Techstrong Gang – May 27, 2025
Alan, Mike, Tracy Ragan, Chris Blask and Jack Poller dive into the controversy over Microsoft Recall now that Signal has found a way to turn off the screen capture technology in Windows 11 before discussing to what degree are cybersecurity professionals addicted to too many tools.
Then the gang takes a look at CloudBees effort to unify DevOps workflows in the age of platform engineering.
Transcript
Hey everyone. Have you heard about the new sequel to Total Recall? It's called Can't Recall.
You're watching Text on Gang. Hi everyone, it's Alan Shimel for Techstrong. Welcome back from your holiday weekend.
It's Tuesday. It's not Monday, it's Tuesday, but get ready for work. Me, I'm personally excited.
I'm outta here tomorrow, heading out to Italy for about 10 days with family. Looking forward to it. Um, you know, I I it's, it's interesting as an American traveling the world these days, so I'll report when I get back.
But let, let's jump into what we have going on here today. We've got, it's a bit of a security heavy day, and it's good 'cause we have some really security heavy people. I don't mean they're heavy, I mean, they're big into security.
Let me introduce you to our, our group for today. First of all, from the great white north. We'll go north to south, perhaps from the great white North.
He's a resident security expert. Frank, Chris Blas. Hey, Chris, how are you?
I am good. And uh, I just wanna put a, a term in your ear to think about as we go forward. Narrative resilience.
Narrative resilience. Yeah, we will, over the coming weeks and months, I think it'll be a fascinating topic. Okay.
You heard it here first from Chris Blak again, moving. Well, I'm not sure who's further north here. I'm gonna go with Mike Ard in, in upstate New York.
Well, it's not really upstate, but It is, it is a grand total of 20 minutes north of New York City. So it just depends on where your definition of upstate is. But on Long Island, anything north of the Bronx is upstate For, for us locals.
It's generally anything north of New Paltz. But what do we know? What do you know?
All right, Mike, welcome. Welcome home. Next we'll go to Jack Poller.
Jack, I'm forgetting where exactly you're based. Well, I am in the north of the south. I am in Chapel Hill, North Carolina.
That's, remember right now I remember. Yes, right. We got Three square miles of Northerners, very deep in Yankee, uh, you know, in, in southern territory here.
Yep. Around C they called it. So down here in Florida, we call that the halfback.
Right. It's for people who came all the way down here and then only moved halfway back. And it's, it's halfback land.
Well, continuing south though, to the mountains of New Mexico. She's the CEO of the Deploy hub and open source extraordinaire expert, our friend Tracy Reagan. Hey, Tracy, how are you?
I'm doing great, and I hope you have a fabulous trip in Italy. It sounds like a wonderful thing to do right now, and it's a well deserved vacation, I'm sure. Yes, it is.
Yes. I'm taking, uh, well, it it's 10 of us going. It's gonna be fun.
What makes you think you're gonna be let back in you? That was pretty optimistic statement. You know, I've told Bonnie the do not be surprised if at some point on one of our trips I'm detained because they, they could look up my social media or they'll look at something and say, I don't, I'm not a huge fan of this administration, So we'll just have to call it Text on Gang International after that.
Yeah, yeah. We got your back. We got your back.
Alan, let me just for, for posterity. Look at my hands right now. I have no tattoos on my fingers.
Okay. Oh, they could fix that in case they have, right? Oh, they'll, but in case they try to pull that, I want, I want a record.
Um, let's, let's, let's move along here and, and jump into today's, into today's, um, topics. So, Mike, you wanna take this one? It looks like Signal is telling Microsoft No.
Can do. Yeah. Basically, uh, the controversy surrounding this recall feature that Microsoft is putting into Windows 11 continues.
Uh, now Signal is saying that they're gonna block that feature for recall, which is designed to capture, uh, automatic screenshots and everything on your screen and will make that available somehow or other on that platform, but maybe in the cloud. Who knows where all that data winds up. And Signal, of course, is all about, you know, privacy and not sharing data.
So, Chris, are we gonna see more of this? Will other folks follow suit, do you think? And is data privacy like actually becoming a real thing now?
Well, As you know, I try to find a positive, you know, path out of these sort of things. Either there's teaching lessons and so forth, and not use terms too much like dumb ass. I don't actually, can I use dumb ass on this show?
I mean, I, no, this is, it's an indication of the immaturity of corporate governance in certain ways, right? Regarding privacy and so forth. I mean, this is tone deaf is the, right, I mean, I mean, you, you said it literally everyone on earth now.
I mean, you know, signal has been this sort of geeky app, you know, for years and years and years, but suddenly everyone, literally, everyone knows. So someone at Microsoft, you know, made a decision that indicates that the decision making structure of Microsoft on this issue, we is not mature. Yeah.
So maybe it's a forcing function to get better process in place, but, uh, it has us talking about it. So maybe that's the upside, Jack. Is this just another example of the well-intentioned gone wrong, you know, that road paved to hell?
Yeah, I think so, sort of. But it's also an indication where Microsoft forgot all about security, right? The very first, you know, yeah, shocker.
They forgot about security. Um, the, the, the first release of recall when it was first announced, had no concept of security whatsoever. They went back and rethought it and said, okay, well we'll tie it to your, um, windows, hello login.
And so you can't access that, but that ignores a whole bunch of other concerns. Like, do you want an AI engine to be indexing your private data to begin with? You know?
And so I look at it and I say, you know, many years ago I called Java the virus description language, and I think we can call recall is remember everything secure? Nothing. It's just, it's really just a huge privacy issue.
