Tackling Secure DevOps in an IoT World | DevOps Experience 2022
At DevOps Experience 2022, Stephen Chin, Amit Ezer, Jim Mercer, Lori Lorusso and Amit Serper discuss securing DevOps in an IoT world.
Transcript
Good afternoon, everyone. Thank you for joining us for tackling iot in a devops world. They're tackling secure devops and iot World.
Excuse me. My name is Lori Larusso and I am with Jay frog I am our open source program manager, and I'm very happy to be moderating our panel today. And so I would love for our guests to introduce themselves and I'm going to start with a meet either to my left.
Hey, yeah, my name is Amit. Thank you for having me here today. I'm managing a group called connect in jfrag doing everything that is about iot and previously was the founder co-founder and CEO of apps with that was acquired by Jay for a year ago.
So so happy to be here and looking forward to speak with you. Thank you and next. Let's go to gym.
Hey, thanks, Laurie. Yeah, my name is Jim Mercer. I'm our research vice president here at IDC.
So I focus in the area of devops and devsecops. So a lot going on there in terms of devops and looking at the entire devops pipeline, but also a security is is a huge impact there and you know how organizations are trying to inject application security into their devops pipeline. So nice to meet everybody.
Thank you very much. And our next meet a meat Serpa, please hi. So I'm also a meet.
So there's a twice as twice as much a meats here, which means that twice the fun just for the sake of clarity since everyone anyways referred to me by my last name. So just to make it easier you can just I'll be super here in this discussion. I'm the director of security research at a startup company from Israel called sternum personally.
I'm based out of the us and what we do on my team is we look for a lot of vulnerabilities and iot devices and we try to make them safer and better with our product great to be here with you and I'm looking forward to with discussion. Thank you very much. And last by no means least we've got Stephen chin who is joining us from the airport in Atlanta.
Hey, so thanks for having me. So I'm the VP of develop relations at jayfrog. I think being in an iot panel.
There's no place more appropriate the iot session from then being surrounded by well a lot of people but also a lot of iot devices. So I'm literally in an airport as you can see and the plane is outside. So We love your dedication and we appreciate you being here right before your flight.
This is crazy. Okay, so since we're all here, we're all just getting warmed up. I thought I'd start with a very easy question very light and just what gets you excited or interested in iot?
What kind of turn that spark on in your brain and Stephen. Let's just start with you. So I I mean, I've been a huge fan of iot devices and the internet of things for for a long time both.
I think it's something which impacts all of our Lives now that we have. Smart cars and we're heavily reliant on cell phones at different devices. But even more importantly it's something which is software developers.
We can program we can control I think Raspberry Pi is really brought industrial iot devices to you the hands of your average developer in a very easy to use modern Linux based platform. But you know similar sorts of custom armchips and devices are what power a lot of the different iot devices running behind the scenes and I think it's something which we all need to understand the technology understand the security aspects of it. And this will help us to build better more maintainable software that power is all of the critical systems which we use day to day.
Awesome, super I saw you nodding you go next. Yeah, so with me, excuse me with me it started I think over a decade more than decade ago about 13 14 years ago. I had I had a router a Linksys wrt 54gl that anybody in my field almost knows it by heart.
It was a router that links is made where you could it was based on Linux and you could load your own custom Linux to it or use third-party distributions like DDWRT or openwrt. That's what got me into it from a security perspective and what got me excited about breaking those devices and finding vulnerabilities in them was That those devices are often the most important device in your network where if you're talking about a router all of the traffic goes through it inside a network and outside of it back to the internet and all of the firewalls and all of the all of the fancy stuff. The fancy security stuff is always behind the router.
But if the router is the first thing that touches the internet you can actually connect to it and maybe find a vulnerability in it, maybe exploited maybe do a whole bunch of stuff with it. So that got me into really into like hacking routers and other iot devices and I have used those devices all the time here on my desk and I have my workbench over there and I just I just love it and and just like Steven says it's At the end of the day or you can with Linux you can control a whole bunch of stuff that's really important. And that's around you all the time and is often overlooked and that's that's what I really about this field.
Well speaking of breaking devices. How about the other meet? cool So well, my story is a bit different.
