Techstrong TV – December 11, 2024
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Good morning. Is China cutting off its nose spite its face? Are they dropping outta the GPU game?
You're watching Textron Gang. Hey, good morning everyone. It's a Shimo for Techstrong and Tech strong gang.
Thanks for joining us on this lovely Wednesday, right in the middle of the week. We've got some great stuff to cover for you and some great people to cover it with. Let me go over it.
Let me introduce you to our gang for today. First of all, he's back out on his perch overlooking Silicon Valley. He's the czar there after a short stint in Las Vegas for reinvent, where we got to see, actually see him in person.
I felt blessed to be around royalty, our own John Schwartz. Hey John, how are you? Hi, Alan.
It was great to see you in Las Vegas. You, Mike, Mitch, uh, the gang assorted individuals, Daniel Newman. It was great.
It's, but it's better to be back here. Yeah, well, you know, from where you sit, you can see from miles and miles and miles as the who one sit. A Little hazy today, I really can't see that far.
It's a little hazy, but, uh, I'll do my best. Um, and then we've got two people joining us from the great state of Texas. Uh, first of all, he is a analyst with Futurum Group and one of the co-founders of Visible Impact, our own Guy Courier.
Hey Guy. Welcome. How are you?
Very good. Good to be back. Uh, uh, well, actually, I didn't go, you, you, you, you, you went somewhere.
Yes. You did something. Maybe even more important.
You did your civic duty by reporting in for jury duty. And, and for those of you out there who know, you know, try to skip it or get around it. It's, it's one of the few things as a citizen that it's called on us to do in this country.
And Guy, thanks for doing your duty. We salute you. Well, thank you.
Um, but it's good to have you back and I'm glad you didn't get on a long trial that was gonna have you out for weeks or months. Also, joining us though, from the beautiful city of San Angelo, Texas, right out of Abilene, it's our editor for, uh, tech Strong AI and digital CXO and so much more. Amma, Amanda, Rini, Ani, Ani, Ani.
What of these days? We'll get it right, Amanda, but I always try. Amanda.
Ani. Amanda, good to see you. Yes, happy to be here.
Thank you. Okay. And then last but not least, still licking his wounds over a major loss of personnel for his Yankees, our chief content Officer, Mike Ard.
Hey, Mike. All right. Uh, I'm just counting all the budget dollars that the Yankees freed up and maybe we'll just buy like 20 other players.
See how it goes. Well, you know, I did the math. It's really not 20 other players, but I think they can get three to four top line people in here for that.
Right. Uhhuh, maybe one starting pitcher, a first baseman, and either a second or third baseman and an outfielder. Alright.
I think that's what it's gonna take. And the price of meds. Tickets are on the way up for sure.
Yeah. Who cares? No one goes anyway, but, and we also need a bullpen.
We need to do some bullpen additions there. Not necessarily. I mean, if this guy weaver's gonna be, his clothes are great, but we need some setup med for him.
All Right. In other words, we just need a team and we're good to go. All right.
Well, we got, we got all off season. I, I've got, I'm confident anyway, enough baseball, let's turn to the matter at hand. You know, trade wars make for strange bedfellows and, um, in the latest salvo in the American Sino trade wars, you like the way I used that word sino instead of China, because that was very sophisticated on my part.
Um, China is opening up, and you don't hear this from them that often, a formal antitrust probe of Nvidia. So they're not banning Nvidia right now, but the, you know, firing a, a broadside salvo that they're looking into potential antitrust probes of, of Nvidia. What does this mean?
What, what's the real deal behind it? I think we've gotta go to the, the, the eye in Silicon Valley here and, uh, find out, John, this is one of your stories, isn't It? Yeah, yeah, yeah.
It's hard to keep track. There's a lot of moving parts in the us um, Sino relationship. Um, so China's issued this very bizarre press release.
It was sparsely worded, it was very vague. It's the state administration for market regulation, which I'd never heard of before. It said it is gonna focus on Nvidia for allegedly violating China's anti-monopoly laws.
They're looking into the nearly $7 billion acquisition of Mellanox Technologies as a, a network in data transmission company. Um, it, it's interesting, it's kind of almost a tit for tat uh, timeline. If you look at it.
I think last week the US imposed its third, I believe it's it third crack down in three years on China's semiconductor industry. So they're expanding, curbing the exports to 140 companies that include ship makers. So China in turn has taken this action, uh, this is significant, especially for Nvidia, because it literally dominates the AI chip market with more than 90% market share.
And, um, it's gonna have an impact. And this is going to be something that other companies in this region are gonna be looking at, especially because in a sense, NVIDIA's kind of caught in the middle between these two countries. And in, in effect, it's actually had an impact on the business.
I, I believe 17% of Nvidia revenue through the last 12 months through expected through January, is down to 17%. In China, it was 26% two years ago. So again, there are other things in motion that are happening between the US and China.
We have the upcoming tariffs from the Trump administration. We had this whole spying stealing data from major telecoms. We've got the TikTok ban, which is headed towards January 19th showdown.
It's just a lot to, to chew and mull over. And, um, it's created, uh, a lot of tension, especially for the companies out here and how the US and China Sabre rattle one another. This is getting hot and heavy quickly.
They also put out a, a fleet of ships yesterday and an unannounced exercise that, um, or actually two days ago, um, that they just wanted to show that they could surround the island of Taiwan and cut it off. And, you know, usually it's the kind of thing that they would, you know, send a signal that we're gonna go do, but this time they didn't. So this whole thing can get hot and heavy quickly, You know?
Yeah, yeah. There's also always, China also banned the exports to the US with the, these chip materials like Gallium, German, Romanian, et cetera. The rare arts.
Uh, Rare arts. Yeah. Now, luckily we've been finding a lot of deposits right here in the US of some of these rare earth things like lithium and, and stuff like that, that will make us less dependent on China for these things, though, China's also trying to buy it up.
You know, like Brazil has some rare earth resources that China's been trying to take control over. Mike, I, I, I wanna just, 'cause you know me, I'm a peacemaker. I just wanna ratchet it down.
I don't think the Nvidia antitrust is necessarily related to the military actions around Taiwan. I think these are two very separate things as Chinese views the world in the Chinese view of the world. Um, I think, no doubt they're involved in the chip wars with the US or, and it, there's an argument to be made that we started this one, right?
We, we threw the first stone. Um, so there's this chip war going on, but that's not, that's separate and apart from that longstanding position that Taiwan is part of China, and sooner or later, you know, John Willis has said 2027 is what numbers he's heard. At some point, something's gonna happen there.
And then depending who's president here and how we're going to deal with it, we're either going to, you know, go to the mattresses over it or we won't. But for this particular thing, this is classic Chinese saber rattling. Does anyone know, does China even have anti-monopoly laws?
Or is that just something they put in by fiat? That's A, that, that's a really good point. I've Never heard of That.
I mean, I, I I've never heard of it either. Me, either. It was in this organization that, you know, these, these, there was another announcement among a bunch of, uh, associations where they said that US chips are a threat or it's not safe to use them, so please only use locally.
Yeah, I know. Well produce Chips All these on these, but yeah, I mean, let's hold, let's be, let, let's be realistic here though for a moment. Until there's a viable alternative to Nvidia GPUs.
Do you really think China is gonna stop importing and using Nvidia GPUs for their AI uses and risk falling behind in the AI race and FW and FW and, uh, go on better? I guarantee you, there are people rubbing their hands in glee in Singapore and Korea and all of the east, you know, the tigers of, uh, east Asia who trade with China because they're gonna be buying up as much Nvidia star, uh, uh, Nvidia, you know, product as they can. Because you know damn well, China's not gonna stop using Nvidia.
They may, you know, for public purposes, slap them as a monopolist and say, we're not going to import them directly. And the, the gray market will, will blow up with Nvidia ex imports into China from places like Singapore and Malaysia and Indonesia. And, you know, other, the Philippines is not so friendly because of China's military posture in the South China Sea.
But, you know, they're not gonna stop using Nvidia chips. They're not, and they'll pay for them. They may pay More.
I don't, I don't know, Alan. I I, I appreciate ratcheting down the temperature for sure. Uh, but, well, first of all, China does have extensive antitrust and anti-monopoly laws.
I think what can confuse us is that they don't really apply to state owned enterprises. And there's a lot of state ownership, uh, majority ownership, or at least minority ownership and state interest in a lot of the, you know, private, um, private, uh, companies in China. But I think that to, to my mind, this, this is a replay of the oil wars and battles, the late, uh, 19th century for example, or early 20th century.
It's just that the material now is not quite as fungible as they say. You know, oil is, oil is oil around the world, but chips may not be, chips may not chips around the world. I do think that China's plan is to, um, manufacture everything itself.
They have the, the talent, the knowledge, the intelligence, the educational system and the materials to do that. And they have the long view as well. And they showed this with aircraft, for example.
They've shown this with the space industry. They've shown this with military. Um, I think that they are going through severe economic difficulties right now related to, uh, you know, how they've run their economy in their own real estate bubble and things like that.
And, um, they have to deal with like every nation with, uh, uh, making sure that people are happy enough, like domestic concern, people are happy enough, prosperous enough, uh, not to challenge the status quo. Every nation has to do that, even democratic ones. So I do think that this is, uh, a continuing escalation that's gonna reach a peak at some point.
Um, there, it's not just the US and Brazil, Australia has the same rare earths, it's just more expensive to get them. And uh, uh, you know, it's some point that cost hits consumer pockets in the Western countries. It can, you know, cause inflation or inflationary issues, like all the same classic stuff going back hundreds going back centuries.
China wasn't really in the oil wars though back then. A couple of things here. The opium Wars.
Well, yeah, there was different actors in the oil wars, but it's the same phenomenon. Uh, or similar phenomenon. Anyway, I don't wanna overstate it.
I think there's a couple other factors at play here. One is we're finding those metals, not just in Brazil, but in Wyoming and Japan just found a huge mm-hmm. US Has Some Yeah.
Thing. So I think that will become less of an issue. I also think we're gonna be less dependent upon GPUs to train AI models as the next generation of AI processors come around and where they're gonna be made will be the issue.
And then we're seeing TMSC, I think that's what they're TSMC Yeah. Is going by what they're saying. They're now licensing their manufacturing technology.
So we can make those GPU someplace cells. 'cause the one issue we have is that all that stuff leads back to Japan. I mean, to, uh, Taiwan.
Taiwan currently. But let's be clear, there's no way in God's green earth that the United States is gonna put boots on the ground to protect Taiwan. And the Chinese know this, and we have signaled this left, right and center around the world.
And you bet that they're gonna push hard in the next couple of years. 'cause they're gonna be like, you know what guys? You may think that the island of Taiwan and GPUs are not connected, but in their mind, they're very connected.
I'm not so sure. Sure. That we don't think the moving of, I'm sorry, the moving to manufacturing on shore, like TSMC, onshore meaning on, on, or us, I think Arizona or I think it's gonna be in the us Yeah, yeah, yeah.
Uh, the CHIPS act in general, like, it's interesting how the pandemic showed us how dependent we are on choke points in world supply, including chips. And so I agree with you, Mike. I I think that the US is, is, or at least, you know, under the latest administration in doing everything, it can't to, to it strategic dependency on choke points everywhere, including Taiwan, such that, um, if and when the day comes that China absorbs peacefully or otherwise potentially Taiwan, just like it did Hong Kong, that it has this little impact on western economies as possible.
At that Point, guys, I think you're operating on old information. Let me bring you up to date. First of all, the, the, the CHIPS factory in Arizona by, uh, Taiwan manufacturing has not progressed very much at all.
And it's kind wallowing. It's not even close to being ready. But Alan, there was a report, I think there was a report, I'm not sure how valid it is that NVIDIA and TSMC might have, might try to, Might Mike, there was a report.
They might, they called out a rumor, right? There's also a rumor that the Trump administration will do away with the CHIPS act. And then where are you?
Nowhere. There's also a story, not a rumor that TSMC has said they are not going to export or license their latest two nanometer technology anywhere outside of Taiwan. And I'll tell you why they're doing it.
'cause they're not stupid people. In order to get the US and the West to protect them against China, the the US isn't gonna do it outta the kindness of their heart. They're gonna do it because there's some strategic asset there.
And if that strategic asset is the technology and knowhow for the latest generation of chips, GPU or otherwise, that makes Taiwan strategic. And if it's, Or it just makes it, or just makes it really important to get that technology out of harm's way. And if, and if you, your TPMC, which is Taiwan, don't you re don't you think they realize that if they keep that there, it's like it, it's an insurance policy.
Or we may just say, you know what, we're gonna move off GPUs and say we won't be dependent upon that and we'll use other processors. So there's other ways to go. We've seen AWS is out touting its processors that have nothing to do with GPUs for training AI models.
I don't know if they work better or worse than GPUs, but there's a lot of folks who are saying, you know what? GPUs are expensive and hard to come by in the first place, so maybe we don't need 'em. What Are some of the most viable companies that could step up?
I mean, it seems Nvidia really has the, the market, but what are some Of the other most viable, Well, a lot of people are designing their own GPUs, including Amazon. Google is bett both sides of this thing. They're gonna bet on their own GPUs.
And this titanium thing is an alternative. Google and Microsoft have similar playbooks. So, you know, all those cloud service people went out and said, we're not gonna be dependent upon external suppliers because of this very issue.
So I think, you know, The, the problem is though, and, and frankly it's the same problem China faces in, in making their own domestic market for these things. There's going to be a window where you don't have it. And in something that is deemed as strategically vital is AI progress.
Who could afford to to go through that desert before you reach the oasis? Right? Who could afford to, to make it through that window?
And that's the issue. That's the issue. I think we're inadvertently, um, uh, uh, combining a design process.
It's fab though. TSMC is the world leader in process and fab. Not, I mean, and they, they, they certainly cooperate and work with video.
They work with a MD I'm pretty sure they work with, uh, Amazon on design. But the design is portable around the world. Um, process is actually not just Taiwan, but I think the Netherlands, if I remember right, is, is a, is the world's leading, um, manufacturer of, uh, fab equipment.
And then there's the fabs and the fab, the fa fa fabrication, the fabs themselves. That is really the choke point right now, more than anything else. Uh, uh, you know, I think and, um, the push to build fabs, you know, on US soil in Europe and everything just takes a long time full of potential problems.
Um, and that's why it remains a choke point. So maybe less of a problem and less of an issue around Nvidia, specifically if there is enough fab supply, which categorically there, it's not right now. So We shall see.
I mean, this is, look, this is global trade in the 21st century. And we, we'll see how that plays out. Um, let's take a break here on Textron Gang.
Let's come back something more domestically focused. Looking at AI in healthcare. You're watching Textron Gang Modernize your business to fuel innovation and elevate customer experiences with the builder community.
Hub AWS and its partner network provide essential tools for transforming applications and infrastructure to fully leverage the cloud. Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably. Visit the builder community hub to learn more.
Folks, we're back. And I guess, you know, if you've been under a rock, you're may not be aware, but there have been some tragic events in New York City involving the CEO of United Healthcare, and none of that is, uh, excusable. But it has led to this conversation about what is the proper usage of AI in healthcare and in claims, because there are folks who are concerned that, um, issues are being not properly investigated.
'cause the AI is essentially just denying everything. And this is creating a lot of angst in the world. Uh, social media is full of this stuff and people are starting to complain about healthcare vociferously.
Everybody's been complaining about it for a while. But John, I know you looked into this and wrote a story about what's going on with healthcare. So what's your assessment of their usage of it?
'cause, you know, one thing that comes to mind is lack of visibility, Right? Right. So, I mean, the only thing we really knew about healthcare and AI was there was a lawsuit that was filed about a year ago, November, 2023, that pointed out it was a class action suit out of Minnesota.
A couple of customers, patients, families found that there was a system in place that the murdered CEO had approved of, that automatically denied claims, basically from sick, elderly customers. And in a sense, I started calling around other healthcare professionals and folks I could find. And they were telling me that what UHC did was not unique.
It's actually quite common, the use of AI to escalate denied claims. And it's kind of sparked this debate on the ethical use of, of ai. And one of the things that someone told me that was really interesting was that there's a, there's a, uh, phrase or a syndrome that they're talking about in the healthcare industry about the use of AI called the slow motion Hal Effect.
Now, I know you all probably are familiar and know extremely well the movie 2001 of Space Odyssey. There's a scene in the movie where Hal, the evil computer methodically turns off the life life support systems of the hibernating astronauts, which they are killed. This is what people in, at hospitals and doctors are saying about the insurers, uh, that were kind of in this, this, this lightning rod issue of, of intersection of AI and healthcare, healthcare transformation, where, um, it's leading to a lot of bad results.
And this, in a sense, in a weird way, this murder has kind of opened up this whole debate on the healthcare system, and even if you want to go deeper into class warfare. But I found it, I found it very interesting. And when I talked to the healthcare professionals, they said, everyone's doing this now.
They're using this health, they're using AI in a sense to deepen their profits and, uh, nullify or discourage claims. So, um, I just found this, this whole thing really fascinating, and it opens up a whole can of worms about not just our healthcare system and how it compares to the rest of the world, but also with, uh, struggles in, in class warfare. So I Would like to point out one thing about this, though, right?
We are conflating a workflow and a process and a strategy with ai. And that strategy existed before AI came along. AI may have amplified it, but it did.
Yeah. Though our, the process didn't existed before AI came along. So, you know, we're kind of like pointing a finger at ai, but I'm kind of looking at, I'm not saying that it was a flawed system to begin with.
It's been a source of frustration. AI in a sense has just kind of turbocharged, uh, the de the percentage of denial of claims. I think with, um, UHC, it's cited in somewhere in the lawsuit, it went from like 10 per 11% to 22% in certain instances.
Yeah. And if so, very few people fight back and appeal the claims. They just, they'll pay out of pocket.
It'll just give up altogether on carrot. Sorry, I'm Amanda. So I got a few things here, John, with what you said.
I've got some issues. Number one, the how 9,000 computer was not evil. I don't even know if it computer can be evil, but as we saw in 2010, this follow up film, there was some problems with, oh, that was a terrible movie with circuits and programming, but it wasn't evil.
Right? Hal 9,000 was a great computer. Dr.
Chandra kind of restored it, right? So, but it's a microcosm for this, let's not blame the computer for the evil of men, right? This was a corporate policy right out of a John Grisham model, right.
To deny cases, to deny claims, and until people fight back. And it goes to the whole for-profit health industry, health insurance industry, because they certainly don't give a crap about your health. They care about their profits.
Now that being said, I, I'll be honest with you, it made my stomach turn watching my Facebook. Yeah. I'm on Facebook.
I'm a boomer. Um, watching my Facebook feed of, of people applauding the death of a man being showing on, on Elon Musk's ex, the, the, the video footage of the, of this guy getting killed is not something I think is appropriate. Right.
That video should not be being shown on there. The hell with freedom of speech. It's wrong.
And anyone who applauds the death of someone like that getting shot in the back deserves no better themselves. It's wrong. I was chagrined when they came out last night.
I'm using some big words today, huh? I was chagrined when they, the news came out last night that the, the person they brought into custody is not who you think it would be. This is an Ivy League UPenn, educated data engineer, a techie, nonetheless, since when the techie shoot people we're, we're pacifists, we're good people.
We don't shoot people. I don't care what the guy did, He was also from a wealthy family, right? Yeah.
Not, and he was this, this very highly regarded private school. I mean, it's just everything. So it came out, he wouldn't Overnight that, um, or at least yesterday, um, that he was also somewhat estranged from his friends and family because they hadn't heard from him for a while.
Apparently he's been suffering some issues with back pain for a long time. And he was exhibiting a lot of the sin symptoms of somebody who, you know, might do this even Though he, well, he was a big fan of the Una barma, una Barma, whatever that kki Yes. He posted on good reads, his, his thoughts about the manifesto.
He read through it thorough. Um, but, but nevertheless, I, I'm not saying the, the CEO of United is a saint, nor is he the devil. He certainly doesn't deserve to get shot down dead in the streets in Manhattan in the back like that.
That's just, and anyone who condones that and makes this guy into some kind of folk era, you're twisted. That's twisted. And it has no place.
Um, And especially one man, the CEOI think people don't realize one man doesn't control everything at the company. I mean, he had just come into the company recently. No, he's been at United a long time.
He's been CEO just three or four years, but he's 17 years. That's what I meant there something there. You know, I'd hate to see things someone wants to shoot me for something our editorial department did.
But that being said, let's Long silence there for a second. Yeah. Well, we were, We were thinking through some examples in case you didn't realize it.
But let's, let's come back, let's come back to focus on AI and healthcare. Right? I, I put forth the proposition that this isn't AI in healthcare.
This is ai and he insurance, AI and healthcare is gonna do great things to make us healthier and help us with our health. That that's a that's an excellent point. Yes.
Right. You know, I, my mother a surgeon, people, yeah. My mother was a surgeon in, in, in New York City.
She was trained as a, as a trauma surgeon. She worked in emergency rooms, um, and as a women's health surgeon and, uh, at a very prestigious, uh, hospital system in, in, in New York City. And, um, right around, uh, the early nineties or something like that, she was called in by her new department chair, a surgeon, um, and, uh, uh, for a meeting with his new controller, the finance person, um, who had her new compensation plan, which involves something like, here's, uh, here's, you know, one quarter of your base salary, and here's how much money we expect you to bring into the hospital, and here's your share of that money to balance it out.
This was a, someone who didn't go to business school, someone who went to medical school, someone who did not get into medicine for the interest of, uh, um, making money, which a lot of folks did at that time, still do. But because she wanted to provide healthcare to people who needed it. And, uh, the immediate result was, uh, a loss of her personal revenue, um, and a six to a 10 year period where she was kind of in the wilderness, um, as far as her professional development goes.
And so, Alan, I think that, that the issue is actually endemic, um, throughout healthcare. It's not just on the payer side, it's on the provider side too. I, I completely agree that AI as the opportunity to, uh, improve outcomes, uh, and under human trained supervision.
But I wonder at the other, the, you know, if the other influences of ai, because of a healthcare system that's profit oriented, not public benefit oriented, if, if those are gonna overwhelm the, you know, I, I think this is the beginning of something that we're gonna see over and over again. What's gonna be is that there's all these flaws in all these systems inside and outside of healthcare, and they exist everywhere, and they're all gonna get exacerbated by ai. And it's, you know, and we'll blame ai, but ultimately the flaw already exists, and we're gonna see this over and over again.
It's gonna be this societal impact of ai. And, and that's, you know, this is just the tip of the iceberg, I think. Right?
Exactly. That, that's, that's what I keep, that's what I got from these healthcare professionals. They mentioned all the good things that AI can do in the field.
But I, I got to thinking Mike, also about this idea of how it applies to other industries. And we'll have the same different types of scenarios where, um, the best parts of AI will be used. But there will also be the, the, the downside and pitfalls, which will probably get more attention, honestly, because that's the way the press works, right?
Uh, As Alan said, AI is only doing what it was trained to do, Right? And, and if the issue before AI arrived was only impacting, you know, 5% of the people over an extended period of time, you know, it will go unnoticed. But once you get up into the realm at 20, 25%, then everybody starts talking about it and it becomes, you know, a political issue.
So we'll see what happens. And, you know, that's not necessarily a bad thing. Not that it becomes a political issue per se, but that at least people start noticing it.
Because, look, there are too many people in the US who say, it's okay. We still have the best healthcare in the world. And those people haven't traveled very much.
Um, we need, we need a redo around healthcare here, guy. What you pointed out with your mom is from the nineties, but unfortunately, I don't think it's very different today, Right? No, no.
It's worse. If anything. Yeah, it, I I have friends down here in Boca who are doctors and, and you know, whether they're working for the big hospitals or the big healthcare, you know, healthcare has gone big.
There's no kinda local hospital. The local hospital is part of this system, and the doctors all work for the system, and it's all part of the system. And the system is profit driven, and so it has a, it, it's gotten worse.
You're right. We need to figure out something in this country. Yeah.
I'm just, I feel like this is a canary in the coal mine. What, what does this teach us about the use of AI just generally as a public bene benefit versus as a profit motive? I mean, I, I asked the group here, like, the what's, what, what, what should the audience, our audience, you know, think, um, should they be behaving differently?
Should they wish for better systems? Like, do we need to just learn? Like I, I, we talk a lot about reminding ourselves what AI is good for and what it's bad for, and how to manage it, and how to use it productively.
But is this a cultural question? I don't even know. I don't either.
I mean, but wishing for better isn't going to. We've gotta work to make it better. And if that means lobbying, you know, voting with your pocketbook and with the ballot and everything else, it's, it's a bad, I mean, I'll be honest, you know, as the CEO of a company here at Techstrong, I've always made up my business to make sure that we have what I consider great healthcare options in, in terms of insurance and affordability and coverage, so that you could go to a doctor anywhere and get treated, that you can go to just about any facility and get treated.
And we've had people who've come here to Techstrong and said, Hey, I appreciate that. I've had young people who say, I never get sick. I don't need the health insurance.
And God bless 'em if that's what they wanna do. But it's, it's an important, it's important. And I, I just, you know, I'm at a loss, honestly, I, I get very disappointed that as a country, we haven't figured it out.
And we keep talking about repealing Obamacare. Like Obamacare was the be all and end all. It wasn't bad.
It, it improved a bad system, but it didn't, I mean, there's so much that needs to be done in our healthcare system. It, it's this, this Has been a debate that's been going on for 70, 80 years back to the Truman administration. Yeah.
Before that. So, Al, lemme ask you this just for grins, right? What percentage of your costs are tied up in healthcare and, um, why are companies on the hook for this, for the insurance, when, if we had a different system that would all move into more of a government function, right?
Hmm. Oh, I wanna answer the second question. Go ahead, Aaron.
First. No, you go first. I Get's interesting.
So the reason why private companies or private, uh, not private, like, uh, uh, uh, you know, the government is not, uh, involved directly in healthcare is because in World War ii, during World War ii, uh, there were, uh, controls put on during the war effort as to how much people could be paid in order to try and keep government costs down because of all the, you know, profiteering that's going on. And so, uh, companies started to offer non-monetary benefits, um, instead of salary in order to attract, uh, workers, which were scarce. And one of those was healthcare.
Yeah. And there you go. I mean, I will tell you, Mike, you know, it depends on what people make, right?
Because if people aren't highly compensated, the percentage of their salary that it costs us as a company to give them health insurance is higher than someone who makes more money. But if you take the average person here at Techstrong, and again, I, I think we pay a decent wage. If you take the average person here at Techstrong, um, and we, you know, I'm not gonna advertise our benefits on the gang, but we, we pay a good, healthy percentage of your insurance, whether you're a person, a couple, or a family, we pay a, a very healthy percentage of that.
It, it winds up costing 18% over and above just your healthcare. I'm not talking 401k and matching and all that stuff. Healthcare is 18, 20% of an average person's salary.
A additional in terms of a benefit. So that means if someone makes, let's say, a hundred thousand dollars a year to make it real simple, it winds up costing me 120. Mm-hmm.
All of which could theoretically, if you add up all the employees, maybe we're not hiring additional folks because of the total cost of healthcare. Right? Well, but I, and you know what, I'm glad you brought it up because as a CEO, that's something I wrestle with every day.
But I'd rather have less people who don't have to worry that, God forbid, they or their children got sick or their spouse got sick and they don't have coverage, or they, they're gonna go for an operation and some insurance company's gonna tell 'em, I can only give you anesthesia for 30 minutes. I don't care if your operation's 40 minutes. What kind of nonsense is that?
I, For one, I'm very grateful for our insurance. Yeah, no, I mean, I, I am too. I think we have, and, and I'll, I'll be transparent.
Our insurance is United. I've never had this UnitedHealthcare. Yes.
Yeah. And I've, we've never had the issues that you read about, but nope, I don't know. You know, I don't know.
But I, I do believe every, you know, healthcare rights are human rights and everyone's entitled to healthcare, or should be. Anyway, on that note, let's take a break here on Textron Gang. We're gonna come back something a little lighter.
Uh, snowplow alerts. Amanda has the news on it. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
All right. Alan referred to this as something lighter. I've never heard of a light snow cloud, but, um, we're talking about how in New York State, they are testing technology so that as a driver, you can know where that snowplow is and hopefully maybe not run into it, or as most New Yorkers will probably do, just follow it because, well, it's, you know, cleaning up the highway and it's just kind of like what New Yorkers do sometimes when they are following ambulances and fire trucks, right?
Not necessarily the right smartest thing to do, but that's kind of how it gets rolled up. Amanda, this was on, uh, digital CXO, so, you know, what's your take on this? And, and, you know, are we gonna see more of this?
Yes, I love this. Um, and I think where I see this being really beneficial is, you know, I live in Texas, so I do think we're gonna see more of this, because if you think a couple years ago, uh, and you would remember this, we had the Snowmageddon and our, uh, we don't have the infrastructure or the equipment to really, um, handle a, a lot of these hazardous conditions. So I see this eventually being really helpful in these areas.
Um, as far as safety on the road, um, it would've been helpful back then everybody was just kind of stuck at home. Um, so, but yeah, and in the big cities too, with the traffic, you know, with the traffic situations there, I think it's great because it's gonna reduce a lot of accidents. Um, and I will kick it off to John to share more about it.
'cause he's the one who wrote the article. Okay. Thanks, Amanda.
So, the, the company is called Icon Products. I talked to the CTO, interesting guy who, um, kind of downplayed in a weird way what they were doing. But this goes far beyond New York.
They have, uh, systems in dozens of states, and they're actually in the process of talking to Tesla, general Motors and Ford about using their technology somehow incorporating it into their cards. So it's onboard, and it, it, you think about it, it's not just snow plow, it's any type of construction equipment on the shoulder of a road. The construction workers themselves who are endangered.
And what this guy, and what they're trying to do is, I think, and I'm not, I'm gonna, I don't mean to be hyperbolic, but in a sense it's kind of a safety advancement for drivers. I think of seat belts, airbags, Ralph Nader, anti-lock brakes, rear view video systems. And I think of this now with the technology, it's, it's available on Google in ways.
And in fact, I've experienced it because in a, in a roundabout way, because I just upgraded my iPhone to the latest system, and now it's giving me alerts approximately about cars on the side of the road or some sort of accident before I get there, so I can avoid it, or, or at least I know about it. So, um, I was quite interested in this. Um, there actually also have been studies down, I think Purdue does a lot of studies on emergency breaking near work zones, and found that technology, technology like this has resulted in a reduction in emergency braking near these types of sites.
So again, you know, technology can do a lot of really good things, and I, I think it's important to write about these types of things and not always dwell on the dark side of tech as some of us, especially me do. I thought ways are well, dark side of tech. I mean, go ahead.
I mean, shout out to Texas, the only state I've been in where, uh, people actually drive faster when there's ice on the road. It's sort of slower. You don't know how to drive Jesus.
I think that that, um, as someone who, uh, very recently, uh, uh, uh, uh, like a good New Yorker in Texas, uh, drove behind lease car, that was clearing away for me. Um, I think that, that John has the essential point here, which is, um, first of all, increasing awareness generally in information without fuss. Um, I'm a Google Maps user, but they've started to incorporate that kind of Google ways information about what's going on on the road.
Um, and, uh, this is, uh, you know, one of the, one of the non uhdr related leading sources of accidents is inattentive drivers who, uh, don't see things like blockages, um, or weather conditions or what have you, and get caught by surprise. And, um, I learned a new term internet of road work. Is it, um, that, uh, this, this spender talks about.
Yeah. Um, the more information, the more data we get in, that's, uh, an opportunity for the app developers. It's an opportunity for the AI developers.
Um, and we just, I'm not gonna turn dark on this at all. It's, these are opportunities. We just wanna be cautious and, and, and smart about using them, because ultimately this data, right, Amanda, this is gonna be incorporated into, uh, you know, automated driving and other kinds of driver assist, whether on vehicle or in af, right?
