Techstrong TV August 14, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. It's time you read The Signal You're watching Text on Gang. Hi everyone, it's a Shiell.
Welcome to Thursday on the Gang. We've got, we've got a, a special episode for you today. We, we had a, you know, we've been working really hard, all the little workers, big workers, little workers at, at Future German that hard at work for months and months working on something that we really were, I know Daniel was busting to talk about it, excuse me.
But we really haven't been able to say anything until now. So we're really looking forward to talking about it. But, um, we're gonna be talking about something called Futurum Signal.
Let me introduce you quickly to our gang members today as we get started. First of all, joining us from Toronto, Garima Boal out west. He's our man in Silicon Valley.
John Schwartz and Futurum, CEO founder Daniel Newman gang. Welcome Daniel. Let's jump right into this man.
Rum signal. What are we talking about? I'm glowing ear to ear.
Now, first of all, anyone that knows me knows that when you say we've been working on something, it's, we've been working on some things. There's a lot of things that we're working on here. But, you know, I've been around this industry.
I started this company eight years ago, and from the time I started the company, I truly believe this industry was fundamentally broken. Um, the way technology decisions have been made for the longest time have been friction laden. They've been slow information is often a year or two years old.
And the inflection to, to change the calculus on how this all gets done really came when AI started to proliferate at scale. When we saw, you know, how much faster, uh, tools can be developed, how much more interactive people are, uh, you know, we've entered an era where people would rather interact with a chatbot. People would rather talk to a generative AI LLM to get information.
Um, but we've also entered an era where we have to move incredibly fast. If you're a board of director, a CEO, uh, it leader, CIO, right now, you are under incredible pressure from your company to make a pivot that you've never seen because you actually have never seen technology move this fast, and you don't actually know how all these things are gonna work. But what you know for sure is if you're a company that you know is in a services business, like, uh, you hear a lot of things right now about McKinsey or you hear about, you know, what Gartner's doing, and it takes you 15 or 16,000 people to generate a series of reports that look two years into the past to help people make decisions on how to spend millions or billions of dollars in the future.
It's just fundamentally broken. So over the last few weeks, we've done a lot of things and made some serious announcements, uh, last week, uh, and depending when you're watching this, it was a week ago here in, uh, August of 2025, it partnered with G two. And for those of you that don't know G two, we became the exclusive utili, uh, provider of G two signal inside of our evaluations.
And that provided over 3 million customer reviews that are now AI powered in real time. Now with our signal. What we're doing is we're combining our proprietary data, our insights, our analysis, our research, our media, our content, and we built a completely AI powered real time dynamic evaluation that instead of looking at where things are today, or even worse, where things were one or two years ago, um, we are looking a year into the future or more, and we are gonna help those that evaluate technology and those that are making the most important decisions about their company's futures, make better decisions with the best information in a platform that feels just like you're using chat GPT.
And so it's win for everybody in this industry. And it's in market starting on August 20th. So this isn't some vaporware, this isn't even as bad as when I announced future AI two years ago, and we were trying to pilot this thing.
We announced it, we saw it coming, we put our heads down, we did the work, and you out there, the customers, the vendors, the implementers and the executives are gonna be the beneficiaries, and that couldn't be more exciting. Absolutely. Um, I'm gonna jump in and then Reemer John, feel free.
So, you know, Daniel, I I just published an article this morning about the ever increasing complexity of it, right? And there are plenty of studies, as you said, old, old school studies, old style studies that look at what's been going on the last six months, nine months, year, two years. But it's clear that whether it's entropy or something else, you know, there's laws of physics at play, it is becoming more complex, and we can look at AI as something that can help solve that complexity or something that contributes to that complexity.
It sounds to me like you are saying Signal helps solve that complexity. I mean, you're in this business, right? I mean, we're partners, we work in the business.
You're, you're very dedicated in the security, DevOps, and AI space. You work with lots of small, uh, companies, startup companies that are trying to break through and enter, first of all, you would agree with me, right? That, uh, AI has probably been the most revolutionary and the most level setting in terms of giving companies that have a lot, a lot less size and a lot less scale, the opportunity to, to build things that the market can desire, right?
Even like an open ai, right? The fact that they were able to even come in and compete with a Google, with a Microsoft, or in some cases, even their technology so good at supported a Microsoft that they're able to, you know, is, is a sign of the positive disruption, but it's also a sign of the speed that's actually putting legacy businesses at risk. So over the last few weeks, you heard me mention it before you, you know, you saw articles come out, you know, Bloomberg reached out to me and asked me about AI sensitive businesses, um, and their disruption.
We saw companies including those in our industry. Like I said, those that are heavily consultant and persona based organizations see their stocks drop 30 or 40%. And by the way, Ellen, it's not just, it's not just services companies.
We saw SaaS companies because we all know that AI is eating software. And so the fact of the matter is, is that entire industries are being upended. And I always like to say slow at first, then all at once.
So for the last two years, I've been kind of pulling the alarm, but just like in the big short, if anybody's seen that movie, you know, being early can also be the same thing as being wrong. You know, when you get too early on the trade. So for two years, everybody, you know, I'm sitting there, I'm screaming, I'm like, AI is gonna change this business, it's gonna change it.
And everyone's like, ah, it's fine. Nothing's changed. Earnings are great.
Service businesses are, are are booming. And by the way, a lot of AI comp, a lot of companies that can support AI consulting have done quite well. You know, you look at IBM, their IT consulting business completely went away, but their AI consulting business exploded, right?
But at some point, this stuff becomes more and more self-actualizing, it becomes more autonomous, and the companies can move a lot faster with a lot less bodies. So we have to build something that can move as fast as the way people want information that's not done with six months of meetings and inquiries and forms that need to be filled out. This happens when you can take the vast, uh, corpus of information that's available in the markets.
We take the everyday interactions, the media, the press, the data, company's own releases, voice of customer data, and we're able to put all that together and actually give very realistic, highly tuned insights as to where the market is going, the trend lines, the buying decision data, the, uh, market size data. We can put all that together and we can basically make some as assessments. And in an era, and you've heard me say this all, at least you have Alan, in an era where data and information is largely become commoditized, the ability to provide knowledge and wisdom.
And I think McKinsey put that out there with some level of empathy. My little add to that knowledge, wisdom with empathy is going to win the day. And the more we can make it seamless, you know, in the way that we interact with our cons, our, our commerce every day, the way we interact with the information sourcing every day is going to enable us to deliver what the market has failed to do.
So I believe the companies that that we compete with absolutely have the chance to, to, to go after this. I think companies like Gartner have an amazing corpus of data. They have an amazing ac uh, access to their customers, but they're also gonna have to make meaningful decisions of how they scale their company.
They can't ask you to have 10 meetings with 20 different analysts that are focused on one tiny sliver of the market. They're gonna need to figure out a way to right size the business to make all that information useful and deliver it in a way that's modern. We can't keep asking people to have all these meetings and all these face-to-face and attend all these events.
And by the way, we do all this stuff. So it's self disruption. I'm not sitting here saying we don't have to disrupt ourselves.
I'm just saying being a little smaller, having a little smaller fleet of people and being a little more platform centric allows us to be nimble and allows us to go fast. And this is absolutely what I believe the right decision of how to go forward is or looks like. You know, can I, if I can just jump in for a second.
Yeah. You know, so this is kind of what I, from a journalism prism, this is one of my conundrums or has been for years. AI is, is never been faster.
Speed is everything in this era. And as a reporter for years, I've struggled with getting market research reports that I know were obsolete or almost, uh, outdated because they were based on something that happened three months or six months ago. So the idea, the concept of this to me is very useful.
So I just wanted to throw the, I just wanted to throw that in because for me, it's essential. And, you know, having worked with Daniel as a reporter source for years, this is something I think that's, that's been lo long overdue. Absolutely.
Daniel, I, I've got two, two comments, questions, and Reemer. John, you could jump in on these as well. Number one, you know, you mentioned Techron.
Most of our customers, not necessarily people watching this, but our sponsors are startup companies. I, I've been a startup founder multiple times. Traditionally, analysts are expensive, right?
We all had to pay the kind of blood money, or whatever you want to call it, the ransom, right? To, to, to get in front of some analyst and, and maybe get into a magic quadrant or what. And I'm not just singling out Gartner, but for many of us, Gartner was the first and only analyst we would pay.
Um, and, but we always felt like the good stuff was a little out of our reach. It was just too expensive. It was a big boys game, right?
It was for the IBMs of the world. Is Signal a a equalizer? Is Signal a a democracy bringer to bringing this kind of analysis to companies large and small?
We see, well, there's two sides of this. So we still think in a world where content, the information is so easily created with ai, and the data is so easily abstracted, that influence and attention will be the currency of which most, uh, startups and technology companies are going to need to invest. Meaning, how do you stand out when it's even harder to stand out?
So we do believe that what made that pricing a asymmetry so significant was there was a time when that was the only way to be seen. Meaning you wanted to be seen in lights next to these other companies that were considered leaders and established to just put your name in the conversation. Okay?
So we are absolutely building our product and platform to provide more access to pro to provide levels of, of entry levels. You know, we've got a emerging vendors category where vendors will be able to be seen, and then we will have sub reports and, and, uh, you know, assets that will be, uh, available for those companies that got mentioned, maybe didn't hit our, it didn't quite hit our, our, our, our signal entirely. But we also are building a platform and an AI based subscription service at Futurum that allows those smaller vendors to get access at a smaller level, but an entry level that's actually affordable and achievable for these smaller companies.
And I'm really excited about that because, you know, we do believe that a lot of these smaller companies, they're looking for a little visibility. com, they're looking for maybe, uh, a mention on a podcast that one of our team members do, or this show itself. Um, and so working with us, we don't only do just the research, just the data, just the analysis, just the evaluation.
But of course, we've got this whole plethora of media events. We've got field days, we've got six five, we've got testing labs and assessments. We've got Techstrong.
We've got all these places become accessible to our vendors. So we absolutely believe that the longer tail is important that we provide optionality and, and, and, and programs, products, platforms, and subscriptions for these smaller vendors. Um, and the big thing to remember, Alan, and you've been around long enough to know this, is some of these vendors start small and they become very, very large.
And so it's quite nice when you're there and you were there in the beginning when they were growing and coming up, and you were there to give them advice. You were there to help, you were there to give access to meaningful information, important signal that they're going to use and carry into their growth phase. Because I certainly believe that the companies that are the biggest today won't all be the biggest companies in the future.
Um, it's been the truth for hundreds of years. This has continued to happen. The only thing that's moving faster is disruption.
So the period of time in which leaders stay leaders in most cases are shorter, um, except maybe the Mag seven, because when you're worth $4 trillion, it's gonna take quite a long time for, for that, that far to fade. But you are seeing a lot of big established technology companies that are kind of falling down the ladder. Companies that absolutely own the SAS era companies that absolutely own the software and infrastructure eras that are now having to take back seats to the companies that came up, the companies that disrupted.
And so we wanna be there to help those companies stay on top. And we also wanna be there to help the new companies rise. And so I think this is just one part.
And by the way, the signals just one thing of many more that we're gonna be doing that is gonna continue to change this industry. I, I don't make those kinds of promises lightly. I expect that the things that we're gonna do in the coming weeks and months will continue to, to send meaningful vibes to the industry about what they can look forward to in the future.
All right. Hey, I, I know you gotta get outta here top of the hour, but, um, August 20th is the date, right? August 20th.
Um, hopefully you guys will share a little more info in the show notes to send a link. People that wanna learn more, um, we would love to, you know, hear from y'all. Uh, anyone that's out there knows you can find me on x my little, little tags down below.
Uh, I'm not, I'm not hiding. My opinions aren't hiding either. You can find 'em all over the internet.
Um, and, uh, you know, I'm excited to continue to work with the industry, uh, bring great empathy, um, great humility and, you know, continue to make this industry super relevant in a feature that will be powered by AI and technology. ai that I wrote that has a bunch of information, even a sneak peek of one graphic of what this looks like. But, um, you, you could check it out there.
Um, Daniel, Hey man. Thanks. I, I think one last thought I wanna leave our audience with.
This is a, a momentous moment, I think, in the consulting analyst industry because it moves it from a services to a product. And I, you didn't mention it, Daniel, but I, I feel really that's an important distinction, right? 'cause services means it's, it's like tied into a human how many humans you have working at it, and you just gotta throw more humans at it when you have a product.
I'm sorry, go ahead. Yeah, I mean, I think, uh, uh, my parting words are, you know, we, we were a 90% services company with 10% products. And I see us quickly driving towards a 80% platform company with 20% value added services.
And I think that's where you wanna be right now. I don't think you wanna be a heavily services oriented company that just, uh, grows on, on, on headcount. I think you have to be thinking about how to scale, because, you know, we've left the, even, this is the greatest parallel I'll give you, but in, in SaaS it was always user based.
But in the era of ai, it's gonna be token based. And so when a company can be a thousand times more productive with 10% of the head counts, you're gonna want to charge on tokens, on outputs, and on outcomes, not on, on seats. And so every business has to think about how to adjust for that.
And so, and one thing I'll say is, 'cause, you know, I talk about great empathy, but is like, when it comes to humans, I mean, humans are gonna be incredibly important in this transition, but I do very much look at it through the lens of Pareto. You know, the 80 20 rule is the 20% that are incredibly important and, and incremental and, and, and exponential to their businesses will only become more important in this era. And that's why I genuinely recommend everybody out there learn to make AI your business partner, make it your partner.
It, it is a super, uh, accelerator of your skills. You can go faster in everything you do. And so 10 x yourself and you will be invaluable to the organization.
Um, and you will make yourself part of this incredible journey ahead. Absolutely. Hey, Daniel, are, we're gonna let you run you churn signal.
Check it out. We're gonna take a break here on the gang. We're gonna come back and talk about is perplexity buying Chrome?
Why? Stay tuned. You're watching Textron Gang, Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group.
5 billion, reportedly. Now, no one seems to know if this is a serious thing or if it's just some sort of PR stunt, but John, you're out in the valley, and what are they saying? Yeah, I think you're right.
I think it's a PR stunt. Um, th this, this idea, this concept of perplexity spending twice its valuation to acquire Chrome at the, at a at a time when the federal antitrust legis litigation against, uh, alphabet could force divest divestiture of the, of, of the browser, seems like a play for pr. Remember, this is the same company Perplexity back in January that proposed a, a bid to merge itself with TikTok us.
Uh, also, uh, a victim of a, of us concerns over tiktoks Chinese ownership. So we had the same situation six months later, seven months later. Um, the, the, the idea of perplexity buying Chrome was characterized even in the journal story as a long shot.
Um, the company insists it's lined up several investors and can do it. Um, the guest we just had, Daniel Newman, I asked him about this when it was breaking, and he said, there is quote, a 0% chance Google spins Chrome to perplexity. Uh, my al what my, I would suggest is that Perplexity actually itself might end up being acquired either by Apple or Meta.
Meta took a look at them before they went to scale ai. So, uh, perplexity actually might be in play more than anything else. Um, this is a, a very bizarre story.
It was almost like a trial blown, it was almost like a play for pr. I, I just find myself, as Mike said in, um, our nutshell notes. This is a very perplexing situation.
Perplexing a perplexity, huh? What a revolt in development. But let me, let me, let me, let me take a, a con contrary position.
I don't think this was just a PR stunt. I, I think Perplexity, first of all, is on to something that, hey, when gov, it's almost like a fire sale, right? When companies have to react to government regulatory actions, TikTok must be sold.
