Techstrong Gang – May 2, 2024
Alan, Mike, Bonnie and special guests Daniel Newman, CEO of The Futurum Group, and Chris Blask, discuss Oracle’s move to Nashville from Austin. Then, the gang dives into how Docker Hub became a vehicle for distributing malicious content before trying to make sense of the Federal government’s efforts to improve cybersecurity.
Transcript
Happy Thursday. It's a busy Thursday too. Oracle goes country.
Docker hub has another security surprise and AI insecurity, security. I don't know yet. You are watching Textron Gang.
Hi everyone. Happy Thursday to you. Alan Shimmel here at Techron or Techron Gang.
We've got a loaded gang today with people from all over the place. Let me introduce you to who we have, first of all, joining us. I think from a foreign country, perhaps.
Uh, well, Canada. Anyway, it's our resident cyber expert, the one and only Chris Blast. Hey Chris, good to have you on.
Good to see you folks. Are you, are you in Canada now or? I'm in Canada, yes.
In the studio in Canada, yes. Fantastic. Thank you.
Chris joining us from New York where we're actually grabbing him before he goes on CNBC or some other chat actually. Where are you going today, Daniel? Yeah, I'll be down at the, uh, New York Stock Exchange today.
Uh, doing a number of interviews. It's Fed Day here, so we're gonna be talking, you know, fed and tech, and then I'll be, uh, all over the city because it's been a big wave of tech earnings. And of course, uh, I think we'll talk a little bit about one of those, uh, big names that isn't reporting this week, but, uh, one of the big clouds for sure.
Sure. So that's Daniel Newman, CEO, founder of Futurum Group, joining us on the Gang today. As he said in New York.
We're happy to have him. I think also joining us in New York, his native land, um, hailing from the Bronx, uh, the one and only Mike Ard, our chief content Officer. Hey, Mike, how are you?
I'm good. I'm Hi, Nat and Dobbs Ferry today. Dobbs Ferry.
A little, little up upstate there, as we call it. And then joining me here at our book of Raton, uh, headquarters is our Echo Insights editor, Bonnie Schneider. Bonnie, thanks for joining.
Oh, My pleasure. Good to be here. Alright, so let's kick it off.
So, as I mentioned in the outset, Oracle's going country. I don't know, does this mean Larry Ellison gets a cowboy hat, but they have, uh, you know, skewed what has been sort of the normal migration path for tech companies from California to Austin and hopped all the way over to Nashville, which is, look, I I love Nashville. It's an up and coming tech town as well as a great music town, as Austin's a great music town too.
But Daniel, you're an Austin Guy, what do you think? Well, first of all, it was exciting when Oracle made its move. It has a big campus, uh, right near the, uh, the Lake Lady Bird Lake in, uh, Austin, in the city.
And, uh, you know, one of the interesting things about it was, is while Oracle did claim the headquarters there, if you talk to most Oracles, they would tell you that, uh, they were still mostly in the Bay Area. Now, I don't know if Larry changed his mind about the kind of sauce he wants on his barbecue or the type of country music he wants to listen to, but the move to me is, is in many ways, city-wise, community-wise is, is is very lateral. It's very similar.
Now, having said that, uh, and Nashville has something that I believe Austin lacks and that that's it's healthcare and its focus on healthcare systems. And of course it has a very, very well, uh, reputed university there at Vanderbilt. And I'm not gonna say that ut is not reputed, but there's kind of these elements that if you want to be in a city around a certain subject matter and, and ellison's all in on healthcare, you need to be in a place where that is the central sort of industry in that community.
And so, I'm sure he is getting some great tax subsidies. I read about some of them, and I'm sure this process is gonna take some years. Uh, as an Ian, uh, of course we like to brag about having Oracle in our town.
Um, but they'll still be there. You know, the headquarters they built will still be there. People will still be there, but they'll be naming the new domicile in Nashville because healthcare is the center of the Oracle universe.
At least that's how Allison is describing it, Really. So, I I wasn't aware of that strong, I mean, I, I know they had a strong healthcare focus. I didn't realize it was the, the center of it, but, you know, look, a couple of things come to my mind.
