth. And we'll talk ai, it's a huge new world as well to discuss with and when it comes to like the risk on the employee side and so on, um, there's a lot more, again, being inside, um, risk or not. Um, I think the important part is that there's a huge diversity, right?
Like regardless how well you're training your organization, you have a very dispersed technology stack that's trying to solve the same problem for each of your entry points, right? So you have a very different thing for from email to web traffic to file transfers to collaboration tools to success versus OnPrem and so on and so forth. You don't have a unique way of handing those things.
You have don't have a very easy way to manage across the board enterprise wide. And so, and the idea of a defense in depth is, uh, implemented or some level is with zero trust and so on, uh, technologies. But at the same time, there are a lot of workloads these days that never touch even an end user.
They actually go into application, application and then you actually end up being hack because you are relying on the endpoint security product to kick in and do its uh, job and contain the risk and so on and so forth. And when it comes to the AI part, and I think this is the part that's getting more interesting and we've seen that in the report as well, there's a lot of adoption. Everybody's trying to adopt ai.
There's a lot of push for like adopting AI four or five security as well. But it's only like 25% actually have like a formal process on how they can handle ai. And 29% are actually banning gen AI as part of the organization.
So it, they're like exactly the opposite sides or like, um, less than a third are restricting access to ai but the quarter only have like a formal process out of the 70% that actually are allowing gene AI usage and so on. So then the risk becomes a lot more work. People are empowered to use Gene AI to like simplify their work, right?
I can, I easily have a copilot or like have an integration for my email with the like of open AI Gemini like JGPT and so on and so forth, right? But at the same time they're sending the data and the emails they might be like find them uploading to generate a report or representation for me and so on and so forth. And that increases the risk a lot more.
So it's a matter of like you are empowering, you give new tools to the organization, what is the risk associated with that one and how efficient are the guards that are putting in place on that? And I think the most important part I saw like a very good um, presentation a while ago where there was an entire revolution for cloud, the entire revolution for mobile and so on. The AI is the first one that nobody's pushing back.
Almost like everybody on the border organization is saying you need to adopt to adopt, right? But at the same time there there's a speed of the business that needs to be allowed to grow fast on the AI side and security is trying to find measures to contain the risk there because people are starting uploading even sensitive documents and so on. Um, through this.
Um, again, chat bots and um, I dunno, AI tools and so on. Mm-hmm. Hopefully that makes sense.
So coming back for a minute, these insider threats, are they actually malicious people who are going out to do something or is it just more accidental because people are not aware and as a result, uh, you know, we don't go looking for that as aggressively as we might, but maybe the bigger issue is the fact that well people are people and they're just gonna do stuff that's the path of least resistance, right? Uh, sure. So it's a mix of both, right?
Like I, I think we've all seen in the news in the last six, 12 months if no longer with like, uh, remote employees that are US based, but they're actually more North Koreans and so on and like how they're bypassing some um, employment background checks and so on so forth, right? So there are some of those cases like cyber espionage and things like that, but I think a lot of them are, I don't want to call it ignorance, but it's actually trying to work faster, easier, better. And they don't realize they're actually exposing company to a risk, right?
So I want to say that a big chunk of them, I want to give them the benefit of a doubt, but yes, there are some inside traders as uh, sorry, inside risk as well where people have a malicious intent from the beginning. You talked about AI and how do I strike a balance there? 'cause I think we uh, do want people to use AI but we want it to be done responsibly.
And I think the issue is that sometimes they're not thinking through the sensitive information that might be in a file. They're just kind of uploading stuff to get some help from AI to help them write an email or whatever it may be. But um, is there a way to think about that smarter and maybe make sure that sensitive data isn't going out to the AI model that eventually might wind up using that to train some model down the road?
Sure. So two aspects there, right? Like the organization that do have like enterprise licensing and they're making sure they're not uh, uh, using their data.
Like the organizations, the, I dunno, the providers not using their data for training and so on, but a lot of people are using their personal accounts, right? Our people are even like uploading in free accounts and so on and even paid accounts. And I think that's where the biggest risk comes to play.
Um, yes there are mechanisms to put in place. So like regardless how much you're gonna trade the people, let's start with that. Like regardless how much you're gonna trade them, someone is gonna sleep, right?
Like someone is gonna make a mistake. It's very similar to like don't click a link and someone still in these days are still clicking like phish links and so on. Same thing here.
People are gonna upload. Now there are guard layers you can put in place. There are measurements, measures that you can put in place to make sure what is getting uploaded doesn't have sense information and so on.
DLP market's been a while around for a while, like everybody's repurposing DLP for like AI guard rails, but it's not a one-to-one match, right? And I think it's a matter of like how well these mechanisms are put in place, but also how, what kinda information you allow people to, um, access, right? And I think it gets back to that common I of framework on like how you look at these files and their risk associated with that one.
Also, how you look at the business from a performance perspective, right? If you're not using, I dunno, AI these days, you're kind of like seeing almost like a dinosaur, but at the same time you want to be able to like restrict the risk, right? So, which it still like still puzzles me is that we're going even for us as like an organization when we go and we have like I know, uh, master agreements with very large organizations, there's the team that wants ai and there's the team, like the legal AI risk that's restricting in those agreements, like what you can do with AI and so on and so forth.
So they're trying to put those guarders from both legal technology perspective, but at the same time, they need to have a fast adoption to that as well. So it's a very hard thing to balance, but I do think that the taking a step back and identifying what, who can have access to what and what tools they are allowed to use as part of that will be, um, a more balanced way of actually approaching this than actually saying, you have access to everything, let's say in our CRM and then I download the Salesforce database, upload check GPT to generate a new fancy report I can show in the next, I dunno, presentation or something like that, right? Like that will be a really bad thing.
But at the end of the day, yes, people can go and like redact some things, simplify the content, anonymize some things, and then generate reports. But the more work you're asking them to do, the less likely they're gonna do it, right? 'cause the entire idea is to move fast and so on.
So, um, I'm not trying to preach now that everyone should go and buy enterprise licenses for these tools, but at the same time, there is a risk in allowing people to use their personal or organic free accounts, uh, with that. Mm-hmm. Um, people are sharing files probably more aggressively than, uh, anyone cares to admit without much care for various, uh, regulations.
But, you know, do you think the auditors are gonna get savvier about this and start cracking down a little bit more? And, um, and if so, maybe how long might that be? Um, it's still a relatively new thing, right?
Like they, and I think this is still, uh, a very hard decision, right? Like EU adopted, like AI risk laws and so on, right? Like us adopted a couple of things and so on.
So it's still a little bit of back and forth. I do think that, uh, 'cause we have literally this conversation part of our legal reviews as well with those domestic agreements I was telling you about and so on. I still think like in it should normalize in less than two years, to be honest.
Like I've seen, um, a lot of pushback. There's still some pushback that, but they already start like trying to figure out ways to like, I don't know, align. Um, there've been conversations.
For instance, I'll give you a quick example with FS iec. If, uh, the audience familiar with FS iec, um, in financial services, information sharing and so on, there've been discussions on like how they should tackle AI risk and how, what are some recommendations, if not even regulation to put in place on how to use AI as part of financial services and so on. So all the industries that are trying to look into, like, I know not necessarily regulate, but normalize how they're using these tools for them to be able to move faster as well.
'cause otherwise these organiza some organizations like Healthcare Financial and so on, have a lot of PIIA lot of information that it's very, I dunno, appealing for threat actors, right? And they don't want to be able to, like, they want to move fast on the ai, they don't have to be the dinosaurs that we talked about. But at the same time, they want to make sure that there is a guideline, uh, blueprint.