We can't sell CPUs to China. Oh, we can, if we pay 'em, um, we, we gotta spin off the browser. We gotta charge for the av it pro it pre, it's a distressed buyer, right?
It's a distressed sale, excuse me, not a, you know, so they're looking to scoop up and 34, 30 $5 billion may be cheap for a browser that controls I think 60 or 70% of the market or something like that. On top of that, there's a couple of other things. Perplexity would get access to oodles and oodles and pets and pets and whatever's after pets and ERs and of data.
I think, you know, I read an interesting article or LinkedIn post by Reen Cohen, I don't know if any of you guys follow Reen Reen was one of the leaders in Cloud Gima, you're shaking your head. Yeah. Hello, hello Canadian.
Yeah. And yes, he's a fellow Canadian, brilliant, brilliant guy. Ruben looked at the, uh, GPT five, and it does something, you know, it's definitely an improvement somewhat over four.
But he said the problem that the ai, the model, the frontier model guys have, they've run outta data. They've scraped the internet clean to the best that they can. And in order to continue to make the kind of growth and improvements and leaps and bounds that we've seen up to now, they need fresh data.
It could be synthetic data, but we don't know how good that's gonna be and how much of it can you generate. But I would imagine getting access to the kind of data you could get to from Chrome is going to fuel the next iterations, the next models that we, they build their ais on. And, and that could, that alone may be worth that kind of money, right?
Oh, yeah. On the surface, no, it all makes total sense. The motivation is clearly there.
I just don't think they have the tools necessary to do it. And, and by the way, o Open AI and Duck Deck go have also expressed interest in buying Chrome, perhaps as a distress sale, if it's, if it's forced to happen. 5 billion Chrome users.
I think there are 8 billion people on the planets. So, I mean, if the motivation is there, I just don't know practically if it could happen with perplexity. Sounds Like.
So Assuming, assuming that Alan is ripe for a minute, why in God's name would Google wanna do this deal? Because it's just setting up, like not just some random competitor, but a serious competitor, and I think serious A gun to their head, Right? Well, I think they're gonna look for somebody to give go Chrome to who maybe is not such a threat and something that will just let it kind sit off something Who buys it's a threat instantly becomes a threat.
And also, this is a very Gordon Gecko moment, right? Um, you, you don't know, I mean, there are ways you could structure a deal behind this. It may be perplexity buying it with a bunch of investments lined up in them.
You know, think about Microsoft's investment in open AI or something like that, where someone else, not just perplexity, but through perplexity, could step in and have a pretty amazing, pretty amazing deal. Maybe Google themselves. Another reaction I had to this, Alan, is, is this seemed to me it could backfire on perplexity.
This could start the, uh, the bidding war or Chrome too, and, you know, put 'em out of the league for it. What look at I thinks Interesting here is Let Garima go. Go ahead.
Yeah. I, what I think is interesting here is two things. You know, keeping aside, you know, the speculations, there are two things which will happen from this point onwards.
One is, people are already talking about the AI browser race. And you know, we have touched upon that part, right? You know, how, uh, the traffic, how the data, how the monetization also, how the integration of AI into browsers would kind of steer new investments, right?
So it, uh, the browsers are not only, um, an application anymore. It becomes a platform for AI agents and doing stuff, right? So a a lot of like, uh, privacy direction of, you know, how web will be enabled by AI is kind of, you know, in making, so somebody who's investing or has an intention of investing into this space is also clearly indicating that they are setting the direction for web ai, for example, right?
So it's more than you know, what, uh, you see on the surface. And there is a lot more to be discussed from a technology perspective, because at the core, people can question, you know what, this is an open source based on chromium, right? So why should we pay, uh, this billion dollars for that, right?
So it's, it's not only data war, it's also like setting the direction for the next, uh, web AI and how that will shape up. I'll go a step further, and maybe perplexity is somebody else's stalking horse and somebody who wants this, but Google wouldn't sell it to them. So now I'll put perplexity in there, we'll throw some cash their way.
And then, you know, after the deal is done, six months later, perplexity is picked up by, who knows John's Point, apple or somebody. But maybe it's a more deliberate strategy, Thus my Gordon Gecko strategy. Yes, agreed.
It is good. Agreed. Here's the another thing I wanted to mention, and that is, you know, Chrome, Chrome became the winner of the browser wars, and these browser wars have been going on almost since the internet went commercial.
Netscape to Internet Explorer, internet Explorer to Mozilla, then Chrome. Microsoft's been trying to get back into it ever since. I feel like I'm watching the Wacky Racers on the Saturday morning tv, right?
Penelope Pit stopped, Dick Dastardly. You remember that show? But, uh, you gotta be of a certain age.
But anyway, um, the, the fact of the matter is the next stop on the browser war race circuit is not Monte Carlo, but it's the AI browser, right? Perplexity has an AI browser already. I think it's available to their highest tier customer.
Yep. Uh, OpenAI, uh, I'm on the waiting list for whenever that comes out. Um, I think others, right?
Are we about to see the, the next iteration of the Browser Wars and Perplexity is looking to, you know, take a, a what do they call it in horse racing, when you have a one and a one A in a, in a race, two horses in the same stable. Mm-hmm. Uh, and maybe, maybe that's the play here.
I don't know. I'm not enjoying my AI browsing experience anymore than my existing browser experience now. I feel like I'm, I don't think, I don't think this next generation of AI browsers is really, I don't know if you've played with it yet.
I don't know if any of us have, unless I I think you gotta be paying complexity, some good money to use their browser, but it's supposed to be a very different experience. Well, what I've seen so far is, especially from Google, is that, you know, basically annoying summarizations of things that are now getting in the way of the ads that I can't get through to get to what I actually wanted to see in the first place. So I'm just kind of shaking my head at the whole way.
Well, we're gonna, we're gonna clearly know where, what's gonna happen soon, because I think this month, the judge, um, who, who's looking at this case is gonna decide whether Crumb has to be divested from Google. So it's gonna happen any day. And there might be, there might be a bidding more, maybe Perplexes just trying to get to the front of the line.
Sure. John, that's naive. That's naive.
John. This is gonna have to be that. You're not the first person to call me naive.
No, but this is, look, anything like Google having to divest itself of Chrome is gonna go right up to the big man, and he'll make this, Oh, wow, I see where this is going. Okay. You know, maybe he'll take 15%, 20%, but courts don't get to make these decisions anymore in this country.
Oh, gotcha. I I, I stand corrected. Sorry.
Um, So wait, will there be, will, will, will Google just make a trip to Mar-a-Lago and make the whole thing go away? Is that what you're saying? It worked for Intel.
They gotta wait in line behind, uh, live Lipton Nvidia Ad Apple, apple. It worked till work for Nvidia. Why won't it work for Google?
Who knows. You know, this is, uh, this reminds me of a story. When I was a young boy, my grandfather rest his soul.
My grandfather was a contractor, general contractor in New York City, and the biggest building project in New York City in the early sixties, early to mid sixties was the New York World's Fair. And quite truthfully, I'm too young. I, I might have been there as a toddler, but I don't remember, but I think it was like 63, 64, 65, maybe Mike or 65 Was World Fair.
Yeah. Something, my, my my my father worked there on some side gigs during the, during his railroad days. They were paying good money for anybody.
They were paying good money. My, my grandfather did a lot of construction there, but, you know, the World's Fair was run by a guy named Robert Moses. And, you know, he's the subject of a, a subject of a great book by Robert Carrow, like the Master Builder or something.
Robert Moses, builder Power Broker. I, I, I finished reading it. 1300 pages.
Yeah. Amazing, amazing story. Amazing.
But true story. The man built all the bridges and tunnels, all the highways, all the parks, kicked the Dodgers outta Brooklyn and everything else, and the Giants out in New York. But my grandfather used to tell me that in order to get any projects at the World's Fair, he used to have to go to Belmont Park, which wasn't just the racetrack.
There was a park there. And that's where Robert Moses had an office and his brother was there, and you had to bring the brother a suitcase of money, and then you would get your contract signed. And that's really how it worked in New York in in those days.
I don't know how different things are now. Now you're just, today you just go find a union guy in a bar. That's a separate story.
Um, I think, uh, you know, it's interesting you bring all this up. I was just in an antique store store a couple of weeks ago, and I bought a little bowl from the World's Fair from 1964, so I was a little souvenir kind of thing. So it's floating around in the back Office.
Yeah. Very interesting. But, but, you know, but nevertheless, look, the point is stranger things have happened.
And, and in a world where you can make deals like this, and, you know, the old rules don't seem to apply. What's, you know, this could, this could happen. It could happen.
We'll see. Never say never. Mm-hmm.
Never say never. All right, let's take a break. I, I mentioned Intel.
We're gonna come back and talk more about that. You're watching Textron. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. All Right, folks, we're back.
And our third segment deals with, well, another issue involving CEOs and the president, the CEO of Intel apparently went to see the president bend the proverbial knee, and suddenly everybody's all good with each other. Helen, we were talking about this in a show earlier this week, but what do you make of all this? What do I make of all this?
You don't really wanna know, do you? A lot. Um, you know, again, we live in interesting times, right?
Mitchell, I think you said it when we discussed this earlier the week, that, hey, if the Intel CEO goes there with some 24 Carrick gold kind bobble or something, you could probably get this undone. Well, Tim Cook style. Yes.
Yeah. I guess, I guess that's what happened. But you know, it, it, it's such a, this is such a signature moment of the insanity that we're living in that Monday.
We spoke about how the president, who has inserted himself as the defacto manager of our high tech industry, 'cause of course he knows better than any of these people do on Monday, said, the man must resign immediately, immediately. Thank you very much. Or whatever.
However, he ends his, his fiats. And then as John wrote, uh, he, he went, he brought whatever he brought to him, I don't know if it was a suitcase of cash ilo Robert Moses or, or, or a 24 carat bobble or something, or some kind of deal. And now all of a sudden, what a fine gentleman this Intel CEO is.
And we may laugh, but, you know, I'm sorry, go ahead, Mitch. It, it reminds me not to, to make this, uh, you know, the day I ascended the mountain to get, you know, a, a word of it, of wisdom from Alan Shimmel. But I recall back years ago, you said something to me that I still remember today, and that, and it was went something like, today's golden child is tomorrow's blank head.
Yeah. You know, Uhhuh, it's, it's very much. And, and, and could, well, this was reversed, could be tomorrow's.
He was, he was the head. Now he's the golden child. Now he's back the golden child again.
So, had we finished the last segment, never say never. It seems like that's where we're at. But here's the thing, you know, of course one may wanna ask, well, what deal was made here?
Our deal was made here that, that allowed this, that, that this just changed everything. And now I have another theory. I was talking about it because by the way, when I saw your article, John, I sent it to our friend Jack Poer, you know, who is, he was so dead set.
What? Well, how this intel CEO was so guilty, guilty, guilty. And Trump was doing the right thing.
And, and of course, you know, and, and granted that, That that's a little harsh, but okay, Well, the Kettle Ball, a apologetic matter. He said, well, you know, he, these guys know better than us. I don't think they know better than us.
I learned that lesson in my career. Don't assume people know better than you. 'cause they don't often.
More than often. So, but anyway, here's my theory. Well, there, There, there's an announcement is gonna come.
I mean, they, Trump can't help himself. He, what he wrote on truth social was that Mr. Tan and my cabinet members are gonna spend time together and bring suggestions to me during the next week.
So we will hear how they bend at the knee. Just They added hundred million dollars. How much el d****e, d****e or douch or whatever.
What's his beak? So I'm trying to figure out though, how the hell all this got started, because as far as I can tell, Tom Cotton or the Senator from Arkansas teed off on this, Trump picked up on it. Does Tom Cotton know?
I believe it's from Nebraska. No, I believe he's gone. Nebraska.
It's from Well, that, And Blaming Nebraska again, and don't blame Nebraska. What I'm trying to figure out is who put this bug in Tom Cotton's ear, who is not known for a being the brightest bulb in the Senate, and b wouldn't know a semiconductor from a potato chip. So what the hell, where did this all start, John?
Did anybody talk About Oh, well, probably, yeah. You know, it could have been one of the minions of, of, of the Trump administration could have been a competitor. For all we know.
I mean, Jesus Christ. Oh, the Heritage Foundation. It's, it's, it's just like, it's Trump deals in gossip, innuendo, rumors, conspiracies.
You know, you say, you mentioned anything, float anything to him. He'll, he'll run with it. And, and you know, he, he assumes this guy, uh, Bhutan is a, is a spy.
And then he decides, oh, he is a very successful, nice businessman after he meets him. Has Trump or Cotton ever used? I mean, do they use computers at all?
Have they ever used them? I know Trump hasn't. Anyway, I'll stop.
So, so clearly, clearly somebody put a bug in Tom Cotton's ear. Now, did they do that because they have motivation to do that? Was it a competitor?
Was it somebody sitting on the board who was arguing with the CEO EO of this thing? I mean, this is worthy some additional investment. Well, That's, ask you, Mike, that's a very interesting point you make about the board, because the intel board is a disaster.
I mean, there's no, I don't think there's any debate Or that it's a per, It's a vice. It's a fit. And you know what?
Tan, tan kind have fed off through there to get rid of Gelsinger. And maybe some people have turned on him. It's, it's just self-feeding a fren.
It's this company. So you watch your back. I feel like I should ripped off my mask.
And it's Pat Gelsinger here. Pat Gelsinger all along. So, so lemme make up a scenario.
I don't think it's the truth, but it's, it's in the realm of possibility. You can imagine someone going to Trump or whoever and saying, you know what Intel is, just needs to be knocked down a peg and needs to come, come to us with a hat and hand and make a deal. So, hey, hey, who, who can do that?
Tom Cotton? You issue a, a memo, you know, giving them the business and I'll whack on it, on, on true social and pump it up. And guess who's gonna become knocking on our door in, in a day or two?
Well, maybe something like that. Maybe it was intentional. I, I, Mitch, I wouldn't put it past these brilliant gentlemen.
I, it would be a lot simpler just to make a phone call to accomplish that goal. I'm, I don't think, no, I, I think Tom Con was looking, I think Tom, Tom Cotton got his pound of flesh in terms of PR and his bonafides in the maga maga crusade. But that being said, here's the, here's the real truth, guys.
Intel is too big to fail. Mm-hmm. Mm-hmm.
And I think someone got a hold of Trump and said, Hey bucko, you keep talking in truth social like that, you're gonna drive Intel down. And then we don't have an American manufacturer. And that's pretty funny that Trump would get behind the company because they're too big to fail.
'cause I remember him having an awful big mouth when they bailed out the banks that were too big to fail in the recession. But sitting in big chair, he does the same thing. Yeah.
If he would've done it, build him out, he wouldn't have a problem with it. This, this is a radical thought, but what happens one day when Intel wakes up and says, you know, this is just a little too much noise for me and we're just gonna move this whole thing to Taiwan or somewhere else. I don't.
Well, but here's another thing. I, I read an article, one of the former Intel CEOs, and I don't remember who now. Not Gordon, you said Craig Barrett, perhaps.
Craig Barrett. Craig Barrett, yeah. Craig Barrett.
I, I saw that story. Yeah. Put out a, uh, you know, some information that look, he thinks, and you don't break Intel out, number one.
Number two, Intel needs about $40 billion to get competitive quick. And, and Right. The ship right there.
And, but that Intel is basically an American institution. And worthy and I, I wouldn't be surprised if we don't see the US taking a golden share in Intel this way. Donald can run it day to day as he likes.
