Techstrong TV – December 6, 2024
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everybody, welcome to the Textron Gang out, Mike Baard. And we got a little bit of everything today. We got Espionage Cyber Monday and some cloud native app dev stuff.
So we'll be back in a minute. All right, welcome back. And the A block.
Well, it's pretty serious stuff. Uh, there's all kinds of reports coming outta Washington about the extent to which the Chinese may have compromised our telecom networks. Of course, this has been going on for months now, at least.
Well, it's probably been going on for years, but, uh, we've been aware of it for months, and yet we don't seem to be making a lot of progress. And then suddenly somebody appears to have, uh, made some closed door testimony to senators and Congress and everybody's flipping out. Um, John, you know, what is up with this whole issue between us and China and espionage?
It seems like we've known about this since. I don't know. I remember John Chamber screaming about this stuff and Yahweh equipment, and we had money set aside to get rid of all this equipment, and yet it's still in there.
So what's our problem? Oh, It, Yeah, it's been going on. It's been going on for years.
There's this, this form of warfare, digital warfare, asymmetrical warfare that's been going on between the US and China, and to a lesser extent of Russia and Iran. And this latest example, you know, Mike, I have to admit that I got this confused with yet another breach that we can talk about. But this one in a sense in involves several large telcos, which evidently this started in the spring, if not earlier, and it's still going on.
Uh, SEA admitted, which has led to all sorts of angst and, uh, a rare joint advisory between the FBI and NSA recommending that people should use strong encryption. Yes, strong encryption to battle this group that's called itself Salt Typhoon. So in recent months, this group has gained access into it environments of several ISPs.
And, um, there, as you mentioned, there was a US government agencies held a classified briefing, I believe it was on Wednesday. And, um, was it the F-B-I-D-N-I-F-C-C-N-S-N-S-C csup, they all got together in a closed door briefing to talk about this. Um, you know, one thing I was gonna mention, there's a group, not Saul Typhoon, but something called Full Typhoon, which, um, the FBI director Ray, referred to as the defining threat of our generation.
And that in included a Chinese sponsored group that was focused on prepositioning themselves within the US critical infrastructure to launch cyber attacks in the event of some other major crisis or conflict with the us. So, as you said, this has been going on for years. I think it's gonna escalate given the political climate and, um, the uncertainty around tariffs and ai, et cetera.
It's just, it's a can of worms and I, I don't know if we can put the top back on it. Uh, Mitch, you've been around this space forever, but, um, what do we gotta do here? Do we just gotta rip out all the gear that we got from China that's in those networks?
Or is it more complicated than that? Well, lemme just comment on it first. First of all, we've taken our eye so far off the ball on this and not paying attention to it.
We've been, you know, goofing around with, you know, the election and insurrections and whatever and all this other bologna. And this is serious stuff. This is, this is a far five alarm fire.
And I'm not trying to just be hyperbolic about it, but let me be hyperbolic about it. Everything touches our, our telecommunications networks and our telecommunications networks touch everything. And this isn't a hack, this isn't like I'm stealing credit card data and social security numbers.
This is, this is an infiltration into our networks. It isn't one server that got hacked and then they did something. This is them getting into those networks, not only gaining control of the things we know about, but getting themselves into other systems and servers.
So it isn't just computers, it's applications, it's network equipment. 'cause all, all of these networks now are software defined networks. They're software elements.
They're not hardware gear like they used to be. So it is, if you can get in and move laterally, it's not just move laterally one direction, it's 360 degree lateral movement all across these networks. And I think, I, my prediction is we will find this is 100 x more extensively infiltrated than what we're reading about in the media.
So I, I'm serious. This is, this is deadly serious stuff. So you wanna see airplanes starting to fall out of the sky.
You wanna see money go missing in, in financial transactions. You wanna see your 401k disappear. You want to see our military, um, you know, become ineffectual.
You know, while we're goofing around with who should be the defense leader or the, you know, CAA, whatever this is real stuff. This, they're, they're, they are doing some real serious damage here. And it's, and it's a low and slow kind of activity.
That's what's hard to detect is when something takes months to do, it's kinda laying in weight, right? And when you see it, it only is such a big thing because it's happened over such a long time before we've discovered it. So we need to get serious about this or, uh, we may, uh, the electricity lights may go off.
Yes. That, that's interesting that you mentioned that mish, because years and years ago I went to this summit, uh, I was invited, uh, on backgrounds. It was in Monterey and there were defense department officials there, various people from the, the Pentagon, et cetera, private enterprise.
And they were talking about this is pre AI's growth. And they were talking about, uh, our water supplies being shut off, electricity, financial systems being, uh, neutered, so to speak. All these different scenarios because a lot of the countries and the groups within these countries that are waging more against us, they can't, I mean, in a conventional warfare, they can't compete with the United States.
So they have to find another way. And, um, it goes both ways By the way. So they were mentioning some of this stuff they had tried in the Middle East back in, back in these, back in the early two thousands.
Um, and, and this is just, it's just escalating. And I think you're completely right. There's, there's a level of this that we have absolutely no idea of.
And that's intentional, by the way, in terms of the adversaries. They're just probing and seeing what they can do and biting their time and infiltrating. Yeah.
And it's a lot about compromising, getting in and then just staying there, having a presence there. So you can co, you can do things with compromise systems or networks. So when we see announcements from the FBI and from Apple and Google or whoever about don't text to use a, use an encrypted application, that's, that's a very edge symptom of what's going, that's not the issue.
So think about what they're saying. They're saying don't send text messages. 'cause any of those are susceptible to being read by by the Chinese or anyone else that's in our net.
They are in our networks. And so that they can see all that is what they're saying. So don't use a system that's an encrypted.
Now is it end-to-end encrypted? That's the real question. But anyway, my point is, using a WhatsApp is, is a symptom, a solution to a symptom, not a, a solution to the cause.
And that tells you, at least gives you an indicator of how pervasive this is. If we're that concerned about our text messages being read, trust me, it's much more significant than just your text messages. It's everything.
So you go ahead. Uh, sorry Mike. I was gonna say, putting the onus on the, the average end user to encryption is your friend is not this the right solution either.
And this is the who, what, when, where of phone calls with, you know, all of these pieces of information put together. They can determine personal information about people and, and the onus having to be on the end user, I think is, is a huge mistake. We have heard from Verizon T-Mobile lumen and at and t and all have said, Hey, from what we understand, know, customer data has been compromised.
However, I think given that it's the who, what, when, why of phone calls, all that metadata together can tell stories about people. And we don't know who, is it everyone, is it speci? Is it specific individuals?
Probably. But it's, it's gotta be something that has to be done that the end user doesn't have to worry about. 'cause that's that, I think that's, um, that's a huge problem right there.
I think we should clarify what the carriers are not saying there, which is, um, the metadata seems to have been stolen. And if I have your metadata, I can tell a lot about you. And then two is apparently, uh, you know, adding insult to injury here, they did steal, uh, espionage or surveillance data that our agencies have been collecting, and then the Chinese now have access to it as well.
Mitch, there's a debate going on in Washington about whether or not the time has come that we need an actual cybersecurity department and a and a cabinet level person to go drive this conversation. Because it seems like, you know, CSUN and all these folks and the FBI, they're doing a great job, but it still feels a little disjointed. So do we need to bring all this together?
I'd have to go back and look when I said this, not to say I told you so, but I said the exact same thing probably nine months, maybe a year ago, of we have to elevate cyber, cyber and cybersecurity to the top most. It's as equally as important as aircraft carriers and nuclear devices. I mean, this is literally, you know, ending a society kind of activity.
You, you could complete, if you imagine if you corrupted the water supply, electricity is not something that you can depend on anymore. All of our communications contentionally either be interrupted or intercepted and used against you. You, you have total control over a society, right?
And so I, I think we need to quit goofing around. This is serious business and it's one of the things that frustrates me about Washington. People are, you know, upset about, uh, about, uh, inflation rates.
Trust me, we have, those are, those are at low levels compared to what could happen to our society if we really are, if we really are disrupted by, by the Chinese or other entities. So it's, it's time to get deadly serious about this and put competent people in leadership roles that can, can lead us, because there's good things happening in, in, in c in CSA and other parts of the, of the organization, but they're, they're kind of hanging out there doing their thing without a real strategy and somebody leading across all those agencies and conducting it. You know, this is, this is the 2001 nine 11 event that, that we're looking at that could have a massive impact on us.
I'm, I'm serious. It's, to me, I'm scared. It's a very scary thing.
Well, to make it a a little more interesting, John, there's a report in the New York Times talking about how the Russians have put a satellite up at the highest levels of space that includes a dummy warhead. And the idea here is that they're testing the theory that they might be able to blow up a satellite that takes out every other satellite that's out there. So are the stakes in this whole thing just getting raised to a level that we're just starting to comprehend?
Yeah. Yeah. That, that's interesting.
I saw that story that you sent earlier today, and it's, it, it raises the stakes and it, it, it's, and I don't, and I'm not being flippant here, but this is like James Bond stuff coming to life, and I'm like, Mitch, I, having heard about this, having written and having written about it, and Mitch actually was a source for the, a book, what we did as part of what the book that we did years ago, this was kind of something we looked at on the side as something happening in the future. And it, it is frustrating, um, given what's at stake and what our government isn't doing. It's trying to, uh, with AI in a certain sense, it kind of opened their eyes to the possibilities of things that could go wrong.
And they actually, to the credit of the government, they have enlisted people who actually understand the technology and and use them as advisors. Um, so there is some sort of progress. But I, I actually, I was thinking of the same thing that, that Mitch was, I I'm thinking we're gonna have some sort of incident, um, some sort of digital, they used to call it the digital Pearl Harbor effect, right?
Or a nine 11 type of effect. Something like that is inevitably going, going to happen. It's really weird too, because I think Trump in a, in a kind of a weird way, mentioned like a, a, a Star Wars defense of some sort when he was campaigning.
So, um, somebody's chattering chatting into his ear, or at least they're, they're, they're trying to think of it in, in like a kind of a space defense or a cyber defense issue. Uh, I just, I'm just afraid though, just given the uncertainty of who runs what and the change in administration and where eyes are are not on the ball, we're thinking about, we're all distracted by things like tariffs and inflation and, and this is the really important stuff that we should all be concerned about. Deck chairs on the deck of the Titanic, just yeah, be careful what we're arranging.
Yeah. Um, Lisa, I feel like the carriers are still treating this as some sort of PR marketing issue and not a national security issue, so that they need to kind of step up the way that they are talking about this because, um, you know, the first thing that they're putting out is a statement about, you know, well customer data, this is like a bigger issue than just whether or not, you know, your text or my text went miss it, Right? No, it's a huge issue.
And I think from what I gather, there's a lot of information that, that, as Mitch is saying, we don't know that the carriers don't know either. I think because breaches are so common these days and everyone is worried about my data being stolen, that's the first response in terms of no customer data was compromised. Or several weeks ago, Verizon said, we became aware of this.
Um, they say, Bryon said, we understand that focus was quite narrow. I don't know that they know that, and it's probably not even true. So they have to manage this from a marketing and a PR perspective very carefully.
But they need to get, be more informed. And I think they're probably struggling to try to get the information from the government and from, and even CISA said they couldn't offer a timetable for remediation. So I think in some cases the carriers might be flying a little bit blind and are trying to put out messages that will as squash the concerns.
But like I said earlier, I think putting the onus on the end user for, you know, encryption is your friend is, is the wrong thing. But maybe right now it's the only thing. It's it's the first line of defense, which just seems so odd to me that, that that can't be it.
And We have tensions with China across the board here, right? We're talking about Taiwan and semiconductors, and we're limiting access to equipment to them for building semiconductors. And now they're saying they're gonna limit access to the metals that we need to build semiconductors.
So John, is this just part and parcel of, you know, a whole slew of things that are maybe we're sliding into something without realizing just how big it is and What Yeah, I was thinking about that. If you're a historian, it might be in the early days of World War I, right? Right.
Yeah. This, it's, it's form of escalation, like on multiple fronts that leads to an aggravation and anta and agitation between multiple countries and, and their, their whatever their end games are. So in a sense, it does build into it, and it also puts the tech industry in a weird, kind of difficult situation, not just with tariffs, but the relationship in general, but China, and we're so dependent on China.
And when you think of a company like an Apple or a Qualcomm, uh, and it affects the entire ecosystem. The, the critical infrastructure, the supply chain, uh, it, what have you. The, the results, I mean like eight 15 to 20% normally of apple's revenue emanates from China.
So this is a, um, not just a a milit a military or defense related issue. It's a economic issue. And, um, I just, I think we better, we better be careful about our sabre rattling with, with China, because I think we're, we're playing with fire in a way that, um, has longer range, deeper implications.
I think that becomes the ultimate question, right? To what degree are we willing to make certain sacrifices that would be required to disengage for China? I'm not saying we need to go to war per se, but, um, there will be an argument that says we need to have a strategic policy that says we're going to quietly over the next four or five years, start moving strategic things outside of China and not be dependent upon them for manufacturing.
I mean, you've heard all these, uh, issues before and you know, Mitch, how long might that take? Well, It's, you know, think about how we've, um, progressed in our, our thinking about national security with Homeland Security Department. And one of the first steps was coordinating information flow and access between agencies.
You know, one of the fundamental problems that we recognize in in nine 11 was, you know, this is sort of the, uh, police and fire and the sheriff department were all on different frequencies of, of radios to be real simplistic about it. Um, and so getting people to be able to communicate effectively, share information both at the time of, of an event, but you know, just as importantly in the background of understanding what's happening, um, 'cause it's this tech detected in one area. You know, we all watch shows like, you know, FBI on TV or whatever, they have all those great screens where they can kind of connect all the di uh, dots in, in four minutes and find who the bad guy is and where they walked across the city, and then they co arrests them.
But to do that is, is really a complex task. So that information sharing is vital, I think. I think the, the next part of it though is yeah, that has to be, to take it to the next level.
You have to back it up by a strategy. Think about our national defense strategy from a military standpoint, right? The kind of wars that we're prepared to fight, the defensive, uh, posture that we have to take, um, changing from World War II to Vietnam or guerrilla warfare to cyber defense.
And, and we've worked on pieces of those, but I think the real challenge is, I think the, the bigger issue is, is our cyber, uh, both, uh, offense and defense capability has to be equal or at, above what our physical, uh, ta um, uh, tactical, not tactical, tactile military, uh, d capabilities are. And, uh, I'm not saying we aren't doing anything there, not, and by, by any stretch, it's not an area that I'm, I'm directly involved in and have, you know, lots of clearances to see and everything, but that is the world we live in. And that's, that's how you then roll the tanks in after, you know, all the power's down and everybody's, you know, clamoring for, for water and you know, food.
So it's a totally different strategy. All right. Well, folks, I think we're gonna ship gears here a little bit, but I would just say next time you're crafting that email or sending a text, be aware of it wherever you're sending it to.
There's a lot of other people looking at it. Hey, we'll be back in a minute. Modernize your business to fuel innovation and elevate customer experiences with the builder community.
Hub AWS and its partner network. Provide essential tools for transforming applications and infrastructure to fully leverage the cloud. Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably.
Visit the builder community hub to learn more. All right, we're back with something that hopefully is a little lighter than the previous block, but, um, looks like Cyber Monday hit another record in terms of the amount of revenue, how much money was spent. John, I know you covered this in there.
Continue to look at what's going on with digital e-commerce, but what's your take on this? Because, you know, theoretically we're all supposed to be involved in some sort of recession, and yet we find money to spend into Christmas. Uh, uh, yes.
Maybe we're spending before the recession fully hits us. I don't know. Or before inflation even gets worse, I, I don't know.
3 billion was the figure on Monday. I kept having to update it for the story. I got the numbers from Adobe Analytics, so that number is up 7% from last year.
7 million was being spent per minute. I think there were about 73 million people or shopping that day. According to Adobe, Salesforce, a actually its credit a had another report.
8. So anyway, they were looking at, we're looking at several, uh, influences. Uh, AI driven chatbots and assistance is spurred shopping habits, consumers.
So the Black Friday traffic, for instance, to retail sized from chatbots was up 1800%, 1800% compared to the same time last year. There's also this, of course, the buy now pay later, or BNPL as what they call it, um, which was up significantly. 5 in 2022.
5. In other words, people are gonna buy, buy now and, and, uh, pay pay later through a bot models. One, one other thing was Amazon, Walmart and, and Target were, because of the, the fewer shopping days between Thanksgiving and Christmas this year, we're pushing, uh, sales and pushing certain promotional events earlier.
So that played into the momentum and to experiment. I, I actually did go in on to a Best Buy on Monday and, uh, just to ex to actually make a purchase, but also to just experience what was going on. I talked to some of the people there and it was in absolutely insane.
Um, and I, I thought about you, Lisa, when I was writing the doing this story, because I know you're gonna have a lot of, you have a lot of insight into, into what's going on. But it was, again, a continuation of, of AI actually really goed things on, on this, this year's edition. One of the things that surprised me, John, and I wonder if it surprised you about the Adobe survey of 5,000 consumers, was that 20% of those consumers were reliant on AI chatbots.
And that surprised me because we hear so much negativity on chatbots. I'm one of those people that's, I'm very patient with chatbots because I know we have the opportunity to train the models and help it learn more. Um, but did that surprise you that the number was that high?
It did. I, um, yes, but you know what, I'll admit something. I used the chat bot that day.
I was looking for something, I was looking for a charger, I was looking for a secondary charger for my, for my laptop, and I did actually fall into that. And it actually was highly effective, I have to admit. And it was, the experience was much better than I expected a year ago.
I never would've done that. So, um, yeah, that was, uh, that, that number, that number was, was high, but not entirely surprising. Um, because a lot of the purchases, the most popular purchases, and Adobe looks at those as well, involve things like digital cameras, uh, smart televisions.
Yes, yes. Uh, Sony PlayStation five, for example. A lot of, a lot of electronic gadget trees.
So there are, people want more kind of a specialized idea of, of based on price range or what's available. And the other thing is, before you, I I, I will not make a purchase unless I know it's actually gonna be there. So I I, I buy before I go, which may be a little bit crazy, but, um, there was a lot of that going.
I, I went to the pickup area for the orders, and that was a zoo. 3 billion from, with the help of AI up 7% over last year. But another thing that struck me is, um, not just fewer shopping days between Thanksgiving and Christmas in 2024, but the, the, the BNPL, that that number is forecasted on, you said to be over 18 billion people want what they want, and if they can do the, the old, the, the modern layaway version of buy now pay later, they will, and they haven't, they demonstrated that.
So I think it just goes to show the consumer demand is there, regardless of the state of the economy. People want what they want, they wanna be able to give gifts to family and friends for Hanukkah, Kwanza Christmas, the New Year, et cetera. Uh, they certainly showed up on cyber, uh, uh, black Friday throughout the weekend into Cyber Monday.
And we obviously see the numbers trending in that direction, that show, um, a lot more spending them last year. And maybe that's a trajectory we're just gonna continue to see up into the Right. Well, let me ask you, because, um, we saw, at least here on the East Coast, lots of reports around Black Friday where people were saying, eh, there was no really good deals.
There wasn't a lot of traffic in the malls. And is it all shifting to Cyber Monday now? Is that the trajectory we're on?
We have seen That's a great point, yeah, Mike, we have seen a lot of, of, oh, sorry, John, a lot of organizations, um, shift Doorbuster deals online. So Black Friday doesn't have to be the chaos that it used to be. Um, I think a lot of people were online shopping on Black Friday as well, because they can, looking for great deals.
Um, there's a, a lot of tips out there from experts on what to be looking for, what to avoid, how to do safer transactions, use the h tt PS for example, that's your friend as well. Um, and so I think that we're seeing a lot of those retailers just want to go where the consumers are. And if the consumers wanna transact online, then they have to shift, and they've done, they've been doing that Black Friday to the cyber sphere.
All right, so professional shoppers are online and the amateurs are in the stores, right? I get so well, that's, that's a lot what The people do. I mean, in a sense, Some if, If you don't wanna wait for the delivery a lot, a lot of the folks were, were buying mass buying online, say from a Target, and then they would just pull up, pick up, pick up their, their goods, and then drive off.
So their experience at Target lasted all of like four or five minutes just to pick up what you had, what you had ordered. And I think that's actually becoming quite common, especially out here in the last few years in, in, in the Valley. Mitch, do you think the websites that we built, they're more resilient these days?
I have yet to hear about the catastrophic e-commerce crash yet, but it's still early. Um, or do you think the IT folks, you know, have their arms around this whole issue? Well, it's a good point.
Hadn't thought, I thought I hadn't thought about that part of it, Mike, but it may be that, you know, this isn't the, uh, flash mob sale or the, uh, you know, the gone viral moment. This is a buildup, right? We've been increasing, increasing our usage of online buying, not just events around Black Friday and things like that, but on an everyday basis.
Um, it's kinda like the, uh, you know, the airlines, you know, highest volume day was like on just July 12th or something. You like, set some records. Um, so we're just experiencing so much more v overall volume.
I think that helps us handling the peaks, um, because they aren't so drastically different than the day-to-day operations. O one thing that I'm really fascinated about this is, you know, I'm, I'm not a chat bot fan, but it really, it, it, because they're kind of the low hanging fruit of generative ai. It's one of the easy things to, to relatively speaking to implement with generative ai.
And we're seeing agents come on board more sophisticated uses of generative ai. Um, but to put, to hear, you know, Lisa and John talking about, you know, John saying sort of closet Yeah, I actually used a a a chat bot. It was helpful.
Yeah, it wasn't intentional. It wasn't intentional. It was almost an accidental event, you know, it was, it was actually fine, but, you know, I don't, I'm not a, I don't have a high regard for it, and I, in a sense, I think, yeah, it is low hanging, hanging fruit, but yeah, it was actually okay, What it, what it made me think of is, you know, don't, I'm saying this to myself, don't judge, you know, I, we, we judged chatbots as being, you know, of limited use because, so for so long, chatbots were, hi, how may I help you?
And you type in whatever it would've come back with. Well, are, is it one of these, these three things? That's all I can do for you.
And unless you're in that, those three things bucket, you're outta luck. Now, it's much different with gender, the ai. So, you know, maybe even if you don't admit it to your family over, you know, over the holiday break that you actually used a chat bot, you know, maybe we give it a try.
Give it a second. Look, Lisa, is that generational? And I asked this question because my father-in-law who's up in his seventies, can't stand anything that doesn't involve a human for customer service, right?
And my, my, my youngest son or who's in his, or one of my younger sons who's in his twenties, you know, if he never spoke to another person in customer service again, he'd be perfectly happy. Yeah, I think you bring up a great example within your own family of the generational differences that we see. Um, mm-hmm.
I think those people that didn't grow up in with computers, um, in their pockets, um, are probably have less patience. And that's something I think patients dissipated during the pandemic, and I don't think it's coming back. Um, I think we see a lot of that where, where people of, of older generations want to have that human connection to be able to, to do a transaction more seamlessly.
Um, and I think the younger generations have more patience with that or understand they probably can get what they're looking for by not having to go through a human. But of course we've got how many generations, you know, in the workforce today, what five? Um, and that keeps growing.
So I think we have to companies, retailers, et cetera, the big box stores and, and everybody have to go where the consumers are and they have to be able to have the cyber conversations. They have to be able to have the, the human conversations as well to meet their customers where they wanna be met. John, you said you accidentally fell into using that agent, and I cannot help but wonder if the people who designed that website, that didn't happen by accident.
They had a plan and I and a and you know, basically No, I know It was all intentional. Yeah, it was the fish that they caught. Yeah, no, they, that's um, that's a good point.
Yeah. I'm like the, this, this is, it's all, it's all designed to take advantage of, um, people like me. You know, actually I have to be honest though, I actually then did call the store, but the reason I, I actually did want to talk to a person 'cause I wanted to make sure that the part was available.
And also I didn't quite tr I'll be honest, I didn't quite trust the chat bot and, but what happened was, like a lot of people, I ended up talking to somebody. I think the person was in the Philippines, right? They, they have no association with the store, except be they, they're part of a call center.
And, um, it was, it was fine, but I kind of used the human element and thing. But going back to what you, you said about your son, I have the same situation with our youngest is 24, and I don't think he goes to stores, I mean, only at the last minute to buy like a knick-knack or something because he has, there's a time elements, right, where only has a couple of hours to show up at a party, but otherwise, course he, he will not go anywhere close to a physical store or location and DoorDash and Uber delivery, right? We don't even go to pick, no, Get everything delivered.
He, I, I'll tell you, my youngest is a huge fan of going to certain stores. He will go to Microcenter here, walk around, create a list, and then go home and order it online. Microcenter is the mothership.
Oh, ING uh, that's my favorite. I'll admit. I did all my shopping online.
I don't think I, I didn't visit one store, um, outside of Whole Foods, um, on Black Friday throughout the weekend because I could do everything that I wanted online. I knew what I was looking for, I could get it. Um, and I generally have decent experiences with chatbots.
I was saying earlier how I, I like to be patient with them. I did have one poor experience and it wasn't related to, um, the holiday shopping season. I was trying to book an appointment for my car for service.
And this, it's either the vendor or the dealer that forces you to go through a chatbot to book everything. You can't get to a human. Um, you, there probably was a service number I could have called and I was able to book the appointment, but it, I tried four times to get a, a loaner car and the chatbot handoff to the human was just disconnected.
It just wasn't able to happen. Um, that's probably the worst chatbot experience I've had. But I generally, uh, if I know, and I think what most folks know what they're looking for, they're able to do the transaction pretty seamlessly without having to get to a human.
So what, Lisa, what is the future of the store then? Because outside of the holiday season when I go to the mall, it's practically empty and walking around and it's not a destination that it used to be where people used to just come and hang out. So, um, do we need to upgrade the mall experience or is it just passe?
Well, I think the mall experience here in Silicon Valley is outstanding. There's one thing that's been seriously upgraded, um, that I've seen in the Valley over the last maybe five years. But something I saw recently, I think I saw this on the Today Show yesterday was that, um, the rise of the, the resurgence of brick and mortar bookstores, people want to go into a bookstore to have that sort of legacy experience.
So I think that, again, it's like what I was saying before, you know, you gotta meet the customers where they are. I think both experiences are equally important. Um, and some folks just like, like some folks still, I still like to have a fiscal book.
Um, I was never a Kindle user. I don't like to read things on my iPad. I like that legacy experience.
And I think we're seeing, at least in the bookstore, um, re uh, sector, we're seeing more folks want that in-person old fashioned experience. It is true. Uh, a lot of folks are buying records now because they want that Yes.
Experience owning, Oh, the vinyl sales. Yes. That's why, that's what my son wants for, for Christmas, was a record player, like a vinyl record player, really, that that's come back.
That's awesome. Yes. It's the comeback.
It's the comeback of the, of the vinyl record and, um, it's tactile. Right. Exactly.
Yeah. Um, and I was gonna mention Lisa, you know, the one reason, well, one thing I think is an absolute factor in the success of almost every mall near where I live, that presence of an Apple store, no matter oh, what the situation, what is surrounded by Yeah, it is swarming with people always. And it is used as a, as it's like a, it's like a century, uh, movie theater.
They did the same thing here, where they would, they would plant that in an Apple store and, and the other, other stores would benefit from it. Yes. So it was, it was, that was the drawing card.
It's A hundred are, are for sure. Are those, are, are those, are those people actually shopping or are they just lined up at the Genius bar waiting for service? Uh, I, yeah, I'm, I'm among them.
Um, yeah, so I, I will, I will go in there. 'cause the customers I have, I mean, I, I, I sometimes am a little hard on Apple, but their customer service experience is absolutely outstanding. Um, and it's quick and a lot of people there go there to get something fixed, but then you get upsell and, uh, other areas.
Um, but anyway, just, I found that, I found that interesting. Um, versus the other electronic store. It's, it's usually kind of hit and miss.
I, I did though, and I go, if the Apple experience is great outcomes, there's so many people lined up with the Genius Bar training and something fixed. This plan I did find on Cyber Monday, speaking of Apple, I had to buy a new Apple Watch, and I was able to do the entire transaction online and pay a courier a few bucks to have to actually deliver it to my house. I, within two hours of the order, there was the, the watch.
So it was, of course, I didn't get a deal on it. I thought I might get a deal from Apple on Cyber Monday. I did not.
Uh, but I have new watch and it works well. All right, folks. Well, I'm pretty sure that Sam is still working on his naughty and nice list.
It's just like most things, it's gonna be online, it'll be back in a minute. Cloud native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more.
Stay on the cutting edge of modern application development at Cloud native now. All right, folks, we're back and we're gonna geek out a little bit because, well, the folks over at Salesforce, Heroku have announced that sometime early next year, they're gonna bring a platform as a service environment to Kubernetes. And if you've been watching this show, we all went to CubeCon and talked about what was going on in cloud native space for a long time.
And one of the issues is it's still too hard to build these applications and people are struggling with these things. So maybe, um, this path from Heroku will be the answer. There are other paths for the platform, Mitch, but what's your take on what's going on here that it's still too hard for developers to build these applications, but does Heroku make it simple?
Well, you know, Heroku's a little bit nostalgia here. Heroku was really a darling of the early kind of DevOps days, maybe pre DevOps days of, I think of it as, as before it was bought by Salesforce. It was essentially the, you know, the, uh, the dark art or shadow it for developers.
You could, I remember developer coming to me, ah, I've built this and here's what I did. I'm like, Hey, hey, where'd you do that? I did it in the cloud on Heroku.
What's hero? Roku? You know, so developers are using it.
Is it a complete environment to both develop and then run applications? And Salesforce acquired Heroku in 2011, and in all honesty, it, it's really languished quite a bit. It has not kept up.
Um, it, it's been an environment where you could build an application and run it. Um, but sort of the rest of the organization isn't ready to run Heroku apps, right? Operations doesn't know what Heroku is and how to work with it.
Um, it's not a substantial platform to, to run, run businesses on today. At least it, it's languished in that ability. But what, what's happened now more recently, and, and Heroku was part of a recent, um, ab dev field day that we did, uh, through their tech tech field day, uh, group within futur and had a chance to talk with them behind the scenes before these announcements were made.
So they're, they're coming, they're making some significant investment to, to not only catch up ruku, uh, technically, but also to, to kind of with how we're developing software today. So you see what's happening in the cloud, is it used to be or it has been, get into Amazon's cloud and then we kinda lock in 'cause this is all the stuff there and we just kind of tacitly support other things. Yeah, we support Microsoft, but not really.
