Techstrong TV September 5, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Perplexity. CEO is really relieved. He saved $35 billion 'cause he can't buy Chrome.
You're watching Textron Gang. Hey everyone. Happy Friday.
Can you believe it's Friday? I, I love Fridays. Um, we're here at Textron gang.
We've got a great way to end the week for you with a fantastic show and a great panel of people to talk about stuff with. Let me introduce you to him and we'll get right to it. We have some, uh, up in the northwest.
Fred Wilmont joining us, I assume down Texas West. It's good to have her back and a whole award. John Schwartz, and of course, everybody's favorite Yankee fan.
Mike Ard. Welcome gang members. We've got a great show to talk about.
So, Mike, Google. Google got a favorable ruling. Um, but you know how the courts are, I don't know.
We will, maybe it'll be appealed. Maybe it won't be, but for now anyway, even though they might be a monopoly, they could still keep Chrome. Well, you know, there, it's, it's a small but exclusive club being a convicted monopolist.
Right? But that's a whole other issue. Um, I guess, you know, what I'm trying to figure out here though, is what does this actually mean?
I mean, I get the fact that they're not gonna sell Chrome, at least not anytime soon, but, and they're supposed to share data with other search engines. Like who and for what and what does this mean to people? Absolutely.
Well, I think all you need to know when a court decision is rendered in a, by a federal judge, if your stock goes up almost 10%, that, that, that ruling was absolutely favorable to you. Um, so the federal judge said, Hey, yes, you are operating illegally. This is a monopoly, but did not force the breakup.
He basically is allowing Chrome and Android to remain intact while ordering Google to stop these exclusive contracts. They have, like they do with Apple, where Apple ships its computers with Google as the default browser. They also have to share some search data with competitors, which I think is going to be heavily litigated.
I don't know that this is actually going to happen. I think it's going to be appealed. I think that this was just a, like a, a punch with a feather.
This was not a, a warning shot, uh, the way that it, it could of or should have been. But the exclusivity in their search contracts has been their secret sauce for maintaining dominance for a long time. So if this holds up, then I think we are gonna see a shakeup in the search industry because a lot of people tend to use the default browser that comes on their machines.
So if they can break that up successfully versus the sharing of data, I think we're gonna see some kind of a shakeup as it is by the numbers chat. 5 x growth compared to Google. So giving given enough time, uh, LLMs may overtake Google as Google is a search engine that thinks it's an LLM and all these LLMs think their search engines, so they're all gonna converge.
But I do think that this was a good decision in a weak enforcement. So I, I've got a few thoughts on this. First of all, does, does this mean that we're gonna have bing again?
'cause Bing has become this generation's clippy? It does, yeah. You know what I mean?
It's, it's a loser that just keeps coming back and, um, I don't know. I, okay, well give Bing another look. But, but here's the thing.
When I went to law school, you know, there's this, there's the, a theory of judicial economy. Courts and judges don't like to make decisions if they don't have to. And I think had the court kept quiet here, another six to nine months, they might not have had to, because I think once these AI browsers hit the market, and we, there was news again today about, I don't know if you guys, actually it was yesterday.
Um, oh, who makes Jira? Atlassian? Atlassian bought the browser company in New York.
They've got two like next gen browsers that leverage AI or something. I, I think the word is out that AI browsers maybe a throw up the cards in the air moment in the browser market, much like we've seen in the past, when we move from Netscape to Internet Explorer to Mozilla to Chrome and chromium and and so forth, are we about to see a new generation of browser that maybe just maybe takes Google's m word off the table here in terms of, of this, It's gonna take a long time for that to happen, but in the younger age groups, it has already happened. TikTok has surpassed Google and local search for people underage 30 for multiple years now.
Oh yeah. Social media is another factor. People will go to YouTube, people will go, although YouTube's Google, right?
But people will go to TikTok, Twitter, blue Sky, wherever they go for information just as readily as a search. But you mentioned AI search, uh, uh, open AI search. Yes.
I think it's like Google. I open AI is only about, I, I forgot if it was 27% or 30% of Google searches, you know, comparatively, but still in a relatively short time. That's a huge market.
And as you said, Anne, it's, it's going three and a half times the growth. So that's only a matter of time as well. And if you take the chrome out of the search monopoly, do you really have a search monopoly Now?
You know, it's interesting you mentioned perplexity at the top, and it's interesting, you know, we didn't take that bid very seriously when it, when it first came out, it seemed like it's a play for headlines. But in a sense, perplexity in the long term is gonna be a competitor with, with Chrome. And maybe in a sense they thought they jumped the line, but, uh, well, That's what I thought though all along, right?
They were gonna Exactly. Interesting. Make, instantly make Comet, I think is their browser right?
Comment. Yeah. And they're, and they're, um, you know, this, this whole mark, this whole browser market's just in, in tumult, it's gonna be upended.
I mean, we're, we hear, uh, rumors of Apple adding an AI search engine to Siri to compete with open ai. Uh, Chrome is, I mean, actually Google is moving more towards Gemini. I mean, they were making a transition of sorts.
So even they see what's, what's going on, obviously in front of 'em. But it's just, can I just throw one thing out though, which, which to me is so maddening about the court system, is we have this judgment ruling last year that finds that Google is liable for monopolization, and then the remedy in a sense, lets, it lets it protect its monopoly. It's, um, it just, to me, it was just like this long wi tumultuous exercise in, in nothing in the end except with the, the, the, the, uh, the sharing of the search data.
But for the most part it was just kind of a, a, a, a nothing remedy. John, you sound like some I Well, how does It benefit the consumer? Oh, sorry.
I was gonna say, how does it benefit the consumer who cares, care, their data cares, right? Don't care About the consumers anymore. Care.
I don't care. Yeah. Well, and it, I think the Google is going to, although Gemini is nowhere near as good as perplexity or open ai, or Claude or any of the others, or even on a good day, maybe you could say gr but I wouldn't say Grok is good at anything at this point.
But the biggest winners here, biggest in in AI in this arms race, are gonna be the ones with tons of data, large data centers, and lots of compute. And Google has all three. And that you, so You're a hundred percent correct.
I'm, I'm, didn't, No, I'm, so first of all, John, to your, to your comment about the courts, you sound like someone who still believes these, our court system here has integrity. Oh, No, I know where this is going. I mean, I, you know, I sense, right, you know, what I thought happened between the decision and the remedy.
I, I mean, honestly, no. When I, when I see court decisions come down in this country these days, first I know I go look up and see who appointed that judge. Mm-hmm.
Right? Terrible. And that often tells you all you need to know.
But that being said, a quick anecdotal shimmy story. I was at my fantasy football draft Tuesday night, and in my draft is my friend Jeff, who's a VP over at Google Cloud. And, uh, he's been there, he's been at Google now almost 15 years.
So I imagine he's sitting on some decent Google stock, though he got divorced, but another story anyway. And to your point, that's exactly what he said. Look, he said, we're, we're gearing up for a war and the, and the munitions in this war, data, data centers, CPUs, market share.
And no one, no one has the four in that combination as good as Google does. And so they're ready for war. Bring it on baby.
Yeah. Yeah. That, that was his message to me.
I lot of, he picked a lousy football team, I'm going to kill him. But that's another story. I think a lot of people are getting fed up with all of it.
And the part of it that they're fed up with is the Google search experience kind of stinks, and the AI capabilities put on top of it aren't much better. And for that matter, you know, what you're seeing out of the AI browser stuff so far, it's early, but it doesn't really feel like it's a whole lot better either. So I'm kind of like waiting for somebody to do something innovative here, because it's kind of just like starting to be noise everywhere.
Well, AI overviews are hot garbage. I, I will agree with that, but I mean, look at how many times they've rolled it out and rolled it back. Right?
They've rolled it out to a certain percentage, rolled it back. It's usually not a good sign. But now there's, there's such a high percentage Of people, well there's, and you know, they're in this for the long haul.
And I'll tell you something, Gemini has gotten better, right? It, it would, it used to be, you know, way behind it. It's, it's gotten better.
I feel, I know a lot of people who like to use Gemini for certain tasks. I feel like there's, It should within the Google workspace especially. Yeah, you can use it within that domain.
Yeah, it's helpful. But outside, exterior, am I using their agents? Not really.
I am in that, you know, it gives me insights into search, but, but it, it in and of itself is not a great tool at this point compared to others. Um, I think the use case matters there. Yeah.
I, uh, I use, I use, absolutely, I use Gemini Pro pretty frequently for code validation and audit. Um, and I might use other things to help build something. But, um, What about Quad?
Yeah, I use, I use Quad too. Um, the, the models plus the, plus the engine, the framework. But I think the, the question mark there is which model writes better code for what particular use case, and then which model writes better tests?
So ag genetically speaking, uh, either one works fine, but I feel like, uh, from our experience anyway here, uh, we use Gemini Pro two five basically to validate my quad results, right? In a lot of cases. Mm-hmm.
And we'll pass other models through that, uh, you know, do an ab comparison. But, you know, to your point, I think the, the bigger thing here is, you know, if it's data and data centers and, uh, compute and access, uh, you don't have to be a first mover here. You have a lot of uphill battle.
Yeah. That, that's how Google feels. They don't have to be first mover because they have the resources to see this through.
Is there not rules to a third party app does that just kind of sits on top of all this stuff? And, you know, I can invoke that and it will give you the best results from all of these things because, and to Fred's point, you know, I'm using whatever AI happens to be in the app that I'm using. So if I'm in Google Docs, I'm using Gemini, or if I'm in Microsoft, I'm using their thing, but I'm not really going out of my way to go find, you Know, so Mike, I I think I, I, I don't think you're in the majority there.
Mm-hmm. I, I think people are finding that they have their favorite AI they use. I mean, for me it's, it's chat GPT, and then I'll go to Claude as my close second that I cla Says, do the same thing you do, Alan, in terms of Research, I don't use deep Google and consider I don't use copilot.
You Is fine. But yeah, just a classic Google search. Forget It.
I think you're in that 1%. And I think I'm in the majority with most people who are kind of late. Of course you do.
Of course you do. Of course you do. Everybody.
Good question. Everybody's entitled to their opinion. The the big question is, is whether or not you have the apps on your laptops and your phones for those AI engines.
I Do. You have? Yeah.
So that's more, but, So let me, but let me tell you what I did today. Unfortunately, I didn't get it done in time for today's show, but I wrote a quick article this morning at like six o'clock, um, a about iPhone 17. But I took a different take on it.
I went to the experts to ask them what they thought was gonna be in the iPhone 17, and what experts did I go to? I went to the ais. So I went to chat.
GPT, I went to Claude, I went to Gemini, um, and I went, uh, uh, uh, to X to Grok, whatever. And they, they all, you know, there was some overlap, but they all had at least one or two different things that the other one didn't have. Maybe.
But then I asked Chachi pt, what did it think the other ones would say? Mm-hmm. And it was interesting how it, it, and it, and it's in my article, if you check the article, it, it said, well, Gemini's going to go big and make bold things that may not be true.
Claude, you know, is very, uh, very conservative. And it's going to, you know, give you the obvious grok, I forgot, oh, rock's gonna crack jokes 'cause it tries to be funny. And, and, um, Lama llama is all about Instagram anyway, or something like that.
And she's like, so, so It reflects the personalities not wrong that they represent. I mean, but it was in, so that was chat GT's take of what those guys would say or what guys, what those ais would say. That's cool.
But an inter, it was an interesting exercise. That's a great conversation to figure out whether or not there's a consensus in quorum that can be had here. Or are we really just gonna have five people on the block having a debate about their personalities Yeah.
With their hot stakes. Yeah. Be curious to see There is good, but, Well, I think I, go ahead.
I was gonna say in this case, I think, um, just getting back to the actual decision on Remicade, I think both sides are gonna appeal. I just wanted to mention that there is a, there, I think it's DOJ and Google are supposed to meet and confer and submit this revised final judgment next week. But I think this is just gonna continue to go through the court system.
Absolutely. They're not gonna just accept this. I doubt it.
No, there's, I just can't see a world where they're gonna go, okay, here's the data guys As favorable as it as it was for Google and, and Apple. Yeah. They're not, they're still not gonna accept it.
So I, I'm not sure you're gonna see the government appeal this, they, they're not, this, this administration is not into enforcing antitrust monopolistic on American based companies. No, no. The least that's, that's the facts, guys, right?
And, and I understand why they do it, but remember, why do we have these antitrust laws in place to foster competition to have the next generation of innovation? And, and, and in, in saying, we need, these companies are too big to fail, whether it's Microsoft, Google, Intel, Facebook, apple, what have you. If they're too big to fail, they block the sunlight for the next generation of companies who need that energy to grow and bring us our next Googles and our next AI and our next what have you.
