Techstrong TV September 26, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, there. We're in a New York state of mind. You're watching Textron Gang.
Happy Friday, and another Busy News Week, especially New York where we have UN Week, climate Week and the Ryder Cup this weekend. I'm John Schwartz, your Silicon Valley correspondent, but I'm in the big Apple this week visiting my daughter in Brooklyn and covering some news from UN week and the Ryder Cup. Alan and Mike have the day off, though I suspect Mike is puttering around Long Island at the Ryder Cup.
Joining us is always a lovely panel of our guests and want to introduce them in no particular order. There's the great Stephen Foskett, Gina Rosenthal, and Ira Winkler, our cybersecurity Ian. Yes.
Um, so we're gonna start off with something that I know I sense a little skepticism from. Um, our, our panel, and I love it. Um, it revolves around this AI diplomacy, this, there's something called the AI Safety Connect, which was convened among a hundred high level participants during the, uh, UN General Assembly to address what organizers describe as an urgent need for global AI governance frameworks.
Um, their thesis is that the quarterly pace of AI breakthroughs has created systems that are more powerful, ag agentic, opaque and difficult to control. And this has heightened concerns about unintended consequences and deliberate misuse of AI technologies. They, in a sense, are so alarmed that they think that with AI systems advancing at unprecedented speed, we need the same kind of international cooperation that governs nuclear security or climate change.
Now, I know Gina and I, I'm pretty sure Ira and Steven, you all have opinions about this, and I'm just gonna open it to the floor. So I will start and let me talk about things and I'll take a step back, talk about general. What happens is you have an issue and then you have a company that organizes events and put things on and says, oh, let's convene a bunch of leaders in the field and we'll go ahead and try to be the leader in this and address a problem proactively.
And then what they do is they bring in a whole bunch of people who just want to add AI to their resume in this case and start to say, we are now AI governance experts because why? It's a soft topic and nobody knows a different thing than the fact we are experts, except of course, for the few experts, we're not gonna involve. We are gonna invite some experts who we like and who are friendly, and who will go ahead and give minimal credibility to our people, but not talk badly about us.
In the meantime, highlighting the fact that these people can't tell the difference, I will politely say the difference between generative AI and agentic ai, just for example, or frankly might refer to AI as a one in many cases. So these organizations start fluff to make money off of something like they'll have fundraisers who now support their efforts and these organizations who support them just make money off of these fundraising efforts saying that you're now a sponsor for this group of world leaders who now will go around adding AI governance to their speaking topics when they charge 20 to $50,000 for a keynote talk. I'll leave it there.
So, Gina, you did a little res you did, you did a little research into some of the individuals behind this. I thought that was interesting. Maybe you could share that with us.
Well, Yeah, of course. I mean, the whole idea, if we're gonna do ai, the first thing you look at is the data, and can you trust the data? Where did the data come from?
We don't even know most of that stuff except for the wide world internet. So of course, I looked at the board that this organization has nobody of color that obviously of cover of color. I'll say that, which is, and nobody that you would know.
And I thought it was very interesting. I just checked on my phone. Again, there's no real readout of who these leaders were that came to this conference and this convening of world leader.
Who were they? And did they include the people that we see on both sides? So we, they include the doers who are actually, and have been CR involved with HPC and machine learning and deep learning, and now we call all that ai.
So, and the people that have been raising the flag about here's what's gonna happen if we don't, um, think about the unintended consequences. So you have this group of leaders that are not doers. They are exactly how IRA said they are talkers, and they have their own companies, and they've been doing AI for a couple of years.
And so they are now bringing together the experts. Who are the experts Are we talking about? You know, one of the things that I think is really important we stopped talking about is the global south.
So Gina, the interesting thing to me was that in fact, there are some doers involved in this. Um, the, the initiative, the, uh, uh, uh, AI safety, uh, connect is backed by what's called the Future of Life Institute, which sounds like something from the sixties where you get a sit around and, and, and meditate. But instead, it's actually a, um, reaction to the development of ai.
Back in the previous decade, the Future of Life Institute was organized by, uh, an MIT professor and so on. Uh, the co-founder of Skype, uh, the one of the researchers from DeepMind, a lot of these people are actually really interesting experts. Um, I should point out that another one of the founders of the Future of Life Institute was somebody named Elon Musk, who I, I, I'm not sure if you're familiar with that guy.
Um, previously this institute was well known for authoring, uh, letters and reports, uh, warning of the dangers of AI and the dangers of artificial gen, general intelligence. In fact, uh, the FLI actually proposed a halt on, uh, development of AI in an open letter that was co-signed by Elon Musk and Steve Wozniak and other folks and all of the, and, and so those are some of the people that are, that are behind this. Now, another aspect here, the one of the founders of this AI Safety Connect is a guy named Cyrus Hoes, which he, he's not really well known, but he's the co-founder of Stability AI that dev generated, that created stable diffusion, that AI image generator a few years ago that everybody was going nuts about.
Um, so we do have some interesting, uh, people in here. My question when reading things like this, whether it's the Future of Life Institute or the AI warnings about artificial general intelligence or this safety initiative, is, um, how can you be, I don't know, Elon Musk and co you know, co-sign a letter warning of the dangers of developing artificial intelligence and then walk away and go generate giant AI data centers? I mean, how do you reconcile that if you are the guy who created stable diffusion or you know, the guy who created DeepMind and you're warning about artificial intelligence?
Yeah, you reconcile, sorry. You reconcile that with the fact that these people are just creating fluff. You know, you can't say, we've gotta put a moratorium on ai.
AI is just math. These are mathematical formulas. You can't tell people, don't implement math in computers because that's all computers.
And these are just different formulas. The question is what you're doing with it and how are you applying the, where are you drawing input from might be a concern, and what are you doing with the output? Those are the issues that may be AI provides a more robust concern that other things, but generally, I mean, when you, these people come up with love for all this thing, yes, it's like these things sound good.
And I don't think these people who put like a little bit of money or their name because they convinced 'em, it sounds prestigious to join. Elon Musk probably had zero involvement with this thing. I don't know about that.
So, so it Sorry, I'm sorry. You could go ahead. Uh, I'm sorry, I cut up to cut on you, but I I remember that I take it back.
Okay. These people are so-called doers, but I remember that paper and, and what that paper's all about, even the future of life, if you think about what does that stand for and what does it mean, and Elon Musk has talked about this a lot. Um, their, their main purpose people that are some of these types of people is to get to a GI and to get to a SI, they want to be to the point where we're past all the machine learning and the machines can do it themselves, and they're a smart or smarter, actually is the, the criteria for that than humans are.
And part of the concern, and part of the commentary around that paper when it came out was, okay, they want us to stop, but they're the ones that are gonna run these consortiums, run these groups, and influence the politics. So they're the only ones that will be in the business of delivering a GI and a SI that that race to get that first is what this is all about. And that's even more dangerous than what I thought it was because here you do have all the global self left out.
All of, I don't see anybody from Africa involved you and people that have material right now just with the machine learning part of this, um, issues and safety issues around how we're dealing with ai, not even part of the safety discussion. So the safety discussion may not be what we think it should be, but it's a safety to maybe guardrail and make sure we get to a GI as fast as possible. I believe that is the goal.
And I, I remember when that letter came out, Regina, I think you and I were speculating that maybe one of the reasons that Elon signed on is because his company was behind and they wanted to put a roadblock in front of some of their competitors in hopes that they could catch up. 0 that talks about life under artificial intelligence. Um, he, along with the Future of Life Institute, is also the scientific director for the Foundational Questions Institute, which again, oh, who names these things anyway, um, which is a big proponent of the effective altruism movement, if you guys are familiar with all this stuff.
So essentially what we have is the Silicon Valley ai, uh, I don't know, mentat, uh, pushing their Silicon Valley AI mindset to the United Nations in the guise of AI safety, when really what they're pushing is this sort of weird techno utopian future vision that I think a lot of people are pretty worried about. Yep. I, Yeah, there's a comment.
Can I just ask one quick, quick question? Yeah. Um, so I, I am so skeptical of these types of movements or initiatives, and I just want before I, we, we can ask just a quick answer, but does this amount to anything, um, especially with no real regulation in the US to speak of involving ai or is this just a, a publicity stuff?
Let me, because your question is what I was gonna say, because there are two things that these type of organizations do. Number one, they just create a bunch of fluff to get sponsorship to keep the people who run the organization in little to organize fancy meeting traveling around the world. Yep.
The other thing sometimes they do is they get organizations who wanna go ahead and push governments or regulation or something, and then they like these type of organ, like lobbying org, lo lobbyist type of thing. Then try to tie themselves to something, give them money and take the legitimacy of a hundred world leaders and push their own agenda forward. So this could be one of the two, frankly, at this point, given the whole influence of the UN at this time, it's more fluff than anything else.
If they wanted to really do something useful and drive things, they would just buy congressmen and, uh, you know, and like donate to like a, a presidential library or something. Instead the un that's probably one of the least effective places to try to get movement here. But I think the thing is, and the danger of this is that when they're at the un, when there's a World Congress convened, they also have the ability not just to attend this Congress and they attend this conference and figure out what to do.
They have the ability to meet the lawmakers and influence them and persuade them to fund what they're doing. And then that funding turns into the legislation and the legislation turns into harmful things that are only gonna be good at protecting this idea that a GI are bust. That that's what society needs or society, the, the effect of altruism movement, their main thing is society must live into the future for eons.
No, no matter mankind, right? No matter who gets hurt in the process. So, no, no.
That's why there's no looking right now at, okay, how are black skinned people being impacted by, um, facial recognition and how dangerous it is? And that's not looked at and seen. It's like, no, we've got to make sure that we have the machines that can do everything for us and we'll figure it out.
Then even you had, um, the open AI CEO saying, I don't know how we're gonna make money off of this. I'm gonna wait till we get a GI and then I'm gonna ask it and it's gonna tell me 42. So, you know, it's, this is this whole mindset and they know that they have to control the government.
This is a way to meet the government to understand even if they don't meet with the right people, they can meet with their, um, their representatives and understand the process and get into that process and that workflow and, and change the workflow so it suits them and it, and it, and this will go through faster. I wanted to say just real quick too, that the one outcome of this was, uh, I lost it. A global risk and AI safety preparedness.
Um, so I'm gonna look into that a little bit more. Maybe this will be a nice blog post or LinkedIn post. But, um, the other thing is, is if they're able to get the, the, the idea of risk and what that means, change to suit them before all the normal, you know, people that aren't really caring about this right now, um, people get to know about ai, they will define it, and that's the road that it will go down.
So it is, it's just like ai, it's bad information going in to steer one way and, and we need to watch it really carefully. Yeah, I don't wanna sound like that crazy guy in the meme with like the strings and the corkboard and the, and and, you know, all that kind of stuff. Um, but as Gina's pointing out, when you're evaluating these things, you basically have to try to figure out what's the mindset and the motivation of the people behind it.
And I, I, I, I completely agree with you Gina. The goal of this is to influence the law and the direction that world leaders are gonna have a, across the, across the entire world. Because, you know, you can make the United States pass a law that does this or that, you know, with some influence like Iris suggested, uh, you know, some influence, uh, maybe you can make the, make their, but what they're trying to do is, is basically influence the global conversation.
And that's why I think that it is valid to look at who's behind this, who are these people, what are their motivations? Because that will tell us more about what they're trying to do than sort of the fluff that's on their website about AI safety. Because to, to be honest, if you look at the website for this, I think most of us could get on board with the message that they have to say.
The challenge is, is that really what they're trying to do? Maybe it is, maybe these people have turned over a new stone or maybe it's a more nefarious plot. Well, on that nefarious ending, I think we should move on.
Uh, we'll, we'll be back in a moment. We're gonna talk about tele crime and, uh, I guess I, I can't wait to hear what IRA has to say about this, especially this is tied around the general assembly. So, and I expect Steven to give us our, his best Allen impersonation and that's coming up next.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Techron Group. So, as you might have heard, the UN General Assembly is meeting in New York this week, and just before the meeting there was a report that the Secret Service and the FBI have busted a massive, well, I I guess you could call it a hidden telecom network, uh, not just in New York, but all around New York, basically multiple locations with literally hundred thousand SIM cards in these SIM servers. And, um, they, they dismantled this network.
They've been making a lot of press about it. Uh, but the questions remain about sort of what is this thing? Was it related to the UN general assembly at all?
And, um, why did they announce this now? So Ira, this is your area. This is something that I know that you love to talk about.
Um, what is this telecom secret Telecom network? So basically what this type of thing allow, it uses the generic infrastructure of the telecom network, but puts kind of a sub infrastructure in there. And there's a lot being made out of, oh, this was, they, they announced it right before the UN General Assembly.
This thing has likely been built over possibly a decade, but definitely over years. And the thing is that the criminal underground at all these people, this helps them do a lot of things, lessening the chance, not preventing the chance of surveillance. And these type of networks do allow for communications among criminals and things like that.
So it benefits them to put networks like this in place all over the place. There was a whole bunch of talk right around the UN general assembly. They said they discovered this network back in August.
I don't think criminals would've built this network over the course of a decade to just go ahead to sabotage an escalator in the un the way people are making the sound like. And so, you know, that is for a proverbial red herring simultaneously, you know, then they say like, there's no offense to your tech strong writers, but they say within a 35 mile radius of the un. You know, that's just kind, I mean, what, What percentage of the, of the population lives there, right?
Yeah. I mean you're, you're talking that's the New York metropolitan region for the lack of a better way of phrasing it with tens of millions of people in the vicinity. Well, or 10, you know, more roughly 10 to 20 million people.
And so what's going on is this seems like this is a criminal underground network. They make a big deal. Oh, car drug cartels are using it.
It's like, yeah, criminals are going to use this. A foreign nation has used this. Yeah, foreign nations are gonna use it.
It's likely, it's, I, I won't say likely, but possible even US services are using this network too, to some extent, frankly, the FBI probably had to go ahead and investigate this and figure out, wait a second, are we infiltrating this watching bad guys do bad things? Because a lot of times what'll happen for intelligence purposes, you find out about these underground networks and you just use them for intelligence gathering purposes, which is likely what probably happened as well because they were probably monitoring these things to pick up activities. 'cause it could have been much more useful.
Like for example, what was the one on the criminal website that Silk Road, they let Silk Road continue for a period of time just to go ahead and monitor the criminal activity. So it would've behooved them to keep watching these things. And this was at a point where I guess they theoretically got enough information or thought they dried out the information they could get and then took it down.
Now the fact that this could theoretically because, um, be used for damage and people need to understand this does have the ability, the size of the network would have the ability to be a denial of service attack because you could use all these hundred thousand sim cards to theoretically overwhelm individual towers or whatever. And that can happen at certain critical times. But I think people are, you know, this is probably just a criminal infrastructure that criminals put in place to support their activities with lower likelihood of monitoring.
And they have these all over the country, I would think now they're probably gonna start to abandon them because now their FBI has indicated they know about them in other areas, which means if I was a criminal, I would think, hey, they're gonna be monitoring what we're doing on these networks, which is probably what they have been doing for months at this point. I was gonna say it, it's, it's, it's interesting, some of the other articles I read that were more in depth said that the, the reason they found it a few months ago was they were investigating all the doxing of, uh, some of Trump's when Trump went into office, it was mostly Republican people that got docs. Like one of the articles I read said, um, Marjorie Taylor Green, well, Specifically they were, there was a swatting attempt against That, right?
Yeah. I'm sorry, swatting, not doxing. So, uh, Mar they'd swatted Marjorie Taylor Green's house saying somebody called from this network saying, I've killed my girlfriend and I'm about to kill myself and try to talk me down.
But basically what they do is they, what swatting is is they make a phone call to nine one one and send 9 1 1 to your house and hoping they'll come bust your door down and make a big ruckus. So, um, and it was lots of people on Trump's team got, um, swatted from this network. That's why they started investigating it.
So it was definitely, they said the things they did say is it was nation state. Um, lots of people that they knew that they were already watching had been communicating through these, these servers. And one of the things, I guess Ira, I don't know details a lot about networking.
That's my new phase of life. But, but um, they say they can change the phone numbers all the time. So that's one of the reasons it's great for criminals is you got all these SIM cards, but then you can just use electronically.
You know, you don't not on, you're putting it in a phone, you're putting it in the server and you can just change phone numbers all the time and hide your tracks and do your criminal business as you need. Yeah. I mean, it is an incredibly helpful criminal tool and, you know, the fact that they are able to keep something, 'cause it's a lot like, um, uh, what was the name of the ransomware gang that took down hospitals?
Because likely what's happening is that, um, much like that, uh, I get, there's so many gangs that come and go between silk roads and everything, but much like what happens is some criminals probably just put this together and then some idiot starts to do stupid things like doxing politicians with it. And that is how things get exposed. That's why, for example, you know, like the ransomware gang I'm thinking of like that they license out their ransomware software and infrastructure that somebody all of a sudden says, oh, we're gonna do a hospital and ripple a hospital system, and then all of a sudden it brings attention to them and then they get mad and p**s, you know, and p**s the people off.
And then they have to cut these criminals off of the network. And this case, they, the ransomware gang, somebody knows what it is off the top of their head, I'm sure just had to change their name, which is the worst case in this case. Somebody does stupid childish things like swatting.
'cause there is really no benefit to it, per se, from a criminal perspective except to be annoying and things like that. The way it sounds like it wa it was executed and that things like that uncover the entire criminal infrastructure because they are gonna investigate and, and frankly, I don't care which political side you're on, that was flat out wrong to do something that gets people killed. Yeah, exactly.
And luckily they investigated it. And this is what uncovered, and this is really what happens where somebody pulls strings where they use these things like criminals use these things for infrastructure purposes, support and everything in ways that don't attract attention. It's kind of like using the major roads and not attracting attention by not driving like an idiot.
You know, on the other hand, somebody decides I'm gonna take my, you know, truck full of drugs and drive 150 miles an hour up I 95, that will compromise the whole network. And this is what's happened here that likely this infrastructure put in place, which has nothing to do with the UN general assembly Yeah. Has been uncovered because of people who just wanna do stupid things.
Could it be used for nefarious purposes, you know, to cause damage? Like articles wanna imply the answer is yes, but fundamentally it'll allow criminals to hide their activities, to change cell phone numbers, to make it more difficult for law enforcement to track them. And the good or the bad is however you want, like on which side you're on.
Somebody did something incredibly dangerous, attracting a lot of attention, which allowed this network and likely others in place to be discovered Can see, like, all I to think about is like, you know, watching only murders on the building, in the building right now. And of course watching all of the Marvel stuff about Hell's Kitchen. And all you can think about is those back rooms.
Like, why did you do this? Why do you know how hard it's gonna be for us to build up another sim farm in the tri-state area? Again, somebody's getting intro.
Well, is it gonna be hard? I mean, so, so it's funny, this story, um, reminded me. So yesterday, um, this, I read this story, uh, I started off the day recording a podcast with, uh, Commvault, I was with you where they were talking about with, with Gina, where we were talking about how, Um, These criminal ransomware gangs have become ransomware companies.
They're effectively real companies with profit and loss and presidents and a, you know, all this kind of stuff. They're basically, I don't know, dark side companies. And then I was, um, listening to the, uh, Infoblox presentation at Security Field Day and Infoblox was pointing out that there are criminal DNS providers Yeah.
And basically a criminal Bitly that registers like 75,000 domains a year in order to be able to serve ransomware links and those are businesses too. And then I read this story and like Ira said, my mind immediately jumped to this is not nation state hackers or ransomware gangs or s swatters, this is a business. Somebody created a business that was, you know, telecom network, you know, black dark telecom for hire and, and all of these things.
I mean, gee, we live in a world where there's basically an evil Economy. So is it is, so this is very fascinating to me. So these organizations set up like a proper business where they have like a chief operating officer of the dark web?
Or did, I mean, how, how does this, how can you just maybe go a little bit over it? That's that's what it sounds like. Yeah, so like, well, And just for, oh, sorry.
Just for example, the ransomware gang, I said they basically have software developers that write ransomware and then they have other people who like focus on, you know, the delivery of ransomware and stuff like that. They put the infrastructure together and then they license it out. This is crime as a a service.
And the thing is this, I'm sorry, ar I keep doing that to you. I'm Go ahead, Gina. No, that's Okay.
I do it to you too. Okay. Um, and, and so part of this, if you think about ransomware, the delivery, the most effective mechanism is to trick people into click in a link.
So that's done through marketing. So all the marketing tools that we use, this, these companies, literal companies that run this as a service, they are using AI now because like, one of the easiest ways to notice if it was okay, I think this is probably not a clickable thing because the English is all wrong. They use AI to write all their messaging, all their, or all of they can learn, um, they can learn someone's voice and how they would act and how they would say things so they can, you know, when they're really spearfishing, they can get that email down to sound exactly like the person they're impersonating.
They probably use this networking infrastructure that got taken down to do all of these activities. Um, and what's interesting to me is like, that's what I think probably happened is we're talking about this, whoever got jumped on here to do this swatting, um, blew up their thing. Probably was just got the, as a service networking that they provide.
And I wonder what happened to them. I'm really wondering if somebody already took care of Well, Some somebody might mess you up. Yeah.
If you did. If you mess with the criminal gang, well, but You'd be, yeah. So I mean, you'd be surprised they're not, I mean, the criminals are not gonna enforce, they're probably p****d off that they found this.
And frankly, there's probably a half dozen other networks just like this throughout the New York metropolitan region. Yeah. In fact, that's actually one of the things I, I, let's leave it with this.
Um, part of the article in Wired was an interview with somebody, uh, who's familiar with the FBI and they said, this isn't the largest network that they know of, and it's not even the largest one they've busted. So you may be impressed, I'm impressed by the scale of this thing, but it really isn't anything compared to what all is out there in the evil, criminal, dark economy. Mm-hmm.
So thanks very much. We'll be right back with another story, uh, here with the textron game. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. So we've just talked about the ways that criminals are using technology to really change the game around crime.
Well, there's another kind of crime out there, and that's cheating at golf. Uh, let's talk a little bit about, uh, wait A second. Now Let's, let's talk a little bit about this.
There are a bunch of data and analytics companies that are trying to apply IQ or AI to improve, uh, their chances at winning golf, uh, like the the Ryder Cup and so on. Uh, John, uh, start us off here. What, what do we know about these evil criminal golf Masterminds?
Oh My god, Steven. Yeah, you stole my lead. Damn you.
Um, it's about any event. So the Rider Cup is taking place this weekend and AI is gonna be everywhere. There are five major technology partners.
There's Cap Gemini, S-A-P-H-P-E, Motorola, and T-Mobile. One of the most interesting aspects to me is the influence of ai, as you said, and data analytics in particular on the competition. And I talked to the CTO of the Ryder Cup Europe team, and he basically told me something that kind of blew my mind.
He's saying that there are basically no limitations to what they can do in terms of using AI by the coaches or the captains to, uh, assess shots, weather forecasts, which include wind distance to a, a whole or, uh, what club to select. And, and, and it's interesting to me because in other sports, like the NFL in particular, everyone plays by the same rules in terms of their use of of ai. Um, they're limited in what they can do.
But then again, the NFL is a very socialist, like, like organization in the golf, golf world. You can't even wear a watch. You can't wear a smartphone and you can't have anything on your person as a golfer.
Now we have this new kind of elements where maybe the Team Europe has an edge. I don't know, I don't know what the US team has in store, but it opens up this possibility, as you said, to cheat. And I, and I, and I, it's funny, the more I, I would talk to him, I, I also asked this guy and he laughed, but he told me it's true.
He is like, when do caddies get replaced by AI agents or robotic physical ai, where they are your, um, advisor. The caddies is just as important as the golfer. And so they're gonna get smarter in a certain way.
So maybe the golf gets better, but then again, it becomes an arms race. And this has happened throughout all major professional sports. Back in the day, long time ago, the Dallas Cowboys actually had an advantage over a lot of other teams because they used computers at the time to assess, uh, drafts and players and free agency.
Uh, you also had an F1. It's, it's rampant. But I also think in baseball, it goes back to Moneyball and the whole idea of the Oakland days and maximizing efficiency.
So I think this is what's happening with golf, and it'll be interesting to see how it plays out. We were not, we're not gonna see it. It's not gonna be obvious, but we'll probably find out later after this weekend.
I, I, I wanna start, I I wanna respond to that first by just pointing out that I was being flippant. I don't consider this cheating. Oh, I, I think You're onto something.
And these are not criminal masterminds. Uh, basically these are people using technology to try to improve their game. Well, this, and as you said, that is something that happens in all sorts of sports.
And by the way, I'll just point out that baseball, major league baseball yesterday announced that they're gonna do, um, a robo ump. They're gonna have appealable balls and strikes next year in Major League baseball using, uh, AI and, um, and, and, and sensors. So, uh, IRA, Yeah, so this, the, what gets me is that this is a conversation.
What should be the news story is that okay, they're using better mathematics and computer technology to improve a golf game. Like you mentioned with Moneyball, where they started to implement basic statistics, which is really, I mean, frankly, AI is just more advanced statistical algorithms. And, but they've been using this at, like, I, I worked with some people a while back who like, back in the 2000th timeframe, the Sports Performance Institute like P three and things like that, who analyzed people like baseball swings, and were doing motion sensors to see how they do that, to get them to figure out how to perfect their swings.
And in this case, with the golf and taking advantage of like, okay, the poorer golfers who can't use the same algorithms, and it's gonna be widely available probably to sell to anyone unless some golf golfer is gonna tailor and have hire his own people, which is unlikely. These same algorithms are gonna be available to everyone. Like, what's the wind direction?
And they're gonna have little sensors on their golf caddies and store their bags and everything. And I could see this as, I mean, I'm kind of like, let's clap and let's applaud. And if golf thinks this is too much of an impact, yes, they can start to make rules.
Like, for example, who would've thought that headsets into football helmets, you know mm-hmm. Where the coaches are calling the plays. I mean, you're literally, yeah.
They're there to, there's Ever, if there's ever a sport though, that is incredibly regulated to the point where it's kind of a**l in terms of their rules, it's golf. But just to go back and I'll let, I'm sorry Gina to interrupt, but I'm just, just to, to go back to this, one thing I didn't mention is that it's also gonna be a fan experience. Evidently there is going to be dynamic merchandise inventory so they don't run out of certain types of goods in, because at these golf tournaments, they sell a ton of merchandise.
People who go to these events buy and, and, and so this, this way, they're gonna increase the sales as well. And I think the broadcasters gonna be using ai, although I'm not quite sure how they're gonna do it. I mean, I, there's gonna be a day when AI replaces announcers all together.
That's just inevitable. Oh, I, sorry, Gina, That's not gonna happen. I don't believe that.
I think they'll enhance the, there's no way you'll get rid of announcers, but that's an argument for another day. But like, how much of this has already been implemented or has been used on historical data to create video games? Because I know I've been to conferences and they've had, and I haven't gone, but I've stood with my guy friends and like, all right, what's happening?
'cause I don't understand golf. But, um, yeah, there's like, they, you would swing and it would tell you this and that the video game would tell you like, what, where's the wind coming from? What's the humidity?