'cause who knows better than him? And, and Intel gets $40 billion. You, you heard it here first.
Mm-hmm. There you go. Gordon Ley.
I had Coco when I need them. Come on, man. Oh Geez.
Oh God. Doing, doing somersaults. I'm sure.
Unless I say Gordon Gecko again. But anyway, that's enough. But it is interesting.
And you know, and, and we can't blame this on ai, but the news cycle here of Monday to, we, we recorded this on Wednesday, how quickly mm-hmm. These things are. But it, it's, it's that kind of chaos and uncertainty that I think winds up bringing this whole thing down because industry and business, it, it doesn't do well with, with that kind of yo-yoing, my 2 cents.
I dunno. I think it's such a, yo-yo, they're ignoring it. Well, maybe they don't ignore the initial yank of, you know, Intel stock takes a drop.
But rule point, it's kind of becomes noise. So I guess it's, it's, I think there, there are more long-term consequences for this. Like be moving beyond the controversy and the political, you know, stakeholder alignment and all that.
I think it also is dangerous for trust as well as, uh, you know, commitment towards the people who are actually working for emerging technology. So you can't compromise the trust and the commitment, otherwise you'll fall short of the talent pool you have. Disagree.
To me, It all sounds like Yahoos and yo-yos gonna be like, gonna be fun. Buckle in guys. We're in for a rough trip.
Alright, I, I think that's gonna do it for us on the, uh, on the gang today. I, I know it was a little disjointed. We had Daniel in here on Signal earlier and, and then covered our normal stuff.
Garima, John, Mitch and Mike, thanks for joining. We hope you've enjoyed this. Again, Futurum Signals coming out a August 20th.
Check that out. ai. Um, and we'll be back tomorrow.
Who knows what'll happen by then. Only the shadow knows, I guess. But we'll find out.
Thanks everyone. Have a great day. We're out.
Hey everyone, we're back here. We're on the floor of Black Hat though. You really can't tell.
'cause we, we went with a black screen here, but I couldn't think of two better people I'd like to introduce you to, if you read Security Boulevard, if you've been in the security world for more than a minute, you probably know both of these guys though you may not know them, you know them. Let me introduce you to two friends. I know them both 20, 25 years to my immediate right, Robert Hansen.
A lot of you may know him as our snake though. Look, as we get more gray with less hair, we, we go by real names. So it's Robert Hansen.
It's my far right. Is a really good friend. I, I've known him for a really long 25 years too.
He could tell you about his history. It's my friend Jeremiah Grossman. Jeremiah, Robert, thanks for joining us on Techstrong tv.
Always a pleasure. So guys, you know, you're like cyber royalty to me, cyber security royalty to me. But you guys made a big announcement about a week before, a couple days before the, uh, event this year.
Why don't we dive right into that and then we could come back and talk about what's up in your lives and everything else. Sure. Um, Robert and I, we've been running companies together for a long, long time.
What we care about most of the industry is keeping people safe, keeping people from getting hacked. And the way we do that is we try to find the world's most important cybersecurity problem. The one that has to be solved.
We learn everything we can about it. Once we find a solution, then we start a company and we go after it. So we don't start with a technology looking for a problem, we find the problem and we go after it for as long as hard as it takes.
Absolutely. And I mean, just for people who aren't familiar, companies you've done together. So look, the first, I think I met you, you were still at Yahoo.
Yeah. You had, or maybe just leaving Yahoo. You did White hat.
Yeah, I, I started my career, uh, 25 years ago at Yahoo. I was one of those kids that hacked Yahoo Mail and they gave me a job instead of calling the FBI. Yeah, Lucky you For you.
I took what I learned there and I learned that web security was a problem. Mm-hmm. And I wanted to solve it.
So we created White Hat Security to, uh, scale and mechanize application security and vulnerability assessments. And of course you had to get the other best in the World Asset guy out there. And that was Robert.
Absolutely. Right. And, and look, white Hat kind of invented, uh, you know, uh, pen test or AppSec testing as a service almost, if you will.
Um, but then that was one company. What came next. Uh, the next one was, uh, when, when, uh, we left a, let's say a white hat.
I, I did a short time at Send One in the early days to focus on ransomware, which wasn't a thing yet. And, uh, go after, uh, endpoint. But, uh, that was two years.
In the meantime, while we were working on something for Attack Surface Management, what we were learning was a significant number of the breaches were having to do it a previously unknown asset that's, they would've secured if they know it, they owned it. And so I'll have to, I have to pass it to Robert here, but I said, Robert, the we only where we're gonna solve the attack surface management problem is to download a copy of the internet first. And, uh, so Robert, true to what he is, he goes, okay.
Yeah, Yeah. I think, I think, uh, people when they hear that, they're like, that's can't be possible. But we were processing by the end, like multi petabytes a month.
And I remember, and when people think of the word internet, they're thinking Google, that's just the web, that's a searchable web. What we really needed was a copy of every piece of metadata, Every ip, I Just, everything, everything, every ip, telephone and printer and whatever. So that was a pretty big challenge, but it enabled us to answer the question, what do people own?
And uh, so that kind of took us down this path. I, I remember you working on that. You know, one of the before I did still secure my friend Raj, who's one of the co-founders with me, is still secure.
He started a company Cova, which was IPG location, very similar thing. You had a geolocate every IP address. So figure out, you know, which IP address went where.
It's a huge undertaking. It was simpler then, 'cause it was smaller then it was bigger by the, a lot bigger by the time you did it. And of course, that led to another company, and I'm blanking on the name right now.
Oh, that there most recent one. Uh, so, uh, so Bit Discovery, the attack source management company. So we raised money and, uh, during the pandemic and uh, the company lasted a whopping three years.
So it was a very fast moving company. It was very successful, very fast. And it was acquired by Tenable, right?
So, uh, you know, so Robert and I were, we have a background in application vulnerability management, but not, uh, so network or CDE vulnerability management was, uh, familiar to us. And so what we learned there was that this is a very big 25-year-old problem. Everybody has a vulnerability management problem.
They were sick of it. Everybody was buried in vs. Didn't know what to fix first.
And everybody was still getting hacked. So we're like, okay, we gotta set out and solve this problem. So Robert and I have TA taken hundreds of meetings to learn everything we can from everybody we could about this problem to figure out what the problem was before we could solve it.
So two years later, we're ready to launch the company 'cause we think we had some answers. Mm-hmm. And that company is, That's rude evidence.
Uh, also known as just evidence. We go by that as well. But I think one of the cool things is, um, we pulled in tons and tons and tons of data.
We, instead of like, most people are just like anecdotal evidence only, but we pulled in information from every source we could possibly find just to see if there's anybody who agreed. And it turns out no one agrees. And that was sort of the premise that got us thinking down this path is like, well, if everyone is disagreeing, that probably means that everyone is, at least everybody, but one is wrong, but probably everybody's wrong.
And so we gotta think of a entirely new T Like how do we, how do we tackle that? Fortunately we've been talking to the insurance industry for years and years and years. So we had really, really good relationships with them and they started sharing with us some, some details about claims.
And it turns out you don't need to look for 300,000 CVEs. It's a much, much more finite number. Much easier to do.
Absolutely. So I have a little experience in this, right? I started a vulnerability management product that's still secure in 2003, a lesson I learned in business, if there was a really good solution, there'd be one, maybe three.
There's a reason why there's dozens of vulnerability solutions. And I would say, Robert, it's not that one is right or one is wrong, they're all a little wrong and a little right? That's right.
Everybody, right? Everybody has kind of nibbled on the edges here, but no one, no one's really solved it. So, And, and enterprises feel that, so, oh, absolutely.
So the one observation that, uh, you can reference this, um, only 1% of all known vulnerabilities have ever been exploited. And that has been the case for quite some time. So if the prioritization models are working, why is it always 1% of vulnerabilities?
So that's something to uh, something to contend with. So the concept that we're bringing forward is evidence-based vulnerability management. And the way to describe it is, any given vulnerability could have evidence of exploitability, it could have evidence of attacker activity and evidence of attacker breach and loss, financial loss.
If you have all those three, those are the ones you First you got, Right? If you don't have breach and loss data, you have effectively a Kev list vulnerability, which is fine, but that's the next down the list. You remove evidence of, uh, attacker activity, then you get into prediction and prioritization.
So what we wanna do is concern ourselves with the ones you absolutely must fix. Now, no ratings, no scoring, no color codings. You fix these and if you do that, you're better than 99% of everybody and you're not going to get hacked.
You know, I'm reminded, I don't know, do you guys know Giddy, giddy Cohen? Oh, he sold the company, but it's not 20 years old. Giddy was the first one I saw who generated attack maps of vulnerabilities.
So it would find a vulnerability and then work backwards from there out to the internet to see is it reachable? Is it exploitable, is it fixable? And how is it fixable?
Is it patchable? Can you close a port down? You know, what's the remediation path?
And darn, I can't remember the name of his company, but Giddy Co was the founder. And I thought that was one of the best things I've ever seen. And, and how do we tackle this?
Now, we didn't have ai, we didn't have the, the reams of data that you guys had, but it was a, it was a holistic approach to saying, let's get out of the hamster wheel of just giving you a phone book of CVEs in South, see you next year. Right? Which is was the kind of state of the art when I was doing this in 2003, right?
Well imagine, imagine that's what you get, right? You have like 50, a hundred thousand vulnerabilities. Some of these companies have millions of vulnerabilities.
You go fish fix a bunch of vulnerabilities the next day you have more vulnerabilities, you're not actually really moving the needle at all. And we, we spent a lot of time thinking about like, like what, what if you have 10 vulnerabilities equal chance of a bad thing happening to each one of 'em, and you have a million dollars in the pot in the middle. Any one of 'em gets you there.
If you only fix nine, but you leave the last one there, like you actually just wasted time. You Probably shouldn't have fixed. You Probably shouldn't.
Well, shouldn't have fixed any of them, which is a weird concept. And I think security is gonna have a really tough time, like really thinking through that. And of course there's a lot of variables there, but, but I think one of the cool things about looking at the insurance industry is we're like, here is loss.
We are actively seeing loss in these places. Why don't we fix these first? Right?
And, and the nice part about that is now we're talking dollars and cents. We're no longer talking about, you know, some prediction model that, I mean, and no offense to those guys 'cause I think that is really very tricky and interesting. It's just that it's very hard to predict when there's only a handful of loans.
And depending on who you talk to and we have reasons to believe some of these numbers, it's definitely less than a thousand, let's call it that. So we're talking a fraction of a percent. So if you're gonna make a prediction, you have better be perfect if you're gonna get exactly those vulnerabilities.
Absolutely. Look, no one manages risk better than the insurance industry. That's what they do.
And I've never met a poor insurance company, right? Um, so I think that's a great model. My my question though to you guys is does it wind up being like the OAS pop 20 where it's like a static list and, and right, this is a list that needs to be constantly cared for and guarded.
That's, uh, that's a great question. Um, to lead into that, what we learned, uh, what we've learning is about 50% of the breaches that lead to loss have something to do with a remote exploitable, CVE. So if we wipe those out, the ones that Robert was mentioning, we can reduce 50% of the losses.
That's huge. That's the impact that, that we wanna have. Does that list is a thousand vulnerabilities?
How does that get updated? So right now, it's generally speaking a static list. That's why we know the vul management industry is getting it wrong.
Because if it's only 1% of VULs, that means the adversary is not forced to innovate, to take on the next one. So if we get the prioritization right, we should expect the list to change over time. Right.
And that's our gonna be our bellwether if we're doing it right. So If we see that list starting to That's right. That's a good Thing.
So, so if the list changes, we're doing it right. And that's what our intent is. Increasing costs.
Yep. Let me ask you another question. So there's finding vulnerabilities and there's fixing vulnerabilities.
I get what you're doing to help find the, the right vulnerabilities, let's call it that. What, what is evidence hub to fix those vulnerabilities? So ultimately that's not our job, that's the customer's job.
Uh, but we can make it easier. Uh, and I think the major way we make it easier is we help them make their own business case to their own executive team about why they should prioritize, both by reducing the amount of, you know, chaff, a bunch of vulnerabilities that'll never be exploited, have never been exploited by anyone. Now, if it's a much small, a much more definitive list with known attribution, um, to claims data, and we know what the claims losses are, now, it's just a matter of how much, what kind of cost it is.
So if it's like a million dollars to fix a vulnerability, that'll cost you 5 million if you don't fix it. Well, that's a $4 million. ROI.
That's, that is a very easy business case to make to your CFO who make no mistake. That is the real risk officer of the company. Not, not the, not The CSO or, or any of Those people.
Exactly. Exactly. So I think that's really where our main focus is.
Now, we could always pivot more into that area later, but just by starting talking dollars and cents, I think that's a big win for the customer. Absolutely. I, I, you know, another, another piece of this though is I used to call job security, right?
The vulnerability, the guy who's responsible, or gal, whatever, the person responsible for, vulnerabilities, vulnerability management, the team, they've gotta be incented to hit the right stuff. You know, you know what they say, right? If nothing happens, we did our job.
That's not a hundred percent true, to tell you the truth. Nothing happens 'cause it didn't happen yet. That doesn't mean you're doing your job.
How do you, how do you help that worker or show metrics that, hey, I am doing my job and we're doing a damn good job with evidence. So that's a fantastic question. One we contend with all, all the time.
'cause if we're gonna reduce the set of vulnerabilities that matter, then we should get to VUL zero really, really quick. Yep. So what we, what we want to be able to do right now, when, when companies get hacked, the standard PR answer is, the attacker was sophisticated.
Please don't sue us. We did everything we possible. It was a zero day, of course.
Where we wanna move people to is if somebody gets breached, it will only be by a vulnerability that no one has ever exploited, ever. That's a defensible position. What more could they have done?
They fixed every VM that has ever gotten anybody breached. Right? That's pretty good.
That's better than It's the zero day argument. Correct. Not even a zero day.
It just, no one exploited that one for whatever reason. Zero day. Otherwise It happens.
Now, let me just business model a little bit. Uh, back in the day, we used to sell it by how many hosts we were scanning. 'cause it was scanning, right?
How many hosts we were scanning, how many ips, how many nodes, how many vulnerabilities? I how do you want to, you know, skin the cat today? How, how is this packaged?
Uh, uh, the business model will be software as a service. You should be able to go to a website, put in your company name and hit scan. It's the straightforward thing around.
And what we want to be able to do is we don't want to wow the customer with, look how many giant plates of red you have and all this red, you know, no, no, no. We want to help them in terms of dollars and cents. This is what you need to fix.
This is what it's gonna cost to fix, and this is how much money you'll retire. You'll retire at risk. We want to get to VUL zero, at least for the VULs that matter.
That's the best anyone could ask for in this world. Hmm. So you don't, I know this sounds old fashioned, no agents, no internal sensors, pizza boxes or Any of that stuff.
We only need as much as the adversary does. Right. Which is effectively not The hack side view.
Yes. Right. Again, our background is breaking into things.
That's where we came from. So we want as little as possible, we want to see what the actual risk is. Let's talk a little bit rollout availability.
Robert, is it, can people go on right now? Uh, no. Uh, we, uh, we, we literally just started fundra.
We've got our fundraise, whatever it was two weeks ago now. So, uh, it'll probably be a few months before we're ready for design partners to start really like actually using it. Uh, it'll probably take another six months, I'd guess before a fully rolled out UI is, you know, freely available to anybody.