And, you know, we think about it on a personal level, but for, you know, if you think about it in the enterprise, to have something that screenshots and executives, uh, PC every three seconds on what they're doing is just a huge opportunity for data leak, data exposure. Uh, and I just can't see how this is gonna be successful in the long run. I, I think it's a Darwinian sort of thing, you know, and again, that's what always gives me hope on this stuff, because, you know, this is so blindingly, fumble, fingered, you know, for a big corporation.
To be clear, Microsoft actually does a lot of good security, a lot of good folks there. We all, you know, many of us here, remember the days when they really did Trustworthy computing initiative. They had some of the best security people in the world.
But, so it's, again, not so much a Microsoft thing. And again, maybe it's my focus on supply chain, but I don't see how we can have secure functional supply chains, particularly in certain critical sectors in the very near future, measured in a handful of years without the kind of clarity on policy, you know, implemented for that. But I think, you know, maybe I'm trying to strike the analogy, but I think this is the same sort of thing.
And Jack, to your point, you know, this is a big corporation that actually spends a lot of money and does some good security stuff, and even they can't have enough operational policy at the product management level for someone to say, not only, no, I mean, no, that's, no, this Is not a, but I, I think the ques the question is, who were they listening to when they, uh, decided to implement this, uh, feature? Uh, were they listening to enterprises that said, we do want this to feature on all of our employees, uh, workstations. We find that this would be a useful feature.
Um, or maybe they weren't listening to anybody and they thought it was a really cool idea and don't have really good use cases and forgot about the spyware aspect of it. I wanna give 'em at least some benefit of the doubt. But we don't, we don't know who asked for this and somebody asked for that.
I, I can't imagine Microsoft just delivering something because they thought it would be a good idea without doing any kind of customer discovery. I, it would be shocking. It would be shocking for me for to know that they just did it without asking.
So who asked for it? And what are, what were the use cases and why can't you turn it on and off is the question I'd be asking Microsoft? Yeah, I think there's, there, there is a, there is a, uh, an ulterior motive here is that PCs were had become commodity items, right?
And I think there was a lot of movement towards Apple as a different form of a pc and to take advantage of AI and push more AI hardware and reinvigorate PC sales, which become stagnant, right? In order to use these features, you really do need, um, you know, not to do the screenshot version, but to do the analysis. You need the AI PCs and have an AI chip in your pc.
So there is a motivation to sell more hardware to take advantage of these features, or, you know, and so that's part of the motivation is to push more hardware. And part of it is to make the PC something more than a dumb client where the web browser is your interface to everything. Or Chromebook as you me, I'm sorry.
Yeah, Chromebooks. Right. Alan, we're at the point now where Microsoft is quite literally begging slash forcing people into Windows 11.
So does this become another reason maybe not to go to Windows 11 and use a Mac, or to your earlier point, Chromebook, or having forbid a Linux desktop? So I'm, I'm gonna be the contrarian here. I think you guys are missing the boat.
As a matter of fact, I would expect a feature like this more from Mac, from Apple than I would from Microsoft. I think this is clearly aimed at to consumers, because here's the newsflash old people like us. We, we tend to give a crap about our so-called privacy.
Young people don't, a lot of them don't even have a concept of privacy. They think everything online is online. Well, it is by definition.
If it's online, it's online. But that being said, it may be more important to them to have the utility of this recall feature than it is to have the risk of that information making its way out there because they don't have a concept of privacy anymore. We've younger the, and I don't want to be go play in front of your old household man, but you know, a lot of the younger generations do not have a concept of privacy.
And when they do, if they do, then they are very selective about it. And if Microsoft were to put this on right, in terms of when you want to turn it on, when you want to turn it off, what kind of things it recalls, what kind of things it doesn't, it may find a market in people who, who, who, like, you know, it sound, I mean, you take the security aspect outta it. Yeah.
That's a pretty cool, useful thing I might have. Right? And if, and if security's not important to you, privacy's not important to you, Chris.
Yeah. Let me see if I can combine my pointment with yours. Right.
You know, I, because I stand by my, my point that there isn't the governance structure inside corporations to make these sort of decisions. You know, there, there, you know, there should be a function that if I say I wanna do this or some internal control that says before X do Y and y is, is the decision point doesn't exist. But to your, to your point, just map those two together because that's a very common perception of, of folks our age, right?
And I think, and I've been, this is to be pedantic, one of my inevitability curve things decades ago, I'm, I was looking at this and saying, alright, in the future there will be cameras everywhere, everywhere. Nothing on earth is going to stop that. It maybe sooner or later it's happened at some point.
And after that point forever, for all of human future for thousands of millions, where people who live in the world where cameras are everywhere, this is the last part where we don't, and they will either exist in that world in a constant soup of privacy compromise, or they will have figured it out. And I think this is a perfect example of how much we haven't figured it out. And your comments about the current generation, I think mark this difference between our generation that says we can build a wall around all of this and no one will ever find it.
And a generation that grew up in it, who, I wouldn't take it as far as your point privacy is, is is a more fundable thing. We just think that it's a, a save for the brick, you know, wall, uh, it'll never get open. You know, this generation understands that nothing privacy isn't forever.
And they may have thrown their hands up because us folks who built this system have no governance structure for what privacy even means, Right? I'll disagree on two points. One is the Europeans damn well do care about this regardless of their age.
