AI Acceleration, Chip Competition & Market Overheating | TSG Ep. 939
Alan Shimel, Mike Vizard, JP Morgenthal, Stephen Foskett and Chhaya Gunawat dive into the alliance between OpenAI and AMD as part of a larger discussion about the rapid pace of artificial intelligence (AI) accelerator advances. The gang explores how these developments are reshaping the semiconductor market, fueling both innovation and investor speculation.
The conversation then turns to broader market dynamics — from concerns about irrational exuberance and overheating in the chip sector to the long-term economic implications of AI’s impact on GDP. They also examine how AI is transforming cybersecurity, spotlighting Microsoft’s latest technologies while highlighting the inherent risks of automating security and compliance functions.
Transcript
Ah, I love the smell of irrational exuberance. In the morning you're watching Textron Gang. Hey, good morning everyone.
Happy Tuesday. What a Tuesday. This is coming off a crazy Monday.
Yesterday, you know, I, I thought things were so overheated that we were gonna like, reach the superconductor phase pretty soon, but yesterday, I, you know, we torched it yet again even higher with, with the most recent announcement of this open AI A MD deal coming on top of Huawei News and TDK and AWS advancing their own chip business and rumors of an Intel and a MD hookup. You gotta love it when chip makers hook up, they make baby chips. I don't know.
Um, but so, so much going on, so much going on. We've got a great gang to discuss this with. Let me introduce you to our gang members.
We've got JP Morgenthal Sporting a new, a new set at his home studio, uh, chia Gun What Chaya welcome. Steven FoST, as usual from downtown Hudson, Ohio. And, uh, coming at us, I think from Barcelona today where he's a Yankee refugee.
He just couldn't stand it anymore. Mike Ard. Hey, gang guy, gang members, welcome.
Thanks for joining here. So, Mike, when half of the U-S-G-D-P is data center and, and AI related, and as the time says, we, we have a bifurcated economy, the AI economy, and the rest of the economy, are we in a bubble? What the heck is going on here?
I think we're in a small bubble, but I look at these, um, announcements from various folks and I say, Hey, maybe rational thought is starting to prevail here, and here's how I get there. Well, maybe a M D's got a little more efficient processor capability. I mean, OpenAI found them for a reason.
They're not just doing it for the heck of it. It, I'm assuming it's not just some second source supplier that they actually intend to use these chips. And there's also been advancements to your point about Huawei and, um, TDK, and everybody seems to be working on chips that are more efficient in terms of the use processing of ai.
And I almost feel like we lost sight of that goal or that requirement, because every time I look at every announcement for the last two years, it always seemed to be about, well, how can we figure out how to use a bigger, better processor instead of being more efficient with what we have and what we need? And that's why we have all these big data centers in the bubbles. But jp, am I engaging in some wishful thinking?
I think that the, you know, there's just a, a, a natural inclination, still was so much room to run. There's such a big runway on this technology. We're we're just really in infancy, right?
So, you know, obviously, uh, optimization, uh, is one of the key things that has gotta take place. There has to be, uh, some answers for the economic, um, management or, uh, profitability at some point, uh, of these platforms, which, you know, I think some attention has already been paid to. This just doesn't make sense financially unless you're looking at it from the long game perspective in which we're seeding a market, uh, with the expectation this technology will eventually become, uh, less expensive to, uh, buy and operate it.
And you're building your audience now, and, and hopefully they're sticky. Uh, you know, there, there's a lot going on with, you know, just general new market movements. And there are market makers is a, the technology is changing rapidly.
You have a number of players, you know, if you remember the discussion in the beginning was Nvidia, Nvidia, Nvidia, Nvidia, Nvidia, everything was Nvidia. Now you, you have a MD you have, uh, AWS you have even TDK, right? Uh, you have a number of players that are getting into the, um, game of providing, uh, not just GPUs, but asics around AI and AI processing.
