Techstrong Gang – October 18, 2024
In this episode of Techstrong Gang, Jon Swartz, Mitch Ashley and Guy Currier dive into the hot topics shaking up the tech landscape. Has AI lost its halo? Our experts debate the implications of this shift in AI governance. The gang also explores the growing concerns around biometrics — are we moving too fast in adopting these technologies without considering the risks? Plus, chaos engineering continues to challenge traditional approaches to building resilient systems.
Transcript
Has AI lost its Halo certification, chaos, and the trouble with biometrics. Three intriguing topics we're gonna be touching on, on Textron Gang coming up. Welcome back to Techron Gang.
I'm John Swartz. I'm here in Seattle at the Lenovo Tech World Conference. Just finishing it up and joining me up for our guest panel in a very kind of meaning, but super sized panel or Guy Courier.
Hey Guy, how are you? Great, John. Good to be here on a super, super panel.
There are strength in numbers are, so whereabouts are you, uh, talking to us from? Um, I'm in San Jose, uh, where I've been here all week for the Open Compute Project's Global Summit. Okay, great.
Um, I was born and raised in San Jose. That's my hometown. So welcome to San Jose.
Uh, which is by the way, is larger than San Francisco. There are a million people in San Jose, and also, of course, I, my hero, our mentor, the man who just was promoted. Mitch Hasley.
Mitch, welcome back. You are in San Francisco? I think I am in San Francisco.
I take it. I must need to check my email. Do you have some request something you need me to write or something?
Is that what all that was about here, John? Well, I, I know also you saw, uh, you've gotta get another title. Maybe you could just fill everybody in.
I saw that on LinkedIn. Yeah. Well, thank you.
You know, that's how we do all of our announcements, you know, on LinkedIn and then, then all, everybody internally can read it. No, I'm just kidding. Um, yeah, just, just recently, um, moved into the role of VP and practice, um, leader for our DevOps and application development.
Um, Paul nti, uh, filled that role before. He's doing some other things now and, and, uh, so they asked me to step in, you know, I was working with Paul kind of in this space already, uh, but just taking over his practice leads. So I'm excited into this extinction.
Of course, the work that, um, we've done at Textron and Textron research and, you know, I love working with Guy and all the people we have at RUM yourself, of course, John. So, um, just kind of more, more of the, the same, but even better. So I'm looking forward to it.
So without issuing a, a spoiler alert, I mean, I will say it, I think we're about to merge with the Futurum group that's gonna happen any day. So we're very excited. We're gonna merge all of our resources, so we're gonna have not just all these great research reports, we're gonna have more stories tied together.
I'm really excited about it. I actually saw Daniel Newman, who backstage interviewed Lisa and Pat Geling here after their announce. So, and the, uh, the interesting Patrick Moorhead, Patrick Moorhead, who floats everywhere.
He is kind of the, the analyst God in tech who, uh, ever present in Austin, ever present. That's the perfect word to, to describe him. He is everywhere and everything at every time.
So let's start off with the, the first topic, which is basically has AI lost its halo. And we had a column from Elliot Coken Hound who said he's optimistic about the impact of ai, particularly in doing work that takes slow, low level, mundane work off people's plates. And he's not only excited about that, but he also has some qualms.
He's, he wrote from San Francisco where there's a lot of hand wring as always about technology. So we can't get enough of a good thing, but when we do, we start worrying about the repercussions and where it goes from, from there. And there are plenty of concerns, I would think, in terms of security, trust, misinformation, guardrails, sustainability.
But I wanted to, let's start off with Guy, guy. Where, where do you take this in terms of a ai AI and its, its upside versus the, the, the whispers of some of the downsides? Well, I think that, um, it's really interesting to be at the Open Compute Project, global Summit this week because like every conference, uh, and virtual in-person, whatever, everywhere for the last year, it's all about ai.
Um, but the OCP tends to be, in my view, a bit of a bellwether for future trends because, um, it's filled with practitioners, but especially vendors. And, uh, there's a lot of collaboration on where they see, um, you know, the future and of any given trend. 'cause they're trying to establish as quickly as possible standards to address that future.
Um, so, and OCP is pretty hardware oriented, infrastructure oriented. So there's was a whole lot of discussion around the need for high speed connectivity between accelerators and nodes and that sort of thing, because that's needed for AI training. And then also the need for a lot of memory that's very close to the processing, like all that kind of thing.
Um, but what's really interesting, um, is, uh, so I think that there's sort of two trends going on. Um, one is visible and one is less visible. And the one that's really visible is this idea of we need to understand AI better, how it works.
