Power Struggles | TSG Ep. 863
Alan, Mike, Jon, Terri Robinson, and John Morello explore the rising cyber warfare tensions surrounding the Israel-Iran conflict. They break down how cyber espionage and critical infrastructure attacks are reshaping global conflict, drawing parallels to tactics seen in Ukraine and beyond.
The discussion then shifts to the Model Context Protocol (MCP) and how it will help integrate AI agents into DevOps workflows. Finally, the gang unpacks the brewing GPU battle between AMD and NVIDIA as both companies race to dominate the AI hardware space.
Transcript
Hey, so there's a shadow cyber war shadowing this Israeli Iranian conflict. We're gonna talk about it. You're watching Textron Gang.
Hey, everyone, happy Thursday, and welcome to Textron Gang. We've got a great show lined up for you. We've got some important things we want to talk about today, and we've got some important people to talk about it with.
Let me introduce you to our gang line up for today. First of all, I'm happy to introduce someone making his debut on our Textron gang, but he's no stranger. If you've been in the world of cyber and DevOps and DevSecOps, I, I've known the man for a long time and thrilled to have him on here.
Let me introduce you to John Morello. Hey, John, how are you? Hey, Alan.
Good to see you again, and thanks for, thanks for having me. My pleasure. John, since it's your first time on, give people a little, be beyond what I said.
Give him a little bit of who John Morelo is. Sure. So, like you said, I've been, uh, doing this cyber stuff for, uh, I guess 25 years at this point, going back to, uh, many years at Microsoft in the two, early two thousands, uh, then probably we're best known for, uh, the company we had in 2015 Twistlock that kind of started the whole container security world.
And we sold Twistlock to Palo in, uh, 2019. Uh, and we have a company now minimus, uh, that basically helps organizations reduce the risks in their, uh, containerized environments by giving them purposeful built, uh, images that reduce the number of vulnerabilities by 95 to 98%. So really dramatic changes in, in like their risk posture.
Uh, so you can see more of that and try 'em out at minimus io. But appreciate you having us all, Alex. Absolutely.
I interviewed Minimus. Great, great, great product there. John, you're usually CTO.
Are you CTO at minimus? Is that I am, yeah. We, we all, we all have our little, uh, roles that we play.
Yeah, No, that's, that's your way. My team is the, yep. Team is the VP of r and d.
Same as usual. Yep. Good for you.
All right. Moving on from John, our, we have another resident cyber expert we're thrilled to have on. She writes at Security Boulevard, as well as just really well known in the cyber media world.
Our friend Terry Robinson. Hey, Terry, how are you? Good.
How are you doing this morning? I'm happy to be here. Happy to be here, and glad to have you on.
Thank you. Glad to be here. So, moving from the East coast to the West coast, our, our Silicon Valley man on the scene.
John Swartz. Hey, John, how are you? I'm good.
How's it going? Well, it great to be here. I'm looking forward to the show.
I'm looking forward to hearing what you have to say. Hmm. And then I'll go.
Well, there's no joy in Harrisonville today. The mighty Yankees have struck out again. Is it about 30 innings without a run now, Mike?
Yeah, I think it's some sort of contagious disease that's got the whole offense suffering. Four, nothing coming off a two a one, nothing. A two, nothing.
It's kind of disgusting. Let me just say that down here in Florida land, we're real happy to be celebrating our hometown Panthers winning a Stanley Cup. The second in a row, I, let me just, for the record, I'm a New York Rangers fan, but look, I live down here.
You gotta give the boys credit two Stanley cups and a row. Not bad. So go Panthers.
Um, it's, It, it's the frigging middle of June, and we're playing hockey. How silly is Brett? It's South Florida and we're playing hockey.
It's silly to begin with. What, what do you want? Anyway, let's get into our show real quick here.
Right. So, Mike, as I say, I teased in the opening, you know, there's a, there's a shadow cyber war of kind of ghosting or following this, the hot war between Israel and Iran. What do we got?
Yeah, Terry has a story about the hacktivist part of this equation, but, um, there's also cyber espionage and all kinds of attacks on critical infrastructure. And Terry, I guess, has this just kind of emerged as a, as a new front that needs to be battled in the same way we have more on sea and more in the air and war in the ground. There's war in cyber, So no sooner had Israel launched its strikes against the, you know, um, Iran nuclear infrastructure than the cyber theater opened up.