And so, uh, you know, this is just gen general build out and, and infrastructure and chip makers finding their, their place, uh, or making their way at the table, pushing their way to the table. And so, you know, we don't, we don't even know what the outcome of this might be, right? We, if, if we, if we're seeing significant improvement at lower costs, that's gonna have a huge impact on how the market, you know, starts to, uh, move.
And, and who's doing deals with who. Like you said, OpenAI probably, you know, has communications with every chip manufacturer out there in the world. I'm sure they did a very thorough study.
Why did they choose a MD? I'm sure it was a combination of factors, but, you know, the, the point is that they did their due diligence and they chose a MD for all we know. It could have just been the fact that a M D's the only one agreed to give 'em 10% state, but it's true, right?
I mean, uh, upside on the business, right? But here, if OpenAI put their weight behind a MD, what's that gonna do to Nvidia? It definitely shuffles the deck.
Sure. So for me, uh, the way I look at it in the chip market, it was nvidia. Now there are other players, which is good.
You get a better technology and speed up in terms of the timeline, the way the chips are developed. But my concern is, as in terms of usage, it's only open AI that's controlling all this chip providers who are the competitors for OpenAI to challenge that. These are the chips used for this business use case, because, uh, believe it or not, we still haven't find a good strong business use case for AI yet.
So that's something I will believe for Stephen to comment further. Yeah. Yes.
Believe it or not, we still haven't found a use case for this. Absolutely true. And, you know, the thing is, I I think that, uh, you know, to be a little bit cynical here, um, the reason they made this deal with a MD is because a MD is effectively paying them for the deal.
So for, for, for reference 160 million shares of a MD stock, which is what, um, OpenAI stands to potentially gain according to multiple milestones of delivery, is worth $33 billion. Which is effectively, um, I don't know that it's exactly the amount of money, but that's a lot of money that is going to be used then to buy a MD chips to power this, uh, approach. So essentially this is the same game of passing around revenue in order to subsidize sales.
And, and, and, you know, in this case, it's only two players. Sometimes it's three players, sometimes it's four players. But essentially that's what we're seeing in Silicon Valley right now.
We're seeing companies passing around revenue in order to all write up, uh, massive sales that aren't actually leading to anything necessarily. Ultimately, like Chaya said, the thing that we need is productive and beneficial and financially rewarding use cases for all of this work. We are not seeing it yet.
So let me jump in here and be patient with me. I got a lot to say on this one. So first of all, Mike, there is no such thing as a little bubble.
You know, my father rest, his soul used to tell me if a Jewish person is going to eat pork, they shouldn't nibble at the corners. It's doesn't pay. Go for the meat, go for the gusto.
Let it like the juice run from your mouth because you're sinning anyway. So there is no little bubble. There's a full on, there's a full on pigs at the trout bubble of total irrational exuberance.
Steven, to your point and try you to your point, what we have here is a situation where basically the GDP, the investment in AI is roughly the size of Singapore's entire economy. The profits and output is roughly the size of Somalia's economy, right? It doesn't end up, it doesn't add up.
You look at these deals, God bless Sam Altman in OpenAI. He's not dis Nvidia. He promised them hundreds of billions of dollars in business last week.
This week he's, he got 10% of a, of a a MD. And by the way, we're not using these processors in Stargate data centers in Texas and here and there and everywhere. These are gonna be yet different data centers, I assume, in the US because everyone has to make Duche happy.
But my question is, when are we going to pinch ourselves and say, who, who are we kidding here? This is a Ponzi scheme. This is me giving it to you.
You giving it to me, me giving it back. I give it to the next guy. He trades it to this guy.
com. I went to Houston in this big building that had an e at the bottom of it. You know, the building I'm talking about?
We were in a, yep. I Used to work across the street from that building at their Competitor. So, you know, that building, we were, we were stuck in a bad contract with WorldCom buying bandwidth.
Not much different than buying a and d above AI chips. And we, we, we were paying a thousand dollars a megabit. The market rate was six, 700.
They invited us down. I sat at a long table. There were like eight different Enron people around me.
Each one of them had a card that had a different division of Enron. And they told me if I sold my WorldCom bandwidth to them and a thousand dollars here a megabit, he would give it to him to give it to him, to give it to him, to give it to her, to give it to him, to give it to her, to sell it back to me at 600. How do you do that?