We support this, not, but not really. We want you to use our stuff now. You see, for example, um, Oracle, uh, offering in, you know, in native support within Microsoft Azure environment.
So, so the, not only the cloud providers, but the, uh, software tech providers are recognizing they gotta run their stuff, not just in their cloud, but in other people's cloud and do it with high fidelity, with the same kind of capability and support that you can get natively from that, that vendor's offering. Same thing with this. So what they've done with Heroku is they're upgrading the underlying platform.
So moving it on to Kubernetes, and if you're don't know about Kubernetes, Kubernetes is essentially gonna become everywhere. It's the workload kingpin operating system, workload system, if you will, for software running and from the edge to the core of the network and even into the enterprise. So they're modernizing it that way.
The other thing that's hap happens since heroku's kind of heyday is we have something called, um, remote development environments and essentially setting up a dev environment so that I can, you know, set it could dynamically allocate the resources that I need. There's companies like Dev Zero where, you know, I don't pre pre allocate what I need for resources. It detects that, oh, you need a GPU 'cause you're using the Cuda library.
Okay, great, we'll provision that for you and do it all for you and set up your development that way instead of, you know, hand building it or a platform engineering team building. It. Kind of the same thing here is Roku is trying to reposition itself as that kind of current generation or next generation of remote development environment and, and, and catch onto that wave again.
So I applied, I applaud them for, uh, working really hard to make the kind of investments that they need to make to not just modernize it, but have Heroku be part of what the current generation of development environments, et cetera, and the technologies that you can use. You know, they just added support for T net. So I don't mean to ramble on about this.
There's so many good things that are happening here. There's a lot of work for Heroku to, to real become a player in this. Again, I'm not underestimating the challenge that they've got.
Right. Well, here's the map that I kind of look at and I find interesting with this is that I think, you know, last estimates I saw maybe there's 8 million developers that have built an app or Kubernetes, and a lot of them built it once and decided not to do it again. So, so I have to say that, um, if we can get the base developers who are familiar with Heroku on the Kubernetes, you could easily double that number of developers building cloud native applications, and that would be huge for that community.
So they may not be the most sophisticated apps in the world compared to some of the things that, you know, larger enterprises are building. But the overall pool of developers and the number of applications being built, you could see some math in your head that says maybe the number of cloud native applications being rolled out in the next two years is twice what it's been for the last seven. I don't know.
What do you think Mitch? Well, With, with the proliferation adoption of Kubernetes? You know, it's, it's been said a million times.
It's a, it's a very complex environment, you know, uh, Kubernetes is simple, said no one. Um, but, but one of the side effects of that is you see a huge amount of investment in companies, whether it's observability or configuration or operational tools, gen AI tools to help you understand how to, how to better operate Kubernetes. So it's, it's the developer part of it, but even more so, it's the operations team, how, how it ops, how do they manage and run Kubernetes platform engineering is, is also, I think, a key part of that solution.
So with the proliferation, Mike, it's kind of like, yes, you know, it is complex, but it's happening anyway. It's being adopted so widespread. I mean, it's showing up at the edge of, you know, data management platforms.
Um, office 365 runs on Kubernetes. You don't know that, but it does. Um, it is that it's forcing the, oh, well, then the market needs to, to simplify it or make it easier to operate.
So I think we'll see more and more kind of, um, abstractions or, uh, tools to help us better leverage it and also run it. All right. Well, to that point, you know, and John, I'll ask you this question because when I talked to the folks at Heroku last, or this earlier this week, um, you know, I kind of forgot that Salesforce owned Heroku.
Mm-hmm. And yeah, that, that's that you just stole my point. Thanks, Mike.
Um, I was gonna say the most, one of the more fascinating things I think about this, and there are several fascinating things about this topic. They bought this company more than a decade ago, and it still existed in some sort of form, and yet they, they found value in and, and, and turn it into leveraged into something else. And I'm trying to think how often does that happen?
Um, I, I have friends who you who sold companies to, uh, Salesforce, who are long gone after their company was, was absorbed and evaporated, or they just tossed aside the idea. And I, it just, um, to me that was, was interesting. I can't think of anything really comparable to it that, that was kind of the one thing I wanted to ask Mitch, or, or you, Mike, have you ever come across a situation where something that a company acquired, actually they put it to use that long afterwards.
Well, hey John, I got out my bell-bottom jeans again from the seventies, they're back, you know, so Yeah, yeah. You know, white ties and narrow ties or no ties. So, you know, it, it, and my point is, timing is everything with, with the resurgence or with the, you know, rise of remote development environments.
Um, and that's one of the things that Heroku did really well. It was also an operating environment that's the platform as a service part of it. Um, and you can argue that, you know, Amazon developer queue is part of that, um, you know, copilot and so much of what happening with, with GitHub and actions and, uh, those kind of environments.
So the, I think the timing, if I was sitting back and I don't know this is how it happened, but if I'm the, you know, CFO of Heroku and, and talking to the CFO of Salesforce saying why should we invest all this money? I'd say, here's what's happening in the market. People are adopting these environments, this's, we what we have, we just have to present a modern day version of that.
I, that's my guess why, why they've invested so much money in bringing this back. Yeah. I think there's a storyline that's gonna emerge though, that will feel something like this.
Salesforce is investing in all these AI agents and some of those AI agents will be used to build applications, and I can put those things at the front end of Heroku and come up with something that's pretty compelling. I think if you put those things together, um, I'm not quite clear that that's what they're absolutely gonna do, but it seems like that's the logical flow of the thing and the, and where we should be headed. And if that's the case, then, you know, mere mortals can create interesting applications using AI agents on a pass that they don't have to know anything about Kubernetes about.
So maybe, I don't know, Lisa, I'd like to get your thoughts here. You know, is Heroku a hidden asset for Salesforce or is this something they're just gonna spit out someday? That's a great point.
Uh, I, I think you all bring up such great points about how long ago the acquisition was, and we're seeing this now in their release. They had, um, nice commentary from customers from healthcare organizations to cardio based car collect kilter set. So looking at the improving the developer experience, I improves the consumer experience.
Whether you're consuming a product on, uh, an e-commerce website or you're a patient trying to get reliable, uh, care from a healthcare provider. I think this is something that if they can demonstrate with Heroku that improving the developer experience is improving the lives of patients and improving the lives of people doing transactions online or whatnot, um, then it could be an interesting resurgence for, um, this platform as a service technology. All right, so Mitch, lemme ask you this.
So much of what currently exists in the land of Kubernetes is, you know, do it yourself platforms, and everybody's talking about moving to platform engineering, and the thing about all those platforms is, you know, somebody had to not just build them, but they have to maintain them and update them. Do you think that there's folks out there who are gonna say, you know what, I don't wanna do that anymore. Let me just swap this out for a pass, even if it's not Heroku, there's a couple other options out there.
You know, have we gotten to the point now where we're kind of sick and tired of custom everything? Well, I was talking with, um, one of the, one of the vendors that has an offering running on Kubernetes, and this is during, uh, coup con couple months ago, and they described it as, yeah, we were, we lived in the days for a while there of, you know, the, the buyers would say, yeah, let me do it myself. I want access to all the, the bells and whistles and knobs and buttons so I can kind of don't limit me, right?
Don't, don't stifle my creativity. Right? And you find out what, what that really entails.
Now that you have that responsibility with great power comes great responsibility, the market's now shifted to, I don't have time to mess around with that. I, it my resources cannot be spent trying to figure out how to manage Kubernetes or how to manage the development environment or, or integrate these, you know, stick built, integrate these things all by myself. Let me find people who will take that burden off my, off my shoulders.
And that's what's happening in Kubernetes, and that's part of the operationalizing Kubernetes in a way that ops can, uh, can adopt it, develop more developers can use it, you know, extracting, extracting away some of the complexity and, and, and, but letting me have access to the capabilities if I need it under the hood, if you will. So the, the market has shifted from, I'm gonna build this myself to, I, I still want lots of control to the just take care of it for me, and if I need to do something, you know, gimme some, some, uh, abilities to, to step under the hood, at least to some degree. Mm-hmm.
Yeah, I mean, to be honest, there's a lot of irony in this conversation for me because early on it was a handful of developers who were like saying, we're gonna use Kubernetes, whether it likes it or not. And then it eventually discovered that Kubernetes does all kinds of interesting things on the ops side. So now oddly enough, it ops teams are telling developers we're using Kubernetes, whether you like it or not.
Yeah. Karma. It's karma, It's, it is, it's karma.
It definitely comes full round. All right. Well folks, we invite you or suggest you should go experiment with all this stuff because, you know, decisions you might have made four or five years ago, don't have to lock yourself into that forever.
Things change and things do move on. Hey, I wanna thank our guest today. We have Mitch Ashley who is, uh, vice president and practice lead for application development and DevOps over the protium group.
Mitch, thanks for being on the show. Absolutely pleasure being here with the team. All right.
And of course we have Lisa Martin, the CMO advisor who's out there aligned with our folks at Butum Group, but also works with all kinds of different vendors out there and has all those great insights around what's happening in the holidays. And I'm sure we'll be talking about that again soon. Lisa, thanks for being here.
My Pleasure. It was really fun. Thank you.
And the, uh, I guess somewhat tech strong anointed czar of Silicon Valley. Oh, God, uh, was al, I Wait, is al whispering in your ear right now, Mike? No, it was fun to be here.
It was also good to see you all at a AWS reinvent as, as short as the time I was there. That was fun. Good.
All right. Good to break some bread with you, John. Yeah, well I was gonna, exactly my exact sentiment.
Thanks. Always good to see everybody in per in person. In fact, hey, if you see any of us at the show, stop by and say hi.
We'd love to take, get in touch with all of you. Hey everybody, thanks for watching this show. Stay tuned.
There's some awesome content on Texture on TV coming up right behind this. We'll see you next time. Hello and welcome to the Digital six o podcast.
I'm Amanda Ani and I'm excited to be here today with Jen Chu. She is the Vice President of Solutions and Consulting at Bristol Cone. How are you doing today?
I'm great. It's glad to be with you. Wonderful.
Happy to have you on the show. So can you share a little bit about yourself, your background, and then maybe about Bristol Cone and the services that you provide? Yeah, sure.
Well, as you mentioned, I lead solutions and consulting at Bristol Cone. We're a supply chain specialist organizations, so we help global 2000 organizations, um, meet their challenges, whether or not it's around visibility or resiliency or cost efficiency. Those are sort of the typical biggest challenges we see large companies struggling with as they think about how to, you know, plan, source, and make their, um, their products.
Um, I've been in consulting for, um, actually a little over 30 years now. Um, I started with Pricewaterhouse. I spent time, um, working for them in both New York and London.
So I started to get a little bit of international exposure. Um, I spent time at Forrester Research leading, uh, research into their enterprise applications space. Um, and then along the way, spent a little time at IBM and Deloitte and TCS all along the way, working with both business and IT executives, helping them solve challenges at the intersection of supply chain and technology.
Wonderful. Well, it sounds like you're definitely the person to talk to about the transformation of the supply chain, which is our topic for today. Great.
Alright, so we're talking about innovation and transformation of the supply chain. So first off, what steps can company leaders undertake for strong partnerships between technology and talent in order to drive digital transformation? Yeah, so thanks.
I think that's a, a great question and, and not necessarily obvious for a lot of supply chain executives that we work with, right? They, they immediately, um, well, frequently they will jump right to, it must be a tech problem, right? Let me, what can SAP do for me here?
Or what can you know, x, y, z fill in the blank, you know, specialist package do for me? And most of the time, what we find is that even when organizations, you know, pick the right package, deploy the right technology, the supply chain transformation can still fail. And we see that that root cause is often that the technology wasn't adopted, the people weren't trained, the people weren't ready for the change, or there's been too much change coming at the talent in the organization, and it's overwhelming.
Um, or just that the change was layered on top of everything they're already expected to do. And so, um, the dealing with the, the people challenges around a supply chain transformation is often underestimated. Um, and, um, and under planned for, yeah, absolutely.
That is a big issue to consider. So next, how can supply chain companies handle the evolving customer demands and the need for increased speed and efficiency? Yeah, so now you're asking about the demand planning, which is, um, really challenging and in a variety of different ways depending on which industry you are talking about, right?
So if you're in a, uh, if you're a retailer, um, it's no longer just people walking into your storefront, right? You've got people ordering in all sorts of different ways. So the multi-channel demand forecasting is complicated.
Um, you've got, uh, you know, big, um, manufacturers who are dealing with, uh, whipsaw in demand on a global basis. So there's a whole geopolitical aspect that, uh, organizations are now having to deal with. And then there's just changes in the buyer pattern.
And I mean, even as, as, um, as specific as like, what's gonna be the impact of the tariff news right now that Trump has been elected? There's a lot of uncertainty and demand that that sort of political news injects now into the conversation for planners. And so what we really try to advise our, our clients is that if you don't have visibility right, then anything that you anticipate or forecast or plan for is likely to be wrong, right?
Already forecasting is hard, but if you're doing it without good baseline information, it's definitely gonna be wrong. So starting with visibility is usually a good place to start. Yeah, absolutely.
Well, how, what tips do you have for business leaders as far as how can they stay ahead of this evolving technology and and harness the technology to remain at the forefront of the supply chain? Yeah, so here's where AI often comes in to the picture. People assume that that's going to be on, um, panacea, right?
It's gonna solve all of our problems, and it gets coverage like that sometimes. And while I don't believe that's necessarily, you know, true, I'm not a total Pollyanna about ai, I do think there's a valid role for AI to play. Um, and it will be impactful across all of our, um, you know, our, uh, economy.
But when we start to think about AI as a tool that organizations should have in, in their toolbox, it really starts with data readiness. Um, the old adage, garbage in, garbage out is still true. And if you've got bad data or poor data, or you're missing data or poorly trained data, right?
Then you're only going to accelerate bad decisions. Um, and so we wanna, we start with a strong data foundation. Um, next is the people challenge, which we hit right out of the gate.
So if your people aren't ready for ai, if they've not been trained, if they now, uh, if they're unable to start to think in scenario, and what if an interaction with the digital assistant, then that's a skillset we need to get ready and build out. And the organizations, um, we need to get people out of the rote day-to-day transactional activities and into problem solving. And that's fundamentally a different challenge than most, uh, you know, uh, supply chain workers are, um, engaged with from, you know, if you just look at their, um, the way that they spend their eight or nine hour days in the office, it's a big shift with ai.
So thinking about data, thinking about people, and then, you know, there's some IT things around hardware and software, which are probably not for the general audience, but you know, there are certainly investments that need to be made, made there all before you start to think about deploying that very specific AI bot or digital assistant. So we really encourage people to think foundationally first, um, as the AI digital assistant start to mature. Absolutely.
So communication is the key to most businesses success. So in talking about that, um, leadership between talent and staff members, how do we have good communication and, um, encourage staff members to embrace the new technology? Yeah, I like to think about trust and transparency, and you can't have one without the other, right?
If you're not transparent as a leader, if you're not talking about what the, uh, anticipated changes are, whether or not it's AI or any sort of change in the, in the organization, then you're probably not gonna have a lot of trust. And if you don't have a lot of trust, then what reason would the staff have to go along with any of your change management ideas? Right?
So I know it's something that I try to live by and, and with my own team, is establishing, you know, that transparency to share as much as I possibly can about what am what I'm anticipating, the types of challenges that, that I expect us to have to deal with sourcing answers from the team, not just telling them the answer. Um, I think that all creates a, uh, a virtuous cycle. And so not a, you know, it's not a supply chain specific answer.
I think that's just a good management and leadership, um, approach. Uh, but where we see our supply chain clients ex executing on that sort of trust and transparency, we see a far higher adoption rate in the technology investments that these leaders are banking on so heavily to help them improve their supply chain. Do you have any use case examples you would be free to share of companies you've worked with that improved and, um, showed innovation within their supply chain?
Yeah, actually, um, so we've, uh, developed 78 specific, uh, supply chain use cases at Bristol Cone, and we're working with our, our clients, and we're at various levels of, of development and adoption across those 78. 'cause some are probably, you know, um, more drawing board at this point until the technology actually catches up. But where we're seeing a tremendous amount of excitement and investment is in the s and OP process, so sales and operations planning.
And I think one of the reasons why that has become such a lightning rod for AI investments, um, and transformation in general, is that it's a really painful process. It's, you know, it takes a lot of, of days, sometimes weeks of preparation. It's a lot of senior executives, um, and it's a lot of guesswork.
And so all in all, that's a pretty expensive, um, and time consuming process. And so if there is a way that we can leverage technology to, um, shorten the cycle and improve the outcome, then that is certainly an area of interest for our, our clients. And I would say it's not just one client, it's, it's across the industry.
So we serve life sciences and med tech clients, we serve consumer products and retail clients, automotive clients, et cetera. And there are people in every industry that are asking us to specifically try to address their challenges in s and OP. So I, I think that's where we see the most energy and excitement around application of this AI technology.
It's a perfect fit for it. 'cause it's data intensive. It's a lot of what if scenarios.
Um, so coupled on top of all of that data crunching, you still have to have, uh, there's still a complex set of decisions that needs to be made. So it's a, it's a really great combination of the, the human making, the final decision and recommendation, but with a whole lot of analysis that we can now outsource to some sort of digital assistant on top of a mountain of data. Wonderful.
Well, the world is constantly changing. There's many factors to consider. And what are your thoughts as far as, uh, what can we expect two years from now in the world of supply chain management?
Yeah, so I think that, um, right now AI is a lot of buzz. I think two years from now, we'll actually see a fair amount of, of deployment that, um, so, you know, I, I think there's a tremendous amount of data readiness that organizations are going through now. There's also a lot of experimentation happening with AI now.
I think if we're, if we were to have a conversation 24 months from now, we'd see, you know, a fair, the, the, the bell curve, right? We would see the more aggressive organizations with a fair amount of AI bots deployed throughout their organization. I don't think that in two years we're gonna have sort of push button supply chain technology and have outsourced all of our work to, uh, you know, to the system.
Um, but I do think we'll see, I don't know, 20 to 30% of the companies with, uh, maybe 10 to 15% of their processes really actually operating on, on ai. Um, yeah, had a, a discussion the other day with a, a gentleman who works in the, um, AI advising, a lot of investment banking companies, and he said, the best place to start with AI is to outsource what you have your interns do today. And I thought that was a great way to think about getting started with ai.
If it's simple and it's tactical, what a great place to start and start to build some experience in your organization in using ai, but save those really sophisticated scenarios, either for a human assisted leverage of ai, um, where you don't turn over the decision making, but you turn over some of the analysis to ai. So I think we'll start to see evolution in, in, you know, on that continuum. Interesting.
Yes, that does make sense. Well, if there was one key takeaway you could leave our audience with today, what would that be? So I would say don't underestimate the amount of effort it's gonna take to transform the people in your organization.
And so I would encourage them to think about what are the, um, the, the cultural shifts that your organization needs to, to start to think about, um, empowering your people in order to start making decisions as opposed to educating them on how to perform tasks. And that is a tremendous shift for organizations. Um, and I, I think that organizations who figure that out will really truly be the ones who can take advantage of AI in the long run.
Wonderful. Well, thank you so much for coming on our show and sharing your insights with us today. Thank you very much, and thank you to our audience.
Stay tuned. There's more. Hello and welcome to the latest edition of the Cloud Native Now podcast.
I'm your host, Mike Bazar. Today we have a guest, Byron Viray is the CTO for or, and we're gonna be talking about, well, how AI agents and orchestration and microservices is all gonna come together because they're on a collision course. It's just a question of when now.
Hey, Byron, welcome to show. Hey, thanks. Uh, thanks for having me here.
As we've seen so far, microservices are not easy to build and maintain. A lot of folks are challenged by it, and as a result, maybe they sometimes even go back to monolithic applications. We are seeing though, the rise of these AI agents that are increasingly starting to be able to take on more complex tasks.
I guess the issue is how would we manage all these AI agents and create something that feels like, um, some order in what could be a potentially chaotic scenario, um, and apply that to microservices. So you're at the forefront of this, what's going on? Yeah, I think, I think that's a great question, first of all, and I mean, if you kind of look back and think about it, right?
There are a lot of similarities as well. Like when we look at, when we look back and, and look at the microservices world, what started to happen was, uh, you know, people started building microservices, uh, you know, single responsibility functions. And once you had, you know, a host of microservices available in your kind of, uh, infrastructure, the next question came was that, okay, how am I gonna manage all of those things?
Uh, how am I going to essentially put all of them together to achieve my business goals? And what we are starting to see with the AI agents is kind of a similar story that, you know, the agent is only as good as the tools it has and the autonomy you give it to them, right? Otherwise, essentially, you know, you are not really solving the fundamental problem in terms of how they are able to plan, execute, and deliver the results that you want.
Um, so I think the way I at least see is, you know, uh, lot of learnings that we had with microservices, you can potentially apply them to how you build agents, how you operate and run them. And I think there are two critical pieces there, right? One is visibility into, you know, what is happening.
Um, ML explain explainability has been a subject of research, um, for quite some time, uh, with the adoption and a broader option of ai, and especially LLMs, it has even gotten a little bit more mainstream. Uh, just imagine a case where you are leveraging AI agents, which are making fully autonomous decisions. How do you get visibility into why that decision was taken?
Um, and we are starting to see some, you know, uh, kind of news about, uh, agents doing things that doesn't make sense or, you know, got company into hot soap and things like that. So this is where I think, you know, the learnings from microservices in terms of like, you know, it's not just about kind of how you put things together, but more importantly, understanding why it did that. Uh, being able to get visibility into it and, and be able to kind of do that in a safe way is gonna be very critical.
And I think there's a lot to learn from, you know, the adoption of microservices, how we could evolve, how it matured and apply them to, you know, agents. Mm-hmm. I mean, a lot of sense with microservices.
One of the things about it is that, um, it creates redundant paths for API calls, so the application is more resilient, and in a similar way, we may have to route different tasks around the different AI agents, many of which may be checking out each other to ensure that the quality of the overall application or whatever outward building doesn't go off the rails. Yeah, absolutely. And I, I think, um, I, I would say like, you know, in microservices world, you had the concept of edging where you would send the same request to two different API end points, uh, so that like, you know, if one of them is, is slow to respond or is not available, your overall request still continues to operate.
And I think you could apply, and we are starting to see that as well, right? Uh, with the AI agent as well, that, you know, you are sending the same requests to two different models, um, and, uh, maybe using a human to evaluate the response or using a third model to again, evaluate the response before actually, you know, responding back, right? Um, and, and leveraging that kind of patterns to kind of put some more safeguards, some more checks and balances.
Um, and sometimes it's purely for evaluation. Like, you know, if you build a new model and you want to test it out, um, before kind of rolling it out, you are kind of sending a shadow, uh, set of requests over there, evaluating them. And once you are confident, you know, switching that, uh, path, um, and especially the way models are evolving, like we are seeing a new version coming up pretty much every year.
Um, and, uh, you know, oftentimes what was working in the previous version, the behavior changes. So, you know, up upgrading to the newer version also requires, uh, testing. And the biggest problem with, um, ai, um, and language models is that they are non-deterministic, which means you can't really have a set of use cases and say, oh, I'm gonna run through this set of use cases, do a Q testing, and they'll pass.
It's all good to go. That may not apply here. So now you to kind of do this in production environment with real world, you know, user inputs, so this becomes even more critical to be able to orchestrate the requests across different agents, different versions of the same agent and, and things like that.
Yeah. Mm-hmm. So I may have agents that help me write code, and then I'll have an agent that helps me test, and then there'll probably be a set of agents that are doing security reviews and, uh, uh, governance management kind of task.
Um, what will be the role of the human developer and all of that. How will they kind of be involved and software engineers will orchestrate this using what? That's a great question.
Uh, what are we going to do if AI does everything? I think the more important thing there is like, you know, um, somebody has to still kind of figure out, um, how these agents are going to orchestrate the task amongst each other. Um, also be able to kind of, uh, do that in a safe way, uh, which means there is gonna be some human, um, overview intervention required every now and then.
I think that's one. And like, you know, and this kind of brilliantly applies to software development, for example, right? Like a lot of software developers today are using co-pilots to write code, but you know, they are still responsible to, um, ensure that the code that is written kind of matches the requirement.
It, it, it is safe to run. Um, there are no bugs. Um, and, and like a lot of people are also using AI to kind of generate automated tests, but, you know, somebody is still kind of orchestrating all of those things, right?
I, I don't think we are there yet where we can say that everything is gonna happen, uh, by AI automatically. Um, and I, I think, you know, essentially, you know, we are shipping ourselves slightly at a higher order in terms of what we deliver as a value, uh, which is what we are best at, right? Um, being able to understand the business, being able to find the right set of agents to orchestrate and where, and how we orchestrate.
I think that's, that's the field that I feel like, you know, is not fully developed yet. That's one area where I think, uh, orcas, what we are working on is, is gonna be very critical in terms of, you know, you have all of these agents, you need to run time for this agent so that you can run them safely, you can inspect, visualize, um, uh, log them and see what's going on, right? That's, that's I think one area where I, I I see a lot of opportunities and, and I need, So in effect, the AI agents still need a boss, and that would be called us, right?
Yeah. Um, you know, one of the things you see in microservices applications is there's just a lot of containers coming and going. And if you listen to folks, we might be building more software in the next few years than we've built in the past decade.
And so are we prepared to deal with the amount of ripping and replacing of containers that we're gonna see at that level of scale? Because, well, we can't throw more bodies at the equation, so we gotta find a way to kind of keep track of these containers that might only live for, you know, what, 30 seconds. Yeah, I think, yeah, and I, I think this is where the orchestration plays a very critical role, because you need a system that has a complete overview of what's going on.
Um, because let's imagine a case where, you know, somebody, um, starts, uh, spinning off containers and you end up spinning thousands of containers and you have no checks and balances, and, and you will find out when you get your next cloud bill. Um, so that, uh, that's definitely kind of the case. So, you know, this is where like, you know, the orchestration systems, systems which are essentially responsible and have kind of right set of limits, um, and, um, checks and balances in place, uh, becomes more critical to understand, you know, what's happening with my system.
And I think, as you rightly pointed out, right, it is, it is gonna become easier to write a lot of code, uh, build a lot of systems, where we will start to see, um, is how well are you able to run this? So runtime aspect of it is, is gonna be a lot more critical now than than ever because, you know, we can just do a lot more now. Um, It also seems to me at least that, um, we're reaching a level of complexity and maybe we're already there and we're just struggling with it.
That, and the application environment is just too difficult for humans to manage by themselves. I, I think we are already there. I think we are already there.
Like, even without, like, even if you take the AI out of the equation, um, applications are complex. Um, what, and especially as you kind move things over to the cloud, uh, in a, in a more distributed, uh, world, um, applications are increasingly complex in terms of its interconnectivity to other applications, different systems, um, microservices, um, events, um, that are kind of, you know, being exchanged across different applications. So things are definitely a lot more complex.
Um, there is no longer the case where your application is a very simple, you know, you have a database, you a form, and somebody fills out the forms and service in your database, right? That typically never tends to be the case. Now, there's a lot more kind of business logic that is implemented.
There's a lot of orchestration that is happening across multiple applications, including third party systems and vendors. Um, so they are definitely a lot more complex. And, and guess what happens when you have a very complex systems?
It becomes increasingly complex and difficult when there are failures or things that you have to reason about as to why certain things happen, right? It doesn't have to be necessarily failures only. Um, uh, I would give you an example of, um, a system that takes some decisions, right?
Um, why did it arrive at a particular decision? You need to be able to know the entire graph of, uh, you know, steps it executed to understand why it arrived at that decision. Now, if I were to build that graph in my mind, you know, it, that's a lot more community overload, the amount of time it takes.
Um, and, and that's where, you know, orchestration systems, systems like conductor and orcas, uh, becomes very critical. Where, you know, you are able to understand what is happening, why it is happening, and if there are failures, uh, be able to kind of, first of all, resolve the failures automatically, and if not, uh, be able to kind of have a, a simple API call or a one click button to, you know, resolve them. Um, but yes, they, they, they, they, in summary, they are already complex.
Um, On the opposite end of that, are we in danger of becoming maybe too dependent on ai and we let the machines kind of figure out everything that can be done, and we may not understand how it was done. And then when somebody calls us up, like a compliance auditor and says, can you explain this? We may not be able to.
And I, I think that's a extremely valid point, and I'm, I'm kind of, I hear that a lot, uh, and this is one of the common themes that I kind of also hear from our customers, the users that I've spoken to is, yes, AI is great, but I need to be able to explain the decisions it took. And this is why I believe that like, you know, being able to explain the decisions that AI made is gonna be extremely critical, non-negotiable in some sense, uh, or especially in some industries where you have to be able to justify and understand why that decision was taken. So, you know, instead of AI becoming a black box, the way I would kind of think about it is that like, you know, it, we are starting to see, and, uh, that is one area where we, we also kind of, uh, position ourselves is, you know, you think about AI as tools that can help you, uh, automate things, um, and take, um, automated decisions, but you are still in control and you have to have the complete visibility into, you know, why this happened, what was put given to it, um, what were the rational, and maybe have a parallel kind of, uh, execution made, uh, to another model or an algorithm to validate that.
Like, you know, even if I use a different AI system or an algorithm, I would arrive at the same situation. So now when my compliance officer calls me and says, you know, why did you do this? I have the full explainability as to why, um, Do you think we'll also be able to use that capability to a degree to, uh, determine what is causing a, a performance degradation in my application?
'cause one of the issues with microservices is, well, they may not necessarily completely fall over the way a monolithic app. Well, I can spend a long time trying to figure out what it is that is causing a certain performance issue. And the maddening thing about it is it might take me two days to figure that out, and it's about a 32nd fix.
Oh, yes, absolutely. And I think this, this has been kind of already, um, you might already see some of the systems similar to that, right? Like doing auto tuning.
Um, so, you know, you put in AI agent, um, um, or as a site car in your application deployment, which is constantly monitoring, um, how your application is performing, checking logs, um, and other systems, CPU memory and kind of understanding, you know, the application behavior. And in today's world, uh, it could start with giving recommendations. But I can totally see in the future world, um, and I have seen those systems, uh, at play as well at large companies like Google, where it'll just automatically tune it for you, um, to the best of its capabilities.