Let's say that they're using, that they're gonna reduce the risk and they're gonna get the buy-in from the organizational as well. Hmm. How much of this is something that requires a technology solution versus how much of this is something where, well, we just need to train people better and get them to think about the fact that there is sensitive data in those files and they should be careful.
I mean, I, I feel like if, let's say, if training would work properly, 90% of the cybersecurity industry will not exist. May, maybe I'm exaggerating, I'm sorry, but I'm, I don't wanna make like bombastic statements here. But at the same time, like again, phishing, it's still a thing, right?
Like the fact that people are still clicking on links that coming from we, I know random people and so on, or like even spearfishing person, CO and so on, those mechanisms are still working. It means that training is a checkbox is not fully efficient. And again, you are as weak as your weakest link, right?
Like there's enough one person organization to do it and you're gonna, um, be exposed anyway. So I do think that yes, training is definitely mandatory. You're gonna probably cover, but let's say 80% or so, but you still need to have a proper measures in place, right?
Like you're not gonna eliminate the risk completely just by doing training or relying on people's common sense. It also seems like the bad guys are getting a little more sophisticated in the sense that, um, they're stealing credentials and then they're logging in and hanging out for a while and maybe you starting to look like they're an actual insider that should be trusted and then they start doing stuff that is malicious. But, um, is it hard to distinguish now between an insider and an external threat?
Well, I would like to believe that, um, like we've seen that in the report as well, right? It, it's not an instant detection. It takes a week.
Sometimes it takes even a lot more than a week to actually detect, uh, if you, uh, have a breach. Now, the entire I important part is that once you have access on the network side, you're trying to do lateral movement, you don't want to like, I dunno, start dosing left and right to see what you can get, right? You are slowly moving and try to identify a bit more and so on and trying to see how much access you can get to like, what relevant information and so on.
They will have the patience, right? Because you're going after the crown jewel, you're not going for like a, a small bit and so on, right? So I think this is where things become more tricky.
And again, I don't want to, uh, call it doomsday or not, but um, also the way we're using AI to optimize our workload and so on. There was also a report, uh, a report from Atropic, uh, couple weeks back on how they're using, um, their cloud solution to actually try to build more malicious content and so on and like optimize their solution and so on. Um, there's also been like a couple of, um, things on the software supply chain instead of for them to try to, uh, get an organization, they're rather just like kind of poison one of the repositories and then they'll walk them in with crypto miners, PE or sniffers or things like that as well.
So there's been a lot more mechanisms where there are to some level, like some blind spots for the organization, right? Because for instance, on open source, uh, libraries, the main focus in the past was actually vulnerability. Do I have a critical vulnerability?
I should patch it and so on. But right now, a lot of them you're seeing almost on a daily basis, like this week has been, um, the rapport affected like 2 billion, um, uh, downs and so on. So as you think this through, what's your best advice to folks?
Or what's that one thing that kind of makes you shake your head and go, folks, we need to be a little smarter. I think we need to like, take a step back and look at the probably more holistic, right? Instead of saying that, Hey, we have measures in place in for X, Y, and Z.
It's more like, what is the risk for any of these data exchanges either coming in or going out and how we can, um, have a more holistic view on, on that one. Because if we're just relying to have like, I don't wanna call them like point solutions, but there was some level, there are like point solutions without clear visibility like what they're doing, um, then you're not gonna have a good view. And I think this is the part that we had the like, good conclusion of the report as well, where people are unhappy that, that they don't trust necessarily on how they have this, uh, set up right now.
And they need to have a better, I know, overview let's say on like what happens in the organization and better control over their files as well. And this is not a data discovery problem. This is more of a threat and, uh, security risk, uh, assessment than anything else.
That's how I see it. Um, the long game, it's still, again, if email be like malicious files on emails, let's say it's no longer that big of a threat, but phishing is, everybody's rushing to address phishing, but the threat actors are moving to something else to walk in the organization or like, I know compromise the user and so on and so forth. So again, it's still a moving target, but from that perspective, you kind of like always move your focus one project to the other, to more or less batch different, I dunno, potholes instead of like looking to like how we can actually build a proper highway.
All right. Sense? That makes sense.
Well, folks, you heard in here they say that sharing is caring, but you need to be careful out there because you don't know what you're sharing. You don't know where it might wind up. George, thanks for being on the show.
Thanks much for having me, Mike. All right, thanks everyone. You guys in the studio?
Hi everyone. We're back here in Napa Valley at, uh, it's Swamp Up j Rog Swamp Up event. It's been a great two days.
We're kinda winding down, but we saved some of the best for last few. Take a look at this guy. You've seen him on tech drunk TV before.
Um, we've been working with Steven Chin for four or five years, maybe more. We've seen him when he first came to Jfr, coming from the Java community, leaving Jfr, Neo four J and now back. Well, you're not, you're not a frog, but you're, You're Well presenting.
I'm bringing the best of both worlds. 'cause now we can use graph intelligence, uhhuh plus DevOps and solve some real security challenges, supply chain challenges. So I can I call that dev graph intel ops 'cause Yeah, Yeah.
Let's call that, let's call that, yeah. Yeah. That'll be Columbia next year.
Next year. Have graph intel ops. Yeah.
If you can get him to say that you really are a magician. Okay. Um, but seriously, Steven, it's great to have you on, you presented this year here at, at, uh, swamp Up.
But before we get into your presentation, you are a swamp up veteran as much as I am or more even. What'd you think? It's nice to be back in Napa.
Yeah. So the first swamp up was actually here at the Meritage right resort in 2015. Um, and I remember like super casual, but all of the thought leaders in what probably didn't wasn't even called DevOps at the time, but like, like people actually doing real world deployments and infrastructure dealing with security issues, dealing with challenges, getting to deployment.
Now you fast forward 11 years from now, we're back at the Meritage humongous event sold out Yeah. Full audience. And now we're looking at the same problems, but with the lens of how we use ai right?
To solve and to automate and to really like, streamline your DevOps processes, because that's the biggest challenge with AI that nobody's talking about is getting AI outta production, releasing ai. Everybody has amazing prototypes, amazing applications. They have this humongous value, but the quality Is not there.
Those are humongous investment. Let's in investment Investment, the quality is not there. It's not providing business stakeholder value.
It's not production ready. It's not secured. No, I mean, this came out, there was a recent study you probably saw from MIT, there was another one I think from, I wanna say from Deloitte, though it might have been Accenture.
One said 95% of, uh, AI apps have not affected the bottom line or been classified as not successful. Another one said 80%. So depending who you wanna believe, neither one of a good picture.
But, but you know what, I remember when they said the same thing about DevOps. I remember when they said the same sort of things about cloud. This is, you know, it take, the thing about AI is it's so much a victim of its own success that to hype me know, went so sky high, you know, Um, Defying gravity to Well, well you said, you said that in past tense.
It's still going up. You Think it's still going up the, the height meter? I, no, I, you know, I'm starting to see a lot of people say, you know, already going down to that trow of disillusionment, right?
Y you know, like, so, so when you look at AI in aggregate mm-hmm. Like, like a lot of the early things like LMS and, and models and inferencing, like those, those are more stable. Like the, the progression is more incremental.
But when you look at what people are doing with AI on top of that, where they're building agent systems, they're incorporating like different knowledge sources in their organization, um, they're taking advantage of, of data science and different like layer techniques. Those are still new buzzwords every six months. New techniques for doing it, like new advancements and what the capabilities you're able to bring.
And, um, what start out with chatbots, which are kind of, you know, passe now is turning into business intelligence and, and dashboards and like insights into customers. And there's a whole bunch of real use cases which, um, if if they were production ready, if they were accurate, if they could provide explainable auditable results, it would be amazing. But there's just a gap in getting to production and, um, I think swamp up and like a conference like this, which is so focused on releasing and DevOps is a really good, um, litmus ground for the latest in getting to production because it's, it's just focused on professionals who do this for a living.
