Techstrong Gang – June 25, 2024
Alan, Mike, Mitch, Bonnie, Jon and special guest Stephen Foskett, president of the Tech Field Day business unit for The Futurum Group, discuss the arrival of the cloud-native application era. Then, they dive into why Open AI is acquiring Rockset to improve the accuracy of artificial intelligence (AI) applications that make use of large language models (LLMs).
Finally, the gang turns its attention to the move by the U.S. government to ban the sale of cybersecurity software from Kaspersky.
Transcript
Hey, everyone. Happy Tuesday to you. It's Alan Shimel.
You know, are there clouds on the horizon for, uh, cloud native Open AI is now acquisitive and more you are watching Textron Gang. Hi everyone, it's Alan Shiel Techron Group here for another episode of the Techron Gang. It's Tuesday.
We're getting towards the end of June. It's summer. It's warm for many of you, I hope for those of you in the Midwest of the US we, you're not too affected by this flooding and everything else.
But as usual, there's a lot of news out in tech. We're going to, uh, we picked three topics we want to jump in on here today. But before we do, let me introduce you to the, to today's gang members who are in attendance, first of all, joining us.
Well, he is back home in, in, uh, Colorado. He is a, uh, he's, well, he's the CTO here at Techstrong, as well as a Chief Technology Advisor with the Futurum Group one and only Mitchell Ashley. Hey, Mitchell.
Did I get that right? You, you, you can introduce me anytime, Alan. Of course.
Okay. Good to be with everybody today. Absolutely.
Next, joining us from way out in the West Coast. Well, the West Coast, it's not that way out, but he, he's an editor here, ed Techstrong and, uh, newly minted editor at Techstrong, but well known in in our field. It's our friend John Swartz.
Hey, John. Welcome. Hey.
Hey, Alan. Good to be here. Okay.
And speaking of Midwest floods, I don't, I hope he's not getting anybody where he lives, but, uh, he's also the founder of Tech Field Day and Gestalt it, and he's a certified tech strong gang member, Steven Foskett. Hi, Steven. Any, any floods out by you?
Everything. Okay. Well, it rained cats and dogs yesterday for a little while, but then the sun came back out, so we're all right.
We can handle it. That's that Midwest attitude of you gotta love it. We can handle it.
All right. And joining us here in the, uh, studio, to my immediate left, well, it's easy to tell the two apart here, but to my immediate left is our Echo Insight Analyst and Sustainable it editor, Bonnie Schneider. Hi, Bonnie.
Hi Al. Welcome. And then on my far left, well, it was a bad weekend for the Yankees, but I won't say anything Yankee wise, but it's our Chief Content Officer, Mike Ard.
Hey, Mike, good to see you as always. Good to see you. So, state of cloud native.
You wanna pick this one? Yeah, we, in the Last say six weeks, there's been no less than five different studies put out about the adoption of Cloud native and Kubernetes and all the things that's going on around that. I think a lot of it was tied to the 10th anniversary of Kubernetes, but sometimes I feel like when you're looking at one research report, it's kind of like looking at a keyhole and trying to see what's on the other side of the room.
And when you get five of them, suddenly you get some, uh, visibility into this. And what's interesting is it seems like Kubernetes has finally maybe crossed that proverbial chasm in the enterprise. There's enough clusters out there to suggest that, um, the default option now for new applications is to build them in a cloud native format.
There's a lot of mixed stuff out there. There's still a ton of, um, monolithic apps out there, and a lot of complexity and a lot of challenges to deal with. And of course there are always security issues.
But Steven, let's start with you. Is it, is it your sense something is going on here? I feel like this has kind of been a trend that we've been talking about for half a decade.
What is it finally happening? Well, isn't that funny how things like this, uh, happen and, uh, things like this kind of get real, you know, you, uh, you, uh, we all get excited about new technology. We're all excited about the possibilities.
Uh, you know, we get all hyped on the, on the buzzwords, and then things get real. Uh, you know, you know, people start realizing, uh, what things can and can't do, and the reality of moving applications from, uh, conventional infrastructure into Cloud native. And, uh, you know, we saw that happen with virtualization.
I think we absolutely are seeing it. Um, you know, first off, uh, I'll have to say there's remarkable consistency across all of these studies in terms of, uh, you know, the numbers, the, uh, approach, the embrace of Kubernetes. But the fact that, uh, uh, real, uh, enterprise cloud native applications, microservices applications is lagging.
Um, but I guess lagging, who lagging what, um, does anyone really expect enterprises to wholesale move everything from conventional monolithic apps to microservices based cloud native apps in just a couple of years? Of course not. Uh, that being said, they are absolutely an adopting Kubernetes.
Uh, we've been seeing this as we've been going to CubeCon. I know that you guys are there. We are, you know, tech field day's been there, we're gonna be there again.
Um, it's become the new VM world. It's become the new enterprise, uh, application, uh, conference because that is where enterprises are going. I think there's been a lot of buzz about, oh, you know, VMware, Broadcom, you know, which, which virtualization platform do I switch to?