Like, all the stuff. And, and that's how you would try, how is this different except that it's real time on the day of versus using historical machine learning to, to create a really realistic game. Yeah.
And, and as Ira points out, I mean, AI is just statistics. That's all it is. You know, generative AI is just a whole mess of statistics, um, all munged into one.
And that is no different. I was actually listening to an interview the other day with a professional chess player, and he was talking about how playing chess these days is completely different than it used to be because of the advent of computers and advanced statistics. And he said that basically, um, any player today would absolutely wipe up the board with any previous player because they have access to all this training and statistics that have been gathered and, and processed and that it's transformed the whole game.
And that's very true of, of, of many other sports Formula One racing. Uh, as you mentioned, I mean, you know, baseball, but I do wanna point out one thing that's kind of interesting. So I'm a big baseball fan, and the whole Moneyball thing, it was a very big, it was a great competitive advantage for the Oakland A, but it rapidly ran outta steam.
I'm not sure if you guys know about this, but today there's actually a big backlash against Moneyball. Yes. What happened was it changed the game Book I'm reading In the wrong direction.
I'm using a book to prop my, my laptop up. The book is Jane Levy's book about what's wrong with baseball. And part of the problem with what's wrong with baseball is that baseball's beauty.
I think Steven and I, and I will agree, was it's unpredictability. Anything could happen. There, there, there was a saying that every time you went to a ball game, you saw something you'd never seen before.
What analytics ha in a sense has done is made it a very predictable sport where, uh, athletes are taught these launch angles of their swings. They have a certain philosophy about hitting with two strikes. It's still to hit a home run because it's hard to string hits together because the pitching's so good.
In other words, baseball's become just the, the very antithesis of what made what we loved about it. It's so predictable. It's either a walk, a strikeout or a home run it scenes.
And it, it, and Moneyball was fed into that, and it kind of, kind of made it a bland sport. It made it a longer, a longer game is definitely, so, um, yeah, there are consequences. Yeah.
But the cons, I mean, I mean, I just have to say the consequences are, 'cause what this allows things to do is to make every element, like every piece of a game, whatever it happens to be, allows you to perfect it more. So in the case of Moneyball, like you're saying, for example, it allows an individual batter to know how to microt tune their batting. It allows pitchers to microt tune how they pitch things, throw things like, but, but One, one of the problems in sports is that athletes actually perform better when they don't think, and that sounds weird, but they act, they react.
I mean, that's, that's who they are. That's why they're great. And, and when you, when you drum something into them about a certain way to play under certain circumstances, they don't, they forget how to play the game and they don't know how to perform other aspects of it.
And that is a major problem with baseball. Oh, one thing I should also mention is that with this data, and Nobody knows how to burnt anymore. Oh, that's, no one knows how to field or how to run the bases throw to which base.
But, um, there are 15 data points, free, shot free, uh, golf shot under the, this, this analytics. And that's, that's gonna escalate, by the way. So, uh, to IRA's point, you are perfecting these are, these athletes have never been better, they've never been better trained, but I think almost in a sense, they become robotic.
And I think you see that not just in baseball. I think you see it in, in football, and it can becomes like vanilla and bland, and they're all kind of stealing and repeating what each other does. So There's ai Slot sports Is what you're saying.
It's not just marketing fighting. It's in sports too. Yeah, true.
Well, As any, as any fan, as any fan, uh, who's watched, um, sports recently knows too, there's a lot of impact, you know, in terms of the fan experience, whether it is the, um, scourge of gambling statistics that are everywhere, or whether it is the absolutely asinine, uh, predictive statistics that appear on screen. Apple, by the way, Apple's coverage of every sport is the worst about this, because they put little percentages in the corner of what's gonna happen next To next. Well, likelihood it's one team beating the other, or whatever the result is.
Yeah. It's just nonsense that EPN does this on their app all the time, and it is maddening because one team will go from a 87% favorite to a, a 13% favorite based on one play, you know? So it's like, what's the point?
Um, but, uh, yeah, sorry. It's just, I I don't, I don't know. I Yeah.
Sorry. Go ahead. Thanks so much.
Th this, it's a, it's an interesting conversation. I think, um, ultimately what's gonna happen is that it's, it's gonna be all about the athletes. And some of them are gonna be able to use this technology and be greater than they ever could be before.
Uh, some of them are going to, uh, use this technology wrong and it's gonna derail their careers. And ultimately the, uh, the escalation of technology in golf and in other sports is going to, uh, change the game in some fundamental ways. And we'll see where that works out.
So, um, thanks a lot for, uh, joining us here for Textron Gang. Um, before we go, I do wanna point out that, uh, we are live with Security Field Day here on Textron TV today, uh, yesterday and today. And we will be broadcasting, uh, if you liked these security stories.
Uh, we're gonna be broadcasting presentations from security companies, and you'll be able to catch recordings of that on the Tech Field Day YouTube channel, as well as the Textron TV app. John. Hey, uh, thanks everybody.
You were all great today. This was a fun conversation. I love when people interrupt one another, that means that we are exchange.
No, I disagreements over talking. You know, I, I disagree with that, John. Hey, stop it.
Um, but you know, I, I, no, I, and, and you brought up the idea about cheating in golf, but in a sense, cheating in sports is like very common. You're always looking for the edge. And it goes back to the days of the 1950s with the, the people spying out of the center field, center field wall, you know, and, and relaying, or our Houston Astros banging a garbage can.
Something as low tech as that. So, um, it was fascinating conversation. I'm, I'm glad there's a lot going on in New York, and I think you all did an excellent job of laying it out.
And, um, we want to thank the audience for watching Techstrong Gang, and, uh, we'll be back Monday. Alan and Mike should be back by then. And, uh, have a great weekend.
Hey, everyone, we're back here on Tech Trunk tv. I'm really happy to have my next guest, Tanya. You know, sometimes ships crossing in the night could be in the same industry for, I don't know, 20 years, 25 years.
And somehow or another, you just never got a chance to catch, catch up or meet each other. So in, in setting this interview up today, I had a chance to meet a new friend in the security space who's been here as long as I have. And that's always a good thing.
Let me introduce you to Craig Adams. He's the Chief Product Officer over at Rapid seven. Hey Craig, welcome to Tech Strum tv.
Uh, Alan, the pleasure is all mine. Big fan of the show, and thrilled to be on it for the first time. Uh, it's pleasure to have you on there.
So I gotta just ask 'cause people are looking, that's a really nice background. Is that, that's real, I'm assuming. Yes, This is real.
This is the home in beautiful Waltham, Massachusetts. Well be That is, it's a good, it's a nice time of year to be in Waltham. It's the, uh, this is the tricky thing about New England is while we have four seasons, the winter one is six months long, so you're in that sweet spot, uh, before it's not too hot.
And then, or That six at the end, six months starts. I know Florida, it's a very different dynamic though, so, uh, this is not something we have in common. No, well, I'm, I'm from the north, if you couldn't tell from my funny French accent.
And I am from the Northeast and grew up out in the wilds of Long Island. But, um, yes, we are in Florida now, and if I undid my window back there out to the balcony, yeah, we are. I'm on the intercoastal in it.
It's beautiful here today, but hot as hot, hot, hot, hot. Anyway, Craig, I don't know how long you've been a CP over at Rapid seven, but as I mentioned earlier, you have a distinguished history in the cyber InfoSec space. Share with our audience a little bit about your journey.
Uh, very kind. Uh, so I spent two decades at Akamai Technologies building out their security business. Really the thesis was that while organizations were investing a lot of things on-prem, there was a, a fundamental different layered security we need to add on top.
Um, after two decades there, I realized the world was moving to not just the magic application, but the intelligence of data we put in the application. So became Chief Product Officer, a recorded future. And then I recognize what a lot of your viewers recognize, which is yes, uh, data is key, but fragmented data from all of the 35 different security tools, or 45 or 55 different security tools we use.
And so I moved over to come, uh, as Chief Product Officer, rapid seven, approximately a year and a half ago, helping customers better leverage their security investment and reduce some of the fragmentation of their environments. Excellent. Excellent.
You know, as we were talking off, off camera, I've, I, I've literally been following Rapid seven since the day Alan Wallace launched Rapid seven. And that was, that had to be, what, about 22 years ago? I'm going to guess 20, 21 years ago in that range.
Yeah. And, um, it's come a long way, right? What, what started as sort of a very basic vulnerability scanner, and this was back in the days when you did vulnerability scanning.
Once a year you delivered a phone book right. To the security admin. And he worked through that phone book, basically you scanned around Christmas, right?
You gave it to him and you came back and gave him another Christmas present next year. That's how long it took him to work through the book. Yeah.
Dude, interesting definition of present. I've never seen a vulnerability list referred to as their present. Well, I'll, I'll that one.
I'll be honest. It's funny you bring it up. 'cause the, you know, the company I had co-founded still secure.
We, we had a product similar to Rapid seven called Van, and we used to call it the Bad News Generator because that's what it was. It was the bad news generator. That's right.
That's right. But to be fair, Craig, and it's a, you know, it's a view into our industry, other people called the job security. Sure, sure.
Because I had plenty of vulnerabilities to work on. They needed me. That's right.
Of course, the, the, the game has changed a little bit, right? Absolutely. We've shifted scanning left, we shift more often.
We, we remediation processes are better than they were. Um, not just patching and the whole, the whole AppSec thing came into being right. Yeah.
And testing and yeah. SecOps, which is, you know, something I obviously got very involved in, um, talk, you know, for our people out there who still think Rapid seven is a quick vulnerability scan, you do once a year, Craig, your chief product officer, give them the vision of the Rapid seven product line. Yeah.
So, so absolutely. So still, we, we honor our heritage by of course identifying exposures in an environment, but that's actually the minority of what the company is today. Mm-hmm.
So to be clear, there's three things that Rapid Seven does for our customers. Uh, the first is we help them understand their attack surface, um, which is the first mistake most organizations make. Gartner will say 17% of organizations can identify 95% of their tax surface.
We're not even looking at the things we're trying to protect at the end. We give them an aggregate view, looking at everything across the environment. The second, of course, is we help them prioritize exposures based on risk in their environment.
It doesn't matter if it's on-prem cloud in an application, uh, a mised, uh, identity or a mis inconsistent control, but we're gonna help them risk prioritize exposures. But then finally, and where we spent the most of both our time as well as most of the company's revenue today comes from detection response. So how do you provide an AI driven both sim MDR service intelligence with the critical validation wrapper around it that allows organizations to be helpful?
You know, what makes us unique in this space is, uh, I believe religiously that environmental context matters. So when you're doing detection response, when you're investigating a threat, as much information as you can have about that environment, AKA, does that machine have an exposure that's currently being exploited in the wild? Is that cloud account perhaps misconfigured?
Or does that application have a vulnerability attached to it as much environmental context as you could integrate into a detection response that allows you to prioritize faster, respond faster, and of course understand quicker the path to remediation. That's where we're spending a lot of time focused today with our customers. I, I would imagine what a time for something like AI to come out and help you with that.
Oh, The, the, and, and first, you know, we, because we hit AI in the first five minutes, you and I also need to be intellectually honest that there's a lot of AI washing of things. Uh, ML models have been around a long time at the same time with all the ML models. Even if you just flip 'em and call 'em ai, we knew that in detection response, what was doing in the past wasn't working today.
It wasn't working just to do predictive analytics. We actually had to go to an agentic world where truthfully, when a threat's identified, it's instigating a series of actions that each, depending on the previous data sources, are calling out other actions. That agentic AI workflow is one of the things that we believe is gonna drive detection response across our horizon.
Um, I disagree, I'm convinced it's finally gonna give us the best path to the cyber skills shortage that everyone know is so pronounced these days. Absolutely. I agree with you a hundred percent correct.
Of course. Getting from here to there isn't always easy, right? I, one, one of the lessons I learned the hard way in security over the years was, you know, we, we've had the ability to automate things for a long time.
Sure. Like, I remember, you know, the company I helped start, we went IDS to IPS and people were freaking out. You can't block stuff automatically.
I gotta see. Sure, sure, sure. I would've blocked the CEO's horn or something.
Who knows. Right. But, um, I was gonna say important memo, but still Yeah, well, something like that, you know, the ability to, to remediate vulnerabilities for so long has been something we all give lip service to.
And, and yet we're just now really starting to see as part of detection and response automated remediation. Right. You know, and it's, it, it's, it is what it is.
We've seen it in the whole shift left thing and moving Absolutely. From, from, you know, once upon a time scanning to continuous testing. Yeah.
You, you're, you're, you're so accurate at first, and this is the always the grand debate of what do you want clippy to do? Uh, yeah. Use clippy.
'cause you and I are of a certain age. We remember Clippy, we Remember Clippy, we remember he's co-pilot the next clippy. But that's a whole nother ending And that's a separate episode.
That's not for today. But, but I think the, there is something that I believe we're now at the point, and this is what we've been working so hard, and we recently announced, as you know, around how do you take something that was being done like it was 30 years ago, which is this validation assessment or pen testing environment, a continuous red teaming, um, the mythical environment that most people wanted that no one can afford. But how do you actually use AI as well as environmental context to bring together a validation view of an environment?
Because if we actually look at problems that exist, every, the number one question every CISO is asked by the board is, are we protected? Uh, they want that clarity that fundamentally is a validation question. They're asking our traditional way of doing that, of one pen test a year or two, only for the largest organizations with the largest budget of continuous red team service.
That's not sufficient. And that's what we've been working hard at recently. Rat Seven.
We're gonna dive more into that here. You know, one of the reasons I had left still secure and gone outta that whole thing is I came to the conclusion that security was too hard, except for the very largest and not even the Fortune 500 maybe the Fortune 100, the Fortune's 50, have the ability to do continuous red teaming in house, have the resources for true 24 7 knock sock layer differences. I, I felt like for the, for the average guy, for the medium, small, medium enterprise, let's call it, they didn't have the budget.
The, they Don't have the budget. They probably didn't have the end of the day, Craig, they didn't have the stomach for it either, because it's a huge undertake, you know, we throw around things like, oh, continuous red testing and, and this, and tell the board what your risk is. What's the CSO to do?
Just stick his finger up in the air and say, I think my risk is 30% about today. That's Right. You, you need sophisticated tools in addition to people That's Right's, right?
And, and so it, it, and, and I'm not alone, right? This is every security not at all dilemma, right? We, we get frustrated because we know we, for the most part, the overwhelming majority of organizations don't have the wherewithal to do what they need to do to really protect themselves.
So instead they become zebras in a herd and hope the lion eats a different zebra today. And, and I think even worse, the limited budget, I shouldn't say worse, and the limited budget they have is often forced on things that are regulatory compliant. So, so take, so, so take, um, take even if I'm a zebra in a herd, but I'm in a regular industry, I have to do a pen test.
WW which is, but, but I, I get the budget to do essentially that, that, right? And it's the lowest common denominator Once a year, Right? I check the box Because we know our environments aren't constantly changing.
We know the front landscape. Is it constantly, well, it's not, Yeah, it's Static once a year is am, but I'm writing one does 95. And So the question we heard from our customers was, how do we change that?
Like how do we actually take the thing that was a checkbox to actually create a posture validation service? And I do believe this is one of the areas that without ai, we would not have been able to do it in a cost effective way for our customers. But the ability to do continuous red teaming with the penetration testing included, which is critical for, um, compliance authorities, combined with the attack surface visibility, exposure visibility.
That's what makes it unique. So if I can go there for a second, like one of the things I get excited about is, um, being able to look at the external world. Just E-A-S-M-I is just such a minimal step in an operation.
Everyone knows it's movement inside of an organization. Attack path navigation. This is where the unique technology we already had and the ability of service command, the ability to see across your environment, how those things connect combined with the exposures inside of it, with our continuous testing services, allow organizations on a regular basis to get validation of the controls they have in place if they're working, what are the newest identified hotspots in their environment, and of course the deep penetration testing that whatever their industry requires.
But, but that's unique and is gonna be a significant disruptor, in my opinion, to the traditional pentest market. I agree with you, Craig. We, we keep biting at the edges of this thing.
Yeah. So does it have a name? Oh, of course it has a name, uh, vector Command Advanced.
Uh, the intent of vector command is as you're looking across your environment, you need to be able to see of all of your attack vectors, do you have command and control of what's happening across the advanced? Recognizes that in addition to continuous red teaming, you need that deep penetration test as well. If you're regulatory compliance vector commanded advance is the main Absolutely.
VCA vector command advance. Now is it, it tradi, it combines traditional pen testing. What about like a, is there an AppSec element to it as well?
Like to the left of the event horizon of deployment or, Yeah, absolutely. Yeah, absolutely. So, so there's a few key things that separates.
So first of course it has pen testing, but pen testing is Table, I'm gonna put that to the side for a second, right? Uh, the, the critical things that does this. First it was organized and built to be compliant supportive.
So we recognize that many organizations, one of the things they're trying to figure out is how do they get the materials go back to them in a way that directly supports whatever audit readiness they're going through. The second is a need to integrate into your exposure management visibility. So that means what exposures exist inside of my environment, whether it's application on-prem or cloud, it can also critically include the attack pathing information that Rapid seven has.
So again, just being able to see that I was able to access this machine, I wanna be able to see that inside out view based on, uh, what we enable from attack pathing, which then allows organizations to understand just the significance behind it. But critically, it's not a once a year thing. That's one of the things we constantly heard from our customers is I need regular validation if my security controls are actually protected.
Because we know with the way modern compromises work, we're seeing a significant rise in the spray and prey. We're seeing a significant rise of when a exposure or compromise happens, it's broad, uh, or threat actors are able to go broad fast. So the adversary is constantly validating your defense.
Um, how, how are you? Uh, and I don't believe it's just enough to have the controls. I think you need to actually do the work and do the test to be able to see it yourself.
Agreed. Agreed. Is it available right now?
Craig? Available now we have over 40 customers already using it, and we have not had a customer yet. That said it didn't fundamentally change their view and approach the security posture.
I love that. How can we, how could people now watching this right now go grab more information on this? Oh, so first, uh, if you're already rapid seven customer contact your account team.
If you're not, come on the website, you'll find a clippy ish thing to chat into. Reach out to us, let us know more. And we're happy to engage, to talk to you more about Vector Command Advanced, as well as what's new at Rapid seven.
Because if you're still viewing us as a vulnerability management company, oh my goodness, quite a bit has changed. We'd love to talk to you about our SIM MDR service and all of the capabilities to keep you protected. Gotta ask a stupid question.
For those of you out there who don't know, rapid seven is R-A-P-I-D number seven, if I could. That's Correct. Dot com.
Dot com. I just wanna make sure we get that out there. Alright.
Hey, Craig, unfortunately, this is too short a format for us to really dive deep, but I, I'd like to continue the conversation 'cause I, I, we spoke about it off camera, we didn't get to it, which is, what's the CISO's dilemma here, right? They have, okay, now I've got another tool to use here. How do I integrate this?
How do I, how do I pick and choose, right, the right lineup to, to deliver, bang for the buck, measure my risk, convey that risk exposure and everything. You're A hundred percent right. Um, uh, every ciso, and I'm using the word every, um, if they're trying to figure out how they better consolidate to use both the time and treasurer of their teams effectively, that's the most frequent conversations we're having with our new customers coming on board today is like, wait, I can consolidate my vmem MDR validation, threat intelligence, CAP chasm, all in one place.
Or by the way, uh, you operate an open platform to find one of these three things of yours, three things of someone else's, Not how do, how do I, they choose. Yeah. And That's a big contrast to other, Uh, platform organizations with their closed approach is the ability for people to choose how they wanna work with us and engage.
We'll continue the conversation. Alan, I love this. Thank you so much again for having me on You.
Welcome Craig Adams, chief product officer, rapid seven, enjoying the season up in Walham. Alright, thanks all. We'll be back here in a second on text Drunk tv.
Hey guys, thanks for the throw. We're here with Phil Haiku, who's head of developer experience for valis and we're talking about multi-cloud and well, there's some hidden costs in there and some might even call them a tax bill. Welcome to show.
Thanks for having me. Alright, Walk us through what goes on here, because everybody thinks that maybe they want multiple clouds and they wanna be able to put workloads everywhere, and they think that there's a lot of flexibility in all of that, but I think every time I add a new platform, I gotta add new folks with different levels of expertise. So maybe the costs outweigh the benefits.
Phil, what's your take on what's going on here? I think it's, uh, almost always gonna be a trade off question, right? And that's gonna differ contextually with everybody.
But you're right. I think the, uh, while conceptually a lot of the cloud, multi-cloud, especially the larger ones, will offer the same things. Language will be a little different.
The specifics will be a little different around each one. So you're gonna have local changes in tradition or trade-offs that you wanna make. Uh, and then you'll have people who obviously have built their careers around one or the other.
And then at the end of the day, I think really it's gonna be around what it is, right for you from business context. Do you want to have very strong separation of concerns? Do you want to have very strong consolidation of your finances so you can make sure you're not paying too much for what you're doing?
Um, but it all becomes just a question of like, here's the trade off. Let's make sure we are making them deliberately. Because if you don't, you're still gonna end up paying it, but you just don't know what the trade off is.
And then that might bite you later. Is it really possible to have kinda one IT team that is master of multiple platforms, or do they wind up just being kind of jacks of all trades as it were? And ultimately, I wind up having to get a bunch of different specialists anyway.
Uh, at a certain size, it's gonna be impossible to really have one central IT team that manages everything and does all that, but that at that size, you're gonna have consultants coming every now and then for specialized things anyway. Um, so I don't think that's also the goal, to be honest with you. I think the the thing that you do want though is making sure you have insight and some level of governance on where you're, you're having your assets deployed and where you're spending your money.
Um, and that is very much possible, but like I said, it, as long as you're deliberate about what you're choosing, you don't have to be contained to one service or one company, but you just wanna make sure you're doing it with understanding the reasons and the constraints, the trade offs. Mm-hmm. How do I get that visibility?
Am I kind of deploying some sort of platform to drive that or am I pulling together all these different dashboards from all these different cloud providers into some single portal? What's the magic there? Well, I don't know if there's gonna be a lot of magic involved, but you're probably doing a little bit of column A, a little bit of column B.
Uh, so each one will have their own billing interface, um, and they'll never be quite perfect for what you want out of it. So you're always gonna have some form of observ, uh, observ observability platform or tool on top of that. Um, and, um, attached to that, you also wanna make sure that you can segment it the right way.
So obviously your total dashboard, which just tells you whatever your dollar figure is and how many, if you're in AWS, right? EC2 instances you have and everything else isn't gonna give you the right contextual information that you have, you need to be able to pair that with which teams are using it, how often are they revenue generating, are they experimental, all that stuff. So if you're always gonna end up needing to pipe that to a BI tool or maybe even a, a data science team who kind of slices that up in their data lake.
Um, but again, a lot of it will, will end up being a, how much that visibility do you need? How much that are you pushing down? Um, we see a lot of companies have a lot of success with leaving the details to the either regional business owners or, or whatever terminology they have, right?
You use GMs, um, and they just own the budget for a lot of that, and they'll just come in overhead and say like, all right, we made a deal with this company for this, but we'll take on internal IT ops centrally. So it's possible, but again, it, a lot of it will depend in context and it's always gonna be a combination of tools because depending on the question you have, because you're going there to answer a question, you're gonna have to, you know, heaven forbid export to Excel and write your own pivot table. But most of the time it'll be a combination of like, all right, I've got this list here.
This is what's happening. Put 'em both in your own working memory and then figure out kinda what's going on Is in your sense that some organizations are truly multi-cloud or is it more likely they have one cloud that's kind of dominant and then they have a couple of smaller clouds running because they picked them up through some sort of merger and acquisition, or somebody decided that there was a particular workload that really had a run there. But, uh, for the most part, they are standardized on one larger cloud and then have a bunch of smaller clouds.
There is almost always gonna be one dominant one. And, um, there's always kind of a, there's A and B, and then everybody else is kind of much smaller in my experience, right? So you've got for companies that are software companies, right, in the traditional andreesen software leading the world terminology, like all their production work is going on a cloud somewhere or hybrid cloud, right?
They'll have some data center somewhere. That's the biggest one. And that's also your most important one.
'cause frankly, like that's how you make money. Um, and so that will always be consolidated as a general rule. You might have some separate products, like you said, from m and a and stuff like that that live somewhere else, but the effort post m and a is always gonna be some form of consolidation, if that's possible.
Um, and then you'll have your internal ops stuff sometimes on the same cloud, sometimes separated by design. Uh, it really kind of different. Like it's kind of 50 50 in my experience, but I, I don't have a broaden up view to really get that authoritative number.
Um, and then everything else just kind of lives where it happens to live, right? The, the usual tool sprawl that just over time or somebody got a corporate credit card, they need to spin something up real quick and then well shoot, we can't fill that process yet and it's not worth migrating. So we'll just keep it over there.
Like it, it ends up in this kind of like, there was an element of deliberateness here, but there's also some organic growth around the edges that you definitely will always have a little bit of, like, it's unavoidable. Of course, you can't walk down the street these days without somebody talking about their great new AI thing. Um, and I wonder, you know, mighty become easier to centralize the management of clouds in the age of AI when I have my small army of AI agents that have been trained to do things.
I mean, is that a reasonable expectation or is that still fanciful thinking? There is probably some truth to that. I think there's, there's two ways to look at that really.
There's where the AI agents are running, right? That's not a trivial cost in most organizations, right? So you're gonna end up having the stuff that you're hosting yourself will live in some cloud instance, and that'll be a non-trivial bill.
Um, there's also what you want to do. Um, migrations traditionally have been non-trivial in my experience, even though conceptually very similar things have been offered. Uh, AI agents will probably make it a little easier, but you're still end up gonna have, like, you're still gonna end up having that constant conversation around is the opportunity cost of focusing on this and the potential disruption worth doing?
And AI agents may change the ratio of some of that, but it's always gonna be, again, that trade off of like, is this the best production or deployment of our resources? And oftentimes in my experience, like not really until it gets to a certain size and then it becomes too complex to really want to leave it outta hand because you need an accountability aspect of it. I've, in my experience, while a lot of the agents show a lot of promise in what they can do, you can't hold 'em accountable for what they're supposed to do yet.
You still need humans for that. Mm-hmm. Now, we also talked briefly about finops, and I'd love to get your insight about this, but, um, are people setting up like a finops office where there's the finance team and a, and a couple of IT folks and they're kind of doing that as a center of excellence and or maybe the better part of valor is just to put some sort of cost metric in front of the SREs and DevOps team so they know how much things actually cost and they'll just do the right thing accordingly?
There's a bit of truth in the first one. I think people start with that. Like, uh, we know like over the last say two years with the macroeconomics of what it is, cost has become very much top of mind and people have looked at it that way.
Finops has become the popular way to, to manage that. Um, historically finops sits, I think right now as the third party. And what was also happening with quality and security in terms of like, it's sat all the way at the end of a decision making process in terms of the chain of what happened.
But the goal is to move it as left as possible, right? Like you want security and QA to be things that are in the planning stage and the development stage, not at the deployment stage. And similarly with finops, like you actually want that to become as early a like principled concept or thing that you discuss with your product teams.
