Techstrong Gang – April 29, 2024
Alan, Mike, Mitch and special guest Tracy Ragan debate the degree to which artificial intelligence (AI) might one day improve application security. Then, they dive into what motivated NVIDIA to buy a company that makes it possible to use graphical processor units (GPUs) more efficiently. Additionally, the Techstrong Gang turns its attention to the need for everyone to go to “prompt camp” to learn how to use generative AI
Transcript
It's a great Monday here. We got a lot of great stuff coming up to you, uh, coming up for you. As usual.
It's a little AI heavy this week. I hope I open. You know, it's, it's gonna be an AI week.
We've got a lot for you to watch. You are watching Textron Gang. Hey everyone.
Here's Monday start of a new week, and we're starting the week off on a heavy AI news front. It looks like. Let me introduce you to our gang members today here on Textron Gang.
First of all, one of our roping gang members from the Wild Hills of New Mexico. She's also the CEO of Deploy, having co-host of tech strong women, our good friend, Tracy Reagan. Tracy, welcome.
How are you? I'm doing great. Glad to be here, Ellen.
Good to have you on. Um, joining Tracy and myself today. Um, again, from the Mile High City, no reflection on his current state of mind.
Um, is our CTO and Principal Research Analyst at Techstrong Research. Mitch Ashley. Hey, Mitchell.
Welcome. Welcome, Alan. Good to be here.
Good to be with the gang, and joining Mitchell, Tracy and I to my left hailing from Dub Bronx, our Chief Content Officer, Mike Ard. All right, let's go. Yankees.
Yeah. Huh? Go.
Yankees is right. All righty. Um, so, so team, as I said earlier, it, it's gonna be a big AI day, it looks like today, in terms of our news.
And, and that's nothing news. I mean, nothing new. I mean, AI is just, It's everywhere.
Everywhere. And then everything, um, the next, the, the first kind of bit is a piece coming off of Security Boulevard. Um, and it's really about, you know, is AI gonna help us with AppSec?
Yeah, it's interesting. Evan's Data has a survey out there that says, roughly a third of the developers they talk to expect AI will improve the security of the code they write. And of course, you know, I looked at that and I scratched my chin a little bit, and I went, Hmm.
So two thirds, does that mean two thirds don't expect it to help them at all? And they think that they are fine as they are, because the evidence would suggest maybe not. And the other thing is, well, and I'm gonna kick this to Tracy, you know, are just a third of all developers, not good coders in the first place.
And it's just the nature of the business. So, Tracy, what are your thoughts here? Um, I think there's a lot of opportunity, uh, in co-development.
Um, uh, when it comes to ai, however, I don't believe it's going to solve problems at the, at the initial coding state. Uh, so in other words, I don't know if AI's gonna generate any better code than a developer would write. Um, you know, we, we do static code analysis.
In fact, I was at, uh, uh, the secure open source software conference, uh, about a couple weeks ago. And I was kind of disappointed to hear some of the individuals who are running some of these working groups talk about how static code analysis is really all we have to do. But the problem is in the statement, it's static, right?
So if we think about, if we go beyond just doing development and, and generating code, and we start looking at how AI can apply the remediation of vulnerabilities, now that gets me excited. I mean, we're doing a lot of that, uh, research right now at Deploy Hub. The idea that if you track the code with the deployment and the SBO m would AI then would allow you to say, okay, I know there's a vulnerability in this package.
It's listed as high, I'm gonna go out and find the, the correct, uh, new package, bring it in and redeploy. Boy, wouldn't that help us? According to jfr, it's taking us 227 days to remediate a, a vulnerability.
AI can fix that, but I don't really see that as part of the development process. I see that as the DevSecOps process where AppSec kind of fits in. So yes and no, um, AI's AI may make, uh, generate better code, but if it's pulls from its examples that already has bad code, it's just gonna create, you know, the same thing that a human would.
