Shai-Hulud Worm Threat, Social Media Transparency, and AWS re:Invent | TSG Ep. 976
Transcript
Spice flows again on the desert planet. Arra, shy Haud. You're watching Text and Gang, Man, anytime I could start my day with a little dune reference, I'm a happy camper.
Um, who knew that it would take some kind of, you know, bad malware for me to talk Dune on Textron gang. But hey, whatever. I'm, I'm happy with it.
I'm happy to go with Dune. Um, welcome everyone to our Monday version of Textron Gang. And, uh, I hope you had a, for those of you who celebrated the long Thanksgiving holiday, I hope you had a great time, a great time with family and friends and loved ones, and enjoyed your day off or your days off.
And you're here refreshed, ready, eager to get back to work and talk about things that are important to us in the tech world. Uh, we've got a great gang lineup to, to talk about stuff today. Let me introduce you to them.
We have, uh, Teri Robinson, resident cyber person, our Silicon Valley, Jon Swartz up in Canada. She celebrated Thanksgiving earlier. Karima Bal Karima, good to see you.
And of course, well, we we're calling him the dean, but yesterday, I think, or at our last show, pre-Thanksgiving, we decided he's now a Bard. The Bard, Mike Vizard, um, welcome gang. How are you today?
I hope you all had a great weekend and long holiday. So, Mike Ude is back. The spice is flowing again on ar Iraqis.
Yeah. The Guild is happy Security people and Linux administrators, not so much what's going on. Yeah, things are a little crazy out there.
Most of a lot of security folks spent the holiday cleaning up after this mess because, well, ude is back. It is a self propagating worm this time. It seems to have also included some malware that basically exposed everybody's tokens.
So now anybody could just basically log into anybody's repository. This mainly affects MPM packages and, uh, repositories holding a lot of JavaScript code, but it's a bit of a mess. And Alan, I'm gonna put this to you.
I mean, this is not the first time that we've gotten this kinda wake up call about software supply chain security. But my question is, we're just gonna roll over and hit the snooze button one more time. You know, this ain't my first worm, as they say on dude.
Um, seriously, I, I don't wanna minimize this, right? We've got a serious problem in NPMs, and it's the same kind of problem we see, of course, the repo world in general, which is people because they download it from a repo or from a, a package manager, assume all is well, and they, and off they run with their software. And no one is policing these packages.
No one is policing the uploads to the reposts. So, you know, buyer beware, user beware is the, is the day, but is this worm, I mean, we've seen a lot of worms come over the years, right? The worms crawl in, the worms crawl out.
This particular UDE two, or the sequel, or whatever you want to call it, seems to be a better version than the original in that it's faster, it propagates better, and it can therefore be more dangerous. Um, and we've seen this happen too, right? You, you get iterations and reiterations of, of these, of these malware variants like viruses, you know, that's what their name, we call 'em viruses, right?
Because they're like viruses in the real world that are constantly evolving and evading, right? It's a cat and mouse game. And now we see the next variant of Shy Haute.
Is this gonna be the last one? Probably not. I, the bigger issue though is what do we do?
We all, you know, 80%, 75% of the software in our apps is downloaded from JavaScript repositories or Artifactory, you know, artifact repositories or, you know, Maven Java or, or there's so many different repos where we get our software docker containers. Um, there are, you know, what do we do? There are a lot of companies that are now starting to put out safe packages, safe distros safe containers that they certify, you know, for these common, and, and you know, you can't have one for everything.
'cause there's millions of different variants. But for these very popular ones, we have a, you know, a clean version that we guarantee is clean. And if you use our stuff and use that, you're okay.
SUSE does it for one, right? Uh, there are others. Maybe that is where we're headed that because, and I've said this before, I lay this at the blame of the, of the repo managers of the maintainers, I think they have a duty to make sure what goes into their repos, into their collections is safe.