And so I think you're right, like the, you want that to be, I dunno if I put it in the SREs hands to be honest with you, that just probably gonna lead to a lot of containers getting nuked. But I think that if, if you move that to a product piece that yeah, the end goal would be definitely for them to make that decision, right? They'll own a local budget, they can advocate from a business case perspective, like, we need this money for these services and this, they know what it costs because they'll have the local bill and it's a lot easier and, and tighter.
But I think that that's more the end state they're working towards. Most organizations are really not there yet. They're really in that first area of like, we're doing some initial IT financial management.
We know what our bill is, we need to bring this down. How do we do this? Well, it starts with understanding what's running.
That has to be done centrally. 'cause again, a lot of these budgets have historically been managed centrally. And then you can start to push responsibility out kind of incrementally.
But I think we're on an evolution or a path there and we know where it's gonna be, but it's gonna take a while to get that culture change going. Of course, you are in charge of the developer experience. Um, and I have to ask the question, do we give the developers too much control over the cloud?
It seems like historically we have decided that speed was everything and we let these folks provision the infrastructure, and then we're surprised when there are misconfigurations and mistakes get made and uh, data gets exfiltrated. But do we need to find some way to maybe more centrally manage that? Does that look like some sort of newfangled platform engineering team, or how do should we be thinking about all this?
That's a really good question. I think there's an element of risk that you have to accept on that front though. Um, as someone who's blown up our Google maps, API bill once before, like, I know what that's like, you feel bad never happens again.
Um, so this is a like learning experience cost to it, and you learn from a retros perspective how to manage these things kind of proactively as well. Um, I think that because you want developers who are truly informed, like if you're having that actual agile team, they should be responsible and accountable for that. Um, historically in the zero hs rate environment, that was a lot easier 'cause cash was cheap.
Um, but now like, yeah, I think that becomes kind of a, a new muscle they have to learn. Um, there probably needs to be some central oversight. Um, but it becomes a, the typical balance of enablement and governance.
I think the enablement sits at the developer side. Governance needs to be something centrally done. And if you kind of balance that, right, this is not something that becomes overly complicated to solve.
I think the developers can still have enough freedom to do their job while not blowing up anybody's budget centrally most of the time. So what's that one thing you see folks doing that just makes you shake your head these days and go, folks? I think we need to be a little bit smarter than that.
Um, one central rule is often the case that that never works. Um, so they'll have like a central rule, for example, that, um, just as an example, right? Containers need to be spun down at 5:00 PM and they'll spun back up at 8:00 PM or, you know, whatever the number ends up being right at 8:00 AM Sorry.
Um, that in theory is a great idea, but if you make that a policy across different time zones never works, uh, if you make that a policy, but you have production environments or that are running, or you have jobs that have been all allocated over and that you need to run over the weekend, but you took down one of the microservices that they rely on, like, I see that oversimplification type of thing is, is definitely something that people are, are struggling with. So they'll have a central policy, we can't do more than this, or here's our limit, and they'll cap things on a budget perspective. Um, I saw a customer, for example, they had a, uh, a hard cap on the budget for their serverless processes, but that's great, but if that's in the middle of your customer environment and they were gonna blow up their bill, but they're gonna pay you anyway, but you cut them off, now you have an unhappy customer and you've take them down your services.
So I, I think the overly simplistic approach that we've seen that a lot of customers take sometimes, like that has a tendency to, to not work. And it's easier to have guidance rules and then make it something that, all right, somebody exceeded this guidance, let's figure out if there was a good reason for it. Amend the rule then to have these hard and fast cutoffs.
'cause I've seen those come in and and they never work. Like they'll keep the bill down, but you're paying for it later. Mm-hmm.
Of course, there's an old joke that says, you know, in the future of the data center is one person and a dog, and the dog is there to keep them from touching anything. Um, what is the level of automation that we should actually be maybe working towards? 'cause I feel like we'll never get to total automation yet.
I also feel like we seem to be erring too far these days on manual processes. I Think the goal will always be a little bit more than what we have now from an automation perspective. Um, there's always, but it's, it's interesting how the same rule applies.
There's always an exception. Therefore, whatever rule we have codified doesn't work because the context, whether it's the business context or the goal for the, um, the product or like the circumstances around our, you know, infrastructure has changed a little bit and you have to change, tweak things a little bit. Um, there's that flexibility that you trade off.
But I think it's also important that, uh, maybe I'm old fashioned in that sense, but the fact that you can and have to understand the manual process a little bit to get it up and running is an important thing to have. Because at some point, if you abstract everything away and no one ever touches it, when something breaks, it takes a lot longer to debug and figure out. Um, so I, I I, I, I, that's not a reason to do it.
I think that this is kind of a side benefit for it, but yeah, you're always gonna try and automate a little bit more. But yeah, it's, it's kind of unavoidable that you're always gonna have some manual processes and that's okay. I don't think that the, the tax on that is too steep.
All right, folks, will, you're heard it here. Hey, no matter how much it advances, you still need to get your hands dirty from time to time. Hey, Phil, thanks for being on the show.
Thanks, buddy. All right. And thank you all for watching the latest episode.
Back to you guys in the studio. Hi everyone. Welcome back here to our day two coverage of Jfr Swamp Up event in, uh, beautiful Napa Valley.
We're at the Meritage Resort, and if you've never been here, highly, highly recommend. It is a full on resort and spa with wineries on and vineyards on premises. It's really a lot of fun.
I I really do, do recommend it to all you. Um, let me introduce you to our next guest, though. We have two guests here.
We have Aman Sana, and I hopefully get this right. Vijay Kumar. Hey.
Hi, Aman and Vijay work for a large financial financial institution. And they're here talking about, you know, in a hybrid AI world, how, you know, how large financial institutions can get a hold of their, or it can, you know, manage their CICD pipeline, their software, supply chain, security of it, and everything else. So Armand is closest to me here, vj, to my far left gentleman, welcome to Textron tv.
It's great to have you on here. Yeah, thank you so much. Yeah, we are, we appreciate the opportunity to be here and in this beautiful Napa Valley.
Yeah, this beautiful day. There's worst, worst places to be. Sure.
Um, so let, let us talk a little bit about you guys presented, actually. Yes, yes, we did. So if you wouldn't mind share with the audience a little bit about your presentation.
Sure. So, uh, we gave a talk yesterday. It was, uh, a good opportunity to come here and, and present in front of like a large crowd talking about like how, uh, a large financial institution might do, uh, uh, a resident release of their workload, especially in a hybrid cloud setup, where the complexities are very different, right?
I mean, uh, uh, typically like companies, they start small, uh, going on-prem, especially in large financial institution. Uh, there's a lot of legacy stuff that still runs on-prem, right? I mean, uh, especially in bank financial domain.
Uh, companies started with building the infrastructure, uh, in eighties, nineties, early nineties. And that infrastructure still runs on-prem. But the challenge is that, uh, in order to compete in the marketplace, uh, companies have to evolve and, and make sure that, uh, they, they are able to seamlessly integrate with FinTech, uh, especially like the, the new age companies, modern age companies.
And there is a pull, like on, uh, on the other side to build modern software. And that brings a unique opportunity as well for the companies to start looking at how they can modernize their existing workload. But the challenge is it's very hard for the companies to migrate everything and in one single shot.
So the strategic choice that company has is to invest in hybrid cloud capabilities, which doesn't come for free. I mean, there are challenges, uh, that we can talk about, but definitely, uh, there are a lot of opportunities that show up with hybrid cloud where companies can scale, they have capacity burst. Um, and then a lot of like the, uh, advantages when it comes to like innovation, making use of like, um, a lot of like different, like new technologies that are being developed and, and are cloud first.
So that kind of like bridges sort of like the gap with hybrid cloudware. Companies can still run the critical workload on-prem, but then at the same time, they find a way to sort of like, uh, gradually move, uh, to cloud in a phased approach in a phased manner. Excellent.
You know, I, I think, well, I'll speak for myself. I'm not gonna speak for everyone. That's kind of the way I always envisioned it, right?
That you don't, I remember, I, I was at an IBM conference eight years ago, seven, eight years ago, talking to the CIO of Hertz, you know, the car rental company. And, and he said they decided to go to the cloud. And what they did is they built from, from scratch all new cloud-based applications, and soon as they had those up and running, they literally just shut down their old on-prem data center applications and switched over.
Well, it was a disaster. Turt wound up filing bankruptcy, if you remember a few years back. Yeah.
He lost his job. Yeah. And, and so I always knew that that was not the way to do a cloud migration, right?
You don't do it that way. You had to do it over time, and you're gonna have this hybrid model and that, and there's nothing that mattered. That hybrid model may last forever, quite frankly.
There's nothing saying that yet. Move everything into the public cloud, right? Yeah.
I mean, if you look at, right, we are kind of home of innovation right here and, uh, California, and as you go from Napa Valley to south, you start seeing the innovation every, every mile, every minute, right? Yeah. So if you look at this space and the, not just fintechs, the large electronics company, you know, the apples and Googles, how they innovated in last, uh, you know, one and a half, uh, um, uh, decade.
And if you look at all these things happening together, they're integrating with financial institution, they're integrating with healthcare and whatnot, right? So if you see the innovation is happening and financial institution cannot be left behind, right? So they need to be, they need to make sure that the customer experience is retained.
Customer wants everything on the fingertips. So all these digital payments coming together, it's, it's, it cannot stay on the legacy because legacy may not meet the customer expectations. So I agree, bridging the gap requires, you know, the resiliency everywhere, right?
And we have a kind of a environment where customer is at the center and everything needs to be delivered quickly to the customer. So that's where the, the cloud and the DevOps and automation comes into the play, and that finances services are catching up if they were behind, but they are not too far from getting, you know, no, uh, to the space where they're supposed to. So, I, I'll tell you a, a funny, not funny, but I'll tell you an observation I've had, right?
com, it was 2013, so this is 12 years already. Yeah. And, um, yes, traditionally, finops financial institutions being conservative and highly regulated don't necessarily have bleeding edge, right?
They make sure something's tried and proven before they, they leap into it. But when it came to DevOps, and then DevSecOps, right? I saw financial institutions take the lead.
And the reason for it was, quite frankly, where they were, was not a good space from a security point. They were being attacked and hacked, and they had to do something. They had to get better control of that, number one.
Number two, the market was changing. You had this new breed of financial institution that was, was born in the cloud, that was born on the internet that was more nimble, right? Because customers, you know, when I was a little boy, we didn't have ATMs even yet.
You had to write a check. You wait online at the bank to the teller. Yeah.
Yeah. And they would give you the money. ATMs came out, but then apps came out on the phone, the cell phone, right?
Yeah. It just changed it. All of a sudden, people were, how often do you actually go in a bank anymore?
How often do you deal with the human at your financial institution group? Only if there's a problem, basically. Yeah.
So as a result of this, I, I think the market flipped finance became a leader in customer, you know, giving the customer what they want, when they want, how they want, which was primarily through a app. Yeah. Not through a brick and mortar.
Mm-hmm. And, um, so my experiences is that they have led the way in DevOps, they have led the way in a lot of these innovations. However, they still gotta worry about highly reg being in a highly regulated industry.
Right. Let me though, ask you again, you, you made this move into this hybrid environment. Do you envision going total cloud, or will you always, you know, I look, a a lot of financial institutions still also have mainframes, right?
Yeah. And you're not gonna move, you know, to walk away from your mainframe. Yeah.
That's a statement, right? That, that that's, that's not easy. Yeah.
com and their Textron, they have, you know, they maintain a sy a system of record and a system of engagement, right? Yeah. Record being usually a mainframe at a data center somewhere, and engagement may be up in the cloud, right?
Is that how you guys envision your go forward? Yeah. I mean, the way I say is that, never say never, okay.
But at the same time, as an organization, and depending upon how you are set up, you build the strategy and the strategy as the time passes because of the other factors. You know, you may plan and say, okay, I want to move into cloud, you know, but as you see the opportunity, you could probably shift and then get rid of the on-prem, or you think that Yes, probably in the long-term strategy, I have the midterm milestone to determine whether I can get rid of, or I still need to maintain. So the ag organizations build their strategy depending on the size of organization, depending on the customers they are serving, depending on the partners they do have, they make the strategy in general.
There are a lot of organization they can get rid of this, um, on-prem setup just because the way they are set up and the customers they are serving in probably our case. And there are some similar cases, probably it might be a time to see, you know, in next couple of years or few years to see that, oh, now we have moved enough. Probably it's time to, you know, get completely, uh, other side of the bridge.
So that, that's kind of strategy, you know, as, as, as we go. So, so short answer is we are yet to see that, how the strategy evolves to, you know, get to the fully cloud that we stay on to hybrid mode. Yeah.
And just to add to like what we just said, I think, which was very well said, um, I think companies also have to make sure that they're doing it in a very sustainable manner, right? So, um, I think we just alluded a little bit, uh, on that as well, that it should not be like a big bank sort of like move to cloud. Uh, of course, I mean, it's a learning opportunity for a larger institutions, right?
I mean, where, uh, they might have like thousands and thousands of applications running on-prem. Uh, they have a few applications running in cloud. Now there are challenges that show up, right?
I mean, you might have a data setting on-prem, there might be regulations right around how you store the data. Uh, you might have to be in compliance with, with your data, right? So, uh, sometimes you might want to move the compute to cloud, uh, to the cloud, but then you might have, uh, some restrictions that you cannot move the data to cloud.
Uh, there might be some, uh, innovation that might have to be done in order to be able to move the data to cloud. Uh, but I think that's probably, uh, uh, kind of like a, uh, uh, an approach that company can take where they can take some steps in a phased approach before they finally land in, in a, in a, in a state where they can declare that they're fully running into the cloud. But I think that that should be probably the mantra for any company.
I mean, that could be the north go north star for the company, but again, there are various factors that can, that could influence that journey, uh, towards the North Star. Agreed. Yeah, agreed.
You know, another phenomenon, so I hybrid to me was always obvious. Yeah. You know, what wasn't obvious to me, multi-cloud, right?
So do you see an institution like yours going multi-cloud using more than one hyperscaler cloud provider? Yeah. Maybe I can just quickly, uh, uh, throw some light on that.
So definitely there are like a lot of different cloud providers, public cloud provider, and every cloud provider has their own sort of like, niche, right? Yep. Uh, you can look at my Microsoft Azure, uh, Google Cloud, Amazon Web Services, uh, all of these like big cloud providers, I think, uh, they, they all are innovating.
Um, they are sort of equally good. Uh, but some cloud providers have services that pro that pro that probably might be like more niche and more sort of like cater to a certain sort of like, um, uh, industry, right? So, um, I think in general, companies are sort of like investing, uh, in one major crowd provider, but also being at the same time cautious about the fact that, uh, there has to be some sort of like a risk management approach that has to take, well, You don't want to be locked In.
Yeah, you don't wanna worry locked in. But at the same time, uh, it's also, uh, conversation around like the cost management. Uh, you don't wanna put all your eggs in one basket.
Yeah, that is true. At the same time, if you divest too much, then uh, you are also kind of like, uh, not reaping the full benefit of like having a cost, sort of like optimization by putting more workload in, in one single cloud provider, and then kind of like being able to negotiate, uh, a price point that serves you well, right? So, uh, it kind of like, it can go either way, but then of course, I mean, you have to have a balanced approach as to like how much you diversify, but at the same time how much you concentrate and then kinda like get the cost optimization.
Yeah. To add to, among what he said, like if you look at probably no organization, which is using a service as a SaaS is insulated from multiple cloud, you know, um, uh, environment, probably directly running its own workload or probably via a service provider, there could be likelihood that you are using underneath, right? But the important point is that if, depending upon the size of the company, the customer, it is serving the geographic location and pricing point, the organization chooses to be, you know, into the multi-cloud versus single cloud now, and then the on-prem, right?
So if you look at the landscape, they are, you know, in the multi-cloud strategy probably is better in certain cases when you are like global company and then you are serving the, you know, different type of, um, customers and services and then, you know, um, the kind of, uh, product you are offering. And in that case, sometimes you may, you may have, we not have a choice other than going to multi-cloud. So those factors come in.
But if you are like a small organization, probably you may opt in to have probably two providers, and probably you are happy with that. And so you can negotiate the pricing and do other things. But at the same time, if you are, say if you're going to a CF aspect reason, and you do not have that cloud provider capability, you are bound to have use another cloud provider, which is already there because you want to serve your customers.
So those factors kick in. But certainly from the, from the financial institution or you know, the global companies which are serving the customer, they probably make those, uh, smart choices depending upon their business strategy, uh, in global landscape. I love it.
Gentlemen. I apologize. We've got a lot of background noise.
Hopefully it's coming out well in MyPhone. Um, last subject, ai, how's that playing into this? I think no company is shielded from ai.
Uh, I think that's, given that in order to stay ahead, uh, companies have to make investments into ai, but again, it at the same time, financial institution, uh, banking and a lot of different industries have to be very cautious about like how they use AI in a responsible manner. I think one of the biggest challenges, uh, especially when it, when, when, like, when it, when it relates to like financial matters, right? Um, AI can sometimes make a decision that may not, uh, be very well in kind of like aligned with regulators, right?
So in general, um, AI has a lot of potential, but I think there is still, uh, some work that needs to be done to make sure that AI is used in a very, very responsible manner. Uh, there are use cases where, uh, AI can be easily used, right? I mean, uh, we have seen financial institution investing like in deploying AI in call center applications just to help agents serve better, uh, for the customer.
But I think what we have seen, like in the industry in general, is AI being adopted in a core sort of like processing is still sort of like something that has to be, uh, uh, has to be, well, kind of like, um, uh, there has, I mean, it requires some sort of like investigation as to how it can be incorporated in a responsible manner. Because I mean, anything that you do has to be explainable, right? And sometimes the challenge with AI is that it, it's not very conducive to explain like how decisions were made, like, uh, by the ai Yeah.
For certain industry it might be simpler, you know, if you go to manufacturing, it might be simpler because you are doing mechanical in most of the cases. So it's a simple, it's a repeatable process, you know, you're not making a lot of decisions there. But if you go to the healthcare or, you know, uh, into the spaces where humanists are involved, you know, decisions are involved, financials are involved.
I think it's, it's, it's very, you know, the area where it's not easy to Not in the highly regulated Can go move forward with that Highly regulated. Yeah, Exactly. So, agreed, those considerations, you know, are you always there?
But as AI matures, who knows, you know, in next few years things may change differently. You know, what if the public, if your customers demand that sort of functionality, you're not gonna have a choice. That is true.
I mean that, I mean, customer comes first. It's a Customer led business. Yes.
Yes. Yep. Anyway.
Hey guys, thank you for coming on You for having us today. You get swamp up. Thank you.
Yeah. Thank you so much. Yeah.
All right. VJ Oman Ahman here on Text Drunk tv. We're gonna take a break.
We'll be back in a moment. Hey everyone, we're back here. Hey, this is our last interview for Swamp Up 2025.
Woo. I think I am gonna wear my jfr hat. How's that?
Oh, you look beautiful. All right. I won't mess my hair up.
Yeah. Um, so let me introduce you to our guest for our last interview today. They're two folks from Adobe.
On my far left we have Shiba, Shiba, RA. Thank you. We call 'em Shibu.
Shibu. Yeah. I go by Shibu.
Yep. Shibu is here. And to my immediate left, we have Vishal Reyna.
Yes, sir. Right. And we're just gonna call you Vishal.
Yes, sir. No shortened names there, gentlemen. Welcome.
And thank you for being our last guest here on Swamp Up 2025. Before we go further, I mentioned you both with Adobe. Mm-hmm.
And we, and as we were talking offline, we actually did a whole, what I considered a great series of interview with the Adobe security team around security and ai and how Adobe kind of eats their own dog food, if you will, or drinks their own champagne around security and to secure the products because all of us have Adobe accounts and we don't want that information getting hacked. Um, and we did a series of articles on it, you know, it was a whole treatment. But you guys, you know those fellas from the security Yes.
But you're on a different team. Correct. Tell us about your team.
So I'll introduce our team. Um, we are the platforming group at Adobe. So when any developer wants to build something and ship it to their customers in one way or the other, we are providing the capability to those developers to make it happen.
And, um, we, the pa the organization is named developer platforms, uh, and we partner very closely with Security organization, uh, led by Brian and Sure. Chlorine and others who joined you in the past. And, uh, we work with them closely and, um, yeah, that's, that's our mandate, help our developer ship software faster to our customers, better software.
So when you say developer platform, is it like a true IDP At this? Yes, at this. com.
Mm-hmm. org group. Awesome.
Um, so I know a little bit about Enough to get in trouble about IDP. Is the IDP sort of like based on like a backstage type of Yes. Thing, and is it, do you want to talk about that or, I know it's not really part of what we were gonna talk here, but I'm curious.
I can talk about it. I think, um, in fact, Adobe was one of the first companies who worked with the industry, and we actually put out a lot of, back in 2022 when IDP as a term was picking up. And yeah, go and look at, uh, the different journals, I'm sure including some of yours, you would find that Adobe had made contribution.
So we were the first few adopters of the IDP concept, and we implemented at our company, we built it on top of open source software like, uh, backstage, which you talked about. That is the portal that our developers use. But it is powered by a lot of the CNCF community open source software.
Um, we are a big consumer of, uh, Argo. Yes. Uh, we are a big consumer of Kubernetes, and there are many more, Well, the, all the backstage stuff has Kubernetes at the heart mm-hmm.
And then of course the Argo GI Ops. Yeah. And all of this is now, you know.
Yeah. It's, so I'm proud to say that we are probably one of the biggest, uh, installs of, uh, GitHub software in the industry. I think we really set really big scale.
We have really collaborated, uh, very closely with the community to scale the infrastructure. In fact, there is A-C-N-C-F blog that we have published on how we have scaled, uh, Argo setup for ourselves to meet the needs where the, the off the shelf, the open source software doesn't meet our needs. Uh, and I'll probably send you the link and you feel free to forward Please do.
Well, May not be what we wanted to talk about today, but Q con is coming Absolutely right. Q con cloud native con will be, uh, I guess November Yes. In Atlanta.
And of course we'll be there live the whole time. Um, so, and that'll be both for our cloud native now and platform engineering sites. So maybe we'll, we'll talk more about that.
I need to shift though, 'cause we are here at For J Rog Jfr and talk about what you're doing at Swamp Up. I let that, uh, so, uh, We, we did a database migration. Um, and as you know, most of the database migrations need downtime.
We were able to accomplish a zero downtime for our end users, and we wanted to come in here and share the best practices with our peers. I thought because we don't have AI in our subject or presentation, we are not going to get any audience. Turned out that room was full and we got a lot of exci engagement right up to the point where we were meeting co couple of industry colleagues here.
The goal was like how, how we came up with an eight hour downtime and that got shot down, and how did we pivot in less than 28 days and made a zero downtime using cloud architecture, um, to accomplish a, and many of historical Jfr Artifactory users who are on MySQL or Microsoft, um, SQO will need to do this to come to the Postgres. And we shared our best practices, both in terms of how we solve it with technology and also best practices in terms of processes and people and communication. And at the end, how we accomplish that whole, uh, zero downtime.
That's a great case study, a great case study. Let me ask a question just between us. Yeah.
Um, is the fact that it didn't have AI in it, a reason why there were so many people in the group? I Don't know. Maybe Have we all maybe AI doubt a little bit?
Absolutely. You know, and I'm not downplaying AI or badmouthing ai, but it's refreshing to have a discussion that's not necessarily leading with ai. Um, you mentioned Postgres, right?
Yeah. Now Postgres is sort of one of the best kept secrets of it is not a secret, but, you know, it doesn't get the de the, the what it deserves, the acclaim it deserves. It really has become an engine, you know, and it started, I'm not, again, I'm not taking sides, but when my, when Oracle bought my sequel mm-hmm.
It set Postgres on fire. Fire. Yep.
Yeah. And, and since then, you know, you have, there are several different Postgres, uh, providers now in versions and some pure open source, some open core mm-hmm. What have you.
But it really has become sort of the database or record, if you will Correct. For, for a lot of these large, large, you know, hyperscale kind of environments. So, you know, that's something that, um, you know, I think a lot of our audience realizes it, but there it's worth repeating.
It's worth saying out loud. Yeah. What I can attest is the performance issues we saw prior years when we were running MySQL with lot of optimization hacks and everything else since we did the migration platform just scaled up and has been performing awesomely and we were apprehensive, like, is it just one of those things that we have to do it with no gains, but we are seeing real benefits of this migration on top of it.
Those of you who are running Artifactory do consider using direct downloads. It just is cherry on the, uh, cake and will give you more performance. Really.
Yeah. Direct downloads from artifact. Yeah.
Just to my 2 cents on progress, um, Means it has become, um, such a good database and persistent choice that in the recent years, at least in the last five years, anything that we have that my team has built in-house has lean to Postgres as the persistent solution. So the developers who are on the ground writing a lot of code day in and day out, it's their choice to do relational databases and persistence. So plus one to what you said, Postgres has become that thing where, where probably Oracle of the last decade or, uh, so like, but but it has become that like Database.
No, it is, it is. So I've been in this world a long time. My SQL was the standard Yeah, yeah.
In SQL database because, you know, you weren't locked into a vendor and it was, you had the community developing it in essence. And, and maybe it was, it was probably still a, a small handful of people who were contributing code, but you had the community driving the, the, the development visions and, you know, featured set request and, and quite frankly, you know, Martin Kins and the people who were running it back then. Yeah.
It was, it was a great open source success start. Yep. Yeah.
So for any project beyond the con core contributors, it's the ecosystem around it. Yes. Like the different use cases.
Oh, I, I, Hey, just a conversation just between us, like, Hey, I'm trying to build this app in this scale. Go use Postgres. Here's what you should do.
Yep. So these things which we just take for granted, basically make the, somebody wrote a blog post or we came in and spoke about its success in just specific to artifact. These things do add up and Absolutely Do, or as technology more successful.
Now you look at up, and I've been to a lot of Swamp up in many ways. This is the company and the conference that Artifactory built. Yes.
Mm-hmm. Right? That was the acorn that there's Oak Tree mm-hmm.
Grew from. But there's more to Jfr here. There's more to swamp up than just Artifactory.
We saw today, you know, this week we, we saw, uh, uh, uh, JFR fly the, the agent AI repository. We saw the AI catalog. We saw a lot.
Yeah. How does that fit in with your mission at Adobe and your, I maintaining your, uh, IDPs and, and your developers? Are they using these new tools yet, or you think they'll want to use these new tools?
Uh, go ahead. Going off to you. I, so, Um, we just started, uh, we were locked in Origins because of the database migrations.
We just started opening up. We are current and now we are in a position to start exploring and getting benefits from the machine learning repos coming in, or the catalog. And certainly the agent take workflows.
We, we are going to go in and see where all working with Jfr, uh, our partners, see how we can tap into these new offerings that have come in. And let's not forget about the SBO m uh, AppSec, uh, offering that has come too. So we, we are going to go and explore.
Please. No, we are very interested. And so I think, um, there are two sides to it.
One is, as a platform group, whatever we are offering our customers, we want to make those capabilities more urgent tech. So we, between Vishal and myself and our teams, we need to build more agents. And the capabilities that kind of were, uh, published in this year's sw up some of that.