Uh, one of my little hobby horses that, you know, probably you guys have both been exposed to is that AI is actually three distinct things with three distinct life cycles. Um, because there's training, there's tuning, and then there's, uh, rag for, uh, uh, for inference. Um, and what you're starting to see is this first trend, which is this sort of maturing of understanding.
It doesn't have to be my hobby horse, just this idea that not everything needs to be a huge model. Not every AI is generative ai, um, and so forth. One of the really interesting sessions that I attended, uh, talked about how smaller models can get the job done, and we've all known that, but that coming more into public consciousness, I don't think it will for a little while.
But like I said, OCP tends to be the sort of bellwether for that sort of thing. So that's trend number one. Trend number two, which I think this column is, uh, uh, uh, uh, sort of hinting at and is less visible is when the shoe, other shoe drops in ai, which is, you know, to my sense, and we've talked about that on this, uh, pod before, is when we start to actually run outta power in certain spots when we start to run out of silicon, um, there'll be this sort of other reaction, which is, uh, AI doesn't do everything it's supposed to do all the time like it had been promised at the same time.
Is, it's actually not available to me, or we are having trouble implementing it. And it's that in six months is in 18 months, we don't really know. But, uh, that I think is where we can remain optimists if we're thinking in the right time window.
But we have to remain realists in the sense that there's a whole lot you can do right now, but it's not just like cloud and everything else before, it's not everything that it's promised to be, not yet. And we're gonna have stumbles, we're gonna have security issues, we're gonna have all these other sort of things, but what's really gonna be the problem is when we can't advance because of the resource issue. So that's, that's, that's gonna something I wanted to, I was expound upon something you said, uh, guy, in terms of like the timing, in terms of the expectations and Mitch, that that's, it's, it's interesting.
We have, um, this, this kind of impatience around something that we know will be incredibly significant. Who knows how long. And, and maybe you could touch on that, because I think that's also kind of goes to the core of what Elliot was writing about.
Well, I'm gonna, I'm gonna draw an analogy. When I, when I started my career, I worked in, in IT and banking, building banking software, and we had these giant rooms with checks, sorting machines. They looked like a long conveyor belt that just had checks fine by, they would take buckets of checks, set 'em in there, they'd all get sorted into bins.
They'd take each of those bins, combine those similar bins together, re-sort 'em. Eventually you get the check going to the right place. What stayed here, what went to another bank?
La la la. This was like when physical checks are actually, is what it took to deposit funds inside the bank. We, we go through this sorting out process with technologies.
We did it with cloud, right? Oh, everything's gonna move to the cloud. We over promise and deliver in the beginning.
Oh, what about security? Oh, what about reliability? Oh, can we move everything?
Oh, you know, it's, we, we way over rotate on what the expectations are. Some of it, some of it, um, yeah, all, all of it. And good intentions for the most part.
Sometimes it starts to get pulled back by a little bit of over hype, maybe a lot. Um, and we're going through that sorting out process now with the next phase of AI moving be probably because of, uh, te ai. So I think we're part of this sorting, and I like your framework that you laid out, guy.
I think that's very well informed and, and, you know, very, very disciplined CTO mindset. I appreciate the way you approached it. Thank you, peer.
Yeah, you bet. Um, I, I think another side of that coin, the way to look at it, uh, what's happening is also in parallel is we're going through that hype cycle. Um, and we're, and we've thought about ai, largely generative AI as all the things it's gonna do or for us or to us as individuals in our lives and in our work.
How's it gonna improve my writing? How's this gonna improve my calendar? And how's this gonna improve my code?
Whatever it might be. Um, or is it gonna eliminate those things? Well, we start to see us not eliminating everything.
It's gonna change, uh, in large part how we work. Now we're starting to see, okay, how is it gonna be part of my work, not just eliminate my work. So you'll see a lot of people talking about agents.
We're gonna talk about BMC coming up here. Um, yes, I just got back from Atlassian. They're, they were introducing their agents, which happens to be, their philosophy is, uh, there are human teammates and AI teammates, then they're all, uh, teammates.
They're people in the system. And ai, AI gets assigned work. It's supervised by people.
It doesn't get, you know, uh, it's not ag agent yet the new phase, right? Not everything's gonna be that way. Maybe not that way for, for a long time.
So we're seeing where AI fits not into my own individual productivity, but also into workflows, into teamwork and into operational aspects of our business. And a lot of it's being assigned, um, let's say the toil work. Okay, let's automate things we don't, we don't want to repetitively do, right?