So that's where I am. Did they, did, you know, you talked about, did we roll over and hit the snooze button, whatever rollover? Um, is that what happened between September and now?
Um, or did this just come so quickly? No, no. This is a new variant.
Okay. This is definitely a new variant. You, it's, look, this is a virus and vaccine, right?
You, you change the, the DNA coding or the cellular coding or what have you, and it evades what you had before. Mm. So though you may have thought you were protected against shy ude one, this, this is definitely a, a, a, a better version of it.
That's more insidious Mima are developers just frankly spending too much time engaging in what you might refer to as unprotected downloading, I dunno, Right? I mean, uh, to build some more context, and I'll come to that question, uh, Mike, uh, in a while. So what this, uh, virus is all about, this is a major cyber attack, which is also very fast moving and dangerous as, uh, the article refers to, because it hits the supply chain.
And what it does is it does data harvesting, it steals developer credentials. For example, if you have open credentials in your, like, you know, ecosystem, API keys cloud tokens, and it exfiltrate them to a public repository, right? So when this infected packages are installed, the warms harvest developer credentials or API keys or cloud tokens, and then, you know, uh, you can kind of, uh, be susceptible to any number of, uh, you know, attacks like secrets from your local environment, CI/CD pipeline.
Your credentials are kind of, you know, at a risk and stolen data, for example. So it becomes a Dropbox for stolen, stolen data, for example, right? Mm-hmm.
So now what we can do as practitioners and developers, I mean, uh, the first and foremost thing, I mean, uh, Ellen, you mentioned about this. Many organizations have been, uh, working tightly, uh, with this open source ecosystem. Our good old friend, Tracy Reagan, for example, is heavily invested in open SSF.
And, uh, we have from CD Foundation, there is, uh, sig, which looks at these kind of, you know, practical cyber attacks on ci cd pipelines. There, there are assessments and order mechanisms available. Now, what we should be doing as an organization, of course, you know, there are, uh, from enterprise perspective, we always have wrappers, for example, right?
Security, uh, guidelines to kind of ensure and secure our environment. But more or less, I think it also, uh, is a strategic imperative for defenders. You know, how do we build robust supply chain audits, for example?
And this is not something which is like off the table. I mean, you have to do it because, you know, these attacks are getting even more smarter, like dependencies to detect an anomalies. For example, unexpected pre-installed scripts, which in this case you will see that, right?
Suspicious package updates. So these are things which you should actually monitor your system for credential hygienes least privilege. Uh, of course, if you expose your credentials, uh, it's like combined risk of, you know, having, uh, these attackers to kind of, uh, also decipher it.
Also, I think, uh, from a hygiene perspective, it limits the possibility of what your application could do. Proactive threat hunting and anomaly detection. I mean, we have been talking about kiosk engineering and all those kind of things.
It's time we take it seriously, right? So if this kind of attack happens, what is, uh, uh, the, uh, poster, we have to hunt them back and to try to kind of be, uh, from a real time perspective, uh, more proactive in, um, detecting as well as, uh, protecting our environment, collaboration with open source communities. I mean, uh, it is leadless to say, if you're not aware of what open SF uh, foundation is doing, CD Foundation is doing, um, talk to, uh, some of our, like, community leaders like Tracy Reagan.
And there are many more in the ecosystem who can actually guide and help you in this direction. And, uh, more or less, I mean, it's matter of education and awareness. I mean, uh, again, these attacks are not new.
It's just faster and more dangerous, as Ellen you mentioned, right? So how do we educate our ecosystem? How do you invest in more like AI native defending technology applications, which can defend your kind of, you know, um, applications, uh, from these attacks?
And I mean, from long term attack patterns perspective, it's evident that this supply chain risk persists. You know? So we have to think about how we manage these, uh, malwares.
We, how do we manage these risk attacks and, uh, how do we ensure that automated self replication doesn't happen, right? Credentials, thefts, and, you know, reuse of these kind of attacking mechanism do not happen over and over again. To your point, Terry, you know, what we were doing from September to now?
