Salesforce SaaS Cyberattacks, Atlassian Buys Browser Co., OpenAI Acquires Statsig | TSG Ep. 918
Mike, Mitch, Tracy Ragan, Jack Poller and Futurum Group analyst Guy Currier dive into the root cause of a wave of cyberattacks being made against Salesforce software-as-a-service(SaaS) application environments.
Then the gang turns its attention to the reasons why Atlassian is buying The Browser Company before similarly looking at why OpenAI decided to acquire Statsig for $1.1 billion.
Transcript
Hey, everybody. Are you feeling insecure about your Salesforce apps? You're not alone, you're watching Textron.
Hey, everybody, welcome to the show. We got an awesome lineup. Once again, our friends, Mitch Ashley, Tracy Ragan, Guy Currier, Jack Poller, and we're talking about all kinds of fun stuff.
And let's jump right in with Salesforce and this whole security issue, as I understand it, it's kind of complicated as following, but, um, a company called Sales Loft, which provides an integration engine and apps to plug into Salesforce, bought something called Drift ai Drift. AI turns out had some, uh, issues with authentication and credentials, and now everybody's waking up one morning and discovered that their Salesforce platforms have been hacked. Jack, I know I grossly oversimplified that, but kind walk us through what's happened here, and is this something we should expect more of?
Yes and yes. This is really ugly and complicated. So you Sales Loft, which is not Salesforce Sales Loft, has an app called Drift.
It's an AI chat bot that does real-time scoring of interactions, uh, to help people, uh, qualify leads this. The Salesforce Sales Loft app is connected to Salesforce through an OAuth token. And so every user of every company that implements SalesLoft Drift gets an OAuth token to connect to their Salesforce instance.
Apparently, the sales loft drift environment was compromised. It's unclear how, whether that was phishing, phishing or, um, another attack. But as part of that attack, the attackers got access to the OAuth tokens that Drift uses to authenticate to Salesforce, that let the attackers directly access the company's Salesforce instances to acquire and download and extract the data stored in Salesforce.
So that's sort of the attack itself. The outcome of this is being portrayed as really a SaaS issue and a supply chain issue. And it is, but there's some more fundamental security problems that we need to talk about here.
As you noted, this is really an identity issue. An identity authentication issue is the organizations were originally compromised through a phishing attack. At least that's what we believe today.
This reinforces what I've been saying for a long time now, is a lot of organizations are worried about network security and, uh, zero day attacks and those types of more exotic or more, um, let's say press worthy type things, whereas most organizations today are leaving their front door wide open with having very insecure authentication policies, not implementing F-F-M-F-A, not implementing password lists, um, and not doing adequate training. Uh, and apparently, again, like some other recent attacks, this attack was targeted at the, uh, organization's, uh, customer support arm, not the main body of the organization. And it appears that, uh, many companies are giving their customer support portals and their customers employed employees, which may often be third party contractors.
They're not giving them the same level of security attention or training. So, you know, that's, that's a big issue, right? Yeah, that's a scary, it's a kind of, when you use OAuth often, right?
We're not talking about a token theft is the worst case scenario. It really is, because I don't even know how you would implement, you know, multifactor in, uh, a workflow. Now we're talking about SalesLoft and Drift and, and, uh, and Salesforce, but this is all stuff that's automated on the back end, so that's why it's harder to to, to secure it.
But this impacts a lot of different structures. I mean, I go back to my DevOps, we, OAuth is used across DevOps pipelines. It's used in platform engineering, it's used in medical records, transferring data across, uh, you know, from from one doctor to the next.
It's, it's out there, it's used a lot, and there's no worse kind of threat than an oof token theft. And that's what it is. It stole the token.
So once it stills the token, it's good to go. It's, it's, it's a bad, bad problem. Um, and I have no idea how we're gonna look at it and fix it across so many different industries and address these things in a timely manner.
Well, and, and one of the issues, lemme just pipe in real quickly, Mike. One of the issues is that we're not treating OAuth tokens as secrets the way we do other secrets. Any secret that you have should be stored in a hardware security module in HSM, which is essentially a write once read never device that you cannot extract the OAuth token from again.
And if we do that, that goes a long way towards securing our LT environment. It's not, uh, it's not a silver bullet cure, it's not the only thing we need to do, but that would really help a lot. Mitch, is this one of those teachable moments that we always look for?