I I it's it's from from Ellie from you know, familiarly actually started the to love Tech challenges and at some point I found myself playing with Raspberry Pi Arduino and without even knowing how to Program I've just started to to tackle these boards and turned it to understand. What can I do with them and and then from another aspect of my life my parents actually running and Engineering house. and they just saw the need of taking devices or basically taking products or anything that we can see in the airport to to the next level and they started to hear that from the customers that are coming to them and want to do better devices with the much better software on them and as someone who loves who love to you know to Title deck challenges.
I was I was just the in the right time to to learn and explore this world the moment more. So that was for me that the beginning of up Swift and then of course being at Jay frog thinking about the whole picture of how you take this amazing world of iot that we have today and devops and searching the right for the right connections that as a developer you want to have I think this is a great segue into gym when Meets talking about segwaying between iot and devops. So what got you excited Jim?
So yeah, actually. I guess back in around 2012 or so. I was in I haven't always been an analyst right?
I was working for a vendor and we were putting together in iot monitoring, you know kind of a mock-up or MVP proposal, you know for an iot learning solution. And the project didn't really make it to real product at the time, but I found some of the challenges and opportunities to be, you know, really interesting. you know, of course, you know today iot is is really kind of matured a bit and you know, so some of the things of yesterday back to 2012 some of those Concepts as Stephen was born out of the airport, you know become a reality with more and more devices being connected across Industries and in our homes and our wearables matter of fact I'm actually part of a very well-known study called the Framingham heart study.
That has been collecting data, you know following multiple generations of individuals and with covid it was really difficult to get people physically into the office to collect data. So they've been collecting my health data off of my iWatch and I have you know, blood pressure thing. They collect the data off of that.
I haven't been in the office years there. So, you know, it's really kind of cool how it's it's affecting all of our lives and a bunch of different ways, you know, you know, we all have Alexa and smart devices and smart outlets and smart lights and our home and we you know, we've come to rely on this stuff and it's it's really interesting to see how it's going to grow and I think you know, in terms of iot use cases. We're really just kind of scratching the service on that.
Well, I think you bring up a really interesting topic and point like you are working on a study and a challenge that you face is that you haven't been able to actually go in and check in. So you're using your watch using your heart rate monitor, you're doing all of this stuff virtually. So a me I would like to ask you what do you see is one of the biggest challenges facing iot right now.
Like this was a nice example of one that is solved by our SmartWatches, but what do you see as facing the industry? yeah, so this is I mean I'm speaking with the companies that produced products and iot devices almost every day and most of the of the guys that I'm sticking with are are between I will say developers to products Engineers to iot gigs that trying to to find themselves in this in this world and this market and the the most common question that always come to to the conversation is about best practices, you know, we're speaking about whether the cloud is and the the amazing tools that we have out there if it's kubernetes or anti-bill or so many great automations capabilities that can save you a lot of time and then when it comes to iot the water devops is is the world devops is actually a big strange right? I mean What can how can you really deploy devices?
How can you really supervise this your Fleet of devices? So I think the biggest challenge today in our world is actually having good useful best practices for those developers that have this amazing job of deploying and supervising the devices that are getting smarter, right? You can't control it anymore.
It's gonna it's gonna stay like that and we're gonna see more and more complex software running in the edge. So so I think this is one of the biggest challenges having The the best content out there follow these those developers to help them do their job easily without having them, you know inventing the world of devops for the use case. so this is this is just a perspective that I mean, I see it every day speaking with developers.
It's just amazing how we just Started we just started right? Thinking about this Market. So Steve, since you wrote a book on Raspberry pies, and what I would assume have some best practices listed in that what do you feel is something that is a challenge in addition to this?
so when I Steve I think you went on mute. Oh, sorry. Sorry.
So I think when you look at all the different. Devices which we have to support there's there's such a wide variety of platforms and devices and things which you need to be able to deploy to you need to be able to get internet connectivity to you need to be able to update. and part part of the challenge and iot, is that why diversity of devices right?
So when you when you're doing devops and you're pulling the systems and on the cloud or in the hosted Solutions? You have a lot more control and uniformity over the systems and the types of things which you're doing software updates and software delivery, too. When you're doing deployments to devices in the field with different chipsets different menufacturers, you know difference capabilities on them.
The variation in devices you need to support is really challenging and I think the the other thing which strikes people when they first start working in large-scale iot deployments. Is you know, it's it's a hard problem to deploy to and to support hundreds or thousands of of servers in a kubernetes large-scale deployment. But iot takes it to the next level.