Uh, it depends a little bit on what we, feedback we get from the customers. Um, 'cause one thing Jira and I really spent a lot of time doing is absolutely making sure our customers are just, this has solved the problem. If it doesn't, like, we have to go back and fix it.
So that's the real question mark, is what rejiggering do we need to do to make it, you know, one of the things we really wanna focus on is speed, for instance. Uh, like being really, really, really fast. Well, if it turns out that causes problems, you know, we're gonna have to do workarounds, you know, for whatever reason.
So that's, uh, it's an unknown until we get there. But, uh, the good news is we do have a lot of experience building these kinds of things, so, sure. Uh, so, uh, for those that are, that are interested, so, uh, we have a really good idea of what needs to be built, where we're gonna need help from the industry.
You know, practitioners, bone management teams, with the people we've been meeting with the last two years, is what does it look like? What do you need it to look like? We know what needs to be done.
What do you need it to look like? So for those that are interested, reach out. We want to hear from you.
We don't have all the answers. We'll get into that camera. Where did they reach out?
Oh, reach out. Um, root evidence, uh, dot com. Sign up for, uh, you know, the mailing list.
And, uh, we will reach out. We will, we will meet with you. We want to learn from you.
We want to solve this problem. We're not ever gonna have all the answers, but we'll build nonstop until we solve it. And with your track record, you got a good chance that's happening sooner than later.
Guys, I can't wish you enough luck, success and, and you know, strong tailwinds as as you go forward here. If you don't mind, I'd like to just pivot a little bit. Let's talk black hat.
Yeah. So I first met you in Black Hat, I think in 2005. I got hacked on my iPhone three, I remember.
Yep. And it was, I, I forgot the dude's name. I think he's still in jail, not for hacking me, of course.
But he was an idiot. Anyway, but, and Jeremiah, I probably met you around the same time, but you started, I knew you more for Black Hat fit the Juujitsu stuff with Hoff and everything, right? Yeah.
That had to start also around 2005, 2007 maybe, something like that. My, uh, my first black hat was, uh, 2001. Yeah.
Well, my, mine was 2003. I got you. We used to be at Caesar's in the hallway.
Yeah. I had a booth overlooking the, uh, the Venus pool. And if you would take a briefing from my guys, I'd let you use the, uh, binoculars.
That's how long ago and wrong that was. But anyway, black hats changed over the years. It's, in many ways it's not what it was, but it's something better different than what it was.
You guys are both intimately involved in the whole week's worth of activities. Give give the share with the audience, if you wouldn't mind a little background on this. Yeah.
Uh, I was probably, if memory serves, I think I might've been one of the very first board members for the main conference. Uh, so helping select talks and make sure that they're of the quality that we want. Um, but gradually, Jeremiah and I, I think we, he was also on that with me.
I think we decided it was better to spend more of our time on the CISO summit. Uh, it is just really important to make sure that the CISOs are getting the kinds of information they need to get. Um, and so fortunately there's a lot of people backfilled and did a great job, and that's why the main conference has done so well.
But our focus has really been more on the CISO event, the Cyber Insurance Summit, it's a micro summit, and the Innovation and Investor Summit, which is all these sort of Micros summits. It kind of floated around the, the periphery of the con con, uh, conference, but are really important to sort of pushing the, the needle Field. No, I, I think that's the model.
Whether you go to the cloud native like CubeCon Summit or RSA or Black Hat. It's these satellite conferences or what I call the more conference within the conference micros, that really, you really get a lot. If, if that's your thing, you, it's a deep dive, a deeper dive than you're going to get going to a keynote or walking the floor and getting, you know, distracted by lights and buzzers.
So it, it's great that you do that. Give us kind of a metrics. So for instance, Jeremiah, the CISO Summit.
How many people are in there? Uh, so the CISO summit is fantastic 'cause uh, we like talking to ciso, see what's top of, what's top of mind for them. And, uh, so the CISO summit, uh, this year was 400 CISOs all in the same room.
So the way we do the CISO summit is a little bit different than the briefings. The briefings take submissions, and then the review board picks the best of the best. And, uh, you know, Robert and I have both given many talks there.
They do a fantastic job. The CISOs summit's different. The CISOs have an agenda, they know exactly what they want to learn.
So we get about 10 topics down to things that they wanna learn. And then the review board sources the world's leading experts in those topics. And we invite fight them in and just let them loose to, to speak their message and what they know.
So the content is, uh, super high quality. We have, uh, generals and, you know, all the people that are front line of the, uh, uh, the breach, uh, uh, salt typhoon breach and things like that. Right.
Things you can't get anywhere else. Absolutely. I, I had friends at the Investors and Innovators Summit.
They said it was Greg Robert. Oh, yeah. People who are home maybe didn't see it, don't know about it.
Yeah. It's, it's a brand new as of last year, uh, event. Uh, so this the second time we've done it, and I think we learned a lot of lessons last year, and it was really good.
So the content is basically a mix of people who are, you know, entrepreneurs getting into the industry. Maybe they have a company, but they haven't quite figured out how to take money or haven't figured out how to talk to customers, or they're sort of in that growth phase, and they're just starting to figure their, their way through. And then the other half is a whole bunch of very seasoned VCs who are trying to meet those same people.
So it's a really, it's a really kind of magical thing, you know, it's like everyone's just kind of coming together and sharing stories and kind of like, who are you? And let me give your business card. It's like, just tons of deals getting made right and left.
But, but it's also a lot of great advice, really well-meaning advice because there's a, there's a peer group there too. It's a whole bunch of other people who are struggling to meet the other people on the other side of the fence. It's great.
It's a great Conference. It is. No, it's great.
I I stopped by Bri. I was, I was grabbing Michael Fardo out there. But, um, so guys, what are you doing in your spare time?
You still doing your podcast? Occasionally? Yeah.
You got, sorry. Yeah, occasionally. Um, so I do, uh, demos, product demos.
So companies will come to me and, uh, and for free, you don't charge anybody anything, but they'll come on there and they'll do a, uh, about an hour long, uh, presentation, 45 minute presentation. I ask him questions with Trey Ford. He is my sort of co co-presenter.
And, uh, but we just, we ask him kind of, I wouldn't say elbows out hard questions, but the kinds of questions that if you're sitting on the other side of the fence and you're a security expert, you know, if that answer was a good answer or not, you know what I mean? And the nice part is, unlike having to put your email address in somewhere, you could just watch it and enjoy it. And, and if you want to do something with them, you reach out to them.
And we've got a whole bunch of people who've be wanted to meet that company. So it's, it's ended up being a great sales channel for a lot of companies. Good for you, man.
Where, where can people get that podcast? Uh, just look for arsenic show demo day. Beautiful.
Thanks. Robert, what about you, Jeremiah? Uh, for hobbies?
So, uh, I guess, uh, for the blackout related hobby, so, um, a long time, a long time ago, you know, I started Brazilian juujitsu like 20 years ago. And, uh, rather than go out to the vendor parties after blackout in the conferences where there's crowds and noise and things like that, I decided to get a workout in. So I would visit Juujitsu Academ.
So at blackout, I'd rather go to the vendor parties. I would find a, an academy. And, uh, somebody saw me leave the conference once and they said, can we come?
That was Chris Hoff. And I said, yeah, sure. So we started trading them like the next year, more people wanted to come.
And then it grew to a, a life of its own. Where now I put a 60 plus, uh, computer security people on the mat with UFC fighters, and we learn and spar. It's like, it's a, it's a crazy event.
No, it's, it's Really cool. The pictures are fantastic. It's fun every time, so I love it, guys.
Fantastic. It's great seeing both of you. com.
Check it out. This is gonna be something you can get, you can get in early here and, and watch it. Robert.
Pleasure man. Jeremiah, two of my heroes in, in security. Uh, we're live, well, we're not live.
You're watching this recorded, but we were live when we recorded it. We're a black hat. Stay tuned.
We'll have more. Bye-Bye. Hey everyone, welcome back.
You know, we made it up from the show floor of Black Hat to our suite here, uh, in Las Vegas to do some a little bit quieter. Hopefully the quality will be better for you. Um, I'm really happy to introduce you to Dave Heimer.
Fair enough, fair enough. You say it for me. K Hamer cr hammer.
Either way. Dave is here with us. And, uh, Dave, the company's called Q Secure.
Yeah, Q Secure. That's Q like Quantum. QU Secure.
Yeah. Yep. Quantum Secure.
And, um, well, we're going to hear all about the company, Dave, but first let's hear a little bit about you. Sure. Um, so again, Dave Coffer.
I have a computer science background from before. There were computers a long, long time ago, and I kind of spent a lot of time in it, became a Chief Information Officer in telecom. Um, and then I founded, uh, what became the, uh, Oracle's largest cloud partner services partner.
So grew up in that kind of enterprise software realm. And I grew up in a very nerdy Caltech family, JPL family, and was always really fascinated with physics. Um, although I didn't have a physics background.
So we founded a company that was really focused on quantum computing, quantum algorithms, and quantum development, and then pivoted into this quantum security paradigm that we've been doing since, uh, roughly 18, 19, 20 19. And just been having a really fun time. But, um, just focusing in on creating new layers of security to protect us from current and future attacks.
Un un that's fantastic. If you don't mind me asking Sure. What, what possessed you to this was what, about four or five years ago?
Yeah. What possessed you four or five years ago to jump into quantum computing? Uh, that's a, that's a great question, Alan.
So, you know, like I said, I, I, I grew up in a very nerdy, you know, family. My mom was a college professor, and I was always really just fascinated with future, next things, really exciting things that were occurring. And they were kind of on the cusp of quantum computing becoming a real thing and what do you do with it?
And so I've had some exits and I was in a good position to kind of do something really fun. Um, I founded the company with my daughter, uh, who's now the CEO. That's Fantastic.
And it was just really a wonderful opportunity to focus on some really future cool stuff, make it a now thing, you know, work with my daughter and just do some cool things. Love it. You know, it, it's funny, Dave, we're about the same age Yeah.
And we've seen waves of technology, as you said, come and go in our time, not just go. 'cause technology never leaves, it doesn't fade away. Right.
Like Douglas MacArthur says about, you know, old generals. Um, it, it gets built into the foundation and then we build on top of it and on top of it and on top of it. Yeah.
Now, quantum, I, I have to admit, when I first became aware about quantum computing, it sounded Star Trek ish to me. Yeah. You know what I mean?
Yeah. And, um, I didn't think I would see it in my lifetime, let alone in my work and career. Yeah.
But then again, I didn't think I'd see artificial intelligence In your career. Yeah. In my career either.
We're in here, we are. Um, there's so many aspects to quantum computing. I was actually talking to a friend of mine, John Willis Day, he was doing a book on quantum computing.
He was telling me he's about 150 pages into this book. And he said, Alan, you don't realize how long this has been sort of a, a holy grail, if you will, because it could do everything and nothing all at the same time, so to speak. Absolutely.
Um, I think for a lot of our audience out here, they don't, they don't understand Yeah. What quantum really brings. Sure.
I I think probably the easiest use case is the security post quantum encryption that we hear about and stuff like that. Yeah. But Dave, if you don't mind, let's pick your brain a little bit Sure.
With our audience, when we talk about quantum computing. Yeah. You know, we toss around terms like qubits Yeah.
We, you know, and, and the whole non-binary kind of being both a one and a zero at the same time kind of thing. Yeah. But what do we really, what does it really mean?
Where does the rubber meet the road for our audience? That's a great question. So when we talk about conventional computing, conventional computing processes, a, a transaction or a word really fast, and these transactions are like 64 bits, you've heard of a 64 bit computer.
So I process 64 bits worth of information at a time, which is great. We've figured out how to do that really fast. But it's linear in nature, meaning it goes from step to step to step, which is good for a lot of problems.
But, you know, in the Venn diagram of problems, there's all these problems out here that you can't solve linearly. Um, hacking RSA is one of them because it's prime and refactor, right? So just if the quantum thing is, computing is really simple, it takes that word of 64 bits and a qubit, which is like a quantum bit.
It's basically an atom. A qubit is an atom. Mm-hmm.
And when I create a word of 64 bit word out of 64 qubits, instead of being 64 bits, it's 64 2 to the 64th. So the word size of 64 qubits is equivalent to like all the data stored in the world in the last year in one transaction. So instead of like linearly going from step A to step B with one instruction, it did such a massive amount of volume and capability, I can solve these problems.
That, like, one good example is like, if I go into a maze with a conventional computer, I turn right, I go left, I do this. If you go in with that quantum surrogate, I can take every path simultaneously all at once. So really, if you boil down quantum computing, it's just the word size is really, really big.
And, um, and it lets us do kind of amazing things with significant amounts of data in an instant. You know, I've never heard it explained that simply eloquently good Work. It's really actually a simple concept that they use some fundamental natures in the bit, because it can be one zero anything.
It's, it's not just on and off. It's, and I put 'em together and it's just really a lot of capability. But It's two to the 64th power root To the 60 volt power, which is equal to a Yoda bit of data, which is equal to all the data stored in the world in the last year.
It's a lot of data about Transactions. Crazy. Now you understand why it's so hard to develop Now.
As hard as it is though, I, I don't want to be, I, I, I think we owe it to the audience the time we've been making tremendous progress Yeah. In the quantum field, in the quantum, uh, computing field. Talk to us a little bit about the state of the art today in quantum computing.
Yeah. So, so this quantum bit, which is just an atom, right? Different kinds of atoms for different, for different applications.
Um, the, the quantum bit, the, the whole issue is error correction. They're very noisy. So measuring a quantum bit is really hard.
So there's been really significant improvements in the noise of these bits. So, to crack, RSA, which is what we're here to talk about, RSA, is the encryption used on most devices. It's a prime number 20 thou 2048 bits launch.
Um, you need about 4,000 quantum bits, but high quality noise reduced bits. So what happened in the past two, three years ago, if you had a million cubits, which you didn't, it would reduce down to, you know, a hundred clean bits. Now they're improving the error correction to where, you know, you can have one qubit that's error corrected.
And, uh, once you have error corrected qubits, which we're racing towards really fast, you mentioned it Yeah. That the power of what you can do is, you know, is unimaginable. We're gonna have, you know, instead of ai, we're gonna have convolutional neural nets that can parse your whole complex neural nets at once.
So instead of like going, well, I'll do this, put something in a bucket, they'll be like, they'll be able, you have about 400 billion neurons in your brain, and it's highly parallel. So with quantum, you could actually understand the whole state of the system. Error corrections is the key.
We're making monumental strides in error correction, and it's really exciting time. Yeah. The other thing I've heard, and, and look, I'm no quantum expert, I'll say that up, up front, is we used to say, well, we had to reach a thousand qubits to have sort of a working quantum computer model.
But now they're saying, well, no, we may not truly need a thousand qubit machine. We could do these in parallel. Yeah.
And we get away with a lot less to have functional quantum. Yeah, yeah. Yeah.
So, um, you know, the, the, the, the holy grail is getting to 4,000 qubits to crack RSA and when that happens, we'll talk about it in a minute, but every device is vulnerable. Your camera, your plug, Anything that's encrypted, Anything that's encrypted is vulnerable. It's kind of like the new malware.
Um, so, um, you know, there, there lies, the, the challenge State of the art RSA is 2048. Yeah. But there's a lot of legacy stuff out there that's 1 0 2 4.
Yeah. And that needs half 4,000. You say you need 4,000 for 2048, you probably need 2000.