And, and that's the downside of that. Hey, how much is 10% at Google's search revenue anyway, More than you'll ever need. It would get you, it would get you really good.
Like, you know, you'd have your own suite at Yankee Stadium with your, you probably get A monument. You Can too. Isn't, isn't this how we deal with companies that are too m to fail Now we just make them revenue generators for the United States.
Isn't that how that's gonna apply? Yeah. That, that could, because We, we buy a stake in these companies.
We don't buy a steak. We don't buy a steak. We get a steak.
We take a steak. Mm-hmm. What do I know about the restaurant business?
All right, let's, let's, let's end it right here. 'cause we're descending and, uh, we'll come back up and we will more court. We, we got nothing to do, but talk court cases today, uh, philanthropic reached a settlement in their copyright case.
We'll talk about that next on Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back. And we're talking about this settlement that Anthropic had with a bunch of authors who are suing it for violating their copyrights.
And the details of this are a little light and sparse still, but apparently, um, philanthropic was looking at maybe a trillion dollars in potential liability. And so they settled in some ways that we don't know exactly what for, but everybody seems to be watching this case, John, because, well, there's a lot of these suits up there. Yeah.
It's getting a, it's getting a lot of attention. This was the most high profile of a number of, of these types of lawsuits. And, um, it was a class action suit that's been settled.
We haven't heard terms of the settlement, but what essentially the judge said in, um, in his ruling or his, the announcement of the settlement was that, um, he, he had agreed that anthropics process of training models on these copyrighted works was, quote, exceedingly transformative. In other words, anthropics said it legally bought paperback versions of these three authors books scanned and digitized material, and then destroyed the originals. But what it didn't mention, and this was discovered in the case, which could lead to heavy damage to philanthropic, is that it also illegally downloaded 7 million books to accelerate training of Claude.
And it kept those copies. Now, uh, wired came up with an estimate that had it gone to court and lost in these other cases, it would've been on the hook for up to a trillion dollars in damages. So it's settled here, but this case is far from over.
Um, and I think there are other cases that are gonna evolve or that we've been hearing about, uh, some involving News Corp. Is, is suing. I think Ziff Davis has been another that's sued.
Uh, we have the New York Times scuffle with open ai, so it's far from over, but this is the first settlement, maybe the first settlement of many. I don't know. We're gonna see more lawsuits probably crop up.
Um, you know, AI moves fast, and so the so are these lawsuits. Absolutely. And I, I don't think philanthropic is alone.
I mean, quite famously, Tim O'Reilly came out and said, Hey, o Open ai, you scraped all of our O'Reilly books. And as an O'Reilly author, I obviously took offense to this 'cause I worked very hard on that, and it's gonna tank my book sales. My book has also been out for eight years, so war were those sales anyway.
But it just seems like such an egregious violation of copyright laws. And it's, it's the move fast and break things ethos. I mean that the, this is how that comes to play.
I have a question about how you get to derivative works issues here, right? All of them, right? So if it's a book that I wrote, right?
And I wanna write a series of books, but you've read without my consent, right? Those books, uh, and violated the copyright there, and you write my next couple of books because you have access to all the domain knowledge plus all of my writing style and so on and so forth. Where does that come to play here?
It's fruit from the Poison Tree. Not at all. Because what, what it, because I mean, there could be a scenario if I said, Hey, this is my new book by Fred Wilmont, or this is my new book in the Voice and style of Fred Wilmont, or this is my new book based upon Fred's book, right?
But that's not how AI is working here, right? It's, it's taking your book and, you know, into its knowledge base, but in essence recreating, you know, the closest legal analogy you have to this is the sampling in music, Right? So yeah, this happened just recently to an artist named Emily Portman.
She's, people were complimenting her on her new album. I just read a BBC story about this yesterday. People were complimenting her on social media about her new album, and she was like, what new album?
And it had been put out as an AI fake. So that, that clearly is, you know, crossing the line. But that, that's not where a lot of this is using.
I gotta tell you though, this settlement, and usually look, when you see settlements, there are win-win settlements. There are gun to the head settlements, and there are, you know, just save my bacon settlement and make it go away. This was sort of a hometown.
Again, I think we protected anthropic, which I'm not sure if Philanthropics us or UK based, I forget. But you know, we, we protected the hometown here. They, they, I think they're getting away relatively easy compared to what it could, should be.
And, and it's gonna set the bar for the other ones to settle as well. Yeah. It's gonna set a precedent for some of the other cases, right?
Right. This is, It's based in San Francisco, by the way. Yes.
It's local. Um, I think, I think they also noticed there are hearings on this topic now in Washington, and the noise coming out of there isn't pro ai, it's pro content. So Right.
Content creators in Congress. Does that matter anymore? We'll see, Yeah.
Come on. Too big to fail again. I mean, that's just like, yeah.
More Questions and answers, Right? Are you talking about congress or Congress? Yeah, Just checking.
Yeah, I'm talking about that. There's gonna be a lot of finger pointing and Raise. 0.
Watch out. 0. I'm aware of that.
It's the save the taxpayer money bill now. Mm-hmm. They've rebranded it, right?
Well, content creators are taxpayers. So there you go. That brings up another thing.
I don't know if you guys have seen this, but you know, when I look, well, not so much on my posts, but when I look at other posts on social media and they, and, and the, and I see some of the comments are, you know, crazy fantas old conspiracy wielding crazies. And I say, who the hell writes this s**t? Excuse my language.
And I, and I click on the person's name, how many times that person will say, I'm a digital creator. That's what they do for a living. They're a digital creator.
I think digital creators are bots that are full of crap and just put out there to so discord in our, in our world and country. And we should, anybody who, any profile that says they're a digital creator, let's just erase it. I like that.
I like that. Check it out. I don't disagree, but Self, so I, so I know people who are digital creators, they're actual people, and I'm kind of trying to wrap my head around their first amendment rights and what you just said.
I'm gonna have an executive order and suspend it. There's, you know, there was this little lone loss passed in 1791 that in times of emergencies, I could do whatever I want. Oh, Okay.
I'm waiting for the Supreme Court to rule on that. All right, on that note, we'll wrap this one up. Let's come back and, and maybe, and well, it's a good segue into AI mental health crises.
Are we all crazy? com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network at work. Hey folks, as Alan said, we're gonna talk a little bit about AI mental health and on a previous shows, and especially with Fred, we've talked about the positive side of that where, uh, folks who may not have access to healthcare can maybe rely on ai. But now there's a negative side too where, uh, parents are suing because their son, uh, harmed themselves because of ai, or at least that's what they're blamed for.
The providers of the models are now saying that they're gonna provide more guardrails for distressed teenagers. There's, um, uh, cases in New York where somebody is allegedly killed themselves and their spouse because of what AI told them. And now there's even a congressman in Staten Island saying, we need to do some regulations here because this is gonna be the next big crisis.
Fred, I know that you've been on the positive side of this, but what's your take on the latest negatives? I think with the pervasive use and the, you know, erosion of human connection, the exacerbating symptoms of what's going on in the world, and the warning signs we don't see about bot behavior is this is the downside. And absolutely, it's, it's pretty scary to think about what those types of influences are, right?
Uh, example, uh, I have a, you know, a 21-year-old daughter that, that goes to school in England, and, uh, she is pretty removed from her support group, let's say. You know, if the types of ways that we've talked about are positive, can actually turn very negative and support negative behavior and activity without guardrails, it has, that will have an incredible amount of consequence in society. Right?
So, Adam Rain's parents suing Open ai. Interesting. Um, what's the, what's the viability of that?
Having actual legs to create reform and requirements? I think the notion of self-harm and suicide eating disorders, all of the chaos that, you know, young people have today are, are magnified by their access to influential data. And some of that, whether it's, you know, chat GPT or it's anthropic or it's whomever, right?
The interesting illustrations here are that there is more and more pathos being evolved in the way that the communication unfolds between folks that are spending more and more time, uh, you know, uh, Eric Solberg's situation, right? Clearly delusional and manifested over a long period of time, uh, that had predictable consequences. So, you know, whether it's diagnosis, misdiagnosis, harm, you know, what is the shared responsibility model here that hasn't been established, or the guardrails that illustrated, You know, oh, go ahead.
Go ahead, Aaron. This is an old problem. Yeah.
Yes. Feels like a new problem. Yes.
0. Uh, social media was not, and has not been historically a safe place for kids. Uh, you, you have all sorts of things going into place, and without parental oversight there, there's harm, right?
And so I think that we're seeing some very exaggerated cases that are bringing this to, to the forefront. We have a loneliness epidemic. We have, uh, you know, there is no chart and map for where we are now.
And I think the, the biggest misnomer I see with people, this isn't new. It feels new because it's got a different twist on it, but it's, it's not, Yeah. You know, that's, I was my exact sentiments and I, there was a cons controlled study by open AI and MIT that found increased daily chatbot use was associated with loneliness and restricted socialization.
And when I saw that, I thought, well, didn't we hear that about Facebook? Didn't we hear that about even MySpace? I'll date myself.
Um, this isn't new. And I, maybe these are outliers, but they're still a very important examples of what is happening that we know of. And I think it took us, OpenAI was working on making, uh, adding guardrails to address this.
But I'm telling you, in the New York Times has a front page story outlining what happened to Adam Rain that's gonna move things up and accelerate actions by them. And by meta, by the way, I, I would liken this to the Victorians where, you know, uh, they, they were scared of gaslighting because gaslighting in the home meant poisonings. It meant fires.
Uh, and we are in that era. We are in the gaslighting era. And I don't mean that in the term it's used, how it's used now.
I mean, literal gaslighting. Uh, you, there is always a price to pay for the advancement of technology, and these poor people are paying it. And, and that's the unfortunate thing.
But I'm gonna disagree. And I'm gonna say that there's a world of difference between people on social media maybe saying things that are wrong or encouraging people to harm themselves, and a machine program by a company saying that that's a whole other level of responsibility and, and li and liability. So I don't think that this is quite the same thing as what we've seen before.
And when you got a machine that is sick of, it's Not, I think when a human, when a human says, I mean, I don't know. This is, this is a really, this Is difficult is son, this is son of, son of Sam, right? There was a black dog talking to him, telling him to go shoot people here.
It's AI telling me to go do it. Let's not, you know what, yes, we are in a little bit of a new area and we have a new whipping boy that we can whip, but sick people do sick things. And, and so this makes Garbage in garbage out.
Yeah. And, and so this is, you know, they, if it, this is just the latest, you know, wave of this, but sick people do sick things. I, I think Fred, I think was referencing that.
But let me tell you the good news here. 'cause there's a silver lining here. Why can't we train?
Why can't we train the AI to be a better mental health counselor and give everyone their own personal therapist, their own personal, you know, I, look, I, I tell you, I went for therapy for many, not many years, but a good amount of years during my life. And I found it incredibly helpful to have someone who would listen, not necessarily give you answers, make you go on a journey of finding your own answers, but would listen and help guide you on your journey there. I think, you know, why, why don't people do that more?
Why don't more people do it? Well, there's a little stigma to it, but it's also money, time, privacy, having a, a personal therapist that, that, and I think we could do that well with ai. I think that would be fantastic and would help a lot of people with, with mental health issues.
Look at what it's doing for the elderly. They're using, they're using AI in robots to, to be companions to elderly, that that's something that's happening in Asia. And, and I think as absolutely what this technology can and should be doing.
Yep. Just making People's lives better. Now, I'm, I'm a little concerned about the AI girlfriend boyfriend things.
Yeah. That's icky. It's not a replacement.
Well, you know. No, no, it's just like junk food, right? We like junk food, we like chocolate cake, but we know not to eat it for every meal, or we get sick.
Yeah, I know. Plenty, plenty of people who people Aren't who gorge on junk food all the time, unfortunately. Right?
But, but the, it's like a digital health thing, right? Yeah. You, you go back to the same, well, you keep going back.
I met a gentleman at a networking event at the Soho House not too long ago who told me he spent all day talking open ai. He said, well, you're a digital expert. Tell me, you know, I'm asking for career advice.
It's giving it to me. It's telling me to be a developer. It's dah, dah, dah, dah.
And I said, s first of all, go outside touch grass. Secondly, don't rely on one model. So when I, I hear sort of edging towards addiction, I say, don't go, do not get locked into one universe.
That's the number one thing. You the context Context. When those are getting bigger and bigger and bigger.
Yeah. Don't, don't get locked into one universe. Also, There is gonna also be that though there is gonna, there are gonna be people who, who are infatuated with it kinda Thing.