And so I'm being, making broad generalizations based on age. I don't see that. I also see my kids routinely use apps like WhatsApp, even here in the US now, because they are conscious of the privacy issues.
And so they have a whole separate channel for certain conversations that they wanna have. And then I also would say, yeah, maybe we'll have video cameras everywhere and we're also gonna have meetings and block parties where there'll be no cameras a lot. So there you go.
You might, Well, to Alan's point, go ahead. To Alan's point, there was a market, there was a market because Microsoft is, Um, yeah, my are too smart. They just roll that out.
Yeah. Yeah. They, there was a market, and I think to, to Alan's point, I think he might be spot on, um, that this was a market to a younger generation, uh, because of the way that they're much more voyeuristic than we would ever have been.
They're used to having things on that, you know, all of them wanna be content creators. Anybody I speak to who's under the age of 19 think that that's their next job. So, um, yeah, I think that there, there's a market for it.
And as a, to Alan's point, turning it on and off would've been a good idea. Well, that, that, that may be the answer that the Microsoft makes it easier to say, like, before it recall. So is this something you wanna recall?
You, you wanna set your recall policies, you know, or, or what have you? Because I'm, I can see a, I can see a a a total use for this for gamers. I'm sorry.
I just can, yeah, No, I, I it's A great application for gamers. It's like, you know, as the, the, the best intentions, right? The road to perdition and all that good stuff.
But, you know, is this where we're heading? I mean, your point about cameras, we, I, I got, so I'm president of the HOA where I live, don't ask, but we, I get a thing last week that, um, we had a, a break in. I said, oh my God, there's like no crime where I live.
What kind of break in? So we send out a thing, if anyone has video of, of the, you know, of last night showing someone potentially breaking in, let us know every, almost every house. So I live in a, on a canal to the Intercoastal, and there's houses on, it's sort of a U shape, if you will, right on both sides of the canal.
And we, every house has video, it seems, either it's ring or whatever. These are not official like surveillance videos. It's, it, each house has their own thing.
We have this guy walking in at 1130 at night. He tries to jump on someone's boat and misses, 'cause he misses the boat, winds up in the canal, pulls himself out of the canal, climbing up some, some, uh, a ladder that is encrusted with barnacles. He must have cut himself all up.
He comes off the water with one shoe and no shirt, and he's walking around, he doesn't know what to do. He sees a ladder, two doors down, he grabs a ladder, he, 'cause the door was closed, he puts the ladder up and he's cl trying to climb to the second floor of this villa to get in there. He climbs up the ladder, he falls down the ladder, how this guy didn't die trying to break into the house.
He then gets up and he says, I better get the hell outta here. And he grabs his shirt in one shoe and he leaves the neighbor, and we have him walking through 4, 5, 6 house, you know, backyards to get outta my neighborhood. And we gave it all to the police.
The police said, we go, we know this guy. We caught him on the LinkedIn Boulevard Bridge at a half hour before this, but he doesn't doing anything illegal. So we let him go.
He was just kinda walking around, you know, crazy. So he never broke into anything, by the way. But yes, that's the world we live in.
And those are good things to have, I guess It kind of always has been, right? Uh, you know, if you ever lived in a small town, right? And you on a Sunday morning, put on your spouse's bathrobe and walk out of the backyard and walk back inside, they know about it downtown before you get inside, right?
And that's so, and, and what I said about the past and the future, like, look, privacy, since we, you know, unless we live in a tree stump by yourself, privacy is a relative thing. And we all deal with it all the time. If you're out in public, you are out in public, you know, people may see you, people may take pictures.
It's a funny thing. And it's, but again, in 1742, it was the same. You know, old Broderick walked down the street yesterday.
Did you see him? Oh my God, where's he going? We'll figure it out.
But, well, You had well-armed militias back then, though. So, So this, this issue that starts us with this again, I, I think it is just an indication of the immaturity of our handling of this tech, right? We can figure it out.
But this is a, this is a misstep they should have thought on through at optics. So clarify that point for me. Is being online, essentially being out in public, or is my laptop the equivalent of my castle is my home, is my laptop?
Only If you bring down the cone of silence, It's the same being done in public, honestly. You're gonna, you, you're gonna send information in a email or a parchment on a carrier pigeon it's out in public Or a whole lot of stuff we do on our computers is not involved sending that information out to the internet. And that's not public, right?
We do a whole lot of confidential work, whether it's our own personal accounting, our own personal journal, whatever you wanna talk about. We use our computers for a whole lot of stuff the same. We use our phones and everything else.
And it is not stuff that we ever intend to be shared or make public. And I think the challenge of what, you know, getting all the way circling all the way back to the beginning with Signal Signal's challenge, is there is no granular control of recall. And they had to do unnatural acts to make recall, not take screenshots of what Signal is doing, which was never meant, Right.
It definitely needs more granular control. But, you know, Jack, I'm reminded of what I used to tell people when they were talking about risk and how could they be more secure. Don't connect to the internet, unplug your router, right?
If that, if that's, you know, if you're gonna have a machine that you're gonna do stuff that you don't want it to find its way online, don't connect to the internet. Because anytime you connect to the internet, there's going to be some risk. Whether you want to accept that risk or not, that's a risk management issue.
And this is, and this is their job, right? Like Jack, you're saying. Right?
You know, and to be really clear online and online this, my machines actually have cloud bits. You know, it's, I'm not all about physically here. There's a difference between online and online, but you know, there's also, you know, in the physical world, it's not that clear either.