Frankly, that's the wrong conversation. Uh, everybody's going toward Kubernetes. And not only that, but people are embracing multiple Kubernetes.
They're embracing, embracing multiple, uh, platform as a service. And, and yet it's taken them a while to get there. For me, I think the big question is, are the applications being deployed on Kubernetes truly cloud native apps?
Or is this just another vSphere? Are they basically containerizing monolithic apps and putting 'em up there and calling it kind of done for now? Or Mm-Hmm.
Are we gonna see real adoption of cloud native? Mm-Hmm. So we used to call that cloud washing, right?
Be when you would just take your old app and shoub it up on the cloud and, and cloud wash it or lift and shift was the other. Yeah, it wasn't, yeah, it wasn't taking advantage of the cloud. But look, here, here's the deal.
The war over what is the right infrastructure to use for greenfield projects, for new applications was for, and one years ago, I think whether you look at AWS or Google or, or Azure, Azure, um, something like 75 or 80% or more of new applicant, brand new applications are done on a cloud native containerized infrastructure. The real as it always is, where wars are won and lost is in the brown, muddy fields, right? And that, that's, to your point, Mike, that's what's happening is do I want to convert my monolithic my old application that works okay to a multithreaded, you know, cloud native, native kind of application.
And that's a big job for a lot of these companies. And if there's not overwhelming advantages to doing so, they won't, that that's as simple as it comes. But two, two clouds on the horizon for me when it comes to the cloud native stuff.
Number one is Kubernetes is still way too hard. It's just hard. And, and number two, though, they've made some progress.
Number two, the bigger issue is open source. Because as much as cloud native is sort of the new VM world, or, or is the new VM world, what drives that event is the open source community. And the open source community is under siege here on a couple of fronts.
The biggest thing is on security. This, this, uh, was it the X, Y, Z or X, YXZ? Yeah.
XZ has everybody thinking, are there sleeper cells? Are there time bombs in my open source project that I'm using, number two, the commercial viability of open source models. When you have companies like Hashi and Red Hat and others who are changing their licensing, it's, it's creating you.
Now, we had a report from Mitch last week or yesterday actually on suse, right? They, they seem to be filling that vacuum because they're kind of that classic open source model. But the whole open source business model, I think is, is being questioned right now.
And those are the kinds of things that I think can undermine this whole cloud native infrastructure, because the cloud native stack is an open source stack, right? Make no mistake About it, Mitchell. There's a lot to unpack there.
So let me ask you a couple of questions. If I take a monolith and I containerize it and I stick it on Kubernetes, a lot of folks are just calling that a big ass microservice, right? And they're just kind of looking at it and saying, everything is kind of a microservice, it's just a question of size now.
And over time, I will take the monolith and chop it up in the microservices when I'm good and ready. So is the whole argument over software architectures just become, to his analogy, a a muddy brown field, and we're just using stuff where we feel like we need it? Well, I, I, I think the way, you know, Alan described it of greenfield, sure, you're gonna start out cloud native, meaning you're gonna do containers, you're gonna look at microservices, maybe service mesh, right?
You're gonna build it in sort of a modern contemporary architecture. But that's very little of the world that most enterprises work in. And they rarely, even in modernization efforts, don't replace whole applications whole scale.
Not, not across the board. Those are major tasks. I can't tell you the number of, uh, new billing system projects.
I worked in telcos, uh, you know, every three years there was a new billing replacement project, and none of 'em ever lasted very long. That's why they get occurred every three years. It is hard to justify replacing an application to change the technology that it's using.
Even just an underlying database. It doesn't make sense to do the makes more sense. And whether containerizing things is a really easy thing to do.
'cause it's a packaging concept, you know, it's delivering the app and everything that it needs into, into one container. Okay, great. You've got it containerized At least, at least in one or maybe a few.
It's not a microservice, it's still the same monolith application. But what what makes more sense is 99% of that app may need to just kind of stay the way it is. What it's doing is, okay, that's not what we need to fix.
That's not what we need to modernize. We're doing business differently over here. So go build in a cloud native with microservices, containerized, et cetera, build that new functionality, and it talks to the old monolith application through its kind of, uh, external, the m and m external APIs, right?
Kind of in and out. And that's really what its APIs do not inside the, inside the app and build the, the functionality that you need to get it out faster. Uh, iterate on it faster, maybe develop more capabilities that you want in that, or multiple applications.
So you live in this hybrid world, and we don't talk about that in, in, uh, in cloud native land. But that's really the land that enterprises work in. And so I think that's why the other reason why you see Kubernetes being adopted so well is how do you manage all this stuff?
You know, okay, now I got a thousand, 10,000 more than 10,000 containers. How do I, how do I operate this stuff? That's what Kubernetes, Kubernetes does very well for cloud native applications, but people manage their, uh, DevOps tool, chain pipeline using Kubernetes for the different parts of it.
