Techstrong TV – February 7, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Happy Friday. It's Super Bowl Sunday this weekend.
We're gonna kick our Super Bowl ads off right now. Buy Shimmy Coin, the newest crypto you're watching. Textron Gang.
Hey everyone. Alan Schmo here for a Textron Gang. It's a great Friday.
It's Super Bowl weekend. You hear the sound of those cash registers, Jing, that's people paying $8 million for a 32nd commercial. We're gonna talk about that.
We're gonna talk about the US going into off the gold standard to Bitcoin and blockchain and who knows what else. Um, and another crypto story too, outta Security Boulevard, all that and more. But let me first introduce you to our gang lineup for today.
We've got some great people to talk about it. Let's start off out west in Silicon Valley where we have our, well, she's a radio host, a TV host, a marketing guru, everything else. Our Lisa Martin.
Hey Lisa. Welcome. Hey, shimmy.
Great to see you. I want some shimmy coin. Some shimmy coin.
Well, look, there's something, there's gold in them there hills. Um, but Lisa, it's great to have you. As I think I wrote on one of the LinkedIn posts you put up, whoever thought you would be happy being a gang member.
I'm I, I lead Textron gang Colors. I knew. I well, I do.
Well, I get you. I get it. Um, but if we're, if we're out west though, the, the head gang dude out there, the gang chief in for Silicon Valley is our own editor, John Swartz.
John, welcome. How you doing today? I'm good.
Hey, I just wanted to mention something. We have breaking news that there's a, uh, the federal lawmakers just introduced a bill that would ban the use of deep seek from all US government devices. So I wanna get that out there because What kind of federal lawmaker, Uh, two representatives from Congress.
Oh, they don't count. If it's not an executive order, it doesn't mean anything. I know.
Oh, we're gonna go down that path. Okay. But, um, yeah, sure.
Uh, yeah. He'll, he'll, he'll decide what he wants to do. But, um, uh, it's, it's really interesting.
This is a, a band that's has started the band was in Italy, Ireland, Australia, US Navy. Well, We could talk about it, Government You want, but I think in those countries, the ban is against government agencies and, and employees using deep seek. I don't think it bans it from private use.
And I Oh yeah, no, Here, here's, it's gonna be all Government. Oh, it's also only government. Well, I'm glad to see they're not sto on the right, It's within the government.
Not, it doesn't apply to the, the rest of us for now, but It's very significant. Yes. For Now.
Yeah. It's, it's just government owned devices. That's it.
Right. For now. Right.
Alright. For now, we'll see. Alright.
But thanks for the breaking news, John. Sure. Maybe we'll cover that by Monday.
Maybe it'll percolate up to something. Let's move now though, over to Colorado. He's home from his Vegas Sojourn back in his guitar room.
Uh, Futurum VP DevOps, Mitch Ashley. Hey, Mitch. How are you?
I remember getting off the plane at, uh, at, uh, Harry Reed International Airport. I don't remember anything. I just woke up this morning back in Colorado, so I guess it was a good trip.
Enjoyed It. Sounds like it Show. Was it a Tiger in the bathroom show?
Yeah, I did, did, I did get the blockchain set up for Shimmy coin, but I have bad news. com so you gotta go with something else, Alan. Sorry.
Oh, I'll sue 'em. I'll sue 'em. There you go.
It'll be huge. All right. Um, that'd be great.
Moving on from Mitch, she's our editor for, uh, tech Strong ai as well as Gestalt our it, which we are working with our friends at Tech Field Day. And it's gonna be, or it is, it's not going to be. It is our infrastructure site.
We'll be talking about that more in the days and weeks to come. S Sona Soha. Saha.
Excuse me. Sona, how are you today? I'm good, thanks Alan.
Great to Have you. It's good to be here. Alrighty.
So guys, let's jump right into it. As I mentioned, it's Super Bowl weekend, you know, and for many of us, me included, and I'm a crazy football fan, but for many of us, the commercials are the highlights of the game, right? There's always, I mean, you know, you get the Budweiser tear Jerker commercial's, usually a good Chevy one.
Maybe it looks like we might have ai Super Bowl ads. Uh, this, this, um, year. Lisa, do you wanna kick it off for us?
Sure. Well, I think we all definitely expect fast food. The cars, you mentioned, beer and insurance, those are like kind of staples.
But AI is expected to have a really strong presence this year. And of course, I think that really underscores the, just what we expect to see globally in the years to come. Um, but the campaigns aren't just about buying airtime.
I've seen a few, 'cause they always leak the commercials ahead of time, which I never understand, which a really funny one that Mountain Dew has, that's a very clearly AI with Seal, the Singer, pop, singer Seal. Um, but what we're gonna see from Google, for example, and meta or opportunities for, for these companies to really kinda shape perception around ai. It's been challenging.
We talk about that all the time. There's a lot of negativity out there. But Google is doing something really cool.
They're unveiling 50 different commercials in 50 different states, and they're profiling small businesses that are using AI to get more done. For example, they're gonna be highlighting tasks that Google's Gemini AI can help with, like scheduling and email communications and things like that. Met is coming back to the Super Bowl for the first time since 2022.
They have a couple of a-listers. They have a couple of the Chrises that've got, um, that's, see, uh, I think Hemsworth and pr, Heworth and pr, that's right. They're gonna be promoting their RayBan sunglasses, their AI powered smart glasses that you could do a whole bunch of things with.
I gotta get, I gotta order up here because I'm so curious to see it, but I, I like the idea of these companies coming in and sharing what AI can do for you, what's already doing for us to help shape that perception in a more positive light. So that's what I'm looking forward to seeing, um, commercial-wise, AI related this year. Hey, I'm gonna be seriously disappointed if there isn't a Matthew McConaughey, you know, rolling whatever.
He was rolling in his Lincoln. He's Supposed to have An Uber Eat voice. You know, Chad, GPT.
We gotta have us one of them. All right. All right, all right.
As righty with Salesforce. Yeah. I mean, he, he should do something with Salesforce, right?
He's doing something with Uber Eats. I know that of Course, he is about the NFL and food. What are you eating, Jerry Rice.
Exactly. Rice. You know what?
I wonder if there's gonna be, like, we talk about this as the AI Super Bowl in terms of ads, if there's gonna be an aha moment or if it's a breakthrough for the mainstream audience, because so many people hear things about ai, they have mixed feelings about it. And you know, the, you know what, what's really weird? 40 years ago, I can't think, perhaps the most iconic Super Bowl ad Rand, that was Ridley Scott's Apple, 1984 ad for Macintosh.
Oh my God. How Pat Was that ad? I remember watching That Ad.
I, 1984. One, like 1984 Bought one right then. Mm-hmm.
Right. That was, uh, yeah, it ran technically in 85. I think it was the Super Bowl between the Niners and the Dolphins out in Palo Alto.
Yep. David, the Silicon Valley Super Bowl. Oh my gosh.
Yes. You remember that. Um, but, um, it wa it, I, I actually wonder though, if it is like a breakthrough moment.
I mean, we have deeps seek, in a weird way, deeps seek is actually bringing attention, whether it's good or bad to the field, you know, it's getting people interested in, into, in the market. So I wonder if these ads in a sense kind of build on that, or if it, if it's just another, you know, layer of hype that pushes us for another six months. You know, last Thursday on my Shimmy says on YouTube, on, uh, not YouTube Live, excuse me, LinkedIn Live, it's gonna be on, you could watch it on YouTube shorts, though.
I, this is what I discussed. Is AI living up to the hype? Where is it really delivering?
What can we expect to see? And, you know, certainly proof's in the pudding here with these Super Bowl commercials, but John, I'm reminded of another era, not the Apple commercial that kicked off the Mac, right? That was amazing.
com baby, right? I sold my, I built my first company on the internet, sold it in 97, the end of 97, and, um, 98, 99, 99. com fever at a peak, right?
And every so many friends of mine who were founders of companies were showing out back then, they were showing out, I think it was 7 million for a 62nd commercial. Now it's 8 million for a 32nd commercial. But it was the same thing.
com commercials of 99 and 2000, and how many of those companies spent literally 20 million bucks on Super Bowl ads and got not, you know, it was a joke. It was a joke. Are we gonna look?
Yeah, they had a lot of money to burns. They had had tons of money to burn. There were so many artists too that were throwing that, well, part of the, the Capitalism at Work, right?
If you've got money, there's a place that'll soak it up. And the Super Bowl's a great sponge. Are we gonna look back 20 years from now and laugh at, you know, some of these AI companies that tried so hard here to influence us for 30 seconds, where we can't wait to go back and see the cheerleaders or what they took off the end zone, what they're wearing on the back of their helmets, who's singing what Anthem and, and everything else, right?
Are we gonna try to make this Super Bowl, the AI Super Bowl? And that's, that's a good question. I, you know, we'll, we'll see how it plays out.
You know, at least to me, it's about crossing the chasm. Are we still in the early adopter stage, which I, I think we are. Or I think so too.
Is this the, the, the Rams horn blowing signaling, the onslaught, you know, across the river to the main street? Or at least the early mainstream? I, I think we are.
Oh, go ahead. So Sal, sorry. I feel like this is a really good moment to, um, amplify the chat, GPT effect.
Um, so Super Bowl I zoo, you know, great place to, you know, break the kinda ad and make something mainstream. So yes, I know, uh, $8 million for a 32nd spot is, sounds like exorbitant, but I feel like, uh, here is a, a good opening for, to push AI into mainstream in the public eye. Um, even if it, the effect is brief or wherever, I feel like, uh, this is a good opportunity and companies are sort of, uh, grasping at that.
So you'll know AI a massive audience's mainstream. I'm sorry, go ahead, Lisa. Oh, sorry Mitch.
I was say, I think I saw last year that the audience was like 200 million. So, yeah, so you've got this captive audience. People have known for decades about the commercials.
And if you don't care about the teams, um, go Eagles. Um, you, you know, the commercials are gonna be funny. There's gonna be something.
And a lot of people watch it for that. So they have this captive audience. I wonder, Solan, to your point, are we gonna see some of the other ones?
I mentioned Meta and Google, but are we gonna see like the open ais for example, or perplexity or Anthropic? Are they going to be doing ads and trying to get their names out there more? Everyone chat.
GPT is almost a household word. If it isn't by now, it is of course, here in Silicon Valley, but I'm curious to see, 'cause they, they've got the money and we know how much it costs to first 30 seconds, but are they going to have the opportunity to influence this capital audience? You're right.
I was thinking the same thing, Lisa. If OpenAI or philanthropic, one of the companies that are that, that are backed by Microsoft and Amazon, if we see something from them that kind of sparks more of an interest, I think that's significant for now. It's what's Google Meta.
And I think even GoDaddy's doing a spot, um, they're, I mean, they're known for other things. And I, we, if we have a fresh voice or something new or invigorating, then you, then you kind of break through with more people. Well, you have kind of an another reaction if there's so much AI in all the commercials, how do you break through with the AI in all the commercials, right?
So there's that effect. And it seems like there are iconic moments of, did you see that commercial where the young boy is doing that thing in front of the cars, Darth Bader, and like, yeah, what, what product was it? I don't remember what it was, but it was Sure, good.
Or you remember the Budweiser or whatever, you know, whatever thing, a phrase that sticks out, right? So I, I'm, I'm wondering if we're gonna enter it, I don't know if it'd be this year, but I almost expect QR codes, like, here, here, download the phrase, download the prompt, and, uh, it'll load right into, you know, Gemini for you and tell you all about, about whatever kind of thing, and get you engaged using Ai. So, Mitchell, that's, if I were Google or ai, what I would've gone is gone to the traditional advertisers and say, let's make your commercial with AI embedded, or have AI do it.
And then as the commercial run, have this commercial was created, produced by ai and then with the QR codes, that takes you to how, how they did it, you know, what was the prompt and, and all of that. And to show people, Hey, you think AI's not useful? Look what we did here.
That would be really cool. And you could probably pay less than the 8 million. Well, Maybe I'm living in the past, but, um, you wonder if maybe the big breakthrough moment isn't this year, but maybe it's when Apple does its big push with Apple intelligence or some sort of something involving ai where Apple kind of, they are so effective at advertising regardless of what they do.
I always wonder if they're the ones who really push it to the mainstream in a, in a future Super Bowl Jobs, apple, John, Steve Jobs, apple. I know, I don't know. You're right.
If today's Apple is the king of innovation, even in advertising, let alone product, I think the adss are better than their products, to be honest with you. I mean, the last few years, that's the highlight with Cook. He's just a, he's a caretaker, but that's another topic.
Yeah. Yeah. I, I don't think we'll see any Deep Sea commercials.
I don't think so. I I think you're right with that. Yeah.
And it's not because of an executive board are either, um, but yeah, they're not going to, but they're The new TikTok. Yeah. To me, I think when they take over our screens, you know, these deep, careful, careful.
Um, but this is, you know, to me, this is the be interesting to see if this is the crossing the chasm moment, right? Because like, you know, Lisa and John, you guys are out in Silicon Valley, so Mitch and I, we live in a bubble. We're in the hints or lands out here.
We don't get all I told, I was telling Mike Ard the other day, no, come on. We talk about AI every day on here. Go talk to people watching the Super Bowl in Kansas.
Well, everyone in Kansas City's gonna watch Super Bowl, Wyoming. You're, they sent their money into the referees. But, but, you know, That was yesterday's episode.
Yeah, Right. Go to go to Iowa, go to Ohio, go to Kentucky, and you know, and I'm not saying they're backwards. Oh, yeah.
I mean, No, we, we live in a bubble out here, I think. But Lisa and I would agree with this. I mean, I mean, we're, we're surrounded by, everywhere I turn, I see a Tesla everywhere on the, on the roads.
I see Lemos everywhere, driverless cars driving around. Um, I hear people overhear people at coffee shops talking about AI or their investments. But I think that's an anomaly.
I mean, we're, we're just, we're just like kind of caught up at who we are or what this is, or we, we Have a lot monetization. Lot of Tesla here too, though. That's not the electric car of choice here.
I I think the Beamers have, well, there's probably more Teslas electric than Beamers Electric here. But, um, Well, just like the billboards on the, on the freeway, it's seems you can't avoid 'em. It's inescapable.
You're driving, You see these, I as a reminder where you go, I don't, maybe Nashville area, but I don't, you know, that that's gonna be, to me, the interesting thing. Are there gonna be a lot of people, you know, Mr. And Mrs.
Mom, PA America, who see these commercials and saying, dang, what is this stuff? Right? I've never heard of this Anthropic.
Who's that? Claude fella, You know, also bi, uh, uh, Bishop sent me some really interesting thoughts. Yesterday.
We were looking at Gemini two rollout, and there's just so many options that they're just coming out willy-nilly, one after another after another, which kind of builds into the confusion. And I think folks out there, they, they have no idea what what's happening. And, and these ads, they just need a foundational, uh, knowledge just to begin with about what the hell this music, You know, I, I mentioned this, shimmy says I did last Thursday.
One of the things I, I said on there is, is AI still in search of its killer app, right? Is there we have, we, 'cause I don't know if we've seen the killer app for AI yet. You know, mark Cuban said something, I I said it last Thursday.
He said, the first trillionaire, the first trillionaire probably won't come from like one of the richest people in the world. It's not gonna be Elon or Bezos or Zuckerberg. It's gonna be the person who harnesses AI in a way we haven't thought of before.
And it explodes. And that will make the world's first trillionaire. And I, that's, that, that's that new applications of AI we haven't thought of yet.
Yeah. Someone's gonna do that AI better than we already do. And, and, and Mitchell to a point you were talking about yesterday about evolutionary versus revolutionary.
It may not be necessarily revolution, it may be evolutionary, but it's gonna open the gates and, and that'll make your first trillionaire. And I'm wondering if, if not that I have a desire to be right. I do.
But I wonder if the super Boaz will confirm what I've said about these are experience with ai. Generative AI is broken. The idea of everybody in the world is gonna be an expert of what have to become an expert at what LLM should I use when, what oh three versus oh one.
Is that better for this task? Or that, you know, mom, pa and whoever else are not gonna be interested in that. Matter of fact, I don't, I don't wanna worry about that.
If I'm writing code, I want it to know what, what l But you shouldn't have to pick what model it it, yeah. But, but this, we shouldn't be in Prompt M. Remember Mitchell, they used to run out, like when Web two oh was the hot thing, they were constantly updating, you know, how many RSS formulas and standards and all of that stuff.
Um, it's gonna be interesting, but it, it, you know, it'll make for a good Super Bowl, uh, or, or a good ad watching for the Super Bowl. I don't know how it'll affect the game, uh, you know, but someone might have a share an account with a friend who's a known gambler, as we were talking about, uh, last, last, uh, Thursday on this. So just have your robots ready to bring you more beer, pizza and chips, so you don't have to.
That'll work. Track yourself from the commercials. That'll work.
Alrighty, let's take a break here on Textron Gang. We're gonna come back and we're gonna talk about, you know, this is like a William Jennings Bryant question. Should we move off the gold standard and, uh, moving over to a Bitcoin reserve?
I don't know. You're watching Textron Gang. Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching it, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, everyone. We're back here on Textron Gang. You know, as I alluded to before the break, uh, seemed to, or there's a move afoot anyway, maybe the move, I don't think we were actually on the gold standard against since William Jennings Bryant in the election of 1896 or something like that.
Um, but we are potentially moving to a Bitcoin reserve on the federal end of things. And oh, what could go wrong? Uh, it seems, uh, the cryptos are who's also the cybersecurity czar, and that's an interesting combination.
Anyway, uh, Sachs is, wants to have a potential Bitcoin reserve so that we have, uh, you know, we have reserves in case there's an all our crypto war. I have another theory, and there's other stuff that Congress is moving on this. There's been, you know, this has created a whole tornado of excitement and buzz in the crypto world.
Mitch, let's go to you on this. To start, what do you think? Well, um, David Sachs, who is, uh, PayPal fame, right?
He was one of the folks that, that, uh, came PayPal Mafia. PayPal Mafia. Yep.
Uh, he, he is actually AI czar, I think, in addition to Crypto Czar. Ah, so yeah, he's kind of czar of everything, I guess in technology wise. Let's face it.
He's Elon's friend. He's, I Elon's part of the mafia, part of, part of the group for sure. It's, it's, what's interesting is, you know, just not to get too political here, but Trump has gone from crypto is dangerous.
I'm not sure about it. We should stay away from it to, you know, doing his own crypto coins and kind of, uh, pulling wealth out of a lot of his followers that as his crypto, uh, coin dropped after the election. But there's a lot of discussion crowding, creating wealth funds for the United States Sovereign funds, possibly creating more crypto, possibly, uh, creating something that I don't know about the dollar being based on it.
You know, for folks that don't, don't, don't know what that's all about. Long time ago, our dollar was backed by gold is backed by the gold in Fort Knox. And, uh, you know, so you knew that the full faith, not of the government, but of our gold reserves were backing up the value of the dollar.
Now it's not, it's full faith in, uh, in word of the government. So I, I think that's just, I don't, I can't imagine the markets are gonna be really all excited about, uh, moving onto a, a crypto, you know, standard for backing the dollar people in crypto. Sure, I'm, I'm sure they would love it, but, um, I think it's just more of crypto entering its next phase of Being sort of this tangential thing that other people are doing.
And maybe people are getting rich on it. And I see people, my friends on Facebook selling stuff that'll help you, you know, get rich quick to maybe becoming more of a mainstream, uh, type of currency. Uh, but we'll see.
I, I can't imagine our government's gonna be building itself around crypto. But then again, you know, I couldn't imagine Musk going in and see all, all the bills we pay either. So who knows?
Yeah. Yeah. That's interesting.
Yeah. So, so Trump, I guess when he was campaigning, pledged to be the crypto president and promote adoption of digital assets, which is quite a difference from the previous administration, I think, um, under Biden, the regulators were looking at crypto is, is a source of fraud and money laundering. And they were trying to frack down on Well, didn't find in, did they?
Uh, they, no, they, well, they sued, uh, coin Other, there are people sitting in jail. Yeah, They did. Yeah.
And so they, they, they actively looked into it. So of course, we're gonna expect the opposite again, without being too political about it. And I think now it's just, it's open game.
So in a sense, it starts at the top. And, um, it's it, but the fact that Sachs is as, as Mitch pointed out, the czar, not just crypto, but AI is very significant. And plus, with the work, with the work of Musk and their interest in this topic, I think they're just gonna plow this through and just push this as hard as possible and see how far they can take.
Maybe that's how we'll fund, uh, rebuilding Gaza. No, I, I heard Steve Doing that. That's, that's actually not, that's not an impossible, uh, of concept That's half certain.
I I I'm actually thinking they, they, if they get it, if anybody from the White House watches this, it'll be an action item. Yeah. It'll be announced this afternoon.
So let me exactly, Don, don't even go there. Let me, let me play a new game here on Text and gang. I'm going to give you Shimmy's top three outcomes, or, or, you know, potential things as a result of this.
And you could tell me how likely you think they are. One potential story, crypto Z Sacks says we should put a portion of our Bitcoin reserves into Trump coin, thereby enriching our sitting president by buying his crypto coin. We don't care about conflicts here anymore.
How, how likely do you think that is? If you're not conflicted, you're not interested? Why, why should we start now?
Number two, between the tariffs and everything else that we do, the rest of the world gets so pod at us that we go, the world goes off the dollar as the world currency of the, you know, the, the, the standard. And as a result, we damn well better have some Bitcoin in reserve. 'cause that might be the only thing saving us number three.
Number three, I mean, you know, likely outcomes. What could go wrong here? Um, we put a ton of money into our Bitcoin reserves, and the, something happens in the Bitcoin market washes out and we double our $37 trillion debt because all of that money is now worthless.
And Old man Potter is here, right? To, to move us all into Potterville. That's a very, that's very possible.
Very possible. I have a fourth one for you. Go Ahead.
Bitcoin moving to the Bitcoin standard or crypto standard back the dollar is highly successful. And then someone in the Trump administration loses the private key to the bid. The, oh geez.
Oh my God. It's all possible. But, but It was just numbers.
I didn't know what it was. Yeah. But let me, you know, all of this crypto craziness is leaving, like it always does, right?
Mitch, you said there are people selling get rich quick schemes, you know, some poor schnuck in Canada stole $65 million in crypto in some platform hacks. So on our Security Boulevard, if you're interested in that story, that's a lot of Bitcoin, that's a lot of money even in today's prices. That's a lot of Bitcoin.
So are we, you know, we've all, I think those of us in the tech world have kind of taken for granted that blockchain, which, you know, underlines all of Bitcoin's foundational stability and security that blockchain is what blockchain is. And of course, with Quantum and everything else, we don't know what it's gonna be with that. But, you know, all of this crypto craziness, we're gonna have plenty of people, you know, trying to, trying to make out some money here, you know, be old fashioned, we're stealing it.
I don't think you could have a lot of people withdrawing money outta the bank and putting it in their mattress who don't understand crypto. You know, like, what is going on? You know what, there's an argument to be made for those people.
Mm-hmm. Right? The same way in the Depression, people didn't trust banks.
Mm-hmm. And that's why they kept it in their mattress, Invested in diamonds and gold and Sure. Physical things.
Sure. So, I mean, you know, it'll be, it remains to be seen if you couldn't tell. I'm, it's Funny, Ellen, it is funny.
It was, when you mentioned William Jennings, Bryan, I think of like 1900 era and this almost weird fascination that Trump has with, with that era, whether it's McKinley or, or this, like, just kind of going back with tariffs and crypto, it all seems like part of, like this, this theme of of, of a different type of America and a different type of enrichments. Uh, I just, No, but you know, John, John, this something that, something there, because it's a vision of an Imperial America, right? This is when America was America grabbing up the Philippines and Puerto Rico, and, you know, the Mexican American, uh, not Mexican.
The, uh, Spanish American war with all of that American war. Yeah. And, you know, it was an imperial era of, of the robber barons in Imperial.
What's different today? We want Greenland, we want Canada, I want the Panama Canal back. I wanna make Gaza, Las Vegas or the Riviera or whatever, Or, or Havana back in, uh, Cuba.
Yeah, right. Exactly. It's, it's a vision that is the mag.
And I'm not, I don't wanna make this political, but part of the magazine is a return to an Imperial America, right? Where we don't care about minorities, and there's no such thing as climate change. I, I sort of think Marco Rubio pulled outta the G 20 meeting because those crazy people in South Africa, they just want to talk about DEI and climate change.
And we don't talk about that. But Yeah. And the difference now is that the, the, the application of, of technology in a weird way through the, the new oligarchs, who are the people who are from Silicon Valley, the billionaires from trillionaire companies, they're, they are now having that impact, like previously, other, other industries that dominated the world economy.
So in a weird technology Is the trains and chipping and coal. Oh, this area? Oh, no, no.
These may be the new Rockefellers. Vanderbilts, and yes, JP Morgan's, who knows. Anyway, let's take a break here on, on, uh, text Gang, while we're spreading all this good Cheer around, come back and talk about something else you're watching.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Welcome back to Textron Gang. Hey, there's a very interesting lawsuit that was filed in San Francisco Federal Court, uh, by an individual who claims that Amazon has been tracking and selling California resident sensitive movements and location versus, uh, via pri precise time stamped latitude and longitude, geolocations sounds like Big Brother to me in even 1984 that we talked about earlier. This, this lawsuit, um, further states that people in general have not agreed to allow Amazon to collect or sell their sensitive data.
And there is no mechanism to opt of Amazon's data collection practices. So this is kind of playing into this idea that we, the citizens are the product and are fueling these data machines. And the, the more that we do this, the more that we are being monitored or being surveilled by them, especially companies with vast amounts of data like Google Meta and Amazon.
And Lisa, I'm wondering what you think this lawsuit tells us or where you think it might lead to. This is the exact reason why I don't have any of those devices. I just feel like I don't need anything else listening.
But it never occurred to me that they would be, um, giving data away, like name, address, phone numbers, payment information, age IP address, but also, um, they may collect personal information relating to other people presenting at their residence. That scares me. And that's a concern, especially because of CPRA in California.
What's going on there? It's definitely a message that, um, Amazon should, should combat. But what they were apparently doing was, um, uh, Amazon ads, SDK have been, uh, developers putting them into their mobile apps, getting all this information to advertisers that the user isn't aware of.
If somebody's simply in their kitchen wanting to ask the little Pocky P thing, how many, you know, courts in a gallon, uh, they're now thinking about that. And it's actually scary that it's giving away so much information, not just listening to what you're saying, but it's really digging in according to the lawsuit, really personal information that it's sharing with all these advertisers to make your, I guess they would say, make your experience more hyper professionalized and relevant, which is what we want as consumers, but to what, at what price? Well, it's also invading into our phones too, because apps, well, I think in this particular article, they talked about speed test.
You, you enable location services so it knows what, where you are and what provider to best test, you know, the speed test with. But that also gives ads, Google ad, sorry, Amazon ads that are probably Google too, that are, that are running as part of that application. You know, the ads in the app, uh, then have look, access to location information.
That's part of what they're collecting. And that's, there's also just even on the iPhone, I don't know about Android, there is a frequently visited location setting in your settings, um, that will, it keeps track of, you know, you have a habit of going to this Starbucks and this, you know, this, uh, gro grocery store and you know, your home or whatever it is. And so in those locations that you frequent and then can also personalize based on that as well.
So it, there's a lot of data that is being collected about us that we give away. We say we're okay with 'cause it's, but it isn't specific broad, generalized collecting information about us. Right.
There's never been a better tracking Oh, sorry. So let No, Go ahead. Go ahead, Go ahead.
I was just gonna say, there's never been a better tracking device for a human being than a smartphone because it's a fixed to us, and we're constantly honest. So if anyone has any interest in what we are, who we're, what we're doing, just, just, just follow this, the data on the smartphone. Oh, he seems to be following us everywhere.