I mean, it's a different form of form, but then again, uh, is our poster improving? Do we have taken enough action on this? Right?
And again, it's needless to say that, you know, one of the most important things, which will change our developer's profile is how security savvy we are. This is what like, you know, how your, uh, developer ecosystem would change is So garima. I, I've gotta disagree.
Yeah. As someone who is in instrumental in starting the whole DevSecOps movement as being real, one of the lessons I've learned 10 years doing this is don't throw this on the developer's shoulders. It's not the developer's job to be the security professional.
It's the security professional's job to be the security professional. When the developer goes to a repo, whether it's an NPM or Artifactory or Maven or wherever they're downloading their software from GitHub, there's got, there's gotta be a level of trust or docker containers. There's gotta be a level of trust that what I am getting from here, at least today, it may wind up down the road, I find out there was a bug in it or something.
But at least today, it's free from this kind of worm. It's free from this kind of self-replicating Trojan. And to say, you know, buyer beware, it's on the developer.
When the developer's downloading literally dozens of these from different places, you know, packages and components and scripts. I don't think that ever works. It, it hasn't worked.
And we've come down this road in DevSecOps, don't, the developer has enough on their shoulders. We, you know, we came up with the whole system of SBOs. That's something we haven't mentioned here, right?
SBOs was supposed to help secure the supply chain. No. And SBOs a great tool for forensics, right?
What did this have in it? Where did this bad? How did this bad piece get put into my package?
Into my pipeline? But it doesn't really address this issue. And I, I, and I've been preaching about this for years, we need repo firewalls.
When before you can download something from a repo, it has to, you know, JFR has it for Artifactory, Justin, it's called X-ray. But we need one that's generic that goes across repos and, and either puts scripts and, and, and so forth in a sandbox and make sure that they're free of malware or something. So that a developer has a high degree of, of, of, uh, certainty that the, this software is, is good to use, otherwise you're just making the developer's job impossible.
Well, yeah, I hear you. I think, uh, um, I agree with certain aspects of what you're saying, but it's also not this or that, right? I mean, you, uh, have actually put forward a very good point on, you know, what kind of security, uh, loopholes we have today, which we can restrict or have strict control on, which probably, uh, be the job or responsibility of the security professionals.
But let's assume that this attack happens. The defenders are, you know, if they are not supported by the developer ecosystem, they would be be failing at that point in time. So this is a cross-functional collaboration like vulnerability disclosure, or transparency of dependency of, uh, you know, on, on dependencies or, you know, health of the, uh, code itself.
The, the, the whole, you know, rapid patching mechanism. We need some kind of, you know, ecosystems to support that. And the developers need that support.
But I think it's also needless to say that developers also need to move and shift in the direction to understand what kind of modern attack patterns are happening, what kind of hygiene in, you know, coding needs to be kind of put in practice. What, what collaboration your security professionals would need. If you don't see the guardrails in the CI/CD pipeline, would you be the whistleblower and try to kind of ensure that this collaboration gets developed?
So I think there is some kind of potential in, you know, securing that collaboration. Of course, we have been talking about this since like two decades now, Elaine, you know, about DevOps and DevSecOps and mm-hmm. Those kind of, uh, definitions and, you know, how do you put this into practice?
But I think the sweet spot lies into the synergy rather than building, like, uh, hard boundaries. I think it's, you know, and shared responsibility kind of, you know, on, on, on both sides. Yeah.
Alan, it's not fair to just put everything on the developer's shoulders. They're not security people, but they have to be somewhat savvy in security, you know, for all of this to work. I, I, I think in, well, I mean, if You're a security person, the way you look at this as you go, Hey, I told you not to go and engage in that behavior, and you went and engaged in that behavior, and then you came back and I patched you up and I sent you back out there again, but now you're just gonna do the same thing over again.
