Techstrong Gang – July 3, 2024
Alan, Mike, Mitch and special guests Daniel Newman, The Futurum Group CEO, and Paul Nashawaty, practice lead for application development at The Futurum Group, dive into the technological chaos that will reign in the wake of a Supreme Court decision to limit the power of Federal agencies. Then, they dive into what inalienable rights content creators should have.
Next, the gang turns its attention to whether application developers should have a bill of rights in a platform engineering era, in which IT organizations are centralizing more control. Finally, in this episode of Byte Me, Ira Winkler “addresses” his outrage that UnitedHealthcare had a CISO who had no experience in cybersecurity.
Transcript
Hey, everyone. Happy Wednesday. Happy day before the 4th of July.
It's always one of my favorite holidays. We've got a great pre fourth, uh, show for you. We've got, we've got some Supreme Court rulings that could really shake up just about everything in the tech world as well as the rest of the world.
Who do you believe when an agency tells you to do something? What about the inalienable rights of content creators? That's a great July 4th kind of thing.
And do we need a bill of rights for developers? We're Patriots here. You're watching Textron Gang.
Hey everyone, it's Alan Shimmel from Textron, and we're back here for a Textron gang. Very special edition of Textron Gang. Today, it's our pre July 4th special, and we have sort of the, I guess it's the founding fathers of Textron gang.
Um, unfortunately we had some sickness and, and the, and, uh, two of our guests, regular gang members today had a drop for this morning. And, you know, COVID is still out there as well as just the good old flu. So we wish Lisa and Samantha a a quick recovery and they'll be back on next week's text on gang.
So we had to, we had to go to kind of the bottom of the barrel and drafted someone here last second, actually, we didn't go to the bottom of the barrel, but we're really happy he's making his second appearance here on Textron Gang. It's the CEO of the Futurum Group coming to us out of Austin, Texas today. Daniel Newman.
Hey, Daniel, it's great to have you on. Thanks for coming on. Great to be here.
Fantastic. Joining Daniel and I today from up in Lake Placid. He's still covering the Winter Olympics 20 years later.
It's our Chief Content officer, Mike Baard. Hey Mike, welcome. Hey guys.
Lots of Patriots up here. This is the miracle on Ice Man. Absolutely.
1990. That's right. 1980.
What am I saying? Um, also joining us from Futurum Group today, he's there, he's our DevOps research analyst. He covers a lot of cloud native, he covers a lot of things.
Paul Nash, Nati. Hey, Paul, welcome to have you. Welcome and great to have you.
Hey, Alan. Hey, team. Great to be here.
Absolutely. And then least, but certainly not or less, but certainly not least distinction. CT O and CTA at Futurum Group from high up in the Rocky Mountains.
I'm, I may be leased, but I've got the best guitars. So, Hey, what guys? Absolutely, Mitchell.
Ashley. Hey, Mitchell. Welcome.
Good to see everybody. So guys, we're gonna do something a little different today, not just because it's pre July 4th, but because as I mentioned, we lost two of our panelists for today. And, and to keep things straight here on our panel, Mitchell and Paul are gonna drop for our first segment, and then they'll be back for the bill of rights for developers and inalienable rights of content creator segments coming up.
Um, but so Mitch and Paul, we'll have you back on here in in about 10, 15 minutes, but thank you. And we'll, we'll see you in a bit. Mike, I'm gonna kick it over to you to kick things off here.
All right. There's a lot going on in the world around this whole case involving Chevron. And what people are starting to figure out is that the Supreme Court didn't just rule on this one case.
They basically said that all these federal agencies do not have the authority to apply these rather, uh, sometimes comprehensive rules that wind up being fairly onerous. And they address those rules, can be almost anything. Uh, they can be financial rules, they can be spam rules, they can be FCC, internet rules.
All these things now seem to be in question because, well, it turns out that maybe these agencies don't have the authority to fully apply them in the first place. So, um, Alan, you're a, in a previous lifetime, you've been a legal eagle. So what's your take on what's going on here?
I'm still a legal eagle. Um, but look, I, you know, for purposes of our discussion today, let's limit this to how it affects technology, because this thing can affect everything. F you know, F-C-C-F-D-A-F, uh, you know, FTA, all of the federal agencies now, they're all chartered, usually by a passing a congress passes a bill and empowering them.
And the executive branch of our government has usually brought authority to carry out the will or as, as it is expressed in the act of Congress and signed by the president. But for business to flourish, for businesses to succeed, they need certainty. You can have a bad rule, you can have a good rule, but at least give me a rule that I could bank on, and I'll work around it and work through it.
When you have rules that are Swiss cheese though, and if I don't like a particular rule, I'm just gonna go down the block and hire a lawyer and institute a claim, and I'll take it all the way to the Supreme Court that's gonna, I'm afraid, create chaos and, and lack of certainty in our business climate. And that's what, that's part of what makes America great, is that we have a stable climate for business. Um, Daniel, you deal with bigger companies, you deal with a lot of the chip manufacturers.
How do you think, I mean, how, if you can't bank on anything, how do you bank on anything? Yeah. Well, first of All, um, I just wanna say I'm the only person that's gonna be on this particular Textron gang show that wasn't actually born yet for those 1980 Olympics.