Right. And I think that, um, at to, to no one's surprise that that happens. I think that, of course, um, we need to start treating that, um, like its own, its own theater and have the defenses shored up, um, before this stuff even gets started.
Uh, Radware was the one that first observed sort of an uptick in, um, activity and telegram channels, and they're, you know, from the actors that are sympathetic to Iran. Um, and, but this is, this battle in cyber with these two countries is not new. You go all the way back to stucks net, um, was that, gee, 2010, um, when the Stuxnet worm was deployed to hobble the centrifuge critical to the, to Iran's nuclear program, and then DDoS attacks, uh, just a decade ago on US financial institutions.
So, um, in, in early indications, there were claims by the Arabian ghost that Israeli radio stations had been shut down. I think the one that it sort of concerned me and, and made me wonder why they weren't, their defenses weren't showing up, is that the Mossad website was shuttered. So I, I'm not sure why these things haven't been more protected.
Um, in addition to sort of this disruption and, um, some of the damage that they can do, um, there's a huge disinformation campaign already underway, and as we know, the disinformation campaigns are extremely dangerous these days. So John Morello, um, is the cyber community, um, is the cybersecurity community watching this closely? Because there's things to be learned here.
There's new tactics and techniques, and this will become, uh, something of an example that we cite for many years to come. Yeah, I mean, I think there's, you know, anytime you have a major geopolitical event like this, and there's cyber response and cyber acts that are occurring as part of it, there's always an opportunity to lge just as there is on the, you know, kinetic battlefield. I mean, I think one of the things that's been most amazing, uh, in these conflicts in, in both Iran and in Ukraine in the past, uh, just few weeks, has been, uh, the use of drones as a way to really asymmetrically, uh, do things that, you know, historically would've required, you know, substantially more risks, substantially more military hardware and planning and so forth.
But I mean, the, the notion that, like, for example, with Ukraine being able to disable, you know, a third depending on, you know, the numbers that, that you believe disable or destroy a third of, of Russia strategic, uh, you know, aircraft. Uh, and with Israel potentially destroying substantial amounts of ballistic missiles on the ground using drones. And the fact that those drones were not launched from the territory of the attacker, but rather were launched from within the territory of the attack, I think is a really amazing, uh, thing.
And frankly, something that, that concerns me a lot as an American, I mean, if you think about just having like the free society that we do in the US where it's relatively easy to travel around, it's relatively easy to, you know, to import materials. It's relatively easy to buy properties. You know, you can even, um, easily imagine adversaries, you know, purchasing properties, you know, close to American military bases and spending years developing facilities and, and capabilities for drones and be able to do things in the US homeland that historically, you know, the, the oceans had basically shielded us from.
So I think there's a lot to learn from the cyber standpoint. Um, you know, I think one of the things that's been interesting to me with it is there has been less obvious, uh, actions on the cyber side, which I don't think implies that there have been less actions, maybe just less things that have been visible. I think what, what what we don't know is maybe all those things that have occurred, you know, that have not yet made it into reporting like what Terry's done or not yet made it into the, uh, historical records that we'll find out years hints from now, which probably were involved in Israel having such, you know, exquisite intelligence about the locations of Iranian leadership.
You know, there's a good chance cyber had a role in that. Um, and you know, there's really no telling what else cyber is doing to be able to inform Israeli war planning around the location of ballistic missiles, the status of the Iranian nuclear program, you know, and, and other activities that, that directly result in actual, like, kinetic decisions about how they go to, to battle. So, um, I think Terry's reporting is really interesting, but I think there's probably a lot more that we'll all learn in the coming years that, that it's gonna reveal more about how cyber was so instrumental in All of this.
Yeah. That blend of cyber and kinetic is, is gonna be something to, you know, to watch going forward. I honestly believe that they're codependent at this point.
Um, and they're working in tandem. Yeah. So, um, I think it will be interesting to see what, uh, kinds of actions emerge later on.
Hopefully we find it out, out about 'em sooner rather than, than, uh, than later. But I, I tend to think it'll take a while. But, but let me let, let's be clear, John, you mentioned the Ukrainian conflict.