Or are we just gonna ignore all this? I mean, you know, we'll, in, in a couple of months we'll be able to say to people, Hey, don't pull a sales loft. Then they'll know what we mean.
You mean, uh, shame on me once, shame on knew twice, or whatever the phrase is. Right? Of course, This will happen again.
I think only me Once. Yeah, yeah. I don't remember the phrase.
Thanks. You, you know, it points to how vulnerable you are to, to trace's issue if you can get in and Jack too, if you can get in at the authentication step somewhere in the identity and authentication part of this. It's, it's a akin to getting the, you know, root password to a, to a server in some ways.
I mean, you've got that user's, uh, authentication or their, uh, access controls into whatever systems that they're using. And it's very common to use OAuth and, and other forms of this. Matter of fact, OAuth is very, very popular today.
I think. I think it's part of, it has to be viewed more as part of the security stack, not just part of the software stack. And, you know, I think when you turn folks loose, like Jack as a security engineer saying, you know, are we properly secured?
Are we stor storing our tokens appropriately? Do we have the controls in place around this as opposed to, great, here's an API call this API, you'll get this back. Let's move on.
We're all good. Reminds me of when I was in the, um, certificate business, a business for, um, let's call 'em entertainment devices, things that are, are in your home. And people would email me back and say, I got this public, I got this private key, and what am I supposed to do with it?
I said, well throw that one away. 'cause I have to give you a different one since you sent it to me. You know, don't, yeah.
There's hygiene with this that you have to practice. Is it a teachable moment, meaning we won't happen, happen a year, happen again. Uh, it'll happen again.
And, and be, and this gets noticed because it is such a broad access and can really bring down a lot of data. Lot Of, and I don't think this was a, This wasn't a user, this was an application authentication, right? Mm-hmm.
App to app. Well, It's right, it's unclear. It may have been a, it was originally, that's why I think is it was originally a user phishing attack that got them access to the Drift environment where they were able to then get tokens.
Okay? Right. So that's why I mentioned MFA is I believe that the, and, and it's not clear because everybody's focusing on the blast radius that this impacted Salesforce and people were able to extract Salesforce stuff, but the, or the original attack apparently was compromised users.
But I feel like Tracys question is Theus Radius. Let's, let's, let's, let's, I got Tracy's question is perspective is, is the critical one though, because, uh, there's so much focus on, on, on user access and, and, and sort of the perimeter, perimeter defense, all that sort of thing. And, and I kind of wonder where Zero trust figures into all of this, because reading, uh, about this incident, and this story wasn't directly about zero trust, but, um, it, it, it made me feel like zero trust is, we've always felt it's a bit of a misnomer, right?
But more so here than, than than ever. I think it's, I'm a fan of Zero Trust from what I know. It's a great concept.
Um, but I think you have to keep in the back of your mind that, um, it, it, it's, it's a, it's an aspiration, not, not a reality. And, and the, and the way that I think of Tracy's question, you know, as being relevant here is there's a lot of app access. There's a whole supply chain of services and tools and lifecycle management and all that other sort of stuff.
And if you're really doing zero trust, you're assuming that any point along the way is not tru not can't be trusted. Um, but I, I think there's so much focus on things like user access and millennial and or AI access, but not thinking in terms of those app connections. Not as often, Mitch.
I think that this is just one example of maybe hundreds of things that will happen, because it seems like the bad guys are viewing SaaS applications now as massive honeypots, and they're looking for ways to get in there. And they're not looking to break in. They're just looking to log in.
And that's very difficult to fight against, even with zero trust, because, uh, somebody may have those credentials they've stolen, and as far as I know, they're a legitimate end user, and I don't know how we combat this. It's kind of path of least resistance, right? That's what and, and attacker is gonna take.
And if going after your tokens for OAuth for an application or an end user, if it's susceptible, great, they're gonna grab that and run with it. Especially if they see a major application like a Salesforce C-R-M-E-R-P system, whatever it might be, that they're gonna really gonna have goods in it, that they can leverage that data and sell that data. Um, I, I think, I think are we gonna see more of this?
Yes. Because we see more and more machine and machine identity and, and access, yeah. Both a applications, Yeah.
We got CP to deal with now too. Pardon? Yes.
And, you know, um, we have MCP to deal with now too. That's, that just, that just exponentially grows the issue. That'll be fine.
