Techstrong Gang – April 21, 2025
Alan, Mike, Mitch, Sulagna and Tracy Ragan delve into the implications of a ruling that acknowledges Google has been operating as a monopoly in the online advertising sector.
Then, the gang takes a look at why Microsoft is investing more in advancing cloud-native technologies before discussing the degree to which commercial software is just as rife with vulnerabilities as open source software.
Transcript
Hey everyone. Have you played the latest game out there? Google Opoly.
You're watching Text Drug Gang. Hi everyone, happy Monday. It's Alan Shimo and I am thrilled to be here on Textron Gang.
I hope you are too. Uh, we've got some great gang members. We're gonna be talking about the news of the day, as we always do.
Let me quickly introduce them to you first. I, I think we're gonna go to New Mexico and yes, she has a new camera and we could really, really see her here. And, and we're so happy I, you know, thrilled to have, I'm So glad.
I'm so glad I'm no longer pixelated. Yeah, well, no, you weren't pixelated. You are always a little foggy.
Just a little fog. It's like, I feel like I went from the TV where I had to sit and hold the antenna or put some aluminum foil on it to my first hd, so, Well, I still feel foggy. It's early in the morning, but I'm so happy to be here, you know, discussing topics that are gonna be thrown at me that I'm, I gotta dance to.
Okay. Tracy Reagan, CEO of Deloy. Huff here.
I'm the gang. Moving from Tracy. We're gonna move to a text drawing editor.
I think she's in Ohio, probably back home in Ohio. She is our techstrong editor for Text Strong. It Text strong ai, I believe, and she does so much more our own Sag Saha.
Hi. Hi Sagner, how are you? Hi, Alan.
I'm good thanks. Good to be out. Very nice and red today too.
So thank you for joining us on this lovely Monday. I hope everyone had a nice Easter moving from Soner to Colorado. He, I don't see any red lipstick on him, but he is future MVP, uh, DevOps.
Getting ready to get out to RSA next week. Our own Mitch Ashley. Hey Mitchell, you're on mute.
I think I am. 'cause the dogs were barking, but they've settled down. So I, I wanted to say, you know, I love Tracy Reagan so much.
There is no camera made that can adequately capture the awesomeness that it's Tracy. She's such an, an amazing, I really mean That's such an amazing person. We're just, do you owe that Owe money or something, Mitch, what's going on here?
Uh, but yeah, no, we're all on the Tracy bandwagon today. That's how it is. All right.
And then, you know, in the, in the Center Square on Hollywood Squares today, uh, he's a Yankee fan. That's lefty Throws Righty four tool guy, our Chief content officer, Mike Ard, And, and happy to be home and generally recovered from jet lag. So it's all good.
All good. Happy Monday. Well guys, we're a week out from RSA conference, one of my favorite times of the year.
You know, Mitchell and I have been going to RSA together, what, since 2002 maybe, Mitch. Yeah, 2002. That's right.
It's been a couple years. We, and there's been a lot of water and vodka and everything else under that bridge. Um, Many, many evenings and cabs and viewers And, yes.
Yeah, having fun. But I'm looking forward to being out there with you again next week. Of course, we'll be kicking off our 10th Annual DevSecOps event if you're going to RSA Monday, which is kinda like satellite conference day, zero day in the Moscone Center.
I think we're in Moscone. I always get confused between North and South. If at Moscone West, it's the one on this side.
Um, I think it's north. You would be south now if West is to the Left. No, we West is where broadcast Alley is.
Then you got north and South. So anyway, you can look it up. It's DevSecOps Connect.
We're talking about ai, cyber and app dev. Mitch will be doing a great panel there. I'll be hosting all day.
So if you're at RSA, stop on up, even if you just have an expo pass, he gets you in on Monday to see our event. Um, and we'll be our broadcast alley all week after that. So be sure to check that out.
Uh, it's still not too late to register for RSA, by the way. And if you need an Expo pass hunt around the Textron or Security Boulevard LinkedIn pages, I think we've put up, uh, codes for free expo passes. If you can't find it right, me, I'll get you an expo pass.