Yeah. I think it'll be so helpful, uh, like I said, in reducing accidents, um, and allowing people in, especially in places like Texas, that just aren't comfortable or familiar with driving and hazardous conditions to feel safer. So, You know, In California and California, we freak out when it drizzles, right?
And so we also, I, the, the thing that I was thinking about more and more is with the Infra Infrastructure Act, there was so much construction going on. We have portions of Highway 1 0 1, which is a major artery here that are closed or divert traffic at week, every weekend because they're still working on these projects, repaving the roads, and there's so much equipment out there. I really want to know before I get on the roads, what's, what's there.
So I'm not only delayed, but I also feel unsafe sometimes because there are quite a few lanes that are abruptly shut off. I'll tell you what, a lot of small towns do not appreciate about this ways thing and all this other stuff. And I'll give 95 as an example.
Every time there's a frigging slowdown on 95, everybody stops hopping off and goes on Route one through all these small towns. And it's only about 10 minutes later before that entire small town comes to a But luck. But some people stop there and grab a bite to eat or guess up, and they make, and, and, but, and I don't mean to make light of it, let me tell you why.
'cause I'm not an unreasonable man. So the, the deal is that, okay, doc of all, I'm, I think you got that too, guy. Uh, this, this kind of functionality has been available in Waze for many years.
I've used Waze for years and years, especially when this hurricane's down here. Waze gives you the best way around. It tells you what's cra what's bad and what's not.
Um, the issue is it can't be a do-gooder thing. There's gotta be a profit motive, otherwise it's not gonna make it right ways. God Bless was a bunch of Israeli guys.
Google paid a billion dollars for technology that brought in $0 in revenue, and they've been trying to figure out how to do revenue ever since. Now they've got it where, you know, McDonald's will show up on your ways. Hey, where's the nearest McDonald's?
Where's the nearest Kentucky Fried Chicken? Where's it? Or KFC, where's the nearest whatever?
And so they're trying to put advertising on your ways Maps and your Google Maps to make it somewhat, you know, uh, revenue neutral, if not downright profitable. If you can't figure out a way to make this make money, the do good aspect, they're only gonna take you so far. And I think that is the problem with all of these.
I mean, it's great technology, it's lifesaving technology, but if you, if it doesn't have a path to profitability, as Alphabet gets squeezed, You know, the CTO of of Icon actually told me he was frustrated because dealing with the automakers, because he said they were more preoccupied with the EVs, and that's where their budget and their most of their money Went. No, because where's show me the money? Show me the Money.
Right? So Exactly. And to your point, and he said, now they're beginning to see that if people pay a premium for cars in particular, they want everything imaginable that can make it a safe experience.
Um, but yes, yes, he said that the profit motive wasn't there yet for them to put it on board. That's a point. And I won't be able to, I won't be able to go To McDonald's anymore.
'cause the AI is tracking the fact that I ate all that crappy food and then that won't get covered when I get that disease. So, you know, what's the point There is that it all comes back, you know, Hey, It all comes back. Yes.
Be careful what you wish for. Anyway, guys, we gotta pull the plug on this edition of the Gang. We've all got places to go.
What a great, comfortable couple, bunch of conversations today. I hope you've all enjoyed it at home. Reminder, as always, we have a full day of text on TV immediately following.
So stay right here at your favorite bat channel, bat time, and, uh, check out what else we've got. Guy, Amanda, Mike, and John, thank you very much for joining us here on The Gang Today. This is Alan Shimel.
We're out. This is Textron tv. Hey, everyone back here.
This is Alan Shimel back here in, uh, Las Vegas. We're at the Wind, our Wind Studio at The Wind Hotel right across the street from AWS Reinvent Expo floor. I was able to pull my friend Kobe Siria.
Did I get that right, Kobe? Yeah. Uh, off, or, well, he wasn't really on the floor either.
He's been in meetings since he got here, but he, we, he took some time out to come sit with us and talk a little bit. Kobe is the, uh, chief Product Officer at Check Marks company. We, we follow for a long time.
Kobe, first of all, welcome. Thanks for coming up. I know you're busy as heck, so I appreciate it.
Thank you. Thank you for having me here. No, it's a pleasure.
Are you much appreciated, Kobe, you've been on before, but I don't know if everyone remembers. Give us a little bit of your kind of background, your story to be as you became the Chief product officer at Check marks. Yeah.
Well, I've been with, with check marks, uh, for more than 11 years now. Um, you know, for my first seven years, I actually built the engineering in the field, meaning, uh, the entire group that, uh, that deals with sales, engineering, professional services, technical account management as customer success about a bit more than four years ago, uh, our former CEO, he asked me to, uh, to take over a product in order to build our next generation product, which is, uh, check mark one. Yeah.
Our, our our cloud name platform, uh, for, for application secure for application security. And this is what I've done. Like we, uh, you know, we, I headed, I spearheaded the leading building, this platform.
Um, we actually officially launched it, uh, uh, three years ago. Yeah. Now we have over one, you know, um, about half of our a RR actually lives on that platform.
That's great. Just within, uh, three years, hundreds of hundreds of, uh, hundreds of customers, large customers are using it. It utilization of the platform is, uh, uh, skyrocketing.
Um, I think there's two, two things that that says though. Number one is you built a good product, right? Check Marks.
Bills. Thank you. Check Mark.
You're welcome. Check Marks has good, we talk about app dev and, and, and, and so forth. Check Marks is a leader and builds has great product.
Number two though, is the cloud native market, right? The cloud native market has really over the last three, four years, it is the stack now, right? It is the compute stack.
If you are building something, you know, they use this euphemism modernizing applications. When they say modernizing applications, they mean for the most part microservices, cloud native architecture. Exactly.
I describe it as a Lego. Yeah. You know, that's exactly what we did.
It's like, you know, the former generations of, of apps where, you know, you had your front, your front end layer, your business logic, your database, right? Right Now it's a whole Lego. You have your propriety code.
Most of the code is, uh, is open source, open source. You have your microservices. Um, you, you, you have, uh, infrastructures code that that actually builds the, uh, the runtime environment that, uh, that, that, uh, that sure.
That, that, you know, that, that you, that you run, um, and then you Yeah, exactly. You have, they stitch in all in one ap. The other, you, you have, you, you have APIs, so um, you have APIs, you have, uh, you know, all kind of secret detections.
Yes. All, you know, all of that kind of, you need kind of, if you really want to provide security, you need to build solutions for all that. And this is why we thought that, you know, the right way to do it is actually to have a platform that will have, uh, you know, multiple, multiple scanners.
But since you have so many scanners, because the technology is, is kind of Lego mm-hmm. Uh, Lego, you need on top of it an A SPN layer that, that will provide you actionability. Um, you also need, uh, you also need connectivity to runtime in order to provide you the runtime context.
So it actually takes you to, to the next level of, of actionability. Does it really run in, uh, does it really run in runtime or it just lies in my repo, right? In dev in the dev place.
Yeah. In, in, in the dev place. And of course, the entire developer experience.
Today, our customers are the developers and kind of, we, we, we kind of will build that. So, so developers will feel comfortable and will have a, a very, uh, smooth and very good experience, uh, using, using the, using the check, uh, platform. You mentioned developers are your customer, you know, and look, I've been in developers are are users and users necessarily, but they're very, very impactful users.
Yes. They're also highly impacted by this. Right.
com in March of 2014, so over 10 years, almost 11 years now. And, you know, shift left shift, left shift is far left as you could go. Right.
And then I think what we've seen again in the last three, four years, maybe two, three years, is that developer, a lot of companies made the mistake, especially security companies, not Jack Marks, but a lot of security companies that they gave security tools to developers and developers are not security people. You need developer tools for developers that help them build better, better secure, more secure code. Not, don't mistake them for the security professional, but some companies made that mistake.
Right, exactly. So, kind of, you know, when we started to build the, the, um, the CX one platform, we actually realized that, you know, that, that because the burden of security was actually shifting to developers, and they are the most, as you said, impacted and in impactful users. We need to provide, we need to provide them an experience.
And the experience is speed is, um, actionability and less noise. Okay. Because you cannot waste your retirement.
Also, simplicity. Yeah. Okay.
Simplicity. So kind of, these are the pillars that, that, that we work by. This is why I mentioned code to cloud, uh, the, the cloud integration runtime.
Mm-hmm. Before, why is it so important? We think that it's going to, is we think that it's going to change the way application security is being done.
Because if I can tell you, Hey, deal with, uh, vulnerability, X, Y, and ZY because there are the ones who really impact your runtime. Right? Okay.
And, and kind of, they're, they're the ones who are actually open to the internet. So start with them. Okay.
Yep. So, I mean, but this is a lesson. Look, I started a company in 2001 called Still Secure, 2003.
We came out with a, something called van Vulnerability. Access and Management was a scanner, not not in runtime, uh, in runtime only, not, you know, pre-deployment. It was the same thing.
Then, you know, we would, we used to internally, we would call it the bad news generator because it was a bad news generator. We would scan your infrastructure, and we give you this, this is nothing, we give you something like a telephone. People don't know what a telephone book is anymore, but like a telephone book, you remember?
Yeah. A lot of people out here don't, but a telephone book full. And then, you know, some poor guy there would have to go through and say, okay, well this is a priority.
This one's not really accessible. This one's not reachable. This is a, a Linux device.
We don't have to worry about window stuff. This is a port that doesn't get you. There was all kinds of things that allowed people to say, Hey, we're gonna get the biggest bang for my buck in terms of remediation, in terms of lowering my risk, which is what it's all about.
So, so kind of, so here comes the next thing, uh, uh mm-hmm. First of all, uh, first of all, you know, um, we also, we're not also, we're not only giving you the headache as, as you said, right. But bad news, Joe.
So kind of let's say, you know, I give the bad news start and work on, uh, vulnerability, X, Y, and Z. Okay? Right.
I'm with ai, we're also helping developers to remediate. Okay. So, uh, we, uh, uh, we have either auto remediation, right?
Okay. Uh, or guided remediation, because a lot of time developers don't like, they don't like, don't people to mess with their record. So kind of we guide them.
This is all done with ai. Okay? So we didn't have AI in 2000 in three.
I know it made it a lot harder, but, but that brings up this whole AI issue, right? In the role it's playing here. Uh, I mean, no pun, but it gets smarter every day, right?
It's getting smarter every day. And, and as we train it better and everything else, um, if it follows other adoption curves that I've seen, there will come a time where developers are gonna say, let the AI fix it. Right?
I'd rather, you know, right now they're going slow because they don't have confidence. And maybe rightfully so. So, so kind of the REI strategy is actually built again, on, on three pillars.
One is detection, right? Okay. Detection.
Uh, we do that through, uh, integration with, uh, uh, with copilot. Mm-hmm. Uh, integration with, so you're already integrated well with chat, PT, Uhhuh, uh, we also have an engine of our own, which is called, which is called the vpa uhhuh.
We embed all of that into the IDE. Okay. So that's where it's at today, the id, this is kind of, this is where it lives.
Mm-hmm. So it helps you detect things like, you know, SCA hallucinations, uh, bad practices of, of, of coding in real time within, within the ID for your AI generated code. So kind of, this is the, this is the detect the pillar.
Right. The second pillar is what I talked before, is remediation. Okay.
And maybe, maybe you, you're probably right. Maybe there will come a time that, that the remediation will be it's a confidence build date. Exactly.
So maybe there'll probably come a time that the remediation will kind of, will be done automatically. Mm-hmm. Okay.
Automatically. Yeah. For, for, for the garden variety stuff.
Right. Yeah. There'll be corner cases.
There's always corner cases. And, and the third pillar is to secure your LLMs. Okay.
Which I think it's also one big issue that the market is only now starting to, uh, to, to approach and build solutions for. We are already deep in the research work on how we secure, how we secure LLMs, how we secure open source lms. I believe that that, just like people today, 80% of the code is not proprietary open source.
Right. By open source. This what will happen to, uh, this, this also, what, what will happen to, uh, to LLMs.
I, I think you're gonna have sort of LLM marketplaces, most probably. You, you already have these, uh, you already have such, such companies that, and, and you, you know what, what they're doing. That LLM you download from the marketplace might have 80%, 90% of what you need.
And you'll customize just like real code today. It's the same thing. Just just like you do.
Yeah. Building code, just like you do with open source. This is why securing, securing open source of a lens is, is going, is going to become, it's probably going to become very, very big.
I, I, I agree with you a hundred percent. We are at AWS reinvent. I gotta bring some AWS into this.
So they made some announcements also around AI and ai, the Q developer tools, and actually came out, they came out with their own ai, their own GPU Silicon and their own sort of chat. GPTI think it's called Nova, Nova Light, Nova Pro. Um, you mentioned working with copilot.
Uh, you're a, you're a, uh, a partner at AWS We partner, are you working with the Q Tools yet, or the a Yeah, we're, uh, we're, we're working on integration with, uh, with qq with Q Tools also working, uh, on integration with, with Bedrock. Yeah. With Bedrock.
These are the, these are kind of the, the two, the two AI pillars that, that we're, we're working on with, with AWS. Okay. We have very close relationship and, um, you know, the outcome will probably be seen, uh, sooner, sooner than later before RSA in the end of, uh, April.
Yeah. Okay. Yeah.
I'm, I'm gonna press, I'm gonna press the button. You'll press the button on that. I wanna bring up another area though that Sure.
Uh, I think is important and at the part of the learning of developers not being Security Pros has been the emergence of what we call platform engineering. Yeah. Right.
So if we can give the developers a better house, a better environment, a better environment to work in, that already has some security rules in it that already has sort of guardrails in it, it allows them to go faster and again, not have to worry about certain things. They just worry about their code. How does check Marks view that whole, I mean, a lot of people say, eh, we call platform engineering when it's really ops, right?
And, and it it is and it isn't. Right. It, it is.
There's a lot of the old ops stuff is in there, but how do you guys look at platform engineering? We think that it'll become a domain. Yeah.
Okay. This, this, this is what we think of it. And you know, we, you know us for a long time.
Yeah. We're the first one who were integrated into pipelines into IDE and, and also into the, uh, what before it was called the Dev, uh, DevOps. Yeah.
It was DevOps, dev SecOps, dev SecOps, and SecOps. So I, I feel I see it as the kind of the next step of the DevSecOps. And I think that if will be that we'll be able to provide solutions that will be part of that.
Okay. That, that, that, that will be part of that and kind of will give the, uh, you says guardrails. Right.
Uh, for, for security, either in, uh, the DevOps part of the, uh, platform engineering, um, and also with the, uh, also, also with the direct tools that developers use, like IDs and stuff like that I mentioned before mm-hmm. Which is kind of an engines that provide you realtime feedback on your, uh, on best practice of, of security. I love it.
I, I, I think that this is where it goes. The, and these are the solutions that, that, you know, we, we are, we are building excellent at, at the end of the day, you know, we live there. Absolutely no one.
I know it'll be real when you come here and tell me. Developers and platform engineers are our users. Yeah.
Oh, okay. Yeah. That's when I know.
Okay. It's real. Right?
Yeah. Um, but I agree, you know, right now, you know, um, platform engineering is something that people start to talk about. Yeah.
We have to see kind of how catchy it'll be in, in, in, in reality in the market. But we are building tools for it. You have to, you have to.
com, our site platform engineering. 'cause Yeah, I've been doing this a little while and I, I watch these things I watch because you don't wanna miss the boat. Of course.
You don't wanna be too early. org. The community, they got 300,000 people in the community there.
When I go to CubeCon, I don't know if you were out in Salt Lake City, uh, recently for CubeCon a couple weeks ago, few months ago, I was lot of talk around platform engineering. I, I think this is, as you said, this is becoming a domain and Absolutely. Now is the time, I think, to kind, not a land grab, but put your flag down, stay, you know, claim your, your, your no doubt as, as I told you, you see that kind of word.
Yep. But I think AI will have, its, I think what we're gonna see is AI is gonna bring all DevOps, dev, SecOps, platform engineering, SRE, traditional security pros. AI is like shortening the distance between all of that.
Of course. Also observability. Yeah.
Also observability of Yeah. Observability as well. Yeah.
And how you fix issues once you, once you, uh, you know, once you identify something in your observability, you know, we run cloud platforms, so kind of we are eating your own dog food with Yeah. You see for yourself. Exactly.
Absolutely. What else? Exciting from check marks?
I know we talked, we probably over time, but what else do we got? What else do we got? Um, you know, we released a supply chain security model, uh, just last, last month.
Uh, which actually includes, uh, first of all, secret, uh, secret detection. Yeah. I mentioned earlier.
Yes. Secret detection and also repo health. Oh.
So what exactly is that? Meaning we look at your repo, uh, the code and open source, uh, and mainly open sources that are in there and based on our knowledge. And we have a huge database of, uh, open source packages.
Mm-hmm. Not only kind of the standard vulnerabilities, but also malicious, and, uh, also based on info that kind of, we track the contributors themselves. We can kind of provide you a, a grade of, of your, of, of, of your What about, what about of, of your, of, of your, of your, of your overall half of, yeah.
So it doesn't make a difference how many different repos I'm pulling. You know, you're just looking at all of that. And, um, you know, we also, um, uh, we're also working hard on our, that solution.
Uh, you know, we, uh, um, zap is now powered by, uh, by Zap, by by Checkmarks. Yes. The core team of Zap is actually employees.
Employees of, of Checkmark. So kind of we are impacting, uh, we we're, we're impacting there. Um, we also released a new, uh, containers, uh, security model really in August.
Yeah. Which is, uh, kind of topnotch. Uh, we have very, very good, uh, very good, uh, feedback for that.
We have our, uh, we have our integration with Wiz, which is making a lot of noise and getting a lot of, a lot of attraction also with Cystic. That's, that's the runtime. Uh, yeah.
I know cys, we, so both companies, we cover a lot. Yeah. Uh, that we have.
Um, and we are, um, as I said before, we're working very hard on improving the developer experience and user experience of, of, of the platform. We're getting good feedback. So for that, uh, for, for that as well.
Mainly on the simplicity. Mainly on the simplicity side, so, sure. Kind of.
Well then, and we need that, and I'll change it every day. And ai, we talk about AI all the time. You, you ask me, you study.
It just sucks the, the very conversation. No doubt. No doubt.
Anyway, Kobe, thanks for stopping up. It's always a pleasure my to see you. Thank you.
Check Marks. com. Dot com.
Exactly. Go check them out. We're live here in Vegas at AWS reinvent.
I hope it won't be till RS actually, we, you might be doing something with me, a panel I'm doing on Predict. Did they mention this to you? Um, not yet.
I'm doing a c I'm doing a CPO panel. Okay. I'll, I'll be more than happy to, to be there.
January 9th. Our Predict 2025 conference. Kobe will be there.
We've got, uh, David DeSanto, the CPO from GitLab and a few others. Well, I'll talk to you about it. Right.
All right. We're live at AWS reinvent. We'll be back in a little bit.
This is Alan Shimel. Until then, stay tuned. This is Techstrong tv.
Hey, everyone. Good morning. It's Alan Shimmel here at our Techstrong Wind Studio, where we're doing our coverage of, uh, AWS Reinvent.
You know, I got out here on Sunday. Today is Thursday. I've had about enough reinvent.
It's been a great show though, along with, you know, me and 60,000 other people. There's been a lot of keynotes, a lot of announcements, a lot of catching up with industry friends. Speaking of industry friends, I want to introduce you to do Lavo.
Do, did I say it right? Lau, it's, uh, hard to get. Yeah.
It's not so hard. Do Lor, um, do, if you don't know, is the founder or co-founder, CEO of a company called Cila cdb, makers of the CDB database. You may or may not be familiar with it, but hopefully by the end of this interview, you will be Do welcome to Text on tv.
It's great to have you back on. Thank you. Good morning.
Good morning. Wonderful to, to be here. Absolutely.
So do, before we get into Cila and News here at Reinvent, let's talk a little about you, right? You're, you're a co-founder, CEO, but give us kind of your journey. Mm-hmm.
Absolutely. You, you know, as, as a co-founder and a CEO, I get, I feel married and kind of me to the company, but, uh, don't Have to tell me. Yeah.
I do have life and a mountain bike and ski, so, oh, good. Not only that. And family, of course.
Uh, if we watch, um, so, um, Amor, uh, originally from Israel, uh, I co-founded RA 12, uh, years ago, together with my partner Avi. Uh, we're strong in tech, in low level computing. Like my, my first, uh, company I was involved with, uh, as an employee was, eh, Charlotte Web Networks, uh, interesting name.
We, we tried to compete with Cisco's core business, abit Router, and we created one, and it worked, eh, later on with Avi, uh, um, and Benny, my chairman, we created the KVM hypervisor at another startup, uh, eventually acquired by Red Hat and KVM runs, uh, AWS, uh, cloud and Google Cloud. Yeah, no, it's one of the most popular ones out there. I remember those days.
Yeah. It was some win. And, uh, we used to fight against open Source, Zen and VMware.
And, uh, eventually KVM like became a standard in, in cloud computing. Mm-hmm. A wonderful ride.
And afterwards, we, we came up with, uh, CB initially, uh, we tried to shoot at the operating system domain and take Linux down. Linux is so strong, we couldn't take it down. We, we, we had an operating system for virtualized environment.
You're not the only one to, to die at that mountain. Yeah. You know what the funny people have to tried to get.
Yeah. But it's, it was a worth worthy ride. Absolutely.
That us we created still exists today in open source and still kicks ass. Sorry if I joke Five. It's okay.
So it's an adult channel. Um, and then now we switched to the database, uh, the development, which is fascinating. It's a big world out there.
Absolutely. And with the increased focus on data, as we've seen here at Arena Event, you know, data, it's about the data. You know what's interesting though?
You spoke about hypervisor. Here we are. So, I, you know, I first became aware of the whole hypervisor world.
I, I guess it was early 2000, maybe 2001. And, um, you know, VMware was part of spun outta VMC Dell the whole, but it was 25 years ago. Mm-hmm.
Right. If you go to the opening keynote here, uh, Tuesday morning mm-hmm. They're still talking about migrating from VMware mm-hmm.
Onto an Amazon stack, or, you know, and then as popular as Kubernetes. And the whole cloud native thing is still hypervisor. Mm-hmm.
Right. The hyper, the, the hypervisor doesn't go away. And it's the same thing with the Linux now.
No, we haven't replaced Linux Os, but if you look, there's been a lot Rocky Linux, you know, 'cause Red Hat's done some things with their Linux, and so other people have said os and other people have come out. So though it may look like a monolith, there are cracks, there are changes that you see happening. Same thing with database.
Right. Another announcement here this week by Amazon, you know, they're claiming, uh, I guess it's based on Postgres, right? Yeah.
Or Aurora. The, the better, uh, better Aurora. Mm-hmm.
Just, uh, folks in my team said, oh, we need to add a Postgres, uh, compatibility. And, uh, SCL ourselves. I told them like, look, I definitely want to do that, but let's be focused.
Uh, and I gave Aurora as an example. The, the, the great team at AWS have been working for years and years with like huge teams and huge scales on Aurora, just to add it. And they compete with, uh, the plenty of other fantastic players like a cockroach and Hugo Bite and various flavors of, uh, um, of Postgres.
It's, it's kind of, uh, you've got to be focused, and we're trying to be as much focused as what we Do. You know what, so I wasn't always on the media side. I've done tech startups most of my life, and that's, that's really the job of A CEO sometimes is you gotta know when to say no.
Right? You can't, you can't boil the ocean. You can't be everything.
You gotta pick your fights, right. Pick your bullets. And the, um, yes, there's a lot of Postgres kind noise and tumble out here, but you don't, if it's not your, you know, it's gotta be in your priorities and you can't do everything on every time.
Now, Cilla people who, what, what, what, what's, what's the special sauce? Why do people want to, why would people want to use? Um, sure.
So, CA is a distributed database. Uh, it's a no SQL database. It doesn't, uh, support SQL, but the trade off is that it's, uh, extremely fast.
It has distributed, uh, very re resilient for, uh, any type of, uh, availability failure, disaster recovery failure. We run, uh, deployments across, uh, eight regions in, in one cluster. And all of them were zone aware.
So extremely, extremely resilient. NSS So three nodes can do a million operations per second. Um, so it, it's extremely fast.
Originally we rewrote Cassandra from scratch. We, we started their project by stumbling on Cassandra. We figured Cassandra is a very interesting project, Cassandra itself, uh, to try to implement an open source alternative to Dynamo DB and Google big tables.
Yeah. And, uh, they have, and it's a viable, uh, project. The, the problem with Cassandra, it's more of a high level implementation in Java, not the best choice for, uh, low level software.
And throughout all of our careers, we were working in really low level, like, uh, AVI checks, uh, every c plus last line to check how the assembly looks like. And also, we, we check to maximize the, the bottleneck of every compute, uh, instance, network instance, uh, eh, the storage at the NVME drive. So we squeeze every bit of, of the hardware in order to have the best, uh, throughput la uh, latency and efficiency.
That's excellent. That was an excellent, uh, description for the people. Um, for people who want to maybe give this a world, give it a try, find out more, what's the best sort on-ramp?
Mm-hmm. So there, there are multiple options. Uh, one can just download the, the free open source version and another, uh, and running a docker or, uh, run an enterprise trial.
And we have a database as a service. Uh, two thirds of our revenue comes from the database as a service. Uh, we can run in our account, in the customer's account.
Uh, so it's relevantly simple to, to consume that. There's free trial, free tier over there too. Uh, so pretty simple to run.
It really is simple. And you know, like you said, there's a lot going on within the whole database space. The No SQL look, no, I, no SQL databases probably came out.
They really hit their heyday around 2000, or, you know, we first became really, uh, aware of them 2008, 2009, maybe 2010 in that area. Couch base, Mongo. Actually, it wasn't.
There was couch and then there was, I forgot what base was. Mm-hmm. They, they merged a big couch base.
Right. And, um, so it's a, a relatively mature technology at this point. Some people say, well, what, what's new under the sun?
What, how else, how else do you address this? Mm-hmm. But you guys announced some news here, or relatively recently for, for reinvent.
Why don't you, if you don't mind, do share a little bit of that with us. Absolutely. Um, so, um, for years we were trying to simplify what Sila is by, by having a one sentence of, uh, the power of Cassandra.
'cause we were, uh, we, we give everything Cassandra can can do with the wire compatibility at the speed of Redis. Uh, Redis is super fast in memory database, uh, mostly used for caching. And we can, uh, provide almost the same, uh, latency and INM memory.
Um, cache can give you, but from the disc, uh, with persistency. So we used this, uh, uh, power of Cassandra at the speed of red. The missing, um, piece was the usability of DynamoDB.
'cause, 'cause DynamoDB, uh, it preceded MongoDB. The, uh, the develop, its, its, uh, internal development from, uh, 2004, only later we became public. And, uh, like a lot of things that AWS do, it's relatively easy to use the, uh, as a service nature, uh, it's really easy to spin and it's, uh, um, the elasticity to add and remove.
It's, it's more for serverless nature. You don't see the servers in, in the front and, uh, probably the, the rest of the industry, how they develop. It's more of a, okay, let's take these servers and, uh, make them available to the users and also have a, as a service on top of that.
But, but these, uh, it's hard to get away from those servers component. Uh, what we've done recently, we, we did the major architecture change. Uh, we, we changed all of how we deal with metadata.
We added consistency layer based on the rough consensus protocol. Very, very important for consistency and ease of operations. That, that one big piece, it's, it's a big project that took us four years to roll out in, in stages.
Uh, and the last bit is, uh, a portion called tablets. The, the idea is to not to think about the server as in, in the da, the database cluster as big tables. They're gigantic tables.
Uh, but divide them not just for like charted per server, but chart them into tiny pieces called tablets of, uh, five gigabyte, uh, each. And those tablets are very elastic. So let's say if I need to load balance, uh, in my deployment, and I need to add double the amount of servers I've got, so we add servers, but, uh, then we need to stream the data to those servers.
And normally if every server has, let's say, 10 terabytes, a relatively large amount, need to divide it and send half away, it's, it's a lot of, uh, streaming to do to be done. And it takes time to do that. And until half a terabyte in, in the past release, uh, would stream to the other server, then you would sit and wait and you use the old capacity.
And this process, uh, could have taken, uh, hours, sometimes more depending, depending on the schema. With tablets, it's all five gigabyte pieces. So five gigabytes, it take us about, uh, a second or two to send each piece.
And immediately that piece become functional. 'cause all of the metadata is consistent, and the clients become aware, the new data moved from one server to the other. And the clients do not need to know.
They, they get notifications. And it's, it's, uh, the streaming is becomes automatic, a super easy to scale up and down. We do it best better than DynamoDB, which led the industry.
So we can double, uh, your capacity in something like 10 minutes. It's a function of, of the amount of data, but easily double a big cluster in, in 10 minutes. It's nothing and shrink back.
Um, and if you're a customer that changes the way, uh, you, you do your planning sizing, um, with Sila, because let's say many customers have the workloads, uh, baseline of let's say 100,000 operation per second. And here and there, they may have spikes of usage for, um, like live, we watch the audience live up to 400,000. Sure.
So instead of be provisioned all year long with 400,000, uh, operation per second, it's more expensive. You get provisioned a base, and if there is a spike in minutes, uh, the, the, the database as a service adjust to the spikes. That's fantastic.
I mean, that really, it's almost from what you're describing, I'm think almost like nanoparticles, but they like transformers, right? They transform into, you know, into one thing. Um, this tablets is available in the database as a service.
Is it also available in the open source, or that's strictly a, there's a premium kind of feature. It's also available in, in open source. It is, there is differentiation, uh, with the enterprise, uh, visits.
It's a bit faster, but, but the open source one is available too. That's fantastic. Let's talk a minute, if you don't mind.
You know, a lot of companies over the last year or so, we've seen a lot of companies changing their open source licensing, uh, you know, been a lot going on with how do we make a profitable business with an open source model. And I thought we solved that before, but evidently it, it's come back up now, you know, you're this co you're CEO co-founder. You maintain a very robust open source community around cdp.
What, you know, how do you view this whole licensing? And are other people using it to create a commercial product and, you know, kind of living off of your hard work? How, how do you view all that?
It, it is definitely challenging and it's pretty much never solved. 'cause, um, even companies like, uh, you mentioned Rocky Linux and, uh, uh, red after Santos, e even a mature company like Red Hat need to, uh, constantly adjust the, uh, uh, what, what they do for free, what, what they do for paid. And, uh, uh, when I was a Red Hat employee back in 2008 to 12, there were lots of internal discussions about, uh, how not to expose, how, uh, um, red Hat Enterprise is being, uh, built and, and all of the composition of the packages.
But because, for good reasons, because other people, uh, clone it and come up with a free ride. Yeah. From understandable reasons.
But, uh, it, it, it's really tricky, this model. Yeah. Um, it's really, it's all open source, uh, work really well when, when it's not your core business.
Uh, so let's say if, if you're a Facebook and you publish your ai, then it's, it's not still, it's supportive to your business, but not core. That's great for companies that the open source is core for their business. Uh, it's a give and take relationship.
Uh, and it needs to be adjusted. Uh, and we see what other database companies have done, um, with licensing, it's, uh, it, it's hard out there, uh, especially now, uh, where the, the entire market is, becomes more healthy. Uh, we don't have like, huge amount of piles of money, like 2021.
No. And the industry tries to be profitable. Uh, it pushes a lot of users to, uh, free usage, free usage, and that creates pressures on vendors.
And it's more of a cycle. So sometimes it moves here and it moves back and need constantly to figure out what's the right thing to do. And we adjust from time to time what we try to do to minimize the amount of change, eh, that what's available for free, what's available for paid, eh, we, we do try to minimize and not to make, uh, wave, eh, to absorb those web.
Sure, Sure. Have we mentioned the website? Uh, did we give the URL?
I don't think we did. Uh, so thank you. com.
That's Both for the open source and for the, uh, database as a service, or you get everything from one site. Mm-hmm. That's fantastic.