So I felt that was important. That, okay, alright, point me. So not a legal scholar here, but we do work quite a bit with tech companies around policy regulation.
Um, this is an interesting inflection because, you know, you try to kind of think about what was the genesis of giving this power to the agencies? And, you know, the government, and again, this is not partisan, but our government's gotten very large. We have lots of, uh, ireg regulatory bodies.
We have lots of different branches, and of course we have, you know, things within the executive branch. And then we have the actual policymakers in, in, you know, Congress. And then of course we have these agencies and they're all sort of inflicting their various influence on different industries.
And the goal is generally to, uh, be enabler of, of a healthy economic climate, while at the same time mitigating things that could be done that may be, you know, whether it's polluting our water, whether it's enabling, you know, cyber risk of the grid, uh, whether it's creating, you know, more sustainable rules to reduce carbon. And so I think what we have is this really interesting scenario in which the regulatory bodies, uh, and then of course the agencies have been created to sort of expedite focus into certain areas. So, you know, whether, you know, it's, it's the trade commissions that work on, you know, regulatory agreements and frameworks for shipping GPUs to countries in which we don't want to give too much ai, uh, capability too fast.
You know, we've been able to quickly, um, implement controls and that those controls can be executive, they can be legislative, and I think largely they're agreed upon. But right now, what you sort of alluded to, Alan, that's really interesting, at least in my opinion, is whether it's been like, you know, I think Mazar mentioned can spam, um, and I think that's Canada, but California has similar rules. And then of course, you know, whether that's been, um, net neutrality rules, whether that's, you know, again, some of these various chip controls, whether that's been data and email storage rules, things that have come down from these agencies are now going to be, um, tried and tested if enterprises feel that those rules are unfair.
So, like I said, you know, right now rules that have potentially come down from agencies that have limited the shipments of, of chips into certain countries, um, for the sake of economic, uh, growth and stability, some of these, uh, chip makers may challenge these rules and see if they can get an overturn from Supreme Court. That's just a for instance. But I guess where I'm up, and I'm gonna, I'm gonna pause here 'cause I could go on and drone on a little bit here, but is what enables us to go fast, which is really important to our economic health and climate here.
But at the same time, what doesn't enable bodies to be, uh, able to implement rules that are not fair or not at least been deemed fair by a, uh, non-biased body. How can, you know, lobbying and influence to agencies, uh, enable them to take too much control? How do we manage that without slowing down our economic growth and slowing down enterprise?
I think that's the key is what are we gonna do to, to have stability and speed and, and certainty? I I'll tell you this, as a former lawyer, I'm lawyers out there are gonna be foaming at their mouth waiting for the starting gun to start, you know, challenging every single one of these agency's rulings in court and start billing their hours. They're gonna bill a lot of frigging hours on this.
Um, and, and it's gonna take years for these things to wind their way through the court system. And then what do you do with your business in the meantime? Do you get a preliminary injunction, a temporary restraining order?
You just ignore the ruling and damn the torpedoes full speed ahead. This is, this is potential chaos in the business. And one thing businesses hate are, is chaos is chaotic times they need, they need that certainty, they need structure to, to, i, i, I just think this is bad for business.
So, Alan j just one thing I was gonna mention you guys maybe worth debating is, you know, recently the FTC did a non-compete ban. Um, is this sort of a for instance, right? So they voted three to two, they're gonna ban non-competes, and that's going to obviously put a lot of power back to the individual employees, take a lot of power away from companies, and of course there's some limitations to that ban.
But again, do you not see something like this just getting a flood of Supreme Court cases in which companies are going to say, Of course they are. We, we, we train people, we educate 'em, we give 'em all this access, we, we, you know, and then they basically take all their knowledge to a competitor for a few dollars and you know, it's gonna dis incent companies investing in employees. I'm just giving a for instance.
No, absolutely. But its gonna, but who's going get rich off of this? Lawyers?
The fact doesn't matter is most non-competes weren't very enforceable to begin with. To Daniel's point, though, doesn't all this shift, this focus back over to Congress that's gonna a, after re review all these acts and make them more granular and specific in terms of their permissions that are granted to the agencies. It seems like to me, part of the problem here is that the bills, as they were written by often lobbyists are just overly broad because they were assuming that the agency could have some discretion.
And now we gotta go back in and kind of negotiate every little Thing because it never worked. It's not in the bill. Never, because you can't, what happens is, when did Congress establish the FDC or the FDA they Congress, first of all, assuming you have a functional congress, which I'm not even gonna get into right here, but Congress paints broad strokes, brush broad strokes.
You can't expect Congress to legislate or, or decide or non-compete. Take Daniels example or non-competes legal or not, or enforceable or not, or what are the, what are the caveats and special circumstances? You know, when a non-compete is or is not legal, they're not gonna do that.
They don't, they don't work at that detail. The idea was to have what we call legislative intent, right? Courts, when they look at whether or not an agent, historically courts look at whether, whether or not an agency was ruling based upon the legislative intent of, of the Congress of the people who wrote the bill or the, that became law when it was passed.