The, the fact of the matter is we've seen the cyber theater play a role. I, I guess the first time I saw it that I remember was when, uh, Russia was going after the Republic of Georgia, right? They, they took out, they kind of instigated a coup and took out the President Shakia Valley or whatever his name was.
They, they really, they shut down George's internet basically. Uh, they also did it, I think in Chechnya when, when they had a, an uprising there. So Russia's been at a, a leader in this a while.
Um, but I think in every conflict we're seeing cyber plays a role and there's, there's offensive and defensive aspects of it. John, you mentioned intelligence gathering. I'm sure, I'm sure they, you know, they had find my iPhones on, on some of these Iranian leaders, you know, uh, it's crazy when you think about it, you know, and, and then when you look though at the two combatants here, you look at Iran, you look at Israel, yes, there are Iranian hacktivists that are funded by Iran.
And you know, they're, they're not slouches. They're not slouches. I don't think if they, they didn't take down the Mossad site unless the Mossad site wanted to be taken down, because Israel had the advantage of surprise here.
They knew what they were doing, so they probably had a chance to shore up before the attack. On the other side, you're talking about Israel, the people behind unit 8,200 or whatever, 8,600 talking about the people who like, have invented a lot of offensive cybersecurity, though, let's not think that the NSA are, are choir boys, they're not. Right.
Probably us is as guilty as anyone or as thick admit as anyone else. I I, I hope so. As an American citizen, yeah.
I hope that's The case. Case. I mean, everything I've always learned, and, you know, having also been John in cyber 25, 30 years and sold to a lot of the agencies over the years before I got into this, the NSA still probably the premier outfit in the world, right?
And, uh, but the Israelis are no slouch, hence the whole Israeli cybersecurity industry. So you've gotta assume that they've been doing offensive and defensive type of, of operations that are, you know, thick and full there. Um, but, but let me put my bow around all of this.
Modern warfare is cyber warfare. Women's rights are human rights, modern warfare. Warfare is cyber warfare too.
And any, any combatant who doesn't put that into their mix is seeding out some really big territory. I suspect this has already gone global too, right? Because you gotta figure that Russia and North Korea are helping Iran and the NSA here is probably helping out Israel.
And so I don't, the con the physical con, I, I don't know, Mike, I don't know. Because you know what, if you are Russia and, and it's, and you could see it by Russia's public actions as well, you may not wanna, you may not want to get that involved in, uh, in this, certainly not leaving any fingerprints. No, but I, I'll, I'll also bring up another point that I think is, is like really, uh, probably very directly relevant to the IT backgrounds that, you know, I think all of us had, and probably a lot of the audience has with it too, is, you know, we talk a lot about supply chain security and software supply chain security.
You know, you can see kind the physical manifestation of that in at least a cyber adjacent way with, with what, uh, Israel did with Hezbollah and the pagers and, you know, the VHFA is, which was, you know, honestly like an incr incredible operation. I mean, just like stuff From us, I mean, truly, truly. But it also really makes, I mean like, as, as somebody who's like, you know, very much into the industry, our whole business is about, you know, providing customers with secure software, images that include all this open source stuff.
You know, one of the things that I think about often with this, and that there's not really easy answers to, is there are so many, uh, individual open source packages, libraries, projects, whatever you wanna refer to them as, that are fundamental to everybody's usage of the modern internet infrastructure as we know it. And many of those projects are not things that are common sort of household or industry names. You know, like every, if I said Nginx, everybody knows that everybody's used that and so forth.
But there's probably, you know, a few dozen individual tiny little components that go into making an n engine X build work that are much lesser known projects that might be maintained by, you know, one or just a small number of people that don't really have very much name recognition at all. And, you know, you saw, I believe it was maybe a year or so ago with, uh, an example of, you know, what I believe was, was likely some nation state actor trying to compromise a, a, a compression library that was widely used in a very, like, um, you know, I think very, uh, skillful way that was not like an obvious kind of compromise that they were trying to poison that supply chain very far upstream so that it could emanate down into lots of other applications that use that. One of the things that really concerns me is our ability as a, you know, frankly as a society, I would say to, uh, to, you know, that we're both reliant completely in our, in our just normal operation of all these systems that everybody, uh, uses that, you know, are frankly maintained as, as almost like hobbyist things in the open source.
