Techstrong TV December 12, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Did you hear about the latest foundation? No, not another sci-fi book You are watching.
Textron Gang. Hi everyone. Happy Friday.
Hey, man, I am, I gotta be honest. Fridays, as we get closer to Christmas and New Year's, they're kind of special 'cause we've got stuff doing all weekend, getting ready for the holidays and enjoying that festive spirit. I hope you're all festive out there.
I hope your plans for the holidays are going well. Um, I, I know mine are, I'm, I'm happy to be home, to tell you the truth. Everything feels like months of traveling.
We've got a great gang, a full house here for us today. Let me introduce you to our amazing gang. We've got my friend Fred Wilmar out in Seattle.
We've got Gina Rosenthal, Wiki Wang, Mitch Ashley, John Swartz, John Schwartz, the Bard, Mike Ard, and yours truly, Alan Shimel. We've got a great gang for us. Mike, I, I said something about a new foundation.
I'm not talking about a new Asimov book or an Apple TV spinoff, but no, a Linux Foundation Foundation. It, it is Yet, yet another foundation from the folks at the Linux Foundation. I've lost track of all the different foundations and I've also lost track of all the different AI projects.
But this one seems to be about, well, the AI Agentic Foundation is gonna be home to the MCP protocol, which is being used widely in servers for different use cases. And also something called GOOSE at Block Built, which is an integration framework for AI agents. md that you can use to provide a standard interface for accessing code repositories.
So, Mitch, what's your take on what's going on here? Because these guys also have the A to A protocol and there's a couple of gateways and it's starting to look a little much like maybe, I don't know, shake and bake. You throw all this stuff in a bag and something good happens.
What's going on? I, I think that's the idea, is not put 'em all into one place and either have them get lost inside the Linux Foundation or get coupled into something else, but give its, its its own space to develop. And does the world need another foundation?
Yeah, I actually think it does another foundation book too, in Siri, but also another tech foundation. So, thi this, what what's impressive about A A IF is that it, one is that MCP was donated to it. That is like the most popular, of course, open Standard, if you've heard of one, you've heard of that.
And, but there are a lot of other really important contributions. Um, you mentioned there's something called Agents md. If you're not a developer, you're probably not that familiar with it.
What Agents MD is, is actually a markdown document that provides a structured way of how agents are built. So it gives the structure of the agent the required components, what the inputs and outputs are, um, interfaces for tooling constraints and guardrails, et cetera. So it's kind of like you heard about structured prompts.
This is like structured how to build your agent. Uh, so it's almost like an instruction manual for it. I think that's super helpful.
OpenAI gave, gave another number of other things to the foundation. So you, it, we are in this age of, okay, if we're gonna start doing more agentic type workflows, agentic work, whatever it is that agents are doing, you know, enterprises, all of us are asking, well, what are these things doing? How do I trust them?
How do I control 'em? You know, anybody creates one. What do these things look like?
They're gonna be well-developed ones, they're gonna be por poorly developed. So there's a lot of really good reasons why I think A A IF has been set up and kudos to the, uh, links foundation. So I I, I have some views on this Need.
Lemme give you Sherry Steak here. I'm, I'm of a mixed, mixed mind on this. Part of me says, look, they were donated this MCP, uh, protocol, right?
And they had to find a home for it. They probably didn't wanna put it in CNCF. It really didn't belong there.
And do we really need more players in CNCF with over 200 projects there. Now, at the same time you, I, I wasn't the a to a, uh, moved over to Linux Foundation too. I thought that this would be in here.
Yeah, I I thought it might be too. Maybe those things will move. I don't know.
I I think it has to be in there. I I felt like, you know, this was the first time where they had a, they had an open source protocol or an open source project, and they, they literally, you know, they created a whole foundation around it and threw everything else in. My, my issue is because autonomous AI is going to be so intrinsic in every single thing that we do, how do you separate out the autonomous AI work being done in CNCF projects, the autonomous AI being done in mainframe projects, the autonomous AI being done on the Linux kernel itself and everything else that the Linux Foundation does to try to say that we're going to keep all of this autonomous AI stuff in this foundation, I think we're kidding ourselves.
It's gonna leak into everything, and then it's gonna get messy. Well, does it belong in in this one? Why is it in that one?
And, you know, and there'll be, there'll be political fights over at Turf Wars. Um, and then if, if the NCP is really the centerpiece of this whole thing, I, I got news here. Look, it went out there.
It's, it's a year old and it became the defacto standard. Doesn't mean it's gonna be the standard next year. We're, we're liable to have something that is replaces it or updates it or what have you.
Or maybe it is a to a or something else. Um, I, you know, I, I do think, look, we are in the foundation era, right? Open source can't be ruled by one big brother per project.
You, it's good to have it in a, a not-for-profit foundation where you can have cooperation among competing companies. But, you know, I I, I think this one's gonna have to be handled delicately. So let me, let me jump in.
'cause I don't want, I don't wanna take the microphone from everybody else, but I will for a little bit. This is like CNCF forming. The CNCF, with the exception of it has the characteristic you're talking about Cloud native isn't go, doesn't go across everything like agentic AI does.
So I think that's inevitable that whatever you do, Alan, is, if you didn't set this up, it's gonna be that way anyway. What are the things that you want to have common and done more consistently across the industry? And given the list of vendors that have signed up for this, it's pretty massive.
Uh, very extensive. You know, it could either be a big political fight or it could be really helpful, um, to the industry. So I think, I think the goal is to make this successful, and if it is, it will deliver about a lot of value.
So I'll be quiet now. I'll let everybody else talk. I think my concern is though, to Alan's point, is that if you look at the CNCF, there's all these projects, right?
And the CNCN landscape is unreadable. No one knows what all these things do. And all these projects have a life of their own, and they never get folded into any other project.
And then the whole thing becomes unwieldy. So, is anybody concerned that this is gonna happen again in the age of ai? I don't know.
Fred, what do you think? Well, I think there's a couple of the, it's a good, you know, how do we manage projects that have been officially open source is definitely one problem. But I think there's a second problem.
There isn't a standard today, and this sort of codifies a place where the Frontier Labs can actually do the work and be accountable for that work in an open source way, right? So you have the ability to understand, Hey, I have an MCP server standard that's required, uh, for protocol behaviors. You, you have some other things that go with that instructions that are required in order for me to build an agent.
And the agent framework, right? So this is, if anyone wants to walk into how do I do this as a business and now have a set of, uh, of, of conscripts in this project that allows 'em to do that. And I think that how that, how that materializes into other parts of the business of that I, that's to be seen.
And I agree, a a two a probably, you know, belongs in here, but I would say it's the first consorted effort to, to get the technology into one place where people can use and operate that, where it's not, you know, at the behest of whatever technology organization is running it. So there some standards are good, and a technical standard with open source projects is a, is a terrific way to allow people to, you know, get their feet into something they can measure between businesses. I think too, like what is the commercial?
Is there a commercial, um, undertaking that is gonna be the counterpart to the open source? And right now, I don't think there's anything, 'cause everybody's trying to learn everything. So I think it's pretty smart to put it all in one place, like Fred was saying, because if you don't, then someone's gonna come along and from a commercial perspective and see how to do it, and that's gonna be the next big thing.
And that becomes the standard, but then it's locked up in private. Yeah. Um, I also agree with, put everything in one place and also get all those supports from the most significant players in this ecosystem, right?
You can see that he historically, the biggest technology revolutions or never, um, about products, right? It's about the shared standard infrastructures. It's kind of like internet has a TCP IP or like smartphones has like OIS or like Android, right?
For, um, agents. Uh, it's, it's, it's about the point. Like no one can avoid and we do need to have like standard way to regulate it.
So, uh, so that in the future, the corporate adoption can make it better. Yeah. I I I'll say this though too, at, at some level, this is yet another milestone in autonomous AI agent AI's, um, you know, move to, to, not relevancy, but to dominance, to, to visibility to the top of the heat.
The mat maturation is part of the, the maturation. But, you know, it's, it's a thing when the Linux Foundation creates a foundation just for you. That said, that's a statement.
It's a big deal. So I am concerned about one thing, and we've seen this in the CNCF, right? I can't help but feel like there's an artificial cap on innovation when these projects go into the foundations because suddenly the vendors are there.
Well, you know, we want this in the project, but not that because we monetize this as part of our quote unquote support service for that thing. And, you know, it winds up ultimately being a force for stagnation. So I'm hoping, you know, it's still early days here, but I'm hoping this doesn't play out with, with MCP, which is kind of critical in my mind.
Well, it's politics, but, and, and that's, you know, you get into these foundations and, and that's part of it is the politics of a, of a multiparty group. They're always ting these, these foundations and projects always seem to be tinged with politics, especially based on the players involved, right? And what they, the standards they set or where we go.
But I, yeah, it's, it's interesting. This is kind of a transitional transformative moment for genic ai, which is not, we're gonna talk about this later, but it hasn't gained traction within companies as quickly as we had thought, or we we're told it was gonna happen by the vendors. Well, I, I think this actually is the, the wind in the sails here, right?
So if you're not sure what to standardize on, right? Having this as a defacto standard, uh, by proxy right, is a terrific way to allow organizations to be able to adopt it. Otherwise, you know, I think on the innovation front, Mike, I love it.
The, the, let's make sure we don't stifle innovation here. I think we're not gonna stifle it yet. I think what we've done is we've said, okay, look, we're putting a stick in the sand.
These are required. There's probably a lot more innovation, and every company has the opportunity in this day and age, right? There's the saying that there's gonna be more millionaires made in the next three years over ai, you know, as opposed to the 20 years of the internet, right?
Is a, is a statement that's been made. So I think innovation's probably still gonna flourish. But the challenge is, is if we look at that rate of adoption, which we're gonna talk about, you know, that's, that's the worry.
If we don't have the standards here, then, then we're at very worst not going to be able to adopt the things we have now. Yeah. I mean, if I took away their phrase open source from this thing, and I said, you know, six vendors are gonna get together and form a governing committee to decide what thing is gonna be the standard.
Everybody would howl. So, Sounds like the Java Foundation, Well, at least they're All invested in each other. That's good.
But like people, I'm sorry, go ahead. Wiki. Yeah.
In reality, right? MCP is one of the most acceptable standard way to do things, right? No matter is like get into the open source or like nonprofit or something.
People support MCP in the best way. So I think it's easier to use MCP to standard to make it standard. And what will happen is the same is is the politics, right?
So you'll have all these vendors in there, and they'll start arguing that they need this and that, and when they're told no, they'll go and build a version of it of their own and they'll come up with something new and other people will come. So that, that's kind of where traditionally this has happened and what ends up being the standard is often the result of politics. Yeah.
And to your point about that, you know, Alan said mc P'S a year old. Well, from what I can see, MCP doesn't look anything like it did a year ago. Today it's very different and it seems to be updated every quarter.
So a year from now, I'm not sure what we're calling MCP will be the same MCP that we have today. And I'm not even sure then we backwards compatible. But who knows, If you wanna see politics go to a standard body that's real politics.
These open source projects are babies compared to that. All right. Hey, we're about outta time for this segment.
We've got a lot more to talk about and, and, uh, you know, do you trust your agent secret agents? Maybe not Textron Gang will be right back. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life in included that work, your protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back and we're talking about AI agents some more. There was an AI conference this week in New York that I was at, and everybody was talking about, well, AI agents, including a fellow from N two, got up and told everybody that, uh, from what they've seen so far, that maybe you should not give any data that you care about to an AI agent because, well, a hundred percent of the models and agents that they tested were all hacked. So it's still early days.
And John has a couple stories talking about the fact that, well, AI agent is a lot of enthusiasm for it, but adoption remains relatively low. That may not come as a surprise, but Wiki I'm starting to feel like maybe people are cutting onto this whole AI thing and that they're, you know, going slow because they're not wholly confident in what's gonna happen. Yeah.
Uh, actually recently, we just had some discussion in our Yeah. Infrastructure, uh, gathering, right? Uh, we talk about this AI agent, why the adoption is, is so low at this moment, right?
Um, there are three things currently happening. Um, number one is people are not very sure, like, uh, if, if they adopt AI agent, right? Is does the AI agent can keep consistently perform what they try to do.
And then second one is, uh, there, uh, is related to identity and, uh, um, um, authorization concern, uh, 'cause currently majority of the, uh, AI agent, if you try to create one, uh, it will be based on the person's identity who created it. So, but, um, after a while, you see the, when AI agents start to work with each other, it's a little bit hard to identify, oh, if, if this is a personal, uh, behavior or like, uh, it's a AI agent behavior. So there are a lot of, uh, new startups try to address this issue.
You can see also, uh, ServiceNow also acquired a, a cybersecurity company to address identity issues so they can adopt the AI Yeah. Agent more easily. Right?
Um, and then also there's some like observability, observability issues, uh, like lot of, lot of work Yeah. Agent do still in the black box, even though people keep the logs, but it's still hard to predict where's the fault, where something wrong. So that, I guess that's the three main reason it's a little bit hard to adopt AI agent in the co corporation environment.
Plus, related to our, uh, first topic currently, we don't have a good standard and the regulation is on the way. So everybody's trying to figure out, oh, if I do this, is it my responsibility? If if something happening and what's the consequence?
No one know exactly. Alan, this reminds me of your, the cloud's not secure. We can't use it.
And analogy kind of, we're at that phase, right? Yeah. So I'm glad to see all those, uh, new things happening, like the, uh, US National Institute of Standard and Technology that try to build up the, uh, uh, securing, uh, artificial intelligence agent dis discussion, right?
And also for, uh, the, also in the, like hat Europe 2025, uh, O-W-A-S-P, they also published the guidance, which gave people a little bit light, but this is still long way to go. Yeah. Hey, friend.
Um, one of the things that struck me about the Oasp Blist is that a lot of these hacks for AI agents are pretty trivial stuff. I mean, it doesn't look like it's very hard. And, you know, it seems to me that bad guys can just kind of create a prompt injection and take over an AI agent, and they're off to the races in split seconds.
Uh, there's a lot of it just the same as you would think about, uh, imagine That we didn't have any, uh, armor for our identities as humans, and now you have non-human identities that don't understand the context of why armor would matter, right? Not, not relevant. I just now have a notion of agents md and the way that my, the way that my agent should operate, let alone what other influences can change that.
So CEEs are on the table, uh, you know, the, the human boundary trust exploitation on the table, uh, supply chain. There's, you know, there's more than 20,000 MCP servers out there. So, you know, direct compromise, indirect compromise adjacency, supply chains, like memory and context poisoning.
Uh, there's tons of things available. And part of what wiki's referencing is really where we think about, you know, today we have this notion, uh, we talk about this thing called zero trust. And, you know, we talk about this other thing called identity and access management, where we have authorization and authentication that is in the just infant stages here with this.
So even with those things, when we've delegated our credentials to an agent, that is also non-deterministic outcomes, right? It's an absolute recipe for that. So there's a lot of people talking about it, for sure, and it is a widely, uh, utilized vehicle.
If you'll look at, uh, you know, like N-C-P-S-O has, you know, probably around 20,000 servers on it, and, uh, your guess is as good as mine, Mike, how many of those are real valid, uh, servers that are available for you that have been trusted, let alone what they do? So, uh, completely valid concerns on that. And I think that's part of why some of the relation on ways to do some of the CTF work around this becomes very important.
Mm-hmm. You know, Alan, I would love to get your thoughts on one of the things that the fellow from NIST said was that in effect, there's no perimeter anymore to defend then. So, Oh, there hasn't been a perimeter since the Jericho Foundation went back in the box.
But let, let me give you Shimmy's take on this. Just, just as I, Mitch mentioned in the last segment, this is a sign of maturity. It's a sign of maturity.
When you got all of this news about securing AI agents, this is like no one, no one, no one ever wrote about max security when it only had 3% of the laptop market, right? Max was in vulnerable because no one gave a crap. And it was only, they weren't a target.
They weren't a target like Windows. Yeah. Right?
Now, Mac gots 20% of the, of the laptop of the PC market. Well, all of a sudden, there's some bugs in that Mac os. The fact that this many people are, are writing about it is a sign of the success of Agen ai, right?
Secondly, a lifetime of learning in the security company, these guys could stamp their feet, hold their breath, and turn blue in the face. No one's stopping trains left the station, either get on the moving train or get left behind. So these are, these are, as we say in Vegas, a fine beginning, but you know, it's not gonna stop the, the forward progress of agentic ai.
And the problem is it's moving so fast that many of these things are kind of obsolete by the time we, we, you know, they decide on them and we report on them. Mitch, to your comment about the cloud, right? We shouldn't use the cloud because of security.
So, Although I, I wanna ask, but still, there might be some folks at ServiceNow in Salesforce and Adobe and whoever else is carting out these genic ai, uh, projects with a little bit of concern. When I look at the 6% figure, the 6% figure that Harvard Business Review came to the conclusion that they found that only 6% of companies fully trust the agents to autonomously ha autonomously handle their core business function. So there is widespread enthusiasm, Absolutely, but Judge, here's, here's the, But the confidence is scarce for now.
It's the hippo. So that, that's one of the underlying hypocrisies in the whole AI thing. 90% of developers use AI to develop code.
40% of them don't trust it. 65% of them think it introduces instability, but still 90% of them use it. 6% of the people using ag agentic AI don't trust it.
Think it might be not so good. Does it stop them from using it? That that's the, at the, at the nitty gritty core of the equation?
Yeah, that's what we're dealing with, doesn't stop. But I think it slows, I think it slows the adoption. That's, I guess that's was my, is my point, is that we anointed 2025 as a year of genic ai, yet there are a lot of concerns that are cropping up.
And you see them from studies, you see them from real life examples. So I'm just saying it, maybe we're, we're just maybe being more cautious, But you also see studies how many, how many enterprises have, whether they trust them or not, are using agen ai. How many agents are out there?
That would be the question, right? Because I think number one studies are, are they're just numbers. And anybody can make a number say anything they wanted to do by, by how they represent the data.
Number one, I think what's happened, yeah, maybe 90% of developers use AI for whatever, but when it got back to operations, and we're the ones that are responsible for that data, and to make sure that things didn't get stunk, it stolen, that we can recover it, that it, we don't break any regulatory rules, all the rest of it, that's where it's slowing down. Yeah, it's cool. Yeah, you can make it do really cool stuff, but we wanna do it within a box that is protecting the organization and not just saying, we're doing ai.
It's amazing. So I don't believe the numbers for one thing. Uh, it, if you dive into the surveys, some of these surveys are kind of questionable.
Yeah. So I mean, yeah, there are, there are some infamously Lies, damn lies and metrics I know Was the, the, that was the worst. The worst.
But I mean, I, I, I also wonder though, like when you press companies to try to get examples of like significant use, it's usually at the very, very low level for now. But again, maybe that's just the process and they will accelerate and they will graduate. The type of uses, Uh, I completely Go ahead, go please.
Just really quick, I just wrote a blog post about this. People are starting now to lay off and let go some of their low level, you know, like, like L one support, these kind of things, and what do we get? We get these stupid agent box that can't tell us a answer, a question, and can't do anything.
Even an L one could do mad. So that's mad maddening. I hate it.
Sorry. No, that's okay. I think in addition to that, and I, I agree, I think we've all had some occurrences where that, that that will naturally snap back.
I think that, uh, the customer interaction with, with AI is a very defined thing that open AI thinks they're gonna own. But anyway, the, the, the behavior of utilizing, implementing and then fully adopting, I think is an enterprise. I mean, it's a very long curve as it is.
And if we see right now that, you know, 86% of those organizations pulled know that they're gonna make future investments and so on. I mean, they can't do that without standards. That's now something they have.
And now we can start going through an adoption process. But, you know, whether or not it's the core functionality of the business, I mean, I think we treat everything with the same cake gloves of the core function of the business to hand over in any way, shape, or form. But I, I, I see rapid adoption in a lot of the areas that are, you know, the workflows and the behaviors, writing code, testing, validating code, validating vulnerabilities, uh, you know, there's a, a massive amount of multiplicative, uh, benefit from being able to do that with agents.
Uh, there's a, a guy that, uh, used to, used to work for me that operates like 10 engineers now, and I mean 10, right? With the number of agents and tasks that he is able to perform at the same time by coordination. And when we think about the effect of what it means to be able to do massively more work for folks that are capable of doing it, it only can have that type of effect down the road.
So it's exciting and it's early days. You guys are all, I think, a hundred percent on point. We should question all of the process to get there, but next year is going to be that year, next year.
Yeah. I, I guess that's why they Start the foundation now, In part, you know, at every one of these tech vendor conferences, whether it's Reinvent or Google's or who you, you name it, they spend an inordinate amount of time with two, three customers essentially doing a use case of what they're doing with agents. And of course, you know, they, they're positive stories.
I'm not gonna put the bad ones up there, but the vendors know the industry needs some examples, successes to build on, and what we will see more and more of that. Yeah, I think, you know, to Fred's point, there's a lot of people who have awesome skills that to do that, but I think that they're a small percentage of the overall population, and it's gonna take a while for the mere mortals of the world to get the cognitive capabilities to manage 20 agents to run a process. So that's just gonna take time.
Yeah. I I also feel like there's a huge market about this agent, right? Even though the adoption is low, you can say there are a lot of companies, they have huge needs, but they don't have enough budget.
That's where the agent will play the role. What's a block here? Currently, the regulation compliance and standards are not clear, right?
So I'm not sure, I'm not so sure how cheap the agent is either if I can have to keep paying for all the tokens to use it. But we'll see. But I think also, Mike, to your, your statement, I think there's a lot of people that are stuck in jobs where they could do a lot more, but they're, what they are actually able to do is just burying what they're cognitively capable of.
So if it's, if it's this very low level stuff, if, if people can wrap their heads around that and, and elevate people to the point of, okay, this boring bit we've automated, now you use that to do the things you've always wanted to do, then that could be pretty amazing. Fair enough. I just want an agent that says, I know you do this a lot, a lot of this is action.
Here you go. I've, I've automated it for you. Thank God, thank you very much.
That's behavior number one. And, and I would love that. But if I ask you to do the same thing and then tomorrow it will do it differently.
So Yeah, it is a little bit of a memory problem, doesn't it? Persistent agents. All right, let, let's take a break here.
We'll come back. We've got our C blocks still to go a little bit off of the ai. Well, it's still ai.
What can I tell you? It's Techron gang. We'll be right back.
Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, everybody, we're back and, and write this date down because I'm about to say something that I rarely say, but it looks like Alan was right. And we are seeing this innovation in the AI space with data centers and energy and consumption, and we've seen some stuff from an outfit called Palantir that's pretty famous in Washington circles, at least for building out AI applications.
And they have a chain os that's gonna help us maybe consume power more efficiently in our new modern AI data centers. Gina, what do you think? Well, let me tell you what it is first.
So volunteer is partnering with Nvidia and CenterPoint Energy, which is really as a Texas resident kind of gives me a pause for concern. But, um, they're to build the, to, to use something called chain reaction, which is, uh, I guess a service forum, um, from Palantir to, I'm just gonna read what it does. It will accelerate Nvidia AI infrastructure in installations across the US by streamlining the complexity of managing the complex supply chains, supporting what power is needed for the gigawatt ai, um, data centers.
Um, and the, the thing it will do, hopefully is look at where the, the blocks are in power distribution, construction, all the, all the, uh, the, the, the legal things that, that the municipalities have and data center operations. So this reminds me of a, and I couldn't find it. Um, of course I wrote a whole bunch about it, and it was probably in a chat about something.
The US government just had an, uh, uh, the president signed an, uh, executive order to get this done, to get the data centers built to, to do better with data center. And it's all resting within the Department of Energy. And of course, the Department of Energy is all run by people who are oil and gas.
So my, I'm really concerned, like as, as just a Texas resident, um, who their, uh, center point is in the Houston Cold Coast area, and they have been horrendous, just like the entire Texas grid is at keeping power on during, um, emergencies. I'm in Austin and I lived through the ice storm ice apocalypse a few years ago, and it's crazy. So the last hurricane, big hurricane, um, they had in Houston, they lost power for weeks, some places, um, they just weren't able to get it back up.
So this all is not, does not seem to be about that, though. It doesn't seem to be about keeping the local, um, grids, firming them up, modernizing them, all. The rest of it, it seems to be about having a separate, um, roadmap to building the AI data centers.
And so I a little concerned about that because it doesn't mention anything about heating, it doesn't mention anything about cooling, the amount of things that'll be pulled away from the resources that'll be pulled away from local, um, in local areas. It's just about building AI data centers, which are important and we all want our agents to happen. We want to move forward into the next century.
I'm not sure this is the same as, uh, building the atom bomb, which is what it's been compared to at Palantir levels and government levels. Um, and I'm not sure if you look at all of the information, which is very kind of scarce actually about what they're planning to do. Um, it's, it, it's not very, and it's not about anything but building out for AI data centers.
So I was probably the wrong one to throw this to because I have a totally, I do not have a, I do not have a, um, I don't have really a technical response for this. I know we need the power. I know we need everything we talk about, but it's being put, all of these data centers are being put in areas that are either very, very poor or very, very remote that in Texas do not have the infrastructure for this, that it will have to be, will have there a second.
Infrastructure will have to be built. But all of the towns and cities that these are affecting are being promised the moon with jobs. I hear one more meta commercial about how many jobs these data centers are going to bring.
I might shoot my radio, so it's not going to do it. It's, it's dangerous to our water. It's not supporting anything local as far as power grid, which in Texas is a really, really big problem.
And I don't like it. So I think we should bring out into the open, like, what is this doing? How is this, you know, how we know there's all sorts of things that AI is impacting, but, and we want to, we don't want to stop ai.
We want to build the data centers. We want to have the things work, but are we doing this in a way that is going to disenfranchise the people that are most disenfranchised now because they're not being on the level and the marketing is so slick to make it seem like this is a wonderful thing. Tina, you're in good company.
I don't understand it either. I, I read it over. I'm like, what exactly is This?
Well, let, let me see if I could, let me see if I could illuminate it for you, Mitch Gino. Please do, please do. This is Peter Theo who owns Palantir preaching the gospel of whatever freaking gospel he's been preaching lately to ride the, the teat of the government's dollars as we bite around the edges trying to squeeze out one or 2% more efficiency by burning our fossil fuels to, to power these AI factories because they don't wanna acknowledge that solar and wind and renewable energy is the way to go and that these age and that these data centers are gonna be manned by robots and they're not really gonna have a lot of jobs.
So if you want the truth, that's the truth. Gina, you weren't strong enough in saying what it is, Huh? Thank you.
You know, I'm glad you, I'm glad you pointed out your, your your I'll leave it right there. Yeah, because This is like, this is something that's happening in community after community across the country is Ohio, Pennsylvania, Texas, what, what have you. I mean, it's the same old story and I think Al nailed it.
This is just a very cynical approach. Of course, it is. It seems, Seems to me we need another foundation here to solve this one Need a revolution.
Foundation will take care of Everything. Well, but from like a in investment perspective, right? Currently we do need some sort of new infrastructure to solve the problem, which, um, plan plant, uh, planter solving, right?
We need the full, uh, whole set, um, on the, to, to make things quicker, to solve the bottom neck problem. It's no longer the algorithm, it's power land, the transfers, chips, construction materials or like great inter in interconnections. I think they're doing, uh, the right product for the, for the market.
But you can see like different companies, they react differently to try to address this needs, right? One is like this way they build up the OS to get a, like a new different, um, physical backbone on the ai, uh, AI stage. And you can also see company like x they try to go to space, make a new different market to address this problem.
Everything, uh, every, everybody react differently, which is very interesting to see. Yeah. So, so lemme throw, lemme throw a couple things on here 'cause uh, it's a contrarian perspective from both what, what both you and Alan shared.
So, uh, the first thing is, is, uh, I, I want to make sure everybody's super clear that we did not build the power infrastructure for today's usage alone today, right now, right? As a person that has spent a lot of time on operational technology and security of such things in planes, trains, automobiles, cars, ships, all the things, uh, it is currently not built for what we do. The second part of that is we talk about the resiliency requirements of what power is now, let alone what power needs to be in the future.
It's not optimized at all. If you look at the amount of electricity and power loss in major cities, 40 to 60% of that, if you look at fifth wall statistics is caused by old buildings, old lighting, old electronic infrastructure that is not managed and is just electronic loss. So when we think about resiliency of the future and the optimization efficiency requirements, it only makes sense to do that.
And does a, a rising tide raise all boats? Uh, we would like to think it would, right? And, and part of that is a requirement to do such a thing.
The US Navy signed a thing with Palantir in the same way to have react to some of the, the reacts to some of the ship Os for them to build the supply chain parts of that. 5 trillion. So doing that effectively, efficiently with operational, uh, crispness is what builds the resiliency we need for the future.
I don't know whether or not Palantir's gonna solve all those problems, but I guarantee you it's a problem that needs to be solved. I agree with that. I don't disagree with that at all.
But what I disagree with is, number one, the marketing for this solution. 'cause the places that I found the most information, um, were on the finance pages. So you're absolutely right.
There's obviously a huge, um, a huge, um, market for the transfer of energy, which of course, Texas is not part of that market, which is interesting why they put CenterPoint as their main partners is what I'm trying to say, right? So, um, but yeah, I mean the en the energy problem, uh, all of us know that. All of us know that, especially if you live in a place where we're not on that grid.
Everybody I know has a generator. Everybody I know has portable backups. Everybody I know.
I mean, like when you go for a week in Texas dealing with an ice and snowstorm with no electricity, it gets pretty hairy. Like really, really quick. It was deadly.
So, absolutely. And that's just, that's just like one place. This is happening all over.
So I agree with you, and that's kind of my point, our entire grid is it needs to be updated, things need to be up updated. You need, um, all of the municipalities needs something. I don't know if, and Palantir os is like, there's, there's no competition to it.
That's the other thing. And that's the only thing that's being bought. Hang on.
So, so, so why aren't we fixing the entire grid to also provide, to make sure as we fix the entire grid to provide that, make sure that it can provide the excess for what we can see, plus what we will see 20 years, 30 years, 40 years down the road. That's not what's happening. They're concentrating on building AI data centers out.
That's what they're working on. That's what this is for. And that's not okay.
It needs To be, but if that's the engine that pulls the train, that does improve the whole thing, that's not a bad thing. My my point though is, Gina, what you're describing, Fred, what you're describing is not gonna be solved by a smarter os helping us try to manage what is an inadequate system, right? That was the whole point I thought under the last administration, this whole infrastructure package, where we're actually going to address the fundamental issue, which is we don't have the right infrastructure, right?
You could, you could marginally improve, you know what, what, what we is a generation or two old right now, or you could, you know, it reminds me when, when, when cell service first came out, right? And internet access here in the us we had pot slides, right? And once a matter with a plain old telephone service, right?
Where like places like, you know, the tigers in, uh, in Asia and Korea and Singapore and some of these places, they didn't have that existing infrastructure that they tried to e every last dime out of. They went and built fresh and new. So broadband was much easier to deliver there.
Meaningful broadband, not, not DSL and stuff like that. And we, we almost need that kind of effort, I think on our energy grid where we, it it's not just incrementally squeezing another percent or three outta what we have. We, we need a fundamental infrastructure built here for a gener for the next generation, not last generation, not this generation for the next generation of power consumption.
I Agree with that. A stupid question, Fred. Why don't we just build a grid for the AI data centers and let them have their own grid?
That's What they're doing. Uh, well, that it's starting this way, but I mean, I I would also caution there too, right? So when the internet was invented, right, it started off in very isolated points, the way that organizations like IBM and, uh, and, and some of the other bigger companies that drove both adoption of servers and infrastructure and connections.
When I ran a data center at IBM, right? I would be out at every Sears store in Washington, New Jersey, New York, all of the things ran through those transits. And those transits were not owned by the federal government, right?
They were owned by an organization that invested in the outcome. And Palantir is no different whether or not they support the infrastructure for building these data centers, right? The same thing.
A rising tide, uh, raises all boats. What happens is democratization of what happens to, you know, the access to those things. And I fully agree with you that that's exactly what should happen.
And super sensitive to the fact that you also went through something very specific in a place that is the origin of energy, right? Uh, especially if you watch Landman. Uh, so I love Landman.
It's great. Uh, the, the, the biggest challenge I think is, is what is the rate of adoption? Let's, let's let, let's let them get a prototype out, right?
Let's get a prototype out and see what that looks like and see what can be adopted there. But I think the hard part is if, if they're going to build a net new grid, you can't just start off with that intent, right? We would all agree that if you started off to build an entirely new national grid, you'd probably fail in today's what?
That's too much. And it's also too much money. And so the way the grid works today, right?
May not be the way the grid needs to work in the future, right? So today, it's not a mesh, right? It's, it's kind of a mesh, but controls flow down in this particular case, maybe they're all adjacencies in the same way we talk about MCP servers, maybe.
I don't know, Fred, I I think that's a great way to end this. You brought some reason to the chaos here. Thank you for that.
But guys, we're outta time. I know we can talk about this stuff for days, but we, we can't, um, we all got work to do, including you. But hey, what a great way to end the week here on this Friday.
As usual, we have Techstrong TV immediately following this. You could check it out. Or if you're watching this on demand, maybe on the OTT app on a big TV or wherever you're watching it.
Thank you very much. Stay tuned for Textron TV gang. Thank you.
It's, you've been great today. We'll be back Monday with Fresh Textron Gang. In the meantime though, have a great weekend.
Get your shopping done, and enjoy this Alan Shemel. We're out. Hey everyone, welcome back here to another Text Drunk TV interview.
My guest for this segment is Dean Hickman Smith. Dean is the CRO Chief Revenue Officer over at Telio. And let's welcome him.
Hey, Dean, welcome to Text Drug tv. It's great to have you on here, Alan, it's a pleasure. Thanks for having me, and, uh, looking forward to the conversation.
Absolutely. So Dean, you know, we were talking off camera, people wanna know who they're talking to and you know, what cred they have and so forth. Give, you know, this isn't your first stop on the, on the railroad.
Give people a sense of, you know, what your, what your trip has been like. Yeah, my trip has been very interesting, Alan. Thank you.
Um, I guess I've had many stops on the, on the railroad, as you say. Mm-hmm. Uh, I came from the uk from the old country, from the old south, from London, Uhhuh landed, uh, landed on these Fair Shores about 20 years ago.
And, uh, that's when my journey in the, in the tech world, you know, really started, started off life in the military, um, got into tech and I've loved the journey ever since. It's been a fascinating one. I came to America with a company called Net Screen back in around 2000.
Sure. I Remember well. And, uh, yeah, we were Juniper.
Yeah. You know, it's good to be lucky sometimes. And you, you, you arrive with an amazing team of people doing something incredible and, um, that went really, really well.
And, uh, then we were acquired by, you know, Juniper Networks, and I was the VP of Emerging Technology at Juniper Networks for a while, which, uh, was a much more technical role introducing new products to the world. And it gave me my first real insight into, you know, the wave that it was back then, which was, um, uh, essentially the emerging cloud, um mm-hmm. Service providers that were coming.
So we were providing, uh, deep inspection, security technology, very, very deep in the weed stuff. But, uh, that went really well. And then I was at Proofpoint for a good while, and we took that one from, uh, you know, small to familiar to an IPO.
So Proofpoint, we did a lot of messaging security, so I've seen yes, network security, I've seen messaging, security. And then, um, I got into identity, did a couple of identity companies, got into the biometric space and, uh, and that, that actually then introduced me to a kind of called Hacker One. So we did, uh, sure.
Crowd crowdsourced ethical hacking, uh, that was at big scale million, million plus people in the community. And I learned all about this kind of crowdsourcing space. So I guess what I'm saying, Alan, is that my journey has actually ultimately prepared me for life at testlio because each of those different things that I've learned, you know, new emerging technology, different types of security technology, different types of experiences, and also that combination with the crowd has equipped me well to, uh, to feel very comfortable in my, in my slippers here at, uh, Telio and at Telio.
I am, I'm leading our global expansion. It's an exciting time to be here. So we're in growth mode, scale up, and, uh, there's a big boost from this whole AI thing that's happening right now.
Gonna want to hear about that. You know, Dean, I, I, look I remember net screen. I, I, I've done four or five venture startups myself over the years, and I'm in security a lot for about 25 years plus.
Um, I do remember net screen, wasn't it the We Brothers, right? Were the founders? Ken, Ken, and Yes, exactly.
Um, the, uh, they went off, uh, ultimately now they're at, uh, Fortinet. Kenzie, yes. They started Fortinet after NetScreen.
They did pretty well for themselves. I got to work with, but Net I got to work with not, not only them, but also the, you know, the near Z who went off and Lee CLA went off to go and, uh, to Pa Palo Alto Networks and Yep. It was a cast of characters doing amazing things at that time.
And I, I Worked, it was, it was, it was a good time to be. And you know, I was, so, I had founded a company outta Boulder called Still Secure, and we were, we were intrusion prevention, vulnerability management, network access Control, Mac. Yeah.
And, um, and it was in, those are interesting times in security. Um, but as you say, you know, we are, um, AI's changing everything and these are very interesting times to be doing anything in tech that, that AI is touching on like this. So, but I'm, I'm, I'm, I'm just worried a lot of folks out here may not be familiar with Telio.
So before we jump into some of the higher level things I want to discuss with you, give me a, give our audience a sense of who telio is and what you guys do. Uh, I love to, yeah. Telio spent the, over the last decade testing customers digital product offerings.
Uh, it's a crowdsourced, um, A Global crowdsourced offering. We have about 60,000 crowdsourced testers on the platform. And basically we provide access to projects.
And projects really are customers expose their digital assets to us and we test them, uh, and we test them deeply. We've tested over two and a half million, uh, test runs over, over the period of the company in 150 different countries on about 600,000 different appliances. Wow.