And that's kind of what AI is supposed to do anyway. Um, what we have to do is start developing more AI collecting, gathering more data, understanding the threats, understanding threat threat models, and start building out these, um, LLMs that can actually solve problems post coding. And that's where I think AI's gonna do the most.
Mitchell, is this an unreasonable expectation for developers to write more secure code? I, we've talked about this in the past where our, you know, we want to shift left, but to Tracy's point, we give 'em all these tools and then they get inundated with alerts. And a lot of them were absent that day when they were supposed to be taking that cybersecurity elective.
And they don't know what those alerts mean, and they just ignore 'em and hope that, you know, something good happens on the back end. But how did we get where we are? Oh boy.
Developers love more alerts, Not, Um, well, to me, yes. Will this improve it? I think it will improve it.
And to Tracy's point, I think one way it will is, is we take the broad suite of data of code that goes into LLMs for doing software development. We can refine that LLM to do better jobs at writing secure code. It's much like we would say, well, we'll train our developers to write better code.
Well, with a, in theory, with an LLM, that should be a more reliable way to do that. I think, uh, security is so broad, it's difficult to train developers on all the ways of thinking about how you write more secure code. And that's where SaaS did das and, and other things come into play.
Um, My, my problem with it though, is that's just one place in the, um, software supply chain where security, where we have to address security for dev DevSecOps and developers, developers writing unsecured code is part, part of it. But you've got a lot of code coming into developers didn't write. You have a lot of things that you're integrating with.
You have the stack of software it's running on that. All of that could have security vulnerabilities. It could be the cloud infrastructure that's just being deployed onto.
So it's, it's one drop in the bucket, I think, of the security air things that we need to do, and anything we do to improve that part of it is a good thing. And I wanna say that I feel like the developers are getting, um, a lot put on their plate. Mm-Hmm.
Uh, and in most organizations, uh, it's true. Most of the developers that they're becoming the entry level positions, um, especially with, uh, you know, generating code. It's gonna even be more so and more, uh, senior developers are gonna be off doing other things.
Uh, so I, I really do believe that it's gonna be hard to, to train our way out of this problem. I don't believe we can either train or scan our way out of this problem at that first step at when a, a piece of code gets committed to a repo. So I really do feel that the, the, the solution is gonna be an auto in better automated tools in managing the pipeline and catching things, and using AI to really predict vulnerabilities and not put it on the developer's shoulders to say, Hey, that's string copy function you use is using some library that has a transitive dependency that now has a vulnerability.
There's no way that they're gonna know that it's, it's almost unfair for them to be asked to, to try to know all of that all the time. I totally Agree. You know, I I I think going back to the survey reference then here, and you look at that and you asked, well, two thirds didn't think it, it, it's not that two thirds didn't think it's gonna improve security.
I, I think there's some people who just, I, I think when you ask developers about AI improving the security of code, it's not just about the, they don't think of it as just about the code, their writing being insecure. They're looking at the totality of application security, not just as it relates to them. Right.
And I think Mitchell touched on it, and Tracy touched on it a little. There's more to application security than the, than the developer coding the code. There is SAS and das and, and software composition analysis, SCA scan, and, you know, all of these things, AppSec, there's, there's many facets of asset, uh, uh, many facets of AppSec that AI can interact with and make it better for developers and make it more importantly, better to have, you know, more secure code, more secure applications.
And so I do think that AI will overall improve application security without hopefully putting more burden on the developers. I think the developers, no one sets out developing insecure code. However, I just also think that we need to be realistic about how AI can be used to thwart application security.
Right. And I, and it's almost for every good that it could do, there's a corresponding potential pitfall there too. So, So it's a, it's a game of whack-a-mole.
It really is, especially right now. Mm-Hmm. You know, and just like in qa, you can't, oftentimes you can catch a lot, but you, uh, but you can't always QA your way out of, of bugs and production.
You can catch some, but there's, things are gonna get through. Well, is This a moment in time though? And Tracy, I think you touched on it lightly, but, so today, the LLM is trained on pretty much code pulled from across the web written by people who were imperfect.