As we all and the security people, I can listen to you in your house, in your basement with an audio microphone from not that bloody far away and, and damned right, you know, security and risk all relative, as you said, we accept a re no, we need to address all of this the same way we do all other risks. Some of it we worry way too much. Some of it we don't worry nearly enough and we have a lot of work to do yet.
Crazy. All right. Hey, we're over time on this one.
So we're gonna have to boogie for the next ones. Let's take a break here on the gang. We're gonna come back and speaking of the cone of silence, we're gonna talk about cybersecurity chaos.
Is that a new organization that Maxwell Smart is fighting? I don't know. You're watching Textron Gang.
Hey everyone, we're back here. Hey, you know, I was reminded during the commercial break. We, we broke protocol here.
We got so excited over this recall stuff. We went back, recalled it, and realized we made a mistake. You know, Jack Poller, who, who I've known now for some time, I, I met Jack most recently via the tech Field Day gang, Steve FoST and, and Tech Field Day.
Jack's a regular delegate on tech field days, but Jack's also a pretty well known fellow in the security space analyst. But Jack, I don't want to introduce you. Introduce yourself.
Well, thank you Alan. It is a pleasure to be here. Uh, and yes, uh, I am, uh, a tech Field Day delegate, and actually next week we'll be doing security field day live.
So that'll be very interesting. Uh, I actually started life as an engineer developing chips and software, and then turned myself into a marketing person and did marketing for startups for a while, and then became an industry analyst focused on cybersecurity. Uh, so I, uh, speak a lot about a lot of different, speak a little bit about a lot of different things.
And That's the perfect profile for a, a, uh, Textron gang member. So welcome to the gang jacket. It's great to have ya on.
We look forward to having ya on as a regular. Um, excuse me, that being said, chaos in cybersecurity. Imagine that.
So Splunk has this report out where they surveyed a bunch of folks and they found that nearly half, 46% at least, claim that they're spending more time maintaining their cybersecurity tools and environments than they are actually protecting the organization. And we've talked in the past on the show about the potential rise of what you might call the cybersecurity industrial complex. But Jack, are, are we a little outta control on our tools here, and is something amiss or, um, you know, is this just kinda, uh, nature of the game?
Uh, well, I like the, uh, the reference to the cybersecurity industrial complex. Um, there are more than 4,000 cybersecurity tool vendors with more than 10,000 products. So it is a huge endeavor.
And I think what the Splunk report sort of highlights is three perpetual evergreen themes. One of which is, you know, from a cybersecurity tools perspective is platforms versus point tools, and one of which is people and process. And the third is the critical lack of cybersecurity skills, right?
And so if we think about, so go back to that is, um, you know, platforms versus point tools, and I've done my own research in this area, and practitioners always tell us that they want platforms because they want all the different domains of cybersecurity. Whether you're thinking about endpoint security or network security or identity, they want it all to talk together and integrate, because there's just so many different domains that are, that interact with each other. The problem is, platforms never provide, in their opinion, the practitioner's opinion never provide the best tools for each particular area.
So they always, while they say they want platforms, they always buy point tools or best of breed tools, right? And so when you do that, you end up with tools from different vendors that don't talk to each other or collect the same data, but store it in a different way or so you have overlapping data sets and huge data sets. And managing this becomes a problem, particularly when you think about Splunk, who originated the study in their environment where they're collecting so much data that simply the cost of storing man collecting, storing, and managing that data is a problem in and of itself, where there are now other tools available to solve that problem, right?
So now you have to manage, just solve the problem of how expensive it is to collect data you need in order to figure out if you, how to secure your environment. So it is a, you know, it's, it's something that I've seen before. It's a big problem.
It's a big challenge. And then when you throw on top of that the lack of cybersecurity skills, right? And, you know, and the research that I've done over the last 15 years, perpetually says that roughly half of organizations say they don't have the skills and they can't hire for those skills.
They don't have the, the resources to staff up. If for one reason or another, then it's just, it becomes an overwhelming challenge of how do I, you know, I need this tool because it's the best at securing this particular part of my environment, and I need this tool over here. It's the best at securing this part of my environment, but how do I make 'em work together without me spending an inordinate amount of time and doing unnatural acts?
So I think a lot of people suffer from this. So I'm not surprised at all with the, the, the data from s spam. I, I've got two, two things on this sort.
Number one, something that really drives the, the chaos here is shiny trinket syndrome. Jack, you touched on it. You go talk to the security administrator, he says, oh yeah, no, I wanna standardize, I wanna standardize on the platform.
I'm all, I'm all in on Palo, I'm all in on Cisco, I'm all in on whoever de Jo platform is, right? And then they're like little kids in the candy store. They walk the aisles of RSA and all those blinking lights and puppies and goats that were there this year and everything else.
And, and they see the, the shiny trinket, the magic bullet that's gonna kill those vampires. And they just gotta have it. They just gotta have the sh But it doesn't work with your platform.
It's okay, because I gotta have, I gotta have the shiny new trinket. And we have suffered from shining trinket syndrome and security for as long as I'm insecurity and I'm insecurity 25 plus years. And how many of those shiny trinkets, like gifts that I buy for my wife that she's ashamed to tell me she doesn't like wind up staying in the jewelry box in the top drawer of her dresser, right?
So did these, a lot of these shiny trinkets and, and, and I, until we break that syndrome, I don't know if we'll ever solve this. Totally. Secondly though, I started a company called Still Secure in 2001, co-founded company in 2007 eight.