Where every single device behaves like a server that you need to maintain you need to update you need to be deploying to and it just scales it to the the tens of thousands or or more in terms of devices. You need to support and at that scale. There's no way to do it without the right automation without the right security practices and you have to start from the beginning with a devops automation mindset.
I think that one of the things you just kind of touched on Steven was was Security in that you want to make sure that what you are deploying to all of your devices is secure so super I you are our security guy. So I'd kind of like to ask you, you know, what are some of the biggest security risk you see today that could affect iot devices and deployments. Well, the devices themselves, I I you know, there's a project that we're working on on my team right now.
It's a consumer device that's being sold in the stores right now. We're in year 2022 almost 2023 and there are on that device. There are libraries and code that that haven't been updated since the beginning of last decade I want to say so I think that if if we're again if we're connecting back to what Stephen says with with supporting those devices at scale and making sure that they all run and have connectivity and updates and all of those things.
That that is a that is a big Challenge on its own. But then when you have all of those devices connected to the internet and they're running a bunch of really really outdated code from I don't know from 2008 or Linux kernels from when I was back in high school and I'll be turning 36 soon. So you can do the math.
I think that I think that this is this is the problem because if We're always talking about iot security as if it's something that exists and it doesn't because if we're comparing it to like, you know, our computer like the computer that I'm talking to you right now is getting I use Linux. I get updates every morning I wake up and I have a bunch of updates to install on the other hand. I have a bunch of iot devices around me that I'm using them all the time they're on all the time and not only that they're not getting any updates.
They will never get any updates. So I think that and and for a company like us like sternum. Our challenge our our the problem that we want to solve is to make sure that those devices are always protected even if there will never be a patchwork.
So When I look at iot in general as a field, it's it's cool and I love it. And I'm very committed to it and I have I have a I have an exploit tattoo on my arm for iot. I'm very committed to it.
But I'm also very aware of how fragile it is. and how how much how much of a way we have to Traverse and go through until we will be able to achieve some sort of parity of security between our regular computers and our iot devices. So I think this is super interesting and Jim.
I'd like to hear your take on it since serper is turning the ripe old age of 36 and you've been doing this for a little bit longer. You know, what what have you seen in terms of the evolution of iot and you know, are we still using the devices that you were working on back in the day? You know, how what what do you think has been the biggest advancement in the field?
And you know, how can you address some of surfers concerns? Yeah, well first I'm only 35 to be clear. So yeah, I mean, I think I think it's really really interesting, you know, certainly devices that change availability advice to change I think five G's had something to do with that as well in terms of acceptability of devices or what I found really interesting about what what you know in service was talking about, you know security You know because it's not just the security of the software or the device.
There's that physical level of security too right the company. I mean you held up a device where it looked like you've been snipping some wires or something this every yeah, I don't know what I don't know what he's doing over there. Right?
But you know, it's it's there's a you know, there's there's the, you know, the physical aspect and it feels like Maybe it's a little bit like some of the challenges we face with mobile security to an extent. Right? We you know, do we need code obfuscation.
Should we you know, what should we do with encryption, you know other man in the middle type of attacks, we should be concerned about. You know, how am I protecting my data? How do I know?
I can even trust the device that I'm sending an update to right? I don't know. How can I trust that is there is a bad actor and impersonating a device to gain access, you know to my supply chain, you know how exposed again physically is that device?
You know? Well, I you know, I'm I'll probably need some level of thinking about my network and network segmentation and make sure that I'm you know, segmentating, you know different parts of my iot network, you know, so there's no front door if you will to maybe other networks or my corporate Network. Um, you know, it's it's crazy and when you think about it, you know iot devices art.
Stationary devices, right? We just saw you pick one up there, right? You know, it's you know, we could be we could be pushing software to devices on trucks or cars, you know, you know wins inappropriate time for me to push that software up, you know, so I I think that you know, there's so many things going on here and I think a point that somebody made before I think maybe it was a minute about about best practices I think is is huge here because I think one of the challenges around iot to me, you know as I look at it is, you know, when you talk about iot usually the response as well.
It depends right? It depends on the devices. It depends upon the architecture depends upon the software.
It depends upon the use case right there. So it's really hard for that standardization. And and I think that's that's really.
I think we're still lacking that right that that level of standardization in in iot and how we can actually say, you know, this is the way you deploy software to an iot device, you know, maybe it needs to be broken down my domain or or device types or something along those lines, but you know there needs to be in conversations like this. I think are helpful right there needs to be more. Work a collaboratively, you know across the community to kind of make all that happen.