We are very interested into, um, looking at and see how that can help. Uh, the second side of it is, as our product teams are taking that agent journey and bringing in agent features into the products product like Photoshop, illustrator and several others, they need a platform where they can run agents. So we are solving that agent platform problem as well as we are building agents for ourselves, which would let us kind of expose our capabilities back to, so on both sides, the, the, the, um, the announcement that came from jfr, the excites, uh, the Excite Us, be it AI catalog or any other feature, I feel that can really help us.
Um, so we will go back and start looking at them and see how we can factor them into our, um, our use cases. I love it. You know, um, people don't realize about Adobe.
You know, Adobe is, look, it's kind of a Blue blood, a royalty name. In, in the software world, we all came up using Adobe products, whether it's for video or graphics or PDF or what have you. But I don't know how many people out here really realize Adobe is a company that's very transparent about how they build, how they secure what they do internally, like their, their own best customer in some ways, right?
We we're gonna show you what we think are best practices, and you should feel free then to use them, right? We, we've already paid the idiot tax in some respect, learning these things, and we're trying to save you from paying that tax going forward. I don't think they get enough credit.
I mean, you make great Photoshop, you make great Acrobat, but really being a good, a good community member Yeah. Right. In the software industry is, is commendable.
And, and I, you know, congratulations to you not just that you two, you but the whole organization. Yeah, yeah. For the, for the way you do it.
It's, it's really, I wish more companies were like that. Absolutely. No, I think, uh, this has been a practice in the company since long time before we began our stint here.
And we are just continuing that, right? So, um, our leaders tell us, like, whatever we learn, it's our responsibility to go and pass on to the community, and we are doing it. Vishal and his team did extremely great job of this really difficult migration.
I want to thank him and his team and all of the people who really did the work on the ground, and his team is coming in and sharing all of that with the community. And it, it, there's a lot of interest. I'm sure other teams are going to do the same.
And, uh, this is going to have A lot you've well received. Yeah. Where's, where's, where's the next conference you're presenting at?
I haven't decided yet, but will identify something soon. Yeah. Our group is, um, going to CubeCon.
We have some presentation. We Will be, we'll be a CubeCon going live. com site.
Yeah. To find out more what you're doing with Platform and how you're building it out. Yeah.
Because this is, you know, DevOps, cloud native platform engineering. These are all just different pieces of today's software factory, including ai. You know, AI plays on all of them.
Yeah. It, it, it just basically, uh, compressing, uh, I was talking to one of the, uh, conference attendees. What AI or generated AI in particular has done.
It, has flattened the learning curve, like getting a particular sector or a piece of technology or coding for that matter, where, which is what Shibu and I are closest to the getting a prompt in and start learning about, or basically porting a technology which was written on one technology to another technology. It's not completely solved, but it certainly is easier. You can understand legacy codes better.
All of these have intangible, uh, benefits, and that's why we'll see more software coming faster at us, which basically puts stress on all the underlying plumbing or the CICD supply chain. That's where the, the platforms had to come up to basically, um, deal with the new throughput of, um, innovation coming in and making sure that each of the right customers. Absolutely.
Gentlemen, I want to thank you. Thank you, Micha. Pleasure.
Shibu. Thank you. We're gonna wrap up our, our Swamp up coverage.
I hope you've enjoyed it. We will be back. Well, I guess we'll be back tomorrow with more text on gang, just not out here in beautiful Napa.
But until then, this is Alan Shimel on behalf of Jay Frog and all of our guests, thank you for watching and staying with us, and, uh, we hope it was valuable to you. We'll talk soon. Bye-bye.
AI is the hottest topic in tech right now, evolving dramatically over the previous eight seasons of this podcast. We're kicking off season nine of utilizing Tech with a discussion of the state of the art of Ag agentic AI with Frederick Van Herrin, guy Coer, and myself, Steven Foskett. Learn about a agentic AI and learn about season nine of utilizing tech in this episode.
Welcome to Utilizing Tech, the podcast about emerging technology from Tech Field Day part of the Futurum Group. This brand new season focuses on practical applications for AI and specifically agentic AI and related technologies. I'm your host, Stephen Foskett, organizer of the Tech Field Day event series, including our AI Field Day event.
And joining me for this season is a familiar face and a new one. Before we begin, let's go ahead and meet them. Well, thanks for having me.
Um, I'm Frederick Vann, the founder of ens. Uh, we are a consultancy and services organization, helping customers accelerate their AI journey. And you can find me on LinkedIn as Frederick v Herrin.
Yeah, I'm Guy Carer. I'm, uh, an analyst at Futurum Group. I'm also the chief analyst for another futurum group subsidiary Visible Impact.
And, uh, we help vendors, uh, articulate and, and, and bring to market, um, their, uh, offerings, including AI offerings. But I also have a background in market research and product management, product marketing, uh, including ai. Back before it was ai, And I'm, uh, Stephen Foskett, as I mentioned.
Uh, this is in fact, uh, the ninth season of utilizing tech, uh, of those nine seasons by my Count six focused on, uh, and not including this one of the eight seasons previous six focused on AI and various sorts. Uh, last season we talked about AI at the Edge. Before that, we talked about AI data infrastructure.
Um, and, and as guy said, we actually started Frederick, you and I, uh, talking about AI before, uh, chat GPT was released. In fact, we finished our first three seasons before chat before AI became the topic that it is today. I mean, it's safe to say that as far as technology goes, AI is the most important thing in the world.
Um, that sounded like a, a one of those, uh, uh, movie openings, right? AI is the most important thing in The world. Uh, do you concur?
Is AI the biggest topic? I don't wanna say the most important, but the biggest topic, Frederick? I I think so.
I think a lot of the innovation, uh, that is happening today is, is heavily focused on ai, maybe a little bit too much sometime. That's why people sometimes are kind of worried that AI is maybe a little bit too much hype as opposed to practical. But I definitely believe that a lot of the funding and a lot of the innovation today is going towards that direction.
And if you, you know, you and I, we have talked so long about ai. We have the seen the traditional ai, we have seen the generative ai, and now it's agen ai. I mean, to a certain degree, what's in a word, right?
We can, we can define a little bit about agentic ai, but I definitely believe that AI is really gonna stay a, a hot topic. Uh, the problem of course is AI is a generic word, right? So we, we kind of, as podcasters just kind of our, our responsibility to kind of narrow down and, and, and define things.
Yeah, I think that, uh, actually your first choice of words, Stephen, were the right ones important, important in the sense, maybe not of market size or of current impact, although everyone seems to have encountered it at this point. Um, I use the word everyone loosely, but in terms of, uh, its ability to transform for the good and for the bad, to make things better, to make things worse, and to do that, in either case, extremely rapidly, uh, I don't think we've ever seen anything like it. So I, I think important is, is actually the right word.
Even if, uh, we rightly should put it in its place, explain what it is and what it isn't. There's a lot of misconceptions about what it is and all of that. I don't think there's any more, uh, effective conversation to have right now, just pretty much across the technology and business landscape than the AI conversation.
So, if that's not important, I don't know what is, You know, my litmus test for the importance of things is, uh, and, and no offense to grandmothers here, but, uh, you know, uh, have, have the grandmothers of the world heard about it, and that is certainly the case. Uh, well, my grandmother is not with us anymore, but my mother-in-law asked me about AI and chat GPT the other day. Uh, my father has said, sounds like this AI thing is gonna be replacing jobs.
Um, you know, everyone I talk to, if they find out that I'm in tech, you know, they, they wanna know what does this really mean? And I am always sounding a cautious note for them. You know, I don't think that AI is not important far from it, but I feel like at this point, we are still in the new toy phase of ai rather than the, let's get some work done here.
Phase, um, um, you know, Frederick, uh, you know, what do you, what do you think, uh, what is, what would you say if a non-tech person came to you and said, you know, what is this, what is this ai, what is this agentic ai? Maybe they've heard of AG Agentic. What does that mean?
Right. So, first of all, I mean, when there, I guess there are two questions. There is, when, when people ask me about AI in general, you know, I, I try to explain it as it augments our capabilities.
I mean, you bring, you brought up your grandfather. My mother is 90 years old, and she uses chat, GPT, and I didn't teach her chat, G gt, she's using it for translation and for writing, you know, documents. So I think we're, we're entering a phase where when I explain AI to somebody, there's a low hanging fruit, right?
It's the, the, the, the grammar, the translation, looking up things, you know, instead of Googling now nowadays it's chat chatt. So that's, that's a generic term as far as agen ai, uh, the way I explain it to people is, first of all, if they're familiar with chat GPT, then I will refer to it, you know, this is a type of generative ai. And I will say that Agen AI does two things, and one, the first thing it does is it introduces the concept of an agent.
And an agent is like translation or sending an email. And then the second component that, that makes agen ai, agen AI is the reasoning. And so the way I explain that to people is, is that agen AI is, is similar to, um, kind of thinking before saying something, right?
The traditional large language models, generative AI spits out the first thing that comes to mind and, and sends it to the users. Agentic AI is where there's a little bit more reasoning just like us humans. So in a nutshell, agentic ai, the concept of agents or plugins, if you wish.
And then the second piece is the fact that there's more reasoning going on than traditional generative AI Reasoning. It's an interesting choice of words. The usual word that I stress when people ask me about AI and how to use it is simulation.
AI is not intelligent despite the name. It's a simulation of intelligence, generative AI in particular. And I, I do mention that mostly I'm talking about generative ai since that's anywhere between 90 and 99% of the attention right now.
Anyway, generative AI in particular is designed to simulate reasoning or simulate, um, speech simulate. Well, it can simulate a lot of strings, it can add a lot of strings to a lot of other strings. So it can simulate, uh, a DNA strand, for example, based on input.
And I think that's a really important distinction to make. It's the source of hallucinations, it's the source of, um, AI's general stupidity. But what AI does do in, for, in terms of simulation, is extremely useful and helpful, especially as long as you keep that in mind.
So, I dunno if I'd use the word reasoning for agentic ai. Um, I mean, the idea of agency is just that, uh, it's like you said, it's something that can go do things. And, um, an AI agent that can go and do things without, um, having specific algorithms or sets of instructions, um, that can more or less with permission prompt itself to send that email based on certain conditions.
And then really importantly, uh, do what amounts to learning or retraining as it goes, so it can do it better. I think that's where I land on in terms of agentic ai. Yeah, definitely.
I mean, we, we can call it whatever we want, right? Reasoning, simulation, uh, or other terminology. The bottom line is, is, is that there is data, there is, there is, there is, um, background information and historical data, and that historical data is being manipulated by math, right?
Um, the reason why in a lot of the technical industry, the word reason is being used. It's because it's referring to the fact that it's, that the first answer the system comes up with is not necessarily the right answer, right? So you can, you can call it simulation or iterative approach if you want.
The idea is, is that just like with us humans, is that the first answer is not necessarily the right answer. It could be, but it doesn't necessarily mean it's the right thing from a technology standpoint. It basically means there is a lot more going on when you ask the system an agent AI system, a question, while you could ask a generative AI system, exactly the same question, the same, the agentic AI will do a lot more in the background than a generative ai.
And it's, it's very difficult to explain it to people, right? So because people even does, don't necessarily understand to word reasoning or simulation, right? It's in the end, it's still a machine, it's not a human, right?
And nobody's trying to say that generative, generative ai, or I should say agentic AI is a replacement for a human, right? Yeah. And, and I think that that's the, the key there is that, um, well, I don't wanna get too philoso philosophical here on episode one, but I do think that you could make a, an argument could be made that at some point, it doesn't matter whether it's thinking or not, if the result is the result that a thinking machine would come up with.
I think that also, it is very, very true to say that it is not thinking the way that we would consider thinking it is statistical, but that the combination of, uh, iteration, as Frederick said, and, um, selective use of data can result in something that is the same effect as an intelligent system, even if it's not one of us. Yeah. And, and Agen does take us a little bit out of the bind that generative leads us into in terms of that simulation idea.
Uh, the way I usually put it is that the design point for generative AI is a simulation. It's, it's not truth. So this is, you know, commonly well known within ai, and I think a lot of the general public is picking up on this, that, uh, the, the results produced by AI can be just dead wrong.
Um, the problem is that because simulation is the design point, it's appears true, it appears equally true. Um, and, and to Frederick's point, and to your point, um, when you're thinking about agent ai, you're thinking about a process. You're thinking about, um, some automated, uh, or semi-automated process, even if, even if it looks just like the same chat bot that generative AI is, is, is behind, um, that process is designed, it's designed by humans, it can be adapted to some degree by the agent itself.
Um, and so the result is that, uh, you, you're, you're missing some of that simulative character. So I don't think that's philosoph philosophizing at all. Um, I think, um, it, it's a useful corrective for us to understand what's going on, uh, right now with AI and what it's, what its promise is.
I just worry that even the creators of these, um, agents, um, are fooled themselves into, uh, into what they're capable of and what they're doing. Well, hopefully that won't be happening here. Um, I think that, uh, we've got some, some folks here who really do understand, you know, what's really going on.
Um, but you know, Frederick mentioned another aspect as well of ag agentic ai. That's, I think, equally important, and that is the ability to, in a way, to perform work. And of course, it has to have, uh, context, it has to have a chain of thought, uh, sort of an iterative re reasoning process to analyze that data and decide, you know, not to, I, I am anthropomorphizing to, uh, Output A, an action, and then it has to have the ability to take that action.
And that has led to a need for standard frameworks to allow these AI agents to interact with each other. And one of the ones that we're hearing a lot about, and I think we're gonna hear a lot about this season, is what's called MCP or Model Context Protocol. Um, which of you would like to explain what a, what MCP is?
Well, Frederick's been on the firing line first, so I'll go first, then he will correct me if that's okay. Um, because I think of it as pretty relatively simple. MCP is a way for, um, AI based applications or AI agents, uh, to seek context, um, to request context, and to receive it.
Um, largely it can be from other, you know, ais or AI engines. Um, and it can do this using a relatively standard a p iLike interface. So it can be programmed in, or it can be, it can, uh, uh, discover these, uh, resources, you know, in its system.
And that is what allows these, uh, systems of AI, including agen AI to be more effective into, to work together. Yeah, exactly. It's, uh, it's, you know, agent AI is, as I mentioned just about agents.
You have different agents. A lot of organizations are deploying and delivering agents that consumers can pull together. And an MCP server has the ability to pull all these agents together and generate the content.
I mean, it's, it's important to note that there's, there's a few versions of the MCP server. You know, some are task driven, others have a, a different, a different approach. But in the end, you can look at it as a, as a way to standardize, right?
You, you, you have a bunch of agents that are very capable. Um, you, you have the ability to daisy chain those agents, right? And so you can build very, and when I say you, I mean, you as a non-technical person or consumer can build a reasonable, workable, uh, application with MCP servers.
It has to be said that MCP, there are probably like two or three different server types today. Um, it's evolving really quickly, but you can see how many organizations are jumping on board and delivering capabilities, right? So for example, Docker desktop is, uh, is an application install on your desktop, which comes with, with MCP servers ready to go.
Uh, and can Steven, can I add a little, a little con uh, not context a little bit to, to this, the importance of MCP, of course, M CCP being an open standard. So you knowis, uh, to just give a general label to all this stuff. Ais have interacted with each other before, programmatically before, uh, less than a year ago is when the first MCP specification was published.
I mean, this thing has grown super rapidly. Um, but here's what I wanted to say. The import of something like MCP cannot be overstated.
If you think of just a regular generative ai, um, uh, model, it's taking a string of things and outputting a string of things that should follow that string of things. Usually the string of things is words, and it follows with more words. So when you are doing good prompt engineering, you're adding all this context and all this stuff to make that input of words and attachments.
They're all, it's all, you know, a string of things to generate more things. The more you provide, the more complete, the more on point it all is, the better your output. That's generative ai.
Now, imagine that the AI did not have to rely on whatever you happen to put in, but could go out and seek other contexts. That's what MCP allows. That is critical for an AI to be agentic and not just generative.
Yeah. And you know, ultimately, like, as, as Frederick was saying, I think the, the thing about MCP that is exciting is to me, the way that it encapsulates this context in a way that is standardized. In fact, I could see MCP being leveraged by non gen AI technologies as well, because it is very much, it, it just makes a lot of sense.
Those of us who've been using, for example, process automation technologies for, for years now, or this sort of, if this, then that type technologies have encountered the problems of, um, basically AI rot or API rot, um, uh, making sure that as things are upgraded, that they continue to work. Um, figuring out how to pass data from, um, I, I hate to use the word agent, but from agent to agent, from component to component. An MCP actually, um, takes a lot of that work.
And in the context of generative ai moves it forward into a extensible framework. Now, that's exciting beyond ai, but in the context of ai, it's ex especially exciting because what it means is that you can basically give, uh, a package a payload to the next, uh, worker in the chain, the next ai a, you know, agent in the chain and say, here, do something with this. And unlike conventional APIs that are somewhat brittle and fragile, uh, it can be a lot more robust because it uses generative ai.
At least that's how it's been to me. Um, what do you think of that, Frederick? Yeah, that's exactly right.
I mean, uh, i, I know you don't like the word agent, but the agent in an agentic AI environment doesn't have to be AI driven. It can be something very, very simple. Um, and to your point, you can have agents that are non-AI driven, but by, by enabling it with an MCP server, you end up with a, an application that can do a lot more than the components individually by himself.
I, I'm not sure if we actually defined cp, you know, it stands for model context protocol, uh, in case people wanna look it up. Um, but you're absolutely right. I mean, I, I think what it, what what Agen does, what Gen AI does for the community and people out there, it, it enables people to do a lot more.
And we see that, right? People that we're asking for basic applications in the past are now asking for similar applications, or at least similar functionality, but then driven by an MCP server. And it's, it's, it's fascinating how easy it is to set it up, right?
And, and we have said it before, but the, the, the speed of innovation is incredible. Um, certainly combined with vibe coding, I mean, who needs an engineer to build a prototype? I'm not talking about production, but prototype wise, it's, it's an incredible time to, to be around.
I do think that we need engineers, and I, I know you, you're not being an absolutist about this, Frederick not at all. Um, but it's that, it's that whole idea that when you're using generative ai, for example, it really helps to have expertise in the area that you are working on, um, so that you can utilize what comes out, um, for good and not, and recognize the part that might be problematic. And in the same way, um, I I, not for nothing.
I think, uh, you know, if if there's such a thing as elegant code, there's probably such a thing as elegance in a vibe code. Well, sure. I, I could, uh, I, I'm with you on that.
I, I actually am concerned that as people are vibe coding more, they may mistake vibes for quality and think that they actually have developed, not a prototype, but a fin, but a finished product. That's right. That doesn't sound great.
Um, but that being said, I hope that, uh, I hope that that won't happen. And I am actually, um, you know, fairly optimistic about a lot of the work that's been happening. I mean, if you look at what MCP does, it constrains the context that, um, the next link in the chain can work with.
You look at some of the other, um, guardrail type, uh, things, uh, that, that are being put up around, um, AI systems. I think that that's all good, because a lot of the problems that we've been having with ai, um, you know, I mean, certainly my biggest problem with using AI is that it's non-deterministic. Um, you know, I can throw, uh, a set of data at Gemini and get this output, and then I can throw it this same set of data at Gemini and get a completely different output.
And that's challenging for me as a, as a developer. I think that there's, um, many ways in which we can kind of address that with additional guardrails and boundaries and context setting that can hopefully help kind of constrain some of that randomness. But at the same time, um, I do think that it's exciting where this stuff can go.
Um, again, you know, one of the, the words that I used before was brittle. I have found, um, agentic systems prior to AI to be extremely brittle, to the point that I became very frustrated in a lot of these process automation technologies, because essentially those links in the chain would be changed without notice somewhere. And so, even though it was deterministic, it always gave the same output.
Um, it sure didn't once they changed the API on me. And, you know, I actually, in this, actually, these days, I'm, I'm using, uh, generative AI as sort of an A API super glue already, uh, where I'll throw it some JSON from something that I know sometimes is a little bit iffy and say, give me a js ON output from this JSON input. And, and the result is usually a lot more sturdy and reliable than, than anything else.
And that's what I'm hoping that we'll see with Agen Paths agent to agent and MCP. Yeah, so we, we talked about two different sides of Agen ai. One, one is a developer site, which is, which is an interesting piece by itself.
But, but I, I have to reiterate, what I always say is, is AI in general, whatever it is, is augment our capabilities not to replace. So you'll never hear me say that, you know, vibe coding replaces a, a developer. Um, when I use Vibe Coding, if I even can call it like that, it's the equivalent of me buying a book and looking up for a reference.
You know, an API call now I go to Vibe Coding and, and Pro, and it'll provide me with some, some reasonable, um, guidance around API calls. And then, and then there's the flip side on, on people consuming Agen ai, right? I mean, I, I think another, another thing I, I have a problem with, with people kind of assuming that whatever Agen AI spits out that it has to be exactly, uh, what you expect.
I mean, it's, it's having different opinions. It's not bad, right? It's the same data, different opinions.
That's, that's what we all do, right? That's why we have this conversation. We all have the same data or similar data, but we might have a different, different opinion.
I think it's important to, to note that agen AI by itself, um, might give you different answers and, and evolves, right? I mean, another thing which we haven't talked about agen ai, but RAG is really important in agen ai. So RAG is the, the retrieve, augment generate, which is the, the ability to inject almost in real time information and change the behavior of an AI system, right?
So, so the expectation is, is that the system should behave differently if you ask the same question over and over and over. Yeah. I, I'm looking forward to, to learning how, um, practitioners and, and, and, you know, I suppose vendors as well are, um, uh, putting, putting borders around or, or I, I guess identifying scenarios is really what I'm really thinking of.
That here's a good scenario for this type of AI work. Here's a good scenario to avoid. And I don't mean, I, I guess the reason I eventually avoided the word scenarios is I'm talking about sort of not, uh, oh, this is really great for computer vision.
This is really not that, not that kind of scenario. I mean, scenarios where the type of work, the type of environment, uh, the type of decision making required, um, some will be obvious, uh, regardless of the application for AgTech or for generative or for both, and some will be obvious ones to avoid. I think that that kind, everyone's throwing AI at everything all the time right now in a certain sense.
And that's makes sense when no one is really sure exactly, uh, where it's going to be productive and we're not productive. But I, I, I wonder if, if there are, there are practitioners out there right now who have enough experience at this point to be able to say, no, we don't have the right personnel, or we don't, this is not useful for this particular type of work. I'd, I'd like to find that out.
So as we look forward to the next, uh, you know, uh, eight episodes of this season, I wanna take a moment here before the end to ask each of you, you know, what, what would be your ideal, uh, outcome for this? What would you like to learn? And who would you like to talk to, uh, over the next, uh, coming weeks to learn that, to reach that, um, guy you wanna, you wanna kick us off?
What would you like to learn this season? I'd like to learn if, um, twofold, if there are, um, productivity measures that are, that are, uh, lighting people on fire. I've been maintaining from the beginning that productivity is a secondary benefit of ai, that it's just, um, it helps you or humans or certain types of work to be more reliable because you can just get started instantly.
No writer's block. Um, so it's more reliable and that you can fit more review cycles in, so you can come up with higher quality work, and that productivity flows from that. But I do think that productivity is why everyone's in it, and I wanna understand, um, what people are seeing.
And I think there's less productivity out there than, uh, advertised, but people are still pursuing it. So why they're doing that, I, I think that there are lots of benefits that don't necessarily come down to dollars and cents or ROI or that sort of thing. And, uh, I, I would love to help understand and shape the discussion around that.
Richard Frederick. Yeah, I think, I mean, the engineer in me says, I wanna learn about innovation, right? What do, what don't I know and what's around the corner?
Um, and I think that's, that's the first thing is always to learn something from, from other people. Um, the second thing is, is, um, the, the fact that that systems are becoming more and more complex, it's, it's to the point where the people who provide the models and provide agents don't even know how their, a final product will be used. So it's governance and security.
I really would like to find out, and this is the holy grail, right? How do you, how do you diagnose or analyze a given, uh, agent AI system for governance, security, and bias? Even, even today?
It's a problem, right? We're, we're, we're giving a system and we have no good metric to validate those components. And as technology goes faster and faster, there is a tendency for, you know, leaving that behind or as an afterthought.
Um, which, you know, Steven, you and I have been talking for it for a long time, you know, governance, security, um, is, is a big concern. I think it's, it's getting worse. And then my final statement is I look at AI as an assistant, so I would like AI to be a better assistance to, to me, in my work, uh, in my private life, Really good points, especially the, the, you know, security or, you know, let's not use a fancy word, let's just say sort of, you know, human control if you like or something.
I think that's a big worry. And maybe that's an area where we need to mature a bit. Uh, just saying like, you did Steven, like, it's non-deterministic.
That's a fancy way of saying, I don't know what it's gonna do. And, and, and, you know, that can be a problem, but that's true of the humans we interact with, so, you know, better get used to it. That's certainly true.
Uh, you know, I didn't expect you to No, that, that's certainly true. Um, and, and I would add, you know, one more thing I'd like to see is I'd like to hear, um, about productive uses of this technology. I really wanna know what are people doing with this that they couldn't do before?
And that, to me, is the hallmark of any kind of successful technology. I think right now we've, we've, we've got a really cool thing going, but we need to make sure that this isn't just a parlor trick. That this isn't just, um, a toy.
It needs to be something that's useful. And so, again, back to the title of this podcast way back eight seasons ago, uh, when we said, utilizing ai, why did we call it that, that means to make productive use of a technology. And so let's figure out how we can actually utilize AI now that we've got technology that works, now that we have a context protocol, now that we have the ability to connect AI with external data sources, uh, we've got infrastructure, um, how are we actually using this stuff?
And that's actually one of the things we're gonna talk about on the very next episode. So on, on the first episode of the regular episode of this season, uh, we're gonna be talking to, uh, a great, uh, a great leader and thinker on this about how, um, his company is building AI models and genix systems, uh, that are specific to, uh, industry verticals. So they're not just putting a chat bot on the side of the website to say, how can I help you?
They're building applications that do things in specific verticals, and, and so you'll learn a lot more about that. And over the season, we're gonna be inviting more people like that, whether it is companies that are designing and building products or, um, thinkers, uh, doers who are out there creating this or, uh, thinking about it and advising on it. And hopefully, uh, when November comes around and this season is, uh, is done, you will have learned a thing or two because I'm pretty sure that I will have, uh, along with Frederick and Guy.
So thank you very much for listening. It's great to have you join us for this season of Utilizing Tech. You will find this podcast in your favorite podcast application.
You can also find videos of it on YouTube, and, uh, you can find it streaming in the Techstrong app on Roku and Apple tv and other places like that. If you enjoyed this discussion, please, uh, leave us a rating. Leave us a nice review.
Uh, this podcast is brought to you by Tech Field Day, which is part of the Futurum Group. com, or follow us on X Twitter, uh, blue sky and Mastodon at utilizing Tech. Thanks for listening, and we will see you next week.
