AI, Cybersecurity & MongoDB’s Role in DevSecOps | TSG Ep. 928
Alan, Mike, Mitch and Jack Poller break down today’s cybersecurity challenges in the age of AI. The gang looks at the risks AI introduces, why regulation matters, and how basic security hygiene and stronger authentication remain critical. They also examine how AI is being operationalized with MongoDB, a database developers continue to favor for its simplicity and growing importance in the AI market.
Transcript
What's that cracking noise you hear? It could be DevSecOps Foundations. You're watching.
Textron Gang. Hi everyone. Happy Monday.
I hope you've had a great weekend. I'm Alan Shimel, and this is Textron Gang. Um, man, I don't know, my weekend was much too short.
I wa I was looking forward to doing so many things and I I had a honey do list instead, so it was a bit of a honey do weekend for me, and I don't mean the green melon. Um, I'm almost happy to be here talking tech strong and tech with y'all. Let me introduce you to my compadres on the, uh, panel this morning, wearing his Indiana Jones hat Jack Poller guitar man, Mitch Ashley, and, uh, well, I don't know if he's still a Yankee fan, but he's chief content officer.
You know, Mike Ard. Gentlemen, welcome to Text Strung gang. Happy Monday to you, Mike.
com and other sites, other text trunk sites, non-tech trunk sites, software, supply chain security, DevSecOps. You know, it's a, it's, it's enough to shake to shake your confidence, you know, but it's the Security pros dilemma. We never seem, you know, we just never win.
There's always something else out there. Let me, yeah, let me, let me go through the list of what we're talking about though. I mean, shy Ude is attacking the CrowdStrike environments and other software supply chains and traffic is reporting that people are abusing Claude, the Lodge attacks White Cobra is a criminal group that's targeting, uh, visual Studio extensions.
And then we see Oasis Security made a note of the fact that there's a lot of weaknesses in the cursor AI coding tool. Like, again, exploited and checks marks did the same thing and said, Hey, you know what? You can lie to these AI agents and tell 'em anything you want 'em to know, and then they'll give you access and do all kinds of weird things in your code.
Mitch, none of this sounds good. And, uh, Alan has a piece talking about how the foundations of our DevSecOps world are starting to crack. Do you agree?
And what are we supposed to be doing about all this? Well, I see many futures, many possible futures of how this may take place. So, and actually, there, there are, I mean, I think these are real examples, right?
Of how AI can be used or is being used in an offensive standpoint. And, and I don't know if you mentioned in, in the case of even anthropic and generating code, it's about extortion. It's about getting, you know, money from people.
It's about how we craft now software that can go after not just large amounts of, uh, you know, individuals in a particular n and m kind of fashion, but also it can be done on a personalized individual basis. So I think these are all good examples. I hope it, it sort of heats up the, the, the water, if you will, and ramps up the interest on getting more secure code generated out of software.
But also more importantly is, is making sure that there are security guardrails that we can contain. I did a piece on is regulation gonna save us? No regulation's not gonna save us.
I think the market has to respond to creating and secure guardrails that we can control and manage. But right now we're sort of seeing kind of if and every, any and everything that can happen with, uh, security around ai. Mm-hmm.
Jack, let me ask you d does it feel like we're being a little reckless from the security standpoint? It seems like we're just letting these developers turn loose, do whatever the hell they demo want, and it shows up in a production environment. And then guys like you are asked to clean it all up.
Why should today be different than any other day? I was just gonna say that New boss, just like the old boss. Exactly, yes.
We're being reckless. I mean, there is a lack of fundamental cybersecurity hygiene, you know, uh, there's the AI issue, and then you look at something like the shy MPM attack, the root cause of that attack isn't supply chain, it's actually poor password, it's passwords, right? You had people who were phished that then got access that enabled the bad guys to get access to the code base and then propagate it from there.
So why are we still doing password based authentication? We have passwordless authentication, we have MFA, why are people leaving the front door unlocked? Mm-hmm.
You know, and then all Go ahead. I'm sorry, Jack. Oh, I was just gonna say, and the AI doesn't make, it doesn't make necessarily change the attack path.