I came to the conclusion that for all but a handful of organizations, security is just too g*****n hard. They're never gonna have the the enough resources, manpower, skill sets, everything needed to really do security, right? And that the only answer to this was mssp, right?
You had to just let them buy this security and you come in and, and provide all the security they need and want and could use pivoted. The company bought an MSSP and then organically started building more tools. And then the board 2008 came 2009, you know, the economic downturn.
And, and the board didn't want to give us more money to buy more MSPs 'cause I was out shopping. Um, I don't think it's really changed. I, I think we have more tools.
We have more attack surfaces. We, you know, we, we, we may even have more budget, but that's a good thing. I guess we have more budget for security than we did then, but it's still too hard.
It's still too hard. And there's still too many tools and a lot of them are shelfware. And it's, you know, I think that some irony in that Splunk did this survey, but I'm not going to get into that one.
Chris, you got your hand up? I am gonna get into that one, right? 'cause I, I happened to be, I didn't even know this was a segment of hair.
I'm wearing a Tigo shirt, you know, the, my first round in the sim space, and then there was alien vault was, I think it was around the times punk came out. And yeah, at that point, you know, to, to Jack, to your point, you know, then there was, Hey, we already have these platforms and logging and so forth, why do we need this extra thing? But there was, and we sold this to Cisco, who in theory plug it into their bigger, uh, to your point, Alan, you know, uh, Cisco platform, and we keep doing this.
And the analogy might be, I'm trying to think of something physical, maybe a house. Like, you know, you get a brand new house that's perfect, it's fine, but you start adding this and adding that in 20 years later, it's a bit of a mess. You know, put all that in the, in the context of this ever-growing cybersecurity answer we're trying to find while we are building and sailing one internet that's half finished, right?
So we keep saying, it's too many pieces. Here's a platform, oh, thank God. And right or wrong, you know, Alan s maybe a not on you.
Things maybe we're like, oh, it doesn't have one of those. We bolt that on and bolted on and bolted on until somebody says it's not a platform anymore. And does that, is it an infinite regress forever?
I don't think so, but I think it again, marks that, you know, we thought we had everything in the platform and realized there's a bunch of things. We're doing it all yet. So here we are again.
And it's a ma it's a matter of focus. We have a focus issue. We really do.
Or A lack of focus issue. It's a lack of focus. Yeah.
If you look at, uh, and you're right, Alan, the attack service for cyber is massive. So there may be a reason to have different tools for different applications of cyber, but if you just look at open source packages, which is, you know, sort of what I specialize in, we have, there has been billions of dollars invested in this space, literally billions of dollars. And it still takes us over 90 days to fix a vulnerability, a single vulnerability.
And we have, what, 10,000 were reported in the first quarter of this year. And it takes us 90 days to fix one with all the billions spent. So again, we, we started with observability, you know, uh, uh, event management systems that says if you find an issue, these are the steps you have to go through.
And these tools can be very, um, create a lot of toil in the process, but they're not focused on fixing a problem. And it's the same with the, with, um, any of the, um, uh, networking tools. A lot of it has to do with observability.
And I'm hoping that we will see in the future, AI applied to helping us get through this problem. Because we can't throw up our hands and say, we, we have to stop doing this because it's too, too hard. We can't do that.
We don't have an option. So is AI the new, is ai the new silver bullet? I don't know, but I can tell you right now that, that we, I've been working with the CI CD cybersecurity working group at the CDF, and our goal was to take the secure software dev development framework, take every task and map it to a tool.
And I have a team of hotshot DevOps engineers and some security folks on that. And we are struggling to do it. So the the software development framework is actually too complicated.
It's, it's too, um, uh, it, it's, it, it doesn't have fo it, it tries to have focus, but it, it's really hard to think through how you would actually implement it. So the result is you don't do it. So yes, it, we, we, we need to do work in this area, but we can't throw the baby out with the bath water.
And I'm hoping AI can help. I, I really do believe that in, in terms of some work that can be done, being able to do predictive analysis, being able to troubleshoot things before they happen, being able to update configurations on a network before that they're, they're a problem or fix things in a palm file because you have the wrong pin version and, and it's done automatically for you is the way out. So, so Tracy, you're highlighting a lot of what, you know, one of the themes that I said this highlights is that, uh, it's a people process problem, right?
And it's a people process problem. Developing the tools is a said, the people process problem and chasing the shiny toy, the new bubble, rather than focusing on cybersecurity hygiene. Look, we know from things like the Verizon Data Breach Investigative report, that the vast majority of cybersecurity, uh, data breaches are originate in an identity related attack.
And if organizations would simply make MFA mandatory, we would probably cut that in half overnight. I mean, I've, I've talked to a, I talked to a CISO of a financial institution with had 30 million customers. And when they made MFA mandatory for their 30 million customers, they saw the number of attacks, not successful attacks, just the number of attacks they faced on a daily basis dropped 95% in a week, right?
It's just, it's simple things like this that isn't a shiny toy. It's well known. It works.
And it will stop most of the breaches that most companies attack. The real that, that most fun companies face. The reality is most companies aren't getting attacked by nation state actors.
And most companies aren't getting attacked. But with, uh, zero day obscure things that they haven't discovered yet, most of it is we've somehow, somewhere, somehow got, uh, somebody's account and we're logging in and going from there. And if we could simply focus on these low hanging fruit, we'd be just so much better off than implementing yet another tool in our tool chain.
There are people starting to ask the question about whether cybersecurity people are Craig Cray, right? The amount of investment that we keep putting into this space keeps going up, keep buying tools, and then you tell us that you don't have enough people. Well then where are you getting the people to master all the tools you wanna buy?