It's just a easier, better way, not only to manage it, but scale it and use some of the advantages of, and those aren't cloud native apps. That's just infrastructure, the new VMware to, uh, Steven's Point. Yeah.
And, uh, to Mitch's point here too, um, absolutely. You just don't see people taking, um, just, just completely rehashing the entire enterprise application environment. It, it's not gonna happen.
I can't think of any enterprises, especially large ones, you know, banks and those kind. They, they, they just, they haven't rewritten some of their applications since they were deployed decades ago. There's gonna be mainframes, there's gonna be open systems, there's gonna be virtualized apps, there's gonna be, uh, uh, cloud native apps, and they're all gonna be working together.
I think that's just the practical reality of the situation. But lemme tell you, speaking as an old school, cis admin, containerization, love it. Absolutely love it.
If I was deploying an application today, it, would it be in a container? Absolutely. There's no way I would deploy anything without it.
We have seen this buzzword application modernization for decades now, and if I listen to those guys, it's not really happening. So do people go back into modernize applications or is that kind of like an exercise in maintenance? No, no.
So I, Mitchell kind of dead on. I i, you don't need to, you only modernize what you need to. So we're seeing this a lot in mainframe applications, right?
Dollar for dollar, penny for penny. It's hard to, to do better, you know, be more efficient, more secure than the mainframe. However, a lot of mainframe applications are bifurcating into systems of records and systems of engagement where I want that stability, security, performance on my systems of record.
But for engagement, I wanna be, you know, I wanna a, a an interface for the following and for this and that. And I, I'll keep that front end, if you will. I'll put it up on the cloud.
And if I'm doing that and I'm putting it on the cloud, I might as well multithread it and use Kubernetes and a cloud native infrastructure to do it. And, you know, kudos to the modern mainframe teams with like Project Zoe and stuff like this, where you actually have, um, the ability to do that and, and have them talk to each other pre, and it's a pretty cool thing. So that is a form of that modernization.
Now, there are other people when they talk main mainframe at modernization, who really means let's move off the mainframe. And there's, you know, there, there's a segment of the market that does that's gonna do that too, I guess, um, though, if you've already invested millions, if not billions of dollars in mainframes, and who the hell wants to do that? But I think the point, Mike, if I could grab a bow on it, is business does what it needs to do.
When it needs to do it. No one's going to, or very few people are gonna multithread their application and modernize it, just 'cause it's the cool thing to do this week. It it, if it makes sense, they'll do it.
I, I, and I've said this story before, caveat to that story, Hertz, they moved to this beautiful new world headquarters here on the west coast of Florida near Bonita Springs, and I don't remember the name of the town right now, but they decided they were gonna move to the cloud and they just, rather than migrating, built from scratch new cloud apps, and once they turned the lights on those, they shut the lights on the data center app. And they did, you know, and they touted this as the way to go. There wasn't really a migration per se, it was a clear, you know, bifurcation old new, and that went well till they went into bankruptcy and they fired that CIO.
So, you know, there's your experience, Stephen, one of the surveys points out to the prevalence of Java in these new cloud native application environments. And, um, do you think Java's gonna be with us forever or is Java kind of the new cold ball? And this is the thing that we're eventually gonna replace as part of this motion?
I mean, um, is Java here with us forever? I would say that Java would, uh, surprisingly, Java is probably here with us for a long time, and one of the reasons for it might, uh, be, uh, shocking to people who love to dismiss things as old technology. Uh, Java lends itself really well to app modernization, and there's a bunch of companies in the app modernization space who've come up with really excellent ways of converting monolithic Java applications into microservices.
Frankly, I think that could be low hanging fruit doesn't mean they're moving away from Java, but we could end up with a new Java renaissance here in terms of Java powered microservices. Mitchell, I want to throw a wrench into this. If I look at some of this AI stuff, one of the things that's interesting about it is it makes it a lot easier to reverse engineer an existing application.
And I think it was, uh, AWS was talking about, uh, rewriting an entire Java application inside like, uh, two months or so using AI tools that they have. So are we maybe underestimating or overestimating what it might take to rewrite a lot of this stuff in the future? And we will modernize, Uh, crawl, walk, run, Mike?
We we're not anywhere close to being able to do that. Yes, we can give, um, AI copilots and being ai, you know, code and say, rewrite this code and add this to it, and they will do some interesting stuff to you. But it doesn't design systems.
It, it doesn't design architectures. Um, be today, will it? Sure, of course.
I think it absolutely will and it will be a major, major aid, if not driver of, of a lot of what we do down the road. We're just not there yet. So, you know, like the CCIO who suggests we need to replace all of our apps with rust tomorrow.
Um, you know, that's a pretty tough sell because they won't be around here for the second budget cycle, I promise. Well, it's certainly not the third budget cycle. They won't be here.