Arbitrage. We are the kings of arbitrage. We know what we're doing.
I walked outta there. I asked my CEO herb rebar. I said, herb, how did they do this?
He said, Alan, it beats the s**t outta me. Either they're the smartest people on earth, or they're the biggest crooks. As it turned out, they were the biggest crooks.
Mark my words. This is a Ponzi scheme. I, you know, I, when, when, in, in terms of a little bubble, when AI and data centers represent 50% of the GDP of the us when this Ponzi scheme goes south, we're, we're all getting dragged down into it.
We're all bat in the hatches put on your life jackets because this is going to, this is gonna make, this could make 1929 look like a picnic. Let, let me add something about the a MD deal that I'm really, I have to say a MD you might think that a MD is being taken advantage of here. No, no, no, no.
They're the smart ones here. Effectively what they've done is they've guaranteed that future open AI models will run on a MD hardware. They've guaranteed a market for a MD hardware and all this, and A seat at the table, Very low cross of nothing, because it's all predicated on shares and stock market valuation.
So effectively, a MD just earned them, just bought themselves a, a seat at the table for nothing more than some theoretical stock. And that's pretty good way to enter the Ponzi scheme. Absolutely.
And a MD was always the bridesmaid and never the bride. Right? And now they, here's their wedding day.
God bless 'em. Mazel tough to a MD. But here's the next thing.
Let's go beyond the a MD open a I deal. Look, last week we had news, uh, from deep seek, right? They're coming out with an intermediate, more efficient, right?
The Chinese clearly are, are trying to play the role of the Russians in the, in the migs, right? Making a, a cheaper but effective jet fighter. They're making a cheaper, effective ai.
Huawei unveils this sink, S-I-N-Q-I don't know if it's sync or synq. Um, we mentioned TDK with their own announcement of a, of a, a, a chip that never loses rock paper, scissors. That's, that's a reason to buy a chip.
Okay? In case for all you rock paper scissor players out there, there's, well, The DDK thing is, is very different than that. But yeah, There's, there's a way, there is a world of difference between saying I have a design and actually building it at scale too.
So that, That's another thing. There's a piece to this that you're leaving out, which is they've created a sticky technology. All these people who are now have made changes in their business to incorporate generative AI as a component of how they do business.
Um, you can't just shut that off. So these companies, you know, when the, let's say it does quote unquote blow up, where do these people turn? These people are gonna have to turn to doing it themselves, buying their own hardware, setting up their own data centers, uh, you know, being able to deploy and move the, their call to the commercial LLMs to local LLMs, right?
If, if it should blow up. I don't see how it can blow up. It.
It's getting to that too big to fail. Too big to fail. I think.
I, you just can't pull the rug out. It's like Getting electricity. When you start hearing it's a new paradigm and a new, a new reality sell.
I, I don't, I don't disagree with you that there is something amiss that it's fishy. What I'm saying is it's connected to this, you know, this par of the game that I think that people are gonna keep up. They're not gonna let it fall down.
Because if it falls down, it, it's, it's devastating beyond just the, the small market that, you know, I is creating the bubble. Well, You gotta have total faith that the people in the administration, 'cause after all, they would never let that happen. There's a guy who never declared bankruptcy.
Hold on, Chaya, let me ask you something. So, let's say that I am company A and I have an investment in an and in company B. Company B is makes a processor.
And I have no real incentive anymore to run my software more efficiently. 'cause I'm making money every time that that processor gets bought. So, um, it seems to me like the bubble will bust because there'll be more efficient software, but open OpenAI might not have the incentive to go bust that bubble anymore.
'cause they're now got money coming out of the hardware side. So I think that there's a mismatch here in terms of, um, goals and value to shareholders, Right? I, first of all, for me, it's not a bubble, it's a technology evolution.
I would say being a technologist myself, I just think the whole way of the way software are being developed over years has been changing. And because it's such a big shift, it feels like a bubble. I don't think it's a bubble, it's just that it'll get stabilized in terms of every week there's a new news that is coming up.
