Techstrong TV September 25, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, folks, is there an open source economic crisis? We're about to find out. You're watching Techron.
Hey, folks, we're back and we've got an awesome lineup. Again, talking about wealth. Some of the most interesting things that have happened in the land of app dev are all happening this week.
And we're gonna get started with this open letter from not 1, 2, 3, but four or five different open source associations, consortiums, whatever you want to talk, call them, complaining about the fact that they're paying for infrastructure that people are using within their software development life cycles, especially the package managers. Uh, and they're bearing the cost for all of that, and nobody seems to be helping them out, and it's costing tens of millions of dollars. And they're putting everybody on notice that either somebody has to help them fund this, or they're gonna start throttling access to those APIs.
Grima, I know you've been monitoring this whole space, but, um, what's your assessment of what's going on here? Because they seem to be pointing to large enterprises specifically and saying that you're abusing the privilege. I think, uh, I'll start from the basic and the fundamental, uh, shift.
And I wrote, uh, a article on this as well, new era of open source. But I mean, uh, going back to the basics, open source represents a paradigm shift, right? So collaboration, transparency, community driven, uh, innovation, our key to this, uh, movement.
But, uh, often open source is, uh, considered to be like access to free code, which is not the case, right? So open source, uh, describes that the software has to have the permission to use copy distribute, and either, uh, either to modify it or from a commercial standpoint, or it has to be free, right? So there are license implications, obligations to follow, and there are definitions laid out by open source, uh, initiatives like open source, uh, software, for example.
And I'm quite passionate about this space because if you see, uh, DevOps has been, um, the front runners to create, uh, innovative solutions in open source, uh, like for example, open Telemetry or Argo, uh, it's kind of contributing, uh, to a certain extent. Uh, a lot of innovative solutions which are coming to DevOps. Now, the difficulty which, uh, you referred in the article and the, these people who have been pointing out that there is not enough funding, uh, I had also pointed this out in my blog that, you know, why it is arising is that there is lack of centralized tracking.
15 billion, but the demand side is around, uh, 8 trillion, but there is no central tracking for it, right? And that's the reason why you see a lot of these open source initiatives are not well funded. Uh, there was another report which, uh, uh, I will quote state of open source report, which also highlights some of the operational pain points.
I mean, it's great to have an open source initiative, but they struggle to maintain, uh, security for examples. There are not e enough maintainers for the open source capability, technical support, for example. There are gaps in it.
Um, there are also lack of skill, experience, and proficiency in this area. So I, I think all in all, um, what it reflects is, you know, we are at a pivotal point where open source, uh, community, uh, drivers need to think about, uh, newer business models. You know, how we ensure that we get enough funded, uh, you know, projects and the funding has to flow in the right direction.
Uh, foundations like clinics, foundation, uh, CNCF, uh, CDF, they have done a great job, right, to protect some of the innovation and bring some funding to the, the space. But I think it's not enough. It's also like one other factor.
I I can go on and on on this topic, but one other factor, which I also see is single vendor-driven open source initiatives, I think, um, that needs to be thought through well, because, you know, it's, it's evident that, you know, those open source initiatives die down in the middle. And, uh, there is a specific commercialization aspect from the beginning or the inception stages. So what we see, uh, for example, with Terraform or Elasticsearch, these are like great examples, just like they now, these projects have been pivoting to a different, uh, business license.
And, uh, this is also reflective of the fact that open source community leaders have to come together to see what other funding models are available, what kind of business model we have to pivot to, to ensure that this whole, uh, open source innovation remains sustainable and well funded. And I know that, Robert, you come from that, uh, space. So maybe you also shared some of your thoughts on this topic.
Oh, for sure. That's, that's why I changed the title. Chopper of Wood and Carrier of Water.
You know, it's what we do in open source, right? It's based on the effort that you put in is the impact that you're having on the project. Um, and really the most thing, the, the thing that's valued the most in open source communities is contributions.
What this letter is calling out is that some companies aren't contributing. They're benefiting from this, um, and expecting not-for-profit organizations to pick up the slack while they make money off of it. And so this is a classic tragedy of the commons problem here.
So is as the use of Kubernetes increases, um, certainly every single one of those Kubernetes installations has to pull down containers. And where are those containers at? Um, and who is hosting those?
org, um, petabytes, um, the, as the, uh, that project becomes more and more popular, you would expect that if it was a private company, they would make more re revenue. Uh, so as EKS goes up in, uh, uh, you know, popularity, Amazon makes more money. Oh, it works out.
So yes, they're incurring more network storage, compute costs, but they're making more money off of it. Not-for-profit foundations that host these projects that pay for the CICD hosting infrastructure, they don't make more money. And so eventually what happens is it's not sustainable.
And guess what? All the companies that depend on that, and we're not just talking about technology companies, we're talking about banks, insurance companies, retailers, they should be very concerned about this. Uh, especially if they're using services that depend on this open source.
If they're concerned about these things being available and their business is dependent upon it, and they're paying a service provider to run this, I would expect that they, well, I would hope that they would demand from the service provider that they support these things because it is part of their value chain. It's just good business to, to support this. And unfortunately, with the tragedy of the Commons, uh, a lot of large companies that are making plenty of money off this say, eh, somebody else will do it.
So do we not know who's using this stuff? And I get that there's an issue here, but I'm not quite clear that an open letter was the way to go with this. Or could I not just call up, you know, the CIO of some of these organizations and say, you know, you guys, you know, maybe I'll send them in a little note.
It will say, you know, dear, CIO freeloader, you know, you're causing me issues. This is all gonna be, Well, it said a little nicer than that, Mike, You know, but Robert, I mean, you're right. I mean, this is just like a digital common problem at scale.
And you and Mike is exactly right about this freeloader aspect. Like, they're, like surveys done on this. Like, what is it?
But almost a hundred percent, like up to 97% of the users at open source really don't give anything back, whether it's financially code, documentation, bug reports, I mean, it's, and, but addressing it in a letter, my eyes kind of glaze over at these, these attempts, like in terms of any type of consortium or initiative, you almost have to go directly to the, to the, the, you have to go directly to the offenders, and you say, look, you, you need to change your, your approach. But, Oh, I, I agree. org, you know, with, with, you know, uh, and, and heck, I remember, um, a year and a half ago, Fastly making ane dash over at Fastly made a big announcement about, uh, 40 million a year, um, to open source projects, uh, with their Fast Forward program, and they really focused on the Linux Foundation.
So Colonel and CNCF Jenkins, um, certainly our friends over at Node, uh, open js. So, you know, what's missing from this is, I agree with you in an open letter, is is, is like a, a, to steal a line from, from Rick and Morty. It's like, you know, a, a a a temper tantrum to say you're quitting Twitter.
Um, it's, it's just like, okay, great. Yeah, do that. Yeah.
Yeah. And, and so what I would, oh, go ahead, Gina. The Problem on this, like, there are this, this is twofold, right?
So the funding pipeline, which we are talking about, right? So open letter is only a motivation to say that we are in trouble, right? But there is another thing which we should not overlook, is the payback models.
Why we should concentrate on both of them is it'll trigger a lot of open washing. It'll trigger a lot of fleet, uh, capitalism in the open source space, which we have seen with Terraforms of the world and elastic searches of the world. So I, I believe that, you know, I mean, I, uh, fully believe that these people have tried to approach enterprises and try to kind of trigger negotiations on how, uh, they can get the funding pipeline healthy, healthier.
But at the end of the day, it's a, it's a basic issue of, you know, we cannot sustain or survive with the same models, which were defined in 1980s. Uh, we are now have, having AI triggers, for example, the current contributors, like, how would you stop ai, uh, native contributions to these open source projects, right? Yeah.
We have to fill the security gaps. We, we have a lot more, like 95% of your code base, uh, according to a black deck survey is open source. So there is a fundamental issue.
The nineties low. All right, Tom, Tom, how far do we go with this? So let's assume that, uh, there has been some sort of communication and it's been roundly ignored.
Do these associations then engage in some form of public shaming to get everybody in line? I mean, how far do we go? Because, you know, other people are suffering because of, you might argue, gluttony.
Well, I, I think that you're right. These people probably did already reach out to the CIOs of some of the worst defenders. And and we've covered this a few times on the rundown where companies have come out and said, you know, Hey, Amazon, do you realize how much of our money that you're stealing every month by, uh, using our open source database in your product and basically causing backend hits on our servers?
And, and there's a, you are, right? There's a point where you get to where you have to just name and shame, right? And, and I think though, the problem we're gonna run into is that most of the naming and shaming is gonna be the same eight or nine or 10 companies that have, you know, huge workloads that they've built off of this stuff.
And, and in order to illustrate that perfectly, I'm going to steal this meme from the internet that has copyright images in it, and I'm just gonna broadcast it everywhere. Oh, what do you mean that I have to pay for that image? Oh, I, I don't understand licensing.
I don't know how it works. Why, why are you holding me accountable for something that I had no clue about? And that's kind of the game that they're playing, right?
Well, I, I was just using it for a project. I, I didn't realize that I had to pay if it was a commercial entity. What do you mean by commercial entity?
I mean, yeah, I make money off of your software, but not me. 'cause I'm just, I'm a small little mom and pop bookstore on the internet. And that's the, where you're getting into the, the trying to slice that, that pie really thin to get what you want.
Because to, to Gramma's point, we're using ideas from the nineties in the eighties of collaborative development and kind of this, um, for lack of a better term, touchy-feely development style, uh, in a world of cutthroat capitalism where if I can take a free piece of software and make money off of it, then my profit margin is infinite. And that's what developer or that, not developers, developers hate that, but shareholders love it. And that's what they want, right?
Is they want to build the biggest, most massive empire off of the cheapest, freely available things that they can find, and they'll solve that problem later. How many times have we heard that, oh, this is just a temporary fix. We'll, we'll, we'll make something better later.
They, they won't, they'll keep using this until they absolutely have to stop. And the way to do that, unfortunately, for open source developers is to play hardball and say, okay, cool, we're cutting you off. So, yeah, I suspect what you saying, oh, go Ahead, Tom.
I'm Sorry. I just wanted to respond to that, the project. Yeah.
So I suspect that they, that they probably did, as you said, Tom, they went through back channels and probably didn't have much, much luck. So they're escalating it up to a letter. And then beyond that though, how, how, what do you do?
Like, how do you affect change from these bad habits that have been lingering for years? You, you literally have to cut them off publicly. You have to come right out and say, okay, you are not allowed to use this anymore.
And if you do, you have breached the terms of the license and we will sue you. Now, if an open source project can't afford to keep the lights on, I don't think they can afford lawyers. However, there are luckily, a lot of lawyers out there that would love to work for one of these projects, um, and kind of make a name as the people who brought down Amazon or something along those lines.
But no, you're, you, you're gonna have to play hardball and all you, I was thinking it's gonna go legal, get one developer to lose. Yeah, if Amazon, Uh, not more, like, there are a few more, uh, steps which we can take. And I'm a open source advocate, and I'm, I don't go that strong as Tom is advocating for, but I think we, I think the central problem is that there is no central tracking for all this, right?
I mean, we'll have to get serious about that. The second thing I also would advocate for is start to look into what works for today's era, right? What licensing, licensing models like this late, uh, late shift to, you know, commercial models, why is it happening?
It, is it a trigger? It's, is it saying something to you? Because like open source help desk, uh, open source services open, like be more creative in, you know, uh, thinking through how you can solve these problems with new capacity, new service models, new initiatives, new services, right?
And these foundations need to think through, like hosting a project in their capacity and space is not sufficient. They need to also be creative in building that funding pipeline with, uh, the enterprises and have a dialogue of co-creation with these guys. I will tell you, it's all gonna break much sooner than you think.
So let's think this through for a minute. For every developer, there's gonna be 10 AI agents that are essentially 10 more developers paying, banging on these platforms, trying to pull down containers and whatever else it is. So I don't think any of these associations are set up to, uh, provide that level of capacity.
So it's probably only a matter of months now before some of these projects just keel over and break. So that'll force the issue. No, Well, they, they rely on the service providers, um, CDNs cloud to, to host, um, these releases.
And, and that's the real issue here, that as usage goes up, the, the foundation's revenue doesn't go up. So all the money is going back to these companies, which are ironically, or maybe not, ironically, making a lot of money off these, these things. Now, I will say this, there are a large number of these big companies that are supporting this, but not in a holistic way.
They are supporting projects that they believe are important to their company. So understand this, AWS is a huge supporter of container D. Um, maintainer works at A WSS and only works on container D not any AWS stuff.
Um, AWS also donates millions and millions to CNCF. So does Google, um, Microsoft, Oracle. It's the other things.
It's the other things that are, are, are crucial to this infrastructure that are neglected. Um, you know, it, it's, I don't think people understand that node is petabytes of data. It's really expensive, and thank God vastly stepped up for that.
But what about that long tail? Um, we need to get a holistic approach for this, and I would argue that the foundations need to get better at communicating what's in it for me. The, with 'em for the provider.
If you give us support and credits, we are gonna tell the world that this open source project uses you. And of course, you know, the sales people that big IT company, when they run up against the big bank, the big insurance company, and they question scalability, that company, that salesperson could say, well, you know, we help out this little open source project called, you know, the Linux kernel. I think we can handle you.
Um, they need to weave that story into help the company make more revenue. And with marketing, I don't think they're doing that. And, and that's an opportunity for our friends that signed that open letter to kind of lean in on that.
All right, folks, we can go on forever about this, but I'm gonna move on to the next topic. Just in one point, Hey, foundations are mad as hell and they're not taking it anymore. Now we'll see how it all plays up.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Techron Group. Hey, folks, we're back and continuing our conversation about interesting open source technologies. 0 is finally complete.
It's been worked on now for, I don't know, I feel like maybe a year or two. It's hard to keep track of these things, but web assembly, the theory of the promise at least, is that there is a file format that we're gonna be able to use so that our software as we build it, can run anywhere. You remember the promise of Java.
Well, you know, Wassom is trying to like, bring that whole notion back, and we're gonna write once and run it anywhere. At least that's the theory. And there's a consortium called, uh, by international that kind of heads up the, I guess, the development side of wasm.
And then we've seen the cloud Native computing foundation kind of step up to handle more of the runtime environments for wasm. And these things are supposed to be coming together in some interesting way that will drive some level of innovation. 0, we finally got a version that works.
And, and well, you're right, it is, it has taken a long time to get these, uh, features and new releases out. Um, and, you know, but remember, this is free. Uh, so nobody's paying for it.
Uh, uh, well, rather we aren't paying for it. Somebody is. Um, and, uh, but it takes time to do this.
You know, it, it, remember how long it took to get data persistence in Kubernetes. Uh, we, we went through several paths, uh, to, to get there. This release is really boring and necessary.
This release has got a lot of stuff dealing with memory and garbage collection, and these are the blockers for greater adoption. Um, and, and that's what's exciting about this. Um, you know, um, you know, gem is certainly far more of an expert about this than I am, but what I see here is that they're coming out prior to CubeCon, um, and, and being able to say, Hey, look, we've got a release out.
It, it's, it's a major release. It starts with a three. And, and so, um, you know, they're coming out and saying, we have solved a lot of the blockers to adoption, and that's gonna be really exciting.
Now, I don't think any of these features are, are, are, there's going to be issues with one, two, maybe all of 'em. But now that they're released, the companies that are dependent upon this stuff, and you're choosing Wasm as a platform for running cloud native at the edge, great, now they get to start looking at it and really pushing it. This is a good thing.
The more opportunities we have to take this huge body of open source and cloud native and get it to work in other places. We did it for web services, we did it for GPU workloads, now we're doing the edge. This is a very positive thing.
And yes, it took a long time, Mike, And well, we'll come back to that issue in a minute, but I just want to get Garima's opinion on this. One particular thing is, you know, what I heard from developers all the time is that they like this idea, but every time they put their hands on it, they come away with one impression. It's frigging hard.
And we don't have really a good set of tools for the developers to go make this, you know, dream a reality just yet. So do we need, you know, a whole nother rev of tools here for the developers to make this work? Yeah, I think it's very interesting times, uh, now, and we are talking about this AI browser race and all that, right?
So it all boils down to the fact that we will see a lot of action in the edge space, and we have to go cloud native at the edge. I articulate a few use cases for you just to kind of, uh, uh, for the viewers to understand why we are talking about this and why this is, uh, becoming extremely important in the age of ai. So for example, who is, who would be the potential users for web assembly?
Um, kind of applications would be like e-commerce platforms. 0 release because it enhances user experience. You know, if you think about, uh, uh, 3D configurators for example, or realtime image editors, uh, that it makes it more easier for e-commerce platform to adopt to that edge native capacity, right?
Then we also see a lot of like sensors and sensor based use cases for, uh, you know, get to the kind of real life. There's another great example, which I will use is, uh, web assembly, uh, in online ID platforms. If you see replicate, for example, if you have used it or Code Sandbox, these are great use cases where you can run compilers and interpreters in the browser, right?
So why this whole, uh, you know, the suite of features are important is that, uh, they have enhanced language support, right? And they also have, uh, done some performance optimization as, uh, Robert was speaking about the various, uh, performance enhancements, uh, regarding, uh, 64 bit addressing, for example, uh, memory space, uh, and so on and so forth. So I think it creates, uh, a lot of, uh, more capacity for the web ecosystem and the edge native computing itself, uh, which was resource constrained, uh, from the beginning, right?
Um, there are other, uh, aspects of this release, which are also addressing some kind of, uh, service serverless challenges in the past, and they have, uh, some, uh, advocate for some potential solutions, uh, in this release. So that is also a great start to kind of, you know, watch out for. All right, Tom, um, going back to what I was talking about on timing with Robert, uh, I get that this is a major undertaking and it has a lot of promise, but it has taken a long time, and I have a conspiracy theory that says that maybe, you know, we're just underfunding the effort required here because it's so disruptive, and a lot of players are like, yeah, we don't wanna rush this one because it's gonna change a lot of, uh, you know, who's the dominant players of what, I think you're right, but maybe not malice, just lack of thought about it, right?
Uh, maybe they're hoping, well, it's complex, people don't want to implement it because they don't know how to do it. And my way is easier, even if it doesn't do exactly what you want it to do, and we'll kick the can down the road a little bit further. Uh, I would rather them take the extra time, right?
How many times have we seen a standard get rushed out the door, or, uh, my favorite analog to this is things like operating systems, right? Uh, how many times have you heard from people, oh, well, there was nothing in that release of insert operating system here, uh, that really wowed me. So I, I I, I, I don't, I think they've lost the plot, right?
Like, there's nothing magical about this anymore. Um, I hear that literally every quarter when there's new release of an OS or every year when there's new release of a mobile device. And then going back to what Robert said earlier, yeah, sometimes what you have to do is you have to have the release that worries about mundane things like garbage collection or ensuring that when you install it on a certain model of edge router, that it's not gonna make it catch on fire and burn down a base station.
Uh, you have to do those things because that's how you make it a stable, reliable platform. It's like Debbie and, uh, releases. They're, they're built on old packaging because it works.
We've proven that it works, and I think that the, the companies that are kind of positioning themselves as alternatives to this standard are wanting to capture the early adopters. They're wanting to get people to jump out there and use their platform and write code that's more sticky to their platform instead of doing something that's more standardized, like using wasm. So I, I would hope that by taking the slow road, eventually this will emerge as the dominant way to do it, because it's the way that you can do it that doesn't require you to refactor your code every three months, and it's not going to cause massive problems with devices that adhere strongly to the standards.
All Right, Robert, is Tom right? Simple inertia, or is there something else at work here? No, he, he nailed it.
He, he paraphrased the quote that Miyamoto never said, which was a delayed game is eventually good, but a rush game is forever bad. Uh, you know, it, it's, you're, it, this takes time. And, and, and Tom, I agree completely.
Look, you're dealing with open source, you're dealing with a lot of different stakeholders, and they do it out in the open. You know, this isn't a small Tiger team that is releasing, um, you know, the first version of the iPhone, uh, and get it out. Um, it, it, it, and, and remember that didn't even have an app store.
Um, so, uh, you know, and, and it had that weird connector, strange, um, but look, it, this takes time, and I really appreciate that they're focusing on boring infrastructure, memory, languages, you know, that sort of stuff, because those are the things that are making it difficult to adopt their bet is that the tooling around that will get there. Our friends that make tooling for, uh, containers, um, you know, we would hope that, uh, our friends over at maybe vs code IntelliJ Eclipse would, would start building. Uh, and they already have this, but better, uh, tooling to use wasm.
Our CICD friends would start working on this. They, they've got a lot of great experience with Docker deploying containers. Let's apply this to wasm.
I Believe you can use Docker desktop to build wasm apps. And so they've definitely seen Perfect example of the tool vendors catching up. There You go.
Yeah, there is one more aspect to it is that this space is also evolving, right? I mean, if you think about devices or backend systems or, uh, language support, all this is kind of evolving at, at a great pace. And that is also a challenge for this kind of capability, which looks at portability, interoperability, performance issues, and engineer is not, uh, you know, easy to kind of deploy, right?
So it has its own nuances and, uh, it takes time to kind of ensure that everything is, uh, safely portable and interoperable. All right, let me, let me test a polling here of one. John Schwartz, you sit out in the valley, you, you hear, you talk to these companies all day long.
Anybody out there like even knows how to spell Wasm? I mean, you hear anybody talking about Wasm? No.
Zero. Um, but my takeaway from this is that although this might on the surface seem like some sort of incremental announcement, I think at the courts, pretty profound. I mean, and I, it's, it's basically this is a platform that's gonna support high level programming languages and allow for larger applications.
I mean, that's kind of significance, but I guess here, I'm in New York right now, but saying here, euphemistically in the valley, it's all about, it's pretty superficial, varnished, shiny objects, AI agents. That's, that's, that's the focus and the obsession, the stuff below the, uh, beneath the weeds or the, the, the, the mechanisms that make things happen, they're almost secondary. It's all about the surface.
All right, well, folks, I'm gonna leave it there, but I would remind everybody that if you wanna learn more about Wasm, do come to CubeCon. It's in Atlanta in November, and that's where a lot of these conversations will be taking place in like most revolutions, I think they started a long time before anybody actually recognized that they were happening. And I think this is the example thereof.
But meanwhile, we're gonna be committed to shining the light on Waza more and more because, well, we think it's a good idea, and we'll see where it goes from there. We'll be back in a minute. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. Hey, folks, we're back.
And the third block deals with an announcement that was led by Snowflake and a bunch of its partners for a new specification for a, uh, semantic model interchange format. And the idea here is that, and I'm, let me explain what semantic models are. First is a lot of organizations will take the terminology that they use to drive their business, or what the terminology that drives their vertical industry and put it into something that feels like a semantic model so that they can simplify interoperability.
And if you have this in place, it also makes it easier to move from one application environment to another. Now, the number of companies that have one of these is probably not that large, but more and more folks are thinking about building these things in the age of AI because they're gonna be needed to drive a lot of these AI agents, um, John, you know, snowflake and all these data management companies, are they the folks that are really gonna be supplying the, uh, picks and shovels that make all the money in this AI gold rush? 'cause it sure seems that way.
Yeah, I think you're right. I think you're right. That's what makes them so significant.
Um, and that's what I, I think makes them a pillar in a sense, like the Switzerland of the development. So yes, they are a key provider and they have created a niche for themselves like a few other companies have, um, where they work with everyone rather than work against someone over for a small piece of turf or some sort of developing, developing part of the, of the ecosystem. So, yes, absolutely.
Although, um, I was gonna ask you this, Mike, we've been talking in the previous segment about initiatives and letters. Do you think there's a lot of hef behind this one given the players? I think that the players are still relatively small.
I don't see a lot of snowflakes direct competitors are signing up for this just yet, but they are interested in having a chat with one of the consortiums about taking over the governance for this thing. And Robert, it seems to me, whenever these initiatives get started, those consortiums play a big role in getting the momentum going and the world. Absolutely.
Absolutely. Um, you know, if, if it's just one company, if it's just one company that's a steward of a thing, open source project standards, it makes the other people in that space nervous. They're concerned that that individual company has too much power.
So when you place that company, instead of owning everything and controlling everything, puts it into a place where others can provide input, that actually increases the surface Area. And so it, it's basically, we're going to turn this over to a neutral third party that is gonna oversee this and make sure that we all follow the rules that we agree upon. And so we're all gonna collaborate on this thing, and then we're gonna go and do our own thing to make money off of it.
It actually is the weight is the best way that we have, uh, there's always areas for improvement, but currently it's the best way that we have to collaborate and well encourage collaboration and bring people in and lower risk for those other companies to invest their time and money. Yeah, there's not a lot of critics available, uh, around this, uh, announcement yet, but I opened this forum for some critical comments, and I think Robert has pointed out a very good point. Like, you know, when a competitor or a specific company dominates to, you know, build up a standard, it's no longer a standard, right?
So it'll be very, very interesting to see how this translate into a third party vendor neutral consortium based, you know, movement, uh, adoption as well is also something which I am looking forward for, like how companies applications, you know, suite of enterprises would adopt to this kind of, you know, open standard is another area, gray area as is today and implementation, like how the implementation will happen. Like, this is all fancy, like looks good on paper, but implementation is the real meat of the conversation. So you've got to have real people who can do the job for you.
So you will have to have, you'll, uh, have to go beyond a founder driven roadmap to a community driven roadmap for this. Mm-hmm. Tom, I have a pet theory and it goes something like this and I'll grant you, it's another conspiracy.
But, um, in the rush to support AI agents, and we need to make data accessible to these things, we have seen movements to standards like this one. And I'll add in, uh, MCP and A to a protocols and all those things. But an interesting event might occur on the back end of all of this.
We're gonna turn all these data platforms that we've found ourselves locked into over the years. We'll become replaceable. They'll become disposable because they'll be able to pull data from them dynamically as needed.
And maybe AI is finally gonna set us free from all these data lock-ins. What do you think? Am I crazy?
You're not crazy, but I think there's a little bit more to it than that. I love the idea of being able to finally escape from the chains of the database that's been silent silently, toiling underneath the, the hood this whole time. But the problem is that companies have a way of building in, you know, additional features that allow you to, uh, take advantage of some tweaks.
Uh, my, my favorite is from the networking world, that while OSPF is a standard R protocol, nobody's OSPF is identical amongst any of the implementations because they all do something a little bit different to handle corner cases or increase performance. Because it's, one of the other things that I'm hearing from a lot of companies is I, uh, do research into AI security is that a lot of these data platforms are kind of monolithic and built in a certain way to do things in a very certain like cadence. And when you need it to do something other than that, you eventually end up having to build your, your own version of it because you need, you know, better performance for record retrieval or something like that.
Or the, the snowflake can't mung the, the data the way they want it to, and, and then they go out and build their own. And then they realize that maintaining their own is stupidly hard. And by that point, hopefully, uh, a more standard model is, uh, caught up with some of the features that they need.