But, but last, It's Last time I checked, if a human encourages another person to harm themselves, that is a crime. And you will go to jail. So it's not like, this is not maybe net new, but it is a significant liability even if you're AC company just saying, So, so in the eighties, right, there was this band called Judas Priest, you may remember.
I Remember, right, Exactly. So in Alive Yeah. Sued for, you know, demonic worship that caused people to do, you know, any number of things.
A teen locked himself in his room and listened to priest and then committed suicide and so on. And all of the social, uh, you know, triggers are there every day all the time, right? And the notion of the erosion of human connection, right, is actually the complete opposite of what we want to happen with shimmy, as you suggest.
Right. Some healthy opportunities for not only, you know, sort of teens at risk. 'cause you know, 19 year olds have the highest suicide rate of any absolutely.
Age group, but also, you know, the elderly who don't have, because their kids don't live around 'em anymore. They don't, their social circles have died off or whatever the case would be. And another Group, Fred Veterans, Absolutely.
23 a day. Yeah. I would love for some way to stop that statistic from growing.
Yep. But that, that exact case, right? And to your point, the, the rationale between trusting one voice or distrusting all voices equally, it's not human nature.
You want to establish that trust and you want to hear the truth, air quotes, uh, about what they know about you. That's really what that type of connectivity is about. That's the part that worries me a little bit.
And the shared responsibility construct is if you're gonna give me a device that I keep in my house, like Alexa or whatever, I don't have any of that in my house. But if you did, uh, that, that device would allow you the opportunity to understand you better, right? To, to Shimmy's point about counseling and, and management of, you know, sort of health issues.
How much of that is a shared responsibility that that company, that organization has to be accountable for, just like Mike said, like it, if somebody told you, you know, Hey, you should go jump off a bridge, what do we tell our kids? Just because somebody told you to go jump off Somebody told you to do that, right? Doesn't mean you should.
Where is that sort of come to be part of the pathos of how we interact in society today? That's, I'm curious If this goes, if this goes to core, it'd be really interesting to see where, as Mike alluded to, liability of the companies themselves behind the models. Um, I don't know if it would, if it will, But it'd be be a fascinating test case.
We'll see. We'll see you. Well, we've already spoken Our courts.
Alright. I just, nothing to say about all this. There is no substitute for a good bartender.
That's all I gotta say. How about an AI bartender? I'm in.
I'm in. All right. There you go.
Hey, we're gonna call a wrap. You know what? It wraps up a week, a great week here on the gang.
We hope you've enjoyed it. As usual, we've got tech drunk TV coming up immediately after this. And, uh, we will be back Monday with fresh gang content to go over.
But have a great weekend, everyone. We will see you Monday. On behalf of Fred and Ann, and John and Mike and myself, and the rest of Techstrong, have a great weekend.
We're out. Hey everyone. Welcome back here to Techstrong tv.
I want to introduce you to a CEO of authentic, the CEO of authentic Security here. His name is Fletcher Heisler. I hope I got that right.
Fletcher, did we pronounce that right? Sounds good. All right.
Hey, Fletcher, welcome to Text Drug tv. It's great having you on. Thanks so much for having me.
Pleasure. Um, Fletcher, we're going to, Fletcher we're gonna talk a lot about authentic and authentic security 'cause there's a difference. But before we do that, I wanted to give people a sense of who they're listening to.
So if you wouldn't mind, give us, give us kind of your story. Give us the Fletcher story. Sure.
I can give a, a little bit of the authentic story and we can get into that as well as a bit of my background. Sure. I've been in tech since learning q Basic and middle school, Uhhuh and, uh, futsing around in the security world, maybe in ways that, uh, I wouldn't do these days.
You shouldn't have. Uh, um, but we all, you know, got, We've all been there, right? Things we did we're not really proud of, but it helped make us who we are Learned by doing.
Absolutely. Uh, um, I most recently prior to, uh, authentic, uh, ran a company called Hunter Two. Uh, went through Y Combinator, it was a, uh, application security training company for, for developers, so helping them Oh, very cool.
Write secure code, but they get to actually hack and patch up live applications. Um, so that was a fun adventure, um, acquired by Veracode. I worked there as the director of developer enablement for a few years.
Um, sure, you know, was, uh, a, a little tired of wearing all the hats. I I had a newborn, so it was time for a little bit of a break. And someone from, uh, open Core Ventures, which is the original sort of pre-seed funder of, of authentic security of the company, um, reached out to me saying, I know you've been poking around in security and identity, and this guy's been working on a really cool project, um, that, that you might be interested in.
Uh, so Ys, uh, our, our founding CTO, who's in in Germany, um, was an infrastructure engineer at Yelp. Um, and he started building out authentic, really, because he couldn't do what he wanted with Key Cloak, which is our only other sort of open source competitor when it comes to, uh, identity providers. Um, that was seven years ago.
So he's been building this out for a, a very long time. Um, built in, built it in Python, it's a, a Django application under the hood. Um, I'd also, prior to that, uh, started Real Python, which is now a big community for, uh, engineers learning web development and so forth.
So we were tech aligned, uh, in terms of using the, the right kind of technology, um, making it easy for, for developers to use as well. Um, and he was building it all open source. So it's an open core company, um, authentic as an identity provider.
Um, you know, you can just download and use, um, for free. Um, and it also means it's all built in the open. So even our enterprise features are our source available.
And that just made a lot of sense to me. Um, you know, it's, it's almost like, uh, you know, would you choose a crypto library that's is proprietary and, you know, only hackers can examine it, and you as a customer don't get to, to have any say. No one's really reviewed how this works, uh, behind the scenes, of course not.
But that was kind of the state of the art when it came to, uh, I am. So the fact that Jens had built out a full fledged IDP from the ground up was starting to build a team around this, this really stellar, um, product. Um, you know, I, I realized that companies will also want this too.
Um, on the enterprise side, we were getting a lot of interest from folks saying, we need something that is secure, that is reliable, that we can host. We don't have to rely on you to be up all the time. We don't have to rely on you to make all the right security decisions behind closed doors.
Um, and so we've been at it a few years now, um, with a lot of interest from, you know, we have a million different, uh, home lab installations that we know of. We have very limited telemetry that's all optional. So, um, you know, we, we find out every week, uh, someone running authentic in production that, uh, we, we just get to find out about.
Um, and then on the enterprise side, you know, a lot of big companies and, and agencies and institutions, uh, starting to, to run authentic at tremendous scale. So it's been a fun journey. Absolutely.
Lot to unpack here. I I just wanna try to get this into, you know, how you eat the elephant, right? One bite at a time.
Yeah. I wanna get this into bite-sized chunks for our audience. First of all, when we talk about authentic, the product versus authentic security, the company authentic, the product is the open source project, if you will.
That is just what we say it is. It's open source. Anybody can download, use it, and it has the same positives and negatives that, you know, millions of other open source projects do, right?
Yeah. So the, the vast majority of authentic is MIT licensed. Uh, you can use it however you'd like.
There is a separate, essentially enterprise folder of code in there, uh, which is part of, you know, how the company survives and makes money. Um, sure, but is focused on all of those features that you probably need as a large enterprise, but as a home lab user, uh, you know, wouldn't provide, uh, much value in most of the cases. So it's kind of an open core model, if you will.
Exactly right. With a freemium adar. Um, let's let, if you don't mind, our audience, as I told you, is technical.
First of all, when you say a home lab user, what about the S-M-B-S-M-E market? 10 users, 25 users? Do they need that enterprise functionality?
Some of it, all of it, none of it Sometimes. Um, so if you're talking about kind of a, a mom and pop shop, they're probably fine using Google Workspace or something like that. As they start scaling up, having more complex needs, uh, they might need something like authentic to tie all those pieces together.
Um, but we have had a number of small specialty teams, uh, that, that also want to tie into some, you know, a, a customer's active directory or, uh, they just have, you know, maybe they're in a, a cybersecurity space or a particular country or particular vertical where they have, um, data concerns about sharing that with anyone. And so running authentic locally, or even air gapped in some cases, um, can be useful even for very small teams if they have those, those kind of specific requirements. Excellent.
Now, Fletcher, what are the, so let me back up. com for 12, 13 years, security Boulevard Cloud native. Now, I'm, I'm very familiar and I've been involved in open source 25 plus years, so I'm really familiar with the models and, and everything else.
I, I wanna first dig in technically and ask you, and, and I'm familiar with IAM, right? I, I've always felt that that was the, the killer app of cloud security, right? That was the biggest difference.
Most of my security experience was free cloud, you know, as an entrepreneur. And so was the Moten Castle error cloud changes, all that. IAM becomes the, you know, focal point of, of your security posture there, I think.
Anyway. Um, when you say enterprise class functionality for the authentic, uh, program, what are, what are we talking, you think? Um, so there are specific integrations, um, you know, a significant, a significantly large enough company.
Uh, you might have multiple IDPs in play. And so sort of orchestrating across those, or dynamically migrating off of some legacy provider, um, their compliance requirements. So if you have government customers, you might have FedRAMP needs, we have a FIPs compliant build.
Um, also other auditing pieces we've just introduced, uh, an event map so you can visually see where different, you know, logins or other actions and activities are happening. Um, so those, those sorts of things. Uh, when it comes to scaling this out at an enterprise and making sure that you do so securely and in a way that you can, can easily manage ongoing, Absolutely.
Um, you know, you look at most open source business models, your modern ones, right? And they give away the, I mean, obviously the open source project's free, and there's some open core is a very popular, uh, model. Probably the most popular model is sort of, well take it from us as a SaaS, right?
And then, and so you convert that open source, uh, software, that open source project into a SaaS offering, you know, and people pay for you to maintain it, improve it, secure it, et cetera. I didn't hear you talk about that. Yeah, I'm not, so it seems like consciously, I'm not saying it won't happen.
Uh, we've, we've laid most of the groundwork to help support that. Um, but somewhat to our surprise, we've had just a tremendous amount of interest in self-hosted ia. So these are folks who are worried about reliability, worried about security.
If Okta or Ping or whomever else, uh, entra goes down and none of your employees can access anything right now, the state of the art solution is, well, you should train up and purchase two different IDPs and a third product that orchestrates between them and have a failover that's just too complex and too expensive. Um, so being able to run authentic on-prem or in your own private cloud where the rest of your infrastructure already lies, um, you know, we have cloud formation templates. You can run that very easily in AWS or other standard providers.
Uh, you could do that cross region. Um, but essentially you as the customer now get to choose what kind of reliability are we looking for? What kind of usage are we expecting, uh, and have a lot more control over that, uh, in a, in a much more cost effective way than saying, I am as a service.
I hope it works. Right. Excellent.
Um, you know, the mission of IAM has expanded, right? I, I think for a lot of people, you know, when they hear IAM you mention some of the players in there, right? Like TER and, and so forth, you think single sign on, right?
And, and sometimes it begins and ends right there, but there's more to IAM today, right? You, you mentioned, uh, uh, active directory integration or, you know, the, and Active directory is not the only directory out there anymore, right? Uh, JumpCloud another company I'm familiar with in, in the IAM space, right?
Uh, kind of a cloud-based directory, if you will. Um, when we talk about modern IAM in, in, you know, in one authentic does give us kind of the spectrum of, of what's in there. Yeah.
I think there, um, a couple dimensions there. One is, there's a broad set of standards and protocols. Um, so if you're speaking Skim or OIDC, you know, using Web Auth with ideally hard keys of, of various kinds and, and you know, those levels of security and integration with, with other systems, um, there are just a lot of languages to speak there, a lot, a lot of protocols to speak.
Um, uh, so I think that's, that's kind of the, the broad base of being an IDP today is not just can you do an OAuth handshake, but can you very flexibly support all these different pieces. Um, even to the point of, as you mentioned, starts with SSO, some applications haven't gotten that far. Can you do a reverse proxy and support some of these legacy apps behind SSO, um, but then still maintain, you know, group ownerships and so forth.
Um, so there's all of the, our backside of, you know, now how do we manage across different teams, different sub or organizations and so forth. Um, so something you mentioned toward the start, I think it's becoming even more difficult and more important as we get more automation, uh, as we get more service accounts. If you're thinking of, you know, your, your, uh, bots on your behalf, having access to who knows how many applications, um, so being able with authentic, to use Terraform, to use, you know, short-lived service accounts, things like that, that actually integrate directly, um, with your various applications in a very seamless way, uh, is, is core to every business now.
Um, so that's also why, you know, everything you could do in authentic, you're not just clicking through a gui. You can, but it's also an API on the backend. We want all of our customers to be able to automate as much as possible to use infrastructure as code, uh, to, to be able then to not have that, have that lock-in and say, we're going to host it over here now, or we're going to switch this up, but in an assured way, uh, do, you know, a, a seamless migration from another service or whatever that, that next challenge might be.