So first of all, you know, we've been hearing for so long that Austin, sort of the new Silicon Valley, right? All of the California folks, not all, but many of the California companies had a migrating into Austin, and it's a business friendly, and look ut uh, the, the business school, there's a, I forget the name of the business school, my son was McCombs accepted to it. Excuse me.
McCombs. McCombs, right? That's a fantastic business school.
Um, and they, I mean, in UT's one of the bigger universities, I I was just reading an article the other day about the new Ivys, and they had 10 public Ivys that are, they say are in par with, you know, the private ivy, traditional Ivy League schools. So, and, and Vanderbilt look, Vanderbilt's obviously one of those kind of Ivy League or Ivy League analog schools. But I mean, is this sort of a one-off deal, Tennessee sort of dropped its jaws on the, on the subsidies and everything to make it worthwhile for Oracle?
Or do you think this is the next migration wave, I think where may even, you know, go directly from California into Tennessee? Yeah, Yeah. I mean, look, I think Tennessee has some favorable tax, uh, scenarios for employees.
People wanna live there. It's, it does have great music and it has the barbecue's. Okay.
Uh, it's not Austin, but, uh, I know everybody, everybody out there is at least, you know, someone in North Carolina and Kansas City that's booing all of us. Yeah. But the point is, is that, you know, when it comes to the environment, Nashville is a growing, uh, community.
Its infrastructure is growing. You know, one of the things I could tell you as someone that transplanted from Chicago to Austin is there are some elements that are required to be the center of a tech hub, and Austin has some of them, but it lacks some of them. And that's gonna be on Texas to figure it out.
And I mentioned the, the school, yes, UT is good, but it doesn't have a Stanford, it just doesn't. Yeah. And so that's different.
And then of course, um, it's infrastructure, the education, I'm not talking about higher ed, I'm talking about the, the education for the, for the kids. The school systems have not been developed up to the point where they can attract as much talent and young talent and, and the infrastructure like roads and stuff. It's very difficult to get around Austin.
It's overcrowded now. Um, they have not built the west to east of the city. Most of it's north south to Dell, but the beautiful part of Austin's west of Austin in the hill country.
And it's hard to get out there. And so, you know, they need to continue to expand the infrastructure. We brought a lot of people in Quick, Tesla came in, and then Oracle came in.
And of course you've got big campuses from companies like a MD, uh, Intel is out there. Uh, Qualcomm has offices. Apple has a big office.
IBM has a huge presence. So there's a lot of tech there. This isn't the beginning or the end, the Nashville question.
And, and I know I'm, I'm dragging a bit here. So the Nashville question, it really is probably more of a one-off related to what Ellison's talking about. You know, when they bought Cerner for $28 billion to revolutionize the electronic health records business, it really was about changing healthcare.
This was a big play for its OCI business winning more workloads in its cloud. And if it could be the dominant cloud provider to healthcare, one of the largest verticals that is going to need to migrate from prem to cloud, Oracle has a huge chance to become a much bigger cloud provider. Remember, they're the fourth provider by revenue right now.
Yeah. If they wanna become bigger, they need to really think about how to specialize and drive that high demand to the OCI cloud versus the other offerings that are out there. And specializing is gonna be important.
That's, you're gonna see it with Google, you're gonna see it with, um, with Oracle because to keep up with Azure and AWS at that more general level, they're gonna need to have specialty, even IBM's done it with like financial services. They've gotta zero in on something. Oracle's zeroing in on health and health is very big in Nashville, Tennessee.
To what degree do you think it really matters where the company is? Because, you know, to your earlier point, most of the employees for Oracle are global. They're large sections in California, Texas, but they're everywhere.
And I think most companies today are kind of highly distributed. So are we really looking at, you know, Oracle is in Nashville, but they're basically, you know, 10 offices for CEOs and execs that come by once in a blue moon. Well, The, the CEO didn't really move to Texas.
He, he has been in Austin. So, you know, what I'd say is he has a plan of the kind of community he's, he, if you read the outlay of what they're intending to do, they're planning to build kind of this park building community with, uh, clinics and test areas where all the technology can be leveraged in healthcare in real time. I do think it's, to some extent, it's a tax play.