Right. And in parallel, you could get almost in spinning distance of that right now, from what I understand. Yeah.
And there's, you know, in large corporations, um, they'll have thousands of applications that have embedded cryptography. Some of this is from companies that have gone outta business. Sure.
Some of it's, you know, des triple des old, old encryption that's already been hacked. So we already have this cryptographic debt is a term I was a CIO in my old des We have this cryptographic debt, and as I said, only about 25% of the companies actually monitor what cryptography they have. So the networks are strewn with older stuff mis implementations, and we don't even know what debt we have.
So it's really, yeah. It's not just cracking RSA, it's, there's just a vast array of stuff out there that we don't even know what it is. I Know RSA might be the gold standard, but there's a lot of silver, bronze, and copper.
Yeah. It's in play here that, that's highly Vulnerable. Sure.
Um, now look, I've, I've had the pleasure over the years of, of working with a few companies in the quantum encryption field, one of which, or post quantum Yeah. Encryption, I think is the right term. One of which is DigiCert, which is probably the worldwide, worldwide leader in digital certificates.
Web certificates. Yeah. You know, and of course NIST has been involved in this Yeah.
Mire, you know, quasi-governmental agencies and, and we have come out with post quantum algorithm. Yeah. That is supposedly quantum proof.
Yes. Now, the adoption of that, you, you know how security is, we don't, do we have what we call just in time security. Yes.
They don't do it till it's probably a little too late, then they all of a sudden everybody gets religion. Yeah. But what, what about, what's the state of post quantum cryptography for these kinds of Sure.
Digital certificates? Um, great question. Just I wanna be really clear that post quantum is just better math.
So RSA primer, refactored post quantum is just lattice math. It's just better math. So I like to equate it with RSA.
If I wanted to have tea with the queen, I go to Windsor Castle, there's one guard, I push motor and go havet with the lattice based math or post quantum, it's like every inch of that palace is filled with a guard, so I'm just not gonna get through it. So I think the term post quantum is a little confusing and deceptive. It's just a better math algorithm that can withstand these quantum attacks because they're just not prone to the large word size in a quantum computer.
Sure. So I think, um, you know, when it comes to post quantum, so we've established, NIST is established basically with crypto. You're starting to see a lot of compliance regimens mandating, um, post quantum, but more important than post quantum.
And post quantum is just the next algorithm is this concept of crypto agility. And that is, you know, now that, uh, we have a new algorithm, what if that fails tomorrow? How do I swap that out?
So in the past, you know, these implementations of cryptography have been very static. You can't change them. But this move to crypto modernization is really about crypto agility.
Meaning if I have a million cell phones and I need to swap out the algorithm, I can say I've got a threat. I can press a button and upgrade to post quantum two, or whatever it might be. Um, so that's the field we are in at q secure is basically crypto agility and orchestrating this new cryptography to any endpoint when the threat occurs, and monitoring and understanding where we're at.
And so I'd like to demystify post quantum better math, um, quantum computing, bigger word size. You know, the concepts are pretty straightforward, but how do you swap it out in real time? That's the question.
Yep. So look, I feel like we gave everyone out here a terrific, uh, you know, quick cursory, cursory costs on quantum Yeah. No charge.
Um, but let's now turn to Q secure. Sure. Yeah.
So you said you, you started the company was about four or five years ago. Yeah. Uh, your daughter is now the CEO I'm gonna assume she has a little bit of a background in quantum and computers As well.
She does, yeah. Um, well first let me do proud Papa with you. Tell us about your daughter, who's the CEO of background.
Yeah. So, uh, our, my daughter Rebecca, who's the CEO, she's a Stanford artificial intelligence. Um, so she focused on AI and kind of went into the quantum field because the promise of AI when you have a quantum capability, right.
So, just really exciting. Um, she was, uh, Forbes 30 and a 30 in quantum physics and quantum computing. She's on the World Economic Forum, the board for AI and quantum, and just really has carved out a really cool position for herself.
Um, and so she's, you know, and by the way, she's just a phenomenal leader. She's taken over the company and just a visionary and really leading us into kind of this AI driven, quantum crypto, agile world. And so, Uh, you must be very proud and you should be very proud.
Terrific story. Um, so let's talk Q secure. Yeah.
What, what's the mission? What are you guys doing exactly here in quantum and security? Yeah.
So, you know, I've had some exits. My ethos is really to create a safer future for everybody. We're at kind of this pivotal time when, you know, the internet was built with kind of no walls.
It was built to trust everyone. Scientists. Scientists.
It was, but so we're going through a transition where, you know, we've got to, we've gotta rebuild it in the image of that, you know, Alan's, Allen, we can guarantee Alan's Allen, we can guarantee, you know, Alan's talking to Dave and, and, um, so we've gotta rethink it. And so the future should be safe. We should be afforded, it should be a human right, that you're afforded a degree of privacy and control.
So income's Q secure. So what Q Secure does, um, we have an orchestration platform, fancy word for the software that basically orchestrates this cryptography and keys to any point. It can live in the cloud, it can live on a server, it can live in a air gapped environment if you're high security zone.
And then it orchestrates this crypto to any endpoint and you can manage it one single pane of grass glass. And, um, so that's what we do. In essence, we enforce, um, policy and then let you swap out broad slots of your network in real time.
Really easy to deploy. We've done like post quantum 5G, uh, in a couple hours. And, um, so it's a really easy way to set the stage for crypto agile networks.
Um, if you're in the networking space, there's a concept that SD wan, which is a network orchestrated Sure. Think of us as SD WAN for cryptography, and that we can orchestrate it across the network in real time. All in software.
Really. Yeah. That's fantastic.
Now there are customers that are more, uh, attuned Sure. I think is a good word. Customers that are more attuned to this kind of solution.
Talk to us about Sure. You know, the target customer personas for Q Secure. Great.
Um, yeah, we, we kind of cut our teeth, um, working with the government. Um, there's been a number of executive orders. One just came out a couple weeks ago, mandating post quantum cryptography and the path there that, you know, the deadline when they think there's gonna be a quantum computer that can hack RSA, it's coming in towards us quickly.
It was 2035, it's now 2030. Um, and this journey closing quick and closing quick. And so, um, it, it's a governmental mandate.
And, um, so there's real, if you're working with DOD or working with the government in that supply chain, it's mandated. Now what we're starting to see by verticals, and this is pharma banking, a lot of telco energy is now, there's a compliance regimen coming out where they're saying you have to deploy crypto agility. Like PCI, which is the credit card standards now has a requirement for crypto agility.
Um, we were working with a banking customer and they had the regulators in, and they said, the regulators have never mentioned post quantum. And the last time they were in, they were like, you know, you gotta be, you've gotta get this done. You, you.
And so they were like, boy, this is really creeping up. So I think what's happened is in this certified crypto, all these compliance regimens, Dora Fido, they're all saying you need crypto agility. And now there's kind of a mad rush in the verticals like pharma, energy banking, kinda The usual suspects for this, but for good reason, right?
Yeah. Uh, either mission critical or highly, highly, uh, regulated kinds of industries where you can't afford to have, you know, kind of New York Times headline kind of, uh, incidents happening. Right?
Yeah, Absolutely. I'll tell you something else, just again, my opinion. Yeah.
I think the speed that AI Yeah. Has tsunami, for lack of a better word, the tech industry Yeah. Has made people quantum shy.
If that's, that's, Hey, I said that word first. Quantum shy. Quantum shy call it because they, they, if, if AI can come on like that, so can quantum and though the government, you know, it's like secretariat coming around the bed for the Belmont stakes and pulling away from the field, they're saying 2030, it could very well be 2028.
It could be. It could be. And it's not the kind of thing you can turn on.
I mean, the, the, there's so much embedded infrastructure that would need to be updated. Upgraded. Yeah, quantified.
That's a good word. Um, you know, that we, we, we do need now is the time to get outta ahead. Right.
We could, yeah. Don't, don't let it, you know, for those people who, you know, AI came on, it was almost auto magical, right? Yeah.
Wow. What It is crazy. It's fun, you know?
Unbelievable. Um, yet it, it's not magic for those of us who are in a neural nets and, and understand how AI does what it does. Yeah.
Really putting one word in front of the other Yeah. It, where it's the same thing with quantum. I think we're seeing inch by inch, step by step, you know, how do you eat an elephant?
One spoonful at a time? Yeah. And we're eating the quantum elephant one spoonful at a time.
Yeah. So I, I, I do think people are starting to now feel the, uh, the, the, the, uh, the weight of it, you know, breathing down our necks a bit. Um, I've always asked friends of mine who are into the quantum field, what's the killer app?
Is, is it the cryptography piece of it? Yeah. But what are some of the other Sure.
Killer apps out there that you think quantum may unlock for us? Yeah, I think, I think at the top of the pyramid for me, um, is like molecular simulation. Because right now, if, if I wanna simulate a molecule, you know, we don't have the math or the computing capable to do it.
So if you think about the future where I can just engineer materials, I can engineer pharma, um, and I like to impute proteins, um, it, it, it's just fascinating what we're gonna be able to do. Um, there's quantum sensing, which is really hitting hard. And that's the ability to sensor environment at the atomic level.
'cause when you can kind of come down to the atomic level, it's amazing what you can do. It's almost subatomic, right? Subatomic.
Yeah. Yeah. And it, it is, it opens, you know, no, no pun intended, but it opens a whole new world, right?
It, The Whole world of, of Another thing on the, on the security side, one of the big threats we face right now is steel. Now decrypt later, our data's already being harvested. So, um, they're harvesting the encrypted data.
And in the past they've been like, if you have encrypted data, we don't care, but we should care because no born nation states are, are taking our encrypted data. They're ordering the, what do they call 'em? Hash hash balls or whatever.
Uh, yeah, I got the name for it. There's one foreign nation state that's speculated howers to 25% of the global encrypted data. When they have enough qubits to crack it, they can crack that data.
And if it's health records, if it's credit card data, if it's banking data, um, that points a little scary. The other big thing about quantum kudos can be revolutionary is quantum neural nets. And this concept of being able to understand the state of a neural net instantaneously, it's gonna open up this kind of super intelligence, this gateway to super intelligence FPI and super intelligence.
Yeah. Yeah. So I mean, your, your brain, your neurons function at very slow speed.
It's like four bits. But if you had a quantum neural net that the capabilities for artificial intelligence, it's really the real, It's a little, a little scary. Yeah.
Let me give you another kind of pulled right at it. Sci-fi out of a Hollywood movie, once you have the ability to create a neural net that exceeds the capacity of our brain. Yeah, yeah, yeah.
You know, immortality has been a, a dream. If you look at it, it drives, it drives religion, right? Yeah.
The thought of being able to live forever. We have this whole class of billionaires. It's not about the money for the, I mean, they have more money than their children's, children's, children's children will use.
But immortality is, is, you know, a a sure. It's the holy grail. Is it possible with a neural net to like download someone's mind?
Yeah. So we, I don't know if you've heard of Ray Kurt's wheel. Sure.
You know, the singularity. So right. Google.
Um, so this concept of yeah. Creating a, creating a neural net that, you know, when it's a quantum neural net, you know, right now the challenge with AI is it can only resolve the next word in a really sophisticated way. But when you add these quantum capabilities, it can then create things outside of the known knowledge stack.
Exactly. So I'm a, I'm a, I'm a believer in the singularity, which is the nerdy side of me. Right.
And that they will develop this capability that, um, you know, you can transcend into that. There's a joke about the singularity is that if you don't have a lot of money, you'll have ads in the sky when you're in the singularity. And Yeah.
Well, you'll have to pay for, right. You gotta pay for it one way or the other. But the other, the interesting thing about the singularity is that, you know, it was usually, Ray said it was 2050.
Now it's like supposed to be 20, 29. People are saying, we may already be reaching it somewhere. We May already be reaching it Somewhere.
Last thing. And then we gotta go. 'cause we're way over time.
I apologize, but I, I actually like this stuff. Um, marrying AI and quantum, we've talked a little bit about it. It maybe it brings on the singularity, maybe it brings on a GI super intelligence, but you, you marry that along with what we're calling physical AI robotics.
Yeah, Yeah, yeah. Super smart machines that have quantum capability and ai. Yeah.
Do we have to be afraid? Wow, that was a, I wasn't expecting that. Um, obviously that's a big topic right now.
There, there's a lot of thought concern, optimism, pessimism around that. Um, you know, I, I, I personally, so my personal belief is that, you know, the trajectory bends towards morality. Martin Luther King.
Right. Um, and uh, absolutely. We definitely need to be concerned, um, because uncontrolled, where it leads us is once it exceeds our capacity to understand, then, you know, it just, it's, it's an interesting thing.
But I think, I think, you know, our, our ambition is to create a safer future. I think if the ethos we bring to things collectively is that we wanna create a good outcome with this, then we'll bring that ethos to this discussion and create technology that really has a moral arc to it. And there will be a lot of problems along the way.
There. There certainly will, there'll be growing things. But I, I agree with you.
I, I, I believe in the goodness of, of humanity at a core level. And I think we will build in those guardrails. I love It.
So I think there's an opportunity to build unimaginably beautiful things. Absolutely. And that's why you're doing it.
You know what we didn't mention though, Dave, what's you secure? What's the website? com.
My email is Dave at q Secure. And feel free to reach out. It's a really fascinating topic and it is really appreciate this.
We're we're planning on doing a, uh, a virtual event on Quantum either later this year, early next year, virtual. We're gonna call it Quantum Leap of all things Quantum. But, um, we'd love to have you come talk about, maybe we'll have Rebecca come on too.
Yeah, she's really, really Good. Kinda like she would be, Would love to talk about Quantum. It's a pleasure.
You, It's great hanging out with you. Q Secure here on Tech Drunk tv. Go check 'em out.
We're gonna be continuing our black hat coverage, uh, in a little bit. So stay tuned. You're watching Text from tv.
Hey guys, thanks for the throw. We're here with Igor Debitor, who's CEO for upload care. And we're talking about the impact that video is having on website performance.
'cause I think everybody in his brother these days has got video on their websites, but I'm not sure we all understand the implications and especially when it comes to performance. Igor, welcome the show. Hi there.
Hi Mike. What is going on here? It does seem to me every site now has some video component to it, but do we really understand how to optimize the performance of those sites?
'cause there's a attacks that comes with a video and it seems to be in the form of performance, but I'm not quite clear that we even know how to measure that much less manage it. Uh, it's, the problem should, should be simple already in 2025, but it's not as simple as we want it to be. So everything regarding videos, it starts when people want to upload something.
And usually videos are recorded as more than devices. They wait a ton. So there are huge video files not compressed, and then you need to upload them somewhere.
So it's the first potential problem when they're uploaded. The people who build a website or platform, they want to compress them and ideally to deliver on a proper format. Depending on the browser, depending on the web internet connection or depending on the screen size.
If you want to deliver them to an iPhone, it's one resolution. If you want to deliver them at large display, it's a different game. And also you don't want to deliver them at once.
You want to deliver them chunk by chunk. You want to stream videos. And if you want to build all of that, it's still quite tricky nowadays.
And unless you build everything, every part, the videos takes long to download and uh, people spend a lot of time to just to view them. And yet video is core now to the website experience, even for the average consumer somewhere, not just professionals. And, um, do we really understand what we're doing here?
Because as far as I can tell, everything from your Google page rank now to, um, how many seconds people will give you before they leave your website all comes down to performance. That's right. Unless you optimize your videos and images and all kinds of media content, you won't win the race.