Why do we pay our, you know, our, our well talented operations or security or development or testing people to do those repetitive tasks? Let's have them do higher order functions. Or it can also be used as a, um, I, no one can consume all that information, but let's go apply some guidelines.
We have brand guidelines. Let's go look at all of our marketing content or all of our published content. Are we following those brand guidelines?
No wrist slapping, no changing automatically, but now we know what to go. Okay, got some adjusting to do to kind of bring it back in. You can imagine for compliance, for security, lots of different applications.
So, um, yeah, I, I think it's very natural for the Valley Valley to be in freakout mode. 'cause uh, if you've been, I haven't lived in the valley, but certainly experienced enough cycles of boom to job loss, to boom, to job loss, and everybody wonders what it's gonna happen to them is not just jobs change, but companies come and go. And that's part of that freak out mode.
I think we're seeing. So very long answer. Yeah.
Not as well disciplined as guys, but here are some thoughts about What we're going Well, no, It's excellent. So Mitch, here's the, here's, here's the thing. So, so what, what do we want our audience to know and do, right?
Um, the, the hype cycle, the valley of despair or whatever it's called. Like all those sort of sort of things, right? Remember, you have goals and needs in your business and in your technology use.
And I like to say you both may disagree that the productivity aspect of ai, which gets all the focus and that's the, it's gonna take my jobs or I can fire a bunch of people, or like, whatever it is. I think that's truly secondary or third in line to the two great benefits of ai, which are reliability and quality, frankly, reliability and quality. Let's remember that as I like to say, there's no such thing as an AI application.
There are AI services that change, automate, inform, assist applications. So when what you're trying to do is give your workers, give the workers the ability to reliably produce, that is a productivity gain because AI assists them. AI proposes, AI gets them away from, from procrastination, from being stuck, or any of that sort of thing.
All of us are saying all the time, don't leave AI alone. There needs to be a human to review it. So now you have a human who is more reliable thanks to ai and who can get more cycles of review or start from a further starting point thanks to ai.
And that's what improves quality. And you can do that whatever the troughs and values and all the whatever tools you have available to you. It might not be the best model, latest model, the latest service or any of that sort of thing.
You can continue to pursue those goals through any peaks, valleys, shoes, dropping, any of that other sort of stuff that might be going on. Yeah, you know, it's interest. There is a parallel between Silicon Valley and Hollywood in a certain sense that we like these storylines and we follow them.
Maybe a even a more enhanced steroid induced cycle than Hollywood, where we go rags to riches to rags, back to riches. So there's this kind of trough, I think Elliot refers to trough of disillusionment. But I, I wanted to go back just briefly, uh, to something Mitch mentioned, uh, out of VMC, which Mike Baard wrote about, um, they previewed at their show in Las Vegas, a pair of tools that should make it simpler to ensure high quality data is only used to train AI models.
Maybe that is assures us in a certain sense, maybe each of you or one of you could, could kind of address what BMC is doing and how that might play into this whole story. Well, I, I think, and, and you mentioned rag guy, uh, one of, one of the ways to introduce your own data into generative AI without having to train the model, but then there's also training the model. Um, the challenge with these very large, um, large language models is the vast information that's being consumed or built into the training process of those, which takes a lot of this power that we're requiring in, in our infrastructure.
You know, not, not all things are equal. Some of it is good quality, high quality information. Some of it is just out there in junk.
And, you know, we as humans are not in the process of sorting that out. We're relying on AI to do that and improving the algorithms and things to do that. But in an organization you can't afford that.
You're not, you're not gonna have, you know, the Bank of America building the next most massive, a large language model, at least not anytime soon, that will overcome anything that Nvidia and open AI are doing, right? They, they want models, whether they're machine learning and, and, uh, AI models, or they're large language, small language models, whether they might be to be well tuned to specific needs, not just general purpose models. So you, you have two different ends of the spectrum, right?
I'm gonna use this for writing 'cause it's got, you know, massive quantities to, I want something that's really tailored to writing highly technical engineering documents for building designs, right? Where do we get that? 'cause I can't have this other stuff seeping in, right?
And so that's, that's part of this winnowing down that sorting machine, sending the right checks to the right location. That's that process we're going through is, okay, how are we gonna be creating those things? And the tools that, that, things like BMC are coming out with are things that aid organizations in doing that.
So they know what things to build into the model. What do we really need to train? What things can we put in front of, you know, through a rag process that might be in a ve you know, might be, uh, accelerated through a vector database, but might come from file servers and data storage devices and document systems or whatever, uh, search algorithms that might actually feed into that.