And it's very difficult to know, in many cases, are the people that contribute updates to those things, are they doing so like, you know, in a good faith manner to improve that? Or, you know, are they potentially working for some kind of nation state or just motivated, you know, um, you know, kind of hacktivist sort of actor there to do something to poison it? And you know, so far we haven't seen tremendous amounts of examples of that occurring other than like the one that I mentioned, and, and probably a few others.
But I also always wonder if you really got into a situation where a, a major player in this, a Russia, China, United States for example, felt really existentially threatened, what other cyber weapons would come out that we don't know about yet that are out there that would be very difficult for organizations to defend against. 'cause they already were running that stuff inside their environments. And like I said, there's no easy answers to that, but it's something that, you know, being in this space, being very intimate in this space, it's something that really I think about a lot and concerns me a lot.
'cause there's not easy answers for how do we reap the benefits of this kind of open source ecosystem while still being able to protect against that kind of threat. You know, with, with this asymmetrical warfare, there's like a sidebar going on that's kind of interesting to me that applies to Silicon Valley in the beltway. And there's this emergence of, of AI and these AI contracts that are being awarded by the federal government for cyber defense purposes.
So Monday OpenAI has something called OpenAI for Government Initiative, and they got their first big contract from the Pentagon on Monday, one year, $200 million. So their AI tools are gonna be used for, for, for proactive cyber defense. Um, they also have a partnership with and oral, uh, to improve our defense systems.
And it, it's interesting too that there, that we have, uh, yet another partnership between Anthropic AWS and Palantir to provide Claude models to intelligence defense agencies. So you're starting to see these, these companies and, and for open ai, they really are want to concentrate as much on government contracts as the consumer side. And so we're starting to see that development of that, that angle as well.
And, um, it's gonna be lucrative and it's gain gaining a lot of attention and a lot of interest from AI companies. It's gonna get scary because the bad guys are using LLMs to take vulnerability and create an exploit in a matter of minutes. And the attacks are gonna be essentially in real time.
And we're not really set up to do that kind of defense. So, you know, maybe Amazon is, but most companies are still running around, you know, trying to manually update firewall rules and it's just gonna be crazy. Let me, let me bring it back to the Iranian Israeli conflict.
You know, there's a difference between sympathetic hacktivist and the state itself and the hacktivists are nice, but it kind of sounds like Matthew Broderick to me, let's play thermonuclear war versus trained professional cyber warfare cyber soldiers. And, and I think the results you're seeing in the field probably point to the difference between them. Um, they're facing the website.
I mean, we're hearing reports that the Iranian, uh, the internet in Iran is, is very much on and off now. Is that the Iranian government shutting it down so that people don't shutting down descent perhaps, or shutting down, you know, information that could lead to Israel and and used for targeting and so forth? Or is it the Israelis shutting down the internet to affect Iranian communications?
Little or both. Maybe AB absent. I mean, I guess that points to another problem.
It's kinda like the democratization of, of, uh, cyber warfare for less of a, for lack of a better term, um, has certainly made that a more complicated, um, picture, hasn't it? Like who's doing what to whom is the government involved? Yeah, you know, you know, you don't know who the good guys, the bad guys and what the good guys consider good and what the bad guys consider bad.
It's all, it's all cyber to me. Anyway. Hey, let's take a break.
We, we've kind of gone overboard overtime on this one. We're gonna come back and let's talk about MCCs and DevOps. You're watching Techron Gang.
Hey folks, we're back. And as Alan alluded, we're gonna shift gears a little bit, maybe something quite not as serious, but definitely important and profound. There's this thing called the Model Context protocol created by Anthropic, and it basically provides a, a bi-directional link for AI agents to communicate and access data.
And now we're starting to see this in DevOps. New Relic and CloudBees are both at the forefront of kind of putting together early previews of this. But Alan, we've been around this block for a long time.
I think I'm gonna see, like every vendor in the planet is suddenly gonna have an MCP server. You know, Mike, it's funny, I you are not kidding. I think I've already, it, it, you know, in this week alone, I've probably done four interviews around companies rolling cps, not counting New Relic and, and CloudBees, but what is it point to, right?
