Techstrong TV Thursday, April 9, 2026
On today’s Techstrong TV, Alan Shimel goes live from RSAC with Backslash Security’s Gil Friedman on the hidden attack surfaces inside AI-native development pipelines, and Deloitte’s Dr. Colin Soutar on why Q-Day is closer than most organizations realize. Mike Vizard reports from KubeCon Europe on how OpenSearch’s hybrid vector approach is keeping generative AI from hallucinating in production. Plus, Veeam’s Rick Vanover on the company’s evolution beyond backup, and Cloud Field Day 25 rounds out the hour.
Transcript
Hey everyone. We're back here continuing our afternoon coverage on day three of RSA. We've got a few more coming at you today, and looking forward to it.
But let me introduce you to our next guest. His name is Gil Friedman. Gil is with a company called Backslash.
And if our friend Ronnie Osnet is watching this, a big hello to Ronnie who's now with Backslash full time, I know for a number of months, and unfortunately couldn't be here with us in person. So hello to you, Ronnie, and I hope to see you soon. But Gil, welcome to Techstrong TV.
Thank you. It's good to have you here. Before we talk about Backslash and before we talk about AI, because everybody wants to talk about AI- Of course ...
and RSA, let's talk about you a little bit. Give people an idea of your journey of how you came to be at Backslash, and a little bit of your background. Definitely.
So I have long history in our industry, coming from background at SAP. I was VP of engineering over there. Mm-hmm.
I was VP of engineering of this expense solution of Concur. Mm-hmm. After that, I moved to Meta.
Really? I was a senior engineering manager over there in the worlds of ads and VR. An interesting place to be.
Interesting, a super fast pace, right? Mm-hmm. And then moved to Zilliant.
I was VP of engineering over there. Okay. Yeah.
And then after all this experience from the other side of the fence, the people that- You went to the dark side ... To the dark side, which is actually the bright side in some ways. The more interesting side.
Yes. So from being in large companies, some of them move slow, some of them move extremely fast and pretty much lead our industry, right? Meta.
It was interesting for me to join Backslash Security because the domain is fascinating. This is the right time to be covering this space, this problem space. And it's interesting to see how people understand the whole domain, and slowly they realize that these new things that we have there, it's not just for engineers, it's not just about code anymore.
We have now few AI components, and actually even by the time that we speak right now, probably there are more. Yeah. Okay?
Every day. Every day. And each one of these components, it's a new attacking surface.
And unfortunately, the AI security teams, or security teams, they have zero visibility into this world. And we would like to help them with that. Right?
We don't want them to be the office of no. We would like them to be part of the discussions, and we would like to help them with their journey to have safe AI adoption. Love it.
Love it. When did you join Backslash? I joined Backslash almost six months ago.
Okay. So I know the co-founders. Yeah.
I know some of the employees over there. We used to work before, at SAP. Okay.
Of course, we had great experience, and we did amazing things back then. For me, it was a very easy decision- Yeah ... to join them- We were friends ...
and be part of the journey. Yeah. Yeah.
And look I've done, four or five startups. It's always good. Even here at Techstrong, my executive team basically are people I've worked with 20 years.
Right? And so we're very- Amazing ... comfortable.
It's like family and it works. How would you describe Backslash to people today? So the easy thing when we start describing about Backslash is even to ask some simple questions.
Do you know which AI agents are being installed across all the machines? Do you know which MCPs, which skills? Right?
And this is where kind of CISOs pause. Okay? They don't know.
They are currently in a perfect storm, and they are terrified. And they understand the risks slowly, and we're here to support them with the journey. And this journey consists of three important steps.
The first step is about visibility. First of all, to turn the light on to see what we have there. Okay?
What we have there in the form of AI agents, and even who is logged in. Is it kind of they are logged in with their corporate account, with the private account? This is super important information, right?
Which MCPs, which AI skills, which rules. And we don't just stop there. Even if you know which AI skills are there, we provide you the information about the security posture of these AI skills.
So it's not just to know what you have. Okay? You need to know what does it mean.
After this step, there's a second step about defining policies, and not just on some wiki page. Okay? Real policies about this environment, these AI agents and so on.
After you set up that, you can define guardrails to harden the environmentAnd then once you have a safe environment on all the workstations, we provide real-time protection, so you won't be exposed to any prompt injections, a data leakage from all these components. Love it. That was great.
That was a great way of describing it. So, Yoav, before we go further, people who want to maybe get more information on Backslash, what's the website? It's Backslash Security.
Just type it, and it's there. Backslash Security. Yep.
Okay. Now, to say we're living in an interesting time in security-- Well, to say we're living in an interesting time in general- General ... is an understatement.
Yep. And certainly in security, right? I don't know if we've ever seen this kind of rapid change.
I mean, not just change. I'll use the word disruption, right? Rapid disruption in how, what, who we did.
Even six months ago when you joined Backslash, you probably didn't foresee the impact and how quickly the impact of- Yeah ... agentic and things like Claude Code Security, and these kinds of things are. Right?
Because, fundamentally, we've moved from a world where the bottleneck was how much code can I-- How many engineers? Each engineer averages 400 lines a day. Yeah.
A good engineer. 40 lines- Which lines, right? Right.
Which lines. Exactly. But 400 lines a day, and I got 10 engineers, right?
So I could do 4,000 lines of code. That's amazing. That's an expense.
That was a big operation to do 4,000 lines of code a day. Yeah. Well, with AI, we could do that in an hour or two, it seems, right?
True. So the whole focus, it's like when you have an equation, X plus Y equals Z, and all of a sudden X becomes 10X. Yeah.
Y and Z have to change. I agree. And that's Y is security here, right?
You got 10X the code. What are you doing around governance, around testing it, securing it? " If they're using AI to generate that much more code, we just don't have enough people to ever keep up.
We've got to use AI for the governance piece of it. I agree. But part of the problem is that it's not just engineers.
No. It's also financial advisors- Everybody ... right?
The artifact now, it's not just code. Right. Okay?
It can be spreadsheets, can be LinkedIn posts, can be even applications, can be even skills, right? And the problem that you have these new attacking surfaces that, as much as there is no visibility, and the problem that in some of the cases, even it's not about generating something. You can use your AI agent with MCP to pull some information.
For example, I would like to integrate with an API. My prompt will be, okay, I need more information. How can you use this API for this specific purpose?
The AI agent will come to MCP. The MCP will call some public repo. This public repo, okay, might contain some prompt injection, base64 encoded, means it's not meant for me or for you.
No. We know who's the target, and that will be fed into the AI model. So it's not even about generating any code, okay?
The factory that now we have there that works in a non-deterministic way with all kind of interesting components that we know-- Actually, we don't know how they interact between each other, okay? And we start with definitely very safe approach, okay? But slowly, we trust all these components, right?
And this is where the problem starts, okay? And our last line of defense, unfortunately, right now, is the AI agent and the model. Yeah.
We cannot trust these two to make the right decisions for securing our environment and to make sure that there won't be any prompt injections for one side, and to make also sure that there won't be any data leakage, and also to make sure that they won't run any script on our machine. So it's not even about the code that's being generated, and definitely, I agree with you, this problem just got amplified, right? For sure.
But now we have new problem that the traditional security solutions out there, whether it's a gateway, whether it's EDRs, whether it's AppSec, they're focusing on different problems. And now we have new attacking surface that is out of sight for all the CISOs out there. Agreed.
But if Mohammed doesn't come to the mountain, the mountain has to come to Mohammed. Yeah. So if we can't trust this AI to do this, we don't know is that code really secure.
But yet we're still just churning out code. We can't hire enough people, right? We've proven that.
What is the answer? The answer... Okay, let's start with part of the problem, okay?
Few years ago, the model was engineer writes code, you have the output. Means that in explicit way, you know what was being produced. Slowly, through the years, it started with Copilot.
That we had auto-suggest over there. Still, from security perspective, the risk was low because you can still see in front of your eyes, okay, you typed few commands, auto-complete. Okay, still fine.
Slowly, we have more sophisticated AI agents that they don't just generate one line of code. They generate 50 files at once. And although we think that it generates just as an output of our prompt, this is part of the problem.