Um, Java is here to Stage J is a fine language. I don't know the percentage of applications that are written in Java, but it's massive. Whenever you talk to enterprises, you talk to j you, you talk about Java, they have large implementations of Java in most cases.
Totally. And like you said, it's, it's a modern language. I mean, it, it is, uh, more object oriented and written.
It's not like, you know, some COBOL app or something written in a really ancient archaic language Somewhere. Scott McNeely is smiling And a guy named Gosling is laughing. Yeah.
I wanna I wanna ask you one other question about all this. We've talked about platform engineering in other shows. I somehow feel in my mind that platform engineering becomes the thing that we use to kind of make Kubernetes and all these things more accessible.
You hear people talking about internal developer portals and you know, are they two sides of the same coin? This whole shift to cloud native and Kubernetes and platform engineering, they all go together. Um, they can, I don't know if it's peanut butter and chocolate.
I, I think, I think platform engineering, the job of platform engineering is almost to abstract out all that stuff from the developer and leave the developer to develop, right? And the platform engineers creates that platform. Whether that platform is cloud native or, or something else.
I'll leave it to the platform engineers and the architects and the business leaders to decide what's best. What About, um, energy efficiency and does that go into the motivation as terms of modernization with apps? It seems to me that it is.
You know, I don't, uh, that would be an interesting thing. 'cause I don't remember seeing a lot of surveys over the energy efficiency of a multi-threaded app versus a monolithic architecture. Yeah, there's, there's research in that space and there's certainly a lot of applications that are not very efficient in terms of how much heat they generate.
But whether that's gonna drive or rewrite, I'm not sure. But it's an interesting thought. Okay.
Like I said, we will see a big migration to multi-threaded, you know, cloud native stuff when it makes dollars and cents to do it, and not a second before Our new, uh, DevOps next report will have something to say about this. 'cause we asked about, uh, for efficiency, for con energy conservation, other reasons, what, what areas in your organization are, do you have programs around that that fall into DevOps, platform engineering, other things like that. DevOp, uh, platform engineering came out quite well.
So we'll share some more results of that with you pretty quick here. Hang in there. Now Ops next is coming actually more on platform engineering too, but we're gonna take a break here on Textron Gang.
We've got a lot more to cover open AI acquiring companies, that that's a seminal kind of time shift right there. You're watching. com is the number one online destination for DevOps education and community building.
com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com where the world meets DevOps. All right, folks, we're back. And as Alan hinted, suddenly we are talking about that Three, We are talking about Open AI has acquired Rock Set, which is a provider of, uh, databases and some tools that are used for, uh, rag, which exposes data to LLMs.
And John, you wrote this story, so we're gonna go to you, but one of the things that struck me as odd about the whole thing, or at least interesting, was that a company that is in the AI LLM spaces learning how to spell enterprise. Yeah, exactly. That's maybe the way open AI distinguishes itself in this, in this race, right?
So we have this race, we talked a few days ago about anthropic and how they're ratcheting up the speed and we kind of made this, um, equivalency to a space race. But I mean, what's more interesting to me, and I think what's been picked up by OpenAI is you wanna build out your enterprise elements in a sense. Uh, something that Mish told me was that generative ai, large language models cannot rely solely on throwing G-P-U-N-P-U and for processors at them to meet this kind of, the growing demand for Chad GBT of Open AI must pursue accelerators like Rock said, as Mitch said, to add vector databases, streaming and data lakes and other performance data services to deliver.
So open AI, in a sense, sees an opportunity, and this is very significant in terms of their acquisition because not only do they acqui they acquire the technology, but they are bringing people within the company, which is a little bit of a departure from what they've done before. Uh, it it's gonna be interesting, we're gonna see two tracks in generative AI race, one involving speed, which is understandable, but the one that's probably more significant, I think Mitch would agree, is building out within your model the applications that apply to enterprises who are ultimately your customers. Enterprise, enterprise enterprise, John, right?
This is the maturation of gen ai, part of that progression. Um, it's not just about APIs. Yes, you have to be able to do that, but what, what Rock Set brings, and, and I've talked to, uh, Venkat Ramani I believe is his name is the CEO, and he and another co-founder came from Facebook, and what they brought with them is very high speed data retrieval and how to do that effectively.
Now, you might say, well, I thought that was vector databases. Well, vector databases are just like one kind of, you know, high speed retrieval. So there's all kinds of an analytics and, um, kind of data driven architectures that they've got that is applicable through Rock Set.
So I think of it as what they're talking about in integrating that within Open AI's capabilities. So think of it as I don't need to go get another data, an analysis or high speed, uh, query type tool, um, that, that is gonna accelerate my ability to utilize this LLM or a small language model or augment it with other data in and out, which is another thing, by the way, rock said does really well, is ingest the data very quickly. Doesn't that doesn't have to go into the LLM.
So think about how our modern AI applications of these hybrids, right, with language models, with high speed analytics, high speed data ingestion and retrieval, and you know, APIs built around that. That's what the enterprises are driving open AI to make an acquisition like Rock said. What?