So there's a lot of folks who are standing around going, you know, do these cybersecurity people really understand the ROI of the situation? And why are we giving 'em more money? There's no ROI, I mean, look, I I, and you're talking to someone who you made an ROI calculator when I used to sell security, right?
It's very hard to prove ROI 'cause how do you prove when nothing happened? But to, to, to Jack's point, you know, recently identity has been recognized as the leading cause of breaches In previous versions of the Verizon data breach report. They used to give you a, a statistic like 80 to 85% of all breaches took place from known vulnerabilities.
If we would just patch our vulnerabilities, we wouldn't have 80 to 85% of these things. Now it's 80 to 85% of these take place because we've given up identity. If we would just put in multifactor authentication, we would do these things.
I don't know. I don't know. Did Jack and Tracy with both pain points that sort of speak to that?
You know, Jack, the way I read your point, I, I agree is that most of the time if you, you just, you can mold the Juan and get rid of most of the problem, then you just focus on the rest. You know, to your point, um, is the rest gonna expand again to take over the lawn? Yeah.
I mean lines, however, right? You know, it's this focus part of it that you were talking about, Tracy, right? You know, because as the average consumer, uh, where do you start?
You read an article, you do that thing, does it solve a problem? No, that's our focus is messed up. We're not, you know, quite often not addressing the easy things that would at least let us focus back on the big things.
Let, Let's look at, let's look at MFA for a second, right? So we're on a big push here with FU and Touch Strong. We, we've gone to MFA mandatory get a lot of pushback from people.
Why? Anybody, same thing like developers in DevOps. Anybody raise their hand and say, I wanna develop insecure code.
No, we all want secure code. Anybody say, I don't wanna do MFA 'cause I like to be insecure and live on the edge. No one raises their hand for that.
Why can't we get people to adopt more MFA then? Is she even what? Like the fact we need to make it mandatory.
Why wouldn't everyone say, I wanna be more secure. I wanna make sure my company's not the next headline. What is it about MFA that's such a giant PIA that we can't get people to do this Because it is a PIA there you go's API, Wait, it introduces friction.
And that's, that's an implementation issue. And the market should be beating up the vendors for that. How many people use, how many of you guys use Face ID on your, your Android or your Apple phones, right?
That's MFA, that's the very secure way of Logging. Well, that, that's what I've gone to. They call 'em pass keys and everything else.
It's all fine. Pass Keys and pass keys, which is Passwordless is a much more secure way of doing it. No doubt.
I'd love to see the whole world go there. And, and so what I, and it takes time, right? And, and I'd be happy if most organizations said, we don't have MFA, let's skip over MFA completely and go to Passkey.
But that's not a realistic journey for most organizations. And, but, but my point, it wasn't like, but, But the technology's there, Jack to do it. We all have phones that have recognition.
We all can get keyboards with the fingerprint. We all can get fobs if we wanted it. I'm telling you that to me, it screams that people are not seeing this as a priority.
They don't see security as a good enough priority to just do something simple like that. And if more vendors built it in and made it mandatory, don't rely on the organization, go to the vendor with it, we'd be better off. And I'm convinced it's not gonna happen during my work lifetime.
Well, so now here's the interesting thing is Microsoft just flipped the switch and is now making password this mandatory for its consumer accounts. And that is, and that is under total recall too. So, so, So my issue, my issue with MFA is not that it, I'm against it on any level, but I swear every time I go implement it, it takes three times to implement it.
Then somebody goes and upgrades something and I gotta go back in and re-implement everything that we previously implemented. So, you know, it is not a one and done kind of thing. It's like I constantly have to do that.
Now how many apps do I have and how many platforms? You know, I could be doing MFA every day of the week if I wanted to. Oh, several times.
I'll, many times during the day. It's not just once a week. It's many times.
Yeah, no, it's every time you log in, I know I'm off, I'm, I have to have my phone by my desk just to use my software. That's exactly what it is. You need your phone in your hand.
But let me just tell you something I learned in security early on too. You gotta have a little bit of a breach to get religion. So Mike, when we see naked pictures of you up on the internet, you'll go to MFA.
That's gonna be, I'll tell you, that's gonna be an awesome story for Security Boulevards. Absolutely. Let, let's take, let's take a break here.
Mike's going to go put on some clothes or whatever. We're gonna come back and we're gonna shift a little bit to DevOps. You're watching Textron gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back and we're gonna talk about DevOps and of course they'll probably be a little dovetail in the DevSecOps 'cause it's that kind of theme this week. But we're talking about a new effort by CloudBees, which kind of help pioneer this whole space with the development at Jenkins to unify DevOps. And what they're saying is that they'll provide a control plane that will talk to multiple DevOps platforms.
Not just Jenkins, but GitHub actions and GitLab or whatever else you can imagine. Tracing, you've been around this space for a long time. The land of DevOps is the land of bespoke tools.
Is is that gonna change? And can we just have an overlay? Well, you know, we've been, um, work, we, the CD Foundation has been working on, um, CD events for a very long time and trying to create a standard control plane that would define, uh, actions within the pipeline that could be managed as an event.
So, you know, CloudBees, I'm glad Cloud CloudBees is talking about Jenkins again, thank you. Uh, but I don't know if, if we're going the right direction, um, for solving this problem. So if we think about where we've been, and I've been in, so in configuration management my entire career, there was a point in time that there was an argument that you should only have one SEM tool and everybody should stay on that standard SEM tool.