There are a lot of things that can influence what eventually will be generated. And the AI agents and the models, they understand English. String.
Okay. And there are some AI rules that can be injected. Yeah.
They provide some malicious kind of- Activity ... commands. Yep.
Right? They can be even, as I mentioned, they are agent. They have also their own rules.
Okay. Whether we can trust them or not, I don't know. They are agents.
Part of the way for them to satisfy our prompt, they get a context. Which context? Maybe by mistake, we just add there, just for testing purposes, the API key.
They will take that. Okay. They will do something with that, that it's out of our sight because we already trust this whole thing, right, and push it, and will generate code with that.
Right. There are also now skills that will also impact this whole factory behind the scenes. You have rules.
Later on, you'll have more things over there. And again, the problem is not just us with the agent. The problem is now there's a lot of components out there that impacts this prompt and will impact the generated code.
And not just the generated code, because I would even argue that the generated code, it's output that we can see. They all can do within this process some things that are not even impacting the generated code. It will impact the code, the machine behind the scenes.
Oh, yeah. So it's not just the generated code. And I can argue that generated code, okay, it's been amplified.
The same tools that we had before, okay, they use some AI, it's going to scan it. But that's in a way the same problem that we had before just amplified. Right.
But now we have different set of problems that it's not being amplified. We didn't have them before. Right.
So the traditional tools we already have won't cover us for protecting our environment from all these new attacking surfaces. I love it. Gil, we're about out of time.
Awesome. Backslash security. Yep.
That's where it's at. Hey, thanks for coming in. I appreciate it.
Thank you much. Best of luck. Hope you're good.
Look, I think we all agree. Interesting times. Exactly.
And we'll see how this works out. Awesome. We're going to wrap up stuff here at RSA today.
But hey, Ronnie, if you are watching, I hope to see you in person soon. We will continue our coverage in just a bit. But right now, we'll take a quick break.
This is Alan Shimel. Hey, everybody. We're back in Amsterdam at the KubeCon + CloudNativeCon Europe Conference.
And we're having a chat with my friend Bianca, who runs the OpenSearch Foundation. How are you doing? I'm good.
Great to be here, Mike, and great to see you again. Good to see you again as well. There's been a lot of movement and a lot of momentum around the whole foundation and the whole...
I think there's a lot more interest and maybe even newfound respect for search engines in the age of AI. But I know you have some new members that joined recently, so walk us through and give us a little update on what's going on with the foundation. Great starting point.
So let's start at the top, where the foundation's really, really happy that we've just announced a bunch of new members that include companies like Resolve Technologies and BigData Boutique and Open Source Connections, which are super important. There's more that's going to be announced, so stay tuned, everyone. It's exciting times that we're living in.
Since the last time that we spoke, obviously there's been a lot of growth within the foundation, which I guess is the proof that OpenSearch as a part of your AI infrastructure layer is definitely heading in the right direction. We're on a wave of innovation now. But in terms of announcements, pure announcements, you will see, and I encourage all of the viewers to look it up for themselves, we just released a great case study from Atlassian, which is large scale use of OpenSearch across multiple different use cases, whichPlays into the narrative of a foundational layer of infrastructure that you can build different use cases, whether that be search, observability, security, FinOps, and you can build that all out in the same data layer.
It's a really interesting case study. Another one just released is Changi Airport, which, if I'm not mistaken, is the largest airport in the world. It's based in Singapore.
Yeah. And they're using OpenSearch for super interesting use cases. From search use cases, they're using it for their retail, where they want 1,000 retail outlets.
And what they're doing is they're using it to not only geolocate, but also as a recommendation engine. So I'll buy a pair of shoes, and it's going to recommend a pair of socks to go with the shoes, which is geolocated behind me. There we go.
I think that there is a perception that says search engines are for indexing, and I'm going to surface up a bunch of text, but it's gone beyond that as a technology, and it seems it's really about surfacing the right data at the right place at the right time, and that's a big challenge, especially in the AI era, given how much data there is. So are people starting to understand exactly how to use search in that context? Or what are you hearing and seeing?
So let's break that question, which is a really good question, into two different parts. Let's concentrate on the search and how we need to use that in the world of AI and what that means in the broader context, the second part of that question. In search itself, we are modernizing the search.
As we spoke about last year, 2025, I think, was all about vectors. Mm-hmm. Everything is a vector database.
Now that's kind of parity. Table stakes. Yeah.
Exactly. So you said that- ... much more eloquently than I did.
But what it is now, it's all about how do we make a agentic search efficient and safe? And that modernizing on the search engine, OpenSearch is doing some really interesting things. As examples, we're creating a very, very powerful hybrid search.
We all know it's running on GPUs, it's expensive infrastructure, it's a bottleneck, and we've got to be really efficient about our search results. So before we go and search it on vectors, and we search for brown dogs, and I get brown cats, and I get white dogs, and I get all the adjacent vectors, we combine that with the lexical search within OpenSearch, which will give the vector search the context that it needs to provide more accurate results, less hallucinations, and provide a more efficient and reliable layer of RAG. Mm-hmm.
And so that, to me, sounds like the foundation for what people are calling context engineering because I have to pull that data together in a way that I expose it to the AI- Yeah ... so that it knows what to go do. Otherwise, it just might go do something in an infinite loop, right?
There we go. Essentially, what we need to be doing now, because we're scaling at not one query a second that Bianca's writing, we are scaling at hundreds of thousands of queries a second. So what we need to do is we need to build agentic AI.
We need to let AI monitor AI and control AI at that sort of a scale. Mm-hmm. And that actually goes to the second part of your question, that now with that infrastructure layer, we can't think about it as search being isolated in the bucket of the search project.
We have to think about search and observability and security and costs and business decisions as a whole, all as this part of the same thing. Mm-hmm. And giving each of those different necessities the right context to automate.
Mm-hmm. Do you think we're going to see a more convergence of different data management functions as we go along to achieve that goal? Because historically, things were always kind of treated in isolation.
And if I wanted to be really honest, a lot of enterprises, well, let's just say they wouldn't get a good housekeeping seal of approval for the way they manage data. No. That's so right.
I can't tell you how many companies I've spoken to who are great on modernizing the AI infrastructure up until the point where they're realizing my data's not ready for it. However, yeah, I think that's a critical section is that the whole data infrastructure layer has to be re-looked at now so that it can support what's going to happen with all of the scale in AI automation. Without that, it's kind of like, I would say, having a supercar with no safety mechanisms and no road to drive it on, but try and drive it at your own peril.
Now, last time I looked, there wasn't a huge pool of data engineers out there to help me sort all this stuff out. So will we use AI to manage the data a little bit more to scale those people so we can basically use AI to make the data ready for AI? Yeah.
And I think we're still in that kind of paradigm, right? Can we use AI to do functions for the skills of people that we don't have? Which we haven't quite got to that point, at least in the senior part of the organization.
And rather, what we see now is the skill set we do haveInstead of looking to supplement the people, we're looking to take the people that we've already got in limited numbers and make them superpowered to solve the problems and to supplement their abilities. And the paradigm shift there is not to do it on an ad hoc individual basis, but much more on the organizational level, so it's coordinated. So we've heard this metaphor a million times where people say data's the new oil.
But truth be told, if you've ever actually seen a barrel of oil, it's pretty useless on its own, standing there doing anything. You have to refine it into something to make it into something that we can monetize. Is that kind of the same conversation we're having in the age of AI, where now we got to figure out how to refine the data and process it in a way that really drives some value out of it?
Yes, and really interesting to think about it in terms of looking at AI as oil. It's necessary to run things, but by itself, it does nothing. So you're absolutely right.
What's interesting, though, is the machinery using the oil will now be generating more oil because the AI is going to generate more data that has had to be used to manage the AI. This is true. So it becomes a virtuous loop at the end of the day.
There we go. So the days of having my oil and then having my engines to run the oil and then having the driver for the engines, that linear building block is past. And what we instead have is we have a virtuous loop, a continuous loop of development, and that's going to accelerate the pace of development now.