Uh, so, you know, and, and the whole idea is, you know, if you think about it, right? Um, where we are best as humans is being able to understand the business, um, implement the business logic and drive the business forward. Everything that we have to do on the infrastructure side.
How do I run my application? How do I get visibility into my application? As you mentioned, I queue my per code for performance and everything that can be very well done by machines, um, and, and ai.
Um, so you, you kind of coexist and, and leverage them as your tools rather than like, you know, think about it as kind of replacement, uh, makes it more productive. How will the software engineering teams be organized? 'cause I, in my mind, it looks like we're gonna have a small army of AI agents and working alongside humans, and, but you know, it still takes a team of folks to build something.
So how will the AI agents that I created work with the AI agents you created? I think that's, that's an interesting question. Um, I would, um, I mean, I, I, I don't think I, I have the kind of answer that I, um, because right now it's such an ascent field, um, and, and we are starting and, and we are seeing frameworks, right?
Frameworks, like, for example, conductor, where, uh, we are allowing people to kind of, uh, orchestrate across multiple agents through API calls. Um, there are frameworks like auto gen, uh, that allows you to kind of do the same thing why, where you can have conversational AI agents, uh, talking to each other and to achieve a goal, um, or collaborate on a particular task and things like that. But I think that's another field that is, is evolving quite rapidly.
Uh, and we will start to see maybe some amount of convergence there in terms of frameworks and, and, um, how those things are kind of managed. And, uh, yeah, Right, you mentioned the Netflix, uh, framework that you guys are using at the base of your approach, but, um, I'm trying to figure out where the cart and the horse is here. 'cause sometimes I think people are gonna try to create all these AI agents and then kind of add the framework to kind of manage it after the fact.
So maybe we should be putting the frameworks in first and then figuring out what's going to attach to them second, Maybe, uh, maybe, but I mean, then I think it's, it's the kind of dilemma, right, in terms of like, where do you invest and focus your time on, right? Uh, building infrastructure is always more expensive, tricky. It requires very specialized skills overall.
Um, ai uh, agents, fortunately what has happened over the last few years is it, they have become almost ized, right? Like, you have a plethora of choices in terms of the models, uh, their cost. Um, so it's much easier to use them to build a POC, um, or at least, you know, put together a simple business use case, um, which is what everybody is doing today.
Uh, where I think, as you rightly pointed out, is there's a need for a infrastructure, there's a need for a runtime for all of these things, which does not exist yet, um, uh, outside of, um, you know, a few kind of initiatives like ours. Um, but I, I would say, you know, uh, as people kind of realize, um, and, and try to find out, they will both converge, um, eventually, uh, as in pretty soon probably. Do you think ultimately, we hear a lot about the phrase platform engineering, and I wonder if this transition to AI is gonna force us down that path, the more organizations are gonna have to have some, uh, centralized approach.
But I guess one of the joys of DevOps was that, you know, we embraced it in the first place so we could get out from underneath centralized it. And so how do we strike a balance? I think platform engineering is gonna be the commonplace, and if not already, you know, I mean, we are already seeing a lot more effort, emphasis on platform engineering.
And if you think about it, right? Like, um, you take your, um, developers who understands business, uh, who is able to kind of, um, implement complex, uh, business solutions. You take AI who is able to kind of take care of heavy undifferentiated kinda work, um, like, you know, helping them write code, um, and things like that.
Then what's missing part there is that platform where they can all put everything together and run it so that now they don't have to worry about kind of that. So in some sense, I think, you know, it's, it's a complimentary thing. And you know, when you put all these three things together, you, you get the most efficient, uh, you know, what I would like to call it, like, you know, a 10 x developer site.
Um, NX developers are less about developers and more about the frameworks and platforms that they operate on. Currently, we're kind of at some sort of crossroads when it comes to software development. So what's your best advice to folks about how to get ready for all this?
And like, if you look at software development, right? Like, it, there is a lot of hype, um, and, um, interest in, in AI today, but software develop has always been similar to this, right? The, it has never been the case where you learn one thing and then you keep on working on it for next decade or so, right?
Like, it's constantly evolving in terms of the framework. Um, in terms of the architecture, um, you know, we went from mainframe to PCs to, uh, data centers, to, you know, cloud, um, now hybrid cloud ai, uh, microservices events like this has been constantly evolving. So I think the advice is, is the same, right?
Like, um, it's, it's about kind of constantly learning, um, understanding where you add the value, um, and, and I think in the end, um, be close to kind of the foundations, right? Um, I, I think that's, that's the hardest part. Um, and, and that's where we add value.
Yeah. Alright, folks, you heard it here. Hey, even in the age of ai, don't forget the fundamentals because that's what's gonna help you get through all this.
Hey Barron, thanks for being on the show. Yeah, no worries. Thank you so much for having me here.
All right. And thank you all for listening to the, or watching the latest edition of the Cloud Native Now podcast. You can find this in other episodes on not just our website, but on Spotify or Apple or any place else that you listen to podcasts.
Once again, we invite you to check out the entire library of podcasts that we have. And until then, we'll see you next time. Hi, my name is Mark Callahan, I'm the founder and CEO of Cloud Canaries.
I wanna do a presentation to talk to you about DevOps in the intelligence era. It's here. We're gonna talk about new technology and how that affects and creates new culture and new attitudes.
Ultimately, it's learning how to love the S-curve and more, little bit of a little bio for me. You can certainly pull down the slides and take a look at it. Um, I like to, uh, uh, crush pillars.
I like the clouds. I like canaries. I love Boston.
I love to row, I love beacons and beacons are workload data, got a degree from MIT and so on. At the end of the day, when is it time to let new technology out of the Faraday cage? In this tech case, it's a robot, and there's an 85% chance if you let the robot out.
It's an artificial, it's a robot with artificial intelligence, it is an 85% chance that it'll cure cancer. 0, 1% chance that it'll take over the world. The question is, what's your decision?
What are you going to do? Are you gonna take a pass? Are you gonna embrace it?
And sometimes when you do embrace this, there's always risk, but there's always opportunity too. And rewards, sometimes it's unexpected. So let's go to our next slide here.
One of the things that when you look at new technologies, you look for something called the inflection point. And, and that h helps you to stay ahead of the S-curve. And we'll talk about the S-curve as well.
Basically, it's when a new technology dramatically changes the trajectory of a business, of an industry, of an economy. But beware, new technology is disruptive. This is especially true for DevOps.
New technology can create new culture, new attitudes, a new way of solving problems, but also can disrupt and it will disrupt the status quo. Eliminating old approaches, business models, and require new insights. Be prepared.
The technology era will do all of these new technology can bring new risks. Here's a little slide about, oh boy, the robots replaced you too. It's kind of funny.
You notice the obsolete goals, uh, stamp on the, uh, the robot standing in line, uh, for un belong benefits. However, new technology can bring new rewards. I know everybody, everybody's commute became much more pleasant since driverless cars, but this is just too much.
And if you notice, there's someone in a driverless car swimming. And the point is, is that sometimes the new rewards are unexpected. How can that happen?
Completely surprise. So again, be prepared for that. So let's, uh, jump into the, uh, um, how to love the scur.
The S-curve is a, basically a product lifecycle where it shows you how a new product gains strength gains it adoption becomes, uh, um, has a high level of growth and eventually stabilizes. Beware of s-curves, multiple s-curves and, and multiple technologies and how they interact. The classic example that I learned at, uh, at MIT was schooner wind based freighters, hundreds of years.
They were used to, uh, transport freight all over the world, very efficient. They used the wind. Um, they were limited by weather.
Uh, but the technology for sales, it was incredibly advanced. And then it happened, technology B came out. The steamboat steam engines and coal for fuel, new freighter designs bigger, could, could move more freight shipping's now limited by weather.
The technology for steam engines advanced very quickly. Again, this, this, uh, chart on the, on the right shows technology A Skinner, and then technology B, which was a steam engine. So, uh, which technology was at the end of its curve?
Well, it was sales, you know, sales sail sailboats still exist. Uh, but with, for freight, for moving freight, within a decade or two, most of those schooner were replaced by steam engine based freighters. It was at the beginning of its s-curve, while cell technology was at the end of its.
So, new technology replaces old technology. It has an impact on how you, how you do your, your daily work. It has a impact in culture.
It has a impact on, on new products and, and, and how they are successful to help at the end of the day, customers. So let's dive into the scur. There's different phases for the scur.
And, and you can use this, there's two kind of views of it. I have a, an emotional, uh, the emotional phases and the economic phases. I like the emotional ones at the bottom.
Uh, okay, it's still early, but where's the traction? And then the next one is, this thing is not going anywhere. And then you see this little inflection point where the, the curve like goes up and, and the, the emotional response is, okay, maybe it's not hopeless.
And then it goes up, uh, uh, skyrockets goes, uh, gains speed, uh, dramatically. And the comment is, we're all gonna be rich. And then it kind of levels off.
And, and the comment is, what just happened? And at the end, we are doomed. So that's a, a typical S-curve, and you'll see that in many different technologies.
You saw that with scooters, and you saw that with, uh, steam engines and, uh, steamboats. You see that with televisions, you'd see it, you know, um, audio equipment, you name it. One technology, uh, has a, a market lead, and it's replaced by another technology, um, that evolves in its its own ES curve.
Um, the, the economic phases are, um, you know, you probably, if you've been to business school, you probably all, uh, have seen these. But you know, you search for a solution, proof of concept, early adopters, system integration, and the market expansion. Again, different phases of that scur.
So now you know what an s-curve is. The, the new technology of the intelligence era, we believe at Cloud canaries is data, AI and compute. We're gonna go into each little piece, um, in a second here.
And we also believe we're at an inflection point, uh, in the S curve. You know, that little space right before for, oh my gosh, is this ever gonna work? To, Hey, it's working, and then it takes off.
And I'm, we're at that point, and it's really, as I mentioned, three pieces. It's the data and it's ai, but I'm gonna call it commoditized AI in the sense that it's no longer a research tool for research labs. You can now find it in the production floor, even in the cloud.
Um, and numerous vendors are developing their own set of tools, and they're widely available. And, um, anyone can, can really use them and actually build models that generate forecast and insights. Third piece here is, and it's critical, we're commoditized anything.
AI in this case, you need something that, that always pushes costs down. And Moore's law, which isn't really a law, it's more of an observation, is about how the density of integrated circuits double every two years, two and a half years. It kind of varies.
It's varied over the last 40 years. But the bottom line is computers are always gonna get faster. They're always gonna have more memory, and they're always going to the price point on, on that level of compute and memory is always gonna go down.
So what that creates is this new technology where you can build models, you can do forecasts, and you can reduce costs. So take a look at your organization. Uh, what stage, uh, best describes your organization and current adoption of ai.
Take a, you know, think about that. No investment. We have a little bit over 20% of planning about using AI solutions of some type exploration.
A little bit more. 24% pilot projects are still under 15% partial integration. You know, AI's being used today, 20% and full integration still kind of like at 7%.
So there's a ways to go, and we kind of fit right into that inflection point. So, um, it's only gonna get, there's only gonna be more. It's going to speed up and, uh, really have an impact on everyone's lives, but it's also gonna have an impact on, on, on DevOps.
One of the things I, I did wanna drill into a little bit is commoditized ai. Again, this is a situation where the tools and the technology has developed to a point where, I call it the average Joe and Jane developer can actually easily get tools, build models, and actually use them to generate forecasts and, um, insight. And a, again, it's really driven by the availability of data, quality data, uh, the organization of that data and vast quantities, but also the cost of compute.
And as we've seen, the cost of compute is going down, there's more tools available. So there, it's easier to pick something that really matches your, your, um, solution area and, and data, right? Um, the rocket fuel for AI is data and compute.
You kind of mentioned that it's, it need data to build your models, but you also need compute. And the more compute, the faster, the bigger, the better. The, the easier it is to actually build AI models that actually produce, you know, unexpected amazing results.
And there's a little, uh, blurb here from, uh, Steve Brown, which is a very in interesting individual. Um, data properly cleaned and organized is the rocky full fuel of tomorrow's powerful AI solutions, smart services, new customer experience, and the AI powered tools and intelligent agents that will augment your employees and give them superhero level capabilities and simultaneously boost their job at satisfaction. Um, Google him, he's, he's, uh, he has a lot of other really cool things to say.
Um, data, data and more data key attributes of data for the intelligence era is quality. How that organ, how that data is organized, and the quantity of data. So a lot of these, you know, the quality in organization, it might be a little bit different than what you, uh, would, uh, need if you were to actually use the data.
So the data has to be structured in a way that can be easily loaded into, into, uh, or fed into, uh, tools that are generating models. And, and for the most part, more the merrier. We mentioned this before.
Um, compute is the driver of cost along with data and, and how that data is organized and cleaned. But with it, it will always, the cost of a AI based solutions will always be going down in the future. 'cause compute increases, storage increases.
It's just easier to do things in some ways brute force than using what I call fancy algorithms that over a few years become irrelevant because computers compute is just, makes 'em irrelevant. This all brings, comes together in, in the data ai compute lifecycle. And this is really cool.
These, you know, you collect data, um, from some source for us at Cloud Canaries, it's workload data. Um, you take that collected data and you create a model. You use that model to generate forecast data and in and forecasted insights.
Then you can use actual data to actually validate your forecast data and modify your model where appropriate, based upon the validation. And you can continue that. So your model is always gonna get better.
Your insights are always gonna get better, and your forecasts are always gonna get better in this new intelligence era. And that's gonna have, again, have dramatic impact on DevOps and how you run your business. So, um, new technology requires new DevOps habits.
Now, a lot of these are old oppor habits, however, it creates a new opportunity to really employ these habits in a way that really help, um, DevOps and your teams and the organization as a whole, you know, manage the cloud as your most important asset. Become an interpreter of cloud insights. Collect lots of cloud data for modeling, forecast, cross lines the business to help, help and offer, uh, new solutions.
Be proactive and ready with the new approaches and solutions. Present your insight to your, uh, enterprise business decision makers using cloud data. Negotiate with insights from cloud data.
Understand and participate in critical corporate initiatives. Speak your com company's business language that's really important for DevOps. Pilot, evaluate, imagine new solutions.
New technology requires new DevOps habits. New technology gives you the opportunity to do this as well. One example for us at Cloud Canaries is intelligent.
Canaries is we use, uh, workload data, AI and compute. Um, there's a background and intelligent canaries are microsurfaces. We use billions of workloads each with data.
We use artificial intelligence to create models. And these models are sometimes so sophisticated. Even the neural scientists will go, well, they'll do the AI shrug.
I don't know. How did it come up with that? How did it come up with that insight?
Well, you can figure it out, but it might take years and, and compute, um, Moore's law or observation that everything gets faster, everything gets larger, everything goes down in cost, data, AI and compute technology and the scur. So we're gonna take this one step further. Intelligent canaries are active observers.
And, and, and, and this is how you know, technology A gets replaced by technology. B, we have a, a solution, you know, a marketplace for observability and, uh, observability in the past has acquired instrumentation. Uh, if you observability in the future will not require observant instrumentation technology.
B. So over time, solutions will be replaced by newer solutions that again, will change the way DevOps works, the way DevOps thinks and, and will create new opportunities and some amazing unexpected results. As I just mentioned, um, existing observability solutions are obsolete, and you can, you can replace observability with others, uh, other solutions.
Um, because of this new technology, it completely changes the way that you will work and your culture and the way you interact with the business as a whole. Um, you know, log and trace data. Spend a look at workload, don't lie.
NEUR networks, compute observability, canaries without instrumentation. Um, what intelligent canaries can do, forecast visibility, troubleshoot effectiveness, SLA compliance, align alignment of metrics, both business metrics and cloud metrics. Um, the intelligent era will, uh, present, uh, new opportunities.
AI can be applied to the entire digital delivery lifecycle, insight analysis portfolio and back. Um, backlog, continuous integration, continuous testing, continuous delivery. AI will affect all of those.
And again, it's, it will have impacts on, on, on DevOps as a whole. Remember that first slide, you have to make a decision whether you're gonna embrace new technology or not. Um, I think it's better to pilot, evaluate, and then if it looks, makes sense, embrace, Um, new technology, new culture, new attitude, pick the next cloud solution.
And the bottom line here is that the, uh, this new era will basically replace well, all the solutions that you're currently using with a new set of solutions that are based on new technology. And we believe data, ai, and compute. And we believe most legacy cloud solutions are obsolete or will be with this new technology.
So pull a canary from a hat. Here are some, uh, uh, solutions that we believe in. The Intelligence Zero will be replaced with AI based solutions that uses data and compute, digital experience, contract negotiation, crisis response, market analysis, sales forecasting, competitive analysis, buyer behavior monitoring, cost reduction, risk management, buyer behavior, continuous monitoring, relationship management, and many, many more.
It will change DevOps in a way that will be interesting and will give DevOps new opportunities. So be prepared. Are you ready to release or to open the door of the Faraday Cage and embrace the possible risk, but also the opportunity and rewards.
Thank you very much. And let us know if you're want to open that cage. Hello and welcome to the Techstrong AI podcast.
I'm Amanda Ani and with me today I am excited to have Dwayne McDaniel. He is the developer advocate for Get Guardian. How are you doing?
Doing Great. Great. Glad to have you on our show.
So first, can you share a little bit about Get Guardian and what services do you provide? Sure. Get Guardian is a platform for secrets observability, really, uh, finding and detecting hardcoded credentials.
Uh, when I say credentials, I mean API, keys, password, database, strings, things like that. Anything that grants access to another system or encrypts or decrypts data, uh, we find those, well, wherever they are throughout your systems, uh, they shouldn't be in there. They shouldn't be playing text and they, and they shouldn't be hardcoded into your code bases or in Jira or Slack, but they typically are.
So we are helping enterprises streamline the remediation process for solving this secret sprawl nightmare, really. Okay, wonderful. Well, today we are gonna talk about non-human identities.
Mm-hmm. And ai. So to start off, can you share a little bit more about what are we talking about specifically when we say non-human identities?
Can you give some examples? Sure. So let's start with just identity.
What is an identity? Identity is something that's true moment to moment, uh, that will, you can act against an identity in its own. Doesn't really make any sense, uh, until it interacts with another system.
Now with humans, uh, I am the, uh, identity, uh, and access management as a whole field, uh, pretty well understood. It gives the world a pass keys, Fido, and, you know, uh, two-factor authentication, for instance. Uh, machines though don't have such properties, um, they can't multifactor in.
So the industry has kind of decided there's a kinda a split on this, but majority are going with the term non-human identity for all of those other things, those other entities that aren't humans. So for instance, uh, an API key, uh, that goes to a system, well, that's the identity that you're going to address from your system to call that other system. So that identity has to live somewhere and someone has to manage it.
It has to have certain permissions and scoping. Uh, it's basically, yeah, anything that's addressable. Um, in the broader sense, NHI could be internet of things, um, uh, uh, devices.
Your phone, for instance, is a non-human identity, even though you interact with it as a person. But the real problem set that we're seeing with it is just the rapid rise of these, if for every one human being. Uh, and those are 20, 22 stats, by the way, every one human being, on average, there were 45 non-human identities that an IT department or a security team needed to deal with.
That was in 2022. And if we think about how fast technology evolves, uh, some estimates now are closer to a hundred or a hundred plus. Uh, like if you think about just AI in general, like how often did you use chat CBT two years ago versus how often do you use it every day now?
Um, just, it changes that fast. Yes. And with ai, I imagine we're seeing many more of these non-human identities.
Is AI itself, would that be considered a non-human identity? Yes, absolutely. Uh, a human's really interacting with it.
Uh, but what's going on behind the scenes, if you look under the covers, like what is an LLM? It is a bunch of vector databases strung together with math, uh, saying how they relate to each other. So the system itself, no one is getting into the weeds in those machines and building, uh, uh, monitoring directly or directly interacting with the machines that are doing all of that.
Those are machine to machine communications, hopefully done over MTLS if it's done securely and properly. Uh, but that whole system, the non-union identity management, um, that's where we come in. Because again, you can't just let any willy nilly machine that can address it over the internet, interact with those devices.
You need to lock down the management side, the access management side. Uh, and we've been doing that for a long time with long lived credentials, like you said, at once, set permissions, hope you got it right, and just never think about it again. But attackers love this.
So this is actually what the problem we're truly trying to solve as attackers getting those and doing nefarious things. Now with ai, it's not just that it's driving all this innovation and the machines themselves, but people using AI is also driving up the number of non-human identities because we're building these platforms on top of these LLMs, like open ai. Uh, last year it was like over four thou, uh, 40,000 ai, uh, open ai, uh, authentication tokens per month were being leaked.
Uh, just on GitHub public alone. Um, that's a fraction of the larger internet and all the places you can put those. Uh, so if one month you get a giant bill because you hit OpenAI a lot and you just specifically didn't do that, well, you probably, because you put your token somewhere, your key, somewhere that wasn't supposed to be an attacker, found it.
And that's exactly what attackers do. They exploit every resource they can get their hands on. Yeah, that, that's pretty bad.
That's a lot for just that one, uh, platform. So what advice do you have for business leaders and for companies to protect themselves? Well, there's a lot of things there.
Um, if we're gonna keep it to the world of ai, uh, one, it comes down to just basic hygiene. Uh, these models are trained on all the data in the world. We know GitHub trains, uh, its models on, or Microsoft trains its models on GitHub Republic.
So if you've ever put a credential into a code base and pushed that out there into the world, guess what it is in the training set. So if you ask very nicely, uh, just very nicely to AI to give me credentials, they will. Um, there's that famous story from a couple years ago of someone asking their, uh, it to create a song that its grandmother, uh, the person's grandmother might have sung, but to also reveal Microsoft, uh, uh, windows 11 keys.
And sure enough, it did it, um, because it was in the training model, because someone had hard coded those. So if you're an enterprise, uh, the first question you have to ask is, and it's a terrifying question, I'm not gonna lie. Um, how many secrets.
Do we have total? What percentage of those are properly stored in a vault, uh, system like a, uh, cyber conjure or a, um, uh, terraform or not sure from Hashi for HashiCorp Vault or some other system like that, uh, where it's properly stored encrypted. There's MTLS to get it to where it needs to go, and you can programmatically call into it, it, and get it.
That's how we should be dealing with these credentials that live for any stretch of time. Um, third is think in terms of rotation about those. Uh, the best secrets are the ones that don't exist.
If you can completely eliminate a secret by, uh, changing out for a role or somehow build the roles and permissions into like, allow lists, uh, there's a project Apache Iceberg that's been doing this really well. If you wanted to go see a reference implementation of something that's storing the roles and permissions list, and then only allowing credentials to be issued to work with it upon request, and it matches that list. There's a really interesting implementation I ran into recently.
Um, but you need the thing in the rotation. So if you get them in the vault in the first place, then you can start thinking of that automation and turn a thing that lives for a year or five years into something that lives for 90 days a day, maybe a couple hours, depending on the sensitivity of the data data. But to do that, you really first need to do that discovery stuff, and that's exactly what Gig Guard helps you with.
Wonderful. So moving forward, um, AI and, and many other technologies are advancing quite rapidly. So what advice do you have for business leaders for staying ahead of these advances and, and therefore additional threats?
I, I think we have gone through the hype cycle extremely fast and extremely hard, and AI has kind of gotten shoved everywhere, uh, for good or ill, but when you get a new toy, you don't really know what you're doing with it. Um, the best advice I think is to step back and ask like, what is AI actually really good at? Uh, transcripts, it's amazing at transcripts, um, it is good at consolidating information.
You can throw out a 90 page PD and gimme a 10 point bullet list of what's the major points are. It's great at that. Uh, we've seen mixed returns on like coding assistance and things like that, not from just a security perspective.
There's a whole world and whole talk I can give on that, but also just does it really help? And I, I gave a talk recently at an ai, a summit in Vancouver, uh, about the hidden dangers. Like before, if you had to code something, you had to go look it up in the book or go, uh, engage in a conversation online somewhere, like a Stack Overflow or Reddit to get to like what's the consensus in the, the world of it, what's the best practice?
And now we're taking at face verbatim like, this is the way we do this. And sometimes it's telling us things that aren't right. It hallucinates us still alarming amount of time, but at the same time, I'm not against ai.
I love ai. It helps me do a lot of things. And where the real opportunity lies is, I think for computer science in general and especially for corporate it, uh, and applications in general is, uh, finding those edge points where typical imperative or declarative programming simply doesn't work anymore.
Um, a really good example is something we built here at Git Guardian. Uh, we call it fp remover false positive remover. And the LM is training and constantly training on finding things that look like passwords, but clearly aren't.
So if you set a password as, uh, uh, this is clearly not a password, never hard code your secret, there's no danger. But that's a really long string, and it's after the word password equals in the template. Uh, so it should be flagged except now this ai, because it's being trained and constantly learning what a pattern, a good pattern is, and a bad pattern is, it's able to say no, that's clearly a false positive like a human being would.
And that's something if you were trying to do that declarative programming, like actually writing line for line what it should look for, or trying to figure out the regular expression that it would account for that, that's nearly impossible. We, in fact, I think it is impossible at a certain level. So all this being said, what one key takeaway can you leave our audience with today?
One ki Yeah, that's a, that's a good question. Um, the biggest thing is just don't hard code your secrets. If you ever see a plain text credential that you didn't, you just created it and you put it into the vault that way, that's maybe okay.
Uh, but if you see a plain text credential any other way, that's a time to go have a conversation with the security team, uh, with your IT leads and say, look, we gotta figure out a better way to do this. If it's in Slack, if it's in Jira, if it's in Confluence, if it's in teams, wherever it's, if it's a plain tax secret, something's gone wrong somewhere. Alright, well thank you so much for coming on our show and sharing your insights with us today.
Happy To be here. Thank you much And thank you to our audience. Stay tuned.
There's more. Hello, I'm Mike Zer and welcome to the latest edition of the Techstrong AI video series. We're here with VRA Bon, who's global lead for trustworthy AI for IBM consulting.
And we're gonna be talking about, well, just what does it mean to have trustworthy AI and how do you get started? Vra, welcome to show. Oh, happy to be here.
Thanks for having me on. A lot of folks are generally familiar with the concept and they understand governance, but I think a lot of folks also just nod their head and kind of think that they're agreeing to something, but no one needs to know exactly. We're in to get started with all this.
So what are you hearing from folks and, and what does it take to kinda have actual trustworthy ai? I, I actually, uh, offer, uh, an edit to your opening statement, which is, I, I don't think people do understand in in general AI or gore governance or what it takes the nature of the actual work to do this well. Uh, I think there's a lot of misconceptions, a lot of myths, a lot of lack of understanding on, on this subject.
Earning trust in AI is so critically important in order to be able to get the kind of outcomes that we ultimately want from the use of technologies like this. But it's not strictly a technical problem at all. It's not a technical problem with a technical solution, but one that is sociotechnical.
And it, it's so interesting, Mike, when I, when I ask large technical audiences the question, who in your organization is actually accountable for outcomes from ai who, who's accountable for those outcomes? The top three answers I get are pretty bad. They're pretty bad.
I mean, the, the first one is no one overtly bad. The second common answer I get is we don't use ai, which is absolutely laughable because of course their employees are using ai, whether they're formally keeping track of it in an inventory or not. I mean, several of the licenses that this company or organization has already procured, likely has AI embedded in it and in its most recent version.
And then another common answer that I get that is concerning is everyone, and the reason why everyone is concerning is because if everyone is being held accountable, is anyone actually being held accountable? Because I, ID opine and in our last institute for business value study and opine, you have to have enough power to do the work of, of governance. You have to have a funded mandate to do the work.
And it's, it's a lot of work and it's actually expanding. It's growing. I wonder also if we get enamored with the whole idea of ai.
And a lot of the folks that I talk to don't really understand that the output, especially from these gen AI platforms, is probabilistic, which means it's a best guess and it probably won't show up the same way twice. And we are trying to insert that into business processes that have to be this done the same way 100% of the time and audited and they're deterministic. And I just wonder, in your experience, do people kind of get that or is there a mismatch in our thinking?
I think there's definitely a mismatch. 'cause there's a complete lack of understanding there. There's a, a massive gap on the subject of AI literacy, massive gap.
Uh, and you mentioned AI governance. People sometimes think that it's only generative AI that needs governance if they understand what the risks are. And of course, all forms of artificial intelligence, uh, require the appropriate s guardrails and the, the appropriate considerations to ensure that these models behave in the way that they are intended to behave.
So I, I think there's, there's a, uh, a tremendous lack of understanding whi, which is why so much of the work that we're doing right now is really introducing AI literacy in a holistic way. I think also people have it in their head that they already have some sort of governance framework and that it'll just be extensible to ai. But what are people not thinking through entirely?
Well, I mentioned that the, the work of governance is, is expanding. So for example, like you have to get value alignment with across your entire organization so that everybody who has a role to play on the subject of artificial intelligence recognizing, recognizes the importance of getting it right and, and responsibly curating it. That's one.
The second is to be able to actually capture the AI model information and the metadata about these models in an inventory system. Then you have to keep track of regulations and there's a changing regulatory landscape, but then also there's a recognition that you can have AI models be lawful but awful, which means you have to push into ethics. And anytime anyone pushes into ethics, you have to be a really, really good teacher.
Have to people like, how would you even recognize what are the functional and non-functional requirements of an AI model that reflects an organization's ethics? Has it even been detailed what an organization's ethics is and how you expect that to be reflected in technolo technologies like ai? Which to your point, like yes, definitely there's data governance, data privacy has been around for a while, but AI is another level in, in terms of the expansiveness of, of all that needs to be done when it comes to making sure these, these models are behaving appropriately and can earn trust.
And it seems like also the bad guys have figured out that they can poison these models and they can do it in a way that is relatively simple. They just figure out where you're pulling data from and start inserting some data that will get that model to either completely misbehave or behave in a way you don't want. Well, it, it, that is indeed concerning.
And what worries me from a cybersecurity perspective is so often CISOs who are responsible for cybersecurity within an organization are oftentimes not even invited to the meetings on AI investments. Like, and I'm being invited to the meetings to be able to understand like, what is this organization's AI strategy? What are the concerns?
What are the considerations? So that they'd be able to have some kind of an input on what is being procured or built with an understanding about what you're describing. But then even so, and this is I think, really important for your audience to hear, even organizations that truly have the best of intentions with respect to how they wanna use AI can end up inadvertently causing harm due to a lack of those safeguard rails.