What was the legislative intent here? What were they, what authority were they giving the agency not to get into the pants of every single little nitpicky ruling? Congress can't, Congress passed 12 bills last year.
You think they're gonna pass a couple thousand things that the agencies do? Yeah. Whoa.
It's gonna be chaos. Yeah. So they gave a ton of power to the agencies, and this may look to pull a little bit of that power back, but the problem is just the incredible inefficiency of Congress.
Um, there's way too much horse trading, uh, decisions are not necessarily always made, uh, you know, at any sort of speed or pace. It takes a long time to, of course, make a bill into law. And remember it was a two step test, you know, and I, and I, and I just think for everybody out there, this is complicated.
You know, it's great Alan having you as a, uh, someone with a legal background. But, uh, you know, one is the idea was that Congress does speak to some issues. Um, and if so, their law is the overarching and overriding law.
But if there is no, uh, for specific law or statute on an issue, basically this gave the, you know, the deference to the agencies. And so that gave the agencies a ton of power. 'cause there's very few laws relatively speaking to all of the policy that's set out by the agencies.
So this is a, it's an interesting inflection. I wouldn't, I wouldn't call it a, a setback entirely, but it makes the agencies a lot less effective and it puts way too much of the onus on Congress, which can't get things done because of various partisan issues and red tape. So I know we said we wouldn't talk politics, but the politics of getting laws passed will make this difficult.
I ultimately think power ends up back with the agencies. That's what they were set up to do. Um, not always for the best, but I think it's more efficient than trying to have the courts manage it and legislators create bills and laws for it.
I agree with you, Daniel. And the, the other thing I, I will tell you, 'cause you know, SCOTUS came out with some other, uh, decisions. One of them is that the executive chief executive and the executive branch have to have the authority, have to have the ability to fulfill their duties under the Constitution and the executive branch.
Congress doesn't run the government day to day Congress funds the government. Congress, as I said, points broad brushes, right? It's not just a question of going to law school.
Look, I was a political science history major. This is how the founding father set this up. Congress funds the government, Congress puts broad policies in place.
It's the executive branch that kind runs the day-to-day of our government. And, and SCOTUS has said the executive branch has to be free to run the day to day of our government. Well, today, it's not just, you know, what is the day-to-day of our government?
It's not just the post office, it's, it's the Treasury Department and it's the DOD and it's the FTC and the FDA and every other agencies, let alone the quasi-government governmental kinds of agencies, American ferc right? For nuclear regulatory, and, you know, power plant regulations. All of these kinds of things are being called into question now.
And if the, if nothing is solid, if not, if you can't, you can't build on quick send. And that, that's, that's my fear here. But so, So are we gonna miss the bureaucrats?
'cause you know, we've been railing against them for so long now, and now it's suddenly we're gonna wake up one morning and go, geez, we missed those guys. You'll never get rid of them. Go ahead.
I just wanna run a company at $33 trillion in debt and not worry. 'cause I know that the next trillion will just appear out of thin air. Again, not political, I don't care that both parties do this very badly.
But a I mean, just imagine if we could run the shop, but you know, you know, a trillion, well, You can't, you Every quarter, This is a, so that's a whole nother issue that that's not spending the money. If You talked about what Congress needs to, uh, to, to, to authorize the government to run, I'm just saying, I don't think that's a great job they're doing. And I would like to work.
They Haven't done a great job Dollars. So if they can't do that job right, what makes you think they can get into even more detail on what the agency, Here's my point. Thank you.
So if the agencies can't do it, let's not get ourselves into ving Congress ka Anyway. Hey, Daniel, you have an open invitation here, you know, to come on anytime. So it's been like two months since the last time you're on.
Yeah, we're gonna try and get you in here. People on the Rum and Textron team, you know, I wanna give everybody the air and you guys do a great job. But listen, when you got a topic like this and you want me to come, I'm happy to be here.
Great to see you guys. If I don't talk again, happy 4th of July, Alrightyy Daniel Newman, CEO founder of the Futurum Group. And of course, you know, tech Strong is becoming part of FU Group and we're having a great time doing it.
Daniel, happy for the July to you and yours. I know you're heading out on vacation as well, so enjoy. We're gonna take a break here on the gang.
We'll be back in just a moment. All right. Hey, we're back here on Text and Gang, and we've swapped out Mike Ard and, and Dan Daniel Newman.
And now we have Mitchell Ashley and Paul Nati with us, and we've got two players to be named later and a protected future draft pick in this deal. So I think we made out pretty damn good. Anyway, Paul and Mitch, welcome, welcome back.
Our next topic is, uh, it comes out of a recent article we saw up on social media today, and it was actually an announcement from the White House, uh, protecting the inalienable rights of content creators in the age of ai, right? And we hold these to be life, liberty and the pursuit of happiness or something like that. But Mitch, you wanna know Paul, who would like to kick this one off?
I'll, I'll jump in real quick, Paul. Oh, really? We can, we can kind of take it from there.
You know, the, um, it reminds me of kind of the maker economy, right? People that make things and do things mm-Hmm. Hobbies become businesses, et cetera.