I, I think that ultimately what's going to happen is that companies are going to agree on a set of standards that everybody should adhere to, which is what the whole standards body should be, because they don't want to do the hard work of programming a better solution on the underside. They wanna sell features to companies that are gonna buy on, you know, the, the front side, right? Um, you know, it, it allows you to, I don't know, solve the riddles of the universe or I, I don't know, make sure your CEO's never late for a meeting, but that means that the data on the back end has to be consistent.
It has to be usable, it has to not exist in some kind of weird foreign SQL language that nobody understands anymore. And that part's boring for most developers. So we all just agree we're all gonna use this database even though we hate it, because the best one we've got right now, 'cause I don't wanna write another one.
Grima, do you agree with that? Were you just putting up with the database though? I think, uh, this is great arguments, right?
And, uh, again, uh, there are flip sides to both, uh, uh, if you don't put implementation meat to all this, it becomes a checklist item, right? So who invest in those standards? So I think there is a right balance to be found, and this is to be found by the community itself.
I mean, that is the beauty of, you know, all these standards and open source initiatives that once the community buys into this, I think it'll all, um, you know, already be evolving and trying to kind of foster the need in the right direction. John probability assessment that I'm gonna see Oracle anywhere near this project. That's a good question.
Wow. Yeah. With them, you never, you never know whether what, whatever they tell you.
Um, that aside, um, this was, I think its going back to think where something Robert said, this is a very savvy move by Snowflake. You know, you, you, you, you collaborate with others and then you benefit in the end. So, um, I, I, I think there's a high probability of of success here.
I usually, I'm usually really down on consortiums, but this one, I'm, I, I think there's some upside. Wow. Robert, I'm always reminded of that saying, uh, if you wanna go fast, go alone.
Yeah. If you wanna go far, go with a team. Mm-hmm.
So Robert, you've been around these projects before, um, you know, it's interesting to me that they launched the project before they went to a consortium. So, um, to what degree are they just trying to force somebody's hand here and then they're just trying to force an issue and maybe whatever we come up with won't even look anything like this thing, but, um, how much politics is at play here? No, it's a thousand percent.
It's all political. All political. Yeah.
It, that's a hundred, a hundred percent. There you go. I mean, look, it, it is, um, they wanted to get this out.
Uh, you can see a lot of these announcements leading up till Q con because they want, they know everybody's gonna be there. So let's get it out there and we could talk about it in person. Um, and so this is, look, anytime you start working with, um, your partners, other ISVs, bring 'em in.
Uh, that's a good thing. But I think that BlackRock getting listed there, that's really interesting. Um, and they worked really hard to get an end user, um, involved, you know, with, with some, with some brand.
And BlackRock is great. They love sharing their opinion, uh, good, bad or indifferent about technology. They're, they're, they're awesome about it.
And, um, so I, I think that this was their way of just getting this out. This is where we're going. Would you like to join us?
And so I think part of this was to get other people to join. I don't think it was to, you know, warn anybody. I think they're committed to this.
I think they want to make it successful. And I believe they announced it so that they could get more support, multiple hands make for shallow bugs. I'll play a devil's advocate here.
And Robert, you know, this game, right? Um, we have played it, uh, many times that, you know, standardization, um, all always relies on the fact that what is the intent? If the intent is capitalism, it would not fly.
So I think, uh, there is some course correction and some learnings which needs to take place because, um, uh, if you see, uh, how the community will join in this movement is the reputation and the intent, and, uh, the aspects that, you know, how do you invite the contributors in the space, right? So I, I believe that there will be some trigger points if they really want to make it a success. They would like to bring in people who have high credibility and reputation within the community to drive some initiatives, right?
They need to, uh, focus on how to build a broader capacity with community, right? So how that contribution, uh, takes place. And then the third aspect is intent.
You know, the intent need it is needless to say, if it is commercialization or capitalism, it wouldn't fly at the end. I think I do. I I do think that, oh, I'm sorry, Mike, I just wanted to, to add to that, you know, you're, you're absolutely right.
Rema, I bet you the big takeaway from this, what's happening right now, now that this is, has gotten announced, is that everybody that competes with BlackRock is looking at this like, well, wait a minute. If BlackRock is doing this, maybe we should. And that's much more powerful than the tech companies getting involved.
That's really interesting. A lot of conversations in Jersey and Long Island, Connecticut and Manhattan happening right now. I think that Tom has the right point.
There is a lot of end users who are just p****d off and fed up with IT companies that have taken their data and locked it up for them, and they can't get to it. And I think that, you know, there's gonna be a movement around this. And this may not be the specific specification that drives it, but it is an ongoing conversation.
And so my prediction is we will see the launch of something called the Data Freedom Foundation, gave me all these kinds of little projects around One notion is that the data belongs to the people who created it and not the people who provided the IT platform that housed it. 'cause people are getting angry. And you, and, and as you can see, there's a, there's a trend around that whole topic for the last three series.
So anyway, I wanna thank our folks for sharing their knowledge and their expertise today. As always, they were great. And I wanna encourage you all to stay tuned for the next lineup of the Techstrong tv, uh, portfolio of shows that are coming up right behind us.
They're all equally awesome. And thank you for spending some time with us. We'll see you next time.
Hey everyone, welcome back here to Tech Drunk tv. You know, I've been trying to get this next guest on our show for since the summer, and it's already almost the middle of it's past the middle of September between my travel and his travel and scheduling. It's just his people Couldn't get my people to make these people get it together.
But we finally did. I'm really, really happy and proud to introduce you all to Imron Khan. Imron is the Chief Customer Officer at suse.
Imron, welcome. Thank you, Alan to Tech Drunk tv. Yeah, Thank you.
And I'm, we finally got here. Yes, we did. Better late than ever, my friend.
Better late than ever. Hey, Imron, before we even start, I got a personal question there. It's not personal to you, but it's a personal question to me.
I am always caught in between, and it's probably been my funny French accent, suse, soa. I've heard it pronounced all different ways. How do you pronounce it?
I pronounce it as soa Susa. Okay. We're gonna go with Susa today until I'm told differently.
Very good. Fair enough. Mrad, chief Customer Officer that cov that title, can cover a lot of sids.
Give us an idea of kinda what actually you as chief customer Officer at Souse does, and maybe a little bit of your personal journey journey getting here. Yeah, sure. Thank you.
Um, Alan. So, um, I, as you said, I'm the chief customer offer for suse. Um, so what do I do?
I I look after our customers, right? So I manage all of our post-sales organization, our support, our services, our customer success folks, um, and anything to do with the customer experience. That's pretty much what I look after Atsa.
Um, my journey, I've been with SUSE for about three and a half years. Um, I came from another software vendor called BMC Software, um, sure. Where I was their Chief Customer Officer, uh, for a number of years.
I think it's just over five years. Prior to that, I was a, a supply chain software company called JDA software, which is now Blue Yonder. And prior to that I was a hp.
Um, so yeah, I've been in, I've been in this world now for a, for a little while now, always in the customer facing kind of activities. Very cool. Yeah, no, very familiar with BNC, actually, the CEO.
And I'm, I'm old and I'm drawing a blank, I apologize. But he came from ca. Oh, I'm in sae.
Uh, I'm all right, I'm on Saeed, so I know, I know I'm on. Well, I know him from his ca days actually even. Right?
What a, a great gentleman. I, I enjoyed interviewing him. I always enjoy any time we get a chance to spend any time with him, but they built a great company there as well.
Um, but Imran, we're here to talk about SUSE today and and you're obviously eminently qualified for this chief customer officer role. As we were talking off camera, I was mentioning, you know, depending who you talk to, you ask them who's Susa? Some people tell you, oh, they're an open source company.
Other people tell you, oh, they're the Linux company. Other people say, oh no, they're cloud native. They're the cloud native company.
Of course, in recent times we've added AI and there's a security element and there's more. If, if I had to say, Imran, I'm going to give you 60 seconds. Tell me who SSA is.
Yeah, no, that's a great question. Um, uh, so suse, we, uh, open source, uh, primarily, um, uh, Linux, absolutely right Edge ai, um, as well as cloud native. Um, so we do all of the above, right?
So you're absolutely right. And I had the same, I had the same experience when I joined suse. I had to go and Google them and go to their website to um, uh, kind of figure out exactly what portfolio they covered.
'cause there was so many. com to actually look at our extended portfolio. Absolutely.
But they, there, there are building blocks, right? Open source is, is fundamental to the DNA there. It's kinda Absolutely.
It's your heritage. Yeah. Uh, as is Linux, right?
One of the probably early foundational Linux distro providers, right? Uh, through acquisition and, and, and really support of CNCF Kubernetes containers, really a cloud native, native company, if that's a word or a phrase, right? Um, early into ai Yeah.
Big adopters and, and, and prevalent of ai. Um, it, it's interesting, you know, when you layer these up, and then I I, I'm gonna throw one other thing at it, and, and it really goes segueing into our topic of discussion. SUSE is a European based, it's a global powerhouse, but proud of its European heritage ly.
Absolutely. Right? Absolutely.
And, and I, and I think that is also part of that DNA that makes suse Susa. Yeah, you got it. Absolutely.
And that's, and you know, back to, we are very proud of our, uh, European heritage, and, and you're absolutely right. We op offer, um, operate globally in multiple countries, uh, multiple regions across the world. So it doesn't actually hold us back.
It actually makes us more stronger, especially with the subject that we're gonna cover today, Especially in this day and age. It's not a bad thing. Um, Imron, let, let's talk about that subject.
Suse recently, uh, you know, a month or two ago, uh, announced a, a big push into, uh, digital sovereignty and, and, you know, sovereign IT as what's being called now, sovereign it, uh, operations, sovereign IT solutions. Talk to us a bit about that. Yeah, no, absolutely.
Um, and one of the things we announced a, a new offering, um, way back in July when we were first meant to talk, um, when it was fresh off the press. And some of that was driven by customer demand as well. And, and as you mentioned, digital sovereignty is this kind of like three pillars to it, right?
Which is around data, technology and operations. Um, we'd already started the journey on some of our data and operations based upon customer demand. Um, but it was something that was kind of like more of a prototype because they wanted to know, look, how are we gonna ring fence their data and how we are gonna ring fence the operations and how we actually support them as a customer.
Um, but then with all the kind of global stuff that was going on, um, uh, you know, it was something that we needed to formalize as well, right? And this is why we actually came up with our, our effectively our sovereign offering of premium support to make sure that we understand exactly what our customers wanted and how we could actually make sure that we kept them, you know, sovereign as I would say. Absolutely.
You know, and, and look, there's a lot of macro factors that are driving the, the sovereignty issue, I think one is, is obviously political turmoil. I I don't wanna say turmoil, political, uh, well let's say turmoil, I can't think of a better word, but, you know, uh, political uncertainty, right? Yeah.
Let's, let's say that political uncertainty we're here in the US obviously, I'm here in the US recording this, and it seems every day there's a new headline about a different direction or what's on again, off again? Tariffs. No tariffs, who's our friends, who's, it's, it's certainly interesting times in terms of world, uh, you know, relations.
We have the EU arising as you know, it's a multipolar world that we live in. Yeah. And the EU is certainly one of those poles, right?
One of the powerhouses. And, and in many ways, especially when it comes to technology, seems to have more of a political will to get things done rather than a sort of laissez-faire, just, you know, let it happen. Um, you have the age of ai, AI's, you know, it's changing everything.
As, as you well know, as SUSE is on top of it. It's creating all new bedfellows, if you will. Um, increased competition, supply chain, shortening supply chains, you know, people having coming outta post COVID out in the pandemic understanding about supply chains and, and wanting to shorten our supply chains.
All of these things are driving the sovereignty issue. Let's peel back the layers on Seuss's offering here. What, what, what exactly is it?
Why does it work? Yeah, so this was born out of a, a customer request. Um, whereas they wanted to make sure that we ring-fenced their data.
Um, and we actually supported them through EU employees. Um, and obviously having a global organization, um, sometimes we have a follow the sun model. We have, um, you know, with regards to support to make sure they get 24 by seven support.
We kind of leverage the infrastructure that we've got around the world to actually make it more effective for the customer. It gave us a challenge. Um, so what we had to do was ring fence their data in Europe, set up a localized EU support center that could do that coverage, um, to make sure that we were actually meeting their needs and give, and make sure that they could actually tick off their compliance as well.
The good news is, is that we had a level of experience of doing this. One of the arms of our, uh, company is called uh, uh, Rancho Rancher Government Solutions. Um, so we were used to actually doing that.
And Rancher government solutions is, obviously, it's in the us it supports the federal government and a lot of activities out there. So we had some experience of doing that where we'd ring fenced a lot of that infrastructure as well. So, um, it was a, it was a company called OVH, uh, cloud, um, that actually came with the request to us, and we actually built that for them.
Um, but then when, as you rightly said, with the uncertainty of the world, um, and some of the political drivers, it was an offering that was required, right? So we were able to actually take that and actually kind of make it more of a prescriptive offering. So that way now they get localized support, localized contact, localized engineers, everything is actually, as I said, ring fence from that perspective.
And it's dedicated support as well. Um, and you know, we've got a number of different contracts out there now. We launched it hard launch in July.
As I said, most of it was actually requested, uh, prior to that by some of our, our European customers. And now we're actually gone to market with it as part of, uh, one of our offerings, which is the three pillars that we spoke about earlier around sovereignty. It covers data and it covers our operations.
And we're doing a lot of work within our product organization as well to make sure that we go down the same route on the technology side as well. I love it. You know, one, one of the challenges around this digital sovereignty, uh, space is there's different aspects to it.
One is where is that data that you're, what was the term you used? Ringed, Ringfenced, Ringfenced. Where is the data that's being ringfenced?
Where is it actually stored? Is it, you know, is it in one of the hyperscaler cloud providers? Is it in a private data center?
I, I'm not aware. Is SUSE running private data centers now, or are, would you have partners who run the, the, where the, the, the, the physical plant, if you will? It's all on our data centers.
So You wrote, so SUSE owns their own, operates their own data centers. Yeah. It's, it's our own.
Yeah. That's great. It's our own.
So we worked with our own IT organization to make sure that we could actually have that, to give that level of comfort as well. That's fantastic. You know, we were talking off camera, I, I wrote an article a couple weeks ago about the long arm of Uncle Sam, right?
If, if you're, you could have a whole digital sovereignty ring fence situation, but if you're hosting it in a data center owned by a US company, a US based company, and the US government makes a demand on that for that data or access or what have you, the US company may very well open the, the kimono, you know, give the, the government, the US government access to that data. And, and that sort of defeats the whole purpose of digital sovereignty, doesn't it? Yeah, absolutely.
To me, that's just like a, no, it's just a glossary on front of what they're actually proposing. Um, and that's the difference between, um, US at Susa, right? We've actually got it end to end.
Um, and that's what makes it more powerful. And it's right what I said right at the start, um, our European heritage allows us to do that more. So, Absolutely.
You know, Imron, there's, there's an aspect of this whole sovereignty thing that makes me sad. Uh, you know, I, one of the greatest joys I've always had on the internet, and I've been on the internet since it went commercial, right. And probably before that a little too.
And, um, I always get a kick out of, even today we do webinars and stuff, and I get people who log on from, from India and Singapore and Australia, New Zealand, and Pap New Guinea, as well as all over Europe and Nigeria and South America. I, even if, and I luckily I, I've had a chance to travel and see the world. Yeah.
But it still gives me joy to see the whole world joining up Right On at a webinar or some event with sovereignty. I feel like we are balkanizing if, if you will, the internet a bit. Is that the future?
Are are we gonna go back to a global thing, or, or is, is digital sovereignty the, the way of the world now? Yeah. And that's such a, and you know, uh, you know, not that that it's use this as a therapy session, but I I, I, I have the same like-minded thoughts as you, right?
So now I've worked for global companies for the last nearly 30 years of my career. You know, having, you know, offshore locations, onshore locations across the world in countries that some people can't pronounce. Um, and I loved it and I enjoyed it, and I still do today.
I think with regards to the future on sovereignty, you know, it's like what you said with regards to this uncertainty, you know, who knows how it's gonna play out, right? I hope it doesn't go too hard in that direction, because I think we've done a good job in the world that we live in today, actually kind of unpicking those borders, if that makes sense. Um, so that's my own personal kind of view on the subject.
I think we're of a like mind on that. Um, so obviously the digital sovereignty offering is available in the eu. Yes.
What about other parts of the world where, you know, where is this also available? Yeah, so we started with the eu 'cause that was the biggest kind of request for demand that we had. Um, but we are looking to actually go and push it out into different locations as well.
So we're looking at other territories, and most of it is gonna be demand generated, right? So once things start to pop up elsewhere, there might be situations like, we've already doing it in the US with regards to our government services arm, right? As I spoke about.
Um, but there might be other areas as well that we actually look to tap into whether it could be contagious, right? So that before you know, it, Latin America might start wanting sovereignty rules and regulations based upon some of the things that are going on in, in the world today as well. So I think there's an opportunity for us to actually roll it out depending upon where, where the demand sits or unpick it, depending upon what we just spoke about, right?
Yeah. That, that true. Absolutely.
You know, I'm just sitting here thinking too, is we, we spoke about who is suse before we said Linux and open source cloud native ai. We didn't mention that you're operating your own data centers, that you're an infrastructure provider as well. So, you know, I, I think that's one of the, uh, best kept secrets, if you will, in technology, is really the, the full scope of SUSE's offerings, right?
And we only have 15 minutes here, but we could probably spend a day jumping in, you know, you mentioned rancher gov. You know, there's more I to, I totally agree with you, Alan. com to look at all the extended portfolio of what we do.
'cause I thought it was just the Linux company at that particular time. And I remember speaking with some colleagues of mine, ORX folks that I'd worked with in the Bay Area who said, oh, no, you know, they've got, they've got containers as well. They're, they're really big into Kubernetes.
They just acquired this, this company called Rancher not so long ago. So the more I double clicked on it as well, the more I realized we were a really good kept secret, um, and we're a little powerhouse all by ourselves and, and, you know, ultimately open this video, we'll do some of that. The more we can keep on pushing our message out to actually realize what extended portfolio that we have to offer, uh, the, the better it is for us as well as Susa.
And, and I thank you for your, for your pushes for us as well. Um, even at our customer event earlier this year. I appreciate it.
No, was I, I was telling you off, it was one of the best events I've attended in the last year. I really enjoyed my time there. Um, m Rudd for people who are watching in insane, this is just what I'm looking for.
How can they, how can they get more information and maybe, uh, you know, move along the path here with this, uh, digital sovereignty offering. Absolutely. com, it's all on there.
You'll see it. We've done a number of different publications around it. This is obviously one of them as well.
Um, we keep on pushing the message out. We are there, we are ready, ready to rock and roll. We've sold a number of contracts already, um, and we see the demand increasing.
com, you'll see everything you need to do, um, to actually buy the offering as well, as well as look at our extended portfolio. Thank you, Imran. Thank you for coming on Techstrong tv.
You know, I think I'm gonna add another thing to the Susa kind of DNA and that is opportunistic. When SUSE sees the needs in the market, they fill it, right? And there's a great example of it.
And, and the, the whole way it came about from a customer asking for, it says a lot about the product process there, right? When customers ask for things, you provide 'em. Absolutely.
And thank you. And I'd love to come back on the show again, Alan, Anytime. Let's not wait three months to make it happen, but we will.
And we're going to, we should give a quick shout out. Uh, Han's gonna be in Prague in April, which we'll be here before we know it. Hopefully we'll talk to you before then, though.
And, uh, we'll, we'll try to do something from there as well. Absolutely. Thank you, Alan.
Really appreciate It. Thank you. Imran Khan, chief Customer Officer at suse here on Tech Drunk tv.
We're gonna take a break, go check out their digital sovereignty offering, as well as their rancher containers, Linux, and even data centers. But we're here on Tech Drunk tv. We'll be right back.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. I'm your host, Mike Baard. Today we're with Daniel Barden Stein, who's CTO for Manifest, and we're having a chat about the need for software bill of materials known as SBOs for ai.
Daniel, welcome the show. Thanks so much for having me, Mike. Pleasure to be here.
Alright, we have what's known as SBOs that are gaining some traction in the traditional world of application development. At least we think that folks are doing the right thing, and we're getting a little progress on DevSecOps. But, um, in the, in, in the world of ai, what's different here about the way we need to think about a software bill of materials and, and what should people be kind of working through?
So about 18 months ago now, I embarked on a, uh, a bit of a research, uh, adventure with a, started with a very simple question, which is, given that SBOs are taking off as this globally accepted way to think about software, supply chain and transparency and software, how much of this applies to ai? Right? There are many of us in this space who believe that AI is in many ways a subset of software that you can't build or use AI without putting it into software.
Therefore, how much of those common risks that we think about on this, uh, for software supply chain applied to ai? And after consulting with hundreds of experts, much smarter and more technical than myself around the world, it became very clear that many of those same classes of risk that affect organizations around the world, um, that most people think about when it comes to software supply chain security, also apply to AI security. Um, and I'm sure we'll get into the details, but everything from thinking about sources from open source risk, third party risk, continuous monitoring, lineage licensing, all terms that if I said them in a securities software security context, CISOs around the world would say, yep, I understand what all those things are.
And then you turn around and ask, so how do you plan to tackle that for ai? And most CISOs would probably scratch their heads and say, I don't know. I don't have a tool to do that.
Mm-hmm. And, uh, and, and I think this is all also bolstered, bolstered by two fact, or one fact, and one piece of news, to your point about the adoption of SBOs, even last week, cis a published, um, uh, uh, a document that was co-signed by 19 different governments around the world, all effectively endorsing SBOs is a very powerful tool for software supply chain security workflows. And the other fact that that makes us all the more urgent is we all know that whatever percentage it is, 90 plus percent of CEOs around the world are basically telling their companies to accelerate AI adoption as much as possible.
And that's putting security leaders in the bind because they don't have the tools and processes to catch up with this rapid, rapid proliferation of AI systems. If I do have an s om program in place, can I extend it to ai and is it really just another piece of software or a different set of art artifacts, or am I gonna need a separate framework for AI? And s om, That is exactly why we kicked off the AI SOM working group under ssa, of which I'm, uh, one of the co-chairs to help answer and educate the, the public on exactly these questions.
So it's my goal that people shouldn't need an entirely different set of processes or frameworks to handle this stuff. The last thing an enterprise security team needs. You know, I think the average enterprise security team has somewhere between 15 a hundred tools right now.
The last thing I need is to multiply that number by two, to have an AI flavor of their endpoint tool and their firewall tool and their DLP tool. But They, they will Need existing tools to adapt to the in, uh, intricacies of generating AI bumps, scanning models, scanning data sets. There are different types of risks that we're looking for and different ways of searching for those risks.
And so what I continue to, um, advise security leaders, both in public and private, uh, industry, is as much as possible user existing processes and frameworks. But you need to be able to think about some of those more tactical bits, the ingestion, the scanning, the monitoring a little bit differently, um, as it pertains to AI security. But ultimately you want something integrated because even if you've developed the best model in the world, at some point you gotta put it into your software.
And so you need to have those two things integrated rather than having two new siloed security systems. What level of depth can I get to? Because a lot of times somebody will, for example, build an AI agent and then it's invoking an API to an LLM somewhere.
But how do I know what went into the LLM and how do I discover that? Fantastic question. So one of the things that we've been hard at work at building is, uh, basically an AI bomb generator.
So that, for example, helps our, um, partners and customers get from a model that's pre-trained, that's out on a hugging face into a robust history and lineage of how this thing came to be, what data sets it was trained on, the lineage of the data sets, who put them together, how are they licensed, et cetera. So we can help organizations already go from, here's a Google Bert model or a Meta Lama 3, 1, 3, 2, whatever it is, and get to a very robust story about what is this thing, where did it come from? How's it built?
Can I use it legally for my specific use case? Um, when it comes to something like, uh, an agent system or an MCP, this is, uh, another great use case for why we want these tools integrated with software analysis tools because an agent at the end of the day is just software plus ai. It's a little bit more recursive, but we wanna be able to scan source code to figure out what APIs is it calling?
What tools does it have access tool, what credentials might it have? How do we put guard guardrails around that? So it's another great example for why, you know, an S bum isn't the the cure to all security evils, but it gives a very, uh, robust and structured account of how something is built and perhaps what it can do.
And that's why it applies so well to models and data sets. And then the ultimate vision here is not to create a brand new artifact, but you know, I'll, I'll provide examples. You know, we work with a next gen defense contractor that's actively being asked for a IS bombs from their government customers.
And so what they end up handing over is one software bill of materials that not just lists the normal dependencies and licenses that they put in their software, but also the models that are included as well, and how they were trained in information about their providence and lineage. So the goal is not to recreate a new framework, a new standard here, it's making sure that organizations have the abilities to ask questions about their ai, their models, and their data sets, and then put them into the formats or compliance artifacts they need to actually do something with them. Hmm.
How will we keep up with the dynamic nature of some of these applications? 'cause I'm likely to have multiple AI agents that will eventually invoke multiple LLMs and the LLMs may change, and it just seems like the pace and the rate of change is gonna be very high. So how do I kind of keep track with all the updates and changes to the underlying software In the same way that we do already with traditional software?
Like more, uh, very mature modern organizations with modern CICD pipelines push software to production multiple times per day, certainly much faster than LLMs are going to be regularly trained and tuned. And so it's another example we're learning from AI security and how to get a, you know, take a big step should come from what we've already been doing on the software side. So if we look to the software security side, how do we make sure we are regularly scanning code, given that it's now being written even faster with tools like Cursor and, and rept is, we have automation in the CICD pipeline.
So as developers write code and they push the code, there are a bunch of scans or processes that kick off that find various types of risk enforce policies, and then help tell the developer, Hey, you need to go fix this thing, patch this vulnerability before this goes to production. We just need to replicate that on the ML side of the house. And we've also already seen success doing this as well, right?
Whereas we have the CICD pipeline for software. We have the ML ops pipeline for AI and ml. And so in the same way that there are automated tooling that helps developers write code quickly, find issues and fix code, we need to replicate that for model developers.
So if I'm fine tuning a model or updating a model or quantizing a model, how do I understand if there's anything that I'm doing risky as I'm doing it, or find issues automatically that get pushed to me before I've finally saved this model and put it in my model registry? So at the end of the day, it's all about automation. It's all about plugging things in as far left as possible.
And ultimately, again, we're trying not to recreate the wheel when it comes to AI security. There's a lot we can learn here from existing software supplied, uh, software security analogs. Should we be working towards, um, unifying these pipelines a little bit?
'cause I think in a lot of organizations you'll see, you know, something that looks like a TIGER team is off building an AI project and they may not have the security best practices in place. And in fact, many of those data scientists probably know less about security than the average developer. But, um, should we be rethinking all these workflows to bring our existing pipelines and DevSecOps workflows and apply it to the development of AI applications?