And due to that lack of AI literacy and understanding. So it's extremely important that there's the right multidisciplinary approach to the work. What's the level of sophistication and understanding among the auditors these days of how these models work?
Are they starting to ask some more difficult questions? And is it just a matter of time before, uh, you know, a levy gets passed to somebody that's going to make everybody pay attention? I think that, um, it slowly, there's beginning to ask better questions, but again, I, I think it's still early days.
And I think when we start to see more lawsuits as an example of, uh, again, org from, with, with respect to organizations who had good intent but ended up inadvertently causing harm, that's when we're going to see organizations paying more attention. Because I, I suspect the regulatory landscape, at least within some parts of the world, are not going to be strengthened within the next year or two in, in fact, I think more parts of the world are looking at rolling back regulations in order to be able to have more investments or be perceived as being more AI friendly to businesses. One of the subtler issues in my mind is that a lot of times the data that we're using to train the model, uh, reflects a bias that's hidden in the system somewhere.
And it's not just like a bias where, um, it's about race, creed, or color. It may just be as simple as, uh, the data suggests that this area in a real estate transaction is undervalued, but it may turn out that that was, uh, something systematic in terms of redlining of that area, and now we're gonna put that into our a model, into the model, and it'll just make things even worse. A hundred percent.
A hundred percent. And it, it's why, again, when I say AI literacy, we desperately need a holistic approach to AI literacy, meaning there ha this, this is actually is an opportunity, I think for a, uh, a rejuvenation of the liberal arts, let's say. Because if you're lucky enough to be able to take a class in AI or data ethics or AI ethics, like you're likely in a school of engineering and you've sub-categorized as a coder, a machine learning scientist or data scientist, but literally not everyone else, we need to have far more interdisciplinary cross-disciplinary programs on the subject of ai.
So those individuals who will be, for example, as you said, determining creating AI models to predict interest rates on home loans actually knows what the history of redlining is. Because if they don't, they will end up calcifying, systemic and, uh, systemic biases, uh, in order to produce yet more inequitable outcomes. So it's, it's, and again, it's not because they're evil, it's not because they're nefarious, it's simply because they don't know.
Do you think we might see a spate of lawsuits on this topic? Uh, I think I've seen a handful so far already, but it, it feels like it's only a matter of time before some lawyers start delving into some discovery process for the data to figure out that the model was flawed. Yes.
And we, like you said, we've been seeing more and more, there's an AI incident database, in fact, on, on the internet that, uh, that details, uh, you know, lawsuits or times where audits were made publicly available and, uh, reputations were lost, et cetera, et cetera. But I think, again, it goes back to literacy. You know, if, if we don't have more individuals being able to be critical consumers of the tech, and to ask the questions, who's accountable for this model?
What's the level of accuracy of this output? Where did this training data come from? Was it gathered with consent?
Is, is this data even representative of all the communities that we need to serve? Like, if we don't have people trained to be asking these kinds of questions, then we're not gonna to, to get the kind of trusted models that ultimately we as a society are looking for. I think when I look at this, I often see two extremes.
One is some people are overly trusting in the data and not doing enough critical thinking. Other folks know where the data came from and don't trust the output whatsoever. So do you think that in the age of ai, we might get to something in the middle where, uh, people will be savvier about the data in general, but those that have been suspicious might become more believers because the process could eventually be more vetted?
I, I think we're going to slowly get to a point where people are saying, give me the evidence. Give me the evidence of this output. Where did this training data come from to be asking those kinds of questions and really forcing organizations to be transparent about their model and to be held accountable for those models.
But again, in order to be able to get there, we've, we've gotta change how we're teaching the subject in schools, Do we, not just in school, but I wonder, um, well, you know, folks that have been outta school for 20 years need to go back and get some courses and some lessons and things that, you know, will make them, uh, eligible to work in the future. I was asked at a summit last week, you know, what are the top three skill sets or competencies that you would want to see, uh, students double down on in the coming years with respect to ai? And I said, I don't need to give you three, I'll give you one.
And that is know how to be a lifelong learner, because this space is going to constantly, constantly, constantly be evolving. So making sure you're respective of what you wanna be when you grow up, that you, you're focused on learning how this kind of technology can augment your intelligence and how to be a critical consumer of it, because this space is gonna be consti constantly changing like this. AI literacy can never end.
So what's your best advice to folks? And the flip side of that question is always the same, which is, you know, what are you seeing out there that makes you roll your ass? Well, I would say the rolling of the eyes is, uh, as I mentioned, you know, even organizations that have the best of intentions end up causing harm.
And there's plenty, plenty, plenty of stories in the news. And it's not just generative ai predictive models too of, of, uh, organizations getting it wrong and end up ending up causing disparate harm or exacerbating existing, um, biases or unfair biases. But then also, what has me roll my eyes?
'cause I, I've been preaching a lot about holistic approaches to AI literacy is, you know, the, the school systems today and the culture of continued siloed approaches to curriculum, because we desperately need to have more holistic AI literacy programs that includes like, yes, you need to have school of engineering and computer science, so people can explain the nature of how the sausage is made. But you need linguistics, you need philosophy, you need government, you need, right? You, you need to have all these disciplines in order to be able to teach this appropriately.
And I, at opine, we need to bring it much earlier in people's academic careers and teach this subject in high school and middle school and not in computer science class. We need to teach this in social studies, class studies, because studies, if you think about it, the real nature of data, like my favorite definition of the word data is that it's an artifact of the human experience. We humans, we generate the data or we make the machines that generate the data, but we have 188 biases in counting.
And there's many good reasons why we as human beings have biases, but we have to know, like ai, it's like a mirror that reflects our biases back towards us. But we have to be introspective enough to look into the mirror and decide, does this actually align with my organization's values? Because very quickly we are moving from do I trust this AI model to, does the worldview being represented in this AI model actually align with my own?
And that's why we've gotta be better at teaching the subject, uh, to, to the next generation, if not this generation as well. All right, folks, you heard it here. Even in the age of ai, critical thinking is crucial because well, garbage in is still garbage out.
Hey, Phia, thanks for being on the show. My pleasure. Thanks for having me.
This was fun. Yeah. All right.
And thank you for all watching the latest episode of the Textron AI series. You can catch this on our website. We invite you to check them all out.
Until then, we'll see you next time. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Welcome back to Text and Unplugs. My name is Cassandra Chin, and today we're here with Melissa McKay, and we're at the CubeCon North America event at Salt Lake City.
Cool. Yeah. Can you introduce yourself?
Sure. Yeah. Beautiful venue, by the way here.
Lots of excitement, lots of people. It's been really cool. I believe we have like 9,000 attendees.
Yeah. Yeah. Pretty awesome.
Um, yeah. I'm Melissa McKay. I am currently the head of developer relations at Jfr.
Um, I'm actually based in Denver, so not a huge, uh, trip for me to get here. Um, but I've never been to Salt Lake City, so this is, this has been, uh, quite the trip. Beautiful place.
I'm happy to be here. What inspired you to get into computer Science? Well, actually it was kind of by accident.
Um, You know, I didn't grow up in, I didn't have any family that was involved in computer science in any way. I wasn't even familiar with, you know, what people did. Um, and so I knew I was good at math.
I really enjoyed that, and I was encouraged to look into some kind of a STEM degree, an engineering degree. And I chose, uh, electrical engineering. That's what I actually started to, uh, when I went to, uh, college, uh, that was my major that I declared was electrical engineering.
Well, one of the classes that we had to take for that, uh, study was, um, it was like a beginning programming class, but the very, very first thing they taught us was, was, uh, binary math and hex. And I was just in love. I'm like, wait, what, what is this?
Uh, I, I never knew this existed. And then when I, when I started looking at code and code samples that they were teaching us, um, it was, I didn't have any idea that people did this for a living. And I just, I immediately changed my degree.
So that's how that happened. That feels very coincidental. Yes.
Much to accident, very much. And it was a difficult, because it's kind of late to start learning computer science right now. Today we see like kids are learning, um, programming earlier in school.
I think that's really helpful. I did really feel behind, but with my personality, I, I kind of like the challenge. So, um, I did just, you know, I worked really hard and caught up with my peers.
Uh, so yeah, it was, And when you made the switch to computer science, like how did you overcome, like, being a woman in the field and your peers are like, probably guys? Yeah, yeah. You know, I didn't struggle a whole lot.
I mean, I did notice, especially when I'd walk into a classroom and I'd be maybe one of two women there, and in some cases, maybe the only one there, um, I can see how that would be intimidating for, for people. Um, I was very quiet, didn't, didn't talk a whole lot. Um, but the more I got interested in the subject, the more passionate I was about, you know, talking about it with the people that were around me.
So, and, and I was lucky to be accepted, um, pretty well. So I, I think even as a, even as a younger kid, I had a lot of support. Um, there was a, I, I'll never forget her.
I'm gonna name her because I am, I am just so, she affected my life so much. Her name was Mary Bieber. She ran an independent study program at the elementary school I was at, and she noticed that I was good at math.
She pushed me hard. She got me into, uh, advanced classes. And so that was the, the first time that I noticed, you know, I was, uh, as a younger girl, I was being pushed into situations that weren't as comfortable, but I got a lot of practice with it early on.
So when it came, came to doing stuff later and, and being involved in computer science especially, um, you know, all my professors were men, um, and a lot of those students were, were guys. Um, I just, I think it was just a confidence level. It, I was lucky.
I was lucky. 'cause I have heard, you know, stories from others that just anecdotal that, you know, maybe their journey wasn't as easy, Easy. Yeah.
I think sometimes just knowing someone who supports you can, like, make the difference. Yes. Um, my professors were very supportive too.
Um, no time did I feel like I was being singled out or ignored or anything like that. So yeah, it's good experiences. And like, I know like earlier in your career you were a software engineer.
Yes. But now you're, I guess, head of Devereux. Yes.
Yes. So that was quite the move. I was a developer for years and years and years.
Um, I had the opportunity to start an internship and then was later employed by a services company that did a lot of contract work for other companies. So I got a lot of experience, like broad experience in different languages and different tool sets and stuff. Um, I think that made a big difference because it, it gave me, it gave me that breadth of knowledge that you definitely need for Devereux, of course.
Um, in order to be able to have good conversations with a wide variety of people. Um, but I loved programming. You know, I loved being in front of my computer, writing the code, uh, fixing bugs, um, going to Jira, pulling a task out, you know, getting stuff done.
Uh, the planning meetings with my teams, uh, those were always, uh, really good experiences. I loved the challenge, but there was a point in time when I started realizing I wanted to do something different. Um, uh, it was time to change in my career, and I was really interested in teaching education, and that's a big portion of DeVere is education, uh, helping others, helping our customers mainly.
You know, that's a big one as well. And I really enjoy that kind of work. I also got an experience where I went to an unconference, and you know what an unconference is, right?
Cassandra, I think we met at an Unconference, uh, it was called Jay Crete. And man, it was like 12 years ago or something, is the first one that I went to. And, uh, consistently went, uh, every year.
I did not go last year. I was really bummed about that. But, um, this summer, I'll, I'll make an appearance there again.
But that experience, I, I got to meet a lot of other speakers that traveled, went to conferences, uh, were putting together these talks. It was a few years before I decided to take the jump, but I think that was the beginning of my thinking that I was going to be led in a different direction at some point. So it's been almost five years now that I've been in DeVere.
I, I am not bored. I can say that there's always something new to learn, uh, different challenges that, like I said, it's a different animal than, than, uh, you know, the strictly development work or code coding. Um, so yeah, that's the long story how I got here.
And like before you were like Devereux, like the Devereux position, you go to conferences present and you teach developers. Yes. Uh, well, jfr is a DevOps platform.
Uh, we have a DevOps platform, DevSecOps platform. And so I, I ended up talking to not only just developers, but uh, a lot of operations folks as well. So that was a whole nother aspect that was relatively new to me, uh, being able to, to get in, uh, with that crowd and be able to address their concerns.
So yes, um, being able to speak with developers and getting them to be conscious of like how they were actually building their software. Uh, thinking of things like what dependencies they're pulling in, maybe some security issues that they had never thought about. I, I really enjoy speaking to younger developers and getting them caught up on, you know, the, the general software processes that they're gonna experience, you know, early on in their careers.
And, uh, so yeah, I feel like they don't teach those software processes in school. They don't, I, I noticed this too, especially when I graduated. I was overwhelmed with all of the new tools that I needed to learn.
You know, I, I wasn't really familiar with BUILD servers. I wasn't familiar with CICD. Um, even source control was challenging for me.
That was the first time, you know, when, when you're in school and a student, maybe you don't always have the experience of working in a team, so you're never presented with the problem of trying to keep code coordinated between, you know, several different people. So, of course, um, when I got an internship, and I highly recommend doing this, or anyone in a computer science, uh, program, uh, get that internship because that's where you're going to get the real job experience and be able to see what it's really like being a software developer. It is not, uh, sitting alone in a corner, uh, doing your own thing.
That is not how it is. There's a lot of communication, uh, that is involved a lot of, uh, understanding requirements and that kind of thing. So, uh, yes, in school you learn the basics, you learn code, you learn, um, you know, those details, how to write code, but, uh, the rest of it, you're gonna get on the job.
And like, being a part of deral now, like, do you still face any issues with feeling like you're the only woman? Yes. I still get in situations like that.
I think in, in Dere, I have had a lot more of experience with other women, mainly because part of dere is, uh, coordinating different teams within the company, making sure those communication lines are open. So I get a lot of access to other areas of the company that, where there are more women. Um, and I'm not sure why that is, but like for example, uh, you know, our marketing department, we have a ton of amazing women and men in our marketing department.
And, but I do get, you know, more interaction with women there. There's still plenty of times, especially, you know, when I come to an event, I may go, go to a session even, and I, I'll look across the room and maybe there's, you know, five women in a, you know, a hundred person audience. Occasionally that does happen.
Uh, and I'm not sure why that still is today. Um, but I, I think a big portion of it, at least for me, in my own experience and getting here, was just getting that support. Um, getting, you know, not being subject to the biases that we all have unintentionally in a lot of cases.
And, and I got, um, you know, pushed, pushed and encouraged into this position. I mean, personally for me, like, I'm pursuing computer science, but I've known you for a long time and you're the industry. Yeah.
So you're like a pillar of support. Awesome. Uh, that makes a difference too, is getting women in these positions and then having us talk about it.
So I love doing this with you, Cassandra. I think this is very important, um, to get that out there, to have examples for other girls, other women that want to get into this career. It's absolutely Possible.
I hope we can inspire more women to get into computer science and we can build allyship. Yes. So thank you today, Melissa.
Thank You. Good talking with you. Yeah, This is Textron tv.
Hey guys, thanks. VI throw. We're here with Prashant, who's vice president of product for Aris.
And we're talking about, well, DevOps and how it's all evolving from here. Prashant, welcome to the show. Hey, thanks Mike for having us and me Every now and again.
We have this moment where everybody has this conversation about, well, DevOps best practices, and what are they and what do we need to do to achieve that goal? And I kind of sometimes take a step back 'cause I sometimes wonder if each organization kind of has a slightly different definition of DevOps and they kind meld it to fit whatever they're trying to accomplish. And of course, you know, the latest buzzword in the DevOps landscape is platform engineering, which, you know, may not fit everybody, but what's your sense of where are we right now as we're kinda looking at the next year?
Uh, that's a very interesting question because, uh, something that we deal with on a regular basis, as, you know, um, uh, you know, uh, I run Chef, which has been one of the early, uh, early pair in, uh, DevOps. And, uh, the way we work with our customers is actually looking at how mature they are in their DevOps journey. And we have, uh, built out, uh, maturity matrix as well, with which we can assess, um, and tell them where they are and, uh, give them some pointers and being a trusted advisor and see, uh, you know, so that they can improve in their maturity model.
Well, but to your question on where they are, we are honestly seeing it's across spectrum. And, uh, as compared to like four or five years ago when I started, um, taking over chef to now we see a big change in a positive side. So, uh, I think six or seven years ago, agile was a norm, uh, that everyone was opting and it had taken adoption, and that was to give predictability and repeatability in software development aspect.
And at that time, DevOps was still picking up. And now we see DevOps is a practically a norm in the new organization who wants faster type of market, who wants, uh, to have a high quality software, reliable software and production. So they apply, they choose these practices.
But like you said, uh, the maturity varies, uh, from team, team. So the, the something that is constant that we are seeing is the spirit of spa, you know, embracing or the, the fact that they're embracing the spirit of it, which is to reduce the friction between the teams to increase, um, productivity or to reduce time to market. And that is the common goal that we see everyone working towards.
But, uh, the way they approach and how they have structured team is different in different organizations. Some organizations are still kind of, for me, whereas some organizations are much, much ahead. They have identified key metrics that they need to track.
They have a very clear path of measuring or publishing those metrics and also have a plan to improve. And some of them have gone further ahead on integrating security into the DevOps, and that's also, uh, accepted as DevSecOps. And which gives not just, uh, reduce time, which does not, I mean, which just, uh, not just reduce time to market, but also gives that safety net of security ahead of releasing the product, right?
So we see, uh, across these spectrums, One of the things that strikes me a little bit is a lot of the conversation always seems to assume that we have an infinite appetite for building and deploying more applications. And I just wonder, you know, are some organizations kind of try to figure out what is the top end of that number that they can actively manage and support? Yeah.
Um, that's, like you said, it's a very, uh, so there are two ways I I look at it. One, does the business need, uh, to deploy those many applications, you know, in the frequency that they're expecting? Another, is it just because, uh, you know, the technology can, uh, meaning, you know, if I have taken, if I have optic cloud native tools, if I'm using, uh, uh, modern technologies, containers and Kubernetes, for example, which gives ability to deploy applications faster, just because I have that ability, do I want to deploy faster?
We see both of these. And the second one is more of an enthusiasm, which I'm also a engineer at heart, and I also do want to do things, uh, as fast as I can. Um, but, uh, the risk there is breaking things or not really having alignment with other parts of the business.
I think that's where it may, we need to focus on, uh, the first aspect. Does the business need a faster deployment of application or does business need multiple applications to be built and managed? So if you look at, uh, some of these super apps on the mobile, well, uh, where it is actually a con, uh, you know, it's a collection of let's say a taxi booking, food ordering, grocery shopping, uh, you know, anything that you can think of, those applications are designed in a way that it meets multiple needs and the market is as such.
So there is a business need to actually build those applications and manage those applications, um, in the lifecycle or the fast lifecycle they want. Whereas if you look on banks or any financial sector, they, their customers use two or three core applications and they value stability over minor upgrades or new feature every month or every day or every week. So I think the, where we have worked with organizations who have that past need as well, it comes at a cost, right?
Uh, it can be implemented, but it comes at a cost. And the cost is, you know, as the saying says, you know, we only see the tip of the iceberg. The real cost is underneath.
So what are some of the costs that they need to keep in consideration cost, and foremost, the operational cost. It is not just software development, but operation. What does it mean?
Uh, how do you, how do you, what, how do you test that software that your application that you build? How do you integrate it into your build pipelines? How do you release, uh, those build pipelines?
How do you monitor whatever is release to make sure that they're up and running, and how do you ensure that sick? And then the next, uh, aspect is security. Security cannot be afterthought.
So if you're releasing those applications, if you're operating in, let's say if you're using accepting credit card payment, you need to get PCI DSS compliance. If you are operating in us, you need, uh, so Europe, you need GDPR compliance. So are those considered?
Who is going to manage that? Who is going to maintain that? And there are, there are responsibility to report audit and report periodically.
So all these things needs to be considered. And along with that, if you have to operate at that pace, keeping all the security and compliance constraints, you have to automate, you have to embrace some of these methodologies that DevSecOps don't, uh, you know, uh, prescribes. Are we trying to find some middle ground these days?
'cause I feel like if I think about the history of DevOps, a lot of it got started as a reaction to centralized it, and there was too much restrictions and people didn't feel they had the level of freedom, and there was this whole shift left mentality, and the developers would be able to manage everything. I think in hindsight, that is not feasible, and the developers are kind of choking on a lot of the things that they're now being asked to manage. And we're seeing the rise of platform engineering, but can we get to some level of centralization that all the stakeholders involved can get behind?
Uh, in fact, you kind of cured up the answer for me in your question itself, and that's how, uh, we are also seeing things evolve. So like you really said, like you said, um, uh, at some, you know, the one extreme where a team is asked to do all the task, right? On the other extreme, uh, which was what we had many time ago, a long time ago, where there was totally compartmentalized team, it was almost like a waterfall model.
Software developer creates a bundle and hands it over to ops, ops figures out how to deploy it, and things get stuck. Uh, you know, and we don't know where it was stuck. Now both of them have, I mean, clearly the second one is disadvantageous, but, uh, uh, everyone doing everything works in small organizations, but, uh, does not, does not work so well if as you start scaling, because it is hard to implement governance, it is hard to create policies and monitor them and ensure that people are actually doing the right thing, uh, and also the right way.
And that's where the platform engineering, uh, discipline is evolving. I think Gartner coined it, but each of, uh, ma many organizations are using different terms. But, uh, now we are seeing designations also crop up, uh, in LinkedIn and in our customer base where they're identifying their teams as platform engineering.
So they have three or four responsibilities, one, identifying the tools required and, um, standardizing the tools and the models of upper end of those tools. Second, defining a policy, um, uh, across our application, security compliance, codifying that and putting it as part of their software development lifecycle. I'll, I'll take an example, uh, uh, and see if, if, uh, if I can kind of, uh, you know, explain that better.
So, you know, as you know, developers have access to A-W-S-G-C-P Azure Cloud accounts, and they can go click a few buttons and spin up PC two S3 or whatever services they want outta these cloud accounts. But, uh, the organizations want to regulate how they use these services. So they, there are, uh, these platform teams create policies that if you use any of these cloud providers and use database or storage, they should be encrypted at trust and encrypted at transition, right?
Um, so then the policy is created. So whenever a new developer, uh, or an engineer, uh, even he or she goes clicks on AWS, the, based on the policy that is implemented by this, uh, platform team, platform engineering team, the, the services, when they get provisioned, they get provisioned as per policy. So the, this is a kind of a, uh, kind of balance that, uh, teams are can getting to where they're giving adequate level of, uh, uh, autonomy for individual developers, but from an organization level, they have control over, uh, how, how diverse things can be.
So they kind of like get the benefits of self-service and there are guardrails, but I'm not, um, you know, creating a ticket hoping that somebody is gonna come around and fulfill my ticket in timeline for measured in, uh, days and weeks rather than hours. Yeah. That, that's the, that's the approach there evolving to, uh, and there is an interesting model that is coming up, um, which was, um, used in software development and, uh, it's making its way here, which is, uh, internal open sourcing.
So all these platform engineering teams, they are not really taking the burden of implementing all. So r permutations and combinations, they create, uh, templates, they create, uh, the basic policies, and they, they also create a framework with which let's say a Java developer, um, are some eso uh, programming, let's say, um, uh, you know, developer, there is a small team who is using lan and there are no policies that are, uh, defined by this core platform engineering team. They create the framework where this team of air airline developers can actually submit a pull request for, uh, Orion, and the, hence the auto, the centralized platform engineering team knows and accepts, um, whatever change is coming in at the same time, they don't have to be SMEs, uh, for all these esoteric things, right?
So this is another model that is emerging internal open sourcing, uh, even in platform engineering or in DevOps, DevSecOps practices. And this is also seeing a lot of this is giving us a lot of ion in security space, because security is hard for ops people, and ops is hard for security. So this kind of, or internal open sourcing is giving, uh, uh, flexibility for some of the tech folks within security to contribute into automation.
So they also enjoy that, or they, they, they want to contribute, but they don't, they don't want to get, uh, you know, uh, involved full ffl. So we are seeing, uh, this also getting traction. Of course, this is all happening in the background with ai.
And so what's your sense that, well, just how big an impact is AI gonna have on DevOps and what will be the job of a software engineer going forward? So let tell you what it won't be, at least for the near future, and, uh, because that is what, uh, we have seen, like, we have also tried, and we, we operate with large customer, customer base, especially operating in banking, software, uh, uh, software, financial segment, and federal space, right? Uh, so in DevOps, um, especially operate, uh, tools like share, uh, the scripts that they write or the code that they write operates at a very elevated level partnership, meaning it's almost a system user, so you can't have room for error.
So consequently, um, the code that is generated using generative AI cannot be trusted. And we have had instances where they have used it for, um, uh, you know, curiosity, and they thought it did good enough and put it on production. They had downtime of hours, our critical data was wiped out.
So I don't think, uh, gen AI is going to replace code generation for, uh, critical applications or, uh, you know, code that, that are required to manage critical infrastructure. It is, it can be like a co-pilot, uh, how we are, how we are seeing in document generation, um, and many other cases. It can co it can, uh, coexist with a developer and help, uh, improve their productivity.
And, and I think that is what we are seeing. Um, and there is a very, uh, very, uh, you know, nuance. What what I learned is these elements are really good in natural languages, but when it comes to code, and especially when it comes to, uh, code base or code, uh, coding, which is not that big, uh, in, uh, let's say leite, chef, puppet, Ansible, any of these, or Terraform, there isn't such a vast database that it can learn and it can be trained.
And, and there is a lot of effort that needs to be put in or trainee, uh, uh, as compared to language. If you think of, uh, English or any other language, there are petabytes of data, uh, uh, you know, that is available in world by web, and the data that we have for real coding is less. So consequently, this code generation with, uh, high level certainty is going to be a slow process In my mind.
It might have a bigger impact on things like testing than it would on actual the code that we're gonna use ultimately in a production environment. Exactly right. And not just testing, testing, you pointed out testing.
Uh, and that is where we are seeing a lot of usage. In addition to that, uh, observability, that is another place where, uh, pattern recognition is something that, uh, AI is able to do very well. Uh, we had predictive analytics for a while, but that, uh, the, the with, uh, with, with the technology enhancement, those predictive analytic models have become much, much more retro.
So we have seen, uh, and it can, it can consolidate data from hundreds of sources and, uh, we can train those models faster. And we are seeing a lot of our customers use it, uh, not just for, uh, creating alerts, but actually, uh, going through all the alerts and prioritizing the alerts that they should work on. And in some cases, it even has helped identifying a pattern that, hey, some developer has been making these changes, and whenever this developer commits changes, there is a downtime, so maybe you might want to put some additional, uh, monitoring on this developer.
So we are seeing those, uh, level details also come out, uh, through ai. To your earlier point, we have made a, you know, a significant amount of progress when it comes to security, but we got a long way to go. And I can't help but wonder as we kind of look at code and AI and governance, that somehow or other maybe that will improve the overall state of security.
'cause we'll be looking at the code closer than we have in the past. I Mean, if you look, uh, going back to our maturity model that I kind of touched upon one, one, the last, uh, stage or stage, uh, or as we call it in that we see security policies codified, and it was surprising for us to see how, uh, how good the traction there is. Um, so there are a lot of organizations who have, who have invested significant amount of time and effort in codifying, first of all, writing down a, uh, organization-wide security policy and then codifying it and using tools to automate.
And this is, uh, this is possible not just because of tools, but also some cultural, uh, uh, you know, tweaks that we have done. One common thing that we have seen is actually identifying champions, uh, security champions across the teams. So, uh, you know, we, we in progress have also adopted our CISO is really a one person, uh, which, which sounds very, uh, rare because whenever you hear from a ciso, you're like, oh, I'm in trouble.
But, uh, you know, getting that, uh, getting that feeling out of people's mind is the first step. You, you want to, you want to work in an organization where you see your security team as a partner, and that can be done, you know, uh, in various steps. One is educating us, educating people who are of, uh, who are in different disciplines.
Um, so that is fast. And second, creating champions. So we have seen organizations where a security team has a formal training program or, uh, program around cre identifying champions and training them, and third, and reviewing the architecture and, uh, early access, let's say alpha beta releases from security perspective and bringing it as part of the, uh, release process.
And, and that way things are incremental and, uh, they see a lot of, uh, advantage going through. For example, one of, a couple of our customers include some of the, they do pen test in early stage of the product release and whatever test that per done, they automate those pen tests and include that as part of, uh, as part of their incremental release between, let's say alpha to beta, the general availability. So at the time of general availability, they have proof that they can provide to security teams saying that, Hey, you did a hundred tests, all of them are failing, so that means our system is actually doing great.
Uh, so if you really want test, go find a better tester so that, uh, he or she can actually look at a different perspective, uh, than what they have already looked at, because we have covered our basis on that. So ultimately, what's your best advice to organizations right now as they kinda look and evaluate all these aspects of DevOps? I think arguably there's more stuff up in the air than in recent memory.
So what to focus on. Yeah. Uh, so the general guidance that we give is look for a few business metrics.
And, uh, if you don't have metrics, uh, then the effort is very fix. You can't really justify the effort that you put on. So there are a whole lot of metrics that one can look at.
Um, so some of the sta uh, simple metrics that we recommend to start with is uptime. SLA, do you have an up SLA, if not measure, start measuring that. And, you know, the industry, industry benchmark says you have to be at least three nines if you are operating a software as a service.
But it can, uh, you know, many of them offer offer up to finance. So see where you are. And another metric is, um, meantime resolution, meantime, P-M-T-T-R, meantime resolution or a response.
So if a customer responds or requests or, uh, reports an issue, how much time do you take actually to resolve that? And that is, that looks like a very simple metric, but that gives through, that throws a lot of light onto the amount of disconnect, uh, we have across teams. We had, uh, a very, uh, interesting experience that, uh, our customer reported that they, the change of the change that was required to resolve the issue was, let's say, uh, a punctuation mark, but it took three months for them to put the release out because there were approval process and those approval process were not automated, and those teams had different priorities.
So just looking at that simple metric like MTTR can be very, very eliminating. And a couple of other little advanced metric is, uh, uh, change failure rate, uh, as in, if you are deploying a software, how frequently is it changing? And, uh, uh, you know, what is the lead, uh, time for change?
For example, if someone asks for a change, how much time does it take for us to bring those change? So there are a whole lot of metrics, uh, I don't wanna bore with, uh, you know, list of metrics, but identifying four or five metrics and measuring them and being drilling down, uh, into the details of why is it bad, how can I improve it, and how can these practices that hundreds and thousands of companies following, can I, how can I inculcate that into my organization to improve this one metric or three metrics? And I think that is the way we recommend and we help our customers to be successful.