Oh, I'm sorry. Go ahead. No, I'm sorry.
I'll be really quick. One other thing that was interesting was that I think there's been a report out that OpenAI is developing a search engine product to compete with Google and Perplexity. So there's there's that as well.
So, um, yeah, I just wanted to throw that out because I I think it's significant. Absolutely. Well, I think it's, yeah, it's more than, and it's the, the answer is it's more than typing in natural language search in, right?
That's part of the access to, to generative ai. But applications don't always talk natural language. So, you know, I'm, I'm reminded of, I I, I guess it was 10 years ago, eight years ago, Docker, man, Docker was raising money at Crazy Valuations.
They had the world by the, by the straight, I guess is the terrible use. Um, and, and they started being inquisitive. They started acquiring a lot of companies within that ecosystem that had grown up around dockers core offerings.
And in many ways it kind of was like eating your young, because what happened was, is when Docker would buy a company, all of the other competitors within that particular niche were, were rendered obsolete because you, they couldn't compete with Docker itself, with the mothership. So what became a very healthy ecosystem, quickly kind of withered on the vine and Docker suffered as a result, right? Um, same thing here.
They bought Rockside. Okay, what about the rock set competitors? Now they say, well, there goes our open AI business, we better go mosey up to Anthropic or Google or, or Lam or whoever, more Acquisitions to come.
Yes, Well, it, but it's eating your own young and you wind up. That's why we talk about Cloud native and Kubernetes and not cloud Native and Docker, right? And, and so I would caution open AI and yeah, you want to acquire that kind of technology, but you gotta be careful you don't eat your own young and destroy your ecosystem.
Don't you think we're kind of in this hedonist acquisition phase, Alan, of investing in, in, uh, startup companies buying everybody's gobbling up something that they're gonna need in their, their toolbox for ai, right? Yep. Steven, I'd love to get your opinion on this.
'cause one of the things that Rock said is saying is that, um, the value of its approach is that it enables the search and the query to run in parallel against the LLM and the separate database versus, um, what historically has been the LLM runs through its own data first, and then it reaches out. And what Rxi is saying is their approach will reduce hallucinations because we will be able to, uh, have a better, more trustworthy set of data, shall we say. Um, is it your sense that the AI guys are trying to figure out ways to reduce those hallucinations to make themselves more relevant in the enterprise?
And this is kind of core, Well, a hundred percent, a thousand percent, million percent now a hundred percent is all you can get. Um, yes, absolutely. Um, I've said it before on Textron gang.
I'll say it again today. Uh, LLM is user interface. It is not the end of the application.
LLM is fact not an application at all. It's a feature. And if, uh, you know, a lot of people have criticized OpenAI in including, uh, Google themselves criticizing themselves and OpenAI with regard to, um, LLMs because, uh, basically there's no moat to an LLM, uh, everyone.
There's, there's a new LLM all the time. OpenAI should be commended for trying to build some kind of a enterprise moat, enterprise momentum here by integrating data, this whole trend toward retrieval, augmented generation or rag. I think that's the answer.
Because essentially you can have, uh, the LLMB, the user interface to a, uh, an enterprise data set, or as you guys were saying as well, to a search engine data set. I mean, the nice thing about, uh, rock set is that this company specialized in vector search and, uh, vector databases are the primary database interface that LLMs need in order to integrate real data, not made up data, not fictitious, whatever. The AI is gonna come up with data.
And, uh, absolutely that's what this is all about. Uh, I understand what you're saying, that theoretically this could be, uh, challenging to the ecosystem. It could be, uh, this, it could be that.
But ultimately what I see here is that OpenAI is admitting what I think they certainly know and what the rest of us probably see about this market. And that's, that there is no market until you have a real application, a real product, a real useful tool, and not just we're we're just playing with a toy here, we're playing with this LLM ultimately, you cannot have, even if you have a gazillion, uh, parameter, I just made that up, you know, LLM, it will never know everything. In order to have an LLM that is useful, that doesn't have hallucinations, you need to have it integrated with external data sources and more to the point in the enterprise especially, but frankly, outside the enterprise too, having an LLM that can query actual data sets and bring and expose real data is really useful as opposed to the toys that we're playing with.
You know, Steven, I I, tell me, tell me what you think about this. I think we've made the mistake of thinking as an an LLM as a database, you know, it, it's request re, you know, send back response. Like we would retrieve data out of a database and I'm, I'm not gonna, I'm not gonna query the LLM from my account balance on my, you know, on my 401k, I'm not gonna trust that it's accurate.
That's gonna come out of a different database, out of a different system. I don't need that to go through an L and maybe I use a natural language, you know, query to do it. No, actually, I probably don't even wanna do that in most cases.
So I think it, it's just recognition of the new shiny object. We can't put everything in it. There are some things that belong in it and some things that don't.