A short answer is absolutely yes. We continue to see examples where you have employees, or like you said, small groups just going off and building application, uh, ML enabled applications that may not have, uh, security best practices in place. We've already heard and seen stories of people that try to circumvent compliance needs for AI ML by, you know, doing various sorts of trickery.
Again, ultimately, again, just like with software, we work with some of the largest organizations around the world, and they have often have different business units. And each of those business unit is often treated like a, you know, special snowflake. They have their own processes and tools inside the business unit, but you still often have a central security team across the whole enterprise that's responsible for making sure that there's consistency and inventory and scanning across the business units.
We need the exact same thing for, for A NI ml. So how do we make this happen again? The last thing we wanna do is slow down innovation to get in the way of data scientists writing, um, you know, developing new models for their use cases.
But this is where automation and integration are so key. So as they're doing their work, there's tooling that's in place that can tell them, Hey, you tried to load a model that is unauthorized, or this data set that you tried to use from the public internet isn't licensed properly. So you're able to alert them to issues before they go deep on training them.
And then I think the fundamental issue that most organizations are still struggling with here, which is the most foundational, is inventory and awareness, right? You can't secure what you don't know about. We all are familiar with the concept of shadow it when the cloud became big 10, 15 years ago, now we're dealing with shadow ai.
How do I know what models are being used across my enterprise? How do I know if we put some custom model in a medical device that the cardiology business unit wrote it or the, you know, pulmonology business unit wrote it. Organizations just lack basic inventory and awareness about what are the models and data sets we have across our enterprise?
Where did they come from, who built them, where they're being deployed? And, you know, asset management is a hard problem as you know, um, but that doesn't mean we can't help organizations try to take a big step forward on it when it comes to ai. Hmm.
Most of the AI software that I know is pretty much built using the same tools and components that we use to build other applications. So they would naturally have the same vulnerabilities. But are there also unique things that people should be looking for in AI applications that are attack vectors that they might not be thinking about?
Fantastic question. So as most people probably know, models can have traditional software vulnerabilities just like software. Can we think of your pickle serialization or pickle to serialization threats, for example.
You can exploit the software itself, but there are lots of other issues when it comes to other types of business and legal risk when it comes to models. So for example, responsible AI licenses and traditional software licenses. We think, you know, permissive Apache two is good strong copy left.
LGPL is bad with AI licenses. They're use case specific. And this has already caused trouble with some very large, um, companies and government agencies where I might legally be able to use a model like Llama three one for something like summarizing emails, but I can't use it for anything with heavy manufacturing or defense or military or biometric applications.
And so there's a signif a significant amount of legal risk based on how you can use this model. It goes even deeper than the model because it also depends on the data sets. So we worked with some very mature organizations that aren't allowed to use models that were trained on illegally gotten or improperly licensed data sets.
So again, we're back to kind of a legal business risk because if that gets put into a product or a weapon system or a plane that might have to get ripped out at some point and, you know, ultimately cause revenue lost for, for organizations, you also have other sorts of, um, traditional supply chain issues. Like when Deep Seq was announced, many people found various types of bias that, you know, the, the Chinese authors of the model may have written into the system prompts that would affect its output. So understanding who the supplier is of the model and this dataset are they trusted, especially for those who work and sell with the Department of Defense in the us.
Um, there's just a, a memo that came out a few weeks ago saying that there can't be any nexus to China and Russia in DOD acquired systems. So there's a compliance burden. Um, and there's a, just like with software and the concept of, of Lineage and Providence, the same is true for, for models.
There's a story with one of the world's largest IT companies that had an explicit ban on, um, a model like Deep Seek, for example. And there's a user in a business unit that really wanted to use that model for a use case, took the model from the internet, uh, fine tuned it with some lightly with some data, and then declared that he had a brand new model that wasn't related to any noncompliant models and tried to get that one approved by his compliance team. So again, going back to there's yes or traditional security issues and exploitation of models and data sets, um, your prompt injections, your data poisoning, et cetera.
But there's a whole raft of new issues around business risk, around legal risk, around compliance risk as well that comes with models, data sets. Because at the end of the day, these things are black boxes and we need to understand how they were built and how they were trained. Mm-hmm.
Under the heading of physician Heal thyself, will we at some point see AI tools for creating SBOs for AI applications? Yes. And we've already started, uh, along that path.
As with anything else, the balance of AI is comprehensiveness versus accuracy. So we've been able to generate some SBOs using AI and be able, uh, are able to extract information that traditional software scanning tools or SBO M generators don't necessarily find. But you always have to make sure that they're not hallucinating, that the information is, uh, is indeed present and kind of validate the findings.
So the short answer is yes, and we, and we've personally used this, um, uh, within Manifest, for example, to help solve some, um, difficult to solve problems around extracting dependencies that are just an unstructured code. For example, things in c and c plus plus to get very technical about it. So ultimately, yes, there's a role for SBOs to help secure ai.
There's all and security. There's also a role for AI to help bolster SBOs and security. Um, even talking about things like vex, the vulnerability and exploitability exchange, which, you know, as a companion document to SBOs help organizations save time, you know, responding to vulnerabilities.
There's a role for AI in generating and disseminating these documents as well. Alright. So what is your best advice to folks then who are just getting started with this whole thing and, um, where should they be focusing their efforts in the short term?
'cause generally speaking, they're gonna have to deal with it eventually, right? Absolutely. It's certainly a matter of when more than if.
My primary advice to organizations that are already launched down the AI adoption path or are soon to, especially for SEC from the SEC for the security practitioners, is first to understand what their AI risk policies are, what allows them to, uh, use an external model or dataset and how they validate whether something is secure and trusted. So first you have to know what good it looks like or what bad looks like. The next step is to actually start applying those policies automatically, right?
So if somebody in the business unit asks, Hey, I found this model out on the internet, that's really good, good for this use case. Can we use it? How can you get to a yes or no answer as quickly as possible?
Third, then is all about inventory. So once you define what good and bad looks like, and you now have a formalized process for how AI gets into the sys the, the organization, since most organizations aren't building their own models from scratch, you need to build an inventory because without that inventory and awareness, you can't effectively secure. And then from there, there's some more advanced steps around how do you track all of your custom models or where the models get deployed into software.
But it all starts with defining good and bad and making sure there's a central process by which models and data sets are adjudicated when they first come into the organization. All right, folks, you heard it here. Transparency is gonna be everything.
And right now we might be living in a age of black boxes, but eventually we're gonna know exactly what happened, when and where, and you're gonna need something that looks like an SBO to help start that process. Daniel, thanks for being on the show. Thanks for having me, Mike.
It was a pleasure. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership Insight series.
You can find this episode, others on our website. We invite you to check them all out till then, we'll see you next day. Hi, everyone's Alan Hummel.
We're back here in our part two of our interview with Rebecca er. Uh, Rebecca is the CEO of a company called Q Secure. com.
We've had a few videos with the Q Secure team, including Rebecca's dad, David, my friend, Jennifer Legio, and part one of our interview with Rebecca. And all three of those really talked about Q Secure post Quantum cryptography and how Q Secure is helping organizations large and small, uh, get ready for as we call it, Q Day. Um, but Rebecca, first of all, thanks for joining us.
Secondly, there's a lot of people out here, you know, you mentioned quantum computing, and they say, oh yeah, that's something I gotta worry about in five years. That worry about it in five years kind of mantra has been a consistent thing with, with Quantum, it's kind of the same thing we hear with fusion nuclear fusion too. It might have a working model in five years, right?
Where we're making more energy than we expect to make it. Um, but from everything I know about quantum computing, it's not five years anymore. We're getting much closer.
There are people I think IBM has committed to having a commercially available quantum computer, I wanna say by 2029 or 2028, something like that. Um, another friends of ours behind a company called, uh, ionic, I think it's called IONQ, uh, Nicholas, who's actually, so we're part of the Futurum group, and Nicholas Nicolo, excuse me, who's the CEO of Ioni is the chairman, just six degrees of separation of fu. So I've had a chance to talk to him, but you know, everyone I speak to, including my friend John Willis, shout out to John, says that Quantum is quickly approaching us in the rear view mirror.
Yeah. Um, first of all, I want your thoughts on that, on, you know, timelines for Q Day, but secondly, if you wouldn't mind, Rebecca, your dad did a great job a little bit in Las Vegas when we talked a black hat, bring quantum down to everyone's level out here. What, when we talk about quantum computing, why the excitement?
What exactly does it do? What will it be game changing about? What won't it be game changing about?
We've got 20 minutes rock and roll. All right. We're gonna cover all of quantum physics and quantum computing in 20 minutes, so, okay.
No, I Chop it on. Yeah, go ahead. This is one of my favorite things because it's, uh, it's such an important technology and the implications are so important, right?
We know that quantum will do incredible things. We also know at a certain point it will break encryption that keeps my data safe, your data safe, the government's data safe. So it's really important to be talking about how it works so that it brings everybody into the conversation.
And it doesn't have to be that complicated. So we started working in quantum computing. I came from the AI world and got into quantum computing in 20 18, 20 19.
And the idea was we, we started a venture studio to connect, uh, research that was coming out of academia with pathways to commercialization. And looking back then, it was a little bit early to be building commercially viable applications on early Quantum Peters. Now, fast forward six, seven years, things really feel different.
And if, uh, if anyone is of sort of the venture capital persuasion, for example, and you're thinking about investing in quantum the next 10 years, there's gonna be the Google, the Microsoft, the Atari of quantum computers that's gonna be started, maybe not in a garage, but, uh, it's worth, it's worth paying attention to the space really closely. Mm-hmm. Quantum computers, they are not just bigger, better, faster, stronger, regular computers.
And that's where a lot of people kind of get, get caught up. They're not gonna solve every problem, but there are certain problems that they're gonna solve a lot better than regular computers. And one of the most exciting things is we're still figuring out what those problems are, but we know a handful of them.
And a lot of those problems can be boiled down to the problems where we wanna solve a really complicated problem. For example, self-driving, car fleet route optimization. That's a harder problem than it looks like because you need to know where every car is in relation to every other, and you need to know exactly what route each is taking in relation to the other.
And as soon as you start getting multiple stops on each of these routes, it sort of multiplies and multiplies and multiplies the amount of combinations you can see. So that's a ultimately impossible problem to solve on regular computers. But with quantum computers, if you come up with the right algorithm, that's the kind of thing they're really good at.
The way that I always tell people to start building intuition for how a quantum computer thinks is, if you imagine that you're trying to solve a maze as a person, how do you think about doing that? So you enter into this maze and you hit your first t you have to choose right or left, right? Okay, I go left, I hit another T, right or left, let's go right, and so on and so forth.
I iterate through that maze and ultimately find my way out. Quantum computer runner's a maze. Quantum computer hits its first t the quantum computer doesn't have to choose, goes both, goes both at the same time, and then again hits the next T both at the same time, and so on and so forth.
And with the right algorithm, the right quantum algorithm, it can hold all of those paths through the maze in memory at once, and then ultimately chop off the ones that are not the most optimal path through the maze. So that when you're, when you open the box at the end, it gives you that most optimal, that moved optimal path through the maze. So that's, that's the power of quantum computing.
And that that intuition can help understand some of the problems that we can start to look at with a quantum computer that we can never look at with a regular computer. There's, uh, there's more ways to shuffle a deck of cards than there are atoms in the known universe, right? Really?
Yeah. Yeah. It's true.
Okay. And if you tried to, to compute all of these different combinations of just 52 cards, you'd never be able to do that on a regular computer. Yeah, no.
So all of these say same kind of problem goes for modeling things like interactions between molecules when you're doing drug discovery, uh, route optimization. And that's things that people hope to be able to use sufficiently powerful quantum computers to solve, is these problems that are just too complex, too many combinations of things to look at and find the optimal answer. So, and obviously one of those use cases is encryption, which we spoke about in earlier mm-hmm.
Right? Where you have, whether it's, was it 124 or 248 bid encryption? Mm-hmm.
Right? With traditional computers, you have to sort of brute foursome, if you will, which I mean, the amount of horsepower needed is measured in decades, if not hundreds of years, with the most powerful computers where quantum, much like the route algorithm, it fills the whole every conceivable route up, you know, simultaneously. Mm-hmm.
And therefore renders that brute for it's no longer brute force. It's just, it's almost like the Borg assimilate force, right? Uh, and, and it does that.
So Q day, what does Q day mean? Q day is, is now what people are starting to call this day. When a cryptographically relevant quantum computer comes online, that is sufficiently powerful enough to break today's encryption, like you were saying.
Yep. The stuff that keeps us, uh, safe as we share data across networks, Well, it gives us the, uh, the appearance of safety anyway. Right, right, right.
Um, what's stopping us from achieving Q Day right now? That's a great question. Q Day, a cryptographically relevant quantum computer is a quantum computer that has on the order of 4,000 air corrected qubits and qubits being on the, the, where we have bits for regular computers.
Mm-hmm. Quantum computers have qubits and they behave a little bit differently. They're not quite binary.
So a quantum computer to break today's standard encryption, you need something on the order of 4,000 error corrected qubits. Well, what's stopping us right now is two things. We don't have a quantum computer that is that powerful in terms of number of qubits, and we don't have a quantum computer where those qubits are sort of harnessed where they are error corrected and stable.
So, like you were saying, there's, there's a number of really exciting quantum computing companies that are making breakthroughs and have now committed to these, these really aggressive timelines for when they'll have uhs. Quantum is a company that just raised a billion dollars Yeah. And they're building a quantum peter, and they've, for the first time come out with a timeline to say, I think 2029, they wanna have a million non-air corrected Cupids.
A million. A million. A million.
Yeah. And there's a few other companies that have come out and said something similar. Right.
And, and if we have a million non-air corrected qubits, we can start to do some really, really exciting stuff with a quantum computer, whether it's psych quantum or IBM, or there's also billions of dollars million going into quantum research across the globe. We know that China, for example, has spent over $15 billion on a government quantum computing research program where they're looking to build more and more powerful quantum computers. DARPA has started a program where it puts funding into these different US companies mm-hmm.
To build that commercially viable, relevant quantum computer by, uh, early 2030. So, So are we, you know, over the course of my life, I've seen cycles and cycles of innovation and discovery. Are, are we in strictly the research, the r and d phase right now?
Or do you think we're sort of coming to the end of that and starting to, you know, really think about commercialization here? I always tell people the same thing. The moment that you hear there's a quantum computing breakthrough on a problem that you recognize.
You know, if you hear, you'll hear a lot in the news, quantum computers solved bo on sampling or sort of these esoteric terms, millions of times faster than regular computer. But the thing to be listening for is, quantum computer solves drug discovery problem, or materials problem, or route optimization problem, or, or something that you recognize and is perhaps relevant to your life. That's when you know something has really changed.
And we're getting, they call that quantum advantage. Okay. When we get that qu when we start getting that quantum advantage, that's the big inflection point.
And we're close. We're getting, we're getting close to that. Uh, so it's an exciting time.
Absolutely. Now, there are other people who say, you know, what we're doing now with AI is phenomenal to, to people who don't understand how AI works, it's almost auto magical. Mm-hmm.
Right? Like, you know, fire the cavemen or rain to people who, you know, do rain dances for rain. But, you know, people say that, wait, you haven't seen anything.
Once we combine AI with quantum, that's like craziness squared. Right. Um, how does, so they're not mutually exclusive.
Obviously there's some sort of connection here between what we could do on AI and what we could do with AI on a quantum computing platform. Talk to us about that. Is it like peanut butter and chocolate, or what are we doing?
It's, it's one of the most exciting and interesting areas of, of active research. And like you said, right? The, the difference between regular computing and quantum computing, uh, is gonna be like the difference between a candle and a microwave or, uh, going from alchemy to chemistry, it's gonna open our eyes to so much.
Uh, the Richard Feinman mm-hmm. One of the, the, the fathers of modern physics, he said that if you wanna understand the nature of the universe, the nature of nature, essentially you need a computer that can model that directly rather than simulate. And that's what a quantum computer do.
So when you think about combining AI and quantum, there's an incredible amount of potential to gain the advantage of that, that power of quantum to solve and look at problems that we never will be able to in regular computing and then build on automation. And not only, one thing that's interesting to point out too, is not only quantum and AI is an exciting field, but we have the advantage when it comes to advancements in quantum technology of using AI to accelerate quantum development. And that's something we didn't have in the 1960s, seventies for regular computers.
Right? No. So it's, uh, you know, in part, it, it remains to really be seen how quantum and AI are gonna play off each other.
But it's, it's absolutely inevitable that, that, uh, yeah. It's in some specific areas. Again, materials discovery, drug discovery, uh, AI and quantum together are gonna be, it's, it's why I got into the field.
'cause I came from ai. Mm-hmm. There are gonna be fundamental doors that get unlocked by leveraging quantum and ai.
Wow. Exciting times, exciting times. You know, we're here in Boca Raton in our offices, in our studio.
I don't know if you know this, but the I-B-M-P-C was actually developed right here in Boca Raton. I, I, Boca used to be an IBM town, uh, if if on your way home Yeah. If you go to ADA Road, which is right out the main road off of our Congress here, Congress Avenue, there's a place called Brick, which is now the Boca Raton Innovation Center.
It's actually the old IBM campus. Wow. And they, they still have a room there if you do a press release, uh, where Bill Gates signed the DOS licensing agreement, licensing dos to IBM, they'll let you use it for a press conference or whatever if you're tenant there.
Wow. So cool. But literally, the IBM PC was designed here, and then they decided to make manufacturing other places, other countries, obviously.
And eventually they moved out of here. Boca Raton went into a depression for about 10 years in the nineties and became more well known for retirement and financial, uh, advisors. But anyway, um, funny thing back then, and I remember, 'cause I was old enough, a good IBM PC was five to $7,000 a Mac, a good Mac five to, or Apple before Mac even five to $7,000.
It was a standard running thing that yeah, you could buy a PC for $2,000, but basically if you wanted a good computer, it was $5,000. That was always kind of the bench line. Now, $5,000 when I was 18 was a tremendous amount of money.
When I was 40, it wasn't. Right. I have a few PCs.
Um, but of course with the advent of cheaper electronics and globalism and everything else, computers, PCs got less expensive. I think a lot of people worry. Is Quantum going to be another, like only the Mag seven are in it and some nation states?
Or do you ever think us little people get to work on a quantum computer? I, I, I like to be a pragmatic optimist. Okay.
When it comes to technology. 'cause I think we have to be, to build a, to build a future that we wanna see. We gotta think and mm-hmm.
And, uh, and visualize that future. So one of the things that I love about Quantum is it started out on the cloud. So I can access, we could all access a quantum computer right now, one of IBM's, um, probably smaller chips, but we could, we could go on right now.
So could someone in Nairobi really? Or Seoul or, yeah. And I, that kind of democratizes it in a way that, that, like you're saying, it was prohibitively expensive for a lot of people to be able to, to learn how to program on, on earlier computers.
So that's, I absolutely hope that that continues. Now, I have heard that some of these companies, as they develop more and more powerful chips, they have to think about, do I release this kind of power to the public or do I not? Mm-hmm.
And so that's, that's a kind of, with great power comes great responsibility sort of question. Should we leave that power in people's hands or should that be governments making those decisions? That is a fantastic and fundamental question.
I, for one thing, I hope we get the option to choose Or both, So, right. We, one thing I like to remind people about when it comes to Q Day that day, that that Quantum Peters will become cryptographically threatening, is not just that we have to think about getting ahead of it today and, and deploying protections because that data's being actively harvested and stockpiled for, for, for QA to unzip it with QA when QA comes, the thing I like to remind people is that we probably, as the general public, will not know when that computer comes online, because if you have that powerful of a tool, you are not gonna release a press release about it. Right, right.
Just like in World War ii, when Alan Turing and the team figured out how to break Enigma Enigma. Right. They didn't advertise that to Yeah.
To Germany. Right. They, that was, that was something that they kept close to the vest and were able to save many, many lives because of that.
So, uh, when that, that 4,000 aircraft cubic quantum Peter comes online, we probably won't. No. So that's something that people have to keep in mind is that there, there are things that are going on behind the scenes, and while I think we, we should all kind of demand and push forward this democratization of how we access these really powerful computers and train people to use them.
And, uh, there's also, inevitably it's a very, very powerful tool when it gets to scale. Absolutely. All right, we've got time for one last question.
I'm gonna put you on the spot. Pick a day for Q Day. Oh man.
I, I'll give you a day, but I'll, I'll also say that anyone who tells you definitively is, is a little in their mind is out of their minds. But We'll put it out there just 'cause what the heck, it's, you might as well plant the flag in the ground. Totally.
Well, I'll tell you, Gartner for example, says Good chance by 2029. Yeah. So be ready.
Um, it could be 2029, it could be beyond, it could be sooner. Uh, But like you said, we may not know, or in two quantum fashion we may know and not know same type. No.
Yeah, exactly. Exactly. So yeah, we might start seeing this data, these data breaches that are kind of suspicious and, And then that'll give us a clue.
Well, look, God willing, I hope it's not the bad guys who get this first. It's Gotta be the good guys. We gotta, we gotta make sure That's one thing we do have to make sure.
Yeah. Rebecca, I want to thank you for coming up here to our studio. This was great.
If you haven't seen part one of this interview, please go back and check that out. Again. com.
Check them out if you want to stay on top of this whole post quantum cryptography, uh, security dilemma and problem. They've got answers, but for now, this is Alan Shimmel for Textron tv. Thanks very much.
Hey everyone, it's Alan Shimel and we are live. That's right. Live, uh, it at Swamp Up.
Swamp Up is back in Napa after I think two or three years it's been since they were in Napa Should End, I'm thinking it might have been since before COVID that we were in Napa last. But we're really thrilled to be here. It's beautiful here.
It's a beautiful resort, but more importantly, there is so much going on. It's so swamp up, you know, like everything else in the tech world, it's kind of the year of AI more than the year. It's the era of a, the dawning of the era of ai.
Still, I like to tell people we're still at the beginning of the beginning, not even the end of the beginning on ai. Let me introduce you to my first two guests of our Techstrong TV coverage here at Swamp. Up to my far left.
He's the guy in the, in the, in the, uh, shift happens Frog shirt, Yuval. Let me make sure I get it right. Excuse me.
Yuval Fern back. Yuval, welcome back. It's good to see you again.
You good to see you as well. You know what, before we get to our next guest, Yuval give share with the audience your title and role at jfr. Sure.
So everyone, I am, uh, Yuval Farba, I'm VP and CTO of MOFs here in Jfr. Um, actually joined Jfr a year ago as part of an acquisition of a company called Quack. Um, and nowadays, of course, part of jfr ML and the new product that we launched today that of course we'll talk about in a second.
Thank you uva to my immediate left not in the frog shirt. Is is Del Elick. You got that right?
You got that. Perfect. You got that on the money.
All righty. Al is with, uh, Nvidia and Ade, introduce yourself. Well, thank you for having me.
It's great to be in Napa. I was joking around earlier telling folks that, uh, you know, I'm glad we're doing this 'cause now my family really believe that I'm here for work. So got the proof right.
I got the proof now. So, uh, my name's Al. I'm a senior director of product, uh, at Nvidia.
And my job is to, um, take the software that our, uh, awesome core tech team creates, um, a hardened those make them production grade for enterprises and help our ecosystem build, um, agents, right, that are fra frankly transformative in everything that we do. Something we were just talking about. Absolutely.
And, and that's a great segue. I i little something extra for giving us that segue. We were at the keynotes this morning, right?
You all led off, came on Yuval you, you, uh, introduced a new product for Jfr called the jfr AI Catalog. Explain to our audience a little bit, what, what is it? Yeah, so, um, as I shared, I joined jfr a year ago, and as part of that, I've seen and got a lot of responses from J four customers about the challenges they have with adopting ai, the challenges that they have with actually trusting AI and the amount of new models that are being launched daily, right?
Um, everyone's speaking about ai, but actually using that in production require more than just, you know, testing the new and shiny model. It requires the ability to trust that, the ability to trust where that model is coming from, um, who's the owner of that model, and even who is actually going to use that model. And as part of that, and it's part of all that feedback that we received in the last year, we decide to launch the J four catalog.
And that's basically a solution that allow organizations, allow our customers to manage the entire life cycle of AI usage. I'll call it, from discovering which models actually exist, um, to deciding who should they permissions to which models, and eventually then serve those models, uh, track the, uh, usage measure of the models and understand which application uses models and how. So the goal is eventually to allow organizations to understand where those models are being used by whom, and make sure that they trust those processes that are, you know, shifting in, in such a magnitude, in such a, a, a pace of innovation that we haven't seen before.
Absolutely. We're gonna come back to that. 'cause I, I have some thoughts and questions, but not open.
Explain to me the Nvidia Yeah. I mean connection, a reason for this awesome partnership, right? Right.
And so, uh, we're a full stack acceleration company. What that means is, right, uh, we're not just about producing processors or, or systems. We actually build out AI factories, but we go all the, all the way up, right?
For optimizing runtimes for not just models that Nvidia publishes, but also the ecosystem models as well. We call that nim nim inference and microservices. And so, uh, what we do, you can think of a nim as as a, a model with its runtime package as a single microservice, we spend a lot of time tuning that runtime to make sure it runs it efficiently as performing as possible, uh, on the Nvidia stack.
Um, but equally right, we contribute a lot to the open source domain. We're very, uh, we're huge participants in the open source community because going back to Eva's point of having that, that trust, having that transparency, it isn't just that we provide the Nemo tron open weights, which are fantastic by the way, and Excel really good at reasoning. But we, we also open source our, our training data sets.
We open source our recipes so enterprise can then take those models, further tune them for their agenda, uh, capabilities. And so being the ones that provide the secure runtime and the open source of the models and the weights and partnering with J Rog, what drives the services for having all that lineage was just an amazing partnership. Absolutely.
I, I want to dive a little deeper on this, right? So I was at Swamp Hub last year in Austin where they announced the, uh, jfr oog Nvidia partnership now Adel over the course of the 12 months, how have, you know, what, have you seen how this partner, well look, AI has been on a hockey stick trajectory for these 12 months, right? But how has that affected, what's the, the, the net that our audience could take about this partnership?
What does it mean to them? I mean, look, you know, you've kind of set the scene, right? There's so much happening and it's happening so fast.
I joke around and tell people that at one point I think my kids thought I was a vet 'cause I was talking about new animals every week from llamas to Mambas to, you know, you name it, right? But, but it's awesome innovation that's happening in the ecosystem, right? So a couple things that are, that I think critical number one is all this innovation that happens, right?
Yes, you wanna be experimenting a lot, et cetera, but when you have all this innovation that's happening, right? And you have all this open source, the potential for exploits grow significantly as well. Right?
And that's something we talked about earlier when, you know, we were on stage. And so, uh, being, having that transparency, understanding essentially what's part of your run times where malicious code can be potentially like implemented is, is super critical. So you wanna be experimenting, but you also wanna be careful and prudent when you're experimenting.