That won't be a problem. No, I, Oh, okay. Alright.
Now I thought better, Tracy, just Wanna, I wanna point out how many, um, websites out there use SalesLoft and Drift and Salesforce there, and we used to, we had Salesforce connected in the backend. We had SalesLoft, uh, passing data. We used Drift for our bots, and I started watching what was coming into our Salesforce account and a lot of garbage.
And me being a little bit paranoid in a small company, I said, you know what? It's not, the bots are not worth the risk. This was years ago.
I'm not saying I, I had a vision that this would happen, but I, I could see the kind of phishing attacks that I was getting in my Salesforce based on, you know, who was trying to download stuff, and I could tell that they were out there, uh, trying to, to play with the bots. So I, this is not a new thing. I don't believe it's a new thing.
So maybe the, the answer to this is be careful what you decide to throw out to the general public, because in those ca all of those ins in those cases, you didn't have to log onto the Deploy hub website. You just had to interact with the Deploy hub website for the bots to come up. And it was the bots that were, uh, and I, I believe in this case, it was the bots that, uh, the tokens were stolen from.
So nobody logged in. They're just out there talking to our website and looking for forms to fill out, to try to see if they can break in. And sometimes you gotta look at the data, right?
So the difference, Tracy, when you're a small company versus a bigger company, is that in a bigger company, there's gonna be somebody whose whole job, or half of their job is implementing tools like Drift, and they're gonna be reporting on the success of Drift using metrics that'll say things like this many interactions, this many this, this many that. And so there's this kinda layer where the expert is not necessarily, is not self-evaluating in particular, I'm gonna keep my job and get promoted because I showed that our drift usage grew like this and our efficiency went like this and all this stuff in some report, and then someone else looking at, it's just like, wow, that's great, right? That's why lead generation or demand generation organizations in big companies can throw through lots of chunk at sales and never get really, like, dinged for it.
So, you know, there's this, there's this, uh, uh, issue in larger companies where this sort of vulnerability seems to need to be greater. Mm-hmm. It would seem to me at least that as we get more bots going, we need to be wary of what they're doing.
Because every time you open up those things, to Tracy's point, you're creating an avenue for phishing attacks. Is that not the case, Mitch? Well, the, yeah, the more vectors, the more open it is to attack, no doubt.
And, and if these things aren't closed down, you know, that's the more, the more it happens, I think there's more opportunity for people to learn from it, like you were asking about earlier, and people will start to be, take it more seriously. You, you would think. But then again, there's always, you know, guy brought up the great question.
What about the mid-tier? What about the small company who don't have the security resources, but are still trying to use, use MP MCP servers or, or accessing SaaS applications? Um, so security has gotta get easier for folks to lock these environments down, which creates opportunities for security companies.
All right? Sadly, we're gonna be talking about this issue more. There's gonna be more of these incidents going forward, and, um, I got a bad feeling that the only way we're gonna learn about this is the hard way.
But hey, everybody, at least you heard something about it here. First 'cause to be forewarned is to be forearmed. We'll be back in a minute.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're moving on to our next topic, which is Atlassian bought a company called The Browser Company for I think 610 million. And the idea here, I guess is that they want access to what will be AI browser technology that they will embed inside their applications and their workflows.
And Guy, when I saw this, it reminded me of an old debate that's been going on for a long time about, you know, why are we using all these consumer grade browsers inside our enterprise apps? And, uh, but we never seem to move off them and we keep using them no matter what. And we've had enterprise class browsers forever, and adoption rates are minimal.
Um, is this gonna be, you know, the beginning of something different here, or is this just, you know, uh, somebody making a hope for 610 million? Oh, an easy question. It's somebody making hope for 610 million.
Shall we move to the next block? Well, We lead the witness there, Mike, come on. So look, um, first of all, um, arc, um, I haven't used dia, which is the browser company's other, uh, browser.
I'll get to that. Arc is a really cool browser. Um, a real focus on the user experience and on a front end, obviously to SaaS like Atlassian produces, Atlassian produces software, SaaS, um, for the developer community.
Um, uh, you know, its many parts and forms. Um, and, uh, our friend and leader of this pod, um, uh, Alan Shimmel wrote a great column, uh, about the acquisition, where he made the basic point that if you are on essentially a web application SaaS company, um, which is every, every software company is now, um, why wouldn't you want to own the final mile? Uh, you would.