Um, or at least an expo pass code. You still have to register. Anyway, moving right along.
Our first story today is actually a judge's decision that came out, uh, last week. I don't think it was unexpected. Uh, you know, they've labeled Google a monopolist, a monopolist.
That means they've, does that mean they don't pass going? They go directly to jail. They don't get to $200.
What does it mean, Mike, you want to take it? I'm not entirely sure what it means myself, but I am like, well, it's 2025 and we finally figured this out. So congratulations, everybody.
But I feel like, you know, we've been abused for a long time and I'm much more interested in what the potential remedies might be. Alan, do you have any thoughts about how this should play out? I mean, because Well, I, I think, I think there's, I don't wanna get all lawyerly and nitpicking, but I think you gotta understand what this particular ruling is versus other rulings both in the EU and the US have, you know, regarding monopolist practices by Google, quite frankly, usually Google is considered a monopoly for search, right?
And AdWords and so forth on search, because they do control 90 plus percent probably of the organic search market. And, and so they sort of get to set the market for things like Edwards and search and rankings and all of that. And they have been found guilty of monopolistic practices on that issue in the past, I think in the eu for sure.
This monopoly, uh, board game was not around search, it's around their advertising monopoly. Um, it's basically, you know, they own double click and then they said how, what the, what the rates are for you to get an ad in there. And so this one is around advertising.
So it subtle follow me here, right? It's nuanced. This isn't a search monopoly.
This is an advertising monopoly. So that's two monopolies against them. It's like, well, putting two hotels on Boardwalk.
Oh my God. It, I think it's about time. It's been, you know, if we call it, call the spade to spade, right?
I mean, as a small company, I can't even tell you how frustrating it's been or the course of my career as a CEO running small companies to try to compete for advertising because it's so expensive and there's no place else to do it. But I can tell you, I'm very happy to say that. I don't even talk about, uh, you know, advertising anymore on Google.
All we talk about is optimizing for ai. So while I'm glad that she's called this out, I don't know if it matters because I think that that line of business will be falling off. I would pharma, I would rather use a, you know, something like a chat BT or even Gemini itself to get information and not have to look at the ads, and the ads come up based on your searches.
So they are, it is different. No, no. But these ads that they're talking about here, Tracy, are not the ads on Google search.
It, what's you, it's the business of what used to be called Double Click, which is now Google, uh, I forgot what the official word title is for double click Google advertising, Google banner ads. They run the banner ads market, Right? Right.
Which is a market we could never play in. We never, it was just like, there was no problem down. No, I mean that, look, the price down, people don't click on those anyway, but, but that being said, the repercussions of this could be severe because this combined with the search monopoly makes a pretty strong case of, you know, do you gotta mabell this?
Do you got it at and t and cut it up into nine different regionals, or in, in this case, cut Google up into different businesses. Does the search business somehow get decoupled from the advertising business, from the AdWord business? How, how would you even do that?
How would you support the search business without the advertising business? Maybe search. I, I don't know.
How would You, how would you drive Gemini without all the data that you're using to drive it Into, well, how, how, how would you justify Google's stock price without having this monopoly? Right? But you know, Tracy, you said something and it, and it, and it, it resonates to me because, you know, one of the things they teach you in law school is the principle of judicial economy.
Don't make, don't don't make a law if you don't have to. Don't make a decision if you don't have to. Sometimes these things take care of themselves, and it may very well be that we sat on our hands so long on Google's stranglehold on certain markets that we finally have seen the worm turn and new technology come out that may allow us, that may take care of this by itself, as you say, right?
If ai, if AI represents an opportunity where we're throwing all the cards back up in the air and seeing where they land, right? Maybe Google doesn't wind up with that stranglehold that they've had. Yeah, I mean, I think all of us would rather watch, uh, TV without commercials, Right?
Someone's gotta Pay. Then who, as the content officer, who's gonna pay for the content that gets created on these things? If there's no ads and it's all surfaced up through ai, who's, uh, how is that gonna get monetized?