Well, we have an economy of people who create content, right? And, um, you know, it, it's, I think it's pretty well known secret that many of those people don't work for the big media companies or the, the Facebooks of the world, or, um, places that can create license agreements with Apple and others about, um, do, does our content go into open ai, LLMs, et cetera. It's, it's everyday regular people probably making less than a hundred thousand dollars doing their work.
And so what rights do they have, I think is, you know, what in inhalable rights, maybe what rights period do they have for their content? So easy to get swept up in the, uh, the consumption of content going into AI systems today. So that was in part what the, what the White House kicked off is, is, I would call it a community discussion about what do we need or what are the needs of this creator community?
It reminds me of our security, security bloggers network that became the Security Creators Network, right? And how do you foster that group of people so that they can, you know, thrive, do what they do well and give them not only an audience, but, um, uh, maybe some protections Now given the last segment about, you know, what, what, what can agencies really do? Uh, anymore, we're not quite sure, maybe this, this is up for grabs as well, but that's at least the start of the conversation.
What would go anywhere? Uh, we'll have to see. 1 of an event happening.
So, Paul, Paul, what are you, what's your perspective on this? Yeah, thanks, Mitch. Thanks Alan, for having me here.
You know, I I, I, I'm kind of in agreement with you, but I also want to add a little bit more color to it. Um, when I think of the, uh, content creators, there's, you know, the gig economy is out there. It's, it's, uh, some of it's by choice, some of it's by necessity.
Um, but I think you're right, right? When I, when I look at the number of people that make you say, under a hundred thousand dollars, it's, uh, a year, it's, it's like 4% under 4%. Uh, you know, which is, which is interesting.
But when you're, when you work in the gig economy, um, you know, you, you get hired to do a, a, a job, and you get hired to do a task. When you get hired to do that, I, the rights of the work that you do for that person who's hiring you, or that company that's hiring you should transfer with that company. So that company owns the responsibility of putting out that content.
So think about it like this. If, um, if a, if an organization hires somebody and they create content, and that information is incorrect, when the organization puts that information out, who's responsible for that? The organization is right?
Not the individual necessarily, that created the content. Now, um, with that said, the, the rights of tho those content, um, really goes with the person who's funding or buying that content to be created in, in my opinion. Now, this also goes with a trend that we're seeing, uh, across the developer community, which is the, the skill gap issues, right?
Not just developers, everyone. We're seeing this across every, every industry, right? But skill gap issues, uh, it, it also breeds the necessity where, uh, if there is opportunity for someone to come in to do work, uh, it has to be a little bit of give and take.
So unless an organization is going to hire, say, a, an entity that owns the rights to those, those that content that they're creating, that organization should own that information. And it just, that's just kind of how, how it works. And, and, and when it comes down to the responsibilities.
So, Paul, Mitch, I think you both bring up good points, but to me, there's a couple of things here. So, first at, at its very core, this is about ip. You know, we get wheeled when companies around the world use American IP without permission, right?
At a lot, at a, at its core, it's big part of the issue economically with, with China, for instance, right? Um, you know, the, the, the whole idea behind patents and IP protection at some level, to go back to the, the, the previous discussion I had with Daniel and Mike around this Chevron and, uh, ruling, the, you know, businesses need certainty. Business need, businesses need a structure to operate in so that they know what's right, wrong, allowed, not allowed what they can do, what they can't do.
The i the principle of ip, of intellectual property, that if I made something, I created something, someone else cannot rip it off and use it to my detriment or without compensating me, is, is a, a foundational principle of our economy. Now, yes, you wanna hire me to do something, and then you are going to use that IP that I created when you hired me. Well, that's a work for hire, and that's well settled law.
Of course, you could have it as a work for hire, but that's not the case here in the age of ai. What the AI people are doing is they are taking people's IP that was put out on the internet and then ingesting that into their LLMs of which they train their AI with, and then regurgitating that IP out in a similar or different form. But nevertheless, it's based on my, on that, that old ip, and then profiting off of that.
And I'm not being compensated for the use of my I IP at its heart. That's the issue here. Now, if you are the New York Times, or, you know, one of these big media companies, you have the cloud to go to the AI company and say, you're gonna compensate me if you're using my IP in, in, you know, making your, and training your ai.
And that's great. But I'm talking now as the CEO of text trunk group. We're a small, we're a small player here.
com sure as heck went into, I'm sure the, the training of some of the AI out here. No one's paying us a dime for that, a for that ip. And that at its heart, I think that's what it's about.
We can't lose sight of that. I think it's That in its work product that can come from that ip, right? Mm-hmm.
So it's the IP and its origination. And as you mentioned, work for hire law, well established, it seems copyright laws kinda lost its teeth in this too. Um, or even licensing agreements, right?
com, and you said, yes, you can. You, you know, creative Commons, you can use it, but you need to, uh, attribute it to, you know, the source. Well, that doesn't happen in, in LLMs, right?
So I think there's a lot of things that are being leapfrogged in AI's hunger for data, specifically generative AI that, you know, is the individual blogger gonna be able to sue, you know, the Microsofts or the open ais or, um, anthropics of the world and say, you're using my stuff. It's hard enough for Textron to do that, right? More or less an individual person.
