Techstrong Gang – July 26, 2024
Mike, Mitch and Chris Blask examine the degree to which CrowdStrike will be able to recover from the Windows outage debacle. Then, the gang takes a look at the privacy implications of a Google decision to not eliminate cookies and a decision by Oracle to cough up $115 million to settle a digital privacy lawsuit.
Transcript
Hello, and welcome to Textron Gang. I'm your host, Mike Baard. Today we're gonna be talking about CrowdStrike and gift cards.
Cookies, apparently don't crumble, and well, I receive violations. Might cost you $115 million. You're watching Textron Gang, and we'll be back in a minute.
Alright, folks, welcome back. Our guest today are Chris Blask, who is still hiding out somewhere north of the border, but it's actually not the government that he's hiding from. It's the heat wave.
Chris, welcome to show. Good to see you, Mike. Good to see you.
And of course, we have Mitch Ashley, who is not necessarily hiding out in Denver, but he's in his usual location. Mitch, how you doing? I'm, uh, in my perch high above Denver and the Rocky, the Rockies of the Colorado.
So, And, and I of course am baking in Florida one more time. So here we go. That's a song, isn't it?
Baking in Florida. One more time. It should be, I don't know who sang it, but we'll see what happens.
Jimmy Buffett, I think. Alright, I wanna jump in. It's been a week now since this whole CrowdStrike thing blew up in our faces.
And I don't know if you guys are watching this, but apparently the CrowdStrike's handing out $10 gift cards to everybody, they're troubles. I'm not quite sure if that qualifies as insult injury, but it's debatable at the very least. We'll see how it goes.
But Chris, what's your sense of, you know, looking back at this now for the past week, how much trouble is CrowdStrike really in? Because we've seen, uh, they were kind enough to be transparent about what it went wrong, but, um, well, people have faith in CrowdStrike going forward, or what do you think? Well, I, I think we can look at, you know, our advice as security people to organizations writ large, right?
It, it's, you know, in this case it's one of us. It's one of one of our companies, you know, it's the cybersecurity company that's the problem this time. But they seem to be, to be doing the right things.
You know, we look at the grand breaches of history, most of those companies are still here, and they recovered and they moved on. So I think generally speaking, yeah, they'll, they'll make it through this, but it's a, it's not a happy day, Mitch. What should they be doing?
I, I'm not quite clear to me that $10 gift card's gonna do it, but, um, I think, you know, I think they should, uh, be sending, uh, a weekend in Cancun to every system, system, admin, security engineer, or wherever your choice of island you want to go to. That's what they should be sending. Or just have one massive cruise or something, a big party for people.
Um, you know, CrowdStrike isn't a consumer brand, right? It's a security brand in, in our industry, it's not even, not even well known to business people, but security people know about it. CISO know about it.
Maybe the organization knows more about it, or they have experienced a breach, or CrowdStrike has been part of investigating something. So, you know, every, every, it just shows you, I think the lesson is this can happen to anybody. And, and if it can happen, CrowdStrike can, can happen to you in your, in your software process and how you deploy software because the fact of the matter errors happen.
We do everything we can to improve quality and fix 'em. And, you know, if they were perfect, we wouldn't need to test 'em anymore. But we have, we have errors, they just happen.
So, you know, it's interesting, uh, I did a, uh, a webinar yesterday talking about embedded data analytics in products. And one of the purposes of that is to have telemetry about performance and availability and how products are performing. And I immediately thought of, hmm, you know, of the recommendations.
Maybe that's another one for CrowdStrike, is, you know, really think about how you get better telemetry on your software performing in organizations. Maybe they have that already. I'm not, uh, in embedded that much into CrowdStrike's products, but, um, provided, you know, you can address the privacy concerns, I think that would be really helpful.
I'm pretty sure that when we start doing, uh, DevOps case studies in the years ahead, that CrowdStrike will be a primary example of what not to do. Um, but Chris, you know, to Mitch's point a week ago, hardly anybody knew who CrowdStrike was. So do you think, uh, I don't know, a month from now, executives are gonna be asking security people who are we using for security?
Or is it just gonna go back to being something that, you know, only the security people care about? Well, y you know, history doesn't repeat itself, but it does rhyme, right? You know, so don't expect, you know, uh, you know, c level attention to maintain its excitement level for, for security.
Um, it'll come back down, but it'll be at a different level and different shape, right? You know, with the, you know, we're on this ratcheting course moving forward, right? And there's a lot to be said about this particular, uh, incident.
You know, I, I can say some, I'm sure, Mitch, you know, you have lots of points you made, you made some already and, and that's good, you know, for us to all look at. But, uh, I think the real lesson is that we still have systems, these global systems, not individual components like CrowdStrike, CrowdStrike or Microsoft or whoever, but airline systems, global, global transportation systems that don't have a lot of redundancy, right? That a single point of failure, a single mistake somewhere, uh, can bring the whole thing down.