Excellent. You know, Fletcher, I, I don't think we, ra we mentioned the websites URLs. Sure.
Uh, so if you just look for authentic with a k, uh, A-U-T-H-E-N-T-I-K, uh, that will turn it up. io. Um, but, uh, you know, you can find the project that way.
Obviously, there's, uh, a lot of traction on the GitHub page as well. Um, we Were the, I was gonna say, I'm sure it's on GitHub. Yeah.
Yep. Uh, a few months back, we ended up as the number one trending project on GitHub for a while. So really got a lot of That's Cool.
That's, congratulations. Lot Eyeballs from that. Yeah, Absolutely.
Very cool. Um, you know, we haven't really mentioned ai. How can we do an interview without mentioning ai?
What, what's the role, if any, for AI here, Fletcher? I, I alluded to the bots. Uh, so, you know, if, if you have a lot of service accounts or agents, um, you know, acting on your behalf, uh, obviously you're going to want to secure those in the same and possibly more flexible automated ways.
Um, so being able to, to support that with authentic is very important for us. Um, that said, from our side internally, we're not looking to shove AI into features of our, our IDP, just for the sake of, uh, saying, uh, us too. Um, you know, we're, we're certainly trying out all the latest and greatest tools in terms of development, but, uh, we also see the value in, um, careful human coding and human ingenuity still.
So, uh, you know, we'll, um, we'll be a maybe a little more conservative than other folks to, to start announcing AI powered this and that. Uh, I think a lot of our customers are, are feeling, uh, a little wary from the amount of, of, uh, AI that's being pushed upon them from their own products. Absolutely.
Say that again. Amen. Anyway, Fletcher, we're about outta time.
I want to thank you for coming on Textron tv today and, and getting us a little smart about authentic and authentic security. Keep up the great work. Come back and visit us again soon.
Will do. Thanks so much. Alright.
Fletcher Heisler, CEO, authentic security here, ATech Strong tv. We're gonna take a break and we'll be back in a moment. Hey guys.
Thanks, Withrow. We're here with Bill Waki, who's a principal architect for quantum computing at SaaS. And we're gonna be talking about well, quantum quantum ai and what the quantum advantage all that adds up to.
But Bill, I'm gonna let you explain to folks what that is. 'cause I think everybody hears those terms and nods their heads, but I'm not entirely sure everybody knows exactly what they mean. Great.
Mike, uh, thanks for inviting me on to your show. This is, um, a great experience. So what is quantum ai?
Um, the way we define it at SaaS is it's a combination of quantum machine learning and, and quantum optimization. And currently quantum computing is similar to computing, was in the 1970s and early 1980s. Um, anything that we do with quantum, a ai, AI or optimization is gonna be a hybrid method between classical and, and quantum technologies.
Um, which brings me to the concept of quantum advantage. Um, every now and then we hear about a news article that this company solved the problem in a fractional amount of time in a classical, uh, computer or, um, you know, solve the problem that a classical computer just cannot do. Those problems typically are designed for that purpose, and they're not real world problems.
At SaaS, we are concentrated on solving real world problems for our customers, um, which allows us to be, be a little bit freer in the way we define quantum advantage. Is quantum advantage about the amount of time it takes to solve a problem? Is it about the ability to represent, um, a problem structure in ways that a classical computer cannot?
Is it simply about, um, the, the, the savings in the amount of power that a quantum computer has over its, um, you know, GPU counterparts? So that's really, you know, when we talk to customers and we talk about different problems and we define quantum advantage, it's really tailored to, to different types of quantum advantage, not just about speed. Mm-hmm.
When people think about quantum computing, they still think of it as largely theoretical, but are there use cases now that people are working on that are making a real world difference, as you noted? Yeah. There, there, there are many use cases.
Um, probably the low hanging fruit of use cases are optimization problems. Quantum computers lend themselves very, very well to, um, finding global minimums of optimization problems. And, uh, that was really the beginning or the, the, the primary, um, area that quantum computing showed some sort of advantage or some sort of benefit when combined with, uh, classical solvers.
Other areas that are, are up and coming, um, and a lot of research is being done in 'em is quantum machine learning. Uh, you can think of quantum machine learning as, you know, special types of optimization problems. Uh, we're doing a lot of research in quantum reservoir computing and, and quantum neural networks, variational type of problems.
And by those, uh, I mean that they are, um, variational in the sense that they are going back and forth between quantum computing and classic computing. Uh, another big area is molecular modeling. Um, protein folding things that need to be represented in a much higher dimensional space than classical computing can do by itself.
Uh, going back to quantum machine learning, you know, the, the funny thing about that is that it's, it's industry agnostic. Banking uses, you know, machine learning, um, sciences use, machine learning, marketing uses machine learning. So it's a similar sort of algorithm that goes across all different disciplines.
We keep thinking about quantum computing as kind of like some isolated second coming of a mainframe, and it's gonna be used in some sort of unique application. But to your points earlier, I feel like maybe this whole situation is gonna be much more hybrid and maybe we'll have classical computers kind of connected to quantum computers, and there'll be AI on the classical computers invoking quantum. I mean, is that how this is gonna play out?
Or is that an a, you know, what I might argue could be a gross oversimplification of that relationship, but how will these things come together? No, I mean, you're right on. Um, with saying it that way, it, it's similar to, um, tools in a toolbox, right?
You, you don't walk into, if you're a contractor, you don't walk into a job site with just a hammer. You walk in there with a many different tools. And, um, each tool has a specific purpose.
But together, those tools help you construct a house. So it's the same sort of thing with, um, with computations, right? We have CPUs, we have GPUs, we have qub for quantum.
Um, there's even, you know, things like LPs, you know, laser processing units as well. And each one has a, a very specific purpose. We're not gonna just use quantum computers, right?
They're never gonna take over computations. They're gonna be used in conjunction with, um, all these other different types of, you know, PEs, right? It's just gonna be another tool in toolbox.
And the idea is to have quantum do what it's really good at. There are certain problems and certain representations, um, of problems that quantum excels at. And that's the, you know, the, the, the thin slice that quantum would be used at it, almost like an accelerator.
Mm-hmm. What's your sense of how affordable will quantum computing become, not just today, but over the next, I don't know, let's say five years? It does seem like we're making some progress on the hardware these days, but is this gonna become more affordable?
I mean, or is this gonna be even someday, I don't know, uh, an API that I invoke a cloud servicer? Well, it's funny you say that because the quantum computers, people are typically not buying quantum computers. You're not gonna find too many organizations that own a quantum computer.
Most of quantum computing is happening through a cloud API. Most of them happen. Like, for example, IBM has their own cloud.
Um, you have AWS, you have Azure, you have Google. Um, that's all happening through, through cloud calls to the quantum computer and getting the results back. Um, as far as costs go, that remains to be seen.
It, it could cost a lot of money to run, um, jobs in quantum computers. You know, I, I could give you an example. Um, you know, if, if you have a, a quantum circuit that you need to run and you need to test it, and you're designing it and you're testing the output, um, you typically will run that job, you know, you know, 10, 15, 20 times.
It may be even longer more to, to, to narrow down what your parameters should be or what the circuit should be, should look like. Um, each job has a, you know, you, you, you can't run the job once, right? Quantum is not deterministic, it's probabilistic.
So you need to get a probability distribution of your results. So running it, once we call that a shot is, um, is useless. You need to run it, you know, thousands of times.
So that cost could increase, um, dramatically because you typically will get charged by the number of shots and by the number of jobs that you run. So, uh, what we typically do, um, at, at SaaS at least, is that we will do all of our designing on simulators and emulators. Those are locally hosted simulators and emulators that simulate the quantum processes or emulate the noise, um, distribution in a quantum computer.
And then when we narrow down what our algorithm should look like, then we will run that on the quantum computer. Hmm. Will it get easier to build quantum applications?
'cause I don't have a sense that there's some magic quantum compiler out there, but maybe there is, but how will we build these applications? Well, you know, it's, it's interesting you say that every, and, and that's something that we're thinking about at sas. Uh, every vendor has their own Python software development kit.
Every, every vendor has their own API. So in a sense, you know, there's a quantum language for every quantum computer or every vendor that makes a quantum computer. What we're trying to do is we're trying to, you know, do all of that work behind the scenes.
So customers, um, don't necessarily need to know every single Python, SDK, they could really, uh, use the SaaS language or the SaaS framework to run quantum jobs, uh, without need needing to know the intricacies. So I guess the, the short answer is, um, there's a tremendous amount of algorithm development that has to occur, but that algorithm development, we try to shield from our customers. Hmm.
Also, there's a lot of countries in the world investing in quantum. I mean, is this becoming, or does it need to become more of a national priority? Do we need an actual strategy for this in the us or I'm assuming other countries may be a little further ahead on that, I'm not sure.
But is this something we should be discussing at a higher level? Well, we actually have a national quantum initiative. Um, you have a national quantum, uh, act that was imposed years ago.
Uh, a lot of these national, um, initiatives, every country is kind of building one, but most of them are designed around quantum encryption. Um, you know, that quantum computing was theoretical back when I was in graduate school, and I remember reading about it, and we were talking about, you know, early two thousands, late 1990s that I first read about it. And an algorithm came out by Peter Shore from MIT called Shor's Algorithm.
That, you know, long story short, it's, it, it, it could break RSA encryption theoretically with, if you have enough, a large enough quantum computer, it could conceivably break, um, RSA encryption. Well, that kind of lit the fire, you know, under all these governments say, well, you know, all of our encryption from banking, from everything is going to, has the potential to be decrypted at some point. You may have heard, you know, har, you know, harvest now decrypt later, you know, you know, they, they steal all the information.
They dec the hopes of decrypting it later. That became a real fear. And that is kind of what led to these quantum initiatives to come up with, um, quantum safe encryption algorithms.
We call 'em post quantum encryption or, or even quantum key distributions. So I think that's kind of what brought quantum to the, to the forefront of people's minds. But with that being said, all the other use cases around quantum, um, is they're currently actively being explored by governments.
Mm-hmm. So what's your best advice to organizations then, right now? I mean, do I set up like a little quantum computing tiger team now?
Or do I have an r and d unit? How do I kind of approach this? Well, if you're gonna do quantum in house, I think that you should, uh, you know, there's two ways of doing it, right?
One, you know, I I I use the analogy of, of a pool, right? You know, you could wind up going to a pool party and then, you know, just jumping in the pool, right? And you could just jump into quantum, right?
You could hire a team, you could build up your, your workforce. And the other way is, you know, you kind of put your foot in, right? And, and you kind of test the waters, and you do it slowly.
You bring in a couple of people, you start training them, you create partnerships with universities. You create partnerships with quantum vendors, you begin to learn the, the landscape, but you can't, you know, spend the entire night at the pool party, just, you know, putting your foot in, because at some point that party's gonna end. Then you will not have jumped in the pool.
So you don't want to, you know, you know, be in slow motion this entire time. Because, you know, what companies are doing is they are investing in, in either it the all in method or, you know, the slow method. But right now, the, the idea is to get the IP right, get the patents, get the publications, own the ip.
Because at, at some point, um, when Quantum Day comes around, when quantum computers can handle large problems, when there is, you know, you know, quantifiable advantage, uh, you don't want to first jump in the pool then, right? You're, you're, the party's over. You're too late.
So you wanna start doing the research now, the development, now building your, your, your IP now. So when those quantum computers come, you're ready. So, if you look into the future, are there things that you think that we'll be able to do that previously were just unimaginable because we're gonna figure out how to, uh, take advantage of quantum computing.
I mean, what are you looking forward to? The imagination runs wild with quantum computing. You know, it's funny 'cause like, you know, I'm, I grew up in the 1970s and 1980s.
I remember, you know, my first, you know, Commodore Vic 20, right? It was just a keyboard you plug into a TV and five, they had like five KA memory, and you put a tape in there, you and, and you, you know, you loaded your program, you waited a half an hour for your program to load, and then you hit run, and then it failed on a syntax error on line 14, and nobody knew what to do with it, right? It was a very clunky system.
Nobody ever, in a million years back then would've thought that those computers would have evolved into the fact that we're having this discussion now over, you know, the computer. Um, the same thing with the internet, right? I remember when, you know, the 14 K board modems, remember war games back in the mm-hmm.
Early days where you put the modem on there, you had all those sounds and, you know, you just got text. Nobody would've ever have imagined that I would not have a cable box in my house anymore and be streaming everything through the internet. Um, I think asking that question, now, you can make a best educated guess, but who knows, right?
I mean, what the future's gonna bring, just like back then, I never would've predicted, you know, what things are. And we're at that sort of horizon where it's really exciting and the imagination will kind of dictate where we wind up. To that point, some folks would say, maybe we're a little overly obsessed with AI and not paying enough attention to other innovations like quantum.