And so that's why having a single source of truth right, for your system of records, for all your artifacts is critical. And that's why that relationship's been awesome. And, sorry, go ahead.
No, no, go ahead. And I think the second point is right, um, one of the first use cases we started using agent AI was in actually defining the contextual, um, analysis. Doing the contextual analysis to understand whether vulnerability can be exploited or not, right?
And I think, uh, I, I really appreciate the partnership that we have with the JFAR platform because that's something they take very seriously as well. Just 'cause the CVE says, you know, it's got a high CVE score doesn't mean it's exploitable. There's a lot that goes in to be able to exploit that.
And so, you know, we see eye to eye in terms of how we go about really going deep and understanding the potential for exploits and protecting our, our, our customer base. Absolutely. And by the way, this, this partnership didn't start because, you know, US Invidia thought that we should work together.
It started because the J four customers approached us, told us that they need to trust the source of their models. And, you know, the only models from face, by the way, I think the target face is an amazing hub for models, but it's not enough in many cases. And customers approached us and told us that they want to have a trusted source of models.
And Nvidia is one of those trusted sources. So a year ago, we, we partnered to make sure that the J four customers can actually get the Nvidia need models directly from multifactor and trust the origin of those models. Um, and from there, of course, we progressed with that partnership with the security solution.
So the contextual analysis, the ability to actually understand how those, uh, artifact, how those models are vulnerable, and how we can make sure that in the production environment there will be no vulnerability. So eventually it's part of the same goal of making sure that the J four customers, and of course the NVIDIA customers can actually trust the model, trust the origin of the models, and trust that there are no security incident that will arise because of those new artifacts that they not need to manage and, of course have to manage to actually make their product progress over time. Excellent.
Ada, I wanna come back to you 'cause you said something right in the beginning that I want our audience to understand. And that is, a lot of people hear Nvidia and they're thinking G-P-U-G-P-U-G-P-U, not that you make a bad GPU, don't get me wrong, but the real key to NVIDIA's position is the software, is the community, is the ecosystem around Cuda and, and, you know, uh, um, NIMS and, and so forth. Talk to us about that a little bit.
And while you are, we're on live tv, Paul, uh, cameraman, I'm gonna ask you to grab outta my bag, my AI catalog paper. We'll bring it up. We're gonna talk more about it.
But Al talk about Yeah. What the secret sauce at Nvidia? Uh, Well, we're a full stack acceleration company, right?
I mean, um, yes. We, we start at, at the silicon, but we go all the way up the stack, right? And so we have AI factories, we have our, our software portfolio that goes all the way up to the, um, you know, what what we call blueprints, right?
Reference workflows for how you'd go implement a specific use case for, for agents. And you get the full benefits of Nvidia when you take the full stack, right? Because we're able to optimize all the way down to stack.
But by no means you have to take the full stack, right? And we leave it up to our audience, our ecosystem, to meet us where they think is best. Some just wanna run on our infrastructure.
We love them. Some want to utilize right? Wanna go higher up in the stack and take advantage of the optimizations that we drive through software to enable that.
I think one key to NVIDIA's, um, you know, call it success or, or or secret sauce, is just how, how ingrained we are with the ecosystem. We, we go to market through our ecosystem. Our partners such as J Far are super critical to our success at the marketplace.
And so you're spot on. We're not just a chip company, we're a full stack company. Um, right.
You can take us, you know, you can go with us up all the way, you know, all throughout. Or you can just choose to meet us where you think is best for your, for your, for your domain. I love It.
Thank you. So Yuval talking about the jfr AI catalog, you know, I've written a lot recently about what I call shadow. I, uh, shadow ai, right?
And we've seen shadow, look, I've been in, I've been in the tech business probably longer than both of you. Okay. Um, I seen Shadow before I saw Shadow open source.
There was a time where enterprises official policy was no open source allowed. It was, it was a danger, right? I've seen shadow wifi.
I remember being at a US Army base and the, uh, army Information Assurance officer telling me we don't have a wifi security problem 'cause we don't allow wifi. And as I'm walking with them, I see people unplugging laps and throwing them under their desk. As soon as he walks by, they plug them back in.
And wifi, we saw it with the cloud developers whipping out their credit cards and opening instances. It's no different, no different with, it's probably even easier with ai. Yeah.
Because you have take your pick, right? Whatever one you want to use. So we call this a prop, right?
They gave this out at the, at the keynote today for your talk. You're joint talk. Talk to us about the different models and how we're going to control shadow AI at the enterprise level.
Yeah, yeah. So, so first of all, yes, it is a prop because, you know, this, this booklet have six models in it. Um, I believe that the current number in I phase of models is around 2 million.
And, you know, on top of that, there are, um, external like model providers like OpenAI and others. So that's another couple hundreds of models. So, you know, the numbers are way more than that.
And of course, no book can actually, you know, manage and track the amount of models that are being launched. Um, and models are nowadays used for, you know, so many different tasks. So, actually Shadow, um, Aline his, in his talk talk about different type of models like reasoning models and, and, you know, voice models and models are being used for different tasks and not just for language models.
Like, there are many models around computer vision and many models that are still used for structured data. And that's still a valid use case and still something that customers, you know, use as part of their use cases. Eventually, the goal of the air catalog is for organization to have the visibility about those models, about where those models are being used and how, and on top of that, as part of our launch, we actually launched a new product that will be available in a couple of months, um, called Shadow ai.
Now, the, the issue of shadow ai, the problem with shadow AI is that in many cases, you don't even know that the model is actually adding one of your packages. It's possible that you downloaded the third party doer image. Uh, that doer image that you use actually uses ai.
Um, and it's not something that you can just, you know, not know about. Because nowadays, even the regulators in many places, for example, in the EU, actually force you to show that part of your product uses ai. It's something that you need to have visibility on.
It's something that you need to be transparent on. So the goal of the shadow AI product that of course, is connected to the J four Gaia catalog, is to just not, not just allow you with AI catalog to choose which models should be used, but also to see, to have the visibility about where model is being used, what you are not really aware of. And if those models are being used, for example, malicious or those models that are being used are actually not approved in your organization, you'll be able to actually block those from being used or, you know, go through through the process and approve those specific models.
Um, so the goal is about visibility and the ability to discover where AI is actually being used in the organization. You know, again, my experience is you don't wanna stop people from using ai. Yeah.
And quite frankly, stopping people from using AI is like trying to grab sand in your hand. The, the tighter you make it, the more it slips out between your fingers. What you wanna do is just, okay, you're using ai, let's let us document it.
Let's make sure it's safe. Let's make sure it's secure. Right?
And that, because otherwise you're fighting a losing battle. Nvidia has to see that as well. Al No, I, I'm, no, I mean, right.
We're not, we're not, we're not definitely fighting ai. Right. To your point, right?
It's, it's, I mean, there's plenty of productivity gains new markets that it opens up, as I said, right? Uh, the, the only reason we're able to publish and maintain so many of these NIMS is because we're using AgTech ai. Right?
Absolutely. But to your point, you do have to be cautious, especially with all this open source that's happening, all this innovation, et cetera. You wanna create an environment that allows your developers to experiment.
That is for sure, right? You wanna, you wanna continue creating that, that experimentation, right? Uh, that you wanna enable as well.
But then when you're going into, into production, yes, you want to have the safeguards that are in place. Um, you want to be able to have the observability, the tooling that is in place, right? I, I go back to, you know, the nitron models that we provide, just being open source in terms of not just the model weights, but the data sets of what it was actually trained on, the recipes of how we got there.
Just to give the enterprises and the ecosystem that level of comfort to know exactly what's going on, such that you always have that lineage that's super critical. Yeah. I don't think you can, you know, on the contrary, right?
Like, we're just on the, I think you called the be era, right? Beginning. Beginning of the beginning, Right?
And just imagine when physical AI comes into, comes into this world, right? Today we're talking about digital workforces, but very soon, right? We're, we have these world foundation models where you're simulating and generating data to train these robots and these anonymous vehicles, man, it's, it's about to get exciting.
It, it already is. It already is. Um, but, you know, I, that bring, both of you mentioned this, but you kind of ate at the edges.
You didn't eat the middle, which is something else that they spoke about in the keynote saying, I'm trying to remember the exact name. Was it AI gov or ai gov ops? Something?
It Was, uh, dev gov Ops. Dev gov. Ops, excuse me.
Dev gov. 'cause there's always something in the middle between dev and ops, whether it's sco, whatever, dev gov ops. I learned a couple new ones today.
Yeah. Sorry. Yeah.
Yeah. So, but that's really what we're talking about here. We want, we need governance.
Not, we're not here deporting AI models, right? We're here talking about you wanna use ai, use the ai, but let's have some governance around it. Let's have some guardrails, some knowledge, right?
And that's, to me, that's the enlightened way of doing this, right? We're not discouraging use ai. I know.
So, textron's, part of futur, and we, we have a policy now where we're encouraging all of our people, the cameramen, the editors, the writers, the marketing, the decoders, use AI to your heart's content experiment. We expect you to make some mistakes. That's okay.
Make the mis I'd rather you make mistakes trying something new than digging in your heels and saying, I, I don't want to use ai. 'cause if you don't use, I tell young people this, who ask me all the time, you're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than, That's right.
Look, this is something we think about as well, right? And kind of now you're, you're going above and beyond just serving a given model or talking about managing the lifecycle of, of agents, if I may do that, right? Yep.
And, and that pipeline, right? We use, we, we have something called the NEMO platform for managing life cycles of ages. And that starts from data curation, uh, creating additional data that is, um, doesn't have the potential PII, that, you know, you're not just collecting people's prompts, right?
To then up taking a model and adapting it for a specific domain. Then once you have that right, and, and putting it as part of a, of, of an agent, make sure you have the guardrails that are in place, right? Such that it doesn't go re make sure you have the traceabilities, you can backtrack across the way.
We have, uh, something called the NEMO Agent toolkit that allows us to drive all that traceability, all that observability, all that ping profiling around. It's almost like, it's almost like onboarding a new employee. You have to teach 'em about your cultures and your norms at the company.
You have to tell them the dos and don't dos, kind of like, you know, I'm doing in this interview. Right? They're, yeah.
Right. And so, so it's exactly like onboarding a new employee and putting all those kind of, you know, managing it throughout this lifecycle. And to your point, it, it first, organizationally, you have to, I love what you just said, right?
Everybody's gotta be experimenting, but then making sure that your enterprise is leveraging the likes of the NEMO microservices to right. To manage that entire lifecycle. I love it.
Yuval, I'm gonna give you the last word and then we're gonna wrap up. No. So actually going back to this, uh, dev gov ops term, and, and again, we talked about it today.
And, and this is in a way the theme of this swamper because, you know, automation is already around. We're seeing that as part of the development lifecycle. We're seeing that now as part of the DevSecOps lifecycle and also around, you know, ML and AI adoption.
The challenge is not, or is becoming not how to automate those processes and how to actually, um, um, use new technology. It's how to make that in a governed way, right? How to protect the way that we use the new technology and make sure that while we are researching new technologies, while we are actually adopting ourself to this new future, we do have the visibility and the governance on top of that to make sure that we're not doing anything wrong.
And that eventually our customers of our product can actually get benefit from those new technologies that we actually use in our products. I love it. Yuval Ado, thank you.
Ado. No, You got it. You got it.
You, Alan, Thank you so much for coming on here, kicking off our coverage of Swamp Up 2025. We've got a lot more coming at you. Unfortunately, not all of it's live, but we're recording it all.
And over the next days and weeks, you'll be able to see everyone we spoke to here. I encourage you. com or Techstrong It, tech Strong, AI digital, cxo, cloud native, now, even Security Boulevard.
'cause we'll probably do something about dev gov ops on there to, for our full coverage at Swamp Up. But we're gonna take a break here. Stay tuned.
We'll be back with more from Swamp Up This Tech Drunk tv. Hey everyone, welcome back here to our day two coverage of, uh, swamp Up J Frog's, uh, conference out here in beautiful Napa Valley this year. We're happy to be back.
Uh, we're continuing with some of the people we've been meeting. I wanna introduce you to a frog right now. His name is Yossi Shaul.
Yossi is the SVP of DevOps, right? Which is a great job when you're working for a DevOps company, right? So, first of all, Yossi, welcome to Tech Drunk tv.
I, you know, in all the years that I've been interviewing frogs, I don't think I've had the chance to sit down and talk with you before. So it's great to have you on. Um, if you don't mind, share with the audience a little bit about kind of your journey, how you got to be here.
Okay, thank you. So, I'm Yai and I'm in this business for, um, I would say for most of my career. I started with, uh, J four, about 16 years ago.
16. So right from the beginning. Long time.
Yeah. Yeah. Uh, we were working, uh, at the beginning of Artifactory, creating the, this new domain before DevOps was a term even.
Mm-hmm. Uh, so I've been working on Artifactory since the beginning. I managed the, the team and the, and the product for quite some time.
Uh, then I shifted a little bit to do some more, um, architectural, uh, leadership inside jfo. Okay. And in the last, uh, three years, I'm, uh, back to leading the entire DevOps organization in, in jfo, uh, both product and engineering.
Product and engineering. Yeah. So that's, uh, that's really challenging.
Really interesting. Yes, It is. And very, very interesting time.
So yeah. Glad to be here with you. You know, it's funny you say that.
It's, it is interesting times. Look, I, you know, I've, I'm in tech 30 years, 30 something years, mostly cyber was in infrastructure then security. We didn't call it cyber, then we called it info side, right?
And then when, when DevOps first around 2012 maybe mm-hmm. I, I said, wow, what a great thing for security, right? DevOps is right.
Is going to be. And that's when I started really getting involved. com in, uh, 2013.
And, you know, I will sit here as you sit here, the DevOps we were talking about and doing and, and working on. Then today, it's a different animal, a little bit, right? Today, it's, it's not radical.
We don't have to explain what DevOps is. We don't have to fight on whether it's real or not. But on the other token, you know, people become too familiar with it.
They take it for granted. Mm-hmm. Right?
Ah, yeah. It's DevOps, right? It's just DevOps.
What, I mean, I see this as a challenge. Okay. com, what do you see from where you sit?
Yossi is, are people like, just shrug their shoulders, like DevOps is built into the table here and it's, or do they, you know, they continue to explore. They continue to evolve. Okay, great question.
So I am, as I said, I'm long time in this, and I remember myself, uh, explaining absolutely. I, artifact is a thing. Uhhuh okay.
And arguing with people why they should not, uh, store their binaries in subversion, for instance. Mm-hmm. So we've, we've been a long way, uh, stumbled That way.
And, um, and while I think that many organization, um, discovered and now maybe even think that they know what DevOps is, the world keeps shifting and keeps changing, and it never ends. Okay. The, uh, we had the first revolution, then another one with Docker, then with Kubernetes, and now we are what we are doing with ai.
It's keep shifting, keep changing. Mm-hmm. And also the security is a big part of it.
Yes. And while I think we also discussed it in one of the keynotes, that it's not a, so it's not a solve, um, issue. Okay.
Yeah. Not DevOps and definitely not, Not dev, DevOps, And definitely not with, uh, new regulation, new, uh, things that AI brings with it. So I think that we, we've come a long way, as you said, but, uh, I, I wouldn't say that, um, we nail it.
Okay. There's still lots of things to, to discover to, Well, the, the thing is, and, and I tried to explain this to someone the other day. I was talking to a younger person who wanted to be in tech.
Mm-hmm. And, you know, they were making it like, you know, like, uh, like tech is done. Not, not that it's over, but that there's nothing new.
You know? And what I tried to explain to them is, no, we, it reinvents itself. Right.
It's constantly changing. It's constantly evolving. Yes.
AI is what we're all crazy with right now. Right. It's, it's kind of the biggest revolution in my, I think, almost as big as the internet itself maybe.
Right? I agree. Um, but every little piece of it, whether it's DevOps or, or, or agile or cloud native as you, you mentioned mm-hmm.
It's all still evolving. Right. And, and we learned this now.
You did a keynote yesterday. True. Here at Swamp Up, you know, most of the people watching this were not here, obviously.
That's why they're watching. Um, tell them what you spoke about. Alright.
So yesterday we introduced a new product, a new solution, uh, in the J four platform. It's called UP trusts. Yes.
And I think this is another big step of the evolution that actually shows that DevOps is not yet done. Right. Um, we are, uh, offering now solution that allows, uh, development teams to manage their applications inside the platform with a clear lifecycle and policies that controls it.
So, as you all know, we all manage in one way or another, a lifecycle for software development lifecycle, it's called like that. Yeah. Uh, but we used to code it, and still it is coded and scattered in many, many places inside the ci where there's no, um, one location that you can control it and visualize it.
Um, and this is what we are offering now. So the APTA solution is, uh, built upon three different pillars. One of them is the concept of an application.
So we are releasing applications. All of us application can be a library, it can be a full blown application. Um, so that's one thing.
Now it has a representation inside the JO platform that you can, uh, you can fully control. The second, the second pillar is evidence. Evidence is basically assigned metadata or an attestation that you can attach to a binary to an artifact.
Um, now this can be, uh, internal, uh, evidence that the jfo platform generates. And it can be, uh, things that we are partnered with GitHub, like attestations from GitHub that are attached. And it can be any other, uh, evidence that can talk about it a bit more later.
So that's the second pillar. And the last pillar is the actual lifecycle that you can predefine. That's my lifecycle.
It can be as simple as dev, qa, staging, production, and it can be much complex than than that. And you can customize it. Pillar, each team Now, besides, um, having a clear visual lifecycle, you can put gates, what can get in and out of these gates based on the evidence that I just mentioned.
And this, I think it's a big, big change that we are bringing, uh, uh, to the table. Absolutely. It's a huge change.
It, it's a huge change. And you know what's funny? Is it, it's, it's almost common sense.
It makes sense when you explain it. We sit here and say to ourselves, why did it take this long? That's true.
Like, You know what I mean? We, we kind of knew this was what to do. So you've put good words around the titles, right, right.
To the, to the process. But, but this is why when we talk about why things don't, are, it's never done. It's just like we're constantly things that we we're apparent but not apparent.
Do you know what I'm saying? I agree. Yeah.
It was there, but we never kind of wrapped around. Definitely takes time. And even for us, it's the second iteration that, uh, we, we try to nail it and we did a lot of improvement.
And that's the second iteration. But That's DevOps. Yeah.
Iterate, reiterate, learn feedback, loop, iterate. Right. Exactly.
And, and that, that's what it's about. I wanna talk AI with you a little bit though. Okay.
So, as I said, I think this could be as big or bigger even than what the internet was mm-hmm. When it first came out. Um, I mean, it's had a profound, if you were on the, you know, I reported yesterday on from the keynotes and everything, it was a lot of ai.
Right. I think Shlomi said, if you're not using AI now, you might want to step out. Mm-hmm.
Right? Correct. How is, how are you leading the DevOps team mm-hmm.
Sort of eating your own dog food? How are you using AI to make jfr better? Okay.
Great question. So definitely, um, jfo was always, um, a company where we had a lot of innovation and a lot of, um, adoption of new technology. So we are doing it for quite some time.
Um, like many other companies, we are doing it to increase our productivity. And it's internal, and we are doing a lot of it. And it's very, very interesting.
Um, there are also, we are also serving this audience, uh, whether it's the data scientist or the new mops, uh, audience. So we also are providers of solution, uh, to this area. Now, the third pillar is how do we actually integrate AI inside our products?
So some of it you heard about, um, when a staff, uh, leader from, uh, security Yes. Um, mentioned how, how we can provide remediation based of data formal, uh, catalog. That's, that's one, one offering.
The other one was the AI catalog that was also announced yesterday. Yes. About it.
And this is amazing. And, and even us jfo, we are not huge company. It's very, and we want, as I mentioned, we want to adopt new technology.
We want to adopt ai, but we want to do it in responsible manner, and we need to help our legal and compliance team to help us. Sure. And AI catalog is one of those solution that, that can help us promote it internally.
So you have one location where you can see all of the models, all of the services, external APIs that you, you want to use. And this is where you can approve it and you make sure it's secured and you can know who is using it. And so I'm very excited, uh, about it, both as offering solution.
I was too, but also using it. I, I think this will wind up being one of the big compliance tools, because, you know, what's this is like, remember when cloud first came out, every developer had whipped out his credit card and, and spinning up instances. Mm-hmm.
They weren't shutting him down, and then they submit the expense. Right. All of a sudden someone would add up and say, oh my God, we got how much cloud instances running.
Right. I think at some point, what, what's going on now is everybody's experimenting, right. It doesn't seem like you pay $20 a month here, $20 a month there.
It comes with my Google over here. Mm-hmm. You know, you know, we don't recognize the full scope of, of how much AI we're actually using at the, at the company wide.
Even a smaller, we're smaller than you. Right? Yeah.
But I see every single one of these people have their own $20 a month accounts. And that's just the foundational models. Then they got video editing, ai, uhhuh, graphics, ai, and marketing ai.
You know, sooner or later something's gotta blow up. Right. Hopefully we'll be there to control.
Well, Unless we do something like this. Yeah, exactly. Right.
That can control. So we know at least what we're doing. But here's the other side of that.
I know as, as you know, the manager of my team as the CEO of Textron Uhhuh, I don't wanna stifle experimentation. I don't want to crimp their style. Right?
Right. I want them to use AI figure, show, figure out new ways of doing things, how to leverage this to be better. Mm-hmm.
So I gotta balance, right? I don't want to be like the, oh, you can't use that. 'cause it's not in the catalog.
Mm-hmm. I wanna say use what you want. Just put it in the catalog.
Okay. Got it. Right.
Make sure we know about it. So when something happens, we, we have something to point to. Mm-hmm.
Is what do you see? You have a bigger team than me. What do you see with that?
Let, let me give you an example, which is, um, the reality. So in my keynote yesterday, uh, I mentioned that we have, uh, controls gates to make sure that you, you pass through what we think. I, as a development manager wanted my team to go through testing, coverage, quality, et cetera.
Uh, so for this demo, I asked the team, Hey, I'm going to use Cursor and I'm not going to click a button to, to release it. I'm going to do it like you are doing it. I'm going to tell it, Hey, release it to production.
Um, and they got panicked. Really? Yeah.
Why? Listen, you are going to do a live demo, and this agent is not predictable. We are telling you sometimes it works, sometimes, sometimes it doesn't Work.
That's AI today. So my answer was, okay. But that's exactly what we are building.
We are building gates that if it doesn't work, we stop it. We detect it. Exactly.
We stop it, and then we tell it how to do it the right way. Uh, so it's actually was exactly what we needed for the demo. And it's actually what happened.
It Didn't work. Yeah. We tell it didn't work.
Like I expected it not to work. Okay. Um, we told it to release something to production, and this is how we want to work.
Right. Future. Yeah.
Release something to production. And guess what? It actually tried to take from the development, the release from the development stage, and put it right into production.
No testing, no coverage, no security scanning, vo. And this is what he tried to do. And it failed.
And that's exactly what I wanted to demonstrate. That's so it Was so it actually worked. Yeah.
The failure was a good thing. Yeah. So that's one example.
And then I told it, Hey, make sure you run the test. It figured it out. And I guess that if we train it more, it'll know how to do it.
This is how our team will work. Uh, but that's one example of, of how those controls and the things that we are bringing with the new solution are making us making it easier for our customers and take Taking some of the risk gap. Yeah.
Really. Because that's what, you know, it's all about the risk. Um, so I gotta ask you the hard question.
You're probably hearing it from your team. I know I hear it from my team. Mm-hmm.
Are their jobs safe? Is this gonna replace them? Should they start looking for a new career?
What do you think? Uh, So no one knows the future. Okay.
And I think the, the, there are going to be, and there are already happening, a lot of changes in the way that we work. Uh, and some jobs or some roles will either disappear or change completely. Uh, I think that, uh, we are still not there.
Okay. I think that, uh, and, and again, we are adopting it a lot and it helps with productivity. Yeah.
Mainly, uh, it helps also taking the mundane parts of the work, uh, to someone who doesn't care. Uh, but I don't see it yet replacing, uh, junior developers. I don't see it increasing, uh, uh, 10 times the productivity of the, it's still not there.
Yeah. Um, and I still don't see it happening. However, look at how it looks like two years ago.
So who knows? The advancements are really, really fast, but it's still not there. It's, it's a, now it's a valuable tool, but it's still not replacing, uh, definitely not experienced developers.
But I think it'll always be a tool. Right. And we, and we're humans.
That's what separates us. Yeah. We're tool users by definition.
Right. Right. That's part of being human.
I, I, I think the, like, in my mind, it's going to get better. 'cause you see it gets better week to week. It gets better.
Definitely. Right. I mean, I use it with writing and it's, it's a, it's really getting better every day.
However, I think at the end of the day, it's always will be a tool. Mm-hmm. And it won't replace the spark of creativity that makes a human.
Do you know what I mean? I agree. You'll come up with an idea and it'll help you bring that idea to reality.
Mm-hmm. I don't know if it'll ever come up with the idea itself. Do, do you follow that spark?
I, I follow. Yeah. We'll See.
And, and I, you know, I, I wanna believe that anyway. We'll think that's exactly, let's see. Um, I wanna emphasize something.
We, I asked a few people yesterday, we spoke about, which is all of the stuff you showed yesterday, it's available now. This isn't pie in the sky coming next year. It'll be continually improved with feedback and everything else, but all of the things that we've been talking about here for two days now, people could go on Jfr right now and go play with it, see it, use it, test it, whatever they want.
Yeah. So, so the concept in, uh, swamp up is that, uh, we arrive here, we are ready. Right.
Okay. We're not showing you anything that's pie in this. Exactly.
It's there. Or it's coming in in several weeks. Right.
That's it. So APTA is there. AI catalog is there.
We also spoke about, uh, solution for ID extensions. It's there. Mm-hmm.
Uh, identical remediation is there. Yeah. Um, I also demonstrated, uh, yesterday on stage, we have a new partnership with ServiceNow.
Yes. I saw, Uh, this is where we, we are connecting the two words of, uh, itt. SM Yeah.
ITSM management processes things, amazing things that are done on service now with the evidence and lifecycle management that the DevOps guys are doing. So this is something that we started working, uh, a few months ago after the feedback we got in the LEAP event. Uh, and this one is coming.
This one is in development, or we wanted to announce it to put it on the table because our customers are really excited, really ask for it. And we are working on it. This is coming, uh, later this year, or probably at the beginning of the next year.
Other than that, still there. All the things that we announced are, are there? Yeah.
Well, Yoi, 16 years. 16 years ago, do you think you'd be sitting here at something like this? You never know.
You never know, man. You never know. Hey, congratulations.
Thank, thank you. You've done a great job. It's really Fun.
Yoi Shaul, uh, SVP DevOps here at, uh, JFR. We're gonna continue our day two coverage today. We've got more coming.