" How much time do we have today, Mike? Okay, I'm just going to throw out a couple of examples of what keeps me up at night. There you go.
One great example is in the age of AI, people have seen this coming, and there's a whole lot of compliance regulations like CRA coming in Europe and things like this. And what does that mean in terms of data sovereignty? Nobody really knows.
And where the scales and how it's going to be implemented is going to be a challenge. Now, what does that mean? In the world of AI, data is my everything.
It's my oil, it's my assets. The world is not going to go round without my data. So instead of putting my data into different services and having it all over the show, I have to have data sovereignty over my own data so I've got the flexibility to comply with things that can be changing very quickly.
So I want to now bring my services towards my data instead of throwing my data into those services. I think the paradigm is shifting, and I see a lot of companies I'm talking to struggling with just simple decisions like that, how quickly, where, how? And we actually focus in very much to make OpenSearch part of that solution to give you data sovereignty then.
Oddly enough, have we come full circle because at least I'm old enough to remember back in the day- Yeah ... we told everybody we should bring the compute to the data, and then we spent 10 years or so pushing data into the cloud. Into the compute, yeah.
And now we're back full circle trying to bring the compute to the data again. Yeah. The more things change, the more we realize that things stay the same.
I don't think AI is going to be much different in the long run. We'll become much more productive. The scale's going to be different, of course.
There are going to be new challenges. But I think we'll always work cyclically. There's a reason why the 1960s fashion comes back every 30 years, right?
There you go. How do folks get involved with the foundation? What's the entry point for folks?
" Yeah. So thank you for asking, and it gives me the chance to showcase the OpenSearch Software Foundation, which I'm excited to do. You can join in multiple different ways.
You can do things very simply. We've got community Slacks. You can contribute code to one of our 141 repositories.
You can link to me on LinkedIn, and I will help you out personally. We've got a team just willing to talk to you. And we've got a huge number of announcements coming in April at OpenSearchCon EU about benefits, which are going to really make your life easier as an enterprise customer of OpenSearch.
Stay tuned, be in touch, and I'll help you to get on board in the foundation. Sounds good. Folks, you heard it here.
If you want to join the foundation, just find Bianca on LinkedIn. It's that simple, and then they go from there and everything else will be easy. There's also an event coming up for you guys, right?
Right. In April 16 in Prague, OpenSearchCon EU. And like I said, we've got so many exciting and new announcements that I'm dying to tell everybody now at KubeCon because I think that this is an exciting event.
But we have to have our patience and announce everything at the right time. So see you all in Prague. And if you've never been to Prague, this is the best excuse for going.
Hey, thanks for coming by. Mike, thank you so much. Always a pleasure.
Okay. And we'll be back in a minute. Hey everyone.
Welcome back here to Techstrong TV. I want to introduce you to our next guest. His name is Colin Soutar.
Colin is the Global Quantum Cyber Readiness Leader at Deloitte, and he was one of our initial Quantum Security 25 list members. I was going to say nominees, but we actually announced the finalists, the winners, and he was one of the list members. So you can bet he probably knows a thing or two about quantum, and we're going to talk to him about it.
Let's welcome him first. Hey, Colin. Welcome to Techstrong TV.
Thank you, Alan. Thanks for having me here. It's my pleasure.
Colin, before we jump into quantum and what Deloitte is doing with quantum and everything else, let's hear a little bit about your journey to quantum, if you will. Yeah. Interesting.
So I started off in emerging technology in biometrics way back in the mid-'90s. I did a two-year postdoc at NASA, and then started with a company, ended up being called BioScript out of Toronto, Canada. And we were one of the early pioneers of biometrics.
And so I saw the interaction between such emerging tech, potential regulations, how public reacts to it, and so on, firsthand. In fact, after the tragic events of 9/11, I helped NIST, the National Institute of Standards and Technologies, to develop national and international standards for biometrics. So I've sort of watched emerging tech evolve before, in the backdrop of frameworks, regulations, standards, and so on.
So about six years ago, when Deloitte started looking at the topic of quantum, both sides of the quantum coin, we would say, the use cases and the applications of quantum, as well as the cyber implications, which I lead globally. We started looking at that, and it was a good choice for me then to lead that, given that background. And so, I've been doing that for the last six years, as I mentioned.
Excellent. That's interesting, right? From emerging tech to, well, and quantum may be the ultimate emerging tech, as we say.
Colin, a lot of people look at Deloitte and say, "Okay, they're advising the biggest companies in the world. Deloitte does a lot of things, but what have they got to do with quantum? " Well, like you mentioned, there's the two sides of the quantum coin, right?
There's the applications, simulation and modeling. My colleague, Scott Buchholz, has been leading that for the same time as I have, and we've worked together very closely. So he's looking at those applications of the quantum computer, and that helps our global clients align on how to get value out of quantum computers.
And in fact, they're getting value out of modeling techniques that are sort of quantum-like or using quantum thinking. In other words, based on the physics that quantum computers will operate under, and they're already seeing some benefits there in terms of the efficiency of algorithms. On the other side, we are concerned that our clients, especially global clients, but all of our clients, are able to essentially put the cyber risk aspect to bed and not have to worry about it in the long term.
Really what we are talking about, the good news is to mitigate the threat of a cryptanalytically relevant quantum computer being able to break asymmetric cryptography. We're looking at the mitigation being a classical algorithm, essentially. It runs on a normal machine, right?
It runs on a classical computer. And those have been out, as I'm sure you're aware, for almost two years now. It's August 13th, I think, 2024.
And so we are trying to help our clients navigate that transition in a fairly straightforward way with all the different dynamics that are going on around third parties, supply chain, all the steps that they have to take, and so on. Ten years from now, we want our clients to look back and say, "Well, we dealt with the cyber risk aspects and things were fine there. " And then on the other side, we're getting all this value out of using quantum computers.
So those are the main reasons that Deloitte is looking to drive this industry forward. Absolutely. And at some level, though, you've got to think that, hey, Deloitte is a company that other companies and organizations and governments and everyone else looks to for thought leadership, for guidance, right?
It's a big part of the business, and you would almost be negligent at some level at this stage of the game not to have your eye on the quantum prize, so to speak, and on the market and what's going on. Speaking of the prize, I mentioned you were one of the initial Quantum Security 25 list members, and I don't pretend to be an expert in quantum security or anything quantum. Maybe it'd be very quantum of me to say I both pretend to be and don't pretend to be.
But in any event, looking at the list, it was certainly chock-full of a lot of distinguished folks who-... have made their mark in this industry. Some because of their technical expertise, some because of their business expertise, some both.
But really, the idea behind the list was to call out the fact that, hey, this is no longer a five to 10 year out thing. " It's kind of like nuclear fusion has been like this my whole life, too. The idea of harnessing the power of the sun to cure our, solve our energy needs and so forth.
It's always five to 10 years out. But now it looks like we're not in that five to 10 years out. Q day, the proverbial Q day, as they call it, might be within our grasp.
There are several organizations, more than one, saying '28, '29, certainly by 2030, we will have achieved Q day. So where do you sit on that divide, Colin? What do you think?
Well, there's a few things in there, so let me unpack that just a little bit. First and foremost, on your introduction there around a firm like Deloitte and doing the right thing. It's actually something that stuck with me as I've traveled around and talked to different CISOs of large organizations, a lot of financial institutions, and try to help them through this journey.
" Because, this was four years ago or so, and even at that point, there were still a lot of people that were saying, "Maybe this doesn't ever happen. " The world is not going to fall apart as long as we take the right steps. And so we are trying to do that and have been trying to do that for the last six years or so.
In terms of dates and predictions, I think we've been consistent throughout the journey that we've had in saying that it's less about a date, and it's more about making sure that one is prepared for when this threat materializes. And I personally think that there's being a little bit of over-fixation, over-indexing by industry on harvest now, decrypt later. I'm not saying that it's not a real threat, but I think where it gravitates people's minds to is more around the confidentiality of data and personal information, of course, is very private.