So it seems to me that the Pandora's box has been already thrown open and, uh, we're well past the, how do we solve this upfront? Is there anything you can do after the fact? Yeah.
Well, Mitch, uh, good points, and Alan, absolutely great points, uh, uh, talking about this. You know, I think that there's, there is a separation between work, uh, work for hire and, uh, patented or copyrighted, uh, infringements or, or, or protections. You know, Mitch, I will, I will comment on the fact that, you know, what we are seeing in AI is, uh, attribution to data sources, so that that is coming, right?
We are seeing that it's not as, um, robust as it should be, so to speak. Uh, but it is out there. You know, I, I mean, I think I, when I look at this scenario and I think about it, it's, it's, it's a, it's a number of different things.
One, if I, if I'm doing research and I read a number of different books, or, and I need to read a number of different, um, you know, articles or whatever, and then I form my own decisions and, and opinions and then create a product based on that, that's my ip. I was informed by these different things, and then I create something. Okay?
That's one way to look at it. Another way to look at it is if, um, if you, well, I should say historically, we would have to do, uh, you know, a lot of that footwork, and it's a manual process, right? Go out, get books, go out there and get, you know, search the internet yourself or whatever it may be.
Now that's accelerated, right? It's the screwdriver and drill approach, right? You no longer need a hand screwdriver to screw stuff, and you haven't pulled the trigger, and now you have a drill.
So it's happening much faster. And, um, you know, this is really where it's, I think it's, it's, it's amplifying the problem of if you're just regurgitating what's, there's patent infringements and, and copyright infringements, absolutely. That's a, that's against the law that needs to be enforced.
Um, and then needs to be, uh, uh, enablers for, uh, not just the large corporations, but also the, the individuals that are creating that content as well. But I also think that we don't wanna over pivot to say that unrealized gains are created, or now, you know, now we're, we're sue happy because somebody create, read something and then created something based off what they read. Where's the IP there?
Well, that, that is the, the IP is if, if you created based off something you read, or in this case, in the a in, in AI ingested, let me give you a better example, Paul. I write a song, clearly, I wrote the song, it's my song, the melody, the words, or Mike, right? And now you heard that song, and with one of those songs that stuck in your head, right?
Right. And, um, and then later on that night, you said, I feel like writing a song. And you had this tune in your head, and you may not even have realized it, that that's the tune you heard on the radio this morning or whatever.
But you wrote, you write a song on that tune, change the words, 'cause they're your words on something. But you use that tune because that was in your head, and now you go out and sell that song, right? Do you think the the person who wrote the original tune is entitled to something?
Well, you know what I think is kind of irrelevant, but I, I'll give you my, Well, I'll, I'll tell you what the law says about it if you want. I just wanted your opinion. Yeah.
My opinion on this is, as long as the, the creation of the new asset is built on, um, uh, originality and with the, with the guidance and bumpers and, and guardrails in place, as long as those things are met and you follow the rules of the law, then sure, you can monetize it. But if you're breaking the rules, then either you have to address the rules or change the rules, right? Those, that's, that's where we're at with ai.
It's like, you know, we're starting to add in things on AI to start changing the rules. Uh, so it applies to this, this type of, uh, scenario that you're describing. Now, I'm curious what the law says.
I, I'll tell you, Mitch, you're a musician. What do you think? Well, I, you know, there's the law, and then I kind of go back to Harlan Howard who created the phrase, uh, three chords and the truth, you know?
Mm-Hmm. There's a, there's a lot of commonality across music. Meaning there's, you know, there's, there's only eight notes in the scale of any, of any song, and usually three chord, three or four chords in the song.
There are others that have more than that, but it's all variations. And it's the artistic creation around it, which goes back to intellectual property, uh, so that you're creating, and that in music world is created, it's protected by performance rights and copyrights. There isn't intellectual property rights around it.
So we have a little bit different thing in text, but it does remind me of the, of the music subscription business, right? Where all of a sudden all the artists who are creating music and selling CDs or albums or whatever, suddenly you're up on Spotify and how do they make money? Right?
And now you do make a little bit of money as an artist to that, but it's, it's tiny. You may not have made a lot of money to begin with, but it, it's, it's changed the financial of the, of the business drastically. You know, is that what the creator economy is gonna be?
Something like that. It's gonna go the way the business. Well, but yet, musicians are making out, okay, in the world of Spotify, they, they get their royalties.
It's 'cause they went independent. That's why they did, why They, yeah, they had, it did break down the big record labels. But back to Paul's question, what does the law say?
There's plenty of cases where it's been upheld that if you use someone's melody, you change the words, you owe them royalties on it, you gotta stop using it. The bigger cases, and most recent cases came out over what they call sampling. I, and I'm, look, I'm, what do I know from rap sampling and all that, Been listening to some run, run DMC.
Are you Well run, DMCI listened to you, Mitch. I'm not that old. Well, they brought in a Aerosmith for their stuff, so they're called.
Right? Well, but no, but more recently, there's been cases around sampling of music. It became very popular.