And every tool out there fought for it ca with Harvest fought very hard for that position. There were other tools who were fighting for that position, but it never worked. So now we're thinking about, we're giving up on that conversation and now we're thinking about doing the same, but with a control plane on top of it so that we can try to unify and standardize, um, this fragmented information that comes from multiple locations.
You know, deploy hub's, doing it too. We're doing it with, with configuration data around deployments. But to be quite honest, I think that it's time that we disrupt, uh, DevOps tools completely.
I'm ready for a, you know, a, a hand grenade to be thrown in the middle of it all. We need a massive disruption in the way that, that we do, um, work manage workflows and do DevOps because it is not, it's very inflexible. Uh, I have complained many times on this show about the how brittle all the DevOps workflows are.
Why are teams not able to add easily things like an SBO m or a collection of evidence so that they have a historical record of what occurred? Why is it so hard? Well, it's so hard because we keep doing the same thing over and over and over, and that is scripts.
So I don't know if adding a control plane for unifying the DevOps information goes far enough. And in their announcement, they did talk about standardizing on some other tooling that probably will make it hard for them to implement or to get adoption across, um, a broad audience. Because every team wants to use their own tools.
And this kind of goes back to our previous discussion around security. We are, we're creatures of habit. We have a culture around security that says we hate having to use multifactor authentication.
And in DevOps, we, we like to have our custom scripts built. And until we can step aside and figure out a better way to manage this, um, we're always gonna be having this conversation about unifying the, the configuration management data into one place. My point is though, not to necessarily manage the workflows in one place or even to watch the workflows, but as to gather the data about the workflows.
Because if we're gonna ever build a, you know, an SML that's DevOps data, we're gonna have to start collecting it. And we don't do that as a community. When if you talk to CloudBees, they, they run, I don't know, 50 million workflows and their, uh, CloudBees SaaS environment.
How much of that data do they collect? And that is where I believe the answer's going to be in terms of better DevOps processing, uh, in the future. I have a few thoughts.
First of all, cloud who I haven't, I, I'll be very honest with you. I thought CloudBees was either in some quiet period that they were getting acquired or that everyone left and the last person shut the lights out. I haven't heard anything come outta CloudBees in months and months and months, if not a year or more now, right?
Um, to be clear, they, they were sort of the Jenkins company, but they didn't invent Jenkins. Jenkins was a fork of Hudson by KK cus cusa before he joined CloudBees, they brought him into CloudBees as chief, uh, tech CTO, and then Chief Science Officer. And then KK and Harpe left to start Launchable.
And then they brought Launchable, which I'm not quite sure what they're doing with Launchable. That was all about testing. But I think they wanted to have KK back because once he left, kind of the whole momentum behind Cloud Beats seemed to have gone with them.
They've had a bunch of fits and starts over the last couple years, right? They tried, first they were the Jenkins company, then they weren't the Jenkins company then they were sometimes the Jenkins company, then they were the partial Jenkins company. Then they gave Jenkins to the CDF and they were big behind it then They weren't so big behind it.
It's, it's been a muddled path for them. And now what do they do? They say, wait a second.
There's a lot of people using GitLab. There's a lot of people using GitHub. Wouldn't it be great if we could suck in that information and just give them one pane of glass or one plane where we can manage these other open source based tools that'll get us back in with the good DevOps guys, I don't, I don't know if this is what the industry wants.
I don't know if this is what the industry needs. I, I don't see a lot of, you know, streamlining CICD management. Tracy, to your point, hey, I say better off.
Go look up something called native AI dev. Patrick Dubar started, DevOps is behind it. Geico, Jeremy, Geico from Snyk DevSecOps behind it.
There's a lot of people coming behind it. They are looking at a better way of doing development and deployment utilizing AI and, and maybe missing some of the, uh, the sins. And, and I'm not blaming anyone.
DevOps was very organic. It grew very organically almost by design. com, I'm still a big fan.
And I think it's done wonders for our industry and how we build and deploy software. I think the platform engineering people have some ideas, right? That that helps.
They don't replace the DevOps engineer, but it's like a precursor to the developer and DevOps engineer. Here's the real bottom line though, fundamentally, I had this conversation with Mitch Ashley the other day. Fundamentally, we make software in a factory.
Software has outgrown being a craftsman, gilded, kinda small cottage kinda way of building stuff to factory level where you have hundreds if not thousands of people involved in, in developing and deploying your software. And in a factory, you have specialists, you have robots, you have, you know, all different kinds of people working in that factory. DevOps is one kind of worker there.
The security guy will be a worker there. The platform engineer will be a worker there. The testers a worker there.
Certainly the developer is a worker there. They all work at the factory. Mike's saying, eh, maybe not.
No, don't, don't nec. I don't look, most developers that I know are are not excited about going to work in Detroit and factory. It's just not, well, Not every factory's in Detroit, Right?
But that's the idea. So, you know, they, they, they, they're, they are in their minds problem solvers and artisans, not just craftsmen. So, you know, presenting them with that metaphor has always been problematic.
And they have resisted it immensely for years now, and I don't see them changing that. Well, they'll be, they'll be replaced by ai. I'm kidding.
I'm kidding. I, I do see an opportunity for, you know, this platform and platform engineering to kind of converge. Like, I think there's a certain amount of, uh, desire for something that feels more like an easy button.