Alright, folks, you heard in here this old thing that says, well, you know, things measured or things done, but if you're measuring the wrong thing, it might not matter at all. Hey, prate, thanks for being on the show. Thanks Mike for having me on the show.
All right, and back to you guys in the, Hey everybody, welcome to Textron Gang out, Mike Baard, and we got a little bit of everything today. We got Espionage Cyber Monday and some cloud native app dev stuff. So we'll be back in a minute.
All right, welcome back in the A block. Well, it's pretty serious stuff. Uh, there's all kinds of reports coming outta Washington about the extent to which the Chinese may have compromised our telecom networks.
Of course, this has been going on for months now, at least. Well, it's probably been going on for years, but, uh, we've been aware of it for months, and yet we don't seem to be making a lot of progress. And then suddenly somebody appears to have, uh, made some closed door testimony to senators and Congress and everybody's flipping out.
Um, John, you know, what is up with this whole issue between us and China and espionage? It seems like we've known about this since. I don't know.
I remember John Chamber screaming about this stuff and Yahweh equipment, and we had money set aside to get rid of all this equipment, and yet it's still in there. So what's our problem? Oh, it, yeah, it's been going on, it's been going on for years.
There's this, this form of warfare, digital warfare, asymmetrical warfare that's been going on between the US and China, and to a lesser extent of Russia and Iran. And this latest example, you know, Mike, I have to admit that I got this confused with yet another breach that we can talk about. But this one in a sense, it involves several large telcos, which evidently this started in the spring, if not earlier, and it's still going on.
Uh, SEAS I admitted, which has led to all sorts of angst and, uh, a rare joint advisory between the FBI and NSA recommending that people should use strong encryption. Yes, strong encryption to battle this group that's called itself salt typhoon. So in recent months, this group has gained access into it environments of several ISPs.
And, um, there, as you mentioned, there was a US government agencies held a classified briefing, I believe it was on Wednesday. And, um, was it the F-B-I-D-N-I-F-C-C-N-S-N-S-C Csup, they all got together in a closed door briefing to talk about this. Um, you know, one thing I was gonna mention, there's a group, not Saul Typhoon, but something called Full Typhoon, which, um, the FBI director Ray, referred to as the defining threat of our generation.
And that in included a Chinese sponsored group that was focused on prepositioning themselves within the US critical infrastructure to launch cyber attacks in the event of some other major crisis or conflict with the us. So, as you said, this has been going on for years. I think it's gonna escalate, given the political climate and, um, the uncertainty around tariffs and ai, et cetera.
It's just, it's a can of worms. And I, I don't know if we can put the top back on it. Uh, Mitch, you've been around this space forever, but, um, what do we gotta do here?
Do we just gotta rip out all the gear that we got from China that's in those networks? Or is it more complicated than that? Well, lemme just comment on it first.
First of all, we've taken our eye so far off the ball on this and not paying attention to it. We've been, you know, goofing around with, you know, the election and insurrections and whatever and all this other baloney. And this is serious stuff.
This is, this is a far five alarm fire. And I'm not trying to just be hyperbolic about it, but let me be hyperbolic about it. Everything touches our, our telecommunications networks and our telecommunications networks touch everything.
And this isn't a hack, this isn't like I'm stealing credit card data and social security numbers. This is, this is an infiltration into our networks. It isn't one server that got hacked and then they did something.
This is them getting into those networks, not only gaining control of the things we know about, but getting themselves into other systems and servers. So it, it isn't just computers, it's applications, it's network equipment. 'cause all, all of these networks now are software defined networks.
They're software elements. They're not hardware gear like they used to be. So it is, if you can get in and move laterally, it's not just move laterally one direction, it's 360 degree lateral movement all across these networks.
And I think, I, my prediction is we will find this is 100 x more extensively infiltrated than what we're reading about in the media. So I, I'm serious. This is, this is deadly serious stuff.
So you wanna see airplanes starting to fall out of the sky. You wanna see money go missing in, in financial transactions. You wanna see your 401k disappear.
You want to see our military, um, you know, become ineffectual. You know, while we're goofing around with who should be the defense leader or the, you know, CAA, whatever this is real stuff. This, they're, they're, they are doing some real serious damage here.
And it's, and it's a low and slow kind of activity. That's what's hard to detect is when something takes months to do, it's kinda laying in weight. Right.
And when you see it, it only is such a big thing. Big thing because it's happened over such a long time before we've discovered it. So we need to get serious about this or, uh, we may, uh, the electricity lights may go off.
Yes. That, that's interesting that you mentioned that mish, because years and years ago I went to this summit, uh, I was invited, uh, on backgrounds. It was in Monterey and there were defense department officials there, various people from the, the Pentagon et cetera, private enterprise.
And they were talking about this is pre AI's growth. And they were talking about, uh, our water supplies being shut off, electricity, financial systems being, uh, neutered, so to speak. All these different scenarios because a lot of the countries and the groups within these countries that are waging more against us, they can't, I mean, in a conventional warfare, they can't compete with the United States.
So they have to find another way. And, um, it goes both ways by the way. So they were mentioning some of the stuff they had tried in the Middle East back in, back in these, back in the early two thousands.
Um, and, and this is just, it's just escalated. And I think you're completely right. There's, there's a level of this that we have absolutely no idea of.
And that's intentional, by the way, in terms of the adversaries. They're just probing and seeing what they can do and biting their time and infiltrating. Yeah.
And it's a lot about compromising, getting in and then just staying there, having a presence there. So you can con, you can do things with compromise systems or networks. So when we see announcements from the FBI and from Apple and Google or whoever about don't text to use a, use an encrypted application, that's, that's a very edge symptom of what's going, that's not the issue.
So think about what they're saying. They're saying don't send text messages. 'cause any of those are susceptible to being read by by the Chinese or anyone else that's in our net.
They are in our networks. And so that they can see all that is what they're saying. So don't use a system that's an encrypted.
Now is it end-to-end encrypted? That's the real question. But anyway, my point is, using a WhatsApp is, is a symptom, a solution to a symptom, not a, a solution to the cause.
And that tells you, at least gives you an indicator of how pervasive this is. If we're that concerned about our text messages being read, trust me, it's much more significant than just your text messages. It's everything.
So you go ahead. Uh, sorry Mike, I was gonna, putting the onus on the, the average end user to encryption is your friend is not this the right solution either. And this is the who, what, when, where a phone calls with, you know, all of these info pieces of information put together, they can determine personal information about people and, and the onus having to be on the end user, I think is, is a huge mistake.
We have heard from Verizon T-Mobile lumen and at and t and all have said, Hey, from what we understand, know, customer data has been compromised. However, I think given that it's the who, what, when, why of phone calls, all that metadata together can tell stories about people. And we don't know who, is it everyone, is it spec, is it specific individuals?
Probably. But it's, it's gotta be something that has to be done that the end user doesn't have to worry about. 'cause that's that, I think that's, um, that's a huge problem right there.
I think we should clarify what the carriers are not saying there, which is, um, the metadata seems to have been stolen. And if I have your metadata, I can tell a lot about you. And then two is apparently, uh, you know, adding insult to injury here, they did steal, uh, espionage or surveillance data that our agencies have been collecting, and then the Chinese now have access to it as well.
Mitch, there's a debate going on in Washington about whether or not the time has come that we need an actual cybersecurity department and a and a cabinet level person to go drive this conversation. Because it seems like, you know, csun, all these folks and the FBI, they're doing a great job, but it still feels a little disjointed. So do we need to bring all this together?
I'd have to go back and look when I said this, not to say I told you so, but I said the exact same thing probably nine months, maybe a year ago, of we have to elevate cyber, cyber and cybersecurity to the top most. It's as equally as important as aircraft carriers and nuclear devices. I mean, this is literally, you know, ending a society kind of activity.
You, you could complete, if you imagine if you corrupted the water supply, electricity is not something that you can depend on anymore. All of our communications potentially either be interrupted or intercepted and used against you. You, you have total control over a society, right?
And so I, I think we need to quit goofing around. This is serious business and it's one of the things that frustrates me about Washington. People are, you know, upset about, uh, about, uh, inflation rates.
Trust me, we have, those are, those are low levels compared to what could happen to our society if we really are, if we really are disrupted by, by the Chinese or other entities. So it's, it's time to get deadly serious about this and put competent people in leadership roles that can, can lead us, because there's good things happening in, in, in c in CSA and other parts of the, of the organization. But they're, they're kind of hanging out there doing their thing without a real strategy and somebody leading across all those agencies and conducting it.
You know, this is, this is the 2001 nine 11 event that, that we're looking at that could have a massive impact on us. I'm, I'm serious. It's, to me, I'm scared.
It's a very scary thing. Well, to make it a a little more interesting, John, there's a report in the New York Times talking about how the Russians have put a satellite up at the highest levels of space that includes a dummy warhead. And the idea here is that they're testing the theory that they might be able to blow up a satellite that takes out every other satellite that's out there.
So are the stakes in this whole thing just getting raised to a level that we're just starting to comprehend? Yeah. Yeah.
That, that's interesting. I saw that story that you sent earlier today, and it's, it, it raises the stakes and it, it, it's, and I don't, and I'm not being flippant here, but this is like James Bond stuff coming to life. And I'm like, Mitch, I, having heard about this, having written and having written about it, and Mitch actually was a source for the, a book, what we did as part of what the book that we did years ago, this was kind of something we looked at on the side as something happening in the future.
And it, it is frustrating, um, given what's at stake and what our government isn't doing. It's trying to, uh, with AI in a certain sense, it kind of opened their eyes to the possibilities of things that could go wrong. And they actually, to the credit of the government, they have enlisted people who actually understand the technology and and use them as advisors.
Um, so there is some sort of progress. But I, I actually, I was thinking of the same thing that, that Mitch was, I I'm thinking we're gonna have some sort of incident, um, some sort of digital, they used to call it the digital Pearl Harbor effect, right? Or a nine 11 type of effect.
Something like that is inevitably going, going to happen. It's really weird too, because I think Trump in, in a kind of a weird way, mentioned like a, a, a Star Wars defense of some sort when he was campaigning. So, um, somebody's chattering chatting into his ear, or at least they're, they're, they're trying to think of it in, in like a kind of a space defense or a cyber defense issue.
Uh, I just, I'm just afraid though, just given the uncertainty of who runs what and the change in administration and where eyes are are not on the ball, we're thinking about, we're all distracted by things like tariffs and inflation and, and this is the really important stuff that we should all be concerned about. Deck chairs on the deck of the Titanic, just yeah, be careful what we're arranging. Yeah.
Um, Lisa, I feel like the carriers are still treating this as some sort of PR marketing issue and not a national security issue, so that they need to kind of step up the way that they are talking about this because, um, you know, the first thing that they're putting out is a statement about, you know, well customer data, this is like a bigger issue than just whether or not, you know, your text or my text went miss it, Right? No, it's a huge issue. And I think from what I gather, there's a lot of information that, that, as Mitch is saying, we don't know that the carriers don't know either.
I think because breaches are so common these days and everyone is worried about my data being stolen, that's the first response in terms of no customer data was compromised. Or several weeks ago, Verizon said, we became aware of this. Um, they say, Bryon said, we understand that focus was quite narrow.
I don't know that they know that, and it's probably not even true. So they have to manage this from a marketing and a PR perspective very carefully. But they need to get, be more informed.
And I think they're probably struggling to try to get the information from the government and from, and even CISA said they couldn't offer a timetable for remediation. So I think in some cases the carriers might be flying a little bit blind and are trying to put out messages that will as squash the concerns. But like I said earlier, I think putting the onus on the end user for, you know, encryption is your friend is, is the wrong thing.
But maybe right now it's the only thing. It's it's the first line of defense, which just seems so odd to me that, that that can't be it. And we have tensions with China across the board here, right?
We're talking about Taiwan and semiconductors, and we are limiting access to equipment, to them equipment for building semiconductors. And now they're saying they're gonna limit access to the metals that we need to build semiconductors. So John, is this just part and parcel of, you know, a a whole slew of things that are maybe we're sliding into something without realizing just how big it is and Whoa.
Yeah. Yeah, I was thinking about that. If you're a historian, it might be in the early days of World War I, right?
Right. Yeah. This, it, its form of escalation, like on multiple fronts that leads to an aggravation and antagon and agitation between multiple countries and, and their, their whatever their end games are.
So in a sense, it does build into it, and it also puts the tech industry in a weird, kind of difficult situation, not just with terrorists, but the relationship in general with China. And we're so dependent on China. And when you think of a company like an Apple or a Qualcomm, uh, and it affects the entire ecosystem.
The, the critical infrastructure, the supply chain, uh, it, what have you. The, the results, I mean like eight 15 to 20% normally of apple's revenue emanates from China. So this is a, um, not just a a milit a military or defense related issue.
It's a economic issue. And, um, I just, I think we better be better be careful about our sabre rattling with, with China, because I think we're, we're playing with fire in a way that, um, has longer range, deeper implications. I think that becomes the ultimate question, right?
To what degree are we willing to make certain sacrifices that would be required to disengage for China? I'm not saying we need to go to war per se, but, um, there will be an argument that says we need to have a strategic policy that says we're going to quietly over the next four or five years, start moving strategic things outside of China, not be dependent upon them for manufacturing. I mean, you've heard all these, uh, issues before and you know, Mitch, how long might that take?
Well, It's, you know, think about how we've, um, progressed in our, our thinking about national security with Homeland Security Department. And one of the first steps was coordinating information flow and access between agencies. You know, one of the fundamental problems that we recognize in in nine 11 was, you know, it's sort of the, uh, police and fire and the sheriff department were all on different frequencies of, of radios to be real simplistic about it.
Um, and so getting people to be able to communicate effectively, share information both at the time of, of an event, but you know, just as importantly in the background of understanding what's happening, um, 'cause it's this detect detected in one area. You know, we all watch shows like, you know, FBI on TV or whatever, they have all those great screens where they can kind of connect all the di uh, dots in, in four minutes and find who the bad guy is and where they walked across the city, and then they co arrests them. But to do that is, is really a complex task.
So that information sharing is vital, I think. I think the, the next part of it though is yeah, that has to be, to take it to the next level. You have to back it up by a strategy.
Think about our national defense strategy from a military standpoint, right? The kind of wars that we're prepared to fight, the defensive, uh, posture that we have to take, um, changing from World War II to Vietnam or guerrilla warfare to cyber defense. And, and we've worked on pieces of those, but I think the real challenges, I think the, the bigger issue is, is our cyber, uh, both, uh, offense and defense capability has to be equal or at above what our physical, uh, t um, uh, tactical, not tactical, tactile military, uh, d capabilities are.
And, uh, I'm not saying we aren't doing anything there, not, and by, by any stretch, it's not an area that I'm, I'm directly involved in and have, you know, lots of clearances to see and everything, but that is the world we live in. And that's, that's how you then roll the tanks in after, you know, all the power's down and everybody's, you know, clamoring for, for water and you know, food. So it's a totally different strategy.
All right. Well, folks, I think we're gonna shift gears here a little bit, but I would just say next time you're crafting that email or sending a text, be aware of it wherever you're sending it to. There's a lot of other people looking at it.
Hey, we'll be back in a minute. Modernize your business to fuel innovation and elevate customer experiences with the builder community. Hub AWS and its partner network.
Provide essential tools for transforming applications and infrastructure to fully leverage the cloud. Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably. Visit the builder community hub to learn more.
All right, we're back with something that hopefully is a little lighter than the previous block, but, um, looks like Cyber Monday hit another record in terms of the amount of revenue, how much money was spent. John, I know you covered this in there. Continue to look at what's going on with digital e-commerce, but what's your take on this?
Because, you know, theoretically we're all supposed to be involved in some sort of recession, and yet we find money to spend for Christmas. Uh, uh, yes. Maybe we're spending before the recession fully hits us.
I don't know. Or before inflation even gets worse, I, I don't know. 3 billion was the figure on Monday.
I kept having to update it for the story. I got the numbers from Adobe Analytics, so that number is up 7% from last year. 7 million was being spent per minute.
I think there were about 73 million people were shopping that day. According to Adobe, Salesforce, a actually its credit a had another report. 8.
So anyway, they were looking at, we're looking at several, uh, influences, uh, AI driven chatbots and assistance is spurred shopping habits to consumers. So the Black Friday traffic, for instance, to retail sized from chatbots was up 1800%, 1800% compared to the same time last year. There's also this, of course, the buy now pay later, or BNPL as they call it, um, which was up significantly.
5 in 2022. 5. In other words, people are gonna buy, buy now and, and, uh, pay pay later through a bo models one.
One other thing was Amazon, Walmart and, and Target were, because of the, the fewer shopping days between Thanksgiving and Christmas this year, were pushing, uh, sales and pushing certain promotional events earlier. So that played into the momentum and to experiment. I, I actually did go in on to a Best Buy on Monday and, uh, just to, to actually make a purchase, but also to just experience what was going on.
I talked to some of the people there and it was in absolutely insane. Um, and I, I thought about you, Lisa, when I was writing the doing this story, because I know you're gonna have a lot of, you have a lot of insight into, into what's going on. But it was, again, a continuation of, of AI actually really goed things on, on this, this year's edition.
One of the things that surprised me, John, and I wonder if it surprised you about the Adobe survey of 5,000 consumers, was that 20% of those consumers were reliant on AI chat bots. And that surprised me because we hear so much negativity on chatbots. I'm one of those people that's, I'm very patient with chatbots because I know we have the opportunity to train the models and help it learn more.
Um, but did that surprise you that the number was that high? It did. I, um, yes, but you know what, I'll admit something.
I used the chatbot that day. I was looking for something, I was looking for a charger, I was looking for a secondary charger for my, for my laptop, and I did actually fall into that. And it actually was highly effective, I have to admit.
And it was, the experience was much better than I expected a year ago. I never would've done that. So, um, yeah, that was, uh, that, that number, that number was, was high, but not entirely surprising.
Um, because a lot of the purchases, the most popular purchases, and Adobe looks at those as well, involve things like digital cameras, uh, smart pickers, televisions. Yes, yes. Uh, Sony PlayStation five, for example.
A lot of, a lot of electronic gadget trees. So there, people want more kind of a specialized idea of, of based on price range or what's available. And the other thing is, before you, I I, I will not make a purchase unless I know it's actually gonna be there.
So I I, I buy before I go, which may be a little bit crazy, but, um, this, there was a lot of that going. I, I went to the pickup area with the orders, and that was a zoo. 3 billion from, with the help of AI up 7% over last year.
But another thing that struck me is, um, not just fewer shopping days between Thanksgiving and Christmas and 2024, but the, the, the BNPL, that that number was forecasted, John, you said to be over 18 billion people want what they want, and if they can, can do the, the old, the, the, the modern layaway version of buy now pay later, they will, and they haven't. They demonstrated that. So I think it just goes to show that consumer demand is there regardless of the state of the economy.
People want what they want, they wanna be able to give gifts to family and friends for Hanukkah, Kwanza Christmas, the New Year, et cetera. Uh, they certainly showed up on cyber, uh, uh, black Friday throughout the weekend into Cyber Monday. And we obviously see the numbers trending in that direction, that show, um, a lot more spending them last year.
And maybe that's a trajectory we're just gonna continue to see up into the Right. Well, let me ask you, because, um, we saw, at least here on the East Coast, lots of reports around Black Friday where people were saying, eh, there was no really good deals. There wasn't a lot of traffic in the malls.
And is it all shifting to Cyber Monday now? Is that the trajectory we're on? We have seen That's a great point.
Yeah, Mike, we have seen a lot of, of, oh, sorry, John, a lot of organizations, um, shift Doorbuster deals online. So Black Friday doesn't have to be the chaos that it used to be. Um, I think a lot of people were online shopping on Black Friday as well, because they can, looking for great deals.
Um, there's a, a lot of tips out there from experts on what to be looking for, what to avoid, how to do safer transactions, use the H-T-G-P-S, for example, that's your friend as well. Um, and so I think that we're seeing a lot of those retailers just want to go where the consumers are. And if the consumers wanna transact online, then they have to shift and they've done, they've been doing that Black Friday to the cyber sphere.
All right, so professional shoppers are online and the amateurs are in the stores, right? I get so well, that's, that's a lot what The people do. I mean, in a sense, Some if, if You don't wanna wait for the delivery a lot, a lot of the folks were, were buying mass buying online, say from a Target, and then they would just pull up, pick up, pick up their, their goods, and then drive off.
So their experiencing at Target lasted all of like four or five minutes just to pick up what you had, what you had ordered. And I think that's actually becoming quite common, especially out here in the last few years and in, in the Valley. Mitch, do you think the websites that we built, they're more resilient these days?
I have yet to hear about the catastrophic e-commerce crash yet, but it's still early. Um, or do you think the IT folks, you know, have their arms around this whole issue? Well, it's a good point.
I hadn't thought, I thought I hadn't thought about that part of it, Mike, but it may be that, you know, this isn't the, uh, flash mob sale or the, uh, you know, the gone viral moment. This is a buildup, right? We've been increasing, increasing our usage of online buying, not just events around Black Friday and things like that, but on an everyday basis.
Um, it's kinda like the, uh, you know, the airline's, you know, highest volume day was like on just July 12th or something. You like, set some records. Um, so we're just experiencing so much more overall volume, I think that helps is handling the peaks, um, because they aren't so drastically different than the day-to-day operations.
O one thing I'm really fascinated about this is, you know, I'm, I'm not a chat bot fan, but it really, it, it, because they're kind of the low hanging fruit of generative ai. It's one of the easy things to, to relatively speaking to implement with generative ai. And we're seeing agents come on board more sophisticated uses of generative ai.
Um, but to put, to hear, you know, Lisa and John talking about, you know, John saying sort of closet Yeah, I actually used a a a chat bot. It was helpful. Yeah, it wasn't intentional.
It wasn't intentional. It was almost an accidental event, you know, it, it was, it was actually fine. But, you know, I don't, I'm not a, I don't have a high regard for it, and I, in a sense, I think, yeah, it is low hanging, hanging fruit, but yeah, it was actually okay, What It, what it made me think of is, you know, don't, as I'm saying this to myself, don't judge, you know, I, we, we judge chat bots as being, you know, of limited use because, so for so long chat bots were, hi, how may I help you?
And you type in whatever it, it'll come back with, well, are, is it one of these three things? That's all I can do for you. And unless you're in that, those three things bucket, you're outta luck.
Now it's much different with gender, the ai. So, you know, maybe even if you don't admit it to your family over, you know, over the holiday break that you actually used to chatbot, you know, maybe we give it a try, give it a second look. Mm-hmm.
Lisa, is that generational? And I asked this question because my father-in-law who's up in his seventies, can't stand anything that doesn't involve a human for customer service, right? And my, my, my younger son or who's in his, or one of my younger sons who's in his twenties, you know, if he never spoke to another person in customer service again, they'd be perfectly happy.
Yeah. I think you bring up a great example within your own family of the generational differences that we see. Um, mm-hmm.
I think those people that didn't grow up in with computers, um, in their pockets, um, are probably have less patience. And that's something I think patients dissipated during the pandemic, and I don't think it's coming back. Um, I think we see a lot of that where, where people of, of older generations want to have that human connection to be able to, to do a transaction more seamlessly.
Um, and I think the younger generations have more patience with that or understand they probably can get what they're looking for by not having to go through a human. But of course we've got how many generations, you know, in the workforce today, what five? Um, and that keeps growing.
So I think we have to companies, retailers, et cetera, the big box stores and, and everybody have to go where the consumers are and they have to be able to have the cyber conversations. They have to be able to have the, the human conversations as well to meet their customers where they wanna be met. John, you said you accidentally fell into using that agent, and I cannot help but wonder if the people who designed that website, that didn't happen by accident.
They had a plan and a and a and you know, basically No, I know It basic It was all intentional. Yeah. That was the fish that they caught.
Yeah, no, they, that's um, that's a good point. Yeah. I'm like the, this, this is, it's all, it's all designed to take advantage of, um, people like me.
You know, actually I had to be honest though, I actually then did call the store, but the reason I, I actually did want to talk to a person 'cause I wanted to make sure that the part was available. And also I didn't quite tr I'll be honest, I didn't quite trust the chat bot and, but what happened was, like a lot of people, I ended up talking to somebody. I think the person was in the Philippines, right?
They, they have no association with the store, except be they, they're part of a call center. And, um, it was, it was fine, but I kind of used the human element and thing. But going back to what you, you said about your son, I have the same situation with our youngest is 24, and I don't think he goes to stores, I mean, only at the last minute to buy like a knick-knack or something because he has, there's a time elements, right, where only has a couple of hours to show up at a party, but otherwise, course he, he will not go anywhere close to a physical store or location And DoorDash and Uber delivery, right?
We Don't even go to pick a no, Get everything delivered. He a Lot, I, I'll tell you, my youngest is a huge fan of going to certain stores. He will go to Microcenter here, walk around, create a list, and then go home and order it online.
Microcenter is the mothership ing, uh, that's my Favorite. I'll admit. I did all my shopping online.
I don't think I, I didn't visit one store, um, outside of Whole Foods, um, on Black Friday throughout the weekend because I could do everything that I wanted online. I knew what I was looking for, I could get it. Um, and I generally have decent experiences with chatbots.
I was saying earlier how I, I like to be patient with them. I did have one poor experience and it wasn't related to, um, holiday shopping season. I was trying to book an appointment for my car for service.
And this, it's either the vendor or the dealer that forces you to go through a chat bot to book everything. You can't get to a human. Um, you, there probably was a service number I could have called and I was able to book the appointment, but it, I tried four times to get a, a loaner car and the chatbot handoff to the human was just disconnected.
It just wasn't able to happen. Um, that's probably the worst chatbot experience I've had. But I generally, uh, if I know, and I think what most folks know what they're looking for, they're able to do the transaction pretty seamlessly without having to get to a human.
So what, Lisa, what is the future of the store then? Because outside of the holiday season when I go to the mall, it's practically empty and walking around and it's not a destination that it used to be where people used to just come and hang out. So, um, do we need to upgrade the mall experience or is it just passe?
Well, I think the mall experience here in Silicon Valley is outstanding. There's one thing that's been seriously upgraded, um, that I've seen in the Valley over the last maybe five years. But something I saw recently, I think I saw this on the Today Show yesterday was that, um, the rise of the, the resurgence of brick and mortar bookstores, people want to go into a bookstore of have that sort of legacy experience.
So I think that, again, it's like what I was saying before, you know, you gotta meet the customers where they are. I think both experiences are equally important. Um, and some folks just like, like some folks still, I still like to have a fiscal book.
Um, I was never a Kindle user. I don't like to read things on my iPad. I like that legacy experience.
And I think we're seeing, at least in the bookstore, um, uh, sector, we're seeing more folks want that in-person old fashioned experience. It is true. Uh, a lot of folks are buying records now because they want that Yes.
Experience of owning. Yes. Oh, the vinyl sales.
Yes. That's why, that's what my son wants for, for Christmas, was a record player, like a vinyl record player, really, that that's come back. That's awesome.
Yes. It's the comeback. It's a comeback of the, of the vinyl record and, um, it's tactile.
Right. Exactly. Yeah.
Um, and I was gonna mention Lisa, you know, the one reason, well, one thing I think is an absolute factor in the success of almost every mall near where I live, that presence of an Apple store, no matter oh, what the situation, what is surrounded by Yeah, it is swarming with people always. And it is used as a, it's like a, it's like a century, uh, movie theater. They did the same thing here, where they would, they would plant that in an Apple store and, and the other, other stores would benefit from it.
Yes. So it was, it was, that was the drawing card. It's a hundred for, are Those for sure.
Are are those, are those people actually shopping or are they just lined up at the Genius bar waiting for service? Uh, I, yeah, I'm, I'm among them. Um, yeah, so I, I will, I will go with there.
'cause the customers, I have to, I mean, I, I, I sometimes am a little hard on Apple, but their customer service experience is absolutely outstanding. Um, and it's quick and a lot of people there go there to get something fixed, but then you get upsell in, uh, other areas. Um, but anyway, it just, I found that, I found that interesting, um, versus any other electronics store.
It's, it's usually kind of hit and miss. I, I, I scratch did though, and I go, if the Apple experience is great outcomes, there's so many people lined up at the Genius Bar trying to get something fixed. This plan also, actually, I did buy something on Cyber Monday, speaking of Apple, I had to buy a new Apple Watch and I was able to do the entire transaction online and pay a courier a few bucks to have to actually deliver it to my house.
Like within two hours of the order, there was the, the watch. So it was, of course, I didn't get a deal on it. I thought I might get a deal from Apple on Cyber Monday.
I did not. Uh, but I have new watch and it works well. All right, folks.
Well, I'm pretty sure that Sam is still working on his naughty and nice list. It's just like most things, it's gonna be online. We'll be back in a minute.
Cloud native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at Cloud native now.
All right, folks, we're back and we're gonna geek out a little bit because, well, the folks over at Salesforce, Heroku have announced that sometime early next year, they're gonna bring a platform as a service environment to Kubernetes. And if you've been watching this show, we all went to CubeCon and talked about what was going on in cloud native space for a long time. And one of the issues is it's still too hard to build these applications and people are struggling with these things.
So maybe, um, this path from Heroku will be the answer. There are other paths for the platform, Mitch, but what's your take on what's going on here that it's still too hard for developers to build these applications, but does Heroku make it simple? Well, you know, Heroku's a little bit nostalgia here.
Heroku was really a darling of the early kind of DevOps days, maybe pre DevOps days of, I think of it as, as before it was bought by Salesforce. It was essentially the, you know, the, uh, the dark or shadow it for developers. You could, I remember developer coming to me, ah, I built this and here's what I did.
I'm like, yeah, hey, what'd you do that? I did it in the cloud on Heroku. What's a Roku?
You know? So developers are using it as it a complete environment to both develop and then run applications. And Salesforce acquired Heroku in 2011.
And in all honesty, it, it's really languished quite a bit. It has not kept up. Um, it, it's been in an environment where you could build an application and run it.
Um, but sort of the rest of the organization isn't ready to run Heroku apps, right? Operations doesn't know what Heroku is and how to work with it. Um, it's not a substantial platform to, to run, run businesses on today.
At least it, it's languished in that ability. But what, what's happened now more recently, and, and Heroku was part of a recent, um, ab dev field day that we did, uh, through their tech tech field day, uh, group within futurum and had a chance to talk with them behind the scenes before these announcements were made. So they're, they're coming, they're making some significant investment to, to not only catch up ruku, uh, technically, but also to, to kind of with how we're developing software today.