So standby here on Tech Drunk tv. Hey folks, is there an open source economic crisis? We're about to find out.
You're watching Techstrong. Hey, folks, we're back and we got an awesome lineup again, talking about, well, some of the most interesting things that have happened in the land of app dev are all happening this week. And we're gonna get started with this open letter from not 1, 2, 3, but four or five different open source associations, consortiums, whatever you want to talk, call them, complaining about the fact that they're paying for infrastructure that people are using within their software development life cycles, especially the package managers.
Uh, and they're bearing the cost for all of that. And nobody seems to be helping them out, and it's costing tens of millions of dollars. And they're putting everybody on notice that either somebody has to help them fund this, or they're gonna start throttling access to those APIs.
I know you've been monitoring this whole space, but, um, what's your assessment of what's going on here? 'cause they seem to be pointing to large enterprises specifically and saying that you're abusing the privilege. I think, uh, I'll start from the basic and the fundamental, uh, shift.
And I wrote, uh, uh, article on this as well, new era of open source. But I mean, uh, going back to the basics, open source represents a paradigm shift, right? So collaboration, transparency, community driven, uh, innovation are key to this, uh, movement.
But, uh, often open source is, uh, considered to be like access to free code, which is not the case, right? So open source, uh, describes that the software has to have the permission to use copy distribute, and either, uh, either to modify it, uh, from a commercial standpoint, or it has to be free, right? So there are license implications, obligations to follow, and there are definitions laid out by open source, uh, initiatives like open source, uh, software, for example.
And I'm quite passionate about this space because if you see, uh, DevOps has been, um, the front runners to create, uh, innovative solutions in open source, uh, like for example, open Telemetry or Argo, uh, it's kind of contributing, uh, to a certain extent. Uh, a lot of innovative solutions which are coming to DevOps. Now, the difficulty, which, uh, you referred in the article and the, these people who have been pointing out that there is not enough funding.
15 billion, but the demand side is around, uh, $8 trillion. But there is no central tracking for it, right? And that's the reason why you see a lot of these open source initiatives are not well funded.
Uh, there was another report which, uh, uh, I will call it state of open source report, which also highlights some of the operational pain points. I mean, it's great to have an open source initiative, but they struggle to maintain, uh, security for examples. There are not e enough maintainers for the open source capability, technical support, for example.
There are gaps in it. Um, there are also lack of skill, experience, and proficiency in this area. So I, I think all in all, um, what it reflects is, you know, we are at a pivotal point where open source, uh, community, uh, drivers need to think about, uh, newer business models.
You know, how we ensure that we get enough funded, uh, you know, projects and the funding has to flow in the right direction. Uh, foundations like clinics, foundation, uh, CNCF, uh, CDF, they have done a great job, right, to protect some of the innovation and bring some funding to the, this space. But I think it's not enough.
It's also like one other factor. I I can go on and on on this topic, but one other factor, which I also see is single vendor driven open source initiatives, I think, um, that needs to be thought through well, because, you know, it's, it's evident that, you know, those open source initiatives die down in the middle. And, uh, there is a specific commercialization aspect from the beginning or the inception stages.
So what we see, uh, for example, with Terraform Elasticsearch, these are like great examples. Just like they now, these projects have been pivoting to a different, uh, business license. And, uh, this is also reflective of the fact that open source community leaders have to come together to see what other funding models are available, what kind of business model we have to pivot to, to ensure that this whole, uh, open source innovation remains sustainable and well funded.
And I know that, Robert, you come from that, um, space. So maybe you also shared some of your thoughts on this topic. Oh, for sure.
That's, that's why I changed the title. Chopper of Wood and Carry of Water. You know, it's what we do in open source, right?
It's based on the effort that you put in is the impact that you're having on the project. Um, and really the most thing, the, the thing that's valued the most in open source communities is contributions. What this letter is calling out is that some companies aren't contributing.
They're benefiting from this, um, and expecting not-for-profit organizations to pick up the slack while they make money off of it. And so this is a classic tragedy of the commons problem here. So is as the use of Kubernetes increases, um, certainly every single one of those Kubernetes installations has to pull down containers.
And where are those containers at? Um, and who is hosting those? org, um, petabytes, um, the, as the, uh, that project becomes more and more popular, you would expect that if it was a private company, they would make more re revenue.
Uh, so as EKS goes up in, uh, uh, you know, popularity, Amazon makes more money. Oh, it works out. So yes, they're incurring more network storage, compute costs, but they're making more money off of it.
Not-for-profit foundations that host these projects that pay for the CICD hosting infrastructure, they don't make more money. And so eventually what happens is it's not sustainable. And guess what?
All the companies that depend on that, and we're not just talking about technology companies, we're talking about banks, insurance companies, retailers, they should be very concerned about this. Uh, especially if they're using services that depend on this open source. If they're concerned about these things being available and their business is dependent upon it, and they're paying a service provider to run this, I would expect that they, well, I would hope that they would demand from the service provider that they support these things because it is part of their value chain.
It's just good business to, to support this. And unfortunately, with the tragedy of the commons, uh, a lot of large companies that are making plenty of money off this say, eh, somebody else will do it. So do we not know who's using this stuff?
And I get that there's an issue here, but I'm not quite clear that an open letter was the way to go with this. Or could I not just call up, you know, the CIO of some of these organizations and say, you know, you guys, you know, maybe I'll send them in a little note. It will say, you know, dear, CIO freeloader, you know, you're causing me issues.
This is all gonna be, Well, it said a little nicer than that, Mike, You know, but Robert, I mean, you're right. I mean, this is like a digital common problem at scale. And you and Mike is exactly right about this freeloader aspect.
Like, they're, like surveys done on this. Like, what is it? But almost a hundred percent, like up to 97% of the users that open source really don't give anything back, whether it's financially code, documentation, bug reports, I mean, it's, and but addressing it in a letter, my eyes kind of glazed over at these, these attempts, like in terms of any type of consortium or initiative, you almost have to go directly to the, to the, you have to go directly to the offenders, and you say, look, you, you need to change your, your approach.
But, Oh, I, I agree. org, you know, with, with, you know, uh, and, and heck, I remember, um, a year and a half ago, Fastly making ane dash over at Fastly made a big announcement about, uh, 40 million a year, um, to open source projects, uh, with their Fast Forward program. And they really focused on the Linux Foundation.
So Colonel and CNCF Jenkins, um, certainly our friends over at Node, uh, open js. So, you know, what's missing from this is, I agree with you in an open letter I is, is like a, a, to steal a line from, from Rick and Morty. It's like, you know, a, a a a temper tantrum to say you're quitting Twitter.
Um, it, it's, it's just like, okay, great. I do it. That.
Yeah. Yeah. And, and so what I would, oh, go ahead.
Doina the Problem on this, like, there are this, this is twofold, right? So the funding pipeline, which we are talking about, right? So open letter is only a motivation to say that we are in trouble, right?
But there is another thing which we should not overlook, is the payback models. Why we should concentrate on both of them is it'll trigger a lot of open washing. It'll trigger a lot of late, uh, capitalism in the open source space, which we have seen with Terraforms of the world and elastic searches of the world.
So I, I believe that, you know, I mean, I, uh, fully believe that these people have tried to approach enterprises and tried to kind of trigger negotiations on how, uh, they can get the funding pipeline healthy, healthier. But at the end of the day, it's a, it's a basic issue of, you know, we cannot sustain or survive with the same models, which were defined in 1980s. Uh, we are now having AI triggers, for example, the con contributors, like, how would you stop ai, uh, native contributions to these open source projects, right?
Yeah. We have to fill the security gaps. We, we have a lot more, like 95% of your code base, uh, according to a black deck survey is open source.
So there is a fundamental issue. The nineties low. All right, Tom, Tom, how far do we go with this?
So let's assume that, uh, there has been some sort of communication and it's been roundly ignored. Do these associations then engage in some form of public shaming to get everybody in line? I mean, how far do we go?
Because, you know, other people are suffering because of, you might argue, gluttony. Well, I, I think that you're right. These people probably did already reach out to the CIOs of some of the worst defenders.
And and we've covered this a few times on the rundown where companies have come out and said, you know, Hey, Amazon, do you realize how much of our money that you're stealing every month by, uh, using our open source database in your product and basically causing backend hits on our servers? And, and there's a, you are, right? There's a point where you get to where you have to just name and shame, right?
And, and I think though, the problem we're gonna run into is that most of the naming and shaming is gonna be the same eight or nine or 10 companies that have, you know, huge workloads that they built off of this stuff. And, and in order to illustrate that perfectly, I'm going to steal this meme from the internet that has copyright images in it, and I'm just gonna broadcast it everywhere. Oh, what do you mean that I have to pay for that image?
Oh, I, I don't understand licensing. I don't know how it works. Why, why are you holding me accountable for something that I had no clue about?
And that's kind of the game that they're playing, right? Well, I, I was just using it for a project. I, I didn't realize that I had to pay if it was a commercial entity.
What do you mean by commercial entity? I mean, yeah, I make money off of your software, but not me. 'cause I'm just, I'm a small little mom and pop bookstore on the internet.
And that's the, where you're getting into the, the trying to slice that, that pie really thin to get what you want. Because to, to Gramma's point, we're using ideas from the nineties in the eighties of collaborative development and kind of this, um, for lack of a better term, touchy-feely development style, uh, in a world of cutthroat capitalism where if I can take a free piece of software and make money off of it, then my profit margin is infinite. And that's what developer, or that, not developers, developers hate that, but shareholders love it.
And that's what they want, right? Is they want to build the biggest, most massive empire off of the cheapest, freely available things that they can find, and they'll solve that problem later. How many times have we heard that, oh, this is just a temporary fix.
We'll, we'll, we'll make something better later. They, they won't, they'll keep using this until they absolutely have to stop. And the way to do that, unfortunately, for open source developers is to play hardball and say, okay, cool, we're cutting you off.
So, yeah, I, I suspect what you're saying, Oh, go ahead, Tom. I'm sorry. I just wanted to respond to that.
Just the project. Yeah. So I suspect that they, that they probably did, as you said, Tom, they went through back channels and probably didn't have much, much luck.
So they're escalating it up to a letter. And then beyond that though, how, how, what do you do? Like, how do you affect change from these bad habits that have been lingering for years?
You, you literally have to cut them off publicly. You have to come right out and say, okay, you are not allowed to use this anymore. And if you do, you have breached the terms of the license and we will sue you.
Now, if an open source project can't afford to keep the lights on, I don't think they can afford lawyers. However, there are luckily a lot of lawyers out there that would love to work for one of these projects, um, and kind of make a name as the people who brought down Amazon or something along those lines. But no, you're, you, you're gonna have to play hardball and all you, I Was thinking it's gonna go Legal, get one developer to lose.
Yeah. If Amazon, Uh, not more, like there are a few more, uh, steps which we can take, and I'm open source advocate, and I'm, I don't go that strong as Tom is advocating for, but I think we all, I think the central problem is that there is no central tracking for all this, right? I mean, we'll have to get serious about that.
The second thing I also would advocate for is start to look into what works for today's era, right? What licensing, licensing models like this late, uh, late shift to, you know, commercial models, why is it happening? It, is it a trigger?
It's, is it saying something to you? Because like open source help desks, uh, open source services open, like be more creative in, you know, uh, thinking through how you can solve these problems with new capacity, new service models, new initiatives, new services, right? And these foundations need to think through, like hosting a project in their capacity and space is not sufficient.
They need to also be creative in building that funding pipeline with, uh, the enterprises and have a dialogue of co-creation with these guys. I will tell you, it's all gonna break much sooner than you think. So let's think this through for a minute.
For every developer, there's gonna be 10 AI agents that are essentially 10 more developers paint banging on these platforms, trying to pull down containers and whatever else it is. So I don't think any of these associations are set up to, uh, provide that level of capacity. So it's probably only a matter of months now before some of these projects just keel over and break.
So that'll force the issue. No, Well, they, they rely on the service providers, um, CDNs cloud to, to host, um, these releases. And, and that's the real issue here, that as usage goes up, the, the foundation's revenue doesn't go up.
So all the money is going back to these companies, which are ironically or maybe not, ironically, making a lot of money off these, these things. Now, I will say this, there are a large number of these big companies that are supporting this, but not in a holistic way. They are supporting projects that they believe are important to their company.
So understand this, AWS is a huge supporter of container D. Um, maintainer works at AWS and only works on container D not any AWS stuff. Um, AWS also donates millions and millions to CNCF.
So does Google, um, Microsoft, Oracle. It's the other things. It's the other things that are, are, are crucial to this infrastructure that are neglected.
Um, you know, it, it's, I don't think people understand that node is petabytes of data. It's really expensive, and thank God vastly stepped up for that. But what about that long tail?
Um, we need to get a holistic approach for this, and I would argue that the foundations need to get better at communicating what's in it for me. The with them for the provider. If you give us support and credits, we are gonna tell the world that this open source project uses you.
And of course, you know, the salespeople that big IT company, when they run up against the big bank, the big insurance company, and they question scalability, that company, that salesperson could say, well, you know, we help out this little open source project called, you know, the Linux kernel. I think we can handle you. Um, they need to weave that story in to help the company make more revenue.
And with marketing, I don't think they're doing that. And, and that's an opportunity for our friends that signed that open letter to kind of lean in on that. All right, folks, we can go on forever about this, but I'm gonna move on to the next topic.
Just at one point, hey, foundations are mad as hell and they're not taking it anymore. Now we'll see how it all plays out. Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back in continuing our conversation about interesting open source technologies. 0 is finally complete. It's been worked on now for, I don't know, I feel like maybe a year or two.
It's hard to keep track of these things, but Web assembly, the theory of the promise at least, is that there's a file format that we're gonna be able to use so that our software as we build it, can run anywhere. You remember the promise of Java. Well, you know, wasm is trying to like bring that whole notion back and we're gonna write once and run it anywhere.
At least that's the theory. And there's a consortium called, uh, byte International that kind of heads up the, I guess the development side of wasm. And then we've seen the Cloud Native Computing Foundation kind of step up to handle more of the runtime environments for wasm.
And these things are supposed to be coming together in some interesting way that will drive some level of innovation. 0, we finally got a version that works. And, and well, you're right, it is, it has taken a long time to get these, uh, features and new releases out.
Um, and, you know, but remember, this is free. Uh, so nobody's paying for it. Uh, uh, well, rather we aren't paying for it.
Somebody is. Um, and, uh, but it takes time to do this. You know, it, it, remember how long it took to get data persistence in Kubernetes.
Uh, we, we went through several paths, uh, to, to get there. This release is really boring and necessary. This release has got a lot of stuff dealing with memory and garbage collection, and these are the blockers for greater adoption.
Um, and, and that's what's exciting about this. Um, you know, um, you know, Gima is certainly far more of an expert about this than I am, but what I see here is that they're coming out prior to CubeCon. Um, and, and being able to say, Hey, look, we've got a release out.
It, it's, it's a major release. It starts with a three. And, and so, um, you know, they're coming out and saying, we have solved a lot of the blockers to adoption, and that's gonna be really exciting.
Now, I don't think any of these features are, are, are, there's going to be issues with one, two, maybe all of 'em. But now that they're released, the companies that are dependent upon this stuff, and you're choosing Wasm as a platform for running cloud native at the edge, great now they get to start looking at it and really pushing it. This is a good thing.
The more opportunities we have to take this huge body of open source and cloud native and get it to work in other places. We did it for web services, we did it for GPU workloads. Now we're doing the edge.
This is a very positive thing. And yes, it took a long time, Mike, And well, we'll come back to that issue in a minute, but I just want to get Garima's opinion on this. One particular thing is, you know, what I heard from developers all the time is that they like this idea, but every time they put their hands on it, they come away with one impression.
It's frigging hard, and we don't have really a good set of tools for the developers to go make this, you know, dream a reality just yet. So do we need, you know, a whole nother rev of tools here for the developers to make this work? Yeah, I think it's very interesting times, uh, now and we are talking about this AI browser race and all that, right?
So it all boils down to the fact that we will see a lot of action in the edge space, and we have to go cloud native at the edge. I articulate a few use cases for use just to kind of, uh, for the viewers to understand why we are talking about this and why this is, uh, becoming extremely important in the age of ai. So for example, who is, who would be the potential users for web assembly?
Um, kind of applications would be like e-commerce platforms. 0 release because it enhances user experience. You know, if you think about, uh, uh, 3D configurators for example, or real time image editors, uh, that it makes it more easier for e-commerce platform to adopt to that edge native capacity, right?
Then we also see a lot of like sensors and sensor based use cases for, uh, you know, get to the kind of real life. There's another great example, which I will use is, uh, web assembly, uh, in online ID platforms. If you see replicate, for example, if you have used it or Code Sandbox, these are great use cases where you can run compilers and interpreters in the browser, right?
So why this whole, uh, you know, the suite of features are important is that, uh, they have enhanced language support, right? And they also have, uh, done some performance optimization as, uh, Robert was speaking about the various, uh, performance enhancements, uh, regarding, uh, 64 bit addressing, for example, uh, memory space, uh, and so on and so forth. So I think it creates, uh, a lot of, uh, more capacity for the web ecosystem and the edge native computing itself, uh, which was resource constraint, uh, from the beginning, right?
Um, there are other, uh, aspects of this release, which are also addressing some kind of, uh, service lead serverless challenges in the past, and they have, uh, some, uh, advocate for some potential solutions, uh, in this release. So that is also a great start to kind of, you know, watch out for. All right, Tom.
Um, going back to what I was talking about on timing with Robert, uh, I get that this is a major undertaking and it has a lot of promise, but it has taken a long time, and I have a conspiracy theory that says that maybe, you know, we're just underfunding the effort required here because it's so disruptive, and a lot of players are like, yeah, we don't wanna rush this one because it's gonna change a lot of, uh, you know, who's the dominant players of what, I think you're right, but maybe not malice, just lack of thought about it, right? Uh, maybe they're hoping, well, it's complex. People don't want to implement it because they don't know how to do it, and my way is easier, even if it doesn't do exactly what you want it to do, and we'll kick the can down the road a little bit further.
Uh, I would rather them take the extra time, right? How many times have we seen a standard get rushed out the door, or, uh, my favorite analog to this is things like operating systems, right? Uh, how many times have you heard from people, oh, well, there was nothing in that release of insert operating system here, uh, that really wowed me.
So IIII don't, I think they've lost the plot, right? Like, there's nothing magical about this anymore. Um, I hear that literally every quarter when there's new release of an OS or every year when there's new release of a mobile device.
And then going back to what Robert said earlier, yeah, sometimes what you have to do is you have to have the release that worries about mundane things like garbage collection or ensuring that when you install it on a certain model of edge router, that it's not gonna make it catch on fire and burn down a base station. Uh, you have to do those things because that's how you make it a stable, reliable platform. Like, it's like Debbie and, uh, releases.
They're, they're built on old packaging because it works. We've proven that it works, and I think that the, the companies that are kind of positioning themselves as alternatives to this standard are wanting to capture the early adopters. They're wanting to get people to jump out there and use their platform and write code that's more sticky to their platform instead of doing something that's more standardized, like using wasm.
So I, I would hope that by taking the slow road, eventually this will emerge as the dominant way to do it, because it's the way that you can do it that doesn't require you refactor your code every three months, and it's not going to cause massive problems with devices that adhere strongly to the standards All. Robert is Tom, right? Simple inertia, or is there something else at work here?
No, he, he nailed it. He, he paraphrased the quote that Miyamoto never said, which was a delayed game is eventually good, but a rush game is forever bad. Uh, you know, it, it's, you, it, this takes time.
And, and, and Tom, I agree completely. Look, you're dealing with open source, you're dealing with a lot of different stakeholders, and they do it out in the open. You know, this isn't a small Tiger team that is releasing, um, you know, the first version of the iPhone, uh, and get it out.
Um, it, it, it, and, and remember that didn't even have an app store. Um, so, uh, you know, and, and it had that weird connector, strange, um, but look, it, this takes time, and I really appreciate that they're focusing on boring infrastructure, memory, languages, you know, that sort of stuff, because those are the things that are making it difficult to adopt their bet is that the tooling around that will get there. Our friends that make tooling for, uh, containers, um, you know, we would hope that, uh, our friends over at maybe vs code IntelliJ Eclipse would, would start building.
Uh, and they already have this, but better, uh, tooling to use wasm. Our CICD friends would start working on this. They, they've got a lot of great experience with Docker deploying containers.
Let's apply this to wasm. I believe You can use Docker desktop to build wise and apps. And so they've definitely seen Perfect example of the tool vendors catching up.
There You go. Yeah, there is one more aspect to it is that this space is also evolving, right? I mean, if you think about devices or backend systems or, uh, language support, all this is kind of evolving at a great pace, and that is also a challenge for this kind of capability, which looks at portability, interoperability, performance issues, and Edge Native is not, uh, you know, easy to kind of deploy, right?
So it has its own nuances and it takes time to kind of ensure that everything is, uh, safely portable and interoperable. Alright, let me, let me test a polling here of one John Schwartz, you sit out in the valley, you, you hear, you talk to these companies all day long. Anybody out there like even knows how to spell Wasm?
I mean, you hear anybody talking about was No zero. Um, but my takeaway from this is that although this might on the surface seem like some sort of incremental announcement, I think at the core it's pretty profound. I mean, and I, it's, it's basically this is a platform that's gonna support high level programming languages and allow for larger applications.
I mean, that's kind of significance, but I guess here, I'm in New York right now, but saying here, euphemistically in the valley, it's all about, it's pretty superficial, varnished, shiny objects, AI agents. That's, that's, that's the focus and the obsession, the stuff below the, uh, beneath the weeds or the, the, the, the mechanisms that make things happen, they're almost secondary. It's all about the surface.
All right, well, folks, I'm gonna leave it there, but I would remind everybody then, if you wanna learn more about Wasm, do come to CubeCon. It's in Atlanta in November, and that's where a lot of these conversations will be taking place in like most revolutions, I think they started a long time before anybody actually recognized that they were happening. And I think this is the example thereof.
But meanwhile, we're gonna be committed to shine and the light on Wasm more and more because, well, we think it's a good idea, and we'll see where it goes from there. We'll be back in a minute. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers Network. Hey, folks, we're back.
And the third block deals with an announcement that was led by Snowflake and a bunch of its partners for a new specification for a, uh, semantic model interchange format. And the idea here is that, and I'm, let me explain what semantic models are. First is a lot of organizations will take the terminology that they use to drive their business, or what the terminology that drives their vertical industry and put it into something that feels like a semantic model so that they can simplify interoperability.
And if you have this in place, it also makes it easier to move from one application environment to another. Now, the number of companies that have one of these is probably not that large, but more and more folks are thinking about building these things in the age of AI because they're gonna be needed to drive a lot of these AI agents, um, John, you know, snowflake and all these data management companies. Are they the folks that are really gonna be supplying the, uh, picks and shovels that make all the money in this AI gold rush?
'cause it sure seems that way. Yeah, I think you're right. I think you're right.
That's what makes them so significant. Um, and that's what I, I think makes them a pillar in a sense, like the Switzerland of the development. So yes, they are a key provider and they have created a niche for themselves like a few other companies have, um, where they work with everyone rather than work against someone over for a small piece of turf or some sort of developing, developing part of the, of the ecosystem.
So, yes, absolutely. Although, um, I'm gonna ask, gonna ask you this, Mike, we've been talking in the previous segment about initiatives and letters. Do you think there's a lot of hef behind this one given the players?
I think that the players are still relatively small. I don't see a lot of snowflakes direct competitors signing up for this just yet, but they are interested in having a chat with one of the consortiums about taking over the governance for this thing. And Robert, it seems to me, whenever these initiatives get started, those consortiums play a big role in getting the momentum going and the word Absolutely.
Absolutely. Um, you know, if, if it's just one company, if it's just one company that's a steward of a thing, open source project standards, it makes the other people in that space nervous. They're Concerned that that individual company has too much power.
So when you place that company, instead of owning everything and controlling everything, puts it into a place where others can provide input, that actually increases the surface area. And so it, it's basically, we're going to turn this over to a neutral third party that is gonna oversee this and make sure that we all follow the rules that we agree upon. And so we're all gonna collaborate on this thing, and then we're gonna go and do our own thing to make money off of it.
It actually is the way, is the best way that we have, uh, there's always areas for improvement, but currently it's the best way that we have to collaborate and well encourage collaboration and bring people in and lower risk for those other companies to invest their time and money. Yeah, there's not a lot of critics available, uh, around this, uh, announcement yet, but I opened this forum for some critical comments, and I think Robert has pointed out a very good point. Like, you know, when a competitor or a specific company dominates to, you know, build up a standard, it's no longer a standard, right?
So it'll be very, very interesting to see how this translate into a third party vendor neutral consortium based, you know, movement, uh, adoption as well is also something which I am looking forward for, like how companies applications, you know, suite of enterprises would adopt to this kind of, you know, open standard is another area, gray area as is today and implementation, like how the implementation will happen. Like, this is all fancy, like looks good on paper, but implementation is the real meat of the conversation. So you got to have real people who can do the job for you.
So you'll have to have, you'll, uh, have to go beyond a founder driven roadmap to a community driven roadmap for this. Mm-hmm. Tom, I have a pet theory and it goes something like this and I'll grant you, it's another conspiracy.
But, um, in the rush to support AI agents, and we need to make data accessible to these things, we have seen movements to standards like this one. And I'll add in, uh, MCP and A to a protocols and all those things. But an interesting event might occur on the back end of all of this.
We're gonna turn all these data platforms that we've found ourselves locked into over the years will become replaceable. They'll become disposable because I'll be able to pull data from them dynamically as needed. And maybe AI is finally gonna set us free from all these data lock-ins.
What do you think? Am I crazy? You're not crazy, but I think there's a little bit more to it than that.
I love the idea of being able to finally escape from the chains of the database that's been silently toiling underneath the, the hood this whole time. But the problem is that companies have a way of building in, you know, additional features that allow you to, uh, take advantage of some tweaks. Uh, my, my favorite is from the networking world, that while OSPF is a standard R protocol, nobody's OSPF is identical amongst any of the implementations because they all do something a little bit different to handle corner cases or increase performance.
Because it's, one of the other things that I'm hearing from a lot of companies is I, uh, do research into AI security is that a lot of these data platforms or kind of monolithic and built in a certain way to do things in a very certain like cadence. And when you need it to do something other than that, you eventually end up having to build your, your own version of it because you need, you know, better performance for record retrieval or something like that. Or the, the snowflake can't munge the, the data the way they want it to, and, and then they go out and build their own.
And then they realize that maintaining their own is stupidly hard. And by that point, hopefully, uh, a more standard model is, uh, caught up with some of the features that they need. I, I think that ultimately what's going to happen is that companies are going to agree on a set of standards that everybody should adhere to, which is what the whole standards body should be, because they don't want to do the hard work of programming a better solution on the underside.