Uh, who does astroland? My, my, my sons are into this, right? Travis Scott, Travis Scott and stuff.
I mean, these guys do a lot of sampling. And, and the courts have upheld that, you know, you got, you gotta pay royalties on that. 'cause that's their music.
You're sampling. And That's, and that's fair, right? And that's kind of to my point, if, if you're doing sampling within music, or if you're doing sample sampling within content creation, and in, in my world and the developer world, um, you know, code creation has changed quite a bit over the years, right?
There's, uh, the, you know, we, we've kind of evolved to a, a development perspective where you're compiling code and you're taking code snippets and making those code snippets work to be more efficient, more effective. That's quote, sampling of using code to address your business problems is, is, you know, other patents and, and, and trademarks and royalties and copyrights around that. Absolutely.
Right? But again, those are, and we see it all day long, right? There are, there are software packages that are created that are used in, so, uh, code snippets that, uh, you know, may, may have been protected, but you either pay those royalties or you follow within the rules that are out there.
I mean, it's, it's, you know, it doesn't, I don't wanna make it sound like it's as, as clean as black and white, but if you are creating something, you have to know what the, what the rules are and what the guidance are, and then stay within those boundaries. That's just, that's just the way it is. You know, I want to jump on your, your drill analogy, Paul, because we also now live in a world where, let's say my code escapes, it shouldn't have gone into the wild, right?
Yeah. It's, it's, it's intellectual property for the company. It gets scarfed into an LLM, right?
In, in, in whatever time period, could be seconds or minutes and moments later, someone else is, it's appearing at other people code unintentionally, right? So this whole idea in, in, in the AI data science of data poisoning, that information has gotten into the, to the system. It can't easily be retracted and extracted, especially after people begin to use it.
So what do you do in that case, right? It, it's not just, yeah, you got out there and somebody used it, uh, unknowingly. Yeah.
It may have been then propagated tens, hundreds, maybe thousands of times in the very short window. Yeah. We're seeing changes in this space, right?
I mean, in the, in the repositories, we're seeing that there's, you know, the movement to use read only code, for example, and, and, and make it so it's, um, you know, you can only read, you can't modify code. So, so there's, there's kind of, uh, you know, look, this is an evolution. This is, we're all learning how to work in this new world and how fast things are changing, how to protect your information.
I mean, data sovereignty is a big, big deal in certain countries. Mm-Hmm. And obviously for obvious reasons, right?
Um, in the, in the US it's less of a concern there. It, it seems to be more like we could propagate information and get it stored in, in multiple locations, but that also gives the opportunity for, uh, you know, various actors to come out there and, and, and utilize that code. If, you know, whether it's malicious or not, they can utilize that code.
Uh, so there has to be some rules in place. And again, I, I don't wanna make this sound so black and white that, you know, gee, there, it's on or off. Uh, there has to be a little bit of, of grayness in there.
But, um, there are ways to protect what you're doing, having your code leak out into an LLM. Well, how did it leak out in the first place? I mean, why was it in a, uh, you know, in, in a situation that it was able to leak out?
And if it was, I mean, there needs to be corporate controls and governance and compliance within organizations to make sure things like that, that do not happen. I mean, we see this with a lot of different, uh, large companies, for example, with their roadmaps that went into LLMs and they have, that went down the public domain for their three to five year roadmaps. That's not good, right?
Companies don't want that. And obviously for obvious reasons, but that needs to be in control within the organization and the, those, this is a new world we're living in, and we have to adjust to those compliance and those regulations appropriately. Agreed.
Guys, we gotta take a break. We've got another topic and then a special report for today's show. So you're watching Textural Gang, we'll be back in a minute.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Hi everyone. We're back here on Techstrong Gang. So continuing our July 4th celebration theme today.
Our next topic is, do we need a bill of rights for developers? com. What is it for?
Uh, uh, and two other interviews on Text Drug tv. Mitch, why don't you kick this one? Well, this is an outcropping or growth of developer experience.
Mike, what are we, what, you know, there's been talks of unionizing developers, things like guilds, things like that. Nothing's really come about that in any of any substance, but we are focusing on developer experience. In some cases, that's kind of masking this developer productivity.
How do we get more for less or more for the same out of the same people? Don't, people don't always like to be told they, you know, we're working in making you more productive. Your output needs to increase.
It isn't always a compliment. Sometimes it is. It, it, it's interesting 'cause one of our friends, uh, you remember Dr.
Nicole Forsgren, right? Mm-Hmm. The Dora Metrics.
I know Paul's very familiar with this as well. Um, did a study, was commissioned by Microsoft to do a study on this, looking at what are some of the key factors around developer experience. So, you know, is there a bill of rights?
I don't know that there is that, but I think, um, we have to kind of be more definitive about when we mean developer experience, what does that mean? And we mean increasing productivity. It's not just about the developers, it's really about the whole system of getting, you know, soft code into production or getting the output done.
Um, I mentioned Dora, uh, y it's a, I know that's a familiar, passionate topic of yours as well, Paul. Absolutely. You know, when I think of Dora and I think of, uh, the, you know, the regulations for the DevOps community, you know, I, it, it, it really does come down to a couple of points that you touched on, Mitch.