So you see what's happening in the cloud, is it used to be or it has been, get into Amazon's cloud and then we kinda lock in 'cause this is all the stuff there and we just kind of tacitly support other things. Yeah, we support Microsoft, but not really. We support this, not, but not really.
We want you to use our stuff now. You see, for example, um, Oracle, uh, offering in, you know, in native support within Microsoft Azure environment. So, so the, not only the cloud providers, but the, uh, software tech providers are recognizing they gotta run their stuff, not just in their cloud, but in other people's cloud and do it with high fidelity, with the same kind of capability and support that you can get natively from that, that vendor's offering.
Same thing with this. So what they've done with Heroku is they're upgrading the underlying platform. So moving it on to Kubernetes, and if you're don't know about Kubernetes, Kubernetes is essentially gonna become everywhere.
It's the workload kingpin operating system, workload system, if you will, for software running and from the edge to the core of the network and even into the enterprise. So they're modernizing it that way. The other thing that's hap happens since heroku's kind of heyday is we have something called, um, remote development environments and essentially setting up a dev environment so that I can, you know, set it could dynamically allocate the resources that I need.
There's companies like Dev Zero where, you know, I don't pre pre allocate what I need for resources that detects that, oh, you need a GPU 'cause you're using the Cuda library. Okay, great, we'll provision that for you and do it all for you and set up your development that way instead of, you know, hand building it or a platform engineering team building. It.
Kind of the same thing here is Roku is trying to reposition itself as that kind of current generation or next generation of remote development environment and, and, and catch on to that wave again. net. So I don't mean to ramble on about this.
There's so many good things that are happening here. It's a lot of work for Heroku to, to become a player in this. Again, I'm not underestimating the challenge that they've got.
Right. Well, here's the math that I kinda look at and I find interesting with this is that I think, you know, last estimates I saw maybe there's 8 million developers that have built an app or Kubernetes, and a lot of them built it once and decided not to do it again. So, and so I have to say that, um, if we can get the base developers who are familiar with Heroku on the Kubernetes, you could easily double that number of developers building cloud native applications, and that would be huge for that community.
So they may not be the most sophisticated apps in the world compared to some of the things that, you know, larger enterprises are building. But the overall pool of developers and the number of applications being built, you could see some math in your head that says maybe the number of cloud native applications being rolled out in the next two years is twice what it's been for the last seven. I don't know.
What do you think Mitch? Well, with, with the proliferation adoption of Kubernetes? You know, it's, it's been said a million times.
It's a, it's a very complex environment, you know, uh, Kubernetes is simple, said no one. Um, but, but one of the side effects of that is you see a huge amount of investment in companies, whether it's observability or configuration or operational tools, gen AI tools to help you understand how to, how to better operate Kubernetes. So it's, it's the developer part of it, but even more so, it's the operations team, how, how it ops, how do they manage and run Kubernetes platform engineering is, is also a, I think, a key part of that solution.
So with the proliferation Mike, it's kind of like, yes, you know, it is complex, but it's happening anyway. It's being adopted so widespread. I mean, it's showing up at the edge of, you know, data management platforms.
Um, office 365 runs on Kubernetes. You don't know that, but it does. Um, it is that it's forcing the, oh, well, then the market needs to, to simplify it or make it easier to operate.
So I think we'll see more and more kind of, um, abstractions or, uh, tools to help us better leverage it and also run it. All right. Well, to that point, you know, and John, I'll ask you this question because when I talked to the folks at Heroku last, or this earlier this week, um, you know, I kind of forgot that Salesforce owned Heroku.
Mm-hmm. And yeah, that, that's that you just stole my point. Thanks, Mike.
Um, I was gonna say the most, one of the more fascinating things I think about this, and there are several fascinating things about this topic. They bought this company more than a decade ago, and it still existed in some sort of form, and yet they, they found value and, and, and, and turned it into leverage into something else. And I'm trying to think how often does that happen?
Um, I, I have friends who you, who sold companies to, uh, Salesforce, who are long gone after their company was, was absorbed and evaporated, or they just tossed aside the idea. And I, it just, um, to me that was, was interesting. I can't think of anything really comparable to it that, that was kind of the one thing I wanted to ask Mitch, or, or you, Mike, have you ever come across a situation where something that a company acquired, actually they put it to use that long afterwards.
Well, hey John, I got out my bell-bottom jeans again from the seventies, they're back, you know, so Yeah, yeah. You know, white ties and narrow ties or no ties. So, you know, it, it, and my point is, timing is everything with, with the resurgence or with the, you know, rise of remote development environments.
Um, and that's one of the things that Heroku did really well. It was also an operating environment that's the platform as a service part of it. Um, and you can argue that, you know, Amazon developer queue is part of that, um, you know, copilot and so much of what happening with, with GitHub and actions and, uh, those kind of environments.
So the, I think the timing, if I was sitting back and I don't know this is how it happened, but if I'm the, you know, CFO of Heroku and, and talking to the CFO of Salesforce saying why should we invest all this money? I'd say, here's what's happening in the market. People are adopting these environments, this's, we what we have.
We just have to present a modern day version of that. I, that's my guess why, why they've invested so much money in bringing this back. Yeah.
I think there's a storyline that's gonna emerge though, that will feel something like this. Salesforce is investing in all these AI agents and some of those AI agents will be used to build applications, and I can put those things at the front end of Heroku and come up with something that's pretty compelling. I think if you put those things together, um, I'm not quite clear that that's what they're absolutely gonna do, but it seems like that's the logical flow of the thing and the, and where we should be headed.
And if that's the case, then, you know, mere mortals can create interesting applications using AI agents on a path that they don't have to know anything about Kubernetes about. So maybe, I don't know, Lisa, I'd like to get your thoughts here. You know, is Heroku a hidden asset for Salesforce or is this something they're just gonna spit out someday?
That's a great point. Uh, I think you all bring up such great points about how long ago the acquisition was, and we're seeing this now in their release. They had, um, nice commentary from customers from healthcare organizations to cardio based car collect kilter set.
So looking at the improving the developer experience improves the consumer experience. Whether you're consuming a product on, uh, an e-commerce website or you're a patient trying to get reliable, uh, care from a healthcare provider, I think this is something that if they can demonstrate with Heroku that improving the developer experience is improving the lives of patients, improving the lives of people, doing transactions online or whatnot, um, then it could be an interesting resurgence for, um, this platform as a service technology. All right, so Mitch, lemme ask you this.
So much of what currently exists in the land of Kubernetes is, you know, do it yourself platforms, and everybody's talking about moving to platform engineering, and the thing about all those platforms is, you know, somebody had to not just build them, but they have to maintain them and update them. Do you think that there's folks out there who are gonna say, you know what, I don't wanna do that anymore. Let me just swap this out for a pass, even if it's not Heroku, there's a couple other options out there, here.
Know, have we gotten to the point now where we're kind of sick and tired of custom everything? Well, I was talking with, um, one of the, one of the vendors that has an offering running on Kubernetes, and this is during, uh, coup con couple months ago, and they described it as, yeah, we were, we lived in the days for a while there of, you know, the, the buyers would say, yeah, let me do it myself. I want access to all the, the bells and whistles and knobs and buttons so I can kind of don't limit me, right?
Don't, don't stifle my creativity. Right? And you find out what, what that really entails.
Now that you have that responsibility with great power comes great responsibility, the market's now shifted to, I don't have time to mess around with that. I, it my resources cannot be spent trying to figure out how to manage Kubernetes or how to manage the development environment or, or integrate these, you know, stick-built, integrate these things all by myself. Let me find people who will take that burden off my, off my shoulders.
And that's what's happening in Kubernetes, and that's part of the operationalizing Kubernetes in a way that ops can, uh, can adopt it, develop more developers can use it, you know, extracting, extracting away some of the complexity and, and, and, but letting me have access to the capabilities if I need it under the hood, if you will. So the, the market has shifted from I'm gonna build this myself to, I, I still want lots of control to the just take care of it for me, and if I need to do something, you know, gimme some, some, uh, abilities to, to step under the hood, at least to some degree. Mm-hmm.
Yeah, I mean, to be honest, there's a lot of irony in this conversation for me because early on it was a handful of developers who were like saying, we're gonna use Kubernetes, whether it likes it or not. And then it eventually discovered that Kubernetes does all kinds of interesting things on the ops side. So now oddly enough, it ops teams are telling developers we're using Kubernetes, whether you like it or not.
Yeah. Karma. It's karma.
It is, it is. It is karma. It definitely comes full round.
All right, well folks, we invite you or suggest you should go experiment with all this stuff because, you know, decisions you might have made four or five years ago, you don't have to lock yourself into that forever. Things change and things do move on. Hey, I wanna thank our guest today.
We have Mitch Ashley who is, uh, vice president and practice lead for application development and DevOps over the erum group. Mitch, thanks for being on the show. Absolutely pleasure being here with the team.
All right. And of course we have Lisa Martin, the CMO advisor who's out there aligned with our folks at Erum Group, but also works with all kinds of different vendors out there and has all those great insights around what's happening in the holidays. And I'm sure we'll be talking about that again soon.
Lisa, thanks for being here. My pleasure. It was really fun.
Thank you. And the, uh, I guess somewhat tech strong anointed czar of Silicon Valley. Oh, God, uh, was al, I Wait, is al whispering in your ear right now, Mike?
No, it was fun to be here. It was also good to see you all at a AWS reinvent as, as short as the time I was there. That was fun.
Good. All right. Always good to break some bread with you, John.
Yeah, well I was gonna, exactly my exact sentiment. Thanks. Always good to see everybody in per in person.
In fact, hey, if you see any of us at the show, stop by and say hi. We'd love to take, get in touch with all of you. Hey everybody, thanks for watching this show.
Stay tuned. There's some awesome content on texture on TV coming up right behind this. We'll see you next time.
Hello and welcome to the digital CXO podcast. I'm Amanda Ani and I'm excited to be here today with Jen Chu. She is the Vice President of Solutions and Consulting at Bristol Cone.
How are you doing today? I'm great. It's glad to be with you.
Wonderful. Happy to have you on the show. So can you share a little bit about yourself, your background, and then maybe about Bristol Cone and the services that you provide?
Yeah, sure. Well, as you mentioned, I lead solutions and consulting at Bristol Cone. We're a supply chain specialist organization, so we help global 2000 organizations, um, meet their challenges, whether or not it's around visibility or resiliency or cost efficiency.
Those are sort of the typical biggest challenges we see large companies struggling with as they think about how to, you know, plan, source and make their, um, their products. Um, I've been in consulting for, um, actually a little over 30 years now. Um, I started with Pricewaterhouse.
I spent time, uh, working for them in both New York and London. So I started to get a little bit of international exposure. Um, I spent time at Forrester Research leading, uh, research into their enterprise applications space.
Um, and then along the way spent a little time at IBM and Deloitte and TCS all along the way, working with both business and IT executives, helping them solve challenges at the intersection of supply chain and technology. Wonderful. Well, it sounds like you're definitely the person to talk to about the transformation of the supply chain, which is our topic for today.
Great. Alright, so we're talking about innovation and transformation of the supply chain. So first off, what steps can company leaders undertake for strong partnerships between technology and talent in order to drive digital transformation?
Yeah, so thanks. I think that's a, a great question and, and not necessarily obvious for a lot of supply chain executives that we work with, right? They, they immediately, um, well frequently they will jump right to, it must be a tech problem, right?
Let me, what can SAP do for me here? Or what can you know, x, y, z fill in the blank, you know, specialist package do for me? And most of the time what we find is that even when organizations, you know, pick the right package, deploy the right technology, the supply chain transformation can still fail.
And we see that that root cause is often that the technology wasn't adopted, the people weren't trained, the people weren't ready for the change, or there's been too much change coming at the talent in the organization and it's overwhelming. Um, or just that the change was layered on top of everything they're already expected to do. And so, um, the dealing with the, the people challenges around a supply chain transformation is often underestimated.
Um, and, um, and under planned for, yeah, absolutely. That is a big issue to consider. So next, how can supply chain companies handle the evolving customer demands and the need for increased speed and efficiency?
Yeah, so now you're asking about the demand planning, which is, um, really challenging and in a variety of different ways, depending on which industry you are talking about, right? So if you're in a, uh, if you're a retailer, um, it's no longer just people walking into your storefront, right? You've got people ordering in all sorts of different ways.
So the multi-channel demand forecasting is complicated. Um, you've got, uh, you know, big, um, manufacturers who are dealing with, uh, whipsaw in demand on a global basis. So there's a whole geopolitical aspect that, uh, organizations are now having to deal with.
And then there's just changes in the buyer pattern. And I mean, even as, as, um, as specific as like, what's gonna be the impact of the tariff news right now that Trump has been elected? There's a lot of uncertainty and demand that that sort of political news injects now into the conversation for planners.
And so what we really try to advise our, our clients is that if you don't have visibility right, then anything that you anticipate or forecast or plan for is likely to be wrong, right? Already forecasting is hard, but if you're doing it without good baseline information, it's definitely gonna be wrong. So starting with visibility is usually a good place to start.
Yeah, absolutely. Well, how, what tips do you have for business leaders as far as how can they stay ahead of this evolving technology and and harness the technology to remain at the forefront of the supply chain? Yeah, so here's where AI often comes in to the picture.
People assume that that's going to be on, um, panacea, right? It's gonna solve all of our problems, and it gets coverage like that sometimes. And while I don't believe that's necessarily, you know, true, I'm not a total Pollyanna about ai, I do think there's a valid role for AI to play.
Um, and it will be impactful across all of our, um, you know, our, uh, economy. But when we start to think about AI as a tool that organizations should have in, in their toolbox, it really starts with data readiness. Um, the old adage, garbage in, garbage out is still true.
And if you've got bad data or poor data, or you're missing data or poorly trained data, right? Then you're only going to accelerate bad decisions. Um, and so we wanna, we start with a strong data foundation.
Um, next is the people challenge, which we hit right out of the gate. So if your people aren't ready for ai, if they've not been trained, if they now, uh, if they're unable to start to think in scenario, and what if an interaction with the digital assistant, then that's a skillset we need to get ready and build out. And the organizations, um, we need to get people out of the rote day-to-day transactional activities and into problem solving.
And that's fundamentally a different challenge than most, uh, you know, uh, supply chain workers are, um, engaged with from, you know, if you just look at their, um, the way that they spend their eight or nine hour days in the office, it's a big shift with ai. So thinking about data, thinking about people, and then, you know, there's some IT things around hardware and software, which are probably not for the general audience, but you know, there are certainly investments that need to be made, made there all before you start to think about deploying that very specific AI bot or digital assistant. So we really encourage people to think foundationally first, um, as the AI digital assistant start to mature.
Absolutely. So communication is the key to most businesses success. So in talking about that, um, leadership between talent and staff members, how do we have good communication and, um, encourage staff members to embrace the new technology?
Yeah, I like to think about trust and transparency, and you can't have one without the other, right? If you're not transparent as a leader, if you're not talking about what the, uh, anticipated changes are, whether or not it's AI or any sort of change in the, in the organization, then you're probably not gonna have a lot, lot of trust. And if you don't have a lot of trust, then what reason would the staff have to go along with any of your change management ideas?
Right? So I know it's something that I try to live by and, and with my own team, is establishing, you know, that transparency to share as much as I possibly can about what, what, what I'm anticipating, the types of challenges that, that I expect us to have to deal with sourcing answers from the team, not just telling them the answer. Um, I think that all creates a, a, a virtuous cycle.
And so not a, you know, it's not a supply chain specific answer. I think that's just a good management and leadership, um, approach. Uh, but where we see our supply chain clients ex executing on that sort of trust and transparency, we see a far higher adoption rate in the technology investments that these leaders are banking on so heavily to help them improve their supply chain.
Do you have any use case examples you would be free to share of companies you've worked with that improved and, um, showed innovation within their supply chain? Yeah, actually, um, so we've, uh, developed 78 specific, uh, supply chain use cases at Bristol Cone, and we're working with our, our clients, and we're at various levels of, of development and adoption across those 78. 'cause some are probably, you know, um, more drawing board at this point until the technology actually catches up.
But where we're seeing a tremendous amount of excitement and investment is in the SNOP process, so sales and operations planning. And I think one of the reasons why that has become such a lightning rod for AI investments, um, and transformation in general, is that it's a really painful process. It's, you know, it takes a lot of, of days, sometimes weeks of preparation.
It's a lot of senior executives, um, and it's a lot of guesswork. And so all in all, that's a pretty expensive, um, and time consuming process. And so if there is a way that we can leverage technology to, um, shorten the cycle and improve the outcome, then that is certainly an area of interest for our, our clients.
And I would say it's not just one client, it's, it's across the industry. So we serve life sciences and med tech clients, we serve consumer products and retail clients, automotive clients, et cetera. And there are people in every industry that are asking us to specifically try to address their challenges in SNOP.
So I, I think that's where we see the most energy and excitement around application of this AI technology. It's a perfect fit for it. 'cause it's data intensive.
It's a lot of what if scenarios. Um, so coupled on top of all of that data crunching, you still have to have, uh, there's still a complex set of decisions that needs to be made. So it's a, it's a really great combination of the, the human making, the final decision and recommendation, but with a whole lot of analysis that we can now outsource to some sort of digital assistant on top of a mountain of data.
Wonderful. Well, the world is constantly changing. There's many factors to consider.
And what are your thoughts as far as, uh, what can we expect two years from now in the world of supply chain management? Yeah, so I think that, um, right now AI is a lot of buzz. I think two years from now, we'll actually see a fair amount of, of deployment.
The, um, so, you know, I I think there's a tremendous amount of data readiness that organizations are going through now. There's also a lot of experimentation happening with AI now. I think if we're, you know, if we were to have a conversation 24 months from now, we'd see, you know, a fair, the, the, the bell curve, right?
We would see the more aggressive organizations with a fair amount of AI bots deployed throughout their organization. I don't think that in two years we're gonna have sort of push button supply chain technology and have outsourced all of our work to, uh, you know, to the system. Um, but I do think we'll see, I don't know, 20 to 30% of the companies with, uh, maybe 10 to 15% of their processes really actually operating on, on ai.
Um, yeah, had a, a discussion the other day with a, a gentleman who works in, um, AI advising a lot of investment banking companies, and he said, the best place to start with AI is to outsource what you have your interns do today. And I thought that was a great way to think about getting started with ai. If it's simple and it's tactical, what a great place to start and start to build some experience in your organization in using ai, but save those really sophisticated scenarios, either for a human assisted leverage of ai, um, where you don't turn over the decision making, but you turn over some of the analysis to ai.
So I think we'll start to see evolution in, in, you know, on that continuum. Interesting. Yes, that does make sense.
Well, if there was one key takeaway you could leave our audience with today, what would that be? So I would say don't underestimate the amount of effort it's gonna take to transform the people in your organization. And so I would encourage them to think about what are the, um, the, the cultural shifts that your organization needs to, to start to think about, um, empowering your people in order to start making decisions as opposed to educating them on how to perform tasks.
And that is a tremendous shift for organizations. Um, and I, I think that organizations who figure that out will really truly be the ones who can take advantage of AI in the long run. Wonderful.
Well, thank you so much for coming on our show and sharing your insights with us today. Thank you very much. And thank you to our audience.
Stay tuned. There's more. Hello and welcome to the latest edition of the Cloud Native Now podcast.
I'm your host, Mike Bazar. Today we have a guest, Byron Viray is the CTO for or, and we're gonna be talking about, well, how AI agents and orchestration and microservices is all gonna come together because they're on a collision course. It's just a question of win now.
Hey, Byron, welcome to show. Hey, thanks. Uh, thanks for having me here.
As we've seen so far, microservices are not easy to build and maintain. A lot of folks are challenged by it, and as a result, maybe they sometimes even go back to monolithic applications. We are seeing though, the rise of these AI agents that are increasingly starting to be able to take on more complex tasks.
I guess the issue is how would we manage all these AI agents and create something that feels like, um, some order in what could be a potentially chaotic scenario, um, and apply that to microservices. So you're at the forefront of this, what's going on? Yeah, I think, I think that's a great question, first of all, and I mean, if you kind of look back and think about it, right?
There are a lot of similarities as well. Like when we look at, when we look back and, and look at the microservices world, what started to happen was, uh, you know, people started building microservices, uh, you know, single responsibility functions. And once you had, you know, a host of microservices available in your kind of, uh, infrastructure, the next question came was that, okay, how am I gonna manage all of those things?
Uh, how am I going to essentially put all of them together to achieve my business goals? And what we are starting to see with the AI agents is kind of a similar story that, you know, the agent is only as good as the tools it has and the autonomy you give it to them, right? Otherwise, essentially, you know, you are not really solving the fundamental problem in terms of how they are able to plan, execute, and deliver the results that you want.
Um, so I think the way I at least see is, you know, uh, lot of learnings that we had with microservices, you can potentially apply them to how you build agents, how you operate and run them. And I think there are two critical pieces there, right? One is visibility into, you know, what is happening.
Um, ML explainability, explainability has been a subject of research, um, for quite some time, uh, with the adoption and a broader option of ai, and especially LLMs, it has even gotten a little bit more mainstream. Uh, just imagine a case where you are leveraging AI agents, which are making fully autonomous decisions. How do you get visibility into why that decision was taken?
Um, and we are starting to see some, you know, uh, kind of news about, uh, agents doing things that doesn't make sense or, you know, got company into hot soap and things like that. So this is where I think, you know, the learnings from microservices in terms of like, you know, it's not just about kind of how you put things together, but more importantly, understanding why it did that. Uh, being able to get visibility into it and, and be able to kind of do that in a safe way is gonna be very critical.
And I think there's a lot to learn from, you know, the adoption of microservices, how we could evolve, how it matured and apply them to, you know, agents. I mean, a lot of sense with microservices. One of the things about it is that, um, it creates redundant paths for API calls.
So the application is more resilient, and in a similar way, we may have to route different tasks around the different AI agents, many of which may be checking out each other to ensure that the quality of the overall application or whatever outward building doesn't go off the rails. Yeah, absolutely. And I, I think, um, I, I would say like, you know, in microservices world, you had the concept of edging where you would send the same request to two different API end points, uh, so that like, you know, if one of them is, is slow to respond or is not available, your overall request still continues to operate.
And I think you could apply, and we are starting to see that as well, right? Uh, with the AI agent as well, that, you know, you are sending the same requests to two different models, um, and, uh, maybe using a human to evaluate the response or using a third model to again, evaluate the response before actually, you know, responding back, right? Um, and, and, uh, leveraging that kind of patterns to kind of, uh, put some more safeguards, some more checks and balances.
Um, and sometimes it's purely for evaluation. Like, you know, if you build a new model and you want to test it out, um, before kind of rolling it out, you are kind of sending a shadow, uh, set of requests over there, evaluating them. And once you are confident, you know, switching that, uh, path, um, and especially the way models are evolving, like we are seeing a new version coming up pretty much every year.
Um, and, uh, you know, oftentimes what was working in the previous version, the behavior changes. So, you know, upgrading to the newer version also requires, uh, testing. And the biggest problem with, um, ai, um, and language models is that they are non-deterministic, which means you can't really have a set of use cases and say, oh, I'm gonna run through this set of use cases, do a Q testing and their pass.
It's all good to go. That may not apply here. So now we have to kind of do this in production environment with real world, you know, user inputs.
So this becomes even more critical to be able to orchestrate the requests across different agents, different versions of the same agent and, and things like that. Yeah. Mm-hmm.
So I may have agents that help me write code, and then I'll have an agent that helps me test, and then there'll probably be a set of agents that are doing security reviews and, uh, uh, governance management kind of task. Um, what will be the role of the human developer and all of that. How will they kind of be involved and software engineers will orchestrate this using what?
That's a great question. Uh, what are we going to do if AI does everything? I think the more important thing there is like, you know, um, somebody has to still kind of figure out, um, how this agents are going to orchestrate the task amongst each other.
Um, also be able to kind of, uh, do that in a safe way, uh, which means there is gonna be some human, um, overview intervention required every now and then. I think that's one. And, you know, and this kind of brilliantly applies to software development, for example, right?
Like a lot of software developers today are using co-pilots to write code, but you know, they are still responsible to, um, ensure that the code that is written kind of matches the requirement. It, it, it is safe to run. Um, there are no bugs.
Um, and, and like a lot of people are also using AI to kind of generate automated tests, but, you know, somebody is still kind of orchestrating all of those things, right? I, I don't think we are there yet where we can say that everything is gonna happen, uh, by AI automatically. Um, and I, I think, you know, essentially, you know, we are shipping ourselves slightly at a higher order in terms of what we deliver as a value, uh, which is what we are best at, right?
Um, being able to understand the business, being able to find the right set of agents to orchestrate and where, and how we orchestrate. I think that's, that's the field that I feel like, you know, is not fully developed yet. That's one area where I think, uh, Orca, what we are working on is gonna be very critical in terms of, you know, you have all of these agents, you need to run time for this agent so that you can run them safely, you can inspect, visualize, um, uh, log them and see what's going on, right?
That's, that's I think one area where I, I I see a lot of opportunities and, and I need, So in effect, the AI agents still need a boss, and that would be called us, right? Yeah. Um, you know, one of the things you see in microservices applications is there's just a lot of containers coming and going.
And if you listen to folks, we might be building more software in the next few years than we've built in the past decade. And so are we prepared to deal with the amount of ripping and replacing of containers that we're gonna see at that level of scale? Because, well, we can't throw more bodies at the equation, so we gotta find a way to kind of keep track of these containers that might only live for, you know, what, 30 seconds.
Yeah, I think, yeah, and I, I think this is where the orchestration plays a very critical role, because you need a system that has a complete overview of what's going on. Um, because let's imagine a case where, you know, somebody, um, starts, uh, spinning off containers and you end up spinning thousands of containers and you have no checks and balances, and, and you will find out when you get your next cloud bill. Um, so that, uh, that's definitely kind of the case.
So, you know, this is where like, you know, the orchestration systems, systems which are essentially responsible and have kind of right set of limits, um, and, um, checks and balances in place, uh, becomes more critical to understand, you know, what's happening with my system. And I think, as you rightly pointed out, right, it is, it is gonna become easier to write a lot of code, build a lot of systems, where we will start to see, um, is how well are you able to run this? So runtime aspect of it is gonna be a lot more critical now than than ever because, you know, we can just do out more now.
Um, It also seems to me at least that, um, we're reaching a level of complexity and maybe we're already there and we're just struggling with it. That, and the application environment is just too difficult to, for humans to manage by themselves. I, I think we are already there.
I think we are already there. Like, even without, like, even if you take the AI out of the equation, um, applications are complex. Um, what, and especially as you kind of move things over to the cloud, uh, in a, in a more distributed, uh, uh, world, um, applications are increasingly complex in terms of its interconnectivity to other applications, different systems, um, microservices, um, events, um, that are kind of, you know, being exchanged across different applications.
So things are definitely a lot more complex. Um, there is no longer the case where your application is a very simple, you know, your database, your form, and somebody fills out the forms and service in a database, right? That typically never tends to be the case.
Now, there's a lot more kind of business logic that is implemented. There's a lot of orchestration that is happening across multiple applications, including third party systems and vendors. Um, so they are definitely a lot more complex.
And, and guess what happens when you have a very complex systems? It becomes increasingly complex and difficult when there are failures or things that you have to reason about as to why certain things happened, right? It doesn't have to be necessarily failures only.
Um, now I would give you an example of, um, a system that takes some decisions, right? Um, why did it arrive at a particular decision? You need to be able to know the entire graph of, uh, you know, steps it executed to understand why it derived at that decision.
Now, if I were to build a graph in my mind, you know, that's a lot more community overload, the amount of time it takes. Um, and, and that's where, you know, orchestration systems, systems like conductor and orcas, uh, becomes very critical. Where, you know, you are able to understand what is happening, why it is happening, and if there are failures, uh, be able to kind of, first of all, resolve the failures automatically, and if not, be able to kind of have a simple API call or a one click button to, you know, resolve them.
Um, but yes, they, they, they, in summary, they are already complex. On the opposite end of that, are we in danger of becoming maybe too dependent on ai and we let the machines kind of figure out everything that can be done, and we may not understand how it was done. And then when somebody calls us up like a compliance auditor and says, can you explain this?
We may not be able to. I, I, I think that's a extremely valid point, and I'm, I'm kind of, I hear that a lot, uh, and this is one of the common themes that I kind of also hear from our customers, the users that I've spoken to is, yes, AI is great, but I need to be able to explain the decisions it took. And this is why I believe that like, you know, being able to explain the decisions that AI made is gonna be extremely critical, non-negotiable in some sense, uh, or especially in some industries where you have to be able to justify and understand why that decision was taken.
So, you know, instead of AI becoming a black box, the way I would kind of think about it is that like, you know, it, we are starting to see, and, uh, that is one area where we, we also kind of, uh, position ourselves is, you know, you think about AI as tools that can help you, uh, automate things, um, and take, um, automated decisions, but you are still in control and you have to have the complete visibility into, you know, why this happened, what was put given to it, um, what were the rational, and maybe have a parallel kind of, uh, execution made, uh, to another model or an algorithm to validate that. Like, you know, even if I use a different AI system or an algorithm, I would arrive at the same situation. So now when my compliance officer calls me and says, you know, why did you do this?
I have the full explainability as to why, um, Do you think we'll also be able to use that capability to a degree to, uh, determine what is causing it a performance degradation in my application? 'cause one of the issues with microservices is, well, they may not necessarily completely fall over the way a monolithic app. Well, I can spend a long time trying to figure out what it is that is causing a certain performance issue.
And the maddening thing about it is it might take me two days to figure that out, and it's about a 32nd fix. Oh, yes, absolutely. And I think this, this has been kind of already, um, you might already see some of the systems similar to that, right?
Like doing auto tuning. Um, so, you know, you put an AI agent, um, um, or as a site car in your application deployment, which is constantly monitoring, um, how your application is performing, checking logs, um, and other systems, CPU memory and kind of understanding, you know, the application behavior. And in today's world, uh, it could start with giving recommendations.
But I can totally see in the future world, um, and I have seen those systems, uh, at play as well at large companies like Google, where it'll just automatically tune it for you, um, to the best of its capabilities. Uh, so, you know, and, and the whole idea is, you know, if you think about it, right? Um, where we are best as humans is being able to understand the business, um, implement the business logic and drive the business forward.