So again, I think this is that maturation process of learning to guy's point, how, how we use AI and how, how to get the outcome we want out of it. Not just the next coolest thing that, uh, the folks at, uh, Textron will write about. You know, we write about Shepherd that, but you know what, what, what's not gonna just grab an a headline, but what's really going to make my operations more efficient, help people get more done, take away the toil and work on the things that actually make a difference to continuity, customer value, business value, things like that.
That's good. Hey, uh, guy, we only have about 30 seconds here. Do you want to add anything?
If not, we can move on to the next segment, but, uh, I want to give you the final words. Well, thank you. I think that, uh, we would all agree 30 Seconds.
Remember that I think we'd all agree that, that that AI is the greatest technology wave EA that we have ever seen. Um, and it reminds me most of the PC revolution in the eighties and nineties. I mentioned that here before, where there was in intense investment for decades with no perceived economic impact on productivity at all, because the benefits were so obvious.
And I think that it'll be a shorter cycle here, but it's the same thing. So full speed ahead. Um, and I think we're learning quickly also.
And that's encouraging. Speaking of full speed ahead, we're gonna go to the next segment, which has something to do with a truncated type of schedule in terms of certifications. So we'll be talking about that and we'll be right back.
Cloud native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at cloud native Now.
Alright, we've rounded, uh, turn two here. And John is ceremoniously handed off the baton to me. So I'm taking the lead.
We're gonna be talking about certificate or certificates actually. Um, apple and Google, many many folks have talked about the lifespan of digital certificates that we use in our systems, our servers, our applications that are in our browsers that are in our phone. They are essential to how we do encrypt, both encryption, uh, between devices, applications, software, et cetera.
But also identity of, uh, and authenticity of, um, and trust of devices and, and software as well. Um, and we've been in a world where certificates might last 20 years, they might last five years. I'm, I'm issued many or require, uh, issued a lot of certificates in my past lives, uh, and in the certificate authority business and also consume those certificates, putting them in in servers and devices and things like that.
But that window of trust, I think we're realizing because the pace of innovation so happens, software change happens so quickly and so rapidly. What might be trusted today may not be as trustworthy or at least question the trustworthiness of it tomorrow. I'm here at, uh, security Field Day this week in San Francisco, not just enjoying the sunny weather here.
Uh, but, um, and, and we actually had a presentation yesterday from DigiCert talking about their business, who I've worked with in the past as a partner. Um, and there's a great article up on sec on, uh, security Boulevard, talking about Apple wanting to shorten the time span a lifetime of a digital certificate. Now, digital certificate's gonna come and go.
They live until it's, uh, a date, and then they're gone according to the date in, in that certificate. What's different here is Apple wants to shorten that because again, of the issues that I mentioned around how long can we trust that certificate, um, but also not just relying on the date inside the TI certificate, but applying their own timeframe after a certain timeframe, even if it's issued for three years after 45 days, we will we'll decide not to honor that anymore, which is a bit of an oxymoron because now we, as if it's an end user or a digital certificate on our phone and we have to get something renewed. What is that?
I don't know how to use the CT manager. Hey, what, what do I need to do? Or it's developers, um, uh, providing updated code with, uh, digital signing of the code certificates of the changes to that.
So we're in this new kind of window of, well, maybe we don't follow the certificate anymore. We apply our own policies to it, which could improve security, and it could also open up a Pandora's box of, you know, well guide trusts 'em for 90 days, but I only trust him for 45. And John trusts the data and the certificate, who's right?
And how do we as the consumer of software, hardware, and services not get screwed in the end, because now all of a sudden things are unreliable and stop working without us realizing it. We're talking about Mitch on Yeah. Oh yeah, go ahead, John.
You go ahead. Go ahead guys. No, no, you go ahead.
So, uh, Mitch, we're talking about, um, uh, the, the way this works 'cause you know, it's not really an area I go deep on. Um, the way this works is the, the certificate, um, allows for a secure, meaning an encrypted connection, um, between the user agent, which is usually a browser, but it can be a mobile app, it could be a lot of things, um, between the user agent and the server. And that means that, um, I know that, uh, uh, you know, the communications are essentially private between, you know, me as the user using the user agent and the, the, the company running the server.
So, um, I'm just wondering, uh, why did we ever wanna put that in the hands of the company to begin with? And we don't see, it's not, so when the cert gets set, um, the validating authority, first of all, it's a central val centralized or central val validating authority. There are a lot of them, but, uh, most of them are private companies.