So if you show up with a SaaS platform, there's some folks who are gonna say, yeah, that's good enough for now. And, but there is to Tracy's point, much work to be done. And there are people talking about how AI agents will eliminate scripts altogether.
So it could be a journey, Could be Chris, You folks know more about, you know, the current state of DevOps than I do. But you know, something, uh, you said Tracy, you know, uh, sparked this. You asked, you mentioned SBOs, right?
And in the SBO world, in the working groups where we're all working, we got putting this stuff together, you know, week to week and month to month or the last couple years, you know, when some of this people like me will say, you know, we're not just talking about an bomb attached to some product. We're talking about through the development life cycle, all sorts of telemetry about what's going on being produced and retained. And I think the reason that makes people's head reboots is 'cause how much data is that?
But again, this is where we're going, you know what, and, and, and not that not to try or to try to combine too many issues, Alan, this is the, that that sort of an everlasting, uh, security issue. You know, it's, if it's just a cost and something complicated I need to add to things, it doesn't add a bi business value, then yes, security's a problem. But I see in the development life cycle, actual benefits of having the kind of telemetry that Tracy, you were talking about, where, where you really do have that continuity of visibility in the workflows so that, you know, 'cause because it is a factory of world, how do we actually do this if it's not all done by hand and we don't do it with the amount of telemetry and, and visibility into how we into, into the COBRA building.
All right. So Microsoft's gonna come out with GitHub recall and they we will have it solved. Yeah, Exactly.
I was thinking we need recall in DevOps. I mean, Jenkins doesn't even create, you don't really have a history in Jenkins doesn't even have the, the concept of his, of historical records, right? The ch The challenge is don't have any recall at all.
The, the, the, the challenge is that corporations have an idealized picture of the software factory and a, uh, a, a large corporation like a Home Depot or a Target may have a hundred or 200 engineers working in a software factory. The reality is that most open source tools originated from some guy saying, I have a very specific problem I'm gonna solve. I've created that.
I built a tool to solve it. I'm gonna throw it out in the wild, right? It's, it's sort of a variation of you love something set of free if it comes back to you, it was yours, right?
And it's, you know, if you love your software set of free, if it comes back improved, great. And that's how, so, you know, open source. So that, that, that's basic open source.
But Jack, when you look at the open source of DevOps, when you look at things like GitHub and GitLab and change, But how did those, how did those tools arise? Those tools arose not because somebody did a market test, not because somebody created minimum viable product, figured out what's actually needed in the world and did it. They grew organically with somebody adding this and somebody adding that.
So I point, I'm gonna, I'm gonna call bs I'm gonna call BS on you. GitLab was started because Sid Ani looked at GitHub and said, I could build a better GitHub. This is something people want.
Jenkins was forked because they said, Hudson, we don't like the rules around Hudson and who has it And we can make an industrial strength Hudson, right? For most open source, Jack, you're right. But for DevOps tools, these were tools that were supposed to in conference.
Your developer Team. They did, right? Except for if they had done that, they would've thought about some, a lot of these issues They did that we're talking about.
They absolutely did. In the case of Glab, they did. No, no, no, no.
This is why 25 years after we created make files, which are tab delimited files that are stupid, we created YAML with the same stupid thing of requiring tabs and spaces to set structure. If we had thought about it and said, rather than saying, I'm gonna create something that solves my problem and grow it organically, if we thought about it and said, how do you create a config file that actually works that doesn't have syntax? All of that.
We know we had 25 years of history with make files before we ever got to yamo. Right? We could have, we, we should never have gotten to where we are today.
If we had done an MVP for yamo, somebody would've said, this is ridiculous that I actually have to figure out how many indents I need in order to, But I know people who love yamo. Okay, let, let, let me could chime in here. Part of the problem has been open source, because it's free could be easily downloaded and a DevOps engineer or a developer can get started with it without doing what?
Without doing a single product evaluation. Now if it's a paid for product, they're gonna say, we need to find two or three products. We need to sit down and write what our criteria and them off should be, right.
And bake them off. And I used to get so frustrated in my open make meister days when, you know, go back to, to make, we were generating, um, what we called build control files that got rid of a lot of the problems with a standard make, uh, and standardizing how libraries were being pulled in. And we struggled because we would try to go out and do a bake off with nobody else and the developers would already had written these massive make scripts and the companies would say, well, we've, they already fixed it, but they really hadn't.
They just have something running. Right. But there was never in open source and Jenkins benefited from this.
You never had to go through a proper, uh, uh, product, uh, evaluation. And so what happened? We stopped listening to our end users because they would just download whatever they could get their hands on.
And if it was failing in certain areas, they overlooked it because It was great. Well, so that was the tool, right? Jenkins was the tool.
That was the tool. It had the most attention. I Gotta pull the plug.
I'm gonna take the prerogative here as host to give you my last word. A lot of the open source DevOps tools. Jack didn't follow that.
Cathedral and Bizarre do Open Source because it's, it's cool they did Open source as a business model. And there's a difference when you do open source as a business model. You're just thinking, how could I use open source to get greater distribution of my product that I fully intend to make a lot of money from?
Anyway, we're gonna break. We're coming back tomorrow with more Tech Drunk Gang. Jack, it's been a great first time out here.
Can't wait to have you back on Chris. Good seeing you, Mike. Tracy, we will have you on again real soon.
Maybe tomorrow. Stay tuned for Tech Drunk tv. I think we have no, no Tech Field day's next week.
We won't have a Tech Field Day immediately following, but text drunk TV's on. Check it out. I'm Alan Hummel.
We're out.