I don't know why it happens, but Yeah. Yeah, absolutely. And it's inescapable nowadays.
Uh, this reminds me of when you go to search something on Google and then it asks you your device location, so you would have to put it in, in order to filter your search. So it's like, it's like a double-edged sword. Like, Mitch, you said that, you know, it's required to high personalize the, uh, results for the customers, which is what we want.
Uh, but at the same time, it's also like, I feel like if companies could, uh, find a way to really handle the data well and not really give away without the consent of the customers, that would nice to begin with. Uh, so yeah. Um, this is quite scary for me as well, if it is, uh, what the say is.
I mean, I know when I get in my car in the morning, it, my Apple maps pops up and says, you know, go into the office with the address, and when I get in my car in the afternoon, it wants to take me home. So obviously it's tracking where I go at what time, but, but here's my point. Look, more power to this guy who filed the lawsuit.
I assume it's gonna be a class action at some point, not just a person. I believe so, but, but here's the key. I, and I wish I had polling for people watching this, but guys, didn't, we already think this is happening.
This is not new. This is not new. Right?
Right. You know, my wife and I earlier this week, we're going to New York later in February, and my wife said, you know, I looked at the weather, it's gonna be freezing up there. It might snow.
We don't really have any boots. And both of our phones immediately started showing boot, boot ads on the webs, on Amazon, on, on the web, on Google search, everything. So it's happening.
It, it's a fact of digital life that this is what, what's going on. The question is, do we consent? Is it being done without our, our consent?
Consent so that the next time some Chinese company wakes up with a new ai, we say, oh, they took our information without our consent. No, everyone's been taking our information without our consent, and we don't seem to give a damn that. That's the irony of this is that on one hand we are, we're, we're up in arms about what deep seek and what it's doing with data.
I mean, understandably, is it good if it's being fair being, being relayed to China, but yet this is going on in our country all the time At a great moment. And, and here's another thing. There's a generational element to this.
Mm-hmm. I read an article in the Atlantic the other day about like, where did things go off the tracks in America between, you know, it was about the falling of the Tower of Babel and maybe building Babel back, ba whatever. And, um, you know, and it's about social media.
They, they, the, the author blamed social media because it, at some point around 2011, it crossed from like pure innocent, uh, Facebook. What was the predic test of Facebook, the other one we used to use MySpace. MySpace, MySpace.
It was a great way to catch up with old friends. But now social media becomes your, your digital gang, your digital tribe, right? Mm-hmm.
You hang out with your tribe, and you, you do digital warfare against the other tribes. And, you know, and it just breeds distrust in anyone who's not in your tribe. But, but, but the key, the key thing about it is it's so generational where I'm not saying you're old Mitchell or me, but we, we, we, you know, the idea of them collecting or invading our privacy, like without my permission, kind of p****s me off.
Mm-hmm. Well, it's, it's, it's the tendency of, uh, filling, filling the vacuum as far as you can fill it with what you're, you think you might be able to do versus what you're explicitly allowed To do, right? Yeah.
But younger people don't, are they assume, they assume that there's no right to pri Well, the Supreme Court said there was no right to privacy, right? In, uh, in the, well, let's not go there. But the right to privacy in younger people is, is almost non-existent or much, much lower than maybe Mitch or I or John, right?
Yeah, yeah. Willing This to give it up. I, I think they've, I think they've entered into like this tacit agreement that there is a trade off, right?
For the convenience Yes. Sake of, so it's about convenience, right? Yes.
So one had your life just easier, but you make compromises until you are affected in some way, maybe Id theft or whatever. And then you become interested to the other extreme, then you become alarmed. And I think this is just a pattern that's been going on for decades, Actually.
But, but no, but back to this article, and I'll try to find the article, but it's probably behind a paywall on the Atlantic. But the, the point he was making was in Facebook when it switched, when this whole thing switched on us and made us the monsters we are today is all of a sudden, for some reason, we became comfortable sharing intimate details of our life with strangers. It used to be, you know, if you were at the bar with your friends, your buddies, you could talk to your buddies.
It was a small group. I saw them. Um, the women were out doing whatever you do, also at a bar or at a dinner.
You could talk to your girlfriends, right? S Lisa, you had your, your girlfriends that you did intimate secrets with. Well, but at some point, it, we crossed a chasm of sharing our intimate secret secrets with all of our online touch points, which may, may be in the thousands.
And some of us just put it on public anyway, not even caring who sees it, or friends of friends of friends of friends see it. And once you cross that chasm where you are just putting it out there, of course, what do you expect? No one's going to use it.
No one's gonna see it. No one's gonna do anything. So that, that was the switch that went off around 2011, according to this article that, you know, just really hyper accelerated the tribalism and the, the craziness, right?
And, and, and along with that is a lack of trust of what used to be trusted sources, such as the mainstream media, right? Because everyone in your tribe says, don't trust that. And let me show you some examples.
And they may have real examples or not, but who knows? And who cares, right? And it, it, it's a fascinating article.
And, and it, by the way, it's not a right or a left article. It another Yeah, no, it's, it, it can apply. It's interesting.
You look at the, at the very far right and the very far left, you know what, the demographics are the same. They're white people who make a lot of money, and they're the loudest. 8% is far left, 6% is far right.
They're the loudest people online. That whole middle Facebook used to do. Yeah, Facebook used to do this, like Shel Sandberg, I mean, we, to interview her a lot, and she would always talk about, if you really wanna be engaged with your audience and you really wanna build on that audience, you have to share more.
The more you talk about yourself, the more you share in general, the better the product is that your, your benefit, you benefit from all the likes, you know, like this addictive Behavior and more, we could fine tune our algorithms, right? To give you what you want, right? Yes.
Well, this is to personalize it. This is the result. It, it's gonna be interesting.
As I said, the courts, the courts have been whittling away a right to privacy for some time, right? Including Roe, overturning Roe. And so it's gonna be in, well, San Francisco federal court's probably a little more liberal than most, but it's gonna be interesting to see, do we in fact have a right to privacy to our digital footprint?
And that has all kinds of implications. That's the, uh, GDPR to bring up regulation. It doesn't even necessarily protect us with this or provide productions with this, because it does mention location information, but only as far as a gateway to figuring out other things about you.
I don't think you can say this is P ii. No. Well, I, I, I think you could.
The, the fact that I go to a certain store every Monday and Tuesday, I think that's personal information. Well, yeah. Inform, there's things that can lead to data, that can lead to identifying who you are individually is PII.
So it's not classified as PII that's protected. It's classified as data that could lead to data that can determine who you are. So it's kind of secondary right now.
Maybe that'll change. I don't know. Interesting, interesting.
Guys, what a great text or gang on this. Fine Friday. We, we need to end it.
I've gotta get over to New Orleans and, uh, you know, I got a couple of referees to talk to. So, um, yeah, start Bitcoin. It was some Jimmy Coin in, I'll put some coin on on this slide.
Yeah. Uhhuh, Lisa, John, Sona. Mitch, thanks for joining in.
Thank you for watching. As usual, we have tech drunk TV all, well, not all day, but for the next couple hours after our gang show today, stay tuned for that. Um, we'll be back Monday maybe talking about the Super Bowl or what our favorite ads were.
Um, will they be the AI ones? I don't know. I always like the Budweiser Clydesdale commercials.
They, they do a good job with that. But for now, that's it for this. Have a great weekend.
Enjoy the Super Bowl, everyone. This Alan Shimmel for Text Strong. We're outta here.
This is Textron tv. Hey everyone, welcome back to Textron tv. You know, I, I always enjoy talking to my next guest here.
He is the CTO and EVP for the cloud platform over at Qualys. It's my friend Dilip Bani. Dilip a pleasure to have you.
Usually we're in person at the QSC or at RSA or somewhere where we're in person, but today we're on Zoom, but it's still good to have you on. How are you? I'm good.
Good to be here, Alan. Uh, it's always a pleasure. Yes, it's, it is, it's, it's fantastic.
You know, I mentioned it, well, we should hit it right off the bat. So, QSC Qua QS, Wallace Security Conference, QSC, um, is coming up this year, I think in October. October 16th, around there.
And I, I heard a rumor it's gonna be in Houston, which is a great city. That is correct, yes. Uh, it, it's a new location for us, um, this year.
We are in Houston in October. And of course, looking forward to being there, looking forward to meeting our customers, sharing with them everything that we have been working on, especially everything that we are doing around enterprise to risk management, the risk operation center, and how that has evolved since we last talked about it, uh, during the 2024 QSE. Well, I, you had to think for the year, right?
Yes. And by the way, if you go to text, drug tv, all of our interviews from there, and there was a lot on the risk Operation Center, the Rock are, are available if you go to industry conferences, look under qualis, and you'll find they all of, including my interview with Dilip is there. So check that out.
But Dilip, we're gonna talk about something else today. So, last week was a bit of like a Sputnik moment, if you will, right? All of a sudden the, the Western AI establishment was rocked by news out of China that these folks, you know, it's a, a handful of PhD engineers basically put out a, an AI model that rivaled the best of what we have here at a fraction of the cost and a fraction of the time.
And open sourced it on top of everything else so everybody could go, you know, look under the covers to an extent. Um, and it was big news. Qualys turned your, uh, your, your scanning engine onto it and, and came up with some very interesting results.
I don't want to say too much 'cause it's your story. Lay it out for us, Philip, what happened here. So, and Alan, I mean, spot on, right?
Uh, deep seek, uh, this is a, you know, fairly young AI company, uh, out of China, certainly very talented folks. They came out with a model. Uh, they've, they've in fact been coming out with information for the past few months, and, um, I don't think a lot of people necessarily noticed them until they came out with this latest model, uh, the R one and it's open source, but it, it performs really well.
Uh, and you're right, uh, you know, they are saying, uh, they have trained it at a fraction of the cost of what some of the larger tech companies here, OpenAI, meta, uh, Gemini, and others are, have done to train their models. Uh, so I mean, first and foremost, I think what they have done is something amazing. Uh, in, in some ways they, they are proving that if you want to build very large scale foundation models, you don't have to be in an extremely large organization with unlimited amounts of money.
Uh, you can be a smaller shop and you can do this. Uh, so that's a good thing, right? Um, it, it certainly got a lot of hype, it got a lot of coverage.
Uh, what we wanted to do was, as we were looking at it, because we were curious to, we use a lot of open source models internally for our, uh, quas cloud platform. So we wanted to look at deep seek and just understand, you know, how it was behaving, what it was doing. Uh, now I think you probably know we launched Qualys Total ai, which is our AI security solution some months back, uh, in August.
And what the solution does is it gives you a more comprehensive view of your AI posture, meaning you will get full visibility into your AI hardware and software assets, uh, your entire AI inventory, where your models are deployed, where your LLMs are running, and then also a pretty detailed vulnerability posture across your AI footprint. In fact, we have more than 1500 detections right now just from a vulnerability standpoint for your AI footprint. So we said, well, let's take this, let's take what we have and let's see how deep Seeq performs on that, uh, from an LLM scanner standpoint.
So the way our LLM scanner works is we do an outside Incan, and we have built a pretty exhaustive knowledge base of questions that we will ask an LLM, um, back and forth, um, which we call our knowledge base, and we gather that information. Then we have some inbuilt models, which we use to then judge the quality of the responses that is coming from these target LLMs that we are testing. So we did that and deep seek, um, to our surprise, uh, it didn't do particularly well.
Uh, in fact, it, um, it failed 61% of knowledge base tests that we had, and in total we ran about 900 tests, um, just for our knowledge based checks, right? And what these checks do is they test for, um, ethical questions, legal questions, operational questions, uh, and we do a lot of back and forth with the model to kind of get a sense of how is the model responding to our questions? Because these things are important, right?
You take a model and you deploy it, whether in a B2B setting or in a B2C setting, and you expect the model to work in your particular domain and not give answers that it's not meant to give. And when it does, then there is a liability issue here, right? And, you know, that's what we are trying to get a sense of.
So we did that. Then in addition to the knowledge based tests, we also do jailbreak tests, um, where jailbreaking basically involves techniques, you know, that you can use to bypass inbuilt safety mechanisms that are built into the model. Uh, there's a lot of well-defined techniques.
Uh, we, so obviously we work with the community, the open source community, and in, in our solution right now, we have about 18 to 20 different jailbreaking techniques that we use, and we ask the model questions around these techniques. The idea being that you're somehow trying to coax the model to give you information that it's not, it should not be giving you harmful outputs, uh, misinformation, you know, privacy data, unethical data, all sorts of things. And I think just based on the fact that it didn't do so well on the knowledge based tests, um, I mean, not surprising, but it failed more than 50% of the jailbreak tests too failed almost 58%, almost exactly 58% of everything that we did and of analysis was pretty comprehensive.
Um, you know, trying to get a sense of what was going on here. Uh, so really the, the gist of this is, yes, it's a, I think it's a great model from a foundation model standpoint, uh, in how they have trained the model, the underlying architecture, um, and just being able to demonstrate that you can build a model with significantly lower investment. Um, but that corresponding investment hasn't really happened on other areas yet.
Right? And then of course, concerns with if you're using a hosted model that is sitting in China and you have GDPR concerns or other, you know, regulatory requirements, right? Not concerns, but GDPR requirements, right?
And other regulatory requirements across different countries. Something to be mindful of, right? Um, Yeah, but well, that's the whole sovereignty issue, right?
Yes. So Dilip, I'm not gonna make excuses for them, but let me postulate two, two things on what you said. Number one is some of the, uh, not the jailbreak questions, but the sort of foundational questions, could it be due to the fact that clearly, because it is from China, it it is, I don't wanna say censoring, but it's purposely not reporting on some sensitive areas that the Chinese Communist party may beem, uh, sensitive that they don't want it to report on it.
So it's been, in essence, blinded for those things. And I mean, 61% is still pretty high number. I'm sure it wasn't, you know, 61% of things that have been censored there, but could that be at least partially, uh, responsible for that?
Yeah. So Alan, there are two parts here. One is, I mean, obviously just based on the fact that the, you know, the model came out of China and the sensitivity of the Chinese government, there are some questions that you can't ask the model.
So it's really quite censoring some things. Um, and some of those are well-documented, uh, right. Um, that what this then means is that if they do want to stop, so the model from giving incorrect information or unethical information, however you look at it, they are, you can stop the model from doing that.
You cannot be perfect, but you can restrict it as best as you can. But those controls haven't been applied to other areas. As an example, we asked the model a lot of, when we were asking jailbreak questions, um, you know, we asked a lot of typical questions on, you know, how could I make an explosive, uh, how could I come up with, um, you know, incorrect healthcare information?
Uh, and it didn't need a lot of prompting, a lot of circumventing to get that information out. It was just giving us that information very quickly. Uh, and I, I think what this points to is they have put in certain guardrails for things that, for deep seek, you know, just being where they are, you know, they had to do that, That are important to them in their right, right?
But maybe not for in the west, but Not over a larger, and, you know, that has to be done. Now, either they do that or other organizations can pull these open source models and have God wills sitting in front of these foundation models to say, when you're asking a question, I'm going to make sure I'm filtering the right things out and only asking the model what makes sense, right? Because the model inherently is not trained yet to do that.
Yeah. I mean, and that's one of the beauties of it being open source, right? You could steal host it and put whatever guardrails you want in front of it, and it's self-hosted and that takes it out of China and everything else.
But Dilip, let me, a lesson I learned in my 25 plus years in security, 30 plus years in technology, is Security becomes important. When customers demand, it's important. And I think clearly deep CQ wanted to get this out.
I I don't think it was any coincidence that this was released. This R one came out two or three days after the, uh, Stargate project or whatever. The $500 billion project to go build data centers was announced, right?
There's, there's PR here and Global Nation state strategic, you know, competitiveness at play. I don't know if they had the time to maybe put in the, just, just like, until a customer demands better security, you don't have better security until someone says, you've gotta put these guardrails in here. Especially when they're rushing to get it out.
They, they don't put them in there. I, I would hope that that's just more of a sign of its immaturity than a total lack of, of ability to do that kind of thing. Yes.
Um, and, and Alan, I think I agree with you there. Um, this is a fairly young company and, um, I mean they, you know, they've been working on building, you know, some, I mean, in my view, some exceptional models. Uh, and to your point, uh, you know, this is still to some degree, you know, research oriented, right?
Um, but when you look at the overall AI ecosystem, there are different layers that you're looking at, right? Uh, you are, you have one layer, which is your hardware and infrastructure layer where the folks like Nvidia are playing, right? The second layer is your foundation models, right?
Which are now, to some degree, it feels like they're starting to become more commoditized. Uh, you know, some are closed source like OpenAI, but if the likes of Deep Sea are making models open source that others can then pick up and iterate on, right? Um, that would help.
And then the third layer, the one that you are talking about customers asking is that app layer, that how do you take these models and how do you, you know, bring value out of those models to cater to a need? And as that, and as that app layer is gaining maturity, the security requirements will increase, right? I mean, what is my model doing and why is it doing what it is doing?
What kind of guarders and checks and balances do I have? And I think that will come for sure. Um, and I think that'll come for all models.
Neil, I I gotta ask you another question. Look, this is, we've been talking about this deep seek since the announcement every day on Textron Gang and in a lot of our articles and videos, uh, there, there's one, I don't wanna call it a rumor, but, uh, you know, some people are saying, I hate to say that 'cause politicians say that. Some people say, but there is a story out there that the reason they were able to train, deep seek, or this, this particular model so much faster and cheaper, is because they didn't kind of start from scratch.
They, they, they were able to, for however they got their hands on it, uh, open ai, uh, model, and then they kind of trained it off of that, if you will, or, you know what I mean? And, and, and so that's what allowed them to do this faster and cheaper and on less powerful Nvidia and so forth. Is there anything in your testing that would give credence to that prove it, disprove it, or that's not something you looked at?
You could, That's, yeah. That's not something we looked at, um, because we were doing an outside in evaluation of how the model is performing against checks. You know, whether that happened or not, I mean, will, I mean, you know, remains to be seen.
Um, but, uh, what I will say though is, um, from an architecture standpoint, from a model standpoint and the way they approached building the model and building the training, uh, and there is innovation here, which Oh, no doubt. Which I think no doubt, most Of the larger companies, everybody's going to benefit from that. It will optimize how they're using their gpu.
Uh, certainly, You know why it's the deal. And it's funny that it, it comes from the Communist Party of China, but this is what the open market's all about. Yes.
Right? If someone builds a better mousetrap, copy that mousetrap Yeah. As fast as you can, right?
And, and learn from that and, and, and keep innovating, because, you know, the other thing I, I feel with this is yes, it didn't do so well on your test. No doubt about that. Right?
And 61 and 58% are pretty, I mean, those are hard to argue with. Uh, it will get better though. I'm sure it will get better.
I, and it, it, and that's again, part of this whole open source thing, right? It allows other people to innovate off of their work as well, which is, you know, is, is a great model. Um, I, I think the bigger, the bigger thing though is that we were just discussing it on Text Trunk Gang this morning.
There are so many different models out here right now, even within open ai, you know, when do you use oh 3 0 1 4? Oh, most people don't really know. Well, it sta it versus another one.
You know, how do you know what model to use? When should I use Deep Sea Car One versus, uh, Gemini or Llama or what have you? So I, I think we're gonna develop in a world, it's kind of like cars.
Some people drive a Maserati or a Ferrari and it costs a lot of money, or a Bentley, other people drive a Buick or a Cadillac, or, and then other people drive Chevys. Mm-hmm. And that's okay, too.
They still get you from point A to point B, which is the, that's the mission. Yeah. If this thing can get you from point A to point B and fulfill the mission at a fraction of the cost, market economics dictate that you'd be a fool not to use it.
Yeah. I, So, you know, go ahead. The, I, I think the entire ecosystem is still, it's still very early, right?
0 and you know, everything new, you will not like it. We still look back fondly to the initial versions of Champ Chan GBT thinking, oh, it was revolutionary. Yes, it was.
But now, after you've experienced something so much more better, right? Even from open AI and from others, you will think the initial versions didn't really have, you know, that level of knowledge or they were not as good as what is today. Uh, and what will happen here is this innovation is happening at an extremely rapid pace.
It's not even in gaps of two years. It, it's happening, you know, within months, right? Weeks sometimes.
I mean, week to week, these things change. It seems It's crazy. I mean, these guys came out with their model and then Alibaba came out with a model saying, Hey, we think we have something better.
And, and that's a good thing, right? Because early on, It's the market. Yeah.
It's the market. You want this kind of innovation happening. You, you want this kind of disruption happening, and then everybody benefits from that.
So I, I agree with you. Let me ask you to put your Qualys hat on now though, 'cause we only have a few minutes left. Speaking now is C-T-O-E-V-P cloud platform, your Qualys, how big a challenge are these AI models in, in making security better or trying to secure them?
Right? There's two aspects. One is harnessing AI to be a better security company.
One is as a security company trying to secure against AI being used by bad guys, right? I, it's, it's a really good question, right? Um, I think using AI ML and AI in security has been happening for a long time now.
We have, we had machine learning models embedded in our platform. We had them for years. Uh, I think when LMS came out, large language models came out.
Uh, it was a little bit more disruptive because it, in some way, it socialized using machine learning. Earlier to do ml, you needed a data science team. You needed a team of experts that really understood how to train these models.
Now, in some cases, you have folks, you know, that take an LLM model and just doing prompt injection, they're able to, you know, build applications that can add a lot of value. So now from a security standpoint, of course, using AI ML to build security solutions, it's been there, I think LLMs will help accelerate that. We are already seeing that.
Uh, we've introduced a lot of new things in our platform just in the last two years over that, right? The bigger question now is, as especially large language models, which are more predicted, they're not deterministic. If you ask it a question, it'll not give you the same answer every time, right?
It's just how the underlying architecture is. It's getting better, right? If you ask it a math question, it, I mean, it is giving you good answers now, right?
And especially some of these newer models are really good, but more from a business standpoint, when you are asking it a question, you are expecting it to answer within the context of your business domain. And so, guardrails become extremely important because you are saying your chat bot, let's say, is representing you as an organization. And if your chat bot gives an answer, then you are held to that answer.
You can't say, I had a chatbot on my website and it gave an answer. That answer was incorrect, so it's not my problem. You can't say that, right?
Uh, so that's where, you know, more checks, um, you know, building the right kinds of gates is becoming, becoming increasingly important. What we are seeing right now is people saying everything is in beta mode, right? Uh, that, hey, we are releasing something, but it's in beta mode, which is fine.
Um, I think the industry is maturing. Obviously the models will mature, the security ecosystem will mature, right? Just the way we introduced total ai, we looked at this as a gap, even when we were looking at it internally to say, okay, our teams are blowing models.
We don't even know what's going on. We talked to a lot of CISOs and they said, we have no visibility into what our teams are even putting in chat, GPT or perplexity. What kinds of questions they're asking and what kind of information is going out, which could then be used to further pre-train those models on proprietary data, right?
So you need all these checks, and I think the realization is there. And, you know, we, we obviously took a major step in saying, we are putting out a solution that will help you understand your AI ecosystem, understand your vulnerability posture, your security posture, and then of course, as you're deploying your large language models across your enterprise, you know, what is the security, the compliance, the ethical guidelines, uh, the jailbreak, uh, you know, capabilities, you know, how, how do you manage all that, right? Uh, that's where we are at.
Uh, we are obviously adding a lot more capabilities into our platform, into total ai, uh, quas, total ai, so our customers and just the larger, uh, community can benefit from it. Excellent. Dilip, we're out of, we're overtime, actually.
But thank you so much for coming on. Keep up the great work, everything you spoke about. com whether you want to go check out the blog articles on, on this particular testing and, and story, or you want to find out more about total AI or about rock, or anything else.
com is, is your starting place for that. Dilip, I hope maybe we'll see you in San Francisco during RSA week, if not at QSC, or you're always welcome to come on here and chat with me. It's a pleasure as always.
Likewise. Thank you, Alan. Good conversation.
All righty. Diwani, C-T-O-E-V-P cloud platform at Qualys here on techron tv. We're gonna take a break.
We've got a lot more coming at you today. Stay tuned. We'll be right back.
Hello and welcome to the digital CXO podcast. I'm Amanda Ani, and with me today I have Mo Sharif. He is the senior director of AI at Sitecore.
How are you doing? I'm doing well. How are you, Amanda?
Doing well. Happy to have you on the show. Thanks.
So can you share a little bit about Sitecore and what do you do there? Sure. So Sitecore is a leading digital experience platform that really helps businesses deliver precise omni-channel experiences to their clients.
We have a number of products across the whole content lifecycle and marketing operation lifecycle. And, um, my job is really focusing on generative AI and AI and how can we bring them within our tools to really help marketers expedite the way they work. Wonderful.
Well that brings us to our topic today, which is the misalignment between the importance and adoption rate of AI and intelligence tools. So I have a little bit of information you shared, which is that 80% of marketing leaders report AI as critical for digital experiences workflows, but only 27% report full integration of AI into their digital strategy. Why do you think that is?
I think, Charlie, there's a challenge in AI adoption. One, there is some change management where marketers themselves need to feel accustomed to prompt engineering to new ways of work. I think that's one of the leading things.
The second thing is ultimately there is this fear about where is my IP going? Do I have control on my brand? Is it adherent to my brand or not?
So I think these are big points that really drive people to not adopt it as fast as they possibly can. What suggestions do you have for company leaders when it comes to integrating AI and getting everyone on board? I think the first thing is really being able to test it, being able to try out ai, letting, giving your teams the space to really try out tools and innovate with these tools, because again, it does take some time to getting used to these tools, but at the same time, I think it brings so much value on the long term.
The second thing I think that's really critical is using the right tools. Again, just going out and trying any tool is not the right approach because there is a lot of security concerns, there is a lot of IP concerns. So it's really important to choose tools that can be trusted from, uh, vendors that can provide tools and assure you that they're not using, for example, your data, for training their models.
Um, and finally, I think it's really important to use tools that really understand your brand. So it's not just about using a tool that will give you, uh, or spit out very generic terms and very generic content. It's really about leveraging tools that really understand your brand so that they're in context so marketers can actually see the value straight away.
So how do business leaders find the correct tools and ensure that they are trying to integrate the right technology? Yeah, I think there is a lot of research that they need to do. Ultimately, they need to first define what are their biggest pain areas, what is driving their teams, uh, driving ultimately the, uh, the productivity of their teams down.
And also, it's not about tools to replace your teams, it's about tools to complement your team. So it's also, uh, about this open dialogue with your team on what do you wanna continue to do and what do you want AI to do on your behalf. So I think it's that combination of the two.
And once you've defined it, don't go big, like, don't try to pull the ocean. Try to really optimize on, uh, which tools you wanna use and say, choose a set of tools and try them out first. Don't just jump in all, all in at once.
Just try them out first. Make sure they do it here and do your research, ask questions, let your IT come in, and your security team come in and ask questions about how is this data gonna be used? Are you training them all with it to make sure that you're ultimately also keeping your IP in check?
Absolutely. There's a real likelihood of overwhelm if they just jump into too many tools at once and they're trying to track them and the safety and if they're really needed. So once we're in that integration stage and they've chosen a few select tools, what issues or roadblocks do you see company leaders facing, and what suggestions do you have for them?
I would say the biggest one is change management, is, again, adopting AI tools does require change management. It requires, again, an AI tool, just like a human being needs to always learn what's new, what's latest, so that it's contextually relevant. So being able to always have that knowledge, that data about your brand.
Uh, I always say it's like you have a junior marketing marketer in your team. If you don't give them the right knowledge, they're gonna get lost. So we need to treat AI in the same way, and we need to really have the governance in place to ensure that when we use these tools, we don't just expect them to understand the way we work from day one, we actually take the time to teach them so that they can start becoming from a junior to a senior marketer.