I mean, do we need to kind of recalibrate a little bit? Or what's your thought there? I think that, I think ai, um, you know, I think that is very, very important.
And I think it, you know, it's, it's justly deserved, right? I mean, you look at some of these la large language models and, you know, the amount of work that they save in development or any, or research is tremendous. I think that AI is, is very important.
And I don't think that resources should be taken away from it, but I think that quantum computing is, you know, is the next big technological thing. But like, you know, AI will run with quantum computers, so, so they're not separate. You wouldn't take, you wouldn't divert resources necessarily from AI to Quantum, or you wouldn't, um, pay more attention to one or the other.
I think they're gonna work together. I think that, you know, for example, you could use AI to optimize and build quantum circuits. So they work together.
You know, there's research being done in, um, using Agent ai, married with quantum optimization. There is, you know, I don't think there, they're two different things. I think that as they both develop, they will come together, um, closer and closer over time.
All right. Well, folks, you're hearing it here. I think we're all rightly amazed by all things ai, but to Bill's point, you ain't seen nothing yet.
Bill, thanks for being on the show. Thank you. All right.
And back to you guys in the studio. Hey, everyone, welcome to Control Alt Deploy. This is episode two, and we're glad you've joined us.
I'm Alan Shimmel of Techstrong Control. Alt Deploy is a video show we do with our good friends at OpenText, where we talk about cutting edge, leading edge stuff, topics around DevOps of all things. Um, we're really glad you're joining us.
We have a great panel. How often does this happen? I'm the only guy on the panel.
I have three amazing women to introduce you to. Who, who are on our panel today. Let me introduce you to them right off the bat.
First of all, joining us, uh, from New Mexico. She's the CEO of Deploy hub, open source, CDF board members, uh, on several boards, our friend JC Reagan. Hey, Tracy, how are you?
I'm doing great. I was gonna mention this. I think that this is the first time I've been in an all female panel.
It's very cool. I love it. Did not that I don't like the, the dudes on the panel, as I'm not saying that.
It's just is extraordinary. It's all women. Yeah.
Now, you know, we didn't plan it this way, to tell you the truth, but hey, more power to you. Good for you guys. And it's, it's, I, I feel flattered to be here joining us from Canada.
She runs the, uh, one of the leaders of the Canadian DevOps community, but really a worldwide, uh, person in the DevOps world, as well as top contributor at the CDF. We've just been informed, my good friend, Garima Boal. Hi, Garima, how are you?
I'm good, how about you? Excellent. Glad to have you here.
And then last but not least, he's from OpenText, Hillary Johnson. Hillary, welcome to Control Alt Deploy. It's great to have you on.
Um, I give a little bit of background. Um, I'm sure I was Gonna say I'm the new person. Tell us.
Yeah, I'm The new person. I'm the senior industry strategist here at OpenText for manufacturing. I've been in manufacturing for 14 years now.
Um, and so I've got a vast background from really small job shops to really large enterprise like me, medical devices. So been in this for a hot minute. Got it.
I appreciate you being on. So, so panel, today's, uh, title is, uh, compliance and code security and DevOps navigate regulations and supply chain risk with ai. Well, everything's with AI today, but really as we get into it, it's a how can, how can our DevOps teams and, and let's not just confine IT to DevOps team.
It could be platform engineering teams, developer teams. How can we stay audit ready and secure the software supply chain, you know, leveraging things like AI and SBOs and of course automation. And, you know, this was a hot topic before AI was hot.
Of course, we weren't talking about using ai, but securing supply chain has been a problem. Certainly, you know, it first burst on the scene, I guess, with the SolarWinds breach back during CO, right? Where there was a, some malicious code inserted into shipping product.
Um, Tracy, I know you spend a lot of your time focused on this, where, you know, has AI changed the game here for us? Where, where do you see Poten? Where do you see progress?
Where do you see we still need to make a lot more progress? Um, well, um, before last week, I would be far more optimistic. Um, uh, I was at CD Con and we did a, a, a focus group around CICD cybersecurity.
And I discovered that many of the DevOps engineers are not interested in adding security to their pipelines. In fact, they're flat against it. They don't want to do it.
Um, and that's because I, I don't think that there's, maybe, I don't know what the reason is. I don't think they wanna be disrupted. Again, I don't think they wanna touch their workflows.
Uh, so we have some work to do in DevOps around the understanding of why security is important. You know, I, I keep my foot in two different worlds. I'm on the board of the open source security foundation, so I understand and hear what they're working on.
I know about their new tooling, like proto bomb, and then I have the other foot in the, in the C station, and I'm on their technology oversight committee. And I see that there is a very, very large gap. I'm practically doing this place here, folks, between the two worlds, because there is such a wide gap.
Um, at our focus group, one of the most concerning things that I heard, but I heard many of them, the, the first one was, they don't believe that SBOs are important to incorporate into DevOps pipelines, because they're not always accurate. They're just a checkbox. And without consuming the data, it's useless.
Which I agree, that's why Orillia is around. We're consuming that data and making actionable. But the point is that they don't see a strong need for securing the code base through the CICD pipeline that somehow is an engineer's job, a software engineer's job, and not something to be automated.
And I, you know, this, this concerns me because if we're not looking at disrupting ourselves, we will be disrupted. There will be younger people come along and do things differently, and AI will be part of that solution. There's just no way to stop it.
It's a freight train. Get off the tracks. Yeah.
Gima, I'm, I got to tell you the truth. I'm, I'm shocked. How about you?
I'm not that shocked. I think that, you know, I understand where Tracy's coming from. I am also associated with the Cortes Delivery Foundation.
We have a lot of ambassadors who are trying to steer the needle in the right direction. And I also see that Tracy is heavily invested in, uh, open source security. But I understand, uh, the community kind of sentiment and, you know, not overlooking the recent past.
Right? You mentioned about SolarWind. We have seen log four js, and we have seen ex uh, Z back doors, you know, so the regulatory pressure is intensifying on us, whether we see it or not, right?
Regulations like EU Cyber Resiliency Act, or even the NIST two in Europe, or executive order in, you know, us. I think they are all reflective of the fact that we have to take security seriously. And sbo, OM is comprising of one of the biggest pieces of the puzzle when it comes to contest monitoring, the vulnerability scanning, and maintaining that transparency in the system.
So I would like to have more discussion on this topic and, uh, raise awareness and see how, what we can do from a practitioner's point of view, community point of view, to ensure that we, uh, move the needle in the right direction. Hillary, help us Labor shift going on right now, right? You've got old labor kind of coming towards the end of their career, younger labor, who doesn't quite understand some of the, the trades or some of the manufacturing world.
Um, and they're looking for new tools. So I think it's gonna be, at least from what I can tell, is there needs to be a shift in thinking from upper management and from owners, and even SMBs. You know, nobody likes change, but it's inevitable, kind of like cybersecurity was when you were breached and, and manufacture, I know from a manufacturing point of view, they didn't think it was gonna happen to them.
Um, and so they, their, their guard was down. So eventually, maybe it's, you know, um, where they need to see it, that it's happening to somebody else, or, you know, okay, I, it hasn't happened to me yet, so maybe it won't happen to me and I can focus on getting some other things done with my business. And so there's, there's gonna need to be a shift with the different kinds of people who are coming into the business full stop.
Um, and whether or not you like it is one thing, um, that's, I mean, my 2 cents, but kind of it needs to be a shift in mentality. Well, we, that, and now part of the problem, we've been shifting. We've been shifting left, shifting, left, shifting left, shifting left to the point that DevOps engineers are not shift, they're not left, they're not software developers.
So we've been pushing it all to the software developers and the DevOps engineers are like, that's not our job. We shifted all that to the, the, the developers. They're the ones that should be protecting their software supply chain.
But that's exactly the point. It's not the software dev software developers want to develop quality code, but they're not security experts either. It's the security people or the security experts.
But that's one of the, you know, I was at while you were at the Open Source summit last week, I was in New York at the platform Engineering Con. And, and that's, you know, what a, what a dynamic community with lots of buzz and lots of, a lot of young people, to your point, Hillary, right? A lot of young people coming in here.
Even though, you know what was funny? I interviewed a lot of folks that were closer to my age, and they said, I've been managing platforms for two, three decades. Managing platforms is not a new discipline.
Calling it platform engineering maybe is newer, but managing platforms is what we've been doing. And I think one of the reasons that platform engineering has struck an a chord and, and gotten as popular is it has, is that part of their, not manifesto, but part of their reason for doing it is you can't just keep shifting left and saying it's the developer's job to do. Developers want to develop, right?
Developers want to develop code. They're not security people. They're not DevOps engineers, nor are they platform engineers telling developers that you're responsible for security.
Oh, and by the way, you're also responsible for building the platform that you develop on because we're shifting everything left. Well, that's not, that doesn't scale, doesn't, when you get, when you get to enterprise levels, that doesn't scale. However, I am surprised to hear that DevOps engineers would wanna sort of abdicate their responsibility in terms of, because it, in terms of secure code, because it's not just the software engineer who makes sure it's secure code.
What about testing, right? That to code, code needs to be tested. Whether it's, it's whether the code's written by AI or people or both, it needs to be tested, right?
We, there should be a pride in what we are in what we are doing at our jobs where, no, I'm not gonna release shoddy code, I'm not gonna release insecure code, I'm not gonna release code that doesn't comply with regulations and compliance. Right? I think what we're hearing is more what Hillary said is it there is sort of an old guard that wants to stick their head out the window and say, I'm fed up and I'm not gonna take it anymore, right out of a movie.
And there's also a lot of people in, in the workplace who, you know, this is their fifth disruption in the last three years. And, and they're shell-shocked, right? They just want to dig their heels and, and honestly, I'm fed up, I'm not gonna take it anymore.
But progress waits for no person, man or woman or what have you, right? No person. And so they could, they can protest all they want.
That doesn't mean that SBOs aren't gonna be required. That doesn't mean that AI is going to stop writing more code and having as big a, a bigger impact. Wait, wait till the agents come in, right?
We, we, we spoke about that earlier in our episode, one of control alt Deploy. And I apologize, Tracy Hil, you weren't on that episode, but Gerima was on with me. And, and, um, you know, we spoke about what agentic AI is going to mean for DevOps engineers, right?
So thinking your head in the sand and your head and your, and your heels in the sand, I don't think that's a, I don't think that's gonna work here. Yeah. So I think what I, what I, what I saw, what, what in that meeting, uh, was a lack of curiosity.
Um, because I am one of the most curious people. I know, me and Brian Dawson were kind of OCD about things, and we'll get on something and we really will research it and have fun playing with it and trying to understand it. And I, I saw a lack of that curiosity in that group.
Um, and I understand that they probably have a lot of work on their plate to keep those brittle workflows up and running. And the thought of trying to create something new, maybe an overwhelming task. But what one person said, struck with me, stuck with me, is he said, PE people will start generating SBOs when their bottom line depends on it.
And he was a company servicing the, the, the public sector. Uh, he said, we don't have a choice. We have to, but we still fill, it's like a checkbox.
And I could submit the same SBO over and over and over and nobody would know the difference, which is a true fact. Totally true. So that, that is true, right?
Yeah. To me, the SBOs always seemed like the tag on my pillow, that if I tear it off, it's a federal offense. But whoever reads what's on that tag, right?
And I'm always eager to tear it off just so I can Break the law. So that's, that's the kind of person you are. Exactly.
Who else here, Hillary? Do you pull the tag off? What?
Do you read the tag? No, I don't want the tag in my ear if it pops out of my pillowcase. Um, uh, I think, I think the thing is that is so true.
People are learning AI out of necessity. I learned AI out of necessity. 'cause I was doing the job before people, so as we're, as all of these comps companies are still running lean, they're gonna have to figure out that, that to date their, their heels in and start testing it.
I think the other thing about AI is it's not a hundred percent accurate. Um, right. You know, so you've got that, that cautious behavior behind it.
Like, well, what if it isn't? I can't trust it fully. Yeah.
You still need a person to verify some of this stuff. And so how do you, how do you start progressing, um, still knowing that there's, you gotta have somebody who, who's checking all of this. So, um, just 2 cents.
I, I agree. See, so Tracy, I'm more like you. I started using AI purely outta curiosity.
Now I find it an indispensable tool. Me too. To your point.
Yeah. To your point though, you were doing the job, you had to do the job of four people, so you had to use AI as a force multiplier. So I was reading an article, I think I mentioned in the earlier episode, uh, mark Benioff from Salesforce claims that maybe up to 50% of the work being done at Salesforce now is being done by AI and agents and stuff.