It, it points to everybody wants to cash in or at least be perceived as riding the agent AI wave. And you know, what does it really mean? And I, I have this problem.
Where do we draw the line between agents and APIs, right? Or do agents now manipulate APIs or master APIs or use APIs? I don't know.
But certainly mc here, here's an an interesting thing. Anthropic floated this MCP protocol and it has become the defacto standard now for agents talking to agents. And that's why everyone's adopting building A MCP in, into their platform.
Now, I, I see it a lot with the observability players for sure, right? And, and so New Relic to me was with all due respect, a little bit of a, of a me too. I think CloudBees is out ahead.
I I haven't seen GitLab. And maybe so though, I think Jfr, JFR OOG has MCP, uh, in their, in their stuff. But certainly all of the DevOps players are gonna have MCP, uh, availability because it, you know, we spoke in cyber about the, the pi, the cyber store.
We were talking about software supply chains and stuff. That's what DevOps is focused on. The, the software supply chain, the CICD pipeline.
And you're going to, you know, you're gonna have agents and APIs throughout this, and you, you need that m you know, if MCP is the lingo franca of, of this, you, you need to have that built in. There is this debate about what exactly MCP is, because some people would say it's a variation of an API written in JSON. And, um, you know, and that's what makes it accessible.
Other folks say it's a, something that sits between an API and a full boat connector and it provides that level of integration. But John Morello, um, are these gonna be like big fat new Ridge targets for cyber attacks? Because it seems like that would be the first place to go if I was a bad Guy.
Well, I mean, I think, I think attackers like always naturally follow like the, the places where there is the most uncertainty and chaos and churn in organizations. 'cause usually those are the things that are least understood and most susceptible and, you know, most frequently changing. And so because of that, there's more opportunities, you know, to find potential weaknesses and, and vulnerabilities in that.
Um, I, I do think it's interesting in this space that you, you know, like you see almost every new major wave of technology, Colin, following similar adoption characteristics. And I think about, like, this is very akin to when containers really started coming out and, you know, the, the mid 2010s and people started using them and everybody, you know, was using Docker. And there was a few other like management frameworks that were like a big deal at the time.
You had, um, you know, DCOS and you had Docker Swarm and you had Kubernetes and so forth. But, but usually in these things, the industry sort of on its own, just as a, you know, free market, uh, evolutionary, uh, uh, path tends to, to converge around one set of standards for manageability. When you've got all these kind of like, diversity of, of implementations.
You know, obviously in the container world that's been Kubernetes, MCP seems to be that around how do you programmatically connect applications to models. Um, but I think the thing that's, that's really interesting about this from a cyber standpoint is everybody to Alan's point has rushed to say like, oh, we have Ancp two, right? How, how high quality that's been done, how rigorous that's, you know, it's been, you know, really threat modeled and tested and thoughtfully built and so forth.
I think it's, it'd be wise for people to have some skepticism about that because to build something that's potentially so complex and sophisticated and enables access to data and resources that are, are not just complex and high value and sophisticated, but actually can take actions, you know, on their behalf, uh, is, is kind of a different level of threat than we've really seen before. You know, like if, if you think about the securing technology, really up until the prevalence of, of all these, uh, AI capabilities that have, have really become mainstream over the past couple of years, you were typically saying like, I want to protect access to my data or to computing resources that if an attacker took control of them, they would still have to manipulate and, you know, run commands from them and basically act as though they were the owner of that resource. You know, but it was the attacker that was telling the compromise resource what to do.
They be that to exfiltrate data or to be used as a node in some sort of doss attack or whatever you have for the first time. Now, though, something I think is really interesting in that none of us really fully understand at this point, which is you can have attackers compromise that MCP layer and potentially through that access layer, be able to interact with models that can take unknown actions on their behalf. You know, of course if they give it a sufficiently detailed and focused prompt, they can control that a lot, but you don't really necessarily know what it's going to do, and not, not in nearly as a deterministic manner as, as you did in the past.
Uh, and so I think for, you know, for everybody in this industry, it's, it's a, a whole new world of potential risks and threats and scenarios to consider. Uh, and frankly, I don't think anybody has really an answer for it because we haven't seen enough of it in reality to know, like, what does that mean? What are some of the things that people are gonna exploit with it?