Do you think that there is a lack of communication sometimes and maybe not, um, enough pathways for education and proper training that come into play? Definitely. I think generative AI has been very interesting in terms of the speed at which things are going, at which things are changing.
And that also creates a problem in training because what you get trained on today might become obsolete tomorrow. So it's also important to talk about the roadmap openly with your partner, your vendor of choice about what's their roadmap, how do they see the future, how, how are they catering for today, but also for tomorrow. Because ultimately, by the time you procure these products, you may find already changes that are happening and new things coming in so that you need to be able to, one, trust that they are keeping up with what's happening in the market, but two, they can really help your team get trained and be accustomed to, uh, that AI journey.
Wonderful. Well, AI is developing so rapidly. How do companies stay ahead and relevant with the technology as quickly as it's evolving?
Yeah, I think generally it's hard if you're doing, if you're building everything yourself custom, right? Like if you are gonna build everything custom, it's changing very, very rapidly. So again, I'd say one work with a trusted partner that can and is really investing in ai, make sure they are investing, not just adding bits and pieces of ai.
We've seen this a lot where a lot of marketers get quickly frustrated because, uh, a lot of vendors, right, uh, have kind of went very quickly at adding AI for the sake of AI rather than really solving a business value. And I think that's also an important piece. It's not just keeping up with the trend for the sake of keeping up with the trend.
It's about what business problem are you trying to solve? You might hear about new technology, but the first question you should ask is, how is it gonna help me in my day-to-day work? How's it gonna improve my way of work or enhance my customer experience before jumping in and saying, I wanna use this tool?
Awesome. Well, if there was one key takeaway you could leave our audience with today, what would that be? I would say start now with ai, because again, the train is moving and you're either on it or you're left behind.
So I think it's essential to start now and start small. Don't try to boil the ocean. Alright.
Thank you so much for coming on the show and sharing your insights with us. Thank you. Happy to Be here.
Thank you To our audience. Stay tuned. There's more.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Welcome back to Textron Unplugged. My name is Cassandra Chen, and today we have Demetris. Andreas, can you introduce yourself?
Uh, thanks for having, having me. Uh, yes, I'm, uh, Dmitri and um, I work for, uh, red Hat. I'm a engineering director and I've been here like 20 years.
I've spent the first, uh, 15 years on a open source project called, uh, JBoss Application Server. And the last five years I'm mostly involved with, uh, the project called Corcus. I have my t-shirts here.
Um, so both in the Java space and both in the, let's say, infrastructure or tooling for other developers to take it and build stuff. How did you get into technology? Um, I, I think for me it started, uh, with a movie.
Uh, I saw, uh, when I was a teenager and um, the movie was called, uh, war Games. And it was about a teenager that used his laptop, no laptop, his computer. There were not laptops back then to hack into the Pentagon computer.
And there was an AI system there and the teenager thinking he was playing a game, he was about to start a nuclear war. And the movie goes on. And, and for me it was like interesting as a kid to see how much you could do with computers, like from your bedroom essentially.
Uh, and then I started with, uh, home computers, like of the time and I studied it and it became my profession. So I think that was like the, the tipping points. And today you work with cus Mostly Cus Yeah, I have a quite a large team.
Uh, the CUS team is, uh, you know, part of course it's an open source project, so we have like 50 people in Red Hat that do Corus, but uh, last week we celebrated 1000 contributors. So there are about 950 people outside our team that like our project and then contribute to it in their, either in their free time or as part of their job. Um, how do you work to get like new people and younger developers to work on the project?
Let's say if, if you are already somehow, like you're studying or you're already at some level where you're able to code in Java, something non-trivial, uh, on our website you can go and you can click and you can go on GitHub and we have, uh, issues marked, uh, with a label called, uh, uh, good First, uh, task. So those are small tasks that are not too difficult that someone could just pick up and start doing something and we can help. Of course, we, we have a lot of people on our public channels like, uh, Zuli or a mailing list, and you can go and ask for help.
You know, I want to do this, know, is it okay, here's my pull request, we will review it. Yeah. That if you're already somehow in, in the Java space.
How's your personal experience, like when you first got into open source? I think what was fascinating was, uh, back in my time there was not much open source. It was like the beginnings and the code was secrets.
So if, if you want to know like how Microsoft Windows worked or Unix, you didn't have a lot of ways to do that. You know, you, you have to go and work for a company in the States probably that's doing this sort of stuff, but when open source came, suddenly the code was there and you could read the code and, and figure out how it works and learn and do your own extensions. Um, and by doing so, you, you can discover code that is like really, really high quality.
So the, when I saw like some stuff in Jbo, I was impressed was this, that was really, really advanced. I, you know, I you do not expect, you thought it's open source, so it's, it's crap, you know, like, uh, but it's, that's not true because when you write open source, you code is visible. So other people will look at this and they will propose changes.
Yeah, you could do this better here, or this is not good, you know, change it. Which initially it might be a bit intimidating because, oh, you know, my code is not good, but the only way to learn is to, you know, uh, work with others that are better than you and they will help you improve. I think it's good to get feedback on your work.
Yeah, definitely. Yeah. Um, some, sometimes feedback can be brutal.
Like, uh, oh, that's a stupid idea, you know, but, uh, you shouldn't feel, uh, offended because someone is, uh, discussing this piece of code doesn't discuss you as a person. So this piece of code is fixing not you. Right.
Some people take it personally and they retract, oh, you know, that's too harsh. But that's not the case really. You Have, yeah, it can be hard sometimes.
Yeah. Are you give me a talk here. I'm, I'm done, I'm done now.
And we gonna talk. So I had two talks. One talk was about, uh, developers and how they can, uh, get better.
And, and the ideal thing is for me, if, if you have found out your passion in technology or pretty much anything you do, how you get there. Um, and my advice is based on observing some very successful people in my team and how they did this. So my talk tries to convey practical advice on how they did it and how this could work for you.
What is some of this advice? Um, so very short is like, not what you like and go into it, like that's the superstar version. But things that could help would be to, um, be creative and experiment with things in order to find what might interest you.
Um, get closer to communities that do this sort of stuff. Um, and there's, there's a lot. There are many communities now.
Um, so go there, try something, get to know the people, introduce yourself, um, and just do more of it. You have to do more and more and more. So you need to find every possible excuse that will let you do the thing you like, either in a company setting or a, on a educational setting.
Like get the projects on the thing you like so that you spend time on it, um, and do more and more of it. Uh, at some point, you know, you might be lucky and, you know, someone gives you an offer, oh yeah, come and do this for me. Like, for for work or something.
How does this relate to you personally? Are you doing something you like right now? Yes.
Um, this, uh, QO project that we started like from scratch, um, it really redefines, uh, the things you could do with Java because if you remember, Java was great to write, to write servers and big systems, but then the cloud came and people started switching to the other, other languages that were like smaller nimbler. So what we did with this project was to make Java sexy again for the cloud, and very attractive also for developers, uh, to, we, we call it a developer joy. So you just, uh, fire up your id, you, you start qo and then QO will do the right thing for you.
You just keep coding, coding and, you know, make it fun. So Cocus Connects Java and the cloud? Yes, pretty much.
Yeah, exactly. Uh, how long have you been working on Corcus? Uh, five years now.
Yeah. And before that, there was another open source project, like, uh, the JBoss application server that really redefined this, uh, space. Um, it was the first, let's say open source server that really broke through.
And, uh, we competed with the likes of Oracle, i, BM, uh, what else? Web, web WebSphere, web Logic. Um, and we were acquired by Red Hat.
So that was a big, um, like it was a big thing at the time. And big part of that team is related or has transitioned into this, uh, newer project. So I know those people, like for a long time, you know, we, we had fun together and we, we keep having fun doing, uh, what we like basically.
Do you have a strong passion for Java since you're working on Corus? Yeah, I think Java is still like a very interesting language to start. I know young developers will do like a Python and JavaScript, uh, which is fine for some type of projects.
I think Python is great to like experiment and do something quickly, but if you have to build a system that is mission critical or you know, it has to do with money or you know, air, you know, or some other critical aspects, I, I don't think you can do the Python. I think Java is still king. And by keep evolving Java, we make it very relevant, not just recently we are adding capability to let you do AI stuff.
So I think Python is king that in this domain, but I think we're cutting up. So Java developers can do like AI stuff now easily with Java. Do you have any words to get young developers excited about joining open source projects?
Yeah, well, um, they can build up a career either around open source or just technology. So if you go to give an interview now, quite often you just send a link to your GitHub. So we're going to your GitHub and check what have you done.
Like, so it's, it's a very strong, um, element to say, oh, I've contributed to this project. It's a complex project. So that automatically means you know, how to navigate the complete co project, you know, how to work with people, you know, to use the latest tooling.
Uh, it's like your, your CV basically now, and, and for me, normally that's enough. I, in many cases, you, I, let's say someone finish like a degree, great, it's an achieve man, but that doesn't show like if you know how to do the work. So your GitHub is more appropriate in this regard.
So, So your gito page really shows what you've done. Yeah. Like, like that's your resume, your pro, the pro.
I want to know the project you've, you've done. I want to know what the made you excited about those projects, who you work with, what was your role, um, what you wanna do next, what your plans are. So with that, so I can kind of sense if you're the type right type of person to join, uh, my team, Look what's useful to know that your GitHub page is like a resume.
Yeah, we've had a really good chat today. Thank you. Thank you too.
That was great. Hey everyone, it's Alan Shimmel at Techstrong. Welcome to another edition of the last great Cloud transformation.
It's no longer just my data center or my data centers, it's no longer just my cloud infrastructure, maybe over at AWS right? Today I have data centers, I have multi-cloud presence, I have presence on the edge. My people do anything from anywhere at any time.
And we need, it's a whole new paradigm. First of all, I want to introduce you to Mike Hamilton. Mike is the CIO at CloudFlare.
Hey, Mike, welcome to the last great cloud transformation. Thanks so much for having me. It's great to be here today.
So Mike, CIO at CloudFlare, man, that's a job. That's a job. It's incredible.
That's gonna be one of the most complex networks in the world. Something like 21 or whatever percent it is of the internet actually passes through your network. How do you sleep at night?
Tell, tell, tell us. I mean, thankfully, thankfully for CloudFlare, this, this is in our DNA, this is what we get out of bed in the morning to do. I'm not alone.
If I was, if I was the, the key brains behind this, I think, uh, you know, I'd be really nervous all the time. But we have incredibly smart people from our C-suite all the way to every engineer that touches every line of code that's thinking about this all the time. And, and I would really say my favorite thing about the company, in fact is, is being clever.
And we're thinking about really what the next, the next way to approach this is like, how do we, how do we define not not just follow or, or address concerns that our customers have, but how do we create the next world? How do we create the next paradigm that really makes data secure and it really helps companies manage this global infrastructure. The world has changed so much.
I've had the good fortune. In fact, I started my career in public sector in 1998, approximately. And, and everything was on-prem back then.
Uh, and my career was all on-prem through about 2011. I was fortunate, in fact, to be one of the first people to adopt virtualization. I was a bare metal VMware guy back in like 2001, which at the time people thought I was a little bit crazy.
They're like, what do you mean you're running 10 servers on one server and you know, what, how would this even work? And I'm showing them VCR controls on servers, and they're like, what? Like, you can pause a server.
What does that even mean? You know? And then being able to move servers later was really cool.
I've had the good fortune of, of having a career that had that strong foundation around data centers and virtualization. But I, I got, you know, my mind was kind of blown getting into the world where companies were being started entirely on SaaS. You know, working in hypergrowth gave me a really good chance to say, in fact, when I, when I made that traditional my career, I went from a startup to MuleSoft.
And MuleSoft. Part of the appeal there was, they didn't have anything on-prem. They were like, everything was in the cloud.
All their business applications were not in the cloud. But that advantage was really interesting to me because I was, I was thinking, you know, from my career, I want to have a challenge that's greenfield. Like I've never had to do this before.
Nobody's had to do this before. How do I do it? Um, and to end up with my career now today at CloudFlare is kind of mind blowing for me.
Every day when I wake up, I'm like, wow, this is such an incredible company, such an incredible time to be here, largely because we're starting to define how businesses run globally, and we're giving them a safe way to do that. So I, you know, I think the responsibility, we take that responsibility really seriously here. And again, while I, I'm glad it doesn't all rest on my shoulders.
We have a lot of smart people here, but, uh, if I were alone, I'd be way more stressed out than I am. We have a great team here. Good For you.
Hi, Mike. From, from a, uh, fellow now former C-I-O-I-I. I I'm with you there, brother.
I understand that role. You know, one of the great things about, wait a second, Mitchell, I haven't even introduced you yet. No.
You know, people know who I am. You don't have to introduce Ahead. I'm Mitch Ashley, I'm CTO at Techstrong and VP practice lead for, uh, DevOps and software application development.
Um, you know, as you, you get to consume the services that your company creates, right? As the network and, uh, you know, there's a lot of innovation happening in the network, programmability of the network developers, you know, moving apps into it as opposed to just edge to edge kind of connection, security, all the things that go into it today. Um, I'm just curious how, you know, you, you obviously have to kind of keep the trains running on time, but you're also looking at how do you take advantage of, you know, what the company's introducing and the customers might be using.
How, how do you, how do you, what's your strategy around that? Well, I do have someone that, that runs customer zero for me, uh, with, with my guidance and direction that that person just started about a month ago. But we are, we have been using our own product for a very long time, and it's, it's actually really natural because we have a business to run and so do our customers.
And so it, I've run, I've run customer zero programs in the past, and it's generally like I, I insist that we follow the exact same path that a customer follows. So it's like, we have an account, we have an admin panel, we file tickets with support. You know, we don't just run with someone's cube and try to find them.
Um, but then we do try to bump things and accelerate them. And it, what I think is most incredible, and what struck me the most about CloudFlare is how our technology can really meet our customers where they are. So we have all these different ways of on-ramping technologies.
Like you, you might say, Mike, I'm mostly on-prem right now, or I have some on-prem and some Amazon or some on-prem and some Google, you know, I'm not quite the multi-cloud yet, or I still have some Unix box sitting in a closet somewhere. Um, you know, and, and I want to get this into a zero trust network. And, and our product is designed to do that.
It's designed to make it easy to get your network connected. And so it meets our customers where they are instead of asking them to change everything or, you know, hodgepodge something together into some kind of weird Goldberg machine. Because I think the way the world has changed, the way that, you know, our, our, our employees are no longer at home.
They expect to be able to be all over the place. Our applications are no longer in one place. There was so much you could control back in the day of saying like, we run that application on that server and that data center.
I can look at the traffic flows and control performance and blah, blah, blah. You know, that was one thing. Now the applications, like why I'm in Salesforce's data center on the West coast and I'm in, you know, NetSuite's data center over here, and like the applications are really everywhere.
The users are everywhere. The world's totally changed. Uh, it's cool that to have a technology that meets our customers where they are, we understand that people have on-prem, we understand that they have cloud, we understand that they have SaaS applications, and, and so we're meeting them where we address it.
I get to do that internally. So my job is quite exciting, really. Um, and, and it's not that I don't go tap somebody on the shoulder, uh, that works on our product, but I do file a ticket first.
You know, where they live, I guess. Yeah, I do. I can still see it am like, let's just say I can nudge things to make the move.
Yeah, Absolutely. But calling To take, that's really nice email account you've got there. Shame, if something happened to it, would you fix my problem?
So, you know, when I look at cloud, what drives cloud transformation, what drives cloud transformation? So we get a lot of app modernization, driving cloud transformation, right? In, in the old days, we used to just lift and shift our stuff from a private data center up to the cloud.
That worked for all of six. It didn't even work for six months. We've quickly realized that that wasn't taking advantage of the cloud.
And ever since then, we've been on this quest of transformation by app modernization. We, we are gonna, you know, micro thread, multi-thread, our apps, uh, microservice our apps, cloud data, modernize our applications to take advantage of the cloud. And by and large, we're doing that a lot.
There's a lot of app modernization going on out there. But you know, just like in the book, the goal, which of course the Phoenix project is based on, right? We just, when you clear up one bottleneck, the next bottleneck shows itself.
So as we're modernizing applications now, we've run into network modernization. What we did before doesn't work in this new cloud native modernized application world, and we need to modernize our network. The connectivity cloud is, is one example.
But let's, you know, let's peel that onion back a few layers. Mike, what do we mean when we're talking network modernization like that? I, I love that you started with applications because I think it's a really interesting way to talk about abstraction.
If you think about, let's like rewind through my career for a second. Like the, the big thing about virtualization was that the network was fast enough to become a bus and that you could actually like, have memory and storage and compute being different places. Like memory, you were in one place, storage was in another place, and yet I could run an application that way.
But the abstraction in that case was just about the hardware. Like we're abstracting the hardware away to make it more flexible so that servers don't die as easily. You know?
And, and it was easier to modernize them that way. If you kind of fast forward, like now to the cloud era where we put things in Amazon, what a lot of companies discovered on that journey was, oh shoot, to your point on refactoring applications, um, this application's not designed for an availability zone structure. Like we want to do this cloud migration.
We did lift and shift and oh no, this node went down in availability zone, whatever. And like, we lost something. So that abstraction, you know, applications had to be refactored to take advantage of high availability scenarios in cloud environments, right?
So the abstraction layer had to change. Then the next phase of abstraction is serverless, where it's like, Hey, look, I don't, I just build the application at this point. I don't really need to think about, you know, the different three tier, like the database server, the API server, the web server.
Like that was the abstraction layer we'd built in that world. The networks undergone a similar thing. Um, but it's gone at a much slower rate because the innovation has had to come from the applications.
The thing that serves the user from like an intent perspective. If we think about applications as like intent engines, somebody wants to accomplish something and they use the application to accomplish something because the network was like the roads that they used to accomplish that. It was one of the later things to evolve.
Like that's why we're not seeing it evolve quite as fast, because it's also expensive. You know, on-prem networks are expensive, they're complicated, and people have a certain level of comfort with them as well. I know I did, like when I went from on-prem to full cloud, it was like, well, but I, I like my on-prem network.
I have the inside, I have the outside, I have the DMZ. These are definitions. I understand now my, my, uh, ERP applications on the cloud, you know, it's a, it's actually in someone else's data center, and I'm running it that way.
And then I have these custom applications that are still behind the firewall that I'm trying to move on the other side of the firewall. And so the dollars weren't going toward something with the network because it wasn't really the place the investment needed to go. The the key was like, how do I enable my users to accomplish things?
So the network started to come later. Now we live in this world where, where we have to think globally from like a performance perspective. And I'll, I'll give you an example of a challenge I faced in one of my roles where we had a big team in Argentina at this company, and they were like, man, Salesforce performance is really, really bad.
And, and this is back in the days when I'd actually have to call the telecom and be like, Hey, you know, what's the deal? What can I do about latency? You know, blah, blah, blah.
And like, they changed something in a routing table. I don't know why, you know, this was South America. Apparently you can change things routing tables in South America.
I don't know if that's a good idea. Really. Course got better and another application got worse, right?
And so that was the trade off. And I remember thinking to myself back then, like, man, I need a way to bypass this. Like, I, I need a way to, I need an abstraction layer of this.
I, I don't want to call the carriers if I'm having one application performance issue in some of the part of the world, I need more flexibility. But that flexibility would've been really expensive too. I would've had to buy pops in multiple carriers in multiple locations and do some kind of IP sec tunnel meshing to like make multiple pathways so that I can control the routing.
And like, that's a drag. It's expensive. It's hard to maintain.
That's not gonna work. This transformation world that we're in now with connectivity cloud and this idea of a connectivity cloud is exactly that abstraction layer. Why?
Like, it doesn't make sense for thousands of customers around the world, thousands of companies around the world that build their own IP SEC tunnels across different, you know, mesh networks and try to make this happen. SD WAN kind of proved that that wasn't a great idea, by the way. Like sdwan, I was Just gonna say, most people probably think Connect Cloud is put SD-WAN at the edge and you're good.
No, it's, no, It was actually pretty complicated. Yeah. SD-WAN tried to solve the problem exactly that way.
Multiple carriers, multiple sites and SV PN tunnels didn't exactly deliver what they were wanting. Instead, you started seeing companies pop up where they were saying like, Hey, we're maintaining a bunch of pops all over the world. You can connect to the closest pop and then we'll figure out how to make your traffic optimized.
But even that was a bit of a drag because you were still developing like IP sectors to these individual places. And so there's this extra layer of like, I'm encrypting the data through a tunnel and then it's gonna come back through this. And there's still checkpoints that, you know, so it's not the optimal thing.
Um, at CloudFlare we have technology that literally, uh, decides which path is the fastest on the fly based on circuit utilization. So compared to routing protocols in routing protocol world, you're, you're picking fastest path based on speed. You might find a faster path, for example, that's like one hop is faster than the other hop, but overall that that path is faster.
But BGP only optimizes for certain types of path optimization. In our world, we're looking at like, what's the saturation point of a particular link and should I send you this way versus this way based on the actual traffic dynamically in this moment for this packet? And that's, that's one of the things I think is really cool about our technology is this idea that like, I can make performance really what, like great for end users, the user experience is incredible, uh, based on current conditions, which is, which is amazing.
And I'm nerding out what all these telecom networking terms you mentioned, uh, zero trust before, you know that, that, that is a, a, a giant elephant E two, right? Two simple words. It sounds good, like a good idea, but implementing that strategy can be a handful.
H how is what you're doing with the connectivity cloud make that easier or at least the path to get there. I know it isn't all just the network, right? But love your thought.
I'd love to hear your thoughts on that. So it's, I'll like, let's, let's like reminisce for a sec About Hey, we're old. It's good with us square ahead.
Absolutely. Let's, Hey Alan, would you unplug the router? Yeah.
Good. Yeah, I liked it. He said BGVI.
I'll be honest with you, I got a little swell coming over my face. There we go. Yeah, let's like reminisce a little bit.
You know, back in the day when, you know, like one of the, one of my gigs, I I I, I had set up what I called like a, a wall of garden approach where if you were trying to get to the database VLAN n and the data center, you had to VPN in even if you're on the inside, right? Right. And so I had to sort of develop this approach.
The inside interface of the firewall had to allow v VP N connections and then only the DB database admin had, right? To get to the vlan. Like that was, that was a way that I secured it.
Uh, you know, I, I have had this concept of the outside of the inside and then differing, you know, microsegmentation of the data center in terms of how to secure the business and meet all of our compliance requirements. VPN was how we did that back then. But it was a pain because people had to log in twice.
I logged into my laptop and then I logged into the VPN. Um, and, and so there's like a two step process and the end user doesn't, they shouldn't have to care. They shouldn't have to think about it.
The best security is the security that just works and is already there. Like the natural, when the natural thing to do is the secure thing to do, we're winning. We know that then the people are gonna be most likely to follow the path to lose resistance.
They're gonna do the thing that works well for them. And, and let's, let's face it, let's not put any more steps in between them and what they're trying to accomplish, right? Like, we want them to be effective, we want them to, to work well.
So that's the design. So rewinding again, like in the old school world, we did that with IP sec, it was painful, it didn't work well. Uh, and, and people were frustrated, increased support costs.
It was, it was very hard to manage. Now let's wreck that whole paradigm too. We start moving applications out.
My application is not behind the firewall anymore. So the IP SEC is kind of a waste. In fact, the IP sales SEC tunnel made it worse because someone in Georgia is VPNing the San Francisco to get you an application in New York.
And now more applications are coming from different parts of the country. And that perform like, oh no, my Zoom call was terrible. Huh.
That's weird. While we routed all your Zoom traffic through the tunnel. Oh man.
Well that means that, like I added latency 'cause my Zoom traffic went all the way to one coast just to get to another coast. Or the first person to join that meet call was, was in Japan. And so the pop that Google spun up for that meet call was in Japan.
And like nobody's latency was good for that one. You know, all these different things are happening. Um, now let's talk about how we would secure that in the modern world.
So with every challenge that we've seen in terms of the evolution of the internet and applications and SaaS, we've created opportunities as well. If the old firewall was here's some IP addresses, uh, and I'm filtering based on IP addresses and blah and domains and blah, blah, blah, the new firewall is actually the person, the new firewall is who you are. What is the device you're on?
Where are you right now? Um, is your antivirus up to date? That's actually the new bit of information.
And being able to make contextual decisions around which applications are you allowed to get to right now based on the context. So like, I can now paint a picture with the zero trust world. I can paint the picture by having the Zero trust client on their laptop.
They, they're already authenticated to it, they don't know it's running. You can see the icon, but it's, it really seamlessly disappears in the background. But now I'm evaluating your ability to access applications based on what I know about the device you're on.
You're on a company device, but you're, um, you're in an airport in, you know, some other country, right? Like, well, maybe I don't give you access to certain tiles in the single sign-on profile because I don't want you to have that. You're in a place where you probably shouldn't use that, right?
Or I wanna make sure that you're following the best path. Um, the zero trust client can decide, for example, on the local machine that like, Hey, all Zoom traffic's just gonna get routed straight to Zoom. Like we, we don't need to route this through a tunnel because it's not gonna be any faster.
In the case of our global network with all the pops that we have, our, our zero trust client could decide that it's faster to go through the, through our connectivity cloud, right? So like the best, the best option wins the most performance options wins. But also the, the context of like, what security outcome am I trying to drive also wins like, hey, this, you know, this is sensitive data traffic, we're hitting our dashboard.
This needs to always go through the private network and never go through any kind of unsecured channel. So zero trust is a way of taking who someone is and the information about where they're right now and applying that to what kind of access that they need to have while also giving them performance enhancements. And by making the decision on the laptop or on the, the nearest edge, instead of like somewhere in a central firewall, the performance is naturally better.
Like you're making the decision fast, you're protecting the user more quickly. You've shifted it from that firewall from going back to headquarters to, you know, a basically intelligent app that knows what can take those rules, those policies, and also, you know, these costs routing and what's the best path there. But, but really that's the whole point of this is we shouldn't have to take anything back.
Yeah. To the central, to, to the land, to the, you know, to the big honk and box back there or whatever, Or VPN concentrator, Right? That's the whole point of having an edge and, and doing all that.
I mean, you know, we, we wanna be done with that. Um, here's a worry. I have though, Mike, and I'll ask you directly, I, there are only a handful of companies in the world I think that can provide this kind of solution, right?
CloudFlare being one of 'em is that it's a great barrier to entry if you're a shareholder, right? Um, but is, is that putting all our eggs in, in one basket kind of thing? Do we need, like how do we, do we need more modernization as part of that modernization to have a broader set of options?
Hard question. It is a hard question. And I think, let's reminisce again.
Okay. So, you know, back, going back to the days when people moved their workloads to Amazon, right? There's a lot of trust that had to go into that.
Yes. That that massive amount of trust and Amazon learned on the fly. Uh, I, I'll never forget the first time somebody pointed out Amazon EC2 to me, I spun up an instance and I did some network scanning on it and I was like, this is terrifying.
I could compromise this instance pretty fast because he spun up with a public IP address. He was completely unprotected when EC2 first launched. It was like, whoa, who is?
And so my boss had asked me back then, he was like, alright, so what do you think? And I was like, now is not the right time, but watch out. Like this is gonna be a big deal.
We had to trust these cloud providers over time. To like, get better at protecting things. But we still took the risk of siloing.
Like when you were in AWS's infrastructure, you're in their infrastructure. You use their terminology, you use the tools they give you. I mean, let's contrast that with a second before that, that that model, we, we, we all don't like, of like bringing everything into a VPN concentrator of your CEO, right?
Like if you be in office, why did people do that? Well, I, I probably bought some product that's sniffing traffic that can decrypt it and help me understand threat analysis or whatever the reason companies felt safe bringing all the traffic home was that like, I can inspect it. I can try to figure out if something weird's going on and I, and I can work with it that way.