And eventually, like a good doctor, they just shrug and go, I'm telling you not to do this, but you know, you gotta, at some point stop doing it. That's like one, right? And going out and committing the same sin over and over again.
Wait, What? So, so like in theory, you're talking about all these prescriptive measures in this history, but I mean, when I read both these stories, I come to the conclusion of pace. It's always about the pace, and the pace is it's getting worse.
Yeah. And it's probably gonna give, so you're talking about a thousand new repositories re uh, surfacing every 30 minutes, which is significantly more than the previous iteration. At the same time, you've got more code being developed, which is just gonna increase the number of repositories that need to be secured.
So it's just like this escalating math. And I, I know it's not easy to solve, but it's, that's just a terrifying takeaway for me at least. Yeah.
And of this code is written through ai, you know? Right? Yeah, exactly.
Yeah. 0, I'm pretty sure it's coming. That's coming.
That's where that's coming too. Look, yeah. Yeah.
So Shy Ude happens to be the one hitting NPMs and JavaScript. They'll, they'll, they'll be the Barron Hocon next on somewhere else, right? And the Paul Lares Modi over here.
There's, we've been, we've been naming these worms for as long as I've been in tech mm-hmm. From the Love virus. Remember the Love bug virus or whatever it was called to bug codex code red, you know, there, there's, there's always a next one.
No, We, Another sound novel. We need a sanitary a a a a checkpoint Charlie for these things. Oh dear.
So who, anyway, hey, we're over time on this though. We gotta take a break. We, I'm sure we'll be talking about it again, unfortunately.
But you are watching Text Junk Gang. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders.
Lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back in, well interesting times in the land of social media, but we may have some actual transparency into what's going on, or at least a little more political chaos.
But apparently the folks at X are letting you see where the account is that somebody is actually following. And turns out some of the political accounts are in places that are not in the United States. They're in Africa and all kinds of places.
'cause somebody's paying for that. But John, is this gonna become the new standard? Will everybody have this level of transparency, or is this a one-off kind of thing and it's just gonna go away?
You know, it may be a one-off base on what's happening with X. Uh, this is, I mean, we talked about Dune. How about Dr.
Strangelove? This is like some dark satire that, that, you know, I know the intent is the intent for security purposes. So there's this transparency tool that X introduced over the weekend that re reveals accounts that claim to be that claim to represent American political views.
And what they're finding is that, wait a second, through their geotracking, they're finding that they're coming from overseas. So I'll give you a couple of examples. There's, there's an account called Ultra MAGA Trump 2028, which claimed to be from Washington, DC Well, it's actually from Africa.
There's another account Where in Africa though, John, I, I don't know. Well, because, you know, I have a Nigerian prince who runs a lot of these things. Alright, well, good.
So there's another, exactly, there's another account that shows up that, that's, that's, that is coming from Macedonia where it was subsequently deleted. Then there's another one, uh, called just, uh, ampersand American, which is a bald eagle for flag. And that originated from South Asia.
So that's all well and good. So they're identifying these, there's a one little glitch out. So some reporters started looking into it, and the accuracy is not always on the spot.
So NBC for instance, they had several of their reporters display their locations where they had recently traveled, and that's where they were located rather than where their actually base where they do their job. Um, the controversy got even worse when there were some viral screenshots that claimed the Department of Homeland Security account was based in Tel Aviv. So that was, that was disabled the same night.
So DHS has issued this denial stating the account has only ever been run and operated from the us. So X is finding itself scrambling, trying to, trying to fix the accounts that it got wrong. So we don't know what the percentage is.
I think it's highly accurate, but there's just enough to leave doubt. And again, I, I mean this, you can't make this stuff up. When Mike sent this to me, I thought it was a satire.
And then I started reading some accounts in NBC and, and BBC and elsewhere. And it's, I, I know the intent, but the execution as it always is with x, is a little off base. It's so funny too, though, I have to say, if you've been sort of online and watching this, like, you know, on, on X and people, you know, chatting or whatever, now there are some commenters who are using this like, as a bludgeon, right?