And we're not going to avoid single mistakes ever, right? But we will mature out of having systems that, you know, if one company somewhere makes one mistake, you know, large, you know, these, this scale of ramifications is on rule. As a saying that goes something about the her but the grace of God go, I, do you think that, uh, other companies are gonna learn from this CrowdStrike incident?
Or are they kind of just watching it much like a traffic accident, but they're not actually thinking that maybe they need to improve their DevOps workflows? Well, every, every time I write something about CrowdStrike's outage, I, I think of that he or she cast the first stone, you know, that just like, oh, I'm not being guilty of anything, of course, you know, do what I say, not what I do. But, um, you know, I, I think, uh, for all, for all of us, if we thought, or if we had an experiences that said these issues are systemic at CrowdStrike, and there's all these things that, you know, fundamentally have to be fixed in something about how they work a process, how they deliver software, et cetera, um, then I think the market, I think the security that people who buy these products and services would elevate the security of it much more seriously.
Now, if we had another outage in a month, guess what? It, it's, it's moving on the heap right now. You're really, you can't justify to the business.
I'm gonna give them three strikes, um, you know, and by the way, cost us millions of dollars. You know, it's just a little strike, that's all. So, it, it definitely gets the attention pun.
Is there, is there a pun intended in that? I just wonder? Yeah, you saw what I did there.
I realized I did that after I said it, but, you know, I'll take credit, but I'm bumped to Chris's rim shot. Thank you, Chris. Um, anyway, I have no idea where I was going with that, but no, if, if this is systemic, it's a different issue.
If it's, uh, okay, even, even though it's tremendously bad if it's a one time event. Either way we all can learn from this because we can be guilty on a small scale or on a big scale in our own worlds of making these kinds of mistakes. Chris, is there any irony in this?
And I asked the question because, you know, for so long now we've been security people have been telling developers that you need to get your supply chain in order and you need to, you know, make sure your software is secure. And yet one of the biggest instances of somebody not following the rules is a security company. Yeah.
I mean, you know, we all love irony, right? You know, and when it happens to us, you, if, if we have good grace, you know, we can grin and take it because yes. You know, at the same time, you know, and this is a lesson for everyone, I, I suppose is the security companies are just companies.
You know, we, I, you know, I, you know, uh, vice president one out there right now, and, and they have the same struggles as everyone else. And so we, this is why, this is why, you know, the internet works. This is why open source works, why freedom of speech and all this good stuff works is 'cause there's communities, there's communities of companies, right?
And to my earlier point, you know, as a critical infrastructure consumer, you know, as much as possible I should be building redundancy in, so I'm not, uh, counting on any one particular company. Not to make any mistakes whatsoever, but the point is that even as a security company, we have to use the tools available. And there are not yet, um, the, you know, you mentioned supply chain where I spent a great deal of my time these days, we're working really hard on making the tools and the structure so you can really see across this entire, you know, in the, you know, in the department of Homeland security supply chain working groups that I'm part of every week, um, CrowdStrike is a com topic of conversation.
And I said the same thing there that I, that I say here, that what we need, you know, our systems, so that across the supply chain, you can see everything quick enough to do things about it. Those don't exist yet. So can any one company, you know, no matter, you know, CrowdStrike's a big security company, they have the resources, but the tools aren't there for us, for them any more than they are for anybody else.
Not really, not yet yet. Mm-Hmm, Mitch, you know, whenever there's an issue like this, there's always a call for accountability and somebody wants to, you know, put somebody's head on the proverbial block. But, you know, as you think about it a little bit, maybe the folks at CrowdStrike who are involved in this are probably know more now about DevSecOps workflows than anybody out there.
So they learned it the hard way, obviously. But, um, you know, we have this principle of empathy in DevOps. I mean, you know, should we just take a step back and give everybody a break?
Well, we're, we're, I think in our culture, our country, we are a society of second chances. We do give people another shot at it. And, uh, whether that's company and products, you know, there's one time where, you know, I loved Apple and then I hated Apple, and now I dunno if I love it, but I in the ecosystem, again, you know, it certainly, if you thought CrowdStrike was bullheaded and wasn't learning from this experience, then you'd really question like, okay, that's not a good bet long term.
Or maybe even short term, given the level of transparency and what they've said in their remediation of what, they're not only fixing the problem, but they came out with a, their preliminary incident, uh, report and talking about the things that they were gonna change. And I was very happy to see, yes, we're gonna change these quality processes, reviewing it, uh, looking for bugs in their, their validator tools, things like that. Now, that's one of the things I think also kind of a reliance on your own technology to validate your, your stuff and, uh, the kind of the, the tool that one of the bugs was in the testing tool, validation tool.
So it, I I certainly believe a company like CrowdStrike, um, given their credibility in the security space is learning from this. Now, are they gonna be the leader in DevOps and DevSecOps? I don't know that that's the case.
Boy, it'd be a great position for them to take if they really wanna say, let's turn this tragedy into something that hope helps the whole industry. We're gonna sh we're gonna kind of do an open seminar on how you really elevate, um, what you're doing in a DevSecOps world, something like that. Talk about a, a benefit out of a real tragedy.