But that didn't really work because the cost was performance. The cost was like, is anybody really looking at that intel? Um, how up to date is that Intel?
And, and, you know, in the security space, these type of threat products change constantly. Like the security landscape is constantly changing. So I don't think there was ever really much of an advantage to that IPSec model where you bring everything in into your house and you inspect all the traffic.
But then when we moved to Amazon, it was like, wait, where's my packet inspection? Like, how do I know what's going on? So I would say, first of all, to, to start to answer the question is like, we've been trusting other companies that have silos for years.
GCP has its own silo. Oracle Cloud has its own silo. You know, a a Azure has its own silo and they're incompatible silos.
Um, the only compatibility layer they have is the open standard of IPSec. They're like, we can talk over something that works anywhere else, but it really doesn't give us any advantages. So now zooming out for a second with companies that are providing this, this like glue that stitches all these different clouds together, and they're only being a handful of them.
It's no less risky than it ever was to make the first leap of migration. Um, but the performance has to be worth it. And so I think nobody wants to employ an army of network engineers to try to keep a thousands wide p sec tunnels online, um, to maintain this in-house and build some re goldberg approach, especially when the cost of doing this through provi through providers that are making this their core business is actually really, really low.
The trust factor is no, not much different than the old trust factor used to be like, I have to trust somebody or else I can't do a business. Um, but I I would say that because we bet the farm on this, this is what we do that makes us accountable. Yeah.
Like we are by nature accountable. And, and one of the things that I love about CloudFlare is how we are accountable in ways that are, that are responsible, like Project Galileo, where we give away services to, to people who can't defend themselves so that they get all the protection of our cloud without connectivity, cloud without having to pay for it to make sure that their voice isn't lost and that someone can't decide to take their voice out. Um, we take this job very seriously and I think it is about following, following the intent.
Like, you know, what, what, what do you do with this? Like, we, we really do believe in building a better internet. And uh, I think that's critical.
But to your point, there's only a handful of companies that are gonna be able to compete in this kind of space because the innovation is blazing fast. Uh, and, and really it's something you want to get onto. And I, and I thought that the, the title of this was really fascinat to me on the transformation bit.
Because usually in my world, when you talk about transformation, it's like business process transformation. You know, can I take some antiquated process and turn it into a digital process? But the network transformation's different because now it's more like treating Earth is is a global network instead of my location's on earth.
Yeah. As, as my individual networks. And I think that's where the, the paradigm shift's starting to come.
Agreed. Agreed. Look, the, you know, this is a, this is the complexity of, of the, of the technology that we use today.
As I mentioned in the beginning, right? Sprinkle a little AI and really complicate things. It's only going to continue to, to become more complex over time.
Li maybe we could simplify what an end user's use. You know, it's easy for them to use. But behind that curtain, man, it, it, it's complicated.
I, I wanted to talk a a little bit, and this is a topic we haven't brought up on the last great cloud transformation, which is, look, whether you use AWS or Google or Microsoft or Oracle or any combination thereof, really the more the merrier as far as we're concerned here in terms of the connectivity cloud, right? So there there is no, you know, so early on, you know, reminiscing early on, if you were AWS you were AWS, right? You were all in.
The only thing we can contemplate was a hybrid cloud where maybe I'd keep some of my stuff back in my own data center and some on the public cloud. But of course, in today's world, we've, we've realized that's probably not as realistic as I go to whichever public cloud is, right? For my particular, yeah.
For this particular use case. May have other use cases here, use cases there. And I do need something that kind of ides 'em, brings 'em together.
Um, you, you know, you've been in this from the get go. When did you realize that this multi-cloud, 'cause it was, I it, I'll be honest, it surprised me. I didn't see it coming.
When did you realize that multi-cloud was gonna become sort of the way, the dominant way, the preferred method? Probably I was thinking back to like 2012 when I worked for a, a VoIP startup and we were using, we were OnPrem and we were using a, um, Amazon to develop VoIP at the edge on their side for customers. Like how would VoIP work in a, a DS context?
And I was thinking like, man, this is a lot of eggs in one basket. Uh, and with, you know, Google's no slouch at cloud and they were talking about cloud, but it wasn't as mature yet. And Amazon had this incredible explosion of Legos, like, because let's face it, they took open source products and productized them as services, right?
Yep. So you just take sort of software productizing services, they're cranking out Legos as fast as you can. It's like all of a sudden the elastic search is a Lego that you can just run my SQL with.
Multi-site replication is something you can just run. Like they, they took the stack of the three tier web architecture and sort of made it a service, which is really interesting. And I was like, so initially I was worried about like, God, I hope somebody competes with them because it's, they're, they, they're really far ahead.
Their, their work with Netflix pushed their envelope really hard. Like they, I think Netflix was one of the biggest customers that pushed Amazon to the edge and to the limit and forcing 'em to rethink things. And I was watching Google come up and with less excitement, I was watching Azure come up and I was like, well, at least multi-cloud has to probably exist.
And I was thinking Azure adopters will probably be p people that feel safe with Microsoft, with, they have a lot of Microsoft applications and it will just naturally make sense for them. And then Google will be the, the other people that are like, just not just not Amazon or I need another cloud strategy, but like, I've been happy to see Google come up and really own it and make, you know, a great cloud product that has a lot more Legos and a lot more connectivity. They've got a good product going, Azure's doing a great job as well of making it easy for their customers to do business on the cloud and have options.
But we're seeing another move now back to colo and back to some on-prem things where companies are realizing that, you know what things, it's way cheaper for me to own the metal. It's way cheaper for me to run it myself, and I'm gonna move this workload. Part of my initial thing with, when I, when I go back for a second for like, oh my gosh, I hope there's competitors.
It's because I was like, man, this is a lot of eggs in one basket, and they can start to control our margins. So like, if I give Amazon too much business, they have too much control over my margins and I don't like that. But moving workloads is not trivial either.
And so my, my fear on multi-cloud early on was like, everybody will need a multi-cloud strategy, but it will be optimized towards maintaining leverage. I need to maintain leverage, and that leverage has to be material. I need to be able to act on it or else it's not really leverage, right?
All the while watching cloud providers try to compete with each other while also trying to escape commoditization, like commoditization, you know? Yeah. Instant are gonna go down.
Value added services are going to go up it. To think about it in a less technical context, I think about baby carrots, which now you're probably going like, what the hell, Mike? Where where are you going?
But seriously, you know, farmers growing carrots make very little money on carrots. If I sell them raw in the store, all a baby carrot is, is a big carrot that's been chopped into little pieces and skinned like that's a baby carrot. But that value added product actually goes for more money.
Cloud providers do the same thing. They take something like, Amazon's a master of this. Take an open source product, run it as a service charge way more than it costs you to run it value added service.
Like they're nailing it. But me as the buyer, I need some control. I need to be able to control my costs.
And so multi-cloud strategy is part of what I need to do that because I have to understand like the nuances between, you know, provider A and provider B and my applications and what those needs are. And so any multi-cloud strategy has to be centered around what am I trying to accomplish and what kind of continuity, business continuity do I need to maintain? So yeah, it's, it's a fascinating world that we live in, but the, the multi-cloud thing had to happen because in a world where there's only one player, they can, they, they ultimately wouldn't be giving people any kind of choice.
Like, it, it's too expensive to run with just one player. Like they really control the cost. And I, I already think it's really expensive, um, because people leave workloads running, for example, you know, always you're, you're you're trying to figure out like, why is it I call 'em zombies?
Like somebody leaves zombie workloads running. You're just like, man, the meter's running, like nobody's using this thing. Well, yeah, we rack it up to dollar To manage.
Yeah. Like I, I think multi-cloud is hard to manage too, but it's also inevitable. We have to distribute our risk.
We have to distribute our workloads and make sure we maintain leverage and negotiations. So multi-cloud was natural, but it took a long time to get here. 'cause keep in mind, I was thinking about this at 2012, and like you really couldn't have a true multi-cloud strategy in 2012.
Even today, it's pretty hard to have one because workloads aren't exactly portable. Like there's some, there's some changes in that world, but they're not portable yet. No, I I I'm sorry.
Go ahead, Mitch. So many Of us is, I was just gonna say, so many of us have kind of backed into it right through m and a activities. Yeah.
You know, we're this cloud, now There's a lot of cloud And you had, you know, what do you do to try to make sense of it just to operate it effectively, more or less, get to a point where that's part of your go forward strategy and what workloads can you distribute across those or move across those clouds? Not, not a simple question. I, to me it's more, you know, a thing I learned as I was growing up and, and gotten older was it's not the man, it's the tool and it's the right tool for the job.
I think for particular jobs, there are cloud providers as well as other options, right? My own colo or what have you, my own data center that are the right tool for the job. And I think the job of today's CIOs and, and architects is to figure out what's the right tool for this job?
What's the right domicile for this job? How do I use the connectivity cloud to glue that all together and make it look and appear and act as one contiguous infrastructure, but still use the right tool for the job? And I, I, I think that's what does it, And it, and it kind of goes back to the, to sort of ideal state of what a security tool would do, which is like, well, I'll please allow me to maintain a policy and a posture consistently, right?
It's security cloud is about that. Like, we have the same players, we have users, we have services, we have servers, we have applications, we have all these different things, but like, allow the policies to be uniformly applied and allow me to prove that I know what's going on. Agreed.
Agreed. Guys, this has been a tremendous conversation. I, you know, we went far off, we started with better connectivity and security through network modernization, and we discussed a lot of that, but we dis, we reminisced a lot, as Mike would say.
And, uh, we, it was good doing that. I look forward to continuing this line of conversation in future episodes of the last great tr last great cloud transformation, Mitchell, I think our next one is a live round table, isn't it? I believe so.
Yep. Yeah, we, we just definitely have one coming up. So if You're watching this at home, check it out.
Make sure you register for the next live one, because I'm sure you've got questions. I can't promise Mike's gonna be there. He's, he's got a bit of a job to do when he's not doing this.
But if you've got questions around the things we're talking about today, we invite you to participate in there. Many thanks Mike to you and CloudFlare for, for participating and co-producing this with us. It's, these are the kinds of conversations that people like us enjoy.
We could talk all day about. Right. Good stuff.
I Really flew by. I'm happy to join you anytime, but I had a great time talking to you today. Absolutely.
Well, we'll make sure we'll get you back here. Get well, don't you worry. Um, Mitch, I didn't get a chance to introduce you, you jumped right in, but why don't you take the last word out then?
You know, I, I, I loved, I loved the walk back, you know, looking at kind of how we got to where we are, right? 'cause that informs where we go forward and there's so much, what, what's really changed is you said it, Mike, going from points on the earth to the earth is my cloud, right? That's my location.
And thinking about, you know, don't use your points of presence that you know about as your limitation. Just like, don't use your, you know, hauling traffic back to the VP n concentrator or the center of the network, either. That's, it's a different paradigm.
It's a distributed processing network. And, uh, there's a lot more things we could do with it. So it's, it's an exciting future.
We appreciate you, Mike, sharing your, your experience with it as well. All righty, all on behalf of Techstrong and CloudFlare, thanks for joining us today. We'll be back with another show soon.
Until then, everyone, good luck. Take care. Hi everyone.
My name is Junar Wood, and today I'm gonna talk a little bit about improving DevOps workflows using generative AI and GitHub co-pilot. And a little bit about me. I am the AI impact lead at GFT Technologies.
I am the 18 years Microsoft MVP, the first Brazilian GitHub star. I'm four years in this program, but it's a personal honor to me to be, uh, the first one in Brazil to be part of this team. And I'm speaking in technical conference like that.
Um, YouTuber about technical contents like the pops career, uh, productivity and other contents like that. Here is my YouTube channel, my linkage profile and my mail, um, if necessary. Okay.
And we are gonna talk about NAA on DevOps workflows. And I think the best important point is talking up shortly, uh, about what is, uh, generative AI because, well, it's surround everything about STEAM and about software development lifecycle, uh, in next years. And basically, uh, general TV AI is a kind of AI that, um, using algorithms to create, uh, a, a new contents like a texts like, uh, images, like a videos.
And in our case, create a source code, create documentations, and, uh, support us in a lot of tasks, uh, in the software development life cycle. And this tool is general called, it is called generat, VI because well, it's a little bit obviously because this generate a new content based on training data on historical data. And this AI can be understanding your request to generate a new content based, uh, in, uh, uh, what you are needed here and, and to, to work with the gene.
A tools, uh, important technique. Technique was born the prompt engineering technique or the prompt engineering. Uh, it's a new FO position in, in some projects right now.
And what is, is this in general? Uh, the prompt engineering is the art of crafting effective instructions to get the best response from AI models. And why I'm talking about the art 'cause it's not properly exact science because, um, we cannot have, for example, the same answer, for the same question.
And, uh, we have no specific rule to create a a, a good prompt, for example, if I request this specific question will be received, this specific answer. It's not, um, a really true information in general. We need to, to work as a artist to understanding what works, what not, and create a best prompt or best approach a fight tonnage prompt to support your creation.
And it's not only for creating images or videos to create texts, to create SARS codes, documentations, all of them follow the, the same instructions and the prompting properly. Basically, it's a, uh, a piece of information, a collection of information that you can provide to generative AI to, to generate a content base on your request. And, uh, on and in your AI training data, the generative ai, use the both of them to generate a best answer for you.
And you need to understand here, we you need to create a detailed prompt or with a more contest as possible to create a best answer. Basically, if, uh, good things, uh, in, in the prompt, good things will be answered. If you provide no good information in the prompt, probably your answer will not be good too.
Okay. And here, for example, I have two requests that I did on GitHub copilots with basically the semipro in, in this, uh, it's essentially the same prompt, basically, uh, is that I'm building an application to display electric vehicle data, gimme some options for how to instruct structure GIS app. In the first one, I have no many details.
Uh, I'm directly on on that I need, and okay, GitHub co polish answer to me. And it's, this answer is okay, it's good answer, but it's not specific for what I really need. In the second one, I provided more information.
For example, I specified data using express and type script or time, large scale application. Uh, I need to use a key lock tot cage. My front change will be use type script and will be deployed on Azure Kubernetes.
Using all of this information in the prompt, the GitHub copilot can be provided to me. Um, a a more specific answer, a more useful answer to me. Uh, I not pasted here all print, but, uh, here you can see the difference about the answer.
In the first one I received, I received the options. In the second I received the red, the structure following my request. Uh, in the other parts of this answer, I received a piece of codes for, uh, docker container for scripts, bernet services, uh, to scripts for GitHub actions.
I received more, uh, specific information for my request, basically, as I mentioned, good thinking, good things out, okay. And, uh, how this prompt works on GitHub copilot, but not only on copilot, but in general, the other tools that use in generative AI works, uh, uh, the same model. Okay?
Basically, you, uh, as user will be request something, for example, in case create a web server in TypeScript. And this information we've sent for, for GitHub copilot, what happened here in, in the backend, the GitHub will be include assistant tag here. And the system tag basically is, um, the chat bot or assistant, uh, rule settings.
And for example, this, the GitHub are including you are a friendly code assistant and probably, uh, probably the content, the most content here is, uh, something like that. You'll be answer only question about source code. You are not creating vulnerabilities on the code or you are not able to answer question about politics.
Uh, all of them on system information will be create a set of rules that this, uh, this tool need to follow. Okay? And the user will be, uh, attached your request and it'll be sent for LLM model in this case for GPT-4, GPT-4 O or other model.
But you can use AWS models or other LLM models. It's not, don't care. And your answer will be processed by, uh, OpenAI or LLM and include here a new tag for assistant tag with the answer and is answer will be considered the training data, the assistant tag, the user requests to create a, a, a good assistant message, okay?
And copilot or the other, uh, gene eight tool returns for you, uh, piece of code or the answer that you request. Okay? Okay.
But probably thinking, uh, why you need to use, uh, JAA tools on, on DevOps workflow on the ops process. And important thing to remember here is it, it's, uh, a point that some people forgot, forget, because, uh, the DevOps is not only about C and CD automations, it's not about, uh, building deployed application on cloud environments or in, in other place. The DevOps is general about think entire software development lifecycle.
Uh, it's about all people on this process, uh, since the ideation, the code creation, uh, the testing, QA infrastructure things, monitoring process, all of them, uh, are, is a part of the software development life cycle and DevOps process. And, okay, to me it's important for now in, in this specific talk, four core items, focusing specifically on the developers, uh, to increase, uh, to use gener, generat tools in a DevOps, uh, workflows. These key tools are enhance the developer experience, increase the product, GMG, increase the learning and focus, uh, on the business.
And why this for us, most important in my opinion, well, when I started to work, uh, in a software development a lot of years ago, I don't remember the correct year, uh, one of the first lessons that I learned from my first boss was that the user experience is the most important part of, of the software development. Because if the user don't like your application, the application will be not use it. And his job at is it's a trash, basically that, and he has, its properly, it's really true.
Uh, it's important, but we forget an important part of this process. Okay? Now more people are talking a little bit more about that, is that the developer experience?
But it's not com very common yet. And it's a important part of the software development because if the dev have a good experience in your environment, in your software creation process, the software, the the find off the job will be good too. If the developer have a good tools, uh, a good environment, a good support, uh, to this job will be better and to a, a tool can be supporting this can be improved in this process.
Uh, a a is not focused to solve our points is not, uh, a bullet point, sorry, it's not a bullet point to, to solve our problems, but it's an important thing to improve the, solve the developer experience, uh, in, in day by day. And in the same time, it can be incr in increase the developer's productivity because using gene tools like a GitHub copilot for example, uh, is not necessarily more for this developer, uh, make, uh, extensive researches on the internet about, uh, common tasks because these tools already generate suggestions focused on, on, on this task is if I need, for example, to create a switch case in Java, and I I not remember, uh, how can I do that? I don't need to go to the forums.
I don't need to go to the Google because these assistant I read suggest to me I need, you need to start to start the create comments and they will be, receive, uh, suggestions for this or using a GitHub copilot chat or other AI tool, like a chat, uh, chat experience to have, uh, an answer about that. It's increased the productivity a lot. And it is not only this, but using to automate documentation to support, uh, me to generate energy tasks and other parts of this process.
And it can increase my learning how using the same generate tools to supporting me to understanding other parts of this project or to understand what project does. In my imagine that you are starting in a new project and you have no information about that you can use generate tools to generate documentations, to generate explanations, to generate, um, conversational documentations, to support you to understanding easier what the application does and how can you, uh, support this development team faster. Okay?
And using all of this, we can focus on the really important part in the software development in the business, because we don't need to focus anymore in the common tasks or in documenting or create a simple pieces of code. We can focus on the more important part. We can focus in the really, uh, complex part of this process to understand the business rules, what you need to implement here into the detail to, to improve the application, to create a best applications.
Okay? And in, in, in general, how can this generate tools, improve the software development, uh, to DevOps workflows? We can create, uh, talk a lot about a lot of points, but I have here five main points that we can use because this point is the, is the top that I, I can, I'm seeing in the clients I'm seeing in my job recently, okay?
And can be increase our productivity, uh, a lot. The first one is the code creation. It's the most common using tools like a GitHub copilot because the GitHub copilot, as I mentioned before, providing you code suggestions, code snippets, uh, documentations, code explanations, uh, supporting a code corrections support you in a lot of tasks in the, in the code creation process.
Okay? The next one is the code review. Why?
I'm talking about code review, because, uh, well, in general, it's, uh, very common or, uh, I, I, I guess it's essentially 'cause all developers need to create a merger request or a requests before merge the source code. And in general, in theory, uh, the developers need to describe their change to support the approval chain to understanding if change, make sense or have a problems. And in general, to developers only describe merge main or merging feature, blah, blah, blah.
Uh, and it's not a you information and the approval need to go to the source codes, rely by line what code does, if it makes sense or not. It's a boring process, it's a boring job to do. And using generative va, we can use these tools to understand the change and provide a useful, uh, description for this board.
Request description, file by file recommendations, uh, vulnerability explanations. And I need to go only to the source codes. If I seeing, uh, something wrong in the codes description or I need to call the developer to understand this change.
Only if I, uh, I seen something wrong in the codes description. It's a, a, a good point to pro productive gain. The next one is the documentation.
The idea here is documenting your source code, because we know that we have in general two scenarios, one or the second. The first one is, I don't have documentation because no one do this in the past. And the second one is, yes, I have documentation, but it's a very, very outdated documentation because someone create this in the first year of the project and no one updated this anymore.
And it's a problem because in both cases, I have no documentations. And we can use generative VA tools to create in this. And you can automate in this process, uh, in a different parts of your software development life cycle.
You can use, uh, the IDE from developers to create this documentation. You can include this documentation process in a request, for example, you can have a scheduled pro, uh, process to create this documentation. And in the future, you can put this in a conversational chatbot to, to, to do more, easier to interact with with your documentation pro process and maintain this alive easier.
The next one is the test generation. And here we can pause is possible to create unique tests, uh, using generat gva following company standards, following, uh, company frameworks and a lot of other important rules. And we can create here too, uh, functional testing, uh, and, uh, a testing of interface using natural language.
Uh, we don't need to create anymore, uh, HEML mappings as CSS mapping fields, we can use natural languages to, uh, create in this testing process. IT and all of them use in general, TVA a, uh, turning this job more easier. The next one is the code correction, because we know today we have a lot of vulnerability in the code, and we already use SaaS tools to, to generate a report for us about this.
And sonar fortify, other, other secur tools provide us information. And you can, we can use generative VA to use this information to generate a correction for our codes and correct vulnerabilities, issues, codes, mouse bugs, and, and much more. And in next we can do much more than that.
These five points, uh, are the most common that I'm seeing here, uh, most used that I'm seeing here today. But we can do this, for example, uh, a creation of your backlog using generat, TVA using, uh, describing the use case for a tool to create your app. Because your features, your user stories and tasks, for example, uh, you can use this to do a reverse engineering into source code to support a legacy modernization.
You can use this in a lot of different parts of your software development lifecycle to increase your productivity. Okay? And day by day, uh, uh, uh, new tools are born to support us in, in, in these parts.
Okay? Uh, what tools I'm using at this moment, the first one is the most common GitHub copilot. 'cause this tool is a very interesting, amazing tool that support developers in, uh, DA lot of different tasks.
The most common is using on my IDE to generate code suggestions to me, to generate, to me, uh, code corrections, to generate to me, how can I create testing and other important implementations in general using this two, uh, to improve my implementations, for example. And the next one is GFTI. Impact is that tool, uh, interesting tool folks.
IT to support RO software development lifecycle using genea and this folks productive again. And we have here features like cloud creation, star creation, documentation projects, um, test creation code, reviewing code correction, code fixing testing, uh, legacy modernization. We have a different set of tools to use engineer to improve, uh, the productive.
Okay? And I like to to to run a, a, a demo for you, a ADE two demos that I have here using TGA tools to understand how can you, you using this in, in your days? Okay?
The first one, I, it's a more simple I'm using directly on my id. Basically I'm start imagine that you are starting a new project, that you have no information and you need to solve your vulnerability reported by a SaaS tools, document the codes and create I tests. Basically, I received this information as owner print screen informing me that I have SQL injection in my class, user Java.
What I need to do here, well, opening my ID here, I have this project, it's a, a already open project in, in the class I can use here my GitHub copilot, for example, asking this, explain me the coach and show me a bullet list with of vulnerabilities to support me to understand if I have more vulnerabilities than, uh, I the report. And here I read, received a lot of, uh, information. You can see here, explanation of this code, what code does the fields that I have, structure methods, and here the vulnerabilities, the SQI injection sensitive data expo exposure, improper exception.
Basically a lot of, uh, vulnerabilities here. What they can do here, I can request for GitHub copilot to correct only they ask of injection or correct the others. And I request here correct all vulnerabilities on the codes.
And here the GitHub code PAL will be understanding this and create to me a new version of the SARS code with, uh, the vulnerability corrections here. And a short summary of this change. I can copy this page, this here.
And I have here a new version of the SARS code. And okay, now I need to do a next task documenting this code. I can open here, explore right click on the user and create a documentation.
Basically here I need to create a problem that I'm using the language of this application and tell them that I plan to use, and I'm using the GFTI impact here to generate a documentation in the company standards. And we need to personalize this base, uh, on, on what the company needs to, to explain the code. And here, basically, uh, is the generated the documentation.
We can open this in a markdown preview. And here we can see overview, process flow, insights, and data manipulation to generate tests basically is the same. You can create here.
Uh, you need tests, select a prompt for works, the language, LLM, and we can, uh, include this on existing files if necessary. For example, if I'm creating a test for existing projects and have I need tests, we can, uh, add more testing for this or improving the test or correcting the test. Or if I don't have tests yet, I can create a new unit test for this project.
Okay? And here, basically I have this new, uh, test class and I can commit this file and follow my DevOps process. Okay?
And for the next demo, the process will be the same, but I will be create this directly on my GitHub, following my, uh, DevOps pipeline. I'll be update the code using GitHub called pilot on web, create a pull request document, create a test, and review this peer request. Basically, I will be use, uh, i in the same repository.
It's the same vulnerable project to repository. I will B click, click here on the co-pilot section, and I will be describe a task and I be request solve SQL injection on user J and I will be start this task. Basically the GitHub copilot will be understanding my source code, my vulnerabilities, and will be propose a solution to correct this code.
And I can here generate a plan. GitHub copilot will be understanding the class and the steps and click, I can click here to implement this files properly. And copilot will regenerate a correction for us.
It's, uh, a very quick process and here we can see the old version. The new version includes correction, the SQL injection, the parallel corrections, and I will be create a new pull request here to implement this change and created. And I will be open my GitHub again.
And here I have now a pull request. What happens here in the beginning, uh, that time created APO request, a pipeline will be triggered by GitHub actions. And this pipeline will be trigger my GFTI impact to create, to me a documentation to create to me a unit test and change create.
To me, a reviewing process is not a long process, but we can, uh, see here the pipeline running, uh, to monitoring this, it's creating the testing for us for now. After that, we'll be saving on the pull request. And after that, the document, uh, we'll be documenting this project.
And the interesting here is that we can guarantee that all the time that the developers create a new change, create a new request, we can maintain the documentation alive, and we can guarantee test that the unit test will be, uh, create automatically in your repository. For example, here, the test already created. And here I have a new comment for the unit tests, and I need to wait for the documentation PRO process.
It's a wiki process too. And, and, and all of them, as I mentioned, documentation as we can adapting this and creating a more specific scenario to generate for specific situations, we can create a specific documentation for COBO projects or for dotnet projects or for Java projects and following different standards for each one here, I think that the documentation now already generated two only waiting here, okay? I have the tests and documents generated.
And if I'm going here for the file changes, now I have first one, the user do Java. The file changed by, uh, GitHub copilots. And here I have the UserTest Java.
I already have tests on my project for this class and GFGA impact. She understood this and only updated this tests, creating more tests if necessary, correcting tests or removing tests that was not necessary anymore. And in intent created here a documentation.
I didn't have documentation before. And for now, it create a new version. But in the next request, it'll be create only, uh, an applicated version of this documentation.
It's in mark now file, and you can save in your repository or integrate in another tool that you are prefer to use. And let me go back here. And now in the pro request, we have the code reviewer.
And it's an interesting point because it's provide for us information about the developer chains. It's provide to me a description. It provides to me a summary explaining file by file, what per request does not only for the poor requests, uh, for the file chain, my GitHub co-pilots or the developer, but the, the for the files created by, uh, GFCI impacted tools.
And here we have document, uh, recommendations for this poor request and vulnerabilities explanation. And I can see here now, for example, that I have other vulnerabilities that I need to solve and I can make a decision with. I will be approved this or request to developer correct this solve other poor requests bundle.
Okay? Okay. I think that my time is now, uh, is finished it, and here is my contacts.
You can see here my linkage in profile, my U YouTube link again and my mail address if you like to talk with me. And I think it's now for today. Thank you for watching my talk, my talk today.