Against MAGA or whatever. They're like saying, they're just dismissing whatever they said because they said, oh, well that was from Nigeria, that was from, uh, Russia. You know, or whatever.
So it's been a little hilarious to watch people try to respond. Well, you know, the one, one of the thing I should have mentioned was, um, that's right, Terry. One, one thing I wanna mention is that X this is like, to me, confounds me.
They, they, it's like an Elon Musk move. They eviscerate their technical support. They get rid of all their, their engineering talent.
Then they try something like this. For what reason? I'm not quite sure.
And it just blows up in their face. I mean, what did they expect was going to happen? This is not the first time this type of scenario has unfolded at X.
But again, I couldn't, then again, I shouldn't be surprised 'cause of social media, Well, didn't they like test this out before they sort of made it public or rolled It out? Ostensibly, You would think Go fast, baby Have two people. That's, that's the valley.
But, but guys, let, lemme lemme play play devil's advocate here. I think this is a great thing because anything that gives us a little transparency on the fake news of social media, and if we remember right, that's why Elon supposedly bought Twitter, the bots and the fake stuff. He was going to, you know, eliminate all of that.
Now, my friend Andy Ellis, who's a pretty well known ciso, he was, was CSO at Akamai for 20 years. He, he posted something on this, and it was around the, the supposedly, uh, pro Gaza news media and news and Pro Gaza X accounts that it turned out none of them are actually in Gaza, right? They're all reporting from Gaza, but from somewhere else.
And I'm not saying that makes it any, I'm not getting involved in the Israeli Gaza thing. I, you know, but it's that kind of transparency that I think we'd all applaud. Hey, all these people who are, are supposedly MAGA haters or MAGA supporters, it's good to see that they're coming from Venezuela or China or North Korea or South Korea or wherever.
Right? It, it, I think it does give us transparency that we all would like, my problem is what stops a Chinese deep state, uh, uh, campaign activity from flying into Nigeria or Venezuela or Brazil and carrying this on from there. So at least it doesn't point back to China, right?
It points to Brazil rather, or for that matter, what stops it, the now that this is the cat's outta the bagg, what stops them from using Chinese nationals who are here in the us Right? So while I, I think it's a great idea and I applaud it. I just don't know how effective it'll ever be.
Yeah. Yeah. The concept is good.
This is, the execution is flawed. I mean, but yeah, It's, I just want the other social media platforms to follow suit. I mean, some transparency is better than no transparency.
Yeah. So I wanna know if this raises the bar. Well, okay.
And I agree with all of that, except that there's also a whole facet of our society that doesn't care about the transparency. They're gonna believe whatever that stuff says, they don't care if Elon Musk and them find out it's from Nigeria or Moscow or wherever. Right?
They're, um, they're going to, they're gonna stick to the narrative. I guess that's a whole different problem in not, Well, there, there is that right? That's the Joe Bels, Joe Joe Goebbels social media view.
If you say it loud enough and often enough people believe you. Yeah. I guess, you know, when they forward that stuff to me, I just want to know where it came from in the first place so I can at least have something that feels like a rational conversation.
Yeah. I also feel this is a generational thing, right? I mean, uh, we would see more generational awareness about how to treat social media and what kind of social engineering happens in the background.
So for example, me being from a millennial club, we are a bit more aware. But I think, uh, moving on, I think the Gen Zs and the gen Alphas, I think they're very conscious about their choices. And I think these social engineering of, uh, you know, politicizing things, I, I think this will not be something which is something which we have seen so far.
Yeah. Agreed. Agreed.
I wouldn't be surprised to see, uh, meta try, you try to use this concept. No, I know. I think we'll see copy cats here.
Yeah. Yeah. They're all, we definitely see, and and here's the thing.
As we get other social media companies copycatting this, they'll continue to refine it. Mm-hmm. Right?