We want to retain that privacy. But at the end of the day, the actual impact that a cryptoanalytically relevant quantum computer would have on commerce and business operations is that every single point of mutual authentication where devices come together, people come together, all of the online communications that we do, that will be eroded. The trust, the bedrock of trust that we have in that, that is going to be a huge implication.
And so you think about that. When is that going to happen? What's the probability it's going to happen?
And you look to experts like Michele Mosca. And by the way, I feel very blessed to be on the same list as people like Michele in terms of the top, so thank you very much for that honor. It really was a privilege.
You look at the predictions that he's working with different experts around the world. In fact, they published in the report that came out, I think it was at the tail end of last year, and he just briefed on it at a conference. There was actually less variability as time went forward as people think.
" But in actual fact, if you look at the predictions that were made every time, there's a reasonable alignment in terms of when they thought that was going to happen. And so at the end of the day, what I say to our clients is, if there's a finite probability that this is going to happen in the next five to 10 years, and you can pick whatever that probability is, 50%, 100%, 10%, the impact is so significant that you want to make sure that you're well prepared. And whether it's going to take five, 10 years to do the upgrade, some people say more than a decade.
" That's their opinion based, but it was a very sort of diligent set of steps that they'd worked through. So to me, whenever there's enough proximity of the time that it will take to upgrade versus the time at which you think this threat is going to materialize, then it's time to act. That's the way that we look at it.
Because, by the way, Q day, again, I'm not a big fan of Q day because the impact that will be suffered, especially from economic means in terms of that lack of trust, that's likely to be well before the world knows that it exists, a cryptanalytically relevant quantum computer, which a lot of people define as Q day. And so we are more concerned again about being ready in advance of that day, whenever it is. I have a couple of thoughts on that.
So first of all, in terms of the harvest now, decrypt later, to me, that information is radioactive in that it has a half-life. Every period of time, it becomes less and less. Over every period of time, it becomes less and less useful because some of the information, I'm not going to say it's eternal, some of the information has a longer lived kind of thing, maybe your social security number or something like that.
But the overwhelming majority of this information that's been pilfered, harvested now and to decrypt at some point in the future, we see it here with our email list. Over time, the average email, it's almost ephemeral, right? In terms of the useful life of that information.
It truly is radioactive. And so, if you told me you were harvesting stuff years ago, by the time you get-- First is having a computer that is, as you say, is capable of doing it, then B, it's getting access to that computer with your harvest now payloads or your harvest then payloads to decrypt them now, and that's another time frame. I think by the time that happens, a small percentage of that information is actually going to be really, really valuable.
On the other hand, as you mentioned, the withering of trust, just a simple handshake. I go to a website, I'm me, you're, it's it. This is really that website.
I think that starts ripping at the fabric of what we've built here in the web and the internet. The good news is, is I think that is something that NIST and the industry have sort of gotten, not in front of, but they're not as behind as we've seen in other technology sort of innovation cycles, right? They're out there, they're pushing certificates to expire faster so that you need to upgrade and hopefully, these certificates you're upgrading to have post-quantum algorithms built in.
People are becoming more aware that a good partnership, it seems, still between private industry and government here in terms of tackling that core issue. So maybe I'm just a damn fool optimist, but I'm hoping this is one that we can kind of get in front of. Well, the thing is that if you never get started, you don't give yourself the latitude of being an optimist, right?
Yeah. And that's sort of our overall perspective. It shouldn't really be a game of hope.
And by the way, when we have often found that, again, sort of taking a step back, sure, quantum is the threat that we talk about here, but some of the cryptographic governance techniques, the policies, just even having a cryptographic center of excellence or a clear line of responsibility with an organization, those are big steps forward that one could argue should've been taken over the last two or three decades. We've been kind of lucky in that asymmetric cryptography to date has stood the test of time. So we are, or I should say, the variants that have been used, we are definitely seeing that, and we're positioning this much more as cryptographic governance and starting to try and-- You asked earlier about Deloitte specifically, and we obviously have an audit practice, and we are at arm's length from the audit practice in terms of independence.
However, some of the preparation, internal audit readiness activities, getting customers and clients ready so that they're able to address this problem, we're starting to look now more towards can that be done in essentially a self-regulatory way? And we talk to regulators quite often around the world. Our concern is that there may not be a clear enough message that the regulators want to put out there in time, and organizations may be waiting for that before they can get the proper attention at the board level.
So we're trying to drive industry momentum around essentially self-regulation, and we put out a profile to the NIST Cybersecurity Framework. I had the pleasure of helping NIST to develop that back, what? 13 years or so ago now.
And that stood the test of time as a reasonable outcome-based process to determine what cyber capability should look like, while applying that logic to cryptographic resiliency is what we've taken the next step. " This is not going to be a straight do A, B, C, and D and we're done, right? That's the thing.
It's a dynamic environment, and so it's very important, we think, to put out some sort of line in the sand there that people can address. Absolutely. Colin, these are 15-minute interviews, and we're about out of time, but for people who want to maybe follow you, follow the practice at DeloitteStay abreast of this.
What's your best advice for them? I think we will continue to be out there advocating that it's good to get started. We're not being alarmist, but we are saying you should start now.
You could always put it on pause a year from now, two years from now. But getting started now allows you to figure out where are the most important assets and business processes, mission-critical operations, that you should address initially. And don't get overly distracted, as I said earlier.
Harvest now, decrypt later. And I look at that in two areas, personal information, as you talked about, and then also national security information. So national security information clearly has high significance and should always be protected to the utmost degree.
I think as we go forward over the next five to 10 years, the way that we authenticate ourselves as individuals is going to modify a little bit, too. So there'll be other means by which to protect that information. The bigger impact is going to be on the erosion of trust by not having these mutual authentication channels that we've relied upon today, and that ultimately comes down to interoperability between organizations that want to do transactions together.
If one, two, three, four, or five have upgraded and the sixth one hasn't, will that sixth one still be trusted? Can they still do business together? That's where it's really going to hit operations.
Yeah. And it'll be lumpy. It'll be lumpy for sure.
It's not- Anyway ... going to be straightforward. Yeah.
Yeah. That's for sure. Colin, thank you for coming on and talking to us a little bit about this real issue.
Congratulations again on being selected in the Quantum Security 25 initial list. Keep up the great work and hopefully we'll talk to you again soon. Thank you so much, Alan.
It's been a pleasure. My pleasure. Colin Soutar, Global Quantum Cyber Readiness Leader at Deloitte and one of the initial Quantum Security 25 list members.
We're going to take a break on Textron TV. We'll be back in a moment. Control, this is Agent Dev.
I'm in position. Copy that, Dev. Stand by for go.
Standing by. Hey, everybody. Welcome.
You've joined another episode of Agents of Dev. My name is Mitch Ashley and I lead the software lifecycle engineering practice. I'm joined, of course, by co-host and none other than Brad Shimmin.
How you doing, Brad? I am doing well, Mitch. How are you?
And where are you? You are not at your usual position for our podcast, my friend. Well, I heard there's a new position open in Washington over the Justice Department, so I wanted to be sort of in range- ...
in case they called. But, no, I'm actually in New York City for the MCP Dev Summit, which is kind of an interesting place to be right after RSAC, but we're going to talk about that. For sure.
Yeah. Now you've been on the road, too. They're kind of self-balancing.
They're- Yeah ... pulling against each other. They are.
I do feel a pulling effect. So you've been globe hopping, at least- Yeah ... coast hopping on the US coast.
What's up with you? Yeah. The last couple weeks I've been both down in Atlanta with Microsoft, which actually I would love to do as a call-out, because I think that the company, as is always the case with Microsoft, which is still an engineering-led company, let us not forget- Mm-hmm.
That. And with their Fabric, and on top of Fabric, a number of capabilities like OneLake and their new database hub, which is what I really love. They're doing some great things.
And one of those, and that is the database hub, is basically taking all of the managed hosted databases that you might want to build and run on inside of your enterprise, like a Postgres- Mm-hmm ... instance, let's say- Mm-hmm ... and manage that on a single control plane across all the databases.
So- Very interesting ... you don't, right, you don't have to basically stand up and provision and manage separate database instances. You can have them all governed and managed centrally.