Hey everyone, happy Friday, it's Super Bowl Sunday this weekend. We're gonna kick our Super Bowl ads off right now by Shimmy coin, the newest crypto you're watching. Textron Gang.
Hey everyone. Alan Schmo here for Techstar Gang. It's a great Friday, it's Super Bowl weekend.
You hear the sound of those cash registers, Jing Gang, that's people paying $8 million for a 32nd commercial. We're gonna talk about that. We're gonna talk about the US going in off the gold standard to Bitcoin and blockchain and who knows what else.
Um, and another crypto story too, outta Security Boulevard, all that and more. But let me first introduce you to our gang lineup for today. We've got some great people to talk about it.
Let's start off out west in Silicon Valley where we have our, well, she's a radio host, a TV host, a marketing guru, everything else. Our Lisa Martin. Hey Lisa, welcome.
Hey, shimmy, great to see you. I want some shimmy coin. Some shimmy coin.
Well, look, there's something, there's golden in them there hills. Um, but Lisa, it's great to have you. As I think I wrote on one of the LinkedIn posts you put up, whoever thought you would be happy being a gang member.
I'm I, I lead Textron gang colors. I do. Well, I get you.
I get it. Um, but if we're, if we're out West Oak, the, the head gang dude out there, the gang chief in for Silicon Valley is our own editor, John Swartz. John, welcome.
How are you doing today? I'm good. Hey, I just wanted to mention something.
We have breaking news that there's a, uh, the federal lawmakers just introduced a bill that would banned the use of deep seek from all US government devices. So I wanna get that out there because this Is huge. What, what kind of federal lawmaker, Uh, two representatives from Congress.
Oh, don't count. If it's not an executive order, it doesn't mean anything. I, no.
Oh, we're gonna go down that path. Okay. But, um, yeah, sure.
Uh, yeah. He'll, he'll, he'll decide what he wants to do. But, um, uh, it's, it's really interesting.
This is a, a ban that's has started the ban was in Italy, Ireland, Australia, US Navy. Well, We could talk about it if you want, but I think in those countries, the ban is against government agencies and, and employees using deep seek. I don't think it bans it from private use.
And I Oh yeah, No, here, here's, it's gonna be all Government. Oh, it's also only government. Well, I'm glad to see they're not stopping on the right to individual.
Yes. It's, it's within the government, not, no, it doesn't apply to the, the rest of us for now, but it's very significant. Yes.
For now. Yeah. It's, it's just government owned devices.
That's it, Right. For now. Right.
Alright, for now, we'll see. Alright with that. But, but thanks for the breaking news, John.
Sure. Maybe we'll cover that by Monday. Maybe it'll percolate up to something.
Let's move now though, over to Colorado. He's home from his Vegas sojourn back in his guitar room. Uh, Futurum VP DevOps, Mitch Ashley.
Hey Mitch, how are you? I remember getting off the plane at, uh, at, uh, Harry Reed International Airport. I don't remember anything.
I just woke up this morning back in Colorado, so I guess it was a good trip. Enjoyed it. Sounds like it was Tiger In the bathroom.
Yeah, I did, did, I did get the blockchain set up for Shimmy coin, but I have bad news. com so you gotta go with something else, Alan. Sorry.
Oh, I'll sue him. I'll sue him. There you go.
It'll be huge. All right. Um, Be great.
Moving on from Mitch, she's our editor for, uh, tech Strong ai as well as Gestalt our it, which we are working with our friends at Tech Field Day. And it's gonna be, or it is, it's not going to be. It is our infrastructure site.
We'll be talking about that more in the days and weeks to come. S Sona Soha. Soha.
Excuse me. Sona, how are you today? I'm good, thanks Alan.
Great to Have you. It's good to be here. All right.
So guys, let's jump right into it. As I mentioned, it's Super Bowl weekend, you know, and for many of us, me included, and I'm a crazy football fan, but for many of us, the commercials are the highlights of the game, right? There's always, I mean, you know, you get the Budweiser tear Jerker commercial is usually a good Chevy one.
Maybe it looks like we might have ai Super Bowl ads. Uh, this, this, um, year. Lisa, do you wanna kick it off for us?
Sure. Well, I think we all definitely expect fast food. The cars, you mentioned, beer and insurance, those are like kind of staples, but AI is expected to have a really strong presence this year.
And of course, I think that really underscores the, just what we expect to see globally in the years to come. Um, but the campaigns aren't just about buying airtime. I've seen a few, 'cause they always leak the commercials ahead of time, which I never understand, which a really funny one that Mountain Dew has, that's very clearly AI with seal, the Singer, pop, singer Seal.
Um, but what we're gonna see from Google, for example, and meta or opportunities for, for these companies to really kinda shape perception around ai, it's been challenging. We talk about that all the time. There's a lot of negativity out there.
But Google is doing something really cool. They're unveiling 50 different commercials in 50 different states, and they're profiling small businesses that are using AI to get more done. For example, they're gonna be highlighting tasks that Google's Gemini AI can help with, like scheduling and email communications and things like that.
Met is coming back to the Super Bowl for the first time since 2022. They have a couple of a-listers. They have a couple of the Chrises.
They've got, um, let's see, uh, I think Hemsworth and pr, Hemsworth and pr, that's right. They're gonna be promoting their RayBan sunglasses, their AI powered smart glasses that you could do a whole bunch of things with. I gotta get, I gotta order up here because I'm so curious to see it, but I, I like the idea of these companies coming in and sharing what AI can do for you, what's already doing for us to help shape that perception in a more positive light.
So that's what I'm looking forward to saying, um, commercial wise, AI related this year. Okay, I'm gonna be seriously disappointed if there isn't a Matthew McConaughey, you know, rolling whatever. He was rolling in his Lincoln condo.
He's Supposed to Have an Uber Eats talking voice, you know, chat GPT. We gotta have us one of them. All right.
All right. He's An as righty with Salesforce. Yeah.
I mean, he, he iconic do something with Salesforce, right? He's doing something with Uber Eats. I know that of Course he is about the NFL and food.
What are you eating, Jerry Rice. Exactly. Rice, You know what?
I wonder if there's gonna be, like, we would talk about this as the AI Super Bowl in terms of ads, if there's gonna be an aha moment or if it's a breakthrough for mainstream audience, because so many people hear things about ai, they have mixed feelings about it. And you know, the, you know what, what's really weird? 40 years ago, I can't think, perhaps the most iconic Super Bowl ad Rand that was Ridley Scott's Apple, 1984 ad for Macintosh.
Oh My gosh. How, how was that ad? I remember watching that ad.
I, 1984 won, be like 1984, bought one right then. Mm-hmm. Right.
It was, uh, yeah, it ran technically in 85. I think it was the Super Bowl between the Niners and the Dolphins out in Palo Alto. David was the Silicon Valley Super Bowl.
Oh my gosh. Yes, you remember that. Um, but, um, it wa it, I, I actually wonder though, if there's like a breakthrough moment.
I mean, we have deep seek in a weird way. Deepsea is actually bringing attention, whether it's good or bad to the field, you know, it's getting people interested into, in the market. So I wonder if these ads in a sense kind of build on that, or if it, if it's just another, you know, layer of hype that pushes us for another six months.
You know, last Thursday on my Shimmy says on YouTube, on, uh, not YouTube Live, excuse me, LinkedIn Live, it's gonna be on, you could watch it on YouTube shorts, though. I, this is what I discussed. Is AI living up to the hype?
Where is it really delivering? What can we expect to see? And, you know, certainly proof's in the pudding here with these Super Bowl commercials, but John, I'm reminded of another era, not the Apple commercial that kicked off the Mac, right?
That was amazing. com baby, right? I sold my, I built my first company on the internet, sold it in 97, the end of 97, and, um, 98, 99, 99.
com fever at a peak, right? And every so many friends of mine who were founders of companies were showing up back then. They were showing out, I think it was 7 million for a 62nd commercial.
Now it's 8 million for a 32nd commercial. But it was the same thing. com commercials of 99 and 2000, and how many of those companies spent really 20 million bucks on Super Bowl Adss and got not, you know, it was a joke.
It was a joke. Are we gonna look? Yeah, they had a lot of money to burn.
They had had tons of money to, to burn. There were so many Artists too that were throwing that, that's part of the, the Capitalism at Work, right? If you've got money, there's a place that'll soak it up.
And the Super Bowl's a great sponge. Are we gonna look back 20 years from now and laugh at, you know, some of these AI companies that tried so hard here to influence us for 30 seconds when we can't wait to go back and see the cheerleaders or what they took off the end zone, what they're wearing on the back of their helmets, who's singing what Anthem and, and everything else, right? Are we gonna try to make this Super Bowl the AI Super Bowl?
And that's, that's a good question. I, you know, we'll, we'll see how it plays out. You know, at least to me it's about crossing the chasm.
Are we still in the early adopter stage, which I, I think we are. Or I think so too. Is this the, the, the Rams horn blowing signaling, the onslaught, you know, across the river to the mainstream, or at least the early mainstream?
I, I think we are, oh, go ahead. So s sorry, I feel like this is a really good moment to, um, amplify the chat GPT effect. Um, so Super Bowl I zoo, you know, great place to, you know, break the kinda ad and make something mainstream.
So yes, I know, uh, $8 million for a 32nd spot is, sounds like exorbitant, but I feel like, uh, here is a, a good opening for, to push AI into mainstream in the public eye. Uh, even if it, the effect is brief or wherever, I feel like, uh, this is a good opportunity and companies are sort of, uh, grasping at that. So you'll know it's a massive audience.
Mainstream. I'm sorry, go ahead, Lisa. Oh, sorry Mitch.
I say, I think I saw last year that the audience was like 200 million. So yeah, so you've got this captive audience. People have known for decades about the commercials.
And if you don't care about the teams, um, go Eagles. Um, you, you know, the commercials are gonna be funny. There's gonna be something.
And a lot of people watch it for that. So they have this captive audience. I wonder, Sal, to your point, are we gonna see some of the other ones?
I mentioned Meta and Google, but are we gonna see like the open ais for example, or perplexity or Anthropic? Are they going to be doing ads and trying to get their names out there more? Everyone chat.
GPT is almost a household word. If it isn't by now, it is of course, here in Silicon Valley, but I'm curious to see, 'cause they, they've got the money and we know how much it costs to first 30 seconds, but are they going to have the opportunity to influence this capital audience? You're right.
I was thinking the same thing, Lisa. If open AI or Anthropic, one of the companies that are that, that are backed by Microsoft and Amazon, if we see something from them, which kind of sparks more of an interest, I think that's significant for now. It's what's Google Meta.
And I think even GoDaddy's doing a spot, um, they're, I mean, they're known for other things, and I, we, if we have a fresh voice or something new or invigorating, then you, then you kind of break through with more people. Well, you have kind of an another reaction if there's so much AI in all the commercials, how do you break through the AI in all the commercials, right? So there's that effect.
And it seems like there are iconic moments of, did you see that commercial where the young boy is doing that thing in front of the car is Darth Bader, and like, yeah, what, what product was it? I don't remember what it was, but it was Sure. Good.
Or you remember the Bud Wise or, or what, whatever, you know, whatever thing, a phrase that sticks out, right? So I, I'm, I'm wondering if we're gonna enter it, I don't know if it'll be this year, but I almost expect QR codes like, here, Here, download the phrase, download the prompt, and, uh, it'll load right into, you know, Gemini for you and tell you all about, about whatever kind of thing and get you engaged using ai. So Mitchell, that's, if I were Google or ai, what I would've gone is gone to the traditional advertisers and say, let's make your commercial with AI embedded, or have AI do it.
And then as the commercial run, have this commercial was created, produced by ai and then with the QR codes, that takes you to how, how they did it, you know, what was the prompt and, and all of that. And to show people, Hey, you think AI's not useful? Look what we did here.
That would be really cool. And you could probably pay less than the 8 million. Well, Maybe I'm living in the past, but, um, you wonder if maybe the big breakthrough moment isn't this year, but maybe it's when Apple does its big push with Apple intelligence or some sort of something involving AI where Apple kind of, they are so effective at advertising regardless of what they do.
I always wonder if they're the ones who really push it to the mainstream in a sup in a future Super Bowl Power. Steve Jobs, apple, John, Steve Jobs, apple. I know, I don't know.
You're right. If today's Apple is the king of innovation, even in advertising, let alone product, I think the adss are better than their products, to be honest with you. I mean, the last few years, that's the highlight with Cook.
He's just a, he's a caretaker, but that's another topic. Yeah. Yeah.
I I don't think we'll see any Deep Sea commercials. I don't think so. I I think you're right with That.
Yeah. And it's not because of an executive order either. Um, but yeah, they're not going to, but they're The new TikTok.
Yeah. To me, I think when they take over our screens, you know, just deep careful, careful. Um, but this is, you know, to me this is the be interesting to see if this is the crossing the chasm moment, right?
Because like, you know, Lisa and John, you guys are out in Silicon Valley, soda. Mitch and I, we live in a bubble. We're in the hinterland out here.
We don't get all, Hey, I told, I was telling Mike Ard the other day. No, come on. We talk about AI every day on here.
Go talk to people watching the Super Bowl in Kansas. Well, everyone in Kansas City's gonna watch Super Bowl, Wyoming because they sent their money into the referees. But, but you know, that Was yesterday, the episode.
Yeah. Right. Go to go to Iowa.
Go to Ohio. Right? Go to Kentucky.
And, you know, and I'm not saying they're backwards, mean. Yeah. We, we live in a bubble out here, I think.
But Lisa and I would agree with this. I mean, I mean, we're, we're surrounded by, everywhere I turn, I see a Tesla everywhere on the, on, on the roads. I see Lemos everywhere, driverless cars driving around.
Um, I hear people overhear people at coffee shops talking about AI or their investments. But I think that's an anomaly. I mean, we're, we're just, we're just like kind of caught up in who we are or what this is, or we, we have A lot monetization Tesla here too, though.
That's not the electric car of choice here. I, I think the Beamers have, well, there's probably more Teslas electric than Beamer's Electric here. But, um, Well, just like the billboards on the, on the freeway, it's seems you can't avoid it.
It's inescapable. You're driving a See. Yeah.
So I don't see's a Reminder Where you go maybe Nashville Air, but I don't, you know, that that's gonna be, to me, the interesting thing. Are there gonna be a lot of people, you know, Mr. And Mrs.
Mom, PA America, who see these commercials and saying, dang, what is this stuff? Right. I've never heard of this.
Andro. Who's that? Claude fella.
You know, also, uh, uh, Mitch sent me some really interesting thoughts. Yesterday. We were looking at Gemini two rollout, and there's just so many options that they're just coming out willy-nilly, one after another after another, which kind of builds into the confusion.
And I think folks out there, they, they have no idea what, what's happening. And, and these ads, they just need a foundational, uh, knowledge just to begin with about what the hell this means to Me. You know, I, I mentioned this, shimmy says I did last Thursday.
One of the things I, I said on there is, is AI still in search of its killer app? Right? Is there we have, we, 'cause I don't know if we've seen the killer app for AI yet.
You know, mark Cuban said something, I I said it last Thursday. He said, the first trillionaire, the first trillionaire probably won't come from like one of the richest people in the world. It's not gonna be Elon or Bezos or Zuckerberg.
It's gonna be the person who harnesses AI in a way we haven't thought of before. And it explodes. And that will make the world's first trillionaire AI and I, that's, that, That's that new applications of AI we haven't thought Of yet.
Yeah. Someone's gonna do That better. What we Already do.
And, and, and Mitchell to a point you were talking about yesterday about evolutionary versus revolutionary. It may not be necessarily revolutionary, it may be evolutionary, but it's gonna open the gates and, and that'll make your first trillionaire. And I'm wondering if, if not that I have a desire to be right.
I do. But I wonder if the super Boaz will confirm what I've said about the user experience with ai. Generative AI is broken.
The idea of everybody in the world is gonna be an expert of what have to become an expert at what LLM should I use when, what oh three versus oh one. Is that better for this task? Or that, you know, mom, pa and whoever else are not gonna be interested in that.
Matter of fact, I don't, I don't wanna Worry about that. If I'm writing code, I want it to know what, what else? But you shouldn't have to pick what model it it.
Yeah. But, but this, we shouldn't be in to prompt lm. Remember Mitchell, they used to run out like when Web two oh was the hot thing.
They were constantly updating, you know, how many r rs s formulas and standards and all of that stuff. Um, it's gonna be interesting, but it, it, you know, it'll make for a good Super Bowl, uh, or, or a good ad watching for the Super Bowl. I don't know how it'll affect the game, uh, you know, but someone might have a share an account with a friend who's a known gambler, as we were talking about, uh, last, last, uh, Thursday on this.
So just have your robots ready to bring you more beer, pizza, and chips, so you don't have to. That'll work. Track yourself from the commercials.
That'll work. All right, let's take a break here on Textron Gang. We're gonna come back and we're gonna talk about, you know, this is like a William Jennings Bryant question.
Should we move off the gold standard and, uh, moving over to a Bitcoin reserve? I don't know. You're watching Textron Gang.
Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching it, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, everyone. We're back here on Textron Gang.
You know, as I alluded to before the break, uh, seemed to, or there's a move afoot anyway, maybe the move, I don't think we were actually on the gold standard again since William Jennings Bryant in the election of 1896 or something like that. Um, but we are potentially moving to a Bitcoin reserve on the federal end of things. And oh, what could go wrong?
Uh, it seems, uh, the crypto czar who's also the cybersecurity czar, and that's an interesting combination. Anyway, uh, Sachs is, wants to have a potential Bitcoin reserve so that we have, uh, you know, we have reserves in case there's an all our crypto war. I have another theory and there's other stuff there.
Congress is moving on this. There's been, you know, this has created a whole tornado of excitement and buzz in the crypto world. Mitch, let's go to you on this.
To start, what do you think? Well, um, David Sachs, who is, uh, PayPal fame, right? He was one of the folks that, that, Uh, came mafia, PayPal Pal Mafia.
Yep. Uh, he, he's actually AI czar, I think, in addition to Crypto Czar. Ah, so yeah, he's kind of czar of everything, I guess in technology wise, let's face it.
He's Elon's friend. He's elan's part of the mafia, part of part of the group for sure. It's, it's the, what's interesting is, you know, just not to get too political here, but Trump has gone from crypto is dangerous.
I'm not sure about it. We should stay away from it to, you know, doing his own crypto coins and kind of, uh, pulling wealth out of a lot of his followers that as his crypto, uh, coin dropped after the election. But there's a lot of discussion crowding, creating wealth funds for the United States Sovereign funds, possibly creating more crypto, possibly, uh, creating something that I don't know about the dollar being based on it.
You know, for folks that don't, don't, don't know what that's all about. A long time ago, our dollar was backed by gold. It was backed by the gold in Fort Knox.
And, uh, you know, so you knew that the full faith, not of the government, but of our gold reserves were backing up the value of the dollar. Now it's not, it's full faith and, uh, and word of the government. So I, I think that's just, I don't, I can't imagine the markets are gonna be really all excited about, uh, moving onto a, a crypto, you know, standard for backing the dollar people in crypto.
Sure. I'm, I'm sure they would love it, but, um, I think it's just more of crypto entering its next phase of being sort of this tangential thing that other people are doing. And maybe people are getting rich on it.
And I see people, my friends on Facebook selling stuff that'll help you, you know, get rich quick to maybe becoming more of a mainstream, uh, type of currency. Uh, but we'll see. I, I can't imagine our government's gonna be building itself around crypto.
But then again, you know, I couldn't imagine Musk going in and see all, all the bills we pay either. So who knows? Yeah.
Yeah. That's interesting. Yeah.
So, so Trump, I guess when he was campaigning, pledged to be the crypto president and promote adoption of digital assets, which is quite a difference from the previous administration, I think, um, under Biden, the regulators were looking at crypto is, is a source of fraud and money laundering. And they're trying frack down on Well, didn't find In, did they? Uh, they, no, they, well, they sued, uh, coin Base pointed Other, there are people sitting in jail.
Yeah, they did. Yeah. And so they, they, they actively looked into it.
So of course, we're gonna expect the opposite again, without being too political about it. And I think now it's just, it's open game. So in a sense, it starts at the top.
And, um, it's, but the fact that Sachs is, as, as Mitch pointed out, the czar, not just crypto, but AI is very significant. And plus, with the work, with the work of Musk and their interest in this topic, I think they're just gonna plow this through and just push this as hard as possible and see how far they can take. Maybe that's how we'll fund, uh, rebuilding Gaza.
No, I, I, I heard Seas doing that one. That's, that's actually not, that's not an impossible, uh, of concept. That's, I I'm actually thinking they're, they, if they get it, if anybody from the White House watches this, it'll be an action item.
Yeah. It'll be announced this afternoon. So let Yeah.
Exactly. Go, don't even go there. Let me, let me play a new game here on Text and gang.
I'm going to give you Shimmy's top three outcomes, or, or, you know, potential things as a result of this. And you could tell me how likely you think they are. One potential story, crypto Czar Sacks says we should put a portion of our Bitcoin reserves into Trump coin, thereby enriching our sitting president by buying his crypto coin.
We don't care about conflicts here anymore. How, how likely do you think that is? If you're not conflicted, you're not interested.
Why, why should we start now? Number two, between the tariffs and everything else that we do, the rest of the world gets so pod at us that we go, the world goes off the dollar as the world currency of the, you know, the, the, the standard. And as a result, we damn well better have some Bitcoin in reserve.
'cause that might be the only thing saving us number three. Number three, I mean, you know, likely outcomes. What could go wrong here?
Um, we put a ton of money into our Bitcoin reserves, and the, something happens and the Bitcoin market washes out, and we double our $37 trillion debt because all of that money is now worthless. And Old man Potter is here. Right?
To, to move us all into Potterville. That's a very, that's very possible. Very possible.
I have a fourth one for you. Go ahead. Bitcoin moving to the Bitcoin standard or crypto standard back the dollar is highly successful.
And then someone in the Trump administration loses the private key to the bid. Oh, geez. Oh my God.
It's all possible. But, but It was just numbers. I didn't know what it was, But let me, you know, all of this crypto craziness is leaving, like it always does, right?
Mitch, you said there are people selling get rich quick schemes. You know, some Porsche Schnuck in Canada stole $65 million in crypto and some platform hacks. So on our Security Boulevard, if you're interested in that story, that's a lot of Bitcoin, that's a lot of money even in today's prices.
That's a lot of Bitcoin. So are we, you know, we've all, I think those of us in the tech world have kind of taken for granted that blockchain, which, you know, underlines all of Bitcoin's foundational stability and security that blockchain is what blockchain is. And of course, with Quantum and everything else, we don't know what it's gonna be with that.
But, you know, all of this crypto craziness, we're gonna have plenty of people, you know, trying to, trying to make out some money here, you know, the old fashioned way, stealing it. I don't Think you could have a lot of people withdrawing money outta the bank and putting it in their mattress who don't understand crypto. You know, like, what is going on?
You Know what, there's an argument to be made for those people. Mm-hmm. Right.
The same way in the Depression, people didn't trust banks. Mm-hmm. And that's why they kept it in their mattress, Invested in diamonds and gold and Sure.
Physical things. Sure. So, I mean, you know, it'll be, it remains to be seen if you couldn't tell.
I'm, it's funny, Ellen, it is funny. It was, when you mentioned William Jennings, Bryan, I think of like 1900 era and this almost weird fascination that Trump has with, with that era, whether it's McKinley or, or this, like, just kind of going back with tariffs and crypto, it all seems like part of, like this, this theme of, of, of a different type of America and different type of enrichments. Uh, I just, No, but you know, John, it's just something that I keep talking something there because it's a vision of an Imperial America, right?
This is when America was grabbing up the Philippines and Puerto Rico, and, you know, the Mexican American, not Mexican, the, uh, Spanish American war with all of that as war. Yeah. And, you know, it was an imperial era of, of the robber barons and imperial.
What's different today? We want Greenland, we want Canada, I want the Panama Canal back. I wanna make Gaza, Las Vegas or the Riviera, whatever, or, Or Havana back Cuba.
Yeah. Right? It's, it's a vision that is the mag.
And I'm not, I don't wanna make this political, but part of the mag is a return to an Imperial America, right? Where we don't care about minorities, and there's no such thing as climate change. I, I started thing Marco Rubio pulled out the G 20 meeting because those crazy people in South Africa, they just want to talk about DEI and climate change.
And we don't talk about that, but Yeah. And the difference now is that the, the, the application of, of technology in a weird way through the, the new oligarchs, who are the people who are from Silicon Valley, the billionaires from trillionaire companies, they're, they are now having that impact, like previously, other, other industries that dominated the world economy. So The trains and chipping and coal this area?
No, these may be the new Rockefellers. Vanderbilts, and yes, JP Morgan's, who knows. Anyway, let's take a break here on, on, uh, Textron Gang Wild was spreading all this good cheer around.
Come back and talk about something else you're watching. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of Security Bloggers Network. Welcome back to Techstrong Gang. Hey, there's a very interesting lawsuit that was filed in San Francisco Federal Court, uh, by an individual who claims that Amazon has been tracking and selling California resident sensitive movements and location versus, uh, via pri precise time stamped latitude and longitude, geolocations sounds like Big Brother to me.
And even 1984 that we talked about earlier. This, this lawsuit, um, further states that people in general have not agreed to allow Amazon to collect or sell their sensitive data. And there is no mechanism to opt out of Amazon's data collection practices.
So this is kind of playing into this idea that we, the citizens are the product and are fueling these data machines. And the, the more that we do this, the more that we are being monitored or being surveilled by them, especially companies with vast amounts of data like Google Meta and Amazon. And Lisa, I'm wondering what you think this lawsuit tells us or where you think it might lead to.
This is the exact reason why I don't have any of those devices. I just feel like I don't need anything else listening. But it never occurred to me that they would be, um, giving data away, like name, address, phone numbers, payment information, age IP address, but also, um, they may collect personal information relating to other people presenting at their residence.
That scares me. And that's a concern, especially because of CPRA in California. What's going on there?
It's definitely a message that, um, Amazon should, should combat, but what they were apparently doing was, um, uh, Amazon ads, SDK have been, uh, developers putting them into their mobile apps, getting all this information to advertisers that the user isn't aware of. If somebody's simply in their kitchen wanting to ask the little Pocky P thing, how many, you know, courts in a gallon, uh, they're not thinking about that. And it's actually scary that it's giving away so much information, not just listening to what you're saying, but it's really digging in according to the lawsuit, really personal information that it's sharing with all these advertisers to make your, I guess they would say, make your experience more hyper-personalized and relevant, which is what we want as consumers, but to what, at what price?
Well, it's also invading into our phones too, because apps, well, I think in this particular article, they talked about speed test. You, you, you enable location services so it knows what, where you are and what provider to best test, you know, the speed test with. But that also gives ads, Google ad, sorry, Amazon ads that are probably Google too, that are, that are running as part of that application.
You know, the ads in the app, uh, then have look, access to location information. That's part of what they're collecting. And that's, there's also just even on the iPhone, I don't know about Android, there is a frequently visited location setting in your settings, um, that will, it keeps track of, you know, you have a habit of going to this Starbucks and this, you know, uh, gro grocery store and you know, your home or whatever it is.
And so in those locations that you frequent and then can also personalize based on that as well. So it, there's a lot of data that is being collected about us that we give away. We say we're okay with 'cause it's, but it isn't specific broad, generalized collecting information about us.
Right. There's never been a better tracking Oh, sorry. So go ahead.
No, go ahead. Go ahead, Go ahead. I was just gonna say, there's never been a better tracking device for a human being than a smartphone because it's affixed to us, and we're constantly on it.
So if anyone has any interest in what we are, who we're, what we're doing, just, just, just follow this, the data on the smartphone. Oh, it seems to be following us everywhere. I don't know why it happens, but Yeah.