Dora, thanks for stopping up. I hope you've enjoyed AWS reinvent this week. It's been a good show for you.
Yeah, it was super busy as always. Yeah. Uh, lots of meeting, like it's an industry Show together.
Yeah. Wonderful to meet everybody. And now where the, the brand is no more known.
Like, people stop me and say, oh yeah, sure. Need to like, f folks from Korea folks, folks from, uh, Well that's the internet all over the world, right? I, I still get a kick outta that when we do our webinars and people log out and say hello from here and hello from there, from everywhere, you know, and I, it kind of blows my mind still, even though I'm not doing this, I don't know, 30 years.
Uh, anyway, continued success with cdb. Come back, keep us posted and we'll talk soon. Absolutely.
Thank you. Alright. Cilla DB here at AWS reinvent.
We'll be wrapping up our coverage at the end of today. Uh, it's been an exciting week, and if you're watching this live, all of our, uh, interviews and content from this week, we'll be replayed on text Drunk TV next week. So not to worry.
If you wanna rewatch this or whatever, you'll catch it next week on Text Drunk tv. Until then, though, this is Alan Shemel four Textron, thanks for watching. We'll be back in a little bit.
Hey everyone, it's Sunny and Cher. Ladies and gentlemen, tech enthusiasts and Future Gazers Gather round the biggest, boldest, most mind blowing predictions for 2025 are coming your way at the Predict 2025 virtual event on January 9th. Oh, Sonny, you're predicting something.
Again, last time you tried this, you said Laser disc were the future. How that work out for you? Hey, hey, Cher.
Not every prediction's a hit, you know, but that's why we've got the real experts this time, top analysts, visionaries and tech leaders sharing what's going to rock our world in 2025. So, no sunny predictions this time, no flying toasters making a comeback. Very funny sheriff.
But seriously, we're talking AI breakthroughs, cybersecurity game changers, the future of DevOps, cloud Innovations, and so much more. And what about my favorite prediction? A smart mirror that tells you how fabulous you look every morning.
That's real innovation. You're already ahead of the tech share, but if you wanna hear the really big stories in tech for 2025, you've gotta tune in on January 9th. The event kicks off at 8:45 AM Eastern and runs until 2:30 PM And the best part, it's all virtual.
No stuffy conference rooms, no long commutes. Just grab your coffee, your laptop, and join us from anywhere in the world. You know what else?
It's not just predictions, it's insights, strategies, and a whole lot of fun. 0, predicting your jokes before you tell them. That's a good one, Cher.
But the real joke is if you're missing out on this. So don't miss Predict 2025. That's right.
Mark your calendars. January 9th, 8:45 AM Eastern. Be there or you'll miss the biggest scoop on the future of tech.
See you at Predict 2025. Be there. This is Textron tv.
Hello everybody. We're back at OpenText World in Las Vegas and we're here with Shannon, who is the CIO and Chief Digital Officer for OpenText. And you made, even by Las Vegas standards, a pretty big bet today, a billion dollars in savings in 10 years.
It's not a bet. Uh, billion dollars in savings in 10 years, we will absolutely achieve as part of our plans. Yes.
All right, So walk us through how that's gonna be accomplished. I know there's a mix of hard savings and soft savings and what does that look like? Yeah, absolutely.
Um, the billion dollars in savings is really the result of an aggressive program to deploy our own technology. And so it's based on our program of OT trust, sot where we've deployed over 60 of our products, uh, that have a large focus on, um, helping operations. So we have a portfolio of IT operations, management products and developer tools and so on.
And so by deploying those products, we're real, we're seeing real savings. And the savings roughly break down in about five categories, um, which is focused on our, um, footprint in terms of our hardware and data centers. Um, optimizing those, consolidating those, optimizing our cloud costs.
Uh, we have an amazing finops platform that, that we use internally, um, which drives some of our, our financial savings around cloud optimization. Um, we see automation, AI and process management. We showed at the conference this week our Ali AI tool, which we use as our internal knowledge management.
Again, driving cost out, uh, by putting knowledge at people's fingertips and using that intelligence, uh, from a service management perspective, we're taking cost out in terms of employee productivity and efficiency. I shared in my keynote today that we've actually been able to reduce 25% of our level one help desk staff, um, by deploying our service management platform. And so when you look at the breakdown of productivity, efficiency, automation, data centers, um, and as well as cost avoidance, I mean those are real savings contributing to the $1 billion in terms of soft costs.
Again, not part of the $1 billion buildup. Um, but we see massive benefits for our customers as well by adopting our own technology. Um, number one, from an operations management perspective, it means we can be much more proactive in terms of addressing incidents and helping our customers in terms of resolving those incidents.
So there's major upside for customers as well. As part of that overall $1 billion program. Do you have milestones to hit or is it just after 10 years we're gonna have this amount of savings?
Or is every year is there a target? Oh, absolutely. We've set up targets as part of the program.
Um, it wouldn't be a formalized program if we didn't have targets. And so as we deploy new technology, as we, um, are introducing new capabilities, uh, we've built business cases to show the value. Um, and these are business cases that our customers as well can realize by adopting our technology.
And so we are absolutely measuring it. My team is very aggressively measuring it. Um, and that's why we had the confidence to share the story today here at OpenText World.
You mentioned finops and that's kind of an emerging discipline in the land of it. And yet, you know, I scratch my head sometimes 'cause I'm kind of like, well, were we not paying attention to how much we were spending in the first place? Or so, you know, what is finops?
How do you implement it? And you know, 'cause it's almost, to me it's about culture as much as it is tech. That's, it's a great question.
You're right. It is a culture. Um, it is culture as well as technology.
And I think the, the world of finops has evolved as people have been spending more and more on the cloud. And so I see finops not as a basic practice to manage my financials in it. I see it as a very specialized area where we're looking at our cloud costs and optimizing our cloud costs and managing those very proactively.
And I think for many organizations, the move to cloud meant that they were either lifting and shifting technology onto the cloud, which in some cases people found to be more expensive than running it in their own data center. Where the real value comes is when you, um, optimize your products for the cloud. And that's where finops plays a key role.
Inside our organization, we use one of our own tools, um, which is part of the IT om portfolio, uh, for financial operations management. Um, but we have a team whose focus is developing placement strategies around the cloud and looking at constantly, um, how to, um, right size what we have in the cloud and optimize what are the cloud technologies that are available, are we using them? So it's very, very much a part of the, the, um, uh, culture of the organization to understand the cost and the benefits and the business case for why you're doing things.
Mm-hmm. And you're also the chief digital officer and a lot of organizations, the CIO and the Chief digital officer are not always the same person. And now we're starting to see the rise of everything from chief AI officers and chief data officers.
Um, and I can't help but wonder if that maybe is too many silos and maybe a little counterproductive. And maybe is everything coming back towards the CIO in the first place? It's a great question.
I it has evolved and you've seen it kind of expand and contract. I think that depending how your organization is set up, depends what roles you have. Um, data is also part of my responsibilities and uh, and we have a data team that's part of our IT organization.
Again, different organizations set up differently. I think for me, what's unique about my role is that, um, in addition to managing the corporate IT side where I'm supporting our 22,000 um employees, I'm also managing our commercial operations, supporting our 330,000 plus customers. And so those pieces coming together has been, um, has been fantastic in terms of, you know, driving real commonality and standardization in our approach and meaning that we can actually deliver better experiences for our internal and external users.
So you can call me what you want, I think. Um, but uh, but I, I know my role, my role is to drive the best possible experiences for my internal stakeholders and my external customers. One of the questions kicking around the show is with the rise of ai, if I look inside it today, there's a lot of silos and each of those silos has specialists.
And I can't help but wonder with the rise of ai, will we see some sort of reorganization of the way IT teams themselves are structured as we kind of change those workflows? Yeah, it's a great question. I think that, um, AI brings a lot of capability and a lot of possibility for how you, um, design and build and test and run your applications and your code.
And so we definitely are constantly looking at, at that in the IT organization. I do think that there's always a need for domain expertise and you're not inherently getting that out of AI today doesn't mean it might not be there in the future, but definitely I don't see that there today. And when I say domain expertise, I'm thinking about, you know, my ERP system, um, my HR systems, um, my service management.
You know, definitely there's knowledge and experience in terms of those systems and business processes and capabilities, um, that when married with technology means that you can actually deliver great products for your business users. And so where I see the rise of AI is, you know, more in the repeatable tasks and areas where I'm designing and testing or I'm built, sorry, building and testing and running versus that design phase where I really need that domain expertise to make good business decisions and drive the strategy for the products and applications we're rolling out. Mm-hmm.
It sounds like you're all in on AI and other organizations are still testing the waters and some people are even resistant. Um, what do you know about using AI today that you kind of wish you knew maybe a year ago? I think that, um, you know, being all in on AI doesn't mean that you're deploying it for every single use case.
And I think that's been an important learning because in the early days of AI and lots of organizations are still in that test phase where they're doing a lot of pilots, they're figuring out what works. I think that, um, that is critical because you need to have that learning curve for your organization as well as figuring out the business case for what makes sense from an AI perspective. And so, you know, if I looked back a year ago, I would tell myself, don't rush.
Take your time. Figure out what makes sense and make sure you're getting real business value out of what you're trying to implement. Because not every use case you can implement anything in software.
I always tell my team we could do anything in software. The answer is always yes, everything's possible, it's software, but it doesn't mean it's the right thing to do. And so it's exact same with ai.
It's possible, yes, but it doesn't mean you should do it. And so really understanding the drivers, the business case, the impact on the organization, um, you know, looking at the whole, um, security and risk profile, making good decisions that are right for the organization takes time. And you need to learn and understand the technology.
Your teams need to understand the technology. And so there's always going to be a journey for organizations. And I think that's what excites me the most about our approach to AI At OpenText, we are bringing AI and the aviators to the data.
And so in a lot of organizations, and you know, when CIOs that I talk to, they tell me they're struggling with moving all of their data into a cloud that could take them a year, 18 months, 24 months to do. And then they've gotta build the AI on top of it and the use cases then they're trying to figure out as well. Whereas our approach is we have the data, we're bringing the use cases and the aviators to the data.
So you eliminate that phase, um, and that investment that's required by organizations to move the data and you're able to get to the business value much faster. And that means you have a greater tolerance for test and fail as well, right? Um, because you haven't had to make that massive investment.
So I really believe we're spot on with our strategy and that's why I'm very bullish on the opportunity with ai. Old timers will tell you that moving data, nothing good ever happens. Um, and you're talking about bringing the compute essentially to the data.
Have we come full circle on that? 'cause in the cloud era, we were moving data into the cloud all the time, and now maybe we're coming back to some fundamental principles In some sense we, we have come full circle and I think, you know, you see that a lot in technology. We end up coming full circle on many things.
Um, and concepts that held in the past, you know, become true. Again, I think that, um, you know, there, there, there can be cases where you want to move data, uh, there will always be those organizations that are striving to move data. Um, but the less data movement, um, is better for organizations, especially when you're trying to secure and protect your data.
Um, you've got re regulations that you have to abide by, your customers are concerned about data protection. The less movement you're making of that data, the better. And so bringing AI to the data makes a lot of sense.
Alright, There's an old joke about what CIO stands for. I think everybody knows what that is. Career is over.
Um, what do you say to your fellow CIOs about where they are in their positions these days? Is it, is now the best time to be a CIO in memory or is it kind of in a state of flux somewhere? I think it's a great time to be a CIO and I think the CIO has never been more important to the business.
And I think that, um, you know, I always tell my teams and, and my colleagues that, you know, CIOs need to focus on driving real outcomes for the business. And where CIOs fail is when they're implementing technology for technology's sake. And, you know, we're technologists, that's kind of fun.
Um, but that's not a path to success. And so I think, you know, really embracing driving business outcomes and being a strong partner with the business and, you know, business leaders are becoming more and more tech savvy, and so they want to work with the newest technology and they want to embrace it. They want their teams to be part of that journey.
And so that makes, um, you know, I think that makes it a fantastic place to be these days In that regard is we've had this divide between IT and the business that people have talked about for decades. It's clearly getting better, but I can't figure out if it's, are the IT people understanding the business better or are the business people really understanding technology better? It's both.
It's absolutely both. I think that, um, good IT people spend the time to understand what's driving the business and the challenges they're facing and they frame the problems they're solving in business language. Similarly, great business partners understand technology and are able to translate.
And so when you have both teams coming together, um, that's when magic happens. And you know, when projects go wrong, it's usually because one team or the other is not meeting in the middle and someone's trying to compensate. So I do think both is happening.
I think that, you know, you talk to finance leaders, you talk to, um, sales leaders, HR leaders, they're all talking about technology and they want to understand how they can use ai, how they can use new tools to become more productive and meet their KPIs. And so there's um, definitely a vested interest in getting the right technology and that that makes life easier for IT partners, uh, because they're not trying to drag the business along. The business is in partnership with them.
Um, so I think it's definitely both As CIO. What is that number one priority for you right now? What's at the top of the to-do list?
What's the thing that you're like most focused on in the next few months? Well, definitely the operationalization of the plan I talked about today. Um, so we need to continue to deliver on that.
Um, but I think it's supporting the business objectives. I think, you know, number one, knowing and having a team that understands each and every day how we contribute to driving the outcomes of the business, the top priority. And that will translate into a set of activities the team needs to engage in to support the business, but it's not transforming this system or that system or introducing this new technology.
It's really tying our strategy to the business strategy and knowing exactly on a quarter by quarter basis, how are we helping drive the outcomes for the business. Um, that's where I want my team focused and that's where I'm focused. One of the things you will hear from application developers is they think that because of AI tools, they might be writing more software in the next couple of years than they wrote all last decades.
Are we from an IT perspective, prepared to deploy and manage that volume of software? Yeah, that's a great question. I think equally as um, developers become more productive with new tools, it becomes more productive in being, in terms of being able to, um, launch products, manage products and operations.
And definitely if you looked at the ratio of applications to um, resources, it's grown over time. So, uh, the, the capacity that you have is able to manage a larger set of applications because there's tools for deployment, there's tools for release management, there's automation around upgrades and so on. And so I think that, um, that value chain of having, um, automation and capabilities for developers follows through into how you deploy and manage.
So equally, I think that, that, uh, that landscape will grow for it. All right, folks, you heard it here. Hey, when it comes to IT, AI and being in this industry, there's more opportunity than ever.
Great man, once said, all we have to in fear is fear itself. And it's probably still true today. Hey, thanks for being on the show.
Thank you very much. All right, We'll be back in a minute. This is Textron tv.
Hello folks. We're back at Open Text World in Las Vegas and we're talking about reinventing the knowledge worker with my friend Lindsay. Lindsay, welcome Michelle.
Thank you so much. You know, I read this study just the other day and it surmised that the number of management positions was increasing and it suggested that the reason for this was because more of these AI agents needed to be managed. And so people are starting to reinvent some workflows.
And I wonder if the term knowledge worker itself is becoming obsolete because we're all becoming maybe knowledge managers. That's actually a very interesting way to put it. We haven't thought about it that way, but something that we're talking about this week is about the use of AI to elevate or reinvent the knowledge worker, right?
That, um, instead of our best and most talented people in the company spending their time managing information, um, you know, trying to work through these manual arduous tasks, right? That there is an opportunity for knowledge workers to leverage AI to put the information to work for them. Mm-hmm.
Um, so in, in the sense of, um, you know, what you said is, what was the term that you used? Knowledge management? Uh, Knowledge managers.
Knowledge managers, right? I think it's really about, um, enabling knowledge workers or knowledge management to leverage information in more powerful ways, right? I think also one of the dirty little secrets about this business in general is that there are people who are specialists, they have a lot of knowledge and they're working on their own projects, but everybody knows that they exist and they keep asking them questions that interrupt what they're trying to do because they're trying to be helpful with other folks.
Will it become easier to kind of distribute knowledge in a way that doesn't always require a human to sit down with somebody to do that? Absolutely. And, and maybe we can consume all this stuff in a better, more efficient fashion.
That's Exactly right. Um, the whole premise of Aviator, um, which is something that we've been talking about this week, is the opportunity to leverage interactive chat interfaces, natural language questions, to interact with information in entirely different ways, right? So when we think about really document heavy processes or aspects of the business where in the past somebody may have had to manually comb through hundreds of pages of documents, imagine something like that being as easy as just typing a question into a chat to get a nice consumable summary or an analysis of a piece of information, right?
That's just the beginning though. How are we gonna manage all these AI agents that are working on our behalf? I know you have like 15 of them now, or what you call, um, The aviators, Aviators, um, which are actually super sets of a hundred or more agents themselves.
Um, will we as humans be able to manage that workforce? And It's a really interesting topic and something that we've been excited to talk to our customers about. Um, many of the customers that we've spoken to this week or at different stages of their own AI journey, and whether that's at the start of kind of ideating the strategy, upskilling the workforce, or even going, you know, full through to adoption.
And, um, a big topic that we've had with some of those customers this week has been the topic of upskill in particular, right? Because the lack of, um, the right skills or the resources is often what's holding organizations behind from being able to take that next leap into ai. Um, so to your question, I think that there is, um, a lot of learning and we should all be ready to embrace new skills, and that's what's gonna help us take it to the next level.
I'm not sure looking at the agents what skills I need to learn because it seems like the agents are pretty, uh, simple to use. They're kind of, um, self-evident and I'm not, and I didn't feel like I had to become a prompt engineering expert anymore if I look at these agents. So we kind of move beyond prompt engineering now and we are gone to a higher level.
I think you're right. Um, it's been very much about, um, simplifying the knowledge work or that end user experience versus more of the technical, um, things that are happening behind the scenes. I'm a marketer, right?
So I'm, I don't claim to understand all the, you know, the deep things that are happening underneath the hood, but it is that simple in some cases. And, um, I think that, you know, again, it's um, there's an opportunity for all of us to be thinking about what the next jobs are that these AI tools or these, um, interactive chat interfaces are gonna unlock for us. Is it your sense that the folks that we used to call knowledge workers, um, are they excited about this or are they, is there a little fear in, in trepidation in, in the mix as well?
And how do they kind of navigate that? That's A great question too. Um, I think that, uh, there's an obviously an opportunity for AI to eliminate a lot of, again, those like manual tasks and that like, you know, the, the arduous work again, right?
That things that are holding us back from being able to do more meaningful work and make those strategic decisions. Um, but I don't think that we're at a point where AI is going to replace knowledge workers. It's really about taking them, allowing them to, to be elevated within the organization.
There's an old saying that says, if you do something enjoy, you never work a day in your life. Are we getting to that point now where we can focus on the stuff that's fun and all the other stuff that gets in the way will just be automated? That's The vision, right?
I think that's, that's absolutely the vision. So that again, those most talented people in your organization are no longer bogged down with managing information, but that they can focus on doing, um, things that are going to deliver, you know, it's innovating new products or it's, you know, expanding meeting new customers or expediting medical care, things like that, that are much more impactful. Mm-hmm.
Is there gonna be large scale re-engineering of some of the workflows that knowledge workers are tied to? Because it seems to me that I'm gonna have all these new capabilities and maybe doing things the same old way, it might not make as much sense. So are we gonna take a moment to kinda rethink all those workflows?
I dunno if we're rethinking the workflows as much as sort of re-engineering the way that they happen, right? So again, um, one of the awesome examples that we showed in one of our sessions this week was taking something as simple as a sales contract approval, right? And being able to use an interactive chat interface and natural language questions to actually prompt that workflow and then automate some of the things that are happening on the backend, such as when, you know, in this particular example, the document needed a certain sales director approval, right?
Once it was approved by that person, the AI is actually then taking it to the next step of being able to PDF and water market, right? So the step itself or the workflow itself is very much the same. It's just how it's actually happening.
That's that much easier for the knowledge worker. Do you think maybe eventually we might restructure organizations in the age of ai because a lot of the tasks are created and roles assigned to tasks are based on the fact that some thing had to be manually done. Well, if it doesn't have to be manually done anymore, can we maybe take a step back and say, Hey, what is your job description and, and what might that look like?
Yeah, I think you're absolutely right. Again, it's, um, not so much about replacing jobs, but freeing up knowledge workers for the next job, right? And that's, that's truly the reinvention of knowledge work.
What are you hearing from customers? What are they struggling with in this whole conversation? I mean, you've been walking around the show floor here.
What's the feedback you got so far? So again, um, we have customers at all sorts of stages of the journey. And the things that we're finding are most common from a, a challenges or limitations to getting started perspective is, um, again, the, the lack of, uh, sort of a formulated foundational strategy, um, having the right skills or the resources to actually implement that strategy.
But also, and perhaps most importantly, um, and why OpenText becomes so critical to this conversation is that data readiness perspective, right? And so where we come from in the content management, the document management business, um, and our customers who've been with us for a long time and they've, they've trusted us with their unstructured information, um, they're coming from a standpoint of grade advantage because they've already invested a lot of time, um, and effort into getting the information prepared, metadata and, and all those things that makes gen AI that much more impactful. One of the things I hear people kind of struggling with a little bit is that, um, the responses from the AI agents are probabilistic and they might not be the same over and over again.
And if you're a knowledge worker, you're kinda like, you know, driving a process that's a little more deterministic. So the fact that the thing tells you something that's similar but in a different way, kind of drives you crazy. Again, that's where, um, I think OpenText customers have an advantage where, um, we're through the concept of something that we call the business workspace.
You're curating information that's all related to each other, and by virtue of asking questions against documents and data that all are, are, you know, related to a certain use case or, um, what have you, that the results that you get back are that much more relevant and accurate. How do you think this will play out when I, as a knowledge worker will have my small army of AI agents and you as a knowledge worker will have your small army of AI agents and somehow or other we're all gonna collaborate together and to do something. How does that process work in your mind?
Because everybody's gonna have all these different AI agents? That's a another excellent question. Um, I think that that's something that we're still trying to explore right now.
And one of the things that we're hearing a lot from customers is, you know, how can we anticipate that all of these, um, AI agents, as you say, how will they interact? How will they interoperate? Right?
And so we have some really excellent partnerships with organizations like SAP Salesforce and Microsoft that we're really going to build, build upon and leverage to make sure that we can, um, deliver impactful solutions to our customers that allow for that AI to ai um, integration. Do you think I'm gonna have like one kind of senior level AI agent that manages all the other AI agents? Is this gonna be like Downton Abbey where there's a head butler Perhaps.
And from my point of view, content aviator could really be that head ai, uh, butler, if you will. Um, something that we actually showed this week, in fact was, um, content aviator, sort of the primary, uh, agent that you're interacting with. But, um, in the backend it also has its own, uh, a, uh, tool or, or agent also, which is knowledge discovery, which is another really powerful tool, um, or solution within our portfolio that does a lot of deep, um, rich media analysis and things like that.
So it is certainly possible. Can I ask you a question? Sure.
All right. So my favorite question to ask all of the customers this week was, um, okay, imagine every knowledge worker had an intelligent assistant. Um, what if you had your own personal intelligent assistant, what kind of impact would that have on your life and your work?
I think it would make me a lot more efficient, but I'm not sure I would use that time wisely to do something fun and leisurely. I would probably just do more work. 'cause it's kind of how I'm wired.
Um, so, um, but then again, my family might figure that out and they might be saying, you know, you don't have to spend as much time working on the weekends, so we can go do this, this, and this. So I'm sure that, for example, my wife will probably have an AI agent somewhere that figures that out for her and she'll just start scheduling stuff and she'll say, devil be damned. You're gone.
A scheduling agent would be the best thing for all parents, wouldn't it? Yeah, that would be kind of cool. Well, the kids will have one too, so then the kids will start scheduling things for parents too, so things can get a little kind of topsy-turvy and upside down.
Absolutely. Let me flip that question back to you. You're clearly on the front end of using this technology.
How has it changed your job, your daily life? What do you know what's different today than from a year ago? So, I'm a marketer again.
Um, we create a lot of content and one of the most immediate benefits that I think we're gonna see in marketing specifically is the ability to, you know, again, think about, um, we've managed a diverse portfolio of products and every time we launch something, there's new content that has to be created for those products. What if we could take, um, you know, release notes and things like this that are coming out of our product management team and leverage AI to translate that into marketing content, right? Content creation and content generation is an super impactful productivity gain that we're gonna see the benefits benefits from very quickly.
We have our own sales statement. We're constantly now yelling at them going, Hey, why don't you just create your own marketing collateral? Exactly.
Exactly. It's a huge enablement tool. And even when we think about emails and, you know, maybe I can get some creative inspiration and, you know, help get a, an, uh, a content aviator to write this email for me, right?
Learn, learn to do it in my tone and my style, right? And I think the tone and the style is a, a, an important part of this equation. 'cause in fact, we were just having this conversation with, uh, Alan Shimel who runs Textron, and I'm like, I see this content, but it needs more personality.
It needs you in that story, and it needs to come through there. So, um, I wonder if we'll go through a phase here where everybody will be like just auto generating some content and letting the machine do it not, but not adding that human element that makes a difference. And that's where, again, we can, it's a starting point.
And we, with our, you know, again, our skills and the knowledge that we have about the business can then come in and fine tune the result. It's all about just those quick productivity gains initially, I think. All right, so what's your prediction?
2025? How fast is all this gonna come? I mean, is is that knowledge worker gonna be reinvented next year or the year after?
How fast It's a journey and things are happening so fast. Um, it's hard to predict, but I think that we'll absolutely see from OpenText at least. Um, you know, once we get the, the, the phase that we're in right now again are like those quick productivity gains, automating, um, you know, some of these like, you know, common things like, you know, making information easier to find, right?
That's an easy thing for us to do. Um, breaking down content silos, creating or generating content, um, I would say by the end of next year, that will certainly have made some impactful advancements. The workflow automation part.
That's something that's gonna be really exciting to talk about next year. Alright, and last question. What do you know now that you kind of wish you knew a year ago about all this?
Oh, tough question for the last question. Um, I think that it's, you know, we're still, um, our customers are still on the journey, right? So one year later we've got, you know, every conversation that we're having is about ai and that's super exciting.
Um, we have customers that are buying it and trying it. Um, will we be at a point where everybody's using content aviator by next year? I hope so.
Um, but you know, I think because of a lot of the unknowns and how rapidly the, the market is changing, um, the technology behind it is, is evolving that, um, you know, we're, it's still, we're still learning as we go, right? Yeah. All right, folks.
Hey, you heard in here, instead of being a knowledge worker, maybe you become a knowledge manager and give yourself a raise. Hey, Lindsay, thanks for being on The show. Thanks so much for having me.
All right, And we'll be back soon. On this episode of the Tech Field Day podcast, we take a look at AI, specifically how AI tools can help your operations inside of enterprise it. The answer is quite simple, but more complicated than you might think.
Welcome to the Tech Field Day podcast. We bring together a group of IT experts to discuss an idea about key topics in the industry. And this podcast features a variety of perspectives from members of a Tech Field Day delegate community, and is often recorded in association with one of our events.
Tech Field Day is a part of the futureum Group, and this podcast is also published on our sister sites Techstrong tv. I'd like to take a moment for our guests to introduce themselves before we jump into the topic or the premise for this episode. Uh, hi, I'm Kerry Culp.
I'm a founding partner at Velas Span, uh, an enterprise mobility and cybersecurity consulting firm. Uh, my name is Keith Parsons. com.
Thank you Tom Ron Westfall, research director here at the Futurum Group. I lead our networking practice and always a pleasure to be joining a Tech Field Day podcast. All right, thank you all for joining us.
Let's jump into the premise for this episode. You've probably seen a lot about AI in the news recently, and you may be confused because AI is everything, but it's also nothing. And when something is everything and nothing, is it really anything at all, the key is to figure out what AI can help you do.
And that's why we brought together some professionals today to talk about this, because it turns out AI has a lot to do with the way that we do our jobs, especially in the operational side of enterprise it. And we need to get a handle on what that is. The premise for this episode is that AI can help with operations.
Now, I'll be the first person to admit that last year, 2023, everyone was talking about putting AI in everything. It all had to be AI enabled. There had to be LLM support for my recipe application.
And it's dumb. Let's, let's be fair. I I don't really need that.
But as things move along, we have found ways to use specific aspects of what AI is capable of doing to make our operational lives easier. So I kind of wanna open up the floor to you gentlemen. What are some ways that you have used AI in enterprise IT operations to make your lives easier, Like probably everyone else?
Uh, as you said about a year ago, we kind of dove headfirst into ai, generative AI as a concept and understanding what it can do for us. Uh, obviously we've had exposure to AI for quite a long time, but generative a AI tools really kind of changed the dynamic quite a lot. Um, we quickly realized that, like you said, it's everything and nothing all at the same time.
Um, but fairly quickly we started to evolve how we engaged with it, and we really learned that it's good at a lot of things that maybe humans aren't as good at. Analytics is an example. So feeding it large data sets and letting it parse those data sets and pull things out of 'em that are meaningful, or I, I search for those meaningful items.
I think that's how we pretty quickly figured out where AI can help us. So from that perspective, um, log file analysis, pulling logs, feeding it into, uh, generative AI tool set, giving it some parameters, giving it maybe a, a, a persona that we'd like it to adopt and helping it help us identify trends or anomalies or errors or warnings or something like that in that log file, which could be millions and millions of lines of data that would take us, you know, mere humans hours and hours to parse it does it nearly instantly. It's not perfect.
It doesn't necessarily land on exactly the answer, but it is so much better than starting from zero. It just gets us down the road farther faster, and then the brains have to get in involved and, and really dig into it. That's gold, Carrie.
'cause, uh, what I am seeing is that AI can do just what you're pointing to that is improve the workforce experience, and that includes, uh, making operations more efficient, automation of data gathering, uh, getting data insights, and also quite simply improving business outcomes. And this is the good news part of ai. Yes, there's challenges.
It's still, you know, the data and data out challenge. It's been with us for decades. AI is only good as the data management tools that you have in place, but it's still, we're seeing, I think, tangible improvements in outcomes.
Uh, for example, uh, by using AI powered predictive maintenance models, I've seen that there could be up to a 30% reduction in unplanned downtime and also like, uh, up to a three-four improvement in service resolution times. And this is data coming, you know, that's, uh, readily available. It's like, uh, that source was field acts.
Uh, and, but I think the bottom line here is that AI is going to deliver more good news and bad news is not going to be this technology that's gonna cause in itself widespread, uh, reductions in workforces is going to actually improve the experience for the workforce. And it's really the outcome is that whoever can leverage AI the best is going to quite simply have a better workforce experience and also improve, you know, what the business can do. Uh, well, I I, I like what you said, Ron.
I just wanna add, add a little warning caveat. One of the things I've seen the AI can do is very quickly solve the easy problems. The ones that, that, that an experienced person would look at and go, yeah, I got that.
So it starts doing those easy ones, meaning IT professionals who are working on a system don't have experience on those little things that, that, that break and that you get really good at fixing all the time. And it's kind of boring. So it takes that away.
And what happens though is it's now AI is fixing so many of the issues that the issues it runs across are really difficult. And I'm, I'm concerned that practitioners won't have that, that baseline understanding by the time it gets to a really what AI can't do, no one has that experience that that, that all of us old folks have that we've, we've figured out over, over the years. So there is a little gap in between there.
One of the things I've tried is using AI to do packet analysis in, in wireless, we have to point the finger at someone. And if it's not the client, it's the infrastructure side. And neither of 'em will admit until you can say, look at this frame, did this thing and yours did the wrong answer.
Finding those is really difficult. It takes a lot of experience to, to get into the packet analysis. Ai, even in packet analysis, can take you like cor like Kerry said, 80% of the way there, but that last 20% is even harder than it was finding the other.
So I, I, I agree it can help the workflows a lot, but that last little bit is still even more difficult than it was before. So, a thought there, Keith, because this is something I hear a lot from people who are starting out in the industry that, you know, why am I solving this problem over and over again? Why, why can't I automate this?