What it does is just enables people to act faster on the attack path, just like AI does for everything else. It's an acceleration function. Okay?
I think it's an acceleration function and it's, it's a breath. You can do everything all at once, anything, everything everywhere, all at once, that kind of thing. That's, that's one of the big differences.
It's not just, It's a force multiplier for the bad guys, unfortunately at this point. Good way to say it. But, but let me back up a little bit.
First of all, I gotta give credit to whoever comes up with these names. I mean, I saw Shy Ude, it had me at Shy. I was, I was ready to go Blue eye and blue and blue eyes and you know, I, my mind was running away with me, right?
You're ready To start the galactic Worm. What a great name for a worm. Why didn't I think of this?
Where names been all this Time, right? White Cobra. What was the movie where there was that guy, fat Cobra or something was his name and he, it, it was one of these spoofs of like a James Bond thing, and the guy goes out and it's, the guy's name is Fat Cobra, but he, he's like a ruthless killer or whatever.
I mean, what, who comes up with the names for these things? I'd love to know, right? Spider.
What's the other thing? Spider this together. Spider scatter spider.
Yeah. Yeah. These are great names.
This is like outta Hollywood. But, but seriously for a second. All of our chickens are coming home to roost.
We've known, we've known about our software supply chain issues, security issues. For some reason we thought putting SBOs in making SBOs mandatory would somehow fix this. No, it doesn't fix it.
No, it doesn't fix it, number one. Number two, we've known AI is going to be a force multiplier that the bad guys, we're going to use ai. And that if we're gonna rely on these models that are taken from the bad code, we've been, been using all these years to generate new code, and we're surprised that the code it generates is insecure.
It doesn't stop us from using it. 60% of the code out there has, has AI's fingerprints on it. And, and we sit here and say, gee, I didn't see that comment.
Right? Th this is, this is, you reap what you sow, right? Mm-hmm.
This is, you reap what you sow. We, this is, this is what happens here to us. And you know, and look, Jack, Mitch, me, Mike, we've all been around the block.
We've all been in involved in the security game a long time. We're always one step away from the ultimate calamity, but somehow, somehow we live on to the next episode, right? We, we, we squeeze through, you know, it doesn't turn out as bad as we, we it could be.
So let me, let me challenge you on that, Alan, because I think we're in a, in a situation of fighting the next war with the last war's weapons. Oh, no doubt. And we're, we're, we're think thinking about with fracking and scanning and mm-hmm.
Doing all these things that are passive after the fact. SBOs, you name it. All, all good things, good practice.
It's a security measure though. Line. It, it, it is actually, I'm Gonna write in, I'm gonna write an article about that Security measurement.
You Gotta, you gotta be over, you gotta be over 45 to know what that means. But Go ahead. The students of students of history know at that.
Are there any students of history left? But we're, we're, we're, the new war is, you know, this is battlefield. You know, where, where the, where the, uh, red coats or something is it, it can, we're not in a world of, it's about creating defenses.
You have to fight fire with fire. You have to fight AI with ai. And I'm not just saying that because AI is the answer to everything, but you know what, if, if they're doing calculus and you're doing algebra, you better damn well learn calculus.
Matter of fact, you better be really good at calculus. And that's what we've gotta do. And so, you know, my wake up call to everybody, software developers, security professionals, all of this is get on the fricking AI bandwagon.
Not just because it's the thing to do and it's popular. And, you know, chatbots are that cool. Is that, is that's the new war.
That's the new environment. And if you ain't good at it, you know you're gonna get rolled over by the, the digital tanks of Tron taking care of you, taking you out. Right?
I mean, to Mitch's point, I mean, I would love to be able to say to every developer in the world that thou shall have two factor authentication in you. You're being, you know, maybe subject to some penalties. 'cause you don't, but I don't think that's realistic.
I do think when we need something that detects an anomaly, like instantaneously and then applies policies instantaneously. 'cause the amount of time for which havoc is wrecked is now measured in seconds. Right?
And this is where the whole thing is moved to. It's machine versus machine. And we don't have machines that can fight the fight we're gonna lose, for sure.
Well, I think the other part of it is we need to prioritize security hire. Right now, a lot of what we do is productivity. We focus on productivity, both on output of developers and on making their lives easier.