And I think to your point right like you can't bring all devices in to get updated, right? You can't bring a device in to make sure your Hardware is is up and running in the right way. So so Steven I want to ask you like what is a way to to deploy software knowing that it's secure even though your device might not be so I I think that it's like deploying secure software to devices is tricky and like I think I totally agree with my fellow panelists have said but there's kind of two aspects to it.
So that one is the desire of the the person who's supplying the software or the firmware or like like what's running on device to make sure that it's up to date. And the second part is the willingness of the user or the the person who's applying the device. To to actually publish and to make those devices those updates to deploy those those updates the device.
And I I think we've seen a big change in terms of our Behavior as consumers in this. So if you remember the days where we would be asked to update our device? And you could choose if you want to update or you didn't want to update it and often.
Usually the right choice was not to update because if you if you updated there was no guarantee that you're your laptop your mobile phone whatever it was would actually finish the update successfully and there's still to this day are classic failures in updates of laptops and other devices. when you take this at iot scale it exacerbates the same problem and the question is what's What's the risk of pushing and deploying a new update to device and one of the critical strategies which we can learn from from server deployments and should just be a standard on all iot device deployments is automatic rollbacks. So if you're pushing to an iot device in the field or somewhere, which is inaccessible having a failed update or an update which bricks the device is unacceptable.
That's that's complete failure of the system. So designing systems with automatic rollbacks and making sure that when you push an update it will seamlessly fall back to the last known working version of the firmware or the operating system. We're having an entire like Linux container.
Docker container image you can fall back on is the ideal way of doing these sort of deployments and it it takes best practices from server side deployments and kubernetes and then applies it to iot and devices at the edge. We do have a bit of a of a celebrity on here and while the audience starts putting in their questions. So yes audience, please type in the questions.
This panel is going to be more interesting if the questions that you want answered are asked and I'm happy to ask them for you, but server. Can you just tell us a little bit about what you discovered or what you worked on in 2017? So I'm the celebrity.
Wow. Well my apologies. yeah, I think you're probably referring to not that you yeah, so on if If I can tie not pet your Loosely to the topic that we're we're discussing here.
So just a quick refresher in summer of 2017 Russia Unleashed a devastating ransomware attack on Ukraine which then propagated out of Ukraine throughout the rest of the world and started encrypting and rendering machines useless all over the world in hours and I just happened to be in the right place at the right time or at the wrong place at the wrong time that depends on how you look at it and and I found a way to to stop this malware or not. Stop it but rather cause it not to run if it gets to your machine almost like I I called it a vaccine which is a similar approach to what we're doing at sternum with our product and What was interesting about not petia other than the ransomware part of it, which was actually not really interesting. It was the fact that it was a supply chain attack.
It was the fact that um, the threat group was behind this attack nicknamed sandworm. By the way. There's a really good book called sandworm by Andy Greenberg that discusses this attack and incident very thoroughly.
I strongly recommend it. And and what happened was that the threat actors reached a company in Ukraine that makes an accounting software almost like QuickBooks if I have to compare to the states. Um, and they have planted malicious update.
in the code of that accounting software and that got pushed pretty much to every every computer that does business in in Ukraine or with Ukraine because they all had to have this accounting software and that's that's how the the ransomware started to propagate all over the world. And it was very interesting to see a supply chain attack in real time and how how it affects so many computers and so many like it affected actual actual lives the gigantic Shipping Company stopped working because of that they had container ships all over the world that couldn't do business. It was kind of crazy and I I just happened to be with my with my laptop visiting my parents in Israel.
And as they were just talking about it over the news. I I started reverse I got a sample of the malware and I started reverse engineering it and while a lot of other people I was talking to at the same time. They were dealing with cryptography aspect of it.
How can we decrypt the files that were encrypted and so on since I'm not a crypto guy and I pretty I'm pretty bad with math in general. I just I just started to look at the code and see what happens like what Causes the the program being the ransomware what causes it to terminate itself? Then I found that there's a it checks for the existence of a specific file in a specific path.
And if you put that file in that specific path if the malware will ever get to your machine, it'll see that the file is there and it will simply not run by the way only after I read that book that I mentioned sandworm. I discovered that this was a mechanism that was put there by the attackers on purpose so that they could still have access to systems that they don't want to Nuke off the face of the Earth. So that was an interesting thing but finding out finding out this solution to this really big problem other than you know, my personal benefit of it made me interns famous for five minutes it really it really demonstrated the importance of Of having your supply chain if I can use that term having it.