Uh, 'cause like I'd like to see is, okay, so this account that's in Nigeria, what's its history, right? Where, what, what's the connection here? And, and see if you can start tracing it back.
And, and maybe that's the first steps towards retaking, right? Taking back our society from, from the, the fake news. I would also wanna know how much of the content of AI generated, I'm not saying they use it, but I just wanna know like, how much of this is noise?
Well, not all AI contact is noise there, boomer? No, it is not. But a lot of it is, you know, somebody created sort of video that doesn't exist.
And, you know, it's like, I wanna know. Yeah. But it's a matter of trust also, right?
I mean, even if it's not noise, nobody trusts us. Well, but, and that's the whole thing. If we're gonna have trust and if you're gonna be able to, you know, look, Terry, to your point, people who are living in an echo chamber and just weren't their particular message reinforced, don't give a crap whether it's fake or not at some level, right?
They just wanna reinforce their, they just wanna reinforce their bias, right? Yeah. But for the rest of us, and especially for young people, 'cause I think young people are savvier than, you know, I made fun of Mike, I'm older than him.
You know, young people are savvier than we are. I'm getting tired of, you know, people coming up to me and showing me stuff on social media. And the first thing they ask me is, is this true?
'cause nobody believes anything anymore. Anyway, so, but it's crazy. But this is the same thing.
90% of developers use AI and 40% of them don't trust it. But they use it anyway. They use It anyway.
Well, you know, it was interesting, and not that this is so related, but I had a recently in a estate sale at my mom's house. And one of the things that they, when they staged everything and, you know, whatever, it was all great, but they had my, my world book encyclopedias. Oh, I loved the World book.
Yeah. From the sixties and seventies, right? Mm-hmm.
So I had every like the yearbook that they put out every year. Yeah, Yeah. Whatever.
And it got us to talking about like, how we were kid when we were kids. We would consult the World book. And it seemed to be the authority on, you know, It was A certain level of How many reports did you write using your world book?
Of Course. Exactly. You know, and, and, uh, my fiance said that his dad, like if they were at the dinner table and they ask a question about something, his dad would say, go get the World Book.
Yeah. And let's look at That. You know what?
I'll show you how crazy we were in my house. My brother, I have two brothers, but the one closest to me, we would each take turns with a different letter every night. Because we remember the World Book used to have the transparency.
Oh, like the human, human body, the circulatory system and oh Gosh, my favorite one, Or, or ones you know, about exotic places that we wanted to visit one day. My brother made that list and kept that list and he's visited all those places. That's, Yeah.
You know, it was, it was the source of all knowledge, Those trans That was back, that was back in the day where you had the encyclopedia. You had like only three networks and you could basically trust, Oh yeah. You had three, three networks and you had the World book, or you could go down to the library And not, not, not criticizing, getting a lot of information from a lot of different places, but there's something to be said, like when you just had the three networks, there was a certain amount of journalist discretion.
Right. You, they chose what was sort of important and they didn't necessarily hype, you know, sort of bsy little, Their view of things. But you knew Walter Cronkite was in CBS headquarters in New York and Yeah.
And, and so was Huntley and Brinkley and whoever else was on, uh, a, b, C at the time. Mm-hmm. But Right.
It was, you didn't have the subterfuge of I am in the Congo. And, and you know, commenting on, on what's going on in the US or, or what have you. Those are simpler times.
So, so let's bring back New World Book, social media site. What you see. I know.
I, I see, I see Nobody only all I see a niche for World Book book here. You know, I really didn't. Well, you know what?
I could have AI draw me up on in no time. I don't know. Those transparencies were the bomb though, man.
They were, they were, I I used to trace over them from my book reports. They too. Me too.
Reem is looking at us like, what are these old people talking about? He's like, what the hell are you talking About? Yeah.
It's another, but the rest of us remember. Yeah. Okay.
Alright. Hey, hey, let's take a break here. We are coming at you from Boca.