I don't know if I believe that to tell you the truth, but that seems, you know, is, is this where we're heading? Are we, let's say it's not 50%, is it 25% Garima? You talk to people in DevOps all over the world, there's more than anyone.
What do you, are we, are we already using AI that much? As I said, uh, in the first episode, I will stick to that. I think we are in the experimental phase for ai, right?
I mean, we are using AI for experimenting around a lot of productivity and efficiency gaps, which we have, right? And then we are also thinking about using it in different dimensions when it comes to like, um, exponential scaling. But we are not yet there.
And I, as I pointed out earlier in the episode as well, that, you know, when we look at things around, you know, we are building things with ai, like what type of code are we referring to? What kind of enterprise we are, like comparing it to? Because if it's a large enterprise, we have lot of legacy, uh, systems, right?
So it's not easy to refactor, rebuild, you know, repurpose code, um, even for humans. So, I mean, AI is, uh, something which we should have a secondary thought on. If you are an AI native company, you are building an AI native platform, I would believe that there is a substantial amount of, you know, excitement, enthusiasm, as well as potential what we can do with ai.
But again, you know, uh, we haven't substantiated this. Nobody has product defined it in a larger scale. So we don't know how much technical depth we have built around this, right?
So there's a lot of questions around, you know, how AI is enhancing the productivity for DevOps pro professionals. This is yet to be seen. Hilary, what about your experience at OpenText?
And don't say anything that's going to get us all in trouble, but, you know, is, is AI doing that much of the work around there? That's what part of the company you're in. Um, you know, from, from a marketing standpoint, probably more so, uh, really, um, yeah, very much so.
I mean, it does all the research for me. It, it, it writes a lot of stuff. It gets me started.
I'm not a writer. So, you know, there's plenty of times where I need someone to get, um, my thought process going. Um, you know, in a manufacturing, uh, in a manufacturing perspective.
I know of friends who have smaller manufacturing business. Let's take this from the size of the business. You were saying.
Enterprise has a harder time. 'cause they have legacy systems, they've got disjointed, you know, Salesforce, half the time, one's in Europe, one's in the us one, you know, they're all over the place. Um, smaller companies are really starting to explore this more.
'cause they have the bandwidth to do it. They don't have as many legacy systems. So I would say almost reach out to those smaller innovation businesses and see how they're handling it.
Maybe let them be the Guinea pigs, create some friends, create some networks, right? And figure out how they're using it, because it's gonna need to scale. Enterprises is incredibly disjointed and it, there's so many processes.
I think small, I think the smaller to medium sized companies are actually gonna kind of pave the way on this. And this is just my prediction if I get my crystal ball out that, you know, they're gonna be the ones helping this. Yeah.
You know, we saw this in DevOps, right? When DevOps first burst on the scene, there was this whole argument, is DevOps better for small medium companies where they have to do it by necessity? Or is it better in enterprises where you can do it at kind of great scale?
And, you know, counterintuitively, I I think it was both, right? It worked. It worked at both.
Now, if you talk to the platform engineering people, they'll tell you, it's when you really start scaling up that DevOps runs into scale issues. And that's why you, you can help with platform. But let me, let me put something else in front of you, the three of you, and see what you think about this.
If you are gonna believe that SBOs and, and like a lot of security, it's what we call checkbox security, right? Compliance is the least common denominator type of security. It's doing the minimum you gotta do to comply with whatever your regulations are.
But if, if SBOs are part of that least common denominator security that we need, isn't automating that with ai, the easiest thing to do then, because if, if it really is not that important, but we still gotta comply. Wouldn't I wanna just automate it and get it out of the way? Tracy, I'll go it to you first.
Yeah. Generate, generating an SBO is easy. We don't, there's many tools out there that will generate an sbo.
It's very simple, uh, command line to add to your workflow, by the way, folks, very simple as about as simple as they get, it's probably four words. So generating SBO m is not necessarily the issue. I think what the issue is, is touching the scripts and dealing with, um, any modifications to the workflows themselves.
That's the, that's the real issue. Unless it has real benefit. And that is the problem with sbo s yes, everybody should be doing 'em because it's the first step down the road, right?
But then there should be a second step. Evidence stores are important. Let's start gathering that information.
Let's start watching for changes in the SOM. What is different between this, this build and the last build? Are we bringing in new package versions that we were, um, that the, the developers have have updated now we need to make sure that the testers go through that.
Make sure that it's properly tested. How can we make the data actionable? If we do that, then DevOps engineers will be more motivated to use an s om, because it has a purpose.
Right now it's just a government regulation that says you have to have one. So why, if I'm a not, if I'm not delivering code to the US government, and I don't have customers who are demanding an SOM, why would I bother? I, I totally understand the sentiment.
I understand why I would bother, because I, I wanna know what, uh, I, I really do wanna know how compliant those packages are that I'm consuming because I'm delivering code to customers. So I need to protect myself. And the way to do that is to know, again, I'm curious.
I'm a curious person, so I wanna know what's happening. I wanna know what's coming through the pipeline, but not everybody is. And you know what's really gonna change DevOps?
It's when DevOps engineers are gonna start having to manage AI agents and LLMs, that means that they're going to have to change the way they, you know, our, our DevOps pipelines are pretty traditional still. The two, the two pieces that we do is we run a build, right? We take code and we turn it into binaries, create a container, and then we call a deployment tool.
We, you know, DevOps pipelines themselves don't do deployments, and they don't do builds. They call scripts that do that work, or they call external tools. So we're doing builds and we're doing deploys, and we're happy.
And that deploy may go out and may go out to testing, or it may go out to production. We don't even have to worry about that because the deployment tool deals with that. And most of the time we're consuming something that's a helm chart for that.
Or where we have GI ops, that's, that's supporting the de the, the deployment. So we really don't have a lot in the pipeline anymore. We just have a ton of pipelines.
Thousands of them. Thousands and thousands of pipelines. So when we start asking for things like what version of the LLM was used in this build, that's when they're gonna say, well, I don't have an AI bomb to tell you that.
And that's when we're gonna start seeing changes in the pipeline. In the pipeline itself. It has to be driven by a serious need that's going to motivate a DevOps engineer to dig into thousands of workflow files and start updating them.
Or guess what they might do. They might use AI to dig that. So they, And, and if it, if it checks the box, they will.
Right? If it's, yeah. If it's just a check.
Checkbox check, yeah. And so, you know, maybe compliance isn't the right driver, is what I'm hearing you say. I don't think compliance is, is something that they really are focused on.
The compliance is being forced at the dev, uh, at the shift left side, there's quite a bit of work that developers are doing. They're taking classes. They're trying to learn to write better code, make sure that they don't have stack overflow issues, for example.
They're working at that. But the DevOps pipeline, there is tooling that can be added to it that's not necessarily being added at the CD foundation's at our focus group, I asked if anybody knew what proto bomb was, which is a big tool that the CI that open SSF has been working on. Nobody understood what it was.
They had no idea. That's a big, there's a big disconnect between the two. And I wanna p point out that these tools are coming out on a very fierce, there, there, there's new ones all the time for security that can be added to the DevOps pipeline.
At the CD foundation, we're working on something called the CICD cybersecurity sig. We're putting up a website that will have defined for achieving, um, the software, the secure software development framework, for example, NIST 800, whatever it is. Uh, we're gonna, we have, we are working on every single task, and we're finding what open source tool could be added to the pipeline in order to achieve that NIST task.
Because dev develop DevOps engineers don't have time to go hunt down tools and understand exactly every single task that you have to comply with, which is numerous, and what tools you have to add for that. So we're trying very hard to understand what the DevOps teams are looking for. And what they're looking for is just gimme the information.
What do you want me to add to the pipeline? I don't wanna go sort out security. I manage the pipeline.
What do you want me to add to it? And how will it benefit you? So that's where we need to get to.
Fair. You know, I remember being a little boy in school and some sixth grade philosopher told me, all spaghetti is macaroni, but not all macaroni is spaghetti. Okay?
Bear with me. AI helps us with automation, but not all automation is ai, right? And automation is something we've been trying to do in DevOps from day one.
'cause the very idea of automation seems to at least, you know, the idea behind it is, oh, we could go faster because it's automated. We get humans out of the way. We, we can go fast.
It just runs as fast as it can. It's automated. And that's very much like AI is part, is a, you know, automation is a big part of one of the, the, uh, you know, the things that attract us to AI is it can automate stuff, take humans outta the equation and just do it.
And we've spoke in episode one, the difference between automation and autonomous, right? Is autonomous ai, AI does more than automation, right? AI could bring autonomy, AI can do, it replaces humans in, in so many in some ways.
Um, what about non-AI automation and DevOps helping to navigate compliance and regulation and, and supply chain risk? Is it all AI is, is that, has all automation now become ai? No.
Kareem, or I see you wanna talk or thinking? Yeah, I, I think, um, and, uh, you are right that automation is different from what we are seeing now. Because if you think about SBO management, for example, we can automate a lot of SBO management stuff, uh, in the CICD pipeline itself, right?
Versioning of SBOs, for example, vulnerability management scanning tools. There is also SBO M platform management. If you're a fan of PLA platform engineering, you could appreciate that.
But when we talk about ai, it is, uh, I would say there are four aspects which we have to consider, which is different. First of all, timing of when and how we are putting automation into the stream, right? So that is very important because when we consider secure by design with respect to ai, it makes a lot of difference.
You know, throughout the lifecycle, we are considering ai. And that, uh, also kind of helps us understand that why timing of security is important. Our approach is also another factor because, you know, automation is often reactive.
Um, uh, from AI perspective, we are more proactive, right? They anticipate and mitigate threats before they occur, right? Integration, for example, is another, uh, aspect, which is also different because we are not only considering code, we are also considering data processes and all other aspects of like, modern model training, deployment, as Gracie mentioned, you know, what version of LLM you have used in the pipeline.
So all those kind of things also become important. And lastly, I would say adaptability. Adaptability becomes, uh, more critical.
Because, you know, when you're talking about AI in the mix, it's more real time, you know, self-learning loops, you know, they, they can kind of enhance itself. So it's a lot of other factors which you have to think about. And again, that's the reason why I was thinking that, uh, you know, the AI integration and the, the, the journey of AI integration and SOM in security management is still at an experimental stage.
So I think RIMA used a very important word in that. And that's adaptability. So right now, we have, we have job schedulers.
Let's just, CI CD is all driven by job schedulers. Jens Jenkins, a job scheduler, harnesses job scheduler, they're job schedulers, and you pass things to them for them to execute and order. That is what we call workflow automation, right?
That is what we do. The problem is adaptability. Because of the fact that we use scripts to build that automation, it makes us less agile.
Even though we preach agility all the time, we ourselves are not very agile because we can't adapt easily, which is why we can't add a lot of security steps to the pipeline. So that takes me to why l uh, the potential for AI to manage our workflow instead of having a job scheduler. When we start moving into AI and having an LLM actually manage the workflow like a, like a cloud Opus four, then we can be more agile, we can be more adaptable.
We can ask it to change faster. So right now, humans are struggling with the, with being adaptable and changing what AI has an could offer to DevOps in the future, or platform engineering, whoever takes it on first as a more adaptable way of managing the automation. That's where we're stuck.
Fair? Fair. Sorry, as I'm listening, um, I'm thinking about machine, uh, monitoring and lens learning, and then what is, what can come from that?
So, you know, when you have a lot of information coming in machine monitoring, it's just putting the data out, and then you have a human who's, who's reading that information, the next step then is to take that information and have, um, your AI then analyze that information and say, oh, I'm seeing a forecast here, or I'm noticing a, a trend here. And then you can align it with things that are going on in, in the natural world. I, I'm wondering if it's just a lack of like, curiosity, like we're saying, and they don't even know that there's this capability out there.
As I've talked to people about ai, one, the biggest things, I, I talked, I talked to the president of an old company I worked for, I was 3D metal printing. He's fantastic. But I, he asked me, he said, Hey, how can I use ai?
And I was like, you were one of the smartest, you're, I mean, really, really smart gentleman. But we had a lunch meeting and I said, this is how you can use it, personal and professional. It goes a whole, I didn't even know.
And the amount of platforms out there. So I wonder if it's more or less like opening it up and saying, here's what the actual capabilities are, versus just saying who's gonna take it first? Maybe you point out both you, you, your PO particular position can do it this way.
And here's an example. I just think it's lack of understanding a lot of it, um, and not actually knowing what the different capabilities are because they haven't had the time to jump in. Everybody's working lean.
Um, so sorry, 2 cents there. It's almost, it's a progression one, right? You get, you get in all this data, but what are you gonna do with all that data?
Right? We got data everywhere. Everywhere, right?