So we give as close to a real world non-biased test experience as a customer can get. So we have an amazing diversity of customers that are in tech, they're in finance, they're in the sporting world, and they test their apps on our footprint of, of testers, and we give them direct feedback. So it's kinda like a customer simulator for want of a better word.
Well, we test the real world experience, and what it also gives you is real world experience of things like the demographic, uh, that's testing it, the network, it's being tested on the type of device that's being used so the customer can really get an experience of, okay, what's it gonna be like if I launch my new Premiership football app in Indonesia or in Columbia, what's the customer gonna experience? So we work with global brands that care about their brand identity, care about their digital product, working straight, uh, outta the box, and we give them real word feedback so that they can feed that back into their development loop and make a better product. So essentially we're helping global brands build better products in a very, very efficient way.
Excellent. I love it. Dean, of course, as I, I inferred earlier, AI is having a tremendous impact, especially in tech and, and within tech, certain areas, well, sales and marketing and for one, but testing is one area where, hey, look, AI just makes a lot of sense, right?
If you could train the AI to figure out what tests to run and then run those tests, that's, that's a pretty good thing. But of course, you know, nothing's perfect. The ais have bias built in.
They do hallucinate know they're getting better. I'm not gonna deny that they're getting better. Um, and they're, from a compliance point of view, if you don't have a human in the loop, did it really happen?
These are all kinds of things that we're running into from where you sit, right? Are these issues that, number one, we, we we're dealing with, and number two, what, what's Tely and our QA folks out here to do? Yeah, no, I think it's the tremendous opportunity for Testlio to continue to add massive value to our customers.
And we, you know, we talk, I love getting out and seeing customers, Alan, it's probably the best part of my, uh, of my job is to go and see customers globally and get, get an understanding for what they're doing. And I see, um, I talked about those different evolutions of stuff that I've been involved with, right? I came to America when mobility, when the, when the iPhone kind of went, went wild and everybody started working remote.
So we did a lot of remote access stuff, we did a lot of device security. Then it was all about cloud. Then the next wave after that, I think I can probably say was shadow it.
I dunno if you, do you remember that kind of era where do, do mm-hmm. People were worried about, okay, what apps are we really worrying? Or what are we really using?
We Running well, people were whipping out credit cards and just spinning stuff up. Yeah. And now honestly, I see a similar kind of shadow AI world.
Absolutely. Everybody's using it. If, if you don't think your team's using it, you know, just think again because they are.
So, I think everybody now is, is struggling. They're running hard because they've got board pressure to use AI to increase efficiency, uh, to roll out new services, to roll out software faster than ever. And that's compounding the fact that underneath the ai, it's still learning.
It's, it's, as you said, it's improving. It's much better every time. It comes out, but it's still improving.
So we polled our customers and, you know, we are seeing that like 82% of the bugs there now reporting are coming from AI hallucination, just AI trying to give you an answer when inherently it doesn't have enough data yet. So we are in a way policing AI at Telio. You know, we are helping AI get better.
I think it's exciting for me because of two things. Number one, we are helping, we are very, very involved with AI testing, AI policing a, the AI experience, verification for customers, giving customers an understanding of how confident they can be in with ai. And then secondly, we're creating very meaningful work for our crowd community to be AI testers.
So we've created an AI testing program, a prompt injection program, a whole, um, category, a new category in our, in, in our testing world where people can come and learn how to be testers and be valuable in that kind of AI feedback loop. So I think it's great to always be the helping humans, uh, you know, globally and we're creating meaningful work with this AI testing program that we're, em, em, embroiled with right now. So, a super exciting time, huge opportunity.
But I think what we're trying to do, Alan, is give customers confidence in their commercial adoption of AI and helping them avoid very costly pitfalls if they get it wrong. I agree with you. It interesting, Dean, I was talking recently with a friend of mine who's involved in another company that uses crowdsourcing to help deliver the goods.
Um, and they were saying that to a certain extent they could set up ai, I dunno if you want to use the word simulations or, or what have you. But in essence, they don't need as many people doing the crowdsourcing. 'cause the AI can simulate, you know, thousands of people doing this.
Um, I'm wondering, is that, is that a good thing or a bad thing for us? And, you know, Uh, I think it's an interesting thing for us. Like, yes, AI is good at replacing repetitive work for us, and it's good at doing repeat tasks that it has a good data set from.
I think we're a way off having the reliable data set, but I do think that, and we see it, of course, a lot of the data that we're gathering is coming into our own platform. 5 million plus test runs that we run. Um, and turning that into insights that can be predictive in nature for our customers rather than reactive.
So I agree that you can do more, um, with AI than we, uh, historically could. The question is, can we do the insightful stuff that we need to do to make sure that AI is constantly improving for good? And I think that's where Testlio comes in.
We've always got the human in the loop that's gonna be able to challenge ai, reinforce the learning, uh, of, of the, of the, of the ai, uh, data set, and continually feed that back to our customers in a way so that over time we can give them good predictive. It's a bit, a little bit like, um, I forget the name of the movie now. The, the, you know, the Tom Cruise movie, um, where, where we're giving, uh, proactive advice to customers about going into a market, what they should be worried about before, uh, before they go into a market.
Minority report, minority Report. Thank you very much. Yeah, Exactly.
Yeah. They get arrested for what they're thinking. Yeah.
Um, I don't think I, I, that's not as far out as it used to be. I agree. Uh, I, I get it though.
Uh, look, it's certainly interesting, interesting times to, to be doing all this. And I, I think, you know, if the bar is here today about how much of the AI versus how much of the human in the loop, I, I think over time as we gain more confidence as these models get better, you know, as things happen along those ways, that that bar is gonna move too. Right?
And, um, I don't know if it'll ever go fully automatic or fully automated, whatever you want to call it. I think you're always gonna need some human in the loop kinda stuff. I just, you know, I think it, it, as the AI gets better, like it, and it's not just fessing.
This is everything, right? Yeah. As it, it's better, You know, I speak to a lot of interesting people in, in, actually, I speak to more interesting people here because we work with such a wide set of industries, right?
So we, we work a lot in, in the, in the media. So we do a lot of tv mm-hmm. Streaming media.
So you meet a lot of creative people. Sure. You know, they don't want AI to replace the creativity.
They want AI to replace the mundane so they can focus on the creativity. Uh, I see a lot of people, you know, myself included, I've got more time to think strategically now, um, than I have before because AI is helping me with a lot of the mundane stuff that, that I, you know, I used to need to do. So I'm an optimist, uh, Alan, I, I think that we can use, you know, to lift a lot of the load.
It's kind of, it's like the industrial revolution all over again. You can either sit there and you can destroy the machines because you think it's gonna take your job, or you can get on board with it, embrace it, and then become more efficient and, and embrace AI that way. And I actually, I used that analogy twice already this morning.
I'm getting boring with my industrial revolution. Yeah. But, but you know what it, so they, you know, I think, look, I, the fund's really gonna start when the robots start using the ai.
And then we're truly gonna have, I don't know if it's the fourth or fifth industrial revolution, or it'll be a combination, but you get AI with robots and, and, uh, quantum computing things get real exciting, you know, it gets real interesting. We'll have to see where it goes. But I, I wanna Talk to you about quantum computing sometime.
'cause that's my next big passion project, right? It's, is It, you know what it is. Don't wait too long, Dean.
'cause it's happening. Oh, it's quantum. There's stuff happening every day.
Every day. We're seeing it's building. It's building.
You know, they call this so-called Q day, right. Where we, we, yeah. Yeah, sure.
And, uh, We need to get into, into really interesting encryption when, when quantum hits, right. All sorts of Tic stuff. Well, we gotta get out in front of it.
You can't wait till it to hit. We gotta be in front, you know, like you love your job. This is one of the reasons I love doing what I do, right.
I, I get to talk to people about all of these things all day. And so most people are much smarter than me. So I really, it's fascinating, fascinating stuff.
Um, Well, you actually, you talked about the robot stuff, right? I, I mean, Silicon Valley right now has got so much interesting. Well, we were in, uh, in Amsterdam, we last week, we're seeing a financial services customer that's, that's using a lot of robotics to test payment devices.
It sounds like. It's just incredibly efficient. They've got fabulous robots just sitting there trying to, trying to break payment devices instead of a human having to do it.
Yeah. I've got an old boss now who's running a swarm warfare company, and they're making swarm AI driven drones to accompany humans on missions. It's fascinating.
The, the, the, the breadth and diversity of, it's Crazy. The, the applications. You wanna go check out something, go look up a company figure.
I don't know if you're familiar with these guys. F-I-G-U-R-E? No.
Go on YouTube and look at their, they, their newest model is called Figure three. So this is the company that BM BMW uses to build B BMWs. Okay.
And, uh, they're retiring the robot that VMW was using. That's the figure two. Go look up.
Figure three, figure three washes your clothes, folds, your t-shirts, plays, fetch with your dog. It's, it's, it's both exhilarating and frightening. Right.
Is the best way I could tell you, because I love it. They have them like delivering UPS packages. They have another one at the hotel desk checking you in, giving you your keys and telling you where to go.
The, the hands on it and the movement of it is humanlike. It's, It's crazy. No, it's fascinating.
I, I, um, I wake up every day excited about the potential. Me too. I'm, I'm a pilot.
It's my, my, my other passion is flying. And, um, Look what it's doing there. I was at an air show where they had full ev to, you know, electric personal vehicles.
Um, yeah. And interestingly, it's, they're basically run by iPads. It's, it's Uber.
I know, you know, in the air, you sit in the thing, you press where you want to go, and it delivers you to an alport somewhere, somewhere close. But the interesting thing is the, the micro meshing of these things. So you can have hundreds of them in the same airspace at the same time.
Auto de conflicting Over a, as long as there's not a person there because a person involved in the loop screws the whole thing up. 'cause we don't, we don't always act as logically as the sheets You say there. So at the moment, there is a human in there ready to pull the handle in case it goes wrong.
Oh. In case they've gotta pull the parachute handle. But yeah, like, there's so much innovation happening at a pace that So got time to be alive.
Right? It is. And isn't it exciting to be here right now?
I mean, it, you know, we've, we've both lived a bit and we've seen these things before, but hopefully, But not at this scale, Dean. We, we have lived a bit, we've seen the advent of the internet. You know, we've seen the cell phone.
We, we've seen, you know, landing men on the moon, though we did it once and we haven't done it, you know, a couple times and we haven't done it since. Um, but this, the, the promise of how this affects not just you and I. Right?
You're, you've had a good career. I've had a good career, but I'm, but just like lifting up humanity. Right?
E Elon Musk last week said, you know, with human, with robots andis, you might eliminate poverty. You might eliminate money too. But, you know, the whole human condi, I mean, this is at a scale I don't think we've seen before, is the potential if we don't kill ourselves first.
But that's a whole nother story. I got into a very deep conversation on Friday night about AI ethics with a medical friend. And, uh, Uhhuh, we were talking about healthcare in North America and how AI can assist.
It can prolong life, it can provide medication, but it could also at some point decide that, uh, you know, certain people aren't worth saving, certain demographics aren't worth saving, or certain age groups aren't worth saving. So where does the human well ethics come together with AI at that point? Well, that, and that's the flip side.
What if they decide humanity's not worth saving? Right. At some point in the future.
It's crazy. But hey, right now we're just worried about crowdsourcing some testing and getting that done. Done right.
Did We go? He's a little bit There. Sorry.
Yeah, We, we got a little off there, but it's all right. Hey, Dean, the pleasure having you on. We didn't mention Tess Leo's website though.
Can you give us the website? Yeah. com.
Um, love to, you know, we've got a bunch of case studies and stuff, and we're in a period of, I think, excitement at Telio because we've got so much stuff that we want to educate people on. com, and I'll be very happy to connect with the right people in the right countries. We've got people all around the world, uh, customers in 150 different countries.
So it'd be great to connect and, uh, yeah, really enjoyed meeting you, Alan. It was we Nice meeting you as well. All right.
De good luck. com. com.
We're on text on tv. We'll be back with more in a moment, Guys. Thanks for the throw.
We're here with Sandeep Anand, who's vice president of Machine Learning Solutions for Infor. And we're talking about, well, the five things that are keeping IT leaders up at night about ai. Cindy, welcome to share.
Thank you, Mike. Nice. Happy to be here.
Alright, So I imagine there's probably a lot more than five, but at least there's five that comes to mind. But, um, lead us off a little bit. You know, when you think about it, what should it folks be?
Well, maybe actually worried about versus maybe worried about too much. But, you know, start us off. Uh, yes.
And, and, and thank you for the opportunity to talk about, uh, artificial intelligence. Um, so, you know, my role in Infor is about leveraging AI ML for, from a enterprise perspective, right? And so if you think of what that means from an info perspective, we focus on business applications, ERP software, things that help, you know, businesses, help businesses be productive.
Um, the number one thing is, um, you know, driving useful, measurable business gain out of it, right? And so it's, it's from a, from a benefit perspective, the, the number one thing to worry about is how is this helping a business improved productivity, right? So, if you think, what is the value?
This is driving my organization in leveraging this, because we know that technology works. We know that it's used across the board. So the question just becomes, what am I gonna get out of it?
That'll be my number one, that consideration. And how do I evaluate that successfully? 'cause I think a lot of it, people are trying to figure out what's the math here on the ROI that makes sense?
Absolutely. Which is the, which is, you know, in some ways, um, the, the, the secondary point to it, right? It's, you know, always you are going to talk about, uh, productivity measurements.
Um, you know, it's very easy to say, well, this is going to reduce the, the amount of time I need to spend in trying to figure this out, um, manually or in my current business process. The other thing you can look at is, uh, this is going to help me be more, um, accurate. You know, when you talk about inventory optimization or anything to do with, uh, scrap management, right?
So we are looking at, uh, you know, we are looking at challenges in your business that are impacting the revenue side or the cost side, or the quality side, right? So those are good, easy metrics to, uh, anchor against because you are probably tracking those, uh, in some analytics, uh, part of your business. So an improvement of those.
Um, you know, the other metric would, could be considered around timeliness, right? So we talk about productivity, savings, business benefit, um, being able to do it faster, right? Will be another thing to consider.
Uh, and it's not a, uh, or it's an and, right? Is the, is three prisms of it. The fourth thing, uh, is also how is it helping my workforce, uh, be productive?
You know, allowing them to, uh, be more satisfied. Because in some parts of our, our ecosystems and manufacturing distribution, uh, the retention of these workforce, so the ability to leverage, uh, you know, do more with less of sorts, how can you get them, uh, excited to leverage these technologies to drive that better business outcome is also very important. I think part of the issue too these days is that there's no shortage of these projects, but there's only so many resources and so many people with the skills.
So, um, is there's some way to think about prioritizing these things. 'cause I don't think we can do everything we wanna do all at once. Yes.
And, and, um, um, it's a very important question, and I think it talks to the, the company culture. Uh, you know, if you think of, uh, what do you want your business to be in the next quarter, next half a year, next year, where is your business priority, right? So for, for the prism of what are you looking at?
Are you looking at it from a revenue perspective, uh, business transformation to, you know, do more with less? Are you looking at, um, a challenge to the way your business is run because you have supply chain issues because of the current macro conditions, and it's really important for you to stay ahead of your competitors, right? So that's where, from the culture perspective, what is driving your business's push and how are you enabling your, your, your team in driving and pushing that would ultimately be the best way to push this forward?
So it's not a side project, it's critical for your business to be successful. And, and, and if so, how are you then getting your team on, on board, right? And be the, the right prism of how to start, which use case with in doubt, I always say pick something that impacts revenue on cost, you can go wrong, right?
But also from a financial forecasting perspective, it's also good to understand how your business is moving forward. So generally, that'll be another consideration. But, um, I, I'm always partial to anything related to supply chain, uh, when you wanna get started, It also seems like there's more of a separation and concerns these days, and the data science teams are maybe focused a little bit more on training and maybe the creating of the initial AI model, but the IT teams are taking more responsibility for the inference engines and the deployment thereof.
So is that part of it more where the IT leaders are more concerned about things versus, say, the actual training of the model itself? It's, it's, um, it's a very important question, and you talk about the blurring of the lines that have traditionally governed, uh, these types of projects. And, you know, of course when you even talk about generative ai, right?
And agents, and how that is also causing further blurring whether business are now able to do things that the IT or the science team were able to do, right? So your example, you're talking about the science team builds the models IT team manages, maintains, executes on the, the models in the terms of the value. And then with gen ai, you have the business also coming in, Mike, and also coming in and saying, well, I can automate these things, uh, or I can leverage, uh, a gen AI type of assistant to drive better analytic knowledge.
So I don't need as much investment in analytic dashboards, right? And so it's important question of, uh, as your organization, uh, evolves and depending on how they're set up, how those roles can play nice together, right? So everyone is now on everyone's turf, which is good and bad, depending on how you manage it.
Mm-hmm. Also, I think that there's some concern about, well, what should I actually go build myself versus quote unquote buy? Because there are software vendors that I currently rely on who are building AI and ML into their various offerings.
So I'm trying to figure out, like, uh, I don't think I want to be in the position where I've just spent a year building out an AI model to wake up one morning and figure out that my software vendor's given it to me for, you know, a nominal extra cost within the application itself, Right? Um, the age old, uh, challenge with the build versus buy, right? If you think of it, and with, uh, with, uh, if you think of cloud providers, it's no longer, um, uh, just simply build versus buy, but which part of the things are you building versus which parts of the things are you buying, right?
It's a, it's, it's a un enviable position of how to make those choices. Uh, I was recently, um, we were recently talking about, um, you know, how do you from a prism of an end user navigate these challenges that are, uh, or opportunities, depending on how you look at AI and the excitement, uh, and potential of it is, do you look at a vendor as a monolith thing? Give me, give me the outcome and you just take care of everything?
Or are you in, um, in the kind of a maturity phase where you're saying, I, you know, um, if you think of a shirt, right? I I don't want the shirt. I just want you to take care of the sleeve.
I'll take care of the buttons and you help me get the fabric. Right? And so I think that is kind of the, a case by case decision.
I think, uh, if you're starting off, uh, again, if I follow up my, my very simple example, just get the shirt, and then ultimately when you get comfortable wearing your shirt and you want different shirts, you can start trying different things. Uh, but once you, you know, as you get more and more into it, you are going to want to have more control on those decisions yourself, right? We, we haven't talked about IP and data rights, but ultimately over time, uh, there's a gravitation towards I want to do something special for myself, but I do want things that are very easy and common just to be handled by my partner.
Mm-hmm. The other thing, it's still unclear to me, but who's responsible for securing all this stuff? Because to your point, um, not only are bad guys trying to poison models, but in some cases, they're trying to just steal the model entirely because, well, it's valuable ip.
So, um, do we need to rethink security in the age of ai or will we just kind of have the same old it does the deployment and security people secure it? Um, I, I, I definitely think that we have to keep up with the times. Um, right.
If you think of, um, if you think of all the challenges we have, uh, with some of the items, the examples you just gave in the news, where I think the, the agents, the LMS can now catch security intrusions as they're being tried, injected into your organization. So there is a, a newfound respect for the power of, uh, using, um, advanced technologies to protect you beyond just the data and, uh, uh, kind of people protections of, you know, keeping things behind firewalls, right? So those will continue being a necessity looking at, you know, LMS that allow you to be more secure, making sure your partners with the, those models aren't leveraging your data to learn from, right.
And causing your IP being pushed is important. So I think, uh, it's evolving, right? We'll continue adapting with all the, the advancement of technology, but I don't think you can, uh, have a stance that I want to firewall myself.
I think the trade off of protecting overly protective, uh, uh, setups will ultimately limit you from being able to power of all the advancements in technology. Mm-hmm. Is there something that we're overlooking or maybe not paying enough attention to as IT leaders?
Because maybe we're spending too much time obsessing about one thing and not paying enough attention to something else. I think that's why we have such white hair, right? Because I don't think that's ever going to change.
There's always something, Mike, that we will always not be taken care of, right? I think when, when we got the, um, when we got Gen ai, we were like, oh, this is great. And then we were like, oh my God, but this is just taking all this information and pushing it out.
And then we were like, oh my God, this is telling me the wrong information. What we should have some guardrails. And it was like, well, it's just telling me this information I can't do much without.
So I think that's a, I think to you and me, that's a IT problem. We all cherish and love to have, not business, don't you think? Right?
So we always be something One impact will all this have on the role of the senior IT leaders out there, do you think it's gonna elevate their positions a little bit within their organizations? And, um, how should they kind of view themselves within the context of an organization? Because you could argue conversely, that AI is really a line of business issue, because you've got people who are experts in a process and they need to understand how the models work and validate them, but at the same time, you're probably not gonna get very far without it.
So how's the relationship gonna change? Uh, it's always, it's always symbiotic, and I use that word intentionally, right? I think from a, um, investment perspective, there is always a need to continue investing in it.
Uh, not only from a security and governance perspective, but project management of these transformations. You're always going to look at using different tools to drive your business. You're never gonna have a monolithic single, uh, software policy.
And this is where it is especially suited when it comes to technology and technology change. We are also looking at, you know, how do we be, um, how do we get the right evangelist from a business perspective to help drive those productivity benefits, those revenue benefits, and things like that. So I think that, I think there was always a need for it.
I think where with gen AI and agents agentic ai, I think you're starting to blend some of the business and IT responsibilities, especially when it comes to analytics. But now you're also getting a new level of understanding around, to your point, the security, the governance, the concept of how is my data interpreted in my organization or outside as we start looking at, uh, you know, some of the new technologies around the agent to agent, where the hope is two businesses can talk to each other without requiring anyone, right? And so I think, um, older paradigms get replaced by newer paradigms where it has to change and upskill, but also provide more and more help, and even if not oversight, but some way to control the, the, the use of this AI in and outside our organizations.
Mm-hmm. Am I gonna see organizations build these kinda massive AI models that everybody's worried about what the RI is gonna be? Or is it more likely that for the purposes of a business, I'm gonna rely more on smaller models that are distilled, maybe from those bigger models, but ultimately they don't need to be nearly as big and as difficult to manage?
And should I be, you know, focusing my efforts on, uh, uh, set of AI models that are maybe better trained with a particular set of vetted content? I think that, I think that's unlikely, um, that we would have companies invest in their own large language module. To your point, uh, soft, uh, smaller language models or very small language models or domain specific language models will probably be, uh, for certain companies a better preferential treatment.
I mean, if you think of our phone, it's this example of a, a small language model. If you think of the, the fact that when you type a email, you get the autocorrecting the information, right? That is not what a SLM is.
But at a basics level, we are already at some point, uh, uh, able to take advantage of very specific use cases, uh, around large lan around, uh, language modules. But, um, you know, I just don't see that big need for your own LLM. I do think there will be more and more adoption of, uh, help my business make better decisions.
Uh, but it, I don't think it needs to be a small language model. I think you could do something even more pragmatic very quickly, uh, with the technologies in place. And I think that's where a lot of, where from an info perspective, we are also seeing the initial stepping into the, the waters of sort, is that we, he know we want to help us with our procurement process.
We wanna help with our customer service, uh, and being able to look at documents and help with knowledge bases to help kind of troubleshoot information. Those don't require such a large investment. In fact, those things could be almost out of the box in this day and age, the way technology's moving, right?
And we see a lot of that initially. Um, I think some will go into the s SLMs, but, you know, I don't think that's fully needed to get the advantage of, um, the benefits of ai. Mm-hmm.
In my conversations with people, I, it seems like they're starting to realize that there is this need for more context. When you're working around those LLMs and you hear the phrase, context engineering is kind of the next super set of prompt engineering. And that's right.
But then it seems to me, as I look at it more and more, it's as much art and skill as it is science. So how do I make sure I'm putting the right data at the right place at the right time to ensure the, the context that I need to get some sort of output that's more reliable is occurring? It, it, it is a million dollar question.
I think that is, uh, one of the questions that is keeping, uh, uh, organizations up at night, right? They, this is, uh, this is part of the reason it jobs are always going to be, uh, required, right? Because we started off with, you build a software, and then you're, you're, you're good, right?
You just have to worry about this software being used by the business, and then you realize, oh my God, this is just connecting to other software. And then you're like, oh, but this is putting in data that needs analytics dashboards. And you're like, oh, these dashboards are just telling me what's in the backend.
So we need ai. Now we have ai. You're like, oh, I don't know if this AI is the right AI for me, because it's just telling me things that probably not true and need to be curated or need to be better managed.
And then when they are managed, you're gonna say, well, I want to automate this so that I don't actually have to worry about it. I don't need to have analytics. I don't need to have software.
Like you see the thing, right? We build a software and you build analytics, and you build the ai, then you build the, the, the ages that run the AI on the software so you don't have to use the software, and then what's next? What's next?
What's next? Right? And I think, I think that's the, that's why we love this job, right?
We are moving so fast and moving so fast in some places that I didn't think we would be able to do in five years ago, right? And so I'm very happy with that. So in some ways, half glass full, right?
That's the kind of thing, the way I look at this. Yes. So what's your best advice to folks?
Because the opposite of the glass that's half full is the glass is half empty. And a lot of folks are intimidated by all the moving parts here, and almost to the point where they basically freeze and do nothing and are just kind of watching and waiting for things to kind of maybe evolve. But, um, what should folks be doing today?
I I think we'll go back to the, the premise of the conversation. Don't worry about, don't worry about all the hype around the technology and the promise of it. I think distill it to, um, what's important for my business to do now, next, later, uh, how am I able to quickly do the now next, later, uh, with the people, process and technology at my fingertip?
How do I measure? Uh, and, and those are, you know, simple principles not related to ai. That's just anything.
Anytime you're investing in any, um, initiative, you, you look at, you know, what do I want out of it? How am I gonna measure it? How quickly can I get it pragmatically without having a big, large investment?
And is this gonna be a market differentiator? And then you just take that action. And, and the reason that's so important is because it's tried and trusted.
It is not about ai. It's ultimately about how you want to succeed. And therefore, you're less likely to worry too much about, am I doing the wrong thing?
Because it's the thing you every business should always be doing. And if this helps that, then you're easy more likely to do it versus trying something new and unexpected. Because at the end of the day, we're still talking about quick ROI, measurable, RROI, bringing people along, measuring business outcome, and then, you know, rinse, repeat, right?
And so, as long as you keep it in the prism of what everyone does, you're less likely to just, you know, be paralyzed with this indecision, right? And I think that's how I think everyone should think of it. All right, folks.
I heard it here. Despite all the hype and concerns about the fear of missing out, turns out slow and steady still wins the race. Hey, Sandeep, thanks for being on the show.
Thank you so much. All right. And back to you guys in the studio.
Hey, everyone. Welcome back here to Tech Drunk tv. Uh, you know, we're continuing our coverage of in interviewing folks here at, uh, AWS reinvent from our suite up in the wind.
Um, it's been a, an interesting couple days, obviously, a lot, a lot of news, a lot of information, a lot about AI and agent ai. If you haven't had a chance to catch, you know, a lot of our coverage, uh, sponsored by our friends at suse, by the way, we've also had a great, some great conversations with SUSE and a WSI recommend. But let me introduce you to my next guest.
His name is Kim Bohan. Yes. Uh, Kim is the, uh, CEO of a company called Skyhawk Security.
Security. And if I'm not mistaken, it's Skyhawk security. Skyhawk not Security, correct.
Is the website. So Kim, welcome back. We, well, welcome back.
The last time I saw you weren't sitting across from me, you were on Zoom, but now we're here in person in Las Vegas. Um, Very excited to be here, and thank you For Thank you. My pleasure.
But look, not everyone watching this saw you last week. Yeah. So I'm afraid we gotta do a little bit of ground keeping here, give people an idea of kinda your journey and what Skyhawk does.
Yeah. So first of all, IO obviously recommend everyone to see our, uh, previous recording Absolutely. Get more in depth coverage.
Kayak is a, a cloud security company. Uh, our roots are in cloud threat detection and response. In the past years, we added, uh, AI based threat team, uh, and transform the platform into an autonomous purple team platform.
Basically, we have a, a red team in AI that fights the cloud detection engine and creates, uh, uh, basically a purple team automated autonomous purple team on customers environment. And I'm inviting you to talk with us, uh, further to learn more. Absolutely.
And you know, it was interesting. I actually, we, I was mentioning with SUSE earlier, we did a, a panel and we were talking about AI and, and what autonomy it brings in software development. And, and one of the examples came up, sort of like an AI red team, right?
Where, where, look, the code might be generated by one LLM, but we're going to use an AI red team by a different LLM or a different, you know, model to check the code mm-hmm. Before, and I said, at what point does the human go into this loop? Right?
At what point is if, if the code's generated and the testing of that code is generated and the deploying is generated? So, you know, in my case, I see generative AI as a force multiplier, not, it's not eliminating humans. Mm-hmm.
Uh, in our experience, uh, I was able to build, uh, an AI based threat team with extremely efficient, a very small team. We have, uh, companies that were building, uh, you know, breach and attack simulation with tens of people in r and d. And over years, we were able to do with a relatively small team, where would otherwise, before generative AI take probably tens, right?
So it's a force multiplier. Uh, even more importantly, in our case, it was, uh, uh, a design, uh, a fundamental design consideration because we thought that adversaries are gonna change, right? They are going to use generative AI in order to build A test.
They are, And, you know, we started that, uh, claim three years ago, and people were a little bit hesitant. Now it's obvious because we see it in the wild. Uh, OpenAI talks about how, uh, GPT was used, uh, uh, and traffic were, uh, uh, talking about how cloud was, uh, just used by adversary to build attack.
So now it's reality, it's obvious, uh, it's a force multiplier for adversaries, and therefore we as the defenders have to use it in order to help our customers protect mm-hmm. Uh, against what they're going to encounter in real life. Uh, so it's not zero human in the loop.
Uh, there is, you know, still a research team, there's still development team. We, we do have, uh, some human in the loop, but, uh, the pace in which we're able to, uh, build basically attacks their parallel to customers environments just amazing. It's unparalleled.
Uh, No, this is, I mean, look, I had friends who started like, uh, like for instance, cobalt, you, I'm sure you know, cobalt, you know, crowdsourced penetration testing, right? Because before that, the limiting factor was how many pen testers can you have, right? Right.
And now, you know, with crowdsourced, I could have literally hundreds, but even that's not enough in today's world where, where we're talking scale, Right? And that, you know, what I, again, something that I spoke about on a bunch of the talks over the last couple days is the scale and then the scale, the scale that you see at an AWS or, or Google or Microsoft, any of that. They don't call 'em hyperscale.
It's for nothing. Yeah. The scale is phenomenal.
Yeah. And, and it's, it's the scale and it's also the velocity, you know, that we see, yeah. That the time from initial access still impact shortened from months to weeks to now less than an hour, right?
Yeah. It's, it's, it used to be that you would have adversaries in your environment for days or weeks before they would make their lateral movement. And, and the negative impact now from initial access to negative impact less than an hour, it's crazy.
It's industry statistics. Yeah. And It's crazy.
And, and it's going down from there too. I, I imagine, Kim, when we had you on last week, it was right around the embargo lifting on this announcement, right? That you guys made.
Again, people may not be familiar if they are great, but let's go over it again. Let's go over the announcement. And now that you're here and you've had a chance to kind of have it, get some legs uhhuh with people, let's hear what you're hearing.
Yeah. So we basically announced adding a gent, KI, uh, into our platform to help with security validation to understand that statement. There's some background that, uh, I need to repeat.
Uh, as I mentioned, we are providing a purple team platform. Basically, we have the detectors that are continuously being fought by an AI based threat team, uh, generative AI based, that builds customer specific attacks against our defense engine. And, but by that, we were able to show customers the true weaponized risks, uh, and how our system would detect that, uh, incident when it happens, uh, and how the, uh, uh, alerts how the CDR portion of the system will look like.
That was well received by customers, and they basically said, it's amazing, but we also have other, uh, security controls in our environment. And apart from seeing how Scoc will, uh, react to that incident when it happens, we also wanna make sure that the rest of the security controls we have in the environment will properly behave, uh, to do that. That's where Gent, KI, the new addition we just announced comes in.
Instead of just providing security control, validation of the customer specific risks and our detectors, we're now learning with the Gent KI, uh, framework, basically learning everything that the customer have in their environment. There are sim solutions, their eds, uh, basically we're learning everything that they have. And we, uh, show them how their, uh, ecosystem of security will behave when a weaponized risk will materialize.
That helps them do a few things. First of all, it prepares the soc. Uh, so it creates an automation, uh, of basically verifying that you have all the right detectors.
You can almost do a continuous tabletop exercise so that the SOC knows exactly when they see that sequence of events fired, that it's a true positive that was pre verified, already know how to respond to that. And again, we're now doing that ecosystem wide, uh, on the customer's environment and integration with Splunk, with CrowdStrike, uh, that we were doing, uh, in order to provide customers, uh, full coverage. Love it.
You've been here a couple days now. What, what's the feedback been? What are, what are you hearing?
What are You seeing? So, first of all, uh, customers are, uh, really, really excited. Uh, even my own customers, uh, not just here, existing one, right?
Existing customers are extremely excited about what we announced. It came from feedback. So that's, uh, obvious.
We always good thing, right? Listen to customers. They teach us, uh, more than, uh, anyone else.
Uh, but, you know, the traffic at the booth was amazing. The reactions were, uh, good. Uh, I feel that it touches true pains of customers.
You know, they get a lot of noise, a lot of alert fatigue. They don't know what to do with it. You know, people stand by the booth and, and they see the metricses that we placed out there, uh, that customers reported to us.
And they say, okay, I have that pain. I, I want to, uh, uh, learn more and, and resolve the same thing. It's real world.
It's a real world pain that they have. Like, they have real, literally, people told us, you know, hundreds of thousands of, uh, alerts that they need to deal with, whether it's on the risk side, on the vulnerability scanning, uh, as well as, uh, on the runtime side, you know, right. Left of the boom and right of the boom.
And we basically help with all of that. Uh, I must say that if you look on the announcements that were made this week by AWS and others, different places of the stack, but generally the same messages of, uh, AI agents that are, you know, doing analysis, each one of their on their own layer, uh, talking about noise reduction, about the ability to use, uh, AI agents in order to provide security. So I think you've see in different places of the stock, uh, exactly the same messages that are being, uh, conveyed to customers, which means there is a, a pain that the industry experience, again, in, in coding, in cloud infrastructure, in vulnerability management.
We see it all over. Uh, I think that there is a, um, a tsunami of, uh, yeah, solution. The solutions from that family that, uh, we're gonna see.
And I'm happy that we were there three years as innovators and think about It. Well, it's always nice to be, you know, early in, in, in that, yeah. In the movement.
Um, this will be over tomorrow. What, what's next for you at Skyhawk? So we're, first of all, we're going to continue to listen to our customers.
They tell us, uh, you know, the best, uh, where we should add next. Uh, I think that what we have right now is really innovative and probably two or three years forward of where most of the market is. Uh, our approach at Sky Oak was to create two major innovation every year, uh, that we announced.
Uh, and we'll continue to do it, you know, with the iGen, uh, simulation and verification. I think we, we mentioned it, uh, in our previous conversation, right? One of the things that we can do is also become a recommendation engine on what, what else to add in order to close gaps.
So, you know, these are areas we can expand to. Uh, but, you know, the core essence remains being a purple team platform, solving the pains of noise reduction, getting the SOC prepared to, uh, respond to events, showing customers their true weaponized risks rather than, you know, laundry list of vulnerabilities. They have nothing to do with the, the core values remain, and we will innovate, uh, around them more and more and more.
Absolutely. Excellent. Excellent.
Hey, I want to thank you for popping up here. Thank you for inviting me. Um, again, it's Skyhawk security.
Skyhawk security. Check it out. Um, I, I think you said you were gonna be at RSA or We usually do every year.
Yeah, maybe. We'll, we'll, we'll, we'll be doing this on Broadcast Alley there, so hopefully we'll see you then. Looking forward up.
A pleasure. Pleasure. Thank you very much.
Skyhawk Security, check him out here at, uh, AWS re invent. We're gonna take a break. We, we have more coming, uh, today, and of course a full day tomorrow.
So stay tuned. You're watching Tech Drunk tv. Hey everyone, we are live here at AWS Reinvent, continuing our coverage of day one.
A lot going on a lot of ai, a lot of agentic ai. You know what? I don't hear a lot about Cloud.
AWS Reinvent used to be all about cloud. Now we're talking ai, but we're gonna talk some security. One of my favorite topics, I want to introduce you two and make, I'm gonna mess up his name, but we practiced it 12 times and I still didn't get it right.
Sne, Ben Shimo, Shimo, almost, I wanna say Shlomo and I keep Schmo, but he likes to be called Ben. Ben, what's, thank you for coming on to Text Drug tv. It's great to have you on here, man.
Thank you for having me. So from the name, I'm gonna guess you, maybe you have some Israeli roots. Yeah.
But you live, you're a New Yorker, New Jersey, like me. So I guess that makes us kind of almost related, but, um, tell us about your journey. How, how did you come here?
Yeah, definitely. So currently based in New York, almost in the past 10 years, uh, been in cybersecurity for many years, as you all know. Uh, I'm Israeli originally.
So we started a journey in the military. Uh, I'm not 8,200. You're not 82?
No, My 1200 Is a few. Not 8,200, But actually 8,200 is quite big, yes. To the place that I used to serve.
I used to serve in more of a secret service. Okay. The Prime Minister office, which is, uh, more boutique, more unique, uh, harder to get into if you're 8,200.
Don't hate me, but we're better. Okay. Hey, he said it.