Hey, there, we're in a New York state of mind. You're watching Textron Gang, Happy Friday and another Busy News Week, especially in New York where we have UN Week Climate Week and the Ryder Cup this weekend. I'm John Swartz, your Silicon Valley correspondent, but I'm in the big Apple this week visiting my daughter in Brooklyn and covering some news from UN week and the Ryder Cup.
Alan and Mike have the day off, though I suspect Mike is puttering around Long Island at the Ryder Cup. Joining us is always a lovely panel of our guests and want to introduce them in no particular order. There's the great Steven and Fasque, Gina Rosenthal, and Ira Winkler, our cybersecurity Doan.
Yes. Um, so we're gonna start off with something that I know I sense a little skepticism from. Um, our, our panel, and I love it.
Um, it revolves around this AI diplomacy, this, there's something called the AI Safety Connect, which was convened among a hundred high level participants during the, uh, UN General Assembly to address what organizers describe as an urgent need for global AI governance frameworks. Um, their thesis is, at the quarterly pace of AI breakthroughs has created systems that are more powerful, ag agentic, opaque and difficult to control. And this has heightened concerns about unintended consequences in deliberate misuse of AI technologies.
They, in a sense, are so alarmed that they think that with AI systems advancing at unprecedented speed, we need the same kind of international cooperation that governs nuclear security or climate change. Now, I know Gina and I, I'm pretty sure Ira and Steven, you all have opinions about this, and I'm just gonna open it to the floor. So I will start and let me talk about things, and I'll take a step back, talk about general.
What happens is you have an issue, and then you have a company that organizes events and put things on and says, oh, let's convene a bunch of leaders in the field, and we'll go ahead and try to be the leader in this and address a problem proactively. And then what they do is they bring in a whole bunch of people who just want to add AI to their resume in this case, and start to say, we are now AI governance experts because why? It's a soft topic and nobody knows a different thing than the fact we are experts, except of course, for the few experts, we're not gonna involve.
We are gonna invite some experts who we like and who are friendly, and who will go ahead and give minimal credibility to our people, but not talk badly about us. In the meantime, highlighting the fact that these people can't tell the difference, I will politely say the difference between generative AI and agentic ai, just for example, or frankly might refer to AI as a one in many cases. So these organizations start fluff to make money off of something like they'll have fundraisers who now support their efforts and these organizations who support them just make money off of these fundraising efforts saying that you're now a sponsor for this group of world leaders who now will go around adding AI governance to their speaking topics when they charge 20 to $50,000 for a keynote talk.
I'll leave it there. So, Gina, you did a little res you did, you did a little research into some of the individuals behind this. I thought that was interesting.
Maybe you could share that with us. Well, yeah, of course. I mean, the whole idea, if we're gonna do ai, the first thing you look at is the data, and can you trust the data?
Where did the data come from? We don't even know most of that stuff except for the wide world internet. So of course, I looked at the board that this organization has nobody of color that obviously of cover of color, I'll say that, which is, and nobody that you would know.
And I thought it was very interesting. I just checked on my phone. Again, there's no real readout of who these leaders were that came to this conference and this convening of world leaders.
Who were they? And did they include the people that we see on both sides? So we, they include the doers who are actually, and have been CR involved with HPC and machine learning and deep learning, and now we call all that ai.
So, and the people that had been raising the flag about here's what's gonna happen if we don't, um, think about the unintended consequences. So you, you have this group of leaders that are not doers. They are exactly how IRA said they are talkers, and they have their own companies, and they've been doing AI for a couple of years.
And so they are now bringing together the experts. Who are the experts Are we talking about? You know, one of the things that I think is really important we stopped talking about is the global south.
So Gina, the interesting thing to me was that in fact, there are some doers involved in this. Um, the, the initiative, the, uh, uh, uh, AI safety, uh, connect is backed by what's called the Future of Life Institute, which sounds like something from the sixties where you get a sit around and, and, and meditate. But instead, it's actually a, um, reaction to the development of ai.
Back in the previous decade, the Future of Life Institute was organized by, uh, an MIT professor and so on. Uh, the co-founder of Skype, uh, the one of the researchers from DeepMind, a lot of these people are actually really interesting experts. Um, I should point out that another one of the founders of the Future of Life Institute was somebody named Elon Musk, who I, I, I'm not sure if you're familiar with that guy.
Um, previously this institute was well known for authoring, uh, letters and reports, uh, warning of the dangers of AI and the dangers of artificial gen, general intelligence. In fact, uh, the FLI actually proposed a halt on, uh, development of AI in an open letter that was co-signed by Elon Musk and Steve Wozniak and other folks and all of the, and, and so those are some of the people that are, that are behind this. Now, another aspect here, the one of the founders of this AI Safety Connect is a guy named Cyrus Hoes, which he, he's not really well known, but he's the co-founder of Stability AI that dev generated, that created stable diffusion, that AI image generator a few years ago that everybody was going nuts about.
Um, so we do have some interesting, uh, people in here. My question when reading things like this, whether it's the Future of Life Institute or the AI warnings about artificial general intelligence or this safety initiative, is, um, how can you be, I don't know, Elon Musk and co you know, co-sign a letter warning of the dangers of developing artificial intelligence and then walk away and go generate giant AI data centers? I mean, how do you reconcile that if you are the guy who created stable diffusion or you know, the guy who created DeepMind and you're warning about artificial intelligence?
Yeah, you reconcile, sorry, you reconcile that with the fact that these people are just creating fluff. You know, you can't say, we've gotta put a moratorium on ai. AI is just math.
These are mathematical formulas. You can't tell people, don't implement math in computers because that's all computers. And these are just different formulas.
The question is what you're doing with it and how are you applying the, where are you drawing input from might be a concern, and what are you doing with the output? Those are the issues that maybe AI provides a more robust concern than other things. But generally, I mean, when you, these people come up with fluff for all this thing, yes, it's like these things sound good.
And I don't think these people who put like a little bit of money or their name because they convinced 'em, it sounds prestigious to join. Elon Musk probably had zero involvement with this thing. I don't know about that.
So, so sorry. I'm sorry. You could go ahead.
Uh oh, Sorry. Hi, I cut up to cut on you, but I remember that I take it back. Okay.
These people are so-called doers, but I remember that paper and, and what that paper's all about, even the future of life, if you think about what does that stand for and what does it mean, and Elon Musk has talked about this a lot. Um, they, their main purpose people that are some of these types of people is to get to a GI and to get to a SI, they want to be to the point where we're past all the machine learning and the machines can do it themselves, and they're as smart or smarter actually is the, the criteria for that than humans are. And part of the concern, and part of the commentary around that paper when it came out was, okay, they want us to stop, but they're the ones that are gonna run these consortiums, run these groups, and influence the politics.
So they're the only ones that will be in the business of delivering a GI and a SI that that race to get that first is what this is all about. And that's even more dangerous than what I thought it was, because here you do have all the global self left out, all of, I don't see anybody from Africa involved you and people that have material right now just with the machine learning part of this, um, issues and safety issues around how we're dealing with ai, not even part of the safety discussion. So the safety discussion may not be what we think it should be, but it's a safety to maybe guardrail and make sure we get to a GI as fast as possible.
I believe that is the goal. And I, I remember when that letter came out, Regina, I think you and I were speculating that maybe one of the reasons that Elon signed on is because his company was behind and they wanted to put a roadblock in front of some of their competitors in hopes that they could catch up. 0 that talks about life under artificial intelligence.
Um, he, along with The Future of Life Institute, is also the scientific director for the Foundational Questions Institute, which again, oh, who names these things anyway, um, which is a big proponent of the effective altruism movement, if you guys are familiar with all this stuff. So essentially what we have is the Silicon Valley ai, uh, I don't know, mentat, uh, pushing their Silicon Valley AI mindset to the United Nations in the guise of AI safety, when really what they're pushing is this sort of weird techno utopian future vision that I think a lot of people are pretty worried about. Yep.
I Well, there's a comment. Can ask, can I just ask one quick, quick question because, um, so I, I've so skeptical of these types of movements or initiatives, and I just want before I, we, we can ask just a quick answer, but does this amount to anything, um, especially with no real regulation in the US to speak of involving ai or is this just a, a publicity stuff? Let me, because your question is what I was gonna say.
'cause there are two things that these type of organizations do. Number one, they just create a bunch of fluff to get sponsorship to keep the people who run the organization in to organize fancy meeting and traveling around the world. Yep.
The other thing sometimes they do is they get organizations who wanna go ahead and push governments or regulation or something, and then they like these type of organ, like lobbying org, lo lobbyist type of thing. Then try to tie themselves to something, give them money and take the legitimacy of a hundred world leaders and push their own agenda forward. So this could be one of the two, frankly, at this point, given the whole influence of the UN at this time, it's more fluff than anything else.
If they wanted to really do something useful and drive things, they would just buy congressmen and, uh, you know, and like donate to like a, a presidential library or something, instead the un that's probably one of the least effective places to try to get movement here. But I think the thing is, and the danger of this is that when they're at the un, when there's a World Congress convened, they also have the ability not just to attend this Congress and they attend this conference and figure out what to do, they have the ability to meet the lawmakers and influence them and persuade them to fund what they're doing. And then that funding turns into the legislation and the legislation turns into harmful things that are only gonna be good at protecting this idea that a GI are bust.
That that's what society needs or society, the, the effect of altruism movement, their main thing is society must live into the future for eons. No, no matter mankind, right? No matter who gets hurt in the process.
So no, no. That's why there's no looking right now at, okay, how are black skinned people being impacted by, um, facial recognition and how dangerous it is? And that's not looked at and seen.
It's like, no, we've got to make sure that we have the machines that can do everything for us and we'll figure it out. Then even you had, um, the open AI o saying, I don't know how we're gonna make money off of this. I'm gonna wait till we get a GI and then I'm gonna ask it and it's gonna tell me 42.
So, you know, it's, this is this whole mindset and they know that they have to control the government. This is a way to meet the government to understand even if they don't meet with the right people, they can meet with their, um, their representatives and understand the process and get into that process and that workflow and, and change the workflow so it suits them and it, and it, and this will go through faster. I wanted to say just real quick too, that the one outcome of this was, uh, lost it, a global risk and AI safety preparedness.
Um, so I'm gonna look into that a little bit more. Maybe this will be a nice blog post or LinkedIn post. But, um, the other thing is, is if they're able to get the, the, the idea of risk and what that means, change to suit them before all the normal, you know, people that aren't really caring about this right now, um, people get to know about ai, they will define it, and that's the road that it will go down.
So it is, it's just like ai, it's bad information going in to steer one way and, and we need to watch it really carefully. Yeah, I don't wanna sound like that crazy guy in the meme with like the strings and the corkboard and the, and and, you know, all that kind of stuff. Um, but as Gina's pointing out, when you're evaluating these things, you basically have to try to figure out what's the mindset and the motivation of the people behind it.
And I, I, I completely agree with you Gina. The goal of this is to influence the law and the direction that world leaders are gonna have across the, across the entire world. Because, you know, you can make the United States pass a law that does this or that, you know, with some influence like Iris suggested, uh, you know, some influence, uh, maybe you can make the, make their, but what they're trying to do is, is basically influence the global conversation.
And that's why I think that it is valid to look at who's behind this, who are these people, what are their motivations? Because that will tell us more about what they're trying to do than sort of the fluff that's on their website about AI safety. Because to, to be honest, if you look at the website for this, I think most of us could get on board with the message that they have to say, the challenge is, is that really what they're trying to do?
Maybe it is, maybe these people have turned over a new stone or maybe it's a more nefarious plot. Well, on that nefarious ending, I think we should move on. Uh, we'll, we'll be back in a moment.
We're gonna talk about tele crime and, uh, I guess I, I can't wait to hear what IRA has to say about this, especially this is tied around the general assembly. So, and I expect Steven to give us our, his best Allen impersonation, and that's coming up next. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
So, as you might have heard, the UN General Assembly is meeting in New York this week, and just before the meeting, there was a report that the Secret Service and the FBI have busted a massive, well, I I guess you could call it a hidden telecom network, uh, not just in New York, but all around New York, basically multiple locations with literally hundred thousand SIM cards in these SIM servers. And, um, they, they dismantled this network. They've been making a lot of press about it.
Uh, but the questions remain about sort of what is this thing? Was it related to the UN general assembly at all? And, um, why did they announce this now?
So Ira, this is your area. This is something that I know that you love to talk about. Um, what is this telecom secret Telecom network?
So basically what this type of thing allow, it uses the generic infrastructure of the telecom network, but puts kind of a sub infrastructure in there and there's a lot being made out of, oh, this was, they, they announced it right before the UN General Assembly. This thing has likely been built over possibly a decade, but definitely over years. And the thing is that the criminal underground at all these people, this helps them do a lot of things, lessening the chance, not preventing the chance of surveillance.
And these type of networks do allow for communications among criminals and things like that. So it benefits them to put networks like this in place all over the place. There was a whole bunch of talk right around the UN general assembly.
They said they discovered this network back in August. I don't think criminals would've built this network over the course of a decade to just go ahead to sabotage an escalator in the un the way people are making the sound like. And so, you know, that is for a proverbial red herring simultaneously, you know, then they say like, there's no offense to your text, strong writers, but they say within a 35 mile radius of the un.
You know, that's just kind, I mean, why, what percentage of the, of the population lives there, right? Yeah. I mean you're, you're talking that's the New York metropolitan region.
For the lack of a better way of phrasing it would tens of millions of people in the vicinity, well, or 10, you know, more roughly 10 to 20 million people. And so what's going on is this seems like this is a criminal underground network. They make a big deal.
Oh, car drug cartels are using it. It's like, yeah, criminals are gonna to use this. A foreign nation has used this.
Yeah, foreign nations are gonna use it. It's likely, it's, I, I won't say likely, but possible even US services are using this network to, to some extent, frankly, the FBI probably had to go ahead and investigate this and figure out, wait a second, are we infiltrating this watching bad guys do bad things? Because a lot of times what'll happen for intelligence purposes, you find out about these underground networks and you just use them for intelligence gathering purposes, which is likely what probably happened as well because they were probably monitoring these things to pick up activities.
'cause it could have been much more useful. Like for example, what was the one on the criminal website that Silk Road, they let Silk Road continue for a period of time just to go ahead and monitor the criminal activity. So it would've behooved them to keep watching these things.
And this was at a point where I guess they theoretically got enough information or thought they dried out the information they could get and then took it down. Now the fact that this could theoretically because, um, be used for damage and people need to understand this does have the ability, the size of the network would have the ability to be a denial of service attack because you could use all these hundred thousand sim cards to theoretically overwhelm individual towers or whatever. And that can happen at certain critical times.
But I think people are, you know, this is probably just a criminal infrastructure that criminals put in place to support their activities with lower likelihood of monitoring. And they have these all over the country, I would think now they're probably gonna start to abandon them because now their FBI has indicated they know about them in other areas, which means if I was a criminal, I would think, Hey, they're gonna be monitoring what we're doing on these networks, which is probably what they have been doing for months at this point. I was gonna say it, it's, it's, it's interesting, some of the other articles I read that were more in depth said that the, the reason they found it a few months ago was they were investigating all the doxing of, uh, some of Trump's When Trump went into office, it was mostly Republican people that got dox.
Like one of the articles I read said, um, Marjorie Taylor Green, well, Specifically they were, there was a swatting attempt against swatting, Right? Yeah. I'm sorry.
Swatting not doxing. So, uh, Mar they'd swatted Marjorie Taylor Greene's house saying somebody called from this network saying, I've killed my girlfriend and I'm about to kill myself and try to talk me down. But basically what they do is they, what swatting is, is they make a phone call to nine one one and send 9 1 1 to your house and hoping they'll come bust your door down and make a big ruckus.
So, um, and it was lots of people on Trump's team got, um, swatted from this network. That's why they started investigating it. So it was definitely, they said the things they did say is it was nation state.
Um, lots of people that they knew that they were already watching had been communicating through these, these servers. And one of the things, I guess Ira, I don't know details a lot about networking. That's my new phase of life.
But, but, um, they say they can change the phone numbers all the time. So that's one of the reasons it's great for criminals is you found all these SIM cards, but then you can just use electronically. You know, you don't, not on, you're putting it in a phone, you're putting it in the server and you can just change phone numbers all the time and hide your tracks and do your criminal business as you need.
Yeah. I mean, it is an incredibly helpful criminal tool. And, you know, the fact that they are able to keep something, 'cause it's a lot like, um, oh, what was the name of the ransomware gang that took down hospitals?
Because likely what's happening is that, um, much like that, uh, I get, there's so many gangs that come and go between silk roads and everything, but much like what happens is some criminals probably just put this together and then some idiot starts to do stupid things like doxing politicians with it. And that is how things get exposed. That's why, for example, you know, like the ransomware gang I'm thinking of like that they license out their ransomware software and infrastructure that somebody all of a sudden says, oh, we're gonna do a hospital and ripple a hospital system.
And then all of a sudden it brings attention to them and then they get mad and p**s, you know, and p**s the people off. And then they have to cut these criminals off of the network. In this case, they, the ransomware gang, somebody knows what it is off the top of their head, I'm sure just had to change their name, which is the worst case in this case.
Somebody does stupid childish things like swatting. 'cause there is really no benefit to it, per se, from a criminal perspective except to be annoying and things like that. The way it sounds like it wa it was executed and that things like that uncover the entire criminal infrastructure because they are gonna investigate and, and frankly, I don't care which political side you're on, that was flat out wrong to do something that gets people killed.
Yeah, exactly. And luckily they investigated it. And this is what uncovered, and this is really what happens where somebody pulls strings where they use these things like criminals use these things for infrastructure purposes, support and everything in ways that don't attract attention.
It's kind of like using the major roads and not attracting attention by not driving like an idiot. You know, on the other hand, somebody decides I'm gonna take my, you know, truck full of drugs and drive 150 miles an hour up I 95, that will compromise the whole network. And this is what's happened here that likely this infrastructure put in place, which has nothing to do with the UN general assembly Yeah.
Has been uncovered because of people who just wanna do stupid things. Could it be used for nefarious purposes, you know, to cause damage? Like articles wanna imply the answer is yes, but fundamentally it allowed criminals to hide their activities, to change cell phone numbers to make it more difficult for law enforcement to track them.
And the good or the bad is however you want, like on which side you're on. Somebody did something incredibly dangerous attracting a lot of attention, which allowed this network and likely others in place to be discovered. You can see, like I like to think about is like, you know, I'm watching only murders on the building in the building right now, and of course watching all of the Marvel stuff about Hell's Kitchen.
And all you can think about is those back rooms. Like, why did you do this? Why do you know how hard it's gonna be for us to build up another sim farm in the tri-state area?
Somebody's getting intro. Well, Is it gonna be hard? I mean, so, so it's funny, this story, um, reminded me.
So yesterday, um, this, I read this story, uh, I started off the day recording a podcast with, uh, Commvault, I was with you where they were talking about with, with Gina, where we were talking about how, um, these criminal ransomware gangs have become ransomware companies. They're effectively real companies with profit and loss and presidents and a, you know, all this kind of stuff. They're basically, I don't know, dark side companies.
And then I was, um, listening to the, uh, Infoblox presentation at Security Field Day and Infoblox was pointing out that there are criminal DNS providers Yeah. And basically a criminal Bitly that registers like 75,000 domains a year in order to be able to serve ransomware links. And those are businesses too.
And then I read this story and like Ira said, my mind immediately jumped to this is not nation state hackers or ransomware gangs or Swatters, this is a business. Somebody created a business that was, you know, telecom network, you know, black dark telecom for hire and, and all of these things. I mean, gee, we live in a world where there's basically an evil Economy.
So is it is, so this is very fascinating to me. So these organizations set up like a proper business where they have like a chief operating officer of the dark web? Or did, I mean, how, how does this, how can you just maybe go a little bit over That's that's that's what it sounds like.
Yeah, so like, well, And just for, oh, sorry. Just for example, the ransomware gang, I said they basically have software developers that write ransomware and then they have other people who like focus on, you know, the delivery of ransomware and stuff like that. They put the infrastructure together and then they license it out.
This is crime as a a service. And the thing is this, I'm sorry, ar I keep doing that to you. I'm, Go ahead, Gina.
No, That's okay. I do it to you too. Okay.
So, Um, and, and so part of, so you think about ransomware, the delivery, the most effective mechanism is to trick people into click in a link. So that's done through marketing. So all the marketing tools that we use, this, these companies, literal companies that run this as a service, they are using AI now because like, one of the easiest ways to notice if it was okay, I think this is probably not a clickable thing because the English is all wrong.
They use AI to write all their messaging, all their, all, all of, they can learn, um, they can learn someone's voice and how they would act and how they would say things so they can, you know, when they're really spearfishing, they can get that email down to sound exactly like the person they're impersonating. They probably use this networking infrastructure that got taken down to do all of these activities. Um, and what's interesting to me is like, that's what I think probably happened is we're talking about this, whoever got jumped on here to do this swatting, um, blew up their thing.
Probably was just got the, as a service networking that they provide. And I wonder what happened to 'em. I'm really wondering if somebody already took care of'em.
Well, Some somebody might mess you up. Yeah. If you did.
If you mess with the criminal gang. But You'd be, yeah. So I mean, you'd be surprised they're not, I mean, the criminals are not gonna enforce, they're probably p****d off that they found this.
And frankly, there's probably a half dozen other networks just like this throughout the New York metropolitan region. Yeah. In fact, that's actually one of the things I, I, let's leave it with this.
Um, part of the article in Wired was an interview with somebody, uh, who's familiar with the FBI and they said, this isn't the largest network that they know of, and it's not even the largest one they've busted. So you may be impressed, I'm impressed by the scale of this thing, but it really isn't anything compared to what all is out there in the evil, criminal, dark economy. Mm-hmm.
So thanks very much. We'll be right back with another story, uh, here with the textron game. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. So we've just talked about the ways that criminals are using technology to really change the game around crime.
Well, there's another kind of crime out there, and that's cheating at golf. Uh, let's talk a little bit about, uh, wait A second. Let's, let's talk a little bit about this.
There are a bunch of data and analytics companies that are trying to apply IQ or AI to improve, uh, their chances at winning golf, uh, like the, the Ryder Cup and so on. Uh, John, uh, start us off here. What, what do we know about these evil criminal golf Masterminds?
Oh My god, Steven. Yeah, you stole my lead. Damn you.
Um, so, but any event, so the Ryder Cup is taking place this weekend and AI's gonna be everywhere. There are five major technology partners. There's Cap Gemini, S-A-P-H-P-E, Motorola, and T-Mobile.
One of the most interesting aspects to me is the influence of ai, as you said, and data analytics in particular on the competition. And I talked to the CTO of the Ryder Cup Europe team, and he basically told me something that kind of blew my mind. He's saying that there are basically no limitations to what they can do in terms of using AI by the coaches or the captains to, uh, assess shots, weather forecast, which include wind distance to a, a hole or, uh, uh, what club to select.
And, and, and it's interesting to me because in other sports, like the NFL in particular, everyone plays by the same rules in terms of their use of of ai. Um, they're limited in what they can do. But then again, the NFL is a very socialist, like, like organization in the golf, golf world.
You can't even wear a watch. You can't wear a smartphone, and you can't have anything on your person as a golfer. Now we have this new kind of elements where maybe the Team Europe has an edge.
I don't know, I don't know what the US team has in store, but it opens up this possibility, as you said, to cheat. And I, and I, and I, it's funny, the more I, I talked to him, I, I also asked this guy and he laughed, but he told me it's true. He was like, when do caddies get replaced by AI agents or robotic physical ai, where they are your, um, advisor.
Now the caddies is just as important as the golfer, and so they're gonna get smarter in a certain way. So maybe the golf gets better, but then again, it becomes an arms race. And this has happened throughout all major professional sports.
Back in the day, long time ago, the Dallas Cowboys actually had an advantage over a lot of other teams because they used computers at the time to assess, uh, drafts and players and free agency. Uh, you also had an F1. It's, it's rampant.
But I also think in baseball, it goes back to Moneyball and the whole idea of the Oakland A and maximizing efficiency. So I think this is what's happening with golf, and it'll be interesting to see how it plays out. We were not, we're not gonna see it.
It's not gonna be obvious, but we'll probably find out later after this weekend. I, I, I wanna start, I I wanna respond to that first by just pointing out that I was being flippant. I don't consider this cheating.
Oh, I, I think You're onto something though. And these are not criminal masterminds. Uh, basically these are people using technology to try to improve their game.
And this, and as you said, that is something that happens in all sorts of sports. And by the way, I'll just point out that baseball, major league baseball yesterday announced that they're gonna do, um, a robo ump. They're gonna have appealable balls and strikes next year in Major League baseball using, uh, AI and, um, and, and, and sensors.
So, uh, IRA, Yeah, so this, what gets me is that this is a conversation. What should be the news story is that, okay, they're using better mathematics and computer technology to improve a golf game. Like you mentioned with Moneyball, where they started to implement basic statistics, which is really, I mean, frankly, AI is just more advanced statistical algorithms.
And, but they've been using this as like, I, I worked with some people a while back who, like, back in the 2000th timeframe, the Sports Performance Institute like P three and things like that, who analyze people like baseball swings. And we're doing motion sensors to see how they do that, to get them to figure out how to perfect their swings. And in this case, with the golf and taking advantage of like, okay, the poorer golfers who can't use the same algorithms, and it's gonna be widely available probably to sell to anyone unless some golf golfer is gonna tailor and have hire his own people, which is unlikely.
These same algorithms are gonna be available to everyone. Like, what's the wind direction? And they're gonna have little sensors on their golf caddies and store their bags and everything.
And I could see this as, I mean, I'm kind of like, let's clap and let's applaud. And if golf thinks this is too much of an impact, yes, they can start to make rules. Like, for example, who would've thought that headsets into football helmets?
You know? Mm-hmm. Where the coaches are calling the plays.
I mean, you're saying they're Yeah, they're talking to them and play. If there's Ever a, if there's ever a sport though, that is incredibly regulated to the point where it's kind of a**l in terms of their rules, it's golf. But just to go back and I'll let, I'm sorry Gina to interrupt, but I'm just, just to, to go back to this, one thing I didn't mention is that it's also gonna be a fan experience.
Evidently there is going to be dynamic merchandise inventory so they don't run out of certain types of goods in, because at these golf tournaments, they sell a ton of merchandise. People who go to these events buy and, and, and so this, this way, they're gonna increase the sales as well. And I think the broadcasters are gonna be using ai, although I'm not quite sure how they're gonna do it.
I mean, I, there's gonna be a day when AI replaces announcers altogether. That's just inevitable. Oh, sorry, Gina.
That's not gonna happen. I don't believe that. I think they'll enhance the, there's no way you'll get rid of announcers, but that's an argument for another day.
But like, how much of this has already been implemented or has been used on historical data to create video games? Because I know I've been to conferences and they've had, and I haven't gone, but I've stood with my guy friends and like, all right, what's happening? 'cause I don't understand golf.
But, um, yeah, there's like, they, you would swing and it would tell you this and that the video game would tell you like, what, where's the wind coming from? What's the humidity? Like, all the stuff.