Guess some, the security people who are impacted by this and all the organizations impacted, are they in a forgiving mood by now? Or what's, what's this, what's the mood? Oh, I think so.
And, and as I look across our topics, uh, for today, you know, I think it's, uh, it's a good day for me, you know, 'cause, you know, I like to talk about the maturity of things, you know, let's set our expectations. If we just came up with something, you know, and everybody adopts it, you know, we shouldn't be surprised, you know, that it falls over from time to time, right? And we are sort of halfway, we're somewhere in the middle of developing the internet and cybersecurity and so forth, and some of those artifacts, you know, to your point, yeah.
If, if you've been in this industry as an operator to your, to your point exactly for a period of time and you can't gr a little bit and forgive, then you haven't learned the lesson. So I, I think they'll, I think, you know, we as a community will be fine. You know, a lot of our friends, you know, the CEO of, you know, over there and I, uh, we all know each other, right?
You, and we're not, we're not in a really aggressive mood, I don't think, Mitch, do you, do you disagree or I don't, people seem really cranky, or are we all just sort of shrugging and smiling? Well, I, I can't speak for customers per se. I mean, if when you have a real bottom line financial impact, guess what?
It gets screw big scrutiny and big attention. Like, so if you're gonna stay with this vendor, whoever it is, how are you assuring me this isn't gonna happen again? And that's a tough question to answer when you're not.
It's not your stuff. It's from a third party. Um, and there's risks in switching, you know, and it's not an easy flip the switch, oh, this just down to a different agent and poof, we're done.
No, it's not that. It's simple. Um, so it's a tough question to answer.
I think that's the, you know, post of the ungodly hours people have had to spend to get servers to reboot and, and not be corrupted anymore. Um, in addition to that, I think that's where the hard conversations are happening between the cso, the C-I-O-C-T-O, and the rest of the executive, maybe even the board, to say, what are other companies doing? Are people flocking in a way?
What do they, well, if they're staying with, with CrowdStrike, why? And what are they doing for assurances? What do we need to do?
Those would be the questions I would be asking no matter what it was. If something caused causes kind of a financial damage to my company. Thank, Well, I think you're, your comment a minute ago about the way they've handled the transparency is sort of like the answer to vice question.
I think the reason, you know, they think I, the gestalt feel I get from our community is that, alright, we're watching, you know, and they're not messing up, they're owning it and so forth. And frankly, call out to, to the, the team at CrowdStrike. I think Mitch has the exact right idea.
Think about the cost, spend a million dollars, you know, have a big event for all the people who literally worked 72 hours over the weekend to get the world back. Right? Why not?
All right? Just one point about all those people who worked that hard and God bless them for doing it, but let's be fair, plenty of blame to go around. If I'm on the board, I'm asking those people, how is it we got so dependent on one company that could take down our entire IT environment?
So let's not all just start pointing fingers because, And where else do we have that dependency, right? Is there some other vendor that could do the same thing to us? Right, Exactly.
I think we're all learning, we're all learning some lessons the hard way. So, um, hopefully by this time next week we'll be past this conversation. As they say, new cycles come and go, and hopefully there won't be a second round of this, but cross your fingers, toes.
And, uh, in the meantime, we wish everybody involved. Best of luck and we hope that, uh, your next week is much better. All right, we'll be back in a minute.
All right, we're back. And we're talking about Google and cookies. Apparently Google at one point said they would eliminate cookies and that got all the folks who are concerned about privacy, very excited.
And then now it turns out Google saying, well, not so fast, we're not quite gonna get rid of these cookies. And that has all kinds of implications, not just for privacy, but I think security as well. And the folks at the Electronic Freedom Foundation are a little ticked off.
Chris, what's your take on cookies? I mean, I think we all take 'em for granted, and yet it seems like we should revisit this whole conversation. Well, you know, that, that's Security Boulevard, uh, article on this topic, you know, I think makes a really good point.
You know, Google's making 80% of their revenue through advertising the motivations, economic motivations widen up a certain way. And I think this, as I mentioned in the green room, I think this leads into our last topic. I think we're moving down a path where issues like this are commonly understood enough that, look, we, you know, I, I, I'm okay with advertising.
I'm okay not paying for things and letting people who wanna sell me things, advertise and uh, and cover the costs. Um, and if, you know, we have systems out there that mean the ads I see will be of things that I might even theoretically care about even better, right? And this is my point about where we are as, and this is not even the industry.
This is the world, this global population, all of our friends who are not IT people, not security people. There's a general shared understanding that that's, we're okay with that, however, you know, so now we're getting to that point where we can have the however conversation, and it's not just a, a bunch of, uh, you know, hardcore tech nerds like me, but it's everybody. It's the, it is the classic Thanksgiving, uh, dinner table.
So, yeah, I, I find this, and, you know, the, the issues I'm talking about, about the next SEC segment leading us down the path where we can have the kind of conversations we need to have, where it's not, oh, I don't want anybody looking at me whatsoever. Um, you know, the, you know, I'll throw it an old story, right? Early nineties, uh, uh, before the web had really caught on, was all sort of text and use that someone on a group was traveling from Toronto down to Florida and put a camera on their porch.