So the code is imperfect, and it probably has Vulnerability In it as well. But is the next generation of these things gonna be an LLM that's been trained using code that's been vetted? So we'll get better outputs on the other side of this, and maybe developers will trust it more.
Well, and that was what I was saying, Mike, is that when you're getting code out of an LLM, there's just from across the internet, you get what you get as we train those models to be more, you know, to generate better quality code or be, or more secure code or whatever things we do to, you know, up the game. The good thing about that is not only does it do a better job of it, it does it consistently. You know, you don't have to train the next developer on secure code or this esoteric thing to watch out for.
Um, that's built into the model. So I think that is where the promise of AI is, is building better models at writing secure code, and that being something that will consistently do that for us, not just one point in time. And none of that's gonna ever stop another XE backdoor from happening.
No. That's just the reality of it. And if you looked at the, the, um, the process that that individual went through to get that in that code, he, he planned it for a while.
It was, you know, he, he worked at it, he worked at it to build trust and get, get his pull requests accepted. So, uh, he, he, again, it's a game of whack-a-mole. And I, I do believe that AI will help.
Uh, I think where AI is gonna be the best is, is in remediating. We don't need to remediate manually. And that's where I think AI is gonna provide the biggest, uh, it's, it's the chaos engineering theory, right?
It's not about trying to stop. Well, that is a good, that, you know, that is a good guardrail to prevent these things from coming into our supply chain. But once they're in that supply chain and we don't know about it, how do we respond as quickly as possible?
And that will be our best defense. Fast remediation. And you know, I, I always say we need a FEMA response.
We need to be able to organize a FEMA response. We need to know and be able to communicate to, uh, organizations when there is a, a vulnerability that everybody should know about it. And how do we get that information out and how do they remediate as quickly as possible?
So, and then we can ask later how it got there. Huh? You're singing my tune.
Yeah. Responses. That's where is is important.
Yeah. Doing it quickly. Yeah, Absolutely.
I always tend to look at things when I flip them over and I scratch my head around that, um, sabotage of that, um, module because there was probably a hundred other ways to compromise that entire environment that was a lot easier. And yet for some reason, you know, he spent the better part of months, maybe even a year or more infiltrating into that project and then injecting this malware in three years. Yeah.
Does this mean that maybe we're getting better at application security? Because certainly the bar to achieve what he is needed to achieve is a lot was higher than it used to be. I mean, kind of used to be, I would just kinda steal, steal your credentials and inject some code and go home from, you know, be done by lunch.
Well, first a lot of that trust building was through sock cup, but email accounts and automation, it wasn't like, you know, it was person to person building all that trust relationship. Um, the other is, that's one data point. There are others that this has happened to.
So that same person could have been doing this across 25 projects, not just one. And that's the one that, uh, 'cause he targeted it. 'cause it was something that was in the Linux Journal.
It's gonna get wide distribution. If it pays off, it's a good payday. Right.
So I think that's, it's, it's a model of attacking open source software projects, an instance of that. I think there's a lot more. And that's what Ryan, I think that's the one we found, right?
I mean, That's, yeah. This is, this is Like joy inter Yeah, I know. Well, you know, infiltration like that is, you know, standard espionage fair, right?
From a John LeClaire novel or something. Sleeper cell, right? Yeah.
And sleeper cells. I, I think this is, when you think about it, yes, it takes time. It's a low and slow kind of attack maybe, right.
Versus what you're talking about. But it's also not a very sophisticated, right. You don't need to, you know, crack passwords or, or root force things.
You just, you know, you show up and you, and you participate or you pretend to or whatever. And it's a low and slow way in until you get to a position of trust. And then boom.
And, and like I said, I think this is the one we found. 9, we've talked about this in the last gang. 9 million open source projects out there.
How many of them have been infiltrated this way? Mm-Hmm. I think it's the new Red menace I have here in my hand.
The paper. Um, Well, let me ask Tracy. Are we moving from the, uh, I used to call it the smash and grab era of cybersecurity breaches.