But I think a lot of it is maybe they just don't know what the capabilities are and they need someone to show them. Well, and, but also their attitude. You gotta be open to learning about the capabilities.
I'm sorry, go ahead. Jacey. We, we don't keep data in DevOps.
That is a big problem. We, uh, so the data that we keep in DevOps is stored in log files. Okay?
Um, sometime they're checked in, but generally they're probably left on the, in the directory where the, the deployment was, uh, executed or the build was executed. Uh, we don't even create, uh, historical records of how, what a, a workflow look like when it executed. That's not stuff that's a DevOps pipeline, uh, gathers.
So we have a problem with actually implementing AI around DevOps with a lack of, of data. So we can't, so let's say we are, we take a large company, I don't know, standard oil, whoever we wanna think about and watch their DevOps pipelines over the course of time and store that information in an evidence store, we could absolutely start watching a model and, and having that model make predictions, but without the data, we struggle. Um, so these pipelines don't have that kind of information.
Now, what we do have is we have workflow files that are checked into gi. We have, um, build files that are checked into gi, we have palm files that are checked into gi and we have, uh, helm charts that are checked in to get, and the, the existing models can go look at those to regenerate things for us, right? But we don't have historical data to do predictive work because we are, the data is fragmented in log files everywhere.
Every tool has a different log file. They just get stuck in the director that they executed. And we're not doing anything with them, kind of like an bum, exactly.
Like an S bum. So without that, we as DevOps engineers are going to struggle with having the ability to do anything more than generates a, a new helm chart or a new, uh, work profile from ai, which you can already do today. You know, God helps those who help themselves.
And I think people, I think there are so many things that AI can do for us, not take our jobs or replace us, but augment us and extend us and make our lives easier, better that, you know, there's gonna be, there's going to be people who work because of ai, and then there's gonna be people who don't work because they just don't want to recognize the ai, if you will. So I would, uh, also add something here, because we have been talking about this for a long time, that, you know, there's a la lack of awareness at every level that, you know, how AI is adding value to our ecosystem as a software developer, I did a talk, uh, at, uh, DevOps con, uh, in Berlin, and I started with this, that in 20, 35 years down the line, do you think that your software development, uh, would look the same? Is the job the same, you know, five years down the line, what could change and what will be the challenges and risks?
And when you start thinking about it, there is like a change in how practitioners would see, you know, software development and what skills are needed, how teams will be structured. Because there will be, if you like it or not, there will be a lot of AI assisted software development in the ecosystem. There will be teams where you'll have like five code assistants as well as, you know, four senior devs in the same team.
So how do you cope up with that? And then from an enterprise perspective, do you think that all the big bank changes which are happening, they're not human led anymore. They are AI led micro changes which are happening in the ecosystem.
You know, if you open your eyes, you see you, you're using copilot, you are using, you know, all these tools and time has come, you know, people have to realize that their job is changing. So now you have to think about your left hand side and right hand side of the brain, like what needs to be getting added to your left hand side of the brain, which is like creativity, you know, like your co-creation with AI tools and capabilities and right hand side of the brain, like what computational logic, statics stakes and LLM models and all those kind of things, which needs to be up, uh, you know, upgraded to your skillset. So this is like, you know, this is a self re reation, you know, you have to think about what, how the industry is changing and what is in for me as an individual, as a team, as an enterprise, right?
As a leader. Agreed on. Hold on.
Yeah, you agree too, Hillary? All right. Hey, you know what, though?
We're at, we're about outta time here. This has been a great conversation. Look, I, I think every day the way how fast this AI stuff is moving and, and compliance will need to catch up towards doable with AI too, right?
Compliance is, is in, in and of itself will become a moving target. So this is gonna be something we're gonna be watching going forward. But for now, Garima, Tracy, Hillary, thank you for joining us on Control Alt Deploy.
Thank you to our friends at OpenText for sponsoring. This is Alan Hummel. I hope you've enjoyed this episode.
Stay tuned for more. Hey everyone, welcome back. You know, we made it up from the show floor of Black Hat to our suite here in, in Las Vegas to do something a little bit quieter.
Hopefully the quality will be better for you. Um, I'm really happy to introduce you to Dave Heimer. Fair enough, fair enough.
You say it for me. Kraemer cr Hammerer. Either way, Dave is here with us.
And, uh, Dave, the company's called Q Secure. Yeah, Q Secure. That's Q like Quantum.
QU Secure. Yeah. Yep.
Quantum Secure. And, um, well, we're going to hear all about the company, Dave, but first let's hear a little bit about you. Sure.
Um, so again, Dave Coffer. I have a computer science background from before. There were computers a long, long time ago, and I kind of spent a lot of time in it, became a Chief Information Officer in telecom.
Um, and then I founded, uh, what became the, uh, Oracle's largest cloud partner services partner. So grew up in that kind of enterprise software realm. And I grew up in a very nerdy Caltech family, JPL family, and was always really fascinated with physics.
Um, although I didn't have a physics background. So we founded a company that was really focused on quantum computing, quantum algorithms, and quantum development, and then pivoted into this quantum security paradigm that we've been doing since, uh, roughly 18, 19, 20 19. And just been having a really fun time.
But, um, just focusing in on creating new layers of security to protect us from current and future attacks. Un un that's fantastic. If you don't mind me asking Sure.
What, what possessed you to this was what, about four or five years ago? Yeah. What possessed you four or five years ago to jump into quantum computing?
Uh, as a, as a great question, Alan. So, you know, like I said, I, I, I grew up in a very nerdy, you know, family. My mom was a college professor, and I was always really just fascinated with future, next things, really exciting things that were occurring.
And they were kind of on the cusp of quantum computing becoming a real thing and what do you do with it? And so I've had some exits and I was in a good position to kind of do something really fun. Um, I founded the company with my daughter, uh, who's now the CEO.
That's fantastic. And it was just really a wonderful opportunity to focus on some really future cool stuff, make it a now thing, you know, work with my daughter and just do some cool things. Love it.
You know, it, it's funny, Dave, we're about the same h Yeah. And we've seen waves of technology, as you said, come and go in our time, not just go. 'cause technology never leaves, it doesn't fade away.
Right? Like Douglas MacArthur says about, you know, old generals. Um, it, it gets built into the foundation and then we build on top of it and on top of it and on top of it.
Yeah. Now, quantum, I, I have to admit, when I first became aware about quantum computing, it sounded Star Trek ish to me. Yeah.
You know what I mean? Yeah. And, um, I didn't think I would see it in my lifetime, let alone in my working career.
Yeah. But then again, I didn't think I'd see artificial intelligence In your career. Yeah.
In my career either. In here we are, um, there's so many aspects to quantum computing. I was actually talking to a friend of mine, John Will Estate, who's doing a book on quantum computing.
He's telling me he's about 150 pages into this book. And he said, Alan, you don't realize how long this has been sort of a, a holy grail, if you will, because it could do everything and nothing all at the same time, so to speak. Absolutely.
Um, I think for a lot of our audience out here, they don't, they don't understand Yeah. What Quantum really brings. Sure.
I I think probably the easiest use case is the security post quantum encryption that we hear about and stuff like that. Sure. But Dave, if you don't mind, let's pick your brain a little bit Sure.
With our audience, when we talk about quantum computing. Yeah. You know, we toss around terms like qubits Yeah.
We, you know, and, and the whole non-binary kind of being both a one and a zero at the same time kind of thing. Yeah. But what do we really, what does it really mean?
Where does the rubber meet the road for our Audience? That's a great question. So when we talk about conventional computing, conventional computing processes, a, a transaction or a word really fast, and these transactions are like 64 bits.
You've heard of a 64 Sure. Bit computer. So I process 64 bits worth of information at a time, which is great.
We figured out how to do that really fast. But it's linear in nature, meaning it goes from step to step to step, which is good for a lot of problems. But, you know, in the Venn diagram of problems, there's all these problems out here that you can't solve linearly, um, hacking RSA as one of them because it's prime to refactor.
Right. So just if the quantum thing is, computing is really simple, it takes that word of 64 bits and a qubit, which is like a quantum bit. It's basically an atom.
A qubit is an atom. Mm-hmm. And when I create a word of 64 bit word outta 64 qubits, instead of being 64 bits, it's 64 2 to the 64th.
So the word size of 64 qubits is equivalent to like all the data stored in the world in the last year in one transaction. So instead of like linearly going from step A to step B with one instruction, that's such a massive amount of volume and capability, I can solve these problems. That like one good example is like if I go into a maze with a conventional computer, I turn right, I go left, I do this.
If you go in with that quantum surrogate, I can take every path simultaneously, all at once. So really, if you boil down quantum computing, it's just the word size is really, really big. And, um, and it lets us do kind of amazing things with significant amounts of data in an instant.
You know, I've never heard it explained that simply, eloquently, good Work. It's really actually a simple concept that they use some fundamental natures and the bit, because it can be one zero anything. It's, it's not just on and off.
It's, and I put 'em together and it's just really a lot of capability. But it's two to the 64th power, Two to the 64th power, which is equal to a Yoda bit of data, which is equal to all the data stored in the world in the last year. It's a lot of data about Transactions.
Crazy. Now you understand why it's so hard to develop Now. As hard as it is though, I, I don't want to be, I, I, I think we owe it to the audience, to Tom.
We've been making tremendous progress Yeah. In the quantum field, in the quantum, uh, computing field. Talk to us a little bit about the state of the art today in quantum computing.
Yeah, So, so this quantum bit, which is just an atom, right? Different kinds of atoms for different, for different applications. Um, the, the quantum bit, the, the whole issue is error correction.
They're very noisy. So measuring a quantum bit is really hard. So there's been really significant improvements in the noise of these bits.
So, to crack, RSA, which is what we're here to talk about, RSA, is the encryption used on most devices. It's a prime number 20 thou, 2048 bits long. Um, you need about 4,000 quantum bits, but high quality noise reduced bits.
So what happened in the past two, three years ago, if you had a million qubits, which you didn't, it would reduce down to, you know, a hundred clean bits. Now they're improving the error correction to where, you know, you can have one qubit that's error corrected. And, uh, once you have error corrected qubits, which we're racing towards really fast, you mentioned it Yeah.
That the power of what you can do is, you know, is unimaginable. We're gonna have, you know, instead of ai, we're gonna have convolutional neural nets that can parse your whole complex neural nets at once. So instead of like going, well, I'll do this, put something in a bucket, they'll be like, they'll be able, you have about 400 billion neurons in your brain, and it's highly parallel.
So with quantum, you could actually understand the whole state of the system. Error corrections, the key, we're making monumental strides in error correction. It's really exciting time.
Yeah. The other thing I've heard, and, and look, I'm no quantum expert, I'll say that up, up front, is we used to say, well, we had to reach a thousand qubits to have sort of a working quantum computer model, but now they're saying, well, no, we may not truly need a thousand cubic machine. We could do these in parallel.
Yeah. And we get away with a lot less to have functional quantum. Yeah, yeah, yeah.
So, um, you know, the, the, the holy grail is getting to 4,000 qubits to crack RSA and when that happens, we'll talk about it in a minute, but every device is vulnerable. Your camera, your, Anything that's encrypted, Anything that's encrypted is vulnerable. It's kind of like the new malware.
Um, so, um, you know, there, there lies, the, the challenge State of the art RSA is 2048. Yeah. But there's a lot of legacy stuff out there that's 1 0 2 4.
Yeah. And that needs half 4,000. You say you need 4,000 for 2048, you probably need 2000.
Right. And in parallel, you could get almost in spinning distance of that right now, from what I understand. Yeah.
And there's, you know, in large corporations, um, they'll have thousands of applications that have embedded cryptography. Some of this is from companies that have gone outta business. Sure.
Some of it's, you know, des triple des old, old encryption that's already been hacked. So we already have this cryptographic debt is a term I was a CIO in my old days. We have this cryptographic debt, and as I said, only about 25% of the companies actually monitor what cryptography they have.
So the networks are strewn with older stuff mis implementations, and we don't even know what debt we have. So it's really, yeah. It's not just cracking RSA, it's, there's just a vast array of stuff out there that we don't even know what it is.
You Know, RSA might be the gold standard, but there's a lot of silver, bronze, and copper. Yeah. It's in plague here that, that's highly Vulnerable.
Um, now look, I've, I've had the pleasure over the years of, of working with a few companies in the quantum encryption field, one of which, or post quantum Yeah. Encryption, I think is the right term. One of which is DigiCert, which is probably the worldwide, worldwide leader in digital certificates.
Web certificates. Yeah. You know, and of course NIST has been involved in this Yeah.
Mitre, you know, quasi-governmental agencies and, and we have come out with post quantum algorithm. Yeah. That is supposedly quantum proof.