Um, you know, operational or developer efficiencies, no developer wants to hear that they need to be more efficient and more effective, right? Because they, they are doing what they can. Um, but what I would say is based on our research, based on our studies, you know, we see that, um, 75% of software companies are really looking to, uh, you know, improve their CICD pipelines.
And, and the reason why is because the, excuse me, the release of code is happening far more frequently than, um, than in the past. So what we see in our latest 2024 research study, uh, 24% of organizations, excuse me, 24% of organizations wanna release code on an hourly basis, yet only 8% are able to do so. And part of this is, um, you know, the, the addressing the market change, addressing the developer experience, but also the customer experience.
But I will say, I will say this, um, when we think about releasing code that rapidly, think of, I use the example of Stonehenge. If you, I don't know how this was done, and I'm not claiming to know how it was done, but if you take Stonehenge and you put a bunch of people underneath a bunch of hands on that rock, and you push that rock up, I still don't believe in my opinion, that, uh, a bunch of hands could lift that rock up to, or stand on top of the other rock. I see the same analogy with, um, with software development.
You, you can't keep throwing bodies and developers at, uh, at releasing code. So you have to start taking advantage of tech stacks like automation and AI in order to, uh, release that a code on an, on a regular basis. So there should be some type of rules and governance and compliance in place in order for the appropriate workflows to be delivered and the appropriate governance to be delivering those applications.
Isn't it? Ironic, Alan, we're going, we've gone from, we only need developers to DevOps in the two. Now we need a bill of rights for developers.
It's the theme. The pendulum swings, The pendulum goes round and round, as does the Wheel of Karma. Um, I thought from menopause was going to, uh, aliens are coming in to help developers write more code.
I mean, that might happen. We never know. Well, You know, but I, I, I'll tell you this though, as we go forward in the future with AI and, and AI does start doing more developer tasks, I, I think the delineation between what AI does and what humans do, in this case, developers is gonna become more important.
It's gonna become, it can't be as wishy-washy. And, and humans in this case, developers are gonna wanna have some rules that this is their purview, the law of robotics. No, but you know, this is what humans do, and this is how humans use AI in terms of developing.
Um, and maybe that'll change as time goes on and, and capabilities increase. But I, I do think you, if you don't carve these out, you, you know, they're gonna disappear. Yeah.
And, and it's important. Anyway, go ahead Paul. Just a, just a quick, uh, comment on that.
I think that there, there's absolutely a human, a need for a human in the loop. There's no question. Um, but there's also a desire, actually, we see in our research that 67% of organizations are hiring generalists over specialists in specific areas.
So they're really looking for, um, organizations are looking to reduce the complexity of these, uh, deliveries. So they can, it can be done with more of a generic, a, a generalist to do it. And, and really the goal here is to take those actionable insights, apply it to the code, but have the human capital focus on more innovation and more, um, uh, higher value tasks and get the, um, tedious tasks kind of handled by automation and ai.
That's, that's kind of where the, the, the goal is, I think for most organizations. I absolutely, I'm gonna put in a plug at the end of July. I think it's the, around the 28th.
Um, we're releasing AI and DevOps report. So we're specifically looking at how much is AI playing a role already throughout the development lifecycle, as well as what developers are doing. So stay tuned for that.
I know Paul's on, you know, kind of competent to bit to get a hold of that. All righty. Hey, we're gonna take a break, but when we come back, we're gonna do one of our featured, uh, soloists.
And we have two, we have role Bob, Bob Ruman, and then we have my friend Ira Winkler. IRA's. Little solos are called Bite Me.
For those of you who aren't familiar with Ira, IRA is a well-known personality in the security space, but also a very accomplished security person, both at his time at the NSA and you know, also discovering one of the major hacks in, in historical hacks. Um, but Ira also has strong opinions on the workplace, on the cyber market, and everything else in this episode, he's going to talk about to CISO's need security experience. You would think so, but maybe not.
We'll get to go to Ira Winkler and we'll be back, right back here after that. Hi, this is Ira Winkler with today's episode of Bite Me. Today.
I'm gonna do something that I'm not overly comfortable doing, and it's gonna be obvious why, and it amounts to essentially criticizing another, God, I don't even wanna say it, a si another cybersecurity professional. And I, I feel bad 'cause he's not even a cybersecurity professional, despite the fact he wasn't accepted a position as CSO of a Fortune 50 company. If you haven't figured it out.
Now I'm talking about the hack of UnitedHealthcare and their change, um, group that they have. For those of you that aren't familiar with it, UnitedHealthcare is a incredibly large company, a Fortune 50 I believe. And they were a victim of a hack.
And this hack, well should say, one of their subsidiaries was victim of a hack, which essentially shut down the ability for lots of bureaucratic paperwork to be processed in the United States, change healthcare, and that's what they do. And they're a critical part of the US healthcare system facilitating all this healthcare being delivered. And what happened was they were called in front of Congress, obviously after a major hack like Congress loves to do, to get attention for themselves.
And one of the criticisms Senator Wyden actually leveled was that the CISO of United Healthcare, Steve Martin has no cybersecurity experience. And honestly, when I heard that, I'm like, really? And I looked at it and it's g*****n true.