And there was this huge conversation about, you know, oh my God, how terrible it is, and privacy and whatnot. And I made the point then it's like, if you live in a small town, right? Walk out in your backyard on a Sunday in your RO before you're back inside your neighbors, they know about it at the barbershop.
And we accept that we're okay with that because that's familiar. So this cookies, you know, is a, is a great thing because everybody understands it to a certain extent. Most people don't really know what it means, but it's this common word that the entire population associates with this issue.
You know, where is my information? Who has it? Uh, because frankly, you know, the answers to that are not good.
You know, it's the motivations of organizations. Again, I've been a vendor. I'm, I'm one of the people to, to blame for this effectively.
'cause I make money by having my products and services and so forth succeed on the internet and having other people do. So. So my economic motivations, the organizations I work with, uh, don't necessarily lead themselves down that privacy, uh, rabbit hole.
So we haven't gotten the real public input, you know, 'cause the public hasn't really understood it well on that. So I think this is a great topic, right? Let's put, you know, everybody understands browsers.
Everybody knows about Google, everybody knows about Chrome, everybody knows about cookies. Let's put this on the dinner table and say, how comfortable are we with this really? And the answer is not much.
And it shouldn't be because we don't have the transparency. Nobody really knows what their information is. Mitch, do you think people are more aware of this?
And, and I asked the question 'cause it's almost, um, impossible these days to go to any website that doesn't pop up with a little thing that says, accept all cookies. And I think that's part of the EU essentially gets the credit for making people do that. And I, and I think people first, they look at it and it's kind of annoying, and then they click on it and they're like, okay, whatever.
But then after a while, you keep getting hit with this thing, and then you're like, well, what are these cookies? And, and then it becomes, you're aware that suddenly people are tracking what you're doing. And, you know, some folks I talked to are moving over to Duck, duck go.
And are we seeing a shift here in what browsers we might use because of cookies and tracking? You know, I don't know that it's that substantial Mike, but first thing I gotta say is, you know, I love me some Chris Blask, however, in the morning. So thank you Chris, for checking that off for me.
I always could have a conversation. You know, I've got a, I've got a sign on the front of our house that says, no soliciting and no banjos. And so far, only the no banjos part has worked.
No banjos have showed up at my house so far. So I'm just not a fan. Sorry, banjo players.
Um, I, I think cookies are the same thing to people. They're just like, I don't, why do I wanna deal with it? Only time I really care about it is when it starts doing things that make me uncomfortable.
Like, how did it know that I was looking at this, uh, dot card on, on, uh, TikTok and suddenly that's popping up in my email or in another application on, on, uh, a Amazon or something like that. So when it gets kind of the creepy factor, people get concerned about it. Like, I really don't want, you know, uh, you're reading my browsers or history, what are you doing?
Wanna know? I, I think that the, the thing here is it's hard, the lesson for me is, it's hard even for Google to change the momentum around an industry adopted standard, not small as standard of cookies. And they came up with the new scheme and basically people pushed back and said, you gotta be kidding.
You know, we're not gonna do this. Nobody else is gonna do this. This costs us a lot of money.
And yes, you're Google, but you know, we're gonna hold out until we see that this is a, a smart thing to do. So in place of that, they came up with a, they put it back on the end user. Wrong answer of, now you can, you know, in the browser, we'll let you manage cookies and what the hell are all those things for anyway?
How are end users gonna know what cookies they wanna have and don't wanna have? Because if you, you, if you look, there's so many things there that nobody's gonna recognize unless they're in advertising or, you know, the kind of browser and software space. So I think cookies are here forever.
Big, big C cookies. I love little c cookies with browsers. They're both here forever.
You know, I've changed my behavior and it, and it kind of goes this way. And maybe I'm the only one. So don't follow.
This is gospel. But you know, I am reluctant now to search for things on one-offs, right? Because I don't want this massive stream of content.
And I, you know, a simple example would be I'm a Yankees fan, so I'm not likely to search stuff for Red Sox. 'cause I just suddenly don't wanna stream of massive amount of web content about the Red Sox coming into my browser. And so it's kind of counterproductive with all these cookies.
'cause on now I'm thinking longer about what it is I might actually use Google for, because I know it's gonna manifest into everything, including all my social media feeds. Or at least it feels that way. And, um, so to a certain degree, Chris, has it become counterproductive?
It has, right? And this is, you know, it's either to blame the companies, right? But you have to think, you know, think this through.
You know, if you work for Google and it's a publicly traded company and you put in in place processes that lower shareholder value, you know, then you've got, you've got some splaining to do, right? There are retired people out there that invest in your company, expect you to maximize, you know, their investment in you. So they, the economic economic motive isn't just greed.
You know, there's a fiscal and, you know, uh, quite often a legal responsibility to, as an actor inside a corporation do what, uh, makes the most profit. So we need this public pushback. We need to get to this point where, yeah, the word creepy, how often does the word creepy come up in this context?