They wanna sell features to companies that are gonna buy on, you know, the, the front side, right? Um, you know, it, it allows you to, I don't know, solve the riddles of the universe or I, I don't know, make sure your CEO's never late for a meeting, but that means that the data on the backend has to be consistent. It has to be usable, it has to not exist in some kind of weird foreign SQL language that nobody understands anymore.
And that part's boring for most developers. So we all just agree we're all gonna use this database even though we hate it, because the best one we've got right now, 'cause I don't wanna write another one. Grima, do you agree with that?
Were you just putting up with the database though? I think, uh, this is great arguments, right? And, uh, again, uh, there are flip sides to both, uh, uh, if you don't put implementation meat to all this, it becomes a checklist item, right?
So who invest in those standards? So I think there is a right balance to be found, and this is to be found by the community itself. I mean, that is the beauty of, you know, all these standards and open source initiatives that once the community buys into this, I think it'll all, um, you know, already be evolving and trying to kind of foster the need in the right direction.
John probability assessment that I'm gonna see Oracle anywhere near this project. That's A good question. Wow.
Yeah, with them, you never, you never know whether what, whatever they tell you. Um, that aside, um, this was, I think its going back to think where something Robert said, this is a very savvy move by Snowflake. You know, you, you, you, you, you collaborate with others and then you benefit in the end.
So, um, I, I, I think there's a high probability of of success here. I usually, I'm usually really down on consortiums, but this one, I'm, I, I think there's some upside. I'm always reminded of that saying, uh, if you wanna go fast, go alone.
Yeah. If you wanna go far, go with a team. Mm-hmm.
So Robert, you've been around these projects before, um, you know, it's interesting to me that they launched a project before they went to a consortium. So, um, to what degree are they just trying to force somebody's hand here and then they're just trying to force an issue and maybe whatever we come up with won't even look anything like this thing, but, um, how much politics is at play here? No, it's a thousand percent.
It's all political. Yeah, that's a a hundred percent. There you go.
I mean, look, it, it is, um, they wanted to get this out. Uh, you can see a lot of these announcements leading up till Q con because they want, they know everybody's gonna be there, so let's get it out there and we could talk about it in person. Um, and so this is, look, anytime you start working with, um, your partners, other ISVs, bring 'em in.
Uh, that's a good thing. But I think that BlackRock getting listed there, that's really interesting. Um, and they worked really hard to get an end user, um, involved, you know, with, with some, with some brand.
And BlackRock is great. They love sharing their opinion, uh, good, bad or indifferent about technology. They're, they're, they're awesome about it.
And, um, so I, I think that this was their way of just getting this out. This is where we're going. Would you like to join us?
And so I think part of this was to get other people to join. I don't think it was to, you know, warn anybody. I think they're committed to this.
I think they want to make it successful. And I believe they announced it so that they could get more support, multiple hands make for shallow bugs. I'll play a devil's advocate here.
And Robert, you know, this game, right? Um, we have played it, uh, many times that, you know, standardization. Um, al always relies on the fact that what is the intent?
If the intent is capitalism, it would not fly. So I think, uh, there is some course correction and some learnings which needs to take place because, um, uh, if you see, uh, how the community will join in this movement is the reputation and the intent and the aspects that, you know, how do you invite the contributors in the space, right? So I, I believe that there will be some trigger points if they really want to make it a success.
They would like to bring in people who have high credibility and reputation within the community to drive some initiatives, right? They need to, uh, focus on how to build a broader capacity with community, right? So how that contribution, uh, takes place.
And then the third aspect is intent. You know, the intent need it is needless to say, if it is commercialization or capitalism, it wouldn't fly at the end. I think.
Do I think, I do think that, oh, I'm sorry, Mike, I just wanted to, to add to that. You know, you're, you're absolutely right. Rema, I bet you the big takeaway from this, what's happening right now, now that this is, has gotten announced, is that everybody that competes with BlackRock is looking at this like, well, wait a minute.
If BlackRock is doing this, maybe we should. And that's much more powerful than the tech companies getting involved. That's really interesting.
A lot of conversations in Jersey and Long Island, Connecticut, Manhattan happening right now. I think that Tom has the right point. There is a lot of end users who are just p****d off and fed up with IT companies that have taken their data and locked it up for them, and they can't get to it.
And I think that, you know, there's gonna be a movement around this. And this may not be the specific specification that drives it, but it is an ongoing conversation. And so my prediction is we will see the launch of something called the Data Freedom Foundation, gave me all these kinds of little projects around One notion is that the data belongs to the people who created it and not the people who provided the IT platform that housed it.
'cause people are getting angry. And you, and, and as you can see, there's a, there's a trend around that whole topic for the last three series. So anyway, I wanna thank our folks for sharing their knowledge and their expertise today.
As always, they were great. And I wanna encourage you all to stay tuned for the next lineup of the Techstrong tv, uh, portfolio of shows that are coming up right behind us. They're all equally awesome.
And thank you for spending some time with us. We'll see you next time. Hey everyone, welcome back here to Techstrong tv.
You know, I've been trying to get this next guest on our show for since the summer, and it's already almost middle of it's past the middle of September between my travel and his travel and scheduling. It's just his people. Couldn't get my people to make these people get it together.
But we finally did. I'm really, really happy and proud to introduce you all to Imron Khan. Imron is the Chief Customer Officer at suse.
Imron, welcome. Thank you, Alan, to Tech Drunk tv. Yeah, Thank you.
And I'm, we finally got here. Yes, we did. Better late than ever, my friend.
Better late than never. Hey, Imel, before we even start, I got a personal question there. It's not personal to you, but it's a personal question to me.
I am always caught in between, and it's probably been my funny French accent, suse, su ssa. I've heard it pronounced all different ways. How do you pronounce it?
I pronounce it as soa Susa. Okay. We're gonna go with Susa today until I'm told differently.
Very good. Fair enough. Imrad, chief Customer Officer, that conv that title, can cover a lot of sids.
Give us an idea of kinda what actually you as Chief customer Officer at SUSE does, and maybe a little bit of your personal journey journey getting here. Yeah, sure. Thank you.
Um, Alan. So, um, I, as you rightly said, I'm the chief customer officer for suse. Um, so what do I do?
I, I look after our customers, right? So I manage all of our post-sales organization, our support, our services, our customer success folks, um, and anything to do with the customer experience. That's pretty much what I look after at suse.
Um, my journey, I've been with SUSE for about three and a half years. Um, I came from another software vendor called BMC Software, um, sure. Where I was their Chief Customer Officer, uh, for a number of years.
I think it just over five years prior to that, I was a, a supply chain software company called JDO Software, which is now Blue Yonder. And prior to that I was at hp. Um, so yeah, I've been in, I've been in this world now for a, for a little while now, always in the customer facing kind of activities.
Very cool. Yeah, no, very familiar with B NM C, actually the CEO. And I'm, I'm old and I'm drawing a blank, I apologize.
But he came from ca Oh, I'm in sae. Uh, I'm right. I'm on Saeed, so I know, I know I'm on.
Well, I know him from his ca days actually even. Right? What a, a great gentleman.
I, I enjoyed interviewing him. I always enjoy any time we get a chance to spend any time with him, but they built a great company there as well. Um, but Imran, we're here to talk about Susa today.
And and you're obviously eminently qualified for this chief customer officer role. As we were talking off camera, I was mentioning, you know, depending who you talk to, you ask them who Susa. Some people tell you, oh, they're an open source company.
Other people tell you, oh, they're the Linux company. Other people say, oh no, they're cloud native. They're the cloud native company.
Of course, in recent times we've added AI and there's a security element and there's more it, if I had it, say, Imran, I'm going to give you 60 seconds. Tell me who Susa is. Yeah, no, that's a great question.
Um, uh, so suse, we, uh, open source, uh, primarily, um, uh, Linux, absolutely right? Edge ai, um, as well as cloud native. Um, so we do all of the above, right?
So you're absolutely right. And I had the same, I had the same experience when I joined suse. I had to go and Google them and go to their website to um, uh, kind of figure out exactly what portfolio they covered.
'cause there was so many. com to actually look at our extended portfolio. Absolutely.
But there, there, there are, are building blocks, right? Open source is, is fundamental to the DNA there, it's kinda Absolutely Your heritage. Yeah.
Uh, as is Linux, right? One of the probably early foundational Linux distro providers, right? Uh, through acquisition and, and, and really support of CNCF Kubernetes containers, really a cloud native, native company, if that's a word or a phrase, right?
Um, early into ai Yeah. Big adopters and, and, and prevalent of ai. Um, it, it's interesting, you know, when you layer these up, and then I I, I'm gonna throw one other thing at it, and, and it really goes segueing into our topic of discussion.
SUSE is a European based, it's a global powerhouse, but proud of its European heritage. Absolutely. Absolutely.
And, and I, and I think that is also part of that DNA that makes Susa Susa. Yeah, you got it. Absolutely.
And that's, and you know, back to, we are very proud of our, our European heritage. And, and you're absolutely right. We operate, offer, um, operate globally in multiple countries, uh, multiple regions across the world.
So it doesn't actually hold us back. It actually makes us more stronger, especially with the subject that we're gonna cover today, Especially in this day and age. It's not a bad thing.
Um, Enron, let, let's talk about that subject. Suse recently, uh, you know, a month or two ago, uh, announced a, a big push into, uh, digital sovereignty and, and, you know, sovereign IT as it's being called now, sovereign it, uh, operations, sovereign IT solutions. Talk to us a bit about that.
Yeah, no, absolutely. Uh, and one of the things we announced a, a new offering, um, way back in July when we were first meant to talk, um, when it was fresh off the press. And some of that was driven by customer demand as well.
And, and as you mentioned, digital sovereignty is, there's kind of like three pillars to it, right? Which is around data, technology and operations. Um, we'd already started the journey on some of our data and operations based upon customer demand.
Um, but it was something that was kind of like more of a prototype because they wanted to know, look, how are we gonna ring fence their data and how we are gonna ring fence the operations and how we actually support them as a customer. Um, but then with all the kind of global stuff that was going on, um, you know, it was something that we needed to formalize as well, right? And this is why we actually came up with our, our effectively our sovereign offering of premium support to make sure that we understand exactly what our customers wanted and how we could actually make sure that we kept them, you know, sovereign, as I would say.
Absolutely. You know, and look, it's a lot of macro factors that are driving the, the sovereignty issue, I think one is, is obviously political turmoil. I I don't wanna say turmoil, political, uh, well, let's say turmoil.
I can't think of a better word, but, you know, political uncertainty, right? Yeah. Let's, let's say that political uncertainty we're here in the US obviously, I'm here in the US recording this, and it seems every day there's a new headline about a different direction or what's on again, off again?
Tariffs. No tariffs, who's our friends, who's, it's, it's certainly interesting times in terms of world, uh, you know, relations. We have the EU arising as you know, it's a multipolar world that we live in.
Yeah. And the EU is certainly one of those poles, right? One of the powerhouses.
And, and in many ways, especially when it comes to technology, seems to have more of a political will to get things done rather than a sort of laissez-faire, just, you know, let it happen. Um, you have the age of ai, AI's, you know, it's changing everything. As, as you well know, as Souse is on top of it.
It's creating all new bedfellows, if you will. Um, increased competition, supply chains, shortening supply chains, you know, people having coming outta post COVID v out in the pandemic understanding about supply chains and, and wanting to shorten our supply chains. All of these things are driving this sovereignty issue.
Let's peel back the layers on Seuss's offering here. What, what, what exactly is it? Why does it work?
Yeah, so this was born out of a, a customer request. Um, whereas they wanted to make sure that we ring-fenced their data. Um, and we actually supported them through EU employees.
Um, and obviously having a global organization, um, sometimes we have a follow the sun model. We have, um, you know, with regards to support to make sure they get 24 by seven support. We kind of leverage the infrastructure that we've got around the world to actually make it more effective for the customer.
It gave us a challenge. Um, so what we had to do was ring fence their data in Europe, set up a localized EU support center that could do that coverage, um, to make sure that we were actually meeting their needs and give, and make sure that they could actually tick off their compliance as well. The good news is, is that we had a level of experience of doing this.
Uh, one of the arms of our, uh, company is called, uh, uh, ranch or rancher Government solutions. Um, so we were used to actually doing that. And rancher government solutions is, obviously, it's in the us it supports the federal government and a lot of activities out there.
So we had some experience of doing that where we'd ring-fenced a lot of that infrastructure as well. So, um, it was a, it was a company called OVH, uh, cloud, um, that actually came with the request to us, and we actually built that for them. Um, but then when, as you rightly said, with the uncertainty of the world, um, and some of the political drivers, it was an offering that was required, right?
So we were able to actually take that and actually kind of make it more of a prescriptive offering. So that way now they get localized support, localized contact, localized engineers, everything is actually, as I said, ringfence from that perspective, and it's dedicated support as well. Um, and you know, we've got a number of different contracts out there now.
We launched it hard launch in July. As I said, most of it was actually requested, uh, prior to that by some of our, our European customers. And now we're actually gone to market with it as part of, uh, one of our offerings, which is the three pillars that we spoke about earlier around sovereignty.
It covers data and it covers our operations. And we're doing a lot of work within our product organization as well to make sure that we go down the same route on the technology side as well. I love it.
You know, one, one of the challenges around this digital sovereignty, uh, space is this different aspects to it. One is where is that data that you're, what was the term you used? Ringed Ring-fenced, Ring-fenced.
Where is the data that's being ring-fenced? Where is it actually stored? Is it, you know, is it in one of the hyperscaler cloud providers?
Is it in a private data center? I, I'm not aware, is SUSE running private data centers now, or are you have partners who run the, the where the, the, the, the physical plant, if you will. It's all on our data centers.
So you Own, so SUSE owns their own, operates their own data centers. Yeah, it's a, it's our own. Yeah, that's great.
It's our, it's our own. So we worked with our own IT organization to make sure that we could actually have that, to give that level of comfort as well. That's fantastic.
You know, we were talking off camera, I, I wrote an article a couple weeks ago about the long arm of Uncle Sam, right? If, if you're, you could have a whole digital sovereignty ring fence situation, but if you are hosting it in a data center owned by a US company, a US based company, and the US government makes a demand on that for that data or access or what have you, the US company may very well open the, the kimono, you know, give the, the government, the US government access to that data. And, and that sort of defeats the whole purpose of digital sovereignty, doesn't it?
Yeah, absolutely. To me, that's just like a, no, it's just a glossary on front of what they're actually proposing. Um, and that's the difference between, um, US at suse, right?
We've actually got it end to end. Um, and that's what makes it more powerful. And it's right what I said right at the start, um, our European heritage allows us to do that more.
So, Absolutely. You know, Imron, there's, there's an aspect of this whole sovereignty thing that makes me sad. Uh, you know, I, one of the greatest joys I've always had on the internet, and I've been on the internet since it went commercial, right?
And probably before that a little too. And, um, I always get a kick out of, even today we do webinars and stuff, and I get people who log on from, from India and Singapore and Australia and New Zealand and Pap New Guinea, as well as all over Europe and Nigeria and South America. I, even if, and I luckily I, I've had a chance to travel and see the world.
Yeah. But it still gives me joy to see the whole world joining up right On at a webinar or some event with sovereignty. I feel like we are balkanizing if, if you will, the internet a bit.
Is that the future? Are are we gonna go back to a global thing, or, or is, is digital sovereignty the, the way of the world now? Yeah.
And that's such a, and you know, uh, you know, not that that's use this as a therapy session, but I I, I, I have the same like-minded thoughts as you, right? So now I've worked for global companies for the last nearly 30 years of my career, you know, having, you know, offshore locations, onshore locations across the world in countries that some people can't pronounce. Um, and I loved it and I enjoyed it and I still do today.
I think with regards to the future on sovereignty, you know, it's like what you said with regards to this uncertainty, you know, who knows how it's gonna play out, right? I hope it doesn't go too hard in that direction. 'cause I think we've done a good job in the world that we live in today, actually kind of unpicking those borders, if that makes sense.
Um, so that's my own personal kind of view on the subject. I think we're of a like mind on that. Um, so obviously the digital sovereignty offering is available in the eu.
Yes. What about other parts of the world where, you know, where is this also available? Yeah, so we started with the eu 'cause that was the biggest kind of request for demand that we had.
Um, but we are looking to actually go and push it out into different locations as well. So we're looking at other territories and most of it is gonna be demand generated, right? So once things start to pop up elsewhere, there might be situations like we've already doing it in the US with regards to our government services arm, right?
As I spoke about. Um, but there might be other areas as well that we actually look to tap into whether it could be contagious, right? So that before you know, it, Latin America might start wanting sovereignty rules and regulations based upon some of the things that are going on in, in the world today as well.
So I think there's an opportunity for us to actually roll it out dependent upon where, where the demand sits or unpick it, depending upon what we just spoke about. Right? Yeah, that too.
I absolutely, you know, I'm just sitting here thinking too is we, we spoke about who is suse before we said Linux and open source cloud native ai. We didn't mention that you're operating your own data centers, that you're an infrastructure provider as well. You know, I, I think that's one of the, uh, best kept secrets, if you will, in technology is really the, the full scope of SUSE's offerings, right?
And we only have 15 minutes here, but we could probably spend a day jumping in, you know, you mentioned rancher gov, you know, there's more I to, I totally agree with you, Alan. com to look at all the extended portfolio of what we do. 'cause I thought it was just a Linux company at that particular time.
And I remember speaking with some colleagues of mine, ORX folks that I'd worked with in the Bay Area who said, oh no, you know, they've got, they've got containers as well. They're, they're really big into Kubernetes. They just acquired this, this company called Rancher not so long ago.
So the more I double clicked on it as well, the more I realized we were a really good kept secret, um, uh, and we're a little powerhouse all by ourselves and, and, you know, ultimately open this video, we'll do some of that. The more we can keep on pushing our message out to actually realize what extended portfolio that we have to offer, uh, the, the better it is for us as well as suse. And, and I thank you for your, for your pushes for us as well.
Um, even our customer event earlier this year. I appreciate it. No, it was, I, I was telling you off, it was one of the best events I've attended in the last year.
I really enjoyed my time there. Um, Imran for people who are watching in this and saying, this is just what I'm looking for. How can they, how can they get more information and maybe, uh, you know, move along the path here with this, uh, digital sovereignty offering.
Absolutely. com, it's all on there. You'll see it.
We've done a number of different publications around it. This is obviously one of them as well. Um, we keep on pushing the message out.
We are there, we are ready, ready to rock and roll. We've sold a number of contracts already, um, and we see the demand increasing. com, you'll see everything you need to do, um, to actually buy the offering as well, as well as look at our extended portfolio.
Thank you, Imran. Thank you for coming on Techstrong tv. You know, I think I'm gonna add another thing to the Susa kind of DNA and that is opportunistic.
When Susa sees the needs in the market, they fill it. And there's a great example of it. And, and the, the whole way it came about from a customer asking for, it says a lot about the product process there, right?
When customers ask for things, you provide 'em. Absolutely. And thank you, and I'd love to come back on the show again, Alan, Anytime.
Let's not wait three months to make it happen, but we will. And we're going to, we should give a quick shout out. Uh, Han's gonna be in Prague in April, which we'll be here before we know it.
Hopefully we'll talk to you before then though. And, uh, we'll, we'll try to do something from there as well. Absolutely.
Thank you, Alan. Really appreciate It. Thank you.
Imran Kahan, chief Customer Officer at SUSE here on Tech Drunk tv. We're gonna take a break, go check out their digital sovereignty offering, as well as their rancher containers, Linux, and even data centers. But we're here on Tech Drunk tv.
We'll be right back. Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. I'm your host, Mike Baard.
Today we're with Daniel Barden Stein, who's CTO for Manifest, and we're having a chat about the need for software bill of materials known as SBOs for ai. Daniel, welcome the show. Thanks so much for having me, Mike.
Pleasure to be here. Alright, We have what's known as SBOs that are gaining some traction in the traditional world of application development. At least we think that folks are doing the right thing, and we're getting a little progress on DevSecOps.
But, um, in the, in, in the world of ai, what's different here about the way we need to think about, uh, software bill of materials and, and what should people be kind of working through? So about 18 months ago now, I embarked on a, uh, a bit of a research adventure with a, started with a very simple question, which is, given that SBOs are taking off as this globally accepted way to think about software, supply chain and transparency and software, how much of this applies to ai, right? There are many of us in this space who believe that AI is in many ways a subset of software that you can't build or use AI without putting it into software.
Therefore, how much of those common risks that we think about on this, uh, for software supply chain apply to ai? And after consulting with hundreds of experts, much smarter and more technical than myself around the world, it became very clear that many of those same classes of risk that affect organizations around the world, um, that most people think about when it comes to software supply chain security, also apply to AI security. Um, and I'm sure we'll get into the details, but everything from thinking about sources from open source risk, third party risk, continuous monitoring, lineage licensing, all terms that if I said them in a securities software security context, CISOs around the world would say, yep, I understand what all those things are.
And then you turn around and ask, so how do you plan to tackle that for ai? And most CISOs would probably scratch their heads and say, I don't know. I don't have a tool to do that.
And, uh, and, and I think this is all also bolstered, bolstered by two fact, or one fact, and one piece of news, to your point about the adoption of SBOs, even last week, cis a published, um, uh, uh, a document that was co-signed by 19 different governments around the world, all effectively endorsing SBOs is a very powerful tool for software supply chain security workflows. And the other fact that that makes us all the more urgent is we all know that whatever percentage it is, 90 plus percent of CEOs around the world are basically telling their companies to accelerate AI adoption as much as possible. And that's putting security leaders in the bind because they don't have the tools and processes to catch up with this rapid, rapid proliferation of AI systems.
Mm-hmm. If I do have an SBO M program in place, can I extend it to AI and is it really just another piece of software or a different set of art artifacts, or am I gonna need a separate framework for AI and sbo? Om, This is exactly why we kicked off the AI SBO m working group under ssa, of which I'm, uh, one of the co-chairs to help answer and educate the, the public on exactly these questions.
So it's my goal that people shouldn't need an entirely different set of processes or frameworks to handle this stuff. The last thing an enterprise security team needs, you know, I think the average enterprise security team has somewhere between 15 a hundred tools right now. The last thing I need is to multiply that number by two, to have an AI flavor of their endpoint tool and their firewall tool and their DLP tool.
But they, they will need Existing tools to adapt to the in, uh, intricacies of generating AI bumps, scanning models, scanning data sets. There are different types of risks that we're looking for and different ways of searching for those risks. And so what I continue to, um, advise security leaders, both in public and private, uh, industry is as much as possible user existing processes and frameworks.
But you need to be able to think about some of those more tactical bits, the ingestion, the scanning, the monitoring a little bit differently, um, as it pertains to AI security. But ultimately you want something integrated because even if you've developed the best model in the world, at some point you gotta put it into your software. And so you need to have those two things integrated rather than having two new siloed security systems.
What level of depth can I get to? Because a lot of times somebody will, for example, build an AI agent and then it's in invoking an API to an LLM somewhere. But how do I know what went into the LLM and how do I discover that?
Fantastic question. So one of the things that we've been hard at work at building is, uh, basically an AI bomb generator. So that, for example, helps our, um, partners and customers get from a model that's pre-trained, that's out on a hugging face into a robust history and lineage of how this thing came to be, what data sets it was trained on, the lineage of the data sets, who put them together, how are they licensed, et cetera.
So we can help organizations already go from, here's a Google Bert model or a Meta Lama 3, 1, 3, 2, whatever it is, and get to a very robust story about what is this thing, where did it come from? How's it built? Can I use it legally for my specific use case?
Um, when it comes to something like, uh, an agent system or an MCP, this is, uh, another great use case for why we want these tools integrated with software analysis tools because an agent at the end of the day is just software plus ai. It's a little bit more recursive, but we wanna be able to scan source code to figure out what APIs is it calling, what tools does it have access tool, what credentials might it have? How do we put guards guardrails around that?
So it's another great example for why, you know, an SBO bum isn't the the cure to all security evils, but it gives a very, uh, robust and structured account of how something is built and perhaps what it can do. And that's why it applies so well to models and data sets. And then the ultimate vision here is not to create a brand new artifact, but you know, I'll, I'll provide examples.
You know, we work with the next gen defense contractor that's actively being asked for a IS bombs from their government customers. And so what they end up handing over is one software bill of materials that not just lists the normal dependencies and licenses that they put in their software, but also the models that are included as well, and how they were trained in information about their providence and lineage. So the goal is not to recreate a new framework, a new standard here, it's making sure that organizations have the abilities to ask questions about their ai, their models and their data sets, and then put them into the formats or compliance artifacts they need to actually do something with them.
Hmm. How will we keep up with the dynamic nature of some of these applications? 'cause I'm likely to have multiple AI agents that will eventually invoke multiple LLMs and the LLMs may change, and it just seems like the pace and the rate of change is gonna be very high.
So how do I kind of keep track with all the updates and changes to the underlying software In the same way that we do already with traditional software? Like more, uh, very mature modern organizations with modern CICD pipelines push software to production multiple times per day, certainly much faster than LLMs are going to be regularly trained and tuned. And so it's another example we're learning from AI security and how to get a, you know, take a big step should come from what we've already been doing on the software side.
So if we look to the software security side, how do we make sure we are regularly scanning code given that it's now being written even faster with tools like Cursor and, and rept is we have automation in the CICD pipeline. So as developers write code and they push the code, there are a bunch of scans or processes that kick off that find various types of risk enforce policies and then help tell the developer, Hey, you need to go fix this thing, patch this vulnerability before this goes to production. We just need to replicate that on the ML side of the house.
And we've also already seen success doing this as well, right? Whereas we have the CICD pipeline for software, we have the ML ops pipeline for AI and ml. And so in the same way that there are automated tooling that helps developers write code quickly, find issues and fix code, we need to replicate that for model developers.
So if I'm fine tuning a model or updating a model or quantizing a model, how do I understand if there's anything that I'm doing risky as I'm doing it or find issues automatically that get pushed to me before I've finally saved this model and put it in my model registry? So at the end of the day, it's all about automation. It's all about plugging things in as far left as possible.
And ultimately, again, we're trying not to recreate the wheel when it comes to AI security. There's a lot we can learn here from existing software SU supply, uh, software security analogs. Should we be working towards, um, unifying these pipelines a little bit?
'cause I think in a lot of organizations you'll see, you know, something that looks like a TIGER team is off building an AI project and they may not have the security best practices in place. And fact, many of those data scientists probably know less about security than the average developer. But, um, should we be rethinking all these workflows to bring our existing pipelines and DevSecOps workflows and apply it to the development of AI applications?
Short answer is absolutely yes. We continue to see examples where you have employees or like you said, small groups just going off and building application, uh, ML enabled applications that may not have, uh, security best practices in place. We've already heard and seen stories of people that try to circumvent compliance needs for AI and ML by, you know, doing various sorts of trickery.