And these are gonna be more to his point, you know, slow burns. Well, that, Uh, I don't think we've left the, the, i i I think that we're, we're, we're straddling both worlds right now. But, you know, we, we talk about finding all these vulnerabilities.
We're just starting to look for them. So now we're reporting all these vulnerabilities, right? So we're, we're just now starting to touch it.
We've barely put our toe in the water, in my opinion, in terms of really addressing it. Um, this has always been there. Exactly.
I was just gonna say advanced threat prevention, right? We hit this in security. Same 18.
You've been Around for a while now. This is the low and slow method, right? This is what they do.
It's not the 50,000 bot hits that you got in 10 minutes. It's low and slow across weeks, days, weeks, months before the actual break in occurs. You don't notice it.
'cause the time is so spread out. Yeah. You don't see the events are Connected.
This is, to me, that's exactly what it is. Anyway. We need That ex that, that XY One more.
One that xy backdoor of vulnerability to though it was a lot easier than getting, trying to, you know, get past pen testing. Yeah, No, that's what, that was Much easier. Yeah.
It's a low and slow technique that will bypass a lot of the smash and grab defenses that we have. All Right. I got fingers and toes crossed application.
Security's gonna be better a year from now. It will be, but so will the be so will They. Yeah.
So will be, and that's, that's the, that's the nature of this beast. I've lived here for 20 something years and it, I don't know what changes fundamentally. Anyway, we're gonna take a break here on the gang.
We're gonna be back with more AI stuff. Is Nvidia trying to solve the GPU shortage? Did they have an incentive to Let's find out.
All right, and we're back. So last week, Nvidia confirmed that they were acquiring an outfit call run ai. I don't know how else to do run semicolon AI or whatever it is.
But, um, at this core, this is a platform that runs on top of Kubernetes and its workflow orchestration. And it, it's designed to help you maximize the utilization of the underlying GPUs. Most of those GPUs are currently being used to train the AI models.
And they're scarce and hard to find, and they're expensive. So, um, it's kind of surprising to see Nvidia buy something that makes it more efficient in the first place to use those GPUs. 'cause it's not clear to me that that's necessarily in their best interest.
But I guess keeping customers happy is a good thing. But it also seems to me, and I'll start with you 'cause I know we were talking to some of our friends at Futurum about this, but, um, our GPU's just gonna wind up being used to train the AI model, and we're gonna use other processors that are less expensive, easier to get to run the inference engines wherever we need to run 'em. And there's gonna be a, a, a split here, Or maybe there'll be something better than GP used to train on as well.
I mean, here, you know, my, my first, I, I gotta tell you how cynical I've become. My first reaction to this given, given the, uh, goings on at the criminal trial in New York City, was, was this a national Enquirer, what do they call it? Hut and kill or, oh Yeah.
You know what? Catch and kill. Catch and kill.
Are they, are they buying this company to kind of kosh it so that people need more gps? Now? Let's not be that cynical.
They're really gonna sell these things. Um, They promise to leave it as a standalone end, right? Yeah.
They, the road to perdition is paved promises. But, um, but you know, at the end of the day, in my mind, this is this really gonna mitigate the GPU shortage? Hell no.
Stop. Come on. This is, I mean, what are they looking for here?
Metal or just a pint on, um, this, this, this is not mitigating the GPU shortage. Yeah, I just, you know, yesterday I also saw a picture of a, a Jensen, is it Wong? Right?
Is this CEO with, uh, Sam Altman delivery to open ai, the latest, greatest, you know, uh, Nvidia super package with an inscription, you know, it it for, for the good of mankind or something like that. And I was, you know, the recipe for, man, I was thinking of that old Twilight Zone. Uh, Again, 10 people know what you're talking about.
I know It's people like Sun Green, But they among 10 people. But, um, You know, but that, but that's the way I see this. I mean, the only thing that's gonna mitigate the GPU shortage is something that really turns on g you know, GPU production, which you, you don't turn up foundries in six months, right.