Not me, but go ahead. So, yeah, we, um, basically moved to the states after, um, managing a lot of cybersecurity, public company research division, building from scratch. Really, really passionate about research, anything related to vulnerabilities, attacks, offensive security defense.
And, uh, I found myself in, in New York as like one of the big companies. I build their product. They couldn't sell their product to the ciso.
And I was blown away because such a great product, we need to explain the value. And when I moved to the states, uh, I was really kind of exposed to, no matter how good product you're building, you need to be close to the customer. You need to be really close to the team, you need to close to the security executives and explain to them what's going to come next.
Mm-hmm. The thing with security is like, check, if you're playing, if you're trying to survive the next week or maybe the next year, you're probably going to fail in year two. In year three.
So when I moved to the states, one of my biggest goal was to educate them right? In like, what's coming up next to build a strategy in the right way. I used to be a CISO as well, and managing security organization.
Mm-hmm. Over 100 people. Um, um, very quickly, um, after that built a startup, a couple of really good friends named Cider Security very quickly sold.
I know Them well. Sure. Yeah.
So really quickly, we had a huge success. We sold it to Palo Alto Network. Mm-hmm.
Spot of Prisma Cloud. And I ended up loving the cyber, uh, security and startup. I'm like, wow.
I can do, I can build, I can do whatever I want. Versus enterprise. That was a little bit slower.
Yeah. So I decided to take some time off after the exit, and my co-founder, uh, who I didn't know is going to be my co-founder called me. His name is Uri based in Boston.
And he's like, Hey, so I have something interesting for you. I got to a point, you manage vulnerability management and cloud security for Akamai from Cambridge. Sure.
And he is like, Hey, I got to zero vulnerabilities in three of the massive Akamai environment. I'm like, great, Julie, you accepted the risk. Everyone can accept risk.
It's like, no, no, no, no. Actually remediate it. Actually.
It's like, excuse me. Look, vulnerability management is never happened, never happened, never happened. Vulnerability management is a list of problems everyone have.
And you just wait for, you know, s****y defense and bad things will happen, but it is what it is, right? And he's like, no, no. I was able to do something about it.
Uh, it sounds very promising. I opened a plane, went to Boston, and I spent a few days with Uwe. And what he showed me, I was blown away because I couldn't achieve it with the best team in the world of security people for all the decade I'm in cybersecurity.
And this is where I realized that vulnerability management, the dead market of vulnerability management, exposure management is, can be solved. We can actually win the vulnerability battle. Call me skeptical, but okay, I'm listening.
You got my intention. So after a long journey of speaking to over 100 good friends, CISOs and large enterprises, and also smaller one, everyone were, we're skeptical. What we ask him, it's like, Hey, if we can come in and take your backlog, your vulnerability backlog, and all these vulnerabilities that you're getting from Tenable, from Wiz, from AWS inspector for, and we'll talk about AWS later on while we are here.
But all these crazy vulnerability data from on-prem, from the cloud, take all this vulnerability data. You can sift through it. You don't have enough people in the team to review it.
And then you have work workflows, but you cannot automate vulnerability management because it's deterministic. Every CV is different, every vulnerability is different and the environment is different. So how can you automate?
You can't. This is why we're failing. And I ask him like, if I can take this problem and automatically reduce 90% of that backlog automatically without any human touch, just eliminate it and leave you with that 10 or maybe 5% to actually handle.
It's like, that sounds good. That sounds great. That's great prioritization.
And then I, then they told me, what about remediation? I was like, okay. So once we have that 10 or 5%, I know and we practice that, then we identify it, take that five to 10% and simulate remediation and give you that one, two, or three steps that you need in order to reduce Back to the buck.
Exactly. That's exactly what we're saying in our website. Mm-hmm.
And they say like, that's amazing. If I have something like that, I will, I will buy it. We, uh, close a seed round in a month really quickly.
We just took the money, great investors, and we built Zes security, which is the current company we're at today. Very excited about it. So that's basically the story of, Of you and Ze security.
Yeah. And ui. So lemme give you a little background.
I, I've been inside, but we didn't call it cyber, we called it security. I've been in security 30 years. Information security Info InfoSec.
Yep. Exactly. And, um, I actually, I've co-founded a couple companies, one of which was called still Secure back in 2001.
And we in 2003 came out with a vulnerability management product. And back then it was very different. Back then you had to convince people to do a scan once a year.
Mm-hmm. It was like pulling teeth. But when you, but it was job security for the security guy.
'cause you would do the scan, you'd deliver like a telephone book of vulnerabilities. Let's say I give it to 'em for Christmas or New Year's, you know, you're from New York. It was like painting the Veno Bridge.
You know how they paint it? Theno Bridge. Amazing.
They start on one end, it takes 'em a whole year To finish, To finish. And then when they're done, you know what they do, they go back and start again on the other. It's the Best job security ever.
That Was vulnerability management. It was almost by design that you didn't get to zero vulnerabilities. So then people got smarter.
They said, look, we don't need to get to zero vulnerabilities. We should only worry about the vulnerabilities that are exploitable, reachable real. You know, I had, I had a friend, I don't know if you ever heard of this guy, giddy Cohen, Skybox Security.
Yeah, of course. Giddy just started a new company. I know too.
I know. Um, you know, and that was one of when I first saw his attack maps is what he called them, right? Mm-hmm.
I was a revelation. I was like, wow, this is great. Now I only have to worry about 20%, 25%, Which is a couple of millions.
It's Still a couple of still job security. Yeah. But unfortunately, it's been almost by design that we never get to zero vulnerabilities.
And as a matter of fact, even you mentioned, we were talking off camera about black hat. I was a black hat in August. I was talking to a friend of mine, uh, two friends who actually just, uh, just starting a new company.
They just raised money now. And, um, their, their thing is, look, forget all these vulnerabilities. There's only a handful that are real mm-hmm.
That are responsible for incidents and just focus in on those. That's good. If I knew exactly which ones to focus in on, you know, that's like the old, an old joke.
A plumber comes and says, the lady says, I don't have heat. A plumber says, let me look. He takes out his pipe and he, he bangs the, he takes out his wrench and he bangs the pipe with the wrench and the heat starts working.
And the lady says, oh my God, what do I owe you? He says, $250. She says, $250.
All you did was bang your wrench on the pipe. He said, oh no, that was free. Knowing where to bang my wrench on the pipe is $250.
I love that. I I am going to use that. Tell You Got it.
Awesome. It's yours. Wow.
This, but that's the thing about vulnerabilities, right? If you know, which of the ones that are exploitable are dangerous, you can mitigate. But to get to zero, I'm not gonna ask you to give away secrets here, but what is the secret to getting to zero vulnerabilities?
So what we, and, um, I don't know if we want to get to zero. Okay. I don't think we need to get to zero.
Yeah. But we definitely need, like, why do the, the world need is important since you start talking about scanning. Today's scanning is mandatory Yes.
Of requirements, right? You have continuous regulators. You have auditors.
More than that, if you want to provide services as a SaaS, company to customers, you need to have an SLA. Yep. And what happened in 2025?
These regulators, uh, re requirements are stop asking you for visibility. Because visibility, everyone knows everyone have that list of vulnerabilities, right? Mm-hmm.
Everyone can scan. Everyone's scanning today, even SMBs, they're required to. But now the regulators starting to ask because again, I will, I will give some more information because I think it's important.
Over 60% of incidents today, and this is vouch number, are related directly to vulnerabilities that were known to the organization. Absolutely. I think it's higher than 60.
I think it's closer to 80. Um, I'm just basing on ENT report and Verizon report. Yep.
The time to exploit this vulnerability were reduced in the past three years in 90%. Now it's less than a day. Last year in 2024 was less than three days.
Before that it was five. So we got to less than A day. Remember it was 30, 45 days.
Exactly. It keeps going down. So regulators, cyber insurance, your customers want, if you have something critical, they want you to commit to an SLA and god forbid something happened.
You miss your SLA, your regulators will come after to you, especially if you highly regulated environment. Yep. Most of our customers are biotech, financial services, health and even SaaS company that provide services to this healthcare.
And Today, look, it's it's about who your third parties are. Yeah. Right.
It's not who you are. It's who they are when, so, you know, and further down the list And they want to get these deals. It's like, yeah, I cannot get these deals because I cannot commit.
Or they're committing. But now they need to deliver a seven days or six days critical vulnerability in production remediation. Absolutely.
It's the whole SOC two, all of these Other audits. Yeah. And what we actually realize is there is a need like not in zero vulnerability.
There is a need in remediation. Yeah. And how we do what we do is basically you cannot automate, but you can AI it.
So we using different type of LLA models, we acting as an army of security engineers that going one by one of these vulnerabilities. And it doesn't matter if they have high score or low score. It doesn't matter if they're being exploited in the wild or not exploited in the wild.
They're in your environment. Yeah. And what I need to tell you, if in your environment this vulnerability is actually risky or not, and you'll be surprised how the more the most advanced scanners, these tools that you paying million dollars to, they're giving you this list of vulnerabilities with attack path, with what will happen if, but they're not correlating that with your environment.
No. So you have an open SSH vulnerabilities, right. That open SSH vulnerability have requirements for exploitation.
You need to run the service with specific permission. That asset that is vulnerable need to live in specific environment, environment terms. Without them, this vulnerability can never be exploited.
And to understand that you need to send someone to do this test. Yeah. That's exactly what our agenda, uh, uh, capabilities are.
Wait, I needed to say it. You said it. We but you made a long time till you mentioned it.
Look, exactly. We're here at AWS reinvent. I don't hear them talking about cloud.
I hear them talking about ai. So talk to me about how your agent is working to do this. Uh, we actually announce, uh, we're going to have an announcement, uh, early next year, but in a reinvent, we doing a private preview of a new capability that was very, very interesting to all of our AWS enterprise customers.
AWS investing a lot in security. Yes, they are. And we call it native security controls.
So they're allowing today DevOps and, and platform teams and engineering teams that build a cloud to build a cloud in a secure by default way. And they have a lot of native capabilities around resources. You can build policies around services.
You can have security policies without paying money, just using the native capabilities of the cloud. If you will look in this native security capabilities and you will correlate that information. The hard work that your cloud architect actually infuse into your cloud correlate that with your vulnerability backlog that you need to solve.
You will realize very fast that many of these native security controls basically reducing 50 to 60 to sometimes 70% of your attack surface. But because you're not marrying these two together, you, you don't know. That means that you can focus on vulnerabilities that were already diffused and solved by and mitigated by this amazing AWS cloud native controls that you have.
So one of the capabilities of our agenda AI is to look and understand your policies around services, resources, encryptions, VPCs, microsegmentation in your cloud, and understand if this remote code execution vulnerability can actually exist. Even if you take into consideration these policies, most of them are not exploitable. Right.
That's the idea. I love it. It's great.
You already, you, you don't have a problem. You already solved the problem. Right.
And you don't know that you solved it. You know, some, some part of me sits here and says, did it take AI agents agent AI to reach this level? Like it's always bothered me to tell you the truth, why we didn't do better with this problem.
Right. I I was working on it 2003 22 years ago. It's Ago's a technology limitation.
It's not a need limitation. We always have that need. I think we've always had the need.
I I always thought we didn't have the will. Right. People, people talk a good game, but their hands don't reach their pockets when it comes time to, to really prioritize.
But this makes it easier more, it's, I don't wanna say automated, but it, it's just, it's easier to, to do this. You can win. I love it.
Yeah. I, I agree. We, We are giving a lot of, I I I'm really proud of it, but we giving more life years to our security engineering.
Yeah. Every time we talk to a team and the team sounds tired and unmotivated mm-hmm. This is the team we want to work with, the teams that have this backlog of vulnerabilities that every day of their life is chasing down these Vulnerability.
Look, this is a whole big problem. You, you've been in security long enough, you know this. Right?
The, the depression of, because for those of us who've been in security a long time, we have a lot of people in security who are, they suffer from depression. They, it, the, the, the issue is, it's like what does winning look like in security? I know that question winning is, I didn't get breached today.
Mm-hmm. Right. Did I not get breached?
'cause I was the zebra in the herd and the lion ain't someone else today. Or because I did a good job or I convinced my CISO and the board how to manage risk, what, you know, what's acceptable risk or not. And, and so anything that I think Im improves that is, is an amazing thing.
I was gonna ask you what Zest security's doing here at AWS, but you already answered that Ben, so that's fantastic. Um, what has been, so there are security people here, but there's everyone here, there's CIOs, CSOs, there's do people understand like the security people obviously do, but does the CIO does the cloud engineers understand what a, a load this is off of their chest, right off of their shoulders? Mm-hmm.
I don't think they care. No. I think at the end of the day it's Part of the problem too.
I like it's not part of the problem as much as, you know, we, me managing over 100 people, I knew everyone personally and I cared. Right. When you walk in a large enterprise, you like many times you can't do that.
You don't know what the security team in the trenches actually going through. Even not the ciso. Yeah.
Not talking about the CEO and the CO what I, what I actually, um, what what what I like to surface is if your security team, if your vulnerability management team that in charge of prioritizing vulnerabilities and fight the vulnerabilities are drowning, which they are, it's going to bubble up into management problem. Yeah. It's going to bubble up in audits.
It's going to bubble up the way you look in front of your customers that asking you about what you do about this, what do you do about that? It's going to bubble up when you have a red team or penetration test. It's going to look bad when you have a customer that's saying like, Hey, I asked you about this couple of days ago, what's going on?
And we're getting these emails, right? So the management team needs to look good and needs to act good and it start from the vulnerability. Start from the team.
So what I'm, I'm basically telling this COO and CIO is like today you have a backlog of do you have vulnerabilities? It's like, yes. Do you want to eliminate a and at least 90% of this vulnerabilities without spending money and asking favors from the CTO and engineering team without asking and pushing tickets into teams that need to build your business?
It's like, yes, of course. It's like I can guarantee you that with agent AI infuse into your exposure management program, your C program, you don't need to hire 200 security engineer. You can walk with your existing team, maybe add some more people if you want to, but you can win.
If you infuse AI into that operation, you can open less ticket. But each and every ticket you give to your engineering team, that ticket was 20 or 30% of your risk reduction. Got it.
And that's what they like, they, they sync numbers. Right. But at the end of the day, I'm helping the vulnerability management team.
Yeah. And if they do a better job, the COO, the CFO even will be happier. They don't understand that.
But it's okay, that's my job to make sure that both sides agree to embrace our technology. This will get, like these guys will get their executive report and the vulnerability management will get an amazing, amazing tool that will make them survive the holidays. We need to survive the holidays, right?
Yeah. Always. But then there's always another holiday.
You know, Ben, we're running low on time. I want to just make sure we hit a couple of things for people out there who like what they're hearing, what's the website to go to here? io.
Very Zs t Zs t zes Like the Lemon Ze. Yeah. io.
And we're very transparent about what we do and about our technology and we have our customers use cases there. Everything you need to know. It's in the website if you want to see it live.
If you don't believe what you're reading, which is okay, we have a dedicated security team that can show you a 30 demo, 30 minutes demo and actually to see it by yourself. And we also have, um, um, a free, we just announced a few months ago a free remediation assessment really, which is not a risk assessment. We're not showing you your problems, right.
Uh, we are basically showing you, uh, the probability of remediation operation. How can you remediate more with less? And it, it takes I think seven days of the platform to run, analyze, and get you everything you need without having any sales calls during that time.
So Absolutely. Yeah. io.
Yeah. Hey, I think you're onto something, man. Good for you.
Thank you so much. I really enjoyed the Conversation. I enjoyed having you on here.
We'll have you on again, Z security io. Go check it out. Look, this is, this is, uh, this is kind of a holy grail a little bit if you've been in vulnerability management and security like I have.
So go check it out for yourselves. I'd love to hear what you say about it. Enjoy the rest of reinvent.
I will. Thank you. All right.
We're live. We'll be back with more Stay tuned. All right.
Today we're going to talk about what a, a topic of how to generate an sbam, a software build materials with free open source tools. So we'll just kinda get moving. My name is Josh Bresser.
I am the vice president of security at a company called ancor. We are a kind of next generation supply chain company and we have a lot of focus on software, bill of materials, and we have some open source projects. I'm gonna specifically talk about those today.
But I am, I'm Josh. I do a lot of outreach. I do a lot of vulnerability work.
I've got a couple podcasts. I've got one, it's called the open Source security podcast. I do a podcast called Hacker History.
I'm on like all the socials at Josh Bresser. I love talking about this stuff. So by all means reach out, say hi.
I will talk your ear off about most any security topic you can possibly imagine, but this stuff's a lot of fun. So I'm really excited to share it with you today. So let's just kind of start out our conversation with what is an SBO m right?
Software bill materials. If you've been in this space for any amount of time, and you've heard about a software bill of materials, an SBO m often the comparison made is an ingredients list, right? Like I took a picture here.
This is literally a picture I took so I couldn't find when I liked of a can of it's, it's, uh, spaghetti sauce I think. And obviously there's ingredients and I picked out tomatoes specifically. And there's a good reason for this because when we think about it, our ingredients, when we think about the things in our software, like what is an ingredient, right?
What do we mean when we say that? And I think tomatoes is a great example because what, what is a tomato, right? When most of us think of tomatoes, this is probably what comes to mind, right?
Like a nice piece of fruit or vegetable, whatever you want to call it, I won't get in that argument growing on a plant, right? They look great, they taste great, everyone loves them, but the reality is this is what tomatoes are for a lot of us, right? But remember, our ingredient just says tomatoes.
Is it this, is it this, or is it this? And so that's what we're gonna kind of talk about today, is how do we go from an ingredients list into an explanation of what is in our software? So now what is an SBO m When we say SBO m, we are really talking about these two data formats.
One is called SPDX, the other is called Cyclone dx. Now, you could of course get into arguments, which is better. They're functionally the same thing.
SP X and Cyclone DX are both internationally recognized standards. They're open source projects. You can get involved, you can pay attention to them.
SPDX is run through the Linux Foundation. Cyclone DX is run through oasp, but I, at the end of the day, the thing they accomplish is basically the same thing, right? Where you somehow collect an inventory of your software and you put it in a machine readable format.
And we'll kind of talk about what that format is in a little while. But fundamentally, if someone says, I want an sbo m what think we're gonna mean is one of these two formats, and now which one? That's the question, right?
You'll find that some organizations will say, oh, we only want SPDX. Some will say, I only want Cycle and dx. You'll most won't ask for both.
Some might, but generally speaking, you'll find that every organization looking to do spons has settled on one just because it's easier to deal with one format instead of both, right? Obviously that's just the reality of computers. So when do we create these things?
And now this is one of the fun topics that come up with SBOs because there's different kind of times you can do it, right? Are you generating SBOs from your source code? Are you generating SBOs while you're building software?
Are you generating SBOs after you build to the thing you're gonna distribute to your customer or put on GitHub or whatever you're doing, if you're the consumer receiving a thing, are you, are you generating an SBO to see what's inside of it? And I, I stole this graphic actually from salsa, which is like a whole other open source project on supply chain security. But the graphic does, I think a nice job of kind of simplifying the various stages of software development.
And so from our perspective, we're kind of, I'm thinking of us as like the consumer, right? We're the person at the end. And so we're gonna do some talking about what that means and what we can do to generate a software billing materials kind of as a consumer.
You know, maybe if you're a distributor, you're gonna be over here. It's a little different. It's very similar.
But once we get into like build and source things get quite a bit different. And what I mean by that is like when you have a a, a pile of source code, what are you scanning? Are you scanning just your source code?
Are you scanning your source code plus all the dependencies it's gonna pull in. Like you don't always know what those dependencies are. An example being if I install a package right now from let's say NPM, we're gonna show off some NPM stuff later.
If I install a package from NPM right now and there's an update in an hour and then I install my package again in two hours, I might get a different version. So there's a lot of weird challenges that happen in some of these stages. Build is another good one.
If I take my source code, I put it in a container. Now there's the stuff that was in the container, right? That's some new software.
It's different. So the thing I generated over here in source isn't the thing I'm gonna generate during the build necessarily. It might not be the thing generated during dis distribution because maybe I add some things before it goes out the door.
Like who knows? There could be customization. And then when you're the consumer, it can change even more because obviously, am I installing software on top?
If I take a container base image, am I putting my private keys in there? Am I putting API access information in there? Am I customizing it with plugins?
It, it gets very complicated very quickly, but that's okay. We're not gonna worry about a ton of the complications. We're just gonna kind of go go with what we've got.
And then YI think a Y is the big one. And prior to I think 2025 SBOs were a novelty to many of us where we thought, this is neat technology. We think they're useful, they're interesting, but they're kind of a pain in the butt and it's a lot of work and I don't really want to do it, right?
This is one of those situations where everyone will say, oh yes, I want security. And then you say, I need a million dollars. And they're like, eh, our security's pretty good.
It'll do, but it's kind of a changing world out there today. So compliance, compliance is why we're gonna need SBOs. And that's just the simple answer.
It's not about security necessarily. It's not about like we'll say doing the right thing. It's it's compliance.
And the one to really keep an eye on is over here the Cyber Resiliency Act. It's called the CRA, this is a thing from Europe. It's going to, I think, change a lot of how we do a lot of software.
And the CRA has language that literally says you need an SBO M like it says the word SBO M, it's not like you need an inventory, you don't need an ingredients list. It says SBO M. And they're specifically calling about out SBOs in cycle and DX and SBDX format, unsurprisingly.
So the CRA is going to affect an an enormous number of companies. And you might say, but I don't, I don't, I'm not a European company. This won't affect me if you are selling into the European market, you need to pay attention to this.
If you have people downstream from you selling into the European market, they're going to tell you to pay attention to this because A CRA doesn't just give you like a blanket, oh, just make an SBO for your stuff and you're done. They want SBOs from your suppliers and then your suppliers will need SBOs from their suppliers and it's kind of SBOs all the way down. So the CRA is probably going to change the way we do a lot of things.
Now, the FDA is another one in the us. The FDA has SBOs literally written into law. So this is like a non-negotiable thing, right?
This isn't like, oh, you need an inventory sometimes. Like you literally have to have it. If you're doing medical device, you're doing kind of medical software.
SBOs are mandatory, there are other things going on. You've got, like the United States Department of Defense is saying they want SBOs. That one is not written into law.
So it's not quite as, it doesn't have the teeth like FDA and CRA do. But we're even seeing this in things like, you know, the new PCI, it doesn't say you need an spon, but it talks about an inventory of your software. You need an inventory of your software.
Guess how you're going to do it, right? I mean, same thing like FedRAMP, SSDF, this do, there's all these things happening. So this is a topic that is going to affect all of us at some point in the near future.
Okay, well how do we get started? Just pick a tool. Easy, right?
Pick a scanner and run it in. You're done. So there's a project I help with at the open SSF, the Open Source Security foundation that we call ourselves SBO M everywhere.
And we have this thing called the SBO M catalog. I've got the URL down here and the SBO M catalog has, we'll say a collection of tools in it. It is not comprehensive, it is not complete.
But these are the tools we have. And you can see this is already like an untenable list of things. How do you possibly decide which of these things you want?
And this is gonna be one of the challenges is there are a lot of tools, there are a lot of things you might need to do. And so inside of this tool, you have the ability to pick out like certain features you want. Like do I only care about SPDX?
I only care about cycling dx, maybe I care about both of them. I want make SBOs, I wanna convert SBOs, I wanna parse SBOs. Like there's all this stuff you can do.
There's the licenses of the tools, like the actual license. The tool is you can be like, is this free? Is this commercial?
I don't know what this is. There's a supported ecosystems. We've got this huge list over here.
So this particular one is for a tool called Sift. And we're gonna talk about Sift in a moment because it is one of the tools I help work on. It is an open source tool for Manco.
It is free and it is very useful and I obviously I'm highly biased, but I think it's the best one. Okay. Now what to scan, this kind of comes back to that, that salsa picture we had just a few minutes ago.
And it's not as simple as just saying, I'm gonna scan a directory, I'm gonna scan a container. There's a lot of artifacts we generate in like the world of software, right? You've got like source code repositories, you might have virtual machines, you might have like zip files, you can have tar files, you've got your container registry, which is where you store your container images.
You've got like a Kubernetes cluster that's running stuff. You might have this stuff you're getting from vendors. So like these are all things you need to think about is what is the thing I'm trying to scan.
Again, not every tool can do everything. Like as much as I would love to say, SIF does it all. It doesn't do everything.
It does a lot, but it doesn't do everything. So this is a very, you have to think about what you are doing in your situation. There's no easy answer.
You might have to do some research. You can come find someone like me and I'll talk your ear off about this if you want. There's groups like, you know, at the open SSF, we're doing this sort of work of trying to unwind some of this.
There's people at oas, there's, there's groups all over the place that are trying to help everyone understand this. And I'm sure as we see things like the CRA come into force more, you're gonna see even more guidance and even more written about these topics. So it's an interesting concept that is not simple yet.
It's getting there, it's getting better, although maybe it'll get worse as everyone writes an spon tool. Okay, so to get started, we're going to install Sift. Now sift is a very simple application.
It's just a go binary one binary, right? We're not talking about like installing this big Linux distribution and putting all these packages on top and all this. It's really small.
There's a container, you can install it on your local system. There's like GitHub runners, there's CICD integrations, all that stuff, right? But we're talking about functionally one binary.
It's written and go. And so it's nice and easy to install, which is one of the goals of the projects to make it easy because obviously if something is really hard to install, if something is really hard to use that that's, that makes it more difficult and it, it pushes people away. So I've got a couple videos that I'm gonna show and we're gonna start with containers.
So I'm gonna hit play and I'll pause and kind of explain along the way as we go. So if we just wanna scan a container, this is kind of what we do, right? We can just say Sift Debbie and latest and that's going to scan a, the container name Debbie and Latest.
But where's it coming from, right? It Sift has a DA bunch of different places it might look. It's gonna look at your local Docker, it's gonna look out into registry, it's gonna see if it's, you know, on your system.
We can find it. So just saying Debbie and Latest might not do what you want it to do, but it's as simple as that. Like you can just type that in and it's gonna do what it wants.
So we're gonna delete that and we're gonna say I want to use my local Docker instance to scan Debbie and Latest. And so now I'm saying I have Docker running on my system Sift. I want you to ask my Docker for Debbie and Latest.
Okay, that's not too bad. Now though, we can also ask an OCI registry. io and download Debbie and latest from there.
So now Sift will reach to the registry and it'll pull that container in. Now we're doing that right now we're actually scanning it. Okay, so now we can see it scanned the Deion container.
There's 78 packages installed, 655 executables, you know, 4,000 files. It's gonna give us this nice table output of the, you know, the package name, the package version, the the thing it found. So in this case, most of them are gonna be Debs, you know, Debbie in packages makes sense since we're dealing with Debian.
But you can imagine if you have Python packages installed, if you have Java jars installed, kind of, there's all these ecosystems and there's all this stuff and we're working, especially with containers, you will have a collection of random things. And so it might be a bunch of, you know, DEBON packages plus the, the Python I put inside of it, whatever. And SIF tries really hard to figure out what all that stuff is.
Now I have another piece to this example which will play, let's scan the Alpine container. And Alpine, for those of you who don't know, is just a tiny Linux distribution. And so that's gonna scan, obviously it goes pretty quick, but now we can see 16 packages instead of 78, right?
It's quite a bit smaller. We see kind of the same information and the point just being like, these are just two examples of things CIF can do. Now I'm gonna hit play again and it's gonna run for a minute.
And we're gonna talk about outputting. I talked about SPDX and Cyclone dx. This table format is for humans, it's not machine readable.
So it has the ability to output, for example, an SPDX JSON file, right? Seems easy enough, makes sense. Like boom, we're done.
We have A-J-S-O-N file, that's our sbo, that's the thing we can store, we can give it to customers. Whatever we need to do with it, we can do with it. I have another example now where I'm gonna scan a directory instead of a container and we're gonna create a little NPM project.
And I wanna kind of explain one of the, I guess, unique challenges of installing software. So we're gonna install this thing called Axios, which is just a, a node package I picked on it because it, it has a lot of dependencies but not too many dependencies. One of the jokes and like the node ecosystem is that you're gonna end up with thousands of dependencies.
You can see I install Axios, I get 23 packages and it's like, wait a minute, I installed one thing so I can look at my package JSON file and it shows Axios. I installed one thing like what is going on? Why did this happen?
And this is something sift is really good at. in this instance and then show me what you get. We see it from 23 packages.
That is interesting. That's the same thing. That's good it matches up because sometimes it doesn't.
And then you have to ask questions about why are the numbers not the same? But again, we have this situation where it's gonna show, right? We've got the name of the package, the version of the package and then the type in this instance NPM, 'cause we're scanning a directory full of NPM files.
So this is like, this is what SIF does. It tries to go as deep as it can. It goes inside of all the dependencies.
If you have like for Java jars are especially gnarly 'cause you can have jars inside of jars inside of jars and it's like jars all the way down. And so this is what sift does. It tries to figure this out, it tries to go as deep as it can.
Now for outputs you're gonna say what should I output, right? Sift has all these different formats that it can help with. This is actually the list I took from the dash dash help, I just made it look prettier 'cause dash dash help is kind of ugly, but at the end of the day the formats you want are cycle and DX and SPDX, right?
And I even put a, a little pointer at, I said use these two. So they do like X-M-L-S-P-D-X is this thing called tag value, which looks like a human readable table. There's just use the JSON.
And the reason I say that is most of the tools today that are capable of doing something with an SOM, they are expecting JSON because JSON one, I'm not gonna get into an argument over, you know, JSON versus XML but JS O one. Now there is a format from sift called sift JSO. And this is kind of a magical format because of what sift JSO does is you can imagine Cyclin DX and SPDX are a little different as all good standards are and you can't like convert from one to the other.
If I say I have an S-P-D-X-S bomb, but I wanna turn it into a cycle and DX sbo, like there are ways you convert them but you will lose information. They are not lossless when you convert them from one to the other. So what we did with sift is we created this format we call sift js ON, that's just like the Venn diagram of everything.
And so sift js O can be converted to cycle DX or SPDX without losing any data. Sift JSO is not a standard, do not give it to anyone ever. That is not why we did it.
We did it because we needed the ability to output either format or both formats in some cases. So if you're storing them for yourself, CIF JSO has some advantages, but if you need to give them to someone, do not give them a cif. JSON like things, there are no tools except sift and gripe that know what to do with these things.
So what does an spon look like? This is the just output of an spon file, right? This is actually from that alpine image we scanned just a moment ago.
And this is what it looks like, right? You've got like some metadata information, it's got package information and it goes on and on and on. And these these files are pretty big.
Like we're talking, you know, hundreds of kilobytes, maybe megabytes. There are some SBOs I've seen that are hundreds of megabytes. It just depends, right?
It depends how big the thing you're scanning is, how much stuff is in it and what you're doing with it. In this instance, obviously it's s the SPDX format, like these are not for humans. So I would never suggest you necessarily spend a lot of time in it.
However, if you are writing tools and need need to parse these, the JSON is well formed. It is easy to understand. These are well-defined standards so you can look up documentation and get an idea of what you need to do.
And there are tons of libraries, like if you are for example, writing a a Python application, a go application, and you wanna parse an SPDX file or a cycle NDX file, there are libraries from these projects that do that. So you don't necessarily have to be the one that's, you know, writing your own pares and trying to understand the JSON, which is good because they get very complicated very quickly and the standards change, they are both under active development. You will see new versions of SPDX and Cyclone DX coming out on a regular basis.
So even if you write a parser today, you aren't necessarily going to be able to parse whatever's coming out next. So this is just kind of one of those things as a developer to keep in mind. Okay?
There are also some additional sift tricks that we could do, right? We can obviously output the SBO M to a file, which I showed you can put the file wherever you want, you know, unsurprisingly, as almost any tool would do, there's excluding paths, excluding paths I think is an underrated feature that is extremely useful. And the example I will use is literally sift itself.
So you can imagine that sift the source code has like a bunch of tests and the tests are gnarly things, right? This is on purpose because it's anytime a bug is found, you create your test. And the test obviously does something ridiculous as all tests do.
And so inside of the SIF test suite, there are like weird SBOs, there's weird examples of like applications of like package lock files, things like that. And so if you scan the sift source repository, it looks like sift has like 30 some thousand things inside of this directory. It doesn't really, it's full of test material.
And so you can imagine that when you scan something with like weird tests or just weird content, you're going to get, uh, false positives or false negatives in many instances. In this case, sift has a huge number of false positives. This is a pain in the butt.
So this is an example where like if we scan the sift, uh, source code, we're just gonna say don't, don't scan the test. Ignore that stuff. That's not legitimate content.
Now obviously after we build the binary, and if we scan the sift binary, which you can do, you can scan sift with sift, which is extremely amusing to me. But if we scan, sift with sift, like the, the tests don't get built in. So obviously they're not there.
And so we're just gonna get a list of, of what you need. Um, sift has a configuration file format, right? We can preset some of this stuff.
We can preset what directories to skip. We could tell it what output we expect. We could tell it where to store things.
These are just handy, handy tools we can use, right? That way we're not having to remember or try to not make mistakes when we type it in in the future. Um, you can also connect it, you know, private registries, that's a big one.
A lot of us now have our own private registries, be it hosted somewhere else or we're hosting in-house, right? And again, you have to send credentials in things like that. Like that.
It works, it works great and it's widely used. Alright, so there's some next steps we can take as well. Automate automation is key in this day and age, right?
No one would expect you to run all this every time you do something. So one of the things you can do is like sift has an SBO M action for GitHub. So you can just say, every time I build a release, build an sbo and now the SBO is part of your release, right?
Automatic, we're done. There's a bunch of open source projects doing things like that. Like python's.
A good example, the Python project is automatically generating SBOs now, which is cool. And like humans aren't involved, which is good 'cause humans make mistakes and they sleep and things like that. You can scan an SBO M for vulnerabilities.
This is probably the most widely used use case today because obviously via list of software, you can say, what are my vulnerabilities? What are the problems my software has? Makes sense.
The cool thing about scanning an ason for vulnerabilities is it's really fast. If I scan a great big container, let's say it's gonna take, I don't know, a 10 seconds, 30 seconds, whatever to look for all the packages. And then it creates the, the list of packages and then we scan it for vulnerabilities.
If I already have the SBO M I've already used up my 30 seconds of compute time making the SBO M and now I can scan it for vulnerabilities usually in milliseconds. So it's a super cool feature and I really like it and it's so much easier 'cause the reality is like SBOs are static. Like once I have a list of my stuff that doesn't change, well, it will change in the next release obviously, but then I just generate my next sbo.
Whereas vulnerabilities are like, the arrow of time continues to bring us new vulnerabilities. So the number of vulnerabilities I have today won't be the number of vulnerabilities I have tomorrow. We're adding what, like 7,000 a day or something in CBE right now, like it's gigantic.
And then store them somewhere. Now whenever people ask me like, okay, I started making SBUs, what do I do? And my first answer is like, just put 'em in a directory.
There's tooling you can use. There are applications, some paid, some free that let you like ingest these SBOs and, and do interesting things with them like scan for vulnerabilities. But to start, just use a directory because this is one of those situations where like, you know, crawl, walk, run, just start putting them somewhere easy.
Eventually you can, yes, put them into your NoSQL database, you can put them in your SBO management tool. You can use, you know, like Splunk at elastic search to extract information. There's all these things we can do, but just start, don't worry about any of that stuff, right?
Just start simple. All right, vulnerability scans. I've got a little preview here.
This little guy over there on the side, that's the gripe mascot. The SST mascot was a bird with glasses, you know, many slides ago. But this is an example where I take my, that Alpine S bomb we made, right?
And we can scan it for vulnerabilities and gripe is meant to be just as easy to use a sift. We're not talking about gripe today, but I just wanted to kind of show an example where we take our sbo, we scan it with gripe, we get our list. Obviously this is a human formatted list you can output to JSON and various other formats.
Some are industry standards, some are like the gripe made up, one that can output into industry standards. We get the idea, right? It's meant to be simple.
And now we can take, if we have that sbo, we can scan it every day and we can look at what the results are. We can store the results. We can ask questions like, what are the new things from today?
What are the stuff, you know, what's the stuff I have to worry about? What are the packages I should upgrade? Uh, alright.
Now there's also, when we talk about use cases, there are many more use cases than just vulnerabilities. Vulnerabilities are just, I'm a vulnerability nerd. So that's the one I won't shut up about.
So other use cases, there is a paper from the open SSF, that group I'm involved with at the Linux Foundation, SBO M everywhere. We published a paper recently. The title of the paper is over here is Improving Risk Management Decisions.
That Sbam Data, which is a mouthful. It doesn't necessarily sound like something exciting to read, it's a very good paper. But one of the things it has is use cases.
And obviously I just grabbed a snapshot. There's many, many pages that detail what this means. But there's more than just vulnerabilities, right?
We've got like our CVEs at the top of the list, of course. But then there's things like open source licenses. What are the open source licenses in your application?
End of life software, right? Do we know how old some of this stuff is? Once we know the name and the version, we can ask a question of how old is it?
Where did it come from? There's, you know, risk assessment. This is turning into a thing where companies will say, gimme your bum, I wanna see what's in your stuff.
And you could be like, you haven't updated anything in 10 years. We're not buying your software. Uh, component usage, this is a great one where the idea is how many, how many groups inside of your organization are using Axios?
How many are using Log four J, right? Things like that. And so you can be like, okay, we're using 30 versions of Axios, so what if we started using two instead?
So there's, there's a lot of interesting questions you can start to ask once you start to capture this data. And that, that's part of the fund right there is, you know, incident response is a big one. Uh, log four J was an incident response incident, right?