Um, but your point is a really good one, Mike. Um, so let me ask you a question. Why is everybody still using whatever it's Chrome.
Why is everybody still using Chrome? Let's, let's just stick to that. Why?
Well, because the machine that I got came with, you know, two choices, and so I picked one, Right? Right. And you picked the one that's the cool one, or that the one everybody knows, or the one you're familiar with or whatever it is.
I think that the, um, the, the, as long as, um, Atlassian, let's just take Atlass as long as it Atlassian suite is gonna be available in any browser, which presumably it will be, um, otherwise we're going back to the days of Citrix where, you know, Atlassian, you have to, you know, install the, uh, their particular client reuse it. I don't think they're gonna do that. Um, are they gonna do something where the experience is so much better If you use Arc D.
Now, DIA is a radically simplified interface that still allows you to browse, but with, uh, the use of ai, so it's like an AI chat where you get to browse instead of having to poke around or click here, click that do a search, and all that other sort of stuff. The AI acts like sort of an agent for you to help you do it. This is all great, this is innovation in the user experience.
It's fantastic love. A sure is, you know, uh, built along similar lines. Um, but 610 million for this one, one can't help but think that the whole idea is, like Alan said, to own the entire software experience and to end.
I just don't see how they're gonna impose that control on the client's side just because it's an enterprise. Just because everybody says to all these developers who all have their own opinions, obviously, um, go use this every time you want to use Jira. You know, you go open this other piece of software instead of just doing it integrated in, in Chrome like you've always done.
That's where I think, um, uh, the, the questions still lie Now, Atlassian very smart company, and I am, uh, famous, at least in my own mind for not understanding things that become clear to OB and obvious to everybody later. But that's my initial take, which is, it's, it's, it's an effort to improve the user experience, the developer experience, which is Atlassian's core, um, value proposition to the market. But I think there's a lot of friction that they're up against here, and I'm not sure how they'd solve that.
Mm-hmm. This kind of reminds me of a ca purchase back in the day. Ca I used to, we used to say they're not superior by design.
They were superior by acquisition. Um, and Atlassian's got a big enterprise customer base, probably, I don't know, 250,000 plus something like that. That's kind of how ca built tools that none of the rest of us would ever use.
But they sold into the, specifically to the enterprise customer, The mainframe customer specifically. Yeah. Go on Mainframe customers.
But they spread out quite, quite well into networking into DevOps for quite some time by acquiring companies, right? And it feels like to me that they're looking at selling this into the enterprise accounts, and I bet it has some security on the back end of it that they're interested in that they'll probably do quite well selling this into those enterprise accounts. And when you get a, when you have a giant list of customers like that, that are enterprise, you don't look at, you don't really worry about selling to the masses.
You worry about selling to those enterprise customers and giving them new, new stuff to buy. 'cause you got a book and you wanna sell everything in the book. I was actually just talking with Atlassian this morning about this and some other things.
First of all, uh, Atlassian is one of those companies that has a very, very solid ethos. You know, we talk about culture, and then there's ethos, right? You, it is a certain way.
They have a definite model of how they do business, and they're not a rollup company. You know, let's go buy a bunch of companies and roll it up and, you know, try to make them work together. They're very intentional about doing this.
And their CEO Mike is, is, is pretty brilliant business person. Now, it tends to put Atlassian on its own path compared to other companies. But I think there's, there's a way to look at this as both a offenses offense and a defensive move.
I don't think it's to become the next chrome. Maybe that's what could happen. Now, like you were saying, Mike, that's, that's a big nut to crack, right?
You're gonna go after that. Good luck. On the other hand, if you look at what's happening in the, in the AI browser space, there's many people that think that the current web browser, you know, Google's working on how do I transform from doing Google searches to doing Gemini searches?
Well, there's much more layers past that or steps past that. When you think about AI and agents and workflows, because browsers are very passive things. They, they render information to you, you do some interaction with it through JavaScript, things that are running in the browser, uh, and, and other ways, but it's pretty much a passive experience.
If you're working in an environment where, um, you're orchestrating, you're, you're having work orchestrated for you. Agents are running and doing things. You're having information put into LLMs and brought back and something else done with it.