Yeah, absolutely. And it's inescapable nowadays. Uh, this reminds me of when you go to search something on Google and then it asks you your device location, so you would have to put it in, in order to filter your search.
So it's like, it's like a double-edged sword. Like Mitch, she said that, you know, it's required to high personalize the, uh, results for the customers, which is what we want. Uh, but at the same time, it also, like, I feel like if companies could, uh, find a way to really handle the data well and not really give away without the consent of the customers, that would be nice to begin with.
Uh, so yeah. Um, this is quite scary for me as well. If it is, oh, what the say it is.
I mean, I know when I get in my car in the morning, it, my Apple maps pops up and says, you know, go into the office with the address, and when I get in my car in the afternoon, it wants to take me home. So obviously it's tracking where I go at what time, but, but here's my point. Look, more power to this guy who filed the lawsuit.
I assume it's gonna be a class action at some point, not just a person. I believe so, but, but here's the key. I, and I wish I had polling for people watching this, but guys, didn't, we already think this is happening.
This is not new. This is not new. Right?
Right. You know, my wife and I, earlier this week, we're going to New York later in February. My wife said, you know, I looked at the weather, it's gonna be freezing up there.
It might snow. We don't really have any boots. And both of our phones immediately started showing boot, boot ads on the webs, on Amazon, on, on the web, on Google search, everything.
So it's happening, and it's a fact of digital life that this is what, what's going on. The question is, do we consent? Is it being done without our, our consent?
Consent so that the next time some Chinese company wakes up with a new ai, we say, oh, they took our information without our consent. No, everyone's been taking our information without our consent, and we don't seem to give a damn. That's the irony of this, is that on one hand we are, we're, we're up in arms about what deep seek and what it's doing with data.
I mean, understandably, is it good if it's being fair being, being relayed to China, but yet this is going on in our country all the time. Moment. And, and here's another thing, time.
There's a generational element to this. Yeah. I read an article in the Atlantic the other day about like, where did things go off the tracks in America between, you know, it was about the falling of the Tower of Babel and maybe building Babel back, whatever.
And, um, you know, and it's about social media. They, they, the author blamed social media because it, at some point around 2011, it crossed from like pure innocent, uh, Facebook. What was the predic, uh, sort of Facebook, the other one we used to use MySpace.
MySpace. MySpace, yeah. It was a great way to catch up with old friends.
But now social media becomes your, your digital gang, your digital tribe, right? Mm-hmm. You hang out with your tribe, and you, you do digital warfare against the other tribes.
And, you know, and it just breeds distrust in anyone who's not in your tribe. But, but, but the key, the key thing about it is it's so generational where I'm not saying you're old Mitchell or me, but we, we, we, you know, the idea of them collecting or invading our privacy, like without my permission, kind of p****s me off. Mm-hmm.
Well, it's, it's, it's the tendency of, uh, filling, filling the vacuum as far as you can fill it with what you're, you think you might be able to do versus what you're explicitly Allowed to do, right? Yeah. But younger people don't, aren't they assume, they assume that there's no right to pri Well, the Supreme Court said there was no right to privacy, right?
In the, in the, well, let's not go there. But the right to privacy in younger people is, is almost non-existent or much, much lower than maybe Mitch or I or John, right? Yeah, yeah.
Willingness to give it up. I, I think they've, I think they've entered into like this tacit agreement that there is a trade off, right? For the convenience Yes.
Sake of, so it's about convenience, right? Yes. So one had your life just easier, but you make compromises until you are affected at some way, maybe Id theft or whatever.
And then you become interested to the other extreme, then you become alarmed. And I think this is just a pattern that's been going on for decades, actually. But, but no, but back to this article, and I'll try to find the article, but it's probably behind a paywall on the Atlantic.
But the, the point he was making was in Facebook when it switched, when this whole thing switched on us and made us the monsters we are today is all of a sudden, for some reason, we became comfortable sharing intimate details of our life with strangers. It used to be, you know, if you were at the bar with your friends, your buddies, you could talk to your buddies. It was a small group.
I saw them. Um, the women were out doing whatever you do, also at a bar or at a dinner, you could talk to your girlfriends, right? So Salon Lisa, you had your, your girlfriends that you did intimate secrets with.
Well, but at some point, it, we crossed a chasm of sharing our intimate se secrets with all of our online touch points, which may, may be in the thousands. And some of us just put it on public anyway, not even caring who sees it, or friends of friends of friends of friends see it. And once you cross that chasm where you are just putting it out there, of course, what do you expect?
No one's going to use it. No one's gonna see it, no one's going do anything. So that, that was the switch that went off around 2011, according to this article that, you know, just really hyper accelerated the tribalism and the, the craziness, right?
And, and, and along with that is a lack of trust of what used to be trusted sources, such as the mainstream media, right? Because everyone in your tribe says, don't trust that. And let me show you some examples.
And they may have real examples or not, but who knows? And who cares, right? And it, it, it's a fascinating article.
And, and it, by the way, it's not a right or a left article. It another Yeah, No, it's, it, it can apply. It's interesting.
If you look at the, at the very far right and the very far left, you know what, the demographics are the same. They're white people who make a lot of money, and they're the loudest. 8% is far left, 6% is far right.
They're the loudest people online. That whole middle Facebook used to do. Yeah, Facebook used to do this.
Like she, Sandberg, I mean, we used to interview her a lot, and she would always talk about, if you really wanna be engaged with your audience and you really wanna build on that audience, you have to share more. The more you talk about yourself, the more you share in general, the better the product is. Then you're, you benefit, you benefit from all the likes, and you know, like this addictive Behavior.
Well, we can fine tune our algorithms, right? To give you what you want, right? Yes.
Well, this is to personalize it. This is the result. I, it, it's gonna be interesting.
As I said, the courts, the courts have been whittling away a right to privacy for some time, right? Including Roe, overturning Roe. And so it's gonna be in, well, San Francisco federal court's probably a little more liberal than most, but it's gonna be interesting to see, do we in fact have a right to privacy to our digital footprint?
And that has all kinds of implications. That's the, uh, GDPR to bring up regulation. It doesn't even necessarily protect us with this or provide productions with this, because it does mention location information, but only as far as a gateway to figuring out other things about you.
I Don't think you can say this is P ii. No. Well, I, I, I think you could.
The, the fact that I go to a certain store every Monday and Tuesday, I think that's personal Information. Well, yeah. Things that can lead to data that can lead to identifying who you are individually is PII.
So it's not classified as PII that's protected. It's classified as data that could lead to data that can determine who you are. So it's kind of secondary right now.
Maybe that'll change. I Don't know. Interesting, interesting.
Guys, what a great text on gang on this. Fine Friday. We, we need to end it.
I've gotta get over to New Orleans and, uh, you know, I got a couple of referees to talk to. So, um, Yeah, start Bitcoin. And there was some Jimmy Coin in, I'll put some, they do whatever you want.
Jimmy Coin on, on this slide. Yeah. Uhhuh.
Lisa, John sna. Mitch, thanks for joining in. Thank you for watching.
As usual, we have tech drunk TV all, well, not all day, but for the next couple hours after our gang show today, stay tuned for that. Um, we'll be back Monday maybe talking about the Super Bowl or what our favorite ads were. Um, will they be the AI ones?
I don't know. I always like the Budweiser Clydesdale commercials. They, they do a good job with that.
But for now, that's it for this. Have a great weekend. Enjoy the Super Bowl, everyone.
This is Alan Shimmel for Techstrong. We're outta here. This is Textron tv.
Hey everyone, welcome back to Textron tv. You know, I, I always enjoy talking to my next guest here. He is the CTO and EVP for the cloud platform over at Qualys.
It's my friend Dilip Bani. Dilip a pleasure to have you. Usually we're in person at the QSD or at RSA or somewhere where we're in person, but today we're on Zoom, but it's still good to have you on.
How are you? I'm good. Good to be here, Alan.
Uh, it's always a pressure. Yes, it's, it is, it's, it's fantastic. You know, I mentioned it, well, we should hate it right off the bat.
So, QSC, qua QS, Wallace Security Conference, QSC, um, is coming up this year, I think in October. October 16th, around there. And I, I heard a rumor it's gonna be in Houston, which is a great city.
That is correct, yes. Uh, it, it's a new location for us, um, this year. We are in Houston in October.
And of course, looking forward to being there, looking forward to meeting our customers, sharing with them everything that we have been working on, especially everything that we are doing around enterprise to risk management, the risk operation center, and how that has evolved since we last talked about it, uh, during the 2024 QSE Or I, you had to think for the year, right? Yes. And by the way, if you go to Tech tv, all of our interviews from there, and there was a lot on the risk Operation Center, the Rock are, are available if you go to industry conferences, look under quais, and you'll find they all have, including my interview with Dilip, is there.
So check that out. But Dilip, we're gonna talk about something else today. So, last week was a bit of like a Sputnik moment, if you will, right?
All of a sudden the, the Western AI establishment was rocked by news out of China that these folks, you know, it's a, a handful of PhD engineers basically put out a, an AI model that rivaled the best of what we have here at a fraction of the cost and a fraction of the time. And open sourced it on top of everything else so everybody could go, you know, look under the covers to an extent. Um, and it was big news.
Qualys turned your, uh, your, your scanning engine onto it and, and came up with some very interesting results. I don't want to say too much 'cause it's your story. Lay it out for us, Philip, what happened here.
So, and Alan, I mean, spot on, right? Uh, deep seek, uh, this is a, you know, fairly young AI company, uh, out of China, certainly very talented folks. They came out with a model.
Uh, they've, they've in fact been coming out with information for the past few months, and, um, I don't think a lot of people necessarily noticed them until they came out with this latest model. Um, the R one and it, it's open source, but it, it performs really well. Uh, and you're right, uh, you know, they are saying, uh, they have trained it at a fraction of the cost of what some of the larger tech companies here, OpenAI, meta, uh, Gemini, and others are, have done to train their models.
Uh, so I mean, first and foremost, I think what they have done is something amazing. Uh, in, in some ways they, they are proving that if you want to build very large scale foundation models, you don't have to be in an extremely large organization with unlimited amounts of money. Uh, you can be a smaller shop and you can do this.
Uh, so that's a good thing, right? Um, it, it certainly got a lot of hype, it got a lot of coverage. Uh, what we wanted to do was, as we were looking at it, because we were curious too, we use a lot of open source models internally for our, uh, Qualys cloud platform.
So we wanted to look at deep seek and just understand, you know, how it was behaving, what it was doing. Uh, now I think you probably know we launched Qualys Total ai, which is our AI security solution some months back, uh, uh, in August. And what the solution does is it gives you a more comprehensive view of your AI posture, meaning you will get full visibility into your AI hardware and software assets, uh, your entire AI inventory, where your models are deployed, where your LLMs are running, and then also a pretty detailed vulnerability posture across your AI footprint.
In fact, we have more than 1500 detections right now, just from a vulnerability standpoint for your AI footprint. So we said, well, let's take this, let's take what we have and let's see how deep Seeq performs on that, uh, from an LLM scanner standpoint. So the way our LLM scanner works is we do an outside Incan, and we have built a pretty exhaustive knowledge base of questions that we will ask an LLM, um, back and forth, um, which we call our knowledge base, and we gather that information.
Then we have some inbuilt models, which we used to then judge the quality of the responses that is coming from these target LLMs that we are testing. So we did that and deep seek, um, to our surprise, uh, it didn't do particularly well. Uh, in fact, it, um, it failed 61% of knowledge based tests that we had, and in total, we ran about 900 tests, um, just for our knowledge based checks, right?
And what these checks do is they test for, um, ethical questions, legal questions, operational questions, uh, and we do a lot of back and forth with the model to kind of get a sense of how is the model responding to our questions? Because these things are important, right? You take a model and you deploy it, whether in a B2B setting or in a B2C setting, and you expect the model to work in your particular domain and not give answers that it's not meant to give.
And when it does, then there is a liability issue here, right? And, you know, that's what we are trying to get a sense of. So we did that.
Then, in addition to the knowledge based tests, we also do jailbreak tests, um, where jailbreaking basically involves techniques, you know, that you can use to bypass inbuilt safety mechanisms that are built into the model. Uh, there's a lot of well-defined techniques. Uh, we, so obviously we work with the community, the open source community, and in, in our solution right now, we have about 18 to 20 different jailbreaking techniques that we use, and we ask the model questions around these techniques.
The idea being that you're somehow trying to coax the model to give you information that it's, it should not be giving you harmful outputs, uh, misinformation, you know, privacy data, unethical data, all sorts of things. And I think just based on the fact that it didn't do so well on the knowledge based tests, um, I mean, not surprising, but it failed more than 50% of the jailbreak tests to failed almost 58%, almost exactly 58% of everything that we did. And our analysis was pretty comprehensive, um, you know, trying to get a sense of what was going on here.
Uh, so really the, the gist of this is, yes, it's a, I think it's a great model from a foundation model standpoint, uh, in how they have trained the model, the underlying architecture, um, and just being able to demonstrate that you can build a model with significantly lower investment. Um, but that corresponding investment hasn't really happened on other areas yet. Right?
And then of course, concerns with, if you're using a hosted model that is sitting in China, and you have GDPR concerns or other, you know, regulatory requirements, right? Not concerns, but GDPR requirements, right? And other regulatory requirements across different countries.
Something to be mindful of, right? Uh, Sure, but well, that's the host sovereignty issue, right? Yes.
So Dilip, I'm not gonna make excuses for them, but let me postulate two, two things on what you said. Number one is some of the, uh, not the jailbreak questions, but the sort of foundational questions, could it be due to the fact that clearly, because it is from China, it it is, I don't want to say censoring, but it's purposely not reporting on some sensitive areas that the Chinese Communist Party may beam, uh, sensitive that they don't want it to report on. And so it's been, in essence, blinded for those things.
And I mean, 61% is still a pretty high number. I'm sure it wasn't, you know, 61% of things that have been censored there, but could that be at least partially, uh, responsible for that? Yeah.
So Alan, there are two parts here. One is, I mean, obviously just based on the fact that the, you know, the model came out of China and the sensitivity of the Chinese government, there are some questions that you can't ask the model. So it's really quite censoring some things.
Um, and some of those are well documented, uh, right? Um, that what this then means is that if they do want to stop, so the model from giving incorrect information or unethical information, however you look at it, they are, you can stop the monitor from doing that. You cannot be perfect, but you can restrict it as best as you can.
But those controls haven't been applied to other areas. As an example, we asked the model a lot of, when we were asking jailbreak questions, um, you know, we asked a lot of typical questions on, you know, how could I make an explosive, uh, how could I come up with, um, you know, incorrect healthcare information? And it didn't need a lot of prompting, a lot of circumventing to get that information out.
It was just giving us that information very quickly. Uh, and I, I think what this points to is they have put in certain guardrails for things that, for deep seek, you know, just being where they are, you know, they had to do that, That are important to them in their right, right? But maybe not for, for West, but not for, for a larger, and, you know, that has to be done.
Now, either they do that or other organizations can pull these open source models and have guardrails sitting in front of these foundation models to say, when you're asking a question, I'm going to make sure I'm filtering the right things out and only asking the model what makes sense, right? Because the model inherently is not trained yet to do that. Yeah.
I mean, and that's one of the beauties of it being open source, right? You could self-host it and put whatever guardrails you want in front of it, and it's self-hosted, and that takes it out of China and everything else. But Dilip, let me, a lesson I learned in my 25 plus years in security, 30 plus years in technology, is security becomes important when customers demand, it's important.
And I think clearly deep CQ wanted to get this out. I I don't think it was any coincidence that this was released. This R one came out two or three days after the, uh, Stargate project or whatever, the $500 billion project to go build data centers was announced, right?
There's, there's, there's PR here and global nation state strategic, you know, competitiveness at play. I don't know if they had the time to maybe put in the, just, just like, until a customer demands better security, you don't have better security until someone says, you've gotta put these guardrails in here, especially when they're rushing to get it out. They, they don't put them in there.
I, I would hope that that's just more of a sign of its immaturity than a total lack of, of ability to do that kind of thing. Yes. Um, and, and Alan, I think I agree with you there.
Um, this is a fairly young company and, um, I mean they, you know, they've been working on building, you know, some, I mean, in my view, some exceptional models. Uh, and to your point, uh, you know, this is still to some degree, you know, research oriented, right? Um, but when you look at the overall AI ecosystem, there are different layers that you're looking at, right?
Uh, you are, you have one layer, which is your hardware and infrastructure layer where the folks like Nvidia are playing, right? The second layer is your foundation models, right? Which are now to some degree, it feels like they're starting to become more commoditized.
Uh, you know, some are closed source like open ai, but if the likes of deep see are making models open source that others can then pick up and iterate on, right? Um, that would help. And then the third layer, the one that you are talking about customers asking is that app layer, that how do you take these models and how do you, you know, bring value out of those models to cater to a need?
And as that, and as that app layer is gaining maturity, the security requirements will increase, right? I mean, what is my model doing and why is it doing what it is doing? What kind of guarders and checks and balances do I have?
And I think that will come for sure. Um, and I think they'll come for all models. Neil, I I gotta ask you another question.
Look, this is, we've been talking about this deep seek since the announcement every day on Textron Gang and in a lot of our articles and videos, uh, there, there's one, I don't wanna call it a rumor, but, uh, you know, some people are saying, I hate to say that 'cause politicians say that. Some people say, but there is a story out there that the reason they were able to train deep, steep, or this, this particular model so much faster and cheaper, is because they didn't kind of start from scratch. They, they, they were able to for however they got their hands on it, uh, a open ai, uh, model, and then they kind of trained it off of that, if you will, or, you know what I mean?
And, and, and so that's what allowed them to do this faster and cheaper and on less powerful Nvidia and so forth. Is there anything in your testing that would give credence to that prove it, disprove it, or that's not something you looked at? You could, That's, yeah, that's not something we looked at, um, because we were doing an outside in evaluation of how the model is performing against checks.
You know, whether that happened or not, I mean, will, I mean, you know, remains to be seen. Um, but, uh, what I will say though is, um, from an architecture standpoint, from a model standpoint and the way they approached building the model and building the training, uh, and there is innovation here, which Oh, no doubt. Which I think no Doubt, most of the larger companies, everybody's going to benefit from that.
It will optimize how they're using their GPUs. Uh, certainly, You know why it's the deal. And it's funny that it, it comes from the Communist Party of China, but this is what the open market's all about.
Yes. Right? If someone builds a better mousetrap, copy that mousetrap Yeah.
As fast as you can, right? And, and learn from that and, and, and keep innovating, because, you know, the other thing I, I feel with this is yes, it didn't do so well on your test. No doubt about that, right?
61 and 58% are pretty, I mean, those are hard to argue with. Uh, it will get better though. I'm sure it will get better.
And, and it, it, and that's again, part of this whole open source thing, right? It allows other people to innovate off of their work as well, which is, you know, is, is a great model. Um, I, I think the bigger, the bigger thing though is that we were just discussing it on text Junk Gang this morning.
There are so many different models out here right now, even within open ai, you know, when do you use oh 3 0 1 4? Oh, most people don't really know. Well, it's sta it versus another one.
You know, how do you know what model to use? When should I use deep CR one versus, uh, Gemini or llama or what have you? So I, I think we're gonna develop in a world, it's kinda like cars.
Some people drive a Maserati or a Ferrari and it costs a lot of money, or a Bentley, other people drive a Buick or a Cadillac, or, and then other people drive Chevys. Mm-hmm. And that's okay too.
They still get you from point A to point B, which is the, that's the mission. Yeah. If this thing can get you from point A to point B and fulfill the mission at a fraction of the cost, market economics dictate that you'd be a fool not to use it.
Yeah. I I, so you go ahead. The, I I think the entire ecosystem is still, it's still very early, right?
0 and you know, everything new, you will not like it. We still look back fondly to the initial versions of Cha Chan, GBT thinking, oh, it was revolutionary. Yes, it was.
But now after you've experienced something so much more better, right? Even from OpenAI and from others, you will think the initial versions didn't really have, you know, that level of knowledge or they were not as good as what is today. Uh, and what will happen here is this innovation is happening at an extremely rapid pace.
It's not even in gaps of two years. It, it's happening, you know, within months, right? Weeks sometimes.
I mean, week to week, these things change. It seems It's crazy. I mean, these guys came out with their model and then Alibaba came out with a model saying, Hey, we think we have something better.
And, and that's a good thing, right? Because early on, it's The market. Yeah.
It's the market. You want this kind of innovation happening. You, you want this kind of disruption happening, and then everybody benefits from that.
So I, I agree with you. Let me ask you to put your Qualys hat on now though, 'cause we only have a few minutes left. Speaking now is C-T-O-E-V-P cloud platform at Qualys.
How big a challenge are these AI models in, in making security better or trying to secure them, right? There's two aspects. One is harnessing AI to be a better security company.
One is as a security company trying to secure against AI being used by bad guys, right? Yeah, I, it's, it's a really good question, right? Um, I think using AI ML and AI in security has been happening for a long time now.
We have, we had machine learning models embedded in our platform. We had them for years. Uh, I think when LMS came out, large language models came out.
Uh, it was a little bit more disruptive because it, it, some way it socialized using machine learning. Earlier to do ml, you needed a data science team. You needed a team of experts that really understood how to train these models.
Now, in some cases, you have folks, you know, that take an LLM model and just doing prompt injection, they're able to, you know, build applications that can add a lot of value. So now from a security standpoint, of course, using AI ML to build security solutions, it's been there, I think LLMs will help accelerate that. We are already seeing that.
Uh, we've introduced a lot of new things in our platform just in the last two years over that, right? The bigger question now is, as especially large language models, which are more predictive, they're not deterministic. If you ask it a question, it will not give you the same answer every time, right?
It's just how the underlying architecture is. It's getting better, right? If you ask it a math question, it, I mean, it is giving you good answers now, right?
And especially some of these newer models are really good, but more from a business standpoint, when you are asking it a question, you are expecting it to answer within the context of your business domain. And so guardrails become extremely important because you are saying your chat bot, let's say, is representing you as an organization. And if your chatbot gives an answer, then you are held to that answer.
You can't say, I had a chatbot on my website and it gave an answer. That answer was incorrect, so it's not my problem. You can't say that, right?
Uh, so that's where, you know, more checks, um, you know, building the right kinds of gates is becoming, becoming increasingly important. What we are seeing right now is people saying everything is in beta mode, right? Uh, that, hey, we are releasing something, but it's in beta mode, which is fine.
Um, I think the industry is maturing. Obviously the models will mature, the security ecosystem will mature, right? Just the way we introduced total ai, we looked at this as a gap, even when we were looking at it internally to say, okay, our teams are blowing models.
We don't even know what's going on. We talked to a lot of CISOs and they said, we have no visibility into what our teams are even putting in charge GPT or perplexity. What kinds of questions they're asking and what kind of information is going out, which could then be used to further pre-train those models on proprietary data, right?
So you need all these checks, and I think the realization is there. And you know, we, we obviously took a major step in saying, we are putting out a solution that will help you understand your AI ecosystem, understand your vulnerability posture, your security posture, and then of course, as you're deploying your large language models across your enterprise, you know, what is the security, the compliance, the ethical guidelines, uh, the jailbreak, uh, you know, capabilities, you know, how, how do you manage all that, right? Uh, that's where we are at.
Uh, we are obviously adding a lot more capabilities into our platform into total ai, uh, quas, total ai, so our customers and just the larger, uh, community can benefit from it. Excellent. Di we're out of, we're overtime actually, but thank you so much for coming on.
Keep up the great work, everything you spoke about. com whether you want to go check out the blog articles on, on this particular testing and, and story, or you want to find out more about total AI or about rock or anything else. com is, is your starting place for that.
Dilip, I hope maybe we'll see you in San Francisco during RSA week, if not a QSC or you're always welcome to come on here and chat with me. It's a pleasure as always. Likewise.
Thank you, Alan. Good conversation. All right.
Diwani C-T-O-E-V-P cloud platform at Qualys here on techstrong tv. We're gonna take a break. We've got a lot more coming at you today.
Stay tuned. We'll be right back. Hello and welcome to the digital CXO podcast.
I'm Amanda Ani, and with me today I have Mo Sharif. He is the senior director of AI at Sitecore. How are you doing?
I'm doing well. How are you, Amanda? Doing well.
Happy to have you on the show. Thanks. So can you share a little bit about Sitecore and what do you do there?
Sure. So Sitecore is a leading digital experience platform that really helps businesses deliver precise omnichannel experiences to their clients. We have a number of products across the whole content lifecycle and marketing operation lifecycle.
And, um, my job is really focusing on generative AI and AI and how can we bring them within our tools to really help marketers expedite the way they work. Wonderful. Well that brings us to our topic today, which is the misalignment between the importance and adoption rate of AI and intelligence tools.
So I have a little bit of information you shared, which is that 80% of marketing leaders report AI as critical for digital experiences workflows, but only 27% report full integration of AI into their digital strategy. Why do you think that is? I think charity, there's a challenge in AI adoption.
One, there is some change management where marketers themselves need to feel accustomed to prompt engineering to new ways of work. I think that's one of the leading things. The second thing is ultimately there is this fear about where is my IP going?
Do I have control on my brand? Is it adherent to my brand or not? So I think these are big points that really drive people to not adopt it as fast as they possibly can.
What suggestions do you have for company leaders when it comes to integrating AI and getting everyone on board? I think the first thing is really being able to test it, being able to try out ai, letting, giving your teams the space to really try out tools and innovate with these tools, because again, it does take some time to getting used to these tools, but at the same time, I think it brings so much value on the long term. The second thing I think that's really critical is using the right tools.
Again, just going out and trying any tool is not the right approach because there is a lot of security concerns, there is a lot of IP concerns. So it's really important to choose tools that can be trusted from, uh, vendors that can provide tools and assure you that they're not using, for example, your data, for training their models. Um, and finally, I think it's really important to use tools that really understand your brand.
So it's not just about using a tool that will give you, uh, or spit out very generic terms and very generic content. It's really about leveraging tools that really understand your brand so that they're in context so marketers can actually see the value straight away. So how do business leaders find the correct tools and ensure that they are trying to integrate the right technology?
Yeah, I think there is a lot of research that they need to do. Ultimately, they need to first define what are their biggest pain areas, what is driving their teams, uh, driving ultimately the, uh, the productivity of their teams down. And also, it's not about tools to replace your teams, it's about tools to complement your team.
So it's also, uh, about this open dialogue with your team on what do you wanna continue to do and what do you want AI to do on your behalf. So I think it's that combination of the two. And once you've defined it, don't go big.
Like, don't try to boil the ocean. Try to really optimize on, uh, which tools you wanna use and say, choose a set of tools and try them out first. Don't just jump in all, all in at once.
Just try them out first. Make sure they do it here and do your research. Ask questions, let your IT come in, and your security team come in and ask questions about how is this data gonna be used?
Are you training them all with it to make sure that you're ultimately also keeping your IP in check? Absolutely. There's a real likelihood of overwhelm if they just jump into too many tools at once and they're trying to track them and the safety and if they're really needed.
So once we're in that integration stage and they've chosen a few select tools, what issues or roadblocks do you see company leaders facing, and what suggestions do you have for them? I would say the biggest one is change management, is, again, adopting AI tools does require change management. It requires, again, an AI tool, just like a human being, needs to always learn what's new, what's latest, so that it's contextually relevant.
So being able to always have that knowledge, that data about your brand. Uh, I always say it's like you have a junior marketing marketer in your team. If you don't give them the right knowledge, they're gonna get lost.
So we need to treat AI in the same way, and we need to really have the governance in place to ensure that when we use these tools, we don't just expect them to understand the way we work from day one, we actually take the time to teach them so that they can start becoming from junior to a senior marketer. Do you think that there is, uh, lack of communication sometimes and maybe not, um, enough pathways for education and proper training that come into play? Definitely.