I don't think ads are going away anytime soon. I mean, we've all predicted, or these thought ads might be going away, but there, as ever present as before. And that's how a lot of mobile apps have been funded or paid for revenue.
You know, I think the question about, I I looked up before we got on, uh, the Textron gang today, and I didn't use Google to look this up. 8, something like that of the, uh, search, uh, is happening through Google. So, you know, if it's any closer in it's a hundred percent.
I mean, you're, you're almost there. Well, right, Anything over 80, 85% is, is monopolistic. But we don't live in the days of standard oil where things get broken up into separate companies and, you know, torn apart.
And at least that hasn't been the pattern for, uh, anti, uh, competitive behaviors. Monolith, monolith, monopoly behaviors, monopolist behaviors. Um, more likely it'll be some tweak this thing here.
So you don't have quite the advantage there. Uh, take that away from that browser there. So you're not the default here.
Pay a fine there. Usually, those are the remedies that we get out of these, these, uh, legal actions, antitrust actions. So I, I'm not anticipating any great or shaking revelations to come out of this.
I could be wrong, but that's not the history. I, I, I, I, I'll say this, no matter what they do, the cows are already outta the barn and the damage has been done. You know, I, I did on one of, I did two Shimmy says segments last week on LinkedIn Live.
The second one linked to an article that I wrote, and it was, that article was also published in the newsletter of a, a Comprises, which is a, an organization that seeks to bring together like PR agencies and media companies and stuff like this. And, um, the problem is, is it's fundamentally changed my business anyway. Sounds like it's changed Traci's business a bit, but in the media business, right?
There was a golden age of, of digital internet media, maybe five years ago, 10 years ago. And that media, uh, you know, the, the big revenue stream was, was ads, banners and ads. Never for tech strong, I might add, right?
Because we serve a tech audience, and banners are just never a big, a big component of our rev mix. But, um, for the media world, Google had to stranglehold on, on the traffic that you got from organic search. And they were, as you say, Mitch serving up 82% of 80 plus percent of the digital ads.
And, and I, you've seen in the media world, not just tech media, but you know, all media, huge companies going under big re, you know, uh, just all kinds of craziness and chaos going on because the bottom fell out of that market because instead of just relying on building a big audience like a TV model where you build a big audience, your Nielsen ratings are up and you charge more for advertisers, you couldn't, 'cause you could charge more for advertisers. Google charged more for advertisers, but you didn't get it. And, and so the model has drastically changed.
And media companies now have to say, maybe I want a smaller audience, but I know more about that audience. It's a more engaged audience. It's, you know, I could better monetize that than just trying to be a mass marketer with, with Google Banners running.
Nobody talks about this. But that model you described did massive amounts of harm to readers. 'cause media companies turned their content models upside down, and they started chasing stories that had the highest ad rates associated with them.
So they'd spend an ornament amount of time on narrow topics that somebody was paying a premium ad for versus a mainstream topic. And it kind of just changed their entire content strategy in a lot of these organizations, and not in a way that was in the interest of the reader, to be frank, Spoken like a true chief content officer there. Mr.
Vard. I, I don't disagree. I don't disagree.
Somi, you're an editor. What do you think about that? Yeah, obviously, um, as we have seen in the case that publishers have been affected by this, uh, monopolization of, uh, advertisement by Google.
And yes, at the end of the day, it is the readers, it is the consumers, uh, that it comes down to, uh, to heart. And, uh, and not only does this kind of behavior kills competition, uh, they also work unfavorably for businesses as well, and like the entire s swath of, uh, entities. And I agree, uh, to some extent with meh, that nothing big or revelry is really gonna come out of this, um, uh, antitrust case, really.
Uh, 'cause you know, like we have seen this over and over. Google got, I'm sorry, apple got sued too, uh, by the DOJ for its, uh, closed ecosystem that makes it difficult for customers to leave. Um, Amazon Meta, they have all been accused of, uh, monopolistic behavior, uh, the FTC suit, Amazon, uh, for monopolizing the marketplace, um, like squeezing sellers and not letting them sell their products, uh, on other websites for, um, lesser price.