In fabs. So, you know, that's, that's a while out. Or we come up with a better, a better mouse trap than GP used to, to do this job.
I don't think, you know, putting AI workloads on Kubernetes more efficiently than it is now moves the needle and all. So, you know, but, and again, I'm being a survey today, so you're Not gonna short Nvidia, is that what you're saying? I'm not shorting it.
Well, now's a buying time there. The, the stock has taken a huge hit. Mm-Hmm.
Or I haven't seen it the last couple days, but it, it took a big hit. But, but here's the other thing. This is the kind of, this is, this is AI click bait as far as I'm concerned.
This is the kind of stuff that's sucking the oxygen out of our tech world, tech news world, um, where I, you know, let's talk about something other than, yeah, let's talk about making Kubernetes more efficient, period, right? Let's talk about, you know, how we can do more with Kubernetes and, and get more people using it. But instead, if you put a little AI news on it, we're all running to it.
We Were just at CubeCon and all anybody talks about was how to make Kubernetes more efficient to run what? Ai Yeah, no, I, you know, it, it's, it's the world we're living in today and, you know, but this too shall pass. How do You think, I'm gonna take an even deeper cynical view, Alan, which is, you could look at this as a way to sell more chips, not to address the shortage problem.
So if you're, you know, we, we know Kubernetes well, right? This is, you know, Kubernetes for ai, AI training models, et cetera. So if you, you're more efficient, better, you're better at distributing those workloads across whatever setters instead of, I can put my own stuff here.
Well, guess what? You're gonna use a lot more CPUs and a lot more locations edge, you know, at the core, all that stuff. So you could look at this as a way of, no, I want, uh, Nvidia chips everywhere.
So my, my work, my orchestrator will run on all that stuff. Yeah. If I could find them, I would agree.
But I think that's the issue is they're just generally a shortage. I love, Yeah, I, I, it was a re it was a, it was kind of a head scratcher for me when, um, I saw that article come through, uh, because I don't know if run ai, like a, Alan says it has AI in it, so let's, let's, let's suck all the oxygen out the air. But I don't, you know, I didn't, I've never looked at that, uh, solution, but I really dunno how much AI is in it.
Um, Kubernetes can be, uh, a little hard to manage as complex. They tried to make it simple. Microsoft wrote a book called fpi Goes to the Zoo to try to break out what, how Kubernetes actually works.
But to be able to spin up, um, you know, uh, more space and get more GPUs out of the process. I don't know if everybody's achieved that. And tools like run ai, uh, could, could be useful.
However, I think open source communities and people are already writing them themselves. Uh, so I, you know, 700 million was a lot for that tool. That's, that's what I was thinking at the time.
Uh, because I, I don't know if, um, I don't really see the market for it, but I could totally be wrong. Um, because maybe people would prefer to buy a tool that would help them, uh, spin up, uh, you know, more clusters or more namespace and build, you know, build out more GPUs. But as, uh, you have all already said, it's just gonna mean that it's gonna have to have more chips and bigger processing.
So I always like to talk about quantum computing. If we wanna really, if we really wanna fix the problem, it's not gonna be from run ai. And it's, it's, it's gonna be, you know, IBM's work in, in the quantum space.
And eventually I believe that's where we're gonna go to. So, and I, you know, I'm, I'm surprised that the Linux Foundation hasn't, uh, started a project that's similar to run ai, for example, so that, you know, that that kind of processing, I believe will be, you know, solved in other ways. Yeah.
So I, I, I was surprised it may Be that the, uh, TOC for Kubernetes finally gets around to solving this run. The AI workloads better issue themselves as a project. But, but let me ask you, Tracy, is it getting harder to write software?
Because it's like, you know, there's so many processors in the zoo today. There's GPUs and X 86 and Arms and dpu, and it's not like the old days where I just had a compiler in the X 86 and the way I went. It seems like it's getting more challenging.