So I'm trusting that I'm trusting that the user agent or the browser or Apple or whoever trusts that company. That's okay. I can see that.
But, uh, then the company itself, like you say, they could set it for 20 years, they could set it for whatever, I have no idea what they're setting it for as the user. Why did I ever want that to begin with? Well, why didn't I wanna do it myself?
Or, or go and say, you know, like, um, I don't trust any cert ever forever, so I'll do it per session. And after that it expires. I guess the, the analogy I'd make is if you thought with managing passwords or the pain in the butt, can you imagine managing what certificate?
I mean, there are literally hundreds, maybe thousands of certificates in a device. Um, everything from hardware subsystems, modules to individual applications in the, what they use for, you know, S-S-L-T-T-L-S, encrypted communications. Um, without getting too way into digital crypto cryptography, there are, are issuing organizations that we, uh, put our trust in.
Google is one, dig certs another, entrust a whole number of them. Um, and including some kind of open public things that are available to issue certificates. And they serve many different purposes.
If I'm buying a, uh, a computer and it has digital certs in it to say that the bios is valid and it's not been come from a corrupted source, or my application software from Microsoft is valid, and it came from a trusted source, we don't, as end users don't have to worry about that stuff, that should be them. And, and Microsoft gets to set their policies around how long that certificate is valid, because guess what? They're the ones that have to reissue it and distribute it when it is, when it goes out of date.
Um, so I know this from working in the wifi and the cable modem and set top industry. And what's interesting is even when you set 'em for a long time, oftentimes that those devices live much, much longer than intended, um, we've had to issue reissue new certificate to the devices that are 10, 15, 20 years old that we thought would not be in use anymore, but they still are. So here, I, I think I, what I don't really get yet is what the motivation, true motivation is behind why an apple would say we're gonna limit a website certificate below.
It's just 45 to days. Even, even if the certificate says something else. On the one hand, the principle of shortening the lifespan, and by the way, some certificates can live, have a lifetime of seconds or minutes.
They don't have to last a long time. 'cause that one communication, I want to be able to, uh, set the trust of it for a very short window. Um, but the, the purpose of doing that tells me there is something they are seeing in websites.
Um, and I think it's to thwart, um, those who have acquired them nefariously, and they're, uh, they are bad actors that are setting up websites to do spa, uh, uh, not just spam, but, um, spoofing, um, phishing, things like that. So it's easier to say, I don't care what the certificate is that, that we're not gonna honor. And I think that's probably the motivation, but we'll have to explore this some more.
Yeah. Long answer guide. That's that, that's a guide Your question.
I apologies. Yeah, you know what? Well, that I was gonna say that, that you answered the question I was gonna ask you, Mitch.
Like, it seems as if these cert lifespans are absurdly short now or the, the, the bar is being lowered or not lowered, but, but truncated, I think, was it Google's 90 days, Apple's 45 days, right? Which in a sense, I guess it's in the name of internet security, but it, it shifts the burden squarely to the shoulders of the systems administrators. And I'm wondering, does is what's going on?
Is that a reflection, uh, of a larger reflection of this ramped up our amped up tech development cycle during this age of ai? I mean, is that somehow related? I, I just don't know.
I think I so, so, so boohoo, I I really don't like, you know, for 90 days, 45 days, I, I, I get it, it's a headache. But these are not, these are not scenarios like credit cards where Congress passed a law 30, 40 years ago whenever it was holding the credit card companies liable in the case of fraud or, or a hack or whatever. Like, you know, that if you lose your credit card, you literally lose it, or you pull it outta your wallet and toss it into a room and say, have at it people, right?
That you're liable for whatever, it's $250 and the credit card company has to handle the rest that puts the burden on them to ensure security. And that's how it ought to be. And I don't, you know, I think one second or one minute or maybe five minutes that sounds about right to me in terms of how much trust I have in this whole complicated system of, uh, ensuring, um, you know, encrypted secure communications and we're just, we're talking about a system problem that may be hard, but could be really helpful to solve.
And I have to think, uh, Mitch, you know, I, I, I think about zero trust scenarios. Um, and zero trust, uh, has a lot of appeal in the sense of why should I even trust this cer, you know, this TLS or this SSL necessarily, when the system at the other end could certainly be compromised. And I have no way of knowing, and I might wind up paying as a result.