And that mix of all these existing databases, high retrieve, fast retrieval mechanisms. By the way, I don't have enough compute power to put it all into an LM anyway, so it, it's just, to me, it's just being more mature and realistic about how we use generative AI as part of our architecture, not as the only thing in our architecture. And we look at an lm, an LLM is that annoying kid that, you know, that always has an answer for everything.
You know, you're like, you know, Hey, check out that cool motorcycle. And he is like, well, that's a 1958 Harley, you know, and you're like, really? Really?
And then eventually you realize that he's, it's just pulling that, yeah, he does know a lot about some things, but he doesn't know everything about everything. Send that kid to college, get him a library card, you know, have him look things up and suddenly he becomes a useful member of society. Well, let me, let me ask you this.
Are we at the, looking at the wrong end of the gold rush here, because it feels like to me, we're looking at LLMs and looking at all the miners and the people driving into cashing on that, and yet the folks who made all the money were Levi selling shovels and shovels. Yeah. And the database guys seem to be the shovel makers for the LLM, Um, today.
I mean, but you know what's interesting? I've friend John Willis and Patrick Dubar and all those folks we had in for the hackathon on operationalizing ai. It's almost a year ago.
It was August of last year, by the way, that that whole, there's a great team, a great, uh, video recap of that on Techstrong tv if anyone's really interested in this subject. A lot of stuff about LLMs. Um, I think once this matures a little bit, the LLM may not be the dominant data source for most AI workloads, right?
You're gonna have s SLMs and you're gonna have other data sets that are not these urvan, what did you call 'em, Steven? A hundred gigabit or a gazillion gigabit? Uh, well, I'm, I, those are unwieldy.
And, and I don't think they're going to, you know, you, you need that maybe as your baseline, you know, universal standard. But most ai uh, workloads are going to use highly specialized data sets or, Or give you the opportunity like the perplexity where you have choices of, of which one you wanna see, to see who's hallucinating, who isn't. It's kind of like what Steven was saying.
Instead of having one friend that knows it all, well, let's have a group of friends and see who really knows the most. Uh, so Steven, does this make you laugh a little bit? It's 2024, and we're having the same conversation we had in the 1980s.
It's about the data stupid. Hey man, I was in high school in the 1980s. I don't know what you're talking about here, but it's, but yes, it is, it is about the data.
It's still about the data, and it'll always be about the data. Absolutely. We need, uh, we need a panel of experts, not just one expert that tells us everything.
It's always about the data. Um, I'm trying to think. I wasn't in high school.
The, I I was in college and actually I graduated in college in the early eighties, but Eddie went too. Um, all right. I think that, I think we beat this one to, to a fairly well, we're gonna take a break here on Techstrong Gang.
We've got, you know, poor Kaspersky, or maybe not poor Kaper Kaspersky. Let's, let's see what happened here. We'll be back.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com, home of Security Bloggers Network. And we're back.
And if you've been around cybersecurity at all, you've heard these conversations that have been going on for years. I, following Kaspersky Software and its ties to the Russian government, which it denies and has denied for more than I can remember. But, uh, department of Commerce and the Department of Treasury got together and basically said, we're banning that software and we're sanctioning, I don't know, eight or nine of their executives.
And this whole thing has suddenly become a much bigger deal. Let's start with John. What's your thoughts on what's going on here since you know, you've been around this conversation as long that Yeah, Uh, yeah.
I've been exposed to these guys for about two decades, and, um, you know, first of all, it's an election year, right? Yeah. So we have the TikTok ban, and I'm not ordinarily, I'm dead set against bans, but the thing about the Kaspersky Labs was e even dating back, I went to one of their developer conferences in St.
Petersburg, and this was almost 20 years ago. And there was a lot of speculation about the ties, not only to the government to organize crime, not just Eugene, but his ex-wife, who is an executive at Kaspersky. I don't wanna slander anyone, but it was very, very mysterious.
But please don't. No, no. Yeah, I don't even want, don't, Steve, they just parted here.
I don't wanna, I love this show. Um, but, but under Russian law, right? The government has total access to Ksky systems and therefore access to all of its customers.
Kaspersky made a huge push in the US market 20 years ago, and actually had a fair amount of success. So what the Biden administration is doing, in a sense, is probably something they, they feel they have to, um, they don't want, uh, the Russian companies like Kaspersky to exploit our data, et cetera. And also, it's an election year.
Mm-Hmm. It, it's, to me, it, it's interesting because again, we go back to the history of Kaspersky, and I saw some things that were very interesting and, and kind of frightening around this company, and there's always been an element of fear around them. I mean, this is on the, the political and cultural side.
Um, getting into the weeds, I think Mitch probably would do a better job of, of explaining how rational or how legal this is or we're trying to do to them, or what, what our government's trying to do to them. Well, it, it, thanks, John. You gimme me a lot.
Credit. I didn't mean to do this to you, sort of, but, uh, No, no, that's, no, it's sort of like, kind of the, what comes to mind is, duh, you know, does the Russian government know everything that's happening in Russia? If they don't, they can find out, right?