I think the problem is not in, it's harder to write software, uh, in a microservices, uh, environment. Things become more complex. And there is an association to usage of a particular service that you, that there's an operational side of that software.
So we have developers writing, you know, APIs and functions, and we have operation teams trying to observe how they're being consumed and what we have to do to spin them up. And if we think about the, in the AI world, we're think, if you think about AI agents, they're gonna be highly, uh, fragmented running, uh, in all kinds of locations. Uh, which is gonna require more tooling like run AI to help spin up, um, more, uh, resources and better manage resources so that we, we can better consume GPUs without buying more computing power.
Uh, so I, I, you know, I think that's where the problem is. And it's, it's a, it's a problem between dev and ops, uh, and better management of Kubernetes itself and understanding how these functions are working and who's consuming 'em and where they're at, and what versions are running across different environments and who's connecting to them. It's com it's very complex.
It really is. And, but the development side has gotten a lot easier. A lot easier with, with Kubernetes.
You can write in your own language. You don't have to, you know, if you wanna write and go write and go, you wanna write in Python, write in Python, um, you can write one little function and everybody else can consume it. Uh, so there's a lot to be said about this new decoupled architecture from the ease of coding.
But boy does it get complicated on the operation side. Well, Mitchell, do you think that the management of the inference engines is gonna shift over to DevOps? 'cause today, right, it sits within these kinda ml ops data science teams.
And I feel like the thing is gonna split where the training will be left to the data science folks, but the, the implementation is gonna be just part of your standard DevOps workflow. Uh, I, I've talked about this before. It's, I think it behooves us to make it part of the workflow, one of the workflow work streams that are going on in a DevOps process.
Um, and it'll have its own kind of gravity of how frequently and what comes with it. 'cause it's got data and training that go with models and all that. But it can't be this thing over on the side because it may, it may help do the AI work, but the interdependencies between applications and systems that are using those functions, you have to be able to orate interdependent releases or, or components of code.
So the best thing, and actually wrote a paper for one of the container vendors around containerizing and starting your, your AI work in the AI expert teams, you know, and the data scientists teams so that they can eventually become part of that workflow. So I, I don't think it just kind of disappears in the workflow. I think it's got its own unique characteristics, but it's part of the workflow, um, across the DevOps pipeline.
Fact, DevOps. DevOps, I like ending on DevOps. We're gonna take a break on Textron, on Textron Gang today.
We'll be back with some, is it a Rolling Stone song? No, it's not. But we'll be back.
I'm Bonnie Schneider, sustainability contributor to the Techstrong Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong Research. And we're back with our third and final segment. The folks at Salesforce were in New York last week, and they were touting all their new AI capabilities, but buried in, there was a survey they put out that noted that more than half the folks that they talked to who were knowledge workers said they couldn't get AI to do what they wanted.
They were frustrated and it was just they couldn't get the outputs. It was, the prompts are too hard to master. And so, I know you're a big AI advocate, but, you know, are we just doing that and we're just throwing prompts at people and saying, go figure it out?
Or do we need to kind of think this through a little bit better? Before I answer that though, I just wanna call out the name of, of this here. You can't get what you AI want, right?
You can't always get what AI wants, right? To paraphrase M**k. But you do get what you need.
And, uh, you know, shout out to Jagger and, and, uh, and, uh, M**k Jagger, who's my favorite? Keith Richard. Keith.
Keith Richards. Ja geez. Um, and Prevagen is now a sponsor for the show.
Yes. Well, I had a little mental block about Keith Richards. Okay.
Um, wouldn't been the first time. But anyway, so, so, you know, I talk to people about AI all the time, and some people are knowledge workers as I think you called them. Mm-Hmm.
And, and some people are just, you know, not knowledge workers. And that kind of, I guess that's a good way of looking at the world, those who are and those who aren't. But the biggest thing I think today is for most people, AI still means that chat GPT product, right?
They, they're not using the copilot aspect that's integrated into, let's say, slack now and everything. I mean, we've all seen these in our applications. There's always this little blue button, get AI or use ai or what would AI do or whatever.