So I might as well have, uh, user agents or devices or what have you, that is that assume that this certified, you know, connection is not actually, you know, uh, uh, without risk. Well, there, there, and our next neglected dimension, um, they're working through organizations like the certificate authority browser forum, which is who set these standards for the browsers here. Here's what I think it really is going on.
The, the, the punchline here is we're moving from a very manual world of issuing certificates. By the way, can you imagine in today's world, there are revocation lists Sure that you know, are, these are no longer valid. Even though they say they are, we're not gonna honor these certificates.
Can you imagine, you know, how many certificates have been warranted to be not trustworthy? So what we're, what we're moving to is this world of issue. It eventually gets renewed or, or might be revoked to.
It all needs to be managed. It needs to be in a, in a, uh, certificate management system that's automated. And it doesn't matter if I change 'em every second or every five minutes, or every five weeks or five years, the reissuance and the revocation of an invalid, uh, certificate and the application, putting the certificate where it needs to be in our device, in our software, in our servers, wherever it might be, that's all automatic.
So it doesn't matter how long it, it, it issues for, if I wanna make it for 10 minutes today, 'cause I'm Apple and I've got this, this whim, great. Everything updates. Now, there's a cost updating certificates there on big, big heavyweight things, but I just want, don't, we don't wanna be in this sort of manual back to the sorter machine that I used, uh, previously in that example, it needs to be all digital automated, no manual process involved, and easy to, uh, operate system.
So imagine how often our AI systems are, are updated, right, with new data through rag new training in, in ai, generative AI new, uh, AI models for machine learning that cycles can shorten and shorten and shorten and shorten. And same issue. What's trustworthy?
Is this model a trustworthy one versus a one I saw five minutes ago? Yes, I know it is because who said they issued it and says it is trustworthy is by that certificate, but nobody had to get involved because when it was deployed, that certificate was created to an automated process that we trust. That's what we're moving to.
Well, our certs is almost expired for this segment, so I think we'll leave it. I'm doing at that and we'll, I know, I know. And I think I, we, we'll, we're gonna, uh, make a shift and talk about something that I, I remember writing about forever long ago, biometrics in kind of a new twist on the whole topic.
com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com where the world meets DevOps. We're back at techron gang.
And, uh, we're gonna talk about biometrics, which is something I remember writing about decades ago, which is dating me in this industry. But in, in any event, so is AI technology advances. We're seeing more sophisticated, secure, biometric authentication solutions that are emerging.
And the reason why is we only need to pave the way for a, a future of the frictionless and trustworthy digital transactions. Um, I, I think maybe some of the emerging biometric modalities, uh, will be iris recognition and gate analysis, gate analysis. Um, and, and I think with the kind of the, the, the addition of AI is gonna create a lot of interesting, potentially interesting models.
I leave it up to, to both of you all to, to tell me what is the difference or going to be the difference between biometric authentication, which I remember back in the day is scanning my fingerprints or pattern passwords or facial recognition or eye scanning. How's this gonna move on to this next era? Well, I'll, I'll jump in and say, think of the transition from physical attributes of us that we might scan and do facial recognition and fingerprints and things like that to, and I don't remember if the article that we, that we, uh, that we put up references this or not, but think almost of as a digital twin of here's us and our behaviors, right?
Here's what we do online. Here's our digital behaviors online. Here's our everything from, you know, when I go and order Mexican food, I usually get a burrito.
But Mitch suddenly is ordering something different. Why is that? You know, something very different.
I'm just picking a ridiculous example here, but think of where this is heading, is creating essentially a behavioral model, digital twin of us and our behaviors, and identify using AI to identify both the factors that will help not just one, but many potentially thousands that help identify behaviors about us that would indicate something out of the ordinary that might indicate that there's fraud, or that the identity of who is doing this is not the same identity. And that's where you couldn't do this any other way without ai. 'cause the amount of data and na number of points to assess and analyze the models it would take to determine this really do require an ai.
So I think the, the identity, the fraud, the finance, um, economics of this are driving us to think about how do we take AI and biometrics to the next level and think about our digital biometrics, if we wanna think of it that way, uh, to help identify fraud and, and errant behavior that might lead to helping us from not getting our data stolen or fraudulent transactions happening. That's wonderful. Um, I think actually Mitch, uh, the burrito ordering analogy is, it's not, it's not actually analogy.
I think it's perfect. I think it's perfect because I think that the driving force behind biometrics is not security, it's convenience, it's simple and easy. I'm just, you know, like the TSA, uh, lines, uh, I, I'm based outta Austin, Texas, so I don't know how widespread this is.