So you don't have MFA because it's friction. You don't, you have automatic updates of your NPM packages because it's easy and quick, and you can press a button and you get an update, but that bypasses a check of what exactly are you pulling in, in your packages, which is how this worm propagates, right? It automatically gets updated and it often goes to the next package.
So if we look at our environments that we're building and the environment that we use to build things, we should be saying, yes, we've made it. So it's super simple. It's PhD, it's push here, dummy, right?
Everything's a push button. You get an update, you get this, you get that, and let's sort of maybe dial that back and say, how do we layer in a little bit more checks to prevent bad stuff coming in, in one way or another? Right?
And I, I used to talk about this in terms of we need to compensate, you know, we compensate developers on feature functionality and not on security. The problem is it's open source. So how do you, you're not compensating them.
They're doing this for free. They're volunteers, so you can't penalize them and you can't compensate them for good or bad security. So we have to think about it in a different way.
You can though, but I think you can. I think you can. Okay.
You know, here's, here's my take on the software supply chain issue. The fact of the matter is, most developers are not conjuring up this open source software outta thin air. They're downloading it from a repo, from multiple repos, whether it's GitHub or, or NPM or Artifactory or Maven or, or whatever, right?
Wherever they're grabbing this stuff from. The point where they downloaded from the repo, in my mind, has always been a choke point. It's always been the point where you could say, wait a second, is this piece, is this script?
Is this component, is this container secure? Is it the latest version? Has it been scanned from malware?
Right? Is it, and, and, and some, some things are still going to get by, right? Because we don't know that it had the vulnerability.
It's a zero day or whatever. But so much of our aggravation here, of our security stuff could be solved at that border of the repo, uh, from the downloading from the repo. Now, I know certain repo security companies have talked about sort of a repo firewall for forever, that if you're gonna download their software before you get that software in, it's gonna be x-rayed, it's gonna be scanned, it's gonna be tested.
But we don't, but developers don't do it. We don't do it. We don't as a rule do it.
We, that's the hygiene we need here. We need Well, and That's, that's my point exactly, is that's the, the, that's the slowing down of the development cycle. Don't do it automatically.
Have it go through some steps to check it in some way or another. But can, why Can't we make it automatic Jack? It's easy enough.
It's easy Enough. Well, that's my, that's my point, Alan, is, is it should never be a next step is when security happens. It should be never be a, and then we scan it and then we go, and then we put it through a firewall, and then we do this right?
In an age of AI code to, to your earlier point, Mike, the code that we're getting out of, out of LMS today is all the insecure code that we put into it, right? We're getting back and we're, we're reaping what we sewed. But so to solve that, you're not gonna, you're not gonna improve it by just adding better steps at the end, after we've generated code, generate code that's created by ai, should already be secure by agents, ai, LLMs, all kinds of things can make it secure.
Whether it got it through a good firewall or it downloaded from the, you know, crappiest, whatever. That software should be secured before it ever was presented to a repo or to a human or whatever. Those steps can happen before we touch it, rather than, here you go, Mitch, here's somewhere JavaScript code.
Try that. But that now has some new things in it that, whoops, you know, I do, I need to run that through a scanner every time I test it on my system so that, you know, I don't get compromised. Let's get real.
You're not gonna create secure software by bolting on more steps just faster. You've gotta build it in. You've, instead of shift left, you've gotta shift in a security has, You know, what built this reminds me of like the Apple walled garden approach to apps versus the Google Play.
Not, not Google Play today, but the Google Play store earlier on mm-hmm. Where anybody could basically upload an app to Google. And there was a lot of malware infested apps in the Google Play Store where Apple, yeah.
They were a pain in the butt. But they did it. They did.
I think they did. Anyway, check your apps before it was accepted into the Apple store to make sure it wasn't a security risk. And so we had much less security incidents from downloading apps.
And I'm not saying it 'cause I'm a fanboy, but we had, you know, they did do a better job of, of testing them on the way in instead of just on the way out. It maybe, maybe that, maybe that's the thing to do. So, so Mitch, let me ask you the question here.
Yeah. We keep talking about best practices. You should do the right thing.