And they're, they're the ones where all the apps and the companies feed into, and they have to make sure they meet the quality bar. They're actually like at a level where you can release them and maintain them and support them. Agreed.
Agreed. All right. Let's pivot.
Let's talk about your talk here at Swamp Up. Yeah. So what, what I did here, because it's, it's an audience of people dealing with security issues with software bill materials, with like releases is I used Artifactory as the system of record exported a bunch of SBO M and VEX files and Cyclone DX format.
Um, you could also do SBDX. Mm-hmm. And I fed those into a knowledge graph system where now you're using an LM to take all that information and construct a knowledge graph, pull in a bunch of insights from the data, and then create these connections.
And so when you, when you ask like an lm let's say you're like a security scenario, you're like, well, you know, in this library, what, what sec secure security vulnerabilities are they, how exposed am I, yada yada. It will, it will tell you a wonderful story, very, very long-winded. And like, like it'll find similar things, similar security exploits, like similar production issues, but it's not very relevant to your system.
No. Like, is it a library you use? Do you even call the API which matters for it?
Um, so what knowledge graphs are really good at is grounding. And so they take that information, they encode it into a, a knowledge graph and a knowledge system. And then what you do is you tell the LM answer from this knowledge graph.
And I, I did it two different ways. One is, um, it's called, um, doing a a, a graph vector search with graph enhancement. Mm-hmm.
And you first acts, uh, vector database, um, NEO four J also has a vector store for the answer, and it does similarity searches. So it gives you back related information, but not very pertinent at all times. And then you then pull some of those nodes out and you say, what nodes are similar to this?
So like, if you find the particular security exploit by the first search, now you'll pull in all the libraries, it's nested in the authors of those libraries, the systems it's deployed in. You pass that as context to the lm and it does a ver a more precise job of answering. And it's also very fast because the vector search returns immediately, the graph look ups quick and you get back a very quick response.
The second thing I did, and this was, um, new this year, and I think this is the future and why people are investing in some of the new AI technologies, is I stood up an MCP server. Um, so I used Claude Desktop, I deployed the MCP server as a DXT file to the local desktop. So super easy.
We, we have an open source, um, cipher. Cipher is the query language for graph to, um, um, text decipher MCP agent. And I gave it the same database, the same knowledge graph, but then asked it to solve the question.
And this time it wasn't doing a vector lookup at all, but the agent was using the tool to help answer the question. So first it retrieved the schema of the database, and I saw, okay, well, you know, you're asking about a library now I see like that's a package. Now I'm gonna ask about all the vulnerabilities which relates to that package.
So I did a query. I was like, okay, well you asked about how the vulnerability applies to my application. So then it dug in deeper which applications were deployed that used it.
And after a couple round trips where it was querying the knowledge graph and building it out, and without any, I didn't need to write queries, I didn't need to optimize the flow. It, it navigated this, it came up with basically a very detailed report on, you know, this is your application, this is the risk areas, this is the things you should investigate, here's all the information I know about it. And it's, it's the same sort of research like we would do as security researchers.
Yep. So let me ask a question though. 'cause one of the beauties of SBM is that they're not static as the release you are using or the, the component that's in this piece of software as that component we find out about vulnerabilities in it.
The, there's a new version of the component, whatever SBOs are supposed to be telling us all that. Does that kind of, um, not portability, but automated updating, does that live in the graph as well then? Yeah, so the, the nice thing about graphs and, and like graph database technology is, it's been around for a long time.
So like doing updates of the graph, like doing transformation of the graph is all a pretty solved problem. Yep. Um, so you can continually update the graph, you can use.
Does it continually update itself? I guess? Well, my, My question, my demo didn't, well, This is just a demo.
I mean, yeah, Yeah, yeah. But you, you, you can basically set up an automated system where as you make changes, it'll update and it'll pull, pull the entities out, update the graph, and then the other thing, which, um, graphs are very commonly used for is removing data silos across the organization. So my, my use case was, um, all the data was an artifactory.
So theoretically, like this could be a product capability in an artifactory, but what if you also need to cross reference those security vulnerabilities and the, the applications against like another database, which is our, you know, our known mitigations for different vulnerabilities. Maybe you have like a another application list, which is our, where all the applications are deployed to different environments, what hardware they're running on. And now you can use the graph to pull all this information together, have it be the system of record, which gets, you know, updated and managed from all these different systems.
And then you can directly derive value by building dashboards, by building query interfaces and things on top of the graph database. Absolutely. Um, exciting times, huh?
Exciting times. How do people, the regular people, and keep in mind our audience are not regular people. Our audience are our people, right?
They're, they're techie people, they're developers, they're DevOps engineers, they're platform engineers and security folk and, and so forth. Is this beyond them, Steven, can they do this themselves? Is someone gonna come along and wrap this into a product or SAS or something?
Yeah. So that's, that's interesting. Now, I think the point we're at in AI evolution is anybody who tries to sell you a, like a platform or a package solution, it's, it's never gonna provide the business value you need for, for your system and your use case.
Now, on, on the flip side, it's never been easier to raw your own. And I'm not even talking about vibe coding. So literally my demo was, um, I created a knowledge graph using an LLM, and I used a prototype web application or a knowledge graph builder.
It's open source, it's free. I threw the documents in it, connected to a free or a database that's our cloud database. And I have my knowledge graph built without writing a single line of code.
That's what people want to hear. And then for the MCP server, so of course you could, you could do it, you know, a docker deployment and it's like, do all the infrastructure and do all the port configuration, yada, yada. I didn't even bother with that.
I downloaded Claude Desktop, took the open source MCP server, which is, you know, in a packaged format, and I added it as an MCP tool to Claude configured a few like URLs and usernames and passwords for the database, and then I could query it. So this is something anybody can do, and it's really lowered the bar for, um, people who are technically skilled. Mm-hmm.
Right? They, they understand the business domain, they understand the requirements, they understand even like, like how to architect systems, but you just don't have the time to, to build and maintain a, a large code base to do a specialized application. The, the toolings got to the point where you can take off the shelf MCV tools, you can take some technologies like graph databases, and you can compose a very custom tailored and productive system for use cases and scenarios you have internally with, you know, in, in a, in a quick hackathon project, you know, 24 hours a few days with a team, and you have like a, like a working system Fantastic.
That you gotta love. I mean, it's an in, you know, they say, may you live in interesting times. It's crazy times to be living in crazy times.
Hey man, we're about outta time. We're gonna bring on, I think it's gonna be our last, uh, swamp up. Steven, it's a pleasure seeing you.
Say hello to Cassandra. Check out Steven's just, he's almost the precursor, but you know, chin two oh is Cassandra. Check her out.
She's doing amazing things too. We're here at Swamp Up. I think we've got one more great one for you and we'll be back.
Hey everyone, it's Alan Shimel and we're back here and we're back live at Swamp Up in the beautiful Napa Valley. You couldn't ask for a better location. The sun has come out, you know, it's good for the grapes.
They say it gets a little cooler, a little warmer, the sun, the rain, you get good grapes, good wine. But we're here with really maybe the highlight of our panel today. Um, three, three of the VIPs of, of the, uh, event The man to my immediate left.
Actually, I'm gonna let you go left. Okay. Let me start to my far left, I wanna introduce you to Rahul ti.
Raul is the GVP and GM of the ITSM, something I'm a little familiar with business unit at ServiceNow. Rahul, welcome to Techstrong tv. Thank You.
Thanks for having me here. Give our audience needs, no introduction to ServiceNow, but give them a little bit of your background maybe and a little bit of what you're doing at ServiceNow. Yeah, so I'm relatively new to ServiceNow.