To some extent, it is being closer to the healthcare community play. I think to some extent it's Larry determining his politics and taking his money where he thinks it will be best appreciated. Um, and of course, uh, I think Oracle likes to be different.
It always has. Yeah. You know, it went, it was in the valley long before everyone else was, and now everyone else is there and he sees an opportunity to maybe, uh, win talent and win markets elsewhere.
And to your point, um, maybe do it with better economics. The economics of the Bay Area are not great or most companies. And so it works for the talent, but if you don't need the talent to, I think both of your points, doing it elsewhere can make a lot of sense.
So I wouldn't bet against Oracle, um, here, I think it's really being more deterministic in its plans to run with healthcare. And it's doing a, it, it's a move that seems pretty lateral to me, Nashville from Austin. But for Larry and for Oracle, I guarantee you the books, the numbers have been well, uh, reviewed and it makes sense for their business.
It Is getting a, a reputation Nashville for being healthcare, health tech. There's 900, uh, startups in tech, in healthcare, in national and work. Absolutely.
Yeah. So it's, it's definitely, um, a hub for that. If, if that's their, their aim, which sounds like it is.
I I don't think it's a knock on Oracle at all or, or anything. I think this is a plus for Nashville. Look, I'll, I'll tell you here in, in Florida, when people I speak to who are disenchanted, because Florida is a crazy place to live now, given the economics and insurance and the, the political pushes and pulls, where do most people I speak to go to move?
They're moving to Tennessee, to the Nashville area and the suburbs around Nashville. It is, it's got a great wrap is a good place. As Daniel mentioned, the K 12 school system there is supposedly at least better than it is here, I'm assuming maybe in Austin too.
Um, look good, good on Nashville. Good on Tennessee. Good for them.
Good on Oregon. It's got expensive. It's got expensive just like Austin has.
But, uh, Well that, that's the problem with all the, you know, it's that boom cycle thing, right? Everybody goes there 'cause it's cheap, and then it's not cheap no more. And, um, you, you know, Florida's a great example of it as well.
I hear that Californians are moving back, Alan from Austin at least. So We're very, you know, I I have Heard some of that myself from folks, You know, I, I, so Hey, you gotta live there, Daniel. I'm not gonna put your address out there.
So we have protesters or anything. We have enough protests in this country, but, um, Austin's still a great town and to all my friends in Austin out there, I gotcha. I don't care what he says.
Um, all right, well, the barbecue's still the best Blacks. Um, well, Well, t Texas and Nashville have been fighting it out for country music for decades, so now it's just That's true too. They're both great music towns for, you know, if you're into music, I think Nashville gets the cake there.
Yeah, yeah. Just kidding. For country, we get the barbecue, we get the barbecue.
I'll give you barbecue, they get the music. They and Tex-Mex. Yeah, we've got great TexMex.
Yeah. But anyway, and look UT's in the SEC now, they'll be playing Tennessee all the time. So we make for good football.
I think we're gonna call a a, a shot a a break here on our Oracle news. Daniel, I know you, you have to run down to the stock exchange. Thanks for stopping by today.
We hope to see you back here soon on the gang. And, uh, we'll be in touch. Daniel Newman, CEO founder fu group here on Techstar Gang.
We're gonna take a break and we're gonna come back with some security surprises on Docker hub. Stay tuned. All right, we're back here on Techstrong Gang.
You know, having Daniel Newman from FU Group on Zoe is, is great. He brings a lot of insights to it, but you know, as part of our Fu Textron hookup, we're gonna see more and more with the FU analyst community on Textron Gang, as well as Techron tv. And we think it adds a lot of value to you and to what you are wanting to know about.
So that's something to look forward to going on. For now though, let, let's jump over to this news on, uh, a little security surprise here with DACA Hub. I'm gonna ask Mike Baard if you want to kick that one off, Mike, over to you.
Yeah. It turns out that Jfr did some work with, uh, Docker, and I think Jfr did most of the work, but they discovered that all this, um, content, and we're not talking about the code, but actual content that sits on Docker hub has been loaded up with links to phishing sites and malware and the eBooks have been compromised. And all the people who've been kind of using that as a quote unquote marketing vehicle for sharing content, I guess nobody was watching the store because everybody started on the cyber criminal side, started uploading millions of these pages and these repositories that are basically codeless and they're just a bunch of content with links that people are being asked to click on.