If you think about these interactive workflows, which is what rode the Rvo platform, the Atlassian platform is about, is taking out an AI plugged into something, but an AI platform plugged into all of the suite of applications that they have, and they've already done some nice work on this, it takes it to the next level. So I think it's, it's one is they're not leaving their fate to the browser wars for other people to figure this out and either to win or lose based on somebody else's decisions. I think, I think they're taking the bull by the horns.
And at a minimum, if that turns into radical chaos, they've got a structured good program going forward. If you know something else or, or Google or something else, turns out, turns out to be the next best thing. Okay, great.
Maybe they, you know, continue down the browser, company d that path until that. But I think, I think it's a very strategic move. It's, it's a, um, sort of a wild card move, right?
You don't think about that right off the bat. Why would Atlassian wanna be a browser company? I don't think they think they wanna be a browser company.
I think they want to be an enterprise apps company in an AI era, Tracy And productivity tool. Yeah. Mm-hmm.
Tracy, what, walk that through a little bit with me because I think Mitch may be onto something, but let's take it to the end degree, right? What is the future UI gonna be for these applications? Is it gonna be something that is optimized specifically for AI agents rather than humans?
And we just need a different interface to talk to the AI agents, which will probably be natural language or even voice soon. So is the whole end user experience about the change? I think that what we're looking at in this particular scenario is a marriage between a browser and an IDE, right?
It's, I believe it will become the next IDE for productivity in developing in an ai, uh, under an AI platform. It may and Tracy, when you think about it from that per per perspective, it totally makes sense for it last in to go down this road. Who owns the IDE today?
Uh, Microsoft. Well, the biggest one is V code code vs code from Microsoft, right? Yeah.
That's the thing is who owns the ID today? I mean, it's open source BS code is the most widely used, but Yeah. And so is the Cliff, and then there's this whole i DP movement as well, so, right.
But it's, but so, so I think, and Mitch and Tracy, um, uh, I, I, I agree with Mike, you're onto something here that didn't occur to me, which is, I, first of all, you know, I, I don't think anyone thought that, uh, you know, Atlassian's now gonna try and become the dominant browser, whatever, whatever it is, no matter how disruptive and innovative, um, ARC and DIA might be. But it's really helpful actually for them as a developer focused SaaS company to own and have a product development lifecycle and investment in a browser because of the way standards and norms are set in SaaS across everything, this gives them a foothold in that, that they didn't have before. They're more like, like knocking on the glass and looking and say, oh, can you please do this?
Can you please add this feature? Can we please add this security capability? Whatever it is here, they actually are gonna have a seat at the table because of the personnel and the history behind the browser company, as well as when you produce a freaking cool product, people wanna listen to you more.
I mean, Chrome and Chromium, I think made its name with, uh, true, truly, um, uh, breakthrough JavaScript, uh, hosting and, and, and, and capabilities. Um, and so this could be breakthrough AI capabilities, I don't know, or, or user interface or whatever. That actually makes a lot of sense to me that this is Atlassian's way of helping to have ownership in the development of SaaS broadly across the board.
Also, think about it also, I love your analogy, Tracy, of the IDE and meets browser, and, and I take your mention of ID is not literally, you know, BS code or something, but it's, it's taking the, the model we have of, of how we work today with AI is vastly broken because it's, we have the mode of, I'm gonna use a, a chat interface, right? Um, and we have some CLI tools for developers and things like that, but it's, it's natural language. Either spending all our time in that or taking existing applications and hanging sidecar an app, an AI functionality to be able to query your email or go look something up or whatever.
It's not integrated into the application that Log Jam's gotta break for AI to really become, um, essentially what, what we really can get the most out of ai. It's gotta be part of the applications, not, it's not an application. And so what's that user experience like?
And your, your analogy of it's sort of the chocolate and the peanut butter. We get a Reese's Peanut butter cup. I think that's what they're hoping for, is the next Reese's peanut butter cup of user experience, um, in an AI workflow driven process world.
Uh, and that's, that's A focus on their tooling with a focus on their tooling. Mm-hmm. Make sure there's another, there's another aspect to this, Jack, there's another aspect to this as well, which is that this is not unusual for, you know, it's not an absurd dollar value for a browser, not at all, right?
We've seen this with Signal, sorry, with, uh, island and some of the others. And you know, when we've talked about this in the past, I said, I don't understand why Microsoft and, uh, Google haven't looked at this and said, that's a business we can own, right? Because they can make enterprise browsers and Secur add security to browsers pretty easily.