But it's certainly an area that, uh, you know, that's gonna be very interesting to see how it develops in the, over the next few years. Because like I say, it's, it's really the first time I think that a cyber risk could expose potentially open-ended, unknown potential downstream effects beyond what even the attacker themselves intends to do. Mm-hmm.
Terry Robinson, how many days or weeks away are we from the great MCP server misconfiguration Crisis? That's what I was actually just thinking about. I'd say minutes, Mike.
Um, this just, just tore creates greater potential for misconfigurations. You know, that's a, that's a particular source spot for me. I, I don't wanna say sore spot, but I get annoyed every time I have to write about a misconfiguration.
Um, but, but I think, uh, probably what John says, you know, aggravates that, right? That sort of rush to market or rush to, you know, get these things out there and then that just makes the, the, the possibility of misconfigurations that much higher and that much quicker. I, I say minutes, I say it's happening as we speak right now, You know, let me, let me throw something else at it, the panel and take your thoughts on this.
Are we rushing MCP, right? Everybody's talking about agents, everybody, you know, we're all gonna have all of these agents. I've got agent 86, 99, 0 7, 0 0 7, all of these agents, and we're building these CPS to handle all of these agents, but are we building like a lot of dark fiber, like level three did in 2001 when the internet boom kind of had died down and we overbuilt capacity.
When are we really going to use these cps? When, when will we really run of these agents going mainstream? I know everybody.
And that may sound, what's the word, treasonous in, in today's tech world, right? Because we're all about the agents. Actually, Alan, I very much, uh, agree with you and from the standpoint of like, I think it's good to have a bit of a, like a reality check and some skepticism on it.
Um, I can tell you, it's just being like, you know, in the venture backed world for the past, uh, decade now, the amount of hype and noise, um, that surrounds anything related to AI today, uh, is, is kind of overwhelming. And, you know, the, the money is, is flowing to, to kind of, for you to get any of the money that flows through that VC machine, you, you have to have some kind of story around ai. Um, I think, you know, all of us have used various ais, particularly like LLM type of implementations, you know, in our daily lives and work lives and so forth.
There's amazing stuff that they can do. I mean, like, there, it's, I'm not at all downplaying the capabilities of it, um, but I think that there's also a lot of sort of, uh, breathless, uh, talk that's probably not really realistic, um, today, you know, like, you know, you hear, I, I think the philanthropic CEO had some quote the other day that like, you know, uh, AI was gonna result in like 80% unemployment in two years or something like that. You know, like there's, there's aspects of this that, that Yeah.
He said, yeah, ba he basically had John, yeah, basically he said whether it was like half the white collar jobs are gonna be lost within two to five years, but then the caveat always is that they're fundraising right now. So I think he's growing out as much fear as possible. Right, Exactly.
Well, I just think, like, to me, Elise, I think a lot back to like the, the very late nineties, early two thousands with the internet itself, where like there was similar predictions, like everything was gonna change and so forth, and obviously like it did, it's like a fundamental innovation in human society. And I think AI is the same thing, but you know, like the idea that that's all gonna happen like in the next two years, and that like, everything just kind of like magically gets solved and, um, you know, I I think it's probably unrealistic. I think much like the internet, you'll see like, you know, 10 years from now, five years from now even.
Yeah, exactly. Look, I, and there'll things where it's valid really good. Remember John, and you were around then, John, both Johns were around Terry, Mike, you were too, right?
com days, you know, you'd put together a PowerPoint of a business model, and you would claim in the PowerPoint that your present value was seven $70 million, and you're looking to do a post raise at a hundred, you've got no revenue, a business plan, and you lose 10 cents on every dollar you do, but you're gonna make it up in volume, right? And, and that model, you know, internet sch internet, it doesn't work. It's, it, it's, it's against the laws of physics.
And I think there's a lot of that same, what did he call it? Alan Greenspan. Irrational exuberance.
Irrational exuberance. There's a lot of that going around here too. And part of that exuberance is let's get an MCP server in here.
We'll see. Anyway, we're over time on this segment too. It seems we're over time on every segment you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide, our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back with our final block and it's about a MD versus Nvidia.