And I guess they trusted that, and I have no idea, Chris, but how many folks do you think might actually have been involved? But it, every Docker developer I know plays around on that hub and clicks on just about everything. Yeah.
The short answer is sort of all of 'em, right? And I'm thinking about what, you know, comments you and Daniel made about the, about the, the Oracle move to Nashville. And it's, you know, I'm, I'm, I'm in the midst of a move.
I'm unpacking all sorts of old things. My Apple two C is running upstairs, right? And we think about Silicon Valley, um, it was apples, literally apples before that, like, we're old up when we were kids.
Silicon Valley wasn't Silicon Valley. And then it was, and then Austin, when we, I, I remember these same conversations you guys just had about, uh, Nashville, about Austin. Austin really?
Yeah. And that was Nashville. And these things just evolve, right?
And it's, you, you know, I I, as we try to do, if we're, we're reasonable folks, we're trying to filter our biases out, and I'm so deep in supply chain security and companies like Jfr and so forth, and it's exactly like this, that I, it's easy to think that I'm seeing it because I'm, you know, I'm focusing on it. But no, this is where we are right now, right? And it's just like, you know, the buildup in, in the, the, the tech hubs like Silicon Valley and Austin and so forth will lead to, uh, moving.
And since we're building an electronic network, that leads to, to your point, you know, distributed companies, you know, where are the employees anyways to the physicality matter. And in this case, it leads to all these supply chain things. If I'm building repositories as we have been doing for decades, for lots of good reasons, and this is a good example, um, yeah, that's also a vector.
And if we haven't gotten around to looking at that issue from a security perspective, but we have been working through the other issues. We're raising the cost of real estate in, in exploits, uh, that, that you can read about in historical exploits from five years or more ago. Now we're getting to the, the supply chain exploits.
You know, you could have been dumping things into places like this for decades, you know, but mostly the adversaries were dumping things into other places last couple years. As always, the adversaries are ahead of us and they've been doing things like xz and like this, and we should expect to find this around, you know, if I was, uh, spending my time being a nefarious actor, this is the area that I'm exploring right now. Supply chain is rife, You know, so first of all, this isn't the first docker hub security kind of embarrassment, right?
There was, uh, there were previously a lot of like the, uh, crypto mining folks had put up, uh, fraudulent docker containers, you know, a docker hub that, you know, they would like one letter off of a very well-known used container. So if you're using, you know, a, an image in Docker hub that was called X, Y, Z, they would put up something called XYZZ. And a lot of people just carelessly would click on X, Y, Z, Z instead of X, Y, Z.
But I don't mean to just nail docker a docker hub here for this, this is a prevalent problem, as Chris says, across all of our re reports. And when we build Frank Frankenstein like software by stitching together a lot of components from a bunch of different repos, right? And we call it software supply chain security now, right?
But that's really what it is, is we are, we're, we're stitching together software from components and all of these repos. I don't understand why someone's smart out there and, and maybe I should stop the tech strong thing and go do my next startup. I want repo firewalls.
I want something that sits in front of your infrastructure or in at the end gateway to that repo and doesn't let anything out unless it's been vetted and checked, right? And I think if we put that onus on the repo holders, and you know what, JFR has one called Artifactory. It had, you know, and they have X-ray that supposedly checks it.
And our friends that sonatype with the Maven and, and you know, their repos and GitHub, all of these repos need to have repo firewalls at the gateway, making sure that what you're downloading, if you're downloading an old version of something, warning you there's an old version, do it at your old risk if it's, if it's not what it purports to be, we have enough, God knows, we have enough AI and all this stuff to figure that out too. Someone, I mean, either make a business around it or, or force the repo owners operators to make a business around it. People Who work with, I Guess that's where had two opinions on that one.
I'm sorry. No, No, I was just saying that people were clicking on it on because it would say, here's, um, a free version of a video game. You know, it wasn't like we were saying somewhere by mistake.