In every household, you know, around the world in the last 12 months? You know, is Mitch what you're saying? It's like, well, both of you, right?
You know this, we, we all have this creepy feeling that no matter what I do, I'm suddenly gonna get this massive flood. And, and this is the point for everybody out there who's not a, not a, a tech nerd. Look I am.
And I don't know because I can swear I'm just having conversations sitting here talking with my friend, and all of a sudden I start getting ads on my phone. Are the bloody microphones open? Are you really listening that much?
Is it because I have Alexia here? I don't know. And nobody knows.
And it's that lack of transparency that causes the dissatisfaction that makes us want to resolve this. You know, you're not the only one who's seeing that phenomenon where you feel like you're having an actual conversation with somebody and then all this stuff pops up on your machine. I know I've seen it.
My wife has remarked on it. Many of my friends have remarked on it. So, um, it's, I don't know what causes that, but, and maybe it's just 'cause we're all more aware of it and maybe it's not causation is correlation and all that other stuff.
But Mitch, do you think, uh, you know, things are getting a little weird? Well, privacy is much more of a topic than it has been for the general users and consumers. Um, I still think all of us give away too much permission because we just click on the yellows and move forward, or click on the yell, allow all cookies and move forward, right?
It's, it's, do we wanna spend our lives detailed management of who has what data about me? And nor can they use it. It it's a real challenge because there's a trust that people have, or at least a belief that, you know, it must be okay 'cause they're being allowed to do this when it isn't necessarily true.
So, you know, are we gonna have a, you know, a wood fire, fire shed incident of some privacy more than just data getting stolen, but because of cookies and that kind of thing, we, we'd have to have something that would drive us away from this and really sour, um, end users from like, I don't want those on my machine. I'm, yes, it's, it's at the creepy factor, but it just, does it get to the like, creepy guy outside the window factor? Then, then I'm worried and, and I'm gonna do something about it.
There's another technical term, right, Chris, Right? Well, and you know, there's an app called Light 360, if anybody knows this one. And we as a family, you know, me and my wife, our three three grown kids, we use it and it shares your location.
You can see each other on maps, right? And this is the kind of thing that I've played with over the, over this whole era, over the decades. Yeah, there was a car one, I'm trying to think of the first time this came up.
Anyways, there was a car app, we bought a car and I realized I'm in Germany and I can see where the car is. And it was interesting. This, it was a comforting, it was like a connection with my family at home.
I don't feel so separate. And as we talk about the Life 360 thing, it's, look, if you are going to be looking, you know, tracking and I see, see articles written about this, tracking your kids, it's not about tracking your kids, it's about knowing where people are. Now, if you're going to use that in a creepy way, You Are a creep, right?
Most aren't right. And you can just as well do it without the technology. You can ha have your friends who live on the other side of town call you when they see your kids.
Or, you know, there's, if you are going to use it, is my point about the small towns, right? We understand privacy intrinsically, we have, we can may not be able to describe it, but we have a good idea of what we expect. People may to know and not know, but in this digital world, we just don't.
Right? And even if it was possible to find out what people know, it would take more time than we have. So yeah, there's, if people are intrinsically creepy, you know, then they're gonna be creepy regardless if company, you know, we allow companies to go down this path, they get creepy.
We have allowed companies to get creepy. I have friends that would love an app similar to that, but it would show them maybe at the grocery store when they're in a bar across town. That would be good.
Yeah. It's like I had a friend who, who, uh, well you can If you want to, but again, if, if, But if I turn it off, it's immediately suspicious behavior, right? Because they're like, can't find you.
The first butt dial I know of is a friend of mine who got a cellular phone that kind of used to be in the box that you carried, you know, like a briefcase. And they took, took it with him golfing and butt dialed it and called his wife. And, you know, how was work today, honey?
Oh, it was really, really bad. Well, what were you talking about on the third green there with Bob and Tim? So, so it's, it's, it's still happening.
I think ultimately it's gonna come down to awareness. And who knows, maybe we need some congressional hearings to drive that awareness. Um, again, we're probably not gonna count on Congress to actually do something about it.
But, you know, those forums, they create certainly lead to a lot of conversation. And, um, I guess before we leave this topic, I would just remind everybody, hey, next time you're watching that instructional video on a site that you're not supposed to be looking at, just remember you're not the only one watching it. We'll be back in a minute, Discover how cloud native is becoming the new compute stack at Cloud Native.
Now on July 25th, we will explore the transformative shift towards modern containerized and microservices based applications. Learn my Kubernetes remains a dominant force in container orchestration and how web assembly is emerging as a powerful compliment. Don't miss this opportunity to stay ahead in cloud native development.
Register now and claim your spot in the future of tech innovation. And we're back with our third block on data privacy. And there was a lawsuit involving Oracle, alleged.
Oracle apparently settled for $115 million, citing regulations from the state of California and federal regulations that said that they had violated, um, policies. Oracle declined to admit any guilt, but settled the case anyway. But it seems to me at the core of this was, uh, allegedly Oracle was, uh, grabbing data from places out that they didn't have permission to get, and then correlating that with data that they had internally.