We should have some empathy. We should all lock arms and do the right thing, and yet we don't. So at what point are we gonna get to where, you know, it's gonna take, you know, to use a phrase that's popular these days, we're gonna have to lock a couple of people up to make the point.
Well, it could be locked the couple of people up. I think the, the real answer is enterprising entrepreneurial companies, people that solve this to make money, that's the way to solve it, because that's absolutely the way We'll catch on and take me, yeah. Let me just say some putting In regulation and penalties and all that, that's, that's nice, but that ain't Gonna stop.
And, and guys, in all honesty, Mike, I gotta take issue with what you said. 'cause of the world we live in and the country we live in today, okay? We don't lock people up because they made a mistake with computer code.
People get locked up when they commit crimes, intentional crimes, right? Let's, let's be clear about, I'd like, in all honesty, I'm, I'm not playing that game no more. We're not locking people up for, for negligence or computer stuff.
I would point out, I would point out if you drive your car and you know that the brakes are not working and you smash into something, you will go to jail. So that, so that, that is, well, not if you smash into something, you don't go to jail necessarily. If you hurt something or kill someone, you do.
Right? And they, they call that negligent homicide. So, So, but, but Legally there's a whole hierarchy there.
I'm sorry Jack, but I, but I, I think, I think you have a, both you and Mitch have a valid point where Apple created a Walt garden and Apple was responsible for the trust. So you trusted Apple. Yes.
Apple enforced it, and you went from there. Mm-hmm. Google's approach today is there's a Google Walt Garden, but if you want to install something from somewhere else outside of the Google Trust in search circle of trust, you can make the decision.
We've told you we haven't vetted this, right? Personal responsibility. Personal responsibility right now, software development in general is all on the personal responsibility.
It's up to you. And there's no circle of trust for you to go to an enterprising company. Or entrepreneurs could go and create that and say, we'll, take the open source repositories, we'll validate it, and you come to our repository and you pay us to come to our repository because we've done this extra level of work to create this circle of trust.
That's one possible solution to this problem. It's not. And just with everything else in security, it is maybe necessary, but not sufficient.
It doesn't solve the entire problem, but it goes a good step forward. It's a, it is a step forward. I will tell you my last thing, and I'll put this back on the free market.
If people are selling you insecure software, don't renew the license. Boy Boycott, insecure software boycott, cancel your subscription to insecure software. That's, that's the mantra.
Hey, we gotta we gotta take a break here. I'm gonna leave you with one thing on this. Fear is the mind killer.
You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and there's a war on, in a place that we can't see it. It's up in space and involves all these GPS satellites and most of this issue seems to be emanating out of the conflict in Ukraine.
But Jack, you have an article about this Overrid Security Boulevard. Educate us. What's going on here?
Well, to no surprise to if, unless you've been, you know, sleeping for the last 5, 6, 7, 10, 10 years, there's a war between Russia and Ukraine. And no surprise Russia is playing dirty tricks in jamming GPS and Russia being Russia, they're sort of a little bit or maybe a lot indiscriminate. So basically just saying, we don't care, we're just gonna blanket the entire region with jamming signals and corrupting the, in the GPS signals.
Uh, civilian GPS is insecure by design and is also used everywhere. And not only by your cars and your phones, but much more critically by airplanes to navigate. And in fact, you can use GPS to pretty much land a commercial jetliner today, except when GPS signals are jam.
Some birds use it. We wish. Yeah.
Um, but this essentially goes back to sort of a continuation of the discussion we had earlier, which is if you don't design security in from the beginning, you're going to have problems. In this case, we have a very big GPS problem where the jamming extends out from the Ukraine to cover all of the Baltics. And in fact, even Sweden is reporting an increase in loss of GPS signals in airplanes and other things.
And it's a very huge problem. I mean, this is life critical, mission critical stuff. When a plane is trying to land and it doesn't have GPS anymore, it potentially lands in the field and crashes rather than lands on the runway 500 feet to the right or to the left, right?
Yeah. And there, there are other uses of GPS that there are pretty mission critical too, right? Yeah.
It's all around emergency Services, as you name It, everything. But, but let me Go ahead. I'm sorry.