I've seen it a lot of places, but, um, uh, they do a little, uh, facial recognition now, um, instead of, uh, uh, a physical id. Um, and I'm just kind of wandering by and it's already taken my picture and identified me. Um, and, uh, the burrito ordering analogy, I mean, I totally, completely agree about your digital sort of persona, if you like, behavior, your IP address, um, or, or your relay or if there's all kinds of, let's say metadata about you, a as you are using, um, the internet in various ways, um, that can help identify you and make things much more convenient for you.
It's just like the, the, you know, going to your favorite store. They know you, um, they know or your favorite restaurant, they already know what your order is. And when you do something different, they're like, oh, but they recognize you.
They may not even know your name, but they recognize you. This also points to the problem with it because, um, I don't know if you have ever experienced AI making a mistake before, but I have, in fact, Mitch, you probably did that earlier today. Um, so, so in the end right now, it's humans training and building these systems to do this sort of thing.
And, um, it may be more accurate, but it may be less accurate than a human would. Maybe it'll end up being more accurate than a human, but it can't, by its nature be infallible. And so we start putting more trust in something that doesn't deserve that level of trust.
And that's what concerns me. And, and it can't be unilateral. I mean, think of a no-fly list that's, I'm talking about ai, well, maybe it's AI contributed now too, but you know, one, you don't want to be on the no-fly list of fraudulent transactions.
So now you can't get yourself off what happens when there is a mistake, guy, you know, inaccurate. And there's also, you know, other factors to consider, like data poisoning. Once data gets into an AI system that is fallible, inaccurate, maybe even just an inaccurate algorithm calculated your, your property taxes, and now suddenly it looks like you own something you don't own, um, you know, that data can get into models and live on forever and poison follow on, um, you know, inferences and and analysis that are performed.
So this is, uh, I think is one of those. I I like your TSA analogy too, by the way, because when we have that in Denver and several other cities in Denver, you notice it takes a picture of you and there's also a person standing there next to it, talking to the TSA agent, at least the clear person anyway, has a picture of you and looks at you and the picture and the TSA looks at your, at, at your information. So there's a human in the loop there too, is what I'm trying to point out.
So it, uh, it, it's an, uh, it's an inevitable idea, I think of how AI applies too, Because of the convenience. Because of the convenience. So that's the tension.
Yeah, that's the tension here. It's, it's, it's, it's similar to what we did with cloud, which was that, you know, uh, led by Amazon, but all the cloud meter cloud vendors were saying, you know, it's pay per use, it's very efficient, you're gonna save money. And the opposite turned out to be true because the reason people were doing it was actually to cut out, you know, ticketing and having to run infrastructure themselves and all these other things.
Were driving them there despite the headline benefit. And in the same way we have this tension, the headline benefit is, oh, it's more secure because you can't really fake your fingerprint. Well, I mean now we know you can, but yeah, exactly.
So there's this tension between what's driving it, which is the convenience for the user and the supposed headline, you know, benefit of greater security. And when you add AI into the mix on both sides, I don't know, John, what's the truth anymore at this point? Seriously, It's, I've been trying to figure that out, especially in this era, day to day, hour to hour.
And you know, it's interesting, uh, guy, you mentioned convenience. And I think whenever I think of convenience, I think of commerce and in a sense we've talked about, and we've written about AI's impact on the holiday shopping season. And I think, I guess where it all comes down to if the customer feels more secure and there are u user-friendly ways to perform a digital payment, they're going to adapt to this and they are going to follow.
I mean, I remember the day when we were reluctant to buy something online and, and now it's second nature. I buy everything online and, and online knows everything that I want, and that kind of mirrors the way I, I buy coffee for instance. I go to the same place every day because they know who I am.
As soon as they see me, they start making the drink before I even get to the front, you know, so they're assuming and they're assuming correctly what I want, what I need, and I feel very secure in that scenario. So, um, again, it's always with tech, the telehealth tech industry, it's always been about convenience and ratcheting up sales in a sense for consumers. Enterprise may be a little bit different, but nonetheless, it's, it's kind of, it's, it's fascinating with, with the, the stories getting to the core at and, and what biometrics might mean, especially in the next couple years.
I think we're, we're seeing, we're seeing a c change in the process here because think about two factor, how many people think two factor is a pain in the ass, whether it's a text I have to type in the code for, or, or an authenticator app that I've gotta get out. I think with the, the c change that's happening here is we're now designing because we have more capabilities, we're now designing convenience in instead of testing where the limits of I have to take my shoes and my belt and my off and I gotta get out my, my credit card and my, uh, passport and my, and my driver's license Id just to get through security. Now I can walk through, I mean, I've literal walked all the way through, um, you know, other than a biometric on my eye, which kicked off in addition to getting photo taken that I didn't stop for.