And apparently that's a no-no. Um, Chris, what's your sense of, um, are the data privacy regulations getting better and we just haven't noticed? And will we see more of these kinds of enforcement actions?
Uh, yes and yes. Right. You know, you know, we see GDPR and you know, some things that catch our attention and so forth.
But this has been incrementally coming along for a while and this is why, uh, I, I said, as I looked at our topics today, this builds well, right? I think that you have to have a feedback. Oh, where is this quote from?
You had to have the crime before the law, right? You have to have the problem before we figure out what the solution is. And these are big issues, right?
How do we get what we want, which is all this access to all the information and communication and so forth without, you know, losing the things that we want to. We also want, like our privacy and this, this particular instance, this ruling Yeah. I think is, is a good sum on the scale, you know, to help companies, you know, have the, the arguments for their shareholders, why they're not going after, you know, things that may be lucrative because, you know, there's a financial downside.
You know, we may get sued and lose. Um, you know, those are, you know, it's a, it's a hammer. This is not, you know, fine, uh, machinery.
You know, they'll, they will, to your point of your question, you know, the regulations, the laws, the, the, the, uh, uh, both explicit and implicit regulations, right? You know, maybe meaning not be a law, but, you know, companies will find out that it's better behaving a certain way. Mitch, do you think that this will actually result in some better behavior?
Because somebody will look up and say, do we wanna be the next Oracle in a lawsuit? Well, 150 million sounds like a lot of money, but to a large organization, large company, you know, is it really a lot of money, um, when you're, you know, revenues in the billions? I I think one of the things that caught my attention about this is the way the plaintiffs filed the suit or, or filed for the, the, uh, the agreement that they came to was talking about digital dossiers.
Um, we all hear kind of dossiers in the political sense, I think these days. But it, you know, we, we have to get agreement from people that are coming to tech strong sites to sign up for a webinar or a virtual event. And, you know, we, we say right there that, um, we, we will use this information and we'll share it with sponsors of said events to market the things that we have to offer to you.
We don't, we don't then take it and look at their browser history and figure out where they bank and where they bought gas and where they ate dinner at and shopped and which credit cards they used. I mean, that's essentially what, according to the, to what was filed that they had accused Oracle doing. So I have to ask who, who thought that was an okay thing to do and who thought they had permission to do that, uh, at Oracle.
And so every company, if they're gonna check anything, they're going to hopefully ask those two questions. But I'm not sure if this is gonna drive a lot of change of behavior. Chris, who owns the data?
And I asked this question 'cause you think it would be intuitively obvious that we own our data, but if I take my data and I type it into a system owned by somebody else, didn't I just kind of give them my data and did I understand the implications of that? Or, you know, what is the definition of personal data? Well, we, yeah.
The, the real issue is we having to find that appropriately for our purposes, otherwise we wouldn't be talking about this. Right? You know?
Mm-Hmm. But, you know, we're all old enough to remember before all this, and there was some mimeograph form that put your social security number and everything else on so that you could, you know, do some banking or rent a house or anything. You know, the soc you know, in the early nineties, social security number hacks, you know, and, and breaches were a lot of the conversation at, at that time.
I made a lot of comments. But it's like I have given that away to so many people, right? You know, I'm gonna base all of my security on the idea that nobody else on earth except me knows that that, uh, nine at a digit number, I got some bigger problems.
So we're kind of in, you know, an advanced state of that. Now we have some bigger problems, you know, we really don't know. And I think, you know, to, to the point of this, you know, particular incident, and I agree with Mitch, there's not a lot of money.
It's enough. You know, and it said, you know, reputational damages and so forth, that rats, uh, raise some eyebrows again, tiny little ratchets, uh, moving forward. Um, but, uh, the, the, the, you know, the answer inside Oracle, and to be clear, I have no insight into this, so I'm just guessing is there were some legal people who looked at existing laws and regulations and said, you know, we probably can't.
And it turns out they weren't. Right. Um, but how would you really know, you know, you would have, and this, this is a company with a serious money for serious legal team.
Hard to imagine. There was no review whatsoever. So somebody somewhere erroneously looked at the policy environment they're in and said, we could probably do this.
We'd make more money. And they probably made more money, but turned out they got in trouble for it. Mm-Hmm.
And mid site, you know, we own websites here at Techstrong and we're aware of all these folks who are quote unquote data brokers out there who were selling information to each other and sharing that. And it seems like it's a highly unregulated environment. So maybe we need to take a look at what's going on in the, in that business as well, because I think this whole Oracle thing is part of that whole motion around data brokers and people are kind of buying and selling data and correlating stuff and, and matching that up with cookies.
So they may not know it's you specifically, but they have like a 99% confidence rate that it is you, that they're locked in on this by your IP address and all this other stuff. So do we need to kind of take a giant step back and, and regulate this stuff? 'cause it seems like it just kind of grew up without any oversight.