So there, there's gonna be a point where there'll be standards of technology and it'll stable it down. And that's when the competitors to open AI will also come in and will have players on both side. So the negotiations will be on the table.
Right now, it's open AI versus all the chip providers. That's kind of, uh, is what the game looks like to me. Um, for now, going back to the deep seek point, what Alan just made, uh, remember when, uh, deep seek came for the first time and the market crashed because people think that, oh, this, we don't need a hardware.
We can run. I played around with that technology myself. It is nowhere close to what we have with OpenAI models and the way of efficiency that yes, it's a good experimental thing.
So I don't trust that technology enough that we start using it for business use cases. So there's a lot to go in, in deep sake to gain that trust. What existing, um, generative AI models with open AI and existing chip providers are been promising at the moment?
I don't think it's generative ai. That is, is that's the, the push of this, I think it's agent ai. Yes.
Kind of. I think they both are go hand in hand on top of it. Agent AI just gives you more power, but it's equally risky also, right?
Because it, you, you have less control on in terms of the actions it's gonna perform. And, and then we, we haven't discussed AWS right? They're coming out, what is it?
The Tanium, not Tanium. Tanium three. Tanium three.
Yep. Right. You know, how long is it gonna be till Microsoft or Google do it as well?
Um, They already have them. I mean, they already have in-house Asics. Yep.
Yeah. And then, you know, Broadcom is part of this guys. Yep.
It it's all in, it's all in and, and China, you know what, I remember what you talking about. I remember saying in 2000, the company I helped take public too big. Of course, you know, if we're going to use all this technology, every company's gonna have a website, we're gonna need all this bandwidth, we're gonna need all those data centers.
And then the bubble did burst, and it took almost 8, 9, 10 years for us to recover. Back to that point, no matter how you deal it, like when did the NASDAQ go back over 20,000 or whatever it was. When did, uh, you know, when did we stop having all that dark fiber?
When was all that dark fiber actually used in the data center build outs? I'm not saying that AI is without merit or without value, but when you are turning the largest economy in the world to 50% of its GDP being data center, you know, the old saying about putting all your eggs in a basket, you wind up with a lot of egg on your face. Right?
But if you go back to the bubble that you just referred, best of the companies did came out after that bubble. Google came out after it, Amazon came out after it, and they are the trillion dollar companies today. So We do, but it it took 10 years.
Yeah. But 10 Years, and for every, for every Google and Amazon, there were a hundred or a thousand companies that are cratered that went outta business. Right?
So I'm not saying there's not gonna be winners here. What I'm saying is, you know, I'll quote my, you know, bill Clinton, this is simple arithmetic. The numbers don't add up.
The numbers don't add up. There's just two, you know, it's, this is like a Bernie Madoff gone wild. Yeah.
And, and just to be clear, the bubble isn't ai. No. The bubble is using this circular economy of investment to bolster the irrational and and excessive investment into specific AI hardware.
The, you know, the rest of this stuff we're talking about, you know, deep seek, like chia was saying, um, ag agentic, ai, asics, all of this stuff actually makes sense and I can see a market for it. The problem is that we're that there, that there's also this thing over here that's just churning through money. And for what, Who gets fooled by this then?
Because you would think that there are, uh, wall Street who gets pulled MD is up 32%. Yeah. Yeah.
So that, but you would think that the Wall Street analyst would be wise to this circular shifting of money. But they seem to be all in on it. I, let me tell you something.
Oh, God. Does the name Henry Blott mean anything to you? Yes, he was, he was our advisor at Interline.
The company I, I helped when we went public in 2000, Henry Blodgett was our advisor. He was touting us and, and taking us public at the same time. What, what, what do you think Wall Street has clean hands here?
This is, this is a made, this is, this is a made by Wall Street movie. I I think some sort of poor day trader investor gets hurt at the end of the day. No, because they don't, because they're playing it too.
A MD is up 32% today. They're day traders who made a fortune today. And if they're smart, they'll take their money and go home.