And, and that's how you would try and how is this different except that it's real time on the day of versus using historical machine learning to, to create a really realistic game. Yeah. And, and as Ira points out, I mean, AI is just statistics.
That's all it is. You know, generative AI is just a whole mess of statistics, um, all munged into one. And that is no different.
I was actually listening to an interview the other day with a professional chess player. Chess player, and he was talking about how playing chess these days is completely different than it used to be because of the advent of computers and advanced statistics. And he said that basically, um, any player today would absolutely wipe up the board with any previous player because they have access to all this training and statistics that have been gathered and, and processed and that it's transformed the whole game.
And that's very true of, of, of many other sports Formula One racing. Uh, as you mentioned, I mean, you know, baseball, but I do wanna point out one thing that's kind of interesting. So I'm a big baseball fan, and the whole Moneyball thing, it was a very big, it was a great competitive advantage for the Oakland A, but it rapidly ran outta steam.
I'm not sure if you guys know about this, but today there's actually a big backlash against Moneyball. What happened was it changed the game Book I'm reading In the wrong direction. I'm using a book to prop my, my laptop up.
The book is Jane Levy's book about what's wrong with baseball. And part of the problem with what's wrong with baseball is that baseball's beauty. I think Steven and I, and I will agree was it's unpredictability.
Anything could happen that there, there was a saying that every time you went to a ballgame, you saw something you'd never seen before. What analytics, in a sense has done is made it a very predictable sport where, uh, athletes are taught these launch angles of their swings. They have a certain philosophy about hitting with two strikes.
It's still to hit a home run because it's hard to string hits together because the pitching so good. In other words, baseball's become just the, the very antithesis of what made what we loved about it. It's so predictable.
It's either a walk, a strikeout or a home run it scenes. And it, it, and Moneyball was fed into that and it kind of, kind of made it a bland sport. It made it a longer, a longer game is definitely, so, um, yeah, there are consequences.
Yeah. But the cons, I mean, I mean, I just have to say the consequences are, 'cause what this allows things to do is to make every element, like every piece of a game, whatever it happens to be, allows you to perfect it more. So in the case of Moneyball, like you're saying, for example, it allows an individual batter to know how to micro tune their batting.
It allows pitchers to micro tune how pitch throw, things like that. But one of the, one of the problems in sports is that athletes actually perform better when they don't think, and that sounds weird, but they act, they react. I mean, that's, that's who they are.
That's why they're great. And, and when you, when you drum something into them about a certain way to play, and their certain c circumstances, they don't, they forget how to play the game and they don't know how to perform other aspects of it. And that is a major problem with baseball.
Oh, one thing I should also mention is that with this data, and nobody Knows how to burnt anymore. Oh, that's, no one knows how to field or how to run the bases throw to which base. But, um, there are 15 data points, free shot, free shot, golf shot under this, this, this analytics.
And that's, that's gonna escalate, by the way. So, uh, so IRA's point, you are perfecting these are, these athletes have never been better, they've never been better trained, but I think almost in a sense, they become robotic. And I think you see that not just in baseball.
I think you see it in, in football, and it can becomes like vanilla and bland, and they're all kind of stealing and repeating what each other does. So There's AI slot and sports is what you're saying. It's not just marketing and fighting.
It's in sports too. Yeah, true. Yeah.
As it's happening, any, as any fan, as any fan, uh, who's watched, um, sports recently knows too, there's a lot of impact, you know, in terms of the fan experience, whether it is the, um, scourge of gambling statistics that are everywhere, or whether it is the absolutely asinine, uh, predictive statistics that appear on screen. Apple, by the way, apple's coverage of every sport is the worst about this, because they put little percentages in the corner of what's gonna happen next, next, I, it's one team beating the other or whatever the result is. It, it's just nonsense that ESPN does this on their app all the time.
And it is maddening because one team will go from a 87% favorite to the a, a 13% favorite based on one play, you know? So it's like, what's the point? Um, but, uh, yeah, sorry.
It's just, I I don't, I don't know. I, oh, sorry. Go ahead.
Thanks so much. This, it's a, it's an interesting conversation. I think, um, ultimately what's gonna happen is that it's, it's gonna be all about the athletes.
And some of them are gonna be able to use this technology and be greater than they ever could be before. Uh, some of them are going to, uh, use this technology wrong and it's gonna derail their careers. And ultimately the, uh, the escalation of technology in golf and in other sports is going to, uh, change the game in some fundamental ways.
And we'll see where that works out. So, um, thanks a lot for, uh, joining us here for Textron Gang. Um, before we go, I do wanna point out that, uh, we are live with Security Field Day here on Textron TV today, uh, yesterday and today.
And we will be broadcasting, uh, if you liked these security stories. Uh, we're gonna be broadcasting presentations from security companies, and you'll be able to catch recordings of that on the Tech Field Day YouTube channel, as well as the techron TV app. John.
Hey, uh, thanks everybody. You were all great today. This was a fun conversation.
I love when people interrupt one another. That means that we are exchange, you know, what? Disagreements over, You know, I, I disagree with that, John.
Hey, stop it. Uh, but you know, I, I know I, and, and you brought up the idea about cheating in golf, but in a sense, cheating in sports is like very common. You're always looking for the edge.
And it goes back to the days of the 1950s with the, the people spying out of the centerfield centerfield wall, you know, and, and relaying, or our Houston Astros banging a garbage can. Something as low tech as that. So, um, it was fascinating conversation.
I'm, I'm glad there's a lot going on in New York, and I think you all did an excellent job of laying it out. And, um, we want to thank the audience for watching Techstrong Gang, and, uh, we'll be back Monday. Ellen and Mike should be back by then.
And, uh, have a great weekend. Hey, everyone, we're back here on Tech Drunk tv. I'm really happy to have my next guest on.
You know, sometimes ships crossing in the night could be in the same industry for, I don't know, 20 years, 25 years. And somehow or another, you just never got a chance to catch, catch up or meet each other. So in, in setting this interview up today, I had a chance to meet a new friend in the security space who's been here as long as I have.
And that's always a good thing. Let me introduce you to Craig Adams. He's the Chief Product Officer over at Rapid seven.
Hey Craig, welcome to Tech Drunk tv. Uh, Alan, the pleasure is all mine. Big fan of the show, and thrilled to be on it for the first time.
Uh, it's a pleasure to have you on there. So I gotta just ask 'cause people are looking, that's a really nice background. Is that, that's real, I'm assuming.
Yes, This is real. This is the home in beautiful Waltham, Massachusetts. Well be that.
It's a good, it's a nice time of year to be in Waltham. It's the, uh, this is the tricky thing about New England is while we have four seasons, the winter one is six months long, so you're in that sweet spot, uh, before it's not too hot. And then, well, That's six at the end, six months starts, I know.
In Florida it's a very different dynamic though. So, uh, this is not something we have in common. No, well, I'm, I'm from the north, you couldn't tell from my funny French accent.
And I am from the Northeast and grew up out in the wilds of Long Island. But, um, yes, we are in Florida now, and if I undid my window back there out to the balcony, yeah, we are, I'm on the Intercoastal in it. It's beautiful here today, but Hot is, hot, is hot, hot, hot, hot.
Anyway, Craig, I don't know how long you've been a CP over at Rapid seven, but as I mentioned earlier, you have a distinguished history in the cyber InfoSec space. Share with our audience a little bit about your journey. Uh, very kind.
Uh, so I spent two decades at Akamai Technologies building out their security business. Really the thesis was that while organizations were investing a lot of things on-prem, there was a, a fundamental different layered security we need add on top. Um, after two decades there, I realized the world was moving to not just the magic application, but the intelligence and data we put in the application.
So became Chief Product Officer a recorded future. Uh, and then I recognize what a lot of your viewers recognize, which is yes, uh, data is key, but fragmented data from all of the 35 different security tools, or 45 or 55 different security tools we use. And so I moved over to come, uh, as Chief Product Officer, rapid seven, approximately a year and a half ago, helping customers better leverage their security investment and reduce some of the fragmentation in their environments.
Excellent. Excellent. You know, as we were talking off, off camera, I've, I, I've literally been following Rapid seven since the day Alan Wallace launched Rapid seven.
And that was, that had to be, what, about 22 years ago? I'm going to guess 20, 21 years ago in that range. Yeah.
And, um, it's come a long way, right? What, what started as sort of a very basic vulnerability scanner, and this was back in the days when you did vulnerability scanning. Once a year you delivered a phone book to the security admin, and he worked through that phone book, basically you scanned around Christmas, right?
You gave it to him and you came back and gave him another Christmas present next year. That's how long it took him to work through the book. Yeah.
Dude, interesting definition of present. I've never seen a vulnerability list refer to as a present. Well, I, I'll That one, I'll be honest with, it's funny you bring it up.
'cause the, you know, the company I had co-founded still secure. We, we had a product similar to Rapid seven called Van, and we used to call it the Bad News generator because that's what it was. It was the bad news generator.
That's Right. That's right. But to be fair, Craig, and it's a, you know, it's a view into our industry, other people called the job security.
Sure, sure. Because I had plenty of vulnerabilities to work on. They needed me.
That's right. Of course. The, the, the, the game has changed a little bit, right?
Absolutely. We've shifted scanning left, we shift more often. We, we remediation processes are better than they were.
Um, not just patching and the whole, the whole AppSec thing came into being right. And testing and Yeah. And SecOps, which is, you know, something I obviously got very involved in, um, talk, you know, for our people out there who still think Rapid seven is a quick vulnerability scan, you do once a year, Craig, your chief product officer, give them the vision of the Rapid seven product.
Like Yeah, so, so absolutely. So still, we, we honor our heritage by of course identifying exposures in an environment, but that's actually the minority of what the company is today. Mm-hmm.
So to be clear, there's three things that Rapid Seven does for our customers. Uh, the first is we help them understand their attack surface, um, which is the first mistake most organizations make. Gartner will say 17% of organizations can identify 95% of their tax surface.
We're not even looking at the things we're trying to protect at the end. We give them an aggregate view, looking at everything across the environment. The second, of course, is we help them prioritize exposures based on risk in their environment.
It doesn't matter if it's on-prem cloud in an application, uh, a mis uh, identity or miss inconsistent control, but we're gonna help them risk prioritize exposures. But then finally, and where we spent the most of both our time as well as most of the company's revenue today comes from detection response. So how do you provide an AI driven both sim MDR service intelligence with the critical validation wrapper around it that allows organizations to be helpful?
You know, what makes us unique in this space is, uh, I believe religiously that environmental context matters. So when you're doing detection response, when you're investigating a threat, as much information as you can have about that environment, AKA, does that machine have an exposure that's currently being exploited in the wild? Is that cloud account, perhaps misconfigured or that application, have a vulnerability attached to it, as much environmental context as you could integrate into a detection response that allows you to prioritize faster, respond faster, and of course understand quicker the path to remediation.
That's where we're spending a lot of time folks today with our customers. I, I would imagine what a time for something like AI to come out and help you with that. Oh, the, the, and, and first, you know, we, because we hit AI in the first five minutes, you and I also need to be intellectually honest that there's a lot of AI washing of things.
Uh, ML models have been around a long time at the same time with all the ML models. Even if you just flip 'em and call 'em ai, we knew that in detection and response, what was doing in the past wasn't working today. It wasn't working just to do predictive analytics.
We actually had to go to Angen world where truthfully, when a threat's identified, it's instigating a series of actions that each, depending on the previous data sources, are calling out other actions. That agentic AI workflow is one of the things that we believe is gonna drive detection response across our horizon. Um, I disagree, I'm convinced it's finally gonna give us the best path to the cyber skills shortage that everyone know is so pronounced these days.
Absolutely. I agree with you a hundred percent, Craig. Of course, getting from here to there is an always easy, right?
I, one, one of the lessons I learned the hard way in security over the years was, you know, we, we've had the ability to automate things for a long time. Sure. I remember, you know, the company I helped start, we went IDS to IPS and people were freaking out.
You can't block stuff automatically. I gotta see. Sure, sure, sure.
I would've blocked the CEO's porn or something. Who knows. Right.
But, um, I was gonna say important memo, but still Yeah, well, something like that, you know, the ability to, to remediate vulnerabilities for so long has been something we all give lip service to. And, and yet we're just now really starting to see as part of detection and response automated remediation. Right.
You know, and it's, it's, it is what it is. We've seen it in the whole shift left thing and moving from, from, you know, once upon a time scanning to continuous testing. Yeah.
You're, you're, you're so accurate at first, and this is the always the grand debate of what do you want clippy to do? Uh, not use clippy. 'cause you and I are of a certain age.
We remember Clippy, we Remember Clippy, we remember clip. He's co-pilot the next clippy. But that's a whole nother Ending and that's a separate episode.
We'll, that's not for Today. But, but I think the, there is something that I believe we're now at the point, and this is what we've been working so hard, and we recently announced, as you know, around how do you take something that was being done like it was 30 years ago, which is this validation assessment or pen testing environment, a continuous red teaming, um, the mythical environment that most people wanted that no one can afford. But how do you actually use AI as well as environmental context to bring together a validation view of an environment?
Because if we actually look at problems that exist, every, the number one question that every CISO is asked by the board is, are we protected? Uh, they want that clarity that fundamentally is a validation question. They're asking our traditional way of doing that, of one pen test a year or two, only for the largest organizations with the largest budget of continuous red team service.
That's not sufficient. And that's what we've been working hard at recently. We're gonna dive more into that here.
You know, one of the reasons I had left still secure and gone outta that whole thing is I came to the conclusion that security was too hard, except for the very largest, and not even the Fortune 500, maybe the Fortune 100, the Fortune 50, have the ability to do continuous red teaming in house, have the resources for true 24 7 knock sock layer differences. I, I felt like for the, for the average guy, for the medium, small, medium enterprise, let's call it, they didn't have the budget. The they Don't have the budget.
They probably didn't at the end of the day, Craig, they didn't have the stomach for it either, because it's a huge undertake, you know, we throw around things like, oh, continuous red testing and, and this tell the board what your risk is. What's the CSO to do? Just stick his finger up in the air and say, I think my risk is 30% about today.
That's Right. You, you need sophisticated tools in addition to people That's right. Assesses right.
And, and so it, it, and, and I'm not alone, right? This is every security not at all dilemma. Right?
We, we get frustrated because we know we, for the most part, the overwhelming majority of organizations don't have the wherewithal to do what they need to do to really protect themselves. So instead they become zebras in a herd and hope the lion eats a different zebra today. Uh, and I think even worse, the limited budget, I shouldn't say worse, and the limited budget they have is often forced on things that are regulatory compliant.
So, so take, right? So, so take, um, take even if I'm a zebra and a herd, but I'm in a regular industry, I have to do a pen test. WW which is, but, but I, I get the budget to do essentially that, that, and It's the lowest common denominator Once a year.
Right? I check the box Because we know our environments aren't constantly changing. We know the front landscape isn't constantly, oh, it's not, Yeah, It's static once a year is am, but I'm writing Windows does 95.
And so the question we heard from our customers was, how do we change that? Like how do we actually take the thing that was a check checkbox to actually create a posture validation service? And I do believe this is one of the areas that without ai, we would not have been able to do it in a cost effective way for our customers.
But the ability to do continuous red teaming with the penetration testing included, which is critical for, um, compliance authorities combined with the attack surface visibility, exposure visibility, that's what makes it unique. So if I can go there for a second, like one of the things I get excited about is, um, being able to look at the external world, just E-A-S-M-I is just such a minimal step in an operation. Everyone knows its movement inside of an organization.
Attack path navigation, this is where the unique technology we already had and the ability of service command, the ability to see across your environment, how those things connect combined with the exposures inside of it, with our continuous testing services, allow organizations on a regular basis to get validation of the controls they have in place if they're working, what are the newest identified hotspots in their environment, and of course the deep penetration testing that whatever their industry requires. But, but that's unique and is gonna be a significant disruptor, in my opinion, to the traditional pentest market. I agree with you Craig.
We, we keep biting at the edges of this thing. Yeah, let's go. Does it have a name?
Oh, of course. It has a name. Uh, vector Command Advanced.
Uh, the intent of vector command is as you're looking across your environment, you need to be able to see of all of your attack vectors, do you have command and control of what's happening across the advanced? Recognizes that in addition to continuous red teaming, you need that deep penetration test as well. If you're regulatory compliance, vector command advance is the main Absolutely.
VCA vector command advance. Now is it, it tradi, it combines traditional pen testing. What about like a, is there an AppSec element to it as well?
Like to the left of the event horizon of deployment Or, yeah, absolutely. Yeah, absolutely. So, so there's a few key things that separate.
So first of course it has pen testing, but pen testing is Table stake Since I'm gonna put that to the side for a second, right? Uh, the, the critical things that does this, first it was organized and built to be compliant supportive. So we recognize that many organizations, one of the things they're trying to figure out is how do they get the materials to go back to them away that directly supports whatever audit readiness they're going through.
The second is a need to integrate into your exposure management visibility. So that means what exposures exist inside of my environment, whether it's application on-prem or cloud, it can also critically include the attack pathing information that Rapid seven has. So again, just being able to see that I was able to access this machine, I wanna be able to see that inside out view based on, uh, what we enable from attack pathing, which then allows organizations to understand just the significance behind it.
But critically, it's not a once a year thing. That's one of the things we constantly heard from our customers is I need regular validation if my security controls are actually protected. Because we know with the way modern compromises work, we're seeing a significant rise in the spray and prey.
We're seeing a significant rise of when a exposure or compromise happens, it's broad, uh, or threat actor is able to go broad fast. So the adversary is constantly validating your defense. Um, how, how are you?
Uh, and I don't believe it's just enough to have the controls. I think you need to actually do the work and do the test to be able to see it yourself. Agreed.
Agreed. Is it available right now? Craig?
Available now we have over 40 customers already using it, and we have not had a customer yet. That said it didn't fundamentally change their view and approach the security posture. I love that.
How can we, how could people now watching this right now go grab more information on this? Oh, so first, uh, if you're already rapid seven customer contact or account team, if you're not come on the website, you'll find a clippy ish thing to chat into. Reach out to us, let us know more.
And we're happy to engage to talk to you more about Vector Command Advanced as well as what's new at Rapid seven. Because if you're still viewing us as a vulnerability management company, oh my goodness, quite a bit has changed. We'd love to talk to you about our SIM MDR service and all of the capabilities to keep you protected.
Gotta ask a stupid question. For those of you out there who don't know, rapid seven is R-A-P-I-D number seven, if I correct, that's Correct. Dot com.
Dot com. I just wanna make sure we get that out there. Alright.
Hey Craig, unfortunately this is too short a format for us to really dive deep, but I, I'd like to continue the conversation 'cause I, I, we spoke about it off camera, we didn't get to it, which is what's the CISO's dilemma here, right? They have, okay, now I've got another tool to use here. How do I integrate this?
How do I, how do I pick and choose, right, the right lineup to, to deliver, bang for the buck, measure my risk, convey that risk exposure and everything. You're a hundred percent right. Um, uh, every ciso, and I'm using the word every, um, if they're trying to figure out how they better consolidate to use both the time and treasurer of their teams effectively, that's the most frequent conversations we're having with our new customers coming on board today is like, wait, I can consolidate my vmem MDR validation, threat intelligence, CAP chasm, all in one place.
Or by the way, uh, you operate an open platform to find one of those three things of yours, three things of someone else's, not Locked. How do, how do I and choose? Yeah.
And That's a big contrast to Other, uh, platform organizations with their closed approach is the ability for people to choose how they wanna work with us and engage. We'll continue the conversation. Alan, I love this.
Thank you so much again for having me on. You're welcome. Craig Adams, chief product officer, rapid seven, enjoying the season up in Walham.
Alright, thanks all. We'll be back here in a second on text Drunk tv. Hey guys, thanks for the throw.
We're here with Phil Haiku, who's head of developer experience for valis and we're talking about multi-cloud and well, there's some hidden costs in there and some might even call them attacks. Bill, welcome the show. Thanks for having me.
Alright, Walk us through what goes on here because everybody thinks that maybe they want multiple clouds and they wanna be able to put workloads everywhere, and they think that there's a lot of flexibility in all of that, but I think every time I add a new platform, I gotta add new folks with different levels of expertise. So maybe the costs outweigh the benefits. Phil, what's your take on what's going on here?
I think it's, uh, almost always gonna be a trade off question, right? And that's gonna differ contextually with everybody. But you're right.
I think the, uh, well conceptually a lot of the cloud, multi-cloud, especially the larger ones, will offer the same things. Language will be a little different. The specifics will be a little different around each one.
So you're gonna have local changes in tradition or trade offs that you wanna make. Uh, and then you'll have people who obviously have built their careers around one or the other. And then at the end of the day, I think really it's gonna be around what it is, right for you from business context.
Do you want to have very strong separation of concerns? Do you want to have very strong consolidation of your finances so you can make sure you're not paying too much for what you're doing? Um, but it all becomes just a question of like, here's the trade off.
Let's make sure we are making them deliberately. Because if you don't, you're still gonna end up paying it, but you just don't know what the trade off is. And then that might bite you later.
Is it really possible to have kinda one IT team that is master of multiple platforms or do they wind up just being kind of jacks of all trades as it were? And ultimately I wind up having to get a bunch of different specialists anyway. Uh, at a certain size it's gonna be impossible to really have one central IT team that manage everything and does all that, but that at that size, you're gonna have consultants coming every now and then for specialized things anyway.
Um, so I don't think that's also the goal, to be honest with you. I think the the thing that you do want though is making sure you have insight and some level of governance on where you're, you're having your assets deployed and where you're spending your money. Um, and that is very much possible, but like I said, it, as long as you're deliberate about what you're choosing, you don't have to be contained to one service or one company, but you just wanna make sure you're doing it with understanding the reasons and the constraints, the tradeoffs.
Mm-hmm. How do I get that visibility? Am I kind of deploying some sort of platform to drive that or am I pulling together all these different dashboards from all these different cloud providers into some single portal?
What's the magic there? Well, I don't know if there's gonna be a lot of magic involved, but you're probably doing a little bit of column A, a little bit of column B. Uh, so each one will have their own billing interface, um, and they'll never be quite perfect for what you want out of it.
So you're always gonna have some form of observ, uh, of observ observability platform or tool on top of that. Um, and um, attached to that, you also wanna make sure that you can segment it the right way. So obviously your total dashboard, which just tells you whatever your dollar figure is and how many, if you're in AWS, right?
EC2 instances you have and everything else isn't gonna give you the right contextual information that you have, you need to be able to pair that with which teams are using it, how often are they revenue generating, are they experimental, all that stuff. So if you're always gonna end up needing to pipe that to a BI tool or maybe even a, a data science team who kind of slices that up in their data lake. Um, but again, a lot of it will, will end up being a, how much that visibility do you need?
How much that are you pushing down? Um, we see a lot of companies have a lot of success with leaving the details to the either regional business owners or, or whatever terminology they have, right? You use GMs, um, and they just own the budget for a lot of that and they'll just come in overhead and say like, all right, we've made a deal with this company for this, but we'll take on internal IT ops centrally.
So it's possible, but again, it, a lot of it will depending context and it's always gonna be a combination of tools because depending on the question you have, 'cause you're going there to answer a question, you're gonna have to, you know, heaven forbid export to Excel and write your own pivot table. But most of the time it'll be a combination of like, all right, I've got this list here. This is what's happening.
Put 'em both in your own working memory and then figure out kind of what's going on Is in your sense that some organizations are truly multi-cloud or is it more likely they have one cloud that's kind of dominant and then they have a couple of smaller clouds running because they picked them up through some sort of merger and acquisition or somebody decided that there was a particular workload that really had a run there. But, uh, for the most part they are standardized on one larger cloud and then have a bunch of smaller clouds. There is almost always gonna be one dominant one.
And um, there's always kind of a, there's A and B and then everybody else is kind of much smaller in my experience, right? So you've got for companies that are software companies, right, in the traditional entries and softwares leading the world, terminology, like all their production work is going on a cloud somewhere or hybrid cloud, right? They'll have some data center somewhere.
That's the biggest one and that's also your most important one. 'cause frankly, like that's how you make money. Um, and so that will always be consolidated as a general rule.
You might have some separate products, like you said from m and a and stuff like that that live somewhere else, but the effort post m and a is always gonna be some form of consolidation, if that's possible. Um, and then you'll have your internal ops stuff sometimes on the same cloud, sometimes separated by design. Uh, it really kind of different, like it's kind of 50 50 in my experience, but I, I don't have a broaden up view to really give that authoritative number.
Um, and then everything else just kind of lives where it happens to live, right? The, the usual tool sprawl it just over time or somebody got a corporate credit card, they need to spin something up real quick and then well shoot, we can't fill that process yet and it's not worth migrating. So we'll just keep that over there.
Like it, it ends up in this kind of like there was an element of deliberateness here, but there's also some organic growth around the edges that you definitely will always have a little bit of, like it's unavoidable. Mm-hmm. Of course you can't walk down the street these days without somebody talking about their great new AI thing.
Um, and I wonder, you know, might it become easier to centralize the management of clouds in the age of AI when I have my small army of AI agents that have been trained to do things? I mean, is that a reasonable expectation or is that still fanciful thinking? There is probably some truth to that.
I think there's, there's two ways to look at that. Really. There's where the AI agents are running, right?
That's not a trivial cost in most organizations, right? So you're gonna end up having the stuff that you're hosting yourself will live in some cloud instance, and that'll be a non-trivial bill. Um, there's also what you wanna do.
Um, migrations traditionally have been non-trivial in my experience, even though conceptually very similar things have been offered. Uh, AI agents will probably make it a little easier, but you're still end up gonna have, like, you're still gonna end up having that constant conversation around is the opportunity cost of focusing on this and the potential disruption worth doing? And AI agents may change the ratio of some of that, but it's always gonna be, again, that trade off of like, is this the best production or deployment of our resources?
And oftentimes in my experience, like not really until it gets to a certain size and then it becomes too complex to really want to leave it outta hand because you need an accountability aspect of it. And I, in my experience, while a lot of the agents show a lot of promise in what they can do, you can't hold them accountable for what they're supposed to do yet, you still need humans for that. Mm-hmm.
Now we also talked briefly about finops, and I'd love to get your insight about this, but, um, are people setting up like a finops office where there's the finance team and a, and a couple of IT folks and they're kind of doing that as a center of excellence and or maybe the better part of valor is just to put some sort of cost metric in front of the SREs and DevOps team so they know how much things actually cost and they'll just do the right thing accordingly? There's a bit of truth in the first one. I think people start with that.
Like, uh, we know like over the last say two years with the macroeconomics of what it is, cost has become very much top of mind and people have looked at it that way. Finops has become the popular way to, to manage that. Um, historically finops sits, I think right now as the third party and what was also happening with quality and security in terms of like, it's sat all the way at the end of a decision making process in terms of the chain of what happened.
But the goal is to move it as left as possible, right? Like you want security and QA to be things that are in the planning stage and the development stage, not at the deployment stage. And similarly with finops, like you actually want that to become as early of like principled concept or thing that you discuss with your product teams.