If you had a catalog of all your software, instead of saying, I don't even know what software I have, we could say, let's go see what has log four J in it. And, and this is actually something I saw during that was an organization had SBOs for all their stuff, and in literally like 10 minutes, they knew where lock four J was and everything. It was amazing.
It was so cool. But anyway, you get the idea, it does more than vulnerabilities. Now there's some gotchas in this data though, too.
Accuracy, SBOs scanners aren't perfect as much as I would love to tell you, sift is perfect and doesn't make mistakes. It is not perfect if you run it and you find false positives, false negatives, weird bugs, whatever, like file, file, file an issue. And GitHub, we want to know, we want to fix it.
Our our goal is perfection. We know it's unattainable, but that's what we're working towards. There's things we just can't scan right now, right?
There's some archive formats that aren't necessarily supported. You're like an encrypted zip file. Like we, there's nothing we can do with that.
There's, there are things in the works, and that's okay, right? This is just one. You have to know what you can and can't do.
Every, every tool has limitations. Know what they are. There's things we can't see.
So one of my favorites is every couple months someone shows up is like, Hey, did you know if you delete, like your package locked at JSON, the SBO M scanners won't find anything. It's like, yeah, we know. Don't do that.
So there are malicious attempts to hide from an SBO M scanner, which will be successful. It's not that hard to do, but there's still like, there's, there's ecosystems that might not be supported. There's some package formats that might not be supported.
So like, it's not, it, it's not perfect. Again, file bugs, we'd love to hear about it. And then convening, converting between formats, right?
You just, you can't take an SPDX and turn it into a cycle in DX at this time, that does not work. It's on the list. They're working on it.
But in the interim, this is where like the sift JSO format can be useful. So there are things, there are things you can do. It's not simple.
So kind of next steps, this is, this is some ANCO links, right? We've got like a link to sift here. We've got a nice introduction to s om site that, that can help with that.
You know, we've got a discourse for our open source tools, sift and gripe. We have a tool called Grant, some things like that. Um, SOM getting started guide s om at scale.
Google did a great job of that. They literally scan like millions of these things on a regular basis. Absolutely amazing.
So there's a lot of cool content. There's a lot more cool content coming, you know, if you want come find me. I'd love to chat.
I absolutely love chatting about this stuff. It is one of my favorite topics. Most people I know aren't willing to chat about it.
So please, please come and chat. But otherwise, thank you so much. This has been an absolute treat and a ton of fun.
And I hope you learned something new today. Nvidia is gonna sell chips to China. Reactive hackers.
IBM is buying confluent. Intel's not selling their networking, bu after all IBM says the data center boom is a bust. CloudFlare is gonna break the internet again.
And we're gonna take a closer look at Micron because they're moving on from consumer Ram in this week's episode of the Tech Field Day rundown. Hello everyone, welcome to the Tech Field Day rundown for December the 10th. And you know, something else that's important that's measured off in tenths, that's the Dewey Decimal system.
If you don't know what I'm talking about, you should watch UHF Conan, the librarian will teach you all about the Dewey Decimal system. Uh, but luckily when it comes to things that are decimals and measuring and stuff like that, I have a co-host who knows all about that because he measures everything in science units. Al it's good to see you again, always a pleasure to be here and particularly on National Lagger day.
Uh, it is of course summer here in New Zealand and it has just been rather hot. Uh, and so a nice cool lagger is always a great way to finish a hot day. Well, good luck with that because you know what else we've got that's hot is some news from this week.
I know you, you think to yourself, well the, the year's winding down, how much more excitement can you pack into the last three weeks of the year? The answer, of course, is quite a bit. We're gonna start off with probably one of the bigger stories.
The Trump administration has reversed an earlier export limit and will now allow Nvidia to sell its H 200 AI chips to approved customers in China. But they are gonna keep the most advanced models from being exported. They're still banned.
In exchange, the US government is going to take a hefty 25% cut of the chip. Sales officials say that the move balances national security concerns with economic interests, but those pesky critics warn that it could boost China's AI capabilities despite ongoing concerns. Al, do you think that it's a good idea that Nvidia should be able to sell its old busted H two hundreds to China?
Well, it seems that there's confusion here that national security being absolutely vital and staying ahead of China near pure enemy, uh, at least potentially enemy, uh, is, is absolutely vital. Yet if you give the corporate treasury or the government treasury a little bit more money, it's no longer a concern. Um, seems a little weird.
We've covered China's progress on AI previously and have particularly seen that Chinese chip foundries are building their own AI chips and although they're not quite up to the standard of what producing progress is gonna be fast there. So I'm not sure whether this is simply a case of the horses already bolted and allowing China to receive some of the older, uh, GPUs from Nvidia as no longer so much of a risk because they have their own organically created GPUs that maybe are, are gonna be at least as good. So we're, we're not necessarily letting them get any further ahead than they would've been.
Of course, this doesn't cover the latest, uh, Blackwell and the, the upcoming ban chips. Uh, those are still not gonna be allowed to export to China. And there's also some interesting language around exports to approved buyers within China.
Uh, we know that the US government is somewhat skeptical of the technology companies in China that are aligned to the Chinese Communist Party and the Chinese military. And so we wonder just how many approved buyers there will be in China for this new technology. Of course, we've also covered in the past the ways that, uh, non-approved buyers in China and also other sanctioned states have been acquiring this kind of, uh, advanced technology despite all of the best sanctions.
So I'm not sure that walls around the export of these products are working very well. So maybe just taking some money as these, uh, illegal exports or maybe, uh, restricted exports are happening, make them legal and take some money. That's an argument we've seen before around all kinds of, uh, regulation.
There's a critical vulnerability in react server, really common web framework, and it lets, uh, attackers run malicious code using a single unauthenticated http request. The, uh, floor is tagged as CVE 20 25 5 5 180 2, and it comes from the unsafe deserialization and react server components and effect a whole lot of the Java frameworks like Next JS and, and Vita uh, pass on Redwood, uh, exploit's a highly reliable, that's the last thing we want from exploit. Uh, and proof of concept code is public making it very easy to get on board.
Many apps are at risk given that ev uh, even if they don't use React directly, because they use components that themselves have react in them, admins and developers are urged to update react, uh, related dependencies and maybe imp uh, implement some further security controls to avoid this remote code execution. Uh, this seems pretty horrific to me, Tom. Uh, are you aware of React in your environments?
Uh, no, I'm not and mostly because I think 5 5 1 8 2 is so impersonal. Why don't we give it some cool name like react to Shell? Yeah.
That that's what they're calling it. This is another example of a little problem that I like to call. Well, how could they figure that part out?
So you, you mentioned that there was a deserialization problem. Basically the client server connection is allowing a specifically, um, crafted HT TP packet to hijack the execution logic because it's not secured and it's not looking for incorrect data structures. Again, I go back to how, how, how did you figure this out?
I know I just threw a whole bunch of stuff at your server until it broke and that's what they did. 0, you've got a problem and you need to upgrade sooner rather than later. 10 out of 10 is not something to mess around with.
And I, I've noticed that we've seen that a lot over the last year. 8 10 out of 10 because they are so easy to use. This is not one of those things where, you know, it's, it's got a high score, but it's so difficult to like, you know, gain access to the data center and put a CD in the drive to hack it.
No, no, no. This is pretty easy to pull off and it's almost 100% effective. Effective on the effective versions.
You've got to upgrade and don't just assume, oh, well I don't use React. Figure out what software you have do does use React. You mentioned next Js, wku, uh, Redwood, s St SDK.
There's a whole list that is a huge mess that you're gonna have to sort out. You've got to go upgrade these things because if this is as easy as it looks in the proof of concept, you're probably gonna get owned before you know what's going on. So don't, don't walk, run.
And I know you're probably on change freeze December, but security patches are uh, probably an exception to that rule. IBM is set to buy data streaming company cofluent for $11 billion in cash. They're aiming to strengthen their AI and cloud services with Confluence real-time data technology.
This is the biggest deal that IBM has done in years and they're expecting to close it sometime in 2026. The intention is to improve how businesses feed data into AI systems and analytics tools. This one hit in the morning, uh, this morning and it was kind of interesting to see how it went from, well, there's a rumor that this could possibly happen to within a couple of hours.
It absolutely was gonna be happening. Al do you think that IBM making this big acquisition is a good move for them? I think it is.
I think one of the things we've seen with IBM is that they've recognized that getting into new markets that transforming IBM to be relevant in the cloud and AI world is not just a matter of big science projects that they've done in the back row, but it's also about finding innovation that's happened outside of IBM and acquiring that, that innovation. Uh, the last huge deal they did, of course, was acquiring Red Hat in 2019, which was very much a recognition that, uh, Linux systems and large scale deployment of Linux systems is vital to having any kind of cloud estate and that IBM needed some presence in that cloud estate. We're highlighting also that last year, uh, IBM acquired HashiCorp, who, uh, have a whole bunch of tools for helping developers and infrastructure professionals work at cloud scale on things that aren't necessarily restricted to, to just public cloud can also be on premises.
So we're seeing this as part of the, uh, approach that IBM has shifted to from let's build everything in-house. Let's lead by being the most expert, and, uh, understanding by building our own things to let's also acquire things from outside that are gonna be valuable to build our portfolio up. And I think it's a really good thing.
Uh, I was interested that $11 billion was the price for Confluent and Confluent is, uh, essentially a managed services tool, manage management tool for dealing with Apache. Kafka itself is an open source, uh, and free software tool. Uh, it is probably one of the most widely deployed tools for dealing with large volumes of streaming data.
And this is, as I play into ai, this is about data that's coming into your organization and large volumes, but with what I characterize as low value per unit of data. And using AI to translate that into actually higher, uh, value data in, in smaller volumes. So getting, handling large volumes of data, feeding it into your AI pipeline absolutely is part of how people are, how businesses are going to get value out of AI long term.
Dealing with that huge volume of, uh, business data and logistics data, and even operational data, and trying to make sure that we can efficiently operate at large scale. This is absolutely where IBM should be playing. So, really glad to see this acquisition.
Of course, it's great news for Confluent. Uh, the offer was at a roughly 34% premium on the stock price that Confluent had when this was announced. Of course, confluent is now trading up 30%, so it's matching up.
Uh, the market loves this as well, because IBM stock prices also going up, despite the fact that they're about to spend 11 billion. Uh, yeah, seems like a really good move for IBM and should bolster the deployment of IBM software and solutions into Cloud hungry customers, and of course, ai, because we can't have a story without AI in it, Intel has decided maybe not to sell or shut down its networking and Edge Group, the NEX group, after all, saying that the unit's important for integrating its chips, software and systems across AI data centers and Edge computing, uh, talks with Ericsson about taking a minorities stake in, in Next have ended, and the business unit will remain a part of Intel as the company reinforces under its new leadership. Uh, the reversal comes as Intel's finances improve, and so it's requirement to sell off assets comes away 'cause of investments by Nvidia, the US government and SoftBank, uh, gives Intel a bit more space, a bit more breathing room to rebuild its strategy and focus on the core things that make Intel unique.
Uh, seems like lots of up and up for Intel in the last couple of months, Tom. It has, and that all comes thanks to money. It's amazing how that fixes almost all problems, right?
This very much comes down to Intel looking to offload a business unit because they needed cash because they were not doing so well in the first half of 2025, and then round about August or so, suddenly some people are interested in them. We've seen big investments from US government, from SoftBank, from Nvidia, from a lot of companies, pouring billions of dollars into Intel, which has allowed them to renegotiate some deals, which has allowed them to say, maybe we need these pieces after all. I get it.
Originally the idea was let's get rid of anything that's not a chip making business and toss it out to see who will buy it. In this case, Ericsson really wanted this networking business unit because we need the cash to bring all these foundries and factories online to be able to continue business. But again, with an infusion of a few billion dollars into your capital fund, turns out you can do a lot and not have to sell off everything that's bolted down.
I, I applaud Intel for sticking around here because one of the things that this provides is not just networking. These components are manufactured and integrated into a lot of things. We've talked, you know, over the year about how Intel has been forced to cancel products, has been forced to lay off thousands of workers.
I think that the, the Tide has finally turned for Intel. I mean, I saw a report yesterday that there's a good possibility they might actually end up shipping one of those gaming gps that they've been trying to put out for a while that could give them bolster in the market to open up a new line of business that will then allow them to take in some money, maybe get those foundries online so that companies like Apple will start buying chips from them again. And once they're back on firm footing, that really will give them an opportunity to shine.
The question is, will it be enough to topple the rest of the companies in the market who are screaming ahead, selling things that are not boring, old gaming, GPUs and edge networking gear? Because we all know that everybody's hot for AI right now, and that's not an area where Intel's really focusing. I think what they're doing is they're providing an alternative in the country to manufacture those chips, to manufacture those devices that would potentially avoid tariffs and other things like that.
I'm glad Intel's holding onto it. I hope Aons not too disappointed that they're not gonna be able to buy it out. But look, folks, it's a good possibility that if this, if all of this goes sideways, you may get to pick it up cheaper than you were hoping.
We're gonna go back to IBM because CEO Arvan Krishna argues that the data center industry's massive AI plans really don't make economic sense. He estimates that it would take around $8 trillion to build the capacity that companies are currently promising. He says, the odds of reaching artificial general intelligence soon are about 1%.
Data centers are gonna need to be rebuilt every five years, and the revenue that they generate can't cover the debt that you need to fund them. Krishna's warning echoes a growing consensus that the current AI build out might be a little bit over hyped, and that financially unrealistic goals, uh, are there unless major technological or economic changes occur. Al, this isn't the first time that we've heard somebody throwing cold water on the current AI planning, but it's the first time that we've heard the CEO of a large company involved in the whole market tossing what it bounced to a pretty big pale of cold water on it.
Do you think Arvin Krishna is onto something here? Well, I think it, it lines up with what I've been seeing that a lot of the AI hype seems to be talking about a continuous exponential growth forever. And anybody who's looked at exponential growth knows that it can't go on forever.
Uh, sooner or later, you end up with, uh, needing more resources than exist to support that, that growth and with exponential growth, that happens really fast. So this idea of, uh, needing $8 trillion to build out all of the data centers that are being committed to that doesn't actually seem unreasonable. The math kind of adds up that, that's the forecast.
So where is the, well presumably two to three times that much, 16 to $24 trillion worth of value coming from. Because if you're spending $8 trillion to build out the infrastructure, you'd be better be getting a multiple of that back in terms of value to business. And that's where I see the big challenge at the moment.
So simply going by this, we're gonna exponentially increase the amount of resources we use to build ever bigger and more complex things that just doesn't stack up for long. Uh, it, it absolutely works at the beginning. What's likely to happen along the way?
Well, people are gonna run outta money, people building some of these infrastructures. Now, it's not gonna be the really big companies, the, the really large companies building out these infrastructures have have deep pockets. They don't run outta money fast.
It'll be the smaller, uh, I'm expecting to, to see some of the neo cloud struggle. Uh, maybe their exits will be to sell their, the capacity they've built to these larger companies that are promising to deliver these huge amounts of capacity. But I'm expecting to see some, some changes in there.
What I'm really hoping for is a fundamental technological change. That means we don't have to continuously go with this exponential growth building a model that is 10 or a hundred times as big as the last model that we built in doing this every 18 months. That's what's driving this exponential kind of thing.
My other concern about it is that these models are supposed to be built on human created content. And I think deep seek was the first model that we saw where the, the content that was being used to build the AI was generated by ai, by ai. And that seems like a sort of, uh, robber, a snake eating its own tail situation where you eventually run out of anything that's valuable.
You, you end up with a completely garbage model because it's being fed so much AI generated content. And we know AI generated content is currently not nearly as good as human generated content. So there's some, some interesting things about how this market's gonna play out.
I continue to keep my fingers crossed for some technological shift that will get us away from exponential growth in order to get not exponential improvements. There is definitely a challenge with the size of data centers, the amount of power those data centers are gonna require. And then that financial challenge of replacing them every, well, Ivan said five years, maybe it's as quick as three years, because that's the pace at which GPUs become outdated and need to be replaced to be cost effective to continue to use.
Uh, no, whenever somebody tells you there isn't a bubble, it can't possibly be a bubble, uh, it's quite often as a bubble and maybe we'll see this, uh, come back down again. My hope is we don't see a huge loss of business value. We see new technology that allows us to deliver more business value without more cost.
Often a requirement that we're looking for in business. Hey, remember that? React to shell vulnerability, kindly titled CVE 25 20 25 5 5 1 8 2.
Uh, well, it's being actively exploited by China linked groups, and it's attacking all kinds of tools. I think this is going to be, uh, our next, uh, log for Js Turkey hunt or, uh, Whack-a-Mole trying to find all of the places, uh, cloud CloudFlare forced a global outage to block these attacks because of course, you inspect the attacks and say we're having those. Um, and AWS is warning organizations to patch immediately.
Experts say rapid AI assisted weaponization of vulnerabilities is becoming the new norm. Just when you thought security stories could avoid the trap of ai, Tom, here it is for you again. Yeah, you're probably thinking to yourself, didn't Tom just talk about this?
Yeah, but I'm not talking about the vulnerability. I'm talking about the response to it. Because what happened, CloudFlare shut down to block those incoming connections because one of the things that you see a lot when you have one of these brand new zero days is you have a bunch of people that are trying to make as much hay about it as possible as quickly as they can.
And that's exactly what happened here. Everybody rushed out and tried to use it as an attack. Well, the downside of having CloudFlare as your is your, uh, proxy layer, if you wanna call it that, is that when CloudFlare goes down like it did a few weeks ago, it can knock the whole internet offline.
The good news about having CloudFlare as your proxy layer is that when they detect spikes in traffic that are related to certain things like this, they can do something about it. Now, you probably are thinking to yourself, well, CloudFlare didn't go down. You're right.
It didn't go down for long because all they had to do was drop all of the current connections and then institute rules that prevented react cer sessions from flying all over the place using malformed packets. Pretty easy, huh? The AWS component of this story is even more interesting because, you know what I would do if I was AWS to limit my liability for all of these things?
If I detect that you're running a vulnerable version of React, I deny incoming connections to your cloud until you patch. That is the new area that we are gonna live in. We are going to be at the mercy of our providers because I don't think AWS or Google or Microsoft or Oracle or IBM or anybody who runs a cloud wants to have that much extra exploitation traffic running across their network.
And so if they have an opportunity to create some momentary pain for their customers, for the good of them, then take your castor oil and be done with it. Now, I, I don't know if a if Amazon's gonna go quite that far, but I wouldn't doubt it. Maybe the next time this rolls around or sometime in the future that they're willing to say, Nope, enough is enough and we're gonna make you fix it this time.
We'll have to see what happens. But, you know, hope springs eternal. Right?
We've got a story that we wanted to take a closer look at because quite honestly, I haven't gotten off my soapbox yet. Micron is leaving the consumer memory market. That would be their crucial brand.
Now, you're probably thinking to yourself, but Tom k Crucial is one of the biggest memory sellers out there. Why are they doing that? Oh, it's because they've decided to focus on high bandwidth memory for AI data centers.
The company is gonna continue to sell consumer products until February of next year, 2026, probably because that's the stock that they have built up. And you may recall in the news over the last couple of weeks that you've heard that there is a global RAM shortage. High bandwidth memory sales are growing super fast, and that means that AI focused memory is more profitable than consumer products.
Hence Micron deciding that now's the time to exit stage. Right. Al, I'm gonna let you start off on this while I put an extra level on my soapbox.
Do you think that this is a good move for Micron? Good for micron? Undoubtedly, they're doing this because they get more money per gigabyte for, or more money per wafer producing high bandwidth memory than they do producing consumer wrap.
Uh, bear in mind that the same foundry that makes the this ram also makes SSDs. Mm-hmm. Now, crucial SSDs also gonna disappear to make more high bandwidth memory.
Uh, it's absolutely good for, for, uh, micron, but for consumers. Yeah. I'm already hearing stories even in, in the Discord servers that I'm on that are completely unrelated to, to computers and ice.
Hey, I'm hearing stories of people basically making decisions not to buy new computers 'cause RAM costs so much and they simply can't afford to buy enough RAM to make the upgrade worthwhile. Uh, this is something that we're seeing from essentially that massive demand for AI resources. It's taking all of the oxygen outta the industry, and it's now affecting consumers as well as professional organizations.
Uh, when can we see an end to this, this tightness that we're seeing in, in the RAM market? Well, there need to be new foundries for building ram, or there needs to be a decrease in the demand for high bandwidth memory. Um, I don't see new foundries coming online fast.
They take quite a while to build. So Foundry capacity is definitely a, a limited resource. Uh, hopefully there's some of those foundries being built in the US being that will come online not in the next couple of years.
Uh, so yeah, this, this, uh, shortage of server ram and then the flow on will be SSDs is, is gonna be with us. It's gonna to have some impact on us as long as AI is soaking up all of the high bandwidth memory resources that are available at a high value. Um, Tom, have you got that second box on your soapbox?
So, uh, you can take a whole other tack on this. Yeah. This is the turning into a CrossFit soapbox right now.
Uh, I think this is actually a terrible decision by Byron and they're not gonna know it for another two quarters, so that's might as well be in the next century as far as they're concerned. Um, I think about it like this, uh, there's this influencer culture out there, right? Um, obviously we're influencers in the tech space and, and that's why we have this, uh, podcast.
But I want to think about the people who do like the influencer thing, where like they, they order a bunch of like cheap clothes from Amazon and then they try 'em on, right? You've seen these halls, right, where it's Temu or Sheen or Amazon or, or whomever. And a lot of times what happens is when the influencer starts out, they're buying the affordable stuff, right?
You know, this is a $3 top, these are $5 shoes and whatever, and they get popular because everybody wants to see the cool new looks or whatever. And then they start getting sponsored, and then they start getting brand deals. And the next thing you know, they're not opening $5 shoes, they're opening $500 bags, they're opening thousand dollars coats because the people who sent that to them want to show off for this big audience.
Well, what happens when that audience suddenly thinks, well, these people are not speaking to me anymore. They're chasing the big dollars, they're chasing the clout. I'm not gonna follow them anymore.
This is actually a crisis that's going on in the influencer culture right now because of that very thing. They've gotten too successful. They've, they've tried to get too much money from everybody, and in doing so, they've wrecked the audience that got them where they are.
Do you see the parallels in this story at all? I know you do al I mean, I'm talking to the people at, uh, at Micron right now. Um, do, do you see the parallels in that story?
Lemme give you a hint. I need you to, to close the email chat that you have with your stakeholders for a minute. Your shareholders, they don't matter because in three months you won't matter because once you've sold out of all of the ram that you have in stock for your consumer markets, yes, nobody's building new PCs right now because they can't get ahold of the parts because there's no ram, there's no video cards.
Well, that, that's actually not true. There're starting to become a lot of video cards that are still in stock. They're just too damned expensive.
What's next? Like Al mentioned, maybe the hard drives are next. Who knows?
Maybe monitors are gonna go out, I don't know. But when nobody's building new PCs because they can't afford it, because they can't find the parts, that means that nobody is going to be putting money into your company anymore. Yeah, yeah.
You're gonna be living high off the fat of the land while you can build more HBM and sell it to Nvidia a MD. Qualcomm got news for you guys. Nvidia may be trying to buy as much HBM as they can right now, but do you know what happens when there are only one or two companies in a market?
They can dictate the price. Could you imagine what would happen if Nvidia pulled a Lee a Coca and walked up and said, I will buy Ram for you for a hundred dollars a stick. And you're like, no, HBM costs $500 a stick.
And Nvidia says, no, it costs a hundred dollars a stick because that's all I'm going to buy it for. In case you're curious, that's how Koka ended a uh, UAW strike. He walked in, he said, I have a whole bunch of jobs for people that wanna earn this much money, but I don't have any jobs for people that wanna earn what you're asking.
Nvidia can control your market. Well, who are you gonna fall back on? Oh, that's right.
You can't sell the consumers anymore 'cause you killed off that brand because you turned all of your printing presses into business focused printing presses. Now, the stakeholders and the shareholders are gonna tell you, this is a brilliant move because there's more margin in Ram right up until there's not. What's the old quote about going bankrupt?
It happens slowly and then all at once. Well, what's gonna happen to the demand for HBM? Well, it's gonna grow slowly and then fall off all at once when nobody has a market for these things anymore.
And when nobody suddenly wants to have AI accelerators because they can't figure out what to do with them, then what are you gonna do? Oh, hey, we're bringing the crucial brand back in three or four months when we get the things moved back over to making consumer Ram again. I hope there's still a market for PCs.
I hope the Steam machine and the PlayStation five haven't wrecked everybody's desire to buy a machine now, because I promise you, the people who are doing work who are writing all that code for ai, they're buying laptops that already have RAM integrated into it. They're not buying the Ram individually. You know what's gonna happen?
All the people who are building these PCs to play games are gonna move on and do something else. And then Crucial is not gonna have a market to go back into because the two or three companies that are left speaking to those hobbyists are gonna be selling it for whatever they can. And your big market, your high margin market is gonna go poof there.
I've jumped onto my soapbox. Well, it's always good to have you on your soap soapbox for a little while. What's also always good is having Tick Field Day events to look forward to.
We're gonna take a little break from events over the holiday season. We're gonna return at the end of January. I'm going to be hosting AI infrastructure field day four in, uh, Silicon Valley, January 28th to 30th.
It's looking to be a pretty packed schedule as we've seen on the rundown. AI gets everybody to the, uh, to the, uh, and then of course, I'll be back for Cloud Field day 25 in March 11th and 12th. And there seems to be a month in between.
And it's February. And we have a couple of things that might just turn up on the Tech Field Day website in February. Keep your eyes open for those.
They might be, uh, familiar things coming back again. I think, uh, there should be some really fun stuff in February. We will, of course have a schedule of events right through 2026, uh, for us to have lots of fun at as, as the year progresses on lots of, uh, security events.
I know there's more AI events to come. Uh, so thank you very much for joining us for this episode of the Tech Field Day rundown. It's awesome to have you with us as we run down the news of this week.
Of course, you can catch the new episodes every Wednesday, eyes that a YouTube video or in your favorite podcast application. Make sure to give us a like and, uh, nice review as you are following us there. The rundown is also streamed on text, on tv, because of course, we are part of the RUM group.
And you'll find Tom and myself as well as Stephen Foskett on various of the Futurum Group programs. We will be back next week on Wednesday to talk about the IT news of the week. Well, in fact, we'll be back on Wednesday to talk about the news of the year.
That was Tom and I will wrap up the year with a review of the biggest things in the year. That was until then for myself and for Tom Hollingsworth from all of us here at the tech team, we're wishing you and yours a great day. And This Isn't steady evolution, it's collision.
And what comes next will be defined by how we steer through the impact. Hey everyone, it's Shimmy. Hope you like that little AI video we did there.
Of course, that was a fake of me on the video, but this is the real shimmy right here. And you know, this week's episode is a fun one. I think it's called Shimmy Says the World, according to me, if you've been following what I've been writing and speaking and doing videos about over the last couple weeks, you know, sometimes you get lost in the forest for the trees because I write each piece and I do each segment based upon something I see or something I'm thinking about.
And I I get in on it. But when you step back and look at the bulk of it at the body of it, you see there's a pattern there, right? And, um, today I'm gonna be specifically talking about the last, well, not the last couple, but some of the last articles and segments I've been doing, right?
That dealt around, uh, ai of course, in data centers. And what I saw at AWS reinvent and what I've been hearing and seeing and reading about the VC market and the the economic market in general, and a potential bubble, or at least how AI is driving the economy. E economics here.
And I want to talk a little bit about a crazy how far we've come in robotics and what we're seeing there. And then how do we be responsible? How do we be mindful of all these things to make sure that we, we do it the right way?
And that one day when your children or grandchildren ask, what did you do when all of this was happening? You could answer with a clear conscience that said, I helped and I did the right thing. Because make no mistake, what all of this adds up to me, guys, is we are at the dawn of a new era in so many ways.
You know, I remember when the 20th century turned into the 21st century and I kept asking, when are we gonna stop living off of what we did in the century before? You know? 'cause even the internet was kind of from the nineties, cell phones were from the nineties.
Cloud was a 21st century thing. But really where we are now with AI and robotics, and I think quantum is, is going to define the rest of this century, or at least for the next 30 to 50 years. So, you know, it, it's not good.
What I get excited, it's not just one thing. It's like multiple tectonic plates coming together, causing massive earthquakes, volcanoes, all kinds of disruption. So don't, you know, you're not alone feeling that the ground is shifting under your feet.
It is. That's the kind of thing we're seeing. And that's what Shimmy says.
And this is the world according to me. I wanna start with an article I had written coming out of, uh, some comments by IBM, uh, CEO Arvin, uh, Krishna's comments. And, you know, he, he wasn't afraid to say that the emperor forgot his pants, that in all of this talk about an $8 trillion data center build out and, and all of the great things that can come, he thinks there's like a one to 2% chance that we actually achieve a GI given current levels, um, current technology, that the cost of these data centers, the economics and IBM is a company that knows something about data centers just don't add up.
And unless something fundamentally changes, it's broken. And sooner or later someone's gonna pay the piper for that. Um, we've got it.
We've gotta figure it out. 'cause this is not just being a skeptic or, or pundit. It's, it's arithmetic guys.
And so I think we need to, you know, that's one factoid that we gotta put in our pipe here to smoke. Um, secondly, I was at Vegas last week with 60,000 other people or so for AWS reinvent. And it was painfully clear AI AWS came out of the chute and they wanted you to know one thing, they're big, they're bullish on agentic ai.
It was agentic ai, all agentic AI all the time. At least you would get that from the keynotes. It's when you peeled the back a little bit and went to the sessions when you spoke to people in the hallways, when you spoke on the floor that you saw that this whole AI and this agentic AI thing doesn't live in a vacuum.
It's not just gonna work on, on Nvidia processors and Cuda, right? There's got the, there's the train, there's the inference. There's so many things going on, but it's built on cloud.
It's funny, you didn't hear the word cloud very much as you would think at an AWS conference 'cause they were so busy talking ai. But this whole thing is built on the cloud. It may not all be public cloud, it's hybrid, it's multi it's edge, it's everywhere.
But it's built on cloud. It's built on DevOps. It's built on platforms.
It's built on cloud native. It's built on the building blocks that we've been building our technology on, the infrastructure that we've been building on all along. It sits on top of it.
It doesn't replace it. So I think that's important to remember these, these other communities, these other talents and skill sets will be enhanced by ai, but not replaced by ai. So they're essential.
And we may not mention cloud as much as we can, but you can't take the cloud outta cloud. And, and that's a, a, a point there to say, okay, next, here's a clear sign of the bubble. I read a, I read a, uh, an op-ed over the, over in the New York Times that caused me to write one.
It was about VCs chasing AI startups. They had one VC who was driving a, an entrepreneur to his rock climbing session because that was the only time the entrepreneur had to talk to the vc. It used to be a time where an entrepreneur would, would give their eye teeth or some other body part to have to be able to get a VC's time to sit and pitch them and tell them about their product.
But that's turned on its head. The VCs are chasing the entrepreneurs now trying to give them money, whether it's going to a rock climbing session or another example in the Times article. They're flying entrepreneurs out to Vegas to drive Ferraris, right?
And then while they're driving the Ferraris, or on their way back and forth trying to get 'em to sign a term sheet, they're not doing due diligence. They're not, you know, this is like vibe coding your VC business without testing. It don't make sense.
com bubble. So to me, this screamed like, what the hell's going on? Two one, and I wrote an article about this.
You can find it on, uh, on text Strong, uh, it or text strong ai, excuse me. And, but you know, the, it's one of two things. Either, you know, the old saying of fool in their money is quickly parted or something else is going on here and it, it's something else is going on here.
So, but we've seen how this plays out before, right? And it, and it works, works its way down. And guys, when I wrote this and what I put in there, please go read this article 'cause it was really near and dear to me, guys, I've lived this for 20 years, right?
com bubble. I did companies then I, I saw how it trickled down. And you know what, the VCs are fine.
Their model is, if they get one outta 10 companies that do a 10 Xer or even even a little less than that, they get a few singles and doubles. It's okay if they get a lot of failures. And you know what the founders look, they're playing OPM other people's money, right?
And so if things go south, they'll go found another company. In the meantime, they made a nice salary and then maybe they'll get something salvageable and come out of it. You know, who really gets hurt?
You do. The workers, the workers who get promised stock options and stocks take a flyer that this thing gets a great exit work for a little less work a little harder. It's the workers who get caught.
Yeah, there'll be some of you who are lucky who get the Willy Wonka golden ticket. But you know, those are the minority. Those are the lucky ones.
Not everyone gets the brass ring. So, you know, you look at, uh, Arvin Krishna, and then you look at this VC article, and we may not have an AI tech bubble 'cause AI tech is real, but we may have an AI financial bubble and someone's going to get left holding that bag. The next thing I want to talk to you about is physical AI is some call it, I call it robotics.
There was an article, it wasn't by me, but it was on our tech strong ai, I think it was by John Schwartz about, uh, over in China. They, they had a, uh, demonstration of a couple of their leading robot companies. And you know, here in the US we, we have Boston Scientific, we have figure, and we have the Tesla robots.
China has their whole own robotic economy rocking. And what they showed was absolutely scary legions of robots goosestepping in unison, like a military, you know, it, it was right out of attack of the clones in Star Wars. They had another robot that looked like a T nine at a Terminator.
Man, this guy, you know, and there's no doubt they could break your boats. And, and he looked mean, or it looked mean. Then they had another robot that was a agile enough to like do jujitsu with you.
Man, this isn't that clunky. You know, like we saw at the Russian demo a month or two ago, they marched at a robot who fell flat on its face and they had to pick it up and walk it off the stage like it had too much vodka. No, these were Chinese ninja warriors doing kung fu and stuff.
And, and they did it well, it was absolutely scary, right? The question becomes, what are we using robots for? Are they tomorrow Cyborg warriors?
Are they butlers? Are they manual workers? All of the above.
Look robots paired with AI could be a bigger influence on our lives as humans, on civilization than on how we're using AI to even develop software, which is where the bulk of our kind of attention is right now. But guys, don't sleep on the robot revolution. It's happening.
And it is crazy. So another, you know, a couple weeks ago I was on shimmy sets here, and I, and I talked about tech used to be the good guys, right? We got all of this promise, all this potential.
Are we going to use it to just make a couple of tech bros, couple more zeros at the end of their billions? Are we going to use it for the good of humanity? Right?
And this goes back to what I said in the beginning. When your children and grandchildren ask you, what do you, what did you do when, when things were being formed, when it was still moldable? Did you help or did you just ride that gravy train?
You wanna say, I was responsible. And so I was really happy to see the launch of something called the Resonant Computing Manifesto that really brings this home. We need to be responsible the tech industry.
It's, it's our destiny. It's our, but it's more than our destiny. It's also our heritage, right?
So from the beginning to now to the future, we have an obligation to do the right thing here. Don't let the tech bro sell us out for 16 pieces of silver to, to the government or anyone else. We, we have got it while we can.
Right now is the time to make sure we do this in a meaningful, impactful, responsible way. So, and I, I wrote an article on this also on the manifesto moment, resident computing. So I, you know, please check that out.
So I've been busy, boy, I've been a busy boy. What does this all mean? I think you take all of these pieces together, you start to see the patterns.
There's an emerging view here of a new world, a new era, right? AI is advancing faster than our infrastructure that's gonna be required to power. It is.
We've gotta get that aligned. Cloud DevOps, cloud native platform engineering, agile. All of the ways we've been building software all this time ain't going away.
We gotta double down and use that. Leverage AI with it. VCs here are Overclocking.
If you remember Overclocking CPUs, they're overclocking and overheating the moment, right? John Chamber said it. He doesn't think the AI bubble bursts in 26, but there's gonna be some violent collisions.
There's gonna be some big winners, there's gonna be some big losers. The VCs are okay with that. The founders are okay with that.
You've gotta be okay with that. AI is embodied, embedded, and becoming part of the fabric of everything. We do embrace it.
We don't have the guardrails to do that now. We need things like that resident computing manifesto to make it happen, right? As an industry, the tech industry is facing its biggest sca scaling challenge.
Since the birth of the internet, enterprises are being forced to rethink architecture. Regulators are gonna be scrambling to catch up. They're gonna be three years behind.
And all of us humans, humanity, we need to decide what role we play in a world where intelligence is no longer solely biological. So what does this mean to you? I'll tell you what, if you're a practitioner, a leader, a founder, or in even just an enthusiastic enthusiast watching, here's the deal, guys.
Your skills are more valuable than ever. But you can't sit on them. You gotta advance them.
You gotta incorporate AI into it. You can't sit this one out. If you think you're gonna sit out the AI wave, you're rip Van Weel, and I'll wake you in a hundred years and you're obsolete.
Get curious about constraints. Understand where the boundaries are. Be intentional and responsible and meaningful about the systems you're building and what you're working on.
Because here's the truth, man, the future's not being just handed to us. We're building it in real time, in real time. And the values we embed now will last for decades.
So where does shimming land? We're at a crossroads. We're at the dawn of a new era.
It's a rare, maybe once in a lifetime moment for most of us, not as companies, not as governments, but as builders and as humans, we need to set the right tone for the next half century. It's not about greed. Um, ai, cloud, robotics, the economics.
They're not separate stories or silos. Just like DevOps bust down silos. We've gotta bust down the silos.
This has to all be coming in here. 'cause history, his, as I said before, history is gonna ask a simple question. When the foundations were still wet and the future was malleable, what did you do?
Ask yourself that. What are you doing? My hope in Shimmy's world, according to Shimmy, is that we choose stewardship over speed, clarity over chaos, collaboration over fragmentation.
Because the next era of tech isn't just about innovation. It's about responsibility. And that folks is the world according to Shimmy.