You know, uh, if there's an issue with a service not starting, is there a way for me to basically say, okay, if if I have to wait five minutes to start the service until the system reboots, then why not put a timer on it? These kinds of simple things. Now, obviously you have to understand the underlying infrastructure to know, well, why does the servicing to wait to start?
Or something like that. But I think kind of coming back to it where you said, being able to do like log analysis or packet capture analysis, like, like Carrie you were saying as well, um, is giving our people a chance to focus on those hard problems. Maybe they do need to spend a little bit more time studying so that they understand seeing this log entry followed by this log entry that's correlated with this other log entry means that this is this problem.
But at the same time, by being able to correlate those things together and feeding that feedback back into the system, we're effectively making the AI tool smarter by saying, the next time you see this pattern, this grouping of messages, it's indicative of this problem. So we're, we're basically training ourselves to make those problems easier to spot because we're using knowledge that can be gained by filtering out the noise effectively. Yeah, and I think, Keith, you, you touched on a problem that I don't know that I really ever put into words.
It's a, it's kind of like a future problem, right? If we're not, if we're not letting the junior engineers fix those simple problems that would be, would start to form the foundation of knowledge that they need to dive into the deeper, more complex problems later, that probably really is a bit of a, you know, down the road, let's say expert shortage, you know, foresight that we might, we might have. Now that said, I, I think, uh, so for us, we are using it a little less to solve problems and a little more to speed up the, an analysis.
So it's, it's less to say, tell me what's wrong and more about giving it a, a set of parameters for what we're trying to identify and helping it parse the data or having it parse the data for us. Another use case that we're, we haven't actually really nailed down just yet, or, or gotten it to work quite right just yet is for change management. Because we do, we do an awful lot of large scale enterprise deployments that will often have us making large scale, potentially very impactful changes to big fortune 25 kind of companies networks.
Well, when we cause a sev one incident that's not great, that doesn't look good, right? So we're working on kind of building out a, um, uh, a not a model of its own, but effectively, let's call it just a GPT of its own, where, where we can use it to feed in information about the current state, the change state, the change, the, you know, the, the projected changes and have it help analyze whether or not we're going to introduce a problem. And I think that hits a key point about, you know, what is down the horizon.
I think Carrie, uh, that's very, uh, valuable to bear in mind what is going on to make these AI models better, particularly on the training side, but certainly also on the inferencing side. So we're seeing RAG capabilities join with the vector databases to do that specific, you know, customer aligned, uh, language model training so that the data sets are truly correlated with what the business actually needs and can then be automated and then, you know, make everything else run quite simply smoother. And yes, uh, to Keith's point, it's always going to require that balance between here is the AI enabled capabilities, but you still need a human safeguard or fail safe, okay?
The AI engine comes up here is something that is an emergency, something an anomaly, uh, something that needs to be looked at. Do you want to authorize this recommended fix? Or is there something else we need to do?
The bottom line is AI is inevitable. I mean, we're seeing all the investments flowing in that direction, and we just have to figure out how to optimize these AI capabilities, you know, throughout the organization. So I, I wanted, I just wanna interject there one quick thing.
Ron, you, you made a really good point, I think about that. You know, having the human involved, one thing that we did before we even allowed our team, or, or anybody inside the organization besides a couple of us that were testing things before we allowed them to use it, we implemented an, uh, generative AI acceptable use policy. And that basically dictates the framework with within, you know, that, that, that our users have to work within to interact with generat AI tools.
And probably the key tenet of that policy is that you, the human, are still accountable for the output. So it's not, it's not the ai, it's not the tools, it's not the GPT that you used. You can't point back at that and say, that was chat GPT or it was Claude, or it was whatever that made the mistake.
Nope. You, the human are still accountable for the output. You need to review it.
You are the expert. You need to make sure that what is coming out of that and what you're then putting into whatever, whatever format is going outwardly is actually accurate and true. We also set some rules around how you can use it with regard to imagery and things like that.
You can't use it with real, real people's images. You can't use it with anything like that because we're trying to kind of put the guardrails up that keep us, you know, from, from doing silly things that, that we don't want to have happen. Those, those are good things, Carrie, for your business entity, yet I see vendors moving past that.
They're taking the, the human out of the loop, especially for the low tier things. I, I need to change some, uh, channels to fix a problem. So its, it fixes itself.
It then does a pre and a post, did clients improve after I did this or not? And then it sticks and it goes, and there's no human in that loop. So I, I, I don't think we want humans in all of the loops when the AI is smart enough to know, and when they train it on their own vendor code, their own vendor data sets, they get, they get really accurate at the good stuff, at the easy stuff.
So I see that a lot of vendors are moving away from that. The human's not in the loop on the easy pieces. And that human only comes in when the AI doesn't have data to support.
We did this automatically. So I, I don't have any fear of the AI doing automatic things. Um, when it's the vendor's ai, 'cause they have, they have way better data because they trained it on their, their own internal thing.
Some vendors are even using it to write their own code that because we know how we code and we have all these little things done, we can have it on the fly, build something. Um, and an example, homina built a tool to do wifi design in AI in mere minutes. Now, it was not even close to, I wouldn't even say 80%, maybe 50% of the way there, but AI self coded itself.
And then they went, well, we'd also like to add heat maps, and within a couple minutes it was adding heat maps. So there, there's things that can do that can give us better tools that the human can use, but it can also do solve the easy problem. That's where I want to focus on yes, easy problems.
Let the AI do it. I don't want to have it bug me every time. You know, a door lock changes, just, just fix it.
So who's the, so the question ultimately becomes, uh, is so, so with a lot of our customers, you know, these are massive enterprises that have really comprehensive change management processes. They have to go through the, you know, the cab and get approval and they have to have rollback plans and everything else. And, and I don't think, while those organizations are almost all using generative AI tools, at some level, I don't think they've matured enough yet to turn over change management to something fully automated.
I guess it Change, it, it depends on what we're talking about in change manage. I, maybe not, not switching VLANs around, but changing a channel on access point. We've been having that automated for years now.
Yeah, maybe changing power settings, changing whether or not we, uh, I, I saw one where the MCS rates were at a certain average, and then we would change automatically the data rates that were supported until that dropped. And then you change the data rate back down to get the maximum throughput of your airtime. Uh, I used to do that manually and it took hours on site.
And vendor, vendor AI can do it really, really quick and have that feedback loop that said, we tried it, things got worse, so we put it back. That's exactly what I would do personally over a long period of time. And yet AI has way more dataset data to make that decision than I would, and I really don't wanna do those dumb things anymore.
So in, in, in the important things that could cause major failures, I, I see what you're talking about, but there's a lot of pieces in our networks that just need to be tuned. And I think that's an important point, Keith, because when you look at the way that things like LLMs and, and current generation AI work, it's very much focused on correlations, right? I we see this, which means this, or you know, more appropriately for a thing like an LLM, statistically speaking, this word follows this other word in a chain of words.
And so there's a strong correlation that this is a sentence you wanted to type, but one of the reasons why that works so well is that you're getting feedback, like you said, tune this and if it doesn't work, turn it back because obviously that didn't work and then the AI eventually learns, okay, that's a bad correlation. I shouldn't recommend that anymore. But how can we as practitioners avoid those kinds of traps?
Because we can see tons of examples of people just reading through the output of chat GPT for example, and saying, oh, well, I'll just go ahead and do what chat GPT said, because obviously it's brilliant. And as, as Ron alluded to, hallucinations are still a thing. Whether or not you are using rag, you have to know, wait a minute, configuring that command or doing that thing is kind of like putting Elmer's glue on my pizza, even though the system says I should do it.
I know better than that. How can, how can we train people to effectively avoid those traps? Well, I think part of it is chat, GTP or clot are the big LLM models that are more generic that they've been, they've been trained on some huge, you know, everything that's ever been written on the internet compared to a vendor's own model that's only looking at its own dataset.
And the one things I, I'd like to begin up and get Kerry and Ron's feedback, what do you think about digital twins? Where I, where as a vendor, I know the whole code. I wrote all the firm where I know where it is, I'm gonna make a digital twin of that and let AI play all day long, and then it's not gonna hurt the real world.
And then maybe the result of that has the human back in the loop to make the big changes. I, I like that it can do things really fast. I I just don't want it to do it and break real systems.
Yeah, that's music to my ears. Digital twins, uh, I think we have all firsthand experience with it. GPS maps, you're able to get that real time interactive information and then act on it accordingly.
Ultimately, you have to use your own experience to enhance that information that's being provided to you by, you know, an AI capable or AI enhanced, uh, engine, uh, or platform. And I think, uh, what's also important here is that I think it's about right sizing the model. Uh, that is absolutely right, Keith.
It has to be according to the specific needs of the customer, of the vendor and so forth. And well, ultimately, yes, you know, the, the broad based LLMs will become smarter reducing hallucinations to the point where, uh, say a year or two out from now, they could even be natively not requiring a rag or vector database capabilities because of all of this intense training that's being accumulated, just getting smarter and smarter. So I think all these will be, uh, factors into answering Tom's question.
Yeah, I think so Keith, the digital twin piece is really critical when with it, sticking with the concept of change management, if we have a digital twin that we can let the AI kind of turn it loose on that and let it do its thing and, and then we can actually start to work up the chain to more and more complex changes because it's not breaking anything. I mean, it might break something in the digital twin, but that's okay because it's just the digital twin. If we can use, if we can let it work its way up the chain there, prove out that it's working and it's not introducing problems, let it go on, let it run that same process on the production network at that point.
I think that's where it really gets to the point where it can be more autonomous. It's still kind of, it needs that human oversight, I think, you know, to make sure that for the really big impactful things that nothing's going sideways. But then if we have that digital twin and it doesn't break that, turn it loose on the production network and let it go implement that same thing, Or even multiple digital twins that are iterative and it could, like, like chess playing AI from a generation ago, it goes down a path until it breaks, it goes down another path.
We, we could let it run across a hundred thousand, 10,000 digital twins and run it for a year or two years into the future. And it, it's all about how much compute you have to pull that off. Nvidia Liked that comment And, and I agree that a lot of companies that are kind of focused on the AI aspect of things are leaving off that digital twin capability, whereas companies that are developing digital twin technology are finally starting to embrace AI to kind of augment what they're doing.
In some ways. They're using current generation AI for things like querying for network information and stuff like that. But obviously that next step is going to be offering capability to do stress testing or to do, uh, change management and things like that.
Do you foresee a time though where we will get to a point where we trust the AI enough to turn it loose to say, okay, if the change checks out here on your digital twin, go ahead and implement it in production. And this kind of goes hand in hand with what Carrie was saying about this generative AI use policy. Will we ever trust AI enough to say, I'm ready to let you kind of run the show at a certain level of confidence with non-complicated tasks?
I I think it's, the definition is the non-complicated task. The other thing I just wanted to throw out and see, I think this is an advantage for NAS vendors where they own the whole stack. They can run a digital twin from soup to nuts the entire thing.
Whereas in the real world who people who are aren't with, with a Nile or a meter or a ramen or something, you have, you have a heterogeneous stack and there's a breaking point as it switches vendors. So their digital twins are way more complex as, as it changes vendors in the stack. Those that hold that own the whole thing have a little advantage that their digital twins can be fairly accurate 'cause they own everything in there.
So, so Tom, I I wanna answer your question specifically. I think there's two parts to your question or two answers to it. Will we ever trust AI enough to let it go?
Depends who we is in that statement, right? Yeah, I think, I think to some degree, yes. That and, and that will progress further and further through the population who the we is is representing.
On the other hand, I think there's going to, there is going to be a, probably the biggest hurdle or biggest roadblock to just enabling us to do that and to trust AI to do things is going to be more of a legal question. Who's accountable? Who do I hold responsible when this thing goes sideways?
Now, is it, so if it's inside the vendor, pick the, you pick the vendor that's running some AI tool set, well then the vendor's responsible, right? It's, it's their, their AI is their tool, it's their network, they broke it. But what if it is a third party or maybe, uh, uh, not even one tool, maybe it's a, a, a mix of tools that are doing things, who is actually held accountable for it?
And I think that's the kind of what I was getting to earlier on with regard to the cha, you know, getting a change approved, getting it through cab, making the changes and, and making sure it, it, you know, everything works. We are responsible for that. And if something goes wrong, the fingers get pointed at us.
We have to accept responsibility. We have to, you know, we, we, we get called to the carpet and have to fix it and explain why it went wrong if we just turned it over to a trusted AI and it broke something who's ultimately responsible. And to follow on that, I think, uh, winners, uh, from digital twins and, you know, AI capabilities include the cybersecurity realm, basically, it's essential.
Uh, this is the week of Black hat, and we saw like the announcements are cybersecurity is going to require AI capabilities just to be able to, you know, make the good guys help fight that battle. And for example, we saw HPE Aruba networking coming out, uh, with the audition of NDR capabilities and ZTNA enhancements, and that puts a spotlight on network detection response and zero trust basically are gonna require these digital twin capabilities and then these AI capabilities just to stay on top of the telemetry, uh, particularly when it comes to proliferating iot devices, which are notorious for being, you know, targets, uh, real cybersecurity threats to an organization. And so this is coming together.
This is demonstrating why ai, you know, why digital twins, well, certainly cybersecurity, I think, brings that to the forefront. Yeah, I'll, I'll second that. I mean, we, we look at it, uh, from our cybersecurity practice viewpoint.
One of the biggest challenges that we see in the industry is that the r in all of the, you, you say whatever the, the EDR, the NDR, the, the, you know, MDR, the XDR, the r is lacking in all of them. The response is truly lacking across the board. And if we can start to leverage AI first to help on the detection side, so on, on the, the detect and identify the threat or the breach or whatever it might be, but to the point of then trusting the a AI to participate in the response, theoretically, the response starts to, to get better and, and more, uh, let's say more responsive.
Well, as you can hear from the discussion, there's a lot of potential with generative AI tools being used to support operations in an enterprise environment. The key, of course, is that you use AI like any other tool that you would use. You need to have a firm handle on how it operates.
You need to find the best possible role for that tool. And you need to create guardrails policies in place to ensure that if something doesn't work, then you are not left with a giant blast radius. And as the tool proves itself more and more capable of doing things, you can widen its scope, you can add additional, uh, capabilities that you are adding to the policy to make sure that your employees are using it to its most effective capabilities.
Maybe one day down the road, AI will take care of all the easy stuff and let us focus on the hard things. Or maybe you find that AI isn't a good fit for your role, whatever it is, you're gonna have to do the groundwork to make sure that you're using it effectively. Don't believe the hype, believe what it can do for you.
Thank you for listening to this episode of the Tech Field Day podcast. If you enjoyed this discussion, please subscribe to our YouTube channel or subscribe to the podcast in your favorite podcast application so you don't miss an episode. Make sure to leave us a rating and a review.
This podcast is brought to you by Tech Field Day, the home of IT experts from across the enterprise, which is a part of the Futurum Group. com/podcast or check out some of our episodes on Techstrong tv. Thanks for listening and we'll see you next week.
Welcome everybody. Uh, I'm Pete Garon, director of Products at Active State. And today we're gonna talk about, uh, taming the complexity of open source with active state.
And you probably know a little bit about active state. Uh, we've been around for over two decades. Uh, we're currently helping 97% of the Fortune 1000 secure their open source.
And we've been around since the sort of late nineties, uh, when we started doing, uh, Pearl on Windows and doing that port, and we sort of, we were also a founding member of the PSF. And we've been working with, uh, enterprises to help, uh, manage their open source for the better part of those two decades. And one of the things we've done recently, uh, we partnered with PI PI on a trusted publishing initiative.
And as over time as things evolved, we went from doing things like Active Pearl, active Python, uh, where you might just download a sort of curated distribution of, uh, open source and open source packages to something where instead, what you're doing now is having a tool to manage all of your open source. And so what we did was we evolved, uh, our product first to meet our own needs, uh, internally in terms of what we were doing to manage open source for various enterprises, and instead move that to a product where all of our users could use this and to sort of help them manage, uh, all of that open source and tame bit of that complexity, uh, around what's involved in managing open source from the ingestion point all the way through to the, uh, deployment stage. And so one of the things is when you're not managing unmanaged open source is exposing you to sort of escalating security and license threats.
Uh, supply chain threats and managing this stuff at scale is really challenging. Uh, you know, it's one thing to know I've got a vulnerability in this package, right? I've got, you know, my, my s e's tool is telling me, oh, yeah, you've got a vulnerability in this package package, you need to update that.
But it's another thing to actually successfully update that dependency, all of its dependencies. So everything, all of its transitive dependencies. And to ensure, like the providence of all of that stuff that you're ingesting, you know, dependency hells a real thing that can really consume a lot of developer time.
And knowing whether that is a breaking change or not, how safe is it for me to update that? It's really, really challenging. And so just that, uh, that element alone is really, really simple.
I'll just say that one again there. Just managing, bringing in the updates alone is really, really challenging. And then we move over to observability where I can even understand what I'm using in the first place, right?
I'm a large organization, I'm running thousands of pieces of open source software. Is that cataloged? Is it versioned, auditable, reproducible?
Where is it running? Who's running it? All of that is super challenging.
And if you don't have systems in place, it can be very, very painful. And then on the other end of things, if you're trying to comply with, uh, government regulations or security audits, do you have tools in place there to actually develop and deliver the, uh, artifacts that you need to support the security guarantees that you're giving, right? Can you produce the documentation, the chain of custody information to be and be able to verify that and supply it when needed?
All of this stuff is really, really complex, uh, and it's very, very rarely, uh, an end-to-end solution. And so it's really, you know, it's no, no wonder that there's a lot of shortcuts that are being taken and, uh, people are shipping with known vulnerabilities or they're doing a lot of ad hoc things. And that's really what we see is that people are really stitching point solutions together.
Uh, they're, they're maintaining spreadsheets. They're, uh, running an ad hoc report. Uh, they're doing, you know, audits on demand, very reactionary, uh, you know, they've got solutions that are kind of diffused throughout the organization department.
There's no standardization. Um, you're managing all these different, uh, upstreams, right? You've got source code, you've got vulnerability DA databases, you've got vulnerability scanning tools, you've got container registries, you've got licenses, you've got SBOs, you've got all these different tools, all these different processes for each one individually, and they're probably largely duct taped together.
They're not pro brought together in a coherent, cohesive way, and they're really only partially addressing the solution, right? They're not seamlessly stitched together. So one of the things that we've seen over the years is that you really do need to think about this holistically, especially when you're thinking about supply chain security.
And so what we're doing at active state, and what we're sort of talking about today is like, what's, how do you tame that complexity of all of this stuff? How do I deal with all of those stages across my software development lifecycle in a way, uh, that is systematic and reproducible and auditable and understandable and also low friction for those inside my organization? So what we're doing at ActiveState here is sort of bringing our, our, you know, decades of experience with o open source management to bear and to provide a kind of holistic solution.
And so let me sort of walk you through what that looks like here from the discovery of everything that's running inside your org, right down to the deployment. And so we saw before there's an open source ecosystem and maybe your even your own private ecosystem, and there's a lot of information that's out there that you're pulling from all these different sources, and you also have a lot of open source that's running inside your organization. So the first stage is really about discovering that, right?
It's about discovering and cataloging all the open source that's running inside your organization. So discovering it from various sources, uh, knowing who's running it and where having a kind of auditable inventory, we'll see that this, this notion of having an auditable inventory is really important. Um, you know, having a spreadsheet of all the open source that's running, probably not gonna cut it, right?
Having a diffused set of requirements that TXT files or for whatever language you have diffused across your source code repo repository, also probably not going to cut it. You can't do any kind of sophisticated reporting against that kind of thing. And so then we move on.
Once you've discovered, once you even know you can't even begin to manage what you're doing, if you don't know what you're running, then we can move on to the analysis stage where we can gain insights into the risk profile and generate some reports and share that intelligence across the organization, right? When you have, you know, a DevSecOps, uh, scenario where you've got collaboration happening between development and security and, uh, DevOps professionals, you need to have, uh, ways to share information across that organization and to collaborate effectively. And so the first thing you need is analysis of all that stuff that's running.
So you need license and vulnerability reports. You need, what's the impact of taking this upgrade, right? Do it, does it have a breaking change in it?
Do I have all of the, uh, supporting artifacts that we talked about from the compliance standpoint, you know, in terms of SBOs at stations, all that stuff. But then once you have the analysis, okay, now we have to take an action, right? We need to do something about it.
We have to remediate the issue, or we need to get it deployed, or whatever. And so then you need to have tools in place to be able to scale that across your organization. So, uh, once I, once I'm taking the action to remediate something, I need to know, first of all, do I need to remediate that?
Does it, does it hit the threshold that we have to remediate? And do I have tools in place? So whether that's policies to be able to say, um, we don't, we don't want, uh, any vulnerabilities inside our organization that are, uh, you know, higher than a high, we don't want any criticals or highs inside.
But then do you have the ability to scale that across all of those upstream sources, right? So we start to think about having a curated immutable catalog where instead of drawing from all of these various, you know, unsecured, unmonitored, uh, you know, public sources, that we can have our own curated catalog where we have control over what's in there, and we also have the ability to, you know, enforce that across our organization. And then finally, okay, great, I'm gonna download, I need a new version of my package and I need to go from version one to version two, but does it build, does it work with all of the other, uh, dependencies inside my, uh, inside my project or, uh, you know, in my deployment?
And, and so what we've done is we've had, you know, two decades of experience building open source, and we have, you know, a very powerful, uh, build cluster where we can build things in hermetically sealed containers with guaranteed provenance. Everything is built from source, and we can integrate with your systems to be able to, uh, deploy, um, in whatever scenario you have, uh, whether it's a container or whether it's just a, a simple application and getting that into your organization. And so then we get back to the beginning, and now, instead of discovery, we're talking about monitoring on an ongoing basis, knowing what's running inside your organization and being able to keep up up with that, whether there are changes, whether you need to, you know, emerging vulnerabilities, I need to remediate that, get it redeployed, rinse, and repeat across the cycle.
And so this sort of holistic end to end where right from the discovery, right from the source code all the way through the intermediate artifacts in the building, that kind of holistic end to end is really, uh, key to, uh, sort of taming that complexity and to having something that is a reproducible, uh, simple, understandable collaborative system, uh, across your organization. And so, when really what we're talking about is various set of different use cases where we're talking about, you know, the idea of continuous open source integration, how, how quickly can I get new versions deployed within my, uh, organization? How quickly can I get new versions ingested into my pipeline?
How can I ensure that my different environments are consistent and reproducible across my entire organization? Do I have the tools in place for effective governance so that everybody's pulling from the same catalog, everybody's pulling from the same set of trusted artifacts? Do I have insights into all of the usage across my organization?
Do I have insight into all of the places where things are deployed? Do I have the tools to be meet regulatory compliance, right? Do I have those, you know, those SBOs, those attestations, those type of things?
And do I have, uh, support for things that are going beyond the community supported end of life? So if I need something, uh, supported beyond that, do I have a a catalog that supports that kind of thing? And then we're gonna kind of jump into that, uh, today and sort of show you what that might look like actually in practice.
You know, I showed you the little diagram here. I talked a little bit about the process, but let's talk about what that actually seems like in practice. So I'm gonna jump over here.
Let's say that we have a, a little environment where, uh, we wanna discover everything that's running inside our organization. We, it's gonna live in a lot of different places, right? It might be in a Kubernetes cluster, right?
It might be just in GitHub, basically, oh, we've got all of our, our requirements files and, and, uh, dependency manifest files across various projects. In GitHub, it might be, we might already have a bunch of SBOs and we don't know really what to do with them, but they can be a very valuable, uh, tool for understanding what's running inside your organization. So we can get directly from our requirements file or an SBO from GitHub from, you know, helm or Kubernetes.
And so let's say, we're just gonna say Kubernetes here today. So we're gonna scan our Kubernetes cluster, and here we discovered that we've got a number of sort community images that are running here. We've got Postgres and Nginx and Spark and Elastic search.
And, but what's inside of those things, right? It's one thing to know, okay, yeah, I'm running Postgres, but what, you know, what's actually inside that? And so our tool can analyze these dependencies and vulnerabilities and give us information and intelligence right down to the system level.
Like you really need to understand, it's one thing to know that, uh, you know, I'm running TensorFlow, but there's a whole bunch of C libraries that underpin that, and that's where you sort of, that's where a lot of the vulnerabilities that tend to be is in languages like c in those type of, uh, libraries. And so what we've got here is we've got an immediate analysis where we can get that information at a glance. So, you know, across my little, uh, pretend organization here, uh, I've got six Docker images running, and 47% of that is C code.
There's 1,099 C seed dependencies running there. I've got a bunch of Java, some go, some Python in there. It's given me a vulnerability profile that's showing me, uh, here's, I've got 14 criticals 136 highs.
I've got a profile of the different licenses. So at a glance for my organization, I can see what my risk profile looks like, and I can do things like download a CBE report or download an SBO m But the key thing here is that I've discovered at an early stage what open source is running and what its composition is, and, uh, you know, sort of what my risk profile is here. And I can see some more details on those things, but we sort of covered those first two boxes.
We've got a thing where we've discovered, so now we have that, and we've also, you know, pre presumably got something in place now where we can monitor this on an ongoing basis. But then we've also got some analysis here where initially we can see what our composition is. Okay, well, we've got a lot of vulnerabilities.
How do we upgrade that, right? How do we go from, you know, 1500, um, vulnerabilities to something that's, that's less, right? And so what we can do is generate something, uh, a remediation plan, right?
We can get, we have a lot of information in our catalog, right? We're, we're going out there and we are ingesting a lot of these public ecosystems. We're pulling in all of pi pi, we're pulling in, uh, all of, uh, you know, uh, the pearl ecosystem.
We're pulling in all of the Java ecosystem, et cetera, et cetera. And we have all of this information around versions. And so we can say immediately here, you know, what, before you had 150, after you're gonna have 188, here's what you can do.
We can also give you some additional intelligence, uh, around the risk profile here. But, uh, essentially what, what we can do is show you that we can remediate all these things. They're relatively, uh, low risk right now.
And so then what we're going to do is we're gonna take those things and we're gonna import them into our platform and manage them as projects. So each one of those containers that we saw before now becomes a project on our platform, where now I have a, a contained unit where what I can do is manage that over time. I can configure that over time.
I can see the auditable history of that. So let's say, let's pop over here and see what that actually looks like. So this is a, a little demonstration organization I have here where I've got, uh, five projects, 468 dependencies, mostly go and Java here, and a number of vulnerabilities.
But each one of these things represents either a container that's running in my, um, cluster, my Kubernetes cluster, like we saw, or maybe just a basic, uh, project that I created. So in this case, like, um, my a basic Python project. And what I can do is I can manage the dependencies individually in those things.
I can also browse them at organization level. So, you know what, if I'm sitting there and I'm in my, uh, an organization, I'm like, I hear about some critical vulnerability. Do you have a index of all the open source that's running inside your organization that you can very quickly, uh, you know, inquire and say, am I exposed to this?
So let's say we hear about something log four J and we type that in here right now across my entire organization, I can type that in and immediately see that, well actually I have this thing log four j append that's running in one of my containers here. It's running in this Kafka test container. And so maybe I should go and investigate that, right?
And I can drill into that exact project and see the details. Um, and that project will then I'll, I'll be able to configure that. I can also see the vulnerabilities across my entire organization, and then I can go in here to my project and configure it.
So let's go like a really simple example, uh, with the, uh, Python, and let's take a look at what that, how that actually manifests. So let me just quickly turn that off. And, um, what you see here is, here's this, the packages that are in my project.
So in this case, I've got a very simple web application, safe flask and pillow. And this is sort of maybe running out there on my cluster somewhere. But I've seen here that I've got vulnerabilities, I've got a critical vulnerability here.
I've, uh, four highs and I'm getting in. I, I, so I'm inspecting what, you know, what the problem is here. I've got a couple highs here in the Python version as well.
I can see my, all of my dependencies all the way down here to the system level. I can see, you know, not just that, you know, flask brings in blinker and click and flick, it's dangerous and stuff like that. I can scroll down here and see right down 11 LZMA and the system level C libraries.
So I've got sort of unprecedented visibility right down to the deepest level. But then I can go and I can remediate these things very simply. I can say, here's what one is not vulnerable.
I'm on Python nine, uh, pillow nine 10 while I'm at one critical four highs, I need to pick one that doesn't have a vulnerability. Because we are ingesting all of this open source into our catalog. We're building it all from source.
You've got a trusted upstream for essentially all of the, you know, open internet. So rather than going into a situation where you are, um, managing 50 different upstreams, you can say, well, I'm just gonna point to, uh, active states trust catalog for everything. And I can choose that version though from our catalog where we know that that doesn't have any vulnerabilities.
So we're gonna say fixing vulnerability here, then we're gonna save those changes. And now that's been changed to, uh, to the non vulnerable version. It's gonna resol and refigure out all of the things that are in there.
But one thing that's interesting that is a critical piece of the puzzle here in terms of taming the complexity of your open source is the idea of that change management auditable history that you saw me do. So I logged the change. So here, rather than me just editing a text file and committing that, or you know, just installing it on my developer laptop or something, what we've done here is kind of merge the concept of source control with dependency management, where I've got the, you can see here, here's my base project that I created.
Here's an initial commit with flask and pillow. 4. And you can see that at any point, I can go back in history and revert to this commit.
I can generate an S bomb at any point in history. So I have a fully auditable chain of custody here where I can see that, you know, Pete made this on October 24th at this exact time. Here's the commit id.
It's fully reproducible. And unlike you can see here that we also have this catalog revision id. And unlike the sort of public repositories where if I run, you know, NPM install on a Friday, and I run N-N-P-M-N-P-M install on a Monday, I'm gonna get a different result.
But what we are doing is we, we're revisioning the catalog every point in time. So it's fully reproducible. So not only, uh, is this saving the state of your dependencies at any point in time and all the open source that you're using, it's also saving the state of the world at that time so that you are fully reproducible, fully auditable from end to end.
The other piece that you can see is that what it's doing is it's kicked off a build in, in our cluster, where it will be building this, uh, from source, these individual packages. 4. It'll be building that from the source in our cluster here.
And so you can see as well, our critical went away over here on our total vulnerabilities, and it's rebuilding on Macs here. Those things get rebuilt completely in, uh, uh, in hermetically sealed containers and completely, um, in a completely reproducible way. You can get SBOs for all of those things.
If I go to my overview here, I can see I can generate things like an SBO for this. I can download a vulnerability report, I can do collaboration. But the key thing is that what we're doing is we're taking stuff from the beginning where we're discovering all the open source that's running in our organization.
We're then doing some basic analysis on it to give you sort of, uh, the breakdown of the inventory, whether it's go or Java or C or Python. We're giving you the high level rollup across your entire organization of all the vulnerabilities. So you have that initial analysis stage, then we're giving you the tools to be able to curate those things and manage a catalog, have a fully auditable history to give you the sort of, uh, governance tools that you need to be able to curate that.
And then the tools to be able to build, deploy, and redeploy that. And so I think that that key cycle there, where you have end to end control and visibility on everything that you do, whether it is, um, just discovering what's going on in your organization, all the open source that you're using, cataloging that in an auditable database, then being able to do analysis, collaborate with across your organization, across your, uh, development team, your ops team, your security team, to be able to then curate that, upgrade it seamlessly remediate as we just saw. And then build and deploy that, whether it's integrating with your CICD to get deployed it out, out to your, uh, cluster or whether it's just on your developer laptop, to be able to keep working and streamline that development process.
Having a system that streamlines that entire process holistically end to end, is really important. And that's sort of our vision for how we should be sort of simplifying and streamlining and tame taming the complexity of managing open source, because it's really complicated, it's very complex. There's a lot of moving parts, a lot of information as we saw shifting landscape as well.
And accuracy has been really focused on taming that complexity. So I want to, uh, call it there and say, you know, thanks for coming to check this out and, uh, if you have any questions, just let us know. And, uh, thanks very much.