And so I think you're right, like the, you want that to be, I dunno if I put in the SREs hands, to be honest with you, that's just probably gonna lead to a lot of containers getting nuked. But I think that if, if you move that to a product piece that yeah, the end goal would be definitely for them to that decision, right? They'll own a local budget, they can advocate from a business case perspective like, we need this money for these services and this, they know what it costs because they'll have the local bill and it's a lot easier and, and tighter but I think that that's more the end state they're working towards.
Most organizations are really not there yet. They're really in that first area of like, we're doing some initial IT financial management. We know what our bill is, we need to bring this down.
How do we do this? Well, it starts with understanding what's running. That has to be done centrally.
'cause again, a lot of these budgets have historically been managed centrally. And then you can start to push responsibility out kind of incrementally. But I think we're on an evolution or a path there, and we know where it's gonna be, but it's gonna take a while to get that culture change going.
Of course, you are in charge of the developer experience. Um, and I have to ask the question, do we give the developers too much control over the cloud? It seems like historically we have decided that speed was everything and we let these folks provision the infrastructure, and then we're surprised when there are misconfigurations and mistakes get made and uh, data gets exfiltrated.
But do we need to find some way to maybe more centrally manage that? Does that look like some sort of newfangled platform engineering team, or how do, should we be thinking about all this? That's a really good question.
I think there's an element of risk that you have to accept on that front though. Um, as someone who's blown up our Google maps, API bill once before, like, I know what that's like. You feel bad never happens again.
Um, so there's a like learning experience cost to it, and you learn from a retros perspective how to manage these things kind of proactively as well. Um, I think that because you want developers who are truly informed, like if you're having that actual agile team, they should be responsible and accountable for that. Um, uh, historically in the zero HS rate environment, that was a lot easier.
'cause cash was cheap. Um, but now like, yeah, I think that becomes kind of a, a new muscle they have to learn. Um, there probably needs to be some central oversight.
Um, but it becomes a, the typical balance of enablement and governance. I think the enablement sits at the developer side. Governance needs to be something centrally done.
And if you kind of balance that, right, this is not something that becomes overly complicated to solve. I think the developers can still have enough freedom to do their job while not blowing up anybody's budget centrally most of the time. So what's that one thing you see folks doing that just makes you shake your head these days and go, folks?
I think we need to be a little bit smarter than that. Um, one central rule is often the case that that never works. Um, so they'll have like a central rule, for example, that, um, just as an example, right?
Containers need to be spun down at 5:00 PM and they'll spun back up at 8:00 PM or, you know, whatever the number ends up being right at 8:00 AM Sorry. Um, that in theory is a great idea, but if you make that a policy across different time zones never works, uh, if you make that a policy, but you have production environments or that are running, or you have jobs that have been all allocated over and that you need to run over the weekend, but you took down one of the microservices that they rely on. Like, I see that oversimplification type of thing is, is definitely something that people are, are struggling with.
So they'll have a central policy, we can't do more than this, or here's our limit, and they'll cap things on a budget perspective. Um, I saw a customer, for example, they had a, uh, a hard cap on the budget for their serverless processes, but that's great, but if that's in the middle of your customer environment and they were gonna blow up their bill, but they're gonna pay you anyway, but you cut them off, now you have an unhappy customer and you take down your services. So I, I think the overly simplistic approach that we've seen that a lot of customers take sometimes, like that has a tendency to, to not work.
And it's easier to have guidance rules and then make it something that, all right, somebody ex exceeded this guidance. Let's figure out if there was a good reason for it. Amend the rule than to have these hard and fast cutoffs.
'cause I've seen those come in and and they never work. Like they'll keep the bill down, but you're paying for it later. Mm-hmm.
Of course, there's an old joke that says, you know, in the future of the data center is one person and a dog, and the dog is there to keep them from touching anything. Um, what is the level of automation that we should actually be maybe working towards? 'cause I feel like we'll never get to total automation yet.
I also feel like we seem to be erring too far these days on manual processes. I think the goal will always be a little bit more than what we have now from automation perspective. Um, there's always, but it's, it's interesting how the same rule applies.
There's always an exception. Therefore, whatever rule we have codified doesn't work because the context, whether it's the business context or the goal for the, um, the product, or like the circumstances around our, you know, infrastructure has changed a little bit, and you have to change that, tweak things a little bit. Um, there, there's that flexibility that you're gonna trade off.
But I think it's also important that, uh, maybe I'm old fashioned in that sense, but the fact that you can and have to understand the manual process a little bit to get it up and running is an important thing to have. Because at some point, if you abstract everything away and no one ever touches it, when something breaks, it takes a lot longer to debug and figure out. Um, so I, I I, I, that's not a reason to do it.
I think that this is kind of a side benefit for it, but yeah, you're always gonna try and automate a little bit more. But yeah, it's, it's kind of unavoidable that you're always gonna have some manual processes, and that's okay. I don't think that the, the tax on that is too steep.
All right, folks. Well, you heard it here. Hey, no matter how much it advances, you still need to get your hands dirty from time to time.
Hey, Phil, thanks for being on the show. Thanks, Mike. All right.
And thank you all for watching the latest episode. Back to you guys in the studio. Hi everyone.
Welcome back here to our day two coverage of Jfr Swamp Up event in a beautiful Napa Valley or at the Meritage Resort. And if you've never been here, highly, highly recommend. It is a full on resort and spa with wineries on and vineyards on premises.
It's really a lot of fun. I I really do, do recommend it to all you. Um, let me introduce you to our next guest, though.
We have two guests here. We have Amman, Sana and I hopefully get this right. Vijay Kumars.
Hey. Hi, Amman and Vijay work for a large financial financial institution. And they're here talking about, you know, in a hybrid AI world, how, you know, how large financial institutions can get ahold of their, or it can, you know, manage their CICD pipeline, their software, supply chain, security of it, and everything else.
So Armand is closest to me here, vj, to my far left. Gentlemen, welcome to Textron tv. It's great to have you on here.
Yeah, Thank you so much. Yeah, we are, we appreciate the opportunity to be here and in this beautiful Napa Valley. Yeah, it was a beautiful day.
There's worst, worst places to be. Sure. Um, so let, let us talk a little bit about you guys presented, actually.
Yes, yes, we did. So if you wouldn't mind, share with the audience a little bit about your presentation. Sure.
So, uh, we gave a talk yesterday. It was, uh, a good opportunity to come here and, and present it in front of like a large crowd talking about like how, uh, a large financial institution might do, uh, uh, a resident release of their workload, especially in a hybrid cloud setup, where the complexities are very different, right? I mean, uh, uh, typically like companies, they start small, uh, going on-prem, especially in large financial institution.
Uh, there's a lot of legacy stuff that still runs on-prem, right? I mean, uh, especially in bank financial domain. Uh, companies started with building the infrastructure, uh, in eighties, nineties, early nineties.
And that infrastructure still runs on-prem. But the challenge is that, uh, in order to compete in the marketplace, uh, companies have to evolve and, and make sure that, uh, they, they are able to seamlessly integrate with FinTech, uh, especially like the, the new age companies, modern age companies. And there is a pull, like on, uh, on the other side to build modern software.
And that brings a unique opportunity as well for the companies to start looking at how they can modernize their existing workload. But the challenge is it's very hard for the companies to migrate everything and in one single shot. So the strategic choice that company has is to invest in hybrid cloud capabilities, which doesn't come for free.
I mean, there are challenges, uh, that we can talk about, but definitely, uh, there are a lot of opportunities that show up with hybrid cloud where companies can scale, they have a capacity burst. Um, and then a lot of like the, uh, advantages when it comes to like innovation, making use of like, um, a lot of like different, like new technologies that are being developed and, and are cloud first. So that kind of like bridges sort of like the gap with hybrid cloud, where companies can still run the critical workload on-prem, but then at the same time, they find a way to sort of like, uh, gradually move, uh, to cloud in a phased approach in a phased manner.
Excellent. You know, I, I think, well, I'll speak for myself. I'm not gonna speak for everyone.
That's kind of the way I always envisioned it, right? That you don't, I remember, I, I was at an IBM conference eight years ago, seven, eight years ago, talking to the CIO of Hertz, you know, the car rental company. And, and he said they decided to go to the cloud.
And what they did is they built from, from scratch all new cloud-based applications. And soon as they had those up and running, they literally just shut down their old on-prem data center applications and switched over. Well, it was a disaster.
Kurtz wound up filing bankruptcy, if you remember a few years back. Yeah. He lost his job.
Yeah. And, and so I always knew that that was not the way to do a cloud migration, right? You don't do it that way.
You had to do it over time, and you're gonna have this hybrid model and that, and there's nothing that matter. That hybrid model may last forever, quite frankly. There's nothing saying that get to move everything into the public cloud, right?
Yeah. I mean, if you look at, right, we are kind of home of innovation right here in, uh, California, and as you go from Napa Valley to south, you start seeing the innovation every, every mile, every minute, right? Yeah.
So if you look at this space and the, not just fintechs, the large electronics company, you know, the apples and Googles, how they innovated in last, uh, you know, one and a half, uh, um, uh, decade. And if you look at all these things happening together, they're integrating with financial institution, they're integrating with healthcare and whatnot, right? So if you see the innovation is happening, and financial institution cannot be left behind, right?
So they need to be, they need to make sure that the customer experience is retained. Customer wants everything on the fingertips. So all these digital payments coming together, it's, it's, it cannot stay on the legacy because legacy may not meet the customer expectations.
So I agree, bridging the gap requires, you know, the resiliency everywhere, right? And we have a kind of a environment where customer is at the center and everything needs to be delivered quickly to the customer. So that's where the, the cloud and the DevOps and automation comes into the play, and that finances services are catching up if they were behind, but they are not too far from getting, you know, no, uh, to the space where they're Supposed to.
So, I, I'll tell you a, a funny, not funny, but I'll tell you an observation I've had, right? com, it was 2013, so this is 12 years already. Yeah.
And, um, yes, traditionally, finops financial institutions being conservative and highly regulated don't necessarily have bleeding edge, right? They make sure something's tried and proven before they, they leap into it. But when it came to DevOps, and then DevSecOps, right?
I saw financial institutions take the lead. And the reason for it was, quite frankly, where they were, was not a good space from a security point. They were being attacked and hacked, and they had to do something.
They had to get better control of that, number one. Number two, the market was changing. You had this new breed of financial institution that was, was born in the cloud, that was born on the internet that was more nimble, right?
Because customers, you know, when I was a little boy, we didn't have ATMs even yet. You had to write a check. You wait online at the bank to the teller.
Yeah. Yeah. And they would give you the money.
ATMs came out, but then apps came out on the phone, the cell phone, right? Yeah. It just changed it.
All of a sudden, people were, how often do you actually go in a bank anymore? How often do you deal with the human at your financial institution group? Only if there's a problem, basically.
Yeah. So as a result of this, I, I think the market flipped finance became a leader in customer, you know, giving the customer what they want, when they want, how they want, which was primarily through a app. Yeah.
Not through a brick and mortar. Mm-hmm. And, um, so my experiences is that they have led the way in DevOps, they have led the way in a lot of these innovations.
However, they still gotta worry about highly reg being in a highly regulated industry. Right. Let me though, ask you again, you are, you made this move into this hybrid environment.
Do you envision going total cloud, or will you always, you know, I look, a a lot of financial institutions still also have mainframes, right? Yeah. And you're not gonna move, you know, to walk away from your mainframe.
Yeah. That's a statement, right? That, that that's, that's not easy.
Yeah. com, and they text on, they have, you know, they maintain a sy a system of record and a system of engagement, right? Yeah.
Record being usually a mainframe at a data center somewhere. And engagement may be up in the cloud, right? Is that how you guys envision your go forward?
Yeah. I mean, the way I say is that, never say never. Okay.
But at the same time, as an organization, and depending upon how you are set up, you build a strategy. And the strategy as the time passed because of the other factors, you know, you may plan and say, okay, I want to move into cloud, you know, but as you see the opportunity, you could probably shift and then get rid of the on-prem, or you think that Yes, probably in the long term strategy, I have the midterm milestone to determine whether I can get rid of, or I still need to maintain. So the ag organizations build their strategy, depending on the size of organization, depending on the customers they are serving, depending upon the partners they do have, they make the strategy in general.
There are a lot of organization they can get rid of this, um, on-prem setup just because the way they are set up and the customers they are serving in probably our case. And there are some similar cases, probably it might be a time to see, you know, in next couple of years or few years to see that, oh, now we have moved enough. Probably it's time to, you know, get completely, uh, other side of the bridge.
So that's, that's kind of strategy, you know, as, as, as we go. So, so short answer is we are yet to see that how the strategy evolves to, you know, get to the fully cloud and we stay onto hybrid mode. Yeah.
And just to add to like what we just said, I think, which was very well said, um, I think companies also have to make sure that they're doing in a very sustainable manner, right? So, um, I think we just alluded a little bit, uh, on that as well, that it should not be like a big bank sort of like move to cloud. Uh, of course, I mean, it's a learning opportunity for a larger institutions, right?
I mean, where, uh, they might have like thousands and thousands of applications running on-prem. Uh, they have like few applications running in cloud. Now there are challenges that show up, right?
I mean, you might have a data setting, OnPrem, there might be regulations right? Around how you store the data. Uh, you might have to be in compliance with, with your data, right?
So, uh, sometimes you might want to move the compute to crowd, uh, to the cloud, but then you might have, uh, some restrictions that you cannot move the data to cloud. Uh, there might be some, uh, innovation that might have to be done in order to be able to move the data to cloud. Uh, but I think that's probably, uh, uh, kind of like a, uh, uh, an approach that company can take where they can take some steps in a phased approach before they finally land in, in a, in a, in a state where they can declare that they're fully running into the cloud.
But I think that that should be probably the mantra for any company. I mean, that could be the north go north star for the company, but again, there are various factors that can, that could influence that journey, uh, towards the North Star. Agreed.
Yeah, agreed. You know, another phenomenon, so I hybrid to me was always obvious. Yeah.
You know, what wasn't obvious to me, multi-cloud, right? So do you see an institution like yours going multi-cloud using more than one hyperscaler cloud provider? Yeah.
Maybe I can just quickly, uh, throw some light on that. So definitely there are like a lot of different cloud providers, public cloud provider, and every cloud provider has their own sort of like, niche, right? Yep.
Uh, you can look at my Microsoft Azure, uh, Google Cloud, Amazon Web Services, uh, all of these like big cloud providers, I think, uh, they, they all are innovating. Um, they are sort of equally good. Uh, but some cloud providers have services that pro that pro that probably might be like more niche and more sort of like cater to a certain sort of like, um, uh, industry, right?
So, um, I think in general, companies are sort of like investing, uh, in one major crowd provider, but also being at the same time cautious about the fact that, uh, there has to be some sort of like a risk management approach that has, well, You don't want locked In. Yeah. You don't want worry locked in.
But at the same time, it's also a conversation around like the cost management. You don't want to put all your eggs in one basket. Yeah, that is true.
But at the same time, if you divert too much, then you are also kind of like not reaping the full benefit of like having a cost, sort of like optimization by putting more workload in, in one single cloud provider, and then kind of like being able to negotiate, uh, a price point that serves you well, right? So, uh, it kind of like, it can go either way, but then of course, I mean, you have to have a balanced approach as to like how much you diversify, but at the same time how much you concentrate and, and kinda like get the cost optimization. Yeah.
To add to, among what he said, like if you look at probably no organization, which is using a service as a SaaS is insulated from multiple cloud, you know, um, uh, environment, probably directly running its own workload or probably via a service provider, there could be likelihood that you are using underneath, right? But the important point is that if, depending upon the size of the company, the customer, it is serving the geographic location and pricing point, the organization chooses to be, you know, into the multi-cloud versus single cloud now, and then the on-prem, right? So if you look at the landscape, they are, you know, in the multi-cloud strategy probably is better in certain cases when you are like global company and then you are serving the, you know, different type of, uh, um, customers and services and then, you know, um, the kind of, uh, product you are offering.
And in that case, sometimes you may, you may have, we not have a choice other than going to multi-cloud. So those factors come in. But if you are like a small organization, probably you may opt in to have probably two providers, and probably you are happy with that.
And so you can negotiate the pricing and do other things. But at the same time, if you are, say if you're going to a CF aspect reason, and you do not have that cloud provider capability, you are bound to have use another cloud provider, which is already there because you want to serve your customer. So those factors kick in.
But certainly from the, from the financial institution or, you know, the global companies which are serving the customer, they probably make those, uh, smart choices depending upon their business strategy, uh, in global landscape. I love it, gentlemen. I apologize.
We've got a lot of background noise. Hopefully it's coming out well. And microphones, um, last subject, ai, how's that playing into this?
I think no company is shielded from ai. Uh, I think that's, given that in order to stay ahead, uh, companies have to make investments into ai. But again, it at the same time, financial institution, uh, banking and lot of like different industries have to be very cautious about like how they use AI in a responsible manner.
I think one of the biggest challenges, uh, especially when it, when, when, like, when it, when it relates like financial matters, right? Um, AI can sometimes make a decision that may not, uh, be very well and kind of like aligned with regulators, right? So in general, um, AI has a lot of potential, but I think there is still, uh, some work that needs to be done to make sure that AI is using a very, very responsible manner.
Now, there are use cases where, uh, AI can be easily used, right? I mean, uh, we have seen financial institution investing like in deploying AI in call center applications just to help agents serve better, uh, for the customer. But I think what we have seen, like in the industry in general, is AI being adopted in a core sort of like processing is still sort of like something that has to be, uh, uh, has to be, well, kind of like, um, uh, there has, I mean, it requires some sort of like investigation has to how it can be incorporated in a responsible manner.
Because I mean, anything that you do has to be explainable, right? And sometimes the challenge with AI is that it, it's not very conducive to explain like how decisions were made, like, uh, by the ai Yeah. For certain industry it might be simpler, you know, if you go to manufacturing, it might be simpler because you're doing mechanical in most of the cases.
So it's a simple, it's a repeatable process, you know, you're not making a lot of decisions there. But if you go to the healthcare or, you know, uh, into the spaces where humanists are involved, you know, decisions are involved, financials are involved. I think it's, it's, it's very, you know, the area where it's not easy to Not in the highly regulated, You can go move forward with that.
Highly regulated. Yeah, exactly. So, agreed.
Those considerations, you know, are, you are always there, but as AI matures, who knows, you know, in the next few years things may change differently. You know, what if the public, if your customers demand that sort of functionality, you're not gonna have a choice. That is true.
I mean, that, I mean, customer comes first. It's A customer led business. Yes.
Yes. Yep. Anyway.
Hey guys, thank you for coming on. Thanks for having us today. Thank you.
Yeah. Good. Swamp up.
Thank you. Yeah, thank you so much. Yeah.
All right. VJ, Oman? Aman, yes.
Here on Techstrong tv. We're gonna take a break. We'll be back in a moment.
Hey everyone, we're back here. Hey, this is our last interview for Swamp Up 2025. I think I am gonna wear my Jfr hat.
How's that? Oh, You look beautiful. All right.
I won't mess my hair up. Yeah. Um, so let me introduce you to our guest for our last interview today.
There are two folks from Adobe. On my far left, we have Shiba Shiba, she Ra. Thank you.
We call him Shibu. Shibu. Yeah.
I go by Shibu. Yep. Shibu is here.
And to my immediate left, we have Vishal Reyna. Yes, sir. Right.
And we're just gonna call you Vishal. Yes, sir. No shortened names there, gentlemen.
Welcome. And thank you for being our last guest here on Swamp Up 2025. Before we go further, I mentioned you both with Adobe.
Mm-hmm. And we, and as we were talking offline, we actually did a whole, what I considered a great series of interview with the Adobe security team around security and ai, and how Adobe kind of eats their own dog food, if you will, or drinks their own champagne around security and to secure the products because all of us have Adobe accounts and we don't want that information getting Hack. Um, and we did a series of articles on it, you know, it was a whole treatment.
But you guys, you know those fellas from the security team? Yes. But you're on a different team.
Correct. Tell us about your team. So I'll introduce our team.
Um, we are the platforming group at Adobe. So when any developer wants to build something and ship it to their customers in one way or the other, we are providing the capability to those developers to make it happen. And, um, we, the pa the organization is named developer platforms, uh, and we partner very closely with Security Organization, uh, led by Brian and Sure.
Chlorine and others who joined you in the past. And, uh, we work with them closely. And, um, yeah, that's, that's our mandate, help our developer ship software faster to our customers, better software.
So when you say developer platform, is it like a true IDP At this? Yes. At this.
com. Mm-hmm. Yeah.
org group. Awesome. You're indeed.
Um, so I know a little bit about Enough to get in trouble about IDP. Is the IDP sort of like based on like a backstage type of Yes. Thing.
And is it, do you want to talk about that or, I know it's not really part of what we were gonna talk here, but I'm curious. No, I can talk about it. I think, um, in fact, Adobe was one of the first companies who worked with the industry, and we actually put out a lot of content back in 2022 when IDP as a term was picking up.
And yeah, we go and look at, uh, the different journals, I'm sure, including some of yours, you would find that Adobe and Mud Contribution. So we were the first few adopters of the IDP concept, and we implemented at our company, we built it on top of open source software like, uh, backstage, which you talked about. That is the portal that our developers use.
But it is powered by a lot of the CNCF community open source software. Um, we are a big consumer of, uh, Argo. Yes.
Uh, we are a big consumer of Kubernetes, and there are many modes. Well, the, all the backstage stuff has Kubernetes at the heart mm-hmm. And then of course the Argo GI Ops.
Yeah. And all of this is now, you know. Yeah.
So I'm proud to say that we are probably one of the biggest, uh, installs of, uh, GitHub software in the industry. I think we really set really big scale. We have really collaborated, uh, very closely with the community to scale the infrastructure.
In fact, there is A-C-N-C-F blog that we have published on how we have scaled, uh, Argo set up for ourselves to meet the needs where the, the off the shelf, the open source software doesn't meet our needs. Uh, and I'll probably send you the link and you feel free to forward it to you. Please do.
Well, may not be what we wanted to talk about. Hey. But Q Con is coming Absolutely right.
Q con cloud native con will be, uh, I guess it's in November. Yes. In Atlanta.
And of course we'll be there live the whole time. Um, so, and that'll be both for our cloud native now and platform engineering sites. So maybe we'll, we'll talk, talk more about that.
I need to shift though 'cause we are here at, But J Rog Jfr and talk about what you're doing at Swamp Up. I'll let that, uh, Vishal. So, uh, We, we did a database migration.
Um, and as you know, most of the database migrations need downtime. We were able to accomplish a zero downtime for our end users, and we wanted to come in here and share the best practices with our peers. I thought because we don't have AI in our subject or presentation, we are not going to get any audience.
Turned out the room was full and we got a lot of exci engagement right up to the point where we were meeting co couple of industry colleagues here. The goal was like, how, how we came up with an eight hour downtime and that got shot down, and how did we pivot in less than 28 days and made a zero downtime using cloud architecture, um, to accomplishes. And many of historical Jfr Artifactory users who are on MySQL or Microsoft, um, SQO will need to do this to come to the Postgres.
And we shared our best practices, both in terms of how we solve it with technology and also best practices in terms of processes and people and communication. And at the end, how we accomplish that whole, uh, zero downtime. That's A great case study, a great case study.
Let me ask a question just between us. Yeah. Um, is the fact that it didn't have AI in it a, a reason why there were so many people in the room?
I don't Know. Maybe have we all maybe AIed out a little bit? Absolutely.
You know, and I'm not downplaying AI or badmouthing ai, but it's refreshing to have a discussion that's not necessarily leading with ai. Um, you mentioned Postgres, right? Yeah.
Now Postgres is sort of one of the best kept secrets. It is not a secret, but you know, it doesn't get the de the the and what it deserves. You claim it deserves, it really has become an engine, you know, and it started, I'm not, again, I'm not taking sides, but when my, when Oracle bought MySQL mm-hmm.
It set Postgres on fire. Fire. Yep.
Yeah. And, and since then, you know, you have, there are several different Postgres, uh, providers now in versions and some pure open source, some open core mm-hmm. What have you.
But it really has become sort of the database or record, if you will Correct. For, for a lot of these large, large, you know, hyperscale kind of environments. So, you know, that's something that, um, you know, I think a lot of our audience realizes it, but there it's worth repeating.
It's worth saying out loud. Yeah. What I can attest is the performance issues we saw prior years when we were running MySQL with a lot of optimization hacks and everything else since we did the migration platform just scaled up and has been performing awesomely.
And we were apprehensive, like, is it just one of those things that we have to do it with no gains, but we are seeing real benefits of this migration on top of it. Those of you who are running Artifactory do consider using direct downloads. It just is cherry on the, uh, cake and will give you more performance.
Really? Yeah. Direct downloads from Artifactory.
Yeah. Just the mind 2 cents on progress, um, means it has become, um, such a good database and persistent choice that in the recent years, at least in the last five years, anything that we have that my team has built in-house has leaned to Postgres as the persistent solution. So the developers who are on the ground writing a lot of code day in and day out, it's their choice to do relational databases and persistence.
So plus one to what you said, Postgres has become that thing where, where probably Oracle of the last decade or, uh, so like, but but it has become that LI database. No, it is, it is. So I've been in this world a long time.
My SQL was the standard Yeah, yeah. In SQL database because, you know, you weren't locked into a vendor and it was, you had the community developing it in essence. And, and maybe it was, it was probably still a, a small handful of people who were contributing code, but you had the community driving the, the, the, the development visions and, you know, feature set requests and, and quite frankly, you know, Martin Mickens and the people who were running it back then, yeah.
It was, it was a great open source success start. Yeah. So for any project beyond the con core contributors, it's the ecosystem around it.
Yes. Like the different use cases. Oh, I, I, Hey, just a conversation just between us, like, Hey, I'm trying to build this app and this scale.
Go use Postgres. Here's what you should do. Yep.
So these things which we just take for granted, basically make the, somebody wrote a blog post or we came in and spoke about its success in just specific to artifact. These things do add up and Absolutely. To, or as technology more successful.
Now, you, you look at Swamper, and I've been to a lot of Swamp Up in many ways. This is the company and the conference that Artifactory built. Yes.
Mm-hmm. Right? That was the acorn that there's Oak Tree grew from.
But there's more to Jfr here. There's more to swamp up than just Artifactory. We saw today, you know, this week we, we saw, uh, uh, uh, JFR fly the, the agent AI repository.
We saw the AI catalog. We saw a lot. Yeah.
How does that fit in with your mission at Adobe and your, I maintaining your, uh, IDPs and, and your developers? Are they using these new tools yet, or you think they'll want to use these new tools? Uh, we go ahead.
Going off to you, ILA. So, Um, we just started, uh, we were locked in Origins because of the database migrations. We just started opening up.
We are current and now we are in a position to start exploring and getting benefits from the machine learning repos coming in, or the catalog. And certainly the agent take workflows. We, we are going to go in and see where all working with jfr, uh, or partners, see how we can tap into these new offerings that have come in.
And let's not forget about the SBO m uh, AppSec, uh, offering that has come in too. So we, we are going to go and explore these. No, we are very interested.