A lot of it was intentional and Yeah, sure. Yeah. And, and I believe what they found that it's been going on for years, it wasn't like it was a, you know, something I just noticed it was there for a long time, Chris.
Yeah, yeah. I mean, you know, I feel sometimes like, I'm like, I sound like I'm making excuses for the problems, but yeah, a lot of 'em seem unavoidable, you know? So Alan, I think there probably are business opportunities to do the kind of things you're talking about right now, and maybe that's the right thing.
And I think people will certainly try that and, and more power on. I think, honestly, I think structurally the answer is, is different. But maybe we're not close enough to that to really stitch these things together.
Um, but yeah, this, this is, you know, this is where we are right now. And if, and if, you know, docker hub as an example, if, if a repo or whoever's go back to their origin, and there's probably somebody else was trying to do the same thing. If one of them had added all the security that we would like to have on these things, they may have not, not have become the, the, the default repo in the first place.
'cause they would've been slow or more expensive. So this Darwinian, you know, you can't put the security in place unless every, unless your competitors are putting in place until the time is right that everybody has to do it. If you fall victim to this, I'm kind of gonna blame the victim here, but the developers, it's kinda like, let me get this straight.
If I told you you were gonna go to a foreign country where malaria is prevalent, and then you decided to go to a public pool and swim in it with everybody else, bad things are gonna happen. And people gotta be more careful about what they're doing and thinking about. And you know, it's, I get that Docker hub has a responsibility here, but, um, it's still a public repository.
And these days, anything that is a public, anything you need to be really careful about using it. I'm not saying you should be incredibly paranoid, but you need to be careful and think it through. It seems like a lot of people are not.
They're just kind of like, woo, there's a thing here, I'll just click on it. And not realizing they have a responsibility to the organizations they work for. And I click on stupid stuff.
So, personal responsibility, a new political position by Mike Baard out here, um, Look, I, I don't think even if it's a quote unquote person, a public repository, I think the repository owners still have some responsibility to take the junk out of there. You know what, you can knock Apple all you want, but when I go to the Apple store, I'm assuming that those apps have been vetted, that I'm not downloading malware. And when I do, all hell breaks loose, right?
Everybody comes down. Same thing for the Google Play Store load's, probably a little bit more open than the Apple store. We need to look, software is inherently built via repos today via components downloaded from repos.
We have gotta do something about cleaning the sewers there. I I think it's an ex, there's an ex existential choice people need to make, you know, you know, for all I say about the passage of time right now, if you are to your point, if you're responsible for repo like that and you're not thinking about this, and I would think dollars and cents and days and weeks, if you don't have the time and the resources to address this, you're probably gonna get wiped out. You're not gonna be the one around in a year or two.
And same thing on the developers, right? I get it, you know, a year or 2, 3, 5 years ago. There's no way you could competitively write every line of code to yourself.
We need to pull it in. However, you know, we're here now, if you aren't right now, thinking about what this means, you know, how do I put in place in a realistic timeframe at a realistic cost of dollars and resources? Uh, you're not gonna be the more round in a couple years either.
Now the time I don't disagree. I I think that's true too. So there is a little bit of buyer beware or downloaded, beware.
Um, I, I just, as I said right from the beginning, guys, I don't understand this is a business problem that needs to be solved. Why hasn't some smart entrepreneurs solved it? I, I think there's money to be had here.
So, you know, look, look for my new startup shoe, the repo wall. Are you gonna be repo man? Is that now, that's gonna be, maybe I will be the, the repo man.
You, you bet. Um, there, there's a new sheriff in town cleaning up repos. But you know, it, it, it's just too big a problem.
I mean, this, this latest one is, you know, it's, it, I I, I don't think it's, it's only one facet of the problem with repos. A a lot of it is also just downloading outdated versions of components and, and stuff. I I don't, you know, we, we need to lock that down a little better too.
Um, then there's other, not just, you know, click schemes like this, but true malware that people download and, uh, turns zombie computers for, uh, you know, for mining and stuff and ransomware, it, it's too big a problem. We, we can't just, we can't just kind of turn the other cheek anymore. We, this needs to be solved, and it's something that can be solved.
It's central to the software supply chain security issue. Anyway, I guess that's gonna be the last word on that one. We're gonna take a break here on Textron Gang.