And I think the answer is proving out to be that they're either not interested in that business or unable to in, to execute on that business. And there's a lot of other companies that are executing in this environment and are saying that the browser doesn't have to be just a passive part of the user experience. Uh, and Mitch, I think you said it renders, you know, traditionally it just renders information and I think there's, uh, people are looking at it and saying, there's an opportunity here for the browser to become more than just a passive part of the landscape.
And I think that's, that's really interesting and exciting. Yeah, but I gotta, I gotta say again. Um, so just to blend the two concepts, I agree with you, Jack, if these capabilities wind up commonly used across a lot of browsers, or in particular the Chrome browser itself, because the idea of Atlassian, um, or anyone going and saying, you're gonna get the best experience from our suite if you use this browser, that we're gonna give you a deal on it, it's gonna be this and this.
We're gonna enable you and all this other sort stuff. I just need the, at the end of the day, the user's gotta go use it. And if you're gonna restrict the user, that will cause backlash in those enterprise accounts Tracy was talking about.
So you don't wanna restrict them. You wanna give them freedom of choice and user agent. It's just, there's a lot all right of difficulty in trying to do that.
So, Tracy, last question on this one, but, and feel free to call me crazy, but isn't this like a memo to the open source community? This is kind of what we need is the next generation open source AI browser that all ISVs can use as opposed to getting locked into one from, I don't know, Microsoft, Google, or Atlassian or wherever it may be. Uh, it'll end up there, it'll end up open source.
If they wanted to take it to the masses, they they would, it would end up there. I don't think that's the, that's not the play here. Uh, I, I really do.
You know, there's something about having sticky products and a company like Atlassian's gonna want sticky products and being able to build this, this browser, this AI browser that enterprises can use as a productivity tool. And as I'm seeing it, uh, kind of morphing into an IDE, uh, is different from what the open source communities usually, uh, focus on and remember, even though we're all open source, we're not necessarily talking to each other and trying to build broader kind of enterprise facing tools. So yes and no.
Uh, I think Visual Studio, how long was it before it became open source? You know, it was part of your subscription for a very long time. Uh, certainly Eclipse has been out there for, for quite some time, but IBM drove that trying to hold on to developers, and it did that job for them.
So, no, I don't think that it's, we're gonna see this as an open source tool, not for a while. Not until, um, enterprises love it so much that they start saying that they want an open source version. All right, folks, we'll see where this all goes, but I'm willing to bet by end of this year, we, we will see an open source project started, at least in this vein.
It may not deliver it for another year or so, but we'll see what happens. We'll be back in a minute. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers Network. Hey, folks back and we're talking about, well, another acquisition.
1 billion. Now I'm a simple mind, Mitch, but I'm gonna start with you on this one. 1 billion still seems like a lot of money for a company that, as far as I can tell, is a feature management platform for experimentation.
I mean, uh, why, you know, we argue a lot about buy versus build, but this is going to take bye to a whole other direction. I mean, did they need this? What's your thought here?
Well, I think it's an example of try before you buy, because OpenAI has been a customer stat sig, or sig stat, excuse me, my dyslexia kicking in there. Um, in, in that it's more than an ab ab capability. Um, they specialize in AI and AI models and collecting data around deploying features around different models and different capabilities in the application.
So what, what I, the way I read this is it's been beneficial for OpenAI to use that in their product development. They see this as a big boon to expanding the, uh, OpenAI co codex and their capabilities, uh, you know, things that they acquired from, you know, windsurf, the licensing deal that they have to start to build in that capability in the software that they're, they're generating through the models. So think about it that way, as, as not as a, um, I'm gonna add this and put as a feature, add this as a, I'm gonna put this into my models and my code building process that now I can also provide that directly in the code that I'm generating, and I don't have to think about, it's another product I gotta integrate.
This will be our product and, and built into how it kind of automatically works. So if you wanna turn on this kind of testing or collect this kind of user data, or go do a feature out here in this part of the, the world, great. It's really easy to do.
It's already built into the code. It's been factored, it's already instrumented. Boom, you're ready to go.
Mm-hmm. Tracy, how much of this was, uh, acquihire was hiring the people, buying the people Rather than That's, That's what I was gonna say. Yeah.
Sorry, Tracy didn't mean to step On you. I that's a really big sign on bonus. Yeah, that's It's sign on.