And the beautiful part about that is it also ties into OneLake, which is something Microsoft is building as the "Lord of the Rings" style One Lake to rule them all. Mm-hmm. For building a consistent semantic layer within the enterprise.
So through- Ah ... capabilities that they have had, and are doubling down on right now, like mirroring and what they call linking, which is, and I cannot believe I am saying this with a straight face. It's symlinking for databases.
Ooh. Symlinking data. You are the symlink guy, for sure.
Right. Just trying to manage your doc files with symlinks, as we all do, is sometimes fraught with peril, but apparently it's a great idea for data. So they're- Mm-hmm ...
allowing people to basically create this very centralized, yet still open platform that's all sitting on top of running on Delta/Iceberg compatible object storage, and that's sexy. I like that. It's very cool.
Well, you said OneLake. I just kind of thought maybe that was named after Bob Marley. " That kind of thing.
One Drive. One Drive. Ooh, okay, there, we took a hard left.
That or it's a Backstreet Boys song. I'm not sure which it is. But anyway, one late- What's your call-out?
What are you thinking about this week? So I had a really interesting one. Anthropic published, I guess a blog post, an article- Mm ...
about how they monitor their own agents. Now, when you really read into it, I'm happy to provide the link to folks, what they're really monitoring is sort of the extremes of their agents. From their agents doing things like, okay, writing things in byte code, and different levels that can get past the monitors.
Okay. And there are several. This is part of monitoring agents as they move towards general intelligence, right?
And so there's a lot of things of agents. It's kind of like unruly teenagers. It's like you're hosting- Are they not?
Yes ... your 13-year-old's birthday party, but not it's a birthday party because he's too old to have a birthday party, with 13 of his best friends. And of course, they're always going to get in trouble and push the bounds and break things.
So- Yep ... but it's really, how do you monitor things that are trying to thwart or do things you don't want them to do, and they're also trying to thwart your monitoring? Mm.
So what happens when one of the agents co-ops your monitoring agents? It's all kinds of interesting things there. And it really touched on something I love to talk about, of course, is observability native- Oh, yeah ...
and control planes. And that is getting into the reasoning of what happens in the moment that it happens, and by trying to keep that reasoning hidden to the monitors, so they don't really know what they're trying to do. So- Interesting ...
you and I kind of talk in code, but you know what I'm doing because I'm not- Yeah ... really telling you what I'm doing. That kind of thing.
Interesting job. I'd love to see that job description of somebody doing that work. I thought it was fascinating.
I just asked my friends, did they publish this before or after the leak this week? Let me see what date it was. I don't know if I have it up and I can check that.
It just came out, so it had to be really close to that, right? Because, was this a response to the leak, or was this just a happy circumstance of- Oh ... what Freud would call synchronicity?
I don't know. So this is not the data leak you're looking for. Go left, go right.
Right. Yes. These are not the agents you're looking for.
It was just pretty interesting. It's interesting. Which is-- Go ahead.
Oh, sorry, man. But it is really, because what they, I think, and we've talked about this before in the past, is that Anthropic does a good job of actually trying to expose some of the warts that come along with this transformer rollercoaster that we're on right now. Mm-hmm.
Vis-a-vis things like memory ablation and how in a model you can sort of zap some certain perceptrons to make a model think it's the Golden Gate Bridge, for example. And, so I love that they're doing that, that kind of work. And it brings me back actually to what I'd forgotten to mention with Microsoft earlier, and that is that they're working on forgetfulness.
I forgot to talk about forgetfulness. That's ironic. This is the key takeaway there.
You did that on purpose, I know. Yeah. I know you did that on purpose.
And this again loops back to Anthropic's leak. Because in a part of that, there was a lot of work exposed about a continuously running daemon in the background called Kairos. And what this daemon was doing was memory consolidation.
They basically refer to it as dreaming, which is kind of shockingly how we humans consolidate memories in the hippocampus- Mm-hmm ... at night when we sleep. It's not just sluicing out the bad prions or whatever that build up in the daytime, the plaques, whatever they're called, but also consolidating memories, which is, for models and agents, extremely crucial, right?
Because what if you have conflicting information when you change your knowledge because something new happens, how do you go back and forget the old knowledge? Really difficult for humans to do. Maybe easier for agents?
What do you think? Well, it's an interesting topic because one of the things I did a while back that's kind of related to this is, in the work that I'm doing with AI and agents, is I institute a policy, a rule- Mm-hmm ... that we will journal about what we're doing as part of the memory retention, sort of the dreaming, like let's retain this stuff long term.
md and whatever ways we have of retaining- Right ... memories between sessions and things like that. And lots of things get persisted to disk to be able to perpetuate whatever we're working on to the next session or across sessions or whatever, because oftentimes, even agents themselves don't share memory.
No. But what I was concerned about is repeating the same mistakes. " Kind of like talking to your four-year-old.
"We talked about this. " The bane of my existence, by the way. So, I instituted this, we're going to journal, and when we do things like close down projects and write what we learned.
And there was a whole segment where we were working on how to figure out what the best model is to use for the best work- Mm-hmm ... or the right work, right workload, running on multiple computers, workload locally, as well as using the models in the cloud, AI services, Anthropic, Gemini, et cetera. Yeah.
And understanding price, that these things aren't free. The local ones are free per se, but they also consume resources. I don't have the cloud sitting on my desktop.
And that the model loves to pick the most expensive or one of the most expensive services- It's not thinking about your wallet ... just to do a really great job. Yeah.
Even though I told it we have a budget, here's what we have. So we went through, and interesting in doing this journaling, long story, but to get to the point is in going through, yeah, but we didn't capture this, and let's make sure you document this. But as we actually realized, oh, there's something that we didn't know that we learned- Mm-hmm ...
about what we did. It sort of came out of just the fact that we were doing this process, just like you might journal for yourself, right? You might do it for- Right ...
" And then, of course, now it's like, how do we persist this? How do we use this going forward? So this is always part of it, so there's certain things that we do with the journal to be, as part of our recall when we load things into memory and things like that.
So this whole dreaming and persisting and making things, the retention of that, more than what the technology currently does. It'll do this itself someday, I assume. But- Well- ...
I find it really fascinating ... I mean, maybe just like with humans and we learn different methodologies and practices that work better for us. I have friends who do zettelkasting, and I don't understand them.
But I'm sure it works for them. Then I have other friends- What is zettel-- I don't know what that is. What is zettelkasting?
It's just a form of documenting your life to make a second brain out of all your notes. Oh, okay. I- Digital twin.
Okay ... I'm just an Obsidian junkie, but I do not do links. I do tags.
I'm a tag guy, so hash- Oh, you're a tagger. Okay ... hashtags all day.
Mm-hmm. Yep. But- Okay ...
we learn different approaches all the time. And so maybe today, the methodology that OpenClaw uses with its... It has a journaling system, just like you're describing.
Mm-hmm. You have your soul file and all that other stuff, but the journaling is kind of a critical aspect of that because it puts things in a temporal context. And if you don't have that, how do you forget something?
How do you forget and create a new memory of something based upon whatever that change was? Mm-hmm. For example- Mm-hmm ...
1, which brings me back to the bane of my existence. I cannot believe that in March, now April 2026, that I'm still arguing with Gemini CLI about what year it is and which model is the current model. I gave up on context seven just because it was expensive, heavy, and didn't always use it accurately.
So I've baked into the memory for Gemini, these are the current models. This is what I want you to use for that, just as you were describing. Mm-hmm.
And it still runs home to mama because that's what's in its training data. That's hilarious. Well, I've been struggling with a...
No, April 1st is not on Wednesday. Well, whatever day it was. It thought Tuesday was Wednesday.
Yeah. And I'm like: No, that's not the right date. Cognitive dissonance.
Yeah. It was arguing with me. It kept putting in that I'm like: No, this is the wrong date.
That's not the right date. Oh, that's hilarious. What was the solution?
Did you just keep arguing till it relented? I put it in the prompt every time I tell it today. And on Tuesday, I had to give it the day.
The 31st as opposed to Wednesday the 1st. I think that's right. Yeah.