And you click that. I don't know how many people, I mean I do 'cause I like to see what it comes up with, but for most people, it's still, they're sitting at a chat bot prompt. And what they get is a direct result of what prompt they put in.
And 90% of people don't know how to prompt. Well that, and that's really the issue. I, I agree with the survey there.
The, the, the you, the AI you get is the AI you put in the prompt. And, and we need to train people. 'cause I mean, in my own personal journey, it's made a huge difference.
You know, we did that hackathon that we have on Textron TV with the operationalizing ai, talking to those guys, learning about how to do prompt. You wanna call it prompt engineering. I don't know if it rises to that level, but, um, but learning how to do a proper prompt makes all the difference in the world.
I, I, you know, and again, I think, uh, I think young people who are, will be, you know, gen AI natives are going to know it intuitively how to do great prompts. I think old people like us, we, we need to learn how to do prompts if we're gonna really get out of AI what we want, Tracy, do we need to go to pro camp this summer? Oh, yes.
I agree with everything that Alex is saying. I know from my own experience, I, you know, I'll use Chachi pt, and it was like, well, that was definitely not the right question. What is the right question to ask so I can get the, the correct information back?
But, you know, I wanna step back for a minute. We do need to go to prom cam. I mean, that is, that's for sure.
But we're, the thing about the, the Salesforce, Salesforce has an a massive amount of data. And these companies who have been gathering data for years and years and years, just like, just like, uh, GitHub, they have a big advantage, um, over everybody else in terms of, uh, being able to execute and apply AI in different kinds of situations. Certainly when we get to a point where Salesforce can say, Hey, based on the people who are your, your contacts, we know and deliver this to me in a easy way.
Or if I could just simply do a prompt in Salesforce and ask who's searching for these kinds of things and do the prompt correctly, and it gives me back a nice list of the correct leads that is gonna, that's gonna save me so much time. But it's because they have the data and it's the data that I, I always get excited about who's got, who's got big data and what can they do with it. And Salesforce has big data.
So their Slack ai, if they're, you know, and of course Slack and Discord, that has a ton of data. Um, anytime that somebody's responding and, and complaining, let's say about a product, or there's common problems that are, are coming across through the Slack, slack channel, you are getting a ton of information about your community. And I find that a, an extremely, um, useful, uh, set of data points that I've not been able to see before.
So I, I applaud Salesforce and where they're going with what they're doing, but we all need to get better at understanding how to ask the right questions. No doubt, Mitchell, you run our IT environment. And one of the things about Slack AI is that it will connect not just to the Salesforce data, but it connects to Google and it connects to LinkedIn.
But what it doesn't connect to surprisingly is other CRMs, at least not without some additional programming help. Um, do you think as AI evolves that we're gonna change out our platforms because of the capabilities of a given prompt engine? Or are we just gonna wait for all this stuff to become, you know, it's, everybody's gonna have a prompt AI capability, so we don't need to switch out platforms?
Well, you're, you're pointing out a really good problem, which is, I'm, I'm overrun with copilots and, and chat bots that are ai, right? Every damn tool that, that we use, I get an email saying, we know have AI for an extra $10 a user, which is what Slacks prices will add AI to it. The problem is, you don't know what you'll get for it until you go out and experiment and use it.
And some are gonna be better than others. So I feel like we're in the land of, you know, I have one hammer and, and everybody selling nails and that I don't need everybody to sell me nails. I just need some better solutions.
So I think the, the vendors that are really good at fine tuning the use cases and the value that you get from using it, not just connecting it so you can query all this other crap, um, you know, I don't need that. I've got enough things to query and yes, I need to go to prompt camp too. Uh, so I think we we're, we're in this era where it's the low hanging fruit of AI is just added to your product and connect it to whatever you can connect it to.
And I'm not minimizing of it. It's, it's a good start, but that's not the answer. No.