Good morning. Is China cutting off Its nose spite its face. Are they dropping outta the GPU game?
You're watching Textron Gang. Hey, good morning everyone. It's a Shimo for Textron and Textron Gang, thanks for joining us on this lovely Wednesday, right in the middle of the week.
We've got some great stuff to cover for you and some great people to cover it with. Let me go over, let me introduce you to our gang for today. First of all, he's back out on his perch overlooking Silicon Valley.
He's the czar there after a short stint in Las Vegas for reinvent, where we got to see, actually see him in person. I felt blessed to be around royalty, our own John Schwartz. Hey John, how are you?
Hi, Alan. It was great to see you in Las Vegas. You, Mike, Mitch, uh, the gang assorted individuals, Daniel Newman.
It was great. It's, but it's better to be back here. Yeah, well, you know, from where you sit, you can see from miles and miles and miles as the who one said a little Hazy today.
I really can't see that far. It's a little hazy, but, uh, I'll do my best. Um, and then we've got two people joining us from the great state of Texas.
Uh, first of all, he is a analyst with Futurum Group and one of the co-founders of Visible Impact, our own Guy Courier. Hey, guy. Welcome.
How are you? Very good. Good to be back.
Uh, uh, well, actually, I didn't go, you, you, you, you, you went somewhere. It's good to see you. Yes.
But you did something maybe even more important. You did your civic duty by reporting in for jury duty. And, and for those of you out there who know, you know, try to skip it or get around it, it's, it's one of the few things as a citizen that it's called on us to do in this country.
And Guy, thanks for doing your duty. We salute you. Well, thank you.
Um, but it's good to have you back and I'm glad you didn't get on a long trial that was gonna have you out for weeks or months. Also, joining us though, from the beautiful city of San Angelo, Texas, right out of Abilene, it's our editor for, uh, tech Strong AI and digital CXO and so much more. Amma, Amanda, Rini, Ani, Ani, Ani.
What are these days? We'll get it right, Amanda, but I always try. Amanda.
Ani. Amanda, good to see you. Yes, happy to be here.
Thank you. Okay. And then last but not least, still licking his wounds over a major loss of personnel for his Yankees, our chief content officer, Mike Ard.
Hey, Mike. All right. Uh, I'm just counting all the budget dollars that the Yankees freed up and maybe we'll just buy like 20 other players.
See how it goes. Well, You know, I did the math. It's really not 20 other plays, but I think they can get three to four top line people in here for that.
Right? Uh, maybe one starting pitcher, a first baseman, and either a second or third baseman and an outfielder all. I think that's what it's gonna take.
And the price of meds, tickets are on the way up for sure. Yeah. Who cares?
No one goes anyway, but, and we also need a bullpen. We need to do some bullpen additions there. Not necessarily.
I mean, if this guy weaver's gonna be, his clothes are great, but we need some setup med for him. All right. In other words, we just need a team and we're good to go.
Alright, Well, we got, we got all off season. I, I've got, I'm confident anyway, enough baseball, let's turn to the matter at hand. You know, trade wars make for strange bedfellows and, um, in the latest salvo in the American Sino trade wars, you like the way I used that word, sino instead of China.
Thought that was very sophisticated on my part. Uh, China is opening up, and you don't hear this from them that often, a formal antitrust probe of Nvidia. So they're not banning Nvidia right now, but they, you know, firing a, a broadside salvo that they're looking into potential antitrust probes of, of Nvidia.
What does this mean? What, what's the real deal behind it? I think we've gotta go to the, the, the eye in Silicon Valley here and, uh, find out, John, this is one of your stories, Isn't it?
Yeah, Yeah, yeah. It's hard to keep track. There's a lot of moving parts in the us um, Sino relationship.
Um, so China's issued this very bizarre press release. It was sparsely worded, it was very vague. It's the state administration for market regulation, which I'd never heard of before.
It said it is gonna focus on Nvidia for allegedly violating China's anti-monopoly laws. They're looking into the nearly $7 billion acquisition of Mellanox Technologies as a network in data transmission company. Um, it, it's interesting, it's kind of almost a tit for tat uh, timeline.
If you look at it. I think last week the US imposed its third, I believe it's it, third crackdown in three years on China's semiconductor industry. So they're expanding, curbing the exports to 140 companies that include ship makers.
So China in turn has taken this action, uh, this is significant, especially for Nvidia, because it literally dominates the AI chip market with more than 90% market share. And, um, it's gonna have an impact. And this is gonna be something that other companies in this region are gonna be looking at, especially because in a sense, NVIDIA's kind of caught in the middle between these two countries.
And in effect, it's actually had an impact on the business. I, I believe 17% of NVIDIA's revenue through the last 12 months through expected through January, is down to 17%. In China, it was 26% two years ago.
So again, there are other things in motion that are happening between the US and China. We have the upcoming tariffs from the Trump administration. We had this whole spying stealing data from major telecoms.
We've got the TikTok ban, which is headed towards January 19th showdown. It's just a lot to, to chew and mull over. And, um, it's created, uh, a lot of tension, especially for the companies out here and how the US and China Sare rattle one another.
This is getting hot and heavy quickly. They also put out a, a fleet of ships yesterday and an unannounced exercise that, um, or actually two days ago, um, that they just wanted to show that they could surround the island of Taiwan and cut it off. And, you know, usually it's the kind of thing that they would, you know, send a signal that we're gonna go do, but this time they didn't.
So this whole thing can get hot and heavy quickly. Yeah. You know?
Yeah. There's also always, China also banned the exports to the US with, uh, these chip materials like gallium germanium, et cetera. Yeah.
The rare arts. Uh, Rare arts. Yeah.
Now, luckily we've been finding a lot of deposits right here in the US of some of these rare earth things like lithium and, and stuff like that, that will make us less dependent on China for these things, though, China's also trying to buy it up. You know, like Brazil has some rare earth resources that China has been trying to take control over. Mike.
I, I, I wanna just, 'cause you know me, I'm a peacemaker. I just wanna ratchet it down. I don't think the Nvidia antitrust is necessarily related to the military actions around Taiwan.
I think these are two very separate things as Chinese views the world and the Chinese view of the world. Um, I think, no doubt they're involved in a chip wars with the US or, and it, there's an argument to be made that we started this one, right? We, we threw the first stone.
Um, so there's this chip war going on, but that's not, that's separate and apart from their longstanding position that Taiwan is part of China. And sooner or later, you know, John Willis has said 2027 is what numbers he's heard. At some point, something's gonna happen there.
And then depending who's president here and how we're going to deal with it, we're either going to, you know, go to the mattresses over it or we won't. But for this particular thing, this is classic Chinese saber rattling. Does anyone know this China even have anti-monopoly laws?
Or is that just something they put in by fiat? That's A, that that's a really good point. I've never Heard of it.
I mean, I, I I've never heard of it either. Neither It was in this organization that, you know, these, these, there was another announcement among a bunch of, uh, associations where they said that US chips are a threat or it's not safe to use them, so please only use locally. Yeah, I know.
Well, these Chips, All these on. But yeah, I mean, let's let, let's be realistic here though for a moment. Until there's a viable alternative to Nvidia GPUs.
Do you really think China is gonna stop importing and using Nvidia GPUs for their AI uses and risk falling behind in the AI race? NFW and FW? And I'll go on better.
I guarantee you there are people rubbing their hands in glee in Singapore and Korea and all of the east, you know, the tigers of, uh, east Asia who trade with China because they're gonna be buying up as much Nvidia star, uh, uh, Nvidia, you know, product as they can. Because you know damn well, China's not gonna stop using Nvidia. They may, you know, for public purposes, slap them as a monopolist and say, we're not gonna import them directly.
And the, the gray market will, will blow up with Nvidia ex imports into China from places like Singapore and Malaysia and Indonesia. And, you know, other, the Philippines is not so friendly because of China's military posture in the South China Sea. But, you know, they're not gonna stop using Nvidia chips.
They're not, and they'll pay for them. They may pay More. I don't, I don't know, Alan.
I I, I appreciate ratcheting down the temperature for sure. Uh, but, well, first of all, China does have extensive antitrust and anti-monopoly laws. I think what can confuse us is that they don't really apply to state owned enterprises.
And there's a lot of state ownership, uh, majority ownership, or at least minority ownership and state interest in a lot of the, you know, private, um, private, uh, companies in China. But I think that to, to my mind, this, this is a replay of the oil wars and battles, the late, uh, 19th century for example, or early 20th century. It's just that the material now is not quite as fungible as they say.
You know, oil is, oil is oil around the world, but chips may not be, chips may not be chips around the world. I do think that China's plan is to, um, manufacture everything itself. They have the, the talent, the knowledge, the intelligence, the educational system and the materials to do that.
And they have the long view as well. And they showed this with aircraft, for example. They've shown this with the space industry.
They've shown this with military. Um, I think that they are going through severe economic difficulties right now related to, uh, you know, how they've run their economy in their own real estate bubble and things like that. And, um, they have to deal with like every nation with, uh, uh, making sure that people are happy enough, like the best of concern.
People are happy enough, prosperous enough, uh, not to challenge the status quo. Every nation has to do that, even democratic ones. So I do think that this is, uh, a continuing escalation that's gonna reach a peak at some point.
Um, there, it's not just the US and Brazil, Australia has the same rare earths, it's just more expensive to get them. And uh, uh, you know, at some point that cost hits consumer pockets in the Western countries, it can, you know, cause inflation or inflationary issues, like all the same classic stuff going back hundreds going back centuries. China wasn't really in the oil wars though back then, A couple of things here.
The Other was the opium wars. Well, yeah, there was different actors in the oil wars, but it's the same phenomenon. Uh, or similar phenomenon.
Anyway, I don't wanna overstate it. I think there's a couple other factors at play here. One is we're finding those medals, not just in Brazil, but in Wyoming and Japan just found a huge mm-hmm.
Us. Yeah. So I think that will become less of an issue.
I also think we're gonna be less dependent upon GPUs to train AI models as the next generation of AI processors come around and where they're gonna be made will be the issue. And then we're seeing TMSC, I think that's what they're TSM C Yeah. Is going by, but they're saying they're now licensing their manufacturing technology so we can make those GPU someplace cells.
'cause they, one issue we have is that all that stuff leads back to Japan. I mean, to, uh, Taiwan. Taiwan currently.
But let's be clear, there's no way in God's green earth that the United States is gonna put boots on the ground to protect Taiwan. And the Chinese know this, and we have signaled this left, right and center around the world. And you bet that they're gonna push hard in the next couple of years.
'cause they're gonna be like, you know what guys? You may think that the island of Taiwan and GPUs are not connected, but in their mind, they're very connected. I'm not so sure that we don't, the moving of, I'm Sorry, the, the moving of manufacturing on shore, like TSMC on I, meaning Entrepr, I think Arizona, or I think it's be in the us Yeah, yeah, yeah.
Uh, the CHIPS act in general, like, it's interesting how the pandemic showed us how dependent we are on choke points in world supply, including chips. And so I agree with you, Mike. I I think that the US is, is, or at least, you know, under the latest administration, is doing everything it can to, to loosen its strategic dependency on choke points everywhere, including Taiwan.
Such that, um, if and when the day comes that China absorbs peacefully or otherwise potentially Taiwan, just like it did Hong Kong, that it has as little impact on western economies as possible. At that point, Guys, I think you're operating on old information. Let me bring you up to date.
First of all, the, the, the chip factory in Arizona by, uh, Taiwan manufacturing has not very much at all. And it's kinda wallowing. It's not even close to being ready.
But Alan, there was a report, I think there was a report, I'm not sure how valid it is that NVIDIA and TSMC might have, might try to, Might might. There was a report. They might, they called out a rumor, right?
There's also a rumor that the Trump administration will do away with the CHIPS act. And then where are you? Nowhere.
There's also a story, not a rumor that TSMC has said they are not going to export or license their latest two nanometer technology anywhere outside of Taiwan. And I'll tell you why they're doing it. 'cause they're not stupid people.
In order to get the US and the West to protect them against China, the US isn't gonna do it outta the kindness of their heart. They're gonna do it because there's some strategic asset there. And if that strategic asset is the technology and know-how for the latest generation of chips, GPU or otherwise, that makes Taiwan strategic.
And if it's, Or it just makes it, or just makes it really important to get that technology out of harm's way. And if, and if your, your TPMC, which is Taiwan, don't you, don't you think they realize that if they keep that there, it's like it, it's an insurance policy. Or we may just say, you know what, we're gonna move off GPUs and say we won't be dependent upon that and we'll use other processors.
So there's other ways to go. We've seen AWS AWS is out touting its processors that have nothing to do with GPUs for training AI models. I don't know if they work better or worse than GPUs, but there's a lot of folks who are saying, you know what, GPUs are expensive and hard to come by in the first place.
So maybe we don't need 'em. What are some of the most viable companies that could step up? I mean, it seems Nvidia really has the, the market, but what are some of the other most viable, Well, a lot of people are designing their own GPUs, including Amazon is betting sides of this thing.
Google. They're gonna bet on their own GPUs and this titanium thing as an alternative. Google and Microsoft have similar playbooks.
So, you know, all those cloud service people went out and said, we're not gonna be dependent upon external suppliers because of this very issue. So I think, you know, The, the problem is though, and, and frankly it's the same problem China faces in, in making their own domestic market for these things. There's going to be a window where you don't have it.
And in something that is deemed as strategically vital as AI progress, who could afford to, to go through that desert before you reach the oasis, right? Who could afford to, to make it through that window? And that's the issue.
That's the issue. I think we're inadvertently, um, uh, uh, combining a design process. It's fab though.
TSMC is the world leader in process and fab. Not, I mean, and they, they, they certainly cooperate and work with video. They with a MD I'm pretty sure they work with, uh, Amazon on design.
But the design is portable around the world. Um, process is actually not just Taiwan, but I think the Netherlands, if I remember right, is, is a, is the world's leading, um, manufacturer of, uh, fab equipment. And then there's the fabs and the fab, the fab fab fabrication, the fabs themselves.
That is really the choke point right now, more than anything else. Uh, uh, you know, I think and, um, the push to build fabs, you know, on US soil in Europe and everything just takes a long time full of potential problems. Um, and that's why it remains a choke point.
So maybe less of a problem and, and less of an issue around Nvidia, specifically if there is enough fab supply, which categorically there, it's not right now. So We shall see. I mean, this is, look, this is global trade in the 21st century.
And we, we'll see how that plays out. Um, let's take a break here on Textron Gang. Let's come back something more domestically focused.
Looking at AI and healthcare. You're watching Textron Gang Modernize your business to fuel innovation and elevate customer experiences with the builder community. Hub AWS and its partner network provide essential tools for transforming applications and infrastructure to fully leverage the cloud.
Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably. Visit the builder community hub to learn more. All right, folks, we're back.
And I guess, you know, if you've been under a rock, you're may not be aware, but there have been some tragic events in New York City involving the CEO of United Healthcare, and none of that is, uh, excusable. But it has led to this conversation about what is the proper usage of AI in healthcare and in claims, because there are folks who are concerned that, um, issues are being not properly investigated. 'cause the AI is essentially just denying everything.
And this is creating a lot of angst in the world. Uh, social media is full of this stuff and people are starting to complain about healthcare vociferously. Everybody's been complaining about it for a while.
But John, I know you looked into this and wrote a story about what's going on with healthcare. So what's your assessment of their usage of it? 'cause, you know, one thing that comes to mind is lack of visibility, Right?
Right. So, I mean, the only thing we really knew about UnitedHealthcare and AI was there was a lawsuit that was filed about a year ago, November, 2023, that pointed out it was a class action suit outta of Minnesota. A couple of customers, patients, families found that there was a system in place that the murdered CEO had approved of, that automatically denied claims, basically from sick, elderly customers.
And in a sense, I started calling around other healthcare professionals and folks I could find, and they were telling me that what UHC did was not unique. It's actually quite common, the use of AI to escalate denied claims. And it's kind of sparked this debate on the ethical use of, of ai.
And one of the things that someone told me that was really interesting was that there's a, there's a, a phrase or a syndrome that they're talking about in the healthcare industry about the use of AI called the slow motion. How effect. Now, I know you all probably are familiar and know extremely well the movie 2001 of Space Odyssey.
There's a scene in the movie where Hal, the evil computer methodically turns off the life life support systems of the hibernating astronauts, which they are killed. This is what people in, at hospitals and doctors are saying about the insurers, uh, that were kind of in this, this, this lightning rod issue of, of intersection of AI and healthcare, healthcare transformation, where, um, it's leading to a lot of bad results. And this, in a sense, in a weird way, this murder has kind of opened up this whole debate on the healthcare system, and even if you want to go deeper into class warfare.
But I found it, I found it very interesting. And when I talked to the healthcare professionals, they said, everyone's doing this now. They're using this health, they're using AI in a sense to deepen their profits and, uh, nullify or discourage claims.
So, um, I just found this, this whole thing really fascinating and it opens up a whole can of worms about not just our healthcare system and how it compares to the rest of the world, but also with, uh, struggles in, in the class warfare. So I would Like to point out one thing about this, though, right? We are conflating a workflow and a process and a strategy with ai.
And that strategy existed before AI came along. AI may have amplified it, but it did. Yeah.
The process didn't existed before AI came along. So, you know, we're kind of like pointing a finger at ai, but I'm kind of looking at, I'm not saying that I, it was a flawed system to begin with. It's been a source of frustration.
AI in a sense has just kind of turbocharged, uh, the de the percentage of denial of claims. I think with, um, UHC cited in somewhere in the lawsuit, it went from like 10, 11% to 22% in certain instances. Yeah.
And if so, very few people fight back and appeal the claims. They just, they'll pay out of pocket. It'll just give up altogether on carrot.
Sorry, Amanda. So I got a few things here, John, with what you said. I've got some issues.
Number one, the hell 9,000 computer was not evil. I don't even know if a computer can be evil, but as we saw in 2010, this follow-up film, there was some problems with Circuit. Oh, that was a terrible movie with circuits and programming, but it wasn't evil, right?
Hal 9,000 was a great computer. Dr. Chandra kinda restored it, right?
So, but it's a microcosm for this. Let's not blame the computer for the evil of men, right? This was a corporate policy right out of a John Grisham novel, right?
To deny cases, to deny claims. And until people fight back. And it goes to the whole for-profit health industry, health insurance industry, because they certainly don't give a crap about your health.
They care about their profits. Now that being said, I, I'll be honest with you, it made my stomach turn watching my Facebook. Yeah.
I'm on Facebook. I'm a boomer. Um, watching my Facebook feed of, of people applauding the death of a man being showing on, on Elon Musk's ex, the, the, the video footage of the, of this guy getting killed is not something I think is appropriate.
Right. That video should not be being shown on their, the hell with freedom of speech. That's wrong.
And anyone who applauds the death of someone like that getting shot in the back deserves no better themselves. It's wrong. I was chag grinned when they came out last night.
I'm using some big words today, huh? I was chagrined when they, the news came out last night that the fir the person they brought into custody is not who you think it would be. This is an Ivy League UPenn, educated data engineer, a techie nonetheless, since when the techie shoot people we're, we're pacifists, we're good people.
We don't shoot people. I don't care what the guy did, He was also from a wealthy family, right? Yeah.
Not sick. He was this, this, this very highly regarded private school. I mean, it's just everything.
So it came out, he wouldn't Overnight that, um, or at least yesterday, um, that he was also somewhat estranged from his friends and family because they hadn't heard from him for a while. Apparently he's been suffering some issues with back pain for a long time. And he was exhibiting a lot of the sin symptoms of somebody who, you know, might do this even.
Well. Well, He's a big fan of the Alma Una barma, whatever that kki Yes. He posted on Good reads, his, his thoughts about the manifesto.
He read through it thoroughly. Um, but, but nevertheless, I, I'm not saying that the CEO of United is a saint, nor is he the devil. He certainly doesn't deserve to get shot down dead in the streets of Manhattan in the back like that.
That's just, and anyone who condones that and makes this guy into some kind of folk era, you're twisted, that's twisted and has no place. Um, And especially one man, the CEOI think people don't realize one man doesn't control everything at the company. I mean, he had just come into the company Recently.
No, he's been at United a long time. He's been CEO just three or four years, but he's 17 years. That's meant or something there.
What, you know, I'd hate to see things someone wants to shoot me for something our editorial department did. But that being said, let's Long silence there for a second. Yeah.
Well, we were, was a, We were thinking through some examples. You didn't realize it, but let's, let's come back, let's come back to focus on AI and healthcare. Right?
I, I put forth the proposition that this isn't AI in healthcare. This is AI and health insurance. AI and healthcare is gonna do great things to make us healthier and help us with our health.
That That's a that's an excellent point. Yes. Right.
You know. Yeah. I talked a surgeon, people.
Yeah. My mother was a surgeon in, in, in New York City. She was trained as a, as a trauma surgeon.
She worked in emergency rooms, um, and as a women's health surgeon and, uh, at a very prestigious, uh, hospital system in, in, in New York City. And, um, right around, uh, the early nineties or something like that, she was called in by her new department chair, a surgeon, um, and, uh, uh, for a meeting with his new controller, the finance person, um, who had her new compensation plan, which involves something like, here's, uh, here's, you know, one quarter of your base salary, and here's how much money we expect you to bring into the hospital, and here's your share of that money to balance it out. This was a, someone who didn't go to business school, someone who went to medical school, someone who did not get into medicine for the interest of, uh, um, making money, which a lot of folks did at that time, still do.
But because, uh, she wanted to provide healthcare to people who needed it. And, uh, the immediate result was, uh, a loss of her personal revenue, um, and a six to a 10 year period where she was kind of in the wilderness, um, as far as her professional development goes. And so, Alan, I think that, that the issue is actually endemic, um, throughout healthcare.
It's not just on the payer side, it's on the provider side too. I, I completely agree that AI has the opportunity to, uh, improve outcomes, uh, and under human trained supervision. But I wonder at the other, the, you know, if the other influences of ai, because of a healthcare system that's profit oriented, not public benefit oriented, if, if those are gonna overwhelm the, you Know, the benefits, I, I think this is the beginning of something that we're gonna see over and over again.
What's gonna be is that there's all these flaws and all these systems inside and outside of healthcare, and they exist everywhere, and they're all going to get exacerbated by ai. And it's, you know, and we'll blame ai, but ultimately the flaw already exists, and we're gonna see this over and over again. It's gonna be this societal impact of ai.
And, and that's, you know, this is just the tip of the iceberg. I think, you know, we're Exactly that. That's, that's what I, that's what I got from these healthcare professionals.
They mentioned all the good things that AI can do in the field. But I, I got to thinking Mike also about this idea of how it applies to other industries. And we'll have the same different types of scenarios where, um, the best parts of AI will be used.
But there will also be the, the, the downside in pitfalls, which will probably get more attention, honestly, because that's the way the press works, right? Uh, As Alan said, AI is only doing what it was trained to do, Right? And, and if the issue before AI arrived was only impacting, you know, 5% of the people over an extended period of time, you know, it will go unnoticed.
But once you get up into the realm at 20, 25%, then everybody starts talking about it and it becomes, you know, a political issue. So we'll see what Happens. But, you know, that's not necessarily a bad thing.
Not that it becomes a political issue per se, but that at least people start noticing it. Because look, there are too many people in the US who say, it's okay. We still have the best healthcare in the world.
And those people haven't traveled very much. Um, we need, we need a redo around healthcare here, guy. What you pointed out with your mom is from the nineties, but unfortunately, I don't think it's very different today, right?
No, no, it's worse. If anything, yeah, it's, it's, I I have friends down here in Boca who are doctors and, and you know, whether they're working for the big hospitals or the big healthcare, you know, healthcare has gone big. There's no kinda local hospital.
The local hospital's part of this system, and the doctors all work for the system, and it's all part of the system. And the system is profit driven, and so it has, it, it, it's gotten worse. You're right.
We need to figure out something in this country. Yeah. I'm just, I feel like this is a canary in a coal mine.
What, what does this teach us about the use of AI just generally as a public bene benefit versus as a profit motive? I mean, I, I asked the group here, like, the what's, what, what, what should the audience, our audience, you know, think, um, should they be behaving differently? Should they wish for better systems?
Like, do we need to just learn, like I I, we talk a lot about reminding ourselves what AI is good for and what it's bad for, and how to manage it and how to use it productively. But is this a cultural question? I don't even know.
I don't either. I mean, but wishing for better isn't going to. We've gotta work to make it better.
And if that means lobbying, you know, voting with your pocketbook and that the ballot and everything else, it's, it's a bad, I mean, I'll be honest, you know, as the CEO of a company here at Techstrong, I've always made up my business to make sure that we have what I consider great healthcare options in, in terms of insurance and affordability and coverage, so that you could go to a doctor anywhere and get treated, that you can go into just about any facility and get treated. And we've had people who've come here to back strong and said, Hey, I appreciate that. I've had young people who say, I never get sick.
I don't need the health insurance. And God bless 'em if that's what they wanna do. But it's, it's an important, it's important.
And I, I just, you know, I'm at a loss, honestly, I, I get very disappointed that as a country, we haven't figured it out. And we keep talking about repealing Obamacare. Like Obamacare was the be all and end all.
It wasn't bad. It, it improved a bad system, but it didn't, I mean, there's so much that needs to be done in our healthcare system. It, it's, this Has been a debate that's been going on for 78 year back to the Truman administration.
Yeah. So, Been before that. So, Al, lemme ask you this just for grins, right?
What percentage of your costs are tied up in healthcare and, um, why are companies on the hook for this, for the insurance, when, if we had a different system that would all move into more of a government function, right? Hmm. Well, I wanna answer the second question.
Go ahead, Alan first. No, you go first. I get, it's really interesting.
So the reason why private companies or private, uh, not private, like, uh, uh, uh, you know, the government is not, uh, involved directly in healthcare is because in World War ii, during World War ii, uh, there were, uh, controls put on during a war effort as to how much people could be paid in order to try and keep government costs down because of all the, you know, profiteering that's going on. And so, uh, companies started to offer non-monetary benefits, um, instead of salary in order to attract, uh, workers, which were scarce. And one of those was healthcare.
Yeah, there you go. I mean, I will tell you, Mike, you know, it depends on what people make, right? Because if people aren't highly compensated, the percentage of their salary that it costs us as a company to give them health insurance is higher than someone who makes more money.
But if you take the average person here at Techstrong, and again, I, I think we pay a decent wage if you take the average person here at Techstrong, um, and we, you know, I am not gonna advertise our benefits on the gang, but we, we pay a good, healthy percentage of your insurance, whether you're a person, a couple, or a family, we pay a, a very healthy percentage of that. It, it winds up costing 18% over and above just your healthcare. I'm not talking 401k and matching and all that stuff.
Healthcare is 18, 20% of an average person's salary a additional in terms of a benefit. So that means if someone makes, let's say, a hundred thousand dollars a year to make it real simple, it winds up costing me 120. Mm-hmm.
All of which could theoretically, if you add up all the employees, maybe we're not hiring additional folks because of the total cost of healthcare. Right? Well, but I, and you know what, I'm glad you brought it up because as a CEO, that's something I wrestle with every day.
But I'd rather have less people who, who don't have to worry that God forbid, they or their children got sick or their spouse got sick and they don't have coverage, or they, they're gonna go for an operation and some insurance companies are gonna tell 'em, I can only give you anesthesia for 30 minutes. I don't care if your operation's 40 minutes. What kind of nonsense is that?
I, for one, I'm very grateful for insurance benefits. Yeah, no, I mean, I, I am too. I think we have, and I'll, I'll be transparent.
Our insurance is United. I've never had, is United Healthcare. Yes.
Yeah. And I, we've never had the issues that you read about, but nope, I don't know. You know, I don't know.
But I, I do believe every, you know, healthcare rights are human rights and everyone's entitled to healthcare, or should be. Anyway, on that note, let's take a break here on Textron Gang. We're gonna come back something a little lighter.
Uh, snowplow alerts. Amanda has the news on it. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
All right. Alan referred to this as something lighter. I've never heard of a light snow plow, but, um, we're talking about how in New York State they are testing technology so that as a driver, you can know where that snowplow is and hopefully maybe not run into it, or as most New Yorkers will probably do, just follow it because, well, it's, you know, cleaning up the highway and it's just kinda like what New Yorkers do sometimes when they are following ambulances and fire trucks, right?
Not necessarily the right smartest thing to do, but that's kind of how it gets rolled up. Amanda, this was on, uh, digital CXO, so, you know, what's your take on this? And, and, you know, are we gonna see more of this?
Yes, I love this. Um, and I think where I see this being really beneficial is, you know, I live in Texas, so I do think we're gonna see more of this, because if you think a couple years ago, uh, and you would remember this, we had the Snowmageddon and our, uh, we don't have the infrastructure or the equipment to really, um, handle a, a lot of these hazardous conditions. So I see this eventually being really helpful in these areas.
Um, as far as safety on the road, um, it would've been helpful back then everybody was just kind of stuck at home. Um, so, but yeah, and in the big cities too, with the traffic, you know, with the traffic situations there, I think it's great because it's gonna reduce a lot of accidents. Um, and I will kick it off to John to share more about it.
'cause he's the one who wrote the article. Okay. Thanks, Amanda.
So, the, the company is called Icon Products. I talked to the CTO, interesting guy who, um, kind of downplayed in a weird way what they were doing. But this goes far beyond New York.
They have a systems in dozens of states, and they're actually in the process of talking to Tesla, general Motors and Ford about using their technology somehow incorporating it into their cards. So it's onboard, and it, it, you think about it, it's not just snow plow, it's any type of construction equipment on the shoulder of a road. The construction workers themselves who are endangered.
And what this guy, and what they're trying to do is, I think, and I'm not, I'm gonna, I don't mean to be hyperbolic, but in a sense it's kind of a safety advancement for drivers. I think of seat belts, airbags, Ralph Nader, anti-lock brakes, rear view video systems. And I think of this now with the technology, it's, it's available on Google in ways.
And in fact, I've experienced it be in a, in a roundabout way because I just upgraded my iPhone to the latest system, and now it's giving me alerts approximately about cars on the side of the road, or some sort of accidents before I get there, so I can avoid it, or, or at least I know about it. So, um, I was quite interested in this. Um, there actually also have been studies done.
I think Purdue does a lot of studies on emergency braking your work zones, and found that technology, technology like this has resulted in a reduction in emergency braking near these types of sites. So again, you know, technology can do a lot of really good things, and I, I think it's important to write about these types of things and not always dwell on the dark side of tech as some of us, especially me do. I thought ways hard, dark side of tech.
I mean, go ahead, guy. Shout out to Texas, the only state I've been in where, uh, people actually drive faster when there's ice on the road. It's sort of slower.
You don't know how to drive Jesus. I think that that, um, as someone who, uh, very recently, uh, uh, uh, uh, like a good New Yorker in Texas, uh, drove behind lease car, that was clearing away for me. Um, I think that, that John has the essential point here, which is, um, first of all, increasing awareness generally in information without fuss.
Um, I'm a Google Maps user, but they've started to incorporate that kind of Google ways information about what's going on on the road. Um, and, uh, th this is, uh, you know, one of the, one of the non, uh, drug related leading sources of accidents is inattentive drivers who, uh, don't see things like blockages, um, or weather conditions or what have you, and get caught by surprise. And, um, I learned a new term internet of road work.
Is it, um, that, uh, this, this spend talks about. Yeah. Um, the more information, the more data we get in, that's, uh, an opportunity for the app developers.
It's an opportunity for the AI developers. Um, and we just, I'm not gonna turn dark on this at all. It's, these are opportunities.
We just wanna be cautious and, and, and smart about using them, because ultimately this data, right, Amanda, this is gonna be incorporated into, uh, you know, uh, automated driving and other kinds of driver assist, whether on vehicle or in act, right? Yeah. I think it'll be so helpful, uh, like I said, in reducing accidents, um, and allowing people in, especially in places like Texas, that just aren't comfortable or familiar with driving and hazardous conditions to feel safer.