We're gonna be back about more in security. I'm Bonnie Schneider, sustainability contributor to the Techron Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter.
The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong research. All right, folks, and we're back, and everybody out there is talking about AI and a subset of folks are also starting to talk about security in ai.
And, uh, we recently saw the NSA is calling for folks to follow some best practices for implementing ai. And at the same time, there's, uh, the other folks over at nist, and if you don't know who NIST is, they're part of the Department of Congress and they do a lot of work on IT frameworks, but they came out with some guidance about how those frameworks should be built. And our friend Chris here, is pretty close to all these guys, and a lot of vendors, of course, are starting to implement those guidelines.
So we saw CYSTIC do something similar with along that line, and I expect there'll be about a hundred more of these in the next weeks ahead. But Chris, what is going on here with the US government and security? Uh, it seems like they're much more active than ever, but there's a lot of acronyms and I don't know exactly who does what, and maybe you might wanna sort this out a little bit for us.
Yeah, I, I'll approach this with my, uh, traditional Pollyanna optimism. I think it's going quite well, frankly, you know, uh, this is, I spent a lot of time with, with folks who were older than me, who were the first ones to brief Congress and so on and so forth. In my career, I've spent, uh, a lot of time at each state, the nineties and the two thousands and 2010s.
And now in this decade, working with the government of various levels, the, the US federal government, other federal governments, and it, and I think you, I I try to stay away from politics and maybe just, you know, have to get into ideology, right? I think the US system works really well as compared to like the, the opposite. Some totalitarian, you know, authoritarian socialist or fascist, whatever, where there's gonna be some central committee's gonna tell us how this works.
We saw that play on the Cold War, right? You know, our, you know, chaotic approach of, uh, of governance and private and public sector just out competed, you know, the, the Soviet model of centralized control. And I think this issue sort of plays out the strengths and weaknesses.
But this, I I would say the strengths of, of this model where, you know, today, the public, private and private public working groups that I'm involved with, with, with the Department of Homeland Security, particularly the Department of Commerce before that same groups are much more mature than they were, say, 20 and 30 years ago, where we're sort of naive. You look at the presidential directive that created the first information sharing and analysis center, and I finally just recently talked to someone who was part of the conversation that led to that, uh, executive order in the, the late nineties, and is a good example. So some, uh, private sector experts working with government sector folks saying, you know, we need an information sharing analysis center that the private sector runs.
So it gets written. And what happens is almost that except six or 12 or maybe a hundred heart, it depends on how you count ISACs. Uh, were, were developed and the public-private working groups that I'm involved with now, I think, you know, are on average leveraging this model.
The private sector has all the expertise, but we don't have the authority, and we don't always have the focus because we have to stay in business. The public sector has a lot of scope and responsibilities, but they don't have the expertise and flexibility. Um, and nist, the National Institute Institute of Standards of Technology is, you know, someone will know about, no doubt, correct me in the comments, sort of a Cold War era institute, you know, a National Federal Institute of Standards and technology to come up with frameworks that are by and large generated by conversations with the private sector, bringing a bunch of folks like you and I into a room and saying, all right, you know, we're gonna publish under the, the auspices of the government, the general consensus of what the industry thinks right now.
Um, so fast forward all the way to this particular era, AI regulation, you know, I'm confused. You're confused. We're among, and our peers are among the world's leading experts on this topic, and none of us can say exactly what the rules should be.
So I think there's a good time for the public sector to step in with something. Let them be wrong in our, let us be wrong in their name, right? And we'll work through that and we'll find the flaws and we'll iterate back to what the right rules are.
Because I don't know, I mean, do you know what the right rules for regulating AI ar are today? No, But I, I, I'm not so sure the public sector does either. I think that's something, oh, not a clue.
Need to develop. I mean, here is where I see it, Chris. You know, I'm here, I'm from the government and I'm here to help, right?
The eight scariest words in, in the English language, to me, the federal government does. The problem is it's a security chacha. It's, it's one step forward, two steps back, two steps forward, one step back, yes, NIST is working on these things at the same time.