And then that's the promise. I'm sorry. Go ahead, Tracy.
The part of the problem is when it, when it comes to, even in investors, they only wanna look at AI products. They're, you know, that's the shiny new object. And it's the, you could have a great product and a great pitch.
Uh, if you don't have something about AI in it, they don't even wanna hear it. So everybody's running to be, you know, relevant. And so they're adding, uh, you know, they're trying to add AI to their products.
I just thought, I just upgraded something on WordPress and, um, one of the plugins wanted me to upgrade for $10 a month to their AI version. It was like, what does it do? Why do I need it?
Do I really need to spend $120 a month for your AI version? I don't know. Why Are you gonna be able to charge extra for ai?
And I'm asking the question. 'cause a lot of times I bought the software in the first place. I'm only getting 20% of the functionality out of it.
'cause it's too hard to use. So isn it not incumbent upon the vendor to gimme a tool to get the rest of the value that I already paid for. Hey, having AI integrated into your products gonna is table stake.
There already is table stakes. If you don't have an AI story about your product, go home. That's the fact that we're sitting here for 45 minutes and all we're talking about is ai.
And we do this three days a week and we're supposed to talk about everything is proof in the pudding. If you don't have an AI story, go home. And, and if you don't have AI integrated into whether it's your word process or whatever application, you're not gonna be able to charge for that.
It's expected. Mm-Hmm. Yeah.
It's like, would you pay for the next spell checker now? No, I wouldn't. Yeah, but you used to be able to buy a spellcheckers long, long time ago.
Right? It's gonna be a, it's a feature. It's not a product.
Not in in that level anyway. No, But there are these massive data centers out there that are processing all these prompts and running all these, uh, context windows. So how do we pay for that, Tracy?
Yeah. I don't know, but it is the data that matters. Yeah.
SKI ask, You know, let's ask you a prompt for that. ai, how do we pay for you? Yeah.
Because data can be expensive. By the way, we've all been to prompt camp already. It's called Google.
We know how to craft prompts To get What out of Google. They're Just One. This is the new kind of prompt I was sitting here thinking while we were talking, what a great little thing we should do in the winter.
Bring people down here to South Florida for prompt camp. Mm-Hmm, right? Combine it with some fun in the sun, some light how to do prompts, right?
And we, you know, we, we'd have like a group kind of thing. This could be the next great business. Yeah.
I went to Prompt Kemp and Boca and I go, I got, was this Textron t-shirt? Yeah. We, Maybe we could combine it with like ozempic or wavy or something and not whose weight while learning the prompt.
I don't know. I think though, you know, the machines are teaching us how to, to, to think, right? Because we're structuring things to get more interesting information outta the machines.
And we're, the sign of intelligence they say is not so much how, you know, as much as it is how to frame the question. And I think that gen AI is teaching us all, or will teach us all how to frame the questions better and as did search for that matter. So maybe we're all about to learn something that we didn't know.
It's interesting. I I think a lot of people, unfortunately, especially not knowledge workers, they, they still think of it as some like parla trick and they're not taking the time to do prompts better because they don't know that's what they need to do. Um, as I said, as kids come up, you'll, you'll see that become a, a real thing.
Anyway, though, we're outta time. We, we've been going on here. Tracy, I want to thank you for joining us.
As always. It's a pleasure to have you on Mitchell. You too.
Talk, we'll talk in a little bit. Uh, Mike, thank you most of all. Hey, thank you guys out there for joining us with Text and Gang.
We've been doing this now over a month and, uh, it's, it's, it's a blast. We love doing it. But you know what, we don't hear a lot in terms of what you guys would like to hear and see on, on the gang.
com with any suggestions, comments, we'd love to hear them. Also, we will be expanding the gang. We're on a gang recruitment kick and we're gonna join in with some of our future, uh, analysts joining the gang and other personalities.
So stay tuned. We'll keep it fresh. We'll try to do a, as much AI as you can take, but more.
And, uh, that's it. Have a great week here. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security bloggers network.