Have a great week. I'll see you next week. Hey everyone.
Did you hear about the latest foundation? No, not another sci-fi book You're watching. Textron Gang.
Hi everyone. Happy Friday. Hey man, I am, I gotta be honest.
Fridays, as we get closer to Christmas and New Year's, they're kind of special 'cause we've got stuff doing all weekend, getting ready for the holidays and enjoying that festive spirit. I hope you're all festive out there. I hope your plans for the holidays are going well.
Um, I, I know mine are, I'm, I'm happy to be home, to tell you the truth. Everything feels like months of traveling. We've got a great gang, a full house here for us today.
Let me introduce you to our amazing gang. We've got my friend Fred Wilmar out in Seattle. We've got Gina Rosenthal, Wiki Wang, Mitch Ashley, John Swartz, John Swartz, the Bard, Mike Ard, and you.
It's truly Allen Shimel. We've got a great gang for us. Mike, I, I said something about a new foundation.
I'm not talking about a new Asimov book or an Apple TV spinoff, but a Linux Foundation Foundation. It, it Is yet yet another foundation from the folks at the Linux Foundation. I've lost track of all the different foundations and I've also lost track of all the different AI projects.
But this one seems to be about, while the AI Agentic Foundation is gonna be home to the MCP protocol, which is being used widely in servers for different use cases, and also something called Goose that Block Built, which is an integration framework for AI agents. And then I think there's also something from Open AI that is, uh, agents MD that you can use to provide a standard interface for accessing code repositories. So Mitch, what's your take on what's going on here?
Because these guys also have the A to A protocol and there's a couple of gateways and it's starting to look a little much like maybe, I don't know, shake and bake. You throw all this stuff in a bag and something good happens. What's going on?
I, I think that's the idea, is not put 'em all into one place and either have them get lost inside the Linux Foundation or get coupled into something else, but give its its own space to develop. And does the world need another foundation? Yeah, I actually think it does another foundation book too in Siri, but also another tech foundation.
So this, this, what what's impressive about A A IF is that it, one is that MCP was donated to it. That is like the most popular, of course, open Standard, if you've heard of one, you've heard of that. And, but there are a lot of other really important contributions.
Um, you mentioned there's something called Agents md. If you're not a developer, you're probably not that familiar with it. What Agents MD is, is actually a markdown document that provides a structured way of how agents are built.
So it gives the structure of the agent the required components, what the inputs and outputs are, um, interfaces for tooling constraints and guardrails, et cetera. So it's kind of like you heard about structured prompts. This is like structured how to build your agent.
Uh, so it's almost like an instruction manual for it. I think that's super helpful. OpenAI gave, gave a number of other things to the foundation.
So you, it, we are in this age of, okay, if we're gonna start doing more agentic type workflows, agentic work, whatever it is that agents are doing, you know, enterprises, all of us are asking, well, what are these things doing? How do I trust them? How do I control 'em?
You know, anybody creates one. What do these things look like? They're gonna be well developed ones, they're gonna be por poorly developed.
So there's a lot of really good reasons why I think A A IF has been set up and kudos to the, uh, links foundation. So I I, I have some views on this because one Might need, Lemme give you SHA steak here. I'm, I'm of a mixed, mixed mind on this.
Part of me says, look, they were donated this MCP, uh, protocol, right? And they had to find a home for it. They probably didn't wanna put it in CNCF.
It really didn't belong there. And do we really need more players in CNCF with over 200 projects there. Now at the same time you, I, I wasn't the a to a, uh, moved over to Linux Foundation too.
Yeah, I thought that this would be in here. Yeah, I I thought it might be too. Maybe those things will move.
I don't know. I I think it has to be in there. I I felt like, you know, this was the first time where they had a, they had an open source protocol or an open source project, and they, they literally, you know, they created a whole foundation around it and threw everything else in.
My, my issue is because autonomous AI is going to be so intrinsic in every single thing that we do, how do you separate out the autonomous AI work being done in CNCF projects, the autonomous AI being done in mainframe projects, the autonomous AI being done on the Linux kernel itself and everything else that the Linux Foundation does to try to say that we're going to keep all of this autonomous AI stuff in this Foundation nation, I think we're kidding ourselves. It's gonna leak into everything and then it's gonna get messy. Well, does it belong in in this one?
Why is it in that one? And you know, and there'll be, there'll be political fights over at Turf Wars. Um, and then if, if the MCP is really the centerpiece of this whole thing, I, I got news for look at, went out there.
It's, it's a year old and it became the defacto standard. Doesn't mean it's gonna be the standard next year. We're, we're liable to have something that is replaces it or updates it or what have you.
Or maybe it is a to a or something else. Um, I, you know, I, I do think, look, we are in the foundation era, right? Open source can't be ruled by one big brother per project.
You, it's good to have it in a, a not-for-profit foundation where you could have cooperation among competing companies. But, you know, I I I think this one's gonna have to be handled delicately. So let me, let me jump in because I don't want, I don't wanna take the microphone from everybody else, but I will for a little bit.
This is like CNCF forming. The CNCF, with the exception of it has the characteristic you're talking about Cloud native isn't go, doesn't go across everything like agentic AI does. So I think that's inevitable that whatever you do, Alan, is, if you didn't set this up, it's gonna be that way anyway.
What are the things that you want to have common and done more consistently across the industry? And given the list of vendors that have signed up for this, it's pretty massive. Uh, very extensive.
You know, it could either be a big political fight or it could be really helpful, uh, to the industry. So I think, I think the goal is to make this successful, and if it is, it will deliver about a lot of value. So I'll be quiet now.
I'll let everybody else talk. I think my concern is though, to Alan's point, is that if you look at the CNCF, there's all these projects, right? And the CNCN landscape is unreadable.
No one knows what all these things do. And all these projects have a life of their own and they never get folded into any other project. And then the whole thing becomes unwieldy.
So is anybody concerned that this is gonna happen again in the age of ai? I don't know. Fred, what do you think?
Well, I think there's a couple of, it's a good, you know, how do we manage projects that have been officially open source is definitely one problem. But I think there's a second problem. There isn't a standard today, and this sort of codifies a place where the Frontier Labs can actually do the work and be accountable for that work in an open source way, right?
So you have the ability to understand, hey, I have an MCP server standard that's required, uh, for protocol behaviors. You, you have some other things that go with that instructions that are required in order for me to build an agent. And the agent framework, right?
So this is, if anyone wants to walk into how do I do this as a business and now have a set of, uh, of, of conscripts in this project that allows 'em to do that. And I think that how that, how that materializes into other parts of the business of that I, that's to be seen. And I agree, a a two a probably, you know, belongs in here, but I would say it's the first consorted effort to, to get the technology into one place where people can use and operate that, where it's not, you know, at the behest of whatever technology organization is running it.
So there some standards are good and a technical standard with open source projects is a, is a terrific way to allow people to, you know, get their feet into something they can measure between businesses. I think too, like what is the commercial? Is there a commercial, um, undertaking that is gonna be the counterpart to the open source?
And right now, I don't think there's anything 'cause everybody's trying to learn everything. So I think it's pretty smart to put it all in one place, like Fred was saying, because if you don't, then someone's gonna come along and from a commercial perspective and see how to do it, and that's gonna be the next big thing. And that becomes the standard, but then it's locked up in private.
Yeah. Um, I also agree with, put everything in one place and also get all those supports from the most significant players in this ecosystem, right? You can see that he, historically, the biggest technology revolutions were never, um, about products, right?
It's about the shared standard infrastructures. It's kind of like internet has a TCP IP or like smartphones has like os or like Android right? For um, agents.
Uh, it's, it's, it's about the point. Like no one can avoid and we do need to have a standard way to regulate it. So, uh, so that in the future, the corporate adoption can make it better.
Yeah, I I I'll say this though too, at, at some level, this is yet another milestone in autonomous ai agent ai, uh, you know, move to, to not relevancy, but to dominance, to, to visibility to the top of the heat. The mat maturation is part of the, the maturation. But you know, it's, it's a thing when the Linux Foundation creates a foundation just for you.
That's a, that's a statement. It's a big deal. So I am concerned about one thing, and we've seen this in the CNCF, right?
I can't help but feel like there's an artificial cap on innovation when these projects go into the foundations because suddenly the vendors are there. Well, you know, we want this in the project, but not that because we monetize this as part of our quote unquote support service for that thing. And, you know, it winds up ultimately being a force for stagnation.
So I'm hoping, you know, it's still early days here, but I'm hoping this doesn't play out with MCP, which is kind of critical in my mind. Well, it's politics, but, and, and that's, you know, you get into these foundations and and that's part of it is the politics Yeah. Of a, of a multiparty group.
There are always tinge. These, these foundations and projects always seem to be tinged with politics. Oh, cannot hear.
Especially based on the players involved, right. And what they, the standards they set or where we go. But I, yeah, it's, it's interesting.
This is kind of a transitional transformative moment for genic ai, which is not, we're gonna talk about this later, but it hasn't gained traction within companies as quickly as we had thought, or we were told it was gonna happen by the vendors. Well, I, I think this actually is the, the wind in the sails here, right? So if you're not sure what to standardize on, right?
Having this as a defacto standard, uh, by proxy right, is a terrific way to allow organizations to be able to adopt it. Otherwise, you know, I think on the innovation front, Mike, I love it. The, the, let's make sure we don't stifle innovation here.
I think we're not gonna stifle it yet. I think what we've done is we've said, okay, look, we're putting a stick in the sand. These are required.
There's probably a lot more innovation and every company has the opportunity in this day and age, right? There's the saying that there's gonna be more millionaires made in the next three years over ai, you know, as opposed to the 20 years of the internet, right? Is a, is a statement that's been made.
So I think innovation's probably still gonna flourish. But the challenge is, is if we look at that rate of adoption, which we're gonna talk about, you know, that's, that's the worry. If we don't have the standards here, then, then we're at very worst not going to be able to adopt the things we have now.
Yeah. I mean, if I took away their phrase open source from this thing, and I said, you know, six vendors are gonna get together and form a governing committee to decide what thing is gonna be the standard. Everybody would howl.
So sounds Like the Java Foundation, Well, at least they're all invested In each other. That's good. But like people See, I'm sorry, go ahead.
Wy. Yeah. In reality, right?
MCP is one of the most acceptable standard way to do things, right? No matter is like get into the open source or like nonprofit or something. People support MCP in the best way.
So I think it's easier to use MCP to standard to make it standard. And what will happen is the same as is the politics, right? So you'll have all these vendors in there and they'll start arguing that they need this and that, and when they're told no, they'll go and build a version of it of their own and they'll come up with something new and other people will come.
So that, that's kind of where traditionally this has happened and what ends up being the standard is often the result of politics. Yeah. And to your point about that, you know, Alan said CPS a year old.
Well, from what I can see, MCP doesn't look anything like it did a year ago. Today it's very different and it seems to be updated every quarter. So a year from now, I'm not sure what we're calling MCP, we'll be the same MCP that we have today.
And I'm not even sure that we backwards compatible, but who knows? If you wanna see politics go to a standard body that's real politics. These open source projects are babies compared to that.
All right. Hey, we're about outta time for this segment. We've got a lot more to talk about and, and, uh, you know, do you trust your agent, secret agents secret?
Maybe not. Textron Gang will be right back. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back and we're talking about AI agents some more.
There was an AI conference this week in New York that I was at and everybody was talking about, well, AI agents, including a fellow from ntu, got up and told everybody that, uh, from what they've seen so far, that maybe you should not give any data that you care about to an AI agent because, well, a hundred percent of the models and agents that they tested were all hacked. So it's still early days. And John has a couple stories talking about the fact that, well, AI agent is a lot of enthusiasm for it, but adoption remains relatively low.
That may not come as a surprise, but Wiki, I'm starting to feel like maybe people are cutting onto this whole AI thing and that they're, you know, going slow because they're not wholly confident in what's gonna happen. Yeah. Actually recently, we just had some discussion in our AI infrastructure, uh, gathering, right?
Uh, we talk about this AI agent, why the adoption is, is so low at this moment, right? Um, there are three things currently happening. Um, number one is people are not very sure, like, uh, if, if they adopt AI agent, right?
Is, does the AI agent can keep consistently perform what they try to do. And then second one is, uh, there, uh, is related to identity and, uh, um, um, authorization concern, uh, 'cause currently majority of the, uh, AI agent, if you try to create one, uh, it will be based on the person's identity who created it. So, but, um, after a while, you see the, when AI agents start to work with each other, it's a little bit hard to identify, oh, if, if this is a personal, uh, behavior or like a, uh, it's a AI agent behavior.
So there are a lot of, uh, new startups try to address this issue. You can see also, uh, ServiceNow also acquired a, a cybersecurity company to address identity issues so they can adopt ai, AI agent more easily. Right?
Um, and then also there's some like observability, observability issues, uh, like lot of, lot of work, yeah. Agent do still in the black box, even though people keep the logs, but it's still hard to predict where's the fault, where something wrong. So that, I guess that's the three main reason it's a little bit hard to adopt AI agent in the corporation environment.
Plus, related to our, uh, first topic currently, we don't have a good standard and the regulation is on the way. So everybody's trying to figure out, oh, if I do this, is it my responsibility? If if something happening and what's the consequence?
No one know exactly. Alan, this reminds me of your, the cloud's not secure. We can't use it.
An analogy kind of, we're at that phase, right? Yeah. So I'm glad to see all those, uh, new things happening, like the, uh, US National Institute of Standard and Technology that try to build up the, uh, uh, securing, uh, artificial intelligence agent dis discussion, right?
And also for, uh, the, also in the, like hat Europe 2025, uh, O-W-A-S-P, they also published the guidance, which gave people a little bit lights, but this is still long way to go. Yeah. Hey, friend.
Um, one of the things that struck me about the OASP is that a lot of these hacks for AI agents are pretty trivial stuff. I mean, it doesn't look like it's very hard. And, you know, it seems to me that bad guys can just kind of create a prompt injection and take over an AI agent, and they're off to the races in split seconds.
Uh, there's a lot of, just the same as you would think about, uh, imagine that we didn't have any, uh, armor for our identities as humans, and now you have non-human identities that don't understand the context of why armor would matter, right? Not, not relevant. I just now have a notion of agents md and the way that my, the way that my agent should operate, let alone what other influences can change that.
So CEEs are on the table, uh, you know, the, the human boundary trust exploitation on the table, uh, supply chain will realize there's, you know, there's more than 20,000 MCP servers out there. So, you know, direct compromise, indirect compromise adjacency, supply chains, like memory and context poisoning. Uh, there's tons of things available.
And part of what wiki's referencing is really where we think about, you know, today we have this notion, uh, we talk about this thing called zero trust. And, you know, we talk about this other thing called identity and access management, where we have authorization and authentication that is in the just infant stages here with this. So even with those things, when we've delegated our credentials to an agent, that is also non-deterministic outcomes, right?
It's an absolute recipe for that. So there's a lot of people talking about it, for sure, and it is a widely, uh, utilized vehicle. If you'll look at, uh, you know, like N-C-P-S-O has, you know, probably around 20,000 servers on it, and, uh, your guess is as good as mine, Mike, how many of those are real valid, uh, servers that are available for you that have been trusted, let alone what they do?
So, uh, completely valid concerns on that. And I think that's part of why some of the relation on ways to do some of the CTF work around this becomes very important. Mm-hmm.
You know, Alan, I would love to get your thoughts on one of the things that the fellow from NIST said was that in effect, there's no perimeter anymore to defend then. So, Oh, there hasn't been a perimeter since the Jericho Foundation went back in the box. But let, let me give you Shimmy's take on this.
Just, just as I, Mitch mentioned in the last segment, this is a sign of maturity. It's a sign of maturity. When you got all of this news about securing AI agents, this is like no one, no one, no one ever wrote about max security when it only had 3% of the laptop market, right?
Max was in vulnerable because no one gave a crap. And it was only, they weren't a target. They weren't a target like Windows.
Yeah. Right. Now, Mac got 20% of the, of the laptop of the PC market.
Well, all of a sudden, there's some bugs in that Mac os. The fact that this many people are, are writing about it is a sign of the success of AgTech ai, right? Secondly, a lifetime of learning in the security company, these guys could stamp their feet, hold their breath, and turn blue in the face.
No one's stopping trains left the station, either get on the moving train or get left behind. So these are, these are, as we say in Vegas, a fine beginning, but you know, it's not gonna stop the, the forward progress of ag agentic ai. And the problem is it's moving so fast that many of these things are kind of obsolete by the time we, we, you know, they decide on them and we report on them.
Mitch, to your comment about the cloud, right? We shouldn't use the cloud because of security. So, Although I, I wanna ask, but still, there might be some folks at ServiceNow in Salesforce and Adobe and whoever else is carting out these genetic ai, uh, projects with a little bit of concern.
When I look at the 6% figure, the 6% figure that Harvard Business Review came to the conclusion that they found that only 6% of companies fully trust the agents to autonomously ha autonomously handle their core business function. So there is widespread enthusiasm, Absolutely, but Judge, here's, here's The, but the confidence is scarce ality, It's the hippo. So that, that's one of the underlying hypocrisies in the whole AI thing.
90% of developers use AI to develop code. 40% of them don't trust it. 65% of them think it introduces instability, but still 90% of them use it.
6% of the people using ag agentic AI don't trust it. Think it might be not so good. Does it stop them from using it?
That that's the, at the, at the nitty gritty core of the equation? Yeah, that's what we're dealing was it Doesn't stop. I think it slows, I think it slows the adoption.
That's, I guess that's was my, is my point, is that we anointed 2025 as a year of genic ai, yet there are a lot of concerns that are cropping up. And you see them from studies, you see them from real life examples. So I'm just saying it, maybe we're, we're just maybe being more cautious, But you also see studies how many, how many enterprises have, whether they trust them or not, are using ag agentic ai.
How many agents are out there? That would be the question, right? Because I think number one studies are, are they're just numbers.
And anybody can make a number say anything they wanted to do by, by how they represent the data. Number one, I think what's happened, yeah, maybe 90% of developers use AI for whatever, but when it got back to operations, and we're the ones that are responsible for that data, and to make sure that things didn't get stunk, get stolen, that we can recover it, that it, we don't break any regulatory rules, all the rest of it, that's where it's slowing down. Yeah, it's cool.
Yeah, it can make a do really cool stuff, but we wanna do it within a box that is protecting the organization and not just saying, we're doing ai. It's amazing. So I don't believe the numbers for one thing.
Uh, it, if you dive into the surveys, some of these surveys are kind of questionable. Yeah. So I mean, yeah, there are, there are some Lies, damn lies and metrics I know Was the, the, that was the worst or worst.
But I mean, I, I, I also wonder though, like when you press companies to try to get examples of like significant use, it's usually at the very, very low level for now. But again, maybe that's just the process and they will accelerate and they will graduate the type of eases I completely, go ahead. Go Alina, please.
Just really quick, I just wrote a blog post about this. People are starting now to lay off and let go some of their low level, you know, like, like L one support, these kind of things, and what do we get? We get these stupid agent box that can't tell us a answer, a question, and can't do anything.
Even an L one could do Madden. So That's mad maddening. I hate it.
Sorry. No, that's okay. I think in addition to that, and I, I agree, I think we've all had some occurrences where that, that that will naturally snap back, I think.
But, uh, the customer interaction with, with AI is a very defined thing that OpenAI thinks they're gonna own. But anyway, the, the, the behavior of utilizing, implementing and then fully adopting, I think is an enterprise. I mean, it's a very long curve as it is.
And if we see right now that, you know, 86% of those organizations pulled know that they're gonna make future investments and so on. I mean, they can't do that without standards. That's now something they have.
And now we can start going through an adoption process. But, you know, whether or not it's the core functionality of the business, I mean, I think we treat everything with the same cake gloves of the core function of the business to hand over in any way, shape, or form. But I, I, I see rapid adoption in a lot of the areas that are, you know, the workflows and the behaviors, writing code, testing, validating code, validating vulnerabilities, uh, you know, there's a, a massive amount of multiplicative, uh, benefit from being able to do that with agents.
Uh, there's a, a guy that, uh, used to, used to work for me that operates like 10 engineers now, and I mean 10, right? With the number of agents and tasks that he is able to perform at the same time by coordination. And when we think about the effect of what it means to be able to do massively more work for folks that are capable of doing it, it only can have that type of effect down the road.
So it's exciting and it's early days. You guys are all, I think, a hundred percent on point. We should question all of the process to get there, but next year is going to be that year, next year.
Yeah. I, I guess that's why they start the foundation now, In part, you know, at every one of these tech vendor conferences, whether it's Reinvent or Google's or who you, you name it, they spend an inordinate amount of time with two, three customers essentially doing a use case of what they're doing with agents. And of course, you know, they, they're positive stories.
I'm not gonna put the bad ones up there, but the vendors know the industry needs some examples, successes to build on, and we, we will see more and more of that. Yeah, I think, you know, to Fred's point, there's a lot of people who have awesome skills that to do that, but I think that there're a small percentage of the overall population, and it's gonna take a while for the mere mortals of the world to get the cognitive capabilities to manage 20 agents to run a process. So that's just gonna take time.
Yeah. I I also feel like there's a huge market about this agent, right? Even though the adoption is low, you can see there are a lot of companies, they have huge needs, but they don't have enough budget.
That's where the agent will play the role. What's a block here? Currently, the regulation compliance and standards are not clear, right?
So I'm not sure, I'm not so sure how cheap the agent is either if I can have to keep paying for all the tokens to use it. But we'll see. But I think also, Mike, to your, your statement, I think there's a lot of people that are stuck in jobs where they could do a lot more, but they're, what they are actually able to do is just burying what they're cognitively capable of.
So if it's, if it's this very low level stuff, if, if people can wrap their heads around that and, and elevate people to the point of, okay, this boring bit we've automated, now you use that to do the things you've always wanted to do, then that could be pretty amazing. Fair Enough. I just want an agent that says, I know you do this a lot, a lot of this is action.
Here you go. I've, I've automated it for you. Thank God, thank you very much.
That's behavior number one. And, and I would love that. But if I ask you to do the same thing and then tomorrow it will do it differently.
So Yeah, it is a little bit of a memory problem, doesn't it? Persistent agents. All right, let, let's take a break here.
We'll come back. We've got our C blocks still to go a little bit off of the ai. Well, it's still ai.
What can I tell you? It's Techron gang. We'll be right back.
Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, everybody, we're back. And, and write this state down, because I'm about to say something that I rarely say, but it looks like Alan was right.
And we are seeing this innovation in the AI space with data centers and energy and consumption, and we've seen some stuff from an outfit called Palantir that's pretty famous in Washington circles, at least for building out AI applications. And they have a chain os that's gonna help us maybe consume power more efficiently in our new modern AI data centers. Gina, what do you think?
Well, let me tell you what it is first. So volunteer is partnering with Nvidia and CenterPoint Energy, which is really as a Texas resident kind of gives me a pause for concern. But, um, they're to build the, to, to use something called chain reaction, which is, uh, I guess a service forum, um, from Palantir to, I'm just gonna read what it does.
It will accelerate Nvidia AI infrastructure in installations across the US by streamlining the complexity of managing the complex supply chains, supporting what power is needed for the gigawatt ai, um, data centers. Um, and the, the thing it will do, hopefully is look at where the, the blocks are in power distribution, construction, all the, all the, uh, the, the, the legal things that, that the municipalities have and data center operations. So this reminds me of a, and I couldn't find it.
Um, of course I wrote a whole bunch about it, and it was probably in a chat about something. The US government just had an, uh, uh, the president signed an, uh, executive order to get this done, to get the data centers built to, to do better with data center. And it's all resting within the Department of Energy.
And of course, the Department of Energy is all run by people who are oil and gas. So my, I'm really concerned, like as, as just a Texas resident, um, who their, uh, center point is in the Houston Cold Coast area, and they have been horrendous, just like the entire Texas grid is at keeping power on during, um, emergencies. I'm in Austin, and I lived through the ice storm ice apocalypse a few years ago, and it's crazy.
So the last hurricane, big hurricane, um, they had in Houston, they lost power for weeks, some places, um, they just weren't able to get it back up. So this all is not, does not seem to be about that, though. It doesn't seem to be about keeping the local, um, grids, firming them up, modernizing them, all.
The rest of it, it seems to be about having a separate, um, roadmap to building the AI data centers. And so I a little concerned about that because it doesn't mention anything about heating, it doesn't mention anything about cooling, the amount of things that'll be pulled away from the resources that'll be pulled away from local, um, in local areas. It's just about building AI data centers, which are important, and we all want our agents to happen.
We want to move forward into the next century. I'm not sure this is the same as, uh, building the atom bomb, which is what it's been compared to at Palantir levels and government levels. Um, and I'm not sure if you look at all of the information, which is very kind of scarce actually about what they're planning to do.
Um, it's, it, it's not very, and it's not about anything but building out for AI data centers. So I was probably the wrong one to throw this to because I have a totally, I do not have a, I do not have a, um, I don't have really a technical response for this. I know we need the power.
I know we need everything we talk about, but it's being put, all of these data centers are being put in areas that are either very, very poor or very, very remote that in Texas do not have the infrastructure for this, that it will have to be, will there a second, infrastructure will have to be built that all of the towns and cities that these are affecting are being promised the moon with jobs. I hear one more meta commercial about how many jobs these data centers are going to bring. I might shoot my radio, so it's not going to do it.
It's, it's dangerous to our water. It's not supporting anything local as far as power grid, which in Texas is a really, really big problem. And I don't like it.
So I think we should bring out into the open, like, what is this doing? How is this, I, you know, we know there's all sorts of things that AI is impacting, but, and we want to, we don't want to stop ai. We want to build the data centers.
We want to have the things work, but are we doing this in a way that is going to disenfranchise the people that are most disenfranchised now because they're not being on the level and the marketing is so slick to make it seem like this is a wonderful thing. And I said, Tina, you're in good company. I don't understand it either.
I, I read it over. I'm like, what exactly is this? Well, let, let me see if I could, let me see if I could illuminate it for you, Mitch and Gina, please do.
Please. This is Peter Thiel who owns Palantir preaching the gospel of whatever frigging gospel he is been preaching lately to ride the, the teat of the government's dollars as we bite around the edges trying to squeeze out one or 2% more efficiency by burning our fossil fuels to, to power these AI factories because they don't wanna acknowledge that solar and wind and renewable energy is the way to go, and that these aged and that these data centers are gonna be manned by robots and they're not really gonna have a lot of jobs. So if you want the truth, that's the truth.
Gina, you weren't strong enough in saying what it is, huh? Thank you. You know, I'm glad, glad you, I'm glad you pointed out your, your, your, I'll leave it right there.
Yeah, because this is like, this is something that's happening in community after community across the country is Ohio, Pennsylvania, Texas, what, what have you. I mean, it's the same old story and I think Al nailed it. This is just a very cynical approach.
Of course it is. I, it seems, seems to me we need another foundation here to solve this one, need a revolution. Field foundation will take care of everything.
Well, but from like a in investment perspective, right? Currently we do need some sort of new infrastructure to solve the problem, which, um, plan plant, uh, planter solving, right? We need the full, uh, whole set, um, on the, to, to make things quicker, to solve the bottom neck problem.
It's no longer the algorithm, it's power land, transformers, chips, construction materials, or like great inter in interconnections. I think they're doing, uh, the right product for the, for the market. But you can see like different companies, they react differently.
Try, try to address this needs, right? One is like this way they build up the OS to get a, like a new different, um, physical backbone on the ai, uh, AI stage. And you can also see company like x, they try to go to space, make a new different market to address this problem.
Everything, uh, every, everybody react differently, which is very interesting to see. Yeah. So, so lemme throw, lemme throw a couple things on here 'cause uh, it's a contrarian perspective from both what, what both you and Alan shared.
So, uh, the first thing is, is, uh, I, I want to make sure everybody's super clear that we did not build the power infrastructure for today's usage alone today, right now, right? As a person that has spent a lot of time on operational technology and security of such things in planes, trains, automobiles, cars, ships, all the things, uh, it is currently not built for what we do. The second part of that is we talk about the resiliency requirements of what power is now, let alone what power needs to be in the future.
It's not optimized at all. If you look at the amount of electricity and power loss in major cities, 40 to 60% of that, you look at fifth wall statistics is caused by old buildings, old lighting, old electronic infrastructure that is not managed. And it is just electronic loss.
So when we think about resiliency of the future and the optimization efficiency requirements, it only makes sense to do that. Does a a rising tide raise all boats? We would like to think it would, right?
And, and part of that is a requirement to do such a thing. The US Navy signed a thing wither in the same way to have react to some of the, the react to some of the ship Os for them to build the supply chain parts of that. 5 trillion.
So doing that effectively, efficiently with operational, uh, crispness is what builds the resiliency we need for the future. I don't know whether or not Palantir's gonna solve all those problems, but I guarantee you it's a problem that needs to be solved. I agree with that.
I don't disagree with that at all. But what I disagree with is, number one, the marketing for this solution. 'cause the places that I found the most information, um, we're on the finance pages.
So you're absolutely right. There's obviously a huge, um, a huge, um, market for the transfer of energy, which of course, Texas is not part of that market, which is interesting why they put CenterPoint as their main partners is what I'm trying to say, right? So, um, but yeah, I mean the en the energy problem, uh, all of us know that.
All of us know that, especially if you live in a place where we're not on that grid. Everybody I know has a generator. Everybody I know has portable backups.
Everybody I know. I mean, like when you go for a week in Texas dealing with an ice and snowstorm with no electricity, it gets pretty hairy. Like really, really quick.
It was deadly. So, absolutely. And, and that's just, that's just like one place.
This is happening all over. So I agree with you, and that's kind of my point, our entire grid is, it needs to be updated, things need to be up updated. You need, um, all of the municipalities need something.
I don't know if, and Palantir os is like, there's, there's no competition to it. That's the other thing. And that's the only thing that's being bought.
Hang on. So, so, so why aren't we fixing the entire grid to also provide, to make sure as we fix the entire grid to provide that, make sure that it can provide the excess for what we can see, plus what we will see 20 years, 30 years, 40 years down the road. That's not what's happening.
They're concentrating on building AI data centers out. That's what they're working on. That's what this is for.
And that's not okay. It means Everything. But if that's the engine that pulls the train, that does improve the whole thing, that's not a bad thing.
My my point though is, Gina, what you're describing, Fred, what you're describing is not gonna be solved by a smarter os helping us try to manage what is an inadequate system, right? That was the whole point I thought under the last administration, this whole infrastructure package, where we're actually going to address the fundamental issue, which is we don't have the right infrastructure, right? You could, you could marginally improve, you know what, what, what we is a generation or two old right now, or you could, you know, it reminds me when, when, when cell service first came out, right?
And internet access here in the us we had pot slides, right? And once a matter with a plaino telephone service, right? Where like places like, you know, the tigers in, uh, in Asia and Korea and Singapore and some of these places, they didn't have that existing infrastructure that they tried to e every last dime out of.
They went and built fresh and new. So broadband was much easier to deliver there. Meaningful broadband, not, not DSL and stuff like that.
And we, we almost need that kind of effort, I think on our energy grid where we, it, it's not just incrementally squeezing another percent or three outta what we have. We, we need a fundamental infrastructure built here for a gener for the next generation, not last generation, not this generation for the next generation of power consumption. I agree With that.
I'm a stupid question friend. Why don't we just build a grid for the AI data centers and let them have their own grid? That's what they're doing.
Uh, well, that it's starting this way. But I mean, I I would also caution there too, right? So when the internet was invented, right?
It started off in very isolated points, the way that organizations like IBM and, uh, and, and some of the other bigger companies that drove both adoption of servers and infrastructure and connections. When I ran a data center at IBM, right? I would be out at every Sears store in Washington, New Jersey, New York, all of the things ran through those transits.
And those transits were not owned by the federal government, right? They were owned by an organization that invested in the outcome. And Palantir is no different whether or not they support the infrastructure for building these data centers, right?
The same thing. A rising tide, uh, raises all boats. What happens is democratization of what happens to, you know, the access to those things.
And I fully agree with you that that's exactly what should happen. And super sensitive to the fact that you also went through something very specific in a place that is the origin of energy, right? Uh, especially if you watch Landman.
Uh, so when you think I Love Landman, It's great. Uh, the, the, the biggest challenge I think is, is what is the rate of adoption? Let's, let's let, let's let them get a prototype out, right?
Let's get a prototype out and see what that looks like and see what can be adopted there. But I think the hard part is if, if they're going to build a net new grid, you can't just start off with that intent, right? We would all agree that if you started off to build an entirely new national grid, you'd probably fail in today's, what?
That's too much. And it's also too much money. And so the way the grid works today, right?
May not be the way the grid needs to work in the future, right? So today, it's not a mesh, right? It's, it's kind of a mesh, but controls flow down in this particular case, maybe they're all adjacencies in the same way we talk about MCP servers, maybe.
I don't know, Fred, I I think that's a great way to end this. You brought some reason to the chaos here. Thank you for that.
But guys, we're outta time. I know we can talk about this stuff for days, but we, we can't, um, we all got work to do, including you. But hey, what a great way to end the week here on this Friday.
As usual, we have techstrong TV immediately following this. You could check it out. Or if you're watching this on demand, maybe on the OTT app on a big TV or wherever you're watching it.
Thank you very much. Stay tuned for Textron TV gang. Thank you.
It's, you've been great today. We'll be back Monday with Fresh Textron Gang. In the meantime, though, have a great weekend.
Get your shopping done and enjoy. This is Alan Shimel, we're out. Hey everyone.
Welcome back here to another Text Drunk TV interview. My guest for this segment is Dean Hickman Smith. Dean is the CRO Chief Revenue Officer over at Testlio.
And let's welcome him. Hey, Dean, welcome to Text Drug tv. It's great to have you on here, Alan, it's a pleasure.
Thanks for having me. And, uh, looking forward to the conversation. Absolutely.
So Dean, you know, we were talking off camera, people wanna know who they're talking to and you know, what cred they have and so forth. Give, you know, this isn't your first stop on the, on the railroad. Give people a sense of, you know, what your, what your trip has been like.
Yeah, my trip has been very interesting, Alan. Thank you. Um, I guess I've had many stops on the, on the railroad, as you say.
Mm-hmm. Uh, I came from the uk from the old country, from the old south, from London, Uhhuh landed, uh, landed on these Fair Shores about 20 years ago. And, uh, that's when my journey in the, in the tech world, you know, really started, started off life in the military, um, got into tech, and I've loved the journey ever since.
It's been a fascinating one. I came to America with a company called NetScreen back in around 2000. Sure I remember well.
And, uh, yeah, we were quite absolutely Juniper. You know, it's good to be lucky sometimes. And you, you, you arrive with an amazing team of people doing something incredible.
And, um, that went really, really well. And, uh, then we were acquired by, you know, Juniper Networks, and I was the VP of emerging technology at Juniper Networks for a while, which, uh, was a much more technical role, introducing new products to the world. And it gave me my first real insight into, you know, the wave that it was back then, which was, um, uh, essentially the emerging cloud, um mm-hmm.
Service providers that were coming. So we were providing, uh, deep inspection, security technology, very, very deep in the weed stuff. But, uh, that went really well.
And then I was at Proofpoint for a good while, and we took that one from, uh, you know, small to familiar with that, to an IPO. So Proofpoint, we did a lot of messaging security, so I've seen yes, network security, I've seen messaging, security. And then, um, I got into identity, did a couple of identity companies, got into the biometric space and, uh, and that, that actually then introduced me to a company called Hacker One.
So we did, uh, sure. Crowd crowdsourced ethical hacking, uh, that was at big scale Million, million plus people in the community. And I learned all about this kind of crowdsourcing space.
So I guess what I'm saying, Alan, is that my journey has actually ultimately prepared me for life at telio because each of those different things that I've learned, you know, new emerging technology, different types of security technology, different types of experiences, and also that combination with the crowd has equipped me well to, uh, to feel very comfortable in my, in my slippers here at Telio and at Telio. I am, I'm leading our global expansion. It's an exciting time to be here.
So we're in growth mode, scale up, and, uh, there's a big boost from this whole AI thing that's happening right now. Going to want to hear about that. You know, Dean, I, I, look I remember net screen.
I, I, I've done four or five venture startups myself over the years, and I've in security a lot for about 25 years plus. Um, I do remember net screen, wasn't it? The we brothers, right?
We the founders. Ken. Ken, and, Yes, exactly.
And, um, they, uh, they went off, uh, ultimately now they're at, uh, Fortinet. Kenzie, yes, Yes. They started Fortinet after net screen.
They did pretty well for themselves. I got to work with, but I got to work with, sorry, not, not only them, but also the, you know, the near who went off and Lee Clare went off to go and, uh, to pao, Palo Alto Networks. And yeah, it was a cast of characters doing amazing things at that time.
And I, I, It was, it was, it was a good time to be. And, you know, I was, so, I had founded a company outta Boulder called Still Secure, and we were, we were intrusion prevention, vulnerability management, network access control, Mac. Yeah.
And, um, I was in, those are interesting times in security. Um, but as you say, you know, we are, um, AI's changing everything and these are very interesting times to be doing anything in tech that, that AI is touching on like this. So, but I'm, I'm, I'm, I'm just worried a lot of folks out here may not be familiar with Telio.
So before we jump into some of the higher level things I want to discuss with you, you give me a, give our audience a sense of who telio is and what you guys do. Uh, I'd love to, yeah. Telio has spent the, over the last decade testing customers digital product offerings.
Uh, it's a crowdsourced, um, the global crowdsourced offering. We have about 60,000 crowdsourced testers on the platform. And basically we provide access to projects.