I joined little over four months back. Oh, really? Are new.
And I'm running ITSM, which is the bread and butter, the largest business ServiceNow does. That's where ServiceNow was founded. My background has been building products for a long time for large enterprise companies, but the interesting bit is I switched midway to being a practitioner myself.
So I was running DevOps teams in the cloud space in my last startup before I came to ServiceNow. So I've been on both sides of the equation, building products and consuming products. That's, and that, that's missing in too many of our vendors.
As someone who speaks to vendors all the time, you, it's good to have that practitioner side to see what it is they, they're actually feeling. As Zach goes by, let's introduce Justin Boitano. Justin is VP of Enterprise AI at Nvidia.
Justin, welcome. Thanks for being on text on tv. Thank you for having us today.
Give us a little, maybe a little bit of your background. Yeah. Well, I've, I've been at Nvidia now, actually for 13 years, I guess.
Wow. A little bit of everything over that time, but, uh, we've seen It come, it's been, It's been, it's been, you know, quite a fun ride, uh, you know, watching us really reinvent how computing is done. Um, you know, from really the ground up.
Uh, and I think it was, uh, when I first joined in 2008, we had just invented Cuda. Nobody knew what it was. We were going around library by library, trying to port applications onto GPUs.
People, you know, thought we were crazy, I guess in the early days, but eventually, you know, every, uh, overnight success is, is 10 years in the making. Right? And so we've been working Hard.
That's exactly the biggest secret in tech, the 10 year overnight success. Yeah. You know, we had Aon earlier, and we were talking about so many people think of Nvidia and they think GPUs and the hardware, but the real secret sauce here is Cuda and the software and the ecosystem with partners like ServiceNow and Frog, and, and that we had Sonar CEO here as well.
Um, and that's really the, the key that's driving all of this is as much as the GPUs do agreed to my immediate left, immediate left, this man needs no introduction to our audience either. I've had the pleasure of interviewing him for, um, 10 years, 12 years, something long time. He's the CEO co-founder of Jfr Shlomi.
Ben Hayo. Shlomi, welcome. Pleasure being here again.
Again, you, thank you very much for having you. So, look, I was in the keynote this morning. It was an amazing keynote.
And as one would expect this year in tech, AI was front and center. We've been talking about it all day here. The thing about this is, look, all of us have been around the block.
We've seen technology waves calm and go flow and flow up and down. We've never seen something this disruptive across the entire breadth of, of our industry, right? I, I think Satya Nadella maybe said it best, or the best that I've seen in that we are moving from becoming, you know how Mark Andreessen said every company's a software company.
Yeah. We, were all software companies, but we're moving from software companies to intelligence engines. Right?
And what, that's a profound change in our business. Show me if it's okay, I'm gonna ask you to kick it off. What does that intelligence engine bring that to some of what we talked about today here at Swamp Up Ag, ai, the whole ecosystem, dev gov, ops, all of it kick us off.
So, Ellen, I, I, I think we will need two days to cover this, uh, And that some, But, uh, but I, I will touch the immediate things that we see in the market. And this is a across all, it goes beyond sectors. It goes beyond, um, company size.
It goes beyond, uh, geographies. What we see is a revolution, a disruption, uh, that changes everything we knew about the day-to-day practice. And a company like Jfr, we are not the native AI company.
We are the infrastructure company. We are the providers of the peak and shovels. We are not the gold miners.
And therefore, we have the privilege to see from below the changes that are happening. So one thing that we see happening across, uh, our portfolio is that consolidation happens not only in terms of technology, but also the inner organization, the CIO and the ciso, the compliance managers, the audit managers, all of them must collaborate in order to overcome the chasm, to bridge it, and to eliminate silos. Otherwise, they will stay behind.
The second thing that we see is that developers, it used to build called, it used to be called, used to deliver software. And then few years ago, they started to be security expert. And now they have to be released expert.
And they also have to be AI experts. 0. They are changing the world for everyone.
And the last thing that, uh, we see is that if we are not looking at the, uh, opportunity as coexisting, uh, providers, one of us will stay behind. If we go together, we will change the world together. This is not a race.
And, uh, and therefore I'm privileged, I'm honored to work with companies like ServiceNow and Nvidia, um, to give my customers a better experience, an experience that they expect a one platform experience. Absolutely. Rahul, I'd like to come to you, right?
So you think ITSM, is there any sector of our tech world that is more rule bound that you would think needs a little shaking up maybe, or, or maybe doesn't need a shaking up, but is certainly getting a shaking up with ai? If you don't mind, share with our audience a little bit of the profound impact that AI's having in the world of ITSM. Yeah.
So I think it's getting shaken up. And honestly, we, being the leaders in that segment, we would like it to shake up. Because if, the way I look at it is it of yesterday have changed.
Now it is true truly a broker of services, right? They're managing SaaS assets, they're managing cloud assets. So go on as the IT of yesterday.
The service has changed from IT providing services to I want my self service, right? So when Jensen was in stage on knowledge, he's like, his main thing thing was, I want my service now, right? That was his ra.
So people want their service now and management is no longer like, top down, let me tell you what to do, what not to do. People are not used to that kind of thing. So we are kind of reinventing it.
Service management and AI actually helps you really create that agility on top of the more fixed workflows, because now you can do more with AI to create value out of the workflow. So workflows can still exist. Like the example we gave this morning, compliance and regulation is still required because who wants to have an application that is gonna be breached tomorrow?
Right? That's at the same time. Does it take, should it take a week to get approval?
No. Right. So I think we are reinventing those ITSM processes and kind of integration with jfr, looking at the AI patterns and everything else, because the speed has gone whatever, 10 XA hundred x, right?
So things that were taking weeks are taking seconds. So that's where our head is at from an ITSM perspective. Absolutely.
It's velocity. It's velocity. Yeah.
You know, talking about the profound change, if we, if I asked a hundred people watching this live right now, what is the AI company? 98 of them are gonna tell us Nvidia, but Justin, you know, this, and even Nvidia, I wouldnt know who all the other two, who the other two, they've, they're living somewhere who knows on a, on an island somewhere talking to a volleyball. But, but Justin, even Nvidia knows that as great as Nvidia is, and as they've led the char help lead the charge here, you can't do it alone.
You need partners like Jay Froog, like ServiceNow, like sonar, like, you know, so many. You, I mean, one of the, the real strengths here is NVIDIA's ecosystem. Talk to our audience a little bit about that.
Yeah, I mean, I, I think that's, uh, well, a, a great point. Um, you know, Nvidia forever, honestly, has been an ecosystem led company. And I think honestly, it's, it, it comes top down at Nvidia.
Like Jensen realizes the power of an ecosystem for selling our physical hardware through OEMs and OEMs globally, uh, through infrastructure companies, uh, you know, uh, plumbing, the runtimes of these accelerators, uh, up to the AIOps applications and into the GSIs. So we work across the entire ecosystem to try and provide acceleration to, I'll call it, uh, key, you know, workloads that we know are gonna deliver a lot of productivity or performance gains or, um, you know, really kind of transform the, the business, uh, if you would. Right?
Um, and, uh, you know, this, this latest version of it, I mean, for a long time we did it in high performance computing to, to, uh, deal with F-E-F-E-A and, uh, you know, CAE and like the simulation, uh, of the physical world. 0 where it's the, the reality is it's a probably a $3 trillion industry, you know, a a trillion dollars in, uh, pure software that gets bought per year across enterprises and $2 trillion in services. That entire industry is being rethought now through this, uh, this new way of building software where you've got agentic systems that can break down problems, try and solve the problems on their own, and then reflect on the answers.