You will be less, your ranking won't be as good just because the website, it doesn't perform as well. Also, when we, people will still visit your website, they will definitely leave if they fail, uh, to view the content you want to show to them. So how are people managing this today and what should they be doing differently?
They're usually using some platforms. In some cases it'll be a combination of some open source software that you use to get these videos from users. Could be an open source file uploader, then you put them to some AWS storage, you put some Lambda functions or you put some platform to encode this videos.
And then you find and uh, integrate some open source video player just to render them and browser for people that, to view them. It's one way. Another way is to generate some code with lms, but basically when you generate all the code, you are doing more or less the same.
You find some open source code that was rewritten for your use case and you have to deploy and maintain all of this. Another way is just to use a redate platform. So there are several platforms available that help you.
They encode videos. There are in code videos, they're integrated with player and they try to deliver everything as a, in a proper format optimized, uh, for your connection, for your display. Uh, I'm CEO of one of these companies.
So how many folks are kinda, for lack of a better phrase, trying to roll their own here versus relying on a platform? I would say that we, we started, uh, about a decade ago and when we started, I would think that maybe 30% of people were looking for some readymade solutions. Other tried to build stuff by their own.
Now this has dramatically changed. People value their time, they want something that just works. They don't want to spend time building this from scratch or integrate some open source libraries because when you use open source or when you generate some code by LLMs, you still have to maintain this code.
It takes time. It's, uh, usually a burden for developers. So I like, uh, the joke, but it's not a joke.
It's a fact that our best customers are CTOs who tried to build some file management video and code and media and coding platforms. They do not want to do this again. Never.
Mm-hmm. Um, as you kind of think through this whole thing a little bit, um, how do I, is storage part of this issue? I mean, am I putting all this stuff in S3 buckets and trying to call it from the cloud?
Am I putting it locally? Am I caching on various websites? Is this part of the process and is that something the platform entirely handles for me?
Or how much do I have to think about this? Uh, when you look at the iceberg from the top, it looks very simple. You just place everything in S3 and this is it.
It's infinitely scalable. Price is decent. You can store any amount of videos you want, but the problem starts where you need to generate, uh, versions, derivatives of this, files for different devices, different resolutions, uh, encoded with different, uh, codex and then it just multiplies.
One way is to just generate versions for every screen, every size, and to store all of this. Another version, uh, how our platform, how upload care is built. We store the source file and we generate versions on the fly.
So if the video video is not large and we have different viewers with different demands, we generate versions for all of them. And you do not need to think about these versions. We just generate them on the fly for via requests by users.
And how does that avoid the performance tax we were talking about? 'cause it sounds like maybe I'm just shifting it to your platform or do you have some way of optimizing the, the management of those video files on my behalf? We manage them on our customer's behalf and we generate versions that are the perfect fit for the specific user who wants to view this video on the fly.
Um, you wanna explain a little bit about how that works? What's the magic behind that? The magic is that we have a set of algorithms that are quite fast.
It's not just a basic FFMP configured. It's something, uh, more advanced and scalable. Then we generate, uh, the version based on user requests and what we know about this user, uh, screen size, uh, connection, speed and other parameters.
And we generate this version and we deliver optimized video instead of delivering the source content. Yeah. And when you say algorithms, is that AI or a different form of algorithms?
Exactly. What are we talking about? Video and coding.
It's not ai, it's just a set of like normal, uh, algorithms because you don't want to use AI for everything. And also it's not that fast. So when you want to do deliver videos at scale, usually it's not ai, it's just a set of algorithms.
If you want to apply some more advanced, uh, transformations for videos, to change backgrounds or to do something else, you want to use ai. But it's not in real time. It's, uh, it works with rest API.
So you send the request, then you wait for a result for images, it's different though. So if you want to optimize images, even based on ai, it can be done in real time videos. There are just more resource, uh, not not effective resource demanding.
Are we in the age of AI creating more videos than ever? Have we gotten to that point? I know we create a lot of images, but how soon will most of the videos we're watching be generated using ai?
Plenty of videos are generated using AI and in advertisement. I think, I don't know the percentage, but I would say that maybe 30 persons or more are of advertisement videos are generated with AI or at least modified with AI because it's just quicker, simpler. And in many cases people do not see the difference or if they see the difference, they do not care.
So one point will websites start to keel over from the load because we're gonna create more video than ever. And if I don't have some sort of service to manage that, and I'm trying to do it on my own, isn't it just a question of time before I run into all the issues you just described. You'll definitely run, uh, to all the issues.
And when people think about building some file management, uh, file management and delivery platform, they think that it consists of about five, six parts and it's uh, tens of parts. It's 50, 60, maybe even one 100 parts because you built it, you built a file uploading part storage, part delivery part, and the player sounds simple. But then what about, uh, scale resilience of the platform security and changing cha check in files for NSFW content?
What if someone uploads some really dark stuff to the platform and start sharing it to others? People will have to think about all of this and that's why I wouldn't generate video management platform with LLM so far. And I wouldn't use some open source software just because it's too tricky.
Videos wait too much and it's so much easier just to use some platform. If I wasn't a CEO of upload care and I built something else, I would've definitely used the platform 100%. So you mentioned that there are other services besides yourselves, but one differentiate one service versus another.
I think it's just number of features for sure. Some features are more important for one audience, some features are more important for a different audience. Some platforms are meant just for videos.
Some platforms are meant for all kinds of media content, including videos, images, or even documents like PDFs whatsoever. Some platforms are targeted enterprise customers, some platforms are more open for startups and for people who just started building. So very different approach and one size doesn't fit all.
What is that one thing you see folks still doing these days besides the fact that they're trying to roll their own file management system here for videos. But, um, that makes you kinda shake your head a little bit and go, folks, we gotta be a little bit smarter than that. I think right now everyone is overly optimistic that they can generate everything using LMS and they're firing a lot of people expecting the same results or even better results.
In some cases it's a bit premature because generated code is not, it's just different from people can write and it should be proofread. Someone should understand how this works. You cannot just generate, uh, a lot of code.
Even if it works, if someone, something breaks, someone should understand how to fix it. So it does make things easier. We do use this in our day-to-day routines, but I think just to be a little slower with changing team structures, getting used to it, getting used, how to develop optimized platforms that are safe and secure.
Because one of the things is that, uh, all the LLMs, their trade using code that was available, it was open source or somehow this LLMs had access to some code. But the thing is, the best code, most of the best code is proprietary. So LLMs are not trained on the code that was created for secure, scalable platforms.
They're based on something that was available on GitHub all the way. And it's just very different. So you cannot expect the same quality of the code that use the, that was used to build Facebook or some Apple software.
You cannot expect to get it, get it written for your software because it wasn't public in the very beginning. So it's not used to train these lms. Alright folks, you heard it here.
You can of course build anything, but the question is, is what to do with your time and which is more valuable, the time you have to allocate to other things or the manual process of managing a bunch of video files that may not provide a whole lot of differentiated value to your endeavor. Hey Igor, thanks for being on the show. Sure.
Thank you Mike. All right, and back to you guys in the studio. Hey everyone, welcome back here to Techstrong tv.
You know, I was just a black hat last week and I, I didn't get a chance to see this gentleman, I'm glad we getting to catch up so soon after. Let me introduce you to, uh, Jens Wessling. Jens is of course Chief Technology Officer at Veracode.
It's been on here before, but not often enough. But Jens, it's great to see you here. How are you?
I'm doing great. It's good to see you too. It's been a minute.
Yes, it has. I think the last time we had yarn, you had just become CTO. Yep.
It was about a year ago, so Yeah, it's been A long, yeah. How, how's it, how's it been going? It's been going fantastic.
It's, uh, been doing a lot of research and innovation stuff and as AI and the market changes, there's been a lot of opportunities and a lot of discoveries and it's kind of part of what we're here to talk about today. God knows. God knows.
Yeah. It's, most people in our audience are familiar with Veracode. We've been covering Veracode, I think, since I started Security Boulevard.
com. But in case someone out here's not familiar, give them a little Veracode background. Uh, so Veracode, uh, specialize in, in securing software.
We're an application security specialty company. We do static scanning and dynamic scanning and security component analysis. And we're getting more and more into ai.
And we had the, the per automated security remediation product in the market and we continue to press on with innovation and doing new and interesting things. Excellent. Alright.
com and find it all there. Absolutely. Yep.
You know, yeah. Veracode's research team has always been a, uh, just a stellar part of the company, a stellar part of the industry. Uh, absolutely.
The annual security report from Veracode is, is kind of a, you know, a benchmark. You guys did a new report for this year though, and, uh, why don't you tell us a little about it? Yeah.
So as AI has taken a bigger and bigger role in our industry, it became clear and clear that we didn't necessarily have the answers to all the questions we wanted. And if you look around at all the reports people do on AI and security, depending on who produces the report and what you're asking, you'll get a lot of different answers. And a lot of the answers were sort of snapshot in time answers and not really what we're looking for.
So we really wanted to sit down and put together a report that would look at the state of ai, the impact that has on security and software and application development, and put the data together that we needed to make the, the important decisions that we needed strategically to move forward. And as we put it together, we said, this seems like it'd be a great resource for a lot of people. So we actually put a report together and released our results.
And we sort of, I think we shared that at Black Hat and we're here talking about that today. Absolutely. AB and look, this is, I think, a very timely report, right?
0, which is supposedly a little better with coding than its predecessor. Of course, Claude has a, a, a, well, it's not new anymore because if it's over a week old, it's not new anymore in ai. Yeah.
I came out on the fifth, I mean, that was whole six, well, six days ago we can call a new for another day. It's crazy, isn't it? Yeah.
It's, but uh, but Claude has a new version out Gemini keeps pumping out new stuff. We've got, you know, the promise of, of, uh, AI browsers coming out. But clearly the race is on in, in terms of what AI is best for coding.
Right. Everybody's talking about vibe, coding and coding and, you know, which AI is the best for it. Um, as we were talking off camera, I don't know if we're ever gonna have a definitive answer to that, but what we do know is there's a lot of people generating a lot of code using ai.
Yes. Mm-hmm. And, and while you know, I'm, I'm never one to say, oh, we need less code.
Right. More code's good. I guess, um, secure code would be nice.
And I think that's Yes, it Would be, that's where, that's where rubber meets the road here on this report. Yeah. That's one of the big questions we wanted to answer.
It's like, yeah. Is the code generated by AI Secure as a whole? And we look back through a couple years and clearly it started out a little chaotic and it's got a lot more consistent over the last year or so.
But what we've discovered is that they've sort of, there's very clear trends. So their ability to produce syntactically correct code has increased by leaps and bounds. Yes, you should expect it to be in the high 90 percentiles, but as far as secure code goes, sort of entered in around 60% Correct.
Code, which is not really where you'd like it. Right. Especially if you're producing a lot more volume of code.
If it's only right. Six times in 10 and producing something that's secure, you're producing twice as much code, much code, you have a lot more problems than you did a month ago. Right.
I mean, look, the only analogy I could tell you with that is when you, you know, forever and ever, it's been my dream that I don't have to type and I could dictate, right? Yeah. And transcription and, and, you know, even nine outta 10, which sounds great.
Well go back in and change every 10th word. It's, It's a pain In, it's a lot in the butt. Yeah.
Six outta 10 don't even bother. I'm doing that more than I am co. You know what I mean?
I, I just, it's not useful at all. Um, is it really that low, Jen? In some cases it's worse.
It, it really is that low. And we also evaluated it across different programming languages and across some of the most important cws that we run into and over time with sort of different models and different sizes and the size and the, the recency of the model doesn't seem to have a significant impact on its ability to produce secure code, which was a bit of a surprise to us. 'cause we expect it to move similar to how Syntax did, where it just keeps getting better.
But I think a lot of the code that's out there isn't by default secure. And that's what it's training on. So it's not really getting more secure than what you see in the wild.
Huh. Like, programmers aren't gonna check in code that doesn't compile. They can tell that right away, but they'll check in code that's not secure and maybe never know.
Yeah. You know, it's interesting, the last week while I was outta black hat, everybody there was touting some new study or another and there was such a discrepancy in dichotomy between them. Right.
You know, I, I saw one, I saw one, uh, study that said, oh, by having AI do the code where increasing code production, I forgot if it was 60% or some crazy number, 40%, you know, not only increasing produ pro code production, but making developers more productive. Yep. Right.
Then I saw another study that said, no, the fact of the matter is, using AI to generate code makes developers 19 or 20% less Productive. Yeah, I saw, I saw the same study and the part of the reason we did our own report, because if you look, I dunno if you can find whatever results you want out there, and usually it's someone that well Yeah. Interest in a particular result.
Yeah. Yeah. But, but you gotta ask yourself, look, if I have to correct six out of every 10, there's no way I'm more productive.
Excuse me, four out of every 10. Yeah. It, it's tough.
I mean, what we don't have is like, if the same situ, if you're given the same task to a developer, what would their accuracy have been? Well, that, that is interesting. Right.
And, you know, 'cause for instance, Microsoft did a a, a study, or they released some numbers about, I guess was over a month ago that this new product they have for, for diagnosing medical conditions was for x more accurate than human doctors. So I think it was like about 80% accuracy on diagnoses, you know, uh, for things out of like the New England Journal of Medicine, but real life di you know, human doctors were only 20% or 21%, something like that. So, you know, you had a good comparison.
Humans here, machine there, we don't have that with the 40 60 here. Right. We don't Is that in par for the course?
I don't know. I mean, what we do know is that whether humans are 10% or 90% accurate, you don't want 40% of your code going with security implications going out with a, a vulnerability in it. Right?
Yep. Agreed. Agreed.
It's humans. Someone's gotta do something. You gotta make sure that it's secure.
And that's sort of, AI is not fixing that problem for us. We still need to make sure that we're addressing the security issues and they're getting remediated. So here's something that I've seen though, in speaking to people with AI in security.
If you use AI to generate your code, you should have a human check it for vulnerabilities. If you use a human to generate your code, you should have an AI check it for vulnerabilities. What do you think about that?
I don't trust anything to scan for vulnerabilities that might occasionally hallucinate on me. Okay. Well, humans have been known to hallucinate, right?
I mean, usually drug induced, but nevertheless, but That's why we had security scanners that are trying to keep us all honest, that aren't gonna hallucinate and are gonna make sure they find all the issues and none of the false positives and sort of help humans do that job effectively. AG agentic AI could run scanners. Yes.
That's already going out. And we have products in the works for doing exactly that kind of thing. And I think that provides a lot of value, but you need the security expertise to train the agents to make sure that they're looking for the right things and doing the right things and returning the right results.
Fair. Um, yeah, it's just reading kind of the headlines here is you, you did this by testing over 100 LLMs. Mm-hmm.
So that sounds like it goes well beyond the frontier models that most of us are familiar with. What other, you know, LLM models, if you can talk about were, were part of this study. I mean, also keep in mind that we're testing all of the models from open a AP OpenAI, for instance, and breach release of chat GPT.
There might be three or four different models they release as part of that. They'll have their, their mini model or their nano model and their chat model and sort of, that sort of adds up to being quite a few of them. And we sort of grabbed a lot of the bigger open source models, um, deep seek.
So it is mostly the pro the frontier models, if we can call it that. Those are certainly the most important ones in there. And we made sure that all those were covered and we few others in there.
But yes, we weren't searching out edge case models that were hardly used to do the evaluation. This was, we made sure all the mainstream models were covered and evaluated. So in that 40 60 number, is that including like Chad, GPT 3 0 1 oh like older models where we knew Oh, yeah.