Or control it. So, of course. So I mean, just put the pieces together.
If we're concerned about our critical infrastructure, concerned about everything from every, you know, every device that's, uh, running some type of anti-malware. And if it was, if we had a large installed base of Ka persky, just think about how easy it would be. Let me send out a few new updates, signatures, or what, whatever it is to, to the malware, uh, updates to those agents, Russian agents running on your computers, and suddenly, you know, we, our defenses are down, right?
Or at least in terms of, uh, uh, a pathway into a lot of our computers. So, so many of us at the time when kiski started kind of getting ratings in the magazines and PC world and, uh, the different places of, yeah, it's a good one. It's up there, you know, with clam maybe and all the different, you know, other ones.
At the time it was like, yeah, but why would I wanna do that? Do I really want to, you know, be the, the next Kevin Mitnick kind of, uh, wall Street Journal story? No, I'm not gonna do that.
So I think most organizations have said, yeah, this, if it's, if it's anywhere, it's in the consumer world. I can't believe many, um, enterprise business organizations are running it. Or at least if they don't, they're not thinking twice.
So it, it's just a whole vector. It reminds me of the Huawei situation. If you think back a few years, not that many years, maybe, uh, um, probably about eight, 10 years or ago or so, all the Huawei equipment, um, uh, coming from China and have chips in it that we don't know what they do, are those back doors into everything.
It's, you know, of course a company that, um, partially owned by the Chinese government. It's the same issue. Again, it isn't a, it isn't a free marketplace with unfettered in no strings.
Some things come with big strings attached, and is that worth our national security risk, uh, to put that at risk? So I'm gonna take a contrary position here. Surprise.
First of all, we're a nation of laws, right? And the last I checked, you're innocent until proven guilty. Now, 20 years ago, there was a very different political climate between Russia and the us, right?
It was, uh, it was early two thousands. I don't even know, maybe Putin had already come into power, but it wasn't what it is today. What we're seeing here with Kaspersky is pure election year politics at its worst, right?
And, but I do applaud the US government for at least being proactive in this and saying they're doing it versus what they've done to checkpoint software for 30 years, which is the whisper was always don't use Checkpoint because the Mossad has a, a, a back door into your firewall. And, and so, and Mitchell, you know, this, when we sold security into the federal government, checkpoint was kind of a no-go because of the rumors of that. Absolutely.
Now, in, in the case of Huawei, it was, well, we actually had I think, more proof that, that there were, there was absolutely, um, it was more than just the connection. There was real proof that these chips and, and, and back doors in the Huawei, uh, hardware. Now, in, in the case of, I've, I've dealt with Kaspersky for years too, and I've seen them in enterprise accounts.
I thought there was something at some point where they had migrated a lot of their databases and stuff to the US in the Russian government, still have access to it. Absolutely. Can the Russian government still have access to a lot of companies that aren't based in Russia?
Let's not be naive. Let, let's, this is election year politics at Yeah, exactly. There's been a concerns in 2017 and now in 2024, right?
The war in Ukraine and pressure that Biden probably feels on an, on the international stage, especially for mm-Hmm. Opponent a little suspicious. I mean, 2017 this's been going on, John, you said, I know, three days, 20 years ago.
Do You think this has anything beyond politics? 'cause Putin is in North Korea and signing a defense alliance with those guys who happen to be some of the most Yeah, very well they hack for a living because that's their national gross national product Exactly. Is what they can, you know, steal.
But, but that's what this is about. Let's be clear. I I, I think the real evidence of Kaspersky, uh, being used that way is that I, like, I haven't seen real incidents where you can say they, they put a fake update in, or they did something is the potential their year.
Yeah. But you know, this is, let's close our borders and stop immigration because there could be terrorists in there, or drug dealers or child pornography or something else. We're a national laws.
If you're not gonna, you, you and, and you at some point, you gotta put up your evidence. I don't have the evidence. I don't know that we're ever gonna see the evidence of this Allen.
I mean, we're not talking about, um, you know, industrial espionage here. We're talking about nation state security stuff. And frankly, um, I, I think that what you just described actually is the reason for this not, uh, refuting this.
If you're in the US government and you are looking at a product that is known to be a pretty good product, very widely used in enterprise and business, you know, you have to decide whether this is something that should be used in national security sensitive places. And frankly, um, the US government has always been, and when, I mean always, I mean like 200 years, always been skeptical of non-native born people and non-native born solutions and so on. I mean, remember, uh, the, you know, requirements for being the president here.
Uh, but it goes beyond that. If you've ever worked with, uh, the intelligence agencies, you know, that they are very skeptical about using, um, even people who, uh, were born outside the United States. Um, it, it, they're just being cautious.
I, I will say yes, is this election year stuff, yes, but it's also not announcing it now is election year stuff, but having this, having gone on, I mean this, it's been banned for seven years from the federal government, from federal government use. So then what's the story here? Well, the story there is honestly not much of a story here, except that they're finally saying what they've already been saying behind closed doors, which is, you know, no matter what the intentions of the people at Kaspersky are, they're still connected with Russia.