Wednesday was the 1st. Anyway, so I just had to prompt it and just keep going because I'm like, it's in here, it's in this file, put this in your memory, blah, blah, blah. I'm telling it what to do.
Mm-hmm. And I get stuck on those things, too. You can be tall.
We do, right? Leap year, springing forward and back, just any temporal shift, I think is very difficult for any reasoning species. Mm-hmm.
There are some- It is ... that don't reason, I'm saying, but for most of us that do, or we think we do, it is important. And I've run into that with the work we're doing internally to use agentic processes for- Mm-hmm ...
gathering, collating, and analyzing news, for instance. Mm-hmm. And I've noticed that the place where agents have the most difficulty is when you have, let's say, it's ingesting a press release that is a rear look, or sorry, retrospective of the past, for a financial result for year-over-year financials.
And if that were to publish in, let's say, January and discuss the prior year, if that were to publish from a company that's using fiscal years instead of calendar years- Mm-hmm ... the agents get extremely confused. I mean- Mm-hmm ...
catastrophically confused, just because it's trying to reconcile these sort of concepts, these abstract concepts of time. And it's hard for humans, it's hard for computers, it turns out. I was going to say, I struggle with what's your fiscal year?
It starts in February. Okay, how do I remember that? Right.
So you've got to work within what that structure is. Of course, that sort of cascades to a bunch of other things that change the timing of it, because whether it's budgets and performance reviews or whatever it might be, or decisions to make, buy products and things like that, you just kind of work in this temporal world of everybody's maybe on a different time dimension than you are. So interesting stuff.
Yeah. Time zones suck. I would very much love it if in North America we went with the Asian route, of China with just one time zone.
One time zones rule them all. One lake, one time. Boy, you are on a singularity on a track here, aren't you?
Definitely. I have, you might say, a one-track mind today. One track.
I tried not to say it. Thanks for saying it. So can we talk about a four?
Can we talk about four? Four. As in Gemma 4.
Gemma- Can we do that much? Boy. Okay, let's jump.
Go for it. I was going to go to graph database, so we'll go to Gemma 4. Oh, we have to talk graph because that is a favorite topic of mine.
But yes- Well, that's- ... let's do really quick because numerology is important and so I have two words for you about Gemma 4. Okay.
All right. 0. Mm-hmm.
I mean, we've all come to terms, I think, in this industry with open weights and what open weights means, which is not at all what open source means. Oh, yeah. No.
And Gemma has been a great project because it takes Google DeepMind labs and externalizes a lot of what they're learning and doing in a way that is freely available and can be used to build upon by others. 0. So Gemma 4 is distillation from Gemini 3 family- Mm-hmm ...
in various forms and sundry, because there's a whole family of these Gemma 4 models. And prior to that, they were all open weights with some very bizarre restrictive, got to read the full fine print to understand what the heck you can do with this or not do with this. Yeah.
And now we are open source. And it is ironic in a way because we are seeing this sort of flip-flop between the East and the West right now in terms of the East perhaps pulling back as we saw with the Qwen team, we're losing the Qwen team, and this sort of rumors of this is going to be locked down coming out of China. " And if you think about the family itself, you've got this Qwen beater that is a mixture of experts' model that only leaves, I think, four billion parameters running at any given time across a whole bunch of experts, which looks a lot like the Qwen 35, four billion active parameter model they have.
And the two of them I would see as duking it out directly. And then you have these smaller, what they call, I think they call them edge models or can I start trying to remember- Edge models, yeah ... yeah, much smaller.
Mm-hmm. Much smaller, that are themselves multimodal, able to do things like on-device translation from heard audio to written words. So, you could listen to English and translate into Chinese or Japanese in real-time on your device with a 300-million parameter model.
Actually, the ASR stuff is actually 150 million parameters, so it's even tinier than it was before. Mm-hmm. That is impressive because the reason why it's impressive to me, by the way, is Apple.
Boy, okay, taking a swing there. All right. Right out of left field because- Just because you want to talk about GDC, or not GDC- Yeah, WWDC ...
but Apple I always do. Yeah, WWDC. Sorry.
I'm an Apple fanboy. I'm a Linux fanboy, but an Apple fanboy as well. But, yeah, because they have, as everyone knows, Apple is working with Google for its AI.
And it doesn't take a lot of stretch to think, well, gosh, on-device AI from Google is looking pretty good right now. And- Mm-hmm ... if Siri is ever to move forward and not be something we loathe using, but instead to something that's consistently available across all of the applications that are running on an Apple device, and that they all can seamlessly use whatever available AI, like translation or what have you, on device.
Yep. And think now about all of the app builders, because they do have a bit of an app ecosystem, Apple does. Oh, very much so.
Yeah. Absolutely. And one of the things that's rumored to be coming out of WWDC is this thing called Application Intents, I think is what it is.
Yeah. App Intents, which is the intent of an application to say, for doing X, whatever, I'm available to Siri. That's a big opportunity for those app developers and for Apple.
So maybe being late and initially wrong is better than being right and early. Well, or being wrong and early. Because- That's a full stop right there.
Yeah. Well, which has happened. We've seen that already.
Mm-hmm. And I've been an Apple user since my Apple II Plus, so let me put that out there. When I was going to college.
Yeah, that's like last year, I think it was. Yeah, that was- Yeah ... right before the current MacBook Pro.
One of the things that they've consistently done is gone back to Steve Jobs, is they will work at it, and work at it. Yes. And then they'll work on it again until it's right.
Not that they don't make mistakes, they certainly do, and they've been known lately for the operating systems having kind of, oops, slipped a little off the rails. They're back on, kind of getting things on the track. But everybody complains about, "Well, all you do is make phones and laptops and a few desktop computers," which happen to be really popular at the moment.
Just a few. Minis. Yeah.
But they have held back and said, "Yeah, we're not going to go out there and stub our toe in front of everybody, and everybody's already got great expectations for us. Help them help us fail. Let's just- Right ...
" And so you know they've been working on this behind the scenes, and my first question was, "Well, hey, we have all these neural processors sitting around in our phones. " Right. Is this some grand secret plan they're going to launch things on us once AI becomes ready to do that?
Well, maybe, but maybe it's just going to take a little longer to go. My long-winded point of being, whatever they do, I think they're going to make sure it's done right. So, yeah, we don't like Siri, and Siri's a little bit of the Clippy of the day.
And - Don't diss Clippy. Clippy at least wanted to help. Yeah.
Go away, Clippy. He's like that annoying neighbor kid. "Go away, go away.
" Anyway, so, but I have this feeling that when it comes out, we'll see if it's at the Worldwide Developer Conference this year. Hopefully it is. We'll see what happens.
But I think it's going to make a splash because they're going to- Absolutely ... it's not going to do everything, and everybody's going to just poo-poo because it didn't do this open claw use case that everything else does, or whatever it is. But what it does, it will do well.
It tends to be Apple's plan. And if it doesn't, they keep at it until it does it right, or they pull it back and stop doing it. So, like Apple TV- Which they did already ...
and Apple Cars. We've seen that with Apple Intelligence. That they're like, "Hey, whoa, wait.
" And I'm sure the class action lawsuit helped with that. But the point is that they are willing to turn a very large ship in the ocean there. And so I applaud them for that, and I wish them well with this endeavor because I think right now, and then this is particularly with regards to how these agentic harnesses are taking over our lives, many of them.
And it's for those of us, like you and I, and the folks listening to this podcast, we love to experiment and play with this stuff. But- Mm-hmm ... you have to remember that somebody who's maybe not that familiar with technology, that still yet depends upon it to get through the day, to- Oh ...
perhaps even stay healthy and safe. And so you've got to do it right. You've got to do it in a responsible way that is going to help both freaks like us and the, I'm sorry to say the word normies, but there are a lot of people that don't need this as intently as we do in their lives, but still depend upon it.
" I said, "No, you're nerd adjacent. " There's a nerd curious. So, one of the things I wanted to bring up, because I am at the conference here at the MCP Dev Summit, I guess is actually the third one.