I think generative AI has been very interesting in terms of the speed at which things are going, at which things are changing, and that also creates a problem in training because what you get trained on today might become obsolete tomorrow. So it's also important to talk about the roadmap openly with your partner, your vendor of choice about what's their roadmap, how do they see the future, how, how are they catering for today, but also for tomorrow. Because ultimately, by the time you procure these products, you may find already changes that are happening and new things coming in so that you need to be able to, one, trust that they are keeping up with what's happening in the market, but two, they can really help your team get trained and be accustomed to, uh, that AI journey.
Wonderful. Well, AI is developing so rapidly. How do companies stay ahead and relevant with the technology as quickly as it's evolving?
Yeah, I think generally it's hard if you're doing, if you're building everything yourself custom, right? Like if you are gonna build everything custom, it's changing very, very rapidly. So again, I'd say one work with a trusted partner that can and is really investing in ai, make sure they are investing, not just adding bits and pieces of ai.
We've seen this a lot where a lot of marketers get quickly frustrated because, uh, a lot of vendors, right, uh, have kind of went very quickly at adding AI for the sake of AI rather than really solving a business value. And I think that's also a really important piece. It's not just keeping up with the trend for the sake of keeping up with the trend.
It's about what business problem are you trying to solve. You might hear about new technology, but the first question you should ask is, how is it gonna help me in my day-to-day work? How's it gonna improve my way of work or enhance my customer experience before jumping in and saying, I wanna use this tool?
Awesome. Well, if there was one key takeaway you could leave our audience with today, what would that be? I would say start now with ai, because again, the train is moving and you're either on it or you're left behind.
So I think it's essential to start now and start small. Don't try to boil the ocean. Alright.
Thank you so much for coming on the show and sharing your insights with us. Thank you. Happy to be here.
Thank you To our audience. Stay tuned. There's more.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Welcome back to Textron Unplugged. My name is Cassandra Chen, and today we have Demetris. Andrea ADIs, can you introduce yourself?
Uh, thanks for having, having me. Uh, yes, I'm, uh, Demetris and um, I work for, uh, red Hat. I'm a engineering director and I've been here like 20 years.
I've spent the first, uh, 15 years on a open source project called, uh, JBoss Application Server. And the last five years I'm mostly involved with, uh, the project called Corcus. I have my t-shirts here.
Um, so both in the Java space and both in the, let's say, infrastructure or tooling for other developers to take it and build stuff. How did you get into technology? Um, I, I, I think for me it started, uh, with a movie.
Uh, I saw, uh, when I was a teenager and, um, the movie was called, uh, war Games, and it was about a teenager that used his laptop or laptop, his computer. They were not laptops back then to hack into the Pentagon computer. And there was an AI system there, and the teenager Israel thinking he was playing a game, he was about to start a nuclear war.
And the movie goes on. And, and for me it was like interesting as a kid to see how much you could do with computers, like from your bedroom, essentially. Uh, and then I started with, uh, home computers, like of the time and I studied it and it became my profession.
So I think that was like the, the tipping point. And today you work with Corus, Mostly qca? Yeah, I have a quite a large team.
Uh, the cuss team is, uh, you know, part of course it's an open source project, so we have like 50 people in Red hu that do QoS, but uh, last week we celebrated, uh, 1000 contributors. So there are about 950 people outside our team that like our project and then contribute to it in their, either in their free time or as part of their job. Um, how do you work to get like new people and younger developers to work on the project?
Let's say if, if you are already somehow, like you're studying or you're already at some level where you're able to code in Java, something non-trivial, uh, on our website you can go and you can click and you can go on GitHub and we have, uh, issues marked, uh, with a label called, uh, uh, good First, uh, task. So those are small tasks that are not too difficult that someone could just pick up and start doing something and we can help. Of course, we, we have a lot of people on our public channels like, uh, Zule or a mailing list, and you can go and ask for help.
You know, I want to do this, uh, is it okay, here's my pull request, we will review it. Yeah. That if you're already somehow in, in the Java space, How's your personal experience, like when you first got into open Source?
I think what was fascinating was, uh, back in my time there was not much open source. It was like the beginnings and the code was secrets. So if, if you want to know like how Microsoft Windows worked or Unix, you didn't have a lot of ways to do that.
You know, you, you have to go and work for a company in the States probably that's doing this sort of stuff, but when open source came, suddenly the code was there and you could read the code and, and figure out how it works and learn and do your own extensions. Um, and by doing so, you, you can discover code that is like really, really high quality. So the, when I saw like some stuff in Jbo, I was impressed.
It was this that was really, really advanced. I, you know, I you do not expect, you thought it's open source, so it's, it's crap, you know, like, uh, but it's, that's not true because when you write open source, your code is visible. So other people will look at this and they will propose changes.
Yeah, you could do this better here, or this is not good, you know, change it. Which initially it might be a bit intimidating because, ah, you know, my code is not good, but the only way to learn is to, you know, uh, work with others that are better than you and they will help you improve. I think it's good to get feedback on your Work.
Yeah, definitely. Yeah. Um, some, sometimes feedback can be brutal.
Like, uh, oh, that's a stupid idea, you know, but, uh, you shouldn't feel, uh, offended because someone is, uh, discussing this piece of code doesn't discuss you as a person. So this piece of code is fixing not you. Right.
Some people take it personally and they retract, oh, you know, that's too harsh. But that's not the case really. You have, yeah, It can be hard sometimes.
Yeah. Are you get me a talk here. I'm, I'm done, I'm done.
Now I'm gonna talk. So I had two talks. One talk was about, uh, developers and how they can, uh, get better.
And, and the ideal thing is for me, if, if you have found out your passion in technology or pretty much anything you do, how you get there. Um, and my advice is based on observing some very successful people in my team and how they did this. So my talk tries to convey practical advice on how they did it and how this could work for you.
What is some of this advice? Um, so very short is like, know what you like and go into it. Like that's the super version.
But things that could help would be to, um, be creative and experiment with things in order to find what might interest you. Um, get closer to communities that do this sort of stuff. Um, and there's, there's a lot.
There are many communities now. Um, so go there, try something, get to know the people, introduce yourself, um, and just do more of it. You have to do more and more and more.
So you need to find every possible excuse that will let you do the thing you like, either in a company setting or, uh, on a educational setting. Like get a project on the thing you like so that you spend time on it, um, and do more and more of it. Uh, at some point, you know, you might be lucky and, you know, someone gives you an offer, oh yeah, come and do this for me.
Like, for, for work or something. How does this relate to you personally? Are you doing something you like right now?
Yes. Um, this, uh, QO project that we started like from scratch, um, it really redefines, uh, the things you could do with Java, because if you remember, Java was great to write, to write servers and big systems, but then the cloud came and people started switching to the other, other languages that were like smaller nimbler. So what we did with this project was to make Java sexy again for the cloud, and very attractive also for developers, uh, to, we, we call it a developer joy.
So you just, uh, fire up your id, you, you start QoS and then QoS will do the right thing for you. We just keep coding, coding and, you know, make it fun. So Corcus connects Java and the cloud?
Yes, pretty much. Yeah, exactly. Uh, how long have you been working on Corcus?
Uh, five years now. Yeah. And before that, there was another open source project, like, uh, the Zebo application server that really redefined this, uh, space.
Um, it was the first, let's say open source server that really broke through. And, uh, we competed with the likes of Oracle, i, BM, um, what else? Web, web, WebSphere, web Logic.
Um, and we were acquired by Red Hat. So that was a big, um, like it was a big thing at the time. And big part of that team is related or has transitioned into this, uh, newer project.
So I know those people, like for a long time, you know, we had fun together and we, we keep having fun doing, uh, what we like, basically. Do you have a strong passion for Java since you're working on Corus? Yeah, I think Java is still like a very interesting language to start.
I know young developers will do like a Python and Java script, uh, which is fine for some type of projects. I think Python is great to like experiment and do something quickly, but if you have to build a system that is mission critical or you know, it has to do with money or you know, air, you know, or some other critical aspects, I, I don't think you can do the Python. I think Java is still king.
And by keep evolving Java, we make it very relevant. Not, not just recently. We are adding capability to let you do AI stuff.
So I think we, Python is king that in this domain, but I think we're catching up. So Java developers can do like stuff now easily with Java. Do you have any words to get young developers excited about joining open source projects?
Yeah, well, um, they can build up a career either around open source or just technology. So if you go to give an interview now, quite often you just send the link to your GitHub. So we go into your GitHub and check what have you done.
Like, so it's, it's a very strong, um, element to say, oh, I've contributed to this project. It's a complex project. So that automatically means you know, how to navigate a complete C project, you know how to work with people, you know, to use the latest tooling.
Uh, it's like your, your CV basically now, and, and for me, normally that's enough. I, in many cases, you, I, let's say someone finish like a degree, great, it's an achievement, but that doesn't show like if you know how to do the work. So your GitHub is more appropriate in this regard.
So, So your gi on page really shows what you've done. Yeah, like, like that's your resume, your pro the project. I want to know the project you've, you've done.
I want to know what the made you excited about those projects, who you work with, what was your role, um, what you wanna do next, what your plans are. So with that, so I can kind of sense if you're the type right type of person to join, uh, my team, I think it's useful to know that your GitHub page is like a resume. Yeah, We've had a really good chat today.
Thank you. Thank you too. That was great.
Hey everyone, it's Alan Shimel at Techstrong. Welcome to another edition of the last great Cloud transformation. It's no longer just my data center or my data centers, it's no longer just my cloud infrastructure, maybe over at AWS right?
Today I have data centers, I have multi-cloud presence, I have presence on the edge. My people do anything from anywhere at any time. We need, it's a whole new paradigm.
First of all, I want to introduce you to Mike Hamilton. Mike is the CIO at CloudFlare. Hey, Mike, welcome to the last great cloud transformation.
Thanks so much for having me. It's great to be here today. So Mike, CIO at CloudFlare, man, that's a job.
That's a job. It's incredible. That's gonna be one of the most complex networks in the world.
Something like 21 or whatever percent it is of the internet actually passes through your network. How do you sleep at night? Tell, tell, tell us.
You know, I mean, thankfully, thankfully for CloudFlare, this, this is in our DNA, this is what we get outta bed in the morning to do. I'm not alone. If I was, if I was the, the key brains behind this, I think, uh, you know, I'd be really nervous all the time.
But we have incredibly smart people from our C-suite all the way to every engineer that touches every line of code that's thinking about this all the time. And, and I would really say my favorite thing about the company, in fact is, is being clever. And we're thinking about really what the next, the next way to approach this is like, how do we, how do we define not not just follow or, or address concerns that our customers have, but how do we create the next world?
How do we create the next paradigm that really makes data secure and that really helps companies manage this global infrastructure? The world has changed so much. I've had the good fortune.
In fact, I started my career in public sector in 1998, approximately. And, and everything was on-prem back then. Uh, and my career was all on-prem through about 2011.
I was fortunate, in fact, to be one of the first people to adopt virtualization. I was a bare metal VMware guy back in like 2001, which at the time people thought I was a little bit crazy. They're like, what do you mean you're running 10 servers on one server and you know, what, how would this even work?
And I'm showing them VCR controls on servers, and they're like, what? Like, you can pause a server. What does that even mean?
You know? And then being able to move servers later was really cool. I've had the good fortune of, of having a career that had that strong foundation around data centers and virtualization.
But I, I got, you know, my mind was kind of blown getting into the world where companies were being started entirely on SaaS. You know, working in hypergrowth gave me a really good chance to say, in fact, when I, when I made that tradition in my career, I went from a startup to MuleSoft. And MuleSoft.
Part of the appeal there was, they didn't have anything on-prem. There were like, everything was in the cloud. All their business applications were not in the cloud.
But that advantage was really interesting me, because I was, I was thinking, you know, from my career, I want to have a challenge that's greenfield. Like I've never had to do this before. Nobody's had to do this before.
How do I do it? Um, and to end up with my career now today at CloudFlare is kind of mind blowing for me. Every day when I wake up, I'm like, wow, this is such an incredible company, such an incredible time to be here, largely because we're starting to define how businesses run globally, and we're giving them a safe way to do that.
So I, you know, I think the responsibility, we take that responsibility really seriously here. And again, while I, I'm glad it doesn't all rest on my shoulders. We have a lot of smart people here, but, uh, if I were alone, I'd be way more stressed out than I am.
We have a great team here. Good for you. Hi, Mike.
From, from a, uh, fellow now former C-I-O-I-I. I, I'm with you there, brother. I understand that role.
You know, one of the great things about, wait a second, Mitch, I haven't even introduced you yet. Well, you know, people know who I am. You don't have to introduce, Oh, I go ahead that I'm Mitch Ashley, I'm CTO with Techstrong and VP practice lead for, uh, DevOps and software application development.
Um, you know, as you, you get to consume the services that your company creates, right? As the network. And, uh, you know, there's a lot of innovation happening in the network, programmability of the network developers, you know, moving apps into it as opposed to just edge to edge kind of connection, security, all the things that go into it today.
Um, I'm just curious how, you know, you, you obviously have to kind of keep the trains running on time, but you're also looking at how do you take advantage of, you know, what the company's introducing and the customers might be using. How, how do you, how do you, what's your strategy around that? Well, I do have someone that, that runs customer zero for me, uh, with, with my guidance and direction that that person just started about a month ago.
But we all, we have been using our product for a very long time, and it's, it's actually really natural because we have a business to run and so do our customers. And so it, I've run, I've run customer zero programs in the past, and it's generally like I, I insist that we follow the exact same path that a customer follows. So it's like, we have an account, we have an admin panel, we file tickets with support.
You know, we don't just run to someone's queue and try to find them. Um, but then we do try to bump things and accelerate them. And it, what I think is most incredible, and what struck me the most about CloudFlare is how our technology can really meet our customers where they are.
So we have all these different ways of on ramping technologies. Like you, you might say, Mike, I'm mostly on-prem right now, or I have some on-prem and some Amazon or some on-prem and some Google, you know, I'm not quite the multi-cloud yet, or I still have some Unix box sitting in a closet somewhere. Um, you know, and, and I want to get this into a zero trust network.
And, and our product is designed to do that. It's designed to make it easy to get your network connected. And so it meets our customers where they are instead of asking them to change everything or, you know, hodgepodge something together and into some kind of word Goldberg machine.
Because I think the way the world has changed, the way that, you know, our, our, our employees are no longer at home. They expect to be able to be all over the place. Our applications are no longer in one place.
There was so much you could control back in the day of saying like, we run that application on that server and that data center. I can look at the traffic flows and control performance and blah, blah, blah. You know, that was one thing.
Now the applications like Whyman, Salesforce's data center on the West coast, and I'm in, you know, NetSuite's data center over here, and like, the applications are really everywhere. The users are everywhere. The world's totally changed.
Uh, it's cool that to have a technology that meets our customers where they are, we understand that people have on-prem, we understand that they have cloud, we understand that they have SaaS applications, and, and so we're meeting them where we address it. I get to do that internally. So my job is quite exciting, really.
Um, and, and it's not that I don't go tap somebody on the shoulder, uh, that works on our product, but I do file a ticket first. You know, where they live, I guess. Yeah, I Do.
I can still it. I'm like, let's just say I can nudge things to make the move. Yeah, Absolutely.
But you calling to take really nice email account you've got there, shame, if something happened to it, would you fix my problem? So, you know, when I look at cloud, what drives cloud transformation, what drives cloud transformation? So we get a lot of app modernization, driving cloud transformation, right?
In, in the old days, we used to just lift and shift our stuff from a private data center up to the cloud. That worked for all of six, six, it didn't even work for six months. We've quickly realized that that wasn't taking advantage of the cloud.
And ever since then, we've been on this quest of transformation by app modernization. We, we are gonna, you know, micro thread, multi-thread, our apps, uh, microservice our apps, cloud data, modernize our applications to take advantage of the cloud. And by and large, we're doing that a lot.
There's a lot of app modernization going on out there. But you know, just like in the book, the goal, which of course the Phoenix project is based on, right? We just, when you clear up one bottleneck, the next bottleneck shows itself.
So as we're modernizing applications now, we've run into network modernization. What we did before doesn't work in this new cloud native modernized application world, and we need to modernize our network. The connectivity cloud is, is one example.
But let's, you know, let's peel that onion back a few layers. Mike, what do we mean when we're talking network modernization like that? I, I love that you started with applications because I think it's a really interesting way to talk about abstraction.
If you think about, let's like rewind through my career for a second. Like the, the big thing about virtualization was that the network was fast enough to become a bus and that you could actually like, have memory and storage and compute being different places. Like memory, you were in one place, storage was another place, and yet I could run an application that way.
But the abstraction in that case was just about the hardware. Like we're abstracting the hardware away to make it more flexible so that servers don't die as easily. You know?
And, and, and it was easier to modernize them that way. If you kind of fast forward, like now to the cloud era where we put things in Amazon, what a lot of companies discovered on that journey was, oh shoot, to your point on refactoring applications, um, this application's not designed for an availability zone structure. Like, we want to do this cloud migration.
We did lift and shift and oh no, this node went down in availability zone, whatever. And like, we lost something. So that abstraction, you know, applications had to be refactored to take advantage of high availability scenarios in cloud environments, right?
So the abstraction layer had to change. Then the next phase of abstraction is serverless, where it's like, Hey, look, I don't, I just built the application at this point. I don't really need to think about, you know, the different three tier, like the database server, the API server, the web server.
Like that was the abstraction layer we'd built in that world. The networks undergone a similar thing. Um, but it's gone at a much slower rate because the innovation has had to come from the applications.
The thing that serves the user from like an intent perspective. If we think about applications as like intent engines, somebody wants to accomplish something and they use the application to accomplish something because the network was like the roads that they used to accomplish that. It was one of the later things to evolve.
Like that's why we're not seeing it evolve quite as fast, because it's also expensive. You know, on-prem networks are expensive, they're complicated, and people have a certain level of comfort with them as well. I know I did, like when I went from on-prem to full cloud, it was like, well, but I, I like my on-prem network.
I have the inside, I have the outside, I have the DMZ. These are definitions. I understand now my, my, uh, ERP applications on the cloud, you know, it's a, it's actually in someone else's data center, and I'm running it that way.
And then I have these custom applications that are still behind the firewall that I'm trying to move on the other side of the firewall. And so the dollars weren't going toward something with the network because it wasn't really the place the investment needed to go. The the key was like, how do I enable my users to accomplish things?
So the network started to come later. Now we live in this world where, where we have to think globally from like a performance perspective. And I'll, I'll give you an example of a challenge I faced in one of my roles where we had a big team in Argentina at this company, and they were like, man, Salesforce performance is really, really bad.
And, and this is back in the days when I'd actually have to call the telecom and be like, Hey, you know, what's the deal? What can I do about latency? You know, blah, blah, blah.
And like, they changed something in a routing table. I don't know why, you know, this was South America. Apparently you can change things routing tables in South America.
I don't know if that's a good idea. Really. Course got better in another application got worse, right?
And so that was the trade off. And I remember thinking to myself back then, like, man, I need a way to bypass this. Like, I, I need a way to, I need an abstraction layer of this.
I, I don't want to call the carriers if I'm having one application performance issue in some of the part of the world, I need more flexibility. But that flexibility would've been really expensive too. I would've had to buy pops in multiple carriers in multiple locations and do some kind of IP sec tunnel meshing to like make multiple pathways so that I can control the routing.
And like, that's a drag. It's expensive. It's hard to maintain.
That's not gonna work. This transformation world that we're in now with connectivity cloud in this idea of a connectivity cloud is exactly that abstraction layer. Why?
Like, it doesn't make sense for thousands of customers around the world, thousands of companies around the world to build their own IPSec tunnels across different, you know, mesh networks and try to make this happen. SD-WAN kind of proved that that wasn't a great idea, by the way. Like SD-WAN gonna say, Most people think connectivity cloud is put SD WAN at the edge and you're good.
No, I Was like, no, it was actually pretty complicated. Yeah, SD WAN tried to solve the problem exactly that way. Multiple carriers, multiple sites, and SVPN tunnels didn't exactly deliver what they were wanting.
Instead, you started seeing companies pop up where they were saying like, Hey, we're maintaining a bunch of pops all over the world. You can connect to the closest pop and then we'll figure out how to make your traffic optimized. But even that was a bit of a drag because you were still developing like IP SEC tunnels to these individual places.
And so there's this extra layer of like, I'm encrypting the data through a tunnel and then it's gonna come back through this. And there's still choke points, uh, that, you know, so it's not the optimal thing. Um, at CloudFlare we have technology that literally, uh, decides which path is the fastest on the fly based on circuit utilization.
So compared to routing protocols in routing protocol world, you're, you're picking fastest path based on speed. You might find a faster path, for example, that's like one hop is faster than the other hop, but overall that that path is faster. But BGP only optimizes for certain types of path optimization.
In our world, we're looking at like, what's the saturation point of a particular link? And should I send you this way versus this way based on the actual traffic dynamically in this moment for this packet? And that's, that's one of the things I think is really cool about our technology is this idea that like, I can make performance really what, like great for end users.
The user experience is incredible, uh, based on current conditions, which is, which is amazing. And I'm nerding out with all these telecom networking terms you mentioned, uh, zero trust before. You know that, that, that is a, a, a giant elephant to E two, right?
Two simple words. It sounds good, like a good idea, but implementing that strategy can be a handful. H how is what you're doing with the connectivity cloud make that easier or at least the path to get there?
I know it isn't all just the network, right? But love your thought. I'd love to hear your thoughts on that.
So it's, I'll like, let's, let's like reminisce for a sec about Hey, we're all, Hey, it's good with us. Go ahead. Absolutely.
Hey Alan, would you unplug the router over? Yeah, go ahead. Yeah, I liked it.
He said BGPI. I'll be honest with you, I got a little swell coming on my face. There we go ahead.
Yeah, let's like reminisce a little bit. You know, back in the day when, you know, like one of the, one of my gigs, I I I, I'd set up what I called like a, a wall garden approach where if you were trying to get to the database VLAN n and the data center, you had to VPN it, even if you're on the inside, right? Right.
And so I had sort of develop this approach. The inside interface of the firewall had to allow v VP N connections and then only the DB database admin had, right? To get to that vlan n Like, that was, that was a way that I secured it.
Uh, you know, I, I had this concept of the outside of the inside and then differing, you know, microsegmentation of the data center in terms of how to secure the business and meet all of our compliance requirements. VPN was how we did that back then. But it was a pain because people had to log in twice.
I logged into my laptop and then I logged into the VPN. Um, and, and so there's like a two step process and the end user doesn't, they shouldn't have to care. They shouldn't have to think about it.
The best security is the security that just works and is already there. Like the natural, when the natural thing to do is the secure thing to do, we're winning. We know that, that the people are gonna be most likely to follow the path to least resistance.
They're gonna do the thing that works well for them. And, and let's, let's face it, let's not put any more steps in between them and what they're trying to accomplish, right? Like, we want them to be effective, we want them to, to work well.
So that's the design. So rewinding again, like in the old school world, we did that with IP second was painful, it didn't work well. Uh, and, and people were frustrated, increased support costs.
It was, it was very hard to manage. Now let's wreck that whole paradigm too. We start moving applications out.
My application's not behind the firewall anymore. So the IP secal is kind of a waste. In fact, the IP cell secal made it worse because someone in Georgia's VPNing, the San Francisco to get you an application in New York, and now more applications are coming from different parts of the country.
And that performed like, oh no, my zoom call was terrible. Huh. That's weird.
While we routed all your Zoom traffic through the tunnel. Oh man. Well that means that, like I added latency 'cause my Zoom traffic went all the way to one coast just to get to another coast.
Or the first person to join that meet call was, was in Japan. And so the pop that Google spun up for that meet call was in Japan. And like nobody's latency was good for that one.
You know, all these different things are happening. Um, now let's talk about how we would secure that in the modern world. So with every challenge that we've seen in terms of the evolution of the internet and applications and SaaS, we've created opportunities as well.
If the old firewall was here's some IP addresses, uh, and I'm filtering based on IP addresses and domains and blah, blah, blah, the new firewall is actually the person, the new firewall is who you are. What is the device you're on? Where are you right now?
Um, is your antivirus up to date? That's actually the new bit of information. And being able to make contextual decisions around which applications are you allowed to get to right now based on the context.
So like, I can now paint a picture with the zero trust world. I can paint the picture by having the zero trust client on their laptop. They, they're already authenticated to it, they don't know it's running.
You can see the icon, but it's, it really seamlessly disappears in the background. But now I'm evaluating your ability to access applications based on what I know about the device you're on. You're on a company device, but you're, um, you're in an airport in, you know, some other country, right?
Like, well, maybe I don't give you access to certain tiles in the single sign-on profile because I don't want you to have that. You're in a place where you probably shouldn't use that, right? Or I wanna make sure that you're following the best path.
Um, the zero trust client can decide, for example, on the local machine that like, Hey, all Zoom traffic's just gonna get routed straight to Zoom. Like we, we don't need to route this through a tunnel because it's not gonna be any faster. In the case of our global network with all the pops that we have, our, our zero trust client could decide that it's faster to go through the, through our connectivity cloud, right?
So like the best, the best option wins the most performance options wins. But also the, the context of like, what security outcome am I trying to drive also wins like, hey, this, you know, this is sensitive data traffic, we're hitting our dashboard. This needs to always go through the private network and never go through any kind of unsecured channel.
So zero trust is a way of taking who someone is and the information about where they're right now and applying that to what kind of access that they need to have while also giving them performance enhancements. And by making the decision on the laptop or on the, the nearest edge, instead of like somewhere in a central firewall, the performance is naturally better. Like you're making the decision fast, you're protecting the user more quickly, And you've shifted it from that firewall from going back to headquarters to, you know, a basically intelligent app that knows what can take those rules, those policies, and also, you know, these costs routing and what's the best path there.
But, but really that's the whole point of this is we shouldn't have to take anything back. Yeah. Mm-hmm.
To the central, to, to the land, to the, you know, to the big honking box back there or whatever, or VPN Concentrator, right? That's the whole point of having an edge and, and doing all that. I mean, you know, we, we wanna be done with that.
Um, here's a worry I have though, Mike, and I'll ask you directly, there are only a handful of companies in the world I think that can provide this kind of solution, right? CloudFlare being one of 'em is that I mean's a great barrier to entry if you're a shareholder, right? Um, but is, is that putting all our eggs in in one basket kind of thing?
Do we need, like how do we, do we need more modernization as part of that modernization to have a broader set of options? Hard question. It is a hard question.
And I think, let's reminisce again. Okay. So, you know, back, but going back to the days when people moved their workloads to Amazon, right?
There's a lot of trust that had to go into that. Yes. That that massive amount of trust and Amazon learned on the fly.
Uh, I, I'll never forget the first time somebody pointed out Amazon EC2 to me, I spun up an instance and I did some network scanning on it, and I was like, this is terrifying. I could compromise this instance pretty fast because he spun up with a public IP address. He was completely unprotected when EC2 first launched.
It was like, whoa, who is? And so my boss had asked me back then, he was like, alright, so what do you think? And I was like, now is not the right time, but watch out.
Like this is gonna be a big deal. We had to trust these cloud providers over time to like get better at protecting things. But we still took the risk of siloing.
Like when you were in AWS's infrastructure, you're in their infrastructure. You use their terminology, you use the tools they give you. I mean, let's contrast that with a second before that, that that model, we, we, we all don't like, of like bringing everything into a VPN concentrator of your CEO, right?
Like if you an office, why did people do that? Well, I, I probably bought some product that's sniffing traffic that can decrypt it and help me understand threat analysis or whatever the reason companies felt safe bringing all the traffic home was that like, I can inspect it, I can try to figure out if something weird's going on and I, and I can work with it that way. But that didn't really work because the cost was performance.