And so there's, there's a, a tremendous opportunity, I'd say, for all vendors in this space, really to, to ride that wave with us, uh, in the era of ai. Agreed. If I may add, add to it, uh, Alan, look at, uh, what Nvidia did, um, in, in the history of software, the first thing that they act was a community native company.
They released their software as open source. Yeah. Um, today, um, uh, Justin and his team presented on stage, like everything they build in order to optimize GPU with software is open source available.
That's right. For the community. Open source is not only we build it for you, but we build it with you wi with the community.
So I, I think it's really speaks for itself. Uh, ab absolutely. We are looking at the improvement that software brings to the world of ai.
Yeah. com today, my mom rest it all used to always tell me, show me your friends, I'll show you who you are. Right?
You've probably all heard that. Or similar thing from your moms, I'm gonna ask, you already said it, Justin, but Rahul, and then I'll come to you. Shlomi.
What's the importance of your partner ecosystem in this brave new world of ai? So, I think any, anyway, at the core of it, if you look at ServiceNow, it is only about workflows data. So that's what we have built our business on, right?
Because enterprise has front office data, back office data, asset data. And if you don't unify the data, then you can be desperate systems on top of it. You tie it with the workflow.
So now the third leg of this tool is AI for us, because AI helps you do your workflows better and faster, and there is no way we can own all the pieces of the workflow anyway, right? There is the software supply chain that multiple players, including jfr, are there from a hardware perspective or from a software infrastructure perspective. Then we have cloud vendors, there are model vendors.
So at the very heritage of the company, we believe that partner ecosystem is critical to it, because that's what our customers want. They cannot rely on a platform that is closed, monolithic does not allow for partnerships. I think it's the DNA of the company.
That's why we are so excited to partner with. We call it like any model, any industry, any infrastructure is what our ethos is From. Excellent.
Yeah. Shlomi, I, I believe that, uh, um, what our customers are telling us is the, uh, the honest, true and the pain that they experience. And they also know how to put the volume on this pain.
Is it a major pain or something that we can handle? And, uh, every time that, uh, that the technology company is coming with a piece of innovation, the second question should be, what's my ecosystem? And, uh, some people immediately ask the opposite question of asking, am I overlapping?
Am I competing that we are running a platform? We have, I dunno, thousands and thousands of thousands of logos in, in our joint portfolio. For sure, there will be some overlap, but if the one plus one equals more than two and our customers, um, actually ask for it, how can you go wrong?
And when we present that up, trust the, um, the, um, dev gov ops solution we discussed today. We didn't present it as an ecosystem tool yet. It was just an idea in the beginning of the year.
And our enterprise customers stopped us right there and said, listen, the people who need to use appt trusts the application owner. They're not coming to jfr, they're going to ServiceNow. And, uh, when we started to, to work with Rahul team, um, and we spoke with the customers, they actually echoed that.
And, uh, and what we've built together and presented on stage here today is just a representation of our, uh, of our customer's voice. Uh, I'm, I'm very proud to be part of a company that instead of coming as an arrogant vendor, telling them what is right for them is asking the, the customers, what will be better? How can I make your life better?
I love it, guys. I gotta bring up a difficult one. It's not on our list, but I've gotta ask you, I've talked to a lot of people about ai, as you would imagine, it's almost impossible to live up to the hype.
The hype, the hype cycle is there, right? And there are a lot of people out here who are starting to, you know, the ankle biters. It's not everything we thought it was gonna be.
It's not. This is a lot harder than we thought. It's gonna take longer than we thought.
I think was the expect we set such expectations of it changing the world so quickly. I, and I said this, even if we stopped developing AI right now, and we just said, okay, let's digest what we have, it would take seven years to fully integrate it into all of our ecosystems. But what do you say to the naysayers who are saying, we're not going fast enough.
It's not good enough yet we may never get to the holy land to the promised land. Justin, you're, you're Nvidia, I'm laughing and you're gonna go walk A day in my shoes. It's moving really quickly.
Yep. Is all I can say. And I think, you know, in the, the early days of generative ai, uh, you know, people were kind of dabbling.
They, they treated it like Java. It was a new technology. They wanted to upscale themselves, but they didn't know how to apply it to their most pressing business problems.
Um, you know, and, and we see now every enterprise really focusing on like, how do I reinvent the core of my business? Honestly, at Nvidia, we've done it ourselves too. Like Jensen gave us the challenge, you know, double the number of chips that you produce, uh, every other year.
So instead of doing a chip every 18 months, do it every year with a design cycle in between. And the only way to innovate at that pace without obviously exploding your workforce, is by using AI and infusing it into the, the business process of the organization. So we're applying it, you know, to reinvent how we design chips, how we develop software, uh, how we engage customers, you know, through every business function of the company.
And we're starting to see that in, in a big way, happen really across every vertical industry, from retail to telecommunications, to healthcare. Um, and so I, I think it's moving faster than you might think. I think, uh, you know, and, uh, enterprise in some regard has always been a slow beast.
Um, it's always moved. The transitions have happened, you know, more slowly than than we would like. Um, but in my conversations with CIOs, I think what they realize now is it's time to make that shift.
Instead of reinvesting CapEx standard data center infrastructure, take the leap to accelerated computing and, you know, and focus on building agents that address your core business. And, uh, people are seeing, you know, huge, uh, productivity gains and huge improvements to margins that way. Excellent.
Guys, I got one more question, and it's for Rahul and Shlomi. I want each of you to answer this question looking into this camera. Rahul, you're gonna go first for all my friends in ITSM, and I'm very good friends with the folks at Idol.
My, my friends at People Cert and, uh, Demetrius, and they're out in Greece watching this. But talk to all of the ITSM people out there who were worried, is this gonna take my job? Am I gonna have a career?
I just got into this profession five years ago. What is AI gonna do to my job? So I think my thinking is the train has left the station.
If you get on the train, you will have a job. If you don't get on the train and start kind of on the side kind of okay with naying, I think you may actually lose your job. The reason is when I've seen the successes, people who have embraced, they are having AI do the job they did not want to do in the first place.
Like summarization after closing every incident, really going after knowledge base updates. Who wants to do it? I've seen people who have started going that direction, then they realize, oh, I have not submitted that knowledge.
Why can't I have agent tech do it for you? So slowly they are getting on the train, and the train has gone to the next station. People who are left behind, is it not good enough and all that?
Sorry, that is not gonna work. So let me talk to the software developers out there. First of all, whatever Raul said, I'm in, uh, no, no, no, nothing to add.
Software developers, if you remember the days of CICD that you doubted building software with some tools and automation, if you remember the days that, uh, you said that developers in order to be faster, they need to be a bit dirty and not secure. Those who didn't, uh, um, jumped on the train left behind, and they're not software developers anymore. You have more responsibility and the next generation trusts you to build it, right?
Because we are changing everyone's world. Absolutely. I'll end it with this.
I said it before, I'll say it again. You're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than you.
Right? And amen to that. We've gotta learn.
It's a tool. It doesn't replace the spark, the spark that's in now all of our brains, right? That cre the creator, but it's a golden age for creators.
Absolutely. And we're lucky to be here. Rahul, Justin Shlomi, thank you.
Thank you for watching. We've got, we've got two more, oh, another day after this. Another half a day here of, uh, uh, JFR Swamp Up coverage.
So check it out. We're on Techstrong tv. We'll be right back.
Power borrow tosses their data centers. Broadcom is powering open AI now. Microsoft is making more deals, lapses, scatters.
A rolling stone summarizes no moss. Claude is a criminal. And we're gonna take a look at all of the big AI cloud news of the week in this episode of the Tech Field Day rundown.
Hello everyone, it is time for the Tech Field Day rundown. I am your host, Tom Hollingsworth, and I'm on location this week. But joining me as always is Al and Al, I have a question for you.