So, you know, In California, in California, we freak out when it drizzles, right? And so we also, I, the, the thing that I was thinking about more and more is with the Infra Infrastructure Act, there was so much construction going on. We have portions of Highway 1 0 1, which is a major artery here that are closed or divert traffic week every weekend because they're still working on these projects, repaving the roads, and there's so much equipment out there.
I really want to know before I get on the roads, what's, what's there. So I'm not only delay, but I also feel unsafe sometimes because there are quite a few lanes that are abruptly shut off. I'll tell you what, a lot of small towns do not appreciate about this ways thing and all this other stuff.
And I'll give 95 as an example. Every time there's a frigging slowdown on 95, everybody stops hopping off and goes on route one through all these small towns. And it's only about 10 minutes later before that entire small town comes to Luck.
But some people stop there and grab a bite to eat or guess up, and they make, and, and, but, and I don't mean to make light of it, let me tell you why it's 'cause I'm not an unreasonable man. So the, the deal is, okay, doc, first of all, I'm think you got that too, guy. Um, thi this kind of functionality has been available in Waze for many years.
I've used Waze for years and years, especially when this hurricane's down here. Waze gives you the best way around. It tells you what's, what's bad and what's not.
Um, the issue is it can't be a do-gooder thing. There's gotta be a profit motive, otherwise it's not gonna make it right ways. God Bless was a bunch of Israeli guys.
Google paid a billion dollars for technology that brought in $0 in revenue, and they've been trying to figure out how to do revenue ever since. Now they've got it where, you know, McDonald's will show up on your ways. Hey, where's the nearest McDonald's?
Where's the nearest Kentucky Fried Chicken? Where's the, or KFC, where's the nearest whatever? And so they're trying to put advertising on your ways Maps and your Google Maps to make it somewhat, you know, uh, revenue neutral if not downright profitable.
If you can't figure out a way to make this make money, the do good aspect, they're only gonna take you so far. And I think that is the problem with all of these. I mean, it's great technology, it's life-saving technology, but if you, if it doesn't have a path to profitability, as Alphabet gets squeezed, You know, the CTO of of Icon actually told me he was frustrated because dealing with the automakers, because he said they were more preoccupied with the EVs and that's where their budget and their most of their Money went.
No, because where's show me the money? Show me the money. Right?
So exactly. And to your point, and he said, now they're beginning to see that if people pay a premium for cars in particular, they want everything imaginable that can make it a safe experience. Um, but yes, yes, he said that the profit motive wasn't there yet for them to put it on board.
That's a point. And I won't be Able to, I won't be able to go to McDonald's anymore. 'cause the AI is tracking the fact that I ate all that crappy food and then that won't get coverage when I get that disease.
So, you know, what's the point There is that it all comes back, you know, Hey, It all comes back. Yes. Be careful what you wish for.
Anyway, guys, we gotta pull the plug on this edition of the gang. We've all got places to go. What a great con couple of bunch of conversations today.
I hope you've all enjoyed it at home. Reminder, as always, we have a full day of text on TV immediately following. So stay right here at your favorite bat channel, bat time, and, uh, check out what else we've got.
Guy, Amanda, Mike, and John, thank you very much for joining us here on The Gang Today. This is Alan Shival. We're out.
This is Textron tv. Hey, everyone back here. This is Alan Shimmel back here in, uh, Las Vegas.
We're at the Wind, A Wind Studio at The Wind Hotel right across the street from AWS Reinvent Expo floor. Was able to pull my friend Kobe. Did I get that right, Kobe?
Yeah. Uh, off or, well, he wasn't really on the floor either. He's been in meetings since he got here, but he, we, he took some time out to come sit with us and talk a little bit.
Kobe is the, uh, chief Product Officer at Check Marks company. We, we follow for a long time. Kobe, first of all, welcome.
Thanks for coming up. I know you're busy as heck, so I appreciate it. Thank you.
Thank you for having me here. No, it's a pleasure. Appreciate Kobe, you've been on before, but I don't know if everyone remembers.
Give us a little bit of your kind of background, your story to be as you became the Chief product officer at Check marks. Yeah, well, I've been with, with check marks, uh, for more than 11 years now. Um, you know, for my first seven years, I actually built the engineering in the field, meaning, uh, the entire group that, uh, that deals with sales, engineering, professional services, technical account management as customer success about a bit more than four years ago, uh, our former CEO in, he asked me to, uh, to take over a product in order to build our next generation product, which is, uh, check markwan.
Yes. Our cloud, our our cloud platform, uh, for, for application secu for application security. And this is what I've done.
Like we, uh, you know, we, I headed, I spearheaded the leading of building this platform. Um, we actually officially launched it, uh, uh, three years ago. Yeah.
Now we have over one, you know, um, about half of our a RR actually lives on that platform. That's great. Just within, uh, three years, hundreds of hundreds of, uh, hundreds of customers, large customers are using it.
Utilization of the platform is, uh, uh, skyrocketing. Um, I think there's two, two things that that says though. Number one is you built a good product, right?
Check Marks builds. Thank you. Check marks, guys.
You're welcome. Check Marks has good, we talk about app dev and, and, and, and so forth. Check Marks is a leader and builds has great product.
Number two though, is the cloud native market, right? The cloud native market has really over the last three, four years, it is the stack now, right? It is the compute stack.
If you are building something, you know, they use this euphemism modernizing applications. When they say modernizing applications, they mean for the most part microservices, cloud native architecture. Exactly.
I describe it as a Lego. Yeah. You know, that's exactly what we did.
It's like, you know, the former generations of, of apps where, you know, you had your front, your front end layer, your business logic, your database, right? Right Now it's a whole Lego. You have your propriety code.
Most of the code is, uh, is open source, open source. You have your microservices. Um, you, you have, uh, infrastructure is code that that actually builds the, uh, the runtime environment.
That, that, that sure. That, that, you know, that that euro that you run, um, and then you api you have exactly, you have a, they stitch in all the one api. You, you have, you, you have APIs, so um, you have APIs, you have, uh, you know, all kind of secret detections.
Yes. All, you know, all of that kind of, you need kind of, if you really want to provide security, you need to build solutions for all that. And this is why we thought that, you know, the right way to do it is actually to have a platform that will have, uh, you know, multiple, multiple scanners.
But since you have so many scanners, because the technology is, is kind of Lego. Mm-hmm. Uh, Lego, you need on top of it an A SPN layer that, that will provide you actionability.
Um, you also need, uh, you also need connectivity to runtime in order to provide you the runtime context. So it actually takes you to, to the next level of, of actionability. Does it really run in, uh, does it really run in runtime or it just lies in my repo right in in the dev place?
Yeah. In, in, in the dev place. And of course, the entire developer experience today, our customers are the developers and kind of we, we, we kind of, we built that.
So, so developers will feel comfortable and will have, uh, a very, uh, smooth and very good experience, uh, using, using the, using the checkbox, uh, platform. You mentioned developers are your customer, you know, and look, I've been in developers are are users and users, users, but they're very, very impactful years. Yes.
Okay. They're also highly impacted by this. Right.
com in March of 2014, so over 10 years, almost 11 years now. And, you know, shift left, shift, left shift as far left as you could go. Right.
And then I think what we've seen again in the last three, four years maybe Yeah, two, three years, is that developer, a lot of companies made the mistake, especially security companies, not Jack Marks, but a lot of security companies that they gave security tools to developers and developers are not security people. You need developer tools for developers that help them build better, better secure, more secure code. Not, don't mistake them for the security professional, but some companies made that mistake.
Right, exactly. So, kind of, you know, when we started to build the, the, um, the CX one platform, we actually realized that, you know, that, that because the burden of security was actually shifting to developers, and they are the most, as you said, impacted and impactful users. We need to provide, we need to provide them an experience.
And the experience is speed is, um, actionability and less noise. Okay. Because you cannot waste your time.
And also simplicity. Yeah. Okay.
Simplicity. So kind of, these are the pillars that, that, that we work by. This is why I mentioned code to cloud, uh, the, the cloud integration runtime.
Mm-hmm. Before, why is it so important? We think that it's going to, we think that it's going to change the way application security is being done.
Because if I can tell you, Hey, deal with, uh, vulnerability, X, Y, and ZY because they're the ones who really impact your runtime. Right? Okay.
And, and kind of, they're, they're the ones who are actually open to the internet. So start with them. Okay.
Yep. So, I mean, but this is a lesson. Look, I started a company in 2001 called Still Secure.
2003. We came out with a, something called van, vulnerability Access and Management. It was a scanner, not not in runtime, uh, in runtime only, not, you know, pre-deployment.
It was the same thing. Then, you know, we would, we used to internally, we would call it the bad news generator because it was a bad news generator. We would scan your infrastructure, and we give you, this is nothing, we give you something like a telephone.
People don't know what a telephone book is anymore, but like a telephone book, you remember? Yeah. A lot of people out here don't, but a telephone book full.
And then, you know, some poor guy there would have to go through and say, okay, well, this is a priority. This one's not really accessible. This one's not reachable.
This is a, a Linux device. We don't have to worry about Windows stuff. This is a port that doesn't get you.
There was all kinds of things that allowed people to say, Hey, we're gonna get the biggest bang from my buck in terms of remediation, in terms of lowering my risk, which is what it's all about. So, so kind of, so here comes the next thing, uh, uh mm-hmm. First of all, uh, first of all, you know, um, we also, we're not also, we're not only giving you the headache, you know, as, as you said, right.
But bad news, Joe. So kind of, let's say, you know, I give the bad news start and work on, uh, vulnerability, X, Y, and Z. Okay?
Right. I'm with ai, we're also helping developers to remediate. Okay.
So, uh, we, uh, we have either auto remediation, right? Okay. Uh, or guided remediation, because a lot of time developers don't like, they don't like, don't people to mess with their record.
So kind of, we guide them. This is all done with ai. Okay?
So we didn't have AI in 2003. It made it a lot harder. But, but that brings up this whole AI issue, right?
In the role it's playing here. Uh, I mean, no pun, but it gets smarter every day, right? It's getting smarter every day.
And, and as we train it better and everything else, um, if it follows other adoption curves that I've seen, there will come a time where developers are gonna say, let the AI fix it. Right? I'd rather, you know, right now they're going slow because they don't have confidence, and maybe rightfully so.
So, so kind of the REI strategy is actually built again, on, on three pillars. One is detection, right? Okay.
Detection. We do that through, uh, integration with, uh, uh, with copilot. Mm-hmm.
Uh, integration with, so you already integrated check? Well, with chat PT Uhhuh, uh, we also have an engine of our own, which is called, which is called the vpa uhhuh. We embed all of that into the IDE.
Okay. So that's where it's at Today, the id, this is kind of, this is where it lives, so mm-hmm. It helps you detect things like, you know, SCA hallucinations, uh, bad practices of, of, of coding in real time within, within the ID for your AI generated code.
So kind of, this is the, this is the detect, uh, pillar, right? The second pillar is what I talked before, is remediation. Okay.
And maybe, maybe you, you're probably right. Maybe there will come a times that, that the remediation, it's a confidence build date. Exactly.
So may, maybe there'll probably come a time that the remediation will kind of, will be done automatically. Mm-hmm. Okay.
Automatically. Yeah. For, for, for the garden variety stuff, right?
Yeah. There'll be corner cases. There's always corner cases.
And, and the third pillar is to secure your lms. Okay. Which I think it's also one big issue that the market is only now starting to, uh, to, to approach and build solutions for.
We are already deep in the research work on how we secure, how we secure LLMs, how we secure open source lms. I believe that that, just like people today, 80% of the code is not proprietary, is open source. Right.
By open source. This what will happen to, uh, this, this also, what, what will happen to, uh, to LLMs. I, I think you're gonna have sort of LLM marketplaces, most probably.
You, you already have these, uh, you already have such, such companies that, and, and you, you know what, what they're doing. That LLM you download from the marketplace might have 80%, 90% of what you need. And you'll customize just like real code today.
It's the same thing. Just like you do Yeah. Building code, just like you do with open source.
This is why securing, securing open source of lens is, is going, is going to become, is going, probably going to become very, very big. I, I, I agree with you a hundred percent. We are at AWS reinvent.
I gotta bring some AWS into this. Yeah. So they made some announcements also around AI and ai, the Q developer tools, and actually came out, well, they came out with their own ai, their own GPU Silicon and their own sort of chat, GPT, I think it's called Nova, Nova Light, Nova Pro.
Um, you mentioned working with copilot. Uh, you're a, you're a, uh, a partner at AWS We, are you working with the Q tools yet? Or the a d Yeah, we're, uh, we're, we're working on integration with, uh, with Q with Q tools also working, uh, on integration with, with Bedrock.
Yeah, with Bedrock. These are the, these are kind of the, the two, the two AI pillars that, that we're, we're working on with, with AWS. Okay.
We are very close relationship and, um, you know, the outcome will probably be seen, uh, sooner, sooner than later before RSA in the end of, uh, April. Yeah. Okay.
Yeah. I'm, I'm gonna press, I'm gonna press the button. You'll press the button on that.
I wanna bring up another area though that Sure. Uh, I think is important and at the part of the learning of developers not being Security Pros has been the emergence of what we call platform engineering. Yeah.
Right. So if we can give the developers a better house, a better environment, a better environment to work in, that already has some security rules in it that already has sort of guardrails in it, it allows them to go faster and again, not have to worry about certain things. They just worry about their coat.
How does check Marks view that whole, I mean, a lot of people think that we call platform engineering when it's really ops, right? And, and it it is and it isn't. Right?
It do, it is, there's a lot of the old ops stuff is in there, but how do you guys look at platform engineering? We think that it'll become a domain. Yeah.
Okay. This, this, this, this is what we think of it. And you know, we, you know us for a long time.
Yeah. We're the first one who were integrated into pipelines into IDE and, and also into the, uh, what before it was called the Dev, uh, DevOps. Yeah.
It was DevOps, dev SecOps, dev SecOps, and SecOps. So I, I, I see it as the kind of the next step of the DevSecOps, and I think that it'll be, that we'll be able to provide solutions that will be part of that. Okay.
That, that, that will be part of that and kind of will give the, uh, you said guardrails, right. Uh, for, for security, either in, uh, the DevOps part of the, uh, platform engineering, um, and also with the, uh, also, also with the direct tools that developers use, like IDs and stuff like that I mentioned before mm-hmm. Which is kind of an engine that provide you real time feedback on your, uh, on best practice of, of security.
I love it. I, I, I think that this is where it goes. The, and these are the solutions that, that, you know, we, we are, we are building Excellent.
At the end of the day, you know, we live there. Absolutely. We no one, I know it'll be real when you come here and tell me.
Developers and platform engineers are our users. Yeah. Oh, okay.
Yeah. That's when I know. Okay.
It's real. Right? Yeah.
Um, but I agree, you know, right now, you know, um, platform engineering is something that people start to talk about. Yeah. We have to see kind of how catchy it'll be in, in, in, in reality in the market.
But we are billing tools for it. You have to. You have to.
com, our site, our platform engine. 'cause you know, I've been doing this a little while, and I, I watch these things I watch, because you don't wanna miss the boat. Of course.
You don't wanna be too early. org. The community, they got 300,000 people in the community there.
When I go to CubeCon, I don't know if you were out in Salt Lake City, uh, recently for CubeCon, a couple weeks ago, months ago, I was lot of talk around platform engineering. I, I think this is, as you said, this is becoming a domain and Absolutely. Now is the time, I think, to kinda, not a land grab, but put your flag down, stay, you know, claim your, your, your right.
As, as I told you, you see that kind of where. Yep. But I think ai, it'll have, its, I think what we're gonna see is AI is gonna bring all DevOps, dev, SecOps, platform engineering, SRE, traditional security pros.
AI is like shortening the distance between all of that. Of course. Also observability.
Yeah. Also observability. Yeah.
Observability as well. Yeah. And how you fix issues once you, once you, uh, you know, once you identify something in your observability, you know, we run cloud platforms, so kind of we are eating your own dog food with Yeah.
You see for yourself. Exactly. Absolutely.
What else? Exciting from check marks? I know we talked, we probably overtime, but what else do we got?
What else do we got? Um, you know, we released a supply chain security model, um, just last, last month. Uh, which actually includes, uh, first of all secret, uh, secret detection I mentioned earlier.
Yes. Secret detection and also repo health. Oh.
So what exactly is that? Meaning we look at your repo, uh, the code and open source, and mainly open source that are in there and based on our knowledge, and we have a huge database of, uh, open source packages. Mm-hmm.
Not only kind of the standard vulnerabilities, but also malicious, and, uh, also based on info that kind of, we track the contributors themselves. We can kind of provide you a, a grade of, of your, of, of, of your What about, what about of, of your, of, of your, of your, of your overall half of, yeah. So it does make a difference to how many different repos on pull.
You know, you're just looking at all of that. And, um, you know, we also, um, uh, we're also working hard on our, that solution. Uh, you know, we, uh, um, zap is now powered by, uh, by, by, by check marks.
Yes. The core team of Zap is actually employees, employees of, of check mark. So kind of, we are impacting, uh, we, we we're, we're impacting there.
Um, we also released a new, uh, containers, uh, security model really in August. Yeah. Which is, uh, kind of topnotch.
Uh, we have very, very good, uh, very good, uh, feedback for that. Uh, we have our, uh, we have our integration with Wiz, which is making a lot of noise and getting a lot of, a lot of attraction also with Cystic. That's, that's the runtime.
Uh, yeah, I know, sis. We, so both companies, we cover a lot. Yeah.
Uh, that we have. Um, and we are, um, as I said before, we're working very hard on improving the developer experience and user experience of, of, of the platform. We're getting good feedback.
So for that, uh, for, for, for that as well. Mainly on the simplicity. Mainly on the simplicity side, so, sure.
Kind of. Well then, and we need that. And a IL change it every day.
And ai, we talk about it all the time. You, you ask me, you, the study, it just sucks the, the very conversation. No doubt.
No doubt. Anyway, Colby, thanks for stopping up. It's always a pleasure my to see you.
Thank you. Check Mark. com.
Dot com. Exactly. Go check them out.
We're live here in Vegas at AWS Reinvent. I hope it won't be till RS actually, you might be doing something with me, a panel I'm doing on Predict. Did they mention this to you?
Um, not yet. I'm doing a c I'm doing a CPO panel. Okay.
I'll, I'll be more than happy to, to be there. January 9th. Our Predict 2025 conference.
Kobe will be there. We've got, uh, David DeSanto, the CPO from GitLab and a few others. Well, I'll talk to you about it.
Right. All right. We're live at AWS reinvent.
We'll be back in a little bit. This is Alan Shimel. Until then, stay tuned.
This is Textron tv. Hey, everyone, good morning. It's Alan Shimel here at our Techstrong Wind Studio, where we're doing our coverage of, uh, AWS Reinvent.
You know, I got out here on Sunday. Today is Thursday. I've had about enough reinvent.
It's been a great show though, along with, you know, me and 60,000 other people. There's been a lot of keynotes, a lot of announcements, a lot of catching up with industry friends. Speaking of industry friends, I want to introduce you to do Lavo.
Do, did I say it right? Ur la. But it's, uh, hard to get.
Yeah. It's, that's a hard door Laur. Um, do, if you don't know, is the Found or co-founder, CEO of a company called cdb, makers of the CDB database, you may or may not be familiar with it, but hopefully by the end of this interview, you will be Do welcome to Text on tv.
It's great to have you back on. Thank you. Good morning.
Good morning. Wonderful to, to be here. Absolutely.
So, Dore, before we get into Siller and News here at Reinvent, let's talk a little about you, right? You're, you're a co-founder, CEO, but give us a kind of your journey. Mm-hmm.
Absolutely. You, you know, as, as a co-founder and a CEO, I get, I feel married and kind of merge the company, but, uh, don't have To tell me. Yeah.
I do have life and a mountain bike and ski. So not only that, and family, of course. Uh, if we watch, um, so, um, Amor, um, originally from Israel, uh, I co-founded RA 12, uh, years ago, together with my partner Avi.
Uh, we're strong in tech, in low level computing. Like my, my first, uh, company I was involved with, uh, as an employee was, uh, Charlotte Web Networks, uh, interesting name. We, we tried to compete with Cisco's core business.
They bit router, and we created one, and it worked, uh, later on with Avi, uh, um, and Benny, my chairman, we created the KVM hypervisor at another startup, uh, eventually acquired by Red Hat and KVM runs, uh, AWS, uh, cloud and Google Cloud. Yeah, no, it's one of the most popular ones out there. I remember those days.
Yeah. It was, was some win. And, uh, we used to fight against open source, Zen and VMware.
And, uh, eventually KVM like became a standard in, in cloud computing. Wonderful. Ride.
And afterwards, we, we came up with the CDB initially, uh, we tried to shoot at the operating system domain and take Linux down. Linux is so strong we couldn't take it down. We, we, we had an operating system for virtualized environment.
You're not the only one to, to die at that mountain. Yeah. You know what the funny people to tried to get.
Yeah. But it's A, it's was a worth worthy ride. Absolutely.
The, the, that west we created still exists today in, in open source and still kicks ass. Sorry if I do. Okay.
So it's an adult channel. Um, and then now we switched to the database, uh, the development, which is fascinating. It's a big world out There.
Absolutely. And with the increased focus on data, as we've seen here at Reinvent, you know, data, it's about the data. You know what's interesting though?
You spoke about hypervisor. Here we are. So, I, you know, I first became aware of the whole hypervisor world.
I, I guess it was early 2000, maybe 2001. And, um, You know, VMware was part of spun out of EMC Dell, the whole, but it was 25 years ago. Mm-hmm.
Right. If you go to the opening keynote here, uh, Tuesday morning mm-hmm. They're still talking about migrating from VMware mm-hmm.
Onto an Amazon stack, or, you know, and then as popular as Kubernetes. And the whole cloud native thing is still hypervisor. Mm-hmm.
Right. The hyper, the, the hypervisor doesn't go away. And it's the same thing with the Linux now.
No, we haven't replaced Linux os, but if you look, there's been a lot Rocky Linux, you know, 'cause Red Hat's done some things with their Linux, and so other people have said OS and so are other people have come out. So though it may look like a monolith, there are cracks, there are changes that you see happening. Same thing with database.
Right. Another announcement here this week by Amazon, you know, they're claiming, uh, I guess it's based on Postgres, right? Yeah.
Or Aurora. The, the, the better, A better Aurora. Mm-hmm.
Uh, just, uh, folks in my team said, oh, we need to add a Postgres, uh, compatibility and, uh, SEL ourselves. I told them like, look, I definitely want to do that, but let's be focused. Uh, and I gave Aurora as an example.
The, the, the great team at AWS have been working for years and years with like huge teams and huge scales on Aurora, just to add it. And they compete with, uh, the plenty of other fantastic players like a cockroach and Hugo Bite and various flavors of, uh, um, of Postgres. It's, it's kind of, uh, you've got to be focused, and we're trying to be as much focused as what we do.
You know what, so I wasn't always on the media side. I've done tech startups most of my life, and that's, that's really the job of A CEO sometimes is you gotta know when to say no. Right?
You can't, you can't boil the ocean. You can't be everything. You gotta pick your fights, right?
Pick your bullets. And the, um, yes, there's a lot of Postgres kind of noise and tumble out here, but you don't, if it's not your, you know, it's gotta be in your priorities and you can't do everything on every time. Now, Sila people who, what, what, what, what, what's, what's the special source?
Why do people want to, why would people want to use cela? Um, sure. So CELA is a distributed database.
Uh, it's a no SQL database. It doesn't, uh, support SQL, but the trade off is that it's, uh, extremely fast. It, it's fast distributed is, uh, very res resilient for, uh, any type of, uh, high availability failure, disaster recovery failure.
We run a deployment across, uh, eight regions in, in one cluster. And all of them were zone aware. So extremely, extremely resilient.
And its fast. So three nodes can do a million operations per second. Um, so it, it's extraordinary fast.
Or originally we rewrote Cassandra from scratch. We, we started their project by stumbling on Cassandra. We figured Cassandra is a very interesting project, Cassandra itself, uh, to try to implement an open source alternative to Dynamo, DP and Google big tables.
Yeah. And, uh, they have, and it's a viable, uh, project. The, the problem with Cassandra, it's more of a high level implementation in Java, not the best choice for, uh, low level software.
And throughout all of our careers, we were working in really low level, like, uh, AVI checks, uh, every c plus last line to check how the assembly looks like. And also, we, we check to maximize the, the bottleneck of every compute, uh, instance, network instance, uh, eh, the storage at the NVME drive. So we squeeze every bit of, of the hardware in order to have the best, uh, throughput, uh, latency and efficiency.
That's excellent. That was an excellent, uh, description for the people. Um, for people who want to maybe give this a world, give it a try, find out more, what's the best sort of on ramp?
Mm-hmm. So the, there are multiple options. Uh, one can just download the, the free open source version and another, and running a docker or run an enterprise trial.
And we have a database as a service. Uh, two third of our revenue comes from the database as a service. Uh, we can run in our account, in the customer's account.
Uh, so it's relevantly simple to, to consume there. There's free trial, free tier over there too. And so pretty simple to run.
Really simple. And, you know, like you said, there's a lot going on within the whole database space. The No SQL look, no, I, no SQL databases probably came out.
They really hit their heyday around 2000, or, you know, we first became really, uh, aware of them 2008, 2009, maybe 2010 in that area. Couch base, Mongo. Actually, it wasn't.
There was couch and then there was, I forgot what base was they, they merged a big couch base. Right. And, um, so it's a, a relatively mature technology at this point.
Some people say, well, what, what's new under the sun? What, how else, how else do you address this? Mm-hmm.
But you guys announced some news here, or relatively recently for, for reinvent. Why don't you, if you don't mind, do share a little bit of that with us. Absolutely.
Um, so, um, for years we were trying to simplify what Sila is by, by having a one sentence of, uh, the power of Cassandra. 'cause we're, uh, we give everything Cassandra can can do with the wire compatibility at the speed of Redis. Redis is super fast in memory database, eh, mostly used for caching.
And we can, uh, provide almost the same latency and in memory, um, cache can give you, but from the disc, uh, with persistency. So we used this, uh, uh, power of Cassandra at the speed of red. The missing, um, piece was the usability of DynamoDB.
'cause, 'cause DynamoDB, uh, it preceded MongoDB. The, uh, they develop, it's, it's, uh, internal development from, uh, 2004 only later became public. And, uh, like a lot of things that AWS do, it's relatively easy to use the, uh, as a service nature, uh, it's really easy to spin and it's, uh, um, the elasticity to add and remove.
It's, it's more for serverless nature. You don't see the servers in, in the front and, uh, probably the, the rest of the industry, how they develop. It's more of a, uh, okay, let's take these servers and, uh, make them available to the users and also have a, as a service on top of that.
But, but these, uh, it's hard to get away from those servers component. Uh, what we've done recently, we, we did the major architecture change. Uh, we, we changed all of how we deal with metadata.
We added consistency layer based on the rough consensus protocol. Very, very important for consistency and ease of operations. That, that one big piece, it's, it's a big project that took us four years to roll out in, in stages.
Uh, and the last bit is, uh, a portion called tablets. The, the idea is to not to think about the server as in, in the da, the database cluster as big tables. They're gigantic tables, eh, but divide them not just for like charted per server, but chart them into tiny pieces called tablets of, uh, five gigabyte, uh, each.
And those tablets are very elastic. So let's say if I need to load balance, uh, in my deployment, and I need to add double the amount of servers I've got, so we add servers, but, uh, then we need to stream the data to those servers. And normally if every server has, let's say, 10 terabytes, a relatively large amount, need to divide it and send half away, it's, it's a lot of, uh, streaming to do to be done.
And it takes time to do that. And until half of their right in, in the past release, uh, would stream to the other server, then you would sit and wait and you use the old capacity. And this process, uh, could have taken, uh, hours, uh, sometimes more depending, depending on the schema.
With tablets, it's all five gigabyte pieces. So five gigabytes, it take us about, uh, a second or two to send each piece. And immediately that piece become functional.
'cause all of the metadata is consistent, and the clients become aware, the new data moved from one server to the other. Uh, the clients do not need to know. They, they get notifications and it's, it's, uh, the streaming is becomes automatic, uh, super easy to scale up and down.
We do it best better than DynamoDB, which led the industry. So we can double, uh, your capacity in something like 10 minutes. It's a function of, of the amount of data, but easily double a big cluster in, in 10 minutes.
It's nothing and shrink back. Um, and if you're a customer that changes the way, uh, you, you do your planning sizing, uh, with Sila, because let's say many customers have the workloads a baseline of let's say 100,000 operation per second. And here and there, they may have spikes of usage for, um, like live, we watch live, the audience live up to 400,000.
Sure. So instead of be provisioned all year long with 400,000, uh, operation per second, it's more expensive. You get provision the base, and if there is a spike in minutes, uh, the, the, the database as a service adjust to the spikes.
That's fantastic. I mean, that really, it's almost from what you're describing, I think almost like nanoparticles, but they like transformers, right? They transform into, you know, into one, one thing.
Um, this tablets is available in the database as a service. Is it also available in the open source, or that's strictly a, there's a premium kind of feature. It's also available in, in open source.
It is, but there's differentiation, uh, with the enterprise, uh, visit, it's a bit faster, but, but the open source one is available to, It's fantastic. Let's talk a minute, if you don't mind. You know, a lot of companies over the last year or so, we've seen a lot of companies changing their open source licensing, uh, you know, been a lot going on with how do we make a profitable business with an open source model.
And I thought we solved that before, but evidently it, it's come back up now, you know, you're this co you're CEO co-founder. You maintain a very robust open source community around Solar db. What, you know, how do you view this whole licensing?
And are other people using it to create a commercial product and, you know, kind of living off of your hard work? How, how do you view all that? It, it's definitely challenging and it's pretty much never solved.
'cause, um, e even companies like, uh, you mentioned Rocky Linux and, uh, uh, red after Santos, e even a mature company like Red Hat need to, uh, constantly adjust the, uh, uh, what, what they do for free, what, what they do for paid. And, uh, uh, when I was a Red Hat employee back in 2008 to 12, there were lots of internal discussions about, uh, how not to expose, how, uh, um, red Hat Enterprise is being, uh, built and, and all of the composition of the packages. But because, for good reasons, because other people, uh, clone it and come up with a free ride.
Yeah. From understandable reasons. But, uh, it, it, it's really tricky, this model.
Yeah. Um, it's really, it all open source, uh, work really well when, when it's not your core business. Uh, so let, let's say if, if you're a Facebook and you publish your ai, then it's, it's not still, it's supportive to your business, but not core.
That's great for companies that the open source is core for their business. Uh, it's a give and take relationship. Uh, and it needs to be adjusted.
Uh, and we see what other database companies have done. Um, with, with licensing, it's, uh, it, it's hard out there, uh, especially now, uh, where the, the entire market is, becomes more healthy. Uh, we don't have like, huge amount of piles of money, like 2021.
No. And the industry tries to be profitable. Uh, it pushes a lot of users to, uh, free or free usage.
And that's creates the pressures on vendors. And it's more of a cycle. So sometimes it moves here and it moves back and need constantly to figure out what's the right thing to do.
And we adjust from time to time what we try to do to minimize the amount of change, uh, that what's available for free, what's available for paid. Uh, we, we do try to minimize and not to make, uh, wave, uh, to absorb those wave. Sure, Sure.
Have we mentioned the website? Uh, Did we give the URL? I don't think we did.
Uh, So thank you. com, And that's both for the open source and for the, uh, database as a service, or you get everything from one site. Mm-hmm.
That's fantastic. Dora, thanks for stopping up. I hope you've enjoyed AWS reinvent this week.
It's been a good show for you. Yeah, it was super busy as always. Yeah.