And this has been a battle that's been long brewing, but a MD is now showing some chips or AI chips in actual servers that people can buy. And so the argument is is, you know, a MD John Schwartz has wrapped itself in this open source flag and is saying that, you know, Nvidia is all about lock in and they are all about openness. But the question is, is can a MD really catch Nvidia?
Is Nvidia just too far ahead and Yeah. You know, yeah, you, yeah, you, you read in my mind. I mean, it's, I mean, it's almost to the point that we're thinking, we're saying remember a MD somewhere that, that company, that other company, right?
So there was all those hoopla around Nvidia dominance. There was, where in the world is Jensen Wang? We, you know, he has a special guest appearance at every conceivable, a ai AI event the last two years.
And then if we're not talking about them, we're talking about the FIEs at Intel. So somewhere a MD got lost in the shuffle, and, and it is kind of, it's what's unfortunate, even this company's reputation, which is incredibly good, I think in the Valley, it's a universally lauded CEO, and it's, and it's kind of avoided this whole political fallout with, with Trump and kind of maintained its dignity. But they, in a sense, Mike, yes, as you said, they, they were trying to offer this clear message to differentiate themselves from Nvidia at their event in San Jose.
And, uh, they wanna present themselves as this leading player in an enterprise AI market, and at least be in the conversation. I think that's what they're trying to do. And, and the way they're trying to do it, I think core to it is this competitive strategy of a focus on open standards and interoperative approach versus Nvidia, which is mix of open source and proprietary approach.
So in event, and sent in some way, and Alan has always said this, he's always driven at home in every major market, there are like three major players that are gonna survive. A m D's gonna be fine, they're going to be a distant second to Nvidia the foreseeable future, but I I la them and, and, and, um, give them major credit for at least trying to differentiate themselves and kind of try to counterbalance this, this, this fusel lot of, of these constant Nvidia news. Um, so competition is good, and I think we need to have like another choice.
Nvidia kind of scares me in a certain sense too, because they're too powerful for the wrong good. I think of AD is the Jan Brady of, uh, chip Knickers. So the Marsha, Marsha, Marsha is, uh, Nvidia, But you know, what if I, I love the Brady Bunch reference, but if I had to pick a company to play this role, a M D's damn good at it.
They, they played this to Intel for 20 years, and you know what? As we sit here today, they did a damn good job, right? Intel was, for all intents and purposes a monopoly, but a MD stayed in the game.
They couldn't go toe to toe with the Intels, but they stayed in the game. I suspect it'll be a similar thing here, right? And then, look, Q Day is coming, Q day is coming, and who has the quantum chip?
And is that, is that guy gonna wear a synthetic leather jacket and go to every conference and, and Hey, well, I wouldn't count a MD, uh, for the following reasons. One is they're actually doing quite well in traditional servers, and, you know, most of the, at least more than half of the new servers that people are rolling out have a MD processors in there. So they have the, the chops to fight the fight and open source is it, it's a classic, you know, tortoise versus the hare kind of thing.
Open source has historically been slow off the mark, but eventually wins the race. So I don't know, Alan, you know, if I look at these open source libraries, developers like that, maybe eventually a MD will resonate with those folks. What, what I find interesting though, Mike, is if you, if you listen to Jensen CDA and the rest of the, of their software empire is open source, isn't it?
I don't think CDA is open source, but, and the people who write it are all Nvidia people, and Nvidia has a strong No, I was gonna say, I think it's an example of one of those things that's, uh, you know, like I kind of refer to as like a, a quasi open source. I mean, like, technically it may be, but to like Mike's point, when it's completely driven by one organization, like all the contributors, the, you know, the people that actually own who can, who can do check-ins and so forth, all work for one company. Like, I mean, I guess technically it is soon, but not truly community, John, how soon we forget because we're all used to what I call the foundational model of open source now, where you have the Linux Foundation, the Eclipse Foundation, Apache Foundation, and you have coopetition among competitors, and we're all kumbaya gathering around the maple, but before there was a, a foundational error, there's, there was what I call the big brother era of open source where every open source project was basically owned lock, stock, and barrel by one organization, and they ran it for their own benefit, right?