How do you feel about Deep Fried Club sandwiches with a side of Sweet Jam? I'm sorry, it's going to take me a moment of three to process that. Um, not something I've really come across.
Steep fried Mars bars in England is the nearest thing I've come across. Well, luckily for you, it is Monte Kristo Day, which is not just an, a novel by Alexander Duma, but in fact is probably one of the most decadent sandwiches you're ever going to eat. But, uh, if you feel somewhat ill after that, don't worry because it's World Patient Safety Day, uh, along with a whole other host of things.
Uh, but what we are definitely making sure we're taken care of this week is the news, because we are thrilled to have a lot of interesting things going on. And we are gonna be bringing you all of that news as we go forward. 4 billion data center.
That was proposed by energy storage solution, the reason, resource, and community concerns. Although you will be shocked to learn that the company is going to be challenging that decision in court, the ruling based on legal criteria rather than public opinion reflects broader tensions in North Carolina over rapid AI driven data center growth and its impact on local communities and utilities. Al do you think that this, uh, tenant is gonna be able to overcome city Hall?
Well, I think there's a couple of fun things in here. 4 billion. Uh, they're even a North Carolina company.
So it's not like big business coming in from out of state trying to ruin our, our local, uh, city of, of Taver. And the concerns are the usual concerns about having a big data center built next to, um, noise, uh, water consumption. 'cause the data center was going to use a huge amount of water for cooling.
Uh, and then also the cost and cost of power. The proposal itself was primarily that the power generation was gonna be on site. And so there shouldn't have been a grid impact or cost of power consumption impact.
But the, the locals were a little concerned around that as often happens when these big data center projects are turning up. This particular one was interesting because the, the, the, um, area was already zoned for heavy industrial. So it didn't require a, um, council decision to allow heavy use of what maybe was previously fine land.
And this was already zoned for, for heavy industrial. Uh, and that rezoning process is what you normally see in a council of very open meetings and lots of submissions from the community. The interesting thing for this one is that they had a special use permit application where their council, instead of taking public consultation, looks more at the science of what's going to go on than the public feeling.
And that caused a little bit of a challenge in here, and that's the opening that a SS has to challenge this. Uh, the mayor even recused himself because he didn't feel he would be able to be independent in the decisions. And that's definitely an opening for a SS to say the whole council couldn't be independent in no sway by public opinion, which isn't supposed to matter in the special use permits.
This is a weird one. Um, but it is, it does carry on with themes, uh, that we see around concerns for power costs, water consumption in, in these communities where these massive AI data centers are being built out. Uh, it won't be the last time that we see it.
I think there'll be some changes to how councils operate as a result of, of these challenges. So in particular, the special use permits, uh, processes are gonna need to be tightened up and, uh, made much more judicial looking rather than consultative looking. Uh, in order for these these things to have the, the rulings here, and it was an overwhelming, it was a six to one ruling here, uh, this overwhelming ruling to, to actually stand up to further review.
They need to be more judicial in their processes there. Uh, it's gonna continue to see more of these big data centers being built, and they'll be built in places where power is abundant or can be developed and where cooling is either latent inherent in the, uh, geography or is something that can be managed easily, of course, North Carolina, uh, and pretty high humidity and pretty warm at times. And those aren't good things for free year and, and low cost calling.
So I can imagine the, the concerns from the locals open AI plans to launch its own AI chip next year, co-designed with broad, uh, to meet the soaring demands for computing power and also to mitigate that single source supply chain issue from Nvidia that plagues many of the AI companies. Chip will be used internally to run the, uh, run and train AI models. Uh, following the, the same sorts of trends we've seen from some of the other hyperscale, uh, vendors, Google and Amazon Meta.
Uh, Broadcom confirmed a major new customer with a $10 billion of orders. Broadcom didn't say that it was OpenAI, but that's what we all believe, uh, move comes as OpenAI tries to bring in more resources to compete, uh, with products like chat, GPT and particularly GPT five that's coming. Uh, we're seeing huge growth in AI data centers.
Tom, does this mean huge growth for Broadcom as well? It should. And I think this is an area that Broadcom has been particularly worried about because when you look at where all the growth has been happening in the industry, it has been happening around these AI accelerators and Broadcom powers a lot of the AI infrastructure that's going in on the backend, but not the actual GPUs themselves.
And I think that that's something that they really want to be a part of. Plus, they haven't exactly been on the best of terms with Nvidia over the years. I remember there was a kerfuffle that involved Melanox and Cumulus Linux and Broadcom API access that, that happened many, well, I say many a few years ago.
But realistically speaking, Broadcom is giving open AI something that they couldn't get from Nvidia. Essentially they're getting custom silicon. Now, that's not exactly the way that this is being portrayed, but hear me out, Nvidia is gonna make Nvidia silicon and you're gonna run your stuff on Nvidia, right?
But so is everybody else. And that's part of the problem is that if you can optimize your models to run on Nvidia silicon a little bit better than everybody else's, then you have an obvious advantage. That's one of the things that we've seen from some of the, you know, AI platforms that shoot to the top of the App store, uh, for a little while.
Was it deep seek, I think was one they just figured out how to run a little bit faster. So what's open AI to do? Because if they're trying to optimize their code to run on the same thing that everybody else is using, there may not be a way to win.
Well, what if the manufacturer was optimizing their hardware to take advantage of the way that you do things, but in a way that makes it so that not everybody has that same chance? Now, I'm not saying that there's any kind of a deal here that Broadcom is giving open AI to make them kind of dominant in that space. I'm just saying that when you look at the handwriting on this wall, Broadcom really wants open AI to be one of their biggest customers when it comes to purchases, right?
And the only way to really make that happen is to play ball with them to give them something they can't get from nvidia, which is a little bit more insight into the design process. So I think what we're probably going to see is, you know, a large purchase, what was the, the number, $10 billion in order, you know that that's a pocket change anymore. What it is though is an opportunity for open AI to really kind of innovate around these new chips and possibly get people chasing those performance gains.
And how do you do that? Well, if you're writing your software to take advantage of what open AI offers, why not go buy the hardware from the same group up to see what happens with this one? Speaking of open ai, they and Microsoft have signed a new non-binding agreement that's going to allow open AI to restructure itself into a for-profit company and potentially go public down the road.
That means that Microsoft gets to secure continued access to their AI technology. Open AI's nonprofit parent would of course retain oversight and a $100 billion equity stake, you know, pocket change. There are some regulatory hurdles, and of course, there's that lawsuit from somebody that owns a social media platform that complicates the process.
The move supports open AI's, growth plans, partnerships with cloud providers and long-term revenue goals. But of course, the other elephant in the room is that OpenAI is continuing to project losses all the way through 2029. The agreement comes amid rising tension between open AI and Microsoft as both pursue competing AI initiatives.
Alistair, do you think that this non-binding agreement is going to give open AI the flexibility that it needs to really start making money? Yeah, it is making money really the point, you know, we're transforming society and building a better world for the fu. Uh, no, I can't do it.
Um, yeah, profitability is, has gotta be somewhere in the path along the way here for open ai. There's an awful lot of money has been invested and the investors are gonna want their money back sometime. Currently, uh, open AI is valued at half a trillion dollars, $500 billion, and, uh, that's an awfully high valuation for a company that is supposedly not-for-profit.
Uh, the transition across from being not-for-profit restructure to having a for-profit part and maybe retaining a not-for-profit, that's gonna be the complex bit and that's the bit that, um, is, is under a little bit of attack in the, uh, in the courts with, uh, yeah, Mr. Mr. Musk, uh, suing, uh, along with, uh, ex AI is, uh, his AI company suing open AI around this, uh, move from its original nonprofit agenda.