And, um, and there's the antitrust against Meta for, uh, creating a monopoly in social media, buying, uh, WhatsApp, Instagram, and what have you, uh, crushing competition. So Google might be forced to sell some portions of its ad technology. I don't know, double click maybe.
Um, uh, yeah. But, and that probably will check some of its influence, uh, to a certain degree. Uh, but yeah, I don't see any, anything big happening from it.
86 trillion company, and it's basically the face of big tech. And they've always influenced, um, the way we use internet, the way we, uh, browse the way we shop online. So it would be quite difficult to completely cut that back, that kind of influence.
Mm-hmm. You could argue though, that Google has generated a lot of revenue that is Ill-gotten. And so, and you could theoretically come up with a case that says, you know, here's the level of fine that needs to be applied, and maybe people can make a claim for some level of damage on that.
Fine. And we'll all get emails saying, you know, we qualify for, you know, a $25 payment from Google because, you know, they're part of this massive settlement that somebody created. But theoretically there is, I think, some sort of penalty that stings needs to be applied here to make, uh, you know, not becoming a monopolist attractive in the future, right?
Otherwise, we have all these crimes that people are committing, but if no one's actually getting penalized, then the next person will just do the same thing. Unfortunately, um, for, uh, cases like that, so many companies, so many businesses, so many people are affected that a small fine does not make justice for, uh, uh, the damage caused. So yeah, obviously cumulatively it would be a big amount for, probably for Google, but, well, they have got money, you know, that I would guess a a Google's gonna appeal this and it'll get pushed back for Yeah.
Years mm-hmm. Before anything ever happens. And they have an ar They, I mean, they could certainly argue that there's TikTok out there.
The tiktoks probably taken a good portion of their, their, their business because people have learned to do things in different ways that we, Everybody Well, that, that, that's exactly my point on judicial economy, right? Where if you wait long enough, the situation will rectify itself. Hopefully.
Let me play devil's advocate just for a quick second. Would the internet be all it is had it not been for Google's dominance and search and ads? Yes and no.
I, I would say that search played a, a key role in that, but we could have had multiple search engines of People. Well, we did, right? I'm old enough to remember Alavita and Infoseek and site at home, and of course, Yahoo.
But eventually Google cut deals with people and gave them a kickback on revenue that loaded Google in front of you, and it became like a, a dominant thing. And I think ultimately it wound up being a preference. And also, you know, they had a better indexing engine that they were using.
No, no. They had a better mouse trap. And, and, but it wound up being monopolistic perhaps.
But because of that, was the internet able to become better or more useful? I think there's, there's two sides to this coin, Alan. One is by being a dominant player, they put all the eyeballs in one place.
You know, going to Google, that's where you're gonna get the most search traffic, looking at traffic. The downside is they control all that. They control the algorithms, they control the advertising.
Um, and they're constantly changing. I mean, how, how often do we talk about, oh, the algorithms change, something's different, our traffic is looking different, what do we do? And everybody gets out there magic eight ball in their Rubik's cube and whatever Ouija board to figure out what the algorithm is doing now.
And that's been harder and harder to do over time. And as, as generative AI has come on board and people are starting to use perplexity and Gemini and other things in place of Google, you know, is putting pressure. 'cause those are not ad driven, uh, those services.
So it's, it's, it's an interesting time. But, you know, I think, I think choice and freedom of choice always wins the day. And as soon as someone is the dominant player, and it's a far distance to the second, that's not healthy for, for our environment because now we're not getting the best products we can get.
I Think their addiction to ad revenue is killing search. Because if you go in on Google now and still use it, you know what comes up is four to five ad units before you actually get to the point of what you want. And ultimately, people are just walking away from that model because they're like, this thing isn't particularly useful.
And then they'll run around and start saying, we need to change the algorithm to make it more useful. But the fundamental issue is the algorithm's being tweaked to drive the ad revenue and the ad revenue is popping up results that nobody wants. Yeah.