And projects really are customers expose their digital assets to us, and we test them, uh, and we test them deeply. We've tested over two and a half million, uh, test runs over, over the period of the company in 150 different countries on about 600,000 different appliances. Wow.
So we give as close to a real world non-biased test experience as a customer can get. So we have an amazing diversity of customers that are in tech, they're in finance, they're in the sporting world, and they test their apps on our footprint of, of testers, and we give them direct feedback. So it's kinda like a customer simulator for want of a better word, where we test the real world experience.
And what it also gives you is real world experience of things like the demographic, uh, that's testing it, the network, it's being tested on the type of device that's being used so the customer can really get an experience of, okay, what's it gonna be like if I launch my new Premiership football app in Indonesia or in Columbia, what's the customer gonna experience? So we work with global brands that care about their brand identity, care about their digital product, working straight, uh, out of the box, and we give them real word feedback so that they can feed that back into their development loop and make a better product. So essentially we're helping global brands build better products in a very, very efficient way.
Excellent. I love it. Dean, of course, as I, I inferred earlier, AI is having a tremendous impact, especially in tech and, and within tech, certain areas, well, sales and marketing and for one, but testing is one area where, hey, look, AI just makes a lot of sense, right?
If you could train the AI to figure out what tests to run and then run those tests, that's, that's a pretty good thing. But of course, you know, nothing's perfect. Theis have bias built in.
They do hallucinate know they're getting better. I'm not going to deny that they're getting better. Um, and they're, from a compliance point of view, if you don't have a human in the loop, did it really happen?
These are all kinds of things that we're running into from where you sit, right? It are these issues that, number one, we, we we're dealing with. And number two, what, what's Telio and our QA folks out here to do?
Yeah. No, I think it's the tremendous opportunity for Telio to continue to add massive value to our customers. And we, you know, we talk, I love getting out and seeing customers, Alan, it's probably the best part of my, uh, of my job is to go and see customers globally and get, get an understanding for what they're doing.
And I see, um, I talked about those different evolutions of stuff that I've been involved with, right? I came to America when mobility, when the, when the iPhone kind of went, went wild and everybody started working remote. So we did a lot of remote access stuff.
We did a lot of device security, then it was all about cloud. Then the next wave after that, I think I can probably say was shadow it. I dunno if you, do you remember that kind of era where we do mm-hmm.
People were worried about, okay, what apps are we really worrying? Or what are we really using? We running well, people were whipping out credit cards and just spinning stuff up.
But yeah. And now honestly, I see a similar kind of shadow AI world. Absolutely.
Everybody's using it. If, if you don't think your team's using it, you know, just think again because they are. So, I think everybody now is, is struggling.
They're running hard because they've got board pressure to use AI to increase efficiency, uh, to roll out new services, to roll out software faster than ever. And that's compounding the fact that underneath the ai, it's still learning. It's it, as you said, it's improving.
It's much better every time it comes out, but it's still improving. So we polled our customers and you know, we are seeing that like 82% of the bugs there now, reporting are coming from AI hallucination, just AI trying to give you an answer when inherently it doesn't have enough data yet. So we are in a way policing AI at Testlio.
You know, we are helping AI get better. I think it's exciting for me because of two things. Number one, we are helping, we're very, very involved with AI testing, AI policing a, the AI experience, verification for customers, giving customers an understanding of how confident they can be in with ai.
And then secondly, we're creating very meaningful work for our crowd community to be AI testers. So we've created an AI testing program, a prompt injection program, a whole, um, category, a new category in our, in, in our testing world where people can come and learn how to be testers and be valuable in that kind of AI feedback loop. So I think it's great to always be the helping humans, uh, you know, globally and we're creating meaningful work with this AI testing program that we're, em, em embroiled with right now.
So, super exciting time, huge opportunity. But I think what we're trying to do, Alan, is give customers confidence in their commercial adoption of AI and helping them avoid very costly pitfalls if they get it wrong. I agree with you and interesting, Dean, I was talking recently with a friend of mine who's involved in another company that uses crowdsourcing to help deliver the goods.
Um, and they were saying that to a certain extent they could set up ai, I dunno if you want to use the word simulations or, or what have you. But in essence, they don't need as many people doing the crowdsourcing. 'cause the AI can simulate, you know, thousands of people doing this.
Um, I'm wondering, is that, is that a good thing or a bad thing for us? And you know, Uh, I think it's an interesting thing for us. Like, yes, AI is good at replacing repetitive work for us, and it's good at doing repeat tasks that it has a good data set from.
I think we're a way off having the reliable data set, but I do think that, and we see it, of course, a lot of the data that we're gathering is coming into our own platform. 5 million plus test runs that we run. Um, and turning that into insights that can be predictive in nature for our customers rather than reactive.
So I agree that you can do more, um, with AI than we, uh, historically could. The question is, can we do the insightful stuff that we need to do to make sure that AI is constantly improving for good? And I think that's where Testlio comes in.
We've always got the human in the loop that's gonna be able to challenge ai, reinforce the learning, uh, of, of the, of the, of the ai, uh, data set, and continually feed that back to our customers in a way so that over time we can give them good predictive. It's a bit, a little bit like, um, I forget the name of the movie now. The, the, you know, the Tom Cruise movie.
Um, where, where, where we're giving, uh, proactive advice to customers about going into a market, what they should be worried about before, uh, before they go into a market. Minority report, minority Report. Thank you very much.
Yeah, exactly. Yeah. They get arrested for what they're thinking.
Yeah. Um, I don't think I, I, that's not as far out as it used to be. I agree.
Uh, I, I get it though. Uh, look, it's certainly interesting, interesting times to, to be doing all this. And I, I think, you know, if the bar is here today about how much of the AI versus how much of the human in the loop, I, I think over time as we gain more confidence as these models get better, you know, as things happen along those ways, that that bar is gonna move too, right?
And, um, I don't know if it'll ever go fully automatic or fully automated, whatever you want to call it. I think you're always gonna need some human in the loop kinda stuff. I just, you know, I think it, it, as the AI gets better, I like it.
And it's not just sing, this is everything, right? Yeah. I spoke to, I Gets better, You know, I speak to a lot of interesting people in, in, actually, I speak to more interesting people here because we work with such a wide set of industries, right?
So we, we work a lot in, in the, in the media. So we do a lot of TV streaming media. So you meet a lot of creative people.
Sure. You know, they don't want AI to replace the creativity. They want AI to replace the mundane so they can focus on the creativity.
Uh, I see a lot of people, you know, myself included, I've got more time to think strategically now, um, than I had before because AI is helping me with a lot of the mundane stuff that, that I, you know, I used to need to do. So I'm an optimist, uh, Alan, I, I think that we can use someday, you know, to lift a lot of the load. It's kind of, it's like the industrial revolution all over again.
You can either sit there and you can destroy the machines because you think it's gonna take your job, or you can get on board with it, embrace it, and then become more efficient and, and embrace AI that way. And I actually, I used that analogy twice already this morning. I'm getting boring with my industrial revolution.
Yeah. But, but you know what it, so they, you know, I think, look, I think the fund's really gonna start when the robots start using the ai. And then we're truly gonna have, I don't know if it's the fourth or fifth industrial revolution, or it'll be a combination, but you get AI with robots and, and, uh, quantum computing things get real exciting, you know, it gets real interesting.
We'll have to see where it goes. But I do, I Wanna talk to you about quantum computing sometime. 'cause that's my next big passion project, right?
It's, is It, you know what it is, don't wait too long, Dean. 'cause it's happening. Oh, it's quantum.
There's stuff happening every day. Every day. We're seeing it's building.
It's building. You know, they call this so-called Q day, right? Where we, we, yeah.
Yeah, sure. And, uh, We need to get into, into really interesting encryption when, when quantum hits, right. All sorts of Tic stuff.
Well, we gotta get out in front of it. You can't wait till it to hit. We gotta be in front, you know, like you love your job.
This is one of the reasons I love doing what I do, right? I, I get to talk to people about all of these things all day. And so most people are much smarter than me.
So I really, it's fascinating, fascinating stuff. Um, Well you actually, you talked about the robot stuff, right? I mean, Silicon Valley right now has got so much interesting.
Well, we were in, uh, in Amsterdam last week. We're seeing a financial services customer that's, it's using a lot of robotics to test payment devices. It sounds like.
It's just incredibly efficient. They've got fabulous robots just sitting there trying to, trying to break payment devices instead of a human having to do it. Yeah.
I've got an old boss now who's running a swarm warfare company, and they're making swarm AI driven drones to accompany humans on missions. It's fascinating. The, the, the, the breadth and diversity of, It's crazy.
The, the applications. You wanna wanna go check out something, go look up a company figure. I don't know if you're familiar with these guys.
F-I-G-U-R-E? No. Go on YouTube and look at their, they, their newest model is called Figure three.
So this is the company that BMW uses to build BMWs. Okay. And, um, they're retiring the robot that VMW was using.
That's the figure two. Go look up, figure three, figure three washes your clothes, folds, your t-shirts, plays, fetch with your dog. It's, it's, it's both exhilarating and frightening, right?
Is the best way I could tell you because I love it. They have them like delivering UPS packages. They have another one at the hotel desk checking you in, giving you your keys and telling you where to go.
The, the hands on it and the movement of it is human-Like, it's, It's crazy. That's fascinating. I I, um, I wake up every day excited about the potential.
Me too. I'm, I'm a pilot. It's my, my, my other passion is flying and, um, Look what it's doing there.
I was at an air show where they had full ev to, you know, electric personal vehicles. Um, yeah. And interestingly, it's, they're basically run by iPads.
It's, it's Uber. I know, you know, in the air, you sit in the thing, you press where you want to go and it delivers you to an alti port somewhere, somewhere close. But the interesting thing is the, the micro meshing of these things.
So you can have hundreds of them in the same airspace at the same time. Auto de conflicting Over a safe, as long as there's not a person there because a person involved in the loop screws the whole thing up. 'cause we don't, we don't always act as logically as the sheets You say there.
So at the moment, there is a human in there ready to pull the handle in case it goes wrong. Oh. In case they've gotta pull a parachute handle.
But yeah, like there's so much innovation happening at a pace that, So good time to be alive. Right? It is.
And isn't it exciting to be here right now? I mean, it, you know, we've, we've both lived a bit and we've seen these things before, but hopefully, But not at this scale, Dean. We, we have lived a bit, we've seen the advent of the internet.
You know, we've seen the cell phone. We, we've seen, you know, landing men on the moon, though we did it once and we haven't done it, you know, a couple times and we haven't done it since. Um, but this, the, the promise of how this affects not just you and I.
Right? You're, you've had a good career. I've had a good career, but I'm, but just like lifting up humanity, right?
E Elon Musk last week said, you know, with human, with robots andis, you might eliminate poverty. You might eliminate money too. But you know, the whole human condi, I mean, this is at a scale I don't think we've seen before, is the potential if we don't kill ourselves first.
But that's a whole nother story. I got into a very deep conversational Friday night about AI ethics with a medical friend. And, uh, Uhhuh, we were talking about healthcare in North America and how AI can assist.
It can prolong life, it can provide medication, but it could also at some point decide that, uh, you know, certain people aren't worth saving, certain demographics aren't worth saving, or certain age groups aren't worth saving. So where does the human ethics come together with AI at that Point? Well, that, and that's the flip side.
What if they decide humanity's not worth saving? Right. At some point in the future.
It's crazy. But hey, right now we're just worried about crowdsourcing some testing and getting that we, right. We go, he's a little bit there.
Sorry. Yeah, We, we got a little off there, but it's all right. Hey, Dean's a pleasure having you on.
We didn't mention Tess Leo's website though. Can you give us the website? Yeah.
com. Um, love to, you know, we've got a bunch of case studies and stuff, and we're in a period of, I think, excitement at Telio because we've got so much stuff that we wanna educate people on. com and I'll be very happy to connect with the right people in the right countries.
We've got people all around the world, uh, customers in 150 different countries. So it'd be great to connect and, uh, yeah, really enjoyed meeting you, Alan. It was we Nice meeting you as well.
All right. De good luck. com.
com. We're On text on tv. We'll be back with more in a moment, Guys.
Thanks for the throw. We're here with Sandeep Anand, who's vice president of Machine Learning Solutions for Infor. And we're talking about, well, the five things that are keeping IT leaders up at night about ai.
Cindy, welcome to share. Hey, Mike. Nice.
Happy to be here. Alright, So I imagine there's probably a lot more than five, but at least there's five that comes to mind. But, um, lead us off a little bit.
You know, when you think about it, what should it folks be, well, maybe actually worried about versus maybe worried about too much. But, you know, start us off. Uh, yes.
And, and, and thank you for the opportunity to talk about, uh, artificial intelligence. Um, so, you know, my role in Infor is about leveraging AI ML for, from a enterprise perspective, right? And so if you think of what that means from an in info perspective, we focus on business applications, ERP software, things that help, you know, businesses, help businesses be productive.
Um, the number one thing is, um, you know, driving useful, measurable business gain out of it, right? And so it's, it's from a, from a benefit perspective, the, the number one thing to worry about is how is this helping a business improved productivity, right? So if you think what is the value?
This is driving my organization in leveraging this because we know that technology works, we know that it's used across the board. So the question just becomes, what am I going to get out of it? And that'll be my number one consideration.
And how do I evaluate that successfully? 'cause I think a lot of it, people are trying to figure out what's the math here on the ROI that makes sense? Absolutely.
Which is the, which is, you know, in some ways, um, the, the, the secondary point to it, right? It's, you know, always you are going to talk about, uh, productivity measurements. Um, you know, it's very easy to say, well, this is going to reduce the, the amount of time I need to spend in trying to figure this out, um, manually or in my current business process.
The other thing you can look at is, uh, this is going to help me be more, um, accurate. You know, when you talk about inventory optimization or anything to do with, uh, scrap management, right? So we are looking at, uh, you know, we are looking at challenges in your business that are impacting the revenue side or the cost side, or the quality side, right?
So those are good, easy metrics to, uh, anchor against because you are probably tracking those, uh, in some analytics, uh, part of your business. So an improvement of those. Um, you know, the other metric could, could be considered around timeliness, right?
So we talk about productivity, savings, business benefit, um, being able to do it faster, right? Will be another thing to consider. Uh, and it's not a, uh, or it's a, and right is a, is three PRIs of it.
The fourth thing, uh, is also how is it helping my workforce, uh, be more productive? You know, allowing them to, uh, be more satisfied. Because in some parts of our, our ecosystems and manufacturing distribution, uh, the retention of these workforce, so the ability to leverage, uh, you know, do more with less of sorts, how can you get them, uh, excited to leverage these technologies to drive that better business outcome is also very important.
Uh, I think part of the issue too these days is that there's no shortage of these projects, but there's only so many resources and so many people with the skills. So, um, is there some way to think about prioritizing these things? 'cause I don't think we can do everything we wanna do all at once.
Yes. And, and, um, um, it's a very important question, and I think it talks to the, the company culture. Uh, you know, if you think of, uh, what do you want your business to be in the next quarter, next half a year, next year, where is your business priority?
Right? So from the prism of what are you looking at? Are you looking at it from a revenue perspective, uh, business transformation to, you know, do more with less.
Are you looking at, um, a challenge to the way your business is run because you have supply chain issues because of the current macro conditions, and it's really important for you to stay ahead of your competitors, right? So that's where, from the culture perspective, what is driving your business's push and how are you enabling your, your, your team in driving and pushing that would ultimately be the best way to push this forward. So it's not a side project, it's critical for your business to be successful.
And, and, and if so, how are you then getting your team on, on board, right. And be the, the right prism of how to start, which use case with in doubt, I always say pick something that impacts revenue on cost, you can go wrong, right? But also from a financial forecasting perspective, it's also good to understand how your business is moving forward.
So generally, that'll be another consideration. But, um, I, I am always partial to anything related to supply chain. Uh, when you wanna get started, It also seems like there's more of a separation and concerns these days, and the data science teams are maybe focused a little bit more on training and maybe the creating of the initial AI model, but the IT teams are taking more responsibility for the inference engines and the deployment thereof.
So is that part of it more where the IT leaders are more concerned about things versus, say, the actual training of the model itself? It's, it's, um, it's a very important question, and you talk about the blurring of the lines that have traditionally governed, uh, these types of projects. And, you know, of course, when you even talk about generative ai, right?
And agents, and how that is also causing further blurring whether business are now able to do things that the IT or the science team were able to do, right? So your example, you're talking about the science team builds the models IT team manages, maintains, executes on the, the models in the terms of the value. And then with gen ai, you have the business also coming in, Mike, and also coming in and saying, well, I can automate these things, uh, or I can leverage, uh, a gen AI type of assistant to drive better analytic knowledge.
So I don't need as much investment in analytic dashboards, right? And so it's an important question of, uh, as your organization, uh, evolves and depending on how they're set up, how those roles can play nice together, right? So everyone is now on everyone's turf, which is good and bad, depending on how you manage it.
Mm-hmm. Also, I think that there's some concern about, well, what should I actually go build myself versus quote unquote buy? Because there are software vendors that I currently rely on who are building AI and ML into their various offerings.
So I'm trying to figure out, like, uh, I don't think I want to be in the position where I've just spent a year building out an AI model to wake up one morning and figure out that my software vendor's given it to me for, you know, a nominal extra cost within the application itself, Right? Um, the age old, uh, challenge with the build versus buy, right? If you think of it, and with, uh, with, uh, if you think of cloud providers, it's no longer, um, uh, just simply build versus buy, but which part of the things are you building versus which parts of the things are you buying, right?
It's a, it's, it's a un enviable position of how to make those choices. Uh, I was recently, um, we were recently talking about, um, you know, how do you from a prism of an end user navigate these challenges that are, uh, or opportunities, depending on how you look at AI and the excitement, uh, and potential of it is, do you look at a vendor as a monolith saying, give me, give me the outcome and you just take care of everything? Or are you in, um, in the kind of a maturity phase where you're saying, I, you know, um, if you think of a shirt, right?
I I don't want the shirt. I just want you to take care of the sleeve. I'll take care of the buttons and you help me get the fabric.
Right? And so I think that is kind of the, a case by case decision. I think, uh, if you're starting off, uh, again, if I follow up my, my very simple example, just get the shirt, and then ultimately when you get comfortable wearing your shirt and you want different shirts, you can start trying different things.
Uh, but once you, you know, as you get more and more into it, you are going to want to have more control on those decisions yourself, right? We, we haven't talked about IP and data rights, but ultimately over time, uh, there's a gravitation towards I want to do something special for myself, but I do want things that are very easy and common just to be handled by my partner. Mm-hmm.
The other thing, it's still unclear to me, but who's responsible for securing all this stuff? Because to your point, um, not only are bad guys trying to poison models, but in some cases, they're trying to just steal the model entirely because, well, it's valuable ip. So, um, do we need to rethink security in the age of ai or will we just kinda have the same old it does the deployment and security people secure it?
Um, I, I, I definitely think that we have to keep up with the times. Um, right. If you think of, um, if you think of all the challenges we have, uh, with some of the items, the examples you just gave in the news, where I think the, the agents, the LMS can now catch security intrusions as they're being tried, injected into your organization.
So there is a, a newfound respect for the power of, uh, using, um, advanced technologies to protect you beyond just the data and, uh, uh, kind of people protections of, you know, keeping things behind firewalls, right? So those will continue being a necessity looking at, you know, LMS that allow you to be more secure, making sure your partners with the, those models aren't leveraging your data to learn from, right. And causing your IP being pushed is important.
So I think, uh, it's evolving, right? We will continue adapting with all the, the advancement of technology, but I don't think you can, uh, have a stance that I want to firewall myself. I think the trade off of protecting overly protective, uh, uh, setups will ultimately limit you from being able to take power of all the advancements in technology.
Mm-hmm. Is there something that we're overlooking or maybe not paying enough attention to as IT leaders? Because maybe we're spending too much time obsessing about one thing and not paying enough attention to something else?
I think that's why we have such white hair, right? Because I don't think that's ever going to change. There's always something, Mike, that we will always not be taken care of, right?
I think when, when we got the, um, when we got Gen ai, we were like, oh, this is great. And then we were like, oh my God, but this is just taking all this information and pushing it out. And then we were like, oh, I, God, this is telling me the wrong information.
What we should have some guardrails. And it was like, well, it's just telling me this information I can't do much without. So I think that's a, I think to you and me, that's a IT problem.
We all cherish and love to have, not business, don't you think? Right? So we always be something One impact will all this have on the role of the senior IT leaders out there, do you think it's gonna elevate their positions a little bit within their organizations?
And, um, how should they kind of view themselves within the context of an organization? Because you could argue conversely, that AI is really a line of business issue, because you've got people who are experts in a process and they need to understand how the models work and validate them, but at the same time, you're probably not gonna get very far without it. So how's the relationship gonna change?
Uh, it's always, it's always symbiotic, and I use that word intentionally, right? I think from a, um, investment perspective, there is always a need to continue investing in it. Uh, not only from a security and governance perspective, but project management of these transformations.
You're always going to look at using different tools to drive your business. You're never gonna have a monolithic single, uh, software policy. And this is where it is especially suited when it comes to technology and technology change.
We are also looking at, you know, how do we be, um, how do we get the right evangelist from a business perspective to help drive those productivity benefits, those revenue benefits, and things like that. So I think that, I think there was always a need for it. I think where with gen AI and agents agent ai, I think we're starting to blend some of the business and IT responsibilities, especially when it comes to analytics.
But now you're also getting a new level of understanding around, to your point, the security, the governance, the concept of how is my data interpreted in my organization or outside as we start looking at, uh, you know, some of the new technologies around the agent to agent, where the hope is two businesses can talk to each other without requiring anyone, right? And so I think, um, older paradigms get replaced by newer paradigms where it has to change and upscale, but also provide more and more help, and even if not oversight, but some way to control the, the, the use of this AI in and outside our organizations. Mm-hmm.
Am I gonna see organizations build these kinda massive AI models that everybody's worried about what the ROI is gonna be? Or is it more likely that for the purposes of a business, I'm gonna rely more on smaller models that are distilled, maybe from those bigger models, but ultimately they don't need to be nearly as big and as difficult to manage? And should I be, you know, focusing my efforts on, uh, uh, set of AI models that are maybe better trained with a particular set of vetted content?
I think that, I think that's unlikely, um, that we would have companies invest in their own large language modules. To your point, uh, soft smaller language models or very small language models or domain specific language models will probably be, uh, for certain companies a better preferential treatment. I mean, if you think of our phone, it's this example of a, a small language model.
If you think of the, the fact that when you type a email, you get the autocorrecting the information, right? That is not what a SLM is. But at a basics level, we are already at some point, uh, uh, able to take advantage of very specific use cases, uh, around large lang around, uh, language modules.
But, um, you know, I just don't see that big need for your own LLM. I do think there will be more and more adoption of, uh, help my business make better decisions. Uh, but it, I don't think it needs to be a small language model.
I think you could do something even more pragmatic very quickly, uh, with the technologies in place. And I think that's where a lot of, where from an info perspective, we are also seeing the initial stepping into the, the waters of sort, is that we, you know, we want to help us with our procurement process. We wanna help with our customer service, uh, and being able to look at documents and help with knowledge bases to help kind of troubleshoot information.
Those don't require such a large investment. In fact, those things could be almost out of the box in this day and age, the way technology's moving, right? And we see a lot of that initially.
Um, I think some will go into the s SLMs, but, you know, I don't think that's fully needed to get the advantage of, um, the benefits of AI In my conversations with people that it seems like they're starting to realize that there is this need for more context. When you're working around those LLMs and you hear the phrase, context engineering is kind of the next super set of prompt engineering. And that's right.
Then it, it seems to me, as I look at it more and more, it's as much art and skill as it is science. So how do I make sure I'm putting the right data at the right place at the right time to ensure, uh, the context that I need to get some sort of output that's more reliable is occurring? It, it, it is a million dollar question.
I think that is, uh, one of the questions that is keeping, uh, uh, organizations up at night, right? The, this is, uh, this is part of the reason it jobs are always going to be, uh, required, right? Because we started off with, you build a software, and then you're, you're, you're good, right?
You just have to worry about this software being used by the business, and then you realize, oh my God, this is just connecting to other software. And then you're like, oh, but this is putting in data that needs analytics dashboards. And you're like, oh, these dashboards are just telling me what's in the backend.
So we need ai. Now we have ai. You're like, oh, I don't know if this AI is the right AI for me, because it's just telling me things that probably not true and need to be curated or need to be better managed.
And then when they are managed, you're gonna say, well, I wanna automate this so that I don't actually have to worry about it. I don't need to have analytics. I don't need to have software.
Like you see the thing, right? We build a software and you build analytics, and you build the ai, then you build the, the, the agents that run the AI on the software so you don't have to use the software, and then what's next? What's next?
What's next? Right? And I think, I think that's the, that's why we love this job, right?
We are moving so fast and moving so fast in some places that I didn't think we would be able to do in five years ago, right? And so I'm very happy with that. So in some ways, half glass full, right?
That's the kind of thing, the way I look at this. Yes. So what's your best advice to folks?
Because the opposite of the glass that's half full is the glass is half empty, and a lot of folks are intimidated by all the moving parts here, and almost to the point where they basically freeze and do nothing and are just kind of watching and waiting for things to kind of maybe evolve. But, um, what should folks be doing today? I I think we'll go back to the, the premise of the conversation.
Don't worry about, don't worry about all the hype around the technology and the promise of it. I think distill it to, um, what's important for my business to do now, next, later. Uh, how am I able to quickly do the now next, later, uh, with the people, process and technology at my fingertip?
How do I measure? Uh, and, and also, you know, simple principles not related to ai. That's just anything.
Anytime you're investing in any, um, initiative, you, you look at, you know, what do I want out of it? How am I gonna measure it? How quickly can I get it pragmatically without having a big, large investment?
And is this gonna be a market differentiator? And then you just take that action. And, and the reason that's so important is because it's tried and trusted.
It is not about ai. It's ultimately about how you want to succeed. And therefore, you're less likely to worry too much about, am I doing the wrong thing?
Because it's the thing you every business should always be doing. And if this helps that, then you're easy more likely to do it versus trying something new and unexpected. Because at the end of the day, we're still talking about quick ROI, measurable, RROI, bringing people along, measuring business outcome, and then, you know, rinse, repeat, right?
And so, as long as you keep it in the prism of what everyone does, you're less likely to just, you know, be paralyzed with this indecision, right? And I think that's how I think everyone should think of it. All right, folks.
I heard it here. Despite all the hype and concerns about the fear of missing out, turns out slow and steady still wins the race. Hey, Sandeep, thanks being on the show.
Thank you so much. All right. And back to you guys in the studio.
Hey, everyone. Welcome back here to Tech Drunk tv. Uh, you know, we're continuing our coverage of in interviewing folks here at, uh, AWS reinvent from our suite up in the wind.
Um, it's been a, an interesting couple days, obviously, a lot, a lot of news, a lot of information, a lot about AI and agent ai. If you haven't had a chance to catch, you know, a lot of our coverage, uh, sponsored by our friends at suse, by the way, we've also had a great, some great conversations with Susa and a WSI recommend. But let me introduce you to my next guest.
His name is Kim Bohan. Yes. Uh, Kim is the, uh, CEO of a company called Skyhawk Security.
Security. And if I'm not mistaken, it's Skyhawk Security. Skyhawk Security, correct.
Is the website. So, Kim, welcome back. We, well, welcome back.
The last time I saw you weren't sitting across from me, you are on Zoom, but now we're here in person in Las Vegas. Um, Very excited to be here, and thank You for Thank you. My pleasure.
But look, not everyone watching this saw you last week. Yeah. So I'm afraid we gotta do a little bit of ground keeping here, give people an idea of kind of your journey and what Skyhawk does.
Yeah. So first of all, IO obviously recommend everyone to see our, uh, previous recording Absolutely. More in the coverage.
Skyhawk is a, a cloud security company. Uh, our roots are in cloud threat detection and response. In the past years, we added, uh, AI based red team, uh, and transform the platform into an autonomous purple team platform.
Basically, we have a, a red team in AI that fights the cloud threat detection engine and creates, uh, uh, basically a purple team automated autonomous purple team on customers environment. And I'm inviting you to talk with us, uh, further to learn more. Absolutely.
And you know, it was interesting. I actually, we, I was mentioning with SUSE earlier, we did a, a panel and we were talking about AI and, and what autonomy it brings in software development. And, and one of the examples came up, sort of like an AI red team, right?
Where, where, look, the code might be generated by one LLM, but we're going to use an AI red team by a different LLM or a different, you know, model to check the code mm-hmm. Before, and I said, at what point does the human go into this loop? Right?
At what point is if, if the code's generated and the testing of that code is generated and the deploying is generated? So, you know, in my case, I see generative AI as a force multiplier, not, it's not eliminating humans. Mm-hmm.
Uh, in our experience, uh, I was able to build, um, uh, an AI based threat team with extremely efficiently, with a very small team. We have, uh, companies that we're building, uh, you know, breach and attack simulation with tens of people in r and d. And over years, we were able to do with a relatively small team, what would otherwise, before generative AI take, probably tens, right?
So it's a force multiplier. Uh, even more importantly, in our case, it was, uh, uh, a design, uh, a fundamental design consideration because we thought that adversaries are gonna change, right? They are going to use generative AI in order to build a test.
They Are, And, you know, we started that claim three years ago, and people were a little bit hesitant. Now it's obvious because we see it in the wild. Uh, OpenAI talks about how, uh, chat GPT was used, uh, uh, and traffic were, uh, uh, talking about how cloud was, uh, just used by adversary to build attack.
So now it's reality, it's obvious, uh, it's a force multiplier for adversaries, and therefore we as the defenders have to use it in order to help our customers protect mm-hmm. Uh, against what they're going to encounter in real life. Uh, so it's not zero human in the loop.
Uh, there is, you know, still a research team, there's still development team. We, we do have, uh, some human in loop, but, uh, the pace in which we're able to, uh, build basically attacks that are tailored to customers environments, it's just amazing. It's unparalleled.
Uh, No, this is, I mean, look, I had friends who started like, uh, like for instance, cobalt, you, I'm sure you know, cobalt, you know, crowdsourced penetration testing, right? Because before that, the limiting factor was how many pen testers can you have, right? Right.
And now, you know, with, I could have literally hundreds, but even that's not enough in today's world where, where we're talking scale, right? And that, you know, what I, again, something that I spoke about on a bunch of the talks over the last couple days is the scale and then the scale, the scale that you see at an AWS or, or Google or Microsoft, any of the, they don't call 'em hyperscale. It's for nothing.
Yeah. The scale is phenomenal. Yeah.
And, and it's, it's the scale and it's also the velocity, you know, that we see that the time from initial access still impact shortened from months to weeks to now less than an hour, right? Yeah. It's, it's, it used to be that you would have adversaries in your environment for days or weeks before they would make their lateral movement.
And, and the negative impact now from initial access to negative impact less than an hour, it's crazy. It's industry statistics and, and it's Crazy. And, and it's going down from there too.
I, I imagine, Kim, when we had you on last week, it was right around the embargo lifting on this announcement, right? That you guys made. Again, people may not be familiar, but if they are, great.
But let's go over it again. Let's go over the announcement. And now that you're here and you've had a chance to kind of have it, get some legs uhhuh with people, let's hear what you're Hearing.
Yeah. So we basically announced adding a gent ai, uh, into our platform to help with security validation to understand that statement. There's some background that, uh, I need to repeat.
Uh, as I mentioned, we are providing a purple team platform. Basically, we have the detectors that are continuously being fought by an AI based threat team, uh, generative AI based, that builds customer specific attacks against our defense engine. And, but by that, we were able to show customers the true weaponized risks, uh, and how our system would detect that, uh, incident when it happens, uh, and how the, uh, uh, alerts how the CDR portion of the system will look like.
That was well received by customers, and they basically said, it's amazing, but we also have other, uh, security controls in our environment. And apart from seeing how sky o will, uh, react to that incident when it happens, we also wanna make sure that the rest of the security controls we have in that environment will properly behave, uh, to do that. That's where Agen, TKI, the new addition we just announced comes in.
Instead of just providing security control, validation of the customer specific risks and our detectors, we're now learning with Agen, TKI, uh, framework, basically learning everything that the customer have in the environment. There are sim solutions, there are EDRs, uh, basically we're learning everything that they have. And we, uh, show them how their, uh, ecosystem of security will behave when a weaponized risk will materialize.
That helps them do a few things. First of all, it prepares the sock. Uh, so it creates an automation, uh, of basically verifying that you have all the right detectors.
You can almost do a continuous tabletop exercise so that the sock knows exactly when they see that sequence of events fired, that it's a true positive that was pre verified. You already know how to respond to that. And again, we're now doing that ecosystem wide, uh, on the customer's environment and integration with Splunk, with CrowdStrike, uh, that we were doing, uh, in order to provide customers, uh, full coverage.
Love it. You've been here a couple days now. What, what's the feedback been?
What are, what are you hearing? What are you Seeing? So, first of all, uh, customers are, uh, really, really excited.
Uh, even my own customers, uh, not just here, existing one, right? Existing customers are extremely excited about what we announced. It came from customers feedback.
So that's, uh, obvious. We always good thing, right? Listen to customers.
They teach us, uh, more than, uh, anyone else. Uh, but, you know, the traffic at the booth was amazing. The reactions were, uh, good.
Uh, I feel that it touches true pains of customers. You know, they get a lot of noise, a lot of alert fatigue. They don't know what to do with it.
You know, people stand by the booth and, and they see the metricses that we placed out there, uh, that customers reported to us. And they say, okay, I have that pain. I, I want to, uh, uh, learn more and, and resolve the same thing.
It's real world. It's a real world pain that they have. Like, they have real, literally, people told us, you know, hundreds of thousands of, uh, alerts that they need to deal with, whether it's on the risk side, on the vulnerability scanning, uh, as well as, uh, on the runtime side, you know, right.
Left of the boom and right of the boom. And we basically help with all of that. Uh, I must say that if you look on the announcements that were made this week by AWS and others, different places of the stack, but generally the same messages of, uh, AI agents that are, you know, doing analysis, each one of their on their own layer, uh, talking about noise reduction, about the ability to use a AI agents in order to provide security.
So I think you've see in different places of the stock, uh, exactly the same messages that are being, uh, conveyed to customers, which means there is a, a pain that the industry experience, again, in, in coding, in cloud infrastructure, in vulnerability management. We see it all over. Uh, I think that there is a, um, a tsunami of, uh, yeah, solution.
The solutions from that family that, uh, we're gonna see. And I'm happy that we were there three years as innovators and thinking about It. Well, it's always nice to be, you know, early in, in, in that, yeah.
In the movement. Um, this will be over tomorrow. What, what's next for you at Skyhawk?
So we're, first of all, we're going to continue to listen to our customers. They tell us, uh, you know, the best, uh, where we should add next. Uh, I think that what we have right now is really innovative and probably two or three years forward of where most of the market is.
Uh, our approach at Sky Oak was to create two major innovation every year, uh, that we announced. Uh, and we'll continue to do it, you know, with the iGen, uh, simulation and verification. I think we, we mentioned it, uh, in our previous conversation.
One of the things that we can do is also become a recommendation engine on what, what else to add in order to close gap. So, you know, these are areas we can expand to. Uh, but, you know, the core essence remains being a purple team platform, solving the pains of noise reduction, getting the SOC prepared to, uh, respond to events, showing customers their true weaponized risks rather than, you know, laundry list of vulnerabilities.
They have nothing to do with the, the core values remain, and we will innovate, uh, around them more and more and more. Absolutely. Excellent.
Excellent. Hey, I want to thank you for popping up here. Thank you for inviting Me.
Um, again, it's Skyhawk security. Skyhawk Security. Check it out.
Um, I, I think you said you were gonna be at RSA or We usually do every year. Yeah. Maybe.
We'll, we'll, will we be doing this on Broadcast Alley there? So hopefully we'll see you then. Looking Forward Up.
A pleasure. Pleasure. Thank you very much.
Skyhawk Security, check him out here at, uh, AWS three invent. We're gonna take a break. We, we have more coming, uh, today, and of course, a full day tomorrow.
So stay tuned. You're watching Text Drunk tv e Hey everyone, we are live here at AWS Reinvent, continuing our coverage of day one. A lot going on a lot of ai, a lot of agentic ai.
You know what? I don't hear a lot about Cloud. AWS reinvent used to be all about cloud.
Now we're talking ai, but we're gonna talk some security. One of my favorite topics, I want to introduce you two and make, I'm gonna mess up his name, but we practiced it 12 times and I still didn't get it right. Sne, Ben Shimo, Shimo, almost, I wanna say Shlomo, and I keep Shimo, but he likes to be called Ben.
Ben, what's, thank you for coming on to Text Drug tv. It's great to have you on here, Man. Thank you for having me.
So, from the name, I'm gonna guess you, maybe you have some Israeli roots. Yeah. But You live, you're a New Yorker, New Jersey, like me.
So I guess that makes us kind of almost related, but, um, tell us about your journey. How, how did you come here? Yeah, definitely.
So, currently based in New York, almost in the past 10 years, uh, been in cybersecurity for many years, as you all know. Uh, I'm Israeli originally. So we started the journey in the military.
Uh, I'm not 8,200. You're not 82? No, my 1200 Is what, a few, not 8,200, But actually 8,200 is quite big.
Yes. To the place that I used to serve. I used to serve in more of a secret service.
Okay. The Prime Minister office, which is a more boutique, more unique, eh, harder to get into if you're 8,200. Don't hate me, but we're better.
Okay. Hey, he said it. Not me, but go ahead.