NIST budget got cut in this Arab budget cuts, and they, they killed the national vulnerability, or they're not funding their national vulnerability database, I believe project going forward. But the, the NVD, and again, you know, the pub, the private sector has almost all the expertise. And I, you and I know, fantastic.
You know, we're leading experts who are government employees for the vast majority of the private sector and the national, the NVD, the National Vulnerability database is a perfect example because while I would generally agree that it should have been created, somebody had to do it, um, is that the answer? Is it really workable going forward is the best use of funds? That's a heck of a question.
Yeah. And I would entertain the answer is no, but it kind of comes back to your, to the issue of repositories we were talking about earlier. I think we need to, I think the future of technology and governance of technology looks different than the past.
It's less about firewalls, it's less about having a rebo wall, and it's more about all of us agreeing on efficient systems where we don't have to, you know, build a wall everywhere. I just let ask You this, um, in the history, everybody, whoever fought the next war using the last wars tactics and techniques got whooped for the first two years until they figured out that there was a different set of rules being applied, and it was a different game. So are we in danger here of, you know, reaching back to some Cold War era strategy in trying to use it to fight, you know, essentially a, a two front war against nation states on one side and a bunch of digital pirate criminals on the other?
Yeah, I mean, I, the short answer is yes, and I would say in every, you know, domain, you know, whether it's literally the military, I love aircraft fairs, they're really cool. They're my era. I don't know that, you know, a hundred, they have these wonderful oil tanker based, um, uh, expeditionary based ships, and it's like five or 10 of them out there.
I love those things. They build 'em a couple years. They don't cost that much.
Maybe we span the ocean with those in this whole cybersecurity realm. Yeah, I think centralized controls and even centralized, you know, rules and standards, um, are quite often the wrong approach. You know, you assume you're going to lose some repos.
There shouldn't be one of anything. We should have redundancy and we should have organic redundancy, um, you know, walling off, you know, trying to try to make this one thing perfectly secure as opposed to assuming whether through incompetence, nefarious entropy, whatever, that things will go down. How do I keep the entire system work is more the battleground of the cyber and physical battleground of the future.
You know, for all the years that I've been in security before it was fancy and got called cyber, um, the biggest weakness was the guy behind on the gal or the person behind the keyboard, the human issue. They're the ones who click on the fish. They're the ones who, you know, don't think things through.
I don't think that changes. I, I don't think human nature changes. I, I, you know, who was it?
Ira, IRA, IRA, uh, weaker. His book is you, you can cure Stupid, right? I'm not so sure you can cure stupid.
Um, you know, not that people are necessarily stupid, but we make stupid mistakes, and that's what plagues us. I, I still think that's probably one of our biggest weak, you know, the soft white underbelly, plaguing, you know, security. I, I, and I don't know how you legislate around that policy maker around it, or, you know, at the end of the day, you gotta take that as a given, and all your planning has to start from that.
Chris, I'm gonna give you the last word on it, and then we are gonna wrap up this version of the gang. I, I, I just, you know, I'll reemphasize, you know, that my optimistic proof that we're on this call now, the lights are on, you know, the internet's actually working, you know, our financial system's working, right? So for all the mistakes and we can look back and there's a lot of fun to do, it's like, that was bad.
That was bad, that was a terrible idea. We keep error checking in, in the right time, in the right speed. So I'm a systems person.
I think our systems are general open systems that we have around all this are generally right. And when we come up with terrible ideas, like having a single national vulnerability database as opposed to having that information distributed redundant, we'll find out and fix it just in time. Excellent.
All right, Chris, Mike Ard, Bonnie Schneider, and Daniel Daniel Newman, who was on earlier. Thank you all for being on Textron Gang today. Thank you all for watching Textron Gang.
No Fresh Textron Gang. Tomorrow. We will be back Monday.
Actually, we will be live at RSA conference next Monday. We're also gonna be at Service now next week. So lots of good stuff.
Coming next week here on Tech Drunk tv. Stay tuned for the rest of Tech Drunk TV's schedule today. Until then, I'm Alan Shimel.
We're out. com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more.
com has the largest collection of original DevOps content, featuring breaking news, blog posts, podcasts, and more. com to learn more. com where the world meets DevOps.