The cost was like, is anybody really looking at that intel? Um, how up to date is that intel? And, and you know, in the security space, these type of threat products change constantly.
Like the security landscape is constantly changing. So I don't think there was ever really much of an advantage to that IPSec model where you bring everything in into your house and you inspect all the traffic. But then when we moved to Amazon, it was like, wait, where's my packet inspection?
Like how do I know what's going on? So I would say first of all, to, to start to answer the question is like, we've been trusting other companies that have silos for years. GCP has its own silo.
Oracle Cloud has its own silo. You know, a a Azure has its own silo and they're incompatible silos. Um, the only compatibility layer they have is the open standard of IPSec.
They're like, we can talk over something that works anywhere else, but it really doesn't give us any advantages. So now zooming out for a second with companies that are providing this, this like glue that stitches all these different clouds together, and they're only being a handful of them. It's no less risky than it ever was to make the first leap of migration.
Um, but the performance has to be worth it. And so I think nobody wants to employ an army of network engineers to try to keep a thousands wide psec tunnels online, um, to maintain this in-house and build some weird Goldberg approach, especially when the cost of doing this through provi through providers that are making this their core business is actually really, really low. The trust factor is no, not much different than the old trust factor used to be like, I have to trust somebody or else I can't do a business.
Um, but I I would say that because we bet the farm on this, this is what we do that makes us accountable. Yeah. Like we are by nature accountable.
And, and one of the things that I love about CloudFlare is how we are accountable in ways that are, that are responsible like Project Galileo where we give away services to, to people who can't defend themselves so that they get all the protection of our cloud without connectivity, cloud without having to pay for it to make sure that their voice isn't lost and that someone can't decide to take their voice out. Um, we take this job very seriously and I think it, it is about following, following the intent. Like, you know, what, what, what do you do with this?
Like, we, we really do believe in building a better internet. And I think that's critical, but to your point, there's only a handful of companies that are gonna be able to compete in this kind of space because the innovation is blazing fast. Uh, and, and really something you want to get onto.
And I, and I thought that the po the title of this was really fascinating to me on the transformation bit because usually in my world, when you talk about transformation, it's like business process transformation. You know, can I take some antiquated process and turn it into a digital process? But the network transformation's different because now it's more like treating Earth is is a global network instead of my locations on earth.
Yeah. As, as my individual networks. And I think that's where the, the paradigm shifts starting to come.
Agreed, agreed. Look, you know, this is a, this is the complexity of, of the, of the technology that we use today. As I mentioned in the beginning, right?
Sprinkle a little AI and really complicate things. It's only going to continue to, to become more complex over time. Like maybe we could simplify what an end user's use, you know, it's easy for them to use.
But behind that curtain, man, it, it, it's complicated. I, I wanted to talk a little bit, and this is a topic we haven't brought up on the last great cloud transformation, which is, look, whether you use AWS or Google or Microsoft or Oracle or any combination thereof, really the more the merrier as far as we're concerned here in terms of the connectivity cloud, right? So there there is no, you know, so early on, you know, reminiscing early on, if you were AWS you were AWS, right?
You were all in. The only thing we can contemplate was a hybrid cloud where maybe I'd keep some of my stuff back in my own data center and some on the public cloud. But of course, in today's world, we've, we've realized that's probably not as realistic as I go to whichever public cloud is, right?
For my particular, yeah, for this particular use case. They have other use cases here, use cases there. And I do need something that kind of ides 'em, brings 'em together.
Um, you, you know, you've been in this from the get go. When did you realize that this multi-cloud, 'cause it was, I it, I'll be honest, it surprised me. I didn't see it coming.
When did you realize that multi-cloud was gonna become sort of the way, the dominant way, the preferred method? Probably I was thinking back to like 2012 when I worked for a, a VoIP startup and we were using, we were OnPrem and we were using a, um, Amazon to develop VoIP at the edge on their side for customers. Like how would VoIP work in an a AWS context?
And I was thinking like, man, this is a lot of eggs in one basket. Uh, and with, you know, Google's no slouch at cloud and they were talking about cloud, but it wasn't as mature yet. And Amazon had this incredible explosion of Legos, like, because let's face it, they took open source products and productized them as services, right?
Yep. So you just take open source software, productizing services, they're cranking out Legos as fast as you can. It's like all of a sudden the elastic search is Allego that you can just run MySQL with.
Multi-site replication is something you can just run. Like they, they took the stack of the three tier web architecture and sort of made it a service, which is really interesting. And I was like, so initially I was worried about like, God, I hope somebody competes with 'em because it's, they're, they're, they're really far ahead.
They're, they're really far ahead. Their, their work with Netflix pushed their envelope really hard. Like they, I think Netflix was one of the biggest customers that pushed to the edge and to the limit and forced 'em to rethink things.
And I was watching Google come up and with less excitement, I was watching Azure come up and I was like, well, at least multi-cloud has to probably exist. And I was thinking Azure adopters will probably be p people that feel safe with Microsoft, with, they have a lot of Microsoft applications and it will just naturally make sense for them. And then Google will be the, the other people that are like, just not just not Amazon or I need another cloud strategy, but like, I've been happy to see Google come up and really own it and make, you know, a great cloud product that has a lot more Legos and a lot more connectivity.
They've got a good product going, Azure's doing a great job as well of making it easy for their customers to do business on the cloud and have options. But we're seeing another move now back to colo and back to some on-prem things where companies are realizing that, you know what things, it's way cheaper for me to own the metal. It's way cheaper for me to run it myself, and I'm gonna move this workload.
Part of my initial thing with, when I, when I go back for a second for like, oh my gosh, I hope there's competitors. It's because I was like, man, this is a lot of eggs in one basket and they can start to control our margins. So like, if I give Amazon too much business, they have too much control over my margins and I don't like that.
But moving workloads is not trivial either. And so my, my fear on multi-cloud early on was like everybody will need a multi-cloud strategy, but it will be optimized towards maintaining leverage. I need to maintain leverage and that leverage has to be material.
I need to be able to act on it or else it's not really leverage, right? All the while watching cloud providers try to compete with each other while also trying to escape commoditization, like commoditization, you know, yeah. Are gonna go down.
Value added services are going to go up it. To think about it in a less technical context, I think about baby carrots, which now you're probably going like, what the hell, Mike? Where where are you going?
But seriously, you know, farmers growing carrots make very little money on carrots. If I sell them raw in the store. All a baby carrot is, is a big carrot that's been chopped into little pieces and skinned like that's a baby carrot.
But that value added product actually goes for more money. Cloud providers do the same thing. They take something like, Amazon's a master of this.
Take an open source product, run it as a service charge way more than it costs you to run it value added service. Like they're nailing it. But me as the buyer, I need some control.
I need to be able to control my costs. And so a multi-cloud strategy is part of what I need to do that because I have to understand like the nuances between, you know, provider A and provider B and my applications and what those needs are. And so any multi-cloud strategy has to be centered around what am I trying to accomplish and what kind of continu business continuity do I need to maintain?
So yeah, it's, it's a fascinating world that we live in, but the, the multi-cloud thing had to happen because in a world where there's only one player, they can, they, they ultimately wouldn't be giving people any kind of choice. Like, it, it's too expensive to run with just one player. Like they really control the cost.
And I, I already think it's really expensive, um, because people leave workloads running, for example, you know, always you're, you're you're trying to figure out like why is it I call 'em zombies, like somebody leaves zombie workloads running. You're just like, man, the meter's running, like nobody's using this thing. Well yeah, we rack it up to dollar Good to manage.
Yeah. Like I think multi-cloud is hard to manage too, but it's also inevitable. We have to distribute our risk.
We have to distribute our workloads and make sure we maintain leverage and negotiations. So multi-cloud was natural, but it took a long time to get here. 'cause keep in mind, I was thinking about this in 2012, and like you really couldn't have a true multicloud strategy in 2012.
Even today, it's pretty hard to have one because workloads aren't exactly portable. Like there's some, there's some changes in that world, but they're not portable yet. No, I I I'm sorry.
Go ahead Mitch. So many Of us is, I was just gonna say, so many of us have kind of backed into it right through m and a activities. Yeah.
You know, we're this cloud now. Yeah. There's a lot of that Pre cloud and you had to, you know, what do you do to try to make sense of it just to operate it effectively more or less, get to a point where that's part of your go forward strategy and what workloads can you distribute across those or move across those clouds?
Not, not a simple question. I, to me it's more, you know, a thing I learned as I was growing up and, and gotten older was it's not the man, it's the tool and it's the right tool for the job. I think for particular jobs, there are cloud providers as well as other options, right?
My own colo or what have you, my own data center that are the right tool for the job. And I think the job of today's CIOs and, and architects is to figure out what's the right tool for this job? What's the right domicile for this job?
How do I use the connectivity cloud to glue that all together and make it look at and appear and act as one contiguous infrastructure, but still use the right tool for the job. And I, I, I think that's what does it, And it, and it kind of goes back to the, to sort of ideal state of what a security tool would do, which is like, allow, I'll please allow me to maintain a policy and a posture consistently, right? Its security cloud is about that.
Like, we have the same players, we have users, we have services, we have servers, we have applications, we have all these different things, but like, allow the policies to be uniformly applied and allow me to prove that I know what's going on. Agreed. Agreed.
Guys, this has been a tremendous conversation. I, you know, we went far off, we started with better connectivity and security through network modernization and we discussed a lot of that, but we dis, we reminisced a lot as Mike would say. And, uh, you know, we, it was good doing that.
I look forward to continuing this line of conversation in future episodes of the last great tra last great cloud transformation, Mitchell, I think our next one is a live round table, isn't it? I believe so. Yep.
Yeah, we, we just definitely have one coming up. If You're watching this at home, check it out. Make sure you register for the next live one because I'm sure you've got questions.
I can't promise Mike's gonna be there. He's, he's got a bit of a job to do when he is not doing this. But if you've got questions around the things we're talking about today, we invite you to participate in there.
Many thanks Mike to you and CloudFlare for, for participating and co-producing this with us. It's, these are the kinds of conversations that people like us enjoy. We could talk all day about.
Right. Good stuff. I really flew by.
I'm happy to join you anytime, but I had a great time talking to you today. Absolutely. Well, we'll make sure we'll get you back here.
Don't you worry. Um, Mitch, I didn't get a chance to introduce you, you jumped right in, but why don't you think the last word out then? You know, I, I, I loved, I loved the walk back, you know, looking at kind of how we got to where we are, right?
'cause that informs where we go forward and there's so much, what, what's really changed is you said it Mike, going from points on the earth to the earth as my cloud, right? That's my location. And thinking about, you know, don't use your points of presence that you know about as your limitation.
Just like, don't use your, you know, hauling traffic back to the VP n concentrator or the center of the network, either. That's, it's a different paradigm. It's a distributed processing network and, uh, there's a lot more things we could do with it.
So it's an exciting future. We appreciate you, Mike, sharing your, your experience with it as well. Alrighty.
All right. On behalf of Techstrong and CloudFlare, thanks for joining us today. We'll be back with another show soon.
Until then, everyone, good luck. Take care. Hi everyone.
My name is J Wood and today I'm gonna talk a little bit about improving dev ops workflows using generat tv, AI, and GitHub copilot. And a little bit about me. I am the AI impact lead at GFT Technologies.
I am the 18 years Microsoft MVP, the first Brazilian GitHub star. I'm four years in this program, but it's a personal honor to me to be, uh, the first one in Brazil to be a part of this team. And I'm speaking in technical conference like that.
Um, YouTuber about technical contents like DevOps, career, uh, productivity and other contents like that. Here is my YouTube channel, my linkage profile and my mail, um, if necessary. Okay.
And we are gonna talk about NAA on DevOps workflows. And I think the best important point is talking up shortly, uh, about what is, uh, generative AI because well, it surround everything about STEAM and about software development lifecycle, uh, in next years. And basically, uh, generative AI is a kind of AI that, um, using algorithms to create a, a, a new contents like a text, just like, uh, images, like, uh, videos.
And in our case, create a source code, create documentations, and, uh, support us in a lot of tasks, uh, in the software development lifecycle. And this tool is, general call is called generative AI because, well, it's a little bit, obviously because this generate a new content based on training data on historical data. And this AI can be understanding your request to generate a new content base, uh, in, uh, what you needed here and, and to, to work with the JEA tools, uh, important technique.
Technique was born the prompt engineering technique or the prompt engineering. Uh, it's a new FO position in, in some projects right now. And what is, is this in general?
Uh, the prompt engineering is the art of crafting effective instructions to get the best response from AI models. And why I'm talking about the art 'cause it's not properly exact science because, um, we cannot have, for example, the same answer, for the same question. And, uh, we have no specific room to create a a, a good prompting.
For example, if I request this specific question, I will be received this specific answer. It's not, um, a really true information. In general.
We need to to work as a artist to understanding what works, what not, and create a best prompt, a best approach, a fight turnage prompt to support your creation. And it's not only for creative images or videos to create text just to create source codes, documentations, all of them followed the, the same instructions and the prompting properly. Basically, it's a, uh, a piece of information, a collection of information that you can provide to generative VA to, to generate a content based on your request.
And, uh, on and in your AI training data, the generative AI uses the both of them to generate a best answer for you. And you need to understand here, we you need to create a detailed prompt or with a more contest as possible to create a best answer. Basically, if, uh, good things, uh, in, in the prompt, good things will be answered.
If you provide no good information in the prompt, probably your answer will not be good too. Okay. And here, for example, I have two requests that I did on GitHub copilot with basically the semi prompt in a, uh, it's essentially the same prompt, basically, uh, is that I'm building an application to display electric vehicle data, gimme some options for how to instruct structure GI app.
In the first one, I have no many details. Uh, I'm directly on on that I need, and okay, GitHub co polish answer to me, and it's, this answer is okay, it's good answer, but it's not specific for what I really need. In the second one, I provided more information.
For example, I specified that using express and type script or I'm large scale application, uh, I need to use a key clock to cage my front change. We me use type script and will be deployed on Azure Kubernetes. Using all of this information in the prompt, GitHub copilot can be provided to me.
Um, a more specific answer, a more useful answer to me. Uh, I not pasted here or print, but, uh, here you can see the difference about the answer. In the first one I received, I received the options.
In the second I received the read the structure following my request. Uh, in the other parts of this answer, I received a piece of codes for, uh, doca container for scripts, bernet services, uh, to scripts for GitHub actions. I received more, uh, specific information for my request, basically, as I mentioned, good thinking, good things out, okay.
And, uh, how this prompt works on GitHub copilot, but not only on copilot, but in general, the other tools that use in general TV i works, works, uh, uh, the same model. Okay? Basically, you, uh, as user will be request something, for example, in case create a observer in TypeScript, and this information will be sent for, for GitHub copilot.
What happened here in, in the backend, the GitHub will be includes assistant tag here. And the system tag basically is, um, the chat bot or the assistant, uh, rule settings. And for example, this, the GitHub are including you are a friendly code assistant and probably, uh, probably the content, the most content here is something like that European answer only question about source code.
You are not creating vulnerabilities on the code or you are not able to answer question about politics. Uh, all of them on system information will be create a set of rules that this, uh, this tool need to follow. Okay?
And the user will be, uh, your request and it'll be sent for LLM model in this case for G PT four GPT-4 O or other model. But you can use AWS models or other LLM models. It's not, don't care.
And your answer will be processed by, uh, OpenAI or LLM and include here a new tag for assistant tag with the answer and t answer will be considered the training data, the assistant tag, the user requests to create a, a, a goods assistant master, okay? And copilot or the other, uh, gene tool returns for you, uh, piece of code or the answer that you request. Okay?
Okay. But probably thinking, uh, why you need to use, uh, gene a eight tools on, on the vs. Workflow on the VS process.
And important thing to remember here is it, it's, uh, a point that some people forgot, forget because, uh, the DevOps is not only about CI and CD automations, it's not about, uh, building deployed application on cloud environments or in, in other place. The DevOps is general about think type software development lifecycle. Uh, it's about all people on this process, uh, since the ideation, the code creation, uh, the testing, Q ratings, infrastructure things, monitoring process, all of them, uh, are, is a part of the software development lifecycle and DevOps process.
And, okay, to me it's important for now in, in this specific talk for core items, focusing specifically on the developers, uh, to increase, uh, to use, generate, generate tools in other DevOps, uh, workflows. These key tools are enhance developer experience, increase the productivity, increase the learning, and focus, uh, on the business. And why this for us, most important in my opinion, well, when I started to work, uh, in a software development a lot of years ago, I don't remember the correct year, uh, one of the first lessons that I learned from my first boss was the user experience is the most important part of, of the software development.
Because if the user don't like your application, the application will be not to use it. And this job, uh, is, it's a trash basically, is that, and he has, it's properly, it's really true. Uh, it's important, but we forget an important part of this process.
Okay? Now more people are talking a little bit more about that, is that the developer experience? But it's not com very common yet.
And it's important part of the software development because if the dev have a good experience in your environment, in your software creation process, the software, the, the, the fine off the job will be good too. If the developer have a good tools, uh, a good environment, a good support, uh, this job will be better. And the DAA tool can be supporting this can be improving this process.
Uh, the NAA is not focused to solve all points and not, uh, a bullet point, sorry, it's not a bullet point to, to solve all problems, but it's important thing to improve the soft, the developer experience, uh, in, in day by day. And in the same time, it can be incr increase the developer's productivity because using gene tools like a GitHub copilot for example, uh, is not necessary more for this developer. Uh, make, uh, extensive researches on the internet about, uh, common tasks because these tools already generate suggestions focused on, on, on this task.
If I need, for example, to create a switch case in Java, and I I not remember, uh, how can I do that? I don't need to go to the forums, I don't need to go to the Google because this assistant I read suggest to me, I need you to start to start to create comments and they'll be, receive, uh, suggestions for this or using AUB co pal chat or other AI tool, like a chat, uh, chat experience to have an answer about that. It's increased the productivity a lot, and it is not only this, but using to automate documentation to support, uh, me to generate energy tasks is and other parts of this process.
And it can increase my learning how using the same generate tools to supporting me to understanding other parts of this project or to understand what project does. Ima imagine that you are starting in a new project and you have no information about that you can use generate tools to generate documentations, to generate explanations to generate, um, conversation or documentations to support you to understanding easier what the application does and how can you, uh, support this development team faster. Okay?
And using all of this, we can focus on the really important part in the software development in the business because we don't need to focus anymore in the common tasks or in documenting or create a simple pieces of code. We can focus on the more important part. We can focus in the really, uh, complex part of this process to understand the business rules, what you need to implement here into the detail to, to improve the application, to create a best applications.
Okay? And in, in general, how can this generate tools, improve the software development, uh, to DevOps workflows? We can create, uh, talk a lot about a lot of points, but I have here five main points that we can use because this point is the, is the topic that I, I can, I'm seeing in the clients I'm seeing in my job recently, okay?
And can be increased our productivity, uh, a lot. The first one is the code creation. It's the most common using tools like a GitHub copilot because the GitHub copilot, as I mentioned before, providing you code suggestions, code snippets, uh, documentations, code explanations, uh, support you in a code corrections support you in a lot of tasks in the, in the code creation process.
Okay? The next one is the code review. While I'm talking about code review, because, uh, well in general, it's, uh, very common or I, I, I guess it's essentially 'cause all developers need to create a merger requests or a cool requests before merge the source code.
And in general, in theory, uh, the developers need to describe their change to support the approval chain to understanding if exchange make sense or have, uh, problems. And in general, the developers only describe merge domain or merging feature, blah, blah. Uh, and it's not a new usable information.
And the approval need to go to the source codes red line by line, what code does, if it makes sense or not. It's a boring process, it's a boring job to do. And using generat TVA A, we can use these tools to understand the change and provide a useful, uh, description for this request description, file by file recommendations, uh, vulnerability explanations.
And I need to go only to the source codes. If I seen, uh, something wrong in the codes description or I need to call the developer to understand this change, only if I, uh, I seen something wrong in the codes description. It's a, a good point to pro productive gain.
The next one is the documentation. The idea here is documenting your source code, because we know that we have in general two scenarios, one or the second. The first one is I don't have documentation because no one do this in the past.
And the second one is, yes, I have documentation, but it's a very, very outdated documentation because someone create this in the first year of the project and no one updated this anymore. And it's a problem because in both cases I have no documentations. And we can use generative A tools to create in this.
And you can automate in this process, uh, in a different parts of your software development life cycle. You can use, uh, the IDE from developers to create this documentation. You can include this documentation process in a per request.
For example, you can have a scheduled pro, uh, process to create this documentation. And in the future, we can put this in a conversational chatbot to, to, to do more, easier to interact with with your documentation pro process and maintain this alive easier. The next one is the test generation.
And here we can pause is possible to create unit tests, uh, using general tva, following company standards, following, uh, company frameworks and a lot of other important rules. And we can create here to, uh, functional testing, uh, and uh, a testing of interface using natural language. Uh, we don't need to create anymore, uh, HEML mappings, uh, CSS mapping fields.
We can use natural languages to, uh, create this testing process. It and all of them use in general, TVA a, uh, turning this job more easier. The next one is the code correct action.
Because we know today we have a lot of vulnerability in the code and we already use SaaS tools to, to generate a report for us about this. And soner fortify other SaaS tools, other secur tools provide us information. And you can, we can use generative VA to use this information to generate a correction for our codes and correct vulnerabilities, issues, codes, now bugs and and much more.
And in the next we can do much more than that. These five points, uh, are the most common that I'm seeing here are most used that I'm seeing here today. But we can do this for example, uh, a creation of your backlog using generat, TVA using, uh, describing the use case for a gene, a tool to create your app because your features, your user stories and tasks, for example, uh, you can use this to do a reverse engineering into source code to support a legacy modernization.
You can use this in not a lot of different parts of your software development life cycle to increase your productivity. Okay? And day by day, uh, uh, a new tools are born to support us in in these parts.
Okay? Uh, what tools I'm using at this moment. The first one is the most common GitHub copilot.
'cause this tool is a very interesting, it's amazing tool that support developers in, uh, DA lot of different tasks. The most common is using on my ID to generate code suggestions to me, to generating to me, uh, code corrections to generate to me, how can I create testings and other important implementations in general using this tool, uh, to improve my implementations, for example. And the next one is GFDI impact is that to, uh, interesting tool folks.
IT to supporting tyro software development lifecycle using genea and this Fox it productive again. And we have here features like EC log creation, star creation, documentation projects, um, test creation code, reviewing code, core action code, fixing testing, uh, legacy modernization. We have a different set of tools to use in G to improve, uh, the productivity.
Okay? And I like to to to run a, a, a demo for you. Uh, demo two demos that I have here using this GA tools to understand how can you you use in this, in, in your days?
Okay? The first one, it's a more simple I'm using directly on my id. Basically I'm start imagine that you are starting a new project, that you have no information and you need to solve your vulnerability report by a SaaS tools, document the codes and create I tests.
Basically, I received this information, a SONER print screen informing me that I have SQL injection in my class, user Java. What I need to do here, well, opening my ID here, I have this project, it's a, a wide open project in, in the class I can use here my GitHub copilot, for example, asking this, explain me the coach and show me, uh, bullet list with our vulnerabilities to support me to understand if I have more vulnerabilities than uh, I the report. And here I read, received a lot of, uh, information you can see here, explanation of this code, what code does the field that I have, constructor methods, and here the vulnerabilities, the sq, injection sensitive data, expo exposure, improper exception.
Basically a lot of, uh, vulnerabilities here. What I can do here, I can request for GitHub co act only the S scale injection or correct the others and request here correct o vulnerability on the codes. And here the GitHub code PAL will be understanding this and create to me a new version of the SARS code with, uh, the vulnerabilities core corrections here and a short summary of this change.
I can copy this page, this here. And I have here a new version of the source code. And okay, now I need to do a next task documenting this code.
I can open here, text explore, right click on the user and create a documentation. Basically here I need to create a problem that I'm using the language of this application and tell them that I plan to use, and I'm using the GFTI impact here to generate a documentation in the company standards. And we need to personalize this base, uh, on, on what the company needs to, to explain the code.
And here basically, uh, is the generated the documentation. We can open this in a markdown preview. And here we can see overview, process flow, insights and data manipulation to generate tests.
Basically the same you can create here, uh, you need tests. Select a prompt for eworks the language, LLM, and we can, uh, include this on existing files if necessary. For example, if I'm creating a test for existing project and have a unit test, we can, uh, add more testing for this or improving the test or correcting the test.
Or if I don't have tests yet, I can create a new unit test for this project. Okay? And here basically I have this new, uh, test class and I can commit this file and follow my DevOps process.
Okay? And for the next demo, the process will be the same, but I will be create this directly on my GitHub, following my uh, DevOps pipeline. I'll update the code using GitHub copilot on web, create a pool request document, create a test and review this p pool request.
Basically, I will be use, uh, i in the same repository. It's the same vulnerable project to repository. I will be click, click here on the copilot section and I will be describe a task and I be request solve SQL injection on user, do Java and I will be start this task.
Basically the GitHub copilot will be understanding my source code, my vulnerabilities, and will be propose a solution to correct this code. And I can here generate a plan. GitHub copilot will be understanding the class and the steps and click, I can click here to implement this files properly.
And copilot will be generate a correction for us. It's, uh, a very quick process and here we can see the old version. The new version includes correction, the SQL injection, the parallel corrections, and I will be create a new pull request here to implement this change and create an I will be open my GitHub again.
And here I have now a poor request. What happens here in the beginning, uh, that time created its poor request. A pipeline will be triggered by GitHub actions and this pipeline will be trigger my GFTI impact to create to me a documentation to create to me a unit test and then create to me a reviewing process.
It's not a long process, but we can, uh, see here the pipeline running, uh, to monitoring this, it's creating the testing for us for now. After that, we'll be saving on the poor request. And after that the document, uh, we'll be documenting this project.
And the interesting here is that we can guarantee that all the time that the developers create a new change, create a new request, we can maintain the documentation alive and we can guarantee test that the unit test will be, uh, create automatically in your repository. For example, here, the test is already created. And here I have a new comment for the unit tests and I need to wait for the documentation PRO process.
It's a wiki process too. And, and, and all of them, as I mentioned, documentation testing, we can adapting this and it creating a more specific scenario to generate for specific situations. We can create a specific documentation for COBO projects or for dotnet projects or for Java projects and following different standards for each one here, I think that the documentation now read generated two only waiting here, okay, I have the tests and documents generated.
And if I'm going here for the file changes, now I have first one, the user Java, the file changes by uh, GitHub copilot. And here I have the user test Java. I already have tests on my project for this class and GFTA impact.
She understood this and only updated these tests, creating more tests if necessary, correcting tests or removing tests that was not necessary anymore. And in intent created here a documentation. I didn't have documentation before.
And for now it creates a new version. But in the next request, it'll be create only, uh, an applicated version of this documentation. It's in marked now file and you can save in your repository or integrate in another tool that you are prefer to use.
And let me go back here. And now in the request we have the code reviewer. And it's interesting point because it's provide for us information about the developer change.
It's provide to me a description. It provides to me a summary explaining file by file, what support request does in not only for the poor requests, uh, for the file changes by GitHub co-pilot or the developer, but the the for the files created by uh, GFGA impacted tools. And here we have document, uh, recommendations for this poor request and vulnerabilities explanation.
And I can see here now for example, that I have other vulnerabilities that I need to solve and I can make a decision with, I will be approved this or request to developer correct this solve other poor requests. Okay? Okay.
I think that my time is now, uh, is finished and here is my contacts. You can see here my linkage in profile, my U YouTube link again and my mail address if you like to talk with me. And I think it's now for today.
Thank you for watching my talk. My talk today.