Putin has a, you know, brutal fascist control over everything in that country. And even if the entire company wants things to be secure and wants things to be open, ultimately they may not have that choice. And I think that that's maybe what's being said as well about other software and hardware solutions from other countries.
I don't think that it means that Kaspersky himself is necessarily a bad person, but frankly, it would be pretty easy for Putin's goons to get in there and mess around with it when the time comes. And better safe than sorry, when there are alternative solutions. I think it's more than just politics though, Mitch, I, I gotta do this when the rest of the world does this to our products because we're just as bad as any of them on many of this.
Let's not hit ourselves. Well, let's not both sides. This.
Don't, don't cry and scream what talk to Iran about the centrifuges at their nuclear plants. Okay, Israel might have planted it, but that was built here, right? That's, that's Geopolitics For you, baby.
And if Iran doesn't block Israeli software, then they're stupid and they're not stupid. It wasn't Israeli software. John, let me ask you, so of, are you worried that this is all gonna break down into geopolitical commerce?
Because I already already know already. Yeah, it already has. Alan made some really good points and Steven as well.
I mean, it's just, it's inevitable. And maybe there'll be another comp, another, uh, foreign based company that's gonna be scapegoated, right? In this es war of escalation.
We talk about gen generative AI speed escalation. We then, here we have speed escalation in terms of taking part, see you November. It maybe in kind of even stepping back, bipartisan, uh, viewpoints of tech are, are, are pretty consistent now, from the extreme left to the extreme right, tech is the great whipping boy, the pinata.
You can use it for any type of topic you'd like right now, and you'll gain points among the electorate. So, um, and it's Gonna change as, as the, as The different administrations change and different political opinions become, um, you know, more whatever it is of the main, I I think different, different companies then potentially could be on the receiving end of it. Yeah.
It's kinda a xenophobic, almost viewpoint. Hey, you know, also even go back to all this, a regulation or antitrust talk, it really started with the, the Trump administration, right? That was June of 2019 and it's been accelerated by the trumpet, by the, by the Biden administration through DOJ and FTC.
So we're, we're seeing elements of this across the board, and it, it applies to some of the US companies. So internally, I think it's also part of an onshoring, you know, it's the, the chip bill, right? Yes.
Things back to the us I think that's, that's part of it too. Supply chain. Yeah.
Supply chain and, and, and agree with you. It's, it, yeah, it's election year. Of course everything's about election year, right?
But it, it is, It does resonate with, with a lot of the voters. I mean, I live in a district that's heavily Silicon Valley. Uh, and the candidates who are running have intentionally not talked about their policies out of fear of upsetting the companies, but they also don't want to show a support to the, of the companies because a lot of their constituents have a lot of complaints about privacy, around privacy, around escalating housing costs, et cetera.
So it's kinda this fine line, you know, on a national level, it's, it's okay to blast tech, but, um, you know, we'll see more of this. They may not want, want their own, uh, practices being disclosed either. Who knows what they did in their complaints, right?
That might be controversial. Now that Wasn't, we had Apple in China. I mean, we can go down that road.
Yeah. So, So one of our presidential candidates thinks that he's a good friend of certain leaders Of North Korean leaders. Yeah.
And So does this go all go all away if there's an election and one wins? No, it never goes away. And, and I think for whatever reason, right or wrong, tech will continue to be, big Tech will continue to be the whipping boy, even though it's probably, well, it's probably one of the greatest success stories of the American economy today, but it is what it is.
Anyway, we, we are out of time. I'd love to talk about this all day though. 'cause I, we're even after the show built on immigrants and I, Stephen, I have worked with intelligence agents agencies, and I'm just gonna say that, and there were plenty of immigrants there too.
Um, right. I mean, so that same candidate that you mentioned actually wanted to pass something that if a foreign person comes here into college, they're automatically given a green card. And I am not a fan of any particular candidate, but I love that idea.
By The way, that same candidate doesn't use email either. So Yeah, kinda mo I'm the conversion, Whatever it, it eliminates to Paper Trail, Mitch. Yeah.
Anyway, look guys, we got a call, a break here. Otherwise, we're gonna run into the rest of a great line of, of Tech Drug TV today. We'll be back tomorrow.
We'll, maybe we'll continue this, who knows? Or we'll have a, we'll have a bunch of new gang members tomorrow and, uh, more stuff to, to, to talk about. Hey Alan, just to plug, today is the day, um, my exclusive interview with, uh, Chris Bets CISO at a Ws Playing on Text Drug TV today.
So check it out. You can watch it on demand if you go to text drum tv, just like every other thing we do. Until then, though, on behalf of Steven Bosket, John Swartz, Mitchell, Ashley Bar Schneider, Mike Ard, and myself, have a great day everyone.
You just watched Textron Gang.