So, yeah, we, um, basically moved to the states after, um, managing a lot of cybersecurity, public company research division, building from scratch. Really, really passionate about research, anything related to vulnerabilities, attacks, offensive security, defense. And, uh, I found myself in, in New York as like one of the big companies.
I build their product. They couldn't sell their product to the ciso. And I was blown away because such a great product, we need to explain the value.
And when I moved to the States, uh, I was really kind of exposed to, no matter how good product you're building, you need to be close to the customer. You need to be really close to the team. You need to close to the security executives and explain to them what's going to come next.
The thing with security is like check if you're playing, if you're trying to survive the next week or maybe the next year, you're probably going to fail in year two. In year three. So when I moved to the States, one of my biggest goal was to educate them right?
In like, what's coming up next to build a strategy in the right way. I used to be a CISO as well, and managing security organization over 100 people. Um, um, very quickly, um, after that built a startup, a a couple of really good friends, uh, named Cider Security very quickly.
We sold it. I know them well. Sure.
Yeah. So really quickly, uh, we had a huge success. We sold it to Palo Alto Network.
Mm-hmm. Part of Prisma Cloud. And, and, um, I ended up loving the cyber security and startup.
I'm like, wow. I can do, I can build, I can do whatever I want, versus enterprise. That was a little bit slower.
Yeah. So I decided to take some time off after the exit, and my co-founder, who I didn't know was going to be my co-founder, called me. His name is Uri based in Boston.
And he's like, Hey, so I have something interesting for you. I got to a point, he manage vulnerability management and cloud security for Akamai from Cambridge. Sure.
And he is like, Hey, I got to zero vulnerabilities in three of the massive Akamai environment. I'm like, great, Julie, you accepted the risk. Everyone can accept risk.
It's like, no, no, no, no. Actually remediate it. Actually.
It's like, excuse me. Look, vulnerability management is never happened, never happened, never happened. Vulnerability management is a list of problems everyone have.
And you just wait for, you know, s****y defense and bad things will happen, but it is what it is, right? And he is like, no, no. I was able to do something about it.
Uh, it sounds very promising. I opened a plane, went to Boston, and I spent a few days with Uwe. And what he showed me, I was blown away because I couldn't achieve it with the best team in the world of security people for all the decade I'm in cybersecurity.
And this is where I realized that vulnerability management, the dead market of vulnerability management, exposure management is, can be solved. We can actually win the vulnerability battle. Call me skeptical, but okay, I'm listening.
You got my in. So after a long journey of speaking to over 100 good friends, CISOs and large enterprises, and also smaller one, everyone works, we're skeptical. What we ask him, it's like, Hey, if we can come in and take your backlog, your vulnerability backlog, and all these vulnerabilities that you're getting from Tenable, from Wiz, from AWS inspector for, and we talk about AWS later on while we here, but all this crazy vulnerability data from on-prem, from the cloud, take all this vulnerability data.
You can sift through it. You don't have enough people in the team to review it. And then you have workflows.
But you cannot automate vulnerability management because it's deterministic. Every CV is different, every vulnerability is different, and the environment is different. So how can you automate?
You can't. This is why we're failing. And I ask him like, if I can take this problem and automatically reduce 90% of that backlog automatically without any human touch, just eliminate it and leave you with that 10 or maybe 5% to actually handle.
It's like, that sounds good. That sounds great. That's great prioritization.
And then I, then they told me, what about remediation? I was like, okay. So once we have that 10 or 5%, I know, and we practice that in, we identify it, take that five to 10% and simulate remediation and give you that one, two, or three steps that you need in order to reduce Back to the buck.
Exactly. That's exactly what we're saying in our website. Mm-hmm.
And they say like, that's amazing. If I have something like that, I will, I will buy it. We, uh, close the seed round in a month really quickly.
We just took the money, great investors, and we built Zes security, which is the current company we're at today. Very excited about it. So that's basically the story of, Of you and Zes Security.
Yeah. And ui. So lemme give you a little background.
I, I've been inside, but we didn't call it cyber, we called it security. I've been in security 30 years. Information security InfoSec.
Yep. Exactly. And, um, I actually, I've co-founded a couple companies, one of which was called Still Secure back in 2001.
And we in 2003 came out with a vulnerability management product. And back then it was very different. Back then you had to convince people to do a scan once a year.
Mm-hmm. It was like pulling teeth. But when you, but it was job security for the security guy.
'cause you would do the scan, you deliver like a telephone book of vulnerabilities. Let's say I give it to 'em for Christmas or New Year's, you know, you're from New York. It was like painting the Veno Bridge.
Amazing. You know how they paint Itno Bridge? Amazing.
They start on one end, it takes 'em a whole year To finish, To finish. And then when they're done, you know what they do, they go back and start again on the other Best job security ever. That was vulnerability management.
It was almost by design that you didn't get to zero vulnerabilities. So then people got smarter. They said, look, we don't need to get to zero vulnerabilities.
We should only worry about the vulnerabilities that are exploitable, reachable real. You know, I had, I had a friend, I don't know if you ever heard of this guy, giddy Cohen, Skybox Security. Yeah, Of course.
Giddy just started a new company. I know too. I know.
Um, you know, and that was one of when I first saw his attack maps is what he called them, right? Mm-hmm. That was a revelation.
I was like, wow, this is great. Now I only have to worry about 20%, 25%, Which is a couple of millions. It's still a Couple of still job security.
Yeah. But unfortunately, it's been almost by design that we never get to zero vulnerabilities. A as a matter of fact, even you mentioned, we were talking off camera about black hat.
I was a black hat in August. I was talking to a friend of mine, uh, two friends who actually just, uh, just starting a new company. They just raised money now.
And, um, their, their thing is, look, forget all these vulnerabilities. There's only a handful that are real mm-hmm. That are responsible for incidents.
And just focus in on those. That's good. If I knew exactly which ones to focus in on, you know, that's like, the old's an old joke.
A plumber comes and says, the lady says, I don't have heat. A plumber says, let me look. He takes out his pipe and he, he bangs the, he takes out his wrench and he bangs the pipe with the wrench and the heat starts working.
The lady says, oh my God, what do I owe you? He says, $250. She says, $250.
All you did was bang your wrench on the pipe. He said, oh no. That was free.
Knowing where to bang my wrench on the pipe is $250. I love that. I I'm going to use that.
Tell You got it. This is awesome. Is yours, wow.
But that's the thing about vulnerabilities, right? If you know, which of the ones that are exploitable are dangerous, you can mitigate. But to get to zero, I'm not gonna ask you to give away secrets here, but what is the secret to getting to zero vulnerabilities?
So what we, and, um, I don't know if we want to get to zero. Okay. I don't think we need to get to zero.
Yeah. But we definitely need, like, why do the, the world need is important. Since you start talking about scanning today, scanning is mandatory.
Yes. You have requirements, right? You have continuous regulators.
Yep. You have auditors. More than that.
If you want to provide services as a SaaS company to customers, you need to have an SLA. Yep. And what happened in 2025, these regulators, uh, re requirements are stop asking you for visibility.
Because visibility, everyone knows everyone have that list of vulnerabilities, right? Mm-hmm. Everyone can scan.
Everyone's scanning today, even SMBs. Yeah. They're require to.
Yeah. But now the regulators starting to ask, because again, I will, I will give some more information because I think it's important. Over 60% of incidents today, and this is vouch number, are related directly to vulnerabilities that were known to the organization.
Absolutely. I think it's higher than 60. I think it's close to 80.
I'm, I'm just basing on ENT report and Verizon report. Yep. The time to exploit this vulnerability were reduced in the past three years in 90%.
Now it's less than a day. Last year in 2024 was less than three days before that it was five. So we got to Less than a day.
Remember it was 30, 45 days. Exactly. It keeps going down.
So regulators, cyber insurance, your customers want, if you have something critical, they want you to commit to an SLA and God forbid something happened. You miss your SLA, your regulators will come after to you, especially if you're highly regulated environment. Yep.
Most of our customers are biotech, financial services, health, and even SaaS company that provides services to this healthcare. And today, look, it's, it's about who your third parties are. Yeah.
Right? It's not who you are. It's who they are.
So, you know, and further down the list, And they want to get these deals, it's like, yeah, I cannot get these deals because I cannot commit. Or they're committing. But now they need to deliver a seven days or six days critical vulnerability in production remediation.
Absolutely. It's the whole, so two and all of these other Yeah. Audits.
And what we actually realize is there is a need like not in zero vulnerability. There is a need in remediation. Yeah.
And how we do what we do is basically, you cannot automate, but you can AI it. So we using different type of LLA models, we acting as an army of security engineers that going one by one of these vulnerabilities. And it doesn't matter if they have high score or low score.
It doesn't matter if they're being exploited in the wild or not exploited in the wild, they're in your environment. Yeah. And what I need to tell you, if in your environment this vulnerability is actually risky or not, and you'll be surprised how the more, the most advanced scanners, these tools that you paying million dollars to, they're giving you this list of vulnerabilities with attack path with mm-hmm.
What will happen if, but they're not correlating that with your environment. No. So you have an open SSH vulnerabilities, right.
That open SSH vulnerability have requirements for exploitation. You need to run the service with specific permission. That asset that is vulnerable need to live in specific environment, environment terms.
Without them, this vulnerability can never be exploited. And to understand that you need to send someone to do this test. Yeah.
That's exactly what our gent k uh, uh, capabilities are. Wait, I needed to say it. You said it.
We but you made a long time till you mentioned it. Look, exactly. We're here at AWS reinvent.
I don't hear them talking about cloud. I hear them talking about agent ai. So talk to me about how your agent is working to do this.
Uh, we actually announce, uh, we are going to have an announcement, uh, early next year, but in a reinvent, we doing a private preview of a new capability that was very, very interesting to all of our AWS enterprise customers. AWS investing a lot in security. Yes, they are.
And we call it native security controls. So they're allowing today DevOps and, and platform teams and engineering teams that build a cloud to build a cloud in a secure by default way. And they have a lot of native capabilities around resources.
You can build policies around services. You can have security policies without paying money, just using the native capabilities of the cloud. If you will look in this native security capabilities and you will correlate that information.
The hard work that your cloud architect actually infuse into your cloud correlate that with your vulnerability backlog that you need to solve. You will realize very fast that many of these native security controls basically reducing 50 to 60 to sometimes 70% of your attack surface. But because you're not marrying these two together, you, you don't know.
That means that you can focus on vulnerabilities that were already diffused and solved by and mitigated by this amazing AWS cloud native controls that you have. So one of the capabilities of our agenda AI is to look and understand your policies around services, resources, encryptions, VPCs, micro-segmentation in your cloud, and understand if this remote code execution vulnerability can actually exist. Even if you take into consideration these policies, most of them are not exploitable.
Right. That's the idea. I love it.
It's great. You already, you, you don't have a problem. You already solved the problem.
Right. And you don't know that you solved it. You know, some, some part of me sits here and says, did it take AI agents agent AI to reach this level?
Like, it's always bothered me to tell you the truth, why we didn't do better with this problem. Right. I I was working on it 2003 22 years ago.
It's a technology limitation. It's not a need limitation. We always have that need.
I think we've always had the need. I I always thought we didn't have the will. Right.
People, people talk a good game, but their hands don't reach their pockets when it comes time to, to really prioritize. But this makes it easier more, it, it's, I don't wanna say automated, but it, it's just, it's easier to, to do this. I You can win.
I love it. Yeah. I, I agree.
We, We are giving a lot of, I I, I'm really proud of it, but we giving more life years to our security engineering. Yeah. Every time we talk to a team and the team sounds tired and unmotivated, this is the team we want to work with.
The teams that have these backlog of vulnerabilities that every day of their life is chasing down these vulnerability. Look, this is a whole big problem. You, you've been in security long enough, you know this.
Right? The, the depression of, because for those of us who've been in security a long time, we have a lot of people in security who are, they suffer from depression. They, it, the, the issue is, it's like what does winning look like in security about that question?
I didn't get breached today. Mm-hmm. Right.
Did I not get breached? 'cause I was the zebra in the herd and the lion ate someone else today? Or because I did a good job, or I convinced my CISO and the board how to manage risk, what, you know, what's acceptable risk or not.
And, and so anything that I think I improves that is, is an amazing thing. I was gonna ask you what Zest security's doing here at AWS, but you already answered that Ben, so that's fantastic. Um, what has been, so there are security people here, but there's everyone here, there's CIOs, CI, SSOs, there's that.
Do people understand, like the security people obviously do, but does the CIO there's the cloud engineers understand what a, a load this is off of their chest, right off of their shoulders? Mm-hmm. I don't think they care.
No. I think at the end of the day, it's part Of the problem Too. I like, it's not part of the problem as much as, you know, we, me managing over 100 people, I knew everyone personally and I cared.
Right. When you walk in a large enterprise, you like many times you can't do that. You don't know what the security team in the trenches actually going through.
Even not the CSO not talking about the CEO and the CO what I, what I actually, um, what what what I like to surface is if your security team, if your vulnerability management team that in charge of prioritizing vulnerabilities and fight the vulnerabilities are drowning, which they are, it's going to bubble up into management problem. Yeah. It's going to bubble up in audits.
It's going to bubble up the way you look in front of your customers that asking you about what do you do about this? What do you do about that? It's going to bubble up when you have a red team or penetration test.
It's going to look bad when you have a customer that's saying like, Hey, I asked you about this couple of days ago, what's going on? And we're getting these emails, right? So the management team needs to look good and needs to act good.
And it's start from the vulnerability may start from the team. So what I'm, I'm basically telling this COO and CIO is like today you have a backlog of do you have vulnerabilities? It's like, yes.
Do you want to eliminate a and at least 90% of this vulnerabilities without spending money and asking favors from the CTO and engineering team without asking and pushing tickets into teams that need to build your business? It's like, yes, of course. It's like I can guarantee you that with agent AI infuse into your exposure management program, your C program, you don't need to hire 200 security engineer.
You can walk with your existing team, maybe add some more people if you want to, but you can win. If you infuse AI into that operation, you can open less ticket. But each and every ticket you give to your engineering team, that ticket was 20 or 30% of your risk reduction.
Got it. And that's what they like, they, they sync numbers. Right.
But at the end of the day, I'm helping the vulnerability management team. Yeah. And if they do a better job, the COO, the CFO even will be happier.
They don't understand that. But it's okay. That's my job to make sure that both sides agree to embrace our technology.
This will get, like, these guys will get their executive report and the vulnerability management will get an amazing, amazing tool that will make them survive the holidays. We need to survive the holidays, right? Yeah.
Always. But then there's always another holiday. Um, you know, Ben, we're running low on time.
I want to just make sure we hit a couple of things for people out there who, like what they're hearing, what's the website to go to here? io. We're very VST S tze, like the lemon ze.
Yeah. io. And we're very transparent about what we do and about our technology, and we have our customers use cases there.
Everything you need to know. It's in the website if you want to see it live. If you don't believe what you're reading, which is okay, we have a dedicated security team that can show you a 30 demo, 30 minutes demo and actually to see it by yourself.
And we also have, um, um, a free, we just announced a few months ago, a free remediation assessment, really, which is not a risk assessment. We're not showing you your problems, right. Uh, we are basically showing you, uh, the probability of remediation operation.
How can you remediate more with less? And it, it takes, I think, seven days of the platform to run, analyze, and get you everything you need without having any sales calls during that time. So Absolutely.
Yeah. Just Retesting the website. Security io.
Yeah. Hey, I think you're onto something, man. Good for you.
Thank you so much. I really enjoyed the conversation. I enjoyed having you on here.
We'll have you on again, Z Security io. Go check it out. Look, this is, this is, uh, this is kind of a holy grail a little bit if you've been in vulnerability management and security like I have.
So go check it out for yourselves. I'd love to hear what you say about it. Enjoy the rest of reinvent.
I will. Thank you. All right.
We're live. We'll be back with more Stay tuned. All right.
Today we're going to talk about what a, a topic of how to generate an sbam, a software build materials with free open source tools. So we'll just kinda get moving. My name is Josh Pressers.
I am the vice president of security at a company called ancor. We are a kind of next generation supply chain company, and we have a lot of focus on software, bill of materials, and we have some open source projects. I'm gonna specifically talk about those today.
But I am, I'm Josh. I do a lot of outreach. I do a lot of vulnerability work.
I've got a couple podcasts. I've got one, it's called the Open Source Security podcast. I do a podcast called the Hacker History.
I'm on like all the socials at Josh Bresser. I love talking about this stuff. So by all means, reach out, say hi.
I will talk your ear off about most any security topic you can possibly imagine. But this stuff's a lot of fun. So I'm really excited to share it with you today.
So let's just kind of start out our conversation with what is an SBO m right? Software bill materials. If you've been in this space for any amount of time, and you've heard about a software bill of materials, an SBO m often the comparison made is an ingredients list, right?
Like I took a picture here. This is literally a picture I took, so I couldn't find when I liked of a can of, it's, it's, uh, spaghetti sauce, I think. And obviously there's ingredients, and I picked out tomatoes specifically, and there's a good reason for this because when we think about it, our ingredients, when we think about the things in our software, like what is an ingredient, right?
What do we mean when we say that? And I think tomatoes is a great example because what, what is a tomato, right? When most of us think of tomatoes, this is probably what comes to mind, right?
Like a nice piece of fruit or vegetable, whatever you want to call it, I won't get in that argument. Growing on a plant, right? They look great, they taste great, everyone loves them, but the reality is this is what tomatoes are for a lot of us, right?
But remember, our ingredient just says tomatoes. Is it this, is it this, or is it this? And so that's what we're gonna kind of talk about today, is how do we go from an ingredients list into an explanation of what is in our software?
So now, what is an SOM? When we say SOM, we are really talking about these two data formats. One is called SPDX, the other is called Cycle and dx.
Now, you could of course get into arguments, which is better. They're functionally the same thing. SPDX and Cyclone DX are both internationally recognized standards.
They're open source projects. You can get involved, you can pay attention to them. SPDX is run through the Linux Foundation.
Cyclone DX is run through oasp, but I, at the end of the day, the thing they accomplish is basically the same thing, right? Where you somehow collect an inventory of your software and you put it in a machine readable format. And we'll kind of talk about what that format is in a little while.
But fundamentally, if someone says, I want an sbo M, what think we're gonna mean is one of these two formats, and now which one? That's the question, right? You'll find that some organizations will say, oh, we only want SPDX.
Some will say, I only want Cycle and dx. You'll most won't ask for both. Some might, but generally speaking, you'll find that every organization looking to do S bonds has settled on one, just because it's easier to deal with one format instead of both, right?
Obviously that's just the reality of computers. So when do we create these things? And now this is one of the fun topics that come up with SBOs, because there's different kind of times you can do it, right?
Are you generating SBOs from your source code? Are you generating SBOs while you're building software? Are you generating SBOs after you build to the thing you're gonna distribute to your customer or put on GitHub or whatever you're doing?
If you're the consumer receiving a thing, are you, are you generating an SBO M to see what's inside of it. And I, I stole this graphic actually from salsa, which is like a whole other open source project on supply chain security. But the graphic does, I think a nice job of kind of simplifying the various stages of software development.
And so from our perspective, we're kind of, I'm thinking of us as like the consumer, right? We're the person at the end. And so we're gonna do some talking about what that means and what we can do to generate a software bill of materials kind of as a consumer.
You know, maybe if you're a distributor, you're gonna be over here. That's a little different. It's very similar.
But once we get into like build and source things get quite a bit different. And what I mean by that is like when you have a a, a pile of source code, what are you scanning? Are you scanning just your source code?
Are you scanning your source code plus all the dependencies it's gonna pull in. Like you don't always know what those dependencies are. An example being if I install a package right now from let's say NPM, we're gonna show off some NPM stuff later.
If I install a package from NPM right now and there's an update in an hour and then I install my package again in two hours, I might get a different version. So there's a lot of weird challenges that happen in some of these stages. Build is another good one.
If I take my source code, I put it in a container. Now there's the stuff that was in the container, right? That's some new software, it's different.
So the thing I generated over here in source isn't the thing I'm gonna generate during the build necessarily. It might not be the thing generated during dis distribution because maybe I add some things before it goes out the door. Like who knows?
There could be customization. And then when you're the consumer, it can change even more because obviously, am I installing software on top? If I take a container base image, am I putting my private keys in there?
Am I putting API access information in there? Am I customizing it with plugins? It, it gets very complicated very quickly, but that's okay.
We're not gonna worry about a ton of the complications, we're just gonna kind of go go with what we've got. And then YI think a Y is the big one. And prior to I think 2025 SBOs were a novelty to many of us where we thought, this is a neat technology.
We think they're useful, they're interesting, but they're kind of a pain in the butt and it's a lot of work and I don't really want to do it, right? This is one of those situations where everyone will say, oh yes, I want security. And then you say, I need a million dollars.
And they're like, eh, our security's pretty good. It'll do, but it's kind of a changing world out there today. So compliance, compliance is why we're gonna need SBOs.
And that's just the simple answer. It's not about security necessarily. It's not about like we'll say doing the right thing.
It's, it's compliance. And the one to really keep an eye on is over here the Cyber Resiliency Act. It's called the CRA, this is a thing from Europe.
It's going to, I think, change a lot of how we do a lot of software. And the CRA has language that literally says you need an sbo. Like it says the word SBO M it's not like you need an inventory, you don't need an ingredients list.
It's says SBO M. And they're specifically calling about out SBOs in cycle and DX and SPDX format, unsurprisingly. So the CRA is going to affect an an enormous number of companies and you might say, but I don't, I don't, I'm not a European company.
This won't affect me if you are selling into the European market, you need to pay attention to this. If you have people downstream from you selling into the European market, they're going to tell you to pay attention to this because the CRA doesn't just give you like a blanket, oh, just make an SBO for your stuff and you're done. They want SBOs from your suppliers and then your suppliers will need SBOs from their suppliers.
It's kind of SBOs all the way down. So the CRA is probably going to change the way we do a lot of things. Now, the FDA is another one in the us.
The FDA has SBOs literally written into law. So this is like a non-negotiable thing, right? This isn't like, oh, you need an inventory sometimes, like you literally have to have it.
If you're doing medical device, you're doing kind of medical software. SBOs are mandatory, there are other things going on. You've got, like the United States Department of Defense is saying they want SBOs, that one is not run into loss.
So it's not quite as, it doesn't have the teeth like FDA and CRA do. But we're even seeing this in things like, you know, the new PCI, it doesn't say you need an SBO M, but it talks about an inventory of your software. You need an inventory of your software.
Guess how you're going to do it, right? I mean, same thing like FedRAMP, SSDF, this do, there's all these things happening. So this is a topic that is going to affect all of us at some point in the near future.
Okay, well how do we get started? Just pick a tool. Easy, right?
Pick a scanner and run it in. You're done. So there's a project I help with at the open SSF, the Open Source Security foundation that we call ourselves SBO M everywhere.
And we have this thing called the SBO M catalog. I've got the URL down here and the SBO M catalog has, we'll say a collection of tools in it. It is not comprehensive, it is not complete.
But these are the tools we have. And you can see this is already like an untenable list of things. How do you possibly decide which of these things you want?
And this is gonna be one of the challenges is there are a lot of tools, there are a lot of things you might need to do. And so inside of this tool you have the ability to pick out like certain features you want. Like do I only care about SPDX?
I only care about cycling dx, maybe I care about both of them. I wanna make SBOs, I wanna convert SBOs, I wanna parse SBOs. Like there's all this stuff you can do.
There's the licenses of the tools, like the actual license. The tool is you can be like, is this free? Is this commercial?
I don't know what this is. There's a supported ecosystems. We've got this huge list over here.
So this particular one is for a tool called Sift. And we're gonna talk about Sift in a moment because it is one of the tools I help work on. It is an open source tool for Manco.
It is free and it is very useful and I obviously I'm highly biased, but I think it's the best one. Okay, now what to scan, this kind of comes back to that, that salsa picture we had just a few minutes ago. And it's not as simple as just saying, I'm gonna scan a directory, I'm gonna scan a container.
There's a lot of artifacts we generate in like the world of software, right? You've got like source code repositories, you might have virtual machines, you might have like zip files, you can have tar files, you've got your container registry, which is where you store your container images. You've got like a Kubernetes cluster that's running stuff.
You might have this stuff you're getting from vendors. So like these are all things you need to think about is what is the thing I'm trying to scan. Again, not every tool can do everything.
Like as much as I would love to say, SIF does it all, it doesn't do everything. It does a lot, but it doesn't do everything. So this is a very, you have to think about what you are doing in your situation.
There's no easy answer. You might have to do some research. You can come find someone like me and I'll talk your ear off about this if you want.
There's groups like, you know, at the open SSF, we're doing this sort of work of trying to unwind some of this. There's people at oas, there's, there's groups all over the place that are trying to help everyone understand this. And I'm sure as we see things like the CRA come into force more, you're gonna see even more guidance and even more written about these topics.
So it's an interesting concept that is not simple yet. It's getting there, it's getting better, although maybe it'll get worse as everyone writes an spon tool. Okay, so to get started, we're going to install Sift.
Now sift is a very simple application. It's just a go binary one binary, right? We're not talking about like installing this big Linux distribution and putting all these packages on top and all this.
It's really small. There's a container, you can install it on your local system. There's like GitHub runners, there's CICD integrations, all that stuff, right?
But we're talking about functionally one binary. It's written go. And so it's nice and easy to install, which is one of the goals of the project is to make it easy.
Because obviously if something is really hard to install, if something is really hard to use that that's, that makes it more difficult and it it, it pushes people away. So I've got a couple videos that I'm gonna show and we're gonna start with containers. So I'm gonna hit play and I'll pause and kind of explain along the way as we go.
So if we just wanna scan a container, this is kind of what we do, right? We can just say Sift Debbie and latest and that's going to scan a, the container name Debbie and Latest. But where's it coming from, right?
It is Sift has a DA bunch of different places it might look. It's gonna look at your local Docker, it's gonna look out into registry, it's gonna see if it's, you know, on your system. We can find it.
So just saying Debbie and Latest might not do what you want it to do, but it's as simple as that. Like you can just type that in and it's gonna do what it wants. So we're gonna delete that and we're gonna say I want to use my local Docker instance to scan Debbie and Latest.
And so now I'm saying I have Docker running on my system Sift, I want you to ask my Docker for Debbie and Latest. Okay, that's not too bad. Now though, we can also ask an OCI registry.
io and download Debbie and latest from there. So now will reach to the registry and it'll pull that container in. And we're doing that right now.
We're actually scanning it. Okay, so now we can see it scanned the Deion container. There's 78 packages installed, 655 executables, you know, 4,000 files.
It's gonna give us this nice table output of the, you know, the package name, the package version, the, the thing it found. So in this case, most of them are gonna be Debs, you know, Debbie in packages makes sense since we're dealing with Debian. But you can imagine if you have Python packages installed, if you have Java jars installed, kind of, there's all these ecosystems and there's all this stuff and we're working, especially with containers, you will have a collection of random things and so it might be a bunch of, you know, DEBON packages plus the, the Python I put inside of it, whatever.
And SIF tries really hard to figure out what all that stuff is. Now I have another piece to this example which will play, let's scan the Alpine container. And Alpine for those of you who don't know, is just a tiny Linux distribution.
And so that's gonna scan obviously goes pretty quick, but now we can see 16 packages instead of 78, right? It's quite a bit smaller. We see kind of the same information and the point just being like, these are just two examples of things CIF can do.
Now I'm gonna hit play again and it's gonna run for a minute and we're gonna talk about outputting. I talked about SPDX and Cyclone dx. This table format is for humans, it's not machine readable.
So it has the ability to output, for example, an SPDX JSON file, right? Seems easy enough, makes sense. Like boom, we're done.
We have A-J-S-O-N file, that's our sbo, that's the thing we can store, we can give it to customers. Whatever we need to do with it, we can do with it. I have another example now where I'm gonna scan a directory instead of a container and we're gonna create a little NPM project and I wanna kind of explain one of the, I guess, unique challenges of installing software.
So we're gonna install this thing called Axios, which is just a, a node package I picked on it because it, it has a lot of dependencies but not too many dependencies. One of the jokes in like the node ecosystem is that you're gonna end up with thousands of dependencies. You can see I install Axios, I get 23 packages and it's like wait a minute, I installed one thing so I can look at my package JSON file and it shows Axios.
I installed one thing like what is going on? Why did this happen? And this is something sift is really good at.
in this instance and then show me what you get. We see it from 23 packages. That is interesting.
That's the same thing. That's good it matches up because sometimes it doesn't. And then you have to ask questions about why are the numbers not the same?
But again, we have this situation where it's gonna show, right? We've got the name of the package, the version of the package and then the type like in this instance NPM, 'cause we're scanning a directory full of NPM files. So this is like, this is what sift does.
It tries to go as deep as it can. It goes inside of all the dependencies. If you have like for Java jars are especially gnarly 'cause you can have jars inside of Jars inside of jars and it's like jars all the way down.
And so this is what sift does. It tries to figure this out, it tries to go as deep as it can. Now for outputs you're gonna say what should I output, right?
Sift has all these different formats that it can help output. This is actually the list I took from the dash dash help, I just made it look prettier 'cause dash dash help is kind of ugly, but at the end of the day the formats you want are Cycle and DX and SPDX, right? And I even put a, a little pointer at, I said use these two.
So they do like X-M-L-S-P-D-X is this thing called tag value, which looks like a human readable table. There's just use the JSON. And the reason I say that is most of the tools today that are capable of doing something with an SOM, they are expecting JSON because JSON one, I'm not gonna get into an argument over, you know, JSO versus XML but JSON one.
Now there is a format from sift called Sift, JSON. And this is kind of a magical format because of what SJSO does is you can imagine Cyclin DX and SPDX are a little different as all good standards are and you can't like convert from one to the other. If I say I have an S SP DXS bomb, but I wanna turn it into a Cyclin DX sbo, like there are ways to convert them but you will lose information.
They are not lossless when you convert them from one to the other. So what we did with Sift is we created this format we call sift JSON, that's just like the Venn diagram of everything. And so sift JSON can be converted to Cyclone DX or SPDX without losing any data.
S CT JSO is not a standard, do not give it to anyone ever. That is not why we did it. We did it because we needed the ability to output either format or both formats in some cases.
So if you're storing them for yourself, CIF JSON has some advantages, but if you need to give them to someone, do not give them as cif JSO like things, there are no tools except sift and gripe that know what to do with these things. So what does an spon look like? This is the just output of an spon file, right?
This is actually from that alpine image we scanned just a moment ago. And this is what it looks like, right? You've got like some metadata information, it's got package information and it goes on and on and on.
And these these files are pretty big. Like we're talking, you know, hundreds of kilobytes, maybe megabytes. There are some SBOs I've seen that are hundreds of megabytes.
It just depends, right? It depends how big the thing you're scanning is, how much stuff is in it and what you're doing with it. In this instance, obviously it's s the SPDX format, like these are not for humans.
So I would never suggest you necessarily spend a lot of time in it. However, if you are writing tools and need need to parse these, the JSON is well formed. It is easy to understand.
These are well-defined standards so you can look up documentation and get an idea of what you need to do. And there are tons of libraries, like if you are for example, writing a a Python application, a go application, and you wanna parse an SPDX file or a cycle and DX file, there are libraries from these projects that do that. So you don't necessarily have to be the one that's, you know, writing your own pares and trying to understand the JSON, which is good because they get very complicated very quickly and the standards change, they are both under active development.
You will see new versions of SPDX and Cyclone DX coming out on a regular basis. So even if you write a parser today, you aren't necessarily going to be able to parse whatever's coming out next. So this is just kind of one of those things as a developer to keep in mind.
Okay? There are also some additional sift tricks that we can do, right? We can obviously output the SBO to a file, which I showed you can put the file wherever you want.
You know, unsurprisingly, as almost any tool would do, there's excluding paths. Excluding paths I think is an underrated feature that is extremely useful. And the example I will use is literally sift itself.
So you can imagine that sift the source code has like a bunch of tests and the tests are gnarly things, right? This is on purpose because it's anytime a bug is found, you create your test. And the test obviously does something ridiculous as all tests do.
And so inside of the SIF test suite, there are like weird SBOs, there's weird examples of like applications of like package lock files, things like that. And so if you scan the sift source repository, it looks like sift has like 30 some thousand things inside of this directory. It doesn't really, it's full of test material.
And so you can imagine that when you scan something with like weird tests or just weird content, you're going to get false positives or false negatives in many instances. In this case, sift has a huge number of false positives. This is a pain in the butt.
So this is an example where like if we scan the sift uh, source code, we're just gonna say don't, don't scan the test. Ignore that stuff. That's not legitimate content.
Now obviously after we build the binary and if we scan the sift binary, which you can do, you can scan sift with sift, which is extremely amusing to me. But if we scan sift with sift like the, the tests don't get built in. So obviously they're not there.
And so we're just gonna get a list of, of what you need. Um, sift has a configuration file format, right? We can preset some of this stuff.
We can preset what directories to skip. We could tell it what output we expect. We could tell it where to store things.
These are just handy, handy tools we can use, right? That way we're not having to remember or try to not make mistakes when we type it into the future. Um, you can also connect it, you know, private registries, that's a big one.
A lot of us now have our own private registries, be it hosted somewhere else or we're hosting in-house, right? And again, you have to send credentials in things like that. Like that.
It works, it works great and it's widely used. Alright, so there's some next steps we can take as well. Automate automation is key in this day and age, right?
No one would expect you to run all this every time you do something. So one of the things you can do is like sift has an SBO action for GitHub. So you can just say, every time I build a release, build an sbo and now the SBO is part of your release, right?
Automatic, we're done. There's a bunch of open source projects doing things like that. Like python's.
A good example, the Python project is automatically generating SBOs now, which is cool. And like humans aren't involved, which is good 'cause humans make mistakes and they sleep and things like that. You can scan an SBO M for vulnerabilities.
This is probably the most widely used use case today because obviously if you have a list of software, you can say, what are my vulnerabilities? What are the problems my software has? Makes sense.
The cool thing about scanning an bound for vulnerabilities is it's really fast. If I scan a great big container, let's say it's gonna take, I don't know, 10 seconds, 30 seconds, whatever, to look for all the packages. And then it creates the, the list of packages and then we scan it for vulnerabilities.
If I already have the SBO M I've already used up my 30 seconds of compute time making the SBO M and now I can scan it for vulnerabilities usually in milliseconds. So it's a super cool feature and I really like it and it's so much easier 'cause the reality is like SBOs are static. Like once I have a list of my stuff that doesn't change, well it will change in the next release obviously, but then I just generate my next sbo.
Whereas vulnerabilities are like, the arrow of time continues to bring us new vulnerability. So the number of vulnerabilities I have today won't be the number of vulnerabilities I have tomorrow. We're adding what, like 7,000 a day or something in CBE right now, like it's gigantic.
And then store them somewhere. Now whenever people ask me like, okay, I started making SBUs, what do I do? And my first answer is like, just put 'em in a directory.
There's tooling you can use. There are applications, some paid, some free that let you like ingest these SBOs and, and do interesting things with them like scan for vulnerabilities. But to start, just use a directory because this is one of those situations where like, you know, crawl, walk, run, just start putting 'em somewhere easy.
Eventually you can, yes, put them into your NoSQL database, you can put them in your SBO management tool. You can use, you know, like Splunk at elastic search to extract information. There's all these things we can do.
But just start, don't worry about any of that stuff, right? Just start simple. Alright, vulnerability scans.
I've got a little preview here. This little guy over there on the side, that's the gripe mascot. The sift mascot was a bird with glasses, you know, many slides ago.
But this is an example where I take my, that Alpine S bomb we made, right? And we can scan it for vulnerabilities and gripe is meant to be just as easy to use a sift. We're not talking about gripe today, but I just wanted to kind of show an example where we take our S bound, we scan it with gripe, we get our list.
Obviously this is a human formatted list you can output to JSON and various other formats. Some are industry standards, some are like the gripe made up, one that can output into industry standards. We get the idea, right?
It's meant to be simple. And now we can take, if we have that sbo, we can scan it every day and we can look at what the results are. We can store the results.
We can ask questions like, what are the new things from today? What are the stuff, you know, what's the stuff I have to worry about? What are the packages I should upgrade?
Uh, alright. Now there's also, when we talk about use cases, there are many more use cases than just vulnerabilities. Vulnerabilities are just, I'm a vulnerability nerd.
So that's the one I won't shut up about. So other use cases, there is a paper from the open SSF, that group I'm involved with at the Linux Foundation, SBO M everywhere. We've published a paper recently, the title of the paper's over here's Improving Risk Management Decisions, that that's Bomb Data, which is a mouthful.
It doesn't necessarily sound like something exciting to read, it's a very good paper. But one of the things it has is use cases. And obviously I just grabbed a snapshot.
There's many, many pages that detail what this means. But there's more than just vulnerabilities, right? We've got like our CVEs at the top of the list, of course.
But then there's things like open source licenses. What are the open source licenses in your application? End of life software, right?
Do we know how old some of this stuff is? Once we know the name and the version, we can answer a question of how old is it? Where did it come from?
There's, you know, risk assessment. This is turning into a thing where companies will say, gimme your bum, I wanna see what's in your stuff. And you can be like, you haven't updated anything in 10 years.
We're not buying your software. Uh, component usage, this is a great one where the idea is how many, how many groups inside of your organization are using Axios? How many are using Log four J, right?
Things like that. And so you can be like, okay, we're using 30 versions of Axios, so what if we started using two instead? So there's, there's a lot of interesting questions you can start to ask once you start to capture this data and that that's part of the fund, right?