I'm at least in Boca Raton, Florida. You can count on it. This is Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back in. By the time you're watching this, Alan and I will be in Las Vegas for AWS Reinvent conference. And we've already been a steady drumbeat of news and issues coming up before the conference, including AWS is now using AI tools to accelerate migrations to their cloud platform.
And we'll also see things like, well, Sumo Logic will be talking about how they're gonna reinvent their entire approach to AI using AI agents for security and observability and collecting telemetry data. And there's just gonna be a ton of stuff. AWS will also be, of course, highlighting their Kiro AI agent tool that they are proud of the fact that it is, uh, specification driven.
So if you've watched any of our previous shows, you know what that's all about. But it's a more reliable way of creating AI Coach, shall we say. And they're gonna be touting of the fact that, well, you know what, we can get better AI coach, but there's just gonna be a lot going on.
Alan, I know we've been in this show in the past and you're gonna be doing some videos while we're out there. But, um, what's your take on the state of AWS Well, yes, we we're gonna be doing more than some videos, Mike. We're really booked up for the whole week there.
Um, looking forward to it. I, you know, the state of AWS is, they're still the 800 pound gorilla in the cloud hyperscaler space, right? Google, Microsoft has had, have had some good runs.
Oracle Clouds had some great, well, they have one big customer that accounts for two thirds of their business, but nevertheless, they, they, you know, they have some money on the books. Um, but AWS is still the undisputed king and heavyweight champion. I think we're gonna see a lot of announcements.
It's funny, I've got new next door neighbors. Their son came in for Thanksgiving, turns out he works for AWS and their generator of AI team, and he's presenting at Reinvent, so I'm gonna hook up with him out there. Um, but the beauty of reinvent is it's not just AWS you come for AWS but you get everything else because literally the entire ecosystem is on display there, you know, flashing their wares.
And, um, so it's a great time to hear stories. I, I will tell you that our tech drunk TV coverage, which we will be streaming live Tuesday, Wednesday, and Thursday at, uh, from Vegas, uh, is sponsored this year by Susa, who has a huge rollout of, of, uh, related announcements and technologies around AWS and of course AI and the Edge and everything else. Red Hat is, is very, very much engaged there.
And so you think about that, these are not necessarily companies that you think of as, you know, big AWS components because you need to go, you know, to run, uh, OpenShift, yes, it's available in the AWS marketplace, but it's probably not the default. Same thing with suse and rancher and those kinds of things. So, but just like Mike in the last year or two, look, the big story's gonna be ai.
Mm-hmm. I think the big story this time will be AG agentic ai, where last year was more generative, but AWS you know, from investing in philanthropic to, to doing bedrock and kiro have, have not shied away from being an, uh, an AI friendly hyperscaler. Mm-hmm.
They don't have necessarily Google's position in ai. Right. Google has that vertical integration that's hard to beat.
And they, they are, you know, their stocks flying. They're a $4 trillion company now. And and I think people are recognizing that they, they have a, you know, a catbird seed here coming around the, the bend in the AI race.
They don't have Microsoft's GitHub and, and all that comes with that and their OpenAI, uh, relationship. But they, they seem to be much more open to everybody's ai, right? If you've got some AI stuff, we'll run it on AWS and I think that's what we're going to hear a lot about.
I think there's one shadow that will show up in Las Vegas, and it's this whole notion of sovereign clouds. And folks are kind of think talking more about moving workloads from one cloud, maybe into an on-premise environment or something that they have more control over. It certainly is a bigger conversation in Europe these days.
And maybe our friends in Canada as well. Well, Wella, my Mike, Mike Susa has a whole it sovereign cloud right. Division now.
And, And even though AWS these days is talking about using AI to migrate existing workloads into their cloud, AI will go the other way, right? Mm-hmm. These things mm-hmm.
Will enable people to take workloads more easily out of an AWS cloud and move them to either another cloud or something else. But Garima, what's your take on what's going on here? I agree with you, Mike, and you know, I'll connect the dots here.