I'm just gonna say one more thing and then we gotta go to break. Thank goodness for Linux on the desktop that saved us from that Windows monopoly You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients, let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're gonna have a little chat about what Microsoft is up to in the cloud native space. They were recently at, uh, Q Con in Europe with us, and Mitch met with them and generated a report.
And, um, it's interesting to watch how Microsoft seems to be evolving in the open source space. Um, you know, is is, does, does the tiger have a different set of stripes? Mitch, what's going on?
Well, you know, we don't, don't talk about Microsoft and Kubernetes always in the same breath, right? We all know that they have a k uh, a KS Azure, uh, Kubernetes services. Um, but I think they get overlooked.
A lot of what they do contribute. You know, maybe they're not the number one contributor to Kubernetes, but they're very active in the community. com site, is that the areas that they were beefing up were all around AI workloads.
So there were some things they added to, uh, well, AI workloads and also simplification, addressing the complexity problems with, with Kubernetes that we're all well aware of, um, AI workloads. They did things like adding support for VLLM, which is an open source standard for essentially giving you, giving you programmatic access to different models instead of kind of hard wiring models into your, into your code or into the, the server. And so that gives you better access, but also some things that will drive better performance, higher performance with AI applications kind of get into the weeds of what they are.
But, um, the other is they, they've made some improvements to some of the manageability, like doing some auto upgrades of clusters, making that easier. But one of the things they also contributed was a new open source project called headlamp. com had an article about this at the time when that was made.
And headlamp is an attempt to say, let's kind of step back and put a new fresh skin on top of Kubernetes, uh, from a management standpoint. And then they contributed that back to the CNCF. It's a sandbox project.
It's early, and, you know, is it stunning in terms of what it does? No, but it's, it's pretty simple and it doesn't look like a Microsoft product. It looks like an open source tool, and there's been some good reception of it.
I mean, not everybody's signing up and rush rushing on to be on the project quite yet, but, you know, it holds some promise and I'm glad to see them. Microsoft noted contributing back to Kubernetes and improving a KS, but also, you know, trying to address the, the complexity issues around Kubernetes. Tracy, um, you know, we talked about headlamp when we were out in London at CubeCon on this show, but, um, it seems like a couple of things are coming together here.
Kubernetes is kind of like the new os and then we're seeing Kubernetes used pretty much at the core of every AI project. And now it feels like Microsoft is trying to throw a graphical interface on top of that called headlamp. So are we looking at the window of Kubernetes with AI kind of driving that, or what's your take here?
I think that, uh, Kubernetes is pr pretty complex. Uh, especially if you have like literally hundreds of containers running out there, tons of name spaces, and you need something to make it more, uh, to simplify it, you have to have something that you can see what's happening. Uh, I don't think that we're gonna have, uh, you know, this is a tool for, you know, Kubernetes admins.
Um, so it, it, it's a long time coming. It maybe it'll make chargebacks easier, right? If you can start having some visibility into where your costs are and where, you know, the jobs that are running, you know, the, you know, what the, the demon sets that you're trying to manage it.
I mean, there are so many things to understand when you're building out these large Kubernetes workloads that you have to have something that gives you visibility into what you have created. I, it's, to me, this has been a long time coming. Why didn't they create this sooner?
Why did it take so long to do this? Because when you have these kinds of complex tools, if you really wanna push adoption, you have to simplify it. And I really do believe that we're at a point with Kubernetes and, um, that we're at a point where we really wanna start pushing adoption.
I work, um, a lot with government and they're talking about moving from HBC VMs to a Kubernetes environments, to looking at decoupling. And in those environments, you really have to have something to simplify it. So it's critical, You know, it's a big, it's a big part of the platform for modernizing off of VMware.
People are looking at, you know, KVM and Kubernetes and, and I've called, I've called Kubernetes the dominant workflow platform. I mean, it is everywhere. It's in it, it's what runs my Office 365.
Um, you know, Microsoft had to transaction off their own technology in 2022, I think it was, to start using Kubernetes. And maybe this tool was born out of that in part. But, uh, your point's right on Tracy, I mean, not dinging Microsoft, but why did it take Microsoft to come up with this open source project to do this?