There's, you know, incident response is a big one. Uh, log for J was an incident response incident, right? If you had a catalog of all your software, instead of saying, I don't even know what software I have, we could say, let's go see what has log for J in it.
And, and this is actually something I saw during that was an organization had SBOs for all their stuff, and in literally like 10 minutes, they knew where lock four J was and everything. It was amazing. It was so cool.
But anyway, you get the idea, it does more than vulnerabilities. Now there's some gotchas in this data though, too. Accuracy, SBOs scanners aren't perfect.
As much as I would love to tell you, SIFs is perfect and doesn't make mistakes. It is not perfect if you run it and you find false positives, false negatives, weird bugs, whatever, like file file, file an issue and get up. We want to know, we want to fix it.
Our our goal is perfection. We know it's unattainable, but that's what we're working towards. There's things we just can't scan right now, right?
There's some archive formats that aren't necessarily supported. You're like an encrypted zip file. Like we, there's nothing we can do with that.
There's, there are things in the works, and that's okay, right? This is just one. You have to know what you can and can't do.
Every, every tool has limitations. Know what they are. There's things we can't see.
So one of my favorites is every couple months someone shows up, it's like, Hey, did you know if you delete, like your package locked at JSON, the SBO M scanners won't find anything. It's like, yeah, we know. Don't do that.
So there are malicious attempts to hide from an SBO M scanner, which will be successful. It's not that hard to do, but there's still, like, there's, there's ecosystems that might not be supported. There's some package formats that might not be supported.
So like, it's not, it, it's not perfect. Again, file bugs, we'd love to hear about it. And then convening, converting between formats, right?
You just, you can't take an SPDX and turn it into a cycle in DX at this time, that does not work. It's on the list. They're working on it.
But in the interim, this is where like the sift JSON format can be useful. So there are things, there are things you can do. It's not simple.
So kind of next steps, this is, this is some ancor links, right? We've got like a link to sift here. We've got a nice introduction to SBO M site that, that can help with that.
You know, we've got a discourse for our open source tool, sift and gripe. We have a tool called Grant, some things like that. Um, s om getting started Guide sbo SBOs at scale.
Google did a great job of that. They literally scan like millions of these things on a regular basis. Absolutely amazing.
So there's a lot of cool content. There's a lot more cool content coming, you know, if you want come find me. I'd love to chat.
I absolutely love chatting about this stuff. It is one of my favorite topics. Most people I know aren't willing to chat about it.
So please, please come and chat. But otherwise, thank you so much. This has been an absolute treat and a ton of fun.
And I hope you learned something new today. Nvidia is gonna sell chips to China. Reactive hackers.
IBM is buying confluent. Intel's not selling their networking, bu after all IBM says the data center boom is a bust. CloudFlare is gonna break the internet again.
And we're gonna take a closer look at Micron because they're moving on from consumer Ram in this week's episode of the Tech Field Day rundown. Hello everyone, welcome to the Tech Field Day rundown for December the 10th. And you know, something else that's important that's measured off in tens, that's the Dewey Decimal system.
If you don't know what I'm talking about, you should watch UHF Conan. The librarian will teach you all about the Dewey Decimal system. Uh, but luckily when it comes to things that are decimals and measuring and stuff like that, I have a co-host who knows all about that because he measures everything in science units.
Al it's good to see you again, always a pleasure to be here and particularly on National Lagger day. Uh, it is of course summer here in New Zealand, and it has just been rather hot. Uh, and so a nice cool lagger is always a great way to finish a hot day.
Well, good luck with that because you know what else we've got that's hot is some news from this week. I know you, you think to yourself, well, the, the year's winding down, how much more excitement can you pack into the last three weeks of the year? The answer, of course, is quite a bit.
We're gonna start off with probably one of the bigger stories. The Trump administration has reversed an earlier export limit and will now allow Nvidia to sell its H 200 AI chips to approved customers in China. But they are gonna keep the most advanced models from being exported.
They're still banned. In exchange, the US government is going to take a hefty 25% cut of the chip. Sales officials say that the move balances national security concerns with economic interests, but those pesky critics warn that it could boost China's AI capabilities despite ongoing concerns.
Al, do you think that it's a good idea that Nvidia should be able to sell its old busted H two hundreds to China? Well, it seems that there's confusion here that national security being absolutely vital and staying ahead of China near Pierre enemy, uh, at least potentially enemy, uh, is, is absolutely vital. Yet, if you give the corporate treasury or the government treasury a little bit more money, it's no longer a concern.
Um, seems a little weird. We've covered China's progress on AI previously and have particularly seen that, uh, Chinese chip foundries are building their own AI chips and although they're not quite up to the standard of what producing progress is gonna be fast there. So I'm not sure whether this is simply a case of the horse is already bolted and allowing China to receive some of the older, uh, GPUs from Nvidia as no longer so much of a risk because they have their own organically created GPUs that maybe are, are gonna be at least as good.
So we're, we're not necessarily letting them get any further ahead than they would've been. Of course, this doesn't cover the latest, uh, Blackwell and the, the upcoming Veru chips. Uh, those are still not gonna be allowed to export to China and China.
There's also some interesting language around export to approved buyers within China. Uh, we know that the US government is somewhat skeptical of the technology companies in China that are aligned to the Chinese Communist Party in the Chinese military. And so we wonder just how many approved buyers there will be in China for this new technology.
Of course, we've also covered in the past the ways that, uh, non-approved buyers in China and also other sanctioned states have been acquiring this kind of, uh, advanced technology despite all of the best sanctions. So I'm not sure that walls around the export of these products are working very well. So maybe just taking some money as these, uh, illegal exports or maybe, uh, restrictive exports are happening, make them legal and take some money.
That's an argument we've seen before around all kinds of, uh, regulation. There's a critical vulnerability in React server, really common web framework, and it lets, uh, attackers run malicious code using a single unauthenticated HTDP request. The, uh, floor is tagged as CVE 20 25 5 5 180 2, and it comes from the unsafe deserialization and react server components and effect a whole lot of the Java frameworks like next JS and, and vitae, uh, parcel and redwood, uh, exploit's a highly reliable, that's the last thing we want from exploit.
Uh, and proof of concept code is public making it very easy to get on board. Many apps are at risk given that if, uh, even if they don't use React directly, because they use components that themselves have react in them, admins and developers are urged to update react, uh, related dependencies and maybe imp uh, implement some further security controls to avoid this remote code execution. Uh, this seems pretty horrific to me, Tom.
Uh, I view aware of react in your environments. Uh, no, I'm not and mostly because I think 5 5 1 8 2 is so impersonal. Why don't we give it some cool name like react to Shell?
Yeah. That that's what they're calling it. This is another example of a little problem that I like to call.
Well, how could they figure that part out, part out? So you, you mentioned that there was a de serialization problem. Basically the client server connection is allowing a specifically, um, crafted HTTP packet to hijack the execution logic because it's not secured and it's not looking for incorrect data structures.
Again, I go back to how, how, how did you figure this out? I know I just threw a whole bunch of stuff at your server until it broke, and that's what they did. 0, you've got a problem and you need to upgrade sooner rather than later.
10 out of 10 is not something to mess around with. And I, I've noticed that we've seen that a lot over the last year. 8 10 out of 10 because they are so easy to use.
This is not one of those things where, you know, it's a, it's got a high score, but it's so difficult to like, you know, gain access to the data center and put a CD in the drive to hack it. No, no, no. This is pretty easy to pull off and it's almost 100% effective, effective on the effective versions you've got to upgrade and don't just assume, oh, well I don't use React.
Figure out what software you have do does use React. You mentioned next Js Wu, uh, Redwood, SSDK. There's a whole list that is a huge mess that you're gonna have to sort out.
You've got to go upgrade these things because if this is as easy as it looks in the proof of concept, you're probably gonna get owned before you know what's going on. So don't, don't walk, run. And I know you're probably on change freeze December, but security patches are, uh, probably an exception to that rule.
IBM is set to buy data streaming company cofluent for $11 billion in cash. They're aiming to strengthen their AI and cloud services with Confluence real-time data technology. This is the biggest deal that IBM has done in years, and they're expecting to close it sometime in 2026.
The intention is to improve how businesses feed data into AI systems and analytics tools. This one hit in the morning, uh, this morning and it was kind of interesting to see how it went from, well, there's a rumor that this could possibly happen to within a couple of hours. It absolutely was gonna be happening.
Al do you think that IBM making this big acquisition is a good move for them? I think it is. I think one of the things we've seen with IBM is that they've recognized that getting into new markets that transforming IBM to be relevant in the cloud and AI world is not just a matter of big science projects that they've done in the back row, but it's also about finding innovation that's happened outside of IBM and acquiring that, that innovation.
Uh, the last huge deal they did, of course, was acquiring Red Hat in 2019, which was very much a recognition that, uh, Linux systems and large scale deployment of Linux systems is vital to having any kind of cloud estate and that IBM needed some presence in that cloud estate or highlighting also that last year, uh, IBM acquired HashiCorp, who, uh, have a whole bunch of tools for helping developers and infrastructure professionals work at cloud scale on things that aren't necessarily restricted to, to just public cloud can also be on premises. So we're seeing this as part of the, uh, approach that IBM has shifted to from let's build everything in-house, let's lead by being the most expert and, uh, understanding by building our own things to let's also acquire things from outside that are gonna be valuable to build our portfolio. And I think it's a really good thing.
Uh, I was interested that $11 billion was the price for Confluent and Confluent is, uh, essentially a managed services tool manage management tool for dealing with Apache. Kafka itself is an open source, uh, and free software tool. Uh, it is probably one of the most widely deployed tools for dealing with large volumes of streaming data.
And this is, as I play into ai, this is about data that's coming into your organization and large volumes, but with what I characterize as low value per unit of data and using AI to translate that into actually higher, uh, value data in, in smaller volumes. So getting, handling large volumes of data, feeding it into your AI pipeline absolutely is part of how people are, how businesses are going to get value out of AI long term. Dealing with that huge volume of, uh, business data and logistics data and even operational data and trying to make sure that we can efficiently operate at large scale.
This is absolutely where IBM should be playing. So really glad to see this acquisition. Of course, it's great news for Confluent.
Uh, the offer was at a roughly 34% premium on the stock price that Confluent had when this was announced. Of course, confluence now trading up 30% matching up market loves. Uh, yeah, seems like a really good move for IBM and should bolster the deployment of IBM software and solutions into cloud hungry customers.
And of course, ai. 'cause we can't have a story without AI in it. Intel has decided maybe not to sell or shut down its networking and Edge Group, the NEX group after all, saying that the unit's important for integrating its chips, software and systems across AI data centers and Edge computing, uh, talks with Ericsson about taking a minorities stake in, in next have ended and the business unit will remain a part of Intel as the company reinforces under its new leadership.
Uh, the reversal comes as Intel's finances improve, and so it's requirement to sell off assets comes away 'cause of investments by Nvidia, the US government and SoftBank, uh, gives Intel a bit more space, a bit more breathing room to rebuild its strategy and focus on the core things that make Intel unique. Uh, seems like lots of up and up for Intel in the last couple of months, Tom. It has.
And that all comes thanks to money. It's amazing how that fixes almost all problems, right? This very much comes down to Intel looking to offload a business unit because they needed cash because they were not doing so well in the first half of 2025 and then round about August or so, suddenly some people are interested in them.
We've seen big investments from US government, from SoftBank, from Nvidia, from a lot of companies pouring billions of dollars into Intel, which has allowed them to renegotiate some deals, which has allowed them to say maybe we need these pieces after all. I get it. Originally the idea was let's get rid of anything that's not a chip making business and toss it out to see who will buy it.
In this case, Ericsson really wanted this networking business unit because we need the cash to bring all these foundries and factories online to be able to continue business. But again, with an infusion of a few billion dollars into your capital fund, turns out you can do a lot and not have to sell off everything that's bolted down. I, I applaud Intel for sticking around here because one of the things that this provides is not just networking.
These components are manufactured and integrated into a lot of things. We've talked, you know, over the year about how Intel has been forced to cancel products, has been forced to lay off thousands of workers. I think that the, the Tide has finally turned for Intel.
I mean, I saw a report yesterday that there's a good possibility they might actually end up shipping one of those gaming gps that they've been trying to put out for a while that could give them bolster in the market to open up a new line of business that will then allow them to take in some money, maybe get those foundries online so that companies like Apple will start buying chips from them again. And once they're back on firm footing, that really will give them an opportunity to shine. The question is, will it be enough to topple the rest of the companies in the market who are screaming ahead, selling things that are not boring old gaming GPUs and edge networking gear, because we all know that everybody's hot for AI right now, and that's not an area where Intel's really focusing.
I think what they're doing is they're providing an alternative in the country to manufacture those chips, to manufacture those devices that would potentially avoid tariffs and other things like that. I'm glad Intel's holding onto it. I hope Aons not too disappointed that they're not gonna be able to buy it out.
But look, folks, it's a good possibility that if this, if all of this goes sideways, you may get to pick it up cheaper than you were hoping. We're gonna go back to IBM because CEO Arvan Krishna argues that the data center industry's massive AI plans really don't make economic sense. He estimates that it would take around $8 trillion to build the capacity that companies are currently promising.
He says the odds of reaching artificial general intelligence soon are about 1%. Data centers are gonna need to be rebuilt every five years and the revenue that they generate can't cover the debt that you need to fund them. Krishna's warning echoes a growing consensus that the current AI build out might be a little bit over hyped and that financially unrealistic goals, uh, are there unless major technological or economic changes occur.
Al this isn't the first time that we've heard somebody throwing cold water on the current AI planning, but it's the first time that we've heard the CEO of a large company involved in the whole market tossing what it bounced to a pretty big pale of cold water on it. Do you think Arvin Krishna is onto something here? Well, I think it, it lines up with what I've been seeing that a lot of the AI hype seems to be talking about a continuous exponential growth forever.
And anybody who's looked at exponential growth knows that it can't go on forever. Uh, sooner or later you end up with, uh, needing more resources than exist to support that, that growth and with exponential growth that happens really fast. So this idea of, uh, needing $8 trillion to build out all of the data centers that are being committed to that doesn't actually seem unreasonable.
The math kind of adds up that, that's the forecast. So where is the, well presumably two to three times that much, 16 to $24 trillion worth of value coming, $8 trillion to build out the, the infrastructure. You'd be better be getting a multiple of that back in terms of value to business.
And that's where I see the big challenge at the moment. So simply going by this, we're gonna exponentially increase the amount of resources we use to build ever bigger and more complex things that just doesn't stack up for long. Uh, it it absolutely works at the beginning.
What's likely to happen along the way? Well, people are gonna run outta money, people building some of these infrastructures. Now, it's not gonna be the really big companies, the, the really large companies building up these infrastructures have have deep pockets.
They don't run outta money fast. It'll be the smaller, uh, I'm expecting to, to see some of the neo cloud struggle. Uh, maybe their exits will be to sell their, the capacity they've built to these larger companies that are promising to deliver these huge amounts of capacity.
But I'm expecting to see some, some changes in there. What I'm really hoping for is a fundamental technological change. That means we don't have to continuously go with this exponential growth building a model that is 10 or a hundred times as big as the last model that we built in doing this every 18 months.
That's what's driving this exponential kind of thing. My other concern about it is that these models are supposed to be built on human created content. And I think deep seek was the first model that we saw where the, the content that was being used to build the AI was generated by ai.
By ai. And that's seems like a sort of, uh, robber, a snake eating its own tail situation where you eventually run out of anything that's valuable. You, you end up with a completely garbage model because it's being fed so much AI generated content.
And we know AI generated content is currently not nearly as good as human generated content. So there's some, some interesting things about how this market's gonna play out. I continue to keep my fingers crossed for some technological shift that will get us away from exponential growth in order to get not exponential improvements.
There is definitely a challenge with the size of data centers, the amount of power those data centers are gonna require. And then that financial challenge of replacing them every, well Ivan said five years, maybe it's as quick as three years because that's the pace at which GPUs become outdated and need to be replaced to be cost effective to continue to use. Uh, no, whenever somebody tells you there isn't a bubble, it can't possibly be a bubble, uh, it's quite often is a bubble and maybe we'll see this, uh, come back down again.
My hope is we don't see a huge loss of business value. We see new technology that allows us to deliver more business value without more cost. Often a requirement that we're looking for in this business.
Hey, remember that? React to shell vulnerability, kindly titled CVE 25 20 25 5 5 1 8 2. Uh, well, it's being actively exploited by China linked groups and it's attacking all kinds of tools.
I think this is gonna be, uh, our next, um, log for JS Turkey hunt or, uh, Whack-a-Mole trying to find all of the places, uh, cloud CloudFlare forced a global outage to block these attacks because of course you inspect the attacks and say we're having those. Um, and AWS is warning organizations to patch immediately. Experts say rapid AI assisted weaponization of vulnerabilities is becoming the new norm.
Just when you thought security stories could avoid the trap of ai, Tom, here it is for you again. Yeah, you're probably thinking to yourself, didn't Tom just talk about this? Yeah, but I'm not talking about the vulnerability.
I'm talking about the response to it because what happened, CloudFlare shut down to block those incoming connections because one of the things that you see a lot when you have one of these brand new zero days is you have a bunch of people that are trying to make as much hay about it as possible as quickly as they can. And that's exactly what happened here. Everybody rushed out and tried to use it as an attack.
Well, the downside of having CloudFlare as your is your, uh, proxy layer, if you wanna call it that, is that when CloudFlare goes down like it did a few weeks ago, it can knock the whole internet offline. The good news about having CloudFlare as your proxy layer is that when they detect spikes in traffic that are related to certain things like this, they can do something about it. Now, you probably are thinking to yourself, well, CloudFlare didn't go down.
You're right. It didn't go down for long because all they had to do was drop all of the current connections and then institute rules that prevented react cer sessions from flying all over the place using malformed packets. Pretty easy, huh?
The AWS component of the story is even more interesting because, you know what I would do if I was AWS to limit my liability for all of these things, if I detect that you're running a vulnerable version of React, I deny incoming connections to your cloud until you patch. That is the new area that we are gonna live in. We are going to be at the mercy of our providers because I don't think AWS or Google or Microsoft or Oracle or IBM or anybody who runs a cloud wants to have that much extra exploitation traffic running across their network.
And so if they have an opportunity to create some momentary pain for their customers, for the good of them, then take your castor oil and be done with it. Now, I, I don't know if if Amazon's gonna go quite that far, but I wouldn't doubt it. Maybe the next time this rolls around or sometime in the future that they're willing to say, Nope, enough is enough and we're gonna make you fix it this time.
We'll have to see what happens. But, you know, hope springs eternal. Right?
We've got a story that we wanted to take a closer look at because quite honestly, I haven't gotten off of my soapbox yet. Micron is leaving the consumer memory market that would be their crucial brand. Now you're probably thinking to yourself, but Tom Crucial is one of the biggest memory sellers out there.
Why are they doing that? Oh, it's because they've decided to focus on high bandwidth memory for AI data centers. The company is gonna continue to sell consumer products until February of next year, 2026 probably because that's the stock that they have built up.
And you may recall in the news over the last couple weeks that you've heard that there is a global RAM shortage. High bandwidth memory sales are growing super fast and that means that AI focused memory is more profitable than consumer products. Hence Micron deciding that now is the time to exit stage.
Right. Al I'm gonna let you start off on this while I put an extra level on my soapbox. Do you think that this is a good move for Micron?
Good for micron? Undoubtedly they're doing this because they get more money per gigabyte for more money per wafer producing high bandwidth memory than they do producing consumer round. Uh, bear in mind that the same foundry that makes the this ram also makes SSDs.
Mm-hmm. Now crucial SSDs also gonna disappear to make more high bandwidth memory. Uh, it's absolutely good for, for uh, micron, but for consumers.
Yeah. I'm already hearing stories even in, in the Discord servers that I'm on that are completely unrelated to, to computers and ice. Hey, I'm hearing stories of people basically making decisions not to buy new computers 'cause RAM costs so much and they simply can't afford to buy enough RAM to make the upgrade worthwhile.
Uh, this is something that we're seeing from essentially that massive demand for AI resources. It's taking all of the oxygen outta the industry and it's now affecting consumers as well as professional organizations. Uh, when can we see an end to this, this tightness that we're seeing in, in the RAM market?
Well, there need to be new foundries for building ram or there needs to be a decrease in the demand for high bandwidth memory. Um, I don't see new foundries coming online fast. They take quite a while to build.
So foundry capacity is definitely a, a limited resource. Uh, hopefully there's some of those foundries being built in the US that will come online not in the next couple of years. Uh, so yeah, this, this, uh, shortage of server ram and then the flow-on will be SSDs is is gonna be with us.
It's going to have some impact on us as long as AI is soaking up all of the high bandwidth memory resources that are available at a high value. Um, Tom, have you got that second box on your soapbox? So, uh, you can take a whole other tack on this.
Yeah, this is the turning into a CrossFit soapbox right now. Uh, I think this is actually a terrible decision by Micron and they're not gonna know it for another two quarters, so that's might as well be in the next century as far as they're concerned. Um, I think about it like this, uh, there's this influencer culture out there, right?
Um, obviously we're influencers in the tech space. And, and that's why we have this, uh, podcast. But I want to think about the people who do like the influencer thing, where like they, they order a bunch of like cheap clothes from Amazon and then they try them on, right?
You've seen these halls, right, where there's Temu or Sheen or Amazon or, or whomever. And a lot of times what happens is when the influencer starts out, they're buying the affordable stuff, right? You know, this is a $3 top, these are $5 shoes and whatever, and they get popular because everybody wants to see the cool new looks or whatever.
And then they start getting sponsored, and then they start getting brand deals. And the next thing you know, they're not opening $5 shoes, they're opening $500 bags. They're opening thousand dollars coats because the people who sent that to them want to show off for this big audience.
Well, what happens when that audience suddenly thinks, well, these people are not speaking to me anymore. They're chasing the big dollars, they're chasing the clout. I'm not gonna follow them anymore.
This is actually a crisis that's going on in the influencer culture right now because of that very thing. They've gotten too successful. They've, they've tried to get too much money from everybody, and in doing so, they've wrecked the audience that got them where they are.
Do you see the parallels in this story at all? I know you do Al I mean, I'm talking to the people at, uh, at Micron right now. Um, do, do you see the parallels in that story?
Lemme give you a hint. I need you to, to close the email chat that you have with your stakeholders for a minute. Your shareholders, they don't matter because in three months you won't matter because once you've sold out of all of the ram that you have in stock for your consumer markets, yes, nobody's building new PCs right now because they can't get ahold of the parts because there's no ram, there's no video cards.
Well, that, that's actually not true. There're starting to become a lot of video cards that are still in stock. They're just too damned expensive.
What's next? Like Al mentioned, maybe the hard drives are next. Who knows?
Maybe monitors are gonna go out, I don't know. But when nobody's building new PCs because they can't afford it, because they can't find the parts, that means that nobody is going to be putting money into your company anymore. Yeah, yeah.
You're gonna be living high off the fat of the land while you can build more HBM and sell it to Nvidia a MD. Qualcomm got news for you guys. Nvidia may be trying to buy as much HBM as they can right now, but do you know what happens when there are only one or two companies in a market?
They can dictate the price. Could you imagine what would happen if Nvidia pulled a Lee, a Coca and walked up and said, I will buy Ram for you for a hundred dollars a stick. And you're like, no, HBM costs $500 a stick.
And Nvidia says, no, it costs a hundred dollars a stick because that's all I'm going to buy it for. Case you're curious. That's how Le Koka ended a uh, UAW strike.
He walked in, he said, I have a whole bunch of jobs for people that wanna earn this much money, but I don't have any jobs for people that wanna earn what you're asking. Nvidia can control your market. Well, who are you gonna fall back on?
Oh, that's right. You can't sell the consumers anymore 'cause you killed off that brand because you turned all of your printing presses into business focused printing presses. Now, the stakeholders and the shareholders are gonna tell you, this is a brilliant move because there's more margin in Ram right up until there's not.
What's the old quote about going bankrupt? It happens slowly and then all at once. Well, what's gonna happen to the demand for HBM?
Well, it's gonna grow slowly and then fall off all at once when nobody has a market for these things anymore. And when nobody suddenly wants to have AI accelerators because they can't figure out what to do with them, then what are you gonna do? Oh, hey, we're bringing the crucial brand back in three or four months when we get the things moved back over to making consumer Ram again.
I hope there's still a market for PCs. I hope the Steam machine and the PlayStation five haven't wrecked everybody's desire to buy a machine now, because I promise you the people who are doing work who are writing all that code for ai, they're buying laptops that already have RAM integrated into it. They're not buying the Ram individually.
You know what's gonna happen? All the people who are building these PCs to play games are gonna move on to do something else. And then Crucial is not gonna have a market to go back into because the two or three companies that are left speaking to those hobbyists are gonna be selling it for whatever they can.
And your big market, your high margin market is gonna go poof there. I've jumped onto my soapbox. Well, it's always good to have you on your soap soapbox for a little while.
What's also always good is having Tick Field Day events to look forward to. We're gonna take a little break from events over the holiday season. We're gonna return at the end of January.
I'm going to be hosting AI infrastructure Field day four in, uh, Silicon Valley, January 28th to 30th. It's looking to be a pretty packed schedule as we've seen on the rundown. AI gets everybody to the, uh, to the uh, uh, and then of course I'll be back for Cloud Field day 25 in March 11th and 12th.
And there seems to be a month in between. And it's February. And we have a couple of things that might just turn up on the Tech Field Day website in February.
Keep your eyes open for those. There might be, uh, familiar things coming back again. I think, uh, there should be some really fun stuff in February.
We will of course have a schedule of events right through 2026, uh, for us to have lots of fun at as, as the year progresses on lots of, uh, security events. I know there's more AI events to come. Uh, so thank you very much for joining us for this episode of The Tech Field Day Rundown.
It's awesome to have you with us. This we run down the news of this week. Of course, you can catch the new episodes every Wednesday, eyes at a YouTube video or in your favorite podcast application.
Make sure to give us a like and, uh, nice review as you are following us there. The rundown is also streamed on Techstrong TV because of course we are part of the Futurum Group. And you'll find Tom and myself as well as Stephen Foskett on various of the Futurum Group programs.
We will be back next week on Wednesday to talk about the IT news of the week. Well, in fact, we'll be back on Wednesday to talk about the news of the year. That was Tom and I will wrap up the year with a review of the biggest things in the year.
That was until then for myself and for Tom Hollingsworth from all of us here at the tech Field aid team, we're wishing you and yours a great day and a great week. We'll talk to you next week. This Isn't steady evolution, it's collision and what comes next will be defined by how we steer through the impact.
Hey everyone, it's shimmy. Hope you like that little AI video we did there. Of course, that was a fake of me on the video, but this is the real shimmy right here.
And you know, this week's episode is a fun one. I think it's called Shimmy Says the World, according to me, if you've been following what I've been writing and speaking and doing videos about over the last couple weeks, you know, sometimes you get lost in the forest for the trees because I write each piece and I do each segment based upon something I see or something I'm thinking about. And I I get in on it.
But when you step back and look at the bulk of it at the body of it, you see there's a pattern there, right? And, um, today I'm gonna be specifically talking about the last, well, not the last couple, but some of the last articles and segments I've been doing, right? The dealt around, uh, AI of course, and data centers.
And what I saw at AWS reinvent and what I've been hearing and seeing and reading about the VC market and the the economic market in general and a potential bubble, or at least how AI is driving the economic e economics here. And I want to talk a little bit about a crazy how far we've come in robotics and what we're seeing there. And then how do we be responsible?
How do we be mindful of all these things to make sure that we we do it the right way? And that one day when your children or grandchildren ask, what did you do when all of this was happening? You could answer with a clear conscience that said, I helped and I did the right thing.
Because make no mistake, what all of this adds up to me, guys, is we are at the dawn of a new era in so many ways. You know, I remember when the 20th century turned into the 21st century and I kept asking, when are we gonna stop living off of what we did in the century before? You know?
'cause even the internet was kind of from the nineties, cell phones were from the nineties. Cloud was a 21st century thing. But really where we are now with AI and robotics, and I think quantum is, is going to define the rest of this century, or at least for the next 30 to 50 years.
So, you know, it, it's not good. What I get excited, it's not just one thing. It's like multiple tectonic plates coming together, causing massive earthquakes, volcanoes, all kinds of disruption.
So don't, you know, you are not alone feeling that the ground is shifting under your feet. It is. That's the kind of thing we're seeing.
And that's what Shimmy says. And this is the world according to me. I wanna start with an article I had written coming out of, uh, some comments by IBM, uh, CEO Arvin, uh, Krishna's comments.
And, you know, he, he wasn't afraid to say that the emperor forgot his pants, that in all of this talk about an $8 trillion data center build out and, and all of the great things that can come, he thinks there's like a one to 2% chance that we actually achieve a GI given current levels, um, current technology, that the cost of these data centers, the economics and IBM is a company that knows something about data centers just don't add up. And unless something fundamentally changes, it's broken. And sooner or later someone's gonna pay the piper for that.
Um, we've gotta, we've gotta figure it out. 'cause this is not just being a skeptic or, or pundit. It's, it's arithmetic guys.
And so I think we need to, you know, that's one factoid that we gotta put in our pipe here to smoke. Um, secondly, I was at Vegas last week with 60,000 other people or so for AWS reinvent. And it was painfully clear AI AWS came out of the chute and they wanted you to know one thing, they're big, they're bullish on agentic ai.
It was agentic ai, all agentic AI all the time. At least you would get that from the keynotes. It's when you peeled the back a little bit and went to the sessions when you spoke to people in the hallways, when you spoke on the floor that you saw that this whole AI and this agentic AI thing doesn't live in a vacuum.
It's not just gonna work on, on Nvidia processors and Cuda, right? There's got the, there's the train, there's the inference, there's so many things going on, but it's built on cloud. It's funny you didn't hear the word cloud very much as you would think at an AWS conference 'cause they were so busy talking ai.
But this whole thing is built on the cloud. It may not all be public cloud, it's hybrid, it's multi it's edge, it's everywhere. But it's built on cloud.
It's built on DevOps. It's built on platforms. It's built on cloud native, it's built on the building blocks that we've been building our technology on, the infrastructure that we've been building on all along.
It sits on top of it. It doesn't replace it. So I think that's important to remember these, these other communities, these other talents and skill sets will be enhanced by ai, but not replaced by ai.
So they're essential. And we may not mention cloud as much as we can, but you can't take the cloud outta cloud. And, and that's a, a, a point there to say, okay, next, here's a clear sign of the bubble.
I read a, I read a, uh, an op-ed over the, over in the New York Times that caused me to write one. It was about VCs chasing AI startups. They had one VC who was driving a, an entrepreneur to his rock climbing session because that was the only time the entrepreneur had to talk to the vc.
It used to be a time where an entrepreneur would, would give their eye teeth or some other body part to have to be able to get a VC's time to sit and pitch them and tell them about their product. But that's turned on its head. The VCs are chasing the entrepreneurs now trying to give 'em money, whether it's going to a rock climbing session or another example in the Times article.
They're flying entrepreneurs out to Vegas to drive Ferrari, right? And then while they're driving the Ferraris, or on their way back and forth trying to get 'em to sign a term sheet, they're not doing due diligence. They're not, you know, this is like vibe coding your VC business without testing.
It. Don't make sense. com bubble.
So to me, this screamed like, what the hell's going on? Two one, and I wrote an article about this. You can find it on, uh, on text strong, uh, it or text strong ai, excuse me.
And, but you know, the, the, it's one of two things. Either, you know, the old saying, a fool in their money is quickly parted or something else is going on here and it, it's something else is going on here. So, but we've seen how this plays out before, right?
And it, and it works, works its way down. And guys, when I wrote this and what I put in there, please go read this article 'cause it was really near and dear to me, guys, I've lived this for 20 years, right? com bubble.
I did companies then I, I saw how it trickled down. And you know what, the VCs are fine. Their model is, if they get one outta 10 companies that do a 10 Xer or even even a little less than that, they get a few singles and doubles.
It's okay if they get a lot of failures. And you know what the founders look, they're playing OPM other people's money, right? And so if things go south, they'll go found another company.
In the meantime, they made a nice salary and then maybe they'll get something salvageable and come out of it. You know, who really gets hurt? You do.
The workers, the workers who get promised the stock options and stocks take a flyer that this thing gets a great exit work for a little less work a little harder. It's the workers who get caught. Yeah, there'll be some of you who are lucky who get the Willy Wonka golden ticket.
But you know, those are the minority, those are the lucky ones. Not everyone gets the brass ring. So, you know, you look at, uh, Arvin Krishna and then you look at this VC article, and we may not have an AI tech bubble 'cause AI tech is real, but we may have an AI financial bubble and someone's going to get left holding that bag.
The next thing I want to talk to you about is physical ai, as some call it, I call it robotics. There was an article, it wasn't by me, but it was on our tech strong ai, I think it was by John Schwartz about, uh, over in China. They, they had a, uh, demonstration of a couple of their leading robot companies.
And you know, here in the US we, we have Boston Scientific, we have figure, and we have the Tesla robots. China has their whole own robotic economy rocking. And what they showed was absolutely scary legions of robots goosestepping in unison, like a military, you know, it, it was right out of attack of the clones in Star Wars.
They had another robot that looked like a T nine at a Terminator. Man, this guy, you know, and there's no doubt they could break your bones and, and he looked mean, or it looked mean. Then they had another robot that was a agile enough to like do jujitsu with you.
Man, this isn't that clunky. You know, like we saw at the Russian demo a month or two ago, they marched at a robot who fell flat on its face and had to pick it up and walk it off the stage like it had too much vodka. No, these were Chinese ninja warriors doing kung fu and stuff.
And, and they did it well, it was absolutely scary, right? The question becomes, what are we using robots for? Are they tomorrow Cyborg warriors?
Are they butlers? Are they manual workers? All of the above.
Look robots paired with AI could be a bigger influence on our lives as humans, on civilization than on how we're using AI to even develop software, which is where the bulk of our kind of attention is right now. But guys, don't sleep on the robot revolution. It's happening.
And it is crazy. So another, you know, a couple weeks ago I was on Shimmy says here, and I, and I talked about tech used to be the good guys, right? We got all of this promise, all this potential.
Are we going to use it to just make a couple of tech bros, couple more zeros at the end of their billions? Are we going to use it for the good of humanity? Right?
And this goes back to what I said in the beginning. When your children and grandchildren ask you, what did you, what did you do when, when things were being formed, when it was still moldable, did you help or did you just ride that gravy train? You wanna say, I was responsible.
And so I was really happy to see the launch of something called the Resonant Computing Manifesto that really brings this home. We need to be responsible the tech industry. It's, it's our destiny.
It's our, but it's more than our destiny. It's also our heritage, right? So from the beginning to now to the future, we have an obligation to do the right thing here.
Don't let the tech bro sell us out for 16 pieces of silver to, to the government or anyone else. We, we have got it while we can. Right now is the time to make sure we do this in a meaningful, impactful, responsible way.
So, and I, I wrote an article on this also on the manifesto moment, resident computing. So I, you know, please check that out. So I've been busy, boy, I've been a busy boy.
What does this all mean? I think you take all of these pieces together, you start to see the patterns. There's an emerging view here of a new world, a new era, right?
AI is advancing faster than our infrastructure that's gonna be required to power it as we've gotta get that aligned. Cloud DevOps, cloud native platform engineering, agile, all of the ways we've been building software all this time ain't going away. We gotta double down and use that.
Leverage AI with it. VCs here are Overclocking. If you remember Overclocking CPUs, they're overclocking and overheating the moment, right?
John Chamber said it. He doesn't think the AI bubble burst in 26, but there's gonna be some violent collisions. There's gonna be some big winners, there's gonna be some big losers.
The VCs are okay with that. The founders are okay with that. You've gotta be okay with that.
AI is embodied, embedded, and becoming part of the fabric of everything. We do embrace it. We don't have the guardrails to do that now.
We need things like that resonant computing manifesto to make it happen, right? As an industry, the tech industry is facing its biggest sc scaling challenge. Since the birth of the internet, enterprises are being forced to rethink architecture.
Regulators are gonna be scrambling to catch up. They're gonna be three years behind. And all of us humans, humanity, we need to decide what role we play in a world where intelligence is no longer solely biological.
So what does this mean to you? I'll tell you what, if you're a practitioner, a leader, a founder, or an even just an enthusiastic enthusiast watching, here's the deal, guys. Your skills are more valuable than ever, but you can't sit on them.
You gotta advance them. You gotta incorporate AI into it. You can't sit this one out.
If you think you're gonna sit out the AI wave, your rip van Weel, and I'll wake you in a hundred years and you're obsolete. Get curious about constraints. Understand where the boundaries are.
Be intentional and responsible and meaningful about the systems you're building and what you're working on. Because here's the truth, man, the future's not being just handed to us. We're building it in real time.
In real time. And the values we embed now will last for decades. So where does shimming land?
We're at a crossroads. We're at the dawn of a new era. It's a rare, maybe once in a lifetime moment for most of us, not as companies, not as governments, but as builders and as humans, we need to set the right tone for the next half century.
It's not about greed. Um, ai, cloud, robotics, the economics. They're not separate stories or silos.
Just like DevOps bust down silos, we've gotta bust down the silos. This has to all be coming in here. 'cause history, his, as I said before, history is gonna ask a simple question.
When the foundations were still wet and the future was malleable, what did you do? Ask yourself that. What are you doing?
My hope in Shimmy's world, according to Shimmy, is that we choose stewardship over speed, clarity over chaos, collaboration over fragmentation. Because the next era of tech isn't just about innovation, it's about responsibility. And that folks is the world according to Shimmy.
Have a great week. I'll see you next week.