Uh, lots of meeting, like it's an industry Show together. Yeah. Uh, wonderful to meet everybody.
And, and now where the, the, the brand is no more known. Like, people stop me and say, oh yeah, sure. Need to, like, folks from Korea folks, folks from, Well, that's the internet all over the world, right?
I, it, I still get a kick outta that when we do our webinars and people log out and say hello from here and hello from there, from everywhere, you know, and I, it kind of blows my mind still, even though I'm at doing this, I don't know, 30 years. Uh, anyway, continued success with Cilla db. Come back, keep us posted and we'll talk soon.
Absolutely. Thank you. All right.
Cilla DB here at AWS reinvent. We'll be wrapping up our coverage at the end of today. Uh, it's been a exciting week, and if you're watching this live, all of our, uh, interviews and content from this week will be replayed on text drunk TV next week.
So not to worry. If you wanna rewatch this or whatever, you'll catch it next week on Textron tv. Until then, though, this is Allen Shemel four Textron, thanks for watching.
We'll be back in a little bit. Hey everyone, it's Sunny And Cher. Ladies and gentlemen, tech enthusiasts and future Gazers Gather round the biggest, boldest, most mind blowing predictions for 2025 are coming your way at the Predict 2025 virtual event on January 9th.
Oh, Sonny, you're predicting something. Again, last time you tried this, you said laser dis for the future. How'd that work out for you?
Hey, hey, Cher. Not every prediction's a hit, you know, but that's why we've got the real experts this time, top analysts, visionaries and tech leaders sharing what's going to rock our world in 2025. So, no sunny predictions this time, no flying toasters making a comeback.
Very funny share. But seriously, we're talking AI breakthroughs, cybersecurity game changers, the future of DevOps, cloud Innovations, and so much more. And what about my favorite prediction?
A smart mirror that tells you how fabulous you look every morning. That's real innovation. You're already ahead of the tech share.
But if you want to hear the really big stories in tech for 2025, you've gotta tune in on January 9th. The event kicks off at 8:45 AM Eastern and runs until 2:30 PM And the best part, it's all virtual. No stuffy conference rooms, no long commutes.
Just grab your coffee, your laptop, and join us from anywhere in the world. You know what else? It's not just predictions.
It's insights, strategies, and a whole lot of fun. 0, predicting your jokes before you tell them. That's a good one, Cher.
But the real joke is if you're missing out on this, so don't miss Predict 2025. That's right. Mark, your calendars January 9th, 8:45 AM You start, be there.
Or you'll miss the biggest scoop on the future of tech. See you. I predict 6 20, 25.
Be there. This is Techstrong tv. Hello everybody.
We're back at OpenText World in Las Vegas, and we're here with Shannon, who is the CIO and Chief Digital Officer for OpenText. And you made, even by Las Vegas standards, a pretty big bet today, a billion dollars in savings in 10 years. It's not a bet.
Uh, a billion dollars in savings in 10 years, we will absolutely achieve as part of our plans. Yes. All right.
So walk us through how that's gonna be accomplished. I know there's a mix of hard savings and soft savings, and what does that look like? Yeah, absolutely.
Um, the billion dollars in savings is really the result of an aggressive program to deploy our own technology. And so it's based on our program of OT trusts, ot, where we've deployed over 60 of our products, uh, that have a large focus on, um, helping operations. So we have a portfolio of IT operations, management products and developer tools and so on.
And so by deploying those products, we're real, we're seeing real savings. And the savings roughly break down in about five categories, um, which is focused on our, um, footprint in terms of our hardware and data centers. Um, optimizing those, consolidating those, optimizing our cloud costs.
Uh, we have an amazing finops platform that, that we use internally, um, which drives some of our, our financial savings around cloud optimization. Um, we see automation, AI and process management. We showed at the conference this week our Ali AI tool, which we use as our internal knowledge management.
Again, driving cost out, uh, by putting knowledge at people's fingertips and using that intelligence, uh, from a service management perspective, we're taking cost out in terms of employee productivity and efficiency. I shared in my keynote today that we've actually been able to reduce 25% of our level one help desk staff, um, by deploying our service management platform. And so when you look at the breakdown of productivity, efficiency, automation, data centers, um, and as well as cost avoidance, I mean, those are real savings contributing to the $1 billion in terms of soft costs.
Again, not part of the $1 billion buildup. Um, but we see massive benefits for our customers as well by adopting our own technology. Um, number one, from an operations management perspective, it means we can be much more proactive in terms of addressing incidents and helping our customers in terms of resolving those incidents.
So there's major upside for customers as well. As part of that overall $1 billion program. Do you have milestones to hit or is it just after 10 years we're gonna have this amount of savings?
Or is every year is there a target? Oh, Absolutely. We've set up targets as part of the program.
Um, it wouldn't be a formalized program if we didn't have targets. And so as we deploy new technology, as we, um, are introducing new capabilities, uh, we've built business cases to show the value. Um, and these are business cases that our customers as well can realize by adopting our technology.
And so we are absolutely measuring it. My team is very aggressively measuring it. Um, and that's why we had the confidence to share the story today here at OpenText World.
You mentioned finops, and that's kind of an emerging discipline in the land of it yet. You know, I scratch my head sometimes 'cause I'm kind of like, well, were we not paying attention to how much we were spending in the first place? Or so, you know, what is finops?
How do you implement it? And you know, 'cause it's almost, to me it's about culture as much as it is tech. That's, It's a great question.
You're right. It is a culture. Um, it is culture as well as technology.
And I think the, the world of finops has evolved as people have been spending more and more on the cloud. And so I see finops not as a basic practice to manage my financials in it. I see it as a very specialized area where we're looking at our cloud costs and optimizing our cloud costs and managing those very proactively.
And I think for many organizations, the move to cloud meant that they were either lifting and shifting technology onto the cloud, which in some cases people found to be more expensive than running it in their own data center. Where the real value comes is when you, um, optimize your products for the cloud. And that's where finops plays a key role.
Inside our organization, we use one of our own tools, um, which is part of the IT om portfolio, uh, for financial operations management. Um, but we have a team whose focus is developing placement strategies around the cloud and looking at constantly, um, how to, um, rightsize what we have in the cloud and optimize what are the cloud technologies that are available, are we using them? So it's very, very much a part of the, the, um, uh, culture of the organization to understand the cost and the benefits and the business case for why you're doing things.
Mm-hmm. And you're also the chief digital officer and a lot of organizations, the CIO and the Chief digital officer are not always the same person. And now we're starting to see the rise of everything from chief AI officers and chief data officers.
Um, and I can't help but wonder if that maybe is too many silos and maybe a little counterproductive. And maybe is everything coming back towards the CIO in the first place? It's a great question.
I it has evolved and you've seen it kind of expand and contract. I think that depending how your organization is set up, depends what roles you have. Um, data is also part of my responsibilities and uh, and we have a data team that's part of our IT organization.
Again, different organizations set up differently. I think for me, what's unique about my role is that, um, in addition to managing the corporate IT side where I'm supporting our 22,000 um employees, I'm also managing our commercial operations, supporting our 330,000 plus customers. And so those pieces coming together has been, um, has been fantastic in terms of, you know, driving real commonality and standardization in our approach and meaning that we can actually deliver better experiences for our internal and external users.
So you can call me what you want, I think. Um, but, uh, but I, I know my role, my role is to drive the best possible experiences for my internal stakeholders and my external customers. One of the questions kicking around the show is with the rise of ai, if I look inside it today, there's a lot of silos and each of those silos has specialists.
And I can't help but wonder what the rise of ai will we see some sort of reorganization of the way IT teams themselves are structured as we kind of change those workflows? Yeah, it's a great question. I think that, um, AI brings a lot of capability and a lot of possibility for how you, um, design and build and test and run your applications and your code.
And so we definitely are constantly looking at, at that in the IT organization. I do think that there's always a need for domain expertise, and you're not inherently getting that out of AI today. It doesn't mean it might not be there in the future, but definitely I don't see that there today.
And when I say domain expertise, I'm thinking about, you know, my ERP system, um, my HR systems, um, my service management. You know, definitely there's knowledge and experience in terms of those systems and business processes and capabilities, um, that when married with technology means that you can actually deliver great products for your business users. And so where I see the rise of AI is, you know, more in the repeatable tasks and areas where I'm designing and test, or I'm build, sorry, building and testing and running versus that design phase where I really need that domain expertise to make good business decisions and drive the strategy for the products and applications we're rolling out.
Mm-hmm. It sounds like you're all in on AI and other organizations are still testing the waters and some people are even resistant. Um, what do you know about using AI today that you kind of wish you knew maybe a year ago?
I think that, um, you know, being all in on AI doesn't mean that you're deploying it for every single use case. And I think that's been an important learning because in the early days of AI and lots of organizations are still in that test phase where they're doing a lot of pilots, they're figuring out what works. I think that, um, that is critical because you need to have that learning curve for your organization as well as figuring out the business case for what makes sense from an AI perspective.
And so, you know, if I looked back a year ago, I would tell myself, don't rush. Take your time. Figure out what makes sense and make sure you're getting real business value out of what you're trying to implement.
Because not every use case you can implement anything in software. I always tell my team, we could do anything in software. The answer is always yes, everything's possible, it's software, but it doesn't mean it's the right thing to do.
And so it's exact same with ai. It's possible, yes, but doesn't mean you should do it. And so really understanding the drivers, the business case, the impact on the organization, um, you know, looking at the whole, um, security and risk profile, making good decisions that are right for the organization takes time.
And you need to learn and understand the technology. Your teams need to understand the technology. And so there's always going to be a journey for organizations.
And I think that's what excites me the most about our approach to AI At OpenText, we are bringing AI and the aviators to the data. And so in a lot of organizations, and you know, when CIOs that I talk to, they tell me they're struggling with moving all of their data into a cloud that could take them a year, 18 months, 24 months to do, and then they've gotta build the AI on top of it and the use cases then they're trying to figure out as well. Whereas our approach is we have the data, we're bringing the use cases and the aviators to the data.
So you eliminate that phase, um, and that investment that's required by organizations to move the data and you're able to get to the business value much faster. And that means you have a greater tolerance for test and fail as well, right? Um, because you haven't had to make that massive investment.
So I really believe we're spot on with our strategy and that's why I'm very bullish on the opportunity with ai. Old timers will tell you that moving data, nothing good ever happens. Um, and you're talking about bringing the compute essentially to the data.
Have we come full circle on that? 'cause in the cloud era, we were moving data into the cloud all the time, and now maybe we're coming back to some fundamental principles In some sense. We, we have come full circle and I think, you know, you see that a lot in technology.
We end up coming full circle on many things, um, and concepts that held in the past, you know, become true. Again, I think that, um, you know, there, there, there can be cases where you want to move data, uh, there will always be those organizations that are striving to move data. Um, but the less data movement, um, is better for organizations, especially when you're trying to secure and protect your data.
Um, you've got re regulations that you have to abide by, your customers are concerned about data protection. The less movement you're making of that data, the better. And so bringing AI to the data makes a lot of sense.
All right. There's an old joke about what CIO stands for. I think everybody knows what that is.
Career is over. Um, what do you say to your fellow CIOs about where they are in their positions these days? Is it, is now the best time to be a CIO in memory?
Or is it kind of in a state of flux somewhere? I think it's a great time to be a CIO and I think the CIO has never been more important to the business. And I think that, um, you know, I always tell my teams and, and my colleagues that, you know, CIOs need to focus on driving real outcomes for the business.
And where CIOs fail is when they're implementing technology for technology's sake. And, you know, we're technologists, that's kind of fun. Um, but that's not a path to success.
And so I think, you know, really embracing driving business outcomes and being a strong partner with the business and, you know, business leaders are becoming more and more tech savvy, and so they want to work with the newest technology and they want to embrace it. They want their teams to be part of that journey. And so that makes, um, you know, I think that makes it a fantastic place to be these days In that regard is we've had this divide between IT and the business that people have talked about for decades.
It's clearly getting better, but I can't figure out if it's, are the IT people understanding the business better or are the business people really understanding technology better? It's both. It's absolutely both.
I think that, um, good IT people spend the time to understand what's driving the business and the challenges they're facing, and they frame the problems they're solving in business language. Similarly, great business partners understand technology and are able to translate. And so when you have both teams coming to together, um, that's when magic happens.
And you know, when projects go wrong, it's usually because one team or the other is not meeting in the middle and someone's trying to compensate. So I do think both is happening. I think that, you know, you talk to finance leaders, you talk to, um, sales leaders, HR leaders, they're all talking about technology and they want to understand how they can use ai, how they can use new tools to become more productive and meet their KPIs.
And so there's, um, definitely a vested interest in getting the right technology and that that makes life easier for IT partners, um, because they're not trying to drag the business along the businesses in partnership with them. Um, so I think it's definitely both As CIO, what is that number one priority for you right now? What's at the top of the to-do list?
What's the thing that you're like most focused on in the next few months? Well, definitely the operationalization of the plan I talked about today. Um, so we need to continue to deliver on that.
Um, but I think it's supporting the business objectives. I think, you know, number one, knowing and having a team that understands each and every day how we contribute to driving the outcomes of the business, the top priority. And that will translate into a set of activities the team needs to engage in to support the business, but it's not transforming this system or that system or introducing this new technology.
It's really tying our strategy to the business strategy and knowing exactly on a quarter by quarter basis, how are we helping drive the outcomes for the business. Um, that's where I want my team focused and that's where I'm focused. One of the things you will hear from application developers is they think that because of AI tools, they might be writing more software in the next couple of years than they wrote all last decades.
Are we from an IT perspective, prepared to deploy and manage that volume of software? Yeah, that's a great question. I think equally as, um, developers become more productive with new tools, it becomes more productive in being, in terms of being able to, um, launch products, manage products and operations.
And definitely if you looked at the ratio of applications to, um, resources, it's grown over time. So, uh, the, the capacity that you have is able to manage a larger set of applications because there's tools for deployment, there's tools for release management, there's automation around upgrades and so on. And so I think that, um, that value chain of having, um, automation and capabilities for developers follows through into how you deploy and manage.
So equally, I think that, that, uh, that landscape will grow for it. All right, folks, you heard it here. Hey, when it comes to IT, AI and being in this industry, there's more opportunity than ever.
Great man once said, all we have to fear is fear itself, and it's probably still true today. Hey, thanks for being on the show. Thank You very much.
All right, we'll be back in a minute. This is Textron tv. Hello folks.
We're back at Open Text World in Las Vegas, and we're talking about reinventing the knowledge worker with my friend Lindsay. Lindsay, welcome to show. Thank you so much.
You know, I read this study just the other day and it surmised that the number of management positions was increasing, and it suggested that the reason for this was because more of these AI agents needed to be managed. And so people are starting to reinvent some workflows. And I wonder if the term knowledge worker itself is becoming obsolete because we're all becoming maybe knowledge managers.
That's actually a very interesting way to put it. We haven't thought about it that way, but something that we're talking about this week is about the use of AI to elevate or reinvent the knowledge worker, right? That, um, instead of our best and most talented people in the company spending their time managing information, um, you know, trying to work through these manual arduous tasks, right?
That there is an opportunity for knowledge workers to leverage AI to put the information to work for them. Mm-hmm. Right?
Um, so in, in the sense of, um, you know, what you said is, what was the term that you used? Knowledge management? Um, Knowledge managers.
Knowledge managers, right. Um, I think it's really about, um, enabling knowledge workers or knowledge management to leverage information in more powerful ways, right? I think also one of the dirty little secrets about this business in general is that there are people who are specialists, they have a lot of knowledge, and they're working on their own projects, but everybody knows that they exist and they keep asking them questions that interrupt what they're trying to do because they're trying to be helpful with other folks.
Will it become easier to kind of distribute knowledge in a way that doesn't always require a human to sit down with somebody to do that? Absolutely. And, and maybe we can consume all this stuff in a better, more efficient fashion.
That's exactly right. Um, the whole premise of Aviator, um, which is something that we've been talking about this week, is the opportunity to leverage interactive chat interfaces, natural language questions, to interact with information in entirely different ways, right? So when we think about really document heavy processes or aspects of the business where in the past somebody may have had to manually comb through hundreds of pages of documents, imagine something like that being as easy as just typing a question into a chat to get a nice consumable summary or an analysis of a piece of information, right?
That's just the beginning though. How are we gonna manage all these AI agents that are working on our behalf? I know you have like 15 of them now, or what you call, um, The aviators, Aviators, um, which are actually super sets of a hundred or more agents themselves.
Um, will we as humans be able to manage that workforce? And It's a really interesting topic and something that we've been excited to talk to our customers about. Um, many of the customers that we've spoken to this week are at different stages of their own AI journey, and whether that's at the start of kind of ideating the strategy, upskilling the workforce, or even going, you know, full through to adoption.
And, um, a big topic that we've had with some of those customers this week has been the topic of upskill in particular, right? Because the lack of, um, the right skills or the resources is often what's holding organizations behind from being able to take that next leap into ai. Um, so to your question, I think that there is, um, a lot of learning and we should all be ready to embrace new skills, and that's what's gonna help us take it to the next level.
I'm not sure looking at the agents what skills I need to learn because it seems like the agents are pretty, uh, simple to use. They're kind of, um, self-evident, and I'm not, and I didn't feel like I had to become a prompt engineering expert anymore if I look at these agents. So have we kind of moved beyond prompt engineering now and we are gone to a higher level?
I think you're right. Um, it's been very much about, um, simplifying that knowledge work or that end user experience versus more of the technical, um, things that are happening behind the scenes. I'm a marketer, right?
So I'm, I don't claim to understand all the, you know, the deep things that are happening underneath the hood, but it is that simple in some cases. And, um, I think that, you know, again, it's um, there's an opportunity for all of us to be thinking about what the next jobs are that these AI tools or these, um, interactive chat interfaces are gonna unlock for us. Is it your sense that the folks that we used to call knowledge workers, um, are they excited about this or are they, is there a little fear and in trepidation in, in the mix as well?
And how do they kind of navigate that? That's a great question. Too.
Um, I think that, uh, there's an obviously an opportunity for AI to eliminate a lot of, again, those like manual tasks and that like, you know, the, the arduous work again, right? The things that are holding us back from being able to do more meaningful work and make those strategic decisions. Um, but I don't think that we're at a point where AI is going to replace knowledge workers.
It's really about taking them, allowing them to, to be elevated within the organization. There's an old saying that says, if you do something, enjoy, you never worked a day in your life. Are we getting to that point now where we can focus on the stuff that's fun and all the other stuff that gets in the way will just be automated?
That's the vision, right? I think that's, that's absolutely the vision. So that, again, those most talented people in your organization are no longer bogged down with managing information, but that they can focus on doing, um, things that are going to deliver, you know, it's innovating new products or it's, you know, expanding meeting new customers or expediting medical care, things like that, that are much more impactful.
Mm-hmm. Is there gonna be large scale re-engineering of some of the workflows that knowledge workers are tied to? Because it seems to me that I'm gonna have all these new capabilities and maybe doing things the same old way, it might not make as much sense.
So are we gonna take a moment to kind of rethink all those workflows? I don't know if we're rethinking the workflows as much as sort of re-engineering the way that they happen, right? So again, um, one of the awesome examples that we showed in one of our sessions this week was taking something as simple as a sales contract approval, right?
And being able to use an interactive chat interface and natural language questions to actually prompt that workflow and then automate some of the things that are happening on the backend, such as when, you know, in this particular example, the document needed a certain sales director approval, right? Once it was approved by that person, the AI is actually then taking it to the next step of being able to PDF and water market, right? So the step itself, or the workflow itself is very much the same.
It's just how it's actually happening. That's that much easier for the knowledge worker. Do you think maybe eventually we might restructure organizations in the age of ai?
Because a lot of the tasks are created and roles assigned to tasks are based on the fact that some thing had to be manually done. Well, if it doesn't have to be manually done anymore, can we maybe take a step back and say, Hey, what is your job description? And, and what might that look Like?
Yeah, I think you're absolutely right. Again, it's, um, not so much about replacing jobs, but freeing up knowledge workers for the next job, right? And that's, that's truly the reinvention of knowledge work.
What are you hearing from customers? What are they struggling with in this whole conversation? I mean, you've been walking around the show floor here.
What's the feedback you got so far? So again, um, we have customers at all sorts of stages of the journey. And the things that we're finding are most common from a, a challenges or limitations to getting started perspective is, um, again, the, the lack of, uh, sort of a formulated foundational strategy.
Um, having the right skills or the resources to actually implement that strategy. But also, and perhaps most importantly, um, and why OpenText becomes so critical to this conversation is that data readiness perspective, right? And so where we come from in the content management, the document management business, um, and our customers who've been with us for a long time and they've, they've trusted us with their unstructured information.
Um, they're coming from a standpoint of grade advantage because they've already invested a lot of time, um, and effort into getting the information prepared, metadata and, and all those things that makes gen AI that much more impactful. One of the things I hear people kind of struggling with a little bit is that, um, the responses from the AI agents are probabilistic and they might not be the same over and over again. And if you're knowledge worker, you're kinda like, you know, driving a process that's a little more deterministic.
So the fact that the thing tells you something that's similar but in a different way kind of drives you crazy. Again, that's where, um, I think OpenText customers have an advantage where, um, we're through the concept of something that we call the business workspace. You're curating information that's all related to each other, and by virtue of asking questions against documents and data that all are, are, you know, related to a certain use case or, um, what have you, that the results that you get back are that much more relevant and accurate.
Yeah. How do you think this will play out when I, as a knowledge worker will have my small army of AI agents and you as a knowledge worker will have your small army of AI agents and somehow or other we're all gonna collaborate together and to do something. How does that process work in your mind?
Because everybody's gonna have all these different AI agents? That's a another excellent question. Um, I think that that's something that we're still trying to explore right now.
And one of the things that we're hearing a lot from customers is, you know, how can we anticipate that all of these, um, AI agents, as you say, how will they interact? How will they interoperate, right? And so we have some really excellent partnerships with organizations like SAP Salesforce and Microsoft that we're really going to build up, build upon and leverage to make sure that we can, um, deliver impactful solutions to our customers that allow for that AI to ai um, integration.
Do you think I'm gonna have like one kind of senior level AI agent that manages all the other AI agents? Is this gonna be like Downton Abbey where there's a head butler Perhaps? Um, and from my point of view, content aviator could really be that head ai, uh, butler, if you will.
Um, something that we actually showed this week, in fact was, um, content aviator, sort of the primary, uh, agent that you're interacting with, but, um, in the backend, it also has its own, uh, uh, tool or, or agent also, which is knowledge discovery, which is another really powerful tool, um, or solution within our portfolio that does a lot of deep, um, rich media analysis and things like that. So it is certainly possible. Can I ask you a question?
Sure. All right. So my favorite question to ask all of the customers this week was, um, okay, imagine every knowledge worker had an intelligent assistant.
Um, what if you had your own personal intelligent assistant, what kind of impact would that have on your life and your work? I think it would make me a lot more efficient, but I'm not sure I would use that time wisely to do something fun and leisurely. I would probably just do more work.
'cause it's kind of how I'm wired. Um, so, um, but then again, my family might figure that out and they might be saying, you know, you don't have to spend as much time working on the weekends, so we can go do this, this, and this. So I'm sure that, for example, my wife will probably have an AI agent somewhere that figures that out for her, and she'll just start scheduling stuff and she'll say, devil be damned.
You're going, A scheduling agent would be the best thing for all parents, wouldn't it? Yeah, That would be kind of cool. Although the kids will have one too.
So then the kids will start scheduling things for parents too, so things could get a little kind of topsy-turvy and upside down. Absolutely. Let me flip that question back to you.
You're clearly on the front end of using this technology. How has it changed your job, your daily life? What are, you know, what, what's different today than from a year ago?
So, I'm a marketer again. Um, we create a lot of content and one of the most immediate benefits that I think we're gonna see in marketing specifically is the ability to, you know, again, think about, um, we've managed a diverse portfolio of products and every time we launch something, there's new content that has to be created for those products. What if we could take, um, you know, release notes and things like this that are coming out of our product management team and leverage AI to translate that into marketing content, right?
Content creation and content generation is a super impactful productivity gain that we're gonna see the Ben benefits from very quickly. We have our own sales statement. We're constantly now yelling at them going, Hey, why don't you just create your own marketing collateral?
Exactly. Exactly. It's a huge enablement tool.
And even when we think about emails and, you know, maybe I can get some creative inspiration and, you know, help get a, an, uh, a content aviator to write this email for me, right? Learn, learn to do it in my tone and my style, right? And I think the tone and the style is a, a, an important part of this equation.
'cause in fact, we were just having this conversation with, uh, a shimel who runs text on, and I'm like, I see this content, but it needs more personality. It needs you in that story, and it needs to come through there. So, um, I wonder if we'll go through a phase here where everybody will be like just auto generating some content and letting the machine do it not, but not adding that human element that makes a difference.
And that's where, again, we can, it's a starting point. And we, with our, you know, again, our skills and the knowledge that we have about the business can then come in and fine tune the result. It's all about just those quick productivity gains initially, I think.
All right, so once your prediction 2025, how fast is all this gonna come? I mean, is is that knowledge worker gonna be reinvented next year or the year after? How fast It's a journey and things are happening so fast.
Um, it's hard to predict, but I think that we'll absolutely see from OpenText at least. Um, you know, once we get the, the, the phase that we're in right now again, are like those quick productivity gains, automating, um, you know, some of these like, you know, common things like, you know, making information easier to find, right? That's an easy thing for us to do.
Um, breaking down content silos, creating or generating content, um, I would say by the end of next year that we'll certainly have made some impactful advancements on the workflow automation part. That's something that's gonna be really exciting to talk about next year. All right.
And last question. What do you know now that you kind of wish you knew a year ago about all this? Oh, tough question for the last question.
Um, I think that it's, you know, we're still, um, our customers are still on the journey, right? So one year later we've got, you know, every conversation that we're having is about ai and that's super exciting. Um, we have customers that are buying it and trying it.
Um, will we be at a point where everybody's using content aviator by next year? I hope so. Um, but, you know, I think because of a lot of the unknowns and how rapidly the, the market is changing, um, the technology behind it is, is evolving that, um, you know, we're, it's still, we're still learning as we go, right?
All right, folks. Hey, you heard in here, instead of being a knowledge worker, maybe you become a knowledge manager and give yourself a raise. Hey, Lindsay, thanks for being on the show.
Thanks so much for having me. All right, And we'll be back soon. com is the number one online destination for DevOps education and community building.
com covers all aspects of DevOps, including DevOps, best practices and tools, tools, DevOps, culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content, featuring breaking news, blog posts, podcasts, and more. com to learn more.
com, where the world meets DevOps. On this episode of the Tech Field, a podcast, we take a look at ai, specifically how AI tools can help your operations inside of enterprise it. The answer is quite simple, but more complicated than you might think.
Welcome To the Tech Field Day podcast, where we bring together a group of IT experts to discuss an idea about key topics in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded in association with one of our events. Tech Field Day is a part of the futureum Group, and this podcast is also published on our sister sites Techstrong tv.
I'd like to take a moment for our guest to introduce themselves before we jump into the topic or the premise for this episode. Uh, hi, I'm Kerry Kulp. I'm, uh, founding partner at VEP Span, uh, an enterprise mobility and cybersecurity consulting firm.
Uh, my name is Keith Parsons. com. Thank you Tom Ron Westfall, research director here at the Futurum Group.
I lead our networking practice, and always a pleasure to be joining a Tech Field Day podcast. All right, thank you all for joining us. Let's jump into the premise for this episode.
You've probably seen a lot about AI in the news recently, and you may be confused because AI is everything, but it's also nothing. And when something is everything and nothing, is it really anything at all, the key is to figure out what AI can help you do. And that's why we brought together some professionals today to talk about this, because it turns out AI has a lot to do with the way that we do our jobs, especially in the operational side of enterprise it.
And we need to get a handle on what that is. The premise for this episode is that AI can help with operations. Now, I'll be the first person to admit that last year, 2023, everyone was talking about putting AI in everything.
It all had to be AI enabled. There had to be LLM support for my recipe application. And it's dumb.
Let's, let's be fair. I, I don't really need that. But as things move along, we have found ways to use specific aspects of what AI is capable of doing to make our operational lives easier.
So I kind of wanna open up the floor to you gentlemen. What are some ways that you have used AI in enterprise IT operations to make your lives easier, Like probably everyone else? Uh, as you said about a year ago, we kind of dove headfirst into ai, generative AI as a concept and understanding what it can do for us.
Uh, obviously we've had exposure to AI for quite a long time, but generative ai AI tools really kind of changed the dynamic quite a lot. Um, we quickly realized that, like you said, it's everything and nothing all at the same time. Uh, but fairly quickly we started to evolve how we engaged with it, and we really learned that it's good at a lot of things that maybe humans aren't as good at.
Analytics is an example. So feeding it large data sets and letting it parse those data sets and pull things out of 'em that are meaningful, or I, I search for those meaningful items. I think that's how we pretty quickly figured out where AI can help us.
So from that perspective, um, log file analysis, pulling logs, feeding it into a generative AI tool set, giving it some parameters, giving it maybe a, a, a persona that we'd like it to adopt and helping it help us identify trends or anomalies or errors or warnings or something like that in that log file, which could be millions and millions of lines of data that would take us, you know, mere humans hours and hours to parse. It doesn't nearly instantly. It's not perfect.
It doesn't necessarily land on exactly the answer, but it is so much better than starting from zero. It just gets us down the road farther faster, and then the brains have to get in involved in and really dig into it. That's gold, Kerry.
'cause, uh, what I am seeing is that AI can do just what you're pointing to that is improve the workforce experience, and that includes, uh, making operations more efficient, automation of data gathering, uh, getting data insights, and also quite simply improving business outcomes. And this is the good news part of ai. Yes, there's challenges.
It's still, you know, the data in data out challenge, it's been with us for decades. AI is only good as the data management tools that you have in place, but still we're seeing, I think, tangible improvements in outcomes. Uh, for example, uh, by using AI powered predictive maintenance models, I've seen that there could be up to a 30% reduction in unplanned downtime and also like, uh, up to a three fourth improvement in service resolution times.
And this is data coming, you know, that's, uh, readily available. It's like, uh, that source was field acts. Uh, and, but I think the bottom line here is that AI is going to deliver more good news and bad news is not going to be this technology that's gonna cause in itself widespread, uh, reductions in workforces is going to actually improve the experience for the workforce.
And it's really the outcome is that whoever can leverage AI the best is going to quite simply have a better workforce experience and also improve, you know, what the business can do. Uh, well, I, I, I like what you said, Ron. I just want to add, add a little warning caveat.
One of the things I've seen that AI can do is very quickly solve the easy problems. The ones that, that, that an experienced person would look at and go, yeah, I got that. So it starts doing those easy ones, meaning IT professionals who are working on a system don't have experience on those little things that, that, that break and that you get really good at fixing all the time.
And it's kind of boring. So it takes that away. And what happens though, is it's now AI's fixing so many of the issues that the issues it runs across are really difficult.
And I'm, I'm concerned that practitioners won't have that, that baseline understanding by the time it gets to a really what AI can't do, no one has that experience that that, that all us old folks have that we've, we've figured out over, over the years. So there is a little gap in between there. One of the things I've tried is using AI to do packet analysis in wireless, we have to point the finger at someone.
And if it's not the client, it's the infrastructure side. And neither of 'em will admit until you can say, look at this frame, did this thing and yours did the an the wrong answer. Finding those is really difficult.
It takes a lot of experience to, to get into the packet analysis. Ai, even in packet analysis, can take you like cor like Kerry said, 80% of the way there, but that last 20% is even harder than it was finding the other. So I, I, I agree it can help the workflows a lot, but that last little bit is still even more difficult than it was before.
So, a thought there, Keith, because this is something I hear a lot from people who are starting out in the industry that, you know, why am I solving this problem over and over again? What, why can't I automate this? You know, uh, if there's an issue with a service not starting, is there a way for me to basically say, okay, if if I have to, to wait five minutes to start the service until the system reboots, then why not put a timer on it?