This could have been added contributed. Maybe you and I, Tracy should have done this two years back and, and built something, but more you than me. But, but, you know, well, somebody did it.
So let's see if we can, uh, help support it and see if it takes off and, you know, gets some, gets, uh, people behind it using it. I did have dinner with a, um, very large he healthcare insurance provider who actually, it was a healthcare provider who, I can't tell you the numbers, but it was like in the thousands of Kubernetes clusters that they manage. And one of the big challenges when you kind of get to a certain level of a really large installation of Kubernetes is not just operating it, but upgrading it.
Because Kubernetes is on a, a cycle of how often they come out with releases. And I think it's something like after the fourth, the fourth one back is the last one they'll support. So it isn't supported in pep per perpetuity.
They want you to upgrade it. And when you have a really large installation, you can't upgrade your stuff four times a year or twice a year, maybe once a year. And so anything that helps people do multi cluster multina, space upgrades, uh, deploying patches and fixes, just the blocking and tackling at that scale is extremely difficult.
You know, for the record, I think it was 2016 or 2017, I went to DockerCon down in Austin, Texas, and we were looking at launching what became cloud native. Now, it was originally, if you remember, well, Mike and Mitch, I'm sure you do Container journal, and we changed the name, but at the time, I was thinking of something with the word docker in it, but, you know, Docker had trademarks on everything. And, um, so I went down to DockerCon and I, I did a lot of, I was pressed, I did a lot of interviews, spoke to a lot of people, had a lot of barbecue.
And I came back here to the media ops at the time, not even Tech strong office, and said, you know, Docker's really hot. We can't use that name anyway. But everyone there is talking about some new thing coming outta Google that's gonna be released soon.
8 was the release at that point, this thing called Kubernetes. But I looked at it, and I'm telling you right now, it's so damn hard. It's never gonna catch on.
It is just really, really hard to use. I can't imagine who would want to use this. I'm still working because Chay, Mitch had we done a, a nice gooey for coup back then, we'd probably be on some Caribbean island now, or Greek Island or something, right?
Vacationing. I think we all, I think it was well known. It was obvious that Kubernetes was too hard.
And I think part of the reason that, sorry, go ahead. Uh, it's not just Kubernetes that's hard. It's what you create on top of Kubernetes, right?
When you start blowing apart your monolith, so you can take advantage of a decoupled architecture, your application becomes hard, becomes complex security around it becomes more complex. Deployments become more complex. Jenkins workflows become more complex.
So it, it has a trickle down or a trickle up effect. So it's not just the operating system, it's not just the platform you're running in. It's everything that touches it.
I'm, I'm not saying that correlation is causation here, but the UK is looking hard at Microsoft for charging more for versions of Windows on that run on other clouds than their own. And it may come down to a point that maybe the reason that they wanna make Kubernetes a lot more, uh, graphically friendly as it were, is 'cause they know that at some point someone's gonna come knocking and saying, Hey, you know, this thing you do where you charge people twice as much for running windows on another cloud is, uh, perhaps illegal. But we'll see how that kind of plays out.
But maybe they need an exit. This is it. And yet another reason for Linux on the desktop.
We're gonna take a break on text gang. We'll be back. com Is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security Bloggers Network. Hey folks, we're back and we're talking about, well, application security one more time, but there's a report out from the folks at Reversing Labs that notes that, and we've talked about this on the show multiple times before, that, you know, commercial software is just as prone to have vulnerabilities as open source.
And we see the open source community kind of gets hit on the chin a lot about this particular issue. But Tracy, let's start with you. Um, a I don't think anything in here surprised you, but should we not be maybe beaten up on the open source community so much about this when it seems to be a problem that everybody has?
Uh, well, you know, I'm a fan of open source and I have been frustrated with how much open source has been blamed for, for vulnerabilities coming through the software supply chain. And while it's true there, there, uh, we are starting to demand more accountability from the open source communities and accountability and visibility. I think we still have some problems with, um, exposing if an open source community is actually trying to comply to basic security practices like open SSF scorecard.