But they may think like Shire and say, well, no, this is a new, a new normal. There's a new paradigm to, yet last two weeks ago, it was Oracle. Today, it's a MD tomorrow.
It could be, I don't know, but I, I wanna, you know, do, who was it? A, a sucker and his money When I feel it's everybody's winning. Everybody's winning.
I being the shareholder of Oracle, it went up to three 40. I was happy today. I, I have seen woke up with the news that a MD has gone up.
I don't mind being this in a circular economy for some more time till, till the stocks Up. I didn't mind it either. That's when I thought I had my children's college education paid off in 1999 when they were 1-year-old.
com stocks that I loved watching them go up in Yahoo and everything else. And then in 2001, it wasn't so pretty. So are you Telling everybody to short those stocks?
What are you saying Right now? I would never give investment advice. That's not me.
Yeah. You know what? I will give investment advice.
My investment advice is trust a competent professional investment manager. And don't do this yourselves. I have zero insight into my stock and, um, holdings, and I have professionals handling it, and hopefully they will help protect me when all of, if all of this changes.
How's that for investment advice? Leave it to the professionals. There you go.
Shane. Shane. All right, Mike, I'm gonna give you the last word.
I I think that this battle is just beginning. And I think we're gonna see much more efficient AI models and that will bust the bubble. com bust go.
I just think tech is gonna become more efficient, as it always does. We shall see. All right.
Hey, we're gonna take a break here on Textron Gang. Let's come back and talk about checking my notes. Ai, you are watching Textron gang.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions.
Your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back. And yes, we're talking about ai, but maybe, uh, hopefully a killer use case for it.
HPE has got a whole, um, service Now and around an AI platform that they've built to come up with Section 5 0 8 compliance faster. It involves, uh, of course using their AI platform, but they built something with DataIQ and SHI as the implementation for all this. And 5 0 8 has to do with the American Disabilities Act.
And it takes a long time to comply with all these requirements. But what's interesting about all this is, this is not the only thing that maybe we could shorten the compliance window on it. Instead of taking years to make sure that we comply with all these regulations, we could do it maybe in months, weeks, China, and maybe the whole cost of compliance comes down.
And who knows, maybe politicians stop b******g about what the cost of regulations are. 'cause we can just do the right thing and do it in a way we can afford, Right? So I like their initiative that they're treat giving compliance.
The weightage in the world of ai, west feed matters and compliance and security and policies are always the way which slows down the things. But, uh, again, in the world of agent ai, how do we decide which are the right compliance policies, right? So there has to be some rules, some intervention based on the use cases that can cover up.
For example, when we talk about disabilities and compliance, what disabilities are we talking about? Who are the beneficiaries of these policies so that we can give the advice or we can give the advantage that now this is the best use case. This is where it it's going to be used going forward.
So who is setting the benchmarks here? Is it HPE setting? It, is it the, they have done an industry analysis and they are saying, here is what, how we have done it.
Maybe industry can follow the trend. So yes, compliance is a good initiative agenda, AI can help expedite the development of it. But I am just, uh, right now more in terms of concern, in terms of what are the driving factors for this.
I think if we go along here, you can start modeling it out and say, Hey, how much are we spending going to Alan's point about the GDP, how much money is spent on compliance with all these different security initiatives and every government and every state. And then you map it up around the world and there's just a boatload of money being spent on something that doesn't really add value. I mean, it's important, but it doesn't add economic value in my mind.
So I say automate this stuff as much as possible, and those are the use cases. And nobody likes doing this job and nobody wants to audit it. Anyway, I gotta disagree with you, Mike.
Mm-hmm. Compliance is security's bastard son. Okay?
And if, and really what compliance represents is lowest common denominator security, a basic floor, if you will not ceiling a floor of the minimum you should be doing in terms of best practices, security wise, and everything else. Now, the instant case here of the HPE, automating section 5 0 8 compliance is not really the compliance. Those are not the DRS you're looking for.