Having it safe and secure because by breaching one company. Literally the entire world was affected. So if I'm if I'm taking this this incident and I'm I'm a casting it onto this discussion that we have here and circling back to the example.
I gave a few minutes ago when we have devices that are all over and they could be smart outlet there. You could be a wearables. They could be electric electric meters.
They could be whatever if they're running outdated code or if they're if their supply chain is not secure then I think that not petia is sort of like the harbinger of what's to come but that is my very pessimistic Outlook, and I'm sorry to rain down on people's parades. I I don't know if that's pessimistic realistic or you know, just like a warning Maybe. But I mean you had something to add to Steven's automatic rollback comment.
yeah, well, it's just you know speaking and I think Jim mentioned mentioned it as well and I started to speak about about it in the beginning and What we're looking on the whole aspect of an update to deployment to Edge devices if there are small or big or if they have a good communication network communication or not. So I'm pretty unstable rollback is is really the thing that could save you but adding to that and and I think you know as James as Jim started to say that we need to communicate more about right about iot best practices in the devil's word. So I think this is a good start by saying that Device provisioning is is another layer or maybe a kind of a common ground to begin with when you deploy updates right?
Because when I mean having a good drawback is is a very important thing and having a good system with flexibility of deployment options and features is so important but it's all starting somewhere somewhere down the line where where your device is supervised where you feel that that you can always reach the device. It doesn't matter whether the device. It doesn't matter.
If the device is running is a communicating through cell or modem on you know, on a low then with three G modem or Wi-Fi on the mall. It will always act as a client side speaking with the cloud helping you reaching reaching reaching every everything that you need, you know, though to do your job well and they think it's it's by the way another good connection to the to the security word for iot devices because Again, this is just the first layer of everything that you that we would like to achieve on our iot devices and looking on, you know on last five or four years on the biggest providers on the cloud. If it's AWS or gcp or Azure, they all give you this this, you know.
basic feeling confident that Your instance your server is always in always here and you can always touch everything that you need and this is this is something that we that is kind of. Not there yet. When you are speaking about iot and can give us the the ground to build the other Lego blocks that are missing in this area.
Speaking of like Lego blocks and building in this area. What do you all and I'm Going to throw this out to the panel, but what do you think is going to be the next wave of tech that impacts iot, right? So we're already have been talking about the issue of supply chain attacks.
And if you you know have an update and it goes to 10,000 two million 12 million devices, you know, like what do you do? Right. What's kind of security stuff?
Can you put in place before it gets deployed? And then what can you do after it's deployed to like kind of, you know fix or mediate the issue so whoever wants to kind of go first, but what do you think will be like kind of like the next wave? I was going to say Lori there's a lot there's a lot happening on the hardware side and and I'll admit I'm not an expert on the hardware stuff.
I do have a Raspberry Pi in my draw somewhere. But but there's you know, I think I think one of the interesting things about iot is Hardware. It was almost like Hardware wasn't relevant for a while there in the cloud.
Right? We would say anything software Hardware is becoming relevant again, so there's certainly a lot I think going on there with you know, smaller more accessible more resilient devices that's happening. I think on the software side.
You know, we talked we talked a fair amount about you know, best practices and standardization. And those those are all compelling needs and there's there's some really interesting things going on there between you know, just even between you know hearing what's going on with with a mitt and and Surfer who's it's as Alias. He's his real name is a met right?
I'm changing my name to I met by the way, but it you know on the software side, it feels like you know, maybe things like awesome I think is kind of interesting how that might be able to provide some, you know, interesting capabilities for iot. You know in the edge, you know kind of reduces potentially size of the binaries right and help perhaps with some kind of compatibility issues security, you know, and and I think things like that can can really open things up. I also think, you know, we talked a little bit about the community.
I think, you know oftentimes some of the coolest Innovation tends to come out of our open source community, so I wouldn't be surprised if there's You know, there's more Innovation out there. That's that's you know, coming to the Forefront that you know, eventually you will come out through the open source community and then be commercialized and so forth. I think there's just a lot of exciting things happen.
And when you talk about hard work too, you know, there's the actual supply chain issue and getting the hardware getting the chips, you know in the US is now investing in trying to get more factories to build more chips. Who else has who else would like to kind of jump in on this one? On the supply chain aspect or I'm sorry.