Well, well, it's interesting. What we do regulate is protection of personal, personally identifi identifiable information. Sorry, it's too early in the day to get that out in one breath.
Um, PII and, and that's essentially like any attribute or pieces of elements of data or combination of, of which you can identify, this is Mitch, now I know all about him. I can find out where he lives and all these other things. Um, and to your point, Chris, you know, putting your social security number down on a form now seems akin to writing down your root password today, right?
It's, it's sort of one of the big keys to, to getting your data. So my point being, the, the regulation is about protection of that information because people are gathering it. And, and you have to disclose the uses for that.
I mean, there are companies like Graph ID or Id graph that, that have services that take that data and say, let us help you build, you know, a more personalized experience, right? We talk about personalization a lot in software and experience and websites. So the, the problem with regulation is in, in this sense of something that we're doing on a massive scale is you're, you're looking so much in the rear view mirror and you're, you're forcing a change on what is already or running rampant in the culture unless you have mechanisms of stamping it down, which you do have regulation.
In other words, there really are two true consequences. Um, it, it's kind of, you know, Paul's on deaf ears. I think I would focus more on the, okay, this is where we are.
How do we move forward? What's the way we wanna move forward? And is there regulation that would help us get to that place versus let's take this, uh, insanely, uh, active area and then go try to, you know, herd cats and get it, get it together.
Chris, is there such a thing as a right to privacy? Uh, I'm, I'm finding a hard place to find that in the constitution, and it kind of, uh, impacts a lot of conversations, shall we say, in a lot of other realms. But, um, arguably the internet is a public forum and it's no different than if I walked down the street and decided to, you know, go bang on a few windows and visit this one and that one and the other one.
I mean, that's open for anybody to see. So isn't the internet just another public street? Well, right, and you took the analogy I was gonna, because we walked down the streets, you know, and you know, the fact that a lot of people suddenly walked down the street might be worth knowing.
You know, it might be a, you know, exploding bee hive or something on the other end. You know, a lot of people, a lot of cell phones went into a pharmacy in this part of a city that might be, have some, some value. And if you're walking down the street anyways, you know, but the, I I think we're better looked to philosophy on, on privacy and practicality.
You know, privacy is inside your head and inside your home to a given extent. Um, but if you leave your lights on at night and all your, you know, drapes open and so forth, so somebody walking by in the street, um, and you have flashing lights that yeah, draw attention, whatever the, the situation is. But we all manage to live in this world.
We understand that the people around us, you know, can see us, you know, to my life. 360 example of, you know, I'm literally driving around, you know, there are other ways to get caught doing things. And it's, it's more of a, you know, so we deal with all these things through a lot of practical mechanisms.
You know, the, uh, like on video conferencing right now that we get all turn our cameras on, I've been saying this one for 30 years. When, when we get to this stage and you have a group of people on, on a call and everybody's on the camera except one, no one's gonna ask why they turned their camera off, because that's creepy, you know? Yeah.
We all, sometimes you don't want the camera on, sometimes you turn off your location tracking why none of your business, literally, in fact, asking is weird, right? So I have, you know, I have, I have optimism about this, like so many things, but because we already have ways of dealing with this, the real issue we have right now is time, the transparency. You know, you, you know, I would like to see the technologies and, and perhaps the regulations or laws or whatnot, you know, to require them, the competitive pressures are better so that everybody can see who has their data right now, you know, if it was gonna be regulation, I would like to say within 30 seconds, you know, you know that Mitch should be able to, without taking five days and things that aren't gonna practically happen in the real world, you can say, click, click, here's where my information is.
That would be wonderful. And I think we'll get there someday. And hey, Minch, we talked about, uh, cookies and being creepy in the last segment.
So while we're on that subject a little bit, ai, so now I got all this data and I'm like wrapping all this stuff into these AI models. Uh, is it just gonna get creepier? Well, no doubt AI is, and, and will continue to grow its application to data around advertising and cookies and user behavior.
As I mentioned, I was just on a webinar about embedded analytics within applications, and of course, AI is part of that as well. So I think that's a fact of life. Um, it does, it, Does it venture you into the realm of, Ooh, now that's creepy.
That's a new thing. And I don't like that either. That's certainly possible.
I mean, yeah, I would definitely think that would ha would happen. Um, so you could also flip the coins. Lemme take the Chris Blask.
I'm gonna think about it positively approach. So if you could apply AI in a way that I wanna create these experiences, but do it in these ways of what I'm trying to deliver as a customer experience, either my application or the advertising that I do, or the marketing of what I do, et cetera, um, you know, then, then it could actually be a force for good. But I think it will be equally, if not more so become another, you know, it's not gonna make cookies better to the end users.
I have a hard time believing that Chris, Chris, I can only stay there for so long, Chris, they say sunshine is the best disinfectant. Do we need like a creepy index where we're just tracking, you know, who's doing what in, in the most creepiest way possible? So at least people have an idea.
I think if it's possible to do that sort of thing, someone will make that, and it may be a, a, a useful thing, you know, for a while, but, uh, I think the, the term radical transparency gets used a lot. It. And so in my world, in the supply chain world, and, uh, I think that the ultimate answer to this is that we put systems in place that allow everyone to see in the period of time available again.