Again, ultimately, again, just like with software, we work with some of the largest organizations, uh, around the world and they have often have different business units. And each of those business unit is often treated like a, you know, special snowflake. They have their own processes and tools inside the business unit, but you still often have a central security team across the whole enterprise that's responsible for making sure that there's consistency and inventory and scanning across the business units.
We need the exact same thing for, for A-N-I-M-L. So how do we make this happen again, the last thing we wanna do is slow down innovation to get in the way of data scientists writing, um, you know, developing new models for their use cases. But this is where automation and integration are so key.
So as they're doing their work, there's tooling that's in place that can tell them, Hey, you try to load a model that is unauthorized, or this data set that you try to use from the public internet isn't licensed properly. So you're able to alert them to issues before they go deep on training them. And then I think the fundamental issue that most organizations are still struggling with here, which is the most foundational, is inventory and awareness, right?
You can't secure what you don't know about. We all are familiar with the concept of shadow it when the cloud became big 10, 15 years ago, now we're dealing with shadow ai. How do I know what models are being used across my enterprise?
How do I know if we put some custom model in a medical device that the cardiology business unit wrote it or the, you know, pulmonology business unit wrote it. Organizations just lack basic inventory and awareness about what are the models and data sets we have across our enterprise? Where did they come from?
Who built them? Are they being deployed? And, you know, asset management is a hard problem as you know, um, but that doesn't mean we can't help organizations try to take a big step forward on it.
When it comes to ai, Most of the AI software that I know is pretty much built using the same tools and components that we use to build other applications. So they would naturally have the same vulnerabilities. But are there also unique things that people should be looking for in AI applications that are attack vectors that they might not be thinking about, Fantastic question.
So, as most people probably know, models can have traditional software vulnerabilities just like software. Can we think of your pickle serialization or pickle to serialization threats, for example. You can exploit the software itself, but there are lots of other issues when it comes to other types of business and legal risk when it comes to models.
So for example, responsible AI licenses and traditional software licenses. We think, you know, permissive Apache two is good strong copy left. LGPL is bad with AI licenses.
They're use case specific. And this has already caused trouble with some very large, um, companies and government agencies where I might legally be able to use a model like Llama three one for something like summarizing emails, but I can't use it for anything with heavy manufacturing or defense or military or biometric applications. And so there's a, a significant amount of legal risk based on how you can use this model.
It goes even deeper than the model because it also depends on the data sets. So we worked with some very mature organizations that aren't allowed to use models that were trained on illegally gotten or improperly licensed data sets. So again, we're back to kind of a legal business risk because if that gets put into a product or a weapon system or a plane that might have to get ripped out at some point and, you know, ultimately cause revenue lost for, for organizations.
You also have other sorts of, um, traditional supply chain issues. Like when Deep Seq was announced, many people found various types of bias that, you know, the, the Chinese authors of the model may have written into the system prompts that would affect its output. So understanding who the supplier is of the small and this dataset are they trusted, especially for those who work and sell with the Department of Defense in the us.
Um, there's just a, a memo that came out a few weeks ago saying that there can't be any nexus to China and Russia in DOD acquired systems. So there's a, a compliance burden. Um, and there's a, just like with software in the concept of, of Lineage and Providence, the same is true for, for models.
There's a story with one of the world's largest IT companies that had an explicit ban on, um, a model like Deep Seeq, for example. And there's a user in a business unit that really wanted to use that model for a use case, took the model from the internet, uh, fine tuned it with some lightly with some data, and then declare that he had a brand new model that wasn't related to any noncompliant models and try to get that one approved by his compliance team. So again, going back to there's yes there traditional security issues and exploitation of models and data sets, um, your prompt injections, your data poisoning, et cetera.
But there's a whole raft of new issues around business risk, around legal risk, around compliance risk as well. That comes with model data setss, because at the end of the day, these things are black boxes and we need to understand how they were built and how they were trained Under the heading of physician Heal thyself. Will we at some point see AI tools for creating SBOs for AI applications?
Yes. And we've already started, uh, along that path. As with anything else, the balance of AI is comprehensiveness versus accuracy.
So we've been able to generate some SBOs using AI and be able, uh, are able to extract information that traditional software scanning tools or SBO M generators don't necessarily find. But you always have to make sure that they're not hallucinating, that the information is, uh, is indeed present and kind of validate the findings. So the short answer is yes, and we, and we've personally used this, um, uh, within Manifest, for example, to help solve some, um, difficult to solve problems around extracting dependencies that are just in unstructured code.
For example, things in c and c plus plus to get very technical about it. So ultimately, yes, there's a role for SBOs to help secure ai. There's all and security.
There's also a role for AI to help bolster SBOs and security. Um, even talking about things like vex, the vulnerability and exploitability exchange, which, you know, as a companion document to SBOs help organizations save time, you know, responding to vulnerabilities. There's a role for AI in generating and disseminating these documents as well.
Alright. So what is your best advice to folks then who are just getting started with this whole thing and, um, where should they be focusing their efforts in the short term? 'cause generally speaking, they're gonna have to deal with it eventually, right?
Absolutely. It's certainly a matter of when more than if. My primary advice to organizations that are already launched down the AI adoption path or are soon to, especially for SEC from the SEC for the security practitioners, is first to understand what their AI risk policies are, what allows them to, uh, use an external model or dataset and how they validate whether something is secure and trusted.
So first you have to know what good it looks like or what bad looks like. The next step is to actually start applying those policies automatically, right? So if somebody in a business unit asks, Hey, I found this model out on the internet, that's really good, good for this use case.
Can we use it? How can you get to a yes or no answer as quickly as possible? Third, then is all about inventory.
So once you define what good and bad looks like, and you now have a formalized process for how AI gets into the sys, the, the organization, since most organizations aren't building their own models from scratch, need to build an inventory because without that inventory and awareness you can't effectively secure. And then from there, there's some more advanced steps around how do you track all of your custom models or where the models get deployed into software. But it all starts with defining good and bad and making sure there's a central process by which models and data sets are adjudicated when they first come into the organization.
All right, folks, you heard it here. Transparency is gonna be everything. And right now we might be living in a age of black boxes, but eventually we're gonna know exactly what happened, when and where, and you're gonna need something that looks like an SBO that helped start that process.
Daniel, thanks for being on the show. Thanks for having me, Mike. It was a pleasure.
All right. And thank you all for watching the latest episode of the Techstrong AI Leadership Insight series. You can find this episode and others on our website.
We invite you to check them all out. Until then, we'll see you next. Hi everyone.
Alan Hummel. We're back here in our part two of our interview with Rebecca Kraemer. Uh, Rebecca is the CEO of a company called Q Secure.
com. We've had a few videos with the Q Secure team, including Rebecca's dad, David, my friend, Jennifer Legio, and part one of our interview with Rebecca. And all three of those really talked about Q Secure post Quantum cryptography and how Q Secure is helping organizations large and small, uh, get ready for as we call it, Q Day.
Um, but Rebecca, first of all, thanks for joining us. Secondly, there's a lot of people out here, you know, you mentioned quantum computing, and they say, oh yeah, that's something I gotta worry about in five years. That worry about it in five years kind of mantra has been a consistent thing with, with Quantum, it's kind of the same thing we hear with fusion nuclear fusion too.
We might have a working model in five years, right? Where we're making more energy than we expend to make it. Um, but from everything I know about quantum computing, it's not five years anymore.
We're getting much closer. There are people I think IBM has committed to having a commercially available quantum computer. I wanna say by 2029 or 2028, something like that.
Um, another friends of ours behind a company called, uh, ionic, I think it's called IONQ, uh, Nicholas, who's actually, so we're part of the Futurum group, and Nicholas Nicolo, excuse me, who's the CEO of Ionic is the chairman, just six degrees of separation of fus. I've had a chance to talk to him, but you know, everyone I speak to, including my friend John Willis, shout out to John, says that Quantum is quickly approaching us in the rear view mirror. Yeah.
Um, first of all, I want your thoughts on that, on, you know, timelines for Q Day, but secondly, if you wouldn't mind, Rebecca, your dad did a great job a little bit in Las Vegas when we talked to Black hat, bring quantum down to everyone's level out here. What do, when we talk about quantum computing, why the excitement? What exactly does it do?
What will it be game changing about? What won't it be game changing about? We've got 20 minutes rock and roll.
All right. We're gonna cover all of quantum physics and quantum computing in 20 minutes. So, no, I Jo it on.
Yeah, go ahead. This is one of my favorite things because it's, uh, it's such an important technology and the implications are so important, right? We know that quantum will do incredible things.
We also know at a certain point, it will break encryption that keeps my data safe, your data safe, the government's data safe. So it's really important to be talking about how it works so that it brings everybody into the conversation. And it doesn't have to be that complicated.
So we started working in quantum computing. I came from the AI world and got into quantum computing in 20 18, 20 19. And the idea was we, we started a venture studio to connect, uh, research that was coming out of academia with pathways to commercialization.
And looking back then, it was a little bit early to be building commercially viable applications on early quantum computers. Now, fast forward six, seven years, things really feel different. And if, uh, if anyone is of sort of the venture capital persuasion, for example, and you're thinking about investing in quantum, the next 10 years, there's gonna be the Google, the Microsoft, the Atari of quantum computers that's gonna be started, maybe not in a garage, but, uh, it's worth, it's worth paying attention to the space really closely.
Mm-hmm. Quantum computers, they are not just bigger, better, faster, stronger, regular computers. And that's where a lot of people kind of get, get caught up.
They're not gonna solve every problem, but there are certain problems that they're gonna solve a lot better than regular computers. And one of the most exciting things is we're still figuring out what those problems are, but we know a handful of them. And a lot of those problems can be boiled down to the problems where we wanna solve a really complicated problem.
For example, self-driving, car fleet route optimization. That's a harder problem than it looks like, because you need to know where every car is in relation to every other, and you need to know exactly what route each is taking in relation to the other. And as soon as you start getting multiple stops on each of these routes, it sort of multiplies and multiplies and multiplies the amount of combinations you can see.
So that's a ultimately impossible problem to solve on regular computers. But with quantum computers, if you come up with the right algorithm, that's the kind of thing they're really good at. The way that I always tell people to start building intuition for how a quantum computer thinks is, if you imagine that you're trying to solve a maze as a person, how do you think about doing that?
Do you enter into this maze and you hit your first t? You have to choose right or left, right? Okay, I go left, I hit another T, right or left, let's go right, and so on and so forth.
I iterate through that maze and ultimately find my way out. Quantum computer enters a maze. Quantum computer hits its first TT the quantum computer doesn't have to choose, Goes both, Goes both at the same time, and then again, hits the next T both at the same time, and so on and so forth.
And with the right algorithm, the right quantum algorithm, it can hold all of those paths through the maze in memory at once, and then ultimately chop off the ones that are not the most optimal path through the maze. So that when you're, when you open the box at the end, it gives you that most ultima that most optimal path through the maze. So that's, that's the power of quantum computing.
And that that intuition can help understand some of the problems that we can start to look at with a quantum computer that we can never look at with a regular computer. There's, uh, there's more ways to shuffle a deck of cards than there are atoms in the known universe, right? Really?
Yeah. Yeah. It's true.
Okay. And if you tried to, to compute all of these different combinations of just 52 cards, you'd never be able to do that on a regular computer. Yeah, no.
So all of these say same kind of problem goes for modeling things like interactions between molecules when you're doing drug discovery, uh, route optimization. And that's things that people hope to be able to use. Sufficiently powerful quantum Peters to solve is these problems that are just too complex, too many combinations of things to look at and find the optimal answer.
So obviously, one of those use cases is encryption, which we spoke about in earlier. Mm-hmm. Right.
Where you have, whether it's, was it 124 or 248 bid encryption? Mm-hmm. Right?
With traditional computers, you have to sort of brute for some, if you will, which I mean, the amount of horsepower needed is measured in decades, if not hundreds of years, with the most powerful computers where in quantum, much like the route algorithm, it fills the whole every conceivable route up, you know, simultaneously. Mm-hmm. And therefore renders that brute for it's no longer brute force.
It's just, it's almost like the borg assimilate force, right? Uh, and, and it does that. So Q day, what does Q day mean?
Q day is, is now what people are starting to call this day. When a cryptographically relevant quantum computer comes online, that is sufficiently powerful enough to break today's encryption, like you were saying. Yep.
The stuff that keeps us a safe as we share data across networks, Well, it gives us the, uh, the appearance of safety anyway. Right, right, right. Um, what's stopping us from achieving Q Day right now?
That's a great question. Q Day, a cryptographically relevant quantum computer is a quantum computer that has on the order of 4,000 air corrected qubits and qubits being on the, the, where we have bits for regular computers. Mm-hmm.
Quantum computers have qubits and they behave a little bit differently. They're not quite binary. So a quantum computer to break today's standard encryption, you need something on the order of 4,000 error corrected qubits.
Well, What's stopping us right now is two things. We don't have a quantum computer that is that powerful in terms of number of qubits, and we don't have a quantum computer where those qubits are sort of harnessed where they are error corrected and stable. So, like you were saying, there's, there's a number of really exciting quantum computing companies that are making breakthroughs and have now committed to these, these really aggressive timelines for when they'll have, uh, psych Quantum is a company that just raised a billion dollars million Yeah.
And, and they're building a quantum peter, and they've, for the first time come out with a timeline to say, I think 2029, they wanna have a million non-air corrected cubits. A million. A million.
A million. Yeah. And there's a few other companies that have come out and said something similar.
Right. And, and if we have a million non-air corrected qubits, we can start to do some really, really exciting stuff with a quantum computer, whether it's like quantum or IBM, or there's also billions of dollars going into quantum research across the globe. We know that China, for example, has spent over $15 billion on a government quantum computing research program where they're looking to build more and more powerful quantum computers.
DARPA has started a program where it puts funding into these different US companies mm-hmm. To build that commercially viable, relevant quantum computer by, uh, early 2030. So, So are we, you know, over the course of my life, I've seen cycles and cycles of innovation and discovery.
Are, are we in strictly the research, the r and d phase right now? Or do you think we're sort of coming to the end of that and starting to, you know, really think about commercialization here? I always tell people the same thing.
The moment that you hear, there's a quantum computing breakthrough on a problem that you recognize. You know, if you hear, you'll hear a lot in the news, quantum computers solved boon sampling or sort of these esoteric terms, millions of times faster than regular computer. But the thing to be listening for is, quantum computer solves drug discovery problem, or materials problem, or route optimization problem, or, or something that you recognize and is perhaps relevant to your life.
That's when you know something has really changed. And we're getting, they call that quantum advantage. Okay.
When we get that qu when we start getting that quantum advantage, that's the big inflection point. And we're close. We're getting, we're getting close to that.
Uh, so it's an exciting time. Absolutely. Now, there are other people who say, you know, what we're doing now with AI is phenomenal to, to people who don't understand how AI works, it's almost auto magical.
Mm-hmm. Right? Like, you know, fire the caveman or rain to people who, you know, do rain dances for rain.
But, you know, people say that, wait, you haven't seen anything. Once we combine AI with quantum, that's like craziness squared. Right.
Um, how does, so they're not mutually exclusive. Obviously there's some sort of connection here between what we could do on AI and what we could do with AI on a quantum computing platform. Talk to us about that.
Is it like peanut butter and chocolate, or what are we doing? It's, it's one of the most exciting and interesting areas of, of active research. And like you said, right?
The, the difference between regular computing and quantum computing, uh, is gonna be like the difference between a candle and a microwave, or, uh, going from alchemy to chemistry, it's gonna open our eyes to so much. Uh, the Richard Feynman mm-hmm. One of the, the, the fathers of modern physics, he said that if you wanna understand the nature of the universe, the nature of nature, essentially you need a computer that can model that directly rather than simulate.
And that's what a quantum computer do. So when you think about combining AI and quantum, there's an incredible amount of potential to gain the advantage of that, that power of quantum to solve and look at problems that we never will be able to in regular computing, and then build on automation. And not only, one thing that's interesting to point out too, is not only quantum and AI is an exciting field, but we have the advantage when it comes to advancements in quantum technology of using AI to accelerate quantum development.
And that's something we didn't have in the 1960s, seventies for regular computers. Right? No.
So it's, uh, you know, in part, it, it remains to really be seen how quantum and AI are gonna play off each other. But it's, it's absolutely inevitable that, that, uh, yeah. It's in some specific areas.
Again, materials discovery, drug discovery, uh, AI and quantum together are gonna be, it's, it's why I got into the field. 'cause I came from ai. Mm-hmm.
There are gonna be fundamental doors that get unlocked by leveraging quantum and ai. Wow. Exciting times, exciting times.
You know, we're here in Boca Raton in our offices, in our studio. I don't know if you know this, but the I-B-M-P-C was actually developed right here in Boca Raton. I, I, Boca used to be an IBM town, uh, if if on your way home Yeah.
If you go to ADA Road, which is right out the main road off of our Congress here, Congress Avenue, there's a place called Brick, which is now the Boca Raton Innovation Center. It's actually the old IBM campus. Wow.
And they, they still have a room there if you do a press release, uh, where Bill Gates signed the DOS licensing agreement, licensing dos to IBM, they'll let you use it for a press conference or whatever if you're a tenant there. Wow. So cool.
But literally, the IBM PC was designed here, and then they decided to make manufacturing other places, other countries, obviously. And eventually they moved out of here. Boca Raton went into a depression for about 10 years in the nineties and became more well known for retirement and financial, uh, advisors.
But anyway, um, funny thing back then, and I remember, 'cause I was old enough, a good IBM PC was five to $7,000 a Mac, a good Mac five to, or Apple before Mac even five to $7,000. It was a standard running thing that, yeah, you could buy a PC for $2,000, but basically if you wanted a good computer, it was $5,000. That was always kind of the bench line.
Now, $5,000 when I was 18 was tremendous amount of money when I was 40, it wasn't. Right. I have a few PCs.
Um, but of course, with the advent of cheaper electronics and globalism and everything else, computers, PCs got less expensive. I think a lot of people worry. Is Quantum going to be another, like only the Mag seven are in it and some nation states?
Or do you ever think us little people get to work on a quantum computer? I, I, I like to be a pragmatic optimist. Okay.
When it comes to technology. 'cause I think we have to be, to build a, to build a future that we wanna see. We gotta think and mm-hmm.
And, uh, and visualize that future. So one of the things that I love about Quantum is it started out on the cloud. So I can access, we could all access a quantum computer right now, one of IBM's, um, probably smaller chips, but we could, we could go on right now.
So could someone in Nairobi really? Or Seoul or, yeah. And I, that kind of democratizes it in a way that, that, like you're saying, it was prohibitively expensive for a lot of people to be able to, to learn how to program on an, on earlier computers.
So that's, I absolutely hope that that continues. Now, I have heard that some of these companies, as they develop more and more powerful chips, they have to think about, do I release this kind of power to the public or do I not? Mm-hmm.
And so that's, that's the kind of, with great power comes great responsibility sort of question. Should we leave that power in people's hands, or should that be governments making those decisions? That is a fantastic and fundamental question.
I, for one thing, I hope we get the option to choose We both, So Right. We, one thing I like to remind people about when it comes to Q Day that day, that that Quantum Peters will become cryptographically threatening, is not just that we have to think about getting ahead of it today and, and deploying protections because that data's being actively harvested and stockpiled for, for, for QA to unzip it with QA. When QA comes, the thing I like to remind people is that we probably, as the general public, will not know when that computer comes online, because if you have that powerful of a tool, you're not gonna release a press release about it.
Right. Right. Just like in World War ii, when Alan Turing and the team figured out how to break Enig enigma.
Right. They didn't advertise that to Yeah. To Germany.
Right. They, that was, that was something that they kept close to the vest and were able to save many, many lives because of that. So, uh, when that, that 4,000 air corrected cubic quantum Peter comes online, we probably won't.
No. So that's something that people have to keep in mind is that there, there are things that are going on behind the scenes. And while I think we, we should all kind of demand and push forward this democratization of how we access these really powerful computers and train people to use them.
And, uh, there's also, inevitably, it's a very, very powerful tool when it gets to scale. Absolutely. All right, we've got time for one last question.
I'm gonna put you on the spot. Pick a day for Q Day. Oh man.
I, I'll give you a day, but I'll, I'll also say that anyone who tells you definitively is, is a little in their mind, is out of their minds. But We'll put it out there just 'cause what the heck, it's, you might as well plant the flag in the ground. Totally.
Well, I'll tell you, Gartner, for example, says, good chance by 2029. Yeah. So be ready.
Um, it could be 2029. It could be beyond, it could be sooner. Uh, But like you said, we may not know, or in two quantum fashion we may know and not know.
Say No. Yeah, exactly. Exactly.
So yeah, we might start seeing this data, these data breaches that are kind of suspicious and, And that that'll give us a clue. Give us, well, look, God willing, I hope it's not the bad guys who get this first. It's gotta be the good guys.
We gotta, we gotta make sure That's one thing we do have to make sure. Yeah. Rebecca, I want to thank you for coming up here to our studio.
This was great. If you haven't seen part one of this interview, please go back and check that out. Again.
com. Check them out if you want to stay on top of this whole post quantum cryptography, uh, security dilemma and problem. They've got answers, but for now, this is Alan Shimmel for Text on tv.
Thanks very much. Hey everyone, it's Alan Shimmel and we are live. That's right.
Live, uh, it at Swamp Up. Swamp Up is back in Napa after I think two or three years it's been since they were in Napa Should End, I'm thinking it might have been since before COVID that we were in Napa last. But we're really thrilled to be here.
It's beautiful here. It's a beautiful resort. But more importantly, there is so much going on at Swamp Up, you know, like everything else in the tech world, it's kind of the year of AI more than the year.
It's the era of a, the dawning of the era of ai. Still, I like to tell people we're still at the beginning of the beginning, not even the end of the beginning on ai. Let me introduce you to my first two guests of our Techstrong TV coverage here at Swamp.
Up to my far left. He's the guy in the, in the, in the, uh, shift happens Frog shirt, Yuval. Let me make sure I get it right.
Excuse me. Yuval Fern back. Yuval, welcome back.
It's good to see you again. Thank you. Good to see you as well.
You know what, before we get to our next guest, Yuval give to share with the audience your title and role at jfr. Sure. So, hi everyone.
I am, uh, Yuval Fern, I'm VP and CTO of MOFs here in J Rog. Um, actually joined Jfr a year ago as part of an acquisition of a company called Quack. And nowadays, of course, part of jfr ml and the new product that we launched today that of course we'll talk about in a second.
Thank you, Yuval, to my immediate left not in the Frog shirt. Is is Adult Alek. You, You got that right?
You got that. Perfect. You got that on the money.
All righty. Ale is with, uh, Nvidia and Ale. Introduce yourself.
Well, thank you for having me. Yeah, it's great to be in Napa. I was joking around earlier telling folks that, uh, you know, I'm glad we're doing this 'cause now my family really believe that I'm here for work fruit.
So, got the proof right. I got the proof now. So, uh, my name's Al.
I'm a senior director of product, uh, at Nvidia. And my job is to, um, take the software that our, uh, awesome core tech team creates, um, uh, harden those, make them production grade for enterprises and help our ecosystem build, um, agents, right, that are fra frankly transformative in everything that we do. Something we were just talking about.
Absolutely. And, and that's a great segue. I I little something extra for giving us that segue.
We were at the keynotes this morning, right? You've all led off. Al came on.
You've all, you, you, uh, introduced a new product for jfr called the J Rog AI catalog. Explain to our audience a little bit, what, what is it? Yeah, so, um, as I shared, I joined jfr a year ago, and as part of that, I've seen and got a lot of responses from Jfr customers about the challenges they have with adopting ai, the challenges that they have with actually trusting AI and the amount of new models that are being launched daily, right?
Um, everyone's speaking about ai, but actually using that in production require more than just, you know, testing the new and shiny model. It requires the ability to trust that, the ability to trust where that model is coming from, um, who's the owner of that model, and even who is actually going to use that model. And as part of that, and as part of all that feedback that we received in the last year, we decided to launch the J 4K catalog.
And that's basically a solution that allow organizations, allow our customers to manage the entire lifecycle of AI usage. I'll call it, from discovering which models actually exist, um, to deciding who should have permissions to which models, and eventually then serve those models, uh, track the, uh, usage methods of the models and understand which application uses models and how. So the goal is eventually to allow organizations to understand where those models are being used by whom, and make sure that they trust those processes that are, you know, shifting in, in such a magnitude and such a, a, a pace of innovation that we haven't seen before.
Absolutely. We're gonna come back to that. 'cause I, I have some thoughts and questions, but not open.
Explain to me the Nvidia Yeah. I mean, connection, there's a reason for this awesome partnership, right? And so, uh, we're a full stack acceleration company.
What that means is, right, uh, we're not just about producing processors or, or systems. We actually build out AI factories, but we go all the, all the way up, right? For optimizing runtimes for not just models that Nvidia publishes, but also the ecosystem models as well.
We call that nim nim inference and microservices. And so, uh, what we do, you can think of an name as, as a, a model with its runtime package as a single microservice, we spend a lot of time tuning that runtime to make sure it runs it efficiently as performing as possible, uh, on the Nvidia stack. Um, but equally, right, we contribute a lot to the open source domain.
We're very, uh, we're huge participants in the open source community because going back to Eva's point of having that, that trust, having that transparency, it isn't just that we provide the Nemo tron open weights, which are fantastic by the way, and Excel really good at reasoning. But we, we also open source our, our training data sets. We open source our recipes so enterprise can then take those models further into them for their agenda, uh, capabilities.
And so being the ones that provide the secure runtime and the open source of the models and the weights and partnering with J Rog, what drives the services for having all that lineage was just an amazing partnership. Absolutely. I, I want to dive a little deeper on this, right?
So I was at Swamp Up last year in Austin where they announced the, uh, J Frog Nvidia partnership. Now over the course of the 12 months, how have, you know, what, have you seen how this partner, well, look, AI has been on a hockey stick trajectory for these 12 months, right? But how has that affected, what's the, the, the net that our audience could take about this partnership?
What does it mean to them? I mean, look, you know, you've all kind of set the scene, right? There's so much happening and it's happening so fast.
I joke around and tell people that at one point I think my kids thought I was a vet. 'cause I was talking about new animals every week from llamas to Mambas to, you know, you name it, right? But, but it's awesome innovation that's happening in the ecosystem, right?
So a couple things that are, that I think critical number one is all this innovation that happens. Yes, you wanna be experimenting a lot, et cetera, but when you have all this innovation that's happening, right? And you have all this open source, the potential for exploits growth significantly as well, right?
And that's something we talked about earlier when, you know, we were on stage. And so, uh, being, having that transparency, understanding essentially what's part of your run times where malicious code can be potentially like implemented is, is super critical. So you wanna be experimenting, but you also wanna be careful and prudent when you're experimenting.