You go, Jack. No, Well, I was just gonna say my, I I'm looking at both GPS, but I take this as look at the broader picture, right? Which is really going back to a little bit of the discussion in the, in the, a block of thinking about security, security at day one.
Security should never be a bolt-on afterthought, right? It's, we have to design security into anything and everything we do. And whether it's GPS or how do you print, right?
If you're developing software, hardware, it products, you need to think about security at the very beginning. Okay? So I, I think this is more about something else we spoke about before, which is about fighting this year's, this year's war with last year's tactics.
Absolutely. And I, and I think, look, the loss of life in this war is horrendous. I, I, I'm, I feel bad for the Ukrainians as well as the Russians and all their proxies who have lost lives in this war.
But when we look at the history of this war, much like, I don't know how many of you're a fan of history. I am, I'm a history major, you know, they say that the Franco War in Spain, the Spanish Civil War in the thirties and twenties was a precursor for a lot of the weaponry that was used in World War ii, especially by Germany and Italy, right? They were testing, it was a great test lab.
And for tactics and technologies that found its way into World War ii, I think we're gonna see the same thing here. I hope we don't have another World War ii, but we're gonna see the same thing here in the Russia, Ukraine War. Things like our overreliance on technology, which is not secure like GPS and the ability to take that off as a chip on the battlefield is, is paramount.
Things like cheap drones, unmanned drones, autonomous drones make having billion dollar airfare aircraft obsolete with people driving that, right? There's been a lot of new tactics and new, new technologies that are being deployed here on both sides that I think the folks in war colleges are gonna be digesting for years in terms of how do you fight the next war? Maybe, maybe, you know, look here in the US we pride ourselves, we make the best damn weapons in the world, don't we?
No one makes a plane a fight, a plane like us. No one makes a tank like us. Damn.
No one touches our missiles. But have we have, we made an over-reliance on, on vulnerable technology in our defense or war fighting ability that leaves us vulnerable to very kinda low level jamming like this, right? And we sleep under the security of that blanket is quote, semi quote Jack Nicholson and a few good men, right?
We sleep under the security of that technology and is a problem To, to, to use Min's phrase. We are ironically literally fighting this war with both next year's weapons and last C'S weapons. So Russia has chosen to degrade the Western technology capability by jamming GPS, which affects the high Mars rockets and affects drones.
GPS guided drones, Ukraine is fighting back with. And, and sort of the, the impetus for looking at this is new technology, which is using laser communications to communicate to the drones, right? Also, fiber optics.
They had literally, a drone will have a 10 mile spool of incredibly thin fiber optics that it, that it spools out as it goes to attack the Russians from the Ukrainian side. And there are areas in the fields that this battle has bought that it now look, the, the, that it now looks like a spider's web of all these trails of thin fiber optic cables lying on the ground or caught in trees. Russia, on the other hand, is using artillery pieces and tanks that date back from World War ii, right?
1940 1950s tanks and artillery, because they aren't technolo, they can't be interrupted by GPS jamming. It's, it's a ballistic shell. You fire it and it goes where he wants to go and that's it.
And, you know, and, and Well, but they're doing that outta necessity, Jack. 'cause there are other stuff got blown a up early on. I, I agree with you.
I'm not, I'm not saying, well, you know, it's, it is what it is. Now the other part of this that gets interesting is the loss of life, which I think is abhorrent, but talking about history, Russia has always had a historical basis of treating its own civilian population as cannon fodder. That's actually where the term sort of comes from, is we have 300 million people in the country and we don't mind if we kill 10 or 20 million of 'em in order to get what we want.
It's okay. They're just peasants in the middle of, you know, the, the, the Siberian Peninsula. Why, what do we care?
Right? And so the, the more people they can throw at the problem, they're happy. And the western world doesn't wanna fight a war that way.
We don't like the death and the indiscriminate killing. And so we're trying, we're always trying to find other means technological rather than human to solve this problem. Agreed.
It's a shame. It is, it is. So do you guys think, though, ultimately, and, you know, coming back to this GPS thing, let's say that there was some sort of conflict involving another country to another country, is the GPS thing the first thing that's gonna go, because that's the communication.