You know, we have, you know, in, in the US in most, you know, uh, developed countries, we have reasonable tools where you can really track down information that you should be able to see. But the effort required is, is heroic, right? So I think as technology, both we can make the world such that people can see what they need to see in the time they actually have available.
And I think that's better than having a, a list of, you know, shaming companies though. Yeah. What the heck if it works.
But better yet to take, take the question away. You know, I know where my data is, I know where my information is, I know who's using it. I'm okay with that.
We're not there yet. Mitch, can you envision a world where this is actually a campaign issue? Maybe not in this presidential cycle, but down the road somewhere, as more people become aware of what's going on with their data, will this become something that, um, somebody will make part of a political platform?
Well, a, after we solve the border problem, then we can move, move on to this one. Uh, well that's a data problem. Oh, it's A data problem.
I see. Yes, it's a data problem. Yeah, that's a, that's lots of things.
Um, you know, I I think if, if as far as it being a political campaign, it, it has to be at a level where this is impacting people's lives and you're trying to better that through, you know, through leadership, through government, through regulatory actions, things like that. I think most people are not watching the privacy laws and, and wanting to know when they're gonna add this, their particular flavor to that, unless they're in that industry, right? The Chriss and Mitch's and others that are, you know, heavily into the regulatory side.
Um, could it be, again, I think, I think those behaviors and changes in behaviors are driven by major events. If we had something that really, you know, I I, you, you know, Mike, I've, I've waxed on about don't, don't PR companies don't contact me about another breach. I, that's not news that, that there was another breach, you know, that's like, you know, telling me there's air.
Yes. It just, it happens and yes, it's the big one and right, who cares? That's consumers don't care 'cause they're not changing their behavior.
I wanna know who's done something to make it better, um, to make it less likely to improve it, to help companies recover that. I'm interested in talking about kind of the same thing here. Like I don't really wanna get into the, you know, details of privacy regulation in a political campaign, but I do wanna know what we can do to make it better for the end user.
If it's Chris's idea of, you know, let me make it easy. Be careful what you ask for, but let me make it easy for you to see where your data is and potentially how it's being used. I think that might scare a lot of people.
You know, to your point about you're not googling about Yankees 'cause you don't want to get hammered with, with information and ads and all that kind of stuff. So, um, that, that's how I look at it. All right, well, you know, And lemme I, I gotta, yeah, I gotta get an answer to that one.
'cause I think the short answer is yes and in all capital letters, letters underlined with, you know, five estimation points and you know, I'm in Canada right now, right? You know, and, and it's a good example because these countries are so similar. So you strip everything away.
What is the brand of a company, a country, whatnot, the brand of America is transparent. And I take it, I would take this to 11 and I've actually literally been arguing, uh, debating, arguing, discussing this with folks in three letter agencies in, uh, recently in a, um, conversation, a, a structured conversation with some folks who do influence operations for the Department of Defense, you know, out mountain, you know, in, in, uh, in other nations. And I think as Americas, Americas should say, be transparent literally about everything, just ridiculously so, you know, careful what you wish for, right?
You know, all sorts of way we, ways we do things, you know, we're, we're really putting it up to sea and seeing how it, how it survives in real weather, right? To the, but to the point where, and uh, and I may be naive about this, but I don't know, it's a complex world. I think if the, the US military is performing influence operations, trying to change opinions in some foreign, uh, nation, uh, we should tag it with US military influence operation.
Just say it. Here's the, you know, we want, you know, you folks to, to accept this sort of idea. So we're presenting this sort of idea and always do that.
Always, always. So everybody can always see everything they should, right? Don't, don't, don't we have radio friends.
Transparency, Radical transparency doesn't mean that everybody sees everything. It means that if you have a right to see something, and you can see it now, and you can see it in a timely fashion. And I think on, on the political front, the sociological front, you know, can we have less trust in governance and government?
No. So, you know, just saying we are going to pursue a path Where Every opportunity we have, so constituent stakeholders, citizens have faster access to the information they, you know, they have, uh, every right to have so that you don't have to go down to the courthouse and spend 90 days or 90 minutes even. But we can build into the systems that, that all information is as transparent as physically possible.
And I think you could win elections that way and hearts Alright, we will see if that plays out. But um, the odds that there will be a constitutional amendment that will then need to be approved by two thirds of the states in the next five to six years is probably pretty low. But hey, if we start banging the drum today, who knows?
And remember a lot of That, all I can say, all I can say Mike, is uh, I endorse these subliminal messages of the past 45 minutes in this conversation. There you go. We are trying to do our best.
But that said, you know what, the attitude towards big tech is changing in dc. So who knows? Maybe things will get different in a hurry.
Anyway, thank you all for participating in the latest Tech strong Gang episode. Chris, as always, Mitch, as always, thank you all for watching and we have a great set of lineups for Techstrong TV coming up right behind us. And we will see you guys on Monday.