So sometime back, we covered the story with, uh, OpenAI and AWS partnership, right? So we had speculations at that time that which regions will be benefited out of this, uh, partnership. We saw that Silicon Valley might be like, uh, the key contenders for it, right?
And then the uc that they have launched this tool AI capability, uh, AWS capability tool, which is basically providing you insights into regional capabilities, uh, of services, uh, which a WS has, and also forward thinking roadmaps. So, I mean, pros are obvious to understand, but I will, uh, talk about a little bit of the cons, like how the AWS ecosystem is, uh, you know, developing and ensuring that, you know, they probably move the workloads in the right regions, you know, for the sake of sanity. I would say that, you know, they have not integrated it with the live, uh, like the console management system, but they are putting it as a dashboard.
So the AWS capability tool will give you more possibilities to see through what kind of regions are more proactive forward thinking, what kind of pre-deployment integrations you could do, and also talk about the cost and risk, right? So it's kind of, you know, I'm yet to kind of see if this prediction of mine or this speculation of mine is, uh, to the point or not. But I think this is driving workloads in a, in a pragmatic way to some specific regions for some specific capabilities.
Of course, this, uh, tool, which we have talked about, uh, the AWS capability tool, they don't advocate, they just say that it's a planning tool, right? But you can influence the planning, right? So I, I would see that, you know, that can be one of the possibilities.
And then, uh, like capabilities, like Kiro and all these other things, I think there will be some announcement made, uh, kiro for uh, sure, because it's of interest, it's an id and they, they compete in a large scale kind of ID ecosystem. So it would be interesting to see what they're doing there. You wanna know something else?
I'm looking forward to what's Google's counter programming, right? The last couple years at AWS, Google's always done something on site or around site there to say, Hey, we're here Last year, I think they took over the outside of the sphere and made it into the Google colors. Um, so it'll be interesting to see what, what Google goes there.
But look, it's, you know, it's 60,000 people. It takes up a good part of the strip. I'm, I'm looking forward to it.
You know, what I'm looking forward to, I'm looking forward to discovering that X thinks that Techstrong is now moved to Las Vegas. 'cause we'll be tweeting Out while y'all are there. And I'm also looking forward for some kind of a cloud diagnostic, uh, days, uh, you know, looking ahead of like how we compare AWS Google and other platforms like, or Oracle and so, and Clouds, uh, for example, like Canada has their own coherent, uh, but I mean, from cost constraint perspective, it'll be very interesting discussions, uh, moving on, Right?
I'm with you. I, I am, it's been a long time coming, but I feel like rational conversations are finally being had about where workloads go and AWS is fine and it's a good choice, but it's not the only choice. And I think people are getting smarter about maybe not locking themselves into all those proprietary APIs, and they're figuring out, well, let's let the workload decide where they, You know, they, they make the exact, you know, it's funny you say that.
They make the exact opposite argument when they talk about, and we've done a series of webinars here on, uh, with AWS partners on modernization and transformation and basically moving off of VMware mm-hmm. And an on-prem level. 'cause you're locked in to their pricing and their licensing and everything where AWS actually offers you choices.
Right? And, and so, you know, some people don't view it as a lockin, Right? Well, what they're really saying is give up the VMware proprietary APIs in favor of our proprietary, The old boss From, From the webinar.
Well, we voted Fool. Again. It's a good place to end today's show.
I think the new bus, the old boss guys have a great, have a great, uh, Monday we will be continuing, I think we have one more show before we'll be live doing gangs live in Vegas at, uh, Textron for Strong Gang. We'll probably do our first show there Tuesday. So, uh, hopefully then.
Until then, though, thank you for joining us as always here on the gang, Terry Garima. Mike John, thank you for of course, lending your thoughts and into this. Thank you for watching.
We've got a full text trunk TV following, but for now, I'm Alan Shimel and we're out.