Yeah. No, I, I, I think that is the new, you know, you, you want to black out your enemy like I do. I think the Israelis did this in attacking Iran.
Absolutely. Absolutely. You know what, you know what I'm gonna go buy, I'm gonna go buy some Rand McNally maps, you know, the kind that used to stick in your pocket.
So you, the, The question is, once you open it, can you fold it back up, Mike? That's always the problem with those maps. Um, alright, Well here the 3D book kind.
It's okay. That doesn't lie to, Oh, let's take a break. We're gonna come back on our C block here.
Mike took a little field field trip to Mongo. No, not the Congo, Mongo MongoDB. We're coming back at you.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
To Alan's point, yes, I did go visit a friends at Mongo MongoDB. They had a developer event last week, and it was interesting. They were talking about three things.
The first thing wouldn't surprise you, they're gonna embed search and vector search into the document database, and that makes it easier to manage and you can have all this stuff in one place. The second thing though, they're also noting that you can now use AI agents to reverse engineer other applications faster. So you can do these, uh, application modernization projects that might have taken a year and a half can now be done in maybe a more reasonable four to five month window.
We'll see how that plays out. But here's the most interesting thing in my mind. They're also talking about this whole notion of context engineering.
And they're talking about the fact that one of the reasons that a lot of these AI projects are failing is because we're just slamming data into these things and there's not enough context to drive a workflow. Their argument is, is we need smaller chunks of data thrown into these LLMs and other, uh, processing engines that are, uh, more efficient. So that I'm not doing these massive amounts of processing, but I'm doing it in a way where there's context remains as I kind of do what they call a nested doll approach as I'm processing things.
So these smaller, uh, chunks is technical term. I know, um, we can maintain the relationship between these things, AKA knowing the context. And so what they're really saying is databases are gonna be one of those shovels that drive AI and the, the goal rush associated with it, but we need a better shovel.
So Mitch, I think other folks are starting to talk about similar concepts and ideas, but do we need a different way about thinking about databases to make this AI thing really work? I think that's why, you know, you've, you hear the term context engineering, right? Beyond just more prompting engineering and think all of us who've worked with AI know that instructions are just part of the answer, right?
It's now here's, here's the context in which I want you to perform this task or analyze this data or search this information. So if we review, if we review the data that AI has access to, it's just a giant repository of everything in the world. Kind of like we think about how the model's been trained, right?
They've been trained on the entire internet. Well, little, little more nuanced than that, right? It's, it's contextualized in a much different way.
We have to contextualize how we use ai. So a bot or a prompt or whatever agent, whatever it is, needs more more understanding of what you're trying to do. And that's why you see even in the consumer products, right, that we do with chat, GPT has had, uh, memory for quite a while and now you see Gemini and also Claude, uh, coming out with memory, meaning it keeps some memories about your past, uh, actions, things that you prefer.
Some of 'em are intentionally saved, some of 'em just your prompts, it's a combination of things. But that's all to add context to what you're doing. So I think what Mongo is saying is, look, we can be the repository for your data.
Anybody can do that. How do you do this in a much more intelligent kind of context aware way? So that way, and, and also use structure when you need to use structure.
So for example, they talked about JSON. JSON is is actually a really good thing for AI because it, it takes, what we like to, to type in is natural language and it puts a structure around it makes you really clear what it is, um, sort of a lexicon, um, some definition around it. And it helps it, it gives more structure to what it's doing.
So I think a lot of what we're doing today is experimenting with prompting and we're gonna learn much more about how to do better contexting around prompting. Can I, can I, I just wanna make sure I got this right. A company that sells small databases for unstructured data says what we need to make our AI models better are smaller databases with unstructured data, Is that, that are processed, that are processed more efficiently.
So They're well that be processed more efficiently if you use a smaller database with unstructured data. And by the way, we sell that. So, so you, Well, it doesn't have to be a smaller database, right?
Document databases can get pretty large these days. Yeah. And I can string those together in a way that makes them, you know, feel like one logical entity.
So I don't think size is what matters here, but Yeah, Alan, you make, you make it Sound spoken like a true, like a true, I think there are people would who would disagree with you, but I'll leave it at that. Been wishful thinking in that. Jack, go ahead.