And so that's why having a single source of truth right, for your system of records, for all your artifacts is critical. And that's why that relationship's been awesome. And, sorry, go ahead.
No, no, go ahead. And I think the second point is right, um, one of the first use cases we started using agent AI was, and actually defining the contextual, um, analysis. Doing the contextual analysis to understand whether vulnerability can be exploited or not, right?
And I think, uh, I, I really appreciate the partnership that we have with the JFAR platform because that's something they take very seriously as well. Just 'cause the CVE says, you know, it's got a high CVE score, doesn't mean it's exploitable. There's a lot that goes into be able to exploit that.
And so, you know, we see eye to eye in terms of how we go about really going deep and understanding the potential for exploits and protecting our, our, our customer base. Absolutely. And by the way, this, this partnership didn't start because, you know, us and Nvidia thought that we should work together.
It started because the J four customers approached us, told us that they need to trust the source of their models. And, you know, the only models for face, by the way, I think the tag face is an amazing hub for models, but it's not enough in many cases. And customers approached us and told us that they want to have a trusted source of models, and NVIDIA is one of those trusted sources.
So a year ago, we, we partnered to make sure that the J four customers can actually get the Nvidia need models directly from Artifactory and trust the origin of those models. Um, and from there, of course, we progressed with that partnership with the security solution. So the contextual analysis that we actually understand how those, uh, artifacts, how those models are vulnerable.
And now we can make sure that in the production environment there will be no vulnerability. So eventually it's part of the same goal of making sure that the J four customers, and of course the NVIDIA customers can actually trust the models, trust the region of the models, and trust that there are no security. And then that will arise because of those new artifacts that they not need to manage and of course have to manage to actually make their product progress over time.
Excellent. Ada, I wanna come back to you 'cause you said something right in the beginning that I want our audience to understand. And that is, so a lot of people hear Nvidia and they're thinking G-P-U-G-P-U-G-P-U, not that you make a bad GPU, don't get me wrong, but the real key to NVIDIA's position is the software, is the community, is the ecosystem around Cuda and, and, you know, uh, um, NIMS and, and so forth.
Talk to us about that a little bit and why you are, we're on live tv Paul, uh, cameraman. I'm gonna ask you to grab outta my bag, my AI catalog paper. We'll bring it up.
We're gonna talk more about it. But al talk about yeah, what the secret sauce at Nvidia? Uh, Well, we're a full stack acceleration company, right?
I mean, um, yes. We, we start at, at the silicon, but we go all the way up the stack, right? And so we have AI factories, we have our, our software portfolio that goes all the way up to the, um, you know, what what we call blueprints, right?
Reference workflows for how you'd go implement a specific use case for, for agents. And you get the full benefits of Nvidia when you take the full stack, right? 'cause we're able to optimize all the way down to stack.
But by no means you have to take the full stack, right? And we leave it up to our audience, our ecosystem, to meet us where they think is best. Some just wanna run on our infrastructure.
We love them. Some want to utilize right? Wanna go higher up in the stack and take advantage of the optimizations that we drive through software to enable that.
I think one key to NVIDIA's, um, you know, call it success or or or secret sauce, is just how, how ingrained we are with the ecosystem. We, we go to market through our ecosystem. Our partners such as J Fog are super critical to our success at the marketplace.
And so you're spot on. We're not just a chip company, we're a full stack company. Um, right.
You can take us, you know, you can go with us up all the way, you know, all throughout. Or you can just choose to meet us where you think is best for your, for your, for your domain. I love it.
Thank you. So Yuval talking about the jfr AI catalog, you know, I've written a lot recently about what I call shadow. I, uh, shadow ai, right?
And we've seen shadow, look, I've been in, I've been in the tech business probably longer than both of you. Okay. Um, I've seen Shadow, before I saw shadow open source, there was a time where enterprises official policy was no open source fill out.
It was, it was a danger, right? I've seen shadow wifi. I remember being at a US Army base and the, uh, army Information Assurance officer telling me we don't have a wifi security problem 'cause we don't allow wifi.
And as I'm walking with them, I see people unplugging laps and throwing them under their desk. As soon as he walks by, they plug them back in. And wifi, we saw it with the cloud developers whipping out their credit cards and opening instances.
It's no different, no different with, it's probably even easier with ai. Yeah. 'cause you have take your pick, right?
Whatever one you want to use. So we call this a prop, right? They gave this out at the, at the keynote today for your talk, your joint talk.
Talk to us about the different models and how we're gonna control shadow AI at the enterprise level. Yeah, yeah. So, so first of all, yes, it is a prop because, you know, this, this booklet have six models in it.
Um, I believe that the current number in phase of models is around 2 million. And you know, on top of that there are, um, external like model providers like OpenAI and others. So that's another couple hundreds of models.
So, you know, the numbers are way more than that. And of course, no book can actually, you know, manage and track the amount of models that are being launched. Um, and models are now, they used for, you know, so many different tasks.
So actually Shadow, um, Aline in his talk talk about different type of models like reasoning models and, and, you know, voice models and models are being used for different tasks and not just for language models. Like, there are many models around computer vision and many models that are still used for structured data. And that's still a valid use case and still something that customers, you know, use as part of their use cases.
Eventually, the goal of the AI catalog is for organization to have the visibility about those models, about where those models are being used and how, and on top of that, as part of our launch, we actually launched a new product that will be available in a couple of months, um, called Shadow ai. Now, the, the issue with shadow ai, the problem with shadow AI is that in many cases, you don't even know that the model is actually adding one of your packages. It's possible that you downloaded the third party docker image.
Uh, that image that you use actually uses ai. Um, and it's not something that you can just, you know, not know about. Because nowadays, even the regulators in many places, for example, in the EU, actually force you to show that part of your product uses ai.
It's something that you need to have visibility on. It's something that you need to be transparent on. So the goal of the shadow AI product that of course, is connected to the J four AI catalog, is to just not just allow you with AI catalog to choose which models should be used, but also to see, to have the visibility about where model is being used, but you are not really aware of.
And if those models are being used, for example, malicious or those models that are being used are actually not approved in your organization, you'll be able to actually block those from being used or, you know, go through the pro through the process and approve those specific models. Um, so the goal is about visibility and the ability to discover where AI is actually being used in your organization. You know, again, my experience is you don't wanna stop people from using ai.
Yeah. And quite frankly, stopping people from using AI is like trying to grab sand in your hand. The, the tighter you make it, the more it slips out between your fingers.
What you wanna do is just, okay, you're using ai, let's let us document it. Let's make sure it's safe. Let's make sure it's secure.
Right. And that, because otherwise you're fighting a losing battle. Nvidia has to see that as well.
Al No, I, I'm, I mean, right. We're not, we're not, we're not definitely fighting ai. Right.
To your point, right? It's, it's, I mean, there's plenty of productivity gains new markets that it opens up, as I said, right? Uh, the, the only reason we're able to publish and maintain so many of these NIMS is because we're using Agentic ai.
Right? Absolutely. But to your point, you do have to be cautious, especially with all this open source that's happening, all this innovation, et cetera.
You wanna create an environment that allows your developers to experiment. That is for sure, right? You wanna, you wanna continue creating that, that experimentation, right?
Uh, that you wanna enable as well. But then when you're going into, into production, yes, you want to have the safeguards that are in place. Um, you want to be able to have the observability, the tooling that is in place, right?
I, I go back to, you know, the, the nemo tron models that we provide, right? Just being open source in terms of not just the model weights, but the data sets of what it was actually trained on, the recipes of how we got there. Just to give the enterprises and the ecosystem that level of comfort, right.
To know exactly what's going on, right. Such that you always have that lineage that's super critical. Yeah.
I don't think you can, you know, on the contrary, right? Like, we're just on the, I think you called the era right? Beginning.
The beginning of the beginning, Right? And just imagine when physical AI comes into, comes into this world, right? Today we're talking about digital workforces, but very soon, right?
We're, we have these world foundation models where you're simulating and generating data to train these robots and these autonomous vehicles. Man, it's, it's about to get exciting. It, it already is.
It already is. Um, but, you know, does that bring, both of you mentioned this, but you kind of ate at the edges. You didn't eat the middle, which is something else that they spoke about in the keynote saying, I'm trying to remember the exact name.
Was it AI gov or ai gov ops? Something? It Was, uh, dev gov Ops.
Dev gov. Ops, excuse me. Dev gov.
'cause there's always something in the middle between dev and ops, whether it's saco, whatever, dev gov ops. I learned a couple new ones today. Yeah.
Sorry. Yeah. Yeah.
So, but that's really what we're talking about here. We want, we need governance. Not, not, we're not here deporting AI models, right?
We're here talking about you wanna use ai, use the ai, but let's have some governance around it. Let's have some guardrail, some knowledge, right? And that's, to me, that's the enlightened way of doing this, right?
We're not discouraging use ai. I know. So textron's, part of Futur, and we, we have a policy now where we're encouraging all of our people, the cameramen, the editors, the writers, the marketing, the decoders, use AI to your hearts content experiment.
We expect you to make some mistakes. That's okay. Make the mis I'd rather you make mistakes.
Trying something new than digging in your heels and saying, I, I don't want to use ai. 'cause if you don't use, I tell young people this, who ask me all the time, you're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than you.
That's right. Look, this is something we think about as well, right? And kind of now you're, you're going above and beyond just serving a given model or talking about managing the lifecycle of, of agents, if I may do that, right?
Yep. And, and that pipeline, right? We use, we, we have something called the NEMO platform for managing lifecycles of ages.
Mm-hmm. And that starts from data curation, uh, creating additional data that is, um, doesn't have the potential PII, that you know, you're not just collecting people's prompts, right? To then, uh, taking a model and adapting it for a specific domain.
Then once you have that right, and, and putting it as part of a, of, of an agent, make sure you have the guardrails that are in place, right? Such that it doesn't go, Ari, make sure you have the traceabilities. You can backtrack across the way.
We have, uh, something called the NEMO Agent toolkit that allows us to drive all that traceability, all that observability, all that pri profiling around. It's almost like, it's almost like onboarding a new employee. You have to teach them about your cultures and your norms at the company.
You have to tell them the dos and don't dos, kind of like, you know, I'm doing in this interview right there. Yeah. Right.
And so, so it's exactly like onboarding a new employee and putting all those kind of, you know, managing it throughout this life cycle. And to your point, it, it first, organizationally, you have to, I love what you just said, right? Everybody's gotta be experimenting, but then making sure that your enterprise is leveraging the likes of the NEMO microservices to Right.
To manage that entire lifecycle. I love it. Yuval, I'm gonna give you the last word and then we're gonna wrap up.
No. So actually going back to this, uh, dev gov ops term, and, and again, we talked about it today, and, and this is in a way, the theme of this swamp up because, you know, automation is already around. We're seeing that as part of the development lifecycle.
We're seeing it now as part of the DevSecOps lifecycle and also around, you know, ML and AI adoption. The challenge is not, or is becoming not how to automate those processes and how to actually, um, um, use new technology. It's how to make that in a governed way, right?
How to protect the way that we use the new technology and make sure that while we are researching new technologies, while we are actually adopting ourself to this new future, we do have the visibility and the governance on top of that to make sure that we're not doing anything wrong. And that eventually our customers of, of our product can actually get benefit from those new technologies that we actually use in our products. I love it.
Yuval del, thank you. A del No, You got it. You got it.
Alan, Thank you so much for coming on here, kicking off our coverage of Swamp Up 2025. We've got a lot more coming at you. Unfortunately, not all of it's live, but we're recording it all.
And over the next days and weeks, you'll be able to see everyone we spoke to here. I encourage you. com or Techstrong It Techstrong, AI digital, CXO, cloud native, now, even Security Boulevard.
'cause we'll probably do something about dev gov ops on there to, for our full coverage at Swamp Up. But we're gonna take a break here. Stay tuned.
We'll be back with more from Swamp Up This Tech Drunk tv. Hey everyone, welcome back here to our day two coverage of, uh, swamp Up J Frog's, uh, conference out here in beautiful Napa Valley this year. We're happy to be back.
Uh, we're continuing with some of the people we've been meeting. I wanna introduce you to a frog right now. His name is Yossi Shaul.
Yossi is the SVP of DevOps, right? Which is a great job when you're working for a DevOps company, right? So first of all, Yoi, welcome to Techstrong tv.
I, you know, in all the years that I've been interviewing frogs, I don't think I've had the chance to sit down and talk with you before. So it's great to have you on. Um, if you don't mind, share with the audience a little bit about kinda your journey, how you got to be here.
Okay, thank you. So I'm Yai and I'm in this business for, um, I would say for most of my career. I started with, uh, J for about 16 years ago.
16, right from the be beginning long time. Yeah. Yeah.
Uh, we were working, uh, at the beginning of Artifactory, creating the, this new domain before DevOps was a term even. Mm-hmm. Uh, so I've been working on Artifactory since the beginning.
I managed the, the team and the, and the product for quite some time. Uh, then I shifted a little bit to do some more, um, architectural, uh, leadership inside jfo. Okay.
And in the last, uh, three years, I'm, uh, back to leading the entire DevOps organization in, in jfo, uh, both product and engineering. Product And engineering. Yeah.
So that's, uh, that's really challenging. Really interesting. Yes, It is.
And very, very interesting time. So yeah. Glad to be here with you.
You know, it's funny you say that. It's, it is interesting times. Look, I, you know, I've, I'm in tech 30 years, 30 something years.
Mostly Stride was in infrastructure then security. We didn't call it cyber, then we called it info side. And then when, when DevOps first around 2012 maybe mm-hmm.
I, I said, wow, what a great thing for security, right? DevOps is right. Is going to be.
And that's when I started really getting involved. com in, uh, 2013. And you know, I will sit here as you sit here, the DevOps we were talking about and doing and, and working on.
Then today it's a different animal a little bit, right? Today it's, it's not radical. We don't have to explain what DevOps is.
Yeah. They don't have to fight on whether it's real or not. But on the other token, you know, people become too familiar with it.
They take it for granted. Mm-hmm. Right.
Ah, yeah. It's DevOps, right? It's just DevOps.
What, I mean, I see this as a challenge. Okay. com, what do you see from where you sit?
Yossi is, are people like, just shrug their shoulders, like DevOps is built into the table here and it's, or do they, you know, they continue to explore. They continue to evolve. Okay, great question.
So I am, as I said, I'm long time in this and I remember myself, uh, explaining absolutely. I refactor is a thing, Uhhuh Okay. And arguing with people why they should not, uh, store their binaries in subversion, for instance.
Mm-hmm. So we've, we've been a long way, uh, Stumbled that Way. And, um, and while I think that many organization, um, discovered and now maybe even think that they know what DevOps is, the world keeps shifting and keeps changing and it never ends.
Okay. The, uh, we are the first revolution, then another one with Docker, then with Kubernetes, and now we are what we are doing with ai. It's keep shifting, keep changing.
Mm-hmm. And also the security is a big part of it. Yes.
And while I think we also discussed it in one of the keynotes, that it's not a, so it's not a solved, um, issue. Okay. No.
Not DevOps and definitely not, not DevOps. And definitely not with a new regulation, new, uh, things that AI brings with it. So I think that we, we've come a long way, as you said, but, uh, I, I wouldn't say that, um, we nail it.
Okay. There's still lots of things to, to discover to, well, The thing is, and I try to explain this to someone the other day, I was talking to a younger person who wanted to be in tech. Mm-hmm.
And, you know, they were making it like, you know, like, uh, like tech is done. Not, not that it's over, but that there's nothing new. You know?
And what I tried to explain to them is no, we, it reinvents itself. Uh, it's constantly changing. It's constantly evolving.
Yes. AI is what we're all crazy with right now. Right.
It's, it's kind of the biggest revolution in my, I think almost as big as the internet itself maybe. Right? I agree.
Um, but every little piece of it, whether it's DevOps or or, or Agile or cloud native as you you mentioned mm-hmm. It's all still evolving. Right.
And, and we learned this now. You did a keynote yesterday. True.
Here at Swamp Up. You know, most of the people watching this were not here. Obviously.
That's why they're watching. Uh, tell them what you spoke about. Alright.
So yesterday we introduced a new product, a new solution, uh, in the Jfor platform. It's called UP Trusts. Yes.
And I think this is another big step of the evolution that actually shows that DevOps is not yet done. Right. Um, we are, uh, offering now a solution that allows, uh, development teams to manage their applications inside the platform with a clear lifecycle and policies that controls it.
So as you all know, we all manage in one way or another, a lifecycle for software development lifecycle, it's called like that. Yeah. Uh, but we used to code it and still it is coded and scattered in many, many places inside the CI where there's no, um, one location that you can control it and visualize it.
Um, and this is what we are offering now. So the Apto solution is, uh, built upon three different pillars. One of them is the concept of an application.
So we are releasing applications. All of us application can be a library, it can be a full blown application. Um, so that's one thing.
Now it has a representation inside the GO platform that you can, uh, you can fully control. The second, the second pillar is evidence. Evidence is basically assigned metadata or an attestation that you can attach to a binary, to an artifact.
Um, now this can be, uh, internal, uh, evidence that the jfo platform generates and it can be, uh, things that we are partnered with GitHub, like attestations from GitHub that are attached. And it can be any other, uh, evidence. I can talk about it a bit more later.
So that's the second pillar. And the last pillar is the actual lifecycle that you can predefine. That's my lifecycle.
It can be as simple as dev, qa, staging, production, and it can be much complex than than that. And you can customize it per each team. Now, besides, um, having a clear visual lifecycle, you can put gates, what can get in and out of this gates based on the evidence that I just mentioned.
And this, I think it's a big, big change that we are bringing, uh, uh, to the table. Absolutely. Yeah.
It's a huge change. It, it's a huge change. And, you know, it's funny, is it, it's co it's almost common sense.
It makes sense when you explain it. We sit here and say to ourselves, why did it take this long? That's true.
Like, you know what I mean? We, we kind of knew this was what to do. So you've put good words around the titles right.
To the, to the process. But, but this is why when we talk about why things don't are, it's never done. It's just like we're constantly things that we were apparent but not apparent.
Do you know what I'm saying? I agree. Yeah.
It was there, but we never kind of wrapped around. Definitely takes time. And even for us, it's the second iteration that, uh, we, we tried to nail it and we did a lot of improvement.
And that's the second iteration. But that's DevOps. Yeah.
Iterate, reiterate, learn feedback, loop, iterate. Right. Exactly.
And, and that, that's what it's about. I wanna talk AI with you a little bit though. Okay.
So, as I said, I think this could be as big or bigger even than what the internet was mm-hmm. When it first came out. Um, I mean, it's had a profound, if you were on the, you know, I reported yesterday on from the keynotes and everything, it was a lot of ai.
Right. I think Shlomi said, if you're not using AI now, you might want to step out. Mm-hmm.
Right? Correct. How is, how are you leading the DevOps team mm-hmm.
Sort of eating your own dog food? How are you using AI to make Jfr better? Okay.
Great question. So definitely, um, J OOG was always, um, a company where we had a lot of innovation and a lot of, um, adoption of new technology. So we are doing it for quite some time.
Um, like many other companies, we are doing it to increase our productivity and it's internal, and we are doing a lot of it. And it's very, very interesting. Um, there are also, we are also serving this audience, uh, whether it's the data scientist or the new mops, uh, audience.
So we also are providers of solution, uh, to this area. Now, the third pillar is how do we actually integrate AI inside our products? So some of it you heard about, um, when a staff, uh, leader from, uh, security Yes.
Um, mentioned how, how we can provide a mediation based of data from our, uh, catalog. That's, that's one, one offering. The other one was the AI catalog that was also announced yesterday.
Spoke, spoke about it. And this is amazing. And, and even asked, we are not huge company.
It's very, and we want, as I mentioned, we want to adopt new technology. We want to adopt ai, but we want to do it in responsible manner, and we need to help our legal and compliance team to help us. Sure.
And AI catalog is one of those solutions that, that can help us promote it internally. So you have one location where you can see all of the models, all of the services, external a PS that you, you want to use. And this is where you can approve it and you make sure it's secured and you can know who is using it.
And so I'm very excited, uh, about it, both as offering solution. I was too, but also using it. I, I think this will wind up being one of the big compliance tools because Right.
You know what's this is like, remember when cloud first came out, every developer had whipped out his credit card and, and spinning up instances. Mm-hmm. They weren't shutting him down, and then they submit the expense.
Right. And all of a sudden someone would add up and say, oh my God, we got how much cloud instances running. I think at some point, what, what's going on now is everybody's experimenting.
Right. It doesn't seem like you pay $20 a month here, $20 a month there comes with my Google over here. Mm-hmm.
You know, you know, we don't recognize the full scope of, of how much AI we're actually using at the, at the company wide. Even a smaller, we're smaller than you. Right?
Yeah. But I see every single one of these people have their own $20 a month accounts. And that's just the foundational models.
Then they got video editing, ai, uhhuh, graphics, ai, and marketing ai. You know, sooner or later something's gotta blow up. Right.
Hopefully we'll be there to control. Well, Unless we do something like this Exactly. Right.
That can controls. So we know at least what we're doing. But here's the other side of that.
I know as, as you know, the manager of my team as the CEO of Textron Uhhuh, I Don't wanna stifle experimentation. I don't want to crimp their style. Right?
Right. I want them to use AI figure, show, figure out new ways of doing things, how to leverage this to be better. Mm-hmm.
So I gotta balance, right? I don't want to be like the, oh, you can't use that. 'cause it's not in the catalog.
Mm-hmm. I wanna say use what you want. Just put it in the catalog.
Okay. Got it. Right.
Make sure we know about it. So when something happens, we, we have something to point to. Mm-hmm.
Is what do you see? You have a bigger team than me. What do you see with that?
Let, let me give you an example, which is, um, the reality. So in my keynote yesterday, uh, I mentioned that we have, uh, controls gates to make sure that you, you path through what we think I as a development manager wanted my team to go through mm-hmm. Testing, coverage, quality, et cetera.
Uh, so for this demo, I asked the team, Hey, I'm going to use Cursor and I'm not going to click a button to, to release it. I'm going to do it like you are doing it. I'm going to tell it, Hey, release it to production.
Um, and they got panicked. Really? Yeah.
Why? 'cause the, listen, you are going to do a live demo and this agent is not predictable. We are telling you sometimes it works, sometimes, sometimes it doesn't Work.
That's AI today. So my answer was, okay, but that's exactly what we are building. We are building gates that if it doesn't work, we stop it with Exactly.
We stop it and then we tell it how to do it the right way. Uh, so it's actually was exactly what we needed for the demo. And it's actually what happened.
It didn't work. Yeah. We tell it didn't work like I expected, expected it not to work.
Okay. Um, we told it to release something to production and this is how we want to work. Right.
Future. Yeah. Release something to production.
And guess what? It actually tried to take, uh, from the development, the release from the development stage, and put it right into production, no testing, no coverage, no security scanning, vo, and this is what it tried to do and it failed. And it's exactly what I wanted to demonstrate.
So it Was so it actually worked. Yeah. The failure was a good thing.
Yeah. So that's one example. And then I told it, Hey, make sure you run the test.
It, it figured it out. And I guess that if we train it more, it'll know how to do it. This is how our team will work.
Uh, but that's one example. Or of how those controls and the things that we are bringing with the new solution are making us making it easier for our customers And taking some of the risk out. Yeah.
That really, because that's what it, you know, it's all about the risk. Um, so I gotta ask you the hard question. You're probably hearing it from your team.
I know I hear it from my team. Mm-hmm. Are their jobs safe?
Is this gonna replace them? Should they start looking for a new career? What do you think?
Uh, so no one knows the future. Okay. And I think the, the, there are going to be, and there already happening a lot of changes in the way that we work.
Uh, and some jobs or some roles will either disappear or change completely. Uh, I think that, uh, we are still not there. Okay.
I think that, uh, and, and again, we are adopting it a lot and it helps with productivity. Yeah. Mainly, uh, it helps also taking the mundane parts of the walk, uh, to someone who doesn't care.
Uh, but I don't see it yet replacing, uh, junior developers. I don't see it increasing, uh, uh, 10 times the productivity of the, it's still not there. Yeah.
Um, and I still don't see it happening. However, look at how it looks like two years ago. So who knows?
The advancements are really, really fast, but it's still not there. It's, it's a, now it's a valuable tool, but it's still not replacing, uh, definitely not experienced developers. But I Think it'll always be a tool.
Right. And we, and we're humans. That's what separates us.
Yeah. We're tool users by definition. Right.
Right. That's part of being human. I, I, I think the, like, in my mind, it's going to get better.
'cause you see it gets better week to week. It gets better. Definitely.
Right. I mean, I use it with writing and it's, it's a, it's really getting better every day. However, I think at the end of the day, it's always will be a tool.
Mm-hmm. And it won't replace the spark of creativity that makes a human. Do you know what I mean?
I agree. You'll come up with an idea and it'll help you bring that idea to reality. Mm-hmm.
I don't know if it'll ever come up with the idea itself. Do do you follow that spark? I, I follow.
Yeah. We'll See. And, and I, you know, I, I wanna believe that anyway.
We'll see. That's exactly. We'll see.
Um, I wanna emphasize something we, I asked a few people yesterday, we spoke about, which is all of the stuff you showed yesterday, it's available now. This isn't pie in the sky coming next year. It'll be continually improved with feedback and everything else, but all of the things that we've been talking about here for two days now, people could go on Jfr right now and go play with it, see it, use it, test it, whatever they want.
Yeah. So, so the concept in, uh, swamp up is that, uh, we arrive here, we are ready. Right.
Okay. We're not showing you anything that's pie in this. Exactly.
It's there. Or it's coming in in several weeks. That's it.
Right. So APTA is there. AI catalog is there.
We also spoke about, uh, solution for ID extensions. It's there. Mm-hmm.
Uh, identical remediation is there. Yeah. Um, I also demonstrated, uh, yesterday on stage we have a new partnership with ServiceNow.
Yes. I saw, uh, This is where we, we are connecting the two words of, uh, it sm Yeah. ITSM management processes things, amazing things that are done on service now with the evidence and lifecycle management that the DevOps guys are doing.
So this is something that we started working, uh, few months ago after the feedback we got in the LEAP event. Uh, and this one is coming. This one is in development, or we wanted to announce it to put it on the table because our customers are really excited, really ask for it.
And we are working on it. This is coming, uh, later this year, probably at the beginning of the next year. Other than that, all there, the things that we announced are, are there?
Yeah. Well, Yossi 16 years. 16 years ago, do you think you'd be sitting here at something like this?
You never know. You never know, man. You Never Know.
Hey, congratulations. Thank, thank you. You've done a great job.
It's really fun. Yossi Shaul. Uh, SVP DevOps here at, uh, JFR.
We're gonna continue our day two coverage today. We've got more coming. So standby here on Tech Drunk tv.