This is compliance. We're making a website, uh, accessible to people, let's say, who have vision or hearing, uh, disabilities or challenges, right? And so you have all techs and, and all of the things, it's a very, it's a very well established sort of model.
And, and it lends itself well, I think to an a, uh, an AI type of situation. But when we talk about compliance, it's talking about are you masking PII are you encrypting data in transit and in rest? Are you ensuring, you know, your certificates are up to the latest things, right?
G governance, risk and compliance GRC is, is, you know, I I said an in jest about the bastard son of security. It's an integral part of the security, and it's important. I think We're looking for a he and stepchild.
There you go. These things are being automated today. Let's let not pretend that this, they, they just require humans to spend time developing the automation.
Like the change here is that the AI has the ability to, uh, alleviate the need or the, at least the, the amount of degree that a human needs to be involved in order to check this stuff. So you can, you have what's called the large action model, and it understands, you know, basic UI uh, interactions, right? How to press a button, what it should look like, and it, you can train it to say, this is what it, these are the factors that need to be on the screen in order for it to be compliant with 5 0 8.
And so it very simply, it, it's very simple to tell an ai, listen, here's the script of things I want you to test. Make sure it's 5 0 8 compliant. It understands what 5 0 8 compliant means, and it'll walk through the script.
And no human has to sit there like with an RPA tool, validating and putting all those steps in manually. And it does, it's a huge reduction in time. It's a huge reduction in costs.
Uh, and, and I think what Mike was saying earlier about its value, it's an important requirement. It, you can't sell the software to the government and certain other, you know, um, non-governmental agencies unless you are compliant. So if you wanna sell your software, this is lifeblood, it's table stakes.
Um, but you're right. It's not like it's something you can advertise and say, look, I got 5 0 8 compliance here. Uh, you need, you know, so that makes me better.
So, uh, so the fact that you can pawn that off, and it's no different than what's happening in many QA functions. Uh, a lot of the QA functions and software engineering are being handed off because, uh, again, this is not something that you can charge for, per se, uh, that quality, but you, but it's expected and, and it's now requires less human intervention to get there. And, and I'll just say too, that this may not be, uh, so, so let's kind of refocus on this particular story here, section 5 0 8 compliance that's about complying and, and helping people with disabilities to be able to use software that may not be a big selling feature for a lot of people, but it's a life or death feature for some people.
And as somebody who's active in the dis disabilities community, I can tell you that, um, having websites that are compliant with section 5 0 8 is, um, and I am not joking, is life and death to people who have visual disabilities or motor disabilities or need to use alternate input and output mechanisms. Um, you know, being able to access the social security or the disability, or the Medicaid or Medicare or local disability, uh, websites, uh, using alternative methods. That's the whole ballgame.
And not only that, but it's the whole ball game for these agencies as well. So if you're a board of developmental disability and you're, uh, software and interfaces aren't compatible with alternative disability inputs, well then you might as well just go home. So I'm actually really thrilled to see this.
I want to, you know, give a little shout out here to the folks from kaza who are, uh, field day presenters. Their, their hearts are in the right place. They're, they focused on this because they care about this product and this and this segment of people.
And, you know, I mean, it's easy to get angry and oh, ai, all this and that, but this is a case where we're actually using AI for something useful and, you know, give 'em a pat on the back. I think this is the beginning of a much larger trend, and I think I'm really happy to see section 5 0 8. That's great.
But I think this is gonna play through just about every other compliance mandate there is out there. And this is gonna be the thing that a lot of folks are gonna say, Hey, ar AI delivered some actual value here. Because a lot of this stuff is, consumes an inordinate amount of time.
It's costly and it's expensive, and it, not that, but it's just scut work at the end of the day. Yeah, because that was your best Bogart imitation how Mike Louis, this is the start of a beautiful friendship. There you go.
Hey, we're gonna take a break here on the gang. Let's come back and we will move into our C block, which is around, wait a sec, checking notes again. Microsoft and Security is that at Oxymoron, you are watching Textron Gang, Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back in. Yes, Alan's point, we're gonna have a little chat about Microsoft and security and well, some people love 'em and some people hate 'em, and some folks are just in between. But the latest thing outta Microsoft is that they are gonna use graph technology to make it easier to integrate all these different security tools we use.