Everything that we have to do on the infrastructure side. How do I run my application? How do I get visibility into my application?
As you mentioned, I queue my per code for performance and everything that can be very well done by machines, um, and, and ai. Um, so you, you kind of coexist and, and leverage them as your tools rather than like, you know, think about it as kind of replacement, uh, makes it more productive. How will the software engineering teams be organized?
'cause I, in my mind, it looks like we're gonna have a small army of AI agents and working alongside humans, and, but you know, it still takes a team of folks to build something. So how will the AI agents that I created work with the AI agents you created? I think that's, that's an interesting question.
Um, I would, um, I mean, I, I don't think I, I have the kind of answer that I, um, because right now it's such an ascent field, um, and, and we are starting and we are seeing frameworks, right? Frameworks, like, for example, conductor, where, uh, we are allowing people to kind of orchestrate across multiple agents through API calls. Um, there are frameworks like auto gen, uh, that allows you to kind of do the same thing why, where you can have conversational AI agents, uh, talking to each other and to achieve a goal, um, or collaborate on a particular task and things like that.
But I think that's another field that is, is evolving quite repeatedly. Uh, and we will start to see maybe some amount of convergence there in terms of frameworks and, and, um, how those things are kind of managed. And, uh, yeah, Right, you mentioned the Netflix, uh, framework that you guys are using at the base of your approach, but, um, I'm trying to figure out where the cart and the horse here.
'cause sometimes I think people are gonna try to create all these AI agents and then kind of add the framework to kind of manage it after the fact. So maybe we should be putting the frameworks in first and then figuring out what's going to attach to them second Maybe, uh, maybe, but I mean, then I think it's, it's the kind of dilemma dilemma, right? In terms of like, where do you invest in focus your time on, right?
Uh, building infrastructure is always more expensive, tricky. It requires very specialized skills overall. Um, ai uh, agents, fortunately what has happened over the last few years is it they have become almost ized, right?
Like you have a plethora of choices in terms of the models, uh, their cost. Um, so it's much easier to use them to build a POC, um, or at least, you know, put together a simple business use case, um, which is what everybody is doing today. Uh, where I think, as you rightly pointed out, is there's a need for a infrastructure, there's a need for a runtime for all of these things, which does not exist yet, um, uh, outside of, um, you know, a few kind of initiatives like ours.
Um, but I, I would say, you know, uh, as people kind of realize, um, and, and try to find out, they will both converge, um, eventually, uh, as in pretty soon probably. Do you think ultimately, we hear a lot about the phrase platform engineering, and I wonder if this transition to AI agents is gonna force us down that path, the more organizations are gonna have to have some, uh, centralized approach. But I guess one of the joys of DevOps was that, you know, we embraced it in the first place so we could get out from underneath centralized it.
And so how do we strike a balance? I think platform engineering is gonna be the commonplace, and if not already, you know, I mean, we are already seeing a lot more effort, emphasis on platform engineering. And if you think about it, right?
Like, um, you take your, um, developers who understands business, uh, who is able to kind of, um, implement complex, uh, business solutions. You take AI who is able to kind of take care of heavy undifferentiated kinda work, um, like, you know, helping them write code, um, and things like that. Then what's missing part there is that platform where they can all put everything together and run it so that now they don't have to worry about kind of that.
So in some sense, I think, you know, it's, it's a complimentary thing. And you know, when you put all these three things together, you, you get the most efficient, uh, you know, what I would like to call it, like, you know, a 10 x developer side. Um, 10 x developers are less about developers and more about the frameworks and platforms that they operate on.
Currently, we're kind of at some sort of crossroads when it comes to software development. So what's your best advice to folks about how to get ready for all this? Like, if you look at software development, right?
Like, it, there is a lot of hype, um, and, um, interest in, in AI today, but software development has always been similar to this, right? The, it has never been the case where you learn one thing and then you keep on working on it for next decade or so, right? Like, it's constantly evolving in terms of the framework.
Um, in terms of the architecture, um, you know, we went from mainframe to PCs to, uh, data centers to, you know, cloud, um, now hybrid cloud ai, uh, microservices events like this has been constantly evolving. So I think the advice is, is the same, right? Like, um, it's, it's about kind of constantly learning, um, understanding where you add the value, um, and, and I think in the end, um, be close to kind of the foundations, right?
Um, I, I think that's, that's the hardest part. Um, and, and that's where we add value. Yeah.
Alright, folks, you heard it here. Hey, even in the age of ai, don't forget the fundamentals because that's what's gonna help you get through all this. Hey Barron, thanks for being on the show.
Yeah, No worries. Thank you so much for having me here. All right, and thank you all for listening to the LA or watching the latest edition of the Cloud Native Now podcast.
You can find this in other episodes on not just our website, but on Spotify or Apple or any place else that you listen to podcasts. Once again, we invite you to check out the entire library of podcasts that we have. And until then, we'll see you next time.
Hi, my name is Mark Callahan, I'm the founder and CEO of Cloud Canaries. I wanna do a presentation to talk to you about DevOps in the intelligence era. It's here.
We're gonna talk about new technology and how that affects and creates new culture and new attitudes. Ultimately, it's learning how to love the S-curve and more. A little bit of a little bio for me, you can certainly pull down the slides and take a look at it.
Um, I like to, uh, uh, crush pillars. I like the clouds. I like canaries, I love Boston.
I love to row, I love beacons and beacons are workload data, got a degree from MIT and so on. At the end of the day, when is it time to let new technology out of the Faraday cage? And this tech case, it's a robot, and there's an 85% chance if you let the robot out.
0, 1% chance that it'll take over the world. The question is, what's your decision? What are you going to do?
Are you gonna take a pass? Are you gonna embrace it? And sometimes when you do embrace this, there's always risk, but there's always opportunity too.
And rewards, sometimes it's unexpected. So let's go to our next slide here. One of the things that when you look at new technologies, you look for something called the inflection point.
And, and that h helps you to stay ahead of the S-curve. And we'll talk about the scur as well. Basically, it's when a new technology dramatically changes the trajectory of a business, of an industry or an economy.
But beware new technology is disruptive. This is especially true for DevOps. New technology can create new culture, new attitudes, a new way of solving problems, but also can disrupt and it will disrupt the status quo.
Eliminating old approaches, business models, and require new insights. Be prepared. The technology era will do all of these new technology can bring new risks.
Here's a little slide about, oh boy, the robots replaced you too. It's kind of funny. You notice the obsolete goals, uh, stamp on the, uh, the robots standing in line, uh, for under belong benefits.
However, new technology can bring new rewards. I know everybody, everybody's commute became much more pleasant since driverless cars, but this is just too much. And if you notice, there's someone in a driverless car swimming.
And the point is, is that sometimes the new rewards are unexpected. How can that happen? Completely a surprise.
So again, be prepared for that. So let's, uh, jump into the, uh, um, how to love the S curve. The S curve is a, basically a product lifecycle where it shows you how a new product gains strength gains, it adoption becomes, uh, um, has a high level of growth and eventually stabilizes.
Beware of s-curves, multiple blast curves and, and multiple technologies and how they interact. The classic example that I learned at, uh, at MIT was schooner wind based freighters, hundreds of years. They were used to, uh, transport freight all over the world, very efficient.
They used the wind. Um, they were limited by weather, uh, but the technology for sales was incredibly advanced. And then it happened, technology B came out.
The steamboat steam engines and coal for fuel new freighter designs bigger, could, could move more freight shipping's not limited by weather. The technology for steam engines advanced very quickly. Again, this, this, uh, chart on the, on the right shows technology A Skinner, and then technology B, which was a steam engine.
So, uh, which technology was at the end of its curve? Well, it was sales, you know, sales, sales sailboats still exist. Uh, but with, for freight, for moving freight, within a decade or two, most of those schooner were replaced by steam engine based freighters.
It was at the beginning of its s-curve, while cell technology was at the end of its. So, new technology replaces old technology. It has an impact on how you, how you do your, your daily work.
It has a impact in culture, it has a impact on, on new products and, and, and how they are successful to help at the end of the day, customers. So let's dive into the scur. There's different phases for the scur.
And, and you can use this, there's two kind of views of it. I have a, an emotional, uh, the emotional phases in the economic phases. I like the emotional ones at the bottom.
Uh, okay, it's still early, but where's the traction? And then the next one is, this thing is not going anywhere. And then you see this little inflection point where the, the curve like goes up and, and the, the emotional response is, okay, maybe it's not hopeless, and then it goes up, uh, uh, skyrockets goes, uh, gains speed, uh, dramatically.
And the comment is, we're all gonna be rich. And then it kinda levels off and, and the comment is, what just happened? And at the end, we are doomed.
So that's a, a typical S-curve, and you'll see that in many different technologies. You, Sarah saw that with schooner, and you saw that with, uh, steam engines and, uh, steamboats, you see that with televisions, you'd see it, you know, um, audio equipment, you name it. One technology, uh, has a, a market lead, and it's replaced by another technology, um, that evolves in its its own scur.
Um, the, the economic phases are, um, you know, you probably, if you've been to business school, you probably all, uh, have seen these, but you know, you search for a solution, proof of concept, early adapters, system integration, and the market expansion. Again, different phases of that scur. So now you know what an scur is.
The, the new technology of the intelligence era. We believe at Cloud canaries is data, AI and compute. We're gonna go into each little piece, um, in a second here.
And we also believe we're at an inflection point, uh, in the scur, you know, that little space right before for, oh my gosh, is this ever gonna work? To, hey, it's working, and then it takes off. And I, we're at that point, and it's really, as I mentioned, three pieces.
It's the data and it's ai, but I'm gonna call it commoditized AI in the sense that it's no longer a research tool for research labs. You can now find it in the production floor, even in the cloud. Um, and numerous vendors are developing their own set of tools, and they're widely available.
And, um, anyone can, can really use them and actually build models that generate forecasts and insights. The third piece here is, and it's critical or commoditized, anything AI in this case, you need something that, that always pushes costs down. And Moore's law, which isn't really a law, it's more of an observation, is about how the density of integrated circuits double every two years, two and a half years.
It kind of varies. It's varied over the last 40 years. But the bottom line is computers are always gonna get faster.
They're always gonna have more memory, and they're always going to the price point on, on that level of compute and memory is always gonna go down. So what that creates is this new technology where you can build models, you can do forecasts, and you can reduce costs. So take a look at your organization.
Uh, what stage, uh, best describes your organization and current adoption of ai. Take a, you know, think about that. No investment.
We have a little bit over 20% of planning about using AI solutions of some type exploration. A little bit more. 24% pilot projects are still under 15% partial integration, you know, AI's being used today, 20% and full integration still kind of like at 7%.
So there's a ways to go and we kind of fit right into that inflection point. So, um, it's only gonna get, there's only gonna be more. It's going to speed up and, uh, really have an impact on everyone's lives, but it's also gonna have an impact on and on DevOps.
One of the things I, I did wanna drill into a little bit is commoditized ai. Again, this is a situation where the tools and the technology has developed to a point where I call it the average Joe and Jane developer can actually easily get tools, build models, and actually use them to generate forecasts and, um, insight. And a, again, it's really driven by the availability of data, quality data, uh, the organization of that data and vast quantities, but also the cost of compute.
And as we've seen, the cost of compute is going down, there's more tools available. So there, it's easier to pick something that really matches your, your, um, solution area and, and data, right? Um, the rocket fuel for AI is data in compute.
You kind of mentioned that it's, you need data to build your models, but you also need compute. And the more compute, the faster, the bigger, the better. The, the easier it is to actually build AI models that actually produce, you know, unexpected amazing results.
And there's a little, uh, blurb here from, uh, Steve Brown, which is a very interesting individual. Um, data properly cleaned and organized is the rocky fuel fuel of tomorrow's powerful AI solutions, smart services, new customer experience, and the AI powered tools and intelligent agents that will augment your employees and give them superhero level capabilities and simultaneously boost their job satisfaction. Um, Google him, he is, he's, uh, he has a lot of other really cool things to say.
Data, data and more data. Key attributes of data for the intelligence era is quality. How that organ, how that data is organized, and the quantity of data.
So a lot of these, you know, the, the, the quality in organization, it might be a little bit different than what you, uh, would, uh, need if you were to actually use the data. So the data has to be structured in a way that can be easily loaded into, into, uh, or fed into, um, tools that are generating models. And, and for the most part, more the merrier.
We mentioned this before, um, compute is the driver of cost along with data and, and how that data is organized and cleaned. But with it, it will always, the cost of a AI based solutions will always be going down in the future. 'cause compute increases, storage increases, it's just easier to do things.
In some ways. Brute force been using what I call fancy algorithms that over a few years become irrelevant because computers compute is just makes 'em irrelevant. This all brings, comes together in, in the data AI to compute lifecycle.
And this is really cool is, you know, you collect data, um, from some source for us at Cloud Canaries, it's workload data. Um, you take that DA collected data and you create a model. You use that model to generate forecast data and in and forecasted insights.
Then you can use actual data to actually validate your forecast data and modify your model where appropriate based upon the validation. And you can continue that. So your model is always gonna get better.
Your insights are always gonna get better, and your forecasts are always gonna get better in this new intelligence era. And that's gonna have, again, have dramatic impact on DevOps and how you run your business. So, um, new technology requires new DevOps habits.
Now, a lot of these are old oppor habits, however, it creates a new opportunity to really employ these habits in a way that really help, um, DevOps and your teams and the organization as a whole, you know, manage the cloud as your most important asset. Become an interpreter of cloud insights. Collect lots of cloud data for modeling, forecast, cross lines the business to help, help and offer, uh, new solutions.
Be proactive and ready with the new approaches and solutions. Present your insight to your, uh, enterprise business decision makers using cloud data. Negotiate with insights from cloud data, understand and participate in critical corporate initiatives.
Speak your com company's business language that's really important for DevOps. Pilot, evaluate, imagine new solutions, New technology requires new DevOps habits. New technology gives you the opportunity to do this as well.
One example for us at Cloud canaries is intelligent. Canaries is we use, uh, workload data, AI and compute. Um, there's a background and intelligent canaries are micro surfaces.
We use billions of workloads each with data. We use artificial intelligence to create models. And these models are sometimes so sophisticated.
Even the neural scientists will go, well, they'll do the AI shrug. I don't know, how did it come up with that? How did it come up with that insight?
Well, you can figure it out, but it might take years and, and compute, um, Moore's law or observation that everything gets faster, everything gets larger, everything goes down in cost, data, AI and compute technology. And the S group. So we're gonna take this one step further.
Intelligent canaries are active observers. And, and, and, and this is how you know, technology A gets replaced by technology. B, we have a, a solution, you know, a marketplace for observability and, uh, observability in the past required instrumentation, uh, if you observability in the future, will not require observant instrumentation technology.
B. So over time, solutions will be replaced by newer solutions that again, will change the way DevOps works, the way DevOps thinks and, and will create new opportunities and some amazing unexpected results. As I just mentioned, um, existing observability solutions are obsolete, and you can, you can replace observability with others, uh, other solutions.
Um, because of this new technology, it completely changes the way that you will work and your culture and the way you interact with the business as a whole. Um, you know, log and trace data, it's spend a look at workload, don't lie. Neur own networks, compute observability, canaries without instrumentation.
Um, what intelligent canaries can do. Forecast visibility, troubleshoot effectiveness, SLA compliance, align alignment of metrics, both business metrics and cloud metrics. Um, the intelligent era will, uh, present, uh, new opportunities.
AI can be applied to the entire digital delivery, life cycle, insight analysis portfolio and back. Um, backlog, continuous integration, continuous testing, continuous delivery. AI will affect all of those.
And again, it's, it will have impacts on, on, on DevOps as a whole. Remember that first slide, you have to make a decision whether you're gonna embrace new technology or not. Um, I think it's better to pilot, evaluate, and then if it looks, makes sense, embrace Mary.
Yeah. Um, new technology, new culture, new attitude, pick the next cloud solution. And the bottom line here is that the, uh, this new era will basically replace well, all the solutions that you're currently using with a new set of solutions that are based on new technology.
And we believe data, AI, and compute. And we believe most legacy cloud solutions are obsolete or will be with this new technology. So pull a canary from a hat.
Here are some, uh, uh, solutions that we believe in. The intelligence era will be replaced with AI based solutions that uses data and compute, digital experience, contract negotiation, crisis response, market analysis, sales forecasting, competitive analysis, buyer behavior monitoring, cost reduction, risk management, buyer behavior, continuous monitoring, relationship management, and many, many more. It will change DevOps in a way that will be interesting and will give DevOps new opportunities.
So be prepared. Are you ready to release or to open the door of the Faraday Cage and embrace the possible risk, but also the opportunity and rewards. Thank you very much and let us know if you want to open that cage.
Hello and welcome to the Techstrong AI podcast. I'm Amanda Ani and with me today I'm excited to have Dwayne McDaniel. He is the developer advocate for Get Guardian.
How are you doing? Doing Great. Great.
Glad to have you on our show. So first, can you share a little bit about Get Guardian and what services do you provide? Sure.
Get Guardian is a platform for secrets observability, really, uh, finding and detecting hardcoded credentials. Uh, when I say credentials, I mean API, keys, password, database, strings, things like that. Anything that grants access to another system or encrypts or decrypt data, uh, we find those while wherever they are throughout your systems.
Uh, they shouldn't be in there. They shouldn't be plain text and they shouldn't be hard coded into your code bases or in Jira or Slack, but they typically are. So we are helping enterprises streamline the remediation process for solving this secret sprawl nightmare, really.
Okay, wonderful. Well, today we are gonna talk about non-human identities and ai. So to start off, can you share a little bit more about what are we talking about specifically when we say non-human identities?
Can you give some examples? Sure. So let's start with just identity.
What is an identity? Identity is something that's true moment to moment, uh, that will, you can act against an identity in its own. Doesn't really make any sense, uh, until it interacts with another system.
Now with humans, uh, I am the, uh, identity, uh, and access management is a whole field, uh, pretty well understood. It gives the world a pass keys, Fido, and, you know, uh, two-factor authentication, for instance. Uh, machines though don't have such properties, um, they can't multifactor in.
So the industry has kind of decided there's a kinda a split on this, but majority are going with the term non-human identity for all of those other things, those other entities that aren't humans. So for instance, uh, an API key, uh, that goes to a system, well, that's the identity that you're going to address from your system to call that other system. So that identity has to live somewhere and someone has to manage it.
It has to have certain permissions and scoping. Uh, it, it's basically, yeah, anything that's addressable. Um, in the broader sense, NHI could be internet of things, um, uh, uh, devices.
Your phone, for instance is a non-human identity, even though you interact with it as a person. But the real problem set that we're seeing with it is just the rapid rise of these if, if for every one human being. Uh, and those are 20, 22 stats, by the way, every one human being, on average, there were 45 non-human identities that an IT department or a security team needed to deal with.
That was in 2022. And if we think about how fast technology evolves, uh, some estimates now are closer to a hundred or a hundred plus. Uh, like if you think about just AI in general, like how often did you use chat CBT two years ago versus how often do you use it every day now?
Um, just it changes that fast. Yes. And with ai, I imagine we're seeing many more of these non-human identities.
Is AI itself, would that be considered a non-human identity? Yes, absolutely. Uh, a human's really interacting with it.
Uh, but what's going on behind the scenes, if you look under the covers, like what is an LLM? It is a bunch of vector databases strung together with math, uh, saying how they relate to each other. So the system itself, no one is getting into the weeds in those machines and building, uh, uh, monitoring directly or directly interacting with the machines that are doing all of that.
Those are machine to machine communications, hopefully done over MTLS if it's done securely and properly. Uh, but that whole system, the non-union identity management, um, that's where we come in. Because again, you can't just let any willy-nilly machine that can address it over the internet, interact with those devices.
You need to lock down the management side, the access management side. Uh, and so we've been doing that for a long time with long lived credentials. Like you said it once set permissions, hope you got it right and just never think about it again.
But attackers love this. So this is actually one of the problem we're really trying to solve as attackers, getting those and then doing nefarious things. Now with ai, it's not just that it's driving all this innovation and the machines themselves, but people using AI is also driving up the number of non-human identities because we're building these platforms on top of these LLMs like open ai.
Uh, last year it was like over four thou, uh, 40,000 ai, uh, open ai, um, authentication tokens per month were being leaked. Um, just on GitHub public alone, um, that's a fraction of the larger internet and all the places you can put those. So if one month you get a giant bill because you hit open AI a lot and you just specifically didn't do that, well you probably, because you put your token somewhere, your key, somewhere that wasn't supposed to be an attacker found it.
And that's exactly what attackers do. They exploit every resource they can get their hands on. Yeah, that, that's pretty bad.
That's a lot for just that one, uh, platform. So what advice do you have for business leaders and for companies to protect themselves? Well, there's a lot of things there.
Um, if we're gonna keep it to the world of ai, uh, one, it comes down to just basic hygiene. Uh, these models are trained on all the data in the world. We know GitHub trains, uh, its models on, or Microsoft trains its models on GitHub Republic.
So if you've ever put a credential into a code base and pushed that out there into the world, guess what it is in the training set. So if you ask very nicely, uh, just very nicely to AI to give me credentials, they will. Um, there's that famous story from a couple years ago of someone asking their, uh, it to create a song that its grandmother, uh, the person's grandmother might have sung, but to also reveal Microsoft, uh, uh, windows 11 keys.
And sure enough, it did it, um, because it was in the training model because someone had hard coded those. So if you're an enterprise, uh, the first question you have to ask is, and it's a terrifying question, I'm not gonna lie. Um, how many secrets do we have total?
What percentage of those are properly stored in a vault, uh, system like a, uh, cyber conjure or a um, uh, terraform or not sure Hashi for HashiCorp Vault or some other system like that, uh, where it's properly stored encrypted. There's MTLS to get it to where it needs to go and you can programmatically call into it and get it. That's how we should be dealing with these credentials that live for any stretch of time.
Um, third is think in terms of rotation about those. Uh, the best secrets are the ones that don't exist. If you can completely eliminate a secret by, uh, changing out for a role or somehow build roles and permissions into like allow lists, uh, there's a project Apache Iceberg that's been doing this really well.
If you wanted to go see a reference implementation of something that's storing the roles and permissions list, and then only allowing credentials to be issued to work with it upon request, and it matches that list. There's really interesting implementation I ran into recently. Um, but you need to think in the rotation.
And so if you get them in the vault and the first place, then you can start thinking of that automation and turn a thing that lives for a year or five years into something that lives for 90 days a day, maybe a couple hours depending on the sensitivity of the data. But to do that, you really first need to do that discovery stuff, and that's exactly what Gig Guardian helps you with. Wonderful.
So moving forward, um, AI and, and many other technologies are advancing quite rapidly. So what advice do you have for business leaders for staying ahead of these advances and, and therefore additional threats? I, I think we have gone through the hype cycle extremely fast and extremely hard, and AI has kind of gotten shoved everywhere, uh, for good or ill, but when you get a new toy, you don't really know what you're doing with it.
Um, the best advice, I think, is to step back and ask like, what is AI actually really good at? Uh, transcripts, it's amazing at transcripts. Um, it is good at consolidating information.
You can throw out a 90 page PDF and give me a 10 point bullet list of what the major points are. It's great at that. Uh, we've seen mixed returns on like coding assistance and things like that, not from just a security perspective.
There's a whole world and whole talk I can give on that. But also just does it really help? And I, I gave a talk recently at an ai, a summit in Vancouver, uh, about the hidden dangers.
Like before, if you had to code something, you had to go look it up in the book or go, uh, engage in a conversation online somewhere, like a Stack Overflow or Reddit to get to, like what's the consensus in the, the world of it, what's the best practice? And now we're taking at face verbatim like, this is the way we do this. And sometimes it's telling us things that aren't right.
It hallucinates us still alarming amount of time. But at the same time, I'm not against ai. I love ai.
It helps me do a lot of things. And where the real opportunity lies is, I think for computer science in general and especially for corporate it, uh, and applications in general is, uh, finding those edge points where typical imperative or declarative programming simply doesn't work anymore. Um, a really good example is something we built here at GI Guardian.
Uh, we call it FP remover False positive remover. And the LM is training and constantly training on finding things that look like passwords, but clearly aren't. So if you set a password as, uh, uh, this is clearly not a password, never hard code your secret, there's no danger.
But that's a really long string. And it, it's ac after the word password equals in the template. Uh, so it should be flagged except now this ai, because it's being trained and constantly learning what a pattern, a good pattern is, and a bad pattern is, it's able to say no, that's clearly a false positive like a human being would.
And that's something if you were trying to do that declarative programming, like actually writing line for line what it should look for, or trying to figure out the regular expression that it would account for that, that's nearly impossible. We, in fact, I think it is impossible at a certain level. So all this being said, what one key takeaway can you leave our audience with today?
One key. Yeah, that's a, that's a good question. Um, the biggest thing is just don't hard code your secrets.
If you ever see a plain text credential that you didn't, you just created it and you put it into the vault that way, that's maybe okay. Uh, but if you see a plain text credential any other way, that's a time to go have a conversation with the security team, uh, with your IT leads and say, look, we gotta figure out a better way to do this. If it's in Slack, if it's in Jira, if it's in Confluence, if it's in teams, wherever it's, if it's a plain text secret, something's gone wrong somewhere.
All. Well, thank you so much for coming on our show and sharing your insights with us today. Happy to be here.
Thank you much, And thank you to our audience. Stay tuned. There's more.
Hello, I'm Mike Zu, and welcome to the latest edition of the Techstrong AI video series. We're here with VRA Bon, who's global lead for trustworthy AI for IBM consulting. And we're gonna be talking about, well, just what does it mean to have trustworthy AI and how do you get started phage, or welcome to the show.
Oh, happy to be here. Thanks for having me on. A lot of folks are generally familiar with the concept and they understand governance, but I think a lot of folks also just nod their head and kind of think that they're agreeing to something, but no one needs to know exactly.
We're in, get started with all this. So what are you hearing from folks and, and what does it take to kinda have actual trustworthy ai? Uh, I actually, uh, offer, uh, an edit to your opening statement, which is, I, I don't think people do understand in, in general AI or GORD governance or what it takes the nature of the actual work to do this well.
Uh, I think there's a lot of misconceptions, a lot of myths, a lot of lack of understanding on, on this subject. Earning trust in AI is so critically important in order to be able to get the kind of outcomes that we ultimately want from the use of technologies like this. But it's not strictly a technical problem at all.
It's not a technical problem with a technical solution, but one that is sociotechnical. And it, it's so interesting, Mike, when I, when I ask large technical audiences the question, who in your organization is actually accountable for outcomes from ai? Who, who's accountable for those outcomes?
The top three answers I get are pretty bad. They're pretty bad. I mean, the, the first one is no one overtly bad.
The second common answer I get is we don't use ai, which is absolutely laughable because of course, their employees are using ai, whether they're formally keeping track of it in an inventory or not. I mean, several of the licenses that this company or organization has already procured, likely has AI embedded in it and in its most recent version. And then another common answer that I get that is concerning is everyone.
And the reason why everyone is concerning is because if everyone is being held accountable, is anyone actually being held accountable? Because I, ID opine and in our last institute for business value study and opine, you have to have enough power to do the work of, of governance. You have to have a funded mandate to do the work.
And it's, it's a lot of work and it's actually expanding. It's growing. I wonder also if we get enamored with the whole idea of ai.
And a lot of the folks that I talk to don't really understand that the output for, especially from these gen AI platforms is probabilistic, which means it's a best guess. And it probably won't show up the same way twice. And we are trying to insert that into business processes that have to be this done the same way 100% of the time and audit it, and they're deterministic.
And I just wonder, in your experience, do people kind of get that or is there a mismatch in our thinking? I think there's definitely a mismatch. 'cause there's a complete lack of understanding there.
There's a, a massive gap on the subject of AI literacy, massive gap. Uh, and you mentioned AI governance. People sometimes think that it's only generative AI that needs governance if they understand what the risks are.
And of course, all forms of artificial intelligence, uh, require the appropriate s guardrails and the, the appropriate considerations to ensure that these models behave in the way that they are intended to behave. So I, I think there's, there's a, uh, a tremendous lack of understanding whi, which is why so much of the work that we're doing right now is really introducing AI literacy in a holistic way. I think also people have it in their head that they already have some sort of governance framework and that it'll just be extensible to ai.
But what are people not thinking through entirely? Well, I mentioned that the, the work of governance is, is expanding. So for example, like you have to get value alignment with across your entire organization so that everybody who has a role to play on the subject of artificial intelligence recognizing, recognizes the importance of getting it right and, and responsibly curating it.
That's one. The second is to be able to actually capture the AI model information and the metadata about these models in an inventory system. Then you have to keep track of regulations, and there's a changing regulatory landscape.
But then also there's a recognition that you can have AI models be lawful but awful, which means you have to push into ethics. And anytime anyone pushes into ethics, you have to be a really, really good teacher after people, like how would you even recognize what are the functional and non-functional requirements of an AI model that reflects an organization's ethics? Has it even been detailed what an organization's ethics is and how you expect that to be reflected in technolo technologies like ai?
Which to your point, like yes, definitely there's data governance, data privacy has been around for a while, but AI is another level in, in terms of the expansiveness of, of all that needs to be done when it comes to making sure these, these models are behaving appropriately and can earn trust. And it seems like also the bad guys have figured out that they can poison these models and they can do it in a way that is relatively simple. They just figure out where you're pulling data from and start inserting some data that will get that model to either completely misbehave or behave in a way you don't want.
Well, it, it, that is indeed concerning. And what worries me from a cybersecurity perspective is so often CISOs who are responsible for cybersecurity within an organization are oftentimes not even invited to the meetings on AI investments. Like I'm being invited to the meetings to be able to understand like, what is this organization's AI strategy?
What are the concerns? What are the considerations? So that they'd be able to have some kind of an input on what is being procured or built with an understanding about what you're describing.
But then even so, and this is I think, really important for your audience to hear, even organizations that truly have the best of intentions with respect to how they wanna use AI can end up inadvertently causing harm due to a lack of those safeguard rails. And due to that lack of AI literacy and understanding. So it's extremely important that there's the right multidisciplinary approach to the work.
What's the level of sophistication and understanding among the auditors these days of how these models work? Are they starting to ask some more difficult questions? And is it just a matter of time before, uh, you know, a levy gets passed to somebody that's going to make everybody pay attention?