Because, because the, because the, the president of stats or the, the CEO, whatever it is now, the CTO of OpenAI And it was a stock Swap and, and what's Yeah, and what's, and what's, yeah. And what's really interesting, what, not only is it like hiring in new leadership or buying new leadership, but the current leadership is kind of being, you know, like you notice that there's, there's a, there's a major organizational shift that just happened at OpenAI, um, But isn't, I've seen, I think that's, that's somewhat normal as you transition from being research led to being product led, right? The company was originally structured as a AI research organization with a whole bunch of AI researchers that were, may not have had the right skill sets to build commercial sellable product.
So, so I think that OpenAI doesn't know who they are. I think this is another step towards the yawning grave for OpenAI. And I just like saying this because no, everybody thinks OpenAI is gonna be around forever, just like they thought Yahoo was gonna be around forever, it's original form.
Um, because your point is exactly right, Jay, this is like them saying, actually, we're not an AI company, we're a chat company. I think chat GPT has taken over OpenAI, you know, the, the, the, the, the brain cells of OpenAI, kinda like, you know, yeah, go ahead. Let me explore what Mitch was talking about for a minute, because when OpenAI talked about it, they said using this to accelerate the building of their own products.
However, OpenAI is also an app dev company. Essentially, they have built a framework and won't they stick this feature management platform in some sort of framework that they're establishing or showing other developers, third party developers to help them build apps. And maybe we will have a more integrated approach to building AI apps versus today in the land of DevOps.
You know, we got like, what, 22 different tools that we slapped together. Mitch, is there, is there something different gonna happen here? I think it's akin to back, I, I agree it's part acquihire just like the Johnny Ives kind of agreement with, with OpenAI.
But going back to our prior conversation, this is about shaping the next experience of what it's like to use, if we wanna call 'em apps in an AI world, because this acquisition goes into part of, uh, OpenAI as AI's rebuilding of their product organization. So they're, they're may, maybe they don't know who they are, guy, to your point, maybe this is the sly fox saying, here's who we want to become and we need this to stay ahead of anthropic and the others. So we just don't look like a patchwork of whatever kind of capabilities of as we acquire companies.
Um, I tend to think there's a, a strategic intent behind this in addition to acquiring talent, which is a very valid point. Um, but I think we're in a race for not the next model, but we're in the race for defining the user experience and owning what that's like and becoming the iPhone of AI experiences. Alright, cool.
Tracy, what do you think? Is there a new way of thinking about app dev? I think we're gonna see OpenAI have a new browser.
I would not be a bit surprised. I would not be a bit surprised. I mean, um, Because when I read that, when, when I saw the, the, the, uh, the topic come up for our B block, I was like, you know, OpenAI should have a better browser 'cause it kind of sucks for chat.
So I could have a much more productive, uh, productive browser for this. It's a good point. So, You know, it, it, I I do believe that this was a, a more of an acquisition of personnel than it was of technology.
That doesn't mean that there, uh, oh, I just, you just lost me for a minute. But anyway, I hope you can still hear me. That doesn't mean that the technology was bad, it just means that Didn't wanna ask Jack one final point on this.
Isn't it wonderful that we're gonna have all these additional types of browsers that we need to secure and the attack surface is gonna be so much broader. Aren't security people really thrilled about all this? Uh, I think you've nailed the bucket on the head, which is really that we're, it's expanding the attack surface.
It's another tool then that we have to think about and worry about how to secure. The flip side is theoretically the browsers will, or at least should include additional security features, right? These are targeted much more at enter, well at least the other enterprise browsers and probably, um, whatever comes up out of, uh, OpenAI as well will be targeted enterprises much more than targeted at mass adoption.
Uh, OpenAI maybe not 'cause they really are a consumer based uh, solution, but a lot of the other efforts like the Atlassian effort and the other browsers are really targeted at enterprise users. Where to guys point, it is really forced adoption and forced security around that. So I think that helps a little bit for mass adoption.
Then more browsers we have the scarier becomes from a security point of view. All right, well folks, you're heard it here. Once again, it giveth with one hand and take it with the other.
Thanks everybody for being on the show and sharing their thoughts and insights. We wanna encourage all of you to stay tuned for the rest of the tech strong TV lineup behind us, which is equally awesome. Until then, we'll see you guys tomorrow.