And within the security world, there's this debate going on about whether we should centralize everything on a platform and that we can get rid of our swivel chairs. 'cause we'll all have one set of integrated tools. There are others that continue to say, you cannot rely on one tool and you need to have layered defense.
And Microsoft here is gonna make that easier because we're gonna use graph technologies to integrate all the tools, and we'll live in a more of a kumbaya kind of world in security is yet to be proven. But this is the ongoing debate, and I know that Steven, you a thing coming up around, um, uh, Microsoft and an event that you're doing with Tech Field Day. So you guys are following this space pretty closely, but I don't know, what's your take on what's going on here?
I mean, I seem to see a lot more Microsoft in the security world, but you know, not everybody loves 'em. Well, Microsoft is certainly stepping up in the security world. I think that, uh, they have invested a ton of money in it.
Uh, you know, I mean, Microsoft isn't a charity. Uh, they invested a ton of money in it because I think they see a lot of opportunity in it for, uh, product sales and so on. But, uh, frankly, they are investing, they are working hard at it.
And of course there's a carrot and a stick here, as you pointed out. We also have, uh, you know, uh, Ron Wyden, uh, US Senator, uh, and Microsoft critic, uh, attacking Microsoft for delivering dangerous and insecure software and encouraging the FTC to go after them. So, uh, you know, the challenge with being Microsoft is that they, as the, you know, the makers of, you know, certainly one of the most important infrastructure components in the world, and also one of the, uh, by far the leading, um, end user computing platform in the world, they have to balance a lot.
And I don't envy them in many of these decisions. So for example, if we look at the, uh, the, the, the specifics of the, uh, the Ron Weiden letter, they're talking about, uh, hackers exploiting of vulnerability that was kept in my in windows. 1% of traffic uses this, and if they had deprecated it, they would've blocked by extension thousands or hundreds of thousands of actual and users from using something that they never upgraded.
1%, let's, let's flip that switch. Let's, let's get rid of that vulnerability. Would you maybe, would you do that?
If, if it meant that it affected literally thousands of customers, uh, maybe you wouldn't. And that's the sort of the problem that Microsoft is facing here. Now, on the flip side, Microsoft is doing some really cool things.
They are improving their security tools. They are bringing AI to bear. Um, and as you wrote about, uh, Mike on, uh, you know, security Boulevard, they're using, uh, graph technology.
They're using ai, they're using MCP to build a more collaborative and flexible security framework. Um, as we saw in, uh, the recent article, another recent article by Jeff Bird on SE Security Boulevard, they actually have been seeing some success with these tools, uh, sniffing out some pretty clever AI generated attacks. So, you know, it's not easy to be Microsoft.
I like that they're really putting a lot of energy and effort into this. And I do, uh, look forward to hearing what they have to say on October 9th during this, uh, tech field day presentation. And I think, Stephen, what I want to add is security and fun stuff doesn't go very hand in hand when it comes to ai.
Um, I play it around with a lot of AI tools, and when I try to automate a security use case, yes, it's gonna fix one thing, but it might mess up or open up some other things. So there's a lot of risk, I would say, needs to be reviewed before anyone adopts it end to end. My question about the thing with Microsoft is why does only Microsoft specific operating systems has this so many vulnerabilities that they have to patch so many things, why they can't build a system like Linux or, you know, where the system is strong enough and you don't even need these kind of vulnerabilities to be tackled, which can, you know, played around with users' data As, as a long-term Linux administrator, it pains me to admit this exactly, but Linux has a lot of vulnerabilities To absolutely they do.
You know what, and as a person who's been in security for 25, 30 years, you know, it's hard being Microsoft because damned if you do and damned if you don't. The fact of the matter is, when you had an operating system that at one time represented 95% of the market for, uh, personal, uh, you know, for computers, not servers, desktops, laptops, et cetera, it still represents I think 80 or 75% of, of these devices you have a giant bullseye on your back. It's not that it has necessarily more vulnerabilities to Steven's point as Linux or even Mac.