And the problem is I was like shocked at this. So at one level, let's talk about why this is, or actually, let's talk about Steve's background first, and I'm gonna read something quickly. But Steve was essentially the CIO and CTO of Optum Insight at Optum, which is part of UnitedHealth Group.
And by default some, they are the default technology group. The people from there tended to be CISOs, but this guy also served as CSO of UnitedHealthcare. So he was the CIO and the CTO of a subsidiary.
Yet for whatever reason, they made him CSO of the entire company. And you know, you sit there and wonder, didn't he have enough to do being CIO and CTO of another subsidiary? But no, let's add to that role.
And then he literally had no background as Senator Biden. Why, sorry, Senator Wyden said he had literally no background in cybersecurity. And you know, let's talk about, first off, I think the arrogance of taking a cybersecurity position, being CISO of a Fortune 50 company, having no experience whatsoever.
You think, what the hell? And I was a ciso. And look, the thing is, I admit, you know, as a ciso, you don't have to know hands on technical duties of everybody under you.
But having experience over decades, like a person in his position, should you develop your gut feel over time of what seems right, what seems wrong, how can it be improved and so on. And in this case, he had no experience, he had no gut feel, he didn't know how to create a cybersecurity culture. He doesn't know when a, somebody comes to him who you might trust and say, look, I want to implement this.
And he'd be like, oh, um, a good CISO says, you know what? I trust you, but this isn't right. But more important, he didn't create the underlying culture that should allow the organization to be fundamentally secure to drive everything.
And I don't blame him at one level 'cause he didn't know what to do, but fundamentally he accepted the position. That's a problem. But why should a CSO be, have experience?
A CSO has experience because they have over time, they understand what needs to be done, they understand recommendations, how to approach things. They have networks that they build up of peers to go to with problems. They understand when something doesn't seem right.
And it is not totally I ironic, or that he was part of the technology program at Change Healthcare, which was the entity that was hacked before they were merged into UnitedHealthcare. So there are fundamental issues with this, and I don't have a lot of time for these pieces. So I'm just gonna end this piece now and I'm gonna reiterate the fact that yes, there is a problem when a Fortune 50 company doesn't go to dozens, if not hundreds of qualified CSOs with potentially healthcare or related background to hire them for a CSO position.
But they take someone who's just a technologist from another division and say, Hey, we're gonna add this to your role as well. That is negligence on the part of the board. And let me just say, UnitedHealthcare has some outstanding cybersecurity people working for them, and I've worked with them over decades.
The problem is, in this case, they picked a leader of the organization who did not know what strategic direction to set. And fundamentally, you don't just say, Hey, why not? Let me just add CISO to my resume because hey, I'm kind of busy enough in a full-time, in two full-time jobs.
Let me just add a third 'cause it Rick's really cool on the resume. And yes, for that, I blame him because he trivialized the entire cybersecurity profession by saying yes to the request. He could have easily said no.
And he should know dozens of people who could have stepped up for that position to focus on cybersecurity, not do it as an afterthought. So anyway, this is Iver Winkler in this case. I will say, bite me to UnitedHealthcare for actually going ahead and hiring an unqualified person for the most senior cybersecurity role that they have in the organization.
Hey, we're back. Hope you enjoyed IRA's rant. You know, IRA likes to rant, but his rents usually make a lot of sense.
And, and thank him, thank him for doing them. Mitchell Paul that's gonna wrap up our Techron gang today. You know, I, again, this is day before July 4th, right?
We're gonna be, we're, we're closed tomorrow. We wanna have a fresh show. And we're taking Friday off for an extended holiday.
So I wanted to take this opportunity to say, Hey, this is gonna be the 248th birthday of the United States of America, one of the grandest experiments in democracy and freedom and rights that the world has ever seen. And probably like no time other in my lifetime. And in most of our lifetimes, our freedoms and our democracy are being pushed, pulled, tested in ways that I think our founding fathers never even dreamed of.
I think our discussions today reflect that, right? It's, we are more so than, as I said, anytime in my lifetime, we are heading into very uncertain waters. And this experiment in democracy that we live in here in the US is, is under, under pressures that it, I don't think it's seen in a very, very long time.
I, I consider myself a patriot Mitchell Paul, I know you do too, right? And no matter what your political party or persuasion is, we all wanna see what's best for our country. We may have different attitudes of what's best, but we want what's best for our country and for our fellow citizens and what's best for the world.
We live in a worldwide, you know, it's a small world after all kind of time right now. So take a moment this weekend, give thanks that we live under the freedoms we do, that we can have these discussions like we've had today here on Techstrong Gang. But remember that freedom isn't free or there's a cost to freedom and that's your participation.
Participate, learn, educate yourself about these issues and issues that affect you in government because if you don't, don't let, you don't have a right to say what someone else does that and because you didn't partake in it. So I'll leave it at that. Have a happy 4th of July everyone.
We'll be back next week here on Textron Gang, Mitchell Paul, thanks for, for participating and uh, we'll see you all on the other side. This is Alan Hummel. We're out.