Going back in the security world, you know, Nessus was tenable and, and Snort was source fire and you know, it was open source, but it was controlled by them. And that that was the, that was the way open source ran until, you know, and in this big brother era of open source, IBM was good at this too. Um, so you know that that's the video video, But I think this space is a bit different too, because there's such, uh, you know, when you talk, think specifically about what we're talking about now with a MD and Nvidia, it's, it's not sort of a general purpose software that could be run, you know, independently of the underlying hardware layer, right?
It's, it's software that is to enable the capabilities of hardware. I think almost definitionally it's gonna be much closer. You could have open source software, but if it only runs on my proprietary chip, Doesn't matter.
It doesn't really matter What difference it make, right? Open source my toe. But, um, but like, you know, I, I think we all would like to see a MD be competitive here.
I think you wanna know the truth. I think Nvidia would like to see a MD be competitive, because if they're not, then you start using that M word and the m word gets scary, right? I'll also say having just been at Microsoft for a long time during the early two thousands, yeah, honestly, like, it, like I, I would tell you, and I think most thoughtful people there would've said, you, you are better off when you have some competitor who is credible.
Like, you don't want it to be winning, you know, 50% of the time, but you know, you wanna be credible, it keeps you on your toes, it keeps like, you know, some energy, it makes the market feel like it's something dynamic where it's not just like, yeah, it's just stuff like, it's, you know, I'm just gonna buy it and, and use it until it dies. Like, you really do need that. So, I mean, I think you're right.
Like if, if they're, if they're smart and thoughtful, which I, I'm sure, I'm sure they are. Clearly they've made an incredible business, so, you know, I think there's probably like, they wouldn't wanna admit it publicly, but they probably are more happy that there's like at least some competition that's out there. Agreed.
Agreed. I feel like we're gonna hold this con, I feel like we're gonna have this conversation over again. In theory, there should be a framework, kind of like the risk five people are talking about where having an instruction set that can run on different processors, and that should apply to GPUs theoretically at least.
But the problem I've seen over the years is that developers, you know, for that extra 10 to 15% of performance they might get, are willing to sell their souls for lock-in. Well, the other thing I'll say too is having, you know, we, we do do use some AI capabilities and, and our product and, um, you know, I've certainly worked with a number of companies that, that are customers that, that, you know, are very focused on either building AI services or really focused on AI enablement of their products. Um, one of the things that I hear consistently from them is just that Nvidia has really gone the extra mile to make the developer experience excellent.
Like the, the ability to get started, the ease of use, the integration of the tools, that they've really done a very good job with that. So it's not just simply like, you know, they're here, they kind of had like a, you know, monopoly position to begin with. One of the reasons that they've had that is they've made it as easy as possible for people to build on their hardware by having a great, you know, effectively like SDK, uh, on top of that.
And, you know, again, hopefully a MD is able to replicate that and have an equally good developer experience. But you know, that, that experience is, is what I think you're referring to, Mike, is it's not even necessarily about like, I want a little bit more performance, but if, if my job is 20% easier, let's say by using Nvidia versus using a MD, I'm probably gonna use Nvidia, right? Like, you know, like that's the, that's I think what, what drives a lot of those decisions.
'cause they are fundamental decisions made by the implementers. It's not like there's a corporate strategy in most places where you're gonna have, you know, senior management choosing what is the, the chip set manufacturer that they use. It's gonna be done, done by the people that are building the software.
And if, if that experience is easier on one platform than another, that platform's probably gonna win most of the time. Get, get your goal in handcuffs out. Right?
Exactly. Alright, Hey guys, I think that's going to put a wrap on this episode of Textron Gang. Good, good conversations today.
Important stuff we're talking about. Terry, John, and John and Mike, thanks for joining us on the Gang. Thank you for watching this.
We hope you appreciate it. Whether you're watching it on our tech strung TV stream in the morning, on demand, on Text drunk tv, or any of our sites or, uh, uh, YouTube text from tv, YouTube channel, or check out our OTT channel on Amazon Fire, apple TV and Roku, as well as iOS and, and, uh, Android. So lots of places to watch this.
Don't miss it until tomorrow though, we've got a full, uh, text drunk TV schedule following the gang. So stay tuned right here. But for now, this is Alan Shimmel.
We're out.