I, I, I think it's all about the effort And someone once said, prove me wrong, but go ahead, Jack On Conversation Panel. Of course, Jack, take us out here. Come on.
You Make it sound like a conspiracy theory, Alan, but I believe that there, there really is some validity to what they're saying. So I'm, as you can tell from the hotel background, I'm on the west coast today and this week for a, uh, securities field day. And last week I attended a teleport event and one of the presenters there told a little story, which I think is applicable here.
And it's basically, you know, I used to go, you know, visit a town and you'd say, okay, I wanna find a place to eat. So you go and you hit Yelp or something, you say, go give me a list of my favorite types of restaurants. And you do a manual search and you hit Google and you look at reviews and you say, okay, now Google is this restaurant open right now.
And eventually make a decision. That's how we all used to do it. It was very manual intensive process.
Now you basically go to your little app, AI app on your phone and just say, yeah, hey, I'm interested in a restaurant. Find me a restaurant. The app has context and history that says, I know what type of food you've chosen in the past, and I know where you're located and I know what time of day it is.
And I can take all of that information, that additional context to the query without you having to do that. And it's those little pieces of information that you need to have give to the ai. The problem today is the AI databases are designed for a specific task.
And that's the big stuff, right? That's rag retrieval, augmented generation where you have a very big set of stuff that you're looking at all of the data that's in a company, right? So you're, you know, gigabytes and terabytes of data.
And here what we need to do is track little tiny pieces of information that just, uh, make the prompt and the AI work better. So I think they have a point maybe whether they're the right people for that. That's a different question.
Maybe. I think it's prevagen for AI agents if you think about it. So, but Like, come on.
You know, and I remember when you used your photo guide, you didn't have Google to make recommendations and all those things, but oh, you just stopped. It was ever was open and you took your chances and you found new places like that. It was half the adventure.
But let me, let me come back to our friends at Mongo. You know, they're a little late to the party because I think a lot of the people I know who were looking at operationalizing AI and using ai, you know, had the idea of creating small language modules or vector database kind of information, exactly what we're talking about, to give it more context, to give it more, um, subject matter expertise on a given narrow, uh, field that you won't get when you just use that big LLM. And I think for a long time Mongo was sort of deaf, dumb and blind to quote Pete Town Townsend, right?
Um, to this use case. And now here we are, and Mitch, you know this, you're shaking your head. You were at that AI operationalizing AI workshop we did those two years ago, then you quoted Tommy, so you got me on both.
Well, you, you, you got you on that one. But now two years later, all of a sudden they're saying, oh yeah, we should use that vector database or vector search. Well, let, let, let, let, let's be fair, they had us, they had a vector database of their own or vector search capability.
They just didn't embed it in the database. They had it as kind of ancillary kind of thing. It's not like they've been blind to the use case.
And a lot of folks do use Mongo because of what Mitch was pointing out. It's json, the JSOI don't have a whole lot of conversion. Most of those AI models are speaking JSO already.
So to that end, I think, you know, as far as the convergences, yeah, that could have been done faster. Mm-hmm. But I don't think they've been blind to the use case.
They're yeah. Know, if I go look at a lot of these AI projects, you're gonna find MongoDB in there. I think what's curious to me about, I almost invert announced, I'm sorry, go Mitch.
Now what, what's curious To me, uh, Mike, and I'm Not sure sure if I, if I caught enough to really put all the pieces together, but what Mongo also said is that repositioning databases from being a data store that you access data from is to as an AI platform for workflow and for agents that combines like, you know, native vector search with semantic retrieval and you know, lots of, you know, kind of nice language around, you know, technical terms, queryable, uh, queryable encryption, things like that. I wasn't quite sure that I got the, the transition from data to orchestration or data to AI platform. Um, did, did, did that jive with you at all?
Can you fill in the gaps for me at all? I think that, you know, they will have to decide to what degree they wanna orchestrate those AI agents versus just kind of expose data more dynamically to them. Mm-hmm.