Uh, there's a lot of money at stake, and so of course it goes to the courts. Uh, OpenAI does need to focus on some point becoming profitable, uh, unless they're gonna stay true to their nonprofit, uh, route. I mean, they've been nonprofit sofa, but, uh, that's not in a good way.
And yes, there's a whole lot of stories and we'll, we'll cover this a little bit later, around the longer or medium term plans for all of these AI vendors and AI platforms from Microsoft all the way through. Uh, definitely sort of commitments to multiple vendors. And again, we've, we've seen this in the other stories, uh, having open ai, not just dependent on Microsoft, but having also just done a big deal with Oracle to put a whole bunch of workloads, $300 billion worth of workloads into Oracle's cloud over time.
I think, uh, open AI doesn't want to be stuck to just one partner with Microsoft, uh, particularly when they're looking to do very big deals and be, uh, reducing their risk from single supplier. But again, is a theme we're seeing in the AI infrastructure world as, uh, recognizing some risks around Nvidia and, and other single source suppliers. The recently formed Scattered Lapses Hunters, a merger of scattered spider lapses and shiny hunters announced that they're disbanding after they managed to compromise Angular Land Rover.
Apparently these, uh, attackers, these hackers have decided that they'd like to enjoy their ill got gains and they're gonna retire. But really we think what's gonna be retired is the brand scattered lapis hunters, and that in fact, these, uh, people who are skimming money around, uh, are gonna want to continue to do that. Probably there's somebody at the top who financed it, who's pulling all of the money out, and the people doing the real work who are only getting pennies on the dollar are probably gonna continue to want to do that real work and continue to attack, uh, various companies along the way.
Uh, Tom, do you think the solution to this is for the, uh, attackers themselves, the people who do the real renegotiate contracts in this, uh, malware business? Are, are you saying that the, the criminals need to unionize? I mean, it's not the craziest idea that I've heard now.
I think what you're seeing here is the results of Icarus flying too close to the sun. Again, because this isn't even the first time we've seen this out of either of any of these component groups, right? They, uh, the, you know, the, when they came together, everyone was like, oh, yeah, you know, maybe you're combining resources for something.
And, and I'll admit hacking Land Rover is not a bad hit, but this is like that scene at the end of Oceans 11 when they all kind of walk away and tend like they don't know each other, but they're not gonna stop being criminals like this. This ultimately comes back to they need to let the heat die down for a little bit until people kind of forget about them. Some other nation state backed team or some other group does something, and then we'll hear about them again probably six or seven months when, when we least expect it.
Uh, especially the Lapsis group, they, they kind of thrive on this notoriety. They want people to know who they are. It's, it's not about the money for them.
I, I don't get me wrong, if, if I had millions of dollars just sitting around that I'd per loin from things, I, I would probably be spending it on random stuff too. But it's more about everybody knowing their name, knowing who they are, knowing that they were behind it. Right?
It's, it's the credibility thing. It's like tagging a website back in the nineties. So I I, I wouldn't put too much stock into this retirement.
It's like a professional wrestling and retirement. Give it a month, and I'm sure they'll be back at it. Before you know it.
Penske Media Corporation, which is a company that owns Rolling Stone Variety and Billboard has sued Google. And why would they be doing that? Well, they're accusing it of illegal using its content to train AI models and power.
Google's AI overviews in search. Penske argues that Google is abusing its monopoly by forcing publishers into a deal that they didn't agree to. While Google claims that the feature helps users and drives more traffic to publishers, the case marks one of the very first major lawsuits by a media company against Google over ai, which is of course, adding to fuel to the fire against growing copyright and antitrust challenges that the Czech giant faces in US and Europe.
Al, that was an awful lot for me to read. Can you give me a summary but don't use Google for it? Yeah, I'm, I might get you a, uh, natural or intelligence or natural stupidity based, uh, answer to this.
Um, what's going on here is that Google is starting to use AI to generate articles that summarize what, what's been published elsewhere. Uh, so when you get a search result that points to maybe an article that's on Rolling Stone, Google Wolf's, uh, offered to summarize that for you, rather than suggesting you go and read the original article that Penske Media Corporation paid to have somebody write either with or without ai, and that's the core of it, but Penske, uh, but, um, Penske Media says, yeah, we're perfectly happy for Google to go and, uh, crawl through all of our content and direct interested parties, interested users to come and visit our site. But we put a line where you take that information you've gathered from our site and use it to generate what's essentially your own article on your own site.
And therefore we don't get that connection. Of course, Google says, yeah, you'll get the, the link coming through. People will just read the summary and then they'll want to go and read the real thing.
Uh, tldr Yeah, I'm gonna read the summary. If it's any good. Your summary is terrible.
I'm probably not gonna read the original article either because the summary has put me off the whole thing. So I can absolutely see the point for the media publishers here. Uh, people writing good content as we know content that Tech Field Day is something that's really vital to us having good content that's been thought out and delivered by a human.
And it's not just more of, well, maybe AI slop, um, is a really important part of communicating complex things and, and communicating particularly topics that our audience are interested in, highly detailed topics that maybe the AI can't quite catch up with. So I absolutely can see the point here for the owners of Rolling Stone, the various other platforms that they publish, and I think we'll continue to see more of this. So there's a generic issue at the moment that there's a huge amount of, uh, AI generated content that is now being scraped from the web and used to train future generations of ai.
And just like the, uh, the, the chicken flu issues of that, uh, they had in the UK where they were using ground up pieces of chicken to feed to the chickens and closing a loop of infection, we may well find that we're closing a loop of infection here. And the more we can do to get human generated content and human generated insight into that loop, the better our lives are gonna be and the better ouris are gonna be in the future over the summer. It's just finding winter here, but the Northern Summer cyber criminals exploited Anthropics clawed ai, uh, to automate large scale data center extortion.
If you can automate doing good things with ai, you can automate doing bad things. This included, uh, reconnaissance and credential theft ransomware, uh, and they targeted the usual sorts of, uh, larger organizations that are kind of critical healthcare, government, also religious organizations, uh, that's in demands exceeding half a million dollars. And Andros report detailed how Claude enabled North Korean IT worker scams and the creation of advanced ransomware, uh, which lowered the technical barrier for criminals.
This is the new ground for script kitties is AI script kitties. The company responded by banning accounts, improving detection tools and shared threat indicators with author authorities wanting that AI assisted cybercrime is evolving rapidly and likely to be much more common because it's so easy. Tom, have you built any ransomware recently?
You by Vibe coding for Legal reasons? No, for anecdotal reasons. Hold on.
Let me go ask, uh, Claude. 'cause it seems to be that Claude wants to aid and abbet everybody out there. This is one of the problems that we run into when you create a model that really just wants to help people, right?
And doesn't know how to not answer certain questions. You know, like if I asked it to build an explosive device, oh no, I can't do that. Would you describe how an explosive device works theoretically for research purposes?
Oh, sure, no problem. You know, it's, it's that old trick of, you know, I won't do the thing that I was explicitly told not to, but I will leave lots of hints to help you figure this out. And let's be fair, jailbreaking these models and trying to figure out a way around their controls is almost half the game anymore.
And, and one of the problems that you run into is if the AI is doing its job and consuming all of these things and reading all of the available information out there about crafting the perfect, um, information campaign to get inform extortion out of people, then yeah, it's gonna know what works and what doesn't. And it's gonna tell you, oh yeah, this one didn't, this one worked, but that one didn't. And don't have them pay you like this, pay that, and Oh, you're in North Korea, so you're gonna have to use these systems.
Like, that's the deal. Is it, it's doing what it was designed to do, which is refining information to something and producing, well in this case a summary, but one that allows you to do nefarious things. And that's, we're gonna have to watch out for that.