All the way back to weighted All the way back to one. And you actually see, when you look at the chart, they started out quite terrible at syntax. And then over time you see that they sort of aspen to, to giving really good syntax numbers and roughly 60%.
So we sort of charted over time. Then the important bits is we wanna know where the industry's going. Like is it on track to solve this problem itself or is it not?
And like obviously we need to know that right? As this application security company. So we did the evaluation and they, we hope they get better over time.
Like I think they started to focus more on security now, but we haven't seen it yet. And I think certainly with the volume of code we're producing, we're producing twice as much code, even if it's half as vulnerable as, uh, a software engineer would be still the same amount of security data going in. Yeah.
Yeah. net and Python and curiously, uh, three of the four did almost identically and one did significantly worse than all the rest. Give you one guess who it was?
JavaScript? Java. Java itself.
Java was only accurate about 30% of the time. 30 Oh yy y. Yeah.
That's pretty bad. That's pretty bad. You, it was pretty bad.
Why, why do you, why do you think that? So we have hypothesis, but I wouldn't say we know for sure, but I, I have observed that like Java is older than injection attacks and cross site scripting. It predates a lot of things.
And I think there's code out there that existed prior to us even knowing there were security issues and that's gets trained on just like everything else. Right. Well that, that I was just gonna say, that's really the issue, right?
Yeah. These, you know, these models are only as good as the code they're trained on. And so yes, If we only train them on secure code, they'd probably get much higher scores, but they train on all the code.
Why isn't someone doing that? Why isn't someone doing that then? Well, I would say there's two reasons.
Uh, one, it's relatively expensive to do that. So you'd have to basically fix every security vulnerability in open source code. You're scanning, and I'm imagining that's a, a tall order to do.
So they use what they have available to them and they're not, you know, evaluating it on security. If it goes through the system, that might be something they do in the future. I mean, I would, I'm sure they've asked the question, can we at least identify all the security vulnerabilities before we scan it so we know it's secure and what's not, and use that to train the models.
But based on the data, they haven't accomplished that yet. Yeah, it's interesting, and I've been saying this for a while, lesson I've learned in security in 30 years, is vendors, non-security vendors build in security into their products. You know, the a trustworthy computing kind of initiative when customers demand it.
Yeah, absolutely. And, And it could be, we're at a stage where, where quite frankly, the customers aren't demanding it just yet. I think we're starting to see that happen.
I think there's more and more pressure on LLM, you know, producers and companies are using LMS to do it in a way that's producing secure code because producing more insecure code doesn't ultimately solve the problems we have of making sure we have a, a safe computing environment and we're operating our business in a reasonable way. Absolutely. On the other hand, as you said, we're churning our twice as Mitch code and there's people I would guess we churning point.
Yep. Crazy. It is, it's crazy.
So I think things are need to change. Yep. Yep.
I, I know you guys were talking, or not you guys, but, uh, Veracode was talking about it at blackout last week, but the reports available on the Veracode site. Yes, it is out there and find it. com code linkable right off of that.
Yep. If you're able to find it from there. Um, as you mentioned, this is the first year you did this report.
I'm assuming there's, you said you're gonna try to do it every six months or so? Hopefully, yeah, couple times a year we can provide updates, um, probably when new models come out and people wanna see what the trend is and if things are moving, if there's something very interesting to report, and we may add more data to the report over time and, uh, sort of flesh it out from there. But this answered sort of the core questions we had, and it's been very useful in how we sort of target our research and our AI innovation work to make sure we're addressing the problems that are actually being produced by sort of modern AI based software coding principles.
Let me ask you, the $64 billion question for developers and development shops out out there who see this report, you think it slows 'em down down? No, I don't think you slow down. I was afraid you were gonna say that.
And isn't isn't that the, the security pros dilemma right there, man. Yeah, yeah, it is. Um, I know how it is.
I know how it is. It's, it, it could be depressing and discouraging encouraging, but it's unfortunately, you know, so let, let me, let me try to put a good spin on this. Knowing, knowing that, Jen, what do we do as security pros to, you know, sort of sticking our finger in the DY here, what could we do to make it better?
Uh, I think I'm gonna paraphrase Einstein when he said something along the lines of we generally aren't qualified to solve the problems we create at the time we create them, right? But I think we need to, to figure out a way to solve the problem. And I do think AI can also help contribute to that.
And I think we're looking at how to leverage it, not just to give you a fancy chat bot to explain all your problems, but to actually help remediate them, understand them, and get them addressed. Make sure they never currently code to begin with, and to make sure the systems are more secure fundamentally from the LLM out. And I think there's potential inis and agent to actually do things that actually enhance the security of, of our systems.
But as you said, I don't know that the demand has quite been there yet. Yeah, it will be, you know, it takes time to catch up and until then we keep fighting the good fight, don't we? We do.
We're trying, we're trying our best to hold the line against the tide. Absolutely. Hey, y thanks for coming on.
It better not be a year till I see you again on here, so I hope, hope not. Yeah, no, we'll make that happen. Um, sorry we didn't catch up a black hat.
As you had mentioned, you weren't there and I misfired in seeing my Veracode friends, but we will be in touch. Congratulations and good work on this report. This's a report that I think people need to see.
You know, thank you very much of what's going on. I appreciate it. And we'll speak to you soon.
Always a pleasure. Thanks Alan. Thank you.
S Weslake, chief Technology Officer Veracode, you're on text truck. We're gonna take a break. We'll be back in a moment.
Hi everyone, and welcome to the six five Summit AI Unleashed. I'm joined today by John Ek, chief Market Strategy Officer at Salesforce for an enterprise AI spotlight on how intelligent platforms are reshaping the way we work. John Ek, welcome back to the six five Summit.
So great to have you. I I always love the chance to sit down with you. Thank you, Daniel.
It's, uh, we have the best conversations ever, so I'm, I'm glad to be here. First of all, you know, John, you've got a big remit, you know, leading market strategy and more, uh, you've been around by the way, how long, just for everyone out there, how long you been at Salesforce? Again, just, just gimme that number.
I don't wanna give you the exact number, but it'll be 22 years in July. Do you have, you have one of those little hour tickers and I do, it's a countdown clock. No, no, I love it here.
So it's, you know, 22 years just seems like the beginning to me. Well, you, you've been there for a minute and you've probably been through, uh, many iterations, instantiations, updates, changes, transformations, acquisitions, expansions, contractions, market pivots, shifts, geopolitical ups and downs. You've been through quite a bit, but have you been through anything that's been as fast moving, transformational, disruptive, uh, as this sort of AI agentic moment?
No, and I thought it was, uh, you know, when I joined the company, there were only 300 people at the company, and I thought that was like super fast moving to, you know, move from on on-premises into the cloud on demand or SaaS, whatever it was called back then, but into the cloud. No, this is much faster than that. It's much faster than the internet, which I covered.
It's much faster than database technology. It's much, uh, it's faster than anything, uh, I've ever experienced. At the same time, the company's kind of more or less the same, you know, we're, we address the, the market the same, we have the same values.
We treat ourselves as a startup. I mean, there's well over 70,000 people now, uh, but the culture's very similar. So, uh, we're tackling it on, but it is coming much, much faster.
It's interesting, um, probably a case study in itself of how you go from 300 to 70,000 and keep your culture intact. Uh, but I can say, and I haven't been around it for 22 years, actually, John, if I go back that long, I'm still in college. I dunno if that makes me older.
Not To date me, not to date me, but yes, uh, uh, a lot's changed in 22 years for sure. But, uh, I will say there are definitely some aspects as I experienced, uh, working with and interacting with Salesforce that can be very startup and some of the kind of cultural, the ohana, the family, the sort of, uh, belief, you, you experience it every time, at least I do every time I go to Dreamforce and sort of seeing how the company interacts. And, you know, we're sort of professional event attenders.
John, you know, in my world, I, I probably, you know, make it to 70, 80 a year at least. Um, and you do get to see a lot of different cultures, but you are also a company that kind of catches things first. Um, you know, there's this kind of line I still like from the movie, the Big Short, you know, where, uh, the character that plays Michael Burry, the, the one of the great short sellers that caught that moment.
He goes, I, I may be early, but I'm not wrong. And then, uh, the guy responded to him and he said, oh, it's the same thing. But, uh, Salesforce has been early on many things, right?
On many things. Um, you know, it's, it's pivoted some things. Like for instance, it was very, uh, it saw the opportunity of ai, enterprise AI very early, and now it's had these different instantiations of it, uh, in an Einstein early on and Genie, and, and now you have Agent Force, which is kind of like this progression that went on.
But talk a little bit about, you know, kind of the AI journey that Salesforce has been through, through for yourselves, um, for your customers. Like, this has been a pretty massive pivot, but it hasn't been as fast for you as some companies you've been doing it for. I mean, it's been several years and AI has been really front and center at Salesforce.
Yes, and you're right. And we were early. Uh, it's not that AI didn't exist in a predictive way or rules-based way before Salesforce, but, uh, integrating it into enterprise apps over a decade ago, uh, we acquired a company called MetaMind.
We had done our own predictive research, of course, but when we acquired MetaMind, we started a research lab. We did a lot of work and research on, on ai, especially predictive, but we also started getting into data architectures, uh, LLMs, prompt engineering. We have a lot of patents on that.
That started, uh, years before chat. GPT was released to the wild, which is now just what, two and a half years ago? Crazy, roughly.
Um, that time is very compressed to me. Um, but, uh, yes, the, the, the research lab is an, an incredible amount of work and integrating it into the enterprise applications to make it seamless to the, to the customers who are using it and their customers who are using their solutions. And it, it is given us a, a huge competitive advantage, you know, in a way it doesn't even seem like a pivot.
Um, of course, from, of course, from the outside world, that's exactly what it seems like internally. It seems like a progression that's rapidly evolving. And because we had done this work, um, at in LLMs and Prompt Engineering, we were doing all kinds of things.
We were, um, we were doing like, you know, gene research out of the research lab and, uh, published in Nature Magazine several years ago. And if you call it a pivot, which I won't, um, it, it would be a very, um, quick evolution that started actually four years ago when we were getting our data strategies in order, in order to make AI make more sense, uh, into the, and, and more usable and actionable and embedding that into all the, you know, the platform that we have, uh, the platform and the clouds, you know, sales, cloud, service, marketing, platform commerce, all the, all the things that were traditionally called CRM. And when a Gentech came out and said, well, you know, the first instances that came out were copilots, which more or less added individual productivity, uh, but didn't consider a lot with business policy and, um, the bi the way businesses work.
So very good leapfrog there for copilots. But AgTech gave us a whole new era that we were perfectly well set up for. If I can capture it in a few, in a phrase, John, it's a bit about kind of this pervasive iteration is sort of why it didn't feel like a, you know, a pivot in so many ways because it was sort of the layering on it's very much what SaaS has always been, right?
Is the ability to sort of, you know, perpetual pervasively update and change things to add what is needed. And as AI has come to the forefront, you can do that in SaaS because you don't need to rip and replace, it's a feature. It's the, hey, the next feature was able to use a co-pilot.
The next feature was able to use some type of ML to better maybe understand churn risk or deal likely, you know, hood of deal closing likelihood. Um, but it keeps getting more intelligent and the amount of data that it's able to use keeps becoming larger. And as that data becomes larger, then it's about picking the right data that's gonna likely get you to the right outcome, that's gonna enable an agent to maybe perform the right task to do it concurrently.
But, you know, if there's one thing about Salesforce that you know, someone you know in, in your role and among your team really probably has to answer for in the future is gonna be, how does software change in this era? And agent force is a clear intent. You could say it's not a pivot, I would say it's a pretty big transformation of the company, though.
Um, you are going to get more horizontal. You have to, right? Salesforce has to say, look, we, we don't have every application, but we want our agents to be able to talk to every application.
How are you sort of thinking about doing that so you can become one of the most cri continue to be as a fair work, one of the most critical platforms that companies use day in and day out to run and make decisions in their business, both age genically and with humans? Well, you're kinda asking an existential question and well, as well as a pragmatic question at the same time, when Salesforce started, the business model was one of the innovations that we had along with philanthropic model, as long as delivery model, update model, um, being a platform model, being agnostic through API model, um, and, uh, and continuous delivery roughly three times a year for the product for, for 25 years. That would be the pragmatic.
We still do that, except it's more often more than once a month now, um, changing from model where, where it's per user per month, entirely predictable for you, you're paying for a seat and then you get access to the technology into a business model that involves more flexible pricing and consumption that, uh, consumption based pricing. So that's, that's one of the things that's, that we're doing. As far as the technology goes, the innovation goes, we obviously are still working on every single part of the business, whether it's better sales or better service or customer service or better commerce marketing across the board.
Uh, we're still, uh, we're still doing that. Customers still ask for it, still want it when enta comes in. It's giving actions and autonomy to the agents so that they can work on your behalf.
In order for that to happen, we had to do a bunch of foundational technology, including trust. So if you look at what the way that Salesforce announced the product lines we first came out with, well, you said Genie, but that, that was a short lived name. It's Data Cloud, um, and the data architectures.
The second thing we did, and the first in the agentic world was trust, a whole trust layer, which did toxicity, um, detection. And it, in order for a platform to be usable and valid within a business, and with business policy, it has to be trusted, otherwise they'll use it and get rid of it. So the trust layer was incredibly important.
And that was two years ago. And, um, and since then, the Agentic agent force, which was just launched in at Dreamforce, how many months ago was that? Eight months ago or something like that?
Um, Just yesterday, John. It, it seems like yesterday, again, time is, time is a very, um, elusive to me these days. But, but when we launched, uh, agent Force, which is the agentic part of Salesforce, the foundational parts are already being worked on.
Uh, you know, they're, they're never gonna be complete, but they were already already being worked on and delivered. So AgTech makes more sense when it's, you know, combined with the rest of the architecture. And when you look at, uh, the market, because you mentioned like we, we, we have to go horizontal.
Well, I firmly believe CRM is very horizontal. It's anything that touches the customer. Now, the customer may in, in the future involve an agent, but a customer, it's a pretty wide scope with a very large total addressable market.
But we can go even farther than that. And if I could like, show you right now and visually and visualize our agent force architecture, you'll see a very horizontal platform, and it's already being used in that capacity. I could talk to you about this all day, but the beauty of the six five summit is these are, these are sort of like rapid fire conversations, John, so I've got, uh, I got one more for you.
Um, you know, we assessed very closely the agent space and, uh, we also did some interesting work with, uh, with Salesforce on, on agent ai. We found that there was trillions of dollars of efficiencies to be gained. There's even more trillions of dollars in productivities to be gained.
There's tons and tons of question about what the future of work looks like, which that's a whole nother topic, but just from a standpoint of customers, since this is a, this thousands of enterprise customers watch the summit and they, they're, many of them are the customers of Salesforce or, you know, enterprise software consumers. They're trying to deploy this stuff. You know, I know at Dreamforce last year, mark was, he got up and talked about some customers that were already deploying agents, getting value.
What are you seeing now that you're eight months later, the product's further developed, you've built out more data, more trust. I, I'm really glad you brought up trust, John, because I think that layer sometimes is forgotten because of how fast we're moving, but, uh, we really need to make sure we're not spilling data and doing this. But like, what are you seeing in terms of POCs turning to, um, broader deployments, customers getting value quickly?
Um, how is that accelerating in terms of the, against the objectives that you have at Salesforce? Uh, it's accelerating so fast and it is changing, uh, daily. The customers seem to be aimed at efficiency at the beginning.