And so I think, um, there are two sides to it. One is, as a platform group, whatever we are offering our customers, we want to make those capabilities more urgent tech. So we, between Vishal and myself and our teams, we need to build more agents.
And the capabilities that kind of were, uh, published in this year's swamp up some of that we are very interested into, um, looking at and see how that can help. Uh, the second side of it is, as our product teams are taking that agent journey and bringing in agent features into the products product like Photoshop, illustrator and several others, they need a platform where they can run agents. So we are solving that agent platform problem as well as we are building agents for ourselves, which would let us kind of expose our capabilities back to, so on both sides, the, the, the, um, the announcement that came from jfr, they excites, uh, they excite us, be it AI catalog or any other feature, I feel that can really help us.
Um, so we will go back and start looking at them and see how we can factor them into our, um, our use cases. I love it. You know, um, people don't realize about Adobe.
You know, Adobe is, look, it's kind of a blue blood, a royalty name in, in the software world, we all came up using Adobe products, whether it's for video or graphics or PDF or what have you. But I don't know how many people out here really realize Adobe is a company that's very transparent about how they build, how they secure what they do internally, like the, their own best customer in some ways, right? We we're gonna show you what we think are best practices, and you should feel free then to use them.
Right? We, we've already paid the idiot tax in some respect, learning these things, and we're trying to save you from paying that tax going forward. I don't think they get enough credit.
I mean, you make great Photoshop, you make great acrobat, but really being a good, a good community member Yeah. Right. In the software industry is, is commendable.
And, and I, you know, congratulations to you not just that you two, you but the whole organization. Yeah, yeah. For the, for the way you do it.
It's, it's really, I wish more companies were like that. Absolutely. No, I think, uh, this has been a practice in the company since long time before we began our stint here.
And we are just continuing that, right? So our leaders tell us, like, whatever we learn, it's our responsibility to go and pass on to the community. And we are doing it.
Vishal and his team did extremely great job of this really difficult migration. I want to thank him and his team and all of the people who really did the work on the ground, and his team is coming in and sharing all of that with the community. And it, it, there are a lot of interest.
I'm sure other teams are going to do the same. And, uh, this is going to have A lot. You're well received.
Yeah. Where's, where's, where's the next conference you're presenting at? I haven't decided yet, but we'll identify something soon.
Yeah. Our group is, um, going to CubeCon. We have some presenters.
We will Be, we'll be at CubeCon going live. com site. Yeah.
To find out more what you're doing with Platform and how you're building it out. Yeah. Because this is, you know, DevOps, cloud native platform engineering, these are all just different pieces of today's software factory, including ai.
You know, AI plays on all of them. But yeah, It, it, it just basically, uh, compressing, uh, I was talking to one of the, uh, conference attendees. What AI or generative AI in particular has done, it, has flattened the learning curve, like getting a particular sector or a piece of technology or coding for that matter, where, which is what Shibu and I are closest to the getting a prompt in and start learning about, or basically porting a technology which was written on one technology to another technology.
It's not completely solved, but it certainly is easier. You can understand legacy codes better. All of these have intangible, uh, benefits and that's why we'll see more software coming faster at us, which basically puts stress on all the underlying plumbing or the CICD supply chain.
That's where the, the platforms had to come up to basically, um, deal with the new throughput of, um, innovation coming in and making sure that each of the right customers. Absolutely. Gentlemen, I want to thank you.
Thank you. Al. Pleasure, Shibu.
Thank you. We're gonna wrap up our, our swamp up coverage. I hope you've enjoyed it.
We will be back. Well, I guess we'll be back tomorrow with more texture on gang, just not out here in beautiful Napa. But until then, this is Alan Shimel on behalf of Jay Frog and all of our guests, thank you for watching and staying with us, and, uh, we hope it was valuable to you.
We'll talk soon. Bye-bye. AI is the hottest topic in tech right now, evolving dramatically over the previous eight seasons of this podcast.
We're kicking off season nine of utilizing Tech with a discussion of the state of the art of Ag agentic AI with Frederick Van Herrin, guy Courier, and myself, Steven Foskett. Learn about a AG agentic ai and learn about season nine of utilizing tech in this episode. Welcome To Utilizing Tech, the podcast about emerging technology from Tech Field Day part of the Futurum Group.
This brand new season focuses on practical applications for AI and specifically agent AI and related technologies. I'm your host, Steven Foskett, organizer of the Tech Field Day event series, including our AI Field Day event. And joining me for this season is a familiar face and a new one.
Before we begin, let's go ahead and meet them. Well, thanks for having me. Um, I'm Frederick Van Herron, the founder of ens.
Uh, we are a consultancy and services organization, helping customers accelerate their AI journey. And you can find me on LinkedIn as Frederick v Herrin. Yeah, I'm Guy Carer.
I'm, uh, an analyst at Futurum Group. I'm also the chief analyst for another futurum group subsidiary Visible Impact. And, uh, we help vendors, uh, articulate and, and, and bring to market, um, their, uh, offerings, including AI offerings.
But I also have a background in market research and product management, product marketing, uh, including ai. Back before it was ai. And I'm, uh, Steven Foskett, as I mentioned.
Uh, this is in fact, uh, the ninth season of utilizing tech, uh, of those nine seasons by my Count six focused on, uh, and not including this one of the eight seasons previous six focused on AI and various sorts. Uh, last season we talked about AI at the Edge. Before that, we talked about AI data infrastructure.
Um, and, and as guy said, we actually started Frederick, you and I, uh, talking about AI before, uh, chat GPT was released. In fact, we finished our first three seasons before chat before AI became the topic that it is today. I mean, it's safe to say that as far as technology goes, AI is the most important thing in the world.
Um, that sounded like a a one of those, uh, uh, movie openings, right? AI is the most important thing In the world. Uh, do you concur?
Is AI the biggest topic? I don't wanna say the most important, but the biggest topic, Frederick? I I think so.
I think a lot of the innovation, uh, that is happening today is, is heavily focused on ai, maybe a little bit too much sometime. That's why people sometimes are kind of worried that AI is maybe a little bit too much hype as opposed to practical. But I definitely believe that a lot of the funding and a lot of the innovation today is going towards that direction.
And if you, you know, you and I, we have talked so long about ai. We have the seen the traditional ai, we have seen the generative ai, and now it's agen ai. I mean, to a certain degree, what's in a word, right?
We can, we can define a little bit about agent ai, but I definitely believe that AI is really gonna stay a, a hot topic. Uh, the problem of course is AI is a generic word, right? So we, we kind of, as podcasters just kind of a, our responsibility to kind of narrow down and, and, and define things.
Yeah, I think that, uh, actually your first choice of words, Stephen, were the right ones important, important in the sense, maybe not of market size or of current impact, although everyone seems to have encountered it at this point. Um, I use the word everyone loosely, but in terms of, uh, its ability to transform for the good and for the bad, to make things better, to make things worse, and to do that in either case, extremely rapidly, uh, I don't think we've ever seen anything like it. So I, I think important is, is actually the right word.
Even if, uh, we rightly should put it in its place, explain what it is and what it isn't. There's a lot of misconceptions about what it is and all of that. I don't think there's any more, uh, effective conversation to have right now, just pretty much across the technology and business landscape than the AI conversation.
So if that's not important, I don't know what is, You know, my litmus test for the importance of things is, uh, and, and no offense to grandmothers here, but, uh, you know, uh, have, have the grandmothers of the world heard about it. And that is certainly the case. Uh, well, my grandmother is not with us anymore, but my mother-in-law asked me about AI and chat GPT the other day.
Uh, my father has said, sounds like this AI thing is gonna be replacing jobs. Um, you know, everyone I talk to, if they find out that I'm in tech, you know, they, they wanna know what does this really mean? And I am always sounding a cautious note for them.
You know, I don't think that AI is not important far from it, but I feel like at this point, we are still in the new toy phase of AI rather than the, let's get some work done here. Phase, um, you know, Frederick, uh, you know, what do, what do you think, uh, what is, what would you say if a non-tech person came to you and said, you know, what is this, uh, what is this ai, what is this ag agentic ai? Maybe they've heard of AG Agentic.
What does that mean? Right. So, first of all, I mean, when there, I guess there are two questions.
There is, when, when people ask me about AI in general, you know, I, I try to explain it as it augments our capabilities. I mean, you bring, you brought up your grandfather. My mother is 90 years old, and she uses chat gt, and I didn't teach her chat gt, she's using it for translation and for writing, you know, documents.
So I think we're, we're entering a phase where when I explain AI to somebody, there's a low hanging fruit, right? It's the, the, the, the grammar, the translation, looking up things, you know, instead of Googling now nowadays it's chat gt. So that's, that's a generic term as far as a genetic ai.
Uh, the way I explain it to people is, first of all, if they're familiar with chat GPT, then I will refer to it. You know, this is a type of generative ai. And I will say that Agen AI does two things.
And one, the first thing it does is it introduces the concept of an agent. And an agent is like translation or sending an email. And then the second component that makes agent ai, agent AI is the reasoning.
And so the way I explain that to people is, is that agent AI is, is similar to, um, kind of thinking before saying something, right? The traditional large language models, generative AI spits out the first thing that comes to mind and, and sends it to the users. AG agentic AI is where there's a little bit more reasoning just like us humans.
So in a nutshell, ag agentic ai, the concept of agents or plugins, if you wish. And then the second piece is the fact that there is more reasoning going on than traditional generative AI Reasoning. It's an interesting choice of words.
Uh, the usual word that I stress when people ask me about AI and how to use it is simulation. AI is not intelligent despite the name. It's a simulation of intelligence, generative AI in particular.
And I, I do mention that mostly I'm talking about generative ai since that's anywhere between 90 and 99% of the attention right now. Anyway, generative AI in particular is designed to simulate reasoning or simulate, um, speech simulate. Well, it can simulate a lot of strings, it can add a lot of strings to a lot of other strings.
So it can simulate, uh, a DNA strand, for example, based on input. And I think that's a really important distinction to make. It's the source of hallucinations, it's the source of, um, AI's general stupidity.
But what AI does do in, for, in terms of simulation, is extremely useful and helpful, especially as long as you keep that in mind. So, I dunno if I'd use the word reasoning for agentic ai. Um, I mean, the idea of agency is just that, uh, like you said, it's something that can go do things.
And, um, an AI agent that can go and do things without, um, having specific algorithms or sets of instructions, um, that can more or less with permission prompt itself to send that email based on certain conditions. And then really importantly, uh, do what amounts to learning or retraining as it goes, so it can do it better. I think that's where I land on in terms of agentic ai.
Yeah, definitely. I mean, we, we can call it whatever we want, right? Reasoning, simulation, uh, or o other terminology.
The bottom line is, is, is that there is data, there is, there's, there's, um, background information and historical data, and that historical data is being manipulated by math, right? Um, the reason why in a lot of the technical industry, the word reasoning is being used. It's because it's referring to the fact that it's, that the first answer the system comes up with is not necessarily the right answer, right?
So you can, you can call it simulation or iterative approach if you want. The idea is, is that just like with us humans, is that the first answer is not necessarily the right answer. It could be, but it doesn't necessarily mean it's the right thing from a technology standpoint.
It basically means there is a lot more going on when you ask the system angen AI system a question, while you could ask a generative AI system exactly the same question, the AI will do a lot more in the background than a generative ai. And it's, it's very difficult to explain it to people, right? So because people even does, don't necessarily understand to word reasoning or simulation, right?
It's in the end, it's still a machine, it's not a human, right? And nobody's trying to say that generative, generative ai, or I should say agentic AI is replacement for a human, right? Yeah.
And, and I think that that's the, the key there is that, um, well, I don't wanna get too philosoph philosophical here on episode one, but I do think that you could make, uh, an argument could be made that at some point, it doesn't matter whether it's thinking or not, if the result is the result that a thinking machine would come up with. I think that also, it is very, very true to say that it is not thinking the way that we would consider thinking it is statistical, but that the combination of, uh, iteration as Frederick said, and, um, selective use of data can result in something that is the same effect as an intelligent system, even if it's not one of us. Yeah.
And, and Agen does take us a little bit out of the bind that generative leads us into in terms of that simulation idea. Uh, the way I usually put it is that the design point for generative AI is a simulation. It's, it's not truth, because this is, you know, commonly well known within ai.
And I think a lot of the general public is picking up on this, that, uh, the, the results produced by AI can be just dead wrong. Um, the problem is that because simulation is the design point, it's appears true, it appears equally true. Um, and, and to Frederick's point, and to your point, um, when you're thinking about Egen ai, you're thinking about a process.
You're thinking about, um, some automated, uh, or semi-automated process, even if, even if it looks just like the same chat bot that generative AI is, is is behind, um, that process is designed, it's designed by humans, it can be adapted to some degree by the agent itself. Um, and so the result is that, uh, you, you're, you're missing some of that simulative character. So I don't think that's philosoph philosophizing at all.
Um, I think, um, it, it's a useful corrective for us to understand what's going on, uh, right now with AI and what it's, what its promise is. I just worry that even the creators of these, um, agents, um, are fooled themselves into, uh, into what they're capable of and what they're doing. Well, hopefully that won't be happening here.
Um, I think that, uh, we've got some, some folks here who really do understand, you know, what's really going on. Um, but you know, Frederick mentioned another aspect as well of agentic ai. That's, I think, equally important, and that is the ability to, in a way, to perform work.
And of course it has to have, uh, context, it has to have a chain of thought, uh, sort of an iterative re reasoning process to analyze that data and decide, you know, not to, I I'm anthropomorphizing to, uh, Output A, an action, and then it has to have the ability to take that action. And that has led to a need for standard frameworks to allow these AI agents to interact with each other. And one of the ones that we're hearing a lot about, and I think we're gonna hear a lot about this season, is what's called MCP or Model Context Protocol.
Um, which of you would like to explain what a, what MCP is? Well, Frederick's been on the firing line first, so I'll go first then he will correct me if that's okay. Um, because I think of it as being pretty relatively simple.
MCP is a way for, um, AI based applications or AI agents, uh, to seek context, um, to request context and to receive it. Um, largely it can be from other you knowis or AI engines. Um, and it can do this using a relatively standard API like interface.
So it can be programmed in, or it can be, it can, uh, uh, discover these, uh, resources, you know, in its system. And that is what allows these, uh, systems of AI, including agent AI to be more effective and to, and to work together. Yeah, exactly.
It's, uh, it's, you know, agent ai, as I mentioned, it's about agents have different agents. A lot of organizations are deploying and delivering agents that consumers can pull together. And an MCP server has the ability to pull all these agents together and generate the content.
I mean, it's, it's important to note that there's, there's a few versions of the MCP server. You know, some are task driven, others have a, a different, a different approach. But in the end, you can look at it as a, as a way to standardize, right?
You, you, you have a bunch of agents that are very capable. Um, you, you have the ability to daisy chain those agents, right? And so you can build very, and when I say you, I mean you as a non-technical person or consumer can build a reasonable, workable, uh, application with MCP servers.
It has to be said that MCP, there are probably like two or three different server types today. Um, it's evolving really quickly, but you can see how many organizations are jumping on board and delivering capabilities, right? So for example, Docker desktop is, uh, is an application you can install on your desktop, which comes with, with MCP servers ready to go.
And Ken, Steven, can I add a little, a little con uh, not context a little bit to, to this, the importance of MCP, of course. M CCP being an open standard, so, you know, ai, uh, to just give a general label to all this stuff. Ais have interacted with each other before.
Programmatically before, uh, less than a year ago is when the first MCP specification was published. I mean, this thing has grown super rapidly. Um, but here's what I wanted to say.
The import of something like MCP cannot be overstated. If you think of just a regular generative ai um, uh, model, it's taking a string of things and outputting a string of things that should follow that string of things. Usually the string of things is words, and it follows with more words.
So when you are doing good prompt engineering, you're adding all this context and all this stuff to make that input of words and attachments. They're all, it's all, you know, a string of things to generate more things. The more you provide, the more complete, the more on point it all is, the better your output.
That's generative ai. Now, imagine that the AI did not have to rely on whatever you happen to put in, but could go out and seek other contexts. That's what MCP allows.
That is critical for an AI to be agentic and not just generative. Yeah, and you know, ultimately, like, as, as Frederick was saying, I think the, the thing about MCP that is exciting is to me the way that it encapsulates this context in a way that is standardized. In fact, I could see MCP being leveraged by non gen AI technologies as well, because it is very much, it, it just makes a lot of sense.
Those of us who've been using, for example, process automation technologies for, for years now, or the sort of, if this, then that type technologies have encountered the problems of, um, basically AI rot or API rot, um, uh, making sure that as things are upgraded, that they continue to work. Um, figuring out how to pass data from, um, I, I hate to use the word agent, but from agent to agent, from component to component. And MCP actually, um, takes a lot of that work.
And in the context of generative ai moves it forward into, uh, extensible framework. Now, that's exciting beyond ai, but in the context of ai, it's ex especially exciting because what it means is that you can basically give, uh, a package a payload to the next, uh, worker in the chain, the next ai a, you know, agent in the chain and say, here, do something with this. And unlike conventional APIs that are somewhat brittle and fragile, uh, it can be a lot more robust because it uses generative ai.
At least that's how it's been to me. Um, what do you think of that, Frederick? Yeah, that's exactly right.
I mean, uh, I know you don't like the word agent, but the agent in an AI environment doesn't have to be AI driven. It can be something very, very simple. Um, and to your point, you can have agents that are non-AI driven, but by, by enabling it with an MCP server, you end up with a, an application that can do a lot more than the components individually by himself.
I, I'm not sure if we actually defined MCP, you know, it's stands for model context protocol, uh, in case people wanna look it up. Um, but you're absolutely right. I mean, I, I think what it's, what what AgTech does, what Gentech AI does for the community and people out there, it, it enables people to do a lot more.
And we see that, right? People that we're asking for basic applications in the past are now asking for similar applications or at least similar functionality, but then driven by an MCP server. And it's, it's, it's fascinating how easy it is to set it up, right?
And, and we have set it before, but the, the, the, the speed of innovation is incredible. Um, certainly combined with vibe coating. I mean, who needs an engineer to build a prototype?
I'm not talking about production, but prototype wise, it's, it's an incredible time to, to be around. I do think that we need engineers, and I, I know you, you're not being an absolutist about this, Frederick not at all. Um, but it's that, it's that whole idea that when you're using generative ai, for example, it really helps to have expertise in the area that you are working on, um, so that you can utilize what comes out, um, for good and not, and recognize the part that might be problematic.
And in the same way, um, I I, not for nothing. I think, uh, you know, if if there's such a thing as elegant code, there's probably such a thing as elegance in a vibe code. Well, sure.
I, I could, uh, I, I'm with you on that. I, I actually am concerned that as people are vibe coding more, they may mistake vibes for quality and think that they actually have developed, not a prototype, but a fin, but a finished product. That's right.
And that doesn't sound great. Um, but that being said, I hope that, uh, I hope that that won't happen. And I am actually, um, you know, fairly optimistic about a lot of the work that's been happening.
I mean, if you look at what MCP does, it constrains the context that, um, the next link in the chain can work with. You look at some of the other, um, guardrail type, uh, things, uh, that, that are being put up around, uh, AI systems. I think that that's all good, because a lot of the problems that we've been having with ai, um, you know, I mean, certainly my biggest problem with using AI is that it's non-deterministic.
Um, you know, I can throw, uh, a set of data at Gemini and get this output, and then I can throw it the same set of data at Gemini and get a completely different output. And that's challenging for me as a, as a developer. I think that there's, um, many ways in which we can kind of address that with additional guardrails and boundaries and context setting that can hopefully help kind of constrain some of that randomness.
But at the same time, um, I do think that it's exciting where this stuff can go. Um, again, you know, one of the, the words that I used before was brittle. I have found, um, agentic systems prior to AI to be extremely brittle, to the point that I became very frustrated in a lot of these process automation technologies, because essentially those links in the chain would be changed without notice somewhere.
And so, even though it was deterministic, it always gave the same output. Um, it sure didn't once they changed the API on me. And, you know, I actually, in this actually, these days, I'm, I'm using, uh, generative AI as sort of an A API super glue already, uh, where I'll throw it some JSON from something that I know sometimes is a little bit iffy and say, give me A-J-S-O-N output from this JSON input.
And, and the result is usually a lot more sturdy and reliable than, than anything else. And that's what I'm hoping that we'll see with ag agentic paths agent to agent and MCP. Yeah, so we, we talked about two different sides of ag Agentic ai.
One, one is a developer site, which is, which is an interesting piece by itself. But, but I, I have to reiterate, what I always say is, is AI in general, whatever it is, is, is to augment our capabilities not to replace. So you'll never hear me say that, you know, vibe coding replaces a, a developer.
Um, when I use Vibe Coding, if I even can call it like that, it's the equivalent of me buying a book and looking up for a reference. You know, an API call now I go to Vibe Coding and, and Pro, and it'll provide me with some, some reasonable, um, guidance around API calls. And then, and then there's the flip side on, on people consuming Agen ai, right?
I mean, I, I think another, another thing I, I have a problem with, with people kind of assuming that whatever Agen AI spits out that it has to be exactly, uh, what you expect. I mean, it's, it's having different opinions. It's not bad, right?
It's the same data, different opinions. That's, that's what we all do, right? That's why we have this conversation.
We all have the same data or similar data, but we might have a different, different opinion. I think it's important to, to note that agen AI by itself, um, might give you different answers and, and evolves, right? I mean, another thing which we haven't talked about agen ai, but RAG is really important in agen ai.
So RAG is the, the retrieve, augment generate, which is the, the ability to inject almost in real time information and change the behavior change behavior of Angen AI system, right? So, so the expectation is, is that the system should behave differently if you're asked the same question over and over and over. Yeah.
I, I'm looking forward to, to learning how, um, practitioners and, and, and you, I suppose, vendors as well are, um, uh, putting, putting borders around or, or I, I guess identifying scenarios is really what I'm really thinking of. That here's a good scenario for this type of AI work. Here's a good scenario to avoid.
And I don't mean, I, I guess the reason I eventually avoided the word scenarios is I'm talking about sort of not, uh, oh, this is really great for computer vision. This is really not that, not that kind of scenario. I mean, scenarios where the type of work, the type of environment, uh, the type of decision making required, um, some will be obvious, uh, regardless of the application for AG AgTech or for generative, or for both, and some will be obvious ones to avoid.
I think that that kind of, everyone's throwing AI at everything all the time right now in a certain sense. And that's makes sense when no one is really sure exactly, uh, where it's going to be productive and where not productive. But I, I, I wonder if, if there are, there are practitioners out there right now who have enough experience at this point to be able to say, no, we don't have the right personnel, or we don't, this is not useful for this particular type of work.
I'd like to find that out. So as we look forward to the next, uh, you know, uh, eight episodes of this season, I wanna take a moment here before the end to ask each of you, you know, what, what would be your ideal, uh, outcome for this? What would you like to learn?
And who would you like to talk to, uh, over the next, uh, coming weeks to learn that, to reach that, um, guy you wanna, you wanna kick us off? What would you like to learn this season? I'd like to learn if, um, twofold, if there are, um, productivity measures that are, that are, uh, lighting people on fire.
I've been maintaining from the beginning that productivity is a secondary benefit of ai, that it's just, um, it helps you or humans or certain types of work to be more reliable because you can just get started instantly. No writer's block. Um, so it's more reliable and that you can fit more review cycles in, so you can come up with higher quality work and that productivity flows from that.
But I do think that productivity is why everyone's in it, and I wanna understand, um, what people are seeing. And I think there's less productivity out there than, uh, advertised, but people are still pursuing it. So why they're doing that?
I, I think that there are lots of benefits that don't necessarily come down to dollars and cents or ROI or that sort of thing, thing. And, uh, I, I would love to help understand and shape the discussion around that. Richie Frederick.
Yeah, I think, I mean, the, the engineer in me says, I wanna learn about innovation, right? What, what don't I know and what's around the corner? Um, and I think that's, that's the first thing is always to learn something from, from other people.
Um, the second thing is, is, um, the, the fact that that systems are becoming more and more complex, it's, it's to the point where the people who provide the models and provide agents don't even know how they're a final product will be used. So it's governance and security. I really would like to find out, and this is the holy grail, right?
How do you, how do you diagnose or analyze a given, uh, agent AI system for governance, security, and bias? Even, even today? It's a problem, right?
We're, we're, we're giving a system and we have no good metric to validate those components. And as technology goes faster and faster, there is a tendency for, you know, leaving that behind or as an afterthought. Um, which, you know, Steven, you and I have been talking for it for a long time, you know, governance, security, um, is, is a big concern.
I think it's, it's getting worse. And then my final statement is I look at AI as an assistant, so I would like AI to be a better assistance to, to me, in my work, uh, in my private life, Really good points, especially the, the, you know, security or, you know, let's not use a fancy word, let's just say sort of, you know, human control if you like or something. I think that's a big worry.
And maybe that's an area where we need to mature a bit. Uh, just saying like, you did Steven, like, it's non-deterministic. That's a fancy way of saying, I don't know what it's gonna do.
And, and, and, you know, that can be a problem, but that's true of the humans we interact with, so, you know, gotta get used to it. That's certainly true. Uh, you know, I didn't expect you to No, that, that's certainly true.
Um, and, and I would add, you know, one more thing I'd like to see is I'd like to hear, um, about productive uses of this technology. I really wanna know what are people doing with this that they couldn't do before? And that to me, is the hallmark of any kind of successful technology.
I think right now we've, we've, we've got a really cool thing going, but we need to make sure that this isn't just a parlor trick. That this isn't just a toy. It needs to be something that's useful.
And so, again, back to the title of this podcast way back eight seasons ago, uh, when we said utilizing ai, why did we call it that? That means to make productive use of a technology. And so let's figure out how we can actually utilize AI now that we've got technology that works now that we have a context protocol, now that we have the ability to connect AI with external data sources, uh, we've got infrastructure, um, how are we actually using this stuff?
And that's actually one of the things we're gonna talk about on the very next episode. So on, on the first episode of the regular episode of this season, uh, we're gonna be talking to, uh, a great, uh, a great leader and thinker on this about how, um, his company is building AI models and agentic systems, uh, that are specific to, uh, industry verticals. So they're not just putting a chat bot on the side of the website to say, how can I help you?
They're building applications that do things in specific verticals, and, and so you'll learn a lot more about that. And over the season, we're gonna be inviting more people like that, whether it is companies that are designing and building products or, um, thinkers, uh, doers who are out there creating this or, uh, thinking about it and advising on it. And hopefully, uh, when November comes around and this season is, uh, is done, you will have learned a thing or two because I'm pretty sure that I will have, uh, along with Frederick and Guy.
So thank you very much for listening. It's great to have you join us for this season of Utilizing Tech. You will find this podcast in your favorite podcast application.
You can also find videos of it on YouTube, and, uh, you can find it streaming in the Techstrong app on Roku and Apple tv and other places like that. If you enjoyed this discussion, please uh, leave us a rating. Leave us a nice review.
Uh, this podcast is brought to you by Tech Field Day, which is part of the Futurum Group. com, or follow us on X Twitter, uh, blue sky and Mastodon at utilizing Tech. Thanks for listening, and we will see you next week.