I just on just like kind of what the next wave that's going to hit iot. I think that I think that throughout the last few years there has been and finally I feel like finally, how can I say the shoe drop and people understand that and again it connects perfectly to what I said in the beginning about routers like that that iot devices are also important and they should also get the attention of security people and not just the regular computers and servers servers in the organization. And I think that I think that we're going to see we're already seeing first of all, we're seeing much more we're seeing a lot more companies and technologies that they exist solely to protect iot devices.
So it's not it's not only like a spin-off of another security product. That's that has been Loosely adjusted to support iot devices. We have those things too and they're not that great.
I'm talking about companies like us and like other companies that they only exist. Secure iot devices and and to me as a security researcher and someone who cares a lot about security and and everything that I buy even to my own personal use. I I first thing that I do is I look at it as a security researcher and as a hacker, I think that We're going to see a lot more attacks on iot devices.
We're already seeing them but I think that's gonna be it's gonna grow even more and to counter that we're going to see a lot we're going to see a lot more technology companies trying to mitigate that risk and make sure that the software supply chain is intact the hardware supply chain is intact that updates are being pushed properly or at all. And if they're not being pushed there are Technologies such as ours to help with that problem. So I think that it's gonna really shift and move the market to a more to that area or so, I hope because that's my job security.
Steve what do you think? Yeah, so I'm just a just add what to what Jim and serper said. So I think that one of the fundamental changes if you look at how we're applying and using iot devices.
Is it's it's not just that they're all connected to the internet. It's that the Surfers example of a router. Often when you're putting iot devices 5G devices or even a lot of the home automation.
Everything is exposed individually to the internet and this just exponentially increases the attack surface. Of the entire iot deployments and to Jim's point about open source. I think if you if you look at some of the Innovations happening at a fundamental level in the open source community.
um there they're really trying to change the landscape of security and in a positive way and one of the examples of this is memory safe languages rust is the most commonly used language for Wasim. It's designed for memory safety from the get-go and like having languages which make it hard to get buffer overflows and commonly exploitable security issues makes makes it easier to secure. It doesn't make the devices here, but it reduces the the number of potential attacks against devices.
And other projects like the Persia projects, so that's a t-shirt. I'm wearing are also trying to secure the open source Supply Chain by creating more secure distribution channels for open source projects to publish and make their secure their software available securely because as we all know, The majority of of Enterprise and iot devices. It's our composed of Open Source software.
You're running Linux you're using open source dependencies and the the amount of code. You're actually writing for the device is dwarfed by all these open source dependencies you're pulling in so if they have security issues, your device has security issues regardless of how tight your own corporate security practices are on software development. So I think if I depict where things are going, I would say that it's it's more and faster and interconnected devices, but with a higher focus on secure security and continuous updates to those devices to keep them secure.
So emit we're our kind of coming short on time. So I'm going to let you kind of have the the last little piece of this question and then if anyone has anything they want to follow up with we've got just a few more minutes. All right, so well.
I mean, I'm I'm thinking about myself four or five years ago, you know looking on iot stuff and looking what I can run on boards for maker is even and looking today on on you know and customers that I'm working with and the things that they are doing and number of deployments updates are taking to the edge every week or every day, maybe think from you know from this perspective that the software is in the edge on the edge gonna be complicated from day to day to the point where we're gonna see companies producing products that are getting updates every day in the background without everyone knowing about that and if you think about it for a moment, I think you can we can all agree that the all gonna be extremely You know depend on on their ability to to drop this software on their devices and I think we're going to see more and more companies getting to this field helping from the community to you know, to start ups getting to to this area helping them provide the next solution to really solve these area. Well, and you know what they say every software company sends covid is or every company is now a software company, right? You know how many apps are on your phone?
So it's not just the phone. It's the apps, and it's all of that so we are running out of time. So I would love to thank all of you for participating today a meet Surfer Steven Jim.
I think this was a great panel to hear all of your different viewpoints all of you come at things with a very different eye, and I think it was a great conversation. I hope we can have another conversation in the future. So I'd like to thank text wrong TV and the devops experience conference for letting us talk with you today, and I hope everyone enjoyed the conversation.
And yeah, this is just part one because things are changing. So thank you for everybody and have a good afternoon. Thank you.
Thank you.