Like, how can I be, how can my workforce be more efficient? Sometimes that translates into can I let some people go and, and have the same, uh, capacity, same operations, and there's, there's customers still out there that demand efficiency. 'cause you know, they want it and they need it.
They, they have to manage to their, their own budgets and their own growth. What's changed is much more of a growth mindset is how AgTech can make the company scale broader, using the same people or maybe skills developing, you know, some, some employees to, so to have different skills and more strategic, uh, and it's much more growth focused. And it's also going into industries that are fairly broad.
You know, at Dreamforce, we, we said, Hey, here's a book publisher. They needed to, you know, they have this very streaky, you know, um, you know, life cycle in their year. Um, how do that, how do they just manage that and be great at it?
Well, that's, uh, that's one area we're seeing that when AgTech comes up. And the way we're positioning it is that customers are no longer looking at a particular silo, necessarily. They're not looking at just efficient customer service.
Now, we're our own use case in our own customer service. We have a huge ROI for ourselves in using agent force internally. And that's great, but it also is better.
And your report, your and your methodology was incredible. Thank you Daniel for that. Um, showing that this is a multi-trillion dollar, um, market, uh, as far as, uh, as far as the workforce is concerned, and the total addressable market is just increasing when people start thinking out of their, outta the silos.
And so that's the change. Uh, and only in the last few months. Um, again, agent force is only a few months old, uh, but we're seeing that very dramatically.
And, um, the total addressable market for agents, I think you identified is about 5 billion a few months ago. That was, it's probably grown beyond that. So it's, Oh, it's gonna good.
It's a, it's a, it's an opportunity that will probably land in the trillions just because of the cost takeouts and then the acceleration. John, I mean, look, our perspective is, there are a lot of sort of questions about how these things coexist with work and how we augment the workforce and how we then accelerate. But every, every industrial revolution has created more, not less.
And so sometimes as we get into those sort of, oh my gosh, this thing's gonna write my research for me, we realized that, you know, we automated things like social media posting and it didn't get rid of the need for contact creators on social media. Like, there are things that happen, but AI is incredible the pace that's moving. John, to your point, but one of the things I really wanna just is before we sign off here, is just, it's really great to hear that customers and enterprises are getting value.
We spend a lot of time focusing on these sort of consumer use cases, search, um, you know, uh, LLMs and ai. But the ability for companies to deliver service more quickly or to be able to fulfill orders and products more efficiently, or, you know, to speed up drug discovery to, you know, engineer better design cities, things that AI and agents and, and will help, is just very, very exciting. And of course, in the end, uh, we all have to take care of our customers.
So the best tools that enable us to be very responsive and supportive of customers building those long-term relationships. And it's great to hear, John, that Salesforce is doing the work, it's got deployed product in the field, that it doesn't take years to get this out there. And in fact, in weeks and months that companies can I, uh, employ and deploy this kind of technology.
John, I gotta leave it here. Um, we should definitely reconnect soon. Talk more about this.
I can't imagine a year from now at our summit where this will be at. Thanks so much for joining us at the 20 25 6 5 summit, Then you said that so perfectly. Thank you for allowing me to be here.
It's a true privilege. Thanks for joining us for this enterprise AI spotlight at this six five summit. com slash summit.
More insights coming up next. Welcome back, everybody to the six five summit where we are talking about unleashing ai. You're watching the semiconductor track, uh, where we explore the core technologies for the AI era.
And, you know, on the six five, we love semiconductors. I think we probably talked 30% just about semiconductors. They're so important, whether it's memory, packaging, foundry innovation, and everything in between.
We're opening up with a global leader in this space, Samsung Semiconductor. And as AI workload scale very quickly, memory has become one of the biggest bottlenecks. Not necessarily the GPUs, but if you don't have the right type of memory or enough memory, your GPUs or your accelerators are not gonna work as well as as you want.
And I'm joined by Paul Cho, president of Samsung Semiconductor. We're gonna discuss how the future a of AI is shipped by innovation and memory packaging and systems architecture. We know the six five audience loves semiconductor.
I think you're gonna enjoy this. Paul, welcome to the show. Thank you for having me.
Uh, great to see you. Yeah, it's just been what, what, a couple years here. I mean, it seems like the pace is just torrid.
We're moving forward. The industry is creating new innovations. And listen, I always knew semiconductors were amazing.
I've been in and around semiconductors for 35 years this June, but it took a while for other people to, to catch up. That's right. Yeah.
So it really is a historic moment here, generative AI and semiconductors. You can, you know, whether it's, uh, CapEx, whether it's, uh, market valuations, whether it's the buzz in in the industry, uh, on, on the use cases. Let me ask you, what excites you most about the direction the industry is, is heading right now?
Yeah, pat, uh, as you know, um, AI is evolving at an extraordinary pace from generative models in the data center to robots and autonomous systems at the edge. It is moving faster than any technology for it. Think about it, cars took 62 years to reach 50 million users.
Phones took 50 years, television took 22 years and chat g PT did it just under two months. It's incredible to think about what will be the next. So in just a few years, we've seen companies like OpenAI, Google Meta released powerful models, trained on massive data sets, some with hundreds of billions of parameters.
Model literacy has improved dramatically. The M MLU score, which is a key benchmark, has more than tripled in a few years from around 28% to 92%. So these advances are transforming the entire stack from compute to memory, to packaging, driving a need for faster time to market lower power, and TCO and highly customized architectures.
But what excites me the most is that semiconductors are at the core of this transformation. And Samsung has the right building blocks, memory foundry system packaging, and some selective logic design capabilities all under one roof. So we can help customers optimize for performance, efficiency, scale, and time to market wherever AI leads us to.
Yeah, It is amazing. com and I was part of the runup. In fact, I worked for the number one search engine.
And, and I also, you know, we saw the dot bomb where it came down. But, you know, uh, the, the difference between these two eras is that, uh, the green shoots of benefits, and whether that's with consumers and, and what they're, they're experiencing, by the way, uh, part and parcel to Samsung phones as well. Uh, you are the first to widely adopt AI in your phones.
Mm-hmm. Um, or, or whether it's the industrial edge, uh, or related to businesses where they're seeing benefit, let's say, uh, on the edge, uh, with their CRM systems or the ability to do ERP better. It's, it's pretty much everywhere, and it's pervasive, and there's benefits today, uh, a lot bigger than being able to buy dog food off the internet, uh, in, in the year 2000.
So yeah, that's what gets me super excited is not that this, you know, there's fads and there's trends, and this is clearly a trend. And, and if I look at the CapEx that's being spent, uh, today, currently with the hyperscalers, which I believe will move to the enterprise data center, which will then move, uh, to the edge. And, and again, it's not a serial process, but I'm just looking at the, the, the amount of chips, the amount of compute, uh, uh, required.
0, and we all said, Hey, the edge is gonna change overnight. Well, it didn't, uh, change as much as we, we we would've liked. It did.
But now we have a hundred times performance per watt AI at the edge, and I think things are gonna be dramatically, uh, different. I actually have a question here, right? Not a monologue.
All these, uh, events changes are so exciting, but we'll keep you dizzy. Yes. No, no, absolutely.
Uh, good for analysts, by the way, and analyst firms like mine. So, hey, I wanna drill down into memory. Okay.
You know, typically it was, oh, I have CPU compute and I can put multiple types of memory in, and they don't even need to be that loosely coupled. And, uh, but now, uh, with the, uh, efficiency and the performance required, memory is more important, uh, than, than than ever. Can you talk a little bit about the future of memory in a world where we're pushing the limits on performance power and even form, form factor?
Like, do we, do we reach a point where you're like, Hey, pat, we're done. We're here. We don't need to innovate anymore.
So we are not done yet. That's a great question. Uh, in fact, indeed, you know, memory poses the biggest architectural challenge in AI compute today as model sizes, scale compute grows exponentially, but memory bandwidth lags behind.
So bandwidth improves by tens of percent per generation, uh, while compute jumps by multi multiples. So that gap is widening. And at the system level, AI performance often depends on how efficiently you move huge amounts of data between memory and compute.
So the future of memory lies in bringing data closer to compute, because the real challenge isn't just bandwidth, it's power. And in the data center, power consumption has gone through the roof. 8 trillion parameters.
It took 1 48 gigawatt hours of energy. 5 million Tesla model wise. So with Samsung high bandwidth bandwidth memory, or HBM or increasingly custom, HBM is the answer.
So on package HBM dramatically reduces the energy cost of data movement. And with custom HBM, we tailor performance and capacity for specific AI workloads. HBM as such is core to our AI memory strategy.
We are delivering today and working side by side with our customers to build custom solutions that meet their specific needs for future applications. Future applications. Yeah, I, you know, it's been fascinating watching how HBM started, you know, a long time ago, a very high performance memory was GDDR that was attached to graphics cards, and it still is mm-hmm.
Uh, for that. But we needed something even faster with lower latency. And, and you invented, uh, HBM and HBM in many cases.
'cause I compare the different vendors of GPUs, any of the different asics that get connected, uh, many times power and performance is directly related to the capacity and performance of the HBM. Mm-hmm. I, I can tell you, there's one graphics card that outperforms another, uh, I guess they're not cards anymore.
They're more, you know, big blocks of silicon. Uh, that, because it has more memory, it outperforms, uh, on inference. So, uh, and, and as I talk to, uh, the folks who buy my research, uh, that I advise even on the ASIC side, right, who are, you know, whether it's, uh, you know, whether it's TPU or, or any variant of that, um, there are strategies are, are all around, uh, HBM.
So it's been, it's been amazing to watch. That's right. So I wanna talk about, uh, packaging and then we'll talk a little bit about, uh, uh, uh, Foundry.
Mm-hmm. I mean, the market need, uh, for, and I always like to say, really good markets have three competitors in them, uh, Foundry, and whether it's packaging, can you talk to me a little bit about the, let's start off with packaging, the importance of, of packaging. What does it mean to your strategy and how are you working, uh, with customers?
I have tracked the multiple Foundry customers that you've had a lot of mobile folks, a lot of industrial folks. You had Nvidia, uh, on, on graphics, and it's been, it's been fun to, fun to watch, Right? So, uh, packaging today isn't just about connecting chips to boards anymore.
It now defines the system architecture and must handle growing complexity and performance demands for AI. And HPC, the market wants packages combining logic chips and HBM and more of both. So that requires larger package sizes.
3 radical sizes. I cube e and I Cube R are being explored for even larger configurations to meet rising performance and power needs. Samsung is developing packaging architectures that connect high bandwidth, streamlets, and ensure power integrity.
And as for our customers, they need a strategic foundry partner that provides scalability, innovation, and long-term reliability, especially in the face of growing geopolitical concerns that are impacting global supply chains. So Samsung Foundry is focused on addressing these needs through a comprehensive technology portfolio that spends both mature and advanced process nodes backed by additional system packaging capabilities. So this flexibility allows us to support a wide range of applications from traditional mobile and consumer devices to automotive and emerging ai.
We also understand that supply chain stability has become a critical consideration here for businesses today. With FS in Korea and Texas, we've developed a globally distributed manufacturing network that puts us closer to where our customers are and helps them minimize risks. So with our US fab investment in Texas hitting advanced node milestones and a robust ecosystem of design solution partners, we are building momentum in Foundry.
Yeah, I love to hear that. Texas Go Texas. Go Texas.
Uh, and go, Austin. It's funny for my, from my home, I can see the, uh, Tesla Gigafactory, uh, saw it being built, and I can see it, uh, in operation every, every morning that I, I wake up. Uh, I'm, I'm a little bit too far away from, from your facility here, but, uh, I hope to visit it someday once you start, uh, cranking out wafers.
Isn't it funny, uh, packaging. I mean, 20 years ago when I was at a MD and I was knee deep in products, uh, we probably spent 95% on the wafer and about 5% on the package, you know, of resources. You know, it was kind of, let's throw it over the wall, uh, here.
But, you know, as node shrinks, um, as new technologies have become more difficult, uh, and architectures have become more distributed, particularly on the larger SOCs, packaging has become a first party citizen because squeezing out every ounce of performance per watts and cost, getting the right die done in the right process, right? Everything doesn't need bleeding edge. It just, it just doesn't.
Uh, and pulling this together has become a, a strategic, uh, advantage, um, on the geopolitical stuff, I, I deal with the CEOs of, you know, your customers, your potential customers on, on a weekly basis, and it is very much on, on, on their, on their mind. And I don't think, regardless of whatever tariff, wherever we're gonna wind up with tariffs, uh, I think in the, in the end, just, it, it, these, these, um, chip designers want to have a diversified manufacturing port portfolio. They don't want all their eggs in one basket.
They don't want all their chips being done in a, in a specific, uh, country. And competition is good competition, it breeds innovation. Uh, it typically lowers the overall costs.
Uh, so it's always a good thing. And we need three strong players, uh, in wafers and, and, and in packaging. So that, that's my sermon, Paul.
I like that. So, uh, a surprise, it's a surprise for me to learn that you've not been to our Taylor campus. Not yet.
I was at your, I was at your grand opening party that was, uh, about 10 miles away. But, uh, I am gonna, you know, get in a car as soon as, uh, as soon as I get that invitation, and, and we'll, we'll meet you down there, Right, pat? I, I'd love to, uh, have you there.
Um, you know, uh, I envision the most beautiful, most beautiful semiconductor fab complex and campus in the world. Right? In Texas.
Part of So exciting. So exciting. Uh, Paul, is there anything, um, else you'd like to share, uh, with our, our audience here?
We're, you know, our audience is all the way from, um, enterprise IT to investors, to tech aficionados. Uh, about half of our viewers are deep into semiconductors. Is there anything else you'd like to share?
No, I think we have a lot in common, but the most important keyword today for everyone is AI and, uh, you know, Samsung Semiconductor. We are trying our best to be part of that, not just a part, but the most pivotal to role that we want to bring to the market and the ecosystem. And when it comes to memory, it's the high bandwidth, low power, uh, memory architectures that we, uh, bring on the table with the customization capabilities, uh, that we also bring together so that, uh, our customers can, uh, have their own custom solutions that will serve their workloads in the best way possible.
Because performance, power, reliability, manageability, all those things, you never want to miss any single of them. And when it comes to transistors and integration, we are focusing immensely on honing our advanced logic process, technologies and, uh, system packaging capabilities. So you bring all these two things together, what ends up is you get the best product and the best time to market.
So that's what, uh, we want to, uh, have of, and offer to our customers. I think it's a great way to close this. Paul, I want to thank you, uh, for coming on to six five.
We'd love to have you on again, to just drop these truth bombs, uh, here. And, you know, Samsung semi's been a little bit quiet lately and people wanna know, Hey, what's going on there? So thank you so much.
Yeah. But I'll be happy to come back anytime. Excellent.
I appreciate that, Pat. Thank you. Thanks.
So, hey, thanks for tuning into this kickoff session for the semiconductor track. Uh, Paul did a great job. Hopefully you learned a lot and you disclosed some stuff to me that I wasn't aware of.
Maybe I wasn't paying attention the first time, but, uh, it was very informative for me, and hopefully you found that as well. Memory is not just a component. HBM is core to everything.
Uh, foundry and packaging are, are as important as you know, in the six five audience that we've discussed here. So we'll be hearing from, uh, other folks across the industry as we can explore the chip systems strategies, powering the next generation of compute. Check out the full lineup on the website.
More insights coming up next.