And there's a level of orchestration that's required to do that. But I imagine that they will probably expose their database to the orchestration layer APIs to provide more of that coordination because they'll be the agent and then there'll be the data that has to be accessed and the data will have to be in something that feels like persistent memory. And I think that they're saying that, you know, you're gonna cache the crap out of a, uh, MongoDB database to provide that memory and that they're gonna provide, I guess I would call it the metadata around the memory so that it has that kind of awareness in the context.
So be the data in whatever forms, memory, context, data source, all of those forms that, that would fuel an orchestration layer or workflows that agents do. Is, is that what you're saying? Yeah, I believe that that's what they're in as well.
I don't think they won't be the orchestration layer for the agents themselves. Okay. Right.
That confused me. Okay. Thanks that, that helps a lot.
But I'll Credit you in my next paper. Yeah. But of course, you know, of course next week I'll turn around and they'll buy some orchestration framework and I'll Yeah, true.
Yeah, Exactly. Interesting. Okay, thanks.
And all, all kidding aside, you know, it is quite the a a bit of an unknown story or an under-reported story exactly how big a powerhouse Mongo is. MongoDB is in the ai Yeah. In the AI space.
If you, if you're a certain, if you're a certain database company owner who's recently seen his fortune go up by 34% because he's trading GPUs, may, maybe that makes Mongo a target for some of that money. Chu change. I, I think that there, all the database companies are gonna have to address this issue and everything's gonna have to be in these kind of smaller, dynamically processed chunks.
I don't, so I'm not quite clear that one of them is gonna be, uh, better than the other. I just think that the way we consume that data needs to be changed and we need to think that through, because that's what's holding up a lot of these projects in the enterprise, right? Yeah.
They're just not, I do think Mongo is the new MySQL. It is sort of the new default when you're gonna move to something beyond, And you, you know, what happened to MySQL? Well, I'm, I wasn't trying to foretell that, but maybe what, um, but it is widely used and not just for ai, but it's used in a lot of cases.
You see sort of the default on that of open source in a lot of different projects is you need a database. It's really the Mongos or Mon Mongo, excuse me. Yeah.
And that's because developers are picking the database. And developers don't really like relational databases. They're big, hard, and clunky and hard to manage and document databases are easier for them to deal with.
Whether the IT team likes that when they get handed the app is a whole nother conversation. Hmm. Mm-hmm.
Excellent. Gentlemen, I think we gotta call it a, a wrap on this, Jack. Enjoy the West Coast.
Uh, I I will be joining, uh, the tech field day, I believe on the 24th, isn't it? I'm, I'm not gonna be there in person. I I'm gonna be remote, but, uh, I'll see you on there.
It should be fun course. Yep. Um, I won't be on tomorrow's show.
I'll be observing the Jewish holiday of Rosh Hashanah, or is when I, my grandmother taught me Rosh Hashanah Hashanah, but, uh, you know, it is the Jewish, uh, new Year and start of the Holly High Holy Days. And I'll, I'll be off for that. But Mike, you'll, you'll drive the ship.
I'll be here. And I, I assume you'll be dreaming up new fancy malware names. 'cause you know, now that you've got a new hobby, I'm gonna, I'm, yeah, I'm going to, I'm gonna think about those.
I'm gonna Come up with, with some good ones. Hey, Mike, why, why are the cat away? Just to plant a seed of an idea, let's come up with some intro theme music like they do at the sporting events.
And if Jack's on, on our next show, I wanna make sure he gets Indiana Jones Like they do at Yankee Stadium. When you come ups bring in Mariano. Exactly.
You, it's funny. So I was at Swamp up, uh, last week or the week before, and they're, they, they had a gal or dinner and they had a celloist as the, as the town, you know, as the entertainment. I'm saying to myself, a celloist, my God, this is gonna be boring.
What am I doing here? And turns out she's a very famous woman down in la She does a lot of movie soundtracks, Mitch, including Dune. And she played the theme from Dune on her cello, accompanied by some musicians, and it was amazing.
Amazing. Wow. That sounds awesome.
It was really cool. Really Cool. I'll find out about her.
All right. Hey, enjoy the rest of your day. Enjoy Textron tv immediately following this.
And by the way, on that tech field day, you'll be able to watch it live too, right here on Techstrong tv. I'm Alan Shimmel. We're out.