It's that it's the bad guys exploit it, look for exploits there more so they find more. If we put the same amount of effort into Linux and Mac exploits, you probably find a similar amount of vulnerabilities. No one has a, a, uh, a, a lock on on being the most secure.
They all software has vulnerabilities. Well, and you look, I mean, even, even Apple iOS, which is by far the most locked down operating system with the most security controls of anything we've ever seen in widespread use, and there are zero days. Absolutely.
And there are exploits on that platform as well. So, you know, I don't think it's credible to say, you know, lock the door because I, I just don't think you can. I, I, I think this is why insecurity, we've moved from a prevention to a resilience model, right?
Yeah. Here's the part that I get uncomfortable with, right? So on the one hand, uh, I guess I'm just flat out conflicted.
I really like what Microsoft's doing here with graph technology and some of the AI stuff and the MCP stuff, but I also look at it and I go, so let me get this straight. You're selling software to fix the software you already sold. And so like, you know, why don't you just fix the software?
Well, so, so, so Mike, I'm a, I'm glad you raised, that was the point I was about to make. The a the story is isn't so much about their investments in security, it's how they're leveraging emerging technology to improve, uh, your, your, your security stance, your security posture, identify new, uh, potential threats that before were difficult and what they're doing. I, I don't look at it in the way you just mentioned, right?
One of the issues has been this is highly analytical process. It, it lends itself to time series data. Um, a significant quantity of data needs to be analyzed.
And how do you share that data? And, you know, typically in the past, you know, they've had to build the tools, the analytical tools into the product. Now they have a way of leveraging the, the actual, uh, underlying foundational capabilities like graph database and, uh, MCP to now share that information with a, uh, inference engine and allow the inference engine to do what it does well without having to yet add more weight into the product.
So this is, you know, this is about the ecosystem growing and taking advantage of the ecosystem. And I'm sure for a, a large number of customers who are, you know, in the security office, in the operations teams, they're saying, this is great. I now can add my sentinel data into what I'm watching in addition to, or I can now easily combine sentinel data with my Datadog data because I now have, and, and I can allow the LLM to drive that, right?
Hey, LLI can ask Natural Language Pro tell me, is there any anomalies that you notice in the Sentinel Stream that you didn't pick up in Datadog? Boom. It'll actually go and ask both of those platforms for the right data and then correlate them.
These are things that in the past would've taken operations team, uh, days, months to build special, you know, it would've had a cost associated. It's now an an, you know, a simple prompt. I, I don't disagree.
I think you're dead on. So one, some, but I mean, God bless Microsoft for doing this, but I also look at it and go, well, won't a dozen other companies do the same thing and maybe do it more broadly across different products and use cases and graphs are gonna be everywhere. Maybe they will.
The MCP is native to the, it is just, I, I own a pro software product. I'm providing an MCP. It's almost like providing an integration an API interface for something for, for other people to then leverage my what my proprietary stuff.
That's what the CP is. It's about allowing ev the outside world to connect in and take advantage of my proprietary, uh, universe, right? But isn't MCP or any a table stake?
I mean, everybody and his brother has one. And wow, that's, that's pretty aggressive for something that just came out less than a year ago. Aware.
It's only important to the extent that you have something that you want a, uh, LLM to automate. Steven, we're in a new paradigm, you know, new, Which has bugs. Then we are saying that, oh, we sold your software, which has issues.
Now let's buy a solution to fix your problem, because we know the one that we shipped you has a problem. Well, that's a good business. That's a good business model.
All right. Hey, we're about outta time here, though, for today, guys. What a great gang.
You know, let's, let's face it, it's a, it's a, uh, target rich environment to talk about tech news these days, but it was a great discussion. Jp, Steven Chaya, Mike, thank you so much. Thank you for watching.
As usual, we have Text strong TV following today's show. Enjoy your Tuesday. Uh, on behalf of the gang Techron Tech Field Day Future Charm, this is Alan Hummel.
We're out.