These kinds of simple things. Now, obviously you have to understand the underlying infrastructure to know, well, why does the service need to wait to start? Or something like that.
But I think kind of coming back to it where you said, being able to do like log analysis or packet capture analysis, like, like Carrie you were saying as well, um, is giving our people a chance to focus on those hard problems. Maybe they do need to spend a little bit more time studying so that they understand seeing this log entry followed by this log entry that's correlated with this other log entry means that this is this problem. But at the same time, by being able to correlate those things together and feeding that feedback back into the system, we're effectively making the AI tool smarter by saying, the next time you see this pattern, this grouping of messages, it's indicative of this problem.
So we're, we're basically training ourselves to make those problems easier to spot, because we're using knowledge that can be gained by filtering out the noise effectively. Yeah, and I think, Keith, you, you touched on a problem that I don't know that I really ever put into words. It's a, it's kind of like a future problem, right?
If we're not, if we're not letting the junior engineers fix those simple problems that would be, would start to form the foundation of knowledge that they need to dive into the deeper, more complex problems later, that probably really is a bit of a, you know, down the road, let's say expert shortage, you know, foresight that we might, we might have. Now that said, I, I think, uh, so for us, we are using it a little less to solve problems and a little more to speed up the, an analysis. So it's, it's less to say, tell me what's wrong and more about giving it a, a set of parameters for what we're trying to identify and helping it parse the data or having it parse the data for us.
Another use case that we're, we haven't actually really nailed down just yet, or, or gotten it to work quite right just yet is for change management. Because we do, we do an awful lot of large scale enterprise deployments that will often have us making large scale, potentially very impactful changes to big fortune 25 kind of companies networks. Well, when we cause a sev one incident that's not great, that doesn't look good, right?
So we're working on kind of building out a, um, uh, a not a model of its own, but effectively, let's call it just a GPT of its own, where, where we can use it to feed in information about the current state, the change state, the change, the, you know, the, the projected changes and have it help analyze whether or not we're going to introduce a problem. And I think that hits a key point about, you know, what is down the horizon. I think Carrie, uh, that's very, uh, valuable to bear in mind what is going on to make these AI models better, particularly on the training side, but certainly also in the inferencing side.
So we're seeing RAG capabilities join with the vector databases to do that specific, you know, customer aligned, uh, language model training so that the data sets are truly correlated with what the business actually needs and can then be automated and then, you know, make everything else run quite simply smoother. And yes, uh, to Keith's point, it's always going to require that balance between here is the AI enabled capabilities, but you still need a human safeguard or fail safe, okay? The AI engine comes up here is something that is an emergency, something an anomaly, uh, something that needs to be looked at.
Do you want to authorize this recommended fix? Or is there something else we need to do? The bottom line is AI is inevitable.
I mean, we're seeing all the investments flowing in that direction, and we just have to figure out how to optimize these AI capabilities, you know, throughout the organization. So I, I wanted, I just wanna interject there one quick thing. Ron, you, you made a really good point, I think about that, you know, having the human involved, uh, one thing that we did before we even allowed our team, or, or anybody inside the organization besides a couple of us that were testing things before we allowed them to use it, we implemented an, uh, generative AI acceptable use policy.
And that basically dictates the framework with within, you know, that, that, that our users have to work within to interact with generative AI tools. And probably the key tenet of that policy is that you, the human, are still accountable for the output. So it's not, it's not the ai, it's not the tool, it's not the GPT that you used.
You can't point back at that and say, that was chat GPT or it was clawed, or it was whatever that made the mistake. Nope. You, the human are still accountable for the output.
You need to review it. You are the expert. You need to make sure that what is coming out of that and what you're then putting into whatever, whatever format is going outwardly is actually accurate and true.
We also set some rules around how you can use it with regard to imagery and things like that. You can't use it with real, real people's images. You can't use it with anything like that because we're trying to kind of put the guardrails up that keep us, you know, from, from doing silly things that, that we don't want to have happen.
Those, those are good things, Carrie, for your business entity, yet I see vendors moving past that. They're taking the, the human out of the loop, especially for the low tier things. I, I need to change some, uh, channels to fix the problem.
So it's, it fixes itself. It then does a pre and a post, did clients improve after I did this or not? And then it sticks and it goes, and there's no human in that loop.
So I, I, I don't think we want humans in all of the loops. When the AI is smart enough to know, and when they train it on their own vendor code, their own vendor data sets, they, they get really accurate at the good stuff, at the easy stuff. So I see that a lot of vendors are moving away from that.
The human's not in the loop on the easy pieces. And that human only comes in when the AI doesn't have data to support. We did this automatically.
So I, I don't have any fear of the AI doing automatic things. Um, when it's the vendor's ai, 'cause they have, they have way better data because they trained it on their own internal thing. Some vendors are even using it to write their own code that because we know how we code and we have all these little things done, we can have it on the fly, build something.
Um, and an example, Hamina built a tool to do wifi design in AI in mere minutes. Now, it was not even close to, I wouldn't even say 80%, maybe 50% of the way there, but AI self coded itself. And then they went, well, we'd also like to add heat maps, and within a couple minutes it was adding heat maps.
So there, there's things that can do that can give us better tools that the human can use, but it can also do solve the easy problem. That's what I want to focus on. Yes, easy problems.
Let the AI do it. I don't want to have it bug me every time. You know, a door lock changes, just, just fix it.
So who's the, so the question ultimately becomes, uh, is so, so with a lot of our customers, you know, these are massive enterprises that have really comprehensive change management processes. They have to go through the, you know, the cab and get approval and they have to have rollback plans and everything else. And, and I don't think, while those organizations are almost all using generative AI tools, at some level, I don't think they've matured enough yet to turn over change management to something fully automated.
I Guess it change, it, it depends on what we're talking about in change management. I, maybe not, not switching VLANs around, but changing a channel on access point. We've been having that automated for years now.
Yeah, maybe changing power settings, changing whether or not we, uh, I, I saw one where the MCS rates were at a certain average, and then we would change automatically the data rates that were supported until that dropped, and then you'd change the data rate back down to get the maximum throughput of your airtime. Uh, I used to do that manually and it took hours on site. And vendor, vendor AI can do it really, really quick and have that feedback loop that said, we tried it, things got worse, so we put it back.
That's exactly what I would do personally over a long period of time. And yet AI has way more dataset data to make that decision than I would, and I really don't wanna do those dumb things anymore. So in, in, in the important things that could cause major failures, I, I see what you're talking about, but there's a lot of pieces in our networks that just need to be tuned.
And I think that's an important point, Keith, because when you look at the way that things like LLMs and, and current generation AI work, it's very much focused on correlations, right? I we see this, which means this, or you know, more appropriately for a thing like an LLM, statistically speaking, this word follows this other word in a chain of words. And so there's a strong correlation that this is a sentence you wanted to type, but one of the reasons why that works so well is that you're getting feedback, like you said, tune this and if it doesn't work, turn it back because obviously that didn't work and then the AI eventually learns, okay, that's a bad correlation.
I shouldn't recommend that anymore. But how can we as practitioners avoid those kinds of traps? Because we can see tons of examples of people just reading through the output of chat GPT for example, and saying, oh, well, I'll just go ahead and do what chat GPT said, because obviously it's brilliant.
And as, as Ron alluded to, hallucinations are still a thing. Whether or not you are using rag, you have to know, wait a minute, configuring that command or doing that thing is kind of like putting Elmer's glue on my pizza, even though the system says I should do it. I know better than that.
How can, how can we train people to effectively avoid those traps? Well, I think part of it is chat, GTP or clotter, the big LLM models that are more generic that they've been, they've been trained on some huge, you know, everything that's ever been written on the internet compared to a vendor's own model that's only looking at its own dataset. And the one things I, I'd like to pick up and get Kerry and Ron's feedback, what do you think about digital twins?
Where I, where as a vendor, I know the whole code. I wrote all the firmware, I know where it is. I'm gonna make a digital twin of that and let AI play all day long, and then it's not gonna hurt the real world.
And then maybe the result of that has the human back in the loop to make the big changes. I, I like that it can do things really fast. I I just don't want it to do it and break real systems.
Yeah, that's music to my ears. Digital twins, uh, I think we have all firsthand experience with it. GPS maps, you're able to get that real time interactive information and then act on it accordingly.
Ultimately have to use your own experience to enhance that information that's being provided to you by, you know, an AI capable or AI enhanced, uh, engine, uh, or platform. And I think, uh, what's also important here is that I think it's about right sizing the model. Uh, that is absolutely right, Keith.
It has to be according to the specific needs of the customer, of the vendor and so forth. And well, ultimately, yes, you know, the, the broad based LMS will become smarter reducing hallucinations to the point where, uh, say a year or two out from now, they could even be natively not requiring a rag or vector database capabilities because of all of this intense training that's being accumulated, just getting smarter and smarter. So I think all these will be, uh, factors into answering Tom's question.
Yeah, I think so Keith, the digital twin piece is really critical when with it, sticking with the concept of change management, if we have a digital twin that we can let the AI kind of turn it loose on that and let it do its thing and, and then we can actually start to work up the chain to more and more complex changes because it's not breaking anything. I mean, it might break something in the digital twin, but that's okay because it's just the digital twin. If we can use, if we can let it work its way up the chain there, prove out that it's working and it's not introducing problems, let it go on, let it run that same, let on the production network at that point.
I think that's where it really gets to the point where it can be more autonomous. It's still kind of, it needs that human oversight, I think, you know, to make sure that for the really big impactful things that nothing's going sideways. But then if we have that digital twin and it doesn't break it that turn it loose on the production network and let it go implement that same thing, Or even multiple digital twins that are iterative and it could, like, like chess playing AI from a generation ago, it goes down a path until it breaks, it goes down another path.
We, we could let it run across a hundred thousand, 10,000 digital twins and run it for a year or two years into the future. And it, it's all about how much compute you have to pull that off. Nvidia liked that comment and, and I agree that a lot of companies that are kind of focused on the AI aspect of things are leaving off that digital twin capability, whereas companies that are developing digital twin technology are finally starting to embrace AI to kind of augment what they're doing.
In some ways. They're using current generation AI for things like querying for network information and stuff like that. But obviously that next step is going to be offering capability to do stress testing or to do, uh, change management and things like that.
Do you foresee a time though where we will get to a point where we trust the AI enough to turn it loose to say, okay, if the change checks out here on your digital twin, go ahead and implement it in production. And this kind of goes hand in hand with what Carrie was saying about this generative AI use policy. Will we ever trust AI enough to say, I'm ready to let you kind of run the show at a certain level of confidence with non-complicated tasks?
I I think it's, the definition is the non-complicated task. The other thing I just wanted to throw out and see, I think this is an advantage for NAS vendors where they own the whole stack. They can run a digital twin from soup to nuts the entire thing.
Whereas in the real world who, people who aren't with, with a Nile or a meter or a ramen or something, you have, you have a heterogeneous stack and there's a breaking point as it switches vendors. So their digital twins are way more complex as, as it changes vendors in the stack. Those that whole, that own the whole thing have a little advantage that their digital twins can be fairly accurate 'cause they own everything in there.
So, so Tom, I I want to answer your question specifically. I think there's two parts to your question or two answers to it. Will we ever trust AI enough to let it go?
Depends who we is in that statement, right? Yeah, I think, I think to some degree, yes. That and, and that will progress further and further through the population who the we is is representing.
On the other hand, I think there's going to, there is going to be a, probably the biggest hurdle or biggest roadblock to just enabling us to do that. And to trust AI to do things is going to be more of a legal question. Who's accountable?
Who do I hold responsible when this thing goes sideways? Now, is it, so if it's inside the vendor, pick the, you pick the vendor that's running some AI tool set, well then the vendor's responsible, right? It's, it's their, their ai, it's their tools, it's their network, they broke it.
But what if it is a third party or maybe a, a not even one tool, maybe it's a, a, a mix of tools that are doing things, who is actually held accountable for it? And I think that's the kind of what I was getting to earlier on with regard to the cha, you know, getting a change approved, getting it through cab, making the changes and, and making sure it, it, you know, everything works. We are responsible for that.
And if something goes wrong, the fingers get pointed at us. We have to accept responsibility. We have to, you know, we, we, we get called to the carpet and have to fix it and explain why it went wrong if we just turned it over to a trusted AI and it broke something who's ultimately responsible.
And to follow on that, I think, uh, winners, uh, from digital twins and, you know, AI capabilities include the cybersecurity realm, basically, it's essential. Uh, this is the week of Black hat, and we saw like the announcements are cybersecurity is going to require AI capabilities just to be able to, you know, make the good guys help fight that battle. And for example, we saw HPE Aruba networking coming out, uh, with the addition of NDR capabilities and ZTNA enhancements, and that puts a spotlight on network detection response and zero trust basically are gonna require these digital twin capabilities and then these AI capabilities just to stay on top of the telemetry, particularly when it comes to proliferating iot devices, which are notorious for being, you know, targets, uh, real cybersecurity threats to an organization.
And so this is coming together. This is demonstrating why ai, you know, why digital twins, well, certainly cybersecurity, I think, brings that to the forefront. Yeah, I'll, I'll second that.
I mean, we, we look at it, uh, from our cybersecurity practice viewpoint. One of the biggest challenges that we see in the industry is that the r in all of the, you, you say whatever the, the EDR, the NDR, the, the, you know, MDR, the XDR, the r is lacking in all of them. The response is truly lacking across the board.
And if we can start to leverage AI first to help on the detection side, so on, on the, the detect and identify the threat or the breach or whatever it might be, but to the point of then trusting the a AI to participate in the response, theoretically, the response starts to, to get better and, and more, uh, let's say more responsive. Well, as you can hear from the discussion, there's a lot of potential with generative AI tools being used to support operations in an enterprise environment. The key, of course, is that you use AI like any other tool that you would use.
You need to have a firm handle on how it operates. You need to find the best possible role for that tool. And you need to create guardrails policies in place to ensure that if something doesn't work, then you are not left with a giant blast radius.
And as the tool proves itself more and more capable of doing things, you can widen its scope, you can add additional, uh, capabilities that you are adding to the policy to make sure that your employees are using it to its most effective capabilities. Maybe one day down the road, AI will take care of all the easy stuff and let us focus on the hard things. Or maybe you find that AI isn't a good fit for your role, whatever it is, you're gonna have to do the groundwork to make sure that you're using it effectively.
Don't believe the hype, believe what it can do for you. Thank you for listening to this episode of the Tech Field Day podcast. If you enjoyed this discussion, please subscribe to our YouTube channel or subscribe to the podcast in your favorite podcast application so you don't miss an episode.
Make sure to leave us a rating and a review. This podcast is brought to you by Tech Field Day, the home of IT experts from across the enterprise, which is a part of the Futurum Group. com/podcast or check out some of our episodes on Techstrong tv.
Thanks for listening and we'll see you next week. Welcome everybody. Uh, I'm Pete Garon, director for Products at Active State.
And today we're gonna talk about, uh, taming the complexity of open source with active state. And you probably know a little bit about active state. Uh, we've been around for over two decades.
Uh, we're currently helping 97% of the Fortune 1000 secure their open source. And we've been around since the sort of late nineties, uh, when we started doing, uh, Pearl on Windows and doing that port, and we sort of, we were also a founding member of the PSF. And we've been working with, uh, enterprises to help, uh, manage their open source for the better part of those two decades.
And one of the things we've done recently, uh, we partnered with PI PI on a trusted publishing initiative. And as over time as things evolved, we went from doing things like Active Pearl, active Python, uh, where you might just download a sort of curated distribution of, uh, open source and open source packages to something where instead, what you're doing now is having a tool to manage all of your open source. And so what we did was we evolved, uh, our product first to meet our own needs, uh, internally in terms of what we were doing to manage open source for various enterprises, and instead move that to a product where all of our users could use this and to sort of help them manage, uh, all that open source and tame bit of that complexity, uh, around what's involved in managing open source from the ingestion point all the way through to the, uh, to deployment stage.
And so one of the things is when you're not managing unmanaged open source is exposing you to sort of escalating security and license threats. Uh, supply chain threats and managing this stuff at scale is really challenging. Uh, you know, it's one thing to know I've got a vulnerability in this package, right?
I've got, you know, my, my s e's tool is telling me, oh, yeah, you've got a vulnerability in this package. You need to update that. But it's another thing to actually successfully update that dependency, all of its dependencies.
So everything, all of its transitive dependencies. And to ensure, like the providence of all of that stuff that you're ingesting, you know, dependency hell is a real thing that can really consume a lot of developer time, time. And knowing whether that is a breaking change or not, how safe is it for me to update that?
It's really, really challenging. And so just that, uh, that element alone is really, really simple. I'll just say that one again there.
Just managing, bringing in the updates alone is really, really challenging. And then we move over to observability where I can even understand what I'm using in the first place, right? I'm a large organization, I'm running thousands of pieces of open source software.
Is that cataloged? Is it versioned, auditable, reproducible? Where is it running?
Who's running it? All of that is super challenging. And if you don't have systems in place, it can be very, very painful.
And then on the other end of things, if you're trying to comply with, uh, government regulations or security audits, do you have tools in place there to actually develop and deliver the, uh, artifacts that you need to support the security guarantees that you're giving, right? Can you produce the documentation, the chain of custody information to be and be able to verify that and supply it when needed? All of this stuff is really, really complex, uh, and it's very, very rarely, uh, an end to end solution.
And so it's really, you know, it's no, no wonder that it's, it's a lot of shortcuts that are being taken and, uh, people are shipping with known vulnerabilities or they're doing a lot of ad hoc things. And that's really what we see is that people are really stitching point solutions together. Uh, they're, they're maintaining spreadsheets.
They're, uh, running an ad hoc report. Uh, they're doing, you know, audits on demand, very reactionary, uh, you know, they've got solutions that are kind of diffused throughout the organization department. There's no standardization.
Um, you're managing all these different, uh, upstreams, right? You've got source code, you've got vulnerability DA databases, you've got vulnerability scanning tools, you've got container registries, you've got licenses, you've got SBOs, you've got all these different tools, all these different processes for each one individually, and they're probably largely duct taped together. They're not pro brought together in a coherent, cohesive way, and they're really only partially addressing the solution, right?
They're not seamlessly stitched together. So one of the things that we've seen over the years is that you really do need to think about this holistically, especially when you're thinking about supply chain security. And so what we're doing at active state, and what we're sort of talking about today is like, what's, how do you tame that complexity of all of this stuff?
How do I deal with all of those stages across my software development lifecycle in a way, uh, that is systematic and reproducible and auditable and understandable and also low friction for those inside my organization? So what we're doing at ActiveState here is sort of bringing our, our, you know, decades of experience with os open source management to bear and to provide a kind of holistic solution. And so let me sort of walk you through what that looks like here from the discovery of everything that's running inside your org, right down to the deployment.
And so we saw before there's an open source ecosystem and maybe your even your own private ecosystem, and there's a lot of information that's out there that you're pulling from all these different sources, and you also have a lot of open source that's running inside your organization. So the first stage is really about discovering that, right? It's about discovering and cataloging all the open source that's running inside your organization.
So discovering it from various sources, uh, knowing who's running it and where having a kind of auditable inventory, we'll see that this, this notion of having an auditable inventory is really important. Um, you know, having a spreadsheet of all the open source that's running, probably not gonna cut it, right? Having a diffused set of requirements that TXT files or for whatever language you have diffused across your source code re repository, also probably not going to cut it.
You can't do any kind of sophisticated reporting against that kind of thing. And so then we move on. Once you've discovered, once you even know you can't even begin to manage what you're doing, if you don't know what you're running, then we can move on to the analysis stage where we can gain insights into the risk profile and generate some reports and share that intelligence across the organization, right?
When you have, you know, a DevSecOps, uh, scenario where you've got collaboration happening between development and security and, uh, DevOps professionals, you need to have, uh, ways to share information across that organization into collaborate effectively. And so the first thing you need is analysis of all that stuff that's running. So you need license and vulnerability reports.
You need, what's the impact of taking this upgrade, right? Do it, does it have a breaking change in it? Do I have all of the, uh, supporting artifacts that we talked about from the compliance standpoint, you know, in terms of SBOs, attestations, all that stuff.
But then once you have the analysis, okay, now we have to take an action, right? We need to do something about it. We have to remediate the issue, or we need to get it deployed, or whatever.
And so then you need to have tools in place to be able to scale that across your organization. So, uh, once I, once I'm taking the action to remediate something, I need to know, first of all, do I need to remediate that? Does it, does it hit the threshold that we have to remediate?
And do I have tools in place? So whether that's policies to be able to say, um, we don't, we don't want, uh, any vulnerabilities inside our organization that are, uh, you know, higher than a high, we don't want any criticals or highs inside. But then do you have the ability to scale that across all of those upstream sources, right?
So we start to think about having a curated immutable catalog where instead of drawing from all of these various, you know, unsecured, unmonitored, uh, you know, public sources, that we can have our own curated catalog where we have control over what's in there, and we also have the ability to, you know, enforce that across our organization. And then finally, okay, great, I'm gonna download, I need a new version of my package and I need to go from version one to version two, but does it build, does it work with all of the other, uh, dependencies inside my, uh, inside my project or, uh, you know, in my deployment? And so what we've done is we've had, you know, two decades of experience building open source, and we have, you know, a very powerful, uh, build cluster where we can build things in hermetically sealed containers with guaranteed provenance.
Everything is built from source, and we can integrate with your systems to be able to, uh, deploy, um, in whatever scenario you have, uh, whether it's a container or whether it's just a, a simple application and getting that into your organization. And so then we get back to the beginning, and now, instead of discovery, we're talking about monitoring on an ongoing basis, knowing what's running inside your organization and being able to keep up up with that, whether there are changes, whether you need to, you know, emerging vulnerabilities, I need to remediate that, get it redeployed, rinse, and repeat across the cycle. And so this sort of holistic end to end where right from the discovery, right from the source code all the way through the intermediate artifacts in the building, that kind of holistic end to end is really, uh, key to, uh, sort of taming that complexity and to having something that is a reproducible, uh, simple, understandable collaborative system, uh, across your organization.
And so, when really what we're talking about is various set of different use cases where we're talking about, you know, the idea of continuous open source integration. How, how quickly can I get new versions deployed within my, uh, organization? How quickly can I get new versions ingested into my pipeline?
How can I ensure that my different environments are consistent and reproducible across my entire organization? Do I have the tools in place for effective governance so that everybody's pulling from the same catalog, everybody's pulling from the same set of trusted artifacts? Do I have insights into all of the usage across my organization?
Do I have insight into all of the places where things are deployed? Do I have the tools to meet, meet regulatory compliance, right? Do I have those, you know, the, those SBOs, those attestations, those type of things?
And do I have, uh, support for things that are going beyond the community supported end of life? So if I need something, uh, supported beyond that, do I have a a catalog that supports that kind of thing? And then we're gonna kind of jump into that, uh, today and sort of show you what that might look like actually in practice.
You know, I showed you the little diagram here. I talked a little bit about the process, but let's talk about what that actually seems like in practice. And so I'm gonna jump over here.
Let's say that we have a, a little environment where, uh, we wanna discover everything that's running inside our organization. We, it's gonna live in a lot of different places, right? It might be in a Kubernetes cluster, right?
It might might be just in GitHub, basically, oh, we've got all of our, our requirements files and, and, uh, dependency manifest files across various projects. In GitHub, it might be, we might already have a bunch of SBOs and we don't know really what to do with them, but they can be a very valuable, uh, tool for understanding what's running inside your organization. So we can get directly from our requirements file or an s om from GitHub from, you know, helm or Kubernetes.
And so let's say, we're just gonna say Kubernetes here today. So we're gonna scan our Kubernetes cluster, and here we discovered that we've got a number of sort of community images that are running here. We've got Postgres and Nginx and Spark and Elasticsearch, and, but what's inside of those things, right?
It's one thing to know, okay, yeah, I'm running Postgres, but what, you know, what's actually inside that? And so our tool can analyze these dependencies and vulnerabilities and give us information and intelligence right down to the system level. Like, you really need to understand, it's one thing to know that, uh, you know, I'm running TensorFlow, but there's a whole bunch of C libraries that underpin that, and that's where you sort of, that's where a lot of the vulnerabilities that tend to be is in languages like c in those type of, uh, libraries.
And so what we've got here is we've got an immediate analysis where we can get that information at a glance. So, you know, across my little, uh, pretend organization here, uh, I've got six docker images running, and 47% of that is C code. There's 1,099 CC dependencies running there.
I've got a bunch of Java, some go, some Python in there. It's given me a vulnerability profile that's showing me, uh, here's, I've got 14 criticals 136 highs. I've got a profile of the different licenses.
So at a glance for my organization, I can see what my risk profile looks like, and I can do things like download a CBE report or download an SBO m But the key thing here is that I've discovered at an early stage what open source is running and what its composition is, and, uh, you know, sort of what my risk profile is here. And I can see some more details on those things, but we sort of covered those first two boxes. We've got a thing where we've discovered, so now we have that, and we've also, you know, pre presumably got something in place now where we can monitor this on an ongoing basis.
But then we've also got some analysis here where initially we can see what our composition is. Okay, well, we've got a lot of vulnerabilities. How do we upgrade that, right?
How do we go from, you know, 1500, um, vulnerabilities to something that's, that's less, right? And so what we can do is generate something, uh, a remediation plan, right? We can get, we have a lot of information in our catalog, right?
We're, we're going out there and we are ingesting a lot of these public ecosystems. We're pulling in all of Pipi, we're pulling in, uh, all of, uh, you know, uh, the pearl ecosystem. We're pulling in all of the Java ecosystem, et cetera, et cetera.
And we have all of this information around versions. And so we can say immediately here, you know what, before you add 150, after you're gonna have 188, here's what you can do we can also give you some additional intelligence, uh, around the risk profile here. But, uh, essentially what what we can do is show you that we can remediate all these things.
They're relatively, uh, low risk right now. And so then what we're going to do is we're gonna take those things and we're gonna import them into our platform and manage them as projects. So each one of those containers that we saw before now becomes a project on our platform where now I have a, a contained unit where what I can do is manage that over time.
I can configure that over time. I can see the auditable history of that. So let's say, let's pop over here and see what that actually looks like.
So this is a little demonstration organization I have here where I've got, uh, five projects, 468 dependencies, mostly go and Java here, and a number of vulnerabilities. But each one of these things represents either a container that's running in my, uh, cluster, my Kubernetes cluster, like we saw, or maybe just a basic, uh, project that I created. So in this case, like, um, my a basic Python project.
And what I can do is I can manage the dependencies individually in those things. I can also browse them at organization level. So, you know what, if I'm sitting there and I'm in my, uh, an organization, I'm like, I hear about some critical vulnerability.
Do you have a index of all the open source that's running inside your organization that you can very quickly, uh, you know, inquire and say, am I exposed to this? So let's say we hear about something Log four J and we type that in here right now across my entire organization, I can type that in and immediately see that well actually I have this thing log four J app pender that's running in one of my containers here. It's running in this Kafka test container.
And so maybe I should go and investigate that, right? And I can drill into that exact project and see the details. Um, and that project will then I'll, I'll be able to configure that.
I can also see the vulnerabilities across my entire organization, and then I can go in here to my project and configure it. So let's go like a really simple example, uh, with the, uh, Python and let's take a look at what that, how that actually manifests. So let me just quickly turn that off.
And um, what you see here is, here's this, the packages that are in my project. So in this case, I've got a very simple web application, say flask and pillow. And this is sort of maybe running out there on my cluster somewhere, but I've seen here that I've got vulnerabilities, I've got a critical vulnerability here.
I've, uh, four highs and I'm getting in. I I, so I'm inspecting what, you know, what the problem is here. I've got a couple highs here in the Python version as well.
I can see my, all of my dependencies all the way down here to the system level. I can see, you know, not just that, you know, flask brings in blinker and click and flick corn, it's dangerous and stuff like that. I can scroll down here and see right down 11 LZMA and the system level C libraries.
So I've got sort of unprecedented visibility right down to the deepest level. But then I can go and I can remediate these things very simply. I can say, here's what one is not vulnerable.
I'm on Python nine, uh, pillow nine 10 while I'm at one critical four highs, I need to pick one that doesn't have a vulnerability. Because we are ingesting all of this open source into our catalog. We're building it all from source.
You've got a trusted upstream for essentially all of the, you know, open internet. So rather than going into a situation where you are, um, managing 50 different upstreams, you can say, well, I'm just gonna point to, uh, active state's trust catalog for everything. And I can choose that version though from our catalog where we know that that doesn't have any vulnerabilities.
So we're gonna say fixing vulnerability here, and then we're gonna save those changes. And now that's been changed to, uh, to the non vulnerable version. It's gonna resolve and re-figure out all of the things that are in there.
But one thing that's interesting that is a critical piece of the puzzle here in terms of taming the complexity of your open source is the idea of that change management auditable history that you saw me do. So I logged the change. So here, rather than me just editing a text file and committing that, or you know, just installing it on my developer laptop or something, what we've done here is kind of merge the concept of source control with dependency management.
Where I've got the, you can see here, here's my base project that I created. 4. And you can see that at any point I can go back in history and revert to this commit, I can generate an X bomb at any point in history.
So I have a fully auditable chain of custody here where I can see that, you know, Pete made this on October 24th at this exact time. Here's the commit id. It's fully reproducible.
And unlike you can see here that we also have this catalog revision id. And unlike the sort of public repositories where if I run, you know, NPM install on a Friday and I run an N-P-M-B-N-P-M install on a Monday, I'm gonna get a different result. But what we are doing is we are revisioning the catalog every point in time.
So it's fully reproducible. So not only, uh, is this saving the state of your dependencies at any point in time and all the open source that you're using, it's also saving the state of the world at that time so that you are fully reproducible, fully auditable from end to end. The other piece that you can see is that what it's doing is it's kicked off a build in our cluster where it will be built this, uh, from source, these individual packages.
4, it'll be building that from source in our cluster here. And so you can see as well our critical went away over here on our total vulnerabilities and it's rebuilding on macros here. Those things get rebuilt completely in, uh, uh, in hermetically sealed containers and completely, um, in a completely reproducible way.
You can get SBOs for all of those things. If I go to my overview here, I can see I can generate things like an SBO for this. I can download a vulnerability report, I can do collaboration.
But the key thing is that what we're doing is we're taking stuff from the beginning where we're discovering all the open source that's running in our organization. We're then doing some basic analysis on it to give you sort of, uh, the breakdown of the inventory, whether it's go or Java or see or Python. We're giving you the high level rollup across your entire organization of all the vulnerabilities.
So you have that initial analysis stage, then we're giving you the tools to be able to curate those things and manage a catalog, have a fully auditable history to give you the sort of, uh, governance tools that you need to be able to curate that. And then the tools to be able to build, deploy, and redeploy that. And so I think that that key cycle there where you have end to end control and visibility on everything that you do, whether it is, um, just discovering what's going on in your organization, all the open source that you're using, cataloging that in an auditable database, then being able to do analysis, collaborate with across your organization, across your, uh, development team, your ops team, your security team, to be able to then curate that, upgrade it seamlessly remediate as we just saw, and then build and deploy that, whether it's integrating with your CICD to get deployed it out, out to your, uh, cluster or whether it's just on your developer laptop, to be able to keep working and streamline that development process.
Having a system that streamlines that entire process holistically end to end is, uh, really important. And that's sort of our vision for how, uh, we should be sort of simplifying and streamlining and tame taming the complexity of managing open source because it's really complicated, it's very complex. There's a lot of moving parts, a lot of information as we saw shifting landscape as well.
And accuracy has been really focused on taming that complexity. So I want to, uh, call it there and say, you know, thanks for coming to check this out and uh, if you have any questions, just let us know. And, uh, thanks very much.