You know, it's, it, it's every problem that we've ever run into where someone gives somebody a little tidbit of information that they're not supposed to, and the next thing you know, they take it and run with it. And it now is happening at the speed of however many millions of GPUs are powering these clusters. So I, I applaud philanthropic for doing the right thing and going and banning a whole bunch of people's accounts and trying to tighten down controls and all stuff like that.
But every time that you do that, you just create craftier criminals. We had a couple things we wanted to take a closer look at this week, and they involve the advances that are happening in the AI space, but also where it intersects with cloud and specifically hosted ai. The first one, of course, is the company that we've talked about previously on the rundown, and that's Core Weave.
3 billion order for AI computing capacity with Nvidia agreeing to buy any unused supply through 2032. The deal highlights Core weaves reliance on Nvidia, who is its sole GPU supplier and investor, while boosting its role in powering AI workloads. 21 billion in Q2 revenue, which is up 207% year over year.
The company remains unprofitable losing 290 and a half million dollars. 9 billion deal with OpenAI, and that has fueled demand and pushed Coral Wave's market value above $58 billion. Now Al we've got a story.
We're also gonna be talking about Microsoft, but I wanna kind of get your thoughts on Core Weave and the fact that they seem to be getting a lot of sales but not making a lot of money, and they are almost entirely dependent upon Nvidia to make that happen. Why would Nvidia agree to buy all of their supply for the next seven years? Well, I think having long-term commitments for Nvidia helps 'em deal with the risk that there is an AI bubble and that all of a sudden there may be excess, uh, GPUs in the market the way there were when the cryptocurrency bubble went pop.
And, uh, we needed to find a new use for all of these GPUs. Of course, Nvidia was lucky 'cause a long come generative AI and Nvidia GPUs are vital, uh, having that continued long-term relationship. I think this is very much a trend we've seen in the last couple of months in the coverage we've had here on the, the rundown.
We've talked about some of the deals around long-term electricity supply, building out new data centers and long-term supply of new GPUs. Of course, you always want the newest GPUs because they give you more performance for consuming less power, and these kinds of deals are, are really vital for that continued supply. It should also mean that Core Weavers even further at the front of the queue to get those new GPUs when they're first shipped, and meaning that core, we can then sell more services to companies like Open AI to, to run their infrastructure.
So, uh, the general theme we're looking at in this look is around that long term commitments between the various partners, but with a little overtone of how many of these partners are actually making money. Because we talked earlier, open AI is on track to make money. Well, not this year, not next year, not the year after.
We've may well be in the same place. 3 billion will buy back. What you don't sell doesn't seem like a big risk for Nvidia with the massive profitability they've had from these GPUs.
Of course, another element in here is the neas group. 4 billion. Uh, the Amsterdam based company will provide AI computing power from a New Jersey data center through 2031, and again using a video chips, uh, Microsoft, Hmm.
Already working with Call Weave as another investor. Uh, and the whole deal sort of fits together that Microsoft is using NE's cloud, uh, platform and Nvidia chips in here. Uh, does it seem like it's gonna be hard to differentiate, differentiate yourself as a provider of these cloud platform, these cloud AI platforms?
You know, honestly I don't know the answer to that because they're all running the same stuff on the back end, right? They're all running Invidia. And so why would Microsoft want to use this other platform and Core Weave?
Well, the only reason I can think of is they want, you know, diversity, they wanna make sure that a core weave outage or or weave acquisition doesn't cause problems for them. So I, you know, and you're basically funding this company to do this build out, which of course puts you at the front of the line when you need to, you know, increase capacity or something like that. So I don't think it's a bad move on Microsoft's part.
I think that they're investing smartly if they've got some money in a lot of different pots as opposed to kind of tripling down on using one like Core Weave. Uh, I don't think customers are gonna care one way or the other because one of the things that we've seen over the years is this idea of multi-cloud, right? You know, we're, we're using things like cloud arbitrage to, to make it make sense financially.
And, and I don't necessarily know that that's born out over the years. I think people just like the idea of saying that if we need to, we can cut and run to Azure over AWS And it's funny that AWS is kind of at the front of my thoughts there because there's another company that was unprofitable seemingly forever. Amazon couldn't make money to save its life until it started selling cloud computing and then all of a sudden they were making money faster than they could figure out how to spend it.
And I think that maybe that's the hope is that these companies, core Weave and neas are effectively riding the wave right now of what's hot in the hopes that they can hold on long enough to either make it, make money or find that thing that Amazon did that allowed them to start raking in the money as crazy as possible. I guess my next question is, can these companies hold out from being acquired long enough to make that happen? Or do they need to hold out from being acquired?
They need to be attractive to be acquired as an exit, but I think one of the things that we've been hearing a little bit is that this is still very much the early days of generative AI and that the game will be played out over five or 10 years from now, not over one or two years. And often our horizon is, is much shorter. Um, one of my delegates today, our infrastructure field day last week was talking about as being like when, uh, PCs were brand new and everybody was buying up PCs with no particular plan of how they were gonna use them.
And the predictions were that this PC bubble was gonna burst and everybody be back on their mainframes for everything, or mini systems plays out. No, there's just, as you say, a little more innovation required before you get to the point. We needed, um, service systems to go without our desktops.
Um, that that suited the, the desktops use case and in particular client server computing became the thing that made desktops really valuable to us. I think that same idea of having some innovation, uh, some more artwork is, is still required and that's why we're seeing so much change in the AI infrastructure and the AI models and AI applications. This isn't done yet, this isn't even, uh, it might be the the end of the beginning, but it's definitely not even the, the middle, let alone the end here.
So we, even though we talk up a little bit of feeling that this is a bit of a bubble, you know, whereas if, if the actual natural growth in of value being delivered catches up with the spend, that would stop this being a bubble and make it actually a simple growth. And I think that brings us to the end of the, the news of the week. But of course there is more coming up in the following weeks.
Uh, say I had AI infrastructure field day last week in Santa Clara, and Tom, when you are finished in New York, you'll also have travel next week. Yeah, you're right. I'm gonna be right back out in Silicon Valley for Security Field Day.
We have a wonderful lineup of companies, including new presenter, square X in one password, uh, and Alan Shimmel from Security Boulevard and Textron TV is gonna be joining us as a delegate. You know, Alan's opinionated when it comes to security. You wanna know exactly how opinionated, make sure you tune in.
And then I'm gonna be right back again about a week and a half later because we're gonna be having a special exclusive event with Microsoft Security talking all about Microsoft Sentinel. That's gonna be happening on October the ninth. I just got a look at the schedule.
There's some really good conversations that are gonna be going on. You can join some of my closest security friends from around the globe as we listen in, ask questions and discuss all of the cool stuff going on. And then the end of October, right before all of the candy, you've got something sweet coming up, Al.
I do. I have, it's a beautiful Tasty Cloud Field Day returning, uh, we have HPE Fortinet and Oxide Computing presenting and a few more, you'll be joining the roster as well to entertain and delight my delegates as well as you viewing. That'll be October 22nd and 23rd, and right after that, the following week is AI Field.
They were, Stephen Foster will be back in, uh, the, uh, Silicon Valley area October 29th and 30th with his own focus on what you can actually do with AI rather than the infrastructure, which was my focus. com. And of course, if you missed any of the past events, tick Field Day YouTube channels a great place to find all of the videos.
Thanks for watching the Tech Field Day rundown. You can find new episodes every Wednesday as a YouTube video or on your favorite podcast application. The Rundown is also streamed on text on tv, and you can often catch up with us on other Text Strong or futurism group programs.
We'll be back next Wednesday to talk about the IT news and the week that was. And until then for myself, for Tom Hollingsworth and for all of us here at Tech Field Day, we're wishing you and yours at absolutely beautiful day.