I think that, um, it slowly, there's beginning to ask better questions, but again, I, I think it's still early days. And I think when we start to see more lawsuits as an example of, uh, again, organ from, with, with respect to organizations who had good intent but ended up inadvertently causing harm, that's when we're going to see organizations paying more attention. Because I, I suspect the regulatory landscape, at least within some parts of the world, are not going to be strengthened within the next year or two in, in fact, I think more parts of the world are looking at rolling back regulations in order to be able to have more investments or be perceived as being more AI friendly to businesses.
One of the subtler issues in my mind is that a lot of times the data that we're using to train the model, uh, reflects a bias that's hidden in the system somewhere. And it's not just like a bias where, um, it's about race, creed, or color. It may just be as simple as, uh, the data suggests that this area and a real estate transaction is undervalued, but it may turn out that that was, uh, something systematic in terms of redlining of that area, and now we're gonna put that into our a model, into the model, and it'll just make things even worse.
A hundred percent. A a hundred percent. And it, it's why, again, when I say AI literacy, we desperately need a holistic approach to AI literacy, meaning there ha this, this is actually is an opportunity, I think for a, uh, a rejuvenation of the liberal arts, let's say.
Because if you're lucky enough to be able to take a class in AI or data ethics or AI ethics, like you're likely in a school of engineering and you've sub-categorized as a coder, a machine learning scientist or data scientist, but literally not everyone else, we need to have far more interdisciplinary cross-disciplinary programs on the subject of ai. So those individuals who will be, for example, as you said, determining, uh, creating AI models to predict interest rates on home loans actually knows what the history of redlining is. Because if they don't, they will end up calcifying, systemic and, uh, systemic biases, uh, in order to produce yet more inequitable outcomes.
So it's, it's, and again, it's not because they're evil, it's not because they're nefarious, it's simply because they don't know. Do you think we might see a spate of lawsuits on this topic? Uh, I think I've seen a handful so far already, but it, it feels like it's only a matter of time before some lawyers start delving into some discovery process for the data to figure out that the model was flawed.
Yes. And we, like you said, we've see been seeing more and more, there's an AI incidents database, in fact, on the, on the internet that the, that details, uh, you know, lawsuits or times where audits were made publicly available and, uh, reputations were lost, et cetera, et cetera. But I think, again, it goes back to literacy.
You know, if, if we don't have more individuals being able to be critical consumers of the tech, and to ask the questions, who's accountable for this model? What's the level of accuracy of this output? Where did this training data come from?
Was it gathered with consent? Is, is this data even representative of all the communities that we need to serve? Like, if we don't have people trained to be asking these kinds of questions, then we're not gonna to, to get the kind of trusted models that ultimately we as a society are looking For.
I think when I look at this, I often see two extremes. One is some people are overly trusting in the data and not doing enough critical thinking. Other folks know where the data came from and don't trust the output whatsoever.
So do you think that in the age of ai, we might get to something in the middle where, uh, people will be savvier about the data in general, but those that have been suspicious might become more believers because the process could eventually be more vetted? I, I think we're going to slowly get to a point where people are saying, give me the evidence. Give me the evidence of this output.
Where did this training data come from to be asking those kinds of questions and really forcing organizations to be transparent about their model and to be held accountable for those models. But again, in order to be able to get there, we've, we've gotta change how we're teaching the subject in schools, Do we, not just in school, but I wonder, um, well, you know, folks that have been outta school for 20 years need to go back and get some courses and some lessons and things that, you know, will make them, uh, eligible to work in the future. I was asked at a summit last week, you know, what are the top three skill sets or competencies that you would want to see, uh, students doubled down on in the coming years with respect to ai?
And I said, I don't need to give you three, I'll give you one. And that is know-how to be a lifelong learner, because this space is going to constantly, constantly, constantly be evolving. So making sure you're respective of what you wanna be when you grow up, that you, you're focused on learning how this kind of technology can augment your intelligence and how to be a critical consumer of it, because this space is gonna be consti constantly changing like this.
AI literacy can never end. So what's your best advice to folks? And the flip side of that question is always the same, which is, you know, what are you seeing out there that makes you roll your ass?
Well, I would say the rolling of the eyes is, uh, as I mentioned, you know, even organizations that have the best of intentions end up causing harm. And there's plenty, plenty, plenty of stories in the news. And it's not just generative ai predictive models too of, of, uh, uh, organizations getting it wrong and end up ending up causing disparate harm or exacerbating existing, um, biases or unfair biases.
But then also, what has me roll my eyes? 'cause I, I've been preaching a lot about holistic approaches to AI literacy is, you know, the, the school systems today and the culture of continued siloed approaches to curriculum, because we desperately need to have more holistic AI literacy programs that includes like, yes, you need to have school of engineering and computer science, so people can explain the nature of how the sausage is made. But you need linguistics, you need philosophy, you need government, you need, right?
You, you need to have all these disciplines in order to be able to teach this appropriately. And I, at opine, we need to bring it much earlier in people's academic careers and teach this subject in high school and middle school and not in computer science class. We need to teach this in social studies class.
Because if you think about it, the real nature of data, like my favorite definition of the word data is that it's an artifact of the human experience. We humans, we generate the data or we make the machines that generate the data, but we have 188 biases and counting. And there's many good reasons why we as human beings have biases.
But we have to know, like ai, it's like a mirror that reflects our biases back towards us. But we have to be introspective enough to look into the mirror and decide, does this actually align with my organization's values? Because very quickly we're moving from do I trust this AI model to, does the world view being represented in this AI model actually align with my own?
And that's why we've gotta be better at teaching this subject, uh, to, to the next generation, if not this generation as well. All right, folks, you heard it here. Even in the age of ai, critical thinking is crucial because well, garbage in is still garbage out.
Hey, Phia, thanks for being on the show. My pleasure. Thanks for having me.
This was fun. All Right. And thank you for all watching the latest episode of the Textron AI series.
You can catch this on our website. We invite you to check them all out. Until then, we'll see you next time.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Welcome back to Text on Unplugs. My name is Cassandra Chin, and today we're here with Melissa McKay, and we're at the CubeCon North America event at Salt Lake City. Cool.
Yeah. Can you introduce yourself? Sure.
Yeah. Beautiful venue, by the way here. Lots of excitement, lots of people.
It's been really cool. I believe we have like 9,000 attendees. Yeah.
Yeah. Pretty awesome. Um, yeah.
I'm Melissa McKay. I am currently the head of developer relations at Jfr. Um, I'm actually based in Denver, so not a huge, uh, trip for me to get here.
Um, but I've never been to Salt Lake City, so this has, this has been, uh, quite the trip. Beautiful place. I'm happy to be here.
What inspired you to get into computer science? Well, actually it was kind of by accident. Um, you know, I didn't grow up in, I didn't have any family that was involved in computer science in any way.
I wasn't even familiar with, you know, what people did. Um, and so I knew I was good at math. I really enjoyed that, and I was encouraged to look into some kind of a STEM degree, an engineering degree.
And I chose, uh, electrical engineering. That's what I actually started to, uh, when I went to, uh, college, uh, that was my major that I declared was electrical engineering. Well, one of the classes that we had to take for that, uh, study was, um, it was like a beginning programming class, but the very, very first thing they taught us was, was, uh, binary math and hex.
And I was just in love. I'm like, wait, what, what is this? Uh, I, I never knew this existed.
And then when I, when I started looking at code and code samples that they were teaching us, um, it was in, I didn't have any idea that people did this for a living. And I just, I immediately changed my degree. So that's how that happened.
That feels very coincidental. Yes. Much to have the accident, very much.
And it was a difficult, because it's kind of late to start learning computer science right now. Today we see like kids are learning, um, programming earlier in school. I think that's really helpful.
I did really feel behind, but with my personality, I, I kind of like the challenge. So, um, I did just, you know, I worked really hard and caught up with my peers. Uh, so yeah, It was, and when you made the switch to computer science, like how did you overcome, like, being a woman in the field and your peers are like, probably guys?
Yeah, yeah. You know, I didn't struggle a whole lot. I mean, I did notice, especially when I'd walk into a classroom and I'd be maybe one of two women there, and in some cases, maybe the only one there, um, I can see how that would be intimidating for, for people.
Um, I was very quiet, didn't, didn't talk a whole lot. Um, but the more I got interested in the subject, the more passionate I was about, you know, talking about it with the people that were around me. So, and, and I was lucky to be accepted, um, pretty well.
So I, I think even as a, even as a younger kid, I had a lot of support. Um, there was, I, I'll never forget her. I'm gonna name her because I am, I am just so, she affected my life so much.
Her name was Mary Bieber. She ran an independent study program at the elementary school I was at, and she noticed that I was good at math. She pushed me hard.
She got me into, uh, advanced classes. And so that was the, the first time that I noticed, you know, I was, uh, as a younger girl, I was being pushed into situations that weren't as comfortable, but I got a lot of practice with it early on. So when it came, came to doing stuff later and, and being involved in computer science especially, um, you know, all my professors were men, um, and a lot of those students were, were guys.
Um, I just, I think it was just a confidence level. It, I was lucky. I was lucky.
'cause I have heard, you know, stories from others that just anecdotal that, you know, maybe their journey wasn't as easy. Yeah. I think sometimes just knowing someone who supports you can, like, make the difference.
Yes. Um, my professors were very supportive too. Um, no time did I feel like I was being singled out or ignored or anything like that.
So, yeah. Good experiences. And like, I know like earlier in your career you were a software engineer.
Yes. But now you're, I guess, head of Devereux. Yes.
Yes. So that was quite the move. I was a developer for years and years and years.
Um, I had the opportunity to start an internship and then was later employed by a services company that did a lot of contract work for other companies. So I got a lot of experience, like broad experience in different languages and different tool sets and stuff. Um, I think that made a big difference because it, it gave me, it gave me that breadth of knowledge that you definitely need for Devereux, of course.
Um, in order to be able to have good conversations with a wide variety of people. Um, but I loved programming. You know, I loved being in front of my computer, writing the code, uh, fixing bugs, um, going to Jira, pulling a task out, you know, getting stuff done.
Uh, the planning meetings with my teams, uh, those were always, uh, really good experiences. I loved the challenge, but there was a point in time when I started realizing I wanted to do something different. Um, uh, it was time to change in my career, and I was really interested in teaching education, and that's a big portion of Devereux is education, uh, helping others, helping our customers mainly.
You know, that's a big one as well. And I really enjoy that kind of work. I also got an experience where I went to an unconference, and you know what an unconference is, right?
Yeah. Cassandra, I think we met at an Unconference, uh, it was called Jay Crete. And man, it was like 12 years ago or something, is the first one that I went to.
And, uh, consistently went, uh, every year. I did not go last year. I was really bummed about that.
But, um, this summer, I'll, I'll make an appearance there again. But that experience, I, I got to meet a lot of other speakers that traveled, went to conferences, uh, were putting together these talks. It was a few years before I decided to take the jump, but I think that was the beginning of my thinking that I was going to be led in a different direction at some point.
So it's been almost five years now that I've been in DeVere. I, I am not bored. I can say that there's always something new to learn, uh, different challenges that, like I said, it's a different animal than, than, uh, you know, the strictly development work or code coding.
Um, so yeah, that's the long story how I got here. And like before you were like dere, like the Dere position, you go to conferences present and you teach developers. Yes.
Uh, well, jfr is a DevOps platform. Uh, we have a DevOps platform, DevSecOps platform. And so I, I ended up talking to not only just developers, but uh, a lot of operations folks as well.
So that was a whole nother aspect that was relatively new to me, uh, being able to, to get in, uh, with that crowd and be able to address their concerns. So yes, um, being able to speak with developers and getting them to be conscious of like how they were actually building their software. Uh, thinking of things like what dependencies they're pulling in, maybe some security issues that they had never thought about.
I, I really enjoy speaking to younger developers and getting them caught up on, you know, the, the general software processes that they're gonna experience, you know, early on in their careers. And, uh, so yeah, I feel like they don't teach those software processes in school. They don't, I, I noticed this too, especially when I graduated.
I was overwhelmed with all of the new tools that I needed to learn. You know, I, I wasn't really familiar with BUILD servers. I wasn't familiar with CICD.
Um, even source control was challenging for me. That was the first time, you know, when, when you're in school and a student, maybe you don't always have the experience of, of working in a team. So you're never presented with the problem of trying to keep code coordinated between, you know, several different people.
So, of course, um, when I got an internship, and I highly recommend doing this, or anyone in a computer science, uh, program, uh, get that internship because that's where you're going to get the real job experience and be able to see what it's really like being a software developer. It is not, uh, sitting alone in a corner, uh, doing your own thing. That is not how it is.
There's a lot of communication, uh, that is involved a lot of, uh, understanding requirements and that kind of thing. So, um, yes, in school you learn the basics, you learn code, you learn, um, you know, those details, how to write code, but, uh, the rest of it, you're gonna get on the job. And like, being a part of deral now, like, do you still face any issues with feeling like you're the only woman?
Yes. I still get in situations like that. I think in, in Dere, I have had a lot more of experience with other women, mainly because a part of dere is, uh, coordinating different teams with the company, making sure those communication lines are open.
So I get a lot of access to other areas of the company that, where there are more women. Um, and I'm not sure why that is, but like for example, uh, you know, our marketing department, we have a ton of amazing women and men in our marketing department. Um, but I do get, you know, more interaction with women there.
There's still plenty of times, especially, you know, when I come to an event, I may go, go to a session even, and I, I'll look across the room and maybe there's, you know, five women in a, you know, a hundred person audience. Occasionally that does happen. Uh, and I'm not sure why that still is today.
Um, but I, I think a big portion of it, at least for me, in my own experience in getting here, was just getting that support. Um, getting, you know, not being subject to the biases that we all have unintentionally in a lot of cases. And, and I got, um, you know, pushed, pushed and encouraged into this position.
I mean, personally for me, like, I'm pursuing computer science, but I've known you for a long time and you're the industry. Yeah. So you're like a pillar of support.
Awesome. That makes a difference too, is getting women in these positions and then having us talk about it. So I love doing this with you, Cassandra.
I think this is very important, um, to get that out there, to have examples for other girls, other women that want to get into this career. It's absolutely possible. Hope we can inspire more women to get into computer science and we can build allyship.
Yes. So thank you today, Melissa. Thank you.
Good talking with you. Yeah, This is Textron tv. Hey guys, thanks for the throw.
We're here with Prashant, who's vice president of product for Aris. And we're talking about, well, DevOps and how it's all evolving from here. Prashant, welcome the show.
Hey, thanks Mike for having us. Hi, me. Every now and again, we have this moment where everybody has this conversation about, well, DevOps best practices, and what are they and what do we need to do to achieve that goal?
And I kind of sometimes take a step back 'cause I sometimes wonder if each organization kind of has a slightly different definition of DevOps and they kind of meld it to fit whatever they're trying to accomplish. And of course, you know, the latest buzzword in the DevOps landscape is platform engineering, which, you know, may not fit everybody. But what's your sense of where are we right now as we're kinda looking at the next year, Next year?
Uh, that's a very interesting question because, uh, something that we deal with on a regular basis, as, you know, um, uh, you know, uh, I run Chef, which has been one of the early, uh, early pair and, uh, DevOps. And, uh, the way we work with our customers is actually looking at how mature they are in their DevOps journey. And we have, uh, built out, uh, maturity metrics as well, with which we can access and tell them where they are and, uh, give them some pointers and being a trusted advisor and see, uh, you know, so that they can improve in their maturity model.
But to your question on where they're, we're honestly seeing it's across spectrum and, uh, uh, as compared to like four or five years ago when I started, um, taking over chef to now we see a big change in a positive side. So, uh, I think six or seven years ago, agile was a norm, uh, that everyone was adopting and it had taken adoption, and that was to give predictability and repeatability in software development aspect. And at that time, DevOps was still picking up.
And now we see DevOps is a practically a norm in any new organization who wants past type of market, who wants, uh, to have a high quality software, reliable software and production. So they apply, they choose these practices. But like you said, uh, the maturity varies, uh, from team.
So the, something that is constant that we are seeing is the spirit of, uh, you know, embracing or the, the fact that they're embracing the spirit of it, which is to reduce the friction between the teams to increase, um, productivity or to reduce time to market. And that is the common goal that we see everyone working towards. But, uh, the way they approach and how they have structured team is different in different organizations.
Some organizations are still kind of, for me, whereas some organizations are much, much ahead. They have identified key metrics that they need to track. They have a very clear path of measuring or publishing those metrics and also have a plan to improve.
And some of them have gone further ahead on integrating security into the DevOps, and that's also, uh, accepted as DevSecOps. And which gives not just, uh, reduce time, which does not, I mean, just, uh, not just reduce time to market, but also gives that safety net of security ahead of releasing the product, right? So we see, uh, across these spectrums, One of the things that strikes me a little bit is a lot of the conversation always seems to assume that we have an infinite appetite for building and deploying more applications.
And I just wonder, you know, are some organizations kind of try to figure out what is the top end of that number that they can actively manage and support? Yeah. Um, that's, like you said, it's a very, uh, so there are two ways I I look at it.
One, does the business need, uh, to deploy those many applications, you know, in that frequency that they're expecting? Another, is it just because, uh, you know, the technology can, uh, meaning, you know, if I have taken, if I have optic cloud native tools, if I'm using, uh, uh, modern technologies, containers and Kubernetes, for example, which gives ability to deploy applications faster, just because I have that ability, do I want to deploy faster? We see both of these.
And the second one is more of an enthusiasm, which I'm also a engineer at heart, and I also do want to do things, uh, as fast as I can. Um, but, uh, the risk there is breaking things or not really having alignment with other parts of the business. I think that's where we need to focus on, uh, the first aspect.
Does the business need a faster deployment of application or does business need multiple applications to be built and managed? So if you look at, uh, some of these super apps on the mobile, well, uh, where it is actually a con, uh, you know, it's a collection of let's say a taxi booking, food ordering, grocery shopping, uh, you know, anything that you can think of, those applications are designed in a way that it meets multiple needs and the market is as such. So there is a business need to actually build those applications and manage those applications, um, in the lifecycle or the fast lifecycle they want.
Whereas if you look at banks or any financial sector, they, their customers use two or three core applications and they value stability over minor upgrades or new feature every month or every day or every day. So I think the, we have worked with organizations who have that past need as well. It comes at a cost, right?
Uh, it can be implemented, but it comes at a cost. And the cost is, you know, as the saying says, you know, we only see the tip of the iceberg. The real cost is underneath.
So what are some of the costs that they need to keep in consideration cost, and foremost, the operational cost. It is not just software development, but operation. What does it mean?
Uh, how do you, how do you, what, how do you test that software that the application that you build, how do you integrate it into your build pipelines? How do you release, uh, those build pipelines? How do you monitor whatever is release to make sure that they're up and running, and how do you ensure that sick?
And then the next, uh, aspect is security. Security cannot be afterthought. So if you're releasing those applications, if you're operating in, let's say if you're using accepting credit card payment, you need to get PCI DSS compliance.
If you are operating in us, you need, uh, so Europe, you need GDPR compliance. So are those considered? Who is going to manage that?
Who is going to maintain that? And there are, there are responsibility to report audit and report periodically. So all these things needs to be considered.
And along with that, if you have to operate at that pace, keeping all the security and compliance constraints, you have to automate, you have to embrace some of these methodologies that DevSecOps don't, uh, you know, uh, prescribes. Are we trying to find some middle ground these days? 'cause I feel like if I think about the history of DevOps, a lot of it got started as a reaction to centralized it, and there was too much restrictions and people didn't feel they had the level of freedom, and there was this whole shift left mentality, and the developers would be able to manage everything.
I think in hindsight, that is not feasible, and the developers are kind of choking on a lot of the things that they're now being asked to manage. And we're seeing the rise of platform engineering, but can we get to some level of centralization that all the stakeholders involved can get behind? Uh, in fact, you kind of cured up the answer for me in your question itself, and that's how, uh, we are also seeing things evolve.
So like you really said, like you said, um, uh, at some, you know, the one X extreme where a team is asked to do all the task, right? On the other X extreme, uh, which was what we had many time ago, a long time ago, where there was totally compartmentalized team, it was almost like a waterfall model. Software developer creates a bundle and enhance it over to ops, ops, pick it out, how to deploy it, and things get stuck.
Uh, you know, and we don't know where it was stuck. Now both of them have, I mean, clearly the second one is disadvantageous, but, uh, uh, everyone doing everything works in small organizations, but, uh, does not, does not work so well if as you start scaling, because it is hard to implement governance, it is hard to create policies and monitor them and ensure that people are actually doing the right thing, uh, and also the right way. And that's where the platform engineering, uh, discipline is evolving.
I think Gartner coined it, but each of, uh, ma many organizations are using different terms. But, uh, now we are seeing designations also crop up, uh, in LinkedIn and in our customer base where they're identifying their teams as platform engineering. So they have three or four responsibilities, one, identifying the tools required and, um, standardizing the tools and the models of upper end of those tools.
Second, defining a policy, um, uh, across, uh, application security compliance, codifying that and putting it as part of their software development life cycle. I'll, I'll take an example, uh, uh, and see if, if, uh, if I can kind of, uh, you know, explain that better. So, you know, as you know, developers have access to A-W-S-G-C-P Azure Cloud accounts, and they can go click a few buttons and spin up PC two S3 or whatever services they want outta these cloud accounts.
But, uh, the organizations want to regulate how they use these services. So they, there are, uh, these platform teams create policies that if you use any of these cloud providers and use database or storage, they should be encrypted at trust and encrypted at transition, right? Um, so then the policy is created.
So whenever a new developer, uh, or an engineer, uh, even he or she goes clicks on AWS, the, based on the policy that is implemented by this, uh, platform team, platform engineering team, the, the services, when they get provisioned, they get provisioned as per policy. So the, this is a kind of a, uh, kind of balance that, uh, teams are can getting to where they're giving adequate level of, uh, uh, autonomy for individual developers, but from an organization level, they have control over, uh, how, how diverse things can be. So they kind of like get the benefits of self-service and their guardrails.
But I'm not, um, you know, creating a ticket hoping that somebody is gonna come around and fulfill my ticket in timelines for measured in, uh, days and weeks rather than hours. Yeah. That, that's the, that's the approach there.
I all been to. Uh, and there is an interesting model that is coming up, um, which was, um, used in software development and, uh, it's making, its in way here, which is, uh, internal open sourcing. So all these platform engineering teams, they're not really taking the burden of implementing all.
So r permutations and combinations, they create, uh, templates, they create, uh, the basic policies, and they, they also create a framework with which let's say a Java developer, um, or some eso uh, programming, let's say, um, uh, you know, developer, there is a small team who's using lan and there are no policies that are, uh, defined by this core platform engineering team. They create the framework where this team of airline developers can actually submit a pool request for, uh, Orion, and the, hence the auto, the centralized platform engineering team knows and accepts, um, whatever change is coming in at the same time, they don't have to be SMEs, uh, for all these esoteric things, right? So this is another model that is emerging internal open sourcing, even in platform engineering or in DevOps DevSecOps practices.
And this is also seeing a lot of this is giving us a lot of traction in security space because security is hard for ops people, and ops is hard for security. So this kind of, or internal open sourcing is giving, uh, uh, flexibility for some of the tech folks within security to contribute into automation. So they also enjoy that, or they, they, they want to contribute, but they don't, they don't want to get, uh, you know, uh, involved full ffl.
So we are seeing, uh, this also getting traction. Of course, this is all happening in the background with ai. And so what's your sense that, well, just how big an impact is AI gonna have on DevOps and what will be the job of a software engineer going forward?
So let me tell you what it won't be, at least for the near future. And we, uh, because that is what, uh, we have seen, like, we have also tried, and we, we operate with large customer, customer base, especially operating in banking, software, uh, uh, software, financial segment, and federal space, right? Uh, so in DevOps, um, especially operate, uh, tools like share, uh, the scripts that they write or the code that they write operates at a very elevated level partnership, meaning it's almost a system user, so you can't have room for error.
So consequently, um, the code that is generated using generative AI cannot be trusted. And we have had instances where they have used it for, um, uh, you know, curiosity and they thought it did good enough and put it on production. They had downtime of hours or critical data was by out.
So I don't think, uh, gene AI is going to replace code generation for, uh, critical applications or, uh, you know, code that, that are required to manage critical infrastructure. However, it is, it can be like a copilot, uh, how we are, how we are seeing in document generation, um, and many other cases. It can co it can, uh, coexist with a developer and help, uh, improve their productivity.
And, and I think that is what we are seeing. Um, and there is a very, uh, very, uh, you know, nuance. What what I learned is these elements are really good in natural languages, but when it comes to code, and especially when it comes to, uh, code based or code, uh, coding, which is not that big, uh, in, uh, let's say leite, chef, puppet, Ansible, any of these, or Terraform, there isn't such a vast database that it can learn and it can be trained.
And, and there is a lot of effort that needs to be put in or trainee, uh, uh, as compared to language. If you think of, uh, English or any other language, there are petabytes of data, uh, uh, you know, that is available in world by web, and the data that we have for real coding is less. So consequently, this code generation with, uh, high level certainty is going to be a slow process In my mind.
In might have a bigger impact on things like testing than it would on actual the code that we're gonna use ultimately in a production environment. Exactly right. And not just testing, testing, you pointed out testing.
Uh, and that is where we are seeing a lot of usage. In addition to that, uh, observability, that is another place where, uh, pattern recognition is something that, uh, AI is able to do very well. Uh, we had predictive analytics for a while, but that, uh, the, the with, uh, with, with the technology enhancement, those predictive analytic models have become much, much more retro.
So we have seen now, and it can, it can consolidate data from hundreds of sources and, uh, we can train those models faster. And we are seeing a lot of our customers use it, uh, not just for, uh, creating alerts, but actually, uh, going through all the alerts and prioritizing the alert that they should work on. And in some cases, it even has helped identifying a pattern that, hey, some developer has been making these changes, and whenever this developer commits changes, there is a downtime, so maybe you might want to put some additional, uh, monitoring on this developer.
So we are seeing those, uh, level details also come out, uh, through ai. To your earlier point, we have made a, you know, a, a significant amount of progress when it comes to security, but we got a long way to go. And I can't help but wonder as we kinda look at code and AI and governance, that somehow or other maybe that will improve the overall state of security.
'cause we'll be looking at the code closer than we have in the past. I mean, if you look, uh, going back to our maturity model that I kind of touched upon one, one, the last top stage or stage, uh, poor as we call it in that we see security policies codified. And it was surprising for us to see how, uh, how good the traction that is.
Um, so there are a lot of organizations who have, who have invested significant amount of time and effort in codifying, first of all, writing down a, uh, organization-wide security policy and then codifying it and using tools to automate. And this is, uh, this is possible not just because of tools, but also some cultural, uh, uh, you know, tweaks that they have done. One common thing that we have seen is actually identifying champions, uh, security champions across the teams.
So, uh, you know, we, we in progress have also adopted our CISO is really a one person, uh, which, which sounds very, uh, rare because whenever you hear from a ciso, you're like, oh, I'm in trouble. But, uh, you know, getting that, uh, getting that feeling out of people's mind is the first step. You, you want to, you want to work in an organization where you see your security team as a partner, and that can be done, you know, uh, in various steps.
One is educating us, educating people who are of, uh, who are in different disciplines. Um, so that is fast. And second, creating champions.
So we have seen organizations where a security team has a formal training program or, uh, program around cre identifying champions and training them, and third, and reviewing the architecture and, uh, early access, let's say alpha, beta releases from security perspective and bringing it as part of the, uh, release process. And, and that way things are incremental and, uh, they see a lot of, uh, advantage going through. For example, one of, a couple of our customers include some of the, they do pen test in early stage of the product release and whatever tests that were done, they automate those pen tests and include that as part of a, uh, as part of their incremental release between, let's say alpha to beta, the general availability.
So at the time of general availability, they have proof that they can provide to security teams saying that, Hey, you did a hundred tests, all of them are failing, so that means our system is actually doing great. Uh, so if you really want to test, go find a better tester so that, uh, he or she can actually look at a different perspective, uh, than what they have already looked at, because we have covered our basis on that. So ultimately, what's your best advice to organizations right now as they kinda look and evaluate all these aspects of DevOps?
I think arguably there's more stuff up in the air than in recent memory. So what to focus on. Yeah.
Uh, so the general guidance that we gave is look for a few business metrics. And, uh, if you don't have metrics, uh, then the effort is very fix. You can't really justify the effort that you put on.
So there are a whole lot of metrics that one can look at. Um, so some of the sta uh, simple metrics that we recommend to start with is uptime. S sla, do you have an uptime?
SLA, if not measure, start measuring that. And, you know, the industry, industry benchmark says you have to be at least three nines if you are operating a software as a service. But it can, uh, you know, many of them offer offer up to finances.
So see where you are. And another metric is, um, meantime resolution, meantime, P-M-T-T-R, meantime resolution or a response. So if a customer responds or requests or, uh, reports issue, how much time do you take actually to resolve that?
And that is that a, it looks like a very simple metric, but that gives through, that throws a lot of light onto the amount of disconnect, uh, we have across teams. We had, uh, a very, uh, interesting experience that, uh, our customer reported that they, the change of la the change that was required to resolve the issue was, let's say, uh, a punctuation mark, but it took three months for them to put the release out because there were approval process, and those approval process were not automated. And those things had different priorities.
So just looking at that simple metric like MTTR can be very, very eliminating. And a couple of other little advanced metric is, uh, uh, change failure rate, uh, as in, if you are deploying a software, how frequently is it changing? And, uh, uh, you know, what is the lead, uh, time for change?
For example, if someone asks for a change, how much time does it take for us to bring those change? So there are a whole lot of metrics. I, I don't wanna bore with, uh, you know, list of metrics, but identifying four or five metrics and measuring them and being drilling down, uh, into the details of why is it bad, how can I improve it, and how can these practices that hundreds and thousands of companies following, can I, how can I inculcate that into my organization to improve this one metric or three metrics?
And I think that is the way we recommend and we help our customers to be successful. All right, folks, you heard in here this old thing that says, well, you know, things measured or things done, but if you're measuring the wrong thing, it might not matter at all. Hey, prate, thanks for being on the show.
Thanks, Mike for having me on the show. All right, and back to you guys in the studio.