I thought it was the first one, but there have been a couple, and this has been donated to the Agentic AI Foundation, along with MCP and things that have been rolled up under it. So it was interesting coming off of RSAC, which I've worked in the security world for a long time, and there tends to be a bit of a poo-poohing on things that aren't secure. Those dummies that didn't know what they're doing that create something, how could they do that?
And there was a lot of snarkiness in the hallway about MCP, and it's gone. And even in the platform engineering community, they're frustrated with it because it's just sort of an unwieldy- Yeah ... like, what do we do with this?
And yes, you can use OAuth to talk to it, but it's not a two-way, so when it wants to talk to something else, does it need to do it? You need to send an OAuth through that, and now can you sort of violate your RBAC principles of sharing data? There's all kinds of security issues with it.
And, so one of the reasons I came, well, one, I was invited, but two, really to get a pulse of what's going on. Where is MCCP headed? Is it the thing of the past and something else is taking over?
Yeah. We were just kind of happy about it for a year and a half, and now we're going to do something else. But you've heard me call it the, I call MCP the can opener when all people had was cans of food, but no way to open it.
I love that. At the right time. I love that, Mitch.
Oh my God. Yeah, because- Why didn't somebody create this earlier? to me, I feel like it's like phone books.
Because it is like a phone book, is it not? To look things up. And I challenge anyone listening to this to turn around, look around their house, and tell me that there is a phone book sitting anywhere in sight.
Yeah. There is not. There's not.
You can go to one- So yeah, is it the can opener and phone book? Or is it- It is ... going to evolve into something else?
Well, that's a good question. So if you look at kind of listening to the talks and some of the creators of MCP were there, one of the Anthropic guys was. But they also had people from other organizations, some were maintainers, some were also just frankly users.
And one company, I don't want to kind of mention names for here for this, but because it's on their website. One company had sort of a framework, kind of like my agent control plane framework. Oh, yes.
Nice. Which by the way, just got published. And it was great.
I was like, "Wow, there's some good things in that. " And even Uber, Uber had a really fascinating story about how they've been using agents, and kind of controlling them and governing them, and managing- Mm-hmm ... security.
And then also Datadog, who's also been pretty active- Mm ... in this whole AI community. Yeah.
From observability standpoint, kind of Datadog and Dynatrace are the two that have really stepped out into AI. Independents. Yeah.
Yeah. One of their researchers, who had worked at Anthropic and Google, and several companies, been doing this kind of AI on the edge of how do you control it, how do you manage it all, the putting the guardrails in front, in place, et cetera. So I took it as there wasn't a big, "Oh my God, we've got to secure MCP or we're all going to die, and- ...
" That's for OpenClaw. Yeah. Yes.
Yeah. OpenClaw will do that for us. My sense of it is, yeah, people are asking a lot of questions, and people wish it did a lot more, and there may be some question about is it going to be around forever.
I don't know the answer to that, but I know one thing is true, is people are using it, and using it extensively, and it's pushing the boundaries, and people want to get it into- Mm-hmm ... production. And that forces what?
Yeah. Okay, we've got to go through our security reviews, how we're going to govern it, compliance, all this stuff, especially in large enterprises. And so it's forcing the market, or creating an opportunity for the market to step in and say, "All right.
Here's what we're going to do. Here's the control plane we'll use to manage it. Here's how we're going to do agents, using policies to manage agents," whatever it is.
Is sandboxing enough? No. Is containers enough?
No. Right. But those are right steps along the way.
In talking to one of the maintainers, I'm like, isn't the real answer is you've got to have isolation. You've got to create an environment where you can containerize or limit what the... Really, the agent can't get outside of these bounds, right?
At some fixed way or something like that. So wait, so sorry. Are you saying that they foresee the MCP as a...
Because as you and I know, it basically stands in front of an API and abstracts an API. So are- Mm-hmm ... they saying then that an MCP, which, as you just rightfully pointed out, is perhaps itself a security liability, is the answer to not just its own liability, but the liability for agents in general?
Well, the answer, which is what I kind of suspected, and a few people agreed with that I talked with, is it isn't securing the agent, and it isn't securing the environment the agent runs in. It's both. You have to do both, right?
Interesting. Because, otherwise, you're sort of operating in this bouncing off the walls security, pushing the boundaries, where the agent is out of control. Yeah.
Or on the other hand, the agent's highly secure, but it's working in a world that has terrible security guardrails, and it's bound to still bump up and fail and do something it shouldn't do. Okay. And that's the thinking is- Well, that sounds like a layer ...
you've got to do both. Yeah. In a multilayered attack mitigation scenario.
Because I- Dare I say zero trust? Right. We all would love that, right?
But it's not always possible to implement. Not yet. It has- In my travels, because this week I was at Oracle visiting, working with Oracle in their home office.
And before them, when I was with Microsoft, to a T, you hear the exact same phrases come out of these vendors. And one of them was, there were two. " Mm-hmm.
" Mm-hmm. So yeah. I could do a direct tool call.
I could have a PL/SQL statement that's an actual direct call to the database from an AI agent, but maybe a better way is through a layer of abstraction and security to do that. The second thing, which I find kind of crazy, not crazy, but crazy like a fox, is that they're saying, you should have a control plane that exists at the framework level, for managing your agents. But if you're going to secure what actually happens or what gets done with the agent, you have to secure at the row and column level in the database.
Mm-hmm. And that's where you need to build in the appropriate safeguards to ensure that basic things like IP control or just redacting sensitive HIPAA information happens. And yeah.
Absolutely Kind of makes sense. Yeah. So many things about secure your common sense, isn't very common anymore.
But that common sense doesn't always translate to the enterprise, does it? No. Yogi Berra.
For sure. So anyway, the net of it for me about MCP is I don't know if it's going to be the thing in five years. Yeah.
I kind of don't really care, because if it steps up and evolves to be what it needs to be, great. If it doesn't- Yeah ... " Great.
Okay, it's not this, but now it's Kubernetes. It's not this, but it's something else- I'm with you ... to replace MCP.
So I'm not that worried about it, and I'm not the let's just bash it around until it's got such a bad reputation nobody will hang out with MCP anymore. Yeah. Kind of get over it.
We need to work out solutions is- Exactly ... the goal. And there are a lot of people really...
Because it is the can opener. Everybody has a can opener now for everything you want to get to. I did hear very consistently, "I don't look at code anymore in my development.
I use the tools to do that. I use AI to do that. I don't deal in APIs anymore.
" Mm-hmm. And that's how people are viewing the world, developing apps and systems. I appreciate that because APIs are painful.
Oh. They really are. Keeping up with them is horrible work.
So if I can have- Grandfathering APIs. API life cycles. How do you manage redactions?
It's just ridiculous. Yeah. Mm-hmm.
Yeah, and that's of course, we love to abstract things, so it's a great way to do it. But it will get there and there's just some interesting challenges that they've got to work through, but that's okay. There's some really smart people working on it, too, so I think that helps.
That does help. Hey, I wanted to bring up Graph database because I kind of got religion about it recently. You mentioned- Did you?
Okay. Yeah. And I'm like- ...
I could hear Brad talking over just the nice Brad here. " Then- It's just because every year for the last six years for me has been the year of the Graph database. Okay?
Oh. Well, it is kind of, I don't know if it's the year, but it's certainly up there. I'm doing pretty well these days.
But I got to the point, you mentioned about us using these technologies, and I have to use them to understand it. Yes, me too. Because like you said, every vendor says the same words.
They're saying the words we say, or vice versa, but they don't mean the same thing, and you don't really know. So okay, what does it mean to use an MCP server to talk to something instead of an API? Once you see it, then you know.
And this is a really simple example, and I was getting to the point, because I have my own agent ecosystem that I've built. I call them my 28 little friends that I have running around, my minions doing work for me. But all good things- The council of Mitchs is what I would've gone with.
They may be chaotic, but they're chaotic good. Good. That's all we can ask for.
And I came to the point I'm like, "Yeah, this will only go so far," and to really kind of do what I need to do, what I'm asking it to do, make these associations between data, things that are happening across different sources, only way to do this is a Graph database. So, yield me, got my agent- Mm-hmm ... to download, and just use Neo4j, the community- That's a great- ...
edition. great platform. Yeah.