But when it comes to commercial software that you're purchasing, you're bringing in and you're running, we don't have the habit. And I'm saying collectively, we of asking for an SBO m asking for, um, a, a vulnerability report on a regular basis, or having any way of seeing what exposures might be coming through that commercial software and that commercial software consumes open source packages. How old are those open source packages?
Do they have ones that are, uh, that have, you know, current vulnerabilities that are malicious that they shouldn't have re uh, sent over to a customer? So this really is a discussion in, in my world about accountability, having easier ways to see what's being consumed by the software you purchase or the software you use for free. There really isn't a big difference in my mind because what you're saying is, I want to use this, I'm gonna put it in my environment, whether you pay for it or you get it from a GitHub repo, um, it kind of doesn't matter In my world.
What matters is that we don't, we're not doing a good job of managing this problem. Um, you know, we talk about shifting left, shifting left, doing code scanning, but we seldom ever talk about what is hitting production today? How can we manage it?
How can we react to it as quickly as possible? We always push this conversation over to the left, which is why open source communities get beat up about it when commercial software, they should be pushing things to the left too. But what's operations doing and how does operations or anybody accepting code from a commercial source, what are the standards we should practice to make sure and put accountability on that commercial company to make sure they're giving us code that we can trust?
And if there's a problem, how do they report it? And I know companies like Microsoft, they have an amazing, um, procedures for reporting what is in their, uh, commercial software, but that doesn't mean everybody. And there are, there's a lot of commercial software out there that is, has got lots of exposures they're not trying to do, they're not shifting left, they're not being pushed like the open source community is.
So we have a long way to go. We have a very long way to go to solve this problem. And what we're doing now isn't enough.
I think the transparency is on two ends of the spectrum, right? Open source, it's very visible. What, what the bugs are, what the, the vulnerabilities are.
Um, it, it's not hard to get ahold of it. And because some of them have been coming in parts of Linux or in code that's wide in widespread use, that that catches our attention in the media side of things. Not the same is true necessarily.
I mean, we do hear about, you know, vulnerabilities of something that happened in Zoom or Microsoft product, whatever it might be, but we don't have, you can't go anywhere and say, well, tell me all the bugs that are in your software. Let me see which ones I'm really concerned about, and I just don't have the access to that, nor do I have the time to go look at all that stuff. So one, it's, it's, I think it's easier to, um, to kind of pick at and say, this is an issue when it's, to your point, Tracy, it's just as big an issue for all software, uh, is making sure that we are addressing those vulnerabilities and there's a whole disclosure and not everybody discloses at the same level and the same rate.
So it's, it, I think it's, I don't know if unfair is the word, but I think it's, it's easy to jump on the bandwagon and say, open source is the problem. It's not the problem. It's, it's how we manage vulnerabilities.
The part that drives me. Yeah, the part that drives me crazy is the commercial people will wrap themselves in this thing that says, you know, well, we're not open source. So we we're clearly more secure.
But half of the code that's in that commercial offering is borrowed from some open source code somewhere that some developers have in there, Close it 80, but it, It's a visibility problem. We don't have visibility into the, uh, to what if you, if you bring something into your environment, you don't have visibility into what's happening in that code base. You have no visibility whatsoever.
So we have to fix this problem. I don't wanna call it observability. I've been talking about this forever, is visibility into the packages that you're consuming, mapped to where you're running it so that when a new vulnerability does show up, you know that you are impacted in your environments, whether it be open source or commercial or homegrown.
So We have to have the visibility. com, and I say, oh, my, the worm is turned again, when I first got into technology and security specifically, I think the prevailing thought was that open source was more secure than commercial software. After all, there were a thousand eyes on the code, right?
That was the prevailing argument. There's a thousand eyes and anyone can look at the code and test it for themselves. Of course, we found out that no one really looks at the code.
There's two little guys in a garage that do the mo 90% of the code in there, and it, you know, and then the worm turned and all of a sudden, open source is insecure. Open source is insecure, commercial sauce is more secure. Now we're saying, well, commercial sauce is just as vulnerable as open source.