And I've walked all the way through TSA without stopping other than to get my bags off the belt. That that's what we're seeing here is to guy's point about convenience. It's all about convenience and how much inconvenience the consumer, the end user, the individual will, will see as unacceptable or not acceptable as at all.
And now we're designing systems saying we can do a lot more security. Um, at the time, you know, it's kinda almost like total recall, you know, walking through the, the scanner on Mars, right? And this person gets through this person's carrying guns or whatever.
It's that same, I think of, I think of, I think a minority, sorry to interrupt. I think of minority report and basically, uh, ads are being projected to you as you walk by the certain stores that you might be interested in. And then it sense it goes back to something, uh, a couple years ago I remember interviewing, uh, ed Bastion, the CEO of Delta, and he talked about their long-term plan is to make it as easy as possible for you to get through security, get to your gate, find out all the information you need to know about your flight, the status of it, what your needs are by just kind of glancing at a very personalized messaging board in the future that's directed to you.
Well, let's think about, you can go to an Amazon store in the, in the Las Vegas terminal, walk in, there's no people in it. Pick up what you want and walk out and it's all going off of information that's on your phone in your, in your Amazon account. Imagine getting on a plane.
What, why do we scan our phones with and or scan the, the QR code or the barcode on our ticket, this stupid paper. Typic typic. Even even the, the thing we have in our wallet on our phone, there'll be a day when we walk on the plane without ever getting any of that out.
And it'll know who we are. You'll know we have a valid ticket to get on, uh, and it we'll know where we are 'cause it has other identity information about us in our phone or biometric scanning, et cetera. So that's where this is going, where we don't have to take an action for many of those things to validate the security or identity of who we're, So we're gonna leave it guy, you're gonna get the last words.
'cause I think we're, we're kind of get coming up against it right now. I think that you both mentioned commerce. I've called, uh, uh, retail, the, the, or Yeah, retail essentially I guess includes, you know, food, restaurants, ordering, that sort of thing.
It's the killer app for, um, for generative ai, so to speak, because, um, this kind of, you know, I I talk about like, you know, reliability and quality being the real benefits of adding AI and AI automation, and it's the same sort of thing, which is that your shopping experience is so much improved simply by decent suggestions. We've been dealing with really crappy suggestions for many years because they are not using AI or generative AI and your past history and all this nice tuning and rag and all this sort of, sort of stuff that we're starting to see come online so that Mitch, it's going to know that burrito order that you typically do, but it's not going to force it on you and it's not gonna show you some weirdly sorted example of three recent burrito orders you made. Um, it's going to say, you know, here are, are you, you know, it's somehow going to put somehow, I mean it's, there's a, there's a method behind it that puts together everything and says, well, when Mitch comes in on a Thursday at this time, or enter the site on Thursday at this time, this is much more, this is more likely it's the same sort of thing.
And you just extend that to everything else. Um, when it comes to biometrics, um, or these digital imprints or any of that sort of thing, we're talking about this funny confluence of that kind of prediction with security. And that's where we sort of head off into this unknown of, is that kind of pre, because the, like you've said, Mitch, there's human intervention all along right now with the current systems.
Um, at some point there's not gonna be human intervention and it's gonna be a minority report again. And black clad people are gonna fall out of the sky and grab us and put us on a watch list, um, metaphorically speaking. So we'll just wait for that.
Wow. Cringe. That's gonna be a bad Flashbacks, not the ones you Yeah, Exactly.
Exactly. Wow. Uh, well on that imagery, let's, let's end this segment in, in the show.
We want to wish everybody a great weekend and um, Monday's episode, I think Alan Shimmel and Mike Biard will be back. I think Mike is still celebrating probably the imminent return to the World series of the, of the New York Yankees. So I'm sure that will be top of mind for him.
Well, hey, I Also wanna thank, uh, our sponsors every, uh, burrito restaurant across the globe, ask just to talk. I'm hungry for burritos now, so let's Look. Damn.
Yeah, I can't get outta my mind now. Yeah. Um, in any event, uh, we have a lot of programming coming up later on.
Text rock, tv. Um, thanks guy. Thanks Mitch.
You guys are, are awesome. Uh, pleasure. Great flow of conversation between the two of you.
It's, it makes it so easy to to host this. Uh, so again, everybody have a great weekend and we'll see you down the road.