Yeah. Yeah, exactly. It's great.
Been around for a very well thought of, and set it all up. And it was like, see those commercials where the kid who has really bad eyesight puts on glasses for the first time? Or the- That was you, was it?
the father. Yeah, that was me in 2400. Anyway, the father who puts on glasses, who's color blind, and suddenly now sees colors, or someone who puts the things on their head so that they can hear something for the first time.
It was kind of like that with my agents. " And all of a sudden, the analysis that I could say, "All right, I want to do a strategic analysis on this. " And what I ended up doing is I put in all of my kind of thesis about the research that I'm doing.
I put in things like my agent control plane framework and- Mm-hmm ... observability native framework as well, and put that in there into the graph, along with the other data that I have in there. And the analysis that you can do with it, and it's so much easier to ask or tell AI, Cloud Code, whatever you're using, OpenAI, Codex, to go do the things that you're asking it to do.
Because at some point, it's just bumping around in the dark, trying to ask- Yeah ... an agent to do something it just can't do. And it doesn't know like, "Oh, hey, Mitch, you should download a Graph database.
" I'm surprised by that. " "Yeah, that actually was a great idea, Mitch. " "Well, actually, not really, but-" It does say that, yes.
It's glazing happy. Yeah. To me, man, when I think about agentic processes and what you're talking about, you can make a distinction between meaning, the semantics of what a sentence means.
But if you don't know the context of that meaning, yes, through attention, we can see in a transformer model the context of a sentence- Mm ... in a broader set of sentences. But the relationships that exist when you have a node and an edge, and the edge represents a relationship between the nodes.
And once you combine those together, the meaning and the context becomes something different altogether. And by different- Mm-hmm ... I mean more reflective of the real world and how we-...
move around, interact, and understand our world. And this is what we're building toward. If we can build agentic systems that see the world more as relationships than just isolated meaning, we can do so much more with that.
Well, it really connected with me because I'm a systemic thinker. It's about putting enough of the pieces together, the picture forms. You can understand it in a kind of bigger way, how it works.
You don't understand it always in depth or all of it. It's too big to do that. But that's very much what the graph database did for at least my use cases.
Nice. And it was pretty darn simple, using AI to build it. Show me the code.
We should do a demo here at one point of the stuff that you're building, man. But- ... I would love to see how you're implementing that, because- Yeah.
Happy to share ... it's something that you can look up to Tiger or Neo4j or any vendor that has a graph database, and you will see tutorial after tutorial about just how easy it is to do this. And by the way, what do you think transformers really do well?
They read through sequential information and can extract, I don't know, named entities, relationships between those entities- Mm-hmm ... to create a graph. And so it's not unachievable.
In the past, it's been very difficult not just to build, but to also interact with. You might have to learn- No, I've never built one before. Yeah.
I haven't used it. And I used to be a database person long ago, but- Yeah ... the nice thing about AI too is you can say, "Hey, would this help us?
" Mm. " I have a term for that, over-complexifying what we're doing. That is very self-referential, my friend.
It's a term that defines itself, yes. But oh, yes. "This will do what you want to do.
" But okay, now I understand why you couldn't do it. Yeah. Anyway, so I've gotten religion, Brad.
I guess I'm a sherpa now of data. Is that kind of where I'm headed now- Carry, yes ... on that path to carrying this- Saddle up.
Carry the load. We're all doing it. We're all heading- Okay ...
to the summit. I'm with you, brother. We're going together the same way.
Anyway, if you haven't, I'm sure a lot of people have checked it out, but it was just fascinating for me to see it work and not just in concept what it does. Awesome. " What the heck is that?
Yeah. Okay. I think we used to call these dimensional, database.
I think kind of what it was. Weird. Yes.
For OLAP. We kind of like that, yeah. Interesting stuff.
" So, if anyone remembers the '90s or has read about it, or perhaps watched the movie- It was in all the papers. the movie "Hackers" as just but one example of a film from that era that really brought to the fronts the hacker culture, 2600 style. This device I just showed you guys is called the Hak5 Wi-Fi Pineapple Pager.
It's a pager. It's a Linux box, basically, that you can use- Oh, nice ... for pen testing.
And this weekend's project for me is to set that up with the first payload I'm going to run on it is called Claw Hunter. Excuse me, ClawHunter, which is a payload that basically will look for all of the OpenClaw gateways on a network. Just like in "Deer Hunter," mau mau.
Yes, it is. But less shooting. Less shooting.
Less aggression with that. So, I can see if my OpenClaw is doing bad things, and pen test my own setup. So, looking forward to that for me.
That sounds like a good rock 'em, sock 'em robot wars. Adversarial. Yes.
Actually, that would be a lot of fun. Hey, my call-out is, I got to spend some time, of course, with a lot of companies during RSAC, and I really appreciate everyone taking the time to meet and discuss what they're doing. And first of all, there are people out there, who are kind of saying what you and I are saying, which is, at some point, AI, because AI, the velocity and acceleration of how things are happening and information is being produced, we have to move away from the human-in-the-loop means human looks over everything.
Or human stands at the end of the assembly line and picks out every one once in a while to see if there's a quality issue, to really agents that make decisions, agents that actually perform outcomes. And the outcome isn't giving you more information, it's actually doing work. Hmm.
And one of the companies I talked to was, well, you'll love the name, is Endor Labs. Yes. Oh, I do like that.
Yeah. Yes, and even there, they had taken over part of the W, one of the restaurants there, and the exterior of it was kind of the moss hanging off the side looked like you're in the forest, Endor forest. Glad we're still spending money in this industry.
Yeah. Marketing is still alive and well. Crazy stuff.
So they in particular, what I really liked about what they're doing is they weren't just another software vulnerability company. They had actually takenthinks the next level, for one, is not just knowing what code has vulnerabilities in it, but understanding what lines of code are the vulnerability itself. Ooh.
Right? So you could understand, yeah, you might be using vulnerable code, but if you're never using those lines of code, are you vulnerable, right? Right.
Yep. You know? Ask any COBOL programmer.
Yeah. Yeah. Exactly.
Have a go-to statement that goes around all that stuff. Stepping back. Where they were going, the directionally from what I picked up, and this is my reading in the lines, they didn't announce anything like this, is they're one of the companies who are moving upstream and saying it's not just about being a scanner at the end of the line.
It's not about something in the line that produces information better for somebody then to go fix. They are putting things in place that I think someday will help you actually avoid using those things. Ooh.
Okay. Or work around them. Yeah.
Because you actually know where the problem is, instead of just avoiding big chunks of code. "Oh, that's got vulnerabilities. I don't know if we should use that.
" Building intelligence about code. So hats off to them and a lot of other good folks. So nice shout-out.
That's very cool because it makes me think that the era of determinism that we've been living in and striving for, for decades perhaps, is behind us, and we just don't know it yet. Mm-hmm. And that if you can, just like a human, be able to sit without knowing everything and without having total assurance, and you can do so in a sane way, maybe that's better than trying to get to that set of all sets thing where you don't have any Googolian outliers that are still provable but not in your set.
You know? It is. Yeah.
It always comes back to Google, just saying. You have a way of bringing it back together to that singularity again, to that point. We're all coming together.
It's one Google, one hub and one lake. Well, there's sirens going off, and it may not just be because I'm in New York City. I think I've overstayed my welcome, so we probably ought to sign off here.
Good to be on the East Coast with you, even though it's not the same city, but on the same time zone. It's a great time zone. Yes.
Yep. Time. But thank you, everyone.
And look for us. We're going to be on the road more in more places, going to more things. So if you see us, stop by and say hello.
"Hey, you're the guy with the ponytail. Hey, you're the guy with the beard. " Whatever you do, stop us and chat.
We'd love to talk with you, so it's always good. All right, my friend. Been a lot of fun.
We will talk to everybody on the next "Agents of Dev" podcast episode. Bye-bye. Control, this is Agent Dev.
I'm in position. Copy that, Dev. Stand by for go.
Standing by.