Yes. Now, the adoption of the, you, you know how security is. We don't, do we have what we call just in time security.
Yes. They don't do it till it's probably a little too late. Then they all of a sudden everybody gets religion.
Yeah. But what, what about, what's the state of post quantum cryptography for these kinds of Sure. Digital certificates?
Um, great question. Just I wanna be really clear that post quantum is just better math. So RSA prime or refactored post quantum is just lattice math.
It's just better math. So I like to equate it. If RSA, if I wanted to have tea with the queen, I go to Windsor Castle, there's one guard I push 'em over and go have tea with the lattice based math or post quantum, it's like every inch of that palace is filled with a guard, so I'm just not gonna get through it.
So I think the term post quantum is a little confusing and deceptive. It's just a better math algorithm that can withstand these quantum attacks because they're just not prone to the large word size in a quantum computer. Sure.
So I think, um, you know, when it comes to post quantum, so we've established, NIST is established basically with crypto. You're starting to see a lot of compliance regiments mandating, um, post quantum, but more important than post quantum. And post quantum is just the next algorithm is this concept of crypto agility.
And that is, you know, now that, uh, we have a new algorithm, what if that fails tomorrow? How do I swap that out? So in the past, you know, these implementations of cryptography have been very static.
You can't change them. But this move to crypto modernization is really about crypto agility. Meaning if I have a million cell phones and I need to swap out the algorithm, I can say I've got a threat.
I can press a button and upgrade to post quantum two, or whatever it might be. Um, so that's the field we are in at q secure is basically crypto agility and orchestrating this new cryptography to any endpoint when the threat occurs and monitoring it and understanding where we're at. And so I'd like to demystify post quantum better math, um, quantum computing, bigger word size, you know, the concepts pretty straightforward, but how do you swap it out in real time?
That's the question. Yep. So look, I feel like we gave everyone out here a terrific, uh, you know, quick cursory, cursory costs on quantum Yeah.
No charge. Um, but let's now turn the Q secure. Sure.
Yeah. So you said you, you started the company was about four or five years ago. Yeah.
Uh, your daughter is now the CEO I'm gonna assume she has a little bit of a background in quantum and computers. She Does well, yeah. Um, well first let me do proud Papa with you.
Tell us about your daughter, who's the CEO, her background? Yeah. So, uh, our, my daughter Rebecca, who's the CEO, she was a Stanford artificial intelligence.
Um, so she focused on AI and kind of went into the quantum field because the promise of AI when you have a quantum capability, right. So, just really exciting. Um, she was, uh, Forbes 30 and a 30 in quantum physics and quantum computing.
She's on the World Economic Forum, the board for AI and quantum, and just really has carved out a really cool position for herself. Um, and so she's, you know, and by the way, she's just a phenomenal leader. She's taken over the company and just a visionary and really leading us into kind of this AI driven, quantum crypto, agile world.
And so, uh, You must be very proud and you should be very proud. Terrific story. Um, so let's talk Q Secure.
Yeah. What, what's the mission? What are you guys doing exactly here in quantum, in security?
Yeah. So, you know, I've had some exits. My ethos is really to create a safer future for everybody.
Where at kind of this pivotal time when, you know, the internet was built with kind of no walls, it was built to trust everyone. Scientist, scientist, it was. But, so we're going through a transition where, you know, we've got to, we've gotta rebuild it in the image of that, you know, Alan's, Allen, we can guarantee Alan's Allen, we can guarantee, you know, Alan's talking to Dave and, and, um, so we've gotta rethink it.
And so the future should be safe. We should be afforded, it should be a human right, that you're afforded a degree of privacy and control. So income's Q secure.
So what Q Secure does, um, we have an orchestration platform, fancy word for the software that basically orchestrates this cryptography and keys to any point. It can live in the cloud, it can live on a server, it can live in a air gapped environment if you're high security zone. And then it orchestrates this crypto to any endpoint and you can manage it one single pane of grass glass.
And, um, so that's what we do. In essence, we enforce, um, policy and then let you swap out broad slots of your network in real time. Really easy to deploy.
We've done like post quantum 5G, uh, in a couple hours. And, um, so it's a really easy way to set the stage for crypto agile networks. Um, if you're in the networking space, there's a concept of SD wan, which is a network orchestrated.
Sure. Think of us as SD WAN for cryptography, and that we can orchestrate it across the network in real time, all in software. Really.
That's fantastic. Now there are customers that are more, uh, attuned Sure. I think is a good word.
Customers that are more attuned to this kind of solution. Talk to us about Sure. You know, the target customer personas for Q Secure.
Great. Um, yeah, we, we kind of cut our teeth, um, working with the government. Um, there's been a number of executive orders.
One just came out a couple weeks ago, mandating post quantum cryptography and the path there that, you know, the deadline when they think there's gonna be a quantum computer that can hack RSA, it's coming in towards us quickly. It was 2035, it's now 2030. Um, and this journey closing Quick And closing quick.
And so, um, it, it's a governmental mandate. And, um, so there's real, if you're working with DOD or working with the government in that supply chain, it's mandated. Now what we're starting to see by verticals, and this is pharma banking, a lot of telco energy is now, there's a compliance regimen coming out where they're saying you have to deploy crypto agility.
Like PCI, which is the credit card standards now has a requirement for crypto agility. Um, we were working with a banking customer and they had the regulators in, and they said, the regulators have never mentioned post quantum. And the last time they were in, they were like, you know, You Gotta be, you've gotta get this done.
You, you. And so they were like, boy, this is really creeping up. So I think what's happened is NIST certified crypto, all these compliance regimens, Dora Fido, they're all saying you need crypto agility.
And now there's kind of a mad rush in the verticals like pharma energy banking, kinda Of the usual suspects for this, but for good reason, right? Yeah. Uh, either mission critical or highly, highly, uh, regulated kinds of industries where you can't afford to have, you know, kind of New York Times headline kind of, uh, incidents happening.
Right? Yeah, Absolutely. I'll tell you something else, just again, my opinion.
Yeah. I think the speed that AI Yeah. Has tsunami, for lack of a better word, the tech industry Yeah.
Has made people quantum shy. If that's it, that's, Hey, I said that word first. Quantum shy.
Quantum shy because they, they, if, if AI can come on like that, so can quantum and though the government, you know, it's like secretariat coming around the bed for the Belmont Stakes and pulling away from the field, they're saying 2030, it could very well be 2028. It could be. It could be.
And it's not the kind of thing you can turn on. I mean, the, the, there's so much embedded infrastructure that would need to be updated. Upgraded.
Yeah, quantified. That's a good word. Um, you know, that we, we, we do need now is the time to get outta ahead.
Right? We could, yeah. Don't, don't let you know, for those people who, you know, AI came on, it was almost auto magical.
Right. Wow. What It is crazy.
It's fun, you know? Unbelievable. Um, yet it, it's not magic for those of us who are into neural nets and, and understand how AI does what it does.
Yeah. Really putting one word in front of the other. Yeah.
It wor it's the same thing with quantum. I think we're seeing inch by inch, step by step, you know, how do you eat an elephant? One spoonful at a time.
Yeah. And we're eating the quantum elephant one spoonful at a time. Yeah.
So I, I, I do think people are starting to now feel the, uh, the, the, the, uh, the weight of it, you know, breathing down our necks a bit. Um, I've always asked friends of mine who are into the quantum field, what's the killer app? Is, is it the cryptography piece of it?
Yeah. But what are some of the other Sure. Killer apps out there that you think quantum may unlock for us?
Yeah, I think, I think at the top of the pyramid for me, um, is like molecular simulation. Because right now, if, if I wanna simulate a molecule, you know, we don't have the math or the computing capable to do it. So if you think about the future where I can just engineer materials, I can engineer pharma, um, and I like to compute proteins, um, it, it, it's just fascinating what we're gonna be able to do.
Um, there's quantum sensing, which is really hitting hard. And that's the ability to sense your environment at the atomic level. 'cause when you can kind of come down to the atomic level, it's amazing what you can do.
It's almost subatomic, right? Subatomic. Yeah.
Yeah. And it, it is, it opens, you know, no, no pun intended, but it opens a whole new world, right? It opens whole New world of, of, of, And another thing on the, on the security side, one of the big threats we face right now is steel.
Now decrypt later, our data's already being harvested. So, um, they're harvesting the encrypted data. And in the past they've been like, if you have encrypted data, we don't care, but we should care.
Because no foreign nation states are, they're taking our encrypted data. They're hoarding the, what do they call 'em? Hash hash balls or whatever.
Uh, yeah, I forgot the name for it. There's One for nation state that's speculated halper. 25% of the global encrypted data, when they have enough qubits to crack it, they can crack that data.
And if it's health records, if it's credit card data, if it's banking data, um, that point's a little scary. The other big thing about quantum computers can be revolutionary is quantum neural nets. And this concept of being able to understand the state of a neural net instantaneously, it's gonna open up this kind of super intelligence, this gateway to super intelligence NPI and super intelligence.
Yeah. Yeah. So I mean, your, your brain, your neurons function at very slow speed.
It's like four bits. But if you had a quantum neural net that the capabilities for artificial intelligence, it's really the realization Little, a little scary. Yeah.
Let me give you another kind of pulled right at it. Sci-fi out of a Hollywood movie, once you have the ability to create a neural net that exceeds the capacity of our brain. Yeah, Yeah, yeah.
You know, immortality has been a, a dream. If you look at it, it drives, it drives religion, right? Yeah.
The thought of being able to live forever. We have this whole class of billionaires. It's not about the money for the, I mean, they have more money than their children's, children's, children's children will use, but their mortality is, is, you know, uh, uh, sure.
It's the holy grail. Is it possible with a neural net to like download someone's mind? Yeah.
So we, I don't know if you've heard of Ray Kurtz wheel. Sure. You know, the singularity.
So right. Google. Um, so this concept of yeah.
Creating a, creating a neural net that, you know, when it's a quantum neural net, you know, right now the challenge with AI is it can only resolve the next word in a really sophisticated way. But when you add these quantum capabilities, it can then create things outside of the known knowledge stack. So I'm a, I'm a, I'm a believer in the singularity, which is the nerdy side of me.
Right. And that they will develop this capability that, um, you know, you can transcend into that. There's a joke about the singularity is that if you don't have a lot of money, you'll have ads in the sky when you're in the singularity.
And Yeah. Well, you'll have to pay for, right? You gotta pay for it one way or The other.
But the other, the interesting thing about Singularity is that, you know, it was usually, Ray said it was 2050. Now it's like supposed to be 20, 29. People are saying, we may already be reaching it somewhere, May already be reaching it Somewhere.
Last thing. And then we gotta go. 'cause we're way over time.
I apologize, but I, I actually like this stuff. Um, marrying AI and Quantum. Sure.
We've talked a little bit about it. It maybe it brings on the singularity, maybe it brings on a GI super intelligence, but you, you marry that along with what we're calling physical AI robotics. Yeah, Yeah, yeah.
Super smart machines that have quantum capability and ai. Yeah. Do we have to be afraid?
Wow, that was a, I wasn't expecting that. Um, obviously that's a big topic right now. There, there's a lot of thought concern, optimism, pessimism around that.
Um, you know, I, I, I personally, so my personal belief is that, you know, the trajectory bends towards morality. Martin Luther King. Right.
Um, and, uh, absolutely. We definitely need to be concerned, um, because uncontrolled, where it leads us is once it exceeds our capacity to understand, then, you know, it just, it's, it's an interesting thing. But I think, I think, you know, our, our ambition is to create a safer future.
I think if the ethos we bring to things collectively is that we wanna create a good outcome with this, then we'll bring that ethos to this discussion and create technology that really has a moral arc to it. And there will be a lot of problems along the way. There.
There certainly will, there'll be growing things. But I, I agree with you. I, I, I believe in the goodness of, of humanity at a core level.
And I think we will build in those guardrails. I love it. So I think there's an opportunity to build an imaginably beautiful things.
Absolutely. And that's why you're doing it. You know what we didn't mention though, Dave?
What's Q Secure? What's the website? com.
My email is Dave at Q Secure. And feel free to reach out. It's a really fascinating topic and it is really appreciate.
We're, we're planning on doing a, uh, a virtual event on Quantum either later this year, early next year, virtually. We're gonna call it Quantum Leap of all things Quantum. But, um, we'd love to have you come talk about, maybe we'll have Rebecca come on too.
Yeah, she's really, really Good. Like she would, would Love to talk about Quantum. It's a pleasure.
It's great hanging out with you Too. Secure here on Text Drunk tv. Go check 'em out.
We're gonna be continuing our Black Hat coverage, uh, in a little bit. So stay tuned. You're watching Text Drunk tv.