Well, Mike, you made the point. 80% of the code in commercial source software is open source anyway, or built on open source. Uh, the real answer is all software is insecure.
That's it. Now, will SBOs help us to better manage insecurities as we find them? I hope so.
That's certainly the promise of SBOs. And the thing about SBOs is I've never read a thing that says SBOs only for open source software. SBOs for all your software.
If you're going to mandate the use of SBOs, it's for all software, not just open source or, you know, or closed source. And, and that is, I think, and that's something that could really help here. We, we had a report last Friday about what went on last week with the CVE database and, and then subsequently the national, uh, vulnerability database that NIST maintains.
And, you know, this whole issue of managing vulnerabilities is, is hot again, right? I thought when Mitchell and I worked at Still Secure and Mitchell developed a product that we had called Van Vulnerability Access and Management, I, it, I I thought we were making progress. I thought if you would've asked me in 2003 when we did that, would we be sitting here talking about this problem in 2025?
I would've said, God, no. God no. We'll, we'll, we, we, we'd have figured it out by then, but we haven't.
It's worse now than it was then. I am, I am, I am optimistic on two points though. One is, uh, it's true that providers of commercial software are reluctant to give SBOs 'cause they don't want people to know exactly how their thing was configured.
But some companies and corporations are now telling those people they're on a do not renew list. Because if we don't have visibility into that software and we don't know what the vulnerabilities are, we're Not, so are we looking for them to voluntarily immigrate back to their native country? I think it, I think if you're running software, you have a right to know what's in it, because it, it impacts your entire operation.
So, So just let me just wait. Let me say something about SBOs really quick. Okay.
SBOs are great, but they suck because, you know, There's something about the meaning in li meaning of life in that Chay, they're really great and they suck, but They suck Uhhuh because if you don't consume the data, it's, there's too much volume to it. It's, it's not something a human can interpret or work with. It has to be consumed in order to be relevant.
And we don't have that conversation enough. And I get frustrated because Deploy Hub, that's what we do. We consume SBOs, we aggregate SBOs, we expose SBO M package information, we map it to the production environments.
But just like testing security and testing always gets pushed to the side, especially when you're trying to keep up with AI or you're looking at a recession and you wanna cut staff. So that's why Alan, that's why we're still here. I, I am.
Do you think we'll use AI at some point to make, you know, to consume that SBO m data in a way that humans can wrap their head around it? We Are actually, well, we've already done a quite a bit of work, and the Orillia community is working on, um, you know, model context protocols after we learned about that last week that I reached out to the, our open source community, and they're like, yeah, we're already working on that with our data. So I believe that we are getting to a point with AI that we will make, uh, make us smarter when it comes to reading the SOM data and doing something with it.
But that data still has to be aggregated across multiple containers so that an application can be, can be, um, an application security profile can be seen, and the vulnerabilities at the application level can be dealt with. It has to get aggregated up, and it has to be exploited across all the applications that use that particular container that may have that Conti particular vulnerability. Kubernetes has made this more complex, so now we need the tools to be able to read the data, aggregate it, but everybody start generating an SBO m even though it's just a check mark now.
Agreed. Agreed. I, I think it's, you know, we've been talking about SBOs now for two or three years.
It's time, it's time for that. Anyway, it's also time to end our show today. I hope you've all enjoyed this Monday morning, uh, edition of Text Junk Ynk.
Uh, we have as usual full day of, or a few, couple hours more of Text Drunk TV for you to watch. So check that out, some great content. A reminder again, next Monday, we will be out in San Francisco at RSA and I think, uh, Mitch, you and I will, whoever else we can grab out there, we'll probably be doing some gangs, uh, from RSA.
We'll be broadcasting live from broadcast Alley all week, so please do check that out. Um, we have a, a lot of other activities going on. If you wanna meet up with us at RSA, you could reach out to us on social media or email and, uh, you know, our dance cards are full.
I'll be doing a lot of video interviews, but there might be some time, always time to catch up with friends from the security world. Anyway, until then or until tomorrow, this Alan Shimmel for Textron Gang. Have a great day, everyone.
We're out.